modules/admin-full: allow bssid for sta wds as well
[project/luci.git] / modules / admin-full / luasrc / model / cbi / admin_network / wifi.lua
1 --[[
2 LuCI - Lua Configuration Interface
3
4 Copyright 2008 Steven Barth <steven@midlink.org>
5
6 Licensed under the Apache License, Version 2.0 (the "License");
7 you may not use this file except in compliance with the License.
8 You may obtain a copy of the License at
9
10         http://www.apache.org/licenses/LICENSE-2.0
11
12 $Id$
13 ]]--
14
15 local wa = require "luci.tools.webadmin"
16 local nw = require "luci.model.network"
17 local fs = require "nixio.fs"
18
19 arg[1] = arg[1] or ""
20
21 m = Map("wireless", "",
22         translate("The <em>Device Configuration</em> section covers physical settings of the radio " ..
23                 "hardware such as channel, transmit power or antenna selection which is shared among all " ..
24                 "defined wireless networks (if the radio hardware is multi-SSID capable). Per network settings " ..
25                 "like encryption or operation mode are grouped in the <em>Interface Configuration</em>."))
26
27 m:chain("network")
28 m:chain("firewall")
29
30 local ifsection
31
32 function m.on_commit(map)
33         local wnet = nw:get_wifinet(arg[1])
34         if ifsection and wnet then
35                 ifsection.section = wnet.sid
36                 m.title = luci.util.pcdata(wnet:get_i18n())
37         end
38 end
39
40 nw.init(m.uci)
41
42 local wnet = nw:get_wifinet(arg[1])
43 local wdev = wnet and wnet:get_device()
44
45 -- redirect to overview page if network does not exist anymore (e.g. after a revert)
46 if not wnet or not wdev then
47         luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless"))
48         return
49 end
50
51 -- wireless toggle was requested, commit and reload page
52 function m.parse(map)
53         if m:formvalue("cbid.wireless.%s.__toggle" % wdev:name()) then
54                 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
55                         wnet:set("disabled", nil)
56                 else
57                         wnet:set("disabled", "1")
58                 end
59                 wdev:set("disabled", nil)
60
61                 nw:commit("wireless")
62                 luci.sys.call("(env -i /sbin/wifi down; env -i /sbin/wifi up) >/dev/null 2>/dev/null")
63
64                 luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless", arg[1]))
65                 return
66         end
67         Map.parse(map)
68 end
69
70 m.title = luci.util.pcdata(wnet:get_i18n())
71
72
73 local iw = luci.sys.wifi.getiwinfo(arg[1])
74 local hw_modes  = iw.hwmodelist or { }
75 local tx_powers = iw.txpwrlist  or { }
76 local tx_power  = tostring(
77         (iw.txpower and iw.txpower > 0 and iw.txpower) or
78         (#tx_powers > 0 and tx_powers[#tx_powers].dbm)
79 )
80
81 s = m:section(NamedSection, wdev:name(), "wifi-device", translate("Device Configuration"))
82 s.addremove = false
83
84 s:tab("general", translate("General Setup"))
85 s:tab("macfilter", translate("MAC-Filter"))
86 s:tab("advanced", translate("Advanced Settings"))
87
88 --[[
89 back = s:option(DummyValue, "_overview", translate("Overview"))
90 back.value = ""
91 back.titleref = luci.dispatcher.build_url("admin", "network", "wireless")
92 ]]
93
94 st = s:taboption("general", DummyValue, "__status", translate("Status"))
95 st.template = "admin_network/wifi_status"
96 st.ifname   = arg[1]
97
98 en = s:taboption("general", Button, "__toggle")
99
100 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
101         en.title      = translate("Wireless network is disabled")
102         en.inputtitle = translate("Enable")
103         en.inputstyle = "apply"
104 else
105         en.title      = translate("Wireless network is enabled")
106         en.inputtitle = translate("Disable")
107         en.inputstyle = "reset"
108 end
109
110
111 local hwtype = wdev:get("type")
112 local htcaps = wdev:get("ht_capab") and true or false
113
114 -- NanoFoo
115 local nsantenna = wdev:get("antenna")
116
117 -- Check whether there is a client interface on the same radio,
118 -- if yes, lock the channel choice as the station will dicatate the freq
119 local has_sta = nil
120 local _, net
121 for _, net in ipairs(wdev:get_wifinets()) do
122         if net:mode() == "sta" and net:id() ~= wnet:id() then
123                 has_sta = net
124                 break
125         end
126 end
127
128 if has_sta then
129         ch = s:taboption("general", DummyValue, "choice", translate("Channel"))
130         ch.value = translatef("Locked to channel %d used by %s",
131                 has_sta:channel(), has_sta:shortname())
132 else
133         ch = s:taboption("general", Value, "channel", translate("Channel"))
134         ch:value("auto", translate("auto"))
135         for _, f in ipairs(iw and iw.freqlist or luci.sys.wifi.channels()) do
136                 if not f.restricted then
137                         ch:value(f.channel, "%i (%.3f GHz)" %{ f.channel, f.mhz / 1000 })
138                 end
139         end
140 end
141
142 ------------------- MAC80211 Device ------------------
143
144 if hwtype == "mac80211" then
145         tp = s:taboption("general",
146                 (tx_powers and #tx_powers > 0) and ListValue or Value,
147                 "txpower", translate("Transmit Power"), "dBm")
148
149         tp.rmempty = true
150         tp.default = tx_power
151         for _, p in ipairs(tx_powers or {}) do
152                 tp:value(p.dbm, "%i dBm (%i mW)" %{ p.dbm, p.mw })
153         end
154
155         mode = s:taboption("advanced", ListValue, "hwmode", translate("Mode"))
156         mode:value("", translate("auto"))
157         if hw_modes.b then mode:value("11b", "802.11b") end
158         if hw_modes.g then mode:value("11g", "802.11g") end
159         if hw_modes.a then mode:value("11a", "802.11a") end
160
161         if htcaps then
162                 if hw_modes.g and hw_modes.n then mode:value("11ng", "802.11g+n") end
163                 if hw_modes.a and hw_modes.n then mode:value("11na", "802.11a+n") end
164
165                 htmode = s:taboption("advanced", ListValue, "htmode", translate("HT mode"))
166                 htmode:depends("hwmode", "11na")
167                 htmode:depends("hwmode", "11ng")
168                 htmode:value("HT20", "20MHz")
169                 htmode:value("HT40-", translate("40MHz 2nd channel below"))
170                 htmode:value("HT40+", translate("40MHz 2nd channel above"))
171
172                 --htcapab = s:taboption("advanced", DynamicList, "ht_capab", translate("HT capabilities"))
173                 --htcapab:depends("hwmode", "11na")
174                 --htcapab:depends("hwmode", "11ng")
175         end
176
177         local cl = iw and iw.countrylist
178         if cl and #cl > 0 then
179                 cc = s:taboption("advanced", ListValue, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
180                 cc.default = tostring(iw and iw.country or "00")
181                 for _, c in ipairs(cl) do
182                         cc:value(c.alpha2, "%s - %s" %{ c.alpha2, c.name })
183                 end
184         else
185                 s:taboption("advanced", Value, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
186         end
187
188         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
189                 translate("Distance to farthest network member in meters."))
190
191         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
192         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
193 end
194
195
196 ------------------- Madwifi Device ------------------
197
198 if hwtype == "atheros" then
199         tp = s:taboption("general",
200                 (#tx_powers > 0) and ListValue or Value,
201                 "txpower", translate("Transmit Power"), "dBm")
202
203         tp.rmempty = true
204         tp.default = tx_power
205         for _, p in ipairs(tx_powers or {}) do
206                 tp:value(p.dbm, "%i dBm (%i mW)" %{ p.dbm, p.mw })
207         end
208
209         mode = s:taboption("advanced", ListValue, "hwmode", translate("Mode"))
210         mode:value("", translate("auto"))
211         if hw_modes.b then mode:value("11b", "802.11b") end
212         if hw_modes.g then mode:value("11g", "802.11g") end
213         if hw_modes.a then mode:value("11a", "802.11a") end
214         if hw_modes.g then mode:value("11bg", "802.11b+g") end
215         if hw_modes.g then mode:value("11gst", "802.11g + Turbo") end
216         if hw_modes.a then mode:value("11ast", "802.11a + Turbo") end
217         mode:value("fh", translate("Frequency Hopping"))
218
219         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
220
221         if not nsantenna then
222                 ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
223                 ant1.widget = "radio"
224                 ant1.orientation = "horizontal"
225                 ant1:depends("diversity", "")
226                 ant1:value("0", translate("auto"))
227                 ant1:value("1", translate("Antenna 1"))
228                 ant1:value("2", translate("Antenna 2"))
229
230                 ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
231                 ant2.widget = "radio"
232                 ant2.orientation = "horizontal"
233                 ant2:depends("diversity", "")
234                 ant2:value("0", translate("auto"))
235                 ant2:value("1", translate("Antenna 1"))
236                 ant2:value("2", translate("Antenna 2"))
237
238         else -- NanoFoo
239                 local ant = s:taboption("advanced", ListValue, "antenna", translate("Transmitter Antenna"))
240                 ant:value("auto")
241                 ant:value("vertical")
242                 ant:value("horizontal")
243                 ant:value("external")
244         end
245
246         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
247                 translate("Distance to farthest network member in meters."))
248         s:taboption("advanced", Value, "regdomain", translate("Regulatory Domain"))
249         s:taboption("advanced", Value, "country", translate("Country Code"))
250         s:taboption("advanced", Flag, "outdoor", translate("Outdoor Channels"))
251
252         --s:option(Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
253 end
254
255
256
257 ------------------- Broadcom Device ------------------
258
259 if hwtype == "broadcom" then
260         tp = s:taboption("general",
261                 (#tx_powers > 0) and ListValue or Value,
262                 "txpower", translate("Transmit Power"), "dBm")
263
264         tp.rmempty = true
265         tp.default = tx_power
266         for _, p in ipairs(tx_powers or {}) do
267                 tp:value(p.dbm, "%i dBm (%i mW)" %{ p.dbm, p.mw })
268         end
269
270         mode = s:taboption("advanced", ListValue, "hwmode", translate("Mode"))
271         mode:value("11bg", "802.11b+g")
272         mode:value("11b", "802.11b")
273         mode:value("11g", "802.11g")
274         mode:value("11gst", "802.11g + Turbo")
275
276         ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
277         ant1.widget = "radio"
278         ant1:depends("diversity", "")
279         ant1:value("3", translate("auto"))
280         ant1:value("0", translate("Antenna 1"))
281         ant1:value("1", translate("Antenna 2"))
282
283         ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
284         ant2.widget = "radio"
285         ant2:depends("diversity", "")
286         ant2:value("3", translate("auto"))
287         ant2:value("0", translate("Antenna 1"))
288         ant2:value("1", translate("Antenna 2"))
289
290         s:taboption("advanced", Flag, "frameburst", translate("Frame Bursting"))
291
292         s:taboption("advanced", Value, "distance", translate("Distance Optimization"))
293         --s:option(Value, "slottime", translate("Slot time"))
294
295         s:taboption("advanced", Value, "country", translate("Country Code"))
296         s:taboption("advanced", Value, "maxassoc", translate("Connection Limit"))
297 end
298
299
300 --------------------- HostAP Device ---------------------
301
302 if hwtype == "prism2" then
303         s:taboption("advanced", Value, "txpower", translate("Transmit Power"), "att units").rmempty = true
304
305         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
306
307         s:taboption("advanced", Value, "txantenna", translate("Transmitter Antenna"))
308         s:taboption("advanced", Value, "rxantenna", translate("Receiver Antenna"))
309 end
310
311
312 ----------------------- Interface -----------------------
313
314 s = m:section(NamedSection, wnet.sid, "wifi-iface", translate("Interface Configuration"))
315 ifsection = s
316 s.addremove = false
317 s.anonymous = true
318 s.defaults.device = wdev:name()
319
320 s:tab("general", translate("General Setup"))
321 s:tab("encryption", translate("Wireless Security"))
322 s:tab("macfilter", translate("MAC-Filter"))
323 s:tab("advanced", translate("Advanced Settings"))
324
325 s:taboption("general", Value, "ssid", translate("<abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
326
327 mode = s:taboption("general", ListValue, "mode", translate("Mode"))
328 mode.override_values = true
329 mode:value("ap", translate("Access Point"))
330 mode:value("sta", translate("Client"))
331 mode:value("adhoc", translate("Ad-Hoc"))
332
333 bssid = s:taboption("general", Value, "bssid", translate("<abbr title=\"Basic Service Set Identifier\">BSSID</abbr>"))
334
335 network = s:taboption("general", Value, "network", translate("Network"),
336         translate("Choose the network you want to attach to this wireless interface. " ..
337                 "Select <em>unspecified</em> to not attach any network or fill out the " ..
338                 "<em>create</em> field to define a new network."))
339
340 network.rmempty = true
341 network.template = "cbi/network_netlist"
342 network.widget = "radio"
343
344 function network.write(self, section, value)
345         local i = nw:get_interface(section)
346         if i then
347                 if value == '-' then
348                         value = m:formvalue(self:cbid(section) .. ".newnet")
349                         if value and #value > 0 then
350                                 local n = nw:add_network(value, {proto="none"})
351                                 if n then n:add_interface(i) end
352                         else
353                                 local n = i:get_network()
354                                 if n then n:del_interface(i) end
355                         end
356                 else
357                         local n = nw:get_network(value)
358                         if n then
359                                 n:set("type", "bridge")
360                                 n:add_interface(i)
361                         end
362                 end
363         end
364 end
365
366 -------------------- MAC80211 Interface ----------------------
367
368 if hwtype == "mac80211" then
369         if fs.access("/usr/sbin/iw") then
370                 mode:value("mesh", "802.11s")
371         end
372
373         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
374         mode:value("monitor", translate("Monitor"))
375         bssid:depends({mode="adhoc"})
376         bssid:depends({mode="sta"})
377         bssid:depends({mode="sta-wds"})
378
379         mp = s:taboption("macfilter", ListValue, "macfilter", translate("MAC-Address Filter"))
380         mp:depends({mode="ap"})
381         mp:depends({mode="ap-wds"})
382         mp:value("", translate("disable"))
383         mp:value("allow", translate("Allow listed only"))
384         mp:value("deny", translate("Allow all except listed"))
385
386         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
387         ml.datatype = "macaddr"
388         ml:depends({macfilter="allow"})
389         ml:depends({macfilter="deny"})
390
391         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
392         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
393
394         function mode.write(self, section, value)
395                 if value == "ap-wds" then
396                         ListValue.write(self, section, "ap")
397                         m.uci:set("wireless", section, "wds", 1)
398                 elseif value == "sta-wds" then
399                         ListValue.write(self, section, "sta")
400                         m.uci:set("wireless", section, "wds", 1)
401                 else
402                         ListValue.write(self, section, value)
403                         m.uci:delete("wireless", section, "wds")
404                 end
405         end
406
407         function mode.cfgvalue(self, section)
408                 local mode = ListValue.cfgvalue(self, section)
409                 local wds  = m.uci:get("wireless", section, "wds") == "1"
410
411                 if mode == "ap" and wds then
412                         return "ap-wds"
413                 elseif mode == "sta" and wds then
414                         return "sta-wds"
415                 else
416                         return mode
417                 end
418         end
419
420         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
421         hidden:depends({mode="ap"})
422         hidden:depends({mode="ap-wds"})
423 end
424
425
426
427 -------------------- Madwifi Interface ----------------------
428
429 if hwtype == "atheros" then
430         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
431         mode:value("monitor", translate("Monitor"))
432         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
433         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
434         mode:value("wds", translate("Static WDS"))
435
436         function mode.write(self, section, value)
437                 if value == "ap-wds" then
438                         ListValue.write(self, section, "ap")
439                         m.uci:set("wireless", section, "wds", 1)
440                 elseif value == "sta-wds" then
441                         ListValue.write(self, section, "sta")
442                         m.uci:set("wireless", section, "wds", 1)
443                 else
444                         ListValue.write(self, section, value)
445                         m.uci:delete("wireless", section, "wds")
446                 end
447         end
448
449         function mode.cfgvalue(self, section)
450                 local mode = ListValue.cfgvalue(self, section)
451                 local wds  = m.uci:get("wireless", section, "wds") == "1"
452
453                 if mode == "ap" and wds then
454                         return "ap-wds"
455                 elseif mode == "sta" and wds then
456                         return "sta-wds"
457                 else
458                         return mode
459                 end
460         end
461
462         bssid:depends({mode="adhoc"})
463         bssid:depends({mode="ahdemo"})
464         bssid:depends({mode="wds"})
465
466         wdssep = s:taboption("advanced", Flag, "wdssep", translate("Separate WDS"))
467         wdssep:depends({mode="ap-wds"})
468
469         s:taboption("advanced", Flag, "doth", "802.11h")
470         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
471         hidden:depends({mode="ap"})
472         hidden:depends({mode="adhoc"})
473         hidden:depends({mode="ap-wds"})
474         hidden:depends({mode="sta-wds"})
475         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
476          translate("Prevents client-to-client communication"))
477         isolate:depends({mode="ap"})
478         s:taboption("advanced", Flag, "bgscan", translate("Background Scan"))
479
480         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
481         mp:value("", translate("disable"))
482         mp:value("allow", translate("Allow listed only"))
483         mp:value("deny", translate("Allow all except listed"))
484
485         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
486         ml.datatype = "macaddr"
487         ml:depends({macpolicy="allow"})
488         ml:depends({macpolicy="deny"})
489
490         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
491         s:taboption("advanced", Value, "mcast_rate", translate("Multicast Rate"))
492         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
493         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
494         s:taboption("advanced", Value, "minrate", translate("Minimum Rate"))
495         s:taboption("advanced", Value, "maxrate", translate("Maximum Rate"))
496         s:taboption("advanced", Flag, "compression", translate("Compression"))
497
498         s:taboption("advanced", Flag, "bursting", translate("Frame Bursting"))
499         s:taboption("advanced", Flag, "turbo", translate("Turbo Mode"))
500         s:taboption("advanced", Flag, "ff", translate("Fast Frames"))
501
502         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
503         s:taboption("advanced", Flag, "xr", translate("XR Support"))
504         s:taboption("advanced", Flag, "ar", translate("AR Support"))
505
506         local swm = s:taboption("advanced", Flag, "sw_merge", translate("Disable HW-Beacon timer"))
507         swm:depends({mode="adhoc"})
508
509         local nos = s:taboption("advanced", Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
510         nos:depends({mode="sta"})
511         nos:depends({mode="sta-wds"})
512
513         local probereq = s:taboption("advanced", Flag, "probereq", translate("Do not send probe responses"))
514         probereq.enabled  = "0"
515         probereq.disabled = "1"
516 end
517
518
519 -------------------- Broadcom Interface ----------------------
520
521 if hwtype == "broadcom" then
522         mode:value("wds", translate("WDS"))
523         mode:value("monitor", translate("Monitor"))
524
525         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
526         hidden:depends({mode="ap"})
527         hidden:depends({mode="adhoc"})
528         hidden:depends({mode="wds"})
529
530         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
531          translate("Prevents client-to-client communication"))
532         isolate:depends({mode="ap"})
533
534         s:taboption("advanced", Flag, "doth", "802.11h")
535         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
536
537         bssid:depends({mode="wds"})
538         bssid:depends({mode="adhoc"})
539 end
540
541
542 ----------------------- HostAP Interface ---------------------
543
544 if hwtype == "prism2" then
545         mode:value("wds", translate("WDS"))
546         mode:value("monitor", translate("Monitor"))
547
548         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
549         hidden:depends({mode="ap"})
550         hidden:depends({mode="adhoc"})
551         hidden:depends({mode="wds"})
552
553         bssid:depends({mode="sta"})
554
555         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
556         mp:value("", translate("disable"))
557         mp:value("allow", translate("Allow listed only"))
558         mp:value("deny", translate("Allow all except listed"))
559         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
560         ml:depends({macpolicy="allow"})
561         ml:depends({macpolicy="deny"})
562
563         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
564         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
565         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
566 end
567
568
569 ------------------- WiFI-Encryption -------------------
570
571 encr = s:taboption("encryption", ListValue, "encryption", translate("Encryption"))
572 encr.override_values = true
573 encr.override_depends = true
574 encr:depends({mode="ap"})
575 encr:depends({mode="sta"})
576 encr:depends({mode="adhoc"})
577 encr:depends({mode="ahdemo"})
578 encr:depends({mode="ap-wds"})
579 encr:depends({mode="sta-wds"})
580 encr:depends({mode="mesh"})
581
582 cipher = s:taboption("encryption", ListValue, "cipher", translate("Cipher"))
583 cipher:depends({encryption="wpa"})
584 cipher:depends({encryption="wpa2"})
585 cipher:depends({encryption="psk"})
586 cipher:depends({encryption="psk2"})
587 cipher:depends({encryption="wpa-mixed"})
588 cipher:depends({encryption="psk-mixed"})
589 cipher:value("auto", translate("auto"))
590 cipher:value("ccmp", translate("Force CCMP (AES)"))
591 cipher:value("tkip", translate("Force TKIP"))
592 cipher:value("tkip+ccmp", translate("Force TKIP and CCMP (AES)"))
593
594 function encr.cfgvalue(self, section)
595         local v = tostring(ListValue.cfgvalue(self, section))
596         if v == "wep" then
597                 return "wep-open"
598         elseif v and v:match("%+") then
599                 return (v:gsub("%+.+$", ""))
600         end
601         return v
602 end
603
604 function encr.write(self, section, value)
605         local e = tostring(encr:formvalue(section))
606         local c = tostring(cipher:formvalue(section))
607         if value == "wpa" or value == "wpa2"  then
608                 self.map.uci:delete("wireless", section, "key")
609         end
610         if e and (c == "tkip" or c == "ccmp" or c == "tkip+ccmp") then
611                 e = e .. "+" .. c
612         end
613         self.map:set(section, "encryption", e)
614 end
615
616 function cipher.cfgvalue(self, section)
617         local v = tostring(ListValue.cfgvalue(encr, section))
618         if v and v:match("%+") then
619                 v = v:gsub("^[^%+]+%+", "")
620                 if v == "aes" then v = "ccmp"
621                 elseif v == "tkip+aes" then v = "tkip+ccmp"
622                 elseif v == "aes+tkip" then v = "tkip+ccmp"
623                 elseif v == "ccmp+tkip" then v = "tkip+ccmp"
624                 end
625         end
626         return v
627 end
628
629 function cipher.write(self, section)
630         return encr:write(section)
631 end
632
633
634 encr:value("none", "No Encryption")
635 encr:value("wep-open",   translate("WEP Open System"), {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
636 encr:value("wep-shared", translate("WEP Shared Key"),  {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
637
638 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
639         local supplicant = fs.access("/usr/sbin/wpa_supplicant")
640         local hostapd = fs.access("/usr/sbin/hostapd")
641
642         if hostapd and supplicant then
643                 encr:value("psk", "WPA-PSK")
644                 encr:value("psk2", "WPA2-PSK")
645                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode")
646                 encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
647                 encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
648         elseif hostapd and not supplicant then
649                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="ap-wds"}, {mode="adhoc"}, {mode="ahdemo"})
650                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="ap-wds"}, {mode="adhoc"}, {mode="ahdemo"})
651                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="ap-wds"}, {mode="adhoc"}, {mode="ahdemo"})
652                 encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="ap-wds"})
653                 encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="ap-wds"})
654                 encr.description = translate(
655                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
656                         "and ad-hoc mode) to be installed."
657                 )
658         elseif not hostapd and supplicant then
659                 encr:value("psk", "WPA-PSK", {mode="sta"}, {mode="sta-wds"})
660                 encr:value("psk2", "WPA2-PSK", {mode="sta"}, {mode="sta-wds"})
661                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="sta"}, {mode="sta-wds"})
662                 encr:value("wpa", "WPA-EAP", {mode="sta"}, {mode="sta-wds"})
663                 encr:value("wpa2", "WPA2-EAP", {mode="sta"}, {mode="sta-wds"})
664                 encr.description = translate(
665                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
666                         "and ad-hoc mode) to be installed."
667                 )
668         else
669                 encr.description = translate(
670                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
671                         "and ad-hoc mode) to be installed."
672                 )
673         end
674 elseif hwtype == "broadcom" then
675         encr:value("psk", "WPA-PSK")
676         encr:value("psk2", "WPA2-PSK")
677         encr:value("psk+psk2", "WPA-PSK/WPA2-PSK Mixed Mode")
678 end
679
680 auth_server = s:taboption("encryption", Value, "auth_server", translate("Radius-Authentication-Server"))
681 auth_server:depends({mode="ap", encryption="wpa"})
682 auth_server:depends({mode="ap", encryption="wpa2"})
683 auth_server:depends({mode="ap-wds", encryption="wpa"})
684 auth_server:depends({mode="ap-wds", encryption="wpa2"})
685 auth_server.rmempty = true
686 auth_server.datatype = "host"
687
688 auth_port = s:taboption("encryption", Value, "auth_port", translate("Radius-Authentication-Port"), translatef("Default %d", 1812))
689 auth_port:depends({mode="ap", encryption="wpa"})
690 auth_port:depends({mode="ap", encryption="wpa2"})
691 auth_port:depends({mode="ap-wds", encryption="wpa"})
692 auth_port:depends({mode="ap-wds", encryption="wpa2"})
693 auth_port.rmempty = true
694 auth_port.datatype = "port"
695
696 auth_secret = s:taboption("encryption", Value, "auth_secret", translate("Radius-Authentication-Secret"))
697 auth_secret:depends({mode="ap", encryption="wpa"})
698 auth_secret:depends({mode="ap", encryption="wpa2"})
699 auth_secret:depends({mode="ap-wds", encryption="wpa"})
700 auth_secret:depends({mode="ap-wds", encryption="wpa2"})
701 auth_secret.rmempty = true
702 auth_secret.password = true
703
704 acct_server = s:taboption("encryption", Value, "acct_server", translate("Radius-Accounting-Server"))
705 acct_server:depends({mode="ap", encryption="wpa"})
706 acct_server:depends({mode="ap", encryption="wpa2"})
707 acct_server:depends({mode="ap-wds", encryption="wpa"})
708 acct_server:depends({mode="ap-wds", encryption="wpa2"})
709 acct_server.rmempty = true
710 acct_server.datatype = "host"
711
712 acct_port = s:taboption("encryption", Value, "acct_port", translate("Radius-Accounting-Port"), translatef("Default %d", 1813))
713 acct_port:depends({mode="ap", encryption="wpa"})
714 acct_port:depends({mode="ap", encryption="wpa2"})
715 acct_port:depends({mode="ap-wds", encryption="wpa"})
716 acct_port:depends({mode="ap-wds", encryption="wpa2"})
717 acct_port.rmempty = true
718 acct_port.datatype = "port"
719
720 acct_secret = s:taboption("encryption", Value, "acct_secret", translate("Radius-Accounting-Secret"))
721 acct_secret:depends({mode="ap", encryption="wpa"})
722 acct_secret:depends({mode="ap", encryption="wpa2"})
723 acct_secret:depends({mode="ap-wds", encryption="wpa"})
724 acct_secret:depends({mode="ap-wds", encryption="wpa2"})
725 acct_secret.rmempty = true
726 acct_secret.password = true
727
728 wpakey = s:taboption("encryption", Value, "_wpa_key", translate("Key"))
729 wpakey:depends("encryption", "psk")
730 wpakey:depends("encryption", "psk2")
731 wpakey:depends("encryption", "psk+psk2")
732 wpakey:depends("encryption", "psk-mixed")
733 wpakey.datatype = "wpakey"
734 wpakey.rmempty = true
735 wpakey.password = true
736
737 wpakey.cfgvalue = function(self, section, value)
738         local key = m.uci:get("wireless", section, "key")
739         if key == "1" or key == "2" or key == "3" or key == "4" then
740                 return nil
741         end
742         return key
743 end
744
745 wpakey.write = function(self, section, value)
746         self.map.uci:set("wireless", section, "key", value)
747         self.map.uci:delete("wireless", section, "key1")
748 end
749
750
751 wepslot = s:taboption("encryption", ListValue, "_wep_key", translate("Used Key Slot"))
752 wepslot:depends("encryption", "wep-open")
753 wepslot:depends("encryption", "wep-shared")
754 wepslot:value("1", translatef("Key #%d", 1))
755 wepslot:value("2", translatef("Key #%d", 2))
756 wepslot:value("3", translatef("Key #%d", 3))
757 wepslot:value("4", translatef("Key #%d", 4))
758
759 wepslot.cfgvalue = function(self, section)
760         local slot = tonumber(m.uci:get("wireless", section, "key"))
761         if not slot or slot < 1 or slot > 4 then
762                 return 1
763         end
764         return slot
765 end
766
767 wepslot.write = function(self, section, value)
768         self.map.uci:set("wireless", section, "key", value)
769 end
770
771 local slot
772 for slot=1,4 do
773         wepkey = s:taboption("encryption", Value, "key" .. slot, translatef("Key #%d", slot))
774         wepkey:depends("encryption", "wep-open")
775         wepkey:depends("encryption", "wep-shared")
776         wepkey.datatype = "wepkey"
777         wepkey.rmempty = true
778         wepkey.password = true
779
780         function wepkey.write(self, section, value)
781                 if value and (#value == 5 or #value == 13) then
782                         value = "s:" .. value
783                 end
784                 return Value.write(self, section, value)
785         end
786 end
787
788
789 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
790         nasid = s:taboption("encryption", Value, "nasid", translate("NAS ID"))
791         nasid:depends({mode="ap", encryption="wpa"})
792         nasid:depends({mode="ap", encryption="wpa2"})
793         nasid:depends({mode="ap-wds", encryption="wpa"})
794         nasid:depends({mode="ap-wds", encryption="wpa2"})
795         nasid.rmempty = true
796
797         eaptype = s:taboption("encryption", ListValue, "eap_type", translate("EAP-Method"))
798         eaptype:value("tls",  "TLS")
799         eaptype:value("ttls", "TTLS")
800         eaptype:value("peap", "PEAP")
801         eaptype:depends({mode="sta", encryption="wpa"})
802         eaptype:depends({mode="sta", encryption="wpa2"})
803         eaptype:depends({mode="sta-wds", encryption="wpa"})
804         eaptype:depends({mode="sta-wds", encryption="wpa2"})
805
806         cacert = s:taboption("encryption", FileUpload, "ca_cert", translate("Path to CA-Certificate"))
807         cacert:depends({mode="sta", encryption="wpa"})
808         cacert:depends({mode="sta", encryption="wpa2"})
809         cacert:depends({mode="sta-wds", encryption="wpa"})
810         cacert:depends({mode="sta-wds", encryption="wpa2"})
811
812         privkey = s:taboption("encryption", FileUpload, "priv_key", translate("Path to Private Key"))
813         privkey:depends({mode="sta", eap_type="tls", encryption="wpa2"})
814         privkey:depends({mode="sta", eap_type="tls", encryption="wpa"})
815         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
816         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
817
818         privkeypwd = s:taboption("encryption", Value, "priv_key_pwd", translate("Password of Private Key"))
819         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa2"})
820         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa"})
821         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
822         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
823
824
825         auth = s:taboption("encryption", Value, "auth", translate("Authentication"))
826         auth:value("PAP")
827         auth:value("CHAP")
828         auth:value("MSCHAP")
829         auth:value("MSCHAPV2")
830         auth:depends({mode="sta", eap_type="peap", encryption="wpa2"})
831         auth:depends({mode="sta", eap_type="peap", encryption="wpa"})
832         auth:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
833         auth:depends({mode="sta", eap_type="ttls", encryption="wpa"})
834         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
835         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
836         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
837         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
838
839
840         identity = s:taboption("encryption", Value, "identity", translate("Identity"))
841         identity:depends({mode="sta", eap_type="peap", encryption="wpa2"})
842         identity:depends({mode="sta", eap_type="peap", encryption="wpa"})
843         identity:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
844         identity:depends({mode="sta", eap_type="ttls", encryption="wpa"})
845         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
846         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
847         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
848         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
849
850         password = s:taboption("encryption", Value, "password", translate("Password"))
851         password:depends({mode="sta", eap_type="peap", encryption="wpa2"})
852         password:depends({mode="sta", eap_type="peap", encryption="wpa"})
853         password:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
854         password:depends({mode="sta", eap_type="ttls", encryption="wpa"})
855         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
856         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
857         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
858         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
859 end
860
861 return m