Merge pull request #304 from nmav/ocserv-crypt
[project/luci.git] / modules / luci-mod-admin-full / luasrc / model / cbi / admin_network / wifi.lua
1 -- Copyright 2008 Steven Barth <steven@midlink.org>
2 -- Licensed to the public under the Apache License 2.0.
3
4 local wa = require "luci.tools.webadmin"
5 local nw = require "luci.model.network"
6 local ut = require "luci.util"
7 local nt = require "luci.sys".net
8 local fs = require "nixio.fs"
9
10 arg[1] = arg[1] or ""
11
12 m = Map("wireless", "",
13         translate("The <em>Device Configuration</em> section covers physical settings of the radio " ..
14                 "hardware such as channel, transmit power or antenna selection which are shared among all " ..
15                 "defined wireless networks (if the radio hardware is multi-SSID capable). Per network settings " ..
16                 "like encryption or operation mode are grouped in the <em>Interface Configuration</em>."))
17
18 m:chain("network")
19 m:chain("firewall")
20 m.redirect = luci.dispatcher.build_url("admin/network/wireless")
21
22 local ifsection
23
24 function m.on_commit(map)
25         local wnet = nw:get_wifinet(arg[1])
26         if ifsection and wnet then
27                 ifsection.section = wnet.sid
28                 m.title = luci.util.pcdata(wnet:get_i18n())
29         end
30 end
31
32 nw.init(m.uci)
33
34 local wnet = nw:get_wifinet(arg[1])
35 local wdev = wnet and wnet:get_device()
36
37 -- redirect to overview page if network does not exist anymore (e.g. after a revert)
38 if not wnet or not wdev then
39         luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless"))
40         return
41 end
42
43 -- wireless toggle was requested, commit and reload page
44 function m.parse(map)
45         if m:formvalue("cbid.wireless.%s.__toggle" % wdev:name()) then
46                 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
47                         wnet:set("disabled", nil)
48                 else
49                         wnet:set("disabled", "1")
50                 end
51                 wdev:set("disabled", nil)
52
53                 nw:commit("wireless")
54                 luci.sys.call("(env -i /bin/ubus call network reload) >/dev/null 2>/dev/null")
55
56                 luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless", arg[1]))
57                 return
58         end
59         Map.parse(map)
60 end
61
62 m.title = luci.util.pcdata(wnet:get_i18n())
63
64
65 local function txpower_list(iw)
66         local list = iw.txpwrlist or { }
67         local off  = tonumber(iw.txpower_offset) or 0
68         local new  = { }
69         local prev = -1
70         local _, val
71         for _, val in ipairs(list) do
72                 local dbm = val.dbm + off
73                 local mw  = math.floor(10 ^ (dbm / 10))
74                 if mw ~= prev then
75                         prev = mw
76                         new[#new+1] = {
77                                 display_dbm = dbm,
78                                 display_mw  = mw,
79                                 driver_dbm  = val.dbm,
80                                 driver_mw   = val.mw
81                         }
82                 end
83         end
84         return new
85 end
86
87 local function txpower_current(pwr, list)
88         pwr = tonumber(pwr)
89         if pwr ~= nil then
90                 local _, item
91                 for _, item in ipairs(list) do
92                         if item.driver_dbm >= pwr then
93                                 return item.driver_dbm
94                         end
95                 end
96         end
97         return (list[#list] and list[#list].driver_dbm) or pwr or 0
98 end
99
100 local iw = luci.sys.wifi.getiwinfo(arg[1])
101 local hw_modes      = iw.hwmodelist or { }
102 local tx_power_list = txpower_list(iw)
103 local tx_power_cur  = txpower_current(wdev:get("txpower"), tx_power_list)
104
105 s = m:section(NamedSection, wdev:name(), "wifi-device", translate("Device Configuration"))
106 s.addremove = false
107
108 s:tab("general", translate("General Setup"))
109 s:tab("macfilter", translate("MAC-Filter"))
110 s:tab("advanced", translate("Advanced Settings"))
111
112 --[[
113 back = s:option(DummyValue, "_overview", translate("Overview"))
114 back.value = ""
115 back.titleref = luci.dispatcher.build_url("admin", "network", "wireless")
116 ]]
117
118 st = s:taboption("general", DummyValue, "__status", translate("Status"))
119 st.template = "admin_network/wifi_status"
120 st.ifname   = arg[1]
121
122 en = s:taboption("general", Button, "__toggle")
123
124 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
125         en.title      = translate("Wireless network is disabled")
126         en.inputtitle = translate("Enable")
127         en.inputstyle = "apply"
128 else
129         en.title      = translate("Wireless network is enabled")
130         en.inputtitle = translate("Disable")
131         en.inputstyle = "reset"
132 end
133
134
135 local hwtype = wdev:get("type")
136
137 -- NanoFoo
138 local nsantenna = wdev:get("antenna")
139
140 -- Check whether there are client interfaces on the same radio,
141 -- if yes, lock the channel choice as these stations will dicatate the freq
142 local found_sta = nil
143 local _, net
144 if wnet:mode() ~= "sta" then
145         for _, net in ipairs(wdev:get_wifinets()) do
146                 if net:mode() == "sta" then
147                         if not found_sta then
148                                 found_sta = {}
149                                 found_sta.channel = net:channel()
150                                 found_sta.names = {}
151                         end
152                         found_sta.names[#found_sta.names+1] = net:shortname()
153                 end
154         end
155 end
156
157 if found_sta then
158         ch = s:taboption("general", DummyValue, "choice", translate("Channel"))
159         ch.value = translatef("Locked to channel %d used by: %s",
160                 found_sta.channel, table.concat(found_sta.names, ", "))
161 else
162         ch = s:taboption("general", Value, "_mode_freq", '<br />'..translate("Operating frequency"))
163         ch.hwmodes = iw.hwmodelist
164         ch.freqlist = iw.freqlist
165         ch.template = "cbi/wireless_modefreq"
166
167         function ch.cfgvalue(self, section)
168                 return {
169                         m:get(section, "hwmode") or "",
170                         m:get(section, "channel") or "auto",
171                         m:get(section, "htmode") or ""
172                 }
173         end
174
175         function ch.formvalue(self, section)
176                 return {
177                         m:formvalue(self:cbid(section) .. ".band") or (iw.hwmodelist.g and "11g" or "11a"),
178                         m:formvalue(self:cbid(section) .. ".channel") or "auto",
179                         m:formvalue(self:cbid(section) .. ".htmode") or ""
180                 }
181         end
182
183         function ch.write(self, section, value)
184                 m:set(section, "hwmode", value[1])
185                 m:set(section, "channel", value[2])
186                 m:set(section, "htmode", value[3])
187         end
188 end
189
190 ------------------- MAC80211 Device ------------------
191
192 if hwtype == "mac80211" then
193         if #tx_power_list > 1 then
194                 tp = s:taboption("general", ListValue,
195                         "txpower", translate("Transmit Power"), "dBm")
196                 tp.rmempty = true
197                 tp.default = tx_power_cur
198                 function tp.cfgvalue(...)
199                         return txpower_current(Value.cfgvalue(...), tx_power_list)
200                 end
201
202                 for _, p in ipairs(tx_power_list) do
203                         tp:value(p.driver_dbm, "%i dBm (%i mW)"
204                                 %{ p.display_dbm, p.display_mw })
205                 end
206         end
207
208         local cl = iw and iw.countrylist
209         if cl and #cl > 0 then
210                 cc = s:taboption("advanced", ListValue, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
211                 cc.default = tostring(iw and iw.country or "00")
212                 for _, c in ipairs(cl) do
213                         cc:value(c.alpha2, "%s - %s" %{ c.alpha2, c.name })
214                 end
215         else
216                 s:taboption("advanced", Value, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
217         end
218
219         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
220                 translate("Distance to farthest network member in meters."))
221
222         -- external antenna profiles
223         local eal = iw and iw.extant
224         if eal and #eal > 0 then
225                 ea = s:taboption("advanced", ListValue, "extant", translate("Antenna Configuration"))
226                 for _, eap in ipairs(eal) do
227                         ea:value(eap.id, "%s (%s)" %{ eap.name, eap.description })
228                         if eap.selected then
229                                 ea.default = eap.id
230                         end
231                 end
232         end
233
234         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
235         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
236 end
237
238
239 ------------------- Madwifi Device ------------------
240
241 if hwtype == "atheros" then
242         tp = s:taboption("general",
243                 (#tx_power_list > 0) and ListValue or Value,
244                 "txpower", translate("Transmit Power"), "dBm")
245
246         tp.rmempty = true
247         tp.default = tx_power_cur
248
249         function tp.cfgvalue(...)
250                 return txpower_current(Value.cfgvalue(...), tx_power_list)
251         end
252
253         for _, p in ipairs(tx_power_list) do
254                 tp:value(p.driver_dbm, "%i dBm (%i mW)"
255                         %{ p.display_dbm, p.display_mw })
256         end
257
258         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
259
260         if not nsantenna then
261                 ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
262                 ant1.widget = "radio"
263                 ant1.orientation = "horizontal"
264                 ant1:depends("diversity", "")
265                 ant1:value("0", translate("auto"))
266                 ant1:value("1", translate("Antenna 1"))
267                 ant1:value("2", translate("Antenna 2"))
268
269                 ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
270                 ant2.widget = "radio"
271                 ant2.orientation = "horizontal"
272                 ant2:depends("diversity", "")
273                 ant2:value("0", translate("auto"))
274                 ant2:value("1", translate("Antenna 1"))
275                 ant2:value("2", translate("Antenna 2"))
276
277         else -- NanoFoo
278                 local ant = s:taboption("advanced", ListValue, "antenna", translate("Transmitter Antenna"))
279                 ant:value("auto")
280                 ant:value("vertical")
281                 ant:value("horizontal")
282                 ant:value("external")
283         end
284
285         s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
286                 translate("Distance to farthest network member in meters."))
287         s:taboption("advanced", Value, "regdomain", translate("Regulatory Domain"))
288         s:taboption("advanced", Value, "country", translate("Country Code"))
289         s:taboption("advanced", Flag, "outdoor", translate("Outdoor Channels"))
290
291         --s:option(Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
292 end
293
294
295
296 ------------------- Broadcom Device ------------------
297
298 if hwtype == "broadcom" then
299         tp = s:taboption("general",
300                 (#tx_power_list > 0) and ListValue or Value,
301                 "txpower", translate("Transmit Power"), "dBm")
302
303         tp.rmempty = true
304         tp.default = tx_power_cur
305
306         function tp.cfgvalue(...)
307                 return txpower_current(Value.cfgvalue(...), tx_power_list)
308         end
309
310         for _, p in ipairs(tx_power_list) do
311                 tp:value(p.driver_dbm, "%i dBm (%i mW)"
312                         %{ p.display_dbm, p.display_mw })
313         end
314
315         ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
316         ant1.widget = "radio"
317         ant1:depends("diversity", "")
318         ant1:value("3", translate("auto"))
319         ant1:value("0", translate("Antenna 1"))
320         ant1:value("1", translate("Antenna 2"))
321
322         ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
323         ant2.widget = "radio"
324         ant2:depends("diversity", "")
325         ant2:value("3", translate("auto"))
326         ant2:value("0", translate("Antenna 1"))
327         ant2:value("1", translate("Antenna 2"))
328
329         s:taboption("advanced", Flag, "frameburst", translate("Frame Bursting"))
330
331         s:taboption("advanced", Value, "distance", translate("Distance Optimization"))
332         --s:option(Value, "slottime", translate("Slot time"))
333
334         s:taboption("advanced", Value, "country", translate("Country Code"))
335         s:taboption("advanced", Value, "maxassoc", translate("Connection Limit"))
336 end
337
338
339 --------------------- HostAP Device ---------------------
340
341 if hwtype == "prism2" then
342         s:taboption("advanced", Value, "txpower", translate("Transmit Power"), "att units").rmempty = true
343
344         s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
345
346         s:taboption("advanced", Value, "txantenna", translate("Transmitter Antenna"))
347         s:taboption("advanced", Value, "rxantenna", translate("Receiver Antenna"))
348 end
349
350
351 ----------------------- Interface -----------------------
352
353 s = m:section(NamedSection, wnet.sid, "wifi-iface", translate("Interface Configuration"))
354 ifsection = s
355 s.addremove = false
356 s.anonymous = true
357 s.defaults.device = wdev:name()
358
359 s:tab("general", translate("General Setup"))
360 s:tab("encryption", translate("Wireless Security"))
361 s:tab("macfilter", translate("MAC-Filter"))
362 s:tab("advanced", translate("Advanced Settings"))
363
364 s:taboption("general", Value, "ssid", translate("<abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
365
366 mode = s:taboption("general", ListValue, "mode", translate("Mode"))
367 mode.override_values = true
368 mode:value("ap", translate("Access Point"))
369 mode:value("sta", translate("Client"))
370 mode:value("adhoc", translate("Ad-Hoc"))
371
372 bssid = s:taboption("general", Value, "bssid", translate("<abbr title=\"Basic Service Set Identifier\">BSSID</abbr>"))
373
374 network = s:taboption("general", Value, "network", translate("Network"),
375         translate("Choose the network(s) you want to attach to this wireless interface or " ..
376                 "fill out the <em>create</em> field to define a new network."))
377
378 network.rmempty = true
379 network.template = "cbi/network_netlist"
380 network.widget = "checkbox"
381 network.novirtual = true
382
383 function network.write(self, section, value)
384         local i = nw:get_interface(section)
385         if i then
386                 if value == '-' then
387                         value = m:formvalue(self:cbid(section) .. ".newnet")
388                         if value and #value > 0 then
389                                 local n = nw:add_network(value, {proto="none"})
390                                 if n then n:add_interface(i) end
391                         else
392                                 local n = i:get_network()
393                                 if n then n:del_interface(i) end
394                         end
395                 else
396                         local v
397                         for _, v in ipairs(i:get_networks()) do
398                                 v:del_interface(i)
399                         end
400                         for v in ut.imatch(value) do
401                                 local n = nw:get_network(v)
402                                 if n then
403                                         if not n:is_empty() then
404                                                 n:set("type", "bridge")
405                                         end
406                                         n:add_interface(i)
407                                 end
408                         end
409                 end
410         end
411 end
412
413 -------------------- MAC80211 Interface ----------------------
414
415 if hwtype == "mac80211" then
416         if fs.access("/usr/sbin/iw") then
417                 mode:value("mesh", "802.11s")
418         end
419
420         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
421         mode:value("monitor", translate("Monitor"))
422         bssid:depends({mode="adhoc"})
423         bssid:depends({mode="sta"})
424         bssid:depends({mode="sta-wds"})
425
426         mp = s:taboption("macfilter", ListValue, "macfilter", translate("MAC-Address Filter"))
427         mp:depends({mode="ap"})
428         mp:depends({mode="ap-wds"})
429         mp:value("", translate("disable"))
430         mp:value("allow", translate("Allow listed only"))
431         mp:value("deny", translate("Allow all except listed"))
432
433         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
434         ml.datatype = "macaddr"
435         ml:depends({macfilter="allow"})
436         ml:depends({macfilter="deny"})
437         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
438
439         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
440         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
441
442         function mode.write(self, section, value)
443                 if value == "ap-wds" then
444                         ListValue.write(self, section, "ap")
445                         m.uci:set("wireless", section, "wds", 1)
446                 elseif value == "sta-wds" then
447                         ListValue.write(self, section, "sta")
448                         m.uci:set("wireless", section, "wds", 1)
449                 else
450                         ListValue.write(self, section, value)
451                         m.uci:delete("wireless", section, "wds")
452                 end
453         end
454
455         function mode.cfgvalue(self, section)
456                 local mode = ListValue.cfgvalue(self, section)
457                 local wds  = m.uci:get("wireless", section, "wds") == "1"
458
459                 if mode == "ap" and wds then
460                         return "ap-wds"
461                 elseif mode == "sta" and wds then
462                         return "sta-wds"
463                 else
464                         return mode
465                 end
466         end
467
468         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
469         hidden:depends({mode="ap"})
470         hidden:depends({mode="ap-wds"})
471
472         wmm = s:taboption("general", Flag, "wmm", translate("WMM Mode"))
473         wmm:depends({mode="ap"})
474         wmm:depends({mode="ap-wds"})
475         wmm.default = wmm.enabled
476 end
477
478
479
480 -------------------- Madwifi Interface ----------------------
481
482 if hwtype == "atheros" then
483         mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
484         mode:value("monitor", translate("Monitor"))
485         mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
486         mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
487         mode:value("wds", translate("Static WDS"))
488
489         function mode.write(self, section, value)
490                 if value == "ap-wds" then
491                         ListValue.write(self, section, "ap")
492                         m.uci:set("wireless", section, "wds", 1)
493                 elseif value == "sta-wds" then
494                         ListValue.write(self, section, "sta")
495                         m.uci:set("wireless", section, "wds", 1)
496                 else
497                         ListValue.write(self, section, value)
498                         m.uci:delete("wireless", section, "wds")
499                 end
500         end
501
502         function mode.cfgvalue(self, section)
503                 local mode = ListValue.cfgvalue(self, section)
504                 local wds  = m.uci:get("wireless", section, "wds") == "1"
505
506                 if mode == "ap" and wds then
507                         return "ap-wds"
508                 elseif mode == "sta" and wds then
509                         return "sta-wds"
510                 else
511                         return mode
512                 end
513         end
514
515         bssid:depends({mode="adhoc"})
516         bssid:depends({mode="ahdemo"})
517         bssid:depends({mode="wds"})
518
519         wdssep = s:taboption("advanced", Flag, "wdssep", translate("Separate WDS"))
520         wdssep:depends({mode="ap-wds"})
521
522         s:taboption("advanced", Flag, "doth", "802.11h")
523         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
524         hidden:depends({mode="ap"})
525         hidden:depends({mode="adhoc"})
526         hidden:depends({mode="ap-wds"})
527         hidden:depends({mode="sta-wds"})
528         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
529          translate("Prevents client-to-client communication"))
530         isolate:depends({mode="ap"})
531         s:taboption("advanced", Flag, "bgscan", translate("Background Scan"))
532
533         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
534         mp:value("", translate("disable"))
535         mp:value("allow", translate("Allow listed only"))
536         mp:value("deny", translate("Allow all except listed"))
537
538         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
539         ml.datatype = "macaddr"
540         ml:depends({macpolicy="allow"})
541         ml:depends({macpolicy="deny"})
542         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
543
544         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
545         s:taboption("advanced", Value, "mcast_rate", translate("Multicast Rate"))
546         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
547         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
548         s:taboption("advanced", Value, "minrate", translate("Minimum Rate"))
549         s:taboption("advanced", Value, "maxrate", translate("Maximum Rate"))
550         s:taboption("advanced", Flag, "compression", translate("Compression"))
551
552         s:taboption("advanced", Flag, "bursting", translate("Frame Bursting"))
553         s:taboption("advanced", Flag, "turbo", translate("Turbo Mode"))
554         s:taboption("advanced", Flag, "ff", translate("Fast Frames"))
555
556         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
557         s:taboption("advanced", Flag, "xr", translate("XR Support"))
558         s:taboption("advanced", Flag, "ar", translate("AR Support"))
559
560         local swm = s:taboption("advanced", Flag, "sw_merge", translate("Disable HW-Beacon timer"))
561         swm:depends({mode="adhoc"})
562
563         local nos = s:taboption("advanced", Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
564         nos:depends({mode="sta"})
565         nos:depends({mode="sta-wds"})
566
567         local probereq = s:taboption("advanced", Flag, "probereq", translate("Do not send probe responses"))
568         probereq.enabled  = "0"
569         probereq.disabled = "1"
570 end
571
572
573 -------------------- Broadcom Interface ----------------------
574
575 if hwtype == "broadcom" then
576         mode:value("wds", translate("WDS"))
577         mode:value("monitor", translate("Monitor"))
578
579         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
580         hidden:depends({mode="ap"})
581         hidden:depends({mode="adhoc"})
582         hidden:depends({mode="wds"})
583
584         isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
585          translate("Prevents client-to-client communication"))
586         isolate:depends({mode="ap"})
587
588         s:taboption("advanced", Flag, "doth", "802.11h")
589         s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
590
591         bssid:depends({mode="wds"})
592         bssid:depends({mode="adhoc"})
593 end
594
595
596 ----------------------- HostAP Interface ---------------------
597
598 if hwtype == "prism2" then
599         mode:value("wds", translate("WDS"))
600         mode:value("monitor", translate("Monitor"))
601
602         hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
603         hidden:depends({mode="ap"})
604         hidden:depends({mode="adhoc"})
605         hidden:depends({mode="wds"})
606
607         bssid:depends({mode="sta"})
608
609         mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
610         mp:value("", translate("disable"))
611         mp:value("allow", translate("Allow listed only"))
612         mp:value("deny", translate("Allow all except listed"))
613         ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
614         ml:depends({macpolicy="allow"})
615         ml:depends({macpolicy="deny"})
616         nt.mac_hints(function(mac, name) ml:value(mac, "%s (%s)" %{ mac, name }) end)
617
618         s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
619         s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
620         s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
621 end
622
623
624 ------------------- WiFI-Encryption -------------------
625
626 encr = s:taboption("encryption", ListValue, "encryption", translate("Encryption"))
627 encr.override_values = true
628 encr.override_depends = true
629 encr:depends({mode="ap"})
630 encr:depends({mode="sta"})
631 encr:depends({mode="adhoc"})
632 encr:depends({mode="ahdemo"})
633 encr:depends({mode="ap-wds"})
634 encr:depends({mode="sta-wds"})
635 encr:depends({mode="mesh"})
636
637 cipher = s:taboption("encryption", ListValue, "cipher", translate("Cipher"))
638 cipher:depends({encryption="wpa"})
639 cipher:depends({encryption="wpa2"})
640 cipher:depends({encryption="psk"})
641 cipher:depends({encryption="psk2"})
642 cipher:depends({encryption="wpa-mixed"})
643 cipher:depends({encryption="psk-mixed"})
644 cipher:value("auto", translate("auto"))
645 cipher:value("ccmp", translate("Force CCMP (AES)"))
646 cipher:value("tkip", translate("Force TKIP"))
647 cipher:value("tkip+ccmp", translate("Force TKIP and CCMP (AES)"))
648
649 function encr.cfgvalue(self, section)
650         local v = tostring(ListValue.cfgvalue(self, section))
651         if v == "wep" then
652                 return "wep-open"
653         elseif v and v:match("%+") then
654                 return (v:gsub("%+.+$", ""))
655         end
656         return v
657 end
658
659 function encr.write(self, section, value)
660         local e = tostring(encr:formvalue(section))
661         local c = tostring(cipher:formvalue(section))
662         if value == "wpa" or value == "wpa2"  then
663                 self.map.uci:delete("wireless", section, "key")
664         end
665         if e and (c == "tkip" or c == "ccmp" or c == "tkip+ccmp") then
666                 e = e .. "+" .. c
667         end
668         self.map:set(section, "encryption", e)
669 end
670
671 function cipher.cfgvalue(self, section)
672         local v = tostring(ListValue.cfgvalue(encr, section))
673         if v and v:match("%+") then
674                 v = v:gsub("^[^%+]+%+", "")
675                 if v == "aes" then v = "ccmp"
676                 elseif v == "tkip+aes" then v = "tkip+ccmp"
677                 elseif v == "aes+tkip" then v = "tkip+ccmp"
678                 elseif v == "ccmp+tkip" then v = "tkip+ccmp"
679                 end
680         end
681         return v
682 end
683
684 function cipher.write(self, section)
685         return encr:write(section)
686 end
687
688
689 encr:value("none", "No Encryption")
690 encr:value("wep-open",   translate("WEP Open System"), {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"}, {mode="adhoc"}, {mode="ahdemo"}, {mode="wds"})
691 encr:value("wep-shared", translate("WEP Shared Key"),  {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"}, {mode="adhoc"}, {mode="ahdemo"}, {mode="wds"})
692
693 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
694         local supplicant = fs.access("/usr/sbin/wpa_supplicant")
695         local hostapd = fs.access("/usr/sbin/hostapd")
696
697         -- Probe EAP support
698         local has_ap_eap  = (os.execute("hostapd -veap >/dev/null 2>/dev/null") == 0)
699         local has_sta_eap = (os.execute("wpa_supplicant -veap >/dev/null 2>/dev/null") == 0)
700
701         if hostapd and supplicant then
702                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
703                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
704                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
705                 if has_ap_eap and has_sta_eap then
706                         encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
707                         encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
708                 end
709         elseif hostapd and not supplicant then
710                 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="ap-wds"})
711                 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="ap-wds"})
712                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="ap-wds"})
713                 if has_ap_eap then
714                         encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="ap-wds"})
715                         encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="ap-wds"})
716                 end
717                 encr.description = translate(
718                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
719                         "and ad-hoc mode) to be installed."
720                 )
721         elseif not hostapd and supplicant then
722                 encr:value("psk", "WPA-PSK", {mode="sta"}, {mode="sta-wds"})
723                 encr:value("psk2", "WPA2-PSK", {mode="sta"}, {mode="sta-wds"})
724                 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="sta"}, {mode="sta-wds"})
725                 if has_sta_eap then
726                         encr:value("wpa", "WPA-EAP", {mode="sta"}, {mode="sta-wds"})
727                         encr:value("wpa2", "WPA2-EAP", {mode="sta"}, {mode="sta-wds"})
728                 end
729                 encr.description = translate(
730                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
731                         "and ad-hoc mode) to be installed."
732                 )
733         else
734                 encr.description = translate(
735                         "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
736                         "and ad-hoc mode) to be installed."
737                 )
738         end
739 elseif hwtype == "broadcom" then
740         encr:value("psk", "WPA-PSK")
741         encr:value("psk2", "WPA2-PSK")
742         encr:value("psk+psk2", "WPA-PSK/WPA2-PSK Mixed Mode")
743 end
744
745 auth_server = s:taboption("encryption", Value, "auth_server", translate("Radius-Authentication-Server"))
746 auth_server:depends({mode="ap", encryption="wpa"})
747 auth_server:depends({mode="ap", encryption="wpa2"})
748 auth_server:depends({mode="ap-wds", encryption="wpa"})
749 auth_server:depends({mode="ap-wds", encryption="wpa2"})
750 auth_server.rmempty = true
751 auth_server.datatype = "host"
752
753 auth_port = s:taboption("encryption", Value, "auth_port", translate("Radius-Authentication-Port"), translatef("Default %d", 1812))
754 auth_port:depends({mode="ap", encryption="wpa"})
755 auth_port:depends({mode="ap", encryption="wpa2"})
756 auth_port:depends({mode="ap-wds", encryption="wpa"})
757 auth_port:depends({mode="ap-wds", encryption="wpa2"})
758 auth_port.rmempty = true
759 auth_port.datatype = "port"
760
761 auth_secret = s:taboption("encryption", Value, "auth_secret", translate("Radius-Authentication-Secret"))
762 auth_secret:depends({mode="ap", encryption="wpa"})
763 auth_secret:depends({mode="ap", encryption="wpa2"})
764 auth_secret:depends({mode="ap-wds", encryption="wpa"})
765 auth_secret:depends({mode="ap-wds", encryption="wpa2"})
766 auth_secret.rmempty = true
767 auth_secret.password = true
768
769 acct_server = s:taboption("encryption", Value, "acct_server", translate("Radius-Accounting-Server"))
770 acct_server:depends({mode="ap", encryption="wpa"})
771 acct_server:depends({mode="ap", encryption="wpa2"})
772 acct_server:depends({mode="ap-wds", encryption="wpa"})
773 acct_server:depends({mode="ap-wds", encryption="wpa2"})
774 acct_server.rmempty = true
775 acct_server.datatype = "host"
776
777 acct_port = s:taboption("encryption", Value, "acct_port", translate("Radius-Accounting-Port"), translatef("Default %d", 1813))
778 acct_port:depends({mode="ap", encryption="wpa"})
779 acct_port:depends({mode="ap", encryption="wpa2"})
780 acct_port:depends({mode="ap-wds", encryption="wpa"})
781 acct_port:depends({mode="ap-wds", encryption="wpa2"})
782 acct_port.rmempty = true
783 acct_port.datatype = "port"
784
785 acct_secret = s:taboption("encryption", Value, "acct_secret", translate("Radius-Accounting-Secret"))
786 acct_secret:depends({mode="ap", encryption="wpa"})
787 acct_secret:depends({mode="ap", encryption="wpa2"})
788 acct_secret:depends({mode="ap-wds", encryption="wpa"})
789 acct_secret:depends({mode="ap-wds", encryption="wpa2"})
790 acct_secret.rmempty = true
791 acct_secret.password = true
792
793 wpakey = s:taboption("encryption", Value, "_wpa_key", translate("Key"))
794 wpakey:depends("encryption", "psk")
795 wpakey:depends("encryption", "psk2")
796 wpakey:depends("encryption", "psk+psk2")
797 wpakey:depends("encryption", "psk-mixed")
798 wpakey.datatype = "wpakey"
799 wpakey.rmempty = true
800 wpakey.password = true
801
802 wpakey.cfgvalue = function(self, section, value)
803         local key = m.uci:get("wireless", section, "key")
804         if key == "1" or key == "2" or key == "3" or key == "4" then
805                 return nil
806         end
807         return key
808 end
809
810 wpakey.write = function(self, section, value)
811         self.map.uci:set("wireless", section, "key", value)
812         self.map.uci:delete("wireless", section, "key1")
813 end
814
815
816 wepslot = s:taboption("encryption", ListValue, "_wep_key", translate("Used Key Slot"))
817 wepslot:depends("encryption", "wep-open")
818 wepslot:depends("encryption", "wep-shared")
819 wepslot:value("1", translatef("Key #%d", 1))
820 wepslot:value("2", translatef("Key #%d", 2))
821 wepslot:value("3", translatef("Key #%d", 3))
822 wepslot:value("4", translatef("Key #%d", 4))
823
824 wepslot.cfgvalue = function(self, section)
825         local slot = tonumber(m.uci:get("wireless", section, "key"))
826         if not slot or slot < 1 or slot > 4 then
827                 return 1
828         end
829         return slot
830 end
831
832 wepslot.write = function(self, section, value)
833         self.map.uci:set("wireless", section, "key", value)
834 end
835
836 local slot
837 for slot=1,4 do
838         wepkey = s:taboption("encryption", Value, "key" .. slot, translatef("Key #%d", slot))
839         wepkey:depends("encryption", "wep-open")
840         wepkey:depends("encryption", "wep-shared")
841         wepkey.datatype = "wepkey"
842         wepkey.rmempty = true
843         wepkey.password = true
844
845         function wepkey.write(self, section, value)
846                 if value and (#value == 5 or #value == 13) then
847                         value = "s:" .. value
848                 end
849                 return Value.write(self, section, value)
850         end
851 end
852
853
854 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
855         nasid = s:taboption("encryption", Value, "nasid", translate("NAS ID"))
856         nasid:depends({mode="ap", encryption="wpa"})
857         nasid:depends({mode="ap", encryption="wpa2"})
858         nasid:depends({mode="ap-wds", encryption="wpa"})
859         nasid:depends({mode="ap-wds", encryption="wpa2"})
860         nasid.rmempty = true
861
862         eaptype = s:taboption("encryption", ListValue, "eap_type", translate("EAP-Method"))
863         eaptype:value("tls",  "TLS")
864         eaptype:value("ttls", "TTLS")
865         eaptype:value("peap", "PEAP")
866         eaptype:depends({mode="sta", encryption="wpa"})
867         eaptype:depends({mode="sta", encryption="wpa2"})
868         eaptype:depends({mode="sta-wds", encryption="wpa"})
869         eaptype:depends({mode="sta-wds", encryption="wpa2"})
870
871         cacert = s:taboption("encryption", FileUpload, "ca_cert", translate("Path to CA-Certificate"))
872         cacert:depends({mode="sta", encryption="wpa"})
873         cacert:depends({mode="sta", encryption="wpa2"})
874         cacert:depends({mode="sta-wds", encryption="wpa"})
875         cacert:depends({mode="sta-wds", encryption="wpa2"})
876
877         clientcert = s:taboption("encryption", FileUpload, "client_cert", translate("Path to Client-Certificate"))
878         clientcert:depends({mode="sta", encryption="wpa"})
879         clientcert:depends({mode="sta", encryption="wpa2"})
880         clientcert:depends({mode="sta-wds", encryption="wpa"})
881         clientcert:depends({mode="sta-wds", encryption="wpa2"})
882
883         privkey = s:taboption("encryption", FileUpload, "priv_key", translate("Path to Private Key"))
884         privkey:depends({mode="sta", eap_type="tls", encryption="wpa2"})
885         privkey:depends({mode="sta", eap_type="tls", encryption="wpa"})
886         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
887         privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
888
889         privkeypwd = s:taboption("encryption", Value, "priv_key_pwd", translate("Password of Private Key"))
890         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa2"})
891         privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa"})
892         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
893         privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
894
895
896         auth = s:taboption("encryption", Value, "auth", translate("Authentication"))
897         auth:value("PAP")
898         auth:value("CHAP")
899         auth:value("MSCHAP")
900         auth:value("MSCHAPV2")
901         auth:depends({mode="sta", eap_type="peap", encryption="wpa2"})
902         auth:depends({mode="sta", eap_type="peap", encryption="wpa"})
903         auth:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
904         auth:depends({mode="sta", eap_type="ttls", encryption="wpa"})
905         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
906         auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
907         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
908         auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
909
910
911         identity = s:taboption("encryption", Value, "identity", translate("Identity"))
912         identity:depends({mode="sta", eap_type="peap", encryption="wpa2"})
913         identity:depends({mode="sta", eap_type="peap", encryption="wpa"})
914         identity:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
915         identity:depends({mode="sta", eap_type="ttls", encryption="wpa"})
916         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
917         identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
918         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
919         identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
920
921         password = s:taboption("encryption", Value, "password", translate("Password"))
922         password:depends({mode="sta", eap_type="peap", encryption="wpa2"})
923         password:depends({mode="sta", eap_type="peap", encryption="wpa"})
924         password:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
925         password:depends({mode="sta", eap_type="ttls", encryption="wpa"})
926         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
927         password:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
928         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
929         password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
930 end
931
932 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
933         local wpasupplicant = fs.access("/usr/sbin/wpa_supplicant")
934         local hostcli = fs.access("/usr/sbin/hostapd_cli")
935         if hostcli and wpasupplicant then
936                 wps = s:taboption("encryption", Flag, "wps_pushbutton", translate("Enable WPS pushbutton, requires WPA(2)-PSK"))
937                 wps.enabled = "1"
938                 wps.disabled = "0"
939                 wps.rmempty = false
940                 wps:depends("encryption", "psk")
941                 wps:depends("encryption", "psk2")
942                 wps:depends("encryption", "psk-mixed")
943         end
944 end
945
946 return m