Thomas Gleixner | d2912cb | 2019-06-04 10:11:33 +0200 | [diff] [blame] | 1 | /* SPDX-License-Identifier: GPL-2.0-only */ |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 2 | /* |
| 3 | * Copyright 2002-2004, Instant802 Networks, Inc. |
| 4 | * Copyright 2005, Devicescape Software, Inc. |
Lior Cohen | 624ff4b | 2019-08-30 14:24:49 +0300 | [diff] [blame] | 5 | * Copyright (C) 2019 Intel Corporation |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 6 | */ |
| 7 | |
| 8 | #ifndef IEEE80211_KEY_H |
| 9 | #define IEEE80211_KEY_H |
| 10 | |
| 11 | #include <linux/types.h> |
Johannes Berg | 8f37171 | 2007-08-28 17:01:54 -0400 | [diff] [blame] | 12 | #include <linux/list.h> |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 13 | #include <linux/crypto.h> |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 14 | #include <linux/rcupdate.h> |
Ard Biesheuvel | 5fdb373 | 2019-06-12 18:19:54 +0200 | [diff] [blame] | 15 | #include <crypto/arc4.h> |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 16 | #include <net/mac80211.h> |
| 17 | |
Johannes Berg | e31b821 | 2010-10-05 19:39:30 +0200 | [diff] [blame] | 18 | #define NUM_DEFAULT_KEYS 4 |
| 19 | #define NUM_DEFAULT_MGMT_KEYS 2 |
Alexander Wetzel | 96fc6ef | 2019-03-19 21:34:08 +0100 | [diff] [blame] | 20 | #define INVALID_PTK_KEYIDX 2 /* Keyidx always pointing to a NULL key for PTK */ |
Johannes Berg | e31b821 | 2010-10-05 19:39:30 +0200 | [diff] [blame] | 21 | |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 22 | struct ieee80211_local; |
| 23 | struct ieee80211_sub_if_data; |
| 24 | struct sta_info; |
| 25 | |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 26 | /** |
| 27 | * enum ieee80211_internal_key_flags - internal key flags |
| 28 | * |
| 29 | * @KEY_FLAG_UPLOADED_TO_HARDWARE: Indicates that this key is present |
| 30 | * in the hardware for TX crypto hardware acceleration. |
Johannes Berg | 95acac6 | 2011-07-12 12:30:59 +0200 | [diff] [blame] | 31 | * @KEY_FLAG_TAINTED: Key is tainted and packets should be dropped. |
Cedric Izoard | c7ef38e | 2015-03-17 10:47:33 +0000 | [diff] [blame] | 32 | * @KEY_FLAG_CIPHER_SCHEME: This key is for a hardware cipher scheme |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 33 | */ |
| 34 | enum ieee80211_internal_key_flags { |
| 35 | KEY_FLAG_UPLOADED_TO_HARDWARE = BIT(0), |
Johannes Berg | 95acac6 | 2011-07-12 12:30:59 +0200 | [diff] [blame] | 36 | KEY_FLAG_TAINTED = BIT(1), |
Cedric Izoard | c7ef38e | 2015-03-17 10:47:33 +0000 | [diff] [blame] | 37 | KEY_FLAG_CIPHER_SCHEME = BIT(2), |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 38 | }; |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 39 | |
gregor kowski | ca99861 | 2009-12-09 23:25:05 +0100 | [diff] [blame] | 40 | enum ieee80211_internal_tkip_state { |
| 41 | TKIP_STATE_NOT_INIT, |
| 42 | TKIP_STATE_PHASE1_DONE, |
| 43 | TKIP_STATE_PHASE1_HW_UPLOADED, |
| 44 | }; |
| 45 | |
Harvey Harrison | b0f76b3 | 2008-05-14 16:26:19 -0700 | [diff] [blame] | 46 | struct tkip_ctx { |
Johannes Berg | 523b02e | 2011-07-07 22:28:01 +0200 | [diff] [blame] | 47 | u16 p1k[5]; /* p1k cache */ |
| 48 | u32 p1k_iv32; /* iv32 for which p1k computed */ |
gregor kowski | ca99861 | 2009-12-09 23:25:05 +0100 | [diff] [blame] | 49 | enum ieee80211_internal_tkip_state state; |
Harvey Harrison | b0f76b3 | 2008-05-14 16:26:19 -0700 | [diff] [blame] | 50 | }; |
| 51 | |
Eliad Peller | f8079d4 | 2016-02-14 13:56:35 +0200 | [diff] [blame] | 52 | struct tkip_ctx_rx { |
| 53 | struct tkip_ctx ctx; |
| 54 | u32 iv32; /* current iv32 */ |
| 55 | u16 iv16; /* current iv16 */ |
| 56 | }; |
| 57 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 58 | struct ieee80211_key { |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 59 | struct ieee80211_local *local; |
| 60 | struct ieee80211_sub_if_data *sdata; |
| 61 | struct sta_info *sta; |
| 62 | |
Johannes Berg | 3b96766 | 2008-04-08 17:56:52 +0200 | [diff] [blame] | 63 | /* for sdata list */ |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 64 | struct list_head list; |
| 65 | |
Johannes Berg | ad0e2b5 | 2010-06-01 10:19:19 +0200 | [diff] [blame] | 66 | /* protected by key mutex */ |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 67 | unsigned int flags; |
| 68 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 69 | union { |
| 70 | struct { |
Johannes Berg | 523b02e | 2011-07-07 22:28:01 +0200 | [diff] [blame] | 71 | /* protects tx context */ |
| 72 | spinlock_t txlock; |
| 73 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 74 | /* last used TSC */ |
Harvey Harrison | b0f76b3 | 2008-05-14 16:26:19 -0700 | [diff] [blame] | 75 | struct tkip_ctx tx; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 76 | |
| 77 | /* last received RSC */ |
Eliad Peller | f8079d4 | 2016-02-14 13:56:35 +0200 | [diff] [blame] | 78 | struct tkip_ctx_rx rx[IEEE80211_NUM_TIDS]; |
Saravana | b98ea05 | 2012-12-04 19:47:42 +0530 | [diff] [blame] | 79 | |
| 80 | /* number of mic failures */ |
| 81 | u32 mic_failures; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 82 | } tkip; |
| 83 | struct { |
Jouni Malinen | 9190252 | 2010-06-11 10:27:33 -0700 | [diff] [blame] | 84 | /* |
| 85 | * Last received packet number. The first |
Johannes Berg | 5a306f5 | 2012-11-14 23:22:21 +0100 | [diff] [blame] | 86 | * IEEE80211_NUM_TIDS counters are used with Data |
Jouni Malinen | 9190252 | 2010-06-11 10:27:33 -0700 | [diff] [blame] | 87 | * frames and the last counter is used with Robust |
| 88 | * Management frames. |
| 89 | */ |
Johannes Berg | 4325f6c | 2013-05-08 13:09:08 +0200 | [diff] [blame] | 90 | u8 rx_pn[IEEE80211_NUM_TIDS + 1][IEEE80211_CCMP_PN_LEN]; |
Ard Biesheuvel | 7ec7c4a | 2013-10-10 09:55:20 +0200 | [diff] [blame] | 91 | struct crypto_aead *tfm; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 92 | u32 replays; /* dot11RSNAStatsCCMPReplays */ |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 93 | } ccmp; |
Jouni Malinen | 765cb46 | 2009-01-08 13:32:01 +0200 | [diff] [blame] | 94 | struct { |
Johannes Berg | 4325f6c | 2013-05-08 13:09:08 +0200 | [diff] [blame] | 95 | u8 rx_pn[IEEE80211_CMAC_PN_LEN]; |
Ard Biesheuvel | 2671782 | 2017-02-06 10:49:28 +0000 | [diff] [blame] | 96 | struct crypto_shash *tfm; |
Jouni Malinen | 765cb46 | 2009-01-08 13:32:01 +0200 | [diff] [blame] | 97 | u32 replays; /* dot11RSNAStatsCMACReplays */ |
| 98 | u32 icverrors; /* dot11RSNAStatsCMACICVErrors */ |
Jouni Malinen | 765cb46 | 2009-01-08 13:32:01 +0200 | [diff] [blame] | 99 | } aes_cmac; |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 100 | struct { |
Jouni Malinen | 8ade538 | 2015-01-24 19:52:09 +0200 | [diff] [blame] | 101 | u8 rx_pn[IEEE80211_GMAC_PN_LEN]; |
| 102 | struct crypto_aead *tfm; |
| 103 | u32 replays; /* dot11RSNAStatsCMACReplays */ |
| 104 | u32 icverrors; /* dot11RSNAStatsCMACICVErrors */ |
| 105 | } aes_gmac; |
| 106 | struct { |
Jouni Malinen | 00b9cfa | 2015-01-24 19:52:06 +0200 | [diff] [blame] | 107 | /* Last received packet number. The first |
| 108 | * IEEE80211_NUM_TIDS counters are used with Data |
| 109 | * frames and the last counter is used with Robust |
| 110 | * Management frames. |
| 111 | */ |
| 112 | u8 rx_pn[IEEE80211_NUM_TIDS + 1][IEEE80211_GCMP_PN_LEN]; |
| 113 | struct crypto_aead *tfm; |
| 114 | u32 replays; /* dot11RSNAStatsGCMPReplays */ |
| 115 | } gcmp; |
| 116 | struct { |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 117 | /* generic cipher scheme */ |
Johannes Berg | a31cf1c | 2015-04-20 18:21:58 +0200 | [diff] [blame] | 118 | u8 rx_pn[IEEE80211_NUM_TIDS + 1][IEEE80211_MAX_PN_LEN]; |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 119 | } gen; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 120 | } u; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 121 | |
Jiri Benc | e9f207f | 2007-05-05 11:46:38 -0700 | [diff] [blame] | 122 | #ifdef CONFIG_MAC80211_DEBUGFS |
| 123 | struct { |
| 124 | struct dentry *stalink; |
| 125 | struct dentry *dir; |
Johannes Berg | d9c58f3 | 2008-04-08 16:46:36 -0400 | [diff] [blame] | 126 | int cnt; |
Jiri Benc | e9f207f | 2007-05-05 11:46:38 -0700 | [diff] [blame] | 127 | } debugfs; |
| 128 | #endif |
| 129 | |
Johannes Berg | 8f20fc2 | 2007-08-28 17:01:54 -0400 | [diff] [blame] | 130 | /* |
| 131 | * key config, must be last because it contains key |
| 132 | * material as variable length member |
| 133 | */ |
| 134 | struct ieee80211_key_conf conf; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 135 | }; |
| 136 | |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 137 | struct ieee80211_key * |
| 138 | ieee80211_key_alloc(u32 cipher, int idx, size_t key_len, |
| 139 | const u8 *key_data, |
| 140 | size_t seq_len, const u8 *seq, |
| 141 | const struct ieee80211_cipher_scheme *cs); |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 142 | /* |
| 143 | * Insert a key into data structures (sdata, sta if necessary) |
Johannes Berg | 79cf2df | 2013-03-06 22:53:52 +0100 | [diff] [blame] | 144 | * to make it used, free old key. On failure, also free the new key. |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 145 | */ |
Johannes Berg | 79cf2df | 2013-03-06 22:53:52 +0100 | [diff] [blame] | 146 | int ieee80211_key_link(struct ieee80211_key *key, |
| 147 | struct ieee80211_sub_if_data *sdata, |
| 148 | struct sta_info *sta); |
Alexander Wetzel | 96fc6ef | 2019-03-19 21:34:08 +0100 | [diff] [blame] | 149 | int ieee80211_set_tx_key(struct ieee80211_key *key); |
Johannes Berg | 3b8d9c2 | 2013-03-06 22:58:23 +0100 | [diff] [blame] | 150 | void ieee80211_key_free(struct ieee80211_key *key, bool delay_tailroom); |
Johannes Berg | 79cf2df | 2013-03-06 22:53:52 +0100 | [diff] [blame] | 151 | void ieee80211_key_free_unused(struct ieee80211_key *key); |
Johannes Berg | f7e0104 | 2010-12-09 19:49:02 +0100 | [diff] [blame] | 152 | void ieee80211_set_default_key(struct ieee80211_sub_if_data *sdata, int idx, |
| 153 | bool uni, bool multi); |
Jouni Malinen | 3cfcf6ac | 2009-01-08 13:32:02 +0200 | [diff] [blame] | 154 | void ieee80211_set_default_mgmt_key(struct ieee80211_sub_if_data *sdata, |
| 155 | int idx); |
Johannes Berg | 7907c7d | 2013-12-04 23:47:09 +0100 | [diff] [blame] | 156 | void ieee80211_free_keys(struct ieee80211_sub_if_data *sdata, |
| 157 | bool force_synchronize); |
Johannes Berg | 6d10e46 | 2013-03-06 23:09:11 +0100 | [diff] [blame] | 158 | void ieee80211_free_sta_keys(struct ieee80211_local *local, |
| 159 | struct sta_info *sta); |
Lior Cohen | 624ff4b | 2019-08-30 14:24:49 +0300 | [diff] [blame] | 160 | void ieee80211_reenable_keys(struct ieee80211_sub_if_data *sdata); |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 161 | |
Johannes Berg | 40b275b | 2011-05-13 14:15:49 +0200 | [diff] [blame] | 162 | #define key_mtx_dereference(local, ref) \ |
| 163 | rcu_dereference_protected(ref, lockdep_is_held(&((local)->key_mtx))) |
| 164 | |
Johannes Berg | 8d1f7ec | 2013-02-23 00:59:03 +0100 | [diff] [blame] | 165 | void ieee80211_delayed_tailroom_dec(struct work_struct *wk); |
| 166 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 167 | #endif /* IEEE80211_KEY_H */ |