2 /* @(#) $Header: /tcpdump/master/tcpdump/ieee802_11.h,v 1.12 2007-07-22 19:59:06 guy Exp $ (LBL) */
5 * Fortress Technologies
6 * Charlie Lenahan ( clenahan@fortresstech.com )
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that: (1) source code distributions
10 * retain the above copyright notice and this paragraph in its entirety, (2)
11 * distributions including binary code include the above copyright notice and
12 * this paragraph in its entirety in the documentation or other materials
13 * provided with the distribution, and (3) all advertising materials mentioning
14 * features or use of this software display the following acknowledgement:
15 * ``This product includes software developed by the University of California,
16 * Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
17 * the University nor the names of its contributors may be used to endorse
18 * or promote products derived from this software without specific prior
20 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
21 * WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
22 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
25 /* Lengths of 802.11 header components. */
26 #define IEEE802_11_FC_LEN 2
27 #define IEEE802_11_DUR_LEN 2
28 #define IEEE802_11_DA_LEN 6
29 #define IEEE802_11_SA_LEN 6
30 #define IEEE802_11_BSSID_LEN 6
31 #define IEEE802_11_RA_LEN 6
32 #define IEEE802_11_TA_LEN 6
33 #define IEEE802_11_SEQ_LEN 2
34 #define IEEE802_11_CTL_LEN 2
35 #define IEEE802_11_IV_LEN 3
36 #define IEEE802_11_KID_LEN 1
38 /* Frame check sequence length. */
39 #define IEEE802_11_FCS_LEN 4
41 /* Lengths of beacon components. */
42 #define IEEE802_11_TSTAMP_LEN 8
43 #define IEEE802_11_BCNINT_LEN 2
44 #define IEEE802_11_CAPINFO_LEN 2
45 #define IEEE802_11_LISTENINT_LEN 2
47 #define IEEE802_11_AID_LEN 2
48 #define IEEE802_11_STATUS_LEN 2
49 #define IEEE802_11_REASON_LEN 2
51 /* Length of previous AP in reassocation frame */
52 #define IEEE802_11_AP_LEN 6
54 #define T_MGMT 0x0 /* management */
55 #define T_CTRL 0x1 /* control */
56 #define T_DATA 0x2 /* data */
57 #define T_RESV 0x3 /* reserved */
59 #define ST_ASSOC_REQUEST 0x0
60 #define ST_ASSOC_RESPONSE 0x1
61 #define ST_REASSOC_REQUEST 0x2
62 #define ST_REASSOC_RESPONSE 0x3
63 #define ST_PROBE_REQUEST 0x4
64 #define ST_PROBE_RESPONSE 0x5
69 #define ST_DISASSOC 0xA
79 #define CTRL_PS_POLL 0xA
83 #define CTRL_CF_END 0xE
84 #define CTRL_END_ACK 0xF
87 #define DATA_DATA_CF_ACK 0x1
88 #define DATA_DATA_CF_POLL 0x2
89 #define DATA_DATA_CF_ACK_POLL 0x3
90 #define DATA_NODATA 0x4
91 #define DATA_NODATA_CF_ACK 0x5
92 #define DATA_NODATA_CF_POLL 0x6
93 #define DATA_NODATA_CF_ACK_POLL 0x7
95 #define DATA_QOS_DATA 0x8
96 #define DATA_QOS_DATA_CF_ACK 0x9
97 #define DATA_QOS_DATA_CF_POLL 0xA
98 #define DATA_QOS_DATA_CF_ACK_POLL 0xB
99 #define DATA_QOS_NODATA 0xC
100 #define DATA_QOS_CF_POLL_NODATA 0xE
101 #define DATA_QOS_CF_ACK_POLL_NODATA 0xF
104 * The subtype field of a data frame is, in effect, composed of 4 flag
105 * bits - CF-Ack, CF-Poll, Null (means the frame doesn't actually have
106 * any data), and QoS.
108 #define DATA_FRAME_IS_CF_ACK(x) ((x) & 0x01)
109 #define DATA_FRAME_IS_CF_POLL(x) ((x) & 0x02)
110 #define DATA_FRAME_IS_NULL(x) ((x) & 0x04)
111 #define DATA_FRAME_IS_QOS(x) ((x) & 0x08)
114 * Bits in the frame control field.
116 #define FC_VERSION(fc) ((fc) & 0x3)
117 #define FC_TYPE(fc) (((fc) >> 2) & 0x3)
118 #define FC_SUBTYPE(fc) (((fc) >> 4) & 0xF)
119 #define FC_TO_DS(fc) ((fc) & 0x0100)
120 #define FC_FROM_DS(fc) ((fc) & 0x0200)
121 #define FC_MORE_FLAG(fc) ((fc) & 0x0400)
122 #define FC_RETRY(fc) ((fc) & 0x0800)
123 #define FC_POWER_MGMT(fc) ((fc) & 0x1000)
124 #define FC_MORE_DATA(fc) ((fc) & 0x2000)
125 #define FC_WEP(fc) ((fc) & 0x4000)
126 #define FC_ORDER(fc) ((fc) & 0x8000)
128 struct mgmt_header_t {
137 #define MGMT_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+\
138 IEEE802_11_DA_LEN+IEEE802_11_SA_LEN+\
139 IEEE802_11_BSSID_LEN+IEEE802_11_SEQ_LEN)
141 #define CAPABILITY_ESS(cap) ((cap) & 0x0001)
142 #define CAPABILITY_IBSS(cap) ((cap) & 0x0002)
143 #define CAPABILITY_CFP(cap) ((cap) & 0x0004)
144 #define CAPABILITY_CFP_REQ(cap) ((cap) & 0x0008)
145 #define CAPABILITY_PRIVACY(cap) ((cap) & 0x0010)
156 u_char ssid[33]; /* 32 + 1 for null */
168 u_int8_t text[254]; /* 1-253 + 1 for null */
174 u_int16_t dwell_time;
176 u_int8_t hop_pattern;
191 u_int16_t max_duration;
192 u_int16_t dur_remaing;
200 u_int8_t bitmap_control;
201 u_int8_t bitmap[251];
222 #define E_CHALLENGE 16
231 u_int8_t timestamp[IEEE802_11_TSTAMP_LEN];
232 u_int16_t beacon_interval;
233 u_int16_t listen_interval;
234 u_int16_t status_code;
236 u_char ap[IEEE802_11_AP_LEN];
237 u_int16_t reason_code;
239 u_int16_t auth_trans_seq_num;
240 elem_status_t challenge_status;
241 struct challenge_t challenge;
242 u_int16_t capability_info;
243 elem_status_t ssid_status;
245 elem_status_t rates_status;
246 struct rates_t rates;
247 elem_status_t ds_status;
249 elem_status_t cf_status;
251 elem_status_t fh_status;
253 elem_status_t tim_status;
265 #define CTRL_RTS_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+\
266 IEEE802_11_RA_LEN+IEEE802_11_TA_LEN)
275 #define CTRL_CTS_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+IEEE802_11_RA_LEN)
284 #define CTRL_ACK_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+IEEE802_11_RA_LEN)
286 struct ctrl_ps_poll_t {
294 #define CTRL_PS_POLL_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_AID_LEN+\
295 IEEE802_11_BSSID_LEN+IEEE802_11_TA_LEN)
305 #define CTRL_END_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+\
306 IEEE802_11_RA_LEN+IEEE802_11_BSSID_LEN)
308 struct ctrl_end_ack_t {
316 #define CTRL_END_ACK_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+\
317 IEEE802_11_RA_LEN+IEEE802_11_BSSID_LEN)
326 #define CTRL_BA_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+IEEE802_11_RA_LEN)
338 #define CTRL_BAR_HDRLEN (IEEE802_11_FC_LEN+IEEE802_11_DUR_LEN+\
339 IEEE802_11_RA_LEN+IEEE802_11_TA_LEN+\
340 IEEE802_11_CTL_LEN+IEEE802_11_SEQ_LEN)
351 #define IV_IV(iv) ((iv) & 0xFFFFFF)
352 #define IV_PAD(iv) (((iv) >> 24) & 0x3F)
353 #define IV_KEYID(iv) (((iv) >> 30) & 0x03)