wps.c revision c5ec7f57ead87efa365800228aa0b09a12d9e6c4
18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/*
28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Wi-Fi Protected Setup
38d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license.
6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details.
78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "includes.h"
108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "common.h"
128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "crypto/dh_group5.h"
138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "common/ieee802_11_defs.h"
148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "wps_i.h"
158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "wps_dev_attr.h"
168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef CONFIG_WPS_TESTING
198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_version_number = 0x20;
208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_testing_dummy_cred = 0;
218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* CONFIG_WPS_TESTING */
228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_init - Initialize WPS Registration protocol data
268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @cfg: WPS configuration
278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: Pointer to allocated data or %NULL on failure
288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function is used to initialize WPS data for a registration protocol
308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * instance (i.e., each run of registration protocol as a Registrar of
318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Enrollee. The caller is responsible for freeing this data after the
328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * registration run has been completed by calling wps_deinit().
338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wps_data * wps_init(const struct wps_config *cfg)
358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_data *data = os_zalloc(sizeof(*data));
378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (data == NULL)
388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	data->wps = cfg->wps;
408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	data->registrar = cfg->registrar;
418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->registrar) {
428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->uuid_r, cfg->wps->uuid, WPS_UUID_LEN);
438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	} else {
448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->mac_addr_e, cfg->wps->dev.mac_addr, ETH_ALEN);
458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->uuid_e, cfg->wps->uuid, WPS_UUID_LEN);
468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->pin) {
488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		data->dev_pw_id = data->wps->oob_dev_pw_id == 0 ?
498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			cfg->dev_pw_id : data->wps->oob_dev_pw_id;
508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		data->dev_password = os_malloc(cfg->pin_len);
518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (data->dev_password == NULL) {
528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			os_free(data);
538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return NULL;
548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		}
558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->dev_password, cfg->pin, cfg->pin_len);
568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		data->dev_password_len = cfg->pin_len;
578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	data->pbc = cfg->pbc;
608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->pbc) {
618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		/* Use special PIN '00000000' for PBC */
628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		data->dev_pw_id = DEV_PW_PUSHBUTTON;
638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_free(data->dev_password);
641f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt		data->dev_password = (u8 *) os_strdup("00000000");
658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (data->dev_password == NULL) {
668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			os_free(data);
678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return NULL;
688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		}
698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		data->dev_password_len = 8;
708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	data->state = data->registrar ? RECV_M1 : SEND_M1;
738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->assoc_wps_ie) {
758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		struct wps_parse_attr attr;
768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpa_hexdump_buf(MSG_DEBUG, "WPS: WPS IE from (Re)AssocReq",
778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				cfg->assoc_wps_ie);
788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (wps_parse_msg(cfg->assoc_wps_ie, &attr) < 0) {
798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			wpa_printf(MSG_DEBUG, "WPS: Failed to parse WPS IE "
808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				   "from (Re)AssocReq");
818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		} else if (attr.request_type == NULL) {
828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			wpa_printf(MSG_DEBUG, "WPS: No Request Type attribute "
838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				   "in (Re)AssocReq WPS IE");
848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		} else {
858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			wpa_printf(MSG_DEBUG, "WPS: Request Type (from WPS IE "
868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				   "in (Re)AssocReq WPS IE): %d",
878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				   *attr.request_type);
888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			data->request_type = *attr.request_type;
898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		}
908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->new_ap_settings) {
938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		data->new_ap_settings =
948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			os_malloc(sizeof(*data->new_ap_settings));
958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (data->new_ap_settings == NULL) {
968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			os_free(data);
978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return NULL;
988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		}
998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->new_ap_settings, cfg->new_ap_settings,
1008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			  sizeof(*data->new_ap_settings));
1018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
1028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->peer_addr)
1048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->peer_dev.mac_addr, cfg->peer_addr, ETH_ALEN);
1058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (cfg->p2p_dev_addr)
1068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(data->p2p_dev_addr, cfg->p2p_dev_addr, ETH_ALEN);
1078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	data->use_psk_key = cfg->use_psk_key;
10987fd279308af3f806848c8f2ab65ef18c6ac4c30Jouni Malinen	data->pbc_in_m1 = cfg->pbc_in_m1;
1108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return data;
1128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
1138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
1168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_deinit - Deinitialize WPS Registration protocol data
1178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @data: WPS Registration protocol data from wps_init()
1188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
1198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid wps_deinit(struct wps_data *data)
1208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
1218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (data->wps_pin_revealed) {
1228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpa_printf(MSG_DEBUG, "WPS: Full PIN information revealed and "
1238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			   "negotiation failed");
1248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (data->registrar)
1258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			wps_registrar_invalidate_pin(data->wps->registrar,
1268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt						     data->uuid_e);
1278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	} else if (data->registrar)
1288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wps_registrar_unlock_pin(data->wps->registrar, data->uuid_e);
1298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_free(data->dh_privkey);
1318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_free(data->dh_pubkey_e);
1328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_free(data->dh_pubkey_r);
1338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_free(data->last_msg);
1348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	os_free(data->dev_password);
1358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	os_free(data->new_psk);
1368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wps_device_data_free(&data->peer_dev);
1378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	os_free(data->new_ap_settings);
1388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	dh5_free(data->dh_ctx);
1398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	os_free(data);
1408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
1418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
1448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_process_msg - Process a WPS message
1458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @wps: WPS Registration protocol data from wps_init()
1468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @op_code: Message OP Code
1478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @msg: Message data
1488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: Processing result
1498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
1508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function is used to process WPS messages with OP Codes WSC_ACK,
1518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * WSC_NACK, WSC_MSG, and WSC_Done. The caller (e.g., EAP server/peer) is
1528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * responsible for reassembling the messages before calling this function.
1538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Response to this message is built by calling wps_get_msg().
1548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
1558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtenum wps_process_res wps_process_msg(struct wps_data *wps,
1568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				     enum wsc_op_code op_code,
1578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				     const struct wpabuf *msg)
1588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
1598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps->registrar)
1608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return wps_registrar_process_msg(wps, op_code, msg);
1618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	else
1628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return wps_enrollee_process_msg(wps, op_code, msg);
1638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
1648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
1678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_get_msg - Build a WPS message
1688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @wps: WPS Registration protocol data from wps_init()
1698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @op_code: Buffer for returning message OP Code
1708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: The generated WPS message or %NULL on failure
1718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
1728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function is used to build a response to a message processed by calling
1738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_process_msg(). The caller is responsible for freeing the buffer.
1748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
1758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wpabuf * wps_get_msg(struct wps_data *wps, enum wsc_op_code *op_code)
1768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
1778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps->registrar)
1788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return wps_registrar_get_msg(wps, op_code);
1798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	else
1808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return wps_enrollee_get_msg(wps, op_code);
1818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
1828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
1858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_is_selected_pbc_registrar - Check whether WPS IE indicates active PBC
1868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @msg: WPS IE contents from Beacon or Probe Response frame
1878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 1 if PBC Registrar is active, 0 if not
1888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
1898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_is_selected_pbc_registrar(const struct wpabuf *msg)
1908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
1918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_parse_attr attr;
1928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	/*
1948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * In theory, this could also verify that attr.sel_reg_config_methods
1958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * includes WPS_CONFIG_PUSHBUTTON, but some deployed AP implementations
1968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * do not set Selected Registrar Config Methods attribute properly, so
1978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * it is safer to just use Device Password ID here.
1988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 */
1998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_parse_msg(msg, &attr) < 0 ||
2018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    !attr.selected_registrar || *attr.selected_registrar == 0 ||
2028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    !attr.dev_password_id ||
2038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    WPA_GET_BE16(attr.dev_password_id) != DEV_PW_PUSHBUTTON)
2048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef CONFIG_WPS_STRICT
2078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (!attr.sel_reg_config_methods ||
2088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    !(WPA_GET_BE16(attr.sel_reg_config_methods) &
2098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	      WPS_CONFIG_PUSHBUTTON))
2108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* CONFIG_WPS_STRICT */
2128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return 1;
2148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
2158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int is_selected_pin_registrar(struct wps_parse_attr *attr)
2188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
2198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	/*
2208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * In theory, this could also verify that attr.sel_reg_config_methods
2218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * includes WPS_CONFIG_LABEL, WPS_CONFIG_DISPLAY, or WPS_CONFIG_KEYPAD,
2228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * but some deployed AP implementations do not set Selected Registrar
2238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * Config Methods attribute properly, so it is safer to just use
2248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * Device Password ID here.
2258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 */
2268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (!attr->selected_registrar || *attr->selected_registrar == 0)
2288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr->dev_password_id != NULL &&
2318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    WPA_GET_BE16(attr->dev_password_id) == DEV_PW_PUSHBUTTON)
2328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef CONFIG_WPS_STRICT
2358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (!attr->sel_reg_config_methods ||
2368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    !(WPA_GET_BE16(attr->sel_reg_config_methods) &
2378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	      (WPS_CONFIG_LABEL | WPS_CONFIG_DISPLAY | WPS_CONFIG_KEYPAD)))
2388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* CONFIG_WPS_STRICT */
2408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return 1;
2428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
2438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
2468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_is_selected_pin_registrar - Check whether WPS IE indicates active PIN
2478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @msg: WPS IE contents from Beacon or Probe Response frame
2488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 1 if PIN Registrar is active, 0 if not
2498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
2508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_is_selected_pin_registrar(const struct wpabuf *msg)
2518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
2528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_parse_attr attr;
2538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_parse_msg(msg, &attr) < 0)
2558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return is_selected_pin_registrar(&attr);
2588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
2598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
2628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_is_addr_authorized - Check whether WPS IE authorizes MAC address
2638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @msg: WPS IE contents from Beacon or Probe Response frame
2648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @addr: MAC address to search for
2658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ver1_compat: Whether to use version 1 compatibility mode
2668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 1 if address is authorized, 0 if not
2678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
2688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_is_addr_authorized(const struct wpabuf *msg, const u8 *addr,
2698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			   int ver1_compat)
2708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
2718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_parse_attr attr;
2728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	unsigned int i;
2738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	const u8 *pos;
2748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	const u8 bcast[ETH_ALEN] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
2758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_parse_msg(msg, &attr) < 0)
2778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (!attr.version2 && ver1_compat) {
2808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		/*
2818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		 * Version 1.0 AP - AuthorizedMACs not used, so revert back to
2828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		 * old mechanism of using SelectedRegistrar.
2838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		 */
2848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return is_selected_pin_registrar(&attr);
2858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
2868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (!attr.authorized_macs)
2888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 0;
2898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	pos = attr.authorized_macs;
2918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	for (i = 0; i < attr.authorized_macs_len / ETH_ALEN; i++) {
2928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (os_memcmp(pos, addr, ETH_ALEN) == 0 ||
2938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		    os_memcmp(pos, bcast, ETH_ALEN) == 0)
2948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return 1;
2958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ETH_ALEN;
2968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
2978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return 0;
2998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
3008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
3038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_ap_priority_compar - Prioritize WPS IE from two APs
3048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @wps_a: WPS IE contents from Beacon or Probe Response frame
3058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @wps_b: WPS IE contents from Beacon or Probe Response frame
3068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 1 if wps_b is considered more likely selection for WPS
3078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * provisioning, -1 if wps_a is considered more like, or 0 if no preference
3088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
3098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_ap_priority_compar(const struct wpabuf *wps_a,
3108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			   const struct wpabuf *wps_b)
3118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
3128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_parse_attr attr_a, attr_b;
3138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int sel_a, sel_b;
3148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_a == NULL || wps_parse_msg(wps_a, &attr_a) < 0)
3168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 1;
3178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_b == NULL || wps_parse_msg(wps_b, &attr_b) < 0)
3188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return -1;
3198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	sel_a = attr_a.selected_registrar && *attr_a.selected_registrar != 0;
3218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	sel_b = attr_b.selected_registrar && *attr_b.selected_registrar != 0;
3228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (sel_a && !sel_b)
3248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return -1;
3258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (!sel_a && sel_b)
3268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return 1;
3278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return 0;
3298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
3308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
3338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_get_uuid_e - Get UUID-E from WPS IE
3348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @msg: WPS IE contents from Beacon or Probe Response frame
3358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: Pointer to UUID-E or %NULL if not included
3368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
3378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * The returned pointer is to the msg contents and it remains valid only as
3388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * long as the msg buffer is valid.
3398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
3408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtconst u8 * wps_get_uuid_e(const struct wpabuf *msg)
3418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
3428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_parse_attr attr;
3438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_parse_msg(msg, &attr) < 0)
3458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
3468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return attr.uuid_e;
3478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
3488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
3511f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt * wps_is_20 - Check whether WPS attributes claim support for WPS 2.0
3521f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt */
3531f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidtint wps_is_20(const struct wpabuf *msg)
3541f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt{
3551f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt	struct wps_parse_attr attr;
3561f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt
3571f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt	if (msg == NULL || wps_parse_msg(msg, &attr) < 0)
3581f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt		return 0;
3591f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt	return attr.version2 != NULL;
3601f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt}
3611f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt
3621f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt
3631f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt/**
3648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_build_assoc_req_ie - Build WPS IE for (Re)Association Request
3658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @req_type: Value for Request Type attribute
3668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: WPS IE or %NULL on failure
3678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
3688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * The caller is responsible for freeing the buffer.
3698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
3708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wpabuf * wps_build_assoc_req_ie(enum wps_request_type req_type)
3718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
3728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *ie;
3738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 *len;
3748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpa_printf(MSG_DEBUG, "WPS: Building WPS IE for (Re)Association "
3768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		   "Request");
3778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	ie = wpabuf_alloc(100);
3788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (ie == NULL)
3798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
3808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_put_u8(ie, WLAN_EID_VENDOR_SPECIFIC);
3828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	len = wpabuf_put(ie, 1);
3838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_put_be32(ie, WPS_DEV_OUI_WFA);
3848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_build_version(ie) ||
3868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_req_type(ie, req_type) ||
3878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_wfa_ext(ie, 0, NULL, 0)) {
3888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpabuf_free(ie);
3898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
3908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
3918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	*len = wpabuf_len(ie) - 2;
3938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return ie;
3958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
3968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
3988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
3998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_build_assoc_resp_ie - Build WPS IE for (Re)Association Response
4008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: WPS IE or %NULL on failure
4018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
4028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * The caller is responsible for freeing the buffer.
4038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
4048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wpabuf * wps_build_assoc_resp_ie(void)
4058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
4068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *ie;
4078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 *len;
4088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpa_printf(MSG_DEBUG, "WPS: Building WPS IE for (Re)Association "
4108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		   "Response");
4118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	ie = wpabuf_alloc(100);
4128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (ie == NULL)
4138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
4148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_put_u8(ie, WLAN_EID_VENDOR_SPECIFIC);
4168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	len = wpabuf_put(ie, 1);
4178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpabuf_put_be32(ie, WPS_DEV_OUI_WFA);
4188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_build_version(ie) ||
4208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_resp_type(ie, WPS_RESP_AP) ||
4218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_wfa_ext(ie, 0, NULL, 0)) {
4228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpabuf_free(ie);
4238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
4248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
4258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	*len = wpabuf_len(ie) - 2;
4278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return ie;
4298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
4308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
4338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * wps_build_probe_req_ie - Build WPS IE for Probe Request
4348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @pbc: Whether searching for PBC mode APs
4358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @dev: Device attributes
4368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @uuid: Own UUID
4378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @req_type: Value for Request Type attribute
4388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @num_req_dev_types: Number of requested device types
4398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @req_dev_types: Requested device types (8 * num_req_dev_types octets) or
4408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *	%NULL if none
4418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: WPS IE or %NULL on failure
4428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
4438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * The caller is responsible for freeing the buffer.
4448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
4458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wpabuf * wps_build_probe_req_ie(int pbc, struct wps_device_data *dev,
4468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				       const u8 *uuid,
4478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				       enum wps_request_type req_type,
4488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				       unsigned int num_req_dev_types,
4498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				       const u8 *req_dev_types)
4508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
4518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *ie;
4528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	wpa_printf(MSG_DEBUG, "WPS: Building WPS IE for Probe Request");
4548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	ie = wpabuf_alloc(500);
4568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (ie == NULL)
4578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
4588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_build_version(ie) ||
4608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_req_type(ie, req_type) ||
4611f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt	    wps_build_config_methods(ie, dev->config_methods) ||
4628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_uuid_e(ie, uuid) ||
4638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_primary_dev_type(dev, ie) ||
4648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_rf_bands(dev, ie) ||
4658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_assoc_state(NULL, ie) ||
4668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_config_error(ie, WPS_CFG_NO_ERROR) ||
4678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_dev_password_id(ie, pbc ? DEV_PW_PUSHBUTTON :
4688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				      DEV_PW_DEFAULT) ||
4698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef CONFIG_WPS2
4708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_manufacturer(dev, ie) ||
4718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_model_name(dev, ie) ||
4728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_model_number(dev, ie) ||
4738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_dev_name(dev, ie) ||
4748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_wfa_ext(ie, req_type == WPS_REQ_ENROLLEE, NULL, 0) ||
4758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* CONFIG_WPS2 */
4768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_req_dev_type(dev, ie, num_req_dev_types, req_dev_types)
4778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    ||
4788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	    wps_build_secondary_dev_type(dev, ie)
4798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		) {
4808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpabuf_free(ie);
4818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
4828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
4838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifndef CONFIG_WPS2
4858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (dev->p2p && wps_build_dev_name(dev, ie)) {
4868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpabuf_free(ie);
4878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return NULL;
4888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
4898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* CONFIG_WPS2 */
4908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return wps_ie_encapsulate(ie);
4928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
4938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
4958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid wps_free_pending_msgs(struct upnp_pending_message *msgs)
4968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
4978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct upnp_pending_message *p, *prev;
4988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	p = msgs;
4998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	while (p) {
5008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		prev = p;
5018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		p = p->next;
5028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		wpabuf_free(prev->msg);
5038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_free(prev);
5048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
5068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint wps_attr_text(struct wpabuf *data, char *buf, char *end)
5098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
5108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wps_parse_attr attr;
5118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	char *pos = buf;
5128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int ret;
5138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (wps_parse_msg(data, &attr) < 0)
5158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return -1;
5168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.wps_state) {
5188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (*attr.wps_state == WPS_STATE_NOT_CONFIGURED)
5198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			ret = os_snprintf(pos, end - pos,
5208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt					  "wps_state=unconfigured\n");
5218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		else if (*attr.wps_state == WPS_STATE_CONFIGURED)
5228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			ret = os_snprintf(pos, end - pos,
5238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt					  "wps_state=configured\n");
5248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		else
5258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			ret = 0;
5268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.ap_setup_locked && *attr.ap_setup_locked) {
5328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos,
5338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "wps_ap_setup_locked=1\n");
5348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.selected_registrar && *attr.selected_registrar) {
5408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos,
5418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "wps_selected_registrar=1\n");
5428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.dev_password_id) {
5488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos,
5498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "wps_device_password_id=%u\n",
5508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  WPA_GET_BE16(attr.dev_password_id));
5518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.sel_reg_config_methods) {
5578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos,
5588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "wps_selected_registrar_config_methods="
5598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "0x%04x\n",
5608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  WPA_GET_BE16(attr.sel_reg_config_methods));
5618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.primary_dev_type) {
5678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		char devtype[WPS_DEV_TYPE_BUFSIZE];
5688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos,
5698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "wps_primary_device_type=%s\n",
5708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  wps_dev_type_bin2str(attr.primary_dev_type,
5718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt						       devtype,
5728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt						       sizeof(devtype)));
5738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.dev_name) {
5798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		char *str = os_malloc(attr.dev_name_len + 1);
5808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		size_t i;
5818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (str == NULL)
5828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		for (i = 0; i < attr.dev_name_len; i++) {
5848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			if (attr.dev_name[i] < 32)
5858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				str[i] = '_';
5868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			else
5878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				str[i] = attr.dev_name[i];
5888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		}
5898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		str[i] = '\0';
5908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos, "wps_device_name=%s\n", str);
5918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_free(str);
5928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
5938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
5948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
5958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
5968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
5978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (attr.config_methods) {
5988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		ret = os_snprintf(pos, end - pos,
5998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  "wps_config_methods=0x%04x\n",
6008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  WPA_GET_BE16(attr.config_methods));
6018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (ret < 0 || ret >= end - pos)
6028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return pos - buf;
6038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += ret;
6048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
6058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
6068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return pos - buf;
6078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
608