xref: /freebsd/contrib/wpa/src/ap/sta_info.h (revision 0957b409)
1 /*
2  * hostapd / Station table
3  * Copyright (c) 2002-2017, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8 
9 #ifndef STA_INFO_H
10 #define STA_INFO_H
11 
12 #include "common/defs.h"
13 #include "list.h"
14 #include "vlan.h"
15 #include "common/wpa_common.h"
16 #include "common/ieee802_11_defs.h"
17 
18 /* STA flags */
19 #define WLAN_STA_AUTH BIT(0)
20 #define WLAN_STA_ASSOC BIT(1)
21 #define WLAN_STA_AUTHORIZED BIT(5)
22 #define WLAN_STA_PENDING_POLL BIT(6) /* pending activity poll not ACKed */
23 #define WLAN_STA_SHORT_PREAMBLE BIT(7)
24 #define WLAN_STA_PREAUTH BIT(8)
25 #define WLAN_STA_WMM BIT(9)
26 #define WLAN_STA_MFP BIT(10)
27 #define WLAN_STA_HT BIT(11)
28 #define WLAN_STA_WPS BIT(12)
29 #define WLAN_STA_MAYBE_WPS BIT(13)
30 #define WLAN_STA_WDS BIT(14)
31 #define WLAN_STA_ASSOC_REQ_OK BIT(15)
32 #define WLAN_STA_WPS2 BIT(16)
33 #define WLAN_STA_GAS BIT(17)
34 #define WLAN_STA_VHT BIT(18)
35 #define WLAN_STA_WNM_SLEEP_MODE BIT(19)
36 #define WLAN_STA_VHT_OPMODE_ENABLED BIT(20)
37 #define WLAN_STA_VENDOR_VHT BIT(21)
38 #define WLAN_STA_PENDING_FILS_ERP BIT(22)
39 #define WLAN_STA_PENDING_DISASSOC_CB BIT(29)
40 #define WLAN_STA_PENDING_DEAUTH_CB BIT(30)
41 #define WLAN_STA_NONERP BIT(31)
42 
43 /* Maximum number of supported rates (from both Supported Rates and Extended
44  * Supported Rates IEs). */
45 #define WLAN_SUPP_RATES_MAX 32
46 
47 struct hostapd_data;
48 
49 struct mbo_non_pref_chan_info {
50 	struct mbo_non_pref_chan_info *next;
51 	u8 op_class;
52 	u8 pref;
53 	u8 reason_code;
54 	u8 num_channels;
55 	u8 channels[];
56 };
57 
58 struct pending_eapol_rx {
59 	struct wpabuf *buf;
60 	struct os_reltime rx_time;
61 };
62 
63 struct sta_info {
64 	struct sta_info *next; /* next entry in sta list */
65 	struct sta_info *hnext; /* next entry in hash table list */
66 	u8 addr[6];
67 	be32 ipaddr;
68 	struct dl_list ip6addr; /* list head for struct ip6addr */
69 	u16 aid; /* STA's unique AID (1 .. 2007) or 0 if not yet assigned */
70 	u16 disconnect_reason_code; /* RADIUS server override */
71 	u32 flags; /* Bitfield of WLAN_STA_* */
72 	u16 capability;
73 	u16 listen_interval; /* or beacon_int for APs */
74 	u8 supported_rates[WLAN_SUPP_RATES_MAX];
75 	int supported_rates_len;
76 	u8 qosinfo; /* Valid when WLAN_STA_WMM is set */
77 
78 #ifdef CONFIG_MESH
79 	enum mesh_plink_state plink_state;
80 	u16 peer_lid;
81 	u16 my_lid;
82 	u16 peer_aid;
83 	u16 mpm_close_reason;
84 	int mpm_retries;
85 	u8 my_nonce[WPA_NONCE_LEN];
86 	u8 peer_nonce[WPA_NONCE_LEN];
87 	u8 aek[32];	/* SHA256 digest length */
88 	u8 mtk[WPA_TK_MAX_LEN];
89 	size_t mtk_len;
90 	u8 mgtk_rsc[6];
91 	u8 mgtk_key_id;
92 	u8 mgtk[WPA_TK_MAX_LEN];
93 	size_t mgtk_len;
94 	u8 igtk_rsc[6];
95 	u8 igtk[WPA_TK_MAX_LEN];
96 	size_t igtk_len;
97 	u16 igtk_key_id;
98 	u8 sae_auth_retry;
99 #endif /* CONFIG_MESH */
100 
101 	unsigned int nonerp_set:1;
102 	unsigned int no_short_slot_time_set:1;
103 	unsigned int no_short_preamble_set:1;
104 	unsigned int no_ht_gf_set:1;
105 	unsigned int no_ht_set:1;
106 	unsigned int ht40_intolerant_set:1;
107 	unsigned int ht_20mhz_set:1;
108 	unsigned int no_p2p_set:1;
109 	unsigned int qos_map_enabled:1;
110 	unsigned int remediation:1;
111 	unsigned int hs20_deauth_requested:1;
112 	unsigned int session_timeout_set:1;
113 	unsigned int radius_das_match:1;
114 	unsigned int ecsa_supported:1;
115 	unsigned int added_unassoc:1;
116 	unsigned int pending_wds_enable:1;
117 	unsigned int power_capab:1;
118 	unsigned int agreed_to_steer:1;
119 	unsigned int hs20_t_c_filtering:1;
120 
121 	u16 auth_alg;
122 
123 	enum {
124 		STA_NULLFUNC = 0, STA_DISASSOC, STA_DEAUTH, STA_REMOVE,
125 		STA_DISASSOC_FROM_CLI
126 	} timeout_next;
127 
128 	u16 deauth_reason;
129 	u16 disassoc_reason;
130 
131 	/* IEEE 802.1X related data */
132 	struct eapol_state_machine *eapol_sm;
133 
134 	struct pending_eapol_rx *pending_eapol_rx;
135 
136 	u64 acct_session_id;
137 	struct os_reltime acct_session_start;
138 	int acct_session_started;
139 	int acct_terminate_cause; /* Acct-Terminate-Cause */
140 	int acct_interim_interval; /* Acct-Interim-Interval */
141 	unsigned int acct_interim_errors;
142 
143 	/* For extending 32-bit driver counters to 64-bit counters */
144 	u32 last_rx_bytes_hi;
145 	u32 last_rx_bytes_lo;
146 	u32 last_tx_bytes_hi;
147 	u32 last_tx_bytes_lo;
148 
149 	u8 *challenge; /* IEEE 802.11 Shared Key Authentication Challenge */
150 
151 	struct wpa_state_machine *wpa_sm;
152 	struct rsn_preauth_interface *preauth_iface;
153 
154 	int vlan_id; /* 0: none, >0: VID */
155 	struct vlan_description *vlan_desc;
156 	int vlan_id_bound; /* updated by ap_sta_bind_vlan() */
157 	 /* PSKs from RADIUS authentication server */
158 	struct hostapd_sta_wpa_psk_short *psk;
159 
160 	char *identity; /* User-Name from RADIUS */
161 	char *radius_cui; /* Chargeable-User-Identity from RADIUS */
162 
163 	struct ieee80211_ht_capabilities *ht_capabilities;
164 	struct ieee80211_vht_capabilities *vht_capabilities;
165 	u8 vht_opmode;
166 
167 #ifdef CONFIG_IEEE80211W
168 	int sa_query_count; /* number of pending SA Query requests;
169 			     * 0 = no SA Query in progress */
170 	int sa_query_timed_out;
171 	u8 *sa_query_trans_id; /* buffer of WLAN_SA_QUERY_TR_ID_LEN *
172 				* sa_query_count octets of pending SA Query
173 				* transaction identifiers */
174 	struct os_reltime sa_query_start;
175 #endif /* CONFIG_IEEE80211W */
176 
177 #if defined(CONFIG_INTERWORKING) || defined(CONFIG_DPP)
178 #define GAS_DIALOG_MAX 8 /* Max concurrent dialog number */
179 	struct gas_dialog_info *gas_dialog;
180 	u8 gas_dialog_next;
181 #endif /* CONFIG_INTERWORKING || CONFIG_DPP */
182 
183 	struct wpabuf *wps_ie; /* WPS IE from (Re)Association Request */
184 	struct wpabuf *p2p_ie; /* P2P IE from (Re)Association Request */
185 	struct wpabuf *hs20_ie; /* HS 2.0 IE from (Re)Association Request */
186 	/* Hotspot 2.0 Roaming Consortium from (Re)Association Request */
187 	struct wpabuf *roaming_consortium;
188 	u8 remediation_method;
189 	char *remediation_url; /* HS 2.0 Subscription Remediation Server URL */
190 	char *t_c_url; /* HS 2.0 Terms and Conditions Server URL */
191 	struct wpabuf *hs20_deauth_req;
192 	char *hs20_session_info_url;
193 	int hs20_disassoc_timer;
194 #ifdef CONFIG_FST
195 	struct wpabuf *mb_ies; /* MB IEs from (Re)Association Request */
196 #endif /* CONFIG_FST */
197 
198 	struct os_reltime connected_time;
199 
200 #ifdef CONFIG_SAE
201 	struct sae_data *sae;
202 	unsigned int mesh_sae_pmksa_caching:1;
203 #endif /* CONFIG_SAE */
204 
205 	/* valid only if session_timeout_set == 1 */
206 	struct os_reltime session_timeout;
207 
208 	/* Last Authentication/(Re)Association Request/Action frame sequence
209 	 * control */
210 	u16 last_seq_ctrl;
211 	/* Last Authentication/(Re)Association Request/Action frame subtype */
212 	u8 last_subtype;
213 
214 #ifdef CONFIG_MBO
215 	u8 cell_capa; /* 0 = unknown (not an MBO STA); otherwise,
216 		       * enum mbo_cellular_capa values */
217 	struct mbo_non_pref_chan_info *non_pref_chan;
218 #endif /* CONFIG_MBO */
219 
220 	u8 *supp_op_classes; /* Supported Operating Classes element, if
221 			      * received, starting from the Length field */
222 
223 	u8 rrm_enabled_capa[5];
224 
225 	s8 min_tx_power;
226 	s8 max_tx_power;
227 
228 #ifdef CONFIG_TAXONOMY
229 	struct wpabuf *probe_ie_taxonomy;
230 	struct wpabuf *assoc_ie_taxonomy;
231 #endif /* CONFIG_TAXONOMY */
232 
233 #ifdef CONFIG_FILS
234 	u8 fils_snonce[FILS_NONCE_LEN];
235 	u8 fils_session[FILS_SESSION_LEN];
236 	u8 fils_erp_pmkid[PMKID_LEN];
237 	u8 *fils_pending_assoc_req;
238 	size_t fils_pending_assoc_req_len;
239 	unsigned int fils_pending_assoc_is_reassoc:1;
240 	unsigned int fils_dhcp_rapid_commit_proxy:1;
241 	unsigned int fils_erp_pmkid_set:1;
242 	unsigned int fils_drv_assoc_finish:1;
243 	struct wpabuf *fils_hlp_resp;
244 	struct wpabuf *hlp_dhcp_discover;
245 	void (*fils_pending_cb)(struct hostapd_data *hapd, struct sta_info *sta,
246 				u16 resp, struct wpabuf *data, int pub);
247 #ifdef CONFIG_FILS_SK_PFS
248 	struct crypto_ecdh *fils_ecdh;
249 #endif /* CONFIG_FILS_SK_PFS */
250 	struct wpabuf *fils_dh_ss;
251 	struct wpabuf *fils_g_sta;
252 #endif /* CONFIG_FILS */
253 
254 #ifdef CONFIG_OWE
255 	u8 *owe_pmk;
256 	size_t owe_pmk_len;
257 	struct crypto_ecdh *owe_ecdh;
258 	u16 owe_group;
259 #endif /* CONFIG_OWE */
260 
261 	u8 *ext_capability;
262 	char *ifname_wds; /* WDS ifname, if in use */
263 
264 #ifdef CONFIG_TESTING_OPTIONS
265 	enum wpa_alg last_tk_alg;
266 	int last_tk_key_idx;
267 	u8 last_tk[WPA_TK_MAX_LEN];
268 	size_t last_tk_len;
269 #endif /* CONFIG_TESTING_OPTIONS */
270 };
271 
272 
273 /* Default value for maximum station inactivity. After AP_MAX_INACTIVITY has
274  * passed since last received frame from the station, a nullfunc data frame is
275  * sent to the station. If this frame is not acknowledged and no other frames
276  * have been received, the station will be disassociated after
277  * AP_DISASSOC_DELAY seconds. Similarly, the station will be deauthenticated
278  * after AP_DEAUTH_DELAY seconds has passed after disassociation. */
279 #define AP_MAX_INACTIVITY (5 * 60)
280 #define AP_DISASSOC_DELAY (3)
281 #define AP_DEAUTH_DELAY (1)
282 /* Number of seconds to keep STA entry with Authenticated flag after it has
283  * been disassociated. */
284 #define AP_MAX_INACTIVITY_AFTER_DISASSOC (1 * 30)
285 /* Number of seconds to keep STA entry after it has been deauthenticated. */
286 #define AP_MAX_INACTIVITY_AFTER_DEAUTH (1 * 5)
287 
288 
289 int ap_for_each_sta(struct hostapd_data *hapd,
290 		    int (*cb)(struct hostapd_data *hapd, struct sta_info *sta,
291 			      void *ctx),
292 		    void *ctx);
293 struct sta_info * ap_get_sta(struct hostapd_data *hapd, const u8 *sta);
294 struct sta_info * ap_get_sta_p2p(struct hostapd_data *hapd, const u8 *addr);
295 void ap_sta_hash_add(struct hostapd_data *hapd, struct sta_info *sta);
296 void ap_free_sta(struct hostapd_data *hapd, struct sta_info *sta);
297 void ap_sta_ip6addr_del(struct hostapd_data *hapd, struct sta_info *sta);
298 void hostapd_free_stas(struct hostapd_data *hapd);
299 void ap_handle_timer(void *eloop_ctx, void *timeout_ctx);
300 void ap_sta_replenish_timeout(struct hostapd_data *hapd, struct sta_info *sta,
301 			      u32 session_timeout);
302 void ap_sta_session_timeout(struct hostapd_data *hapd, struct sta_info *sta,
303 			    u32 session_timeout);
304 void ap_sta_no_session_timeout(struct hostapd_data *hapd,
305 			       struct sta_info *sta);
306 void ap_sta_session_warning_timeout(struct hostapd_data *hapd,
307 				    struct sta_info *sta, int warning_time);
308 struct sta_info * ap_sta_add(struct hostapd_data *hapd, const u8 *addr);
309 void ap_sta_disassociate(struct hostapd_data *hapd, struct sta_info *sta,
310 			 u16 reason);
311 void ap_sta_deauthenticate(struct hostapd_data *hapd, struct sta_info *sta,
312 			   u16 reason);
313 #ifdef CONFIG_WPS
314 int ap_sta_wps_cancel(struct hostapd_data *hapd,
315 		      struct sta_info *sta, void *ctx);
316 #endif /* CONFIG_WPS */
317 int ap_sta_bind_vlan(struct hostapd_data *hapd, struct sta_info *sta);
318 int ap_sta_set_vlan(struct hostapd_data *hapd, struct sta_info *sta,
319 		    struct vlan_description *vlan_desc);
320 void ap_sta_start_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
321 void ap_sta_stop_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
322 int ap_check_sa_query_timeout(struct hostapd_data *hapd, struct sta_info *sta);
323 void ap_sta_disconnect(struct hostapd_data *hapd, struct sta_info *sta,
324 		       const u8 *addr, u16 reason);
325 
326 void ap_sta_set_authorized(struct hostapd_data *hapd,
327 			   struct sta_info *sta, int authorized);
328 static inline int ap_sta_is_authorized(struct sta_info *sta)
329 {
330 	return sta->flags & WLAN_STA_AUTHORIZED;
331 }
332 
333 void ap_sta_deauth_cb(struct hostapd_data *hapd, struct sta_info *sta);
334 void ap_sta_disassoc_cb(struct hostapd_data *hapd, struct sta_info *sta);
335 void ap_sta_clear_disconnect_timeouts(struct hostapd_data *hapd,
336 				      struct sta_info *sta);
337 
338 int ap_sta_flags_txt(u32 flags, char *buf, size_t buflen);
339 void ap_sta_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
340 					    struct sta_info *sta);
341 int ap_sta_pending_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
342 						   struct sta_info *sta);
343 
344 #endif /* STA_INFO_H */
345