mesh: Clear wpa_s cipher selection on starting mesh
[mech_eap.git] / wpa_supplicant / mesh.c
1 /*
2  * WPA Supplicant - Basic mesh mode routines
3  * Copyright (c) 2013-2014, cozybit, Inc.  All rights reserved.
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8
9 #include "utils/includes.h"
10
11 #include "utils/common.h"
12 #include "utils/eloop.h"
13 #include "utils/uuid.h"
14 #include "common/ieee802_11_defs.h"
15 #include "common/wpa_ctrl.h"
16 #include "ap/sta_info.h"
17 #include "ap/hostapd.h"
18 #include "ap/ieee802_11.h"
19 #include "config_ssid.h"
20 #include "config.h"
21 #include "wpa_supplicant_i.h"
22 #include "driver_i.h"
23 #include "notify.h"
24 #include "ap.h"
25 #include "mesh_mpm.h"
26 #include "mesh_rsn.h"
27 #include "mesh.h"
28
29
30 static void wpa_supplicant_mesh_deinit(struct wpa_supplicant *wpa_s)
31 {
32         wpa_supplicant_mesh_iface_deinit(wpa_s, wpa_s->ifmsh);
33         wpa_s->ifmsh = NULL;
34         wpa_s->current_ssid = NULL;
35         os_free(wpa_s->mesh_rsn);
36         wpa_s->mesh_rsn = NULL;
37         /* TODO: leave mesh (stop beacon). This will happen on link down
38          * anyway, so it's not urgent */
39 }
40
41
42 void wpa_supplicant_mesh_iface_deinit(struct wpa_supplicant *wpa_s,
43                                       struct hostapd_iface *ifmsh)
44 {
45         if (!ifmsh)
46                 return;
47
48         if (ifmsh->mconf) {
49                 mesh_mpm_deinit(wpa_s, ifmsh);
50                 if (ifmsh->mconf->rsn_ie) {
51                         ifmsh->mconf->rsn_ie = NULL;
52                         /* We cannot free this struct
53                          * because wpa_authenticator on
54                          * hostapd side is also using it
55                          * for now just set to NULL and
56                          * let hostapd code free it.
57                          */
58                 }
59                 os_free(ifmsh->mconf);
60                 ifmsh->mconf = NULL;
61         }
62
63         /* take care of shared data */
64         hostapd_interface_deinit(ifmsh);
65         hostapd_interface_free(ifmsh);
66 }
67
68
69 static struct mesh_conf * mesh_config_create(struct wpa_ssid *ssid)
70 {
71         struct mesh_conf *conf;
72
73         conf = os_zalloc(sizeof(struct mesh_conf));
74         if (!conf)
75                 return NULL;
76
77         os_memcpy(conf->meshid, ssid->ssid, ssid->ssid_len);
78         conf->meshid_len = ssid->ssid_len;
79
80         if (ssid->key_mgmt & WPA_KEY_MGMT_SAE)
81                 conf->security |= MESH_CONF_SEC_AUTH |
82                         MESH_CONF_SEC_AMPE;
83         else
84                 conf->security |= MESH_CONF_SEC_NONE;
85
86         /* defaults */
87         conf->mesh_pp_id = MESH_PATH_PROTOCOL_HWMP;
88         conf->mesh_pm_id = MESH_PATH_METRIC_AIRTIME;
89         conf->mesh_cc_id = 0;
90         conf->mesh_sp_id = MESH_SYNC_METHOD_NEIGHBOR_OFFSET;
91         conf->mesh_auth_id = (conf->security & MESH_CONF_SEC_AUTH) ? 1 : 0;
92         conf->dot11MeshMaxRetries = ssid->dot11MeshMaxRetries;
93         conf->dot11MeshRetryTimeout = ssid->dot11MeshRetryTimeout;
94         conf->dot11MeshConfirmTimeout = ssid->dot11MeshConfirmTimeout;
95         conf->dot11MeshHoldingTimeout = ssid->dot11MeshHoldingTimeout;
96
97         return conf;
98 }
99
100
101 static void wpas_mesh_copy_groups(struct hostapd_data *bss,
102                                   struct wpa_supplicant *wpa_s)
103 {
104         int num_groups;
105         size_t groups_size;
106
107         for (num_groups = 0; wpa_s->conf->sae_groups[num_groups] > 0;
108              num_groups++)
109                 ;
110
111         groups_size = (num_groups + 1) * sizeof(wpa_s->conf->sae_groups[0]);
112         bss->conf->sae_groups = os_malloc(groups_size);
113         if (bss->conf->sae_groups)
114                 os_memcpy(bss->conf->sae_groups, wpa_s->conf->sae_groups,
115                           groups_size);
116 }
117
118
119 static int wpa_supplicant_mesh_init(struct wpa_supplicant *wpa_s,
120                                     struct wpa_ssid *ssid)
121 {
122         struct hostapd_iface *ifmsh;
123         struct hostapd_data *bss;
124         struct hostapd_config *conf;
125         struct mesh_conf *mconf;
126         int basic_rates_erp[] = { 10, 20, 55, 60, 110, 120, 240, -1 };
127         static int default_groups[] = { 19, 20, 21, 25, 26, -1 };
128         size_t len;
129         int rate_len;
130
131         if (!wpa_s->conf->user_mpm) {
132                 /* not much for us to do here */
133                 wpa_msg(wpa_s, MSG_WARNING,
134                         "user_mpm is not enabled in configuration");
135                 return 0;
136         }
137
138         wpa_s->ifmsh = ifmsh = os_zalloc(sizeof(*wpa_s->ifmsh));
139         if (!ifmsh)
140                 return -ENOMEM;
141
142         ifmsh->drv_flags = wpa_s->drv_flags;
143         ifmsh->num_bss = 1;
144         ifmsh->bss = os_calloc(wpa_s->ifmsh->num_bss,
145                                sizeof(struct hostapd_data *));
146         if (!ifmsh->bss)
147                 goto out_free;
148
149         ifmsh->bss[0] = bss = os_zalloc(sizeof(struct hostapd_data));
150         if (!bss)
151                 goto out_free;
152
153         os_memcpy(bss->own_addr, wpa_s->own_addr, ETH_ALEN);
154         bss->driver = wpa_s->driver;
155         bss->drv_priv = wpa_s->drv_priv;
156         bss->iface = ifmsh;
157         bss->mesh_sta_free_cb = mesh_mpm_free_sta;
158         wpa_s->assoc_freq = ssid->frequency;
159         wpa_s->current_ssid = ssid;
160
161         /* setup an AP config for auth processing */
162         conf = hostapd_config_defaults();
163         if (!conf)
164                 goto out_free;
165
166         bss->conf = *conf->bss;
167         bss->conf->start_disabled = 1;
168         bss->conf->mesh = MESH_ENABLED;
169         bss->conf->ap_max_inactivity = wpa_s->conf->mesh_max_inactivity;
170         bss->iconf = conf;
171         ifmsh->conf = conf;
172
173         ifmsh->bss[0]->max_plinks = wpa_s->conf->max_peer_links;
174         ifmsh->bss[0]->dot11RSNASAERetransPeriod =
175                 wpa_s->conf->dot11RSNASAERetransPeriod;
176         os_strlcpy(bss->conf->iface, wpa_s->ifname, sizeof(bss->conf->iface));
177
178         mconf = mesh_config_create(ssid);
179         if (!mconf)
180                 goto out_free;
181         ifmsh->mconf = mconf;
182
183         /* need conf->hw_mode for supported rates. */
184         if (ssid->frequency == 0) {
185                 conf->hw_mode = HOSTAPD_MODE_IEEE80211G;
186                 conf->channel = 1;
187         } else {
188                 conf->hw_mode = ieee80211_freq_to_chan(ssid->frequency,
189                                                        &conf->channel);
190         }
191         if (conf->hw_mode == NUM_HOSTAPD_MODES) {
192                 wpa_printf(MSG_ERROR, "Unsupported mesh mode frequency: %d MHz",
193                            ssid->frequency);
194                 goto out_free;
195         }
196
197         if (ssid->mesh_basic_rates == NULL) {
198                 /*
199                  * XXX: Hack! This is so an MPM which correctly sets the ERP
200                  * mandatory rates as BSSBasicRateSet doesn't reject us. We
201                  * could add a new hw_mode HOSTAPD_MODE_IEEE80211G_ERP, but
202                  * this is way easier. This also makes our BSSBasicRateSet
203                  * advertised in beacons match the one in peering frames, sigh.
204                  */
205                 if (conf->hw_mode == HOSTAPD_MODE_IEEE80211G) {
206                         conf->basic_rates = os_malloc(sizeof(basic_rates_erp));
207                         if (!conf->basic_rates)
208                                 goto out_free;
209                         os_memcpy(conf->basic_rates, basic_rates_erp,
210                                   sizeof(basic_rates_erp));
211                 }
212         } else {
213                 rate_len = 0;
214                 while (1) {
215                         if (ssid->mesh_basic_rates[rate_len] < 1)
216                                 break;
217                         rate_len++;
218                 }
219                 conf->basic_rates = os_calloc(rate_len + 1, sizeof(int));
220                 if (conf->basic_rates == NULL)
221                         goto out_free;
222                 os_memcpy(conf->basic_rates, ssid->mesh_basic_rates,
223                           rate_len * sizeof(int));
224                 conf->basic_rates[rate_len] = -1;
225         }
226
227         if (hostapd_setup_interface(ifmsh)) {
228                 wpa_printf(MSG_ERROR,
229                            "Failed to initialize hostapd interface for mesh");
230                 return -1;
231         }
232
233         if (wpa_drv_init_mesh(wpa_s)) {
234                 wpa_msg(wpa_s, MSG_ERROR, "Failed to init mesh in driver");
235                 return -1;
236         }
237
238         if (mconf->security != MESH_CONF_SEC_NONE) {
239                 if (ssid->passphrase == NULL) {
240                         wpa_printf(MSG_ERROR,
241                                    "mesh: Passphrase for SAE not configured");
242                         goto out_free;
243                 }
244
245                 bss->conf->wpa = ssid->proto;
246                 bss->conf->wpa_key_mgmt = ssid->key_mgmt;
247
248                 if (wpa_s->conf->sae_groups &&
249                     wpa_s->conf->sae_groups[0] > 0) {
250                         wpas_mesh_copy_groups(bss, wpa_s);
251                 } else {
252                         bss->conf->sae_groups =
253                                 os_malloc(sizeof(default_groups));
254                         if (!bss->conf->sae_groups)
255                                 goto out_free;
256                         os_memcpy(bss->conf->sae_groups, default_groups,
257                                   sizeof(default_groups));
258                 }
259
260                 len = os_strlen(ssid->passphrase);
261                 bss->conf->ssid.wpa_passphrase =
262                         dup_binstr(ssid->passphrase, len);
263
264                 wpa_s->mesh_rsn = mesh_rsn_auth_init(wpa_s, mconf);
265                 if (!wpa_s->mesh_rsn)
266                         goto out_free;
267         }
268
269         wpa_supplicant_conf_ap_ht(wpa_s, ssid, conf);
270
271         return 0;
272 out_free:
273         wpa_supplicant_mesh_deinit(wpa_s);
274         return -ENOMEM;
275 }
276
277
278 void wpa_mesh_notify_peer(struct wpa_supplicant *wpa_s, const u8 *addr,
279                           const u8 *ies, size_t ie_len)
280 {
281         struct ieee802_11_elems elems;
282
283         wpa_msg(wpa_s, MSG_INFO,
284                 "new peer notification for " MACSTR, MAC2STR(addr));
285
286         if (ieee802_11_parse_elems(ies, ie_len, &elems, 0) == ParseFailed) {
287                 wpa_msg(wpa_s, MSG_INFO, "Could not parse beacon from " MACSTR,
288                         MAC2STR(addr));
289                 return;
290         }
291         wpa_mesh_new_mesh_peer(wpa_s, addr, &elems);
292 }
293
294
295 void wpa_supplicant_mesh_add_scan_ie(struct wpa_supplicant *wpa_s,
296                                      struct wpabuf **extra_ie)
297 {
298         /* EID + 0-length (wildcard) mesh-id */
299         size_t ielen = 2;
300
301         if (wpabuf_resize(extra_ie, ielen) == 0) {
302                 wpabuf_put_u8(*extra_ie, WLAN_EID_MESH_ID);
303                 wpabuf_put_u8(*extra_ie, 0);
304         }
305 }
306
307
308 int wpa_supplicant_join_mesh(struct wpa_supplicant *wpa_s,
309                              struct wpa_ssid *ssid)
310 {
311         struct wpa_driver_mesh_join_params params;
312         int ret = 0;
313
314         if (!ssid || !ssid->ssid || !ssid->ssid_len || !ssid->frequency) {
315                 ret = -ENOENT;
316                 goto out;
317         }
318
319         wpa_supplicant_mesh_deinit(wpa_s);
320
321         if (ssid->key_mgmt & WPA_KEY_MGMT_SAE) {
322                 wpa_s->pairwise_cipher = WPA_CIPHER_CCMP;
323                 wpa_s->group_cipher = WPA_CIPHER_CCMP;
324                 wpa_s->mgmt_group_cipher = 0;
325         } else {
326                 wpa_s->pairwise_cipher = WPA_CIPHER_NONE;
327                 wpa_s->group_cipher = WPA_CIPHER_NONE;
328                 wpa_s->mgmt_group_cipher = 0;
329         }
330
331         os_memset(&params, 0, sizeof(params));
332         params.meshid = ssid->ssid;
333         params.meshid_len = ssid->ssid_len;
334         ibss_mesh_setup_freq(wpa_s, ssid, &params.freq);
335         wpa_s->mesh_ht_enabled = !!params.freq.ht_enabled;
336         wpa_s->mesh_vht_enabled = !!params.freq.vht_enabled;
337         if (ssid->beacon_int > 0)
338                 params.beacon_int = ssid->beacon_int;
339         else if (wpa_s->conf->beacon_int > 0)
340                 params.beacon_int = wpa_s->conf->beacon_int;
341         params.max_peer_links = wpa_s->conf->max_peer_links;
342
343         if (ssid->key_mgmt & WPA_KEY_MGMT_SAE) {
344                 params.flags |= WPA_DRIVER_MESH_FLAG_SAE_AUTH;
345                 params.flags |= WPA_DRIVER_MESH_FLAG_AMPE;
346                 wpa_s->conf->user_mpm = 1;
347         }
348
349         if (wpa_s->conf->user_mpm) {
350                 params.flags |= WPA_DRIVER_MESH_FLAG_USER_MPM;
351                 params.conf.flags &= ~WPA_DRIVER_MESH_CONF_FLAG_AUTO_PLINKS;
352         } else {
353                 params.flags |= WPA_DRIVER_MESH_FLAG_DRIVER_MPM;
354                 params.conf.flags |= WPA_DRIVER_MESH_CONF_FLAG_AUTO_PLINKS;
355         }
356         params.conf.peer_link_timeout = wpa_s->conf->mesh_max_inactivity;
357
358         if (wpa_supplicant_mesh_init(wpa_s, ssid)) {
359                 wpa_msg(wpa_s, MSG_ERROR, "Failed to init mesh");
360                 wpa_drv_leave_mesh(wpa_s);
361                 ret = -1;
362                 goto out;
363         }
364
365         if (wpa_s->ifmsh) {
366                 params.ies = wpa_s->ifmsh->mconf->rsn_ie;
367                 params.ie_len = wpa_s->ifmsh->mconf->rsn_ie_len;
368                 params.basic_rates = wpa_s->ifmsh->basic_rates;
369         }
370
371         wpa_msg(wpa_s, MSG_INFO, "joining mesh %s",
372                 wpa_ssid_txt(ssid->ssid, ssid->ssid_len));
373         ret = wpa_drv_join_mesh(wpa_s, &params);
374         if (ret)
375                 wpa_msg(wpa_s, MSG_ERROR, "mesh join error=%d\n", ret);
376
377         /* hostapd sets the interface down until we associate */
378         wpa_drv_set_operstate(wpa_s, 1);
379
380 out:
381         return ret;
382 }
383
384
385 int wpa_supplicant_leave_mesh(struct wpa_supplicant *wpa_s)
386 {
387         int ret = 0;
388
389         wpa_msg(wpa_s, MSG_INFO, "leaving mesh");
390
391         /* Need to send peering close messages first */
392         wpa_supplicant_mesh_deinit(wpa_s);
393
394         ret = wpa_drv_leave_mesh(wpa_s);
395         if (ret)
396                 wpa_msg(wpa_s, MSG_ERROR, "mesh leave error=%d", ret);
397
398         wpa_drv_set_operstate(wpa_s, 1);
399
400         return ret;
401 }
402
403
404 static int mesh_attr_text(const u8 *ies, size_t ies_len, char *buf, char *end)
405 {
406         struct ieee802_11_elems elems;
407         char *mesh_id, *pos = buf;
408         u8 *bss_basic_rate_set;
409         int bss_basic_rate_set_len, ret, i;
410
411         if (ieee802_11_parse_elems(ies, ies_len, &elems, 0) == ParseFailed)
412                 return -1;
413
414         if (elems.mesh_id_len < 1)
415                 return 0;
416
417         mesh_id = os_malloc(elems.mesh_id_len + 1);
418         if (mesh_id == NULL)
419                 return -1;
420
421         os_memcpy(mesh_id, elems.mesh_id, elems.mesh_id_len);
422         mesh_id[elems.mesh_id_len] = '\0';
423         ret = os_snprintf(pos, end - pos, "mesh_id=%s\n", mesh_id);
424         os_free(mesh_id);
425         if (os_snprintf_error(end - pos, ret))
426                 return pos - buf;
427         pos += ret;
428
429         if (elems.mesh_config_len > 6) {
430                 ret = os_snprintf(pos, end - pos,
431                                   "active_path_selection_protocol_id=0x%02x\n"
432                                   "active_path_selection_metric_id=0x%02x\n"
433                                   "congestion_control_mode_id=0x%02x\n"
434                                   "synchronization_method_id=0x%02x\n"
435                                   "authentication_protocol_id=0x%02x\n"
436                                   "mesh_formation_info=0x%02x\n"
437                                   "mesh_capability=0x%02x\n",
438                                   elems.mesh_config[0], elems.mesh_config[1],
439                                   elems.mesh_config[2], elems.mesh_config[3],
440                                   elems.mesh_config[4], elems.mesh_config[5],
441                                   elems.mesh_config[6]);
442                 if (os_snprintf_error(end - pos, ret))
443                         return pos - buf;
444                 pos += ret;
445         }
446
447         bss_basic_rate_set = os_malloc(elems.supp_rates_len +
448                 elems.ext_supp_rates_len);
449         if (bss_basic_rate_set == NULL)
450                 return -1;
451
452         bss_basic_rate_set_len = 0;
453         for (i = 0; i < elems.supp_rates_len; i++) {
454                 if (elems.supp_rates[i] & 0x80) {
455                         bss_basic_rate_set[bss_basic_rate_set_len++] =
456                                 (elems.supp_rates[i] & 0x7f) * 5;
457                 }
458         }
459         for (i = 0; i < elems.ext_supp_rates_len; i++) {
460                 if (elems.ext_supp_rates[i] & 0x80) {
461                         bss_basic_rate_set[bss_basic_rate_set_len++] =
462                                 (elems.ext_supp_rates[i] & 0x7f) * 5;
463                 }
464         }
465         if (bss_basic_rate_set_len > 0) {
466                 ret = os_snprintf(pos, end - pos, "bss_basic_rate_set=%d",
467                                   bss_basic_rate_set[0]);
468                 if (os_snprintf_error(end - pos, ret))
469                         goto fail;
470                 pos += ret;
471
472                 for (i = 1; i < bss_basic_rate_set_len; i++) {
473                         ret = os_snprintf(pos, end - pos, " %d",
474                                           bss_basic_rate_set[i]);
475                         if (os_snprintf_error(end - pos, ret))
476                                 goto fail;
477                         pos += ret;
478                 }
479
480                 ret = os_snprintf(pos, end - pos, "\n");
481                 if (os_snprintf_error(end - pos, ret))
482                         goto fail;
483                 pos += ret;
484         }
485 fail:
486         os_free(bss_basic_rate_set);
487
488         return pos - buf;
489 }
490
491
492 int wpas_mesh_scan_result_text(const u8 *ies, size_t ies_len, char *buf,
493                                char *end)
494 {
495         return mesh_attr_text(ies, ies_len, buf, end);
496 }
497
498
499 static int wpas_mesh_get_ifname(struct wpa_supplicant *wpa_s, char *ifname,
500                                 size_t len)
501 {
502         char *ifname_ptr = wpa_s->ifname;
503         int res;
504
505         res = os_snprintf(ifname, len, "mesh-%s-%d", ifname_ptr,
506                           wpa_s->mesh_if_idx);
507         if (os_snprintf_error(len, res) ||
508             (os_strlen(ifname) >= IFNAMSIZ &&
509              os_strlen(wpa_s->ifname) < IFNAMSIZ)) {
510                 /* Try to avoid going over the IFNAMSIZ length limit */
511                 res = os_snprintf(ifname, len, "mesh-%d", wpa_s->mesh_if_idx);
512                 if (os_snprintf_error(len, res))
513                         return -1;
514         }
515         wpa_s->mesh_if_idx++;
516         return 0;
517 }
518
519
520 int wpas_mesh_add_interface(struct wpa_supplicant *wpa_s, char *ifname,
521                             size_t len)
522 {
523         struct wpa_interface iface;
524         struct wpa_supplicant *mesh_wpa_s;
525         u8 addr[ETH_ALEN];
526
527         if (ifname[0] == '\0' && wpas_mesh_get_ifname(wpa_s, ifname, len) < 0)
528                 return -1;
529
530         if (wpa_drv_if_add(wpa_s, WPA_IF_MESH, ifname, NULL, NULL, NULL, addr,
531                            NULL) < 0) {
532                 wpa_printf(MSG_ERROR,
533                            "mesh: Failed to create new mesh interface");
534                 return -1;
535         }
536         wpa_printf(MSG_INFO, "mesh: Created virtual interface %s addr "
537                    MACSTR, ifname, MAC2STR(addr));
538
539         os_memset(&iface, 0, sizeof(iface));
540         iface.ifname = ifname;
541         iface.driver = wpa_s->driver->name;
542         iface.driver_param = wpa_s->conf->driver_param;
543         iface.ctrl_interface = wpa_s->conf->ctrl_interface;
544
545         mesh_wpa_s = wpa_supplicant_add_iface(wpa_s->global, &iface, wpa_s);
546         if (!mesh_wpa_s) {
547                 wpa_printf(MSG_ERROR,
548                            "mesh: Failed to create new wpa_supplicant interface");
549                 wpa_supplicant_remove_iface(wpa_s->global, wpa_s, 0);
550                 return -1;
551         }
552         mesh_wpa_s->mesh_if_created = 1;
553         return 0;
554 }