]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/blob - sys/net80211/ieee80211_hwmp.c
Mesh update: add base Mesh Gate functionality.
[FreeBSD/FreeBSD.git] / sys / net80211 / ieee80211_hwmp.c
1 /*- 
2  * Copyright (c) 2009 The FreeBSD Foundation 
3  * All rights reserved. 
4  * 
5  * This software was developed by Rui Paulo under sponsorship from the
6  * FreeBSD Foundation. 
7  *  
8  * Redistribution and use in source and binary forms, with or without 
9  * modification, are permitted provided that the following conditions 
10  * are met: 
11  * 1. Redistributions of source code must retain the above copyright 
12  *    notice, this list of conditions and the following disclaimer. 
13  * 2. Redistributions in binary form must reproduce the above copyright 
14  *    notice, this list of conditions and the following disclaimer in the 
15  *    documentation and/or other materials provided with the distribution. 
16  * 
17  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 
18  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 
19  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 
20  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 
21  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 
22  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 
23  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 
24  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 
25  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 
26  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 
27  * SUCH DAMAGE. 
28  */ 
29 #include <sys/cdefs.h>
30 #ifdef __FreeBSD__
31 __FBSDID("$FreeBSD$");
32 #endif
33
34 /*
35  * IEEE 802.11s Hybrid Wireless Mesh Protocol, HWMP.
36  *
37  * Based on March 2009, D3.0 802.11s draft spec.
38  */
39 #include "opt_inet.h"
40 #include "opt_wlan.h"
41
42 #include <sys/param.h>
43 #include <sys/systm.h>
44 #include <sys/mbuf.h>
45 #include <sys/malloc.h>
46 #include <sys/kernel.h>
47
48 #include <sys/socket.h>
49 #include <sys/sockio.h>
50 #include <sys/endian.h>
51 #include <sys/errno.h>
52 #include <sys/proc.h>
53 #include <sys/sysctl.h>
54
55 #include <net/if.h>
56 #include <net/if_media.h>
57 #include <net/if_llc.h>
58 #include <net/ethernet.h>
59
60 #include <net/bpf.h>
61
62 #include <net80211/ieee80211_var.h>
63 #include <net80211/ieee80211_action.h>
64 #include <net80211/ieee80211_input.h>
65 #include <net80211/ieee80211_mesh.h>
66
67 static void     hwmp_vattach(struct ieee80211vap *);
68 static void     hwmp_vdetach(struct ieee80211vap *);
69 static int      hwmp_newstate(struct ieee80211vap *,
70                     enum ieee80211_state, int);
71 static int      hwmp_send_action(struct ieee80211_node *,
72                     const uint8_t [IEEE80211_ADDR_LEN],
73                     const uint8_t [IEEE80211_ADDR_LEN],
74                     uint8_t *, size_t);
75 static uint8_t * hwmp_add_meshpreq(uint8_t *,
76                     const struct ieee80211_meshpreq_ie *);
77 static uint8_t * hwmp_add_meshprep(uint8_t *,
78                     const struct ieee80211_meshprep_ie *);
79 static uint8_t * hwmp_add_meshperr(uint8_t *,
80                     const struct ieee80211_meshperr_ie *);
81 static uint8_t * hwmp_add_meshrann(uint8_t *,
82                     const struct ieee80211_meshrann_ie *);
83 static void     hwmp_rootmode_setup(struct ieee80211vap *);
84 static void     hwmp_rootmode_cb(void *);
85 static void     hwmp_rootmode_rann_cb(void *);
86 static void     hwmp_recv_preq(struct ieee80211vap *, struct ieee80211_node *,
87                     const struct ieee80211_frame *,
88                     const struct ieee80211_meshpreq_ie *);
89 static int      hwmp_send_preq(struct ieee80211_node *,
90                     const uint8_t [IEEE80211_ADDR_LEN],
91                     const uint8_t [IEEE80211_ADDR_LEN],
92                     struct ieee80211_meshpreq_ie *,
93                     struct timeval *, struct timeval *);
94 static void     hwmp_recv_prep(struct ieee80211vap *, struct ieee80211_node *,
95                     const struct ieee80211_frame *,
96                     const struct ieee80211_meshprep_ie *);
97 static int      hwmp_send_prep(struct ieee80211_node *,
98                     const uint8_t [IEEE80211_ADDR_LEN],
99                     const uint8_t [IEEE80211_ADDR_LEN],
100                     struct ieee80211_meshprep_ie *);
101 static void     hwmp_recv_perr(struct ieee80211vap *, struct ieee80211_node *,
102                     const struct ieee80211_frame *,
103                     const struct ieee80211_meshperr_ie *);
104 static int      hwmp_send_perr(struct ieee80211_node *,
105                     const uint8_t [IEEE80211_ADDR_LEN],
106                     const uint8_t [IEEE80211_ADDR_LEN],
107                     struct ieee80211_meshperr_ie *);
108 static void     hwmp_senderror(struct ieee80211vap *,
109                     const uint8_t [IEEE80211_ADDR_LEN],
110                     struct ieee80211_mesh_route *, int);
111 static void     hwmp_recv_rann(struct ieee80211vap *, struct ieee80211_node *,
112                    const struct ieee80211_frame *,
113                    const struct ieee80211_meshrann_ie *);
114 static int      hwmp_send_rann(struct ieee80211_node *,
115                     const uint8_t [IEEE80211_ADDR_LEN],
116                     const uint8_t [IEEE80211_ADDR_LEN],
117                     struct ieee80211_meshrann_ie *);
118 static struct ieee80211_node *
119                 hwmp_discover(struct ieee80211vap *,
120                     const uint8_t [IEEE80211_ADDR_LEN], struct mbuf *);
121 static void     hwmp_peerdown(struct ieee80211_node *);
122
123 static struct timeval ieee80211_hwmp_preqminint = { 0, 100000 };
124 static struct timeval ieee80211_hwmp_perrminint = { 0, 100000 };
125
126 /* unalligned little endian access */
127 #define LE_WRITE_2(p, v) do {                           \
128         ((uint8_t *)(p))[0] = (v) & 0xff;               \
129         ((uint8_t *)(p))[1] = ((v) >> 8) & 0xff;        \
130 } while (0)
131 #define LE_WRITE_4(p, v) do {                           \
132         ((uint8_t *)(p))[0] = (v) & 0xff;               \
133         ((uint8_t *)(p))[1] = ((v) >> 8) & 0xff;        \
134         ((uint8_t *)(p))[2] = ((v) >> 16) & 0xff;       \
135         ((uint8_t *)(p))[3] = ((v) >> 24) & 0xff;       \
136 } while (0)
137
138
139 /* NB: the Target Address set in a Proactive PREQ is the broadcast address. */
140 static const uint8_t    broadcastaddr[IEEE80211_ADDR_LEN] =
141         { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
142
143 typedef uint32_t ieee80211_hwmp_seq;
144 #define HWMP_SEQ_LT(a, b)       ((int32_t)((a)-(b)) < 0)
145 #define HWMP_SEQ_LEQ(a, b)      ((int32_t)((a)-(b)) <= 0)
146 #define HWMP_SEQ_EQ(a, b)       ((int32_t)((a)-(b)) == 0)
147 #define HWMP_SEQ_GT(a, b)       ((int32_t)((a)-(b)) > 0)
148 #define HWMP_SEQ_GEQ(a, b)      ((int32_t)((a)-(b)) >= 0)
149
150 #define HWMP_SEQ_MAX(a, b)      (a > b ? a : b)
151
152 /*
153  * Private extension of ieee80211_mesh_route.
154  */
155 struct ieee80211_hwmp_route {
156         ieee80211_hwmp_seq      hr_seq;         /* last HWMP seq seen from dst*/
157         ieee80211_hwmp_seq      hr_preqid;      /* last PREQ ID seen from dst */
158         ieee80211_hwmp_seq      hr_origseq;     /* seq. no. on our latest PREQ*/
159         struct timeval          hr_lastpreq;    /* last time we sent a PREQ */
160         struct timeval          hr_lastrootconf; /* last sent PREQ root conf */
161         int                     hr_preqretries; /* number of discoveries */
162         int                     hr_lastdiscovery; /* last discovery in ticks */
163 };
164 struct ieee80211_hwmp_state {
165         ieee80211_hwmp_seq      hs_seq;         /* next seq to be used */
166         ieee80211_hwmp_seq      hs_preqid;      /* next PREQ ID to be used */
167         int                     hs_rootmode;    /* proactive HWMP */
168         struct timeval          hs_lastperr;    /* last time we sent a PERR */
169         struct callout          hs_roottimer;
170         uint8_t                 hs_maxhops;     /* max hop count */
171 };
172
173 static SYSCTL_NODE(_net_wlan, OID_AUTO, hwmp, CTLFLAG_RD, 0,
174     "IEEE 802.11s HWMP parameters");
175 static int      ieee80211_hwmp_targetonly = 0;
176 SYSCTL_INT(_net_wlan_hwmp, OID_AUTO, targetonly, CTLTYPE_INT | CTLFLAG_RW,
177     &ieee80211_hwmp_targetonly, 0, "Set TO bit on generated PREQs");
178 static int      ieee80211_hwmp_pathtimeout = -1;
179 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, pathlifetime, CTLTYPE_INT | CTLFLAG_RW,
180     &ieee80211_hwmp_pathtimeout, 0, ieee80211_sysctl_msecs_ticks, "I",
181     "path entry lifetime (ms)");
182 static int      ieee80211_hwmp_maxpreq_retries = -1;
183 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, maxpreq_retries, CTLTYPE_INT | CTLFLAG_RW,
184     &ieee80211_hwmp_maxpreq_retries, 0, ieee80211_sysctl_msecs_ticks, "I",
185     "maximum number of preq retries");
186 static int      ieee80211_hwmp_net_diameter_traversaltime = -1;
187 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, net_diameter_traversal_time,
188     CTLTYPE_INT | CTLFLAG_RW, &ieee80211_hwmp_net_diameter_traversaltime, 0,
189     ieee80211_sysctl_msecs_ticks, "I",
190     "estimate travelse time across the MBSS (ms)");
191 static int      ieee80211_hwmp_roottimeout = -1;
192 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, roottimeout, CTLTYPE_INT | CTLFLAG_RW,
193     &ieee80211_hwmp_roottimeout, 0, ieee80211_sysctl_msecs_ticks, "I",
194     "root PREQ timeout (ms)");
195 static int      ieee80211_hwmp_rootint = -1;
196 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, rootint, CTLTYPE_INT | CTLFLAG_RW,
197     &ieee80211_hwmp_rootint, 0, ieee80211_sysctl_msecs_ticks, "I",
198     "root interval (ms)");
199 static int      ieee80211_hwmp_rannint = -1;
200 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, rannint, CTLTYPE_INT | CTLFLAG_RW,
201     &ieee80211_hwmp_rannint, 0, ieee80211_sysctl_msecs_ticks, "I",
202     "root announcement interval (ms)");
203 static struct timeval ieee80211_hwmp_rootconfint = { 0, 0 };
204 static int      ieee80211_hwmp_rootconfint_internal = -1;
205 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, rootconfint, CTLTYPE_INT | CTLFLAG_RD,
206     &ieee80211_hwmp_rootconfint_internal, 0, ieee80211_sysctl_msecs_ticks, "I",
207     "root confirmation interval (ms) (read-only)");
208
209 #define IEEE80211_HWMP_DEFAULT_MAXHOPS  31
210
211 static  ieee80211_recv_action_func hwmp_recv_action_meshpath;
212
213 static struct ieee80211_mesh_proto_path mesh_proto_hwmp = {
214         .mpp_descr      = "HWMP",
215         .mpp_ie         = IEEE80211_MESHCONF_PATH_HWMP,
216         .mpp_discover   = hwmp_discover,
217         .mpp_peerdown   = hwmp_peerdown,
218         .mpp_senderror  = hwmp_senderror,
219         .mpp_vattach    = hwmp_vattach,
220         .mpp_vdetach    = hwmp_vdetach,
221         .mpp_newstate   = hwmp_newstate,
222         .mpp_privlen    = sizeof(struct ieee80211_hwmp_route),
223 };
224 SYSCTL_PROC(_net_wlan_hwmp, OID_AUTO, inact, CTLTYPE_INT | CTLFLAG_RW,
225         &mesh_proto_hwmp.mpp_inact, 0, ieee80211_sysctl_msecs_ticks, "I",
226         "mesh route inactivity timeout (ms)");
227
228
229 static void
230 ieee80211_hwmp_init(void)
231 {
232         /* Default values as per amendment */
233         ieee80211_hwmp_pathtimeout = msecs_to_ticks(5*1000);
234         ieee80211_hwmp_roottimeout = msecs_to_ticks(5*1000);
235         ieee80211_hwmp_rootint = msecs_to_ticks(2*1000);
236         ieee80211_hwmp_rannint = msecs_to_ticks(1*1000);
237         ieee80211_hwmp_rootconfint_internal = msecs_to_ticks(2*1000);
238         ieee80211_hwmp_maxpreq_retries = 3;
239         /*
240          * (TU): A measurement of time equal to 1024 Î¼s,
241          * 500 TU is 512 ms.
242          */
243         ieee80211_hwmp_net_diameter_traversaltime = msecs_to_ticks(512);
244
245         /*
246          * NB: I dont know how to make SYSCTL_PROC that calls ms to ticks
247          * and return a struct timeval...
248          */
249         ieee80211_hwmp_rootconfint.tv_usec =
250             ieee80211_hwmp_rootconfint_internal * 1000;
251
252         /*
253          * Register action frame handler.
254          */
255         ieee80211_recv_action_register(IEEE80211_ACTION_CAT_MESH,
256             IEEE80211_ACTION_MESH_HWMP, hwmp_recv_action_meshpath);
257
258         /* NB: default is 5 secs per spec */
259         mesh_proto_hwmp.mpp_inact = msecs_to_ticks(5*1000);
260
261         /*
262          * Register HWMP.
263          */
264         ieee80211_mesh_register_proto_path(&mesh_proto_hwmp);
265 }
266 SYSINIT(wlan_hwmp, SI_SUB_DRIVERS, SI_ORDER_SECOND, ieee80211_hwmp_init, NULL);
267
268 void
269 hwmp_vattach(struct ieee80211vap *vap)
270 {
271         struct ieee80211_hwmp_state *hs;
272
273         KASSERT(vap->iv_opmode == IEEE80211_M_MBSS,
274             ("not a mesh vap, opmode %d", vap->iv_opmode));
275
276         hs = malloc(sizeof(struct ieee80211_hwmp_state), M_80211_VAP,
277             M_NOWAIT | M_ZERO);
278         if (hs == NULL) {
279                 printf("%s: couldn't alloc HWMP state\n", __func__);
280                 return;
281         }
282         hs->hs_maxhops = IEEE80211_HWMP_DEFAULT_MAXHOPS;
283         callout_init(&hs->hs_roottimer, CALLOUT_MPSAFE);
284         vap->iv_hwmp = hs;
285 }
286
287 void
288 hwmp_vdetach(struct ieee80211vap *vap)
289 {
290         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
291
292         callout_drain(&hs->hs_roottimer);
293         free(vap->iv_hwmp, M_80211_VAP);
294         vap->iv_hwmp = NULL;
295
296
297 int
298 hwmp_newstate(struct ieee80211vap *vap, enum ieee80211_state ostate, int arg)
299 {
300         enum ieee80211_state nstate = vap->iv_state;
301         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
302
303         IEEE80211_DPRINTF(vap, IEEE80211_MSG_STATE, "%s: %s -> %s (%d)\n",
304             __func__, ieee80211_state_name[ostate],
305             ieee80211_state_name[nstate], arg);
306
307         if (nstate != IEEE80211_S_RUN && ostate == IEEE80211_S_RUN)
308                 callout_drain(&hs->hs_roottimer);
309         if (nstate == IEEE80211_S_RUN)
310                 hwmp_rootmode_setup(vap);
311         return 0;
312 }
313
314 /*
315  * Verify the length of an HWMP PREQ and return the number
316  * of destinations >= 1, if verification fails -1 is returned.
317  */
318 static int
319 verify_mesh_preq_len(struct ieee80211vap *vap,
320     const struct ieee80211_frame *wh, const uint8_t *iefrm)
321 {
322         int alloc_sz = -1;
323         int ndest = -1;
324         if (iefrm[2] & IEEE80211_MESHPREQ_FLAGS_AE) {
325                 /* Originator External Address  present */
326                 alloc_sz =  IEEE80211_MESHPREQ_BASE_SZ_AE;
327                 ndest = iefrm[IEEE80211_MESHPREQ_TCNT_OFFSET_AE];
328         } else {
329                 /* w/o Originator External Address */
330                 alloc_sz =  IEEE80211_MESHPREQ_BASE_SZ;
331                 ndest = iefrm[IEEE80211_MESHPREQ_TCNT_OFFSET];
332         }
333         alloc_sz += ndest * IEEE80211_MESHPREQ_TRGT_SZ;
334
335         if(iefrm[1] != (alloc_sz)) {
336                 IEEE80211_DISCARD(vap,
337                     IEEE80211_MSG_ACTION | IEEE80211_MSG_HWMP,
338                     wh, NULL, "PREQ (AE=%s) with wrong len",
339                     iefrm[2] & IEEE80211_MESHPREQ_FLAGS_AE ? "1" : "0");
340                 return (-1);
341         }
342         return ndest;
343 }
344
345 /*
346  * Verify the length of an HWMP PREP and returns 1 on success,
347  * otherwise -1.
348  */
349 static int
350 verify_mesh_prep_len(struct ieee80211vap *vap,
351     const struct ieee80211_frame *wh, const uint8_t *iefrm)
352 {
353         int alloc_sz = -1;
354         if (iefrm[2] & IEEE80211_MESHPREP_FLAGS_AE) {
355                 if (iefrm[1] == IEEE80211_MESHPREP_BASE_SZ_AE)
356                         alloc_sz = IEEE80211_MESHPREP_BASE_SZ_AE;
357         } else if (iefrm[1] == IEEE80211_MESHPREP_BASE_SZ)
358                 alloc_sz = IEEE80211_MESHPREP_BASE_SZ;
359         if(alloc_sz < 0) {
360                 IEEE80211_DISCARD(vap,
361                     IEEE80211_MSG_ACTION | IEEE80211_MSG_HWMP,
362                     wh, NULL, "PREP (AE=%s) with wrong len",
363                     iefrm[2] & IEEE80211_MESHPREP_FLAGS_AE ? "1" : "0");
364                 return (-1);
365         }
366         return (1);
367 }
368
369 /*
370  * Verify the length of an HWMP PERR and return the number
371  * of destinations >= 1, if verification fails -1 is returned.
372  */
373 static int
374 verify_mesh_perr_len(struct ieee80211vap *vap,
375     const struct ieee80211_frame *wh, const uint8_t *iefrm)
376 {
377         int alloc_sz = -1;
378         const uint8_t *iefrm_t = iefrm;
379         uint8_t ndest = iefrm_t[IEEE80211_MESHPERR_NDEST_OFFSET];
380         int i;
381
382         if(ndest > IEEE80211_MESHPERR_MAXDEST) {
383                 IEEE80211_DISCARD(vap,
384                     IEEE80211_MSG_ACTION | IEEE80211_MSG_HWMP,
385                     wh, NULL, "PERR with wrong number of destionat (>19), %u",
386                     ndest);
387                 return (-1);
388         }
389
390         iefrm_t += IEEE80211_MESHPERR_NDEST_OFFSET + 1; /* flag is next field */
391         /* We need to check each destionation flag to know size */
392         for(i = 0; i<ndest; i++) {
393                 if ((*iefrm_t) & IEEE80211_MESHPERR_FLAGS_AE)
394                         iefrm_t += IEEE80211_MESHPERR_DEST_SZ_AE;
395                 else
396                         iefrm_t += IEEE80211_MESHPERR_DEST_SZ;
397         }
398
399         alloc_sz = (iefrm_t - iefrm) - 2; /* action + code */
400         if(alloc_sz !=  iefrm[1]) {
401                 IEEE80211_DISCARD(vap,
402                     IEEE80211_MSG_ACTION | IEEE80211_MSG_HWMP,
403                     wh, NULL, "%s", "PERR with wrong len");
404                 return (-1);
405         }
406         return ndest;
407 }
408
409 static int
410 hwmp_recv_action_meshpath(struct ieee80211_node *ni,
411         const struct ieee80211_frame *wh,
412         const uint8_t *frm, const uint8_t *efrm)
413 {
414         struct ieee80211vap *vap = ni->ni_vap;
415         struct ieee80211_meshpreq_ie *preq;
416         struct ieee80211_meshprep_ie *prep;
417         struct ieee80211_meshperr_ie *perr;
418         struct ieee80211_meshrann_ie rann;
419         const uint8_t *iefrm = frm + 2; /* action + code */
420         const uint8_t *iefrm_t = iefrm; /* temporary pointer */
421         int ndest = -1;
422         int found = 0;
423
424         while (efrm - iefrm > 1) {
425                 IEEE80211_VERIFY_LENGTH(efrm - iefrm, iefrm[1] + 2, return 0);
426                 switch (*iefrm) {
427                 case IEEE80211_ELEMID_MESHPREQ:
428                 {
429                         int i = 0;
430
431                         iefrm_t = iefrm;
432                         ndest = verify_mesh_preq_len(vap, wh, iefrm_t);
433                         if (ndest < 0) {
434                                 vap->iv_stats.is_rx_mgtdiscard++;
435                                 break;
436                         }
437                         preq = malloc(sizeof(*preq) +
438                             (ndest - 1) * sizeof(*preq->preq_targets),
439                             M_80211_MESH_PREQ, M_NOWAIT | M_ZERO);
440                         KASSERT(preq != NULL, ("preq == NULL"));
441
442                         preq->preq_ie = *iefrm_t++;
443                         preq->preq_len = *iefrm_t++;
444                         preq->preq_flags = *iefrm_t++;
445                         preq->preq_hopcount = *iefrm_t++;
446                         preq->preq_ttl = *iefrm_t++;
447                         preq->preq_id = LE_READ_4(iefrm_t); iefrm_t += 4;
448                         IEEE80211_ADDR_COPY(preq->preq_origaddr, iefrm_t);
449                         iefrm_t += 6;
450                         preq->preq_origseq = LE_READ_4(iefrm_t); iefrm_t += 4;
451                         /* NB: may have Originator Proxied Address */
452                         if (preq->preq_flags & IEEE80211_MESHPREQ_FLAGS_AE)  {
453                                 IEEE80211_ADDR_COPY(
454                                     preq->preq_orig_ext_addr, iefrm_t);
455                                 iefrm_t += 6;
456                         }
457                         preq->preq_lifetime = LE_READ_4(iefrm_t); iefrm_t += 4;
458                         preq->preq_metric = LE_READ_4(iefrm_t); iefrm_t += 4;
459                         preq->preq_tcount = *iefrm_t++;
460                         
461                         for (i = 0; i < preq->preq_tcount; i++) {
462                                 preq->preq_targets[i].target_flags = *iefrm_t++;
463                                 IEEE80211_ADDR_COPY(
464                                     preq->preq_targets[i].target_addr, iefrm_t);
465                                 iefrm_t += 6;
466                                 preq->preq_targets[i].target_seq =
467                                     LE_READ_4(iefrm_t);
468                                 iefrm_t += 4;
469                         }
470
471                         hwmp_recv_preq(vap, ni, wh, preq);
472                         free(preq, M_80211_MESH_PREQ);
473                         found++;
474                         break;
475                 }
476                 case IEEE80211_ELEMID_MESHPREP:
477                 {
478                         iefrm_t = iefrm;
479                         ndest = verify_mesh_prep_len(vap, wh, iefrm_t);
480                         if (ndest < 0) {
481                                 vap->iv_stats.is_rx_mgtdiscard++;
482                                 break;
483                         }
484                         prep = malloc(sizeof(*prep),
485                             M_80211_MESH_PREP, M_NOWAIT | M_ZERO);
486                         KASSERT(prep != NULL, ("prep == NULL"));
487
488                         prep->prep_ie = *iefrm_t++;
489                         prep->prep_len = *iefrm_t++;
490                         prep->prep_flags = *iefrm_t++;
491                         prep->prep_hopcount = *iefrm_t++;
492                         prep->prep_ttl = *iefrm_t++;
493                         IEEE80211_ADDR_COPY(prep->prep_targetaddr, iefrm_t);
494                         iefrm_t += 6;
495                         prep->prep_targetseq = LE_READ_4(iefrm_t); iefrm_t += 4;
496                         /* NB: May have Target Proxied Address */
497                         if (prep->prep_flags & IEEE80211_MESHPREP_FLAGS_AE)  {
498                                 IEEE80211_ADDR_COPY(
499                                     prep->prep_target_ext_addr, iefrm_t);
500                                 iefrm_t += 6;
501                         }
502                         prep->prep_lifetime = LE_READ_4(iefrm_t); iefrm_t += 4;
503                         prep->prep_metric = LE_READ_4(iefrm_t); iefrm_t += 4;
504                         IEEE80211_ADDR_COPY(prep->prep_origaddr, iefrm_t);
505                         iefrm_t += 6;
506                         prep->prep_origseq = LE_READ_4(iefrm_t); iefrm_t += 4;
507
508                         hwmp_recv_prep(vap, ni, wh, prep);
509                         free(prep, M_80211_MESH_PREP);
510                         found++;
511                         break;
512                 }
513                 case IEEE80211_ELEMID_MESHPERR:
514                 {
515                         int i = 0;
516
517                         iefrm_t = iefrm;
518                         ndest = verify_mesh_perr_len(vap, wh, iefrm_t);
519                         if (ndest < 0) {
520                                 vap->iv_stats.is_rx_mgtdiscard++;
521                                 break;
522                         }
523                         perr = malloc(sizeof(*perr) +
524                             (ndest - 1) * sizeof(*perr->perr_dests),
525                             M_80211_MESH_PERR, M_NOWAIT | M_ZERO);
526                         KASSERT(perr != NULL, ("perr == NULL"));
527
528                         perr->perr_ie = *iefrm_t++;
529                         perr->perr_len = *iefrm_t++;
530                         perr->perr_ttl = *iefrm_t++;
531                         perr->perr_ndests = *iefrm_t++;
532
533                         for (i = 0; i<perr->perr_ndests; i++) {
534                                 perr->perr_dests[i].dest_flags = *iefrm_t++;
535                                 IEEE80211_ADDR_COPY(
536                                     perr->perr_dests[i].dest_addr, iefrm_t);
537                                 iefrm_t += 6;
538                                 perr->perr_dests[i].dest_seq = LE_READ_4(iefrm_t);
539                                 iefrm_t += 4;
540                                 /* NB: May have Target Proxied Address */
541                                 if (perr->perr_dests[i].dest_flags &
542                                     IEEE80211_MESHPERR_FLAGS_AE) {
543                                         IEEE80211_ADDR_COPY(
544                                             perr->perr_dests[i].dest_ext_addr,
545                                             iefrm_t);
546                                         iefrm_t += 6;
547                                 }
548                                 perr->perr_dests[i].dest_rcode =
549                                     LE_READ_2(iefrm_t);
550                                 iefrm_t += 2;
551                         }
552
553                         hwmp_recv_perr(vap, ni, wh, perr);
554                         free(perr, M_80211_MESH_PERR);
555                         found++;
556                         break;
557                 }
558                 case IEEE80211_ELEMID_MESHRANN:
559                 {
560                         const struct ieee80211_meshrann_ie *mrann =
561                             (const struct ieee80211_meshrann_ie *) iefrm;
562                         if (mrann->rann_len !=
563                             sizeof(struct ieee80211_meshrann_ie) - 2) {
564                                 IEEE80211_DISCARD(vap,
565                                     IEEE80211_MSG_ACTION | IEEE80211_MSG_HWMP,
566                                     wh, NULL, "%s", "RAN with wrong len");
567                                     vap->iv_stats.is_rx_mgtdiscard++;
568                                 return 1;
569                         }
570                         memcpy(&rann, mrann, sizeof(rann));
571                         rann.rann_seq = LE_READ_4(&mrann->rann_seq);
572                         rann.rann_interval = LE_READ_4(&mrann->rann_interval);
573                         rann.rann_metric = LE_READ_4(&mrann->rann_metric);
574                         hwmp_recv_rann(vap, ni, wh, &rann);
575                         found++;
576                         break;
577                 }
578                 }
579                 iefrm += iefrm[1] + 2;
580         }
581         if (!found) {
582                 IEEE80211_DISCARD(vap,
583                     IEEE80211_MSG_ACTION | IEEE80211_MSG_HWMP,
584                     wh, NULL, "%s", "PATH SEL action without IE");
585                 vap->iv_stats.is_rx_mgtdiscard++;
586         }
587         return 0;
588 }
589
590 static int
591 hwmp_send_action(struct ieee80211_node *ni,
592     const uint8_t sa[IEEE80211_ADDR_LEN],
593     const uint8_t da[IEEE80211_ADDR_LEN],
594     uint8_t *ie, size_t len)
595 {
596         struct ieee80211vap *vap = ni->ni_vap;
597         struct ieee80211com *ic = ni->ni_ic;
598         struct ieee80211_bpf_params params;
599         struct mbuf *m;
600         uint8_t *frm;
601
602         if (vap->iv_state == IEEE80211_S_CAC) {
603                 IEEE80211_NOTE(vap, IEEE80211_MSG_OUTPUT, ni,
604                     "block %s frame in CAC state", "HWMP action");
605                 vap->iv_stats.is_tx_badstate++;
606                 return EIO;     /* XXX */
607         }
608
609         KASSERT(ni != NULL, ("null node"));
610         /*
611          * Hold a reference on the node so it doesn't go away until after
612          * the xmit is complete all the way in the driver.  On error we
613          * will remove our reference.
614          */
615 #ifdef IEEE80211_DEBUG_REFCNT
616         IEEE80211_DPRINTF(vap, IEEE80211_MSG_NODE,
617             "ieee80211_ref_node (%s:%u) %p<%s> refcnt %d\n",
618             __func__, __LINE__,
619             ni, ether_sprintf(ni->ni_macaddr),
620             ieee80211_node_refcnt(ni)+1);
621 #endif
622         ieee80211_ref_node(ni);
623
624         m = ieee80211_getmgtframe(&frm,
625             ic->ic_headroom + sizeof(struct ieee80211_frame),
626             sizeof(struct ieee80211_action) + len
627         );
628         if (m == NULL) {
629                 ieee80211_free_node(ni);
630                 vap->iv_stats.is_tx_nobuf++;
631                 return ENOMEM;
632         }
633         *frm++ = IEEE80211_ACTION_CAT_MESH;
634         *frm++ = IEEE80211_ACTION_MESH_HWMP;
635         switch (*ie) {
636         case IEEE80211_ELEMID_MESHPREQ:
637                 frm = hwmp_add_meshpreq(frm,
638                     (struct ieee80211_meshpreq_ie *)ie);
639                 break;
640         case IEEE80211_ELEMID_MESHPREP:
641                 frm = hwmp_add_meshprep(frm,
642                     (struct ieee80211_meshprep_ie *)ie);
643                 break;
644         case IEEE80211_ELEMID_MESHPERR:
645                 frm = hwmp_add_meshperr(frm,
646                     (struct ieee80211_meshperr_ie *)ie);
647                 break;
648         case IEEE80211_ELEMID_MESHRANN:
649                 frm = hwmp_add_meshrann(frm,
650                     (struct ieee80211_meshrann_ie *)ie);
651                 break;
652         }
653
654         m->m_pkthdr.len = m->m_len = frm - mtod(m, uint8_t *);
655         M_PREPEND(m, sizeof(struct ieee80211_frame), M_NOWAIT);
656         if (m == NULL) {
657                 ieee80211_free_node(ni);
658                 vap->iv_stats.is_tx_nobuf++;
659                 return ENOMEM;
660         }
661         ieee80211_send_setup(ni, m,
662             IEEE80211_FC0_TYPE_MGT | IEEE80211_FC0_SUBTYPE_ACTION,
663             IEEE80211_NONQOS_TID, sa, da, sa);
664
665         m->m_flags |= M_ENCAP;          /* mark encapsulated */
666         IEEE80211_NODE_STAT(ni, tx_mgmt);
667
668         memset(&params, 0, sizeof(params));
669         params.ibp_pri = WME_AC_VO;
670         params.ibp_rate0 = ni->ni_txparms->mgmtrate;
671         if (IEEE80211_IS_MULTICAST(da))
672                 params.ibp_try0 = 1;
673         else
674                 params.ibp_try0 = ni->ni_txparms->maxretry;
675         params.ibp_power = ni->ni_txpower;
676         return ic->ic_raw_xmit(ni, m, &params);
677 }
678
679 #define ADDSHORT(frm, v) do {           \
680         frm[0] = (v) & 0xff;            \
681         frm[1] = (v) >> 8;              \
682         frm += 2;                       \
683 } while (0)
684 #define ADDWORD(frm, v) do {            \
685         LE_WRITE_4(frm, v);             \
686         frm += 4;                       \
687 } while (0)
688 /*
689  * Add a Mesh Path Request IE to a frame.
690  */
691 #define PREQ_TFLAGS(n)  preq->preq_targets[n].target_flags
692 #define PREQ_TADDR(n)   preq->preq_targets[n].target_addr
693 #define PREQ_TSEQ(n)    preq->preq_targets[n].target_seq
694 static uint8_t *
695 hwmp_add_meshpreq(uint8_t *frm, const struct ieee80211_meshpreq_ie *preq)
696 {
697         int i;
698
699         *frm++ = IEEE80211_ELEMID_MESHPREQ;
700         *frm++ = preq->preq_len;        /* len already calculated */
701         *frm++ = preq->preq_flags;
702         *frm++ = preq->preq_hopcount;
703         *frm++ = preq->preq_ttl;
704         ADDWORD(frm, preq->preq_id);
705         IEEE80211_ADDR_COPY(frm, preq->preq_origaddr); frm += 6;
706         ADDWORD(frm, preq->preq_origseq);
707         if (preq->preq_flags & IEEE80211_MESHPREQ_FLAGS_AE) {
708                 IEEE80211_ADDR_COPY(frm, preq->preq_orig_ext_addr);
709                 frm += 6;
710         }
711         ADDWORD(frm, preq->preq_lifetime);
712         ADDWORD(frm, preq->preq_metric);
713         *frm++ = preq->preq_tcount;
714         for (i = 0; i < preq->preq_tcount; i++) {
715                 *frm++ = PREQ_TFLAGS(i);
716                 IEEE80211_ADDR_COPY(frm, PREQ_TADDR(i));
717                 frm += 6;
718                 ADDWORD(frm, PREQ_TSEQ(i));
719         }
720         return frm;
721 }
722 #undef  PREQ_TFLAGS
723 #undef  PREQ_TADDR
724 #undef  PREQ_TSEQ
725
726 /*
727  * Add a Mesh Path Reply IE to a frame.
728  */
729 static uint8_t *
730 hwmp_add_meshprep(uint8_t *frm, const struct ieee80211_meshprep_ie *prep)
731 {
732         *frm++ = IEEE80211_ELEMID_MESHPREP;
733         *frm++ = prep->prep_len;        /* len already calculated */
734         *frm++ = prep->prep_flags;
735         *frm++ = prep->prep_hopcount;
736         *frm++ = prep->prep_ttl;
737         IEEE80211_ADDR_COPY(frm, prep->prep_targetaddr); frm += 6;
738         ADDWORD(frm, prep->prep_targetseq);
739         if (prep->prep_flags & IEEE80211_MESHPREP_FLAGS_AE) {
740                 IEEE80211_ADDR_COPY(frm, prep->prep_target_ext_addr);
741                 frm += 6;
742         }
743         ADDWORD(frm, prep->prep_lifetime);
744         ADDWORD(frm, prep->prep_metric);
745         IEEE80211_ADDR_COPY(frm, prep->prep_origaddr); frm += 6;
746         ADDWORD(frm, prep->prep_origseq);
747         return frm;
748 }
749
750 /*
751  * Add a Mesh Path Error IE to a frame.
752  */
753 #define PERR_DFLAGS(n)  perr->perr_dests[n].dest_flags
754 #define PERR_DADDR(n)   perr->perr_dests[n].dest_addr
755 #define PERR_DSEQ(n)    perr->perr_dests[n].dest_seq
756 #define PERR_EXTADDR(n) perr->perr_dests[n].dest_ext_addr
757 #define PERR_DRCODE(n)  perr->perr_dests[n].dest_rcode
758 static uint8_t *
759 hwmp_add_meshperr(uint8_t *frm, const struct ieee80211_meshperr_ie *perr)
760 {
761         int i;
762
763         *frm++ = IEEE80211_ELEMID_MESHPERR;
764         *frm++ = perr->perr_len;        /* len already calculated */
765         *frm++ = perr->perr_ttl;
766         *frm++ = perr->perr_ndests;
767         for (i = 0; i < perr->perr_ndests; i++) {
768                 *frm++ = PERR_DFLAGS(i);
769                 IEEE80211_ADDR_COPY(frm, PERR_DADDR(i));
770                 frm += 6;
771                 ADDWORD(frm, PERR_DSEQ(i));
772                 if (PERR_DFLAGS(i) & IEEE80211_MESHPERR_FLAGS_AE) {
773                         IEEE80211_ADDR_COPY(frm, PERR_EXTADDR(i));
774                         frm += 6;
775                 }
776                 ADDSHORT(frm, PERR_DRCODE(i));
777         }
778         return frm;
779 }
780 #undef  PERR_DFLAGS
781 #undef  PERR_DADDR
782 #undef  PERR_DSEQ
783 #undef  PERR_EXTADDR
784 #undef  PERR_DRCODE
785
786 /*
787  * Add a Root Annoucement IE to a frame.
788  */
789 static uint8_t *
790 hwmp_add_meshrann(uint8_t *frm, const struct ieee80211_meshrann_ie *rann)
791 {
792         *frm++ = IEEE80211_ELEMID_MESHRANN;
793         *frm++ = rann->rann_len;
794         *frm++ = rann->rann_flags;
795         *frm++ = rann->rann_hopcount;
796         *frm++ = rann->rann_ttl;
797         IEEE80211_ADDR_COPY(frm, rann->rann_addr); frm += 6;
798         ADDWORD(frm, rann->rann_seq);
799         ADDWORD(frm, rann->rann_interval);
800         ADDWORD(frm, rann->rann_metric);
801         return frm;
802 }
803
804 static void
805 hwmp_rootmode_setup(struct ieee80211vap *vap)
806 {
807         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
808         struct ieee80211_mesh_state *ms = vap->iv_mesh;
809
810         switch (hs->hs_rootmode) {
811         case IEEE80211_HWMP_ROOTMODE_DISABLED:
812                 callout_drain(&hs->hs_roottimer);
813                 ms->ms_flags &= ~IEEE80211_MESHFLAGS_ROOT;
814                 break;
815         case IEEE80211_HWMP_ROOTMODE_NORMAL:
816         case IEEE80211_HWMP_ROOTMODE_PROACTIVE:
817                 callout_reset(&hs->hs_roottimer, ieee80211_hwmp_rootint,
818                     hwmp_rootmode_cb, vap);
819                 ms->ms_flags |= IEEE80211_MESHFLAGS_ROOT;
820                 break;
821         case IEEE80211_HWMP_ROOTMODE_RANN:
822                 callout_reset(&hs->hs_roottimer, ieee80211_hwmp_rannint,
823                     hwmp_rootmode_rann_cb, vap);
824                 ms->ms_flags |= IEEE80211_MESHFLAGS_ROOT;
825                 break;
826         }
827 }
828
829 /*
830  * Send a broadcast Path Request to find all nodes on the mesh. We are
831  * called when the vap is configured as a HWMP root node.
832  */
833 #define PREQ_TFLAGS(n)  preq.preq_targets[n].target_flags
834 #define PREQ_TADDR(n)   preq.preq_targets[n].target_addr
835 #define PREQ_TSEQ(n)    preq.preq_targets[n].target_seq
836 static void
837 hwmp_rootmode_cb(void *arg)
838 {
839         struct ieee80211vap *vap = (struct ieee80211vap *)arg;
840         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
841         struct ieee80211_mesh_state *ms = vap->iv_mesh;
842         struct ieee80211_meshpreq_ie preq;
843
844         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, vap->iv_bss,
845             "%s", "send broadcast PREQ");
846
847         preq.preq_flags = 0;
848         if (ms->ms_flags & IEEE80211_MESHFLAGS_GATE)
849                 preq.preq_flags |= IEEE80211_MESHPREQ_FLAGS_GATE;
850         if (hs->hs_rootmode == IEEE80211_HWMP_ROOTMODE_PROACTIVE)
851                 preq.preq_flags |= IEEE80211_MESHPREQ_FLAGS_PP;
852         preq.preq_hopcount = 0;
853         preq.preq_ttl = ms->ms_ttl;
854         preq.preq_id = ++hs->hs_preqid;
855         IEEE80211_ADDR_COPY(preq.preq_origaddr, vap->iv_myaddr);
856         preq.preq_origseq = ++hs->hs_seq;
857         preq.preq_lifetime = ticks_to_msecs(ieee80211_hwmp_roottimeout);
858         preq.preq_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
859         preq.preq_tcount = 1;
860         IEEE80211_ADDR_COPY(PREQ_TADDR(0), broadcastaddr);
861         PREQ_TFLAGS(0) = IEEE80211_MESHPREQ_TFLAGS_TO |
862             IEEE80211_MESHPREQ_TFLAGS_USN;
863         PREQ_TSEQ(0) = 0;
864         vap->iv_stats.is_hwmp_rootreqs++;
865         hwmp_send_preq(vap->iv_bss, vap->iv_myaddr, broadcastaddr, &preq,
866             NULL, NULL);        /* NB: we enforce rate check ourself */
867         hwmp_rootmode_setup(vap);
868 }
869 #undef  PREQ_TFLAGS
870 #undef  PREQ_TADDR
871 #undef  PREQ_TSEQ
872
873 /*
874  * Send a Root Annoucement (RANN) to find all the nodes on the mesh. We are
875  * called when the vap is configured as a HWMP RANN root node.
876  */
877 static void
878 hwmp_rootmode_rann_cb(void *arg)
879 {
880         struct ieee80211vap *vap = (struct ieee80211vap *)arg;
881         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
882         struct ieee80211_mesh_state *ms = vap->iv_mesh;
883         struct ieee80211_meshrann_ie rann;
884
885         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, vap->iv_bss,
886             "%s", "send broadcast RANN");
887
888         rann.rann_flags = 0;
889         if (ms->ms_flags & IEEE80211_MESHFLAGS_GATE)
890                 rann.rann_flags |= IEEE80211_MESHFLAGS_GATE;
891         rann.rann_hopcount = 0;
892         rann.rann_ttl = ms->ms_ttl;
893         IEEE80211_ADDR_COPY(rann.rann_addr, vap->iv_myaddr);
894         rann.rann_seq = ++hs->hs_seq;
895         rann.rann_interval = ieee80211_hwmp_rannint;
896         rann.rann_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
897
898         vap->iv_stats.is_hwmp_rootrann++;
899         hwmp_send_rann(vap->iv_bss, vap->iv_myaddr, broadcastaddr, &rann);
900         hwmp_rootmode_setup(vap);
901 }
902
903 #define PREQ_TFLAGS(n)  preq->preq_targets[n].target_flags
904 #define PREQ_TADDR(n)   preq->preq_targets[n].target_addr
905 #define PREQ_TSEQ(n)    preq->preq_targets[n].target_seq
906 static void
907 hwmp_recv_preq(struct ieee80211vap *vap, struct ieee80211_node *ni,
908     const struct ieee80211_frame *wh, const struct ieee80211_meshpreq_ie *preq)
909 {
910         struct ieee80211_mesh_state *ms = vap->iv_mesh;
911         struct ieee80211_mesh_route *rtorig = NULL;
912         struct ieee80211_mesh_route *rtorig_ext = NULL;
913         struct ieee80211_mesh_route *rttarg = NULL;
914         struct ieee80211_hwmp_route *hrorig = NULL;
915         struct ieee80211_hwmp_route *hrtarg = NULL;
916         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
917         struct ieee80211_meshprep_ie prep;
918         ieee80211_hwmp_seq preqid;      /* last seen preqid for orig */
919         uint32_t metric = 0;
920
921         /*
922          * Ignore PREQs from us. Could happen because someone forward it
923          * back to us.
924          */
925         if (IEEE80211_ADDR_EQ(vap->iv_myaddr, preq->preq_origaddr))
926                 return;
927
928         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
929             "received PREQ, orig %6D, targ(0) %6D", preq->preq_origaddr, ":",
930             PREQ_TADDR(0), ":");
931
932         /*
933          * Acceptance criteria: (if the PREQ is not for us or not broadcast,
934          * or an external mac address not proxied by us),
935          * AND forwarding is disabled, discard this PREQ.
936          */
937         rttarg = ieee80211_mesh_rt_find(vap, PREQ_TADDR(0));
938         if (!(ms->ms_flags & IEEE80211_MESHFLAGS_FWD) &&
939             (!IEEE80211_ADDR_EQ(vap->iv_myaddr, PREQ_TADDR(0)) ||
940             !IEEE80211_IS_MULTICAST(PREQ_TADDR(0)) ||
941             (rttarg != NULL &&
942             rttarg->rt_flags & IEEE80211_MESHRT_FLAGS_PROXY &&
943             IEEE80211_ADDR_EQ(vap->iv_myaddr, rttarg->rt_mesh_gate)))) {
944                 IEEE80211_DISCARD_MAC(vap, IEEE80211_MSG_HWMP,
945                     preq->preq_origaddr, NULL, "%s", "not accepting PREQ");
946                 return;
947         }
948         /*
949          * Acceptance criteria: if unicast addressed 
950          * AND no valid forwarding for Target of PREQ, discard this PREQ.
951          */
952         if(rttarg != NULL)
953                 hrtarg = IEEE80211_MESH_ROUTE_PRIV(rttarg,
954                     struct ieee80211_hwmp_route);
955         /* Address mode: ucast */
956         if(preq->preq_flags & IEEE80211_MESHPREQ_FLAGS_AM &&
957             rttarg == NULL &&
958             !IEEE80211_ADDR_EQ(vap->iv_myaddr, PREQ_TADDR(0))) {
959                 IEEE80211_DISCARD_MAC(vap, IEEE80211_MSG_HWMP,
960                     preq->preq_origaddr, NULL,
961                     "unicast addressed PREQ of unknown target %6D",
962                     PREQ_TADDR(0), ":");
963                 return;
964         }
965
966         /* PREQ ACCEPTED */
967
968         rtorig = ieee80211_mesh_rt_find(vap, preq->preq_origaddr);
969         if (rtorig == NULL) {
970                 rtorig = ieee80211_mesh_rt_add(vap, preq->preq_origaddr);
971                 if (rtorig == NULL) {
972                         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
973                             "unable to add orig path to %6D",
974                             preq->preq_origaddr, ":");
975                         vap->iv_stats.is_mesh_rtaddfailed++;
976                         return;
977                 }
978                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
979                     "adding originator %6D", preq->preq_origaddr, ":");
980         }
981         hrorig = IEEE80211_MESH_ROUTE_PRIV(rtorig, struct ieee80211_hwmp_route);
982
983         /* record last seen preqid */
984         preqid = hrorig->hr_preqid;
985         hrorig->hr_preqid = HWMP_SEQ_MAX(hrorig->hr_preqid, preq->preq_id);
986
987         /* Data creation and update of forwarding information
988          * according to Table 11C-8 for originator mesh STA.
989          */
990         metric = preq->preq_metric + ms->ms_pmetric->mpm_metric(ni);
991         if (HWMP_SEQ_GT(preq->preq_origseq, hrorig->hr_seq) ||
992             (HWMP_SEQ_EQ(preq->preq_origseq, hrorig->hr_seq) &&
993             metric < rtorig->rt_metric)) {
994                 hrorig->hr_seq = preq->preq_origseq;
995                 IEEE80211_ADDR_COPY(rtorig->rt_nexthop, wh->i_addr2);
996                 rtorig->rt_metric = metric;
997                 rtorig->rt_nhops  = preq->preq_hopcount + 1;
998                 ieee80211_mesh_rt_update(rtorig, preq->preq_lifetime);
999                 /* Path to orig is valid now.
1000                  * NB: we know it can't be Proxy, and if it is GATE
1001                  * it will be marked below.
1002                  */
1003                 rtorig->rt_flags = IEEE80211_MESHRT_FLAGS_VALID;
1004         }else if ((hrtarg != NULL &&
1005             HWMP_SEQ_EQ(hrtarg->hr_seq, PREQ_TSEQ(0)) &&
1006             ((rtorig->rt_flags & IEEE80211_MESHRT_FLAGS_VALID) == 0)) ||
1007             preqid >= preq->preq_id) {
1008                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1009                     "discard PREQ from %6D, old seqno %u <= %u,"
1010                     " or old preqid %u < %u",
1011                     preq->preq_origaddr, ":",
1012                     preq->preq_origseq, hrorig->hr_seq,
1013                     preq->preq_id, preqid);
1014                 return;
1015         }
1016
1017         /*
1018          * Forwarding information for transmitter mesh STA
1019          * [OPTIONAL: if metric improved]
1020          */
1021
1022         /*
1023          * Check if the PREQ is addressed to us.
1024          * or a Proxy currently supplied by us.
1025          */
1026         if (IEEE80211_ADDR_EQ(vap->iv_myaddr, PREQ_TADDR(0)) ||
1027             (rttarg != NULL &&
1028             rttarg->rt_flags & IEEE80211_MESHRT_FLAGS_PROXY &&
1029             rttarg->rt_flags & IEEE80211_MESHRT_FLAGS_VALID)) {
1030                 /*
1031                  * When we are the target we shall update our own HWMP seq
1032                  * number with max of (current and preq->seq) + 1
1033                  */
1034                 hs->hs_seq = HWMP_SEQ_MAX(hs->hs_seq, PREQ_TSEQ(0)) + 1;
1035
1036                 prep.prep_flags = 0;
1037                 prep.prep_hopcount = 0;
1038                 IEEE80211_ADDR_COPY(prep.prep_targetaddr, vap->iv_myaddr);
1039                 if (rttarg != NULL && /* if NULL it means we are the target */
1040                     rttarg->rt_flags & IEEE80211_MESHRT_FLAGS_PROXY) {
1041                         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1042                             "reply for proxy %6D", rttarg->rt_dest, ":");
1043                         prep.prep_flags |= IEEE80211_MESHPREP_FLAGS_AE;
1044                         IEEE80211_ADDR_COPY(prep.prep_target_ext_addr,
1045                             rttarg->rt_dest);
1046                         /* update proxy seqno to HWMP seqno */
1047                         rttarg->rt_ext_seq = hs->hs_seq;
1048                         prep.prep_hopcount = rttarg->rt_nhops;
1049                         IEEE80211_ADDR_COPY(prep.prep_targetaddr, rttarg->rt_mesh_gate);
1050                 }
1051                 /*
1052                  * Build and send a PREP frame.
1053                  */
1054                 prep.prep_ttl = ms->ms_ttl;
1055                 prep.prep_targetseq = hs->hs_seq;
1056                 prep.prep_lifetime = preq->preq_lifetime;
1057                 prep.prep_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
1058                 IEEE80211_ADDR_COPY(prep.prep_origaddr, preq->preq_origaddr);
1059                 prep.prep_origseq = preq->preq_origseq;
1060
1061                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1062                     "reply to %6D", preq->preq_origaddr, ":");
1063                 hwmp_send_prep(ni, vap->iv_myaddr, wh->i_addr2, &prep);
1064                 return;
1065         }
1066         /* we may update our proxy information for the orig external */
1067         else if (preq->preq_flags & IEEE80211_MESHPREQ_FLAGS_AE) {
1068                 rtorig_ext =
1069                     ieee80211_mesh_rt_find(vap, preq->preq_orig_ext_addr);
1070                 if (rtorig_ext == NULL) {
1071                         rtorig_ext = ieee80211_mesh_rt_add(vap,
1072                             preq->preq_orig_ext_addr);
1073                         if (rtorig_ext == NULL) {
1074                                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1075                                     "unable to add orig ext proxy to %6D",
1076                                     preq->preq_orig_ext_addr, ":");
1077                                 vap->iv_stats.is_mesh_rtaddfailed++;
1078                                 return;
1079                         }
1080                         IEEE80211_ADDR_COPY(rtorig_ext->rt_mesh_gate,
1081                             preq->preq_origaddr);
1082                 }
1083                 rtorig_ext->rt_ext_seq = preq->preq_origseq;
1084                 ieee80211_mesh_rt_update(rtorig_ext, preq->preq_lifetime);
1085         }
1086         /*
1087          * Proactive PREQ: reply with a proactive PREP to the
1088          * root STA if requested.
1089          */
1090         if (IEEE80211_ADDR_EQ(PREQ_TADDR(0), broadcastaddr) &&
1091             (PREQ_TFLAGS(0) & IEEE80211_MESHPREQ_TFLAGS_TO)) {
1092                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1093                     "root mesh station @ %6D", preq->preq_origaddr, ":");
1094
1095                 /*
1096                  * Reply with a PREP if we don't have a path to the root
1097                  * or if the root sent us a proactive PREQ.
1098                  */
1099                 if ((rtorig->rt_flags & IEEE80211_MESHRT_FLAGS_VALID) == 0 ||
1100                     (preq->preq_flags & IEEE80211_MESHPREQ_FLAGS_PP)) {
1101                         prep.prep_flags = 0;
1102                         prep.prep_hopcount = 0;
1103                         prep.prep_ttl = ms->ms_ttl;
1104                         IEEE80211_ADDR_COPY(prep.prep_origaddr,
1105                             preq->preq_origaddr);
1106                         prep.prep_origseq = preq->preq_origseq;
1107                         prep.prep_lifetime = preq->preq_lifetime;
1108                         prep.prep_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
1109                         IEEE80211_ADDR_COPY(prep.prep_targetaddr,
1110                             vap->iv_myaddr);
1111                         prep.prep_targetseq = ++hs->hs_seq;
1112                         hwmp_send_prep(vap->iv_bss, vap->iv_myaddr,
1113                             rtorig->rt_nexthop, &prep);
1114                 }
1115         }
1116
1117         /*
1118          * Forwarding and Intermediate reply for PREQs with 1 target.
1119          */
1120         if ((preq->preq_tcount == 1) && (preq->preq_ttl > 1) &&
1121             (ms->ms_flags & IEEE80211_MESHFLAGS_FWD)) {
1122                 struct ieee80211_meshpreq_ie ppreq; /* propagated PREQ */
1123
1124                 memcpy(&ppreq, preq, sizeof(ppreq));
1125
1126                 /*
1127                  * We have a valid route to this node.
1128                  */
1129                 if (rttarg != NULL &&
1130                     (rttarg->rt_flags & IEEE80211_MESHRT_FLAGS_VALID)) {
1131                         /*
1132                          * Check if we can send an intermediate Path Reply,
1133                          * i.e., Target Only bit is not set and target is not
1134                          * the MAC broadcast address.
1135                          */
1136                         if (!(PREQ_TFLAGS(0) & IEEE80211_MESHPREQ_TFLAGS_TO) &&
1137                             !IEEE80211_ADDR_EQ(PREQ_TADDR(0), broadcastaddr)) {
1138                                 struct ieee80211_meshprep_ie prep;
1139
1140                                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1141                                     "intermediate reply for PREQ from %6D",
1142                                     preq->preq_origaddr, ":");
1143                                 prep.prep_flags = 0;
1144                                 prep.prep_hopcount = rttarg->rt_nhops;
1145                                 prep.prep_ttl = ms->ms_ttl;
1146                                 IEEE80211_ADDR_COPY(&prep.prep_targetaddr,
1147                                     PREQ_TADDR(0));
1148                                 prep.prep_targetseq = hrtarg->hr_seq;
1149                                 prep.prep_lifetime = preq->preq_lifetime;
1150                                 prep.prep_metric =rttarg->rt_metric;
1151                                 IEEE80211_ADDR_COPY(&prep.prep_origaddr,
1152                                     preq->preq_origaddr);
1153                                 prep.prep_origseq = hrorig->hr_seq;
1154                                 hwmp_send_prep(ni, vap->iv_myaddr,
1155                                     rtorig->rt_nexthop, &prep);
1156
1157                                 /*
1158                                  * Set TO and unset RF bits because we have
1159                                  * sent a PREP.
1160                                  */
1161                                 ppreq.preq_targets[0].target_flags |=
1162                                     IEEE80211_MESHPREQ_TFLAGS_TO;
1163                         }
1164                 }
1165
1166                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1167                     "forward PREQ from %6D",
1168                     preq->preq_origaddr, ":");
1169                 ppreq.preq_hopcount += 1;
1170                 ppreq.preq_ttl -= 1;
1171                 ppreq.preq_metric += ms->ms_pmetric->mpm_metric(ni);
1172
1173                 /* don't do PREQ ratecheck when we propagate */
1174                 hwmp_send_preq(ni, vap->iv_myaddr, broadcastaddr,
1175                         &ppreq, NULL, NULL);
1176         }
1177 }
1178 #undef  PREQ_TFLAGS
1179 #undef  PREQ_TADDR
1180 #undef  PREQ_TSEQ
1181
1182 static int
1183 hwmp_send_preq(struct ieee80211_node *ni,
1184     const uint8_t sa[IEEE80211_ADDR_LEN],
1185     const uint8_t da[IEEE80211_ADDR_LEN],
1186     struct ieee80211_meshpreq_ie *preq,
1187     struct timeval *last, struct timeval *minint)
1188 {
1189
1190         /*
1191          * Enforce PREQ interval.
1192          * NB: Proactive ROOT PREQs rate is handled by cb task.
1193          */
1194         if (last != NULL && minint != NULL) {
1195                 if (ratecheck(last, minint) == 0)
1196                         return EALREADY; /* XXX: we should postpone */
1197                 getmicrouptime(last);
1198         }
1199
1200         /*
1201          * mesh preq action frame format
1202          *     [6] da
1203          *     [6] sa
1204          *     [6] addr3 = sa
1205          *     [1] action
1206          *     [1] category
1207          *     [tlv] mesh path request
1208          */
1209         preq->preq_ie = IEEE80211_ELEMID_MESHPREQ;
1210         preq->preq_len = (preq->preq_flags & IEEE80211_MESHPREQ_FLAGS_AE ?
1211             IEEE80211_MESHPREQ_BASE_SZ_AE : IEEE80211_MESHPREQ_BASE_SZ) +
1212             preq->preq_tcount * IEEE80211_MESHPREQ_TRGT_SZ;
1213         return hwmp_send_action(ni, sa, da, (uint8_t *)preq, preq->preq_len+2);
1214 }
1215
1216 static void
1217 hwmp_recv_prep(struct ieee80211vap *vap, struct ieee80211_node *ni,
1218     const struct ieee80211_frame *wh, const struct ieee80211_meshprep_ie *prep)
1219 {
1220 #define IS_PROXY(rt)    (rt->rt_flags & IEEE80211_MESHRT_FLAGS_PROXY)
1221 #define PROXIED_BY_US(rt)               \
1222     (IEEE80211_ADDR_EQ(vap->iv_myaddr, rt->rt_mesh_gate))
1223         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1224         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
1225         struct ieee80211_mesh_route *rt = NULL;
1226         struct ieee80211_mesh_route *rtorig = NULL;
1227         struct ieee80211_mesh_route *rtext = NULL;
1228         struct ieee80211_hwmp_route *hr;
1229         struct ieee80211com *ic = vap->iv_ic;
1230         struct ifnet *ifp = vap->iv_ifp;
1231         struct mbuf *m, *next;
1232         uint32_t metric = 0;
1233         const uint8_t *addr;
1234         int is_encap;
1235         struct ieee80211_node *ni_encap;
1236
1237         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1238             "received PREP, orig %6D, targ %6D", prep->prep_origaddr, ":",
1239             prep->prep_targetaddr, ":");
1240
1241         /*
1242          * Acceptance criteria: (If the corresponding PREP was not generated
1243          * by us OR not generated by an external mac that is not proxied by us)
1244          * AND forwarding is disabled, discard this PREP.
1245          */
1246         rtorig = ieee80211_mesh_rt_find(vap, prep->prep_origaddr);
1247         if ((!IEEE80211_ADDR_EQ(vap->iv_myaddr, prep->prep_origaddr) ||
1248             (rtorig != NULL && IS_PROXY(rtorig) && !PROXIED_BY_US(rtorig))) &&
1249             !(ms->ms_flags & IEEE80211_MESHFLAGS_FWD)){
1250                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1251                     "discard PREP, orig(%6D) not proxied or generated by us",
1252                     prep->prep_origaddr, ":");
1253                 return;
1254         }
1255
1256         /* PREP ACCEPTED */
1257
1258         /*
1259          * If accepted shall create or update the active forwarding information
1260          * it maintains for the target mesh STA of the PREP (according to the
1261          * rules defined in 13.10.8.4). If the conditions for creating or
1262          * updating the forwarding information have not been met in those
1263          * rules, no further steps are applied to the PREP.
1264          * [OPTIONAL]: update forwarding information to TA if metric improves.
1265          */
1266         rt = ieee80211_mesh_rt_find(vap, prep->prep_targetaddr);
1267         if (rt == NULL) {
1268                 rt = ieee80211_mesh_rt_add(vap, prep->prep_targetaddr);
1269                 if (rt == NULL) {
1270                         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1271                             "unable to add PREP path to %6D",
1272                             prep->prep_targetaddr, ":");
1273                         vap->iv_stats.is_mesh_rtaddfailed++;
1274                         return;
1275                 }
1276                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1277                     "adding target %6D", prep->prep_targetaddr, ":");
1278         }
1279         hr = IEEE80211_MESH_ROUTE_PRIV(rt, struct ieee80211_hwmp_route);
1280         /* update path metric */
1281         metric = prep->prep_metric + ms->ms_pmetric->mpm_metric(ni);
1282         if ((rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID)) {
1283                 if (HWMP_SEQ_LT(prep->prep_targetseq, hr->hr_seq)) {
1284                         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1285                             "discard PREP from %6D, old seq no %u < %u",
1286                             prep->prep_targetaddr, ":",
1287                             prep->prep_targetseq, hr->hr_seq);
1288                         return;
1289                 } else if (HWMP_SEQ_LEQ(prep->prep_targetseq, hr->hr_seq) &&
1290                     metric > rt->rt_metric) {
1291                         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1292                             "discard PREP from %6D, new metric %u > %u",
1293                             prep->prep_targetaddr, ":",
1294                             metric, rt->rt_metric);
1295                         return;
1296                 }
1297         }
1298
1299         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1300             "%s path to %6D, hopcount %d:%d metric %d:%d",
1301             rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID ?
1302             "prefer" : "update",
1303             prep->prep_targetaddr, ":",
1304             rt->rt_nhops, prep->prep_hopcount + 1,
1305             rt->rt_metric, metric);
1306
1307         hr->hr_seq = prep->prep_targetseq;
1308         hr->hr_preqretries = 0;
1309         IEEE80211_ADDR_COPY(rt->rt_nexthop, ni->ni_macaddr);
1310         rt->rt_metric = metric;
1311         rt->rt_nhops = prep->prep_hopcount + 1;
1312         ieee80211_mesh_rt_update(rt, prep->prep_lifetime);
1313         if (rt->rt_flags & IEEE80211_MESHRT_FLAGS_DISCOVER) {
1314                 /* discovery complete */
1315                 rt->rt_flags &= ~IEEE80211_MESHRT_FLAGS_DISCOVER;
1316         }
1317         rt->rt_flags |= IEEE80211_MESHRT_FLAGS_VALID; /* mark valid */
1318
1319         /*
1320          * If it's NOT for us, propagate the PREP
1321          */
1322         if (!IEEE80211_ADDR_EQ(vap->iv_myaddr, prep->prep_origaddr) &&
1323             prep->prep_ttl > 1 &&
1324             prep->prep_hopcount < hs->hs_maxhops) {
1325                 struct ieee80211_meshprep_ie pprep; /* propagated PREP */
1326                 /*
1327                  * NB: We should already have setup the path to orig
1328                  * mesh STA when we propagated PREQ to target mesh STA,
1329                  * no PREP is generated without a corresponding PREQ.
1330                  * XXX: for now just ignore.
1331                  */
1332                 if (rtorig == NULL) {
1333                         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1334                             "received PREP for an unknown orig(%6D)",
1335                             prep->prep_origaddr, ":");
1336                         return;
1337                 }
1338
1339                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1340                     "propagate PREP from %6D",
1341                     prep->prep_targetaddr, ":");
1342
1343                 memcpy(&pprep, prep, sizeof(pprep));
1344                 pprep.prep_hopcount += 1;
1345                 pprep.prep_ttl -= 1;
1346                 pprep.prep_metric += ms->ms_pmetric->mpm_metric(ni);
1347                 hwmp_send_prep(ni, vap->iv_myaddr, rtorig->rt_nexthop, &pprep);
1348
1349                 /* precursor list for the Target Mesh STA Address is updated */
1350         }
1351
1352         /*
1353          * Check if we received a PREP w/ AE and store target external address.
1354          * We may store target external address if recevied PREP w/ AE
1355          * and we are not final destination
1356          */
1357         if (prep->prep_flags & IEEE80211_MESHPREP_FLAGS_AE) {
1358                 rtext = ieee80211_mesh_rt_find(vap,
1359                         prep->prep_target_ext_addr);
1360                 if (rtext == NULL) {
1361                         rtext = ieee80211_mesh_rt_add(vap,
1362                                 prep->prep_target_ext_addr);
1363                         if (rtext == NULL) {
1364                                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1365                                     "unable to add PREP path to proxy %6D",
1366                                     prep->prep_targetaddr, ":");
1367                                 vap->iv_stats.is_mesh_rtaddfailed++;
1368                                 return;
1369                         }
1370                 }
1371                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1372                     "%s path to %6D, hopcount %d:%d metric %d:%d",
1373                     rtext->rt_flags & IEEE80211_MESHRT_FLAGS_VALID ?
1374                     "prefer" : "update",
1375                     prep->prep_target_ext_addr, ":",
1376                     rtext->rt_nhops, prep->prep_hopcount + 1,
1377                     rtext->rt_metric, metric);
1378
1379                 rtext->rt_flags = IEEE80211_MESHRT_FLAGS_PROXY |
1380                         IEEE80211_MESHRT_FLAGS_VALID;
1381                 IEEE80211_ADDR_COPY(rtext->rt_dest,
1382                     prep->prep_target_ext_addr);
1383                 IEEE80211_ADDR_COPY(rtext->rt_mesh_gate,
1384                     prep->prep_targetaddr);
1385                 IEEE80211_ADDR_COPY(rtext->rt_nexthop, wh->i_addr2);
1386                 rtext->rt_metric = metric;
1387                 rtext->rt_lifetime = prep->prep_lifetime;
1388                 rtext->rt_nhops = prep->prep_hopcount + 1;
1389                 rtext->rt_ext_seq = prep->prep_origseq; /* new proxy seq */
1390                 /*
1391                  * XXX: proxy entries have no HWMP priv data,
1392                  * nullify them to be sure?
1393                  */
1394         }
1395         /*
1396          * Check for frames queued awaiting path discovery.
1397          * XXX probably can tell exactly and avoid remove call
1398          * NB: hash may have false matches, if so they will get
1399          *     stuck back on the stageq because there won't be
1400          *     a path.
1401          */
1402         addr = prep->prep_flags & IEEE80211_MESHPREP_FLAGS_AE ?
1403             prep->prep_target_ext_addr : prep->prep_targetaddr;
1404         m = ieee80211_ageq_remove(&ic->ic_stageq,
1405             (struct ieee80211_node *)(uintptr_t)
1406             ieee80211_mac_hash(ic, addr)); /* either dest or ext_dest */
1407         for (; m != NULL; m = next) {
1408                 is_encap = !! (m->m_flags & M_ENCAP);
1409                 ni_encap = (struct ieee80211_node *) m->m_pkthdr.rcvif;
1410                 next = m->m_nextpkt;
1411                 m->m_nextpkt = NULL;
1412                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1413                     "flush queued frame %p len %d", m, m->m_pkthdr.len);
1414
1415                 /*
1416                  * If the mbuf has M_ENCAP set, ensure we free it.
1417                  * Note that after if_transmit() is called, m is invalid.
1418                  */
1419                 if (ifp->if_transmit(ifp, m) != 0) {
1420                         if (is_encap)
1421                                 ieee80211_free_node(ni_encap);
1422                 }
1423         }
1424 #undef  IS_PROXY
1425 #undef  PROXIED_BY_US
1426 }
1427
1428 static int
1429 hwmp_send_prep(struct ieee80211_node *ni,
1430     const uint8_t sa[IEEE80211_ADDR_LEN],
1431     const uint8_t da[IEEE80211_ADDR_LEN],
1432     struct ieee80211_meshprep_ie *prep)
1433 {
1434         /* NB: there's no PREP minimum interval. */
1435
1436         /*
1437          * mesh prep action frame format
1438          *     [6] da
1439          *     [6] sa
1440          *     [6] addr3 = sa
1441          *     [1] action
1442          *     [1] category
1443          *     [tlv] mesh path reply
1444          */
1445         prep->prep_ie = IEEE80211_ELEMID_MESHPREP;
1446         prep->prep_len = prep->prep_flags & IEEE80211_MESHPREP_FLAGS_AE ?
1447             IEEE80211_MESHPREP_BASE_SZ_AE : IEEE80211_MESHPREP_BASE_SZ;
1448         return hwmp_send_action(ni, sa, da, (uint8_t *)prep,
1449             prep->prep_len + 2);
1450 }
1451
1452 #define PERR_DFLAGS(n)  perr.perr_dests[n].dest_flags
1453 #define PERR_DADDR(n)   perr.perr_dests[n].dest_addr
1454 #define PERR_DSEQ(n)    perr.perr_dests[n].dest_seq
1455 #define PERR_DRCODE(n)  perr.perr_dests[n].dest_rcode
1456 static void
1457 hwmp_peerdown(struct ieee80211_node *ni)
1458 {
1459         struct ieee80211vap *vap = ni->ni_vap;
1460         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1461         struct ieee80211_meshperr_ie perr;
1462         struct ieee80211_mesh_route *rt;
1463         struct ieee80211_hwmp_route *hr;
1464
1465         rt = ieee80211_mesh_rt_find(vap, ni->ni_macaddr);
1466         if (rt == NULL)
1467                 return;
1468         hr = IEEE80211_MESH_ROUTE_PRIV(rt, struct ieee80211_hwmp_route);
1469         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1470             "%s", "delete route entry");
1471         perr.perr_ttl = ms->ms_ttl;
1472         perr.perr_ndests = 1;
1473         PERR_DFLAGS(0) = 0;
1474         if (hr->hr_seq == 0)
1475                 PERR_DFLAGS(0) |= IEEE80211_MESHPERR_DFLAGS_USN;
1476         PERR_DFLAGS(0) |= IEEE80211_MESHPERR_DFLAGS_RC;
1477         IEEE80211_ADDR_COPY(PERR_DADDR(0), rt->rt_dest);
1478         PERR_DSEQ(0) = ++hr->hr_seq;
1479         PERR_DRCODE(0) = IEEE80211_REASON_MESH_PERR_DEST_UNREACH;
1480         /* NB: flush everything passing through peer */
1481         ieee80211_mesh_rt_flush_peer(vap, ni->ni_macaddr);
1482         hwmp_send_perr(vap->iv_bss, vap->iv_myaddr, broadcastaddr, &perr);
1483 }
1484 #undef  PERR_DFLAGS
1485 #undef  PERR_DADDR
1486 #undef  PERR_DSEQ
1487 #undef  PERR_DRCODE
1488
1489 #define PERR_DFLAGS(n)          perr->perr_dests[n].dest_flags
1490 #define PERR_DADDR(n)           perr->perr_dests[n].dest_addr
1491 #define PERR_DSEQ(n)            perr->perr_dests[n].dest_seq
1492 #define PERR_DEXTADDR(n)        perr->perr_dests[n].dest_ext_addr
1493 #define PERR_DRCODE(n)          perr->perr_dests[n].dest_rcode
1494 static void
1495 hwmp_recv_perr(struct ieee80211vap *vap, struct ieee80211_node *ni,
1496     const struct ieee80211_frame *wh, const struct ieee80211_meshperr_ie *perr)
1497 {
1498         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1499         struct ieee80211_mesh_route *rt = NULL;
1500         struct ieee80211_mesh_route *rt_ext = NULL;
1501         struct ieee80211_hwmp_route *hr;
1502         struct ieee80211_meshperr_ie *pperr = NULL;
1503         int i, j = 0, forward = 0;
1504
1505         IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1506             "received PERR from %6D", wh->i_addr2, ":");
1507
1508         /*
1509          * if forwarding is true, prepare pperr
1510          */
1511         if (ms->ms_flags & IEEE80211_MESHFLAGS_FWD) {
1512                 forward = 1;
1513                 pperr = malloc(sizeof(*perr) + 31*sizeof(*perr->perr_dests),
1514                     M_80211_MESH_PERR, M_NOWAIT); /* XXX: magic number, 32 err dests */
1515         }
1516
1517         /*
1518          * Acceptance criteria: check if we have forwarding information
1519          * stored about destination, and that nexthop == TA of this PERR.
1520          * NB: we also build a new PERR to propagate in case we should forward.
1521          */
1522         for (i = 0; i < perr->perr_ndests; i++) {
1523                 rt = ieee80211_mesh_rt_find(vap, PERR_DADDR(i));
1524                 if (rt == NULL)
1525                         continue;
1526                 if (!IEEE80211_ADDR_EQ(rt->rt_nexthop, wh->i_addr2))
1527                         continue;
1528
1529                 /* found and accepted a PERR ndest element, process it... */
1530                 if (forward)
1531                         memcpy(&pperr->perr_dests[j], &perr->perr_dests[i],
1532                             sizeof(*perr->perr_dests));
1533                 hr = IEEE80211_MESH_ROUTE_PRIV(rt, struct ieee80211_hwmp_route);
1534                 switch(PERR_DFLAGS(i)) {
1535                 case (IEEE80211_REASON_MESH_PERR_NO_FI):
1536                         if (PERR_DSEQ(i) == 0) {
1537                                 hr->hr_seq++;
1538                                 if (forward) {
1539                                         pperr->perr_dests[j].dest_seq =
1540                                             hr->hr_seq;
1541                                 }
1542                         } else {
1543                                 hr->hr_seq = PERR_DSEQ(i);
1544                         }
1545                         rt->rt_flags &= ~IEEE80211_MESHRT_FLAGS_VALID;
1546                         j++;
1547                         break;
1548                 case (IEEE80211_REASON_MESH_PERR_DEST_UNREACH):
1549                         if(HWMP_SEQ_GT(PERR_DSEQ(i), hr->hr_seq)) {
1550                                 hr->hr_seq = PERR_DSEQ(i);
1551                                 rt->rt_flags &= ~IEEE80211_MESHRT_FLAGS_VALID;
1552                                 j++;
1553                         }
1554                         break;
1555                 case (IEEE80211_REASON_MESH_PERR_NO_PROXY):
1556                         rt_ext = ieee80211_mesh_rt_find(vap, PERR_DEXTADDR(i));
1557                         if (rt_ext != NULL) {
1558                                 rt_ext->rt_flags &=
1559                                     ~IEEE80211_MESHRT_FLAGS_VALID;
1560                                 j++;
1561                         }
1562                         break;
1563                 default:
1564                         IEEE80211_DISCARD(vap, IEEE80211_MSG_HWMP, wh, NULL,
1565                             "PERR, unknown reason code %u\n", PERR_DFLAGS(i));
1566                         goto done; /* XXX: stats?? */
1567                 }
1568                 ieee80211_mesh_rt_flush_peer(vap, rt->rt_dest);
1569                 KASSERT(j < 32, ("PERR, error ndest >= 32 (%u)", j));
1570         }
1571         if (j == 0) {
1572                 IEEE80211_DISCARD(vap, IEEE80211_MSG_HWMP, wh, NULL, "%s",
1573                     "PERR not accepted");
1574                 goto done; /* XXX: stats?? */
1575         }
1576
1577         /*
1578          * Propagate the PERR if we previously found it on our routing table.
1579          */
1580         if (forward && perr->perr_ttl > 1) {
1581                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP, ni,
1582                     "propagate PERR from %6D", wh->i_addr2, ":");
1583                 pperr->perr_ndests = j;
1584                 pperr->perr_ttl--;
1585                 hwmp_send_perr(vap->iv_bss, vap->iv_myaddr, broadcastaddr,
1586                     pperr);
1587         }
1588 done:
1589         if (pperr != NULL)
1590                 free(pperr, M_80211_MESH_PERR);
1591 }
1592 #undef  PERR_DFLAGS
1593 #undef  PERR_DADDR
1594 #undef  PERR_DSEQ
1595 #undef  PERR_DEXTADDR
1596 #undef  PERR_DRCODE
1597
1598 static int
1599 hwmp_send_perr(struct ieee80211_node *ni,
1600     const uint8_t sa[IEEE80211_ADDR_LEN],
1601     const uint8_t da[IEEE80211_ADDR_LEN],
1602     struct ieee80211_meshperr_ie *perr)
1603 {
1604         struct ieee80211_hwmp_state *hs = ni->ni_vap->iv_hwmp;
1605         int i;
1606         uint8_t length = 0;
1607
1608         /*
1609          * Enforce PERR interval.
1610          */
1611         if (ratecheck(&hs->hs_lastperr, &ieee80211_hwmp_perrminint) == 0)
1612                 return EALREADY;
1613         getmicrouptime(&hs->hs_lastperr);
1614
1615         /*
1616          * mesh perr action frame format
1617          *     [6] da
1618          *     [6] sa
1619          *     [6] addr3 = sa
1620          *     [1] action
1621          *     [1] category
1622          *     [tlv] mesh path error
1623          */
1624         perr->perr_ie = IEEE80211_ELEMID_MESHPERR;
1625         length = IEEE80211_MESHPERR_BASE_SZ;
1626         for (i = 0; i<perr->perr_ndests; i++) {
1627                 if (perr->perr_dests[i].dest_flags &
1628                     IEEE80211_MESHPERR_FLAGS_AE) {
1629                         length += IEEE80211_MESHPERR_DEST_SZ_AE;
1630                         continue ;
1631                 }
1632                 length += IEEE80211_MESHPERR_DEST_SZ;
1633         }
1634         perr->perr_len =length;
1635         return hwmp_send_action(ni, sa, da, (uint8_t *)perr, perr->perr_len+2);
1636 }
1637
1638 /*
1639  * Called from the rest of the net80211 code (mesh code for example).
1640  * NB: IEEE80211_REASON_MESH_PERR_DEST_UNREACH can be trigger by the fact that
1641  * a mesh STA is unable to forward an MSDU/MMPDU to a next-hop mesh STA.
1642  */
1643 #define PERR_DFLAGS(n)          perr.perr_dests[n].dest_flags
1644 #define PERR_DADDR(n)           perr.perr_dests[n].dest_addr
1645 #define PERR_DSEQ(n)            perr.perr_dests[n].dest_seq
1646 #define PERR_DEXTADDR(n)        perr.perr_dests[n].dest_ext_addr
1647 #define PERR_DRCODE(n)          perr.perr_dests[n].dest_rcode
1648 static void
1649 hwmp_senderror(struct ieee80211vap *vap,
1650     const uint8_t addr[IEEE80211_ADDR_LEN],
1651     struct ieee80211_mesh_route *rt, int rcode)
1652 {
1653         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1654         struct ieee80211_hwmp_route *hr = NULL;
1655         struct ieee80211_meshperr_ie perr;
1656
1657         if (rt != NULL)
1658                 hr = IEEE80211_MESH_ROUTE_PRIV(rt,
1659                     struct ieee80211_hwmp_route);
1660
1661         perr.perr_ndests = 1;
1662         perr.perr_ttl = ms->ms_ttl;
1663         PERR_DFLAGS(0) = 0;
1664         PERR_DRCODE(0) = rcode;
1665
1666         switch (rcode) {
1667         case IEEE80211_REASON_MESH_PERR_NO_FI:
1668                 IEEE80211_ADDR_COPY(PERR_DADDR(0), addr);
1669                 PERR_DSEQ(0) = 0; /* reserved */
1670                 break;
1671         case IEEE80211_REASON_MESH_PERR_NO_PROXY:
1672                 KASSERT(rt != NULL, ("no proxy info for sending PERR"));
1673                 KASSERT(rt->rt_flags & IEEE80211_MESHRT_FLAGS_PROXY,
1674                     ("route is not marked proxy"));
1675                 PERR_DFLAGS(0) |= IEEE80211_MESHPERR_FLAGS_AE;
1676                 IEEE80211_ADDR_COPY(PERR_DADDR(0), vap->iv_myaddr);
1677                 PERR_DSEQ(0) = rt->rt_ext_seq;
1678                 IEEE80211_ADDR_COPY(PERR_DEXTADDR(0), addr);
1679                 break;
1680         case IEEE80211_REASON_MESH_PERR_DEST_UNREACH:
1681                 KASSERT(rt != NULL, ("no route info for sending PERR"));
1682                 IEEE80211_ADDR_COPY(PERR_DADDR(0), addr);
1683                 PERR_DSEQ(0) = hr->hr_seq;
1684                 break;
1685         default:
1686                 KASSERT(0, ("unknown reason code for HWMP PERR (%u)", rcode));
1687         }
1688         hwmp_send_perr(vap->iv_bss, vap->iv_myaddr, broadcastaddr, &perr);
1689 }
1690 #undef  PERR_DFLAGS
1691 #undef  PEER_DADDR
1692 #undef  PERR_DSEQ
1693 #undef  PERR_DEXTADDR
1694 #undef  PERR_DRCODE
1695
1696 static void
1697 hwmp_recv_rann(struct ieee80211vap *vap, struct ieee80211_node *ni,
1698     const struct ieee80211_frame *wh, const struct ieee80211_meshrann_ie *rann)
1699 {
1700         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1701         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
1702         struct ieee80211_mesh_route *rt = NULL;
1703         struct ieee80211_hwmp_route *hr;
1704         struct ieee80211_meshpreq_ie preq;
1705         struct ieee80211_meshrann_ie prann;
1706         uint32_t metric = 0;
1707
1708         if (IEEE80211_ADDR_EQ(rann->rann_addr, vap->iv_myaddr))
1709                 return;
1710
1711         rt = ieee80211_mesh_rt_find(vap, rann->rann_addr);
1712         if (rt != NULL && rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID) {
1713                 hr = IEEE80211_MESH_ROUTE_PRIV(rt, struct ieee80211_hwmp_route);
1714
1715                 /* Acceptance criteria: if RANN.seq < stored seq, discard RANN */
1716                 if (HWMP_SEQ_LT(rann->rann_seq, hr->hr_seq)) {
1717                         IEEE80211_DISCARD(vap, IEEE80211_MSG_HWMP, wh, NULL,
1718                         "RANN seq %u < %u", rann->rann_seq, hr->hr_seq);
1719                         return;
1720                 }
1721
1722                 /* Acceptance criteria: if RANN.seq == stored seq AND
1723                 * RANN.metric > stored metric, discard RANN */
1724                 if (HWMP_SEQ_EQ(rann->rann_seq, hr->hr_seq) &&
1725                 rann->rann_metric > rt->rt_metric) {
1726                         IEEE80211_DISCARD(vap, IEEE80211_MSG_HWMP, wh, NULL,
1727                         "RANN metric %u > %u", rann->rann_metric, rt->rt_metric);
1728                         return;
1729                 }
1730         }
1731
1732         /* RANN ACCEPTED */
1733
1734         ieee80211_hwmp_rannint = rann->rann_interval; /* XXX: mtx lock? */
1735         metric = rann->rann_metric + ms->ms_pmetric->mpm_metric(ni);
1736
1737         if (rt == NULL) {
1738                 rt = ieee80211_mesh_rt_add(vap, rann->rann_addr);
1739                 if (rt == NULL) {
1740                         IEEE80211_DISCARD(vap, IEEE80211_MSG_HWMP, wh, NULL,
1741                             "unable to add mac for RANN root %6D",
1742                             rann->rann_addr, ":");
1743                             vap->iv_stats.is_mesh_rtaddfailed++;
1744                         return;
1745                 }
1746         }
1747         hr = IEEE80211_MESH_ROUTE_PRIV(rt, struct ieee80211_hwmp_route);
1748         /* discovery timeout */
1749         ieee80211_mesh_rt_update(rt,
1750             ticks_to_msecs(ieee80211_hwmp_roottimeout));
1751
1752         preq.preq_flags = IEEE80211_MESHPREQ_FLAGS_AM;
1753         preq.preq_hopcount = 0;
1754         preq.preq_ttl = ms->ms_ttl;
1755         preq.preq_id = 0; /* reserved */
1756         IEEE80211_ADDR_COPY(preq.preq_origaddr, vap->iv_myaddr);
1757         preq.preq_origseq = ++hs->hs_seq;
1758         preq.preq_lifetime = ieee80211_hwmp_roottimeout;
1759         preq.preq_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
1760         preq.preq_tcount = 1;
1761         preq.preq_targets[0].target_flags = IEEE80211_MESHPREQ_TFLAGS_TO;
1762         /* NB: IEEE80211_MESHPREQ_TFLAGS_USN = 0 implicitly implied */
1763         IEEE80211_ADDR_COPY(preq.preq_targets[0].target_addr, rann->rann_addr);
1764         preq.preq_targets[0].target_seq = rann->rann_seq;
1765         /* XXX: if rootconfint have not passed, we built this preq in vain */
1766         hwmp_send_preq(vap->iv_bss, vap->iv_myaddr, wh->i_addr2, &preq,
1767             &hr->hr_lastrootconf, &ieee80211_hwmp_rootconfint);
1768
1769         /* propagate a RANN */
1770         if (rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID &&
1771             rann->rann_ttl > 1 &&
1772             ms->ms_flags & IEEE80211_MESHFLAGS_FWD) {
1773                 hr->hr_seq = rann->rann_seq;
1774                 memcpy(&prann, rann, sizeof(prann));
1775                 prann.rann_hopcount += 1;
1776                 prann.rann_ttl -= 1;
1777                 prann.rann_metric += ms->ms_pmetric->mpm_metric(ni);
1778                 hwmp_send_rann(vap->iv_bss, vap->iv_myaddr,
1779                     broadcastaddr, &prann);
1780         }
1781 }
1782
1783 static int
1784 hwmp_send_rann(struct ieee80211_node *ni,
1785     const uint8_t sa[IEEE80211_ADDR_LEN],
1786     const uint8_t da[IEEE80211_ADDR_LEN],
1787     struct ieee80211_meshrann_ie *rann)
1788 {
1789         /*
1790          * mesh rann action frame format
1791          *     [6] da
1792          *     [6] sa
1793          *     [6] addr3 = sa
1794          *     [1] action
1795          *     [1] category
1796          *     [tlv] root annoucement
1797          */
1798         rann->rann_ie = IEEE80211_ELEMID_MESHRANN;
1799         rann->rann_len = IEEE80211_MESHRANN_BASE_SZ;
1800         return hwmp_send_action(ni, sa, da, (uint8_t *)rann,
1801             rann->rann_len + 2);
1802 }
1803
1804 #define PREQ_TFLAGS(n)  preq.preq_targets[n].target_flags
1805 #define PREQ_TADDR(n)   preq.preq_targets[n].target_addr
1806 #define PREQ_TSEQ(n)    preq.preq_targets[n].target_seq
1807 static void
1808 hwmp_rediscover_cb(void *arg)
1809 {
1810         struct ieee80211_mesh_route *rt = arg;
1811         struct ieee80211vap *vap = rt->rt_vap;
1812         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
1813         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1814         struct ieee80211_hwmp_route *hr;
1815         struct ieee80211_meshpreq_ie preq; /* Optimize: storing first preq? */
1816
1817         if ((rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID))
1818                 return ; /* nothing to do */
1819
1820         hr = IEEE80211_MESH_ROUTE_PRIV(rt, struct ieee80211_hwmp_route);
1821         if (hr->hr_preqretries >=
1822                 ieee80211_hwmp_maxpreq_retries) {
1823                 IEEE80211_DISCARD_MAC(vap, IEEE80211_MSG_ANY,
1824                         rt->rt_dest, NULL, "%s",
1825                         "no valid path , max number of discovery, send GATE");
1826                 /* TODO: send to known gates */
1827                 vap->iv_stats.is_mesh_fwd_nopath++;
1828                 rt->rt_flags = 0; /* Mark invalid */
1829                 return ; /* XXX: flush queue? */
1830         }
1831
1832         hr->hr_preqretries++;
1833
1834
1835         IEEE80211_NOTE_MAC(vap, IEEE80211_MSG_HWMP, rt->rt_dest,
1836             "start path rediscovery , target seq %u", hr->hr_seq);
1837         /*
1838          * Try to discover the path for this node.
1839          * Group addressed PREQ Case A
1840          */
1841         preq.preq_flags = 0;
1842         preq.preq_hopcount = 0;
1843         preq.preq_ttl = ms->ms_ttl;
1844         preq.preq_id = ++hs->hs_preqid;
1845         IEEE80211_ADDR_COPY(preq.preq_origaddr, vap->iv_myaddr);
1846         preq.preq_origseq = hr->hr_origseq;
1847         preq.preq_lifetime = ticks_to_msecs(ieee80211_hwmp_pathtimeout);
1848         preq.preq_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
1849         preq.preq_tcount = 1;
1850         IEEE80211_ADDR_COPY(PREQ_TADDR(0), rt->rt_dest);
1851         PREQ_TFLAGS(0) = 0;
1852         if (ieee80211_hwmp_targetonly)
1853                 PREQ_TFLAGS(0) |= IEEE80211_MESHPREQ_TFLAGS_TO;
1854         PREQ_TFLAGS(0) |= IEEE80211_MESHPREQ_TFLAGS_USN;
1855         PREQ_TSEQ(0) = 0; /* RESERVED when USN flag is set */
1856         /* XXX check return value */
1857         hwmp_send_preq(vap->iv_bss, vap->iv_myaddr,
1858                 broadcastaddr, &preq, &hr->hr_lastpreq,
1859                 &ieee80211_hwmp_preqminint);
1860         callout_reset(&rt->rt_discovery,
1861                 ieee80211_hwmp_net_diameter_traversaltime * 2,
1862                 hwmp_rediscover_cb, rt);
1863 }
1864
1865 static struct ieee80211_node *
1866 hwmp_discover(struct ieee80211vap *vap,
1867     const uint8_t dest[IEEE80211_ADDR_LEN], struct mbuf *m)
1868 {
1869         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
1870         struct ieee80211_mesh_state *ms = vap->iv_mesh;
1871         struct ieee80211_mesh_route *rt = NULL;
1872         struct ieee80211_hwmp_route *hr;
1873         struct ieee80211_meshpreq_ie preq;
1874         struct ieee80211_node *ni;
1875         int sendpreq = 0;
1876
1877         KASSERT(vap->iv_opmode == IEEE80211_M_MBSS,
1878             ("not a mesh vap, opmode %d", vap->iv_opmode));
1879
1880         KASSERT(!IEEE80211_ADDR_EQ(vap->iv_myaddr, dest),
1881             ("%s: discovering self!", __func__));
1882
1883         ni = NULL;
1884         if (!IEEE80211_IS_MULTICAST(dest)) {
1885                 rt = ieee80211_mesh_rt_find(vap, dest);
1886                 if (rt == NULL) {
1887                         rt = ieee80211_mesh_rt_add(vap, dest);
1888                         if (rt == NULL) {
1889                                 IEEE80211_NOTE(vap, IEEE80211_MSG_HWMP,
1890                                     ni, "unable to add discovery path to %6D",
1891                                     dest, ":");
1892                                 vap->iv_stats.is_mesh_rtaddfailed++;
1893                                 goto done;
1894                         }
1895                 }
1896                 hr = IEEE80211_MESH_ROUTE_PRIV(rt,
1897                     struct ieee80211_hwmp_route);
1898                 if ((rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID) == 0) {
1899                         if (hr->hr_lastdiscovery != 0 &&
1900                             (ticks - hr->hr_lastdiscovery <
1901                             (ieee80211_hwmp_net_diameter_traversaltime * 2))) {
1902                                 IEEE80211_DISCARD_MAC(vap, IEEE80211_MSG_ANY,
1903                                     dest, NULL, "%s",
1904                                     "too frequent discovery requeust");
1905                                 /* XXX: stats? */
1906                                 goto done;
1907                         }
1908                         hr->hr_lastdiscovery = ticks;
1909                         if (hr->hr_preqretries >=
1910                             ieee80211_hwmp_maxpreq_retries) {
1911                                 IEEE80211_DISCARD_MAC(vap, IEEE80211_MSG_ANY,
1912                                     dest, NULL, "%s",
1913                                     "no valid path , max number of discovery");
1914                                 vap->iv_stats.is_mesh_fwd_nopath++;
1915                                 goto done;
1916                         }
1917                         rt->rt_flags = IEEE80211_MESHRT_FLAGS_DISCOVER;
1918                         hr->hr_preqretries++;
1919                         if (hr->hr_origseq == 0)
1920                                 hr->hr_origseq = ++hs->hs_seq;
1921                         rt->rt_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
1922                         sendpreq = 1;
1923                         IEEE80211_NOTE_MAC(vap, IEEE80211_MSG_HWMP, dest,
1924                             "start path discovery (src %s), target seq %u",
1925                             m == NULL ? "<none>" : ether_sprintf(
1926                             mtod(m, struct ether_header *)->ether_shost),
1927                             hr->hr_seq);
1928                         /*
1929                          * Try to discover the path for this node.
1930                          * Group addressed PREQ Case A
1931                          */
1932                         preq.preq_flags = 0;
1933                         preq.preq_hopcount = 0;
1934                         preq.preq_ttl = ms->ms_ttl;
1935                         preq.preq_id = ++hs->hs_preqid;
1936                         IEEE80211_ADDR_COPY(preq.preq_origaddr, vap->iv_myaddr);
1937                         preq.preq_origseq = hr->hr_origseq;
1938                         preq.preq_lifetime =
1939                             ticks_to_msecs(ieee80211_hwmp_pathtimeout);
1940                         preq.preq_metric = IEEE80211_MESHLMETRIC_INITIALVAL;
1941                         preq.preq_tcount = 1;
1942                         IEEE80211_ADDR_COPY(PREQ_TADDR(0), dest);
1943                         PREQ_TFLAGS(0) = 0;
1944                         if (ieee80211_hwmp_targetonly)
1945                                 PREQ_TFLAGS(0) |= IEEE80211_MESHPREQ_TFLAGS_TO;
1946                         PREQ_TFLAGS(0) |= IEEE80211_MESHPREQ_TFLAGS_USN;
1947                         PREQ_TSEQ(0) = 0; /* RESERVED when USN flag is set */
1948                         /* XXX check return value */
1949                         hwmp_send_preq(vap->iv_bss, vap->iv_myaddr,
1950                             broadcastaddr, &preq, &hr->hr_lastpreq,
1951                             &ieee80211_hwmp_preqminint);
1952                         callout_reset(&rt->rt_discovery,
1953                             ieee80211_hwmp_net_diameter_traversaltime * 2,
1954                             hwmp_rediscover_cb, rt);
1955                 }
1956                 if (rt->rt_flags & IEEE80211_MESHRT_FLAGS_VALID)
1957                         ni = ieee80211_find_txnode(vap, rt->rt_nexthop);
1958         } else {
1959                 ni = ieee80211_find_txnode(vap, dest);
1960                 /* NB: if null then we leak mbuf */
1961                 KASSERT(ni != NULL, ("leak mcast frame"));
1962                 return ni;
1963         }
1964 done:
1965         if (ni == NULL && m != NULL) {
1966                 if (sendpreq) {
1967                         struct ieee80211com *ic = vap->iv_ic;
1968                         /*
1969                          * Queue packet for transmit when path discovery
1970                          * completes.  If discovery never completes the
1971                          * frame will be flushed by way of the aging timer.
1972                          */
1973                         IEEE80211_NOTE_MAC(vap, IEEE80211_MSG_HWMP, dest,
1974                             "%s", "queue frame until path found");
1975                         m->m_pkthdr.rcvif = (void *)(uintptr_t)
1976                             ieee80211_mac_hash(ic, dest);
1977                         /* XXX age chosen randomly */
1978                         ieee80211_ageq_append(&ic->ic_stageq, m,
1979                             IEEE80211_INACT_WAIT);
1980                 } else {
1981                         IEEE80211_DISCARD_MAC(vap, IEEE80211_MSG_HWMP,
1982                             dest, NULL, "%s", "no valid path to this node");
1983                         m_freem(m);
1984                 }
1985         }
1986         return ni;
1987 }
1988 #undef  PREQ_TFLAGS
1989 #undef  PREQ_TADDR
1990 #undef  PREQ_TSEQ
1991
1992 static int
1993 hwmp_ioctl_get80211(struct ieee80211vap *vap, struct ieee80211req *ireq)
1994 {
1995         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
1996         int error;
1997
1998         if (vap->iv_opmode != IEEE80211_M_MBSS)
1999                 return ENOSYS;
2000         error = 0;
2001         switch (ireq->i_type) {
2002         case IEEE80211_IOC_HWMP_ROOTMODE:
2003                 ireq->i_val = hs->hs_rootmode;
2004                 break;
2005         case IEEE80211_IOC_HWMP_MAXHOPS:
2006                 ireq->i_val = hs->hs_maxhops;
2007                 break;
2008         default:
2009                 return ENOSYS;
2010         }
2011         return error;
2012 }
2013 IEEE80211_IOCTL_GET(hwmp, hwmp_ioctl_get80211);
2014
2015 static int
2016 hwmp_ioctl_set80211(struct ieee80211vap *vap, struct ieee80211req *ireq)
2017 {
2018         struct ieee80211_hwmp_state *hs = vap->iv_hwmp;
2019         int error;
2020
2021         if (vap->iv_opmode != IEEE80211_M_MBSS)
2022                 return ENOSYS;
2023         error = 0;
2024         switch (ireq->i_type) {
2025         case IEEE80211_IOC_HWMP_ROOTMODE:
2026                 if (ireq->i_val < 0 || ireq->i_val > 3)
2027                         return EINVAL;
2028                 hs->hs_rootmode = ireq->i_val;
2029                 hwmp_rootmode_setup(vap);
2030                 break;
2031         case IEEE80211_IOC_HWMP_MAXHOPS:
2032                 if (ireq->i_val <= 0 || ireq->i_val > 255)
2033                         return EINVAL;
2034                 hs->hs_maxhops = ireq->i_val;
2035                 break;
2036         default:
2037                 return ENOSYS;
2038         }
2039         return error;
2040 }
2041 IEEE80211_IOCTL_SET(hwmp, hwmp_ioctl_set80211);