1/*
2 * WPA Supplicant - privilege separated driver interface
3 * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
4 *
5 * This software may be distributed under the terms of the BSD license.
6 * See README for more details.
7 */
8
9#include "includes.h"
10#include <sys/un.h>
11
12#include "common.h"
13#include "driver.h"
14#include "eloop.h"
15#include "common/privsep_commands.h"
16
17
18struct wpa_driver_privsep_data {
19	void *ctx;
20	u8 own_addr[ETH_ALEN];
21	int priv_socket;
22	char *own_socket_path;
23	int cmd_socket;
24	char *own_cmd_path;
25	struct sockaddr_un priv_addr;
26	char ifname[16];
27};
28
29
30static int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
31{
32	int res;
33
34	res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
35		     (struct sockaddr *) &drv->priv_addr,
36		     sizeof(drv->priv_addr));
37	if (res < 0)
38		wpa_printf(MSG_ERROR, "sendto: %s", strerror(errno));
39	return res < 0 ? -1 : 0;
40}
41
42
43static int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
44			const void *data, size_t data_len,
45			void *reply, size_t *reply_len)
46{
47	struct msghdr msg;
48	struct iovec io[2];
49
50	io[0].iov_base = &cmd;
51	io[0].iov_len = sizeof(cmd);
52	io[1].iov_base = (u8 *) data;
53	io[1].iov_len = data_len;
54
55	os_memset(&msg, 0, sizeof(msg));
56	msg.msg_iov = io;
57	msg.msg_iovlen = data ? 2 : 1;
58	msg.msg_name = &drv->priv_addr;
59	msg.msg_namelen = sizeof(drv->priv_addr);
60
61	if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
62		wpa_printf(MSG_ERROR, "sendmsg(cmd_socket): %s",
63			   strerror(errno));
64		return -1;
65	}
66
67	if (reply) {
68		fd_set rfds;
69		struct timeval tv;
70		int res;
71
72		FD_ZERO(&rfds);
73		FD_SET(drv->cmd_socket, &rfds);
74		tv.tv_sec = 5;
75		tv.tv_usec = 0;
76		res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
77		if (res < 0 && errno != EINTR) {
78			wpa_printf(MSG_ERROR, "select: %s", strerror(errno));
79			return -1;
80		}
81
82		if (FD_ISSET(drv->cmd_socket, &rfds)) {
83			res = recv(drv->cmd_socket, reply, *reply_len, 0);
84			if (res < 0) {
85				wpa_printf(MSG_ERROR, "recv: %s",
86					   strerror(errno));
87				return -1;
88			}
89			*reply_len = res;
90		} else {
91			wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
92				   "for reply (cmd=%d)", cmd);
93			return -1;
94		}
95	}
96
97	return 0;
98}
99
100
101static int wpa_driver_privsep_scan(void *priv,
102				   struct wpa_driver_scan_params *params)
103{
104	struct wpa_driver_privsep_data *drv = priv;
105	const u8 *ssid = params->ssids[0].ssid;
106	size_t ssid_len = params->ssids[0].ssid_len;
107	wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
108	return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, ssid, ssid_len,
109			    NULL, NULL);
110}
111
112
113static struct wpa_scan_results *
114wpa_driver_privsep_get_scan_results2(void *priv)
115{
116	struct wpa_driver_privsep_data *drv = priv;
117	int res, num;
118	u8 *buf, *pos, *end;
119	size_t reply_len = 60000;
120	struct wpa_scan_results *results;
121	struct wpa_scan_res *r;
122
123	buf = os_malloc(reply_len);
124	if (buf == NULL)
125		return NULL;
126	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
127			   NULL, 0, buf, &reply_len);
128	if (res < 0) {
129		os_free(buf);
130		return NULL;
131	}
132
133	wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
134		   (unsigned long) reply_len);
135	if (reply_len < sizeof(int)) {
136		wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
137			   (unsigned long) reply_len);
138		os_free(buf);
139		return NULL;
140	}
141
142	pos = buf;
143	end = buf + reply_len;
144	os_memcpy(&num, pos, sizeof(int));
145	if (num < 0 || num > 1000) {
146		os_free(buf);
147		return NULL;
148	}
149	pos += sizeof(int);
150
151	results = os_zalloc(sizeof(*results));
152	if (results == NULL) {
153		os_free(buf);
154		return NULL;
155	}
156
157	results->res = os_calloc(num, sizeof(struct wpa_scan_res *));
158	if (results->res == NULL) {
159		os_free(results);
160		os_free(buf);
161		return NULL;
162	}
163
164	while (results->num < (size_t) num && end - pos > (int) sizeof(int)) {
165		int len;
166		os_memcpy(&len, pos, sizeof(int));
167		pos += sizeof(int);
168		if (len < 0 || len > 10000 || len > end - pos)
169			break;
170
171		r = os_malloc(len);
172		if (r == NULL)
173			break;
174		os_memcpy(r, pos, len);
175		pos += len;
176		if (sizeof(*r) + r->ie_len > (size_t) len) {
177			os_free(r);
178			break;
179		}
180
181		results->res[results->num++] = r;
182	}
183
184	os_free(buf);
185	return results;
186}
187
188
189static int wpa_driver_privsep_set_key(const char *ifname, void *priv,
190				      enum wpa_alg alg, const u8 *addr,
191				      int key_idx, int set_tx,
192				      const u8 *seq, size_t seq_len,
193				      const u8 *key, size_t key_len)
194{
195	struct wpa_driver_privsep_data *drv = priv;
196	struct privsep_cmd_set_key cmd;
197
198	wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
199		   __func__, priv, alg, key_idx, set_tx);
200
201	os_memset(&cmd, 0, sizeof(cmd));
202	cmd.alg = alg;
203	if (addr)
204		os_memcpy(cmd.addr, addr, ETH_ALEN);
205	else
206		os_memset(cmd.addr, 0xff, ETH_ALEN);
207	cmd.key_idx = key_idx;
208	cmd.set_tx = set_tx;
209	if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
210		os_memcpy(cmd.seq, seq, seq_len);
211		cmd.seq_len = seq_len;
212	}
213	if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
214		os_memcpy(cmd.key, key, key_len);
215		cmd.key_len = key_len;
216	}
217
218	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
219			    NULL, NULL);
220}
221
222
223static int wpa_driver_privsep_authenticate(
224	void *priv, struct wpa_driver_auth_params *params)
225{
226	struct wpa_driver_privsep_data *drv = priv;
227	struct privsep_cmd_authenticate *data;
228	int i, res;
229	size_t buflen;
230	u8 *pos;
231
232	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d bssid=" MACSTR
233		   " auth_alg=%d local_state_change=%d p2p=%d",
234		   __func__, priv, params->freq, MAC2STR(params->bssid),
235		   params->auth_alg, params->local_state_change, params->p2p);
236
237	buflen = sizeof(*data) + params->ie_len + params->sae_data_len;
238	data = os_zalloc(buflen);
239	if (data == NULL)
240		return -1;
241
242	data->freq = params->freq;
243	os_memcpy(data->bssid, params->bssid, ETH_ALEN);
244	os_memcpy(data->ssid, params->ssid, params->ssid_len);
245	data->ssid_len = params->ssid_len;
246	data->auth_alg = params->auth_alg;
247	data->ie_len = params->ie_len;
248	for (i = 0; i < 4; i++) {
249		if (params->wep_key[i])
250			os_memcpy(data->wep_key[i], params->wep_key[i],
251				  params->wep_key_len[i]);
252		data->wep_key_len[i] = params->wep_key_len[i];
253	}
254	data->wep_tx_keyidx = params->wep_tx_keyidx;
255	data->local_state_change = params->local_state_change;
256	data->p2p = params->p2p;
257	pos = (u8 *) (data + 1);
258	if (params->ie_len) {
259		os_memcpy(pos, params->ie, params->ie_len);
260		pos += params->ie_len;
261	}
262	if (params->sae_data_len)
263		os_memcpy(pos, params->sae_data, params->sae_data_len);
264
265	res = wpa_priv_cmd(drv, PRIVSEP_CMD_AUTHENTICATE, data, buflen,
266			   NULL, NULL);
267	os_free(data);
268
269	return res;
270}
271
272
273static int wpa_driver_privsep_associate(
274	void *priv, struct wpa_driver_associate_params *params)
275{
276	struct wpa_driver_privsep_data *drv = priv;
277	struct privsep_cmd_associate *data;
278	int res;
279	size_t buflen;
280
281	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
282		   "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
283		   __func__, priv, params->freq.freq, params->pairwise_suite,
284		   params->group_suite, params->key_mgmt_suite,
285		   params->auth_alg, params->mode);
286
287	buflen = sizeof(*data) + params->wpa_ie_len;
288	data = os_zalloc(buflen);
289	if (data == NULL)
290		return -1;
291
292	if (params->bssid)
293		os_memcpy(data->bssid, params->bssid, ETH_ALEN);
294	os_memcpy(data->ssid, params->ssid, params->ssid_len);
295	data->ssid_len = params->ssid_len;
296	data->hwmode = params->freq.mode;
297	data->freq = params->freq.freq;
298	data->channel = params->freq.channel;
299	data->pairwise_suite = params->pairwise_suite;
300	data->group_suite = params->group_suite;
301	data->key_mgmt_suite = params->key_mgmt_suite;
302	data->auth_alg = params->auth_alg;
303	data->mode = params->mode;
304	data->wpa_ie_len = params->wpa_ie_len;
305	if (params->wpa_ie)
306		os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
307	/* TODO: add support for other assoc parameters */
308
309	res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
310			   NULL, NULL);
311	os_free(data);
312
313	return res;
314}
315
316
317static int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
318{
319	struct wpa_driver_privsep_data *drv = priv;
320	int res;
321	size_t len = ETH_ALEN;
322
323	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
324	if (res < 0 || len != ETH_ALEN)
325		return -1;
326	return 0;
327}
328
329
330static int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
331{
332	struct wpa_driver_privsep_data *drv = priv;
333	int res, ssid_len;
334	u8 reply[sizeof(int) + SSID_MAX_LEN];
335	size_t len = sizeof(reply);
336
337	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
338	if (res < 0 || len < sizeof(int))
339		return -1;
340	os_memcpy(&ssid_len, reply, sizeof(int));
341	if (ssid_len < 0 || ssid_len > SSID_MAX_LEN ||
342	    sizeof(int) + ssid_len > len) {
343		wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
344		return -1;
345	}
346	os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
347	return ssid_len;
348}
349
350
351static int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
352					  int reason_code)
353{
354	//struct wpa_driver_privsep_data *drv = priv;
355	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
356		   __func__, MAC2STR(addr), reason_code);
357	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
358	return 0;
359}
360
361
362static void wpa_driver_privsep_event_auth(void *ctx, u8 *buf, size_t len)
363{
364	union wpa_event_data data;
365	struct privsep_event_auth *auth;
366
367	os_memset(&data, 0, sizeof(data));
368	if (len < sizeof(*auth))
369		return;
370	auth = (struct privsep_event_auth *) buf;
371	if (len < sizeof(*auth) + auth->ies_len)
372		return;
373
374	os_memcpy(data.auth.peer, auth->peer, ETH_ALEN);
375	os_memcpy(data.auth.bssid, auth->bssid, ETH_ALEN);
376	data.auth.auth_type = auth->auth_type;
377	data.auth.auth_transaction = auth->auth_transaction;
378	data.auth.status_code = auth->status_code;
379	if (auth->ies_len) {
380		data.auth.ies = (u8 *) (auth + 1);
381		data.auth.ies_len = auth->ies_len;
382	}
383
384	wpa_supplicant_event(ctx, EVENT_AUTH, &data);
385}
386
387
388static void wpa_driver_privsep_event_assoc(void *ctx,
389					   enum wpa_event_type event,
390					   u8 *buf, size_t len)
391{
392	union wpa_event_data data;
393	int inc_data = 0;
394	u8 *pos, *end;
395	int ie_len;
396
397	os_memset(&data, 0, sizeof(data));
398
399	pos = buf;
400	end = buf + len;
401
402	if (end - pos < (int) sizeof(int))
403		return;
404	os_memcpy(&ie_len, pos, sizeof(int));
405	pos += sizeof(int);
406	if (ie_len < 0 || ie_len > end - pos)
407		return;
408	if (ie_len) {
409		data.assoc_info.req_ies = pos;
410		data.assoc_info.req_ies_len = ie_len;
411		pos += ie_len;
412		inc_data = 1;
413	}
414
415	wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
416}
417
418
419static void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
420						      size_t len)
421{
422	union wpa_event_data data;
423	int ievent;
424
425	if (len < sizeof(int) ||
426	    len - sizeof(int) > sizeof(data.interface_status.ifname))
427		return;
428
429	os_memcpy(&ievent, buf, sizeof(int));
430
431	os_memset(&data, 0, sizeof(data));
432	data.interface_status.ievent = ievent;
433	os_memcpy(data.interface_status.ifname, buf + sizeof(int),
434		  len - sizeof(int));
435	wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
436}
437
438
439static void wpa_driver_privsep_event_michael_mic_failure(
440	void *ctx, u8 *buf, size_t len)
441{
442	union wpa_event_data data;
443
444	if (len != sizeof(int))
445		return;
446
447	os_memset(&data, 0, sizeof(data));
448	os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
449	wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
450}
451
452
453static void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
454						     size_t len)
455{
456	union wpa_event_data data;
457
458	if (len != sizeof(struct pmkid_candidate))
459		return;
460
461	os_memset(&data, 0, sizeof(data));
462	os_memcpy(&data.pmkid_candidate, buf, len);
463	wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
464}
465
466
467static void wpa_driver_privsep_event_stkstart(void *ctx, u8 *buf, size_t len)
468{
469	union wpa_event_data data;
470
471	if (len != ETH_ALEN)
472		return;
473
474	os_memset(&data, 0, sizeof(data));
475	os_memcpy(data.stkstart.peer, buf, ETH_ALEN);
476	wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
477}
478
479
480static void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
481						 size_t len)
482{
483	union wpa_event_data data;
484
485	if (len < sizeof(int) + ETH_ALEN)
486		return;
487
488	os_memset(&data, 0, sizeof(data));
489	os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
490	os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
491	data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
492	data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
493	wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
494}
495
496
497static void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
498{
499	if (len < ETH_ALEN)
500		return;
501	drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
502}
503
504
505static void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
506				       void *sock_ctx)
507{
508	struct wpa_driver_privsep_data *drv = eloop_ctx;
509	u8 *buf, *event_buf;
510	size_t event_len;
511	int res, event;
512	enum privsep_event e;
513	struct sockaddr_un from;
514	socklen_t fromlen = sizeof(from);
515	const size_t buflen = 2000;
516
517	buf = os_malloc(buflen);
518	if (buf == NULL)
519		return;
520	res = recvfrom(sock, buf, buflen, 0,
521		       (struct sockaddr *) &from, &fromlen);
522	if (res < 0) {
523		wpa_printf(MSG_ERROR, "recvfrom(priv_socket): %s",
524			   strerror(errno));
525		os_free(buf);
526		return;
527	}
528
529	wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
530
531	if (res < (int) sizeof(int)) {
532		wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
533		return;
534	}
535
536	os_memcpy(&event, buf, sizeof(int));
537	event_buf = &buf[sizeof(int)];
538	event_len = res - sizeof(int);
539	wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
540		   event, (unsigned long) event_len);
541
542	e = event;
543	switch (e) {
544	case PRIVSEP_EVENT_SCAN_RESULTS:
545		wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
546		break;
547	case PRIVSEP_EVENT_SCAN_STARTED:
548		wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, NULL);
549		break;
550	case PRIVSEP_EVENT_ASSOC:
551		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
552					       event_buf, event_len);
553		break;
554	case PRIVSEP_EVENT_DISASSOC:
555		wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
556		break;
557	case PRIVSEP_EVENT_ASSOCINFO:
558		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
559					       event_buf, event_len);
560		break;
561	case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
562		wpa_driver_privsep_event_michael_mic_failure(
563			drv->ctx, event_buf, event_len);
564		break;
565	case PRIVSEP_EVENT_INTERFACE_STATUS:
566		wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
567							  event_len);
568		break;
569	case PRIVSEP_EVENT_PMKID_CANDIDATE:
570		wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
571							 event_len);
572		break;
573	case PRIVSEP_EVENT_STKSTART:
574		wpa_driver_privsep_event_stkstart(drv->ctx, event_buf,
575						  event_len);
576		break;
577	case PRIVSEP_EVENT_FT_RESPONSE:
578		wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
579						     event_len);
580		break;
581	case PRIVSEP_EVENT_RX_EAPOL:
582		wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
583						  event_len);
584		break;
585	case PRIVSEP_EVENT_AUTH:
586		wpa_driver_privsep_event_auth(drv->ctx, event_buf, event_len);
587		break;
588	}
589
590	os_free(buf);
591}
592
593
594static void * wpa_driver_privsep_init(void *ctx, const char *ifname)
595{
596	struct wpa_driver_privsep_data *drv;
597
598	drv = os_zalloc(sizeof(*drv));
599	if (drv == NULL)
600		return NULL;
601	drv->ctx = ctx;
602	drv->priv_socket = -1;
603	drv->cmd_socket = -1;
604	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
605
606	return drv;
607}
608
609
610static void wpa_driver_privsep_deinit(void *priv)
611{
612	struct wpa_driver_privsep_data *drv = priv;
613
614	if (drv->priv_socket >= 0) {
615		wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
616		eloop_unregister_read_sock(drv->priv_socket);
617		close(drv->priv_socket);
618	}
619
620	if (drv->own_socket_path) {
621		unlink(drv->own_socket_path);
622		os_free(drv->own_socket_path);
623	}
624
625	if (drv->cmd_socket >= 0) {
626		eloop_unregister_read_sock(drv->cmd_socket);
627		close(drv->cmd_socket);
628	}
629
630	if (drv->own_cmd_path) {
631		unlink(drv->own_cmd_path);
632		os_free(drv->own_cmd_path);
633	}
634
635	os_free(drv);
636}
637
638
639static int wpa_driver_privsep_set_param(void *priv, const char *param)
640{
641	struct wpa_driver_privsep_data *drv = priv;
642	const char *pos;
643	char *own_dir, *priv_dir;
644	static unsigned int counter = 0;
645	size_t len;
646	struct sockaddr_un addr;
647
648	wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
649	if (param == NULL)
650		pos = NULL;
651	else
652		pos = os_strstr(param, "own_dir=");
653	if (pos) {
654		char *end;
655		own_dir = os_strdup(pos + 8);
656		if (own_dir == NULL)
657			return -1;
658		end = os_strchr(own_dir, ' ');
659		if (end)
660			*end = '\0';
661	} else {
662		own_dir = os_strdup("/tmp");
663		if (own_dir == NULL)
664			return -1;
665	}
666
667	if (param == NULL)
668		pos = NULL;
669	else
670		pos = os_strstr(param, "priv_dir=");
671	if (pos) {
672		char *end;
673		priv_dir = os_strdup(pos + 9);
674		if (priv_dir == NULL) {
675			os_free(own_dir);
676			return -1;
677		}
678		end = os_strchr(priv_dir, ' ');
679		if (end)
680			*end = '\0';
681	} else {
682		priv_dir = os_strdup("/var/run/wpa_priv");
683		if (priv_dir == NULL) {
684			os_free(own_dir);
685			return -1;
686		}
687	}
688
689	len = os_strlen(own_dir) + 50;
690	drv->own_socket_path = os_malloc(len);
691	if (drv->own_socket_path == NULL) {
692		os_free(priv_dir);
693		os_free(own_dir);
694		return -1;
695	}
696	os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
697		    own_dir, getpid(), counter++);
698
699	len = os_strlen(own_dir) + 50;
700	drv->own_cmd_path = os_malloc(len);
701	if (drv->own_cmd_path == NULL) {
702		os_free(drv->own_socket_path);
703		drv->own_socket_path = NULL;
704		os_free(priv_dir);
705		os_free(own_dir);
706		return -1;
707	}
708	os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
709		    own_dir, getpid(), counter++);
710
711	os_free(own_dir);
712
713	drv->priv_addr.sun_family = AF_UNIX;
714	os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
715		    "%s/%s", priv_dir, drv->ifname);
716	os_free(priv_dir);
717
718	drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
719	if (drv->priv_socket < 0) {
720		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
721		os_free(drv->own_socket_path);
722		drv->own_socket_path = NULL;
723		return -1;
724	}
725
726	os_memset(&addr, 0, sizeof(addr));
727	addr.sun_family = AF_UNIX;
728	os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
729	if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
730	    0) {
731		wpa_printf(MSG_ERROR,
732			   "privsep-set-params priv-sock: bind(PF_UNIX): %s",
733			   strerror(errno));
734		close(drv->priv_socket);
735		drv->priv_socket = -1;
736		unlink(drv->own_socket_path);
737		os_free(drv->own_socket_path);
738		drv->own_socket_path = NULL;
739		return -1;
740	}
741
742	eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
743				 drv, NULL);
744
745	drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
746	if (drv->cmd_socket < 0) {
747		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
748		os_free(drv->own_cmd_path);
749		drv->own_cmd_path = NULL;
750		return -1;
751	}
752
753	os_memset(&addr, 0, sizeof(addr));
754	addr.sun_family = AF_UNIX;
755	os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
756	if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
757	{
758		wpa_printf(MSG_ERROR,
759			   "privsep-set-params cmd-sock: bind(PF_UNIX): %s",
760			   strerror(errno));
761		close(drv->cmd_socket);
762		drv->cmd_socket = -1;
763		unlink(drv->own_cmd_path);
764		os_free(drv->own_cmd_path);
765		drv->own_cmd_path = NULL;
766		return -1;
767	}
768
769	if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
770		wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
771		return -1;
772	}
773
774	return 0;
775}
776
777
778static int wpa_driver_privsep_get_capa(void *priv,
779				       struct wpa_driver_capa *capa)
780{
781	struct wpa_driver_privsep_data *drv = priv;
782	int res;
783	size_t len = sizeof(*capa);
784
785	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
786	if (res < 0 || len != sizeof(*capa))
787		return -1;
788	/* For now, no support for passing extended_capa pointers */
789	capa->extended_capa = NULL;
790	capa->extended_capa_mask = NULL;
791	capa->extended_capa_len = 0;
792	return 0;
793}
794
795
796static const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
797{
798	struct wpa_driver_privsep_data *drv = priv;
799	wpa_printf(MSG_DEBUG, "%s", __func__);
800	return drv->own_addr;
801}
802
803
804static int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
805{
806	struct wpa_driver_privsep_data *drv = priv;
807	wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
808	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
809			    os_strlen(alpha2), NULL, NULL);
810}
811
812
813struct wpa_driver_ops wpa_driver_privsep_ops = {
814	"privsep",
815	"wpa_supplicant privilege separated driver",
816	.get_bssid = wpa_driver_privsep_get_bssid,
817	.get_ssid = wpa_driver_privsep_get_ssid,
818	.set_key = wpa_driver_privsep_set_key,
819	.init = wpa_driver_privsep_init,
820	.deinit = wpa_driver_privsep_deinit,
821	.set_param = wpa_driver_privsep_set_param,
822	.scan2 = wpa_driver_privsep_scan,
823	.deauthenticate = wpa_driver_privsep_deauthenticate,
824	.authenticate = wpa_driver_privsep_authenticate,
825	.associate = wpa_driver_privsep_associate,
826	.get_capa = wpa_driver_privsep_get_capa,
827	.get_mac_addr = wpa_driver_privsep_get_mac_addr,
828	.get_scan_results2 = wpa_driver_privsep_get_scan_results2,
829	.set_country = wpa_driver_privsep_set_country,
830};
831
832
833const struct wpa_driver_ops *const wpa_drivers[] =
834{
835	&wpa_driver_privsep_ops,
836	NULL
837};
838