1 /*
2  * BSS list
3  * Copyright (c) 2010, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8 
9 #include "utils/includes.h"
10 
11 #include "utils/common.h"
12 #include "common/defs.h"
13 #include "common/ieee802_11_defs.h"
14 #include "common/ieee802_11_common.h"
15 #include "crypto/sha1.h"
16 #include "wlantest.h"
17 
18 
bss_find(struct wlantest * wt,const u8 * bssid)19 struct wlantest_bss * bss_find(struct wlantest *wt, const u8 *bssid)
20 {
21 	struct wlantest_bss *bss;
22 
23 	dl_list_for_each(bss, &wt->bss, struct wlantest_bss, list) {
24 		if (os_memcmp(bss->bssid, bssid, ETH_ALEN) == 0)
25 			return bss;
26 	}
27 
28 	return NULL;
29 }
30 
31 
bss_get(struct wlantest * wt,const u8 * bssid)32 struct wlantest_bss * bss_get(struct wlantest *wt, const u8 *bssid)
33 {
34 	struct wlantest_bss *bss;
35 
36 	if (bssid[0] & 0x01)
37 		return NULL; /* Skip group addressed frames */
38 
39 	bss = bss_find(wt, bssid);
40 	if (bss)
41 		return bss;
42 
43 	bss = os_zalloc(sizeof(*bss));
44 	if (bss == NULL)
45 		return NULL;
46 	dl_list_init(&bss->sta);
47 	dl_list_init(&bss->pmk);
48 	dl_list_init(&bss->tdls);
49 	os_memcpy(bss->bssid, bssid, ETH_ALEN);
50 	dl_list_add(&wt->bss, &bss->list);
51 	wpa_printf(MSG_DEBUG, "Discovered new BSS - " MACSTR,
52 		   MAC2STR(bss->bssid));
53 	return bss;
54 }
55 
56 
pmk_deinit(struct wlantest_pmk * pmk)57 void pmk_deinit(struct wlantest_pmk *pmk)
58 {
59 	dl_list_del(&pmk->list);
60 	os_free(pmk);
61 }
62 
63 
tdls_deinit(struct wlantest_tdls * tdls)64 void tdls_deinit(struct wlantest_tdls *tdls)
65 {
66 	dl_list_del(&tdls->list);
67 	os_free(tdls);
68 }
69 
70 
bss_deinit(struct wlantest_bss * bss)71 void bss_deinit(struct wlantest_bss *bss)
72 {
73 	struct wlantest_sta *sta, *n;
74 	struct wlantest_pmk *pmk, *np;
75 	struct wlantest_tdls *tdls, *nt;
76 	dl_list_for_each_safe(sta, n, &bss->sta, struct wlantest_sta, list)
77 		sta_deinit(sta);
78 	dl_list_for_each_safe(pmk, np, &bss->pmk, struct wlantest_pmk, list)
79 		pmk_deinit(pmk);
80 	dl_list_for_each_safe(tdls, nt, &bss->tdls, struct wlantest_tdls, list)
81 		tdls_deinit(tdls);
82 	dl_list_del(&bss->list);
83 	os_free(bss);
84 }
85 
86 
bss_add_pmk_from_passphrase(struct wlantest_bss * bss,const char * passphrase)87 int bss_add_pmk_from_passphrase(struct wlantest_bss *bss,
88 				const char *passphrase)
89 {
90 	struct wlantest_pmk *pmk;
91 
92 	pmk = os_zalloc(sizeof(*pmk));
93 	if (pmk == NULL)
94 		return -1;
95 	if (pbkdf2_sha1(passphrase, bss->ssid, bss->ssid_len, 4096,
96 			pmk->pmk, PMK_LEN) < 0) {
97 		os_free(pmk);
98 		return -1;
99 	}
100 
101 	wpa_printf(MSG_INFO, "Add possible PMK for BSSID " MACSTR
102 		   " based on passphrase '%s'",
103 		   MAC2STR(bss->bssid), passphrase);
104 	wpa_hexdump(MSG_DEBUG, "Possible PMK", pmk->pmk, PMK_LEN);
105 	pmk->pmk_len = PMK_LEN;
106 	dl_list_add(&bss->pmk, &pmk->list);
107 
108 	return 0;
109 }
110 
111 
bss_add_pmk(struct wlantest * wt,struct wlantest_bss * bss)112 static void bss_add_pmk(struct wlantest *wt, struct wlantest_bss *bss)
113 {
114 	struct wlantest_passphrase *p;
115 
116 	dl_list_for_each(p, &wt->passphrase, struct wlantest_passphrase, list)
117 	{
118 		if (!is_zero_ether_addr(p->bssid) &&
119 		    os_memcmp(p->bssid, bss->bssid, ETH_ALEN) != 0)
120 			continue;
121 		if (p->ssid_len &&
122 		    (p->ssid_len != bss->ssid_len ||
123 		     os_memcmp(p->ssid, bss->ssid, p->ssid_len) != 0))
124 			continue;
125 
126 		if (bss_add_pmk_from_passphrase(bss, p->passphrase) < 0)
127 			break;
128 	}
129 }
130 
131 
bss_update(struct wlantest * wt,struct wlantest_bss * bss,struct ieee802_11_elems * elems,int beacon)132 void bss_update(struct wlantest *wt, struct wlantest_bss *bss,
133 		struct ieee802_11_elems *elems, int beacon)
134 {
135 	struct wpa_ie_data data;
136 	int update = 0;
137 
138 	if (bss->capab_info != bss->prev_capab_info)
139 		update = 1;
140 
141 	if (beacon && (!elems->ssid || elems->ssid_len > 32)) {
142 		wpa_printf(MSG_INFO,
143 			   "Invalid or missing SSID in a %s frame for " MACSTR,
144 			   beacon == 1 ? "Beacon" : "Probe Response",
145 			   MAC2STR(bss->bssid));
146 		bss->parse_error_reported = 1;
147 		return;
148 	}
149 
150 	if (beacon &&
151 	    (bss->ssid_len != elems->ssid_len ||
152 	     os_memcmp(bss->ssid, elems->ssid, bss->ssid_len) != 0)) {
153 		wpa_printf(MSG_DEBUG, "Store SSID '%s' for BSSID " MACSTR,
154 			   wpa_ssid_txt(elems->ssid, elems->ssid_len),
155 			   MAC2STR(bss->bssid));
156 		os_memcpy(bss->ssid, elems->ssid, elems->ssid_len);
157 		bss->ssid_len = elems->ssid_len;
158 		bss_add_pmk(wt, bss);
159 	}
160 
161 	if (elems->osen == NULL) {
162 		if (bss->osenie[0]) {
163 			add_note(wt, MSG_INFO, "BSS " MACSTR
164 				 " - OSEN IE removed", MAC2STR(bss->bssid));
165 			bss->rsnie[0] = 0;
166 			update = 1;
167 		}
168 	} else {
169 		if (bss->osenie[0] == 0 ||
170 		    os_memcmp(bss->osenie, elems->osen - 2,
171 			      elems->osen_len + 2) != 0) {
172 			wpa_printf(MSG_INFO, "BSS " MACSTR " - OSEN IE "
173 				   "stored", MAC2STR(bss->bssid));
174 			wpa_hexdump(MSG_DEBUG, "OSEN IE", elems->osen - 2,
175 				    elems->osen_len + 2);
176 			update = 1;
177 		}
178 		os_memcpy(bss->osenie, elems->osen - 2,
179 			  elems->osen_len + 2);
180 	}
181 
182 	/* S1G does not include RSNE in beacon, so only clear it from
183 	 * Probe Response frames. Note this assumes short beacons were dropped
184 	 * due to missing SSID above.
185 	 */
186 	if (!elems->rsn_ie && (!elems->s1g_capab || beacon != 1)) {
187 		if (bss->rsnie[0]) {
188 			add_note(wt, MSG_INFO, "BSS " MACSTR
189 				 " - RSN IE removed", MAC2STR(bss->bssid));
190 			bss->rsnie[0] = 0;
191 			update = 1;
192 		}
193 	} else if (elems->rsn_ie) {
194 		if (bss->rsnie[0] == 0 ||
195 		    os_memcmp(bss->rsnie, elems->rsn_ie - 2,
196 			      elems->rsn_ie_len + 2) != 0) {
197 			wpa_printf(MSG_INFO, "BSS " MACSTR " - RSN IE "
198 				   "stored", MAC2STR(bss->bssid));
199 			wpa_hexdump(MSG_DEBUG, "RSN IE", elems->rsn_ie - 2,
200 				    elems->rsn_ie_len + 2);
201 			update = 1;
202 		}
203 		os_memcpy(bss->rsnie, elems->rsn_ie - 2,
204 			  elems->rsn_ie_len + 2);
205 	}
206 
207 	if (elems->wpa_ie == NULL) {
208 		if (bss->wpaie[0]) {
209 			add_note(wt, MSG_INFO, "BSS " MACSTR
210 				 " - WPA IE removed", MAC2STR(bss->bssid));
211 			bss->wpaie[0] = 0;
212 			update = 1;
213 		}
214 	} else {
215 		if (bss->wpaie[0] == 0 ||
216 		    os_memcmp(bss->wpaie, elems->wpa_ie - 2,
217 			      elems->wpa_ie_len + 2) != 0) {
218 			wpa_printf(MSG_INFO, "BSS " MACSTR " - WPA IE "
219 				   "stored", MAC2STR(bss->bssid));
220 			wpa_hexdump(MSG_DEBUG, "WPA IE", elems->wpa_ie - 2,
221 				    elems->wpa_ie_len + 2);
222 			update = 1;
223 		}
224 		os_memcpy(bss->wpaie, elems->wpa_ie - 2,
225 			  elems->wpa_ie_len + 2);
226 	}
227 
228 	if (elems->mdie)
229 		os_memcpy(bss->mdid, elems->mdie, 2);
230 
231 	bss->mesh = elems->mesh_id != NULL;
232 
233 	if (!update)
234 		return;
235 
236 	if (beacon == 1)
237 		bss->beacon_seen = 1;
238 	else if (beacon == 2)
239 		bss->proberesp_seen = 1;
240 	bss->ies_set = 1;
241 	bss->prev_capab_info = bss->capab_info;
242 	bss->proto = 0;
243 	bss->pairwise_cipher = 0;
244 	bss->group_cipher = 0;
245 	bss->key_mgmt = 0;
246 	bss->rsn_capab = 0;
247 	bss->mgmt_group_cipher = 0;
248 
249 	if (bss->wpaie[0]) {
250 		if (wpa_parse_wpa_ie_wpa(bss->wpaie, 2 + bss->wpaie[1], &data)
251 		    < 0) {
252 			add_note(wt, MSG_INFO, "Failed to parse WPA IE from "
253 				 MACSTR, MAC2STR(bss->bssid));
254 		} else {
255 			bss->proto |= data.proto;
256 			bss->pairwise_cipher |= data.pairwise_cipher;
257 			bss->group_cipher |= data.group_cipher;
258 			bss->key_mgmt |= data.key_mgmt;
259 			bss->rsn_capab = data.capabilities;
260 			bss->mgmt_group_cipher |= data.mgmt_group_cipher;
261 		}
262 	}
263 
264 	if (bss->rsnie[0]) {
265 		if (wpa_parse_wpa_ie_rsn(bss->rsnie, 2 + bss->rsnie[1], &data)
266 		    < 0) {
267 			add_note(wt, MSG_INFO, "Failed to parse RSN IE from "
268 				 MACSTR, MAC2STR(bss->bssid));
269 		} else {
270 			bss->proto |= data.proto;
271 			bss->pairwise_cipher |= data.pairwise_cipher;
272 			bss->group_cipher |= data.group_cipher;
273 			bss->key_mgmt |= data.key_mgmt;
274 			bss->rsn_capab = data.capabilities;
275 			bss->mgmt_group_cipher |= data.mgmt_group_cipher;
276 		}
277 	}
278 
279 	if (bss->osenie[0]) {
280 		bss->proto |= WPA_PROTO_OSEN;
281 		bss->pairwise_cipher |= WPA_CIPHER_CCMP;
282 		bss->group_cipher |= WPA_CIPHER_CCMP;
283 		bss->key_mgmt |= WPA_KEY_MGMT_OSEN;
284 	}
285 
286 	if (!(bss->proto & WPA_PROTO_RSN) ||
287 	    !(bss->rsn_capab & WPA_CAPABILITY_MFPC))
288 		bss->mgmt_group_cipher = 0;
289 
290 	if (!bss->wpaie[0] && !bss->rsnie[0] && !bss->osenie[0] &&
291 	    (bss->capab_info & WLAN_CAPABILITY_PRIVACY))
292 		bss->group_cipher = WPA_CIPHER_WEP40;
293 
294 	wpa_printf(MSG_INFO, "BSS " MACSTR
295 		   " proto=%s%s%s%s"
296 		   "pairwise=%s%s%s%s%s%s%s"
297 		   "group=%s%s%s%s%s%s%s%s%s"
298 		   "mgmt_group_cipher=%s%s%s%s%s"
299 		   "key_mgmt=%s%s%s%s%s%s%s%s%s%s%s%s%s%s"
300 		   "rsn_capab=%s%s%s%s%s%s%s%s%s%s",
301 		   MAC2STR(bss->bssid),
302 		   bss->proto == 0 ? "OPEN " : "",
303 		   bss->proto & WPA_PROTO_WPA ? "WPA " : "",
304 		   bss->proto & WPA_PROTO_RSN ? "WPA2 " : "",
305 		   bss->proto & WPA_PROTO_OSEN ? "OSEN " : "",
306 		   bss->pairwise_cipher == 0 ? "N/A " : "",
307 		   bss->pairwise_cipher & WPA_CIPHER_NONE ? "NONE " : "",
308 		   bss->pairwise_cipher & WPA_CIPHER_TKIP ? "TKIP " : "",
309 		   bss->pairwise_cipher & WPA_CIPHER_CCMP ? "CCMP " : "",
310 		   bss->pairwise_cipher & WPA_CIPHER_CCMP_256 ? "CCMP-256 " :
311 		   "",
312 		   bss->pairwise_cipher & WPA_CIPHER_GCMP ? "GCMP " : "",
313 		   bss->pairwise_cipher & WPA_CIPHER_GCMP_256 ? "GCMP-256 " :
314 		   "",
315 		   bss->group_cipher == 0 ? "N/A " : "",
316 		   bss->group_cipher & WPA_CIPHER_NONE ? "NONE " : "",
317 		   bss->group_cipher & WPA_CIPHER_WEP40 ? "WEP40 " : "",
318 		   bss->group_cipher & WPA_CIPHER_WEP104 ? "WEP104 " : "",
319 		   bss->group_cipher & WPA_CIPHER_TKIP ? "TKIP " : "",
320 		   bss->group_cipher & WPA_CIPHER_CCMP ? "CCMP " : "",
321 		   bss->group_cipher & WPA_CIPHER_CCMP_256 ? "CCMP-256 " : "",
322 		   bss->group_cipher & WPA_CIPHER_GCMP ? "GCMP " : "",
323 		   bss->group_cipher & WPA_CIPHER_GCMP_256 ? "GCMP-256 " : "",
324 		   bss->mgmt_group_cipher == 0 ? "N/A " : "",
325 		   bss->mgmt_group_cipher & WPA_CIPHER_AES_128_CMAC ?
326 		   "BIP " : "",
327 		   bss->mgmt_group_cipher & WPA_CIPHER_BIP_GMAC_128 ?
328 		   "BIP-GMAC-128 " : "",
329 		   bss->mgmt_group_cipher & WPA_CIPHER_BIP_GMAC_256 ?
330 		   "BIP-GMAC-256 " : "",
331 		   bss->mgmt_group_cipher & WPA_CIPHER_BIP_CMAC_256 ?
332 		   "BIP-CMAC-256 " : "",
333 		   bss->key_mgmt == 0 ? "N/A " : "",
334 		   bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X ? "EAP " : "",
335 		   bss->key_mgmt & WPA_KEY_MGMT_PSK ? "PSK " : "",
336 		   bss->key_mgmt & WPA_KEY_MGMT_WPA_NONE ? "WPA-NONE " : "",
337 		   bss->key_mgmt & WPA_KEY_MGMT_FT_IEEE8021X ? "FT-EAP " : "",
338 		   bss->key_mgmt & WPA_KEY_MGMT_FT_PSK ? "FT-PSK " : "",
339 		   bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X_SHA256 ?
340 		   "EAP-SHA256 " : "",
341 		   bss->key_mgmt & WPA_KEY_MGMT_PSK_SHA256 ?
342 		   "PSK-SHA256 " : "",
343 		   bss->key_mgmt & WPA_KEY_MGMT_OWE ? "OWE " : "",
344 		   bss->key_mgmt & WPA_KEY_MGMT_PASN ? "PASN " : "",
345 		   bss->key_mgmt & WPA_KEY_MGMT_OSEN ? "OSEN " : "",
346 		   bss->key_mgmt & WPA_KEY_MGMT_DPP ? "DPP " : "",
347 		   bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X_SUITE_B ?
348 		   "EAP-SUITE-B " : "",
349 		   bss->key_mgmt & WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 ?
350 		   "EAP-SUITE-B-192 " : "",
351 		   bss->rsn_capab & WPA_CAPABILITY_PREAUTH ? "PREAUTH " : "",
352 		   bss->rsn_capab & WPA_CAPABILITY_NO_PAIRWISE ?
353 		   "NO_PAIRWISE " : "",
354 		   bss->rsn_capab & WPA_CAPABILITY_MFPR ? "MFPR " : "",
355 		   bss->rsn_capab & WPA_CAPABILITY_MFPC ? "MFPC " : "",
356 		   bss->rsn_capab & WPA_CAPABILITY_PEERKEY_ENABLED ?
357 		   "PEERKEY " : "",
358 		   bss->rsn_capab & WPA_CAPABILITY_SPP_A_MSDU_CAPABLE ?
359 		   "SPP-A-MSDU-CAPAB " : "",
360 		   bss->rsn_capab & WPA_CAPABILITY_SPP_A_MSDU_REQUIRED ?
361 		   "SPP-A-MSDU-REQUIRED " : "",
362 		   bss->rsn_capab & WPA_CAPABILITY_PBAC ? "PBAC " : "",
363 		   bss->rsn_capab & WPA_CAPABILITY_OCVC ? "OCVC " : "",
364 		   bss->rsn_capab & WPA_CAPABILITY_EXT_KEY_ID_FOR_UNICAST ?
365 		   "ExtKeyID " : "");
366 }
367 
368 
bss_flush(struct wlantest * wt)369 void bss_flush(struct wlantest *wt)
370 {
371 	struct wlantest_bss *bss, *n;
372 	dl_list_for_each_safe(bss, n, &wt->bss, struct wlantest_bss, list)
373 		bss_deinit(bss);
374 }
375