key.c 24.1 KB
Newer Older
1 2 3 4
/*
 * Copyright 2002-2005, Instant802 Networks, Inc.
 * Copyright 2005-2006, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
5
 * Copyright 2007-2008	Johannes Berg <johannes@sipsolutions.net>
6 7 8 9 10 11
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

J
Johannes Berg 已提交
12 13 14
#include <linux/if_ether.h>
#include <linux/etherdevice.h>
#include <linux/list.h>
15
#include <linux/rcupdate.h>
16
#include <linux/rtnetlink.h>
17
#include <linux/slab.h>
18
#include <linux/export.h>
19
#include <net/mac80211.h>
20
#include <asm/unaligned.h>
21
#include "ieee80211_i.h"
22
#include "driver-ops.h"
23 24
#include "debugfs_key.h"
#include "aes_ccm.h"
25
#include "aes_cmac.h"
26

J
Johannes Berg 已提交
27

J
Johannes Berg 已提交
28 29
/**
 * DOC: Key handling basics
J
Johannes Berg 已提交
30 31 32 33 34
 *
 * Key handling in mac80211 is done based on per-interface (sub_if_data)
 * keys and per-station keys. Since each station belongs to an interface,
 * each station key also belongs to that interface.
 *
35 36 37 38 39 40 41
 * Hardware acceleration is done on a best-effort basis for algorithms
 * that are implemented in software,  for each key the hardware is asked
 * to enable that key for offloading but if it cannot do that the key is
 * simply kept for software encryption (unless it is for an algorithm
 * that isn't implemented in software).
 * There is currently no way of knowing whether a key is handled in SW
 * or HW except by looking into debugfs.
J
Johannes Berg 已提交
42
 *
43 44 45 46 47 48
 * All key management is internally protected by a mutex. Within all
 * other parts of mac80211, key references are, just as STA structure
 * references, protected by RCU. Note, however, that some things are
 * unprotected, namely the key->sta dereferences within the hardware
 * acceleration functions. This means that sta_info_destroy() must
 * remove the key which waits for an RCU grace period.
J
Johannes Berg 已提交
49 50 51 52
 */

static const u8 bcast_addr[ETH_ALEN] = { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF };

J
Johannes Berg 已提交
53
static void assert_key_lock(struct ieee80211_local *local)
54
{
55
	lockdep_assert_held(&local->key_mtx);
56 57
}

58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87
static void increment_tailroom_need_count(struct ieee80211_sub_if_data *sdata)
{
	/*
	 * When this count is zero, SKB resizing for allocating tailroom
	 * for IV or MMIC is skipped. But, this check has created two race
	 * cases in xmit path while transiting from zero count to one:
	 *
	 * 1. SKB resize was skipped because no key was added but just before
	 * the xmit key is added and SW encryption kicks off.
	 *
	 * 2. SKB resize was skipped because all the keys were hw planted but
	 * just before xmit one of the key is deleted and SW encryption kicks
	 * off.
	 *
	 * In both the above case SW encryption will find not enough space for
	 * tailroom and exits with WARN_ON. (See WARN_ONs at wpa.c)
	 *
	 * Solution has been explained at
	 * http://mid.gmane.org/1308590980.4322.19.camel@jlt3.sipsolutions.net
	 */

	if (!sdata->crypto_tx_tailroom_needed_cnt++) {
		/*
		 * Flush all XMIT packets currently using HW encryption or no
		 * encryption at all if the count transition is from 0 -> 1.
		 */
		synchronize_net();
	}
}

88
static int ieee80211_key_enable_hw_accel(struct ieee80211_key *key)
J
Johannes Berg 已提交
89
{
90
	struct ieee80211_sub_if_data *sdata;
91
	struct sta_info *sta;
J
Johannes Berg 已提交
92 93
	int ret;

94 95
	might_sleep();

96 97 98
	if (key->flags & KEY_FLAG_TAINTED)
		return -EINVAL;

99
	if (!key->local->ops->set_key)
100
		goto out_unsupported;
J
Johannes Berg 已提交
101

J
Johannes Berg 已提交
102 103
	assert_key_lock(key->local);

104
	sta = key->sta;
105

106 107 108 109 110 111 112 113
	/*
	 * If this is a per-STA GTK, check if it
	 * is supported; if not, return.
	 */
	if (sta && !(key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE) &&
	    !(key->local->hw.flags & IEEE80211_HW_SUPPORTS_PER_STA_GTK))
		goto out_unsupported;

114 115 116
	if (sta && !sta->uploaded)
		goto out_unsupported;

117
	sdata = key->sdata;
118 119 120 121 122 123 124 125
	if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN) {
		/*
		 * The driver doesn't know anything about VLAN interfaces.
		 * Hence, don't send GTKs for VLAN interfaces to the driver.
		 */
		if (!(key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE))
			goto out_unsupported;
	}
J
Johannes Berg 已提交
126

127 128
	ret = drv_set_key(key->local, SET_KEY, sdata,
			  sta ? &sta->sta : NULL, &key->conf);
J
Johannes Berg 已提交
129

130
	if (!ret) {
J
Johannes Berg 已提交
131
		key->flags |= KEY_FLAG_UPLOADED_TO_HARDWARE;
132

133
		if (!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIC))
134 135
			sdata->crypto_tx_tailroom_needed_cnt--;

136 137 138
		WARN_ON((key->conf.flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE) &&
			(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_IV));

139 140
		return 0;
	}
J
Johannes Berg 已提交
141

142
	if (ret != -ENOSPC && ret != -EOPNOTSUPP)
J
Johannes Berg 已提交
143
		sdata_err(sdata,
J
Joe Perches 已提交
144
			  "failed to set key (%d, %pM) to hardware (%d)\n",
145 146
			  key->conf.keyidx,
			  sta ? sta->sta.addr : bcast_addr, ret);
147

148 149 150 151 152 153 154 155 156 157 158
 out_unsupported:
	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_WEP40:
	case WLAN_CIPHER_SUITE_WEP104:
	case WLAN_CIPHER_SUITE_TKIP:
	case WLAN_CIPHER_SUITE_CCMP:
	case WLAN_CIPHER_SUITE_AES_CMAC:
		/* all of these we can do in software */
		return 0;
	default:
		return -EINVAL;
159
	}
J
Johannes Berg 已提交
160 161 162 163
}

static void ieee80211_key_disable_hw_accel(struct ieee80211_key *key)
{
164
	struct ieee80211_sub_if_data *sdata;
165
	struct sta_info *sta;
J
Johannes Berg 已提交
166 167
	int ret;

168 169
	might_sleep();

170
	if (!key || !key->local->ops->set_key)
J
Johannes Berg 已提交
171 172
		return;

J
Johannes Berg 已提交
173 174 175
	assert_key_lock(key->local);

	if (!(key->flags & KEY_FLAG_UPLOADED_TO_HARDWARE))
J
Johannes Berg 已提交
176 177
		return;

178
	sta = key->sta;
179 180
	sdata = key->sdata;

181
	if (!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIC))
182 183
		increment_tailroom_need_count(sdata);

J
Johannes Berg 已提交
184
	ret = drv_set_key(key->local, DISABLE_KEY, sdata,
185
			  sta ? &sta->sta : NULL, &key->conf);
J
Johannes Berg 已提交
186 187

	if (ret)
J
Johannes Berg 已提交
188
		sdata_err(sdata,
J
Joe Perches 已提交
189
			  "failed to remove key (%d, %pM) from hardware (%d)\n",
190 191
			  key->conf.keyidx,
			  sta ? sta->sta.addr : bcast_addr, ret);
J
Johannes Berg 已提交
192

193 194 195 196
	key->flags &= ~KEY_FLAG_UPLOADED_TO_HARDWARE;
}

static void __ieee80211_set_default_key(struct ieee80211_sub_if_data *sdata,
197
					int idx, bool uni, bool multi)
198 199 200
{
	struct ieee80211_key *key = NULL;

J
Johannes Berg 已提交
201 202
	assert_key_lock(sdata->local);

203
	if (idx >= 0 && idx < NUM_DEFAULT_KEYS)
J
Johannes Berg 已提交
204
		key = key_mtx_dereference(sdata->local, sdata->keys[idx]);
205

206
	if (uni) {
207
		rcu_assign_pointer(sdata->default_unicast_key, key);
208 209 210
		drv_set_default_unicast_key(sdata->local, sdata, idx);
	}

211 212
	if (multi)
		rcu_assign_pointer(sdata->default_multicast_key, key);
213

214
	ieee80211_debugfs_key_update_default(sdata);
215 216
}

217 218
void ieee80211_set_default_key(struct ieee80211_sub_if_data *sdata, int idx,
			       bool uni, bool multi)
219
{
J
Johannes Berg 已提交
220
	mutex_lock(&sdata->local->key_mtx);
221
	__ieee80211_set_default_key(sdata, idx, uni, multi);
J
Johannes Berg 已提交
222
	mutex_unlock(&sdata->local->key_mtx);
223 224
}

225 226 227 228 229
static void
__ieee80211_set_default_mgmt_key(struct ieee80211_sub_if_data *sdata, int idx)
{
	struct ieee80211_key *key = NULL;

J
Johannes Berg 已提交
230 231
	assert_key_lock(sdata->local);

232 233
	if (idx >= NUM_DEFAULT_KEYS &&
	    idx < NUM_DEFAULT_KEYS + NUM_DEFAULT_MGMT_KEYS)
J
Johannes Berg 已提交
234
		key = key_mtx_dereference(sdata->local, sdata->keys[idx]);
235 236 237

	rcu_assign_pointer(sdata->default_mgmt_key, key);

238
	ieee80211_debugfs_key_update_default(sdata);
239 240 241 242 243
}

void ieee80211_set_default_mgmt_key(struct ieee80211_sub_if_data *sdata,
				    int idx)
{
J
Johannes Berg 已提交
244
	mutex_lock(&sdata->local->key_mtx);
245
	__ieee80211_set_default_mgmt_key(sdata, idx);
J
Johannes Berg 已提交
246
	mutex_unlock(&sdata->local->key_mtx);
247 248
}

249

250 251 252 253 254
static void ieee80211_key_replace(struct ieee80211_sub_if_data *sdata,
				  struct sta_info *sta,
				  bool pairwise,
				  struct ieee80211_key *old,
				  struct ieee80211_key *new)
255
{
256 257
	int idx;
	bool defunikey, defmultikey, defmgmtkey;
258

259 260 261 262
	/* caller must provide at least one old/new */
	if (WARN_ON(!new && !old))
		return;

263
	if (new)
264
		list_add_tail(&new->list, &sdata->key_list);
265

266
	WARN_ON(new && old && new->conf.keyidx != old->conf.keyidx);
267

268 269 270 271
	if (old)
		idx = old->conf.keyidx;
	else
		idx = new->conf.keyidx;
272

273 274 275 276 277 278 279 280 281
	if (sta) {
		if (pairwise) {
			rcu_assign_pointer(sta->ptk[idx], new);
			sta->ptk_idx = idx;
		} else {
			rcu_assign_pointer(sta->gtk[idx], new);
			sta->gtk_idx = idx;
		}
	} else {
J
Johannes Berg 已提交
282 283 284 285 286 287 288 289 290
		defunikey = old &&
			old == key_mtx_dereference(sdata->local,
						sdata->default_unicast_key);
		defmultikey = old &&
			old == key_mtx_dereference(sdata->local,
						sdata->default_multicast_key);
		defmgmtkey = old &&
			old == key_mtx_dereference(sdata->local,
						sdata->default_mgmt_key);
291

292 293 294 295
		if (defunikey && !new)
			__ieee80211_set_default_key(sdata, -1, true, false);
		if (defmultikey && !new)
			__ieee80211_set_default_key(sdata, -1, false, true);
296 297
		if (defmgmtkey && !new)
			__ieee80211_set_default_mgmt_key(sdata, -1);
298 299

		rcu_assign_pointer(sdata->keys[idx], new);
300 301 302 303 304 305
		if (defunikey && new)
			__ieee80211_set_default_key(sdata, new->conf.keyidx,
						    true, false);
		if (defmultikey && new)
			__ieee80211_set_default_key(sdata, new->conf.keyidx,
						    false, true);
306 307 308
		if (defmgmtkey && new)
			__ieee80211_set_default_mgmt_key(sdata,
							 new->conf.keyidx);
309 310
	}

311 312
	if (old)
		list_del(&old->list);
J
Johannes Berg 已提交
313 314
}

315 316 317 318 319
struct ieee80211_key *
ieee80211_key_alloc(u32 cipher, int idx, size_t key_len,
		    const u8 *key_data,
		    size_t seq_len, const u8 *seq,
		    const struct ieee80211_cipher_scheme *cs)
320 321
{
	struct ieee80211_key *key;
322
	int i, j, err;
323

J
Johannes Berg 已提交
324 325
	if (WARN_ON(idx < 0 || idx >= NUM_DEFAULT_KEYS + NUM_DEFAULT_MGMT_KEYS))
		return ERR_PTR(-EINVAL);
J
Johannes Berg 已提交
326 327

	key = kzalloc(sizeof(struct ieee80211_key) + key_len, GFP_KERNEL);
328
	if (!key)
329
		return ERR_PTR(-ENOMEM);
J
Johannes Berg 已提交
330 331 332 333 334 335 336 337

	/*
	 * Default to software encryption; we'll later upload the
	 * key to the hardware if possible.
	 */
	key->conf.flags = 0;
	key->flags = 0;

338
	key->conf.cipher = cipher;
J
Johannes Berg 已提交
339 340
	key->conf.keyidx = idx;
	key->conf.keylen = key_len;
341 342 343
	switch (cipher) {
	case WLAN_CIPHER_SUITE_WEP40:
	case WLAN_CIPHER_SUITE_WEP104:
344 345
		key->conf.iv_len = IEEE80211_WEP_IV_LEN;
		key->conf.icv_len = IEEE80211_WEP_ICV_LEN;
346
		break;
347
	case WLAN_CIPHER_SUITE_TKIP:
348 349
		key->conf.iv_len = IEEE80211_TKIP_IV_LEN;
		key->conf.icv_len = IEEE80211_TKIP_ICV_LEN;
350
		if (seq) {
351
			for (i = 0; i < IEEE80211_NUM_TIDS; i++) {
352 353 354 355 356 357
				key->u.tkip.rx[i].iv32 =
					get_unaligned_le32(&seq[2]);
				key->u.tkip.rx[i].iv16 =
					get_unaligned_le16(seq);
			}
		}
358
		spin_lock_init(&key->u.tkip.txlock);
359
		break;
360
	case WLAN_CIPHER_SUITE_CCMP:
361 362
		key->conf.iv_len = IEEE80211_CCMP_HDR_LEN;
		key->conf.icv_len = IEEE80211_CCMP_MIC_LEN;
363
		if (seq) {
364
			for (i = 0; i < IEEE80211_NUM_TIDS + 1; i++)
365
				for (j = 0; j < IEEE80211_CCMP_PN_LEN; j++)
366
					key->u.ccmp.rx_pn[i][j] =
367
						seq[IEEE80211_CCMP_PN_LEN - j - 1];
368
		}
J
Johannes Berg 已提交
369 370 371 372 373
		/*
		 * Initialize AES key state here as an optimization so that
		 * it does not need to be initialized for every packet.
		 */
		key->u.ccmp.tfm = ieee80211_aes_key_setup_encrypt(key_data);
374 375
		if (IS_ERR(key->u.ccmp.tfm)) {
			err = PTR_ERR(key->u.ccmp.tfm);
376
			kfree(key);
377
			return ERR_PTR(err);
J
Johannes Berg 已提交
378
		}
J
Johannes Berg 已提交
379 380 381 382 383
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		key->conf.iv_len = 0;
		key->conf.icv_len = sizeof(struct ieee80211_mmie);
		if (seq)
384
			for (j = 0; j < IEEE80211_CMAC_PN_LEN; j++)
J
Johannes Berg 已提交
385
				key->u.aes_cmac.rx_pn[j] =
386
					seq[IEEE80211_CMAC_PN_LEN - j - 1];
387 388 389 390 391 392
		/*
		 * Initialize AES key state here as an optimization so that
		 * it does not need to be initialized for every packet.
		 */
		key->u.aes_cmac.tfm =
			ieee80211_aes_cmac_key_setup(key_data);
393 394
		if (IS_ERR(key->u.aes_cmac.tfm)) {
			err = PTR_ERR(key->u.aes_cmac.tfm);
395
			kfree(key);
396
			return ERR_PTR(err);
397
		}
J
Johannes Berg 已提交
398
		break;
399 400 401 402 403 404 405 406 407 408 409 410
	default:
		if (cs) {
			size_t len = (seq_len > MAX_PN_LEN) ?
						MAX_PN_LEN : seq_len;

			key->conf.iv_len = cs->hdr_len;
			key->conf.icv_len = cs->mic_len;
			for (i = 0; i < IEEE80211_NUM_TIDS + 1; i++)
				for (j = 0; j < len; j++)
					key->u.gen.rx_pn[i][j] =
							seq[len - j - 1];
		}
411
	}
J
Johannes Berg 已提交
412 413
	memcpy(key->conf.key, key_data, key_len);
	INIT_LIST_HEAD(&key->list);
414

415 416
	return key;
}
J
Johannes Berg 已提交
417

418 419 420 421 422 423 424 425 426
static void ieee80211_key_free_common(struct ieee80211_key *key)
{
	if (key->conf.cipher == WLAN_CIPHER_SUITE_CCMP)
		ieee80211_aes_key_free(key->u.ccmp.tfm);
	if (key->conf.cipher == WLAN_CIPHER_SUITE_AES_CMAC)
		ieee80211_aes_cmac_key_free(key->u.aes_cmac.tfm);
	kfree(key);
}

427 428
static void __ieee80211_key_destroy(struct ieee80211_key *key,
				    bool delay_tailroom)
J
Johannes Berg 已提交
429
{
430 431
	if (key->local)
		ieee80211_key_disable_hw_accel(key);
J
Johannes Berg 已提交
432

433
	if (key->local) {
434 435
		struct ieee80211_sub_if_data *sdata = key->sdata;

436
		ieee80211_debugfs_key_remove(key);
437 438 439 440 441 442 443 444 445

		if (delay_tailroom) {
			/* see ieee80211_delayed_tailroom_dec */
			sdata->crypto_tx_tailroom_pending_dec++;
			schedule_delayed_work(&sdata->dec_tailroom_needed_wk,
					      HZ/2);
		} else {
			sdata->crypto_tx_tailroom_needed_cnt--;
		}
446
	}
J
Johannes Berg 已提交
447

448 449 450
	ieee80211_key_free_common(key);
}

451 452 453 454 455 456 457 458 459 460 461 462 463 464 465
static void ieee80211_key_destroy(struct ieee80211_key *key,
				  bool delay_tailroom)
{
	if (!key)
		return;

	/*
	 * Synchronize so the TX path can no longer be using
	 * this key before we free/remove it.
	 */
	synchronize_net();

	__ieee80211_key_destroy(key, delay_tailroom);
}

466 467 468 469
void ieee80211_key_free_unused(struct ieee80211_key *key)
{
	WARN_ON(key->sdata || key->local);
	ieee80211_key_free_common(key);
J
Johannes Berg 已提交
470 471
}

472 473 474
int ieee80211_key_link(struct ieee80211_key *key,
		       struct ieee80211_sub_if_data *sdata,
		       struct sta_info *sta)
475
{
476
	struct ieee80211_local *local = sdata->local;
477
	struct ieee80211_key *old_key;
478
	int idx, ret;
479
	bool pairwise;
480

481
	pairwise = key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE;
482 483 484 485 486
	idx = key->conf.keyidx;
	key->local = sdata->local;
	key->sdata = sdata;
	key->sta = sta;

J
Johannes Berg 已提交
487
	mutex_lock(&sdata->local->key_mtx);
488

489
	if (sta && pairwise)
490
		old_key = key_mtx_dereference(sdata->local, sta->ptk[idx]);
491
	else if (sta)
J
Johannes Berg 已提交
492
		old_key = key_mtx_dereference(sdata->local, sta->gtk[idx]);
493
	else
J
Johannes Berg 已提交
494
		old_key = key_mtx_dereference(sdata->local, sdata->keys[idx]);
495

496 497
	increment_tailroom_need_count(sdata);

498 499
	ieee80211_key_replace(sdata, sta, pairwise, old_key, key);
	ieee80211_key_destroy(old_key, true);
500

J
Johannes Berg 已提交
501
	ieee80211_debugfs_key_add(key);
502

503 504 505 506 507 508 509
	if (!local->wowlan) {
		ret = ieee80211_key_enable_hw_accel(key);
		if (ret)
			ieee80211_key_free(key, true);
	} else {
		ret = 0;
	}
510

J
Johannes Berg 已提交
511
	mutex_unlock(&sdata->local->key_mtx);
512 513

	return ret;
514 515
}

516
void ieee80211_key_free(struct ieee80211_key *key, bool delay_tailroom)
517
{
518 519 520
	if (!key)
		return;

521 522 523
	/*
	 * Replace key with nothingness if it was ever used.
	 */
J
Johannes Berg 已提交
524
	if (key->sdata)
525
		ieee80211_key_replace(key->sdata, key->sta,
526 527
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
528
	ieee80211_key_destroy(key, delay_tailroom);
529
}
530

J
Johannes Berg 已提交
531
void ieee80211_enable_keys(struct ieee80211_sub_if_data *sdata)
J
Johannes Berg 已提交
532 533
{
	struct ieee80211_key *key;
J
Johannes Berg 已提交
534

J
Johannes Berg 已提交
535
	ASSERT_RTNL();
J
Johannes Berg 已提交
536

537
	if (WARN_ON(!ieee80211_sdata_running(sdata)))
J
Johannes Berg 已提交
538
		return;
J
Johannes Berg 已提交
539

J
Johannes Berg 已提交
540
	mutex_lock(&sdata->local->key_mtx);
J
Johannes Berg 已提交
541

542 543 544 545
	sdata->crypto_tx_tailroom_needed_cnt = 0;

	list_for_each_entry(key, &sdata->key_list, list) {
		increment_tailroom_need_count(sdata);
J
Johannes Berg 已提交
546
		ieee80211_key_enable_hw_accel(key);
547
	}
548

J
Johannes Berg 已提交
549
	mutex_unlock(&sdata->local->key_mtx);
J
Johannes Berg 已提交
550 551
}

552 553 554 555 556 557 558 559 560 561
void ieee80211_iter_keys(struct ieee80211_hw *hw,
			 struct ieee80211_vif *vif,
			 void (*iter)(struct ieee80211_hw *hw,
				      struct ieee80211_vif *vif,
				      struct ieee80211_sta *sta,
				      struct ieee80211_key_conf *key,
				      void *data),
			 void *iter_data)
{
	struct ieee80211_local *local = hw_to_local(hw);
562
	struct ieee80211_key *key, *tmp;
563 564 565 566 567 568 569
	struct ieee80211_sub_if_data *sdata;

	ASSERT_RTNL();

	mutex_lock(&local->key_mtx);
	if (vif) {
		sdata = vif_to_sdata(vif);
570
		list_for_each_entry_safe(key, tmp, &sdata->key_list, list)
571 572 573 574 575
			iter(hw, &sdata->vif,
			     key->sta ? &key->sta->sta : NULL,
			     &key->conf, iter_data);
	} else {
		list_for_each_entry(sdata, &local->interfaces, list)
576 577
			list_for_each_entry_safe(key, tmp,
						 &sdata->key_list, list)
578 579 580 581 582 583 584 585
				iter(hw, &sdata->vif,
				     key->sta ? &key->sta->sta : NULL,
				     &key->conf, iter_data);
	}
	mutex_unlock(&local->key_mtx);
}
EXPORT_SYMBOL(ieee80211_iter_keys);

586 587
static void ieee80211_free_keys_iface(struct ieee80211_sub_if_data *sdata,
				      struct list_head *keys)
588 589 590
{
	struct ieee80211_key *key, *tmp;

591 592 593 594
	sdata->crypto_tx_tailroom_needed_cnt -=
		sdata->crypto_tx_tailroom_pending_dec;
	sdata->crypto_tx_tailroom_pending_dec = 0;

595
	ieee80211_debugfs_key_remove_mgmt_default(sdata);
596

597 598 599 600
	list_for_each_entry_safe(key, tmp, &sdata->key_list, list) {
		ieee80211_key_replace(key->sdata, key->sta,
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
601
		list_add_tail(&key->list, keys);
602
	}
603

604
	ieee80211_debugfs_key_update_default(sdata);
605
}
606

607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623
void ieee80211_free_keys(struct ieee80211_sub_if_data *sdata,
			 bool force_synchronize)
{
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_sub_if_data *vlan;
	struct ieee80211_key *key, *tmp;
	LIST_HEAD(keys);

	cancel_delayed_work_sync(&sdata->dec_tailroom_needed_wk);

	mutex_lock(&local->key_mtx);

	ieee80211_free_keys_iface(sdata, &keys);

	if (sdata->vif.type == NL80211_IFTYPE_AP) {
		list_for_each_entry(vlan, &sdata->u.ap.vlans, u.vlan.list)
			ieee80211_free_keys_iface(vlan, &keys);
624 625
	}

626 627 628 629 630
	if (!list_empty(&keys) || force_synchronize)
		synchronize_net();
	list_for_each_entry_safe(key, tmp, &keys, list)
		__ieee80211_key_destroy(key, false);

631 632
	WARN_ON_ONCE(sdata->crypto_tx_tailroom_needed_cnt ||
		     sdata->crypto_tx_tailroom_pending_dec);
633 634 635 636 637
	if (sdata->vif.type == NL80211_IFTYPE_AP) {
		list_for_each_entry(vlan, &sdata->u.ap.vlans, u.vlan.list)
			WARN_ON_ONCE(vlan->crypto_tx_tailroom_needed_cnt ||
				     vlan->crypto_tx_tailroom_pending_dec);
	}
638

639
	mutex_unlock(&local->key_mtx);
J
Johannes Berg 已提交
640
}
641

642 643 644
void ieee80211_free_sta_keys(struct ieee80211_local *local,
			     struct sta_info *sta)
{
645
	struct ieee80211_key *key;
646 647 648 649 650 651 652 653 654 655
	int i;

	mutex_lock(&local->key_mtx);
	for (i = 0; i < NUM_DEFAULT_KEYS; i++) {
		key = key_mtx_dereference(local, sta->gtk[i]);
		if (!key)
			continue;
		ieee80211_key_replace(key->sdata, key->sta,
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
656
		__ieee80211_key_destroy(key, true);
657 658
	}

659 660 661 662
	for (i = 0; i < NUM_DEFAULT_KEYS; i++) {
		key = key_mtx_dereference(local, sta->ptk[i]);
		if (!key)
			continue;
663 664 665 666
		ieee80211_key_replace(key->sdata, key->sta,
				key->conf.flags & IEEE80211_KEY_FLAG_PAIRWISE,
				key, NULL);
		__ieee80211_key_destroy(key, true);
667
	}
668 669 670 671

	mutex_unlock(&local->key_mtx);
}

672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700
void ieee80211_delayed_tailroom_dec(struct work_struct *wk)
{
	struct ieee80211_sub_if_data *sdata;

	sdata = container_of(wk, struct ieee80211_sub_if_data,
			     dec_tailroom_needed_wk.work);

	/*
	 * The reason for the delayed tailroom needed decrementing is to
	 * make roaming faster: during roaming, all keys are first deleted
	 * and then new keys are installed. The first new key causes the
	 * crypto_tx_tailroom_needed_cnt to go from 0 to 1, which invokes
	 * the cost of synchronize_net() (which can be slow). Avoid this
	 * by deferring the crypto_tx_tailroom_needed_cnt decrementing on
	 * key removal for a while, so if we roam the value is larger than
	 * zero and no 0->1 transition happens.
	 *
	 * The cost is that if the AP switching was from an AP with keys
	 * to one without, we still allocate tailroom while it would no
	 * longer be needed. However, in the typical (fast) roaming case
	 * within an ESS this usually won't happen.
	 */

	mutex_lock(&sdata->local->key_mtx);
	sdata->crypto_tx_tailroom_needed_cnt -=
		sdata->crypto_tx_tailroom_pending_dec;
	sdata->crypto_tx_tailroom_pending_dec = 0;
	mutex_unlock(&sdata->local->key_mtx);
}
701 702 703 704 705 706 707 708 709 710 711

void ieee80211_gtk_rekey_notify(struct ieee80211_vif *vif, const u8 *bssid,
				const u8 *replay_ctr, gfp_t gfp)
{
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);

	trace_api_gtk_rekey_notify(sdata, bssid, replay_ctr);

	cfg80211_gtk_rekey_notify(sdata->dev, bssid, replay_ctr, gfp);
}
EXPORT_SYMBOL_GPL(ieee80211_gtk_rekey_notify);
712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762

void ieee80211_get_key_tx_seq(struct ieee80211_key_conf *keyconf,
			      struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	u64 pn64;

	if (WARN_ON(!(keyconf->flags & IEEE80211_KEY_FLAG_GENERATE_IV)))
		return;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
		seq->tkip.iv32 = key->u.tkip.tx.iv32;
		seq->tkip.iv16 = key->u.tkip.tx.iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
		pn64 = atomic64_read(&key->u.ccmp.tx_pn);
		seq->ccmp.pn[5] = pn64;
		seq->ccmp.pn[4] = pn64 >> 8;
		seq->ccmp.pn[3] = pn64 >> 16;
		seq->ccmp.pn[2] = pn64 >> 24;
		seq->ccmp.pn[1] = pn64 >> 32;
		seq->ccmp.pn[0] = pn64 >> 40;
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		pn64 = atomic64_read(&key->u.aes_cmac.tx_pn);
		seq->ccmp.pn[5] = pn64;
		seq->ccmp.pn[4] = pn64 >> 8;
		seq->ccmp.pn[3] = pn64 >> 16;
		seq->ccmp.pn[2] = pn64 >> 24;
		seq->ccmp.pn[1] = pn64 >> 32;
		seq->ccmp.pn[0] = pn64 >> 40;
		break;
	default:
		WARN_ON(1);
	}
}
EXPORT_SYMBOL(ieee80211_get_key_tx_seq);

void ieee80211_get_key_rx_seq(struct ieee80211_key_conf *keyconf,
			      int tid, struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	const u8 *pn;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
763
		if (WARN_ON(tid < 0 || tid >= IEEE80211_NUM_TIDS))
764 765 766 767 768
			return;
		seq->tkip.iv32 = key->u.tkip.rx[tid].iv32;
		seq->tkip.iv16 = key->u.tkip.rx[tid].iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
769
		if (WARN_ON(tid < -1 || tid >= IEEE80211_NUM_TIDS))
770 771
			return;
		if (tid < 0)
772
			pn = key->u.ccmp.rx_pn[IEEE80211_NUM_TIDS];
773 774
		else
			pn = key->u.ccmp.rx_pn[tid];
775
		memcpy(seq->ccmp.pn, pn, IEEE80211_CCMP_PN_LEN);
776 777 778 779 780
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		if (WARN_ON(tid != 0))
			return;
		pn = key->u.aes_cmac.rx_pn;
781
		memcpy(seq->aes_cmac.pn, pn, IEEE80211_CMAC_PN_LEN);
782 783 784 785
		break;
	}
}
EXPORT_SYMBOL(ieee80211_get_key_rx_seq);
786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876

void ieee80211_set_key_tx_seq(struct ieee80211_key_conf *keyconf,
			      struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	u64 pn64;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
		key->u.tkip.tx.iv32 = seq->tkip.iv32;
		key->u.tkip.tx.iv16 = seq->tkip.iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
		pn64 = (u64)seq->ccmp.pn[5] |
		       ((u64)seq->ccmp.pn[4] << 8) |
		       ((u64)seq->ccmp.pn[3] << 16) |
		       ((u64)seq->ccmp.pn[2] << 24) |
		       ((u64)seq->ccmp.pn[1] << 32) |
		       ((u64)seq->ccmp.pn[0] << 40);
		atomic64_set(&key->u.ccmp.tx_pn, pn64);
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		pn64 = (u64)seq->aes_cmac.pn[5] |
		       ((u64)seq->aes_cmac.pn[4] << 8) |
		       ((u64)seq->aes_cmac.pn[3] << 16) |
		       ((u64)seq->aes_cmac.pn[2] << 24) |
		       ((u64)seq->aes_cmac.pn[1] << 32) |
		       ((u64)seq->aes_cmac.pn[0] << 40);
		atomic64_set(&key->u.aes_cmac.tx_pn, pn64);
		break;
	default:
		WARN_ON(1);
		break;
	}
}
EXPORT_SYMBOL_GPL(ieee80211_set_key_tx_seq);

void ieee80211_set_key_rx_seq(struct ieee80211_key_conf *keyconf,
			      int tid, struct ieee80211_key_seq *seq)
{
	struct ieee80211_key *key;
	u8 *pn;

	key = container_of(keyconf, struct ieee80211_key, conf);

	switch (key->conf.cipher) {
	case WLAN_CIPHER_SUITE_TKIP:
		if (WARN_ON(tid < 0 || tid >= IEEE80211_NUM_TIDS))
			return;
		key->u.tkip.rx[tid].iv32 = seq->tkip.iv32;
		key->u.tkip.rx[tid].iv16 = seq->tkip.iv16;
		break;
	case WLAN_CIPHER_SUITE_CCMP:
		if (WARN_ON(tid < -1 || tid >= IEEE80211_NUM_TIDS))
			return;
		if (tid < 0)
			pn = key->u.ccmp.rx_pn[IEEE80211_NUM_TIDS];
		else
			pn = key->u.ccmp.rx_pn[tid];
		memcpy(pn, seq->ccmp.pn, IEEE80211_CCMP_PN_LEN);
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		if (WARN_ON(tid != 0))
			return;
		pn = key->u.aes_cmac.rx_pn;
		memcpy(pn, seq->aes_cmac.pn, IEEE80211_CMAC_PN_LEN);
		break;
	default:
		WARN_ON(1);
		break;
	}
}
EXPORT_SYMBOL_GPL(ieee80211_set_key_rx_seq);

void ieee80211_remove_key(struct ieee80211_key_conf *keyconf)
{
	struct ieee80211_key *key;

	key = container_of(keyconf, struct ieee80211_key, conf);

	assert_key_lock(key->local);

	/*
	 * if key was uploaded, we assume the driver will/has remove(d)
	 * it, so adjust bookkeeping accordingly
	 */
	if (key->flags & KEY_FLAG_UPLOADED_TO_HARDWARE) {
		key->flags &= ~KEY_FLAG_UPLOADED_TO_HARDWARE;

877
		if (!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIC))
878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901
			increment_tailroom_need_count(key->sdata);
	}

	ieee80211_key_free(key, false);
}
EXPORT_SYMBOL_GPL(ieee80211_remove_key);

struct ieee80211_key_conf *
ieee80211_gtk_rekey_add(struct ieee80211_vif *vif,
			struct ieee80211_key_conf *keyconf)
{
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_key *key;
	int err;

	if (WARN_ON(!local->wowlan))
		return ERR_PTR(-EINVAL);

	if (WARN_ON(vif->type != NL80211_IFTYPE_STATION))
		return ERR_PTR(-EINVAL);

	key = ieee80211_key_alloc(keyconf->cipher, keyconf->keyidx,
				  keyconf->keylen, keyconf->key,
902
				  0, NULL, NULL);
903
	if (IS_ERR(key))
J
Johannes Berg 已提交
904
		return ERR_CAST(key);
905 906 907 908 909 910 911 912 913 914 915

	if (sdata->u.mgd.mfp != IEEE80211_MFP_DISABLED)
		key->conf.flags |= IEEE80211_KEY_FLAG_RX_MGMT;

	err = ieee80211_key_link(key, sdata, NULL);
	if (err)
		return ERR_PTR(err);

	return &key->conf;
}
EXPORT_SYMBOL_GPL(ieee80211_gtk_rekey_add);