1/*
2 * hostapd / Station table
3 * Copyright (c) 2002-2017, Jouni Malinen <j@w1.fi>
4 *
5 * This software may be distributed under the terms of the BSD license.
6 * See README for more details.
7 */
8
9#ifndef STA_INFO_H
10#define STA_INFO_H
11
12#ifdef CONFIG_MESH
13/* needed for mesh_plink_state enum */
14#include "common/defs.h"
15#endif /* CONFIG_MESH */
16
17#include "list.h"
18#include "vlan.h"
19#include "common/wpa_common.h"
20#include "common/ieee802_11_defs.h"
21
22/* STA flags */
23#define WLAN_STA_AUTH BIT(0)
24#define WLAN_STA_ASSOC BIT(1)
25#define WLAN_STA_AUTHORIZED BIT(5)
26#define WLAN_STA_PENDING_POLL BIT(6) /* pending activity poll not ACKed */
27#define WLAN_STA_SHORT_PREAMBLE BIT(7)
28#define WLAN_STA_PREAUTH BIT(8)
29#define WLAN_STA_WMM BIT(9)
30#define WLAN_STA_MFP BIT(10)
31#define WLAN_STA_HT BIT(11)
32#define WLAN_STA_WPS BIT(12)
33#define WLAN_STA_MAYBE_WPS BIT(13)
34#define WLAN_STA_WDS BIT(14)
35#define WLAN_STA_ASSOC_REQ_OK BIT(15)
36#define WLAN_STA_WPS2 BIT(16)
37#define WLAN_STA_GAS BIT(17)
38#define WLAN_STA_VHT BIT(18)
39#define WLAN_STA_WNM_SLEEP_MODE BIT(19)
40#define WLAN_STA_VHT_OPMODE_ENABLED BIT(20)
41#define WLAN_STA_VENDOR_VHT BIT(21)
42#define WLAN_STA_PENDING_FILS_ERP BIT(22)
43#define WLAN_STA_PENDING_DISASSOC_CB BIT(29)
44#define WLAN_STA_PENDING_DEAUTH_CB BIT(30)
45#define WLAN_STA_NONERP BIT(31)
46
47/* Maximum number of supported rates (from both Supported Rates and Extended
48 * Supported Rates IEs). */
49#define WLAN_SUPP_RATES_MAX 32
50
51struct hostapd_data;
52
53struct mbo_non_pref_chan_info {
54	struct mbo_non_pref_chan_info *next;
55	u8 op_class;
56	u8 pref;
57	u8 reason_code;
58	u8 num_channels;
59	u8 channels[];
60};
61
62struct pending_eapol_rx {
63	struct wpabuf *buf;
64	struct os_reltime rx_time;
65};
66
67struct sta_info {
68	struct sta_info *next; /* next entry in sta list */
69	struct sta_info *hnext; /* next entry in hash table list */
70	u8 addr[6];
71	be32 ipaddr;
72	struct dl_list ip6addr; /* list head for struct ip6addr */
73	u16 aid; /* STA's unique AID (1 .. 2007) or 0 if not yet assigned */
74	u32 flags; /* Bitfield of WLAN_STA_* */
75	u16 capability;
76	u16 listen_interval; /* or beacon_int for APs */
77	u8 supported_rates[WLAN_SUPP_RATES_MAX];
78	int supported_rates_len;
79	u8 qosinfo; /* Valid when WLAN_STA_WMM is set */
80
81#ifdef CONFIG_MESH
82	enum mesh_plink_state plink_state;
83	u16 peer_lid;
84	u16 my_lid;
85	u16 peer_aid;
86	u16 mpm_close_reason;
87	int mpm_retries;
88	u8 my_nonce[WPA_NONCE_LEN];
89	u8 peer_nonce[WPA_NONCE_LEN];
90	u8 aek[32];	/* SHA256 digest length */
91	u8 mtk[WPA_TK_MAX_LEN];
92	size_t mtk_len;
93	u8 mgtk_rsc[6];
94	u8 mgtk_key_id;
95	u8 mgtk[WPA_TK_MAX_LEN];
96	size_t mgtk_len;
97	u8 igtk_rsc[6];
98	u8 igtk[WPA_TK_MAX_LEN];
99	size_t igtk_len;
100	u16 igtk_key_id;
101	u8 sae_auth_retry;
102#endif /* CONFIG_MESH */
103
104	unsigned int nonerp_set:1;
105	unsigned int no_short_slot_time_set:1;
106	unsigned int no_short_preamble_set:1;
107	unsigned int no_ht_gf_set:1;
108	unsigned int no_ht_set:1;
109	unsigned int ht40_intolerant_set:1;
110	unsigned int ht_20mhz_set:1;
111	unsigned int no_p2p_set:1;
112	unsigned int qos_map_enabled:1;
113	unsigned int remediation:1;
114	unsigned int hs20_deauth_requested:1;
115	unsigned int session_timeout_set:1;
116	unsigned int radius_das_match:1;
117	unsigned int ecsa_supported:1;
118	unsigned int added_unassoc:1;
119	unsigned int pending_wds_enable:1;
120
121	u16 auth_alg;
122
123	enum {
124		STA_NULLFUNC = 0, STA_DISASSOC, STA_DEAUTH, STA_REMOVE,
125		STA_DISASSOC_FROM_CLI
126	} timeout_next;
127
128	u16 deauth_reason;
129	u16 disassoc_reason;
130
131	/* IEEE 802.1X related data */
132	struct eapol_state_machine *eapol_sm;
133
134	struct pending_eapol_rx *pending_eapol_rx;
135
136	u64 acct_session_id;
137	struct os_reltime acct_session_start;
138	int acct_session_started;
139	int acct_terminate_cause; /* Acct-Terminate-Cause */
140	int acct_interim_interval; /* Acct-Interim-Interval */
141	unsigned int acct_interim_errors;
142
143	/* For extending 32-bit driver counters to 64-bit counters */
144	u32 last_rx_bytes_hi;
145	u32 last_rx_bytes_lo;
146	u32 last_tx_bytes_hi;
147	u32 last_tx_bytes_lo;
148
149	u8 *challenge; /* IEEE 802.11 Shared Key Authentication Challenge */
150
151	struct wpa_state_machine *wpa_sm;
152	struct rsn_preauth_interface *preauth_iface;
153
154	int vlan_id; /* 0: none, >0: VID */
155	struct vlan_description *vlan_desc;
156	int vlan_id_bound; /* updated by ap_sta_bind_vlan() */
157	 /* PSKs from RADIUS authentication server */
158	struct hostapd_sta_wpa_psk_short *psk;
159
160	char *identity; /* User-Name from RADIUS */
161	char *radius_cui; /* Chargeable-User-Identity from RADIUS */
162
163	struct ieee80211_ht_capabilities *ht_capabilities;
164	struct ieee80211_vht_capabilities *vht_capabilities;
165	u8 vht_opmode;
166
167#ifdef CONFIG_IEEE80211W
168	int sa_query_count; /* number of pending SA Query requests;
169			     * 0 = no SA Query in progress */
170	int sa_query_timed_out;
171	u8 *sa_query_trans_id; /* buffer of WLAN_SA_QUERY_TR_ID_LEN *
172				* sa_query_count octets of pending SA Query
173				* transaction identifiers */
174	struct os_reltime sa_query_start;
175#endif /* CONFIG_IEEE80211W */
176
177#if defined(CONFIG_INTERWORKING) || defined(CONFIG_DPP)
178#define GAS_DIALOG_MAX 8 /* Max concurrent dialog number */
179	struct gas_dialog_info *gas_dialog;
180	u8 gas_dialog_next;
181#endif /* CONFIG_INTERWORKING || CONFIG_DPP */
182
183	struct wpabuf *wps_ie; /* WPS IE from (Re)Association Request */
184	struct wpabuf *p2p_ie; /* P2P IE from (Re)Association Request */
185	struct wpabuf *hs20_ie; /* HS 2.0 IE from (Re)Association Request */
186	u8 remediation_method;
187	char *remediation_url; /* HS 2.0 Subscription Remediation Server URL */
188	struct wpabuf *hs20_deauth_req;
189	char *hs20_session_info_url;
190	int hs20_disassoc_timer;
191#ifdef CONFIG_FST
192	struct wpabuf *mb_ies; /* MB IEs from (Re)Association Request */
193#endif /* CONFIG_FST */
194
195	struct os_reltime connected_time;
196
197#ifdef CONFIG_SAE
198	struct sae_data *sae;
199	unsigned int mesh_sae_pmksa_caching:1;
200#endif /* CONFIG_SAE */
201
202	u32 session_timeout; /* valid only if session_timeout_set == 1 */
203
204	/* Last Authentication/(Re)Association Request/Action frame sequence
205	 * control */
206	u16 last_seq_ctrl;
207	/* Last Authentication/(Re)Association Request/Action frame subtype */
208	u8 last_subtype;
209
210#ifdef CONFIG_MBO
211	u8 cell_capa; /* 0 = unknown (not an MBO STA); otherwise,
212		       * enum mbo_cellular_capa values */
213	struct mbo_non_pref_chan_info *non_pref_chan;
214#endif /* CONFIG_MBO */
215
216	u8 *supp_op_classes; /* Supported Operating Classes element, if
217			      * received, starting from the Length field */
218
219	u8 rrm_enabled_capa[5];
220
221#ifdef CONFIG_TAXONOMY
222	struct wpabuf *probe_ie_taxonomy;
223	struct wpabuf *assoc_ie_taxonomy;
224#endif /* CONFIG_TAXONOMY */
225
226#ifdef CONFIG_FILS
227	u8 fils_snonce[FILS_NONCE_LEN];
228	u8 fils_session[FILS_SESSION_LEN];
229	u8 fils_erp_pmkid[PMKID_LEN];
230	u8 *fils_pending_assoc_req;
231	size_t fils_pending_assoc_req_len;
232	unsigned int fils_pending_assoc_is_reassoc:1;
233	unsigned int fils_dhcp_rapid_commit_proxy:1;
234	unsigned int fils_erp_pmkid_set:1;
235	unsigned int fils_drv_assoc_finish:1;
236	struct wpabuf *fils_hlp_resp;
237	struct wpabuf *hlp_dhcp_discover;
238	void (*fils_pending_cb)(struct hostapd_data *hapd, struct sta_info *sta,
239				u16 resp, struct wpabuf *data, int pub);
240#ifdef CONFIG_FILS_SK_PFS
241	struct crypto_ecdh *fils_ecdh;
242#endif /* CONFIG_FILS_SK_PFS */
243	struct wpabuf *fils_dh_ss;
244	struct wpabuf *fils_g_sta;
245#endif /* CONFIG_FILS */
246
247#ifdef CONFIG_OWE
248	u8 *owe_pmk;
249	size_t owe_pmk_len;
250	struct crypto_ecdh *owe_ecdh;
251	u16 owe_group;
252#endif /* CONFIG_OWE */
253
254#ifdef CONFIG_TESTING_OPTIONS
255	enum wpa_alg last_tk_alg;
256	int last_tk_key_idx;
257	u8 last_tk[WPA_TK_MAX_LEN];
258	size_t last_tk_len;
259#endif /* CONFIG_TESTING_OPTIONS */
260};
261
262
263/* Default value for maximum station inactivity. After AP_MAX_INACTIVITY has
264 * passed since last received frame from the station, a nullfunc data frame is
265 * sent to the station. If this frame is not acknowledged and no other frames
266 * have been received, the station will be disassociated after
267 * AP_DISASSOC_DELAY seconds. Similarly, the station will be deauthenticated
268 * after AP_DEAUTH_DELAY seconds has passed after disassociation. */
269#define AP_MAX_INACTIVITY (5 * 60)
270#define AP_DISASSOC_DELAY (3)
271#define AP_DEAUTH_DELAY (1)
272/* Number of seconds to keep STA entry with Authenticated flag after it has
273 * been disassociated. */
274#define AP_MAX_INACTIVITY_AFTER_DISASSOC (1 * 30)
275/* Number of seconds to keep STA entry after it has been deauthenticated. */
276#define AP_MAX_INACTIVITY_AFTER_DEAUTH (1 * 5)
277
278
279int ap_for_each_sta(struct hostapd_data *hapd,
280		    int (*cb)(struct hostapd_data *hapd, struct sta_info *sta,
281			      void *ctx),
282		    void *ctx);
283struct sta_info * ap_get_sta(struct hostapd_data *hapd, const u8 *sta);
284struct sta_info * ap_get_sta_p2p(struct hostapd_data *hapd, const u8 *addr);
285void ap_sta_hash_add(struct hostapd_data *hapd, struct sta_info *sta);
286void ap_free_sta(struct hostapd_data *hapd, struct sta_info *sta);
287void ap_sta_ip6addr_del(struct hostapd_data *hapd, struct sta_info *sta);
288void hostapd_free_stas(struct hostapd_data *hapd);
289void ap_handle_timer(void *eloop_ctx, void *timeout_ctx);
290void ap_sta_replenish_timeout(struct hostapd_data *hapd, struct sta_info *sta,
291			      u32 session_timeout);
292void ap_sta_session_timeout(struct hostapd_data *hapd, struct sta_info *sta,
293			    u32 session_timeout);
294void ap_sta_no_session_timeout(struct hostapd_data *hapd,
295			       struct sta_info *sta);
296void ap_sta_session_warning_timeout(struct hostapd_data *hapd,
297				    struct sta_info *sta, int warning_time);
298struct sta_info * ap_sta_add(struct hostapd_data *hapd, const u8 *addr);
299void ap_sta_disassociate(struct hostapd_data *hapd, struct sta_info *sta,
300			 u16 reason);
301void ap_sta_deauthenticate(struct hostapd_data *hapd, struct sta_info *sta,
302			   u16 reason);
303#ifdef CONFIG_WPS
304int ap_sta_wps_cancel(struct hostapd_data *hapd,
305		      struct sta_info *sta, void *ctx);
306#endif /* CONFIG_WPS */
307int ap_sta_bind_vlan(struct hostapd_data *hapd, struct sta_info *sta);
308int ap_sta_set_vlan(struct hostapd_data *hapd, struct sta_info *sta,
309		    struct vlan_description *vlan_desc);
310void ap_sta_start_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
311void ap_sta_stop_sa_query(struct hostapd_data *hapd, struct sta_info *sta);
312int ap_check_sa_query_timeout(struct hostapd_data *hapd, struct sta_info *sta);
313void ap_sta_disconnect(struct hostapd_data *hapd, struct sta_info *sta,
314		       const u8 *addr, u16 reason);
315
316void ap_sta_set_authorized(struct hostapd_data *hapd,
317			   struct sta_info *sta, int authorized);
318static inline int ap_sta_is_authorized(struct sta_info *sta)
319{
320	return sta->flags & WLAN_STA_AUTHORIZED;
321}
322
323void ap_sta_deauth_cb(struct hostapd_data *hapd, struct sta_info *sta);
324void ap_sta_disassoc_cb(struct hostapd_data *hapd, struct sta_info *sta);
325void ap_sta_clear_disconnect_timeouts(struct hostapd_data *hapd,
326				      struct sta_info *sta);
327
328int ap_sta_flags_txt(u32 flags, char *buf, size_t buflen);
329void ap_sta_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
330					    struct sta_info *sta);
331int ap_sta_pending_delayed_1x_auth_fail_disconnect(struct hostapd_data *hapd,
332						   struct sta_info *sta);
333
334#endif /* STA_INFO_H */
335