Home | History | Annotate | Line # | Download | only in net80211
ieee80211_input.c revision 1.5
      1  1.5  dyoung /*	$NetBSD: ieee80211_input.c,v 1.5 2003/10/13 04:25:26 dyoung Exp $	*/
      2  1.1  dyoung /*-
      3  1.1  dyoung  * Copyright (c) 2001 Atsushi Onoe
      4  1.1  dyoung  * Copyright (c) 2002, 2003 Sam Leffler, Errno Consulting
      5  1.1  dyoung  * All rights reserved.
      6  1.1  dyoung  *
      7  1.1  dyoung  * Redistribution and use in source and binary forms, with or without
      8  1.1  dyoung  * modification, are permitted provided that the following conditions
      9  1.1  dyoung  * are met:
     10  1.1  dyoung  * 1. Redistributions of source code must retain the above copyright
     11  1.1  dyoung  *    notice, this list of conditions and the following disclaimer.
     12  1.1  dyoung  * 2. Redistributions in binary form must reproduce the above copyright
     13  1.1  dyoung  *    notice, this list of conditions and the following disclaimer in the
     14  1.1  dyoung  *    documentation and/or other materials provided with the distribution.
     15  1.1  dyoung  * 3. The name of the author may not be used to endorse or promote products
     16  1.1  dyoung  *    derived from this software without specific prior written permission.
     17  1.1  dyoung  *
     18  1.1  dyoung  * Alternatively, this software may be distributed under the terms of the
     19  1.1  dyoung  * GNU General Public License ("GPL") version 2 as published by the Free
     20  1.1  dyoung  * Software Foundation.
     21  1.1  dyoung  *
     22  1.1  dyoung  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     23  1.1  dyoung  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     24  1.1  dyoung  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     25  1.1  dyoung  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     26  1.1  dyoung  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     27  1.1  dyoung  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     28  1.1  dyoung  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     29  1.1  dyoung  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     30  1.1  dyoung  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     31  1.1  dyoung  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     32  1.1  dyoung  */
     33  1.1  dyoung 
     34  1.1  dyoung #include <sys/cdefs.h>
     35  1.3  dyoung #ifdef __FreeBSD__
     36  1.1  dyoung __FBSDID("$FreeBSD: src/sys/net80211/ieee80211_input.c,v 1.8 2003/08/19 22:17:03 sam Exp $");
     37  1.3  dyoung #else
     38  1.5  dyoung __KERNEL_RCSID(0, "$NetBSD: ieee80211_input.c,v 1.5 2003/10/13 04:25:26 dyoung Exp $");
     39  1.3  dyoung #endif
     40  1.1  dyoung 
     41  1.1  dyoung #include "opt_inet.h"
     42  1.1  dyoung 
     43  1.5  dyoung #ifdef __NetBSD__
     44  1.5  dyoung #include "bpfilter.h"
     45  1.5  dyoung #endif /* __NetBSD__ */
     46  1.5  dyoung 
     47  1.1  dyoung #include <sys/param.h>
     48  1.1  dyoung #include <sys/systm.h>
     49  1.1  dyoung #include <sys/mbuf.h>
     50  1.1  dyoung #include <sys/malloc.h>
     51  1.1  dyoung #include <sys/kernel.h>
     52  1.1  dyoung #include <sys/socket.h>
     53  1.1  dyoung #include <sys/sockio.h>
     54  1.1  dyoung #include <sys/endian.h>
     55  1.1  dyoung #include <sys/errno.h>
     56  1.4  dyoung #ifdef __FreeBSD__
     57  1.1  dyoung #include <sys/bus.h>
     58  1.4  dyoung #endif
     59  1.1  dyoung #include <sys/proc.h>
     60  1.1  dyoung #include <sys/sysctl.h>
     61  1.1  dyoung 
     62  1.2  dyoung #ifdef __FreeBSD__
     63  1.1  dyoung #include <machine/atomic.h>
     64  1.2  dyoung #endif
     65  1.1  dyoung 
     66  1.1  dyoung #include <net/if.h>
     67  1.1  dyoung #include <net/if_dl.h>
     68  1.1  dyoung #include <net/if_media.h>
     69  1.1  dyoung #include <net/if_arp.h>
     70  1.2  dyoung #ifdef __FreeBSD__
     71  1.1  dyoung #include <net/ethernet.h>
     72  1.4  dyoung #else
     73  1.4  dyoung #include <net/if_ether.h>
     74  1.2  dyoung #endif
     75  1.1  dyoung #include <net/if_llc.h>
     76  1.1  dyoung 
     77  1.1  dyoung #include <net80211/ieee80211_var.h>
     78  1.4  dyoung #include <net80211/ieee80211_compat.h>
     79  1.1  dyoung 
     80  1.5  dyoung #if NBPFILTER > 0
     81  1.1  dyoung #include <net/bpf.h>
     82  1.5  dyoung #endif
     83  1.1  dyoung 
     84  1.1  dyoung #ifdef INET
     85  1.1  dyoung #include <netinet/in.h>
     86  1.4  dyoung #ifdef __FreeBSD__
     87  1.1  dyoung #include <netinet/if_ether.h>
     88  1.4  dyoung #else
     89  1.4  dyoung #include <net/if_ether.h>
     90  1.4  dyoung #endif
     91  1.1  dyoung #endif
     92  1.1  dyoung 
     93  1.5  dyoung static void ieee80211_recv_pspoll(struct ieee80211com *,
     94  1.5  dyoung     struct mbuf *, int, u_int32_t);
     95  1.5  dyoung 
     96  1.1  dyoung /*
     97  1.1  dyoung  * Process a received frame.  The node associated with the sender
     98  1.1  dyoung  * should be supplied.  If nothing was found in the node table then
     99  1.1  dyoung  * the caller is assumed to supply a reference to ic_bss instead.
    100  1.1  dyoung  * The RSSI and a timestamp are also supplied.  The RSSI data is used
    101  1.1  dyoung  * during AP scanning to select a AP to associate with; it can have
    102  1.1  dyoung  * any units so long as values have consistent units and higher values
    103  1.1  dyoung  * mean ``better signal''.  The receive timestamp is currently not used
    104  1.1  dyoung  * by the 802.11 layer.
    105  1.1  dyoung  */
    106  1.1  dyoung void
    107  1.1  dyoung ieee80211_input(struct ifnet *ifp, struct mbuf *m, struct ieee80211_node *ni,
    108  1.1  dyoung 	int rssi, u_int32_t rstamp)
    109  1.1  dyoung {
    110  1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    111  1.1  dyoung 	struct ieee80211_frame *wh;
    112  1.1  dyoung 	struct ether_header *eh;
    113  1.1  dyoung 	struct mbuf *m1;
    114  1.1  dyoung 	int len;
    115  1.1  dyoung 	u_int8_t dir, subtype;
    116  1.1  dyoung 	u_int8_t *bssid;
    117  1.1  dyoung 	u_int16_t rxseq;
    118  1.1  dyoung 
    119  1.1  dyoung 	KASSERT(ni != NULL, ("null node"));
    120  1.1  dyoung 
    121  1.1  dyoung 	/* trim CRC here for WEP can find its own CRC at the end of packet. */
    122  1.1  dyoung 	if (m->m_flags & M_HASFCS) {
    123  1.1  dyoung 		m_adj(m, -IEEE80211_CRC_LEN);
    124  1.1  dyoung 		m->m_flags &= ~M_HASFCS;
    125  1.1  dyoung 	}
    126  1.1  dyoung 
    127  1.1  dyoung 	wh = mtod(m, struct ieee80211_frame *);
    128  1.1  dyoung 	if ((wh->i_fc[0] & IEEE80211_FC0_VERSION_MASK) !=
    129  1.1  dyoung 	    IEEE80211_FC0_VERSION_0) {
    130  1.1  dyoung 		if (ifp->if_flags & IFF_DEBUG)
    131  1.1  dyoung 			if_printf(ifp, "receive packet with wrong version: %x\n",
    132  1.1  dyoung 			    wh->i_fc[0]);
    133  1.1  dyoung 		ieee80211_unref_node(&ni);
    134  1.1  dyoung 		goto err;
    135  1.1  dyoung 	}
    136  1.1  dyoung 
    137  1.1  dyoung 	dir = wh->i_fc[1] & IEEE80211_FC1_DIR_MASK;
    138  1.1  dyoung 
    139  1.1  dyoung 	if (ic->ic_state != IEEE80211_S_SCAN) {
    140  1.1  dyoung 		switch (ic->ic_opmode) {
    141  1.1  dyoung 		case IEEE80211_M_STA:
    142  1.1  dyoung 			if (!IEEE80211_ADDR_EQ(wh->i_addr2, ni->ni_bssid)) {
    143  1.1  dyoung 				IEEE80211_DPRINTF2(("%s: discard frame from "
    144  1.1  dyoung 					"bss %s\n", __func__,
    145  1.1  dyoung 					ether_sprintf(wh->i_addr2)));
    146  1.1  dyoung 				/* not interested in */
    147  1.1  dyoung 				goto out;
    148  1.1  dyoung 			}
    149  1.1  dyoung 			break;
    150  1.1  dyoung 		case IEEE80211_M_IBSS:
    151  1.1  dyoung 		case IEEE80211_M_AHDEMO:
    152  1.1  dyoung 		case IEEE80211_M_HOSTAP:
    153  1.1  dyoung 			if (dir == IEEE80211_FC1_DIR_NODS)
    154  1.1  dyoung 				bssid = wh->i_addr3;
    155  1.1  dyoung 			else
    156  1.1  dyoung 				bssid = wh->i_addr1;
    157  1.1  dyoung 			if (!IEEE80211_ADDR_EQ(bssid, ic->ic_bss->ni_bssid) &&
    158  1.5  dyoung 			    !IEEE80211_ADDR_EQ(bssid, ifp->if_broadcastaddr) &&
    159  1.5  dyoung 			    (wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK) !=
    160  1.5  dyoung 			    IEEE80211_FC0_TYPE_CTL) {
    161  1.1  dyoung 				/* not interested in */
    162  1.1  dyoung 				IEEE80211_DPRINTF2(("%s: other bss %s\n",
    163  1.1  dyoung 					__func__, ether_sprintf(wh->i_addr3)));
    164  1.1  dyoung 				goto out;
    165  1.1  dyoung 			}
    166  1.1  dyoung 			break;
    167  1.1  dyoung 		case IEEE80211_M_MONITOR:
    168  1.1  dyoung 			/* NB: this should collect everything */
    169  1.1  dyoung 			goto out;
    170  1.1  dyoung 		default:
    171  1.1  dyoung 			/* XXX catch bad values */
    172  1.1  dyoung 			break;
    173  1.1  dyoung 		}
    174  1.1  dyoung 		ni->ni_rssi = rssi;
    175  1.1  dyoung 		ni->ni_rstamp = rstamp;
    176  1.1  dyoung 		rxseq = ni->ni_rxseq;
    177  1.1  dyoung 		ni->ni_rxseq =
    178  1.1  dyoung 		    le16toh(*(u_int16_t *)wh->i_seq) >> IEEE80211_SEQ_SEQ_SHIFT;
    179  1.1  dyoung 		/* TODO: fragment */
    180  1.1  dyoung 		if ((wh->i_fc[1] & IEEE80211_FC1_RETRY) &&
    181  1.1  dyoung 		    rxseq == ni->ni_rxseq) {
    182  1.1  dyoung 			/* duplicate, silently discarded */
    183  1.1  dyoung 			goto out;
    184  1.1  dyoung 		}
    185  1.1  dyoung 		ni->ni_inact = 0;
    186  1.1  dyoung 	}
    187  1.1  dyoung 
    188  1.5  dyoung 	if (ic->ic_set_tim != NULL &&
    189  1.5  dyoung 	    (wh->i_fc[1] & IEEE80211_FC1_PWR_MGT)
    190  1.5  dyoung 	    && ni->ni_pwrsave == 0) {
    191  1.5  dyoung 		/* turn on power save mode */
    192  1.5  dyoung 
    193  1.5  dyoung 		if (ifp->if_flags & IFF_DEBUG)
    194  1.5  dyoung 			printf("%s: power save mode on for %s\n",
    195  1.5  dyoung 			    ifp->if_xname, ether_sprintf(wh->i_addr2));
    196  1.5  dyoung 
    197  1.5  dyoung 		ni->ni_pwrsave = IEEE80211_PS_SLEEP;
    198  1.5  dyoung 	}
    199  1.5  dyoung 	if (ic->ic_set_tim != NULL &&
    200  1.5  dyoung 	    (wh->i_fc[1] & IEEE80211_FC1_PWR_MGT) == 0 &&
    201  1.5  dyoung 	    ni->ni_pwrsave != 0) {
    202  1.5  dyoung 		/* turn off power save mode, dequeue stored packets */
    203  1.5  dyoung 
    204  1.5  dyoung 		ni->ni_pwrsave = 0;
    205  1.5  dyoung 		if (ic->ic_set_tim)
    206  1.5  dyoung 			ic->ic_set_tim(ic, ni->ni_associd, 0);
    207  1.5  dyoung 
    208  1.5  dyoung 		if (ifp->if_flags & IFF_DEBUG)
    209  1.5  dyoung 			printf("%s: power save mode off for %s\n",
    210  1.5  dyoung 			    ifp->if_xname, ether_sprintf(wh->i_addr2));
    211  1.5  dyoung 
    212  1.5  dyoung 		while (!IF_IS_EMPTY(&ni->ni_savedq)) {
    213  1.5  dyoung 			struct mbuf *m;
    214  1.5  dyoung 			IF_DEQUEUE(&ni->ni_savedq, m);
    215  1.5  dyoung 			IF_ENQUEUE(&ic->ic_pwrsaveq, m);
    216  1.5  dyoung 			(*ifp->if_start)(ifp);
    217  1.5  dyoung 		}
    218  1.5  dyoung 	}
    219  1.5  dyoung 
    220  1.1  dyoung 	switch (wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK) {
    221  1.1  dyoung 	case IEEE80211_FC0_TYPE_DATA:
    222  1.1  dyoung 		switch (ic->ic_opmode) {
    223  1.1  dyoung 		case IEEE80211_M_STA:
    224  1.1  dyoung 			if (dir != IEEE80211_FC1_DIR_FROMDS)
    225  1.1  dyoung 				goto out;
    226  1.1  dyoung 			if ((ifp->if_flags & IFF_SIMPLEX) &&
    227  1.1  dyoung 			    IEEE80211_IS_MULTICAST(wh->i_addr1) &&
    228  1.1  dyoung 			    IEEE80211_ADDR_EQ(wh->i_addr3, ic->ic_myaddr)) {
    229  1.1  dyoung 				/*
    230  1.1  dyoung 				 * In IEEE802.11 network, multicast packet
    231  1.1  dyoung 				 * sent from me is broadcasted from AP.
    232  1.1  dyoung 				 * It should be silently discarded for
    233  1.1  dyoung 				 * SIMPLEX interface.
    234  1.1  dyoung 				 */
    235  1.1  dyoung 				goto out;
    236  1.1  dyoung 			}
    237  1.1  dyoung 			break;
    238  1.1  dyoung 		case IEEE80211_M_IBSS:
    239  1.1  dyoung 		case IEEE80211_M_AHDEMO:
    240  1.1  dyoung 			if (dir != IEEE80211_FC1_DIR_NODS)
    241  1.1  dyoung 				goto out;
    242  1.1  dyoung 			break;
    243  1.1  dyoung 		case IEEE80211_M_HOSTAP:
    244  1.1  dyoung 			if (dir != IEEE80211_FC1_DIR_TODS)
    245  1.1  dyoung 				goto out;
    246  1.1  dyoung 			/* check if source STA is associated */
    247  1.1  dyoung 			if (ni == ic->ic_bss) {
    248  1.1  dyoung 				IEEE80211_DPRINTF(("%s: data from unknown src "
    249  1.1  dyoung 					"%s\n", __func__,
    250  1.1  dyoung 					ether_sprintf(wh->i_addr2)));
    251  1.1  dyoung 				/* NB: caller deals with reference */
    252  1.1  dyoung 				ni = ieee80211_dup_bss(ic, wh->i_addr2);
    253  1.1  dyoung 				if (ni != NULL) {
    254  1.1  dyoung 					IEEE80211_SEND_MGMT(ic, ni,
    255  1.1  dyoung 					    IEEE80211_FC0_SUBTYPE_DEAUTH,
    256  1.1  dyoung 					    IEEE80211_REASON_NOT_AUTHED);
    257  1.1  dyoung 					ieee80211_free_node(ic, ni);
    258  1.1  dyoung 				}
    259  1.1  dyoung 				goto err;
    260  1.1  dyoung 			}
    261  1.1  dyoung 			if (ni->ni_associd == 0) {
    262  1.1  dyoung 				IEEE80211_DPRINTF(("ieee80211_input: "
    263  1.1  dyoung 				    "data from unassoc src %s\n",
    264  1.1  dyoung 				    ether_sprintf(wh->i_addr2)));
    265  1.1  dyoung 				IEEE80211_SEND_MGMT(ic, ni,
    266  1.1  dyoung 				    IEEE80211_FC0_SUBTYPE_DISASSOC,
    267  1.1  dyoung 				    IEEE80211_REASON_NOT_ASSOCED);
    268  1.1  dyoung 				ieee80211_unref_node(&ni);
    269  1.1  dyoung 				goto err;
    270  1.1  dyoung 			}
    271  1.1  dyoung 			break;
    272  1.1  dyoung 		case IEEE80211_M_MONITOR:
    273  1.1  dyoung 			break;
    274  1.1  dyoung 		}
    275  1.1  dyoung 		if (wh->i_fc[1] & IEEE80211_FC1_WEP) {
    276  1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_WEPON) {
    277  1.1  dyoung 				m = ieee80211_wep_crypt(ifp, m, 0);
    278  1.1  dyoung 				if (m == NULL)
    279  1.1  dyoung 					goto err;
    280  1.1  dyoung 				wh = mtod(m, struct ieee80211_frame *);
    281  1.1  dyoung 			} else
    282  1.1  dyoung 				goto out;
    283  1.1  dyoung 		}
    284  1.5  dyoung #if NBPFILTER > 0
    285  1.1  dyoung 		/* copy to listener after decrypt */
    286  1.1  dyoung 		if (ic->ic_rawbpf)
    287  1.1  dyoung 			bpf_mtap(ic->ic_rawbpf, m);
    288  1.5  dyoung #endif
    289  1.1  dyoung 		m = ieee80211_decap(ifp, m);
    290  1.1  dyoung 		if (m == NULL)
    291  1.1  dyoung 			goto err;
    292  1.1  dyoung 		ifp->if_ipackets++;
    293  1.1  dyoung 
    294  1.1  dyoung 		/* perform as a bridge within the AP */
    295  1.1  dyoung 		m1 = NULL;
    296  1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP) {
    297  1.1  dyoung 			eh = mtod(m, struct ether_header *);
    298  1.1  dyoung 			if (ETHER_IS_MULTICAST(eh->ether_dhost)) {
    299  1.1  dyoung 				m1 = m_copypacket(m, M_DONTWAIT);
    300  1.1  dyoung 				if (m1 == NULL)
    301  1.1  dyoung 					ifp->if_oerrors++;
    302  1.1  dyoung 				else
    303  1.1  dyoung 					m1->m_flags |= M_MCAST;
    304  1.1  dyoung 			} else {
    305  1.1  dyoung 				ni = ieee80211_find_node(ic, eh->ether_dhost);
    306  1.1  dyoung 				if (ni != NULL) {
    307  1.1  dyoung 					if (ni->ni_associd != 0) {
    308  1.1  dyoung 						m1 = m;
    309  1.1  dyoung 						m = NULL;
    310  1.1  dyoung 					}
    311  1.1  dyoung 					ieee80211_unref_node(&ni);
    312  1.1  dyoung 				}
    313  1.1  dyoung 			}
    314  1.1  dyoung 			if (m1 != NULL) {
    315  1.1  dyoung #ifdef ALTQ
    316  1.1  dyoung 				if (ALTQ_IS_ENABLED(&ifp->if_snd))
    317  1.1  dyoung 					altq_etherclassify(&ifp->if_snd, m1,
    318  1.1  dyoung 					    &pktattr);
    319  1.1  dyoung #endif
    320  1.1  dyoung 				len = m1->m_pkthdr.len;
    321  1.1  dyoung 				IF_ENQUEUE(&ifp->if_snd, m1);
    322  1.1  dyoung 				if (m != NULL)
    323  1.1  dyoung 					ifp->if_omcasts++;
    324  1.1  dyoung 				ifp->if_obytes += len;
    325  1.1  dyoung 			}
    326  1.1  dyoung 		}
    327  1.5  dyoung 		if (m != NULL) {
    328  1.5  dyoung #if NBPFILTER > 0
    329  1.5  dyoung 			/*
    330  1.5  dyoung 			 * If we forward packet into transmitter of the AP,
    331  1.5  dyoung 			 * we don't need to duplicate for DLT_EN10MB.
    332  1.5  dyoung 			 */
    333  1.5  dyoung 			if (ifp->if_bpf && m1 == NULL)
    334  1.5  dyoung 				bpf_mtap(ifp->if_bpf, m);
    335  1.5  dyoung #endif
    336  1.1  dyoung 			(*ifp->if_input)(ifp, m);
    337  1.5  dyoung 		}
    338  1.1  dyoung 		return;
    339  1.1  dyoung 
    340  1.1  dyoung 	case IEEE80211_FC0_TYPE_MGT:
    341  1.1  dyoung 		if (dir != IEEE80211_FC1_DIR_NODS)
    342  1.1  dyoung 			goto err;
    343  1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_AHDEMO)
    344  1.1  dyoung 			goto out;
    345  1.1  dyoung 		subtype = wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK;
    346  1.1  dyoung 
    347  1.1  dyoung 		/* drop frames without interest */
    348  1.1  dyoung 		if (ic->ic_state == IEEE80211_S_SCAN) {
    349  1.1  dyoung 			if (subtype != IEEE80211_FC0_SUBTYPE_BEACON &&
    350  1.1  dyoung 			    subtype != IEEE80211_FC0_SUBTYPE_PROBE_RESP)
    351  1.1  dyoung 				goto out;
    352  1.1  dyoung 		} else {
    353  1.1  dyoung 			if (ic->ic_opmode != IEEE80211_M_IBSS &&
    354  1.1  dyoung 			    subtype == IEEE80211_FC0_SUBTYPE_BEACON)
    355  1.1  dyoung 				goto out;
    356  1.1  dyoung 		}
    357  1.1  dyoung 
    358  1.1  dyoung 		if (ifp->if_flags & IFF_DEBUG) {
    359  1.1  dyoung 			/* avoid to print too many frames */
    360  1.1  dyoung 			int doprint = 0;
    361  1.1  dyoung 
    362  1.1  dyoung 			switch (subtype) {
    363  1.1  dyoung 			case IEEE80211_FC0_SUBTYPE_BEACON:
    364  1.1  dyoung 				if (ic->ic_state == IEEE80211_S_SCAN)
    365  1.1  dyoung 					doprint = 1;
    366  1.1  dyoung 				break;
    367  1.1  dyoung 			case IEEE80211_FC0_SUBTYPE_PROBE_REQ:
    368  1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_IBSS)
    369  1.1  dyoung 					doprint = 1;
    370  1.1  dyoung 				break;
    371  1.1  dyoung 			default:
    372  1.1  dyoung 				doprint = 1;
    373  1.1  dyoung 				break;
    374  1.1  dyoung 			}
    375  1.1  dyoung #ifdef IEEE80211_DEBUG
    376  1.1  dyoung 			doprint += ieee80211_debug;
    377  1.1  dyoung #endif
    378  1.1  dyoung 			if (doprint)
    379  1.1  dyoung 				if_printf(ifp, "received %s from %s rssi %d\n",
    380  1.1  dyoung 				    ieee80211_mgt_subtype_name[subtype
    381  1.1  dyoung 				    >> IEEE80211_FC0_SUBTYPE_SHIFT],
    382  1.1  dyoung 				    ether_sprintf(wh->i_addr2), rssi);
    383  1.1  dyoung 		}
    384  1.5  dyoung #if NBPFILTER > 0
    385  1.1  dyoung 		if (ic->ic_rawbpf)
    386  1.1  dyoung 			bpf_mtap(ic->ic_rawbpf, m);
    387  1.5  dyoung #endif
    388  1.1  dyoung 		(*ic->ic_recv_mgmt)(ic, m, ni, subtype, rssi, rstamp);
    389  1.1  dyoung 		m_freem(m);
    390  1.1  dyoung 		return;
    391  1.1  dyoung 
    392  1.1  dyoung 	case IEEE80211_FC0_TYPE_CTL:
    393  1.5  dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP)
    394  1.5  dyoung 			goto out;
    395  1.5  dyoung 		subtype = wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK;
    396  1.5  dyoung 		if (subtype == IEEE80211_FC0_SUBTYPE_PS_POLL) {
    397  1.5  dyoung 			/* Dump out a single packet from the host */
    398  1.5  dyoung 			if (ifp->if_flags & IFF_DEBUG)
    399  1.5  dyoung 				printf("%s: got power save probe from %s\n",
    400  1.5  dyoung 				    ifp->if_xname,
    401  1.5  dyoung 				    ether_sprintf(wh->i_addr2));
    402  1.5  dyoung 			ieee80211_recv_pspoll(ic, m, rssi, rstamp);
    403  1.5  dyoung 		}
    404  1.5  dyoung 		goto out;
    405  1.5  dyoung 
    406  1.1  dyoung 	default:
    407  1.1  dyoung 		IEEE80211_DPRINTF(("%s: bad type %x\n", __func__, wh->i_fc[0]));
    408  1.1  dyoung 		/* should not come here */
    409  1.1  dyoung 		break;
    410  1.1  dyoung 	}
    411  1.1  dyoung   err:
    412  1.1  dyoung 	ifp->if_ierrors++;
    413  1.1  dyoung   out:
    414  1.1  dyoung 	if (m != NULL) {
    415  1.5  dyoung #if NBPFILTER > 0
    416  1.1  dyoung 		if (ic->ic_rawbpf)
    417  1.1  dyoung 			bpf_mtap(ic->ic_rawbpf, m);
    418  1.5  dyoung #endif
    419  1.1  dyoung 		m_freem(m);
    420  1.1  dyoung 	}
    421  1.1  dyoung }
    422  1.1  dyoung 
    423  1.1  dyoung struct mbuf *
    424  1.1  dyoung ieee80211_decap(struct ifnet *ifp, struct mbuf *m)
    425  1.1  dyoung {
    426  1.1  dyoung 	struct ether_header *eh;
    427  1.1  dyoung 	struct ieee80211_frame wh;
    428  1.1  dyoung 	struct llc *llc;
    429  1.1  dyoung 
    430  1.1  dyoung 	if (m->m_len < sizeof(wh) + sizeof(*llc)) {
    431  1.1  dyoung 		m = m_pullup(m, sizeof(wh) + sizeof(*llc));
    432  1.1  dyoung 		if (m == NULL)
    433  1.1  dyoung 			return NULL;
    434  1.1  dyoung 	}
    435  1.1  dyoung 	memcpy(&wh, mtod(m, caddr_t), sizeof(wh));
    436  1.1  dyoung 	llc = (struct llc *)(mtod(m, caddr_t) + sizeof(wh));
    437  1.1  dyoung 	if (llc->llc_dsap == LLC_SNAP_LSAP && llc->llc_ssap == LLC_SNAP_LSAP &&
    438  1.1  dyoung 	    llc->llc_control == LLC_UI && llc->llc_snap.org_code[0] == 0 &&
    439  1.1  dyoung 	    llc->llc_snap.org_code[1] == 0 && llc->llc_snap.org_code[2] == 0) {
    440  1.1  dyoung 		m_adj(m, sizeof(wh) + sizeof(struct llc) - sizeof(*eh));
    441  1.1  dyoung 		llc = NULL;
    442  1.1  dyoung 	} else {
    443  1.1  dyoung 		m_adj(m, sizeof(wh) - sizeof(*eh));
    444  1.1  dyoung 	}
    445  1.1  dyoung 	eh = mtod(m, struct ether_header *);
    446  1.1  dyoung 	switch (wh.i_fc[1] & IEEE80211_FC1_DIR_MASK) {
    447  1.1  dyoung 	case IEEE80211_FC1_DIR_NODS:
    448  1.1  dyoung 		IEEE80211_ADDR_COPY(eh->ether_dhost, wh.i_addr1);
    449  1.1  dyoung 		IEEE80211_ADDR_COPY(eh->ether_shost, wh.i_addr2);
    450  1.1  dyoung 		break;
    451  1.1  dyoung 	case IEEE80211_FC1_DIR_TODS:
    452  1.1  dyoung 		IEEE80211_ADDR_COPY(eh->ether_dhost, wh.i_addr3);
    453  1.1  dyoung 		IEEE80211_ADDR_COPY(eh->ether_shost, wh.i_addr2);
    454  1.1  dyoung 		break;
    455  1.1  dyoung 	case IEEE80211_FC1_DIR_FROMDS:
    456  1.1  dyoung 		IEEE80211_ADDR_COPY(eh->ether_dhost, wh.i_addr1);
    457  1.1  dyoung 		IEEE80211_ADDR_COPY(eh->ether_shost, wh.i_addr3);
    458  1.1  dyoung 		break;
    459  1.1  dyoung 	case IEEE80211_FC1_DIR_DSTODS:
    460  1.1  dyoung 		/* not yet supported */
    461  1.1  dyoung 		IEEE80211_DPRINTF(("%s: DS to DS\n", __func__));
    462  1.1  dyoung 		m_freem(m);
    463  1.1  dyoung 		return NULL;
    464  1.1  dyoung 	}
    465  1.1  dyoung #ifdef ALIGNED_POINTER
    466  1.1  dyoung 	if (!ALIGNED_POINTER(mtod(m, caddr_t) + sizeof(*eh), u_int32_t)) {
    467  1.1  dyoung 		struct mbuf *n, *n0, **np;
    468  1.1  dyoung 		caddr_t newdata;
    469  1.1  dyoung 		int off, pktlen;
    470  1.1  dyoung 
    471  1.1  dyoung 		n0 = NULL;
    472  1.1  dyoung 		np = &n0;
    473  1.1  dyoung 		off = 0;
    474  1.1  dyoung 		pktlen = m->m_pkthdr.len;
    475  1.1  dyoung 		while (pktlen > off) {
    476  1.1  dyoung 			if (n0 == NULL) {
    477  1.1  dyoung 				MGETHDR(n, M_DONTWAIT, MT_DATA);
    478  1.1  dyoung 				if (n == NULL) {
    479  1.1  dyoung 					m_freem(m);
    480  1.1  dyoung 					return NULL;
    481  1.1  dyoung 				}
    482  1.4  dyoung #ifdef __FreeBSD__
    483  1.1  dyoung 				M_MOVE_PKTHDR(n, m);
    484  1.4  dyoung #else
    485  1.4  dyoung 				M_COPY_PKTHDR(n, m);
    486  1.4  dyoung #endif
    487  1.1  dyoung 				n->m_len = MHLEN;
    488  1.1  dyoung 			} else {
    489  1.1  dyoung 				MGET(n, M_DONTWAIT, MT_DATA);
    490  1.1  dyoung 				if (n == NULL) {
    491  1.1  dyoung 					m_freem(m);
    492  1.1  dyoung 					m_freem(n0);
    493  1.1  dyoung 					return NULL;
    494  1.1  dyoung 				}
    495  1.1  dyoung 				n->m_len = MLEN;
    496  1.1  dyoung 			}
    497  1.1  dyoung 			if (pktlen - off >= MINCLSIZE) {
    498  1.1  dyoung 				MCLGET(n, M_DONTWAIT);
    499  1.1  dyoung 				if (n->m_flags & M_EXT)
    500  1.1  dyoung 					n->m_len = n->m_ext.ext_size;
    501  1.1  dyoung 			}
    502  1.1  dyoung 			if (n0 == NULL) {
    503  1.1  dyoung 				newdata =
    504  1.1  dyoung 				    (caddr_t)ALIGN(n->m_data + sizeof(*eh)) -
    505  1.1  dyoung 				    sizeof(*eh);
    506  1.1  dyoung 				n->m_len -= newdata - n->m_data;
    507  1.1  dyoung 				n->m_data = newdata;
    508  1.1  dyoung 			}
    509  1.1  dyoung 			if (n->m_len > pktlen - off)
    510  1.1  dyoung 				n->m_len = pktlen - off;
    511  1.1  dyoung 			m_copydata(m, off, n->m_len, mtod(n, caddr_t));
    512  1.1  dyoung 			off += n->m_len;
    513  1.1  dyoung 			*np = n;
    514  1.1  dyoung 			np = &n->m_next;
    515  1.1  dyoung 		}
    516  1.1  dyoung 		m_freem(m);
    517  1.1  dyoung 		m = n0;
    518  1.1  dyoung 	}
    519  1.1  dyoung #endif /* ALIGNED_POINTER */
    520  1.1  dyoung 	if (llc != NULL) {
    521  1.1  dyoung 		eh = mtod(m, struct ether_header *);
    522  1.1  dyoung 		eh->ether_type = htons(m->m_pkthdr.len - sizeof(*eh));
    523  1.1  dyoung 	}
    524  1.1  dyoung 	return m;
    525  1.1  dyoung }
    526  1.1  dyoung 
    527  1.1  dyoung /*
    528  1.1  dyoung  * Install received rate set information in the node's state block.
    529  1.1  dyoung  */
    530  1.1  dyoung static int
    531  1.1  dyoung ieee80211_setup_rates(struct ieee80211com *ic, struct ieee80211_node *ni,
    532  1.1  dyoung 	u_int8_t *rates, u_int8_t *xrates, int flags)
    533  1.1  dyoung {
    534  1.1  dyoung 	struct ieee80211_rateset *rs = &ni->ni_rates;
    535  1.1  dyoung 
    536  1.1  dyoung 	memset(rs, 0, sizeof(*rs));
    537  1.1  dyoung 	rs->rs_nrates = rates[1];
    538  1.1  dyoung 	memcpy(rs->rs_rates, rates + 2, rs->rs_nrates);
    539  1.1  dyoung 	if (xrates != NULL) {
    540  1.1  dyoung 		u_int8_t nxrates;
    541  1.1  dyoung 		/*
    542  1.1  dyoung 		 * Tack on 11g extended supported rate element.
    543  1.1  dyoung 		 */
    544  1.1  dyoung 		nxrates = xrates[1];
    545  1.1  dyoung 		if (rs->rs_nrates + nxrates > IEEE80211_RATE_MAXSIZE) {
    546  1.1  dyoung 			nxrates = IEEE80211_RATE_MAXSIZE - rs->rs_nrates;
    547  1.1  dyoung 			IEEE80211_DPRINTF(("%s: extended rate set too large;"
    548  1.1  dyoung 				" only using %u of %u rates\n",
    549  1.1  dyoung 				__func__, nxrates, xrates[1]));
    550  1.1  dyoung 		}
    551  1.1  dyoung 		memcpy(rs->rs_rates + rs->rs_nrates, xrates+2, nxrates);
    552  1.1  dyoung 		rs->rs_nrates += nxrates;
    553  1.1  dyoung 	}
    554  1.1  dyoung 	return ieee80211_fix_rate(ic, ni, flags);
    555  1.1  dyoung }
    556  1.1  dyoung 
    557  1.1  dyoung /* XXX statistics */
    558  1.1  dyoung /* Verify the existence and length of __elem or get out. */
    559  1.1  dyoung #define IEEE80211_VERIFY_ELEMENT(__elem, __maxlen) do {			\
    560  1.1  dyoung 	if ((__elem) == NULL) {						\
    561  1.1  dyoung 		IEEE80211_DPRINTF(("%s: no " #__elem "in %s frame\n",	\
    562  1.1  dyoung 			__func__, ieee80211_mgt_subtype_name[subtype >>	\
    563  1.1  dyoung 				IEEE80211_FC0_SUBTYPE_SHIFT]));		\
    564  1.1  dyoung 		return;							\
    565  1.1  dyoung 	}								\
    566  1.1  dyoung 	if ((__elem)[1] > (__maxlen)) {					\
    567  1.1  dyoung 		IEEE80211_DPRINTF(("%s: bad " #__elem " len %d in %s "	\
    568  1.1  dyoung 			"frame from %s\n", __func__, (__elem)[1],	\
    569  1.1  dyoung 			ieee80211_mgt_subtype_name[subtype >>		\
    570  1.1  dyoung 				IEEE80211_FC0_SUBTYPE_SHIFT],		\
    571  1.1  dyoung 			ether_sprintf(wh->i_addr2)));			\
    572  1.1  dyoung 		return;							\
    573  1.1  dyoung 	}								\
    574  1.1  dyoung } while (0)
    575  1.1  dyoung 
    576  1.1  dyoung #define	IEEE80211_VERIFY_LENGTH(_len, _minlen) do {			\
    577  1.1  dyoung 	if ((_len) < (_minlen)) {					\
    578  1.1  dyoung 		IEEE80211_DPRINTF(("%s: %s frame too short from %s\n",	\
    579  1.1  dyoung 			__func__,					\
    580  1.1  dyoung 			ieee80211_mgt_subtype_name[subtype >>		\
    581  1.1  dyoung 				IEEE80211_FC0_SUBTYPE_SHIFT],		\
    582  1.1  dyoung 			ether_sprintf(wh->i_addr2)));			\
    583  1.1  dyoung 		return;							\
    584  1.1  dyoung 	}								\
    585  1.1  dyoung } while (0)
    586  1.1  dyoung 
    587  1.1  dyoung void
    588  1.1  dyoung ieee80211_recv_mgmt(struct ieee80211com *ic, struct mbuf *m0,
    589  1.1  dyoung 	struct ieee80211_node *ni,
    590  1.1  dyoung 	int subtype, int rssi, u_int32_t rstamp)
    591  1.1  dyoung {
    592  1.1  dyoung #define	ISPROBE(_st)	((_st) == IEEE80211_FC0_SUBTYPE_PROBE_RESP)
    593  1.1  dyoung 	struct ifnet *ifp = &ic->ic_if;
    594  1.1  dyoung 	struct ieee80211_frame *wh;
    595  1.1  dyoung 	u_int8_t *frm, *efrm;
    596  1.1  dyoung 	u_int8_t *ssid, *rates, *xrates;
    597  1.1  dyoung 	int reassoc, resp, newassoc, allocbs;
    598  1.1  dyoung 
    599  1.1  dyoung 	wh = mtod(m0, struct ieee80211_frame *);
    600  1.1  dyoung 	frm = (u_int8_t *)&wh[1];
    601  1.1  dyoung 	efrm = mtod(m0, u_int8_t *) + m0->m_len;
    602  1.1  dyoung 	switch (subtype) {
    603  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_PROBE_RESP:
    604  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_BEACON: {
    605  1.1  dyoung 		u_int8_t *tstamp, *bintval, *capinfo, *country;
    606  1.1  dyoung 		u_int8_t chan, bchan, fhindex, erp;
    607  1.1  dyoung 		u_int16_t fhdwell;
    608  1.1  dyoung 
    609  1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_IBSS &&
    610  1.1  dyoung 		    ic->ic_state != IEEE80211_S_SCAN) {
    611  1.1  dyoung 			/* XXX: may be useful for background scan */
    612  1.1  dyoung 			return;
    613  1.1  dyoung 		}
    614  1.1  dyoung 
    615  1.1  dyoung 		/*
    616  1.1  dyoung 		 * beacon/probe response frame format
    617  1.1  dyoung 		 *	[8] time stamp
    618  1.1  dyoung 		 *	[2] beacon interval
    619  1.1  dyoung 		 *	[2] capability information
    620  1.1  dyoung 		 *	[tlv] ssid
    621  1.1  dyoung 		 *	[tlv] supported rates
    622  1.1  dyoung 		 *	[tlv] country information
    623  1.1  dyoung 		 *	[tlv] parameter set (FH/DS)
    624  1.1  dyoung 		 *	[tlv] erp information
    625  1.1  dyoung 		 *	[tlv] extended supported rates
    626  1.1  dyoung 		 */
    627  1.1  dyoung 		IEEE80211_VERIFY_LENGTH(efrm - frm, 12);
    628  1.1  dyoung 		tstamp  = frm;	frm += 8;
    629  1.1  dyoung 		bintval = frm;	frm += 2;
    630  1.1  dyoung 		capinfo = frm;	frm += 2;
    631  1.1  dyoung 		ssid = rates = xrates = country = NULL;
    632  1.1  dyoung 		bchan = ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan);
    633  1.1  dyoung 		chan = bchan;
    634  1.1  dyoung 		fhdwell = 0;
    635  1.1  dyoung 		fhindex = 0;
    636  1.1  dyoung 		erp = 0;
    637  1.1  dyoung 		while (frm < efrm) {
    638  1.1  dyoung 			switch (*frm) {
    639  1.1  dyoung 			case IEEE80211_ELEMID_SSID:
    640  1.1  dyoung 				ssid = frm;
    641  1.1  dyoung 				break;
    642  1.1  dyoung 			case IEEE80211_ELEMID_RATES:
    643  1.1  dyoung 				rates = frm;
    644  1.1  dyoung 				break;
    645  1.1  dyoung 			case IEEE80211_ELEMID_COUNTRY:
    646  1.1  dyoung 				country = frm;
    647  1.1  dyoung 				break;
    648  1.1  dyoung 			case IEEE80211_ELEMID_FHPARMS:
    649  1.1  dyoung 				if (ic->ic_phytype == IEEE80211_T_FH) {
    650  1.1  dyoung 					fhdwell = (frm[3] << 8) | frm[2];
    651  1.1  dyoung 					chan = IEEE80211_FH_CHAN(frm[4], frm[5]);
    652  1.1  dyoung 					fhindex = frm[6];
    653  1.1  dyoung 				}
    654  1.1  dyoung 				break;
    655  1.1  dyoung 			case IEEE80211_ELEMID_DSPARMS:
    656  1.1  dyoung 				/*
    657  1.1  dyoung 				 * XXX hack this since depending on phytype
    658  1.1  dyoung 				 * is problematic for multi-mode devices.
    659  1.1  dyoung 				 */
    660  1.1  dyoung 				if (ic->ic_phytype != IEEE80211_T_FH)
    661  1.1  dyoung 					chan = frm[2];
    662  1.1  dyoung 				break;
    663  1.1  dyoung 			case IEEE80211_ELEMID_TIM:
    664  1.1  dyoung 				break;
    665  1.1  dyoung 			case IEEE80211_ELEMID_XRATES:
    666  1.1  dyoung 				xrates = frm;
    667  1.1  dyoung 				break;
    668  1.1  dyoung 			case IEEE80211_ELEMID_ERP:
    669  1.1  dyoung 				if (frm[1] != 1) {
    670  1.1  dyoung 					IEEE80211_DPRINTF(("%s: invalid ERP "
    671  1.1  dyoung 						"element; length %u, expecting "
    672  1.1  dyoung 						"1\n", __func__, frm[1]));
    673  1.1  dyoung 					break;
    674  1.1  dyoung 				}
    675  1.1  dyoung 				erp = frm[2];
    676  1.1  dyoung 				break;
    677  1.1  dyoung 			default:
    678  1.1  dyoung 				IEEE80211_DPRINTF(("%s: element id %u/len %u "
    679  1.1  dyoung 					"ignored\n", __func__, *frm, frm[1]));
    680  1.1  dyoung 				break;
    681  1.1  dyoung 			}
    682  1.1  dyoung 			frm += frm[1] + 2;
    683  1.1  dyoung 		}
    684  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(rates, IEEE80211_RATE_MAXSIZE);
    685  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(ssid, IEEE80211_NWID_LEN);
    686  1.1  dyoung 		if (
    687  1.1  dyoung #if IEEE80211_CHAN_MAX < 255
    688  1.1  dyoung 		    chan > IEEE80211_CHAN_MAX ||
    689  1.1  dyoung #endif
    690  1.1  dyoung 		    isclr(ic->ic_chan_active, chan)) {
    691  1.1  dyoung 			IEEE80211_DPRINTF(("%s: ignore %s with invalid channel "
    692  1.1  dyoung 				"%u\n", __func__,
    693  1.1  dyoung 				ISPROBE(subtype) ? "probe response" : "beacon",
    694  1.1  dyoung 				chan));
    695  1.1  dyoung 			return;
    696  1.1  dyoung 		}
    697  1.1  dyoung 		if (chan != bchan) {
    698  1.1  dyoung 			/*
    699  1.1  dyoung 			 * Frame was received on a channel different from the
    700  1.1  dyoung 			 * one indicated in the DS/FH params element id;
    701  1.1  dyoung 			 * silently discard it.
    702  1.1  dyoung 			 *
    703  1.1  dyoung 			 * NB: this can happen due to signal leakage.
    704  1.1  dyoung 			 */
    705  1.1  dyoung 			IEEE80211_DPRINTF(("%s: ignore %s on channel %u marked "
    706  1.1  dyoung 				"for channel %u\n", __func__,
    707  1.1  dyoung 				ISPROBE(subtype) ? "probe response" : "beacon",
    708  1.1  dyoung 				bchan, chan));
    709  1.1  dyoung 			/* XXX statistic */
    710  1.1  dyoung 			return;
    711  1.1  dyoung 		}
    712  1.1  dyoung 
    713  1.1  dyoung 		/*
    714  1.1  dyoung 		 * Use mac and channel for lookup so we collect all
    715  1.1  dyoung 		 * potential AP's when scanning.  Otherwise we may
    716  1.1  dyoung 		 * see the same AP on multiple channels and will only
    717  1.1  dyoung 		 * record the last one.  We could filter APs here based
    718  1.1  dyoung 		 * on rssi, etc. but leave that to the end of the scan
    719  1.1  dyoung 		 * so we can keep the selection criteria in one spot.
    720  1.1  dyoung 		 * This may result in a bloat of the scanned AP list but
    721  1.1  dyoung 		 * it shouldn't be too much.
    722  1.1  dyoung 		 */
    723  1.1  dyoung 		ni = ieee80211_lookup_node(ic, wh->i_addr2,
    724  1.1  dyoung 				&ic->ic_channels[chan]);
    725  1.1  dyoung #ifdef IEEE80211_DEBUG
    726  1.1  dyoung 		if (ieee80211_debug &&
    727  1.1  dyoung 		    (ni == NULL || ic->ic_state == IEEE80211_S_SCAN)) {
    728  1.1  dyoung 			printf("%s: %s%s on chan %u (bss chan %u) ",
    729  1.1  dyoung 			    __func__, (ni == NULL ? "new " : ""),
    730  1.1  dyoung 			    ISPROBE(subtype) ? "probe response" : "beacon",
    731  1.1  dyoung 			    chan, bchan);
    732  1.1  dyoung 			ieee80211_print_essid(ssid + 2, ssid[1]);
    733  1.1  dyoung 			printf(" from %s\n", ether_sprintf(wh->i_addr2));
    734  1.1  dyoung 			printf("%s: caps 0x%x bintval %u erp 0x%x\n",
    735  1.1  dyoung 				__func__, le16toh(*(u_int16_t *)capinfo),
    736  1.1  dyoung 				le16toh(*(u_int16_t *)bintval), erp);
    737  1.4  dyoung 			if (country) {
    738  1.4  dyoung 				int i;
    739  1.4  dyoung 				printf("%s: country info", __func__);
    740  1.4  dyoung 				for (i = 0; i < country[1]; i++)
    741  1.4  dyoung 					printf(" %02x", country[i+2]);
    742  1.4  dyoung 				printf("\n");
    743  1.4  dyoung 			}
    744  1.1  dyoung 		}
    745  1.1  dyoung #endif
    746  1.1  dyoung 		if (ni == NULL) {
    747  1.1  dyoung 			ni = ieee80211_alloc_node(ic, wh->i_addr2);
    748  1.1  dyoung 			if (ni == NULL)
    749  1.1  dyoung 				return;
    750  1.1  dyoung 			ni->ni_esslen = ssid[1];
    751  1.1  dyoung 			memset(ni->ni_essid, 0, sizeof(ni->ni_essid));
    752  1.1  dyoung 			memcpy(ni->ni_essid, ssid + 2, ssid[1]);
    753  1.2  dyoung 		} else if (ssid[1] != 0) {
    754  1.1  dyoung 			/*
    755  1.1  dyoung 			 * Update ESSID at probe response to adopt hidden AP by
    756  1.1  dyoung 			 * Lucent/Cisco, which announces null ESSID in beacon.
    757  1.1  dyoung 			 */
    758  1.1  dyoung 			ni->ni_esslen = ssid[1];
    759  1.1  dyoung 			memset(ni->ni_essid, 0, sizeof(ni->ni_essid));
    760  1.1  dyoung 			memcpy(ni->ni_essid, ssid + 2, ssid[1]);
    761  1.1  dyoung 		}
    762  1.1  dyoung 		IEEE80211_ADDR_COPY(ni->ni_bssid, wh->i_addr3);
    763  1.1  dyoung 		ni->ni_rssi = rssi;
    764  1.1  dyoung 		ni->ni_rstamp = rstamp;
    765  1.1  dyoung 		memcpy(ni->ni_tstamp, tstamp, sizeof(ni->ni_tstamp));
    766  1.1  dyoung 		ni->ni_intval = le16toh(*(u_int16_t *)bintval);
    767  1.1  dyoung 		ni->ni_capinfo = le16toh(*(u_int16_t *)capinfo);
    768  1.1  dyoung 		/* XXX validate channel # */
    769  1.1  dyoung 		ni->ni_chan = &ic->ic_channels[chan];
    770  1.1  dyoung 		ni->ni_fhdwell = fhdwell;
    771  1.1  dyoung 		ni->ni_fhindex = fhindex;
    772  1.1  dyoung 		ni->ni_erp = erp;
    773  1.1  dyoung 		/* NB: must be after ni_chan is setup */
    774  1.1  dyoung 		ieee80211_setup_rates(ic, ni, rates, xrates, IEEE80211_F_DOSORT);
    775  1.1  dyoung 		ieee80211_unref_node(&ni);
    776  1.1  dyoung 		break;
    777  1.1  dyoung 	}
    778  1.1  dyoung 
    779  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_PROBE_REQ: {
    780  1.1  dyoung 		u_int8_t rate;
    781  1.1  dyoung 
    782  1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_STA)
    783  1.1  dyoung 			return;
    784  1.1  dyoung 		if (ic->ic_state != IEEE80211_S_RUN)
    785  1.1  dyoung 			return;
    786  1.1  dyoung 
    787  1.1  dyoung 		/*
    788  1.1  dyoung 		 * prreq frame format
    789  1.1  dyoung 		 *	[tlv] ssid
    790  1.1  dyoung 		 *	[tlv] supported rates
    791  1.1  dyoung 		 *	[tlv] extended supported rates
    792  1.1  dyoung 		 */
    793  1.1  dyoung 		ssid = rates = xrates = NULL;
    794  1.1  dyoung 		while (frm < efrm) {
    795  1.1  dyoung 			switch (*frm) {
    796  1.1  dyoung 			case IEEE80211_ELEMID_SSID:
    797  1.1  dyoung 				ssid = frm;
    798  1.1  dyoung 				break;
    799  1.1  dyoung 			case IEEE80211_ELEMID_RATES:
    800  1.1  dyoung 				rates = frm;
    801  1.1  dyoung 				break;
    802  1.1  dyoung 			case IEEE80211_ELEMID_XRATES:
    803  1.1  dyoung 				xrates = frm;
    804  1.1  dyoung 				break;
    805  1.1  dyoung 			}
    806  1.1  dyoung 			frm += frm[1] + 2;
    807  1.1  dyoung 		}
    808  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(rates, IEEE80211_RATE_MAXSIZE);
    809  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(ssid, IEEE80211_NWID_LEN);
    810  1.1  dyoung 		if (ssid[1] != 0 &&
    811  1.1  dyoung 		    (ssid[1] != ic->ic_bss->ni_esslen ||
    812  1.1  dyoung 		    memcmp(ssid + 2, ic->ic_bss->ni_essid, ic->ic_bss->ni_esslen) != 0)) {
    813  1.1  dyoung #ifdef IEEE80211_DEBUG
    814  1.1  dyoung 			if (ieee80211_debug) {
    815  1.5  dyoung 				printf("%s: ssid mismatch ", __func__);
    816  1.1  dyoung 				ieee80211_print_essid(ssid + 2, ssid[1]);
    817  1.1  dyoung 				printf(" from %s\n", ether_sprintf(wh->i_addr2));
    818  1.1  dyoung 			}
    819  1.1  dyoung #endif
    820  1.1  dyoung 			return;
    821  1.1  dyoung 		}
    822  1.1  dyoung 
    823  1.1  dyoung 		if (ni == ic->ic_bss) {
    824  1.1  dyoung 			ni = ieee80211_dup_bss(ic, wh->i_addr2);
    825  1.1  dyoung 			if (ni == NULL)
    826  1.1  dyoung 				return;
    827  1.1  dyoung 			IEEE80211_DPRINTF(("%s: new req from %s\n",
    828  1.1  dyoung 				__func__, ether_sprintf(wh->i_addr2)));
    829  1.1  dyoung 			allocbs = 1;
    830  1.1  dyoung 		} else
    831  1.1  dyoung 			allocbs = 0;
    832  1.1  dyoung 		ni->ni_rssi = rssi;
    833  1.1  dyoung 		ni->ni_rstamp = rstamp;
    834  1.1  dyoung 		rate = ieee80211_setup_rates(ic, ni, rates, xrates,
    835  1.1  dyoung 				IEEE80211_F_DOSORT | IEEE80211_F_DOFRATE
    836  1.1  dyoung 				| IEEE80211_F_DONEGO | IEEE80211_F_DODEL);
    837  1.1  dyoung 		if (rate & IEEE80211_RATE_BASIC) {
    838  1.1  dyoung 			IEEE80211_DPRINTF(("%s: rate negotiation failed: %s\n",
    839  1.1  dyoung 				__func__,ether_sprintf(wh->i_addr2)));
    840  1.1  dyoung 		} else {
    841  1.1  dyoung 			IEEE80211_SEND_MGMT(ic, ni,
    842  1.1  dyoung 				IEEE80211_FC0_SUBTYPE_PROBE_RESP, 0);
    843  1.1  dyoung 		}
    844  1.1  dyoung 		if (allocbs) {
    845  1.1  dyoung 			/* XXX just use free? */
    846  1.1  dyoung 			if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    847  1.1  dyoung 				ieee80211_free_node(ic, ni);
    848  1.1  dyoung 			else
    849  1.1  dyoung 				ieee80211_unref_node(&ni);
    850  1.1  dyoung 		}
    851  1.1  dyoung 		break;
    852  1.1  dyoung 	}
    853  1.1  dyoung 
    854  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_AUTH: {
    855  1.1  dyoung 		u_int16_t algo, seq, status;
    856  1.1  dyoung 		/*
    857  1.1  dyoung 		 * auth frame format
    858  1.1  dyoung 		 *	[2] algorithm
    859  1.1  dyoung 		 *	[2] sequence
    860  1.1  dyoung 		 *	[2] status
    861  1.1  dyoung 		 *	[tlv*] challenge
    862  1.1  dyoung 		 */
    863  1.1  dyoung 		IEEE80211_VERIFY_LENGTH(efrm - frm, 6);
    864  1.1  dyoung 		algo   = le16toh(*(u_int16_t *)frm);
    865  1.1  dyoung 		seq    = le16toh(*(u_int16_t *)(frm + 2));
    866  1.1  dyoung 		status = le16toh(*(u_int16_t *)(frm + 4));
    867  1.1  dyoung 		if (algo != IEEE80211_AUTH_ALG_OPEN) {
    868  1.1  dyoung 			/* TODO: shared key auth */
    869  1.1  dyoung 			IEEE80211_DPRINTF(("%s: unsupported auth %d from %s\n",
    870  1.1  dyoung 				__func__, algo, ether_sprintf(wh->i_addr2)));
    871  1.1  dyoung 			return;
    872  1.1  dyoung 		}
    873  1.1  dyoung 		switch (ic->ic_opmode) {
    874  1.1  dyoung 		case IEEE80211_M_IBSS:
    875  1.1  dyoung 			if (ic->ic_state != IEEE80211_S_RUN || seq != 1)
    876  1.1  dyoung 				return;
    877  1.1  dyoung 			ieee80211_new_state(ic, IEEE80211_S_AUTH,
    878  1.1  dyoung 			    wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK);
    879  1.1  dyoung 			break;
    880  1.1  dyoung 
    881  1.1  dyoung 		case IEEE80211_M_AHDEMO:
    882  1.1  dyoung 			/* should not come here */
    883  1.1  dyoung 			break;
    884  1.1  dyoung 
    885  1.1  dyoung 		case IEEE80211_M_HOSTAP:
    886  1.1  dyoung 			if (ic->ic_state != IEEE80211_S_RUN || seq != 1)
    887  1.1  dyoung 				return;
    888  1.1  dyoung 			if (ni == ic->ic_bss) {
    889  1.1  dyoung 				ni = ieee80211_alloc_node(ic, wh->i_addr2);
    890  1.1  dyoung 				if (ni == NULL)
    891  1.1  dyoung 					return;
    892  1.1  dyoung 				IEEE80211_ADDR_COPY(ni->ni_bssid, ic->ic_bss->ni_bssid);
    893  1.1  dyoung 				ni->ni_rssi = rssi;
    894  1.1  dyoung 				ni->ni_rstamp = rstamp;
    895  1.1  dyoung 				ni->ni_chan = ic->ic_bss->ni_chan;
    896  1.1  dyoung 				allocbs = 1;
    897  1.1  dyoung 			} else
    898  1.1  dyoung 				allocbs = 0;
    899  1.1  dyoung 			IEEE80211_SEND_MGMT(ic, ni,
    900  1.1  dyoung 				IEEE80211_FC0_SUBTYPE_AUTH, 2);
    901  1.1  dyoung 			if (ifp->if_flags & IFF_DEBUG)
    902  1.1  dyoung 				if_printf(ifp, "station %s %s authenticated\n",
    903  1.1  dyoung 				    (allocbs ? "newly" : "already"),
    904  1.1  dyoung 				    ether_sprintf(ni->ni_macaddr));
    905  1.1  dyoung 			break;
    906  1.1  dyoung 
    907  1.1  dyoung 		case IEEE80211_M_STA:
    908  1.1  dyoung 			if (ic->ic_state != IEEE80211_S_AUTH || seq != 2)
    909  1.1  dyoung 				return;
    910  1.1  dyoung 			if (status != 0) {
    911  1.1  dyoung 				if_printf(&ic->ic_if,
    912  1.1  dyoung 				    "authentication failed (reason %d) for %s\n",
    913  1.1  dyoung 				    status,
    914  1.1  dyoung 				    ether_sprintf(wh->i_addr3));
    915  1.1  dyoung 				if (ni != ic->ic_bss)
    916  1.1  dyoung 					ni->ni_fails++;
    917  1.1  dyoung 				return;
    918  1.1  dyoung 			}
    919  1.1  dyoung 			ieee80211_new_state(ic, IEEE80211_S_ASSOC,
    920  1.1  dyoung 			    wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK);
    921  1.1  dyoung 			break;
    922  1.1  dyoung 		case IEEE80211_M_MONITOR:
    923  1.1  dyoung 			break;
    924  1.1  dyoung 		}
    925  1.1  dyoung 		break;
    926  1.1  dyoung 	}
    927  1.1  dyoung 
    928  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_ASSOC_REQ:
    929  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_REASSOC_REQ: {
    930  1.1  dyoung 		u_int16_t capinfo, bintval;
    931  1.1  dyoung 
    932  1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP ||
    933  1.1  dyoung 		    (ic->ic_state != IEEE80211_S_RUN))
    934  1.1  dyoung 			return;
    935  1.1  dyoung 
    936  1.1  dyoung 		if (subtype == IEEE80211_FC0_SUBTYPE_REASSOC_REQ) {
    937  1.1  dyoung 			reassoc = 1;
    938  1.1  dyoung 			resp = IEEE80211_FC0_SUBTYPE_REASSOC_RESP;
    939  1.1  dyoung 		} else {
    940  1.1  dyoung 			reassoc = 0;
    941  1.1  dyoung 			resp = IEEE80211_FC0_SUBTYPE_ASSOC_RESP;
    942  1.1  dyoung 		}
    943  1.1  dyoung 		/*
    944  1.1  dyoung 		 * asreq frame format
    945  1.1  dyoung 		 *	[2] capability information
    946  1.1  dyoung 		 *	[2] listen interval
    947  1.1  dyoung 		 *	[6*] current AP address (reassoc only)
    948  1.1  dyoung 		 *	[tlv] ssid
    949  1.1  dyoung 		 *	[tlv] supported rates
    950  1.1  dyoung 		 *	[tlv] extended supported rates
    951  1.1  dyoung 		 */
    952  1.1  dyoung 		IEEE80211_VERIFY_LENGTH(efrm - frm, (reassoc ? 10 : 4));
    953  1.1  dyoung 		if (!IEEE80211_ADDR_EQ(wh->i_addr3, ic->ic_bss->ni_bssid)) {
    954  1.1  dyoung 			IEEE80211_DPRINTF(("%s: ignore other bss from %s\n",
    955  1.1  dyoung 				__func__, ether_sprintf(wh->i_addr2)));
    956  1.1  dyoung 			return;
    957  1.1  dyoung 		}
    958  1.1  dyoung 		capinfo = le16toh(*(u_int16_t *)frm);	frm += 2;
    959  1.1  dyoung 		bintval = le16toh(*(u_int16_t *)frm);	frm += 2;
    960  1.1  dyoung 		if (reassoc)
    961  1.1  dyoung 			frm += 6;	/* ignore current AP info */
    962  1.1  dyoung 		ssid = rates = xrates = NULL;
    963  1.1  dyoung 		while (frm < efrm) {
    964  1.1  dyoung 			switch (*frm) {
    965  1.1  dyoung 			case IEEE80211_ELEMID_SSID:
    966  1.1  dyoung 				ssid = frm;
    967  1.1  dyoung 				break;
    968  1.1  dyoung 			case IEEE80211_ELEMID_RATES:
    969  1.1  dyoung 				rates = frm;
    970  1.1  dyoung 				break;
    971  1.1  dyoung 			case IEEE80211_ELEMID_XRATES:
    972  1.1  dyoung 				xrates = frm;
    973  1.1  dyoung 				break;
    974  1.1  dyoung 			}
    975  1.1  dyoung 			frm += frm[1] + 2;
    976  1.1  dyoung 		}
    977  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(rates, IEEE80211_RATE_MAXSIZE);
    978  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(ssid, IEEE80211_NWID_LEN);
    979  1.1  dyoung 		if (ssid[1] != ic->ic_bss->ni_esslen ||
    980  1.1  dyoung 		    memcmp(ssid + 2, ic->ic_bss->ni_essid, ssid[1]) != 0) {
    981  1.1  dyoung #ifdef IEEE80211_DEBUG
    982  1.1  dyoung 			if (ieee80211_debug) {
    983  1.5  dyoung 				printf("%s: ssid mismatch ", __func__);
    984  1.1  dyoung 				ieee80211_print_essid(ssid + 2, ssid[1]);
    985  1.1  dyoung 				printf(" from %s\n", ether_sprintf(wh->i_addr2));
    986  1.1  dyoung 			}
    987  1.1  dyoung #endif
    988  1.1  dyoung 			return;
    989  1.1  dyoung 		}
    990  1.1  dyoung 		if (ni == ic->ic_bss) {
    991  1.1  dyoung 			IEEE80211_DPRINTF(("%s: not authenticated for %s\n",
    992  1.1  dyoung 				__func__, ether_sprintf(wh->i_addr2)));
    993  1.1  dyoung 			ni = ieee80211_dup_bss(ic, wh->i_addr2);
    994  1.1  dyoung 			if (ni != NULL) {
    995  1.1  dyoung 				IEEE80211_SEND_MGMT(ic, ni,
    996  1.1  dyoung 				    IEEE80211_FC0_SUBTYPE_DEAUTH,
    997  1.1  dyoung 				    IEEE80211_REASON_ASSOC_NOT_AUTHED);
    998  1.1  dyoung 				ieee80211_free_node(ic, ni);
    999  1.1  dyoung 			}
   1000  1.1  dyoung 			return;
   1001  1.1  dyoung 		}
   1002  1.1  dyoung 		/* XXX per-node cipher suite */
   1003  1.1  dyoung 		/* XXX some stations use the privacy bit for handling APs
   1004  1.1  dyoung 		       that suport both encrypted and unencrypted traffic */
   1005  1.1  dyoung 		if ((capinfo & IEEE80211_CAPINFO_ESS) == 0 ||
   1006  1.1  dyoung 		    (capinfo & IEEE80211_CAPINFO_PRIVACY) !=
   1007  1.1  dyoung 		    ((ic->ic_flags & IEEE80211_F_WEPON) ?
   1008  1.1  dyoung 		     IEEE80211_CAPINFO_PRIVACY : 0)) {
   1009  1.1  dyoung 			IEEE80211_DPRINTF(("%s: capability mismatch %x for %s\n",
   1010  1.1  dyoung 				__func__, capinfo, ether_sprintf(wh->i_addr2)));
   1011  1.5  dyoung 			IEEE80211_AID_CLR(ni->ni_associd, ic->ic_aid_bitmap);
   1012  1.1  dyoung 			ni->ni_associd = 0;
   1013  1.1  dyoung 			IEEE80211_SEND_MGMT(ic, ni, resp,
   1014  1.1  dyoung 				IEEE80211_STATUS_CAPINFO);
   1015  1.1  dyoung 			return;
   1016  1.1  dyoung 		}
   1017  1.1  dyoung 		ieee80211_setup_rates(ic, ni, rates, xrates,
   1018  1.1  dyoung 				IEEE80211_F_DOSORT | IEEE80211_F_DOFRATE |
   1019  1.1  dyoung 				IEEE80211_F_DONEGO | IEEE80211_F_DODEL);
   1020  1.1  dyoung 		if (ni->ni_rates.rs_nrates == 0) {
   1021  1.5  dyoung 			IEEE80211_DPRINTF(("%s: rate mismatch for %s\n",
   1022  1.1  dyoung 				__func__, ether_sprintf(wh->i_addr2)));
   1023  1.5  dyoung 			IEEE80211_AID_CLR(ni->ni_associd, ic->ic_aid_bitmap);
   1024  1.1  dyoung 			ni->ni_associd = 0;
   1025  1.1  dyoung 			IEEE80211_SEND_MGMT(ic, ni, resp,
   1026  1.1  dyoung 				IEEE80211_STATUS_BASIC_RATE);
   1027  1.1  dyoung 			return;
   1028  1.1  dyoung 		}
   1029  1.1  dyoung 		ni->ni_rssi = rssi;
   1030  1.1  dyoung 		ni->ni_rstamp = rstamp;
   1031  1.1  dyoung 		ni->ni_intval = bintval;
   1032  1.1  dyoung 		ni->ni_capinfo = capinfo;
   1033  1.1  dyoung 		ni->ni_chan = ic->ic_bss->ni_chan;
   1034  1.1  dyoung 		ni->ni_fhdwell = ic->ic_bss->ni_fhdwell;
   1035  1.1  dyoung 		ni->ni_fhindex = ic->ic_bss->ni_fhindex;
   1036  1.1  dyoung 		if (ni->ni_associd == 0) {
   1037  1.5  dyoung 			u_int16_t aid;
   1038  1.5  dyoung 
   1039  1.5  dyoung 			/*
   1040  1.5  dyoung 			 * It would be clever to search the bitmap
   1041  1.5  dyoung 			 * more efficiently, but this will do for now.
   1042  1.5  dyoung 			 */
   1043  1.5  dyoung 			for (aid = 1; aid < ic->ic_max_aid; aid++) {
   1044  1.5  dyoung 				if (!IEEE80211_AID_ISSET(aid,
   1045  1.5  dyoung 				    ic->ic_aid_bitmap))
   1046  1.5  dyoung 					break;
   1047  1.5  dyoung 			}
   1048  1.5  dyoung 
   1049  1.5  dyoung 			if (ic->ic_bss->ni_associd >= ic->ic_max_aid) {
   1050  1.5  dyoung 				IEEE80211_SEND_MGMT(ic, ni, resp,
   1051  1.5  dyoung 				    IEEE80211_REASON_ASSOC_TOOMANY);
   1052  1.5  dyoung 				return;
   1053  1.5  dyoung 			} else {
   1054  1.5  dyoung 				ni->ni_associd = aid | 0xc000;
   1055  1.5  dyoung 				IEEE80211_AID_SET(ni->ni_associd,
   1056  1.5  dyoung 				    ic->ic_aid_bitmap);
   1057  1.5  dyoung 				newassoc = 1;
   1058  1.5  dyoung 			}
   1059  1.1  dyoung 		} else
   1060  1.1  dyoung 			newassoc = 0;
   1061  1.1  dyoung 		/* XXX for 11g must turn off short slot time if long
   1062  1.1  dyoung 	           slot time sta associates */
   1063  1.1  dyoung 		IEEE80211_SEND_MGMT(ic, ni, resp, IEEE80211_STATUS_SUCCESS);
   1064  1.1  dyoung 		if (ifp->if_flags & IFF_DEBUG)
   1065  1.5  dyoung 			if_printf(ifp, "station %s %s associated at aid %d\n",
   1066  1.1  dyoung 			    (newassoc ? "newly" : "already"),
   1067  1.5  dyoung 			    ether_sprintf(ni->ni_macaddr),
   1068  1.5  dyoung 			    ni->ni_associd & ~0xc000);
   1069  1.1  dyoung 		/* give driver a chance to setup state like ni_txrate */
   1070  1.1  dyoung 		if (ic->ic_newassoc)
   1071  1.1  dyoung 			(*ic->ic_newassoc)(ic, ni, newassoc);
   1072  1.1  dyoung 		break;
   1073  1.1  dyoung 	}
   1074  1.1  dyoung 
   1075  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_ASSOC_RESP:
   1076  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_REASSOC_RESP: {
   1077  1.1  dyoung 		u_int16_t status;
   1078  1.1  dyoung 
   1079  1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_STA ||
   1080  1.1  dyoung 		    ic->ic_state != IEEE80211_S_ASSOC)
   1081  1.1  dyoung 			return;
   1082  1.1  dyoung 
   1083  1.1  dyoung 		/*
   1084  1.1  dyoung 		 * asresp frame format
   1085  1.1  dyoung 		 *	[2] capability information
   1086  1.1  dyoung 		 *	[2] status
   1087  1.1  dyoung 		 *	[2] association ID
   1088  1.1  dyoung 		 *	[tlv] supported rates
   1089  1.1  dyoung 		 *	[tlv] extended supported rates
   1090  1.1  dyoung 		 */
   1091  1.1  dyoung 		IEEE80211_VERIFY_LENGTH(efrm - frm, 6);
   1092  1.1  dyoung 		ni = ic->ic_bss;
   1093  1.1  dyoung 		ni->ni_capinfo = le16toh(*(u_int16_t *)frm);
   1094  1.1  dyoung 		frm += 2;
   1095  1.1  dyoung 
   1096  1.1  dyoung 		status = le16toh(*(u_int16_t *)frm);
   1097  1.1  dyoung 		frm += 2;
   1098  1.1  dyoung 		if (status != 0) {
   1099  1.1  dyoung 			if_printf(ifp, "association failed (reason %d) for %s\n",
   1100  1.1  dyoung 			    status, ether_sprintf(wh->i_addr3));
   1101  1.1  dyoung 			if (ni != ic->ic_bss)
   1102  1.1  dyoung 				ni->ni_fails++;
   1103  1.1  dyoung 			return;
   1104  1.1  dyoung 		}
   1105  1.1  dyoung 		ni->ni_associd = le16toh(*(u_int16_t *)frm);
   1106  1.1  dyoung 		frm += 2;
   1107  1.1  dyoung 
   1108  1.1  dyoung 		rates = xrates = NULL;
   1109  1.1  dyoung 		while (frm < efrm) {
   1110  1.1  dyoung 			switch (*frm) {
   1111  1.1  dyoung 			case IEEE80211_ELEMID_RATES:
   1112  1.1  dyoung 				rates = frm;
   1113  1.1  dyoung 				break;
   1114  1.1  dyoung 			case IEEE80211_ELEMID_XRATES:
   1115  1.1  dyoung 				xrates = frm;
   1116  1.1  dyoung 				break;
   1117  1.1  dyoung 			}
   1118  1.1  dyoung 			frm += frm[1] + 2;
   1119  1.1  dyoung 		}
   1120  1.1  dyoung 
   1121  1.1  dyoung 		IEEE80211_VERIFY_ELEMENT(rates, IEEE80211_RATE_MAXSIZE);
   1122  1.1  dyoung 		ieee80211_setup_rates(ic, ni, rates, xrates,
   1123  1.1  dyoung 				IEEE80211_F_DOSORT | IEEE80211_F_DOFRATE |
   1124  1.1  dyoung 				IEEE80211_F_DONEGO | IEEE80211_F_DODEL);
   1125  1.1  dyoung 		if (ni->ni_rates.rs_nrates != 0)
   1126  1.1  dyoung 			ieee80211_new_state(ic, IEEE80211_S_RUN,
   1127  1.1  dyoung 				wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK);
   1128  1.1  dyoung 		break;
   1129  1.1  dyoung 	}
   1130  1.1  dyoung 
   1131  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_DEAUTH: {
   1132  1.1  dyoung 		u_int16_t reason;
   1133  1.1  dyoung 		/*
   1134  1.1  dyoung 		 * deauth frame format
   1135  1.1  dyoung 		 *	[2] reason
   1136  1.1  dyoung 		 */
   1137  1.1  dyoung 		IEEE80211_VERIFY_LENGTH(efrm - frm, 2);
   1138  1.1  dyoung 		reason = le16toh(*(u_int16_t *)frm);
   1139  1.1  dyoung 		switch (ic->ic_opmode) {
   1140  1.1  dyoung 		case IEEE80211_M_STA:
   1141  1.1  dyoung 			ieee80211_new_state(ic, IEEE80211_S_AUTH,
   1142  1.1  dyoung 			    wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK);
   1143  1.1  dyoung 			break;
   1144  1.1  dyoung 		case IEEE80211_M_HOSTAP:
   1145  1.1  dyoung 			if (ni != ic->ic_bss) {
   1146  1.1  dyoung 				if (ifp->if_flags & IFF_DEBUG)
   1147  1.1  dyoung 					if_printf(ifp, "station %s deauthenticated"
   1148  1.1  dyoung 					    " by peer (reason %d)\n",
   1149  1.1  dyoung 					    ether_sprintf(ni->ni_macaddr), reason);
   1150  1.1  dyoung 				/* node will be free'd on return */
   1151  1.1  dyoung 				ieee80211_unref_node(&ni);
   1152  1.1  dyoung 			}
   1153  1.1  dyoung 			break;
   1154  1.1  dyoung 		default:
   1155  1.1  dyoung 			break;
   1156  1.1  dyoung 		}
   1157  1.1  dyoung 		break;
   1158  1.1  dyoung 	}
   1159  1.1  dyoung 
   1160  1.1  dyoung 	case IEEE80211_FC0_SUBTYPE_DISASSOC: {
   1161  1.1  dyoung 		u_int16_t reason;
   1162  1.1  dyoung 		/*
   1163  1.1  dyoung 		 * disassoc frame format
   1164  1.1  dyoung 		 *	[2] reason
   1165  1.1  dyoung 		 */
   1166  1.1  dyoung 		IEEE80211_VERIFY_LENGTH(efrm - frm, 2);
   1167  1.1  dyoung 		reason = le16toh(*(u_int16_t *)frm);
   1168  1.1  dyoung 		switch (ic->ic_opmode) {
   1169  1.1  dyoung 		case IEEE80211_M_STA:
   1170  1.1  dyoung 			ieee80211_new_state(ic, IEEE80211_S_ASSOC,
   1171  1.1  dyoung 			    wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK);
   1172  1.1  dyoung 			break;
   1173  1.1  dyoung 		case IEEE80211_M_HOSTAP:
   1174  1.1  dyoung 			if (ni != ic->ic_bss) {
   1175  1.1  dyoung 				if (ifp->if_flags & IFF_DEBUG)
   1176  1.1  dyoung 					if_printf(ifp, "station %s disassociated"
   1177  1.1  dyoung 					    " by peer (reason %d)\n",
   1178  1.1  dyoung 					    ether_sprintf(ni->ni_macaddr), reason);
   1179  1.5  dyoung 				IEEE80211_AID_CLR(ni->ni_associd,
   1180  1.5  dyoung 				    ic->ic_aid_bitmap);
   1181  1.1  dyoung 				ni->ni_associd = 0;
   1182  1.1  dyoung 				/* XXX node reclaimed how? */
   1183  1.1  dyoung 			}
   1184  1.1  dyoung 			break;
   1185  1.1  dyoung 		default:
   1186  1.1  dyoung 			break;
   1187  1.1  dyoung 		}
   1188  1.1  dyoung 		break;
   1189  1.1  dyoung 	}
   1190  1.1  dyoung 	default:
   1191  1.1  dyoung 		IEEE80211_DPRINTF(("%s: mgmt frame with subtype 0x%x not "
   1192  1.1  dyoung 			"handled\n", __func__, subtype));
   1193  1.1  dyoung 		break;
   1194  1.1  dyoung 	}
   1195  1.1  dyoung #undef ISPROBE
   1196  1.5  dyoung }
   1197  1.5  dyoung 
   1198  1.5  dyoung static void
   1199  1.5  dyoung ieee80211_recv_pspoll(struct ieee80211com *ic, struct mbuf *m0, int rssi,
   1200  1.5  dyoung 		      u_int32_t rstamp)
   1201  1.5  dyoung {
   1202  1.5  dyoung 	struct ifnet *ifp = &ic->ic_if;
   1203  1.5  dyoung 	struct ieee80211_frame *wh;
   1204  1.5  dyoung 	struct ieee80211_node *ni;
   1205  1.5  dyoung 	struct mbuf *m;
   1206  1.5  dyoung 	u_int16_t aid;
   1207  1.5  dyoung 
   1208  1.5  dyoung 	if (ic->ic_set_tim == NULL)  /* No powersaving functionality */
   1209  1.5  dyoung 		return;
   1210  1.5  dyoung 
   1211  1.5  dyoung 	wh = mtod(m0, struct ieee80211_frame *);
   1212  1.5  dyoung 
   1213  1.5  dyoung 	if ((ni = ieee80211_find_node(ic, wh->i_addr2)) == NULL) {
   1214  1.5  dyoung 		if (ifp->if_flags & IFF_DEBUG)
   1215  1.5  dyoung 			printf("%s: station %s sent bogus power save poll\n",
   1216  1.5  dyoung 			       ifp->if_xname, ether_sprintf(wh->i_addr2));
   1217  1.5  dyoung 		return;
   1218  1.5  dyoung 	}
   1219  1.5  dyoung 
   1220  1.5  dyoung 	memcpy(&aid, wh->i_dur, sizeof(wh->i_dur));
   1221  1.5  dyoung 	if ((aid & 0xc000) != 0xc000) {
   1222  1.5  dyoung 		if (ifp->if_flags & IFF_DEBUG)
   1223  1.5  dyoung 			printf("%s: station %s sent bogus aid %x\n",
   1224  1.5  dyoung 			       ifp->if_xname, ether_sprintf(wh->i_addr2), aid);
   1225  1.5  dyoung 		return;
   1226  1.5  dyoung 	}
   1227  1.5  dyoung 
   1228  1.5  dyoung 	if (aid != ni->ni_associd) {
   1229  1.5  dyoung 		if (ifp->if_flags & IFF_DEBUG)
   1230  1.5  dyoung 			printf("%s: station %s aid %x doesn't match pspoll "
   1231  1.5  dyoung 			       "aid %x\n",
   1232  1.5  dyoung 			       ifp->if_xname, ether_sprintf(wh->i_addr2),
   1233  1.5  dyoung 			       ni->ni_associd, aid);
   1234  1.5  dyoung 		return;
   1235  1.5  dyoung 	}
   1236  1.5  dyoung 
   1237  1.5  dyoung 	/* Okay, take the first queued packet and put it out... */
   1238  1.5  dyoung 
   1239  1.5  dyoung 	IF_DEQUEUE(&ni->ni_savedq, m);
   1240  1.5  dyoung 	if (m == NULL) {
   1241  1.5  dyoung 		if (ifp->if_flags & IFF_DEBUG)
   1242  1.5  dyoung 			printf("%s: station %s sent pspoll, "
   1243  1.5  dyoung 			       "but no packets are saved\n",
   1244  1.5  dyoung 			       ifp->if_xname, ether_sprintf(wh->i_addr2));
   1245  1.5  dyoung 		return;
   1246  1.5  dyoung 	}
   1247  1.5  dyoung 	wh = mtod(m, struct ieee80211_frame *);
   1248  1.5  dyoung 
   1249  1.5  dyoung 	/*
   1250  1.5  dyoung 	 * If this is the last packet, turn off the TIM fields.
   1251  1.5  dyoung 	 * If there are more packets, set the more packets bit.
   1252  1.5  dyoung 	 */
   1253  1.5  dyoung 
   1254  1.5  dyoung 	if (IF_IS_EMPTY(&ni->ni_savedq)) {
   1255  1.5  dyoung 		if (ic->ic_set_tim)
   1256  1.5  dyoung 			ic->ic_set_tim(ic, ni->ni_associd, 0);
   1257  1.5  dyoung 	} else {
   1258  1.5  dyoung 		wh->i_fc[1] |= IEEE80211_FC1_MORE_DATA;
   1259  1.5  dyoung 	}
   1260  1.5  dyoung 
   1261  1.5  dyoung 	if (ifp->if_flags & IFF_DEBUG)
   1262  1.5  dyoung 		printf("%s: enqueued power saving packet for station %s\n",
   1263  1.5  dyoung 		       ifp->if_xname, ether_sprintf(ni->ni_macaddr));
   1264  1.5  dyoung 
   1265  1.5  dyoung 	IF_ENQUEUE(&ic->ic_pwrsaveq, m);
   1266  1.5  dyoung 	(*ifp->if_start)(ifp);
   1267  1.1  dyoung }
   1268  1.1  dyoung #undef IEEE80211_VERIFY_LENGTH
   1269  1.1  dyoung #undef IEEE80211_VERIFY_ELEMENT
   1270