2 * WPA Supplicant - privilege separated driver interface
3 * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
5 * This software may be distributed under the terms of the BSD license.
6 * See README for more details.
15 #include "common/privsep_commands.h"
18 struct wpa_driver_privsep_data {
20 u8 own_addr[ETH_ALEN];
22 char *own_socket_path;
25 struct sockaddr_un priv_addr;
30 static int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
34 res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
35 (struct sockaddr *) &drv->priv_addr,
36 sizeof(drv->priv_addr));
39 return res < 0 ? -1 : 0;
43 static int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
44 const void *data, size_t data_len,
45 void *reply, size_t *reply_len)
50 io[0].iov_base = &cmd;
51 io[0].iov_len = sizeof(cmd);
52 io[1].iov_base = (u8 *) data;
53 io[1].iov_len = data_len;
55 os_memset(&msg, 0, sizeof(msg));
57 msg.msg_iovlen = data ? 2 : 1;
58 msg.msg_name = &drv->priv_addr;
59 msg.msg_namelen = sizeof(drv->priv_addr);
61 if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
62 perror("sendmsg(cmd_socket)");
72 FD_SET(drv->cmd_socket, &rfds);
75 res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
76 if (res < 0 && errno != EINTR) {
81 if (FD_ISSET(drv->cmd_socket, &rfds)) {
82 res = recv(drv->cmd_socket, reply, *reply_len, 0);
89 wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
90 "for reply (cmd=%d)", cmd);
99 static int wpa_driver_privsep_scan(void *priv,
100 struct wpa_driver_scan_params *params)
102 struct wpa_driver_privsep_data *drv = priv;
103 const u8 *ssid = params->ssids[0].ssid;
104 size_t ssid_len = params->ssids[0].ssid_len;
105 wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
106 return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, ssid, ssid_len,
111 static struct wpa_scan_results *
112 wpa_driver_privsep_get_scan_results2(void *priv)
114 struct wpa_driver_privsep_data *drv = priv;
117 size_t reply_len = 60000;
118 struct wpa_scan_results *results;
119 struct wpa_scan_res *r;
121 buf = os_malloc(reply_len);
124 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
125 NULL, 0, buf, &reply_len);
131 wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
132 (unsigned long) reply_len);
133 if (reply_len < sizeof(int)) {
134 wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
135 (unsigned long) reply_len);
141 end = buf + reply_len;
142 os_memcpy(&num, pos, sizeof(int));
143 if (num < 0 || num > 1000) {
149 results = os_zalloc(sizeof(*results));
150 if (results == NULL) {
155 results->res = os_calloc(num, sizeof(struct wpa_scan_res *));
156 if (results->res == NULL) {
162 while (results->num < (size_t) num && pos + sizeof(int) < end) {
164 os_memcpy(&len, pos, sizeof(int));
166 if (len < 0 || len > 10000 || pos + len > end)
172 os_memcpy(r, pos, len);
174 if (sizeof(*r) + r->ie_len > (size_t) len) {
179 results->res[results->num++] = r;
187 static int wpa_driver_privsep_set_key(const char *ifname, void *priv,
188 enum wpa_alg alg, const u8 *addr,
189 int key_idx, int set_tx,
190 const u8 *seq, size_t seq_len,
191 const u8 *key, size_t key_len)
193 struct wpa_driver_privsep_data *drv = priv;
194 struct privsep_cmd_set_key cmd;
196 wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
197 __func__, priv, alg, key_idx, set_tx);
199 os_memset(&cmd, 0, sizeof(cmd));
202 os_memcpy(cmd.addr, addr, ETH_ALEN);
204 os_memset(cmd.addr, 0xff, ETH_ALEN);
205 cmd.key_idx = key_idx;
207 if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
208 os_memcpy(cmd.seq, seq, seq_len);
209 cmd.seq_len = seq_len;
211 if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
212 os_memcpy(cmd.key, key, key_len);
213 cmd.key_len = key_len;
216 return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
221 static int wpa_driver_privsep_associate(
222 void *priv, struct wpa_driver_associate_params *params)
224 struct wpa_driver_privsep_data *drv = priv;
225 struct privsep_cmd_associate *data;
229 wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
230 "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
231 __func__, priv, params->freq, params->pairwise_suite,
232 params->group_suite, params->key_mgmt_suite,
233 params->auth_alg, params->mode);
235 buflen = sizeof(*data) + params->wpa_ie_len;
236 data = os_zalloc(buflen);
241 os_memcpy(data->bssid, params->bssid, ETH_ALEN);
242 os_memcpy(data->ssid, params->ssid, params->ssid_len);
243 data->ssid_len = params->ssid_len;
244 data->freq = params->freq;
245 data->pairwise_suite = params->pairwise_suite;
246 data->group_suite = params->group_suite;
247 data->key_mgmt_suite = params->key_mgmt_suite;
248 data->auth_alg = params->auth_alg;
249 data->mode = params->mode;
250 data->wpa_ie_len = params->wpa_ie_len;
252 os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
253 /* TODO: add support for other assoc parameters */
255 res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
263 static int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
265 struct wpa_driver_privsep_data *drv = priv;
267 size_t len = ETH_ALEN;
269 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
270 if (res < 0 || len != ETH_ALEN)
276 static int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
278 struct wpa_driver_privsep_data *drv = priv;
280 u8 reply[sizeof(int) + 32];
281 size_t len = sizeof(reply);
283 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
284 if (res < 0 || len < sizeof(int))
286 os_memcpy(&ssid_len, reply, sizeof(int));
287 if (ssid_len < 0 || ssid_len > 32 || sizeof(int) + ssid_len > len) {
288 wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
291 os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
296 static int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
299 //struct wpa_driver_privsep_data *drv = priv;
300 wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
301 __func__, MAC2STR(addr), reason_code);
302 wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
307 static void wpa_driver_privsep_event_assoc(void *ctx,
308 enum wpa_event_type event,
311 union wpa_event_data data;
316 os_memset(&data, 0, sizeof(data));
321 if (end - pos < (int) sizeof(int))
323 os_memcpy(&ie_len, pos, sizeof(int));
325 if (ie_len < 0 || ie_len > end - pos)
328 data.assoc_info.req_ies = pos;
329 data.assoc_info.req_ies_len = ie_len;
334 wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
338 static void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
341 union wpa_event_data data;
344 if (len < sizeof(int) ||
345 len - sizeof(int) > sizeof(data.interface_status.ifname))
348 os_memcpy(&ievent, buf, sizeof(int));
350 os_memset(&data, 0, sizeof(data));
351 data.interface_status.ievent = ievent;
352 os_memcpy(data.interface_status.ifname, buf + sizeof(int),
354 wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
358 static void wpa_driver_privsep_event_michael_mic_failure(
359 void *ctx, u8 *buf, size_t len)
361 union wpa_event_data data;
363 if (len != sizeof(int))
366 os_memset(&data, 0, sizeof(data));
367 os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
368 wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
372 static void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
375 union wpa_event_data data;
377 if (len != sizeof(struct pmkid_candidate))
380 os_memset(&data, 0, sizeof(data));
381 os_memcpy(&data.pmkid_candidate, buf, len);
382 wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
386 static void wpa_driver_privsep_event_stkstart(void *ctx, u8 *buf, size_t len)
388 union wpa_event_data data;
393 os_memset(&data, 0, sizeof(data));
394 os_memcpy(data.stkstart.peer, buf, ETH_ALEN);
395 wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
399 static void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
402 union wpa_event_data data;
404 if (len < sizeof(int) + ETH_ALEN)
407 os_memset(&data, 0, sizeof(data));
408 os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
409 os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
410 data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
411 data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
412 wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
416 static void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
420 drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
424 static void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
427 struct wpa_driver_privsep_data *drv = eloop_ctx;
431 enum privsep_event e;
432 struct sockaddr_un from;
433 socklen_t fromlen = sizeof(from);
434 const size_t buflen = 2000;
436 buf = os_malloc(buflen);
439 res = recvfrom(sock, buf, buflen, 0,
440 (struct sockaddr *) &from, &fromlen);
442 perror("recvfrom(priv_socket)");
447 wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
449 if (res < (int) sizeof(int)) {
450 wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
454 os_memcpy(&event, buf, sizeof(int));
455 event_buf = &buf[sizeof(int)];
456 event_len = res - sizeof(int);
457 wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
458 event, (unsigned long) event_len);
462 case PRIVSEP_EVENT_SCAN_RESULTS:
463 wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
465 case PRIVSEP_EVENT_ASSOC:
466 wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
467 event_buf, event_len);
469 case PRIVSEP_EVENT_DISASSOC:
470 wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
472 case PRIVSEP_EVENT_ASSOCINFO:
473 wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
474 event_buf, event_len);
476 case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
477 wpa_driver_privsep_event_michael_mic_failure(
478 drv->ctx, event_buf, event_len);
480 case PRIVSEP_EVENT_INTERFACE_STATUS:
481 wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
484 case PRIVSEP_EVENT_PMKID_CANDIDATE:
485 wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
488 case PRIVSEP_EVENT_STKSTART:
489 wpa_driver_privsep_event_stkstart(drv->ctx, event_buf,
492 case PRIVSEP_EVENT_FT_RESPONSE:
493 wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
496 case PRIVSEP_EVENT_RX_EAPOL:
497 wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
506 static void * wpa_driver_privsep_init(void *ctx, const char *ifname)
508 struct wpa_driver_privsep_data *drv;
510 drv = os_zalloc(sizeof(*drv));
514 drv->priv_socket = -1;
515 drv->cmd_socket = -1;
516 os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
522 static void wpa_driver_privsep_deinit(void *priv)
524 struct wpa_driver_privsep_data *drv = priv;
526 if (drv->priv_socket >= 0) {
527 wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
528 eloop_unregister_read_sock(drv->priv_socket);
529 close(drv->priv_socket);
532 if (drv->own_socket_path) {
533 unlink(drv->own_socket_path);
534 os_free(drv->own_socket_path);
537 if (drv->cmd_socket >= 0) {
538 eloop_unregister_read_sock(drv->cmd_socket);
539 close(drv->cmd_socket);
542 if (drv->own_cmd_path) {
543 unlink(drv->own_cmd_path);
544 os_free(drv->own_cmd_path);
551 static int wpa_driver_privsep_set_param(void *priv, const char *param)
553 struct wpa_driver_privsep_data *drv = priv;
555 char *own_dir, *priv_dir;
556 static unsigned int counter = 0;
558 struct sockaddr_un addr;
560 wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
564 pos = os_strstr(param, "own_dir=");
567 own_dir = os_strdup(pos + 8);
570 end = os_strchr(own_dir, ' ');
574 own_dir = os_strdup("/tmp");
582 pos = os_strstr(param, "priv_dir=");
585 priv_dir = os_strdup(pos + 9);
586 if (priv_dir == NULL) {
590 end = os_strchr(priv_dir, ' ');
594 priv_dir = os_strdup("/var/run/wpa_priv");
595 if (priv_dir == NULL) {
601 len = os_strlen(own_dir) + 50;
602 drv->own_socket_path = os_malloc(len);
603 if (drv->own_socket_path == NULL) {
608 os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
609 own_dir, getpid(), counter++);
611 len = os_strlen(own_dir) + 50;
612 drv->own_cmd_path = os_malloc(len);
613 if (drv->own_cmd_path == NULL) {
614 os_free(drv->own_socket_path);
615 drv->own_socket_path = NULL;
620 os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
621 own_dir, getpid(), counter++);
625 drv->priv_addr.sun_family = AF_UNIX;
626 os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
627 "%s/%s", priv_dir, drv->ifname);
630 drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
631 if (drv->priv_socket < 0) {
632 perror("socket(PF_UNIX)");
633 os_free(drv->own_socket_path);
634 drv->own_socket_path = NULL;
638 os_memset(&addr, 0, sizeof(addr));
639 addr.sun_family = AF_UNIX;
640 os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
641 if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
643 perror("privsep-set-params priv-sock: bind(PF_UNIX)");
644 close(drv->priv_socket);
645 drv->priv_socket = -1;
646 unlink(drv->own_socket_path);
647 os_free(drv->own_socket_path);
648 drv->own_socket_path = NULL;
652 eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
655 drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
656 if (drv->cmd_socket < 0) {
657 perror("socket(PF_UNIX)");
658 os_free(drv->own_cmd_path);
659 drv->own_cmd_path = NULL;
663 os_memset(&addr, 0, sizeof(addr));
664 addr.sun_family = AF_UNIX;
665 os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
666 if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
668 perror("privsep-set-params cmd-sock: bind(PF_UNIX)");
669 close(drv->cmd_socket);
670 drv->cmd_socket = -1;
671 unlink(drv->own_cmd_path);
672 os_free(drv->own_cmd_path);
673 drv->own_cmd_path = NULL;
677 if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
678 wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
686 static int wpa_driver_privsep_get_capa(void *priv,
687 struct wpa_driver_capa *capa)
689 struct wpa_driver_privsep_data *drv = priv;
691 size_t len = sizeof(*capa);
693 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
694 if (res < 0 || len != sizeof(*capa))
700 static const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
702 struct wpa_driver_privsep_data *drv = priv;
703 wpa_printf(MSG_DEBUG, "%s", __func__);
704 return drv->own_addr;
708 static int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
710 struct wpa_driver_privsep_data *drv = priv;
711 wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
712 return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
713 os_strlen(alpha2), NULL, NULL);
717 struct wpa_driver_ops wpa_driver_privsep_ops = {
719 "wpa_supplicant privilege separated driver",
720 .get_bssid = wpa_driver_privsep_get_bssid,
721 .get_ssid = wpa_driver_privsep_get_ssid,
722 .set_key = wpa_driver_privsep_set_key,
723 .init = wpa_driver_privsep_init,
724 .deinit = wpa_driver_privsep_deinit,
725 .set_param = wpa_driver_privsep_set_param,
726 .scan2 = wpa_driver_privsep_scan,
727 .deauthenticate = wpa_driver_privsep_deauthenticate,
728 .associate = wpa_driver_privsep_associate,
729 .get_capa = wpa_driver_privsep_get_capa,
730 .get_mac_addr = wpa_driver_privsep_get_mac_addr,
731 .get_scan_results2 = wpa_driver_privsep_get_scan_results2,
732 .set_country = wpa_driver_privsep_set_country,
736 struct wpa_driver_ops *wpa_drivers[] =
738 &wpa_driver_privsep_ops,