1 /* 2 * hostapd / Station table 3 * Copyright (c) 2002-2017, Jouni Malinen <j@w1.fi> 4 * 5 * This software may be distributed under the terms of the BSD license. 6 * See README for more details. 7 */ 8 9 #ifndef STA_INFO_H 10 #define STA_INFO_H 11 12 #include "common/defs.h" 13 #include "list.h" 14 #include "vlan.h" 15 #include "common/wpa_common.h" 16 #include "common/ieee802_11_defs.h" 17 #include "common/sae.h" 18 #include "crypto/sha384.h" 19 #include "pasn/pasn_common.h" 20 #include "hostapd.h" 21 22 /* STA flags */ 23 #define WLAN_STA_AUTH BIT(0) 24 #define WLAN_STA_ASSOC BIT(1) 25 #define WLAN_STA_AUTHORIZED BIT(5) 26 #define WLAN_STA_PENDING_POLL BIT(6) /* pending activity poll not ACKed */ 27 #define WLAN_STA_SHORT_PREAMBLE BIT(7) 28 #define WLAN_STA_PREAUTH BIT(8) 29 #define WLAN_STA_WMM BIT(9) 30 #define WLAN_STA_MFP BIT(10) 31 #define WLAN_STA_HT BIT(11) 32 #define WLAN_STA_WPS BIT(12) 33 #define WLAN_STA_MAYBE_WPS BIT(13) 34 #define WLAN_STA_WDS BIT(14) 35 #define WLAN_STA_ASSOC_REQ_OK BIT(15) 36 #define WLAN_STA_WPS2 BIT(16) 37 #define WLAN_STA_GAS BIT(17) 38 #define WLAN_STA_VHT BIT(18) 39 #define WLAN_STA_WNM_SLEEP_MODE BIT(19) 40 #define WLAN_STA_VHT_OPMODE_ENABLED BIT(20) 41 #define WLAN_STA_VENDOR_VHT BIT(21) 42 #define WLAN_STA_PENDING_FILS_ERP BIT(22) 43 #define WLAN_STA_MULTI_AP BIT(23) 44 #define WLAN_STA_HE BIT(24) 45 #define WLAN_STA_6GHZ BIT(25) 46 #define WLAN_STA_PENDING_PASN_FILS_ERP BIT(26) 47 #define WLAN_STA_EHT BIT(27) 48 #define WLAN_STA_PENDING_DISASSOC_CB BIT(29) 49 #define WLAN_STA_PENDING_DEAUTH_CB BIT(30) 50 #define WLAN_STA_NONERP BIT(31) 51 52 /* Maximum number of supported rates (from both Supported Rates and Extended 53 * Supported Rates IEs). */ 54 #define WLAN_SUPP_RATES_MAX 32 55 56 struct hostapd_data; 57 58 struct mbo_non_pref_chan_info { 59 struct mbo_non_pref_chan_info *next; 60 u8 op_class; 61 u8 pref; 62 u8 reason_code; 63 u8 num_channels; 64 u8 channels[]; 65 }; 66 67 struct pending_eapol_rx { 68 struct wpabuf *buf; 69 struct os_reltime rx_time; 70 enum frame_encryption encrypted; 71 }; 72 73 #define EHT_ML_MAX_STA_PROF_LEN 1024 74 struct mld_info { 75 bool mld_sta; 76 77 struct ml_common_info { 78 u8 mld_addr[ETH_ALEN]; 79 u16 medium_sync_delay; 80 u16 eml_capa; 81 u16 mld_capa; 82 } common_info; 83 84 struct mld_link_info { 85 u8 valid:1; 86 u8 nstr_bitmap_len:2; 87 u8 local_addr[ETH_ALEN]; 88 u8 peer_addr[ETH_ALEN]; 89 90 u8 nstr_bitmap[2]; 91 92 u16 capability; 93 94 u16 status; 95 u16 resp_sta_profile_len; 96 u8 *resp_sta_profile; 97 } links[MAX_NUM_MLD_LINKS]; 98 }; 99 100 struct sta_info { 101 struct sta_info *next; /* next entry in sta list */ 102 struct sta_info *hnext; /* next entry in hash table list */ 103 u8 addr[6]; 104 be32 ipaddr; 105 struct dl_list ip6addr; /* list head for struct ip6addr */ 106 u16 aid; /* STA's unique AID (1 .. 2007) or 0 if not yet assigned */ 107 u16 disconnect_reason_code; /* RADIUS server override */ 108 u32 flags; /* Bitfield of WLAN_STA_* */ 109 u16 capability; 110 u16 listen_interval; /* or beacon_int for APs */ 111 u8 supported_rates[WLAN_SUPP_RATES_MAX]; 112 int supported_rates_len; 113 u8 qosinfo; /* Valid when WLAN_STA_WMM is set */ 114 115 #ifdef CONFIG_MESH 116 enum mesh_plink_state plink_state; 117 u16 peer_lid; 118 u16 my_lid; 119 u16 peer_aid; 120 u16 mpm_close_reason; 121 int mpm_retries; 122 u8 my_nonce[WPA_NONCE_LEN]; 123 u8 peer_nonce[WPA_NONCE_LEN]; 124 u8 aek[32]; /* SHA256 digest length */ 125 u8 mtk[WPA_TK_MAX_LEN]; 126 size_t mtk_len; 127 u8 mgtk_rsc[6]; 128 u8 mgtk_key_id; 129 u8 mgtk[WPA_TK_MAX_LEN]; 130 size_t mgtk_len; 131 u8 igtk_rsc[6]; 132 u8 igtk[WPA_TK_MAX_LEN]; 133 size_t igtk_len; 134 u16 igtk_key_id; 135 u8 sae_auth_retry; 136 #endif /* CONFIG_MESH */ 137 138 unsigned int nonerp_set:1; 139 unsigned int no_short_slot_time_set:1; 140 unsigned int no_short_preamble_set:1; 141 unsigned int no_ht_gf_set:1; 142 unsigned int no_ht_set:1; 143 unsigned int ht40_intolerant_set:1; 144 unsigned int ht_20mhz_set:1; 145 unsigned int no_p2p_set:1; 146 unsigned int qos_map_enabled:1; 147 unsigned int remediation:1; 148 unsigned int hs20_deauth_requested:1; 149 unsigned int hs20_deauth_on_ack:1; 150 unsigned int session_timeout_set:1; 151 unsigned int radius_das_match:1; 152 unsigned int ecsa_supported:1; 153 unsigned int added_unassoc:1; 154 unsigned int pending_wds_enable:1; 155 unsigned int power_capab:1; 156 unsigned int agreed_to_steer:1; 157 unsigned int hs20_t_c_filtering:1; 158 unsigned int ft_over_ds:1; 159 unsigned int external_dh_updated:1; 160 unsigned int post_csa_sa_query:1; 161 162 u16 auth_alg; 163 164 enum { 165 STA_NULLFUNC = 0, STA_DISASSOC, STA_DEAUTH, STA_REMOVE, 166 STA_DISASSOC_FROM_CLI 167 } timeout_next; 168 169 u16 deauth_reason; 170 u16 disassoc_reason; 171 172 /* IEEE 802.1X related data */ 173 struct eapol_state_machine *eapol_sm; 174 175 struct pending_eapol_rx *pending_eapol_rx; 176 177 u64 acct_session_id; 178 struct os_reltime acct_session_start; 179 int acct_session_started; 180 int acct_terminate_cause; /* Acct-Terminate-Cause */ 181 int acct_interim_interval; /* Acct-Interim-Interval */ 182 unsigned int acct_interim_errors; 183 184 /* For extending 32-bit driver counters to 64-bit counters */ 185 u32 last_rx_bytes_hi; 186 u32 last_rx_bytes_lo; 187 u32 last_tx_bytes_hi; 188 u32 last_tx_bytes_lo; 189 190 u8 *challenge; /* IEEE 802.11 Shared Key Authentication Challenge */ 191 192 struct wpa_state_machine *wpa_sm; 193 struct rsn_preauth_interface *preauth_iface; 194 195 int vlan_id; /* 0: none, >0: VID */ 196 struct vlan_description *vlan_desc; 197 int vlan_id_bound; /* updated by ap_sta_bind_vlan() */ 198 /* PSKs from RADIUS authentication server */ 199 struct hostapd_sta_wpa_psk_short *psk; 200 201 char *identity; /* User-Name from RADIUS */ 202 char *radius_cui; /* Chargeable-User-Identity from RADIUS */ 203 204 struct ieee80211_ht_capabilities *ht_capabilities; 205 struct ieee80211_vht_capabilities *vht_capabilities; 206 struct ieee80211_vht_operation *vht_operation; 207 u8 vht_opmode; 208 struct ieee80211_he_capabilities *he_capab; 209 size_t he_capab_len; 210 struct ieee80211_he_6ghz_band_cap *he_6ghz_capab; 211 struct ieee80211_eht_capabilities *eht_capab; 212 size_t eht_capab_len; 213 214 int sa_query_count; /* number of pending SA Query requests; 215 * 0 = no SA Query in progress */ 216 int sa_query_timed_out; 217 u8 *sa_query_trans_id; /* buffer of WLAN_SA_QUERY_TR_ID_LEN * 218 * sa_query_count octets of pending SA Query 219 * transaction identifiers */ 220 struct os_reltime sa_query_start; 221 222 #if defined(CONFIG_INTERWORKING) || defined(CONFIG_DPP) 223 #define GAS_DIALOG_MAX 8 /* Max concurrent dialog number */ 224 struct gas_dialog_info *gas_dialog; 225 u8 gas_dialog_next; 226 #endif /* CONFIG_INTERWORKING || CONFIG_DPP */ 227 228 struct wpabuf *wps_ie; /* WPS IE from (Re)Association Request */ 229 struct wpabuf *p2p_ie; /* P2P IE from (Re)Association Request */ 230 struct wpabuf *hs20_ie; /* HS 2.0 IE from (Re)Association Request */ 231 /* Hotspot 2.0 Roaming Consortium from (Re)Association Request */ 232 struct wpabuf *roaming_consortium; 233 u8 remediation_method; 234 char *remediation_url; /* HS 2.0 Subscription Remediation Server URL */ 235 char *t_c_url; /* HS 2.0 Terms and Conditions Server URL */ 236 struct wpabuf *hs20_deauth_req; 237 char *hs20_session_info_url; 238 int hs20_disassoc_timer; 239 #ifdef CONFIG_FST 240 struct wpabuf *mb_ies; /* MB IEs from (Re)Association Request */ 241 #endif /* CONFIG_FST */ 242 243 struct os_reltime connected_time; 244 245 #ifdef CONFIG_SAE 246 struct sae_data *sae; 247 unsigned int mesh_sae_pmksa_caching:1; 248 #endif /* CONFIG_SAE */ 249 250 /* valid only if session_timeout_set == 1 */ 251 struct os_reltime session_timeout; 252 253 /* Last Authentication/(Re)Association Request/Action frame sequence 254 * control */ 255 u16 last_seq_ctrl; 256 /* Last Authentication/(Re)Association Request/Action frame subtype */ 257 u8 last_subtype; 258 259 #ifdef CONFIG_MBO 260 u8 cell_capa; /* 0 = unknown (not an MBO STA); otherwise, 261 * enum mbo_cellular_capa values */ 262 struct mbo_non_pref_chan_info *non_pref_chan; 263 int auth_rssi; /* Last Authentication frame RSSI */ 264 #endif /* CONFIG_MBO */ 265 266 u8 *supp_op_classes; /* Supported Operating Classes element, if 267 * received, starting from the Length field */ 268 269 u8 rrm_enabled_capa[5]; 270 271 s8 min_tx_power; 272 s8 max_tx_power; 273 274 #ifdef CONFIG_TAXONOMY 275 struct wpabuf *probe_ie_taxonomy; 276 struct wpabuf *assoc_ie_taxonomy; 277 #endif /* CONFIG_TAXONOMY */ 278 279 #ifdef CONFIG_FILS 280 u8 fils_snonce[FILS_NONCE_LEN]; 281 u8 fils_session[FILS_SESSION_LEN]; 282 u8 fils_erp_pmkid[PMKID_LEN]; 283 u8 *fils_pending_assoc_req; 284 size_t fils_pending_assoc_req_len; 285 unsigned int fils_pending_assoc_is_reassoc:1; 286 unsigned int fils_dhcp_rapid_commit_proxy:1; 287 unsigned int fils_erp_pmkid_set:1; 288 unsigned int fils_drv_assoc_finish:1; 289 struct wpabuf *fils_hlp_resp; 290 struct wpabuf *hlp_dhcp_discover; 291 void (*fils_pending_cb)(struct hostapd_data *hapd, struct sta_info *sta, 292 u16 resp, struct wpabuf *data, int pub); 293 #ifdef CONFIG_FILS_SK_PFS 294 struct crypto_ecdh *fils_ecdh; 295 #endif /* CONFIG_FILS_SK_PFS */ 296 struct wpabuf *fils_dh_ss; 297 struct wpabuf *fils_g_sta; 298 #endif /* CONFIG_FILS */ 299 300 #ifdef CONFIG_OWE 301 u8 *owe_pmk; 302 size_t owe_pmk_len; 303 struct crypto_ecdh *owe_ecdh; 304 u16 owe_group; 305 #endif /* CONFIG_OWE */ 306 307 u8 *ext_capability; 308 char *ifname_wds; /* WDS ifname, if in use */ 309 310 #ifdef CONFIG_DPP2 311 struct dpp_pfs *dpp_pfs; 312 #endif /* CONFIG_DPP2 */ 313 314 #ifdef CONFIG_TESTING_OPTIONS 315 enum wpa_alg last_tk_alg; 316 int last_tk_key_idx; 317 u8 last_tk[WPA_TK_MAX_LEN]; 318 size_t last_tk_len; 319 u8 *sae_postponed_commit; 320 size_t sae_postponed_commit_len; 321 #endif /* CONFIG_TESTING_OPTIONS */ 322 #ifdef CONFIG_AIRTIME_POLICY 323 unsigned int airtime_weight; 324 struct os_reltime backlogged_until; 325 #endif /* CONFIG_AIRTIME_POLICY */ 326 327 #ifdef CONFIG_PASN 328 struct pasn_data *pasn; 329 #endif /* CONFIG_PASN */ 330 331 #ifdef CONFIG_IEEE80211BE 332 struct mld_info mld_info; 333 u8 mld_assoc_link_id; 334 #endif /* CONFIG_IEEE80211BE */ 335 336 u16 max_idle_period; /* if nonzero, the granted BSS max idle period in 337 * units of 1000 TUs */ 338 }; 339 340 341 /* Default value for maximum station inactivity. After AP_MAX_INACTIVITY has 342 * passed since last received frame from the station, a nullfunc data frame is 343 * sent to the station. If this frame is not acknowledged and no other frames 344 * have been received, the station will be disassociated after 345 * AP_DISASSOC_DELAY seconds. Similarly, the station will be deauthenticated 346 * after AP_DEAUTH_DELAY seconds has passed after disassociation. */ 347 #define AP_MAX_INACTIVITY (5 * 60) 348 #define AP_DISASSOC_DELAY (3) 349 #define AP_DEAUTH_DELAY (1) 350 /* Number of seconds to keep STA entry with Authenticated flag after it has 351 * been disassociated. */ 352 #define AP_MAX_INACTIVITY_AFTER_DISASSOC (1 * 30) 353 /* Number of seconds to keep STA entry after it has been deauthenticated. */ 354 #define AP_MAX_INACTIVITY_AFTER_DEAUTH (1 * 5) 355 356 357 int ap_for_each_sta(struct hostapd_data *hapd, 358 int (*cb)(struct hostapd_data *hapd, struct sta_info *sta, 359 void *ctx), 360 void *ctx); 361 struct sta_info * ap_get_sta(struct hostapd_data *hapd, const u8 *sta); 362 struct sta_info * ap_get_sta_p2p(struct hostapd_data *hapd, const u8 *addr); 363 void ap_sta_hash_add(struct hostapd_data *hapd, struct sta_info *sta); 364 void ap_free_sta(struct hostapd_data *hapd, struct sta_info *sta); 365 void ap_sta_ip6addr_del(struct hostapd_data *hapd, struct sta_info *sta); 366 void hostapd_free_stas(struct hostapd_data *hapd); 367 void ap_handle_timer(void *eloop_ctx, void *timeout_ctx); 368 void ap_sta_replenish_timeout(struct hostapd_data *hapd, struct sta_info *sta, 369 u32 session_timeout); 370 void ap_sta_session_timeout(struct hostapd_data *hapd, struct sta_info *sta, 371 u32 session_timeout); 372 void ap_sta_no_session_timeout(struct hostapd_data *hapd, 373 struct sta_info *sta); 374 void ap_sta_session_warning_timeout(struct hostapd_data *hapd, 375 struct sta_info *sta, int warning_time); 376 struct sta_info * ap_sta_add(struct hostapd_data *hapd, const u8 *addr); 377 void ap_sta_disassociate(struct hostapd_data *hapd, struct sta_info *sta, 378 u16 reason); 379 void ap_sta_deauthenticate(struct hostapd_data *hapd, struct sta_info *sta, 380 u16 reason); 381 #ifdef CONFIG_WPS 382 int ap_sta_wps_cancel(struct hostapd_data *hapd, 383 struct sta_info *sta, void *ctx); 384 #endif /* CONFIG_WPS */ 385 int ap_sta_bind_vlan(struct hostapd_data *hapd, struct sta_info *sta); 386 int ap_sta_set_vlan(struct hostapd_data *hapd, struct sta_info *sta, 387 struct vlan_description *vlan_desc); 388 void ap_sta_start_sa_query(struct hostapd_data *hapd, struct sta_info *sta); 389 void ap_sta_stop_sa_query(struct hostapd_data *hapd, struct sta_info *sta); 390 int ap_check_sa_query_timeout(struct hostapd_data *hapd, struct sta_info *sta); 391 const char * ap_sta_wpa_get_keyid(struct hostapd_data *hapd, 392 struct sta_info *sta); 393 const u8 * ap_sta_wpa_get_dpp_pkhash(struct hostapd_data *hapd, 394 struct sta_info *sta); 395 void ap_sta_disconnect(struct hostapd_data *hapd, struct sta_info *sta, 396 const u8 *addr, u16 reason); 397 398 bool ap_sta_set_authorized_flag(struct hostapd_data *hapd, struct sta_info *sta, 399 int authorized); 400 void ap_sta_set_authorized_event(struct hostapd_data *hapd, 401 struct sta_info *sta, int authorized); 402 void ap_sta_set_authorized(struct hostapd_data *hapd, 403 struct sta_info *sta, int authorized); 404 static inline int ap_sta_is_authorized(struct sta_info *sta) 405 { 406 return sta->flags & WLAN_STA_AUTHORIZED; 407 } 408 409 void ap_sta_deauth_cb(struct hostapd_data *hapd, struct sta_info *sta); 410 void ap_sta_disassoc_cb(struct hostapd_data *hapd, struct sta_info *sta); 411 void ap_sta_clear_disconnect_timeouts(struct hostapd_data *hapd, 412 struct sta_info *sta); 413 414 int ap_sta_flags_txt(u32 flags, char *buf, size_t buflen); 415 void ap_sta_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd, 416 struct sta_info *sta, 417 unsigned timeout); 418 int ap_sta_pending_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd, 419 struct sta_info *sta); 420 int ap_sta_re_add(struct hostapd_data *hapd, struct sta_info *sta); 421 422 void ap_free_sta_pasn(struct hostapd_data *hapd, struct sta_info *sta); 423 424 static inline bool ap_sta_is_mld(struct hostapd_data *hapd, 425 struct sta_info *sta) 426 { 427 #ifdef CONFIG_IEEE80211BE 428 return hapd->conf->mld_ap && sta && sta->mld_info.mld_sta; 429 #else /* CONFIG_IEEE80211BE */ 430 return false; 431 #endif /* CONFIG_IEEE80211BE */ 432 } 433 434 static inline void ap_sta_set_mld(struct sta_info *sta, bool mld) 435 { 436 #ifdef CONFIG_IEEE80211BE 437 if (sta) 438 sta->mld_info.mld_sta = mld; 439 #endif /* CONFIG_IEEE80211BE */ 440 } 441 442 void ap_sta_free_sta_profile(struct mld_info *info); 443 444 void hostapd_free_link_stas(struct hostapd_data *hapd); 445 446 #endif /* STA_INFO_H */ 447