]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/padovan/blueto...
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
e31b8213 96 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
97
98 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101 .len = IEEE80211_MAX_DATA_LEN },
102 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
104 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 109 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 110 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 111 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
112 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113 .len = IEEE80211_MAX_MESH_ID_LEN },
114 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 115
b2e1b302
LR
116 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
9f1ba906
JM
119 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
122 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123 .len = NL80211_MAX_SUPP_RATES },
50b12f59 124 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 125
24bdd9f4 126 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 127 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 128
36aedc90
JM
129 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
130 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
131
132 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
133 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
134 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
135 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
136 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
137
138 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_SSID_LEN },
140 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
141 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 142 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 143 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 144 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
145 [NL80211_ATTR_STA_FLAGS2] = {
146 .len = sizeof(struct nl80211_sta_flag_update),
147 },
3f77316c 148 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
149 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
150 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
151 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
152 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
153 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 154 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 155 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
156 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
157 .len = WLAN_PMKID_LEN },
9588bbd5
JM
158 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
159 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 160 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
161 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
162 .len = IEEE80211_MAX_DATA_LEN },
163 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 164 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 165 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 166 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 167 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
168 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
169 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 170 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
171 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
172 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 173 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 174 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 175 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 176 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 177 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 178 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
55682965
JB
179};
180
e31b8213 181/* policy for the key attributes */
b54452b0 182static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 183 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
184 [NL80211_KEY_IDX] = { .type = NLA_U8 },
185 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
186 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
187 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
188 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 189 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
190 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
191};
192
193/* policy for the key default flags */
194static const struct nla_policy
195nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
196 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
197 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
198};
199
ff1b6e69
JB
200/* policy for WoWLAN attributes */
201static const struct nla_policy
202nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
203 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
204 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
205 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
206 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
207};
208
a043897a
HS
209/* ifidx get helper */
210static int nl80211_get_ifidx(struct netlink_callback *cb)
211{
212 int res;
213
214 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
215 nl80211_fam.attrbuf, nl80211_fam.maxattr,
216 nl80211_policy);
217 if (res)
218 return res;
219
220 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
221 return -EINVAL;
222
223 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
224 if (!res)
225 return -EINVAL;
226 return res;
227}
228
67748893
JB
229static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
230 struct netlink_callback *cb,
231 struct cfg80211_registered_device **rdev,
232 struct net_device **dev)
233{
234 int ifidx = cb->args[0];
235 int err;
236
237 if (!ifidx)
238 ifidx = nl80211_get_ifidx(cb);
239 if (ifidx < 0)
240 return ifidx;
241
242 cb->args[0] = ifidx;
243
244 rtnl_lock();
245
246 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
247 if (!*dev) {
248 err = -ENODEV;
249 goto out_rtnl;
250 }
251
252 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
253 if (IS_ERR(*rdev)) {
254 err = PTR_ERR(*rdev);
67748893
JB
255 goto out_rtnl;
256 }
257
258 return 0;
259 out_rtnl:
260 rtnl_unlock();
261 return err;
262}
263
264static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
265{
266 cfg80211_unlock_rdev(rdev);
267 rtnl_unlock();
268}
269
f4a11bb0
JB
270/* IE validation */
271static bool is_valid_ie_attr(const struct nlattr *attr)
272{
273 const u8 *pos;
274 int len;
275
276 if (!attr)
277 return true;
278
279 pos = nla_data(attr);
280 len = nla_len(attr);
281
282 while (len) {
283 u8 elemlen;
284
285 if (len < 2)
286 return false;
287 len -= 2;
288
289 elemlen = pos[1];
290 if (elemlen > len)
291 return false;
292
293 len -= elemlen;
294 pos += 2 + elemlen;
295 }
296
297 return true;
298}
299
55682965
JB
300/* message building helper */
301static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
302 int flags, u8 cmd)
303{
304 /* since there is no private header just add the generic one */
305 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
306}
307
5dab3b8a
LR
308static int nl80211_msg_put_channel(struct sk_buff *msg,
309 struct ieee80211_channel *chan)
310{
311 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
312 chan->center_freq);
313
314 if (chan->flags & IEEE80211_CHAN_DISABLED)
315 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
316 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
317 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
318 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
319 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
320 if (chan->flags & IEEE80211_CHAN_RADAR)
321 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
322
323 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
324 DBM_TO_MBM(chan->max_power));
325
326 return 0;
327
328 nla_put_failure:
329 return -ENOBUFS;
330}
331
55682965
JB
332/* netlink command implementations */
333
b9454e83
JB
334struct key_parse {
335 struct key_params p;
336 int idx;
e31b8213 337 int type;
b9454e83 338 bool def, defmgmt;
dbd2fd65 339 bool def_uni, def_multi;
b9454e83
JB
340};
341
342static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
343{
344 struct nlattr *tb[NL80211_KEY_MAX + 1];
345 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
346 nl80211_key_policy);
347 if (err)
348 return err;
349
350 k->def = !!tb[NL80211_KEY_DEFAULT];
351 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
352
dbd2fd65
JB
353 if (k->def) {
354 k->def_uni = true;
355 k->def_multi = true;
356 }
357 if (k->defmgmt)
358 k->def_multi = true;
359
b9454e83
JB
360 if (tb[NL80211_KEY_IDX])
361 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
362
363 if (tb[NL80211_KEY_DATA]) {
364 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
365 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
366 }
367
368 if (tb[NL80211_KEY_SEQ]) {
369 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
370 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
371 }
372
373 if (tb[NL80211_KEY_CIPHER])
374 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
375
e31b8213
JB
376 if (tb[NL80211_KEY_TYPE]) {
377 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
378 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
379 return -EINVAL;
380 }
381
dbd2fd65
JB
382 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
383 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
384 int err = nla_parse_nested(kdt,
385 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
386 tb[NL80211_KEY_DEFAULT_TYPES],
387 nl80211_key_default_policy);
388 if (err)
389 return err;
390
391 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
392 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
393 }
394
b9454e83
JB
395 return 0;
396}
397
398static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
399{
400 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
401 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
402 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
403 }
404
405 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
406 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
407 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
408 }
409
410 if (info->attrs[NL80211_ATTR_KEY_IDX])
411 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
412
413 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
414 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
415
416 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
417 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
418
dbd2fd65
JB
419 if (k->def) {
420 k->def_uni = true;
421 k->def_multi = true;
422 }
423 if (k->defmgmt)
424 k->def_multi = true;
425
e31b8213
JB
426 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
427 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
428 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
429 return -EINVAL;
430 }
431
dbd2fd65
JB
432 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
433 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
434 int err = nla_parse_nested(
435 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
436 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
437 nl80211_key_default_policy);
438 if (err)
439 return err;
440
441 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
442 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
443 }
444
b9454e83
JB
445 return 0;
446}
447
448static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
449{
450 int err;
451
452 memset(k, 0, sizeof(*k));
453 k->idx = -1;
e31b8213 454 k->type = -1;
b9454e83
JB
455
456 if (info->attrs[NL80211_ATTR_KEY])
457 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
458 else
459 err = nl80211_parse_key_old(info, k);
460
461 if (err)
462 return err;
463
464 if (k->def && k->defmgmt)
465 return -EINVAL;
466
dbd2fd65
JB
467 if (k->defmgmt) {
468 if (k->def_uni || !k->def_multi)
469 return -EINVAL;
470 }
471
b9454e83
JB
472 if (k->idx != -1) {
473 if (k->defmgmt) {
474 if (k->idx < 4 || k->idx > 5)
475 return -EINVAL;
476 } else if (k->def) {
477 if (k->idx < 0 || k->idx > 3)
478 return -EINVAL;
479 } else {
480 if (k->idx < 0 || k->idx > 5)
481 return -EINVAL;
482 }
483 }
484
485 return 0;
486}
487
fffd0934
JB
488static struct cfg80211_cached_keys *
489nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
490 struct nlattr *keys)
491{
492 struct key_parse parse;
493 struct nlattr *key;
494 struct cfg80211_cached_keys *result;
495 int rem, err, def = 0;
496
497 result = kzalloc(sizeof(*result), GFP_KERNEL);
498 if (!result)
499 return ERR_PTR(-ENOMEM);
500
501 result->def = -1;
502 result->defmgmt = -1;
503
504 nla_for_each_nested(key, keys, rem) {
505 memset(&parse, 0, sizeof(parse));
506 parse.idx = -1;
507
508 err = nl80211_parse_key_new(key, &parse);
509 if (err)
510 goto error;
511 err = -EINVAL;
512 if (!parse.p.key)
513 goto error;
514 if (parse.idx < 0 || parse.idx > 4)
515 goto error;
516 if (parse.def) {
517 if (def)
518 goto error;
519 def = 1;
520 result->def = parse.idx;
dbd2fd65
JB
521 if (!parse.def_uni || !parse.def_multi)
522 goto error;
fffd0934
JB
523 } else if (parse.defmgmt)
524 goto error;
525 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 526 parse.idx, false, NULL);
fffd0934
JB
527 if (err)
528 goto error;
529 result->params[parse.idx].cipher = parse.p.cipher;
530 result->params[parse.idx].key_len = parse.p.key_len;
531 result->params[parse.idx].key = result->data[parse.idx];
532 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
533 }
534
535 return result;
536 error:
537 kfree(result);
538 return ERR_PTR(err);
539}
540
541static int nl80211_key_allowed(struct wireless_dev *wdev)
542{
543 ASSERT_WDEV_LOCK(wdev);
544
fffd0934
JB
545 switch (wdev->iftype) {
546 case NL80211_IFTYPE_AP:
547 case NL80211_IFTYPE_AP_VLAN:
074ac8df 548 case NL80211_IFTYPE_P2P_GO:
ff973af7 549 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
550 break;
551 case NL80211_IFTYPE_ADHOC:
552 if (!wdev->current_bss)
553 return -ENOLINK;
554 break;
555 case NL80211_IFTYPE_STATION:
074ac8df 556 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
557 if (wdev->sme_state != CFG80211_SME_CONNECTED)
558 return -ENOLINK;
559 break;
560 default:
561 return -EINVAL;
562 }
563
564 return 0;
565}
566
55682965
JB
567static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
568 struct cfg80211_registered_device *dev)
569{
570 void *hdr;
ee688b00
JB
571 struct nlattr *nl_bands, *nl_band;
572 struct nlattr *nl_freqs, *nl_freq;
573 struct nlattr *nl_rates, *nl_rate;
f59ac048 574 struct nlattr *nl_modes;
8fdc621d 575 struct nlattr *nl_cmds;
ee688b00
JB
576 enum ieee80211_band band;
577 struct ieee80211_channel *chan;
578 struct ieee80211_rate *rate;
579 int i;
f59ac048 580 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
581 const struct ieee80211_txrx_stypes *mgmt_stypes =
582 dev->wiphy.mgmt_stypes;
55682965
JB
583
584 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
585 if (!hdr)
586 return -1;
587
b5850a7a 588 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 589 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 590
f5ea9120
JB
591 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
592 cfg80211_rdev_list_generation);
593
b9a5f8ca
JM
594 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
595 dev->wiphy.retry_short);
596 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
597 dev->wiphy.retry_long);
598 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
599 dev->wiphy.frag_threshold);
600 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
601 dev->wiphy.rts_threshold);
81077e82
LT
602 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
603 dev->wiphy.coverage_class);
2a519311
JB
604 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
605 dev->wiphy.max_scan_ssids);
18a83659
JB
606 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
607 dev->wiphy.max_scan_ie_len);
ee688b00 608
e31b8213
JB
609 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
610 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
611 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
612 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
e31b8213 613
25e47c18
JB
614 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
615 sizeof(u32) * dev->wiphy.n_cipher_suites,
616 dev->wiphy.cipher_suites);
617
67fbb16b
SO
618 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
619 dev->wiphy.max_num_pmkids);
620
c0692b8f
JB
621 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
622 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
623
39fd5de4
BR
624 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
625 dev->wiphy.available_antennas_tx);
626 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
627 dev->wiphy.available_antennas_rx);
628
7f531e03
BR
629 if ((dev->wiphy.available_antennas_tx ||
630 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
631 u32 tx_ant = 0, rx_ant = 0;
632 int res;
633 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
634 if (!res) {
635 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
636 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
637 }
638 }
639
f59ac048
LR
640 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
641 if (!nl_modes)
642 goto nla_put_failure;
643
644 i = 0;
645 while (ifmodes) {
646 if (ifmodes & 1)
647 NLA_PUT_FLAG(msg, i);
648 ifmodes >>= 1;
649 i++;
650 }
651
652 nla_nest_end(msg, nl_modes);
653
ee688b00
JB
654 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
655 if (!nl_bands)
656 goto nla_put_failure;
657
658 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
659 if (!dev->wiphy.bands[band])
660 continue;
661
662 nl_band = nla_nest_start(msg, band);
663 if (!nl_band)
664 goto nla_put_failure;
665
d51626df
JB
666 /* add HT info */
667 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
668 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
669 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
670 &dev->wiphy.bands[band]->ht_cap.mcs);
671 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
672 dev->wiphy.bands[band]->ht_cap.cap);
673 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
674 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
675 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
676 dev->wiphy.bands[band]->ht_cap.ampdu_density);
677 }
678
ee688b00
JB
679 /* add frequencies */
680 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
681 if (!nl_freqs)
682 goto nla_put_failure;
683
684 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
685 nl_freq = nla_nest_start(msg, i);
686 if (!nl_freq)
687 goto nla_put_failure;
688
689 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
690
691 if (nl80211_msg_put_channel(msg, chan))
692 goto nla_put_failure;
e2f367f2 693
ee688b00
JB
694 nla_nest_end(msg, nl_freq);
695 }
696
697 nla_nest_end(msg, nl_freqs);
698
699 /* add bitrates */
700 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
701 if (!nl_rates)
702 goto nla_put_failure;
703
704 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
705 nl_rate = nla_nest_start(msg, i);
706 if (!nl_rate)
707 goto nla_put_failure;
708
709 rate = &dev->wiphy.bands[band]->bitrates[i];
710 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
711 rate->bitrate);
712 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
713 NLA_PUT_FLAG(msg,
714 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
715
716 nla_nest_end(msg, nl_rate);
717 }
718
719 nla_nest_end(msg, nl_rates);
720
721 nla_nest_end(msg, nl_band);
722 }
723 nla_nest_end(msg, nl_bands);
724
8fdc621d
JB
725 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
726 if (!nl_cmds)
727 goto nla_put_failure;
728
729 i = 0;
730#define CMD(op, n) \
731 do { \
732 if (dev->ops->op) { \
733 i++; \
734 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
735 } \
736 } while (0)
737
738 CMD(add_virtual_intf, NEW_INTERFACE);
739 CMD(change_virtual_intf, SET_INTERFACE);
740 CMD(add_key, NEW_KEY);
741 CMD(add_beacon, NEW_BEACON);
742 CMD(add_station, NEW_STATION);
743 CMD(add_mpath, NEW_MPATH);
24bdd9f4 744 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 745 CMD(change_bss, SET_BSS);
636a5d36
JM
746 CMD(auth, AUTHENTICATE);
747 CMD(assoc, ASSOCIATE);
748 CMD(deauth, DEAUTHENTICATE);
749 CMD(disassoc, DISASSOCIATE);
04a773ad 750 CMD(join_ibss, JOIN_IBSS);
29cbe68c 751 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
752 CMD(set_pmksa, SET_PMKSA);
753 CMD(del_pmksa, DEL_PMKSA);
754 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 755 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 756 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 757 CMD(mgmt_tx, FRAME);
f7ca38df 758 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 759 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
760 i++;
761 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
762 }
f444de05 763 CMD(set_channel, SET_CHANNEL);
e8347eba 764 CMD(set_wds_peer, SET_WDS_PEER);
807f8a8c
LC
765 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
766 CMD(sched_scan_start, START_SCHED_SCAN);
8fdc621d
JB
767
768#undef CMD
b23aa676 769
6829c878 770 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
771 i++;
772 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
773 }
774
6829c878 775 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
776 i++;
777 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
778 }
779
8fdc621d
JB
780 nla_nest_end(msg, nl_cmds);
781
a293911d
JB
782 if (dev->ops->remain_on_channel)
783 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
784 dev->wiphy.max_remain_on_channel_duration);
785
f7ca38df
JB
786 /* for now at least assume all drivers have it */
787 if (dev->ops->mgmt_tx)
788 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
789
2e161f78
JB
790 if (mgmt_stypes) {
791 u16 stypes;
792 struct nlattr *nl_ftypes, *nl_ifs;
793 enum nl80211_iftype ift;
794
795 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
796 if (!nl_ifs)
797 goto nla_put_failure;
798
799 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
800 nl_ftypes = nla_nest_start(msg, ift);
801 if (!nl_ftypes)
802 goto nla_put_failure;
803 i = 0;
804 stypes = mgmt_stypes[ift].tx;
805 while (stypes) {
806 if (stypes & 1)
807 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
808 (i << 4) | IEEE80211_FTYPE_MGMT);
809 stypes >>= 1;
810 i++;
811 }
812 nla_nest_end(msg, nl_ftypes);
813 }
814
74b70a4e
JB
815 nla_nest_end(msg, nl_ifs);
816
2e161f78
JB
817 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
818 if (!nl_ifs)
819 goto nla_put_failure;
820
821 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
822 nl_ftypes = nla_nest_start(msg, ift);
823 if (!nl_ftypes)
824 goto nla_put_failure;
825 i = 0;
826 stypes = mgmt_stypes[ift].rx;
827 while (stypes) {
828 if (stypes & 1)
829 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
830 (i << 4) | IEEE80211_FTYPE_MGMT);
831 stypes >>= 1;
832 i++;
833 }
834 nla_nest_end(msg, nl_ftypes);
835 }
836 nla_nest_end(msg, nl_ifs);
837 }
838
ff1b6e69
JB
839 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
840 struct nlattr *nl_wowlan;
841
842 nl_wowlan = nla_nest_start(msg,
843 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
844 if (!nl_wowlan)
845 goto nla_put_failure;
846
847 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
848 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
849 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
850 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
851 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
852 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
853 if (dev->wiphy.wowlan.n_patterns) {
854 struct nl80211_wowlan_pattern_support pat = {
855 .max_patterns = dev->wiphy.wowlan.n_patterns,
856 .min_pattern_len =
857 dev->wiphy.wowlan.pattern_min_len,
858 .max_pattern_len =
859 dev->wiphy.wowlan.pattern_max_len,
860 };
861 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
862 sizeof(pat), &pat);
863 }
864
865 nla_nest_end(msg, nl_wowlan);
866 }
867
55682965
JB
868 return genlmsg_end(msg, hdr);
869
870 nla_put_failure:
bc3ed28c
TG
871 genlmsg_cancel(msg, hdr);
872 return -EMSGSIZE;
55682965
JB
873}
874
875static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
876{
877 int idx = 0;
878 int start = cb->args[0];
879 struct cfg80211_registered_device *dev;
880
a1794390 881 mutex_lock(&cfg80211_mutex);
79c97e97 882 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
883 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
884 continue;
b4637271 885 if (++idx <= start)
55682965
JB
886 continue;
887 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
888 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
889 dev) < 0) {
890 idx--;
55682965 891 break;
b4637271 892 }
55682965 893 }
a1794390 894 mutex_unlock(&cfg80211_mutex);
55682965
JB
895
896 cb->args[0] = idx;
897
898 return skb->len;
899}
900
901static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
902{
903 struct sk_buff *msg;
4c476991 904 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 905
fd2120ca 906 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 907 if (!msg)
4c476991 908 return -ENOMEM;
55682965 909
4c476991
JB
910 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
911 nlmsg_free(msg);
912 return -ENOBUFS;
913 }
55682965 914
134e6375 915 return genlmsg_reply(msg, info);
55682965
JB
916}
917
31888487
JM
918static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
919 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
920 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
921 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
922 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
923 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
924};
925
926static int parse_txq_params(struct nlattr *tb[],
927 struct ieee80211_txq_params *txq_params)
928{
929 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
930 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
931 !tb[NL80211_TXQ_ATTR_AIFS])
932 return -EINVAL;
933
934 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
935 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
936 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
937 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
938 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
939
940 return 0;
941}
942
f444de05
JB
943static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
944{
945 /*
946 * You can only set the channel explicitly for AP, mesh
947 * and WDS type interfaces; all others have their channel
948 * managed via their respective "establish a connection"
949 * command (connect, join, ...)
950 *
951 * Monitors are special as they are normally slaved to
952 * whatever else is going on, so they behave as though
953 * you tried setting the wiphy channel itself.
954 */
955 return !wdev ||
956 wdev->iftype == NL80211_IFTYPE_AP ||
957 wdev->iftype == NL80211_IFTYPE_WDS ||
958 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
959 wdev->iftype == NL80211_IFTYPE_MONITOR ||
960 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
961}
962
963static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
964 struct wireless_dev *wdev,
965 struct genl_info *info)
966{
967 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
968 u32 freq;
969 int result;
970
971 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
972 return -EINVAL;
973
974 if (!nl80211_can_set_dev_channel(wdev))
975 return -EOPNOTSUPP;
976
977 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
978 channel_type = nla_get_u32(info->attrs[
979 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
980 if (channel_type != NL80211_CHAN_NO_HT &&
981 channel_type != NL80211_CHAN_HT20 &&
982 channel_type != NL80211_CHAN_HT40PLUS &&
983 channel_type != NL80211_CHAN_HT40MINUS)
984 return -EINVAL;
985 }
986
987 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
988
989 mutex_lock(&rdev->devlist_mtx);
990 if (wdev) {
991 wdev_lock(wdev);
992 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
993 wdev_unlock(wdev);
994 } else {
995 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
996 }
997 mutex_unlock(&rdev->devlist_mtx);
998
999 return result;
1000}
1001
1002static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1003{
4c476991
JB
1004 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1005 struct net_device *netdev = info->user_ptr[1];
f444de05 1006
4c476991 1007 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1008}
1009
e8347eba
BJ
1010static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1011{
43b19952
JB
1012 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1013 struct net_device *dev = info->user_ptr[1];
1014 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1015 const u8 *bssid;
e8347eba
BJ
1016
1017 if (!info->attrs[NL80211_ATTR_MAC])
1018 return -EINVAL;
1019
43b19952
JB
1020 if (netif_running(dev))
1021 return -EBUSY;
e8347eba 1022
43b19952
JB
1023 if (!rdev->ops->set_wds_peer)
1024 return -EOPNOTSUPP;
e8347eba 1025
43b19952
JB
1026 if (wdev->iftype != NL80211_IFTYPE_WDS)
1027 return -EOPNOTSUPP;
e8347eba
BJ
1028
1029 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1030 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1031}
1032
1033
55682965
JB
1034static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1035{
1036 struct cfg80211_registered_device *rdev;
f444de05
JB
1037 struct net_device *netdev = NULL;
1038 struct wireless_dev *wdev;
a1e567c8 1039 int result = 0, rem_txq_params = 0;
31888487 1040 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1041 u32 changed;
1042 u8 retry_short = 0, retry_long = 0;
1043 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1044 u8 coverage_class = 0;
55682965 1045
f444de05
JB
1046 /*
1047 * Try to find the wiphy and netdev. Normally this
1048 * function shouldn't need the netdev, but this is
1049 * done for backward compatibility -- previously
1050 * setting the channel was done per wiphy, but now
1051 * it is per netdev. Previous userland like hostapd
1052 * also passed a netdev to set_wiphy, so that it is
1053 * possible to let that go to the right netdev!
1054 */
4bbf4d56
JB
1055 mutex_lock(&cfg80211_mutex);
1056
f444de05
JB
1057 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1058 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1059
1060 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1061 if (netdev && netdev->ieee80211_ptr) {
1062 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1063 mutex_lock(&rdev->mtx);
1064 } else
1065 netdev = NULL;
4bbf4d56
JB
1066 }
1067
f444de05
JB
1068 if (!netdev) {
1069 rdev = __cfg80211_rdev_from_info(info);
1070 if (IS_ERR(rdev)) {
1071 mutex_unlock(&cfg80211_mutex);
4c476991 1072 return PTR_ERR(rdev);
f444de05
JB
1073 }
1074 wdev = NULL;
1075 netdev = NULL;
1076 result = 0;
1077
1078 mutex_lock(&rdev->mtx);
1079 } else if (netif_running(netdev) &&
1080 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1081 wdev = netdev->ieee80211_ptr;
1082 else
1083 wdev = NULL;
1084
1085 /*
1086 * end workaround code, by now the rdev is available
1087 * and locked, and wdev may or may not be NULL.
1088 */
4bbf4d56
JB
1089
1090 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1091 result = cfg80211_dev_rename(
1092 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1093
1094 mutex_unlock(&cfg80211_mutex);
1095
1096 if (result)
1097 goto bad_res;
31888487
JM
1098
1099 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1100 struct ieee80211_txq_params txq_params;
1101 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1102
1103 if (!rdev->ops->set_txq_params) {
1104 result = -EOPNOTSUPP;
1105 goto bad_res;
1106 }
1107
1108 nla_for_each_nested(nl_txq_params,
1109 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1110 rem_txq_params) {
1111 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1112 nla_data(nl_txq_params),
1113 nla_len(nl_txq_params),
1114 txq_params_policy);
1115 result = parse_txq_params(tb, &txq_params);
1116 if (result)
1117 goto bad_res;
1118
1119 result = rdev->ops->set_txq_params(&rdev->wiphy,
1120 &txq_params);
1121 if (result)
1122 goto bad_res;
1123 }
1124 }
55682965 1125
72bdcf34 1126 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1127 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1128 if (result)
1129 goto bad_res;
1130 }
1131
98d2ff8b
JO
1132 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1133 enum nl80211_tx_power_setting type;
1134 int idx, mbm = 0;
1135
1136 if (!rdev->ops->set_tx_power) {
60ea385f 1137 result = -EOPNOTSUPP;
98d2ff8b
JO
1138 goto bad_res;
1139 }
1140
1141 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1142 type = nla_get_u32(info->attrs[idx]);
1143
1144 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1145 (type != NL80211_TX_POWER_AUTOMATIC)) {
1146 result = -EINVAL;
1147 goto bad_res;
1148 }
1149
1150 if (type != NL80211_TX_POWER_AUTOMATIC) {
1151 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1152 mbm = nla_get_u32(info->attrs[idx]);
1153 }
1154
1155 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1156 if (result)
1157 goto bad_res;
1158 }
1159
afe0cbf8
BR
1160 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1161 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1162 u32 tx_ant, rx_ant;
7f531e03
BR
1163 if ((!rdev->wiphy.available_antennas_tx &&
1164 !rdev->wiphy.available_antennas_rx) ||
1165 !rdev->ops->set_antenna) {
afe0cbf8
BR
1166 result = -EOPNOTSUPP;
1167 goto bad_res;
1168 }
1169
1170 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1171 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1172
a7ffac95 1173 /* reject antenna configurations which don't match the
7f531e03
BR
1174 * available antenna masks, except for the "all" mask */
1175 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1176 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1177 result = -EINVAL;
1178 goto bad_res;
1179 }
1180
7f531e03
BR
1181 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1182 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1183
afe0cbf8
BR
1184 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1185 if (result)
1186 goto bad_res;
1187 }
1188
b9a5f8ca
JM
1189 changed = 0;
1190
1191 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1192 retry_short = nla_get_u8(
1193 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1194 if (retry_short == 0) {
1195 result = -EINVAL;
1196 goto bad_res;
1197 }
1198 changed |= WIPHY_PARAM_RETRY_SHORT;
1199 }
1200
1201 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1202 retry_long = nla_get_u8(
1203 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1204 if (retry_long == 0) {
1205 result = -EINVAL;
1206 goto bad_res;
1207 }
1208 changed |= WIPHY_PARAM_RETRY_LONG;
1209 }
1210
1211 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1212 frag_threshold = nla_get_u32(
1213 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1214 if (frag_threshold < 256) {
1215 result = -EINVAL;
1216 goto bad_res;
1217 }
1218 if (frag_threshold != (u32) -1) {
1219 /*
1220 * Fragments (apart from the last one) are required to
1221 * have even length. Make the fragmentation code
1222 * simpler by stripping LSB should someone try to use
1223 * odd threshold value.
1224 */
1225 frag_threshold &= ~0x1;
1226 }
1227 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1228 }
1229
1230 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1231 rts_threshold = nla_get_u32(
1232 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1233 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1234 }
1235
81077e82
LT
1236 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1237 coverage_class = nla_get_u8(
1238 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1239 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1240 }
1241
b9a5f8ca
JM
1242 if (changed) {
1243 u8 old_retry_short, old_retry_long;
1244 u32 old_frag_threshold, old_rts_threshold;
81077e82 1245 u8 old_coverage_class;
b9a5f8ca
JM
1246
1247 if (!rdev->ops->set_wiphy_params) {
1248 result = -EOPNOTSUPP;
1249 goto bad_res;
1250 }
1251
1252 old_retry_short = rdev->wiphy.retry_short;
1253 old_retry_long = rdev->wiphy.retry_long;
1254 old_frag_threshold = rdev->wiphy.frag_threshold;
1255 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1256 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1257
1258 if (changed & WIPHY_PARAM_RETRY_SHORT)
1259 rdev->wiphy.retry_short = retry_short;
1260 if (changed & WIPHY_PARAM_RETRY_LONG)
1261 rdev->wiphy.retry_long = retry_long;
1262 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1263 rdev->wiphy.frag_threshold = frag_threshold;
1264 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1265 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1266 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1267 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1268
1269 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1270 if (result) {
1271 rdev->wiphy.retry_short = old_retry_short;
1272 rdev->wiphy.retry_long = old_retry_long;
1273 rdev->wiphy.frag_threshold = old_frag_threshold;
1274 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1275 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1276 }
1277 }
72bdcf34 1278
306d6112 1279 bad_res:
4bbf4d56 1280 mutex_unlock(&rdev->mtx);
f444de05
JB
1281 if (netdev)
1282 dev_put(netdev);
55682965
JB
1283 return result;
1284}
1285
1286
1287static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1288 struct cfg80211_registered_device *rdev,
55682965
JB
1289 struct net_device *dev)
1290{
1291 void *hdr;
1292
1293 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1294 if (!hdr)
1295 return -1;
1296
1297 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1298 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1299 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1300 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1301
1302 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1303 rdev->devlist_generation ^
1304 (cfg80211_rdev_list_generation << 2));
1305
55682965
JB
1306 return genlmsg_end(msg, hdr);
1307
1308 nla_put_failure:
bc3ed28c
TG
1309 genlmsg_cancel(msg, hdr);
1310 return -EMSGSIZE;
55682965
JB
1311}
1312
1313static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1314{
1315 int wp_idx = 0;
1316 int if_idx = 0;
1317 int wp_start = cb->args[0];
1318 int if_start = cb->args[1];
f5ea9120 1319 struct cfg80211_registered_device *rdev;
55682965
JB
1320 struct wireless_dev *wdev;
1321
a1794390 1322 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1323 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1324 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1325 continue;
bba95fef
JB
1326 if (wp_idx < wp_start) {
1327 wp_idx++;
55682965 1328 continue;
bba95fef 1329 }
55682965
JB
1330 if_idx = 0;
1331
f5ea9120
JB
1332 mutex_lock(&rdev->devlist_mtx);
1333 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1334 if (if_idx < if_start) {
1335 if_idx++;
55682965 1336 continue;
bba95fef 1337 }
55682965
JB
1338 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1339 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1340 rdev, wdev->netdev) < 0) {
1341 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1342 goto out;
1343 }
1344 if_idx++;
55682965 1345 }
f5ea9120 1346 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1347
1348 wp_idx++;
55682965 1349 }
bba95fef 1350 out:
a1794390 1351 mutex_unlock(&cfg80211_mutex);
55682965
JB
1352
1353 cb->args[0] = wp_idx;
1354 cb->args[1] = if_idx;
1355
1356 return skb->len;
1357}
1358
1359static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1360{
1361 struct sk_buff *msg;
4c476991
JB
1362 struct cfg80211_registered_device *dev = info->user_ptr[0];
1363 struct net_device *netdev = info->user_ptr[1];
55682965 1364
fd2120ca 1365 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1366 if (!msg)
4c476991 1367 return -ENOMEM;
55682965 1368
d726405a 1369 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1370 dev, netdev) < 0) {
1371 nlmsg_free(msg);
1372 return -ENOBUFS;
1373 }
55682965 1374
134e6375 1375 return genlmsg_reply(msg, info);
55682965
JB
1376}
1377
66f7ac50
MW
1378static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1379 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1380 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1381 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1382 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1383 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1384};
1385
1386static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1387{
1388 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1389 int flag;
1390
1391 *mntrflags = 0;
1392
1393 if (!nla)
1394 return -EINVAL;
1395
1396 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1397 nla, mntr_flags_policy))
1398 return -EINVAL;
1399
1400 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1401 if (flags[flag])
1402 *mntrflags |= (1<<flag);
1403
1404 return 0;
1405}
1406
9bc383de 1407static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1408 struct net_device *netdev, u8 use_4addr,
1409 enum nl80211_iftype iftype)
9bc383de 1410{
ad4bb6f8 1411 if (!use_4addr) {
f350a0a8 1412 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1413 return -EBUSY;
9bc383de 1414 return 0;
ad4bb6f8 1415 }
9bc383de
JB
1416
1417 switch (iftype) {
1418 case NL80211_IFTYPE_AP_VLAN:
1419 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1420 return 0;
1421 break;
1422 case NL80211_IFTYPE_STATION:
1423 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1424 return 0;
1425 break;
1426 default:
1427 break;
1428 }
1429
1430 return -EOPNOTSUPP;
1431}
1432
55682965
JB
1433static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1434{
4c476991 1435 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1436 struct vif_params params;
e36d56b6 1437 int err;
04a773ad 1438 enum nl80211_iftype otype, ntype;
4c476991 1439 struct net_device *dev = info->user_ptr[1];
92ffe055 1440 u32 _flags, *flags = NULL;
ac7f9cfa 1441 bool change = false;
55682965 1442
2ec600d6
LCC
1443 memset(&params, 0, sizeof(params));
1444
04a773ad 1445 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1446
723b038d 1447 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1448 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1449 if (otype != ntype)
ac7f9cfa 1450 change = true;
4c476991
JB
1451 if (ntype > NL80211_IFTYPE_MAX)
1452 return -EINVAL;
723b038d
JB
1453 }
1454
92ffe055 1455 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1456 struct wireless_dev *wdev = dev->ieee80211_ptr;
1457
4c476991
JB
1458 if (ntype != NL80211_IFTYPE_MESH_POINT)
1459 return -EINVAL;
29cbe68c
JB
1460 if (netif_running(dev))
1461 return -EBUSY;
1462
1463 wdev_lock(wdev);
1464 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1465 IEEE80211_MAX_MESH_ID_LEN);
1466 wdev->mesh_id_up_len =
1467 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1468 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1469 wdev->mesh_id_up_len);
1470 wdev_unlock(wdev);
2ec600d6
LCC
1471 }
1472
8b787643
FF
1473 if (info->attrs[NL80211_ATTR_4ADDR]) {
1474 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1475 change = true;
ad4bb6f8 1476 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1477 if (err)
4c476991 1478 return err;
8b787643
FF
1479 } else {
1480 params.use_4addr = -1;
1481 }
1482
92ffe055 1483 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1484 if (ntype != NL80211_IFTYPE_MONITOR)
1485 return -EINVAL;
92ffe055
JB
1486 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1487 &_flags);
ac7f9cfa 1488 if (err)
4c476991 1489 return err;
ac7f9cfa
JB
1490
1491 flags = &_flags;
1492 change = true;
92ffe055 1493 }
3b85875a 1494
ac7f9cfa 1495 if (change)
3d54d255 1496 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1497 else
1498 err = 0;
60719ffd 1499
9bc383de
JB
1500 if (!err && params.use_4addr != -1)
1501 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1502
55682965
JB
1503 return err;
1504}
1505
1506static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1507{
4c476991 1508 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1509 struct vif_params params;
f9e10ce4 1510 struct net_device *dev;
55682965
JB
1511 int err;
1512 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1513 u32 flags;
55682965 1514
2ec600d6
LCC
1515 memset(&params, 0, sizeof(params));
1516
55682965
JB
1517 if (!info->attrs[NL80211_ATTR_IFNAME])
1518 return -EINVAL;
1519
1520 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1521 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1522 if (type > NL80211_IFTYPE_MAX)
1523 return -EINVAL;
1524 }
1525
79c97e97 1526 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1527 !(rdev->wiphy.interface_modes & (1 << type)))
1528 return -EOPNOTSUPP;
55682965 1529
9bc383de 1530 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1531 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1532 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1533 if (err)
4c476991 1534 return err;
9bc383de 1535 }
8b787643 1536
66f7ac50
MW
1537 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1538 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1539 &flags);
f9e10ce4 1540 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1541 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1542 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1543 if (IS_ERR(dev))
1544 return PTR_ERR(dev);
2ec600d6 1545
29cbe68c
JB
1546 if (type == NL80211_IFTYPE_MESH_POINT &&
1547 info->attrs[NL80211_ATTR_MESH_ID]) {
1548 struct wireless_dev *wdev = dev->ieee80211_ptr;
1549
1550 wdev_lock(wdev);
1551 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1552 IEEE80211_MAX_MESH_ID_LEN);
1553 wdev->mesh_id_up_len =
1554 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1555 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1556 wdev->mesh_id_up_len);
1557 wdev_unlock(wdev);
1558 }
1559
f9e10ce4 1560 return 0;
55682965
JB
1561}
1562
1563static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1564{
4c476991
JB
1565 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1566 struct net_device *dev = info->user_ptr[1];
55682965 1567
4c476991
JB
1568 if (!rdev->ops->del_virtual_intf)
1569 return -EOPNOTSUPP;
55682965 1570
4c476991 1571 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1572}
1573
41ade00f
JB
1574struct get_key_cookie {
1575 struct sk_buff *msg;
1576 int error;
b9454e83 1577 int idx;
41ade00f
JB
1578};
1579
1580static void get_key_callback(void *c, struct key_params *params)
1581{
b9454e83 1582 struct nlattr *key;
41ade00f
JB
1583 struct get_key_cookie *cookie = c;
1584
1585 if (params->key)
1586 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1587 params->key_len, params->key);
1588
1589 if (params->seq)
1590 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1591 params->seq_len, params->seq);
1592
1593 if (params->cipher)
1594 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1595 params->cipher);
1596
b9454e83
JB
1597 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1598 if (!key)
1599 goto nla_put_failure;
1600
1601 if (params->key)
1602 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1603 params->key_len, params->key);
1604
1605 if (params->seq)
1606 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1607 params->seq_len, params->seq);
1608
1609 if (params->cipher)
1610 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1611 params->cipher);
1612
1613 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1614
1615 nla_nest_end(cookie->msg, key);
1616
41ade00f
JB
1617 return;
1618 nla_put_failure:
1619 cookie->error = 1;
1620}
1621
1622static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1623{
4c476991 1624 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1625 int err;
4c476991 1626 struct net_device *dev = info->user_ptr[1];
41ade00f 1627 u8 key_idx = 0;
e31b8213
JB
1628 const u8 *mac_addr = NULL;
1629 bool pairwise;
41ade00f
JB
1630 struct get_key_cookie cookie = {
1631 .error = 0,
1632 };
1633 void *hdr;
1634 struct sk_buff *msg;
1635
1636 if (info->attrs[NL80211_ATTR_KEY_IDX])
1637 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1638
3cfcf6ac 1639 if (key_idx > 5)
41ade00f
JB
1640 return -EINVAL;
1641
1642 if (info->attrs[NL80211_ATTR_MAC])
1643 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1644
e31b8213
JB
1645 pairwise = !!mac_addr;
1646 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1647 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1648 if (kt >= NUM_NL80211_KEYTYPES)
1649 return -EINVAL;
1650 if (kt != NL80211_KEYTYPE_GROUP &&
1651 kt != NL80211_KEYTYPE_PAIRWISE)
1652 return -EINVAL;
1653 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1654 }
1655
4c476991
JB
1656 if (!rdev->ops->get_key)
1657 return -EOPNOTSUPP;
41ade00f 1658
fd2120ca 1659 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1660 if (!msg)
1661 return -ENOMEM;
41ade00f
JB
1662
1663 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1664 NL80211_CMD_NEW_KEY);
4c476991
JB
1665 if (IS_ERR(hdr))
1666 return PTR_ERR(hdr);
41ade00f
JB
1667
1668 cookie.msg = msg;
b9454e83 1669 cookie.idx = key_idx;
41ade00f
JB
1670
1671 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1672 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1673 if (mac_addr)
1674 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1675
e31b8213
JB
1676 if (pairwise && mac_addr &&
1677 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1678 return -ENOENT;
1679
1680 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1681 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1682
1683 if (err)
6c95e2a2 1684 goto free_msg;
41ade00f
JB
1685
1686 if (cookie.error)
1687 goto nla_put_failure;
1688
1689 genlmsg_end(msg, hdr);
4c476991 1690 return genlmsg_reply(msg, info);
41ade00f
JB
1691
1692 nla_put_failure:
1693 err = -ENOBUFS;
6c95e2a2 1694 free_msg:
41ade00f 1695 nlmsg_free(msg);
41ade00f
JB
1696 return err;
1697}
1698
1699static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1700{
4c476991 1701 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1702 struct key_parse key;
41ade00f 1703 int err;
4c476991 1704 struct net_device *dev = info->user_ptr[1];
41ade00f 1705
b9454e83
JB
1706 err = nl80211_parse_key(info, &key);
1707 if (err)
1708 return err;
41ade00f 1709
b9454e83 1710 if (key.idx < 0)
41ade00f
JB
1711 return -EINVAL;
1712
b9454e83
JB
1713 /* only support setting default key */
1714 if (!key.def && !key.defmgmt)
41ade00f
JB
1715 return -EINVAL;
1716
dbd2fd65 1717 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1718
dbd2fd65
JB
1719 if (key.def) {
1720 if (!rdev->ops->set_default_key) {
1721 err = -EOPNOTSUPP;
1722 goto out;
1723 }
41ade00f 1724
dbd2fd65
JB
1725 err = nl80211_key_allowed(dev->ieee80211_ptr);
1726 if (err)
1727 goto out;
1728
dbd2fd65
JB
1729 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1730 key.def_uni, key.def_multi);
1731
1732 if (err)
1733 goto out;
fffd0934 1734
3d23e349 1735#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1736 dev->ieee80211_ptr->wext.default_key = key.idx;
1737#endif
1738 } else {
1739 if (key.def_uni || !key.def_multi) {
1740 err = -EINVAL;
1741 goto out;
1742 }
1743
1744 if (!rdev->ops->set_default_mgmt_key) {
1745 err = -EOPNOTSUPP;
1746 goto out;
1747 }
1748
1749 err = nl80211_key_allowed(dev->ieee80211_ptr);
1750 if (err)
1751 goto out;
1752
1753 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1754 dev, key.idx);
1755 if (err)
1756 goto out;
1757
1758#ifdef CONFIG_CFG80211_WEXT
1759 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1760#endif
dbd2fd65
JB
1761 }
1762
1763 out:
fffd0934 1764 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1765
41ade00f
JB
1766 return err;
1767}
1768
1769static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1770{
4c476991 1771 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1772 int err;
4c476991 1773 struct net_device *dev = info->user_ptr[1];
b9454e83 1774 struct key_parse key;
e31b8213 1775 const u8 *mac_addr = NULL;
41ade00f 1776
b9454e83
JB
1777 err = nl80211_parse_key(info, &key);
1778 if (err)
1779 return err;
41ade00f 1780
b9454e83 1781 if (!key.p.key)
41ade00f
JB
1782 return -EINVAL;
1783
41ade00f
JB
1784 if (info->attrs[NL80211_ATTR_MAC])
1785 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1786
e31b8213
JB
1787 if (key.type == -1) {
1788 if (mac_addr)
1789 key.type = NL80211_KEYTYPE_PAIRWISE;
1790 else
1791 key.type = NL80211_KEYTYPE_GROUP;
1792 }
1793
1794 /* for now */
1795 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1796 key.type != NL80211_KEYTYPE_GROUP)
1797 return -EINVAL;
1798
4c476991
JB
1799 if (!rdev->ops->add_key)
1800 return -EOPNOTSUPP;
25e47c18 1801
e31b8213
JB
1802 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1803 key.type == NL80211_KEYTYPE_PAIRWISE,
1804 mac_addr))
4c476991 1805 return -EINVAL;
41ade00f 1806
fffd0934
JB
1807 wdev_lock(dev->ieee80211_ptr);
1808 err = nl80211_key_allowed(dev->ieee80211_ptr);
1809 if (!err)
1810 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1811 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1812 mac_addr, &key.p);
1813 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1814
41ade00f
JB
1815 return err;
1816}
1817
1818static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1819{
4c476991 1820 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1821 int err;
4c476991 1822 struct net_device *dev = info->user_ptr[1];
41ade00f 1823 u8 *mac_addr = NULL;
b9454e83 1824 struct key_parse key;
41ade00f 1825
b9454e83
JB
1826 err = nl80211_parse_key(info, &key);
1827 if (err)
1828 return err;
41ade00f
JB
1829
1830 if (info->attrs[NL80211_ATTR_MAC])
1831 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1832
e31b8213
JB
1833 if (key.type == -1) {
1834 if (mac_addr)
1835 key.type = NL80211_KEYTYPE_PAIRWISE;
1836 else
1837 key.type = NL80211_KEYTYPE_GROUP;
1838 }
1839
1840 /* for now */
1841 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1842 key.type != NL80211_KEYTYPE_GROUP)
1843 return -EINVAL;
1844
4c476991
JB
1845 if (!rdev->ops->del_key)
1846 return -EOPNOTSUPP;
41ade00f 1847
fffd0934
JB
1848 wdev_lock(dev->ieee80211_ptr);
1849 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
1850
1851 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1852 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1853 err = -ENOENT;
1854
fffd0934 1855 if (!err)
e31b8213
JB
1856 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1857 key.type == NL80211_KEYTYPE_PAIRWISE,
1858 mac_addr);
41ade00f 1859
3d23e349 1860#ifdef CONFIG_CFG80211_WEXT
08645126 1861 if (!err) {
b9454e83 1862 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1863 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1864 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1865 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1866 }
1867#endif
fffd0934 1868 wdev_unlock(dev->ieee80211_ptr);
08645126 1869
41ade00f
JB
1870 return err;
1871}
1872
ed1b6cc7
JB
1873static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1874{
1875 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1876 struct beacon_parameters *info);
4c476991
JB
1877 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1878 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1879 struct beacon_parameters params;
1880 int haveinfo = 0;
1881
f4a11bb0
JB
1882 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1883 return -EINVAL;
1884
074ac8df 1885 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1886 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1887 return -EOPNOTSUPP;
eec60b03 1888
ed1b6cc7
JB
1889 switch (info->genlhdr->cmd) {
1890 case NL80211_CMD_NEW_BEACON:
1891 /* these are required for NEW_BEACON */
1892 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1893 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1894 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1895 return -EINVAL;
ed1b6cc7 1896
79c97e97 1897 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1898 break;
1899 case NL80211_CMD_SET_BEACON:
79c97e97 1900 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1901 break;
1902 default:
1903 WARN_ON(1);
4c476991 1904 return -EOPNOTSUPP;
ed1b6cc7
JB
1905 }
1906
4c476991
JB
1907 if (!call)
1908 return -EOPNOTSUPP;
ed1b6cc7
JB
1909
1910 memset(&params, 0, sizeof(params));
1911
1912 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1913 params.interval =
1914 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1915 haveinfo = 1;
1916 }
1917
1918 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1919 params.dtim_period =
1920 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1921 haveinfo = 1;
1922 }
1923
1924 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1925 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1926 params.head_len =
1927 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1928 haveinfo = 1;
1929 }
1930
1931 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1932 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1933 params.tail_len =
1934 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1935 haveinfo = 1;
1936 }
1937
4c476991
JB
1938 if (!haveinfo)
1939 return -EINVAL;
3b85875a 1940
4c476991 1941 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1942}
1943
1944static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1945{
4c476991
JB
1946 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1947 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1948
4c476991
JB
1949 if (!rdev->ops->del_beacon)
1950 return -EOPNOTSUPP;
ed1b6cc7 1951
074ac8df 1952 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1953 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1954 return -EOPNOTSUPP;
3b85875a 1955
4c476991 1956 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1957}
1958
5727ef1b
JB
1959static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1960 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1961 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1962 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1963 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 1964 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
5727ef1b
JB
1965};
1966
eccb8e8f
JB
1967static int parse_station_flags(struct genl_info *info,
1968 struct station_parameters *params)
5727ef1b
JB
1969{
1970 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1971 struct nlattr *nla;
5727ef1b
JB
1972 int flag;
1973
eccb8e8f
JB
1974 /*
1975 * Try parsing the new attribute first so userspace
1976 * can specify both for older kernels.
1977 */
1978 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1979 if (nla) {
1980 struct nl80211_sta_flag_update *sta_flags;
1981
1982 sta_flags = nla_data(nla);
1983 params->sta_flags_mask = sta_flags->mask;
1984 params->sta_flags_set = sta_flags->set;
1985 if ((params->sta_flags_mask |
1986 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1987 return -EINVAL;
1988 return 0;
1989 }
1990
1991 /* if present, parse the old attribute */
5727ef1b 1992
eccb8e8f 1993 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1994 if (!nla)
1995 return 0;
1996
1997 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1998 nla, sta_flags_policy))
1999 return -EINVAL;
2000
eccb8e8f
JB
2001 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
2002 params->sta_flags_mask &= ~1;
5727ef1b
JB
2003
2004 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2005 if (flags[flag])
eccb8e8f 2006 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2007
2008 return 0;
2009}
2010
c8dcfd8a
FF
2011static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2012 int attr)
2013{
2014 struct nlattr *rate;
2015 u16 bitrate;
2016
2017 rate = nla_nest_start(msg, attr);
2018 if (!rate)
2019 goto nla_put_failure;
2020
2021 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2022 bitrate = cfg80211_calculate_bitrate(info);
2023 if (bitrate > 0)
2024 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2025
2026 if (info->flags & RATE_INFO_FLAGS_MCS)
2027 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2028 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2029 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2030 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2031 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2032
2033 nla_nest_end(msg, rate);
2034 return true;
2035
2036nla_put_failure:
2037 return false;
2038}
2039
fd5b74dc
JB
2040static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2041 int flags, struct net_device *dev,
98b62183 2042 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2043{
2044 void *hdr;
f4263c98 2045 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2046
2047 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2048 if (!hdr)
2049 return -1;
2050
2051 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2052 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2053
f5ea9120
JB
2054 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2055
2ec600d6
LCC
2056 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2057 if (!sinfoattr)
fd5b74dc 2058 goto nla_put_failure;
ebe27c91
MSS
2059 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2060 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2061 sinfo->connected_time);
2ec600d6
LCC
2062 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2063 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2064 sinfo->inactive_time);
2065 if (sinfo->filled & STATION_INFO_RX_BYTES)
2066 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2067 sinfo->rx_bytes);
2068 if (sinfo->filled & STATION_INFO_TX_BYTES)
2069 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2070 sinfo->tx_bytes);
2071 if (sinfo->filled & STATION_INFO_LLID)
2072 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2073 sinfo->llid);
2074 if (sinfo->filled & STATION_INFO_PLID)
2075 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2076 sinfo->plid);
2077 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2078 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2079 sinfo->plink_state);
420e7fab
HR
2080 if (sinfo->filled & STATION_INFO_SIGNAL)
2081 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2082 sinfo->signal);
541a45a1
BR
2083 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2084 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2085 sinfo->signal_avg);
420e7fab 2086 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2087 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2088 NL80211_STA_INFO_TX_BITRATE))
2089 goto nla_put_failure;
2090 }
2091 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2092 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2093 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2094 goto nla_put_failure;
420e7fab 2095 }
98c8a60a
JM
2096 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2097 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2098 sinfo->rx_packets);
2099 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2100 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2101 sinfo->tx_packets);
b206b4ef
BR
2102 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2103 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2104 sinfo->tx_retries);
2105 if (sinfo->filled & STATION_INFO_TX_FAILED)
2106 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2107 sinfo->tx_failed);
f4263c98
PS
2108 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2109 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2110 if (!bss_param)
2111 goto nla_put_failure;
2112
2113 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2114 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2115 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2116 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2117 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2118 NLA_PUT_FLAG(msg,
2119 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2120 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2121 sinfo->bss_param.dtim_period);
2122 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2123 sinfo->bss_param.beacon_interval);
2124
2125 nla_nest_end(msg, bss_param);
2126 }
2ec600d6 2127 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
2128
2129 return genlmsg_end(msg, hdr);
2130
2131 nla_put_failure:
bc3ed28c
TG
2132 genlmsg_cancel(msg, hdr);
2133 return -EMSGSIZE;
fd5b74dc
JB
2134}
2135
2ec600d6 2136static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2137 struct netlink_callback *cb)
2ec600d6 2138{
2ec600d6
LCC
2139 struct station_info sinfo;
2140 struct cfg80211_registered_device *dev;
bba95fef 2141 struct net_device *netdev;
2ec600d6 2142 u8 mac_addr[ETH_ALEN];
bba95fef 2143 int sta_idx = cb->args[1];
2ec600d6 2144 int err;
2ec600d6 2145
67748893
JB
2146 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2147 if (err)
2148 return err;
bba95fef
JB
2149
2150 if (!dev->ops->dump_station) {
eec60b03 2151 err = -EOPNOTSUPP;
bba95fef
JB
2152 goto out_err;
2153 }
2154
bba95fef
JB
2155 while (1) {
2156 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2157 mac_addr, &sinfo);
2158 if (err == -ENOENT)
2159 break;
2160 if (err)
3b85875a 2161 goto out_err;
bba95fef
JB
2162
2163 if (nl80211_send_station(skb,
2164 NETLINK_CB(cb->skb).pid,
2165 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2166 netdev, mac_addr,
2167 &sinfo) < 0)
2168 goto out;
2169
2170 sta_idx++;
2171 }
2172
2173
2174 out:
2175 cb->args[1] = sta_idx;
2176 err = skb->len;
bba95fef 2177 out_err:
67748893 2178 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2179
2180 return err;
2ec600d6 2181}
fd5b74dc 2182
5727ef1b
JB
2183static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2184{
4c476991
JB
2185 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2186 struct net_device *dev = info->user_ptr[1];
2ec600d6 2187 struct station_info sinfo;
fd5b74dc
JB
2188 struct sk_buff *msg;
2189 u8 *mac_addr = NULL;
4c476991 2190 int err;
fd5b74dc 2191
2ec600d6 2192 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2193
2194 if (!info->attrs[NL80211_ATTR_MAC])
2195 return -EINVAL;
2196
2197 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2198
4c476991
JB
2199 if (!rdev->ops->get_station)
2200 return -EOPNOTSUPP;
3b85875a 2201
4c476991 2202 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2203 if (err)
4c476991 2204 return err;
2ec600d6 2205
fd2120ca 2206 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2207 if (!msg)
4c476991 2208 return -ENOMEM;
fd5b74dc
JB
2209
2210 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2211 dev, mac_addr, &sinfo) < 0) {
2212 nlmsg_free(msg);
2213 return -ENOBUFS;
2214 }
3b85875a 2215
4c476991 2216 return genlmsg_reply(msg, info);
5727ef1b
JB
2217}
2218
2219/*
c258d2de 2220 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2221 */
463d0183 2222static int get_vlan(struct genl_info *info,
5727ef1b
JB
2223 struct cfg80211_registered_device *rdev,
2224 struct net_device **vlan)
2225{
463d0183 2226 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2227 *vlan = NULL;
2228
2229 if (vlanattr) {
463d0183
JB
2230 *vlan = dev_get_by_index(genl_info_net(info),
2231 nla_get_u32(vlanattr));
5727ef1b
JB
2232 if (!*vlan)
2233 return -ENODEV;
2234 if (!(*vlan)->ieee80211_ptr)
2235 return -EINVAL;
2236 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2237 return -EINVAL;
c258d2de
FF
2238 if (!netif_running(*vlan))
2239 return -ENETDOWN;
5727ef1b
JB
2240 }
2241 return 0;
2242}
2243
2244static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2245{
4c476991 2246 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2247 int err;
4c476991 2248 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2249 struct station_parameters params;
2250 u8 *mac_addr = NULL;
2251
2252 memset(&params, 0, sizeof(params));
2253
2254 params.listen_interval = -1;
9c3990aa 2255 params.plink_state = PLINK_INVALID;
5727ef1b
JB
2256
2257 if (info->attrs[NL80211_ATTR_STA_AID])
2258 return -EINVAL;
2259
2260 if (!info->attrs[NL80211_ATTR_MAC])
2261 return -EINVAL;
2262
2263 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2264
2265 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2266 params.supported_rates =
2267 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2268 params.supported_rates_len =
2269 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2270 }
2271
2272 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2273 params.listen_interval =
2274 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2275
36aedc90
JM
2276 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2277 params.ht_capa =
2278 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2279
eccb8e8f 2280 if (parse_station_flags(info, &params))
5727ef1b
JB
2281 return -EINVAL;
2282
2ec600d6
LCC
2283 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2284 params.plink_action =
2285 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2286
9c3990aa
JC
2287 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2288 params.plink_state =
2289 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2290
463d0183 2291 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2292 if (err)
034d655e 2293 goto out;
a97f4424
JB
2294
2295 /* validate settings */
2296 err = 0;
2297
2298 switch (dev->ieee80211_ptr->iftype) {
2299 case NL80211_IFTYPE_AP:
2300 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2301 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2302 /* disallow mesh-specific things */
2303 if (params.plink_action)
2304 err = -EINVAL;
2305 break;
074ac8df 2306 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2307 case NL80211_IFTYPE_STATION:
2308 /* disallow everything but AUTHORIZED flag */
2309 if (params.plink_action)
2310 err = -EINVAL;
2311 if (params.vlan)
2312 err = -EINVAL;
2313 if (params.supported_rates)
2314 err = -EINVAL;
2315 if (params.ht_capa)
2316 err = -EINVAL;
2317 if (params.listen_interval >= 0)
2318 err = -EINVAL;
2319 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2320 err = -EINVAL;
2321 break;
2322 case NL80211_IFTYPE_MESH_POINT:
2323 /* disallow things mesh doesn't support */
2324 if (params.vlan)
2325 err = -EINVAL;
2326 if (params.ht_capa)
2327 err = -EINVAL;
2328 if (params.listen_interval >= 0)
2329 err = -EINVAL;
b39c48fa
JC
2330 if (params.sta_flags_mask &
2331 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2332 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2333 BIT(NL80211_STA_FLAG_AUTHORIZED)))
a97f4424
JB
2334 err = -EINVAL;
2335 break;
2336 default:
2337 err = -EINVAL;
034d655e
JB
2338 }
2339
5727ef1b
JB
2340 if (err)
2341 goto out;
2342
79c97e97 2343 if (!rdev->ops->change_station) {
5727ef1b
JB
2344 err = -EOPNOTSUPP;
2345 goto out;
2346 }
2347
79c97e97 2348 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2349
2350 out:
2351 if (params.vlan)
2352 dev_put(params.vlan);
3b85875a 2353
5727ef1b
JB
2354 return err;
2355}
2356
2357static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2358{
4c476991 2359 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2360 int err;
4c476991 2361 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2362 struct station_parameters params;
2363 u8 *mac_addr = NULL;
2364
2365 memset(&params, 0, sizeof(params));
2366
2367 if (!info->attrs[NL80211_ATTR_MAC])
2368 return -EINVAL;
2369
5727ef1b
JB
2370 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2371 return -EINVAL;
2372
2373 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2374 return -EINVAL;
2375
0e956c13
TLSC
2376 if (!info->attrs[NL80211_ATTR_STA_AID])
2377 return -EINVAL;
2378
5727ef1b
JB
2379 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2380 params.supported_rates =
2381 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2382 params.supported_rates_len =
2383 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2384 params.listen_interval =
2385 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2386
0e956c13
TLSC
2387 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2388 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2389 return -EINVAL;
51b50fbe 2390
36aedc90
JM
2391 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2392 params.ht_capa =
2393 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2394
96b78dff
JC
2395 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2396 params.plink_action =
2397 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2398
eccb8e8f 2399 if (parse_station_flags(info, &params))
5727ef1b
JB
2400 return -EINVAL;
2401
0e956c13 2402 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2403 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
96b78dff 2404 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2405 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2406 return -EINVAL;
0e956c13 2407
463d0183 2408 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2409 if (err)
e80cf853 2410 goto out;
a97f4424
JB
2411
2412 /* validate settings */
2413 err = 0;
2414
79c97e97 2415 if (!rdev->ops->add_station) {
5727ef1b
JB
2416 err = -EOPNOTSUPP;
2417 goto out;
2418 }
2419
79c97e97 2420 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2421
2422 out:
2423 if (params.vlan)
2424 dev_put(params.vlan);
5727ef1b
JB
2425 return err;
2426}
2427
2428static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2429{
4c476991
JB
2430 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2431 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2432 u8 *mac_addr = NULL;
2433
2434 if (info->attrs[NL80211_ATTR_MAC])
2435 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2436
e80cf853 2437 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2438 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2439 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2440 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2441 return -EINVAL;
5727ef1b 2442
4c476991
JB
2443 if (!rdev->ops->del_station)
2444 return -EOPNOTSUPP;
3b85875a 2445
4c476991 2446 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2447}
2448
2ec600d6
LCC
2449static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2450 int flags, struct net_device *dev,
2451 u8 *dst, u8 *next_hop,
2452 struct mpath_info *pinfo)
2453{
2454 void *hdr;
2455 struct nlattr *pinfoattr;
2456
2457 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2458 if (!hdr)
2459 return -1;
2460
2461 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2462 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2463 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2464
f5ea9120
JB
2465 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2466
2ec600d6
LCC
2467 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2468 if (!pinfoattr)
2469 goto nla_put_failure;
2470 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2471 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2472 pinfo->frame_qlen);
d19b3bf6
RP
2473 if (pinfo->filled & MPATH_INFO_SN)
2474 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2475 pinfo->sn);
2ec600d6
LCC
2476 if (pinfo->filled & MPATH_INFO_METRIC)
2477 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2478 pinfo->metric);
2479 if (pinfo->filled & MPATH_INFO_EXPTIME)
2480 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2481 pinfo->exptime);
2482 if (pinfo->filled & MPATH_INFO_FLAGS)
2483 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2484 pinfo->flags);
2485 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2486 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2487 pinfo->discovery_timeout);
2488 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2489 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2490 pinfo->discovery_retries);
2491
2492 nla_nest_end(msg, pinfoattr);
2493
2494 return genlmsg_end(msg, hdr);
2495
2496 nla_put_failure:
bc3ed28c
TG
2497 genlmsg_cancel(msg, hdr);
2498 return -EMSGSIZE;
2ec600d6
LCC
2499}
2500
2501static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2502 struct netlink_callback *cb)
2ec600d6 2503{
2ec600d6
LCC
2504 struct mpath_info pinfo;
2505 struct cfg80211_registered_device *dev;
bba95fef 2506 struct net_device *netdev;
2ec600d6
LCC
2507 u8 dst[ETH_ALEN];
2508 u8 next_hop[ETH_ALEN];
bba95fef 2509 int path_idx = cb->args[1];
2ec600d6 2510 int err;
2ec600d6 2511
67748893
JB
2512 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2513 if (err)
2514 return err;
bba95fef
JB
2515
2516 if (!dev->ops->dump_mpath) {
eec60b03 2517 err = -EOPNOTSUPP;
bba95fef
JB
2518 goto out_err;
2519 }
2520
eec60b03
JM
2521 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2522 err = -EOPNOTSUPP;
0448b5fc 2523 goto out_err;
eec60b03
JM
2524 }
2525
bba95fef
JB
2526 while (1) {
2527 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2528 dst, next_hop, &pinfo);
2529 if (err == -ENOENT)
2ec600d6 2530 break;
bba95fef 2531 if (err)
3b85875a 2532 goto out_err;
2ec600d6 2533
bba95fef
JB
2534 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2535 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2536 netdev, dst, next_hop,
2537 &pinfo) < 0)
2538 goto out;
2ec600d6 2539
bba95fef 2540 path_idx++;
2ec600d6 2541 }
2ec600d6 2542
2ec600d6 2543
bba95fef
JB
2544 out:
2545 cb->args[1] = path_idx;
2546 err = skb->len;
bba95fef 2547 out_err:
67748893 2548 nl80211_finish_netdev_dump(dev);
bba95fef 2549 return err;
2ec600d6
LCC
2550}
2551
2552static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2553{
4c476991 2554 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2555 int err;
4c476991 2556 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2557 struct mpath_info pinfo;
2558 struct sk_buff *msg;
2559 u8 *dst = NULL;
2560 u8 next_hop[ETH_ALEN];
2561
2562 memset(&pinfo, 0, sizeof(pinfo));
2563
2564 if (!info->attrs[NL80211_ATTR_MAC])
2565 return -EINVAL;
2566
2567 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2568
4c476991
JB
2569 if (!rdev->ops->get_mpath)
2570 return -EOPNOTSUPP;
2ec600d6 2571
4c476991
JB
2572 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2573 return -EOPNOTSUPP;
eec60b03 2574
79c97e97 2575 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2576 if (err)
4c476991 2577 return err;
2ec600d6 2578
fd2120ca 2579 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2580 if (!msg)
4c476991 2581 return -ENOMEM;
2ec600d6
LCC
2582
2583 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2584 dev, dst, next_hop, &pinfo) < 0) {
2585 nlmsg_free(msg);
2586 return -ENOBUFS;
2587 }
3b85875a 2588
4c476991 2589 return genlmsg_reply(msg, info);
2ec600d6
LCC
2590}
2591
2592static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2593{
4c476991
JB
2594 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2595 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2596 u8 *dst = NULL;
2597 u8 *next_hop = NULL;
2598
2599 if (!info->attrs[NL80211_ATTR_MAC])
2600 return -EINVAL;
2601
2602 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2603 return -EINVAL;
2604
2605 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2606 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2607
4c476991
JB
2608 if (!rdev->ops->change_mpath)
2609 return -EOPNOTSUPP;
35a8efe1 2610
4c476991
JB
2611 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2612 return -EOPNOTSUPP;
2ec600d6 2613
4c476991 2614 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2615}
4c476991 2616
2ec600d6
LCC
2617static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2618{
4c476991
JB
2619 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2620 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2621 u8 *dst = NULL;
2622 u8 *next_hop = NULL;
2623
2624 if (!info->attrs[NL80211_ATTR_MAC])
2625 return -EINVAL;
2626
2627 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2628 return -EINVAL;
2629
2630 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2631 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2632
4c476991
JB
2633 if (!rdev->ops->add_mpath)
2634 return -EOPNOTSUPP;
35a8efe1 2635
4c476991
JB
2636 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2637 return -EOPNOTSUPP;
2ec600d6 2638
4c476991 2639 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2640}
2641
2642static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2643{
4c476991
JB
2644 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2645 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2646 u8 *dst = NULL;
2647
2648 if (info->attrs[NL80211_ATTR_MAC])
2649 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2650
4c476991
JB
2651 if (!rdev->ops->del_mpath)
2652 return -EOPNOTSUPP;
3b85875a 2653
4c476991 2654 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2655}
2656
9f1ba906
JM
2657static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2658{
4c476991
JB
2659 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2660 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2661 struct bss_parameters params;
2662
2663 memset(&params, 0, sizeof(params));
2664 /* default to not changing parameters */
2665 params.use_cts_prot = -1;
2666 params.use_short_preamble = -1;
2667 params.use_short_slot_time = -1;
fd8aaaf3 2668 params.ap_isolate = -1;
50b12f59 2669 params.ht_opmode = -1;
9f1ba906
JM
2670
2671 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2672 params.use_cts_prot =
2673 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2674 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2675 params.use_short_preamble =
2676 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2677 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2678 params.use_short_slot_time =
2679 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2680 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2681 params.basic_rates =
2682 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2683 params.basic_rates_len =
2684 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2685 }
fd8aaaf3
FF
2686 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2687 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2688 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2689 params.ht_opmode =
2690 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2691
4c476991
JB
2692 if (!rdev->ops->change_bss)
2693 return -EOPNOTSUPP;
9f1ba906 2694
074ac8df 2695 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2696 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2697 return -EOPNOTSUPP;
3b85875a 2698
4c476991 2699 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2700}
2701
b54452b0 2702static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2703 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2704 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2705 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2706 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2707 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2708 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2709};
2710
2711static int parse_reg_rule(struct nlattr *tb[],
2712 struct ieee80211_reg_rule *reg_rule)
2713{
2714 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2715 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2716
2717 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2718 return -EINVAL;
2719 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2720 return -EINVAL;
2721 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2722 return -EINVAL;
2723 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2724 return -EINVAL;
2725 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2726 return -EINVAL;
2727
2728 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2729
2730 freq_range->start_freq_khz =
2731 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2732 freq_range->end_freq_khz =
2733 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2734 freq_range->max_bandwidth_khz =
2735 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2736
2737 power_rule->max_eirp =
2738 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2739
2740 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2741 power_rule->max_antenna_gain =
2742 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2743
2744 return 0;
2745}
2746
2747static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2748{
2749 int r;
2750 char *data = NULL;
2751
80778f18
LR
2752 /*
2753 * You should only get this when cfg80211 hasn't yet initialized
2754 * completely when built-in to the kernel right between the time
2755 * window between nl80211_init() and regulatory_init(), if that is
2756 * even possible.
2757 */
2758 mutex_lock(&cfg80211_mutex);
2759 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2760 mutex_unlock(&cfg80211_mutex);
2761 return -EINPROGRESS;
80778f18 2762 }
fe33eb39 2763 mutex_unlock(&cfg80211_mutex);
80778f18 2764
fe33eb39
LR
2765 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2766 return -EINVAL;
b2e1b302
LR
2767
2768 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2769
fe33eb39
LR
2770 r = regulatory_hint_user(data);
2771
b2e1b302
LR
2772 return r;
2773}
2774
24bdd9f4 2775static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 2776 struct genl_info *info)
93da9cc1 2777{
4c476991 2778 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 2779 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
2780 struct wireless_dev *wdev = dev->ieee80211_ptr;
2781 struct mesh_config cur_params;
2782 int err = 0;
93da9cc1 2783 void *hdr;
2784 struct nlattr *pinfoattr;
2785 struct sk_buff *msg;
2786
29cbe68c
JB
2787 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2788 return -EOPNOTSUPP;
2789
24bdd9f4 2790 if (!rdev->ops->get_mesh_config)
4c476991 2791 return -EOPNOTSUPP;
f3f92586 2792
29cbe68c
JB
2793 wdev_lock(wdev);
2794 /* If not connected, get default parameters */
2795 if (!wdev->mesh_id_len)
2796 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2797 else
24bdd9f4 2798 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2799 &cur_params);
2800 wdev_unlock(wdev);
2801
93da9cc1 2802 if (err)
4c476991 2803 return err;
93da9cc1 2804
2805 /* Draw up a netlink message to send back */
fd2120ca 2806 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2807 if (!msg)
2808 return -ENOMEM;
93da9cc1 2809 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 2810 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 2811 if (!hdr)
efe1cf0c 2812 goto out;
24bdd9f4 2813 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 2814 if (!pinfoattr)
2815 goto nla_put_failure;
2816 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2817 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2818 cur_params.dot11MeshRetryTimeout);
2819 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2820 cur_params.dot11MeshConfirmTimeout);
2821 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2822 cur_params.dot11MeshHoldingTimeout);
2823 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2824 cur_params.dot11MeshMaxPeerLinks);
2825 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2826 cur_params.dot11MeshMaxRetries);
2827 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2828 cur_params.dot11MeshTTL);
45904f21
JC
2829 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2830 cur_params.element_ttl);
93da9cc1 2831 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2832 cur_params.auto_open_plinks);
2833 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2834 cur_params.dot11MeshHWMPmaxPREQretries);
2835 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2836 cur_params.path_refresh_time);
2837 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2838 cur_params.min_discovery_timeout);
2839 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2840 cur_params.dot11MeshHWMPactivePathTimeout);
2841 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2842 cur_params.dot11MeshHWMPpreqMinInterval);
2843 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2844 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2845 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2846 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2847 nla_nest_end(msg, pinfoattr);
2848 genlmsg_end(msg, hdr);
4c476991 2849 return genlmsg_reply(msg, info);
93da9cc1 2850
3b85875a 2851 nla_put_failure:
93da9cc1 2852 genlmsg_cancel(msg, hdr);
efe1cf0c 2853 out:
d080e275 2854 nlmsg_free(msg);
4c476991 2855 return -ENOBUFS;
93da9cc1 2856}
2857
b54452b0 2858static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2859 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2860 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2861 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2862 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2863 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2864 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 2865 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 2866 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2867
2868 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2869 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2870 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2871 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2872 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2873 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2874};
2875
c80d545d
JC
2876static const struct nla_policy
2877 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2878 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2879 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 2880 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 2881 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 2882 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 2883 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
2884};
2885
24bdd9f4 2886static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
2887 struct mesh_config *cfg,
2888 u32 *mask_out)
93da9cc1 2889{
93da9cc1 2890 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 2891 u32 mask = 0;
93da9cc1 2892
bd90fdcc
JB
2893#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2894do {\
2895 if (table[attr_num]) {\
2896 cfg->param = nla_fn(table[attr_num]); \
2897 mask |= (1 << (attr_num - 1)); \
2898 } \
2899} while (0);\
2900
2901
24bdd9f4 2902 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 2903 return -EINVAL;
2904 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 2905 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 2906 nl80211_meshconf_params_policy))
93da9cc1 2907 return -EINVAL;
2908
93da9cc1 2909 /* This makes sure that there aren't more than 32 mesh config
2910 * parameters (otherwise our bitfield scheme would not work.) */
2911 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2912
2913 /* Fill in the params struct */
93da9cc1 2914 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2915 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2916 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2917 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2918 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2919 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2920 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2921 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2922 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2923 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2924 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2925 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
2926 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2927 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 2928 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2929 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2930 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2931 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2932 nla_get_u8);
2933 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2934 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2935 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2936 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2937 nla_get_u16);
2938 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2939 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2940 nla_get_u32);
2941 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2942 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2943 nla_get_u16);
2944 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2945 dot11MeshHWMPnetDiameterTraversalTime,
2946 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2947 nla_get_u16);
63c5723b
RP
2948 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2949 dot11MeshHWMPRootMode, mask,
2950 NL80211_MESHCONF_HWMP_ROOTMODE,
2951 nla_get_u8);
bd90fdcc
JB
2952 if (mask_out)
2953 *mask_out = mask;
c80d545d 2954
bd90fdcc
JB
2955 return 0;
2956
2957#undef FILL_IN_MESH_PARAM_IF_SET
2958}
2959
c80d545d
JC
2960static int nl80211_parse_mesh_setup(struct genl_info *info,
2961 struct mesh_setup *setup)
2962{
2963 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
2964
2965 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
2966 return -EINVAL;
2967 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
2968 info->attrs[NL80211_ATTR_MESH_SETUP],
2969 nl80211_mesh_setup_params_policy))
2970 return -EINVAL;
2971
2972 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
2973 setup->path_sel_proto =
2974 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
2975 IEEE80211_PATH_PROTOCOL_VENDOR :
2976 IEEE80211_PATH_PROTOCOL_HWMP;
2977
2978 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
2979 setup->path_metric =
2980 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
2981 IEEE80211_PATH_METRIC_VENDOR :
2982 IEEE80211_PATH_METRIC_AIRTIME;
2983
581a8b0f
JC
2984
2985 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 2986 struct nlattr *ieattr =
581a8b0f 2987 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
2988 if (!is_valid_ie_attr(ieattr))
2989 return -EINVAL;
581a8b0f
JC
2990 setup->ie = nla_data(ieattr);
2991 setup->ie_len = nla_len(ieattr);
c80d545d 2992 }
b130e5ce
JC
2993 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
2994 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
2995
2996 return 0;
2997}
2998
24bdd9f4 2999static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3000 struct genl_info *info)
bd90fdcc
JB
3001{
3002 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3003 struct net_device *dev = info->user_ptr[1];
29cbe68c 3004 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3005 struct mesh_config cfg;
3006 u32 mask;
3007 int err;
3008
29cbe68c
JB
3009 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3010 return -EOPNOTSUPP;
3011
24bdd9f4 3012 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3013 return -EOPNOTSUPP;
3014
24bdd9f4 3015 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3016 if (err)
3017 return err;
3018
29cbe68c
JB
3019 wdev_lock(wdev);
3020 if (!wdev->mesh_id_len)
3021 err = -ENOLINK;
3022
3023 if (!err)
24bdd9f4 3024 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3025 mask, &cfg);
3026
3027 wdev_unlock(wdev);
3028
3029 return err;
93da9cc1 3030}
3031
f130347c
LR
3032static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3033{
3034 struct sk_buff *msg;
3035 void *hdr = NULL;
3036 struct nlattr *nl_reg_rules;
3037 unsigned int i;
3038 int err = -EINVAL;
3039
a1794390 3040 mutex_lock(&cfg80211_mutex);
f130347c
LR
3041
3042 if (!cfg80211_regdomain)
3043 goto out;
3044
fd2120ca 3045 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3046 if (!msg) {
3047 err = -ENOBUFS;
3048 goto out;
3049 }
3050
3051 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3052 NL80211_CMD_GET_REG);
3053 if (!hdr)
efe1cf0c 3054 goto put_failure;
f130347c
LR
3055
3056 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3057 cfg80211_regdomain->alpha2);
3058
3059 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3060 if (!nl_reg_rules)
3061 goto nla_put_failure;
3062
3063 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3064 struct nlattr *nl_reg_rule;
3065 const struct ieee80211_reg_rule *reg_rule;
3066 const struct ieee80211_freq_range *freq_range;
3067 const struct ieee80211_power_rule *power_rule;
3068
3069 reg_rule = &cfg80211_regdomain->reg_rules[i];
3070 freq_range = &reg_rule->freq_range;
3071 power_rule = &reg_rule->power_rule;
3072
3073 nl_reg_rule = nla_nest_start(msg, i);
3074 if (!nl_reg_rule)
3075 goto nla_put_failure;
3076
3077 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3078 reg_rule->flags);
3079 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3080 freq_range->start_freq_khz);
3081 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3082 freq_range->end_freq_khz);
3083 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3084 freq_range->max_bandwidth_khz);
3085 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3086 power_rule->max_antenna_gain);
3087 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3088 power_rule->max_eirp);
3089
3090 nla_nest_end(msg, nl_reg_rule);
3091 }
3092
3093 nla_nest_end(msg, nl_reg_rules);
3094
3095 genlmsg_end(msg, hdr);
134e6375 3096 err = genlmsg_reply(msg, info);
f130347c
LR
3097 goto out;
3098
3099nla_put_failure:
3100 genlmsg_cancel(msg, hdr);
efe1cf0c 3101put_failure:
d080e275 3102 nlmsg_free(msg);
f130347c
LR
3103 err = -EMSGSIZE;
3104out:
a1794390 3105 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3106 return err;
3107}
3108
b2e1b302
LR
3109static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3110{
3111 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3112 struct nlattr *nl_reg_rule;
3113 char *alpha2 = NULL;
3114 int rem_reg_rules = 0, r = 0;
3115 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3116 struct ieee80211_regdomain *rd = NULL;
3117
3118 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3119 return -EINVAL;
3120
3121 if (!info->attrs[NL80211_ATTR_REG_RULES])
3122 return -EINVAL;
3123
3124 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3125
3126 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3127 rem_reg_rules) {
3128 num_rules++;
3129 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3130 return -EINVAL;
b2e1b302
LR
3131 }
3132
61405e97
LR
3133 mutex_lock(&cfg80211_mutex);
3134
d0e18f83
LR
3135 if (!reg_is_valid_request(alpha2)) {
3136 r = -EINVAL;
3137 goto bad_reg;
3138 }
b2e1b302
LR
3139
3140 size_of_regd = sizeof(struct ieee80211_regdomain) +
3141 (num_rules * sizeof(struct ieee80211_reg_rule));
3142
3143 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3144 if (!rd) {
3145 r = -ENOMEM;
3146 goto bad_reg;
3147 }
b2e1b302
LR
3148
3149 rd->n_reg_rules = num_rules;
3150 rd->alpha2[0] = alpha2[0];
3151 rd->alpha2[1] = alpha2[1];
3152
3153 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3154 rem_reg_rules) {
3155 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3156 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3157 reg_rule_policy);
3158 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3159 if (r)
3160 goto bad_reg;
3161
3162 rule_idx++;
3163
d0e18f83
LR
3164 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3165 r = -EINVAL;
b2e1b302 3166 goto bad_reg;
d0e18f83 3167 }
b2e1b302
LR
3168 }
3169
3170 BUG_ON(rule_idx != num_rules);
3171
b2e1b302 3172 r = set_regdom(rd);
61405e97 3173
a1794390 3174 mutex_unlock(&cfg80211_mutex);
d0e18f83 3175
b2e1b302
LR
3176 return r;
3177
d2372b31 3178 bad_reg:
61405e97 3179 mutex_unlock(&cfg80211_mutex);
b2e1b302 3180 kfree(rd);
d0e18f83 3181 return r;
b2e1b302
LR
3182}
3183
83f5e2cf
JB
3184static int validate_scan_freqs(struct nlattr *freqs)
3185{
3186 struct nlattr *attr1, *attr2;
3187 int n_channels = 0, tmp1, tmp2;
3188
3189 nla_for_each_nested(attr1, freqs, tmp1) {
3190 n_channels++;
3191 /*
3192 * Some hardware has a limited channel list for
3193 * scanning, and it is pretty much nonsensical
3194 * to scan for a channel twice, so disallow that
3195 * and don't require drivers to check that the
3196 * channel list they get isn't longer than what
3197 * they can scan, as long as they can scan all
3198 * the channels they registered at once.
3199 */
3200 nla_for_each_nested(attr2, freqs, tmp2)
3201 if (attr1 != attr2 &&
3202 nla_get_u32(attr1) == nla_get_u32(attr2))
3203 return 0;
3204 }
3205
3206 return n_channels;
3207}
3208
2a519311
JB
3209static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3210{
4c476991
JB
3211 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3212 struct net_device *dev = info->user_ptr[1];
2a519311
JB
3213 struct cfg80211_scan_request *request;
3214 struct cfg80211_ssid *ssid;
3215 struct ieee80211_channel *channel;
3216 struct nlattr *attr;
3217 struct wiphy *wiphy;
83f5e2cf 3218 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3219 enum ieee80211_band band;
70692ad2 3220 size_t ie_len;
2a519311 3221
f4a11bb0
JB
3222 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3223 return -EINVAL;
3224
79c97e97 3225 wiphy = &rdev->wiphy;
2a519311 3226
4c476991
JB
3227 if (!rdev->ops->scan)
3228 return -EOPNOTSUPP;
2a519311 3229
4c476991
JB
3230 if (rdev->scan_req)
3231 return -EBUSY;
2a519311
JB
3232
3233 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3234 n_channels = validate_scan_freqs(
3235 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3236 if (!n_channels)
3237 return -EINVAL;
2a519311 3238 } else {
83f5e2cf
JB
3239 n_channels = 0;
3240
2a519311
JB
3241 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3242 if (wiphy->bands[band])
3243 n_channels += wiphy->bands[band]->n_channels;
3244 }
3245
3246 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3247 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3248 n_ssids++;
3249
4c476991
JB
3250 if (n_ssids > wiphy->max_scan_ssids)
3251 return -EINVAL;
2a519311 3252
70692ad2
JM
3253 if (info->attrs[NL80211_ATTR_IE])
3254 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3255 else
3256 ie_len = 0;
3257
4c476991
JB
3258 if (ie_len > wiphy->max_scan_ie_len)
3259 return -EINVAL;
18a83659 3260
2a519311
JB
3261 request = kzalloc(sizeof(*request)
3262 + sizeof(*ssid) * n_ssids
70692ad2
JM
3263 + sizeof(channel) * n_channels
3264 + ie_len, GFP_KERNEL);
4c476991
JB
3265 if (!request)
3266 return -ENOMEM;
2a519311 3267
2a519311 3268 if (n_ssids)
5ba63533 3269 request->ssids = (void *)&request->channels[n_channels];
2a519311 3270 request->n_ssids = n_ssids;
70692ad2
JM
3271 if (ie_len) {
3272 if (request->ssids)
3273 request->ie = (void *)(request->ssids + n_ssids);
3274 else
3275 request->ie = (void *)(request->channels + n_channels);
3276 }
2a519311 3277
584991dc 3278 i = 0;
2a519311
JB
3279 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3280 /* user specified, bail out if channel not found */
2a519311 3281 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3282 struct ieee80211_channel *chan;
3283
3284 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3285
3286 if (!chan) {
2a519311
JB
3287 err = -EINVAL;
3288 goto out_free;
3289 }
584991dc
JB
3290
3291 /* ignore disabled channels */
3292 if (chan->flags & IEEE80211_CHAN_DISABLED)
3293 continue;
3294
3295 request->channels[i] = chan;
2a519311
JB
3296 i++;
3297 }
3298 } else {
3299 /* all channels */
2a519311
JB
3300 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3301 int j;
3302 if (!wiphy->bands[band])
3303 continue;
3304 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3305 struct ieee80211_channel *chan;
3306
3307 chan = &wiphy->bands[band]->channels[j];
3308
3309 if (chan->flags & IEEE80211_CHAN_DISABLED)
3310 continue;
3311
3312 request->channels[i] = chan;
2a519311
JB
3313 i++;
3314 }
3315 }
3316 }
3317
584991dc
JB
3318 if (!i) {
3319 err = -EINVAL;
3320 goto out_free;
3321 }
3322
3323 request->n_channels = i;
3324
2a519311
JB
3325 i = 0;
3326 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3327 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3328 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3329 err = -EINVAL;
3330 goto out_free;
3331 }
3332 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3333 request->ssids[i].ssid_len = nla_len(attr);
3334 i++;
3335 }
3336 }
3337
70692ad2
JM
3338 if (info->attrs[NL80211_ATTR_IE]) {
3339 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3340 memcpy((void *)request->ie,
3341 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3342 request->ie_len);
3343 }
3344
463d0183 3345 request->dev = dev;
79c97e97 3346 request->wiphy = &rdev->wiphy;
2a519311 3347
79c97e97
JB
3348 rdev->scan_req = request;
3349 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3350
463d0183 3351 if (!err) {
79c97e97 3352 nl80211_send_scan_start(rdev, dev);
463d0183 3353 dev_hold(dev);
4c476991 3354 } else {
2a519311 3355 out_free:
79c97e97 3356 rdev->scan_req = NULL;
2a519311
JB
3357 kfree(request);
3358 }
3b85875a 3359
2a519311
JB
3360 return err;
3361}
3362
807f8a8c
LC
3363static int nl80211_start_sched_scan(struct sk_buff *skb,
3364 struct genl_info *info)
3365{
3366 struct cfg80211_sched_scan_request *request;
3367 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3368 struct net_device *dev = info->user_ptr[1];
3369 struct cfg80211_ssid *ssid;
3370 struct ieee80211_channel *channel;
3371 struct nlattr *attr;
3372 struct wiphy *wiphy;
3373 int err, tmp, n_ssids = 0, n_channels, i;
bbe6ad6d 3374 u32 interval;
807f8a8c
LC
3375 enum ieee80211_band band;
3376 size_t ie_len;
3377
3378 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3379 !rdev->ops->sched_scan_start)
3380 return -EOPNOTSUPP;
3381
3382 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3383 return -EINVAL;
3384
3385 if (rdev->sched_scan_req)
3386 return -EINPROGRESS;
3387
bbe6ad6d
LC
3388 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3389 return -EINVAL;
3390
3391 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3392 if (interval == 0)
3393 return -EINVAL;
3394
807f8a8c
LC
3395 wiphy = &rdev->wiphy;
3396
3397 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3398 n_channels = validate_scan_freqs(
3399 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3400 if (!n_channels)
3401 return -EINVAL;
3402 } else {
3403 n_channels = 0;
3404
3405 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3406 if (wiphy->bands[band])
3407 n_channels += wiphy->bands[band]->n_channels;
3408 }
3409
3410 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3411 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3412 tmp)
3413 n_ssids++;
3414
3415 if (n_ssids > wiphy->max_scan_ssids)
3416 return -EINVAL;
3417
3418 if (info->attrs[NL80211_ATTR_IE])
3419 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3420 else
3421 ie_len = 0;
3422
3423 if (ie_len > wiphy->max_scan_ie_len)
3424 return -EINVAL;
3425
3426 request = kzalloc(sizeof(*request)
3427 + sizeof(*ssid) * n_ssids
3428 + sizeof(channel) * n_channels
3429 + ie_len, GFP_KERNEL);
3430 if (!request)
3431 return -ENOMEM;
3432
3433 if (n_ssids)
3434 request->ssids = (void *)&request->channels[n_channels];
3435 request->n_ssids = n_ssids;
3436 if (ie_len) {
3437 if (request->ssids)
3438 request->ie = (void *)(request->ssids + n_ssids);
3439 else
3440 request->ie = (void *)(request->channels + n_channels);
3441 }
3442
3443 i = 0;
3444 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3445 /* user specified, bail out if channel not found */
3446 nla_for_each_nested(attr,
3447 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
3448 tmp) {
3449 struct ieee80211_channel *chan;
3450
3451 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3452
3453 if (!chan) {
3454 err = -EINVAL;
3455 goto out_free;
3456 }
3457
3458 /* ignore disabled channels */
3459 if (chan->flags & IEEE80211_CHAN_DISABLED)
3460 continue;
3461
3462 request->channels[i] = chan;
3463 i++;
3464 }
3465 } else {
3466 /* all channels */
3467 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3468 int j;
3469 if (!wiphy->bands[band])
3470 continue;
3471 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3472 struct ieee80211_channel *chan;
3473
3474 chan = &wiphy->bands[band]->channels[j];
3475
3476 if (chan->flags & IEEE80211_CHAN_DISABLED)
3477 continue;
3478
3479 request->channels[i] = chan;
3480 i++;
3481 }
3482 }
3483 }
3484
3485 if (!i) {
3486 err = -EINVAL;
3487 goto out_free;
3488 }
3489
3490 request->n_channels = i;
3491
3492 i = 0;
3493 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3494 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3495 tmp) {
3496 if (request->ssids[i].ssid_len >
3497 IEEE80211_MAX_SSID_LEN) {
3498 err = -EINVAL;
3499 goto out_free;
3500 }
3501 memcpy(request->ssids[i].ssid, nla_data(attr),
3502 nla_len(attr));
3503 request->ssids[i].ssid_len = nla_len(attr);
3504 i++;
3505 }
3506 }
3507
3508 if (info->attrs[NL80211_ATTR_IE]) {
3509 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3510 memcpy((void *)request->ie,
3511 nla_data(info->attrs[NL80211_ATTR_IE]),
3512 request->ie_len);
3513 }
3514
3515 request->dev = dev;
3516 request->wiphy = &rdev->wiphy;
bbe6ad6d 3517 request->interval = interval;
807f8a8c
LC
3518
3519 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
3520 if (!err) {
3521 rdev->sched_scan_req = request;
3522 nl80211_send_sched_scan(rdev, dev,
3523 NL80211_CMD_START_SCHED_SCAN);
3524 goto out;
3525 }
3526
3527out_free:
3528 kfree(request);
3529out:
3530 return err;
3531}
3532
3533static int nl80211_stop_sched_scan(struct sk_buff *skb,
3534 struct genl_info *info)
3535{
3536 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3537
3538 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3539 !rdev->ops->sched_scan_stop)
3540 return -EOPNOTSUPP;
3541
3542 return __cfg80211_stop_sched_scan(rdev, false);
3543}
3544
2a519311
JB
3545static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3546 struct cfg80211_registered_device *rdev,
48ab905d
JB
3547 struct wireless_dev *wdev,
3548 struct cfg80211_internal_bss *intbss)
2a519311 3549{
48ab905d 3550 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3551 void *hdr;
3552 struct nlattr *bss;
48ab905d
JB
3553 int i;
3554
3555 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3556
3557 hdr = nl80211hdr_put(msg, pid, seq, flags,
3558 NL80211_CMD_NEW_SCAN_RESULTS);
3559 if (!hdr)
3560 return -1;
3561
f5ea9120 3562 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3563 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3564
3565 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3566 if (!bss)
3567 goto nla_put_failure;
3568 if (!is_zero_ether_addr(res->bssid))
3569 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3570 if (res->information_elements && res->len_information_elements)
3571 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3572 res->len_information_elements,
3573 res->information_elements);
34a6eddb
JM
3574 if (res->beacon_ies && res->len_beacon_ies &&
3575 res->beacon_ies != res->information_elements)
3576 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3577 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3578 if (res->tsf)
3579 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3580 if (res->beacon_interval)
3581 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3582 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3583 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3584 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3585 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3586
77965c97 3587 switch (rdev->wiphy.signal_type) {
2a519311
JB
3588 case CFG80211_SIGNAL_TYPE_MBM:
3589 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3590 break;
3591 case CFG80211_SIGNAL_TYPE_UNSPEC:
3592 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3593 break;
3594 default:
3595 break;
3596 }
3597
48ab905d 3598 switch (wdev->iftype) {
074ac8df 3599 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3600 case NL80211_IFTYPE_STATION:
3601 if (intbss == wdev->current_bss)
3602 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3603 NL80211_BSS_STATUS_ASSOCIATED);
3604 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3605 if (intbss != wdev->auth_bsses[i])
3606 continue;
3607 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3608 NL80211_BSS_STATUS_AUTHENTICATED);
3609 break;
3610 }
3611 break;
3612 case NL80211_IFTYPE_ADHOC:
3613 if (intbss == wdev->current_bss)
3614 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3615 NL80211_BSS_STATUS_IBSS_JOINED);
3616 break;
3617 default:
3618 break;
3619 }
3620
2a519311
JB
3621 nla_nest_end(msg, bss);
3622
3623 return genlmsg_end(msg, hdr);
3624
3625 nla_put_failure:
3626 genlmsg_cancel(msg, hdr);
3627 return -EMSGSIZE;
3628}
3629
3630static int nl80211_dump_scan(struct sk_buff *skb,
3631 struct netlink_callback *cb)
3632{
48ab905d
JB
3633 struct cfg80211_registered_device *rdev;
3634 struct net_device *dev;
2a519311 3635 struct cfg80211_internal_bss *scan;
48ab905d 3636 struct wireless_dev *wdev;
2a519311
JB
3637 int start = cb->args[1], idx = 0;
3638 int err;
3639
67748893
JB
3640 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3641 if (err)
3642 return err;
2a519311 3643
48ab905d 3644 wdev = dev->ieee80211_ptr;
2a519311 3645
48ab905d
JB
3646 wdev_lock(wdev);
3647 spin_lock_bh(&rdev->bss_lock);
3648 cfg80211_bss_expire(rdev);
3649
3650 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3651 if (++idx <= start)
3652 continue;
3653 if (nl80211_send_bss(skb,
3654 NETLINK_CB(cb->skb).pid,
3655 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3656 rdev, wdev, scan) < 0) {
2a519311 3657 idx--;
67748893 3658 break;
2a519311
JB
3659 }
3660 }
3661
48ab905d
JB
3662 spin_unlock_bh(&rdev->bss_lock);
3663 wdev_unlock(wdev);
2a519311
JB
3664
3665 cb->args[1] = idx;
67748893 3666 nl80211_finish_netdev_dump(rdev);
2a519311 3667
67748893 3668 return skb->len;
2a519311
JB
3669}
3670
61fa713c
HS
3671static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3672 int flags, struct net_device *dev,
3673 struct survey_info *survey)
3674{
3675 void *hdr;
3676 struct nlattr *infoattr;
3677
3678 /* Survey without a channel doesn't make sense */
3679 if (!survey->channel)
3680 return -EINVAL;
3681
3682 hdr = nl80211hdr_put(msg, pid, seq, flags,
3683 NL80211_CMD_NEW_SURVEY_RESULTS);
3684 if (!hdr)
3685 return -ENOMEM;
3686
3687 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3688
3689 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3690 if (!infoattr)
3691 goto nla_put_failure;
3692
3693 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3694 survey->channel->center_freq);
3695 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3696 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3697 survey->noise);
17e5a808
FF
3698 if (survey->filled & SURVEY_INFO_IN_USE)
3699 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
3700 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3701 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3702 survey->channel_time);
3703 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3704 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3705 survey->channel_time_busy);
3706 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3707 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3708 survey->channel_time_ext_busy);
3709 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3710 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3711 survey->channel_time_rx);
3712 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3713 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3714 survey->channel_time_tx);
61fa713c
HS
3715
3716 nla_nest_end(msg, infoattr);
3717
3718 return genlmsg_end(msg, hdr);
3719
3720 nla_put_failure:
3721 genlmsg_cancel(msg, hdr);
3722 return -EMSGSIZE;
3723}
3724
3725static int nl80211_dump_survey(struct sk_buff *skb,
3726 struct netlink_callback *cb)
3727{
3728 struct survey_info survey;
3729 struct cfg80211_registered_device *dev;
3730 struct net_device *netdev;
61fa713c
HS
3731 int survey_idx = cb->args[1];
3732 int res;
3733
67748893
JB
3734 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3735 if (res)
3736 return res;
61fa713c
HS
3737
3738 if (!dev->ops->dump_survey) {
3739 res = -EOPNOTSUPP;
3740 goto out_err;
3741 }
3742
3743 while (1) {
3744 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3745 &survey);
3746 if (res == -ENOENT)
3747 break;
3748 if (res)
3749 goto out_err;
3750
3751 if (nl80211_send_survey(skb,
3752 NETLINK_CB(cb->skb).pid,
3753 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3754 netdev,
3755 &survey) < 0)
3756 goto out;
3757 survey_idx++;
3758 }
3759
3760 out:
3761 cb->args[1] = survey_idx;
3762 res = skb->len;
3763 out_err:
67748893 3764 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3765 return res;
3766}
3767
255e737e
JM
3768static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3769{
b23aa676
SO
3770 return auth_type <= NL80211_AUTHTYPE_MAX;
3771}
3772
3773static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3774{
3775 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3776 NL80211_WPA_VERSION_2));
3777}
3778
3779static bool nl80211_valid_akm_suite(u32 akm)
3780{
3781 return akm == WLAN_AKM_SUITE_8021X ||
3782 akm == WLAN_AKM_SUITE_PSK;
3783}
3784
3785static bool nl80211_valid_cipher_suite(u32 cipher)
3786{
3787 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3788 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3789 cipher == WLAN_CIPHER_SUITE_TKIP ||
3790 cipher == WLAN_CIPHER_SUITE_CCMP ||
3791 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3792}
3793
b23aa676 3794
636a5d36
JM
3795static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3796{
4c476991
JB
3797 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3798 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3799 struct ieee80211_channel *chan;
3800 const u8 *bssid, *ssid, *ie = NULL;
3801 int err, ssid_len, ie_len = 0;
3802 enum nl80211_auth_type auth_type;
fffd0934 3803 struct key_parse key;
d5cdfacb 3804 bool local_state_change;
636a5d36 3805
f4a11bb0
JB
3806 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3807 return -EINVAL;
3808
3809 if (!info->attrs[NL80211_ATTR_MAC])
3810 return -EINVAL;
3811
1778092e
JM
3812 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3813 return -EINVAL;
3814
19957bb3
JB
3815 if (!info->attrs[NL80211_ATTR_SSID])
3816 return -EINVAL;
3817
3818 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3819 return -EINVAL;
3820
fffd0934
JB
3821 err = nl80211_parse_key(info, &key);
3822 if (err)
3823 return err;
3824
3825 if (key.idx >= 0) {
e31b8213
JB
3826 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3827 return -EINVAL;
fffd0934
JB
3828 if (!key.p.key || !key.p.key_len)
3829 return -EINVAL;
3830 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3831 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3832 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3833 key.p.key_len != WLAN_KEY_LEN_WEP104))
3834 return -EINVAL;
3835 if (key.idx > 4)
3836 return -EINVAL;
3837 } else {
3838 key.p.key_len = 0;
3839 key.p.key = NULL;
3840 }
3841
afea0b7a
JB
3842 if (key.idx >= 0) {
3843 int i;
3844 bool ok = false;
3845 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3846 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3847 ok = true;
3848 break;
3849 }
3850 }
4c476991
JB
3851 if (!ok)
3852 return -EINVAL;
afea0b7a
JB
3853 }
3854
4c476991
JB
3855 if (!rdev->ops->auth)
3856 return -EOPNOTSUPP;
636a5d36 3857
074ac8df 3858 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3859 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3860 return -EOPNOTSUPP;
eec60b03 3861
19957bb3 3862 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3863 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3864 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3865 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3866 return -EINVAL;
636a5d36 3867
19957bb3
JB
3868 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3869 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3870
3871 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3872 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3873 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3874 }
3875
19957bb3 3876 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3877 if (!nl80211_valid_auth_type(auth_type))
3878 return -EINVAL;
636a5d36 3879
d5cdfacb
JM
3880 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3881
4c476991
JB
3882 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3883 ssid, ssid_len, ie, ie_len,
3884 key.p.key, key.p.key_len, key.idx,
3885 local_state_change);
636a5d36
JM
3886}
3887
c0692b8f
JB
3888static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3889 struct genl_info *info,
3dc27d25
JB
3890 struct cfg80211_crypto_settings *settings,
3891 int cipher_limit)
b23aa676 3892{
c0b2bbd8
JB
3893 memset(settings, 0, sizeof(*settings));
3894
b23aa676
SO
3895 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3896
c0692b8f
JB
3897 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3898 u16 proto;
3899 proto = nla_get_u16(
3900 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3901 settings->control_port_ethertype = cpu_to_be16(proto);
3902 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3903 proto != ETH_P_PAE)
3904 return -EINVAL;
3905 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3906 settings->control_port_no_encrypt = true;
3907 } else
3908 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3909
b23aa676
SO
3910 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3911 void *data;
3912 int len, i;
3913
3914 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3915 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3916 settings->n_ciphers_pairwise = len / sizeof(u32);
3917
3918 if (len % sizeof(u32))
3919 return -EINVAL;
3920
3dc27d25 3921 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3922 return -EINVAL;
3923
3924 memcpy(settings->ciphers_pairwise, data, len);
3925
3926 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3927 if (!nl80211_valid_cipher_suite(
3928 settings->ciphers_pairwise[i]))
3929 return -EINVAL;
3930 }
3931
3932 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3933 settings->cipher_group =
3934 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3935 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3936 return -EINVAL;
3937 }
3938
3939 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3940 settings->wpa_versions =
3941 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3942 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3943 return -EINVAL;
3944 }
3945
3946 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3947 void *data;
3948 int len, i;
3949
3950 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3951 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3952 settings->n_akm_suites = len / sizeof(u32);
3953
3954 if (len % sizeof(u32))
3955 return -EINVAL;
3956
3957 memcpy(settings->akm_suites, data, len);
3958
3959 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3960 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3961 return -EINVAL;
3962 }
3963
3964 return 0;
3965}
3966
636a5d36
JM
3967static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3968{
4c476991
JB
3969 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3970 struct net_device *dev = info->user_ptr[1];
19957bb3 3971 struct cfg80211_crypto_settings crypto;
f444de05 3972 struct ieee80211_channel *chan;
3e5d7649 3973 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3974 int err, ssid_len, ie_len = 0;
3975 bool use_mfp = false;
636a5d36 3976
f4a11bb0
JB
3977 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3978 return -EINVAL;
3979
3980 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3981 !info->attrs[NL80211_ATTR_SSID] ||
3982 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3983 return -EINVAL;
3984
4c476991
JB
3985 if (!rdev->ops->assoc)
3986 return -EOPNOTSUPP;
636a5d36 3987
074ac8df 3988 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3989 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3990 return -EOPNOTSUPP;
eec60b03 3991
19957bb3 3992 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3993
19957bb3
JB
3994 chan = ieee80211_get_channel(&rdev->wiphy,
3995 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3996 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3997 return -EINVAL;
636a5d36 3998
19957bb3
JB
3999 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4000 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4001
4002 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4003 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4004 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4005 }
4006
dc6382ce 4007 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4008 enum nl80211_mfp mfp =
dc6382ce 4009 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4010 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4011 use_mfp = true;
4c476991
JB
4012 else if (mfp != NL80211_MFP_NO)
4013 return -EINVAL;
dc6382ce
JM
4014 }
4015
3e5d7649
JB
4016 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4017 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4018
c0692b8f 4019 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4020 if (!err)
3e5d7649
JB
4021 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4022 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 4023 &crypto);
636a5d36 4024
636a5d36
JM
4025 return err;
4026}
4027
4028static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4029{
4c476991
JB
4030 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4031 struct net_device *dev = info->user_ptr[1];
19957bb3 4032 const u8 *ie = NULL, *bssid;
4c476991 4033 int ie_len = 0;
19957bb3 4034 u16 reason_code;
d5cdfacb 4035 bool local_state_change;
636a5d36 4036
f4a11bb0
JB
4037 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4038 return -EINVAL;
4039
4040 if (!info->attrs[NL80211_ATTR_MAC])
4041 return -EINVAL;
4042
4043 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4044 return -EINVAL;
4045
4c476991
JB
4046 if (!rdev->ops->deauth)
4047 return -EOPNOTSUPP;
636a5d36 4048
074ac8df 4049 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4050 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4051 return -EOPNOTSUPP;
eec60b03 4052
19957bb3 4053 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4054
19957bb3
JB
4055 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4056 if (reason_code == 0) {
f4a11bb0 4057 /* Reason Code 0 is reserved */
4c476991 4058 return -EINVAL;
255e737e 4059 }
636a5d36
JM
4060
4061 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4062 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4063 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4064 }
4065
d5cdfacb
JM
4066 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4067
4c476991
JB
4068 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4069 local_state_change);
636a5d36
JM
4070}
4071
4072static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4073{
4c476991
JB
4074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4075 struct net_device *dev = info->user_ptr[1];
19957bb3 4076 const u8 *ie = NULL, *bssid;
4c476991 4077 int ie_len = 0;
19957bb3 4078 u16 reason_code;
d5cdfacb 4079 bool local_state_change;
636a5d36 4080
f4a11bb0
JB
4081 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4082 return -EINVAL;
4083
4084 if (!info->attrs[NL80211_ATTR_MAC])
4085 return -EINVAL;
4086
4087 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4088 return -EINVAL;
4089
4c476991
JB
4090 if (!rdev->ops->disassoc)
4091 return -EOPNOTSUPP;
636a5d36 4092
074ac8df 4093 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4094 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4095 return -EOPNOTSUPP;
eec60b03 4096
19957bb3 4097 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4098
19957bb3
JB
4099 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4100 if (reason_code == 0) {
f4a11bb0 4101 /* Reason Code 0 is reserved */
4c476991 4102 return -EINVAL;
255e737e 4103 }
636a5d36
JM
4104
4105 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4106 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4107 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4108 }
4109
d5cdfacb
JM
4110 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4111
4c476991
JB
4112 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4113 local_state_change);
636a5d36
JM
4114}
4115
dd5b4cc7
FF
4116static bool
4117nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4118 int mcast_rate[IEEE80211_NUM_BANDS],
4119 int rateval)
4120{
4121 struct wiphy *wiphy = &rdev->wiphy;
4122 bool found = false;
4123 int band, i;
4124
4125 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4126 struct ieee80211_supported_band *sband;
4127
4128 sband = wiphy->bands[band];
4129 if (!sband)
4130 continue;
4131
4132 for (i = 0; i < sband->n_bitrates; i++) {
4133 if (sband->bitrates[i].bitrate == rateval) {
4134 mcast_rate[band] = i + 1;
4135 found = true;
4136 break;
4137 }
4138 }
4139 }
4140
4141 return found;
4142}
4143
04a773ad
JB
4144static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4145{
4c476991
JB
4146 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4147 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4148 struct cfg80211_ibss_params ibss;
4149 struct wiphy *wiphy;
fffd0934 4150 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4151 int err;
4152
8e30bc55
JB
4153 memset(&ibss, 0, sizeof(ibss));
4154
04a773ad
JB
4155 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4156 return -EINVAL;
4157
4158 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4159 !info->attrs[NL80211_ATTR_SSID] ||
4160 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4161 return -EINVAL;
4162
8e30bc55
JB
4163 ibss.beacon_interval = 100;
4164
4165 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4166 ibss.beacon_interval =
4167 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4168 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4169 return -EINVAL;
4170 }
4171
4c476991
JB
4172 if (!rdev->ops->join_ibss)
4173 return -EOPNOTSUPP;
04a773ad 4174
4c476991
JB
4175 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4176 return -EOPNOTSUPP;
04a773ad 4177
79c97e97 4178 wiphy = &rdev->wiphy;
04a773ad
JB
4179
4180 if (info->attrs[NL80211_ATTR_MAC])
4181 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4182 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4183 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4184
4185 if (info->attrs[NL80211_ATTR_IE]) {
4186 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4187 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4188 }
4189
4190 ibss.channel = ieee80211_get_channel(wiphy,
4191 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4192 if (!ibss.channel ||
4193 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4194 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4195 return -EINVAL;
04a773ad
JB
4196
4197 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4198 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4199
fbd2c8dc
TP
4200 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4201 u8 *rates =
4202 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4203 int n_rates =
4204 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4205 struct ieee80211_supported_band *sband =
4206 wiphy->bands[ibss.channel->band];
4207 int i, j;
4208
4c476991
JB
4209 if (n_rates == 0)
4210 return -EINVAL;
fbd2c8dc
TP
4211
4212 for (i = 0; i < n_rates; i++) {
4213 int rate = (rates[i] & 0x7f) * 5;
4214 bool found = false;
4215
4216 for (j = 0; j < sband->n_bitrates; j++) {
4217 if (sband->bitrates[j].bitrate == rate) {
4218 found = true;
4219 ibss.basic_rates |= BIT(j);
4220 break;
4221 }
4222 }
4c476991
JB
4223 if (!found)
4224 return -EINVAL;
fbd2c8dc 4225 }
fbd2c8dc 4226 }
dd5b4cc7
FF
4227
4228 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4229 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4230 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4231 return -EINVAL;
fbd2c8dc 4232
4c476991
JB
4233 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4234 connkeys = nl80211_parse_connkeys(rdev,
4235 info->attrs[NL80211_ATTR_KEYS]);
4236 if (IS_ERR(connkeys))
4237 return PTR_ERR(connkeys);
4238 }
04a773ad 4239
4c476991 4240 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4241 if (err)
4242 kfree(connkeys);
04a773ad
JB
4243 return err;
4244}
4245
4246static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4247{
4c476991
JB
4248 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4249 struct net_device *dev = info->user_ptr[1];
04a773ad 4250
4c476991
JB
4251 if (!rdev->ops->leave_ibss)
4252 return -EOPNOTSUPP;
04a773ad 4253
4c476991
JB
4254 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4255 return -EOPNOTSUPP;
04a773ad 4256
4c476991 4257 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4258}
4259
aff89a9b
JB
4260#ifdef CONFIG_NL80211_TESTMODE
4261static struct genl_multicast_group nl80211_testmode_mcgrp = {
4262 .name = "testmode",
4263};
4264
4265static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4266{
4c476991 4267 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4268 int err;
4269
4270 if (!info->attrs[NL80211_ATTR_TESTDATA])
4271 return -EINVAL;
4272
aff89a9b
JB
4273 err = -EOPNOTSUPP;
4274 if (rdev->ops->testmode_cmd) {
4275 rdev->testmode_info = info;
4276 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4277 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4278 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4279 rdev->testmode_info = NULL;
4280 }
4281
aff89a9b
JB
4282 return err;
4283}
4284
4285static struct sk_buff *
4286__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4287 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4288{
4289 struct sk_buff *skb;
4290 void *hdr;
4291 struct nlattr *data;
4292
4293 skb = nlmsg_new(approxlen + 100, gfp);
4294 if (!skb)
4295 return NULL;
4296
4297 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4298 if (!hdr) {
4299 kfree_skb(skb);
4300 return NULL;
4301 }
4302
4303 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4304 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4305
4306 ((void **)skb->cb)[0] = rdev;
4307 ((void **)skb->cb)[1] = hdr;
4308 ((void **)skb->cb)[2] = data;
4309
4310 return skb;
4311
4312 nla_put_failure:
4313 kfree_skb(skb);
4314 return NULL;
4315}
4316
4317struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4318 int approxlen)
4319{
4320 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4321
4322 if (WARN_ON(!rdev->testmode_info))
4323 return NULL;
4324
4325 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4326 rdev->testmode_info->snd_pid,
4327 rdev->testmode_info->snd_seq,
4328 GFP_KERNEL);
4329}
4330EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4331
4332int cfg80211_testmode_reply(struct sk_buff *skb)
4333{
4334 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4335 void *hdr = ((void **)skb->cb)[1];
4336 struct nlattr *data = ((void **)skb->cb)[2];
4337
4338 if (WARN_ON(!rdev->testmode_info)) {
4339 kfree_skb(skb);
4340 return -EINVAL;
4341 }
4342
4343 nla_nest_end(skb, data);
4344 genlmsg_end(skb, hdr);
4345 return genlmsg_reply(skb, rdev->testmode_info);
4346}
4347EXPORT_SYMBOL(cfg80211_testmode_reply);
4348
4349struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4350 int approxlen, gfp_t gfp)
4351{
4352 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4353
4354 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4355}
4356EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4357
4358void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4359{
4360 void *hdr = ((void **)skb->cb)[1];
4361 struct nlattr *data = ((void **)skb->cb)[2];
4362
4363 nla_nest_end(skb, data);
4364 genlmsg_end(skb, hdr);
4365 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4366}
4367EXPORT_SYMBOL(cfg80211_testmode_event);
4368#endif
4369
b23aa676
SO
4370static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4371{
4c476991
JB
4372 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4373 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4374 struct cfg80211_connect_params connect;
4375 struct wiphy *wiphy;
fffd0934 4376 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4377 int err;
4378
4379 memset(&connect, 0, sizeof(connect));
4380
4381 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4382 return -EINVAL;
4383
4384 if (!info->attrs[NL80211_ATTR_SSID] ||
4385 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4386 return -EINVAL;
4387
4388 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4389 connect.auth_type =
4390 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4391 if (!nl80211_valid_auth_type(connect.auth_type))
4392 return -EINVAL;
4393 } else
4394 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4395
4396 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4397
c0692b8f 4398 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4399 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4400 if (err)
4401 return err;
b23aa676 4402
074ac8df 4403 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4404 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4405 return -EOPNOTSUPP;
b23aa676 4406
79c97e97 4407 wiphy = &rdev->wiphy;
b23aa676 4408
b23aa676
SO
4409 if (info->attrs[NL80211_ATTR_MAC])
4410 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4411 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4412 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4413
4414 if (info->attrs[NL80211_ATTR_IE]) {
4415 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4416 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4417 }
4418
4419 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4420 connect.channel =
4421 ieee80211_get_channel(wiphy,
4422 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4423 if (!connect.channel ||
4c476991
JB
4424 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4425 return -EINVAL;
b23aa676
SO
4426 }
4427
fffd0934
JB
4428 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4429 connkeys = nl80211_parse_connkeys(rdev,
4430 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4431 if (IS_ERR(connkeys))
4432 return PTR_ERR(connkeys);
fffd0934
JB
4433 }
4434
4435 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4436 if (err)
4437 kfree(connkeys);
b23aa676
SO
4438 return err;
4439}
4440
4441static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4442{
4c476991
JB
4443 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4444 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4445 u16 reason;
4446
4447 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4448 reason = WLAN_REASON_DEAUTH_LEAVING;
4449 else
4450 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4451
4452 if (reason == 0)
4453 return -EINVAL;
4454
074ac8df 4455 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4456 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4457 return -EOPNOTSUPP;
b23aa676 4458
4c476991 4459 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4460}
4461
463d0183
JB
4462static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4463{
4c476991 4464 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4465 struct net *net;
4466 int err;
4467 u32 pid;
4468
4469 if (!info->attrs[NL80211_ATTR_PID])
4470 return -EINVAL;
4471
4472 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4473
463d0183 4474 net = get_net_ns_by_pid(pid);
4c476991
JB
4475 if (IS_ERR(net))
4476 return PTR_ERR(net);
463d0183
JB
4477
4478 err = 0;
4479
4480 /* check if anything to do */
4c476991
JB
4481 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4482 err = cfg80211_switch_netns(rdev, net);
463d0183 4483
463d0183 4484 put_net(net);
463d0183
JB
4485 return err;
4486}
4487
67fbb16b
SO
4488static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4489{
4c476991 4490 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4491 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4492 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4493 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4494 struct cfg80211_pmksa pmksa;
4495
4496 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4497
4498 if (!info->attrs[NL80211_ATTR_MAC])
4499 return -EINVAL;
4500
4501 if (!info->attrs[NL80211_ATTR_PMKID])
4502 return -EINVAL;
4503
67fbb16b
SO
4504 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4505 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4506
074ac8df 4507 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4508 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4509 return -EOPNOTSUPP;
67fbb16b
SO
4510
4511 switch (info->genlhdr->cmd) {
4512 case NL80211_CMD_SET_PMKSA:
4513 rdev_ops = rdev->ops->set_pmksa;
4514 break;
4515 case NL80211_CMD_DEL_PMKSA:
4516 rdev_ops = rdev->ops->del_pmksa;
4517 break;
4518 default:
4519 WARN_ON(1);
4520 break;
4521 }
4522
4c476991
JB
4523 if (!rdev_ops)
4524 return -EOPNOTSUPP;
67fbb16b 4525
4c476991 4526 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4527}
4528
4529static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4530{
4c476991
JB
4531 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4532 struct net_device *dev = info->user_ptr[1];
67fbb16b 4533
074ac8df 4534 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4535 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4536 return -EOPNOTSUPP;
67fbb16b 4537
4c476991
JB
4538 if (!rdev->ops->flush_pmksa)
4539 return -EOPNOTSUPP;
67fbb16b 4540
4c476991 4541 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
4542}
4543
9588bbd5
JM
4544static int nl80211_remain_on_channel(struct sk_buff *skb,
4545 struct genl_info *info)
4546{
4c476991
JB
4547 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4548 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
4549 struct ieee80211_channel *chan;
4550 struct sk_buff *msg;
4551 void *hdr;
4552 u64 cookie;
4553 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4554 u32 freq, duration;
4555 int err;
4556
4557 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4558 !info->attrs[NL80211_ATTR_DURATION])
4559 return -EINVAL;
4560
4561 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4562
4563 /*
4564 * We should be on that channel for at least one jiffie,
4565 * and more than 5 seconds seems excessive.
4566 */
a293911d
JB
4567 if (!duration || !msecs_to_jiffies(duration) ||
4568 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
4569 return -EINVAL;
4570
4c476991
JB
4571 if (!rdev->ops->remain_on_channel)
4572 return -EOPNOTSUPP;
9588bbd5 4573
9588bbd5
JM
4574 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4575 channel_type = nla_get_u32(
4576 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4577 if (channel_type != NL80211_CHAN_NO_HT &&
4578 channel_type != NL80211_CHAN_HT20 &&
4579 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4580 channel_type != NL80211_CHAN_HT40MINUS)
4581 return -EINVAL;
9588bbd5
JM
4582 }
4583
4584 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4585 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4586 if (chan == NULL)
4587 return -EINVAL;
9588bbd5
JM
4588
4589 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4590 if (!msg)
4591 return -ENOMEM;
9588bbd5
JM
4592
4593 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4594 NL80211_CMD_REMAIN_ON_CHANNEL);
4595
4596 if (IS_ERR(hdr)) {
4597 err = PTR_ERR(hdr);
4598 goto free_msg;
4599 }
4600
4601 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4602 channel_type, duration, &cookie);
4603
4604 if (err)
4605 goto free_msg;
4606
4607 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4608
4609 genlmsg_end(msg, hdr);
4c476991
JB
4610
4611 return genlmsg_reply(msg, info);
9588bbd5
JM
4612
4613 nla_put_failure:
4614 err = -ENOBUFS;
4615 free_msg:
4616 nlmsg_free(msg);
9588bbd5
JM
4617 return err;
4618}
4619
4620static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4621 struct genl_info *info)
4622{
4c476991
JB
4623 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4624 struct net_device *dev = info->user_ptr[1];
9588bbd5 4625 u64 cookie;
9588bbd5
JM
4626
4627 if (!info->attrs[NL80211_ATTR_COOKIE])
4628 return -EINVAL;
4629
4c476991
JB
4630 if (!rdev->ops->cancel_remain_on_channel)
4631 return -EOPNOTSUPP;
9588bbd5 4632
9588bbd5
JM
4633 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4634
4c476991 4635 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
4636}
4637
13ae75b1
JM
4638static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4639 u8 *rates, u8 rates_len)
4640{
4641 u8 i;
4642 u32 mask = 0;
4643
4644 for (i = 0; i < rates_len; i++) {
4645 int rate = (rates[i] & 0x7f) * 5;
4646 int ridx;
4647 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4648 struct ieee80211_rate *srate =
4649 &sband->bitrates[ridx];
4650 if (rate == srate->bitrate) {
4651 mask |= 1 << ridx;
4652 break;
4653 }
4654 }
4655 if (ridx == sband->n_bitrates)
4656 return 0; /* rate not found */
4657 }
4658
4659 return mask;
4660}
4661
b54452b0 4662static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4663 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4664 .len = NL80211_MAX_SUPP_RATES },
4665};
4666
4667static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4668 struct genl_info *info)
4669{
4670 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4671 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4672 struct cfg80211_bitrate_mask mask;
4c476991
JB
4673 int rem, i;
4674 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4675 struct nlattr *tx_rates;
4676 struct ieee80211_supported_band *sband;
4677
4678 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4679 return -EINVAL;
4680
4c476991
JB
4681 if (!rdev->ops->set_bitrate_mask)
4682 return -EOPNOTSUPP;
13ae75b1
JM
4683
4684 memset(&mask, 0, sizeof(mask));
4685 /* Default to all rates enabled */
4686 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4687 sband = rdev->wiphy.bands[i];
4688 mask.control[i].legacy =
4689 sband ? (1 << sband->n_bitrates) - 1 : 0;
4690 }
4691
4692 /*
4693 * The nested attribute uses enum nl80211_band as the index. This maps
4694 * directly to the enum ieee80211_band values used in cfg80211.
4695 */
4696 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4697 {
4698 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4699 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4700 return -EINVAL;
13ae75b1 4701 sband = rdev->wiphy.bands[band];
4c476991
JB
4702 if (sband == NULL)
4703 return -EINVAL;
13ae75b1
JM
4704 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4705 nla_len(tx_rates), nl80211_txattr_policy);
4706 if (tb[NL80211_TXRATE_LEGACY]) {
4707 mask.control[band].legacy = rateset_to_mask(
4708 sband,
4709 nla_data(tb[NL80211_TXRATE_LEGACY]),
4710 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4711 if (mask.control[band].legacy == 0)
4712 return -EINVAL;
13ae75b1
JM
4713 }
4714 }
4715
4c476991 4716 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4717}
4718
2e161f78 4719static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4720{
4c476991
JB
4721 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4722 struct net_device *dev = info->user_ptr[1];
2e161f78 4723 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4724
4725 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4726 return -EINVAL;
4727
2e161f78
JB
4728 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4729 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4730
9d38d85d 4731 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4732 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4733 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4734 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4735 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4736 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4737 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4738 return -EOPNOTSUPP;
026331c4
JM
4739
4740 /* not much point in registering if we can't reply */
4c476991
JB
4741 if (!rdev->ops->mgmt_tx)
4742 return -EOPNOTSUPP;
026331c4 4743
4c476991 4744 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4745 frame_type,
026331c4
JM
4746 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4747 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4748}
4749
2e161f78 4750static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4751{
4c476991
JB
4752 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4753 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4754 struct ieee80211_channel *chan;
4755 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4756 bool channel_type_valid = false;
026331c4
JM
4757 u32 freq;
4758 int err;
4759 void *hdr;
4760 u64 cookie;
4761 struct sk_buff *msg;
f7ca38df
JB
4762 unsigned int wait = 0;
4763 bool offchan;
026331c4
JM
4764
4765 if (!info->attrs[NL80211_ATTR_FRAME] ||
4766 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4767 return -EINVAL;
4768
4c476991
JB
4769 if (!rdev->ops->mgmt_tx)
4770 return -EOPNOTSUPP;
026331c4 4771
9d38d85d 4772 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4773 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4774 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4775 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4776 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4777 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4778 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4779 return -EOPNOTSUPP;
026331c4 4780
f7ca38df
JB
4781 if (info->attrs[NL80211_ATTR_DURATION]) {
4782 if (!rdev->ops->mgmt_tx_cancel_wait)
4783 return -EINVAL;
4784 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4785 }
4786
026331c4
JM
4787 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4788 channel_type = nla_get_u32(
4789 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4790 if (channel_type != NL80211_CHAN_NO_HT &&
4791 channel_type != NL80211_CHAN_HT20 &&
4792 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4793 channel_type != NL80211_CHAN_HT40MINUS)
4794 return -EINVAL;
252aa631 4795 channel_type_valid = true;
026331c4
JM
4796 }
4797
f7ca38df
JB
4798 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4799
026331c4
JM
4800 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4801 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4802 if (chan == NULL)
4803 return -EINVAL;
026331c4
JM
4804
4805 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4806 if (!msg)
4807 return -ENOMEM;
026331c4
JM
4808
4809 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4810 NL80211_CMD_FRAME);
026331c4
JM
4811
4812 if (IS_ERR(hdr)) {
4813 err = PTR_ERR(hdr);
4814 goto free_msg;
4815 }
f7ca38df
JB
4816 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4817 channel_type_valid, wait,
2e161f78
JB
4818 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4819 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4820 &cookie);
026331c4
JM
4821 if (err)
4822 goto free_msg;
4823
4824 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4825
4826 genlmsg_end(msg, hdr);
4c476991 4827 return genlmsg_reply(msg, info);
026331c4
JM
4828
4829 nla_put_failure:
4830 err = -ENOBUFS;
4831 free_msg:
4832 nlmsg_free(msg);
026331c4
JM
4833 return err;
4834}
4835
f7ca38df
JB
4836static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4837{
4838 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4839 struct net_device *dev = info->user_ptr[1];
4840 u64 cookie;
4841
4842 if (!info->attrs[NL80211_ATTR_COOKIE])
4843 return -EINVAL;
4844
4845 if (!rdev->ops->mgmt_tx_cancel_wait)
4846 return -EOPNOTSUPP;
4847
4848 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4849 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4850 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4851 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4852 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4853 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4854 return -EOPNOTSUPP;
4855
4856 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4857
4858 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4859}
4860
ffb9eb3d
KV
4861static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4862{
4c476991 4863 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4864 struct wireless_dev *wdev;
4c476991 4865 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4866 u8 ps_state;
4867 bool state;
4868 int err;
4869
4c476991
JB
4870 if (!info->attrs[NL80211_ATTR_PS_STATE])
4871 return -EINVAL;
ffb9eb3d
KV
4872
4873 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4874
4c476991
JB
4875 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4876 return -EINVAL;
ffb9eb3d
KV
4877
4878 wdev = dev->ieee80211_ptr;
4879
4c476991
JB
4880 if (!rdev->ops->set_power_mgmt)
4881 return -EOPNOTSUPP;
ffb9eb3d
KV
4882
4883 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4884
4885 if (state == wdev->ps)
4c476991 4886 return 0;
ffb9eb3d 4887
4c476991
JB
4888 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4889 wdev->ps_timeout);
4890 if (!err)
4891 wdev->ps = state;
ffb9eb3d
KV
4892 return err;
4893}
4894
4895static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4896{
4c476991 4897 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4898 enum nl80211_ps_state ps_state;
4899 struct wireless_dev *wdev;
4c476991 4900 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4901 struct sk_buff *msg;
4902 void *hdr;
4903 int err;
4904
ffb9eb3d
KV
4905 wdev = dev->ieee80211_ptr;
4906
4c476991
JB
4907 if (!rdev->ops->set_power_mgmt)
4908 return -EOPNOTSUPP;
ffb9eb3d
KV
4909
4910 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4911 if (!msg)
4912 return -ENOMEM;
ffb9eb3d
KV
4913
4914 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4915 NL80211_CMD_GET_POWER_SAVE);
4916 if (!hdr) {
4c476991 4917 err = -ENOBUFS;
ffb9eb3d
KV
4918 goto free_msg;
4919 }
4920
4921 if (wdev->ps)
4922 ps_state = NL80211_PS_ENABLED;
4923 else
4924 ps_state = NL80211_PS_DISABLED;
4925
4926 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4927
4928 genlmsg_end(msg, hdr);
4c476991 4929 return genlmsg_reply(msg, info);
ffb9eb3d 4930
4c476991 4931 nla_put_failure:
ffb9eb3d 4932 err = -ENOBUFS;
4c476991 4933 free_msg:
ffb9eb3d 4934 nlmsg_free(msg);
ffb9eb3d
KV
4935 return err;
4936}
4937
d6dc1a38
JO
4938static struct nla_policy
4939nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4940 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4941 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4942 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4943};
4944
4945static int nl80211_set_cqm_rssi(struct genl_info *info,
4946 s32 threshold, u32 hysteresis)
4947{
4c476991 4948 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4949 struct wireless_dev *wdev;
4c476991 4950 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4951
4952 if (threshold > 0)
4953 return -EINVAL;
4954
d6dc1a38
JO
4955 wdev = dev->ieee80211_ptr;
4956
4c476991
JB
4957 if (!rdev->ops->set_cqm_rssi_config)
4958 return -EOPNOTSUPP;
d6dc1a38 4959
074ac8df 4960 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4961 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4962 return -EOPNOTSUPP;
d6dc1a38 4963
4c476991
JB
4964 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4965 threshold, hysteresis);
d6dc1a38
JO
4966}
4967
4968static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4969{
4970 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4971 struct nlattr *cqm;
4972 int err;
4973
4974 cqm = info->attrs[NL80211_ATTR_CQM];
4975 if (!cqm) {
4976 err = -EINVAL;
4977 goto out;
4978 }
4979
4980 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4981 nl80211_attr_cqm_policy);
4982 if (err)
4983 goto out;
4984
4985 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4986 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4987 s32 threshold;
4988 u32 hysteresis;
4989 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4990 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4991 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4992 } else
4993 err = -EINVAL;
4994
4995out:
4996 return err;
4997}
4998
29cbe68c
JB
4999static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5000{
5001 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5002 struct net_device *dev = info->user_ptr[1];
5003 struct mesh_config cfg;
c80d545d 5004 struct mesh_setup setup;
29cbe68c
JB
5005 int err;
5006
5007 /* start with default */
5008 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 5009 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 5010
24bdd9f4 5011 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 5012 /* and parse parameters if given */
24bdd9f4 5013 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
5014 if (err)
5015 return err;
5016 }
5017
5018 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5019 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5020 return -EINVAL;
5021
c80d545d
JC
5022 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5023 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5024
5025 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5026 /* parse additional setup parameters if given */
5027 err = nl80211_parse_mesh_setup(info, &setup);
5028 if (err)
5029 return err;
5030 }
5031
5032 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
5033}
5034
5035static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5036{
5037 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5038 struct net_device *dev = info->user_ptr[1];
5039
5040 return cfg80211_leave_mesh(rdev, dev);
5041}
5042
ff1b6e69
JB
5043static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5044{
5045 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5046 struct sk_buff *msg;
5047 void *hdr;
5048
5049 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5050 return -EOPNOTSUPP;
5051
5052 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5053 if (!msg)
5054 return -ENOMEM;
5055
5056 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5057 NL80211_CMD_GET_WOWLAN);
5058 if (!hdr)
5059 goto nla_put_failure;
5060
5061 if (rdev->wowlan) {
5062 struct nlattr *nl_wowlan;
5063
5064 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5065 if (!nl_wowlan)
5066 goto nla_put_failure;
5067
5068 if (rdev->wowlan->any)
5069 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5070 if (rdev->wowlan->disconnect)
5071 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5072 if (rdev->wowlan->magic_pkt)
5073 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
5074 if (rdev->wowlan->n_patterns) {
5075 struct nlattr *nl_pats, *nl_pat;
5076 int i, pat_len;
5077
5078 nl_pats = nla_nest_start(msg,
5079 NL80211_WOWLAN_TRIG_PKT_PATTERN);
5080 if (!nl_pats)
5081 goto nla_put_failure;
5082
5083 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5084 nl_pat = nla_nest_start(msg, i + 1);
5085 if (!nl_pat)
5086 goto nla_put_failure;
5087 pat_len = rdev->wowlan->patterns[i].pattern_len;
5088 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5089 DIV_ROUND_UP(pat_len, 8),
5090 rdev->wowlan->patterns[i].mask);
5091 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5092 pat_len,
5093 rdev->wowlan->patterns[i].pattern);
5094 nla_nest_end(msg, nl_pat);
5095 }
5096 nla_nest_end(msg, nl_pats);
5097 }
5098
5099 nla_nest_end(msg, nl_wowlan);
5100 }
5101
5102 genlmsg_end(msg, hdr);
5103 return genlmsg_reply(msg, info);
5104
5105nla_put_failure:
5106 nlmsg_free(msg);
5107 return -ENOBUFS;
5108}
5109
5110static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
5111{
5112 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5113 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
5114 struct cfg80211_wowlan no_triggers = {};
5115 struct cfg80211_wowlan new_triggers = {};
5116 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
5117 int err, i;
5118
5119 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5120 return -EOPNOTSUPP;
5121
5122 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
5123 goto no_triggers;
5124
5125 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
5126 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5127 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5128 nl80211_wowlan_policy);
5129 if (err)
5130 return err;
5131
5132 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
5133 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
5134 return -EINVAL;
5135 new_triggers.any = true;
5136 }
5137
5138 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
5139 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
5140 return -EINVAL;
5141 new_triggers.disconnect = true;
5142 }
5143
5144 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
5145 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
5146 return -EINVAL;
5147 new_triggers.magic_pkt = true;
5148 }
5149
5150 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
5151 struct nlattr *pat;
5152 int n_patterns = 0;
5153 int rem, pat_len, mask_len;
5154 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
5155
5156 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5157 rem)
5158 n_patterns++;
5159 if (n_patterns > wowlan->n_patterns)
5160 return -EINVAL;
5161
5162 new_triggers.patterns = kcalloc(n_patterns,
5163 sizeof(new_triggers.patterns[0]),
5164 GFP_KERNEL);
5165 if (!new_triggers.patterns)
5166 return -ENOMEM;
5167
5168 new_triggers.n_patterns = n_patterns;
5169 i = 0;
5170
5171 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5172 rem) {
5173 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
5174 nla_data(pat), nla_len(pat), NULL);
5175 err = -EINVAL;
5176 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
5177 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
5178 goto error;
5179 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
5180 mask_len = DIV_ROUND_UP(pat_len, 8);
5181 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
5182 mask_len)
5183 goto error;
5184 if (pat_len > wowlan->pattern_max_len ||
5185 pat_len < wowlan->pattern_min_len)
5186 goto error;
5187
5188 new_triggers.patterns[i].mask =
5189 kmalloc(mask_len + pat_len, GFP_KERNEL);
5190 if (!new_triggers.patterns[i].mask) {
5191 err = -ENOMEM;
5192 goto error;
5193 }
5194 new_triggers.patterns[i].pattern =
5195 new_triggers.patterns[i].mask + mask_len;
5196 memcpy(new_triggers.patterns[i].mask,
5197 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
5198 mask_len);
5199 new_triggers.patterns[i].pattern_len = pat_len;
5200 memcpy(new_triggers.patterns[i].pattern,
5201 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
5202 pat_len);
5203 i++;
5204 }
5205 }
5206
5207 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
5208 struct cfg80211_wowlan *ntrig;
5209 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
5210 GFP_KERNEL);
5211 if (!ntrig) {
5212 err = -ENOMEM;
5213 goto error;
5214 }
5215 cfg80211_rdev_free_wowlan(rdev);
5216 rdev->wowlan = ntrig;
5217 } else {
5218 no_triggers:
5219 cfg80211_rdev_free_wowlan(rdev);
5220 rdev->wowlan = NULL;
5221 }
5222
5223 return 0;
5224 error:
5225 for (i = 0; i < new_triggers.n_patterns; i++)
5226 kfree(new_triggers.patterns[i].mask);
5227 kfree(new_triggers.patterns);
5228 return err;
5229}
5230
4c476991
JB
5231#define NL80211_FLAG_NEED_WIPHY 0x01
5232#define NL80211_FLAG_NEED_NETDEV 0x02
5233#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
5234#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
5235#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
5236 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
5237
5238static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
5239 struct genl_info *info)
5240{
5241 struct cfg80211_registered_device *rdev;
5242 struct net_device *dev;
5243 int err;
5244 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
5245
5246 if (rtnl)
5247 rtnl_lock();
5248
5249 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
5250 rdev = cfg80211_get_dev_from_info(info);
5251 if (IS_ERR(rdev)) {
5252 if (rtnl)
5253 rtnl_unlock();
5254 return PTR_ERR(rdev);
5255 }
5256 info->user_ptr[0] = rdev;
5257 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
5258 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5259 if (err) {
5260 if (rtnl)
5261 rtnl_unlock();
5262 return err;
5263 }
41265714
JB
5264 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
5265 !netif_running(dev)) {
d537f5fd
JB
5266 cfg80211_unlock_rdev(rdev);
5267 dev_put(dev);
41265714
JB
5268 if (rtnl)
5269 rtnl_unlock();
5270 return -ENETDOWN;
5271 }
4c476991
JB
5272 info->user_ptr[0] = rdev;
5273 info->user_ptr[1] = dev;
5274 }
5275
5276 return 0;
5277}
5278
5279static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
5280 struct genl_info *info)
5281{
5282 if (info->user_ptr[0])
5283 cfg80211_unlock_rdev(info->user_ptr[0]);
5284 if (info->user_ptr[1])
5285 dev_put(info->user_ptr[1]);
5286 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
5287 rtnl_unlock();
5288}
5289
55682965
JB
5290static struct genl_ops nl80211_ops[] = {
5291 {
5292 .cmd = NL80211_CMD_GET_WIPHY,
5293 .doit = nl80211_get_wiphy,
5294 .dumpit = nl80211_dump_wiphy,
5295 .policy = nl80211_policy,
5296 /* can be retrieved by unprivileged users */
4c476991 5297 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
5298 },
5299 {
5300 .cmd = NL80211_CMD_SET_WIPHY,
5301 .doit = nl80211_set_wiphy,
5302 .policy = nl80211_policy,
5303 .flags = GENL_ADMIN_PERM,
4c476991 5304 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
5305 },
5306 {
5307 .cmd = NL80211_CMD_GET_INTERFACE,
5308 .doit = nl80211_get_interface,
5309 .dumpit = nl80211_dump_interface,
5310 .policy = nl80211_policy,
5311 /* can be retrieved by unprivileged users */
4c476991 5312 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
5313 },
5314 {
5315 .cmd = NL80211_CMD_SET_INTERFACE,
5316 .doit = nl80211_set_interface,
5317 .policy = nl80211_policy,
5318 .flags = GENL_ADMIN_PERM,
4c476991
JB
5319 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5320 NL80211_FLAG_NEED_RTNL,
55682965
JB
5321 },
5322 {
5323 .cmd = NL80211_CMD_NEW_INTERFACE,
5324 .doit = nl80211_new_interface,
5325 .policy = nl80211_policy,
5326 .flags = GENL_ADMIN_PERM,
4c476991
JB
5327 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5328 NL80211_FLAG_NEED_RTNL,
55682965
JB
5329 },
5330 {
5331 .cmd = NL80211_CMD_DEL_INTERFACE,
5332 .doit = nl80211_del_interface,
5333 .policy = nl80211_policy,
41ade00f 5334 .flags = GENL_ADMIN_PERM,
4c476991
JB
5335 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5336 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5337 },
5338 {
5339 .cmd = NL80211_CMD_GET_KEY,
5340 .doit = nl80211_get_key,
5341 .policy = nl80211_policy,
5342 .flags = GENL_ADMIN_PERM,
4c476991
JB
5343 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5344 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5345 },
5346 {
5347 .cmd = NL80211_CMD_SET_KEY,
5348 .doit = nl80211_set_key,
5349 .policy = nl80211_policy,
5350 .flags = GENL_ADMIN_PERM,
41265714 5351 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5352 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5353 },
5354 {
5355 .cmd = NL80211_CMD_NEW_KEY,
5356 .doit = nl80211_new_key,
5357 .policy = nl80211_policy,
5358 .flags = GENL_ADMIN_PERM,
41265714 5359 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5360 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5361 },
5362 {
5363 .cmd = NL80211_CMD_DEL_KEY,
5364 .doit = nl80211_del_key,
5365 .policy = nl80211_policy,
55682965 5366 .flags = GENL_ADMIN_PERM,
41265714 5367 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5368 NL80211_FLAG_NEED_RTNL,
55682965 5369 },
ed1b6cc7
JB
5370 {
5371 .cmd = NL80211_CMD_SET_BEACON,
5372 .policy = nl80211_policy,
5373 .flags = GENL_ADMIN_PERM,
5374 .doit = nl80211_addset_beacon,
4c476991
JB
5375 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5376 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
5377 },
5378 {
5379 .cmd = NL80211_CMD_NEW_BEACON,
5380 .policy = nl80211_policy,
5381 .flags = GENL_ADMIN_PERM,
5382 .doit = nl80211_addset_beacon,
4c476991
JB
5383 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5384 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
5385 },
5386 {
5387 .cmd = NL80211_CMD_DEL_BEACON,
5388 .policy = nl80211_policy,
5389 .flags = GENL_ADMIN_PERM,
5390 .doit = nl80211_del_beacon,
4c476991
JB
5391 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5392 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 5393 },
5727ef1b
JB
5394 {
5395 .cmd = NL80211_CMD_GET_STATION,
5396 .doit = nl80211_get_station,
2ec600d6 5397 .dumpit = nl80211_dump_station,
5727ef1b 5398 .policy = nl80211_policy,
4c476991
JB
5399 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5400 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5401 },
5402 {
5403 .cmd = NL80211_CMD_SET_STATION,
5404 .doit = nl80211_set_station,
5405 .policy = nl80211_policy,
5406 .flags = GENL_ADMIN_PERM,
4c476991
JB
5407 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5408 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5409 },
5410 {
5411 .cmd = NL80211_CMD_NEW_STATION,
5412 .doit = nl80211_new_station,
5413 .policy = nl80211_policy,
5414 .flags = GENL_ADMIN_PERM,
41265714 5415 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5416 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5417 },
5418 {
5419 .cmd = NL80211_CMD_DEL_STATION,
5420 .doit = nl80211_del_station,
5421 .policy = nl80211_policy,
2ec600d6 5422 .flags = GENL_ADMIN_PERM,
4c476991
JB
5423 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5424 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5425 },
5426 {
5427 .cmd = NL80211_CMD_GET_MPATH,
5428 .doit = nl80211_get_mpath,
5429 .dumpit = nl80211_dump_mpath,
5430 .policy = nl80211_policy,
5431 .flags = GENL_ADMIN_PERM,
41265714 5432 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5433 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5434 },
5435 {
5436 .cmd = NL80211_CMD_SET_MPATH,
5437 .doit = nl80211_set_mpath,
5438 .policy = nl80211_policy,
5439 .flags = GENL_ADMIN_PERM,
41265714 5440 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5441 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5442 },
5443 {
5444 .cmd = NL80211_CMD_NEW_MPATH,
5445 .doit = nl80211_new_mpath,
5446 .policy = nl80211_policy,
5447 .flags = GENL_ADMIN_PERM,
41265714 5448 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5449 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5450 },
5451 {
5452 .cmd = NL80211_CMD_DEL_MPATH,
5453 .doit = nl80211_del_mpath,
5454 .policy = nl80211_policy,
9f1ba906 5455 .flags = GENL_ADMIN_PERM,
4c476991
JB
5456 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5457 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
5458 },
5459 {
5460 .cmd = NL80211_CMD_SET_BSS,
5461 .doit = nl80211_set_bss,
5462 .policy = nl80211_policy,
b2e1b302 5463 .flags = GENL_ADMIN_PERM,
4c476991
JB
5464 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5465 NL80211_FLAG_NEED_RTNL,
b2e1b302 5466 },
f130347c
LR
5467 {
5468 .cmd = NL80211_CMD_GET_REG,
5469 .doit = nl80211_get_reg,
5470 .policy = nl80211_policy,
5471 /* can be retrieved by unprivileged users */
5472 },
b2e1b302
LR
5473 {
5474 .cmd = NL80211_CMD_SET_REG,
5475 .doit = nl80211_set_reg,
5476 .policy = nl80211_policy,
5477 .flags = GENL_ADMIN_PERM,
5478 },
5479 {
5480 .cmd = NL80211_CMD_REQ_SET_REG,
5481 .doit = nl80211_req_set_reg,
5482 .policy = nl80211_policy,
93da9cc1 5483 .flags = GENL_ADMIN_PERM,
5484 },
5485 {
24bdd9f4
JC
5486 .cmd = NL80211_CMD_GET_MESH_CONFIG,
5487 .doit = nl80211_get_mesh_config,
93da9cc1 5488 .policy = nl80211_policy,
5489 /* can be retrieved by unprivileged users */
4c476991
JB
5490 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5491 NL80211_FLAG_NEED_RTNL,
93da9cc1 5492 },
5493 {
24bdd9f4
JC
5494 .cmd = NL80211_CMD_SET_MESH_CONFIG,
5495 .doit = nl80211_update_mesh_config,
93da9cc1 5496 .policy = nl80211_policy,
9aed3cc1 5497 .flags = GENL_ADMIN_PERM,
29cbe68c 5498 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5499 NL80211_FLAG_NEED_RTNL,
9aed3cc1 5500 },
2a519311
JB
5501 {
5502 .cmd = NL80211_CMD_TRIGGER_SCAN,
5503 .doit = nl80211_trigger_scan,
5504 .policy = nl80211_policy,
5505 .flags = GENL_ADMIN_PERM,
41265714 5506 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5507 NL80211_FLAG_NEED_RTNL,
2a519311
JB
5508 },
5509 {
5510 .cmd = NL80211_CMD_GET_SCAN,
5511 .policy = nl80211_policy,
5512 .dumpit = nl80211_dump_scan,
5513 },
807f8a8c
LC
5514 {
5515 .cmd = NL80211_CMD_START_SCHED_SCAN,
5516 .doit = nl80211_start_sched_scan,
5517 .policy = nl80211_policy,
5518 .flags = GENL_ADMIN_PERM,
5519 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5520 NL80211_FLAG_NEED_RTNL,
5521 },
5522 {
5523 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
5524 .doit = nl80211_stop_sched_scan,
5525 .policy = nl80211_policy,
5526 .flags = GENL_ADMIN_PERM,
5527 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5528 NL80211_FLAG_NEED_RTNL,
5529 },
636a5d36
JM
5530 {
5531 .cmd = NL80211_CMD_AUTHENTICATE,
5532 .doit = nl80211_authenticate,
5533 .policy = nl80211_policy,
5534 .flags = GENL_ADMIN_PERM,
41265714 5535 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5536 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5537 },
5538 {
5539 .cmd = NL80211_CMD_ASSOCIATE,
5540 .doit = nl80211_associate,
5541 .policy = nl80211_policy,
5542 .flags = GENL_ADMIN_PERM,
41265714 5543 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5544 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5545 },
5546 {
5547 .cmd = NL80211_CMD_DEAUTHENTICATE,
5548 .doit = nl80211_deauthenticate,
5549 .policy = nl80211_policy,
5550 .flags = GENL_ADMIN_PERM,
41265714 5551 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5552 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5553 },
5554 {
5555 .cmd = NL80211_CMD_DISASSOCIATE,
5556 .doit = nl80211_disassociate,
5557 .policy = nl80211_policy,
5558 .flags = GENL_ADMIN_PERM,
41265714 5559 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5560 NL80211_FLAG_NEED_RTNL,
636a5d36 5561 },
04a773ad
JB
5562 {
5563 .cmd = NL80211_CMD_JOIN_IBSS,
5564 .doit = nl80211_join_ibss,
5565 .policy = nl80211_policy,
5566 .flags = GENL_ADMIN_PERM,
41265714 5567 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5568 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
5569 },
5570 {
5571 .cmd = NL80211_CMD_LEAVE_IBSS,
5572 .doit = nl80211_leave_ibss,
5573 .policy = nl80211_policy,
5574 .flags = GENL_ADMIN_PERM,
41265714 5575 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5576 NL80211_FLAG_NEED_RTNL,
04a773ad 5577 },
aff89a9b
JB
5578#ifdef CONFIG_NL80211_TESTMODE
5579 {
5580 .cmd = NL80211_CMD_TESTMODE,
5581 .doit = nl80211_testmode_do,
5582 .policy = nl80211_policy,
5583 .flags = GENL_ADMIN_PERM,
4c476991
JB
5584 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5585 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
5586 },
5587#endif
b23aa676
SO
5588 {
5589 .cmd = NL80211_CMD_CONNECT,
5590 .doit = nl80211_connect,
5591 .policy = nl80211_policy,
5592 .flags = GENL_ADMIN_PERM,
41265714 5593 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5594 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
5595 },
5596 {
5597 .cmd = NL80211_CMD_DISCONNECT,
5598 .doit = nl80211_disconnect,
5599 .policy = nl80211_policy,
5600 .flags = GENL_ADMIN_PERM,
41265714 5601 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5602 NL80211_FLAG_NEED_RTNL,
b23aa676 5603 },
463d0183
JB
5604 {
5605 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5606 .doit = nl80211_wiphy_netns,
5607 .policy = nl80211_policy,
5608 .flags = GENL_ADMIN_PERM,
4c476991
JB
5609 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5610 NL80211_FLAG_NEED_RTNL,
463d0183 5611 },
61fa713c
HS
5612 {
5613 .cmd = NL80211_CMD_GET_SURVEY,
5614 .policy = nl80211_policy,
5615 .dumpit = nl80211_dump_survey,
5616 },
67fbb16b
SO
5617 {
5618 .cmd = NL80211_CMD_SET_PMKSA,
5619 .doit = nl80211_setdel_pmksa,
5620 .policy = nl80211_policy,
5621 .flags = GENL_ADMIN_PERM,
4c476991
JB
5622 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5623 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5624 },
5625 {
5626 .cmd = NL80211_CMD_DEL_PMKSA,
5627 .doit = nl80211_setdel_pmksa,
5628 .policy = nl80211_policy,
5629 .flags = GENL_ADMIN_PERM,
4c476991
JB
5630 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5631 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5632 },
5633 {
5634 .cmd = NL80211_CMD_FLUSH_PMKSA,
5635 .doit = nl80211_flush_pmksa,
5636 .policy = nl80211_policy,
5637 .flags = GENL_ADMIN_PERM,
4c476991
JB
5638 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5639 NL80211_FLAG_NEED_RTNL,
67fbb16b 5640 },
9588bbd5
JM
5641 {
5642 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5643 .doit = nl80211_remain_on_channel,
5644 .policy = nl80211_policy,
5645 .flags = GENL_ADMIN_PERM,
41265714 5646 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5647 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
5648 },
5649 {
5650 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5651 .doit = nl80211_cancel_remain_on_channel,
5652 .policy = nl80211_policy,
5653 .flags = GENL_ADMIN_PERM,
41265714 5654 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5655 NL80211_FLAG_NEED_RTNL,
9588bbd5 5656 },
13ae75b1
JM
5657 {
5658 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5659 .doit = nl80211_set_tx_bitrate_mask,
5660 .policy = nl80211_policy,
5661 .flags = GENL_ADMIN_PERM,
4c476991
JB
5662 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5663 NL80211_FLAG_NEED_RTNL,
13ae75b1 5664 },
026331c4 5665 {
2e161f78
JB
5666 .cmd = NL80211_CMD_REGISTER_FRAME,
5667 .doit = nl80211_register_mgmt,
026331c4
JM
5668 .policy = nl80211_policy,
5669 .flags = GENL_ADMIN_PERM,
4c476991
JB
5670 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5671 NL80211_FLAG_NEED_RTNL,
026331c4
JM
5672 },
5673 {
2e161f78
JB
5674 .cmd = NL80211_CMD_FRAME,
5675 .doit = nl80211_tx_mgmt,
026331c4 5676 .policy = nl80211_policy,
f7ca38df
JB
5677 .flags = GENL_ADMIN_PERM,
5678 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5679 NL80211_FLAG_NEED_RTNL,
5680 },
5681 {
5682 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5683 .doit = nl80211_tx_mgmt_cancel_wait,
5684 .policy = nl80211_policy,
026331c4 5685 .flags = GENL_ADMIN_PERM,
41265714 5686 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5687 NL80211_FLAG_NEED_RTNL,
026331c4 5688 },
ffb9eb3d
KV
5689 {
5690 .cmd = NL80211_CMD_SET_POWER_SAVE,
5691 .doit = nl80211_set_power_save,
5692 .policy = nl80211_policy,
5693 .flags = GENL_ADMIN_PERM,
4c476991
JB
5694 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5695 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
5696 },
5697 {
5698 .cmd = NL80211_CMD_GET_POWER_SAVE,
5699 .doit = nl80211_get_power_save,
5700 .policy = nl80211_policy,
5701 /* can be retrieved by unprivileged users */
4c476991
JB
5702 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5703 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 5704 },
d6dc1a38
JO
5705 {
5706 .cmd = NL80211_CMD_SET_CQM,
5707 .doit = nl80211_set_cqm,
5708 .policy = nl80211_policy,
5709 .flags = GENL_ADMIN_PERM,
4c476991
JB
5710 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5711 NL80211_FLAG_NEED_RTNL,
d6dc1a38 5712 },
f444de05
JB
5713 {
5714 .cmd = NL80211_CMD_SET_CHANNEL,
5715 .doit = nl80211_set_channel,
5716 .policy = nl80211_policy,
5717 .flags = GENL_ADMIN_PERM,
4c476991
JB
5718 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5719 NL80211_FLAG_NEED_RTNL,
f444de05 5720 },
e8347eba
BJ
5721 {
5722 .cmd = NL80211_CMD_SET_WDS_PEER,
5723 .doit = nl80211_set_wds_peer,
5724 .policy = nl80211_policy,
5725 .flags = GENL_ADMIN_PERM,
43b19952
JB
5726 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5727 NL80211_FLAG_NEED_RTNL,
e8347eba 5728 },
29cbe68c
JB
5729 {
5730 .cmd = NL80211_CMD_JOIN_MESH,
5731 .doit = nl80211_join_mesh,
5732 .policy = nl80211_policy,
5733 .flags = GENL_ADMIN_PERM,
5734 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5735 NL80211_FLAG_NEED_RTNL,
5736 },
5737 {
5738 .cmd = NL80211_CMD_LEAVE_MESH,
5739 .doit = nl80211_leave_mesh,
5740 .policy = nl80211_policy,
5741 .flags = GENL_ADMIN_PERM,
5742 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5743 NL80211_FLAG_NEED_RTNL,
5744 },
ff1b6e69
JB
5745 {
5746 .cmd = NL80211_CMD_GET_WOWLAN,
5747 .doit = nl80211_get_wowlan,
5748 .policy = nl80211_policy,
5749 /* can be retrieved by unprivileged users */
5750 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5751 NL80211_FLAG_NEED_RTNL,
5752 },
5753 {
5754 .cmd = NL80211_CMD_SET_WOWLAN,
5755 .doit = nl80211_set_wowlan,
5756 .policy = nl80211_policy,
5757 .flags = GENL_ADMIN_PERM,
5758 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5759 NL80211_FLAG_NEED_RTNL,
5760 },
55682965 5761};
9588bbd5 5762
6039f6d2
JM
5763static struct genl_multicast_group nl80211_mlme_mcgrp = {
5764 .name = "mlme",
5765};
55682965
JB
5766
5767/* multicast groups */
5768static struct genl_multicast_group nl80211_config_mcgrp = {
5769 .name = "config",
5770};
2a519311
JB
5771static struct genl_multicast_group nl80211_scan_mcgrp = {
5772 .name = "scan",
5773};
73d54c9e
LR
5774static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5775 .name = "regulatory",
5776};
55682965
JB
5777
5778/* notification functions */
5779
5780void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5781{
5782 struct sk_buff *msg;
5783
fd2120ca 5784 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5785 if (!msg)
5786 return;
5787
5788 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5789 nlmsg_free(msg);
5790 return;
5791 }
5792
463d0183
JB
5793 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5794 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5795}
5796
362a415d
JB
5797static int nl80211_add_scan_req(struct sk_buff *msg,
5798 struct cfg80211_registered_device *rdev)
5799{
5800 struct cfg80211_scan_request *req = rdev->scan_req;
5801 struct nlattr *nest;
5802 int i;
5803
667503dd
JB
5804 ASSERT_RDEV_LOCK(rdev);
5805
362a415d
JB
5806 if (WARN_ON(!req))
5807 return 0;
5808
5809 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5810 if (!nest)
5811 goto nla_put_failure;
5812 for (i = 0; i < req->n_ssids; i++)
5813 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5814 nla_nest_end(msg, nest);
5815
5816 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5817 if (!nest)
5818 goto nla_put_failure;
5819 for (i = 0; i < req->n_channels; i++)
5820 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5821 nla_nest_end(msg, nest);
5822
5823 if (req->ie)
5824 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5825
5826 return 0;
5827 nla_put_failure:
5828 return -ENOBUFS;
5829}
5830
a538e2d5
JB
5831static int nl80211_send_scan_msg(struct sk_buff *msg,
5832 struct cfg80211_registered_device *rdev,
5833 struct net_device *netdev,
5834 u32 pid, u32 seq, int flags,
5835 u32 cmd)
2a519311
JB
5836{
5837 void *hdr;
5838
5839 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5840 if (!hdr)
5841 return -1;
5842
b5850a7a 5843 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5844 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5845
362a415d
JB
5846 /* ignore errors and send incomplete event anyway */
5847 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5848
5849 return genlmsg_end(msg, hdr);
5850
5851 nla_put_failure:
5852 genlmsg_cancel(msg, hdr);
5853 return -EMSGSIZE;
5854}
5855
807f8a8c
LC
5856static int
5857nl80211_send_sched_scan_msg(struct sk_buff *msg,
5858 struct cfg80211_registered_device *rdev,
5859 struct net_device *netdev,
5860 u32 pid, u32 seq, int flags, u32 cmd)
5861{
5862 void *hdr;
5863
5864 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5865 if (!hdr)
5866 return -1;
5867
5868 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5869 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5870
5871 return genlmsg_end(msg, hdr);
5872
5873 nla_put_failure:
5874 genlmsg_cancel(msg, hdr);
5875 return -EMSGSIZE;
5876}
5877
a538e2d5
JB
5878void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5879 struct net_device *netdev)
5880{
5881 struct sk_buff *msg;
5882
5883 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5884 if (!msg)
5885 return;
5886
5887 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5888 NL80211_CMD_TRIGGER_SCAN) < 0) {
5889 nlmsg_free(msg);
5890 return;
5891 }
5892
463d0183
JB
5893 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5894 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5895}
5896
2a519311
JB
5897void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5898 struct net_device *netdev)
5899{
5900 struct sk_buff *msg;
5901
fd2120ca 5902 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5903 if (!msg)
5904 return;
5905
a538e2d5
JB
5906 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5907 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5908 nlmsg_free(msg);
5909 return;
5910 }
5911
463d0183
JB
5912 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5913 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5914}
5915
5916void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5917 struct net_device *netdev)
5918{
5919 struct sk_buff *msg;
5920
fd2120ca 5921 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5922 if (!msg)
5923 return;
5924
a538e2d5
JB
5925 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5926 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5927 nlmsg_free(msg);
5928 return;
5929 }
5930
463d0183
JB
5931 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5932 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5933}
5934
807f8a8c
LC
5935void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
5936 struct net_device *netdev)
5937{
5938 struct sk_buff *msg;
5939
5940 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5941 if (!msg)
5942 return;
5943
5944 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
5945 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
5946 nlmsg_free(msg);
5947 return;
5948 }
5949
5950 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5951 nl80211_scan_mcgrp.id, GFP_KERNEL);
5952}
5953
5954void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
5955 struct net_device *netdev, u32 cmd)
5956{
5957 struct sk_buff *msg;
5958
5959 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5960 if (!msg)
5961 return;
5962
5963 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
5964 nlmsg_free(msg);
5965 return;
5966 }
5967
5968 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5969 nl80211_scan_mcgrp.id, GFP_KERNEL);
5970}
5971
73d54c9e
LR
5972/*
5973 * This can happen on global regulatory changes or device specific settings
5974 * based on custom world regulatory domains.
5975 */
5976void nl80211_send_reg_change_event(struct regulatory_request *request)
5977{
5978 struct sk_buff *msg;
5979 void *hdr;
5980
fd2120ca 5981 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5982 if (!msg)
5983 return;
5984
5985 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5986 if (!hdr) {
5987 nlmsg_free(msg);
5988 return;
5989 }
5990
5991 /* Userspace can always count this one always being set */
5992 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5993
5994 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5995 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5996 NL80211_REGDOM_TYPE_WORLD);
5997 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5998 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5999 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
6000 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
6001 request->intersect)
6002 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6003 NL80211_REGDOM_TYPE_INTERSECTION);
6004 else {
6005 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6006 NL80211_REGDOM_TYPE_COUNTRY);
6007 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
6008 }
6009
6010 if (wiphy_idx_valid(request->wiphy_idx))
6011 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
6012
6013 if (genlmsg_end(msg, hdr) < 0) {
6014 nlmsg_free(msg);
6015 return;
6016 }
6017
bc43b28c 6018 rcu_read_lock();
463d0183 6019 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
6020 GFP_ATOMIC);
6021 rcu_read_unlock();
73d54c9e
LR
6022
6023 return;
6024
6025nla_put_failure:
6026 genlmsg_cancel(msg, hdr);
6027 nlmsg_free(msg);
6028}
6029
6039f6d2
JM
6030static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
6031 struct net_device *netdev,
6032 const u8 *buf, size_t len,
e6d6e342 6033 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
6034{
6035 struct sk_buff *msg;
6036 void *hdr;
6037
e6d6e342 6038 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
6039 if (!msg)
6040 return;
6041
6042 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6043 if (!hdr) {
6044 nlmsg_free(msg);
6045 return;
6046 }
6047
6048 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6049 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6050 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6051
6052 if (genlmsg_end(msg, hdr) < 0) {
6053 nlmsg_free(msg);
6054 return;
6055 }
6056
463d0183
JB
6057 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6058 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
6059 return;
6060
6061 nla_put_failure:
6062 genlmsg_cancel(msg, hdr);
6063 nlmsg_free(msg);
6064}
6065
6066void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6067 struct net_device *netdev, const u8 *buf,
6068 size_t len, gfp_t gfp)
6039f6d2
JM
6069{
6070 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6071 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
6072}
6073
6074void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
6075 struct net_device *netdev, const u8 *buf,
e6d6e342 6076 size_t len, gfp_t gfp)
6039f6d2 6077{
e6d6e342
JB
6078 nl80211_send_mlme_event(rdev, netdev, buf, len,
6079 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
6080}
6081
53b46b84 6082void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6083 struct net_device *netdev, const u8 *buf,
6084 size_t len, gfp_t gfp)
6039f6d2
JM
6085{
6086 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6087 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
6088}
6089
53b46b84
JM
6090void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
6091 struct net_device *netdev, const u8 *buf,
e6d6e342 6092 size_t len, gfp_t gfp)
6039f6d2
JM
6093{
6094 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6095 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
6096}
6097
cf4e594e
JM
6098void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
6099 struct net_device *netdev, const u8 *buf,
6100 size_t len, gfp_t gfp)
6101{
6102 nl80211_send_mlme_event(rdev, netdev, buf, len,
6103 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
6104}
6105
6106void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
6107 struct net_device *netdev, const u8 *buf,
6108 size_t len, gfp_t gfp)
6109{
6110 nl80211_send_mlme_event(rdev, netdev, buf, len,
6111 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
6112}
6113
1b06bb40
LR
6114static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
6115 struct net_device *netdev, int cmd,
e6d6e342 6116 const u8 *addr, gfp_t gfp)
1965c853
JM
6117{
6118 struct sk_buff *msg;
6119 void *hdr;
6120
e6d6e342 6121 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
6122 if (!msg)
6123 return;
6124
6125 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6126 if (!hdr) {
6127 nlmsg_free(msg);
6128 return;
6129 }
6130
6131 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6132 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6133 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
6134 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6135
6136 if (genlmsg_end(msg, hdr) < 0) {
6137 nlmsg_free(msg);
6138 return;
6139 }
6140
463d0183
JB
6141 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6142 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
6143 return;
6144
6145 nla_put_failure:
6146 genlmsg_cancel(msg, hdr);
6147 nlmsg_free(msg);
6148}
6149
6150void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6151 struct net_device *netdev, const u8 *addr,
6152 gfp_t gfp)
1965c853
JM
6153{
6154 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 6155 addr, gfp);
1965c853
JM
6156}
6157
6158void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6159 struct net_device *netdev, const u8 *addr,
6160 gfp_t gfp)
1965c853 6161{
e6d6e342
JB
6162 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
6163 addr, gfp);
1965c853
JM
6164}
6165
b23aa676
SO
6166void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
6167 struct net_device *netdev, const u8 *bssid,
6168 const u8 *req_ie, size_t req_ie_len,
6169 const u8 *resp_ie, size_t resp_ie_len,
6170 u16 status, gfp_t gfp)
6171{
6172 struct sk_buff *msg;
6173 void *hdr;
6174
6175 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6176 if (!msg)
6177 return;
6178
6179 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
6180 if (!hdr) {
6181 nlmsg_free(msg);
6182 return;
6183 }
6184
6185 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6186 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6187 if (bssid)
6188 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6189 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
6190 if (req_ie)
6191 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6192 if (resp_ie)
6193 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6194
6195 if (genlmsg_end(msg, hdr) < 0) {
6196 nlmsg_free(msg);
6197 return;
6198 }
6199
463d0183
JB
6200 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6201 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
6202 return;
6203
6204 nla_put_failure:
6205 genlmsg_cancel(msg, hdr);
6206 nlmsg_free(msg);
6207
6208}
6209
6210void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
6211 struct net_device *netdev, const u8 *bssid,
6212 const u8 *req_ie, size_t req_ie_len,
6213 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
6214{
6215 struct sk_buff *msg;
6216 void *hdr;
6217
6218 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6219 if (!msg)
6220 return;
6221
6222 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
6223 if (!hdr) {
6224 nlmsg_free(msg);
6225 return;
6226 }
6227
6228 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6229 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6230 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6231 if (req_ie)
6232 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6233 if (resp_ie)
6234 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6235
6236 if (genlmsg_end(msg, hdr) < 0) {
6237 nlmsg_free(msg);
6238 return;
6239 }
6240
463d0183
JB
6241 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6242 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
6243 return;
6244
6245 nla_put_failure:
6246 genlmsg_cancel(msg, hdr);
6247 nlmsg_free(msg);
6248
6249}
6250
6251void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
6252 struct net_device *netdev, u16 reason,
667503dd 6253 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
6254{
6255 struct sk_buff *msg;
6256 void *hdr;
6257
667503dd 6258 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
6259 if (!msg)
6260 return;
6261
6262 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
6263 if (!hdr) {
6264 nlmsg_free(msg);
6265 return;
6266 }
6267
6268 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6269 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6270 if (from_ap && reason)
6271 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
6272 if (from_ap)
6273 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
6274 if (ie)
6275 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
6276
6277 if (genlmsg_end(msg, hdr) < 0) {
6278 nlmsg_free(msg);
6279 return;
6280 }
6281
463d0183
JB
6282 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6283 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
6284 return;
6285
6286 nla_put_failure:
6287 genlmsg_cancel(msg, hdr);
6288 nlmsg_free(msg);
6289
6290}
6291
04a773ad
JB
6292void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
6293 struct net_device *netdev, const u8 *bssid,
6294 gfp_t gfp)
6295{
6296 struct sk_buff *msg;
6297 void *hdr;
6298
fd2120ca 6299 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
6300 if (!msg)
6301 return;
6302
6303 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
6304 if (!hdr) {
6305 nlmsg_free(msg);
6306 return;
6307 }
6308
6309 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6310 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6311 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6312
6313 if (genlmsg_end(msg, hdr) < 0) {
6314 nlmsg_free(msg);
6315 return;
6316 }
6317
463d0183
JB
6318 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6319 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
6320 return;
6321
6322 nla_put_failure:
6323 genlmsg_cancel(msg, hdr);
6324 nlmsg_free(msg);
6325}
6326
c93b5e71
JC
6327void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
6328 struct net_device *netdev,
6329 const u8 *macaddr, const u8* ie, u8 ie_len,
6330 gfp_t gfp)
6331{
6332 struct sk_buff *msg;
6333 void *hdr;
6334
6335 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6336 if (!msg)
6337 return;
6338
6339 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
6340 if (!hdr) {
6341 nlmsg_free(msg);
6342 return;
6343 }
6344
6345 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6346 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6347 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
6348 if (ie_len && ie)
6349 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
6350
6351 if (genlmsg_end(msg, hdr) < 0) {
6352 nlmsg_free(msg);
6353 return;
6354 }
6355
6356 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6357 nl80211_mlme_mcgrp.id, gfp);
6358 return;
6359
6360 nla_put_failure:
6361 genlmsg_cancel(msg, hdr);
6362 nlmsg_free(msg);
6363}
6364
a3b8b056
JM
6365void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
6366 struct net_device *netdev, const u8 *addr,
6367 enum nl80211_key_type key_type, int key_id,
e6d6e342 6368 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
6369{
6370 struct sk_buff *msg;
6371 void *hdr;
6372
e6d6e342 6373 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
6374 if (!msg)
6375 return;
6376
6377 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
6378 if (!hdr) {
6379 nlmsg_free(msg);
6380 return;
6381 }
6382
6383 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6384 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6385 if (addr)
6386 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6387 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
6388 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
6389 if (tsc)
6390 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
6391
6392 if (genlmsg_end(msg, hdr) < 0) {
6393 nlmsg_free(msg);
6394 return;
6395 }
6396
463d0183
JB
6397 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6398 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
6399 return;
6400
6401 nla_put_failure:
6402 genlmsg_cancel(msg, hdr);
6403 nlmsg_free(msg);
6404}
6405
6bad8766
LR
6406void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
6407 struct ieee80211_channel *channel_before,
6408 struct ieee80211_channel *channel_after)
6409{
6410 struct sk_buff *msg;
6411 void *hdr;
6412 struct nlattr *nl_freq;
6413
fd2120ca 6414 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
6415 if (!msg)
6416 return;
6417
6418 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
6419 if (!hdr) {
6420 nlmsg_free(msg);
6421 return;
6422 }
6423
6424 /*
6425 * Since we are applying the beacon hint to a wiphy we know its
6426 * wiphy_idx is valid
6427 */
6428 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
6429
6430 /* Before */
6431 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
6432 if (!nl_freq)
6433 goto nla_put_failure;
6434 if (nl80211_msg_put_channel(msg, channel_before))
6435 goto nla_put_failure;
6436 nla_nest_end(msg, nl_freq);
6437
6438 /* After */
6439 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
6440 if (!nl_freq)
6441 goto nla_put_failure;
6442 if (nl80211_msg_put_channel(msg, channel_after))
6443 goto nla_put_failure;
6444 nla_nest_end(msg, nl_freq);
6445
6446 if (genlmsg_end(msg, hdr) < 0) {
6447 nlmsg_free(msg);
6448 return;
6449 }
6450
463d0183
JB
6451 rcu_read_lock();
6452 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6453 GFP_ATOMIC);
6454 rcu_read_unlock();
6bad8766
LR
6455
6456 return;
6457
6458nla_put_failure:
6459 genlmsg_cancel(msg, hdr);
6460 nlmsg_free(msg);
6461}
6462
9588bbd5
JM
6463static void nl80211_send_remain_on_chan_event(
6464 int cmd, struct cfg80211_registered_device *rdev,
6465 struct net_device *netdev, u64 cookie,
6466 struct ieee80211_channel *chan,
6467 enum nl80211_channel_type channel_type,
6468 unsigned int duration, gfp_t gfp)
6469{
6470 struct sk_buff *msg;
6471 void *hdr;
6472
6473 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6474 if (!msg)
6475 return;
6476
6477 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6478 if (!hdr) {
6479 nlmsg_free(msg);
6480 return;
6481 }
6482
6483 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6484 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6485 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
6486 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
6487 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6488
6489 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6490 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6491
6492 if (genlmsg_end(msg, hdr) < 0) {
6493 nlmsg_free(msg);
6494 return;
6495 }
6496
6497 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6498 nl80211_mlme_mcgrp.id, gfp);
6499 return;
6500
6501 nla_put_failure:
6502 genlmsg_cancel(msg, hdr);
6503 nlmsg_free(msg);
6504}
6505
6506void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6507 struct net_device *netdev, u64 cookie,
6508 struct ieee80211_channel *chan,
6509 enum nl80211_channel_type channel_type,
6510 unsigned int duration, gfp_t gfp)
6511{
6512 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6513 rdev, netdev, cookie, chan,
6514 channel_type, duration, gfp);
6515}
6516
6517void nl80211_send_remain_on_channel_cancel(
6518 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6519 u64 cookie, struct ieee80211_channel *chan,
6520 enum nl80211_channel_type channel_type, gfp_t gfp)
6521{
6522 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6523 rdev, netdev, cookie, chan,
6524 channel_type, 0, gfp);
6525}
6526
98b62183
JB
6527void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6528 struct net_device *dev, const u8 *mac_addr,
6529 struct station_info *sinfo, gfp_t gfp)
6530{
6531 struct sk_buff *msg;
6532
6533 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6534 if (!msg)
6535 return;
6536
6537 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6538 nlmsg_free(msg);
6539 return;
6540 }
6541
6542 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6543 nl80211_mlme_mcgrp.id, gfp);
6544}
6545
ec15e68b
JM
6546void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
6547 struct net_device *dev, const u8 *mac_addr,
6548 gfp_t gfp)
6549{
6550 struct sk_buff *msg;
6551 void *hdr;
6552
6553 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6554 if (!msg)
6555 return;
6556
6557 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
6558 if (!hdr) {
6559 nlmsg_free(msg);
6560 return;
6561 }
6562
6563 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
6564 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
6565
6566 if (genlmsg_end(msg, hdr) < 0) {
6567 nlmsg_free(msg);
6568 return;
6569 }
6570
6571 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6572 nl80211_mlme_mcgrp.id, gfp);
6573 return;
6574
6575 nla_put_failure:
6576 genlmsg_cancel(msg, hdr);
6577 nlmsg_free(msg);
6578}
6579
2e161f78
JB
6580int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6581 struct net_device *netdev, u32 nlpid,
6582 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
6583{
6584 struct sk_buff *msg;
6585 void *hdr;
6586 int err;
6587
6588 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6589 if (!msg)
6590 return -ENOMEM;
6591
2e161f78 6592 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
6593 if (!hdr) {
6594 nlmsg_free(msg);
6595 return -ENOMEM;
6596 }
6597
6598 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6599 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6600 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6601 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6602
6603 err = genlmsg_end(msg, hdr);
6604 if (err < 0) {
6605 nlmsg_free(msg);
6606 return err;
6607 }
6608
6609 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6610 if (err < 0)
6611 return err;
6612 return 0;
6613
6614 nla_put_failure:
6615 genlmsg_cancel(msg, hdr);
6616 nlmsg_free(msg);
6617 return -ENOBUFS;
6618}
6619
2e161f78
JB
6620void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6621 struct net_device *netdev, u64 cookie,
6622 const u8 *buf, size_t len, bool ack,
6623 gfp_t gfp)
026331c4
JM
6624{
6625 struct sk_buff *msg;
6626 void *hdr;
6627
6628 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6629 if (!msg)
6630 return;
6631
2e161f78 6632 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6633 if (!hdr) {
6634 nlmsg_free(msg);
6635 return;
6636 }
6637
6638 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6639 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6640 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6641 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6642 if (ack)
6643 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6644
6645 if (genlmsg_end(msg, hdr) < 0) {
6646 nlmsg_free(msg);
6647 return;
6648 }
6649
6650 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6651 return;
6652
6653 nla_put_failure:
6654 genlmsg_cancel(msg, hdr);
6655 nlmsg_free(msg);
6656}
6657
d6dc1a38
JO
6658void
6659nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6660 struct net_device *netdev,
6661 enum nl80211_cqm_rssi_threshold_event rssi_event,
6662 gfp_t gfp)
6663{
6664 struct sk_buff *msg;
6665 struct nlattr *pinfoattr;
6666 void *hdr;
6667
6668 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6669 if (!msg)
6670 return;
6671
6672 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6673 if (!hdr) {
6674 nlmsg_free(msg);
6675 return;
6676 }
6677
6678 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6679 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6680
6681 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6682 if (!pinfoattr)
6683 goto nla_put_failure;
6684
6685 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6686 rssi_event);
6687
6688 nla_nest_end(msg, pinfoattr);
6689
6690 if (genlmsg_end(msg, hdr) < 0) {
6691 nlmsg_free(msg);
6692 return;
6693 }
6694
6695 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6696 nl80211_mlme_mcgrp.id, gfp);
6697 return;
6698
6699 nla_put_failure:
6700 genlmsg_cancel(msg, hdr);
6701 nlmsg_free(msg);
6702}
6703
c063dbf5
JB
6704void
6705nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6706 struct net_device *netdev, const u8 *peer,
6707 u32 num_packets, gfp_t gfp)
6708{
6709 struct sk_buff *msg;
6710 struct nlattr *pinfoattr;
6711 void *hdr;
6712
6713 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6714 if (!msg)
6715 return;
6716
6717 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6718 if (!hdr) {
6719 nlmsg_free(msg);
6720 return;
6721 }
6722
6723 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6724 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6725 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6726
6727 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6728 if (!pinfoattr)
6729 goto nla_put_failure;
6730
6731 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6732
6733 nla_nest_end(msg, pinfoattr);
6734
6735 if (genlmsg_end(msg, hdr) < 0) {
6736 nlmsg_free(msg);
6737 return;
6738 }
6739
6740 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6741 nl80211_mlme_mcgrp.id, gfp);
6742 return;
6743
6744 nla_put_failure:
6745 genlmsg_cancel(msg, hdr);
6746 nlmsg_free(msg);
6747}
6748
026331c4
JM
6749static int nl80211_netlink_notify(struct notifier_block * nb,
6750 unsigned long state,
6751 void *_notify)
6752{
6753 struct netlink_notify *notify = _notify;
6754 struct cfg80211_registered_device *rdev;
6755 struct wireless_dev *wdev;
6756
6757 if (state != NETLINK_URELEASE)
6758 return NOTIFY_DONE;
6759
6760 rcu_read_lock();
6761
6762 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6763 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6764 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6765
6766 rcu_read_unlock();
6767
6768 return NOTIFY_DONE;
6769}
6770
6771static struct notifier_block nl80211_netlink_notifier = {
6772 .notifier_call = nl80211_netlink_notify,
6773};
6774
55682965
JB
6775/* initialisation/exit functions */
6776
6777int nl80211_init(void)
6778{
0d63cbb5 6779 int err;
55682965 6780
0d63cbb5
MM
6781 err = genl_register_family_with_ops(&nl80211_fam,
6782 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6783 if (err)
6784 return err;
6785
55682965
JB
6786 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6787 if (err)
6788 goto err_out;
6789
2a519311
JB
6790 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6791 if (err)
6792 goto err_out;
6793
73d54c9e
LR
6794 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6795 if (err)
6796 goto err_out;
6797
6039f6d2
JM
6798 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6799 if (err)
6800 goto err_out;
6801
aff89a9b
JB
6802#ifdef CONFIG_NL80211_TESTMODE
6803 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6804 if (err)
6805 goto err_out;
6806#endif
6807
026331c4
JM
6808 err = netlink_register_notifier(&nl80211_netlink_notifier);
6809 if (err)
6810 goto err_out;
6811
55682965
JB
6812 return 0;
6813 err_out:
6814 genl_unregister_family(&nl80211_fam);
6815 return err;
6816}
6817
6818void nl80211_exit(void)
6819{
026331c4 6820 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6821 genl_unregister_family(&nl80211_fam);
6822}