key.c 24.5 KB
Newer Older
1 2 3 4
/*
 * Copyright 2002-2005, Instant802 Networks, Inc.
 * Copyright 2005-2006, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
5
 * Copyright 2007-2008	Johannes Berg <johannes@sipsolutions.net>
6
 * Copyright 2013-2014  Intel Mobile Communications GmbH
7 8 9 10 11 12
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

J
Johannes Berg 已提交
13 14 15
#include <linux/if_ether.h>
#include <linux/etherdevice.h>
#include <linux/list.h>
16
#include <linux/rcupdate.h>
17
#include <linux/rtnetlink.h>
18
#include <linux/slab.h>
19
#include <linux/export.h>
20
#include <net/mac80211.h>
21
#include <asm/unaligned.h>
22
#include "ieee80211_i.h"
23
#include "driver-ops.h"
24 25
#include "debugfs_key.h"
#include "aes_ccm.h"
26
#include "aes_cmac.h"
27

J
Johannes Berg 已提交
28

J
Johannes Berg 已提交
29 30
/**
 * DOC: Key handling basics
J
Johannes Berg 已提交
31 32 33 34 35
 *
 * Key handling in mac80211 is done based on per-interface (sub_if_data)
 * keys and per-station keys. Since each station belongs to an interface,
 * each station key also belongs to that interface.
 *
36 37 38 39 40 41 42
 * Hardware acceleration is done on a best-effort basis for algorithms
 * that are implemented in software,  for each key the hardware is asked
 * to enable that key for offloading but if it cannot do that the key is
 * simply kept for software encryption (unless it is for an algorithm
 * that isn't implemented in software).
 * There is currently no way of knowing whether a key is handled in SW
 * or HW except by looking into debugfs.
J
Johannes Berg 已提交
43
 *
44 45 46 47 48 49
 * All key management is internally protected by a mutex. Within all
 * other parts of mac80211, key references are, just as STA structure
 * references, protected by RCU. Note, however, that some things are
 * unprotected, namely the key->sta dereferences within the hardware
 * acceleration functions. This means that sta_info_destroy() must
 * remove the key which waits for an RCU grace period.
J
Johannes Berg 已提交
50 51 52 53
 */

static const u8 bcast_addr[ETH_ALEN] = { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF };

J
Johannes Berg 已提交
54
static void assert_key_lock(struct ieee80211_local *local)
55
{
56
	lockdep_assert_held(&local->key_mtx);
57 58
}

59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88
static void increment_tailroom_need_count(struct ieee80211_sub_if_data *sdata)
{
	/*
	 * When this count is zero, SKB resizing for allocating tailroom
	 * for IV or MMIC is skipped. But, this check has created two race
	 * cases in xmit path while transiting from zero count to one:
	 *
	 * 1. SKB resize was skipped because no key was added but just before
	 * the xmit key is added and SW encryption kicks off.
	 *
	 * 2. SKB resize was skipped because all the keys were hw planted but
	 * just before xmit one of the key is deleted and SW encryption kicks
	 * off.
	 *
	 * In both the above case SW encryption will find not enough space for
	 * tailroom and exits with WARN_ON. (See WARN_ONs at wpa.c)
	 *
	 * Solution has been explained at
	 * http://mid.gmane.org/1308590980.4322.19.camel@jlt3.sipsolutions.net
	 */

	if (!sdata->crypto_tx_tailroom_needed_cnt++) {
		/*
		 * Flush all XMIT packets currently using HW encryption or no
		 * encryption at all if the count transition is from 0 -> 1.
		 */
		synchronize_net();
	}
}

89
static int ieee80211_key_enable_hw_accel(struct ieee80211_key *key)
J
Johannes Berg 已提交
90
{
91
	struct ieee80211_sub_if_data *sdata;
92
	struct sta_info *sta;
J
Johannes Berg 已提交
93 94
	int ret;

95 96
	might_sleep();

97 98 99 100 101 102 103 104 105
	if (key->flags & KEY_FLAG_TAINTED) {
		/* If we get here, it's during resume and the key is
		 * tainted so shouldn't be used/programmed any more.
		 * However, its flags may still indicate that it was
		 * programmed into the device (since we're in resume)
		 * so clear that flag now to avoid trying to remove
		 * it again later.
		 */
		key->flags &= ~KEY_FLAG_UPLOADED_TO_HARDWARE;
106
		return -EINVAL;
107
	}
108

109
	if (!key->local->ops->set_key)
110
		goto out_unsupported;
J
Johannes Berg 已提交
111

J
Johannes Berg 已提交
112 113
	assert_key_lock(key->local);

114
	sta = key->sta;
115

116 117 118 119 120 121 122 123
	/*
	 * If this is a per-STA GTK, check if it
	 * is supported; if not, return.
	 */
	if (sta && !(key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE) &&
	    !(key->local->hw.flags & IEEE80211_HW_SUPPORTS_PER_STA_GTK))
		goto out_unsupported;

124 125 126
	if (sta && !sta->uploaded)
		goto out_unsupported;

127
	sdata = key->sdata;
128 129 130 131 132 133 134 135
	if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN) {
		/*
		 * The driver doesn't know anything about VLAN interfaces.
		 * Hence, don't send GTKs for VLAN interfaces to the driver.
		 */
		if (!(key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE))
			goto out_unsupported;
	}
J
Johannes Berg 已提交
136

137 138
	ret = drv_set_key(key->local, SET_KEY, sdata,
			  sta ? &sta->sta : NULL, &key->conf);
J
Johannes Berg 已提交
139

140
	if (!ret) {
J
Johannes Berg 已提交
141
		key->flags |= KEY_FLAG_UPLOADED_TO_HARDWARE;
142

143
		if (!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIC))
144 145
			sdata->crypto_tx_tailroom_needed_cnt--;

146 147 148
		WARN_ON((key->conf.flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE) &&
			(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_IV));

149 150
		return 0;
	}
J
Johannes Berg 已提交
151

152
	if (ret != -ENOSPC && ret != -EOPNOTSUPP)
J
Johannes Berg 已提交
153
		sdata_err(sdata,
J
Joe Perches 已提交
154
			  "failed to set key (%d, %pM) to hardware (%d)\n",
155 156
			  key->conf.keyidx,
			  sta ? sta->sta.addr : bcast_addr, ret);
157

158 159 160 161 162 163 164 165 166 167 168
 out_unsupported:
	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_WEP40:
	case WLAN_CIPHER_SUITE_WEP104:
	case WLAN_CIPHER_SUITE_TKIP:
	case WLAN_CIPHER_SUITE_CCMP:
	case WLAN_CIPHER_SUITE_AES_CMAC:
		/* all of these we can do in software */
		return 0;
	default:
		return -EINVAL;
169
	}
J
Johannes Berg 已提交
170 171 172 173
}

static void ieee80211_key_disable_hw_accel(struct ieee80211_key *key)
{
174
	struct ieee80211_sub_if_data *sdata;
175
	struct sta_info *sta;
J
Johannes Berg 已提交
176 177
	int ret;

178 179
	might_sleep();

180
	if (!key || !key->local->ops->set_key)
J
Johannes Berg 已提交
181 182
		return;

J
Johannes Berg 已提交
183 184 185
	assert_key_lock(key->local);

	if (!(key->flags & KEY_FLAG_UPLOADED_TO_HARDWARE))
J
Johannes Berg 已提交
186 187
		return;

188
	sta = key->sta;
189 190
	sdata = key->sdata;

191
	if (!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIC))
192 193
		increment_tailroom_need_count(sdata);

J
Johannes Berg 已提交
194
	ret = drv_set_key(key->local, DISABLE_KEY, sdata,
195
			  sta ? &sta->sta : NULL, &key->conf);
J
Johannes Berg 已提交
196 197

	if (ret)
J
Johannes Berg 已提交
198
		sdata_err(sdata,
J
Joe Perches 已提交
199
			  "failed to remove key (%d, %pM) from hardware (%d)\n",
200 201
			  key->conf.keyidx,
			  sta ? sta->sta.addr : bcast_addr, ret);
J
Johannes Berg 已提交
202

203 204 205 206
	key->flags &= ~KEY_FLAG_UPLOADED_TO_HARDWARE;
}

static void __ieee80211_set_default_key(struct ieee80211_sub_if_data *sdata,
207
					int idx, bool uni, bool multi)
208 209 210
{
	struct ieee80211_key *key = NULL;

J
Johannes Berg 已提交
211 212
	assert_key_lock(sdata->local);

213
	if (idx >= 0 && idx < NUM_DEFAULT_KEYS)
J
Johannes Berg 已提交
214
		key = key_mtx_dereference(sdata->local, sdata->keys[idx]);
215

216
	if (uni) {
217
		rcu_assign_pointer(sdata->default_unicast_key, key);
218 219 220
		drv_set_default_unicast_key(sdata->local, sdata, idx);
	}

221 222
	if (multi)
		rcu_assign_pointer(sdata->default_multicast_key, key);
223

224
	ieee80211_debugfs_key_update_default(sdata);
225 226
}

227 228
void ieee80211_set_default_key(struct ieee80211_sub_if_data *sdata, int idx,
			       bool uni, bool multi)
229
{
J
Johannes Berg 已提交
230
	mutex_lock(&sdata->local->key_mtx);
231
	__ieee80211_set_default_key(sdata, idx, uni, multi);
J
Johannes Berg 已提交
232
	mutex_unlock(&sdata->local->key_mtx);
233 234
}

235 236 237 238 239
static void
__ieee80211_set_default_mgmt_key(struct ieee80211_sub_if_data *sdata, int idx)
{
	struct ieee80211_key *key = NULL;

J
Johannes Berg 已提交
240 241
	assert_key_lock(sdata->local);

242 243
	if (idx >= NUM_DEFAULT_KEYS &&
	    idx < NUM_DEFAULT_KEYS + NUM_DEFAULT_MGMT_KEYS)
J
Johannes Berg 已提交
244
		key = key_mtx_dereference(sdata->local, sdata->keys[idx]);
245 246 247

	rcu_assign_pointer(sdata->default_mgmt_key, key);

248
	ieee80211_debugfs_key_update_default(sdata);
249 250 251 252 253
}

void ieee80211_set_default_mgmt_key(struct ieee80211_sub_if_data *sdata,
				    int idx)
{
J
Johannes Berg 已提交
254
	mutex_lock(&sdata->local->key_mtx);
255
	__ieee80211_set_default_mgmt_key(sdata, idx);
J
Johannes Berg 已提交
256
	mutex_unlock(&sdata->local->key_mtx);
257 258
}

259

260 261 262 263 264
static void ieee80211_key_replace(struct ieee80211_sub_if_data *sdata,
				  struct sta_info *sta,
				  bool pairwise,
				  struct ieee80211_key *old,
				  struct ieee80211_key *new)
265
{
266 267
	int idx;
	bool defunikey, defmultikey, defmgmtkey;
268

269 270 271 272
	/* caller must provide at least one old/new */
	if (WARN_ON(!new && !old))
		return;

273
	if (new)
274
		list_add_tail(&new->list, &sdata->key_list);
275

276
	WARN_ON(new && old && new->conf.keyidx != old->conf.keyidx);
277

278 279 280 281
	if (old)
		idx = old->conf.keyidx;
	else
		idx = new->conf.keyidx;
282

283 284 285 286 287 288 289 290 291
	if (sta) {
		if (pairwise) {
			rcu_assign_pointer(sta->ptk[idx], new);
			sta->ptk_idx = idx;
		} else {
			rcu_assign_pointer(sta->gtk[idx], new);
			sta->gtk_idx = idx;
		}
	} else {
J
Johannes Berg 已提交
292 293 294 295 296 297 298 299 300
		defunikey = old &&
			old == key_mtx_dereference(sdata->local,
						sdata->default_unicast_key);
		defmultikey = old &&
			old == key_mtx_dereference(sdata->local,
						sdata->default_multicast_key);
		defmgmtkey = old &&
			old == key_mtx_dereference(sdata->local,
						sdata->default_mgmt_key);
301

302 303 304 305
		if (defunikey && !new)
			__ieee80211_set_default_key(sdata, -1, true, false);
		if (defmultikey && !new)
			__ieee80211_set_default_key(sdata, -1, false, true);
306 307
		if (defmgmtkey && !new)
			__ieee80211_set_default_mgmt_key(sdata, -1);
308 309

		rcu_assign_pointer(sdata->keys[idx], new);
310 311 312 313 314 315
		if (defunikey && new)
			__ieee80211_set_default_key(sdata, new->conf.keyidx,
						    true, false);
		if (defmultikey && new)
			__ieee80211_set_default_key(sdata, new->conf.keyidx,
						    false, true);
316 317 318
		if (defmgmtkey && new)
			__ieee80211_set_default_mgmt_key(sdata,
							 new->conf.keyidx);
319 320
	}

321 322
	if (old)
		list_del(&old->list);
J
Johannes Berg 已提交
323 324
}

325 326 327 328 329
struct ieee80211_key *
ieee80211_key_alloc(u32 cipher, int idx, size_t key_len,
		    const u8 *key_data,
		    size_t seq_len, const u8 *seq,
		    const struct ieee80211_cipher_scheme *cs)
330 331
{
	struct ieee80211_key *key;
332
	int i, j, err;
333

J
Johannes Berg 已提交
334 335
	if (WARN_ON(idx < 0 || idx >= NUM_DEFAULT_KEYS + NUM_DEFAULT_MGMT_KEYS))
		return ERR_PTR(-EINVAL);
J
Johannes Berg 已提交
336 337

	key = kzalloc(sizeof(struct ieee80211_key) + key_len, GFP_KERNEL);
338
	if (!key)
339
		return ERR_PTR(-ENOMEM);
J
Johannes Berg 已提交
340 341 342 343 344 345 346 347

	/*
	 * Default to software encryption; we'll later upload the
	 * key to the hardware if possible.
	 */
	key->conf.flags = 0;
	key->flags = 0;

348
	key->conf.cipher = cipher;
J
Johannes Berg 已提交
349 350
	key->conf.keyidx = idx;
	key->conf.keylen = key_len;
351 352 353
	switch (cipher) {
	case WLAN_CIPHER_SUITE_WEP40:
	case WLAN_CIPHER_SUITE_WEP104:
354 355
		key->conf.iv_len = IEEE80211_WEP_IV_LEN;
		key->conf.icv_len = IEEE80211_WEP_ICV_LEN;
356
		break;
357
	case WLAN_CIPHER_SUITE_TKIP:
358 359
		key->conf.iv_len = IEEE80211_TKIP_IV_LEN;
		key->conf.icv_len = IEEE80211_TKIP_ICV_LEN;
360
		if (seq) {
361
			for (i = 0; i < IEEE80211_NUM_TIDS; i++) {
362 363 364 365 366 367
				key->u.tkip.rx[i].iv32 =
					get_unaligned_le32(&seq[2]);
				key->u.tkip.rx[i].iv16 =
					get_unaligned_le16(seq);
			}
		}
368
		spin_lock_init(&key->u.tkip.txlock);
369
		break;
370
	case WLAN_CIPHER_SUITE_CCMP:
371 372
		key->conf.iv_len = IEEE80211_CCMP_HDR_LEN;
		key->conf.icv_len = IEEE80211_CCMP_MIC_LEN;
373
		if (seq) {
374
			for (i = 0; i < IEEE80211_NUM_TIDS + 1; i++)
375
				for (j = 0; j < IEEE80211_CCMP_PN_LEN; j++)
376
					key->u.ccmp.rx_pn[i][j] =
377
						seq[IEEE80211_CCMP_PN_LEN - j - 1];
378
		}
J
Johannes Berg 已提交
379 380 381 382 383
		/*
		 * Initialize AES key state here as an optimization so that
		 * it does not need to be initialized for every packet.
		 */
		key->u.ccmp.tfm = ieee80211_aes_key_setup_encrypt(key_data);
384 385
		if (IS_ERR(key->u.ccmp.tfm)) {
			err = PTR_ERR(key->u.ccmp.tfm);
386
			kfree(key);
387
			return ERR_PTR(err);
J
Johannes Berg 已提交
388
		}
J
Johannes Berg 已提交
389 390 391 392 393
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		key->conf.iv_len = 0;
		key->conf.icv_len = sizeof(struct ieee80211_mmie);
		if (seq)
394
			for (j = 0; j < IEEE80211_CMAC_PN_LEN; j++)
J
Johannes Berg 已提交
395
				key->u.aes_cmac.rx_pn[j] =
396
					seq[IEEE80211_CMAC_PN_LEN - j - 1];
397 398 399 400 401 402
		/*
		 * Initialize AES key state here as an optimization so that
		 * it does not need to be initialized for every packet.
		 */
		key->u.aes_cmac.tfm =
			ieee80211_aes_cmac_key_setup(key_data);
403 404
		if (IS_ERR(key->u.aes_cmac.tfm)) {
			err = PTR_ERR(key->u.aes_cmac.tfm);
405
			kfree(key);
406
			return ERR_PTR(err);
407
		}
J
Johannes Berg 已提交
408
		break;
409 410 411 412 413 414 415 416 417 418 419 420
	default:
		if (cs) {
			size_t len = (seq_len > MAX_PN_LEN) ?
						MAX_PN_LEN : seq_len;

			key->conf.iv_len = cs->hdr_len;
			key->conf.icv_len = cs->mic_len;
			for (i = 0; i < IEEE80211_NUM_TIDS + 1; i++)
				for (j = 0; j < len; j++)
					key->u.gen.rx_pn[i][j] =
							seq[len - j - 1];
		}
421
	}
J
Johannes Berg 已提交
422 423
	memcpy(key->conf.key, key_data, key_len);
	INIT_LIST_HEAD(&key->list);
424

425 426
	return key;
}
J
Johannes Berg 已提交
427

428 429 430 431 432 433
static void ieee80211_key_free_common(struct ieee80211_key *key)
{
	if (key->conf.cipher == WLAN_CIPHER_SUITE_CCMP)
		ieee80211_aes_key_free(key->u.ccmp.tfm);
	if (key->conf.cipher == WLAN_CIPHER_SUITE_AES_CMAC)
		ieee80211_aes_cmac_key_free(key->u.aes_cmac.tfm);
434
	kzfree(key);
435 436
}

437 438
static void __ieee80211_key_destroy(struct ieee80211_key *key,
				    bool delay_tailroom)
J
Johannes Berg 已提交
439
{
440 441
	if (key->local)
		ieee80211_key_disable_hw_accel(key);
J
Johannes Berg 已提交
442

443
	if (key->local) {
444 445
		struct ieee80211_sub_if_data *sdata = key->sdata;

446
		ieee80211_debugfs_key_remove(key);
447 448 449 450 451 452 453 454 455

		if (delay_tailroom) {
			/* see ieee80211_delayed_tailroom_dec */
			sdata->crypto_tx_tailroom_pending_dec++;
			schedule_delayed_work(&sdata->dec_tailroom_needed_wk,
					      HZ/2);
		} else {
			sdata->crypto_tx_tailroom_needed_cnt--;
		}
456
	}
J
Johannes Berg 已提交
457

458 459 460
	ieee80211_key_free_common(key);
}

461 462 463 464 465 466 467 468 469 470 471 472 473 474 475
static void ieee80211_key_destroy(struct ieee80211_key *key,
				  bool delay_tailroom)
{
	if (!key)
		return;

	/*
	 * Synchronize so the TX path can no longer be using
	 * this key before we free/remove it.
	 */
	synchronize_net();

	__ieee80211_key_destroy(key, delay_tailroom);
}

476 477 478 479
void ieee80211_key_free_unused(struct ieee80211_key *key)
{
	WARN_ON(key->sdata || key->local);
	ieee80211_key_free_common(key);
J
Johannes Berg 已提交
480 481
}

482 483 484
int ieee80211_key_link(struct ieee80211_key *key,
		       struct ieee80211_sub_if_data *sdata,
		       struct sta_info *sta)
485
{
486
	struct ieee80211_local *local = sdata->local;
487
	struct ieee80211_key *old_key;
488
	int idx, ret;
489
	bool pairwise;
490

491
	pairwise = key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE;
492 493 494 495 496
	idx = key->conf.keyidx;
	key->local = sdata->local;
	key->sdata = sdata;
	key->sta = sta;

J
Johannes Berg 已提交
497
	mutex_lock(&sdata->local->key_mtx);
498

499
	if (sta && pairwise)
500
		old_key = key_mtx_dereference(sdata->local, sta->ptk[idx]);
501
	else if (sta)
J
Johannes Berg 已提交
502
		old_key = key_mtx_dereference(sdata->local, sta->gtk[idx]);
503
	else
J
Johannes Berg 已提交
504
		old_key = key_mtx_dereference(sdata->local, sdata->keys[idx]);
505

506 507
	increment_tailroom_need_count(sdata);

508 509
	ieee80211_key_replace(sdata, sta, pairwise, old_key, key);
	ieee80211_key_destroy(old_key, true);
510

J
Johannes Berg 已提交
511
	ieee80211_debugfs_key_add(key);
512

513 514 515 516 517 518 519
	if (!local->wowlan) {
		ret = ieee80211_key_enable_hw_accel(key);
		if (ret)
			ieee80211_key_free(key, true);
	} else {
		ret = 0;
	}
520

J
Johannes Berg 已提交
521
	mutex_unlock(&sdata->local->key_mtx);
522 523

	return ret;
524 525
}

526
void ieee80211_key_free(struct ieee80211_key *key, bool delay_tailroom)
527
{
528 529 530
	if (!key)
		return;

531 532 533
	/*
	 * Replace key with nothingness if it was ever used.
	 */
J
Johannes Berg 已提交
534
	if (key->sdata)
535
		ieee80211_key_replace(key->sdata, key->sta,
536 537
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
538
	ieee80211_key_destroy(key, delay_tailroom);
539
}
540

J
Johannes Berg 已提交
541
void ieee80211_enable_keys(struct ieee80211_sub_if_data *sdata)
J
Johannes Berg 已提交
542 543
{
	struct ieee80211_key *key;
J
Johannes Berg 已提交
544

J
Johannes Berg 已提交
545
	ASSERT_RTNL();
J
Johannes Berg 已提交
546

547
	if (WARN_ON(!ieee80211_sdata_running(sdata)))
J
Johannes Berg 已提交
548
		return;
J
Johannes Berg 已提交
549

J
Johannes Berg 已提交
550
	mutex_lock(&sdata->local->key_mtx);
J
Johannes Berg 已提交
551

552 553 554 555
	sdata->crypto_tx_tailroom_needed_cnt = 0;

	list_for_each_entry(key, &sdata->key_list, list) {
		increment_tailroom_need_count(sdata);
J
Johannes Berg 已提交
556
		ieee80211_key_enable_hw_accel(key);
557
	}
558

J
Johannes Berg 已提交
559
	mutex_unlock(&sdata->local->key_mtx);
J
Johannes Berg 已提交
560 561
}

562 563 564 565 566 567 568 569 570 571
void ieee80211_iter_keys(struct ieee80211_hw *hw,
			 struct ieee80211_vif *vif,
			 void (*iter)(struct ieee80211_hw *hw,
				      struct ieee80211_vif *vif,
				      struct ieee80211_sta *sta,
				      struct ieee80211_key_conf *key,
				      void *data),
			 void *iter_data)
{
	struct ieee80211_local *local = hw_to_local(hw);
572
	struct ieee80211_key *key, *tmp;
573 574 575 576 577 578 579
	struct ieee80211_sub_if_data *sdata;

	ASSERT_RTNL();

	mutex_lock(&local->key_mtx);
	if (vif) {
		sdata = vif_to_sdata(vif);
580
		list_for_each_entry_safe(key, tmp, &sdata->key_list, list)
581 582 583 584 585
			iter(hw, &sdata->vif,
			     key->sta ? &key->sta->sta : NULL,
			     &key->conf, iter_data);
	} else {
		list_for_each_entry(sdata, &local->interfaces, list)
586 587
			list_for_each_entry_safe(key, tmp,
						 &sdata->key_list, list)
588 589 590 591 592 593 594 595
				iter(hw, &sdata->vif,
				     key->sta ? &key->sta->sta : NULL,
				     &key->conf, iter_data);
	}
	mutex_unlock(&local->key_mtx);
}
EXPORT_SYMBOL(ieee80211_iter_keys);

596 597
static void ieee80211_free_keys_iface(struct ieee80211_sub_if_data *sdata,
				      struct list_head *keys)
598 599 600
{
	struct ieee80211_key *key, *tmp;

601 602 603 604
	sdata->crypto_tx_tailroom_needed_cnt -=
		sdata->crypto_tx_tailroom_pending_dec;
	sdata->crypto_tx_tailroom_pending_dec = 0;

605
	ieee80211_debugfs_key_remove_mgmt_default(sdata);
606

607 608 609 610
	list_for_each_entry_safe(key, tmp, &sdata->key_list, list) {
		ieee80211_key_replace(key->sdata, key->sta,
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
611
		list_add_tail(&key->list, keys);
612
	}
613

614
	ieee80211_debugfs_key_update_default(sdata);
615
}
616

617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633
void ieee80211_free_keys(struct ieee80211_sub_if_data *sdata,
			 bool force_synchronize)
{
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_sub_if_data *vlan;
	struct ieee80211_key *key, *tmp;
	LIST_HEAD(keys);

	cancel_delayed_work_sync(&sdata->dec_tailroom_needed_wk);

	mutex_lock(&local->key_mtx);

	ieee80211_free_keys_iface(sdata, &keys);

	if (sdata->vif.type == NL80211_IFTYPE_AP) {
		list_for_each_entry(vlan, &sdata->u.ap.vlans, u.vlan.list)
			ieee80211_free_keys_iface(vlan, &keys);
634 635
	}

636 637 638 639 640
	if (!list_empty(&keys) || force_synchronize)
		synchronize_net();
	list_for_each_entry_safe(key, tmp, &keys, list)
		__ieee80211_key_destroy(key, false);

641 642
	WARN_ON_ONCE(sdata->crypto_tx_tailroom_needed_cnt ||
		     sdata->crypto_tx_tailroom_pending_dec);
643 644 645 646 647
	if (sdata->vif.type == NL80211_IFTYPE_AP) {
		list_for_each_entry(vlan, &sdata->u.ap.vlans, u.vlan.list)
			WARN_ON_ONCE(vlan->crypto_tx_tailroom_needed_cnt ||
				     vlan->crypto_tx_tailroom_pending_dec);
	}
648

649
	mutex_unlock(&local->key_mtx);
J
Johannes Berg 已提交
650
}
651

652 653 654
void ieee80211_free_sta_keys(struct ieee80211_local *local,
			     struct sta_info *sta)
{
655
	struct ieee80211_key *key;
656 657 658
	int i;

	mutex_lock(&local->key_mtx);
659
	for (i = 0; i < ARRAY_SIZE(sta->gtk); i++) {
660 661 662 663 664 665
		key = key_mtx_dereference(local, sta->gtk[i]);
		if (!key)
			continue;
		ieee80211_key_replace(key->sdata, key->sta,
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
666
		__ieee80211_key_destroy(key, true);
667 668
	}

669 670 671 672
	for (i = 0; i < NUM_DEFAULT_KEYS; i++) {
		key = key_mtx_dereference(local, sta->ptk[i]);
		if (!key)
			continue;
673 674 675 676
		ieee80211_key_replace(key->sdata, key->sta,
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
		__ieee80211_key_destroy(key, true);
677
	}
678 679 680 681

	mutex_unlock(&local->key_mtx);
}

682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710
void ieee80211_delayed_tailroom_dec(struct work_struct *wk)
{
	struct ieee80211_sub_if_data *sdata;

	sdata = container_of(wk, struct ieee80211_sub_if_data,
			     dec_tailroom_needed_wk.work);

	/*
	 * The reason for the delayed tailroom needed decrementing is to
	 * make roaming faster: during roaming, all keys are first deleted
	 * and then new keys are installed. The first new key causes the
	 * crypto_tx_tailroom_needed_cnt to go from 0 to 1, which invokes
	 * the cost of synchronize_net() (which can be slow). Avoid this
	 * by deferring the crypto_tx_tailroom_needed_cnt decrementing on
	 * key removal for a while, so if we roam the value is larger than
	 * zero and no 0->1 transition happens.
	 *
	 * The cost is that if the AP switching was from an AP with keys
	 * to one without, we still allocate tailroom while it would no
	 * longer be needed. However, in the typical (fast) roaming case
	 * within an ESS this usually won't happen.
	 */

	mutex_lock(&sdata->local->key_mtx);
	sdata->crypto_tx_tailroom_needed_cnt -=
		sdata->crypto_tx_tailroom_pending_dec;
	sdata->crypto_tx_tailroom_pending_dec = 0;
	mutex_unlock(&sdata->local->key_mtx);
}
711 712 713 714 715 716 717 718 719 720 721

void ieee80211_gtk_rekey_notify(struct ieee80211_vif *vif, const u8 *bssid,
				const u8 *replay_ctr, gfp_t gfp)
{
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);

	trace_api_gtk_rekey_notify(sdata, bssid, replay_ctr);

	cfg80211_gtk_rekey_notify(sdata->dev, bssid, replay_ctr, gfp);
}
EXPORT_SYMBOL_GPL(ieee80211_gtk_rekey_notify);
722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772

void ieee80211_get_key_tx_seq(struct ieee80211_key_conf *keyconf,
			      struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	u64 pn64;

	if (WARN_ON(!(keyconf->flags & IEEE80211_KEY_FLAG_GENERATE_IV)))
		return;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
		seq->tkip.iv32 = key->u.tkip.tx.iv32;
		seq->tkip.iv16 = key->u.tkip.tx.iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
		pn64 = atomic64_read(&key->u.ccmp.tx_pn);
		seq->ccmp.pn[5] = pn64;
		seq->ccmp.pn[4] = pn64 >> 8;
		seq->ccmp.pn[3] = pn64 >> 16;
		seq->ccmp.pn[2] = pn64 >> 24;
		seq->ccmp.pn[1] = pn64 >> 32;
		seq->ccmp.pn[0] = pn64 >> 40;
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		pn64 = atomic64_read(&key->u.aes_cmac.tx_pn);
		seq->ccmp.pn[5] = pn64;
		seq->ccmp.pn[4] = pn64 >> 8;
		seq->ccmp.pn[3] = pn64 >> 16;
		seq->ccmp.pn[2] = pn64 >> 24;
		seq->ccmp.pn[1] = pn64 >> 32;
		seq->ccmp.pn[0] = pn64 >> 40;
		break;
	default:
		WARN_ON(1);
	}
}
EXPORT_SYMBOL(ieee80211_get_key_tx_seq);

void ieee80211_get_key_rx_seq(struct ieee80211_key_conf *keyconf,
			      int tid, struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	const u8 *pn;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
773
		if (WARN_ON(tid < 0 || tid >= IEEE80211_NUM_TIDS))
774 775 776 777 778
			return;
		seq->tkip.iv32 = key->u.tkip.rx[tid].iv32;
		seq->tkip.iv16 = key->u.tkip.rx[tid].iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
779
		if (WARN_ON(tid < -1 || tid >= IEEE80211_NUM_TIDS))
780 781
			return;
		if (tid < 0)
782
			pn = key->u.ccmp.rx_pn[IEEE80211_NUM_TIDS];
783 784
		else
			pn = key->u.ccmp.rx_pn[tid];
785
		memcpy(seq->ccmp.pn, pn, IEEE80211_CCMP_PN_LEN);
786 787 788 789 790
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		if (WARN_ON(tid != 0))
			return;
		pn = key->u.aes_cmac.rx_pn;
791
		memcpy(seq->aes_cmac.pn, pn, IEEE80211_CMAC_PN_LEN);
792 793 794 795
		break;
	}
}
EXPORT_SYMBOL(ieee80211_get_key_rx_seq);
796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886

void ieee80211_set_key_tx_seq(struct ieee80211_key_conf *keyconf,
			      struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	u64 pn64;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
		key->u.tkip.tx.iv32 = seq->tkip.iv32;
		key->u.tkip.tx.iv16 = seq->tkip.iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
		pn64 = (u64)seq->ccmp.pn[5] |
		       ((u64)seq->ccmp.pn[4] << 8) |
		       ((u64)seq->ccmp.pn[3] << 16) |
		       ((u64)seq->ccmp.pn[2] << 24) |
		       ((u64)seq->ccmp.pn[1] << 32) |
		       ((u64)seq->ccmp.pn[0] << 40);
		atomic64_set(&key->u.ccmp.tx_pn, pn64);
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		pn64 = (u64)seq->aes_cmac.pn[5] |
		       ((u64)seq->aes_cmac.pn[4] << 8) |
		       ((u64)seq->aes_cmac.pn[3] << 16) |
		       ((u64)seq->aes_cmac.pn[2] << 24) |
		       ((u64)seq->aes_cmac.pn[1] << 32) |
		       ((u64)seq->aes_cmac.pn[0] << 40);
		atomic64_set(&key->u.aes_cmac.tx_pn, pn64);
		break;
	default:
		WARN_ON(1);
		break;
	}
}
EXPORT_SYMBOL_GPL(ieee80211_set_key_tx_seq);

void ieee80211_set_key_rx_seq(struct ieee80211_key_conf *keyconf,
			      int tid, struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	u8 *pn;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
		if (WARN_ON(tid < 0 || tid >= IEEE80211_NUM_TIDS))
			return;
		key->u.tkip.rx[tid].iv32 = seq->tkip.iv32;
		key->u.tkip.rx[tid].iv16 = seq->tkip.iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
		if (WARN_ON(tid < -1 || tid >= IEEE80211_NUM_TIDS))
			return;
		if (tid < 0)
			pn = key->u.ccmp.rx_pn[IEEE80211_NUM_TIDS];
		else
			pn = key->u.ccmp.rx_pn[tid];
		memcpy(pn, seq->ccmp.pn, IEEE80211_CCMP_PN_LEN);
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		if (WARN_ON(tid != 0))
			return;
		pn = key->u.aes_cmac.rx_pn;
		memcpy(pn, seq->aes_cmac.pn, IEEE80211_CMAC_PN_LEN);
		break;
	default:
		WARN_ON(1);
		break;
	}
}
EXPORT_SYMBOL_GPL(ieee80211_set_key_rx_seq);

void ieee80211_remove_key(struct ieee80211_key_conf *keyconf)
{
	struct ieee80211_key *key;

	key = container_of(keyconf, struct ieee80211_key, conf);

	assert_key_lock(key->local);

	/*
	 * if key was uploaded, we assume the driver will/has remove(d)
	 * it, so adjust bookkeeping accordingly
	 */
	if (key->flags & KEY_FLAG_UPLOADED_TO_HARDWARE) {
		key->flags &= ~KEY_FLAG_UPLOADED_TO_HARDWARE;

887
		if (!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIC))
888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911
			increment_tailroom_need_count(key->sdata);
	}

	ieee80211_key_free(key, false);
}
EXPORT_SYMBOL_GPL(ieee80211_remove_key);

struct ieee80211_key_conf *
ieee80211_gtk_rekey_add(struct ieee80211_vif *vif,
			struct ieee80211_key_conf *keyconf)
{
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_key *key;
	int err;

	if (WARN_ON(!local->wowlan))
		return ERR_PTR(-EINVAL);

	if (WARN_ON(vif->type != NL80211_IFTYPE_STATION))
		return ERR_PTR(-EINVAL);

	key = ieee80211_key_alloc(keyconf->cipher, keyconf->keyidx,
				  keyconf->keylen, keyconf->key,
912
				  0, NULL, NULL);
913
	if (IS_ERR(key))
J
Johannes Berg 已提交
914
		return ERR_CAST(key);
915 916 917 918 919 920 921 922 923 924 925

	if (sdata->u.mgd.mfp != IEEE80211_MFP_DISABLED)
		key->conf.flags |= IEEE80211_KEY_FLAG_RX_MGMT;

	err = ieee80211_key_link(key, sdata, NULL);
	if (err)
		return ERR_PTR(err);

	return &key->conf;
}
EXPORT_SYMBOL_GPL(ieee80211_gtk_rekey_add);