Home | History | Annotate | Download | only in drivers
      1 /*
      2  * WPA Supplicant - privilege separated driver interface
      3  * Copyright (c) 2007-2009, Jouni Malinen <j (at) w1.fi>
      4  *
      5  * This program is free software; you can redistribute it and/or modify
      6  * it under the terms of the GNU General Public License version 2 as
      7  * published by the Free Software Foundation.
      8  *
      9  * Alternatively, this software may be distributed under the terms of BSD
     10  * license.
     11  *
     12  * See README and COPYING for more details.
     13  */
     14 
     15 #include "includes.h"
     16 #include <sys/un.h>
     17 
     18 #include "common.h"
     19 #include "driver.h"
     20 #include "eloop.h"
     21 #include "common/privsep_commands.h"
     22 
     23 
     24 struct wpa_driver_privsep_data {
     25 	void *ctx;
     26 	u8 own_addr[ETH_ALEN];
     27 	int priv_socket;
     28 	char *own_socket_path;
     29 	int cmd_socket;
     30 	char *own_cmd_path;
     31 	struct sockaddr_un priv_addr;
     32 	char ifname[16];
     33 };
     34 
     35 
     36 static int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
     37 {
     38 	int res;
     39 
     40 	res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
     41 		     (struct sockaddr *) &drv->priv_addr,
     42 		     sizeof(drv->priv_addr));
     43 	if (res < 0)
     44 		perror("sendto");
     45 	return res < 0 ? -1 : 0;
     46 }
     47 
     48 
     49 static int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
     50 			const void *data, size_t data_len,
     51 			void *reply, size_t *reply_len)
     52 {
     53 	struct msghdr msg;
     54 	struct iovec io[2];
     55 
     56 	io[0].iov_base = &cmd;
     57 	io[0].iov_len = sizeof(cmd);
     58 	io[1].iov_base = (u8 *) data;
     59 	io[1].iov_len = data_len;
     60 
     61 	os_memset(&msg, 0, sizeof(msg));
     62 	msg.msg_iov = io;
     63 	msg.msg_iovlen = data ? 2 : 1;
     64 	msg.msg_name = &drv->priv_addr;
     65 	msg.msg_namelen = sizeof(drv->priv_addr);
     66 
     67 	if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
     68 		perror("sendmsg(cmd_socket)");
     69 		return -1;
     70 	}
     71 
     72 	if (reply) {
     73 		fd_set rfds;
     74 		struct timeval tv;
     75 		int res;
     76 
     77 		FD_ZERO(&rfds);
     78 		FD_SET(drv->cmd_socket, &rfds);
     79 		tv.tv_sec = 5;
     80 		tv.tv_usec = 0;
     81 		res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
     82 		if (res < 0 && errno != EINTR) {
     83 			perror("select");
     84 			return -1;
     85 		}
     86 
     87 		if (FD_ISSET(drv->cmd_socket, &rfds)) {
     88 			res = recv(drv->cmd_socket, reply, *reply_len, 0);
     89 			if (res < 0) {
     90 				perror("recv");
     91 				return -1;
     92 			}
     93 			*reply_len = res;
     94 		} else {
     95 			wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
     96 				   "for reply (cmd=%d)", cmd);
     97 			return -1;
     98 		}
     99 	}
    100 
    101 	return 0;
    102 }
    103 
    104 
    105 static int wpa_driver_privsep_scan(void *priv,
    106 				   struct wpa_driver_scan_params *params)
    107 {
    108 	struct wpa_driver_privsep_data *drv = priv;
    109 	const u8 *ssid = params->ssids[0].ssid;
    110 	size_t ssid_len = params->ssids[0].ssid_len;
    111 	wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
    112 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, ssid, ssid_len,
    113 			    NULL, NULL);
    114 }
    115 
    116 
    117 static struct wpa_scan_results *
    118 wpa_driver_privsep_get_scan_results2(void *priv)
    119 {
    120 	struct wpa_driver_privsep_data *drv = priv;
    121 	int res, num;
    122 	u8 *buf, *pos, *end;
    123 	size_t reply_len = 60000;
    124 	struct wpa_scan_results *results;
    125 	struct wpa_scan_res *r;
    126 
    127 	buf = os_malloc(reply_len);
    128 	if (buf == NULL)
    129 		return NULL;
    130 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
    131 			   NULL, 0, buf, &reply_len);
    132 	if (res < 0) {
    133 		os_free(buf);
    134 		return NULL;
    135 	}
    136 
    137 	wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
    138 		   (unsigned long) reply_len);
    139 	if (reply_len < sizeof(int)) {
    140 		wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
    141 			   (unsigned long) reply_len);
    142 		os_free(buf);
    143 		return NULL;
    144 	}
    145 
    146 	pos = buf;
    147 	end = buf + reply_len;
    148 	os_memcpy(&num, pos, sizeof(int));
    149 	if (num < 0 || num > 1000) {
    150 		os_free(buf);
    151 		return NULL;
    152 	}
    153 	pos += sizeof(int);
    154 
    155 	results = os_zalloc(sizeof(*results));
    156 	if (results == NULL) {
    157 		os_free(buf);
    158 		return NULL;
    159 	}
    160 
    161 	results->res = os_zalloc(num * sizeof(struct wpa_scan_res *));
    162 	if (results->res == NULL) {
    163 		os_free(results);
    164 		os_free(buf);
    165 		return NULL;
    166 	}
    167 
    168 	while (results->num < (size_t) num && pos + sizeof(int) < end) {
    169 		int len;
    170 		os_memcpy(&len, pos, sizeof(int));
    171 		pos += sizeof(int);
    172 		if (len < 0 || len > 10000 || pos + len > end)
    173 			break;
    174 
    175 		r = os_malloc(len);
    176 		if (r == NULL)
    177 			break;
    178 		os_memcpy(r, pos, len);
    179 		pos += len;
    180 		if (sizeof(*r) + r->ie_len > (size_t) len) {
    181 			os_free(r);
    182 			break;
    183 		}
    184 
    185 		results->res[results->num++] = r;
    186 	}
    187 
    188 	os_free(buf);
    189 	return results;
    190 }
    191 
    192 
    193 static int wpa_driver_privsep_set_key(const char *ifname, void *priv,
    194 				      enum wpa_alg alg, const u8 *addr,
    195 				      int key_idx, int set_tx,
    196 				      const u8 *seq, size_t seq_len,
    197 				      const u8 *key, size_t key_len)
    198 {
    199 	struct wpa_driver_privsep_data *drv = priv;
    200 	struct privsep_cmd_set_key cmd;
    201 
    202 	wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
    203 		   __func__, priv, alg, key_idx, set_tx);
    204 
    205 	os_memset(&cmd, 0, sizeof(cmd));
    206 	cmd.alg = alg;
    207 	if (addr)
    208 		os_memcpy(cmd.addr, addr, ETH_ALEN);
    209 	else
    210 		os_memset(cmd.addr, 0xff, ETH_ALEN);
    211 	cmd.key_idx = key_idx;
    212 	cmd.set_tx = set_tx;
    213 	if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
    214 		os_memcpy(cmd.seq, seq, seq_len);
    215 		cmd.seq_len = seq_len;
    216 	}
    217 	if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
    218 		os_memcpy(cmd.key, key, key_len);
    219 		cmd.key_len = key_len;
    220 	}
    221 
    222 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
    223 			    NULL, NULL);
    224 }
    225 
    226 
    227 static int wpa_driver_privsep_associate(
    228 	void *priv, struct wpa_driver_associate_params *params)
    229 {
    230 	struct wpa_driver_privsep_data *drv = priv;
    231 	struct privsep_cmd_associate *data;
    232 	int res;
    233 	size_t buflen;
    234 
    235 	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
    236 		   "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
    237 		   __func__, priv, params->freq, params->pairwise_suite,
    238 		   params->group_suite, params->key_mgmt_suite,
    239 		   params->auth_alg, params->mode);
    240 
    241 	buflen = sizeof(*data) + params->wpa_ie_len;
    242 	data = os_zalloc(buflen);
    243 	if (data == NULL)
    244 		return -1;
    245 
    246 	if (params->bssid)
    247 		os_memcpy(data->bssid, params->bssid, ETH_ALEN);
    248 	os_memcpy(data->ssid, params->ssid, params->ssid_len);
    249 	data->ssid_len = params->ssid_len;
    250 	data->freq = params->freq;
    251 	data->pairwise_suite = params->pairwise_suite;
    252 	data->group_suite = params->group_suite;
    253 	data->key_mgmt_suite = params->key_mgmt_suite;
    254 	data->auth_alg = params->auth_alg;
    255 	data->mode = params->mode;
    256 	data->wpa_ie_len = params->wpa_ie_len;
    257 	if (params->wpa_ie)
    258 		os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
    259 	/* TODO: add support for other assoc parameters */
    260 
    261 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
    262 			   NULL, NULL);
    263 	os_free(data);
    264 
    265 	return res;
    266 }
    267 
    268 
    269 static int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
    270 {
    271 	struct wpa_driver_privsep_data *drv = priv;
    272 	int res;
    273 	size_t len = ETH_ALEN;
    274 
    275 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
    276 	if (res < 0 || len != ETH_ALEN)
    277 		return -1;
    278 	return 0;
    279 }
    280 
    281 
    282 static int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
    283 {
    284 	struct wpa_driver_privsep_data *drv = priv;
    285 	int res, ssid_len;
    286 	u8 reply[sizeof(int) + 32];
    287 	size_t len = sizeof(reply);
    288 
    289 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
    290 	if (res < 0 || len < sizeof(int))
    291 		return -1;
    292 	os_memcpy(&ssid_len, reply, sizeof(int));
    293 	if (ssid_len < 0 || ssid_len > 32 || sizeof(int) + ssid_len > len) {
    294 		wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
    295 		return -1;
    296 	}
    297 	os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
    298 	return ssid_len;
    299 }
    300 
    301 
    302 static int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
    303 					  int reason_code)
    304 {
    305 	//struct wpa_driver_privsep_data *drv = priv;
    306 	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
    307 		   __func__, MAC2STR(addr), reason_code);
    308 	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
    309 	return 0;
    310 }
    311 
    312 
    313 static int wpa_driver_privsep_disassociate(void *priv, const u8 *addr,
    314 					int reason_code)
    315 {
    316 	//struct wpa_driver_privsep_data *drv = priv;
    317 	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
    318 		   __func__, MAC2STR(addr), reason_code);
    319 	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
    320 	return 0;
    321 }
    322 
    323 
    324 static void wpa_driver_privsep_event_assoc(void *ctx,
    325 					   enum wpa_event_type event,
    326 					   u8 *buf, size_t len)
    327 {
    328 	union wpa_event_data data;
    329 	int inc_data = 0;
    330 	u8 *pos, *end;
    331 	int ie_len;
    332 
    333 	os_memset(&data, 0, sizeof(data));
    334 
    335 	pos = buf;
    336 	end = buf + len;
    337 
    338 	if (end - pos < (int) sizeof(int))
    339 		return;
    340 	os_memcpy(&ie_len, pos, sizeof(int));
    341 	pos += sizeof(int);
    342 	if (ie_len < 0 || ie_len > end - pos)
    343 		return;
    344 	if (ie_len) {
    345 		data.assoc_info.req_ies = pos;
    346 		data.assoc_info.req_ies_len = ie_len;
    347 		pos += ie_len;
    348 		inc_data = 1;
    349 	}
    350 
    351 	wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
    352 }
    353 
    354 
    355 static void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
    356 						      size_t len)
    357 {
    358 	union wpa_event_data data;
    359 	int ievent;
    360 
    361 	if (len < sizeof(int) ||
    362 	    len - sizeof(int) > sizeof(data.interface_status.ifname))
    363 		return;
    364 
    365 	os_memcpy(&ievent, buf, sizeof(int));
    366 
    367 	os_memset(&data, 0, sizeof(data));
    368 	data.interface_status.ievent = ievent;
    369 	os_memcpy(data.interface_status.ifname, buf + sizeof(int),
    370 		  len - sizeof(int));
    371 	wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
    372 }
    373 
    374 
    375 static void wpa_driver_privsep_event_michael_mic_failure(
    376 	void *ctx, u8 *buf, size_t len)
    377 {
    378 	union wpa_event_data data;
    379 
    380 	if (len != sizeof(int))
    381 		return;
    382 
    383 	os_memset(&data, 0, sizeof(data));
    384 	os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
    385 	wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
    386 }
    387 
    388 
    389 static void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
    390 						     size_t len)
    391 {
    392 	union wpa_event_data data;
    393 
    394 	if (len != sizeof(struct pmkid_candidate))
    395 		return;
    396 
    397 	os_memset(&data, 0, sizeof(data));
    398 	os_memcpy(&data.pmkid_candidate, buf, len);
    399 	wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
    400 }
    401 
    402 
    403 static void wpa_driver_privsep_event_stkstart(void *ctx, u8 *buf, size_t len)
    404 {
    405 	union wpa_event_data data;
    406 
    407 	if (len != ETH_ALEN)
    408 		return;
    409 
    410 	os_memset(&data, 0, sizeof(data));
    411 	os_memcpy(data.stkstart.peer, buf, ETH_ALEN);
    412 	wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
    413 }
    414 
    415 
    416 static void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
    417 						 size_t len)
    418 {
    419 	union wpa_event_data data;
    420 
    421 	if (len < sizeof(int) + ETH_ALEN)
    422 		return;
    423 
    424 	os_memset(&data, 0, sizeof(data));
    425 	os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
    426 	os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
    427 	data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
    428 	data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
    429 	wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
    430 }
    431 
    432 
    433 static void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
    434 {
    435 	if (len < ETH_ALEN)
    436 		return;
    437 	drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
    438 }
    439 
    440 
    441 static void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
    442 				       void *sock_ctx)
    443 {
    444 	struct wpa_driver_privsep_data *drv = eloop_ctx;
    445 	u8 *buf, *event_buf;
    446 	size_t event_len;
    447 	int res, event;
    448 	enum privsep_event e;
    449 	struct sockaddr_un from;
    450 	socklen_t fromlen = sizeof(from);
    451 	const size_t buflen = 2000;
    452 
    453 	buf = os_malloc(buflen);
    454 	if (buf == NULL)
    455 		return;
    456 	res = recvfrom(sock, buf, buflen, 0,
    457 		       (struct sockaddr *) &from, &fromlen);
    458 	if (res < 0) {
    459 		perror("recvfrom(priv_socket)");
    460 		os_free(buf);
    461 		return;
    462 	}
    463 
    464 	wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
    465 
    466 	if (res < (int) sizeof(int)) {
    467 		wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
    468 		return;
    469 	}
    470 
    471 	os_memcpy(&event, buf, sizeof(int));
    472 	event_buf = &buf[sizeof(int)];
    473 	event_len = res - sizeof(int);
    474 	wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
    475 		   event, (unsigned long) event_len);
    476 
    477 	e = event;
    478 	switch (e) {
    479 	case PRIVSEP_EVENT_SCAN_RESULTS:
    480 		wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
    481 		break;
    482 	case PRIVSEP_EVENT_ASSOC:
    483 		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
    484 					       event_buf, event_len);
    485 		break;
    486 	case PRIVSEP_EVENT_DISASSOC:
    487 		wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
    488 		break;
    489 	case PRIVSEP_EVENT_ASSOCINFO:
    490 		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
    491 					       event_buf, event_len);
    492 		break;
    493 	case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
    494 		wpa_driver_privsep_event_michael_mic_failure(
    495 			drv->ctx, event_buf, event_len);
    496 		break;
    497 	case PRIVSEP_EVENT_INTERFACE_STATUS:
    498 		wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
    499 							  event_len);
    500 		break;
    501 	case PRIVSEP_EVENT_PMKID_CANDIDATE:
    502 		wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
    503 							 event_len);
    504 		break;
    505 	case PRIVSEP_EVENT_STKSTART:
    506 		wpa_driver_privsep_event_stkstart(drv->ctx, event_buf,
    507 						  event_len);
    508 		break;
    509 	case PRIVSEP_EVENT_FT_RESPONSE:
    510 		wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
    511 						     event_len);
    512 		break;
    513 	case PRIVSEP_EVENT_RX_EAPOL:
    514 		wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
    515 						  event_len);
    516 		break;
    517 	}
    518 
    519 	os_free(buf);
    520 }
    521 
    522 
    523 static void * wpa_driver_privsep_init(void *ctx, const char *ifname)
    524 {
    525 	struct wpa_driver_privsep_data *drv;
    526 
    527 	drv = os_zalloc(sizeof(*drv));
    528 	if (drv == NULL)
    529 		return NULL;
    530 	drv->ctx = ctx;
    531 	drv->priv_socket = -1;
    532 	drv->cmd_socket = -1;
    533 	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
    534 
    535 	return drv;
    536 }
    537 
    538 
    539 static void wpa_driver_privsep_deinit(void *priv)
    540 {
    541 	struct wpa_driver_privsep_data *drv = priv;
    542 
    543 	if (drv->priv_socket >= 0) {
    544 		wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
    545 		eloop_unregister_read_sock(drv->priv_socket);
    546 		close(drv->priv_socket);
    547 	}
    548 
    549 	if (drv->own_socket_path) {
    550 		unlink(drv->own_socket_path);
    551 		os_free(drv->own_socket_path);
    552 	}
    553 
    554 	if (drv->cmd_socket >= 0) {
    555 		eloop_unregister_read_sock(drv->cmd_socket);
    556 		close(drv->cmd_socket);
    557 	}
    558 
    559 	if (drv->own_cmd_path) {
    560 		unlink(drv->own_cmd_path);
    561 		os_free(drv->own_cmd_path);
    562 	}
    563 
    564 	os_free(drv);
    565 }
    566 
    567 
    568 static int wpa_driver_privsep_set_param(void *priv, const char *param)
    569 {
    570 	struct wpa_driver_privsep_data *drv = priv;
    571 	const char *pos;
    572 	char *own_dir, *priv_dir;
    573 	static unsigned int counter = 0;
    574 	size_t len;
    575 	struct sockaddr_un addr;
    576 
    577 	wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
    578 	if (param == NULL)
    579 		pos = NULL;
    580 	else
    581 		pos = os_strstr(param, "own_dir=");
    582 	if (pos) {
    583 		char *end;
    584 		own_dir = os_strdup(pos + 8);
    585 		if (own_dir == NULL)
    586 			return -1;
    587 		end = os_strchr(own_dir, ' ');
    588 		if (end)
    589 			*end = '\0';
    590 	} else {
    591 		own_dir = os_strdup("/tmp");
    592 		if (own_dir == NULL)
    593 			return -1;
    594 	}
    595 
    596 	if (param == NULL)
    597 		pos = NULL;
    598 	else
    599 		pos = os_strstr(param, "priv_dir=");
    600 	if (pos) {
    601 		char *end;
    602 		priv_dir = os_strdup(pos + 9);
    603 		if (priv_dir == NULL) {
    604 			os_free(own_dir);
    605 			return -1;
    606 		}
    607 		end = os_strchr(priv_dir, ' ');
    608 		if (end)
    609 			*end = '\0';
    610 	} else {
    611 		priv_dir = os_strdup("/var/run/wpa_priv");
    612 		if (priv_dir == NULL) {
    613 			os_free(own_dir);
    614 			return -1;
    615 		}
    616 	}
    617 
    618 	len = os_strlen(own_dir) + 50;
    619 	drv->own_socket_path = os_malloc(len);
    620 	if (drv->own_socket_path == NULL) {
    621 		os_free(priv_dir);
    622 		os_free(own_dir);
    623 		return -1;
    624 	}
    625 	os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
    626 		    own_dir, getpid(), counter++);
    627 
    628 	len = os_strlen(own_dir) + 50;
    629 	drv->own_cmd_path = os_malloc(len);
    630 	if (drv->own_cmd_path == NULL) {
    631 		os_free(drv->own_socket_path);
    632 		drv->own_socket_path = NULL;
    633 		os_free(priv_dir);
    634 		os_free(own_dir);
    635 		return -1;
    636 	}
    637 	os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
    638 		    own_dir, getpid(), counter++);
    639 
    640 	os_free(own_dir);
    641 
    642 	drv->priv_addr.sun_family = AF_UNIX;
    643 	os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
    644 		    "%s/%s", priv_dir, drv->ifname);
    645 	os_free(priv_dir);
    646 
    647 	drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
    648 	if (drv->priv_socket < 0) {
    649 		perror("socket(PF_UNIX)");
    650 		os_free(drv->own_socket_path);
    651 		drv->own_socket_path = NULL;
    652 		return -1;
    653 	}
    654 
    655 	os_memset(&addr, 0, sizeof(addr));
    656 	addr.sun_family = AF_UNIX;
    657 	os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
    658 	if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
    659 	    0) {
    660 		perror("bind(PF_UNIX)");
    661 		close(drv->priv_socket);
    662 		drv->priv_socket = -1;
    663 		unlink(drv->own_socket_path);
    664 		os_free(drv->own_socket_path);
    665 		drv->own_socket_path = NULL;
    666 		return -1;
    667 	}
    668 
    669 	eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
    670 				 drv, NULL);
    671 
    672 	drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
    673 	if (drv->cmd_socket < 0) {
    674 		perror("socket(PF_UNIX)");
    675 		os_free(drv->own_cmd_path);
    676 		drv->own_cmd_path = NULL;
    677 		return -1;
    678 	}
    679 
    680 	os_memset(&addr, 0, sizeof(addr));
    681 	addr.sun_family = AF_UNIX;
    682 	os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
    683 	if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
    684 	{
    685 		perror("bind(PF_UNIX)");
    686 		close(drv->cmd_socket);
    687 		drv->cmd_socket = -1;
    688 		unlink(drv->own_cmd_path);
    689 		os_free(drv->own_cmd_path);
    690 		drv->own_cmd_path = NULL;
    691 		return -1;
    692 	}
    693 
    694 	if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
    695 		wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
    696 		return -1;
    697 	}
    698 
    699 	return 0;
    700 }
    701 
    702 
    703 static int wpa_driver_privsep_get_capa(void *priv,
    704 				       struct wpa_driver_capa *capa)
    705 {
    706 	struct wpa_driver_privsep_data *drv = priv;
    707 	int res;
    708 	size_t len = sizeof(*capa);
    709 
    710 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
    711 	if (res < 0 || len != sizeof(*capa))
    712 		return -1;
    713 	return 0;
    714 }
    715 
    716 
    717 static const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
    718 {
    719 	struct wpa_driver_privsep_data *drv = priv;
    720 	wpa_printf(MSG_DEBUG, "%s", __func__);
    721 	return drv->own_addr;
    722 }
    723 
    724 
    725 static int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
    726 {
    727 	struct wpa_driver_privsep_data *drv = priv;
    728 	wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
    729 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
    730 			    os_strlen(alpha2), NULL, NULL);
    731 }
    732 
    733 
    734 struct wpa_driver_ops wpa_driver_privsep_ops = {
    735 	"privsep",
    736 	"wpa_supplicant privilege separated driver",
    737 	.get_bssid = wpa_driver_privsep_get_bssid,
    738 	.get_ssid = wpa_driver_privsep_get_ssid,
    739 	.set_key = wpa_driver_privsep_set_key,
    740 	.init = wpa_driver_privsep_init,
    741 	.deinit = wpa_driver_privsep_deinit,
    742 	.set_param = wpa_driver_privsep_set_param,
    743 	.scan2 = wpa_driver_privsep_scan,
    744 	.deauthenticate = wpa_driver_privsep_deauthenticate,
    745 	.disassociate = wpa_driver_privsep_disassociate,
    746 	.associate = wpa_driver_privsep_associate,
    747 	.get_capa = wpa_driver_privsep_get_capa,
    748 	.get_mac_addr = wpa_driver_privsep_get_mac_addr,
    749 	.get_scan_results2 = wpa_driver_privsep_get_scan_results2,
    750 	.set_country = wpa_driver_privsep_set_country,
    751 };
    752 
    753 
    754 struct wpa_driver_ops *wpa_drivers[] =
    755 {
    756 	&wpa_driver_privsep_ops,
    757 	NULL
    758 };
    759