• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * wpa_supplicant/hostapd control interface library
3  * Copyright (c) 2004-2007, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8 
9 #include "includes.h"
10 
11 #ifdef CONFIG_CTRL_IFACE
12 
13 #ifdef CONFIG_CTRL_IFACE_UNIX
14 #include <sys/stat.h>
15 #include <fcntl.h>
16 #include <sys/un.h>
17 #include <unistd.h>
18 #include <fcntl.h>
19 #endif /* CONFIG_CTRL_IFACE_UNIX */
20 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
21 #include <netdb.h>
22 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
23 
24 #ifdef ANDROID
25 #include <dirent.h>
26 #include <sys/stat.h>
27 #include <cutils/sockets.h>
28 #include "private/android_filesystem_config.h"
29 #endif /* ANDROID */
30 
31 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
32 #include <net/if.h>
33 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
34 
35 #include "wpa_ctrl.h"
36 #include "common.h"
37 
38 
39 #if defined(CONFIG_CTRL_IFACE_UNIX) || defined(CONFIG_CTRL_IFACE_UDP)
40 #define CTRL_IFACE_SOCKET
41 #endif /* CONFIG_CTRL_IFACE_UNIX || CONFIG_CTRL_IFACE_UDP */
42 
43 
44 /**
45  * struct wpa_ctrl - Internal structure for control interface library
46  *
47  * This structure is used by the wpa_supplicant/hostapd control interface
48  * library to store internal data. Programs using the library should not touch
49  * this data directly. They can only use the pointer to the data structure as
50  * an identifier for the control interface connection and use this as one of
51  * the arguments for most of the control interface library functions.
52  */
53 struct wpa_ctrl {
54 #ifdef CONFIG_CTRL_IFACE_UDP
55 	int s;
56 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
57 	struct sockaddr_in6 local;
58 	struct sockaddr_in6 dest;
59 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
60 	struct sockaddr_in local;
61 	struct sockaddr_in dest;
62 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
63 	char *cookie;
64 	char *remote_ifname;
65 	char *remote_ip;
66 #endif /* CONFIG_CTRL_IFACE_UDP */
67 #ifdef CONFIG_CTRL_IFACE_UNIX
68 	int s;
69 	struct sockaddr_un local;
70 	struct sockaddr_un dest;
71 #endif /* CONFIG_CTRL_IFACE_UNIX */
72 #ifdef CONFIG_CTRL_IFACE_NAMED_PIPE
73 	HANDLE pipe;
74 #endif /* CONFIG_CTRL_IFACE_NAMED_PIPE */
75 };
76 
77 
78 #ifdef CONFIG_CTRL_IFACE_UNIX
79 
80 #ifndef CONFIG_CTRL_IFACE_CLIENT_DIR
81 #define CONFIG_CTRL_IFACE_CLIENT_DIR "/tmp"
82 #endif /* CONFIG_CTRL_IFACE_CLIENT_DIR */
83 #ifndef CONFIG_CTRL_IFACE_CLIENT_PREFIX
84 #define CONFIG_CTRL_IFACE_CLIENT_PREFIX "wpa_ctrl_"
85 #endif /* CONFIG_CTRL_IFACE_CLIENT_PREFIX */
86 
87 
wpa_ctrl_open(const char * ctrl_path)88 struct wpa_ctrl * wpa_ctrl_open(const char *ctrl_path)
89 {
90 	return wpa_ctrl_open2(ctrl_path, NULL);
91 }
92 
93 
wpa_ctrl_open2(const char * ctrl_path,const char * cli_path)94 struct wpa_ctrl * wpa_ctrl_open2(const char *ctrl_path,
95 				 const char *cli_path)
96 {
97 	struct wpa_ctrl *ctrl;
98 	static int counter = 0;
99 	int ret;
100 	size_t res;
101 	int tries = 0;
102 	int flags;
103 
104 	if (ctrl_path == NULL)
105 		return NULL;
106 
107 	ctrl = os_zalloc(sizeof(*ctrl));
108 	if (ctrl == NULL)
109 		return NULL;
110 
111 	ctrl->s = socket(PF_UNIX, SOCK_DGRAM, 0);
112 	if (ctrl->s < 0) {
113 		os_free(ctrl);
114 		return NULL;
115 	}
116 
117 	ctrl->local.sun_family = AF_UNIX;
118 	counter++;
119 try_again:
120 	if (cli_path && cli_path[0] == '/') {
121 		ret = os_snprintf(ctrl->local.sun_path,
122 				  sizeof(ctrl->local.sun_path),
123 				  "%s/" CONFIG_CTRL_IFACE_CLIENT_PREFIX "%d-%d",
124 				  cli_path, (int) getpid(), counter);
125 	} else {
126 		ret = os_snprintf(ctrl->local.sun_path,
127 				  sizeof(ctrl->local.sun_path),
128 				  CONFIG_CTRL_IFACE_CLIENT_DIR "/"
129 				  CONFIG_CTRL_IFACE_CLIENT_PREFIX "%d-%d",
130 				  (int) getpid(), counter);
131 	}
132 	if (os_snprintf_error(sizeof(ctrl->local.sun_path), ret)) {
133 		close(ctrl->s);
134 		os_free(ctrl);
135 		return NULL;
136 	}
137 	tries++;
138 #ifdef ANDROID
139 	/* Set client socket file permissions so that bind() creates the client
140 	 * socket with these permissions and there is no need to try to change
141 	 * them with chmod() after bind() which would have potential issues with
142 	 * race conditions. These permissions are needed to make sure the server
143 	 * side (wpa_supplicant or hostapd) can reply to the control interface
144 	 * messages.
145 	 *
146 	 * The lchown() calls below after bind() are also part of the needed
147 	 * operations to allow the response to go through. Those are using the
148 	 * no-deference-symlinks version to avoid races. */
149 	fchmod(ctrl->s, S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP);
150 #endif /* ANDROID */
151 	if (bind(ctrl->s, (struct sockaddr *) &ctrl->local,
152 		    sizeof(ctrl->local)) < 0) {
153 		if (errno == EADDRINUSE && tries < 2) {
154 			/*
155 			 * getpid() returns unique identifier for this instance
156 			 * of wpa_ctrl, so the existing socket file must have
157 			 * been left by unclean termination of an earlier run.
158 			 * Remove the file and try again.
159 			 */
160 			unlink(ctrl->local.sun_path);
161 			goto try_again;
162 		}
163 		close(ctrl->s);
164 		os_free(ctrl);
165 		return NULL;
166 	}
167 
168 #ifdef ANDROID
169 	/* Set group even if we do not have privileges to change owner */
170 	lchown(ctrl->local.sun_path, -1, AID_WIFI);
171 	lchown(ctrl->local.sun_path, AID_SYSTEM, AID_WIFI);
172 
173 	if (os_strncmp(ctrl_path, "@android:", 9) == 0) {
174 		if (socket_local_client_connect(
175 			    ctrl->s, ctrl_path + 9,
176 			    ANDROID_SOCKET_NAMESPACE_RESERVED,
177 			    SOCK_DGRAM) < 0) {
178 			close(ctrl->s);
179 			unlink(ctrl->local.sun_path);
180 			os_free(ctrl);
181 			return NULL;
182 		}
183 		return ctrl;
184 	}
185 
186 	/*
187 	 * If the ctrl_path isn't an absolute pathname, assume that
188 	 * it's the name of a socket in the Android reserved namespace.
189 	 * Otherwise, it's a normal UNIX domain socket appearing in the
190 	 * filesystem.
191 	 */
192 	if (*ctrl_path != '/') {
193 		char buf[21];
194 		os_snprintf(buf, sizeof(buf), "wpa_%s", ctrl_path);
195 		if (socket_local_client_connect(
196 			    ctrl->s, buf,
197 			    ANDROID_SOCKET_NAMESPACE_RESERVED,
198 			    SOCK_DGRAM) < 0) {
199 			close(ctrl->s);
200 			unlink(ctrl->local.sun_path);
201 			os_free(ctrl);
202 			return NULL;
203 		}
204 		return ctrl;
205 	}
206 #endif /* ANDROID */
207 
208 	ctrl->dest.sun_family = AF_UNIX;
209 	if (os_strncmp(ctrl_path, "@abstract:", 10) == 0) {
210 		ctrl->dest.sun_path[0] = '\0';
211 		os_strlcpy(ctrl->dest.sun_path + 1, ctrl_path + 10,
212 			   sizeof(ctrl->dest.sun_path) - 1);
213 	} else {
214 		res = os_strlcpy(ctrl->dest.sun_path, ctrl_path,
215 				 sizeof(ctrl->dest.sun_path));
216 		if (res >= sizeof(ctrl->dest.sun_path)) {
217 			close(ctrl->s);
218 			os_free(ctrl);
219 			return NULL;
220 		}
221 	}
222 	if (connect(ctrl->s, (struct sockaddr *) &ctrl->dest,
223 		    sizeof(ctrl->dest)) < 0) {
224 		close(ctrl->s);
225 		unlink(ctrl->local.sun_path);
226 		os_free(ctrl);
227 		return NULL;
228 	}
229 
230 	/*
231 	 * Make socket non-blocking so that we don't hang forever if
232 	 * target dies unexpectedly.
233 	 */
234 	flags = fcntl(ctrl->s, F_GETFL);
235 	if (flags >= 0) {
236 		flags |= O_NONBLOCK;
237 		if (fcntl(ctrl->s, F_SETFL, flags) < 0) {
238 			perror("fcntl(ctrl->s, O_NONBLOCK)");
239 			/* Not fatal, continue on.*/
240 		}
241 	}
242 
243 	return ctrl;
244 }
245 
246 
wpa_ctrl_close(struct wpa_ctrl * ctrl)247 void wpa_ctrl_close(struct wpa_ctrl *ctrl)
248 {
249 	if (ctrl == NULL)
250 		return;
251 	unlink(ctrl->local.sun_path);
252 	if (ctrl->s >= 0)
253 		close(ctrl->s);
254 	os_free(ctrl);
255 }
256 
257 
258 #ifdef ANDROID
259 /**
260  * wpa_ctrl_cleanup() - Delete any local UNIX domain socket files that
261  * may be left over from clients that were previously connected to
262  * wpa_supplicant. This keeps these files from being orphaned in the
263  * event of crashes that prevented them from being removed as part
264  * of the normal orderly shutdown.
265  */
wpa_ctrl_cleanup(void)266 void wpa_ctrl_cleanup(void)
267 {
268 	DIR *dir;
269 	struct dirent entry;
270 	struct dirent *result;
271 	size_t dirnamelen;
272 	size_t maxcopy;
273 	char pathname[PATH_MAX];
274 	char *namep;
275 
276 	if ((dir = opendir(CONFIG_CTRL_IFACE_CLIENT_DIR)) == NULL)
277 		return;
278 
279 	dirnamelen = (size_t) os_snprintf(pathname, sizeof(pathname), "%s/",
280 					  CONFIG_CTRL_IFACE_CLIENT_DIR);
281 	if (dirnamelen >= sizeof(pathname)) {
282 		closedir(dir);
283 		return;
284 	}
285 	namep = pathname + dirnamelen;
286 	maxcopy = PATH_MAX - dirnamelen;
287 	while (readdir_r(dir, &entry, &result) == 0 && result != NULL) {
288 		if (os_strlcpy(namep, entry.d_name, maxcopy) < maxcopy)
289 			unlink(pathname);
290 	}
291 	closedir(dir);
292 }
293 #endif /* ANDROID */
294 
295 #else /* CONFIG_CTRL_IFACE_UNIX */
296 
297 #ifdef ANDROID
wpa_ctrl_cleanup(void)298 void wpa_ctrl_cleanup(void)
299 {
300 }
301 #endif /* ANDROID */
302 
303 #endif /* CONFIG_CTRL_IFACE_UNIX */
304 
305 #if defined(CONFIG_OPEN_HARMONY_PATCH) || defined(CONFIG_OPEN_HARMONY_PATCH_LITE)
wpa_ctrl_port(const char * ctrl_path,struct wpa_ctrl * ctrl)306 int wpa_ctrl_port(const char *ctrl_path, struct wpa_ctrl *ctrl)
307 {
308 	if (ctrl_path == NULL || ctrl == NULL) {
309 		return -1;
310 	}
311 
312 	if (os_strcmp(ctrl_path, "global") == 0) {
313 		ctrl->dest.sin_port = htons(WPA_GLOBAL_CTRL_IFACE_PORT);
314 		return 0;
315 	}
316 
317 	char *port, *name;
318 	int port_id;
319 	name = os_strdup(ctrl_path);
320 	if (name == NULL) {
321 		return -1;
322 	}
323 
324 	port = os_strchr(name, ':');
325 	if (port) {
326 		port_id = atoi(&port[1]);
327 		port[0] = '\0';
328 		ctrl->dest.sin_port = htons(port_id);
329 	}
330 	os_free(name);
331 	return 0;
332 }
333 #endif /* CONFIG_OPEN_HARMONY_PATCH */
334 
335 #ifdef CONFIG_CTRL_IFACE_UDP
336 
wpa_ctrl_open(const char * ctrl_path)337 struct wpa_ctrl * wpa_ctrl_open(const char *ctrl_path)
338 {
339 	struct wpa_ctrl *ctrl;
340 	char buf[128];
341 	size_t len;
342 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
343 	struct hostent *h;
344 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
345 
346 	ctrl = os_zalloc(sizeof(*ctrl));
347 	if (ctrl == NULL)
348 		return NULL;
349 
350 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
351 	ctrl->s = socket(PF_INET6, SOCK_DGRAM, 0);
352 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
353 	ctrl->s = socket(PF_INET, SOCK_DGRAM, 0);
354 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
355 	if (ctrl->s < 0) {
356 		perror("socket");
357 		os_free(ctrl);
358 		return NULL;
359 	}
360 
361 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
362 	ctrl->local.sin6_family = AF_INET6;
363 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
364 	ctrl->local.sin6_addr = in6addr_any;
365 #else /* CONFIG_CTRL_IFACE_UDP_REMOTE */
366 	inet_pton(AF_INET6, "::1", &ctrl->local.sin6_addr);
367 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
368 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
369 	ctrl->local.sin_family = AF_INET;
370 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
371 	ctrl->local.sin_addr.s_addr = INADDR_ANY;
372 #else /* CONFIG_CTRL_IFACE_UDP_REMOTE */
373 	ctrl->local.sin_addr.s_addr = htonl((127 << 24) | 1);
374 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
375 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
376 
377 	if (bind(ctrl->s, (struct sockaddr *) &ctrl->local,
378 		 sizeof(ctrl->local)) < 0) {
379 		close(ctrl->s);
380 		os_free(ctrl);
381 		return NULL;
382 	}
383 
384 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
385 	ctrl->dest.sin6_family = AF_INET6;
386 	inet_pton(AF_INET6, "::1", &ctrl->dest.sin6_addr);
387 	ctrl->dest.sin6_port = htons(WPA_CTRL_IFACE_PORT);
388 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
389 	ctrl->dest.sin_family = AF_INET;
390 	ctrl->dest.sin_addr.s_addr = htonl((127 << 24) | 1);
391 	ctrl->dest.sin_port = htons(WPA_CTRL_IFACE_PORT);
392 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
393 
394 #if defined(CONFIG_OPEN_HARMONY_PATCH) || defined(CONFIG_OPEN_HARMONY_PATCH_LITE)
395 	if (wpa_ctrl_port(ctrl_path, ctrl) < 0) {
396 		wpa_printf(MSG_ERROR, "get port fail");
397 	}
398 #endif /* CONFIG_OPEN_HARMONY_PATCH | CONFIG_OPEN_HARMONY_PATCH_LITE */
399 
400 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
401 	if (ctrl_path) {
402 		char *port, *name;
403 		int port_id;
404 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
405 		char *scope;
406 		int scope_id = 0;
407 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
408 
409 		name = os_strdup(ctrl_path);
410 		if (name == NULL) {
411 			close(ctrl->s);
412 			os_free(ctrl);
413 			return NULL;
414 		}
415 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
416 		port = os_strchr(name, ',');
417 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
418 		port = os_strchr(name, ':');
419 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
420 
421 		if (port) {
422 			port_id = atoi(&port[1]);
423 			port[0] = '\0';
424 		} else
425 			port_id = WPA_CTRL_IFACE_PORT;
426 
427 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
428 		scope = os_strchr(name, '%');
429 		if (scope) {
430 			scope_id = if_nametoindex(&scope[1]);
431 			scope[0] = '\0';
432 		}
433 		h = gethostbyname2(name, AF_INET6);
434 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
435 		h = gethostbyname(name);
436 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
437 		ctrl->remote_ip = os_strdup(name);
438 		os_free(name);
439 		if (h == NULL) {
440 			perror("gethostbyname");
441 			close(ctrl->s);
442 			os_free(ctrl->remote_ip);
443 			os_free(ctrl);
444 			return NULL;
445 		}
446 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
447 		ctrl->dest.sin6_scope_id = scope_id;
448 		ctrl->dest.sin6_port = htons(port_id);
449 		os_memcpy(&ctrl->dest.sin6_addr, h->h_addr, h->h_length);
450 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
451 		ctrl->dest.sin_port = htons(port_id);
452 		os_memcpy(&ctrl->dest.sin_addr.s_addr, h->h_addr, h->h_length);
453 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
454 	} else
455 		ctrl->remote_ip = os_strdup("localhost");
456 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
457 
458 	if (connect(ctrl->s, (struct sockaddr *) &ctrl->dest,
459 		    sizeof(ctrl->dest)) < 0) {
460 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
461 		char addr[INET6_ADDRSTRLEN];
462 		wpa_printf(MSG_ERROR, "connect(%s:%d) failed: %s",
463 			   inet_ntop(AF_INET6, &ctrl->dest.sin6_addr, addr,
464 				     sizeof(ctrl->dest)),
465 			   ntohs(ctrl->dest.sin6_port),
466 			   strerror(errno));
467 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
468 		wpa_printf(MSG_ERROR, "connect(%s:%d) failed: %s",
469 			   inet_ntoa(ctrl->dest.sin_addr),
470 			   ntohs(ctrl->dest.sin_port),
471 			   strerror(errno));
472 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
473 		close(ctrl->s);
474 		os_free(ctrl->remote_ip);
475 		os_free(ctrl);
476 		return NULL;
477 	}
478 
479 	len = sizeof(buf) - 1;
480 	if (wpa_ctrl_request(ctrl, "GET_COOKIE", 10, buf, &len, NULL) == 0) {
481 		buf[len] = '\0';
482 		ctrl->cookie = os_strdup(buf);
483 	}
484 
485 	if (wpa_ctrl_request(ctrl, "IFNAME", 6, buf, &len, NULL) == 0) {
486 		buf[len] = '\0';
487 		ctrl->remote_ifname = os_strdup(buf);
488 	}
489 
490 	return ctrl;
491 }
492 
493 
wpa_ctrl_get_remote_ifname(struct wpa_ctrl * ctrl)494 char * wpa_ctrl_get_remote_ifname(struct wpa_ctrl *ctrl)
495 {
496 #define WPA_CTRL_MAX_PS_NAME 100
497 	static char ps[WPA_CTRL_MAX_PS_NAME] = {};
498 	os_snprintf(ps, WPA_CTRL_MAX_PS_NAME, "%s/%s",
499 		    ctrl->remote_ip, ctrl->remote_ifname);
500 	return ps;
501 }
502 
503 
wpa_ctrl_close(struct wpa_ctrl * ctrl)504 void wpa_ctrl_close(struct wpa_ctrl *ctrl)
505 {
506 	close(ctrl->s);
507 	os_free(ctrl->cookie);
508 	os_free(ctrl->remote_ifname);
509 	os_free(ctrl->remote_ip);
510 	os_free(ctrl);
511 }
512 
513 #endif /* CONFIG_CTRL_IFACE_UDP */
514 
515 
516 #ifdef CTRL_IFACE_SOCKET
wpa_ctrl_request(struct wpa_ctrl * ctrl,const char * cmd,size_t cmd_len,char * reply,size_t * reply_len,void (* msg_cb)(char * msg,size_t len))517 int wpa_ctrl_request(struct wpa_ctrl *ctrl, const char *cmd, size_t cmd_len,
518 		     char *reply, size_t *reply_len,
519 		     void (*msg_cb)(char *msg, size_t len))
520 {
521 	struct timeval tv;
522 	struct os_reltime started_at;
523 	int res;
524 	fd_set rfds;
525 	const char *_cmd;
526 	char *cmd_buf = NULL;
527 	size_t _cmd_len;
528 #ifdef CONFIG_OPEN_HARMONY_PATCH
529     wpa_printf(MSG_INFO, "wpa_ctrl_request cmd: %s", cmd);
530 #endif // CONFIG_OPEN_HARMONY_PATCH
531 
532 #ifdef CONFIG_CTRL_IFACE_UDP
533 	if (ctrl->cookie) {
534 		char *pos;
535 		_cmd_len = os_strlen(ctrl->cookie) + 1 + cmd_len;
536 		cmd_buf = os_malloc(_cmd_len);
537 		if (cmd_buf == NULL)
538 			return -1;
539 		_cmd = cmd_buf;
540 		pos = cmd_buf;
541 		os_strlcpy(pos, ctrl->cookie, _cmd_len);
542 		pos += os_strlen(ctrl->cookie);
543 		*pos++ = ' ';
544 		os_memcpy(pos, cmd, cmd_len);
545 	} else
546 #endif /* CONFIG_CTRL_IFACE_UDP */
547 	{
548 		_cmd = cmd;
549 		_cmd_len = cmd_len;
550 	}
551 
552 	errno = 0;
553 	started_at.sec = 0;
554 	started_at.usec = 0;
555 retry_send:
556 	if (send(ctrl->s, _cmd, _cmd_len, 0) < 0) {
557 		if (errno == EAGAIN || errno == EBUSY || errno == EWOULDBLOCK)
558 		{
559 			/*
560 			 * Must be a non-blocking socket... Try for a bit
561 			 * longer before giving up.
562 			 */
563 			if (started_at.sec == 0)
564 				os_get_reltime(&started_at);
565 			else {
566 				struct os_reltime n;
567 				os_get_reltime(&n);
568 				/* Try for a few seconds. */
569 				if (os_reltime_expired(&n, &started_at, 5))
570 					goto send_err;
571 			}
572 			os_sleep(1, 0);
573 			goto retry_send;
574 		}
575 	send_err:
576 		os_free(cmd_buf);
577 		return -1;
578 	}
579 	os_free(cmd_buf);
580 
581 	for (;;) {
582 		tv.tv_sec = 10;
583 		tv.tv_usec = 0;
584 		FD_ZERO(&rfds);
585 		FD_SET(ctrl->s, &rfds);
586 		res = select(ctrl->s + 1, &rfds, NULL, NULL, &tv);
587 		if (res < 0 && errno == EINTR)
588 			continue;
589 		if (res < 0)
590 			return res;
591 		if (FD_ISSET(ctrl->s, &rfds)) {
592 			res = recv(ctrl->s, reply, *reply_len, 0);
593 			if (res < 0)
594 				return res;
595 			if ((res > 0 && reply[0] == '<') ||
596 			    (res > 6 && strncmp(reply, "IFNAME=", 7) == 0)) {
597 				/* This is an unsolicited message from
598 				 * wpa_supplicant, not the reply to the
599 				 * request. Use msg_cb to report this to the
600 				 * caller. */
601 				if (msg_cb) {
602 					/* Make sure the message is nul
603 					 * terminated. */
604 					if ((size_t) res == *reply_len)
605 						res = (*reply_len) - 1;
606 					reply[res] = '\0';
607 					msg_cb(reply, res);
608 				}
609 				continue;
610 			}
611 			*reply_len = res;
612 			break;
613 		} else {
614 			return -2;
615 		}
616 	}
617 	return 0;
618 }
619 #endif /* CTRL_IFACE_SOCKET */
620 
621 
wpa_ctrl_attach_helper(struct wpa_ctrl * ctrl,int attach)622 static int wpa_ctrl_attach_helper(struct wpa_ctrl *ctrl, int attach)
623 {
624 	char buf[10];
625 	int ret;
626 	size_t len = 10;
627 
628 	ret = wpa_ctrl_request(ctrl, attach ? "ATTACH" : "DETACH", 6,
629 			       buf, &len, NULL);
630 	if (ret < 0)
631 		return ret;
632 	if (len == 3 && os_memcmp(buf, "OK\n", 3) == 0)
633 		return 0;
634 	return -1;
635 }
636 
637 
wpa_ctrl_attach(struct wpa_ctrl * ctrl)638 int wpa_ctrl_attach(struct wpa_ctrl *ctrl)
639 {
640 	return wpa_ctrl_attach_helper(ctrl, 1);
641 }
642 
643 
wpa_ctrl_detach(struct wpa_ctrl * ctrl)644 int wpa_ctrl_detach(struct wpa_ctrl *ctrl)
645 {
646 	return wpa_ctrl_attach_helper(ctrl, 0);
647 }
648 
649 
650 #ifdef CTRL_IFACE_SOCKET
651 
wpa_ctrl_recv(struct wpa_ctrl * ctrl,char * reply,size_t * reply_len)652 int wpa_ctrl_recv(struct wpa_ctrl *ctrl, char *reply, size_t *reply_len)
653 {
654 	int res;
655 
656 	res = recv(ctrl->s, reply, *reply_len, 0);
657 	if (res < 0)
658 		return res;
659 	*reply_len = res;
660 	return 0;
661 }
662 
663 
wpa_ctrl_pending(struct wpa_ctrl * ctrl)664 int wpa_ctrl_pending(struct wpa_ctrl *ctrl)
665 {
666 	struct timeval tv;
667 	fd_set rfds;
668 	tv.tv_sec = 0;
669 	tv.tv_usec = 0;
670 	FD_ZERO(&rfds);
671 	FD_SET(ctrl->s, &rfds);
672 	select(ctrl->s + 1, &rfds, NULL, NULL, &tv);
673 	return FD_ISSET(ctrl->s, &rfds);
674 }
675 
676 
wpa_ctrl_get_fd(struct wpa_ctrl * ctrl)677 int wpa_ctrl_get_fd(struct wpa_ctrl *ctrl)
678 {
679 	return ctrl->s;
680 }
681 
682 #endif /* CTRL_IFACE_SOCKET */
683 
684 
685 #ifdef CONFIG_CTRL_IFACE_NAMED_PIPE
686 
687 #ifndef WPA_SUPPLICANT_NAMED_PIPE
688 #define WPA_SUPPLICANT_NAMED_PIPE "WpaSupplicant"
689 #endif
690 #define NAMED_PIPE_PREFIX TEXT("\\\\.\\pipe\\") TEXT(WPA_SUPPLICANT_NAMED_PIPE)
691 
wpa_ctrl_open(const char * ctrl_path)692 struct wpa_ctrl * wpa_ctrl_open(const char *ctrl_path)
693 {
694 	struct wpa_ctrl *ctrl;
695 	DWORD mode;
696 	TCHAR name[256];
697 	int i, ret;
698 
699 	ctrl = os_malloc(sizeof(*ctrl));
700 	if (ctrl == NULL)
701 		return NULL;
702 	os_memset(ctrl, 0, sizeof(*ctrl));
703 
704 #ifdef UNICODE
705 	if (ctrl_path == NULL)
706 		ret = _snwprintf(name, 256, NAMED_PIPE_PREFIX);
707 	else
708 		ret = _snwprintf(name, 256, NAMED_PIPE_PREFIX TEXT("-%S"),
709 				 ctrl_path);
710 #else /* UNICODE */
711 	if (ctrl_path == NULL)
712 		ret = os_snprintf(name, 256, NAMED_PIPE_PREFIX);
713 	else
714 		ret = os_snprintf(name, 256, NAMED_PIPE_PREFIX "-%s",
715 				  ctrl_path);
716 #endif /* UNICODE */
717 	if (os_snprintf_error(256, ret)) {
718 		os_free(ctrl);
719 		return NULL;
720 	}
721 
722 	for (i = 0; i < 10; i++) {
723 		ctrl->pipe = CreateFile(name, GENERIC_READ | GENERIC_WRITE, 0,
724 					NULL, OPEN_EXISTING, 0, NULL);
725 		/*
726 		 * Current named pipe server side in wpa_supplicant is
727 		 * re-opening the pipe for new clients only after the previous
728 		 * one is taken into use. This leaves a small window for race
729 		 * conditions when two connections are being opened at almost
730 		 * the same time. Retry if that was the case.
731 		 */
732 		if (ctrl->pipe != INVALID_HANDLE_VALUE ||
733 		    GetLastError() != ERROR_PIPE_BUSY)
734 			break;
735 		WaitNamedPipe(name, 1000);
736 	}
737 	if (ctrl->pipe == INVALID_HANDLE_VALUE) {
738 		os_free(ctrl);
739 		return NULL;
740 	}
741 
742 	mode = PIPE_READMODE_MESSAGE;
743 	if (!SetNamedPipeHandleState(ctrl->pipe, &mode, NULL, NULL)) {
744 		CloseHandle(ctrl->pipe);
745 		os_free(ctrl);
746 		return NULL;
747 	}
748 
749 	return ctrl;
750 }
751 
752 
wpa_ctrl_close(struct wpa_ctrl * ctrl)753 void wpa_ctrl_close(struct wpa_ctrl *ctrl)
754 {
755 	CloseHandle(ctrl->pipe);
756 	os_free(ctrl);
757 }
758 
759 
wpa_ctrl_request(struct wpa_ctrl * ctrl,const char * cmd,size_t cmd_len,char * reply,size_t * reply_len,void (* msg_cb)(char * msg,size_t len))760 int wpa_ctrl_request(struct wpa_ctrl *ctrl, const char *cmd, size_t cmd_len,
761 		     char *reply, size_t *reply_len,
762 		     void (*msg_cb)(char *msg, size_t len))
763 {
764 	DWORD written;
765 	DWORD readlen = *reply_len;
766 
767 	if (!WriteFile(ctrl->pipe, cmd, cmd_len, &written, NULL))
768 		return -1;
769 
770 	if (!ReadFile(ctrl->pipe, reply, *reply_len, &readlen, NULL))
771 		return -1;
772 	*reply_len = readlen;
773 
774 	return 0;
775 }
776 
777 
wpa_ctrl_recv(struct wpa_ctrl * ctrl,char * reply,size_t * reply_len)778 int wpa_ctrl_recv(struct wpa_ctrl *ctrl, char *reply, size_t *reply_len)
779 {
780 	DWORD len = *reply_len;
781 	if (!ReadFile(ctrl->pipe, reply, *reply_len, &len, NULL))
782 		return -1;
783 	*reply_len = len;
784 	return 0;
785 }
786 
787 
wpa_ctrl_pending(struct wpa_ctrl * ctrl)788 int wpa_ctrl_pending(struct wpa_ctrl *ctrl)
789 {
790 	DWORD left;
791 
792 	if (!PeekNamedPipe(ctrl->pipe, NULL, 0, NULL, &left, NULL))
793 		return -1;
794 	return left ? 1 : 0;
795 }
796 
797 
wpa_ctrl_get_fd(struct wpa_ctrl * ctrl)798 int wpa_ctrl_get_fd(struct wpa_ctrl *ctrl)
799 {
800 	return -1;
801 }
802 
803 #endif /* CONFIG_CTRL_IFACE_NAMED_PIPE */
804 
805 #endif /* CONFIG_CTRL_IFACE */
806