1 /*
2  * WPA Supplicant - privilege separated driver interface
3  * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8 
9 #include "includes.h"
10 #include <sys/un.h>
11 
12 #include "common.h"
13 #include "driver.h"
14 #include "eloop.h"
15 #include "common/privsep_commands.h"
16 
17 
18 struct wpa_driver_privsep_data {
19 	void *ctx;
20 	u8 own_addr[ETH_ALEN];
21 	int priv_socket;
22 	char *own_socket_path;
23 	int cmd_socket;
24 	char *own_cmd_path;
25 	struct sockaddr_un priv_addr;
26 	char ifname[16];
27 };
28 
29 
wpa_priv_reg_cmd(struct wpa_driver_privsep_data * drv,int cmd)30 static int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
31 {
32 	int res;
33 
34 	res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
35 		     (struct sockaddr *) &drv->priv_addr,
36 		     sizeof(drv->priv_addr));
37 	if (res < 0)
38 		wpa_printf(MSG_ERROR, "sendto: %s", strerror(errno));
39 	return res < 0 ? -1 : 0;
40 }
41 
42 
wpa_priv_cmd(struct wpa_driver_privsep_data * drv,int cmd,const void * data,size_t data_len,void * reply,size_t * reply_len)43 static int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
44 			const void *data, size_t data_len,
45 			void *reply, size_t *reply_len)
46 {
47 	struct msghdr msg;
48 	struct iovec io[2];
49 
50 	io[0].iov_base = &cmd;
51 	io[0].iov_len = sizeof(cmd);
52 	io[1].iov_base = (u8 *) data;
53 	io[1].iov_len = data_len;
54 
55 	os_memset(&msg, 0, sizeof(msg));
56 	msg.msg_iov = io;
57 	msg.msg_iovlen = data ? 2 : 1;
58 	msg.msg_name = &drv->priv_addr;
59 	msg.msg_namelen = sizeof(drv->priv_addr);
60 
61 	if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
62 		wpa_printf(MSG_ERROR, "sendmsg(cmd_socket): %s",
63 			   strerror(errno));
64 		return -1;
65 	}
66 
67 	if (reply) {
68 		fd_set rfds;
69 		struct timeval tv;
70 		int res;
71 
72 		FD_ZERO(&rfds);
73 		FD_SET(drv->cmd_socket, &rfds);
74 		tv.tv_sec = 5;
75 		tv.tv_usec = 0;
76 		res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
77 		if (res < 0 && errno != EINTR) {
78 			wpa_printf(MSG_ERROR, "select: %s", strerror(errno));
79 			return -1;
80 		}
81 
82 		if (FD_ISSET(drv->cmd_socket, &rfds)) {
83 			res = recv(drv->cmd_socket, reply, *reply_len, 0);
84 			if (res < 0) {
85 				wpa_printf(MSG_ERROR, "recv: %s",
86 					   strerror(errno));
87 				return -1;
88 			}
89 			*reply_len = res;
90 		} else {
91 			wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
92 				   "for reply (cmd=%d)", cmd);
93 			return -1;
94 		}
95 	}
96 
97 	return 0;
98 }
99 
100 
wpa_driver_privsep_scan(void * priv,struct wpa_driver_scan_params * params)101 static int wpa_driver_privsep_scan(void *priv,
102 				   struct wpa_driver_scan_params *params)
103 {
104 	struct wpa_driver_privsep_data *drv = priv;
105 	struct privsep_cmd_scan scan;
106 	size_t i;
107 
108 	wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
109 	os_memset(&scan, 0, sizeof(scan));
110 	scan.num_ssids = params->num_ssids;
111 	for (i = 0; i < params->num_ssids; i++) {
112 		if (!params->ssids[i].ssid)
113 			continue;
114 		scan.ssid_lens[i] = params->ssids[i].ssid_len;
115 		os_memcpy(scan.ssids[i], params->ssids[i].ssid,
116 			  scan.ssid_lens[i]);
117 	}
118 
119 	for (i = 0; i < PRIVSEP_MAX_SCAN_FREQS &&
120 		     params->freqs && params->freqs[i]; i++)
121 		scan.freqs[i] = params->freqs[i];
122 	scan.num_freqs = i;
123 
124 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, &scan, sizeof(scan),
125 			    NULL, NULL);
126 }
127 
128 
129 static struct wpa_scan_results *
wpa_driver_privsep_get_scan_results2(void * priv)130 wpa_driver_privsep_get_scan_results2(void *priv)
131 {
132 	struct wpa_driver_privsep_data *drv = priv;
133 	int res, num;
134 	u8 *buf, *pos, *end;
135 	size_t reply_len = 60000;
136 	struct wpa_scan_results *results;
137 	struct wpa_scan_res *r;
138 
139 	buf = os_malloc(reply_len);
140 	if (buf == NULL)
141 		return NULL;
142 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
143 			   NULL, 0, buf, &reply_len);
144 	if (res < 0) {
145 		os_free(buf);
146 		return NULL;
147 	}
148 
149 	wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
150 		   (unsigned long) reply_len);
151 	if (reply_len < sizeof(int)) {
152 		wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
153 			   (unsigned long) reply_len);
154 		os_free(buf);
155 		return NULL;
156 	}
157 
158 	pos = buf;
159 	end = buf + reply_len;
160 	os_memcpy(&num, pos, sizeof(int));
161 	if (num < 0 || num > 1000) {
162 		os_free(buf);
163 		return NULL;
164 	}
165 	pos += sizeof(int);
166 
167 	results = os_zalloc(sizeof(*results));
168 	if (results == NULL) {
169 		os_free(buf);
170 		return NULL;
171 	}
172 
173 	results->res = os_calloc(num, sizeof(struct wpa_scan_res *));
174 	if (results->res == NULL) {
175 		os_free(results);
176 		os_free(buf);
177 		return NULL;
178 	}
179 
180 	while (results->num < (size_t) num && end - pos > (int) sizeof(int)) {
181 		int len;
182 		os_memcpy(&len, pos, sizeof(int));
183 		pos += sizeof(int);
184 		if (len < 0 || len > 10000 || len > end - pos)
185 			break;
186 
187 		r = os_memdup(pos, len);
188 		if (r == NULL)
189 			break;
190 		pos += len;
191 		if (sizeof(*r) + r->ie_len + r->beacon_ie_len > (size_t) len) {
192 			wpa_printf(MSG_ERROR,
193 				   "privsep: Invalid scan result len (%d + %d + %d > %d)",
194 				   (int) sizeof(*r), (int) r->ie_len,
195 				   (int) r->beacon_ie_len, len);
196 			os_free(r);
197 			break;
198 		}
199 
200 		results->res[results->num++] = r;
201 	}
202 
203 	os_free(buf);
204 	return results;
205 }
206 
207 
wpa_driver_privsep_set_key(void * priv,struct wpa_driver_set_key_params * params)208 static int wpa_driver_privsep_set_key(void *priv,
209 				      struct wpa_driver_set_key_params *params)
210 {
211 	struct wpa_driver_privsep_data *drv = priv;
212 	struct privsep_cmd_set_key cmd;
213 	enum wpa_alg alg = params->alg;
214 	const u8 *addr = params->addr;
215 	int key_idx = params->key_idx;
216 	int set_tx = params->set_tx;
217 	const u8 *seq = params->seq;
218 	size_t seq_len = params->seq_len;
219 	const u8 *key = params->key;
220 	size_t key_len = params->key_len;
221 
222 	if (params->key_flag & KEY_FLAG_NEXT)
223 		return -1;
224 
225 	wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
226 		   __func__, priv, alg, key_idx, set_tx);
227 
228 	os_memset(&cmd, 0, sizeof(cmd));
229 	cmd.alg = alg;
230 	if (addr)
231 		os_memcpy(cmd.addr, addr, ETH_ALEN);
232 	else
233 		os_memset(cmd.addr, 0xff, ETH_ALEN);
234 	cmd.key_idx = key_idx;
235 	cmd.set_tx = set_tx;
236 	cmd.key_flag = params->key_flag;
237 	if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
238 		os_memcpy(cmd.seq, seq, seq_len);
239 		cmd.seq_len = seq_len;
240 	}
241 	if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
242 		os_memcpy(cmd.key, key, key_len);
243 		cmd.key_len = key_len;
244 	}
245 
246 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
247 			    NULL, NULL);
248 }
249 
250 
wpa_driver_privsep_authenticate(void * priv,struct wpa_driver_auth_params * params)251 static int wpa_driver_privsep_authenticate(
252 	void *priv, struct wpa_driver_auth_params *params)
253 {
254 	struct wpa_driver_privsep_data *drv = priv;
255 	struct privsep_cmd_authenticate *data;
256 	int i, res;
257 	size_t buflen;
258 	u8 *pos;
259 
260 	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d bssid=" MACSTR
261 		   " auth_alg=%d local_state_change=%d p2p=%d",
262 		   __func__, priv, params->freq, MAC2STR(params->bssid),
263 		   params->auth_alg, params->local_state_change, params->p2p);
264 
265 	buflen = sizeof(*data) + params->ie_len + params->auth_data_len;
266 	data = os_zalloc(buflen);
267 	if (data == NULL)
268 		return -1;
269 
270 	data->freq = params->freq;
271 	os_memcpy(data->bssid, params->bssid, ETH_ALEN);
272 	os_memcpy(data->ssid, params->ssid, params->ssid_len);
273 	data->ssid_len = params->ssid_len;
274 	data->auth_alg = params->auth_alg;
275 	data->ie_len = params->ie_len;
276 	for (i = 0; i < 4; i++) {
277 		if (params->wep_key[i])
278 			os_memcpy(data->wep_key[i], params->wep_key[i],
279 				  params->wep_key_len[i]);
280 		data->wep_key_len[i] = params->wep_key_len[i];
281 	}
282 	data->wep_tx_keyidx = params->wep_tx_keyidx;
283 	data->local_state_change = params->local_state_change;
284 	data->p2p = params->p2p;
285 	pos = (u8 *) (data + 1);
286 	if (params->ie_len) {
287 		os_memcpy(pos, params->ie, params->ie_len);
288 		pos += params->ie_len;
289 	}
290 	if (params->auth_data_len)
291 		os_memcpy(pos, params->auth_data, params->auth_data_len);
292 
293 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_AUTHENTICATE, data, buflen,
294 			   NULL, NULL);
295 	os_free(data);
296 
297 	return res;
298 }
299 
300 
wpa_driver_privsep_associate(void * priv,struct wpa_driver_associate_params * params)301 static int wpa_driver_privsep_associate(
302 	void *priv, struct wpa_driver_associate_params *params)
303 {
304 	struct wpa_driver_privsep_data *drv = priv;
305 	struct privsep_cmd_associate *data;
306 	int res;
307 	size_t buflen;
308 
309 	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
310 		   "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
311 		   __func__, priv, params->freq.freq, params->pairwise_suite,
312 		   params->group_suite, params->key_mgmt_suite,
313 		   params->auth_alg, params->mode);
314 
315 	buflen = sizeof(*data) + params->wpa_ie_len;
316 	data = os_zalloc(buflen);
317 	if (data == NULL)
318 		return -1;
319 
320 	if (params->bssid)
321 		os_memcpy(data->bssid, params->bssid, ETH_ALEN);
322 	os_memcpy(data->ssid, params->ssid, params->ssid_len);
323 	data->ssid_len = params->ssid_len;
324 	data->hwmode = params->freq.mode;
325 	data->freq = params->freq.freq;
326 	data->channel = params->freq.channel;
327 	data->pairwise_suite = params->pairwise_suite;
328 	data->group_suite = params->group_suite;
329 	data->key_mgmt_suite = params->key_mgmt_suite;
330 	data->auth_alg = params->auth_alg;
331 	data->mode = params->mode;
332 	data->wpa_ie_len = params->wpa_ie_len;
333 	if (params->wpa_ie)
334 		os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
335 	/* TODO: add support for other assoc parameters */
336 
337 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
338 			   NULL, NULL);
339 	os_free(data);
340 
341 	return res;
342 }
343 
344 
wpa_driver_privsep_get_bssid(void * priv,u8 * bssid)345 static int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
346 {
347 	struct wpa_driver_privsep_data *drv = priv;
348 	int res;
349 	size_t len = ETH_ALEN;
350 
351 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
352 	if (res < 0 || len != ETH_ALEN)
353 		return -1;
354 	return 0;
355 }
356 
357 
wpa_driver_privsep_get_ssid(void * priv,u8 * ssid)358 static int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
359 {
360 	struct wpa_driver_privsep_data *drv = priv;
361 	int res, ssid_len;
362 	u8 reply[sizeof(int) + SSID_MAX_LEN];
363 	size_t len = sizeof(reply);
364 
365 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
366 	if (res < 0 || len < sizeof(int))
367 		return -1;
368 	os_memcpy(&ssid_len, reply, sizeof(int));
369 	if (ssid_len < 0 || ssid_len > SSID_MAX_LEN ||
370 	    sizeof(int) + ssid_len > len) {
371 		wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
372 		return -1;
373 	}
374 	os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
375 	return ssid_len;
376 }
377 
378 
wpa_driver_privsep_deauthenticate(void * priv,const u8 * addr,u16 reason_code)379 static int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
380 					     u16 reason_code)
381 {
382 	//struct wpa_driver_privsep_data *drv = priv;
383 	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
384 		   __func__, MAC2STR(addr), reason_code);
385 	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
386 	return 0;
387 }
388 
389 
wpa_driver_privsep_event_auth(void * ctx,u8 * buf,size_t len)390 static void wpa_driver_privsep_event_auth(void *ctx, u8 *buf, size_t len)
391 {
392 	union wpa_event_data data;
393 	struct privsep_event_auth *auth;
394 
395 	os_memset(&data, 0, sizeof(data));
396 	if (len < sizeof(*auth))
397 		return;
398 	auth = (struct privsep_event_auth *) buf;
399 	if (len < sizeof(*auth) + auth->ies_len)
400 		return;
401 
402 	os_memcpy(data.auth.peer, auth->peer, ETH_ALEN);
403 	os_memcpy(data.auth.bssid, auth->bssid, ETH_ALEN);
404 	data.auth.auth_type = auth->auth_type;
405 	data.auth.auth_transaction = auth->auth_transaction;
406 	data.auth.status_code = auth->status_code;
407 	if (auth->ies_len) {
408 		data.auth.ies = (u8 *) (auth + 1);
409 		data.auth.ies_len = auth->ies_len;
410 	}
411 
412 	wpa_supplicant_event(ctx, EVENT_AUTH, &data);
413 }
414 
415 
wpa_driver_privsep_event_assoc(void * ctx,enum wpa_event_type event,u8 * buf,size_t len)416 static void wpa_driver_privsep_event_assoc(void *ctx,
417 					   enum wpa_event_type event,
418 					   u8 *buf, size_t len)
419 {
420 	union wpa_event_data data;
421 	int inc_data = 0;
422 	u8 *pos, *end;
423 	int ie_len;
424 
425 	os_memset(&data, 0, sizeof(data));
426 
427 	pos = buf;
428 	end = buf + len;
429 
430 	if (end - pos < (int) sizeof(int))
431 		return;
432 	os_memcpy(&ie_len, pos, sizeof(int));
433 	pos += sizeof(int);
434 	if (ie_len < 0 || ie_len > end - pos)
435 		return;
436 	if (ie_len) {
437 		data.assoc_info.req_ies = pos;
438 		data.assoc_info.req_ies_len = ie_len;
439 		pos += ie_len;
440 		inc_data = 1;
441 	}
442 
443 	wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
444 }
445 
446 
wpa_driver_privsep_event_interface_status(void * ctx,u8 * buf,size_t len)447 static void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
448 						      size_t len)
449 {
450 	union wpa_event_data data;
451 	int ievent;
452 
453 	if (len < sizeof(int) ||
454 	    len - sizeof(int) > sizeof(data.interface_status.ifname))
455 		return;
456 
457 	os_memcpy(&ievent, buf, sizeof(int));
458 
459 	os_memset(&data, 0, sizeof(data));
460 	data.interface_status.ievent = ievent;
461 	os_memcpy(data.interface_status.ifname, buf + sizeof(int),
462 		  len - sizeof(int));
463 	wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
464 }
465 
466 
wpa_driver_privsep_event_michael_mic_failure(void * ctx,u8 * buf,size_t len)467 static void wpa_driver_privsep_event_michael_mic_failure(
468 	void *ctx, u8 *buf, size_t len)
469 {
470 	union wpa_event_data data;
471 
472 	if (len != sizeof(int))
473 		return;
474 
475 	os_memset(&data, 0, sizeof(data));
476 	os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
477 	wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
478 }
479 
480 
wpa_driver_privsep_event_pmkid_candidate(void * ctx,u8 * buf,size_t len)481 static void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
482 						     size_t len)
483 {
484 	union wpa_event_data data;
485 
486 	if (len != sizeof(struct pmkid_candidate))
487 		return;
488 
489 	os_memset(&data, 0, sizeof(data));
490 	os_memcpy(&data.pmkid_candidate, buf, len);
491 	wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
492 }
493 
494 
wpa_driver_privsep_event_ft_response(void * ctx,u8 * buf,size_t len)495 static void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
496 						 size_t len)
497 {
498 	union wpa_event_data data;
499 
500 	if (len < sizeof(int) + ETH_ALEN)
501 		return;
502 
503 	os_memset(&data, 0, sizeof(data));
504 	os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
505 	os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
506 	data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
507 	data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
508 	wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
509 }
510 
511 
wpa_driver_privsep_event_rx_eapol(void * ctx,u8 * buf,size_t len)512 static void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
513 {
514 	if (len < ETH_ALEN)
515 		return;
516 	drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
517 }
518 
519 
wpa_driver_privsep_receive(int sock,void * eloop_ctx,void * sock_ctx)520 static void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
521 				       void *sock_ctx)
522 {
523 	struct wpa_driver_privsep_data *drv = eloop_ctx;
524 	u8 *buf, *event_buf;
525 	size_t event_len;
526 	int res, event;
527 	enum privsep_event e;
528 	struct sockaddr_un from;
529 	socklen_t fromlen = sizeof(from);
530 	const size_t buflen = 2000;
531 
532 	buf = os_malloc(buflen);
533 	if (buf == NULL)
534 		return;
535 	res = recvfrom(sock, buf, buflen, 0,
536 		       (struct sockaddr *) &from, &fromlen);
537 	if (res < 0) {
538 		wpa_printf(MSG_ERROR, "recvfrom(priv_socket): %s",
539 			   strerror(errno));
540 		os_free(buf);
541 		return;
542 	}
543 
544 	wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
545 
546 	if (res < (int) sizeof(int)) {
547 		wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
548 		return;
549 	}
550 
551 	os_memcpy(&event, buf, sizeof(int));
552 	event_buf = &buf[sizeof(int)];
553 	event_len = res - sizeof(int);
554 	wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
555 		   event, (unsigned long) event_len);
556 
557 	e = event;
558 	switch (e) {
559 	case PRIVSEP_EVENT_SCAN_RESULTS:
560 		wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
561 		break;
562 	case PRIVSEP_EVENT_SCAN_STARTED:
563 		wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, NULL);
564 		break;
565 	case PRIVSEP_EVENT_ASSOC:
566 		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
567 					       event_buf, event_len);
568 		break;
569 	case PRIVSEP_EVENT_DISASSOC:
570 		wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
571 		break;
572 	case PRIVSEP_EVENT_ASSOCINFO:
573 		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
574 					       event_buf, event_len);
575 		break;
576 	case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
577 		wpa_driver_privsep_event_michael_mic_failure(
578 			drv->ctx, event_buf, event_len);
579 		break;
580 	case PRIVSEP_EVENT_INTERFACE_STATUS:
581 		wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
582 							  event_len);
583 		break;
584 	case PRIVSEP_EVENT_PMKID_CANDIDATE:
585 		wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
586 							 event_len);
587 		break;
588 	case PRIVSEP_EVENT_FT_RESPONSE:
589 		wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
590 						     event_len);
591 		break;
592 	case PRIVSEP_EVENT_RX_EAPOL:
593 		wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
594 						  event_len);
595 		break;
596 	case PRIVSEP_EVENT_AUTH:
597 		wpa_driver_privsep_event_auth(drv->ctx, event_buf, event_len);
598 		break;
599 	}
600 
601 	os_free(buf);
602 }
603 
604 
wpa_driver_privsep_init(void * ctx,const char * ifname)605 static void * wpa_driver_privsep_init(void *ctx, const char *ifname)
606 {
607 	struct wpa_driver_privsep_data *drv;
608 
609 	drv = os_zalloc(sizeof(*drv));
610 	if (drv == NULL)
611 		return NULL;
612 	drv->ctx = ctx;
613 	drv->priv_socket = -1;
614 	drv->cmd_socket = -1;
615 	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
616 
617 	return drv;
618 }
619 
620 
wpa_driver_privsep_deinit(void * priv)621 static void wpa_driver_privsep_deinit(void *priv)
622 {
623 	struct wpa_driver_privsep_data *drv = priv;
624 
625 	if (drv->priv_socket >= 0) {
626 		wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
627 		eloop_unregister_read_sock(drv->priv_socket);
628 		close(drv->priv_socket);
629 	}
630 
631 	if (drv->own_socket_path) {
632 		unlink(drv->own_socket_path);
633 		os_free(drv->own_socket_path);
634 	}
635 
636 	if (drv->cmd_socket >= 0) {
637 		eloop_unregister_read_sock(drv->cmd_socket);
638 		close(drv->cmd_socket);
639 	}
640 
641 	if (drv->own_cmd_path) {
642 		unlink(drv->own_cmd_path);
643 		os_free(drv->own_cmd_path);
644 	}
645 
646 	os_free(drv);
647 }
648 
649 
wpa_driver_privsep_set_param(void * priv,const char * param)650 static int wpa_driver_privsep_set_param(void *priv, const char *param)
651 {
652 	struct wpa_driver_privsep_data *drv = priv;
653 	const char *pos;
654 	char *own_dir, *priv_dir;
655 	static unsigned int counter = 0;
656 	size_t len;
657 	struct sockaddr_un addr;
658 
659 	wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
660 	if (param == NULL)
661 		pos = NULL;
662 	else
663 		pos = os_strstr(param, "own_dir=");
664 	if (pos) {
665 		char *end;
666 		own_dir = os_strdup(pos + 8);
667 		if (own_dir == NULL)
668 			return -1;
669 		end = os_strchr(own_dir, ' ');
670 		if (end)
671 			*end = '\0';
672 	} else {
673 		own_dir = os_strdup("/tmp");
674 		if (own_dir == NULL)
675 			return -1;
676 	}
677 
678 	if (param == NULL)
679 		pos = NULL;
680 	else
681 		pos = os_strstr(param, "priv_dir=");
682 	if (pos) {
683 		char *end;
684 		priv_dir = os_strdup(pos + 9);
685 		if (priv_dir == NULL) {
686 			os_free(own_dir);
687 			return -1;
688 		}
689 		end = os_strchr(priv_dir, ' ');
690 		if (end)
691 			*end = '\0';
692 	} else {
693 		priv_dir = os_strdup("/var/run/wpa_priv");
694 		if (priv_dir == NULL) {
695 			os_free(own_dir);
696 			return -1;
697 		}
698 	}
699 
700 	len = os_strlen(own_dir) + 50;
701 	drv->own_socket_path = os_malloc(len);
702 	if (drv->own_socket_path == NULL) {
703 		os_free(priv_dir);
704 		os_free(own_dir);
705 		return -1;
706 	}
707 	os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
708 		    own_dir, getpid(), counter++);
709 
710 	len = os_strlen(own_dir) + 50;
711 	drv->own_cmd_path = os_malloc(len);
712 	if (drv->own_cmd_path == NULL) {
713 		os_free(drv->own_socket_path);
714 		drv->own_socket_path = NULL;
715 		os_free(priv_dir);
716 		os_free(own_dir);
717 		return -1;
718 	}
719 	os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
720 		    own_dir, getpid(), counter++);
721 
722 	os_free(own_dir);
723 
724 	drv->priv_addr.sun_family = AF_UNIX;
725 	os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
726 		    "%s/%s", priv_dir, drv->ifname);
727 	os_free(priv_dir);
728 
729 	drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
730 	if (drv->priv_socket < 0) {
731 		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
732 		os_free(drv->own_socket_path);
733 		drv->own_socket_path = NULL;
734 		return -1;
735 	}
736 
737 	os_memset(&addr, 0, sizeof(addr));
738 	addr.sun_family = AF_UNIX;
739 	os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
740 	if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
741 	    0) {
742 		wpa_printf(MSG_ERROR,
743 			   "privsep-set-params priv-sock: bind(PF_UNIX): %s",
744 			   strerror(errno));
745 		close(drv->priv_socket);
746 		drv->priv_socket = -1;
747 		unlink(drv->own_socket_path);
748 		os_free(drv->own_socket_path);
749 		drv->own_socket_path = NULL;
750 		return -1;
751 	}
752 
753 	eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
754 				 drv, NULL);
755 
756 	drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
757 	if (drv->cmd_socket < 0) {
758 		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
759 		os_free(drv->own_cmd_path);
760 		drv->own_cmd_path = NULL;
761 		return -1;
762 	}
763 
764 	os_memset(&addr, 0, sizeof(addr));
765 	addr.sun_family = AF_UNIX;
766 	os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
767 	if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
768 	{
769 		wpa_printf(MSG_ERROR,
770 			   "privsep-set-params cmd-sock: bind(PF_UNIX): %s",
771 			   strerror(errno));
772 		close(drv->cmd_socket);
773 		drv->cmd_socket = -1;
774 		unlink(drv->own_cmd_path);
775 		os_free(drv->own_cmd_path);
776 		drv->own_cmd_path = NULL;
777 		return -1;
778 	}
779 
780 	if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
781 		wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
782 		return -1;
783 	}
784 
785 	return 0;
786 }
787 
788 
wpa_driver_privsep_get_capa(void * priv,struct wpa_driver_capa * capa)789 static int wpa_driver_privsep_get_capa(void *priv,
790 				       struct wpa_driver_capa *capa)
791 {
792 	struct wpa_driver_privsep_data *drv = priv;
793 	int res;
794 	size_t len = sizeof(*capa);
795 
796 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
797 	if (res < 0 || len != sizeof(*capa))
798 		return -1;
799 	/* For now, no support for passing extended_capa pointers */
800 	capa->extended_capa = NULL;
801 	capa->extended_capa_mask = NULL;
802 	capa->extended_capa_len = 0;
803 	/* Control port is not yet supported */
804 	capa->flags &= ~WPA_DRIVER_FLAGS_CONTROL_PORT;
805 	return 0;
806 }
807 
808 
wpa_driver_privsep_get_mac_addr(void * priv)809 static const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
810 {
811 	struct wpa_driver_privsep_data *drv = priv;
812 	wpa_printf(MSG_DEBUG, "%s", __func__);
813 	return drv->own_addr;
814 }
815 
816 
wpa_driver_privsep_set_country(void * priv,const char * alpha2)817 static int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
818 {
819 	struct wpa_driver_privsep_data *drv = priv;
820 	wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
821 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
822 			    os_strlen(alpha2), NULL, NULL);
823 }
824 
825 
826 struct wpa_driver_ops wpa_driver_privsep_ops = {
827 	"privsep",
828 	"wpa_supplicant privilege separated driver",
829 	.get_bssid = wpa_driver_privsep_get_bssid,
830 	.get_ssid = wpa_driver_privsep_get_ssid,
831 	.set_key = wpa_driver_privsep_set_key,
832 	.init = wpa_driver_privsep_init,
833 	.deinit = wpa_driver_privsep_deinit,
834 	.set_param = wpa_driver_privsep_set_param,
835 	.scan2 = wpa_driver_privsep_scan,
836 	.deauthenticate = wpa_driver_privsep_deauthenticate,
837 	.authenticate = wpa_driver_privsep_authenticate,
838 	.associate = wpa_driver_privsep_associate,
839 	.get_capa = wpa_driver_privsep_get_capa,
840 	.get_mac_addr = wpa_driver_privsep_get_mac_addr,
841 	.get_scan_results2 = wpa_driver_privsep_get_scan_results2,
842 	.set_country = wpa_driver_privsep_set_country,
843 };
844 
845 
846 const struct wpa_driver_ops *const wpa_drivers[] =
847 {
848 	&wpa_driver_privsep_ops,
849 	NULL
850 };
851