wpa_supplicant: Share attach/detach/send UDP ctrl_iface functions
[mech_eap.git] / wpa_supplicant / ctrl_iface_udp.c
1 /*
2  * WPA Supplicant / UDP socket -based control interface
3  * Copyright (c) 2004-2005, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8
9 #include "includes.h"
10
11 #include "common.h"
12 #include "eloop.h"
13 #include "config.h"
14 #include "eapol_supp/eapol_supp_sm.h"
15 #include "wpa_supplicant_i.h"
16 #include "ctrl_iface.h"
17 #include "common/wpa_ctrl.h"
18
19
20 #define COOKIE_LEN 8
21
22 /* Per-interface ctrl_iface */
23
24 /**
25  * struct wpa_ctrl_dst - Internal data structure of control interface monitors
26  *
27  * This structure is used to store information about registered control
28  * interface monitors into struct wpa_supplicant. This data is private to
29  * ctrl_iface_udp.c and should not be touched directly from other files.
30  */
31 struct wpa_ctrl_dst {
32         struct wpa_ctrl_dst *next;
33 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
34         struct sockaddr_in6 addr;
35 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
36         struct sockaddr_in addr;
37 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
38         socklen_t addrlen;
39         int debug_level;
40         int errors;
41 };
42
43
44 struct ctrl_iface_priv {
45         struct wpa_supplicant *wpa_s;
46         int sock;
47         struct wpa_ctrl_dst *ctrl_dst;
48         u8 cookie[COOKIE_LEN];
49 };
50
51
52 static void wpa_supplicant_ctrl_iface_send(struct wpa_supplicant *wpa_s,
53                                            const char *ifname, int sock,
54                                            struct wpa_ctrl_dst **head,
55                                            int level, const char *buf,
56                                            size_t len);
57
58
59 static int wpa_supplicant_ctrl_iface_attach(struct wpa_ctrl_dst **head,
60 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
61                                             struct sockaddr_in6 *from,
62 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
63                                             struct sockaddr_in *from,
64 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
65                                             socklen_t fromlen)
66 {
67         struct wpa_ctrl_dst *dst;
68 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
69         char addr[INET6_ADDRSTRLEN];
70 #endif /* CONFIG_UDP_IPV6 */
71
72         dst = os_zalloc(sizeof(*dst));
73         if (dst == NULL)
74                 return -1;
75         os_memcpy(&dst->addr, from, sizeof(*from));
76         dst->addrlen = fromlen;
77         dst->debug_level = MSG_INFO;
78         dst->next = *head;
79         *head = dst;
80 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
81         wpa_printf(MSG_DEBUG, "CTRL_IFACE monitor attached %s:%d",
82                    inet_ntop(AF_INET6, &from->sin6_addr, addr, sizeof(*from)),
83                    ntohs(from->sin6_port));
84 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
85         wpa_printf(MSG_DEBUG, "CTRL_IFACE monitor attached %s:%d",
86                    inet_ntoa(from->sin_addr), ntohs(from->sin_port));
87 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
88         return 0;
89 }
90
91
92 static int wpa_supplicant_ctrl_iface_detach(struct wpa_ctrl_dst **head,
93 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
94                                             struct sockaddr_in6 *from,
95 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
96                                             struct sockaddr_in *from,
97 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
98                                             socklen_t fromlen)
99 {
100         struct wpa_ctrl_dst *dst, *prev = NULL;
101 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
102         char addr[INET6_ADDRSTRLEN];
103 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
104
105         dst = *head;
106         while (dst) {
107 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
108                 if (from->sin6_port == dst->addr.sin6_port &&
109                     !os_memcmp(&from->sin6_addr, &dst->addr.sin6_addr,
110                                sizeof(from->sin6_addr))) {
111                         wpa_printf(MSG_DEBUG, "CTRL_IFACE monitor detached %s:%d",
112                                    inet_ntop(AF_INET6, &from->sin6_addr, addr,
113                                              sizeof(*from)),
114                                    ntohs(from->sin6_port));
115 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
116                 if (from->sin_addr.s_addr == dst->addr.sin_addr.s_addr &&
117                     from->sin_port == dst->addr.sin_port) {
118                         wpa_printf(MSG_DEBUG, "CTRL_IFACE monitor detached "
119                                    "%s:%d", inet_ntoa(from->sin_addr),
120                                    ntohs(from->sin_port));
121 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
122                         if (prev == NULL)
123                                 *head = dst->next;
124                         else
125                                 prev->next = dst->next;
126                         os_free(dst);
127                         return 0;
128                 }
129                 prev = dst;
130                 dst = dst->next;
131         }
132         return -1;
133 }
134
135
136 static int wpa_supplicant_ctrl_iface_level(struct ctrl_iface_priv *priv,
137 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
138                                            struct sockaddr_in6 *from,
139 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
140                                            struct sockaddr_in *from,
141 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
142                                            socklen_t fromlen,
143                                            char *level)
144 {
145         struct wpa_ctrl_dst *dst;
146 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
147         char addr[INET6_ADDRSTRLEN];
148 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
149
150         wpa_printf(MSG_DEBUG, "CTRL_IFACE LEVEL %s", level);
151
152         dst = priv->ctrl_dst;
153         while (dst) {
154 #if CONFIG_CTRL_IFACE_UDP_IPV6
155                 if (from->sin6_port == dst->addr.sin6_port &&
156                     !os_memcmp(&from->sin6_addr, &dst->addr.sin6_addr,
157                                sizeof(from->sin6_addr))) {
158                         wpa_printf(MSG_DEBUG, "CTRL_IFACE changed monitor level %s:%d",
159                                    inet_ntop(AF_INET6, &from->sin6_addr, addr,
160                                              sizeof(*from)),
161                                    ntohs(from->sin6_port));
162 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
163                 if (from->sin_addr.s_addr == dst->addr.sin_addr.s_addr &&
164                     from->sin_port == dst->addr.sin_port) {
165                         wpa_printf(MSG_DEBUG, "CTRL_IFACE changed monitor "
166                                    "level %s:%d", inet_ntoa(from->sin_addr),
167                                    ntohs(from->sin_port));
168 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
169                         dst->debug_level = atoi(level);
170                         return 0;
171                 }
172                 dst = dst->next;
173         }
174
175         return -1;
176 }
177
178
179 static char *
180 wpa_supplicant_ctrl_iface_get_cookie(struct ctrl_iface_priv *priv,
181                                      size_t *reply_len)
182 {
183         char *reply;
184         reply = os_malloc(7 + 2 * COOKIE_LEN + 1);
185         if (reply == NULL) {
186                 *reply_len = 1;
187                 return NULL;
188         }
189
190         os_memcpy(reply, "COOKIE=", 7);
191         wpa_snprintf_hex(reply + 7, 2 * COOKIE_LEN + 1,
192                          priv->cookie, COOKIE_LEN);
193
194         *reply_len = 7 + 2 * COOKIE_LEN;
195         return reply;
196 }
197
198
199 static void wpa_supplicant_ctrl_iface_receive(int sock, void *eloop_ctx,
200                                               void *sock_ctx)
201 {
202         struct wpa_supplicant *wpa_s = eloop_ctx;
203         struct ctrl_iface_priv *priv = sock_ctx;
204         char buf[256], *pos;
205         int res;
206 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
207         struct sockaddr_in6 from;
208 #ifndef CONFIG_CTRL_IFACE_UDP_REMOTE
209         char addr[INET6_ADDRSTRLEN];
210 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
211 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
212         struct sockaddr_in from;
213 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
214         socklen_t fromlen = sizeof(from);
215         char *reply = NULL;
216         size_t reply_len = 0;
217         int new_attached = 0;
218         u8 cookie[COOKIE_LEN];
219
220         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
221                        (struct sockaddr *) &from, &fromlen);
222         if (res < 0) {
223                 wpa_printf(MSG_ERROR, "recvfrom(ctrl_iface): %s",
224                            strerror(errno));
225                 return;
226         }
227
228 #ifndef CONFIG_CTRL_IFACE_UDP_REMOTE
229 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
230         inet_ntop(AF_INET6, &from.sin6_addr, addr, sizeof(from));
231         if (os_strcmp(addr, "::1")) {
232                 wpa_printf(MSG_DEBUG, "CTRL: Drop packet from unexpected source %s",
233                            addr);
234         }
235 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
236         if (from.sin_addr.s_addr != htonl((127 << 24) | 1)) {
237                 /*
238                  * The OS networking stack is expected to drop this kind of
239                  * frames since the socket is bound to only localhost address.
240                  * Just in case, drop the frame if it is coming from any other
241                  * address.
242                  */
243                 wpa_printf(MSG_DEBUG, "CTRL: Drop packet from unexpected "
244                            "source %s", inet_ntoa(from.sin_addr));
245                 return;
246         }
247 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
248 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
249
250         buf[res] = '\0';
251
252         if (os_strcmp(buf, "GET_COOKIE") == 0) {
253                 reply = wpa_supplicant_ctrl_iface_get_cookie(priv, &reply_len);
254                 goto done;
255         }
256
257         /*
258          * Require that the client includes a prefix with the 'cookie' value
259          * fetched with GET_COOKIE command. This is used to verify that the
260          * client has access to a bidirectional link over UDP in order to
261          * avoid attacks using forged localhost IP address even if the OS does
262          * not block such frames from remote destinations.
263          */
264         if (os_strncmp(buf, "COOKIE=", 7) != 0) {
265                 wpa_printf(MSG_DEBUG, "CTLR: No cookie in the request - "
266                            "drop request");
267                 return;
268         }
269
270         if (hexstr2bin(buf + 7, cookie, COOKIE_LEN) < 0) {
271                 wpa_printf(MSG_DEBUG, "CTLR: Invalid cookie format in the "
272                            "request - drop request");
273                 return;
274         }
275
276         if (os_memcmp(cookie, priv->cookie, COOKIE_LEN) != 0) {
277                 wpa_printf(MSG_DEBUG, "CTLR: Invalid cookie in the request - "
278                            "drop request");
279                 return;
280         }
281
282         pos = buf + 7 + 2 * COOKIE_LEN;
283         while (*pos == ' ')
284                 pos++;
285
286         if (os_strcmp(pos, "ATTACH") == 0) {
287                 if (wpa_supplicant_ctrl_iface_attach(&priv->ctrl_dst,
288                                                      &from, fromlen))
289                         reply_len = 1;
290                 else {
291                         new_attached = 1;
292                         reply_len = 2;
293                 }
294         } else if (os_strcmp(pos, "DETACH") == 0) {
295                 if (wpa_supplicant_ctrl_iface_detach(&priv->ctrl_dst,
296                                                      &from, fromlen))
297                         reply_len = 1;
298                 else
299                         reply_len = 2;
300         } else if (os_strncmp(pos, "LEVEL ", 6) == 0) {
301                 if (wpa_supplicant_ctrl_iface_level(priv, &from, fromlen,
302                                                     pos + 6))
303                         reply_len = 1;
304                 else
305                         reply_len = 2;
306         } else {
307                 reply = wpa_supplicant_ctrl_iface_process(wpa_s, pos,
308                                                           &reply_len);
309         }
310
311  done:
312         if (reply) {
313                 sendto(sock, reply, reply_len, 0, (struct sockaddr *) &from,
314                        fromlen);
315                 os_free(reply);
316         } else if (reply_len == 1) {
317                 sendto(sock, "FAIL\n", 5, 0, (struct sockaddr *) &from,
318                        fromlen);
319         } else if (reply_len == 2) {
320                 sendto(sock, "OK\n", 3, 0, (struct sockaddr *) &from,
321                        fromlen);
322         }
323
324         if (new_attached)
325                 eapol_sm_notify_ctrl_attached(wpa_s->eapol);
326 }
327
328
329 static void wpa_supplicant_ctrl_iface_msg_cb(void *ctx, int level,
330                                              enum wpa_msg_type type,
331                                              const char *txt, size_t len)
332 {
333         struct wpa_supplicant *wpa_s = ctx;
334         if (wpa_s == NULL || wpa_s->ctrl_iface == NULL)
335                 return;
336         wpa_supplicant_ctrl_iface_send(wpa_s, NULL, wpa_s->ctrl_iface->sock,
337                                        &wpa_s->ctrl_iface->ctrl_dst,
338                                        level, txt, len);
339 }
340
341
342 struct ctrl_iface_priv *
343 wpa_supplicant_ctrl_iface_init(struct wpa_supplicant *wpa_s)
344 {
345         struct ctrl_iface_priv *priv;
346         int port = WPA_CTRL_IFACE_PORT;
347         char *pos;
348 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
349         struct sockaddr_in6 addr;
350         int domain = PF_INET6;
351 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
352         struct sockaddr_in addr;
353         int domain = PF_INET;
354 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
355
356         priv = os_zalloc(sizeof(*priv));
357         if (priv == NULL)
358                 return NULL;
359         priv->wpa_s = wpa_s;
360         priv->sock = -1;
361         os_get_random(priv->cookie, COOKIE_LEN);
362
363         if (wpa_s->conf->ctrl_interface == NULL)
364                 return priv;
365
366         pos = os_strstr(wpa_s->conf->ctrl_interface, "udp:");
367         if (pos) {
368                 pos += 4;
369                 port = atoi(pos);
370                 if (port <= 0) {
371                         wpa_printf(MSG_ERROR, "Invalid ctrl_iface UDP port: %s",
372                                    wpa_s->conf->ctrl_interface);
373                         goto fail;
374                 }
375         }
376
377         priv->sock = socket(domain, SOCK_DGRAM, 0);
378         if (priv->sock < 0) {
379                 wpa_printf(MSG_ERROR, "socket(PF_INET): %s", strerror(errno));
380                 goto fail;
381         }
382
383         os_memset(&addr, 0, sizeof(addr));
384 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
385         addr.sin6_family = AF_INET6;
386 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
387         addr.sin6_addr = in6addr_any;
388 #else /* CONFIG_CTRL_IFACE_UDP_REMOTE */
389         inet_pton(AF_INET6, "::1", &addr.sin6_addr);
390 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
391 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
392         addr.sin_family = AF_INET;
393 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
394         addr.sin_addr.s_addr = INADDR_ANY;
395 #else /* CONFIG_CTRL_IFACE_UDP_REMOTE */
396         addr.sin_addr.s_addr = htonl((127 << 24) | 1);
397 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
398 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
399 try_again:
400 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
401         addr.sin6_port = htons(port);
402 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
403         addr.sin_port = htons(port);
404 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
405         if (bind(priv->sock, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
406                 port--;
407                 if ((WPA_CTRL_IFACE_PORT - port) < WPA_CTRL_IFACE_PORT_LIMIT &&
408                     !pos)
409                         goto try_again;
410                 wpa_printf(MSG_ERROR, "bind(AF_INET): %s", strerror(errno));
411                 goto fail;
412         }
413
414 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
415         wpa_msg(wpa_s, MSG_DEBUG, "ctrl_iface_init UDP port: %d", port);
416 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
417
418         eloop_register_read_sock(priv->sock, wpa_supplicant_ctrl_iface_receive,
419                                  wpa_s, priv);
420         wpa_msg_register_cb(wpa_supplicant_ctrl_iface_msg_cb);
421
422         return priv;
423
424 fail:
425         if (priv->sock >= 0)
426                 close(priv->sock);
427         os_free(priv);
428         return NULL;
429 }
430
431
432 void wpa_supplicant_ctrl_iface_deinit(struct ctrl_iface_priv *priv)
433 {
434         struct wpa_ctrl_dst *dst, *prev;
435
436         if (priv->sock > -1) {
437                 eloop_unregister_read_sock(priv->sock);
438                 if (priv->ctrl_dst) {
439                         /*
440                          * Wait before closing the control socket if
441                          * there are any attached monitors in order to allow
442                          * them to receive any pending messages.
443                          */
444                         wpa_printf(MSG_DEBUG, "CTRL_IFACE wait for attached "
445                                    "monitors to receive messages");
446                         os_sleep(0, 100000);
447                 }
448                 close(priv->sock);
449                 priv->sock = -1;
450         }
451
452         dst = priv->ctrl_dst;
453         while (dst) {
454                 prev = dst;
455                 dst = dst->next;
456                 os_free(prev);
457         }
458         os_free(priv);
459 }
460
461
462 static void wpa_supplicant_ctrl_iface_send(struct wpa_supplicant *wpa_s,
463                                            const char *ifname, int sock,
464                                            struct wpa_ctrl_dst **head,
465                                            int level, const char *buf,
466                                            size_t len)
467 {
468         struct wpa_ctrl_dst *dst, *next;
469         char levelstr[64];
470         int idx;
471         char *sbuf;
472         int llen;
473 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
474         char addr[INET6_ADDRSTRLEN];
475 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
476
477         dst = *head;
478         if (sock < 0 || dst == NULL)
479                 return;
480
481         if (ifname)
482                 os_snprintf(levelstr, sizeof(levelstr), "IFACE=%s <%d>",
483                             ifname, level);
484         else
485                 os_snprintf(levelstr, sizeof(levelstr), "<%d>", level);
486
487         llen = os_strlen(levelstr);
488         sbuf = os_malloc(llen + len);
489         if (sbuf == NULL)
490                 return;
491
492         os_memcpy(sbuf, levelstr, llen);
493         os_memcpy(sbuf + llen, buf, len);
494
495         idx = 0;
496         while (dst) {
497                 next = dst->next;
498                 if (level >= dst->debug_level) {
499 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
500                         wpa_printf(MSG_DEBUG, "CTRL_IFACE monitor send %s:%d",
501                                    inet_ntop(AF_INET6, &dst->addr.sin6_addr,
502                                              addr, sizeof(dst->addr)),
503                                    ntohs(dst->addr.sin6_port));
504 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
505                         wpa_printf(MSG_DEBUG, "CTRL_IFACE monitor send %s:%d",
506                                    inet_ntoa(dst->addr.sin_addr),
507                                    ntohs(dst->addr.sin_port));
508 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
509                         if (sendto(sock, sbuf, llen + len, 0,
510                                    (struct sockaddr *) &dst->addr,
511                                    sizeof(dst->addr)) < 0) {
512                                 wpa_printf(MSG_ERROR,
513                                            "sendto(CTRL_IFACE monitor): %s",
514                                            strerror(errno));
515                                 dst->errors++;
516                                 if (dst->errors > 10) {
517                                         wpa_supplicant_ctrl_iface_detach(
518                                                 head, &dst->addr,
519                                                 dst->addrlen);
520                                 }
521                         } else
522                                 dst->errors = 0;
523                 }
524                 idx++;
525                 dst = next;
526         }
527         os_free(sbuf);
528 }
529
530
531 void wpa_supplicant_ctrl_iface_wait(struct ctrl_iface_priv *priv)
532 {
533         wpa_printf(MSG_DEBUG, "CTRL_IFACE - %s - wait for monitor",
534                    priv->wpa_s->ifname);
535         eloop_wait_for_read_sock(priv->sock);
536 }
537
538
539 /* Global ctrl_iface */
540
541 struct ctrl_iface_global_priv {
542         int sock;
543         u8 cookie[COOKIE_LEN];
544 };
545
546
547 static char *
548 wpa_supplicant_global_get_cookie(struct ctrl_iface_global_priv *priv,
549                                  size_t *reply_len)
550 {
551         char *reply;
552         reply = os_malloc(7 + 2 * COOKIE_LEN + 1);
553         if (reply == NULL) {
554                 *reply_len = 1;
555                 return NULL;
556         }
557
558         os_memcpy(reply, "COOKIE=", 7);
559         wpa_snprintf_hex(reply + 7, 2 * COOKIE_LEN + 1,
560                          priv->cookie, COOKIE_LEN);
561
562         *reply_len = 7 + 2 * COOKIE_LEN;
563         return reply;
564 }
565
566
567 static void wpa_supplicant_global_ctrl_iface_receive(int sock, void *eloop_ctx,
568                                                      void *sock_ctx)
569 {
570         struct wpa_global *global = eloop_ctx;
571         struct ctrl_iface_global_priv *priv = sock_ctx;
572         char buf[256], *pos;
573         int res;
574         struct sockaddr_in from;
575         socklen_t fromlen = sizeof(from);
576         char *reply;
577         size_t reply_len;
578         u8 cookie[COOKIE_LEN];
579
580         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
581                        (struct sockaddr *) &from, &fromlen);
582         if (res < 0) {
583                 wpa_printf(MSG_ERROR, "recvfrom(ctrl_iface): %s",
584                            strerror(errno));
585                 return;
586         }
587
588 #ifndef CONFIG_CTRL_IFACE_UDP_REMOTE
589         if (from.sin_addr.s_addr != htonl((127 << 24) | 1)) {
590                 /*
591                  * The OS networking stack is expected to drop this kind of
592                  * frames since the socket is bound to only localhost address.
593                  * Just in case, drop the frame if it is coming from any other
594                  * address.
595                  */
596                 wpa_printf(MSG_DEBUG, "CTRL: Drop packet from unexpected "
597                            "source %s", inet_ntoa(from.sin_addr));
598                 return;
599         }
600 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
601
602         buf[res] = '\0';
603
604         if (os_strcmp(buf, "GET_COOKIE") == 0) {
605                 reply = wpa_supplicant_global_get_cookie(priv, &reply_len);
606                 goto done;
607         }
608
609         if (os_strncmp(buf, "COOKIE=", 7) != 0) {
610                 wpa_printf(MSG_DEBUG, "CTLR: No cookie in the request - "
611                            "drop request");
612                 return;
613         }
614
615         if (hexstr2bin(buf + 7, cookie, COOKIE_LEN) < 0) {
616                 wpa_printf(MSG_DEBUG, "CTLR: Invalid cookie format in the "
617                            "request - drop request");
618                 return;
619         }
620
621         if (os_memcmp(cookie, priv->cookie, COOKIE_LEN) != 0) {
622                 wpa_printf(MSG_DEBUG, "CTLR: Invalid cookie in the request - "
623                            "drop request");
624                 return;
625         }
626
627         pos = buf + 7 + 2 * COOKIE_LEN;
628         while (*pos == ' ')
629                 pos++;
630
631         reply = wpa_supplicant_global_ctrl_iface_process(global, pos,
632                                                          &reply_len);
633
634  done:
635         if (reply) {
636                 sendto(sock, reply, reply_len, 0, (struct sockaddr *) &from,
637                        fromlen);
638                 os_free(reply);
639         } else if (reply_len) {
640                 sendto(sock, "FAIL\n", 5, 0, (struct sockaddr *) &from,
641                        fromlen);
642         }
643 }
644
645
646 struct ctrl_iface_global_priv *
647 wpa_supplicant_global_ctrl_iface_init(struct wpa_global *global)
648 {
649         struct ctrl_iface_global_priv *priv;
650         struct sockaddr_in addr;
651         char *pos;
652         int port = WPA_GLOBAL_CTRL_IFACE_PORT;
653
654         priv = os_zalloc(sizeof(*priv));
655         if (priv == NULL)
656                 return NULL;
657         priv->sock = -1;
658         os_get_random(priv->cookie, COOKIE_LEN);
659
660         if (global->params.ctrl_interface == NULL)
661                 return priv;
662
663         wpa_printf(MSG_DEBUG, "Global control interface '%s'",
664                    global->params.ctrl_interface);
665
666         pos = os_strstr(global->params.ctrl_interface, "udp:");
667         if (pos) {
668                 pos += 4;
669                 port = atoi(pos);
670                 if (port <= 0) {
671                         wpa_printf(MSG_ERROR, "Invalid global ctrl UDP port %s",
672                                    global->params.ctrl_interface);
673                         goto fail;
674                 }
675         }
676
677         priv->sock = socket(PF_INET, SOCK_DGRAM, 0);
678         if (priv->sock < 0) {
679                 wpa_printf(MSG_ERROR, "socket(PF_INET): %s", strerror(errno));
680                 goto fail;
681         }
682
683         os_memset(&addr, 0, sizeof(addr));
684         addr.sin_family = AF_INET;
685 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
686         addr.sin_addr.s_addr = INADDR_ANY;
687 #else /* CONFIG_CTRL_IFACE_UDP_REMOTE */
688         addr.sin_addr.s_addr = htonl((127 << 24) | 1);
689 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
690 try_again:
691         addr.sin_port = htons(port);
692         if (bind(priv->sock, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
693                 port++;
694                 if ((port - WPA_GLOBAL_CTRL_IFACE_PORT) <
695                     WPA_GLOBAL_CTRL_IFACE_PORT_LIMIT && !pos)
696                         goto try_again;
697                 wpa_printf(MSG_ERROR, "bind(AF_INET): %s", strerror(errno));
698                 goto fail;
699         }
700
701 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
702         wpa_printf(MSG_DEBUG, "global_ctrl_iface_init UDP port: %d", port);
703 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
704
705         eloop_register_read_sock(priv->sock,
706                                  wpa_supplicant_global_ctrl_iface_receive,
707                                  global, priv);
708
709         return priv;
710
711 fail:
712         if (priv->sock >= 0)
713                 close(priv->sock);
714         os_free(priv);
715         return NULL;
716 }
717
718
719 void
720 wpa_supplicant_global_ctrl_iface_deinit(struct ctrl_iface_global_priv *priv)
721 {
722         if (priv->sock >= 0) {
723                 eloop_unregister_read_sock(priv->sock);
724                 close(priv->sock);
725         }
726         os_free(priv);
727 }