blob: 3df753b51e89712dd2128fcbe44a0665e1d18fbd [file] [log] [blame]
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -07001/* src/p80211/p80211conv.c
2*
3* Ether/802.11 conversions and packet buffer routines
4*
5* Copyright (C) 1999 AbsoluteValue Systems, Inc. All Rights Reserved.
6* --------------------------------------------------------------------
7*
8* linux-wlan
9*
10* The contents of this file are subject to the Mozilla Public
11* License Version 1.1 (the "License"); you may not use this file
12* except in compliance with the License. You may obtain a copy of
13* the License at http://www.mozilla.org/MPL/
14*
15* Software distributed under the License is distributed on an "AS
16* IS" basis, WITHOUT WARRANTY OF ANY KIND, either express or
17* implied. See the License for the specific language governing
18* rights and limitations under the License.
19*
20* Alternatively, the contents of this file may be used under the
21* terms of the GNU Public License version 2 (the "GPL"), in which
22* case the provisions of the GPL are applicable instead of the
23* above. If you wish to allow the use of your version of this file
24* only under the terms of the GPL and not to allow others to use
25* your version of this file under the MPL, indicate your decision
26* by deleting the provisions above and replace them with the notice
27* and other provisions required by the GPL. If you do not delete
28* the provisions above, a recipient may use your version of this
29* file under either the MPL or the GPL.
30*
31* --------------------------------------------------------------------
32*
33* Inquiries regarding the linux-wlan Open Source project can be
34* made directly to:
35*
36* AbsoluteValue Systems Inc.
37* info@linux-wlan.com
38* http://www.linux-wlan.com
39*
40* --------------------------------------------------------------------
41*
42* Portions of the development of this software were funded by
43* Intersil Corporation as part of PRISM(R) chipset product development.
44*
45* --------------------------------------------------------------------
46*
47* This file defines the functions that perform Ethernet to/from
48* 802.11 frame conversions.
49*
50* --------------------------------------------------------------------
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +010051*
52*================================================================ */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -070053
54#include <linux/module.h>
55#include <linux/kernel.h>
56#include <linux/sched.h>
57#include <linux/types.h>
58#include <linux/skbuff.h>
59#include <linux/slab.h>
60#include <linux/wireless.h>
61#include <linux/netdevice.h>
62#include <linux/etherdevice.h>
63#include <linux/if_ether.h>
Moritz Muehlenhoffae262302009-01-21 22:00:45 +010064#include <linux/byteorder/generic.h>
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -070065
66#include <asm/byteorder.h>
67
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -070068#include "p80211types.h"
69#include "p80211hdr.h"
70#include "p80211conv.h"
71#include "p80211mgmt.h"
72#include "p80211msg.h"
73#include "p80211netdev.h"
74#include "p80211ioctl.h"
75#include "p80211req.h"
76
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +010077static u8 oui_rfc1042[] = { 0x00, 0x00, 0x00 };
78static u8 oui_8021h[] = { 0x00, 0x00, 0xf8 };
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -070079
80/*----------------------------------------------------------------
81* p80211pb_ether_to_80211
82*
83* Uses the contents of the ether frame and the etherconv setting
84* to build the elements of the 802.11 frame.
85*
86* We don't actually set
87* up the frame header here. That's the MAC's job. We're only handling
88* conversion of DIXII or 802.3+LLC frames to something that works
89* with 802.11.
90*
91* Note -- 802.11 header is NOT part of the skb. Likewise, the 802.11
92* FCS is also not present and will need to be added elsewhere.
93*
94* Arguments:
95* ethconv Conversion type to perform
96* skb skbuff containing the ether frame
97* p80211_hdr 802.11 header
98*
99* Returns:
100* 0 on success, non-zero otherwise
101*
102* Call context:
103* May be called in interrupt or non-interrupt context
104----------------------------------------------------------------*/
Mithlesh Thukral297f06c2009-06-10 19:36:11 +0530105int skb_ether_to_p80211(wlandevice_t *wlandev, u32 ethconv,
Edgardo Hames93df38e2010-07-30 22:51:55 -0300106 struct sk_buff *skb, union p80211_hdr *p80211_hdr,
Edgardo Hames51e48962010-07-31 13:06:52 -0300107 struct p80211_metawep *p80211_wep)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700108{
109
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100110 u16 fc;
111 u16 proto;
Edgardo Hames51e48962010-07-31 13:06:52 -0300112 struct wlan_ethhdr e_hdr;
113 struct wlan_llc *e_llc;
114 struct wlan_snap *e_snap;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700115 int foo;
116
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700117 memcpy(&e_hdr, skb->data, sizeof(e_hdr));
118
119 if (skb->len <= 0) {
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100120 pr_debug("zero-length skb!\n");
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700121 return 1;
122 }
123
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100124 if (ethconv == WLAN_ETHCONV_ENCAP) { /* simplest case */
125 pr_debug("ENCAP len: %d\n", skb->len);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700126 /* here, we don't care what kind of ether frm. Just stick it */
127 /* in the 80211 payload */
128 /* which is to say, leave the skb alone. */
129 } else {
130 /* step 1: classify ether frame, DIX or 802.3? */
131 proto = ntohs(e_hdr.type);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100132 if (proto <= 1500) {
133 pr_debug("802.3 len: %d\n", skb->len);
134 /* codes <= 1500 reserved for 802.3 lengths */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700135 /* it's 802.3, pass ether payload unchanged, */
136
137 /* trim off ethernet header */
138 skb_pull(skb, WLAN_ETHHDR_LEN);
139
140 /* leave off any PAD octets. */
141 skb_trim(skb, proto);
142 } else {
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100143 pr_debug("DIXII len: %d\n", skb->len);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700144 /* it's DIXII, time for some conversion */
145
146 /* trim off ethernet header */
147 skb_pull(skb, WLAN_ETHHDR_LEN);
148
149 /* tack on SNAP */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100150 e_snap =
Johan Meiring4eb28f72010-11-06 15:46:54 +0200151 (struct wlan_snap *) skb_push(skb,
152 sizeof(struct wlan_snap));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700153 e_snap->type = htons(proto);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100154 if (ethconv == WLAN_ETHCONV_8021h
155 && p80211_stt_findproto(proto)) {
156 memcpy(e_snap->oui, oui_8021h,
157 WLAN_IEEE_OUI_LEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700158 } else {
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100159 memcpy(e_snap->oui, oui_rfc1042,
160 WLAN_IEEE_OUI_LEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700161 }
162
163 /* tack on llc */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100164 e_llc =
Johan Meiring4eb28f72010-11-06 15:46:54 +0200165 (struct wlan_llc *) skb_push(skb,
166 sizeof(struct wlan_llc));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700167 e_llc->dsap = 0xAA; /* SNAP, see IEEE 802 */
168 e_llc->ssap = 0xAA;
169 e_llc->ctl = 0x03;
170
171 }
172 }
173
174 /* Set up the 802.11 header */
175 /* It's a data frame */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100176 fc = cpu_to_le16(WLAN_SET_FC_FTYPE(WLAN_FTYPE_DATA) |
177 WLAN_SET_FC_FSTYPE(WLAN_FSTYPE_DATAONLY));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700178
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100179 switch (wlandev->macmode) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700180 case WLAN_MACMODE_IBSS_STA:
Moritz Muehlenhoff28b17a42009-01-21 22:00:41 +0100181 memcpy(p80211_hdr->a3.a1, &e_hdr.daddr, ETH_ALEN);
182 memcpy(p80211_hdr->a3.a2, wlandev->netdev->dev_addr, ETH_ALEN);
183 memcpy(p80211_hdr->a3.a3, wlandev->bssid, ETH_ALEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700184 break;
185 case WLAN_MACMODE_ESS_STA:
Moritz Muehlenhoffae262302009-01-21 22:00:45 +0100186 fc |= cpu_to_le16(WLAN_SET_FC_TODS(1));
Moritz Muehlenhoff28b17a42009-01-21 22:00:41 +0100187 memcpy(p80211_hdr->a3.a1, wlandev->bssid, ETH_ALEN);
188 memcpy(p80211_hdr->a3.a2, wlandev->netdev->dev_addr, ETH_ALEN);
189 memcpy(p80211_hdr->a3.a3, &e_hdr.daddr, ETH_ALEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700190 break;
191 case WLAN_MACMODE_ESS_AP:
Moritz Muehlenhoffae262302009-01-21 22:00:45 +0100192 fc |= cpu_to_le16(WLAN_SET_FC_FROMDS(1));
Moritz Muehlenhoff28b17a42009-01-21 22:00:41 +0100193 memcpy(p80211_hdr->a3.a1, &e_hdr.daddr, ETH_ALEN);
194 memcpy(p80211_hdr->a3.a2, wlandev->bssid, ETH_ALEN);
195 memcpy(p80211_hdr->a3.a3, &e_hdr.saddr, ETH_ALEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700196 break;
197 default:
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100198 printk(KERN_ERR
199 "Error: Converting eth to wlan in unknown mode.\n");
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700200 return 1;
201 break;
202 }
203
204 p80211_wep->data = NULL;
205
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100206 if ((wlandev->hostwep & HOSTWEP_PRIVACYINVOKED)
207 && (wlandev->hostwep & HOSTWEP_ENCRYPT)) {
208 /* XXXX need to pick keynum other than default? */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700209
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700210 p80211_wep->data = kmalloc(skb->len, GFP_ATOMIC);
Svenne Krap5dd8acc2010-02-14 18:59:00 +0100211 foo = wep_encrypt(wlandev, skb->data, p80211_wep->data,
Greg Kroah-Hartmanb02957d2010-03-04 08:14:54 -0800212 skb->len,
Ruslan Pisarev5813b622010-03-15 21:27:42 +0200213 (wlandev->hostwep & HOSTWEP_DEFAULTKEY_MASK),
Andrew Elwell3f4b4e72010-02-18 23:56:13 +0100214 p80211_wep->iv, p80211_wep->icv);
Svenne Krap5dd8acc2010-02-14 18:59:00 +0100215 if (foo) {
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100216 printk(KERN_WARNING
217 "Host en-WEP failed, dropping frame (%d).\n",
218 foo);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700219 return 2;
220 }
Moritz Muehlenhoffae262302009-01-21 22:00:45 +0100221 fc |= cpu_to_le16(WLAN_SET_FC_ISWEP(1));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700222 }
223
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100224 /* skb->nh.raw = skb->data; */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700225
226 p80211_hdr->a3.fc = fc;
227 p80211_hdr->a3.dur = 0;
228 p80211_hdr->a3.seq = 0;
229
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700230 return 0;
231}
232
233/* jkriegl: from orinoco, modified */
Mithlesh Thukral297f06c2009-06-10 19:36:11 +0530234static void orinoco_spy_gather(wlandevice_t *wlandev, char *mac,
Edgardo Hames51e48962010-07-31 13:06:52 -0300235 struct p80211_rxmeta *rxmeta)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700236{
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100237 int i;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700238
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100239 /* Gather wireless spy statistics: for each packet, compare the
240 * source address with out list, and if match, get the stats... */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700241
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100242 for (i = 0; i < wlandev->spy_number; i++) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700243
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100244 if (!memcmp(wlandev->spy_address[i], mac, ETH_ALEN)) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700245 memcpy(wlandev->spy_address[i], mac, ETH_ALEN);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100246 wlandev->spy_stat[i].level = rxmeta->signal;
247 wlandev->spy_stat[i].noise = rxmeta->noise;
248 wlandev->spy_stat[i].qual =
249 (rxmeta->signal >
250 rxmeta->noise) ? (rxmeta->signal -
251 rxmeta->noise) : 0;
252 wlandev->spy_stat[i].updated = 0x7;
253 }
254 }
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700255}
256
257/*----------------------------------------------------------------
258* p80211pb_80211_to_ether
259*
260* Uses the contents of a received 802.11 frame and the etherconv
261* setting to build an ether frame.
262*
263* This function extracts the src and dest address from the 802.11
264* frame to use in the construction of the eth frame.
265*
266* Arguments:
267* ethconv Conversion type to perform
268* skb Packet buffer containing the 802.11 frame
269*
270* Returns:
271* 0 on success, non-zero otherwise
272*
273* Call context:
274* May be called in interrupt or non-interrupt context
275----------------------------------------------------------------*/
Mithlesh Thukral297f06c2009-06-10 19:36:11 +0530276int skb_p80211_to_ether(wlandevice_t *wlandev, u32 ethconv,
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100277 struct sk_buff *skb)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700278{
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100279 netdevice_t *netdev = wlandev->netdev;
280 u16 fc;
281 unsigned int payload_length;
282 unsigned int payload_offset;
283 u8 daddr[WLAN_ETHADDR_LEN];
284 u8 saddr[WLAN_ETHADDR_LEN];
Edgardo Hames93df38e2010-07-30 22:51:55 -0300285 union p80211_hdr *w_hdr;
Edgardo Hames51e48962010-07-31 13:06:52 -0300286 struct wlan_ethhdr *e_hdr;
287 struct wlan_llc *e_llc;
288 struct wlan_snap *e_snap;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700289
290 int foo;
291
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700292 payload_length = skb->len - WLAN_HDR_A3_LEN - WLAN_CRC_LEN;
293 payload_offset = WLAN_HDR_A3_LEN;
294
Edgardo Hames93df38e2010-07-30 22:51:55 -0300295 w_hdr = (union p80211_hdr *) skb->data;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700296
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100297 /* setup some vars for convenience */
Moritz Muehlenhoffae262302009-01-21 22:00:45 +0100298 fc = le16_to_cpu(w_hdr->a3.fc);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100299 if ((WLAN_GET_FC_TODS(fc) == 0) && (WLAN_GET_FC_FROMDS(fc) == 0)) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700300 memcpy(daddr, w_hdr->a3.a1, WLAN_ETHADDR_LEN);
301 memcpy(saddr, w_hdr->a3.a2, WLAN_ETHADDR_LEN);
Johan Meiring4eb28f72010-11-06 15:46:54 +0200302 } else if ((WLAN_GET_FC_TODS(fc) == 0)
303 && (WLAN_GET_FC_FROMDS(fc) == 1)) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700304 memcpy(daddr, w_hdr->a3.a1, WLAN_ETHADDR_LEN);
305 memcpy(saddr, w_hdr->a3.a3, WLAN_ETHADDR_LEN);
Johan Meiring4eb28f72010-11-06 15:46:54 +0200306 } else if ((WLAN_GET_FC_TODS(fc) == 1)
307 && (WLAN_GET_FC_FROMDS(fc) == 0)) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700308 memcpy(daddr, w_hdr->a3.a3, WLAN_ETHADDR_LEN);
309 memcpy(saddr, w_hdr->a3.a2, WLAN_ETHADDR_LEN);
310 } else {
311 payload_offset = WLAN_HDR_A4_LEN;
Roel Kluin1f9e9ce2008-12-03 00:06:39 +0100312 if (payload_length < WLAN_HDR_A4_LEN - WLAN_HDR_A3_LEN) {
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100313 printk(KERN_ERR "A4 frame too short!\n");
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700314 return 1;
315 }
Roel Kluin1f9e9ce2008-12-03 00:06:39 +0100316 payload_length -= (WLAN_HDR_A4_LEN - WLAN_HDR_A3_LEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700317 memcpy(daddr, w_hdr->a4.a3, WLAN_ETHADDR_LEN);
318 memcpy(saddr, w_hdr->a4.a4, WLAN_ETHADDR_LEN);
319 }
320
321 /* perform de-wep if necessary.. */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100322 if ((wlandev->hostwep & HOSTWEP_PRIVACYINVOKED) && WLAN_GET_FC_ISWEP(fc)
323 && (wlandev->hostwep & HOSTWEP_DECRYPT)) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700324 if (payload_length <= 8) {
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100325 printk(KERN_ERR "WEP frame too short (%u).\n",
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100326 skb->len);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700327 return 1;
328 }
Svenne Krap5dd8acc2010-02-14 18:59:00 +0100329 foo = wep_decrypt(wlandev, skb->data + payload_offset + 4,
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700330 payload_length - 8, -1,
331 skb->data + payload_offset,
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100332 skb->data + payload_offset +
Andrew Elwell3f4b4e72010-02-18 23:56:13 +0100333 payload_length - 4);
Svenne Krap5dd8acc2010-02-14 18:59:00 +0100334 if (foo) {
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700335 /* de-wep failed, drop skb. */
Mithlesh Thukral75f49e02009-05-25 19:06:16 +0530336 pr_debug("Host de-WEP failed, dropping frame (%d).\n",
337 foo);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700338 wlandev->rx.decrypt_err++;
339 return 2;
340 }
341
342 /* subtract the IV+ICV length off the payload */
343 payload_length -= 8;
344 /* chop off the IV */
345 skb_pull(skb, 4);
346 /* chop off the ICV. */
347 skb_trim(skb, skb->len - 4);
348
349 wlandev->rx.decrypt++;
350 }
351
Edgardo Hames51e48962010-07-31 13:06:52 -0300352 e_hdr = (struct wlan_ethhdr *) (skb->data + payload_offset);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700353
Edgardo Hames51e48962010-07-31 13:06:52 -0300354 e_llc = (struct wlan_llc *) (skb->data + payload_offset);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100355 e_snap =
Johan Meiring4eb28f72010-11-06 15:46:54 +0200356 (struct wlan_snap *) (skb->data + payload_offset +
357 sizeof(struct wlan_llc));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700358
359 /* Test for the various encodings */
Edgardo Hames51e48962010-07-31 13:06:52 -0300360 if ((payload_length >= sizeof(struct wlan_ethhdr)) &&
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100361 (e_llc->dsap != 0xaa || e_llc->ssap != 0xaa) &&
362 ((memcmp(daddr, e_hdr->daddr, WLAN_ETHADDR_LEN) == 0) ||
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700363 (memcmp(saddr, e_hdr->saddr, WLAN_ETHADDR_LEN) == 0))) {
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100364 pr_debug("802.3 ENCAP len: %d\n", payload_length);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700365 /* 802.3 Encapsulated */
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000366 /* Test for an overlength frame */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100367 if (payload_length > (netdev->mtu + WLAN_ETHHDR_LEN)) {
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000368 /* A bogus length ethfrm has been encap'd. */
369 /* Is someone trying an oflow attack? */
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100370 printk(KERN_ERR "ENCAP frame too large (%d > %d)\n",
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100371 payload_length, netdev->mtu + WLAN_ETHHDR_LEN);
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000372 return 1;
373 }
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700374
375 /* Chop off the 802.11 header. it's already sane. */
376 skb_pull(skb, payload_offset);
377 /* chop off the 802.11 CRC */
378 skb_trim(skb, skb->len - WLAN_CRC_LEN);
379
Johan Meiring4eb28f72010-11-06 15:46:54 +0200380 } else if ((payload_length >= sizeof(struct wlan_llc) +
381 sizeof(struct wlan_snap))
Adam Thompsone80528b2011-01-29 02:08:50 -0500382 && (e_llc->dsap == 0xaa)
Johan Meiring4eb28f72010-11-06 15:46:54 +0200383 && (e_llc->ssap == 0xaa)
384 && (e_llc->ctl == 0x03)
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100385 &&
386 (((memcmp(e_snap->oui, oui_rfc1042, WLAN_IEEE_OUI_LEN) == 0)
387 && (ethconv == WLAN_ETHCONV_8021h)
388 && (p80211_stt_findproto(le16_to_cpu(e_snap->type))))
389 || (memcmp(e_snap->oui, oui_rfc1042, WLAN_IEEE_OUI_LEN) !=
390 0))) {
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100391 pr_debug("SNAP+RFC1042 len: %d\n", payload_length);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700392 /* it's a SNAP + RFC1042 frame && protocol is in STT */
393 /* build 802.3 + RFC1042 */
394
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000395 /* Test for an overlength frame */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100396 if (payload_length > netdev->mtu) {
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000397 /* A bogus length ethfrm has been sent. */
398 /* Is someone trying an oflow attack? */
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100399 printk(KERN_ERR "SNAP frame too large (%d > %d)\n",
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100400 payload_length, netdev->mtu);
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000401 return 1;
402 }
403
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700404 /* chop 802.11 header from skb. */
405 skb_pull(skb, payload_offset);
406
407 /* create 802.3 header at beginning of skb. */
Edgardo Hames51e48962010-07-31 13:06:52 -0300408 e_hdr = (struct wlan_ethhdr *) skb_push(skb, WLAN_ETHHDR_LEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700409 memcpy(e_hdr->daddr, daddr, WLAN_ETHADDR_LEN);
410 memcpy(e_hdr->saddr, saddr, WLAN_ETHADDR_LEN);
411 e_hdr->type = htons(payload_length);
412
413 /* chop off the 802.11 CRC */
414 skb_trim(skb, skb->len - WLAN_CRC_LEN);
415
Johan Meiring4eb28f72010-11-06 15:46:54 +0200416 } else if ((payload_length >= sizeof(struct wlan_llc) +
417 sizeof(struct wlan_snap))
Adam Thompsone80528b2011-01-29 02:08:50 -0500418 && (e_llc->dsap == 0xaa)
Johan Meiring4eb28f72010-11-06 15:46:54 +0200419 && (e_llc->ssap == 0xaa)
420 && (e_llc->ctl == 0x03)) {
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100421 pr_debug("802.1h/RFC1042 len: %d\n", payload_length);
Johan Meiring4eb28f72010-11-06 15:46:54 +0200422 /* it's an 802.1h frame || (an RFC1042 && protocol not in STT)
423 build a DIXII + RFC894 */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700424
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000425 /* Test for an overlength frame */
Johan Meiring4eb28f72010-11-06 15:46:54 +0200426 if ((payload_length - sizeof(struct wlan_llc) -
427 sizeof(struct wlan_snap))
428 > netdev->mtu) {
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000429 /* A bogus length ethfrm has been sent. */
430 /* Is someone trying an oflow attack? */
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100431 printk(KERN_ERR "DIXII frame too large (%ld > %d)\n",
Johan Meiring4eb28f72010-11-06 15:46:54 +0200432 (long int)(payload_length -
433 sizeof(struct wlan_llc) -
434 sizeof(struct wlan_snap)), netdev->mtu);
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000435 return 1;
436 }
437
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700438 /* chop 802.11 header from skb. */
439 skb_pull(skb, payload_offset);
440
441 /* chop llc header from skb. */
Edgardo Hames51e48962010-07-31 13:06:52 -0300442 skb_pull(skb, sizeof(struct wlan_llc));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700443
444 /* chop snap header from skb. */
Edgardo Hames51e48962010-07-31 13:06:52 -0300445 skb_pull(skb, sizeof(struct wlan_snap));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700446
447 /* create 802.3 header at beginning of skb. */
Edgardo Hames51e48962010-07-31 13:06:52 -0300448 e_hdr = (struct wlan_ethhdr *) skb_push(skb, WLAN_ETHHDR_LEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700449 e_hdr->type = e_snap->type;
450 memcpy(e_hdr->daddr, daddr, WLAN_ETHADDR_LEN);
451 memcpy(e_hdr->saddr, saddr, WLAN_ETHADDR_LEN);
452
453 /* chop off the 802.11 CRC */
454 skb_trim(skb, skb->len - WLAN_CRC_LEN);
455 } else {
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100456 pr_debug("NON-ENCAP len: %d\n", payload_length);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700457 /* any NON-ENCAP */
458 /* it's a generic 80211+LLC or IPX 'Raw 802.3' */
459 /* build an 802.3 frame */
460 /* allocate space and setup hostbuf */
461
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000462 /* Test for an overlength frame */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100463 if (payload_length > netdev->mtu) {
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000464 /* A bogus length ethfrm has been sent. */
465 /* Is someone trying an oflow attack? */
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100466 printk(KERN_ERR "OTHER frame too large (%d > %d)\n",
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100467 payload_length, netdev->mtu);
Richard Kennedy33ce0ca2008-11-03 11:24:54 +0000468 return 1;
469 }
470
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700471 /* Chop off the 802.11 header. */
472 skb_pull(skb, payload_offset);
473
474 /* create 802.3 header at beginning of skb. */
Edgardo Hames51e48962010-07-31 13:06:52 -0300475 e_hdr = (struct wlan_ethhdr *) skb_push(skb, WLAN_ETHHDR_LEN);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700476 memcpy(e_hdr->daddr, daddr, WLAN_ETHADDR_LEN);
477 memcpy(e_hdr->saddr, saddr, WLAN_ETHADDR_LEN);
478 e_hdr->type = htons(payload_length);
479
480 /* chop off the 802.11 CRC */
481 skb_trim(skb, skb->len - WLAN_CRC_LEN);
482
483 }
484
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100485 /*
486 * Note that eth_type_trans() expects an skb w/ skb->data pointing
487 * at the MAC header, it then sets the following skb members:
488 * skb->mac_header,
489 * skb->data, and
490 * skb->pkt_type.
491 * It then _returns_ the value that _we're_ supposed to stuff in
492 * skb->protocol. This is nuts.
493 */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700494 skb->protocol = eth_type_trans(skb, netdev);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700495
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100496 /* jkriegl: process signal and noise as set in hfa384x_int_rx() */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700497 /* jkriegl: only process signal/noise if requested by iwspy */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100498 if (wlandev->spy_number)
499 orinoco_spy_gather(wlandev, eth_hdr(skb)->h_source,
500 P80211SKB_RXMETA(skb));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700501
502 /* Free the metadata */
503 p80211skb_rxmeta_detach(skb);
504
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700505 return 0;
506}
507
508/*----------------------------------------------------------------
509* p80211_stt_findproto
510*
511* Searches the 802.1h Selective Translation Table for a given
512* protocol.
513*
514* Arguments:
515* proto protocl number (in host order) to search for.
516*
517* Returns:
518* 1 - if the table is empty or a match is found.
519* 0 - if the table is non-empty and a match is not found.
520*
521* Call context:
522* May be called in interrupt or non-interrupt context
523----------------------------------------------------------------*/
Solomon Peachyaaad4302008-10-29 10:42:53 -0400524int p80211_stt_findproto(u16 proto)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700525{
526 /* Always return found for now. This is the behavior used by the */
527 /* Zoom Win95 driver when 802.1h mode is selected */
528 /* TODO: If necessary, add an actual search we'll probably
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100529 need this to match the CMAC's way of doing things.
530 Need to do some testing to confirm.
531 */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700532
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100533 if (proto == 0x80f3) /* APPLETALK */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700534 return 1;
535
536 return 0;
537}
538
539/*----------------------------------------------------------------
540* p80211skb_rxmeta_detach
541*
542* Disconnects the frmmeta and rxmeta from an skb.
543*
544* Arguments:
545* wlandev The wlandev this skb belongs to.
546* skb The skb we're attaching to.
547*
548* Returns:
549* 0 on success, non-zero otherwise
550*
551* Call context:
552* May be called in interrupt or non-interrupt context
553----------------------------------------------------------------*/
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100554void p80211skb_rxmeta_detach(struct sk_buff *skb)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700555{
Edgardo Hames51e48962010-07-31 13:06:52 -0300556 struct p80211_rxmeta *rxmeta;
557 struct p80211_frmmeta *frmmeta;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700558
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700559 /* Sanity checks */
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100560 if (skb == NULL) { /* bad skb */
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100561 pr_debug("Called w/ null skb.\n");
Devendra Naga311e24f2012-09-09 18:40:59 +0530562 return;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700563 }
564 frmmeta = P80211SKB_FRMMETA(skb);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100565 if (frmmeta == NULL) { /* no magic */
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100566 pr_debug("Called w/ bad frmmeta magic.\n");
Devendra Naga311e24f2012-09-09 18:40:59 +0530567 return;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700568 }
569 rxmeta = frmmeta->rx;
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100570 if (rxmeta == NULL) { /* bad meta ptr */
Moritz Muehlenhoffa7cf7ba2009-02-08 02:01:00 +0100571 pr_debug("Called w/ bad rxmeta ptr.\n");
Devendra Naga311e24f2012-09-09 18:40:59 +0530572 return;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700573 }
574
575 /* Free rxmeta */
576 kfree(rxmeta);
577
578 /* Clear skb->cb */
579 memset(skb->cb, 0, sizeof(skb->cb));
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700580}
581
582/*----------------------------------------------------------------
583* p80211skb_rxmeta_attach
584*
585* Allocates a p80211rxmeta structure, initializes it, and attaches
586* it to an skb.
587*
588* Arguments:
589* wlandev The wlandev this skb belongs to.
590* skb The skb we're attaching to.
591*
592* Returns:
593* 0 on success, non-zero otherwise
594*
595* Call context:
596* May be called in interrupt or non-interrupt context
597----------------------------------------------------------------*/
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100598int p80211skb_rxmeta_attach(struct wlandevice *wlandev, struct sk_buff *skb)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700599{
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100600 int result = 0;
Edgardo Hames51e48962010-07-31 13:06:52 -0300601 struct p80211_rxmeta *rxmeta;
602 struct p80211_frmmeta *frmmeta;
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700603
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700604 /* If these already have metadata, we error out! */
605 if (P80211SKB_RXMETA(skb) != NULL) {
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100606 printk(KERN_ERR "%s: RXmeta already attached!\n",
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100607 wlandev->name);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700608 result = 0;
609 goto exit;
610 }
611
612 /* Allocate the rxmeta */
Edgardo Hames51e48962010-07-31 13:06:52 -0300613 rxmeta = kzalloc(sizeof(struct p80211_rxmeta), GFP_ATOMIC);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700614
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100615 if (rxmeta == NULL) {
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100616 printk(KERN_ERR "%s: Failed to allocate rxmeta.\n",
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100617 wlandev->name);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700618 result = 1;
619 goto exit;
620 }
621
622 /* Initialize the rxmeta */
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700623 rxmeta->wlandev = wlandev;
624 rxmeta->hosttime = jiffies;
625
626 /* Overlay a frmmeta_t onto skb->cb */
Edgardo Hames51e48962010-07-31 13:06:52 -0300627 memset(skb->cb, 0, sizeof(struct p80211_frmmeta));
628 frmmeta = (struct p80211_frmmeta *) (skb->cb);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700629 frmmeta->magic = P80211_FRMMETA_MAGIC;
630 frmmeta->rx = rxmeta;
631exit:
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700632 return result;
633}
634
635/*----------------------------------------------------------------
636* p80211skb_free
637*
638* Frees an entire p80211skb by checking and freeing the meta struct
639* and then freeing the skb.
640*
641* Arguments:
642* wlandev The wlandev this skb belongs to.
643* skb The skb we're attaching to.
644*
645* Returns:
646* 0 on success, non-zero otherwise
647*
648* Call context:
649* May be called in interrupt or non-interrupt context
650----------------------------------------------------------------*/
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100651void p80211skb_free(struct wlandevice *wlandev, struct sk_buff *skb)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700652{
Edgardo Hames51e48962010-07-31 13:06:52 -0300653 struct p80211_frmmeta *meta;
Moritz Muehlenhoff8a251b52009-01-21 22:00:44 +0100654
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700655 meta = P80211SKB_FRMMETA(skb);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100656 if (meta && meta->rx)
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700657 p80211skb_rxmeta_detach(skb);
Moritz Muehlenhoff82eaca72009-02-08 02:20:56 +0100658 else
Moritz Muehlenhoffedbd6062009-01-25 21:55:00 +0100659 printk(KERN_ERR "Freeing an skb (%p) w/ no frmmeta.\n", skb);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700660 dev_kfree_skb(skb);
Greg Kroah-Hartman00b3ed12008-10-02 11:29:28 -0700661}