xref: /freebsd/contrib/wpa/src/ap/sta_info.h (revision 71e72c9e91c4b8007a4292e09669e8b549c29e97)
1 /*
2  * hostapd / Station table
3  * Copyright (c) 2002-2017, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8 
9 #ifndef STA_INFO_H
10 #define STA_INFO_H
11 
12 #include "common/defs.h"
13 #include "list.h"
14 #include "vlan.h"
15 #include "common/wpa_common.h"
16 #include "common/ieee802_11_defs.h"
17 #include "common/sae.h"
18 #include "crypto/sha384.h"
19 #include "pasn/pasn_common.h"
20 #include "hostapd.h"
21 
22 /* STA flags */
23 #define WLAN_STA_AUTH BIT(0)
24 #define WLAN_STA_ASSOC BIT(1)
25 #define WLAN_STA_SPP_AMSDU BIT(2)
26 #define WLAN_STA_AUTHORIZED BIT(5)
27 #define WLAN_STA_PENDING_POLL BIT(6) /* pending activity poll not ACKed */
28 #define WLAN_STA_SHORT_PREAMBLE BIT(7)
29 #define WLAN_STA_PREAUTH BIT(8)
30 #define WLAN_STA_WMM BIT(9)
31 #define WLAN_STA_MFP BIT(10)
32 #define WLAN_STA_HT BIT(11)
33 #define WLAN_STA_WPS BIT(12)
34 #define WLAN_STA_MAYBE_WPS BIT(13)
35 #define WLAN_STA_WDS BIT(14)
36 #define WLAN_STA_ASSOC_REQ_OK BIT(15)
37 #define WLAN_STA_WPS2 BIT(16)
38 #define WLAN_STA_GAS BIT(17)
39 #define WLAN_STA_VHT BIT(18)
40 #define WLAN_STA_WNM_SLEEP_MODE BIT(19)
41 #define WLAN_STA_VHT_OPMODE_ENABLED BIT(20)
42 #define WLAN_STA_VENDOR_VHT BIT(21)
43 #define WLAN_STA_PENDING_FILS_ERP BIT(22)
44 #define WLAN_STA_MULTI_AP BIT(23)
45 #define WLAN_STA_HE BIT(24)
46 #define WLAN_STA_6GHZ BIT(25)
47 #define WLAN_STA_PENDING_PASN_FILS_ERP BIT(26)
48 #define WLAN_STA_EHT BIT(27)
49 #define WLAN_STA_PENDING_DISASSOC_CB BIT(29)
50 #define WLAN_STA_PENDING_DEAUTH_CB BIT(30)
51 #define WLAN_STA_NONERP BIT(31)
52 
53 /* Maximum number of supported rates (from both Supported Rates and Extended
54  * Supported Rates IEs). */
55 #define WLAN_SUPP_RATES_MAX 32
56 
57 struct hostapd_data;
58 
59 struct mbo_non_pref_chan_info {
60 	struct mbo_non_pref_chan_info *next;
61 	u8 op_class;
62 	u8 pref;
63 	u8 reason_code;
64 	u8 num_channels;
65 	u8 channels[];
66 };
67 
68 struct pending_eapol_rx {
69 	struct wpabuf *buf;
70 	struct os_reltime rx_time;
71 	enum frame_encryption encrypted;
72 };
73 
74 struct eap_over_auth_data {
75 	int akm;
76 	int cipher;
77 	u16 group;
78 	u16 auth_transaction;
79 	u8 snonce[WPA_NONCE_LEN];
80 	u8 anonce[WPA_NONCE_LEN];
81 	u8 *rsnxe;
82 	u8 pmk[PMK_LEN_MAX];
83 	size_t pmk_len;
84 	struct wpa_ptk ptk;
85 	size_t rsnxe_len;
86 	struct crypto_ecdh *ecdh;
87 	struct wpabuf *dhss;
88 	bool add_mic;
89 	u8 epp_pmkid_cur[PMKID_LEN];
90 	u8 epp_pmkid_next[PMKID_LEN];
91 };
92 
93 #define EHT_ML_MAX_STA_PROF_LEN 1024
94 struct mld_info {
95 	bool mld_sta;
96 
97 	struct ml_common_info {
98 		u8 mld_addr[ETH_ALEN];
99 		u16 medium_sync_delay;
100 		u16 eml_capa;
101 		u16 mld_capa;
102 	} common_info;
103 
104 	struct mld_link_info links[MAX_NUM_MLD_LINKS];
105 };
106 
107 struct sta_info {
108 	struct sta_info *next; /* next entry in sta list */
109 	struct sta_info *hnext; /* next entry in hash table list */
110 	u8 addr[6];
111 	be32 ipaddr;
112 	struct dl_list ip6addr; /* list head for struct ip6addr */
113 	u16 aid; /* STA's unique AID (1 .. 2007) or 0 if not yet assigned */
114 	u16 disconnect_reason_code; /* RADIUS server override */
115 	u32 flags; /* Bitfield of WLAN_STA_* */
116 	u16 capability;
117 	u16 listen_interval; /* or beacon_int for APs */
118 	u8 supported_rates[WLAN_SUPP_RATES_MAX];
119 	int supported_rates_len;
120 	u8 qosinfo; /* Valid when WLAN_STA_WMM is set */
121 #ifdef CONFIG_ENC_ASSOC
122 	bool epp_sta; /* Indicates if the station is an EPP peer */
123 #endif /* CONFIG_ENC_ASSOC */
124 #ifdef CONFIG_PMKSA_PRIVACY
125 	u8 snonce[NONCE_LEN]; /* SNonce to compute next PMKID if
126 			       * PMKID caching privacy is on */
127 	u8 anonce[NONCE_LEN]; /* ANonce to compute next PMKID if
128 			       * PMKID caching privacy is on */
129 	u8 epp_pmkid_next[PMKID_LEN];
130 #endif /* CONFIG_PMKSA_PRIVACY */
131 
132 #ifdef CONFIG_MESH
133 	enum mesh_plink_state plink_state;
134 	u16 peer_lid;
135 	u16 my_lid;
136 	u16 peer_aid;
137 	u16 mpm_close_reason;
138 	int mpm_retries;
139 	u8 my_nonce[WPA_NONCE_LEN];
140 	u8 peer_nonce[WPA_NONCE_LEN];
141 	u8 aek[32];	/* SHA256 digest length */
142 	u8 mtk[WPA_TK_MAX_LEN];
143 	size_t mtk_len;
144 	u8 mgtk_rsc[6];
145 	u8 mgtk_key_id;
146 	u8 mgtk[WPA_TK_MAX_LEN];
147 	size_t mgtk_len;
148 	u8 igtk_rsc[6];
149 	u8 igtk[WPA_TK_MAX_LEN];
150 	size_t igtk_len;
151 	u16 igtk_key_id;
152 	u8 sae_auth_retry;
153 #endif /* CONFIG_MESH */
154 
155 	unsigned int nonerp_set:1;
156 	unsigned int no_short_slot_time_set:1;
157 	unsigned int no_short_preamble_set:1;
158 	unsigned int no_ht_gf_set:1;
159 	unsigned int no_ht_set:1;
160 	unsigned int ht40_intolerant_set:1;
161 	unsigned int ht_20mhz_set:1;
162 	unsigned int no_p2p_set:1;
163 	unsigned int qos_map_enabled:1;
164 	unsigned int hs20_deauth_requested:1;
165 	unsigned int hs20_deauth_on_ack:1;
166 	unsigned int session_timeout_set:1;
167 	unsigned int radius_das_match:1;
168 	unsigned int ecsa_supported:1;
169 	unsigned int added_unassoc:1;
170 	unsigned int pending_wds_enable:1;
171 	unsigned int power_capab:1;
172 	unsigned int agreed_to_steer:1;
173 	unsigned int hs20_t_c_filtering:1;
174 	unsigned int ft_over_ds:1;
175 	unsigned int external_dh_updated:1;
176 	unsigned int post_csa_sa_query:1;
177 
178 	u16 auth_alg;
179 
180 	enum {
181 		STA_NULLFUNC = 0, STA_DISASSOC, STA_DEAUTH, STA_REMOVE,
182 		STA_DISASSOC_FROM_CLI
183 	} timeout_next;
184 
185 	u16 deauth_reason;
186 	u16 disassoc_reason;
187 
188 	/* IEEE 802.1X related data */
189 	struct eapol_state_machine *eapol_sm;
190 
191 	struct pending_eapol_rx *pending_eapol_rx;
192 
193 	u64 acct_session_id;
194 	struct os_reltime acct_session_start;
195 	int acct_session_started;
196 	int acct_terminate_cause; /* Acct-Terminate-Cause */
197 	int acct_interim_interval; /* Acct-Interim-Interval */
198 	unsigned int acct_interim_errors;
199 
200 	/* For extending 32-bit driver counters to 64-bit counters */
201 	u32 last_rx_bytes_hi;
202 	u32 last_rx_bytes_lo;
203 	u32 last_tx_bytes_hi;
204 	u32 last_tx_bytes_lo;
205 
206 	u8 *challenge; /* IEEE 802.11 Shared Key Authentication Challenge */
207 
208 	struct wpa_state_machine *wpa_sm;
209 	struct rsn_preauth_interface *preauth_iface;
210 
211 	int vlan_id; /* 0: none, >0: VID */
212 	struct vlan_description *vlan_desc;
213 	int vlan_id_bound; /* updated by ap_sta_bind_vlan() */
214 	 /* PSKs from RADIUS authentication server */
215 	struct hostapd_sta_wpa_psk_short *psk;
216 
217 	char *identity; /* User-Name from RADIUS */
218 	char *radius_cui; /* Chargeable-User-Identity from RADIUS */
219 
220 	struct ieee80211_ht_capabilities *ht_capabilities;
221 	struct ieee80211_vht_capabilities *vht_capabilities;
222 	struct ieee80211_vht_operation *vht_operation;
223 	u8 vht_opmode;
224 	struct ieee80211_he_capabilities *he_capab;
225 	size_t he_capab_len;
226 	struct ieee80211_he_6ghz_band_cap *he_6ghz_capab;
227 	struct ieee80211_eht_capabilities *eht_capab;
228 	size_t eht_capab_len;
229 
230 	int sa_query_count; /* number of pending SA Query requests;
231 			     * 0 = no SA Query in progress */
232 	int sa_query_timed_out;
233 	u8 *sa_query_trans_id; /* buffer of WLAN_SA_QUERY_TR_ID_LEN *
234 				* sa_query_count octets of pending SA Query
235 				* transaction identifiers */
236 	struct os_reltime sa_query_start;
237 
238 #if defined(CONFIG_INTERWORKING) || defined(CONFIG_DPP)
239 #define GAS_DIALOG_MAX 8 /* Max concurrent dialog number */
240 	struct gas_dialog_info *gas_dialog;
241 	u8 gas_dialog_next;
242 #endif /* CONFIG_INTERWORKING || CONFIG_DPP */
243 
244 	struct wpabuf *wps_ie; /* WPS IE from (Re)Association Request */
245 	struct wpabuf *p2p_ie; /* P2P IE from (Re)Association Request */
246 	struct wpabuf *hs20_ie; /* HS 2.0 IE from (Re)Association Request */
247 	/* Hotspot 2.0 Roaming Consortium from (Re)Association Request */
248 	struct wpabuf *roaming_consortium;
249 	char *t_c_url; /* HS 2.0 Terms and Conditions Server URL */
250 	struct wpabuf *hs20_deauth_req;
251 	char *hs20_session_info_url;
252 	int hs20_disassoc_timer;
253 #ifdef CONFIG_FST
254 	struct wpabuf *mb_ies; /* MB IEs from (Re)Association Request */
255 #endif /* CONFIG_FST */
256 
257 	struct os_reltime connected_time;
258 
259 #ifdef CONFIG_SAE
260 	struct sae_data *sae;
261 	unsigned int mesh_sae_pmksa_caching:1;
262 #endif /* CONFIG_SAE */
263 
264 	/* valid only if session_timeout_set == 1 */
265 	struct os_reltime session_timeout;
266 
267 	/* Last Authentication/(Re)Association Request/Action frame sequence
268 	 * control */
269 	u16 last_seq_ctrl;
270 	/* Last Authentication/(Re)Association Request/Action frame subtype */
271 	u8 last_subtype;
272 
273 #ifdef CONFIG_MBO
274 	u8 cell_capa; /* 0 = unknown (not an MBO STA); otherwise,
275 		       * enum mbo_cellular_capa values */
276 	struct mbo_non_pref_chan_info *non_pref_chan;
277 	int auth_rssi; /* Last Authentication frame RSSI */
278 #endif /* CONFIG_MBO */
279 
280 	u8 *supp_op_classes; /* Supported Operating Classes element, if
281 			      * received, starting from the Length field */
282 
283 	u8 rrm_enabled_capa[5];
284 
285 	s8 min_tx_power;
286 	s8 max_tx_power;
287 
288 #ifdef CONFIG_TAXONOMY
289 	struct wpabuf *probe_ie_taxonomy;
290 	struct wpabuf *assoc_ie_taxonomy;
291 #endif /* CONFIG_TAXONOMY */
292 
293 #ifdef CONFIG_FILS
294 	u8 fils_snonce[NONCE_LEN];
295 	u8 fils_session[FILS_SESSION_LEN];
296 	u8 fils_erp_pmkid[PMKID_LEN];
297 	u8 *fils_pending_assoc_req;
298 	size_t fils_pending_assoc_req_len;
299 	unsigned int fils_pending_assoc_is_reassoc:1;
300 	unsigned int fils_dhcp_rapid_commit_proxy:1;
301 	unsigned int fils_erp_pmkid_set:1;
302 	unsigned int fils_drv_assoc_finish:1;
303 	struct wpabuf *fils_hlp_resp;
304 	struct wpabuf *hlp_dhcp_discover;
305 	void (*fils_pending_cb)(struct hostapd_data *hapd, struct sta_info *sta,
306 				u16 resp, struct wpabuf *data, int pub);
307 #ifdef CONFIG_FILS_SK_PFS
308 	struct crypto_ecdh *fils_ecdh;
309 #endif /* CONFIG_FILS_SK_PFS */
310 	struct wpabuf *fils_dh_ss;
311 	struct wpabuf *fils_g_sta;
312 #endif /* CONFIG_FILS */
313 
314 #ifdef CONFIG_OWE
315 	u8 *owe_pmk;
316 	size_t owe_pmk_len;
317 	struct crypto_ecdh *owe_ecdh;
318 	u16 owe_group;
319 #endif /* CONFIG_OWE */
320 
321 	u8 *ext_capability;
322 	char *ifname_wds; /* WDS ifname, if in use */
323 
324 #ifdef CONFIG_DPP2
325 	struct dpp_pfs *dpp_pfs;
326 #endif /* CONFIG_DPP2 */
327 
328 #ifdef CONFIG_TESTING_OPTIONS
329 	enum wpa_alg last_tk_alg;
330 	int last_tk_key_idx;
331 	u8 last_tk[WPA_TK_MAX_LEN];
332 	size_t last_tk_len;
333 	u8 *sae_postponed_commit;
334 	size_t sae_postponed_commit_len;
335 #endif /* CONFIG_TESTING_OPTIONS */
336 #ifdef CONFIG_AIRTIME_POLICY
337 	unsigned int airtime_weight;
338 	struct os_reltime backlogged_until;
339 #endif /* CONFIG_AIRTIME_POLICY */
340 
341 #ifdef CONFIG_PASN
342 	struct pasn_data *pasn;
343 #endif /* CONFIG_PASN */
344 
345 #ifdef CONFIG_IEEE80211BE
346 	struct mld_info mld_info;
347 	u8 mld_assoc_link_id;
348 	struct link_reconf_req_list *reconf_req;
349 #endif /* CONFIG_IEEE80211BE */
350 
351 	u16 max_idle_period; /* if nonzero, the granted BSS max idle period in
352 			      * units of 1000 TUs */
353 
354 	u64 last_known_sta_id_timestamp;
355 
356 	struct wpabuf *sae_pw_id;
357 	unsigned int sae_pw_id_counter;
358 
359 #ifdef CONFIG_IEEE8021X_AUTH
360 	struct eap_over_auth_data eap_auth_data;
361 #endif /* CONFIG_IEEE8021X_AUTH */
362 };
363 
364 
365 /* Default value for maximum station inactivity. After AP_MAX_INACTIVITY has
366  * passed since last received frame from the station, a nullfunc data frame is
367  * sent to the station. If this frame is not acknowledged and no other frames
368  * have been received, the station will be disassociated after
369  * AP_DISASSOC_DELAY seconds. Similarly, the station will be deauthenticated
370  * after AP_DEAUTH_DELAY seconds has passed after disassociation. */
371 #define AP_MAX_INACTIVITY (5 * 60)
372 #define AP_DISASSOC_DELAY (3)
373 #define AP_DEAUTH_DELAY (1)
374 /* Number of seconds to keep STA entry with Authenticated flag after it has
375  * been disassociated. */
376 #define AP_MAX_INACTIVITY_AFTER_DISASSOC (1 * 30)
377 /* Number of seconds to keep STA entry after it has been deauthenticated. */
378 #define AP_MAX_INACTIVITY_AFTER_DEAUTH (1 * 5)
379 
380 
381 int ap_for_each_sta(struct hostapd_data *hapd,
382 		    int (*cb)(struct hostapd_data *hapd, struct sta_info *sta,
383 			      void *ctx),
384 		    void *ctx);
385 struct sta_info * ap_get_sta(struct hostapd_data *hapd, const u8 *sta);
386 struct sta_info * ap_get_link_sta(struct hostapd_data *hapd,
387 				  const u8 *link_addr);
388 struct sta_info * ap_get_sta_p2p(struct hostapd_data *hapd, const u8 *addr);
389 void ap_sta_hash_add(struct hostapd_data *hapd, struct sta_info *sta);
390 void ap_free_sta(struct hostapd_data *hapd, struct sta_info *sta);
391 void ap_sta_ip6addr_del(struct hostapd_data *hapd, struct sta_info *sta);
392 void hostapd_free_stas(struct hostapd_data *hapd);
393 void ap_handle_timer(void *eloop_ctx, void *timeout_ctx);
394 void ap_sta_replenish_timeout(struct hostapd_data *hapd, struct sta_info *sta,
395 			      u32 session_timeout);
396 void ap_sta_session_timeout(struct hostapd_data *hapd, struct sta_info *sta,
397 			    u32 session_timeout);
398 void ap_sta_no_session_timeout(struct hostapd_data *hapd,
399 			       struct sta_info *sta);
400 void ap_sta_session_warning_timeout(struct hostapd_data *hapd,
401 				    struct sta_info *sta, int warning_time);
402 struct sta_info * ap_sta_add(struct hostapd_data *hapd, const u8 *addr);
403 void ap_sta_disassociate(struct hostapd_data *hapd, struct sta_info *sta,
404 			 u16 reason);
405 void ap_sta_deauthenticate(struct hostapd_data *hapd, struct sta_info *sta,
406 			   u16 reason);
407 #ifdef CONFIG_WPS
408 int ap_sta_wps_cancel(struct hostapd_data *hapd,
409 		      struct sta_info *sta, void *ctx);
410 #endif /* CONFIG_WPS */
411 int ap_sta_bind_vlan(struct hostapd_data *hapd, struct sta_info *sta);
412 int ap_sta_set_vlan(struct hostapd_data *hapd, struct sta_info *sta,
413 		    struct vlan_description *vlan_desc);
414 void ap_sta_start_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
415 void ap_sta_stop_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
416 void ap_sta_set_sa_query_timeout(struct hostapd_data *hapd,
417 				 struct sta_info *sta, int value);
418 int ap_check_sa_query_timeout(struct hostapd_data *hapd, struct sta_info *sta);
419 const char * ap_sta_wpa_get_keyid(struct hostapd_data *hapd,
420 				  struct sta_info *sta);
421 const u8 * ap_sta_wpa_get_dpp_pkhash(struct hostapd_data *hapd,
422 				     struct sta_info *sta);
423 void ap_sta_disconnect(struct hostapd_data *hapd, struct sta_info *sta,
424 		       const u8 *addr, u16 reason);
425 
426 bool ap_sta_set_authorized_flag(struct hostapd_data *hapd, struct sta_info *sta,
427 				int authorized);
428 void ap_sta_set_authorized_event(struct hostapd_data *hapd,
429 				 struct sta_info *sta, int authorized);
430 bool ap_sta_set_authorized(struct hostapd_data *hapd,
431 			   struct sta_info *sta, int authorized);
ap_sta_is_authorized(struct sta_info * sta)432 static inline int ap_sta_is_authorized(struct sta_info *sta)
433 {
434 	return sta->flags & WLAN_STA_AUTHORIZED;
435 }
436 
437 void ap_sta_deauth_cb(struct hostapd_data *hapd, struct sta_info *sta);
438 void ap_sta_disassoc_cb(struct hostapd_data *hapd, struct sta_info *sta);
439 void ap_sta_clear_disconnect_timeouts(struct hostapd_data *hapd,
440 				      struct sta_info *sta);
441 void ap_sta_clear_assoc_timeout(struct hostapd_data *hapd,
442 				struct sta_info *sta);
443 
444 int ap_sta_flags_txt(u32 flags, char *buf, size_t buflen);
445 void ap_sta_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
446 					    struct sta_info *sta,
447 					    unsigned timeout);
448 int ap_sta_pending_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
449 						   struct sta_info *sta);
450 int ap_sta_re_add(struct hostapd_data *hapd, struct sta_info *sta);
451 
452 void ap_free_sta_pasn(struct hostapd_data *hapd, struct sta_info *sta);
453 
ap_sta_is_mld(struct hostapd_data * hapd,struct sta_info * sta)454 static inline bool ap_sta_is_mld(struct hostapd_data *hapd,
455 				 struct sta_info *sta)
456 {
457 #ifdef CONFIG_IEEE80211BE
458 	return hapd->conf->mld_ap && sta && sta->mld_info.mld_sta;
459 #else /* CONFIG_IEEE80211BE */
460 	return false;
461 #endif /* CONFIG_IEEE80211BE */
462 }
463 
ap_sta_set_mld(struct sta_info * sta,bool mld)464 static inline void ap_sta_set_mld(struct sta_info *sta, bool mld)
465 {
466 #ifdef CONFIG_IEEE80211BE
467 	if (sta)
468 		sta->mld_info.mld_sta = mld;
469 #endif /* CONFIG_IEEE80211BE */
470 }
471 
472 void ap_sta_free_sta_profile(struct mld_info *info);
473 
474 void hostapd_free_link_stas(struct hostapd_data *hapd);
475 void set_wpa_sm_for_each_partner_link(struct hostapd_data *hapd,
476 				      struct sta_info *psta, void *wpa_sm);
477 void clear_wpa_sm_for_each_partner_link(struct hostapd_data *hapd,
478 					struct sta_info *psta);
479 void clear_wpa_sm_for_all_sta(struct hostapd_data *hapd,
480 			      struct wpa_state_machine *wpa_sm);
481 
ap_sta_is_epp(const struct sta_info * sta)482 static inline bool ap_sta_is_epp(const struct sta_info *sta)
483 {
484 #ifdef CONFIG_ENC_ASSOC
485 	return sta && sta->epp_sta;
486 #else /* CONFIG_ENC_ASSOC */
487 	return false;
488 #endif /* CONFIG_ENC_ASSOC */
489 }
490 
ap_sta_support_enc_assoc(struct hostapd_data * hapd,const u8 * rsnxe,size_t rsnxe_len)491 static inline bool ap_sta_support_enc_assoc(struct hostapd_data *hapd,
492 					    const u8 *rsnxe, size_t rsnxe_len)
493 {
494 #ifdef CONFIG_ENC_ASSOC
495 		return (hapd->conf->assoc_frame_encryption &&
496 			ieee802_11_rsnx_capab_len(rsnxe,
497 						  rsnxe_len,
498 						  WLAN_RSNX_CAPAB_ASSOC_FRAME_ENCRYPTION));
499 #else /* CONFIG_ENC_ASSOC */
500 	return false;
501 #endif /* CONFIG_ENC_ASSOC */
502 }
503 #endif /* STA_INFO_H */
504