2 * hostapd / WMM (Wi-Fi Multimedia)
3 * Copyright 2002-2003, Instant802 Networks, Inc.
4 * Copyright 2005-2006, Devicescape Software, Inc.
5 * Copyright (c) 2009, Jouni Malinen <j@w1.fi>
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License version 2 as
9 * published by the Free Software Foundation.
11 * Alternatively, this software may be distributed under the terms of BSD
14 * See README and COPYING for more details.
17 #include "utils/includes.h"
19 #include "utils/common.h"
20 #include "common/ieee802_11_defs.h"
21 #include "common/ieee802_11_common.h"
23 #include "ieee802_11.h"
25 #include "ap_config.h"
29 /* TODO: maintain separate sequence and fragment numbers for each AC
30 * TODO: IGMP snooping to track which multicasts to forward - and use QOS-DATA
31 * if only WMM stations are receiving a certain group */
34 static inline u8
wmm_aci_aifsn(int aifsn
, int acm
, int aci
)
37 ret
= (aifsn
<< WMM_AC_AIFNS_SHIFT
) & WMM_AC_AIFSN_MASK
;
40 ret
|= (aci
<< WMM_AC_ACI_SHIFT
) & WMM_AC_ACI_MASK
;
45 static inline u8
wmm_ecw(int ecwmin
, int ecwmax
)
47 return ((ecwmin
<< WMM_AC_ECWMIN_SHIFT
) & WMM_AC_ECWMIN_MASK
) |
48 ((ecwmax
<< WMM_AC_ECWMAX_SHIFT
) & WMM_AC_ECWMAX_MASK
);
53 * Add WMM Parameter Element to Beacon, Probe Response, and (Re)Association
56 u8
* hostapd_eid_wmm(struct hostapd_data
*hapd
, u8
*eid
)
59 struct wmm_parameter_element
*wmm
=
60 (struct wmm_parameter_element
*) (pos
+ 2);
63 if (!hapd
->conf
->wmm_enabled
)
65 eid
[0] = WLAN_EID_VENDOR_SPECIFIC
;
69 wmm
->oui_type
= WMM_OUI_TYPE
;
70 wmm
->oui_subtype
= WMM_OUI_SUBTYPE_PARAMETER_ELEMENT
;
71 wmm
->version
= WMM_VERSION
;
72 wmm
->qos_info
= hapd
->parameter_set_count
& 0xf;
74 /* fill in a parameter set record for each AC */
75 for (e
= 0; e
< 4; e
++) {
76 struct wmm_ac_parameter
*ac
= &wmm
->ac
[e
];
77 struct hostapd_wmm_ac_params
*acp
=
78 &hapd
->iconf
->wmm_ac_params
[e
];
80 ac
->aci_aifsn
= wmm_aci_aifsn(acp
->aifs
,
81 acp
->admission_control_mandatory
,
83 ac
->cw
= wmm_ecw(acp
->cwmin
, acp
->cwmax
);
84 ac
->txop_limit
= host_to_le16(acp
->txop_limit
);
87 pos
= (u8
*) (wmm
+ 1);
88 eid
[1] = pos
- eid
- 2; /* element length */
94 /* This function is called when a station sends an association request with
95 * WMM info element. The function returns zero on success or non-zero on any
96 * error in WMM element. eid does not include Element ID and Length octets. */
97 int hostapd_eid_wmm_valid(struct hostapd_data
*hapd
, const u8
*eid
, size_t len
)
99 struct wmm_information_element
*wmm
;
101 wpa_hexdump(MSG_MSGDUMP
, "WMM IE", eid
, len
);
103 if (len
< sizeof(struct wmm_information_element
)) {
104 wpa_printf(MSG_DEBUG
, "Too short WMM IE (len=%lu)",
105 (unsigned long) len
);
109 wmm
= (struct wmm_information_element
*) eid
;
110 wpa_printf(MSG_DEBUG
, "Validating WMM IE: OUI %02x:%02x:%02x "
111 "OUI type %d OUI sub-type %d version %d QoS info 0x%x",
112 wmm
->oui
[0], wmm
->oui
[1], wmm
->oui
[2], wmm
->oui_type
,
113 wmm
->oui_subtype
, wmm
->version
, wmm
->qos_info
);
114 if (wmm
->oui_subtype
!= WMM_OUI_SUBTYPE_INFORMATION_ELEMENT
||
115 wmm
->version
!= WMM_VERSION
) {
116 wpa_printf(MSG_DEBUG
, "Unsupported WMM IE Subtype/Version");
124 static void wmm_send_action(struct hostapd_data
*hapd
, const u8
*addr
,
125 const struct wmm_tspec_element
*tspec
,
126 u8 action_code
, u8 dialogue_token
, u8 status_code
)
129 struct ieee80211_mgmt
*m
= (struct ieee80211_mgmt
*) buf
;
130 struct wmm_tspec_element
*t
= (struct wmm_tspec_element
*)
131 m
->u
.action
.u
.wmm_action
.variable
;
134 hostapd_logger(hapd
, addr
, HOSTAPD_MODULE_IEEE80211
,
136 "action response - reason %d", status_code
);
137 os_memset(buf
, 0, sizeof(buf
));
138 m
->frame_control
= IEEE80211_FC(WLAN_FC_TYPE_MGMT
,
139 WLAN_FC_STYPE_ACTION
);
140 os_memcpy(m
->da
, addr
, ETH_ALEN
);
141 os_memcpy(m
->sa
, hapd
->own_addr
, ETH_ALEN
);
142 os_memcpy(m
->bssid
, hapd
->own_addr
, ETH_ALEN
);
143 m
->u
.action
.category
= WLAN_ACTION_WMM
;
144 m
->u
.action
.u
.wmm_action
.action_code
= action_code
;
145 m
->u
.action
.u
.wmm_action
.dialog_token
= dialogue_token
;
146 m
->u
.action
.u
.wmm_action
.status_code
= status_code
;
147 os_memcpy(t
, tspec
, sizeof(struct wmm_tspec_element
));
148 len
= ((u8
*) (t
+ 1)) - buf
;
150 if (hapd
->drv
.send_mgmt_frame(hapd
, m
, len
) < 0)
151 perror("wmm_send_action: send");
155 int wmm_process_tspec(struct wmm_tspec_element
*tspec
)
157 int medium_time
, pps
, duration
;
158 int up
, psb
, dir
, tid
;
161 up
= (tspec
->ts_info
[1] >> 3) & 0x07;
162 psb
= (tspec
->ts_info
[1] >> 2) & 0x01;
163 dir
= (tspec
->ts_info
[0] >> 5) & 0x03;
164 tid
= (tspec
->ts_info
[0] >> 1) & 0x0f;
165 wpa_printf(MSG_DEBUG
, "WMM: TS Info: UP=%d PSB=%d Direction=%d TID=%d",
167 val
= le_to_host16(tspec
->nominal_msdu_size
);
168 wpa_printf(MSG_DEBUG
, "WMM: Nominal MSDU Size: %d%s",
169 val
& 0x7fff, val
& 0x8000 ? " (fixed)" : "");
170 wpa_printf(MSG_DEBUG
, "WMM: Mean Data Rate: %u bps",
171 le_to_host32(tspec
->mean_data_rate
));
172 wpa_printf(MSG_DEBUG
, "WMM: Minimum PHY Rate: %u bps",
173 le_to_host32(tspec
->minimum_phy_rate
));
174 val
= le_to_host16(tspec
->surplus_bandwidth_allowance
);
175 wpa_printf(MSG_DEBUG
, "WMM: Surplus Bandwidth Allowance: %u.%04u",
176 val
>> 13, 10000 * (val
& 0x1fff) / 0x2000);
178 val
= le_to_host16(tspec
->nominal_msdu_size
);
180 wpa_printf(MSG_DEBUG
, "WMM: Invalid Nominal MSDU Size (0)");
181 return WMM_ADDTS_STATUS_INVALID_PARAMETERS
;
183 /* pps = Ceiling((Mean Data Rate / 8) / Nominal MSDU Size) */
184 pps
= ((le_to_host32(tspec
->mean_data_rate
) / 8) + val
- 1) / val
;
185 wpa_printf(MSG_DEBUG
, "WMM: Packets-per-second estimate for TSPEC: %d",
188 if (le_to_host32(tspec
->minimum_phy_rate
) < 1000000) {
189 wpa_printf(MSG_DEBUG
, "WMM: Too small Minimum PHY Rate");
190 return WMM_ADDTS_STATUS_INVALID_PARAMETERS
;
193 duration
= (le_to_host16(tspec
->nominal_msdu_size
) & 0x7fff) * 8 /
194 (le_to_host32(tspec
->minimum_phy_rate
) / 1000000) +
195 50 /* FIX: proper SIFS + ACK duration */;
197 /* unsigned binary number with an implicit binary point after the
198 * leftmost 3 bits, i.e., 0x2000 = 1.0 */
199 surplus
= le_to_host16(tspec
->surplus_bandwidth_allowance
);
200 if (surplus
<= 0x2000) {
201 wpa_printf(MSG_DEBUG
, "WMM: Surplus Bandwidth Allowance not "
202 "greater than unity");
203 return WMM_ADDTS_STATUS_INVALID_PARAMETERS
;
206 medium_time
= surplus
* pps
* duration
/ 0x2000;
207 wpa_printf(MSG_DEBUG
, "WMM: Estimated medium time: %u", medium_time
);
210 * TODO: store list of granted (and still active) TSPECs and check
211 * whether there is available medium time for this request. For now,
212 * just refuse requests that would by themselves take very large
213 * portion of the available bandwidth.
215 if (medium_time
> 750000) {
216 wpa_printf(MSG_DEBUG
, "WMM: Refuse TSPEC request for over "
217 "75%% of available bandwidth");
218 return WMM_ADDTS_STATUS_REFUSED
;
221 /* Convert to 32 microseconds per second unit */
222 tspec
->medium_time
= host_to_le16(medium_time
/ 32);
224 return WMM_ADDTS_STATUS_ADMISSION_ACCEPTED
;
228 static void wmm_addts_req(struct hostapd_data
*hapd
,
229 const struct ieee80211_mgmt
*mgmt
,
230 struct wmm_tspec_element
*tspec
, size_t len
)
232 const u8
*end
= ((const u8
*) mgmt
) + len
;
235 if ((const u8
*) (tspec
+ 1) > end
) {
236 wpa_printf(MSG_DEBUG
, "WMM: TSPEC overflow in ADDTS Request");
240 wpa_printf(MSG_DEBUG
, "WMM: ADDTS Request (Dialog Token %d) for TSPEC "
242 mgmt
->u
.action
.u
.wmm_action
.dialog_token
,
245 res
= wmm_process_tspec(tspec
);
246 wpa_printf(MSG_DEBUG
, "WMM: ADDTS processing result: %d", res
);
248 wmm_send_action(hapd
, mgmt
->sa
, tspec
, WMM_ACTION_CODE_ADDTS_RESP
,
249 mgmt
->u
.action
.u
.wmm_action
.dialog_token
, res
);
253 void hostapd_wmm_action(struct hostapd_data
*hapd
,
254 const struct ieee80211_mgmt
*mgmt
, size_t len
)
257 int left
= len
- IEEE80211_HDRLEN
- 4;
258 const u8
*pos
= ((const u8
*) mgmt
) + IEEE80211_HDRLEN
+ 4;
259 struct ieee802_11_elems elems
;
260 struct sta_info
*sta
= ap_get_sta(hapd
, mgmt
->sa
);
262 /* check that the request comes from a valid station */
264 (sta
->flags
& (WLAN_STA_ASSOC
| WLAN_STA_WMM
)) !=
265 (WLAN_STA_ASSOC
| WLAN_STA_WMM
)) {
266 hostapd_logger(hapd
, mgmt
->sa
, HOSTAPD_MODULE_IEEE80211
,
268 "wmm action received is not from associated wmm"
270 /* TODO: respond with action frame refused status code */
274 /* extract the tspec info element */
275 if (ieee802_11_parse_elems(pos
, left
, &elems
, 1) == ParseFailed
) {
276 hostapd_logger(hapd
, mgmt
->sa
, HOSTAPD_MODULE_IEEE80211
,
278 "hostapd_wmm_action - could not parse wmm "
280 /* TODO: respond with action frame invalid parameters status
285 if (!elems
.wmm_tspec
||
286 elems
.wmm_tspec_len
!= (sizeof(struct wmm_tspec_element
) - 2)) {
287 hostapd_logger(hapd
, mgmt
->sa
, HOSTAPD_MODULE_IEEE80211
,
289 "hostapd_wmm_action - missing or wrong length "
291 /* TODO: respond with action frame invalid parameters status
296 /* TODO: check the request is for an AC with ACM set, if not, refuse
299 action_code
= mgmt
->u
.action
.u
.wmm_action
.action_code
;
300 switch (action_code
) {
301 case WMM_ACTION_CODE_ADDTS_REQ
:
302 wmm_addts_req(hapd
, mgmt
, (struct wmm_tspec_element
*)
303 (elems
.wmm_tspec
- 2), len
);
306 /* TODO: needed for client implementation */
307 case WMM_ACTION_CODE_ADDTS_RESP
:
308 wmm_setup_request(hapd
, mgmt
, len
);
310 /* TODO: handle station teardown requests */
311 case WMM_ACTION_CODE_DELTS
:
312 wmm_teardown(hapd
, mgmt
, len
);
317 hostapd_logger(hapd
, mgmt
->sa
, HOSTAPD_MODULE_IEEE80211
,
319 "hostapd_wmm_action - unknown action code %d",