1 /*
2 * BSS list
3 * Copyright (c) 2010, Jouni Malinen <j@w1.fi>
4 *
5 * This software may be distributed under the terms of the BSD license.
6 * See README for more details.
7 */
8
9 #include "utils/includes.h"
10
11 #include "utils/common.h"
12 #include "common/defs.h"
13 #include "common/ieee802_11_defs.h"
14 #include "common/ieee802_11_common.h"
15 #include "crypto/sha1.h"
16 #include "wlantest.h"
17
18
bss_find(struct wlantest * wt,const u8 * bssid)19 struct wlantest_bss * bss_find(struct wlantest *wt, const u8 *bssid)
20 {
21 struct wlantest_bss *bss;
22
23 dl_list_for_each(bss, &wt->bss, struct wlantest_bss, list) {
24 if (os_memcmp(bss->bssid, bssid, ETH_ALEN) == 0)
25 return bss;
26 }
27
28 return NULL;
29 }
30
31
bss_get(struct wlantest * wt,const u8 * bssid)32 struct wlantest_bss * bss_get(struct wlantest *wt, const u8 *bssid)
33 {
34 struct wlantest_bss *bss;
35
36 if (bssid[0] & 0x01)
37 return NULL; /* Skip group addressed frames */
38
39 bss = bss_find(wt, bssid);
40 if (bss)
41 return bss;
42
43 bss = os_zalloc(sizeof(*bss));
44 if (bss == NULL)
45 return NULL;
46 dl_list_init(&bss->sta);
47 dl_list_init(&bss->pmk);
48 dl_list_init(&bss->tdls);
49 os_memcpy(bss->bssid, bssid, ETH_ALEN);
50 dl_list_add(&wt->bss, &bss->list);
51 wpa_printf(MSG_DEBUG, "Discovered new BSS - " MACSTR,
52 MAC2STR(bss->bssid));
53 return bss;
54 }
55
56
pmk_deinit(struct wlantest_pmk * pmk)57 void pmk_deinit(struct wlantest_pmk *pmk)
58 {
59 dl_list_del(&pmk->list);
60 os_free(pmk);
61 }
62
63
tdls_deinit(struct wlantest_tdls * tdls)64 void tdls_deinit(struct wlantest_tdls *tdls)
65 {
66 dl_list_del(&tdls->list);
67 os_free(tdls);
68 }
69
70
bss_deinit(struct wlantest_bss * bss)71 void bss_deinit(struct wlantest_bss *bss)
72 {
73 struct wlantest_sta *sta, *n;
74 struct wlantest_pmk *pmk, *np;
75 struct wlantest_tdls *tdls, *nt;
76 dl_list_for_each_safe(sta, n, &bss->sta, struct wlantest_sta, list)
77 sta_deinit(sta);
78 dl_list_for_each_safe(pmk, np, &bss->pmk, struct wlantest_pmk, list)
79 pmk_deinit(pmk);
80 dl_list_for_each_safe(tdls, nt, &bss->tdls, struct wlantest_tdls, list)
81 tdls_deinit(tdls);
82 dl_list_del(&bss->list);
83 os_free(bss);
84 }
85
86
bss_add_pmk_from_passphrase(struct wlantest_bss * bss,const char * passphrase)87 int bss_add_pmk_from_passphrase(struct wlantest_bss *bss,
88 const char *passphrase)
89 {
90 struct wlantest_pmk *pmk;
91
92 pmk = os_zalloc(sizeof(*pmk));
93 if (pmk == NULL)
94 return -1;
95 if (pbkdf2_sha1(passphrase, bss->ssid, bss->ssid_len, 4096,
96 pmk->pmk, PMK_LEN) < 0) {
97 os_free(pmk);
98 return -1;
99 }
100
101 wpa_printf(MSG_INFO, "Add possible PMK for BSSID " MACSTR
102 " based on passphrase '%s'",
103 MAC2STR(bss->bssid), passphrase);
104 wpa_hexdump(MSG_DEBUG, "Possible PMK", pmk->pmk, PMK_LEN);
105 pmk->pmk_len = PMK_LEN;
106 dl_list_add(&bss->pmk, &pmk->list);
107
108 return 0;
109 }
110
111
bss_add_pmk(struct wlantest * wt,struct wlantest_bss * bss)112 static void bss_add_pmk(struct wlantest *wt, struct wlantest_bss *bss)
113 {
114 struct wlantest_passphrase *p;
115
116 dl_list_for_each(p, &wt->passphrase, struct wlantest_passphrase, list)
117 {
118 if (!is_zero_ether_addr(p->bssid) &&
119 os_memcmp(p->bssid, bss->bssid, ETH_ALEN) != 0)
120 continue;
121 if (p->ssid_len &&
122 (p->ssid_len != bss->ssid_len ||
123 os_memcmp(p->ssid, bss->ssid, p->ssid_len) != 0))
124 continue;
125
126 if (bss_add_pmk_from_passphrase(bss, p->passphrase) < 0)
127 break;
128 }
129 }
130
131
bss_update(struct wlantest * wt,struct wlantest_bss * bss,struct ieee802_11_elems * elems,int beacon)132 void bss_update(struct wlantest *wt, struct wlantest_bss *bss,
133 struct ieee802_11_elems *elems, int beacon)
134 {
135 struct wpa_ie_data data;
136 int update = 0;
137
138 if (bss->capab_info != bss->prev_capab_info)
139 update = 1;
140
141 if (beacon && (!elems->ssid || elems->ssid_len > 32)) {
142 wpa_printf(MSG_INFO,
143 "Invalid or missing SSID in a %s frame for " MACSTR,
144 beacon == 1 ? "Beacon" : "Probe Response",
145 MAC2STR(bss->bssid));
146 bss->parse_error_reported = 1;
147 return;
148 }
149
150 if (beacon &&
151 (bss->ssid_len != elems->ssid_len ||
152 os_memcmp(bss->ssid, elems->ssid, bss->ssid_len) != 0)) {
153 wpa_printf(MSG_DEBUG, "Store SSID '%s' for BSSID " MACSTR,
154 wpa_ssid_txt(elems->ssid, elems->ssid_len),
155 MAC2STR(bss->bssid));
156 os_memcpy(bss->ssid, elems->ssid, elems->ssid_len);
157 bss->ssid_len = elems->ssid_len;
158 bss_add_pmk(wt, bss);
159 }
160
161 if (elems->osen == NULL) {
162 if (bss->osenie[0]) {
163 add_note(wt, MSG_INFO, "BSS " MACSTR
164 " - OSEN IE removed", MAC2STR(bss->bssid));
165 bss->rsnie[0] = 0;
166 update = 1;
167 }
168 } else {
169 if (bss->osenie[0] == 0 ||
170 os_memcmp(bss->osenie, elems->osen - 2,
171 elems->osen_len + 2) != 0) {
172 wpa_printf(MSG_INFO, "BSS " MACSTR " - OSEN IE "
173 "stored", MAC2STR(bss->bssid));
174 wpa_hexdump(MSG_DEBUG, "OSEN IE", elems->osen - 2,
175 elems->osen_len + 2);
176 update = 1;
177 }
178 os_memcpy(bss->osenie, elems->osen - 2,
179 elems->osen_len + 2);
180 }
181
182 /* S1G does not include RSNE in beacon, so only clear it from
183 * Probe Response frames. Note this assumes short beacons were dropped
184 * due to missing SSID above.
185 */
186 if (!elems->rsn_ie && (!elems->s1g_capab || beacon != 1)) {
187 if (bss->rsnie[0]) {
188 add_note(wt, MSG_INFO, "BSS " MACSTR
189 " - RSN IE removed", MAC2STR(bss->bssid));
190 bss->rsnie[0] = 0;
191 update = 1;
192 }
193 } else if (elems->rsn_ie) {
194 if (bss->rsnie[0] == 0 ||
195 os_memcmp(bss->rsnie, elems->rsn_ie - 2,
196 elems->rsn_ie_len + 2) != 0) {
197 wpa_printf(MSG_INFO, "BSS " MACSTR " - RSN IE "
198 "stored", MAC2STR(bss->bssid));
199 wpa_hexdump(MSG_DEBUG, "RSN IE", elems->rsn_ie - 2,
200 elems->rsn_ie_len + 2);
201 update = 1;
202 }
203 os_memcpy(bss->rsnie, elems->rsn_ie - 2,
204 elems->rsn_ie_len + 2);
205 }
206
207 if (elems->wpa_ie == NULL) {
208 if (bss->wpaie[0]) {
209 add_note(wt, MSG_INFO, "BSS " MACSTR
210 " - WPA IE removed", MAC2STR(bss->bssid));
211 bss->wpaie[0] = 0;
212 update = 1;
213 }
214 } else {
215 if (bss->wpaie[0] == 0 ||
216 os_memcmp(bss->wpaie, elems->wpa_ie - 2,
217 elems->wpa_ie_len + 2) != 0) {
218 wpa_printf(MSG_INFO, "BSS " MACSTR " - WPA IE "
219 "stored", MAC2STR(bss->bssid));
220 wpa_hexdump(MSG_DEBUG, "WPA IE", elems->wpa_ie - 2,
221 elems->wpa_ie_len + 2);
222 update = 1;
223 }
224 os_memcpy(bss->wpaie, elems->wpa_ie - 2,
225 elems->wpa_ie_len + 2);
226 }
227
228 if (elems->mdie)
229 os_memcpy(bss->mdid, elems->mdie, 2);
230
231 bss->mesh = elems->mesh_id != NULL;
232
233 if (!update)
234 return;
235
236 if (beacon == 1)
237 bss->beacon_seen = 1;
238 else if (beacon == 2)
239 bss->proberesp_seen = 1;
240 bss->ies_set = 1;
241 bss->prev_capab_info = bss->capab_info;
242 bss->proto = 0;
243 bss->pairwise_cipher = 0;
244 bss->group_cipher = 0;
245 bss->key_mgmt = 0;
246 bss->rsn_capab = 0;
247 bss->mgmt_group_cipher = 0;
248
249 if (bss->wpaie[0]) {
250 if (wpa_parse_wpa_ie_wpa(bss->wpaie, 2 + bss->wpaie[1], &data)
251 < 0) {
252 add_note(wt, MSG_INFO, "Failed to parse WPA IE from "
253 MACSTR, MAC2STR(bss->bssid));
254 } else {
255 bss->proto |= data.proto;
256 bss->pairwise_cipher |= data.pairwise_cipher;
257 bss->group_cipher |= data.group_cipher;
258 bss->key_mgmt |= data.key_mgmt;
259 bss->rsn_capab = data.capabilities;
260 bss->mgmt_group_cipher |= data.mgmt_group_cipher;
261 }
262 }
263
264 if (bss->rsnie[0]) {
265 if (wpa_parse_wpa_ie_rsn(bss->rsnie, 2 + bss->rsnie[1], &data)
266 < 0) {
267 add_note(wt, MSG_INFO, "Failed to parse RSN IE from "
268 MACSTR, MAC2STR(bss->bssid));
269 } else {
270 bss->proto |= data.proto;
271 bss->pairwise_cipher |= data.pairwise_cipher;
272 bss->group_cipher |= data.group_cipher;
273 bss->key_mgmt |= data.key_mgmt;
274 bss->rsn_capab = data.capabilities;
275 bss->mgmt_group_cipher |= data.mgmt_group_cipher;
276 }
277 }
278
279 if (bss->osenie[0]) {
280 bss->proto |= WPA_PROTO_OSEN;
281 bss->pairwise_cipher |= WPA_CIPHER_CCMP;
282 bss->group_cipher |= WPA_CIPHER_CCMP;
283 bss->key_mgmt |= WPA_KEY_MGMT_OSEN;
284 }
285
286 if (!(bss->proto & WPA_PROTO_RSN) ||
287 !(bss->rsn_capab & WPA_CAPABILITY_MFPC))
288 bss->mgmt_group_cipher = 0;
289
290 if (!bss->wpaie[0] && !bss->rsnie[0] && !bss->osenie[0] &&
291 (bss->capab_info & WLAN_CAPABILITY_PRIVACY))
292 bss->group_cipher = WPA_CIPHER_WEP40;
293
294 wpa_printf(MSG_INFO, "BSS " MACSTR
295 " proto=%s%s%s%s"
296 "pairwise=%s%s%s%s%s%s%s"
297 "group=%s%s%s%s%s%s%s%s%s"
298 "mgmt_group_cipher=%s%s%s%s%s"
299 "key_mgmt=%s%s%s%s%s%s%s%s%s%s%s%s%s%s"
300 "rsn_capab=%s%s%s%s%s%s%s%s%s%s",
301 MAC2STR(bss->bssid),
302 bss->proto == 0 ? "OPEN " : "",
303 bss->proto & WPA_PROTO_WPA ? "WPA " : "",
304 bss->proto & WPA_PROTO_RSN ? "WPA2 " : "",
305 bss->proto & WPA_PROTO_OSEN ? "OSEN " : "",
306 bss->pairwise_cipher == 0 ? "N/A " : "",
307 bss->pairwise_cipher & WPA_CIPHER_NONE ? "NONE " : "",
308 bss->pairwise_cipher & WPA_CIPHER_TKIP ? "TKIP " : "",
309 bss->pairwise_cipher & WPA_CIPHER_CCMP ? "CCMP " : "",
310 bss->pairwise_cipher & WPA_CIPHER_CCMP_256 ? "CCMP-256 " :
311 "",
312 bss->pairwise_cipher & WPA_CIPHER_GCMP ? "GCMP " : "",
313 bss->pairwise_cipher & WPA_CIPHER_GCMP_256 ? "GCMP-256 " :
314 "",
315 bss->group_cipher == 0 ? "N/A " : "",
316 bss->group_cipher & WPA_CIPHER_NONE ? "NONE " : "",
317 bss->group_cipher & WPA_CIPHER_WEP40 ? "WEP40 " : "",
318 bss->group_cipher & WPA_CIPHER_WEP104 ? "WEP104 " : "",
319 bss->group_cipher & WPA_CIPHER_TKIP ? "TKIP " : "",
320 bss->group_cipher & WPA_CIPHER_CCMP ? "CCMP " : "",
321 bss->group_cipher & WPA_CIPHER_CCMP_256 ? "CCMP-256 " : "",
322 bss->group_cipher & WPA_CIPHER_GCMP ? "GCMP " : "",
323 bss->group_cipher & WPA_CIPHER_GCMP_256 ? "GCMP-256 " : "",
324 bss->mgmt_group_cipher == 0 ? "N/A " : "",
325 bss->mgmt_group_cipher & WPA_CIPHER_AES_128_CMAC ?
326 "BIP " : "",
327 bss->mgmt_group_cipher & WPA_CIPHER_BIP_GMAC_128 ?
328 "BIP-GMAC-128 " : "",
329 bss->mgmt_group_cipher & WPA_CIPHER_BIP_GMAC_256 ?
330 "BIP-GMAC-256 " : "",
331 bss->mgmt_group_cipher & WPA_CIPHER_BIP_CMAC_256 ?
332 "BIP-CMAC-256 " : "",
333 bss->key_mgmt == 0 ? "N/A " : "",
334 bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X ? "EAP " : "",
335 bss->key_mgmt & WPA_KEY_MGMT_PSK ? "PSK " : "",
336 bss->key_mgmt & WPA_KEY_MGMT_WPA_NONE ? "WPA-NONE " : "",
337 bss->key_mgmt & WPA_KEY_MGMT_FT_IEEE8021X ? "FT-EAP " : "",
338 bss->key_mgmt & WPA_KEY_MGMT_FT_PSK ? "FT-PSK " : "",
339 bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X_SHA256 ?
340 "EAP-SHA256 " : "",
341 bss->key_mgmt & WPA_KEY_MGMT_PSK_SHA256 ?
342 "PSK-SHA256 " : "",
343 bss->key_mgmt & WPA_KEY_MGMT_OWE ? "OWE " : "",
344 bss->key_mgmt & WPA_KEY_MGMT_PASN ? "PASN " : "",
345 bss->key_mgmt & WPA_KEY_MGMT_OSEN ? "OSEN " : "",
346 bss->key_mgmt & WPA_KEY_MGMT_DPP ? "DPP " : "",
347 bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X_SUITE_B ?
348 "EAP-SUITE-B " : "",
349 bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 ?
350 "EAP-SUITE-B-192 " : "",
351 bss->rsn_capab & WPA_CAPABILITY_PREAUTH ? "PREAUTH " : "",
352 bss->rsn_capab & WPA_CAPABILITY_NO_PAIRWISE ?
353 "NO_PAIRWISE " : "",
354 bss->rsn_capab & WPA_CAPABILITY_MFPR ? "MFPR " : "",
355 bss->rsn_capab & WPA_CAPABILITY_MFPC ? "MFPC " : "",
356 bss->rsn_capab & WPA_CAPABILITY_PEERKEY_ENABLED ?
357 "PEERKEY " : "",
358 bss->rsn_capab & WPA_CAPABILITY_SPP_A_MSDU_CAPABLE ?
359 "SPP-A-MSDU-CAPAB " : "",
360 bss->rsn_capab & WPA_CAPABILITY_SPP_A_MSDU_REQUIRED ?
361 "SPP-A-MSDU-REQUIRED " : "",
362 bss->rsn_capab & WPA_CAPABILITY_PBAC ? "PBAC " : "",
363 bss->rsn_capab & WPA_CAPABILITY_OCVC ? "OCVC " : "",
364 bss->rsn_capab & WPA_CAPABILITY_EXT_KEY_ID_FOR_UNICAST ?
365 "ExtKeyID " : "");
366 }
367
368
bss_flush(struct wlantest * wt)369 void bss_flush(struct wlantest *wt)
370 {
371 struct wlantest_bss *bss, *n;
372 dl_list_for_each_safe(bss, n, &wt->bss, struct wlantest_bss, list)
373 bss_deinit(bss);
374 }
375