]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
wireless: mark element IDs 8 and 9 reserved
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
2740f0cf 5 * Copyright 2013-2014 Intel Mobile Communications GmbH
7bdbe400 6 * Copyright 2015 Intel Deutschland GmbH
55682965
JB
7 */
8
9#include <linux/if.h>
10#include <linux/module.h>
11#include <linux/err.h>
5a0e3ad6 12#include <linux/slab.h>
55682965
JB
13#include <linux/list.h>
14#include <linux/if_ether.h>
15#include <linux/ieee80211.h>
16#include <linux/nl80211.h>
17#include <linux/rtnetlink.h>
18#include <linux/netlink.h>
2a519311 19#include <linux/etherdevice.h>
463d0183 20#include <net/net_namespace.h>
55682965
JB
21#include <net/genetlink.h>
22#include <net/cfg80211.h>
463d0183 23#include <net/sock.h>
2a0e047e 24#include <net/inet_connection_sock.h>
55682965
JB
25#include "core.h"
26#include "nl80211.h"
b2e1b302 27#include "reg.h"
e35e4d28 28#include "rdev-ops.h"
55682965 29
5fb628e9
JM
30static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
31 struct genl_info *info,
32 struct cfg80211_crypto_settings *settings,
33 int cipher_limit);
34
f84f771d 35static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991 36 struct genl_info *info);
f84f771d 37static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
38 struct genl_info *info);
39
55682965
JB
40/* the netlink family */
41static struct genl_family nl80211_fam = {
fb4e1568
MH
42 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
43 .name = NL80211_GENL_NAME, /* have users key off the name instead */
44 .hdrsize = 0, /* no private header */
45 .version = 1, /* no particular meaning now */
55682965 46 .maxattr = NL80211_ATTR_MAX,
463d0183 47 .netnsok = true,
4c476991
JB
48 .pre_doit = nl80211_pre_doit,
49 .post_doit = nl80211_post_doit,
55682965
JB
50};
51
2a94fe48
JB
52/* multicast groups */
53enum nl80211_multicast_groups {
54 NL80211_MCGRP_CONFIG,
55 NL80211_MCGRP_SCAN,
56 NL80211_MCGRP_REGULATORY,
57 NL80211_MCGRP_MLME,
567ffc35 58 NL80211_MCGRP_VENDOR,
2a94fe48
JB
59 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
60};
61
62static const struct genl_multicast_group nl80211_mcgrps[] = {
71b836ec
JB
63 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG },
64 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN },
65 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG },
66 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME },
67 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR },
2a94fe48 68#ifdef CONFIG_NL80211_TESTMODE
71b836ec 69 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE }
2a94fe48
JB
70#endif
71};
72
89a54e48
JB
73/* returns ERR_PTR values */
74static struct wireless_dev *
75__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 76{
89a54e48
JB
77 struct cfg80211_registered_device *rdev;
78 struct wireless_dev *result = NULL;
79 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
80 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
81 u64 wdev_id;
82 int wiphy_idx = -1;
83 int ifidx = -1;
55682965 84
5fe231e8 85 ASSERT_RTNL();
55682965 86
89a54e48
JB
87 if (!have_ifidx && !have_wdev_id)
88 return ERR_PTR(-EINVAL);
55682965 89
89a54e48
JB
90 if (have_ifidx)
91 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
92 if (have_wdev_id) {
93 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
94 wiphy_idx = wdev_id >> 32;
55682965
JB
95 }
96
89a54e48
JB
97 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
98 struct wireless_dev *wdev;
99
100 if (wiphy_net(&rdev->wiphy) != netns)
101 continue;
102
103 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
104 continue;
105
89a54e48
JB
106 list_for_each_entry(wdev, &rdev->wdev_list, list) {
107 if (have_ifidx && wdev->netdev &&
108 wdev->netdev->ifindex == ifidx) {
109 result = wdev;
110 break;
111 }
112 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
113 result = wdev;
114 break;
115 }
116 }
89a54e48
JB
117
118 if (result)
119 break;
120 }
121
122 if (result)
123 return result;
124 return ERR_PTR(-ENODEV);
55682965
JB
125}
126
a9455408 127static struct cfg80211_registered_device *
878d9ec7 128__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 129{
7fee4778
JB
130 struct cfg80211_registered_device *rdev = NULL, *tmp;
131 struct net_device *netdev;
a9455408 132
5fe231e8 133 ASSERT_RTNL();
a9455408 134
878d9ec7 135 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
136 !attrs[NL80211_ATTR_IFINDEX] &&
137 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
138 return ERR_PTR(-EINVAL);
139
878d9ec7 140 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 141 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 142 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 143
89a54e48
JB
144 if (attrs[NL80211_ATTR_WDEV]) {
145 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
146 struct wireless_dev *wdev;
147 bool found = false;
148
149 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
150 if (tmp) {
151 /* make sure wdev exists */
89a54e48
JB
152 list_for_each_entry(wdev, &tmp->wdev_list, list) {
153 if (wdev->identifier != (u32)wdev_id)
154 continue;
155 found = true;
156 break;
157 }
89a54e48
JB
158
159 if (!found)
160 tmp = NULL;
161
162 if (rdev && tmp != rdev)
163 return ERR_PTR(-EINVAL);
164 rdev = tmp;
165 }
166 }
167
878d9ec7
JB
168 if (attrs[NL80211_ATTR_IFINDEX]) {
169 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
7f2b8562 170 netdev = __dev_get_by_index(netns, ifindex);
7fee4778
JB
171 if (netdev) {
172 if (netdev->ieee80211_ptr)
f26cbf40
ZG
173 tmp = wiphy_to_rdev(
174 netdev->ieee80211_ptr->wiphy);
7fee4778
JB
175 else
176 tmp = NULL;
177
7fee4778
JB
178 /* not wireless device -- return error */
179 if (!tmp)
180 return ERR_PTR(-EINVAL);
181
182 /* mismatch -- return error */
183 if (rdev && tmp != rdev)
184 return ERR_PTR(-EINVAL);
185
186 rdev = tmp;
a9455408 187 }
a9455408 188 }
a9455408 189
4f7eff10
JB
190 if (!rdev)
191 return ERR_PTR(-ENODEV);
a9455408 192
4f7eff10
JB
193 if (netns != wiphy_net(&rdev->wiphy))
194 return ERR_PTR(-ENODEV);
195
196 return rdev;
a9455408
JB
197}
198
199/*
200 * This function returns a pointer to the driver
201 * that the genl_info item that is passed refers to.
a9455408
JB
202 *
203 * The result of this can be a PTR_ERR and hence must
204 * be checked with IS_ERR() for errors.
205 */
206static struct cfg80211_registered_device *
4f7eff10 207cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 208{
5fe231e8 209 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
210}
211
55682965 212/* policy for the attributes */
8cd4d456 213static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
55682965
JB
214 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
215 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 216 .len = 20-1 },
31888487 217 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 218
72bdcf34 219 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 220 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
221 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
222 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
223 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
224
b9a5f8ca
JM
225 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
226 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
227 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
228 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 229 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
3057dbfd 230 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG },
55682965
JB
231
232 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
233 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
234 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 235
e007b857
EP
236 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
237 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 238
b9454e83 239 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
240 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
241 .len = WLAN_MAX_KEY_LEN },
242 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
243 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
244 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 245 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 246 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
247
248 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
249 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
250 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
251 .len = IEEE80211_MAX_DATA_LEN },
252 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
253 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
254 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
255 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
256 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
257 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
258 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 259 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 260 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 261 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 262 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 263 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 264 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 265
b2e1b302
LR
266 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
267 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
268
9f1ba906
JM
269 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
270 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
271 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
272 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
273 .len = NL80211_MAX_SUPP_RATES },
50b12f59 274 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 275
24bdd9f4 276 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 277 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 278
6c739419 279 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
280
281 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
282 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
283 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
284 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
285 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
286
287 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
288 .len = IEEE80211_MAX_SSID_LEN },
289 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
290 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 291 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 292 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 293 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
294 [NL80211_ATTR_STA_FLAGS2] = {
295 .len = sizeof(struct nl80211_sta_flag_update),
296 },
3f77316c 297 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
298 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
299 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
300 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
301 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
302 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 303 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 304 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
305 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
306 .len = WLAN_PMKID_LEN },
9588bbd5
JM
307 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
308 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 309 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
310 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
311 .len = IEEE80211_MAX_DATA_LEN },
312 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 313 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 314 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 315 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 316 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
317 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
318 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 319 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
320 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
321 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 322 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 323 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 324 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 325 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 326 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 327 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 328 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 329 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 330 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
331 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
332 .len = IEEE80211_MAX_DATA_LEN },
333 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
334 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 335 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 336 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 337 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
338 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
339 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
340 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
341 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
342 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
31fa97c5 343 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG },
e247bd90 344 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
345 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
346 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 347 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
348 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
349 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
350 .len = NL80211_HT_CAPABILITY_LEN
351 },
1d9d9213 352 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 353 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 354 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 355 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 356 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 357 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 358 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 359 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
360 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
361 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
362 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
363 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
364 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
365 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 366 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
367 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
368 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
369 .len = NL80211_VHT_CAPABILITY_LEN,
370 },
355199e0
JM
371 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
372 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
373 .len = IEEE80211_MAX_DATA_LEN },
5e4b6f56 374 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 },
16ef1fe2
SW
375 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
376 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
377 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
9a774c78
AO
378 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY },
379 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY },
c01fc9ad
SD
380 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY },
381 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY },
5336fa88 382 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
60f4a7b1 383 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
ad7e718c
JB
384 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
385 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
386 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
fa9ffc74
KP
387 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY,
388 .len = IEEE80211_QOS_MAP_LEN_MAX },
1df4a510
JM
389 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN },
390 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
df942e7b 391 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 },
18e5ca65 392 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG },
34d22ce2 393 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY },
bab5ab7d 394 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG },
960d01ac
JB
395 [NL80211_ATTR_TSID] = { .type = NLA_U8 },
396 [NL80211_ATTR_USER_PRIO] = { .type = NLA_U8 },
397 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 },
18998c38 398 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 },
ad2b26ab 399 [NL80211_ATTR_MAC_MASK] = { .len = ETH_ALEN },
1bdd716c 400 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG },
4b681c82 401 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 },
9c748934 402 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 },
05050753 403 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG },
55682965
JB
404};
405
e31b8213 406/* policy for the key attributes */
b54452b0 407static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 408 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
409 [NL80211_KEY_IDX] = { .type = NLA_U8 },
410 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 411 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
412 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
413 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 414 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
415 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
416};
417
418/* policy for the key default flags */
419static const struct nla_policy
420nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
421 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
422 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
423};
424
ff1b6e69
JB
425/* policy for WoWLAN attributes */
426static const struct nla_policy
427nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
428 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
429 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
430 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
431 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
432 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
433 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
434 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
435 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e 436 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
8cd4d456 437 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED },
2a0e047e
JB
438};
439
440static const struct nla_policy
441nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
442 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
443 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
444 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
445 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
446 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
447 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
448 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
449 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
450 },
451 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
452 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
453 },
454 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
455 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
456 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69
JB
457};
458
be29b99a
AK
459/* policy for coalesce rule attributes */
460static const struct nla_policy
461nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
462 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
463 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 },
464 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
465};
466
e5497d76
JB
467/* policy for GTK rekey offload attributes */
468static const struct nla_policy
469nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
470 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
471 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
472 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
473};
474
a1f1c21c
LC
475static const struct nla_policy
476nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 477 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 478 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 479 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
480};
481
97990a06
JB
482static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
483 struct netlink_callback *cb,
484 struct cfg80211_registered_device **rdev,
485 struct wireless_dev **wdev)
a043897a 486{
97990a06 487 int err;
a043897a 488
97990a06 489 rtnl_lock();
a043897a 490
97990a06
JB
491 if (!cb->args[0]) {
492 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
493 nl80211_fam.attrbuf, nl80211_fam.maxattr,
494 nl80211_policy);
495 if (err)
496 goto out_unlock;
67748893 497
97990a06
JB
498 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
499 nl80211_fam.attrbuf);
500 if (IS_ERR(*wdev)) {
501 err = PTR_ERR(*wdev);
502 goto out_unlock;
503 }
f26cbf40 504 *rdev = wiphy_to_rdev((*wdev)->wiphy);
c319d50b
JB
505 /* 0 is the first index - add 1 to parse only once */
506 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
507 cb->args[1] = (*wdev)->identifier;
508 } else {
c319d50b
JB
509 /* subtract the 1 again here */
510 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 511 struct wireless_dev *tmp;
67748893 512
97990a06
JB
513 if (!wiphy) {
514 err = -ENODEV;
515 goto out_unlock;
516 }
f26cbf40 517 *rdev = wiphy_to_rdev(wiphy);
97990a06 518 *wdev = NULL;
67748893 519
97990a06
JB
520 list_for_each_entry(tmp, &(*rdev)->wdev_list, list) {
521 if (tmp->identifier == cb->args[1]) {
522 *wdev = tmp;
523 break;
524 }
525 }
67748893 526
97990a06
JB
527 if (!*wdev) {
528 err = -ENODEV;
529 goto out_unlock;
530 }
67748893
JB
531 }
532
67748893 533 return 0;
97990a06 534 out_unlock:
67748893
JB
535 rtnl_unlock();
536 return err;
537}
538
97990a06 539static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev)
67748893 540{
67748893
JB
541 rtnl_unlock();
542}
543
f4a11bb0
JB
544/* IE validation */
545static bool is_valid_ie_attr(const struct nlattr *attr)
546{
547 const u8 *pos;
548 int len;
549
550 if (!attr)
551 return true;
552
553 pos = nla_data(attr);
554 len = nla_len(attr);
555
556 while (len) {
557 u8 elemlen;
558
559 if (len < 2)
560 return false;
561 len -= 2;
562
563 elemlen = pos[1];
564 if (elemlen > len)
565 return false;
566
567 len -= elemlen;
568 pos += 2 + elemlen;
569 }
570
571 return true;
572}
573
55682965 574/* message building helper */
15e47304 575static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
576 int flags, u8 cmd)
577{
578 /* since there is no private header just add the generic one */
15e47304 579 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
580}
581
5dab3b8a 582static int nl80211_msg_put_channel(struct sk_buff *msg,
cdc89b97
JB
583 struct ieee80211_channel *chan,
584 bool large)
5dab3b8a 585{
ea077c1c
RL
586 /* Some channels must be completely excluded from the
587 * list to protect old user-space tools from breaking
588 */
589 if (!large && chan->flags &
590 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ))
591 return 0;
592
9360ffd1
DM
593 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
594 chan->center_freq))
595 goto nla_put_failure;
5dab3b8a 596
9360ffd1
DM
597 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
598 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
599 goto nla_put_failure;
8fe02e16
LR
600 if (chan->flags & IEEE80211_CHAN_NO_IR) {
601 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
602 goto nla_put_failure;
603 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
604 goto nla_put_failure;
605 }
cdc89b97
JB
606 if (chan->flags & IEEE80211_CHAN_RADAR) {
607 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
608 goto nla_put_failure;
609 if (large) {
610 u32 time;
611
612 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
613
614 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
615 chan->dfs_state))
616 goto nla_put_failure;
617 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
618 time))
619 goto nla_put_failure;
089027e5
JD
620 if (nla_put_u32(msg,
621 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME,
622 chan->dfs_cac_ms))
623 goto nla_put_failure;
cdc89b97
JB
624 }
625 }
5dab3b8a 626
fe1abafd
JB
627 if (large) {
628 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
629 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
630 goto nla_put_failure;
631 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
632 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
633 goto nla_put_failure;
634 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
635 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
636 goto nla_put_failure;
637 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
638 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
639 goto nla_put_failure;
570dbde1
DS
640 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) &&
641 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY))
642 goto nla_put_failure;
06f207fc
AN
643 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) &&
644 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT))
570dbde1 645 goto nla_put_failure;
ea077c1c
RL
646 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) &&
647 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ))
648 goto nla_put_failure;
649 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) &&
650 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ))
651 goto nla_put_failure;
fe1abafd
JB
652 }
653
9360ffd1
DM
654 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
655 DBM_TO_MBM(chan->max_power)))
656 goto nla_put_failure;
5dab3b8a
LR
657
658 return 0;
659
660 nla_put_failure:
661 return -ENOBUFS;
662}
663
55682965
JB
664/* netlink command implementations */
665
b9454e83
JB
666struct key_parse {
667 struct key_params p;
668 int idx;
e31b8213 669 int type;
b9454e83 670 bool def, defmgmt;
dbd2fd65 671 bool def_uni, def_multi;
b9454e83
JB
672};
673
674static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
675{
676 struct nlattr *tb[NL80211_KEY_MAX + 1];
677 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
678 nl80211_key_policy);
679 if (err)
680 return err;
681
682 k->def = !!tb[NL80211_KEY_DEFAULT];
683 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
684
dbd2fd65
JB
685 if (k->def) {
686 k->def_uni = true;
687 k->def_multi = true;
688 }
689 if (k->defmgmt)
690 k->def_multi = true;
691
b9454e83
JB
692 if (tb[NL80211_KEY_IDX])
693 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
694
695 if (tb[NL80211_KEY_DATA]) {
696 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
697 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
698 }
699
700 if (tb[NL80211_KEY_SEQ]) {
701 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
702 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
703 }
704
705 if (tb[NL80211_KEY_CIPHER])
706 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
707
e31b8213
JB
708 if (tb[NL80211_KEY_TYPE]) {
709 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
710 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
711 return -EINVAL;
712 }
713
dbd2fd65
JB
714 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
715 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
716 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
717 tb[NL80211_KEY_DEFAULT_TYPES],
718 nl80211_key_default_policy);
dbd2fd65
JB
719 if (err)
720 return err;
721
722 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
723 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
724 }
725
b9454e83
JB
726 return 0;
727}
728
729static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
730{
731 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
732 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
733 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
734 }
735
736 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
737 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
738 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
739 }
740
741 if (info->attrs[NL80211_ATTR_KEY_IDX])
742 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
743
744 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
745 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
746
747 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
748 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
749
dbd2fd65
JB
750 if (k->def) {
751 k->def_uni = true;
752 k->def_multi = true;
753 }
754 if (k->defmgmt)
755 k->def_multi = true;
756
e31b8213
JB
757 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
758 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
759 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
760 return -EINVAL;
761 }
762
dbd2fd65
JB
763 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
764 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
765 int err = nla_parse_nested(
766 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
767 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
768 nl80211_key_default_policy);
769 if (err)
770 return err;
771
772 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
773 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
774 }
775
b9454e83
JB
776 return 0;
777}
778
779static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
780{
781 int err;
782
783 memset(k, 0, sizeof(*k));
784 k->idx = -1;
e31b8213 785 k->type = -1;
b9454e83
JB
786
787 if (info->attrs[NL80211_ATTR_KEY])
788 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
789 else
790 err = nl80211_parse_key_old(info, k);
791
792 if (err)
793 return err;
794
795 if (k->def && k->defmgmt)
796 return -EINVAL;
797
dbd2fd65
JB
798 if (k->defmgmt) {
799 if (k->def_uni || !k->def_multi)
800 return -EINVAL;
801 }
802
b9454e83
JB
803 if (k->idx != -1) {
804 if (k->defmgmt) {
805 if (k->idx < 4 || k->idx > 5)
806 return -EINVAL;
807 } else if (k->def) {
808 if (k->idx < 0 || k->idx > 3)
809 return -EINVAL;
810 } else {
811 if (k->idx < 0 || k->idx > 5)
812 return -EINVAL;
813 }
814 }
815
816 return 0;
817}
818
fffd0934
JB
819static struct cfg80211_cached_keys *
820nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 821 struct nlattr *keys, bool *no_ht)
fffd0934
JB
822{
823 struct key_parse parse;
824 struct nlattr *key;
825 struct cfg80211_cached_keys *result;
826 int rem, err, def = 0;
827
828 result = kzalloc(sizeof(*result), GFP_KERNEL);
829 if (!result)
830 return ERR_PTR(-ENOMEM);
831
832 result->def = -1;
833 result->defmgmt = -1;
834
835 nla_for_each_nested(key, keys, rem) {
836 memset(&parse, 0, sizeof(parse));
837 parse.idx = -1;
838
839 err = nl80211_parse_key_new(key, &parse);
840 if (err)
841 goto error;
842 err = -EINVAL;
843 if (!parse.p.key)
844 goto error;
845 if (parse.idx < 0 || parse.idx > 4)
846 goto error;
847 if (parse.def) {
848 if (def)
849 goto error;
850 def = 1;
851 result->def = parse.idx;
dbd2fd65
JB
852 if (!parse.def_uni || !parse.def_multi)
853 goto error;
fffd0934
JB
854 } else if (parse.defmgmt)
855 goto error;
856 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 857 parse.idx, false, NULL);
fffd0934
JB
858 if (err)
859 goto error;
860 result->params[parse.idx].cipher = parse.p.cipher;
861 result->params[parse.idx].key_len = parse.p.key_len;
862 result->params[parse.idx].key = result->data[parse.idx];
863 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
864
865 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
866 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
867 if (no_ht)
868 *no_ht = true;
869 }
fffd0934
JB
870 }
871
872 return result;
873 error:
874 kfree(result);
875 return ERR_PTR(err);
876}
877
878static int nl80211_key_allowed(struct wireless_dev *wdev)
879{
880 ASSERT_WDEV_LOCK(wdev);
881
fffd0934
JB
882 switch (wdev->iftype) {
883 case NL80211_IFTYPE_AP:
884 case NL80211_IFTYPE_AP_VLAN:
074ac8df 885 case NL80211_IFTYPE_P2P_GO:
ff973af7 886 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
887 break;
888 case NL80211_IFTYPE_ADHOC:
fffd0934 889 case NL80211_IFTYPE_STATION:
074ac8df 890 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 891 if (!wdev->current_bss)
fffd0934
JB
892 return -ENOLINK;
893 break;
de4fcbad 894 case NL80211_IFTYPE_UNSPECIFIED:
6e0bd6c3 895 case NL80211_IFTYPE_OCB:
de4fcbad
JB
896 case NL80211_IFTYPE_MONITOR:
897 case NL80211_IFTYPE_P2P_DEVICE:
898 case NL80211_IFTYPE_WDS:
899 case NUM_NL80211_IFTYPES:
fffd0934
JB
900 return -EINVAL;
901 }
902
903 return 0;
904}
905
664834de
JM
906static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
907 struct nlattr *tb)
908{
909 struct ieee80211_channel *chan;
910
911 if (tb == NULL)
912 return NULL;
913 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb));
914 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
915 return NULL;
916 return chan;
917}
918
7527a782
JB
919static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
920{
921 struct nlattr *nl_modes = nla_nest_start(msg, attr);
922 int i;
923
924 if (!nl_modes)
925 goto nla_put_failure;
926
927 i = 0;
928 while (ifmodes) {
9360ffd1
DM
929 if ((ifmodes & 1) && nla_put_flag(msg, i))
930 goto nla_put_failure;
7527a782
JB
931 ifmodes >>= 1;
932 i++;
933 }
934
935 nla_nest_end(msg, nl_modes);
936 return 0;
937
938nla_put_failure:
939 return -ENOBUFS;
940}
941
942static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
943 struct sk_buff *msg,
944 bool large)
7527a782
JB
945{
946 struct nlattr *nl_combis;
947 int i, j;
948
949 nl_combis = nla_nest_start(msg,
950 NL80211_ATTR_INTERFACE_COMBINATIONS);
951 if (!nl_combis)
952 goto nla_put_failure;
953
954 for (i = 0; i < wiphy->n_iface_combinations; i++) {
955 const struct ieee80211_iface_combination *c;
956 struct nlattr *nl_combi, *nl_limits;
957
958 c = &wiphy->iface_combinations[i];
959
960 nl_combi = nla_nest_start(msg, i + 1);
961 if (!nl_combi)
962 goto nla_put_failure;
963
964 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
965 if (!nl_limits)
966 goto nla_put_failure;
967
968 for (j = 0; j < c->n_limits; j++) {
969 struct nlattr *nl_limit;
970
971 nl_limit = nla_nest_start(msg, j + 1);
972 if (!nl_limit)
973 goto nla_put_failure;
9360ffd1
DM
974 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
975 c->limits[j].max))
976 goto nla_put_failure;
7527a782
JB
977 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
978 c->limits[j].types))
979 goto nla_put_failure;
980 nla_nest_end(msg, nl_limit);
981 }
982
983 nla_nest_end(msg, nl_limits);
984
9360ffd1
DM
985 if (c->beacon_int_infra_match &&
986 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
987 goto nla_put_failure;
988 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
989 c->num_different_channels) ||
990 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
991 c->max_interfaces))
992 goto nla_put_failure;
cdc89b97 993 if (large &&
8c48b50a
FF
994 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
995 c->radar_detect_widths) ||
996 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS,
997 c->radar_detect_regions)))
cdc89b97 998 goto nla_put_failure;
7527a782
JB
999
1000 nla_nest_end(msg, nl_combi);
1001 }
1002
1003 nla_nest_end(msg, nl_combis);
1004
1005 return 0;
1006nla_put_failure:
1007 return -ENOBUFS;
1008}
1009
3713b4e3 1010#ifdef CONFIG_PM
b56cf720
JB
1011static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
1012 struct sk_buff *msg)
1013{
964dc9e2 1014 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
1015 struct nlattr *nl_tcp;
1016
1017 if (!tcp)
1018 return 0;
1019
1020 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
1021 if (!nl_tcp)
1022 return -ENOBUFS;
1023
1024 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1025 tcp->data_payload_max))
1026 return -ENOBUFS;
1027
1028 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1029 tcp->data_payload_max))
1030 return -ENOBUFS;
1031
1032 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
1033 return -ENOBUFS;
1034
1035 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
1036 sizeof(*tcp->tok), tcp->tok))
1037 return -ENOBUFS;
1038
1039 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
1040 tcp->data_interval_max))
1041 return -ENOBUFS;
1042
1043 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
1044 tcp->wake_payload_max))
1045 return -ENOBUFS;
1046
1047 nla_nest_end(msg, nl_tcp);
1048 return 0;
1049}
1050
3713b4e3 1051static int nl80211_send_wowlan(struct sk_buff *msg,
1b8ec87a 1052 struct cfg80211_registered_device *rdev,
b56cf720 1053 bool large)
55682965 1054{
3713b4e3 1055 struct nlattr *nl_wowlan;
55682965 1056
1b8ec87a 1057 if (!rdev->wiphy.wowlan)
3713b4e3 1058 return 0;
55682965 1059
3713b4e3
JB
1060 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1061 if (!nl_wowlan)
1062 return -ENOBUFS;
9360ffd1 1063
1b8ec87a 1064 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 1065 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1b8ec87a 1066 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 1067 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1b8ec87a 1068 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 1069 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1b8ec87a 1070 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 1071 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1b8ec87a 1072 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 1073 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1b8ec87a 1074 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 1075 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1b8ec87a 1076 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 1077 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1b8ec87a 1078 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
1079 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1080 return -ENOBUFS;
9360ffd1 1081
1b8ec87a 1082 if (rdev->wiphy.wowlan->n_patterns) {
50ac6607 1083 struct nl80211_pattern_support pat = {
1b8ec87a
ZG
1084 .max_patterns = rdev->wiphy.wowlan->n_patterns,
1085 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len,
1086 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len,
1087 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset,
3713b4e3 1088 };
9360ffd1 1089
3713b4e3
JB
1090 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1091 sizeof(pat), &pat))
1092 return -ENOBUFS;
1093 }
9360ffd1 1094
75453ccb
LC
1095 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) &&
1096 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT,
1097 rdev->wiphy.wowlan->max_nd_match_sets))
1098 return -ENOBUFS;
1099
1b8ec87a 1100 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg))
b56cf720
JB
1101 return -ENOBUFS;
1102
3713b4e3 1103 nla_nest_end(msg, nl_wowlan);
9360ffd1 1104
3713b4e3
JB
1105 return 0;
1106}
1107#endif
9360ffd1 1108
be29b99a 1109static int nl80211_send_coalesce(struct sk_buff *msg,
1b8ec87a 1110 struct cfg80211_registered_device *rdev)
be29b99a
AK
1111{
1112 struct nl80211_coalesce_rule_support rule;
1113
1b8ec87a 1114 if (!rdev->wiphy.coalesce)
be29b99a
AK
1115 return 0;
1116
1b8ec87a
ZG
1117 rule.max_rules = rdev->wiphy.coalesce->n_rules;
1118 rule.max_delay = rdev->wiphy.coalesce->max_delay;
1119 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns;
1120 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len;
1121 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len;
1122 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset;
be29b99a
AK
1123
1124 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1125 return -ENOBUFS;
1126
1127 return 0;
1128}
1129
3713b4e3
JB
1130static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1131 struct ieee80211_supported_band *sband)
1132{
1133 struct nlattr *nl_rates, *nl_rate;
1134 struct ieee80211_rate *rate;
1135 int i;
87bbbe22 1136
3713b4e3
JB
1137 /* add HT info */
1138 if (sband->ht_cap.ht_supported &&
1139 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1140 sizeof(sband->ht_cap.mcs),
1141 &sband->ht_cap.mcs) ||
1142 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1143 sband->ht_cap.cap) ||
1144 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1145 sband->ht_cap.ampdu_factor) ||
1146 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1147 sband->ht_cap.ampdu_density)))
1148 return -ENOBUFS;
afe0cbf8 1149
3713b4e3
JB
1150 /* add VHT info */
1151 if (sband->vht_cap.vht_supported &&
1152 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1153 sizeof(sband->vht_cap.vht_mcs),
1154 &sband->vht_cap.vht_mcs) ||
1155 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1156 sband->vht_cap.cap)))
1157 return -ENOBUFS;
f59ac048 1158
3713b4e3
JB
1159 /* add bitrates */
1160 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1161 if (!nl_rates)
1162 return -ENOBUFS;
ee688b00 1163
3713b4e3
JB
1164 for (i = 0; i < sband->n_bitrates; i++) {
1165 nl_rate = nla_nest_start(msg, i);
1166 if (!nl_rate)
1167 return -ENOBUFS;
ee688b00 1168
3713b4e3
JB
1169 rate = &sband->bitrates[i];
1170 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1171 rate->bitrate))
1172 return -ENOBUFS;
1173 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1174 nla_put_flag(msg,
1175 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1176 return -ENOBUFS;
ee688b00 1177
3713b4e3
JB
1178 nla_nest_end(msg, nl_rate);
1179 }
d51626df 1180
3713b4e3 1181 nla_nest_end(msg, nl_rates);
bf0c111e 1182
3713b4e3
JB
1183 return 0;
1184}
ee688b00 1185
3713b4e3
JB
1186static int
1187nl80211_send_mgmt_stypes(struct sk_buff *msg,
1188 const struct ieee80211_txrx_stypes *mgmt_stypes)
1189{
1190 u16 stypes;
1191 struct nlattr *nl_ftypes, *nl_ifs;
1192 enum nl80211_iftype ift;
1193 int i;
ee688b00 1194
3713b4e3
JB
1195 if (!mgmt_stypes)
1196 return 0;
5dab3b8a 1197
3713b4e3
JB
1198 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1199 if (!nl_ifs)
1200 return -ENOBUFS;
e2f367f2 1201
3713b4e3
JB
1202 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1203 nl_ftypes = nla_nest_start(msg, ift);
1204 if (!nl_ftypes)
1205 return -ENOBUFS;
1206 i = 0;
1207 stypes = mgmt_stypes[ift].tx;
1208 while (stypes) {
1209 if ((stypes & 1) &&
1210 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1211 (i << 4) | IEEE80211_FTYPE_MGMT))
1212 return -ENOBUFS;
1213 stypes >>= 1;
1214 i++;
ee688b00 1215 }
3713b4e3
JB
1216 nla_nest_end(msg, nl_ftypes);
1217 }
ee688b00 1218
3713b4e3 1219 nla_nest_end(msg, nl_ifs);
ee688b00 1220
3713b4e3
JB
1221 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1222 if (!nl_ifs)
1223 return -ENOBUFS;
ee688b00 1224
3713b4e3
JB
1225 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1226 nl_ftypes = nla_nest_start(msg, ift);
1227 if (!nl_ftypes)
1228 return -ENOBUFS;
1229 i = 0;
1230 stypes = mgmt_stypes[ift].rx;
1231 while (stypes) {
1232 if ((stypes & 1) &&
1233 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1234 (i << 4) | IEEE80211_FTYPE_MGMT))
1235 return -ENOBUFS;
1236 stypes >>= 1;
1237 i++;
1238 }
1239 nla_nest_end(msg, nl_ftypes);
1240 }
1241 nla_nest_end(msg, nl_ifs);
ee688b00 1242
3713b4e3
JB
1243 return 0;
1244}
ee688b00 1245
86e8cf98
JB
1246struct nl80211_dump_wiphy_state {
1247 s64 filter_wiphy;
1248 long start;
1249 long split_start, band_start, chan_start;
1250 bool split;
1251};
1252
1b8ec87a 1253static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev,
3bb20556 1254 enum nl80211_commands cmd,
3713b4e3 1255 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 1256 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
1257{
1258 void *hdr;
1259 struct nlattr *nl_bands, *nl_band;
1260 struct nlattr *nl_freqs, *nl_freq;
1261 struct nlattr *nl_cmds;
1262 enum ieee80211_band band;
1263 struct ieee80211_channel *chan;
1264 int i;
1265 const struct ieee80211_txrx_stypes *mgmt_stypes =
1b8ec87a 1266 rdev->wiphy.mgmt_stypes;
fe1abafd 1267 u32 features;
ee688b00 1268
3bb20556 1269 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
3713b4e3
JB
1270 if (!hdr)
1271 return -ENOBUFS;
ee688b00 1272
86e8cf98
JB
1273 if (WARN_ON(!state))
1274 return -EINVAL;
ee688b00 1275
1b8ec87a 1276 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3713b4e3 1277 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1b8ec87a 1278 wiphy_name(&rdev->wiphy)) ||
3713b4e3
JB
1279 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1280 cfg80211_rdev_list_generation))
8fdc621d
JB
1281 goto nla_put_failure;
1282
3bb20556
JB
1283 if (cmd != NL80211_CMD_NEW_WIPHY)
1284 goto finish;
1285
86e8cf98 1286 switch (state->split_start) {
3713b4e3
JB
1287 case 0:
1288 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1b8ec87a 1289 rdev->wiphy.retry_short) ||
3713b4e3 1290 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1b8ec87a 1291 rdev->wiphy.retry_long) ||
3713b4e3 1292 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1b8ec87a 1293 rdev->wiphy.frag_threshold) ||
3713b4e3 1294 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1b8ec87a 1295 rdev->wiphy.rts_threshold) ||
3713b4e3 1296 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1b8ec87a 1297 rdev->wiphy.coverage_class) ||
3713b4e3 1298 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1b8ec87a 1299 rdev->wiphy.max_scan_ssids) ||
3713b4e3 1300 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1b8ec87a 1301 rdev->wiphy.max_sched_scan_ssids) ||
3713b4e3 1302 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1b8ec87a 1303 rdev->wiphy.max_scan_ie_len) ||
3713b4e3 1304 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1b8ec87a 1305 rdev->wiphy.max_sched_scan_ie_len) ||
3713b4e3 1306 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
1b8ec87a 1307 rdev->wiphy.max_match_sets))
9360ffd1 1308 goto nla_put_failure;
3713b4e3 1309
1b8ec87a 1310 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
3713b4e3 1311 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1312 goto nla_put_failure;
1b8ec87a 1313 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
3713b4e3
JB
1314 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1315 goto nla_put_failure;
1b8ec87a 1316 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3713b4e3
JB
1317 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1318 goto nla_put_failure;
1b8ec87a 1319 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
3713b4e3
JB
1320 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1321 goto nla_put_failure;
1b8ec87a 1322 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
3713b4e3
JB
1323 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1324 goto nla_put_failure;
1b8ec87a 1325 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
3713b4e3 1326 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1327 goto nla_put_failure;
86e8cf98
JB
1328 state->split_start++;
1329 if (state->split)
3713b4e3
JB
1330 break;
1331 case 1:
1332 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1b8ec87a
ZG
1333 sizeof(u32) * rdev->wiphy.n_cipher_suites,
1334 rdev->wiphy.cipher_suites))
3713b4e3 1335 goto nla_put_failure;
4745fc09 1336
3713b4e3 1337 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1b8ec87a 1338 rdev->wiphy.max_num_pmkids))
3713b4e3 1339 goto nla_put_failure;
b23aa676 1340
1b8ec87a 1341 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3713b4e3 1342 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1343 goto nla_put_failure;
b23aa676 1344
3713b4e3 1345 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1b8ec87a 1346 rdev->wiphy.available_antennas_tx) ||
3713b4e3 1347 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1b8ec87a 1348 rdev->wiphy.available_antennas_rx))
9360ffd1 1349 goto nla_put_failure;
b23aa676 1350
1b8ec87a 1351 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
3713b4e3 1352 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1b8ec87a 1353 rdev->wiphy.probe_resp_offload))
3713b4e3 1354 goto nla_put_failure;
8fdc621d 1355
1b8ec87a
ZG
1356 if ((rdev->wiphy.available_antennas_tx ||
1357 rdev->wiphy.available_antennas_rx) &&
1358 rdev->ops->get_antenna) {
3713b4e3
JB
1359 u32 tx_ant = 0, rx_ant = 0;
1360 int res;
1b8ec87a 1361 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant);
3713b4e3
JB
1362 if (!res) {
1363 if (nla_put_u32(msg,
1364 NL80211_ATTR_WIPHY_ANTENNA_TX,
1365 tx_ant) ||
1366 nla_put_u32(msg,
1367 NL80211_ATTR_WIPHY_ANTENNA_RX,
1368 rx_ant))
1369 goto nla_put_failure;
1370 }
1371 }
a293911d 1372
86e8cf98
JB
1373 state->split_start++;
1374 if (state->split)
3713b4e3
JB
1375 break;
1376 case 2:
1377 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1b8ec87a 1378 rdev->wiphy.interface_modes))
3713b4e3 1379 goto nla_put_failure;
86e8cf98
JB
1380 state->split_start++;
1381 if (state->split)
3713b4e3
JB
1382 break;
1383 case 3:
1384 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1385 if (!nl_bands)
1386 goto nla_put_failure;
f7ca38df 1387
86e8cf98
JB
1388 for (band = state->band_start;
1389 band < IEEE80211_NUM_BANDS; band++) {
3713b4e3 1390 struct ieee80211_supported_band *sband;
2e161f78 1391
1b8ec87a 1392 sband = rdev->wiphy.bands[band];
2e161f78 1393
3713b4e3
JB
1394 if (!sband)
1395 continue;
1396
1397 nl_band = nla_nest_start(msg, band);
1398 if (!nl_band)
2e161f78 1399 goto nla_put_failure;
3713b4e3 1400
86e8cf98 1401 switch (state->chan_start) {
3713b4e3
JB
1402 case 0:
1403 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 1404 goto nla_put_failure;
86e8cf98
JB
1405 state->chan_start++;
1406 if (state->split)
3713b4e3
JB
1407 break;
1408 default:
1409 /* add frequencies */
1410 nl_freqs = nla_nest_start(
1411 msg, NL80211_BAND_ATTR_FREQS);
1412 if (!nl_freqs)
1413 goto nla_put_failure;
1414
86e8cf98 1415 for (i = state->chan_start - 1;
3713b4e3
JB
1416 i < sband->n_channels;
1417 i++) {
1418 nl_freq = nla_nest_start(msg, i);
1419 if (!nl_freq)
1420 goto nla_put_failure;
1421
1422 chan = &sband->channels[i];
1423
86e8cf98
JB
1424 if (nl80211_msg_put_channel(
1425 msg, chan,
1426 state->split))
3713b4e3
JB
1427 goto nla_put_failure;
1428
1429 nla_nest_end(msg, nl_freq);
86e8cf98 1430 if (state->split)
3713b4e3
JB
1431 break;
1432 }
1433 if (i < sband->n_channels)
86e8cf98 1434 state->chan_start = i + 2;
3713b4e3 1435 else
86e8cf98 1436 state->chan_start = 0;
3713b4e3
JB
1437 nla_nest_end(msg, nl_freqs);
1438 }
1439
1440 nla_nest_end(msg, nl_band);
1441
86e8cf98 1442 if (state->split) {
3713b4e3 1443 /* start again here */
86e8cf98 1444 if (state->chan_start)
3713b4e3
JB
1445 band--;
1446 break;
2e161f78 1447 }
2e161f78 1448 }
3713b4e3 1449 nla_nest_end(msg, nl_bands);
2e161f78 1450
3713b4e3 1451 if (band < IEEE80211_NUM_BANDS)
86e8cf98 1452 state->band_start = band + 1;
3713b4e3 1453 else
86e8cf98 1454 state->band_start = 0;
74b70a4e 1455
3713b4e3 1456 /* if bands & channels are done, continue outside */
86e8cf98
JB
1457 if (state->band_start == 0 && state->chan_start == 0)
1458 state->split_start++;
1459 if (state->split)
3713b4e3
JB
1460 break;
1461 case 4:
1462 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1463 if (!nl_cmds)
2e161f78
JB
1464 goto nla_put_failure;
1465
3713b4e3
JB
1466 i = 0;
1467#define CMD(op, n) \
1468 do { \
1b8ec87a 1469 if (rdev->ops->op) { \
3713b4e3
JB
1470 i++; \
1471 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1472 goto nla_put_failure; \
1473 } \
1474 } while (0)
1475
1476 CMD(add_virtual_intf, NEW_INTERFACE);
1477 CMD(change_virtual_intf, SET_INTERFACE);
1478 CMD(add_key, NEW_KEY);
1479 CMD(start_ap, START_AP);
1480 CMD(add_station, NEW_STATION);
1481 CMD(add_mpath, NEW_MPATH);
1482 CMD(update_mesh_config, SET_MESH_CONFIG);
1483 CMD(change_bss, SET_BSS);
1484 CMD(auth, AUTHENTICATE);
1485 CMD(assoc, ASSOCIATE);
1486 CMD(deauth, DEAUTHENTICATE);
1487 CMD(disassoc, DISASSOCIATE);
1488 CMD(join_ibss, JOIN_IBSS);
1489 CMD(join_mesh, JOIN_MESH);
1490 CMD(set_pmksa, SET_PMKSA);
1491 CMD(del_pmksa, DEL_PMKSA);
1492 CMD(flush_pmksa, FLUSH_PMKSA);
1b8ec87a 1493 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
3713b4e3
JB
1494 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1495 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1496 CMD(mgmt_tx, FRAME);
1497 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1b8ec87a 1498 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
3713b4e3
JB
1499 i++;
1500 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
2e161f78 1501 goto nla_put_failure;
2e161f78 1502 }
1b8ec87a
ZG
1503 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap ||
1504 rdev->ops->join_mesh) {
3713b4e3
JB
1505 i++;
1506 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1507 goto nla_put_failure;
1508 }
1509 CMD(set_wds_peer, SET_WDS_PEER);
1b8ec87a 1510 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
3713b4e3
JB
1511 CMD(tdls_mgmt, TDLS_MGMT);
1512 CMD(tdls_oper, TDLS_OPER);
1513 }
1b8ec87a 1514 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
3713b4e3
JB
1515 CMD(sched_scan_start, START_SCHED_SCAN);
1516 CMD(probe_client, PROBE_CLIENT);
1517 CMD(set_noack_map, SET_NOACK_MAP);
1b8ec87a 1518 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
3713b4e3
JB
1519 i++;
1520 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1521 goto nla_put_failure;
1522 }
1523 CMD(start_p2p_device, START_P2P_DEVICE);
1524 CMD(set_mcast_rate, SET_MCAST_RATE);
02df00eb
JB
1525#ifdef CONFIG_NL80211_TESTMODE
1526 CMD(testmode_cmd, TESTMODE);
1527#endif
86e8cf98 1528 if (state->split) {
5de17984
AS
1529 CMD(crit_proto_start, CRIT_PROTOCOL_START);
1530 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
1b8ec87a 1531 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
16ef1fe2 1532 CMD(channel_switch, CHANNEL_SWITCH);
02df00eb 1533 CMD(set_qos_map, SET_QOS_MAP);
723e73ac
JB
1534 if (rdev->wiphy.features &
1535 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)
960d01ac 1536 CMD(add_tx_ts, ADD_TX_TS);
5de17984 1537 }
02df00eb 1538 /* add into the if now */
3713b4e3 1539#undef CMD
ff1b6e69 1540
1b8ec87a 1541 if (rdev->ops->connect || rdev->ops->auth) {
3713b4e3
JB
1542 i++;
1543 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
9360ffd1 1544 goto nla_put_failure;
ff1b6e69
JB
1545 }
1546
1b8ec87a 1547 if (rdev->ops->disconnect || rdev->ops->deauth) {
3713b4e3
JB
1548 i++;
1549 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1550 goto nla_put_failure;
1551 }
1552
1553 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
1554 state->split_start++;
1555 if (state->split)
3713b4e3
JB
1556 break;
1557 case 5:
1b8ec87a
ZG
1558 if (rdev->ops->remain_on_channel &&
1559 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
3713b4e3
JB
1560 nla_put_u32(msg,
1561 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1b8ec87a 1562 rdev->wiphy.max_remain_on_channel_duration))
3713b4e3
JB
1563 goto nla_put_failure;
1564
1b8ec87a 1565 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
3713b4e3
JB
1566 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1567 goto nla_put_failure;
1568
1569 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
1570 goto nla_put_failure;
86e8cf98
JB
1571 state->split_start++;
1572 if (state->split)
3713b4e3
JB
1573 break;
1574 case 6:
1575#ifdef CONFIG_PM
1b8ec87a 1576 if (nl80211_send_wowlan(msg, rdev, state->split))
3713b4e3 1577 goto nla_put_failure;
86e8cf98
JB
1578 state->split_start++;
1579 if (state->split)
3713b4e3
JB
1580 break;
1581#else
86e8cf98 1582 state->split_start++;
dfb89c56 1583#endif
3713b4e3
JB
1584 case 7:
1585 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1b8ec87a 1586 rdev->wiphy.software_iftypes))
3713b4e3 1587 goto nla_put_failure;
ff1b6e69 1588
1b8ec87a 1589 if (nl80211_put_iface_combinations(&rdev->wiphy, msg,
86e8cf98 1590 state->split))
3713b4e3 1591 goto nla_put_failure;
7527a782 1592
86e8cf98
JB
1593 state->split_start++;
1594 if (state->split)
3713b4e3
JB
1595 break;
1596 case 8:
1b8ec87a 1597 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
3713b4e3 1598 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1b8ec87a 1599 rdev->wiphy.ap_sme_capa))
3713b4e3 1600 goto nla_put_failure;
7527a782 1601
1b8ec87a 1602 features = rdev->wiphy.features;
fe1abafd
JB
1603 /*
1604 * We can only add the per-channel limit information if the
1605 * dump is split, otherwise it makes it too big. Therefore
1606 * only advertise it in that case.
1607 */
86e8cf98 1608 if (state->split)
fe1abafd
JB
1609 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
1610 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 1611 goto nla_put_failure;
562a7480 1612
1b8ec87a 1613 if (rdev->wiphy.ht_capa_mod_mask &&
3713b4e3 1614 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1b8ec87a
ZG
1615 sizeof(*rdev->wiphy.ht_capa_mod_mask),
1616 rdev->wiphy.ht_capa_mod_mask))
3713b4e3 1617 goto nla_put_failure;
1f074bd8 1618
1b8ec87a
ZG
1619 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1620 rdev->wiphy.max_acl_mac_addrs &&
3713b4e3 1621 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1b8ec87a 1622 rdev->wiphy.max_acl_mac_addrs))
3713b4e3 1623 goto nla_put_failure;
7e7c8926 1624
3713b4e3
JB
1625 /*
1626 * Any information below this point is only available to
1627 * applications that can deal with it being split. This
1628 * helps ensure that newly added capabilities don't break
1629 * older tools by overrunning their buffers.
1630 *
1631 * We still increment split_start so that in the split
1632 * case we'll continue with more data in the next round,
1633 * but break unconditionally so unsplit data stops here.
1634 */
86e8cf98 1635 state->split_start++;
3713b4e3
JB
1636 break;
1637 case 9:
1b8ec87a 1638 if (rdev->wiphy.extended_capabilities &&
fe1abafd 1639 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1b8ec87a
ZG
1640 rdev->wiphy.extended_capabilities_len,
1641 rdev->wiphy.extended_capabilities) ||
fe1abafd 1642 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1b8ec87a
ZG
1643 rdev->wiphy.extended_capabilities_len,
1644 rdev->wiphy.extended_capabilities_mask)))
fe1abafd 1645 goto nla_put_failure;
a50df0c4 1646
1b8ec87a 1647 if (rdev->wiphy.vht_capa_mod_mask &&
ee2aca34 1648 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1b8ec87a
ZG
1649 sizeof(*rdev->wiphy.vht_capa_mod_mask),
1650 rdev->wiphy.vht_capa_mod_mask))
ee2aca34
JB
1651 goto nla_put_failure;
1652
be29b99a
AK
1653 state->split_start++;
1654 break;
1655 case 10:
1b8ec87a 1656 if (nl80211_send_coalesce(msg, rdev))
be29b99a
AK
1657 goto nla_put_failure;
1658
1b8ec87a 1659 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
01e0daa4
FF
1660 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
1661 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
1662 goto nla_put_failure;
b43504cf 1663
1b8ec87a 1664 if (rdev->wiphy.max_ap_assoc_sta &&
b43504cf 1665 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
1b8ec87a 1666 rdev->wiphy.max_ap_assoc_sta))
b43504cf
JM
1667 goto nla_put_failure;
1668
ad7e718c
JB
1669 state->split_start++;
1670 break;
1671 case 11:
1b8ec87a 1672 if (rdev->wiphy.n_vendor_commands) {
567ffc35
JB
1673 const struct nl80211_vendor_cmd_info *info;
1674 struct nlattr *nested;
1675
1676 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA);
1677 if (!nested)
1678 goto nla_put_failure;
1679
1b8ec87a
ZG
1680 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
1681 info = &rdev->wiphy.vendor_commands[i].info;
567ffc35
JB
1682 if (nla_put(msg, i + 1, sizeof(*info), info))
1683 goto nla_put_failure;
1684 }
1685 nla_nest_end(msg, nested);
1686 }
1687
1b8ec87a 1688 if (rdev->wiphy.n_vendor_events) {
567ffc35
JB
1689 const struct nl80211_vendor_cmd_info *info;
1690 struct nlattr *nested;
ad7e718c 1691
567ffc35
JB
1692 nested = nla_nest_start(msg,
1693 NL80211_ATTR_VENDOR_EVENTS);
1694 if (!nested)
ad7e718c 1695 goto nla_put_failure;
567ffc35 1696
1b8ec87a
ZG
1697 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) {
1698 info = &rdev->wiphy.vendor_events[i];
567ffc35
JB
1699 if (nla_put(msg, i + 1, sizeof(*info), info))
1700 goto nla_put_failure;
1701 }
1702 nla_nest_end(msg, nested);
1703 }
9a774c78
AO
1704 state->split_start++;
1705 break;
1706 case 12:
1707 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH &&
1708 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS,
1709 rdev->wiphy.max_num_csa_counters))
1710 goto nla_put_failure;
01e0daa4 1711
1bdd716c
AN
1712 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
1713 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
1714 goto nla_put_failure;
1715
d75bb06b
GKS
1716 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES,
1717 sizeof(rdev->wiphy.ext_features),
1718 rdev->wiphy.ext_features))
1719 goto nla_put_failure;
1720
3713b4e3 1721 /* done */
86e8cf98 1722 state->split_start = 0;
3713b4e3
JB
1723 break;
1724 }
3bb20556 1725 finish:
053c095a
JB
1726 genlmsg_end(msg, hdr);
1727 return 0;
55682965
JB
1728
1729 nla_put_failure:
bc3ed28c
TG
1730 genlmsg_cancel(msg, hdr);
1731 return -EMSGSIZE;
55682965
JB
1732}
1733
86e8cf98
JB
1734static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
1735 struct netlink_callback *cb,
1736 struct nl80211_dump_wiphy_state *state)
1737{
1738 struct nlattr **tb = nl80211_fam.attrbuf;
1739 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1740 tb, nl80211_fam.maxattr, nl80211_policy);
1741 /* ignore parse errors for backward compatibility */
1742 if (ret)
1743 return 0;
1744
1745 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
1746 if (tb[NL80211_ATTR_WIPHY])
1747 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
1748 if (tb[NL80211_ATTR_WDEV])
1749 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
1750 if (tb[NL80211_ATTR_IFINDEX]) {
1751 struct net_device *netdev;
1752 struct cfg80211_registered_device *rdev;
1753 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
1754
7f2b8562 1755 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
86e8cf98
JB
1756 if (!netdev)
1757 return -ENODEV;
1758 if (netdev->ieee80211_ptr) {
f26cbf40 1759 rdev = wiphy_to_rdev(
86e8cf98
JB
1760 netdev->ieee80211_ptr->wiphy);
1761 state->filter_wiphy = rdev->wiphy_idx;
1762 }
86e8cf98
JB
1763 }
1764
1765 return 0;
1766}
1767
55682965
JB
1768static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1769{
645e77de 1770 int idx = 0, ret;
86e8cf98 1771 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
1b8ec87a 1772 struct cfg80211_registered_device *rdev;
3a5a423b 1773
5fe231e8 1774 rtnl_lock();
86e8cf98
JB
1775 if (!state) {
1776 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
1777 if (!state) {
1778 rtnl_unlock();
86e8cf98 1779 return -ENOMEM;
3713b4e3 1780 }
86e8cf98
JB
1781 state->filter_wiphy = -1;
1782 ret = nl80211_dump_wiphy_parse(skb, cb, state);
1783 if (ret) {
1784 kfree(state);
1785 rtnl_unlock();
1786 return ret;
3713b4e3 1787 }
86e8cf98 1788 cb->args[0] = (long)state;
3713b4e3
JB
1789 }
1790
1b8ec87a
ZG
1791 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1792 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1793 continue;
86e8cf98 1794 if (++idx <= state->start)
55682965 1795 continue;
86e8cf98 1796 if (state->filter_wiphy != -1 &&
1b8ec87a 1797 state->filter_wiphy != rdev->wiphy_idx)
3713b4e3
JB
1798 continue;
1799 /* attempt to fit multiple wiphy data chunks into the skb */
1800 do {
3bb20556
JB
1801 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY,
1802 skb,
3713b4e3
JB
1803 NETLINK_CB(cb->skb).portid,
1804 cb->nlh->nlmsg_seq,
86e8cf98 1805 NLM_F_MULTI, state);
3713b4e3
JB
1806 if (ret < 0) {
1807 /*
1808 * If sending the wiphy data didn't fit (ENOBUFS
1809 * or EMSGSIZE returned), this SKB is still
1810 * empty (so it's not too big because another
1811 * wiphy dataset is already in the skb) and
1812 * we've not tried to adjust the dump allocation
1813 * yet ... then adjust the alloc size to be
1814 * bigger, and return 1 but with the empty skb.
1815 * This results in an empty message being RX'ed
1816 * in userspace, but that is ignored.
1817 *
1818 * We can then retry with the larger buffer.
1819 */
1820 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
f12cb289 1821 !skb->len && !state->split &&
3713b4e3
JB
1822 cb->min_dump_alloc < 4096) {
1823 cb->min_dump_alloc = 4096;
f12cb289 1824 state->split_start = 0;
d98cae64 1825 rtnl_unlock();
3713b4e3
JB
1826 return 1;
1827 }
1828 idx--;
1829 break;
645e77de 1830 }
86e8cf98 1831 } while (state->split_start > 0);
3713b4e3 1832 break;
55682965 1833 }
5fe231e8 1834 rtnl_unlock();
55682965 1835
86e8cf98 1836 state->start = idx;
55682965
JB
1837
1838 return skb->len;
1839}
1840
86e8cf98
JB
1841static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
1842{
1843 kfree((void *)cb->args[0]);
1844 return 0;
1845}
1846
55682965
JB
1847static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1848{
1849 struct sk_buff *msg;
1b8ec87a 1850 struct cfg80211_registered_device *rdev = info->user_ptr[0];
86e8cf98 1851 struct nl80211_dump_wiphy_state state = {};
55682965 1852
645e77de 1853 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 1854 if (!msg)
4c476991 1855 return -ENOMEM;
55682965 1856
3bb20556
JB
1857 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg,
1858 info->snd_portid, info->snd_seq, 0,
86e8cf98 1859 &state) < 0) {
4c476991
JB
1860 nlmsg_free(msg);
1861 return -ENOBUFS;
1862 }
55682965 1863
134e6375 1864 return genlmsg_reply(msg, info);
55682965
JB
1865}
1866
31888487
JM
1867static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1868 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1869 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1870 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1871 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1872 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1873};
1874
1875static int parse_txq_params(struct nlattr *tb[],
1876 struct ieee80211_txq_params *txq_params)
1877{
a3304b0a 1878 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1879 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1880 !tb[NL80211_TXQ_ATTR_AIFS])
1881 return -EINVAL;
1882
a3304b0a 1883 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1884 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1885 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1886 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1887 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1888
a3304b0a
JB
1889 if (txq_params->ac >= NL80211_NUM_ACS)
1890 return -EINVAL;
1891
31888487
JM
1892 return 0;
1893}
1894
f444de05
JB
1895static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1896{
1897 /*
cc1d2806
JB
1898 * You can only set the channel explicitly for WDS interfaces,
1899 * all others have their channel managed via their respective
1900 * "establish a connection" command (connect, join, ...)
1901 *
1902 * For AP/GO and mesh mode, the channel can be set with the
1903 * channel userspace API, but is only stored and passed to the
1904 * low-level driver when the AP starts or the mesh is joined.
1905 * This is for backward compatibility, userspace can also give
1906 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1907 *
1908 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1909 * whatever else is going on, so they have their own special
1910 * operation to set the monitor channel if possible.
f444de05
JB
1911 */
1912 return !wdev ||
1913 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1914 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1915 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1916 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1917}
1918
683b6d3b
JB
1919static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1920 struct genl_info *info,
1921 struct cfg80211_chan_def *chandef)
1922{
dbeca2ea 1923 u32 control_freq;
683b6d3b
JB
1924
1925 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1926 return -EINVAL;
1927
1928 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1929
1930 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1931 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1932 chandef->center_freq1 = control_freq;
1933 chandef->center_freq2 = 0;
683b6d3b
JB
1934
1935 /* Primary channel not allowed */
1936 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1937 return -EINVAL;
1938
3d9d1d66
JB
1939 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1940 enum nl80211_channel_type chantype;
1941
1942 chantype = nla_get_u32(
1943 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1944
1945 switch (chantype) {
1946 case NL80211_CHAN_NO_HT:
1947 case NL80211_CHAN_HT20:
1948 case NL80211_CHAN_HT40PLUS:
1949 case NL80211_CHAN_HT40MINUS:
1950 cfg80211_chandef_create(chandef, chandef->chan,
1951 chantype);
1952 break;
1953 default:
1954 return -EINVAL;
1955 }
1956 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1957 chandef->width =
1958 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1959 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1960 chandef->center_freq1 =
1961 nla_get_u32(
1962 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1963 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1964 chandef->center_freq2 =
1965 nla_get_u32(
1966 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1967 }
1968
9f5e8f6e 1969 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1970 return -EINVAL;
1971
9f5e8f6e
JB
1972 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1973 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1974 return -EINVAL;
1975
2f301ab2
SW
1976 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
1977 chandef->width == NL80211_CHAN_WIDTH_10) &&
1978 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ))
1979 return -EINVAL;
1980
683b6d3b
JB
1981 return 0;
1982}
1983
f444de05 1984static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
e16821bc 1985 struct net_device *dev,
f444de05
JB
1986 struct genl_info *info)
1987{
683b6d3b 1988 struct cfg80211_chan_def chandef;
f444de05 1989 int result;
e8c9bd5b 1990 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
e16821bc 1991 struct wireless_dev *wdev = NULL;
e8c9bd5b 1992
e16821bc
JM
1993 if (dev)
1994 wdev = dev->ieee80211_ptr;
f444de05
JB
1995 if (!nl80211_can_set_dev_channel(wdev))
1996 return -EOPNOTSUPP;
e16821bc
JM
1997 if (wdev)
1998 iftype = wdev->iftype;
f444de05 1999
683b6d3b
JB
2000 result = nl80211_parse_chandef(rdev, info, &chandef);
2001 if (result)
2002 return result;
f444de05 2003
e8c9bd5b 2004 switch (iftype) {
aa430da4
JB
2005 case NL80211_IFTYPE_AP:
2006 case NL80211_IFTYPE_P2P_GO:
923b352f
AN
2007 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
2008 iftype)) {
aa430da4
JB
2009 result = -EINVAL;
2010 break;
2011 }
e16821bc
JM
2012 if (wdev->beacon_interval) {
2013 if (!dev || !rdev->ops->set_ap_chanwidth ||
2014 !(rdev->wiphy.features &
2015 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) {
2016 result = -EBUSY;
2017 break;
2018 }
2019
2020 /* Only allow dynamic channel width changes */
2021 if (chandef.chan != wdev->preset_chandef.chan) {
2022 result = -EBUSY;
2023 break;
2024 }
2025 result = rdev_set_ap_chanwidth(rdev, dev, &chandef);
2026 if (result)
2027 break;
2028 }
683b6d3b 2029 wdev->preset_chandef = chandef;
aa430da4
JB
2030 result = 0;
2031 break;
cc1d2806 2032 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 2033 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 2034 break;
e8c9bd5b 2035 case NL80211_IFTYPE_MONITOR:
683b6d3b 2036 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 2037 break;
aa430da4 2038 default:
e8c9bd5b 2039 result = -EINVAL;
f444de05 2040 }
f444de05
JB
2041
2042 return result;
2043}
2044
2045static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
2046{
4c476991
JB
2047 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2048 struct net_device *netdev = info->user_ptr[1];
f444de05 2049
e16821bc 2050 return __nl80211_set_channel(rdev, netdev, info);
f444de05
JB
2051}
2052
e8347eba
BJ
2053static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
2054{
43b19952
JB
2055 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2056 struct net_device *dev = info->user_ptr[1];
2057 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 2058 const u8 *bssid;
e8347eba
BJ
2059
2060 if (!info->attrs[NL80211_ATTR_MAC])
2061 return -EINVAL;
2062
43b19952
JB
2063 if (netif_running(dev))
2064 return -EBUSY;
e8347eba 2065
43b19952
JB
2066 if (!rdev->ops->set_wds_peer)
2067 return -EOPNOTSUPP;
e8347eba 2068
43b19952
JB
2069 if (wdev->iftype != NL80211_IFTYPE_WDS)
2070 return -EOPNOTSUPP;
e8347eba
BJ
2071
2072 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 2073 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
2074}
2075
2076
55682965
JB
2077static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
2078{
2079 struct cfg80211_registered_device *rdev;
f444de05
JB
2080 struct net_device *netdev = NULL;
2081 struct wireless_dev *wdev;
a1e567c8 2082 int result = 0, rem_txq_params = 0;
31888487 2083 struct nlattr *nl_txq_params;
b9a5f8ca
JM
2084 u32 changed;
2085 u8 retry_short = 0, retry_long = 0;
2086 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 2087 u8 coverage_class = 0;
55682965 2088
5fe231e8
JB
2089 ASSERT_RTNL();
2090
f444de05
JB
2091 /*
2092 * Try to find the wiphy and netdev. Normally this
2093 * function shouldn't need the netdev, but this is
2094 * done for backward compatibility -- previously
2095 * setting the channel was done per wiphy, but now
2096 * it is per netdev. Previous userland like hostapd
2097 * also passed a netdev to set_wiphy, so that it is
2098 * possible to let that go to the right netdev!
2099 */
4bbf4d56 2100
f444de05
JB
2101 if (info->attrs[NL80211_ATTR_IFINDEX]) {
2102 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
2103
7f2b8562 2104 netdev = __dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 2105 if (netdev && netdev->ieee80211_ptr)
f26cbf40 2106 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy);
5fe231e8 2107 else
f444de05 2108 netdev = NULL;
4bbf4d56
JB
2109 }
2110
f444de05 2111 if (!netdev) {
878d9ec7
JB
2112 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
2113 info->attrs);
5fe231e8 2114 if (IS_ERR(rdev))
4c476991 2115 return PTR_ERR(rdev);
f444de05
JB
2116 wdev = NULL;
2117 netdev = NULL;
2118 result = 0;
71fe96bf 2119 } else
f444de05 2120 wdev = netdev->ieee80211_ptr;
f444de05
JB
2121
2122 /*
2123 * end workaround code, by now the rdev is available
2124 * and locked, and wdev may or may not be NULL.
2125 */
4bbf4d56
JB
2126
2127 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
2128 result = cfg80211_dev_rename(
2129 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 2130
4bbf4d56 2131 if (result)
7f2b8562 2132 return result;
31888487
JM
2133
2134 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
2135 struct ieee80211_txq_params txq_params;
2136 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
2137
7f2b8562
YX
2138 if (!rdev->ops->set_txq_params)
2139 return -EOPNOTSUPP;
31888487 2140
7f2b8562
YX
2141 if (!netdev)
2142 return -EINVAL;
f70f01c2 2143
133a3ff2 2144 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7f2b8562
YX
2145 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2146 return -EINVAL;
133a3ff2 2147
7f2b8562
YX
2148 if (!netif_running(netdev))
2149 return -ENETDOWN;
2b5f8b0b 2150
31888487
JM
2151 nla_for_each_nested(nl_txq_params,
2152 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
2153 rem_txq_params) {
ae811e21
JB
2154 result = nla_parse(tb, NL80211_TXQ_ATTR_MAX,
2155 nla_data(nl_txq_params),
2156 nla_len(nl_txq_params),
2157 txq_params_policy);
2158 if (result)
2159 return result;
31888487
JM
2160 result = parse_txq_params(tb, &txq_params);
2161 if (result)
7f2b8562 2162 return result;
31888487 2163
e35e4d28
HG
2164 result = rdev_set_txq_params(rdev, netdev,
2165 &txq_params);
31888487 2166 if (result)
7f2b8562 2167 return result;
31888487
JM
2168 }
2169 }
55682965 2170
72bdcf34 2171 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
e16821bc
JM
2172 result = __nl80211_set_channel(
2173 rdev,
2174 nl80211_can_set_dev_channel(wdev) ? netdev : NULL,
2175 info);
72bdcf34 2176 if (result)
7f2b8562 2177 return result;
72bdcf34
JM
2178 }
2179
98d2ff8b 2180 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 2181 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
2182 enum nl80211_tx_power_setting type;
2183 int idx, mbm = 0;
2184
c8442118
JB
2185 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
2186 txp_wdev = NULL;
2187
7f2b8562
YX
2188 if (!rdev->ops->set_tx_power)
2189 return -EOPNOTSUPP;
98d2ff8b
JO
2190
2191 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
2192 type = nla_get_u32(info->attrs[idx]);
2193
2194 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
7f2b8562
YX
2195 (type != NL80211_TX_POWER_AUTOMATIC))
2196 return -EINVAL;
98d2ff8b
JO
2197
2198 if (type != NL80211_TX_POWER_AUTOMATIC) {
2199 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
2200 mbm = nla_get_u32(info->attrs[idx]);
2201 }
2202
c8442118 2203 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b 2204 if (result)
7f2b8562 2205 return result;
98d2ff8b
JO
2206 }
2207
afe0cbf8
BR
2208 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
2209 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
2210 u32 tx_ant, rx_ant;
7f531e03
BR
2211 if ((!rdev->wiphy.available_antennas_tx &&
2212 !rdev->wiphy.available_antennas_rx) ||
7f2b8562
YX
2213 !rdev->ops->set_antenna)
2214 return -EOPNOTSUPP;
afe0cbf8
BR
2215
2216 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
2217 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
2218
a7ffac95 2219 /* reject antenna configurations which don't match the
7f531e03
BR
2220 * available antenna masks, except for the "all" mask */
2221 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
7f2b8562
YX
2222 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx)))
2223 return -EINVAL;
a7ffac95 2224
7f531e03
BR
2225 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
2226 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 2227
e35e4d28 2228 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8 2229 if (result)
7f2b8562 2230 return result;
afe0cbf8
BR
2231 }
2232
b9a5f8ca
JM
2233 changed = 0;
2234
2235 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
2236 retry_short = nla_get_u8(
2237 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
7f2b8562
YX
2238 if (retry_short == 0)
2239 return -EINVAL;
2240
b9a5f8ca
JM
2241 changed |= WIPHY_PARAM_RETRY_SHORT;
2242 }
2243
2244 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2245 retry_long = nla_get_u8(
2246 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
7f2b8562
YX
2247 if (retry_long == 0)
2248 return -EINVAL;
2249
b9a5f8ca
JM
2250 changed |= WIPHY_PARAM_RETRY_LONG;
2251 }
2252
2253 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2254 frag_threshold = nla_get_u32(
2255 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
7f2b8562
YX
2256 if (frag_threshold < 256)
2257 return -EINVAL;
2258
b9a5f8ca
JM
2259 if (frag_threshold != (u32) -1) {
2260 /*
2261 * Fragments (apart from the last one) are required to
2262 * have even length. Make the fragmentation code
2263 * simpler by stripping LSB should someone try to use
2264 * odd threshold value.
2265 */
2266 frag_threshold &= ~0x1;
2267 }
2268 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2269 }
2270
2271 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2272 rts_threshold = nla_get_u32(
2273 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2274 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2275 }
2276
81077e82 2277 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
3057dbfd
LB
2278 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK])
2279 return -EINVAL;
2280
81077e82
LT
2281 coverage_class = nla_get_u8(
2282 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2283 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2284 }
2285
3057dbfd
LB
2286 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
2287 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION))
2288 return -EOPNOTSUPP;
2289
2290 changed |= WIPHY_PARAM_DYN_ACK;
81077e82
LT
2291 }
2292
b9a5f8ca
JM
2293 if (changed) {
2294 u8 old_retry_short, old_retry_long;
2295 u32 old_frag_threshold, old_rts_threshold;
81077e82 2296 u8 old_coverage_class;
b9a5f8ca 2297
7f2b8562
YX
2298 if (!rdev->ops->set_wiphy_params)
2299 return -EOPNOTSUPP;
b9a5f8ca
JM
2300
2301 old_retry_short = rdev->wiphy.retry_short;
2302 old_retry_long = rdev->wiphy.retry_long;
2303 old_frag_threshold = rdev->wiphy.frag_threshold;
2304 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 2305 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
2306
2307 if (changed & WIPHY_PARAM_RETRY_SHORT)
2308 rdev->wiphy.retry_short = retry_short;
2309 if (changed & WIPHY_PARAM_RETRY_LONG)
2310 rdev->wiphy.retry_long = retry_long;
2311 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
2312 rdev->wiphy.frag_threshold = frag_threshold;
2313 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
2314 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
2315 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
2316 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 2317
e35e4d28 2318 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
2319 if (result) {
2320 rdev->wiphy.retry_short = old_retry_short;
2321 rdev->wiphy.retry_long = old_retry_long;
2322 rdev->wiphy.frag_threshold = old_frag_threshold;
2323 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 2324 rdev->wiphy.coverage_class = old_coverage_class;
9189ee31 2325 return result;
b9a5f8ca
JM
2326 }
2327 }
7f2b8562 2328 return 0;
55682965
JB
2329}
2330
71bbc994
JB
2331static inline u64 wdev_id(struct wireless_dev *wdev)
2332{
2333 return (u64)wdev->identifier |
f26cbf40 2334 ((u64)wiphy_to_rdev(wdev->wiphy)->wiphy_idx << 32);
71bbc994 2335}
55682965 2336
683b6d3b 2337static int nl80211_send_chandef(struct sk_buff *msg,
d2859df5 2338 const struct cfg80211_chan_def *chandef)
683b6d3b 2339{
601555cd
JB
2340 if (WARN_ON(!cfg80211_chandef_valid(chandef)))
2341 return -EINVAL;
3d9d1d66 2342
683b6d3b
JB
2343 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
2344 chandef->chan->center_freq))
2345 return -ENOBUFS;
3d9d1d66
JB
2346 switch (chandef->width) {
2347 case NL80211_CHAN_WIDTH_20_NOHT:
2348 case NL80211_CHAN_WIDTH_20:
2349 case NL80211_CHAN_WIDTH_40:
2350 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2351 cfg80211_get_chandef_type(chandef)))
2352 return -ENOBUFS;
2353 break;
2354 default:
2355 break;
2356 }
2357 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
2358 return -ENOBUFS;
2359 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
2360 return -ENOBUFS;
2361 if (chandef->center_freq2 &&
2362 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
2363 return -ENOBUFS;
2364 return 0;
2365}
2366
15e47304 2367static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 2368 struct cfg80211_registered_device *rdev,
8f894be2 2369 struct wireless_dev *wdev, bool removal)
55682965 2370{
72fb2abc 2371 struct net_device *dev = wdev->netdev;
8f894be2 2372 u8 cmd = NL80211_CMD_NEW_INTERFACE;
55682965
JB
2373 void *hdr;
2374
8f894be2
TB
2375 if (removal)
2376 cmd = NL80211_CMD_DEL_INTERFACE;
2377
2378 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
55682965
JB
2379 if (!hdr)
2380 return -1;
2381
72fb2abc
JB
2382 if (dev &&
2383 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 2384 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
2385 goto nla_put_failure;
2386
2387 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2388 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 2389 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 2390 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
2391 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2392 rdev->devlist_generation ^
2393 (cfg80211_rdev_list_generation << 2)))
2394 goto nla_put_failure;
f5ea9120 2395
5b7ccaf3 2396 if (rdev->ops->get_channel) {
683b6d3b
JB
2397 int ret;
2398 struct cfg80211_chan_def chandef;
2399
2400 ret = rdev_get_channel(rdev, wdev, &chandef);
2401 if (ret == 0) {
2402 if (nl80211_send_chandef(msg, &chandef))
2403 goto nla_put_failure;
2404 }
d91df0e3
PF
2405 }
2406
b84e7a05
AQ
2407 if (wdev->ssid_len) {
2408 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
2409 goto nla_put_failure;
2410 }
2411
053c095a
JB
2412 genlmsg_end(msg, hdr);
2413 return 0;
55682965
JB
2414
2415 nla_put_failure:
bc3ed28c
TG
2416 genlmsg_cancel(msg, hdr);
2417 return -EMSGSIZE;
55682965
JB
2418}
2419
2420static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
2421{
2422 int wp_idx = 0;
2423 int if_idx = 0;
2424 int wp_start = cb->args[0];
2425 int if_start = cb->args[1];
f5ea9120 2426 struct cfg80211_registered_device *rdev;
55682965
JB
2427 struct wireless_dev *wdev;
2428
5fe231e8 2429 rtnl_lock();
f5ea9120
JB
2430 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2431 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2432 continue;
bba95fef
JB
2433 if (wp_idx < wp_start) {
2434 wp_idx++;
55682965 2435 continue;
bba95fef 2436 }
55682965
JB
2437 if_idx = 0;
2438
89a54e48 2439 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
2440 if (if_idx < if_start) {
2441 if_idx++;
55682965 2442 continue;
bba95fef 2443 }
15e47304 2444 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 2445 cb->nlh->nlmsg_seq, NLM_F_MULTI,
8f894be2 2446 rdev, wdev, false) < 0) {
bba95fef
JB
2447 goto out;
2448 }
2449 if_idx++;
55682965 2450 }
bba95fef
JB
2451
2452 wp_idx++;
55682965 2453 }
bba95fef 2454 out:
5fe231e8 2455 rtnl_unlock();
55682965
JB
2456
2457 cb->args[0] = wp_idx;
2458 cb->args[1] = if_idx;
2459
2460 return skb->len;
2461}
2462
2463static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
2464{
2465 struct sk_buff *msg;
1b8ec87a 2466 struct cfg80211_registered_device *rdev = info->user_ptr[0];
72fb2abc 2467 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2468
fd2120ca 2469 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 2470 if (!msg)
4c476991 2471 return -ENOMEM;
55682965 2472
15e47304 2473 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
8f894be2 2474 rdev, wdev, false) < 0) {
4c476991
JB
2475 nlmsg_free(msg);
2476 return -ENOBUFS;
2477 }
55682965 2478
134e6375 2479 return genlmsg_reply(msg, info);
55682965
JB
2480}
2481
66f7ac50
MW
2482static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2483 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2484 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2485 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2486 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2487 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 2488 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
2489};
2490
2491static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2492{
2493 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2494 int flag;
2495
2496 *mntrflags = 0;
2497
2498 if (!nla)
2499 return -EINVAL;
2500
2501 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
2502 nla, mntr_flags_policy))
2503 return -EINVAL;
2504
2505 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2506 if (flags[flag])
2507 *mntrflags |= (1<<flag);
2508
2509 return 0;
2510}
2511
9bc383de 2512static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2513 struct net_device *netdev, u8 use_4addr,
2514 enum nl80211_iftype iftype)
9bc383de 2515{
ad4bb6f8 2516 if (!use_4addr) {
f350a0a8 2517 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2518 return -EBUSY;
9bc383de 2519 return 0;
ad4bb6f8 2520 }
9bc383de
JB
2521
2522 switch (iftype) {
2523 case NL80211_IFTYPE_AP_VLAN:
2524 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2525 return 0;
2526 break;
2527 case NL80211_IFTYPE_STATION:
2528 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2529 return 0;
2530 break;
2531 default:
2532 break;
2533 }
2534
2535 return -EOPNOTSUPP;
2536}
2537
55682965
JB
2538static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2539{
4c476991 2540 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2541 struct vif_params params;
e36d56b6 2542 int err;
04a773ad 2543 enum nl80211_iftype otype, ntype;
4c476991 2544 struct net_device *dev = info->user_ptr[1];
92ffe055 2545 u32 _flags, *flags = NULL;
ac7f9cfa 2546 bool change = false;
55682965 2547
2ec600d6
LCC
2548 memset(&params, 0, sizeof(params));
2549
04a773ad 2550 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2551
723b038d 2552 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2553 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2554 if (otype != ntype)
ac7f9cfa 2555 change = true;
4c476991
JB
2556 if (ntype > NL80211_IFTYPE_MAX)
2557 return -EINVAL;
723b038d
JB
2558 }
2559
92ffe055 2560 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2561 struct wireless_dev *wdev = dev->ieee80211_ptr;
2562
4c476991
JB
2563 if (ntype != NL80211_IFTYPE_MESH_POINT)
2564 return -EINVAL;
29cbe68c
JB
2565 if (netif_running(dev))
2566 return -EBUSY;
2567
2568 wdev_lock(wdev);
2569 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2570 IEEE80211_MAX_MESH_ID_LEN);
2571 wdev->mesh_id_up_len =
2572 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2573 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2574 wdev->mesh_id_up_len);
2575 wdev_unlock(wdev);
2ec600d6
LCC
2576 }
2577
8b787643
FF
2578 if (info->attrs[NL80211_ATTR_4ADDR]) {
2579 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2580 change = true;
ad4bb6f8 2581 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2582 if (err)
4c476991 2583 return err;
8b787643
FF
2584 } else {
2585 params.use_4addr = -1;
2586 }
2587
92ffe055 2588 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2589 if (ntype != NL80211_IFTYPE_MONITOR)
2590 return -EINVAL;
92ffe055
JB
2591 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2592 &_flags);
ac7f9cfa 2593 if (err)
4c476991 2594 return err;
ac7f9cfa
JB
2595
2596 flags = &_flags;
2597 change = true;
92ffe055 2598 }
3b85875a 2599
18003297 2600 if (flags && (*flags & MONITOR_FLAG_ACTIVE) &&
e057d3c3
FF
2601 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2602 return -EOPNOTSUPP;
2603
ac7f9cfa 2604 if (change)
3d54d255 2605 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2606 else
2607 err = 0;
60719ffd 2608
9bc383de
JB
2609 if (!err && params.use_4addr != -1)
2610 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2611
55682965
JB
2612 return err;
2613}
2614
2615static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2616{
4c476991 2617 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2618 struct vif_params params;
84efbb84 2619 struct wireless_dev *wdev;
8f894be2 2620 struct sk_buff *msg, *event;
55682965
JB
2621 int err;
2622 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2623 u32 flags;
55682965 2624
78f22b6a
JB
2625 /* to avoid failing a new interface creation due to pending removal */
2626 cfg80211_destroy_ifaces(rdev);
2627
2ec600d6
LCC
2628 memset(&params, 0, sizeof(params));
2629
55682965
JB
2630 if (!info->attrs[NL80211_ATTR_IFNAME])
2631 return -EINVAL;
2632
2633 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2634 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2635 if (type > NL80211_IFTYPE_MAX)
2636 return -EINVAL;
2637 }
2638
79c97e97 2639 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2640 !(rdev->wiphy.interface_modes & (1 << type)))
2641 return -EOPNOTSUPP;
55682965 2642
e8f479b1
BG
2643 if ((type == NL80211_IFTYPE_P2P_DEVICE ||
2644 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) &&
2645 info->attrs[NL80211_ATTR_MAC]) {
1c18f145
AS
2646 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2647 ETH_ALEN);
2648 if (!is_valid_ether_addr(params.macaddr))
2649 return -EADDRNOTAVAIL;
2650 }
2651
9bc383de 2652 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2653 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2654 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2655 if (err)
4c476991 2656 return err;
9bc383de 2657 }
8b787643 2658
66f7ac50
MW
2659 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2660 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2661 &flags);
e057d3c3 2662
18003297 2663 if (!err && (flags & MONITOR_FLAG_ACTIVE) &&
e057d3c3
FF
2664 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2665 return -EOPNOTSUPP;
2666
a18c7192
JB
2667 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2668 if (!msg)
2669 return -ENOMEM;
2670
e35e4d28
HG
2671 wdev = rdev_add_virtual_intf(rdev,
2672 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
6bab2e19
TG
2673 NET_NAME_USER, type, err ? NULL : &flags,
2674 &params);
d687cbb7
RM
2675 if (WARN_ON(!wdev)) {
2676 nlmsg_free(msg);
2677 return -EPROTO;
2678 } else if (IS_ERR(wdev)) {
1c90f9d4 2679 nlmsg_free(msg);
84efbb84 2680 return PTR_ERR(wdev);
1c90f9d4 2681 }
2ec600d6 2682
18e5ca65 2683 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
78f22b6a
JB
2684 wdev->owner_nlportid = info->snd_portid;
2685
98104fde
JB
2686 switch (type) {
2687 case NL80211_IFTYPE_MESH_POINT:
2688 if (!info->attrs[NL80211_ATTR_MESH_ID])
2689 break;
29cbe68c
JB
2690 wdev_lock(wdev);
2691 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2692 IEEE80211_MAX_MESH_ID_LEN);
2693 wdev->mesh_id_up_len =
2694 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2695 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2696 wdev->mesh_id_up_len);
2697 wdev_unlock(wdev);
98104fde
JB
2698 break;
2699 case NL80211_IFTYPE_P2P_DEVICE:
2700 /*
2701 * P2P Device doesn't have a netdev, so doesn't go
2702 * through the netdev notifier and must be added here
2703 */
2704 mutex_init(&wdev->mtx);
2705 INIT_LIST_HEAD(&wdev->event_list);
2706 spin_lock_init(&wdev->event_lock);
2707 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2708 spin_lock_init(&wdev->mgmt_registrations_lock);
2709
98104fde
JB
2710 wdev->identifier = ++rdev->wdev_id;
2711 list_add_rcu(&wdev->list, &rdev->wdev_list);
2712 rdev->devlist_generation++;
98104fde
JB
2713 break;
2714 default:
2715 break;
29cbe68c
JB
2716 }
2717
15e47304 2718 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
8f894be2 2719 rdev, wdev, false) < 0) {
1c90f9d4
JB
2720 nlmsg_free(msg);
2721 return -ENOBUFS;
2722 }
2723
8f894be2
TB
2724 event = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2725 if (event) {
2726 if (nl80211_send_iface(event, 0, 0, 0,
2727 rdev, wdev, false) < 0) {
2728 nlmsg_free(event);
2729 goto out;
2730 }
2731
2732 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
2733 event, 0, NL80211_MCGRP_CONFIG,
2734 GFP_KERNEL);
2735 }
2736
2737out:
1c90f9d4 2738 return genlmsg_reply(msg, info);
55682965
JB
2739}
2740
2741static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2742{
4c476991 2743 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2744 struct wireless_dev *wdev = info->user_ptr[1];
8f894be2
TB
2745 struct sk_buff *msg;
2746 int status;
55682965 2747
4c476991
JB
2748 if (!rdev->ops->del_virtual_intf)
2749 return -EOPNOTSUPP;
55682965 2750
8f894be2
TB
2751 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2752 if (msg && nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, true) < 0) {
2753 nlmsg_free(msg);
2754 msg = NULL;
2755 }
2756
84efbb84
JB
2757 /*
2758 * If we remove a wireless device without a netdev then clear
2759 * user_ptr[1] so that nl80211_post_doit won't dereference it
2760 * to check if it needs to do dev_put(). Otherwise it crashes
2761 * since the wdev has been freed, unlike with a netdev where
2762 * we need the dev_put() for the netdev to really be freed.
2763 */
2764 if (!wdev->netdev)
2765 info->user_ptr[1] = NULL;
2766
8f894be2
TB
2767 status = rdev_del_virtual_intf(rdev, wdev);
2768 if (status >= 0 && msg)
2769 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
2770 msg, 0, NL80211_MCGRP_CONFIG,
2771 GFP_KERNEL);
2772 else
2773 nlmsg_free(msg);
2774
2775 return status;
55682965
JB
2776}
2777
1d9d9213
SW
2778static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2779{
2780 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2781 struct net_device *dev = info->user_ptr[1];
2782 u16 noack_map;
2783
2784 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2785 return -EINVAL;
2786
2787 if (!rdev->ops->set_noack_map)
2788 return -EOPNOTSUPP;
2789
2790 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2791
e35e4d28 2792 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2793}
2794
41ade00f
JB
2795struct get_key_cookie {
2796 struct sk_buff *msg;
2797 int error;
b9454e83 2798 int idx;
41ade00f
JB
2799};
2800
2801static void get_key_callback(void *c, struct key_params *params)
2802{
b9454e83 2803 struct nlattr *key;
41ade00f
JB
2804 struct get_key_cookie *cookie = c;
2805
9360ffd1
DM
2806 if ((params->key &&
2807 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2808 params->key_len, params->key)) ||
2809 (params->seq &&
2810 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2811 params->seq_len, params->seq)) ||
2812 (params->cipher &&
2813 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2814 params->cipher)))
2815 goto nla_put_failure;
41ade00f 2816
b9454e83
JB
2817 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2818 if (!key)
2819 goto nla_put_failure;
2820
9360ffd1
DM
2821 if ((params->key &&
2822 nla_put(cookie->msg, NL80211_KEY_DATA,
2823 params->key_len, params->key)) ||
2824 (params->seq &&
2825 nla_put(cookie->msg, NL80211_KEY_SEQ,
2826 params->seq_len, params->seq)) ||
2827 (params->cipher &&
2828 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2829 params->cipher)))
2830 goto nla_put_failure;
b9454e83 2831
9360ffd1
DM
2832 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2833 goto nla_put_failure;
b9454e83
JB
2834
2835 nla_nest_end(cookie->msg, key);
2836
41ade00f
JB
2837 return;
2838 nla_put_failure:
2839 cookie->error = 1;
2840}
2841
2842static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2843{
4c476991 2844 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2845 int err;
4c476991 2846 struct net_device *dev = info->user_ptr[1];
41ade00f 2847 u8 key_idx = 0;
e31b8213
JB
2848 const u8 *mac_addr = NULL;
2849 bool pairwise;
41ade00f
JB
2850 struct get_key_cookie cookie = {
2851 .error = 0,
2852 };
2853 void *hdr;
2854 struct sk_buff *msg;
2855
2856 if (info->attrs[NL80211_ATTR_KEY_IDX])
2857 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2858
3cfcf6ac 2859 if (key_idx > 5)
41ade00f
JB
2860 return -EINVAL;
2861
2862 if (info->attrs[NL80211_ATTR_MAC])
2863 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2864
e31b8213
JB
2865 pairwise = !!mac_addr;
2866 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2867 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2868 if (kt >= NUM_NL80211_KEYTYPES)
2869 return -EINVAL;
2870 if (kt != NL80211_KEYTYPE_GROUP &&
2871 kt != NL80211_KEYTYPE_PAIRWISE)
2872 return -EINVAL;
2873 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2874 }
2875
4c476991
JB
2876 if (!rdev->ops->get_key)
2877 return -EOPNOTSUPP;
41ade00f 2878
0fa7b391
JB
2879 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2880 return -ENOENT;
2881
fd2120ca 2882 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2883 if (!msg)
2884 return -ENOMEM;
41ade00f 2885
15e47304 2886 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2887 NL80211_CMD_NEW_KEY);
cb35fba3 2888 if (!hdr)
9fe271af 2889 goto nla_put_failure;
41ade00f
JB
2890
2891 cookie.msg = msg;
b9454e83 2892 cookie.idx = key_idx;
41ade00f 2893
9360ffd1
DM
2894 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2895 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2896 goto nla_put_failure;
2897 if (mac_addr &&
2898 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2899 goto nla_put_failure;
41ade00f 2900
e35e4d28
HG
2901 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2902 get_key_callback);
41ade00f
JB
2903
2904 if (err)
6c95e2a2 2905 goto free_msg;
41ade00f
JB
2906
2907 if (cookie.error)
2908 goto nla_put_failure;
2909
2910 genlmsg_end(msg, hdr);
4c476991 2911 return genlmsg_reply(msg, info);
41ade00f
JB
2912
2913 nla_put_failure:
2914 err = -ENOBUFS;
6c95e2a2 2915 free_msg:
41ade00f 2916 nlmsg_free(msg);
41ade00f
JB
2917 return err;
2918}
2919
2920static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2921{
4c476991 2922 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2923 struct key_parse key;
41ade00f 2924 int err;
4c476991 2925 struct net_device *dev = info->user_ptr[1];
41ade00f 2926
b9454e83
JB
2927 err = nl80211_parse_key(info, &key);
2928 if (err)
2929 return err;
41ade00f 2930
b9454e83 2931 if (key.idx < 0)
41ade00f
JB
2932 return -EINVAL;
2933
b9454e83
JB
2934 /* only support setting default key */
2935 if (!key.def && !key.defmgmt)
41ade00f
JB
2936 return -EINVAL;
2937
dbd2fd65 2938 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2939
dbd2fd65
JB
2940 if (key.def) {
2941 if (!rdev->ops->set_default_key) {
2942 err = -EOPNOTSUPP;
2943 goto out;
2944 }
41ade00f 2945
dbd2fd65
JB
2946 err = nl80211_key_allowed(dev->ieee80211_ptr);
2947 if (err)
2948 goto out;
2949
e35e4d28 2950 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2951 key.def_uni, key.def_multi);
2952
2953 if (err)
2954 goto out;
fffd0934 2955
3d23e349 2956#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2957 dev->ieee80211_ptr->wext.default_key = key.idx;
2958#endif
2959 } else {
2960 if (key.def_uni || !key.def_multi) {
2961 err = -EINVAL;
2962 goto out;
2963 }
2964
2965 if (!rdev->ops->set_default_mgmt_key) {
2966 err = -EOPNOTSUPP;
2967 goto out;
2968 }
2969
2970 err = nl80211_key_allowed(dev->ieee80211_ptr);
2971 if (err)
2972 goto out;
2973
e35e4d28 2974 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2975 if (err)
2976 goto out;
2977
2978#ifdef CONFIG_CFG80211_WEXT
2979 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2980#endif
dbd2fd65
JB
2981 }
2982
2983 out:
fffd0934 2984 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2985
41ade00f
JB
2986 return err;
2987}
2988
2989static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2990{
4c476991 2991 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2992 int err;
4c476991 2993 struct net_device *dev = info->user_ptr[1];
b9454e83 2994 struct key_parse key;
e31b8213 2995 const u8 *mac_addr = NULL;
41ade00f 2996
b9454e83
JB
2997 err = nl80211_parse_key(info, &key);
2998 if (err)
2999 return err;
41ade00f 3000
b9454e83 3001 if (!key.p.key)
41ade00f
JB
3002 return -EINVAL;
3003
41ade00f
JB
3004 if (info->attrs[NL80211_ATTR_MAC])
3005 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3006
e31b8213
JB
3007 if (key.type == -1) {
3008 if (mac_addr)
3009 key.type = NL80211_KEYTYPE_PAIRWISE;
3010 else
3011 key.type = NL80211_KEYTYPE_GROUP;
3012 }
3013
3014 /* for now */
3015 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3016 key.type != NL80211_KEYTYPE_GROUP)
3017 return -EINVAL;
3018
4c476991
JB
3019 if (!rdev->ops->add_key)
3020 return -EOPNOTSUPP;
25e47c18 3021
e31b8213
JB
3022 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
3023 key.type == NL80211_KEYTYPE_PAIRWISE,
3024 mac_addr))
4c476991 3025 return -EINVAL;
41ade00f 3026
fffd0934
JB
3027 wdev_lock(dev->ieee80211_ptr);
3028 err = nl80211_key_allowed(dev->ieee80211_ptr);
3029 if (!err)
e35e4d28
HG
3030 err = rdev_add_key(rdev, dev, key.idx,
3031 key.type == NL80211_KEYTYPE_PAIRWISE,
3032 mac_addr, &key.p);
fffd0934 3033 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3034
41ade00f
JB
3035 return err;
3036}
3037
3038static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
3039{
4c476991 3040 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3041 int err;
4c476991 3042 struct net_device *dev = info->user_ptr[1];
41ade00f 3043 u8 *mac_addr = NULL;
b9454e83 3044 struct key_parse key;
41ade00f 3045
b9454e83
JB
3046 err = nl80211_parse_key(info, &key);
3047 if (err)
3048 return err;
41ade00f
JB
3049
3050 if (info->attrs[NL80211_ATTR_MAC])
3051 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3052
e31b8213
JB
3053 if (key.type == -1) {
3054 if (mac_addr)
3055 key.type = NL80211_KEYTYPE_PAIRWISE;
3056 else
3057 key.type = NL80211_KEYTYPE_GROUP;
3058 }
3059
3060 /* for now */
3061 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3062 key.type != NL80211_KEYTYPE_GROUP)
3063 return -EINVAL;
3064
4c476991
JB
3065 if (!rdev->ops->del_key)
3066 return -EOPNOTSUPP;
41ade00f 3067
fffd0934
JB
3068 wdev_lock(dev->ieee80211_ptr);
3069 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213 3070
0fa7b391 3071 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr &&
e31b8213
JB
3072 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3073 err = -ENOENT;
3074
fffd0934 3075 if (!err)
e35e4d28
HG
3076 err = rdev_del_key(rdev, dev, key.idx,
3077 key.type == NL80211_KEYTYPE_PAIRWISE,
3078 mac_addr);
41ade00f 3079
3d23e349 3080#ifdef CONFIG_CFG80211_WEXT
08645126 3081 if (!err) {
b9454e83 3082 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 3083 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 3084 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
3085 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
3086 }
3087#endif
fffd0934 3088 wdev_unlock(dev->ieee80211_ptr);
08645126 3089
41ade00f
JB
3090 return err;
3091}
3092
77765eaf
VT
3093/* This function returns an error or the number of nested attributes */
3094static int validate_acl_mac_addrs(struct nlattr *nl_attr)
3095{
3096 struct nlattr *attr;
3097 int n_entries = 0, tmp;
3098
3099 nla_for_each_nested(attr, nl_attr, tmp) {
3100 if (nla_len(attr) != ETH_ALEN)
3101 return -EINVAL;
3102
3103 n_entries++;
3104 }
3105
3106 return n_entries;
3107}
3108
3109/*
3110 * This function parses ACL information and allocates memory for ACL data.
3111 * On successful return, the calling function is responsible to free the
3112 * ACL buffer returned by this function.
3113 */
3114static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
3115 struct genl_info *info)
3116{
3117 enum nl80211_acl_policy acl_policy;
3118 struct nlattr *attr;
3119 struct cfg80211_acl_data *acl;
3120 int i = 0, n_entries, tmp;
3121
3122 if (!wiphy->max_acl_mac_addrs)
3123 return ERR_PTR(-EOPNOTSUPP);
3124
3125 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
3126 return ERR_PTR(-EINVAL);
3127
3128 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
3129 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
3130 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
3131 return ERR_PTR(-EINVAL);
3132
3133 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
3134 return ERR_PTR(-EINVAL);
3135
3136 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
3137 if (n_entries < 0)
3138 return ERR_PTR(n_entries);
3139
3140 if (n_entries > wiphy->max_acl_mac_addrs)
3141 return ERR_PTR(-ENOTSUPP);
3142
3143 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
3144 GFP_KERNEL);
3145 if (!acl)
3146 return ERR_PTR(-ENOMEM);
3147
3148 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
3149 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
3150 i++;
3151 }
3152
3153 acl->n_acl_entries = n_entries;
3154 acl->acl_policy = acl_policy;
3155
3156 return acl;
3157}
3158
3159static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
3160{
3161 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3162 struct net_device *dev = info->user_ptr[1];
3163 struct cfg80211_acl_data *acl;
3164 int err;
3165
3166 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3167 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3168 return -EOPNOTSUPP;
3169
3170 if (!dev->ieee80211_ptr->beacon_interval)
3171 return -EINVAL;
3172
3173 acl = parse_acl_data(&rdev->wiphy, info);
3174 if (IS_ERR(acl))
3175 return PTR_ERR(acl);
3176
3177 err = rdev_set_mac_acl(rdev, dev, acl);
3178
3179 kfree(acl);
3180
3181 return err;
3182}
3183
a1193be8 3184static int nl80211_parse_beacon(struct nlattr *attrs[],
8860020e 3185 struct cfg80211_beacon_data *bcn)
ed1b6cc7 3186{
8860020e 3187 bool haveinfo = false;
ed1b6cc7 3188
a1193be8
SW
3189 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) ||
3190 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) ||
3191 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
3192 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
3193 return -EINVAL;
3194
8860020e 3195 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 3196
a1193be8
SW
3197 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
3198 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
3199 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
3200 if (!bcn->head_len)
3201 return -EINVAL;
3202 haveinfo = true;
ed1b6cc7
JB
3203 }
3204
a1193be8
SW
3205 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
3206 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
3207 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 3208 haveinfo = true;
ed1b6cc7
JB
3209 }
3210
4c476991
JB
3211 if (!haveinfo)
3212 return -EINVAL;
3b85875a 3213
a1193be8
SW
3214 if (attrs[NL80211_ATTR_IE]) {
3215 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
3216 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
3217 }
3218
a1193be8 3219 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 3220 bcn->proberesp_ies =
a1193be8 3221 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 3222 bcn->proberesp_ies_len =
a1193be8 3223 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
3224 }
3225
a1193be8 3226 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 3227 bcn->assocresp_ies =
a1193be8 3228 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 3229 bcn->assocresp_ies_len =
a1193be8 3230 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
3231 }
3232
a1193be8
SW
3233 if (attrs[NL80211_ATTR_PROBE_RESP]) {
3234 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
3235 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
3236 }
3237
8860020e
JB
3238 return 0;
3239}
3240
46c1dd0c
FF
3241static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
3242 struct cfg80211_ap_settings *params)
3243{
3244 struct wireless_dev *wdev;
3245 bool ret = false;
3246
89a54e48 3247 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
3248 if (wdev->iftype != NL80211_IFTYPE_AP &&
3249 wdev->iftype != NL80211_IFTYPE_P2P_GO)
3250 continue;
3251
683b6d3b 3252 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
3253 continue;
3254
683b6d3b 3255 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
3256 ret = true;
3257 break;
3258 }
3259
46c1dd0c
FF
3260 return ret;
3261}
3262
e39e5b5e
JM
3263static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
3264 enum nl80211_auth_type auth_type,
3265 enum nl80211_commands cmd)
3266{
3267 if (auth_type > NL80211_AUTHTYPE_MAX)
3268 return false;
3269
3270 switch (cmd) {
3271 case NL80211_CMD_AUTHENTICATE:
3272 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
3273 auth_type == NL80211_AUTHTYPE_SAE)
3274 return false;
3275 return true;
3276 case NL80211_CMD_CONNECT:
3277 case NL80211_CMD_START_AP:
3278 /* SAE not supported yet */
3279 if (auth_type == NL80211_AUTHTYPE_SAE)
3280 return false;
3281 return true;
3282 default:
3283 return false;
3284 }
3285}
3286
8860020e
JB
3287static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
3288{
3289 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3290 struct net_device *dev = info->user_ptr[1];
3291 struct wireless_dev *wdev = dev->ieee80211_ptr;
3292 struct cfg80211_ap_settings params;
3293 int err;
3294
3295 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3296 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3297 return -EOPNOTSUPP;
3298
3299 if (!rdev->ops->start_ap)
3300 return -EOPNOTSUPP;
3301
3302 if (wdev->beacon_interval)
3303 return -EALREADY;
3304
3305 memset(&params, 0, sizeof(params));
3306
3307 /* these are required for START_AP */
3308 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
3309 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
3310 !info->attrs[NL80211_ATTR_BEACON_HEAD])
3311 return -EINVAL;
3312
a1193be8 3313 err = nl80211_parse_beacon(info->attrs, &params.beacon);
8860020e
JB
3314 if (err)
3315 return err;
3316
3317 params.beacon_interval =
3318 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3319 params.dtim_period =
3320 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
3321
3322 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
3323 if (err)
3324 return err;
3325
3326 /*
3327 * In theory, some of these attributes should be required here
3328 * but since they were not used when the command was originally
3329 * added, keep them optional for old user space programs to let
3330 * them continue to work with drivers that do not need the
3331 * additional information -- drivers must check!
3332 */
3333 if (info->attrs[NL80211_ATTR_SSID]) {
3334 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3335 params.ssid_len =
3336 nla_len(info->attrs[NL80211_ATTR_SSID]);
3337 if (params.ssid_len == 0 ||
3338 params.ssid_len > IEEE80211_MAX_SSID_LEN)
3339 return -EINVAL;
3340 }
3341
3342 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
3343 params.hidden_ssid = nla_get_u32(
3344 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
3345 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
3346 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
3347 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
3348 return -EINVAL;
3349 }
3350
3351 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3352
3353 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3354 params.auth_type = nla_get_u32(
3355 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
3356 if (!nl80211_valid_auth_type(rdev, params.auth_type,
3357 NL80211_CMD_START_AP))
8860020e
JB
3358 return -EINVAL;
3359 } else
3360 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3361
3362 err = nl80211_crypto_settings(rdev, info, &params.crypto,
3363 NL80211_MAX_NR_CIPHER_SUITES);
3364 if (err)
3365 return err;
3366
1b658f11
VT
3367 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
3368 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
3369 return -EOPNOTSUPP;
3370 params.inactivity_timeout = nla_get_u16(
3371 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
3372 }
3373
53cabad7
JB
3374 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3375 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3376 return -EINVAL;
3377 params.p2p_ctwindow =
3378 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3379 if (params.p2p_ctwindow > 127)
3380 return -EINVAL;
3381 if (params.p2p_ctwindow != 0 &&
3382 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3383 return -EINVAL;
3384 }
3385
3386 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3387 u8 tmp;
3388
3389 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3390 return -EINVAL;
3391 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3392 if (tmp > 1)
3393 return -EINVAL;
3394 params.p2p_opp_ps = tmp;
3395 if (params.p2p_opp_ps != 0 &&
3396 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3397 return -EINVAL;
3398 }
3399
aa430da4 3400 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
3401 err = nl80211_parse_chandef(rdev, info, &params.chandef);
3402 if (err)
3403 return err;
3404 } else if (wdev->preset_chandef.chan) {
3405 params.chandef = wdev->preset_chandef;
46c1dd0c 3406 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
3407 return -EINVAL;
3408
923b352f
AN
3409 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
3410 wdev->iftype))
aa430da4
JB
3411 return -EINVAL;
3412
77765eaf
VT
3413 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
3414 params.acl = parse_acl_data(&rdev->wiphy, info);
3415 if (IS_ERR(params.acl))
3416 return PTR_ERR(params.acl);
3417 }
3418
18998c38
EP
3419 if (info->attrs[NL80211_ATTR_SMPS_MODE]) {
3420 params.smps_mode =
3421 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]);
3422 switch (params.smps_mode) {
3423 case NL80211_SMPS_OFF:
3424 break;
3425 case NL80211_SMPS_STATIC:
3426 if (!(rdev->wiphy.features &
3427 NL80211_FEATURE_STATIC_SMPS))
3428 return -EINVAL;
3429 break;
3430 case NL80211_SMPS_DYNAMIC:
3431 if (!(rdev->wiphy.features &
3432 NL80211_FEATURE_DYNAMIC_SMPS))
3433 return -EINVAL;
3434 break;
3435 default:
3436 return -EINVAL;
3437 }
3438 } else {
3439 params.smps_mode = NL80211_SMPS_OFF;
3440 }
3441
c56589ed 3442 wdev_lock(wdev);
e35e4d28 3443 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 3444 if (!err) {
683b6d3b 3445 wdev->preset_chandef = params.chandef;
8860020e 3446 wdev->beacon_interval = params.beacon_interval;
9e0e2961 3447 wdev->chandef = params.chandef;
06e191e2
AQ
3448 wdev->ssid_len = params.ssid_len;
3449 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 3450 }
c56589ed 3451 wdev_unlock(wdev);
77765eaf
VT
3452
3453 kfree(params.acl);
3454
56d1893d 3455 return err;
ed1b6cc7
JB
3456}
3457
8860020e
JB
3458static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
3459{
3460 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3461 struct net_device *dev = info->user_ptr[1];
3462 struct wireless_dev *wdev = dev->ieee80211_ptr;
3463 struct cfg80211_beacon_data params;
3464 int err;
3465
3466 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3467 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3468 return -EOPNOTSUPP;
3469
3470 if (!rdev->ops->change_beacon)
3471 return -EOPNOTSUPP;
3472
3473 if (!wdev->beacon_interval)
3474 return -EINVAL;
3475
a1193be8 3476 err = nl80211_parse_beacon(info->attrs, &params);
8860020e
JB
3477 if (err)
3478 return err;
3479
c56589ed
SW
3480 wdev_lock(wdev);
3481 err = rdev_change_beacon(rdev, dev, &params);
3482 wdev_unlock(wdev);
3483
3484 return err;
8860020e
JB
3485}
3486
3487static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 3488{
4c476991
JB
3489 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3490 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 3491
7c8d5e03 3492 return cfg80211_stop_ap(rdev, dev, false);
ed1b6cc7
JB
3493}
3494
5727ef1b
JB
3495static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
3496 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
3497 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
3498 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 3499 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 3500 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 3501 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
3502};
3503
eccb8e8f 3504static int parse_station_flags(struct genl_info *info,
bdd3ae3d 3505 enum nl80211_iftype iftype,
eccb8e8f 3506 struct station_parameters *params)
5727ef1b
JB
3507{
3508 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 3509 struct nlattr *nla;
5727ef1b
JB
3510 int flag;
3511
eccb8e8f
JB
3512 /*
3513 * Try parsing the new attribute first so userspace
3514 * can specify both for older kernels.
3515 */
3516 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
3517 if (nla) {
3518 struct nl80211_sta_flag_update *sta_flags;
3519
3520 sta_flags = nla_data(nla);
3521 params->sta_flags_mask = sta_flags->mask;
3522 params->sta_flags_set = sta_flags->set;
77ee7c89 3523 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
3524 if ((params->sta_flags_mask |
3525 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
3526 return -EINVAL;
3527 return 0;
3528 }
3529
3530 /* if present, parse the old attribute */
5727ef1b 3531
eccb8e8f 3532 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
3533 if (!nla)
3534 return 0;
3535
3536 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
3537 nla, sta_flags_policy))
3538 return -EINVAL;
3539
bdd3ae3d
JB
3540 /*
3541 * Only allow certain flags for interface types so that
3542 * other attributes are silently ignored. Remember that
3543 * this is backward compatibility code with old userspace
3544 * and shouldn't be hit in other cases anyway.
3545 */
3546 switch (iftype) {
3547 case NL80211_IFTYPE_AP:
3548 case NL80211_IFTYPE_AP_VLAN:
3549 case NL80211_IFTYPE_P2P_GO:
3550 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3551 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3552 BIT(NL80211_STA_FLAG_WME) |
3553 BIT(NL80211_STA_FLAG_MFP);
3554 break;
3555 case NL80211_IFTYPE_P2P_CLIENT:
3556 case NL80211_IFTYPE_STATION:
3557 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3558 BIT(NL80211_STA_FLAG_TDLS_PEER);
3559 break;
3560 case NL80211_IFTYPE_MESH_POINT:
3561 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3562 BIT(NL80211_STA_FLAG_MFP) |
3563 BIT(NL80211_STA_FLAG_AUTHORIZED);
3564 default:
3565 return -EINVAL;
3566 }
5727ef1b 3567
3383b5a6
JB
3568 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
3569 if (flags[flag]) {
eccb8e8f 3570 params->sta_flags_set |= (1<<flag);
5727ef1b 3571
3383b5a6
JB
3572 /* no longer support new API additions in old API */
3573 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
3574 return -EINVAL;
3575 }
3576 }
3577
5727ef1b
JB
3578 return 0;
3579}
3580
c8dcfd8a
FF
3581static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
3582 int attr)
3583{
3584 struct nlattr *rate;
8eb41c8d
VK
3585 u32 bitrate;
3586 u16 bitrate_compat;
b51f3bee 3587 enum nl80211_attrs rate_flg;
c8dcfd8a
FF
3588
3589 rate = nla_nest_start(msg, attr);
3590 if (!rate)
db9c64cf 3591 return false;
c8dcfd8a
FF
3592
3593 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
3594 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
3595 /* report 16-bit bitrate only if we can */
3596 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
3597 if (bitrate > 0 &&
3598 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
3599 return false;
3600 if (bitrate_compat > 0 &&
3601 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
3602 return false;
3603
b51f3bee
JB
3604 switch (info->bw) {
3605 case RATE_INFO_BW_5:
3606 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH;
3607 break;
3608 case RATE_INFO_BW_10:
3609 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH;
3610 break;
3611 default:
3612 WARN_ON(1);
3613 /* fall through */
3614 case RATE_INFO_BW_20:
3615 rate_flg = 0;
3616 break;
3617 case RATE_INFO_BW_40:
3618 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH;
3619 break;
3620 case RATE_INFO_BW_80:
3621 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH;
3622 break;
3623 case RATE_INFO_BW_160:
3624 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH;
3625 break;
3626 }
3627
3628 if (rate_flg && nla_put_flag(msg, rate_flg))
3629 return false;
3630
db9c64cf
JB
3631 if (info->flags & RATE_INFO_FLAGS_MCS) {
3632 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
3633 return false;
db9c64cf
JB
3634 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3635 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3636 return false;
3637 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3638 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3639 return false;
3640 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3641 return false;
db9c64cf
JB
3642 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3643 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3644 return false;
3645 }
c8dcfd8a
FF
3646
3647 nla_nest_end(msg, rate);
3648 return true;
c8dcfd8a
FF
3649}
3650
119363c7
FF
3651static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
3652 int id)
3653{
3654 void *attr;
3655 int i = 0;
3656
3657 if (!mask)
3658 return true;
3659
3660 attr = nla_nest_start(msg, id);
3661 if (!attr)
3662 return false;
3663
3664 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
3665 if (!(mask & BIT(i)))
3666 continue;
3667
3668 if (nla_put_u8(msg, i, signal[i]))
3669 return false;
3670 }
3671
3672 nla_nest_end(msg, attr);
3673
3674 return true;
3675}
3676
cf5ead82
JB
3677static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid,
3678 u32 seq, int flags,
66266b3a
JL
3679 struct cfg80211_registered_device *rdev,
3680 struct net_device *dev,
98b62183 3681 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3682{
3683 void *hdr;
f4263c98 3684 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3685
cf5ead82 3686 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
fd5b74dc
JB
3687 if (!hdr)
3688 return -1;
3689
9360ffd1
DM
3690 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3691 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3692 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3693 goto nla_put_failure;
f5ea9120 3694
2ec600d6
LCC
3695 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3696 if (!sinfoattr)
fd5b74dc 3697 goto nla_put_failure;
319090bf
JB
3698
3699#define PUT_SINFO(attr, memb, type) do { \
3700 if (sinfo->filled & BIT(NL80211_STA_INFO_ ## attr) && \
3701 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \
3702 sinfo->memb)) \
3703 goto nla_put_failure; \
3704 } while (0)
3705
3706 PUT_SINFO(CONNECTED_TIME, connected_time, u32);
3707 PUT_SINFO(INACTIVE_TIME, inactive_time, u32);
3708
3709 if (sinfo->filled & (BIT(NL80211_STA_INFO_RX_BYTES) |
3710 BIT(NL80211_STA_INFO_RX_BYTES64)) &&
9360ffd1 3711 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 3712 (u32)sinfo->rx_bytes))
9360ffd1 3713 goto nla_put_failure;
319090bf
JB
3714
3715 if (sinfo->filled & (BIT(NL80211_STA_INFO_TX_BYTES) |
3716 BIT(NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 3717 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
3718 (u32)sinfo->tx_bytes))
3719 goto nla_put_failure;
319090bf
JB
3720
3721 PUT_SINFO(RX_BYTES64, rx_bytes, u64);
3722 PUT_SINFO(TX_BYTES64, tx_bytes, u64);
3723 PUT_SINFO(LLID, llid, u16);
3724 PUT_SINFO(PLID, plid, u16);
3725 PUT_SINFO(PLINK_STATE, plink_state, u8);
3726
66266b3a
JL
3727 switch (rdev->wiphy.signal_type) {
3728 case CFG80211_SIGNAL_TYPE_MBM:
319090bf
JB
3729 PUT_SINFO(SIGNAL, signal, u8);
3730 PUT_SINFO(SIGNAL_AVG, signal_avg, u8);
66266b3a
JL
3731 break;
3732 default:
3733 break;
3734 }
319090bf 3735 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL)) {
119363c7
FF
3736 if (!nl80211_put_signal(msg, sinfo->chains,
3737 sinfo->chain_signal,
3738 NL80211_STA_INFO_CHAIN_SIGNAL))
3739 goto nla_put_failure;
3740 }
319090bf 3741 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) {
119363c7
FF
3742 if (!nl80211_put_signal(msg, sinfo->chains,
3743 sinfo->chain_signal_avg,
3744 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
3745 goto nla_put_failure;
3746 }
319090bf 3747 if (sinfo->filled & BIT(NL80211_STA_INFO_TX_BITRATE)) {
c8dcfd8a
FF
3748 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3749 NL80211_STA_INFO_TX_BITRATE))
3750 goto nla_put_failure;
3751 }
319090bf 3752 if (sinfo->filled & BIT(NL80211_STA_INFO_RX_BITRATE)) {
c8dcfd8a
FF
3753 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3754 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3755 goto nla_put_failure;
420e7fab 3756 }
319090bf
JB
3757
3758 PUT_SINFO(RX_PACKETS, rx_packets, u32);
3759 PUT_SINFO(TX_PACKETS, tx_packets, u32);
3760 PUT_SINFO(TX_RETRIES, tx_retries, u32);
3761 PUT_SINFO(TX_FAILED, tx_failed, u32);
3762 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32);
3763 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32);
3764 PUT_SINFO(LOCAL_PM, local_pm, u32);
3765 PUT_SINFO(PEER_PM, peer_pm, u32);
3766 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32);
3767
3768 if (sinfo->filled & BIT(NL80211_STA_INFO_BSS_PARAM)) {
f4263c98
PS
3769 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3770 if (!bss_param)
3771 goto nla_put_failure;
3772
9360ffd1
DM
3773 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3774 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3775 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3776 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3777 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3778 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3779 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3780 sinfo->bss_param.dtim_period) ||
3781 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3782 sinfo->bss_param.beacon_interval))
3783 goto nla_put_failure;
f4263c98
PS
3784
3785 nla_nest_end(msg, bss_param);
3786 }
319090bf 3787 if ((sinfo->filled & BIT(NL80211_STA_INFO_STA_FLAGS)) &&
9360ffd1
DM
3788 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3789 sizeof(struct nl80211_sta_flag_update),
3790 &sinfo->sta_flags))
3791 goto nla_put_failure;
319090bf
JB
3792
3793 PUT_SINFO(T_OFFSET, t_offset, u64);
3794 PUT_SINFO(RX_DROP_MISC, rx_dropped_misc, u64);
a76b1942
JB
3795 PUT_SINFO(BEACON_RX, rx_beacon, u64);
3796 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8);
319090bf
JB
3797
3798#undef PUT_SINFO
6de39808
JB
3799
3800 if (sinfo->filled & BIT(NL80211_STA_INFO_TID_STATS)) {
3801 struct nlattr *tidsattr;
3802 int tid;
3803
3804 tidsattr = nla_nest_start(msg, NL80211_STA_INFO_TID_STATS);
3805 if (!tidsattr)
3806 goto nla_put_failure;
3807
3808 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) {
3809 struct cfg80211_tid_stats *tidstats;
3810 struct nlattr *tidattr;
3811
3812 tidstats = &sinfo->pertid[tid];
3813
3814 if (!tidstats->filled)
3815 continue;
3816
3817 tidattr = nla_nest_start(msg, tid + 1);
3818 if (!tidattr)
3819 goto nla_put_failure;
3820
3821#define PUT_TIDVAL(attr, memb, type) do { \
3822 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \
3823 nla_put_ ## type(msg, NL80211_TID_STATS_ ## attr, \
3824 tidstats->memb)) \
3825 goto nla_put_failure; \
3826 } while (0)
3827
3828 PUT_TIDVAL(RX_MSDU, rx_msdu, u64);
3829 PUT_TIDVAL(TX_MSDU, tx_msdu, u64);
3830 PUT_TIDVAL(TX_MSDU_RETRIES, tx_msdu_retries, u64);
3831 PUT_TIDVAL(TX_MSDU_FAILED, tx_msdu_failed, u64);
3832
3833#undef PUT_TIDVAL
3834 nla_nest_end(msg, tidattr);
3835 }
3836
3837 nla_nest_end(msg, tidsattr);
3838 }
3839
2ec600d6 3840 nla_nest_end(msg, sinfoattr);
fd5b74dc 3841
319090bf 3842 if (sinfo->assoc_req_ies_len &&
9360ffd1
DM
3843 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3844 sinfo->assoc_req_ies))
3845 goto nla_put_failure;
50d3dfb7 3846
053c095a
JB
3847 genlmsg_end(msg, hdr);
3848 return 0;
fd5b74dc
JB
3849
3850 nla_put_failure:
bc3ed28c
TG
3851 genlmsg_cancel(msg, hdr);
3852 return -EMSGSIZE;
fd5b74dc
JB
3853}
3854
2ec600d6 3855static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3856 struct netlink_callback *cb)
2ec600d6 3857{
2ec600d6 3858 struct station_info sinfo;
1b8ec87a 3859 struct cfg80211_registered_device *rdev;
97990a06 3860 struct wireless_dev *wdev;
2ec600d6 3861 u8 mac_addr[ETH_ALEN];
97990a06 3862 int sta_idx = cb->args[2];
2ec600d6 3863 int err;
2ec600d6 3864
1b8ec87a 3865 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
3866 if (err)
3867 return err;
bba95fef 3868
97990a06
JB
3869 if (!wdev->netdev) {
3870 err = -EINVAL;
3871 goto out_err;
3872 }
3873
1b8ec87a 3874 if (!rdev->ops->dump_station) {
eec60b03 3875 err = -EOPNOTSUPP;
bba95fef
JB
3876 goto out_err;
3877 }
3878
bba95fef 3879 while (1) {
f612cedf 3880 memset(&sinfo, 0, sizeof(sinfo));
1b8ec87a 3881 err = rdev_dump_station(rdev, wdev->netdev, sta_idx,
e35e4d28 3882 mac_addr, &sinfo);
bba95fef
JB
3883 if (err == -ENOENT)
3884 break;
3885 if (err)
3b85875a 3886 goto out_err;
bba95fef 3887
cf5ead82 3888 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION,
15e47304 3889 NETLINK_CB(cb->skb).portid,
bba95fef 3890 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1b8ec87a 3891 rdev, wdev->netdev, mac_addr,
bba95fef
JB
3892 &sinfo) < 0)
3893 goto out;
3894
3895 sta_idx++;
3896 }
3897
3898
3899 out:
97990a06 3900 cb->args[2] = sta_idx;
bba95fef 3901 err = skb->len;
bba95fef 3902 out_err:
1b8ec87a 3903 nl80211_finish_wdev_dump(rdev);
bba95fef
JB
3904
3905 return err;
2ec600d6 3906}
fd5b74dc 3907
5727ef1b
JB
3908static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3909{
4c476991
JB
3910 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3911 struct net_device *dev = info->user_ptr[1];
2ec600d6 3912 struct station_info sinfo;
fd5b74dc
JB
3913 struct sk_buff *msg;
3914 u8 *mac_addr = NULL;
4c476991 3915 int err;
fd5b74dc 3916
2ec600d6 3917 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3918
3919 if (!info->attrs[NL80211_ATTR_MAC])
3920 return -EINVAL;
3921
3922 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3923
4c476991
JB
3924 if (!rdev->ops->get_station)
3925 return -EOPNOTSUPP;
3b85875a 3926
e35e4d28 3927 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3928 if (err)
4c476991 3929 return err;
2ec600d6 3930
fd2120ca 3931 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3932 if (!msg)
4c476991 3933 return -ENOMEM;
fd5b74dc 3934
cf5ead82
JB
3935 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION,
3936 info->snd_portid, info->snd_seq, 0,
66266b3a 3937 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3938 nlmsg_free(msg);
3939 return -ENOBUFS;
3940 }
3b85875a 3941
4c476991 3942 return genlmsg_reply(msg, info);
5727ef1b
JB
3943}
3944
77ee7c89
JB
3945int cfg80211_check_station_change(struct wiphy *wiphy,
3946 struct station_parameters *params,
3947 enum cfg80211_station_type statype)
3948{
3949 if (params->listen_interval != -1)
3950 return -EINVAL;
c72e1140
AN
3951 if (params->aid &&
3952 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
77ee7c89
JB
3953 return -EINVAL;
3954
3955 /* When you run into this, adjust the code below for the new flag */
3956 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
3957
3958 switch (statype) {
eef941e6
TP
3959 case CFG80211_STA_MESH_PEER_KERNEL:
3960 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3961 /*
3962 * No ignoring the TDLS flag here -- the userspace mesh
3963 * code doesn't have the bug of including TDLS in the
3964 * mask everywhere.
3965 */
3966 if (params->sta_flags_mask &
3967 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3968 BIT(NL80211_STA_FLAG_MFP) |
3969 BIT(NL80211_STA_FLAG_AUTHORIZED)))
3970 return -EINVAL;
3971 break;
3972 case CFG80211_STA_TDLS_PEER_SETUP:
3973 case CFG80211_STA_TDLS_PEER_ACTIVE:
3974 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3975 return -EINVAL;
3976 /* ignore since it can't change */
3977 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3978 break;
3979 default:
3980 /* disallow mesh-specific things */
3981 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3982 return -EINVAL;
3983 if (params->local_pm)
3984 return -EINVAL;
3985 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3986 return -EINVAL;
3987 }
3988
3989 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
3990 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
3991 /* TDLS can't be set, ... */
3992 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3993 return -EINVAL;
3994 /*
3995 * ... but don't bother the driver with it. This works around
3996 * a hostapd/wpa_supplicant issue -- it always includes the
3997 * TLDS_PEER flag in the mask even for AP mode.
3998 */
3999 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
4000 }
4001
4002 if (statype != CFG80211_STA_TDLS_PEER_SETUP) {
4003 /* reject other things that can't change */
4004 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
4005 return -EINVAL;
4006 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
4007 return -EINVAL;
4008 if (params->supported_rates)
4009 return -EINVAL;
4010 if (params->ext_capab || params->ht_capa || params->vht_capa)
4011 return -EINVAL;
4012 }
4013
4014 if (statype != CFG80211_STA_AP_CLIENT) {
4015 if (params->vlan)
4016 return -EINVAL;
4017 }
4018
4019 switch (statype) {
4020 case CFG80211_STA_AP_MLME_CLIENT:
4021 /* Use this only for authorizing/unauthorizing a station */
4022 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
4023 return -EOPNOTSUPP;
4024 break;
4025 case CFG80211_STA_AP_CLIENT:
4026 /* accept only the listed bits */
4027 if (params->sta_flags_mask &
4028 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
4029 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4030 BIT(NL80211_STA_FLAG_ASSOCIATED) |
4031 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
4032 BIT(NL80211_STA_FLAG_WME) |
4033 BIT(NL80211_STA_FLAG_MFP)))
4034 return -EINVAL;
4035
4036 /* but authenticated/associated only if driver handles it */
4037 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4038 params->sta_flags_mask &
4039 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4040 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4041 return -EINVAL;
4042 break;
4043 case CFG80211_STA_IBSS:
4044 case CFG80211_STA_AP_STA:
4045 /* reject any changes other than AUTHORIZED */
4046 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
4047 return -EINVAL;
4048 break;
4049 case CFG80211_STA_TDLS_PEER_SETUP:
4050 /* reject any changes other than AUTHORIZED or WME */
4051 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
4052 BIT(NL80211_STA_FLAG_WME)))
4053 return -EINVAL;
4054 /* force (at least) rates when authorizing */
4055 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
4056 !params->supported_rates)
4057 return -EINVAL;
4058 break;
4059 case CFG80211_STA_TDLS_PEER_ACTIVE:
4060 /* reject any changes */
4061 return -EINVAL;
eef941e6 4062 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
4063 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
4064 return -EINVAL;
4065 break;
eef941e6 4066 case CFG80211_STA_MESH_PEER_USER:
42925040
CYY
4067 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION &&
4068 params->plink_action != NL80211_PLINK_ACTION_BLOCK)
77ee7c89
JB
4069 return -EINVAL;
4070 break;
4071 }
4072
4073 return 0;
4074}
4075EXPORT_SYMBOL(cfg80211_check_station_change);
4076
5727ef1b 4077/*
c258d2de 4078 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 4079 */
80b99899
JB
4080static struct net_device *get_vlan(struct genl_info *info,
4081 struct cfg80211_registered_device *rdev)
5727ef1b 4082{
463d0183 4083 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
4084 struct net_device *v;
4085 int ret;
4086
4087 if (!vlanattr)
4088 return NULL;
4089
4090 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
4091 if (!v)
4092 return ERR_PTR(-ENODEV);
4093
4094 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
4095 ret = -EINVAL;
4096 goto error;
5727ef1b 4097 }
80b99899 4098
77ee7c89
JB
4099 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4100 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4101 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
4102 ret = -EINVAL;
4103 goto error;
4104 }
4105
80b99899
JB
4106 if (!netif_running(v)) {
4107 ret = -ENETDOWN;
4108 goto error;
4109 }
4110
4111 return v;
4112 error:
4113 dev_put(v);
4114 return ERR_PTR(ret);
5727ef1b
JB
4115}
4116
94e860f1
JB
4117static const struct nla_policy
4118nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
df881293
JM
4119 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
4120 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
4121};
4122
ff276691
JB
4123static int nl80211_parse_sta_wme(struct genl_info *info,
4124 struct station_parameters *params)
df881293 4125{
df881293
JM
4126 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
4127 struct nlattr *nla;
4128 int err;
4129
df881293
JM
4130 /* parse WME attributes if present */
4131 if (!info->attrs[NL80211_ATTR_STA_WME])
4132 return 0;
4133
4134 nla = info->attrs[NL80211_ATTR_STA_WME];
4135 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
4136 nl80211_sta_wme_policy);
4137 if (err)
4138 return err;
4139
4140 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
4141 params->uapsd_queues = nla_get_u8(
4142 tb[NL80211_STA_WME_UAPSD_QUEUES]);
4143 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
4144 return -EINVAL;
4145
4146 if (tb[NL80211_STA_WME_MAX_SP])
4147 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
4148
4149 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
4150 return -EINVAL;
4151
4152 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
4153
4154 return 0;
4155}
4156
c01fc9ad
SD
4157static int nl80211_parse_sta_channel_info(struct genl_info *info,
4158 struct station_parameters *params)
4159{
4160 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
4161 params->supported_channels =
4162 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
4163 params->supported_channels_len =
4164 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
4165 /*
4166 * Need to include at least one (first channel, number of
4167 * channels) tuple for each subband, and must have proper
4168 * tuples for the rest of the data as well.
4169 */
4170 if (params->supported_channels_len < 2)
4171 return -EINVAL;
4172 if (params->supported_channels_len % 2)
4173 return -EINVAL;
4174 }
4175
4176 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
4177 params->supported_oper_classes =
4178 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
4179 params->supported_oper_classes_len =
4180 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
4181 /*
4182 * The value of the Length field of the Supported Operating
4183 * Classes element is between 2 and 253.
4184 */
4185 if (params->supported_oper_classes_len < 2 ||
4186 params->supported_oper_classes_len > 253)
4187 return -EINVAL;
4188 }
4189 return 0;
4190}
4191
ff276691
JB
4192static int nl80211_set_station_tdls(struct genl_info *info,
4193 struct station_parameters *params)
4194{
c01fc9ad 4195 int err;
ff276691 4196 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
4197 if (info->attrs[NL80211_ATTR_PEER_AID])
4198 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
4199 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4200 params->ht_capa =
4201 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4202 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4203 params->vht_capa =
4204 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4205
c01fc9ad
SD
4206 err = nl80211_parse_sta_channel_info(info, params);
4207 if (err)
4208 return err;
4209
ff276691
JB
4210 return nl80211_parse_sta_wme(info, params);
4211}
4212
5727ef1b
JB
4213static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
4214{
4c476991 4215 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4216 struct net_device *dev = info->user_ptr[1];
5727ef1b 4217 struct station_parameters params;
77ee7c89
JB
4218 u8 *mac_addr;
4219 int err;
5727ef1b
JB
4220
4221 memset(&params, 0, sizeof(params));
4222
4223 params.listen_interval = -1;
4224
77ee7c89
JB
4225 if (!rdev->ops->change_station)
4226 return -EOPNOTSUPP;
4227
5727ef1b
JB
4228 if (info->attrs[NL80211_ATTR_STA_AID])
4229 return -EINVAL;
4230
4231 if (!info->attrs[NL80211_ATTR_MAC])
4232 return -EINVAL;
4233
4234 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4235
4236 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
4237 params.supported_rates =
4238 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4239 params.supported_rates_len =
4240 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4241 }
4242
9d62a986
JM
4243 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4244 params.capability =
4245 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4246 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4247 }
4248
4249 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4250 params.ext_capab =
4251 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4252 params.ext_capab_len =
4253 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4254 }
4255
df881293 4256 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
ba23d206 4257 return -EINVAL;
36aedc90 4258
bdd3ae3d 4259 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4260 return -EINVAL;
4261
f8bacc21 4262 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
2ec600d6 4263 params.plink_action =
f8bacc21
JB
4264 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4265 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4266 return -EINVAL;
4267 }
2ec600d6 4268
f8bacc21 4269 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 4270 params.plink_state =
f8bacc21
JB
4271 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
4272 if (params.plink_state >= NUM_NL80211_PLINK_STATES)
4273 return -EINVAL;
4274 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
4275 }
9c3990aa 4276
3b1c5a53
MP
4277 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
4278 enum nl80211_mesh_power_mode pm = nla_get_u32(
4279 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
4280
4281 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
4282 pm > NL80211_MESH_POWER_MAX)
4283 return -EINVAL;
4284
4285 params.local_pm = pm;
4286 }
4287
77ee7c89
JB
4288 /* Include parameters for TDLS peer (will check later) */
4289 err = nl80211_set_station_tdls(info, &params);
4290 if (err)
4291 return err;
4292
4293 params.vlan = get_vlan(info, rdev);
4294 if (IS_ERR(params.vlan))
4295 return PTR_ERR(params.vlan);
4296
a97f4424
JB
4297 switch (dev->ieee80211_ptr->iftype) {
4298 case NL80211_IFTYPE_AP:
4299 case NL80211_IFTYPE_AP_VLAN:
074ac8df 4300 case NL80211_IFTYPE_P2P_GO:
074ac8df 4301 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 4302 case NL80211_IFTYPE_STATION:
267335d6 4303 case NL80211_IFTYPE_ADHOC:
a97f4424 4304 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
4305 break;
4306 default:
77ee7c89
JB
4307 err = -EOPNOTSUPP;
4308 goto out_put_vlan;
034d655e
JB
4309 }
4310
77ee7c89 4311 /* driver will call cfg80211_check_station_change() */
e35e4d28 4312 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 4313
77ee7c89 4314 out_put_vlan:
5727ef1b
JB
4315 if (params.vlan)
4316 dev_put(params.vlan);
3b85875a 4317
5727ef1b
JB
4318 return err;
4319}
4320
4321static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
4322{
4c476991 4323 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 4324 int err;
4c476991 4325 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4326 struct station_parameters params;
4327 u8 *mac_addr = NULL;
4328
4329 memset(&params, 0, sizeof(params));
4330
984c311b
JB
4331 if (!rdev->ops->add_station)
4332 return -EOPNOTSUPP;
4333
5727ef1b
JB
4334 if (!info->attrs[NL80211_ATTR_MAC])
4335 return -EINVAL;
4336
5727ef1b
JB
4337 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
4338 return -EINVAL;
4339
4340 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
4341 return -EINVAL;
4342
5e4b6f56
JM
4343 if (!info->attrs[NL80211_ATTR_STA_AID] &&
4344 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
4345 return -EINVAL;
4346
5727ef1b
JB
4347 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4348 params.supported_rates =
4349 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4350 params.supported_rates_len =
4351 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4352 params.listen_interval =
4353 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 4354
3d124ea2 4355 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 4356 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
4357 else
4358 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
0e956c13
TLSC
4359 if (!params.aid || params.aid > IEEE80211_MAX_AID)
4360 return -EINVAL;
51b50fbe 4361
9d62a986
JM
4362 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4363 params.capability =
4364 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4365 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4366 }
4367
4368 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4369 params.ext_capab =
4370 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4371 params.ext_capab_len =
4372 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4373 }
4374
36aedc90
JM
4375 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4376 params.ht_capa =
4377 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 4378
f461be3e
MP
4379 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4380 params.vht_capa =
4381 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4382
60f4a7b1
MK
4383 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
4384 params.opmode_notif_used = true;
4385 params.opmode_notif =
4386 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
4387 }
4388
f8bacc21 4389 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
96b78dff 4390 params.plink_action =
f8bacc21
JB
4391 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4392 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4393 return -EINVAL;
4394 }
96b78dff 4395
c01fc9ad
SD
4396 err = nl80211_parse_sta_channel_info(info, &params);
4397 if (err)
4398 return err;
4399
ff276691
JB
4400 err = nl80211_parse_sta_wme(info, &params);
4401 if (err)
4402 return err;
bdd90d5e 4403
bdd3ae3d 4404 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4405 return -EINVAL;
4406
496fcc29
JB
4407 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT
4408 * as userspace might just pass through the capabilities from the IEs
4409 * directly, rather than enforcing this restriction and returning an
4410 * error in this case.
4411 */
4412 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) {
4413 params.ht_capa = NULL;
4414 params.vht_capa = NULL;
4415 }
4416
77ee7c89
JB
4417 /* When you run into this, adjust the code below for the new flag */
4418 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
4419
bdd90d5e
JB
4420 switch (dev->ieee80211_ptr->iftype) {
4421 case NL80211_IFTYPE_AP:
4422 case NL80211_IFTYPE_AP_VLAN:
4423 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
4424 /* ignore WME attributes if iface/sta is not capable */
4425 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
4426 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
4427 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 4428
bdd90d5e 4429 /* TDLS peers cannot be added */
3d124ea2
JM
4430 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4431 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 4432 return -EINVAL;
bdd90d5e
JB
4433 /* but don't bother the driver with it */
4434 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 4435
d582cffb
JB
4436 /* allow authenticated/associated only if driver handles it */
4437 if (!(rdev->wiphy.features &
4438 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4439 params.sta_flags_mask &
4440 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4441 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4442 return -EINVAL;
4443
bdd90d5e
JB
4444 /* must be last in here for error handling */
4445 params.vlan = get_vlan(info, rdev);
4446 if (IS_ERR(params.vlan))
4447 return PTR_ERR(params.vlan);
4448 break;
4449 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
4450 /* ignore uAPSD data */
4451 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4452
d582cffb
JB
4453 /* associated is disallowed */
4454 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
4455 return -EINVAL;
bdd90d5e 4456 /* TDLS peers cannot be added */
3d124ea2
JM
4457 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4458 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
4459 return -EINVAL;
4460 break;
4461 case NL80211_IFTYPE_STATION:
93d08f0b 4462 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
4463 /* ignore uAPSD data */
4464 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4465
77ee7c89
JB
4466 /* these are disallowed */
4467 if (params.sta_flags_mask &
4468 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
4469 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 4470 return -EINVAL;
bdd90d5e
JB
4471 /* Only TDLS peers can be added */
4472 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
4473 return -EINVAL;
4474 /* Can only add if TDLS ... */
4475 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
4476 return -EOPNOTSUPP;
4477 /* ... with external setup is supported */
4478 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
4479 return -EOPNOTSUPP;
77ee7c89
JB
4480 /*
4481 * Older wpa_supplicant versions always mark the TDLS peer
4482 * as authorized, but it shouldn't yet be.
4483 */
4484 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
4485 break;
4486 default:
4487 return -EOPNOTSUPP;
c75786c9
EP
4488 }
4489
bdd90d5e 4490 /* be aware of params.vlan when changing code here */
5727ef1b 4491
e35e4d28 4492 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 4493
5727ef1b
JB
4494 if (params.vlan)
4495 dev_put(params.vlan);
5727ef1b
JB
4496 return err;
4497}
4498
4499static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
4500{
4c476991
JB
4501 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4502 struct net_device *dev = info->user_ptr[1];
89c771e5
JM
4503 struct station_del_parameters params;
4504
4505 memset(&params, 0, sizeof(params));
5727ef1b
JB
4506
4507 if (info->attrs[NL80211_ATTR_MAC])
89c771e5 4508 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
5727ef1b 4509
e80cf853 4510 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 4511 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 4512 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4513 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4514 return -EINVAL;
5727ef1b 4515
4c476991
JB
4516 if (!rdev->ops->del_station)
4517 return -EOPNOTSUPP;
3b85875a 4518
98856866
JM
4519 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) {
4520 params.subtype =
4521 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
4522 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 &&
4523 params.subtype != IEEE80211_STYPE_DEAUTH >> 4)
4524 return -EINVAL;
4525 } else {
4526 /* Default to Deauthentication frame */
4527 params.subtype = IEEE80211_STYPE_DEAUTH >> 4;
4528 }
4529
4530 if (info->attrs[NL80211_ATTR_REASON_CODE]) {
4531 params.reason_code =
4532 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4533 if (params.reason_code == 0)
4534 return -EINVAL; /* 0 is reserved */
4535 } else {
4536 /* Default to reason code 2 */
4537 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID;
4538 }
4539
89c771e5 4540 return rdev_del_station(rdev, dev, &params);
5727ef1b
JB
4541}
4542
15e47304 4543static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
4544 int flags, struct net_device *dev,
4545 u8 *dst, u8 *next_hop,
4546 struct mpath_info *pinfo)
4547{
4548 void *hdr;
4549 struct nlattr *pinfoattr;
4550
1ef4c850 4551 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH);
2ec600d6
LCC
4552 if (!hdr)
4553 return -1;
4554
9360ffd1
DM
4555 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4556 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
4557 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
4558 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
4559 goto nla_put_failure;
f5ea9120 4560
2ec600d6
LCC
4561 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
4562 if (!pinfoattr)
4563 goto nla_put_failure;
9360ffd1
DM
4564 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
4565 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
4566 pinfo->frame_qlen))
4567 goto nla_put_failure;
4568 if (((pinfo->filled & MPATH_INFO_SN) &&
4569 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
4570 ((pinfo->filled & MPATH_INFO_METRIC) &&
4571 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
4572 pinfo->metric)) ||
4573 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
4574 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
4575 pinfo->exptime)) ||
4576 ((pinfo->filled & MPATH_INFO_FLAGS) &&
4577 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
4578 pinfo->flags)) ||
4579 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
4580 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
4581 pinfo->discovery_timeout)) ||
4582 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
4583 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
4584 pinfo->discovery_retries)))
4585 goto nla_put_failure;
2ec600d6
LCC
4586
4587 nla_nest_end(msg, pinfoattr);
4588
053c095a
JB
4589 genlmsg_end(msg, hdr);
4590 return 0;
2ec600d6
LCC
4591
4592 nla_put_failure:
bc3ed28c
TG
4593 genlmsg_cancel(msg, hdr);
4594 return -EMSGSIZE;
2ec600d6
LCC
4595}
4596
4597static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 4598 struct netlink_callback *cb)
2ec600d6 4599{
2ec600d6 4600 struct mpath_info pinfo;
1b8ec87a 4601 struct cfg80211_registered_device *rdev;
97990a06 4602 struct wireless_dev *wdev;
2ec600d6
LCC
4603 u8 dst[ETH_ALEN];
4604 u8 next_hop[ETH_ALEN];
97990a06 4605 int path_idx = cb->args[2];
2ec600d6 4606 int err;
2ec600d6 4607
1b8ec87a 4608 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
4609 if (err)
4610 return err;
bba95fef 4611
1b8ec87a 4612 if (!rdev->ops->dump_mpath) {
eec60b03 4613 err = -EOPNOTSUPP;
bba95fef
JB
4614 goto out_err;
4615 }
4616
97990a06 4617 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 4618 err = -EOPNOTSUPP;
0448b5fc 4619 goto out_err;
eec60b03
JM
4620 }
4621
bba95fef 4622 while (1) {
1b8ec87a 4623 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst,
97990a06 4624 next_hop, &pinfo);
bba95fef 4625 if (err == -ENOENT)
2ec600d6 4626 break;
bba95fef 4627 if (err)
3b85875a 4628 goto out_err;
2ec600d6 4629
15e47304 4630 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 4631 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 4632 wdev->netdev, dst, next_hop,
bba95fef
JB
4633 &pinfo) < 0)
4634 goto out;
2ec600d6 4635
bba95fef 4636 path_idx++;
2ec600d6 4637 }
2ec600d6 4638
2ec600d6 4639
bba95fef 4640 out:
97990a06 4641 cb->args[2] = path_idx;
bba95fef 4642 err = skb->len;
bba95fef 4643 out_err:
1b8ec87a 4644 nl80211_finish_wdev_dump(rdev);
bba95fef 4645 return err;
2ec600d6
LCC
4646}
4647
4648static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
4649{
4c476991 4650 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 4651 int err;
4c476991 4652 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4653 struct mpath_info pinfo;
4654 struct sk_buff *msg;
4655 u8 *dst = NULL;
4656 u8 next_hop[ETH_ALEN];
4657
4658 memset(&pinfo, 0, sizeof(pinfo));
4659
4660 if (!info->attrs[NL80211_ATTR_MAC])
4661 return -EINVAL;
4662
4663 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4664
4c476991
JB
4665 if (!rdev->ops->get_mpath)
4666 return -EOPNOTSUPP;
2ec600d6 4667
4c476991
JB
4668 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4669 return -EOPNOTSUPP;
eec60b03 4670
e35e4d28 4671 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 4672 if (err)
4c476991 4673 return err;
2ec600d6 4674
fd2120ca 4675 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 4676 if (!msg)
4c476991 4677 return -ENOMEM;
2ec600d6 4678
15e47304 4679 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
4680 dev, dst, next_hop, &pinfo) < 0) {
4681 nlmsg_free(msg);
4682 return -ENOBUFS;
4683 }
3b85875a 4684
4c476991 4685 return genlmsg_reply(msg, info);
2ec600d6
LCC
4686}
4687
4688static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
4689{
4c476991
JB
4690 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4691 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4692 u8 *dst = NULL;
4693 u8 *next_hop = NULL;
4694
4695 if (!info->attrs[NL80211_ATTR_MAC])
4696 return -EINVAL;
4697
4698 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4699 return -EINVAL;
4700
4701 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4702 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4703
4c476991
JB
4704 if (!rdev->ops->change_mpath)
4705 return -EOPNOTSUPP;
35a8efe1 4706
4c476991
JB
4707 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4708 return -EOPNOTSUPP;
2ec600d6 4709
e35e4d28 4710 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 4711}
4c476991 4712
2ec600d6
LCC
4713static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
4714{
4c476991
JB
4715 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4716 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4717 u8 *dst = NULL;
4718 u8 *next_hop = NULL;
4719
4720 if (!info->attrs[NL80211_ATTR_MAC])
4721 return -EINVAL;
4722
4723 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4724 return -EINVAL;
4725
4726 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4727 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4728
4c476991
JB
4729 if (!rdev->ops->add_mpath)
4730 return -EOPNOTSUPP;
35a8efe1 4731
4c476991
JB
4732 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4733 return -EOPNOTSUPP;
2ec600d6 4734
e35e4d28 4735 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
4736}
4737
4738static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
4739{
4c476991
JB
4740 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4741 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4742 u8 *dst = NULL;
4743
4744 if (info->attrs[NL80211_ATTR_MAC])
4745 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4746
4c476991
JB
4747 if (!rdev->ops->del_mpath)
4748 return -EOPNOTSUPP;
3b85875a 4749
e35e4d28 4750 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
4751}
4752
66be7d2b
HR
4753static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info)
4754{
4755 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4756 int err;
4757 struct net_device *dev = info->user_ptr[1];
4758 struct mpath_info pinfo;
4759 struct sk_buff *msg;
4760 u8 *dst = NULL;
4761 u8 mpp[ETH_ALEN];
4762
4763 memset(&pinfo, 0, sizeof(pinfo));
4764
4765 if (!info->attrs[NL80211_ATTR_MAC])
4766 return -EINVAL;
4767
4768 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4769
4770 if (!rdev->ops->get_mpp)
4771 return -EOPNOTSUPP;
4772
4773 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4774 return -EOPNOTSUPP;
4775
4776 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo);
4777 if (err)
4778 return err;
4779
4780 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4781 if (!msg)
4782 return -ENOMEM;
4783
4784 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4785 dev, dst, mpp, &pinfo) < 0) {
4786 nlmsg_free(msg);
4787 return -ENOBUFS;
4788 }
4789
4790 return genlmsg_reply(msg, info);
4791}
4792
4793static int nl80211_dump_mpp(struct sk_buff *skb,
4794 struct netlink_callback *cb)
4795{
4796 struct mpath_info pinfo;
4797 struct cfg80211_registered_device *rdev;
4798 struct wireless_dev *wdev;
4799 u8 dst[ETH_ALEN];
4800 u8 mpp[ETH_ALEN];
4801 int path_idx = cb->args[2];
4802 int err;
4803
4804 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
4805 if (err)
4806 return err;
4807
4808 if (!rdev->ops->dump_mpp) {
4809 err = -EOPNOTSUPP;
4810 goto out_err;
4811 }
4812
4813 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
4814 err = -EOPNOTSUPP;
4815 goto out_err;
4816 }
4817
4818 while (1) {
4819 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst,
4820 mpp, &pinfo);
4821 if (err == -ENOENT)
4822 break;
4823 if (err)
4824 goto out_err;
4825
4826 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
4827 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4828 wdev->netdev, dst, mpp,
4829 &pinfo) < 0)
4830 goto out;
4831
4832 path_idx++;
4833 }
4834
4835 out:
4836 cb->args[2] = path_idx;
4837 err = skb->len;
4838 out_err:
4839 nl80211_finish_wdev_dump(rdev);
4840 return err;
4841}
4842
9f1ba906
JM
4843static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
4844{
4c476991
JB
4845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4846 struct net_device *dev = info->user_ptr[1];
c56589ed 4847 struct wireless_dev *wdev = dev->ieee80211_ptr;
9f1ba906 4848 struct bss_parameters params;
c56589ed 4849 int err;
9f1ba906
JM
4850
4851 memset(&params, 0, sizeof(params));
4852 /* default to not changing parameters */
4853 params.use_cts_prot = -1;
4854 params.use_short_preamble = -1;
4855 params.use_short_slot_time = -1;
fd8aaaf3 4856 params.ap_isolate = -1;
50b12f59 4857 params.ht_opmode = -1;
53cabad7
JB
4858 params.p2p_ctwindow = -1;
4859 params.p2p_opp_ps = -1;
9f1ba906
JM
4860
4861 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
4862 params.use_cts_prot =
4863 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
4864 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
4865 params.use_short_preamble =
4866 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
4867 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
4868 params.use_short_slot_time =
4869 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
4870 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4871 params.basic_rates =
4872 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4873 params.basic_rates_len =
4874 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4875 }
fd8aaaf3
FF
4876 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
4877 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
4878 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
4879 params.ht_opmode =
4880 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 4881
53cabad7
JB
4882 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
4883 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4884 return -EINVAL;
4885 params.p2p_ctwindow =
4886 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
4887 if (params.p2p_ctwindow < 0)
4888 return -EINVAL;
4889 if (params.p2p_ctwindow != 0 &&
4890 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
4891 return -EINVAL;
4892 }
4893
4894 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
4895 u8 tmp;
4896
4897 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4898 return -EINVAL;
4899 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
4900 if (tmp > 1)
4901 return -EINVAL;
4902 params.p2p_opp_ps = tmp;
4903 if (params.p2p_opp_ps &&
4904 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
4905 return -EINVAL;
4906 }
4907
4c476991
JB
4908 if (!rdev->ops->change_bss)
4909 return -EOPNOTSUPP;
9f1ba906 4910
074ac8df 4911 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
4912 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4913 return -EOPNOTSUPP;
3b85875a 4914
c56589ed
SW
4915 wdev_lock(wdev);
4916 err = rdev_change_bss(rdev, dev, &params);
4917 wdev_unlock(wdev);
4918
4919 return err;
9f1ba906
JM
4920}
4921
b54452b0 4922static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
4923 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
4924 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
4925 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
4926 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
4927 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
4928 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
089027e5 4929 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 },
b2e1b302
LR
4930};
4931
4932static int parse_reg_rule(struct nlattr *tb[],
4933 struct ieee80211_reg_rule *reg_rule)
4934{
4935 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
4936 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
4937
4938 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
4939 return -EINVAL;
4940 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
4941 return -EINVAL;
4942 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
4943 return -EINVAL;
b0dfd2ea
JD
4944 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
4945 return -EINVAL;
b2e1b302
LR
4946 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
4947 return -EINVAL;
4948
4949 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
4950
4951 freq_range->start_freq_khz =
4952 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
4953 freq_range->end_freq_khz =
4954 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
b0dfd2ea
JD
4955 freq_range->max_bandwidth_khz =
4956 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
b2e1b302
LR
4957
4958 power_rule->max_eirp =
4959 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
4960
4961 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
4962 power_rule->max_antenna_gain =
4963 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
4964
089027e5
JD
4965 if (tb[NL80211_ATTR_DFS_CAC_TIME])
4966 reg_rule->dfs_cac_ms =
4967 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]);
4968
b2e1b302
LR
4969 return 0;
4970}
4971
4972static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
4973{
b2e1b302 4974 char *data = NULL;
05050753 4975 bool is_indoor;
57b5ce07 4976 enum nl80211_user_reg_hint_type user_reg_hint_type;
05050753
I
4977 u32 owner_nlportid;
4978
b2e1b302 4979
80778f18
LR
4980 /*
4981 * You should only get this when cfg80211 hasn't yet initialized
4982 * completely when built-in to the kernel right between the time
4983 * window between nl80211_init() and regulatory_init(), if that is
4984 * even possible.
4985 */
458f4f9e 4986 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 4987 return -EINPROGRESS;
80778f18 4988
57b5ce07
LR
4989 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
4990 user_reg_hint_type =
4991 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
4992 else
4993 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
4994
4995 switch (user_reg_hint_type) {
4996 case NL80211_USER_REG_HINT_USER:
4997 case NL80211_USER_REG_HINT_CELL_BASE:
52616f2b
IP
4998 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4999 return -EINVAL;
5000
5001 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
5002 return regulatory_hint_user(data, user_reg_hint_type);
5003 case NL80211_USER_REG_HINT_INDOOR:
05050753
I
5004 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
5005 owner_nlportid = info->snd_portid;
5006 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR];
5007 } else {
5008 owner_nlportid = 0;
5009 is_indoor = true;
5010 }
5011
5012 return regulatory_hint_indoor(is_indoor, owner_nlportid);
57b5ce07
LR
5013 default:
5014 return -EINVAL;
5015 }
b2e1b302
LR
5016}
5017
24bdd9f4 5018static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 5019 struct genl_info *info)
93da9cc1 5020{
4c476991 5021 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 5022 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
5023 struct wireless_dev *wdev = dev->ieee80211_ptr;
5024 struct mesh_config cur_params;
5025 int err = 0;
93da9cc1 5026 void *hdr;
5027 struct nlattr *pinfoattr;
5028 struct sk_buff *msg;
5029
29cbe68c
JB
5030 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
5031 return -EOPNOTSUPP;
5032
24bdd9f4 5033 if (!rdev->ops->get_mesh_config)
4c476991 5034 return -EOPNOTSUPP;
f3f92586 5035
29cbe68c
JB
5036 wdev_lock(wdev);
5037 /* If not connected, get default parameters */
5038 if (!wdev->mesh_id_len)
5039 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
5040 else
e35e4d28 5041 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
5042 wdev_unlock(wdev);
5043
93da9cc1 5044 if (err)
4c476991 5045 return err;
93da9cc1 5046
5047 /* Draw up a netlink message to send back */
fd2120ca 5048 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5049 if (!msg)
5050 return -ENOMEM;
15e47304 5051 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 5052 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 5053 if (!hdr)
efe1cf0c 5054 goto out;
24bdd9f4 5055 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 5056 if (!pinfoattr)
5057 goto nla_put_failure;
9360ffd1
DM
5058 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5059 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
5060 cur_params.dot11MeshRetryTimeout) ||
5061 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
5062 cur_params.dot11MeshConfirmTimeout) ||
5063 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
5064 cur_params.dot11MeshHoldingTimeout) ||
5065 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
5066 cur_params.dot11MeshMaxPeerLinks) ||
5067 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
5068 cur_params.dot11MeshMaxRetries) ||
5069 nla_put_u8(msg, NL80211_MESHCONF_TTL,
5070 cur_params.dot11MeshTTL) ||
5071 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
5072 cur_params.element_ttl) ||
5073 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
5074 cur_params.auto_open_plinks) ||
7eab0f64
JL
5075 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
5076 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
5077 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
5078 cur_params.dot11MeshHWMPmaxPREQretries) ||
5079 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
5080 cur_params.path_refresh_time) ||
5081 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
5082 cur_params.min_discovery_timeout) ||
5083 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
5084 cur_params.dot11MeshHWMPactivePathTimeout) ||
5085 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
5086 cur_params.dot11MeshHWMPpreqMinInterval) ||
5087 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
5088 cur_params.dot11MeshHWMPperrMinInterval) ||
5089 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
5090 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
5091 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
5092 cur_params.dot11MeshHWMPRootMode) ||
5093 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
5094 cur_params.dot11MeshHWMPRannInterval) ||
5095 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
5096 cur_params.dot11MeshGateAnnouncementProtocol) ||
5097 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
5098 cur_params.dot11MeshForwarding) ||
5099 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
5100 cur_params.rssi_threshold) ||
5101 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
5102 cur_params.ht_opmode) ||
5103 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
5104 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
5105 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
5106 cur_params.dot11MeshHWMProotInterval) ||
5107 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
5108 cur_params.dot11MeshHWMPconfirmationInterval) ||
5109 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
5110 cur_params.power_mode) ||
5111 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
5112 cur_params.dot11MeshAwakeWindowDuration) ||
5113 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
5114 cur_params.plink_timeout))
9360ffd1 5115 goto nla_put_failure;
93da9cc1 5116 nla_nest_end(msg, pinfoattr);
5117 genlmsg_end(msg, hdr);
4c476991 5118 return genlmsg_reply(msg, info);
93da9cc1 5119
3b85875a 5120 nla_put_failure:
93da9cc1 5121 genlmsg_cancel(msg, hdr);
efe1cf0c 5122 out:
d080e275 5123 nlmsg_free(msg);
4c476991 5124 return -ENOBUFS;
93da9cc1 5125}
5126
b54452b0 5127static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 5128 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
5129 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
5130 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
5131 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
5132 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
5133 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 5134 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 5135 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 5136 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 5137 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
5138 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
5139 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
5140 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
5141 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 5142 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 5143 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 5144 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 5145 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 5146 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 5147 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
5148 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
5149 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
5150 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
5151 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 5152 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
5153 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
5154 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 5155 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
93da9cc1 5156};
5157
c80d545d
JC
5158static const struct nla_policy
5159 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 5160 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
5161 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
5162 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 5163 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 5164 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 5165 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
581a8b0f 5166 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 5167 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 5168 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
5169};
5170
24bdd9f4 5171static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
5172 struct mesh_config *cfg,
5173 u32 *mask_out)
93da9cc1 5174{
93da9cc1 5175 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 5176 u32 mask = 0;
93da9cc1 5177
ea54fba2
MP
5178#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
5179do { \
5180 if (tb[attr]) { \
5181 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
5182 return -EINVAL; \
5183 cfg->param = fn(tb[attr]); \
5184 mask |= (1 << (attr - 1)); \
5185 } \
5186} while (0)
bd90fdcc
JB
5187
5188
24bdd9f4 5189 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 5190 return -EINVAL;
5191 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 5192 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 5193 nl80211_meshconf_params_policy))
93da9cc1 5194 return -EINVAL;
5195
93da9cc1 5196 /* This makes sure that there aren't more than 32 mesh config
5197 * parameters (otherwise our bitfield scheme would not work.) */
5198 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
5199
5200 /* Fill in the params struct */
ea54fba2 5201 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
5202 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
5203 nla_get_u16);
ea54fba2 5204 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
5205 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
5206 nla_get_u16);
ea54fba2 5207 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
5208 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
5209 nla_get_u16);
ea54fba2 5210 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
5211 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
5212 nla_get_u16);
ea54fba2 5213 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
5214 mask, NL80211_MESHCONF_MAX_RETRIES,
5215 nla_get_u8);
ea54fba2 5216 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 5217 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 5218 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
5219 mask, NL80211_MESHCONF_ELEMENT_TTL,
5220 nla_get_u8);
ea54fba2 5221 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
5222 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
5223 nla_get_u8);
ea54fba2
MP
5224 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
5225 1, 255, mask,
a4f606ea
CYY
5226 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
5227 nla_get_u32);
ea54fba2 5228 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
5229 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
5230 nla_get_u8);
ea54fba2 5231 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
5232 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
5233 nla_get_u32);
ea54fba2 5234 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
5235 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
5236 nla_get_u16);
ea54fba2
MP
5237 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
5238 1, 65535, mask,
a4f606ea
CYY
5239 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
5240 nla_get_u32);
93da9cc1 5241 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
5242 1, 65535, mask,
5243 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 5244 nla_get_u16);
dca7e943 5245 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
5246 1, 65535, mask,
5247 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 5248 nla_get_u16);
93da9cc1 5249 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
5250 dot11MeshHWMPnetDiameterTraversalTime,
5251 1, 65535, mask,
a4f606ea
CYY
5252 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
5253 nla_get_u16);
ea54fba2
MP
5254 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
5255 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
5256 nla_get_u8);
5257 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
5258 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 5259 nla_get_u16);
63c5723b 5260 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
5261 dot11MeshGateAnnouncementProtocol, 0, 1,
5262 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 5263 nla_get_u8);
ea54fba2 5264 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
5265 mask, NL80211_MESHCONF_FORWARDING,
5266 nla_get_u8);
83374fe9 5267 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0,
a4f606ea 5268 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
83374fe9 5269 nla_get_s32);
ea54fba2 5270 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 5271 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
5272 nla_get_u16);
5273 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 5274 1, 65535, mask,
ac1073a6
CYY
5275 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
5276 nla_get_u32);
ea54fba2 5277 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 5278 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
5279 nla_get_u16);
5280 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
5281 dot11MeshHWMPconfirmationInterval,
5282 1, 65535, mask,
728b19e5 5283 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 5284 nla_get_u16);
3b1c5a53
MP
5285 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
5286 NL80211_MESH_POWER_ACTIVE,
5287 NL80211_MESH_POWER_MAX,
5288 mask, NL80211_MESHCONF_POWER_MODE,
5289 nla_get_u32);
5290 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
5291 0, 65535, mask,
5292 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
31f909a2 5293 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 0, 0xffffffff,
8e7c0538
CT
5294 mask, NL80211_MESHCONF_PLINK_TIMEOUT,
5295 nla_get_u32);
bd90fdcc
JB
5296 if (mask_out)
5297 *mask_out = mask;
c80d545d 5298
bd90fdcc
JB
5299 return 0;
5300
5301#undef FILL_IN_MESH_PARAM_IF_SET
5302}
5303
c80d545d
JC
5304static int nl80211_parse_mesh_setup(struct genl_info *info,
5305 struct mesh_setup *setup)
5306{
bb2798d4 5307 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
5308 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
5309
5310 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
5311 return -EINVAL;
5312 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
5313 info->attrs[NL80211_ATTR_MESH_SETUP],
5314 nl80211_mesh_setup_params_policy))
5315 return -EINVAL;
5316
d299a1f2
JC
5317 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
5318 setup->sync_method =
5319 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
5320 IEEE80211_SYNC_METHOD_VENDOR :
5321 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
5322
c80d545d
JC
5323 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
5324 setup->path_sel_proto =
5325 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
5326 IEEE80211_PATH_PROTOCOL_VENDOR :
5327 IEEE80211_PATH_PROTOCOL_HWMP;
5328
5329 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
5330 setup->path_metric =
5331 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
5332 IEEE80211_PATH_METRIC_VENDOR :
5333 IEEE80211_PATH_METRIC_AIRTIME;
5334
581a8b0f
JC
5335
5336 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 5337 struct nlattr *ieattr =
581a8b0f 5338 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
5339 if (!is_valid_ie_attr(ieattr))
5340 return -EINVAL;
581a8b0f
JC
5341 setup->ie = nla_data(ieattr);
5342 setup->ie_len = nla_len(ieattr);
c80d545d 5343 }
bb2798d4
TP
5344 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
5345 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
5346 return -EINVAL;
5347 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
5348 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
5349 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
5350 if (setup->is_secure)
5351 setup->user_mpm = true;
c80d545d 5352
6e16d90b
CT
5353 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
5354 if (!setup->user_mpm)
5355 return -EINVAL;
5356 setup->auth_id =
5357 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
5358 }
5359
c80d545d
JC
5360 return 0;
5361}
5362
24bdd9f4 5363static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 5364 struct genl_info *info)
bd90fdcc
JB
5365{
5366 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5367 struct net_device *dev = info->user_ptr[1];
29cbe68c 5368 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
5369 struct mesh_config cfg;
5370 u32 mask;
5371 int err;
5372
29cbe68c
JB
5373 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
5374 return -EOPNOTSUPP;
5375
24bdd9f4 5376 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
5377 return -EOPNOTSUPP;
5378
24bdd9f4 5379 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
5380 if (err)
5381 return err;
5382
29cbe68c
JB
5383 wdev_lock(wdev);
5384 if (!wdev->mesh_id_len)
5385 err = -ENOLINK;
5386
5387 if (!err)
e35e4d28 5388 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
5389
5390 wdev_unlock(wdev);
5391
5392 return err;
93da9cc1 5393}
5394
ad30ca2c
AN
5395static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom,
5396 struct sk_buff *msg)
f130347c 5397{
f130347c
LR
5398 struct nlattr *nl_reg_rules;
5399 unsigned int i;
f130347c 5400
458f4f9e
JB
5401 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
5402 (regdom->dfs_region &&
5403 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
ad30ca2c 5404 goto nla_put_failure;
458f4f9e 5405
f130347c
LR
5406 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
5407 if (!nl_reg_rules)
ad30ca2c 5408 goto nla_put_failure;
f130347c 5409
458f4f9e 5410 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
5411 struct nlattr *nl_reg_rule;
5412 const struct ieee80211_reg_rule *reg_rule;
5413 const struct ieee80211_freq_range *freq_range;
5414 const struct ieee80211_power_rule *power_rule;
97524820 5415 unsigned int max_bandwidth_khz;
f130347c 5416
458f4f9e 5417 reg_rule = &regdom->reg_rules[i];
f130347c
LR
5418 freq_range = &reg_rule->freq_range;
5419 power_rule = &reg_rule->power_rule;
5420
5421 nl_reg_rule = nla_nest_start(msg, i);
5422 if (!nl_reg_rule)
ad30ca2c 5423 goto nla_put_failure;
f130347c 5424
97524820
JD
5425 max_bandwidth_khz = freq_range->max_bandwidth_khz;
5426 if (!max_bandwidth_khz)
5427 max_bandwidth_khz = reg_get_max_bandwidth(regdom,
5428 reg_rule);
5429
9360ffd1
DM
5430 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
5431 reg_rule->flags) ||
5432 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
5433 freq_range->start_freq_khz) ||
5434 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
5435 freq_range->end_freq_khz) ||
5436 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
97524820 5437 max_bandwidth_khz) ||
9360ffd1
DM
5438 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
5439 power_rule->max_antenna_gain) ||
5440 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
089027e5
JD
5441 power_rule->max_eirp) ||
5442 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME,
5443 reg_rule->dfs_cac_ms))
ad30ca2c 5444 goto nla_put_failure;
f130347c
LR
5445
5446 nla_nest_end(msg, nl_reg_rule);
5447 }
5448
5449 nla_nest_end(msg, nl_reg_rules);
ad30ca2c
AN
5450 return 0;
5451
5452nla_put_failure:
5453 return -EMSGSIZE;
5454}
5455
5456static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info)
5457{
5458 const struct ieee80211_regdomain *regdom = NULL;
5459 struct cfg80211_registered_device *rdev;
5460 struct wiphy *wiphy = NULL;
5461 struct sk_buff *msg;
5462 void *hdr;
5463
5464 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5465 if (!msg)
5466 return -ENOBUFS;
5467
5468 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
5469 NL80211_CMD_GET_REG);
5470 if (!hdr)
5471 goto put_failure;
5472
5473 if (info->attrs[NL80211_ATTR_WIPHY]) {
1bdd716c
AN
5474 bool self_managed;
5475
ad30ca2c
AN
5476 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
5477 if (IS_ERR(rdev)) {
5478 nlmsg_free(msg);
5479 return PTR_ERR(rdev);
5480 }
5481
5482 wiphy = &rdev->wiphy;
1bdd716c
AN
5483 self_managed = wiphy->regulatory_flags &
5484 REGULATORY_WIPHY_SELF_MANAGED;
ad30ca2c
AN
5485 regdom = get_wiphy_regdom(wiphy);
5486
1bdd716c
AN
5487 /* a self-managed-reg device must have a private regdom */
5488 if (WARN_ON(!regdom && self_managed)) {
5489 nlmsg_free(msg);
5490 return -EINVAL;
5491 }
5492
ad30ca2c
AN
5493 if (regdom &&
5494 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
5495 goto nla_put_failure;
5496 }
5497
5498 if (!wiphy && reg_last_request_cell_base() &&
5499 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
5500 NL80211_USER_REG_HINT_CELL_BASE))
5501 goto nla_put_failure;
5502
5503 rcu_read_lock();
5504
5505 if (!regdom)
5506 regdom = rcu_dereference(cfg80211_regdomain);
5507
5508 if (nl80211_put_regdom(regdom, msg))
5509 goto nla_put_failure_rcu;
5510
5511 rcu_read_unlock();
f130347c
LR
5512
5513 genlmsg_end(msg, hdr);
5fe231e8 5514 return genlmsg_reply(msg, info);
f130347c 5515
458f4f9e
JB
5516nla_put_failure_rcu:
5517 rcu_read_unlock();
f130347c
LR
5518nla_put_failure:
5519 genlmsg_cancel(msg, hdr);
efe1cf0c 5520put_failure:
d080e275 5521 nlmsg_free(msg);
5fe231e8 5522 return -EMSGSIZE;
f130347c
LR
5523}
5524
ad30ca2c
AN
5525static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb,
5526 u32 seq, int flags, struct wiphy *wiphy,
5527 const struct ieee80211_regdomain *regdom)
5528{
5529 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
5530 NL80211_CMD_GET_REG);
5531
5532 if (!hdr)
5533 return -1;
5534
5535 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
5536
5537 if (nl80211_put_regdom(regdom, msg))
5538 goto nla_put_failure;
5539
5540 if (!wiphy && reg_last_request_cell_base() &&
5541 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
5542 NL80211_USER_REG_HINT_CELL_BASE))
5543 goto nla_put_failure;
5544
5545 if (wiphy &&
5546 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
5547 goto nla_put_failure;
5548
1bdd716c
AN
5549 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
5550 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
5551 goto nla_put_failure;
5552
053c095a
JB
5553 genlmsg_end(msg, hdr);
5554 return 0;
ad30ca2c
AN
5555
5556nla_put_failure:
5557 genlmsg_cancel(msg, hdr);
5558 return -EMSGSIZE;
5559}
5560
5561static int nl80211_get_reg_dump(struct sk_buff *skb,
5562 struct netlink_callback *cb)
5563{
5564 const struct ieee80211_regdomain *regdom = NULL;
5565 struct cfg80211_registered_device *rdev;
5566 int err, reg_idx, start = cb->args[2];
5567
5568 rtnl_lock();
5569
5570 if (cfg80211_regdomain && start == 0) {
5571 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
5572 NLM_F_MULTI, NULL,
5573 rtnl_dereference(cfg80211_regdomain));
5574 if (err < 0)
5575 goto out_err;
5576 }
5577
5578 /* the global regdom is idx 0 */
5579 reg_idx = 1;
5580 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
5581 regdom = get_wiphy_regdom(&rdev->wiphy);
5582 if (!regdom)
5583 continue;
5584
5585 if (++reg_idx <= start)
5586 continue;
5587
5588 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
5589 NLM_F_MULTI, &rdev->wiphy, regdom);
5590 if (err < 0) {
5591 reg_idx--;
5592 break;
5593 }
5594 }
5595
5596 cb->args[2] = reg_idx;
5597 err = skb->len;
5598out_err:
5599 rtnl_unlock();
5600 return err;
5601}
5602
b2e1b302
LR
5603static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
5604{
5605 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
5606 struct nlattr *nl_reg_rule;
ea372c54
JB
5607 char *alpha2;
5608 int rem_reg_rules, r;
b2e1b302 5609 u32 num_rules = 0, rule_idx = 0, size_of_regd;
4c7d3982 5610 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
ea372c54 5611 struct ieee80211_regdomain *rd;
b2e1b302
LR
5612
5613 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
5614 return -EINVAL;
5615
5616 if (!info->attrs[NL80211_ATTR_REG_RULES])
5617 return -EINVAL;
5618
5619 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
5620
8b60b078
LR
5621 if (info->attrs[NL80211_ATTR_DFS_REGION])
5622 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
5623
b2e1b302 5624 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5625 rem_reg_rules) {
b2e1b302
LR
5626 num_rules++;
5627 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 5628 return -EINVAL;
b2e1b302
LR
5629 }
5630
e438768f
LR
5631 if (!reg_is_valid_request(alpha2))
5632 return -EINVAL;
5633
b2e1b302 5634 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 5635 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
5636
5637 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
5638 if (!rd)
5639 return -ENOMEM;
b2e1b302
LR
5640
5641 rd->n_reg_rules = num_rules;
5642 rd->alpha2[0] = alpha2[0];
5643 rd->alpha2[1] = alpha2[1];
5644
8b60b078
LR
5645 /*
5646 * Disable DFS master mode if the DFS region was
5647 * not supported or known on this kernel.
5648 */
5649 if (reg_supported_dfs_region(dfs_region))
5650 rd->dfs_region = dfs_region;
5651
b2e1b302 5652 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5653 rem_reg_rules) {
ae811e21
JB
5654 r = nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
5655 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
5656 reg_rule_policy);
5657 if (r)
5658 goto bad_reg;
b2e1b302
LR
5659 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
5660 if (r)
5661 goto bad_reg;
5662
5663 rule_idx++;
5664
d0e18f83
LR
5665 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
5666 r = -EINVAL;
b2e1b302 5667 goto bad_reg;
d0e18f83 5668 }
b2e1b302
LR
5669 }
5670
c37722bd 5671 r = set_regdom(rd, REGD_SOURCE_CRDA);
6913b49a 5672 /* set_regdom took ownership */
1a919318 5673 rd = NULL;
b2e1b302 5674
d2372b31 5675 bad_reg:
b2e1b302 5676 kfree(rd);
d0e18f83 5677 return r;
b2e1b302
LR
5678}
5679
83f5e2cf
JB
5680static int validate_scan_freqs(struct nlattr *freqs)
5681{
5682 struct nlattr *attr1, *attr2;
5683 int n_channels = 0, tmp1, tmp2;
5684
5685 nla_for_each_nested(attr1, freqs, tmp1) {
5686 n_channels++;
5687 /*
5688 * Some hardware has a limited channel list for
5689 * scanning, and it is pretty much nonsensical
5690 * to scan for a channel twice, so disallow that
5691 * and don't require drivers to check that the
5692 * channel list they get isn't longer than what
5693 * they can scan, as long as they can scan all
5694 * the channels they registered at once.
5695 */
5696 nla_for_each_nested(attr2, freqs, tmp2)
5697 if (attr1 != attr2 &&
5698 nla_get_u32(attr1) == nla_get_u32(attr2))
5699 return 0;
5700 }
5701
5702 return n_channels;
5703}
5704
ad2b26ab
JB
5705static int nl80211_parse_random_mac(struct nlattr **attrs,
5706 u8 *mac_addr, u8 *mac_addr_mask)
5707{
5708 int i;
5709
5710 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) {
d2beae10
JP
5711 eth_zero_addr(mac_addr);
5712 eth_zero_addr(mac_addr_mask);
ad2b26ab
JB
5713 mac_addr[0] = 0x2;
5714 mac_addr_mask[0] = 0x3;
5715
5716 return 0;
5717 }
5718
5719 /* need both or none */
5720 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK])
5721 return -EINVAL;
5722
5723 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN);
5724 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN);
5725
5726 /* don't allow or configure an mcast address */
5727 if (!is_multicast_ether_addr(mac_addr_mask) ||
5728 is_multicast_ether_addr(mac_addr))
5729 return -EINVAL;
5730
5731 /*
5732 * allow users to pass a MAC address that has bits set outside
5733 * of the mask, but don't bother drivers with having to deal
5734 * with such bits
5735 */
5736 for (i = 0; i < ETH_ALEN; i++)
5737 mac_addr[i] &= mac_addr_mask[i];
5738
5739 return 0;
5740}
5741
2a519311
JB
5742static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
5743{
4c476991 5744 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 5745 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 5746 struct cfg80211_scan_request *request;
2a519311
JB
5747 struct nlattr *attr;
5748 struct wiphy *wiphy;
83f5e2cf 5749 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 5750 size_t ie_len;
2a519311 5751
f4a11bb0
JB
5752 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5753 return -EINVAL;
5754
79c97e97 5755 wiphy = &rdev->wiphy;
2a519311 5756
4c476991
JB
5757 if (!rdev->ops->scan)
5758 return -EOPNOTSUPP;
2a519311 5759
f9d15d16 5760 if (rdev->scan_req || rdev->scan_msg) {
f9f47529
JB
5761 err = -EBUSY;
5762 goto unlock;
5763 }
2a519311
JB
5764
5765 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
5766 n_channels = validate_scan_freqs(
5767 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
5768 if (!n_channels) {
5769 err = -EINVAL;
5770 goto unlock;
5771 }
2a519311 5772 } else {
bdfbec2d 5773 n_channels = ieee80211_get_num_supported_channels(wiphy);
2a519311
JB
5774 }
5775
5776 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5777 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
5778 n_ssids++;
5779
f9f47529
JB
5780 if (n_ssids > wiphy->max_scan_ssids) {
5781 err = -EINVAL;
5782 goto unlock;
5783 }
2a519311 5784
70692ad2
JM
5785 if (info->attrs[NL80211_ATTR_IE])
5786 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5787 else
5788 ie_len = 0;
5789
f9f47529
JB
5790 if (ie_len > wiphy->max_scan_ie_len) {
5791 err = -EINVAL;
5792 goto unlock;
5793 }
18a83659 5794
2a519311 5795 request = kzalloc(sizeof(*request)
a2cd43c5
LC
5796 + sizeof(*request->ssids) * n_ssids
5797 + sizeof(*request->channels) * n_channels
70692ad2 5798 + ie_len, GFP_KERNEL);
f9f47529
JB
5799 if (!request) {
5800 err = -ENOMEM;
5801 goto unlock;
5802 }
2a519311 5803
2a519311 5804 if (n_ssids)
5ba63533 5805 request->ssids = (void *)&request->channels[n_channels];
2a519311 5806 request->n_ssids = n_ssids;
70692ad2 5807 if (ie_len) {
13874e4b 5808 if (n_ssids)
70692ad2
JM
5809 request->ie = (void *)(request->ssids + n_ssids);
5810 else
5811 request->ie = (void *)(request->channels + n_channels);
5812 }
2a519311 5813
584991dc 5814 i = 0;
2a519311
JB
5815 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5816 /* user specified, bail out if channel not found */
2a519311 5817 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
5818 struct ieee80211_channel *chan;
5819
5820 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5821
5822 if (!chan) {
2a519311
JB
5823 err = -EINVAL;
5824 goto out_free;
5825 }
584991dc
JB
5826
5827 /* ignore disabled channels */
5828 if (chan->flags & IEEE80211_CHAN_DISABLED)
5829 continue;
5830
5831 request->channels[i] = chan;
2a519311
JB
5832 i++;
5833 }
5834 } else {
34850ab2
JB
5835 enum ieee80211_band band;
5836
2a519311 5837 /* all channels */
2a519311
JB
5838 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5839 int j;
5840 if (!wiphy->bands[band])
5841 continue;
5842 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
5843 struct ieee80211_channel *chan;
5844
5845 chan = &wiphy->bands[band]->channels[j];
5846
5847 if (chan->flags & IEEE80211_CHAN_DISABLED)
5848 continue;
5849
5850 request->channels[i] = chan;
2a519311
JB
5851 i++;
5852 }
5853 }
5854 }
5855
584991dc
JB
5856 if (!i) {
5857 err = -EINVAL;
5858 goto out_free;
5859 }
5860
5861 request->n_channels = i;
5862
2a519311 5863 i = 0;
13874e4b 5864 if (n_ssids) {
2a519311 5865 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 5866 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
5867 err = -EINVAL;
5868 goto out_free;
5869 }
57a27e1d 5870 request->ssids[i].ssid_len = nla_len(attr);
2a519311 5871 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
5872 i++;
5873 }
5874 }
5875
70692ad2
JM
5876 if (info->attrs[NL80211_ATTR_IE]) {
5877 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
5878 memcpy((void *)request->ie,
5879 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
5880 request->ie_len);
5881 }
5882
34850ab2 5883 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
5884 if (wiphy->bands[i])
5885 request->rates[i] =
5886 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
5887
5888 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
5889 nla_for_each_nested(attr,
5890 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
5891 tmp) {
5892 enum ieee80211_band band = nla_type(attr);
5893
84404623 5894 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
5895 err = -EINVAL;
5896 goto out_free;
5897 }
1b09cd82
FF
5898
5899 if (!wiphy->bands[band])
5900 continue;
5901
34850ab2
JB
5902 err = ieee80211_get_ratemask(wiphy->bands[band],
5903 nla_data(attr),
5904 nla_len(attr),
5905 &request->rates[band]);
5906 if (err)
5907 goto out_free;
5908 }
5909 }
5910
46856bbf 5911 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5912 request->flags = nla_get_u32(
5913 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
00c3a6ed
JB
5914 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5915 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) {
46856bbf
SL
5916 err = -EOPNOTSUPP;
5917 goto out_free;
5918 }
ad2b26ab
JB
5919
5920 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
5921 if (!(wiphy->features &
5922 NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR)) {
5923 err = -EOPNOTSUPP;
5924 goto out_free;
5925 }
5926
5927 if (wdev->current_bss) {
5928 err = -EOPNOTSUPP;
5929 goto out_free;
5930 }
5931
5932 err = nl80211_parse_random_mac(info->attrs,
5933 request->mac_addr,
5934 request->mac_addr_mask);
5935 if (err)
5936 goto out_free;
5937 }
46856bbf 5938 }
ed473771 5939
e9f935e3
RM
5940 request->no_cck =
5941 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5942
fd014284 5943 request->wdev = wdev;
79c97e97 5944 request->wiphy = &rdev->wiphy;
15d6030b 5945 request->scan_start = jiffies;
2a519311 5946
79c97e97 5947 rdev->scan_req = request;
e35e4d28 5948 err = rdev_scan(rdev, request);
2a519311 5949
463d0183 5950 if (!err) {
fd014284
JB
5951 nl80211_send_scan_start(rdev, wdev);
5952 if (wdev->netdev)
5953 dev_hold(wdev->netdev);
4c476991 5954 } else {
2a519311 5955 out_free:
79c97e97 5956 rdev->scan_req = NULL;
2a519311
JB
5957 kfree(request);
5958 }
3b85875a 5959
f9f47529 5960 unlock:
2a519311
JB
5961 return err;
5962}
5963
256da02d 5964static struct cfg80211_sched_scan_request *
ad2b26ab 5965nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev,
256da02d 5966 struct nlattr **attrs)
807f8a8c
LC
5967{
5968 struct cfg80211_sched_scan_request *request;
807f8a8c 5969 struct nlattr *attr;
a1f1c21c 5970 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 5971 u32 interval;
807f8a8c
LC
5972 enum ieee80211_band band;
5973 size_t ie_len;
a1f1c21c 5974 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
ea73cbce 5975 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF;
807f8a8c 5976
256da02d
LC
5977 if (!is_valid_ie_attr(attrs[NL80211_ATTR_IE]))
5978 return ERR_PTR(-EINVAL);
807f8a8c 5979
256da02d
LC
5980 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
5981 return ERR_PTR(-EINVAL);
bbe6ad6d 5982
256da02d 5983 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
bbe6ad6d 5984 if (interval == 0)
256da02d 5985 return ERR_PTR(-EINVAL);
807f8a8c 5986
256da02d 5987 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c 5988 n_channels = validate_scan_freqs(
256da02d 5989 attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
807f8a8c 5990 if (!n_channels)
256da02d 5991 return ERR_PTR(-EINVAL);
807f8a8c 5992 } else {
bdfbec2d 5993 n_channels = ieee80211_get_num_supported_channels(wiphy);
807f8a8c
LC
5994 }
5995
256da02d
LC
5996 if (attrs[NL80211_ATTR_SCAN_SSIDS])
5997 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c
LC
5998 tmp)
5999 n_ssids++;
6000
93b6aa69 6001 if (n_ssids > wiphy->max_sched_scan_ssids)
256da02d 6002 return ERR_PTR(-EINVAL);
807f8a8c 6003
ea73cbce
JB
6004 /*
6005 * First, count the number of 'real' matchsets. Due to an issue with
6006 * the old implementation, matchsets containing only the RSSI attribute
6007 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default'
6008 * RSSI for all matchsets, rather than their own matchset for reporting
6009 * all APs with a strong RSSI. This is needed to be compatible with
6010 * older userspace that treated a matchset with only the RSSI as the
6011 * global RSSI for all other matchsets - if there are other matchsets.
6012 */
256da02d 6013 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 6014 nla_for_each_nested(attr,
256da02d 6015 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
ea73cbce
JB
6016 tmp) {
6017 struct nlattr *rssi;
6018
6019 err = nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
6020 nla_data(attr), nla_len(attr),
6021 nl80211_match_policy);
6022 if (err)
256da02d 6023 return ERR_PTR(err);
ea73cbce
JB
6024 /* add other standalone attributes here */
6025 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]) {
6026 n_match_sets++;
6027 continue;
6028 }
6029 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
6030 if (rssi)
6031 default_match_rssi = nla_get_s32(rssi);
6032 }
6033 }
6034
6035 /* However, if there's no other matchset, add the RSSI one */
6036 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF)
6037 n_match_sets = 1;
a1f1c21c
LC
6038
6039 if (n_match_sets > wiphy->max_match_sets)
256da02d 6040 return ERR_PTR(-EINVAL);
a1f1c21c 6041
256da02d
LC
6042 if (attrs[NL80211_ATTR_IE])
6043 ie_len = nla_len(attrs[NL80211_ATTR_IE]);
807f8a8c
LC
6044 else
6045 ie_len = 0;
6046
5a865bad 6047 if (ie_len > wiphy->max_sched_scan_ie_len)
256da02d 6048 return ERR_PTR(-EINVAL);
c10841ca 6049
807f8a8c 6050 request = kzalloc(sizeof(*request)
a2cd43c5 6051 + sizeof(*request->ssids) * n_ssids
a1f1c21c 6052 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 6053 + sizeof(*request->channels) * n_channels
807f8a8c 6054 + ie_len, GFP_KERNEL);
256da02d
LC
6055 if (!request)
6056 return ERR_PTR(-ENOMEM);
807f8a8c
LC
6057
6058 if (n_ssids)
6059 request->ssids = (void *)&request->channels[n_channels];
6060 request->n_ssids = n_ssids;
6061 if (ie_len) {
13874e4b 6062 if (n_ssids)
807f8a8c
LC
6063 request->ie = (void *)(request->ssids + n_ssids);
6064 else
6065 request->ie = (void *)(request->channels + n_channels);
6066 }
6067
a1f1c21c
LC
6068 if (n_match_sets) {
6069 if (request->ie)
6070 request->match_sets = (void *)(request->ie + ie_len);
13874e4b 6071 else if (n_ssids)
a1f1c21c
LC
6072 request->match_sets =
6073 (void *)(request->ssids + n_ssids);
6074 else
6075 request->match_sets =
6076 (void *)(request->channels + n_channels);
6077 }
6078 request->n_match_sets = n_match_sets;
6079
807f8a8c 6080 i = 0;
256da02d 6081 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c
LC
6082 /* user specified, bail out if channel not found */
6083 nla_for_each_nested(attr,
256da02d 6084 attrs[NL80211_ATTR_SCAN_FREQUENCIES],
807f8a8c
LC
6085 tmp) {
6086 struct ieee80211_channel *chan;
6087
6088 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
6089
6090 if (!chan) {
6091 err = -EINVAL;
6092 goto out_free;
6093 }
6094
6095 /* ignore disabled channels */
6096 if (chan->flags & IEEE80211_CHAN_DISABLED)
6097 continue;
6098
6099 request->channels[i] = chan;
6100 i++;
6101 }
6102 } else {
6103 /* all channels */
6104 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
6105 int j;
6106 if (!wiphy->bands[band])
6107 continue;
6108 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
6109 struct ieee80211_channel *chan;
6110
6111 chan = &wiphy->bands[band]->channels[j];
6112
6113 if (chan->flags & IEEE80211_CHAN_DISABLED)
6114 continue;
6115
6116 request->channels[i] = chan;
6117 i++;
6118 }
6119 }
6120 }
6121
6122 if (!i) {
6123 err = -EINVAL;
6124 goto out_free;
6125 }
6126
6127 request->n_channels = i;
6128
6129 i = 0;
13874e4b 6130 if (n_ssids) {
256da02d 6131 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c 6132 tmp) {
57a27e1d 6133 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
6134 err = -EINVAL;
6135 goto out_free;
6136 }
57a27e1d 6137 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
6138 memcpy(request->ssids[i].ssid, nla_data(attr),
6139 nla_len(attr));
807f8a8c
LC
6140 i++;
6141 }
6142 }
6143
a1f1c21c 6144 i = 0;
256da02d 6145 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 6146 nla_for_each_nested(attr,
256da02d 6147 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
a1f1c21c 6148 tmp) {
88e920b4 6149 struct nlattr *ssid, *rssi;
a1f1c21c 6150
ae811e21
JB
6151 err = nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
6152 nla_data(attr), nla_len(attr),
6153 nl80211_match_policy);
6154 if (err)
6155 goto out_free;
4a4ab0d7 6156 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c 6157 if (ssid) {
ea73cbce
JB
6158 if (WARN_ON(i >= n_match_sets)) {
6159 /* this indicates a programming error,
6160 * the loop above should have verified
6161 * things properly
6162 */
6163 err = -EINVAL;
6164 goto out_free;
6165 }
6166
a1f1c21c
LC
6167 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
6168 err = -EINVAL;
6169 goto out_free;
6170 }
6171 memcpy(request->match_sets[i].ssid.ssid,
6172 nla_data(ssid), nla_len(ssid));
6173 request->match_sets[i].ssid.ssid_len =
6174 nla_len(ssid);
ea73cbce
JB
6175 /* special attribute - old implemenation w/a */
6176 request->match_sets[i].rssi_thold =
6177 default_match_rssi;
6178 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
6179 if (rssi)
6180 request->match_sets[i].rssi_thold =
6181 nla_get_s32(rssi);
a1f1c21c
LC
6182 }
6183 i++;
6184 }
ea73cbce
JB
6185
6186 /* there was no other matchset, so the RSSI one is alone */
f89f46cf 6187 if (i == 0 && n_match_sets)
ea73cbce
JB
6188 request->match_sets[0].rssi_thold = default_match_rssi;
6189
6190 request->min_rssi_thold = INT_MAX;
6191 for (i = 0; i < n_match_sets; i++)
6192 request->min_rssi_thold =
6193 min(request->match_sets[i].rssi_thold,
6194 request->min_rssi_thold);
6195 } else {
6196 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
6197 }
6198
9900e484
JB
6199 if (ie_len) {
6200 request->ie_len = ie_len;
807f8a8c 6201 memcpy((void *)request->ie,
256da02d 6202 nla_data(attrs[NL80211_ATTR_IE]),
807f8a8c
LC
6203 request->ie_len);
6204 }
6205
256da02d 6206 if (attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771 6207 request->flags = nla_get_u32(
256da02d 6208 attrs[NL80211_ATTR_SCAN_FLAGS]);
00c3a6ed
JB
6209 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
6210 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) {
46856bbf
SL
6211 err = -EOPNOTSUPP;
6212 goto out_free;
6213 }
ad2b26ab
JB
6214
6215 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
6216 u32 flg = NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR;
6217
6218 if (!wdev) /* must be net-detect */
6219 flg = NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
6220
6221 if (!(wiphy->features & flg)) {
6222 err = -EOPNOTSUPP;
6223 goto out_free;
6224 }
6225
6226 if (wdev && wdev->current_bss) {
6227 err = -EOPNOTSUPP;
6228 goto out_free;
6229 }
6230
6231 err = nl80211_parse_random_mac(attrs, request->mac_addr,
6232 request->mac_addr_mask);
6233 if (err)
6234 goto out_free;
6235 }
46856bbf 6236 }
ed473771 6237
9c748934
LC
6238 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY])
6239 request->delay =
6240 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]);
6241
bbe6ad6d 6242 request->interval = interval;
15d6030b 6243 request->scan_start = jiffies;
807f8a8c 6244
256da02d 6245 return request;
807f8a8c
LC
6246
6247out_free:
6248 kfree(request);
256da02d
LC
6249 return ERR_PTR(err);
6250}
6251
6252static int nl80211_start_sched_scan(struct sk_buff *skb,
6253 struct genl_info *info)
6254{
6255 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6256 struct net_device *dev = info->user_ptr[1];
ad2b26ab 6257 struct wireless_dev *wdev = dev->ieee80211_ptr;
31a60ed1 6258 struct cfg80211_sched_scan_request *sched_scan_req;
256da02d
LC
6259 int err;
6260
6261 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
6262 !rdev->ops->sched_scan_start)
6263 return -EOPNOTSUPP;
6264
6265 if (rdev->sched_scan_req)
6266 return -EINPROGRESS;
6267
31a60ed1
JR
6268 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev,
6269 info->attrs);
6270
6271 err = PTR_ERR_OR_ZERO(sched_scan_req);
256da02d
LC
6272 if (err)
6273 goto out_err;
6274
31a60ed1 6275 err = rdev_sched_scan_start(rdev, dev, sched_scan_req);
256da02d
LC
6276 if (err)
6277 goto out_free;
6278
31a60ed1
JR
6279 sched_scan_req->dev = dev;
6280 sched_scan_req->wiphy = &rdev->wiphy;
6281
93a1e86c
JR
6282 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
6283 sched_scan_req->owner_nlportid = info->snd_portid;
6284
31a60ed1 6285 rcu_assign_pointer(rdev->sched_scan_req, sched_scan_req);
256da02d
LC
6286
6287 nl80211_send_sched_scan(rdev, dev,
6288 NL80211_CMD_START_SCHED_SCAN);
6289 return 0;
6290
6291out_free:
31a60ed1 6292 kfree(sched_scan_req);
256da02d 6293out_err:
807f8a8c
LC
6294 return err;
6295}
6296
6297static int nl80211_stop_sched_scan(struct sk_buff *skb,
6298 struct genl_info *info)
6299{
6300 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6301
6302 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
6303 !rdev->ops->sched_scan_stop)
6304 return -EOPNOTSUPP;
6305
5fe231e8 6306 return __cfg80211_stop_sched_scan(rdev, false);
807f8a8c
LC
6307}
6308
04f39047
SW
6309static int nl80211_start_radar_detection(struct sk_buff *skb,
6310 struct genl_info *info)
6311{
6312 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6313 struct net_device *dev = info->user_ptr[1];
6314 struct wireless_dev *wdev = dev->ieee80211_ptr;
6315 struct cfg80211_chan_def chandef;
55f7435c 6316 enum nl80211_dfs_regions dfs_region;
31559f35 6317 unsigned int cac_time_ms;
04f39047
SW
6318 int err;
6319
55f7435c
LR
6320 dfs_region = reg_get_dfs_region(wdev->wiphy);
6321 if (dfs_region == NL80211_DFS_UNSET)
6322 return -EINVAL;
6323
04f39047
SW
6324 err = nl80211_parse_chandef(rdev, info, &chandef);
6325 if (err)
6326 return err;
6327
ff311bc1
SW
6328 if (netif_carrier_ok(dev))
6329 return -EBUSY;
6330
04f39047
SW
6331 if (wdev->cac_started)
6332 return -EBUSY;
6333
2beb6dab 6334 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef,
00ec75fc 6335 wdev->iftype);
04f39047
SW
6336 if (err < 0)
6337 return err;
6338
6339 if (err == 0)
6340 return -EINVAL;
6341
fe7c3a1f 6342 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef))
04f39047
SW
6343 return -EINVAL;
6344
6345 if (!rdev->ops->start_radar_detection)
6346 return -EOPNOTSUPP;
6347
31559f35
JD
6348 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef);
6349 if (WARN_ON(!cac_time_ms))
6350 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
6351
6352 err = rdev->ops->start_radar_detection(&rdev->wiphy, dev, &chandef,
6353 cac_time_ms);
04f39047 6354 if (!err) {
9e0e2961 6355 wdev->chandef = chandef;
04f39047
SW
6356 wdev->cac_started = true;
6357 wdev->cac_start_time = jiffies;
31559f35 6358 wdev->cac_time_ms = cac_time_ms;
04f39047 6359 }
04f39047
SW
6360 return err;
6361}
6362
16ef1fe2
SW
6363static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
6364{
6365 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6366 struct net_device *dev = info->user_ptr[1];
6367 struct wireless_dev *wdev = dev->ieee80211_ptr;
6368 struct cfg80211_csa_settings params;
6369 /* csa_attrs is defined static to avoid waste of stack size - this
6370 * function is called under RTNL lock, so this should not be a problem.
6371 */
6372 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
16ef1fe2 6373 int err;
ee4bc9e7 6374 bool need_new_beacon = false;
9a774c78 6375 int len, i;
252e07ca 6376 u32 cs_count;
16ef1fe2
SW
6377
6378 if (!rdev->ops->channel_switch ||
6379 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
6380 return -EOPNOTSUPP;
6381
ee4bc9e7
SW
6382 switch (dev->ieee80211_ptr->iftype) {
6383 case NL80211_IFTYPE_AP:
6384 case NL80211_IFTYPE_P2P_GO:
6385 need_new_beacon = true;
6386
6387 /* useless if AP is not running */
6388 if (!wdev->beacon_interval)
1ff79dfa 6389 return -ENOTCONN;
ee4bc9e7
SW
6390 break;
6391 case NL80211_IFTYPE_ADHOC:
1ff79dfa
JB
6392 if (!wdev->ssid_len)
6393 return -ENOTCONN;
6394 break;
c6da674a 6395 case NL80211_IFTYPE_MESH_POINT:
1ff79dfa
JB
6396 if (!wdev->mesh_id_len)
6397 return -ENOTCONN;
ee4bc9e7
SW
6398 break;
6399 default:
16ef1fe2 6400 return -EOPNOTSUPP;
ee4bc9e7 6401 }
16ef1fe2
SW
6402
6403 memset(&params, 0, sizeof(params));
6404
6405 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6406 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
6407 return -EINVAL;
6408
6409 /* only important for AP, IBSS and mesh create IEs internally */
d0a361a5 6410 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
16ef1fe2
SW
6411 return -EINVAL;
6412
252e07ca
LC
6413 /* Even though the attribute is u32, the specification says
6414 * u8, so let's make sure we don't overflow.
6415 */
6416 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
6417 if (cs_count > 255)
6418 return -EINVAL;
6419
6420 params.count = cs_count;
16ef1fe2 6421
ee4bc9e7
SW
6422 if (!need_new_beacon)
6423 goto skip_beacons;
6424
16ef1fe2
SW
6425 err = nl80211_parse_beacon(info->attrs, &params.beacon_after);
6426 if (err)
6427 return err;
6428
6429 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX,
6430 info->attrs[NL80211_ATTR_CSA_IES],
6431 nl80211_policy);
6432 if (err)
6433 return err;
6434
6435 err = nl80211_parse_beacon(csa_attrs, &params.beacon_csa);
6436 if (err)
6437 return err;
6438
6439 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
6440 return -EINVAL;
6441
9a774c78
AO
6442 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
6443 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
6444 return -EINVAL;
6445
9a774c78
AO
6446 params.n_counter_offsets_beacon = len / sizeof(u16);
6447 if (rdev->wiphy.max_num_csa_counters &&
6448 (params.n_counter_offsets_beacon >
6449 rdev->wiphy.max_num_csa_counters))
16ef1fe2
SW
6450 return -EINVAL;
6451
9a774c78
AO
6452 params.counter_offsets_beacon =
6453 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
6454
6455 /* sanity checks - counters should fit and be the same */
6456 for (i = 0; i < params.n_counter_offsets_beacon; i++) {
6457 u16 offset = params.counter_offsets_beacon[i];
6458
6459 if (offset >= params.beacon_csa.tail_len)
6460 return -EINVAL;
6461
6462 if (params.beacon_csa.tail[offset] != params.count)
6463 return -EINVAL;
6464 }
6465
16ef1fe2 6466 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
9a774c78
AO
6467 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
6468 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
6469 return -EINVAL;
6470
9a774c78
AO
6471 params.n_counter_offsets_presp = len / sizeof(u16);
6472 if (rdev->wiphy.max_num_csa_counters &&
6473 (params.n_counter_offsets_beacon >
6474 rdev->wiphy.max_num_csa_counters))
16ef1fe2 6475 return -EINVAL;
9a774c78
AO
6476
6477 params.counter_offsets_presp =
6478 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
6479
6480 /* sanity checks - counters should fit and be the same */
6481 for (i = 0; i < params.n_counter_offsets_presp; i++) {
6482 u16 offset = params.counter_offsets_presp[i];
6483
6484 if (offset >= params.beacon_csa.probe_resp_len)
6485 return -EINVAL;
6486
6487 if (params.beacon_csa.probe_resp[offset] !=
6488 params.count)
6489 return -EINVAL;
6490 }
16ef1fe2
SW
6491 }
6492
ee4bc9e7 6493skip_beacons:
16ef1fe2
SW
6494 err = nl80211_parse_chandef(rdev, info, &params.chandef);
6495 if (err)
6496 return err;
6497
923b352f
AN
6498 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
6499 wdev->iftype))
16ef1fe2
SW
6500 return -EINVAL;
6501
2beb6dab
LC
6502 err = cfg80211_chandef_dfs_required(wdev->wiphy,
6503 &params.chandef,
6504 wdev->iftype);
6505 if (err < 0)
6506 return err;
6507
dcc6c2f5 6508 if (err > 0)
2beb6dab 6509 params.radar_required = true;
16ef1fe2 6510
16ef1fe2
SW
6511 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
6512 params.block_tx = true;
6513
c56589ed
SW
6514 wdev_lock(wdev);
6515 err = rdev_channel_switch(rdev, dev, &params);
6516 wdev_unlock(wdev);
6517
6518 return err;
16ef1fe2
SW
6519}
6520
9720bb3a
JB
6521static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
6522 u32 seq, int flags,
2a519311 6523 struct cfg80211_registered_device *rdev,
48ab905d
JB
6524 struct wireless_dev *wdev,
6525 struct cfg80211_internal_bss *intbss)
2a519311 6526{
48ab905d 6527 struct cfg80211_bss *res = &intbss->pub;
9caf0364 6528 const struct cfg80211_bss_ies *ies;
2a519311
JB
6529 void *hdr;
6530 struct nlattr *bss;
48ab905d
JB
6531
6532 ASSERT_WDEV_LOCK(wdev);
2a519311 6533
15e47304 6534 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
6535 NL80211_CMD_NEW_SCAN_RESULTS);
6536 if (!hdr)
6537 return -1;
6538
9720bb3a
JB
6539 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
6540
97990a06
JB
6541 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
6542 goto nla_put_failure;
6543 if (wdev->netdev &&
9360ffd1
DM
6544 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
6545 goto nla_put_failure;
97990a06
JB
6546 if (nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
6547 goto nla_put_failure;
2a519311
JB
6548
6549 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
6550 if (!bss)
6551 goto nla_put_failure;
9360ffd1 6552 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 6553 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 6554 goto nla_put_failure;
9caf0364
JB
6555
6556 rcu_read_lock();
0e227084
JB
6557 /* indicate whether we have probe response data or not */
6558 if (rcu_access_pointer(res->proberesp_ies) &&
6559 nla_put_flag(msg, NL80211_BSS_PRESP_DATA))
6560 goto fail_unlock_rcu;
6561
6562 /* this pointer prefers to be pointed to probe response data
6563 * but is always valid
6564 */
9caf0364 6565 ies = rcu_dereference(res->ies);
8cef2c9d
JB
6566 if (ies) {
6567 if (nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
6568 goto fail_unlock_rcu;
8cef2c9d
JB
6569 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
6570 ies->len, ies->data))
6571 goto fail_unlock_rcu;
9caf0364 6572 }
0e227084
JB
6573
6574 /* and this pointer is always (unless driver didn't know) beacon data */
9caf0364 6575 ies = rcu_dereference(res->beacon_ies);
0e227084
JB
6576 if (ies && ies->from_beacon) {
6577 if (nla_put_u64(msg, NL80211_BSS_BEACON_TSF, ies->tsf))
8cef2c9d
JB
6578 goto fail_unlock_rcu;
6579 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
6580 ies->len, ies->data))
6581 goto fail_unlock_rcu;
9caf0364
JB
6582 }
6583 rcu_read_unlock();
6584
9360ffd1
DM
6585 if (res->beacon_interval &&
6586 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
6587 goto nla_put_failure;
6588 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
6589 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
dcd6eac1 6590 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
6591 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
6592 jiffies_to_msecs(jiffies - intbss->ts)))
6593 goto nla_put_failure;
2a519311 6594
77965c97 6595 switch (rdev->wiphy.signal_type) {
2a519311 6596 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
6597 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
6598 goto nla_put_failure;
2a519311
JB
6599 break;
6600 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
6601 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
6602 goto nla_put_failure;
2a519311
JB
6603 break;
6604 default:
6605 break;
6606 }
6607
48ab905d 6608 switch (wdev->iftype) {
074ac8df 6609 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 6610 case NL80211_IFTYPE_STATION:
9360ffd1
DM
6611 if (intbss == wdev->current_bss &&
6612 nla_put_u32(msg, NL80211_BSS_STATUS,
6613 NL80211_BSS_STATUS_ASSOCIATED))
6614 goto nla_put_failure;
48ab905d
JB
6615 break;
6616 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
6617 if (intbss == wdev->current_bss &&
6618 nla_put_u32(msg, NL80211_BSS_STATUS,
6619 NL80211_BSS_STATUS_IBSS_JOINED))
6620 goto nla_put_failure;
48ab905d
JB
6621 break;
6622 default:
6623 break;
6624 }
6625
2a519311
JB
6626 nla_nest_end(msg, bss);
6627
053c095a
JB
6628 genlmsg_end(msg, hdr);
6629 return 0;
2a519311 6630
8cef2c9d
JB
6631 fail_unlock_rcu:
6632 rcu_read_unlock();
2a519311
JB
6633 nla_put_failure:
6634 genlmsg_cancel(msg, hdr);
6635 return -EMSGSIZE;
6636}
6637
97990a06 6638static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 6639{
48ab905d 6640 struct cfg80211_registered_device *rdev;
2a519311 6641 struct cfg80211_internal_bss *scan;
48ab905d 6642 struct wireless_dev *wdev;
97990a06 6643 int start = cb->args[2], idx = 0;
2a519311
JB
6644 int err;
6645
97990a06 6646 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
6647 if (err)
6648 return err;
2a519311 6649
48ab905d
JB
6650 wdev_lock(wdev);
6651 spin_lock_bh(&rdev->bss_lock);
6652 cfg80211_bss_expire(rdev);
6653
9720bb3a
JB
6654 cb->seq = rdev->bss_generation;
6655
48ab905d 6656 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
6657 if (++idx <= start)
6658 continue;
9720bb3a 6659 if (nl80211_send_bss(skb, cb,
2a519311 6660 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 6661 rdev, wdev, scan) < 0) {
2a519311 6662 idx--;
67748893 6663 break;
2a519311
JB
6664 }
6665 }
6666
48ab905d
JB
6667 spin_unlock_bh(&rdev->bss_lock);
6668 wdev_unlock(wdev);
2a519311 6669
97990a06
JB
6670 cb->args[2] = idx;
6671 nl80211_finish_wdev_dump(rdev);
2a519311 6672
67748893 6673 return skb->len;
2a519311
JB
6674}
6675
15e47304 6676static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
11f78ac3
JB
6677 int flags, struct net_device *dev,
6678 bool allow_radio_stats,
6679 struct survey_info *survey)
61fa713c
HS
6680{
6681 void *hdr;
6682 struct nlattr *infoattr;
6683
11f78ac3
JB
6684 /* skip radio stats if userspace didn't request them */
6685 if (!survey->channel && !allow_radio_stats)
6686 return 0;
6687
15e47304 6688 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
6689 NL80211_CMD_NEW_SURVEY_RESULTS);
6690 if (!hdr)
6691 return -ENOMEM;
6692
9360ffd1
DM
6693 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
6694 goto nla_put_failure;
61fa713c
HS
6695
6696 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
6697 if (!infoattr)
6698 goto nla_put_failure;
6699
11f78ac3
JB
6700 if (survey->channel &&
6701 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
9360ffd1
DM
6702 survey->channel->center_freq))
6703 goto nla_put_failure;
6704
6705 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
6706 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
6707 goto nla_put_failure;
6708 if ((survey->filled & SURVEY_INFO_IN_USE) &&
6709 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
6710 goto nla_put_failure;
4ed20beb
JB
6711 if ((survey->filled & SURVEY_INFO_TIME) &&
6712 nla_put_u64(msg, NL80211_SURVEY_INFO_TIME,
6713 survey->time))
9360ffd1 6714 goto nla_put_failure;
4ed20beb
JB
6715 if ((survey->filled & SURVEY_INFO_TIME_BUSY) &&
6716 nla_put_u64(msg, NL80211_SURVEY_INFO_TIME_BUSY,
6717 survey->time_busy))
9360ffd1 6718 goto nla_put_failure;
4ed20beb
JB
6719 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) &&
6720 nla_put_u64(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY,
6721 survey->time_ext_busy))
9360ffd1 6722 goto nla_put_failure;
4ed20beb
JB
6723 if ((survey->filled & SURVEY_INFO_TIME_RX) &&
6724 nla_put_u64(msg, NL80211_SURVEY_INFO_TIME_RX,
6725 survey->time_rx))
9360ffd1 6726 goto nla_put_failure;
4ed20beb
JB
6727 if ((survey->filled & SURVEY_INFO_TIME_TX) &&
6728 nla_put_u64(msg, NL80211_SURVEY_INFO_TIME_TX,
6729 survey->time_tx))
9360ffd1 6730 goto nla_put_failure;
052536ab
JB
6731 if ((survey->filled & SURVEY_INFO_TIME_SCAN) &&
6732 nla_put_u64(msg, NL80211_SURVEY_INFO_TIME_SCAN,
6733 survey->time_scan))
6734 goto nla_put_failure;
61fa713c
HS
6735
6736 nla_nest_end(msg, infoattr);
6737
053c095a
JB
6738 genlmsg_end(msg, hdr);
6739 return 0;
61fa713c
HS
6740
6741 nla_put_failure:
6742 genlmsg_cancel(msg, hdr);
6743 return -EMSGSIZE;
6744}
6745
11f78ac3 6746static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb)
61fa713c
HS
6747{
6748 struct survey_info survey;
1b8ec87a 6749 struct cfg80211_registered_device *rdev;
97990a06
JB
6750 struct wireless_dev *wdev;
6751 int survey_idx = cb->args[2];
61fa713c 6752 int res;
11f78ac3 6753 bool radio_stats;
61fa713c 6754
1b8ec87a 6755 res = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
6756 if (res)
6757 return res;
61fa713c 6758
11f78ac3
JB
6759 /* prepare_wdev_dump parsed the attributes */
6760 radio_stats = nl80211_fam.attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS];
6761
97990a06
JB
6762 if (!wdev->netdev) {
6763 res = -EINVAL;
6764 goto out_err;
6765 }
6766
1b8ec87a 6767 if (!rdev->ops->dump_survey) {
61fa713c
HS
6768 res = -EOPNOTSUPP;
6769 goto out_err;
6770 }
6771
6772 while (1) {
1b8ec87a 6773 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
6774 if (res == -ENOENT)
6775 break;
6776 if (res)
6777 goto out_err;
6778
11f78ac3
JB
6779 /* don't send disabled channels, but do send non-channel data */
6780 if (survey.channel &&
6781 survey.channel->flags & IEEE80211_CHAN_DISABLED) {
180cdc79
LR
6782 survey_idx++;
6783 continue;
6784 }
6785
61fa713c 6786 if (nl80211_send_survey(skb,
15e47304 6787 NETLINK_CB(cb->skb).portid,
61fa713c 6788 cb->nlh->nlmsg_seq, NLM_F_MULTI,
11f78ac3 6789 wdev->netdev, radio_stats, &survey) < 0)
61fa713c
HS
6790 goto out;
6791 survey_idx++;
6792 }
6793
6794 out:
97990a06 6795 cb->args[2] = survey_idx;
61fa713c
HS
6796 res = skb->len;
6797 out_err:
1b8ec87a 6798 nl80211_finish_wdev_dump(rdev);
61fa713c
HS
6799 return res;
6800}
6801
b23aa676
SO
6802static bool nl80211_valid_wpa_versions(u32 wpa_versions)
6803{
6804 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
6805 NL80211_WPA_VERSION_2));
6806}
6807
636a5d36
JM
6808static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
6809{
4c476991
JB
6810 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6811 struct net_device *dev = info->user_ptr[1];
19957bb3 6812 struct ieee80211_channel *chan;
e39e5b5e
JM
6813 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
6814 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 6815 enum nl80211_auth_type auth_type;
fffd0934 6816 struct key_parse key;
d5cdfacb 6817 bool local_state_change;
636a5d36 6818
f4a11bb0
JB
6819 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6820 return -EINVAL;
6821
6822 if (!info->attrs[NL80211_ATTR_MAC])
6823 return -EINVAL;
6824
1778092e
JM
6825 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
6826 return -EINVAL;
6827
19957bb3
JB
6828 if (!info->attrs[NL80211_ATTR_SSID])
6829 return -EINVAL;
6830
6831 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
6832 return -EINVAL;
6833
fffd0934
JB
6834 err = nl80211_parse_key(info, &key);
6835 if (err)
6836 return err;
6837
6838 if (key.idx >= 0) {
e31b8213
JB
6839 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
6840 return -EINVAL;
fffd0934
JB
6841 if (!key.p.key || !key.p.key_len)
6842 return -EINVAL;
6843 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
6844 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
6845 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
6846 key.p.key_len != WLAN_KEY_LEN_WEP104))
6847 return -EINVAL;
6848 if (key.idx > 4)
6849 return -EINVAL;
6850 } else {
6851 key.p.key_len = 0;
6852 key.p.key = NULL;
6853 }
6854
afea0b7a
JB
6855 if (key.idx >= 0) {
6856 int i;
6857 bool ok = false;
6858 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
6859 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
6860 ok = true;
6861 break;
6862 }
6863 }
4c476991
JB
6864 if (!ok)
6865 return -EINVAL;
afea0b7a
JB
6866 }
6867
4c476991
JB
6868 if (!rdev->ops->auth)
6869 return -EOPNOTSUPP;
636a5d36 6870
074ac8df 6871 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6872 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6873 return -EOPNOTSUPP;
eec60b03 6874
19957bb3 6875 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
664834de
JM
6876 chan = nl80211_get_valid_chan(&rdev->wiphy,
6877 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
6878 if (!chan)
4c476991 6879 return -EINVAL;
636a5d36 6880
19957bb3
JB
6881 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6882 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
6883
6884 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6885 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6886 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6887 }
6888
19957bb3 6889 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 6890 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 6891 return -EINVAL;
636a5d36 6892
e39e5b5e
JM
6893 if (auth_type == NL80211_AUTHTYPE_SAE &&
6894 !info->attrs[NL80211_ATTR_SAE_DATA])
6895 return -EINVAL;
6896
6897 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
6898 if (auth_type != NL80211_AUTHTYPE_SAE)
6899 return -EINVAL;
6900 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
6901 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
6902 /* need to include at least Auth Transaction and Status Code */
6903 if (sae_data_len < 4)
6904 return -EINVAL;
6905 }
6906
d5cdfacb
JM
6907 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6908
95de817b
JB
6909 /*
6910 * Since we no longer track auth state, ignore
6911 * requests to only change local state.
6912 */
6913 if (local_state_change)
6914 return 0;
6915
91bf9b26
JB
6916 wdev_lock(dev->ieee80211_ptr);
6917 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
6918 ssid, ssid_len, ie, ie_len,
6919 key.p.key, key.p.key_len, key.idx,
6920 sae_data, sae_data_len);
6921 wdev_unlock(dev->ieee80211_ptr);
6922 return err;
636a5d36
JM
6923}
6924
c0692b8f
JB
6925static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
6926 struct genl_info *info,
3dc27d25
JB
6927 struct cfg80211_crypto_settings *settings,
6928 int cipher_limit)
b23aa676 6929{
c0b2bbd8
JB
6930 memset(settings, 0, sizeof(*settings));
6931
b23aa676
SO
6932 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
6933
c0692b8f
JB
6934 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
6935 u16 proto;
6936 proto = nla_get_u16(
6937 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
6938 settings->control_port_ethertype = cpu_to_be16(proto);
6939 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
6940 proto != ETH_P_PAE)
6941 return -EINVAL;
6942 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
6943 settings->control_port_no_encrypt = true;
6944 } else
6945 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
6946
b23aa676
SO
6947 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
6948 void *data;
6949 int len, i;
6950
6951 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
6952 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
6953 settings->n_ciphers_pairwise = len / sizeof(u32);
6954
6955 if (len % sizeof(u32))
6956 return -EINVAL;
6957
3dc27d25 6958 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
6959 return -EINVAL;
6960
6961 memcpy(settings->ciphers_pairwise, data, len);
6962
6963 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
6964 if (!cfg80211_supported_cipher_suite(
6965 &rdev->wiphy,
b23aa676
SO
6966 settings->ciphers_pairwise[i]))
6967 return -EINVAL;
6968 }
6969
6970 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
6971 settings->cipher_group =
6972 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
6973 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
6974 settings->cipher_group))
b23aa676
SO
6975 return -EINVAL;
6976 }
6977
6978 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
6979 settings->wpa_versions =
6980 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
6981 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
6982 return -EINVAL;
6983 }
6984
6985 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
6986 void *data;
6d30240e 6987 int len;
b23aa676
SO
6988
6989 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
6990 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
6991 settings->n_akm_suites = len / sizeof(u32);
6992
6993 if (len % sizeof(u32))
6994 return -EINVAL;
6995
1b9ca027
JM
6996 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
6997 return -EINVAL;
6998
b23aa676 6999 memcpy(settings->akm_suites, data, len);
b23aa676
SO
7000 }
7001
7002 return 0;
7003}
7004
636a5d36
JM
7005static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
7006{
4c476991
JB
7007 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7008 struct net_device *dev = info->user_ptr[1];
f444de05 7009 struct ieee80211_channel *chan;
f62fab73
JB
7010 struct cfg80211_assoc_request req = {};
7011 const u8 *bssid, *ssid;
7012 int err, ssid_len = 0;
636a5d36 7013
f4a11bb0
JB
7014 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7015 return -EINVAL;
7016
7017 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
7018 !info->attrs[NL80211_ATTR_SSID] ||
7019 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
7020 return -EINVAL;
7021
4c476991
JB
7022 if (!rdev->ops->assoc)
7023 return -EOPNOTSUPP;
636a5d36 7024
074ac8df 7025 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7026 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7027 return -EOPNOTSUPP;
eec60b03 7028
19957bb3 7029 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 7030
664834de
JM
7031 chan = nl80211_get_valid_chan(&rdev->wiphy,
7032 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
7033 if (!chan)
4c476991 7034 return -EINVAL;
636a5d36 7035
19957bb3
JB
7036 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
7037 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
7038
7039 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
7040 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7041 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
7042 }
7043
dc6382ce 7044 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 7045 enum nl80211_mfp mfp =
dc6382ce 7046 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 7047 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 7048 req.use_mfp = true;
4c476991
JB
7049 else if (mfp != NL80211_MFP_NO)
7050 return -EINVAL;
dc6382ce
JM
7051 }
7052
3e5d7649 7053 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 7054 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 7055
7e7c8926 7056 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 7057 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
7058
7059 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
7060 memcpy(&req.ht_capa_mask,
7061 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
7062 sizeof(req.ht_capa_mask));
7e7c8926
BG
7063
7064 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 7065 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 7066 return -EINVAL;
f62fab73
JB
7067 memcpy(&req.ht_capa,
7068 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
7069 sizeof(req.ht_capa));
7e7c8926
BG
7070 }
7071
ee2aca34 7072 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 7073 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
7074
7075 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
7076 memcpy(&req.vht_capa_mask,
7077 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
7078 sizeof(req.vht_capa_mask));
ee2aca34
JB
7079
7080 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 7081 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 7082 return -EINVAL;
f62fab73
JB
7083 memcpy(&req.vht_capa,
7084 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
7085 sizeof(req.vht_capa));
ee2aca34
JB
7086 }
7087
bab5ab7d
AK
7088 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
7089 if (!(rdev->wiphy.features &
7090 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) ||
7091 !(rdev->wiphy.features & NL80211_FEATURE_QUIET))
7092 return -EINVAL;
7093 req.flags |= ASSOC_REQ_USE_RRM;
7094 }
7095
f62fab73 7096 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
7097 if (!err) {
7098 wdev_lock(dev->ieee80211_ptr);
f62fab73
JB
7099 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
7100 ssid, ssid_len, &req);
91bf9b26
JB
7101 wdev_unlock(dev->ieee80211_ptr);
7102 }
636a5d36 7103
636a5d36
JM
7104 return err;
7105}
7106
7107static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
7108{
4c476991
JB
7109 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7110 struct net_device *dev = info->user_ptr[1];
19957bb3 7111 const u8 *ie = NULL, *bssid;
91bf9b26 7112 int ie_len = 0, err;
19957bb3 7113 u16 reason_code;
d5cdfacb 7114 bool local_state_change;
636a5d36 7115
f4a11bb0
JB
7116 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7117 return -EINVAL;
7118
7119 if (!info->attrs[NL80211_ATTR_MAC])
7120 return -EINVAL;
7121
7122 if (!info->attrs[NL80211_ATTR_REASON_CODE])
7123 return -EINVAL;
7124
4c476991
JB
7125 if (!rdev->ops->deauth)
7126 return -EOPNOTSUPP;
636a5d36 7127
074ac8df 7128 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7129 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7130 return -EOPNOTSUPP;
eec60b03 7131
19957bb3 7132 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 7133
19957bb3
JB
7134 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
7135 if (reason_code == 0) {
f4a11bb0 7136 /* Reason Code 0 is reserved */
4c476991 7137 return -EINVAL;
255e737e 7138 }
636a5d36
JM
7139
7140 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
7141 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7142 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
7143 }
7144
d5cdfacb
JM
7145 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
7146
91bf9b26
JB
7147 wdev_lock(dev->ieee80211_ptr);
7148 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
7149 local_state_change);
7150 wdev_unlock(dev->ieee80211_ptr);
7151 return err;
636a5d36
JM
7152}
7153
7154static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
7155{
4c476991
JB
7156 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7157 struct net_device *dev = info->user_ptr[1];
19957bb3 7158 const u8 *ie = NULL, *bssid;
91bf9b26 7159 int ie_len = 0, err;
19957bb3 7160 u16 reason_code;
d5cdfacb 7161 bool local_state_change;
636a5d36 7162
f4a11bb0
JB
7163 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7164 return -EINVAL;
7165
7166 if (!info->attrs[NL80211_ATTR_MAC])
7167 return -EINVAL;
7168
7169 if (!info->attrs[NL80211_ATTR_REASON_CODE])
7170 return -EINVAL;
7171
4c476991
JB
7172 if (!rdev->ops->disassoc)
7173 return -EOPNOTSUPP;
636a5d36 7174
074ac8df 7175 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7176 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7177 return -EOPNOTSUPP;
eec60b03 7178
19957bb3 7179 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 7180
19957bb3
JB
7181 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
7182 if (reason_code == 0) {
f4a11bb0 7183 /* Reason Code 0 is reserved */
4c476991 7184 return -EINVAL;
255e737e 7185 }
636a5d36
JM
7186
7187 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
7188 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7189 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
7190 }
7191
d5cdfacb
JM
7192 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
7193
91bf9b26
JB
7194 wdev_lock(dev->ieee80211_ptr);
7195 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
7196 local_state_change);
7197 wdev_unlock(dev->ieee80211_ptr);
7198 return err;
636a5d36
JM
7199}
7200
dd5b4cc7
FF
7201static bool
7202nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
7203 int mcast_rate[IEEE80211_NUM_BANDS],
7204 int rateval)
7205{
7206 struct wiphy *wiphy = &rdev->wiphy;
7207 bool found = false;
7208 int band, i;
7209
7210 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
7211 struct ieee80211_supported_band *sband;
7212
7213 sband = wiphy->bands[band];
7214 if (!sband)
7215 continue;
7216
7217 for (i = 0; i < sband->n_bitrates; i++) {
7218 if (sband->bitrates[i].bitrate == rateval) {
7219 mcast_rate[band] = i + 1;
7220 found = true;
7221 break;
7222 }
7223 }
7224 }
7225
7226 return found;
7227}
7228
04a773ad
JB
7229static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
7230{
4c476991
JB
7231 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7232 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
7233 struct cfg80211_ibss_params ibss;
7234 struct wiphy *wiphy;
fffd0934 7235 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
7236 int err;
7237
8e30bc55
JB
7238 memset(&ibss, 0, sizeof(ibss));
7239
04a773ad
JB
7240 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7241 return -EINVAL;
7242
683b6d3b 7243 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
7244 !nla_len(info->attrs[NL80211_ATTR_SSID]))
7245 return -EINVAL;
7246
8e30bc55
JB
7247 ibss.beacon_interval = 100;
7248
7249 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
7250 ibss.beacon_interval =
7251 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
7252 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
7253 return -EINVAL;
7254 }
7255
4c476991
JB
7256 if (!rdev->ops->join_ibss)
7257 return -EOPNOTSUPP;
04a773ad 7258
4c476991
JB
7259 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
7260 return -EOPNOTSUPP;
04a773ad 7261
79c97e97 7262 wiphy = &rdev->wiphy;
04a773ad 7263
39193498 7264 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 7265 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
7266
7267 if (!is_valid_ether_addr(ibss.bssid))
7268 return -EINVAL;
7269 }
04a773ad
JB
7270 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
7271 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
7272
7273 if (info->attrs[NL80211_ATTR_IE]) {
7274 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7275 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
7276 }
7277
683b6d3b
JB
7278 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
7279 if (err)
7280 return err;
04a773ad 7281
174e0cd2
IP
7282 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef,
7283 NL80211_IFTYPE_ADHOC))
54858ee5
AS
7284 return -EINVAL;
7285
2f301ab2 7286 switch (ibss.chandef.width) {
bf372645
SW
7287 case NL80211_CHAN_WIDTH_5:
7288 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
7289 case NL80211_CHAN_WIDTH_20_NOHT:
7290 break;
7291 case NL80211_CHAN_WIDTH_20:
7292 case NL80211_CHAN_WIDTH_40:
ffc11991
JD
7293 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
7294 return -EINVAL;
7295 break;
7296 case NL80211_CHAN_WIDTH_80:
7297 case NL80211_CHAN_WIDTH_80P80:
7298 case NL80211_CHAN_WIDTH_160:
7299 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
7300 return -EINVAL;
7301 if (!wiphy_ext_feature_isset(&rdev->wiphy,
7302 NL80211_EXT_FEATURE_VHT_IBSS))
7303 return -EINVAL;
7304 break;
2f301ab2 7305 default:
c04d6150 7306 return -EINVAL;
2f301ab2 7307 }
db9c64cf 7308
04a773ad 7309 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
7310 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
7311
fbd2c8dc
TP
7312 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
7313 u8 *rates =
7314 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7315 int n_rates =
7316 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7317 struct ieee80211_supported_band *sband =
683b6d3b 7318 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 7319
34850ab2
JB
7320 err = ieee80211_get_ratemask(sband, rates, n_rates,
7321 &ibss.basic_rates);
7322 if (err)
7323 return err;
fbd2c8dc 7324 }
dd5b4cc7 7325
803768f5
SW
7326 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7327 memcpy(&ibss.ht_capa_mask,
7328 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
7329 sizeof(ibss.ht_capa_mask));
7330
7331 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
7332 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7333 return -EINVAL;
7334 memcpy(&ibss.ht_capa,
7335 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
7336 sizeof(ibss.ht_capa));
7337 }
7338
dd5b4cc7
FF
7339 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
7340 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
7341 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
7342 return -EINVAL;
fbd2c8dc 7343
4c476991 7344 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
7345 bool no_ht = false;
7346
4c476991 7347 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
7348 info->attrs[NL80211_ATTR_KEYS],
7349 &no_ht);
4c476991
JB
7350 if (IS_ERR(connkeys))
7351 return PTR_ERR(connkeys);
de7044ee 7352
3d9d1d66
JB
7353 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
7354 no_ht) {
de7044ee
SM
7355 kfree(connkeys);
7356 return -EINVAL;
7357 }
4c476991 7358 }
04a773ad 7359
267335d6
AQ
7360 ibss.control_port =
7361 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
7362
5336fa88
SW
7363 ibss.userspace_handles_dfs =
7364 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
7365
4c476991 7366 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934 7367 if (err)
b47f610b 7368 kzfree(connkeys);
04a773ad
JB
7369 return err;
7370}
7371
7372static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
7373{
4c476991
JB
7374 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7375 struct net_device *dev = info->user_ptr[1];
04a773ad 7376
4c476991
JB
7377 if (!rdev->ops->leave_ibss)
7378 return -EOPNOTSUPP;
04a773ad 7379
4c476991
JB
7380 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
7381 return -EOPNOTSUPP;
04a773ad 7382
4c476991 7383 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
7384}
7385
f4e583c8
AQ
7386static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
7387{
7388 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7389 struct net_device *dev = info->user_ptr[1];
7390 int mcast_rate[IEEE80211_NUM_BANDS];
7391 u32 nla_rate;
7392 int err;
7393
7394 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
876dc930
BVB
7395 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
7396 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB)
f4e583c8
AQ
7397 return -EOPNOTSUPP;
7398
7399 if (!rdev->ops->set_mcast_rate)
7400 return -EOPNOTSUPP;
7401
7402 memset(mcast_rate, 0, sizeof(mcast_rate));
7403
7404 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
7405 return -EINVAL;
7406
7407 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
7408 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
7409 return -EINVAL;
7410
7411 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
7412
7413 return err;
7414}
7415
ad7e718c
JB
7416static struct sk_buff *
7417__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
6c09e791
AK
7418 struct wireless_dev *wdev, int approxlen,
7419 u32 portid, u32 seq, enum nl80211_commands cmd,
567ffc35
JB
7420 enum nl80211_attrs attr,
7421 const struct nl80211_vendor_cmd_info *info,
7422 gfp_t gfp)
ad7e718c
JB
7423{
7424 struct sk_buff *skb;
7425 void *hdr;
7426 struct nlattr *data;
7427
7428 skb = nlmsg_new(approxlen + 100, gfp);
7429 if (!skb)
7430 return NULL;
7431
7432 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
7433 if (!hdr) {
7434 kfree_skb(skb);
7435 return NULL;
7436 }
7437
7438 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
7439 goto nla_put_failure;
567ffc35
JB
7440
7441 if (info) {
7442 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
7443 info->vendor_id))
7444 goto nla_put_failure;
7445 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
7446 info->subcmd))
7447 goto nla_put_failure;
7448 }
7449
6c09e791
AK
7450 if (wdev) {
7451 if (nla_put_u64(skb, NL80211_ATTR_WDEV,
7452 wdev_id(wdev)))
7453 goto nla_put_failure;
7454 if (wdev->netdev &&
7455 nla_put_u32(skb, NL80211_ATTR_IFINDEX,
7456 wdev->netdev->ifindex))
7457 goto nla_put_failure;
7458 }
7459
ad7e718c
JB
7460 data = nla_nest_start(skb, attr);
7461
7462 ((void **)skb->cb)[0] = rdev;
7463 ((void **)skb->cb)[1] = hdr;
7464 ((void **)skb->cb)[2] = data;
7465
7466 return skb;
7467
7468 nla_put_failure:
7469 kfree_skb(skb);
7470 return NULL;
7471}
f4e583c8 7472
e03ad6ea 7473struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
6c09e791 7474 struct wireless_dev *wdev,
e03ad6ea
JB
7475 enum nl80211_commands cmd,
7476 enum nl80211_attrs attr,
7477 int vendor_event_idx,
7478 int approxlen, gfp_t gfp)
7479{
f26cbf40 7480 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
e03ad6ea
JB
7481 const struct nl80211_vendor_cmd_info *info;
7482
7483 switch (cmd) {
7484 case NL80211_CMD_TESTMODE:
7485 if (WARN_ON(vendor_event_idx != -1))
7486 return NULL;
7487 info = NULL;
7488 break;
7489 case NL80211_CMD_VENDOR:
7490 if (WARN_ON(vendor_event_idx < 0 ||
7491 vendor_event_idx >= wiphy->n_vendor_events))
7492 return NULL;
7493 info = &wiphy->vendor_events[vendor_event_idx];
7494 break;
7495 default:
7496 WARN_ON(1);
7497 return NULL;
7498 }
7499
6c09e791 7500 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, 0, 0,
e03ad6ea
JB
7501 cmd, attr, info, gfp);
7502}
7503EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
7504
7505void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
7506{
7507 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
7508 void *hdr = ((void **)skb->cb)[1];
7509 struct nlattr *data = ((void **)skb->cb)[2];
7510 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
7511
bd8c78e7
JB
7512 /* clear CB data for netlink core to own from now on */
7513 memset(skb->cb, 0, sizeof(skb->cb));
7514
e03ad6ea
JB
7515 nla_nest_end(skb, data);
7516 genlmsg_end(skb, hdr);
7517
7518 if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
7519 mcgrp = NL80211_MCGRP_VENDOR;
7520
7521 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0,
7522 mcgrp, gfp);
7523}
7524EXPORT_SYMBOL(__cfg80211_send_event_skb);
7525
aff89a9b 7526#ifdef CONFIG_NL80211_TESTMODE
aff89a9b
JB
7527static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
7528{
4c476991 7529 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
7530 struct wireless_dev *wdev =
7531 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
7532 int err;
7533
fc73f11f
DS
7534 if (!rdev->ops->testmode_cmd)
7535 return -EOPNOTSUPP;
7536
7537 if (IS_ERR(wdev)) {
7538 err = PTR_ERR(wdev);
7539 if (err != -EINVAL)
7540 return err;
7541 wdev = NULL;
7542 } else if (wdev->wiphy != &rdev->wiphy) {
7543 return -EINVAL;
7544 }
7545
aff89a9b
JB
7546 if (!info->attrs[NL80211_ATTR_TESTDATA])
7547 return -EINVAL;
7548
ad7e718c 7549 rdev->cur_cmd_info = info;
fc73f11f 7550 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
7551 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
7552 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
ad7e718c 7553 rdev->cur_cmd_info = NULL;
aff89a9b 7554
aff89a9b
JB
7555 return err;
7556}
7557
71063f0e
WYG
7558static int nl80211_testmode_dump(struct sk_buff *skb,
7559 struct netlink_callback *cb)
7560{
00918d33 7561 struct cfg80211_registered_device *rdev;
71063f0e
WYG
7562 int err;
7563 long phy_idx;
7564 void *data = NULL;
7565 int data_len = 0;
7566
5fe231e8
JB
7567 rtnl_lock();
7568
71063f0e
WYG
7569 if (cb->args[0]) {
7570 /*
7571 * 0 is a valid index, but not valid for args[0],
7572 * so we need to offset by 1.
7573 */
7574 phy_idx = cb->args[0] - 1;
7575 } else {
7576 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
7577 nl80211_fam.attrbuf, nl80211_fam.maxattr,
7578 nl80211_policy);
7579 if (err)
5fe231e8 7580 goto out_err;
00918d33 7581
2bd7e35d
JB
7582 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
7583 nl80211_fam.attrbuf);
7584 if (IS_ERR(rdev)) {
5fe231e8
JB
7585 err = PTR_ERR(rdev);
7586 goto out_err;
00918d33 7587 }
2bd7e35d
JB
7588 phy_idx = rdev->wiphy_idx;
7589 rdev = NULL;
2bd7e35d 7590
71063f0e
WYG
7591 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
7592 cb->args[1] =
7593 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
7594 }
7595
7596 if (cb->args[1]) {
7597 data = nla_data((void *)cb->args[1]);
7598 data_len = nla_len((void *)cb->args[1]);
7599 }
7600
00918d33
JB
7601 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
7602 if (!rdev) {
5fe231e8
JB
7603 err = -ENOENT;
7604 goto out_err;
71063f0e 7605 }
71063f0e 7606
00918d33 7607 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
7608 err = -EOPNOTSUPP;
7609 goto out_err;
7610 }
7611
7612 while (1) {
15e47304 7613 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
7614 cb->nlh->nlmsg_seq, NLM_F_MULTI,
7615 NL80211_CMD_TESTMODE);
7616 struct nlattr *tmdata;
7617
cb35fba3
DC
7618 if (!hdr)
7619 break;
7620
9360ffd1 7621 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
7622 genlmsg_cancel(skb, hdr);
7623 break;
7624 }
7625
7626 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
7627 if (!tmdata) {
7628 genlmsg_cancel(skb, hdr);
7629 break;
7630 }
e35e4d28 7631 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
7632 nla_nest_end(skb, tmdata);
7633
7634 if (err == -ENOBUFS || err == -ENOENT) {
7635 genlmsg_cancel(skb, hdr);
7636 break;
7637 } else if (err) {
7638 genlmsg_cancel(skb, hdr);
7639 goto out_err;
7640 }
7641
7642 genlmsg_end(skb, hdr);
7643 }
7644
7645 err = skb->len;
7646 /* see above */
7647 cb->args[0] = phy_idx + 1;
7648 out_err:
5fe231e8 7649 rtnl_unlock();
71063f0e
WYG
7650 return err;
7651}
aff89a9b
JB
7652#endif
7653
b23aa676
SO
7654static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
7655{
4c476991
JB
7656 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7657 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
7658 struct cfg80211_connect_params connect;
7659 struct wiphy *wiphy;
fffd0934 7660 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
7661 int err;
7662
7663 memset(&connect, 0, sizeof(connect));
7664
7665 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7666 return -EINVAL;
7667
7668 if (!info->attrs[NL80211_ATTR_SSID] ||
7669 !nla_len(info->attrs[NL80211_ATTR_SSID]))
7670 return -EINVAL;
7671
7672 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
7673 connect.auth_type =
7674 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
7675 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
7676 NL80211_CMD_CONNECT))
b23aa676
SO
7677 return -EINVAL;
7678 } else
7679 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
7680
7681 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
7682
c0692b8f 7683 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 7684 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
7685 if (err)
7686 return err;
b23aa676 7687
074ac8df 7688 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7689 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7690 return -EOPNOTSUPP;
b23aa676 7691
79c97e97 7692 wiphy = &rdev->wiphy;
b23aa676 7693
4486ea98
BS
7694 connect.bg_scan_period = -1;
7695 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
7696 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
7697 connect.bg_scan_period =
7698 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
7699 }
7700
b23aa676
SO
7701 if (info->attrs[NL80211_ATTR_MAC])
7702 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1df4a510
JM
7703 else if (info->attrs[NL80211_ATTR_MAC_HINT])
7704 connect.bssid_hint =
7705 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
b23aa676
SO
7706 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
7707 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
7708
7709 if (info->attrs[NL80211_ATTR_IE]) {
7710 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7711 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
7712 }
7713
cee00a95
JM
7714 if (info->attrs[NL80211_ATTR_USE_MFP]) {
7715 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
7716 if (connect.mfp != NL80211_MFP_REQUIRED &&
7717 connect.mfp != NL80211_MFP_NO)
7718 return -EINVAL;
7719 } else {
7720 connect.mfp = NL80211_MFP_NO;
7721 }
7722
b23aa676 7723 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
664834de
JM
7724 connect.channel = nl80211_get_valid_chan(
7725 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]);
7726 if (!connect.channel)
1df4a510
JM
7727 return -EINVAL;
7728 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
664834de
JM
7729 connect.channel_hint = nl80211_get_valid_chan(
7730 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
7731 if (!connect.channel_hint)
4c476991 7732 return -EINVAL;
b23aa676
SO
7733 }
7734
fffd0934
JB
7735 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
7736 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 7737 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
7738 if (IS_ERR(connkeys))
7739 return PTR_ERR(connkeys);
fffd0934
JB
7740 }
7741
7e7c8926
BG
7742 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
7743 connect.flags |= ASSOC_REQ_DISABLE_HT;
7744
7745 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7746 memcpy(&connect.ht_capa_mask,
7747 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
7748 sizeof(connect.ht_capa_mask));
7749
7750 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e 7751 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
b47f610b 7752 kzfree(connkeys);
7e7c8926 7753 return -EINVAL;
b4e4f47e 7754 }
7e7c8926
BG
7755 memcpy(&connect.ht_capa,
7756 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
7757 sizeof(connect.ht_capa));
7758 }
7759
ee2aca34
JB
7760 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
7761 connect.flags |= ASSOC_REQ_DISABLE_VHT;
7762
7763 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
7764 memcpy(&connect.vht_capa_mask,
7765 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
7766 sizeof(connect.vht_capa_mask));
7767
7768 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
7769 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
b47f610b 7770 kzfree(connkeys);
ee2aca34
JB
7771 return -EINVAL;
7772 }
7773 memcpy(&connect.vht_capa,
7774 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
7775 sizeof(connect.vht_capa));
7776 }
7777
bab5ab7d
AK
7778 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
7779 if (!(rdev->wiphy.features &
7780 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) ||
7781 !(rdev->wiphy.features & NL80211_FEATURE_QUIET))
7782 return -EINVAL;
7783 connect.flags |= ASSOC_REQ_USE_RRM;
7784 }
7785
83739b03
JB
7786 wdev_lock(dev->ieee80211_ptr);
7787 err = cfg80211_connect(rdev, dev, &connect, connkeys, NULL);
7788 wdev_unlock(dev->ieee80211_ptr);
fffd0934 7789 if (err)
b47f610b 7790 kzfree(connkeys);
b23aa676
SO
7791 return err;
7792}
7793
7794static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
7795{
4c476991
JB
7796 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7797 struct net_device *dev = info->user_ptr[1];
b23aa676 7798 u16 reason;
83739b03 7799 int ret;
b23aa676
SO
7800
7801 if (!info->attrs[NL80211_ATTR_REASON_CODE])
7802 reason = WLAN_REASON_DEAUTH_LEAVING;
7803 else
7804 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
7805
7806 if (reason == 0)
7807 return -EINVAL;
7808
074ac8df 7809 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7810 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7811 return -EOPNOTSUPP;
b23aa676 7812
83739b03
JB
7813 wdev_lock(dev->ieee80211_ptr);
7814 ret = cfg80211_disconnect(rdev, dev, reason, true);
7815 wdev_unlock(dev->ieee80211_ptr);
7816 return ret;
b23aa676
SO
7817}
7818
463d0183
JB
7819static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
7820{
4c476991 7821 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
7822 struct net *net;
7823 int err;
463d0183 7824
4b681c82
VK
7825 if (info->attrs[NL80211_ATTR_PID]) {
7826 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
7827
7828 net = get_net_ns_by_pid(pid);
7829 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) {
7830 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]);
463d0183 7831
4b681c82
VK
7832 net = get_net_ns_by_fd(fd);
7833 } else {
7834 return -EINVAL;
7835 }
463d0183 7836
4c476991
JB
7837 if (IS_ERR(net))
7838 return PTR_ERR(net);
463d0183
JB
7839
7840 err = 0;
7841
7842 /* check if anything to do */
4c476991
JB
7843 if (!net_eq(wiphy_net(&rdev->wiphy), net))
7844 err = cfg80211_switch_netns(rdev, net);
463d0183 7845
463d0183 7846 put_net(net);
463d0183
JB
7847 return err;
7848}
7849
67fbb16b
SO
7850static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
7851{
4c476991 7852 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
7853 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
7854 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 7855 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
7856 struct cfg80211_pmksa pmksa;
7857
7858 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
7859
7860 if (!info->attrs[NL80211_ATTR_MAC])
7861 return -EINVAL;
7862
7863 if (!info->attrs[NL80211_ATTR_PMKID])
7864 return -EINVAL;
7865
67fbb16b
SO
7866 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
7867 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
7868
074ac8df 7869 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7870 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7871 return -EOPNOTSUPP;
67fbb16b
SO
7872
7873 switch (info->genlhdr->cmd) {
7874 case NL80211_CMD_SET_PMKSA:
7875 rdev_ops = rdev->ops->set_pmksa;
7876 break;
7877 case NL80211_CMD_DEL_PMKSA:
7878 rdev_ops = rdev->ops->del_pmksa;
7879 break;
7880 default:
7881 WARN_ON(1);
7882 break;
7883 }
7884
4c476991
JB
7885 if (!rdev_ops)
7886 return -EOPNOTSUPP;
67fbb16b 7887
4c476991 7888 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
7889}
7890
7891static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
7892{
4c476991
JB
7893 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7894 struct net_device *dev = info->user_ptr[1];
67fbb16b 7895
074ac8df 7896 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7897 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7898 return -EOPNOTSUPP;
67fbb16b 7899
4c476991
JB
7900 if (!rdev->ops->flush_pmksa)
7901 return -EOPNOTSUPP;
67fbb16b 7902
e35e4d28 7903 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
7904}
7905
109086ce
AN
7906static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
7907{
7908 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7909 struct net_device *dev = info->user_ptr[1];
7910 u8 action_code, dialog_token;
df942e7b 7911 u32 peer_capability = 0;
109086ce
AN
7912 u16 status_code;
7913 u8 *peer;
31fa97c5 7914 bool initiator;
109086ce
AN
7915
7916 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
7917 !rdev->ops->tdls_mgmt)
7918 return -EOPNOTSUPP;
7919
7920 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
7921 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
7922 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
7923 !info->attrs[NL80211_ATTR_IE] ||
7924 !info->attrs[NL80211_ATTR_MAC])
7925 return -EINVAL;
7926
7927 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
7928 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
7929 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
7930 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
31fa97c5 7931 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]);
df942e7b
SDU
7932 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
7933 peer_capability =
7934 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
109086ce 7935
e35e4d28 7936 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
df942e7b 7937 dialog_token, status_code, peer_capability,
31fa97c5 7938 initiator,
e35e4d28
HG
7939 nla_data(info->attrs[NL80211_ATTR_IE]),
7940 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
7941}
7942
7943static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
7944{
7945 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7946 struct net_device *dev = info->user_ptr[1];
7947 enum nl80211_tdls_operation operation;
7948 u8 *peer;
7949
7950 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
7951 !rdev->ops->tdls_oper)
7952 return -EOPNOTSUPP;
7953
7954 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
7955 !info->attrs[NL80211_ATTR_MAC])
7956 return -EINVAL;
7957
7958 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
7959 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
7960
e35e4d28 7961 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
7962}
7963
9588bbd5
JM
7964static int nl80211_remain_on_channel(struct sk_buff *skb,
7965 struct genl_info *info)
7966{
4c476991 7967 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7968 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 7969 struct cfg80211_chan_def chandef;
9588bbd5
JM
7970 struct sk_buff *msg;
7971 void *hdr;
7972 u64 cookie;
683b6d3b 7973 u32 duration;
9588bbd5
JM
7974 int err;
7975
7976 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
7977 !info->attrs[NL80211_ATTR_DURATION])
7978 return -EINVAL;
7979
7980 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
7981
ebf348fc
JB
7982 if (!rdev->ops->remain_on_channel ||
7983 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
7984 return -EOPNOTSUPP;
7985
9588bbd5 7986 /*
ebf348fc
JB
7987 * We should be on that channel for at least a minimum amount of
7988 * time (10ms) but no longer than the driver supports.
9588bbd5 7989 */
ebf348fc 7990 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 7991 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
7992 return -EINVAL;
7993
683b6d3b
JB
7994 err = nl80211_parse_chandef(rdev, info, &chandef);
7995 if (err)
7996 return err;
9588bbd5
JM
7997
7998 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
7999 if (!msg)
8000 return -ENOMEM;
9588bbd5 8001
15e47304 8002 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 8003 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
8004 if (!hdr) {
8005 err = -ENOBUFS;
9588bbd5
JM
8006 goto free_msg;
8007 }
8008
683b6d3b
JB
8009 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
8010 duration, &cookie);
9588bbd5
JM
8011
8012 if (err)
8013 goto free_msg;
8014
9360ffd1
DM
8015 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8016 goto nla_put_failure;
9588bbd5
JM
8017
8018 genlmsg_end(msg, hdr);
4c476991
JB
8019
8020 return genlmsg_reply(msg, info);
9588bbd5
JM
8021
8022 nla_put_failure:
8023 err = -ENOBUFS;
8024 free_msg:
8025 nlmsg_free(msg);
9588bbd5
JM
8026 return err;
8027}
8028
8029static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
8030 struct genl_info *info)
8031{
4c476991 8032 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 8033 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 8034 u64 cookie;
9588bbd5
JM
8035
8036 if (!info->attrs[NL80211_ATTR_COOKIE])
8037 return -EINVAL;
8038
4c476991
JB
8039 if (!rdev->ops->cancel_remain_on_channel)
8040 return -EOPNOTSUPP;
9588bbd5 8041
9588bbd5
JM
8042 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
8043
e35e4d28 8044 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
8045}
8046
13ae75b1
JM
8047static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
8048 u8 *rates, u8 rates_len)
8049{
8050 u8 i;
8051 u32 mask = 0;
8052
8053 for (i = 0; i < rates_len; i++) {
8054 int rate = (rates[i] & 0x7f) * 5;
8055 int ridx;
8056 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
8057 struct ieee80211_rate *srate =
8058 &sband->bitrates[ridx];
8059 if (rate == srate->bitrate) {
8060 mask |= 1 << ridx;
8061 break;
8062 }
8063 }
8064 if (ridx == sband->n_bitrates)
8065 return 0; /* rate not found */
8066 }
8067
8068 return mask;
8069}
8070
24db78c0
SW
8071static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
8072 u8 *rates, u8 rates_len,
8073 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
8074{
8075 u8 i;
8076
8077 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
8078
8079 for (i = 0; i < rates_len; i++) {
8080 int ridx, rbit;
8081
8082 ridx = rates[i] / 8;
8083 rbit = BIT(rates[i] % 8);
8084
8085 /* check validity */
910570b5 8086 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
8087 return false;
8088
8089 /* check availability */
8090 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
8091 mcs[ridx] |= rbit;
8092 else
8093 return false;
8094 }
8095
8096 return true;
8097}
8098
204e35a9
JD
8099static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
8100{
8101 u16 mcs_mask = 0;
8102
8103 switch (vht_mcs_map) {
8104 case IEEE80211_VHT_MCS_NOT_SUPPORTED:
8105 break;
8106 case IEEE80211_VHT_MCS_SUPPORT_0_7:
8107 mcs_mask = 0x00FF;
8108 break;
8109 case IEEE80211_VHT_MCS_SUPPORT_0_8:
8110 mcs_mask = 0x01FF;
8111 break;
8112 case IEEE80211_VHT_MCS_SUPPORT_0_9:
8113 mcs_mask = 0x03FF;
8114 break;
8115 default:
8116 break;
8117 }
8118
8119 return mcs_mask;
8120}
8121
8122static void vht_build_mcs_mask(u16 vht_mcs_map,
8123 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
8124{
8125 u8 nss;
8126
8127 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
8128 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
8129 vht_mcs_map >>= 2;
8130 }
8131}
8132
8133static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
8134 struct nl80211_txrate_vht *txrate,
8135 u16 mcs[NL80211_VHT_NSS_MAX])
8136{
8137 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
8138 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
8139 u8 i;
8140
8141 if (!sband->vht_cap.vht_supported)
8142 return false;
8143
8144 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
8145
8146 /* Build vht_mcs_mask from VHT capabilities */
8147 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
8148
8149 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
8150 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
8151 mcs[i] = txrate->mcs[i];
8152 else
8153 return false;
8154 }
8155
8156 return true;
8157}
8158
b54452b0 8159static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
8160 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
8161 .len = NL80211_MAX_SUPP_RATES },
d1e33e65
JD
8162 [NL80211_TXRATE_HT] = { .type = NLA_BINARY,
8163 .len = NL80211_MAX_SUPP_HT_RATES },
204e35a9 8164 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)},
0b9323f6 8165 [NL80211_TXRATE_GI] = { .type = NLA_U8 },
13ae75b1
JM
8166};
8167
8168static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
8169 struct genl_info *info)
8170{
8171 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 8172 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 8173 struct cfg80211_bitrate_mask mask;
4c476991
JB
8174 int rem, i;
8175 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
8176 struct nlattr *tx_rates;
8177 struct ieee80211_supported_band *sband;
204e35a9 8178 u16 vht_tx_mcs_map;
13ae75b1 8179
4c476991
JB
8180 if (!rdev->ops->set_bitrate_mask)
8181 return -EOPNOTSUPP;
13ae75b1
JM
8182
8183 memset(&mask, 0, sizeof(mask));
8184 /* Default to all rates enabled */
8185 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
8186 sband = rdev->wiphy.bands[i];
7869303b
JD
8187
8188 if (!sband)
8189 continue;
8190
8191 mask.control[i].legacy = (1 << sband->n_bitrates) - 1;
d1e33e65 8192 memcpy(mask.control[i].ht_mcs,
7869303b 8193 sband->ht_cap.mcs.rx_mask,
d1e33e65 8194 sizeof(mask.control[i].ht_mcs));
204e35a9
JD
8195
8196 if (!sband->vht_cap.vht_supported)
8197 continue;
8198
8199 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
8200 vht_build_mcs_mask(vht_tx_mcs_map, mask.control[i].vht_mcs);
13ae75b1
JM
8201 }
8202
b9243ab0
JD
8203 /* if no rates are given set it back to the defaults */
8204 if (!info->attrs[NL80211_ATTR_TX_RATES])
8205 goto out;
8206
13ae75b1
JM
8207 /*
8208 * The nested attribute uses enum nl80211_band as the index. This maps
8209 * directly to the enum ieee80211_band values used in cfg80211.
8210 */
24db78c0 8211 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
ae811e21 8212 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) {
13ae75b1 8213 enum ieee80211_band band = nla_type(tx_rates);
ae811e21
JB
8214 int err;
8215
4c476991
JB
8216 if (band < 0 || band >= IEEE80211_NUM_BANDS)
8217 return -EINVAL;
13ae75b1 8218 sband = rdev->wiphy.bands[band];
4c476991
JB
8219 if (sband == NULL)
8220 return -EINVAL;
ae811e21
JB
8221 err = nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
8222 nla_len(tx_rates), nl80211_txattr_policy);
8223 if (err)
8224 return err;
13ae75b1
JM
8225 if (tb[NL80211_TXRATE_LEGACY]) {
8226 mask.control[band].legacy = rateset_to_mask(
8227 sband,
8228 nla_data(tb[NL80211_TXRATE_LEGACY]),
8229 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
8230 if ((mask.control[band].legacy == 0) &&
8231 nla_len(tb[NL80211_TXRATE_LEGACY]))
8232 return -EINVAL;
24db78c0 8233 }
d1e33e65 8234 if (tb[NL80211_TXRATE_HT]) {
24db78c0
SW
8235 if (!ht_rateset_to_mask(
8236 sband,
d1e33e65
JD
8237 nla_data(tb[NL80211_TXRATE_HT]),
8238 nla_len(tb[NL80211_TXRATE_HT]),
8239 mask.control[band].ht_mcs))
24db78c0
SW
8240 return -EINVAL;
8241 }
204e35a9
JD
8242 if (tb[NL80211_TXRATE_VHT]) {
8243 if (!vht_set_mcs_mask(
8244 sband,
8245 nla_data(tb[NL80211_TXRATE_VHT]),
8246 mask.control[band].vht_mcs))
8247 return -EINVAL;
8248 }
0b9323f6
JD
8249 if (tb[NL80211_TXRATE_GI]) {
8250 mask.control[band].gi =
8251 nla_get_u8(tb[NL80211_TXRATE_GI]);
8252 if (mask.control[band].gi > NL80211_TXRATE_FORCE_LGI)
8253 return -EINVAL;
8254 }
24db78c0
SW
8255
8256 if (mask.control[band].legacy == 0) {
204e35a9
JD
8257 /* don't allow empty legacy rates if HT or VHT
8258 * are not even supported.
8259 */
8260 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
8261 rdev->wiphy.bands[band]->vht_cap.vht_supported))
24db78c0
SW
8262 return -EINVAL;
8263
8264 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
d1e33e65 8265 if (mask.control[band].ht_mcs[i])
204e35a9
JD
8266 goto out;
8267
8268 for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
8269 if (mask.control[band].vht_mcs[i])
8270 goto out;
24db78c0
SW
8271
8272 /* legacy and mcs rates may not be both empty */
204e35a9 8273 return -EINVAL;
13ae75b1
JM
8274 }
8275 }
8276
b9243ab0 8277out:
e35e4d28 8278 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
8279}
8280
2e161f78 8281static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 8282{
4c476991 8283 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 8284 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 8285 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
8286
8287 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
8288 return -EINVAL;
8289
2e161f78
JB
8290 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
8291 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 8292
71bbc994
JB
8293 switch (wdev->iftype) {
8294 case NL80211_IFTYPE_STATION:
8295 case NL80211_IFTYPE_ADHOC:
8296 case NL80211_IFTYPE_P2P_CLIENT:
8297 case NL80211_IFTYPE_AP:
8298 case NL80211_IFTYPE_AP_VLAN:
8299 case NL80211_IFTYPE_MESH_POINT:
8300 case NL80211_IFTYPE_P2P_GO:
98104fde 8301 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
8302 break;
8303 default:
4c476991 8304 return -EOPNOTSUPP;
71bbc994 8305 }
026331c4
JM
8306
8307 /* not much point in registering if we can't reply */
4c476991
JB
8308 if (!rdev->ops->mgmt_tx)
8309 return -EOPNOTSUPP;
026331c4 8310
15e47304 8311 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
8312 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
8313 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
8314}
8315
2e161f78 8316static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 8317{
4c476991 8318 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 8319 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 8320 struct cfg80211_chan_def chandef;
026331c4 8321 int err;
d64d373f 8322 void *hdr = NULL;
026331c4 8323 u64 cookie;
e247bd90 8324 struct sk_buff *msg = NULL;
b176e629
AO
8325 struct cfg80211_mgmt_tx_params params = {
8326 .dont_wait_for_ack =
8327 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
8328 };
026331c4 8329
683b6d3b 8330 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
8331 return -EINVAL;
8332
4c476991
JB
8333 if (!rdev->ops->mgmt_tx)
8334 return -EOPNOTSUPP;
026331c4 8335
71bbc994 8336 switch (wdev->iftype) {
ea141b75
AQ
8337 case NL80211_IFTYPE_P2P_DEVICE:
8338 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
8339 return -EINVAL;
71bbc994
JB
8340 case NL80211_IFTYPE_STATION:
8341 case NL80211_IFTYPE_ADHOC:
8342 case NL80211_IFTYPE_P2P_CLIENT:
8343 case NL80211_IFTYPE_AP:
8344 case NL80211_IFTYPE_AP_VLAN:
8345 case NL80211_IFTYPE_MESH_POINT:
8346 case NL80211_IFTYPE_P2P_GO:
8347 break;
8348 default:
4c476991 8349 return -EOPNOTSUPP;
71bbc994 8350 }
026331c4 8351
f7ca38df 8352 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 8353 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df 8354 return -EINVAL;
b176e629 8355 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
8356
8357 /*
8358 * We should wait on the channel for at least a minimum amount
8359 * of time (10ms) but no longer than the driver supports.
8360 */
b176e629
AO
8361 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
8362 params.wait > rdev->wiphy.max_remain_on_channel_duration)
ebf348fc
JB
8363 return -EINVAL;
8364
f7ca38df
JB
8365 }
8366
b176e629 8367 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
f7ca38df 8368
b176e629 8369 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7c4ef712
JB
8370 return -EINVAL;
8371
b176e629 8372 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
e9f935e3 8373
ea141b75
AQ
8374 /* get the channel if any has been specified, otherwise pass NULL to
8375 * the driver. The latter will use the current one
8376 */
8377 chandef.chan = NULL;
8378 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
8379 err = nl80211_parse_chandef(rdev, info, &chandef);
8380 if (err)
8381 return err;
8382 }
8383
b176e629 8384 if (!chandef.chan && params.offchan)
ea141b75 8385 return -EINVAL;
026331c4 8386
34d22ce2
AO
8387 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
8388 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
8389
8390 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) {
8391 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
8392 int i;
8393
8394 if (len % sizeof(u16))
8395 return -EINVAL;
8396
8397 params.n_csa_offsets = len / sizeof(u16);
8398 params.csa_offsets =
8399 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
8400
8401 /* check that all the offsets fit the frame */
8402 for (i = 0; i < params.n_csa_offsets; i++) {
8403 if (params.csa_offsets[i] >= params.len)
8404 return -EINVAL;
8405 }
8406 }
8407
b176e629 8408 if (!params.dont_wait_for_ack) {
e247bd90
JB
8409 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8410 if (!msg)
8411 return -ENOMEM;
026331c4 8412
15e47304 8413 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 8414 NL80211_CMD_FRAME);
cb35fba3
DC
8415 if (!hdr) {
8416 err = -ENOBUFS;
e247bd90
JB
8417 goto free_msg;
8418 }
026331c4 8419 }
e247bd90 8420
b176e629
AO
8421 params.chan = chandef.chan;
8422 err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
026331c4
JM
8423 if (err)
8424 goto free_msg;
8425
e247bd90 8426 if (msg) {
9360ffd1
DM
8427 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8428 goto nla_put_failure;
026331c4 8429
e247bd90
JB
8430 genlmsg_end(msg, hdr);
8431 return genlmsg_reply(msg, info);
8432 }
8433
8434 return 0;
026331c4
JM
8435
8436 nla_put_failure:
8437 err = -ENOBUFS;
8438 free_msg:
8439 nlmsg_free(msg);
026331c4
JM
8440 return err;
8441}
8442
f7ca38df
JB
8443static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
8444{
8445 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 8446 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
8447 u64 cookie;
8448
8449 if (!info->attrs[NL80211_ATTR_COOKIE])
8450 return -EINVAL;
8451
8452 if (!rdev->ops->mgmt_tx_cancel_wait)
8453 return -EOPNOTSUPP;
8454
71bbc994
JB
8455 switch (wdev->iftype) {
8456 case NL80211_IFTYPE_STATION:
8457 case NL80211_IFTYPE_ADHOC:
8458 case NL80211_IFTYPE_P2P_CLIENT:
8459 case NL80211_IFTYPE_AP:
8460 case NL80211_IFTYPE_AP_VLAN:
8461 case NL80211_IFTYPE_P2P_GO:
98104fde 8462 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
8463 break;
8464 default:
f7ca38df 8465 return -EOPNOTSUPP;
71bbc994 8466 }
f7ca38df
JB
8467
8468 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
8469
e35e4d28 8470 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
8471}
8472
ffb9eb3d
KV
8473static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
8474{
4c476991 8475 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 8476 struct wireless_dev *wdev;
4c476991 8477 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
8478 u8 ps_state;
8479 bool state;
8480 int err;
8481
4c476991
JB
8482 if (!info->attrs[NL80211_ATTR_PS_STATE])
8483 return -EINVAL;
ffb9eb3d
KV
8484
8485 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
8486
4c476991
JB
8487 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
8488 return -EINVAL;
ffb9eb3d
KV
8489
8490 wdev = dev->ieee80211_ptr;
8491
4c476991
JB
8492 if (!rdev->ops->set_power_mgmt)
8493 return -EOPNOTSUPP;
ffb9eb3d
KV
8494
8495 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
8496
8497 if (state == wdev->ps)
4c476991 8498 return 0;
ffb9eb3d 8499
e35e4d28 8500 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
8501 if (!err)
8502 wdev->ps = state;
ffb9eb3d
KV
8503 return err;
8504}
8505
8506static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
8507{
4c476991 8508 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
8509 enum nl80211_ps_state ps_state;
8510 struct wireless_dev *wdev;
4c476991 8511 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
8512 struct sk_buff *msg;
8513 void *hdr;
8514 int err;
8515
ffb9eb3d
KV
8516 wdev = dev->ieee80211_ptr;
8517
4c476991
JB
8518 if (!rdev->ops->set_power_mgmt)
8519 return -EOPNOTSUPP;
ffb9eb3d
KV
8520
8521 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
8522 if (!msg)
8523 return -ENOMEM;
ffb9eb3d 8524
15e47304 8525 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
8526 NL80211_CMD_GET_POWER_SAVE);
8527 if (!hdr) {
4c476991 8528 err = -ENOBUFS;
ffb9eb3d
KV
8529 goto free_msg;
8530 }
8531
8532 if (wdev->ps)
8533 ps_state = NL80211_PS_ENABLED;
8534 else
8535 ps_state = NL80211_PS_DISABLED;
8536
9360ffd1
DM
8537 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
8538 goto nla_put_failure;
ffb9eb3d
KV
8539
8540 genlmsg_end(msg, hdr);
4c476991 8541 return genlmsg_reply(msg, info);
ffb9eb3d 8542
4c476991 8543 nla_put_failure:
ffb9eb3d 8544 err = -ENOBUFS;
4c476991 8545 free_msg:
ffb9eb3d 8546 nlmsg_free(msg);
ffb9eb3d
KV
8547 return err;
8548}
8549
94e860f1
JB
8550static const struct nla_policy
8551nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
d6dc1a38
JO
8552 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
8553 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
8554 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
8555 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
8556 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
8557 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
8558};
8559
84f10708 8560static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 8561 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
8562{
8563 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 8564 struct net_device *dev = info->user_ptr[1];
1da5fcc8 8565 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 8566
d9d8b019 8567 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
8568 return -EINVAL;
8569
84f10708
TP
8570 if (!rdev->ops->set_cqm_txe_config)
8571 return -EOPNOTSUPP;
8572
8573 if (wdev->iftype != NL80211_IFTYPE_STATION &&
8574 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
8575 return -EOPNOTSUPP;
8576
e35e4d28 8577 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
8578}
8579
d6dc1a38
JO
8580static int nl80211_set_cqm_rssi(struct genl_info *info,
8581 s32 threshold, u32 hysteresis)
8582{
4c476991 8583 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 8584 struct net_device *dev = info->user_ptr[1];
1da5fcc8 8585 struct wireless_dev *wdev = dev->ieee80211_ptr;
d6dc1a38
JO
8586
8587 if (threshold > 0)
8588 return -EINVAL;
8589
1da5fcc8
JB
8590 /* disabling - hysteresis should also be zero then */
8591 if (threshold == 0)
8592 hysteresis = 0;
d6dc1a38 8593
4c476991
JB
8594 if (!rdev->ops->set_cqm_rssi_config)
8595 return -EOPNOTSUPP;
d6dc1a38 8596
074ac8df 8597 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8598 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
8599 return -EOPNOTSUPP;
d6dc1a38 8600
e35e4d28 8601 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
8602}
8603
8604static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
8605{
8606 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
8607 struct nlattr *cqm;
8608 int err;
8609
8610 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
8611 if (!cqm)
8612 return -EINVAL;
d6dc1a38
JO
8613
8614 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
8615 nl80211_attr_cqm_policy);
8616 if (err)
1da5fcc8 8617 return err;
d6dc1a38
JO
8618
8619 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
8620 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
1da5fcc8
JB
8621 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
8622 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 8623
1da5fcc8
JB
8624 return nl80211_set_cqm_rssi(info, threshold, hysteresis);
8625 }
8626
8627 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
8628 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
8629 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
8630 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
8631 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
8632 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
8633
8634 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
8635 }
8636
8637 return -EINVAL;
d6dc1a38
JO
8638}
8639
6e0bd6c3
RL
8640static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
8641{
8642 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8643 struct net_device *dev = info->user_ptr[1];
8644 struct ocb_setup setup = {};
8645 int err;
8646
8647 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
8648 if (err)
8649 return err;
8650
8651 return cfg80211_join_ocb(rdev, dev, &setup);
8652}
8653
8654static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info)
8655{
8656 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8657 struct net_device *dev = info->user_ptr[1];
8658
8659 return cfg80211_leave_ocb(rdev, dev);
8660}
8661
29cbe68c
JB
8662static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
8663{
8664 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8665 struct net_device *dev = info->user_ptr[1];
8666 struct mesh_config cfg;
c80d545d 8667 struct mesh_setup setup;
29cbe68c
JB
8668 int err;
8669
8670 /* start with default */
8671 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 8672 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 8673
24bdd9f4 8674 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 8675 /* and parse parameters if given */
24bdd9f4 8676 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
8677 if (err)
8678 return err;
8679 }
8680
8681 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
8682 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
8683 return -EINVAL;
8684
c80d545d
JC
8685 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
8686 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
8687
4bb62344
CYY
8688 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
8689 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
8690 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
8691 return -EINVAL;
8692
9bdbf04d
MP
8693 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
8694 setup.beacon_interval =
8695 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
8696 if (setup.beacon_interval < 10 ||
8697 setup.beacon_interval > 10000)
8698 return -EINVAL;
8699 }
8700
8701 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
8702 setup.dtim_period =
8703 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
8704 if (setup.dtim_period < 1 || setup.dtim_period > 100)
8705 return -EINVAL;
8706 }
8707
c80d545d
JC
8708 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
8709 /* parse additional setup parameters if given */
8710 err = nl80211_parse_mesh_setup(info, &setup);
8711 if (err)
8712 return err;
8713 }
8714
d37bb18a
TP
8715 if (setup.user_mpm)
8716 cfg.auto_open_plinks = false;
8717
cc1d2806 8718 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
8719 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
8720 if (err)
8721 return err;
cc1d2806
JB
8722 } else {
8723 /* cfg80211_join_mesh() will sort it out */
683b6d3b 8724 setup.chandef.chan = NULL;
cc1d2806
JB
8725 }
8726
ffb3cf30
AN
8727 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
8728 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8729 int n_rates =
8730 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8731 struct ieee80211_supported_band *sband;
8732
8733 if (!setup.chandef.chan)
8734 return -EINVAL;
8735
8736 sband = rdev->wiphy.bands[setup.chandef.chan->band];
8737
8738 err = ieee80211_get_ratemask(sband, rates, n_rates,
8739 &setup.basic_rates);
8740 if (err)
8741 return err;
8742 }
8743
c80d545d 8744 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
8745}
8746
8747static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
8748{
8749 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8750 struct net_device *dev = info->user_ptr[1];
8751
8752 return cfg80211_leave_mesh(rdev, dev);
8753}
8754
dfb89c56 8755#ifdef CONFIG_PM
bb92d199
AK
8756static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
8757 struct cfg80211_registered_device *rdev)
8758{
6abb9cb9 8759 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
8760 struct nlattr *nl_pats, *nl_pat;
8761 int i, pat_len;
8762
6abb9cb9 8763 if (!wowlan->n_patterns)
bb92d199
AK
8764 return 0;
8765
8766 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
8767 if (!nl_pats)
8768 return -ENOBUFS;
8769
6abb9cb9 8770 for (i = 0; i < wowlan->n_patterns; i++) {
bb92d199
AK
8771 nl_pat = nla_nest_start(msg, i + 1);
8772 if (!nl_pat)
8773 return -ENOBUFS;
6abb9cb9 8774 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 8775 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 8776 wowlan->patterns[i].mask) ||
50ac6607
AK
8777 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
8778 wowlan->patterns[i].pattern) ||
8779 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 8780 wowlan->patterns[i].pkt_offset))
bb92d199
AK
8781 return -ENOBUFS;
8782 nla_nest_end(msg, nl_pat);
8783 }
8784 nla_nest_end(msg, nl_pats);
8785
8786 return 0;
8787}
8788
2a0e047e
JB
8789static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
8790 struct cfg80211_wowlan_tcp *tcp)
8791{
8792 struct nlattr *nl_tcp;
8793
8794 if (!tcp)
8795 return 0;
8796
8797 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
8798 if (!nl_tcp)
8799 return -ENOBUFS;
8800
930345ea
JB
8801 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
8802 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
2a0e047e
JB
8803 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
8804 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
8805 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
8806 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
8807 tcp->payload_len, tcp->payload) ||
8808 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
8809 tcp->data_interval) ||
8810 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
8811 tcp->wake_len, tcp->wake_data) ||
8812 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
8813 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
8814 return -ENOBUFS;
8815
8816 if (tcp->payload_seq.len &&
8817 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
8818 sizeof(tcp->payload_seq), &tcp->payload_seq))
8819 return -ENOBUFS;
8820
8821 if (tcp->payload_tok.len &&
8822 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
8823 sizeof(tcp->payload_tok) + tcp->tokens_size,
8824 &tcp->payload_tok))
8825 return -ENOBUFS;
8826
e248ad30
JB
8827 nla_nest_end(msg, nl_tcp);
8828
2a0e047e
JB
8829 return 0;
8830}
8831
75453ccb
LC
8832static int nl80211_send_wowlan_nd(struct sk_buff *msg,
8833 struct cfg80211_sched_scan_request *req)
8834{
8835 struct nlattr *nd, *freqs, *matches, *match;
8836 int i;
8837
8838 if (!req)
8839 return 0;
8840
8841 nd = nla_nest_start(msg, NL80211_WOWLAN_TRIG_NET_DETECT);
8842 if (!nd)
8843 return -ENOBUFS;
8844
8845 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL, req->interval))
8846 return -ENOBUFS;
8847
21fea567
LC
8848 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay))
8849 return -ENOBUFS;
8850
75453ccb
LC
8851 freqs = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
8852 if (!freqs)
8853 return -ENOBUFS;
8854
8855 for (i = 0; i < req->n_channels; i++)
8856 nla_put_u32(msg, i, req->channels[i]->center_freq);
8857
8858 nla_nest_end(msg, freqs);
8859
8860 if (req->n_match_sets) {
8861 matches = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_MATCH);
8862 for (i = 0; i < req->n_match_sets; i++) {
8863 match = nla_nest_start(msg, i);
8864 nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID,
8865 req->match_sets[i].ssid.ssid_len,
8866 req->match_sets[i].ssid.ssid);
8867 nla_nest_end(msg, match);
8868 }
8869 nla_nest_end(msg, matches);
8870 }
8871
8872 nla_nest_end(msg, nd);
8873
8874 return 0;
8875}
8876
ff1b6e69
JB
8877static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
8878{
8879 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8880 struct sk_buff *msg;
8881 void *hdr;
2a0e047e 8882 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 8883
964dc9e2 8884 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
8885 return -EOPNOTSUPP;
8886
6abb9cb9 8887 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 8888 /* adjust size to have room for all the data */
6abb9cb9
JB
8889 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
8890 rdev->wiphy.wowlan_config->tcp->payload_len +
8891 rdev->wiphy.wowlan_config->tcp->wake_len +
8892 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
8893 }
8894
8895 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
8896 if (!msg)
8897 return -ENOMEM;
8898
15e47304 8899 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
8900 NL80211_CMD_GET_WOWLAN);
8901 if (!hdr)
8902 goto nla_put_failure;
8903
6abb9cb9 8904 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
8905 struct nlattr *nl_wowlan;
8906
8907 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
8908 if (!nl_wowlan)
8909 goto nla_put_failure;
8910
6abb9cb9 8911 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 8912 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 8913 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 8914 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 8915 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 8916 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 8917 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 8918 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 8919 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 8920 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 8921 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 8922 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 8923 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
8924 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
8925 goto nla_put_failure;
2a0e047e 8926
bb92d199
AK
8927 if (nl80211_send_wowlan_patterns(msg, rdev))
8928 goto nla_put_failure;
2a0e047e 8929
6abb9cb9
JB
8930 if (nl80211_send_wowlan_tcp(msg,
8931 rdev->wiphy.wowlan_config->tcp))
2a0e047e 8932 goto nla_put_failure;
75453ccb
LC
8933
8934 if (nl80211_send_wowlan_nd(
8935 msg,
8936 rdev->wiphy.wowlan_config->nd_config))
8937 goto nla_put_failure;
2a0e047e 8938
ff1b6e69
JB
8939 nla_nest_end(msg, nl_wowlan);
8940 }
8941
8942 genlmsg_end(msg, hdr);
8943 return genlmsg_reply(msg, info);
8944
8945nla_put_failure:
8946 nlmsg_free(msg);
8947 return -ENOBUFS;
8948}
8949
2a0e047e
JB
8950static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
8951 struct nlattr *attr,
8952 struct cfg80211_wowlan *trig)
8953{
8954 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
8955 struct cfg80211_wowlan_tcp *cfg;
8956 struct nl80211_wowlan_tcp_data_token *tok = NULL;
8957 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
8958 u32 size;
8959 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
8960 int err, port;
8961
964dc9e2 8962 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
8963 return -EINVAL;
8964
8965 err = nla_parse(tb, MAX_NL80211_WOWLAN_TCP,
8966 nla_data(attr), nla_len(attr),
8967 nl80211_wowlan_tcp_policy);
8968 if (err)
8969 return err;
8970
8971 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
8972 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
8973 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
8974 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
8975 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
8976 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
8977 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
8978 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
8979 return -EINVAL;
8980
8981 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 8982 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
8983 return -EINVAL;
8984
8985 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 8986 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 8987 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
8988 return -EINVAL;
8989
8990 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 8991 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
8992 return -EINVAL;
8993
8994 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
8995 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
8996 return -EINVAL;
8997
8998 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
8999 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
9000
9001 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
9002 tokens_size = tokln - sizeof(*tok);
9003
9004 if (!tok->len || tokens_size % tok->len)
9005 return -EINVAL;
964dc9e2 9006 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 9007 return -EINVAL;
964dc9e2 9008 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 9009 return -EINVAL;
964dc9e2 9010 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 9011 return -EINVAL;
964dc9e2 9012 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
9013 return -EINVAL;
9014 if (tok->offset + tok->len > data_size)
9015 return -EINVAL;
9016 }
9017
9018 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
9019 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 9020 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
9021 return -EINVAL;
9022 if (seq->len == 0 || seq->len > 4)
9023 return -EINVAL;
9024 if (seq->len + seq->offset > data_size)
9025 return -EINVAL;
9026 }
9027
9028 size = sizeof(*cfg);
9029 size += data_size;
9030 size += wake_size + wake_mask_size;
9031 size += tokens_size;
9032
9033 cfg = kzalloc(size, GFP_KERNEL);
9034 if (!cfg)
9035 return -ENOMEM;
67b61f6c
JB
9036 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
9037 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
2a0e047e
JB
9038 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
9039 ETH_ALEN);
9040 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
9041 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
9042 else
9043 port = 0;
9044#ifdef CONFIG_INET
9045 /* allocate a socket and port for it and use it */
9046 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
9047 IPPROTO_TCP, &cfg->sock, 1);
9048 if (err) {
9049 kfree(cfg);
9050 return err;
9051 }
9052 if (inet_csk_get_port(cfg->sock->sk, port)) {
9053 sock_release(cfg->sock);
9054 kfree(cfg);
9055 return -EADDRINUSE;
9056 }
9057 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
9058#else
9059 if (!port) {
9060 kfree(cfg);
9061 return -EINVAL;
9062 }
9063 cfg->src_port = port;
9064#endif
9065
9066 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
9067 cfg->payload_len = data_size;
9068 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
9069 memcpy((void *)cfg->payload,
9070 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
9071 data_size);
9072 if (seq)
9073 cfg->payload_seq = *seq;
9074 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
9075 cfg->wake_len = wake_size;
9076 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
9077 memcpy((void *)cfg->wake_data,
9078 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
9079 wake_size);
9080 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
9081 data_size + wake_size;
9082 memcpy((void *)cfg->wake_mask,
9083 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
9084 wake_mask_size);
9085 if (tok) {
9086 cfg->tokens_size = tokens_size;
9087 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
9088 }
9089
9090 trig->tcp = cfg;
9091
9092 return 0;
9093}
9094
8cd4d456
LC
9095static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev,
9096 const struct wiphy_wowlan_support *wowlan,
9097 struct nlattr *attr,
9098 struct cfg80211_wowlan *trig)
9099{
9100 struct nlattr **tb;
9101 int err;
9102
9103 tb = kzalloc(NUM_NL80211_ATTR * sizeof(*tb), GFP_KERNEL);
9104 if (!tb)
9105 return -ENOMEM;
9106
9107 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) {
9108 err = -EOPNOTSUPP;
9109 goto out;
9110 }
9111
9112 err = nla_parse(tb, NL80211_ATTR_MAX,
9113 nla_data(attr), nla_len(attr),
9114 nl80211_policy);
9115 if (err)
9116 goto out;
9117
ad2b26ab 9118 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb);
8cd4d456
LC
9119 err = PTR_ERR_OR_ZERO(trig->nd_config);
9120 if (err)
9121 trig->nd_config = NULL;
9122
9123out:
9124 kfree(tb);
9125 return err;
9126}
9127
ff1b6e69
JB
9128static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
9129{
9130 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9131 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 9132 struct cfg80211_wowlan new_triggers = {};
ae33bd81 9133 struct cfg80211_wowlan *ntrig;
964dc9e2 9134 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 9135 int err, i;
6abb9cb9 9136 bool prev_enabled = rdev->wiphy.wowlan_config;
98fc4386 9137 bool regular = false;
ff1b6e69 9138
964dc9e2 9139 if (!wowlan)
ff1b6e69
JB
9140 return -EOPNOTSUPP;
9141
ae33bd81
JB
9142 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
9143 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 9144 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
9145 goto set_wakeup;
9146 }
ff1b6e69
JB
9147
9148 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
9149 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
9150 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
9151 nl80211_wowlan_policy);
9152 if (err)
9153 return err;
9154
9155 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
9156 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
9157 return -EINVAL;
9158 new_triggers.any = true;
9159 }
9160
9161 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
9162 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
9163 return -EINVAL;
9164 new_triggers.disconnect = true;
98fc4386 9165 regular = true;
ff1b6e69
JB
9166 }
9167
9168 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
9169 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
9170 return -EINVAL;
9171 new_triggers.magic_pkt = true;
98fc4386 9172 regular = true;
ff1b6e69
JB
9173 }
9174
77dbbb13
JB
9175 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
9176 return -EINVAL;
9177
9178 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
9179 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
9180 return -EINVAL;
9181 new_triggers.gtk_rekey_failure = true;
98fc4386 9182 regular = true;
77dbbb13
JB
9183 }
9184
9185 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
9186 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
9187 return -EINVAL;
9188 new_triggers.eap_identity_req = true;
98fc4386 9189 regular = true;
77dbbb13
JB
9190 }
9191
9192 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
9193 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
9194 return -EINVAL;
9195 new_triggers.four_way_handshake = true;
98fc4386 9196 regular = true;
77dbbb13
JB
9197 }
9198
9199 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
9200 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
9201 return -EINVAL;
9202 new_triggers.rfkill_release = true;
98fc4386 9203 regular = true;
77dbbb13
JB
9204 }
9205
ff1b6e69
JB
9206 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
9207 struct nlattr *pat;
9208 int n_patterns = 0;
bb92d199 9209 int rem, pat_len, mask_len, pkt_offset;
50ac6607 9210 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69 9211
98fc4386
JB
9212 regular = true;
9213
ff1b6e69
JB
9214 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
9215 rem)
9216 n_patterns++;
9217 if (n_patterns > wowlan->n_patterns)
9218 return -EINVAL;
9219
9220 new_triggers.patterns = kcalloc(n_patterns,
9221 sizeof(new_triggers.patterns[0]),
9222 GFP_KERNEL);
9223 if (!new_triggers.patterns)
9224 return -ENOMEM;
9225
9226 new_triggers.n_patterns = n_patterns;
9227 i = 0;
9228
9229 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
9230 rem) {
922bd80f
JB
9231 u8 *mask_pat;
9232
50ac6607
AK
9233 nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
9234 nla_len(pat), NULL);
ff1b6e69 9235 err = -EINVAL;
50ac6607
AK
9236 if (!pat_tb[NL80211_PKTPAT_MASK] ||
9237 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 9238 goto error;
50ac6607 9239 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 9240 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 9241 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
9242 goto error;
9243 if (pat_len > wowlan->pattern_max_len ||
9244 pat_len < wowlan->pattern_min_len)
9245 goto error;
9246
50ac6607 9247 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
9248 pkt_offset = 0;
9249 else
9250 pkt_offset = nla_get_u32(
50ac6607 9251 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
9252 if (pkt_offset > wowlan->max_pkt_offset)
9253 goto error;
9254 new_triggers.patterns[i].pkt_offset = pkt_offset;
9255
922bd80f
JB
9256 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
9257 if (!mask_pat) {
ff1b6e69
JB
9258 err = -ENOMEM;
9259 goto error;
9260 }
922bd80f
JB
9261 new_triggers.patterns[i].mask = mask_pat;
9262 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69 9263 mask_len);
922bd80f
JB
9264 mask_pat += mask_len;
9265 new_triggers.patterns[i].pattern = mask_pat;
ff1b6e69 9266 new_triggers.patterns[i].pattern_len = pat_len;
922bd80f 9267 memcpy(mask_pat,
50ac6607 9268 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
9269 pat_len);
9270 i++;
9271 }
9272 }
9273
2a0e047e 9274 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
98fc4386 9275 regular = true;
2a0e047e
JB
9276 err = nl80211_parse_wowlan_tcp(
9277 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
9278 &new_triggers);
9279 if (err)
9280 goto error;
9281 }
9282
8cd4d456 9283 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) {
98fc4386 9284 regular = true;
8cd4d456
LC
9285 err = nl80211_parse_wowlan_nd(
9286 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT],
9287 &new_triggers);
9288 if (err)
9289 goto error;
9290 }
9291
98fc4386
JB
9292 /* The 'any' trigger means the device continues operating more or less
9293 * as in its normal operation mode and wakes up the host on most of the
9294 * normal interrupts (like packet RX, ...)
9295 * It therefore makes little sense to combine with the more constrained
9296 * wakeup trigger modes.
9297 */
9298 if (new_triggers.any && regular) {
9299 err = -EINVAL;
9300 goto error;
9301 }
9302
ae33bd81
JB
9303 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
9304 if (!ntrig) {
9305 err = -ENOMEM;
9306 goto error;
ff1b6e69 9307 }
ae33bd81 9308 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 9309 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 9310
ae33bd81 9311 set_wakeup:
6abb9cb9
JB
9312 if (rdev->ops->set_wakeup &&
9313 prev_enabled != !!rdev->wiphy.wowlan_config)
9314 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 9315
ff1b6e69
JB
9316 return 0;
9317 error:
9318 for (i = 0; i < new_triggers.n_patterns; i++)
9319 kfree(new_triggers.patterns[i].mask);
9320 kfree(new_triggers.patterns);
2a0e047e
JB
9321 if (new_triggers.tcp && new_triggers.tcp->sock)
9322 sock_release(new_triggers.tcp->sock);
9323 kfree(new_triggers.tcp);
ff1b6e69
JB
9324 return err;
9325}
dfb89c56 9326#endif
ff1b6e69 9327
be29b99a
AK
9328static int nl80211_send_coalesce_rules(struct sk_buff *msg,
9329 struct cfg80211_registered_device *rdev)
9330{
9331 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
9332 int i, j, pat_len;
9333 struct cfg80211_coalesce_rules *rule;
9334
9335 if (!rdev->coalesce->n_rules)
9336 return 0;
9337
9338 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE);
9339 if (!nl_rules)
9340 return -ENOBUFS;
9341
9342 for (i = 0; i < rdev->coalesce->n_rules; i++) {
9343 nl_rule = nla_nest_start(msg, i + 1);
9344 if (!nl_rule)
9345 return -ENOBUFS;
9346
9347 rule = &rdev->coalesce->rules[i];
9348 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
9349 rule->delay))
9350 return -ENOBUFS;
9351
9352 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
9353 rule->condition))
9354 return -ENOBUFS;
9355
9356 nl_pats = nla_nest_start(msg,
9357 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
9358 if (!nl_pats)
9359 return -ENOBUFS;
9360
9361 for (j = 0; j < rule->n_patterns; j++) {
9362 nl_pat = nla_nest_start(msg, j + 1);
9363 if (!nl_pat)
9364 return -ENOBUFS;
9365 pat_len = rule->patterns[j].pattern_len;
9366 if (nla_put(msg, NL80211_PKTPAT_MASK,
9367 DIV_ROUND_UP(pat_len, 8),
9368 rule->patterns[j].mask) ||
9369 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
9370 rule->patterns[j].pattern) ||
9371 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
9372 rule->patterns[j].pkt_offset))
9373 return -ENOBUFS;
9374 nla_nest_end(msg, nl_pat);
9375 }
9376 nla_nest_end(msg, nl_pats);
9377 nla_nest_end(msg, nl_rule);
9378 }
9379 nla_nest_end(msg, nl_rules);
9380
9381 return 0;
9382}
9383
9384static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
9385{
9386 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9387 struct sk_buff *msg;
9388 void *hdr;
9389
9390 if (!rdev->wiphy.coalesce)
9391 return -EOPNOTSUPP;
9392
9393 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9394 if (!msg)
9395 return -ENOMEM;
9396
9397 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9398 NL80211_CMD_GET_COALESCE);
9399 if (!hdr)
9400 goto nla_put_failure;
9401
9402 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
9403 goto nla_put_failure;
9404
9405 genlmsg_end(msg, hdr);
9406 return genlmsg_reply(msg, info);
9407
9408nla_put_failure:
9409 nlmsg_free(msg);
9410 return -ENOBUFS;
9411}
9412
9413void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
9414{
9415 struct cfg80211_coalesce *coalesce = rdev->coalesce;
9416 int i, j;
9417 struct cfg80211_coalesce_rules *rule;
9418
9419 if (!coalesce)
9420 return;
9421
9422 for (i = 0; i < coalesce->n_rules; i++) {
9423 rule = &coalesce->rules[i];
9424 for (j = 0; j < rule->n_patterns; j++)
9425 kfree(rule->patterns[j].mask);
9426 kfree(rule->patterns);
9427 }
9428 kfree(coalesce->rules);
9429 kfree(coalesce);
9430 rdev->coalesce = NULL;
9431}
9432
9433static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
9434 struct nlattr *rule,
9435 struct cfg80211_coalesce_rules *new_rule)
9436{
9437 int err, i;
9438 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
9439 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
9440 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
9441 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
9442
9443 err = nla_parse(tb, NL80211_ATTR_COALESCE_RULE_MAX, nla_data(rule),
9444 nla_len(rule), nl80211_coalesce_policy);
9445 if (err)
9446 return err;
9447
9448 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
9449 new_rule->delay =
9450 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
9451 if (new_rule->delay > coalesce->max_delay)
9452 return -EINVAL;
9453
9454 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
9455 new_rule->condition =
9456 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
9457 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH &&
9458 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH)
9459 return -EINVAL;
9460
9461 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
9462 return -EINVAL;
9463
9464 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
9465 rem)
9466 n_patterns++;
9467 if (n_patterns > coalesce->n_patterns)
9468 return -EINVAL;
9469
9470 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
9471 GFP_KERNEL);
9472 if (!new_rule->patterns)
9473 return -ENOMEM;
9474
9475 new_rule->n_patterns = n_patterns;
9476 i = 0;
9477
9478 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
9479 rem) {
922bd80f
JB
9480 u8 *mask_pat;
9481
be29b99a
AK
9482 nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
9483 nla_len(pat), NULL);
9484 if (!pat_tb[NL80211_PKTPAT_MASK] ||
9485 !pat_tb[NL80211_PKTPAT_PATTERN])
9486 return -EINVAL;
9487 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
9488 mask_len = DIV_ROUND_UP(pat_len, 8);
9489 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
9490 return -EINVAL;
9491 if (pat_len > coalesce->pattern_max_len ||
9492 pat_len < coalesce->pattern_min_len)
9493 return -EINVAL;
9494
9495 if (!pat_tb[NL80211_PKTPAT_OFFSET])
9496 pkt_offset = 0;
9497 else
9498 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
9499 if (pkt_offset > coalesce->max_pkt_offset)
9500 return -EINVAL;
9501 new_rule->patterns[i].pkt_offset = pkt_offset;
9502
922bd80f
JB
9503 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
9504 if (!mask_pat)
be29b99a 9505 return -ENOMEM;
922bd80f
JB
9506
9507 new_rule->patterns[i].mask = mask_pat;
9508 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
9509 mask_len);
9510
9511 mask_pat += mask_len;
9512 new_rule->patterns[i].pattern = mask_pat;
be29b99a 9513 new_rule->patterns[i].pattern_len = pat_len;
922bd80f
JB
9514 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
9515 pat_len);
be29b99a
AK
9516 i++;
9517 }
9518
9519 return 0;
9520}
9521
9522static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
9523{
9524 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9525 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
9526 struct cfg80211_coalesce new_coalesce = {};
9527 struct cfg80211_coalesce *n_coalesce;
9528 int err, rem_rule, n_rules = 0, i, j;
9529 struct nlattr *rule;
9530 struct cfg80211_coalesce_rules *tmp_rule;
9531
9532 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
9533 return -EOPNOTSUPP;
9534
9535 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
9536 cfg80211_rdev_free_coalesce(rdev);
9537 rdev->ops->set_coalesce(&rdev->wiphy, NULL);
9538 return 0;
9539 }
9540
9541 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
9542 rem_rule)
9543 n_rules++;
9544 if (n_rules > coalesce->n_rules)
9545 return -EINVAL;
9546
9547 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
9548 GFP_KERNEL);
9549 if (!new_coalesce.rules)
9550 return -ENOMEM;
9551
9552 new_coalesce.n_rules = n_rules;
9553 i = 0;
9554
9555 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
9556 rem_rule) {
9557 err = nl80211_parse_coalesce_rule(rdev, rule,
9558 &new_coalesce.rules[i]);
9559 if (err)
9560 goto error;
9561
9562 i++;
9563 }
9564
9565 err = rdev->ops->set_coalesce(&rdev->wiphy, &new_coalesce);
9566 if (err)
9567 goto error;
9568
9569 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
9570 if (!n_coalesce) {
9571 err = -ENOMEM;
9572 goto error;
9573 }
9574 cfg80211_rdev_free_coalesce(rdev);
9575 rdev->coalesce = n_coalesce;
9576
9577 return 0;
9578error:
9579 for (i = 0; i < new_coalesce.n_rules; i++) {
9580 tmp_rule = &new_coalesce.rules[i];
9581 for (j = 0; j < tmp_rule->n_patterns; j++)
9582 kfree(tmp_rule->patterns[j].mask);
9583 kfree(tmp_rule->patterns);
9584 }
9585 kfree(new_coalesce.rules);
9586
9587 return err;
9588}
9589
e5497d76
JB
9590static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
9591{
9592 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9593 struct net_device *dev = info->user_ptr[1];
9594 struct wireless_dev *wdev = dev->ieee80211_ptr;
9595 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
9596 struct cfg80211_gtk_rekey_data rekey_data;
9597 int err;
9598
9599 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
9600 return -EINVAL;
9601
9602 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
9603 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
9604 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
9605 nl80211_rekey_policy);
9606 if (err)
9607 return err;
9608
9609 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
9610 return -ERANGE;
9611 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
9612 return -ERANGE;
9613 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
9614 return -ERANGE;
9615
78f686ca
JB
9616 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]);
9617 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]);
9618 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]);
e5497d76
JB
9619
9620 wdev_lock(wdev);
9621 if (!wdev->current_bss) {
9622 err = -ENOTCONN;
9623 goto out;
9624 }
9625
9626 if (!rdev->ops->set_rekey_data) {
9627 err = -EOPNOTSUPP;
9628 goto out;
9629 }
9630
e35e4d28 9631 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
9632 out:
9633 wdev_unlock(wdev);
9634 return err;
9635}
9636
28946da7
JB
9637static int nl80211_register_unexpected_frame(struct sk_buff *skb,
9638 struct genl_info *info)
9639{
9640 struct net_device *dev = info->user_ptr[1];
9641 struct wireless_dev *wdev = dev->ieee80211_ptr;
9642
9643 if (wdev->iftype != NL80211_IFTYPE_AP &&
9644 wdev->iftype != NL80211_IFTYPE_P2P_GO)
9645 return -EINVAL;
9646
15e47304 9647 if (wdev->ap_unexpected_nlportid)
28946da7
JB
9648 return -EBUSY;
9649
15e47304 9650 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
9651 return 0;
9652}
9653
7f6cf311
JB
9654static int nl80211_probe_client(struct sk_buff *skb,
9655 struct genl_info *info)
9656{
9657 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9658 struct net_device *dev = info->user_ptr[1];
9659 struct wireless_dev *wdev = dev->ieee80211_ptr;
9660 struct sk_buff *msg;
9661 void *hdr;
9662 const u8 *addr;
9663 u64 cookie;
9664 int err;
9665
9666 if (wdev->iftype != NL80211_IFTYPE_AP &&
9667 wdev->iftype != NL80211_IFTYPE_P2P_GO)
9668 return -EOPNOTSUPP;
9669
9670 if (!info->attrs[NL80211_ATTR_MAC])
9671 return -EINVAL;
9672
9673 if (!rdev->ops->probe_client)
9674 return -EOPNOTSUPP;
9675
9676 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9677 if (!msg)
9678 return -ENOMEM;
9679
15e47304 9680 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 9681 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
9682 if (!hdr) {
9683 err = -ENOBUFS;
7f6cf311
JB
9684 goto free_msg;
9685 }
9686
9687 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
9688
e35e4d28 9689 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
9690 if (err)
9691 goto free_msg;
9692
9360ffd1
DM
9693 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
9694 goto nla_put_failure;
7f6cf311
JB
9695
9696 genlmsg_end(msg, hdr);
9697
9698 return genlmsg_reply(msg, info);
9699
9700 nla_put_failure:
9701 err = -ENOBUFS;
9702 free_msg:
9703 nlmsg_free(msg);
9704 return err;
9705}
9706
5e760230
JB
9707static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
9708{
9709 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
9710 struct cfg80211_beacon_registration *reg, *nreg;
9711 int rv;
5e760230
JB
9712
9713 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
9714 return -EOPNOTSUPP;
9715
37c73b5f
BG
9716 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
9717 if (!nreg)
9718 return -ENOMEM;
9719
9720 /* First, check if already registered. */
9721 spin_lock_bh(&rdev->beacon_registrations_lock);
9722 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
9723 if (reg->nlportid == info->snd_portid) {
9724 rv = -EALREADY;
9725 goto out_err;
9726 }
9727 }
9728 /* Add it to the list */
9729 nreg->nlportid = info->snd_portid;
9730 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 9731
37c73b5f 9732 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
9733
9734 return 0;
37c73b5f
BG
9735out_err:
9736 spin_unlock_bh(&rdev->beacon_registrations_lock);
9737 kfree(nreg);
9738 return rv;
5e760230
JB
9739}
9740
98104fde
JB
9741static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
9742{
9743 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9744 struct wireless_dev *wdev = info->user_ptr[1];
9745 int err;
9746
9747 if (!rdev->ops->start_p2p_device)
9748 return -EOPNOTSUPP;
9749
9750 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
9751 return -EOPNOTSUPP;
9752
9753 if (wdev->p2p_started)
9754 return 0;
9755
b6a55015
LC
9756 if (rfkill_blocked(rdev->rfkill))
9757 return -ERFKILL;
98104fde 9758
eeb126e9 9759 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
9760 if (err)
9761 return err;
9762
9763 wdev->p2p_started = true;
98104fde 9764 rdev->opencount++;
98104fde
JB
9765
9766 return 0;
9767}
9768
9769static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
9770{
9771 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9772 struct wireless_dev *wdev = info->user_ptr[1];
9773
9774 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
9775 return -EOPNOTSUPP;
9776
9777 if (!rdev->ops->stop_p2p_device)
9778 return -EOPNOTSUPP;
9779
f9f47529 9780 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
9781
9782 return 0;
9783}
9784
3713b4e3
JB
9785static int nl80211_get_protocol_features(struct sk_buff *skb,
9786 struct genl_info *info)
9787{
9788 void *hdr;
9789 struct sk_buff *msg;
9790
9791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9792 if (!msg)
9793 return -ENOMEM;
9794
9795 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9796 NL80211_CMD_GET_PROTOCOL_FEATURES);
9797 if (!hdr)
9798 goto nla_put_failure;
9799
9800 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
9801 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
9802 goto nla_put_failure;
9803
9804 genlmsg_end(msg, hdr);
9805 return genlmsg_reply(msg, info);
9806
9807 nla_put_failure:
9808 kfree_skb(msg);
9809 return -ENOBUFS;
9810}
9811
355199e0
JM
9812static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
9813{
9814 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9815 struct cfg80211_update_ft_ies_params ft_params;
9816 struct net_device *dev = info->user_ptr[1];
9817
9818 if (!rdev->ops->update_ft_ies)
9819 return -EOPNOTSUPP;
9820
9821 if (!info->attrs[NL80211_ATTR_MDID] ||
9822 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
9823 return -EINVAL;
9824
9825 memset(&ft_params, 0, sizeof(ft_params));
9826 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
9827 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9828 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9829
9830 return rdev_update_ft_ies(rdev, dev, &ft_params);
9831}
9832
5de17984
AS
9833static int nl80211_crit_protocol_start(struct sk_buff *skb,
9834 struct genl_info *info)
9835{
9836 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9837 struct wireless_dev *wdev = info->user_ptr[1];
9838 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
9839 u16 duration;
9840 int ret;
9841
9842 if (!rdev->ops->crit_proto_start)
9843 return -EOPNOTSUPP;
9844
9845 if (WARN_ON(!rdev->ops->crit_proto_stop))
9846 return -EINVAL;
9847
9848 if (rdev->crit_proto_nlportid)
9849 return -EBUSY;
9850
9851 /* determine protocol if provided */
9852 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
9853 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
9854
9855 if (proto >= NUM_NL80211_CRIT_PROTO)
9856 return -EINVAL;
9857
9858 /* timeout must be provided */
9859 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
9860 return -EINVAL;
9861
9862 duration =
9863 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
9864
9865 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
9866 return -ERANGE;
9867
9868 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
9869 if (!ret)
9870 rdev->crit_proto_nlportid = info->snd_portid;
9871
9872 return ret;
9873}
9874
9875static int nl80211_crit_protocol_stop(struct sk_buff *skb,
9876 struct genl_info *info)
9877{
9878 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9879 struct wireless_dev *wdev = info->user_ptr[1];
9880
9881 if (!rdev->ops->crit_proto_stop)
9882 return -EOPNOTSUPP;
9883
9884 if (rdev->crit_proto_nlportid) {
9885 rdev->crit_proto_nlportid = 0;
9886 rdev_crit_proto_stop(rdev, wdev);
9887 }
9888 return 0;
9889}
9890
ad7e718c
JB
9891static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
9892{
9893 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9894 struct wireless_dev *wdev =
9895 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
9896 int i, err;
9897 u32 vid, subcmd;
9898
9899 if (!rdev->wiphy.vendor_commands)
9900 return -EOPNOTSUPP;
9901
9902 if (IS_ERR(wdev)) {
9903 err = PTR_ERR(wdev);
9904 if (err != -EINVAL)
9905 return err;
9906 wdev = NULL;
9907 } else if (wdev->wiphy != &rdev->wiphy) {
9908 return -EINVAL;
9909 }
9910
9911 if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
9912 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
9913 return -EINVAL;
9914
9915 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
9916 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
9917 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
9918 const struct wiphy_vendor_command *vcmd;
9919 void *data = NULL;
9920 int len = 0;
9921
9922 vcmd = &rdev->wiphy.vendor_commands[i];
9923
9924 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
9925 continue;
9926
9927 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
9928 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
9929 if (!wdev)
9930 return -EINVAL;
9931 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
9932 !wdev->netdev)
9933 return -EINVAL;
9934
9935 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
9936 if (wdev->netdev &&
9937 !netif_running(wdev->netdev))
9938 return -ENETDOWN;
9939 if (!wdev->netdev && !wdev->p2p_started)
9940 return -ENETDOWN;
9941 }
7bdbe400
JB
9942
9943 if (!vcmd->doit)
9944 return -EOPNOTSUPP;
ad7e718c
JB
9945 } else {
9946 wdev = NULL;
9947 }
9948
9949 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
9950 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
9951 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
9952 }
9953
9954 rdev->cur_cmd_info = info;
9955 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev,
9956 data, len);
9957 rdev->cur_cmd_info = NULL;
9958 return err;
9959 }
9960
9961 return -EOPNOTSUPP;
9962}
9963
7bdbe400
JB
9964static int nl80211_prepare_vendor_dump(struct sk_buff *skb,
9965 struct netlink_callback *cb,
9966 struct cfg80211_registered_device **rdev,
9967 struct wireless_dev **wdev)
9968{
9969 u32 vid, subcmd;
9970 unsigned int i;
9971 int vcmd_idx = -1;
9972 int err;
9973 void *data = NULL;
9974 unsigned int data_len = 0;
9975
9976 rtnl_lock();
9977
9978 if (cb->args[0]) {
9979 /* subtract the 1 again here */
9980 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
9981 struct wireless_dev *tmp;
9982
9983 if (!wiphy) {
9984 err = -ENODEV;
9985 goto out_unlock;
9986 }
9987 *rdev = wiphy_to_rdev(wiphy);
9988 *wdev = NULL;
9989
9990 if (cb->args[1]) {
9991 list_for_each_entry(tmp, &(*rdev)->wdev_list, list) {
9992 if (tmp->identifier == cb->args[1] - 1) {
9993 *wdev = tmp;
9994 break;
9995 }
9996 }
9997 }
9998
9999 /* keep rtnl locked in successful case */
10000 return 0;
10001 }
10002
10003 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
10004 nl80211_fam.attrbuf, nl80211_fam.maxattr,
10005 nl80211_policy);
10006 if (err)
10007 goto out_unlock;
10008
10009 if (!nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_ID] ||
10010 !nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) {
10011 err = -EINVAL;
10012 goto out_unlock;
10013 }
10014
10015 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
10016 nl80211_fam.attrbuf);
10017 if (IS_ERR(*wdev))
10018 *wdev = NULL;
10019
10020 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
10021 nl80211_fam.attrbuf);
10022 if (IS_ERR(*rdev)) {
10023 err = PTR_ERR(*rdev);
10024 goto out_unlock;
10025 }
10026
10027 vid = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_ID]);
10028 subcmd = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_SUBCMD]);
10029
10030 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) {
10031 const struct wiphy_vendor_command *vcmd;
10032
10033 vcmd = &(*rdev)->wiphy.vendor_commands[i];
10034
10035 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
10036 continue;
10037
10038 if (!vcmd->dumpit) {
10039 err = -EOPNOTSUPP;
10040 goto out_unlock;
10041 }
10042
10043 vcmd_idx = i;
10044 break;
10045 }
10046
10047 if (vcmd_idx < 0) {
10048 err = -EOPNOTSUPP;
10049 goto out_unlock;
10050 }
10051
10052 if (nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_DATA]) {
10053 data = nla_data(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_DATA]);
10054 data_len = nla_len(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_DATA]);
10055 }
10056
10057 /* 0 is the first index - add 1 to parse only once */
10058 cb->args[0] = (*rdev)->wiphy_idx + 1;
10059 /* add 1 to know if it was NULL */
10060 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0;
10061 cb->args[2] = vcmd_idx;
10062 cb->args[3] = (unsigned long)data;
10063 cb->args[4] = data_len;
10064
10065 /* keep rtnl locked in successful case */
10066 return 0;
10067 out_unlock:
10068 rtnl_unlock();
10069 return err;
10070}
10071
10072static int nl80211_vendor_cmd_dump(struct sk_buff *skb,
10073 struct netlink_callback *cb)
10074{
10075 struct cfg80211_registered_device *rdev;
10076 struct wireless_dev *wdev;
10077 unsigned int vcmd_idx;
10078 const struct wiphy_vendor_command *vcmd;
10079 void *data;
10080 int data_len;
10081 int err;
10082 struct nlattr *vendor_data;
10083
10084 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev);
10085 if (err)
10086 return err;
10087
10088 vcmd_idx = cb->args[2];
10089 data = (void *)cb->args[3];
10090 data_len = cb->args[4];
10091 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx];
10092
10093 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
10094 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
10095 if (!wdev)
10096 return -EINVAL;
10097 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
10098 !wdev->netdev)
10099 return -EINVAL;
10100
10101 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
10102 if (wdev->netdev &&
10103 !netif_running(wdev->netdev))
10104 return -ENETDOWN;
10105 if (!wdev->netdev && !wdev->p2p_started)
10106 return -ENETDOWN;
10107 }
10108 }
10109
10110 while (1) {
10111 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
10112 cb->nlh->nlmsg_seq, NLM_F_MULTI,
10113 NL80211_CMD_VENDOR);
10114 if (!hdr)
10115 break;
10116
10117 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10118 (wdev && nla_put_u64(skb, NL80211_ATTR_WDEV,
10119 wdev_id(wdev)))) {
10120 genlmsg_cancel(skb, hdr);
10121 break;
10122 }
10123
10124 vendor_data = nla_nest_start(skb, NL80211_ATTR_VENDOR_DATA);
10125 if (!vendor_data) {
10126 genlmsg_cancel(skb, hdr);
10127 break;
10128 }
10129
10130 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len,
10131 (unsigned long *)&cb->args[5]);
10132 nla_nest_end(skb, vendor_data);
10133
10134 if (err == -ENOBUFS || err == -ENOENT) {
10135 genlmsg_cancel(skb, hdr);
10136 break;
10137 } else if (err) {
10138 genlmsg_cancel(skb, hdr);
10139 goto out;
10140 }
10141
10142 genlmsg_end(skb, hdr);
10143 }
10144
10145 err = skb->len;
10146 out:
10147 rtnl_unlock();
10148 return err;
10149}
10150
ad7e718c
JB
10151struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
10152 enum nl80211_commands cmd,
10153 enum nl80211_attrs attr,
10154 int approxlen)
10155{
f26cbf40 10156 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ad7e718c
JB
10157
10158 if (WARN_ON(!rdev->cur_cmd_info))
10159 return NULL;
10160
6c09e791 10161 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen,
ad7e718c
JB
10162 rdev->cur_cmd_info->snd_portid,
10163 rdev->cur_cmd_info->snd_seq,
567ffc35 10164 cmd, attr, NULL, GFP_KERNEL);
ad7e718c
JB
10165}
10166EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
10167
10168int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
10169{
10170 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
10171 void *hdr = ((void **)skb->cb)[1];
10172 struct nlattr *data = ((void **)skb->cb)[2];
10173
bd8c78e7
JB
10174 /* clear CB data for netlink core to own from now on */
10175 memset(skb->cb, 0, sizeof(skb->cb));
10176
ad7e718c
JB
10177 if (WARN_ON(!rdev->cur_cmd_info)) {
10178 kfree_skb(skb);
10179 return -EINVAL;
10180 }
10181
10182 nla_nest_end(skb, data);
10183 genlmsg_end(skb, hdr);
10184 return genlmsg_reply(skb, rdev->cur_cmd_info);
10185}
10186EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
10187
10188
fa9ffc74
KP
10189static int nl80211_set_qos_map(struct sk_buff *skb,
10190 struct genl_info *info)
10191{
10192 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10193 struct cfg80211_qos_map *qos_map = NULL;
10194 struct net_device *dev = info->user_ptr[1];
10195 u8 *pos, len, num_des, des_len, des;
10196 int ret;
10197
10198 if (!rdev->ops->set_qos_map)
10199 return -EOPNOTSUPP;
10200
10201 if (info->attrs[NL80211_ATTR_QOS_MAP]) {
10202 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
10203 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
10204
10205 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN ||
10206 len > IEEE80211_QOS_MAP_LEN_MAX)
10207 return -EINVAL;
10208
10209 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
10210 if (!qos_map)
10211 return -ENOMEM;
10212
10213 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
10214 if (num_des) {
10215 des_len = num_des *
10216 sizeof(struct cfg80211_dscp_exception);
10217 memcpy(qos_map->dscp_exception, pos, des_len);
10218 qos_map->num_des = num_des;
10219 for (des = 0; des < num_des; des++) {
10220 if (qos_map->dscp_exception[des].up > 7) {
10221 kfree(qos_map);
10222 return -EINVAL;
10223 }
10224 }
10225 pos += des_len;
10226 }
10227 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
10228 }
10229
10230 wdev_lock(dev->ieee80211_ptr);
10231 ret = nl80211_key_allowed(dev->ieee80211_ptr);
10232 if (!ret)
10233 ret = rdev_set_qos_map(rdev, dev, qos_map);
10234 wdev_unlock(dev->ieee80211_ptr);
10235
10236 kfree(qos_map);
10237 return ret;
10238}
10239
960d01ac
JB
10240static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info)
10241{
10242 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10243 struct net_device *dev = info->user_ptr[1];
10244 struct wireless_dev *wdev = dev->ieee80211_ptr;
10245 const u8 *peer;
10246 u8 tsid, up;
10247 u16 admitted_time = 0;
10248 int err;
10249
723e73ac 10250 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION))
960d01ac
JB
10251 return -EOPNOTSUPP;
10252
10253 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] ||
10254 !info->attrs[NL80211_ATTR_USER_PRIO])
10255 return -EINVAL;
10256
10257 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
10258 if (tsid >= IEEE80211_NUM_TIDS)
10259 return -EINVAL;
10260
10261 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]);
10262 if (up >= IEEE80211_NUM_UPS)
10263 return -EINVAL;
10264
10265 /* WMM uses TIDs 0-7 even for TSPEC */
723e73ac 10266 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) {
960d01ac 10267 /* TODO: handle 802.11 TSPEC/admission control
723e73ac
JB
10268 * need more attributes for that (e.g. BA session requirement);
10269 * change the WMM adminssion test above to allow both then
960d01ac
JB
10270 */
10271 return -EINVAL;
10272 }
10273
10274 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
10275
10276 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) {
10277 admitted_time =
10278 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]);
10279 if (!admitted_time)
10280 return -EINVAL;
10281 }
10282
10283 wdev_lock(wdev);
10284 switch (wdev->iftype) {
10285 case NL80211_IFTYPE_STATION:
10286 case NL80211_IFTYPE_P2P_CLIENT:
10287 if (wdev->current_bss)
10288 break;
10289 err = -ENOTCONN;
10290 goto out;
10291 default:
10292 err = -EOPNOTSUPP;
10293 goto out;
10294 }
10295
10296 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time);
10297
10298 out:
10299 wdev_unlock(wdev);
10300 return err;
10301}
10302
10303static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info)
10304{
10305 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10306 struct net_device *dev = info->user_ptr[1];
10307 struct wireless_dev *wdev = dev->ieee80211_ptr;
10308 const u8 *peer;
10309 u8 tsid;
10310 int err;
10311
10312 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC])
10313 return -EINVAL;
10314
10315 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
10316 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
10317
10318 wdev_lock(wdev);
10319 err = rdev_del_tx_ts(rdev, dev, tsid, peer);
10320 wdev_unlock(wdev);
10321
10322 return err;
10323}
10324
1057d35e
AN
10325static int nl80211_tdls_channel_switch(struct sk_buff *skb,
10326 struct genl_info *info)
10327{
10328 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10329 struct net_device *dev = info->user_ptr[1];
10330 struct wireless_dev *wdev = dev->ieee80211_ptr;
10331 struct cfg80211_chan_def chandef = {};
10332 const u8 *addr;
10333 u8 oper_class;
10334 int err;
10335
10336 if (!rdev->ops->tdls_channel_switch ||
10337 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
10338 return -EOPNOTSUPP;
10339
10340 switch (dev->ieee80211_ptr->iftype) {
10341 case NL80211_IFTYPE_STATION:
10342 case NL80211_IFTYPE_P2P_CLIENT:
10343 break;
10344 default:
10345 return -EOPNOTSUPP;
10346 }
10347
10348 if (!info->attrs[NL80211_ATTR_MAC] ||
10349 !info->attrs[NL80211_ATTR_OPER_CLASS])
10350 return -EINVAL;
10351
10352 err = nl80211_parse_chandef(rdev, info, &chandef);
10353 if (err)
10354 return err;
10355
10356 /*
10357 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012
10358 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the
10359 * specification is not defined for them.
10360 */
10361 if (chandef.chan->band == IEEE80211_BAND_2GHZ &&
10362 chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
10363 chandef.width != NL80211_CHAN_WIDTH_20)
10364 return -EINVAL;
10365
10366 /* we will be active on the TDLS link */
923b352f
AN
10367 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
10368 wdev->iftype))
1057d35e
AN
10369 return -EINVAL;
10370
10371 /* don't allow switching to DFS channels */
10372 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype))
10373 return -EINVAL;
10374
10375 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
10376 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]);
10377
10378 wdev_lock(wdev);
10379 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef);
10380 wdev_unlock(wdev);
10381
10382 return err;
10383}
10384
10385static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb,
10386 struct genl_info *info)
10387{
10388 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10389 struct net_device *dev = info->user_ptr[1];
10390 struct wireless_dev *wdev = dev->ieee80211_ptr;
10391 const u8 *addr;
10392
10393 if (!rdev->ops->tdls_channel_switch ||
10394 !rdev->ops->tdls_cancel_channel_switch ||
10395 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
10396 return -EOPNOTSUPP;
10397
10398 switch (dev->ieee80211_ptr->iftype) {
10399 case NL80211_IFTYPE_STATION:
10400 case NL80211_IFTYPE_P2P_CLIENT:
10401 break;
10402 default:
10403 return -EOPNOTSUPP;
10404 }
10405
10406 if (!info->attrs[NL80211_ATTR_MAC])
10407 return -EINVAL;
10408
10409 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
10410
10411 wdev_lock(wdev);
10412 rdev_tdls_cancel_channel_switch(rdev, dev, addr);
10413 wdev_unlock(wdev);
10414
10415 return 0;
10416}
10417
4c476991
JB
10418#define NL80211_FLAG_NEED_WIPHY 0x01
10419#define NL80211_FLAG_NEED_NETDEV 0x02
10420#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
10421#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
10422#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
10423 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 10424#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 10425/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
10426#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
10427 NL80211_FLAG_CHECK_NETDEV_UP)
5393b917 10428#define NL80211_FLAG_CLEAR_SKB 0x20
4c476991 10429
f84f771d 10430static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
10431 struct genl_info *info)
10432{
10433 struct cfg80211_registered_device *rdev;
89a54e48 10434 struct wireless_dev *wdev;
4c476991 10435 struct net_device *dev;
4c476991
JB
10436 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
10437
10438 if (rtnl)
10439 rtnl_lock();
10440
10441 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 10442 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
10443 if (IS_ERR(rdev)) {
10444 if (rtnl)
10445 rtnl_unlock();
10446 return PTR_ERR(rdev);
10447 }
10448 info->user_ptr[0] = rdev;
1bf614ef
JB
10449 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
10450 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
10451 ASSERT_RTNL();
10452
89a54e48
JB
10453 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
10454 info->attrs);
10455 if (IS_ERR(wdev)) {
4c476991
JB
10456 if (rtnl)
10457 rtnl_unlock();
89a54e48 10458 return PTR_ERR(wdev);
4c476991 10459 }
89a54e48 10460
89a54e48 10461 dev = wdev->netdev;
f26cbf40 10462 rdev = wiphy_to_rdev(wdev->wiphy);
89a54e48 10463
1bf614ef
JB
10464 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
10465 if (!dev) {
1bf614ef
JB
10466 if (rtnl)
10467 rtnl_unlock();
10468 return -EINVAL;
10469 }
10470
10471 info->user_ptr[1] = dev;
10472 } else {
10473 info->user_ptr[1] = wdev;
41265714 10474 }
1bf614ef
JB
10475
10476 if (dev) {
10477 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
10478 !netif_running(dev)) {
1bf614ef
JB
10479 if (rtnl)
10480 rtnl_unlock();
10481 return -ENETDOWN;
10482 }
10483
10484 dev_hold(dev);
98104fde
JB
10485 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
10486 if (!wdev->p2p_started) {
98104fde
JB
10487 if (rtnl)
10488 rtnl_unlock();
10489 return -ENETDOWN;
10490 }
41265714 10491 }
89a54e48 10492
4c476991 10493 info->user_ptr[0] = rdev;
4c476991
JB
10494 }
10495
10496 return 0;
10497}
10498
f84f771d 10499static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
10500 struct genl_info *info)
10501{
1bf614ef
JB
10502 if (info->user_ptr[1]) {
10503 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
10504 struct wireless_dev *wdev = info->user_ptr[1];
10505
10506 if (wdev->netdev)
10507 dev_put(wdev->netdev);
10508 } else {
10509 dev_put(info->user_ptr[1]);
10510 }
10511 }
5393b917 10512
4c476991
JB
10513 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
10514 rtnl_unlock();
5393b917
JB
10515
10516 /* If needed, clear the netlink message payload from the SKB
10517 * as it might contain key data that shouldn't stick around on
10518 * the heap after the SKB is freed. The netlink message header
10519 * is still needed for further processing, so leave it intact.
10520 */
10521 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) {
10522 struct nlmsghdr *nlh = nlmsg_hdr(skb);
10523
10524 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh));
10525 }
4c476991
JB
10526}
10527
4534de83 10528static const struct genl_ops nl80211_ops[] = {
55682965
JB
10529 {
10530 .cmd = NL80211_CMD_GET_WIPHY,
10531 .doit = nl80211_get_wiphy,
10532 .dumpit = nl80211_dump_wiphy,
86e8cf98 10533 .done = nl80211_dump_wiphy_done,
55682965
JB
10534 .policy = nl80211_policy,
10535 /* can be retrieved by unprivileged users */
5fe231e8
JB
10536 .internal_flags = NL80211_FLAG_NEED_WIPHY |
10537 NL80211_FLAG_NEED_RTNL,
55682965
JB
10538 },
10539 {
10540 .cmd = NL80211_CMD_SET_WIPHY,
10541 .doit = nl80211_set_wiphy,
10542 .policy = nl80211_policy,
10543 .flags = GENL_ADMIN_PERM,
4c476991 10544 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
10545 },
10546 {
10547 .cmd = NL80211_CMD_GET_INTERFACE,
10548 .doit = nl80211_get_interface,
10549 .dumpit = nl80211_dump_interface,
10550 .policy = nl80211_policy,
10551 /* can be retrieved by unprivileged users */
5fe231e8
JB
10552 .internal_flags = NL80211_FLAG_NEED_WDEV |
10553 NL80211_FLAG_NEED_RTNL,
55682965
JB
10554 },
10555 {
10556 .cmd = NL80211_CMD_SET_INTERFACE,
10557 .doit = nl80211_set_interface,
10558 .policy = nl80211_policy,
10559 .flags = GENL_ADMIN_PERM,
4c476991
JB
10560 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10561 NL80211_FLAG_NEED_RTNL,
55682965
JB
10562 },
10563 {
10564 .cmd = NL80211_CMD_NEW_INTERFACE,
10565 .doit = nl80211_new_interface,
10566 .policy = nl80211_policy,
10567 .flags = GENL_ADMIN_PERM,
4c476991
JB
10568 .internal_flags = NL80211_FLAG_NEED_WIPHY |
10569 NL80211_FLAG_NEED_RTNL,
55682965
JB
10570 },
10571 {
10572 .cmd = NL80211_CMD_DEL_INTERFACE,
10573 .doit = nl80211_del_interface,
10574 .policy = nl80211_policy,
41ade00f 10575 .flags = GENL_ADMIN_PERM,
84efbb84 10576 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 10577 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
10578 },
10579 {
10580 .cmd = NL80211_CMD_GET_KEY,
10581 .doit = nl80211_get_key,
10582 .policy = nl80211_policy,
10583 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10584 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10585 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
10586 },
10587 {
10588 .cmd = NL80211_CMD_SET_KEY,
10589 .doit = nl80211_set_key,
10590 .policy = nl80211_policy,
10591 .flags = GENL_ADMIN_PERM,
41265714 10592 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
10593 NL80211_FLAG_NEED_RTNL |
10594 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
10595 },
10596 {
10597 .cmd = NL80211_CMD_NEW_KEY,
10598 .doit = nl80211_new_key,
10599 .policy = nl80211_policy,
10600 .flags = GENL_ADMIN_PERM,
41265714 10601 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
10602 NL80211_FLAG_NEED_RTNL |
10603 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
10604 },
10605 {
10606 .cmd = NL80211_CMD_DEL_KEY,
10607 .doit = nl80211_del_key,
10608 .policy = nl80211_policy,
55682965 10609 .flags = GENL_ADMIN_PERM,
41265714 10610 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10611 NL80211_FLAG_NEED_RTNL,
55682965 10612 },
ed1b6cc7
JB
10613 {
10614 .cmd = NL80211_CMD_SET_BEACON,
10615 .policy = nl80211_policy,
10616 .flags = GENL_ADMIN_PERM,
8860020e 10617 .doit = nl80211_set_beacon,
2b5f8b0b 10618 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10619 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
10620 },
10621 {
8860020e 10622 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
10623 .policy = nl80211_policy,
10624 .flags = GENL_ADMIN_PERM,
8860020e 10625 .doit = nl80211_start_ap,
2b5f8b0b 10626 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10627 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
10628 },
10629 {
8860020e 10630 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
10631 .policy = nl80211_policy,
10632 .flags = GENL_ADMIN_PERM,
8860020e 10633 .doit = nl80211_stop_ap,
2b5f8b0b 10634 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10635 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 10636 },
5727ef1b
JB
10637 {
10638 .cmd = NL80211_CMD_GET_STATION,
10639 .doit = nl80211_get_station,
2ec600d6 10640 .dumpit = nl80211_dump_station,
5727ef1b 10641 .policy = nl80211_policy,
4c476991
JB
10642 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10643 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
10644 },
10645 {
10646 .cmd = NL80211_CMD_SET_STATION,
10647 .doit = nl80211_set_station,
10648 .policy = nl80211_policy,
10649 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10650 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10651 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
10652 },
10653 {
10654 .cmd = NL80211_CMD_NEW_STATION,
10655 .doit = nl80211_new_station,
10656 .policy = nl80211_policy,
10657 .flags = GENL_ADMIN_PERM,
41265714 10658 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10659 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
10660 },
10661 {
10662 .cmd = NL80211_CMD_DEL_STATION,
10663 .doit = nl80211_del_station,
10664 .policy = nl80211_policy,
2ec600d6 10665 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10666 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10667 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
10668 },
10669 {
10670 .cmd = NL80211_CMD_GET_MPATH,
10671 .doit = nl80211_get_mpath,
10672 .dumpit = nl80211_dump_mpath,
10673 .policy = nl80211_policy,
10674 .flags = GENL_ADMIN_PERM,
41265714 10675 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10676 NL80211_FLAG_NEED_RTNL,
2ec600d6 10677 },
66be7d2b
HR
10678 {
10679 .cmd = NL80211_CMD_GET_MPP,
10680 .doit = nl80211_get_mpp,
10681 .dumpit = nl80211_dump_mpp,
10682 .policy = nl80211_policy,
10683 .flags = GENL_ADMIN_PERM,
10684 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
10685 NL80211_FLAG_NEED_RTNL,
10686 },
2ec600d6
LCC
10687 {
10688 .cmd = NL80211_CMD_SET_MPATH,
10689 .doit = nl80211_set_mpath,
10690 .policy = nl80211_policy,
10691 .flags = GENL_ADMIN_PERM,
41265714 10692 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10693 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
10694 },
10695 {
10696 .cmd = NL80211_CMD_NEW_MPATH,
10697 .doit = nl80211_new_mpath,
10698 .policy = nl80211_policy,
10699 .flags = GENL_ADMIN_PERM,
41265714 10700 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10701 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
10702 },
10703 {
10704 .cmd = NL80211_CMD_DEL_MPATH,
10705 .doit = nl80211_del_mpath,
10706 .policy = nl80211_policy,
9f1ba906 10707 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10708 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10709 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
10710 },
10711 {
10712 .cmd = NL80211_CMD_SET_BSS,
10713 .doit = nl80211_set_bss,
10714 .policy = nl80211_policy,
b2e1b302 10715 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10716 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10717 NL80211_FLAG_NEED_RTNL,
b2e1b302 10718 },
f130347c
LR
10719 {
10720 .cmd = NL80211_CMD_GET_REG,
ad30ca2c
AN
10721 .doit = nl80211_get_reg_do,
10722 .dumpit = nl80211_get_reg_dump,
f130347c 10723 .policy = nl80211_policy,
5fe231e8 10724 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
10725 /* can be retrieved by unprivileged users */
10726 },
b2e1b302
LR
10727 {
10728 .cmd = NL80211_CMD_SET_REG,
10729 .doit = nl80211_set_reg,
10730 .policy = nl80211_policy,
10731 .flags = GENL_ADMIN_PERM,
5fe231e8 10732 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302
LR
10733 },
10734 {
10735 .cmd = NL80211_CMD_REQ_SET_REG,
10736 .doit = nl80211_req_set_reg,
10737 .policy = nl80211_policy,
93da9cc1 10738 .flags = GENL_ADMIN_PERM,
10739 },
10740 {
24bdd9f4
JC
10741 .cmd = NL80211_CMD_GET_MESH_CONFIG,
10742 .doit = nl80211_get_mesh_config,
93da9cc1 10743 .policy = nl80211_policy,
10744 /* can be retrieved by unprivileged users */
2b5f8b0b 10745 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10746 NL80211_FLAG_NEED_RTNL,
93da9cc1 10747 },
10748 {
24bdd9f4
JC
10749 .cmd = NL80211_CMD_SET_MESH_CONFIG,
10750 .doit = nl80211_update_mesh_config,
93da9cc1 10751 .policy = nl80211_policy,
9aed3cc1 10752 .flags = GENL_ADMIN_PERM,
29cbe68c 10753 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10754 NL80211_FLAG_NEED_RTNL,
9aed3cc1 10755 },
2a519311
JB
10756 {
10757 .cmd = NL80211_CMD_TRIGGER_SCAN,
10758 .doit = nl80211_trigger_scan,
10759 .policy = nl80211_policy,
10760 .flags = GENL_ADMIN_PERM,
fd014284 10761 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 10762 NL80211_FLAG_NEED_RTNL,
2a519311
JB
10763 },
10764 {
10765 .cmd = NL80211_CMD_GET_SCAN,
10766 .policy = nl80211_policy,
10767 .dumpit = nl80211_dump_scan,
10768 },
807f8a8c
LC
10769 {
10770 .cmd = NL80211_CMD_START_SCHED_SCAN,
10771 .doit = nl80211_start_sched_scan,
10772 .policy = nl80211_policy,
10773 .flags = GENL_ADMIN_PERM,
10774 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
10775 NL80211_FLAG_NEED_RTNL,
10776 },
10777 {
10778 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
10779 .doit = nl80211_stop_sched_scan,
10780 .policy = nl80211_policy,
10781 .flags = GENL_ADMIN_PERM,
10782 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
10783 NL80211_FLAG_NEED_RTNL,
10784 },
636a5d36
JM
10785 {
10786 .cmd = NL80211_CMD_AUTHENTICATE,
10787 .doit = nl80211_authenticate,
10788 .policy = nl80211_policy,
10789 .flags = GENL_ADMIN_PERM,
41265714 10790 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
10791 NL80211_FLAG_NEED_RTNL |
10792 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
10793 },
10794 {
10795 .cmd = NL80211_CMD_ASSOCIATE,
10796 .doit = nl80211_associate,
10797 .policy = nl80211_policy,
10798 .flags = GENL_ADMIN_PERM,
41265714 10799 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10800 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
10801 },
10802 {
10803 .cmd = NL80211_CMD_DEAUTHENTICATE,
10804 .doit = nl80211_deauthenticate,
10805 .policy = nl80211_policy,
10806 .flags = GENL_ADMIN_PERM,
41265714 10807 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10808 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
10809 },
10810 {
10811 .cmd = NL80211_CMD_DISASSOCIATE,
10812 .doit = nl80211_disassociate,
10813 .policy = nl80211_policy,
10814 .flags = GENL_ADMIN_PERM,
41265714 10815 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10816 NL80211_FLAG_NEED_RTNL,
636a5d36 10817 },
04a773ad
JB
10818 {
10819 .cmd = NL80211_CMD_JOIN_IBSS,
10820 .doit = nl80211_join_ibss,
10821 .policy = nl80211_policy,
10822 .flags = GENL_ADMIN_PERM,
41265714 10823 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10824 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
10825 },
10826 {
10827 .cmd = NL80211_CMD_LEAVE_IBSS,
10828 .doit = nl80211_leave_ibss,
10829 .policy = nl80211_policy,
10830 .flags = GENL_ADMIN_PERM,
41265714 10831 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10832 NL80211_FLAG_NEED_RTNL,
04a773ad 10833 },
aff89a9b
JB
10834#ifdef CONFIG_NL80211_TESTMODE
10835 {
10836 .cmd = NL80211_CMD_TESTMODE,
10837 .doit = nl80211_testmode_do,
71063f0e 10838 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
10839 .policy = nl80211_policy,
10840 .flags = GENL_ADMIN_PERM,
4c476991
JB
10841 .internal_flags = NL80211_FLAG_NEED_WIPHY |
10842 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
10843 },
10844#endif
b23aa676
SO
10845 {
10846 .cmd = NL80211_CMD_CONNECT,
10847 .doit = nl80211_connect,
10848 .policy = nl80211_policy,
10849 .flags = GENL_ADMIN_PERM,
41265714 10850 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10851 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
10852 },
10853 {
10854 .cmd = NL80211_CMD_DISCONNECT,
10855 .doit = nl80211_disconnect,
10856 .policy = nl80211_policy,
10857 .flags = GENL_ADMIN_PERM,
41265714 10858 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10859 NL80211_FLAG_NEED_RTNL,
b23aa676 10860 },
463d0183
JB
10861 {
10862 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
10863 .doit = nl80211_wiphy_netns,
10864 .policy = nl80211_policy,
10865 .flags = GENL_ADMIN_PERM,
4c476991
JB
10866 .internal_flags = NL80211_FLAG_NEED_WIPHY |
10867 NL80211_FLAG_NEED_RTNL,
463d0183 10868 },
61fa713c
HS
10869 {
10870 .cmd = NL80211_CMD_GET_SURVEY,
10871 .policy = nl80211_policy,
10872 .dumpit = nl80211_dump_survey,
10873 },
67fbb16b
SO
10874 {
10875 .cmd = NL80211_CMD_SET_PMKSA,
10876 .doit = nl80211_setdel_pmksa,
10877 .policy = nl80211_policy,
10878 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10879 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10880 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
10881 },
10882 {
10883 .cmd = NL80211_CMD_DEL_PMKSA,
10884 .doit = nl80211_setdel_pmksa,
10885 .policy = nl80211_policy,
10886 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10887 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10888 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
10889 },
10890 {
10891 .cmd = NL80211_CMD_FLUSH_PMKSA,
10892 .doit = nl80211_flush_pmksa,
10893 .policy = nl80211_policy,
10894 .flags = GENL_ADMIN_PERM,
2b5f8b0b 10895 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 10896 NL80211_FLAG_NEED_RTNL,
67fbb16b 10897 },
9588bbd5
JM
10898 {
10899 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
10900 .doit = nl80211_remain_on_channel,
10901 .policy = nl80211_policy,
10902 .flags = GENL_ADMIN_PERM,
71bbc994 10903 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 10904 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
10905 },
10906 {
10907 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
10908 .doit = nl80211_cancel_remain_on_channel,
10909 .policy = nl80211_policy,
10910 .flags = GENL_ADMIN_PERM,
71bbc994 10911 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 10912 NL80211_FLAG_NEED_RTNL,
9588bbd5 10913 },
13ae75b1
JM
10914 {
10915 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
10916 .doit = nl80211_set_tx_bitrate_mask,
10917 .policy = nl80211_policy,
10918 .flags = GENL_ADMIN_PERM,
4c476991
JB
10919 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10920 NL80211_FLAG_NEED_RTNL,
13ae75b1 10921 },
026331c4 10922 {
2e161f78
JB
10923 .cmd = NL80211_CMD_REGISTER_FRAME,
10924 .doit = nl80211_register_mgmt,
026331c4
JM
10925 .policy = nl80211_policy,
10926 .flags = GENL_ADMIN_PERM,
71bbc994 10927 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 10928 NL80211_FLAG_NEED_RTNL,
026331c4
JM
10929 },
10930 {
2e161f78
JB
10931 .cmd = NL80211_CMD_FRAME,
10932 .doit = nl80211_tx_mgmt,
026331c4 10933 .policy = nl80211_policy,
f7ca38df 10934 .flags = GENL_ADMIN_PERM,
71bbc994 10935 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
10936 NL80211_FLAG_NEED_RTNL,
10937 },
10938 {
10939 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
10940 .doit = nl80211_tx_mgmt_cancel_wait,
10941 .policy = nl80211_policy,
026331c4 10942 .flags = GENL_ADMIN_PERM,
71bbc994 10943 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 10944 NL80211_FLAG_NEED_RTNL,
026331c4 10945 },
ffb9eb3d
KV
10946 {
10947 .cmd = NL80211_CMD_SET_POWER_SAVE,
10948 .doit = nl80211_set_power_save,
10949 .policy = nl80211_policy,
10950 .flags = GENL_ADMIN_PERM,
4c476991
JB
10951 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10952 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
10953 },
10954 {
10955 .cmd = NL80211_CMD_GET_POWER_SAVE,
10956 .doit = nl80211_get_power_save,
10957 .policy = nl80211_policy,
10958 /* can be retrieved by unprivileged users */
4c476991
JB
10959 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10960 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 10961 },
d6dc1a38
JO
10962 {
10963 .cmd = NL80211_CMD_SET_CQM,
10964 .doit = nl80211_set_cqm,
10965 .policy = nl80211_policy,
10966 .flags = GENL_ADMIN_PERM,
4c476991
JB
10967 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10968 NL80211_FLAG_NEED_RTNL,
d6dc1a38 10969 },
f444de05
JB
10970 {
10971 .cmd = NL80211_CMD_SET_CHANNEL,
10972 .doit = nl80211_set_channel,
10973 .policy = nl80211_policy,
10974 .flags = GENL_ADMIN_PERM,
4c476991
JB
10975 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10976 NL80211_FLAG_NEED_RTNL,
f444de05 10977 },
e8347eba
BJ
10978 {
10979 .cmd = NL80211_CMD_SET_WDS_PEER,
10980 .doit = nl80211_set_wds_peer,
10981 .policy = nl80211_policy,
10982 .flags = GENL_ADMIN_PERM,
43b19952
JB
10983 .internal_flags = NL80211_FLAG_NEED_NETDEV |
10984 NL80211_FLAG_NEED_RTNL,
e8347eba 10985 },
29cbe68c
JB
10986 {
10987 .cmd = NL80211_CMD_JOIN_MESH,
10988 .doit = nl80211_join_mesh,
10989 .policy = nl80211_policy,
10990 .flags = GENL_ADMIN_PERM,
10991 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
10992 NL80211_FLAG_NEED_RTNL,
10993 },
10994 {
10995 .cmd = NL80211_CMD_LEAVE_MESH,
10996 .doit = nl80211_leave_mesh,
10997 .policy = nl80211_policy,
10998 .flags = GENL_ADMIN_PERM,
10999 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11000 NL80211_FLAG_NEED_RTNL,
11001 },
6e0bd6c3
RL
11002 {
11003 .cmd = NL80211_CMD_JOIN_OCB,
11004 .doit = nl80211_join_ocb,
11005 .policy = nl80211_policy,
11006 .flags = GENL_ADMIN_PERM,
11007 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11008 NL80211_FLAG_NEED_RTNL,
11009 },
11010 {
11011 .cmd = NL80211_CMD_LEAVE_OCB,
11012 .doit = nl80211_leave_ocb,
11013 .policy = nl80211_policy,
11014 .flags = GENL_ADMIN_PERM,
11015 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11016 NL80211_FLAG_NEED_RTNL,
11017 },
dfb89c56 11018#ifdef CONFIG_PM
ff1b6e69
JB
11019 {
11020 .cmd = NL80211_CMD_GET_WOWLAN,
11021 .doit = nl80211_get_wowlan,
11022 .policy = nl80211_policy,
11023 /* can be retrieved by unprivileged users */
11024 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11025 NL80211_FLAG_NEED_RTNL,
11026 },
11027 {
11028 .cmd = NL80211_CMD_SET_WOWLAN,
11029 .doit = nl80211_set_wowlan,
11030 .policy = nl80211_policy,
11031 .flags = GENL_ADMIN_PERM,
11032 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11033 NL80211_FLAG_NEED_RTNL,
11034 },
dfb89c56 11035#endif
e5497d76
JB
11036 {
11037 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
11038 .doit = nl80211_set_rekey_data,
11039 .policy = nl80211_policy,
11040 .flags = GENL_ADMIN_PERM,
11041 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
11042 NL80211_FLAG_NEED_RTNL |
11043 NL80211_FLAG_CLEAR_SKB,
e5497d76 11044 },
109086ce
AN
11045 {
11046 .cmd = NL80211_CMD_TDLS_MGMT,
11047 .doit = nl80211_tdls_mgmt,
11048 .policy = nl80211_policy,
11049 .flags = GENL_ADMIN_PERM,
11050 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11051 NL80211_FLAG_NEED_RTNL,
11052 },
11053 {
11054 .cmd = NL80211_CMD_TDLS_OPER,
11055 .doit = nl80211_tdls_oper,
11056 .policy = nl80211_policy,
11057 .flags = GENL_ADMIN_PERM,
11058 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11059 NL80211_FLAG_NEED_RTNL,
11060 },
28946da7
JB
11061 {
11062 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
11063 .doit = nl80211_register_unexpected_frame,
11064 .policy = nl80211_policy,
11065 .flags = GENL_ADMIN_PERM,
11066 .internal_flags = NL80211_FLAG_NEED_NETDEV |
11067 NL80211_FLAG_NEED_RTNL,
11068 },
7f6cf311
JB
11069 {
11070 .cmd = NL80211_CMD_PROBE_CLIENT,
11071 .doit = nl80211_probe_client,
11072 .policy = nl80211_policy,
11073 .flags = GENL_ADMIN_PERM,
2b5f8b0b 11074 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
11075 NL80211_FLAG_NEED_RTNL,
11076 },
5e760230
JB
11077 {
11078 .cmd = NL80211_CMD_REGISTER_BEACONS,
11079 .doit = nl80211_register_beacons,
11080 .policy = nl80211_policy,
11081 .flags = GENL_ADMIN_PERM,
11082 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11083 NL80211_FLAG_NEED_RTNL,
11084 },
1d9d9213
SW
11085 {
11086 .cmd = NL80211_CMD_SET_NOACK_MAP,
11087 .doit = nl80211_set_noack_map,
11088 .policy = nl80211_policy,
11089 .flags = GENL_ADMIN_PERM,
11090 .internal_flags = NL80211_FLAG_NEED_NETDEV |
11091 NL80211_FLAG_NEED_RTNL,
11092 },
98104fde
JB
11093 {
11094 .cmd = NL80211_CMD_START_P2P_DEVICE,
11095 .doit = nl80211_start_p2p_device,
11096 .policy = nl80211_policy,
11097 .flags = GENL_ADMIN_PERM,
11098 .internal_flags = NL80211_FLAG_NEED_WDEV |
11099 NL80211_FLAG_NEED_RTNL,
11100 },
11101 {
11102 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
11103 .doit = nl80211_stop_p2p_device,
11104 .policy = nl80211_policy,
11105 .flags = GENL_ADMIN_PERM,
11106 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
11107 NL80211_FLAG_NEED_RTNL,
11108 },
f4e583c8
AQ
11109 {
11110 .cmd = NL80211_CMD_SET_MCAST_RATE,
11111 .doit = nl80211_set_mcast_rate,
77765eaf
VT
11112 .policy = nl80211_policy,
11113 .flags = GENL_ADMIN_PERM,
11114 .internal_flags = NL80211_FLAG_NEED_NETDEV |
11115 NL80211_FLAG_NEED_RTNL,
11116 },
11117 {
11118 .cmd = NL80211_CMD_SET_MAC_ACL,
11119 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
11120 .policy = nl80211_policy,
11121 .flags = GENL_ADMIN_PERM,
11122 .internal_flags = NL80211_FLAG_NEED_NETDEV |
11123 NL80211_FLAG_NEED_RTNL,
11124 },
04f39047
SW
11125 {
11126 .cmd = NL80211_CMD_RADAR_DETECT,
11127 .doit = nl80211_start_radar_detection,
11128 .policy = nl80211_policy,
11129 .flags = GENL_ADMIN_PERM,
11130 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11131 NL80211_FLAG_NEED_RTNL,
11132 },
3713b4e3
JB
11133 {
11134 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
11135 .doit = nl80211_get_protocol_features,
11136 .policy = nl80211_policy,
11137 },
355199e0
JM
11138 {
11139 .cmd = NL80211_CMD_UPDATE_FT_IES,
11140 .doit = nl80211_update_ft_ies,
11141 .policy = nl80211_policy,
11142 .flags = GENL_ADMIN_PERM,
11143 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11144 NL80211_FLAG_NEED_RTNL,
11145 },
5de17984
AS
11146 {
11147 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
11148 .doit = nl80211_crit_protocol_start,
11149 .policy = nl80211_policy,
11150 .flags = GENL_ADMIN_PERM,
11151 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
11152 NL80211_FLAG_NEED_RTNL,
11153 },
11154 {
11155 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
11156 .doit = nl80211_crit_protocol_stop,
11157 .policy = nl80211_policy,
11158 .flags = GENL_ADMIN_PERM,
11159 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
11160 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
11161 },
11162 {
11163 .cmd = NL80211_CMD_GET_COALESCE,
11164 .doit = nl80211_get_coalesce,
11165 .policy = nl80211_policy,
11166 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11167 NL80211_FLAG_NEED_RTNL,
11168 },
11169 {
11170 .cmd = NL80211_CMD_SET_COALESCE,
11171 .doit = nl80211_set_coalesce,
11172 .policy = nl80211_policy,
11173 .flags = GENL_ADMIN_PERM,
11174 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11175 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
11176 },
11177 {
11178 .cmd = NL80211_CMD_CHANNEL_SWITCH,
11179 .doit = nl80211_channel_switch,
11180 .policy = nl80211_policy,
11181 .flags = GENL_ADMIN_PERM,
11182 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11183 NL80211_FLAG_NEED_RTNL,
11184 },
ad7e718c
JB
11185 {
11186 .cmd = NL80211_CMD_VENDOR,
11187 .doit = nl80211_vendor_cmd,
7bdbe400 11188 .dumpit = nl80211_vendor_cmd_dump,
ad7e718c
JB
11189 .policy = nl80211_policy,
11190 .flags = GENL_ADMIN_PERM,
11191 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11192 NL80211_FLAG_NEED_RTNL,
11193 },
fa9ffc74
KP
11194 {
11195 .cmd = NL80211_CMD_SET_QOS_MAP,
11196 .doit = nl80211_set_qos_map,
11197 .policy = nl80211_policy,
11198 .flags = GENL_ADMIN_PERM,
11199 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11200 NL80211_FLAG_NEED_RTNL,
11201 },
960d01ac
JB
11202 {
11203 .cmd = NL80211_CMD_ADD_TX_TS,
11204 .doit = nl80211_add_tx_ts,
11205 .policy = nl80211_policy,
11206 .flags = GENL_ADMIN_PERM,
11207 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11208 NL80211_FLAG_NEED_RTNL,
11209 },
11210 {
11211 .cmd = NL80211_CMD_DEL_TX_TS,
11212 .doit = nl80211_del_tx_ts,
11213 .policy = nl80211_policy,
11214 .flags = GENL_ADMIN_PERM,
11215 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11216 NL80211_FLAG_NEED_RTNL,
11217 },
1057d35e
AN
11218 {
11219 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH,
11220 .doit = nl80211_tdls_channel_switch,
11221 .policy = nl80211_policy,
11222 .flags = GENL_ADMIN_PERM,
11223 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11224 NL80211_FLAG_NEED_RTNL,
11225 },
11226 {
11227 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH,
11228 .doit = nl80211_tdls_cancel_channel_switch,
11229 .policy = nl80211_policy,
11230 .flags = GENL_ADMIN_PERM,
11231 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
11232 NL80211_FLAG_NEED_RTNL,
11233 },
55682965 11234};
9588bbd5 11235
55682965
JB
11236/* notification functions */
11237
3bb20556
JB
11238void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev,
11239 enum nl80211_commands cmd)
55682965
JB
11240{
11241 struct sk_buff *msg;
86e8cf98 11242 struct nl80211_dump_wiphy_state state = {};
55682965 11243
3bb20556
JB
11244 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY &&
11245 cmd != NL80211_CMD_DEL_WIPHY);
11246
fd2120ca 11247 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
11248 if (!msg)
11249 return;
11250
3bb20556 11251 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) {
55682965
JB
11252 nlmsg_free(msg);
11253 return;
11254 }
11255
68eb5503 11256 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11257 NL80211_MCGRP_CONFIG, GFP_KERNEL);
55682965
JB
11258}
11259
362a415d
JB
11260static int nl80211_add_scan_req(struct sk_buff *msg,
11261 struct cfg80211_registered_device *rdev)
11262{
11263 struct cfg80211_scan_request *req = rdev->scan_req;
11264 struct nlattr *nest;
11265 int i;
11266
11267 if (WARN_ON(!req))
11268 return 0;
11269
11270 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
11271 if (!nest)
11272 goto nla_put_failure;
9360ffd1
DM
11273 for (i = 0; i < req->n_ssids; i++) {
11274 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
11275 goto nla_put_failure;
11276 }
362a415d
JB
11277 nla_nest_end(msg, nest);
11278
11279 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
11280 if (!nest)
11281 goto nla_put_failure;
9360ffd1
DM
11282 for (i = 0; i < req->n_channels; i++) {
11283 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
11284 goto nla_put_failure;
11285 }
362a415d
JB
11286 nla_nest_end(msg, nest);
11287
9360ffd1
DM
11288 if (req->ie &&
11289 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
11290 goto nla_put_failure;
362a415d 11291
ae917c9f
JB
11292 if (req->flags &&
11293 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
11294 goto nla_put_failure;
ed473771 11295
362a415d
JB
11296 return 0;
11297 nla_put_failure:
11298 return -ENOBUFS;
11299}
11300
a538e2d5
JB
11301static int nl80211_send_scan_msg(struct sk_buff *msg,
11302 struct cfg80211_registered_device *rdev,
fd014284 11303 struct wireless_dev *wdev,
15e47304 11304 u32 portid, u32 seq, int flags,
a538e2d5 11305 u32 cmd)
2a519311
JB
11306{
11307 void *hdr;
11308
15e47304 11309 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
11310 if (!hdr)
11311 return -1;
11312
9360ffd1 11313 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
11314 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11315 wdev->netdev->ifindex)) ||
11316 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 11317 goto nla_put_failure;
2a519311 11318
362a415d
JB
11319 /* ignore errors and send incomplete event anyway */
11320 nl80211_add_scan_req(msg, rdev);
2a519311 11321
053c095a
JB
11322 genlmsg_end(msg, hdr);
11323 return 0;
2a519311
JB
11324
11325 nla_put_failure:
11326 genlmsg_cancel(msg, hdr);
11327 return -EMSGSIZE;
11328}
11329
807f8a8c
LC
11330static int
11331nl80211_send_sched_scan_msg(struct sk_buff *msg,
11332 struct cfg80211_registered_device *rdev,
11333 struct net_device *netdev,
15e47304 11334 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
11335{
11336 void *hdr;
11337
15e47304 11338 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
11339 if (!hdr)
11340 return -1;
11341
9360ffd1
DM
11342 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11343 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
11344 goto nla_put_failure;
807f8a8c 11345
053c095a
JB
11346 genlmsg_end(msg, hdr);
11347 return 0;
807f8a8c
LC
11348
11349 nla_put_failure:
11350 genlmsg_cancel(msg, hdr);
11351 return -EMSGSIZE;
11352}
11353
a538e2d5 11354void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 11355 struct wireless_dev *wdev)
a538e2d5
JB
11356{
11357 struct sk_buff *msg;
11358
58050fce 11359 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
11360 if (!msg)
11361 return;
11362
fd014284 11363 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
11364 NL80211_CMD_TRIGGER_SCAN) < 0) {
11365 nlmsg_free(msg);
11366 return;
11367 }
11368
68eb5503 11369 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11370 NL80211_MCGRP_SCAN, GFP_KERNEL);
a538e2d5
JB
11371}
11372
f9d15d16
JB
11373struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev,
11374 struct wireless_dev *wdev, bool aborted)
2a519311
JB
11375{
11376 struct sk_buff *msg;
11377
fd2120ca 11378 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311 11379 if (!msg)
f9d15d16 11380 return NULL;
2a519311 11381
fd014284 11382 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
f9d15d16
JB
11383 aborted ? NL80211_CMD_SCAN_ABORTED :
11384 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311 11385 nlmsg_free(msg);
f9d15d16 11386 return NULL;
2a519311
JB
11387 }
11388
f9d15d16 11389 return msg;
2a519311
JB
11390}
11391
f9d15d16
JB
11392void nl80211_send_scan_result(struct cfg80211_registered_device *rdev,
11393 struct sk_buff *msg)
2a519311 11394{
2a519311
JB
11395 if (!msg)
11396 return;
11397
68eb5503 11398 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11399 NL80211_MCGRP_SCAN, GFP_KERNEL);
2a519311
JB
11400}
11401
807f8a8c
LC
11402void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
11403 struct net_device *netdev)
11404{
11405 struct sk_buff *msg;
11406
11407 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11408 if (!msg)
11409 return;
11410
11411 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
11412 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
11413 nlmsg_free(msg);
11414 return;
11415 }
11416
68eb5503 11417 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11418 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
11419}
11420
11421void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
11422 struct net_device *netdev, u32 cmd)
11423{
11424 struct sk_buff *msg;
11425
58050fce 11426 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
11427 if (!msg)
11428 return;
11429
11430 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
11431 nlmsg_free(msg);
11432 return;
11433 }
11434
68eb5503 11435 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11436 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
11437}
11438
b0d7aa59
JD
11439static bool nl80211_reg_change_event_fill(struct sk_buff *msg,
11440 struct regulatory_request *request)
73d54c9e 11441{
73d54c9e 11442 /* Userspace can always count this one always being set */
9360ffd1
DM
11443 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
11444 goto nla_put_failure;
11445
11446 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
11447 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
11448 NL80211_REGDOM_TYPE_WORLD))
11449 goto nla_put_failure;
11450 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
11451 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
11452 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
11453 goto nla_put_failure;
11454 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
11455 request->intersect) {
11456 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
11457 NL80211_REGDOM_TYPE_INTERSECTION))
11458 goto nla_put_failure;
11459 } else {
11460 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
11461 NL80211_REGDOM_TYPE_COUNTRY) ||
11462 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
11463 request->alpha2))
11464 goto nla_put_failure;
11465 }
11466
ad30ca2c
AN
11467 if (request->wiphy_idx != WIPHY_IDX_INVALID) {
11468 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx);
11469
11470 if (wiphy &&
11471 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
11472 goto nla_put_failure;
1bdd716c
AN
11473
11474 if (wiphy &&
11475 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
11476 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
11477 goto nla_put_failure;
ad30ca2c 11478 }
73d54c9e 11479
b0d7aa59
JD
11480 return true;
11481
11482nla_put_failure:
11483 return false;
11484}
11485
11486/*
11487 * This can happen on global regulatory changes or device specific settings
11488 * based on custom regulatory domains.
11489 */
11490void nl80211_common_reg_change_event(enum nl80211_commands cmd_id,
11491 struct regulatory_request *request)
11492{
11493 struct sk_buff *msg;
11494 void *hdr;
11495
11496 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11497 if (!msg)
11498 return;
11499
11500 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id);
11501 if (!hdr) {
11502 nlmsg_free(msg);
11503 return;
11504 }
11505
11506 if (nl80211_reg_change_event_fill(msg, request) == false)
11507 goto nla_put_failure;
11508
3b7b72ee 11509 genlmsg_end(msg, hdr);
73d54c9e 11510
bc43b28c 11511 rcu_read_lock();
68eb5503 11512 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 11513 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
bc43b28c 11514 rcu_read_unlock();
73d54c9e
LR
11515
11516 return;
11517
11518nla_put_failure:
11519 genlmsg_cancel(msg, hdr);
11520 nlmsg_free(msg);
11521}
11522
6039f6d2
JM
11523static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
11524 struct net_device *netdev,
11525 const u8 *buf, size_t len,
b0b6aa2c
EP
11526 enum nl80211_commands cmd, gfp_t gfp,
11527 int uapsd_queues)
6039f6d2
JM
11528{
11529 struct sk_buff *msg;
11530 void *hdr;
11531
e6d6e342 11532 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
11533 if (!msg)
11534 return;
11535
11536 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
11537 if (!hdr) {
11538 nlmsg_free(msg);
11539 return;
11540 }
11541
9360ffd1
DM
11542 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11543 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11544 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
11545 goto nla_put_failure;
6039f6d2 11546
b0b6aa2c
EP
11547 if (uapsd_queues >= 0) {
11548 struct nlattr *nla_wmm =
11549 nla_nest_start(msg, NL80211_ATTR_STA_WME);
11550 if (!nla_wmm)
11551 goto nla_put_failure;
11552
11553 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
11554 uapsd_queues))
11555 goto nla_put_failure;
11556
11557 nla_nest_end(msg, nla_wmm);
11558 }
11559
3b7b72ee 11560 genlmsg_end(msg, hdr);
6039f6d2 11561
68eb5503 11562 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11563 NL80211_MCGRP_MLME, gfp);
6039f6d2
JM
11564 return;
11565
11566 nla_put_failure:
11567 genlmsg_cancel(msg, hdr);
11568 nlmsg_free(msg);
11569}
11570
11571void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
11572 struct net_device *netdev, const u8 *buf,
11573 size_t len, gfp_t gfp)
6039f6d2
JM
11574{
11575 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 11576 NL80211_CMD_AUTHENTICATE, gfp, -1);
6039f6d2
JM
11577}
11578
11579void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
11580 struct net_device *netdev, const u8 *buf,
b0b6aa2c 11581 size_t len, gfp_t gfp, int uapsd_queues)
6039f6d2 11582{
e6d6e342 11583 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 11584 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues);
6039f6d2
JM
11585}
11586
53b46b84 11587void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
11588 struct net_device *netdev, const u8 *buf,
11589 size_t len, gfp_t gfp)
6039f6d2
JM
11590{
11591 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 11592 NL80211_CMD_DEAUTHENTICATE, gfp, -1);
6039f6d2
JM
11593}
11594
53b46b84
JM
11595void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
11596 struct net_device *netdev, const u8 *buf,
e6d6e342 11597 size_t len, gfp_t gfp)
6039f6d2
JM
11598{
11599 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 11600 NL80211_CMD_DISASSOCIATE, gfp, -1);
6039f6d2
JM
11601}
11602
6ff57cf8
JB
11603void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
11604 size_t len)
cf4e594e 11605{
947add36
JB
11606 struct wireless_dev *wdev = dev->ieee80211_ptr;
11607 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 11608 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
6ff57cf8
JB
11609 const struct ieee80211_mgmt *mgmt = (void *)buf;
11610 u32 cmd;
947add36 11611
6ff57cf8
JB
11612 if (WARN_ON(len < 2))
11613 return;
cf4e594e 11614
6ff57cf8
JB
11615 if (ieee80211_is_deauth(mgmt->frame_control))
11616 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
11617 else
11618 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 11619
6ff57cf8 11620 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
b0b6aa2c 11621 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1);
cf4e594e 11622}
6ff57cf8 11623EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 11624
1b06bb40
LR
11625static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
11626 struct net_device *netdev, int cmd,
e6d6e342 11627 const u8 *addr, gfp_t gfp)
1965c853
JM
11628{
11629 struct sk_buff *msg;
11630 void *hdr;
11631
e6d6e342 11632 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
11633 if (!msg)
11634 return;
11635
11636 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
11637 if (!hdr) {
11638 nlmsg_free(msg);
11639 return;
11640 }
11641
9360ffd1
DM
11642 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11643 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11644 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
11645 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
11646 goto nla_put_failure;
1965c853 11647
3b7b72ee 11648 genlmsg_end(msg, hdr);
1965c853 11649
68eb5503 11650 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11651 NL80211_MCGRP_MLME, gfp);
1965c853
JM
11652 return;
11653
11654 nla_put_failure:
11655 genlmsg_cancel(msg, hdr);
11656 nlmsg_free(msg);
11657}
11658
11659void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
11660 struct net_device *netdev, const u8 *addr,
11661 gfp_t gfp)
1965c853
JM
11662{
11663 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 11664 addr, gfp);
1965c853
JM
11665}
11666
11667void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
11668 struct net_device *netdev, const u8 *addr,
11669 gfp_t gfp)
1965c853 11670{
e6d6e342
JB
11671 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
11672 addr, gfp);
1965c853
JM
11673}
11674
b23aa676
SO
11675void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
11676 struct net_device *netdev, const u8 *bssid,
11677 const u8 *req_ie, size_t req_ie_len,
11678 const u8 *resp_ie, size_t resp_ie_len,
11679 u16 status, gfp_t gfp)
11680{
11681 struct sk_buff *msg;
11682 void *hdr;
11683
58050fce 11684 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
11685 if (!msg)
11686 return;
11687
11688 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
11689 if (!hdr) {
11690 nlmsg_free(msg);
11691 return;
11692 }
11693
9360ffd1
DM
11694 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11695 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11696 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
11697 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
11698 (req_ie &&
11699 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
11700 (resp_ie &&
11701 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
11702 goto nla_put_failure;
b23aa676 11703
3b7b72ee 11704 genlmsg_end(msg, hdr);
b23aa676 11705
68eb5503 11706 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11707 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
11708 return;
11709
11710 nla_put_failure:
11711 genlmsg_cancel(msg, hdr);
11712 nlmsg_free(msg);
11713
11714}
11715
11716void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
11717 struct net_device *netdev, const u8 *bssid,
11718 const u8 *req_ie, size_t req_ie_len,
11719 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
11720{
11721 struct sk_buff *msg;
11722 void *hdr;
11723
58050fce 11724 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
11725 if (!msg)
11726 return;
11727
11728 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
11729 if (!hdr) {
11730 nlmsg_free(msg);
11731 return;
11732 }
11733
9360ffd1
DM
11734 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11735 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11736 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
11737 (req_ie &&
11738 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
11739 (resp_ie &&
11740 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
11741 goto nla_put_failure;
b23aa676 11742
3b7b72ee 11743 genlmsg_end(msg, hdr);
b23aa676 11744
68eb5503 11745 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11746 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
11747 return;
11748
11749 nla_put_failure:
11750 genlmsg_cancel(msg, hdr);
11751 nlmsg_free(msg);
11752
11753}
11754
11755void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
11756 struct net_device *netdev, u16 reason,
667503dd 11757 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
11758{
11759 struct sk_buff *msg;
11760 void *hdr;
11761
58050fce 11762 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
11763 if (!msg)
11764 return;
11765
11766 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
11767 if (!hdr) {
11768 nlmsg_free(msg);
11769 return;
11770 }
11771
9360ffd1
DM
11772 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11773 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11774 (from_ap && reason &&
11775 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
11776 (from_ap &&
11777 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
11778 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
11779 goto nla_put_failure;
b23aa676 11780
3b7b72ee 11781 genlmsg_end(msg, hdr);
b23aa676 11782
68eb5503 11783 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11784 NL80211_MCGRP_MLME, GFP_KERNEL);
b23aa676
SO
11785 return;
11786
11787 nla_put_failure:
11788 genlmsg_cancel(msg, hdr);
11789 nlmsg_free(msg);
11790
11791}
11792
04a773ad
JB
11793void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
11794 struct net_device *netdev, const u8 *bssid,
11795 gfp_t gfp)
11796{
11797 struct sk_buff *msg;
11798 void *hdr;
11799
fd2120ca 11800 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
11801 if (!msg)
11802 return;
11803
11804 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
11805 if (!hdr) {
11806 nlmsg_free(msg);
11807 return;
11808 }
11809
9360ffd1
DM
11810 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11811 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11812 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
11813 goto nla_put_failure;
04a773ad 11814
3b7b72ee 11815 genlmsg_end(msg, hdr);
04a773ad 11816
68eb5503 11817 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11818 NL80211_MCGRP_MLME, gfp);
04a773ad
JB
11819 return;
11820
11821 nla_put_failure:
11822 genlmsg_cancel(msg, hdr);
11823 nlmsg_free(msg);
11824}
11825
947add36
JB
11826void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
11827 const u8* ie, u8 ie_len, gfp_t gfp)
c93b5e71 11828{
947add36 11829 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 11830 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
c93b5e71
JC
11831 struct sk_buff *msg;
11832 void *hdr;
11833
947add36
JB
11834 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
11835 return;
11836
11837 trace_cfg80211_notify_new_peer_candidate(dev, addr);
11838
c93b5e71
JC
11839 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11840 if (!msg)
11841 return;
11842
11843 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
11844 if (!hdr) {
11845 nlmsg_free(msg);
11846 return;
11847 }
11848
9360ffd1 11849 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
11850 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
11851 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1
DM
11852 (ie_len && ie &&
11853 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
11854 goto nla_put_failure;
c93b5e71 11855
3b7b72ee 11856 genlmsg_end(msg, hdr);
c93b5e71 11857
68eb5503 11858 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11859 NL80211_MCGRP_MLME, gfp);
c93b5e71
JC
11860 return;
11861
11862 nla_put_failure:
11863 genlmsg_cancel(msg, hdr);
11864 nlmsg_free(msg);
11865}
947add36 11866EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 11867
a3b8b056
JM
11868void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
11869 struct net_device *netdev, const u8 *addr,
11870 enum nl80211_key_type key_type, int key_id,
e6d6e342 11871 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
11872{
11873 struct sk_buff *msg;
11874 void *hdr;
11875
e6d6e342 11876 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
11877 if (!msg)
11878 return;
11879
11880 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
11881 if (!hdr) {
11882 nlmsg_free(msg);
11883 return;
11884 }
11885
9360ffd1
DM
11886 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11887 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11888 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
11889 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
11890 (key_id != -1 &&
11891 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
11892 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
11893 goto nla_put_failure;
a3b8b056 11894
3b7b72ee 11895 genlmsg_end(msg, hdr);
a3b8b056 11896
68eb5503 11897 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11898 NL80211_MCGRP_MLME, gfp);
a3b8b056
JM
11899 return;
11900
11901 nla_put_failure:
11902 genlmsg_cancel(msg, hdr);
11903 nlmsg_free(msg);
11904}
11905
6bad8766
LR
11906void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
11907 struct ieee80211_channel *channel_before,
11908 struct ieee80211_channel *channel_after)
11909{
11910 struct sk_buff *msg;
11911 void *hdr;
11912 struct nlattr *nl_freq;
11913
fd2120ca 11914 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
11915 if (!msg)
11916 return;
11917
11918 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
11919 if (!hdr) {
11920 nlmsg_free(msg);
11921 return;
11922 }
11923
11924 /*
11925 * Since we are applying the beacon hint to a wiphy we know its
11926 * wiphy_idx is valid
11927 */
9360ffd1
DM
11928 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
11929 goto nla_put_failure;
6bad8766
LR
11930
11931 /* Before */
11932 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
11933 if (!nl_freq)
11934 goto nla_put_failure;
cdc89b97 11935 if (nl80211_msg_put_channel(msg, channel_before, false))
6bad8766
LR
11936 goto nla_put_failure;
11937 nla_nest_end(msg, nl_freq);
11938
11939 /* After */
11940 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
11941 if (!nl_freq)
11942 goto nla_put_failure;
cdc89b97 11943 if (nl80211_msg_put_channel(msg, channel_after, false))
6bad8766
LR
11944 goto nla_put_failure;
11945 nla_nest_end(msg, nl_freq);
11946
3b7b72ee 11947 genlmsg_end(msg, hdr);
6bad8766 11948
463d0183 11949 rcu_read_lock();
68eb5503 11950 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 11951 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
463d0183 11952 rcu_read_unlock();
6bad8766
LR
11953
11954 return;
11955
11956nla_put_failure:
11957 genlmsg_cancel(msg, hdr);
11958 nlmsg_free(msg);
11959}
11960
9588bbd5
JM
11961static void nl80211_send_remain_on_chan_event(
11962 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 11963 struct wireless_dev *wdev, u64 cookie,
9588bbd5 11964 struct ieee80211_channel *chan,
9588bbd5
JM
11965 unsigned int duration, gfp_t gfp)
11966{
11967 struct sk_buff *msg;
11968 void *hdr;
11969
11970 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11971 if (!msg)
11972 return;
11973
11974 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
11975 if (!hdr) {
11976 nlmsg_free(msg);
11977 return;
11978 }
11979
9360ffd1 11980 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
11981 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11982 wdev->netdev->ifindex)) ||
00f53350 11983 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 11984 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
11985 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
11986 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
11987 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
11988 goto nla_put_failure;
9588bbd5 11989
9360ffd1
DM
11990 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
11991 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
11992 goto nla_put_failure;
9588bbd5 11993
3b7b72ee 11994 genlmsg_end(msg, hdr);
9588bbd5 11995
68eb5503 11996 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11997 NL80211_MCGRP_MLME, gfp);
9588bbd5
JM
11998 return;
11999
12000 nla_put_failure:
12001 genlmsg_cancel(msg, hdr);
12002 nlmsg_free(msg);
12003}
12004
947add36
JB
12005void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
12006 struct ieee80211_channel *chan,
12007 unsigned int duration, gfp_t gfp)
9588bbd5 12008{
947add36 12009 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 12010 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
12011
12012 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 12013 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 12014 rdev, wdev, cookie, chan,
42d97a59 12015 duration, gfp);
9588bbd5 12016}
947add36 12017EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 12018
947add36
JB
12019void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
12020 struct ieee80211_channel *chan,
12021 gfp_t gfp)
9588bbd5 12022{
947add36 12023 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 12024 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
12025
12026 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 12027 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 12028 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 12029}
947add36 12030EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 12031
947add36
JB
12032void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
12033 struct station_info *sinfo, gfp_t gfp)
98b62183 12034{
947add36 12035 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 12036 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
98b62183
JB
12037 struct sk_buff *msg;
12038
947add36
JB
12039 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
12040
58050fce 12041 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
12042 if (!msg)
12043 return;
12044
cf5ead82 12045 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0,
66266b3a 12046 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
12047 nlmsg_free(msg);
12048 return;
12049 }
12050
68eb5503 12051 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12052 NL80211_MCGRP_MLME, gfp);
98b62183 12053}
947add36 12054EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 12055
cf5ead82
JB
12056void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr,
12057 struct station_info *sinfo, gfp_t gfp)
ec15e68b 12058{
947add36 12059 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 12060 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ec15e68b 12061 struct sk_buff *msg;
cf5ead82
JB
12062 struct station_info empty_sinfo = {};
12063
12064 if (!sinfo)
12065 sinfo = &empty_sinfo;
ec15e68b 12066
947add36
JB
12067 trace_cfg80211_del_sta(dev, mac_addr);
12068
58050fce 12069 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
12070 if (!msg)
12071 return;
12072
cf5ead82 12073 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0,
57007121 12074 rdev, dev, mac_addr, sinfo) < 0) {
ec15e68b
JM
12075 nlmsg_free(msg);
12076 return;
12077 }
12078
68eb5503 12079 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12080 NL80211_MCGRP_MLME, gfp);
ec15e68b 12081}
cf5ead82 12082EXPORT_SYMBOL(cfg80211_del_sta_sinfo);
ec15e68b 12083
947add36
JB
12084void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
12085 enum nl80211_connect_failed_reason reason,
12086 gfp_t gfp)
ed44a951 12087{
947add36 12088 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 12089 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ed44a951
PP
12090 struct sk_buff *msg;
12091 void *hdr;
12092
12093 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
12094 if (!msg)
12095 return;
12096
12097 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
12098 if (!hdr) {
12099 nlmsg_free(msg);
12100 return;
12101 }
12102
12103 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
12104 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
12105 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
12106 goto nla_put_failure;
12107
12108 genlmsg_end(msg, hdr);
12109
68eb5503 12110 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12111 NL80211_MCGRP_MLME, gfp);
ed44a951
PP
12112 return;
12113
12114 nla_put_failure:
12115 genlmsg_cancel(msg, hdr);
12116 nlmsg_free(msg);
12117}
947add36 12118EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 12119
b92ab5d8
JB
12120static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
12121 const u8 *addr, gfp_t gfp)
28946da7
JB
12122{
12123 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 12124 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
28946da7
JB
12125 struct sk_buff *msg;
12126 void *hdr;
15e47304 12127 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 12128
15e47304 12129 if (!nlportid)
28946da7
JB
12130 return false;
12131
12132 msg = nlmsg_new(100, gfp);
12133 if (!msg)
12134 return true;
12135
b92ab5d8 12136 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
12137 if (!hdr) {
12138 nlmsg_free(msg);
12139 return true;
12140 }
12141
9360ffd1
DM
12142 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12143 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
12144 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
12145 goto nla_put_failure;
28946da7 12146
9c90a9f6 12147 genlmsg_end(msg, hdr);
15e47304 12148 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
12149 return true;
12150
12151 nla_put_failure:
12152 genlmsg_cancel(msg, hdr);
12153 nlmsg_free(msg);
12154 return true;
12155}
12156
947add36
JB
12157bool cfg80211_rx_spurious_frame(struct net_device *dev,
12158 const u8 *addr, gfp_t gfp)
b92ab5d8 12159{
947add36
JB
12160 struct wireless_dev *wdev = dev->ieee80211_ptr;
12161 bool ret;
12162
12163 trace_cfg80211_rx_spurious_frame(dev, addr);
12164
12165 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
12166 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
12167 trace_cfg80211_return_bool(false);
12168 return false;
12169 }
12170 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
12171 addr, gfp);
12172 trace_cfg80211_return_bool(ret);
12173 return ret;
b92ab5d8 12174}
947add36 12175EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 12176
947add36
JB
12177bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
12178 const u8 *addr, gfp_t gfp)
b92ab5d8 12179{
947add36
JB
12180 struct wireless_dev *wdev = dev->ieee80211_ptr;
12181 bool ret;
12182
12183 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
12184
12185 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
12186 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
12187 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
12188 trace_cfg80211_return_bool(false);
12189 return false;
12190 }
12191 ret = __nl80211_unexpected_frame(dev,
12192 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
12193 addr, gfp);
12194 trace_cfg80211_return_bool(ret);
12195 return ret;
b92ab5d8 12196}
947add36 12197EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 12198
2e161f78 12199int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 12200 struct wireless_dev *wdev, u32 nlportid,
804483e9 12201 int freq, int sig_dbm,
19504cf5 12202 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 12203{
71bbc994 12204 struct net_device *netdev = wdev->netdev;
026331c4
JM
12205 struct sk_buff *msg;
12206 void *hdr;
026331c4
JM
12207
12208 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12209 if (!msg)
12210 return -ENOMEM;
12211
2e161f78 12212 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
12213 if (!hdr) {
12214 nlmsg_free(msg);
12215 return -ENOMEM;
12216 }
12217
9360ffd1 12218 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
12219 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
12220 netdev->ifindex)) ||
a838490b 12221 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
12222 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
12223 (sig_dbm &&
12224 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
12225 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
12226 (flags &&
12227 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 12228 goto nla_put_failure;
026331c4 12229
3b7b72ee 12230 genlmsg_end(msg, hdr);
026331c4 12231
15e47304 12232 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
12233
12234 nla_put_failure:
12235 genlmsg_cancel(msg, hdr);
12236 nlmsg_free(msg);
12237 return -ENOBUFS;
12238}
12239
947add36
JB
12240void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
12241 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 12242{
947add36 12243 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 12244 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
71bbc994 12245 struct net_device *netdev = wdev->netdev;
026331c4
JM
12246 struct sk_buff *msg;
12247 void *hdr;
12248
947add36
JB
12249 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
12250
026331c4
JM
12251 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12252 if (!msg)
12253 return;
12254
2e161f78 12255 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
12256 if (!hdr) {
12257 nlmsg_free(msg);
12258 return;
12259 }
12260
9360ffd1 12261 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
12262 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
12263 netdev->ifindex)) ||
a838490b 12264 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
12265 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
12266 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
12267 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
12268 goto nla_put_failure;
026331c4 12269
3b7b72ee 12270 genlmsg_end(msg, hdr);
026331c4 12271
68eb5503 12272 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12273 NL80211_MCGRP_MLME, gfp);
026331c4
JM
12274 return;
12275
12276 nla_put_failure:
12277 genlmsg_cancel(msg, hdr);
12278 nlmsg_free(msg);
12279}
947add36 12280EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 12281
5b97f49d
JB
12282static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev,
12283 const char *mac, gfp_t gfp)
d6dc1a38 12284{
947add36 12285 struct wireless_dev *wdev = dev->ieee80211_ptr;
5b97f49d
JB
12286 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
12287 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12288 void **cb;
947add36 12289
d6dc1a38 12290 if (!msg)
5b97f49d 12291 return NULL;
d6dc1a38 12292
5b97f49d
JB
12293 cb = (void **)msg->cb;
12294
12295 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
12296 if (!cb[0]) {
d6dc1a38 12297 nlmsg_free(msg);
5b97f49d 12298 return NULL;
d6dc1a38
JO
12299 }
12300
9360ffd1 12301 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 12302 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 12303 goto nla_put_failure;
d6dc1a38 12304
5b97f49d 12305 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
d6dc1a38
JO
12306 goto nla_put_failure;
12307
5b97f49d
JB
12308 cb[1] = nla_nest_start(msg, NL80211_ATTR_CQM);
12309 if (!cb[1])
9360ffd1 12310 goto nla_put_failure;
d6dc1a38 12311
5b97f49d 12312 cb[2] = rdev;
d6dc1a38 12313
5b97f49d
JB
12314 return msg;
12315 nla_put_failure:
12316 nlmsg_free(msg);
12317 return NULL;
12318}
12319
12320static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp)
12321{
12322 void **cb = (void **)msg->cb;
12323 struct cfg80211_registered_device *rdev = cb[2];
12324
12325 nla_nest_end(msg, cb[1]);
12326 genlmsg_end(msg, cb[0]);
12327
12328 memset(msg->cb, 0, sizeof(msg->cb));
d6dc1a38 12329
68eb5503 12330 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12331 NL80211_MCGRP_MLME, gfp);
5b97f49d
JB
12332}
12333
12334void cfg80211_cqm_rssi_notify(struct net_device *dev,
12335 enum nl80211_cqm_rssi_threshold_event rssi_event,
12336 gfp_t gfp)
12337{
12338 struct sk_buff *msg;
12339
12340 trace_cfg80211_cqm_rssi_notify(dev, rssi_event);
12341
98f03342
JB
12342 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW &&
12343 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH))
12344 return;
12345
5b97f49d
JB
12346 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
12347 if (!msg)
12348 return;
12349
12350 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
12351 rssi_event))
12352 goto nla_put_failure;
12353
12354 cfg80211_send_cqm(msg, gfp);
12355
d6dc1a38
JO
12356 return;
12357
12358 nla_put_failure:
d6dc1a38
JO
12359 nlmsg_free(msg);
12360}
947add36 12361EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 12362
5b97f49d
JB
12363void cfg80211_cqm_txe_notify(struct net_device *dev,
12364 const u8 *peer, u32 num_packets,
12365 u32 rate, u32 intvl, gfp_t gfp)
12366{
12367 struct sk_buff *msg;
12368
12369 msg = cfg80211_prepare_cqm(dev, peer, gfp);
12370 if (!msg)
12371 return;
12372
12373 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
12374 goto nla_put_failure;
12375
12376 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
12377 goto nla_put_failure;
12378
12379 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
12380 goto nla_put_failure;
12381
12382 cfg80211_send_cqm(msg, gfp);
12383 return;
12384
12385 nla_put_failure:
12386 nlmsg_free(msg);
12387}
12388EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
12389
12390void cfg80211_cqm_pktloss_notify(struct net_device *dev,
12391 const u8 *peer, u32 num_packets, gfp_t gfp)
12392{
12393 struct sk_buff *msg;
12394
12395 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
12396
12397 msg = cfg80211_prepare_cqm(dev, peer, gfp);
12398 if (!msg)
12399 return;
12400
12401 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
12402 goto nla_put_failure;
12403
12404 cfg80211_send_cqm(msg, gfp);
12405 return;
12406
12407 nla_put_failure:
12408 nlmsg_free(msg);
12409}
12410EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
12411
98f03342
JB
12412void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp)
12413{
12414 struct sk_buff *msg;
12415
12416 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
12417 if (!msg)
12418 return;
12419
12420 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT))
12421 goto nla_put_failure;
12422
12423 cfg80211_send_cqm(msg, gfp);
12424 return;
12425
12426 nla_put_failure:
12427 nlmsg_free(msg);
12428}
12429EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify);
12430
947add36
JB
12431static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
12432 struct net_device *netdev, const u8 *bssid,
12433 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
12434{
12435 struct sk_buff *msg;
12436 struct nlattr *rekey_attr;
12437 void *hdr;
12438
58050fce 12439 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
12440 if (!msg)
12441 return;
12442
12443 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
12444 if (!hdr) {
12445 nlmsg_free(msg);
12446 return;
12447 }
12448
9360ffd1
DM
12449 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12450 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
12451 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
12452 goto nla_put_failure;
e5497d76
JB
12453
12454 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
12455 if (!rekey_attr)
12456 goto nla_put_failure;
12457
9360ffd1
DM
12458 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
12459 NL80211_REPLAY_CTR_LEN, replay_ctr))
12460 goto nla_put_failure;
e5497d76
JB
12461
12462 nla_nest_end(msg, rekey_attr);
12463
3b7b72ee 12464 genlmsg_end(msg, hdr);
e5497d76 12465
68eb5503 12466 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12467 NL80211_MCGRP_MLME, gfp);
e5497d76
JB
12468 return;
12469
12470 nla_put_failure:
12471 genlmsg_cancel(msg, hdr);
12472 nlmsg_free(msg);
12473}
12474
947add36
JB
12475void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
12476 const u8 *replay_ctr, gfp_t gfp)
12477{
12478 struct wireless_dev *wdev = dev->ieee80211_ptr;
12479 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 12480 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
12481
12482 trace_cfg80211_gtk_rekey_notify(dev, bssid);
12483 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
12484}
12485EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
12486
12487static void
12488nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
12489 struct net_device *netdev, int index,
12490 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
12491{
12492 struct sk_buff *msg;
12493 struct nlattr *attr;
12494 void *hdr;
12495
58050fce 12496 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
12497 if (!msg)
12498 return;
12499
12500 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
12501 if (!hdr) {
12502 nlmsg_free(msg);
12503 return;
12504 }
12505
9360ffd1
DM
12506 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12507 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
12508 goto nla_put_failure;
c9df56b4
JM
12509
12510 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
12511 if (!attr)
12512 goto nla_put_failure;
12513
9360ffd1
DM
12514 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
12515 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
12516 (preauth &&
12517 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
12518 goto nla_put_failure;
c9df56b4
JM
12519
12520 nla_nest_end(msg, attr);
12521
3b7b72ee 12522 genlmsg_end(msg, hdr);
c9df56b4 12523
68eb5503 12524 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12525 NL80211_MCGRP_MLME, gfp);
c9df56b4
JM
12526 return;
12527
12528 nla_put_failure:
12529 genlmsg_cancel(msg, hdr);
12530 nlmsg_free(msg);
12531}
12532
947add36
JB
12533void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
12534 const u8 *bssid, bool preauth, gfp_t gfp)
12535{
12536 struct wireless_dev *wdev = dev->ieee80211_ptr;
12537 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 12538 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
12539
12540 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
12541 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
12542}
12543EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
12544
12545static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
12546 struct net_device *netdev,
12547 struct cfg80211_chan_def *chandef,
f8d7552e
LC
12548 gfp_t gfp,
12549 enum nl80211_commands notif,
12550 u8 count)
5314526b
TP
12551{
12552 struct sk_buff *msg;
12553 void *hdr;
12554
58050fce 12555 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
12556 if (!msg)
12557 return;
12558
f8d7552e 12559 hdr = nl80211hdr_put(msg, 0, 0, 0, notif);
5314526b
TP
12560 if (!hdr) {
12561 nlmsg_free(msg);
12562 return;
12563 }
12564
683b6d3b
JB
12565 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
12566 goto nla_put_failure;
12567
12568 if (nl80211_send_chandef(msg, chandef))
7eab0f64 12569 goto nla_put_failure;
5314526b 12570
f8d7552e
LC
12571 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) &&
12572 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count)))
12573 goto nla_put_failure;
12574
5314526b
TP
12575 genlmsg_end(msg, hdr);
12576
68eb5503 12577 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12578 NL80211_MCGRP_MLME, gfp);
5314526b
TP
12579 return;
12580
12581 nla_put_failure:
12582 genlmsg_cancel(msg, hdr);
12583 nlmsg_free(msg);
12584}
12585
947add36
JB
12586void cfg80211_ch_switch_notify(struct net_device *dev,
12587 struct cfg80211_chan_def *chandef)
84f10708 12588{
947add36
JB
12589 struct wireless_dev *wdev = dev->ieee80211_ptr;
12590 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 12591 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36 12592
e487eaeb 12593 ASSERT_WDEV_LOCK(wdev);
947add36 12594
e487eaeb 12595 trace_cfg80211_ch_switch_notify(dev, chandef);
947add36 12596
9e0e2961 12597 wdev->chandef = *chandef;
96f55f12 12598 wdev->preset_chandef = *chandef;
f8d7552e
LC
12599 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
12600 NL80211_CMD_CH_SWITCH_NOTIFY, 0);
947add36
JB
12601}
12602EXPORT_SYMBOL(cfg80211_ch_switch_notify);
12603
f8d7552e
LC
12604void cfg80211_ch_switch_started_notify(struct net_device *dev,
12605 struct cfg80211_chan_def *chandef,
12606 u8 count)
12607{
12608 struct wireless_dev *wdev = dev->ieee80211_ptr;
12609 struct wiphy *wiphy = wdev->wiphy;
12610 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
12611
12612 trace_cfg80211_ch_switch_started_notify(dev, chandef);
12613
12614 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
12615 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count);
12616}
12617EXPORT_SYMBOL(cfg80211_ch_switch_started_notify);
12618
04f39047
SW
12619void
12620nl80211_radar_notify(struct cfg80211_registered_device *rdev,
d2859df5 12621 const struct cfg80211_chan_def *chandef,
04f39047
SW
12622 enum nl80211_radar_event event,
12623 struct net_device *netdev, gfp_t gfp)
12624{
12625 struct sk_buff *msg;
12626 void *hdr;
12627
12628 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12629 if (!msg)
12630 return;
12631
12632 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
12633 if (!hdr) {
12634 nlmsg_free(msg);
12635 return;
12636 }
12637
12638 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
12639 goto nla_put_failure;
12640
12641 /* NOP and radar events don't need a netdev parameter */
12642 if (netdev) {
12643 struct wireless_dev *wdev = netdev->ieee80211_ptr;
12644
12645 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
12646 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
12647 goto nla_put_failure;
12648 }
12649
12650 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
12651 goto nla_put_failure;
12652
12653 if (nl80211_send_chandef(msg, chandef))
12654 goto nla_put_failure;
12655
9c90a9f6 12656 genlmsg_end(msg, hdr);
04f39047 12657
68eb5503 12658 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12659 NL80211_MCGRP_MLME, gfp);
04f39047
SW
12660 return;
12661
12662 nla_put_failure:
12663 genlmsg_cancel(msg, hdr);
12664 nlmsg_free(msg);
12665}
12666
7f6cf311
JB
12667void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
12668 u64 cookie, bool acked, gfp_t gfp)
12669{
12670 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 12671 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
7f6cf311
JB
12672 struct sk_buff *msg;
12673 void *hdr;
7f6cf311 12674
4ee3e063
BL
12675 trace_cfg80211_probe_status(dev, addr, cookie, acked);
12676
58050fce 12677 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 12678
7f6cf311
JB
12679 if (!msg)
12680 return;
12681
12682 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
12683 if (!hdr) {
12684 nlmsg_free(msg);
12685 return;
12686 }
12687
9360ffd1
DM
12688 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12689 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
12690 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
12691 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
12692 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
12693 goto nla_put_failure;
7f6cf311 12694
9c90a9f6 12695 genlmsg_end(msg, hdr);
7f6cf311 12696
68eb5503 12697 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12698 NL80211_MCGRP_MLME, gfp);
7f6cf311
JB
12699 return;
12700
12701 nla_put_failure:
12702 genlmsg_cancel(msg, hdr);
12703 nlmsg_free(msg);
12704}
12705EXPORT_SYMBOL(cfg80211_probe_status);
12706
5e760230
JB
12707void cfg80211_report_obss_beacon(struct wiphy *wiphy,
12708 const u8 *frame, size_t len,
37c73b5f 12709 int freq, int sig_dbm)
5e760230 12710{
f26cbf40 12711 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
5e760230
JB
12712 struct sk_buff *msg;
12713 void *hdr;
37c73b5f 12714 struct cfg80211_beacon_registration *reg;
5e760230 12715
4ee3e063
BL
12716 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
12717
37c73b5f
BG
12718 spin_lock_bh(&rdev->beacon_registrations_lock);
12719 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
12720 msg = nlmsg_new(len + 100, GFP_ATOMIC);
12721 if (!msg) {
12722 spin_unlock_bh(&rdev->beacon_registrations_lock);
12723 return;
12724 }
5e760230 12725
37c73b5f
BG
12726 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
12727 if (!hdr)
12728 goto nla_put_failure;
5e760230 12729
37c73b5f
BG
12730 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12731 (freq &&
12732 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
12733 (sig_dbm &&
12734 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
12735 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
12736 goto nla_put_failure;
5e760230 12737
37c73b5f 12738 genlmsg_end(msg, hdr);
5e760230 12739
37c73b5f
BG
12740 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
12741 }
12742 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
12743 return;
12744
12745 nla_put_failure:
37c73b5f
BG
12746 spin_unlock_bh(&rdev->beacon_registrations_lock);
12747 if (hdr)
12748 genlmsg_cancel(msg, hdr);
5e760230
JB
12749 nlmsg_free(msg);
12750}
12751EXPORT_SYMBOL(cfg80211_report_obss_beacon);
12752
cd8f7cb4 12753#ifdef CONFIG_PM
8cd4d456
LC
12754static int cfg80211_net_detect_results(struct sk_buff *msg,
12755 struct cfg80211_wowlan_wakeup *wakeup)
12756{
12757 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect;
12758 struct nlattr *nl_results, *nl_match, *nl_freqs;
12759 int i, j;
12760
12761 nl_results = nla_nest_start(
12762 msg, NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS);
12763 if (!nl_results)
12764 return -EMSGSIZE;
12765
12766 for (i = 0; i < nd->n_matches; i++) {
12767 struct cfg80211_wowlan_nd_match *match = nd->matches[i];
12768
12769 nl_match = nla_nest_start(msg, i);
12770 if (!nl_match)
12771 break;
12772
12773 /* The SSID attribute is optional in nl80211, but for
12774 * simplicity reasons it's always present in the
12775 * cfg80211 structure. If a driver can't pass the
12776 * SSID, that needs to be changed. A zero length SSID
12777 * is still a valid SSID (wildcard), so it cannot be
12778 * used for this purpose.
12779 */
12780 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len,
12781 match->ssid.ssid)) {
12782 nla_nest_cancel(msg, nl_match);
12783 goto out;
12784 }
12785
12786 if (match->n_channels) {
12787 nl_freqs = nla_nest_start(
12788 msg, NL80211_ATTR_SCAN_FREQUENCIES);
12789 if (!nl_freqs) {
12790 nla_nest_cancel(msg, nl_match);
12791 goto out;
12792 }
12793
12794 for (j = 0; j < match->n_channels; j++) {
5528fae8 12795 if (nla_put_u32(msg, j, match->channels[j])) {
8cd4d456
LC
12796 nla_nest_cancel(msg, nl_freqs);
12797 nla_nest_cancel(msg, nl_match);
12798 goto out;
12799 }
12800 }
12801
12802 nla_nest_end(msg, nl_freqs);
12803 }
12804
12805 nla_nest_end(msg, nl_match);
12806 }
12807
12808out:
12809 nla_nest_end(msg, nl_results);
12810 return 0;
12811}
12812
cd8f7cb4
JB
12813void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
12814 struct cfg80211_wowlan_wakeup *wakeup,
12815 gfp_t gfp)
12816{
f26cbf40 12817 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
cd8f7cb4
JB
12818 struct sk_buff *msg;
12819 void *hdr;
9c90a9f6 12820 int size = 200;
cd8f7cb4
JB
12821
12822 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
12823
12824 if (wakeup)
12825 size += wakeup->packet_present_len;
12826
12827 msg = nlmsg_new(size, gfp);
12828 if (!msg)
12829 return;
12830
12831 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
12832 if (!hdr)
12833 goto free_msg;
12834
12835 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12836 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
12837 goto free_msg;
12838
12839 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
12840 wdev->netdev->ifindex))
12841 goto free_msg;
12842
12843 if (wakeup) {
12844 struct nlattr *reasons;
12845
12846 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7fa322c8
JB
12847 if (!reasons)
12848 goto free_msg;
cd8f7cb4
JB
12849
12850 if (wakeup->disconnect &&
12851 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
12852 goto free_msg;
12853 if (wakeup->magic_pkt &&
12854 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
12855 goto free_msg;
12856 if (wakeup->gtk_rekey_failure &&
12857 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
12858 goto free_msg;
12859 if (wakeup->eap_identity_req &&
12860 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
12861 goto free_msg;
12862 if (wakeup->four_way_handshake &&
12863 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
12864 goto free_msg;
12865 if (wakeup->rfkill_release &&
12866 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
12867 goto free_msg;
12868
12869 if (wakeup->pattern_idx >= 0 &&
12870 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
12871 wakeup->pattern_idx))
12872 goto free_msg;
12873
ae917c9f
JB
12874 if (wakeup->tcp_match &&
12875 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
12876 goto free_msg;
2a0e047e 12877
ae917c9f
JB
12878 if (wakeup->tcp_connlost &&
12879 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
12880 goto free_msg;
2a0e047e 12881
ae917c9f
JB
12882 if (wakeup->tcp_nomoretokens &&
12883 nla_put_flag(msg,
12884 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
12885 goto free_msg;
2a0e047e 12886
cd8f7cb4
JB
12887 if (wakeup->packet) {
12888 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
12889 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
12890
12891 if (!wakeup->packet_80211) {
12892 pkt_attr =
12893 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
12894 len_attr =
12895 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
12896 }
12897
12898 if (wakeup->packet_len &&
12899 nla_put_u32(msg, len_attr, wakeup->packet_len))
12900 goto free_msg;
12901
12902 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
12903 wakeup->packet))
12904 goto free_msg;
12905 }
12906
8cd4d456
LC
12907 if (wakeup->net_detect &&
12908 cfg80211_net_detect_results(msg, wakeup))
12909 goto free_msg;
12910
cd8f7cb4
JB
12911 nla_nest_end(msg, reasons);
12912 }
12913
9c90a9f6 12914 genlmsg_end(msg, hdr);
cd8f7cb4 12915
68eb5503 12916 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12917 NL80211_MCGRP_MLME, gfp);
cd8f7cb4
JB
12918 return;
12919
12920 free_msg:
12921 nlmsg_free(msg);
12922}
12923EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
12924#endif
12925
3475b094
JM
12926void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
12927 enum nl80211_tdls_operation oper,
12928 u16 reason_code, gfp_t gfp)
12929{
12930 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 12931 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
3475b094
JM
12932 struct sk_buff *msg;
12933 void *hdr;
3475b094
JM
12934
12935 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
12936 reason_code);
12937
12938 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12939 if (!msg)
12940 return;
12941
12942 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
12943 if (!hdr) {
12944 nlmsg_free(msg);
12945 return;
12946 }
12947
12948 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12949 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
12950 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
12951 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
12952 (reason_code > 0 &&
12953 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
12954 goto nla_put_failure;
12955
9c90a9f6 12956 genlmsg_end(msg, hdr);
3475b094 12957
68eb5503 12958 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12959 NL80211_MCGRP_MLME, gfp);
3475b094
JM
12960 return;
12961
12962 nla_put_failure:
12963 genlmsg_cancel(msg, hdr);
12964 nlmsg_free(msg);
12965}
12966EXPORT_SYMBOL(cfg80211_tdls_oper_request);
12967
026331c4
JM
12968static int nl80211_netlink_notify(struct notifier_block * nb,
12969 unsigned long state,
12970 void *_notify)
12971{
12972 struct netlink_notify *notify = _notify;
12973 struct cfg80211_registered_device *rdev;
12974 struct wireless_dev *wdev;
37c73b5f 12975 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
12976
12977 if (state != NETLINK_URELEASE)
12978 return NOTIFY_DONE;
12979
12980 rcu_read_lock();
12981
5e760230 12982 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
78f22b6a 12983 bool schedule_destroy_work = false;
93a1e86c
JR
12984 bool schedule_scan_stop = false;
12985 struct cfg80211_sched_scan_request *sched_scan_req =
12986 rcu_dereference(rdev->sched_scan_req);
12987
12988 if (sched_scan_req && notify->portid &&
12989 sched_scan_req->owner_nlportid == notify->portid)
12990 schedule_scan_stop = true;
78f22b6a
JB
12991
12992 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list) {
15e47304 12993 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f 12994
78f22b6a
JB
12995 if (wdev->owner_nlportid == notify->portid)
12996 schedule_destroy_work = true;
12997 }
12998
37c73b5f
BG
12999 spin_lock_bh(&rdev->beacon_registrations_lock);
13000 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
13001 list) {
13002 if (reg->nlportid == notify->portid) {
13003 list_del(&reg->list);
13004 kfree(reg);
13005 break;
13006 }
13007 }
13008 spin_unlock_bh(&rdev->beacon_registrations_lock);
78f22b6a
JB
13009
13010 if (schedule_destroy_work) {
13011 struct cfg80211_iface_destroy *destroy;
13012
13013 destroy = kzalloc(sizeof(*destroy), GFP_ATOMIC);
13014 if (destroy) {
13015 destroy->nlportid = notify->portid;
13016 spin_lock(&rdev->destroy_list_lock);
13017 list_add(&destroy->list, &rdev->destroy_list);
13018 spin_unlock(&rdev->destroy_list_lock);
13019 schedule_work(&rdev->destroy_work);
13020 }
93a1e86c
JR
13021 } else if (schedule_scan_stop) {
13022 sched_scan_req->owner_nlportid = 0;
13023
13024 if (rdev->ops->sched_scan_stop &&
13025 rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
13026 schedule_work(&rdev->sched_scan_stop_wk);
78f22b6a 13027 }
5e760230 13028 }
026331c4
JM
13029
13030 rcu_read_unlock();
13031
05050753
I
13032 /*
13033 * It is possible that the user space process that is controlling the
13034 * indoor setting disappeared, so notify the regulatory core.
13035 */
13036 regulatory_netlink_notify(notify->portid);
6784c7db 13037 return NOTIFY_OK;
026331c4
JM
13038}
13039
13040static struct notifier_block nl80211_netlink_notifier = {
13041 .notifier_call = nl80211_netlink_notify,
13042};
13043
355199e0
JM
13044void cfg80211_ft_event(struct net_device *netdev,
13045 struct cfg80211_ft_event_params *ft_event)
13046{
13047 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
f26cbf40 13048 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
355199e0
JM
13049 struct sk_buff *msg;
13050 void *hdr;
355199e0
JM
13051
13052 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
13053
13054 if (!ft_event->target_ap)
13055 return;
13056
13057 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13058 if (!msg)
13059 return;
13060
13061 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
ae917c9f
JB
13062 if (!hdr)
13063 goto out;
355199e0 13064
ae917c9f
JB
13065 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13066 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13067 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
13068 goto out;
355199e0 13069
ae917c9f
JB
13070 if (ft_event->ies &&
13071 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
13072 goto out;
13073 if (ft_event->ric_ies &&
13074 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
13075 ft_event->ric_ies))
13076 goto out;
355199e0 13077
9c90a9f6 13078 genlmsg_end(msg, hdr);
355199e0 13079
68eb5503 13080 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13081 NL80211_MCGRP_MLME, GFP_KERNEL);
ae917c9f
JB
13082 return;
13083 out:
13084 nlmsg_free(msg);
355199e0
JM
13085}
13086EXPORT_SYMBOL(cfg80211_ft_event);
13087
5de17984
AS
13088void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
13089{
13090 struct cfg80211_registered_device *rdev;
13091 struct sk_buff *msg;
13092 void *hdr;
13093 u32 nlportid;
13094
f26cbf40 13095 rdev = wiphy_to_rdev(wdev->wiphy);
5de17984
AS
13096 if (!rdev->crit_proto_nlportid)
13097 return;
13098
13099 nlportid = rdev->crit_proto_nlportid;
13100 rdev->crit_proto_nlportid = 0;
13101
13102 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13103 if (!msg)
13104 return;
13105
13106 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
13107 if (!hdr)
13108 goto nla_put_failure;
13109
13110 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13111 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
13112 goto nla_put_failure;
13113
13114 genlmsg_end(msg, hdr);
13115
13116 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
13117 return;
13118
13119 nla_put_failure:
13120 if (hdr)
13121 genlmsg_cancel(msg, hdr);
13122 nlmsg_free(msg);
13123
13124}
13125EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
13126
348baf0e
JB
13127void nl80211_send_ap_stopped(struct wireless_dev *wdev)
13128{
13129 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13130 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
348baf0e
JB
13131 struct sk_buff *msg;
13132 void *hdr;
13133
13134 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13135 if (!msg)
13136 return;
13137
13138 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP);
13139 if (!hdr)
13140 goto out;
13141
13142 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13143 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
13144 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
13145 goto out;
13146
13147 genlmsg_end(msg, hdr);
13148
13149 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
13150 NL80211_MCGRP_MLME, GFP_KERNEL);
13151 return;
13152 out:
13153 nlmsg_free(msg);
13154}
13155
55682965
JB
13156/* initialisation/exit functions */
13157
13158int nl80211_init(void)
13159{
0d63cbb5 13160 int err;
55682965 13161
2a94fe48
JB
13162 err = genl_register_family_with_ops_groups(&nl80211_fam, nl80211_ops,
13163 nl80211_mcgrps);
55682965
JB
13164 if (err)
13165 return err;
13166
026331c4
JM
13167 err = netlink_register_notifier(&nl80211_netlink_notifier);
13168 if (err)
13169 goto err_out;
13170
55682965
JB
13171 return 0;
13172 err_out:
13173 genl_unregister_family(&nl80211_fam);
13174 return err;
13175}
13176
13177void nl80211_exit(void)
13178{
026331c4 13179 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
13180 genl_unregister_family(&nl80211_fam);
13181}