validation: Add option ipv4only option to host and hostport datatypes
[project/luci.git] / modules / luci-mod-admin-full / luasrc / model / cbi / admin_network / wifi.lua
1 -- Copyright 2008 Steven Barth <steven@midlink.org>
2 -- Licensed to the public under the Apache License 2.0.
3
4 local wa = require "luci.tools.webadmin"
5 local nw = require "luci.model.network"
6 local ut = require "luci.util"
7 local nt = require "luci.sys".net
8 local fs = require "nixio.fs"
9
10 arg[1] = arg[1] or ""
11
12 m = Map("wireless", "",
13         translate("The <em>Device Configuration</em> section covers physical settings of the radio " ..
14                 "hardware such as channel, transmit power or antenna selection which are shared among all " ..
15                 "defined wireless networks (if the radio hardware is multi-SSID capable). Per network settings " ..
16                 "like encryption or operation mode are grouped in the <em>Interface Configuration</em>."))
17
18 m:chain("network")
19 m:chain("firewall")
20 m.redirect = luci.dispatcher.build_url("admin/network/wireless")
21
22 local ifsection
23
24 function m.on_commit(map)
25         local wnet = nw:get_wifinet(arg[1])
26         if ifsection and wnet then
27                 ifsection.section = wnet.sid
28                 m.title = luci.util.pcdata(wnet:get_i18n())
29         end
30 end
31
32 nw.init(m.uci)
33
34 local wnet = nw:get_wifinet(arg[1])
35 local wdev = wnet and wnet:get_device()
36
37 -- redirect to overview page if network does not exist anymore (e.g. after a revert)
38 if not wnet or not wdev then
39         luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless"))
40         return
41 end
42
43 -- wireless toggle was requested, commit and reload page
44 function m.parse(map)
45         if m:formvalue("cbid.wireless.%s.__toggle" % wdev:name()) then
46                 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
47                         wnet:set("disabled", nil)
48                 else
49                         wnet:set("disabled", "1")
50                 end
51                 wdev:set("disabled", nil)
52
53                 nw:commit("wireless")
54                 luci.sys.call("(env -i /bin/ubus call network reload) >/dev/null 2>/dev/null")
55
56                 luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless", arg[1]))
57                 return
58         end
59         Map.parse(map)
60 end
61
62 m.title = luci.util.pcdata(wnet:get_i18n())
63
64
65 local function txpower_list(iw)
66         local list = iw.txpwrlist or { }
67         local off  = tonumber(iw.txpower_offset) or 0
68         local new  = { }
69         local prev = -1
70         local _, val
71         for _, val in ipairs(list) do
72                 local dbm = val.dbm + off
73                 local mw  = math.floor(10 ^ (dbm / 10))
74                 if mw ~= prev then
75                         prev = mw
76                         new[#new+1] = {
77                                 display_dbm = dbm,
78                                 display_mw  = mw,
79                                 driver_dbm  = val.dbm,
80                                 driver_mw   = val.mw
81                         }
82                 end
83         end
84         return new
85 end
86
87 local function txpower_current(pwr, list)
88         pwr = tonumber(pwr)
89         if pwr ~= nil then
90                 local _, item
91                 for _, item in ipairs(list) do
92                         if item.driver_dbm >= pwr then
93                                 return item.driver_dbm
94                         end
95                 end
96         end
97         return (list[#list] and list[#list].driver_dbm) or pwr or 0
98 end
99
100 local iw = luci.sys.wifi.getiwinfo(arg[1])
101 local hw_modes      = iw.hwmodelist or { }
102 local tx_power_list = txpower_list(iw)
103 local tx_power_cur  = txpower_current(wdev:get("txpower"), tx_power_list)
104
105 s = m:section(NamedSection, wdev:name(), "wifi-device", translate("Device Configuration"))
106 s.addremove = false
107
108 s:tab("general", translate("General Setup"))
109 s:tab("macfilter", translate("MAC-Filter"))
110 s:tab("advanced", translate("Advanced Settings"))
111
112 --[[
113 back = s:option(DummyValue, "_overview", translate("Overview"))
114 back.value = ""
115 back.titleref = luci.dispatcher.build_url("admin", "network", "wireless")
116 ]]
117
118 st = s:taboption("general", DummyValue, "__status", translate("Status"))
119 st.template = "admin_network/wifi_status"
120 st.ifname   = arg[1]
121
122 en = s:taboption("general", Button, "__toggle")
123
124 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
125         en.title      = translate("Wireless network is disabled")
126         en.inputtitle = translate("Enable")
127         en.inputstyle = "apply"
128 else
129         en.title      = translate("Wireless network is enabled")
130         en.inputtitle = translate("Disable")
131         en.inputstyle = "reset"
132 end
133
134
135 local hwtype = wdev:get("type")
136
137 -- NanoFoo
138 local nsantenna = wdev:get("antenna")
139
140 -- Check whether there are client interfaces on the same radio,
141 -- if yes, lock the channel choice as these stations will dicatate the freq
142 local found_sta = nil
143 local _, net
144 if wnet:mode() ~= "sta" then
145         for _, net in ipairs(wdev:get_wifinets()) do
146                 if net:mode() == "sta" and net:get("disabled") ~= "1" then
147                         if not found_sta then
148                                 found_sta = {}
149                                 found_sta.channel = net:channel()
150                                 found_sta.names = {}
151                         end
152                         found_sta.names[#found_sta.names+1] = net:shortname()
153                 end
154         end
155 end
156
157 if found_sta then
158         ch = s:taboption("general", DummyValue, "choice", translate("Channel"))
159         ch.value = translatef("Locked to channel %d used by: %s",
160                 found_sta.channel, table.concat(found_sta.names, ", "))
161 else
162         ch = s:taboption("general", Value, "_mode_freq", '<br />'..translate("Operating frequency"))
163         ch.hwmodes = iw.hwmodelist
164         ch.freqlist = iw.freqlist
165         ch.template = "cbi/wireless_modefreq"
166
167         function ch.cfgvalue(self, section)
168                 return {
169                         m:get(section, "hwmode") or "",
170                         m:get(section, "channel") or "auto",
171                         m:get(section, "htmode") or ""
172                 }
173         end
174
175         function ch.formvalue(self, section)
176                 return {
177                         m:formvalue(self:cbid(section) .. ".band") or (iw.hwmodelist.g and "11g" or "11a"),
178                         m:formvalue(self:cbid(section) .. ".channel") or "auto",
179                         m:formvalue(self:cbid(section) .. ".htmode") or ""
180                 }
181         end
182
183         function ch.write(self, section, value)
184                 m:set(section, "hwmode", value[1])
185                 m:set(section, "channel", value[2])
186                 m:set(section, "htmode", value[3])
187         end
188 end
189
190 ------------------- MAC80211 Device ------------------
191
192 if hwtype == "mac80211" then
193         if #tx_power_list > 1 then
194                 tp = s:taboption("general", ListValue,
195                         "txpower", translate("Transmit Power"), "dBm")
196                 tp.rmempty = true
197                 tp.default = tx_power_cur
198                 function tp.cfgvalue(...)
199                         return txpower_current(Value.cfgvalue(...), tx_power_list)
200                 end
201
202                 for _, p in ipairs(tx_power_list) do
203                         tp:value(p.driver_dbm, "%i dBm (%i mW)"
204                                 %{ p.display_dbm, p.display_mw })
205                 end
206         end
207
208         local cl = iw and iw.countrylist
209         if cl and #cl > 0 then
210                 cc = s:taboption("advanced", ListValue, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
211                 cc.default = tostring(iw and iw.country or "00")
212                 for _, c in ipairs(cl) do
213                         cc:value(c.alpha2, "%s - %s" %{ c.alpha2, c.name })
214                 end
215         else
216                 s:taboption("advanced", Value, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
217         end
218
219         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
220                 translate("Distance to farthest network member in meters."))
221
222         -- external antenna profiles
223         local eal = iw and iw.extant
224         if eal and #eal > 0 then
225                 ea = s:taboption("advanced", ListValue, "extant", translate("Antenna Configuration"))
226                 for _, eap in ipairs(eal) do
227                         ea:value(eap.id, "%s (%s)" %{ eap.name, eap.description })
228                         if eap.selected then
229                                 ea.default = eap.id
230                         end
231                 end
232         end
233
234         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
235         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
236 end
237
238
239 ------------------- Madwifi Device ------------------
240
241 if hwtype == "atheros" then
242         tp = s:taboption("general",
243                 (#tx_power_list > 0) and ListValue or Value,
244                 "txpower", translate("Transmit Power"), "dBm")
245
246         tp.rmempty = true
247         tp.default = tx_power_cur
248
249         function tp.cfgvalue(...)
250                 return txpower_current(Value.cfgvalue(...), tx_power_list)
251         end
252
253         for _, p in ipairs(tx_power_list) do
254                 tp:value(p.driver_dbm, "%i dBm (%i mW)"
255                         %{ p.display_dbm, p.display_mw })
256         end
257
258         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
259
260         if not nsantenna then
261                 ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
262                 ant1.widget = "radio"
263                 ant1.orientation = "horizontal"
264                 ant1:depends("diversity", "")
265                 ant1:value("0", translate("auto"))
266                 ant1:value("1", translate("Antenna 1"))
267                 ant1:value("2", translate("Antenna 2"))
268
269                 ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
270                 ant2.widget = "radio"
271                 ant2.orientation = "horizontal"
272                 ant2:depends("diversity", "")
273                 ant2:value("0", translate("auto"))
274                 ant2:value("1", translate("Antenna 1"))
275                 ant2:value("2", translate("Antenna 2"))
276
277         else -- NanoFoo
278                 local ant = s:taboption("advanced", ListValue, "antenna", translate("Transmitter Antenna"))
279                 ant:value("auto")
280                 ant:value("vertical")
281                 ant:value("horizontal")
282                 ant:value("external")
283         end
284
285         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
286                 translate("Distance to farthest network member in meters."))
287         s:taboption("advanced", Value, "regdomain", translate("Regulatory Domain"))
288         s:taboption("advanced", Value, "country", translate("Country Code"))
289         s:taboption("advanced", Flag, "outdoor", translate("Outdoor Channels"))
290
291         --s:option(Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
292 end
293
294
295
296 ------------------- Broadcom Device ------------------
297
298 if hwtype == "broadcom" then
299         tp = s:taboption("general",
300                 (#tx_power_list > 0) and ListValue or Value,
301                 "txpower", translate("Transmit Power"), "dBm")
302
303         tp.rmempty = true
304         tp.default = tx_power_cur
305
306         function tp.cfgvalue(...)
307                 return txpower_current(Value.cfgvalue(...), tx_power_list)
308         end
309
310         for _, p in ipairs(tx_power_list) do
311                 tp:value(p.driver_dbm, "%i dBm (%i mW)"
312                         %{ p.display_dbm, p.display_mw })
313         end
314
315         ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
316         ant1.widget = "radio"
317         ant1:depends("diversity", "")
318         ant1:value("3", translate("auto"))
319         ant1:value("0", translate("Antenna 1"))
320         ant1:value("1", translate("Antenna 2"))
321
322         ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
323         ant2.widget = "radio"
324         ant2:depends("diversity", "")
325         ant2:value("3", translate("auto"))
326         ant2:value("0", translate("Antenna 1"))
327         ant2:value("1", translate("Antenna 2"))
328
329         s:taboption("advanced", Flag, "frameburst", translate("Frame Bursting"))
330
331         s:taboption("advanced", Value, "distance", translate("Distance Optimization"))
332         --s:option(Value, "slottime", translate("Slot time"))
333
334         s:taboption("advanced", Value, "country", translate("Country Code"))
335         s:taboption("advanced", Value, "maxassoc", translate("Connection Limit"))
336 end
337
338
339 --------------------- HostAP Device ---------------------
340
341 if hwtype == "prism2" then
342         s:taboption("advanced", Value, "txpower", translate("Transmit Power"), "att units").rmempty = true
343
344         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
345
346         s:taboption("advanced", Value, "txantenna", translate("Transmitter Antenna"))
347         s:taboption("advanced", Value, "rxantenna", translate("Receiver Antenna"))
348 end
349
350
351 ----------------------- Interface -----------------------
352
353 s = m:section(NamedSection, wnet.sid, "wifi-iface", translate("Interface Configuration"))
354 ifsection = s
355 s.addremove = false
356 s.anonymous = true
357 s.defaults.device = wdev:name()
358
359 s:tab("general", translate("General Setup"))
360 s:tab("encryption", translate("Wireless Security"))
361 s:tab("macfilter", translate("MAC-Filter"))
362 s:tab("advanced", translate("Advanced Settings"))
363
364 ssid = s:taboption("general", Value, "ssid", translate("<abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
365 ssid.datatype = "maxlength(32)"
366
367 mode = s:taboption("general", ListValue, "mode", translate("Mode"))
368 mode.override_values = true
369 mode:value("ap", translate("Access Point"))
370 mode:value("sta", translate("Client"))
371 mode:value("adhoc", translate("Ad-Hoc"))
372
373 bssid = s:taboption("general", Value, "bssid", translate("<abbr title=\"Basic Service Set Identifier\">BSSID</abbr>"))
374
375 network = s:taboption("general", Value, "network", translate("Network"),
376         translate("Choose the network(s) you want to attach to this wireless interface or " ..
377                 "fill out the <em>create</em> field to define a new network."))
378
379 network.rmempty = true
380 network.template = "cbi/network_netlist"
381 network.widget = "checkbox"
382 network.novirtual = true
383
384 function network.write(self, section, value)
385         local i = nw:get_interface(section)
386         if i then
387                 if value == '-' then
388                         value = m:formvalue(self:cbid(section) .. ".newnet")
389                         if value and #value > 0 then
390                                 local n = nw:add_network(value, {proto="none"})
391                                 if n then n:add_interface(i) end
392                         else
393                                 local n = i:get_network()
394                                 if n then n:del_interface(i) end
395                         end
396                 else
397                         local v
398                         for _, v in ipairs(i:get_networks()) do
399                                 v:del_interface(i)
400                         end
401                         for v in ut.imatch(value) do
402                                 local n = nw:get_network(v)
403                                 if n then
404                                         if not n:is_empty() then
405                                                 n:set("type", "bridge")
406                                         end
407                                         n:add_interface(i)
408                                 end
409                         end
410                 end
411         end
412 end
413
414 -------------------- MAC80211 Interface ----------------------
415
416 if hwtype == "mac80211" then
417         if fs.access("/usr/sbin/iw") then
418                 mode:value("mesh", "802.11s")
419         end
420
421         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
422         mode:value("monitor", translate("Monitor"))
423         bssid:depends({mode="adhoc"})
424         bssid:depends({mode="sta"})
425         bssid:depends({mode="sta-wds"})
426
427         mp = s:taboption("macfilter", ListValue, "macfilter", translate("MAC-Address Filter"))
428         mp:depends({mode="ap"})
429         mp:depends({mode="ap-wds"})
430         mp:value("", translate("disable"))
431         mp:value("allow", translate("Allow listed only"))
432         mp:value("deny", translate("Allow all except listed"))
433
434         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
435         ml.datatype = "macaddr"
436         ml:depends({macfilter="allow"})
437         ml:depends({macfilter="deny"})
438         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
439
440         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
441         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
442
443         function mode.write(self, section, value)
444                 if value == "ap-wds" then
445                         ListValue.write(self, section, "ap")
446                         m.uci:set("wireless", section, "wds", 1)
447                 elseif value == "sta-wds" then
448                         ListValue.write(self, section, "sta")
449                         m.uci:set("wireless", section, "wds", 1)
450                 else
451                         ListValue.write(self, section, value)
452                         m.uci:delete("wireless", section, "wds")
453                 end
454         end
455
456         function mode.cfgvalue(self, section)
457                 local mode = ListValue.cfgvalue(self, section)
458                 local wds  = m.uci:get("wireless", section, "wds") == "1"
459
460                 if mode == "ap" and wds then
461                         return "ap-wds"
462                 elseif mode == "sta" and wds then
463                         return "sta-wds"
464                 else
465                         return mode
466                 end
467         end
468
469         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
470         hidden:depends({mode="ap"})
471         hidden:depends({mode="ap-wds"})
472
473         wmm = s:taboption("general", Flag, "wmm", translate("WMM Mode"))
474         wmm:depends({mode="ap"})
475         wmm:depends({mode="ap-wds"})
476         wmm.default = wmm.enabled
477 end
478
479
480
481 -------------------- Madwifi Interface ----------------------
482
483 if hwtype == "atheros" then
484         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
485         mode:value("monitor", translate("Monitor"))
486         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
487         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
488         mode:value("wds", translate("Static WDS"))
489
490         function mode.write(self, section, value)
491                 if value == "ap-wds" then
492                         ListValue.write(self, section, "ap")
493                         m.uci:set("wireless", section, "wds", 1)
494                 elseif value == "sta-wds" then
495                         ListValue.write(self, section, "sta")
496                         m.uci:set("wireless", section, "wds", 1)
497                 else
498                         ListValue.write(self, section, value)
499                         m.uci:delete("wireless", section, "wds")
500                 end
501         end
502
503         function mode.cfgvalue(self, section)
504                 local mode = ListValue.cfgvalue(self, section)
505                 local wds  = m.uci:get("wireless", section, "wds") == "1"
506
507                 if mode == "ap" and wds then
508                         return "ap-wds"
509                 elseif mode == "sta" and wds then
510                         return "sta-wds"
511                 else
512                         return mode
513                 end
514         end
515
516         bssid:depends({mode="adhoc"})
517         bssid:depends({mode="ahdemo"})
518         bssid:depends({mode="wds"})
519
520         wdssep = s:taboption("advanced", Flag, "wdssep", translate("Separate WDS"))
521         wdssep:depends({mode="ap-wds"})
522
523         s:taboption("advanced", Flag, "doth", "802.11h")
524         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
525         hidden:depends({mode="ap"})
526         hidden:depends({mode="adhoc"})
527         hidden:depends({mode="ap-wds"})
528         hidden:depends({mode="sta-wds"})
529         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
530          translate("Prevents client-to-client communication"))
531         isolate:depends({mode="ap"})
532         s:taboption("advanced", Flag, "bgscan", translate("Background Scan"))
533
534         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
535         mp:value("", translate("disable"))
536         mp:value("allow", translate("Allow listed only"))
537         mp:value("deny", translate("Allow all except listed"))
538
539         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
540         ml.datatype = "macaddr"
541         ml:depends({macpolicy="allow"})
542         ml:depends({macpolicy="deny"})
543         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
544
545         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
546         s:taboption("advanced", Value, "mcast_rate", translate("Multicast Rate"))
547         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
548         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
549         s:taboption("advanced", Value, "minrate", translate("Minimum Rate"))
550         s:taboption("advanced", Value, "maxrate", translate("Maximum Rate"))
551         s:taboption("advanced", Flag, "compression", translate("Compression"))
552
553         s:taboption("advanced", Flag, "bursting", translate("Frame Bursting"))
554         s:taboption("advanced", Flag, "turbo", translate("Turbo Mode"))
555         s:taboption("advanced", Flag, "ff", translate("Fast Frames"))
556
557         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
558         s:taboption("advanced", Flag, "xr", translate("XR Support"))
559         s:taboption("advanced", Flag, "ar", translate("AR Support"))
560
561         local swm = s:taboption("advanced", Flag, "sw_merge", translate("Disable HW-Beacon timer"))
562         swm:depends({mode="adhoc"})
563
564         local nos = s:taboption("advanced", Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
565         nos:depends({mode="sta"})
566         nos:depends({mode="sta-wds"})
567
568         local probereq = s:taboption("advanced", Flag, "probereq", translate("Do not send probe responses"))
569         probereq.enabled  = "0"
570         probereq.disabled = "1"
571 end
572
573
574 -------------------- Broadcom Interface ----------------------
575
576 if hwtype == "broadcom" then
577         mode:value("wds", translate("WDS"))
578         mode:value("monitor", translate("Monitor"))
579
580         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
581         hidden:depends({mode="ap"})
582         hidden:depends({mode="adhoc"})
583         hidden:depends({mode="wds"})
584
585         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
586          translate("Prevents client-to-client communication"))
587         isolate:depends({mode="ap"})
588
589         s:taboption("advanced", Flag, "doth", "802.11h")
590         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
591
592         bssid:depends({mode="wds"})
593         bssid:depends({mode="adhoc"})
594 end
595
596
597 ----------------------- HostAP Interface ---------------------
598
599 if hwtype == "prism2" then
600         mode:value("wds", translate("WDS"))
601         mode:value("monitor", translate("Monitor"))
602
603         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
604         hidden:depends({mode="ap"})
605         hidden:depends({mode="adhoc"})
606         hidden:depends({mode="wds"})
607
608         bssid:depends({mode="sta"})
609
610         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
611         mp:value("", translate("disable"))
612         mp:value("allow", translate("Allow listed only"))
613         mp:value("deny", translate("Allow all except listed"))
614         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
615         ml:depends({macpolicy="allow"})
616         ml:depends({macpolicy="deny"})
617         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
618
619         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
620         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
621         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
622 end
623
624
625 ------------------- WiFI-Encryption -------------------
626
627 encr = s:taboption("encryption", ListValue, "encryption", translate("Encryption"))
628 encr.override_values = true
629 encr.override_depends = true
630 encr:depends({mode="ap"})
631 encr:depends({mode="sta"})
632 encr:depends({mode="adhoc"})
633 encr:depends({mode="ahdemo"})
634 encr:depends({mode="ap-wds"})
635 encr:depends({mode="sta-wds"})
636 encr:depends({mode="mesh"})
637
638 cipher = s:taboption("encryption", ListValue, "cipher", translate("Cipher"))
639 cipher:depends({encryption="wpa"})
640 cipher:depends({encryption="wpa2"})
641 cipher:depends({encryption="psk"})
642 cipher:depends({encryption="psk2"})
643 cipher:depends({encryption="wpa-mixed"})
644 cipher:depends({encryption="psk-mixed"})
645 cipher:value("auto", translate("auto"))
646 cipher:value("ccmp", translate("Force CCMP (AES)"))
647 cipher:value("tkip", translate("Force TKIP"))
648 cipher:value("tkip+ccmp", translate("Force TKIP and CCMP (AES)"))
649
650 function encr.cfgvalue(self, section)
651         local v = tostring(ListValue.cfgvalue(self, section))
652         if v == "wep" then
653                 return "wep-open"
654         elseif v and v:match("%+") then
655                 return (v:gsub("%+.+$", ""))
656         end
657         return v
658 end
659
660 function encr.write(self, section, value)
661         local e = tostring(encr:formvalue(section))
662         local c = tostring(cipher:formvalue(section))
663         if value == "wpa" or value == "wpa2"  then
664                 self.map.uci:delete("wireless", section, "key")
665         end
666         if e and (c == "tkip" or c == "ccmp" or c == "tkip+ccmp") then
667                 e = e .. "+" .. c
668         end
669         self.map:set(section, "encryption", e)
670 end
671
672 function cipher.cfgvalue(self, section)
673         local v = tostring(ListValue.cfgvalue(encr, section))
674         if v and v:match("%+") then
675                 v = v:gsub("^[^%+]+%+", "")
676                 if v == "aes" then v = "ccmp"
677                 elseif v == "tkip+aes" then v = "tkip+ccmp"
678                 elseif v == "aes+tkip" then v = "tkip+ccmp"
679                 elseif v == "ccmp+tkip" then v = "tkip+ccmp"
680                 end
681         end
682         return v
683 end
684
685 function cipher.write(self, section)
686         return encr:write(section)
687 end
688
689
690 encr:value("none", "No Encryption")
691 encr:value("wep-open",   translate("WEP Open System"), {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"}, {mode="adhoc"}, {mode="ahdemo"}, {mode="wds"})
692 encr:value("wep-shared", translate("WEP Shared Key"),  {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"}, {mode="adhoc"}, {mode="ahdemo"}, {mode="wds"})
693
694 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
695         local supplicant = fs.access("/usr/sbin/wpa_supplicant")
696         local hostapd = fs.access("/usr/sbin/hostapd")
697
698         -- Probe EAP support
699         local has_ap_eap  = (os.execute("hostapd -veap >/dev/null 2>/dev/null") == 0)
700         local has_sta_eap = (os.execute("wpa_supplicant -veap >/dev/null 2>/dev/null") == 0)
701
702         if hostapd and supplicant then
703                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
704                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
705                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
706                 if has_ap_eap and has_sta_eap then
707                         encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
708                         encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
709                 end
710         elseif hostapd and not supplicant then
711                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="ap-wds"})
712                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="ap-wds"})
713                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="ap-wds"})
714                 if has_ap_eap then
715                         encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="ap-wds"})
716                         encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="ap-wds"})
717                 end
718                 encr.description = translate(
719                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
720                         "and ad-hoc mode) to be installed."
721                 )
722         elseif not hostapd and supplicant then
723                 encr:value("psk", "WPA-PSK", {mode="sta"}, {mode="sta-wds"})
724                 encr:value("psk2", "WPA2-PSK", {mode="sta"}, {mode="sta-wds"})
725                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="sta"}, {mode="sta-wds"})
726                 if has_sta_eap then
727                         encr:value("wpa", "WPA-EAP", {mode="sta"}, {mode="sta-wds"})
728                         encr:value("wpa2", "WPA2-EAP", {mode="sta"}, {mode="sta-wds"})
729                 end
730                 encr.description = translate(
731                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
732                         "and ad-hoc mode) to be installed."
733                 )
734         else
735                 encr.description = translate(
736                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
737                         "and ad-hoc mode) to be installed."
738                 )
739         end
740 elseif hwtype == "broadcom" then
741         encr:value("psk", "WPA-PSK")
742         encr:value("psk2", "WPA2-PSK")
743         encr:value("psk+psk2", "WPA-PSK/WPA2-PSK Mixed Mode")
744 end
745
746 auth_server = s:taboption("encryption", Value, "auth_server", translate("Radius-Authentication-Server"))
747 auth_server:depends({mode="ap", encryption="wpa"})
748 auth_server:depends({mode="ap", encryption="wpa2"})
749 auth_server:depends({mode="ap-wds", encryption="wpa"})
750 auth_server:depends({mode="ap-wds", encryption="wpa2"})
751 auth_server.rmempty = true
752 auth_server.datatype = "host(0)"
753
754 auth_port = s:taboption("encryption", Value, "auth_port", translate("Radius-Authentication-Port"), translatef("Default %d", 1812))
755 auth_port:depends({mode="ap", encryption="wpa"})
756 auth_port:depends({mode="ap", encryption="wpa2"})
757 auth_port:depends({mode="ap-wds", encryption="wpa"})
758 auth_port:depends({mode="ap-wds", encryption="wpa2"})
759 auth_port.rmempty = true
760 auth_port.datatype = "port"
761
762 auth_secret = s:taboption("encryption", Value, "auth_secret", translate("Radius-Authentication-Secret"))
763 auth_secret:depends({mode="ap", encryption="wpa"})
764 auth_secret:depends({mode="ap", encryption="wpa2"})
765 auth_secret:depends({mode="ap-wds", encryption="wpa"})
766 auth_secret:depends({mode="ap-wds", encryption="wpa2"})
767 auth_secret.rmempty = true
768 auth_secret.password = true
769
770 acct_server = s:taboption("encryption", Value, "acct_server", translate("Radius-Accounting-Server"))
771 acct_server:depends({mode="ap", encryption="wpa"})
772 acct_server:depends({mode="ap", encryption="wpa2"})
773 acct_server:depends({mode="ap-wds", encryption="wpa"})
774 acct_server:depends({mode="ap-wds", encryption="wpa2"})
775 acct_server.rmempty = true
776 acct_server.datatype = "host(0)"
777
778 acct_port = s:taboption("encryption", Value, "acct_port", translate("Radius-Accounting-Port"), translatef("Default %d", 1813))
779 acct_port:depends({mode="ap", encryption="wpa"})
780 acct_port:depends({mode="ap", encryption="wpa2"})
781 acct_port:depends({mode="ap-wds", encryption="wpa"})
782 acct_port:depends({mode="ap-wds", encryption="wpa2"})
783 acct_port.rmempty = true
784 acct_port.datatype = "port"
785
786 acct_secret = s:taboption("encryption", Value, "acct_secret", translate("Radius-Accounting-Secret"))
787 acct_secret:depends({mode="ap", encryption="wpa"})
788 acct_secret:depends({mode="ap", encryption="wpa2"})
789 acct_secret:depends({mode="ap-wds", encryption="wpa"})
790 acct_secret:depends({mode="ap-wds", encryption="wpa2"})
791 acct_secret.rmempty = true
792 acct_secret.password = true
793
794 wpakey = s:taboption("encryption", Value, "_wpa_key", translate("Key"))
795 wpakey:depends("encryption", "psk")
796 wpakey:depends("encryption", "psk2")
797 wpakey:depends("encryption", "psk+psk2")
798 wpakey:depends("encryption", "psk-mixed")
799 wpakey.datatype = "wpakey"
800 wpakey.rmempty = true
801 wpakey.password = true
802
803 wpakey.cfgvalue = function(self, section, value)
804         local key = m.uci:get("wireless", section, "key")
805         if key == "1" or key == "2" or key == "3" or key == "4" then
806                 return nil
807         end
808         return key
809 end
810
811 wpakey.write = function(self, section, value)
812         self.map.uci:set("wireless", section, "key", value)
813         self.map.uci:delete("wireless", section, "key1")
814 end
815
816
817 wepslot = s:taboption("encryption", ListValue, "_wep_key", translate("Used Key Slot"))
818 wepslot:depends("encryption", "wep-open")
819 wepslot:depends("encryption", "wep-shared")
820 wepslot:value("1", translatef("Key #%d", 1))
821 wepslot:value("2", translatef("Key #%d", 2))
822 wepslot:value("3", translatef("Key #%d", 3))
823 wepslot:value("4", translatef("Key #%d", 4))
824
825 wepslot.cfgvalue = function(self, section)
826         local slot = tonumber(m.uci:get("wireless", section, "key"))
827         if not slot or slot < 1 or slot > 4 then
828                 return 1
829         end
830         return slot
831 end
832
833 wepslot.write = function(self, section, value)
834         self.map.uci:set("wireless", section, "key", value)
835 end
836
837 local slot
838 for slot=1,4 do
839         wepkey = s:taboption("encryption", Value, "key" .. slot, translatef("Key #%d", slot))
840         wepkey:depends("encryption", "wep-open")
841         wepkey:depends("encryption", "wep-shared")
842         wepkey.datatype = "wepkey"
843         wepkey.rmempty = true
844         wepkey.password = true
845
846         function wepkey.write(self, section, value)
847                 if value and (#value == 5 or #value == 13) then
848                         value = "s:" .. value
849                 end
850                 return Value.write(self, section, value)
851         end
852 end
853
854
855 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
856         nasid = s:taboption("encryption", Value, "nasid", translate("NAS ID"))
857         nasid:depends({mode="ap", encryption="wpa"})
858         nasid:depends({mode="ap", encryption="wpa2"})
859         nasid:depends({mode="ap-wds", encryption="wpa"})
860         nasid:depends({mode="ap-wds", encryption="wpa2"})
861         nasid.rmempty = true
862
863         eaptype = s:taboption("encryption", ListValue, "eap_type", translate("EAP-Method"))
864         eaptype:value("tls",  "TLS")
865         eaptype:value("ttls", "TTLS")
866         eaptype:value("peap", "PEAP")
867         eaptype:depends({mode="sta", encryption="wpa"})
868         eaptype:depends({mode="sta", encryption="wpa2"})
869         eaptype:depends({mode="sta-wds", encryption="wpa"})
870         eaptype:depends({mode="sta-wds", encryption="wpa2"})
871
872         cacert = s:taboption("encryption", FileUpload, "ca_cert", translate("Path to CA-Certificate"))
873         cacert:depends({mode="sta", encryption="wpa"})
874         cacert:depends({mode="sta", encryption="wpa2"})
875         cacert:depends({mode="sta-wds", encryption="wpa"})
876         cacert:depends({mode="sta-wds", encryption="wpa2"})
877
878         clientcert = s:taboption("encryption", FileUpload, "client_cert", translate("Path to Client-Certificate"))
879         clientcert:depends({mode="sta", encryption="wpa"})
880         clientcert:depends({mode="sta", encryption="wpa2"})
881         clientcert:depends({mode="sta-wds", encryption="wpa"})
882         clientcert:depends({mode="sta-wds", encryption="wpa2"})
883
884         privkey = s:taboption("encryption", FileUpload, "priv_key", translate("Path to Private Key"))
885         privkey:depends({mode="sta", eap_type="tls", encryption="wpa2"})
886         privkey:depends({mode="sta", eap_type="tls", encryption="wpa"})
887         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
888         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
889
890         privkeypwd = s:taboption("encryption", Value, "priv_key_pwd", translate("Password of Private Key"))
891         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa2"})
892         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa"})
893         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
894         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
895
896
897         auth = s:taboption("encryption", Value, "auth", translate("Authentication"))
898         auth:value("PAP")
899         auth:value("CHAP")
900         auth:value("MSCHAP")
901         auth:value("MSCHAPV2")
902         auth:depends({mode="sta", eap_type="peap", encryption="wpa2"})
903         auth:depends({mode="sta", eap_type="peap", encryption="wpa"})
904         auth:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
905         auth:depends({mode="sta", eap_type="ttls", encryption="wpa"})
906         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
907         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
908         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
909         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
910
911
912         identity = s:taboption("encryption", Value, "identity", translate("Identity"))
913         identity:depends({mode="sta", eap_type="peap", encryption="wpa2"})
914         identity:depends({mode="sta", eap_type="peap", encryption="wpa"})
915         identity:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
916         identity:depends({mode="sta", eap_type="ttls", encryption="wpa"})
917         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
918         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
919         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
920         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
921
922         password = s:taboption("encryption", Value, "password", translate("Password"))
923         password:depends({mode="sta", eap_type="peap", encryption="wpa2"})
924         password:depends({mode="sta", eap_type="peap", encryption="wpa"})
925         password:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
926         password:depends({mode="sta", eap_type="ttls", encryption="wpa"})
927         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
928         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
929         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
930         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
931 end
932
933 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
934         local wpasupplicant = fs.access("/usr/sbin/wpa_supplicant")
935         local hostcli = fs.access("/usr/sbin/hostapd_cli")
936         if hostcli and wpasupplicant then
937                 wps = s:taboption("encryption", Flag, "wps_pushbutton", translate("Enable WPS pushbutton, requires WPA(2)-PSK"))
938                 wps.enabled = "1"
939                 wps.disabled = "0"
940                 wps.rmempty = false
941                 wps:depends("encryption", "psk")
942                 wps:depends("encryption", "psk2")
943                 wps:depends("encryption", "psk-mixed")
944         end
945 end
946
947 return m