Home | History | Annotate | Download | only in drivers
      1 /*
      2  * WPA Supplicant - privilege separated driver interface
      3  * Copyright (c) 2007-2009, Jouni Malinen <j (at) w1.fi>
      4  *
      5  * This software may be distributed under the terms of the BSD license.
      6  * See README for more details.
      7  */
      8 
      9 #include "includes.h"
     10 #include <sys/un.h>
     11 
     12 #include "common.h"
     13 #include "driver.h"
     14 #include "eloop.h"
     15 #include "common/privsep_commands.h"
     16 
     17 
     18 struct wpa_driver_privsep_data {
     19 	void *ctx;
     20 	u8 own_addr[ETH_ALEN];
     21 	int priv_socket;
     22 	char *own_socket_path;
     23 	int cmd_socket;
     24 	char *own_cmd_path;
     25 	struct sockaddr_un priv_addr;
     26 	char ifname[16];
     27 };
     28 
     29 
     30 static int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
     31 {
     32 	int res;
     33 
     34 	res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
     35 		     (struct sockaddr *) &drv->priv_addr,
     36 		     sizeof(drv->priv_addr));
     37 	if (res < 0)
     38 		wpa_printf(MSG_ERROR, "sendto: %s", strerror(errno));
     39 	return res < 0 ? -1 : 0;
     40 }
     41 
     42 
     43 static int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
     44 			const void *data, size_t data_len,
     45 			void *reply, size_t *reply_len)
     46 {
     47 	struct msghdr msg;
     48 	struct iovec io[2];
     49 
     50 	io[0].iov_base = &cmd;
     51 	io[0].iov_len = sizeof(cmd);
     52 	io[1].iov_base = (u8 *) data;
     53 	io[1].iov_len = data_len;
     54 
     55 	os_memset(&msg, 0, sizeof(msg));
     56 	msg.msg_iov = io;
     57 	msg.msg_iovlen = data ? 2 : 1;
     58 	msg.msg_name = &drv->priv_addr;
     59 	msg.msg_namelen = sizeof(drv->priv_addr);
     60 
     61 	if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
     62 		wpa_printf(MSG_ERROR, "sendmsg(cmd_socket): %s",
     63 			   strerror(errno));
     64 		return -1;
     65 	}
     66 
     67 	if (reply) {
     68 		fd_set rfds;
     69 		struct timeval tv;
     70 		int res;
     71 
     72 		FD_ZERO(&rfds);
     73 		FD_SET(drv->cmd_socket, &rfds);
     74 		tv.tv_sec = 5;
     75 		tv.tv_usec = 0;
     76 		res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
     77 		if (res < 0 && errno != EINTR) {
     78 			wpa_printf(MSG_ERROR, "select: %s", strerror(errno));
     79 			return -1;
     80 		}
     81 
     82 		if (FD_ISSET(drv->cmd_socket, &rfds)) {
     83 			res = recv(drv->cmd_socket, reply, *reply_len, 0);
     84 			if (res < 0) {
     85 				wpa_printf(MSG_ERROR, "recv: %s",
     86 					   strerror(errno));
     87 				return -1;
     88 			}
     89 			*reply_len = res;
     90 		} else {
     91 			wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
     92 				   "for reply (cmd=%d)", cmd);
     93 			return -1;
     94 		}
     95 	}
     96 
     97 	return 0;
     98 }
     99 
    100 
    101 static int wpa_driver_privsep_scan(void *priv,
    102 				   struct wpa_driver_scan_params *params)
    103 {
    104 	struct wpa_driver_privsep_data *drv = priv;
    105 	const u8 *ssid = params->ssids[0].ssid;
    106 	size_t ssid_len = params->ssids[0].ssid_len;
    107 	wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
    108 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, ssid, ssid_len,
    109 			    NULL, NULL);
    110 }
    111 
    112 
    113 static struct wpa_scan_results *
    114 wpa_driver_privsep_get_scan_results2(void *priv)
    115 {
    116 	struct wpa_driver_privsep_data *drv = priv;
    117 	int res, num;
    118 	u8 *buf, *pos, *end;
    119 	size_t reply_len = 60000;
    120 	struct wpa_scan_results *results;
    121 	struct wpa_scan_res *r;
    122 
    123 	buf = os_malloc(reply_len);
    124 	if (buf == NULL)
    125 		return NULL;
    126 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
    127 			   NULL, 0, buf, &reply_len);
    128 	if (res < 0) {
    129 		os_free(buf);
    130 		return NULL;
    131 	}
    132 
    133 	wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
    134 		   (unsigned long) reply_len);
    135 	if (reply_len < sizeof(int)) {
    136 		wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
    137 			   (unsigned long) reply_len);
    138 		os_free(buf);
    139 		return NULL;
    140 	}
    141 
    142 	pos = buf;
    143 	end = buf + reply_len;
    144 	os_memcpy(&num, pos, sizeof(int));
    145 	if (num < 0 || num > 1000) {
    146 		os_free(buf);
    147 		return NULL;
    148 	}
    149 	pos += sizeof(int);
    150 
    151 	results = os_zalloc(sizeof(*results));
    152 	if (results == NULL) {
    153 		os_free(buf);
    154 		return NULL;
    155 	}
    156 
    157 	results->res = os_calloc(num, sizeof(struct wpa_scan_res *));
    158 	if (results->res == NULL) {
    159 		os_free(results);
    160 		os_free(buf);
    161 		return NULL;
    162 	}
    163 
    164 	while (results->num < (size_t) num && end - pos > (int) sizeof(int)) {
    165 		int len;
    166 		os_memcpy(&len, pos, sizeof(int));
    167 		pos += sizeof(int);
    168 		if (len < 0 || len > 10000 || len > end - pos)
    169 			break;
    170 
    171 		r = os_malloc(len);
    172 		if (r == NULL)
    173 			break;
    174 		os_memcpy(r, pos, len);
    175 		pos += len;
    176 		if (sizeof(*r) + r->ie_len > (size_t) len) {
    177 			os_free(r);
    178 			break;
    179 		}
    180 
    181 		results->res[results->num++] = r;
    182 	}
    183 
    184 	os_free(buf);
    185 	return results;
    186 }
    187 
    188 
    189 static int wpa_driver_privsep_set_key(const char *ifname, void *priv,
    190 				      enum wpa_alg alg, const u8 *addr,
    191 				      int key_idx, int set_tx,
    192 				      const u8 *seq, size_t seq_len,
    193 				      const u8 *key, size_t key_len)
    194 {
    195 	struct wpa_driver_privsep_data *drv = priv;
    196 	struct privsep_cmd_set_key cmd;
    197 
    198 	wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
    199 		   __func__, priv, alg, key_idx, set_tx);
    200 
    201 	os_memset(&cmd, 0, sizeof(cmd));
    202 	cmd.alg = alg;
    203 	if (addr)
    204 		os_memcpy(cmd.addr, addr, ETH_ALEN);
    205 	else
    206 		os_memset(cmd.addr, 0xff, ETH_ALEN);
    207 	cmd.key_idx = key_idx;
    208 	cmd.set_tx = set_tx;
    209 	if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
    210 		os_memcpy(cmd.seq, seq, seq_len);
    211 		cmd.seq_len = seq_len;
    212 	}
    213 	if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
    214 		os_memcpy(cmd.key, key, key_len);
    215 		cmd.key_len = key_len;
    216 	}
    217 
    218 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
    219 			    NULL, NULL);
    220 }
    221 
    222 
    223 static int wpa_driver_privsep_authenticate(
    224 	void *priv, struct wpa_driver_auth_params *params)
    225 {
    226 	struct wpa_driver_privsep_data *drv = priv;
    227 	struct privsep_cmd_authenticate *data;
    228 	int i, res;
    229 	size_t buflen;
    230 	u8 *pos;
    231 
    232 	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d bssid=" MACSTR
    233 		   " auth_alg=%d local_state_change=%d p2p=%d",
    234 		   __func__, priv, params->freq, MAC2STR(params->bssid),
    235 		   params->auth_alg, params->local_state_change, params->p2p);
    236 
    237 	buflen = sizeof(*data) + params->ie_len + params->sae_data_len;
    238 	data = os_zalloc(buflen);
    239 	if (data == NULL)
    240 		return -1;
    241 
    242 	data->freq = params->freq;
    243 	os_memcpy(data->bssid, params->bssid, ETH_ALEN);
    244 	os_memcpy(data->ssid, params->ssid, params->ssid_len);
    245 	data->ssid_len = params->ssid_len;
    246 	data->auth_alg = params->auth_alg;
    247 	data->ie_len = params->ie_len;
    248 	for (i = 0; i < 4; i++) {
    249 		if (params->wep_key[i])
    250 			os_memcpy(data->wep_key[i], params->wep_key[i],
    251 				  params->wep_key_len[i]);
    252 		data->wep_key_len[i] = params->wep_key_len[i];
    253 	}
    254 	data->wep_tx_keyidx = params->wep_tx_keyidx;
    255 	data->local_state_change = params->local_state_change;
    256 	data->p2p = params->p2p;
    257 	pos = (u8 *) (data + 1);
    258 	if (params->ie_len) {
    259 		os_memcpy(pos, params->ie, params->ie_len);
    260 		pos += params->ie_len;
    261 	}
    262 	if (params->sae_data_len)
    263 		os_memcpy(pos, params->sae_data, params->sae_data_len);
    264 
    265 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_AUTHENTICATE, data, buflen,
    266 			   NULL, NULL);
    267 	os_free(data);
    268 
    269 	return res;
    270 }
    271 
    272 
    273 static int wpa_driver_privsep_associate(
    274 	void *priv, struct wpa_driver_associate_params *params)
    275 {
    276 	struct wpa_driver_privsep_data *drv = priv;
    277 	struct privsep_cmd_associate *data;
    278 	int res;
    279 	size_t buflen;
    280 
    281 	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
    282 		   "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
    283 		   __func__, priv, params->freq.freq, params->pairwise_suite,
    284 		   params->group_suite, params->key_mgmt_suite,
    285 		   params->auth_alg, params->mode);
    286 
    287 	buflen = sizeof(*data) + params->wpa_ie_len;
    288 	data = os_zalloc(buflen);
    289 	if (data == NULL)
    290 		return -1;
    291 
    292 	if (params->bssid)
    293 		os_memcpy(data->bssid, params->bssid, ETH_ALEN);
    294 	os_memcpy(data->ssid, params->ssid, params->ssid_len);
    295 	data->ssid_len = params->ssid_len;
    296 	data->hwmode = params->freq.mode;
    297 	data->freq = params->freq.freq;
    298 	data->channel = params->freq.channel;
    299 	data->pairwise_suite = params->pairwise_suite;
    300 	data->group_suite = params->group_suite;
    301 	data->key_mgmt_suite = params->key_mgmt_suite;
    302 	data->auth_alg = params->auth_alg;
    303 	data->mode = params->mode;
    304 	data->wpa_ie_len = params->wpa_ie_len;
    305 	if (params->wpa_ie)
    306 		os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
    307 	/* TODO: add support for other assoc parameters */
    308 
    309 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
    310 			   NULL, NULL);
    311 	os_free(data);
    312 
    313 	return res;
    314 }
    315 
    316 
    317 static int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
    318 {
    319 	struct wpa_driver_privsep_data *drv = priv;
    320 	int res;
    321 	size_t len = ETH_ALEN;
    322 
    323 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
    324 	if (res < 0 || len != ETH_ALEN)
    325 		return -1;
    326 	return 0;
    327 }
    328 
    329 
    330 static int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
    331 {
    332 	struct wpa_driver_privsep_data *drv = priv;
    333 	int res, ssid_len;
    334 	u8 reply[sizeof(int) + SSID_MAX_LEN];
    335 	size_t len = sizeof(reply);
    336 
    337 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
    338 	if (res < 0 || len < sizeof(int))
    339 		return -1;
    340 	os_memcpy(&ssid_len, reply, sizeof(int));
    341 	if (ssid_len < 0 || ssid_len > SSID_MAX_LEN ||
    342 	    sizeof(int) + ssid_len > len) {
    343 		wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
    344 		return -1;
    345 	}
    346 	os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
    347 	return ssid_len;
    348 }
    349 
    350 
    351 static int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
    352 					  int reason_code)
    353 {
    354 	//struct wpa_driver_privsep_data *drv = priv;
    355 	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
    356 		   __func__, MAC2STR(addr), reason_code);
    357 	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
    358 	return 0;
    359 }
    360 
    361 
    362 static void wpa_driver_privsep_event_auth(void *ctx, u8 *buf, size_t len)
    363 {
    364 	union wpa_event_data data;
    365 	struct privsep_event_auth *auth;
    366 
    367 	os_memset(&data, 0, sizeof(data));
    368 	if (len < sizeof(*auth))
    369 		return;
    370 	auth = (struct privsep_event_auth *) buf;
    371 	if (len < sizeof(*auth) + auth->ies_len)
    372 		return;
    373 
    374 	os_memcpy(data.auth.peer, auth->peer, ETH_ALEN);
    375 	os_memcpy(data.auth.bssid, auth->bssid, ETH_ALEN);
    376 	data.auth.auth_type = auth->auth_type;
    377 	data.auth.auth_transaction = auth->auth_transaction;
    378 	data.auth.status_code = auth->status_code;
    379 	if (auth->ies_len) {
    380 		data.auth.ies = (u8 *) (auth + 1);
    381 		data.auth.ies_len = auth->ies_len;
    382 	}
    383 
    384 	wpa_supplicant_event(ctx, EVENT_AUTH, &data);
    385 }
    386 
    387 
    388 static void wpa_driver_privsep_event_assoc(void *ctx,
    389 					   enum wpa_event_type event,
    390 					   u8 *buf, size_t len)
    391 {
    392 	union wpa_event_data data;
    393 	int inc_data = 0;
    394 	u8 *pos, *end;
    395 	int ie_len;
    396 
    397 	os_memset(&data, 0, sizeof(data));
    398 
    399 	pos = buf;
    400 	end = buf + len;
    401 
    402 	if (end - pos < (int) sizeof(int))
    403 		return;
    404 	os_memcpy(&ie_len, pos, sizeof(int));
    405 	pos += sizeof(int);
    406 	if (ie_len < 0 || ie_len > end - pos)
    407 		return;
    408 	if (ie_len) {
    409 		data.assoc_info.req_ies = pos;
    410 		data.assoc_info.req_ies_len = ie_len;
    411 		pos += ie_len;
    412 		inc_data = 1;
    413 	}
    414 
    415 	wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
    416 }
    417 
    418 
    419 static void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
    420 						      size_t len)
    421 {
    422 	union wpa_event_data data;
    423 	int ievent;
    424 
    425 	if (len < sizeof(int) ||
    426 	    len - sizeof(int) > sizeof(data.interface_status.ifname))
    427 		return;
    428 
    429 	os_memcpy(&ievent, buf, sizeof(int));
    430 
    431 	os_memset(&data, 0, sizeof(data));
    432 	data.interface_status.ievent = ievent;
    433 	os_memcpy(data.interface_status.ifname, buf + sizeof(int),
    434 		  len - sizeof(int));
    435 	wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
    436 }
    437 
    438 
    439 static void wpa_driver_privsep_event_michael_mic_failure(
    440 	void *ctx, u8 *buf, size_t len)
    441 {
    442 	union wpa_event_data data;
    443 
    444 	if (len != sizeof(int))
    445 		return;
    446 
    447 	os_memset(&data, 0, sizeof(data));
    448 	os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
    449 	wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
    450 }
    451 
    452 
    453 static void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
    454 						     size_t len)
    455 {
    456 	union wpa_event_data data;
    457 
    458 	if (len != sizeof(struct pmkid_candidate))
    459 		return;
    460 
    461 	os_memset(&data, 0, sizeof(data));
    462 	os_memcpy(&data.pmkid_candidate, buf, len);
    463 	wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
    464 }
    465 
    466 
    467 static void wpa_driver_privsep_event_stkstart(void *ctx, u8 *buf, size_t len)
    468 {
    469 	union wpa_event_data data;
    470 
    471 	if (len != ETH_ALEN)
    472 		return;
    473 
    474 	os_memset(&data, 0, sizeof(data));
    475 	os_memcpy(data.stkstart.peer, buf, ETH_ALEN);
    476 	wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
    477 }
    478 
    479 
    480 static void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
    481 						 size_t len)
    482 {
    483 	union wpa_event_data data;
    484 
    485 	if (len < sizeof(int) + ETH_ALEN)
    486 		return;
    487 
    488 	os_memset(&data, 0, sizeof(data));
    489 	os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
    490 	os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
    491 	data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
    492 	data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
    493 	wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
    494 }
    495 
    496 
    497 static void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
    498 {
    499 	if (len < ETH_ALEN)
    500 		return;
    501 	drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
    502 }
    503 
    504 
    505 static void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
    506 				       void *sock_ctx)
    507 {
    508 	struct wpa_driver_privsep_data *drv = eloop_ctx;
    509 	u8 *buf, *event_buf;
    510 	size_t event_len;
    511 	int res, event;
    512 	enum privsep_event e;
    513 	struct sockaddr_un from;
    514 	socklen_t fromlen = sizeof(from);
    515 	const size_t buflen = 2000;
    516 
    517 	buf = os_malloc(buflen);
    518 	if (buf == NULL)
    519 		return;
    520 	res = recvfrom(sock, buf, buflen, 0,
    521 		       (struct sockaddr *) &from, &fromlen);
    522 	if (res < 0) {
    523 		wpa_printf(MSG_ERROR, "recvfrom(priv_socket): %s",
    524 			   strerror(errno));
    525 		os_free(buf);
    526 		return;
    527 	}
    528 
    529 	wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
    530 
    531 	if (res < (int) sizeof(int)) {
    532 		wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
    533 		return;
    534 	}
    535 
    536 	os_memcpy(&event, buf, sizeof(int));
    537 	event_buf = &buf[sizeof(int)];
    538 	event_len = res - sizeof(int);
    539 	wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
    540 		   event, (unsigned long) event_len);
    541 
    542 	e = event;
    543 	switch (e) {
    544 	case PRIVSEP_EVENT_SCAN_RESULTS:
    545 		wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
    546 		break;
    547 	case PRIVSEP_EVENT_SCAN_STARTED:
    548 		wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, NULL);
    549 		break;
    550 	case PRIVSEP_EVENT_ASSOC:
    551 		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
    552 					       event_buf, event_len);
    553 		break;
    554 	case PRIVSEP_EVENT_DISASSOC:
    555 		wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
    556 		break;
    557 	case PRIVSEP_EVENT_ASSOCINFO:
    558 		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
    559 					       event_buf, event_len);
    560 		break;
    561 	case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
    562 		wpa_driver_privsep_event_michael_mic_failure(
    563 			drv->ctx, event_buf, event_len);
    564 		break;
    565 	case PRIVSEP_EVENT_INTERFACE_STATUS:
    566 		wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
    567 							  event_len);
    568 		break;
    569 	case PRIVSEP_EVENT_PMKID_CANDIDATE:
    570 		wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
    571 							 event_len);
    572 		break;
    573 	case PRIVSEP_EVENT_STKSTART:
    574 		wpa_driver_privsep_event_stkstart(drv->ctx, event_buf,
    575 						  event_len);
    576 		break;
    577 	case PRIVSEP_EVENT_FT_RESPONSE:
    578 		wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
    579 						     event_len);
    580 		break;
    581 	case PRIVSEP_EVENT_RX_EAPOL:
    582 		wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
    583 						  event_len);
    584 		break;
    585 	case PRIVSEP_EVENT_AUTH:
    586 		wpa_driver_privsep_event_auth(drv->ctx, event_buf, event_len);
    587 		break;
    588 	}
    589 
    590 	os_free(buf);
    591 }
    592 
    593 
    594 static void * wpa_driver_privsep_init(void *ctx, const char *ifname)
    595 {
    596 	struct wpa_driver_privsep_data *drv;
    597 
    598 	drv = os_zalloc(sizeof(*drv));
    599 	if (drv == NULL)
    600 		return NULL;
    601 	drv->ctx = ctx;
    602 	drv->priv_socket = -1;
    603 	drv->cmd_socket = -1;
    604 	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
    605 
    606 	return drv;
    607 }
    608 
    609 
    610 static void wpa_driver_privsep_deinit(void *priv)
    611 {
    612 	struct wpa_driver_privsep_data *drv = priv;
    613 
    614 	if (drv->priv_socket >= 0) {
    615 		wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
    616 		eloop_unregister_read_sock(drv->priv_socket);
    617 		close(drv->priv_socket);
    618 	}
    619 
    620 	if (drv->own_socket_path) {
    621 		unlink(drv->own_socket_path);
    622 		os_free(drv->own_socket_path);
    623 	}
    624 
    625 	if (drv->cmd_socket >= 0) {
    626 		eloop_unregister_read_sock(drv->cmd_socket);
    627 		close(drv->cmd_socket);
    628 	}
    629 
    630 	if (drv->own_cmd_path) {
    631 		unlink(drv->own_cmd_path);
    632 		os_free(drv->own_cmd_path);
    633 	}
    634 
    635 	os_free(drv);
    636 }
    637 
    638 
    639 static int wpa_driver_privsep_set_param(void *priv, const char *param)
    640 {
    641 	struct wpa_driver_privsep_data *drv = priv;
    642 	const char *pos;
    643 	char *own_dir, *priv_dir;
    644 	static unsigned int counter = 0;
    645 	size_t len;
    646 	struct sockaddr_un addr;
    647 
    648 	wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
    649 	if (param == NULL)
    650 		pos = NULL;
    651 	else
    652 		pos = os_strstr(param, "own_dir=");
    653 	if (pos) {
    654 		char *end;
    655 		own_dir = os_strdup(pos + 8);
    656 		if (own_dir == NULL)
    657 			return -1;
    658 		end = os_strchr(own_dir, ' ');
    659 		if (end)
    660 			*end = '\0';
    661 	} else {
    662 		own_dir = os_strdup("/tmp");
    663 		if (own_dir == NULL)
    664 			return -1;
    665 	}
    666 
    667 	if (param == NULL)
    668 		pos = NULL;
    669 	else
    670 		pos = os_strstr(param, "priv_dir=");
    671 	if (pos) {
    672 		char *end;
    673 		priv_dir = os_strdup(pos + 9);
    674 		if (priv_dir == NULL) {
    675 			os_free(own_dir);
    676 			return -1;
    677 		}
    678 		end = os_strchr(priv_dir, ' ');
    679 		if (end)
    680 			*end = '\0';
    681 	} else {
    682 		priv_dir = os_strdup("/var/run/wpa_priv");
    683 		if (priv_dir == NULL) {
    684 			os_free(own_dir);
    685 			return -1;
    686 		}
    687 	}
    688 
    689 	len = os_strlen(own_dir) + 50;
    690 	drv->own_socket_path = os_malloc(len);
    691 	if (drv->own_socket_path == NULL) {
    692 		os_free(priv_dir);
    693 		os_free(own_dir);
    694 		return -1;
    695 	}
    696 	os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
    697 		    own_dir, getpid(), counter++);
    698 
    699 	len = os_strlen(own_dir) + 50;
    700 	drv->own_cmd_path = os_malloc(len);
    701 	if (drv->own_cmd_path == NULL) {
    702 		os_free(drv->own_socket_path);
    703 		drv->own_socket_path = NULL;
    704 		os_free(priv_dir);
    705 		os_free(own_dir);
    706 		return -1;
    707 	}
    708 	os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
    709 		    own_dir, getpid(), counter++);
    710 
    711 	os_free(own_dir);
    712 
    713 	drv->priv_addr.sun_family = AF_UNIX;
    714 	os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
    715 		    "%s/%s", priv_dir, drv->ifname);
    716 	os_free(priv_dir);
    717 
    718 	drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
    719 	if (drv->priv_socket < 0) {
    720 		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
    721 		os_free(drv->own_socket_path);
    722 		drv->own_socket_path = NULL;
    723 		return -1;
    724 	}
    725 
    726 	os_memset(&addr, 0, sizeof(addr));
    727 	addr.sun_family = AF_UNIX;
    728 	os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
    729 	if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
    730 	    0) {
    731 		wpa_printf(MSG_ERROR,
    732 			   "privsep-set-params priv-sock: bind(PF_UNIX): %s",
    733 			   strerror(errno));
    734 		close(drv->priv_socket);
    735 		drv->priv_socket = -1;
    736 		unlink(drv->own_socket_path);
    737 		os_free(drv->own_socket_path);
    738 		drv->own_socket_path = NULL;
    739 		return -1;
    740 	}
    741 
    742 	eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
    743 				 drv, NULL);
    744 
    745 	drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
    746 	if (drv->cmd_socket < 0) {
    747 		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
    748 		os_free(drv->own_cmd_path);
    749 		drv->own_cmd_path = NULL;
    750 		return -1;
    751 	}
    752 
    753 	os_memset(&addr, 0, sizeof(addr));
    754 	addr.sun_family = AF_UNIX;
    755 	os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
    756 	if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
    757 	{
    758 		wpa_printf(MSG_ERROR,
    759 			   "privsep-set-params cmd-sock: bind(PF_UNIX): %s",
    760 			   strerror(errno));
    761 		close(drv->cmd_socket);
    762 		drv->cmd_socket = -1;
    763 		unlink(drv->own_cmd_path);
    764 		os_free(drv->own_cmd_path);
    765 		drv->own_cmd_path = NULL;
    766 		return -1;
    767 	}
    768 
    769 	if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
    770 		wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
    771 		return -1;
    772 	}
    773 
    774 	return 0;
    775 }
    776 
    777 
    778 static int wpa_driver_privsep_get_capa(void *priv,
    779 				       struct wpa_driver_capa *capa)
    780 {
    781 	struct wpa_driver_privsep_data *drv = priv;
    782 	int res;
    783 	size_t len = sizeof(*capa);
    784 
    785 	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
    786 	if (res < 0 || len != sizeof(*capa))
    787 		return -1;
    788 	/* For now, no support for passing extended_capa pointers */
    789 	capa->extended_capa = NULL;
    790 	capa->extended_capa_mask = NULL;
    791 	capa->extended_capa_len = 0;
    792 	return 0;
    793 }
    794 
    795 
    796 static const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
    797 {
    798 	struct wpa_driver_privsep_data *drv = priv;
    799 	wpa_printf(MSG_DEBUG, "%s", __func__);
    800 	return drv->own_addr;
    801 }
    802 
    803 
    804 static int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
    805 {
    806 	struct wpa_driver_privsep_data *drv = priv;
    807 	wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
    808 	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
    809 			    os_strlen(alpha2), NULL, NULL);
    810 }
    811 
    812 
    813 struct wpa_driver_ops wpa_driver_privsep_ops = {
    814 	"privsep",
    815 	"wpa_supplicant privilege separated driver",
    816 	.get_bssid = wpa_driver_privsep_get_bssid,
    817 	.get_ssid = wpa_driver_privsep_get_ssid,
    818 	.set_key = wpa_driver_privsep_set_key,
    819 	.init = wpa_driver_privsep_init,
    820 	.deinit = wpa_driver_privsep_deinit,
    821 	.set_param = wpa_driver_privsep_set_param,
    822 	.scan2 = wpa_driver_privsep_scan,
    823 	.deauthenticate = wpa_driver_privsep_deauthenticate,
    824 	.authenticate = wpa_driver_privsep_authenticate,
    825 	.associate = wpa_driver_privsep_associate,
    826 	.get_capa = wpa_driver_privsep_get_capa,
    827 	.get_mac_addr = wpa_driver_privsep_get_mac_addr,
    828 	.get_scan_results2 = wpa_driver_privsep_get_scan_results2,
    829 	.set_country = wpa_driver_privsep_set_country,
    830 };
    831 
    832 
    833 const struct wpa_driver_ops *const wpa_drivers[] =
    834 {
    835 	&wpa_driver_privsep_ops,
    836 	NULL
    837 };
    838