1 /*
2  * hostapd / Station table
3  * Copyright (c) 2002-2017, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8 
9 #ifndef STA_INFO_H
10 #define STA_INFO_H
11 
12 #include "common/defs.h"
13 #include "list.h"
14 #include "vlan.h"
15 #include "common/wpa_common.h"
16 #include "common/ieee802_11_defs.h"
17 #include "common/sae.h"
18 #include "crypto/sha384.h"
19 #include "pasn/pasn_common.h"
20 #include "hostapd.h"
21 
22 /* STA flags */
23 #define WLAN_STA_AUTH BIT(0)
24 #define WLAN_STA_ASSOC BIT(1)
25 #define WLAN_STA_AUTHORIZED BIT(5)
26 #define WLAN_STA_PENDING_POLL BIT(6) /* pending activity poll not ACKed */
27 #define WLAN_STA_SHORT_PREAMBLE BIT(7)
28 #define WLAN_STA_PREAUTH BIT(8)
29 #define WLAN_STA_WMM BIT(9)
30 #define WLAN_STA_MFP BIT(10)
31 #define WLAN_STA_HT BIT(11)
32 #define WLAN_STA_WPS BIT(12)
33 #define WLAN_STA_MAYBE_WPS BIT(13)
34 #define WLAN_STA_WDS BIT(14)
35 #define WLAN_STA_ASSOC_REQ_OK BIT(15)
36 #define WLAN_STA_WPS2 BIT(16)
37 #define WLAN_STA_GAS BIT(17)
38 #define WLAN_STA_VHT BIT(18)
39 #define WLAN_STA_WNM_SLEEP_MODE BIT(19)
40 #define WLAN_STA_VHT_OPMODE_ENABLED BIT(20)
41 #define WLAN_STA_VENDOR_VHT BIT(21)
42 #define WLAN_STA_PENDING_FILS_ERP BIT(22)
43 #define WLAN_STA_MULTI_AP BIT(23)
44 #define WLAN_STA_HE BIT(24)
45 #define WLAN_STA_6GHZ BIT(25)
46 #define WLAN_STA_PENDING_PASN_FILS_ERP BIT(26)
47 #define WLAN_STA_EHT BIT(27)
48 #define WLAN_STA_PENDING_DISASSOC_CB BIT(29)
49 #define WLAN_STA_PENDING_DEAUTH_CB BIT(30)
50 #define WLAN_STA_NONERP BIT(31)
51 
52 /* Maximum number of supported rates (from both Supported Rates and Extended
53  * Supported Rates IEs). */
54 #define WLAN_SUPP_RATES_MAX 32
55 
56 struct hostapd_data;
57 
58 struct mbo_non_pref_chan_info {
59           struct mbo_non_pref_chan_info *next;
60           u8 op_class;
61           u8 pref;
62           u8 reason_code;
63           u8 num_channels;
64           u8 channels[];
65 };
66 
67 struct pending_eapol_rx {
68           struct wpabuf *buf;
69           struct os_reltime rx_time;
70           enum frame_encryption encrypted;
71 };
72 
73 #define EHT_ML_MAX_STA_PROF_LEN 1024
74 struct mld_info {
75           bool mld_sta;
76 
77           struct ml_common_info {
78                     u8 mld_addr[ETH_ALEN];
79                     u16 medium_sync_delay;
80                     u16 eml_capa;
81                     u16 mld_capa;
82           } common_info;
83 
84           struct mld_link_info {
85                     u8 valid:1;
86                     u8 nstr_bitmap_len:2;
87                     u8 local_addr[ETH_ALEN];
88                     u8 peer_addr[ETH_ALEN];
89 
90                     u8 nstr_bitmap[2];
91 
92                     u16 capability;
93 
94                     u16 status;
95                     u16 resp_sta_profile_len;
96                     u8 *resp_sta_profile;
97           } links[MAX_NUM_MLD_LINKS];
98 };
99 
100 struct sta_info {
101           struct sta_info *next; /* next entry in sta list */
102           struct sta_info *hnext; /* next entry in hash table list */
103           u8 addr[6];
104           be32 ipaddr;
105           struct dl_list ip6addr; /* list head for struct ip6addr */
106           u16 aid; /* STA's unique AID (1 .. 2007) or 0 if not yet assigned */
107           u16 disconnect_reason_code; /* RADIUS server override */
108           u32 flags; /* Bitfield of WLAN_STA_* */
109           u16 capability;
110           u16 listen_interval; /* or beacon_int for APs */
111           u8 supported_rates[WLAN_SUPP_RATES_MAX];
112           int supported_rates_len;
113           u8 qosinfo; /* Valid when WLAN_STA_WMM is set */
114 
115 #ifdef CONFIG_MESH
116           enum mesh_plink_state plink_state;
117           u16 peer_lid;
118           u16 my_lid;
119           u16 peer_aid;
120           u16 mpm_close_reason;
121           int mpm_retries;
122           u8 my_nonce[WPA_NONCE_LEN];
123           u8 peer_nonce[WPA_NONCE_LEN];
124           u8 aek[32];         /* SHA256 digest length */
125           u8 mtk[WPA_TK_MAX_LEN];
126           size_t mtk_len;
127           u8 mgtk_rsc[6];
128           u8 mgtk_key_id;
129           u8 mgtk[WPA_TK_MAX_LEN];
130           size_t mgtk_len;
131           u8 igtk_rsc[6];
132           u8 igtk[WPA_TK_MAX_LEN];
133           size_t igtk_len;
134           u16 igtk_key_id;
135           u8 sae_auth_retry;
136 #endif /* CONFIG_MESH */
137 
138           unsigned int nonerp_set:1;
139           unsigned int no_short_slot_time_set:1;
140           unsigned int no_short_preamble_set:1;
141           unsigned int no_ht_gf_set:1;
142           unsigned int no_ht_set:1;
143           unsigned int ht40_intolerant_set:1;
144           unsigned int ht_20mhz_set:1;
145           unsigned int no_p2p_set:1;
146           unsigned int qos_map_enabled:1;
147           unsigned int remediation:1;
148           unsigned int hs20_deauth_requested:1;
149           unsigned int hs20_deauth_on_ack:1;
150           unsigned int session_timeout_set:1;
151           unsigned int radius_das_match:1;
152           unsigned int ecsa_supported:1;
153           unsigned int added_unassoc:1;
154           unsigned int pending_wds_enable:1;
155           unsigned int power_capab:1;
156           unsigned int agreed_to_steer:1;
157           unsigned int hs20_t_c_filtering:1;
158           unsigned int ft_over_ds:1;
159           unsigned int external_dh_updated:1;
160           unsigned int post_csa_sa_query:1;
161 
162           u16 auth_alg;
163 
164           enum {
165                     STA_NULLFUNC = 0, STA_DISASSOC, STA_DEAUTH, STA_REMOVE,
166                     STA_DISASSOC_FROM_CLI
167           } timeout_next;
168 
169           u16 deauth_reason;
170           u16 disassoc_reason;
171 
172           /* IEEE 802.1X related data */
173           struct eapol_state_machine *eapol_sm;
174 
175           struct pending_eapol_rx *pending_eapol_rx;
176 
177           u64 acct_session_id;
178           struct os_reltime acct_session_start;
179           int acct_session_started;
180           int acct_terminate_cause; /* Acct-Terminate-Cause */
181           int acct_interim_interval; /* Acct-Interim-Interval */
182           unsigned int acct_interim_errors;
183 
184           /* For extending 32-bit driver counters to 64-bit counters */
185           u32 last_rx_bytes_hi;
186           u32 last_rx_bytes_lo;
187           u32 last_tx_bytes_hi;
188           u32 last_tx_bytes_lo;
189 
190           u8 *challenge; /* IEEE 802.11 Shared Key Authentication Challenge */
191 
192           struct wpa_state_machine *wpa_sm;
193           struct rsn_preauth_interface *preauth_iface;
194 
195           int vlan_id; /* 0: none, >0: VID */
196           struct vlan_description *vlan_desc;
197           int vlan_id_bound; /* updated by ap_sta_bind_vlan() */
198            /* PSKs from RADIUS authentication server */
199           struct hostapd_sta_wpa_psk_short *psk;
200 
201           char *identity; /* User-Name from RADIUS */
202           char *radius_cui; /* Chargeable-User-Identity from RADIUS */
203 
204           struct ieee80211_ht_capabilities *ht_capabilities;
205           struct ieee80211_vht_capabilities *vht_capabilities;
206           struct ieee80211_vht_operation *vht_operation;
207           u8 vht_opmode;
208           struct ieee80211_he_capabilities *he_capab;
209           size_t he_capab_len;
210           struct ieee80211_he_6ghz_band_cap *he_6ghz_capab;
211           struct ieee80211_eht_capabilities *eht_capab;
212           size_t eht_capab_len;
213 
214           int sa_query_count; /* number of pending SA Query requests;
215                                    * 0 = no SA Query in progress */
216           int sa_query_timed_out;
217           u8 *sa_query_trans_id; /* buffer of WLAN_SA_QUERY_TR_ID_LEN *
218                                         * sa_query_count octets of pending SA Query
219                                         * transaction identifiers */
220           struct os_reltime sa_query_start;
221 
222 #if defined(CONFIG_INTERWORKING) || defined(CONFIG_DPP)
223 #define GAS_DIALOG_MAX 8 /* Max concurrent dialog number */
224           struct gas_dialog_info *gas_dialog;
225           u8 gas_dialog_next;
226 #endif /* CONFIG_INTERWORKING || CONFIG_DPP */
227 
228           struct wpabuf *wps_ie; /* WPS IE from (Re)Association Request */
229           struct wpabuf *p2p_ie; /* P2P IE from (Re)Association Request */
230           struct wpabuf *hs20_ie; /* HS 2.0 IE from (Re)Association Request */
231           /* Hotspot 2.0 Roaming Consortium from (Re)Association Request */
232           struct wpabuf *roaming_consortium;
233           u8 remediation_method;
234           char *remediation_url; /* HS 2.0 Subscription Remediation Server URL */
235           char *t_c_url; /* HS 2.0 Terms and Conditions Server URL */
236           struct wpabuf *hs20_deauth_req;
237           char *hs20_session_info_url;
238           int hs20_disassoc_timer;
239 #ifdef CONFIG_FST
240           struct wpabuf *mb_ies; /* MB IEs from (Re)Association Request */
241 #endif /* CONFIG_FST */
242 
243           struct os_reltime connected_time;
244 
245 #ifdef CONFIG_SAE
246           struct sae_data *sae;
247           unsigned int mesh_sae_pmksa_caching:1;
248 #endif /* CONFIG_SAE */
249 
250           /* valid only if session_timeout_set == 1 */
251           struct os_reltime session_timeout;
252 
253           /* Last Authentication/(Re)Association Request/Action frame sequence
254            * control */
255           u16 last_seq_ctrl;
256           /* Last Authentication/(Re)Association Request/Action frame subtype */
257           u8 last_subtype;
258 
259 #ifdef CONFIG_MBO
260           u8 cell_capa; /* 0 = unknown (not an MBO STA); otherwise,
261                            * enum mbo_cellular_capa values */
262           struct mbo_non_pref_chan_info *non_pref_chan;
263           int auth_rssi; /* Last Authentication frame RSSI */
264 #endif /* CONFIG_MBO */
265 
266           u8 *supp_op_classes; /* Supported Operating Classes element, if
267                                     * received, starting from the Length field */
268 
269           u8 rrm_enabled_capa[5];
270 
271           s8 min_tx_power;
272           s8 max_tx_power;
273 
274 #ifdef CONFIG_TAXONOMY
275           struct wpabuf *probe_ie_taxonomy;
276           struct wpabuf *assoc_ie_taxonomy;
277 #endif /* CONFIG_TAXONOMY */
278 
279 #ifdef CONFIG_FILS
280           u8 fils_snonce[FILS_NONCE_LEN];
281           u8 fils_session[FILS_SESSION_LEN];
282           u8 fils_erp_pmkid[PMKID_LEN];
283           u8 *fils_pending_assoc_req;
284           size_t fils_pending_assoc_req_len;
285           unsigned int fils_pending_assoc_is_reassoc:1;
286           unsigned int fils_dhcp_rapid_commit_proxy:1;
287           unsigned int fils_erp_pmkid_set:1;
288           unsigned int fils_drv_assoc_finish:1;
289           struct wpabuf *fils_hlp_resp;
290           struct wpabuf *hlp_dhcp_discover;
291           void (*fils_pending_cb)(struct hostapd_data *hapd, struct sta_info *sta,
292                                         u16 resp, struct wpabuf *data, int pub);
293 #ifdef CONFIG_FILS_SK_PFS
294           struct crypto_ecdh *fils_ecdh;
295 #endif /* CONFIG_FILS_SK_PFS */
296           struct wpabuf *fils_dh_ss;
297           struct wpabuf *fils_g_sta;
298 #endif /* CONFIG_FILS */
299 
300 #ifdef CONFIG_OWE
301           u8 *owe_pmk;
302           size_t owe_pmk_len;
303           struct crypto_ecdh *owe_ecdh;
304           u16 owe_group;
305 #endif /* CONFIG_OWE */
306 
307           u8 *ext_capability;
308           char *ifname_wds; /* WDS ifname, if in use */
309 
310 #ifdef CONFIG_DPP2
311           struct dpp_pfs *dpp_pfs;
312 #endif /* CONFIG_DPP2 */
313 
314 #ifdef CONFIG_TESTING_OPTIONS
315           enum wpa_alg last_tk_alg;
316           int last_tk_key_idx;
317           u8 last_tk[WPA_TK_MAX_LEN];
318           size_t last_tk_len;
319           u8 *sae_postponed_commit;
320           size_t sae_postponed_commit_len;
321 #endif /* CONFIG_TESTING_OPTIONS */
322 #ifdef CONFIG_AIRTIME_POLICY
323           unsigned int airtime_weight;
324           struct os_reltime backlogged_until;
325 #endif /* CONFIG_AIRTIME_POLICY */
326 
327 #ifdef CONFIG_PASN
328           struct pasn_data *pasn;
329 #endif /* CONFIG_PASN */
330 
331 #ifdef CONFIG_IEEE80211BE
332           struct mld_info mld_info;
333           u8 mld_assoc_link_id;
334 #endif /* CONFIG_IEEE80211BE */
335 
336           u16 max_idle_period; /* if nonzero, the granted BSS max idle period in
337                                     * units of 1000 TUs */
338 };
339 
340 
341 /* Default value for maximum station inactivity. After AP_MAX_INACTIVITY has
342  * passed since last received frame from the station, a nullfunc data frame is
343  * sent to the station. If this frame is not acknowledged and no other frames
344  * have been received, the station will be disassociated after
345  * AP_DISASSOC_DELAY seconds. Similarly, the station will be deauthenticated
346  * after AP_DEAUTH_DELAY seconds has passed after disassociation. */
347 #define AP_MAX_INACTIVITY (5 * 60)
348 #define AP_DISASSOC_DELAY (3)
349 #define AP_DEAUTH_DELAY (1)
350 /* Number of seconds to keep STA entry with Authenticated flag after it has
351  * been disassociated. */
352 #define AP_MAX_INACTIVITY_AFTER_DISASSOC (1 * 30)
353 /* Number of seconds to keep STA entry after it has been deauthenticated. */
354 #define AP_MAX_INACTIVITY_AFTER_DEAUTH (1 * 5)
355 
356 
357 int ap_for_each_sta(struct hostapd_data *hapd,
358                         int (*cb)(struct hostapd_data *hapd, struct sta_info *sta,
359                                     void *ctx),
360                         void *ctx);
361 struct sta_info * ap_get_sta(struct hostapd_data *hapd, const u8 *sta);
362 struct sta_info * ap_get_sta_p2p(struct hostapd_data *hapd, const u8 *addr);
363 void ap_sta_hash_add(struct hostapd_data *hapd, struct sta_info *sta);
364 void ap_free_sta(struct hostapd_data *hapd, struct sta_info *sta);
365 void ap_sta_ip6addr_del(struct hostapd_data *hapd, struct sta_info *sta);
366 void hostapd_free_stas(struct hostapd_data *hapd);
367 void ap_handle_timer(void *eloop_ctx, void *timeout_ctx);
368 void ap_sta_replenish_timeout(struct hostapd_data *hapd, struct sta_info *sta,
369                                     u32 session_timeout);
370 void ap_sta_session_timeout(struct hostapd_data *hapd, struct sta_info *sta,
371                                   u32 session_timeout);
372 void ap_sta_no_session_timeout(struct hostapd_data *hapd,
373                                      struct sta_info *sta);
374 void ap_sta_session_warning_timeout(struct hostapd_data *hapd,
375                                             struct sta_info *sta, int warning_time);
376 struct sta_info * ap_sta_add(struct hostapd_data *hapd, const u8 *addr);
377 void ap_sta_disassociate(struct hostapd_data *hapd, struct sta_info *sta,
378                                u16 reason);
379 void ap_sta_deauthenticate(struct hostapd_data *hapd, struct sta_info *sta,
380                                  u16 reason);
381 #ifdef CONFIG_WPS
382 int ap_sta_wps_cancel(struct hostapd_data *hapd,
383                           struct sta_info *sta, void *ctx);
384 #endif /* CONFIG_WPS */
385 int ap_sta_bind_vlan(struct hostapd_data *hapd, struct sta_info *sta);
386 int ap_sta_set_vlan(struct hostapd_data *hapd, struct sta_info *sta,
387                         struct vlan_description *vlan_desc);
388 void ap_sta_start_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
389 void ap_sta_stop_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
390 int ap_check_sa_query_timeout(struct hostapd_data *hapd, struct sta_info *sta);
391 const char * ap_sta_wpa_get_keyid(struct hostapd_data *hapd,
392                                           struct sta_info *sta);
393 const u8 * ap_sta_wpa_get_dpp_pkhash(struct hostapd_data *hapd,
394                                              struct sta_info *sta);
395 void ap_sta_disconnect(struct hostapd_data *hapd, struct sta_info *sta,
396                            const u8 *addr, u16 reason);
397 
398 bool ap_sta_set_authorized_flag(struct hostapd_data *hapd, struct sta_info *sta,
399                                         int authorized);
400 void ap_sta_set_authorized_event(struct hostapd_data *hapd,
401                                          struct sta_info *sta, int authorized);
402 void ap_sta_set_authorized(struct hostapd_data *hapd,
403                                  struct sta_info *sta, int authorized);
ap_sta_is_authorized(struct sta_info * sta)404 static inline int ap_sta_is_authorized(struct sta_info *sta)
405 {
406           return sta->flags & WLAN_STA_AUTHORIZED;
407 }
408 
409 void ap_sta_deauth_cb(struct hostapd_data *hapd, struct sta_info *sta);
410 void ap_sta_disassoc_cb(struct hostapd_data *hapd, struct sta_info *sta);
411 void ap_sta_clear_disconnect_timeouts(struct hostapd_data *hapd,
412                                               struct sta_info *sta);
413 
414 int ap_sta_flags_txt(u32 flags, char *buf, size_t buflen);
415 void ap_sta_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
416                                                       struct sta_info *sta,
417                                                       unsigned timeout);
418 int ap_sta_pending_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
419                                                                struct sta_info *sta);
420 int ap_sta_re_add(struct hostapd_data *hapd, struct sta_info *sta);
421 
422 void ap_free_sta_pasn(struct hostapd_data *hapd, struct sta_info *sta);
423 
ap_sta_is_mld(struct hostapd_data * hapd,struct sta_info * sta)424 static inline bool ap_sta_is_mld(struct hostapd_data *hapd,
425                                          struct sta_info *sta)
426 {
427 #ifdef CONFIG_IEEE80211BE
428           return hapd->conf->mld_ap && sta && sta->mld_info.mld_sta;
429 #else /* CONFIG_IEEE80211BE */
430           return false;
431 #endif /* CONFIG_IEEE80211BE */
432 }
433 
ap_sta_set_mld(struct sta_info * sta,bool mld)434 static inline void ap_sta_set_mld(struct sta_info *sta, bool mld)
435 {
436 #ifdef CONFIG_IEEE80211BE
437           if (sta)
438                     sta->mld_info.mld_sta = mld;
439 #endif /* CONFIG_IEEE80211BE */
440 }
441 
442 void ap_sta_free_sta_profile(struct mld_info *info);
443 
444 void hostapd_free_link_stas(struct hostapd_data *hapd);
445 
446 #endif /* STA_INFO_H */
447