e227b0874695037b4d094bec2a15d6047cd77bfd
[project/luci.git] / modules / luci-mod-admin-full / luasrc / model / cbi / admin_network / wifi.lua
1 -- Copyright 2008 Steven Barth <steven@midlink.org>
2 -- Licensed to the public under the Apache License 2.0.
3
4 local wa = require "luci.tools.webadmin"
5 local nw = require "luci.model.network"
6 local ut = require "luci.util"
7 local nt = require "luci.sys".net
8 local fs = require "nixio.fs"
9
10 arg[1] = arg[1] or ""
11
12 m = Map("wireless", "",
13         translate("The <em>Device Configuration</em> section covers physical settings of the radio " ..
14                 "hardware such as channel, transmit power or antenna selection which are shared among all " ..
15                 "defined wireless networks (if the radio hardware is multi-SSID capable). Per network settings " ..
16                 "like encryption or operation mode are grouped in the <em>Interface Configuration</em>."))
17
18 m:chain("network")
19 m:chain("firewall")
20 m.redirect = luci.dispatcher.build_url("admin/network/wireless")
21
22 local ifsection
23
24 function m.on_commit(map)
25         local wnet = nw:get_wifinet(arg[1])
26         if ifsection and wnet then
27                 ifsection.section = wnet.sid
28                 m.title = luci.util.pcdata(wnet:get_i18n())
29         end
30 end
31
32 nw.init(m.uci)
33
34 local wnet = nw:get_wifinet(arg[1])
35 local wdev = wnet and wnet:get_device()
36
37 -- redirect to overview page if network does not exist anymore (e.g. after a revert)
38 if not wnet or not wdev then
39         luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless"))
40         return
41 end
42
43 -- wireless toggle was requested, commit and reload page
44 function m.parse(map)
45         if m:formvalue("cbid.wireless.%s.__toggle" % wdev:name()) then
46                 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
47                         wnet:set("disabled", nil)
48                 else
49                         wnet:set("disabled", "1")
50                 end
51                 wdev:set("disabled", nil)
52
53                 nw:commit("wireless")
54                 luci.sys.call("(env -i /bin/ubus call network reload) >/dev/null 2>/dev/null")
55
56                 luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless", arg[1]))
57                 return
58         end
59         Map.parse(map)
60 end
61
62 m.title = luci.util.pcdata(wnet:get_i18n())
63
64
65 local function txpower_list(iw)
66         local list = iw.txpwrlist or { }
67         local off  = tonumber(iw.txpower_offset) or 0
68         local new  = { }
69         local prev = -1
70         local _, val
71         for _, val in ipairs(list) do
72                 local dbm = val.dbm + off
73                 local mw  = math.floor(10 ^ (dbm / 10))
74                 if mw ~= prev then
75                         prev = mw
76                         new[#new+1] = {
77                                 display_dbm = dbm,
78                                 display_mw  = mw,
79                                 driver_dbm  = val.dbm,
80                                 driver_mw   = val.mw
81                         }
82                 end
83         end
84         return new
85 end
86
87 local function txpower_current(pwr, list)
88         pwr = tonumber(pwr)
89         if pwr ~= nil then
90                 local _, item
91                 for _, item in ipairs(list) do
92                         if item.driver_dbm >= pwr then
93                                 return item.driver_dbm
94                         end
95                 end
96         end
97         return (list[#list] and list[#list].driver_dbm) or pwr or 0
98 end
99
100 local iw = luci.sys.wifi.getiwinfo(arg[1])
101 local hw_modes      = iw.hwmodelist or { }
102 local tx_power_list = txpower_list(iw)
103 local tx_power_cur  = txpower_current(wdev:get("txpower"), tx_power_list)
104
105 s = m:section(NamedSection, wdev:name(), "wifi-device", translate("Device Configuration"))
106 s.addremove = false
107
108 s:tab("general", translate("General Setup"))
109 s:tab("macfilter", translate("MAC-Filter"))
110 s:tab("advanced", translate("Advanced Settings"))
111
112 --[[
113 back = s:option(DummyValue, "_overview", translate("Overview"))
114 back.value = ""
115 back.titleref = luci.dispatcher.build_url("admin", "network", "wireless")
116 ]]
117
118 st = s:taboption("general", DummyValue, "__status", translate("Status"))
119 st.template = "admin_network/wifi_status"
120 st.ifname   = arg[1]
121
122 en = s:taboption("general", Button, "__toggle")
123
124 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
125         en.title      = translate("Wireless network is disabled")
126         en.inputtitle = translate("Enable")
127         en.inputstyle = "apply"
128 else
129         en.title      = translate("Wireless network is enabled")
130         en.inputtitle = translate("Disable")
131         en.inputstyle = "reset"
132 end
133
134
135 local hwtype = wdev:get("type")
136
137 -- NanoFoo
138 local nsantenna = wdev:get("antenna")
139
140 -- Check whether there are client interfaces on the same radio,
141 -- if yes, lock the channel choice as these stations will dicatate the freq
142 local found_sta = nil
143 local _, net
144 if wnet:mode() ~= "sta" then
145         for _, net in ipairs(wdev:get_wifinets()) do
146                 if net:mode() == "sta" and net:get("disabled") ~= "1" then
147                         if not found_sta then
148                                 found_sta = {}
149                                 found_sta.channel = net:channel()
150                                 found_sta.names = {}
151                         end
152                         found_sta.names[#found_sta.names+1] = net:shortname()
153                 end
154         end
155 end
156
157 if found_sta then
158         ch = s:taboption("general", DummyValue, "choice", translate("Channel"))
159         ch.value = translatef("Locked to channel %s used by: %s",
160                 found_sta.channel or "(auto)", table.concat(found_sta.names, ", "))
161 else
162         ch = s:taboption("general", Value, "_mode_freq", '<br />'..translate("Operating frequency"))
163         ch.hwmodes = hw_modes
164         ch.htmodes = iw.htmodelist
165         ch.freqlist = iw.freqlist
166         ch.template = "cbi/wireless_modefreq"
167
168         function ch.cfgvalue(self, section)
169                 return {
170                         m:get(section, "hwmode") or "",
171                         m:get(section, "channel") or "auto",
172                         m:get(section, "htmode") or ""
173                 }
174         end
175
176         function ch.formvalue(self, section)
177                 return {
178                         m:formvalue(self:cbid(section) .. ".band") or (hw_modes.g and "11g" or "11a"),
179                         m:formvalue(self:cbid(section) .. ".channel") or "auto",
180                         m:formvalue(self:cbid(section) .. ".htmode") or ""
181                 }
182         end
183
184         function ch.write(self, section, value)
185                 m:set(section, "hwmode", value[1])
186                 m:set(section, "channel", value[2])
187                 m:set(section, "htmode", value[3])
188         end
189 end
190
191 ------------------- MAC80211 Device ------------------
192
193 if hwtype == "mac80211" then
194         if #tx_power_list > 1 then
195                 tp = s:taboption("general", ListValue,
196                         "txpower", translate("Transmit Power"), "dBm")
197                 tp.rmempty = true
198                 tp.default = tx_power_cur
199                 function tp.cfgvalue(...)
200                         return txpower_current(Value.cfgvalue(...), tx_power_list)
201                 end
202
203                 for _, p in ipairs(tx_power_list) do
204                         tp:value(p.driver_dbm, "%i dBm (%i mW)"
205                                 %{ p.display_dbm, p.display_mw })
206                 end
207         end
208
209         local cl = iw and iw.countrylist
210         if cl and #cl > 0 then
211                 cc = s:taboption("advanced", ListValue, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
212                 cc.default = tostring(iw and iw.country or "00")
213                 for _, c in ipairs(cl) do
214                         cc:value(c.alpha2, "%s - %s" %{ c.alpha2, c.name })
215                 end
216         else
217                 s:taboption("advanced", Value, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
218         end
219
220         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
221                 translate("Distance to farthest network member in meters."))
222
223         -- external antenna profiles
224         local eal = iw and iw.extant
225         if eal and #eal > 0 then
226                 ea = s:taboption("advanced", ListValue, "extant", translate("Antenna Configuration"))
227                 for _, eap in ipairs(eal) do
228                         ea:value(eap.id, "%s (%s)" %{ eap.name, eap.description })
229                         if eap.selected then
230                                 ea.default = eap.id
231                         end
232                 end
233         end
234
235         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
236         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
237 end
238
239
240 ------------------- Madwifi Device ------------------
241
242 if hwtype == "atheros" then
243         tp = s:taboption("general",
244                 (#tx_power_list > 0) and ListValue or Value,
245                 "txpower", translate("Transmit Power"), "dBm")
246
247         tp.rmempty = true
248         tp.default = tx_power_cur
249
250         function tp.cfgvalue(...)
251                 return txpower_current(Value.cfgvalue(...), tx_power_list)
252         end
253
254         for _, p in ipairs(tx_power_list) do
255                 tp:value(p.driver_dbm, "%i dBm (%i mW)"
256                         %{ p.display_dbm, p.display_mw })
257         end
258
259         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
260
261         if not nsantenna then
262                 ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
263                 ant1.widget = "radio"
264                 ant1.orientation = "horizontal"
265                 ant1:depends("diversity", "")
266                 ant1:value("0", translate("auto"))
267                 ant1:value("1", translate("Antenna 1"))
268                 ant1:value("2", translate("Antenna 2"))
269
270                 ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
271                 ant2.widget = "radio"
272                 ant2.orientation = "horizontal"
273                 ant2:depends("diversity", "")
274                 ant2:value("0", translate("auto"))
275                 ant2:value("1", translate("Antenna 1"))
276                 ant2:value("2", translate("Antenna 2"))
277
278         else -- NanoFoo
279                 local ant = s:taboption("advanced", ListValue, "antenna", translate("Transmitter Antenna"))
280                 ant:value("auto")
281                 ant:value("vertical")
282                 ant:value("horizontal")
283                 ant:value("external")
284         end
285
286         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
287                 translate("Distance to farthest network member in meters."))
288         s:taboption("advanced", Value, "regdomain", translate("Regulatory Domain"))
289         s:taboption("advanced", Value, "country", translate("Country Code"))
290         s:taboption("advanced", Flag, "outdoor", translate("Outdoor Channels"))
291
292         --s:option(Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
293 end
294
295
296
297 ------------------- Broadcom Device ------------------
298
299 if hwtype == "broadcom" then
300         tp = s:taboption("general",
301                 (#tx_power_list > 0) and ListValue or Value,
302                 "txpower", translate("Transmit Power"), "dBm")
303
304         tp.rmempty = true
305         tp.default = tx_power_cur
306
307         function tp.cfgvalue(...)
308                 return txpower_current(Value.cfgvalue(...), tx_power_list)
309         end
310
311         for _, p in ipairs(tx_power_list) do
312                 tp:value(p.driver_dbm, "%i dBm (%i mW)"
313                         %{ p.display_dbm, p.display_mw })
314         end
315
316         ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
317         ant1.widget = "radio"
318         ant1:depends("diversity", "")
319         ant1:value("3", translate("auto"))
320         ant1:value("0", translate("Antenna 1"))
321         ant1:value("1", translate("Antenna 2"))
322
323         ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
324         ant2.widget = "radio"
325         ant2:depends("diversity", "")
326         ant2:value("3", translate("auto"))
327         ant2:value("0", translate("Antenna 1"))
328         ant2:value("1", translate("Antenna 2"))
329
330         s:taboption("advanced", Flag, "frameburst", translate("Frame Bursting"))
331
332         s:taboption("advanced", Value, "distance", translate("Distance Optimization"))
333         --s:option(Value, "slottime", translate("Slot time"))
334
335         s:taboption("advanced", Value, "country", translate("Country Code"))
336         s:taboption("advanced", Value, "maxassoc", translate("Connection Limit"))
337 end
338
339
340 --------------------- HostAP Device ---------------------
341
342 if hwtype == "prism2" then
343         s:taboption("advanced", Value, "txpower", translate("Transmit Power"), "att units").rmempty = true
344
345         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
346
347         s:taboption("advanced", Value, "txantenna", translate("Transmitter Antenna"))
348         s:taboption("advanced", Value, "rxantenna", translate("Receiver Antenna"))
349 end
350
351
352 ----------------------- Interface -----------------------
353
354 s = m:section(NamedSection, wnet.sid, "wifi-iface", translate("Interface Configuration"))
355 ifsection = s
356 s.addremove = false
357 s.anonymous = true
358 s.defaults.device = wdev:name()
359
360 s:tab("general", translate("General Setup"))
361 s:tab("encryption", translate("Wireless Security"))
362 s:tab("macfilter", translate("MAC-Filter"))
363 s:tab("advanced", translate("Advanced Settings"))
364
365 ssid = s:taboption("general", Value, "ssid", translate("<abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
366 ssid.datatype = "maxlength(32)"
367
368 mode = s:taboption("general", ListValue, "mode", translate("Mode"))
369 mode.override_values = true
370 mode:value("ap", translate("Access Point"))
371 mode:value("sta", translate("Client"))
372 mode:value("adhoc", translate("Ad-Hoc"))
373
374 bssid = s:taboption("general", Value, "bssid", translate("<abbr title=\"Basic Service Set Identifier\">BSSID</abbr>"))
375
376 network = s:taboption("general", Value, "network", translate("Network"),
377         translate("Choose the network(s) you want to attach to this wireless interface or " ..
378                 "fill out the <em>create</em> field to define a new network."))
379
380 network.rmempty = true
381 network.template = "cbi/network_netlist"
382 network.widget = "checkbox"
383 network.novirtual = true
384
385 function network.write(self, section, value)
386         local i = nw:get_interface(section)
387         if i then
388                 if value == '-' then
389                         value = m:formvalue(self:cbid(section) .. ".newnet")
390                         if value and #value > 0 then
391                                 local n = nw:add_network(value, {proto="none"})
392                                 if n then n:add_interface(i) end
393                         else
394                                 local n = i:get_network()
395                                 if n then n:del_interface(i) end
396                         end
397                 else
398                         local v
399                         for _, v in ipairs(i:get_networks()) do
400                                 v:del_interface(i)
401                         end
402                         for v in ut.imatch(value) do
403                                 local n = nw:get_network(v)
404                                 if n then
405                                         if not n:is_empty() then
406                                                 n:set("type", "bridge")
407                                         end
408                                         n:add_interface(i)
409                                 end
410                         end
411                 end
412         end
413 end
414
415 -------------------- MAC80211 Interface ----------------------
416
417 if hwtype == "mac80211" then
418         if fs.access("/usr/sbin/iw") then
419                 mode:value("mesh", "802.11s")
420         end
421
422         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
423         mode:value("monitor", translate("Monitor"))
424         bssid:depends({mode="adhoc"})
425         bssid:depends({mode="sta"})
426         bssid:depends({mode="sta-wds"})
427
428         mp = s:taboption("macfilter", ListValue, "macfilter", translate("MAC-Address Filter"))
429         mp:depends({mode="ap"})
430         mp:depends({mode="ap-wds"})
431         mp:value("", translate("disable"))
432         mp:value("allow", translate("Allow listed only"))
433         mp:value("deny", translate("Allow all except listed"))
434
435         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
436         ml.datatype = "macaddr"
437         ml:depends({macfilter="allow"})
438         ml:depends({macfilter="deny"})
439         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
440
441         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
442         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
443
444         function mode.write(self, section, value)
445                 if value == "ap-wds" then
446                         ListValue.write(self, section, "ap")
447                         m.uci:set("wireless", section, "wds", 1)
448                 elseif value == "sta-wds" then
449                         ListValue.write(self, section, "sta")
450                         m.uci:set("wireless", section, "wds", 1)
451                 else
452                         ListValue.write(self, section, value)
453                         m.uci:delete("wireless", section, "wds")
454                 end
455         end
456
457         function mode.cfgvalue(self, section)
458                 local mode = ListValue.cfgvalue(self, section)
459                 local wds  = m.uci:get("wireless", section, "wds") == "1"
460
461                 if mode == "ap" and wds then
462                         return "ap-wds"
463                 elseif mode == "sta" and wds then
464                         return "sta-wds"
465                 else
466                         return mode
467                 end
468         end
469
470         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
471         hidden:depends({mode="ap"})
472         hidden:depends({mode="ap-wds"})
473
474         wmm = s:taboption("general", Flag, "wmm", translate("WMM Mode"))
475         wmm:depends({mode="ap"})
476         wmm:depends({mode="ap-wds"})
477         wmm.default = wmm.enabled
478 end
479
480
481
482 -------------------- Madwifi Interface ----------------------
483
484 if hwtype == "atheros" then
485         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
486         mode:value("monitor", translate("Monitor"))
487         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
488         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
489         mode:value("wds", translate("Static WDS"))
490
491         function mode.write(self, section, value)
492                 if value == "ap-wds" then
493                         ListValue.write(self, section, "ap")
494                         m.uci:set("wireless", section, "wds", 1)
495                 elseif value == "sta-wds" then
496                         ListValue.write(self, section, "sta")
497                         m.uci:set("wireless", section, "wds", 1)
498                 else
499                         ListValue.write(self, section, value)
500                         m.uci:delete("wireless", section, "wds")
501                 end
502         end
503
504         function mode.cfgvalue(self, section)
505                 local mode = ListValue.cfgvalue(self, section)
506                 local wds  = m.uci:get("wireless", section, "wds") == "1"
507
508                 if mode == "ap" and wds then
509                         return "ap-wds"
510                 elseif mode == "sta" and wds then
511                         return "sta-wds"
512                 else
513                         return mode
514                 end
515         end
516
517         bssid:depends({mode="adhoc"})
518         bssid:depends({mode="ahdemo"})
519         bssid:depends({mode="wds"})
520
521         wdssep = s:taboption("advanced", Flag, "wdssep", translate("Separate WDS"))
522         wdssep:depends({mode="ap-wds"})
523
524         s:taboption("advanced", Flag, "doth", "802.11h")
525         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
526         hidden:depends({mode="ap"})
527         hidden:depends({mode="adhoc"})
528         hidden:depends({mode="ap-wds"})
529         hidden:depends({mode="sta-wds"})
530         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
531          translate("Prevents client-to-client communication"))
532         isolate:depends({mode="ap"})
533         s:taboption("advanced", Flag, "bgscan", translate("Background Scan"))
534
535         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
536         mp:value("", translate("disable"))
537         mp:value("allow", translate("Allow listed only"))
538         mp:value("deny", translate("Allow all except listed"))
539
540         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
541         ml.datatype = "macaddr"
542         ml:depends({macpolicy="allow"})
543         ml:depends({macpolicy="deny"})
544         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
545
546         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
547         s:taboption("advanced", Value, "mcast_rate", translate("Multicast Rate"))
548         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
549         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
550         s:taboption("advanced", Value, "minrate", translate("Minimum Rate"))
551         s:taboption("advanced", Value, "maxrate", translate("Maximum Rate"))
552         s:taboption("advanced", Flag, "compression", translate("Compression"))
553
554         s:taboption("advanced", Flag, "bursting", translate("Frame Bursting"))
555         s:taboption("advanced", Flag, "turbo", translate("Turbo Mode"))
556         s:taboption("advanced", Flag, "ff", translate("Fast Frames"))
557
558         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
559         s:taboption("advanced", Flag, "xr", translate("XR Support"))
560         s:taboption("advanced", Flag, "ar", translate("AR Support"))
561
562         local swm = s:taboption("advanced", Flag, "sw_merge", translate("Disable HW-Beacon timer"))
563         swm:depends({mode="adhoc"})
564
565         local nos = s:taboption("advanced", Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
566         nos:depends({mode="sta"})
567         nos:depends({mode="sta-wds"})
568
569         local probereq = s:taboption("advanced", Flag, "probereq", translate("Do not send probe responses"))
570         probereq.enabled  = "0"
571         probereq.disabled = "1"
572 end
573
574
575 -------------------- Broadcom Interface ----------------------
576
577 if hwtype == "broadcom" then
578         mode:value("wds", translate("WDS"))
579         mode:value("monitor", translate("Monitor"))
580
581         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
582         hidden:depends({mode="ap"})
583         hidden:depends({mode="adhoc"})
584         hidden:depends({mode="wds"})
585
586         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
587          translate("Prevents client-to-client communication"))
588         isolate:depends({mode="ap"})
589
590         s:taboption("advanced", Flag, "doth", "802.11h")
591         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
592
593         bssid:depends({mode="wds"})
594         bssid:depends({mode="adhoc"})
595 end
596
597
598 ----------------------- HostAP Interface ---------------------
599
600 if hwtype == "prism2" then
601         mode:value("wds", translate("WDS"))
602         mode:value("monitor", translate("Monitor"))
603
604         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
605         hidden:depends({mode="ap"})
606         hidden:depends({mode="adhoc"})
607         hidden:depends({mode="wds"})
608
609         bssid:depends({mode="sta"})
610
611         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
612         mp:value("", translate("disable"))
613         mp:value("allow", translate("Allow listed only"))
614         mp:value("deny", translate("Allow all except listed"))
615         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
616         ml:depends({macpolicy="allow"})
617         ml:depends({macpolicy="deny"})
618         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
619
620         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
621         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
622         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
623 end
624
625
626 ------------------- WiFI-Encryption -------------------
627
628 encr = s:taboption("encryption", ListValue, "encryption", translate("Encryption"))
629 encr.override_values = true
630 encr.override_depends = true
631 encr:depends({mode="ap"})
632 encr:depends({mode="sta"})
633 encr:depends({mode="adhoc"})
634 encr:depends({mode="ahdemo"})
635 encr:depends({mode="ap-wds"})
636 encr:depends({mode="sta-wds"})
637 encr:depends({mode="mesh"})
638
639 cipher = s:taboption("encryption", ListValue, "cipher", translate("Cipher"))
640 cipher:depends({encryption="wpa"})
641 cipher:depends({encryption="wpa2"})
642 cipher:depends({encryption="psk"})
643 cipher:depends({encryption="psk2"})
644 cipher:depends({encryption="wpa-mixed"})
645 cipher:depends({encryption="psk-mixed"})
646 cipher:value("auto", translate("auto"))
647 cipher:value("ccmp", translate("Force CCMP (AES)"))
648 cipher:value("tkip", translate("Force TKIP"))
649 cipher:value("tkip+ccmp", translate("Force TKIP and CCMP (AES)"))
650
651 function encr.cfgvalue(self, section)
652         local v = tostring(ListValue.cfgvalue(self, section))
653         if v == "wep" then
654                 return "wep-open"
655         elseif v and v:match("%+") then
656                 return (v:gsub("%+.+$", ""))
657         end
658         return v
659 end
660
661 function encr.write(self, section, value)
662         local e = tostring(encr:formvalue(section))
663         local c = tostring(cipher:formvalue(section))
664         if value == "wpa" or value == "wpa2"  then
665                 self.map.uci:delete("wireless", section, "key")
666         end
667         if e and (c == "tkip" or c == "ccmp" or c == "tkip+ccmp") then
668                 e = e .. "+" .. c
669         end
670         self.map:set(section, "encryption", e)
671 end
672
673 function cipher.cfgvalue(self, section)
674         local v = tostring(ListValue.cfgvalue(encr, section))
675         if v and v:match("%+") then
676                 v = v:gsub("^[^%+]+%+", "")
677                 if v == "aes" then v = "ccmp"
678                 elseif v == "tkip+aes" then v = "tkip+ccmp"
679                 elseif v == "aes+tkip" then v = "tkip+ccmp"
680                 elseif v == "ccmp+tkip" then v = "tkip+ccmp"
681                 end
682         end
683         return v
684 end
685
686 function cipher.write(self, section)
687         return encr:write(section)
688 end
689
690
691 encr:value("none", "No Encryption")
692 encr:value("wep-open",   translate("WEP Open System"), {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"}, {mode="adhoc"}, {mode="ahdemo"}, {mode="wds"})
693 encr:value("wep-shared", translate("WEP Shared Key"),  {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"}, {mode="adhoc"}, {mode="ahdemo"}, {mode="wds"})
694
695 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
696         local supplicant = fs.access("/usr/sbin/wpa_supplicant")
697         local hostapd = fs.access("/usr/sbin/hostapd")
698
699         -- Probe EAP support
700         local has_ap_eap  = (os.execute("hostapd -veap >/dev/null 2>/dev/null") == 0)
701         local has_sta_eap = (os.execute("wpa_supplicant -veap >/dev/null 2>/dev/null") == 0)
702
703         if hostapd and supplicant then
704                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
705                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
706                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
707                 if has_ap_eap and has_sta_eap then
708                         encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
709                         encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
710                 end
711         elseif hostapd and not supplicant then
712                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="ap-wds"})
713                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="ap-wds"})
714                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="ap-wds"})
715                 if has_ap_eap then
716                         encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="ap-wds"})
717                         encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="ap-wds"})
718                 end
719                 encr.description = translate(
720                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
721                         "and ad-hoc mode) to be installed."
722                 )
723         elseif not hostapd and supplicant then
724                 encr:value("psk", "WPA-PSK", {mode="sta"}, {mode="sta-wds"})
725                 encr:value("psk2", "WPA2-PSK", {mode="sta"}, {mode="sta-wds"})
726                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="sta"}, {mode="sta-wds"})
727                 if has_sta_eap then
728                         encr:value("wpa", "WPA-EAP", {mode="sta"}, {mode="sta-wds"})
729                         encr:value("wpa2", "WPA2-EAP", {mode="sta"}, {mode="sta-wds"})
730                 end
731                 encr.description = translate(
732                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
733                         "and ad-hoc mode) to be installed."
734                 )
735         else
736                 encr.description = translate(
737                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
738                         "and ad-hoc mode) to be installed."
739                 )
740         end
741 elseif hwtype == "broadcom" then
742         encr:value("psk", "WPA-PSK")
743         encr:value("psk2", "WPA2-PSK")
744         encr:value("psk+psk2", "WPA-PSK/WPA2-PSK Mixed Mode")
745 end
746
747 auth_server = s:taboption("encryption", Value, "auth_server", translate("Radius-Authentication-Server"))
748 auth_server:depends({mode="ap", encryption="wpa"})
749 auth_server:depends({mode="ap", encryption="wpa2"})
750 auth_server:depends({mode="ap-wds", encryption="wpa"})
751 auth_server:depends({mode="ap-wds", encryption="wpa2"})
752 auth_server.rmempty = true
753 auth_server.datatype = "host(0)"
754
755 auth_port = s:taboption("encryption", Value, "auth_port", translate("Radius-Authentication-Port"), translatef("Default %d", 1812))
756 auth_port:depends({mode="ap", encryption="wpa"})
757 auth_port:depends({mode="ap", encryption="wpa2"})
758 auth_port:depends({mode="ap-wds", encryption="wpa"})
759 auth_port:depends({mode="ap-wds", encryption="wpa2"})
760 auth_port.rmempty = true
761 auth_port.datatype = "port"
762
763 auth_secret = s:taboption("encryption", Value, "auth_secret", translate("Radius-Authentication-Secret"))
764 auth_secret:depends({mode="ap", encryption="wpa"})
765 auth_secret:depends({mode="ap", encryption="wpa2"})
766 auth_secret:depends({mode="ap-wds", encryption="wpa"})
767 auth_secret:depends({mode="ap-wds", encryption="wpa2"})
768 auth_secret.rmempty = true
769 auth_secret.password = true
770
771 acct_server = s:taboption("encryption", Value, "acct_server", translate("Radius-Accounting-Server"))
772 acct_server:depends({mode="ap", encryption="wpa"})
773 acct_server:depends({mode="ap", encryption="wpa2"})
774 acct_server:depends({mode="ap-wds", encryption="wpa"})
775 acct_server:depends({mode="ap-wds", encryption="wpa2"})
776 acct_server.rmempty = true
777 acct_server.datatype = "host(0)"
778
779 acct_port = s:taboption("encryption", Value, "acct_port", translate("Radius-Accounting-Port"), translatef("Default %d", 1813))
780 acct_port:depends({mode="ap", encryption="wpa"})
781 acct_port:depends({mode="ap", encryption="wpa2"})
782 acct_port:depends({mode="ap-wds", encryption="wpa"})
783 acct_port:depends({mode="ap-wds", encryption="wpa2"})
784 acct_port.rmempty = true
785 acct_port.datatype = "port"
786
787 acct_secret = s:taboption("encryption", Value, "acct_secret", translate("Radius-Accounting-Secret"))
788 acct_secret:depends({mode="ap", encryption="wpa"})
789 acct_secret:depends({mode="ap", encryption="wpa2"})
790 acct_secret:depends({mode="ap-wds", encryption="wpa"})
791 acct_secret:depends({mode="ap-wds", encryption="wpa2"})
792 acct_secret.rmempty = true
793 acct_secret.password = true
794
795 wpakey = s:taboption("encryption", Value, "_wpa_key", translate("Key"))
796 wpakey:depends("encryption", "psk")
797 wpakey:depends("encryption", "psk2")
798 wpakey:depends("encryption", "psk+psk2")
799 wpakey:depends("encryption", "psk-mixed")
800 wpakey.datatype = "wpakey"
801 wpakey.rmempty = true
802 wpakey.password = true
803
804 wpakey.cfgvalue = function(self, section, value)
805         local key = m.uci:get("wireless", section, "key")
806         if key == "1" or key == "2" or key == "3" or key == "4" then
807                 return nil
808         end
809         return key
810 end
811
812 wpakey.write = function(self, section, value)
813         self.map.uci:set("wireless", section, "key", value)
814         self.map.uci:delete("wireless", section, "key1")
815 end
816
817
818 wepslot = s:taboption("encryption", ListValue, "_wep_key", translate("Used Key Slot"))
819 wepslot:depends("encryption", "wep-open")
820 wepslot:depends("encryption", "wep-shared")
821 wepslot:value("1", translatef("Key #%d", 1))
822 wepslot:value("2", translatef("Key #%d", 2))
823 wepslot:value("3", translatef("Key #%d", 3))
824 wepslot:value("4", translatef("Key #%d", 4))
825
826 wepslot.cfgvalue = function(self, section)
827         local slot = tonumber(m.uci:get("wireless", section, "key"))
828         if not slot or slot < 1 or slot > 4 then
829                 return 1
830         end
831         return slot
832 end
833
834 wepslot.write = function(self, section, value)
835         self.map.uci:set("wireless", section, "key", value)
836 end
837
838 local slot
839 for slot=1,4 do
840         wepkey = s:taboption("encryption", Value, "key" .. slot, translatef("Key #%d", slot))
841         wepkey:depends("encryption", "wep-open")
842         wepkey:depends("encryption", "wep-shared")
843         wepkey.datatype = "wepkey"
844         wepkey.rmempty = true
845         wepkey.password = true
846
847         function wepkey.write(self, section, value)
848                 if value and (#value == 5 or #value == 13) then
849                         value = "s:" .. value
850                 end
851                 return Value.write(self, section, value)
852         end
853 end
854
855
856 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
857         nasid = s:taboption("encryption", Value, "nasid", translate("NAS ID"))
858         nasid:depends({mode="ap", encryption="wpa"})
859         nasid:depends({mode="ap", encryption="wpa2"})
860         nasid:depends({mode="ap-wds", encryption="wpa"})
861         nasid:depends({mode="ap-wds", encryption="wpa2"})
862         nasid.rmempty = true
863
864         eaptype = s:taboption("encryption", ListValue, "eap_type", translate("EAP-Method"))
865         eaptype:value("tls",  "TLS")
866         eaptype:value("ttls", "TTLS")
867         eaptype:value("peap", "PEAP")
868         eaptype:value("fast", "FAST")
869         eaptype:depends({mode="sta", encryption="wpa"})
870         eaptype:depends({mode="sta", encryption="wpa2"})
871         eaptype:depends({mode="sta-wds", encryption="wpa"})
872         eaptype:depends({mode="sta-wds", encryption="wpa2"})
873
874         cacert = s:taboption("encryption", FileUpload, "ca_cert", translate("Path to CA-Certificate"))
875         cacert:depends({mode="sta", encryption="wpa"})
876         cacert:depends({mode="sta", encryption="wpa2"})
877         cacert:depends({mode="sta-wds", encryption="wpa"})
878         cacert:depends({mode="sta-wds", encryption="wpa2"})
879         cacert.rmempty = true
880
881         clientcert = s:taboption("encryption", FileUpload, "client_cert", translate("Path to Client-Certificate"))
882         clientcert:depends({mode="sta", eap_type="tls", encryption="wpa"})
883         clientcert:depends({mode="sta", eap_type="tls", encryption="wpa2"})
884         clientcert:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
885         clientcert:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
886
887         privkey = s:taboption("encryption", FileUpload, "priv_key", translate("Path to Private Key"))
888         privkey:depends({mode="sta", eap_type="tls", encryption="wpa2"})
889         privkey:depends({mode="sta", eap_type="tls", encryption="wpa"})
890         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
891         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
892
893         privkeypwd = s:taboption("encryption", Value, "priv_key_pwd", translate("Password of Private Key"))
894         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa2"})
895         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa"})
896         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
897         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
898         privkeypwd.rmempty = true
899         privkeypwd.password = true
900
901         auth = s:taboption("encryption", ListValue, "auth", translate("Authentication"))
902         auth:value("PAP", "PAP", {eap_type="ttls"})
903         auth:value("CHAP", "CHAP", {eap_type="ttls"})
904         auth:value("MSCHAP", "MSCHAP", {eap_type="ttls"})
905         auth:value("MSCHAPV2", "MSCHAPv2", {eap_type="ttls"})
906         auth:value("EAP-GTC")
907         auth:value("EAP-MD5")
908         auth:value("EAP-MSCHAPV2")
909         auth:value("EAP-TLS")
910         auth:depends({mode="sta", eap_type="fast", encryption="wpa2"})
911         auth:depends({mode="sta", eap_type="fast", encryption="wpa"})
912         auth:depends({mode="sta", eap_type="peap", encryption="wpa2"})
913         auth:depends({mode="sta", eap_type="peap", encryption="wpa"})
914         auth:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
915         auth:depends({mode="sta", eap_type="ttls", encryption="wpa"})
916         auth:depends({mode="sta-wds", eap_type="fast", encryption="wpa2"})
917         auth:depends({mode="sta-wds", eap_type="fast", encryption="wpa"})
918         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
919         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
920         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
921         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
922
923         cacert2 = s:taboption("encryption", FileUpload, "ca_cert2", translate("Path to inner CA-Certificate"))
924         cacert2:depends({mode="sta", auth="EAP-TLS", encryption="wpa"})
925         cacert2:depends({mode="sta", auth="EAP-TLS", encryption="wpa2"})
926         cacert2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa"})
927         cacert2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa2"})
928
929         clientcert2 = s:taboption("encryption", FileUpload, "client_cert2", translate("Path to inner Client-Certificate"))
930         clientcert2:depends({mode="sta", auth="EAP-TLS", encryption="wpa"})
931         clientcert2:depends({mode="sta", auth="EAP-TLS", encryption="wpa2"})
932         clientcert2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa"})
933         clientcert2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa2"})
934
935         privkey2 = s:taboption("encryption", FileUpload, "priv_key2", translate("Path to inner Private Key"))
936         privkey2:depends({mode="sta", auth="EAP-TLS", encryption="wpa"})
937         privkey2:depends({mode="sta", auth="EAP-TLS", encryption="wpa2"})
938         privkey2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa"})
939         privkey2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa2"})
940
941         privkeypwd2 = s:taboption("encryption", Value, "priv_key2_pwd", translate("Password of inner Private Key"))
942         privkeypwd2:depends({mode="sta", auth="EAP-TLS", encryption="wpa"})
943         privkeypwd2:depends({mode="sta", auth="EAP-TLS", encryption="wpa2"})
944         privkeypwd2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa"})
945         privkeypwd2:depends({mode="sta-wds", auth="EAP-TLS", encryption="wpa2"})
946         privkeypwd2.rmempty = true
947         privkeypwd2.password = true
948
949         identity = s:taboption("encryption", Value, "identity", translate("Identity"))
950         identity:depends({mode="sta", eap_type="fast", encryption="wpa2"})
951         identity:depends({mode="sta", eap_type="fast", encryption="wpa"})
952         identity:depends({mode="sta", eap_type="peap", encryption="wpa2"})
953         identity:depends({mode="sta", eap_type="peap", encryption="wpa"})
954         identity:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
955         identity:depends({mode="sta", eap_type="ttls", encryption="wpa"})
956         identity:depends({mode="sta-wds", eap_type="fast", encryption="wpa2"})
957         identity:depends({mode="sta-wds", eap_type="fast", encryption="wpa"})
958         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
959         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
960         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
961         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
962
963         password = s:taboption("encryption", Value, "password", translate("Password"))
964         password:depends({mode="sta", eap_type="fast", encryption="wpa2"})
965         password:depends({mode="sta", eap_type="fast", encryption="wpa"})
966         password:depends({mode="sta", eap_type="peap", encryption="wpa2"})
967         password:depends({mode="sta", eap_type="peap", encryption="wpa"})
968         password:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
969         password:depends({mode="sta", eap_type="ttls", encryption="wpa"})
970         password:depends({mode="sta-wds", eap_type="fast", encryption="wpa2"})
971         password:depends({mode="sta-wds", eap_type="fast", encryption="wpa"})
972         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
973         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
974         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
975         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
976         password.rmempty = true
977         password.password = true
978 end
979
980 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
981         local wpasupplicant = fs.access("/usr/sbin/wpa_supplicant")
982         local hostcli = fs.access("/usr/sbin/hostapd_cli")
983         if hostcli and wpasupplicant then
984                 wps = s:taboption("encryption", Flag, "wps_pushbutton", translate("Enable WPS pushbutton, requires WPA(2)-PSK"))
985                 wps.enabled = "1"
986                 wps.disabled = "0"
987                 wps.rmempty = false
988                 wps:depends("encryption", "psk")
989                 wps:depends("encryption", "psk2")
990                 wps:depends("encryption", "psk-mixed")
991         end
992 end
993
994 return m