1 /* 2 * WPA Supplicant / Configuration backend: text file 3 * Copyright (c) 2003-2019, Jouni Malinen <j@w1.fi> 4 * 5 * This software may be distributed under the terms of the BSD license. 6 * See README for more details. 7 * 8 * This file implements a configuration backend for text files. All the 9 * configuration information is stored in a text file that uses a format 10 * described in the sample configuration file, wpa_supplicant.conf. 11 */ 12 13 #include "includes.h" 14 #ifdef ANDROID 15 #include <sys/stat.h> 16 #endif /* ANDROID */ 17 18 #include "common.h" 19 #include "config.h" 20 #include "base64.h" 21 #include "uuid.h" 22 #include "common/ieee802_1x_defs.h" 23 #include "p2p/p2p.h" 24 #include "eap_peer/eap_methods.h" 25 #include "eap_peer/eap.h" 26 #include "utils/config.h" 27 28 29 static int wpa_config_validate_network(struct wpa_ssid *ssid, int line) 30 { 31 int errors = 0; 32 33 if (ssid->passphrase) { 34 if (ssid->psk_set) { 35 wpa_printf(MSG_ERROR, "Line %d: both PSK and " 36 "passphrase configured.", line); 37 errors++; 38 } 39 wpa_config_update_psk(ssid); 40 } 41 42 if (ssid->disabled == 2) 43 ssid->p2p_persistent_group = 1; 44 45 if ((ssid->group_cipher & WPA_CIPHER_CCMP) && 46 !(ssid->pairwise_cipher & (WPA_CIPHER_CCMP | WPA_CIPHER_CCMP_256 | 47 WPA_CIPHER_GCMP | WPA_CIPHER_GCMP_256 | 48 WPA_CIPHER_NONE))) { 49 /* Group cipher cannot be stronger than the pairwise cipher. */ 50 wpa_printf(MSG_DEBUG, "Line %d: removed CCMP from group cipher" 51 " list since it was not allowed for pairwise " 52 "cipher", line); 53 ssid->group_cipher &= ~WPA_CIPHER_CCMP; 54 } 55 56 if (ssid->mode == WPAS_MODE_MESH && 57 (ssid->key_mgmt != WPA_KEY_MGMT_NONE && 58 ssid->key_mgmt != WPA_KEY_MGMT_SAE)) { 59 wpa_printf(MSG_ERROR, 60 "Line %d: key_mgmt for mesh network should be open or SAE", 61 line); 62 errors++; 63 } 64 65 #ifdef CONFIG_OCV 66 if (ssid->ocv && ssid->ieee80211w == NO_MGMT_FRAME_PROTECTION) { 67 wpa_printf(MSG_ERROR, 68 "Line %d: PMF needs to be enabled whenever using OCV", 69 line); 70 errors++; 71 } 72 #endif /* CONFIG_OCV */ 73 74 return errors; 75 } 76 77 78 static struct wpa_ssid * wpa_config_read_network(FILE *f, int *line, int id) 79 { 80 struct wpa_ssid *ssid; 81 int errors = 0, end = 0; 82 char buf[2000], *pos, *pos2; 83 84 wpa_printf(MSG_MSGDUMP, "Line: %d - start of a new network block", 85 *line); 86 ssid = os_zalloc(sizeof(*ssid)); 87 if (ssid == NULL) 88 return NULL; 89 dl_list_init(&ssid->psk_list); 90 ssid->id = id; 91 92 wpa_config_set_network_defaults(ssid); 93 94 while (wpa_config_get_line(buf, sizeof(buf), f, line, &pos)) { 95 if (os_strcmp(pos, "}") == 0) { 96 end = 1; 97 break; 98 } 99 100 pos2 = os_strchr(pos, '='); 101 if (pos2 == NULL) { 102 wpa_printf(MSG_ERROR, "Line %d: Invalid SSID line " 103 "'%s'.", *line, pos); 104 errors++; 105 continue; 106 } 107 108 *pos2++ = '\0'; 109 if (*pos2 == '"') { 110 if (os_strchr(pos2 + 1, '"') == NULL) { 111 wpa_printf(MSG_ERROR, "Line %d: invalid " 112 "quotation '%s'.", *line, pos2); 113 errors++; 114 continue; 115 } 116 } 117 118 if (wpa_config_set(ssid, pos, pos2, *line) < 0) { 119 #ifndef CONFIG_WEP 120 if (os_strcmp(pos, "wep_key0") == 0 || 121 os_strcmp(pos, "wep_key1") == 0 || 122 os_strcmp(pos, "wep_key2") == 0 || 123 os_strcmp(pos, "wep_key3") == 0 || 124 os_strcmp(pos, "wep_tx_keyidx") == 0) { 125 wpa_printf(MSG_ERROR, 126 "Line %d: unsupported WEP parameter", 127 *line); 128 ssid->disabled = 1; 129 continue; 130 } 131 #endif /* CONFIG_WEP */ 132 errors++; 133 } 134 } 135 136 if (!end) { 137 wpa_printf(MSG_ERROR, "Line %d: network block was not " 138 "terminated properly.", *line); 139 errors++; 140 } 141 142 errors += wpa_config_validate_network(ssid, *line); 143 144 if (errors) { 145 wpa_config_free_ssid(ssid); 146 ssid = NULL; 147 } 148 149 return ssid; 150 } 151 152 153 static struct wpa_cred * wpa_config_read_cred(FILE *f, int *line, int id) 154 { 155 struct wpa_cred *cred; 156 int errors = 0, end = 0; 157 char buf[256], *pos, *pos2; 158 159 wpa_printf(MSG_MSGDUMP, "Line: %d - start of a new cred block", *line); 160 cred = os_zalloc(sizeof(*cred)); 161 if (cred == NULL) 162 return NULL; 163 cred->id = id; 164 cred->sim_num = DEFAULT_USER_SELECTED_SIM; 165 166 while (wpa_config_get_line(buf, sizeof(buf), f, line, &pos)) { 167 if (os_strcmp(pos, "}") == 0) { 168 end = 1; 169 break; 170 } 171 172 pos2 = os_strchr(pos, '='); 173 if (pos2 == NULL) { 174 wpa_printf(MSG_ERROR, "Line %d: Invalid cred line " 175 "'%s'.", *line, pos); 176 errors++; 177 continue; 178 } 179 180 *pos2++ = '\0'; 181 if (*pos2 == '"') { 182 if (os_strchr(pos2 + 1, '"') == NULL) { 183 wpa_printf(MSG_ERROR, "Line %d: invalid " 184 "quotation '%s'.", *line, pos2); 185 errors++; 186 continue; 187 } 188 } 189 190 if (wpa_config_set_cred(cred, pos, pos2, *line) < 0) 191 errors++; 192 } 193 194 if (!end) { 195 wpa_printf(MSG_ERROR, "Line %d: cred block was not " 196 "terminated properly.", *line); 197 errors++; 198 } 199 200 if (errors) { 201 wpa_config_free_cred(cred); 202 cred = NULL; 203 } 204 205 return cred; 206 } 207 208 209 #ifndef CONFIG_NO_CONFIG_BLOBS 210 static struct wpa_config_blob * wpa_config_read_blob(FILE *f, int *line, 211 const char *name) 212 { 213 struct wpa_config_blob *blob; 214 char buf[256], *pos; 215 char *encoded = NULL, *nencoded; 216 int end = 0; 217 size_t encoded_len = 0, len; 218 219 wpa_printf(MSG_MSGDUMP, "Line: %d - start of a new named blob '%s'", 220 *line, name); 221 222 while (wpa_config_get_line(buf, sizeof(buf), f, line, &pos)) { 223 if (os_strcmp(pos, "}") == 0) { 224 end = 1; 225 break; 226 } 227 228 len = os_strlen(pos); 229 nencoded = os_realloc(encoded, encoded_len + len); 230 if (nencoded == NULL) { 231 wpa_printf(MSG_ERROR, "Line %d: not enough memory for " 232 "blob", *line); 233 os_free(encoded); 234 return NULL; 235 } 236 encoded = nencoded; 237 os_memcpy(encoded + encoded_len, pos, len); 238 encoded_len += len; 239 } 240 241 if (!end || !encoded) { 242 wpa_printf(MSG_ERROR, "Line %d: blob was not terminated " 243 "properly", *line); 244 os_free(encoded); 245 return NULL; 246 } 247 248 blob = os_zalloc(sizeof(*blob)); 249 if (blob == NULL) { 250 os_free(encoded); 251 return NULL; 252 } 253 blob->name = os_strdup(name); 254 blob->data = base64_decode(encoded, encoded_len, &blob->len); 255 os_free(encoded); 256 257 if (blob->name == NULL || blob->data == NULL) { 258 wpa_config_free_blob(blob); 259 return NULL; 260 } 261 262 return blob; 263 } 264 265 266 static int wpa_config_process_blob(struct wpa_config *config, FILE *f, 267 int *line, char *bname) 268 { 269 char *name_end; 270 struct wpa_config_blob *blob; 271 272 name_end = os_strchr(bname, '='); 273 if (name_end == NULL) { 274 wpa_printf(MSG_ERROR, "Line %d: no blob name terminator", 275 *line); 276 return -1; 277 } 278 *name_end = '\0'; 279 280 blob = wpa_config_read_blob(f, line, bname); 281 if (blob == NULL) { 282 wpa_printf(MSG_ERROR, "Line %d: failed to read blob %s", 283 *line, bname); 284 return -1; 285 } 286 wpa_config_set_blob(config, blob); 287 return 0; 288 } 289 #endif /* CONFIG_NO_CONFIG_BLOBS */ 290 291 292 struct wpa_config * wpa_config_read(const char *name, struct wpa_config *cfgp) 293 { 294 FILE *f; 295 char buf[512], *pos; 296 int errors = 0, line = 0; 297 struct wpa_ssid *ssid, *tail, *head; 298 struct wpa_cred *cred, *cred_tail, *cred_head; 299 struct wpa_config *config; 300 int id = 0; 301 int cred_id = 0; 302 303 if (name == NULL) 304 return NULL; 305 if (cfgp) 306 config = cfgp; 307 else 308 config = wpa_config_alloc_empty(NULL, NULL); 309 if (config == NULL) { 310 wpa_printf(MSG_ERROR, "Failed to allocate config file " 311 "structure"); 312 return NULL; 313 } 314 tail = head = config->ssid; 315 while (tail && tail->next) 316 tail = tail->next; 317 cred_tail = cred_head = config->cred; 318 while (cred_tail && cred_tail->next) 319 cred_tail = cred_tail->next; 320 321 wpa_printf(MSG_DEBUG, "Reading configuration file '%s'", name); 322 f = fopen(name, "r"); 323 if (f == NULL) { 324 wpa_printf(MSG_ERROR, "Failed to open config file '%s', " 325 "error: %s", name, strerror(errno)); 326 if (config != cfgp) 327 os_free(config); 328 return NULL; 329 } 330 331 while (wpa_config_get_line(buf, sizeof(buf), f, &line, &pos)) { 332 if (os_strcmp(pos, "network={") == 0) { 333 ssid = wpa_config_read_network(f, &line, id++); 334 if (ssid == NULL) { 335 wpa_printf(MSG_ERROR, "Line %d: failed to " 336 "parse network block.", line); 337 errors++; 338 continue; 339 } 340 if (head == NULL) { 341 head = tail = ssid; 342 } else { 343 tail->next = ssid; 344 tail = ssid; 345 } 346 if (wpa_config_add_prio_network(config, ssid)) { 347 wpa_printf(MSG_ERROR, "Line %d: failed to add " 348 "network block to priority list.", 349 line); 350 errors++; 351 continue; 352 } 353 } else if (os_strcmp(pos, "cred={") == 0) { 354 cred = wpa_config_read_cred(f, &line, cred_id++); 355 if (cred == NULL) { 356 wpa_printf(MSG_ERROR, "Line %d: failed to " 357 "parse cred block.", line); 358 errors++; 359 continue; 360 } 361 if (cred_head == NULL) { 362 cred_head = cred_tail = cred; 363 } else { 364 cred_tail->next = cred; 365 cred_tail = cred; 366 } 367 #ifndef CONFIG_NO_CONFIG_BLOBS 368 } else if (os_strncmp(pos, "blob-base64-", 12) == 0) { 369 if (wpa_config_process_blob(config, f, &line, pos + 12) 370 < 0) { 371 wpa_printf(MSG_ERROR, "Line %d: failed to " 372 "process blob.", line); 373 errors++; 374 continue; 375 } 376 #endif /* CONFIG_NO_CONFIG_BLOBS */ 377 } else if (wpa_config_process_global(config, pos, line) < 0) { 378 wpa_printf(MSG_ERROR, "Line %d: Invalid configuration " 379 "line '%s'.", line, pos); 380 errors++; 381 continue; 382 } 383 } 384 385 fclose(f); 386 387 config->ssid = head; 388 wpa_config_debug_dump_networks(config); 389 config->cred = cred_head; 390 391 #ifndef WPA_IGNORE_CONFIG_ERRORS 392 if (errors) { 393 if (config != cfgp) 394 wpa_config_free(config); 395 config = NULL; 396 head = NULL; 397 } 398 #endif /* WPA_IGNORE_CONFIG_ERRORS */ 399 400 return config; 401 } 402 403 404 #ifndef CONFIG_NO_CONFIG_WRITE 405 406 static void write_str(FILE *f, const char *field, struct wpa_ssid *ssid) 407 { 408 char *value = wpa_config_get(ssid, field); 409 if (value == NULL) 410 return; 411 fprintf(f, "\t%s=%s\n", field, value); 412 str_clear_free(value); 413 } 414 415 416 static void write_int(FILE *f, const char *field, int value, int def) 417 { 418 if (value == def) 419 return; 420 fprintf(f, "\t%s=%d\n", field, value); 421 } 422 423 424 static void write_bssid(FILE *f, struct wpa_ssid *ssid) 425 { 426 char *value = wpa_config_get(ssid, "bssid"); 427 if (value == NULL) 428 return; 429 fprintf(f, "\tbssid=%s\n", value); 430 os_free(value); 431 } 432 433 434 static void write_bssid_hint(FILE *f, struct wpa_ssid *ssid) 435 { 436 char *value = wpa_config_get(ssid, "bssid_hint"); 437 438 if (!value) 439 return; 440 fprintf(f, "\tbssid_hint=%s\n", value); 441 os_free(value); 442 } 443 444 445 static void write_psk(FILE *f, struct wpa_ssid *ssid) 446 { 447 char *value; 448 449 if (ssid->mem_only_psk) 450 return; 451 452 value = wpa_config_get(ssid, "psk"); 453 if (value == NULL) 454 return; 455 fprintf(f, "\tpsk=%s\n", value); 456 os_free(value); 457 } 458 459 460 static void write_proto(FILE *f, struct wpa_ssid *ssid) 461 { 462 char *value; 463 464 if (ssid->proto == DEFAULT_PROTO) 465 return; 466 467 value = wpa_config_get(ssid, "proto"); 468 if (value == NULL) 469 return; 470 if (value[0]) 471 fprintf(f, "\tproto=%s\n", value); 472 os_free(value); 473 } 474 475 476 static void write_key_mgmt(FILE *f, struct wpa_ssid *ssid) 477 { 478 char *value; 479 480 if (ssid->key_mgmt == DEFAULT_KEY_MGMT) 481 return; 482 483 value = wpa_config_get(ssid, "key_mgmt"); 484 if (value == NULL) 485 return; 486 if (value[0]) 487 fprintf(f, "\tkey_mgmt=%s\n", value); 488 os_free(value); 489 } 490 491 492 static void write_pairwise(FILE *f, struct wpa_ssid *ssid) 493 { 494 char *value; 495 496 if (ssid->pairwise_cipher == DEFAULT_PAIRWISE) 497 return; 498 499 value = wpa_config_get(ssid, "pairwise"); 500 if (value == NULL) 501 return; 502 if (value[0]) 503 fprintf(f, "\tpairwise=%s\n", value); 504 os_free(value); 505 } 506 507 508 static void write_group(FILE *f, struct wpa_ssid *ssid) 509 { 510 char *value; 511 512 if (ssid->group_cipher == DEFAULT_GROUP) 513 return; 514 515 value = wpa_config_get(ssid, "group"); 516 if (value == NULL) 517 return; 518 if (value[0]) 519 fprintf(f, "\tgroup=%s\n", value); 520 os_free(value); 521 } 522 523 524 static void write_group_mgmt(FILE *f, struct wpa_ssid *ssid) 525 { 526 char *value; 527 528 if (!ssid->group_mgmt_cipher) 529 return; 530 531 value = wpa_config_get(ssid, "group_mgmt"); 532 if (!value) 533 return; 534 if (value[0]) 535 fprintf(f, "\tgroup_mgmt=%s\n", value); 536 os_free(value); 537 } 538 539 540 static void write_auth_alg(FILE *f, struct wpa_ssid *ssid) 541 { 542 char *value; 543 544 if (ssid->auth_alg == 0) 545 return; 546 547 value = wpa_config_get(ssid, "auth_alg"); 548 if (value == NULL) 549 return; 550 if (value[0]) 551 fprintf(f, "\tauth_alg=%s\n", value); 552 os_free(value); 553 } 554 555 556 #ifdef IEEE8021X_EAPOL 557 static void write_eap(FILE *f, struct wpa_ssid *ssid) 558 { 559 char *value; 560 561 value = wpa_config_get(ssid, "eap"); 562 if (value == NULL) 563 return; 564 565 if (value[0]) 566 fprintf(f, "\teap=%s\n", value); 567 os_free(value); 568 } 569 #endif /* IEEE8021X_EAPOL */ 570 571 572 #ifdef CONFIG_WEP 573 static void write_wep_key(FILE *f, int idx, struct wpa_ssid *ssid) 574 { 575 char field[20], *value; 576 int res; 577 578 res = os_snprintf(field, sizeof(field), "wep_key%d", idx); 579 if (os_snprintf_error(sizeof(field), res)) 580 return; 581 value = wpa_config_get(ssid, field); 582 if (value) { 583 fprintf(f, "\t%s=%s\n", field, value); 584 os_free(value); 585 } 586 } 587 #endif /* CONFIG_WEP */ 588 589 590 #ifdef CONFIG_P2P 591 592 static void write_go_p2p_dev_addr(FILE *f, struct wpa_ssid *ssid) 593 { 594 char *value = wpa_config_get(ssid, "go_p2p_dev_addr"); 595 if (value == NULL) 596 return; 597 fprintf(f, "\tgo_p2p_dev_addr=%s\n", value); 598 os_free(value); 599 } 600 601 static void write_p2p_client_list(FILE *f, struct wpa_ssid *ssid) 602 { 603 char *value = wpa_config_get(ssid, "p2p_client_list"); 604 if (value == NULL) 605 return; 606 fprintf(f, "\tp2p_client_list=%s\n", value); 607 os_free(value); 608 } 609 610 611 static void write_psk_list(FILE *f, struct wpa_ssid *ssid) 612 { 613 struct psk_list_entry *psk; 614 char hex[32 * 2 + 1]; 615 616 dl_list_for_each(psk, &ssid->psk_list, struct psk_list_entry, list) { 617 wpa_snprintf_hex(hex, sizeof(hex), psk->psk, sizeof(psk->psk)); 618 fprintf(f, "\tpsk_list=%s" MACSTR "-%s\n", 619 psk->p2p ? "P2P-" : "", MAC2STR(psk->addr), hex); 620 } 621 } 622 623 #endif /* CONFIG_P2P */ 624 625 626 #ifdef CONFIG_MACSEC 627 628 static void write_mka_cak(FILE *f, struct wpa_ssid *ssid) 629 { 630 char *value; 631 632 if (!(ssid->mka_psk_set & MKA_PSK_SET_CAK)) 633 return; 634 635 value = wpa_config_get(ssid, "mka_cak"); 636 if (!value) 637 return; 638 fprintf(f, "\tmka_cak=%s\n", value); 639 os_free(value); 640 } 641 642 643 static void write_mka_ckn(FILE *f, struct wpa_ssid *ssid) 644 { 645 char *value; 646 647 if (!(ssid->mka_psk_set & MKA_PSK_SET_CKN)) 648 return; 649 650 value = wpa_config_get(ssid, "mka_ckn"); 651 if (!value) 652 return; 653 fprintf(f, "\tmka_ckn=%s\n", value); 654 os_free(value); 655 } 656 657 #endif /* CONFIG_MACSEC */ 658 659 660 static void wpa_config_write_network(FILE *f, struct wpa_ssid *ssid) 661 { 662 #define STR(t) write_str(f, #t, ssid) 663 #define INT(t) write_int(f, #t, ssid->t, 0) 664 #define INTe(t, m) write_int(f, #t, ssid->eap.m, 0) 665 #define INT_DEF(t, def) write_int(f, #t, ssid->t, def) 666 #define INT_DEFe(t, m, def) write_int(f, #t, ssid->eap.m, def) 667 668 STR(ssid); 669 INT(scan_ssid); 670 write_bssid(f, ssid); 671 write_bssid_hint(f, ssid); 672 write_str(f, "bssid_ignore", ssid); 673 write_str(f, "bssid_accept", ssid); 674 write_psk(f, ssid); 675 INT(mem_only_psk); 676 STR(sae_password); 677 STR(sae_password_id); 678 write_int(f, "sae_pwe", ssid->sae_pwe, DEFAULT_SAE_PWE); 679 write_proto(f, ssid); 680 write_key_mgmt(f, ssid); 681 INT_DEF(bg_scan_period, DEFAULT_BG_SCAN_PERIOD); 682 write_pairwise(f, ssid); 683 write_group(f, ssid); 684 write_group_mgmt(f, ssid); 685 write_auth_alg(f, ssid); 686 STR(bgscan); 687 STR(autoscan); 688 STR(scan_freq); 689 #ifdef IEEE8021X_EAPOL 690 write_eap(f, ssid); 691 STR(identity); 692 STR(anonymous_identity); 693 STR(imsi_identity); 694 STR(machine_identity); 695 STR(password); 696 STR(machine_password); 697 STR(ca_cert); 698 STR(ca_path); 699 STR(client_cert); 700 STR(private_key); 701 STR(private_key_passwd); 702 STR(dh_file); 703 STR(subject_match); 704 STR(check_cert_subject); 705 STR(altsubject_match); 706 STR(domain_suffix_match); 707 STR(domain_match); 708 STR(ca_cert2); 709 STR(ca_path2); 710 STR(client_cert2); 711 STR(private_key2); 712 STR(private_key2_passwd); 713 STR(dh_file2); 714 STR(subject_match2); 715 STR(check_cert_subject2); 716 STR(altsubject_match2); 717 STR(domain_suffix_match2); 718 STR(domain_match2); 719 STR(machine_ca_cert); 720 STR(machine_ca_path); 721 STR(machine_client_cert); 722 STR(machine_private_key); 723 STR(machine_private_key_passwd); 724 STR(machine_dh_file); 725 STR(machine_subject_match); 726 STR(machine_check_cert_subject); 727 STR(machine_altsubject_match); 728 STR(machine_domain_suffix_match); 729 STR(machine_domain_match); 730 STR(phase1); 731 STR(phase2); 732 STR(machine_phase2); 733 STR(pcsc); 734 STR(pin); 735 STR(engine_id); 736 STR(key_id); 737 STR(cert_id); 738 STR(ca_cert_id); 739 STR(key2_id); 740 STR(pin2); 741 STR(engine2_id); 742 STR(cert2_id); 743 STR(ca_cert2_id); 744 INTe(engine, cert.engine); 745 INTe(engine2, phase2_cert.engine); 746 INTe(machine_engine, machine_cert.engine); 747 INT_DEF(eapol_flags, DEFAULT_EAPOL_FLAGS); 748 STR(openssl_ciphers); 749 INTe(erp, erp); 750 #endif /* IEEE8021X_EAPOL */ 751 #ifdef CONFIG_WEP 752 { 753 int i; 754 755 for (i = 0; i < 4; i++) 756 write_wep_key(f, i, ssid); 757 INT(wep_tx_keyidx); 758 } 759 #endif /* CONFIG_WEP */ 760 INT(priority); 761 #ifdef IEEE8021X_EAPOL 762 INT_DEF(eap_workaround, DEFAULT_EAP_WORKAROUND); 763 STR(pac_file); 764 INT_DEFe(fragment_size, fragment_size, DEFAULT_FRAGMENT_SIZE); 765 INTe(ocsp, cert.ocsp); 766 INTe(ocsp2, phase2_cert.ocsp); 767 INTe(machine_ocsp, machine_cert.ocsp); 768 INT_DEFe(sim_num, sim_num, DEFAULT_USER_SELECTED_SIM); 769 #endif /* IEEE8021X_EAPOL */ 770 INT(mode); 771 INT(no_auto_peer); 772 INT(frequency); 773 INT(enable_edmg); 774 INT(edmg_channel); 775 INT(fixed_freq); 776 #ifdef CONFIG_ACS 777 INT(acs); 778 #endif /* CONFIG_ACS */ 779 write_int(f, "proactive_key_caching", ssid->proactive_key_caching, -1); 780 INT(disabled); 781 INT(mixed_cell); 782 INT_DEF(vht, 1); 783 INT_DEF(ht, 1); 784 INT(ht40); 785 INT_DEF(he, 1); 786 INT_DEF(max_oper_chwidth, DEFAULT_MAX_OPER_CHWIDTH); 787 INT(vht_center_freq1); 788 INT(vht_center_freq2); 789 INT(pbss); 790 INT(wps_disabled); 791 INT(fils_dh_group); 792 write_int(f, "ieee80211w", ssid->ieee80211w, 793 MGMT_FRAME_PROTECTION_DEFAULT); 794 STR(id_str); 795 #ifdef CONFIG_P2P 796 write_go_p2p_dev_addr(f, ssid); 797 write_p2p_client_list(f, ssid); 798 write_psk_list(f, ssid); 799 #endif /* CONFIG_P2P */ 800 INT(ap_max_inactivity); 801 INT(dtim_period); 802 INT(beacon_int); 803 #ifdef CONFIG_MACSEC 804 INT(macsec_policy); 805 write_mka_cak(f, ssid); 806 write_mka_ckn(f, ssid); 807 INT(macsec_integ_only); 808 INT(macsec_replay_protect); 809 INT(macsec_replay_window); 810 INT(macsec_port); 811 INT_DEF(mka_priority, DEFAULT_PRIO_NOT_KEY_SERVER); 812 #endif /* CONFIG_MACSEC */ 813 #ifdef CONFIG_HS20 814 INT(update_identifier); 815 STR(roaming_consortium_selection); 816 #endif /* CONFIG_HS20 */ 817 write_int(f, "mac_addr", ssid->mac_addr, -1); 818 #ifdef CONFIG_MESH 819 STR(mesh_basic_rates); 820 INT_DEF(dot11MeshMaxRetries, DEFAULT_MESH_MAX_RETRIES); 821 INT_DEF(dot11MeshRetryTimeout, DEFAULT_MESH_RETRY_TIMEOUT); 822 INT_DEF(dot11MeshConfirmTimeout, DEFAULT_MESH_CONFIRM_TIMEOUT); 823 INT_DEF(dot11MeshHoldingTimeout, DEFAULT_MESH_HOLDING_TIMEOUT); 824 INT_DEF(mesh_rssi_threshold, DEFAULT_MESH_RSSI_THRESHOLD); 825 #endif /* CONFIG_MESH */ 826 INT(wpa_ptk_rekey); 827 INT(wpa_deny_ptk0_rekey); 828 INT(group_rekey); 829 INT(ignore_broadcast_ssid); 830 #ifdef CONFIG_DPP 831 STR(dpp_connector); 832 STR(dpp_netaccesskey); 833 INT(dpp_netaccesskey_expiry); 834 STR(dpp_csign); 835 STR(dpp_pp_key); 836 INT(dpp_pfs); 837 #endif /* CONFIG_DPP */ 838 INT(owe_group); 839 INT(owe_only); 840 INT(owe_ptk_workaround); 841 INT(multi_ap_backhaul_sta); 842 INT(ft_eap_pmksa_caching); 843 INT(beacon_prot); 844 INT(transition_disable); 845 INT(sae_pk); 846 #ifdef CONFIG_HT_OVERRIDES 847 INT_DEF(disable_ht, DEFAULT_DISABLE_HT); 848 INT_DEF(disable_ht40, DEFAULT_DISABLE_HT40); 849 INT_DEF(disable_sgi, DEFAULT_DISABLE_SGI); 850 INT_DEF(disable_ldpc, DEFAULT_DISABLE_LDPC); 851 INT(ht40_intolerant); 852 INT_DEF(tx_stbc, DEFAULT_TX_STBC); 853 INT_DEF(rx_stbc, DEFAULT_RX_STBC); 854 INT_DEF(disable_max_amsdu, DEFAULT_DISABLE_MAX_AMSDU); 855 INT_DEF(ampdu_factor, DEFAULT_AMPDU_FACTOR); 856 INT_DEF(ampdu_density, DEFAULT_AMPDU_DENSITY); 857 STR(ht_mcs); 858 #endif /* CONFIG_HT_OVERRIDES */ 859 #ifdef CONFIG_VHT_OVERRIDES 860 INT(disable_vht); 861 INT(vht_capa); 862 INT(vht_capa_mask); 863 INT_DEF(vht_rx_mcs_nss_1, -1); 864 INT_DEF(vht_rx_mcs_nss_2, -1); 865 INT_DEF(vht_rx_mcs_nss_3, -1); 866 INT_DEF(vht_rx_mcs_nss_4, -1); 867 INT_DEF(vht_rx_mcs_nss_5, -1); 868 INT_DEF(vht_rx_mcs_nss_6, -1); 869 INT_DEF(vht_rx_mcs_nss_7, -1); 870 INT_DEF(vht_rx_mcs_nss_8, -1); 871 INT_DEF(vht_tx_mcs_nss_1, -1); 872 INT_DEF(vht_tx_mcs_nss_2, -1); 873 INT_DEF(vht_tx_mcs_nss_3, -1); 874 INT_DEF(vht_tx_mcs_nss_4, -1); 875 INT_DEF(vht_tx_mcs_nss_5, -1); 876 INT_DEF(vht_tx_mcs_nss_6, -1); 877 INT_DEF(vht_tx_mcs_nss_7, -1); 878 INT_DEF(vht_tx_mcs_nss_8, -1); 879 #endif /* CONFIG_VHT_OVERRIDES */ 880 #ifdef CONFIG_HE_OVERRIDES 881 INT(disable_he); 882 #endif /* CONFIG_HE_OVERRIDES */ 883 884 #undef STR 885 #undef INT 886 #undef INT_DEF 887 } 888 889 890 static void wpa_config_write_cred(FILE *f, struct wpa_cred *cred) 891 { 892 size_t i; 893 894 if (cred->priority) 895 fprintf(f, "\tpriority=%d\n", cred->priority); 896 if (cred->pcsc) 897 fprintf(f, "\tpcsc=%d\n", cred->pcsc); 898 if (cred->realm) 899 fprintf(f, "\trealm=\"%s\"\n", cred->realm); 900 if (cred->username) 901 fprintf(f, "\tusername=\"%s\"\n", cred->username); 902 if (cred->password && cred->ext_password) 903 fprintf(f, "\tpassword=ext:%s\n", cred->password); 904 else if (cred->password) 905 fprintf(f, "\tpassword=\"%s\"\n", cred->password); 906 if (cred->ca_cert) 907 fprintf(f, "\tca_cert=\"%s\"\n", cred->ca_cert); 908 if (cred->client_cert) 909 fprintf(f, "\tclient_cert=\"%s\"\n", cred->client_cert); 910 if (cred->private_key) 911 fprintf(f, "\tprivate_key=\"%s\"\n", cred->private_key); 912 if (cred->private_key_passwd) 913 fprintf(f, "\tprivate_key_passwd=\"%s\"\n", 914 cred->private_key_passwd); 915 if (cred->imsi) 916 fprintf(f, "\timsi=\"%s\"\n", cred->imsi); 917 if (cred->milenage) 918 fprintf(f, "\tmilenage=\"%s\"\n", cred->milenage); 919 for (i = 0; i < cred->num_domain; i++) 920 fprintf(f, "\tdomain=\"%s\"\n", cred->domain[i]); 921 if (cred->domain_suffix_match) 922 fprintf(f, "\tdomain_suffix_match=\"%s\"\n", 923 cred->domain_suffix_match); 924 if (cred->roaming_consortium_len) { 925 fprintf(f, "\troaming_consortium="); 926 for (i = 0; i < cred->roaming_consortium_len; i++) 927 fprintf(f, "%02x", cred->roaming_consortium[i]); 928 fprintf(f, "\n"); 929 } 930 if (cred->eap_method) { 931 const char *name; 932 name = eap_get_name(cred->eap_method[0].vendor, 933 cred->eap_method[0].method); 934 if (name) 935 fprintf(f, "\teap=%s\n", name); 936 } 937 if (cred->phase1) 938 fprintf(f, "\tphase1=\"%s\"\n", cred->phase1); 939 if (cred->phase2) 940 fprintf(f, "\tphase2=\"%s\"\n", cred->phase2); 941 if (cred->excluded_ssid) { 942 size_t j; 943 for (i = 0; i < cred->num_excluded_ssid; i++) { 944 struct excluded_ssid *e = &cred->excluded_ssid[i]; 945 fprintf(f, "\texcluded_ssid="); 946 for (j = 0; j < e->ssid_len; j++) 947 fprintf(f, "%02x", e->ssid[j]); 948 fprintf(f, "\n"); 949 } 950 } 951 if (cred->roaming_partner) { 952 for (i = 0; i < cred->num_roaming_partner; i++) { 953 struct roaming_partner *p = &cred->roaming_partner[i]; 954 fprintf(f, "\troaming_partner=\"%s,%d,%u,%s\"\n", 955 p->fqdn, p->exact_match, p->priority, 956 p->country); 957 } 958 } 959 if (cred->update_identifier) 960 fprintf(f, "\tupdate_identifier=%d\n", cred->update_identifier); 961 962 if (cred->provisioning_sp) 963 fprintf(f, "\tprovisioning_sp=\"%s\"\n", cred->provisioning_sp); 964 if (cred->sp_priority) 965 fprintf(f, "\tsp_priority=%d\n", cred->sp_priority); 966 967 if (cred->min_dl_bandwidth_home) 968 fprintf(f, "\tmin_dl_bandwidth_home=%u\n", 969 cred->min_dl_bandwidth_home); 970 if (cred->min_ul_bandwidth_home) 971 fprintf(f, "\tmin_ul_bandwidth_home=%u\n", 972 cred->min_ul_bandwidth_home); 973 if (cred->min_dl_bandwidth_roaming) 974 fprintf(f, "\tmin_dl_bandwidth_roaming=%u\n", 975 cred->min_dl_bandwidth_roaming); 976 if (cred->min_ul_bandwidth_roaming) 977 fprintf(f, "\tmin_ul_bandwidth_roaming=%u\n", 978 cred->min_ul_bandwidth_roaming); 979 980 if (cred->max_bss_load) 981 fprintf(f, "\tmax_bss_load=%u\n", 982 cred->max_bss_load); 983 984 if (cred->ocsp) 985 fprintf(f, "\tocsp=%d\n", cred->ocsp); 986 987 if (cred->num_req_conn_capab) { 988 for (i = 0; i < cred->num_req_conn_capab; i++) { 989 int *ports; 990 991 fprintf(f, "\treq_conn_capab=%u", 992 cred->req_conn_capab_proto[i]); 993 ports = cred->req_conn_capab_port[i]; 994 if (ports) { 995 int j; 996 for (j = 0; ports[j] != -1; j++) { 997 fprintf(f, "%s%d", j > 0 ? "," : ":", 998 ports[j]); 999 } 1000 } 1001 fprintf(f, "\n"); 1002 } 1003 } 1004 1005 if (cred->required_roaming_consortium_len) { 1006 fprintf(f, "\trequired_roaming_consortium="); 1007 for (i = 0; i < cred->required_roaming_consortium_len; i++) 1008 fprintf(f, "%02x", 1009 cred->required_roaming_consortium[i]); 1010 fprintf(f, "\n"); 1011 } 1012 1013 if (cred->num_roaming_consortiums) { 1014 size_t j; 1015 1016 fprintf(f, "\troaming_consortiums=\""); 1017 for (i = 0; i < cred->num_roaming_consortiums; i++) { 1018 if (i > 0) 1019 fprintf(f, ","); 1020 for (j = 0; j < cred->roaming_consortiums_len[i]; j++) 1021 fprintf(f, "%02x", 1022 cred->roaming_consortiums[i][j]); 1023 } 1024 fprintf(f, "\"\n"); 1025 } 1026 1027 if (cred->sim_num != DEFAULT_USER_SELECTED_SIM) 1028 fprintf(f, "\tsim_num=%d\n", cred->sim_num); 1029 } 1030 1031 1032 #ifndef CONFIG_NO_CONFIG_BLOBS 1033 static int wpa_config_write_blob(FILE *f, struct wpa_config_blob *blob) 1034 { 1035 char *encoded; 1036 1037 encoded = base64_encode(blob->data, blob->len, NULL); 1038 if (encoded == NULL) 1039 return -1; 1040 1041 fprintf(f, "\nblob-base64-%s={\n%s}\n", blob->name, encoded); 1042 os_free(encoded); 1043 return 0; 1044 } 1045 #endif /* CONFIG_NO_CONFIG_BLOBS */ 1046 1047 1048 static void write_global_bin(FILE *f, const char *field, 1049 const struct wpabuf *val) 1050 { 1051 size_t i; 1052 const u8 *pos; 1053 1054 if (val == NULL) 1055 return; 1056 1057 fprintf(f, "%s=", field); 1058 pos = wpabuf_head(val); 1059 for (i = 0; i < wpabuf_len(val); i++) 1060 fprintf(f, "%02X", *pos++); 1061 fprintf(f, "\n"); 1062 } 1063 1064 1065 static void wpa_config_write_global(FILE *f, struct wpa_config *config) 1066 { 1067 #ifdef CONFIG_CTRL_IFACE 1068 if (config->ctrl_interface) 1069 fprintf(f, "ctrl_interface=%s\n", config->ctrl_interface); 1070 if (config->ctrl_interface_group) 1071 fprintf(f, "ctrl_interface_group=%s\n", 1072 config->ctrl_interface_group); 1073 #endif /* CONFIG_CTRL_IFACE */ 1074 if (config->eapol_version != DEFAULT_EAPOL_VERSION) 1075 fprintf(f, "eapol_version=%d\n", config->eapol_version); 1076 if (config->ap_scan != DEFAULT_AP_SCAN) 1077 fprintf(f, "ap_scan=%d\n", config->ap_scan); 1078 if (config->disable_scan_offload) 1079 fprintf(f, "disable_scan_offload=%d\n", 1080 config->disable_scan_offload); 1081 if (config->fast_reauth != DEFAULT_FAST_REAUTH) 1082 fprintf(f, "fast_reauth=%d\n", config->fast_reauth); 1083 if (config->opensc_engine_path) 1084 fprintf(f, "opensc_engine_path=%s\n", 1085 config->opensc_engine_path); 1086 if (config->pkcs11_engine_path) 1087 fprintf(f, "pkcs11_engine_path=%s\n", 1088 config->pkcs11_engine_path); 1089 if (config->pkcs11_module_path) 1090 fprintf(f, "pkcs11_module_path=%s\n", 1091 config->pkcs11_module_path); 1092 if (config->openssl_ciphers) 1093 fprintf(f, "openssl_ciphers=%s\n", config->openssl_ciphers); 1094 if (config->pcsc_reader) 1095 fprintf(f, "pcsc_reader=%s\n", config->pcsc_reader); 1096 if (config->pcsc_pin) 1097 fprintf(f, "pcsc_pin=%s\n", config->pcsc_pin); 1098 if (config->driver_param) 1099 fprintf(f, "driver_param=%s\n", config->driver_param); 1100 if (config->dot11RSNAConfigPMKLifetime) 1101 fprintf(f, "dot11RSNAConfigPMKLifetime=%u\n", 1102 config->dot11RSNAConfigPMKLifetime); 1103 if (config->dot11RSNAConfigPMKReauthThreshold) 1104 fprintf(f, "dot11RSNAConfigPMKReauthThreshold=%u\n", 1105 config->dot11RSNAConfigPMKReauthThreshold); 1106 if (config->dot11RSNAConfigSATimeout) 1107 fprintf(f, "dot11RSNAConfigSATimeout=%u\n", 1108 config->dot11RSNAConfigSATimeout); 1109 if (config->update_config) 1110 fprintf(f, "update_config=%d\n", config->update_config); 1111 #ifdef CONFIG_WPS 1112 if (!is_nil_uuid(config->uuid)) { 1113 char buf[40]; 1114 uuid_bin2str(config->uuid, buf, sizeof(buf)); 1115 fprintf(f, "uuid=%s\n", buf); 1116 } 1117 if (config->auto_uuid) 1118 fprintf(f, "auto_uuid=%d\n", config->auto_uuid); 1119 if (config->device_name) 1120 fprintf(f, "device_name=%s\n", config->device_name); 1121 if (config->manufacturer) 1122 fprintf(f, "manufacturer=%s\n", config->manufacturer); 1123 if (config->model_name) 1124 fprintf(f, "model_name=%s\n", config->model_name); 1125 if (config->model_number) 1126 fprintf(f, "model_number=%s\n", config->model_number); 1127 if (config->serial_number) 1128 fprintf(f, "serial_number=%s\n", config->serial_number); 1129 { 1130 char _buf[WPS_DEV_TYPE_BUFSIZE], *buf; 1131 buf = wps_dev_type_bin2str(config->device_type, 1132 _buf, sizeof(_buf)); 1133 if (os_strcmp(buf, "0-00000000-0") != 0) 1134 fprintf(f, "device_type=%s\n", buf); 1135 } 1136 if (WPA_GET_BE32(config->os_version)) 1137 fprintf(f, "os_version=%08x\n", 1138 WPA_GET_BE32(config->os_version)); 1139 if (config->config_methods) 1140 fprintf(f, "config_methods=%s\n", config->config_methods); 1141 if (config->wps_cred_processing) 1142 fprintf(f, "wps_cred_processing=%d\n", 1143 config->wps_cred_processing); 1144 if (config->wps_cred_add_sae) 1145 fprintf(f, "wps_cred_add_sae=%d\n", 1146 config->wps_cred_add_sae); 1147 if (config->wps_vendor_ext_m1) { 1148 int i, len = wpabuf_len(config->wps_vendor_ext_m1); 1149 const u8 *p = wpabuf_head_u8(config->wps_vendor_ext_m1); 1150 if (len > 0) { 1151 fprintf(f, "wps_vendor_ext_m1="); 1152 for (i = 0; i < len; i++) 1153 fprintf(f, "%02x", *p++); 1154 fprintf(f, "\n"); 1155 } 1156 } 1157 #endif /* CONFIG_WPS */ 1158 #ifdef CONFIG_P2P 1159 { 1160 int i; 1161 char _buf[WPS_DEV_TYPE_BUFSIZE], *buf; 1162 1163 for (i = 0; i < config->num_sec_device_types; i++) { 1164 buf = wps_dev_type_bin2str(config->sec_device_type[i], 1165 _buf, sizeof(_buf)); 1166 if (buf) 1167 fprintf(f, "sec_device_type=%s\n", buf); 1168 } 1169 } 1170 if (config->p2p_listen_reg_class) 1171 fprintf(f, "p2p_listen_reg_class=%d\n", 1172 config->p2p_listen_reg_class); 1173 if (config->p2p_listen_channel) 1174 fprintf(f, "p2p_listen_channel=%d\n", 1175 config->p2p_listen_channel); 1176 if (config->p2p_oper_reg_class) 1177 fprintf(f, "p2p_oper_reg_class=%d\n", 1178 config->p2p_oper_reg_class); 1179 if (config->p2p_oper_channel) 1180 fprintf(f, "p2p_oper_channel=%d\n", config->p2p_oper_channel); 1181 if (config->p2p_go_intent != DEFAULT_P2P_GO_INTENT) 1182 fprintf(f, "p2p_go_intent=%d\n", config->p2p_go_intent); 1183 if (config->p2p_ssid_postfix) 1184 fprintf(f, "p2p_ssid_postfix=%s\n", config->p2p_ssid_postfix); 1185 if (config->persistent_reconnect) 1186 fprintf(f, "persistent_reconnect=%d\n", 1187 config->persistent_reconnect); 1188 if (config->p2p_intra_bss != DEFAULT_P2P_INTRA_BSS) 1189 fprintf(f, "p2p_intra_bss=%d\n", config->p2p_intra_bss); 1190 if (config->p2p_group_idle) 1191 fprintf(f, "p2p_group_idle=%d\n", config->p2p_group_idle); 1192 if (config->p2p_passphrase_len) 1193 fprintf(f, "p2p_passphrase_len=%u\n", 1194 config->p2p_passphrase_len); 1195 if (config->p2p_pref_chan) { 1196 unsigned int i; 1197 fprintf(f, "p2p_pref_chan="); 1198 for (i = 0; i < config->num_p2p_pref_chan; i++) { 1199 fprintf(f, "%s%u:%u", i > 0 ? "," : "", 1200 config->p2p_pref_chan[i].op_class, 1201 config->p2p_pref_chan[i].chan); 1202 } 1203 fprintf(f, "\n"); 1204 } 1205 if (config->p2p_no_go_freq.num) { 1206 char *val = freq_range_list_str(&config->p2p_no_go_freq); 1207 if (val) { 1208 fprintf(f, "p2p_no_go_freq=%s\n", val); 1209 os_free(val); 1210 } 1211 } 1212 if (config->p2p_add_cli_chan) 1213 fprintf(f, "p2p_add_cli_chan=%d\n", config->p2p_add_cli_chan); 1214 if (config->p2p_optimize_listen_chan != 1215 DEFAULT_P2P_OPTIMIZE_LISTEN_CHAN) 1216 fprintf(f, "p2p_optimize_listen_chan=%d\n", 1217 config->p2p_optimize_listen_chan); 1218 if (config->p2p_go_ht40) 1219 fprintf(f, "p2p_go_ht40=%d\n", config->p2p_go_ht40); 1220 if (config->p2p_go_vht) 1221 fprintf(f, "p2p_go_vht=%d\n", config->p2p_go_vht); 1222 if (config->p2p_go_he) 1223 fprintf(f, "p2p_go_he=%d\n", config->p2p_go_he); 1224 if (config->p2p_go_edmg) 1225 fprintf(f, "p2p_go_edmg=%d\n", config->p2p_go_edmg); 1226 if (config->p2p_go_ctwindow != DEFAULT_P2P_GO_CTWINDOW) 1227 fprintf(f, "p2p_go_ctwindow=%d\n", config->p2p_go_ctwindow); 1228 if (config->p2p_disabled) 1229 fprintf(f, "p2p_disabled=%d\n", config->p2p_disabled); 1230 if (config->p2p_no_group_iface) 1231 fprintf(f, "p2p_no_group_iface=%d\n", 1232 config->p2p_no_group_iface); 1233 if (config->p2p_ignore_shared_freq) 1234 fprintf(f, "p2p_ignore_shared_freq=%d\n", 1235 config->p2p_ignore_shared_freq); 1236 if (config->p2p_cli_probe) 1237 fprintf(f, "p2p_cli_probe=%d\n", config->p2p_cli_probe); 1238 if (config->p2p_go_freq_change_policy != DEFAULT_P2P_GO_FREQ_MOVE) 1239 fprintf(f, "p2p_go_freq_change_policy=%u\n", 1240 config->p2p_go_freq_change_policy); 1241 1242 if (config->p2p_6ghz_disable) 1243 fprintf(f, "p2p_6ghz_disable=%d\n", config->p2p_6ghz_disable); 1244 1245 if (WPA_GET_BE32(config->ip_addr_go)) 1246 fprintf(f, "ip_addr_go=%u.%u.%u.%u\n", 1247 config->ip_addr_go[0], config->ip_addr_go[1], 1248 config->ip_addr_go[2], config->ip_addr_go[3]); 1249 if (WPA_GET_BE32(config->ip_addr_mask)) 1250 fprintf(f, "ip_addr_mask=%u.%u.%u.%u\n", 1251 config->ip_addr_mask[0], config->ip_addr_mask[1], 1252 config->ip_addr_mask[2], config->ip_addr_mask[3]); 1253 if (WPA_GET_BE32(config->ip_addr_start)) 1254 fprintf(f, "ip_addr_start=%u.%u.%u.%u\n", 1255 config->ip_addr_start[0], config->ip_addr_start[1], 1256 config->ip_addr_start[2], config->ip_addr_start[3]); 1257 if (WPA_GET_BE32(config->ip_addr_end)) 1258 fprintf(f, "ip_addr_end=%u.%u.%u.%u\n", 1259 config->ip_addr_end[0], config->ip_addr_end[1], 1260 config->ip_addr_end[2], config->ip_addr_end[3]); 1261 #endif /* CONFIG_P2P */ 1262 if (config->country[0] && config->country[1]) { 1263 fprintf(f, "country=%c%c\n", 1264 config->country[0], config->country[1]); 1265 } 1266 if (config->bss_max_count != DEFAULT_BSS_MAX_COUNT) 1267 fprintf(f, "bss_max_count=%u\n", config->bss_max_count); 1268 if (config->bss_expiration_age != DEFAULT_BSS_EXPIRATION_AGE) 1269 fprintf(f, "bss_expiration_age=%u\n", 1270 config->bss_expiration_age); 1271 if (config->bss_expiration_scan_count != 1272 DEFAULT_BSS_EXPIRATION_SCAN_COUNT) 1273 fprintf(f, "bss_expiration_scan_count=%u\n", 1274 config->bss_expiration_scan_count); 1275 if (config->filter_ssids) 1276 fprintf(f, "filter_ssids=%d\n", config->filter_ssids); 1277 if (config->filter_rssi) 1278 fprintf(f, "filter_rssi=%d\n", config->filter_rssi); 1279 if (config->max_num_sta != DEFAULT_MAX_NUM_STA) 1280 fprintf(f, "max_num_sta=%u\n", config->max_num_sta); 1281 if (config->ap_isolate != DEFAULT_AP_ISOLATE) 1282 fprintf(f, "ap_isolate=%u\n", config->ap_isolate); 1283 if (config->disassoc_low_ack) 1284 fprintf(f, "disassoc_low_ack=%d\n", config->disassoc_low_ack); 1285 #ifdef CONFIG_HS20 1286 if (config->hs20) 1287 fprintf(f, "hs20=1\n"); 1288 #endif /* CONFIG_HS20 */ 1289 #ifdef CONFIG_INTERWORKING 1290 if (config->interworking) 1291 fprintf(f, "interworking=%d\n", config->interworking); 1292 if (!is_zero_ether_addr(config->hessid)) 1293 fprintf(f, "hessid=" MACSTR "\n", MAC2STR(config->hessid)); 1294 if (config->access_network_type != DEFAULT_ACCESS_NETWORK_TYPE) 1295 fprintf(f, "access_network_type=%d\n", 1296 config->access_network_type); 1297 if (config->go_interworking) 1298 fprintf(f, "go_interworking=%d\n", config->go_interworking); 1299 if (config->go_access_network_type) 1300 fprintf(f, "go_access_network_type=%d\n", 1301 config->go_access_network_type); 1302 if (config->go_internet) 1303 fprintf(f, "go_internet=%d\n", config->go_internet); 1304 if (config->go_venue_group) 1305 fprintf(f, "go_venue_group=%d\n", config->go_venue_group); 1306 if (config->go_venue_type) 1307 fprintf(f, "go_venue_type=%d\n", config->go_venue_type); 1308 #endif /* CONFIG_INTERWORKING */ 1309 if (config->pbc_in_m1) 1310 fprintf(f, "pbc_in_m1=%d\n", config->pbc_in_m1); 1311 if (config->wps_nfc_pw_from_config) { 1312 if (config->wps_nfc_dev_pw_id) 1313 fprintf(f, "wps_nfc_dev_pw_id=%d\n", 1314 config->wps_nfc_dev_pw_id); 1315 write_global_bin(f, "wps_nfc_dh_pubkey", 1316 config->wps_nfc_dh_pubkey); 1317 write_global_bin(f, "wps_nfc_dh_privkey", 1318 config->wps_nfc_dh_privkey); 1319 write_global_bin(f, "wps_nfc_dev_pw", config->wps_nfc_dev_pw); 1320 } 1321 1322 if (config->ext_password_backend) 1323 fprintf(f, "ext_password_backend=%s\n", 1324 config->ext_password_backend); 1325 if (config->p2p_go_max_inactivity != DEFAULT_P2P_GO_MAX_INACTIVITY) 1326 fprintf(f, "p2p_go_max_inactivity=%d\n", 1327 config->p2p_go_max_inactivity); 1328 if (config->auto_interworking) 1329 fprintf(f, "auto_interworking=%d\n", 1330 config->auto_interworking); 1331 if (config->okc) 1332 fprintf(f, "okc=%d\n", config->okc); 1333 if (config->pmf) 1334 fprintf(f, "pmf=%d\n", config->pmf); 1335 if (config->dtim_period) 1336 fprintf(f, "dtim_period=%d\n", config->dtim_period); 1337 if (config->beacon_int) 1338 fprintf(f, "beacon_int=%d\n", config->beacon_int); 1339 1340 if (config->sae_groups) { 1341 int i; 1342 fprintf(f, "sae_groups="); 1343 for (i = 0; config->sae_groups[i] > 0; i++) { 1344 fprintf(f, "%s%d", i > 0 ? " " : "", 1345 config->sae_groups[i]); 1346 } 1347 fprintf(f, "\n"); 1348 } 1349 1350 if (config->sae_pwe) 1351 fprintf(f, "sae_pwe=%d\n", config->sae_pwe); 1352 1353 if (config->sae_pmkid_in_assoc) 1354 fprintf(f, "sae_pmkid_in_assoc=%d\n", 1355 config->sae_pmkid_in_assoc); 1356 1357 if (config->ap_vendor_elements) { 1358 int i, len = wpabuf_len(config->ap_vendor_elements); 1359 const u8 *p = wpabuf_head_u8(config->ap_vendor_elements); 1360 if (len > 0) { 1361 fprintf(f, "ap_vendor_elements="); 1362 for (i = 0; i < len; i++) 1363 fprintf(f, "%02x", *p++); 1364 fprintf(f, "\n"); 1365 } 1366 } 1367 1368 if (config->ap_assocresp_elements) { 1369 int i, len = wpabuf_len(config->ap_assocresp_elements); 1370 const u8 *p = wpabuf_head_u8(config->ap_assocresp_elements); 1371 1372 if (len > 0) { 1373 fprintf(f, "ap_assocresp_elements="); 1374 for (i = 0; i < len; i++) 1375 fprintf(f, "%02x", *p++); 1376 fprintf(f, "\n"); 1377 } 1378 } 1379 1380 if (config->ignore_old_scan_res) 1381 fprintf(f, "ignore_old_scan_res=%d\n", 1382 config->ignore_old_scan_res); 1383 1384 if (config->freq_list && config->freq_list[0]) { 1385 int i; 1386 fprintf(f, "freq_list="); 1387 for (i = 0; config->freq_list[i]; i++) { 1388 fprintf(f, "%s%d", i > 0 ? " " : "", 1389 config->freq_list[i]); 1390 } 1391 fprintf(f, "\n"); 1392 } 1393 if (config->initial_freq_list && config->initial_freq_list[0]) { 1394 int i; 1395 fprintf(f, "initial_freq_list="); 1396 for (i = 0; config->initial_freq_list[i]; i++) { 1397 fprintf(f, "%s%d", i > 0 ? " " : "", 1398 config->initial_freq_list[i]); 1399 } 1400 fprintf(f, "\n"); 1401 } 1402 if (config->scan_cur_freq != DEFAULT_SCAN_CUR_FREQ) 1403 fprintf(f, "scan_cur_freq=%d\n", config->scan_cur_freq); 1404 1405 if (config->scan_res_valid_for_connect != 1406 DEFAULT_SCAN_RES_VALID_FOR_CONNECT) 1407 fprintf(f, "scan_res_valid_for_connect=%d\n", 1408 config->scan_res_valid_for_connect); 1409 1410 if (config->sched_scan_interval) 1411 fprintf(f, "sched_scan_interval=%u\n", 1412 config->sched_scan_interval); 1413 1414 if (config->sched_scan_start_delay) 1415 fprintf(f, "sched_scan_start_delay=%u\n", 1416 config->sched_scan_start_delay); 1417 1418 if (config->external_sim) 1419 fprintf(f, "external_sim=%d\n", config->external_sim); 1420 1421 if (config->tdls_external_control) 1422 fprintf(f, "tdls_external_control=%d\n", 1423 config->tdls_external_control); 1424 1425 if (config->wowlan_triggers) 1426 fprintf(f, "wowlan_triggers=%s\n", 1427 config->wowlan_triggers); 1428 1429 if (config->bgscan) 1430 fprintf(f, "bgscan=\"%s\"\n", config->bgscan); 1431 1432 if (config->autoscan) 1433 fprintf(f, "autoscan=%s\n", config->autoscan); 1434 1435 if (config->p2p_search_delay != DEFAULT_P2P_SEARCH_DELAY) 1436 fprintf(f, "p2p_search_delay=%u\n", 1437 config->p2p_search_delay); 1438 1439 if (config->mac_addr) 1440 fprintf(f, "mac_addr=%d\n", config->mac_addr); 1441 1442 if (config->rand_addr_lifetime != DEFAULT_RAND_ADDR_LIFETIME) 1443 fprintf(f, "rand_addr_lifetime=%u\n", 1444 config->rand_addr_lifetime); 1445 1446 if (config->preassoc_mac_addr) 1447 fprintf(f, "preassoc_mac_addr=%d\n", config->preassoc_mac_addr); 1448 1449 if (config->key_mgmt_offload != DEFAULT_KEY_MGMT_OFFLOAD) 1450 fprintf(f, "key_mgmt_offload=%d\n", config->key_mgmt_offload); 1451 1452 if (config->user_mpm != DEFAULT_USER_MPM) 1453 fprintf(f, "user_mpm=%d\n", config->user_mpm); 1454 1455 if (config->max_peer_links != DEFAULT_MAX_PEER_LINKS) 1456 fprintf(f, "max_peer_links=%d\n", config->max_peer_links); 1457 1458 if (config->cert_in_cb != DEFAULT_CERT_IN_CB) 1459 fprintf(f, "cert_in_cb=%d\n", config->cert_in_cb); 1460 1461 if (config->mesh_max_inactivity != DEFAULT_MESH_MAX_INACTIVITY) 1462 fprintf(f, "mesh_max_inactivity=%d\n", 1463 config->mesh_max_inactivity); 1464 1465 if (config->dot11RSNASAERetransPeriod != 1466 DEFAULT_DOT11_RSNA_SAE_RETRANS_PERIOD) 1467 fprintf(f, "dot11RSNASAERetransPeriod=%d\n", 1468 config->dot11RSNASAERetransPeriod); 1469 1470 if (config->passive_scan) 1471 fprintf(f, "passive_scan=%d\n", config->passive_scan); 1472 1473 if (config->reassoc_same_bss_optim) 1474 fprintf(f, "reassoc_same_bss_optim=%d\n", 1475 config->reassoc_same_bss_optim); 1476 1477 if (config->wps_priority) 1478 fprintf(f, "wps_priority=%d\n", config->wps_priority); 1479 1480 if (config->wpa_rsc_relaxation != DEFAULT_WPA_RSC_RELAXATION) 1481 fprintf(f, "wpa_rsc_relaxation=%d\n", 1482 config->wpa_rsc_relaxation); 1483 1484 if (config->sched_scan_plans) 1485 fprintf(f, "sched_scan_plans=%s\n", config->sched_scan_plans); 1486 1487 #ifdef CONFIG_MBO 1488 if (config->non_pref_chan) 1489 fprintf(f, "non_pref_chan=%s\n", config->non_pref_chan); 1490 if (config->mbo_cell_capa != DEFAULT_MBO_CELL_CAPA) 1491 fprintf(f, "mbo_cell_capa=%u\n", config->mbo_cell_capa); 1492 if (config->disassoc_imminent_rssi_threshold != 1493 DEFAULT_DISASSOC_IMMINENT_RSSI_THRESHOLD) 1494 fprintf(f, "disassoc_imminent_rssi_threshold=%d\n", 1495 config->disassoc_imminent_rssi_threshold); 1496 if (config->oce != DEFAULT_OCE_SUPPORT) 1497 fprintf(f, "oce=%u\n", config->oce); 1498 #endif /* CONFIG_MBO */ 1499 1500 if (config->gas_address3) 1501 fprintf(f, "gas_address3=%d\n", config->gas_address3); 1502 1503 if (config->ftm_responder) 1504 fprintf(f, "ftm_responder=%d\n", config->ftm_responder); 1505 if (config->ftm_initiator) 1506 fprintf(f, "ftm_initiator=%d\n", config->ftm_initiator); 1507 1508 if (config->osu_dir) 1509 fprintf(f, "osu_dir=%s\n", config->osu_dir); 1510 1511 if (config->fst_group_id) 1512 fprintf(f, "fst_group_id=%s\n", config->fst_group_id); 1513 if (config->fst_priority) 1514 fprintf(f, "fst_priority=%d\n", config->fst_priority); 1515 if (config->fst_llt) 1516 fprintf(f, "fst_llt=%d\n", config->fst_llt); 1517 1518 if (config->gas_rand_addr_lifetime != DEFAULT_RAND_ADDR_LIFETIME) 1519 fprintf(f, "gas_rand_addr_lifetime=%u\n", 1520 config->gas_rand_addr_lifetime); 1521 if (config->gas_rand_mac_addr) 1522 fprintf(f, "gas_rand_mac_addr=%d\n", config->gas_rand_mac_addr); 1523 if (config->dpp_config_processing) 1524 fprintf(f, "dpp_config_processing=%d\n", 1525 config->dpp_config_processing); 1526 if (config->coloc_intf_reporting) 1527 fprintf(f, "coloc_intf_reporting=%d\n", 1528 config->coloc_intf_reporting); 1529 if (config->p2p_device_random_mac_addr) 1530 fprintf(f, "p2p_device_random_mac_addr=%d\n", 1531 config->p2p_device_random_mac_addr); 1532 if (!is_zero_ether_addr(config->p2p_device_persistent_mac_addr)) 1533 fprintf(f, "p2p_device_persistent_mac_addr=" MACSTR "\n", 1534 MAC2STR(config->p2p_device_persistent_mac_addr)); 1535 if (config->p2p_interface_random_mac_addr) 1536 fprintf(f, "p2p_interface_random_mac_addr=%d\n", 1537 config->p2p_interface_random_mac_addr); 1538 if (config->disable_btm) 1539 fprintf(f, "disable_btm=1\n"); 1540 if (config->extended_key_id != DEFAULT_EXTENDED_KEY_ID) 1541 fprintf(f, "extended_key_id=%d\n", 1542 config->extended_key_id); 1543 if (config->wowlan_disconnect_on_deinit) 1544 fprintf(f, "wowlan_disconnect_on_deinit=%d\n", 1545 config->wowlan_disconnect_on_deinit); 1546 } 1547 1548 #endif /* CONFIG_NO_CONFIG_WRITE */ 1549 1550 1551 int wpa_config_write(const char *name, struct wpa_config *config) 1552 { 1553 #ifndef CONFIG_NO_CONFIG_WRITE 1554 FILE *f; 1555 struct wpa_ssid *ssid; 1556 struct wpa_cred *cred; 1557 #ifndef CONFIG_NO_CONFIG_BLOBS 1558 struct wpa_config_blob *blob; 1559 #endif /* CONFIG_NO_CONFIG_BLOBS */ 1560 int ret = 0; 1561 const char *orig_name = name; 1562 int tmp_len; 1563 char *tmp_name; 1564 1565 if (!name) { 1566 wpa_printf(MSG_ERROR, "No configuration file for writing"); 1567 return -1; 1568 } 1569 1570 tmp_len = os_strlen(name) + 5; /* allow space for .tmp suffix */ 1571 tmp_name = os_malloc(tmp_len); 1572 if (tmp_name) { 1573 os_snprintf(tmp_name, tmp_len, "%s.tmp", name); 1574 name = tmp_name; 1575 } 1576 1577 wpa_printf(MSG_DEBUG, "Writing configuration file '%s'", name); 1578 1579 f = fopen(name, "w"); 1580 if (f == NULL) { 1581 wpa_printf(MSG_DEBUG, "Failed to open '%s' for writing", name); 1582 os_free(tmp_name); 1583 return -1; 1584 } 1585 1586 wpa_config_write_global(f, config); 1587 1588 for (cred = config->cred; cred; cred = cred->next) { 1589 if (cred->temporary) 1590 continue; 1591 fprintf(f, "\ncred={\n"); 1592 wpa_config_write_cred(f, cred); 1593 fprintf(f, "}\n"); 1594 } 1595 1596 for (ssid = config->ssid; ssid; ssid = ssid->next) { 1597 if (ssid->key_mgmt == WPA_KEY_MGMT_WPS || ssid->temporary) 1598 continue; /* do not save temporary networks */ 1599 if (wpa_key_mgmt_wpa_psk_no_sae(ssid->key_mgmt) && 1600 !ssid->psk_set && !ssid->passphrase) 1601 continue; /* do not save invalid network */ 1602 if (wpa_key_mgmt_sae(ssid->key_mgmt) && 1603 !ssid->passphrase && !ssid->sae_password) 1604 continue; /* do not save invalid network */ 1605 fprintf(f, "\nnetwork={\n"); 1606 wpa_config_write_network(f, ssid); 1607 fprintf(f, "}\n"); 1608 } 1609 1610 #ifndef CONFIG_NO_CONFIG_BLOBS 1611 for (blob = config->blobs; blob; blob = blob->next) { 1612 ret = wpa_config_write_blob(f, blob); 1613 if (ret) 1614 break; 1615 } 1616 #endif /* CONFIG_NO_CONFIG_BLOBS */ 1617 1618 os_fdatasync(f); 1619 1620 fclose(f); 1621 1622 if (tmp_name) { 1623 int chmod_ret = 0; 1624 1625 #ifdef ANDROID 1626 chmod_ret = chmod(tmp_name, 1627 S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP); 1628 #endif /* ANDROID */ 1629 if (chmod_ret != 0 || rename(tmp_name, orig_name) != 0) 1630 ret = -1; 1631 1632 os_free(tmp_name); 1633 } 1634 1635 wpa_printf(MSG_DEBUG, "Configuration file '%s' written %ssuccessfully", 1636 orig_name, ret ? "un" : ""); 1637 return ret; 1638 #else /* CONFIG_NO_CONFIG_WRITE */ 1639 return -1; 1640 #endif /* CONFIG_NO_CONFIG_WRITE */ 1641 } 1642