hostapd: Expose the tdls_prohibit option to UCI
[openwrt/openwrt.git] / package / network / services / hostapd / files / hostapd.sh
index 3766b7a7c92f46fb9a6db4b7aaf0dbb930eb451b..4970874e6d8ff40e82ba112caae3d229f3f8a2c2 100644 (file)
@@ -149,6 +149,9 @@ hostapd_common_add_bss_config() {
        config_add_int \
                wep_rekey eap_reauth_period \
                wpa_group_rekey wpa_pair_rekey wpa_master_rekey
+       config_add_boolean wpa_disable_eapol_key_retries
+
+       config_add_boolean tdls_prohibit
 
        config_add_boolean rsn_preauth auth_cache
        config_add_int ieee80211w
@@ -214,6 +217,7 @@ hostapd_set_bss_options() {
 
        json_get_vars \
                wep_rekey wpa_group_rekey wpa_pair_rekey wpa_master_rekey \
+               wpa_disable_eapol_key_retries tdls_prohibit \
                maxassoc max_inactivity disassoc_low_ack isolate auth_cache \
                wps_pushbutton wps_label ext_registrar wps_pbc_in_m1 wps_ap_setup_locked \
                wps_independent wps_device_type wps_device_name wps_manufacturer wps_pin \
@@ -229,6 +233,8 @@ hostapd_set_bss_options() {
        set_default hidden 0
        set_default wmm 1
        set_default uapsd 1
+       set_default wpa_disable_eapol_key_retries 0
+       set_default tdls_prohibit 0
        set_default eapol_version 0
        set_default acct_port 1813
 
@@ -249,6 +255,8 @@ hostapd_set_bss_options() {
        append bss_conf "ignore_broadcast_ssid=$hidden" "$N"
        append bss_conf "uapsd_advertisement_enabled=$uapsd" "$N"
 
+       [ "$tdls_prohibit" -gt 0 ] && append bss_conf "tdls_prohibit=$tdls_prohibit" "$N"
+
        [ "$wpa" -gt 0 ] && {
                [ -n "$wpa_group_rekey"  ] && append bss_conf "wpa_group_rekey=$wpa_group_rekey" "$N"
                [ -n "$wpa_pair_rekey"   ] && append bss_conf "wpa_ptk_rekey=$wpa_pair_rekey"    "$N"
@@ -394,7 +402,6 @@ hostapd_set_bss_options() {
 
                        set_default mobility_domain "4f57"
                        set_default r0_key_lifetime 10000
-                       set_default r1_key_holder "00004f577274"
                        set_default reassociation_deadline 1000
                        set_default pmk_r1_push 0
                        set_default ft_psk_generate_local 0
@@ -402,7 +409,7 @@ hostapd_set_bss_options() {
 
                        append bss_conf "mobility_domain=$mobility_domain" "$N"
                        append bss_conf "r0_key_lifetime=$r0_key_lifetime" "$N"
-                       append bss_conf "r1_key_holder=$r1_key_holder" "$N"
+                       [ -n "$r1_key_holder" ] && append bss_conf "r1_key_holder=$r1_key_holder" "$N"
                        append bss_conf "reassociation_deadline=$reassociation_deadline" "$N"
                        append bss_conf "pmk_r1_push=$pmk_r1_push" "$N"
                        append bss_conf "ft_psk_generate_local=$ft_psk_generate_local" "$N"
@@ -416,6 +423,8 @@ hostapd_set_bss_options() {
                        done
                fi
 
+               append bss_conf "wpa_disable_eapol_key_retries=$wpa_disable_eapol_key_retries" "$N"
+
                hostapd_append_wpa_key_mgmt
                [ -n "$wpa_key_mgmt" ] && append bss_conf "wpa_key_mgmt=$wpa_key_mgmt" "$N"
        fi
@@ -590,8 +599,31 @@ EOF
        return 0
 }
 
+wpa_supplicant_set_fixed_freq() {
+       local freq="$1"
+       local htmode="$2"
+
+       append network_data "fixed_freq=1" "$N$T"
+       append network_data "frequency=$freq" "$N$T"
+       case "$htmode" in
+               NOHT) append network_data "disable_ht=1" "$N$T";;
+               HT20|VHT20) append network_data "disable_ht40=1" "$N$T";;
+               HT40*|VHT40*|VHT80*|VHT160*) append network_data "ht40=1" "$N$T";;
+       esac
+       case "$htmode" in
+               VHT*) append network_data "vht=1" "$N$T";;
+       esac
+       case "$htmode" in
+               VHT80) append network_data "max_oper_chwidth=1" "$N$T";;
+               VHT160) append network_data "max_oper_chwidth=2" "$N$T";;
+               *) append network_data "max_oper_chwidth=0" "$N$T";;
+       esac
+}
+
 wpa_supplicant_add_network() {
        local ifname="$1"
+       local freq="$2"
+       local htmode="$3"
 
        _wpa_supplicant_common "$1"
        wireless_vif_parse_encryption
@@ -613,11 +645,7 @@ wpa_supplicant_add_network() {
 
        [[ "$_w_mode" = "adhoc" ]] && {
                append network_data "mode=1" "$N$T"
-               [ -n "$channel" ] && {
-                       freq="$(get_freq "$phy" "$channel")"
-                       append network_data "fixed_freq=1" "$N$T"
-                       append network_data "frequency=$freq" "$N$T"
-               }
+               [ -n "$channel" ] && wpa_supplicant_set_fixed_freq "$freq" "$htmode"
 
                scan_ssid="scan_ssid=0"
 
@@ -629,10 +657,7 @@ wpa_supplicant_add_network() {
                ssid="${mesh_id}"
 
                append network_data "mode=5" "$N$T"
-               [ -n "$channel" ] && {
-                       freq="$(get_freq "$phy" "$channel")"
-                       append network_data "frequency=$freq" "$N$T"
-               }
+               [ -n "$channel" ] && wpa_supplicant_set_fixed_freq "$freq" "$htmode"
                append wpa_key_mgmt "SAE"
                scan_ssid=""
        }
@@ -726,6 +751,7 @@ wpa_supplicant_add_network() {
                esac
        }
        [ -n "$bssid" ] && append network_data "bssid=$bssid" "$N$T"
+       [ -n "$beacon_int" ] && append network_data "beacon_int=$beacon_int" "$N$T"
 
        local bssid_blacklist bssid_whitelist
        json_get_values bssid_blacklist bssid_blacklist
@@ -748,10 +774,6 @@ wpa_supplicant_add_network() {
                append network_data "mcast_rate=$mc_rate" "$N$T"
        }
 
-       local ht_str
-       [[ "$_w_mode" = adhoc ]] || ibss_htmode=
-       [ -n "$ibss_htmode" ] && append network_data "htmode=$ibss_htmode" "$N$T"
-
        cat >> "$_config" <<EOF
 network={
        $scan_ssid
@@ -768,7 +790,7 @@ wpa_supplicant_run() {
 
        _wpa_supplicant_common "$ifname"
 
-       /usr/sbin/wpa_supplicant -B -s \
+       /usr/sbin/wpa_supplicant -B \
                ${network_bridge:+-b $network_bridge} \
                -P "/var/run/wpa_supplicant-${ifname}.pid" \
                -D ${_w_driver:-wext} \