Wifibox 0.10 — An Environment for Using WiFi Drivers on Linux in FreeBSD

The Wifibox 0.10 project release is aimed at solving the problem of using wireless adapters in FreeBSD for which the necessary drivers are not available. The problematic adapters for FreeBSD are supported by running a guest system with Linux, in which the native Linux wireless device drivers are loaded.

The installation of the guest system with drivers is automated, and all necessary components are packaged as a ready-to-use wifibox package, which is launched at boot with the included rc-service. It also correctly handles transitions to sleep mode. The environment can potentially be used for any WiFi cards supported by Linux but has primarily been tested on Intel chipsets. It has also been verified to work correctly on systems with Qualcomm Atheros and AMD RZ608 (MediaTek MT7921K) wireless chipsets.

The guest system is launched using the Bhyve hypervisor, which organizes access to the wireless card. A system with support for hardware virtualization (AMD-Vi or Intel VT-d) is required. The guest system is based on the Alpine Linux distribution, built on the Musl system library and the BusyBox utility set. The image size on disk is approximately 30MB and consumes about 90MB of RAM.

To connect to the wireless network, the wpa_supplicant package is used, with configuration files synchronized with the settings from the main FreeBSD environment. The created wpa_supplicant controlling Unix socket is passed into the host environment, allowing the use of standard FreeBSD utilities to connect to and work with the wireless network, including utilities like wpa_cli and wpa_gui (net/wpa_supplicant_gui).

In the new release, the mechanism for passing WPA into the main environment has been reworked, enabling compatibility with both wpa_supplicant and hostapd. The memory required for the guest system has been reduced. Support for FreeBSD 13.0-RELEASE has been discontinued.

Additionally, it is worth noting the work on improving the FreeBSD drivers offered for wireless cards based on Intel and Realtek chips. With the support of the FreeBSD Foundation, the development of the new iwlwifi driver, included in FreeBSD 13.1, continues. The driver is based on the Linux driver and code from the Linux net80211 subsystem, supports the 802.11ac standard, and can be used with new Intel wireless chips. The driver loads automatically during boot when the required wireless card is detected. The operation of the components of the Linux wireless stack is supported through the LinuxKPI layer. Previously, a similar driver, iwm, was ported to FreeBSD.

At the same time, the development of the rtw88 and rtw89 drivers for Realtek RTW88 and RTW89 wireless chips began, which are also being developed by transferring the respective drivers from Linux and operate through the LinuxKPI layer. The rtw88 driver is already ready for initial testing, while the rtw89 driver is still under development.

Additionally, details and a ready exploit related to the vulnerability (CVE-2022-23088) in the FreeBSD wireless stack published, which was fixed in the April update. This vulnerability allows executing arbitrary code at the kernel level by sending specially crafted frames while a client is in network scan mode (prior to binding to an SSID). The issue is caused by a buffer overflow in the ieee80211_parse_beacon() function when parsing beacon frames sent by the access point. The overflow was made possible due to the lack of validation of the actual size of the data against the size specified in the header field. This issue appears in FreeBSD versions built since 2009.

Wifibox 0.10 - an environment for using Linux WiFi drivers in FreeBSD.

Among the recent changes in FreeBSD unrelated to the wireless stack: boot time optimization was carried out, which was reduced from 10 to 8 seconds on the test system; a GEOM module gunion was implemented to offload changes made over a read-only disk to another disk; cryptographic primitives XChaCha20-Poly1305 AEAD and curve25519 were prepared for the kernel's crypto API, which are necessary for the driver. VPN WireGuard.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster