Bug: 124017368 Test: Device boots up and connects to WPA3/OWE wifi networks, run traffic. Test: Able to turn on/off softap, associate wifi STA, run traffic. Test: DPP functional test. Test: Regression test passed (Bug: 124301325) fe468b071 HE: Fix set_he_cap() parsing of config options for MU EDCA Params f3a841bbf Do not disassociate not-associated STA on timeout 91205c8eb OpenSSL: Fix uninitialized variable in CRL reloading corner case 092a19222 Use for_each_element() in ieee802_11_parse_elems() b50a63896 common: Use for_each_element_id/_extid for get_ie/get_ie_ext/get_vendor_ie b64479742 common: Use for_each_element_id() in mb_ies_info_by_ies() 9008048f0 common: Use for_each_element_id() in ieee802_11_vendor_ie_concat() eb84238df common: Use for_each_element() in ieee802_11_ie_count() 0e0c31bdc common: Add strongly typed element iteration macros 525923b1d tests: EAPOL-Key fuzzing tool 02a0a2393 RSN: Do not start preauthentication timer without candidates 1e5506588 JSON: Fix string parsing when \\ escape is at the end of buffer 0dedcb315 JSON: Fix parsing of a number from the end of the buffer 79fa1b453 tests: JSON parser fuzzer 62269c8d8 TLS: Fix X.509 certificate name conversion into empty string 3eae9766b TLS: Fix ASN.1 parsing with no room for the header fbc2123a1 TLS: Fix AlertDescription for missing partial processing case 1ac9c020b tests: TLS fuzzing tool f3cca8b1e TLS server: Check credentials have been configured before using them 19dd7a736 TLS server: Local failure information on verify_data mismatch f08ab18bf TLS server: Add internal callbacks get_failed, get_*_alerts b642ab406 TLS server: More complete logging of ClientHello decode errors fdd8a2f0b TLS client: Fix peer certificate event checking for probing e5bffe1aa OpenSSL: Add more handshake message names to debug 21cd8f831 nl80211: Use wpa_ssid_txt() for debug messages more consistently bbdb50146 Note HT overrides in debug log only if set f2a6ac63e P2P: Update find_start timer only when p2p_scan is started. c4e90da6d MBO: Move the WNM-Notification subtype definitions to common location 105b14f54 HS 2.0: Update the T&C Acceptance subtype value 65b487ae5 HS 2.0: Add QUIET=1 support for building hs20-osu-client 73f285dad Add FT-PSK to GET_CAPABILITY key_mgmt 6110753b1 nl80211: Clear PMKID add command message buffer 0fa33e05b nl80211: Clear connect command message buffer b14e8ea1d nl80211: Request kernel to trim off payload of netlink requests from acks 789b48bb4 EAP peer: Clear temporary message buffers before freeing 8f99a3c26 Clear config item writing buffer before freeing it a68e9b698 D-Bus: Fix P2P DeleteService dict iteration 0607346f1 D-Bus: Fix a memory leak in DeleteService handler d05dda61d PEAP: Explicitly clear temporary keys from memory when using CMK 4e1cd3468 EAP-PEAP: Derive EMSK and use 128-octet derivation for MSK d8c20ec59 DPP: Clear dpp_listen_freq on remain-on-channel failure 59fa20538 P2P: Allow the avoid channels for P2P discovery/negotiation e34cd9f06 WNM: Fix WNM-Sleep Mode Request bounds checking 159a7fbde crl_reload_interval: Add CRL reloading support 83c860813 AP: Add wpa_psk_file reloading in runtime ec5c39a55 AP: Allow identifying which passphrase station used with wpa_psk_file b08c9ad0c AP: Expose PMK outside of wpa_auth module 89896c000 tests: Use python3 compatible print statement bab493b90 tests: Use python3 compatible "except" statement 0dab47733 Write multi_ap_backhaul_sta to wpa_supplicant config 98251c6f2 dbus: Document more possible BSS/RSA/KeyMgmt values 1e591df06 Check supported types in wpas_mac_addr_rand_scan_set() c85249aa1 Fix test compilation error related to sme_event_unprot_disconnect() 42d308635 SAE: Advertise Password Identifier use 59c693064 HS 2.0 server: Command line option to fetch the version information 2d1762fa4 HS 2.0 server: Alternative subrem updateNode for certificate credentials d97cf2a11 HS 2.0 server: Use noMOUpdate in client certificate subrem 13a200a92 FILS: Remove notes about experimental implementation 86d4e0537 dbus: Expose support of SAE key management in BSS properties Change-Id: Id507b73f1f4a2e356cbcd3bfcfb9dcd23c8fd9e0
343 lines
9.8 KiB
Python
Executable File
343 lines
9.8 KiB
Python
Executable File
#!/usr/bin/python
|
|
#
|
|
# Example nfcpy to hostapd wrapper for WPS NFC operations
|
|
# Copyright (c) 2012-2013, Jouni Malinen <j@w1.fi>
|
|
#
|
|
# This software may be distributed under the terms of the BSD license.
|
|
# See README for more details.
|
|
|
|
import os
|
|
import sys
|
|
import time
|
|
import argparse
|
|
|
|
import nfc
|
|
import nfc.ndef
|
|
import nfc.llcp
|
|
import nfc.handover
|
|
|
|
import logging
|
|
|
|
import wpaspy
|
|
|
|
wpas_ctrl = '/var/run/hostapd'
|
|
continue_loop = True
|
|
summary_file = None
|
|
success_file = None
|
|
|
|
def summary(txt):
|
|
print(txt)
|
|
if summary_file:
|
|
with open(summary_file, 'a') as f:
|
|
f.write(txt + "\n")
|
|
|
|
def success_report(txt):
|
|
summary(txt)
|
|
if success_file:
|
|
with open(success_file, 'a') as f:
|
|
f.write(txt + "\n")
|
|
|
|
def wpas_connect():
|
|
ifaces = []
|
|
if os.path.isdir(wpas_ctrl):
|
|
try:
|
|
ifaces = [os.path.join(wpas_ctrl, i) for i in os.listdir(wpas_ctrl)]
|
|
except OSError as error:
|
|
print("Could not find hostapd: ", error)
|
|
return None
|
|
|
|
if len(ifaces) < 1:
|
|
print("No hostapd control interface found")
|
|
return None
|
|
|
|
for ctrl in ifaces:
|
|
try:
|
|
wpas = wpaspy.Ctrl(ctrl)
|
|
return wpas
|
|
except Exception as e:
|
|
pass
|
|
return None
|
|
|
|
|
|
def wpas_tag_read(message):
|
|
wpas = wpas_connect()
|
|
if (wpas == None):
|
|
return False
|
|
if "FAIL" in wpas.request("WPS_NFC_TAG_READ " + str(message).encode("hex")):
|
|
return False
|
|
return True
|
|
|
|
|
|
def wpas_get_config_token():
|
|
wpas = wpas_connect()
|
|
if (wpas == None):
|
|
return None
|
|
ret = wpas.request("WPS_NFC_CONFIG_TOKEN NDEF")
|
|
if "FAIL" in ret:
|
|
return None
|
|
return ret.rstrip().decode("hex")
|
|
|
|
|
|
def wpas_get_password_token():
|
|
wpas = wpas_connect()
|
|
if (wpas == None):
|
|
return None
|
|
ret = wpas.request("WPS_NFC_TOKEN NDEF")
|
|
if "FAIL" in ret:
|
|
return None
|
|
return ret.rstrip().decode("hex")
|
|
|
|
|
|
def wpas_get_handover_sel():
|
|
wpas = wpas_connect()
|
|
if (wpas == None):
|
|
return None
|
|
ret = wpas.request("NFC_GET_HANDOVER_SEL NDEF WPS-CR")
|
|
if "FAIL" in ret:
|
|
return None
|
|
return ret.rstrip().decode("hex")
|
|
|
|
|
|
def wpas_report_handover(req, sel):
|
|
wpas = wpas_connect()
|
|
if (wpas == None):
|
|
return None
|
|
return wpas.request("NFC_REPORT_HANDOVER RESP WPS " +
|
|
str(req).encode("hex") + " " +
|
|
str(sel).encode("hex"))
|
|
|
|
|
|
class HandoverServer(nfc.handover.HandoverServer):
|
|
def __init__(self, llc):
|
|
super(HandoverServer, self).__init__(llc)
|
|
self.ho_server_processing = False
|
|
self.success = False
|
|
|
|
# override to avoid parser error in request/response.pretty() in nfcpy
|
|
# due to new WSC handover format
|
|
def _process_request(self, request):
|
|
summary("received handover request {}".format(request.type))
|
|
response = nfc.ndef.Message("\xd1\x02\x01Hs\x12")
|
|
if not request.type == 'urn:nfc:wkt:Hr':
|
|
summary("not a handover request")
|
|
else:
|
|
try:
|
|
request = nfc.ndef.HandoverRequestMessage(request)
|
|
except nfc.ndef.DecodeError as e:
|
|
summary("error decoding 'Hr' message: {}".format(e))
|
|
else:
|
|
response = self.process_request(request)
|
|
summary("send handover response {}".format(response.type))
|
|
return response
|
|
|
|
def process_request(self, request):
|
|
summary("HandoverServer - request received")
|
|
try:
|
|
print("Parsed handover request: " + request.pretty())
|
|
except Exception as e:
|
|
print(e)
|
|
print(str(request).encode("hex"))
|
|
|
|
sel = nfc.ndef.HandoverSelectMessage(version="1.2")
|
|
|
|
for carrier in request.carriers:
|
|
print("Remote carrier type: " + carrier.type)
|
|
if carrier.type == "application/vnd.wfa.wsc":
|
|
summary("WPS carrier type match - add WPS carrier record")
|
|
data = wpas_get_handover_sel()
|
|
if data is None:
|
|
summary("Could not get handover select carrier record from hostapd")
|
|
continue
|
|
print("Handover select carrier record from hostapd:")
|
|
print(data.encode("hex"))
|
|
if "OK" in wpas_report_handover(carrier.record, data):
|
|
success_report("Handover reported successfully")
|
|
else:
|
|
summary("Handover report rejected")
|
|
|
|
message = nfc.ndef.Message(data);
|
|
sel.add_carrier(message[0], "active", message[1:])
|
|
|
|
print("Handover select:")
|
|
try:
|
|
print(sel.pretty())
|
|
except Exception as e:
|
|
print(e)
|
|
print(str(sel).encode("hex"))
|
|
|
|
summary("Sending handover select")
|
|
self.success = True
|
|
return sel
|
|
|
|
|
|
def wps_tag_read(tag):
|
|
success = False
|
|
if len(tag.ndef.message):
|
|
for record in tag.ndef.message:
|
|
print("record type " + record.type)
|
|
if record.type == "application/vnd.wfa.wsc":
|
|
summary("WPS tag - send to hostapd")
|
|
success = wpas_tag_read(tag.ndef.message)
|
|
break
|
|
else:
|
|
summary("Empty tag")
|
|
|
|
if success:
|
|
success_report("Tag read succeeded")
|
|
|
|
return success
|
|
|
|
|
|
def rdwr_connected_write(tag):
|
|
summary("Tag found - writing - " + str(tag))
|
|
global write_data
|
|
tag.ndef.message = str(write_data)
|
|
success_report("Tag write succeeded")
|
|
print("Done - remove tag")
|
|
global only_one
|
|
if only_one:
|
|
global continue_loop
|
|
continue_loop = False
|
|
global write_wait_remove
|
|
while write_wait_remove and tag.is_present:
|
|
time.sleep(0.1)
|
|
|
|
def wps_write_config_tag(clf, wait_remove=True):
|
|
summary("Write WPS config token")
|
|
global write_data, write_wait_remove
|
|
write_wait_remove = wait_remove
|
|
write_data = wpas_get_config_token()
|
|
if write_data == None:
|
|
summary("Could not get WPS config token from hostapd")
|
|
return
|
|
|
|
print("Touch an NFC tag")
|
|
clf.connect(rdwr={'on-connect': rdwr_connected_write})
|
|
|
|
|
|
def wps_write_password_tag(clf, wait_remove=True):
|
|
summary("Write WPS password token")
|
|
global write_data, write_wait_remove
|
|
write_wait_remove = wait_remove
|
|
write_data = wpas_get_password_token()
|
|
if write_data == None:
|
|
summary("Could not get WPS password token from hostapd")
|
|
return
|
|
|
|
print("Touch an NFC tag")
|
|
clf.connect(rdwr={'on-connect': rdwr_connected_write})
|
|
|
|
|
|
def rdwr_connected(tag):
|
|
global only_one, no_wait
|
|
summary("Tag connected: " + str(tag))
|
|
|
|
if tag.ndef:
|
|
print("NDEF tag: " + tag.type)
|
|
try:
|
|
print(tag.ndef.message.pretty())
|
|
except Exception as e:
|
|
print(e)
|
|
success = wps_tag_read(tag)
|
|
if only_one and success:
|
|
global continue_loop
|
|
continue_loop = False
|
|
else:
|
|
summary("Not an NDEF tag - remove tag")
|
|
return True
|
|
|
|
return not no_wait
|
|
|
|
|
|
def llcp_startup(clf, llc):
|
|
print("Start LLCP server")
|
|
global srv
|
|
srv = HandoverServer(llc)
|
|
return llc
|
|
|
|
def llcp_connected(llc):
|
|
print("P2P LLCP connected")
|
|
global wait_connection
|
|
wait_connection = False
|
|
global srv
|
|
srv.start()
|
|
return True
|
|
|
|
|
|
def main():
|
|
clf = nfc.ContactlessFrontend()
|
|
|
|
parser = argparse.ArgumentParser(description='nfcpy to hostapd integration for WPS NFC operations')
|
|
parser.add_argument('-d', const=logging.DEBUG, default=logging.INFO,
|
|
action='store_const', dest='loglevel',
|
|
help='verbose debug output')
|
|
parser.add_argument('-q', const=logging.WARNING, action='store_const',
|
|
dest='loglevel', help='be quiet')
|
|
parser.add_argument('--only-one', '-1', action='store_true',
|
|
help='run only one operation and exit')
|
|
parser.add_argument('--no-wait', action='store_true',
|
|
help='do not wait for tag to be removed before exiting')
|
|
parser.add_argument('--summary',
|
|
help='summary file for writing status updates')
|
|
parser.add_argument('--success',
|
|
help='success file for writing success update')
|
|
parser.add_argument('command', choices=['write-config',
|
|
'write-password'],
|
|
nargs='?')
|
|
args = parser.parse_args()
|
|
|
|
global only_one
|
|
only_one = args.only_one
|
|
|
|
global no_wait
|
|
no_wait = args.no_wait
|
|
|
|
if args.summary:
|
|
global summary_file
|
|
summary_file = args.summary
|
|
|
|
if args.success:
|
|
global success_file
|
|
success_file = args.success
|
|
|
|
logging.basicConfig(level=args.loglevel)
|
|
|
|
try:
|
|
if not clf.open("usb"):
|
|
print("Could not open connection with an NFC device")
|
|
raise SystemExit
|
|
|
|
if args.command == "write-config":
|
|
wps_write_config_tag(clf, wait_remove=not args.no_wait)
|
|
raise SystemExit
|
|
|
|
if args.command == "write-password":
|
|
wps_write_password_tag(clf, wait_remove=not args.no_wait)
|
|
raise SystemExit
|
|
|
|
global continue_loop
|
|
while continue_loop:
|
|
print("Waiting for a tag or peer to be touched")
|
|
wait_connection = True
|
|
try:
|
|
if not clf.connect(rdwr={'on-connect': rdwr_connected},
|
|
llcp={'on-startup': llcp_startup,
|
|
'on-connect': llcp_connected}):
|
|
break
|
|
except Exception as e:
|
|
print("clf.connect failed")
|
|
|
|
global srv
|
|
if only_one and srv and srv.success:
|
|
raise SystemExit
|
|
|
|
except KeyboardInterrupt:
|
|
raise SystemExit
|
|
finally:
|
|
clf.close()
|
|
|
|
raise SystemExit
|
|
|
|
if __name__ == '__main__':
|
|
main()
|