xref: /freebsd/sys/net80211/ieee80211.h (revision 98e0ffaefb0f241cda3a72395d3be04192ae0d47)
1 /*-
2  * Copyright (c) 2001 Atsushi Onoe
3  * Copyright (c) 2002-2009 Sam Leffler, Errno Consulting
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25  *
26  * $FreeBSD$
27  */
28 #ifndef _NET80211_IEEE80211_H_
29 #define _NET80211_IEEE80211_H_
30 
31 /*
32  * 802.11 protocol definitions.
33  */
34 
35 #define	IEEE80211_ADDR_LEN	6		/* size of 802.11 address */
36 /* is 802.11 address multicast/broadcast? */
37 #define	IEEE80211_IS_MULTICAST(_a)	(*(_a) & 0x01)
38 
39 typedef uint16_t ieee80211_seq;
40 
41 /* IEEE 802.11 PLCP header */
42 struct ieee80211_plcp_hdr {
43 	uint16_t	i_sfd;
44 	uint8_t		i_signal;
45 	uint8_t		i_service;
46 	uint16_t	i_length;
47 	uint16_t	i_crc;
48 } __packed;
49 
50 #define IEEE80211_PLCP_SFD      0xF3A0
51 #define IEEE80211_PLCP_SERVICE  0x00
52 #define IEEE80211_PLCP_SERVICE_LOCKED	0x04
53 #define IEEE80211_PLCL_SERVICE_PBCC	0x08
54 #define IEEE80211_PLCP_SERVICE_LENEXT5	0x20
55 #define IEEE80211_PLCP_SERVICE_LENEXT6	0x40
56 #define IEEE80211_PLCP_SERVICE_LENEXT7	0x80
57 
58 /*
59  * generic definitions for IEEE 802.11 frames
60  */
61 struct ieee80211_frame {
62 	uint8_t		i_fc[2];
63 	uint8_t		i_dur[2];
64 	uint8_t		i_addr1[IEEE80211_ADDR_LEN];
65 	uint8_t		i_addr2[IEEE80211_ADDR_LEN];
66 	uint8_t		i_addr3[IEEE80211_ADDR_LEN];
67 	uint8_t		i_seq[2];
68 	/* possibly followed by addr4[IEEE80211_ADDR_LEN]; */
69 	/* see below */
70 } __packed;
71 
72 struct ieee80211_qosframe {
73 	uint8_t		i_fc[2];
74 	uint8_t		i_dur[2];
75 	uint8_t		i_addr1[IEEE80211_ADDR_LEN];
76 	uint8_t		i_addr2[IEEE80211_ADDR_LEN];
77 	uint8_t		i_addr3[IEEE80211_ADDR_LEN];
78 	uint8_t		i_seq[2];
79 	uint8_t		i_qos[2];
80 	/* possibly followed by addr4[IEEE80211_ADDR_LEN]; */
81 	/* see below */
82 } __packed;
83 
84 struct ieee80211_qoscntl {
85 	uint8_t		i_qos[2];
86 };
87 
88 struct ieee80211_frame_addr4 {
89 	uint8_t		i_fc[2];
90 	uint8_t		i_dur[2];
91 	uint8_t		i_addr1[IEEE80211_ADDR_LEN];
92 	uint8_t		i_addr2[IEEE80211_ADDR_LEN];
93 	uint8_t		i_addr3[IEEE80211_ADDR_LEN];
94 	uint8_t		i_seq[2];
95 	uint8_t		i_addr4[IEEE80211_ADDR_LEN];
96 } __packed;
97 
98 
99 struct ieee80211_qosframe_addr4 {
100 	uint8_t		i_fc[2];
101 	uint8_t		i_dur[2];
102 	uint8_t		i_addr1[IEEE80211_ADDR_LEN];
103 	uint8_t		i_addr2[IEEE80211_ADDR_LEN];
104 	uint8_t		i_addr3[IEEE80211_ADDR_LEN];
105 	uint8_t		i_seq[2];
106 	uint8_t		i_addr4[IEEE80211_ADDR_LEN];
107 	uint8_t		i_qos[2];
108 } __packed;
109 
110 #define	IEEE80211_FC0_VERSION_MASK		0x03
111 #define	IEEE80211_FC0_VERSION_SHIFT		0
112 #define	IEEE80211_FC0_VERSION_0			0x00
113 #define	IEEE80211_FC0_TYPE_MASK			0x0c
114 #define	IEEE80211_FC0_TYPE_SHIFT		2
115 #define	IEEE80211_FC0_TYPE_MGT			0x00
116 #define	IEEE80211_FC0_TYPE_CTL			0x04
117 #define	IEEE80211_FC0_TYPE_DATA			0x08
118 
119 #define	IEEE80211_FC0_SUBTYPE_MASK		0xf0
120 #define	IEEE80211_FC0_SUBTYPE_SHIFT		4
121 /* for TYPE_MGT */
122 #define	IEEE80211_FC0_SUBTYPE_ASSOC_REQ		0x00
123 #define	IEEE80211_FC0_SUBTYPE_ASSOC_RESP	0x10
124 #define	IEEE80211_FC0_SUBTYPE_REASSOC_REQ	0x20
125 #define	IEEE80211_FC0_SUBTYPE_REASSOC_RESP	0x30
126 #define	IEEE80211_FC0_SUBTYPE_PROBE_REQ		0x40
127 #define	IEEE80211_FC0_SUBTYPE_PROBE_RESP	0x50
128 #define	IEEE80211_FC0_SUBTYPE_BEACON		0x80
129 #define	IEEE80211_FC0_SUBTYPE_ATIM		0x90
130 #define	IEEE80211_FC0_SUBTYPE_DISASSOC		0xa0
131 #define	IEEE80211_FC0_SUBTYPE_AUTH		0xb0
132 #define	IEEE80211_FC0_SUBTYPE_DEAUTH		0xc0
133 #define	IEEE80211_FC0_SUBTYPE_ACTION		0xd0
134 #define	IEEE80211_FC0_SUBTYPE_ACTION_NOACK	0xe0
135 /* for TYPE_CTL */
136 #define	IEEE80211_FC0_SUBTYPE_BAR		0x80
137 #define	IEEE80211_FC0_SUBTYPE_BA		0x90
138 #define	IEEE80211_FC0_SUBTYPE_PS_POLL		0xa0
139 #define	IEEE80211_FC0_SUBTYPE_RTS		0xb0
140 #define	IEEE80211_FC0_SUBTYPE_CTS		0xc0
141 #define	IEEE80211_FC0_SUBTYPE_ACK		0xd0
142 #define	IEEE80211_FC0_SUBTYPE_CF_END		0xe0
143 #define	IEEE80211_FC0_SUBTYPE_CF_END_ACK	0xf0
144 /* for TYPE_DATA (bit combination) */
145 #define	IEEE80211_FC0_SUBTYPE_DATA		0x00
146 #define	IEEE80211_FC0_SUBTYPE_CF_ACK		0x10
147 #define	IEEE80211_FC0_SUBTYPE_CF_POLL		0x20
148 #define	IEEE80211_FC0_SUBTYPE_CF_ACPL		0x30
149 #define	IEEE80211_FC0_SUBTYPE_NODATA		0x40
150 #define	IEEE80211_FC0_SUBTYPE_CFACK		0x50
151 #define	IEEE80211_FC0_SUBTYPE_CFPOLL		0x60
152 #define	IEEE80211_FC0_SUBTYPE_CF_ACK_CF_ACK	0x70
153 #define	IEEE80211_FC0_SUBTYPE_QOS		0x80
154 #define	IEEE80211_FC0_SUBTYPE_QOS_NULL		0xc0
155 
156 #define	IEEE80211_FC1_DIR_MASK			0x03
157 #define	IEEE80211_FC1_DIR_NODS			0x00	/* STA->STA */
158 #define	IEEE80211_FC1_DIR_TODS			0x01	/* STA->AP  */
159 #define	IEEE80211_FC1_DIR_FROMDS		0x02	/* AP ->STA */
160 #define	IEEE80211_FC1_DIR_DSTODS		0x03	/* AP ->AP  */
161 
162 #define	IEEE80211_IS_DSTODS(wh) \
163 	(((wh)->i_fc[1] & IEEE80211_FC1_DIR_MASK) == IEEE80211_FC1_DIR_DSTODS)
164 
165 #define	IEEE80211_FC1_MORE_FRAG			0x04
166 #define	IEEE80211_FC1_RETRY			0x08
167 #define	IEEE80211_FC1_PWR_MGT			0x10
168 #define	IEEE80211_FC1_MORE_DATA			0x20
169 #define	IEEE80211_FC1_PROTECTED			0x40
170 #define	IEEE80211_FC1_ORDER			0x80
171 
172 #define IEEE80211_HAS_SEQ(type, subtype) \
173 	((type) != IEEE80211_FC0_TYPE_CTL && \
174 	!((type) == IEEE80211_FC0_TYPE_DATA && \
175 	 ((subtype) & IEEE80211_FC0_SUBTYPE_QOS_NULL) == \
176 		      IEEE80211_FC0_SUBTYPE_QOS_NULL))
177 #define	IEEE80211_SEQ_FRAG_MASK			0x000f
178 #define	IEEE80211_SEQ_FRAG_SHIFT		0
179 #define	IEEE80211_SEQ_SEQ_MASK			0xfff0
180 #define	IEEE80211_SEQ_SEQ_SHIFT			4
181 #define	IEEE80211_SEQ_RANGE			4096
182 
183 #define	IEEE80211_SEQ_ADD(seq, incr) \
184 	(((seq) + (incr)) & (IEEE80211_SEQ_RANGE-1))
185 #define	IEEE80211_SEQ_INC(seq)	IEEE80211_SEQ_ADD(seq,1)
186 #define	IEEE80211_SEQ_SUB(a, b) \
187 	(((a) + IEEE80211_SEQ_RANGE - (b)) & (IEEE80211_SEQ_RANGE-1))
188 
189 #define	IEEE80211_SEQ_BA_RANGE			2048	/* 2^11 */
190 #define	IEEE80211_SEQ_BA_BEFORE(a, b) \
191 	(IEEE80211_SEQ_SUB(b, a+1) < IEEE80211_SEQ_BA_RANGE-1)
192 
193 #define	IEEE80211_NWID_LEN			32
194 #define	IEEE80211_MESHID_LEN			32
195 
196 #define	IEEE80211_QOS_TXOP			0x00ff
197 /* bit 8 is reserved */
198 #define	IEEE80211_QOS_AMSDU			0x80
199 #define	IEEE80211_QOS_AMSDU_S			7
200 #define	IEEE80211_QOS_ACKPOLICY			0x60
201 #define	IEEE80211_QOS_ACKPOLICY_S		5
202 #define	IEEE80211_QOS_ACKPOLICY_NOACK		0x20	/* No ACK required */
203 #define	IEEE80211_QOS_ACKPOLICY_BA		0x60	/* Block ACK */
204 #define	IEEE80211_QOS_EOSP			0x10	/* EndOfService Period*/
205 #define	IEEE80211_QOS_EOSP_S			4
206 #define	IEEE80211_QOS_TID			0x0f
207 /* qos[1] byte used for all frames sent by mesh STAs in a mesh BSS */
208 #define IEEE80211_QOS_MC			0x01	/* Mesh control */
209 /* Mesh power save level*/
210 #define IEEE80211_QOS_MESH_PSL			0x02
211 /* Mesh Receiver Service Period Initiated */
212 #define IEEE80211_QOS_RSPI			0x04
213 /* bits 11 to 15 reserved */
214 
215 /* does frame have QoS sequence control data */
216 #define	IEEE80211_QOS_HAS_SEQ(wh) \
217 	(((wh)->i_fc[0] & \
218 	  (IEEE80211_FC0_TYPE_MASK | IEEE80211_FC0_SUBTYPE_QOS)) == \
219 	  (IEEE80211_FC0_TYPE_DATA | IEEE80211_FC0_SUBTYPE_QOS))
220 
221 /*
222  * WME/802.11e information element.
223  */
224 struct ieee80211_wme_info {
225 	uint8_t		wme_id;		/* IEEE80211_ELEMID_VENDOR */
226 	uint8_t		wme_len;	/* length in bytes */
227 	uint8_t		wme_oui[3];	/* 0x00, 0x50, 0xf2 */
228 	uint8_t		wme_type;	/* OUI type */
229 	uint8_t		wme_subtype;	/* OUI subtype */
230 	uint8_t		wme_version;	/* spec revision */
231 	uint8_t		wme_info;	/* QoS info */
232 } __packed;
233 
234 /*
235  * WME/802.11e Tspec Element
236  */
237 struct ieee80211_wme_tspec {
238 	uint8_t		ts_id;
239 	uint8_t		ts_len;
240 	uint8_t		ts_oui[3];
241 	uint8_t		ts_oui_type;
242 	uint8_t		ts_oui_subtype;
243 	uint8_t		ts_version;
244 	uint8_t		ts_tsinfo[3];
245 	uint8_t		ts_nom_msdu[2];
246 	uint8_t		ts_max_msdu[2];
247 	uint8_t		ts_min_svc[4];
248 	uint8_t		ts_max_svc[4];
249 	uint8_t		ts_inactv_intv[4];
250 	uint8_t		ts_susp_intv[4];
251 	uint8_t		ts_start_svc[4];
252 	uint8_t		ts_min_rate[4];
253 	uint8_t		ts_mean_rate[4];
254 	uint8_t		ts_max_burst[4];
255 	uint8_t		ts_min_phy[4];
256 	uint8_t		ts_peak_rate[4];
257 	uint8_t		ts_delay[4];
258 	uint8_t		ts_surplus[2];
259 	uint8_t		ts_medium_time[2];
260 } __packed;
261 
262 /*
263  * WME AC parameter field
264  */
265 struct ieee80211_wme_acparams {
266 	uint8_t		acp_aci_aifsn;
267 	uint8_t		acp_logcwminmax;
268 	uint16_t	acp_txop;
269 } __packed;
270 
271 #define WME_NUM_AC		4	/* 4 AC categories */
272 #define	WME_NUM_TID		16	/* 16 tids */
273 
274 #define WME_PARAM_ACI		0x60	/* Mask for ACI field */
275 #define WME_PARAM_ACI_S		5	/* Shift for ACI field */
276 #define WME_PARAM_ACM		0x10	/* Mask for ACM bit */
277 #define WME_PARAM_ACM_S		4	/* Shift for ACM bit */
278 #define WME_PARAM_AIFSN		0x0f	/* Mask for aifsn field */
279 #define WME_PARAM_AIFSN_S	0	/* Shift for aifsn field */
280 #define WME_PARAM_LOGCWMIN	0x0f	/* Mask for CwMin field (in log) */
281 #define WME_PARAM_LOGCWMIN_S	0	/* Shift for CwMin field */
282 #define WME_PARAM_LOGCWMAX	0xf0	/* Mask for CwMax field (in log) */
283 #define WME_PARAM_LOGCWMAX_S	4	/* Shift for CwMax field */
284 
285 #define WME_AC_TO_TID(_ac) (       \
286 	((_ac) == WME_AC_VO) ? 6 : \
287 	((_ac) == WME_AC_VI) ? 5 : \
288 	((_ac) == WME_AC_BK) ? 1 : \
289 	0)
290 
291 #define TID_TO_WME_AC(_tid) (      \
292 	((_tid) == 0 || (_tid) == 3) ? WME_AC_BE : \
293 	((_tid) < 3) ? WME_AC_BK : \
294 	((_tid) < 6) ? WME_AC_VI : \
295 	WME_AC_VO)
296 
297 /*
298  * WME Parameter Element
299  */
300 struct ieee80211_wme_param {
301 	uint8_t		param_id;
302 	uint8_t		param_len;
303 	uint8_t		param_oui[3];
304 	uint8_t		param_oui_type;
305 	uint8_t		param_oui_subtype;
306 	uint8_t		param_version;
307 	uint8_t		param_qosInfo;
308 #define	WME_QOSINFO_COUNT	0x0f	/* Mask for param count field */
309 	uint8_t		param_reserved;
310 	struct ieee80211_wme_acparams	params_acParams[WME_NUM_AC];
311 } __packed;
312 
313 /*
314  * Management Notification Frame
315  */
316 struct ieee80211_mnf {
317 	uint8_t		mnf_category;
318 	uint8_t		mnf_action;
319 	uint8_t		mnf_dialog;
320 	uint8_t		mnf_status;
321 } __packed;
322 #define	MNF_SETUP_REQ	0
323 #define	MNF_SETUP_RESP	1
324 #define	MNF_TEARDOWN	2
325 
326 /*
327  * 802.11n Management Action Frames
328  */
329 /* generic frame format */
330 struct ieee80211_action {
331 	uint8_t		ia_category;
332 	uint8_t		ia_action;
333 } __packed;
334 
335 #define	IEEE80211_ACTION_CAT_SM		0	/* Spectrum Management */
336 #define	IEEE80211_ACTION_CAT_QOS	1	/* QoS */
337 #define	IEEE80211_ACTION_CAT_DLS	2	/* DLS */
338 #define	IEEE80211_ACTION_CAT_BA		3	/* BA */
339 #define	IEEE80211_ACTION_CAT_HT		7	/* HT */
340 #define	IEEE80211_ACTION_CAT_MESH	13	/* Mesh */
341 #define	IEEE80211_ACTION_CAT_SELF_PROT	15	/* Self-protected */
342 /* 16 - 125 reserved */
343 #define	IEEE80211_ACTION_CAT_VENDOR	127	/* Vendor Specific */
344 
345 #define	IEEE80211_ACTION_HT_TXCHWIDTH	0	/* recommended xmit chan width*/
346 #define	IEEE80211_ACTION_HT_MIMOPWRSAVE	1	/* MIMO power save */
347 
348 /* HT - recommended transmission channel width */
349 struct ieee80211_action_ht_txchwidth {
350 	struct ieee80211_action	at_header;
351 	uint8_t		at_chwidth;
352 } __packed;
353 
354 #define	IEEE80211_A_HT_TXCHWIDTH_20	0
355 #define	IEEE80211_A_HT_TXCHWIDTH_2040	1
356 
357 /* HT - MIMO Power Save (NB: D2.04) */
358 struct ieee80211_action_ht_mimopowersave {
359 	struct ieee80211_action am_header;
360 	uint8_t		am_control;
361 } __packed;
362 
363 #define	IEEE80211_A_HT_MIMOPWRSAVE_ENA		0x01	/* PS enabled */
364 #define	IEEE80211_A_HT_MIMOPWRSAVE_MODE		0x02
365 #define	IEEE80211_A_HT_MIMOPWRSAVE_MODE_S	1
366 #define	IEEE80211_A_HT_MIMOPWRSAVE_DYNAMIC	0x02	/* Dynamic Mode */
367 #define	IEEE80211_A_HT_MIMOPWRSAVE_STATIC	0x00	/* no SM packets */
368 /* bits 2-7 reserved */
369 
370 /* Block Ack actions */
371 #define IEEE80211_ACTION_BA_ADDBA_REQUEST       0   /* ADDBA request */
372 #define IEEE80211_ACTION_BA_ADDBA_RESPONSE      1   /* ADDBA response */
373 #define IEEE80211_ACTION_BA_DELBA	        2   /* DELBA */
374 
375 /* Block Ack Parameter Set */
376 #define	IEEE80211_BAPS_BUFSIZ	0xffc0		/* buffer size */
377 #define	IEEE80211_BAPS_BUFSIZ_S	6
378 #define	IEEE80211_BAPS_TID	0x003c		/* TID */
379 #define	IEEE80211_BAPS_TID_S	2
380 #define	IEEE80211_BAPS_POLICY	0x0002		/* block ack policy */
381 #define	IEEE80211_BAPS_POLICY_S	1
382 
383 #define	IEEE80211_BAPS_POLICY_DELAYED	(0<<IEEE80211_BAPS_POLICY_S)
384 #define	IEEE80211_BAPS_POLICY_IMMEDIATE	(1<<IEEE80211_BAPS_POLICY_S)
385 
386 /* Block Ack Sequence Control */
387 #define	IEEE80211_BASEQ_START	0xfff0		/* starting seqnum */
388 #define	IEEE80211_BASEQ_START_S	4
389 #define	IEEE80211_BASEQ_FRAG	0x000f		/* fragment number */
390 #define	IEEE80211_BASEQ_FRAG_S	0
391 
392 /* Delayed Block Ack Parameter Set */
393 #define	IEEE80211_DELBAPS_TID	0xf000		/* TID */
394 #define	IEEE80211_DELBAPS_TID_S	12
395 #define	IEEE80211_DELBAPS_INIT	0x0800		/* initiator */
396 #define	IEEE80211_DELBAPS_INIT_S 11
397 
398 /* BA - ADDBA request */
399 struct ieee80211_action_ba_addbarequest {
400 	struct ieee80211_action rq_header;
401 	uint8_t		rq_dialogtoken;
402 	uint16_t	rq_baparamset;
403 	uint16_t	rq_batimeout;		/* in TUs */
404 	uint16_t	rq_baseqctl;
405 } __packed;
406 
407 /* BA - ADDBA response */
408 struct ieee80211_action_ba_addbaresponse {
409 	struct ieee80211_action rs_header;
410 	uint8_t		rs_dialogtoken;
411 	uint16_t	rs_statuscode;
412 	uint16_t	rs_baparamset;
413 	uint16_t	rs_batimeout;		/* in TUs */
414 } __packed;
415 
416 /* BA - DELBA */
417 struct ieee80211_action_ba_delba {
418 	struct ieee80211_action dl_header;
419 	uint16_t	dl_baparamset;
420 	uint16_t	dl_reasoncode;
421 } __packed;
422 
423 /* BAR Control */
424 #define	IEEE80211_BAR_TID	0xf000		/* TID */
425 #define	IEEE80211_BAR_TID_S	12
426 #define	IEEE80211_BAR_COMP	0x0004		/* Compressed Bitmap */
427 #define	IEEE80211_BAR_MTID	0x0002		/* Multi-TID */
428 #define	IEEE80211_BAR_NOACK	0x0001		/* No-Ack policy */
429 
430 /* BAR Starting Sequence Control */
431 #define	IEEE80211_BAR_SEQ_START	0xfff0		/* starting seqnum */
432 #define	IEEE80211_BAR_SEQ_START_S	4
433 
434 struct ieee80211_ba_request {
435 	uint16_t	rq_barctl;
436 	uint16_t	rq_barseqctl;
437 } __packed;
438 
439 /*
440  * Control frames.
441  */
442 struct ieee80211_frame_min {
443 	uint8_t		i_fc[2];
444 	uint8_t		i_dur[2];
445 	uint8_t		i_addr1[IEEE80211_ADDR_LEN];
446 	uint8_t		i_addr2[IEEE80211_ADDR_LEN];
447 	/* FCS */
448 } __packed;
449 
450 struct ieee80211_frame_rts {
451 	uint8_t		i_fc[2];
452 	uint8_t		i_dur[2];
453 	uint8_t		i_ra[IEEE80211_ADDR_LEN];
454 	uint8_t		i_ta[IEEE80211_ADDR_LEN];
455 	/* FCS */
456 } __packed;
457 
458 struct ieee80211_frame_cts {
459 	uint8_t		i_fc[2];
460 	uint8_t		i_dur[2];
461 	uint8_t		i_ra[IEEE80211_ADDR_LEN];
462 	/* FCS */
463 } __packed;
464 
465 struct ieee80211_frame_ack {
466 	uint8_t		i_fc[2];
467 	uint8_t		i_dur[2];
468 	uint8_t		i_ra[IEEE80211_ADDR_LEN];
469 	/* FCS */
470 } __packed;
471 
472 struct ieee80211_frame_pspoll {
473 	uint8_t		i_fc[2];
474 	uint8_t		i_aid[2];
475 	uint8_t		i_bssid[IEEE80211_ADDR_LEN];
476 	uint8_t		i_ta[IEEE80211_ADDR_LEN];
477 	/* FCS */
478 } __packed;
479 
480 struct ieee80211_frame_cfend {		/* NB: also CF-End+CF-Ack */
481 	uint8_t		i_fc[2];
482 	uint8_t		i_dur[2];	/* should be zero */
483 	uint8_t		i_ra[IEEE80211_ADDR_LEN];
484 	uint8_t		i_bssid[IEEE80211_ADDR_LEN];
485 	/* FCS */
486 } __packed;
487 
488 struct ieee80211_frame_bar {
489 	uint8_t		i_fc[2];
490 	uint8_t		i_dur[2];
491 	uint8_t		i_ra[IEEE80211_ADDR_LEN];
492 	uint8_t		i_ta[IEEE80211_ADDR_LEN];
493 	uint16_t	i_ctl;
494 	uint16_t	i_seq;
495 	/* FCS */
496 } __packed;
497 
498 /*
499  * BEACON management packets
500  *
501  *	octet timestamp[8]
502  *	octet beacon interval[2]
503  *	octet capability information[2]
504  *	information element
505  *		octet elemid
506  *		octet length
507  *		octet information[length]
508  */
509 
510 #define	IEEE80211_BEACON_INTERVAL(beacon) \
511 	((beacon)[8] | ((beacon)[9] << 8))
512 #define	IEEE80211_BEACON_CAPABILITY(beacon) \
513 	((beacon)[10] | ((beacon)[11] << 8))
514 
515 #define	IEEE80211_CAPINFO_ESS			0x0001
516 #define	IEEE80211_CAPINFO_IBSS			0x0002
517 #define	IEEE80211_CAPINFO_CF_POLLABLE		0x0004
518 #define	IEEE80211_CAPINFO_CF_POLLREQ		0x0008
519 #define	IEEE80211_CAPINFO_PRIVACY		0x0010
520 #define	IEEE80211_CAPINFO_SHORT_PREAMBLE	0x0020
521 #define	IEEE80211_CAPINFO_PBCC			0x0040
522 #define	IEEE80211_CAPINFO_CHNL_AGILITY		0x0080
523 #define	IEEE80211_CAPINFO_SPECTRUM_MGMT		0x0100
524 /* bit 9 is reserved */
525 #define	IEEE80211_CAPINFO_SHORT_SLOTTIME	0x0400
526 #define	IEEE80211_CAPINFO_RSN			0x0800
527 /* bit 12 is reserved */
528 #define	IEEE80211_CAPINFO_DSSSOFDM		0x2000
529 /* bits 14-15 are reserved */
530 
531 #define	IEEE80211_CAPINFO_BITS \
532 	"\20\1ESS\2IBSS\3CF_POLLABLE\4CF_POLLREQ\5PRIVACY\6SHORT_PREAMBLE" \
533 	"\7PBCC\10CHNL_AGILITY\11SPECTRUM_MGMT\13SHORT_SLOTTIME\14RSN" \
534 	"\16DSSOFDM"
535 
536 /*
537  * 802.11i/WPA information element (maximally sized).
538  */
539 struct ieee80211_ie_wpa {
540 	uint8_t		wpa_id;		/* IEEE80211_ELEMID_VENDOR */
541 	uint8_t		wpa_len;	/* length in bytes */
542 	uint8_t		wpa_oui[3];	/* 0x00, 0x50, 0xf2 */
543 	uint8_t		wpa_type;	/* OUI type */
544 	uint16_t	wpa_version;	/* spec revision */
545 	uint32_t	wpa_mcipher[1];	/* multicast/group key cipher */
546 	uint16_t	wpa_uciphercnt;	/* # pairwise key ciphers */
547 	uint32_t	wpa_uciphers[8];/* ciphers */
548 	uint16_t	wpa_authselcnt;	/* authentication selector cnt*/
549 	uint32_t	wpa_authsels[8];/* selectors */
550 	uint16_t	wpa_caps;	/* 802.11i capabilities */
551 	uint16_t	wpa_pmkidcnt;	/* 802.11i pmkid count */
552 	uint16_t	wpa_pmkids[8];	/* 802.11i pmkids */
553 } __packed;
554 
555 /*
556  * 802.11n HT Capability IE
557  * NB: these reflect D1.10
558  */
559 struct ieee80211_ie_htcap {
560 	uint8_t		hc_id;			/* element ID */
561 	uint8_t		hc_len;			/* length in bytes */
562 	uint16_t	hc_cap;			/* HT caps (see below) */
563 	uint8_t		hc_param;		/* HT params (see below) */
564 	uint8_t 	hc_mcsset[16]; 		/* supported MCS set */
565 	uint16_t	hc_extcap;		/* extended HT capabilities */
566 	uint32_t	hc_txbf;		/* txbf capabilities */
567 	uint8_t		hc_antenna;		/* antenna capabilities */
568 } __packed;
569 
570 /* HT capability flags (ht_cap) */
571 #define	IEEE80211_HTCAP_LDPC		0x0001	/* LDPC supported */
572 #define	IEEE80211_HTCAP_CHWIDTH40	0x0002	/* 20/40 supported */
573 #define	IEEE80211_HTCAP_SMPS		0x000c	/* SM Power Save mode */
574 #define	IEEE80211_HTCAP_SMPS_OFF	0x000c	/* disabled */
575 #define	IEEE80211_HTCAP_SMPS_DYNAMIC	0x0004	/* send RTS first */
576 /* NB: SMPS value 2 is reserved */
577 #define	IEEE80211_HTCAP_SMPS_ENA	0x0000	/* enabled (static mode) */
578 #define	IEEE80211_HTCAP_GREENFIELD	0x0010	/* Greenfield supported */
579 #define	IEEE80211_HTCAP_SHORTGI20	0x0020	/* Short GI in 20MHz */
580 #define	IEEE80211_HTCAP_SHORTGI40	0x0040	/* Short GI in 40MHz */
581 #define	IEEE80211_HTCAP_TXSTBC		0x0080	/* STBC tx ok */
582 #define	IEEE80211_HTCAP_RXSTBC		0x0300  /* STBC rx support */
583 #define	IEEE80211_HTCAP_RXSTBC_S	8
584 #define	IEEE80211_HTCAP_RXSTBC_1STREAM	0x0100  /* 1 spatial stream */
585 #define	IEEE80211_HTCAP_RXSTBC_2STREAM	0x0200  /* 1-2 spatial streams*/
586 #define	IEEE80211_HTCAP_RXSTBC_3STREAM	0x0300  /* 1-3 spatial streams*/
587 #define	IEEE80211_HTCAP_DELBA		0x0400	/* HT DELBA supported */
588 #define	IEEE80211_HTCAP_MAXAMSDU	0x0800	/* max A-MSDU length */
589 #define	IEEE80211_HTCAP_MAXAMSDU_7935	0x0800	/* 7935 octets */
590 #define	IEEE80211_HTCAP_MAXAMSDU_3839	0x0000	/* 3839 octets */
591 #define	IEEE80211_HTCAP_DSSSCCK40	0x1000  /* DSSS/CCK in 40MHz */
592 #define	IEEE80211_HTCAP_PSMP		0x2000  /* PSMP supported */
593 #define	IEEE80211_HTCAP_40INTOLERANT	0x4000  /* 40MHz intolerant */
594 #define	IEEE80211_HTCAP_LSIGTXOPPROT	0x8000  /* L-SIG TXOP prot */
595 
596 #define	IEEE80211_HTCAP_BITS \
597 	"\20\1LDPC\2CHWIDTH40\5GREENFIELD\6SHORTGI20\7SHORTGI40\10TXSTBC" \
598 	"\13DELBA\14AMSDU(7935)\15DSSSCCK40\16PSMP\1740INTOLERANT" \
599 	"\20LSIGTXOPPROT"
600 
601 /* HT parameters (hc_param) */
602 #define	IEEE80211_HTCAP_MAXRXAMPDU	0x03	/* max rx A-MPDU factor */
603 #define	IEEE80211_HTCAP_MAXRXAMPDU_S	0
604 #define	IEEE80211_HTCAP_MAXRXAMPDU_8K	0
605 #define	IEEE80211_HTCAP_MAXRXAMPDU_16K	1
606 #define	IEEE80211_HTCAP_MAXRXAMPDU_32K	2
607 #define	IEEE80211_HTCAP_MAXRXAMPDU_64K	3
608 #define	IEEE80211_HTCAP_MPDUDENSITY	0x1c	/* min MPDU start spacing */
609 #define	IEEE80211_HTCAP_MPDUDENSITY_S	2
610 #define	IEEE80211_HTCAP_MPDUDENSITY_NA	0	/* no time restriction */
611 #define	IEEE80211_HTCAP_MPDUDENSITY_025	1	/* 1/4 us */
612 #define	IEEE80211_HTCAP_MPDUDENSITY_05	2	/* 1/2 us */
613 #define	IEEE80211_HTCAP_MPDUDENSITY_1	3	/* 1 us */
614 #define	IEEE80211_HTCAP_MPDUDENSITY_2	4	/* 2 us */
615 #define	IEEE80211_HTCAP_MPDUDENSITY_4	5	/* 4 us */
616 #define	IEEE80211_HTCAP_MPDUDENSITY_8	6	/* 8 us */
617 #define	IEEE80211_HTCAP_MPDUDENSITY_16	7	/* 16 us */
618 
619 /* HT extended capabilities (hc_extcap) */
620 #define	IEEE80211_HTCAP_PCO		0x0001	/* PCO capable */
621 #define	IEEE80211_HTCAP_PCOTRANS	0x0006	/* PCO transition time */
622 #define	IEEE80211_HTCAP_PCOTRANS_S	1
623 #define	IEEE80211_HTCAP_PCOTRANS_04	0x0002	/* 400 us */
624 #define	IEEE80211_HTCAP_PCOTRANS_15	0x0004	/* 1.5 ms */
625 #define	IEEE80211_HTCAP_PCOTRANS_5	0x0006	/* 5 ms */
626 /* bits 3-7 reserved */
627 #define	IEEE80211_HTCAP_MCSFBACK	0x0300	/* MCS feedback */
628 #define	IEEE80211_HTCAP_MCSFBACK_S	8
629 #define	IEEE80211_HTCAP_MCSFBACK_NONE	0x0000	/* nothing provided */
630 #define	IEEE80211_HTCAP_MCSFBACK_UNSOL	0x0200	/* unsolicited feedback */
631 #define	IEEE80211_HTCAP_MCSFBACK_MRQ	0x0300	/* " "+respond to MRQ */
632 #define	IEEE80211_HTCAP_HTC		0x0400	/* +HTC support */
633 #define	IEEE80211_HTCAP_RDR		0x0800	/* reverse direction responder*/
634 /* bits 12-15 reserved */
635 
636 /*
637  * 802.11n HT Information IE
638  */
639 struct ieee80211_ie_htinfo {
640 	uint8_t		hi_id;			/* element ID */
641 	uint8_t		hi_len;			/* length in bytes */
642 	uint8_t		hi_ctrlchannel;		/* primary channel */
643 	uint8_t		hi_byte1;		/* ht ie byte 1 */
644 	uint8_t		hi_byte2;		/* ht ie byte 2 */
645 	uint8_t		hi_byte3;		/* ht ie byte 3 */
646 	uint16_t	hi_byte45;		/* ht ie bytes 4+5 */
647 	uint8_t 	hi_basicmcsset[16]; 	/* basic MCS set */
648 } __packed;
649 
650 /* byte1 */
651 #define	IEEE80211_HTINFO_2NDCHAN	0x03	/* secondary/ext chan offset */
652 #define	IEEE80211_HTINFO_2NDCHAN_S	0
653 #define	IEEE80211_HTINFO_2NDCHAN_NONE	0x00	/* no secondary/ext channel */
654 #define	IEEE80211_HTINFO_2NDCHAN_ABOVE	0x01	/* above private channel */
655 /* NB: 2 is reserved */
656 #define	IEEE80211_HTINFO_2NDCHAN_BELOW	0x03	/* below primary channel */
657 #define	IEEE80211_HTINFO_TXWIDTH	0x04	/* tx channel width */
658 #define	IEEE80211_HTINFO_TXWIDTH_20	0x00	/* 20MHz width */
659 #define	IEEE80211_HTINFO_TXWIDTH_2040	0x04	/* any supported width */
660 #define	IEEE80211_HTINFO_RIFSMODE	0x08	/* Reduced IFS (RIFS) use */
661 #define	IEEE80211_HTINFO_RIFSMODE_PROH	0x00	/* RIFS use prohibited */
662 #define	IEEE80211_HTINFO_RIFSMODE_PERM	0x08	/* RIFS use permitted */
663 #define	IEEE80211_HTINFO_PMSPONLY	0x10	/* PSMP required to associate */
664 #define	IEEE80211_HTINFO_SIGRAN		0xe0	/* shortest Service Interval */
665 #define	IEEE80211_HTINFO_SIGRAN_S	5
666 #define	IEEE80211_HTINFO_SIGRAN_5	0x00	/* 5 ms */
667 /* XXX add rest */
668 
669 /* bytes 2+3 */
670 #define	IEEE80211_HTINFO_OPMODE		0x03	/* operating mode */
671 #define	IEEE80211_HTINFO_OPMODE_S	0
672 #define	IEEE80211_HTINFO_OPMODE_PURE	0x00	/* no protection */
673 #define	IEEE80211_HTINFO_OPMODE_PROTOPT	0x01	/* protection optional */
674 #define	IEEE80211_HTINFO_OPMODE_HT20PR	0x02	/* protection for HT20 sta's */
675 #define	IEEE80211_HTINFO_OPMODE_MIXED	0x03	/* protection for legacy sta's*/
676 #define	IEEE80211_HTINFO_NONGF_PRESENT	0x04	/* non-GF sta's present */
677 #define	IEEE80211_HTINFO_TXBL		0x08	/* transmit burst limit */
678 #define	IEEE80211_HTINFO_NONHT_PRESENT	0x10	/* non-HT sta's present */
679 /* bits 5-15 reserved */
680 
681 /* bytes 4+5 */
682 #define	IEEE80211_HTINFO_2NDARYBEACON	0x01
683 #define	IEEE80211_HTINFO_LSIGTXOPPROT	0x02
684 #define	IEEE80211_HTINFO_PCO_ACTIVE	0x04
685 #define	IEEE80211_HTINFO_40MHZPHASE	0x08
686 
687 /* byte5 */
688 #define	IEEE80211_HTINFO_BASIC_STBCMCS	0x7f
689 #define	IEEE80211_HTINFO_BASIC_STBCMCS_S 0
690 #define	IEEE80211_HTINFO_DUALPROTECTED	0x80
691 
692 /*
693  * Management information element payloads.
694  */
695 
696 enum {
697 	IEEE80211_ELEMID_SSID		= 0,
698 	IEEE80211_ELEMID_RATES		= 1,
699 	IEEE80211_ELEMID_FHPARMS	= 2,
700 	IEEE80211_ELEMID_DSPARMS	= 3,
701 	IEEE80211_ELEMID_CFPARMS	= 4,
702 	IEEE80211_ELEMID_TIM		= 5,
703 	IEEE80211_ELEMID_IBSSPARMS	= 6,
704 	IEEE80211_ELEMID_COUNTRY	= 7,
705 	IEEE80211_ELEMID_CHALLENGE	= 16,
706 	/* 17-31 reserved for challenge text extension */
707 	IEEE80211_ELEMID_PWRCNSTR	= 32,
708 	IEEE80211_ELEMID_PWRCAP		= 33,
709 	IEEE80211_ELEMID_TPCREQ		= 34,
710 	IEEE80211_ELEMID_TPCREP		= 35,
711 	IEEE80211_ELEMID_SUPPCHAN	= 36,
712 	IEEE80211_ELEMID_CSA		= 37,
713 	IEEE80211_ELEMID_MEASREQ	= 38,
714 	IEEE80211_ELEMID_MEASREP	= 39,
715 	IEEE80211_ELEMID_QUIET		= 40,
716 	IEEE80211_ELEMID_IBSSDFS	= 41,
717 	IEEE80211_ELEMID_ERP		= 42,
718 	IEEE80211_ELEMID_HTCAP		= 45,
719 	IEEE80211_ELEMID_QOS		= 46,
720 	IEEE80211_ELEMID_RSN		= 48,
721 	IEEE80211_ELEMID_XRATES		= 50,
722 	IEEE80211_ELEMID_HTINFO		= 61,
723 	IEEE80211_ELEMID_TPC		= 150,
724 	IEEE80211_ELEMID_CCKM		= 156,
725 	IEEE80211_ELEMID_VENDOR		= 221,	/* vendor private */
726 
727 	/*
728 	 * 802.11s IEs
729 	 * NB: On vanilla Linux still IEEE80211_ELEMID_MESHPEER = 55,
730 	 * but they defined a new with id 117 called PEER_MGMT.
731 	 * NB: complies with open80211
732 	 */
733 	IEEE80211_ELEMID_MESHCONF	= 113,
734 	IEEE80211_ELEMID_MESHID		= 114,
735 	IEEE80211_ELEMID_MESHLINK	= 115,
736 	IEEE80211_ELEMID_MESHCNGST	= 116,
737 	IEEE80211_ELEMID_MESHPEER	= 117,
738 	IEEE80211_ELEMID_MESHCSA	= 118,
739 	IEEE80211_ELEMID_MESHTIM	= 39, /* XXX: remove */
740 	IEEE80211_ELEMID_MESHAWAKEW	= 119,
741 	IEEE80211_ELEMID_MESHBEACONT	= 120,
742 	/* 121-124 MMCAOP not implemented yet */
743 	IEEE80211_ELEMID_MESHGANN	= 125,
744 	IEEE80211_ELEMID_MESHRANN	= 126,
745 	/* 127 Extended Capabilities */
746 	/* 128-129 reserved */
747 	IEEE80211_ELEMID_MESHPREQ	= 130,
748 	IEEE80211_ELEMID_MESHPREP	= 131,
749 	IEEE80211_ELEMID_MESHPERR	= 132,
750 	/* 133-136 reserved */
751 	IEEE80211_ELEMID_MESHPXU	= 137,
752 	IEEE80211_ELEMID_MESHPXUC	= 138,
753 	IEEE80211_ELEMID_MESHAH		= 60, /* XXX: remove */
754 };
755 
756 struct ieee80211_tim_ie {
757 	uint8_t		tim_ie;			/* IEEE80211_ELEMID_TIM */
758 	uint8_t		tim_len;
759 	uint8_t		tim_count;		/* DTIM count */
760 	uint8_t		tim_period;		/* DTIM period */
761 	uint8_t		tim_bitctl;		/* bitmap control */
762 	uint8_t		tim_bitmap[1];		/* variable-length bitmap */
763 } __packed;
764 
765 struct ieee80211_country_ie {
766 	uint8_t		ie;			/* IEEE80211_ELEMID_COUNTRY */
767 	uint8_t		len;
768 	uint8_t		cc[3];			/* ISO CC+(I)ndoor/(O)utdoor */
769 	struct {
770 		uint8_t schan;			/* starting channel */
771 		uint8_t nchan;			/* number channels */
772 		uint8_t maxtxpwr;		/* tx power cap */
773 	} __packed band[1];			/* sub bands (NB: var size) */
774 } __packed;
775 
776 #define	IEEE80211_COUNTRY_MAX_BANDS	84	/* max possible bands */
777 #define	IEEE80211_COUNTRY_MAX_SIZE \
778 	(sizeof(struct ieee80211_country_ie) + 3*(IEEE80211_COUNTRY_MAX_BANDS-1))
779 
780 /*
781  * 802.11h Quiet Time Element.
782  */
783 struct ieee80211_quiet_ie {
784 	uint8_t		quiet_ie;		/* IEEE80211_ELEMID_QUIET */
785 	uint8_t		len;
786 	uint8_t		tbttcount;		/* quiet start */
787 	uint8_t		period;			/* beacon intervals between quiets */
788 	uint16_t	duration;		/* TUs of each quiet*/
789 	uint16_t	offset;			/* TUs of from TBTT of quiet start */
790 } __packed;
791 
792 /*
793  * 802.11h Channel Switch Announcement (CSA).
794  */
795 struct ieee80211_csa_ie {
796 	uint8_t		csa_ie;		/* IEEE80211_ELEMID_CHANSWITCHANN */
797 	uint8_t		csa_len;
798 	uint8_t		csa_mode;		/* Channel Switch Mode */
799 	uint8_t		csa_newchan;		/* New Channel Number */
800 	uint8_t		csa_count;		/* Channel Switch Count */
801 } __packed;
802 
803 /*
804  * Note the min acceptable CSA count is used to guard against
805  * malicious CSA injection in station mode.  Defining this value
806  * as other than 0 violates the 11h spec.
807  */
808 #define	IEEE80211_CSA_COUNT_MIN	2
809 #define	IEEE80211_CSA_COUNT_MAX	255
810 
811 /* rate set entries are in .5 Mb/s units, and potentially marked as basic */
812 #define	IEEE80211_RATE_BASIC		0x80
813 #define	IEEE80211_RATE_VAL		0x7f
814 
815 /* EPR information element flags */
816 #define	IEEE80211_ERP_NON_ERP_PRESENT	0x01
817 #define	IEEE80211_ERP_USE_PROTECTION	0x02
818 #define	IEEE80211_ERP_LONG_PREAMBLE	0x04
819 
820 #define	IEEE80211_ERP_BITS \
821 	"\20\1NON_ERP_PRESENT\2USE_PROTECTION\3LONG_PREAMBLE"
822 
823 #define	ATH_OUI			0x7f0300	/* Atheros OUI */
824 #define	ATH_OUI_TYPE		0x01		/* Atheros protocol ie */
825 
826 /* NB: Atheros allocated the OUI for this purpose ~2005 but beware ... */
827 #define	TDMA_OUI		ATH_OUI
828 #define	TDMA_OUI_TYPE		0x02		/* TDMA protocol ie */
829 
830 #define	BCM_OUI			0x4c9000	/* Broadcom OUI */
831 #define	BCM_OUI_HTCAP		51		/* pre-draft HTCAP ie */
832 #define	BCM_OUI_HTINFO		52		/* pre-draft HTINFO ie */
833 
834 #define	WPA_OUI			0xf25000
835 #define	WPA_OUI_TYPE		0x01
836 #define	WPA_VERSION		1		/* current supported version */
837 
838 #define	WPA_CSE_NULL		0x00
839 #define	WPA_CSE_WEP40		0x01
840 #define	WPA_CSE_TKIP		0x02
841 #define	WPA_CSE_CCMP		0x04
842 #define	WPA_CSE_WEP104		0x05
843 
844 #define	WPA_ASE_NONE		0x00
845 #define	WPA_ASE_8021X_UNSPEC	0x01
846 #define	WPA_ASE_8021X_PSK	0x02
847 
848 #define	WPS_OUI_TYPE		0x04
849 
850 #define	RSN_OUI			0xac0f00
851 #define	RSN_VERSION		1		/* current supported version */
852 
853 #define	RSN_CSE_NULL		0x00
854 #define	RSN_CSE_WEP40		0x01
855 #define	RSN_CSE_TKIP		0x02
856 #define	RSN_CSE_WRAP		0x03
857 #define	RSN_CSE_CCMP		0x04
858 #define	RSN_CSE_WEP104		0x05
859 
860 #define	RSN_ASE_NONE		0x00
861 #define	RSN_ASE_8021X_UNSPEC	0x01
862 #define	RSN_ASE_8021X_PSK	0x02
863 
864 #define	RSN_CAP_PREAUTH		0x01
865 
866 #define	WME_OUI			0xf25000
867 #define	WME_OUI_TYPE		0x02
868 #define	WME_INFO_OUI_SUBTYPE	0x00
869 #define	WME_PARAM_OUI_SUBTYPE	0x01
870 #define	WME_VERSION		1
871 
872 /* WME stream classes */
873 #define	WME_AC_BE	0		/* best effort */
874 #define	WME_AC_BK	1		/* background */
875 #define	WME_AC_VI	2		/* video */
876 #define	WME_AC_VO	3		/* voice */
877 
878 /*
879  * AUTH management packets
880  *
881  *	octet algo[2]
882  *	octet seq[2]
883  *	octet status[2]
884  *	octet chal.id
885  *	octet chal.length
886  *	octet chal.text[253]		NB: 1-253 bytes
887  */
888 
889 /* challenge length for shared key auth */
890 #define IEEE80211_CHALLENGE_LEN		128
891 
892 #define	IEEE80211_AUTH_ALG_OPEN		0x0000
893 #define	IEEE80211_AUTH_ALG_SHARED	0x0001
894 #define	IEEE80211_AUTH_ALG_LEAP		0x0080
895 
896 enum {
897 	IEEE80211_AUTH_OPEN_REQUEST		= 1,
898 	IEEE80211_AUTH_OPEN_RESPONSE		= 2,
899 };
900 
901 enum {
902 	IEEE80211_AUTH_SHARED_REQUEST		= 1,
903 	IEEE80211_AUTH_SHARED_CHALLENGE		= 2,
904 	IEEE80211_AUTH_SHARED_RESPONSE		= 3,
905 	IEEE80211_AUTH_SHARED_PASS		= 4,
906 };
907 
908 /*
909  * Reason and status codes.
910  *
911  * Reason codes are used in management frames to indicate why an
912  * action took place (e.g. on disassociation).  Status codes are
913  * used in management frames to indicate the result of an operation.
914  *
915  * Unlisted codes are reserved
916  */
917 
918 enum {
919 	IEEE80211_REASON_UNSPECIFIED		= 1,
920 	IEEE80211_REASON_AUTH_EXPIRE		= 2,
921 	IEEE80211_REASON_AUTH_LEAVE		= 3,
922 	IEEE80211_REASON_ASSOC_EXPIRE		= 4,
923 	IEEE80211_REASON_ASSOC_TOOMANY		= 5,
924 	IEEE80211_REASON_NOT_AUTHED		= 6,
925 	IEEE80211_REASON_NOT_ASSOCED		= 7,
926 	IEEE80211_REASON_ASSOC_LEAVE		= 8,
927 	IEEE80211_REASON_ASSOC_NOT_AUTHED	= 9,
928 	IEEE80211_REASON_DISASSOC_PWRCAP_BAD	= 10,	/* 11h */
929 	IEEE80211_REASON_DISASSOC_SUPCHAN_BAD	= 11,	/* 11h */
930 	IEEE80211_REASON_IE_INVALID		= 13,	/* 11i */
931 	IEEE80211_REASON_MIC_FAILURE		= 14,	/* 11i */
932 	IEEE80211_REASON_4WAY_HANDSHAKE_TIMEOUT	= 15,	/* 11i */
933 	IEEE80211_REASON_GROUP_KEY_UPDATE_TIMEOUT = 16,	/* 11i */
934 	IEEE80211_REASON_IE_IN_4WAY_DIFFERS	= 17,	/* 11i */
935 	IEEE80211_REASON_GROUP_CIPHER_INVALID	= 18,	/* 11i */
936 	IEEE80211_REASON_PAIRWISE_CIPHER_INVALID= 19,	/* 11i */
937 	IEEE80211_REASON_AKMP_INVALID		= 20,	/* 11i */
938 	IEEE80211_REASON_UNSUPP_RSN_IE_VERSION	= 21,	/* 11i */
939 	IEEE80211_REASON_INVALID_RSN_IE_CAP	= 22,	/* 11i */
940 	IEEE80211_REASON_802_1X_AUTH_FAILED	= 23,	/* 11i */
941 	IEEE80211_REASON_CIPHER_SUITE_REJECTED	= 24,	/* 11i */
942 	IEEE80211_REASON_UNSPECIFIED_QOS	= 32,	/* 11e */
943 	IEEE80211_REASON_INSUFFICIENT_BW	= 33,	/* 11e */
944 	IEEE80211_REASON_TOOMANY_FRAMES		= 34,	/* 11e */
945 	IEEE80211_REASON_OUTSIDE_TXOP		= 35,	/* 11e */
946 	IEEE80211_REASON_LEAVING_QBSS		= 36,	/* 11e */
947 	IEEE80211_REASON_BAD_MECHANISM		= 37,	/* 11e */
948 	IEEE80211_REASON_SETUP_NEEDED		= 38,	/* 11e */
949 	IEEE80211_REASON_TIMEOUT		= 39,	/* 11e */
950 
951 	IEEE80211_REASON_PEER_LINK_CANCELED	= 52,	/* 11s */
952 	IEEE80211_REASON_MESH_MAX_PEERS		= 53,	/* 11s */
953 	IEEE80211_REASON_MESH_CPVIOLATION	= 54,	/* 11s */
954 	IEEE80211_REASON_MESH_CLOSE_RCVD	= 55,	/* 11s */
955 	IEEE80211_REASON_MESH_MAX_RETRIES	= 56,	/* 11s */
956 	IEEE80211_REASON_MESH_CONFIRM_TIMEOUT	= 57,	/* 11s */
957 	IEEE80211_REASON_MESH_INVALID_GTK	= 58,	/* 11s */
958 	IEEE80211_REASON_MESH_INCONS_PARAMS	= 59,	/* 11s */
959 	IEEE80211_REASON_MESH_INVALID_SECURITY	= 60,	/* 11s */
960 	IEEE80211_REASON_MESH_PERR_NO_PROXY	= 61,	/* 11s */
961 	IEEE80211_REASON_MESH_PERR_NO_FI	= 62,	/* 11s */
962 	IEEE80211_REASON_MESH_PERR_DEST_UNREACH	= 63,	/* 11s */
963 	IEEE80211_REASON_MESH_MAC_ALRDY_EXISTS_MBSS = 64, /* 11s */
964 	IEEE80211_REASON_MESH_CHAN_SWITCH_REG	= 65,	/* 11s */
965 	IEEE80211_REASON_MESH_CHAN_SWITCH_UNSPEC = 66,	/* 11s */
966 
967 	IEEE80211_STATUS_SUCCESS		= 0,
968 	IEEE80211_STATUS_UNSPECIFIED		= 1,
969 	IEEE80211_STATUS_CAPINFO		= 10,
970 	IEEE80211_STATUS_NOT_ASSOCED		= 11,
971 	IEEE80211_STATUS_OTHER			= 12,
972 	IEEE80211_STATUS_ALG			= 13,
973 	IEEE80211_STATUS_SEQUENCE		= 14,
974 	IEEE80211_STATUS_CHALLENGE		= 15,
975 	IEEE80211_STATUS_TIMEOUT		= 16,
976 	IEEE80211_STATUS_TOOMANY		= 17,
977 	IEEE80211_STATUS_BASIC_RATE		= 18,
978 	IEEE80211_STATUS_SP_REQUIRED		= 19,	/* 11b */
979 	IEEE80211_STATUS_PBCC_REQUIRED		= 20,	/* 11b */
980 	IEEE80211_STATUS_CA_REQUIRED		= 21,	/* 11b */
981 	IEEE80211_STATUS_SPECMGMT_REQUIRED	= 22,	/* 11h */
982 	IEEE80211_STATUS_PWRCAP_REQUIRED	= 23,	/* 11h */
983 	IEEE80211_STATUS_SUPCHAN_REQUIRED	= 24,	/* 11h */
984 	IEEE80211_STATUS_SHORTSLOT_REQUIRED	= 25,	/* 11g */
985 	IEEE80211_STATUS_DSSSOFDM_REQUIRED	= 26,	/* 11g */
986 	IEEE80211_STATUS_MISSING_HT_CAPS	= 27,	/* 11n D3.0 */
987 	IEEE80211_STATUS_INVALID_IE		= 40,	/* 11i */
988 	IEEE80211_STATUS_GROUP_CIPHER_INVALID	= 41,	/* 11i */
989 	IEEE80211_STATUS_PAIRWISE_CIPHER_INVALID = 42,	/* 11i */
990 	IEEE80211_STATUS_AKMP_INVALID		= 43,	/* 11i */
991 	IEEE80211_STATUS_UNSUPP_RSN_IE_VERSION	= 44,	/* 11i */
992 	IEEE80211_STATUS_INVALID_RSN_IE_CAP	= 45,	/* 11i */
993 	IEEE80211_STATUS_CIPHER_SUITE_REJECTED	= 46,	/* 11i */
994 };
995 
996 #define	IEEE80211_WEP_KEYLEN		5	/* 40bit */
997 #define	IEEE80211_WEP_IVLEN		3	/* 24bit */
998 #define	IEEE80211_WEP_KIDLEN		1	/* 1 octet */
999 #define	IEEE80211_WEP_CRCLEN		4	/* CRC-32 */
1000 #define	IEEE80211_WEP_TOTLEN		(IEEE80211_WEP_IVLEN + \
1001 					 IEEE80211_WEP_KIDLEN + \
1002 					 IEEE80211_WEP_CRCLEN)
1003 #define	IEEE80211_WEP_NKID		4	/* number of key ids */
1004 
1005 /*
1006  * 802.11i defines an extended IV for use with non-WEP ciphers.
1007  * When the EXTIV bit is set in the key id byte an additional
1008  * 4 bytes immediately follow the IV for TKIP.  For CCMP the
1009  * EXTIV bit is likewise set but the 8 bytes represent the
1010  * CCMP header rather than IV+extended-IV.
1011  */
1012 #define	IEEE80211_WEP_EXTIV		0x20
1013 #define	IEEE80211_WEP_EXTIVLEN		4	/* extended IV length */
1014 #define	IEEE80211_WEP_MICLEN		8	/* trailing MIC */
1015 
1016 #define	IEEE80211_CRC_LEN		4
1017 
1018 /*
1019  * Maximum acceptable MTU is:
1020  *	IEEE80211_MAX_LEN - WEP overhead - CRC -
1021  *		QoS overhead - RSN/WPA overhead
1022  * Min is arbitrarily chosen > IEEE80211_MIN_LEN.  The default
1023  * mtu is Ethernet-compatible; it's set by ether_ifattach.
1024  */
1025 #define	IEEE80211_MTU_MAX		2290
1026 #define	IEEE80211_MTU_MIN		32
1027 
1028 #define	IEEE80211_MAX_LEN		(2300 + IEEE80211_CRC_LEN + \
1029     (IEEE80211_WEP_IVLEN + IEEE80211_WEP_KIDLEN + IEEE80211_WEP_CRCLEN))
1030 #define	IEEE80211_ACK_LEN \
1031 	(sizeof(struct ieee80211_frame_ack) + IEEE80211_CRC_LEN)
1032 #define	IEEE80211_MIN_LEN \
1033 	(sizeof(struct ieee80211_frame_min) + IEEE80211_CRC_LEN)
1034 
1035 /*
1036  * The 802.11 spec says at most 2007 stations may be
1037  * associated at once.  For most AP's this is way more
1038  * than is feasible so we use a default of IEEE80211_AID_DEF.
1039  * This number may be overridden by the driver and/or by
1040  * user configuration but may not be less than IEEE80211_AID_MIN
1041  * (see _ieee80211.h for implementation-specific settings).
1042  */
1043 #define	IEEE80211_AID_MAX		2007
1044 
1045 #define	IEEE80211_AID(b)	((b) &~ 0xc000)
1046 
1047 /*
1048  * RTS frame length parameters.  The default is specified in
1049  * the 802.11 spec as 512; we treat it as implementation-dependent
1050  * so it's defined in ieee80211_var.h.  The max may be wrong
1051  * for jumbo frames.
1052  */
1053 #define	IEEE80211_RTS_MIN		1
1054 #define	IEEE80211_RTS_MAX		2346
1055 
1056 /*
1057  * TX fragmentation parameters.  As above for RTS, we treat
1058  * default as implementation-dependent so define it elsewhere.
1059  */
1060 #define	IEEE80211_FRAG_MIN		256
1061 #define	IEEE80211_FRAG_MAX		2346
1062 
1063 /*
1064  * Beacon interval (TU's).  Min+max come from WiFi requirements.
1065  * As above, we treat default as implementation-dependent so
1066  * define it elsewhere.
1067  */
1068 #define	IEEE80211_BINTVAL_MAX	1000	/* max beacon interval (TU's) */
1069 #define	IEEE80211_BINTVAL_MIN	25	/* min beacon interval (TU's) */
1070 
1071 /*
1072  * DTIM period (beacons).  Min+max are not really defined
1073  * by the protocol but we want them publicly visible so
1074  * define them here.
1075  */
1076 #define	IEEE80211_DTIM_MAX	15	/* max DTIM period */
1077 #define	IEEE80211_DTIM_MIN	1	/* min DTIM period */
1078 
1079 /*
1080  * Beacon miss threshold (beacons).  As for DTIM, we define
1081  * them here to be publicly visible.  Note the max may be
1082  * clamped depending on device capabilities.
1083  */
1084 #define	IEEE80211_HWBMISS_MIN 	1
1085 #define	IEEE80211_HWBMISS_MAX 	255
1086 
1087 /*
1088  * 802.11 frame duration definitions.
1089  */
1090 
1091 struct ieee80211_duration {
1092 	uint16_t	d_rts_dur;
1093 	uint16_t	d_data_dur;
1094 	uint16_t	d_plcp_len;
1095 	uint8_t		d_residue;	/* unused octets in time slot */
1096 };
1097 
1098 /* One Time Unit (TU) is 1Kus = 1024 microseconds. */
1099 #define IEEE80211_DUR_TU		1024
1100 
1101 /* IEEE 802.11b durations for DSSS PHY in microseconds */
1102 #define IEEE80211_DUR_DS_LONG_PREAMBLE	144
1103 #define IEEE80211_DUR_DS_SHORT_PREAMBLE	72
1104 
1105 #define IEEE80211_DUR_DS_SLOW_PLCPHDR	48
1106 #define IEEE80211_DUR_DS_FAST_PLCPHDR	24
1107 #define IEEE80211_DUR_DS_SLOW_ACK	112
1108 #define IEEE80211_DUR_DS_FAST_ACK	56
1109 #define IEEE80211_DUR_DS_SLOW_CTS	112
1110 #define IEEE80211_DUR_DS_FAST_CTS	56
1111 
1112 #define IEEE80211_DUR_DS_SLOT		20
1113 #define IEEE80211_DUR_DS_SIFS		10
1114 #define IEEE80211_DUR_DS_PIFS	(IEEE80211_DUR_DS_SIFS + IEEE80211_DUR_DS_SLOT)
1115 #define IEEE80211_DUR_DS_DIFS	(IEEE80211_DUR_DS_SIFS + \
1116 				 2 * IEEE80211_DUR_DS_SLOT)
1117 #define IEEE80211_DUR_DS_EIFS	(IEEE80211_DUR_DS_SIFS + \
1118 				 IEEE80211_DUR_DS_SLOW_ACK + \
1119 				 IEEE80211_DUR_DS_LONG_PREAMBLE + \
1120 				 IEEE80211_DUR_DS_SLOW_PLCPHDR + \
1121 				 IEEE80211_DUR_DIFS)
1122 
1123 #endif /* _NET80211_IEEE80211_H_ */
1124