Home | History | Annotate | Line # | Download | only in ap
      1 /*
      2  * hostapd / Station table
      3  * Copyright (c) 2002-2017, Jouni Malinen <j (at) w1.fi>
      4  *
      5  * This software may be distributed under the terms of the BSD license.
      6  * See README for more details.
      7  */
      8 
      9 #ifndef STA_INFO_H
     10 #define STA_INFO_H
     11 
     12 #include "common/defs.h"
     13 #include "list.h"
     14 #include "vlan.h"
     15 #include "common/wpa_common.h"
     16 #include "common/ieee802_11_defs.h"
     17 #include "common/sae.h"
     18 #include "crypto/sha384.h"
     19 #include "pasn/pasn_common.h"
     20 #include "hostapd.h"
     21 
     22 /* STA flags */
     23 #define WLAN_STA_AUTH BIT(0)
     24 #define WLAN_STA_ASSOC BIT(1)
     25 #define WLAN_STA_AUTHORIZED BIT(5)
     26 #define WLAN_STA_PENDING_POLL BIT(6) /* pending activity poll not ACKed */
     27 #define WLAN_STA_SHORT_PREAMBLE BIT(7)
     28 #define WLAN_STA_PREAUTH BIT(8)
     29 #define WLAN_STA_WMM BIT(9)
     30 #define WLAN_STA_MFP BIT(10)
     31 #define WLAN_STA_HT BIT(11)
     32 #define WLAN_STA_WPS BIT(12)
     33 #define WLAN_STA_MAYBE_WPS BIT(13)
     34 #define WLAN_STA_WDS BIT(14)
     35 #define WLAN_STA_ASSOC_REQ_OK BIT(15)
     36 #define WLAN_STA_WPS2 BIT(16)
     37 #define WLAN_STA_GAS BIT(17)
     38 #define WLAN_STA_VHT BIT(18)
     39 #define WLAN_STA_WNM_SLEEP_MODE BIT(19)
     40 #define WLAN_STA_VHT_OPMODE_ENABLED BIT(20)
     41 #define WLAN_STA_VENDOR_VHT BIT(21)
     42 #define WLAN_STA_PENDING_FILS_ERP BIT(22)
     43 #define WLAN_STA_MULTI_AP BIT(23)
     44 #define WLAN_STA_HE BIT(24)
     45 #define WLAN_STA_6GHZ BIT(25)
     46 #define WLAN_STA_PENDING_PASN_FILS_ERP BIT(26)
     47 #define WLAN_STA_EHT BIT(27)
     48 #define WLAN_STA_PENDING_DISASSOC_CB BIT(29)
     49 #define WLAN_STA_PENDING_DEAUTH_CB BIT(30)
     50 #define WLAN_STA_NONERP BIT(31)
     51 
     52 /* Maximum number of supported rates (from both Supported Rates and Extended
     53  * Supported Rates IEs). */
     54 #define WLAN_SUPP_RATES_MAX 32
     55 
     56 struct hostapd_data;
     57 
     58 struct mbo_non_pref_chan_info {
     59 	struct mbo_non_pref_chan_info *next;
     60 	u8 op_class;
     61 	u8 pref;
     62 	u8 reason_code;
     63 	u8 num_channels;
     64 	u8 channels[];
     65 };
     66 
     67 struct pending_eapol_rx {
     68 	struct wpabuf *buf;
     69 	struct os_reltime rx_time;
     70 	enum frame_encryption encrypted;
     71 };
     72 
     73 #define EHT_ML_MAX_STA_PROF_LEN 1024
     74 struct mld_info {
     75 	bool mld_sta;
     76 
     77 	struct ml_common_info {
     78 		u8 mld_addr[ETH_ALEN];
     79 		u16 medium_sync_delay;
     80 		u16 eml_capa;
     81 		u16 mld_capa;
     82 	} common_info;
     83 
     84 	struct mld_link_info {
     85 		u8 valid:1;
     86 		u8 nstr_bitmap_len:2;
     87 		u8 local_addr[ETH_ALEN];
     88 		u8 peer_addr[ETH_ALEN];
     89 
     90 		u8 nstr_bitmap[2];
     91 
     92 		u16 capability;
     93 
     94 		u16 status;
     95 		u16 resp_sta_profile_len;
     96 		u8 *resp_sta_profile;
     97 	} links[MAX_NUM_MLD_LINKS];
     98 };
     99 
    100 struct sta_info {
    101 	struct sta_info *next; /* next entry in sta list */
    102 	struct sta_info *hnext; /* next entry in hash table list */
    103 	u8 addr[6];
    104 	be32 ipaddr;
    105 	struct dl_list ip6addr; /* list head for struct ip6addr */
    106 	u16 aid; /* STA's unique AID (1 .. 2007) or 0 if not yet assigned */
    107 	u16 disconnect_reason_code; /* RADIUS server override */
    108 	u32 flags; /* Bitfield of WLAN_STA_* */
    109 	u16 capability;
    110 	u16 listen_interval; /* or beacon_int for APs */
    111 	u8 supported_rates[WLAN_SUPP_RATES_MAX];
    112 	int supported_rates_len;
    113 	u8 qosinfo; /* Valid when WLAN_STA_WMM is set */
    114 
    115 #ifdef CONFIG_MESH
    116 	enum mesh_plink_state plink_state;
    117 	u16 peer_lid;
    118 	u16 my_lid;
    119 	u16 peer_aid;
    120 	u16 mpm_close_reason;
    121 	int mpm_retries;
    122 	u8 my_nonce[WPA_NONCE_LEN];
    123 	u8 peer_nonce[WPA_NONCE_LEN];
    124 	u8 aek[32];	/* SHA256 digest length */
    125 	u8 mtk[WPA_TK_MAX_LEN];
    126 	size_t mtk_len;
    127 	u8 mgtk_rsc[6];
    128 	u8 mgtk_key_id;
    129 	u8 mgtk[WPA_TK_MAX_LEN];
    130 	size_t mgtk_len;
    131 	u8 igtk_rsc[6];
    132 	u8 igtk[WPA_TK_MAX_LEN];
    133 	size_t igtk_len;
    134 	u16 igtk_key_id;
    135 	u8 sae_auth_retry;
    136 #endif /* CONFIG_MESH */
    137 
    138 	unsigned int nonerp_set:1;
    139 	unsigned int no_short_slot_time_set:1;
    140 	unsigned int no_short_preamble_set:1;
    141 	unsigned int no_ht_gf_set:1;
    142 	unsigned int no_ht_set:1;
    143 	unsigned int ht40_intolerant_set:1;
    144 	unsigned int ht_20mhz_set:1;
    145 	unsigned int no_p2p_set:1;
    146 	unsigned int qos_map_enabled:1;
    147 	unsigned int remediation:1;
    148 	unsigned int hs20_deauth_requested:1;
    149 	unsigned int hs20_deauth_on_ack:1;
    150 	unsigned int session_timeout_set:1;
    151 	unsigned int radius_das_match:1;
    152 	unsigned int ecsa_supported:1;
    153 	unsigned int added_unassoc:1;
    154 	unsigned int pending_wds_enable:1;
    155 	unsigned int power_capab:1;
    156 	unsigned int agreed_to_steer:1;
    157 	unsigned int hs20_t_c_filtering:1;
    158 	unsigned int ft_over_ds:1;
    159 	unsigned int external_dh_updated:1;
    160 	unsigned int post_csa_sa_query:1;
    161 
    162 	u16 auth_alg;
    163 
    164 	enum {
    165 		STA_NULLFUNC = 0, STA_DISASSOC, STA_DEAUTH, STA_REMOVE,
    166 		STA_DISASSOC_FROM_CLI
    167 	} timeout_next;
    168 
    169 	u16 deauth_reason;
    170 	u16 disassoc_reason;
    171 
    172 	/* IEEE 802.1X related data */
    173 	struct eapol_state_machine *eapol_sm;
    174 
    175 	struct pending_eapol_rx *pending_eapol_rx;
    176 
    177 	u64 acct_session_id;
    178 	struct os_reltime acct_session_start;
    179 	int acct_session_started;
    180 	int acct_terminate_cause; /* Acct-Terminate-Cause */
    181 	int acct_interim_interval; /* Acct-Interim-Interval */
    182 	unsigned int acct_interim_errors;
    183 
    184 	/* For extending 32-bit driver counters to 64-bit counters */
    185 	u32 last_rx_bytes_hi;
    186 	u32 last_rx_bytes_lo;
    187 	u32 last_tx_bytes_hi;
    188 	u32 last_tx_bytes_lo;
    189 
    190 	u8 *challenge; /* IEEE 802.11 Shared Key Authentication Challenge */
    191 
    192 	struct wpa_state_machine *wpa_sm;
    193 	struct rsn_preauth_interface *preauth_iface;
    194 
    195 	int vlan_id; /* 0: none, >0: VID */
    196 	struct vlan_description *vlan_desc;
    197 	int vlan_id_bound; /* updated by ap_sta_bind_vlan() */
    198 	 /* PSKs from RADIUS authentication server */
    199 	struct hostapd_sta_wpa_psk_short *psk;
    200 
    201 	char *identity; /* User-Name from RADIUS */
    202 	char *radius_cui; /* Chargeable-User-Identity from RADIUS */
    203 
    204 	struct ieee80211_ht_capabilities *ht_capabilities;
    205 	struct ieee80211_vht_capabilities *vht_capabilities;
    206 	struct ieee80211_vht_operation *vht_operation;
    207 	u8 vht_opmode;
    208 	struct ieee80211_he_capabilities *he_capab;
    209 	size_t he_capab_len;
    210 	struct ieee80211_he_6ghz_band_cap *he_6ghz_capab;
    211 	struct ieee80211_eht_capabilities *eht_capab;
    212 	size_t eht_capab_len;
    213 
    214 	int sa_query_count; /* number of pending SA Query requests;
    215 			     * 0 = no SA Query in progress */
    216 	int sa_query_timed_out;
    217 	u8 *sa_query_trans_id; /* buffer of WLAN_SA_QUERY_TR_ID_LEN *
    218 				* sa_query_count octets of pending SA Query
    219 				* transaction identifiers */
    220 	struct os_reltime sa_query_start;
    221 
    222 #if defined(CONFIG_INTERWORKING) || defined(CONFIG_DPP)
    223 #define GAS_DIALOG_MAX 8 /* Max concurrent dialog number */
    224 	struct gas_dialog_info *gas_dialog;
    225 	u8 gas_dialog_next;
    226 #endif /* CONFIG_INTERWORKING || CONFIG_DPP */
    227 
    228 	struct wpabuf *wps_ie; /* WPS IE from (Re)Association Request */
    229 	struct wpabuf *p2p_ie; /* P2P IE from (Re)Association Request */
    230 	struct wpabuf *hs20_ie; /* HS 2.0 IE from (Re)Association Request */
    231 	/* Hotspot 2.0 Roaming Consortium from (Re)Association Request */
    232 	struct wpabuf *roaming_consortium;
    233 	u8 remediation_method;
    234 	char *remediation_url; /* HS 2.0 Subscription Remediation Server URL */
    235 	char *t_c_url; /* HS 2.0 Terms and Conditions Server URL */
    236 	struct wpabuf *hs20_deauth_req;
    237 	char *hs20_session_info_url;
    238 	int hs20_disassoc_timer;
    239 #ifdef CONFIG_FST
    240 	struct wpabuf *mb_ies; /* MB IEs from (Re)Association Request */
    241 #endif /* CONFIG_FST */
    242 
    243 	struct os_reltime connected_time;
    244 
    245 #ifdef CONFIG_SAE
    246 	struct sae_data *sae;
    247 	unsigned int mesh_sae_pmksa_caching:1;
    248 #endif /* CONFIG_SAE */
    249 
    250 	/* valid only if session_timeout_set == 1 */
    251 	struct os_reltime session_timeout;
    252 
    253 	/* Last Authentication/(Re)Association Request/Action frame sequence
    254 	 * control */
    255 	u16 last_seq_ctrl;
    256 	/* Last Authentication/(Re)Association Request/Action frame subtype */
    257 	u8 last_subtype;
    258 
    259 #ifdef CONFIG_MBO
    260 	u8 cell_capa; /* 0 = unknown (not an MBO STA); otherwise,
    261 		       * enum mbo_cellular_capa values */
    262 	struct mbo_non_pref_chan_info *non_pref_chan;
    263 	int auth_rssi; /* Last Authentication frame RSSI */
    264 #endif /* CONFIG_MBO */
    265 
    266 	u8 *supp_op_classes; /* Supported Operating Classes element, if
    267 			      * received, starting from the Length field */
    268 
    269 	u8 rrm_enabled_capa[5];
    270 
    271 	s8 min_tx_power;
    272 	s8 max_tx_power;
    273 
    274 #ifdef CONFIG_TAXONOMY
    275 	struct wpabuf *probe_ie_taxonomy;
    276 	struct wpabuf *assoc_ie_taxonomy;
    277 #endif /* CONFIG_TAXONOMY */
    278 
    279 #ifdef CONFIG_FILS
    280 	u8 fils_snonce[FILS_NONCE_LEN];
    281 	u8 fils_session[FILS_SESSION_LEN];
    282 	u8 fils_erp_pmkid[PMKID_LEN];
    283 	u8 *fils_pending_assoc_req;
    284 	size_t fils_pending_assoc_req_len;
    285 	unsigned int fils_pending_assoc_is_reassoc:1;
    286 	unsigned int fils_dhcp_rapid_commit_proxy:1;
    287 	unsigned int fils_erp_pmkid_set:1;
    288 	unsigned int fils_drv_assoc_finish:1;
    289 	struct wpabuf *fils_hlp_resp;
    290 	struct wpabuf *hlp_dhcp_discover;
    291 	void (*fils_pending_cb)(struct hostapd_data *hapd, struct sta_info *sta,
    292 				u16 resp, struct wpabuf *data, int pub);
    293 #ifdef CONFIG_FILS_SK_PFS
    294 	struct crypto_ecdh *fils_ecdh;
    295 #endif /* CONFIG_FILS_SK_PFS */
    296 	struct wpabuf *fils_dh_ss;
    297 	struct wpabuf *fils_g_sta;
    298 #endif /* CONFIG_FILS */
    299 
    300 #ifdef CONFIG_OWE
    301 	u8 *owe_pmk;
    302 	size_t owe_pmk_len;
    303 	struct crypto_ecdh *owe_ecdh;
    304 	u16 owe_group;
    305 #endif /* CONFIG_OWE */
    306 
    307 	u8 *ext_capability;
    308 	char *ifname_wds; /* WDS ifname, if in use */
    309 
    310 #ifdef CONFIG_DPP2
    311 	struct dpp_pfs *dpp_pfs;
    312 #endif /* CONFIG_DPP2 */
    313 
    314 #ifdef CONFIG_TESTING_OPTIONS
    315 	enum wpa_alg last_tk_alg;
    316 	int last_tk_key_idx;
    317 	u8 last_tk[WPA_TK_MAX_LEN];
    318 	size_t last_tk_len;
    319 	u8 *sae_postponed_commit;
    320 	size_t sae_postponed_commit_len;
    321 #endif /* CONFIG_TESTING_OPTIONS */
    322 #ifdef CONFIG_AIRTIME_POLICY
    323 	unsigned int airtime_weight;
    324 	struct os_reltime backlogged_until;
    325 #endif /* CONFIG_AIRTIME_POLICY */
    326 
    327 #ifdef CONFIG_PASN
    328 	struct pasn_data *pasn;
    329 #endif /* CONFIG_PASN */
    330 
    331 #ifdef CONFIG_IEEE80211BE
    332 	struct mld_info mld_info;
    333 	u8 mld_assoc_link_id;
    334 #endif /* CONFIG_IEEE80211BE */
    335 
    336 	u16 max_idle_period; /* if nonzero, the granted BSS max idle period in
    337 			      * units of 1000 TUs */
    338 };
    339 
    340 
    341 /* Default value for maximum station inactivity. After AP_MAX_INACTIVITY has
    342  * passed since last received frame from the station, a nullfunc data frame is
    343  * sent to the station. If this frame is not acknowledged and no other frames
    344  * have been received, the station will be disassociated after
    345  * AP_DISASSOC_DELAY seconds. Similarly, the station will be deauthenticated
    346  * after AP_DEAUTH_DELAY seconds has passed after disassociation. */
    347 #define AP_MAX_INACTIVITY (5 * 60)
    348 #define AP_DISASSOC_DELAY (3)
    349 #define AP_DEAUTH_DELAY (1)
    350 /* Number of seconds to keep STA entry with Authenticated flag after it has
    351  * been disassociated. */
    352 #define AP_MAX_INACTIVITY_AFTER_DISASSOC (1 * 30)
    353 /* Number of seconds to keep STA entry after it has been deauthenticated. */
    354 #define AP_MAX_INACTIVITY_AFTER_DEAUTH (1 * 5)
    355 
    356 
    357 int ap_for_each_sta(struct hostapd_data *hapd,
    358 		    int (*cb)(struct hostapd_data *hapd, struct sta_info *sta,
    359 			      void *ctx),
    360 		    void *ctx);
    361 struct sta_info * ap_get_sta(struct hostapd_data *hapd, const u8 *sta);
    362 struct sta_info * ap_get_sta_p2p(struct hostapd_data *hapd, const u8 *addr);
    363 void ap_sta_hash_add(struct hostapd_data *hapd, struct sta_info *sta);
    364 void ap_free_sta(struct hostapd_data *hapd, struct sta_info *sta);
    365 void ap_sta_ip6addr_del(struct hostapd_data *hapd, struct sta_info *sta);
    366 void hostapd_free_stas(struct hostapd_data *hapd);
    367 void ap_handle_timer(void *eloop_ctx, void *timeout_ctx);
    368 void ap_sta_replenish_timeout(struct hostapd_data *hapd, struct sta_info *sta,
    369 			      u32 session_timeout);
    370 void ap_sta_session_timeout(struct hostapd_data *hapd, struct sta_info *sta,
    371 			    u32 session_timeout);
    372 void ap_sta_no_session_timeout(struct hostapd_data *hapd,
    373 			       struct sta_info *sta);
    374 void ap_sta_session_warning_timeout(struct hostapd_data *hapd,
    375 				    struct sta_info *sta, int warning_time);
    376 struct sta_info * ap_sta_add(struct hostapd_data *hapd, const u8 *addr);
    377 void ap_sta_disassociate(struct hostapd_data *hapd, struct sta_info *sta,
    378 			 u16 reason);
    379 void ap_sta_deauthenticate(struct hostapd_data *hapd, struct sta_info *sta,
    380 			   u16 reason);
    381 #ifdef CONFIG_WPS
    382 int ap_sta_wps_cancel(struct hostapd_data *hapd,
    383 		      struct sta_info *sta, void *ctx);
    384 #endif /* CONFIG_WPS */
    385 int ap_sta_bind_vlan(struct hostapd_data *hapd, struct sta_info *sta);
    386 int ap_sta_set_vlan(struct hostapd_data *hapd, struct sta_info *sta,
    387 		    struct vlan_description *vlan_desc);
    388 void ap_sta_start_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
    389 void ap_sta_stop_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
    390 int ap_check_sa_query_timeout(struct hostapd_data *hapd, struct sta_info *sta);
    391 const char * ap_sta_wpa_get_keyid(struct hostapd_data *hapd,
    392 				  struct sta_info *sta);
    393 const u8 * ap_sta_wpa_get_dpp_pkhash(struct hostapd_data *hapd,
    394 				     struct sta_info *sta);
    395 void ap_sta_disconnect(struct hostapd_data *hapd, struct sta_info *sta,
    396 		       const u8 *addr, u16 reason);
    397 
    398 bool ap_sta_set_authorized_flag(struct hostapd_data *hapd, struct sta_info *sta,
    399 				int authorized);
    400 void ap_sta_set_authorized_event(struct hostapd_data *hapd,
    401 				 struct sta_info *sta, int authorized);
    402 void ap_sta_set_authorized(struct hostapd_data *hapd,
    403 			   struct sta_info *sta, int authorized);
    404 static inline int ap_sta_is_authorized(struct sta_info *sta)
    405 {
    406 	return sta->flags & WLAN_STA_AUTHORIZED;
    407 }
    408 
    409 void ap_sta_deauth_cb(struct hostapd_data *hapd, struct sta_info *sta);
    410 void ap_sta_disassoc_cb(struct hostapd_data *hapd, struct sta_info *sta);
    411 void ap_sta_clear_disconnect_timeouts(struct hostapd_data *hapd,
    412 				      struct sta_info *sta);
    413 
    414 int ap_sta_flags_txt(u32 flags, char *buf, size_t buflen);
    415 void ap_sta_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
    416 					    struct sta_info *sta,
    417 					    unsigned timeout);
    418 int ap_sta_pending_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
    419 						   struct sta_info *sta);
    420 int ap_sta_re_add(struct hostapd_data *hapd, struct sta_info *sta);
    421 
    422 void ap_free_sta_pasn(struct hostapd_data *hapd, struct sta_info *sta);
    423 
    424 static inline bool ap_sta_is_mld(struct hostapd_data *hapd,
    425 				 struct sta_info *sta)
    426 {
    427 #ifdef CONFIG_IEEE80211BE
    428 	return hapd->conf->mld_ap && sta && sta->mld_info.mld_sta;
    429 #else /* CONFIG_IEEE80211BE */
    430 	return false;
    431 #endif /* CONFIG_IEEE80211BE */
    432 }
    433 
    434 static inline void ap_sta_set_mld(struct sta_info *sta, bool mld)
    435 {
    436 #ifdef CONFIG_IEEE80211BE
    437 	if (sta)
    438 		sta->mld_info.mld_sta = mld;
    439 #endif /* CONFIG_IEEE80211BE */
    440 }
    441 
    442 void ap_sta_free_sta_profile(struct mld_info *info);
    443 
    444 void hostapd_free_link_stas(struct hostapd_data *hapd);
    445 
    446 #endif /* STA_INFO_H */
    447