1*f05cddf9SRui Paulo /* 2*f05cddf9SRui Paulo * Copyright (c) 2009, Atheros Communications, Inc. 3*f05cddf9SRui Paulo * Copyright (c) 2011-2012, Qualcomm Atheros, Inc. 4*f05cddf9SRui Paulo * 5*f05cddf9SRui Paulo * This software may be distributed under the terms of the BSD license. 6*f05cddf9SRui Paulo * See README for more details. 7*f05cddf9SRui Paulo */ 8*f05cddf9SRui Paulo 9*f05cddf9SRui Paulo #include "includes.h" 10*f05cddf9SRui Paulo 11*f05cddf9SRui Paulo #include "common.h" 12*f05cddf9SRui Paulo #include "eloop.h" 13*f05cddf9SRui Paulo #include "common/ieee802_11_common.h" 14*f05cddf9SRui Paulo #include "common/ieee802_11_defs.h" 15*f05cddf9SRui Paulo #include "common/gas.h" 16*f05cddf9SRui Paulo #include "common/wpa_ctrl.h" 17*f05cddf9SRui Paulo #include "wpa_supplicant_i.h" 18*f05cddf9SRui Paulo #include "driver_i.h" 19*f05cddf9SRui Paulo #include "config.h" 20*f05cddf9SRui Paulo #include "bss.h" 21*f05cddf9SRui Paulo #include "gas_query.h" 22*f05cddf9SRui Paulo #include "interworking.h" 23*f05cddf9SRui Paulo #include "hs20_supplicant.h" 24*f05cddf9SRui Paulo 25*f05cddf9SRui Paulo 26*f05cddf9SRui Paulo void wpas_hs20_add_indication(struct wpabuf *buf) 27*f05cddf9SRui Paulo { 28*f05cddf9SRui Paulo wpabuf_put_u8(buf, WLAN_EID_VENDOR_SPECIFIC); 29*f05cddf9SRui Paulo wpabuf_put_u8(buf, 5); 30*f05cddf9SRui Paulo wpabuf_put_be24(buf, OUI_WFA); 31*f05cddf9SRui Paulo wpabuf_put_u8(buf, HS20_INDICATION_OUI_TYPE); 32*f05cddf9SRui Paulo wpabuf_put_u8(buf, 0x00); /* Hotspot Configuration */ 33*f05cddf9SRui Paulo } 34*f05cddf9SRui Paulo 35*f05cddf9SRui Paulo 36*f05cddf9SRui Paulo struct wpabuf * hs20_build_anqp_req(u32 stypes, const u8 *payload, 37*f05cddf9SRui Paulo size_t payload_len) 38*f05cddf9SRui Paulo { 39*f05cddf9SRui Paulo struct wpabuf *buf; 40*f05cddf9SRui Paulo u8 *len_pos; 41*f05cddf9SRui Paulo 42*f05cddf9SRui Paulo buf = gas_anqp_build_initial_req(0, 100 + payload_len); 43*f05cddf9SRui Paulo if (buf == NULL) 44*f05cddf9SRui Paulo return NULL; 45*f05cddf9SRui Paulo 46*f05cddf9SRui Paulo len_pos = gas_anqp_add_element(buf, ANQP_VENDOR_SPECIFIC); 47*f05cddf9SRui Paulo wpabuf_put_be24(buf, OUI_WFA); 48*f05cddf9SRui Paulo wpabuf_put_u8(buf, HS20_ANQP_OUI_TYPE); 49*f05cddf9SRui Paulo if (stypes == BIT(HS20_STYPE_NAI_HOME_REALM_QUERY)) { 50*f05cddf9SRui Paulo wpabuf_put_u8(buf, HS20_STYPE_NAI_HOME_REALM_QUERY); 51*f05cddf9SRui Paulo wpabuf_put_u8(buf, 0); /* Reserved */ 52*f05cddf9SRui Paulo if (payload) 53*f05cddf9SRui Paulo wpabuf_put_data(buf, payload, payload_len); 54*f05cddf9SRui Paulo } else { 55*f05cddf9SRui Paulo u8 i; 56*f05cddf9SRui Paulo wpabuf_put_u8(buf, HS20_STYPE_QUERY_LIST); 57*f05cddf9SRui Paulo wpabuf_put_u8(buf, 0); /* Reserved */ 58*f05cddf9SRui Paulo for (i = 0; i < 32; i++) { 59*f05cddf9SRui Paulo if (stypes & BIT(i)) 60*f05cddf9SRui Paulo wpabuf_put_u8(buf, i); 61*f05cddf9SRui Paulo } 62*f05cddf9SRui Paulo } 63*f05cddf9SRui Paulo gas_anqp_set_element_len(buf, len_pos); 64*f05cddf9SRui Paulo 65*f05cddf9SRui Paulo gas_anqp_set_len(buf); 66*f05cddf9SRui Paulo 67*f05cddf9SRui Paulo return buf; 68*f05cddf9SRui Paulo } 69*f05cddf9SRui Paulo 70*f05cddf9SRui Paulo 71*f05cddf9SRui Paulo int hs20_anqp_send_req(struct wpa_supplicant *wpa_s, const u8 *dst, u32 stypes, 72*f05cddf9SRui Paulo const u8 *payload, size_t payload_len) 73*f05cddf9SRui Paulo { 74*f05cddf9SRui Paulo struct wpabuf *buf; 75*f05cddf9SRui Paulo int ret = 0; 76*f05cddf9SRui Paulo int freq; 77*f05cddf9SRui Paulo struct wpa_bss *bss; 78*f05cddf9SRui Paulo int res; 79*f05cddf9SRui Paulo 80*f05cddf9SRui Paulo freq = wpa_s->assoc_freq; 81*f05cddf9SRui Paulo bss = wpa_bss_get_bssid(wpa_s, dst); 82*f05cddf9SRui Paulo if (bss) { 83*f05cddf9SRui Paulo wpa_bss_anqp_unshare_alloc(bss); 84*f05cddf9SRui Paulo freq = bss->freq; 85*f05cddf9SRui Paulo } 86*f05cddf9SRui Paulo if (freq <= 0) 87*f05cddf9SRui Paulo return -1; 88*f05cddf9SRui Paulo 89*f05cddf9SRui Paulo wpa_printf(MSG_DEBUG, "HS20: ANQP Query Request to " MACSTR " for " 90*f05cddf9SRui Paulo "subtypes 0x%x", MAC2STR(dst), stypes); 91*f05cddf9SRui Paulo 92*f05cddf9SRui Paulo buf = hs20_build_anqp_req(stypes, payload, payload_len); 93*f05cddf9SRui Paulo if (buf == NULL) 94*f05cddf9SRui Paulo return -1; 95*f05cddf9SRui Paulo 96*f05cddf9SRui Paulo res = gas_query_req(wpa_s->gas, dst, freq, buf, anqp_resp_cb, wpa_s); 97*f05cddf9SRui Paulo if (res < 0) { 98*f05cddf9SRui Paulo wpa_printf(MSG_DEBUG, "ANQP: Failed to send Query Request"); 99*f05cddf9SRui Paulo ret = -1; 100*f05cddf9SRui Paulo } else 101*f05cddf9SRui Paulo wpa_printf(MSG_DEBUG, "ANQP: Query started with dialog token " 102*f05cddf9SRui Paulo "%u", res); 103*f05cddf9SRui Paulo 104*f05cddf9SRui Paulo wpabuf_free(buf); 105*f05cddf9SRui Paulo return ret; 106*f05cddf9SRui Paulo } 107*f05cddf9SRui Paulo 108*f05cddf9SRui Paulo 109*f05cddf9SRui Paulo void hs20_parse_rx_hs20_anqp_resp(struct wpa_supplicant *wpa_s, 110*f05cddf9SRui Paulo const u8 *sa, const u8 *data, size_t slen) 111*f05cddf9SRui Paulo { 112*f05cddf9SRui Paulo const u8 *pos = data; 113*f05cddf9SRui Paulo u8 subtype; 114*f05cddf9SRui Paulo struct wpa_bss *bss = wpa_bss_get_bssid(wpa_s, sa); 115*f05cddf9SRui Paulo struct wpa_bss_anqp *anqp = NULL; 116*f05cddf9SRui Paulo 117*f05cddf9SRui Paulo if (slen < 2) 118*f05cddf9SRui Paulo return; 119*f05cddf9SRui Paulo 120*f05cddf9SRui Paulo if (bss) 121*f05cddf9SRui Paulo anqp = bss->anqp; 122*f05cddf9SRui Paulo 123*f05cddf9SRui Paulo subtype = *pos++; 124*f05cddf9SRui Paulo slen--; 125*f05cddf9SRui Paulo 126*f05cddf9SRui Paulo pos++; /* Reserved */ 127*f05cddf9SRui Paulo slen--; 128*f05cddf9SRui Paulo 129*f05cddf9SRui Paulo switch (subtype) { 130*f05cddf9SRui Paulo case HS20_STYPE_CAPABILITY_LIST: 131*f05cddf9SRui Paulo wpa_msg(wpa_s, MSG_INFO, "RX-HS20-ANQP " MACSTR 132*f05cddf9SRui Paulo " HS Capability List", MAC2STR(sa)); 133*f05cddf9SRui Paulo wpa_hexdump_ascii(MSG_DEBUG, "HS Capability List", pos, slen); 134*f05cddf9SRui Paulo break; 135*f05cddf9SRui Paulo case HS20_STYPE_OPERATOR_FRIENDLY_NAME: 136*f05cddf9SRui Paulo wpa_msg(wpa_s, MSG_INFO, "RX-HS20-ANQP " MACSTR 137*f05cddf9SRui Paulo " Operator Friendly Name", MAC2STR(sa)); 138*f05cddf9SRui Paulo wpa_hexdump_ascii(MSG_DEBUG, "oper friendly name", pos, slen); 139*f05cddf9SRui Paulo if (anqp) { 140*f05cddf9SRui Paulo wpabuf_free(anqp->hs20_operator_friendly_name); 141*f05cddf9SRui Paulo anqp->hs20_operator_friendly_name = 142*f05cddf9SRui Paulo wpabuf_alloc_copy(pos, slen); 143*f05cddf9SRui Paulo } 144*f05cddf9SRui Paulo break; 145*f05cddf9SRui Paulo case HS20_STYPE_WAN_METRICS: 146*f05cddf9SRui Paulo wpa_hexdump(MSG_DEBUG, "WAN Metrics", pos, slen); 147*f05cddf9SRui Paulo if (slen < 13) { 148*f05cddf9SRui Paulo wpa_dbg(wpa_s, MSG_DEBUG, "HS 2.0: Too short WAN " 149*f05cddf9SRui Paulo "Metrics value from " MACSTR, MAC2STR(sa)); 150*f05cddf9SRui Paulo break; 151*f05cddf9SRui Paulo } 152*f05cddf9SRui Paulo wpa_msg(wpa_s, MSG_INFO, "RX-HS20-ANQP " MACSTR 153*f05cddf9SRui Paulo " WAN Metrics %02x:%u:%u:%u:%u:%u", MAC2STR(sa), 154*f05cddf9SRui Paulo pos[0], WPA_GET_LE32(pos + 1), WPA_GET_LE32(pos + 5), 155*f05cddf9SRui Paulo pos[9], pos[10], WPA_GET_LE16(pos + 11)); 156*f05cddf9SRui Paulo if (anqp) { 157*f05cddf9SRui Paulo wpabuf_free(anqp->hs20_wan_metrics); 158*f05cddf9SRui Paulo anqp->hs20_wan_metrics = wpabuf_alloc_copy(pos, slen); 159*f05cddf9SRui Paulo } 160*f05cddf9SRui Paulo break; 161*f05cddf9SRui Paulo case HS20_STYPE_CONNECTION_CAPABILITY: 162*f05cddf9SRui Paulo wpa_msg(wpa_s, MSG_INFO, "RX-HS20-ANQP " MACSTR 163*f05cddf9SRui Paulo " Connection Capability", MAC2STR(sa)); 164*f05cddf9SRui Paulo wpa_hexdump_ascii(MSG_DEBUG, "conn capability", pos, slen); 165*f05cddf9SRui Paulo if (anqp) { 166*f05cddf9SRui Paulo wpabuf_free(anqp->hs20_connection_capability); 167*f05cddf9SRui Paulo anqp->hs20_connection_capability = 168*f05cddf9SRui Paulo wpabuf_alloc_copy(pos, slen); 169*f05cddf9SRui Paulo } 170*f05cddf9SRui Paulo break; 171*f05cddf9SRui Paulo case HS20_STYPE_OPERATING_CLASS: 172*f05cddf9SRui Paulo wpa_msg(wpa_s, MSG_INFO, "RX-HS20-ANQP " MACSTR 173*f05cddf9SRui Paulo " Operating Class", MAC2STR(sa)); 174*f05cddf9SRui Paulo wpa_hexdump_ascii(MSG_DEBUG, "Operating Class", pos, slen); 175*f05cddf9SRui Paulo if (anqp) { 176*f05cddf9SRui Paulo wpabuf_free(anqp->hs20_operating_class); 177*f05cddf9SRui Paulo anqp->hs20_operating_class = 178*f05cddf9SRui Paulo wpabuf_alloc_copy(pos, slen); 179*f05cddf9SRui Paulo } 180*f05cddf9SRui Paulo break; 181*f05cddf9SRui Paulo default: 182*f05cddf9SRui Paulo wpa_printf(MSG_DEBUG, "HS20: Unsupported subtype %u", subtype); 183*f05cddf9SRui Paulo break; 184*f05cddf9SRui Paulo } 185*f05cddf9SRui Paulo } 186