]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: support client probe
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
79c97e97 49/* internal helper: get rdev and dev */
463d0183 50static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 51 struct cfg80211_registered_device **rdev,
55682965
JB
52 struct net_device **dev)
53{
463d0183 54 struct nlattr **attrs = info->attrs;
55682965
JB
55 int ifindex;
56
bba95fef 57 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
58 return -EINVAL;
59
bba95fef 60 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 61 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
62 if (!*dev)
63 return -ENODEV;
64
463d0183 65 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 66 if (IS_ERR(*rdev)) {
55682965 67 dev_put(*dev);
79c97e97 68 return PTR_ERR(*rdev);
55682965
JB
69 }
70
71 return 0;
72}
73
74/* policy for the attributes */
b54452b0 75static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
76 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
77 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 78 .len = 20-1 },
31888487 79 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 80 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 81 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
82 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
84 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
85 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 86 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
87
88 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
90 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
91
92 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 93 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 94
b9454e83 95 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
96 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
97 .len = WLAN_MAX_KEY_LEN },
98 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
99 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
100 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 101 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 102 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
103
104 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
105 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
106 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
107 .len = IEEE80211_MAX_DATA_LEN },
108 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
109 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
110 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
111 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
112 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
113 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
114 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 115 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 116 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 117 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
118 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
119 .len = IEEE80211_MAX_MESH_ID_LEN },
120 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 121
b2e1b302
LR
122 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
123 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
124
9f1ba906
JM
125 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
127 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
128 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
129 .len = NL80211_MAX_SUPP_RATES },
50b12f59 130 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 131
24bdd9f4 132 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 133 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 134
6c739419 135 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
136
137 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
138 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
140 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
141 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
142
143 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
144 .len = IEEE80211_MAX_SSID_LEN },
145 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
146 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 147 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 148 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 149 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
150 [NL80211_ATTR_STA_FLAGS2] = {
151 .len = sizeof(struct nl80211_sta_flag_update),
152 },
3f77316c 153 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
154 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
155 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
156 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
157 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
158 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 159 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 160 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
161 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
162 .len = WLAN_PMKID_LEN },
9588bbd5
JM
163 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
164 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 165 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
166 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
167 .len = IEEE80211_MAX_DATA_LEN },
168 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 169 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 170 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 171 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 172 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
173 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
174 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 175 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
176 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
177 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 178 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 179 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 180 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 181 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 182 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 183 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 184 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 185 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 186 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
187 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
188 .len = IEEE80211_MAX_DATA_LEN },
189 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
190 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 191 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 192 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 193 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
194 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
197 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
198 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
55682965
JB
199};
200
e31b8213 201/* policy for the key attributes */
b54452b0 202static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 203 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
204 [NL80211_KEY_IDX] = { .type = NLA_U8 },
205 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 206 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
207 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
208 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 209 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
210 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
211};
212
213/* policy for the key default flags */
214static const struct nla_policy
215nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
216 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
217 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
218};
219
ff1b6e69
JB
220/* policy for WoWLAN attributes */
221static const struct nla_policy
222nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
223 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
224 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
225 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
226 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
227 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
228 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
229 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
230 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
231};
232
e5497d76
JB
233/* policy for GTK rekey offload attributes */
234static const struct nla_policy
235nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
236 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
237 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
238 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
239};
240
a1f1c21c
LC
241static const struct nla_policy
242nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
243 [NL80211_ATTR_SCHED_SCAN_MATCH_SSID] = { .type = NLA_BINARY,
244 .len = IEEE80211_MAX_SSID_LEN },
245};
246
a043897a
HS
247/* ifidx get helper */
248static int nl80211_get_ifidx(struct netlink_callback *cb)
249{
250 int res;
251
252 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
253 nl80211_fam.attrbuf, nl80211_fam.maxattr,
254 nl80211_policy);
255 if (res)
256 return res;
257
258 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
259 return -EINVAL;
260
261 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
262 if (!res)
263 return -EINVAL;
264 return res;
265}
266
67748893
JB
267static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
268 struct netlink_callback *cb,
269 struct cfg80211_registered_device **rdev,
270 struct net_device **dev)
271{
272 int ifidx = cb->args[0];
273 int err;
274
275 if (!ifidx)
276 ifidx = nl80211_get_ifidx(cb);
277 if (ifidx < 0)
278 return ifidx;
279
280 cb->args[0] = ifidx;
281
282 rtnl_lock();
283
284 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
285 if (!*dev) {
286 err = -ENODEV;
287 goto out_rtnl;
288 }
289
290 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
291 if (IS_ERR(*rdev)) {
292 err = PTR_ERR(*rdev);
67748893
JB
293 goto out_rtnl;
294 }
295
296 return 0;
297 out_rtnl:
298 rtnl_unlock();
299 return err;
300}
301
302static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
303{
304 cfg80211_unlock_rdev(rdev);
305 rtnl_unlock();
306}
307
f4a11bb0
JB
308/* IE validation */
309static bool is_valid_ie_attr(const struct nlattr *attr)
310{
311 const u8 *pos;
312 int len;
313
314 if (!attr)
315 return true;
316
317 pos = nla_data(attr);
318 len = nla_len(attr);
319
320 while (len) {
321 u8 elemlen;
322
323 if (len < 2)
324 return false;
325 len -= 2;
326
327 elemlen = pos[1];
328 if (elemlen > len)
329 return false;
330
331 len -= elemlen;
332 pos += 2 + elemlen;
333 }
334
335 return true;
336}
337
55682965
JB
338/* message building helper */
339static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
340 int flags, u8 cmd)
341{
342 /* since there is no private header just add the generic one */
343 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
344}
345
5dab3b8a
LR
346static int nl80211_msg_put_channel(struct sk_buff *msg,
347 struct ieee80211_channel *chan)
348{
349 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
350 chan->center_freq);
351
352 if (chan->flags & IEEE80211_CHAN_DISABLED)
353 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
354 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
355 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
356 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
357 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
358 if (chan->flags & IEEE80211_CHAN_RADAR)
359 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
360
361 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
362 DBM_TO_MBM(chan->max_power));
363
364 return 0;
365
366 nla_put_failure:
367 return -ENOBUFS;
368}
369
55682965
JB
370/* netlink command implementations */
371
b9454e83
JB
372struct key_parse {
373 struct key_params p;
374 int idx;
e31b8213 375 int type;
b9454e83 376 bool def, defmgmt;
dbd2fd65 377 bool def_uni, def_multi;
b9454e83
JB
378};
379
380static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
381{
382 struct nlattr *tb[NL80211_KEY_MAX + 1];
383 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
384 nl80211_key_policy);
385 if (err)
386 return err;
387
388 k->def = !!tb[NL80211_KEY_DEFAULT];
389 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
390
dbd2fd65
JB
391 if (k->def) {
392 k->def_uni = true;
393 k->def_multi = true;
394 }
395 if (k->defmgmt)
396 k->def_multi = true;
397
b9454e83
JB
398 if (tb[NL80211_KEY_IDX])
399 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
400
401 if (tb[NL80211_KEY_DATA]) {
402 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
403 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
404 }
405
406 if (tb[NL80211_KEY_SEQ]) {
407 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
408 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
409 }
410
411 if (tb[NL80211_KEY_CIPHER])
412 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
413
e31b8213
JB
414 if (tb[NL80211_KEY_TYPE]) {
415 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
416 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
417 return -EINVAL;
418 }
419
dbd2fd65
JB
420 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
421 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
422 int err = nla_parse_nested(kdt,
423 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
424 tb[NL80211_KEY_DEFAULT_TYPES],
425 nl80211_key_default_policy);
426 if (err)
427 return err;
428
429 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
430 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
431 }
432
b9454e83
JB
433 return 0;
434}
435
436static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
437{
438 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
439 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
440 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
441 }
442
443 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
444 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
445 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
446 }
447
448 if (info->attrs[NL80211_ATTR_KEY_IDX])
449 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
450
451 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
452 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
453
454 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
455 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
456
dbd2fd65
JB
457 if (k->def) {
458 k->def_uni = true;
459 k->def_multi = true;
460 }
461 if (k->defmgmt)
462 k->def_multi = true;
463
e31b8213
JB
464 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
465 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
466 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
467 return -EINVAL;
468 }
469
dbd2fd65
JB
470 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
471 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
472 int err = nla_parse_nested(
473 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
474 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
475 nl80211_key_default_policy);
476 if (err)
477 return err;
478
479 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
480 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
481 }
482
b9454e83
JB
483 return 0;
484}
485
486static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
487{
488 int err;
489
490 memset(k, 0, sizeof(*k));
491 k->idx = -1;
e31b8213 492 k->type = -1;
b9454e83
JB
493
494 if (info->attrs[NL80211_ATTR_KEY])
495 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
496 else
497 err = nl80211_parse_key_old(info, k);
498
499 if (err)
500 return err;
501
502 if (k->def && k->defmgmt)
503 return -EINVAL;
504
dbd2fd65
JB
505 if (k->defmgmt) {
506 if (k->def_uni || !k->def_multi)
507 return -EINVAL;
508 }
509
b9454e83
JB
510 if (k->idx != -1) {
511 if (k->defmgmt) {
512 if (k->idx < 4 || k->idx > 5)
513 return -EINVAL;
514 } else if (k->def) {
515 if (k->idx < 0 || k->idx > 3)
516 return -EINVAL;
517 } else {
518 if (k->idx < 0 || k->idx > 5)
519 return -EINVAL;
520 }
521 }
522
523 return 0;
524}
525
fffd0934
JB
526static struct cfg80211_cached_keys *
527nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
528 struct nlattr *keys)
529{
530 struct key_parse parse;
531 struct nlattr *key;
532 struct cfg80211_cached_keys *result;
533 int rem, err, def = 0;
534
535 result = kzalloc(sizeof(*result), GFP_KERNEL);
536 if (!result)
537 return ERR_PTR(-ENOMEM);
538
539 result->def = -1;
540 result->defmgmt = -1;
541
542 nla_for_each_nested(key, keys, rem) {
543 memset(&parse, 0, sizeof(parse));
544 parse.idx = -1;
545
546 err = nl80211_parse_key_new(key, &parse);
547 if (err)
548 goto error;
549 err = -EINVAL;
550 if (!parse.p.key)
551 goto error;
552 if (parse.idx < 0 || parse.idx > 4)
553 goto error;
554 if (parse.def) {
555 if (def)
556 goto error;
557 def = 1;
558 result->def = parse.idx;
dbd2fd65
JB
559 if (!parse.def_uni || !parse.def_multi)
560 goto error;
fffd0934
JB
561 } else if (parse.defmgmt)
562 goto error;
563 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 564 parse.idx, false, NULL);
fffd0934
JB
565 if (err)
566 goto error;
567 result->params[parse.idx].cipher = parse.p.cipher;
568 result->params[parse.idx].key_len = parse.p.key_len;
569 result->params[parse.idx].key = result->data[parse.idx];
570 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
571 }
572
573 return result;
574 error:
575 kfree(result);
576 return ERR_PTR(err);
577}
578
579static int nl80211_key_allowed(struct wireless_dev *wdev)
580{
581 ASSERT_WDEV_LOCK(wdev);
582
fffd0934
JB
583 switch (wdev->iftype) {
584 case NL80211_IFTYPE_AP:
585 case NL80211_IFTYPE_AP_VLAN:
074ac8df 586 case NL80211_IFTYPE_P2P_GO:
ff973af7 587 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
588 break;
589 case NL80211_IFTYPE_ADHOC:
590 if (!wdev->current_bss)
591 return -ENOLINK;
592 break;
593 case NL80211_IFTYPE_STATION:
074ac8df 594 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
595 if (wdev->sme_state != CFG80211_SME_CONNECTED)
596 return -ENOLINK;
597 break;
598 default:
599 return -EINVAL;
600 }
601
602 return 0;
603}
604
7527a782
JB
605static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
606{
607 struct nlattr *nl_modes = nla_nest_start(msg, attr);
608 int i;
609
610 if (!nl_modes)
611 goto nla_put_failure;
612
613 i = 0;
614 while (ifmodes) {
615 if (ifmodes & 1)
616 NLA_PUT_FLAG(msg, i);
617 ifmodes >>= 1;
618 i++;
619 }
620
621 nla_nest_end(msg, nl_modes);
622 return 0;
623
624nla_put_failure:
625 return -ENOBUFS;
626}
627
628static int nl80211_put_iface_combinations(struct wiphy *wiphy,
629 struct sk_buff *msg)
630{
631 struct nlattr *nl_combis;
632 int i, j;
633
634 nl_combis = nla_nest_start(msg,
635 NL80211_ATTR_INTERFACE_COMBINATIONS);
636 if (!nl_combis)
637 goto nla_put_failure;
638
639 for (i = 0; i < wiphy->n_iface_combinations; i++) {
640 const struct ieee80211_iface_combination *c;
641 struct nlattr *nl_combi, *nl_limits;
642
643 c = &wiphy->iface_combinations[i];
644
645 nl_combi = nla_nest_start(msg, i + 1);
646 if (!nl_combi)
647 goto nla_put_failure;
648
649 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
650 if (!nl_limits)
651 goto nla_put_failure;
652
653 for (j = 0; j < c->n_limits; j++) {
654 struct nlattr *nl_limit;
655
656 nl_limit = nla_nest_start(msg, j + 1);
657 if (!nl_limit)
658 goto nla_put_failure;
659 NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
660 c->limits[j].max);
661 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
662 c->limits[j].types))
663 goto nla_put_failure;
664 nla_nest_end(msg, nl_limit);
665 }
666
667 nla_nest_end(msg, nl_limits);
668
669 if (c->beacon_int_infra_match)
670 NLA_PUT_FLAG(msg,
671 NL80211_IFACE_COMB_STA_AP_BI_MATCH);
672 NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
673 c->num_different_channels);
674 NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
675 c->max_interfaces);
676
677 nla_nest_end(msg, nl_combi);
678 }
679
680 nla_nest_end(msg, nl_combis);
681
682 return 0;
683nla_put_failure:
684 return -ENOBUFS;
685}
686
55682965
JB
687static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
688 struct cfg80211_registered_device *dev)
689{
690 void *hdr;
ee688b00
JB
691 struct nlattr *nl_bands, *nl_band;
692 struct nlattr *nl_freqs, *nl_freq;
693 struct nlattr *nl_rates, *nl_rate;
8fdc621d 694 struct nlattr *nl_cmds;
ee688b00
JB
695 enum ieee80211_band band;
696 struct ieee80211_channel *chan;
697 struct ieee80211_rate *rate;
698 int i;
2e161f78
JB
699 const struct ieee80211_txrx_stypes *mgmt_stypes =
700 dev->wiphy.mgmt_stypes;
55682965
JB
701
702 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
703 if (!hdr)
704 return -1;
705
b5850a7a 706 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 707 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 708
f5ea9120
JB
709 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
710 cfg80211_rdev_list_generation);
711
b9a5f8ca
JM
712 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
713 dev->wiphy.retry_short);
714 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
715 dev->wiphy.retry_long);
716 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
717 dev->wiphy.frag_threshold);
718 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
719 dev->wiphy.rts_threshold);
81077e82
LT
720 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
721 dev->wiphy.coverage_class);
2a519311
JB
722 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
723 dev->wiphy.max_scan_ssids);
93b6aa69
LC
724 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
725 dev->wiphy.max_sched_scan_ssids);
18a83659
JB
726 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
727 dev->wiphy.max_scan_ie_len);
5a865bad
LC
728 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
729 dev->wiphy.max_sched_scan_ie_len);
a1f1c21c
LC
730 NLA_PUT_U8(msg, NL80211_ATTR_MAX_MATCH_SETS,
731 dev->wiphy.max_match_sets);
ee688b00 732
e31b8213
JB
733 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
734 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
735 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
736 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
cedb5412
EP
737 if (dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD)
738 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_AP_UAPSD);
f4b34b55
VN
739 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)
740 NLA_PUT_FLAG(msg, NL80211_ATTR_ROAM_SUPPORT);
109086ce
AN
741 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)
742 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_SUPPORT);
743 if (dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)
744 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP);
f4b34b55 745
25e47c18
JB
746 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
747 sizeof(u32) * dev->wiphy.n_cipher_suites,
748 dev->wiphy.cipher_suites);
749
67fbb16b
SO
750 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
751 dev->wiphy.max_num_pmkids);
752
c0692b8f
JB
753 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
754 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
755
39fd5de4
BR
756 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
757 dev->wiphy.available_antennas_tx);
758 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
759 dev->wiphy.available_antennas_rx);
760
7f531e03
BR
761 if ((dev->wiphy.available_antennas_tx ||
762 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
763 u32 tx_ant = 0, rx_ant = 0;
764 int res;
765 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
766 if (!res) {
767 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
768 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
769 }
770 }
771
7527a782
JB
772 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
773 dev->wiphy.interface_modes))
f59ac048
LR
774 goto nla_put_failure;
775
ee688b00
JB
776 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
777 if (!nl_bands)
778 goto nla_put_failure;
779
780 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
781 if (!dev->wiphy.bands[band])
782 continue;
783
784 nl_band = nla_nest_start(msg, band);
785 if (!nl_band)
786 goto nla_put_failure;
787
d51626df
JB
788 /* add HT info */
789 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
790 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
791 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
792 &dev->wiphy.bands[band]->ht_cap.mcs);
793 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
794 dev->wiphy.bands[band]->ht_cap.cap);
795 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
796 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
797 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
798 dev->wiphy.bands[band]->ht_cap.ampdu_density);
799 }
800
ee688b00
JB
801 /* add frequencies */
802 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
803 if (!nl_freqs)
804 goto nla_put_failure;
805
806 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
807 nl_freq = nla_nest_start(msg, i);
808 if (!nl_freq)
809 goto nla_put_failure;
810
811 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
812
813 if (nl80211_msg_put_channel(msg, chan))
814 goto nla_put_failure;
e2f367f2 815
ee688b00
JB
816 nla_nest_end(msg, nl_freq);
817 }
818
819 nla_nest_end(msg, nl_freqs);
820
821 /* add bitrates */
822 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
823 if (!nl_rates)
824 goto nla_put_failure;
825
826 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
827 nl_rate = nla_nest_start(msg, i);
828 if (!nl_rate)
829 goto nla_put_failure;
830
831 rate = &dev->wiphy.bands[band]->bitrates[i];
832 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
833 rate->bitrate);
834 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
835 NLA_PUT_FLAG(msg,
836 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
837
838 nla_nest_end(msg, nl_rate);
839 }
840
841 nla_nest_end(msg, nl_rates);
842
843 nla_nest_end(msg, nl_band);
844 }
845 nla_nest_end(msg, nl_bands);
846
8fdc621d
JB
847 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
848 if (!nl_cmds)
849 goto nla_put_failure;
850
851 i = 0;
852#define CMD(op, n) \
853 do { \
854 if (dev->ops->op) { \
855 i++; \
856 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
857 } \
858 } while (0)
859
860 CMD(add_virtual_intf, NEW_INTERFACE);
861 CMD(change_virtual_intf, SET_INTERFACE);
862 CMD(add_key, NEW_KEY);
863 CMD(add_beacon, NEW_BEACON);
864 CMD(add_station, NEW_STATION);
865 CMD(add_mpath, NEW_MPATH);
24bdd9f4 866 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 867 CMD(change_bss, SET_BSS);
636a5d36
JM
868 CMD(auth, AUTHENTICATE);
869 CMD(assoc, ASSOCIATE);
870 CMD(deauth, DEAUTHENTICATE);
871 CMD(disassoc, DISASSOCIATE);
04a773ad 872 CMD(join_ibss, JOIN_IBSS);
29cbe68c 873 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
874 CMD(set_pmksa, SET_PMKSA);
875 CMD(del_pmksa, DEL_PMKSA);
876 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 877 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 878 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 879 CMD(mgmt_tx, FRAME);
f7ca38df 880 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 881 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
882 i++;
883 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
884 }
f444de05 885 CMD(set_channel, SET_CHANNEL);
e8347eba 886 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
887 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
888 CMD(tdls_mgmt, TDLS_MGMT);
889 CMD(tdls_oper, TDLS_OPER);
890 }
807f8a8c
LC
891 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
892 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 893 CMD(probe_client, PROBE_CLIENT);
8fdc621d
JB
894
895#undef CMD
b23aa676 896
6829c878 897 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
898 i++;
899 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
900 }
901
6829c878 902 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
903 i++;
904 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
905 }
906
8fdc621d
JB
907 nla_nest_end(msg, nl_cmds);
908
a293911d
JB
909 if (dev->ops->remain_on_channel)
910 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
911 dev->wiphy.max_remain_on_channel_duration);
912
d2da5878 913 if (dev->ops->mgmt_tx_cancel_wait)
f7ca38df
JB
914 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
915
2e161f78
JB
916 if (mgmt_stypes) {
917 u16 stypes;
918 struct nlattr *nl_ftypes, *nl_ifs;
919 enum nl80211_iftype ift;
920
921 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
922 if (!nl_ifs)
923 goto nla_put_failure;
924
925 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
926 nl_ftypes = nla_nest_start(msg, ift);
927 if (!nl_ftypes)
928 goto nla_put_failure;
929 i = 0;
930 stypes = mgmt_stypes[ift].tx;
931 while (stypes) {
932 if (stypes & 1)
933 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
934 (i << 4) | IEEE80211_FTYPE_MGMT);
935 stypes >>= 1;
936 i++;
937 }
938 nla_nest_end(msg, nl_ftypes);
939 }
940
74b70a4e
JB
941 nla_nest_end(msg, nl_ifs);
942
2e161f78
JB
943 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
944 if (!nl_ifs)
945 goto nla_put_failure;
946
947 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
948 nl_ftypes = nla_nest_start(msg, ift);
949 if (!nl_ftypes)
950 goto nla_put_failure;
951 i = 0;
952 stypes = mgmt_stypes[ift].rx;
953 while (stypes) {
954 if (stypes & 1)
955 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
956 (i << 4) | IEEE80211_FTYPE_MGMT);
957 stypes >>= 1;
958 i++;
959 }
960 nla_nest_end(msg, nl_ftypes);
961 }
962 nla_nest_end(msg, nl_ifs);
963 }
964
ff1b6e69
JB
965 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
966 struct nlattr *nl_wowlan;
967
968 nl_wowlan = nla_nest_start(msg,
969 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
970 if (!nl_wowlan)
971 goto nla_put_failure;
972
973 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
974 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
975 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
976 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
977 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
978 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
979 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
980 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
981 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
982 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
983 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
984 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
985 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
986 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
987 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
988 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
989 if (dev->wiphy.wowlan.n_patterns) {
990 struct nl80211_wowlan_pattern_support pat = {
991 .max_patterns = dev->wiphy.wowlan.n_patterns,
992 .min_pattern_len =
993 dev->wiphy.wowlan.pattern_min_len,
994 .max_pattern_len =
995 dev->wiphy.wowlan.pattern_max_len,
996 };
997 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
998 sizeof(pat), &pat);
999 }
1000
1001 nla_nest_end(msg, nl_wowlan);
1002 }
1003
7527a782
JB
1004 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1005 dev->wiphy.software_iftypes))
1006 goto nla_put_failure;
1007
1008 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1009 goto nla_put_failure;
1010
562a7480
JB
1011 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME)
1012 NLA_PUT_U32(msg, NL80211_ATTR_DEVICE_AP_SME,
1013 dev->wiphy.ap_sme_capa);
1014
55682965
JB
1015 return genlmsg_end(msg, hdr);
1016
1017 nla_put_failure:
bc3ed28c
TG
1018 genlmsg_cancel(msg, hdr);
1019 return -EMSGSIZE;
55682965
JB
1020}
1021
1022static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1023{
1024 int idx = 0;
1025 int start = cb->args[0];
1026 struct cfg80211_registered_device *dev;
1027
a1794390 1028 mutex_lock(&cfg80211_mutex);
79c97e97 1029 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1030 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1031 continue;
b4637271 1032 if (++idx <= start)
55682965
JB
1033 continue;
1034 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1035 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1036 dev) < 0) {
1037 idx--;
55682965 1038 break;
b4637271 1039 }
55682965 1040 }
a1794390 1041 mutex_unlock(&cfg80211_mutex);
55682965
JB
1042
1043 cb->args[0] = idx;
1044
1045 return skb->len;
1046}
1047
1048static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1049{
1050 struct sk_buff *msg;
4c476991 1051 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1052
fd2120ca 1053 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1054 if (!msg)
4c476991 1055 return -ENOMEM;
55682965 1056
4c476991
JB
1057 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1058 nlmsg_free(msg);
1059 return -ENOBUFS;
1060 }
55682965 1061
134e6375 1062 return genlmsg_reply(msg, info);
55682965
JB
1063}
1064
31888487
JM
1065static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1066 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1067 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1068 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1069 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1070 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1071};
1072
1073static int parse_txq_params(struct nlattr *tb[],
1074 struct ieee80211_txq_params *txq_params)
1075{
1076 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
1077 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1078 !tb[NL80211_TXQ_ATTR_AIFS])
1079 return -EINVAL;
1080
1081 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
1082 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1083 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1084 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1085 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1086
1087 return 0;
1088}
1089
f444de05
JB
1090static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1091{
1092 /*
1093 * You can only set the channel explicitly for AP, mesh
1094 * and WDS type interfaces; all others have their channel
1095 * managed via their respective "establish a connection"
1096 * command (connect, join, ...)
1097 *
1098 * Monitors are special as they are normally slaved to
1099 * whatever else is going on, so they behave as though
1100 * you tried setting the wiphy channel itself.
1101 */
1102 return !wdev ||
1103 wdev->iftype == NL80211_IFTYPE_AP ||
1104 wdev->iftype == NL80211_IFTYPE_WDS ||
1105 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1106 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1107 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1108}
1109
1110static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1111 struct wireless_dev *wdev,
1112 struct genl_info *info)
1113{
1114 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1115 u32 freq;
1116 int result;
1117
1118 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1119 return -EINVAL;
1120
1121 if (!nl80211_can_set_dev_channel(wdev))
1122 return -EOPNOTSUPP;
1123
1124 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1125 channel_type = nla_get_u32(info->attrs[
1126 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1127 if (channel_type != NL80211_CHAN_NO_HT &&
1128 channel_type != NL80211_CHAN_HT20 &&
1129 channel_type != NL80211_CHAN_HT40PLUS &&
1130 channel_type != NL80211_CHAN_HT40MINUS)
1131 return -EINVAL;
1132 }
1133
1134 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1135
1136 mutex_lock(&rdev->devlist_mtx);
1137 if (wdev) {
1138 wdev_lock(wdev);
1139 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1140 wdev_unlock(wdev);
1141 } else {
1142 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1143 }
1144 mutex_unlock(&rdev->devlist_mtx);
1145
1146 return result;
1147}
1148
1149static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1150{
4c476991
JB
1151 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1152 struct net_device *netdev = info->user_ptr[1];
f444de05 1153
4c476991 1154 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1155}
1156
e8347eba
BJ
1157static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1158{
43b19952
JB
1159 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1160 struct net_device *dev = info->user_ptr[1];
1161 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1162 const u8 *bssid;
e8347eba
BJ
1163
1164 if (!info->attrs[NL80211_ATTR_MAC])
1165 return -EINVAL;
1166
43b19952
JB
1167 if (netif_running(dev))
1168 return -EBUSY;
e8347eba 1169
43b19952
JB
1170 if (!rdev->ops->set_wds_peer)
1171 return -EOPNOTSUPP;
e8347eba 1172
43b19952
JB
1173 if (wdev->iftype != NL80211_IFTYPE_WDS)
1174 return -EOPNOTSUPP;
e8347eba
BJ
1175
1176 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1177 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1178}
1179
1180
55682965
JB
1181static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1182{
1183 struct cfg80211_registered_device *rdev;
f444de05
JB
1184 struct net_device *netdev = NULL;
1185 struct wireless_dev *wdev;
a1e567c8 1186 int result = 0, rem_txq_params = 0;
31888487 1187 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1188 u32 changed;
1189 u8 retry_short = 0, retry_long = 0;
1190 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1191 u8 coverage_class = 0;
55682965 1192
f444de05
JB
1193 /*
1194 * Try to find the wiphy and netdev. Normally this
1195 * function shouldn't need the netdev, but this is
1196 * done for backward compatibility -- previously
1197 * setting the channel was done per wiphy, but now
1198 * it is per netdev. Previous userland like hostapd
1199 * also passed a netdev to set_wiphy, so that it is
1200 * possible to let that go to the right netdev!
1201 */
4bbf4d56
JB
1202 mutex_lock(&cfg80211_mutex);
1203
f444de05
JB
1204 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1205 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1206
1207 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1208 if (netdev && netdev->ieee80211_ptr) {
1209 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1210 mutex_lock(&rdev->mtx);
1211 } else
1212 netdev = NULL;
4bbf4d56
JB
1213 }
1214
f444de05
JB
1215 if (!netdev) {
1216 rdev = __cfg80211_rdev_from_info(info);
1217 if (IS_ERR(rdev)) {
1218 mutex_unlock(&cfg80211_mutex);
4c476991 1219 return PTR_ERR(rdev);
f444de05
JB
1220 }
1221 wdev = NULL;
1222 netdev = NULL;
1223 result = 0;
1224
1225 mutex_lock(&rdev->mtx);
1226 } else if (netif_running(netdev) &&
1227 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1228 wdev = netdev->ieee80211_ptr;
1229 else
1230 wdev = NULL;
1231
1232 /*
1233 * end workaround code, by now the rdev is available
1234 * and locked, and wdev may or may not be NULL.
1235 */
4bbf4d56
JB
1236
1237 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1238 result = cfg80211_dev_rename(
1239 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1240
1241 mutex_unlock(&cfg80211_mutex);
1242
1243 if (result)
1244 goto bad_res;
31888487
JM
1245
1246 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1247 struct ieee80211_txq_params txq_params;
1248 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1249
1250 if (!rdev->ops->set_txq_params) {
1251 result = -EOPNOTSUPP;
1252 goto bad_res;
1253 }
1254
f70f01c2
EP
1255 if (!netdev) {
1256 result = -EINVAL;
1257 goto bad_res;
1258 }
1259
133a3ff2
JB
1260 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1261 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1262 result = -EINVAL;
1263 goto bad_res;
1264 }
1265
31888487
JM
1266 nla_for_each_nested(nl_txq_params,
1267 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1268 rem_txq_params) {
1269 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1270 nla_data(nl_txq_params),
1271 nla_len(nl_txq_params),
1272 txq_params_policy);
1273 result = parse_txq_params(tb, &txq_params);
1274 if (result)
1275 goto bad_res;
1276
1277 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1278 netdev,
31888487
JM
1279 &txq_params);
1280 if (result)
1281 goto bad_res;
1282 }
1283 }
55682965 1284
72bdcf34 1285 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1286 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1287 if (result)
1288 goto bad_res;
1289 }
1290
98d2ff8b
JO
1291 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1292 enum nl80211_tx_power_setting type;
1293 int idx, mbm = 0;
1294
1295 if (!rdev->ops->set_tx_power) {
60ea385f 1296 result = -EOPNOTSUPP;
98d2ff8b
JO
1297 goto bad_res;
1298 }
1299
1300 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1301 type = nla_get_u32(info->attrs[idx]);
1302
1303 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1304 (type != NL80211_TX_POWER_AUTOMATIC)) {
1305 result = -EINVAL;
1306 goto bad_res;
1307 }
1308
1309 if (type != NL80211_TX_POWER_AUTOMATIC) {
1310 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1311 mbm = nla_get_u32(info->attrs[idx]);
1312 }
1313
1314 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1315 if (result)
1316 goto bad_res;
1317 }
1318
afe0cbf8
BR
1319 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1320 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1321 u32 tx_ant, rx_ant;
7f531e03
BR
1322 if ((!rdev->wiphy.available_antennas_tx &&
1323 !rdev->wiphy.available_antennas_rx) ||
1324 !rdev->ops->set_antenna) {
afe0cbf8
BR
1325 result = -EOPNOTSUPP;
1326 goto bad_res;
1327 }
1328
1329 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1330 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1331
a7ffac95 1332 /* reject antenna configurations which don't match the
7f531e03
BR
1333 * available antenna masks, except for the "all" mask */
1334 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1335 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1336 result = -EINVAL;
1337 goto bad_res;
1338 }
1339
7f531e03
BR
1340 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1341 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1342
afe0cbf8
BR
1343 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1344 if (result)
1345 goto bad_res;
1346 }
1347
b9a5f8ca
JM
1348 changed = 0;
1349
1350 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1351 retry_short = nla_get_u8(
1352 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1353 if (retry_short == 0) {
1354 result = -EINVAL;
1355 goto bad_res;
1356 }
1357 changed |= WIPHY_PARAM_RETRY_SHORT;
1358 }
1359
1360 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1361 retry_long = nla_get_u8(
1362 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1363 if (retry_long == 0) {
1364 result = -EINVAL;
1365 goto bad_res;
1366 }
1367 changed |= WIPHY_PARAM_RETRY_LONG;
1368 }
1369
1370 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1371 frag_threshold = nla_get_u32(
1372 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1373 if (frag_threshold < 256) {
1374 result = -EINVAL;
1375 goto bad_res;
1376 }
1377 if (frag_threshold != (u32) -1) {
1378 /*
1379 * Fragments (apart from the last one) are required to
1380 * have even length. Make the fragmentation code
1381 * simpler by stripping LSB should someone try to use
1382 * odd threshold value.
1383 */
1384 frag_threshold &= ~0x1;
1385 }
1386 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1387 }
1388
1389 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1390 rts_threshold = nla_get_u32(
1391 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1392 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1393 }
1394
81077e82
LT
1395 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1396 coverage_class = nla_get_u8(
1397 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1398 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1399 }
1400
b9a5f8ca
JM
1401 if (changed) {
1402 u8 old_retry_short, old_retry_long;
1403 u32 old_frag_threshold, old_rts_threshold;
81077e82 1404 u8 old_coverage_class;
b9a5f8ca
JM
1405
1406 if (!rdev->ops->set_wiphy_params) {
1407 result = -EOPNOTSUPP;
1408 goto bad_res;
1409 }
1410
1411 old_retry_short = rdev->wiphy.retry_short;
1412 old_retry_long = rdev->wiphy.retry_long;
1413 old_frag_threshold = rdev->wiphy.frag_threshold;
1414 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1415 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1416
1417 if (changed & WIPHY_PARAM_RETRY_SHORT)
1418 rdev->wiphy.retry_short = retry_short;
1419 if (changed & WIPHY_PARAM_RETRY_LONG)
1420 rdev->wiphy.retry_long = retry_long;
1421 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1422 rdev->wiphy.frag_threshold = frag_threshold;
1423 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1424 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1425 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1426 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1427
1428 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1429 if (result) {
1430 rdev->wiphy.retry_short = old_retry_short;
1431 rdev->wiphy.retry_long = old_retry_long;
1432 rdev->wiphy.frag_threshold = old_frag_threshold;
1433 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1434 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1435 }
1436 }
72bdcf34 1437
306d6112 1438 bad_res:
4bbf4d56 1439 mutex_unlock(&rdev->mtx);
f444de05
JB
1440 if (netdev)
1441 dev_put(netdev);
55682965
JB
1442 return result;
1443}
1444
1445
1446static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1447 struct cfg80211_registered_device *rdev,
55682965
JB
1448 struct net_device *dev)
1449{
1450 void *hdr;
1451
1452 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1453 if (!hdr)
1454 return -1;
1455
1456 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1457 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1458 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1459 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1460
1461 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1462 rdev->devlist_generation ^
1463 (cfg80211_rdev_list_generation << 2));
1464
55682965
JB
1465 return genlmsg_end(msg, hdr);
1466
1467 nla_put_failure:
bc3ed28c
TG
1468 genlmsg_cancel(msg, hdr);
1469 return -EMSGSIZE;
55682965
JB
1470}
1471
1472static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1473{
1474 int wp_idx = 0;
1475 int if_idx = 0;
1476 int wp_start = cb->args[0];
1477 int if_start = cb->args[1];
f5ea9120 1478 struct cfg80211_registered_device *rdev;
55682965
JB
1479 struct wireless_dev *wdev;
1480
a1794390 1481 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1482 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1483 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1484 continue;
bba95fef
JB
1485 if (wp_idx < wp_start) {
1486 wp_idx++;
55682965 1487 continue;
bba95fef 1488 }
55682965
JB
1489 if_idx = 0;
1490
f5ea9120
JB
1491 mutex_lock(&rdev->devlist_mtx);
1492 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1493 if (if_idx < if_start) {
1494 if_idx++;
55682965 1495 continue;
bba95fef 1496 }
55682965
JB
1497 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1498 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1499 rdev, wdev->netdev) < 0) {
1500 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1501 goto out;
1502 }
1503 if_idx++;
55682965 1504 }
f5ea9120 1505 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1506
1507 wp_idx++;
55682965 1508 }
bba95fef 1509 out:
a1794390 1510 mutex_unlock(&cfg80211_mutex);
55682965
JB
1511
1512 cb->args[0] = wp_idx;
1513 cb->args[1] = if_idx;
1514
1515 return skb->len;
1516}
1517
1518static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1519{
1520 struct sk_buff *msg;
4c476991
JB
1521 struct cfg80211_registered_device *dev = info->user_ptr[0];
1522 struct net_device *netdev = info->user_ptr[1];
55682965 1523
fd2120ca 1524 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1525 if (!msg)
4c476991 1526 return -ENOMEM;
55682965 1527
d726405a 1528 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1529 dev, netdev) < 0) {
1530 nlmsg_free(msg);
1531 return -ENOBUFS;
1532 }
55682965 1533
134e6375 1534 return genlmsg_reply(msg, info);
55682965
JB
1535}
1536
66f7ac50
MW
1537static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1538 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1539 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1540 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1541 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1542 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1543};
1544
1545static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1546{
1547 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1548 int flag;
1549
1550 *mntrflags = 0;
1551
1552 if (!nla)
1553 return -EINVAL;
1554
1555 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1556 nla, mntr_flags_policy))
1557 return -EINVAL;
1558
1559 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1560 if (flags[flag])
1561 *mntrflags |= (1<<flag);
1562
1563 return 0;
1564}
1565
9bc383de 1566static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1567 struct net_device *netdev, u8 use_4addr,
1568 enum nl80211_iftype iftype)
9bc383de 1569{
ad4bb6f8 1570 if (!use_4addr) {
f350a0a8 1571 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1572 return -EBUSY;
9bc383de 1573 return 0;
ad4bb6f8 1574 }
9bc383de
JB
1575
1576 switch (iftype) {
1577 case NL80211_IFTYPE_AP_VLAN:
1578 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1579 return 0;
1580 break;
1581 case NL80211_IFTYPE_STATION:
1582 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1583 return 0;
1584 break;
1585 default:
1586 break;
1587 }
1588
1589 return -EOPNOTSUPP;
1590}
1591
55682965
JB
1592static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1593{
4c476991 1594 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1595 struct vif_params params;
e36d56b6 1596 int err;
04a773ad 1597 enum nl80211_iftype otype, ntype;
4c476991 1598 struct net_device *dev = info->user_ptr[1];
92ffe055 1599 u32 _flags, *flags = NULL;
ac7f9cfa 1600 bool change = false;
55682965 1601
2ec600d6
LCC
1602 memset(&params, 0, sizeof(params));
1603
04a773ad 1604 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1605
723b038d 1606 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1607 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1608 if (otype != ntype)
ac7f9cfa 1609 change = true;
4c476991
JB
1610 if (ntype > NL80211_IFTYPE_MAX)
1611 return -EINVAL;
723b038d
JB
1612 }
1613
92ffe055 1614 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1615 struct wireless_dev *wdev = dev->ieee80211_ptr;
1616
4c476991
JB
1617 if (ntype != NL80211_IFTYPE_MESH_POINT)
1618 return -EINVAL;
29cbe68c
JB
1619 if (netif_running(dev))
1620 return -EBUSY;
1621
1622 wdev_lock(wdev);
1623 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1624 IEEE80211_MAX_MESH_ID_LEN);
1625 wdev->mesh_id_up_len =
1626 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1627 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1628 wdev->mesh_id_up_len);
1629 wdev_unlock(wdev);
2ec600d6
LCC
1630 }
1631
8b787643
FF
1632 if (info->attrs[NL80211_ATTR_4ADDR]) {
1633 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1634 change = true;
ad4bb6f8 1635 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1636 if (err)
4c476991 1637 return err;
8b787643
FF
1638 } else {
1639 params.use_4addr = -1;
1640 }
1641
92ffe055 1642 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1643 if (ntype != NL80211_IFTYPE_MONITOR)
1644 return -EINVAL;
92ffe055
JB
1645 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1646 &_flags);
ac7f9cfa 1647 if (err)
4c476991 1648 return err;
ac7f9cfa
JB
1649
1650 flags = &_flags;
1651 change = true;
92ffe055 1652 }
3b85875a 1653
ac7f9cfa 1654 if (change)
3d54d255 1655 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1656 else
1657 err = 0;
60719ffd 1658
9bc383de
JB
1659 if (!err && params.use_4addr != -1)
1660 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1661
55682965
JB
1662 return err;
1663}
1664
1665static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1666{
4c476991 1667 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1668 struct vif_params params;
f9e10ce4 1669 struct net_device *dev;
55682965
JB
1670 int err;
1671 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1672 u32 flags;
55682965 1673
2ec600d6
LCC
1674 memset(&params, 0, sizeof(params));
1675
55682965
JB
1676 if (!info->attrs[NL80211_ATTR_IFNAME])
1677 return -EINVAL;
1678
1679 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1680 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1681 if (type > NL80211_IFTYPE_MAX)
1682 return -EINVAL;
1683 }
1684
79c97e97 1685 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1686 !(rdev->wiphy.interface_modes & (1 << type)))
1687 return -EOPNOTSUPP;
55682965 1688
9bc383de 1689 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1690 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1691 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1692 if (err)
4c476991 1693 return err;
9bc383de 1694 }
8b787643 1695
66f7ac50
MW
1696 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1697 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1698 &flags);
f9e10ce4 1699 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1700 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1701 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1702 if (IS_ERR(dev))
1703 return PTR_ERR(dev);
2ec600d6 1704
29cbe68c
JB
1705 if (type == NL80211_IFTYPE_MESH_POINT &&
1706 info->attrs[NL80211_ATTR_MESH_ID]) {
1707 struct wireless_dev *wdev = dev->ieee80211_ptr;
1708
1709 wdev_lock(wdev);
1710 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1711 IEEE80211_MAX_MESH_ID_LEN);
1712 wdev->mesh_id_up_len =
1713 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1714 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1715 wdev->mesh_id_up_len);
1716 wdev_unlock(wdev);
1717 }
1718
f9e10ce4 1719 return 0;
55682965
JB
1720}
1721
1722static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1723{
4c476991
JB
1724 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1725 struct net_device *dev = info->user_ptr[1];
55682965 1726
4c476991
JB
1727 if (!rdev->ops->del_virtual_intf)
1728 return -EOPNOTSUPP;
55682965 1729
4c476991 1730 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1731}
1732
41ade00f
JB
1733struct get_key_cookie {
1734 struct sk_buff *msg;
1735 int error;
b9454e83 1736 int idx;
41ade00f
JB
1737};
1738
1739static void get_key_callback(void *c, struct key_params *params)
1740{
b9454e83 1741 struct nlattr *key;
41ade00f
JB
1742 struct get_key_cookie *cookie = c;
1743
1744 if (params->key)
1745 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1746 params->key_len, params->key);
1747
1748 if (params->seq)
1749 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1750 params->seq_len, params->seq);
1751
1752 if (params->cipher)
1753 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1754 params->cipher);
1755
b9454e83
JB
1756 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1757 if (!key)
1758 goto nla_put_failure;
1759
1760 if (params->key)
1761 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1762 params->key_len, params->key);
1763
1764 if (params->seq)
1765 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1766 params->seq_len, params->seq);
1767
1768 if (params->cipher)
1769 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1770 params->cipher);
1771
1772 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1773
1774 nla_nest_end(cookie->msg, key);
1775
41ade00f
JB
1776 return;
1777 nla_put_failure:
1778 cookie->error = 1;
1779}
1780
1781static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1782{
4c476991 1783 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1784 int err;
4c476991 1785 struct net_device *dev = info->user_ptr[1];
41ade00f 1786 u8 key_idx = 0;
e31b8213
JB
1787 const u8 *mac_addr = NULL;
1788 bool pairwise;
41ade00f
JB
1789 struct get_key_cookie cookie = {
1790 .error = 0,
1791 };
1792 void *hdr;
1793 struct sk_buff *msg;
1794
1795 if (info->attrs[NL80211_ATTR_KEY_IDX])
1796 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1797
3cfcf6ac 1798 if (key_idx > 5)
41ade00f
JB
1799 return -EINVAL;
1800
1801 if (info->attrs[NL80211_ATTR_MAC])
1802 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1803
e31b8213
JB
1804 pairwise = !!mac_addr;
1805 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1806 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1807 if (kt >= NUM_NL80211_KEYTYPES)
1808 return -EINVAL;
1809 if (kt != NL80211_KEYTYPE_GROUP &&
1810 kt != NL80211_KEYTYPE_PAIRWISE)
1811 return -EINVAL;
1812 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1813 }
1814
4c476991
JB
1815 if (!rdev->ops->get_key)
1816 return -EOPNOTSUPP;
41ade00f 1817
fd2120ca 1818 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1819 if (!msg)
1820 return -ENOMEM;
41ade00f
JB
1821
1822 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1823 NL80211_CMD_NEW_KEY);
4c476991
JB
1824 if (IS_ERR(hdr))
1825 return PTR_ERR(hdr);
41ade00f
JB
1826
1827 cookie.msg = msg;
b9454e83 1828 cookie.idx = key_idx;
41ade00f
JB
1829
1830 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1831 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1832 if (mac_addr)
1833 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1834
e31b8213
JB
1835 if (pairwise && mac_addr &&
1836 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1837 return -ENOENT;
1838
1839 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1840 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1841
1842 if (err)
6c95e2a2 1843 goto free_msg;
41ade00f
JB
1844
1845 if (cookie.error)
1846 goto nla_put_failure;
1847
1848 genlmsg_end(msg, hdr);
4c476991 1849 return genlmsg_reply(msg, info);
41ade00f
JB
1850
1851 nla_put_failure:
1852 err = -ENOBUFS;
6c95e2a2 1853 free_msg:
41ade00f 1854 nlmsg_free(msg);
41ade00f
JB
1855 return err;
1856}
1857
1858static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1859{
4c476991 1860 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1861 struct key_parse key;
41ade00f 1862 int err;
4c476991 1863 struct net_device *dev = info->user_ptr[1];
41ade00f 1864
b9454e83
JB
1865 err = nl80211_parse_key(info, &key);
1866 if (err)
1867 return err;
41ade00f 1868
b9454e83 1869 if (key.idx < 0)
41ade00f
JB
1870 return -EINVAL;
1871
b9454e83
JB
1872 /* only support setting default key */
1873 if (!key.def && !key.defmgmt)
41ade00f
JB
1874 return -EINVAL;
1875
dbd2fd65 1876 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1877
dbd2fd65
JB
1878 if (key.def) {
1879 if (!rdev->ops->set_default_key) {
1880 err = -EOPNOTSUPP;
1881 goto out;
1882 }
41ade00f 1883
dbd2fd65
JB
1884 err = nl80211_key_allowed(dev->ieee80211_ptr);
1885 if (err)
1886 goto out;
1887
dbd2fd65
JB
1888 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1889 key.def_uni, key.def_multi);
1890
1891 if (err)
1892 goto out;
fffd0934 1893
3d23e349 1894#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1895 dev->ieee80211_ptr->wext.default_key = key.idx;
1896#endif
1897 } else {
1898 if (key.def_uni || !key.def_multi) {
1899 err = -EINVAL;
1900 goto out;
1901 }
1902
1903 if (!rdev->ops->set_default_mgmt_key) {
1904 err = -EOPNOTSUPP;
1905 goto out;
1906 }
1907
1908 err = nl80211_key_allowed(dev->ieee80211_ptr);
1909 if (err)
1910 goto out;
1911
1912 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1913 dev, key.idx);
1914 if (err)
1915 goto out;
1916
1917#ifdef CONFIG_CFG80211_WEXT
1918 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1919#endif
dbd2fd65
JB
1920 }
1921
1922 out:
fffd0934 1923 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1924
41ade00f
JB
1925 return err;
1926}
1927
1928static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1929{
4c476991 1930 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1931 int err;
4c476991 1932 struct net_device *dev = info->user_ptr[1];
b9454e83 1933 struct key_parse key;
e31b8213 1934 const u8 *mac_addr = NULL;
41ade00f 1935
b9454e83
JB
1936 err = nl80211_parse_key(info, &key);
1937 if (err)
1938 return err;
41ade00f 1939
b9454e83 1940 if (!key.p.key)
41ade00f
JB
1941 return -EINVAL;
1942
41ade00f
JB
1943 if (info->attrs[NL80211_ATTR_MAC])
1944 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1945
e31b8213
JB
1946 if (key.type == -1) {
1947 if (mac_addr)
1948 key.type = NL80211_KEYTYPE_PAIRWISE;
1949 else
1950 key.type = NL80211_KEYTYPE_GROUP;
1951 }
1952
1953 /* for now */
1954 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1955 key.type != NL80211_KEYTYPE_GROUP)
1956 return -EINVAL;
1957
4c476991
JB
1958 if (!rdev->ops->add_key)
1959 return -EOPNOTSUPP;
25e47c18 1960
e31b8213
JB
1961 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1962 key.type == NL80211_KEYTYPE_PAIRWISE,
1963 mac_addr))
4c476991 1964 return -EINVAL;
41ade00f 1965
fffd0934
JB
1966 wdev_lock(dev->ieee80211_ptr);
1967 err = nl80211_key_allowed(dev->ieee80211_ptr);
1968 if (!err)
1969 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1970 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1971 mac_addr, &key.p);
1972 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1973
41ade00f
JB
1974 return err;
1975}
1976
1977static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1978{
4c476991 1979 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1980 int err;
4c476991 1981 struct net_device *dev = info->user_ptr[1];
41ade00f 1982 u8 *mac_addr = NULL;
b9454e83 1983 struct key_parse key;
41ade00f 1984
b9454e83
JB
1985 err = nl80211_parse_key(info, &key);
1986 if (err)
1987 return err;
41ade00f
JB
1988
1989 if (info->attrs[NL80211_ATTR_MAC])
1990 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1991
e31b8213
JB
1992 if (key.type == -1) {
1993 if (mac_addr)
1994 key.type = NL80211_KEYTYPE_PAIRWISE;
1995 else
1996 key.type = NL80211_KEYTYPE_GROUP;
1997 }
1998
1999 /* for now */
2000 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2001 key.type != NL80211_KEYTYPE_GROUP)
2002 return -EINVAL;
2003
4c476991
JB
2004 if (!rdev->ops->del_key)
2005 return -EOPNOTSUPP;
41ade00f 2006
fffd0934
JB
2007 wdev_lock(dev->ieee80211_ptr);
2008 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2009
2010 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2011 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2012 err = -ENOENT;
2013
fffd0934 2014 if (!err)
e31b8213
JB
2015 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2016 key.type == NL80211_KEYTYPE_PAIRWISE,
2017 mac_addr);
41ade00f 2018
3d23e349 2019#ifdef CONFIG_CFG80211_WEXT
08645126 2020 if (!err) {
b9454e83 2021 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2022 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2023 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2024 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2025 }
2026#endif
fffd0934 2027 wdev_unlock(dev->ieee80211_ptr);
08645126 2028
41ade00f
JB
2029 return err;
2030}
2031
ed1b6cc7
JB
2032static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
2033{
2034 int (*call)(struct wiphy *wiphy, struct net_device *dev,
2035 struct beacon_parameters *info);
4c476991
JB
2036 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2037 struct net_device *dev = info->user_ptr[1];
56d1893d 2038 struct wireless_dev *wdev = dev->ieee80211_ptr;
ed1b6cc7 2039 struct beacon_parameters params;
56d1893d 2040 int haveinfo = 0, err;
ed1b6cc7 2041
9946ecfb
JM
2042 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2043 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2044 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2045 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2046 return -EINVAL;
2047
074ac8df 2048 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2049 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2050 return -EOPNOTSUPP;
eec60b03 2051
56d1893d
JB
2052 memset(&params, 0, sizeof(params));
2053
ed1b6cc7
JB
2054 switch (info->genlhdr->cmd) {
2055 case NL80211_CMD_NEW_BEACON:
2056 /* these are required for NEW_BEACON */
2057 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2058 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
2059 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2060 return -EINVAL;
ed1b6cc7 2061
56d1893d
JB
2062 params.interval =
2063 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2064 params.dtim_period =
2065 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2066
2067 err = cfg80211_validate_beacon_int(rdev, params.interval);
2068 if (err)
2069 return err;
2070
32e9de84
JM
2071 /*
2072 * In theory, some of these attributes could be required for
2073 * NEW_BEACON, but since they were not used when the command was
2074 * originally added, keep them optional for old user space
2075 * programs to work with drivers that do not need the additional
2076 * information.
2077 */
2078 if (info->attrs[NL80211_ATTR_SSID]) {
2079 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2080 params.ssid_len =
2081 nla_len(info->attrs[NL80211_ATTR_SSID]);
2082 if (params.ssid_len == 0 ||
2083 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2084 return -EINVAL;
2085 }
2086
2087 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2088 params.hidden_ssid = nla_get_u32(
2089 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2090 if (params.hidden_ssid !=
2091 NL80211_HIDDEN_SSID_NOT_IN_USE &&
2092 params.hidden_ssid !=
2093 NL80211_HIDDEN_SSID_ZERO_LEN &&
2094 params.hidden_ssid !=
2095 NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2096 return -EINVAL;
2097 }
2098
5fb628e9
JM
2099 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2100
2101 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2102 params.auth_type = nla_get_u32(
2103 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2104 if (!nl80211_valid_auth_type(params.auth_type))
2105 return -EINVAL;
2106 } else
2107 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2108
2109 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2110 NL80211_MAX_NR_CIPHER_SUITES);
2111 if (err)
2112 return err;
2113
79c97e97 2114 call = rdev->ops->add_beacon;
ed1b6cc7
JB
2115 break;
2116 case NL80211_CMD_SET_BEACON:
79c97e97 2117 call = rdev->ops->set_beacon;
ed1b6cc7
JB
2118 break;
2119 default:
2120 WARN_ON(1);
4c476991 2121 return -EOPNOTSUPP;
ed1b6cc7
JB
2122 }
2123
4c476991
JB
2124 if (!call)
2125 return -EOPNOTSUPP;
ed1b6cc7 2126
ed1b6cc7
JB
2127 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
2128 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2129 params.head_len =
2130 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2131 haveinfo = 1;
2132 }
2133
2134 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
2135 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2136 params.tail_len =
2137 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2138 haveinfo = 1;
2139 }
2140
4c476991
JB
2141 if (!haveinfo)
2142 return -EINVAL;
3b85875a 2143
9946ecfb
JM
2144 if (info->attrs[NL80211_ATTR_IE]) {
2145 params.beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2146 params.beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2147 }
2148
2149 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
2150 params.proberesp_ies =
2151 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2152 params.proberesp_ies_len =
2153 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2154 }
2155
2156 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
2157 params.assocresp_ies =
2158 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2159 params.assocresp_ies_len =
2160 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2161 }
2162
56d1893d
JB
2163 err = call(&rdev->wiphy, dev, &params);
2164 if (!err && params.interval)
2165 wdev->beacon_interval = params.interval;
2166 return err;
ed1b6cc7
JB
2167}
2168
2169static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
2170{
4c476991
JB
2171 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2172 struct net_device *dev = info->user_ptr[1];
56d1893d
JB
2173 struct wireless_dev *wdev = dev->ieee80211_ptr;
2174 int err;
ed1b6cc7 2175
4c476991
JB
2176 if (!rdev->ops->del_beacon)
2177 return -EOPNOTSUPP;
ed1b6cc7 2178
074ac8df 2179 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2180 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2181 return -EOPNOTSUPP;
3b85875a 2182
56d1893d
JB
2183 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
2184 if (!err)
2185 wdev->beacon_interval = 0;
2186 return err;
ed1b6cc7
JB
2187}
2188
5727ef1b
JB
2189static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2190 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2191 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2192 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2193 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2194 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
5727ef1b
JB
2195};
2196
eccb8e8f
JB
2197static int parse_station_flags(struct genl_info *info,
2198 struct station_parameters *params)
5727ef1b
JB
2199{
2200 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2201 struct nlattr *nla;
5727ef1b
JB
2202 int flag;
2203
eccb8e8f
JB
2204 /*
2205 * Try parsing the new attribute first so userspace
2206 * can specify both for older kernels.
2207 */
2208 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2209 if (nla) {
2210 struct nl80211_sta_flag_update *sta_flags;
2211
2212 sta_flags = nla_data(nla);
2213 params->sta_flags_mask = sta_flags->mask;
2214 params->sta_flags_set = sta_flags->set;
2215 if ((params->sta_flags_mask |
2216 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2217 return -EINVAL;
2218 return 0;
2219 }
2220
2221 /* if present, parse the old attribute */
5727ef1b 2222
eccb8e8f 2223 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2224 if (!nla)
2225 return 0;
2226
2227 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2228 nla, sta_flags_policy))
2229 return -EINVAL;
2230
eccb8e8f
JB
2231 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
2232 params->sta_flags_mask &= ~1;
5727ef1b
JB
2233
2234 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2235 if (flags[flag])
eccb8e8f 2236 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2237
2238 return 0;
2239}
2240
c8dcfd8a
FF
2241static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2242 int attr)
2243{
2244 struct nlattr *rate;
2245 u16 bitrate;
2246
2247 rate = nla_nest_start(msg, attr);
2248 if (!rate)
2249 goto nla_put_failure;
2250
2251 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2252 bitrate = cfg80211_calculate_bitrate(info);
2253 if (bitrate > 0)
2254 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2255
2256 if (info->flags & RATE_INFO_FLAGS_MCS)
2257 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2258 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2259 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2260 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2261 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2262
2263 nla_nest_end(msg, rate);
2264 return true;
2265
2266nla_put_failure:
2267 return false;
2268}
2269
fd5b74dc
JB
2270static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2271 int flags, struct net_device *dev,
98b62183 2272 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2273{
2274 void *hdr;
f4263c98 2275 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2276
2277 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2278 if (!hdr)
2279 return -1;
2280
2281 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2282 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2283
f5ea9120
JB
2284 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2285
2ec600d6
LCC
2286 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2287 if (!sinfoattr)
fd5b74dc 2288 goto nla_put_failure;
ebe27c91
MSS
2289 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2290 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2291 sinfo->connected_time);
2ec600d6
LCC
2292 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2293 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2294 sinfo->inactive_time);
2295 if (sinfo->filled & STATION_INFO_RX_BYTES)
2296 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2297 sinfo->rx_bytes);
2298 if (sinfo->filled & STATION_INFO_TX_BYTES)
2299 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2300 sinfo->tx_bytes);
2301 if (sinfo->filled & STATION_INFO_LLID)
2302 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2303 sinfo->llid);
2304 if (sinfo->filled & STATION_INFO_PLID)
2305 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2306 sinfo->plid);
2307 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2308 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2309 sinfo->plink_state);
420e7fab
HR
2310 if (sinfo->filled & STATION_INFO_SIGNAL)
2311 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2312 sinfo->signal);
541a45a1
BR
2313 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2314 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2315 sinfo->signal_avg);
420e7fab 2316 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2317 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2318 NL80211_STA_INFO_TX_BITRATE))
2319 goto nla_put_failure;
2320 }
2321 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2322 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2323 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2324 goto nla_put_failure;
420e7fab 2325 }
98c8a60a
JM
2326 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2327 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2328 sinfo->rx_packets);
2329 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2330 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2331 sinfo->tx_packets);
b206b4ef
BR
2332 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2333 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2334 sinfo->tx_retries);
2335 if (sinfo->filled & STATION_INFO_TX_FAILED)
2336 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2337 sinfo->tx_failed);
f4263c98
PS
2338 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2339 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2340 if (!bss_param)
2341 goto nla_put_failure;
2342
2343 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2344 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2345 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2346 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2347 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2348 NLA_PUT_FLAG(msg,
2349 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2350 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2351 sinfo->bss_param.dtim_period);
2352 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2353 sinfo->bss_param.beacon_interval);
2354
2355 nla_nest_end(msg, bss_param);
2356 }
bb6e753e
HS
2357 if (sinfo->filled & STATION_INFO_STA_FLAGS)
2358 NLA_PUT(msg, NL80211_STA_INFO_STA_FLAGS,
2359 sizeof(struct nl80211_sta_flag_update),
2360 &sinfo->sta_flags);
2ec600d6 2361 nla_nest_end(msg, sinfoattr);
fd5b74dc 2362
040bdf71 2363 if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
50d3dfb7
JM
2364 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2365 sinfo->assoc_req_ies);
2366
fd5b74dc
JB
2367 return genlmsg_end(msg, hdr);
2368
2369 nla_put_failure:
bc3ed28c
TG
2370 genlmsg_cancel(msg, hdr);
2371 return -EMSGSIZE;
fd5b74dc
JB
2372}
2373
2ec600d6 2374static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2375 struct netlink_callback *cb)
2ec600d6 2376{
2ec600d6
LCC
2377 struct station_info sinfo;
2378 struct cfg80211_registered_device *dev;
bba95fef 2379 struct net_device *netdev;
2ec600d6 2380 u8 mac_addr[ETH_ALEN];
bba95fef 2381 int sta_idx = cb->args[1];
2ec600d6 2382 int err;
2ec600d6 2383
67748893
JB
2384 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2385 if (err)
2386 return err;
bba95fef
JB
2387
2388 if (!dev->ops->dump_station) {
eec60b03 2389 err = -EOPNOTSUPP;
bba95fef
JB
2390 goto out_err;
2391 }
2392
bba95fef 2393 while (1) {
f612cedf 2394 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2395 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2396 mac_addr, &sinfo);
2397 if (err == -ENOENT)
2398 break;
2399 if (err)
3b85875a 2400 goto out_err;
bba95fef
JB
2401
2402 if (nl80211_send_station(skb,
2403 NETLINK_CB(cb->skb).pid,
2404 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2405 netdev, mac_addr,
2406 &sinfo) < 0)
2407 goto out;
2408
2409 sta_idx++;
2410 }
2411
2412
2413 out:
2414 cb->args[1] = sta_idx;
2415 err = skb->len;
bba95fef 2416 out_err:
67748893 2417 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2418
2419 return err;
2ec600d6 2420}
fd5b74dc 2421
5727ef1b
JB
2422static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2423{
4c476991
JB
2424 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2425 struct net_device *dev = info->user_ptr[1];
2ec600d6 2426 struct station_info sinfo;
fd5b74dc
JB
2427 struct sk_buff *msg;
2428 u8 *mac_addr = NULL;
4c476991 2429 int err;
fd5b74dc 2430
2ec600d6 2431 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2432
2433 if (!info->attrs[NL80211_ATTR_MAC])
2434 return -EINVAL;
2435
2436 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2437
4c476991
JB
2438 if (!rdev->ops->get_station)
2439 return -EOPNOTSUPP;
3b85875a 2440
4c476991 2441 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2442 if (err)
4c476991 2443 return err;
2ec600d6 2444
fd2120ca 2445 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2446 if (!msg)
4c476991 2447 return -ENOMEM;
fd5b74dc
JB
2448
2449 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2450 dev, mac_addr, &sinfo) < 0) {
2451 nlmsg_free(msg);
2452 return -ENOBUFS;
2453 }
3b85875a 2454
4c476991 2455 return genlmsg_reply(msg, info);
5727ef1b
JB
2456}
2457
2458/*
c258d2de 2459 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2460 */
463d0183 2461static int get_vlan(struct genl_info *info,
5727ef1b
JB
2462 struct cfg80211_registered_device *rdev,
2463 struct net_device **vlan)
2464{
463d0183 2465 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2466 *vlan = NULL;
2467
2468 if (vlanattr) {
463d0183
JB
2469 *vlan = dev_get_by_index(genl_info_net(info),
2470 nla_get_u32(vlanattr));
5727ef1b
JB
2471 if (!*vlan)
2472 return -ENODEV;
2473 if (!(*vlan)->ieee80211_ptr)
2474 return -EINVAL;
2475 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2476 return -EINVAL;
c258d2de
FF
2477 if (!netif_running(*vlan))
2478 return -ENETDOWN;
5727ef1b
JB
2479 }
2480 return 0;
2481}
2482
2483static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2484{
4c476991 2485 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2486 int err;
4c476991 2487 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2488 struct station_parameters params;
2489 u8 *mac_addr = NULL;
2490
2491 memset(&params, 0, sizeof(params));
2492
2493 params.listen_interval = -1;
57cf8043 2494 params.plink_state = -1;
5727ef1b
JB
2495
2496 if (info->attrs[NL80211_ATTR_STA_AID])
2497 return -EINVAL;
2498
2499 if (!info->attrs[NL80211_ATTR_MAC])
2500 return -EINVAL;
2501
2502 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2503
2504 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2505 params.supported_rates =
2506 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2507 params.supported_rates_len =
2508 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2509 }
2510
2511 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2512 params.listen_interval =
2513 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2514
36aedc90
JM
2515 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2516 params.ht_capa =
2517 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2518
eccb8e8f 2519 if (parse_station_flags(info, &params))
5727ef1b
JB
2520 return -EINVAL;
2521
2ec600d6
LCC
2522 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2523 params.plink_action =
2524 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2525
9c3990aa
JC
2526 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2527 params.plink_state =
2528 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2529
463d0183 2530 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2531 if (err)
034d655e 2532 goto out;
a97f4424
JB
2533
2534 /* validate settings */
2535 err = 0;
2536
2537 switch (dev->ieee80211_ptr->iftype) {
2538 case NL80211_IFTYPE_AP:
2539 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2540 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2541 /* disallow mesh-specific things */
2542 if (params.plink_action)
2543 err = -EINVAL;
2544 break;
074ac8df 2545 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 2546 case NL80211_IFTYPE_STATION:
07ba55d7 2547 /* disallow things sta doesn't support */
a97f4424
JB
2548 if (params.plink_action)
2549 err = -EINVAL;
2550 if (params.vlan)
2551 err = -EINVAL;
07ba55d7
AN
2552 if (params.supported_rates &&
2553 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
a97f4424
JB
2554 err = -EINVAL;
2555 if (params.ht_capa)
2556 err = -EINVAL;
2557 if (params.listen_interval >= 0)
2558 err = -EINVAL;
07ba55d7
AN
2559 if (params.sta_flags_mask &
2560 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2561 BIT(NL80211_STA_FLAG_TDLS_PEER)))
2562 err = -EINVAL;
2563 /* can't change the TDLS bit */
2564 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
2565 (params.sta_flags_mask & BIT(NL80211_STA_FLAG_TDLS_PEER)))
a97f4424
JB
2566 err = -EINVAL;
2567 break;
2568 case NL80211_IFTYPE_MESH_POINT:
2569 /* disallow things mesh doesn't support */
2570 if (params.vlan)
2571 err = -EINVAL;
2572 if (params.ht_capa)
2573 err = -EINVAL;
2574 if (params.listen_interval >= 0)
2575 err = -EINVAL;
b39c48fa
JC
2576 if (params.sta_flags_mask &
2577 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2578 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2579 BIT(NL80211_STA_FLAG_AUTHORIZED)))
a97f4424
JB
2580 err = -EINVAL;
2581 break;
2582 default:
2583 err = -EINVAL;
034d655e
JB
2584 }
2585
5727ef1b
JB
2586 if (err)
2587 goto out;
2588
79c97e97 2589 if (!rdev->ops->change_station) {
5727ef1b
JB
2590 err = -EOPNOTSUPP;
2591 goto out;
2592 }
2593
79c97e97 2594 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2595
2596 out:
2597 if (params.vlan)
2598 dev_put(params.vlan);
3b85875a 2599
5727ef1b
JB
2600 return err;
2601}
2602
c75786c9
EP
2603static struct nla_policy
2604nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2605 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2606 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2607};
2608
5727ef1b
JB
2609static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2610{
4c476991 2611 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2612 int err;
4c476991 2613 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2614 struct station_parameters params;
2615 u8 *mac_addr = NULL;
2616
2617 memset(&params, 0, sizeof(params));
2618
2619 if (!info->attrs[NL80211_ATTR_MAC])
2620 return -EINVAL;
2621
5727ef1b
JB
2622 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2623 return -EINVAL;
2624
2625 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2626 return -EINVAL;
2627
0e956c13
TLSC
2628 if (!info->attrs[NL80211_ATTR_STA_AID])
2629 return -EINVAL;
2630
5727ef1b
JB
2631 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2632 params.supported_rates =
2633 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2634 params.supported_rates_len =
2635 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2636 params.listen_interval =
2637 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2638
0e956c13
TLSC
2639 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2640 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2641 return -EINVAL;
51b50fbe 2642
36aedc90
JM
2643 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2644 params.ht_capa =
2645 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2646
96b78dff
JC
2647 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2648 params.plink_action =
2649 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2650
eccb8e8f 2651 if (parse_station_flags(info, &params))
5727ef1b
JB
2652 return -EINVAL;
2653
c75786c9 2654 /* parse WME attributes if sta is WME capable */
cedb5412 2655 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
cd32984f 2656 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
c75786c9
EP
2657 info->attrs[NL80211_ATTR_STA_WME]) {
2658 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2659 struct nlattr *nla;
2660
2661 nla = info->attrs[NL80211_ATTR_STA_WME];
2662 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2663 nl80211_sta_wme_policy);
2664 if (err)
2665 return err;
2666
2667 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2668 params.uapsd_queues =
2669 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
4319e193
JB
2670 if (params.uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2671 return -EINVAL;
c75786c9
EP
2672
2673 if (tb[NL80211_STA_WME_MAX_SP])
2674 params.max_sp =
2675 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
4319e193
JB
2676
2677 if (params.max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2678 return -EINVAL;
3b9ce80c
JB
2679
2680 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
c75786c9
EP
2681 }
2682
0e956c13 2683 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2684 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
96b78dff 2685 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
07ba55d7
AN
2686 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO &&
2687 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION)
2688 return -EINVAL;
2689
2690 /*
2691 * Only managed stations can add TDLS peers, and only when the
2692 * wiphy supports external TDLS setup.
2693 */
2694 if (dev->ieee80211_ptr->iftype == NL80211_IFTYPE_STATION &&
2695 !((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
2696 (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
2697 (rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)))
4c476991 2698 return -EINVAL;
0e956c13 2699
463d0183 2700 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2701 if (err)
e80cf853 2702 goto out;
a97f4424
JB
2703
2704 /* validate settings */
2705 err = 0;
2706
79c97e97 2707 if (!rdev->ops->add_station) {
5727ef1b
JB
2708 err = -EOPNOTSUPP;
2709 goto out;
2710 }
2711
79c97e97 2712 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2713
2714 out:
2715 if (params.vlan)
2716 dev_put(params.vlan);
5727ef1b
JB
2717 return err;
2718}
2719
2720static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2721{
4c476991
JB
2722 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2723 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2724 u8 *mac_addr = NULL;
2725
2726 if (info->attrs[NL80211_ATTR_MAC])
2727 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2728
e80cf853 2729 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2730 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2731 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2732 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2733 return -EINVAL;
5727ef1b 2734
4c476991
JB
2735 if (!rdev->ops->del_station)
2736 return -EOPNOTSUPP;
3b85875a 2737
4c476991 2738 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2739}
2740
2ec600d6
LCC
2741static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2742 int flags, struct net_device *dev,
2743 u8 *dst, u8 *next_hop,
2744 struct mpath_info *pinfo)
2745{
2746 void *hdr;
2747 struct nlattr *pinfoattr;
2748
2749 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2750 if (!hdr)
2751 return -1;
2752
2753 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2754 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2755 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2756
f5ea9120
JB
2757 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2758
2ec600d6
LCC
2759 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2760 if (!pinfoattr)
2761 goto nla_put_failure;
2762 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2763 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2764 pinfo->frame_qlen);
d19b3bf6
RP
2765 if (pinfo->filled & MPATH_INFO_SN)
2766 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2767 pinfo->sn);
2ec600d6
LCC
2768 if (pinfo->filled & MPATH_INFO_METRIC)
2769 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2770 pinfo->metric);
2771 if (pinfo->filled & MPATH_INFO_EXPTIME)
2772 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2773 pinfo->exptime);
2774 if (pinfo->filled & MPATH_INFO_FLAGS)
2775 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2776 pinfo->flags);
2777 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2778 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2779 pinfo->discovery_timeout);
2780 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2781 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2782 pinfo->discovery_retries);
2783
2784 nla_nest_end(msg, pinfoattr);
2785
2786 return genlmsg_end(msg, hdr);
2787
2788 nla_put_failure:
bc3ed28c
TG
2789 genlmsg_cancel(msg, hdr);
2790 return -EMSGSIZE;
2ec600d6
LCC
2791}
2792
2793static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2794 struct netlink_callback *cb)
2ec600d6 2795{
2ec600d6
LCC
2796 struct mpath_info pinfo;
2797 struct cfg80211_registered_device *dev;
bba95fef 2798 struct net_device *netdev;
2ec600d6
LCC
2799 u8 dst[ETH_ALEN];
2800 u8 next_hop[ETH_ALEN];
bba95fef 2801 int path_idx = cb->args[1];
2ec600d6 2802 int err;
2ec600d6 2803
67748893
JB
2804 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2805 if (err)
2806 return err;
bba95fef
JB
2807
2808 if (!dev->ops->dump_mpath) {
eec60b03 2809 err = -EOPNOTSUPP;
bba95fef
JB
2810 goto out_err;
2811 }
2812
eec60b03
JM
2813 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2814 err = -EOPNOTSUPP;
0448b5fc 2815 goto out_err;
eec60b03
JM
2816 }
2817
bba95fef
JB
2818 while (1) {
2819 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2820 dst, next_hop, &pinfo);
2821 if (err == -ENOENT)
2ec600d6 2822 break;
bba95fef 2823 if (err)
3b85875a 2824 goto out_err;
2ec600d6 2825
bba95fef
JB
2826 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2827 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2828 netdev, dst, next_hop,
2829 &pinfo) < 0)
2830 goto out;
2ec600d6 2831
bba95fef 2832 path_idx++;
2ec600d6 2833 }
2ec600d6 2834
2ec600d6 2835
bba95fef
JB
2836 out:
2837 cb->args[1] = path_idx;
2838 err = skb->len;
bba95fef 2839 out_err:
67748893 2840 nl80211_finish_netdev_dump(dev);
bba95fef 2841 return err;
2ec600d6
LCC
2842}
2843
2844static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2845{
4c476991 2846 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2847 int err;
4c476991 2848 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2849 struct mpath_info pinfo;
2850 struct sk_buff *msg;
2851 u8 *dst = NULL;
2852 u8 next_hop[ETH_ALEN];
2853
2854 memset(&pinfo, 0, sizeof(pinfo));
2855
2856 if (!info->attrs[NL80211_ATTR_MAC])
2857 return -EINVAL;
2858
2859 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2860
4c476991
JB
2861 if (!rdev->ops->get_mpath)
2862 return -EOPNOTSUPP;
2ec600d6 2863
4c476991
JB
2864 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2865 return -EOPNOTSUPP;
eec60b03 2866
79c97e97 2867 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2868 if (err)
4c476991 2869 return err;
2ec600d6 2870
fd2120ca 2871 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2872 if (!msg)
4c476991 2873 return -ENOMEM;
2ec600d6
LCC
2874
2875 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2876 dev, dst, next_hop, &pinfo) < 0) {
2877 nlmsg_free(msg);
2878 return -ENOBUFS;
2879 }
3b85875a 2880
4c476991 2881 return genlmsg_reply(msg, info);
2ec600d6
LCC
2882}
2883
2884static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2885{
4c476991
JB
2886 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2887 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2888 u8 *dst = NULL;
2889 u8 *next_hop = NULL;
2890
2891 if (!info->attrs[NL80211_ATTR_MAC])
2892 return -EINVAL;
2893
2894 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2895 return -EINVAL;
2896
2897 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2898 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2899
4c476991
JB
2900 if (!rdev->ops->change_mpath)
2901 return -EOPNOTSUPP;
35a8efe1 2902
4c476991
JB
2903 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2904 return -EOPNOTSUPP;
2ec600d6 2905
4c476991 2906 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2907}
4c476991 2908
2ec600d6
LCC
2909static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2910{
4c476991
JB
2911 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2912 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2913 u8 *dst = NULL;
2914 u8 *next_hop = NULL;
2915
2916 if (!info->attrs[NL80211_ATTR_MAC])
2917 return -EINVAL;
2918
2919 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2920 return -EINVAL;
2921
2922 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2923 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2924
4c476991
JB
2925 if (!rdev->ops->add_mpath)
2926 return -EOPNOTSUPP;
35a8efe1 2927
4c476991
JB
2928 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2929 return -EOPNOTSUPP;
2ec600d6 2930
4c476991 2931 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2932}
2933
2934static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2935{
4c476991
JB
2936 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2937 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2938 u8 *dst = NULL;
2939
2940 if (info->attrs[NL80211_ATTR_MAC])
2941 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2942
4c476991
JB
2943 if (!rdev->ops->del_mpath)
2944 return -EOPNOTSUPP;
3b85875a 2945
4c476991 2946 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2947}
2948
9f1ba906
JM
2949static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2950{
4c476991
JB
2951 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2952 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2953 struct bss_parameters params;
2954
2955 memset(&params, 0, sizeof(params));
2956 /* default to not changing parameters */
2957 params.use_cts_prot = -1;
2958 params.use_short_preamble = -1;
2959 params.use_short_slot_time = -1;
fd8aaaf3 2960 params.ap_isolate = -1;
50b12f59 2961 params.ht_opmode = -1;
9f1ba906
JM
2962
2963 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2964 params.use_cts_prot =
2965 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2966 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2967 params.use_short_preamble =
2968 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2969 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2970 params.use_short_slot_time =
2971 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2972 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2973 params.basic_rates =
2974 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2975 params.basic_rates_len =
2976 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2977 }
fd8aaaf3
FF
2978 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2979 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2980 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2981 params.ht_opmode =
2982 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2983
4c476991
JB
2984 if (!rdev->ops->change_bss)
2985 return -EOPNOTSUPP;
9f1ba906 2986
074ac8df 2987 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2988 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2989 return -EOPNOTSUPP;
3b85875a 2990
4c476991 2991 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2992}
2993
b54452b0 2994static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2995 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2996 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2997 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2998 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2999 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3000 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3001};
3002
3003static int parse_reg_rule(struct nlattr *tb[],
3004 struct ieee80211_reg_rule *reg_rule)
3005{
3006 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3007 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3008
3009 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3010 return -EINVAL;
3011 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3012 return -EINVAL;
3013 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3014 return -EINVAL;
3015 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3016 return -EINVAL;
3017 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3018 return -EINVAL;
3019
3020 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3021
3022 freq_range->start_freq_khz =
3023 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3024 freq_range->end_freq_khz =
3025 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3026 freq_range->max_bandwidth_khz =
3027 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3028
3029 power_rule->max_eirp =
3030 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3031
3032 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3033 power_rule->max_antenna_gain =
3034 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3035
3036 return 0;
3037}
3038
3039static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3040{
3041 int r;
3042 char *data = NULL;
3043
80778f18
LR
3044 /*
3045 * You should only get this when cfg80211 hasn't yet initialized
3046 * completely when built-in to the kernel right between the time
3047 * window between nl80211_init() and regulatory_init(), if that is
3048 * even possible.
3049 */
3050 mutex_lock(&cfg80211_mutex);
3051 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3052 mutex_unlock(&cfg80211_mutex);
3053 return -EINPROGRESS;
80778f18 3054 }
fe33eb39 3055 mutex_unlock(&cfg80211_mutex);
80778f18 3056
fe33eb39
LR
3057 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3058 return -EINVAL;
b2e1b302
LR
3059
3060 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3061
fe33eb39
LR
3062 r = regulatory_hint_user(data);
3063
b2e1b302
LR
3064 return r;
3065}
3066
24bdd9f4 3067static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3068 struct genl_info *info)
93da9cc1 3069{
4c476991 3070 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3071 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3072 struct wireless_dev *wdev = dev->ieee80211_ptr;
3073 struct mesh_config cur_params;
3074 int err = 0;
93da9cc1 3075 void *hdr;
3076 struct nlattr *pinfoattr;
3077 struct sk_buff *msg;
3078
29cbe68c
JB
3079 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3080 return -EOPNOTSUPP;
3081
24bdd9f4 3082 if (!rdev->ops->get_mesh_config)
4c476991 3083 return -EOPNOTSUPP;
f3f92586 3084
29cbe68c
JB
3085 wdev_lock(wdev);
3086 /* If not connected, get default parameters */
3087 if (!wdev->mesh_id_len)
3088 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3089 else
24bdd9f4 3090 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3091 &cur_params);
3092 wdev_unlock(wdev);
3093
93da9cc1 3094 if (err)
4c476991 3095 return err;
93da9cc1 3096
3097 /* Draw up a netlink message to send back */
fd2120ca 3098 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3099 if (!msg)
3100 return -ENOMEM;
93da9cc1 3101 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3102 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3103 if (!hdr)
efe1cf0c 3104 goto out;
24bdd9f4 3105 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3106 if (!pinfoattr)
3107 goto nla_put_failure;
3108 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3109 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3110 cur_params.dot11MeshRetryTimeout);
3111 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3112 cur_params.dot11MeshConfirmTimeout);
3113 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3114 cur_params.dot11MeshHoldingTimeout);
3115 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3116 cur_params.dot11MeshMaxPeerLinks);
3117 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
3118 cur_params.dot11MeshMaxRetries);
3119 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
3120 cur_params.dot11MeshTTL);
45904f21
JC
3121 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3122 cur_params.element_ttl);
93da9cc1 3123 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3124 cur_params.auto_open_plinks);
3125 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3126 cur_params.dot11MeshHWMPmaxPREQretries);
3127 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3128 cur_params.path_refresh_time);
3129 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3130 cur_params.min_discovery_timeout);
3131 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3132 cur_params.dot11MeshHWMPactivePathTimeout);
3133 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3134 cur_params.dot11MeshHWMPpreqMinInterval);
3135 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3136 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
3137 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3138 cur_params.dot11MeshHWMPRootMode);
0507e159
JC
3139 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3140 cur_params.dot11MeshHWMPRannInterval);
16dd7267
JC
3141 NLA_PUT_U8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3142 cur_params.dot11MeshGateAnnouncementProtocol);
93da9cc1 3143 nla_nest_end(msg, pinfoattr);
3144 genlmsg_end(msg, hdr);
4c476991 3145 return genlmsg_reply(msg, info);
93da9cc1 3146
3b85875a 3147 nla_put_failure:
93da9cc1 3148 genlmsg_cancel(msg, hdr);
efe1cf0c 3149 out:
d080e275 3150 nlmsg_free(msg);
4c476991 3151 return -ENOBUFS;
93da9cc1 3152}
3153
b54452b0 3154static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3155 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3156 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3157 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3158 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3159 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3160 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3161 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3162 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
3163
3164 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3165 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3166 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3167 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3168 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
3169 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3170 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3171 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3172 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
93da9cc1 3173};
3174
c80d545d
JC
3175static const struct nla_policy
3176 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
3177 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3178 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3179 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3180 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 3181 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3182 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3183};
3184
24bdd9f4 3185static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3186 struct mesh_config *cfg,
3187 u32 *mask_out)
93da9cc1 3188{
93da9cc1 3189 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3190 u32 mask = 0;
93da9cc1 3191
bd90fdcc
JB
3192#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3193do {\
3194 if (table[attr_num]) {\
3195 cfg->param = nla_fn(table[attr_num]); \
3196 mask |= (1 << (attr_num - 1)); \
3197 } \
3198} while (0);\
3199
3200
24bdd9f4 3201 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3202 return -EINVAL;
3203 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3204 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3205 nl80211_meshconf_params_policy))
93da9cc1 3206 return -EINVAL;
3207
93da9cc1 3208 /* This makes sure that there aren't more than 32 mesh config
3209 * parameters (otherwise our bitfield scheme would not work.) */
3210 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3211
3212 /* Fill in the params struct */
93da9cc1 3213 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3214 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3215 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3216 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3217 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3218 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3219 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3220 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3221 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3222 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3223 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3224 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
3225 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3226 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 3227 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3228 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
3229 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3230 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3231 nla_get_u8);
3232 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3233 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3234 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3235 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3236 nla_get_u16);
3237 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3238 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3239 nla_get_u32);
3240 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3241 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3242 nla_get_u16);
3243 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3244 dot11MeshHWMPnetDiameterTraversalTime,
3245 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3246 nla_get_u16);
63c5723b
RP
3247 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3248 dot11MeshHWMPRootMode, mask,
3249 NL80211_MESHCONF_HWMP_ROOTMODE,
3250 nla_get_u8);
0507e159
JC
3251 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3252 dot11MeshHWMPRannInterval, mask,
3253 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3254 nla_get_u16);
16dd7267
JC
3255 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3256 dot11MeshGateAnnouncementProtocol, mask,
3257 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3258 nla_get_u8);
bd90fdcc
JB
3259 if (mask_out)
3260 *mask_out = mask;
c80d545d 3261
bd90fdcc
JB
3262 return 0;
3263
3264#undef FILL_IN_MESH_PARAM_IF_SET
3265}
3266
c80d545d
JC
3267static int nl80211_parse_mesh_setup(struct genl_info *info,
3268 struct mesh_setup *setup)
3269{
3270 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3271
3272 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3273 return -EINVAL;
3274 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3275 info->attrs[NL80211_ATTR_MESH_SETUP],
3276 nl80211_mesh_setup_params_policy))
3277 return -EINVAL;
3278
3279 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3280 setup->path_sel_proto =
3281 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3282 IEEE80211_PATH_PROTOCOL_VENDOR :
3283 IEEE80211_PATH_PROTOCOL_HWMP;
3284
3285 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3286 setup->path_metric =
3287 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3288 IEEE80211_PATH_METRIC_VENDOR :
3289 IEEE80211_PATH_METRIC_AIRTIME;
3290
581a8b0f
JC
3291
3292 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3293 struct nlattr *ieattr =
581a8b0f 3294 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3295 if (!is_valid_ie_attr(ieattr))
3296 return -EINVAL;
581a8b0f
JC
3297 setup->ie = nla_data(ieattr);
3298 setup->ie_len = nla_len(ieattr);
c80d545d 3299 }
b130e5ce
JC
3300 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3301 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3302
3303 return 0;
3304}
3305
24bdd9f4 3306static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3307 struct genl_info *info)
bd90fdcc
JB
3308{
3309 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3310 struct net_device *dev = info->user_ptr[1];
29cbe68c 3311 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3312 struct mesh_config cfg;
3313 u32 mask;
3314 int err;
3315
29cbe68c
JB
3316 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3317 return -EOPNOTSUPP;
3318
24bdd9f4 3319 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3320 return -EOPNOTSUPP;
3321
24bdd9f4 3322 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3323 if (err)
3324 return err;
3325
29cbe68c
JB
3326 wdev_lock(wdev);
3327 if (!wdev->mesh_id_len)
3328 err = -ENOLINK;
3329
3330 if (!err)
24bdd9f4 3331 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3332 mask, &cfg);
3333
3334 wdev_unlock(wdev);
3335
3336 return err;
93da9cc1 3337}
3338
f130347c
LR
3339static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3340{
3341 struct sk_buff *msg;
3342 void *hdr = NULL;
3343 struct nlattr *nl_reg_rules;
3344 unsigned int i;
3345 int err = -EINVAL;
3346
a1794390 3347 mutex_lock(&cfg80211_mutex);
f130347c
LR
3348
3349 if (!cfg80211_regdomain)
3350 goto out;
3351
fd2120ca 3352 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3353 if (!msg) {
3354 err = -ENOBUFS;
3355 goto out;
3356 }
3357
3358 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3359 NL80211_CMD_GET_REG);
3360 if (!hdr)
efe1cf0c 3361 goto put_failure;
f130347c
LR
3362
3363 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3364 cfg80211_regdomain->alpha2);
3365
3366 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3367 if (!nl_reg_rules)
3368 goto nla_put_failure;
3369
3370 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3371 struct nlattr *nl_reg_rule;
3372 const struct ieee80211_reg_rule *reg_rule;
3373 const struct ieee80211_freq_range *freq_range;
3374 const struct ieee80211_power_rule *power_rule;
3375
3376 reg_rule = &cfg80211_regdomain->reg_rules[i];
3377 freq_range = &reg_rule->freq_range;
3378 power_rule = &reg_rule->power_rule;
3379
3380 nl_reg_rule = nla_nest_start(msg, i);
3381 if (!nl_reg_rule)
3382 goto nla_put_failure;
3383
3384 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3385 reg_rule->flags);
3386 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3387 freq_range->start_freq_khz);
3388 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3389 freq_range->end_freq_khz);
3390 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3391 freq_range->max_bandwidth_khz);
3392 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3393 power_rule->max_antenna_gain);
3394 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3395 power_rule->max_eirp);
3396
3397 nla_nest_end(msg, nl_reg_rule);
3398 }
3399
3400 nla_nest_end(msg, nl_reg_rules);
3401
3402 genlmsg_end(msg, hdr);
134e6375 3403 err = genlmsg_reply(msg, info);
f130347c
LR
3404 goto out;
3405
3406nla_put_failure:
3407 genlmsg_cancel(msg, hdr);
efe1cf0c 3408put_failure:
d080e275 3409 nlmsg_free(msg);
f130347c
LR
3410 err = -EMSGSIZE;
3411out:
a1794390 3412 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3413 return err;
3414}
3415
b2e1b302
LR
3416static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3417{
3418 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3419 struct nlattr *nl_reg_rule;
3420 char *alpha2 = NULL;
3421 int rem_reg_rules = 0, r = 0;
3422 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3423 struct ieee80211_regdomain *rd = NULL;
3424
3425 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3426 return -EINVAL;
3427
3428 if (!info->attrs[NL80211_ATTR_REG_RULES])
3429 return -EINVAL;
3430
3431 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3432
3433 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3434 rem_reg_rules) {
3435 num_rules++;
3436 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3437 return -EINVAL;
b2e1b302
LR
3438 }
3439
61405e97
LR
3440 mutex_lock(&cfg80211_mutex);
3441
d0e18f83
LR
3442 if (!reg_is_valid_request(alpha2)) {
3443 r = -EINVAL;
3444 goto bad_reg;
3445 }
b2e1b302
LR
3446
3447 size_of_regd = sizeof(struct ieee80211_regdomain) +
3448 (num_rules * sizeof(struct ieee80211_reg_rule));
3449
3450 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3451 if (!rd) {
3452 r = -ENOMEM;
3453 goto bad_reg;
3454 }
b2e1b302
LR
3455
3456 rd->n_reg_rules = num_rules;
3457 rd->alpha2[0] = alpha2[0];
3458 rd->alpha2[1] = alpha2[1];
3459
3460 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3461 rem_reg_rules) {
3462 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3463 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3464 reg_rule_policy);
3465 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3466 if (r)
3467 goto bad_reg;
3468
3469 rule_idx++;
3470
d0e18f83
LR
3471 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3472 r = -EINVAL;
b2e1b302 3473 goto bad_reg;
d0e18f83 3474 }
b2e1b302
LR
3475 }
3476
3477 BUG_ON(rule_idx != num_rules);
3478
b2e1b302 3479 r = set_regdom(rd);
61405e97 3480
a1794390 3481 mutex_unlock(&cfg80211_mutex);
d0e18f83 3482
b2e1b302
LR
3483 return r;
3484
d2372b31 3485 bad_reg:
61405e97 3486 mutex_unlock(&cfg80211_mutex);
b2e1b302 3487 kfree(rd);
d0e18f83 3488 return r;
b2e1b302
LR
3489}
3490
83f5e2cf
JB
3491static int validate_scan_freqs(struct nlattr *freqs)
3492{
3493 struct nlattr *attr1, *attr2;
3494 int n_channels = 0, tmp1, tmp2;
3495
3496 nla_for_each_nested(attr1, freqs, tmp1) {
3497 n_channels++;
3498 /*
3499 * Some hardware has a limited channel list for
3500 * scanning, and it is pretty much nonsensical
3501 * to scan for a channel twice, so disallow that
3502 * and don't require drivers to check that the
3503 * channel list they get isn't longer than what
3504 * they can scan, as long as they can scan all
3505 * the channels they registered at once.
3506 */
3507 nla_for_each_nested(attr2, freqs, tmp2)
3508 if (attr1 != attr2 &&
3509 nla_get_u32(attr1) == nla_get_u32(attr2))
3510 return 0;
3511 }
3512
3513 return n_channels;
3514}
3515
2a519311
JB
3516static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3517{
4c476991
JB
3518 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3519 struct net_device *dev = info->user_ptr[1];
2a519311 3520 struct cfg80211_scan_request *request;
2a519311
JB
3521 struct nlattr *attr;
3522 struct wiphy *wiphy;
83f5e2cf 3523 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 3524 size_t ie_len;
2a519311 3525
f4a11bb0
JB
3526 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3527 return -EINVAL;
3528
79c97e97 3529 wiphy = &rdev->wiphy;
2a519311 3530
4c476991
JB
3531 if (!rdev->ops->scan)
3532 return -EOPNOTSUPP;
2a519311 3533
4c476991
JB
3534 if (rdev->scan_req)
3535 return -EBUSY;
2a519311
JB
3536
3537 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3538 n_channels = validate_scan_freqs(
3539 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3540 if (!n_channels)
3541 return -EINVAL;
2a519311 3542 } else {
34850ab2 3543 enum ieee80211_band band;
83f5e2cf
JB
3544 n_channels = 0;
3545
2a519311
JB
3546 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3547 if (wiphy->bands[band])
3548 n_channels += wiphy->bands[band]->n_channels;
3549 }
3550
3551 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3552 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3553 n_ssids++;
3554
4c476991
JB
3555 if (n_ssids > wiphy->max_scan_ssids)
3556 return -EINVAL;
2a519311 3557
70692ad2
JM
3558 if (info->attrs[NL80211_ATTR_IE])
3559 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3560 else
3561 ie_len = 0;
3562
4c476991
JB
3563 if (ie_len > wiphy->max_scan_ie_len)
3564 return -EINVAL;
18a83659 3565
2a519311 3566 request = kzalloc(sizeof(*request)
a2cd43c5
LC
3567 + sizeof(*request->ssids) * n_ssids
3568 + sizeof(*request->channels) * n_channels
70692ad2 3569 + ie_len, GFP_KERNEL);
4c476991
JB
3570 if (!request)
3571 return -ENOMEM;
2a519311 3572
2a519311 3573 if (n_ssids)
5ba63533 3574 request->ssids = (void *)&request->channels[n_channels];
2a519311 3575 request->n_ssids = n_ssids;
70692ad2
JM
3576 if (ie_len) {
3577 if (request->ssids)
3578 request->ie = (void *)(request->ssids + n_ssids);
3579 else
3580 request->ie = (void *)(request->channels + n_channels);
3581 }
2a519311 3582
584991dc 3583 i = 0;
2a519311
JB
3584 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3585 /* user specified, bail out if channel not found */
2a519311 3586 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3587 struct ieee80211_channel *chan;
3588
3589 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3590
3591 if (!chan) {
2a519311
JB
3592 err = -EINVAL;
3593 goto out_free;
3594 }
584991dc
JB
3595
3596 /* ignore disabled channels */
3597 if (chan->flags & IEEE80211_CHAN_DISABLED)
3598 continue;
3599
3600 request->channels[i] = chan;
2a519311
JB
3601 i++;
3602 }
3603 } else {
34850ab2
JB
3604 enum ieee80211_band band;
3605
2a519311 3606 /* all channels */
2a519311
JB
3607 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3608 int j;
3609 if (!wiphy->bands[band])
3610 continue;
3611 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3612 struct ieee80211_channel *chan;
3613
3614 chan = &wiphy->bands[band]->channels[j];
3615
3616 if (chan->flags & IEEE80211_CHAN_DISABLED)
3617 continue;
3618
3619 request->channels[i] = chan;
2a519311
JB
3620 i++;
3621 }
3622 }
3623 }
3624
584991dc
JB
3625 if (!i) {
3626 err = -EINVAL;
3627 goto out_free;
3628 }
3629
3630 request->n_channels = i;
3631
2a519311
JB
3632 i = 0;
3633 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3634 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 3635 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
3636 err = -EINVAL;
3637 goto out_free;
3638 }
57a27e1d 3639 request->ssids[i].ssid_len = nla_len(attr);
2a519311 3640 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
3641 i++;
3642 }
3643 }
3644
70692ad2
JM
3645 if (info->attrs[NL80211_ATTR_IE]) {
3646 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3647 memcpy((void *)request->ie,
3648 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3649 request->ie_len);
3650 }
3651
34850ab2 3652 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
3653 if (wiphy->bands[i])
3654 request->rates[i] =
3655 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
3656
3657 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
3658 nla_for_each_nested(attr,
3659 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
3660 tmp) {
3661 enum ieee80211_band band = nla_type(attr);
3662
84404623 3663 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
3664 err = -EINVAL;
3665 goto out_free;
3666 }
3667 err = ieee80211_get_ratemask(wiphy->bands[band],
3668 nla_data(attr),
3669 nla_len(attr),
3670 &request->rates[band]);
3671 if (err)
3672 goto out_free;
3673 }
3674 }
3675
e9f935e3
RM
3676 request->no_cck =
3677 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
3678
463d0183 3679 request->dev = dev;
79c97e97 3680 request->wiphy = &rdev->wiphy;
2a519311 3681
79c97e97
JB
3682 rdev->scan_req = request;
3683 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3684
463d0183 3685 if (!err) {
79c97e97 3686 nl80211_send_scan_start(rdev, dev);
463d0183 3687 dev_hold(dev);
4c476991 3688 } else {
2a519311 3689 out_free:
79c97e97 3690 rdev->scan_req = NULL;
2a519311
JB
3691 kfree(request);
3692 }
3b85875a 3693
2a519311
JB
3694 return err;
3695}
3696
807f8a8c
LC
3697static int nl80211_start_sched_scan(struct sk_buff *skb,
3698 struct genl_info *info)
3699{
3700 struct cfg80211_sched_scan_request *request;
3701 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3702 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
3703 struct nlattr *attr;
3704 struct wiphy *wiphy;
a1f1c21c 3705 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 3706 u32 interval;
807f8a8c
LC
3707 enum ieee80211_band band;
3708 size_t ie_len;
a1f1c21c 3709 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
3710
3711 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3712 !rdev->ops->sched_scan_start)
3713 return -EOPNOTSUPP;
3714
3715 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3716 return -EINVAL;
3717
bbe6ad6d
LC
3718 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3719 return -EINVAL;
3720
3721 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3722 if (interval == 0)
3723 return -EINVAL;
3724
807f8a8c
LC
3725 wiphy = &rdev->wiphy;
3726
3727 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3728 n_channels = validate_scan_freqs(
3729 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3730 if (!n_channels)
3731 return -EINVAL;
3732 } else {
3733 n_channels = 0;
3734
3735 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3736 if (wiphy->bands[band])
3737 n_channels += wiphy->bands[band]->n_channels;
3738 }
3739
3740 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3741 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3742 tmp)
3743 n_ssids++;
3744
93b6aa69 3745 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
3746 return -EINVAL;
3747
a1f1c21c
LC
3748 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
3749 nla_for_each_nested(attr,
3750 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3751 tmp)
3752 n_match_sets++;
3753
3754 if (n_match_sets > wiphy->max_match_sets)
3755 return -EINVAL;
3756
807f8a8c
LC
3757 if (info->attrs[NL80211_ATTR_IE])
3758 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3759 else
3760 ie_len = 0;
3761
5a865bad 3762 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
3763 return -EINVAL;
3764
c10841ca
LC
3765 mutex_lock(&rdev->sched_scan_mtx);
3766
3767 if (rdev->sched_scan_req) {
3768 err = -EINPROGRESS;
3769 goto out;
3770 }
3771
807f8a8c 3772 request = kzalloc(sizeof(*request)
a2cd43c5 3773 + sizeof(*request->ssids) * n_ssids
a1f1c21c 3774 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 3775 + sizeof(*request->channels) * n_channels
807f8a8c 3776 + ie_len, GFP_KERNEL);
c10841ca
LC
3777 if (!request) {
3778 err = -ENOMEM;
3779 goto out;
3780 }
807f8a8c
LC
3781
3782 if (n_ssids)
3783 request->ssids = (void *)&request->channels[n_channels];
3784 request->n_ssids = n_ssids;
3785 if (ie_len) {
3786 if (request->ssids)
3787 request->ie = (void *)(request->ssids + n_ssids);
3788 else
3789 request->ie = (void *)(request->channels + n_channels);
3790 }
3791
a1f1c21c
LC
3792 if (n_match_sets) {
3793 if (request->ie)
3794 request->match_sets = (void *)(request->ie + ie_len);
3795 else if (request->ssids)
3796 request->match_sets =
3797 (void *)(request->ssids + n_ssids);
3798 else
3799 request->match_sets =
3800 (void *)(request->channels + n_channels);
3801 }
3802 request->n_match_sets = n_match_sets;
3803
807f8a8c
LC
3804 i = 0;
3805 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3806 /* user specified, bail out if channel not found */
3807 nla_for_each_nested(attr,
3808 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
3809 tmp) {
3810 struct ieee80211_channel *chan;
3811
3812 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3813
3814 if (!chan) {
3815 err = -EINVAL;
3816 goto out_free;
3817 }
3818
3819 /* ignore disabled channels */
3820 if (chan->flags & IEEE80211_CHAN_DISABLED)
3821 continue;
3822
3823 request->channels[i] = chan;
3824 i++;
3825 }
3826 } else {
3827 /* all channels */
3828 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3829 int j;
3830 if (!wiphy->bands[band])
3831 continue;
3832 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3833 struct ieee80211_channel *chan;
3834
3835 chan = &wiphy->bands[band]->channels[j];
3836
3837 if (chan->flags & IEEE80211_CHAN_DISABLED)
3838 continue;
3839
3840 request->channels[i] = chan;
3841 i++;
3842 }
3843 }
3844 }
3845
3846 if (!i) {
3847 err = -EINVAL;
3848 goto out_free;
3849 }
3850
3851 request->n_channels = i;
3852
3853 i = 0;
3854 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3855 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3856 tmp) {
57a27e1d 3857 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
3858 err = -EINVAL;
3859 goto out_free;
3860 }
57a27e1d 3861 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
3862 memcpy(request->ssids[i].ssid, nla_data(attr),
3863 nla_len(attr));
807f8a8c
LC
3864 i++;
3865 }
3866 }
3867
a1f1c21c
LC
3868 i = 0;
3869 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
3870 nla_for_each_nested(attr,
3871 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3872 tmp) {
3873 struct nlattr *ssid;
3874
3875 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
3876 nla_data(attr), nla_len(attr),
3877 nl80211_match_policy);
3878 ssid = tb[NL80211_ATTR_SCHED_SCAN_MATCH_SSID];
3879 if (ssid) {
3880 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
3881 err = -EINVAL;
3882 goto out_free;
3883 }
3884 memcpy(request->match_sets[i].ssid.ssid,
3885 nla_data(ssid), nla_len(ssid));
3886 request->match_sets[i].ssid.ssid_len =
3887 nla_len(ssid);
3888 }
3889 i++;
3890 }
3891 }
3892
807f8a8c
LC
3893 if (info->attrs[NL80211_ATTR_IE]) {
3894 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3895 memcpy((void *)request->ie,
3896 nla_data(info->attrs[NL80211_ATTR_IE]),
3897 request->ie_len);
3898 }
3899
3900 request->dev = dev;
3901 request->wiphy = &rdev->wiphy;
bbe6ad6d 3902 request->interval = interval;
807f8a8c
LC
3903
3904 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
3905 if (!err) {
3906 rdev->sched_scan_req = request;
3907 nl80211_send_sched_scan(rdev, dev,
3908 NL80211_CMD_START_SCHED_SCAN);
3909 goto out;
3910 }
3911
3912out_free:
3913 kfree(request);
3914out:
c10841ca 3915 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
3916 return err;
3917}
3918
3919static int nl80211_stop_sched_scan(struct sk_buff *skb,
3920 struct genl_info *info)
3921{
3922 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 3923 int err;
807f8a8c
LC
3924
3925 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3926 !rdev->ops->sched_scan_stop)
3927 return -EOPNOTSUPP;
3928
c10841ca
LC
3929 mutex_lock(&rdev->sched_scan_mtx);
3930 err = __cfg80211_stop_sched_scan(rdev, false);
3931 mutex_unlock(&rdev->sched_scan_mtx);
3932
3933 return err;
807f8a8c
LC
3934}
3935
9720bb3a
JB
3936static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
3937 u32 seq, int flags,
2a519311 3938 struct cfg80211_registered_device *rdev,
48ab905d
JB
3939 struct wireless_dev *wdev,
3940 struct cfg80211_internal_bss *intbss)
2a519311 3941{
48ab905d 3942 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3943 void *hdr;
3944 struct nlattr *bss;
48ab905d
JB
3945 int i;
3946
3947 ASSERT_WDEV_LOCK(wdev);
2a519311 3948
9720bb3a 3949 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
3950 NL80211_CMD_NEW_SCAN_RESULTS);
3951 if (!hdr)
3952 return -1;
3953
9720bb3a
JB
3954 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
3955
f5ea9120 3956 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3957 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3958
3959 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3960 if (!bss)
3961 goto nla_put_failure;
3962 if (!is_zero_ether_addr(res->bssid))
3963 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3964 if (res->information_elements && res->len_information_elements)
3965 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3966 res->len_information_elements,
3967 res->information_elements);
34a6eddb
JM
3968 if (res->beacon_ies && res->len_beacon_ies &&
3969 res->beacon_ies != res->information_elements)
3970 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3971 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3972 if (res->tsf)
3973 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3974 if (res->beacon_interval)
3975 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3976 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3977 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3978 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3979 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3980
77965c97 3981 switch (rdev->wiphy.signal_type) {
2a519311
JB
3982 case CFG80211_SIGNAL_TYPE_MBM:
3983 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3984 break;
3985 case CFG80211_SIGNAL_TYPE_UNSPEC:
3986 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3987 break;
3988 default:
3989 break;
3990 }
3991
48ab905d 3992 switch (wdev->iftype) {
074ac8df 3993 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3994 case NL80211_IFTYPE_STATION:
3995 if (intbss == wdev->current_bss)
3996 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3997 NL80211_BSS_STATUS_ASSOCIATED);
3998 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3999 if (intbss != wdev->auth_bsses[i])
4000 continue;
4001 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4002 NL80211_BSS_STATUS_AUTHENTICATED);
4003 break;
4004 }
4005 break;
4006 case NL80211_IFTYPE_ADHOC:
4007 if (intbss == wdev->current_bss)
4008 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4009 NL80211_BSS_STATUS_IBSS_JOINED);
4010 break;
4011 default:
4012 break;
4013 }
4014
2a519311
JB
4015 nla_nest_end(msg, bss);
4016
4017 return genlmsg_end(msg, hdr);
4018
4019 nla_put_failure:
4020 genlmsg_cancel(msg, hdr);
4021 return -EMSGSIZE;
4022}
4023
4024static int nl80211_dump_scan(struct sk_buff *skb,
4025 struct netlink_callback *cb)
4026{
48ab905d
JB
4027 struct cfg80211_registered_device *rdev;
4028 struct net_device *dev;
2a519311 4029 struct cfg80211_internal_bss *scan;
48ab905d 4030 struct wireless_dev *wdev;
2a519311
JB
4031 int start = cb->args[1], idx = 0;
4032 int err;
4033
67748893
JB
4034 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4035 if (err)
4036 return err;
2a519311 4037
48ab905d 4038 wdev = dev->ieee80211_ptr;
2a519311 4039
48ab905d
JB
4040 wdev_lock(wdev);
4041 spin_lock_bh(&rdev->bss_lock);
4042 cfg80211_bss_expire(rdev);
4043
9720bb3a
JB
4044 cb->seq = rdev->bss_generation;
4045
48ab905d 4046 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4047 if (++idx <= start)
4048 continue;
9720bb3a 4049 if (nl80211_send_bss(skb, cb,
2a519311 4050 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4051 rdev, wdev, scan) < 0) {
2a519311 4052 idx--;
67748893 4053 break;
2a519311
JB
4054 }
4055 }
4056
48ab905d
JB
4057 spin_unlock_bh(&rdev->bss_lock);
4058 wdev_unlock(wdev);
2a519311
JB
4059
4060 cb->args[1] = idx;
67748893 4061 nl80211_finish_netdev_dump(rdev);
2a519311 4062
67748893 4063 return skb->len;
2a519311
JB
4064}
4065
61fa713c
HS
4066static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4067 int flags, struct net_device *dev,
4068 struct survey_info *survey)
4069{
4070 void *hdr;
4071 struct nlattr *infoattr;
4072
61fa713c
HS
4073 hdr = nl80211hdr_put(msg, pid, seq, flags,
4074 NL80211_CMD_NEW_SURVEY_RESULTS);
4075 if (!hdr)
4076 return -ENOMEM;
4077
4078 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
4079
4080 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4081 if (!infoattr)
4082 goto nla_put_failure;
4083
4084 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4085 survey->channel->center_freq);
4086 if (survey->filled & SURVEY_INFO_NOISE_DBM)
4087 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
4088 survey->noise);
17e5a808
FF
4089 if (survey->filled & SURVEY_INFO_IN_USE)
4090 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
4091 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
4092 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4093 survey->channel_time);
4094 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
4095 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4096 survey->channel_time_busy);
4097 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
4098 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4099 survey->channel_time_ext_busy);
4100 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
4101 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4102 survey->channel_time_rx);
4103 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
4104 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4105 survey->channel_time_tx);
61fa713c
HS
4106
4107 nla_nest_end(msg, infoattr);
4108
4109 return genlmsg_end(msg, hdr);
4110
4111 nla_put_failure:
4112 genlmsg_cancel(msg, hdr);
4113 return -EMSGSIZE;
4114}
4115
4116static int nl80211_dump_survey(struct sk_buff *skb,
4117 struct netlink_callback *cb)
4118{
4119 struct survey_info survey;
4120 struct cfg80211_registered_device *dev;
4121 struct net_device *netdev;
61fa713c
HS
4122 int survey_idx = cb->args[1];
4123 int res;
4124
67748893
JB
4125 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4126 if (res)
4127 return res;
61fa713c
HS
4128
4129 if (!dev->ops->dump_survey) {
4130 res = -EOPNOTSUPP;
4131 goto out_err;
4132 }
4133
4134 while (1) {
180cdc79
LR
4135 struct ieee80211_channel *chan;
4136
61fa713c
HS
4137 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4138 &survey);
4139 if (res == -ENOENT)
4140 break;
4141 if (res)
4142 goto out_err;
4143
180cdc79
LR
4144 /* Survey without a channel doesn't make sense */
4145 if (!survey.channel) {
4146 res = -EINVAL;
4147 goto out;
4148 }
4149
4150 chan = ieee80211_get_channel(&dev->wiphy,
4151 survey.channel->center_freq);
4152 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4153 survey_idx++;
4154 continue;
4155 }
4156
61fa713c
HS
4157 if (nl80211_send_survey(skb,
4158 NETLINK_CB(cb->skb).pid,
4159 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4160 netdev,
4161 &survey) < 0)
4162 goto out;
4163 survey_idx++;
4164 }
4165
4166 out:
4167 cb->args[1] = survey_idx;
4168 res = skb->len;
4169 out_err:
67748893 4170 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4171 return res;
4172}
4173
255e737e
JM
4174static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4175{
b23aa676
SO
4176 return auth_type <= NL80211_AUTHTYPE_MAX;
4177}
4178
4179static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4180{
4181 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4182 NL80211_WPA_VERSION_2));
4183}
4184
636a5d36
JM
4185static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4186{
4c476991
JB
4187 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4188 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4189 struct ieee80211_channel *chan;
4190 const u8 *bssid, *ssid, *ie = NULL;
4191 int err, ssid_len, ie_len = 0;
4192 enum nl80211_auth_type auth_type;
fffd0934 4193 struct key_parse key;
d5cdfacb 4194 bool local_state_change;
636a5d36 4195
f4a11bb0
JB
4196 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4197 return -EINVAL;
4198
4199 if (!info->attrs[NL80211_ATTR_MAC])
4200 return -EINVAL;
4201
1778092e
JM
4202 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4203 return -EINVAL;
4204
19957bb3
JB
4205 if (!info->attrs[NL80211_ATTR_SSID])
4206 return -EINVAL;
4207
4208 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4209 return -EINVAL;
4210
fffd0934
JB
4211 err = nl80211_parse_key(info, &key);
4212 if (err)
4213 return err;
4214
4215 if (key.idx >= 0) {
e31b8213
JB
4216 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4217 return -EINVAL;
fffd0934
JB
4218 if (!key.p.key || !key.p.key_len)
4219 return -EINVAL;
4220 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4221 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4222 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4223 key.p.key_len != WLAN_KEY_LEN_WEP104))
4224 return -EINVAL;
4225 if (key.idx > 4)
4226 return -EINVAL;
4227 } else {
4228 key.p.key_len = 0;
4229 key.p.key = NULL;
4230 }
4231
afea0b7a
JB
4232 if (key.idx >= 0) {
4233 int i;
4234 bool ok = false;
4235 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4236 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4237 ok = true;
4238 break;
4239 }
4240 }
4c476991
JB
4241 if (!ok)
4242 return -EINVAL;
afea0b7a
JB
4243 }
4244
4c476991
JB
4245 if (!rdev->ops->auth)
4246 return -EOPNOTSUPP;
636a5d36 4247
074ac8df 4248 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4249 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4250 return -EOPNOTSUPP;
eec60b03 4251
19957bb3 4252 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4253 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4254 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4255 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4256 return -EINVAL;
636a5d36 4257
19957bb3
JB
4258 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4259 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4260
4261 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4262 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4263 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4264 }
4265
19957bb3 4266 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4267 if (!nl80211_valid_auth_type(auth_type))
4268 return -EINVAL;
636a5d36 4269
d5cdfacb
JM
4270 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4271
4c476991
JB
4272 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4273 ssid, ssid_len, ie, ie_len,
4274 key.p.key, key.p.key_len, key.idx,
4275 local_state_change);
636a5d36
JM
4276}
4277
c0692b8f
JB
4278static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4279 struct genl_info *info,
3dc27d25
JB
4280 struct cfg80211_crypto_settings *settings,
4281 int cipher_limit)
b23aa676 4282{
c0b2bbd8
JB
4283 memset(settings, 0, sizeof(*settings));
4284
b23aa676
SO
4285 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4286
c0692b8f
JB
4287 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4288 u16 proto;
4289 proto = nla_get_u16(
4290 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4291 settings->control_port_ethertype = cpu_to_be16(proto);
4292 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4293 proto != ETH_P_PAE)
4294 return -EINVAL;
4295 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4296 settings->control_port_no_encrypt = true;
4297 } else
4298 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4299
b23aa676
SO
4300 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4301 void *data;
4302 int len, i;
4303
4304 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4305 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4306 settings->n_ciphers_pairwise = len / sizeof(u32);
4307
4308 if (len % sizeof(u32))
4309 return -EINVAL;
4310
3dc27d25 4311 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4312 return -EINVAL;
4313
4314 memcpy(settings->ciphers_pairwise, data, len);
4315
4316 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4317 if (!cfg80211_supported_cipher_suite(
4318 &rdev->wiphy,
b23aa676
SO
4319 settings->ciphers_pairwise[i]))
4320 return -EINVAL;
4321 }
4322
4323 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4324 settings->cipher_group =
4325 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4326 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4327 settings->cipher_group))
b23aa676
SO
4328 return -EINVAL;
4329 }
4330
4331 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4332 settings->wpa_versions =
4333 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4334 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4335 return -EINVAL;
4336 }
4337
4338 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4339 void *data;
6d30240e 4340 int len;
b23aa676
SO
4341
4342 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4343 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4344 settings->n_akm_suites = len / sizeof(u32);
4345
4346 if (len % sizeof(u32))
4347 return -EINVAL;
4348
1b9ca027
JM
4349 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4350 return -EINVAL;
4351
b23aa676 4352 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4353 }
4354
4355 return 0;
4356}
4357
636a5d36
JM
4358static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4359{
4c476991
JB
4360 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4361 struct net_device *dev = info->user_ptr[1];
19957bb3 4362 struct cfg80211_crypto_settings crypto;
f444de05 4363 struct ieee80211_channel *chan;
3e5d7649 4364 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4365 int err, ssid_len, ie_len = 0;
4366 bool use_mfp = false;
636a5d36 4367
f4a11bb0
JB
4368 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4369 return -EINVAL;
4370
4371 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4372 !info->attrs[NL80211_ATTR_SSID] ||
4373 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4374 return -EINVAL;
4375
4c476991
JB
4376 if (!rdev->ops->assoc)
4377 return -EOPNOTSUPP;
636a5d36 4378
074ac8df 4379 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4380 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4381 return -EOPNOTSUPP;
eec60b03 4382
19957bb3 4383 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4384
19957bb3
JB
4385 chan = ieee80211_get_channel(&rdev->wiphy,
4386 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4387 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4388 return -EINVAL;
636a5d36 4389
19957bb3
JB
4390 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4391 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4392
4393 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4394 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4395 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4396 }
4397
dc6382ce 4398 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4399 enum nl80211_mfp mfp =
dc6382ce 4400 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4401 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4402 use_mfp = true;
4c476991
JB
4403 else if (mfp != NL80211_MFP_NO)
4404 return -EINVAL;
dc6382ce
JM
4405 }
4406
3e5d7649
JB
4407 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4408 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4409
c0692b8f 4410 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4411 if (!err)
3e5d7649
JB
4412 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4413 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 4414 &crypto);
636a5d36 4415
636a5d36
JM
4416 return err;
4417}
4418
4419static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4420{
4c476991
JB
4421 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4422 struct net_device *dev = info->user_ptr[1];
19957bb3 4423 const u8 *ie = NULL, *bssid;
4c476991 4424 int ie_len = 0;
19957bb3 4425 u16 reason_code;
d5cdfacb 4426 bool local_state_change;
636a5d36 4427
f4a11bb0
JB
4428 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4429 return -EINVAL;
4430
4431 if (!info->attrs[NL80211_ATTR_MAC])
4432 return -EINVAL;
4433
4434 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4435 return -EINVAL;
4436
4c476991
JB
4437 if (!rdev->ops->deauth)
4438 return -EOPNOTSUPP;
636a5d36 4439
074ac8df 4440 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4441 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4442 return -EOPNOTSUPP;
eec60b03 4443
19957bb3 4444 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4445
19957bb3
JB
4446 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4447 if (reason_code == 0) {
f4a11bb0 4448 /* Reason Code 0 is reserved */
4c476991 4449 return -EINVAL;
255e737e 4450 }
636a5d36
JM
4451
4452 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4453 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4454 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4455 }
4456
d5cdfacb
JM
4457 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4458
4c476991
JB
4459 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4460 local_state_change);
636a5d36
JM
4461}
4462
4463static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4464{
4c476991
JB
4465 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4466 struct net_device *dev = info->user_ptr[1];
19957bb3 4467 const u8 *ie = NULL, *bssid;
4c476991 4468 int ie_len = 0;
19957bb3 4469 u16 reason_code;
d5cdfacb 4470 bool local_state_change;
636a5d36 4471
f4a11bb0
JB
4472 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4473 return -EINVAL;
4474
4475 if (!info->attrs[NL80211_ATTR_MAC])
4476 return -EINVAL;
4477
4478 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4479 return -EINVAL;
4480
4c476991
JB
4481 if (!rdev->ops->disassoc)
4482 return -EOPNOTSUPP;
636a5d36 4483
074ac8df 4484 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4485 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4486 return -EOPNOTSUPP;
eec60b03 4487
19957bb3 4488 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4489
19957bb3
JB
4490 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4491 if (reason_code == 0) {
f4a11bb0 4492 /* Reason Code 0 is reserved */
4c476991 4493 return -EINVAL;
255e737e 4494 }
636a5d36
JM
4495
4496 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4497 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4498 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4499 }
4500
d5cdfacb
JM
4501 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4502
4c476991
JB
4503 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4504 local_state_change);
636a5d36
JM
4505}
4506
dd5b4cc7
FF
4507static bool
4508nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4509 int mcast_rate[IEEE80211_NUM_BANDS],
4510 int rateval)
4511{
4512 struct wiphy *wiphy = &rdev->wiphy;
4513 bool found = false;
4514 int band, i;
4515
4516 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4517 struct ieee80211_supported_band *sband;
4518
4519 sband = wiphy->bands[band];
4520 if (!sband)
4521 continue;
4522
4523 for (i = 0; i < sband->n_bitrates; i++) {
4524 if (sband->bitrates[i].bitrate == rateval) {
4525 mcast_rate[band] = i + 1;
4526 found = true;
4527 break;
4528 }
4529 }
4530 }
4531
4532 return found;
4533}
4534
04a773ad
JB
4535static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4536{
4c476991
JB
4537 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4538 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4539 struct cfg80211_ibss_params ibss;
4540 struct wiphy *wiphy;
fffd0934 4541 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4542 int err;
4543
8e30bc55
JB
4544 memset(&ibss, 0, sizeof(ibss));
4545
04a773ad
JB
4546 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4547 return -EINVAL;
4548
4549 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4550 !info->attrs[NL80211_ATTR_SSID] ||
4551 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4552 return -EINVAL;
4553
8e30bc55
JB
4554 ibss.beacon_interval = 100;
4555
4556 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4557 ibss.beacon_interval =
4558 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4559 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4560 return -EINVAL;
4561 }
4562
4c476991
JB
4563 if (!rdev->ops->join_ibss)
4564 return -EOPNOTSUPP;
04a773ad 4565
4c476991
JB
4566 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4567 return -EOPNOTSUPP;
04a773ad 4568
79c97e97 4569 wiphy = &rdev->wiphy;
04a773ad 4570
39193498 4571 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 4572 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
4573
4574 if (!is_valid_ether_addr(ibss.bssid))
4575 return -EINVAL;
4576 }
04a773ad
JB
4577 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4578 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4579
4580 if (info->attrs[NL80211_ATTR_IE]) {
4581 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4582 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4583 }
4584
4585 ibss.channel = ieee80211_get_channel(wiphy,
4586 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4587 if (!ibss.channel ||
4588 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4589 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4590 return -EINVAL;
04a773ad
JB
4591
4592 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4593 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4594
fbd2c8dc
TP
4595 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4596 u8 *rates =
4597 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4598 int n_rates =
4599 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4600 struct ieee80211_supported_band *sband =
4601 wiphy->bands[ibss.channel->band];
34850ab2 4602 int err;
fbd2c8dc 4603
34850ab2
JB
4604 err = ieee80211_get_ratemask(sband, rates, n_rates,
4605 &ibss.basic_rates);
4606 if (err)
4607 return err;
fbd2c8dc 4608 }
dd5b4cc7
FF
4609
4610 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4611 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4612 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4613 return -EINVAL;
fbd2c8dc 4614
4c476991
JB
4615 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4616 connkeys = nl80211_parse_connkeys(rdev,
4617 info->attrs[NL80211_ATTR_KEYS]);
4618 if (IS_ERR(connkeys))
4619 return PTR_ERR(connkeys);
4620 }
04a773ad 4621
4c476991 4622 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4623 if (err)
4624 kfree(connkeys);
04a773ad
JB
4625 return err;
4626}
4627
4628static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4629{
4c476991
JB
4630 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4631 struct net_device *dev = info->user_ptr[1];
04a773ad 4632
4c476991
JB
4633 if (!rdev->ops->leave_ibss)
4634 return -EOPNOTSUPP;
04a773ad 4635
4c476991
JB
4636 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4637 return -EOPNOTSUPP;
04a773ad 4638
4c476991 4639 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4640}
4641
aff89a9b
JB
4642#ifdef CONFIG_NL80211_TESTMODE
4643static struct genl_multicast_group nl80211_testmode_mcgrp = {
4644 .name = "testmode",
4645};
4646
4647static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4648{
4c476991 4649 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4650 int err;
4651
4652 if (!info->attrs[NL80211_ATTR_TESTDATA])
4653 return -EINVAL;
4654
aff89a9b
JB
4655 err = -EOPNOTSUPP;
4656 if (rdev->ops->testmode_cmd) {
4657 rdev->testmode_info = info;
4658 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4659 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4660 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4661 rdev->testmode_info = NULL;
4662 }
4663
aff89a9b
JB
4664 return err;
4665}
4666
71063f0e
WYG
4667static int nl80211_testmode_dump(struct sk_buff *skb,
4668 struct netlink_callback *cb)
4669{
4670 struct cfg80211_registered_device *dev;
4671 int err;
4672 long phy_idx;
4673 void *data = NULL;
4674 int data_len = 0;
4675
4676 if (cb->args[0]) {
4677 /*
4678 * 0 is a valid index, but not valid for args[0],
4679 * so we need to offset by 1.
4680 */
4681 phy_idx = cb->args[0] - 1;
4682 } else {
4683 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
4684 nl80211_fam.attrbuf, nl80211_fam.maxattr,
4685 nl80211_policy);
4686 if (err)
4687 return err;
4688 if (!nl80211_fam.attrbuf[NL80211_ATTR_WIPHY])
4689 return -EINVAL;
4690 phy_idx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
4691 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
4692 cb->args[1] =
4693 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
4694 }
4695
4696 if (cb->args[1]) {
4697 data = nla_data((void *)cb->args[1]);
4698 data_len = nla_len((void *)cb->args[1]);
4699 }
4700
4701 mutex_lock(&cfg80211_mutex);
4702 dev = cfg80211_rdev_by_wiphy_idx(phy_idx);
4703 if (!dev) {
4704 mutex_unlock(&cfg80211_mutex);
4705 return -ENOENT;
4706 }
4707 cfg80211_lock_rdev(dev);
4708 mutex_unlock(&cfg80211_mutex);
4709
4710 if (!dev->ops->testmode_dump) {
4711 err = -EOPNOTSUPP;
4712 goto out_err;
4713 }
4714
4715 while (1) {
4716 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
4717 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4718 NL80211_CMD_TESTMODE);
4719 struct nlattr *tmdata;
4720
4721 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, dev->wiphy_idx) < 0) {
4722 genlmsg_cancel(skb, hdr);
4723 break;
4724 }
4725
4726 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4727 if (!tmdata) {
4728 genlmsg_cancel(skb, hdr);
4729 break;
4730 }
4731 err = dev->ops->testmode_dump(&dev->wiphy, skb, cb,
4732 data, data_len);
4733 nla_nest_end(skb, tmdata);
4734
4735 if (err == -ENOBUFS || err == -ENOENT) {
4736 genlmsg_cancel(skb, hdr);
4737 break;
4738 } else if (err) {
4739 genlmsg_cancel(skb, hdr);
4740 goto out_err;
4741 }
4742
4743 genlmsg_end(skb, hdr);
4744 }
4745
4746 err = skb->len;
4747 /* see above */
4748 cb->args[0] = phy_idx + 1;
4749 out_err:
4750 cfg80211_unlock_rdev(dev);
4751 return err;
4752}
4753
aff89a9b
JB
4754static struct sk_buff *
4755__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4756 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4757{
4758 struct sk_buff *skb;
4759 void *hdr;
4760 struct nlattr *data;
4761
4762 skb = nlmsg_new(approxlen + 100, gfp);
4763 if (!skb)
4764 return NULL;
4765
4766 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4767 if (!hdr) {
4768 kfree_skb(skb);
4769 return NULL;
4770 }
4771
4772 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4773 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4774
4775 ((void **)skb->cb)[0] = rdev;
4776 ((void **)skb->cb)[1] = hdr;
4777 ((void **)skb->cb)[2] = data;
4778
4779 return skb;
4780
4781 nla_put_failure:
4782 kfree_skb(skb);
4783 return NULL;
4784}
4785
4786struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4787 int approxlen)
4788{
4789 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4790
4791 if (WARN_ON(!rdev->testmode_info))
4792 return NULL;
4793
4794 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4795 rdev->testmode_info->snd_pid,
4796 rdev->testmode_info->snd_seq,
4797 GFP_KERNEL);
4798}
4799EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4800
4801int cfg80211_testmode_reply(struct sk_buff *skb)
4802{
4803 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4804 void *hdr = ((void **)skb->cb)[1];
4805 struct nlattr *data = ((void **)skb->cb)[2];
4806
4807 if (WARN_ON(!rdev->testmode_info)) {
4808 kfree_skb(skb);
4809 return -EINVAL;
4810 }
4811
4812 nla_nest_end(skb, data);
4813 genlmsg_end(skb, hdr);
4814 return genlmsg_reply(skb, rdev->testmode_info);
4815}
4816EXPORT_SYMBOL(cfg80211_testmode_reply);
4817
4818struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4819 int approxlen, gfp_t gfp)
4820{
4821 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4822
4823 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4824}
4825EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4826
4827void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4828{
4829 void *hdr = ((void **)skb->cb)[1];
4830 struct nlattr *data = ((void **)skb->cb)[2];
4831
4832 nla_nest_end(skb, data);
4833 genlmsg_end(skb, hdr);
4834 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4835}
4836EXPORT_SYMBOL(cfg80211_testmode_event);
4837#endif
4838
b23aa676
SO
4839static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4840{
4c476991
JB
4841 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4842 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4843 struct cfg80211_connect_params connect;
4844 struct wiphy *wiphy;
fffd0934 4845 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4846 int err;
4847
4848 memset(&connect, 0, sizeof(connect));
4849
4850 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4851 return -EINVAL;
4852
4853 if (!info->attrs[NL80211_ATTR_SSID] ||
4854 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4855 return -EINVAL;
4856
4857 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4858 connect.auth_type =
4859 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4860 if (!nl80211_valid_auth_type(connect.auth_type))
4861 return -EINVAL;
4862 } else
4863 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4864
4865 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4866
c0692b8f 4867 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4868 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4869 if (err)
4870 return err;
b23aa676 4871
074ac8df 4872 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4873 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4874 return -EOPNOTSUPP;
b23aa676 4875
79c97e97 4876 wiphy = &rdev->wiphy;
b23aa676 4877
b23aa676
SO
4878 if (info->attrs[NL80211_ATTR_MAC])
4879 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4880 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4881 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4882
4883 if (info->attrs[NL80211_ATTR_IE]) {
4884 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4885 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4886 }
4887
4888 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4889 connect.channel =
4890 ieee80211_get_channel(wiphy,
4891 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4892 if (!connect.channel ||
4c476991
JB
4893 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4894 return -EINVAL;
b23aa676
SO
4895 }
4896
fffd0934
JB
4897 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4898 connkeys = nl80211_parse_connkeys(rdev,
4899 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4900 if (IS_ERR(connkeys))
4901 return PTR_ERR(connkeys);
fffd0934
JB
4902 }
4903
4904 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4905 if (err)
4906 kfree(connkeys);
b23aa676
SO
4907 return err;
4908}
4909
4910static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4911{
4c476991
JB
4912 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4913 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4914 u16 reason;
4915
4916 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4917 reason = WLAN_REASON_DEAUTH_LEAVING;
4918 else
4919 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4920
4921 if (reason == 0)
4922 return -EINVAL;
4923
074ac8df 4924 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4925 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4926 return -EOPNOTSUPP;
b23aa676 4927
4c476991 4928 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4929}
4930
463d0183
JB
4931static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4932{
4c476991 4933 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4934 struct net *net;
4935 int err;
4936 u32 pid;
4937
4938 if (!info->attrs[NL80211_ATTR_PID])
4939 return -EINVAL;
4940
4941 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4942
463d0183 4943 net = get_net_ns_by_pid(pid);
4c476991
JB
4944 if (IS_ERR(net))
4945 return PTR_ERR(net);
463d0183
JB
4946
4947 err = 0;
4948
4949 /* check if anything to do */
4c476991
JB
4950 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4951 err = cfg80211_switch_netns(rdev, net);
463d0183 4952
463d0183 4953 put_net(net);
463d0183
JB
4954 return err;
4955}
4956
67fbb16b
SO
4957static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4958{
4c476991 4959 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4960 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4961 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4962 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4963 struct cfg80211_pmksa pmksa;
4964
4965 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4966
4967 if (!info->attrs[NL80211_ATTR_MAC])
4968 return -EINVAL;
4969
4970 if (!info->attrs[NL80211_ATTR_PMKID])
4971 return -EINVAL;
4972
67fbb16b
SO
4973 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4974 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4975
074ac8df 4976 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4977 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4978 return -EOPNOTSUPP;
67fbb16b
SO
4979
4980 switch (info->genlhdr->cmd) {
4981 case NL80211_CMD_SET_PMKSA:
4982 rdev_ops = rdev->ops->set_pmksa;
4983 break;
4984 case NL80211_CMD_DEL_PMKSA:
4985 rdev_ops = rdev->ops->del_pmksa;
4986 break;
4987 default:
4988 WARN_ON(1);
4989 break;
4990 }
4991
4c476991
JB
4992 if (!rdev_ops)
4993 return -EOPNOTSUPP;
67fbb16b 4994
4c476991 4995 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4996}
4997
4998static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4999{
4c476991
JB
5000 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5001 struct net_device *dev = info->user_ptr[1];
67fbb16b 5002
074ac8df 5003 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5004 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5005 return -EOPNOTSUPP;
67fbb16b 5006
4c476991
JB
5007 if (!rdev->ops->flush_pmksa)
5008 return -EOPNOTSUPP;
67fbb16b 5009
4c476991 5010 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5011}
5012
109086ce
AN
5013static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5014{
5015 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5016 struct net_device *dev = info->user_ptr[1];
5017 u8 action_code, dialog_token;
5018 u16 status_code;
5019 u8 *peer;
5020
5021 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5022 !rdev->ops->tdls_mgmt)
5023 return -EOPNOTSUPP;
5024
5025 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5026 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5027 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5028 !info->attrs[NL80211_ATTR_IE] ||
5029 !info->attrs[NL80211_ATTR_MAC])
5030 return -EINVAL;
5031
5032 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5033 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5034 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5035 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5036
5037 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5038 dialog_token, status_code,
5039 nla_data(info->attrs[NL80211_ATTR_IE]),
5040 nla_len(info->attrs[NL80211_ATTR_IE]));
5041}
5042
5043static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5044{
5045 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5046 struct net_device *dev = info->user_ptr[1];
5047 enum nl80211_tdls_operation operation;
5048 u8 *peer;
5049
5050 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5051 !rdev->ops->tdls_oper)
5052 return -EOPNOTSUPP;
5053
5054 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5055 !info->attrs[NL80211_ATTR_MAC])
5056 return -EINVAL;
5057
5058 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5059 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5060
5061 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5062}
5063
9588bbd5
JM
5064static int nl80211_remain_on_channel(struct sk_buff *skb,
5065 struct genl_info *info)
5066{
4c476991
JB
5067 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5068 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5069 struct ieee80211_channel *chan;
5070 struct sk_buff *msg;
5071 void *hdr;
5072 u64 cookie;
5073 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5074 u32 freq, duration;
5075 int err;
5076
5077 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5078 !info->attrs[NL80211_ATTR_DURATION])
5079 return -EINVAL;
5080
5081 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5082
5083 /*
5084 * We should be on that channel for at least one jiffie,
5085 * and more than 5 seconds seems excessive.
5086 */
a293911d
JB
5087 if (!duration || !msecs_to_jiffies(duration) ||
5088 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5089 return -EINVAL;
5090
4c476991
JB
5091 if (!rdev->ops->remain_on_channel)
5092 return -EOPNOTSUPP;
9588bbd5 5093
9588bbd5
JM
5094 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5095 channel_type = nla_get_u32(
5096 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5097 if (channel_type != NL80211_CHAN_NO_HT &&
5098 channel_type != NL80211_CHAN_HT20 &&
5099 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5100 channel_type != NL80211_CHAN_HT40MINUS)
5101 return -EINVAL;
9588bbd5
JM
5102 }
5103
5104 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5105 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5106 if (chan == NULL)
5107 return -EINVAL;
9588bbd5
JM
5108
5109 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5110 if (!msg)
5111 return -ENOMEM;
9588bbd5
JM
5112
5113 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5114 NL80211_CMD_REMAIN_ON_CHANNEL);
5115
5116 if (IS_ERR(hdr)) {
5117 err = PTR_ERR(hdr);
5118 goto free_msg;
5119 }
5120
5121 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5122 channel_type, duration, &cookie);
5123
5124 if (err)
5125 goto free_msg;
5126
5127 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5128
5129 genlmsg_end(msg, hdr);
4c476991
JB
5130
5131 return genlmsg_reply(msg, info);
9588bbd5
JM
5132
5133 nla_put_failure:
5134 err = -ENOBUFS;
5135 free_msg:
5136 nlmsg_free(msg);
9588bbd5
JM
5137 return err;
5138}
5139
5140static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5141 struct genl_info *info)
5142{
4c476991
JB
5143 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5144 struct net_device *dev = info->user_ptr[1];
9588bbd5 5145 u64 cookie;
9588bbd5
JM
5146
5147 if (!info->attrs[NL80211_ATTR_COOKIE])
5148 return -EINVAL;
5149
4c476991
JB
5150 if (!rdev->ops->cancel_remain_on_channel)
5151 return -EOPNOTSUPP;
9588bbd5 5152
9588bbd5
JM
5153 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5154
4c476991 5155 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5156}
5157
13ae75b1
JM
5158static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5159 u8 *rates, u8 rates_len)
5160{
5161 u8 i;
5162 u32 mask = 0;
5163
5164 for (i = 0; i < rates_len; i++) {
5165 int rate = (rates[i] & 0x7f) * 5;
5166 int ridx;
5167 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5168 struct ieee80211_rate *srate =
5169 &sband->bitrates[ridx];
5170 if (rate == srate->bitrate) {
5171 mask |= 1 << ridx;
5172 break;
5173 }
5174 }
5175 if (ridx == sband->n_bitrates)
5176 return 0; /* rate not found */
5177 }
5178
5179 return mask;
5180}
5181
b54452b0 5182static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5183 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5184 .len = NL80211_MAX_SUPP_RATES },
5185};
5186
5187static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5188 struct genl_info *info)
5189{
5190 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5191 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5192 struct cfg80211_bitrate_mask mask;
4c476991
JB
5193 int rem, i;
5194 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5195 struct nlattr *tx_rates;
5196 struct ieee80211_supported_band *sband;
5197
5198 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5199 return -EINVAL;
5200
4c476991
JB
5201 if (!rdev->ops->set_bitrate_mask)
5202 return -EOPNOTSUPP;
13ae75b1
JM
5203
5204 memset(&mask, 0, sizeof(mask));
5205 /* Default to all rates enabled */
5206 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5207 sband = rdev->wiphy.bands[i];
5208 mask.control[i].legacy =
5209 sband ? (1 << sband->n_bitrates) - 1 : 0;
5210 }
5211
5212 /*
5213 * The nested attribute uses enum nl80211_band as the index. This maps
5214 * directly to the enum ieee80211_band values used in cfg80211.
5215 */
5216 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5217 {
5218 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5219 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5220 return -EINVAL;
13ae75b1 5221 sband = rdev->wiphy.bands[band];
4c476991
JB
5222 if (sband == NULL)
5223 return -EINVAL;
13ae75b1
JM
5224 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5225 nla_len(tx_rates), nl80211_txattr_policy);
5226 if (tb[NL80211_TXRATE_LEGACY]) {
5227 mask.control[band].legacy = rateset_to_mask(
5228 sband,
5229 nla_data(tb[NL80211_TXRATE_LEGACY]),
5230 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
5231 if (mask.control[band].legacy == 0)
5232 return -EINVAL;
13ae75b1
JM
5233 }
5234 }
5235
4c476991 5236 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5237}
5238
2e161f78 5239static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5240{
4c476991
JB
5241 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5242 struct net_device *dev = info->user_ptr[1];
2e161f78 5243 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5244
5245 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5246 return -EINVAL;
5247
2e161f78
JB
5248 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5249 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5250
9d38d85d 5251 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5252 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5253 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5254 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5255 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5256 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5257 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5258 return -EOPNOTSUPP;
026331c4
JM
5259
5260 /* not much point in registering if we can't reply */
4c476991
JB
5261 if (!rdev->ops->mgmt_tx)
5262 return -EOPNOTSUPP;
026331c4 5263
4c476991 5264 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 5265 frame_type,
026331c4
JM
5266 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5267 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
5268}
5269
2e161f78 5270static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5271{
4c476991
JB
5272 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5273 struct net_device *dev = info->user_ptr[1];
026331c4
JM
5274 struct ieee80211_channel *chan;
5275 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 5276 bool channel_type_valid = false;
026331c4
JM
5277 u32 freq;
5278 int err;
5279 void *hdr;
5280 u64 cookie;
5281 struct sk_buff *msg;
f7ca38df
JB
5282 unsigned int wait = 0;
5283 bool offchan;
e9f935e3 5284 bool no_cck;
026331c4
JM
5285
5286 if (!info->attrs[NL80211_ATTR_FRAME] ||
5287 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5288 return -EINVAL;
5289
4c476991
JB
5290 if (!rdev->ops->mgmt_tx)
5291 return -EOPNOTSUPP;
026331c4 5292
9d38d85d 5293 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5294 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5295 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5296 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5297 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5298 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5299 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5300 return -EOPNOTSUPP;
026331c4 5301
f7ca38df
JB
5302 if (info->attrs[NL80211_ATTR_DURATION]) {
5303 if (!rdev->ops->mgmt_tx_cancel_wait)
5304 return -EINVAL;
5305 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5306 }
5307
026331c4
JM
5308 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5309 channel_type = nla_get_u32(
5310 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5311 if (channel_type != NL80211_CHAN_NO_HT &&
5312 channel_type != NL80211_CHAN_HT20 &&
5313 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5314 channel_type != NL80211_CHAN_HT40MINUS)
5315 return -EINVAL;
252aa631 5316 channel_type_valid = true;
026331c4
JM
5317 }
5318
f7ca38df
JB
5319 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5320
e9f935e3
RM
5321 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5322
026331c4
JM
5323 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5324 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5325 if (chan == NULL)
5326 return -EINVAL;
026331c4
JM
5327
5328 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5329 if (!msg)
5330 return -ENOMEM;
026331c4
JM
5331
5332 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 5333 NL80211_CMD_FRAME);
026331c4
JM
5334
5335 if (IS_ERR(hdr)) {
5336 err = PTR_ERR(hdr);
5337 goto free_msg;
5338 }
f7ca38df
JB
5339 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5340 channel_type_valid, wait,
2e161f78
JB
5341 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5342 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e9f935e3 5343 no_cck, &cookie);
026331c4
JM
5344 if (err)
5345 goto free_msg;
5346
5347 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5348
5349 genlmsg_end(msg, hdr);
4c476991 5350 return genlmsg_reply(msg, info);
026331c4
JM
5351
5352 nla_put_failure:
5353 err = -ENOBUFS;
5354 free_msg:
5355 nlmsg_free(msg);
026331c4
JM
5356 return err;
5357}
5358
f7ca38df
JB
5359static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5360{
5361 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5362 struct net_device *dev = info->user_ptr[1];
5363 u64 cookie;
5364
5365 if (!info->attrs[NL80211_ATTR_COOKIE])
5366 return -EINVAL;
5367
5368 if (!rdev->ops->mgmt_tx_cancel_wait)
5369 return -EOPNOTSUPP;
5370
5371 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5372 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5373 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5374 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5375 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5376 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5377 return -EOPNOTSUPP;
5378
5379 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5380
5381 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5382}
5383
ffb9eb3d
KV
5384static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5385{
4c476991 5386 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 5387 struct wireless_dev *wdev;
4c476991 5388 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5389 u8 ps_state;
5390 bool state;
5391 int err;
5392
4c476991
JB
5393 if (!info->attrs[NL80211_ATTR_PS_STATE])
5394 return -EINVAL;
ffb9eb3d
KV
5395
5396 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5397
4c476991
JB
5398 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5399 return -EINVAL;
ffb9eb3d
KV
5400
5401 wdev = dev->ieee80211_ptr;
5402
4c476991
JB
5403 if (!rdev->ops->set_power_mgmt)
5404 return -EOPNOTSUPP;
ffb9eb3d
KV
5405
5406 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5407
5408 if (state == wdev->ps)
4c476991 5409 return 0;
ffb9eb3d 5410
4c476991
JB
5411 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5412 wdev->ps_timeout);
5413 if (!err)
5414 wdev->ps = state;
ffb9eb3d
KV
5415 return err;
5416}
5417
5418static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5419{
4c476991 5420 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
5421 enum nl80211_ps_state ps_state;
5422 struct wireless_dev *wdev;
4c476991 5423 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5424 struct sk_buff *msg;
5425 void *hdr;
5426 int err;
5427
ffb9eb3d
KV
5428 wdev = dev->ieee80211_ptr;
5429
4c476991
JB
5430 if (!rdev->ops->set_power_mgmt)
5431 return -EOPNOTSUPP;
ffb9eb3d
KV
5432
5433 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5434 if (!msg)
5435 return -ENOMEM;
ffb9eb3d
KV
5436
5437 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5438 NL80211_CMD_GET_POWER_SAVE);
5439 if (!hdr) {
4c476991 5440 err = -ENOBUFS;
ffb9eb3d
KV
5441 goto free_msg;
5442 }
5443
5444 if (wdev->ps)
5445 ps_state = NL80211_PS_ENABLED;
5446 else
5447 ps_state = NL80211_PS_DISABLED;
5448
5449 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5450
5451 genlmsg_end(msg, hdr);
4c476991 5452 return genlmsg_reply(msg, info);
ffb9eb3d 5453
4c476991 5454 nla_put_failure:
ffb9eb3d 5455 err = -ENOBUFS;
4c476991 5456 free_msg:
ffb9eb3d 5457 nlmsg_free(msg);
ffb9eb3d
KV
5458 return err;
5459}
5460
d6dc1a38
JO
5461static struct nla_policy
5462nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5463 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5464 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5465 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5466};
5467
5468static int nl80211_set_cqm_rssi(struct genl_info *info,
5469 s32 threshold, u32 hysteresis)
5470{
4c476991 5471 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 5472 struct wireless_dev *wdev;
4c476991 5473 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
5474
5475 if (threshold > 0)
5476 return -EINVAL;
5477
d6dc1a38
JO
5478 wdev = dev->ieee80211_ptr;
5479
4c476991
JB
5480 if (!rdev->ops->set_cqm_rssi_config)
5481 return -EOPNOTSUPP;
d6dc1a38 5482
074ac8df 5483 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5484 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
5485 return -EOPNOTSUPP;
d6dc1a38 5486
4c476991
JB
5487 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5488 threshold, hysteresis);
d6dc1a38
JO
5489}
5490
5491static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5492{
5493 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5494 struct nlattr *cqm;
5495 int err;
5496
5497 cqm = info->attrs[NL80211_ATTR_CQM];
5498 if (!cqm) {
5499 err = -EINVAL;
5500 goto out;
5501 }
5502
5503 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5504 nl80211_attr_cqm_policy);
5505 if (err)
5506 goto out;
5507
5508 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5509 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5510 s32 threshold;
5511 u32 hysteresis;
5512 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5513 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5514 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5515 } else
5516 err = -EINVAL;
5517
5518out:
5519 return err;
5520}
5521
29cbe68c
JB
5522static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5523{
5524 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5525 struct net_device *dev = info->user_ptr[1];
5526 struct mesh_config cfg;
c80d545d 5527 struct mesh_setup setup;
29cbe68c
JB
5528 int err;
5529
5530 /* start with default */
5531 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 5532 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 5533
24bdd9f4 5534 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 5535 /* and parse parameters if given */
24bdd9f4 5536 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
5537 if (err)
5538 return err;
5539 }
5540
5541 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5542 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5543 return -EINVAL;
5544
c80d545d
JC
5545 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5546 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5547
5548 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5549 /* parse additional setup parameters if given */
5550 err = nl80211_parse_mesh_setup(info, &setup);
5551 if (err)
5552 return err;
5553 }
5554
5555 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
5556}
5557
5558static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5559{
5560 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5561 struct net_device *dev = info->user_ptr[1];
5562
5563 return cfg80211_leave_mesh(rdev, dev);
5564}
5565
ff1b6e69
JB
5566static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5567{
5568 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5569 struct sk_buff *msg;
5570 void *hdr;
5571
5572 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5573 return -EOPNOTSUPP;
5574
5575 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5576 if (!msg)
5577 return -ENOMEM;
5578
5579 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5580 NL80211_CMD_GET_WOWLAN);
5581 if (!hdr)
5582 goto nla_put_failure;
5583
5584 if (rdev->wowlan) {
5585 struct nlattr *nl_wowlan;
5586
5587 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5588 if (!nl_wowlan)
5589 goto nla_put_failure;
5590
5591 if (rdev->wowlan->any)
5592 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5593 if (rdev->wowlan->disconnect)
5594 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5595 if (rdev->wowlan->magic_pkt)
5596 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
5597 if (rdev->wowlan->gtk_rekey_failure)
5598 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
5599 if (rdev->wowlan->eap_identity_req)
5600 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
5601 if (rdev->wowlan->four_way_handshake)
5602 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
5603 if (rdev->wowlan->rfkill_release)
5604 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
5605 if (rdev->wowlan->n_patterns) {
5606 struct nlattr *nl_pats, *nl_pat;
5607 int i, pat_len;
5608
5609 nl_pats = nla_nest_start(msg,
5610 NL80211_WOWLAN_TRIG_PKT_PATTERN);
5611 if (!nl_pats)
5612 goto nla_put_failure;
5613
5614 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5615 nl_pat = nla_nest_start(msg, i + 1);
5616 if (!nl_pat)
5617 goto nla_put_failure;
5618 pat_len = rdev->wowlan->patterns[i].pattern_len;
5619 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5620 DIV_ROUND_UP(pat_len, 8),
5621 rdev->wowlan->patterns[i].mask);
5622 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5623 pat_len,
5624 rdev->wowlan->patterns[i].pattern);
5625 nla_nest_end(msg, nl_pat);
5626 }
5627 nla_nest_end(msg, nl_pats);
5628 }
5629
5630 nla_nest_end(msg, nl_wowlan);
5631 }
5632
5633 genlmsg_end(msg, hdr);
5634 return genlmsg_reply(msg, info);
5635
5636nla_put_failure:
5637 nlmsg_free(msg);
5638 return -ENOBUFS;
5639}
5640
5641static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
5642{
5643 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5644 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
5645 struct cfg80211_wowlan no_triggers = {};
5646 struct cfg80211_wowlan new_triggers = {};
5647 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
5648 int err, i;
5649
5650 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5651 return -EOPNOTSUPP;
5652
5653 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
5654 goto no_triggers;
5655
5656 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
5657 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5658 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5659 nl80211_wowlan_policy);
5660 if (err)
5661 return err;
5662
5663 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
5664 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
5665 return -EINVAL;
5666 new_triggers.any = true;
5667 }
5668
5669 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
5670 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
5671 return -EINVAL;
5672 new_triggers.disconnect = true;
5673 }
5674
5675 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
5676 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
5677 return -EINVAL;
5678 new_triggers.magic_pkt = true;
5679 }
5680
77dbbb13
JB
5681 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
5682 return -EINVAL;
5683
5684 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
5685 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
5686 return -EINVAL;
5687 new_triggers.gtk_rekey_failure = true;
5688 }
5689
5690 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
5691 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
5692 return -EINVAL;
5693 new_triggers.eap_identity_req = true;
5694 }
5695
5696 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
5697 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
5698 return -EINVAL;
5699 new_triggers.four_way_handshake = true;
5700 }
5701
5702 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
5703 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
5704 return -EINVAL;
5705 new_triggers.rfkill_release = true;
5706 }
5707
ff1b6e69
JB
5708 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
5709 struct nlattr *pat;
5710 int n_patterns = 0;
5711 int rem, pat_len, mask_len;
5712 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
5713
5714 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5715 rem)
5716 n_patterns++;
5717 if (n_patterns > wowlan->n_patterns)
5718 return -EINVAL;
5719
5720 new_triggers.patterns = kcalloc(n_patterns,
5721 sizeof(new_triggers.patterns[0]),
5722 GFP_KERNEL);
5723 if (!new_triggers.patterns)
5724 return -ENOMEM;
5725
5726 new_triggers.n_patterns = n_patterns;
5727 i = 0;
5728
5729 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5730 rem) {
5731 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
5732 nla_data(pat), nla_len(pat), NULL);
5733 err = -EINVAL;
5734 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
5735 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
5736 goto error;
5737 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
5738 mask_len = DIV_ROUND_UP(pat_len, 8);
5739 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
5740 mask_len)
5741 goto error;
5742 if (pat_len > wowlan->pattern_max_len ||
5743 pat_len < wowlan->pattern_min_len)
5744 goto error;
5745
5746 new_triggers.patterns[i].mask =
5747 kmalloc(mask_len + pat_len, GFP_KERNEL);
5748 if (!new_triggers.patterns[i].mask) {
5749 err = -ENOMEM;
5750 goto error;
5751 }
5752 new_triggers.patterns[i].pattern =
5753 new_triggers.patterns[i].mask + mask_len;
5754 memcpy(new_triggers.patterns[i].mask,
5755 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
5756 mask_len);
5757 new_triggers.patterns[i].pattern_len = pat_len;
5758 memcpy(new_triggers.patterns[i].pattern,
5759 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
5760 pat_len);
5761 i++;
5762 }
5763 }
5764
5765 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
5766 struct cfg80211_wowlan *ntrig;
5767 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
5768 GFP_KERNEL);
5769 if (!ntrig) {
5770 err = -ENOMEM;
5771 goto error;
5772 }
5773 cfg80211_rdev_free_wowlan(rdev);
5774 rdev->wowlan = ntrig;
5775 } else {
5776 no_triggers:
5777 cfg80211_rdev_free_wowlan(rdev);
5778 rdev->wowlan = NULL;
5779 }
5780
5781 return 0;
5782 error:
5783 for (i = 0; i < new_triggers.n_patterns; i++)
5784 kfree(new_triggers.patterns[i].mask);
5785 kfree(new_triggers.patterns);
5786 return err;
5787}
5788
e5497d76
JB
5789static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
5790{
5791 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5792 struct net_device *dev = info->user_ptr[1];
5793 struct wireless_dev *wdev = dev->ieee80211_ptr;
5794 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
5795 struct cfg80211_gtk_rekey_data rekey_data;
5796 int err;
5797
5798 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
5799 return -EINVAL;
5800
5801 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
5802 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
5803 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
5804 nl80211_rekey_policy);
5805 if (err)
5806 return err;
5807
5808 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
5809 return -ERANGE;
5810 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
5811 return -ERANGE;
5812 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
5813 return -ERANGE;
5814
5815 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
5816 NL80211_KEK_LEN);
5817 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
5818 NL80211_KCK_LEN);
5819 memcpy(rekey_data.replay_ctr,
5820 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
5821 NL80211_REPLAY_CTR_LEN);
5822
5823 wdev_lock(wdev);
5824 if (!wdev->current_bss) {
5825 err = -ENOTCONN;
5826 goto out;
5827 }
5828
5829 if (!rdev->ops->set_rekey_data) {
5830 err = -EOPNOTSUPP;
5831 goto out;
5832 }
5833
5834 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
5835 out:
5836 wdev_unlock(wdev);
5837 return err;
5838}
5839
28946da7
JB
5840static int nl80211_register_unexpected_frame(struct sk_buff *skb,
5841 struct genl_info *info)
5842{
5843 struct net_device *dev = info->user_ptr[1];
5844 struct wireless_dev *wdev = dev->ieee80211_ptr;
5845
5846 if (wdev->iftype != NL80211_IFTYPE_AP &&
5847 wdev->iftype != NL80211_IFTYPE_P2P_GO)
5848 return -EINVAL;
5849
5850 if (wdev->ap_unexpected_nlpid)
5851 return -EBUSY;
5852
5853 wdev->ap_unexpected_nlpid = info->snd_pid;
5854 return 0;
5855}
5856
7f6cf311
JB
5857static int nl80211_probe_client(struct sk_buff *skb,
5858 struct genl_info *info)
5859{
5860 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5861 struct net_device *dev = info->user_ptr[1];
5862 struct wireless_dev *wdev = dev->ieee80211_ptr;
5863 struct sk_buff *msg;
5864 void *hdr;
5865 const u8 *addr;
5866 u64 cookie;
5867 int err;
5868
5869 if (wdev->iftype != NL80211_IFTYPE_AP &&
5870 wdev->iftype != NL80211_IFTYPE_P2P_GO)
5871 return -EOPNOTSUPP;
5872
5873 if (!info->attrs[NL80211_ATTR_MAC])
5874 return -EINVAL;
5875
5876 if (!rdev->ops->probe_client)
5877 return -EOPNOTSUPP;
5878
5879 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5880 if (!msg)
5881 return -ENOMEM;
5882
5883 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5884 NL80211_CMD_PROBE_CLIENT);
5885
5886 if (IS_ERR(hdr)) {
5887 err = PTR_ERR(hdr);
5888 goto free_msg;
5889 }
5890
5891 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5892
5893 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
5894 if (err)
5895 goto free_msg;
5896
5897 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5898
5899 genlmsg_end(msg, hdr);
5900
5901 return genlmsg_reply(msg, info);
5902
5903 nla_put_failure:
5904 err = -ENOBUFS;
5905 free_msg:
5906 nlmsg_free(msg);
5907 return err;
5908}
5909
4c476991
JB
5910#define NL80211_FLAG_NEED_WIPHY 0x01
5911#define NL80211_FLAG_NEED_NETDEV 0x02
5912#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
5913#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
5914#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
5915 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
5916
5917static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
5918 struct genl_info *info)
5919{
5920 struct cfg80211_registered_device *rdev;
5921 struct net_device *dev;
5922 int err;
5923 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
5924
5925 if (rtnl)
5926 rtnl_lock();
5927
5928 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
5929 rdev = cfg80211_get_dev_from_info(info);
5930 if (IS_ERR(rdev)) {
5931 if (rtnl)
5932 rtnl_unlock();
5933 return PTR_ERR(rdev);
5934 }
5935 info->user_ptr[0] = rdev;
5936 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
5937 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5938 if (err) {
5939 if (rtnl)
5940 rtnl_unlock();
5941 return err;
5942 }
41265714
JB
5943 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
5944 !netif_running(dev)) {
d537f5fd
JB
5945 cfg80211_unlock_rdev(rdev);
5946 dev_put(dev);
41265714
JB
5947 if (rtnl)
5948 rtnl_unlock();
5949 return -ENETDOWN;
5950 }
4c476991
JB
5951 info->user_ptr[0] = rdev;
5952 info->user_ptr[1] = dev;
5953 }
5954
5955 return 0;
5956}
5957
5958static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
5959 struct genl_info *info)
5960{
5961 if (info->user_ptr[0])
5962 cfg80211_unlock_rdev(info->user_ptr[0]);
5963 if (info->user_ptr[1])
5964 dev_put(info->user_ptr[1]);
5965 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
5966 rtnl_unlock();
5967}
5968
55682965
JB
5969static struct genl_ops nl80211_ops[] = {
5970 {
5971 .cmd = NL80211_CMD_GET_WIPHY,
5972 .doit = nl80211_get_wiphy,
5973 .dumpit = nl80211_dump_wiphy,
5974 .policy = nl80211_policy,
5975 /* can be retrieved by unprivileged users */
4c476991 5976 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
5977 },
5978 {
5979 .cmd = NL80211_CMD_SET_WIPHY,
5980 .doit = nl80211_set_wiphy,
5981 .policy = nl80211_policy,
5982 .flags = GENL_ADMIN_PERM,
4c476991 5983 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
5984 },
5985 {
5986 .cmd = NL80211_CMD_GET_INTERFACE,
5987 .doit = nl80211_get_interface,
5988 .dumpit = nl80211_dump_interface,
5989 .policy = nl80211_policy,
5990 /* can be retrieved by unprivileged users */
4c476991 5991 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
5992 },
5993 {
5994 .cmd = NL80211_CMD_SET_INTERFACE,
5995 .doit = nl80211_set_interface,
5996 .policy = nl80211_policy,
5997 .flags = GENL_ADMIN_PERM,
4c476991
JB
5998 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5999 NL80211_FLAG_NEED_RTNL,
55682965
JB
6000 },
6001 {
6002 .cmd = NL80211_CMD_NEW_INTERFACE,
6003 .doit = nl80211_new_interface,
6004 .policy = nl80211_policy,
6005 .flags = GENL_ADMIN_PERM,
4c476991
JB
6006 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6007 NL80211_FLAG_NEED_RTNL,
55682965
JB
6008 },
6009 {
6010 .cmd = NL80211_CMD_DEL_INTERFACE,
6011 .doit = nl80211_del_interface,
6012 .policy = nl80211_policy,
41ade00f 6013 .flags = GENL_ADMIN_PERM,
4c476991
JB
6014 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6015 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6016 },
6017 {
6018 .cmd = NL80211_CMD_GET_KEY,
6019 .doit = nl80211_get_key,
6020 .policy = nl80211_policy,
6021 .flags = GENL_ADMIN_PERM,
4c476991
JB
6022 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6023 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6024 },
6025 {
6026 .cmd = NL80211_CMD_SET_KEY,
6027 .doit = nl80211_set_key,
6028 .policy = nl80211_policy,
6029 .flags = GENL_ADMIN_PERM,
41265714 6030 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6031 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6032 },
6033 {
6034 .cmd = NL80211_CMD_NEW_KEY,
6035 .doit = nl80211_new_key,
6036 .policy = nl80211_policy,
6037 .flags = GENL_ADMIN_PERM,
41265714 6038 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6039 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6040 },
6041 {
6042 .cmd = NL80211_CMD_DEL_KEY,
6043 .doit = nl80211_del_key,
6044 .policy = nl80211_policy,
55682965 6045 .flags = GENL_ADMIN_PERM,
41265714 6046 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6047 NL80211_FLAG_NEED_RTNL,
55682965 6048 },
ed1b6cc7
JB
6049 {
6050 .cmd = NL80211_CMD_SET_BEACON,
6051 .policy = nl80211_policy,
6052 .flags = GENL_ADMIN_PERM,
6053 .doit = nl80211_addset_beacon,
4c476991
JB
6054 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6055 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6056 },
6057 {
6058 .cmd = NL80211_CMD_NEW_BEACON,
6059 .policy = nl80211_policy,
6060 .flags = GENL_ADMIN_PERM,
6061 .doit = nl80211_addset_beacon,
4c476991
JB
6062 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6063 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6064 },
6065 {
6066 .cmd = NL80211_CMD_DEL_BEACON,
6067 .policy = nl80211_policy,
6068 .flags = GENL_ADMIN_PERM,
6069 .doit = nl80211_del_beacon,
4c476991
JB
6070 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6071 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6072 },
5727ef1b
JB
6073 {
6074 .cmd = NL80211_CMD_GET_STATION,
6075 .doit = nl80211_get_station,
2ec600d6 6076 .dumpit = nl80211_dump_station,
5727ef1b 6077 .policy = nl80211_policy,
4c476991
JB
6078 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6079 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6080 },
6081 {
6082 .cmd = NL80211_CMD_SET_STATION,
6083 .doit = nl80211_set_station,
6084 .policy = nl80211_policy,
6085 .flags = GENL_ADMIN_PERM,
4c476991
JB
6086 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6087 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6088 },
6089 {
6090 .cmd = NL80211_CMD_NEW_STATION,
6091 .doit = nl80211_new_station,
6092 .policy = nl80211_policy,
6093 .flags = GENL_ADMIN_PERM,
41265714 6094 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6095 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6096 },
6097 {
6098 .cmd = NL80211_CMD_DEL_STATION,
6099 .doit = nl80211_del_station,
6100 .policy = nl80211_policy,
2ec600d6 6101 .flags = GENL_ADMIN_PERM,
4c476991
JB
6102 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6103 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6104 },
6105 {
6106 .cmd = NL80211_CMD_GET_MPATH,
6107 .doit = nl80211_get_mpath,
6108 .dumpit = nl80211_dump_mpath,
6109 .policy = nl80211_policy,
6110 .flags = GENL_ADMIN_PERM,
41265714 6111 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6112 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6113 },
6114 {
6115 .cmd = NL80211_CMD_SET_MPATH,
6116 .doit = nl80211_set_mpath,
6117 .policy = nl80211_policy,
6118 .flags = GENL_ADMIN_PERM,
41265714 6119 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6120 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6121 },
6122 {
6123 .cmd = NL80211_CMD_NEW_MPATH,
6124 .doit = nl80211_new_mpath,
6125 .policy = nl80211_policy,
6126 .flags = GENL_ADMIN_PERM,
41265714 6127 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6128 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6129 },
6130 {
6131 .cmd = NL80211_CMD_DEL_MPATH,
6132 .doit = nl80211_del_mpath,
6133 .policy = nl80211_policy,
9f1ba906 6134 .flags = GENL_ADMIN_PERM,
4c476991
JB
6135 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6136 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6137 },
6138 {
6139 .cmd = NL80211_CMD_SET_BSS,
6140 .doit = nl80211_set_bss,
6141 .policy = nl80211_policy,
b2e1b302 6142 .flags = GENL_ADMIN_PERM,
4c476991
JB
6143 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6144 NL80211_FLAG_NEED_RTNL,
b2e1b302 6145 },
f130347c
LR
6146 {
6147 .cmd = NL80211_CMD_GET_REG,
6148 .doit = nl80211_get_reg,
6149 .policy = nl80211_policy,
6150 /* can be retrieved by unprivileged users */
6151 },
b2e1b302
LR
6152 {
6153 .cmd = NL80211_CMD_SET_REG,
6154 .doit = nl80211_set_reg,
6155 .policy = nl80211_policy,
6156 .flags = GENL_ADMIN_PERM,
6157 },
6158 {
6159 .cmd = NL80211_CMD_REQ_SET_REG,
6160 .doit = nl80211_req_set_reg,
6161 .policy = nl80211_policy,
93da9cc1 6162 .flags = GENL_ADMIN_PERM,
6163 },
6164 {
24bdd9f4
JC
6165 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6166 .doit = nl80211_get_mesh_config,
93da9cc1 6167 .policy = nl80211_policy,
6168 /* can be retrieved by unprivileged users */
4c476991
JB
6169 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6170 NL80211_FLAG_NEED_RTNL,
93da9cc1 6171 },
6172 {
24bdd9f4
JC
6173 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6174 .doit = nl80211_update_mesh_config,
93da9cc1 6175 .policy = nl80211_policy,
9aed3cc1 6176 .flags = GENL_ADMIN_PERM,
29cbe68c 6177 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6178 NL80211_FLAG_NEED_RTNL,
9aed3cc1 6179 },
2a519311
JB
6180 {
6181 .cmd = NL80211_CMD_TRIGGER_SCAN,
6182 .doit = nl80211_trigger_scan,
6183 .policy = nl80211_policy,
6184 .flags = GENL_ADMIN_PERM,
41265714 6185 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6186 NL80211_FLAG_NEED_RTNL,
2a519311
JB
6187 },
6188 {
6189 .cmd = NL80211_CMD_GET_SCAN,
6190 .policy = nl80211_policy,
6191 .dumpit = nl80211_dump_scan,
6192 },
807f8a8c
LC
6193 {
6194 .cmd = NL80211_CMD_START_SCHED_SCAN,
6195 .doit = nl80211_start_sched_scan,
6196 .policy = nl80211_policy,
6197 .flags = GENL_ADMIN_PERM,
6198 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6199 NL80211_FLAG_NEED_RTNL,
6200 },
6201 {
6202 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6203 .doit = nl80211_stop_sched_scan,
6204 .policy = nl80211_policy,
6205 .flags = GENL_ADMIN_PERM,
6206 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6207 NL80211_FLAG_NEED_RTNL,
6208 },
636a5d36
JM
6209 {
6210 .cmd = NL80211_CMD_AUTHENTICATE,
6211 .doit = nl80211_authenticate,
6212 .policy = nl80211_policy,
6213 .flags = GENL_ADMIN_PERM,
41265714 6214 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6215 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6216 },
6217 {
6218 .cmd = NL80211_CMD_ASSOCIATE,
6219 .doit = nl80211_associate,
6220 .policy = nl80211_policy,
6221 .flags = GENL_ADMIN_PERM,
41265714 6222 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6223 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6224 },
6225 {
6226 .cmd = NL80211_CMD_DEAUTHENTICATE,
6227 .doit = nl80211_deauthenticate,
6228 .policy = nl80211_policy,
6229 .flags = GENL_ADMIN_PERM,
41265714 6230 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6231 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6232 },
6233 {
6234 .cmd = NL80211_CMD_DISASSOCIATE,
6235 .doit = nl80211_disassociate,
6236 .policy = nl80211_policy,
6237 .flags = GENL_ADMIN_PERM,
41265714 6238 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6239 NL80211_FLAG_NEED_RTNL,
636a5d36 6240 },
04a773ad
JB
6241 {
6242 .cmd = NL80211_CMD_JOIN_IBSS,
6243 .doit = nl80211_join_ibss,
6244 .policy = nl80211_policy,
6245 .flags = GENL_ADMIN_PERM,
41265714 6246 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6247 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
6248 },
6249 {
6250 .cmd = NL80211_CMD_LEAVE_IBSS,
6251 .doit = nl80211_leave_ibss,
6252 .policy = nl80211_policy,
6253 .flags = GENL_ADMIN_PERM,
41265714 6254 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6255 NL80211_FLAG_NEED_RTNL,
04a773ad 6256 },
aff89a9b
JB
6257#ifdef CONFIG_NL80211_TESTMODE
6258 {
6259 .cmd = NL80211_CMD_TESTMODE,
6260 .doit = nl80211_testmode_do,
71063f0e 6261 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
6262 .policy = nl80211_policy,
6263 .flags = GENL_ADMIN_PERM,
4c476991
JB
6264 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6265 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
6266 },
6267#endif
b23aa676
SO
6268 {
6269 .cmd = NL80211_CMD_CONNECT,
6270 .doit = nl80211_connect,
6271 .policy = nl80211_policy,
6272 .flags = GENL_ADMIN_PERM,
41265714 6273 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6274 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
6275 },
6276 {
6277 .cmd = NL80211_CMD_DISCONNECT,
6278 .doit = nl80211_disconnect,
6279 .policy = nl80211_policy,
6280 .flags = GENL_ADMIN_PERM,
41265714 6281 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6282 NL80211_FLAG_NEED_RTNL,
b23aa676 6283 },
463d0183
JB
6284 {
6285 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6286 .doit = nl80211_wiphy_netns,
6287 .policy = nl80211_policy,
6288 .flags = GENL_ADMIN_PERM,
4c476991
JB
6289 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6290 NL80211_FLAG_NEED_RTNL,
463d0183 6291 },
61fa713c
HS
6292 {
6293 .cmd = NL80211_CMD_GET_SURVEY,
6294 .policy = nl80211_policy,
6295 .dumpit = nl80211_dump_survey,
6296 },
67fbb16b
SO
6297 {
6298 .cmd = NL80211_CMD_SET_PMKSA,
6299 .doit = nl80211_setdel_pmksa,
6300 .policy = nl80211_policy,
6301 .flags = GENL_ADMIN_PERM,
4c476991
JB
6302 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6303 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6304 },
6305 {
6306 .cmd = NL80211_CMD_DEL_PMKSA,
6307 .doit = nl80211_setdel_pmksa,
6308 .policy = nl80211_policy,
6309 .flags = GENL_ADMIN_PERM,
4c476991
JB
6310 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6311 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6312 },
6313 {
6314 .cmd = NL80211_CMD_FLUSH_PMKSA,
6315 .doit = nl80211_flush_pmksa,
6316 .policy = nl80211_policy,
6317 .flags = GENL_ADMIN_PERM,
4c476991
JB
6318 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6319 NL80211_FLAG_NEED_RTNL,
67fbb16b 6320 },
9588bbd5
JM
6321 {
6322 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6323 .doit = nl80211_remain_on_channel,
6324 .policy = nl80211_policy,
6325 .flags = GENL_ADMIN_PERM,
41265714 6326 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6327 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
6328 },
6329 {
6330 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6331 .doit = nl80211_cancel_remain_on_channel,
6332 .policy = nl80211_policy,
6333 .flags = GENL_ADMIN_PERM,
41265714 6334 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6335 NL80211_FLAG_NEED_RTNL,
9588bbd5 6336 },
13ae75b1
JM
6337 {
6338 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6339 .doit = nl80211_set_tx_bitrate_mask,
6340 .policy = nl80211_policy,
6341 .flags = GENL_ADMIN_PERM,
4c476991
JB
6342 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6343 NL80211_FLAG_NEED_RTNL,
13ae75b1 6344 },
026331c4 6345 {
2e161f78
JB
6346 .cmd = NL80211_CMD_REGISTER_FRAME,
6347 .doit = nl80211_register_mgmt,
026331c4
JM
6348 .policy = nl80211_policy,
6349 .flags = GENL_ADMIN_PERM,
4c476991
JB
6350 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6351 NL80211_FLAG_NEED_RTNL,
026331c4
JM
6352 },
6353 {
2e161f78
JB
6354 .cmd = NL80211_CMD_FRAME,
6355 .doit = nl80211_tx_mgmt,
026331c4 6356 .policy = nl80211_policy,
f7ca38df
JB
6357 .flags = GENL_ADMIN_PERM,
6358 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6359 NL80211_FLAG_NEED_RTNL,
6360 },
6361 {
6362 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6363 .doit = nl80211_tx_mgmt_cancel_wait,
6364 .policy = nl80211_policy,
026331c4 6365 .flags = GENL_ADMIN_PERM,
41265714 6366 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6367 NL80211_FLAG_NEED_RTNL,
026331c4 6368 },
ffb9eb3d
KV
6369 {
6370 .cmd = NL80211_CMD_SET_POWER_SAVE,
6371 .doit = nl80211_set_power_save,
6372 .policy = nl80211_policy,
6373 .flags = GENL_ADMIN_PERM,
4c476991
JB
6374 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6375 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
6376 },
6377 {
6378 .cmd = NL80211_CMD_GET_POWER_SAVE,
6379 .doit = nl80211_get_power_save,
6380 .policy = nl80211_policy,
6381 /* can be retrieved by unprivileged users */
4c476991
JB
6382 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6383 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 6384 },
d6dc1a38
JO
6385 {
6386 .cmd = NL80211_CMD_SET_CQM,
6387 .doit = nl80211_set_cqm,
6388 .policy = nl80211_policy,
6389 .flags = GENL_ADMIN_PERM,
4c476991
JB
6390 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6391 NL80211_FLAG_NEED_RTNL,
d6dc1a38 6392 },
f444de05
JB
6393 {
6394 .cmd = NL80211_CMD_SET_CHANNEL,
6395 .doit = nl80211_set_channel,
6396 .policy = nl80211_policy,
6397 .flags = GENL_ADMIN_PERM,
4c476991
JB
6398 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6399 NL80211_FLAG_NEED_RTNL,
f444de05 6400 },
e8347eba
BJ
6401 {
6402 .cmd = NL80211_CMD_SET_WDS_PEER,
6403 .doit = nl80211_set_wds_peer,
6404 .policy = nl80211_policy,
6405 .flags = GENL_ADMIN_PERM,
43b19952
JB
6406 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6407 NL80211_FLAG_NEED_RTNL,
e8347eba 6408 },
29cbe68c
JB
6409 {
6410 .cmd = NL80211_CMD_JOIN_MESH,
6411 .doit = nl80211_join_mesh,
6412 .policy = nl80211_policy,
6413 .flags = GENL_ADMIN_PERM,
6414 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6415 NL80211_FLAG_NEED_RTNL,
6416 },
6417 {
6418 .cmd = NL80211_CMD_LEAVE_MESH,
6419 .doit = nl80211_leave_mesh,
6420 .policy = nl80211_policy,
6421 .flags = GENL_ADMIN_PERM,
6422 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6423 NL80211_FLAG_NEED_RTNL,
6424 },
ff1b6e69
JB
6425 {
6426 .cmd = NL80211_CMD_GET_WOWLAN,
6427 .doit = nl80211_get_wowlan,
6428 .policy = nl80211_policy,
6429 /* can be retrieved by unprivileged users */
6430 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6431 NL80211_FLAG_NEED_RTNL,
6432 },
6433 {
6434 .cmd = NL80211_CMD_SET_WOWLAN,
6435 .doit = nl80211_set_wowlan,
6436 .policy = nl80211_policy,
6437 .flags = GENL_ADMIN_PERM,
6438 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6439 NL80211_FLAG_NEED_RTNL,
6440 },
e5497d76
JB
6441 {
6442 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
6443 .doit = nl80211_set_rekey_data,
6444 .policy = nl80211_policy,
6445 .flags = GENL_ADMIN_PERM,
6446 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6447 NL80211_FLAG_NEED_RTNL,
6448 },
109086ce
AN
6449 {
6450 .cmd = NL80211_CMD_TDLS_MGMT,
6451 .doit = nl80211_tdls_mgmt,
6452 .policy = nl80211_policy,
6453 .flags = GENL_ADMIN_PERM,
6454 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6455 NL80211_FLAG_NEED_RTNL,
6456 },
6457 {
6458 .cmd = NL80211_CMD_TDLS_OPER,
6459 .doit = nl80211_tdls_oper,
6460 .policy = nl80211_policy,
6461 .flags = GENL_ADMIN_PERM,
6462 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6463 NL80211_FLAG_NEED_RTNL,
6464 },
28946da7
JB
6465 {
6466 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
6467 .doit = nl80211_register_unexpected_frame,
6468 .policy = nl80211_policy,
6469 .flags = GENL_ADMIN_PERM,
6470 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6471 NL80211_FLAG_NEED_RTNL,
6472 },
7f6cf311
JB
6473 {
6474 .cmd = NL80211_CMD_PROBE_CLIENT,
6475 .doit = nl80211_probe_client,
6476 .policy = nl80211_policy,
6477 .flags = GENL_ADMIN_PERM,
6478 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6479 NL80211_FLAG_NEED_RTNL,
6480 },
55682965 6481};
9588bbd5 6482
6039f6d2
JM
6483static struct genl_multicast_group nl80211_mlme_mcgrp = {
6484 .name = "mlme",
6485};
55682965
JB
6486
6487/* multicast groups */
6488static struct genl_multicast_group nl80211_config_mcgrp = {
6489 .name = "config",
6490};
2a519311
JB
6491static struct genl_multicast_group nl80211_scan_mcgrp = {
6492 .name = "scan",
6493};
73d54c9e
LR
6494static struct genl_multicast_group nl80211_regulatory_mcgrp = {
6495 .name = "regulatory",
6496};
55682965
JB
6497
6498/* notification functions */
6499
6500void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
6501{
6502 struct sk_buff *msg;
6503
fd2120ca 6504 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
6505 if (!msg)
6506 return;
6507
6508 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
6509 nlmsg_free(msg);
6510 return;
6511 }
6512
463d0183
JB
6513 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6514 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
6515}
6516
362a415d
JB
6517static int nl80211_add_scan_req(struct sk_buff *msg,
6518 struct cfg80211_registered_device *rdev)
6519{
6520 struct cfg80211_scan_request *req = rdev->scan_req;
6521 struct nlattr *nest;
6522 int i;
6523
667503dd
JB
6524 ASSERT_RDEV_LOCK(rdev);
6525
362a415d
JB
6526 if (WARN_ON(!req))
6527 return 0;
6528
6529 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
6530 if (!nest)
6531 goto nla_put_failure;
6532 for (i = 0; i < req->n_ssids; i++)
6533 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
6534 nla_nest_end(msg, nest);
6535
6536 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
6537 if (!nest)
6538 goto nla_put_failure;
6539 for (i = 0; i < req->n_channels; i++)
6540 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
6541 nla_nest_end(msg, nest);
6542
6543 if (req->ie)
6544 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
6545
6546 return 0;
6547 nla_put_failure:
6548 return -ENOBUFS;
6549}
6550
a538e2d5
JB
6551static int nl80211_send_scan_msg(struct sk_buff *msg,
6552 struct cfg80211_registered_device *rdev,
6553 struct net_device *netdev,
6554 u32 pid, u32 seq, int flags,
6555 u32 cmd)
2a519311
JB
6556{
6557 void *hdr;
6558
6559 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6560 if (!hdr)
6561 return -1;
6562
b5850a7a 6563 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
6564 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6565
362a415d
JB
6566 /* ignore errors and send incomplete event anyway */
6567 nl80211_add_scan_req(msg, rdev);
2a519311
JB
6568
6569 return genlmsg_end(msg, hdr);
6570
6571 nla_put_failure:
6572 genlmsg_cancel(msg, hdr);
6573 return -EMSGSIZE;
6574}
6575
807f8a8c
LC
6576static int
6577nl80211_send_sched_scan_msg(struct sk_buff *msg,
6578 struct cfg80211_registered_device *rdev,
6579 struct net_device *netdev,
6580 u32 pid, u32 seq, int flags, u32 cmd)
6581{
6582 void *hdr;
6583
6584 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6585 if (!hdr)
6586 return -1;
6587
6588 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6589 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6590
6591 return genlmsg_end(msg, hdr);
6592
6593 nla_put_failure:
6594 genlmsg_cancel(msg, hdr);
6595 return -EMSGSIZE;
6596}
6597
a538e2d5
JB
6598void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
6599 struct net_device *netdev)
6600{
6601 struct sk_buff *msg;
6602
6603 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6604 if (!msg)
6605 return;
6606
6607 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6608 NL80211_CMD_TRIGGER_SCAN) < 0) {
6609 nlmsg_free(msg);
6610 return;
6611 }
6612
463d0183
JB
6613 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6614 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
6615}
6616
2a519311
JB
6617void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
6618 struct net_device *netdev)
6619{
6620 struct sk_buff *msg;
6621
fd2120ca 6622 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
6623 if (!msg)
6624 return;
6625
a538e2d5
JB
6626 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6627 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
6628 nlmsg_free(msg);
6629 return;
6630 }
6631
463d0183
JB
6632 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6633 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
6634}
6635
6636void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
6637 struct net_device *netdev)
6638{
6639 struct sk_buff *msg;
6640
fd2120ca 6641 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
6642 if (!msg)
6643 return;
6644
a538e2d5
JB
6645 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6646 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
6647 nlmsg_free(msg);
6648 return;
6649 }
6650
463d0183
JB
6651 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6652 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
6653}
6654
807f8a8c
LC
6655void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
6656 struct net_device *netdev)
6657{
6658 struct sk_buff *msg;
6659
6660 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6661 if (!msg)
6662 return;
6663
6664 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
6665 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
6666 nlmsg_free(msg);
6667 return;
6668 }
6669
6670 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6671 nl80211_scan_mcgrp.id, GFP_KERNEL);
6672}
6673
6674void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
6675 struct net_device *netdev, u32 cmd)
6676{
6677 struct sk_buff *msg;
6678
6679 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6680 if (!msg)
6681 return;
6682
6683 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
6684 nlmsg_free(msg);
6685 return;
6686 }
6687
6688 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6689 nl80211_scan_mcgrp.id, GFP_KERNEL);
6690}
6691
73d54c9e
LR
6692/*
6693 * This can happen on global regulatory changes or device specific settings
6694 * based on custom world regulatory domains.
6695 */
6696void nl80211_send_reg_change_event(struct regulatory_request *request)
6697{
6698 struct sk_buff *msg;
6699 void *hdr;
6700
fd2120ca 6701 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
6702 if (!msg)
6703 return;
6704
6705 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
6706 if (!hdr) {
6707 nlmsg_free(msg);
6708 return;
6709 }
6710
6711 /* Userspace can always count this one always being set */
6712 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
6713
6714 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
6715 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6716 NL80211_REGDOM_TYPE_WORLD);
6717 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
6718 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6719 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
6720 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
6721 request->intersect)
6722 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6723 NL80211_REGDOM_TYPE_INTERSECTION);
6724 else {
6725 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6726 NL80211_REGDOM_TYPE_COUNTRY);
6727 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
6728 }
6729
6730 if (wiphy_idx_valid(request->wiphy_idx))
6731 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
6732
3b7b72ee 6733 genlmsg_end(msg, hdr);
73d54c9e 6734
bc43b28c 6735 rcu_read_lock();
463d0183 6736 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
6737 GFP_ATOMIC);
6738 rcu_read_unlock();
73d54c9e
LR
6739
6740 return;
6741
6742nla_put_failure:
6743 genlmsg_cancel(msg, hdr);
6744 nlmsg_free(msg);
6745}
6746
6039f6d2
JM
6747static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
6748 struct net_device *netdev,
6749 const u8 *buf, size_t len,
e6d6e342 6750 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
6751{
6752 struct sk_buff *msg;
6753 void *hdr;
6754
e6d6e342 6755 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
6756 if (!msg)
6757 return;
6758
6759 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6760 if (!hdr) {
6761 nlmsg_free(msg);
6762 return;
6763 }
6764
6765 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6766 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6767 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6768
3b7b72ee 6769 genlmsg_end(msg, hdr);
6039f6d2 6770
463d0183
JB
6771 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6772 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
6773 return;
6774
6775 nla_put_failure:
6776 genlmsg_cancel(msg, hdr);
6777 nlmsg_free(msg);
6778}
6779
6780void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6781 struct net_device *netdev, const u8 *buf,
6782 size_t len, gfp_t gfp)
6039f6d2
JM
6783{
6784 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6785 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
6786}
6787
6788void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
6789 struct net_device *netdev, const u8 *buf,
e6d6e342 6790 size_t len, gfp_t gfp)
6039f6d2 6791{
e6d6e342
JB
6792 nl80211_send_mlme_event(rdev, netdev, buf, len,
6793 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
6794}
6795
53b46b84 6796void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6797 struct net_device *netdev, const u8 *buf,
6798 size_t len, gfp_t gfp)
6039f6d2
JM
6799{
6800 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6801 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
6802}
6803
53b46b84
JM
6804void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
6805 struct net_device *netdev, const u8 *buf,
e6d6e342 6806 size_t len, gfp_t gfp)
6039f6d2
JM
6807{
6808 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6809 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
6810}
6811
cf4e594e
JM
6812void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
6813 struct net_device *netdev, const u8 *buf,
6814 size_t len, gfp_t gfp)
6815{
6816 nl80211_send_mlme_event(rdev, netdev, buf, len,
6817 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
6818}
6819
6820void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
6821 struct net_device *netdev, const u8 *buf,
6822 size_t len, gfp_t gfp)
6823{
6824 nl80211_send_mlme_event(rdev, netdev, buf, len,
6825 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
6826}
6827
1b06bb40
LR
6828static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
6829 struct net_device *netdev, int cmd,
e6d6e342 6830 const u8 *addr, gfp_t gfp)
1965c853
JM
6831{
6832 struct sk_buff *msg;
6833 void *hdr;
6834
e6d6e342 6835 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
6836 if (!msg)
6837 return;
6838
6839 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6840 if (!hdr) {
6841 nlmsg_free(msg);
6842 return;
6843 }
6844
6845 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6846 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6847 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
6848 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6849
3b7b72ee 6850 genlmsg_end(msg, hdr);
1965c853 6851
463d0183
JB
6852 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6853 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
6854 return;
6855
6856 nla_put_failure:
6857 genlmsg_cancel(msg, hdr);
6858 nlmsg_free(msg);
6859}
6860
6861void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6862 struct net_device *netdev, const u8 *addr,
6863 gfp_t gfp)
1965c853
JM
6864{
6865 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 6866 addr, gfp);
1965c853
JM
6867}
6868
6869void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6870 struct net_device *netdev, const u8 *addr,
6871 gfp_t gfp)
1965c853 6872{
e6d6e342
JB
6873 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
6874 addr, gfp);
1965c853
JM
6875}
6876
b23aa676
SO
6877void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
6878 struct net_device *netdev, const u8 *bssid,
6879 const u8 *req_ie, size_t req_ie_len,
6880 const u8 *resp_ie, size_t resp_ie_len,
6881 u16 status, gfp_t gfp)
6882{
6883 struct sk_buff *msg;
6884 void *hdr;
6885
6886 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6887 if (!msg)
6888 return;
6889
6890 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
6891 if (!hdr) {
6892 nlmsg_free(msg);
6893 return;
6894 }
6895
6896 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6897 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6898 if (bssid)
6899 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6900 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
6901 if (req_ie)
6902 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6903 if (resp_ie)
6904 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6905
3b7b72ee 6906 genlmsg_end(msg, hdr);
b23aa676 6907
463d0183
JB
6908 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6909 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
6910 return;
6911
6912 nla_put_failure:
6913 genlmsg_cancel(msg, hdr);
6914 nlmsg_free(msg);
6915
6916}
6917
6918void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
6919 struct net_device *netdev, const u8 *bssid,
6920 const u8 *req_ie, size_t req_ie_len,
6921 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
6922{
6923 struct sk_buff *msg;
6924 void *hdr;
6925
6926 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6927 if (!msg)
6928 return;
6929
6930 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
6931 if (!hdr) {
6932 nlmsg_free(msg);
6933 return;
6934 }
6935
6936 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6937 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6938 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6939 if (req_ie)
6940 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6941 if (resp_ie)
6942 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6943
3b7b72ee 6944 genlmsg_end(msg, hdr);
b23aa676 6945
463d0183
JB
6946 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6947 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
6948 return;
6949
6950 nla_put_failure:
6951 genlmsg_cancel(msg, hdr);
6952 nlmsg_free(msg);
6953
6954}
6955
6956void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
6957 struct net_device *netdev, u16 reason,
667503dd 6958 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
6959{
6960 struct sk_buff *msg;
6961 void *hdr;
6962
667503dd 6963 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
6964 if (!msg)
6965 return;
6966
6967 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
6968 if (!hdr) {
6969 nlmsg_free(msg);
6970 return;
6971 }
6972
6973 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6974 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6975 if (from_ap && reason)
6976 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
6977 if (from_ap)
6978 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
6979 if (ie)
6980 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
6981
3b7b72ee 6982 genlmsg_end(msg, hdr);
b23aa676 6983
463d0183
JB
6984 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6985 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
6986 return;
6987
6988 nla_put_failure:
6989 genlmsg_cancel(msg, hdr);
6990 nlmsg_free(msg);
6991
6992}
6993
04a773ad
JB
6994void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
6995 struct net_device *netdev, const u8 *bssid,
6996 gfp_t gfp)
6997{
6998 struct sk_buff *msg;
6999 void *hdr;
7000
fd2120ca 7001 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7002 if (!msg)
7003 return;
7004
7005 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7006 if (!hdr) {
7007 nlmsg_free(msg);
7008 return;
7009 }
7010
7011 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7012 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7013 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7014
3b7b72ee 7015 genlmsg_end(msg, hdr);
04a773ad 7016
463d0183
JB
7017 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7018 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7019 return;
7020
7021 nla_put_failure:
7022 genlmsg_cancel(msg, hdr);
7023 nlmsg_free(msg);
7024}
7025
c93b5e71
JC
7026void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7027 struct net_device *netdev,
7028 const u8 *macaddr, const u8* ie, u8 ie_len,
7029 gfp_t gfp)
7030{
7031 struct sk_buff *msg;
7032 void *hdr;
7033
7034 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7035 if (!msg)
7036 return;
7037
7038 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7039 if (!hdr) {
7040 nlmsg_free(msg);
7041 return;
7042 }
7043
7044 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7045 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7046 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
7047 if (ie_len && ie)
7048 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
7049
3b7b72ee 7050 genlmsg_end(msg, hdr);
c93b5e71
JC
7051
7052 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7053 nl80211_mlme_mcgrp.id, gfp);
7054 return;
7055
7056 nla_put_failure:
7057 genlmsg_cancel(msg, hdr);
7058 nlmsg_free(msg);
7059}
7060
a3b8b056
JM
7061void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7062 struct net_device *netdev, const u8 *addr,
7063 enum nl80211_key_type key_type, int key_id,
e6d6e342 7064 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7065{
7066 struct sk_buff *msg;
7067 void *hdr;
7068
e6d6e342 7069 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7070 if (!msg)
7071 return;
7072
7073 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7074 if (!hdr) {
7075 nlmsg_free(msg);
7076 return;
7077 }
7078
7079 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7080 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7081 if (addr)
7082 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7083 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
a66b98db
AN
7084 if (key_id != -1)
7085 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
a3b8b056
JM
7086 if (tsc)
7087 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
7088
3b7b72ee 7089 genlmsg_end(msg, hdr);
a3b8b056 7090
463d0183
JB
7091 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7092 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7093 return;
7094
7095 nla_put_failure:
7096 genlmsg_cancel(msg, hdr);
7097 nlmsg_free(msg);
7098}
7099
6bad8766
LR
7100void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7101 struct ieee80211_channel *channel_before,
7102 struct ieee80211_channel *channel_after)
7103{
7104 struct sk_buff *msg;
7105 void *hdr;
7106 struct nlattr *nl_freq;
7107
fd2120ca 7108 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7109 if (!msg)
7110 return;
7111
7112 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7113 if (!hdr) {
7114 nlmsg_free(msg);
7115 return;
7116 }
7117
7118 /*
7119 * Since we are applying the beacon hint to a wiphy we know its
7120 * wiphy_idx is valid
7121 */
7122 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
7123
7124 /* Before */
7125 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7126 if (!nl_freq)
7127 goto nla_put_failure;
7128 if (nl80211_msg_put_channel(msg, channel_before))
7129 goto nla_put_failure;
7130 nla_nest_end(msg, nl_freq);
7131
7132 /* After */
7133 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7134 if (!nl_freq)
7135 goto nla_put_failure;
7136 if (nl80211_msg_put_channel(msg, channel_after))
7137 goto nla_put_failure;
7138 nla_nest_end(msg, nl_freq);
7139
3b7b72ee 7140 genlmsg_end(msg, hdr);
6bad8766 7141
463d0183
JB
7142 rcu_read_lock();
7143 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7144 GFP_ATOMIC);
7145 rcu_read_unlock();
6bad8766
LR
7146
7147 return;
7148
7149nla_put_failure:
7150 genlmsg_cancel(msg, hdr);
7151 nlmsg_free(msg);
7152}
7153
9588bbd5
JM
7154static void nl80211_send_remain_on_chan_event(
7155 int cmd, struct cfg80211_registered_device *rdev,
7156 struct net_device *netdev, u64 cookie,
7157 struct ieee80211_channel *chan,
7158 enum nl80211_channel_type channel_type,
7159 unsigned int duration, gfp_t gfp)
7160{
7161 struct sk_buff *msg;
7162 void *hdr;
7163
7164 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7165 if (!msg)
7166 return;
7167
7168 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7169 if (!hdr) {
7170 nlmsg_free(msg);
7171 return;
7172 }
7173
7174 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7175 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7176 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
7177 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
7178 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7179
7180 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
7181 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
7182
3b7b72ee 7183 genlmsg_end(msg, hdr);
9588bbd5
JM
7184
7185 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7186 nl80211_mlme_mcgrp.id, gfp);
7187 return;
7188
7189 nla_put_failure:
7190 genlmsg_cancel(msg, hdr);
7191 nlmsg_free(msg);
7192}
7193
7194void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7195 struct net_device *netdev, u64 cookie,
7196 struct ieee80211_channel *chan,
7197 enum nl80211_channel_type channel_type,
7198 unsigned int duration, gfp_t gfp)
7199{
7200 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7201 rdev, netdev, cookie, chan,
7202 channel_type, duration, gfp);
7203}
7204
7205void nl80211_send_remain_on_channel_cancel(
7206 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7207 u64 cookie, struct ieee80211_channel *chan,
7208 enum nl80211_channel_type channel_type, gfp_t gfp)
7209{
7210 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7211 rdev, netdev, cookie, chan,
7212 channel_type, 0, gfp);
7213}
7214
98b62183
JB
7215void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7216 struct net_device *dev, const u8 *mac_addr,
7217 struct station_info *sinfo, gfp_t gfp)
7218{
7219 struct sk_buff *msg;
7220
7221 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7222 if (!msg)
7223 return;
7224
7225 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
7226 nlmsg_free(msg);
7227 return;
7228 }
7229
7230 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7231 nl80211_mlme_mcgrp.id, gfp);
7232}
7233
ec15e68b
JM
7234void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7235 struct net_device *dev, const u8 *mac_addr,
7236 gfp_t gfp)
7237{
7238 struct sk_buff *msg;
7239 void *hdr;
7240
7241 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7242 if (!msg)
7243 return;
7244
7245 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7246 if (!hdr) {
7247 nlmsg_free(msg);
7248 return;
7249 }
7250
7251 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7252 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
7253
3b7b72ee 7254 genlmsg_end(msg, hdr);
ec15e68b
JM
7255
7256 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7257 nl80211_mlme_mcgrp.id, gfp);
7258 return;
7259
7260 nla_put_failure:
7261 genlmsg_cancel(msg, hdr);
7262 nlmsg_free(msg);
7263}
7264
28946da7
JB
7265bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7266{
7267 struct wireless_dev *wdev = dev->ieee80211_ptr;
7268 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7269 struct sk_buff *msg;
7270 void *hdr;
7271 int err;
7272 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7273
7274 if (!nlpid)
7275 return false;
7276
7277 msg = nlmsg_new(100, gfp);
7278 if (!msg)
7279 return true;
7280
7281 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_UNEXPECTED_FRAME);
7282 if (!hdr) {
7283 nlmsg_free(msg);
7284 return true;
7285 }
7286
7287 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7288 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7289 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7290
7291 err = genlmsg_end(msg, hdr);
7292 if (err < 0) {
7293 nlmsg_free(msg);
7294 return true;
7295 }
7296
7297 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7298 return true;
7299
7300 nla_put_failure:
7301 genlmsg_cancel(msg, hdr);
7302 nlmsg_free(msg);
7303 return true;
7304}
7305
2e161f78
JB
7306int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7307 struct net_device *netdev, u32 nlpid,
7308 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
7309{
7310 struct sk_buff *msg;
7311 void *hdr;
026331c4
JM
7312
7313 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7314 if (!msg)
7315 return -ENOMEM;
7316
2e161f78 7317 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
7318 if (!hdr) {
7319 nlmsg_free(msg);
7320 return -ENOMEM;
7321 }
7322
7323 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7324 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7325 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7326 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7327
3b7b72ee 7328 genlmsg_end(msg, hdr);
026331c4 7329
3b7b72ee 7330 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
7331
7332 nla_put_failure:
7333 genlmsg_cancel(msg, hdr);
7334 nlmsg_free(msg);
7335 return -ENOBUFS;
7336}
7337
2e161f78
JB
7338void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7339 struct net_device *netdev, u64 cookie,
7340 const u8 *buf, size_t len, bool ack,
7341 gfp_t gfp)
026331c4
JM
7342{
7343 struct sk_buff *msg;
7344 void *hdr;
7345
7346 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7347 if (!msg)
7348 return;
7349
2e161f78 7350 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
7351 if (!hdr) {
7352 nlmsg_free(msg);
7353 return;
7354 }
7355
7356 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7357 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7358 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7359 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7360 if (ack)
7361 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7362
3b7b72ee 7363 genlmsg_end(msg, hdr);
026331c4
JM
7364
7365 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
7366 return;
7367
7368 nla_put_failure:
7369 genlmsg_cancel(msg, hdr);
7370 nlmsg_free(msg);
7371}
7372
d6dc1a38
JO
7373void
7374nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
7375 struct net_device *netdev,
7376 enum nl80211_cqm_rssi_threshold_event rssi_event,
7377 gfp_t gfp)
7378{
7379 struct sk_buff *msg;
7380 struct nlattr *pinfoattr;
7381 void *hdr;
7382
7383 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7384 if (!msg)
7385 return;
7386
7387 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7388 if (!hdr) {
7389 nlmsg_free(msg);
7390 return;
7391 }
7392
7393 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7394 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7395
7396 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7397 if (!pinfoattr)
7398 goto nla_put_failure;
7399
7400 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
7401 rssi_event);
7402
7403 nla_nest_end(msg, pinfoattr);
7404
3b7b72ee 7405 genlmsg_end(msg, hdr);
d6dc1a38
JO
7406
7407 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7408 nl80211_mlme_mcgrp.id, gfp);
7409 return;
7410
7411 nla_put_failure:
7412 genlmsg_cancel(msg, hdr);
7413 nlmsg_free(msg);
7414}
7415
e5497d76
JB
7416void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
7417 struct net_device *netdev, const u8 *bssid,
7418 const u8 *replay_ctr, gfp_t gfp)
7419{
7420 struct sk_buff *msg;
7421 struct nlattr *rekey_attr;
7422 void *hdr;
7423
7424 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7425 if (!msg)
7426 return;
7427
7428 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
7429 if (!hdr) {
7430 nlmsg_free(msg);
7431 return;
7432 }
7433
7434 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7435 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7436 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7437
7438 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
7439 if (!rekey_attr)
7440 goto nla_put_failure;
7441
7442 NLA_PUT(msg, NL80211_REKEY_DATA_REPLAY_CTR,
7443 NL80211_REPLAY_CTR_LEN, replay_ctr);
7444
7445 nla_nest_end(msg, rekey_attr);
7446
3b7b72ee 7447 genlmsg_end(msg, hdr);
e5497d76
JB
7448
7449 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7450 nl80211_mlme_mcgrp.id, gfp);
7451 return;
7452
7453 nla_put_failure:
7454 genlmsg_cancel(msg, hdr);
7455 nlmsg_free(msg);
7456}
7457
c9df56b4
JM
7458void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
7459 struct net_device *netdev, int index,
7460 const u8 *bssid, bool preauth, gfp_t gfp)
7461{
7462 struct sk_buff *msg;
7463 struct nlattr *attr;
7464 void *hdr;
7465
7466 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7467 if (!msg)
7468 return;
7469
7470 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
7471 if (!hdr) {
7472 nlmsg_free(msg);
7473 return;
7474 }
7475
7476 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7477 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7478
7479 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
7480 if (!attr)
7481 goto nla_put_failure;
7482
7483 NLA_PUT_U32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index);
7484 NLA_PUT(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid);
7485 if (preauth)
7486 NLA_PUT_FLAG(msg, NL80211_PMKSA_CANDIDATE_PREAUTH);
7487
7488 nla_nest_end(msg, attr);
7489
3b7b72ee 7490 genlmsg_end(msg, hdr);
c9df56b4
JM
7491
7492 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7493 nl80211_mlme_mcgrp.id, gfp);
7494 return;
7495
7496 nla_put_failure:
7497 genlmsg_cancel(msg, hdr);
7498 nlmsg_free(msg);
7499}
7500
c063dbf5
JB
7501void
7502nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
7503 struct net_device *netdev, const u8 *peer,
7504 u32 num_packets, gfp_t gfp)
7505{
7506 struct sk_buff *msg;
7507 struct nlattr *pinfoattr;
7508 void *hdr;
7509
7510 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7511 if (!msg)
7512 return;
7513
7514 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7515 if (!hdr) {
7516 nlmsg_free(msg);
7517 return;
7518 }
7519
7520 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7521 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7522 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
7523
7524 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7525 if (!pinfoattr)
7526 goto nla_put_failure;
7527
7528 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
7529
7530 nla_nest_end(msg, pinfoattr);
7531
3b7b72ee 7532 genlmsg_end(msg, hdr);
c063dbf5
JB
7533
7534 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7535 nl80211_mlme_mcgrp.id, gfp);
7536 return;
7537
7538 nla_put_failure:
7539 genlmsg_cancel(msg, hdr);
7540 nlmsg_free(msg);
7541}
7542
7f6cf311
JB
7543void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
7544 u64 cookie, bool acked, gfp_t gfp)
7545{
7546 struct wireless_dev *wdev = dev->ieee80211_ptr;
7547 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7548 struct sk_buff *msg;
7549 void *hdr;
7550 int err;
7551
7552 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7553 if (!msg)
7554 return;
7555
7556 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
7557 if (!hdr) {
7558 nlmsg_free(msg);
7559 return;
7560 }
7561
7562 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7563 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7564 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7565 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7566 if (acked)
7567 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7568
7569 err = genlmsg_end(msg, hdr);
7570 if (err < 0) {
7571 nlmsg_free(msg);
7572 return;
7573 }
7574
7575 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7576 nl80211_mlme_mcgrp.id, gfp);
7577 return;
7578
7579 nla_put_failure:
7580 genlmsg_cancel(msg, hdr);
7581 nlmsg_free(msg);
7582}
7583EXPORT_SYMBOL(cfg80211_probe_status);
7584
026331c4
JM
7585static int nl80211_netlink_notify(struct notifier_block * nb,
7586 unsigned long state,
7587 void *_notify)
7588{
7589 struct netlink_notify *notify = _notify;
7590 struct cfg80211_registered_device *rdev;
7591 struct wireless_dev *wdev;
7592
7593 if (state != NETLINK_URELEASE)
7594 return NOTIFY_DONE;
7595
7596 rcu_read_lock();
7597
7598 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
7599 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 7600 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
7601
7602 rcu_read_unlock();
7603
7604 return NOTIFY_DONE;
7605}
7606
7607static struct notifier_block nl80211_netlink_notifier = {
7608 .notifier_call = nl80211_netlink_notify,
7609};
7610
55682965
JB
7611/* initialisation/exit functions */
7612
7613int nl80211_init(void)
7614{
0d63cbb5 7615 int err;
55682965 7616
0d63cbb5
MM
7617 err = genl_register_family_with_ops(&nl80211_fam,
7618 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
7619 if (err)
7620 return err;
7621
55682965
JB
7622 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
7623 if (err)
7624 goto err_out;
7625
2a519311
JB
7626 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
7627 if (err)
7628 goto err_out;
7629
73d54c9e
LR
7630 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
7631 if (err)
7632 goto err_out;
7633
6039f6d2
JM
7634 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
7635 if (err)
7636 goto err_out;
7637
aff89a9b
JB
7638#ifdef CONFIG_NL80211_TESTMODE
7639 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
7640 if (err)
7641 goto err_out;
7642#endif
7643
026331c4
JM
7644 err = netlink_register_notifier(&nl80211_netlink_notifier);
7645 if (err)
7646 goto err_out;
7647
55682965
JB
7648 return 0;
7649 err_out:
7650 genl_unregister_family(&nl80211_fam);
7651 return err;
7652}
7653
7654void nl80211_exit(void)
7655{
026331c4 7656 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
7657 genl_unregister_family(&nl80211_fam);
7658}