]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/blame - net/wireless/nl80211.c
mac80211: improve default WMM parameter setting
[mirror_ubuntu-focal-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
2a0e047e 22#include <net/inet_connection_sock.h>
55682965
JB
23#include "core.h"
24#include "nl80211.h"
b2e1b302 25#include "reg.h"
e35e4d28 26#include "rdev-ops.h"
55682965 27
5fb628e9
JM
28static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
29 struct genl_info *info,
30 struct cfg80211_crypto_settings *settings,
31 int cipher_limit);
32
4c476991
JB
33static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
34 struct genl_info *info);
35static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
36 struct genl_info *info);
37
55682965
JB
38/* the netlink family */
39static struct genl_family nl80211_fam = {
fb4e1568
MH
40 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
41 .name = NL80211_GENL_NAME, /* have users key off the name instead */
42 .hdrsize = 0, /* no private header */
43 .version = 1, /* no particular meaning now */
55682965 44 .maxattr = NL80211_ATTR_MAX,
463d0183 45 .netnsok = true,
4c476991
JB
46 .pre_doit = nl80211_pre_doit,
47 .post_doit = nl80211_post_doit,
55682965
JB
48};
49
89a54e48
JB
50/* returns ERR_PTR values */
51static struct wireless_dev *
52__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 53{
89a54e48
JB
54 struct cfg80211_registered_device *rdev;
55 struct wireless_dev *result = NULL;
56 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
57 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
58 u64 wdev_id;
59 int wiphy_idx = -1;
60 int ifidx = -1;
55682965 61
5fe231e8 62 ASSERT_RTNL();
55682965 63
89a54e48
JB
64 if (!have_ifidx && !have_wdev_id)
65 return ERR_PTR(-EINVAL);
55682965 66
89a54e48
JB
67 if (have_ifidx)
68 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
69 if (have_wdev_id) {
70 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
71 wiphy_idx = wdev_id >> 32;
55682965
JB
72 }
73
89a54e48
JB
74 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
75 struct wireless_dev *wdev;
76
77 if (wiphy_net(&rdev->wiphy) != netns)
78 continue;
79
80 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
81 continue;
82
89a54e48
JB
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
89a54e48
JB
94
95 if (result)
96 break;
97 }
98
99 if (result)
100 return result;
101 return ERR_PTR(-ENODEV);
55682965
JB
102}
103
a9455408 104static struct cfg80211_registered_device *
878d9ec7 105__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 106{
7fee4778
JB
107 struct cfg80211_registered_device *rdev = NULL, *tmp;
108 struct net_device *netdev;
a9455408 109
5fe231e8 110 ASSERT_RTNL();
a9455408 111
878d9ec7 112 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
113 !attrs[NL80211_ATTR_IFINDEX] &&
114 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
115 return ERR_PTR(-EINVAL);
116
878d9ec7 117 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 118 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 119 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 120
89a54e48
JB
121 if (attrs[NL80211_ATTR_WDEV]) {
122 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
123 struct wireless_dev *wdev;
124 bool found = false;
125
126 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
127 if (tmp) {
128 /* make sure wdev exists */
89a54e48
JB
129 list_for_each_entry(wdev, &tmp->wdev_list, list) {
130 if (wdev->identifier != (u32)wdev_id)
131 continue;
132 found = true;
133 break;
134 }
89a54e48
JB
135
136 if (!found)
137 tmp = NULL;
138
139 if (rdev && tmp != rdev)
140 return ERR_PTR(-EINVAL);
141 rdev = tmp;
142 }
143 }
144
878d9ec7
JB
145 if (attrs[NL80211_ATTR_IFINDEX]) {
146 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 147 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
148 if (netdev) {
149 if (netdev->ieee80211_ptr)
150 tmp = wiphy_to_dev(
151 netdev->ieee80211_ptr->wiphy);
152 else
153 tmp = NULL;
154
155 dev_put(netdev);
156
157 /* not wireless device -- return error */
158 if (!tmp)
159 return ERR_PTR(-EINVAL);
160
161 /* mismatch -- return error */
162 if (rdev && tmp != rdev)
163 return ERR_PTR(-EINVAL);
164
165 rdev = tmp;
a9455408 166 }
a9455408 167 }
a9455408 168
4f7eff10
JB
169 if (!rdev)
170 return ERR_PTR(-ENODEV);
a9455408 171
4f7eff10
JB
172 if (netns != wiphy_net(&rdev->wiphy))
173 return ERR_PTR(-ENODEV);
174
175 return rdev;
a9455408
JB
176}
177
178/*
179 * This function returns a pointer to the driver
180 * that the genl_info item that is passed refers to.
a9455408
JB
181 *
182 * The result of this can be a PTR_ERR and hence must
183 * be checked with IS_ERR() for errors.
184 */
185static struct cfg80211_registered_device *
4f7eff10 186cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 187{
5fe231e8 188 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
189}
190
55682965 191/* policy for the attributes */
b54452b0 192static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
193 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
194 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 195 .len = 20-1 },
31888487 196 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 197
72bdcf34 198 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 199 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
200 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
201 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
202 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
203
b9a5f8ca
JM
204 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
205 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
206 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
207 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 208 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
209
210 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
211 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
212 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 213
e007b857
EP
214 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
215 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 216
b9454e83 217 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
218 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
219 .len = WLAN_MAX_KEY_LEN },
220 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
221 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
222 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 223 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 224 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
225
226 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
227 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
228 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
229 .len = IEEE80211_MAX_DATA_LEN },
230 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
231 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
232 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
233 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
234 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
235 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
236 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 237 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 238 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 239 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 240 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 241 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 242 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 243
b2e1b302
LR
244 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
245 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
246
9f1ba906
JM
247 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
248 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
249 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
250 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
251 .len = NL80211_MAX_SUPP_RATES },
50b12f59 252 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 253
24bdd9f4 254 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 255 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 256
6c739419 257 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
258
259 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
260 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
261 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
262 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
263 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
264
265 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
266 .len = IEEE80211_MAX_SSID_LEN },
267 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
268 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 269 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 270 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 271 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
272 [NL80211_ATTR_STA_FLAGS2] = {
273 .len = sizeof(struct nl80211_sta_flag_update),
274 },
3f77316c 275 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
276 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
277 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
278 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
279 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
280 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 281 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 282 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
283 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
284 .len = WLAN_PMKID_LEN },
9588bbd5
JM
285 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
286 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 287 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
288 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
289 .len = IEEE80211_MAX_DATA_LEN },
290 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 291 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 292 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 293 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 294 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
295 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
296 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 297 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
298 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
299 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 300 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 301 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 302 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 303 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 304 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 305 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 306 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 307 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 308 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
309 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
310 .len = IEEE80211_MAX_DATA_LEN },
311 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
312 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 313 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 314 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 315 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
316 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
317 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
318 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
319 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
320 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 321 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
322 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
323 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 324 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
325 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
326 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
327 .len = NL80211_HT_CAPABILITY_LEN
328 },
1d9d9213 329 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 330 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 331 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 332 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 333 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 334 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 335 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 336 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
337 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
338 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
339 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
340 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
341 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
342 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 343 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
344 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
345 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
346 .len = NL80211_VHT_CAPABILITY_LEN,
347 },
355199e0
JM
348 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
349 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
350 .len = IEEE80211_MAX_DATA_LEN },
5e4b6f56 351 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 },
16ef1fe2
SW
352 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
353 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
354 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
355 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_U16 },
356 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_U16 },
55682965
JB
357};
358
e31b8213 359/* policy for the key attributes */
b54452b0 360static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 361 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
362 [NL80211_KEY_IDX] = { .type = NLA_U8 },
363 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 364 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
365 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
366 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 367 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
368 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
369};
370
371/* policy for the key default flags */
372static const struct nla_policy
373nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
374 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
375 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
376};
377
ff1b6e69
JB
378/* policy for WoWLAN attributes */
379static const struct nla_policy
380nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
381 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
382 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
383 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
384 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
385 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
386 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
387 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
388 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e
JB
389 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
390};
391
392static const struct nla_policy
393nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
394 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
395 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
396 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
397 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
398 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
399 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
400 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
401 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
402 },
403 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
404 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
405 },
406 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
407 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
408 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69
JB
409};
410
be29b99a
AK
411/* policy for coalesce rule attributes */
412static const struct nla_policy
413nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
414 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
415 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 },
416 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
417};
418
e5497d76
JB
419/* policy for GTK rekey offload attributes */
420static const struct nla_policy
421nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
422 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
423 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
424 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
425};
426
a1f1c21c
LC
427static const struct nla_policy
428nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 429 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 430 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 431 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
432};
433
97990a06
JB
434static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
435 struct netlink_callback *cb,
436 struct cfg80211_registered_device **rdev,
437 struct wireless_dev **wdev)
a043897a 438{
97990a06 439 int err;
a043897a 440
97990a06 441 rtnl_lock();
a043897a 442
97990a06
JB
443 if (!cb->args[0]) {
444 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
445 nl80211_fam.attrbuf, nl80211_fam.maxattr,
446 nl80211_policy);
447 if (err)
448 goto out_unlock;
67748893 449
97990a06
JB
450 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
451 nl80211_fam.attrbuf);
452 if (IS_ERR(*wdev)) {
453 err = PTR_ERR(*wdev);
454 goto out_unlock;
455 }
456 *rdev = wiphy_to_dev((*wdev)->wiphy);
c319d50b
JB
457 /* 0 is the first index - add 1 to parse only once */
458 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
459 cb->args[1] = (*wdev)->identifier;
460 } else {
c319d50b
JB
461 /* subtract the 1 again here */
462 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 463 struct wireless_dev *tmp;
67748893 464
97990a06
JB
465 if (!wiphy) {
466 err = -ENODEV;
467 goto out_unlock;
468 }
469 *rdev = wiphy_to_dev(wiphy);
470 *wdev = NULL;
67748893 471
97990a06
JB
472 list_for_each_entry(tmp, &(*rdev)->wdev_list, list) {
473 if (tmp->identifier == cb->args[1]) {
474 *wdev = tmp;
475 break;
476 }
477 }
67748893 478
97990a06
JB
479 if (!*wdev) {
480 err = -ENODEV;
481 goto out_unlock;
482 }
67748893
JB
483 }
484
67748893 485 return 0;
97990a06 486 out_unlock:
67748893
JB
487 rtnl_unlock();
488 return err;
489}
490
97990a06 491static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev)
67748893 492{
67748893
JB
493 rtnl_unlock();
494}
495
f4a11bb0
JB
496/* IE validation */
497static bool is_valid_ie_attr(const struct nlattr *attr)
498{
499 const u8 *pos;
500 int len;
501
502 if (!attr)
503 return true;
504
505 pos = nla_data(attr);
506 len = nla_len(attr);
507
508 while (len) {
509 u8 elemlen;
510
511 if (len < 2)
512 return false;
513 len -= 2;
514
515 elemlen = pos[1];
516 if (elemlen > len)
517 return false;
518
519 len -= elemlen;
520 pos += 2 + elemlen;
521 }
522
523 return true;
524}
525
55682965 526/* message building helper */
15e47304 527static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
528 int flags, u8 cmd)
529{
530 /* since there is no private header just add the generic one */
15e47304 531 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
532}
533
5dab3b8a 534static int nl80211_msg_put_channel(struct sk_buff *msg,
cdc89b97
JB
535 struct ieee80211_channel *chan,
536 bool large)
5dab3b8a 537{
9360ffd1
DM
538 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
539 chan->center_freq))
540 goto nla_put_failure;
5dab3b8a 541
9360ffd1
DM
542 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
543 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
544 goto nla_put_failure;
545 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
546 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
547 goto nla_put_failure;
548 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
549 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
550 goto nla_put_failure;
cdc89b97
JB
551 if (chan->flags & IEEE80211_CHAN_RADAR) {
552 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
553 goto nla_put_failure;
554 if (large) {
555 u32 time;
556
557 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
558
559 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
560 chan->dfs_state))
561 goto nla_put_failure;
562 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
563 time))
564 goto nla_put_failure;
565 }
566 }
5dab3b8a 567
fe1abafd
JB
568 if (large) {
569 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
570 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
571 goto nla_put_failure;
572 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
573 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
574 goto nla_put_failure;
575 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
576 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
577 goto nla_put_failure;
578 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
579 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
580 goto nla_put_failure;
581 }
582
9360ffd1
DM
583 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
584 DBM_TO_MBM(chan->max_power)))
585 goto nla_put_failure;
5dab3b8a
LR
586
587 return 0;
588
589 nla_put_failure:
590 return -ENOBUFS;
591}
592
55682965
JB
593/* netlink command implementations */
594
b9454e83
JB
595struct key_parse {
596 struct key_params p;
597 int idx;
e31b8213 598 int type;
b9454e83 599 bool def, defmgmt;
dbd2fd65 600 bool def_uni, def_multi;
b9454e83
JB
601};
602
603static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
604{
605 struct nlattr *tb[NL80211_KEY_MAX + 1];
606 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
607 nl80211_key_policy);
608 if (err)
609 return err;
610
611 k->def = !!tb[NL80211_KEY_DEFAULT];
612 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
613
dbd2fd65
JB
614 if (k->def) {
615 k->def_uni = true;
616 k->def_multi = true;
617 }
618 if (k->defmgmt)
619 k->def_multi = true;
620
b9454e83
JB
621 if (tb[NL80211_KEY_IDX])
622 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
623
624 if (tb[NL80211_KEY_DATA]) {
625 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
626 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
627 }
628
629 if (tb[NL80211_KEY_SEQ]) {
630 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
631 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
632 }
633
634 if (tb[NL80211_KEY_CIPHER])
635 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
636
e31b8213
JB
637 if (tb[NL80211_KEY_TYPE]) {
638 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
639 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
640 return -EINVAL;
641 }
642
dbd2fd65
JB
643 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
644 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
645 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
646 tb[NL80211_KEY_DEFAULT_TYPES],
647 nl80211_key_default_policy);
dbd2fd65
JB
648 if (err)
649 return err;
650
651 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
652 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
653 }
654
b9454e83
JB
655 return 0;
656}
657
658static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
659{
660 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
661 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
662 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
663 }
664
665 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
666 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
667 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
668 }
669
670 if (info->attrs[NL80211_ATTR_KEY_IDX])
671 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
672
673 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
674 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
675
676 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
677 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
678
dbd2fd65
JB
679 if (k->def) {
680 k->def_uni = true;
681 k->def_multi = true;
682 }
683 if (k->defmgmt)
684 k->def_multi = true;
685
e31b8213
JB
686 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
687 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
688 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
689 return -EINVAL;
690 }
691
dbd2fd65
JB
692 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
693 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
694 int err = nla_parse_nested(
695 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
696 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
697 nl80211_key_default_policy);
698 if (err)
699 return err;
700
701 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
702 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
703 }
704
b9454e83
JB
705 return 0;
706}
707
708static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
709{
710 int err;
711
712 memset(k, 0, sizeof(*k));
713 k->idx = -1;
e31b8213 714 k->type = -1;
b9454e83
JB
715
716 if (info->attrs[NL80211_ATTR_KEY])
717 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
718 else
719 err = nl80211_parse_key_old(info, k);
720
721 if (err)
722 return err;
723
724 if (k->def && k->defmgmt)
725 return -EINVAL;
726
dbd2fd65
JB
727 if (k->defmgmt) {
728 if (k->def_uni || !k->def_multi)
729 return -EINVAL;
730 }
731
b9454e83
JB
732 if (k->idx != -1) {
733 if (k->defmgmt) {
734 if (k->idx < 4 || k->idx > 5)
735 return -EINVAL;
736 } else if (k->def) {
737 if (k->idx < 0 || k->idx > 3)
738 return -EINVAL;
739 } else {
740 if (k->idx < 0 || k->idx > 5)
741 return -EINVAL;
742 }
743 }
744
745 return 0;
746}
747
fffd0934
JB
748static struct cfg80211_cached_keys *
749nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 750 struct nlattr *keys, bool *no_ht)
fffd0934
JB
751{
752 struct key_parse parse;
753 struct nlattr *key;
754 struct cfg80211_cached_keys *result;
755 int rem, err, def = 0;
756
757 result = kzalloc(sizeof(*result), GFP_KERNEL);
758 if (!result)
759 return ERR_PTR(-ENOMEM);
760
761 result->def = -1;
762 result->defmgmt = -1;
763
764 nla_for_each_nested(key, keys, rem) {
765 memset(&parse, 0, sizeof(parse));
766 parse.idx = -1;
767
768 err = nl80211_parse_key_new(key, &parse);
769 if (err)
770 goto error;
771 err = -EINVAL;
772 if (!parse.p.key)
773 goto error;
774 if (parse.idx < 0 || parse.idx > 4)
775 goto error;
776 if (parse.def) {
777 if (def)
778 goto error;
779 def = 1;
780 result->def = parse.idx;
dbd2fd65
JB
781 if (!parse.def_uni || !parse.def_multi)
782 goto error;
fffd0934
JB
783 } else if (parse.defmgmt)
784 goto error;
785 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 786 parse.idx, false, NULL);
fffd0934
JB
787 if (err)
788 goto error;
789 result->params[parse.idx].cipher = parse.p.cipher;
790 result->params[parse.idx].key_len = parse.p.key_len;
791 result->params[parse.idx].key = result->data[parse.idx];
792 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
793
794 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
795 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
796 if (no_ht)
797 *no_ht = true;
798 }
fffd0934
JB
799 }
800
801 return result;
802 error:
803 kfree(result);
804 return ERR_PTR(err);
805}
806
807static int nl80211_key_allowed(struct wireless_dev *wdev)
808{
809 ASSERT_WDEV_LOCK(wdev);
810
fffd0934
JB
811 switch (wdev->iftype) {
812 case NL80211_IFTYPE_AP:
813 case NL80211_IFTYPE_AP_VLAN:
074ac8df 814 case NL80211_IFTYPE_P2P_GO:
ff973af7 815 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
816 break;
817 case NL80211_IFTYPE_ADHOC:
fffd0934 818 case NL80211_IFTYPE_STATION:
074ac8df 819 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 820 if (!wdev->current_bss)
fffd0934
JB
821 return -ENOLINK;
822 break;
823 default:
824 return -EINVAL;
825 }
826
827 return 0;
828}
829
7527a782
JB
830static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
831{
832 struct nlattr *nl_modes = nla_nest_start(msg, attr);
833 int i;
834
835 if (!nl_modes)
836 goto nla_put_failure;
837
838 i = 0;
839 while (ifmodes) {
9360ffd1
DM
840 if ((ifmodes & 1) && nla_put_flag(msg, i))
841 goto nla_put_failure;
7527a782
JB
842 ifmodes >>= 1;
843 i++;
844 }
845
846 nla_nest_end(msg, nl_modes);
847 return 0;
848
849nla_put_failure:
850 return -ENOBUFS;
851}
852
853static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
854 struct sk_buff *msg,
855 bool large)
7527a782
JB
856{
857 struct nlattr *nl_combis;
858 int i, j;
859
860 nl_combis = nla_nest_start(msg,
861 NL80211_ATTR_INTERFACE_COMBINATIONS);
862 if (!nl_combis)
863 goto nla_put_failure;
864
865 for (i = 0; i < wiphy->n_iface_combinations; i++) {
866 const struct ieee80211_iface_combination *c;
867 struct nlattr *nl_combi, *nl_limits;
868
869 c = &wiphy->iface_combinations[i];
870
871 nl_combi = nla_nest_start(msg, i + 1);
872 if (!nl_combi)
873 goto nla_put_failure;
874
875 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
876 if (!nl_limits)
877 goto nla_put_failure;
878
879 for (j = 0; j < c->n_limits; j++) {
880 struct nlattr *nl_limit;
881
882 nl_limit = nla_nest_start(msg, j + 1);
883 if (!nl_limit)
884 goto nla_put_failure;
9360ffd1
DM
885 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
886 c->limits[j].max))
887 goto nla_put_failure;
7527a782
JB
888 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
889 c->limits[j].types))
890 goto nla_put_failure;
891 nla_nest_end(msg, nl_limit);
892 }
893
894 nla_nest_end(msg, nl_limits);
895
9360ffd1
DM
896 if (c->beacon_int_infra_match &&
897 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
898 goto nla_put_failure;
899 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
900 c->num_different_channels) ||
901 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
902 c->max_interfaces))
903 goto nla_put_failure;
cdc89b97
JB
904 if (large &&
905 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
906 c->radar_detect_widths))
907 goto nla_put_failure;
7527a782
JB
908
909 nla_nest_end(msg, nl_combi);
910 }
911
912 nla_nest_end(msg, nl_combis);
913
914 return 0;
915nla_put_failure:
916 return -ENOBUFS;
917}
918
3713b4e3 919#ifdef CONFIG_PM
b56cf720
JB
920static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
921 struct sk_buff *msg)
922{
964dc9e2 923 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
924 struct nlattr *nl_tcp;
925
926 if (!tcp)
927 return 0;
928
929 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
930 if (!nl_tcp)
931 return -ENOBUFS;
932
933 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
934 tcp->data_payload_max))
935 return -ENOBUFS;
936
937 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
938 tcp->data_payload_max))
939 return -ENOBUFS;
940
941 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
942 return -ENOBUFS;
943
944 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
945 sizeof(*tcp->tok), tcp->tok))
946 return -ENOBUFS;
947
948 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
949 tcp->data_interval_max))
950 return -ENOBUFS;
951
952 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
953 tcp->wake_payload_max))
954 return -ENOBUFS;
955
956 nla_nest_end(msg, nl_tcp);
957 return 0;
958}
959
3713b4e3 960static int nl80211_send_wowlan(struct sk_buff *msg,
b56cf720
JB
961 struct cfg80211_registered_device *dev,
962 bool large)
55682965 963{
3713b4e3 964 struct nlattr *nl_wowlan;
55682965 965
964dc9e2 966 if (!dev->wiphy.wowlan)
3713b4e3 967 return 0;
55682965 968
3713b4e3
JB
969 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
970 if (!nl_wowlan)
971 return -ENOBUFS;
9360ffd1 972
964dc9e2 973 if (((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 974 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
964dc9e2 975 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 976 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
964dc9e2 977 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 978 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
964dc9e2 979 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 980 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
964dc9e2 981 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 982 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
964dc9e2 983 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 984 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
964dc9e2 985 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 986 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
964dc9e2 987 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
988 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
989 return -ENOBUFS;
9360ffd1 990
964dc9e2 991 if (dev->wiphy.wowlan->n_patterns) {
50ac6607 992 struct nl80211_pattern_support pat = {
964dc9e2
JB
993 .max_patterns = dev->wiphy.wowlan->n_patterns,
994 .min_pattern_len = dev->wiphy.wowlan->pattern_min_len,
995 .max_pattern_len = dev->wiphy.wowlan->pattern_max_len,
996 .max_pkt_offset = dev->wiphy.wowlan->max_pkt_offset,
3713b4e3 997 };
9360ffd1 998
3713b4e3
JB
999 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1000 sizeof(pat), &pat))
1001 return -ENOBUFS;
1002 }
9360ffd1 1003
b56cf720
JB
1004 if (large && nl80211_send_wowlan_tcp_caps(dev, msg))
1005 return -ENOBUFS;
1006
3713b4e3 1007 nla_nest_end(msg, nl_wowlan);
9360ffd1 1008
3713b4e3
JB
1009 return 0;
1010}
1011#endif
9360ffd1 1012
be29b99a
AK
1013static int nl80211_send_coalesce(struct sk_buff *msg,
1014 struct cfg80211_registered_device *dev)
1015{
1016 struct nl80211_coalesce_rule_support rule;
1017
1018 if (!dev->wiphy.coalesce)
1019 return 0;
1020
1021 rule.max_rules = dev->wiphy.coalesce->n_rules;
1022 rule.max_delay = dev->wiphy.coalesce->max_delay;
1023 rule.pat.max_patterns = dev->wiphy.coalesce->n_patterns;
1024 rule.pat.min_pattern_len = dev->wiphy.coalesce->pattern_min_len;
1025 rule.pat.max_pattern_len = dev->wiphy.coalesce->pattern_max_len;
1026 rule.pat.max_pkt_offset = dev->wiphy.coalesce->max_pkt_offset;
1027
1028 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1029 return -ENOBUFS;
1030
1031 return 0;
1032}
1033
3713b4e3
JB
1034static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1035 struct ieee80211_supported_band *sband)
1036{
1037 struct nlattr *nl_rates, *nl_rate;
1038 struct ieee80211_rate *rate;
1039 int i;
87bbbe22 1040
3713b4e3
JB
1041 /* add HT info */
1042 if (sband->ht_cap.ht_supported &&
1043 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1044 sizeof(sband->ht_cap.mcs),
1045 &sband->ht_cap.mcs) ||
1046 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1047 sband->ht_cap.cap) ||
1048 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1049 sband->ht_cap.ampdu_factor) ||
1050 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1051 sband->ht_cap.ampdu_density)))
1052 return -ENOBUFS;
afe0cbf8 1053
3713b4e3
JB
1054 /* add VHT info */
1055 if (sband->vht_cap.vht_supported &&
1056 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1057 sizeof(sband->vht_cap.vht_mcs),
1058 &sband->vht_cap.vht_mcs) ||
1059 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1060 sband->vht_cap.cap)))
1061 return -ENOBUFS;
f59ac048 1062
3713b4e3
JB
1063 /* add bitrates */
1064 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1065 if (!nl_rates)
1066 return -ENOBUFS;
ee688b00 1067
3713b4e3
JB
1068 for (i = 0; i < sband->n_bitrates; i++) {
1069 nl_rate = nla_nest_start(msg, i);
1070 if (!nl_rate)
1071 return -ENOBUFS;
ee688b00 1072
3713b4e3
JB
1073 rate = &sband->bitrates[i];
1074 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1075 rate->bitrate))
1076 return -ENOBUFS;
1077 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1078 nla_put_flag(msg,
1079 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1080 return -ENOBUFS;
ee688b00 1081
3713b4e3
JB
1082 nla_nest_end(msg, nl_rate);
1083 }
d51626df 1084
3713b4e3 1085 nla_nest_end(msg, nl_rates);
bf0c111e 1086
3713b4e3
JB
1087 return 0;
1088}
ee688b00 1089
3713b4e3
JB
1090static int
1091nl80211_send_mgmt_stypes(struct sk_buff *msg,
1092 const struct ieee80211_txrx_stypes *mgmt_stypes)
1093{
1094 u16 stypes;
1095 struct nlattr *nl_ftypes, *nl_ifs;
1096 enum nl80211_iftype ift;
1097 int i;
ee688b00 1098
3713b4e3
JB
1099 if (!mgmt_stypes)
1100 return 0;
5dab3b8a 1101
3713b4e3
JB
1102 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1103 if (!nl_ifs)
1104 return -ENOBUFS;
e2f367f2 1105
3713b4e3
JB
1106 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1107 nl_ftypes = nla_nest_start(msg, ift);
1108 if (!nl_ftypes)
1109 return -ENOBUFS;
1110 i = 0;
1111 stypes = mgmt_stypes[ift].tx;
1112 while (stypes) {
1113 if ((stypes & 1) &&
1114 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1115 (i << 4) | IEEE80211_FTYPE_MGMT))
1116 return -ENOBUFS;
1117 stypes >>= 1;
1118 i++;
ee688b00 1119 }
3713b4e3
JB
1120 nla_nest_end(msg, nl_ftypes);
1121 }
ee688b00 1122
3713b4e3 1123 nla_nest_end(msg, nl_ifs);
ee688b00 1124
3713b4e3
JB
1125 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1126 if (!nl_ifs)
1127 return -ENOBUFS;
ee688b00 1128
3713b4e3
JB
1129 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1130 nl_ftypes = nla_nest_start(msg, ift);
1131 if (!nl_ftypes)
1132 return -ENOBUFS;
1133 i = 0;
1134 stypes = mgmt_stypes[ift].rx;
1135 while (stypes) {
1136 if ((stypes & 1) &&
1137 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1138 (i << 4) | IEEE80211_FTYPE_MGMT))
1139 return -ENOBUFS;
1140 stypes >>= 1;
1141 i++;
1142 }
1143 nla_nest_end(msg, nl_ftypes);
1144 }
1145 nla_nest_end(msg, nl_ifs);
ee688b00 1146
3713b4e3
JB
1147 return 0;
1148}
ee688b00 1149
86e8cf98
JB
1150struct nl80211_dump_wiphy_state {
1151 s64 filter_wiphy;
1152 long start;
1153 long split_start, band_start, chan_start;
1154 bool split;
1155};
1156
3713b4e3
JB
1157static int nl80211_send_wiphy(struct cfg80211_registered_device *dev,
1158 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 1159 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
1160{
1161 void *hdr;
1162 struct nlattr *nl_bands, *nl_band;
1163 struct nlattr *nl_freqs, *nl_freq;
1164 struct nlattr *nl_cmds;
1165 enum ieee80211_band band;
1166 struct ieee80211_channel *chan;
1167 int i;
1168 const struct ieee80211_txrx_stypes *mgmt_stypes =
1169 dev->wiphy.mgmt_stypes;
fe1abafd 1170 u32 features;
ee688b00 1171
3713b4e3
JB
1172 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
1173 if (!hdr)
1174 return -ENOBUFS;
ee688b00 1175
86e8cf98
JB
1176 if (WARN_ON(!state))
1177 return -EINVAL;
ee688b00 1178
3713b4e3
JB
1179 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
1180 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1181 wiphy_name(&dev->wiphy)) ||
1182 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1183 cfg80211_rdev_list_generation))
8fdc621d
JB
1184 goto nla_put_failure;
1185
86e8cf98 1186 switch (state->split_start) {
3713b4e3
JB
1187 case 0:
1188 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1189 dev->wiphy.retry_short) ||
1190 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1191 dev->wiphy.retry_long) ||
1192 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1193 dev->wiphy.frag_threshold) ||
1194 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1195 dev->wiphy.rts_threshold) ||
1196 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1197 dev->wiphy.coverage_class) ||
1198 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1199 dev->wiphy.max_scan_ssids) ||
1200 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1201 dev->wiphy.max_sched_scan_ssids) ||
1202 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1203 dev->wiphy.max_scan_ie_len) ||
1204 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1205 dev->wiphy.max_sched_scan_ie_len) ||
1206 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
1207 dev->wiphy.max_match_sets))
9360ffd1 1208 goto nla_put_failure;
3713b4e3
JB
1209
1210 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
1211 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1212 goto nla_put_failure;
3713b4e3
JB
1213 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
1214 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1215 goto nla_put_failure;
1216 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
1217 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1218 goto nla_put_failure;
1219 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
1220 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1221 goto nla_put_failure;
1222 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
1223 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1224 goto nla_put_failure;
1225 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
1226 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1227 goto nla_put_failure;
2f301ab2
SW
1228 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
1229 nla_put_flag(msg, WIPHY_FLAG_SUPPORTS_5_10_MHZ))
1230 goto nla_put_failure;
8fdc621d 1231
86e8cf98
JB
1232 state->split_start++;
1233 if (state->split)
3713b4e3
JB
1234 break;
1235 case 1:
1236 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1237 sizeof(u32) * dev->wiphy.n_cipher_suites,
1238 dev->wiphy.cipher_suites))
1239 goto nla_put_failure;
4745fc09 1240
3713b4e3
JB
1241 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1242 dev->wiphy.max_num_pmkids))
1243 goto nla_put_failure;
b23aa676 1244
3713b4e3
JB
1245 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
1246 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1247 goto nla_put_failure;
b23aa676 1248
3713b4e3
JB
1249 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1250 dev->wiphy.available_antennas_tx) ||
1251 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1252 dev->wiphy.available_antennas_rx))
9360ffd1 1253 goto nla_put_failure;
b23aa676 1254
3713b4e3
JB
1255 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
1256 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1257 dev->wiphy.probe_resp_offload))
1258 goto nla_put_failure;
8fdc621d 1259
3713b4e3
JB
1260 if ((dev->wiphy.available_antennas_tx ||
1261 dev->wiphy.available_antennas_rx) &&
1262 dev->ops->get_antenna) {
1263 u32 tx_ant = 0, rx_ant = 0;
1264 int res;
1265 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
1266 if (!res) {
1267 if (nla_put_u32(msg,
1268 NL80211_ATTR_WIPHY_ANTENNA_TX,
1269 tx_ant) ||
1270 nla_put_u32(msg,
1271 NL80211_ATTR_WIPHY_ANTENNA_RX,
1272 rx_ant))
1273 goto nla_put_failure;
1274 }
1275 }
a293911d 1276
86e8cf98
JB
1277 state->split_start++;
1278 if (state->split)
3713b4e3
JB
1279 break;
1280 case 2:
1281 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1282 dev->wiphy.interface_modes))
1283 goto nla_put_failure;
86e8cf98
JB
1284 state->split_start++;
1285 if (state->split)
3713b4e3
JB
1286 break;
1287 case 3:
1288 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1289 if (!nl_bands)
1290 goto nla_put_failure;
f7ca38df 1291
86e8cf98
JB
1292 for (band = state->band_start;
1293 band < IEEE80211_NUM_BANDS; band++) {
3713b4e3 1294 struct ieee80211_supported_band *sband;
2e161f78 1295
3713b4e3 1296 sband = dev->wiphy.bands[band];
2e161f78 1297
3713b4e3
JB
1298 if (!sband)
1299 continue;
1300
1301 nl_band = nla_nest_start(msg, band);
1302 if (!nl_band)
2e161f78 1303 goto nla_put_failure;
3713b4e3 1304
86e8cf98 1305 switch (state->chan_start) {
3713b4e3
JB
1306 case 0:
1307 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 1308 goto nla_put_failure;
86e8cf98
JB
1309 state->chan_start++;
1310 if (state->split)
3713b4e3
JB
1311 break;
1312 default:
1313 /* add frequencies */
1314 nl_freqs = nla_nest_start(
1315 msg, NL80211_BAND_ATTR_FREQS);
1316 if (!nl_freqs)
1317 goto nla_put_failure;
1318
86e8cf98 1319 for (i = state->chan_start - 1;
3713b4e3
JB
1320 i < sband->n_channels;
1321 i++) {
1322 nl_freq = nla_nest_start(msg, i);
1323 if (!nl_freq)
1324 goto nla_put_failure;
1325
1326 chan = &sband->channels[i];
1327
86e8cf98
JB
1328 if (nl80211_msg_put_channel(
1329 msg, chan,
1330 state->split))
3713b4e3
JB
1331 goto nla_put_failure;
1332
1333 nla_nest_end(msg, nl_freq);
86e8cf98 1334 if (state->split)
3713b4e3
JB
1335 break;
1336 }
1337 if (i < sband->n_channels)
86e8cf98 1338 state->chan_start = i + 2;
3713b4e3 1339 else
86e8cf98 1340 state->chan_start = 0;
3713b4e3
JB
1341 nla_nest_end(msg, nl_freqs);
1342 }
1343
1344 nla_nest_end(msg, nl_band);
1345
86e8cf98 1346 if (state->split) {
3713b4e3 1347 /* start again here */
86e8cf98 1348 if (state->chan_start)
3713b4e3
JB
1349 band--;
1350 break;
2e161f78 1351 }
2e161f78 1352 }
3713b4e3 1353 nla_nest_end(msg, nl_bands);
2e161f78 1354
3713b4e3 1355 if (band < IEEE80211_NUM_BANDS)
86e8cf98 1356 state->band_start = band + 1;
3713b4e3 1357 else
86e8cf98 1358 state->band_start = 0;
74b70a4e 1359
3713b4e3 1360 /* if bands & channels are done, continue outside */
86e8cf98
JB
1361 if (state->band_start == 0 && state->chan_start == 0)
1362 state->split_start++;
1363 if (state->split)
3713b4e3
JB
1364 break;
1365 case 4:
1366 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1367 if (!nl_cmds)
2e161f78
JB
1368 goto nla_put_failure;
1369
3713b4e3
JB
1370 i = 0;
1371#define CMD(op, n) \
1372 do { \
1373 if (dev->ops->op) { \
1374 i++; \
1375 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1376 goto nla_put_failure; \
1377 } \
1378 } while (0)
1379
1380 CMD(add_virtual_intf, NEW_INTERFACE);
1381 CMD(change_virtual_intf, SET_INTERFACE);
1382 CMD(add_key, NEW_KEY);
1383 CMD(start_ap, START_AP);
1384 CMD(add_station, NEW_STATION);
1385 CMD(add_mpath, NEW_MPATH);
1386 CMD(update_mesh_config, SET_MESH_CONFIG);
1387 CMD(change_bss, SET_BSS);
1388 CMD(auth, AUTHENTICATE);
1389 CMD(assoc, ASSOCIATE);
1390 CMD(deauth, DEAUTHENTICATE);
1391 CMD(disassoc, DISASSOCIATE);
1392 CMD(join_ibss, JOIN_IBSS);
1393 CMD(join_mesh, JOIN_MESH);
1394 CMD(set_pmksa, SET_PMKSA);
1395 CMD(del_pmksa, DEL_PMKSA);
1396 CMD(flush_pmksa, FLUSH_PMKSA);
1397 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1398 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1399 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1400 CMD(mgmt_tx, FRAME);
1401 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1402 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1403 i++;
1404 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
2e161f78 1405 goto nla_put_failure;
2e161f78 1406 }
3713b4e3
JB
1407 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
1408 dev->ops->join_mesh) {
1409 i++;
1410 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1411 goto nla_put_failure;
1412 }
1413 CMD(set_wds_peer, SET_WDS_PEER);
1414 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1415 CMD(tdls_mgmt, TDLS_MGMT);
1416 CMD(tdls_oper, TDLS_OPER);
1417 }
1418 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1419 CMD(sched_scan_start, START_SCHED_SCAN);
1420 CMD(probe_client, PROBE_CLIENT);
1421 CMD(set_noack_map, SET_NOACK_MAP);
1422 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1423 i++;
1424 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1425 goto nla_put_failure;
1426 }
1427 CMD(start_p2p_device, START_P2P_DEVICE);
1428 CMD(set_mcast_rate, SET_MCAST_RATE);
86e8cf98 1429 if (state->split) {
5de17984
AS
1430 CMD(crit_proto_start, CRIT_PROTOCOL_START);
1431 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
16ef1fe2
SW
1432 if (dev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
1433 CMD(channel_switch, CHANNEL_SWITCH);
5de17984 1434 }
2e161f78 1435
3713b4e3
JB
1436#ifdef CONFIG_NL80211_TESTMODE
1437 CMD(testmode_cmd, TESTMODE);
1438#endif
ff1b6e69 1439
3713b4e3 1440#undef CMD
ff1b6e69 1441
3713b4e3
JB
1442 if (dev->ops->connect || dev->ops->auth) {
1443 i++;
1444 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
9360ffd1 1445 goto nla_put_failure;
ff1b6e69
JB
1446 }
1447
3713b4e3
JB
1448 if (dev->ops->disconnect || dev->ops->deauth) {
1449 i++;
1450 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1451 goto nla_put_failure;
1452 }
1453
1454 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
1455 state->split_start++;
1456 if (state->split)
3713b4e3
JB
1457 break;
1458 case 5:
1459 if (dev->ops->remain_on_channel &&
1460 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1461 nla_put_u32(msg,
1462 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1463 dev->wiphy.max_remain_on_channel_duration))
1464 goto nla_put_failure;
1465
1466 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1467 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1468 goto nla_put_failure;
1469
1470 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
1471 goto nla_put_failure;
86e8cf98
JB
1472 state->split_start++;
1473 if (state->split)
3713b4e3
JB
1474 break;
1475 case 6:
1476#ifdef CONFIG_PM
86e8cf98 1477 if (nl80211_send_wowlan(msg, dev, state->split))
3713b4e3 1478 goto nla_put_failure;
86e8cf98
JB
1479 state->split_start++;
1480 if (state->split)
3713b4e3
JB
1481 break;
1482#else
86e8cf98 1483 state->split_start++;
dfb89c56 1484#endif
3713b4e3
JB
1485 case 7:
1486 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1487 dev->wiphy.software_iftypes))
1488 goto nla_put_failure;
ff1b6e69 1489
86e8cf98
JB
1490 if (nl80211_put_iface_combinations(&dev->wiphy, msg,
1491 state->split))
3713b4e3 1492 goto nla_put_failure;
7527a782 1493
86e8cf98
JB
1494 state->split_start++;
1495 if (state->split)
3713b4e3
JB
1496 break;
1497 case 8:
1498 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1499 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1500 dev->wiphy.ap_sme_capa))
1501 goto nla_put_failure;
7527a782 1502
fe1abafd
JB
1503 features = dev->wiphy.features;
1504 /*
1505 * We can only add the per-channel limit information if the
1506 * dump is split, otherwise it makes it too big. Therefore
1507 * only advertise it in that case.
1508 */
86e8cf98 1509 if (state->split)
fe1abafd
JB
1510 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
1511 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 1512 goto nla_put_failure;
562a7480 1513
3713b4e3
JB
1514 if (dev->wiphy.ht_capa_mod_mask &&
1515 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1516 sizeof(*dev->wiphy.ht_capa_mod_mask),
1517 dev->wiphy.ht_capa_mod_mask))
1518 goto nla_put_failure;
1f074bd8 1519
3713b4e3
JB
1520 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1521 dev->wiphy.max_acl_mac_addrs &&
1522 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1523 dev->wiphy.max_acl_mac_addrs))
1524 goto nla_put_failure;
7e7c8926 1525
3713b4e3
JB
1526 /*
1527 * Any information below this point is only available to
1528 * applications that can deal with it being split. This
1529 * helps ensure that newly added capabilities don't break
1530 * older tools by overrunning their buffers.
1531 *
1532 * We still increment split_start so that in the split
1533 * case we'll continue with more data in the next round,
1534 * but break unconditionally so unsplit data stops here.
1535 */
86e8cf98 1536 state->split_start++;
3713b4e3
JB
1537 break;
1538 case 9:
fe1abafd
JB
1539 if (dev->wiphy.extended_capabilities &&
1540 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1541 dev->wiphy.extended_capabilities_len,
1542 dev->wiphy.extended_capabilities) ||
1543 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1544 dev->wiphy.extended_capabilities_len,
1545 dev->wiphy.extended_capabilities_mask)))
1546 goto nla_put_failure;
a50df0c4 1547
ee2aca34
JB
1548 if (dev->wiphy.vht_capa_mod_mask &&
1549 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1550 sizeof(*dev->wiphy.vht_capa_mod_mask),
1551 dev->wiphy.vht_capa_mod_mask))
1552 goto nla_put_failure;
1553
be29b99a
AK
1554 state->split_start++;
1555 break;
1556 case 10:
1557 if (nl80211_send_coalesce(msg, dev))
1558 goto nla_put_failure;
1559
3713b4e3 1560 /* done */
86e8cf98 1561 state->split_start = 0;
3713b4e3
JB
1562 break;
1563 }
55682965
JB
1564 return genlmsg_end(msg, hdr);
1565
1566 nla_put_failure:
bc3ed28c
TG
1567 genlmsg_cancel(msg, hdr);
1568 return -EMSGSIZE;
55682965
JB
1569}
1570
86e8cf98
JB
1571static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
1572 struct netlink_callback *cb,
1573 struct nl80211_dump_wiphy_state *state)
1574{
1575 struct nlattr **tb = nl80211_fam.attrbuf;
1576 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1577 tb, nl80211_fam.maxattr, nl80211_policy);
1578 /* ignore parse errors for backward compatibility */
1579 if (ret)
1580 return 0;
1581
1582 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
1583 if (tb[NL80211_ATTR_WIPHY])
1584 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
1585 if (tb[NL80211_ATTR_WDEV])
1586 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
1587 if (tb[NL80211_ATTR_IFINDEX]) {
1588 struct net_device *netdev;
1589 struct cfg80211_registered_device *rdev;
1590 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
1591
1592 netdev = dev_get_by_index(sock_net(skb->sk), ifidx);
1593 if (!netdev)
1594 return -ENODEV;
1595 if (netdev->ieee80211_ptr) {
1596 rdev = wiphy_to_dev(
1597 netdev->ieee80211_ptr->wiphy);
1598 state->filter_wiphy = rdev->wiphy_idx;
1599 }
1600 dev_put(netdev);
1601 }
1602
1603 return 0;
1604}
1605
55682965
JB
1606static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1607{
645e77de 1608 int idx = 0, ret;
86e8cf98 1609 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
55682965 1610 struct cfg80211_registered_device *dev;
3a5a423b 1611
5fe231e8 1612 rtnl_lock();
86e8cf98
JB
1613 if (!state) {
1614 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
1615 if (!state) {
1616 rtnl_unlock();
86e8cf98 1617 return -ENOMEM;
3713b4e3 1618 }
86e8cf98
JB
1619 state->filter_wiphy = -1;
1620 ret = nl80211_dump_wiphy_parse(skb, cb, state);
1621 if (ret) {
1622 kfree(state);
1623 rtnl_unlock();
1624 return ret;
3713b4e3 1625 }
86e8cf98 1626 cb->args[0] = (long)state;
3713b4e3
JB
1627 }
1628
79c97e97 1629 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1630 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1631 continue;
86e8cf98 1632 if (++idx <= state->start)
55682965 1633 continue;
86e8cf98
JB
1634 if (state->filter_wiphy != -1 &&
1635 state->filter_wiphy != dev->wiphy_idx)
3713b4e3
JB
1636 continue;
1637 /* attempt to fit multiple wiphy data chunks into the skb */
1638 do {
1639 ret = nl80211_send_wiphy(dev, skb,
1640 NETLINK_CB(cb->skb).portid,
1641 cb->nlh->nlmsg_seq,
86e8cf98 1642 NLM_F_MULTI, state);
3713b4e3
JB
1643 if (ret < 0) {
1644 /*
1645 * If sending the wiphy data didn't fit (ENOBUFS
1646 * or EMSGSIZE returned), this SKB is still
1647 * empty (so it's not too big because another
1648 * wiphy dataset is already in the skb) and
1649 * we've not tried to adjust the dump allocation
1650 * yet ... then adjust the alloc size to be
1651 * bigger, and return 1 but with the empty skb.
1652 * This results in an empty message being RX'ed
1653 * in userspace, but that is ignored.
1654 *
1655 * We can then retry with the larger buffer.
1656 */
1657 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
1658 !skb->len &&
1659 cb->min_dump_alloc < 4096) {
1660 cb->min_dump_alloc = 4096;
d98cae64 1661 rtnl_unlock();
3713b4e3
JB
1662 return 1;
1663 }
1664 idx--;
1665 break;
645e77de 1666 }
86e8cf98 1667 } while (state->split_start > 0);
3713b4e3 1668 break;
55682965 1669 }
5fe231e8 1670 rtnl_unlock();
55682965 1671
86e8cf98 1672 state->start = idx;
55682965
JB
1673
1674 return skb->len;
1675}
1676
86e8cf98
JB
1677static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
1678{
1679 kfree((void *)cb->args[0]);
1680 return 0;
1681}
1682
55682965
JB
1683static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1684{
1685 struct sk_buff *msg;
4c476991 1686 struct cfg80211_registered_device *dev = info->user_ptr[0];
86e8cf98 1687 struct nl80211_dump_wiphy_state state = {};
55682965 1688
645e77de 1689 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 1690 if (!msg)
4c476991 1691 return -ENOMEM;
55682965 1692
3713b4e3 1693 if (nl80211_send_wiphy(dev, msg, info->snd_portid, info->snd_seq, 0,
86e8cf98 1694 &state) < 0) {
4c476991
JB
1695 nlmsg_free(msg);
1696 return -ENOBUFS;
1697 }
55682965 1698
134e6375 1699 return genlmsg_reply(msg, info);
55682965
JB
1700}
1701
31888487
JM
1702static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1703 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1704 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1705 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1706 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1707 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1708};
1709
1710static int parse_txq_params(struct nlattr *tb[],
1711 struct ieee80211_txq_params *txq_params)
1712{
a3304b0a 1713 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1714 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1715 !tb[NL80211_TXQ_ATTR_AIFS])
1716 return -EINVAL;
1717
a3304b0a 1718 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1719 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1720 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1721 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1722 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1723
a3304b0a
JB
1724 if (txq_params->ac >= NL80211_NUM_ACS)
1725 return -EINVAL;
1726
31888487
JM
1727 return 0;
1728}
1729
f444de05
JB
1730static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1731{
1732 /*
cc1d2806
JB
1733 * You can only set the channel explicitly for WDS interfaces,
1734 * all others have their channel managed via their respective
1735 * "establish a connection" command (connect, join, ...)
1736 *
1737 * For AP/GO and mesh mode, the channel can be set with the
1738 * channel userspace API, but is only stored and passed to the
1739 * low-level driver when the AP starts or the mesh is joined.
1740 * This is for backward compatibility, userspace can also give
1741 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1742 *
1743 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1744 * whatever else is going on, so they have their own special
1745 * operation to set the monitor channel if possible.
f444de05
JB
1746 */
1747 return !wdev ||
1748 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1749 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1750 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1751 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1752}
1753
683b6d3b
JB
1754static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1755 struct genl_info *info,
1756 struct cfg80211_chan_def *chandef)
1757{
dbeca2ea 1758 u32 control_freq;
683b6d3b
JB
1759
1760 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1761 return -EINVAL;
1762
1763 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1764
1765 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1766 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1767 chandef->center_freq1 = control_freq;
1768 chandef->center_freq2 = 0;
683b6d3b
JB
1769
1770 /* Primary channel not allowed */
1771 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1772 return -EINVAL;
1773
3d9d1d66
JB
1774 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1775 enum nl80211_channel_type chantype;
1776
1777 chantype = nla_get_u32(
1778 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1779
1780 switch (chantype) {
1781 case NL80211_CHAN_NO_HT:
1782 case NL80211_CHAN_HT20:
1783 case NL80211_CHAN_HT40PLUS:
1784 case NL80211_CHAN_HT40MINUS:
1785 cfg80211_chandef_create(chandef, chandef->chan,
1786 chantype);
1787 break;
1788 default:
1789 return -EINVAL;
1790 }
1791 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1792 chandef->width =
1793 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1794 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1795 chandef->center_freq1 =
1796 nla_get_u32(
1797 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1798 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1799 chandef->center_freq2 =
1800 nla_get_u32(
1801 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1802 }
1803
9f5e8f6e 1804 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1805 return -EINVAL;
1806
9f5e8f6e
JB
1807 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1808 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1809 return -EINVAL;
1810
2f301ab2
SW
1811 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
1812 chandef->width == NL80211_CHAN_WIDTH_10) &&
1813 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ))
1814 return -EINVAL;
1815
683b6d3b
JB
1816 return 0;
1817}
1818
f444de05
JB
1819static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1820 struct wireless_dev *wdev,
1821 struct genl_info *info)
1822{
683b6d3b 1823 struct cfg80211_chan_def chandef;
f444de05 1824 int result;
e8c9bd5b
JB
1825 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1826
1827 if (wdev)
1828 iftype = wdev->iftype;
f444de05 1829
f444de05
JB
1830 if (!nl80211_can_set_dev_channel(wdev))
1831 return -EOPNOTSUPP;
1832
683b6d3b
JB
1833 result = nl80211_parse_chandef(rdev, info, &chandef);
1834 if (result)
1835 return result;
f444de05 1836
e8c9bd5b 1837 switch (iftype) {
aa430da4
JB
1838 case NL80211_IFTYPE_AP:
1839 case NL80211_IFTYPE_P2P_GO:
1840 if (wdev->beacon_interval) {
1841 result = -EBUSY;
1842 break;
1843 }
683b6d3b 1844 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1845 result = -EINVAL;
1846 break;
1847 }
683b6d3b 1848 wdev->preset_chandef = chandef;
aa430da4
JB
1849 result = 0;
1850 break;
cc1d2806 1851 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1852 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1853 break;
e8c9bd5b 1854 case NL80211_IFTYPE_MONITOR:
683b6d3b 1855 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1856 break;
aa430da4 1857 default:
e8c9bd5b 1858 result = -EINVAL;
f444de05 1859 }
f444de05
JB
1860
1861 return result;
1862}
1863
1864static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1865{
4c476991
JB
1866 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1867 struct net_device *netdev = info->user_ptr[1];
f444de05 1868
4c476991 1869 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1870}
1871
e8347eba
BJ
1872static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1873{
43b19952
JB
1874 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1875 struct net_device *dev = info->user_ptr[1];
1876 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1877 const u8 *bssid;
e8347eba
BJ
1878
1879 if (!info->attrs[NL80211_ATTR_MAC])
1880 return -EINVAL;
1881
43b19952
JB
1882 if (netif_running(dev))
1883 return -EBUSY;
e8347eba 1884
43b19952
JB
1885 if (!rdev->ops->set_wds_peer)
1886 return -EOPNOTSUPP;
e8347eba 1887
43b19952
JB
1888 if (wdev->iftype != NL80211_IFTYPE_WDS)
1889 return -EOPNOTSUPP;
e8347eba
BJ
1890
1891 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1892 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1893}
1894
1895
55682965
JB
1896static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1897{
1898 struct cfg80211_registered_device *rdev;
f444de05
JB
1899 struct net_device *netdev = NULL;
1900 struct wireless_dev *wdev;
a1e567c8 1901 int result = 0, rem_txq_params = 0;
31888487 1902 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1903 u32 changed;
1904 u8 retry_short = 0, retry_long = 0;
1905 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1906 u8 coverage_class = 0;
55682965 1907
5fe231e8
JB
1908 ASSERT_RTNL();
1909
f444de05
JB
1910 /*
1911 * Try to find the wiphy and netdev. Normally this
1912 * function shouldn't need the netdev, but this is
1913 * done for backward compatibility -- previously
1914 * setting the channel was done per wiphy, but now
1915 * it is per netdev. Previous userland like hostapd
1916 * also passed a netdev to set_wiphy, so that it is
1917 * possible to let that go to the right netdev!
1918 */
4bbf4d56 1919
f444de05
JB
1920 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1921 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1922
1923 netdev = dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 1924 if (netdev && netdev->ieee80211_ptr)
f444de05 1925 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
5fe231e8 1926 else
f444de05 1927 netdev = NULL;
4bbf4d56
JB
1928 }
1929
f444de05 1930 if (!netdev) {
878d9ec7
JB
1931 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1932 info->attrs);
5fe231e8 1933 if (IS_ERR(rdev))
4c476991 1934 return PTR_ERR(rdev);
f444de05
JB
1935 wdev = NULL;
1936 netdev = NULL;
1937 result = 0;
71fe96bf 1938 } else
f444de05 1939 wdev = netdev->ieee80211_ptr;
f444de05
JB
1940
1941 /*
1942 * end workaround code, by now the rdev is available
1943 * and locked, and wdev may or may not be NULL.
1944 */
4bbf4d56
JB
1945
1946 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1947 result = cfg80211_dev_rename(
1948 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 1949
4bbf4d56
JB
1950 if (result)
1951 goto bad_res;
31888487
JM
1952
1953 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1954 struct ieee80211_txq_params txq_params;
1955 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1956
1957 if (!rdev->ops->set_txq_params) {
1958 result = -EOPNOTSUPP;
1959 goto bad_res;
1960 }
1961
f70f01c2
EP
1962 if (!netdev) {
1963 result = -EINVAL;
1964 goto bad_res;
1965 }
1966
133a3ff2
JB
1967 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1968 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1969 result = -EINVAL;
1970 goto bad_res;
1971 }
1972
2b5f8b0b
JB
1973 if (!netif_running(netdev)) {
1974 result = -ENETDOWN;
1975 goto bad_res;
1976 }
1977
31888487
JM
1978 nla_for_each_nested(nl_txq_params,
1979 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1980 rem_txq_params) {
1981 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1982 nla_data(nl_txq_params),
1983 nla_len(nl_txq_params),
1984 txq_params_policy);
1985 result = parse_txq_params(tb, &txq_params);
1986 if (result)
1987 goto bad_res;
1988
e35e4d28
HG
1989 result = rdev_set_txq_params(rdev, netdev,
1990 &txq_params);
31888487
JM
1991 if (result)
1992 goto bad_res;
1993 }
1994 }
55682965 1995
72bdcf34 1996 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1997 result = __nl80211_set_channel(rdev,
1998 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1999 info);
72bdcf34
JM
2000 if (result)
2001 goto bad_res;
2002 }
2003
98d2ff8b 2004 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 2005 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
2006 enum nl80211_tx_power_setting type;
2007 int idx, mbm = 0;
2008
c8442118
JB
2009 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
2010 txp_wdev = NULL;
2011
98d2ff8b 2012 if (!rdev->ops->set_tx_power) {
60ea385f 2013 result = -EOPNOTSUPP;
98d2ff8b
JO
2014 goto bad_res;
2015 }
2016
2017 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
2018 type = nla_get_u32(info->attrs[idx]);
2019
2020 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
2021 (type != NL80211_TX_POWER_AUTOMATIC)) {
2022 result = -EINVAL;
2023 goto bad_res;
2024 }
2025
2026 if (type != NL80211_TX_POWER_AUTOMATIC) {
2027 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
2028 mbm = nla_get_u32(info->attrs[idx]);
2029 }
2030
c8442118 2031 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
2032 if (result)
2033 goto bad_res;
2034 }
2035
afe0cbf8
BR
2036 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
2037 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
2038 u32 tx_ant, rx_ant;
7f531e03
BR
2039 if ((!rdev->wiphy.available_antennas_tx &&
2040 !rdev->wiphy.available_antennas_rx) ||
2041 !rdev->ops->set_antenna) {
afe0cbf8
BR
2042 result = -EOPNOTSUPP;
2043 goto bad_res;
2044 }
2045
2046 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
2047 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
2048
a7ffac95 2049 /* reject antenna configurations which don't match the
7f531e03
BR
2050 * available antenna masks, except for the "all" mask */
2051 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
2052 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
2053 result = -EINVAL;
2054 goto bad_res;
2055 }
2056
7f531e03
BR
2057 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
2058 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 2059
e35e4d28 2060 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
2061 if (result)
2062 goto bad_res;
2063 }
2064
b9a5f8ca
JM
2065 changed = 0;
2066
2067 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
2068 retry_short = nla_get_u8(
2069 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
2070 if (retry_short == 0) {
2071 result = -EINVAL;
2072 goto bad_res;
2073 }
2074 changed |= WIPHY_PARAM_RETRY_SHORT;
2075 }
2076
2077 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2078 retry_long = nla_get_u8(
2079 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
2080 if (retry_long == 0) {
2081 result = -EINVAL;
2082 goto bad_res;
2083 }
2084 changed |= WIPHY_PARAM_RETRY_LONG;
2085 }
2086
2087 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2088 frag_threshold = nla_get_u32(
2089 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
2090 if (frag_threshold < 256) {
2091 result = -EINVAL;
2092 goto bad_res;
2093 }
2094 if (frag_threshold != (u32) -1) {
2095 /*
2096 * Fragments (apart from the last one) are required to
2097 * have even length. Make the fragmentation code
2098 * simpler by stripping LSB should someone try to use
2099 * odd threshold value.
2100 */
2101 frag_threshold &= ~0x1;
2102 }
2103 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2104 }
2105
2106 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2107 rts_threshold = nla_get_u32(
2108 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2109 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2110 }
2111
81077e82
LT
2112 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
2113 coverage_class = nla_get_u8(
2114 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2115 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2116 }
2117
b9a5f8ca
JM
2118 if (changed) {
2119 u8 old_retry_short, old_retry_long;
2120 u32 old_frag_threshold, old_rts_threshold;
81077e82 2121 u8 old_coverage_class;
b9a5f8ca
JM
2122
2123 if (!rdev->ops->set_wiphy_params) {
2124 result = -EOPNOTSUPP;
2125 goto bad_res;
2126 }
2127
2128 old_retry_short = rdev->wiphy.retry_short;
2129 old_retry_long = rdev->wiphy.retry_long;
2130 old_frag_threshold = rdev->wiphy.frag_threshold;
2131 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 2132 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
2133
2134 if (changed & WIPHY_PARAM_RETRY_SHORT)
2135 rdev->wiphy.retry_short = retry_short;
2136 if (changed & WIPHY_PARAM_RETRY_LONG)
2137 rdev->wiphy.retry_long = retry_long;
2138 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
2139 rdev->wiphy.frag_threshold = frag_threshold;
2140 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
2141 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
2142 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
2143 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 2144
e35e4d28 2145 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
2146 if (result) {
2147 rdev->wiphy.retry_short = old_retry_short;
2148 rdev->wiphy.retry_long = old_retry_long;
2149 rdev->wiphy.frag_threshold = old_frag_threshold;
2150 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 2151 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
2152 }
2153 }
72bdcf34 2154
306d6112 2155 bad_res:
f444de05
JB
2156 if (netdev)
2157 dev_put(netdev);
55682965
JB
2158 return result;
2159}
2160
71bbc994
JB
2161static inline u64 wdev_id(struct wireless_dev *wdev)
2162{
2163 return (u64)wdev->identifier |
2164 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
2165}
55682965 2166
683b6d3b
JB
2167static int nl80211_send_chandef(struct sk_buff *msg,
2168 struct cfg80211_chan_def *chandef)
2169{
9f5e8f6e 2170 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 2171
683b6d3b
JB
2172 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
2173 chandef->chan->center_freq))
2174 return -ENOBUFS;
3d9d1d66
JB
2175 switch (chandef->width) {
2176 case NL80211_CHAN_WIDTH_20_NOHT:
2177 case NL80211_CHAN_WIDTH_20:
2178 case NL80211_CHAN_WIDTH_40:
2179 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2180 cfg80211_get_chandef_type(chandef)))
2181 return -ENOBUFS;
2182 break;
2183 default:
2184 break;
2185 }
2186 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
2187 return -ENOBUFS;
2188 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
2189 return -ENOBUFS;
2190 if (chandef->center_freq2 &&
2191 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
2192 return -ENOBUFS;
2193 return 0;
2194}
2195
15e47304 2196static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 2197 struct cfg80211_registered_device *rdev,
72fb2abc 2198 struct wireless_dev *wdev)
55682965 2199{
72fb2abc 2200 struct net_device *dev = wdev->netdev;
55682965
JB
2201 void *hdr;
2202
15e47304 2203 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
2204 if (!hdr)
2205 return -1;
2206
72fb2abc
JB
2207 if (dev &&
2208 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 2209 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
2210 goto nla_put_failure;
2211
2212 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2213 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 2214 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 2215 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
2216 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2217 rdev->devlist_generation ^
2218 (cfg80211_rdev_list_generation << 2)))
2219 goto nla_put_failure;
f5ea9120 2220
5b7ccaf3 2221 if (rdev->ops->get_channel) {
683b6d3b
JB
2222 int ret;
2223 struct cfg80211_chan_def chandef;
2224
2225 ret = rdev_get_channel(rdev, wdev, &chandef);
2226 if (ret == 0) {
2227 if (nl80211_send_chandef(msg, &chandef))
2228 goto nla_put_failure;
2229 }
d91df0e3
PF
2230 }
2231
b84e7a05
AQ
2232 if (wdev->ssid_len) {
2233 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
2234 goto nla_put_failure;
2235 }
2236
55682965
JB
2237 return genlmsg_end(msg, hdr);
2238
2239 nla_put_failure:
bc3ed28c
TG
2240 genlmsg_cancel(msg, hdr);
2241 return -EMSGSIZE;
55682965
JB
2242}
2243
2244static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
2245{
2246 int wp_idx = 0;
2247 int if_idx = 0;
2248 int wp_start = cb->args[0];
2249 int if_start = cb->args[1];
f5ea9120 2250 struct cfg80211_registered_device *rdev;
55682965
JB
2251 struct wireless_dev *wdev;
2252
5fe231e8 2253 rtnl_lock();
f5ea9120
JB
2254 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2255 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2256 continue;
bba95fef
JB
2257 if (wp_idx < wp_start) {
2258 wp_idx++;
55682965 2259 continue;
bba95fef 2260 }
55682965
JB
2261 if_idx = 0;
2262
89a54e48 2263 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
2264 if (if_idx < if_start) {
2265 if_idx++;
55682965 2266 continue;
bba95fef 2267 }
15e47304 2268 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 2269 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 2270 rdev, wdev) < 0) {
bba95fef
JB
2271 goto out;
2272 }
2273 if_idx++;
55682965 2274 }
bba95fef
JB
2275
2276 wp_idx++;
55682965 2277 }
bba95fef 2278 out:
5fe231e8 2279 rtnl_unlock();
55682965
JB
2280
2281 cb->args[0] = wp_idx;
2282 cb->args[1] = if_idx;
2283
2284 return skb->len;
2285}
2286
2287static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
2288{
2289 struct sk_buff *msg;
4c476991 2290 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 2291 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2292
fd2120ca 2293 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 2294 if (!msg)
4c476991 2295 return -ENOMEM;
55682965 2296
15e47304 2297 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 2298 dev, wdev) < 0) {
4c476991
JB
2299 nlmsg_free(msg);
2300 return -ENOBUFS;
2301 }
55682965 2302
134e6375 2303 return genlmsg_reply(msg, info);
55682965
JB
2304}
2305
66f7ac50
MW
2306static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2307 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2308 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2309 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2310 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2311 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 2312 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
2313};
2314
2315static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2316{
2317 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2318 int flag;
2319
2320 *mntrflags = 0;
2321
2322 if (!nla)
2323 return -EINVAL;
2324
2325 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
2326 nla, mntr_flags_policy))
2327 return -EINVAL;
2328
2329 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2330 if (flags[flag])
2331 *mntrflags |= (1<<flag);
2332
2333 return 0;
2334}
2335
9bc383de 2336static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2337 struct net_device *netdev, u8 use_4addr,
2338 enum nl80211_iftype iftype)
9bc383de 2339{
ad4bb6f8 2340 if (!use_4addr) {
f350a0a8 2341 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2342 return -EBUSY;
9bc383de 2343 return 0;
ad4bb6f8 2344 }
9bc383de
JB
2345
2346 switch (iftype) {
2347 case NL80211_IFTYPE_AP_VLAN:
2348 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2349 return 0;
2350 break;
2351 case NL80211_IFTYPE_STATION:
2352 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2353 return 0;
2354 break;
2355 default:
2356 break;
2357 }
2358
2359 return -EOPNOTSUPP;
2360}
2361
55682965
JB
2362static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2363{
4c476991 2364 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2365 struct vif_params params;
e36d56b6 2366 int err;
04a773ad 2367 enum nl80211_iftype otype, ntype;
4c476991 2368 struct net_device *dev = info->user_ptr[1];
92ffe055 2369 u32 _flags, *flags = NULL;
ac7f9cfa 2370 bool change = false;
55682965 2371
2ec600d6
LCC
2372 memset(&params, 0, sizeof(params));
2373
04a773ad 2374 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2375
723b038d 2376 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2377 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2378 if (otype != ntype)
ac7f9cfa 2379 change = true;
4c476991
JB
2380 if (ntype > NL80211_IFTYPE_MAX)
2381 return -EINVAL;
723b038d
JB
2382 }
2383
92ffe055 2384 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2385 struct wireless_dev *wdev = dev->ieee80211_ptr;
2386
4c476991
JB
2387 if (ntype != NL80211_IFTYPE_MESH_POINT)
2388 return -EINVAL;
29cbe68c
JB
2389 if (netif_running(dev))
2390 return -EBUSY;
2391
2392 wdev_lock(wdev);
2393 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2394 IEEE80211_MAX_MESH_ID_LEN);
2395 wdev->mesh_id_up_len =
2396 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2397 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2398 wdev->mesh_id_up_len);
2399 wdev_unlock(wdev);
2ec600d6
LCC
2400 }
2401
8b787643
FF
2402 if (info->attrs[NL80211_ATTR_4ADDR]) {
2403 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2404 change = true;
ad4bb6f8 2405 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2406 if (err)
4c476991 2407 return err;
8b787643
FF
2408 } else {
2409 params.use_4addr = -1;
2410 }
2411
92ffe055 2412 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2413 if (ntype != NL80211_IFTYPE_MONITOR)
2414 return -EINVAL;
92ffe055
JB
2415 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2416 &_flags);
ac7f9cfa 2417 if (err)
4c476991 2418 return err;
ac7f9cfa
JB
2419
2420 flags = &_flags;
2421 change = true;
92ffe055 2422 }
3b85875a 2423
e057d3c3
FF
2424 if (flags && (*flags & NL80211_MNTR_FLAG_ACTIVE) &&
2425 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2426 return -EOPNOTSUPP;
2427
ac7f9cfa 2428 if (change)
3d54d255 2429 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2430 else
2431 err = 0;
60719ffd 2432
9bc383de
JB
2433 if (!err && params.use_4addr != -1)
2434 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2435
55682965
JB
2436 return err;
2437}
2438
2439static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2440{
4c476991 2441 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2442 struct vif_params params;
84efbb84 2443 struct wireless_dev *wdev;
1c90f9d4 2444 struct sk_buff *msg;
55682965
JB
2445 int err;
2446 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2447 u32 flags;
55682965 2448
2ec600d6
LCC
2449 memset(&params, 0, sizeof(params));
2450
55682965
JB
2451 if (!info->attrs[NL80211_ATTR_IFNAME])
2452 return -EINVAL;
2453
2454 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2455 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2456 if (type > NL80211_IFTYPE_MAX)
2457 return -EINVAL;
2458 }
2459
79c97e97 2460 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2461 !(rdev->wiphy.interface_modes & (1 << type)))
2462 return -EOPNOTSUPP;
55682965 2463
1c18f145
AS
2464 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2465 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2466 ETH_ALEN);
2467 if (!is_valid_ether_addr(params.macaddr))
2468 return -EADDRNOTAVAIL;
2469 }
2470
9bc383de 2471 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2472 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2473 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2474 if (err)
4c476991 2475 return err;
9bc383de 2476 }
8b787643 2477
1c90f9d4
JB
2478 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2479 if (!msg)
2480 return -ENOMEM;
2481
66f7ac50
MW
2482 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2483 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2484 &flags);
e057d3c3
FF
2485
2486 if (!err && (flags & NL80211_MNTR_FLAG_ACTIVE) &&
2487 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2488 return -EOPNOTSUPP;
2489
e35e4d28
HG
2490 wdev = rdev_add_virtual_intf(rdev,
2491 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2492 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2493 if (IS_ERR(wdev)) {
2494 nlmsg_free(msg);
84efbb84 2495 return PTR_ERR(wdev);
1c90f9d4 2496 }
2ec600d6 2497
98104fde
JB
2498 switch (type) {
2499 case NL80211_IFTYPE_MESH_POINT:
2500 if (!info->attrs[NL80211_ATTR_MESH_ID])
2501 break;
29cbe68c
JB
2502 wdev_lock(wdev);
2503 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2504 IEEE80211_MAX_MESH_ID_LEN);
2505 wdev->mesh_id_up_len =
2506 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2507 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2508 wdev->mesh_id_up_len);
2509 wdev_unlock(wdev);
98104fde
JB
2510 break;
2511 case NL80211_IFTYPE_P2P_DEVICE:
2512 /*
2513 * P2P Device doesn't have a netdev, so doesn't go
2514 * through the netdev notifier and must be added here
2515 */
2516 mutex_init(&wdev->mtx);
2517 INIT_LIST_HEAD(&wdev->event_list);
2518 spin_lock_init(&wdev->event_lock);
2519 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2520 spin_lock_init(&wdev->mgmt_registrations_lock);
2521
98104fde
JB
2522 wdev->identifier = ++rdev->wdev_id;
2523 list_add_rcu(&wdev->list, &rdev->wdev_list);
2524 rdev->devlist_generation++;
98104fde
JB
2525 break;
2526 default:
2527 break;
29cbe68c
JB
2528 }
2529
15e47304 2530 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2531 rdev, wdev) < 0) {
2532 nlmsg_free(msg);
2533 return -ENOBUFS;
2534 }
2535
2536 return genlmsg_reply(msg, info);
55682965
JB
2537}
2538
2539static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2540{
4c476991 2541 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2542 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2543
4c476991
JB
2544 if (!rdev->ops->del_virtual_intf)
2545 return -EOPNOTSUPP;
55682965 2546
84efbb84
JB
2547 /*
2548 * If we remove a wireless device without a netdev then clear
2549 * user_ptr[1] so that nl80211_post_doit won't dereference it
2550 * to check if it needs to do dev_put(). Otherwise it crashes
2551 * since the wdev has been freed, unlike with a netdev where
2552 * we need the dev_put() for the netdev to really be freed.
2553 */
2554 if (!wdev->netdev)
2555 info->user_ptr[1] = NULL;
2556
e35e4d28 2557 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2558}
2559
1d9d9213
SW
2560static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2561{
2562 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2563 struct net_device *dev = info->user_ptr[1];
2564 u16 noack_map;
2565
2566 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2567 return -EINVAL;
2568
2569 if (!rdev->ops->set_noack_map)
2570 return -EOPNOTSUPP;
2571
2572 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2573
e35e4d28 2574 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2575}
2576
41ade00f
JB
2577struct get_key_cookie {
2578 struct sk_buff *msg;
2579 int error;
b9454e83 2580 int idx;
41ade00f
JB
2581};
2582
2583static void get_key_callback(void *c, struct key_params *params)
2584{
b9454e83 2585 struct nlattr *key;
41ade00f
JB
2586 struct get_key_cookie *cookie = c;
2587
9360ffd1
DM
2588 if ((params->key &&
2589 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2590 params->key_len, params->key)) ||
2591 (params->seq &&
2592 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2593 params->seq_len, params->seq)) ||
2594 (params->cipher &&
2595 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2596 params->cipher)))
2597 goto nla_put_failure;
41ade00f 2598
b9454e83
JB
2599 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2600 if (!key)
2601 goto nla_put_failure;
2602
9360ffd1
DM
2603 if ((params->key &&
2604 nla_put(cookie->msg, NL80211_KEY_DATA,
2605 params->key_len, params->key)) ||
2606 (params->seq &&
2607 nla_put(cookie->msg, NL80211_KEY_SEQ,
2608 params->seq_len, params->seq)) ||
2609 (params->cipher &&
2610 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2611 params->cipher)))
2612 goto nla_put_failure;
b9454e83 2613
9360ffd1
DM
2614 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2615 goto nla_put_failure;
b9454e83
JB
2616
2617 nla_nest_end(cookie->msg, key);
2618
41ade00f
JB
2619 return;
2620 nla_put_failure:
2621 cookie->error = 1;
2622}
2623
2624static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2625{
4c476991 2626 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2627 int err;
4c476991 2628 struct net_device *dev = info->user_ptr[1];
41ade00f 2629 u8 key_idx = 0;
e31b8213
JB
2630 const u8 *mac_addr = NULL;
2631 bool pairwise;
41ade00f
JB
2632 struct get_key_cookie cookie = {
2633 .error = 0,
2634 };
2635 void *hdr;
2636 struct sk_buff *msg;
2637
2638 if (info->attrs[NL80211_ATTR_KEY_IDX])
2639 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2640
3cfcf6ac 2641 if (key_idx > 5)
41ade00f
JB
2642 return -EINVAL;
2643
2644 if (info->attrs[NL80211_ATTR_MAC])
2645 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2646
e31b8213
JB
2647 pairwise = !!mac_addr;
2648 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2649 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2650 if (kt >= NUM_NL80211_KEYTYPES)
2651 return -EINVAL;
2652 if (kt != NL80211_KEYTYPE_GROUP &&
2653 kt != NL80211_KEYTYPE_PAIRWISE)
2654 return -EINVAL;
2655 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2656 }
2657
4c476991
JB
2658 if (!rdev->ops->get_key)
2659 return -EOPNOTSUPP;
41ade00f 2660
fd2120ca 2661 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2662 if (!msg)
2663 return -ENOMEM;
41ade00f 2664
15e47304 2665 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2666 NL80211_CMD_NEW_KEY);
cb35fba3
DC
2667 if (!hdr)
2668 return -ENOBUFS;
41ade00f
JB
2669
2670 cookie.msg = msg;
b9454e83 2671 cookie.idx = key_idx;
41ade00f 2672
9360ffd1
DM
2673 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2674 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2675 goto nla_put_failure;
2676 if (mac_addr &&
2677 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2678 goto nla_put_failure;
41ade00f 2679
e31b8213
JB
2680 if (pairwise && mac_addr &&
2681 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2682 return -ENOENT;
2683
e35e4d28
HG
2684 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2685 get_key_callback);
41ade00f
JB
2686
2687 if (err)
6c95e2a2 2688 goto free_msg;
41ade00f
JB
2689
2690 if (cookie.error)
2691 goto nla_put_failure;
2692
2693 genlmsg_end(msg, hdr);
4c476991 2694 return genlmsg_reply(msg, info);
41ade00f
JB
2695
2696 nla_put_failure:
2697 err = -ENOBUFS;
6c95e2a2 2698 free_msg:
41ade00f 2699 nlmsg_free(msg);
41ade00f
JB
2700 return err;
2701}
2702
2703static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2704{
4c476991 2705 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2706 struct key_parse key;
41ade00f 2707 int err;
4c476991 2708 struct net_device *dev = info->user_ptr[1];
41ade00f 2709
b9454e83
JB
2710 err = nl80211_parse_key(info, &key);
2711 if (err)
2712 return err;
41ade00f 2713
b9454e83 2714 if (key.idx < 0)
41ade00f
JB
2715 return -EINVAL;
2716
b9454e83
JB
2717 /* only support setting default key */
2718 if (!key.def && !key.defmgmt)
41ade00f
JB
2719 return -EINVAL;
2720
dbd2fd65 2721 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2722
dbd2fd65
JB
2723 if (key.def) {
2724 if (!rdev->ops->set_default_key) {
2725 err = -EOPNOTSUPP;
2726 goto out;
2727 }
41ade00f 2728
dbd2fd65
JB
2729 err = nl80211_key_allowed(dev->ieee80211_ptr);
2730 if (err)
2731 goto out;
2732
e35e4d28 2733 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2734 key.def_uni, key.def_multi);
2735
2736 if (err)
2737 goto out;
fffd0934 2738
3d23e349 2739#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2740 dev->ieee80211_ptr->wext.default_key = key.idx;
2741#endif
2742 } else {
2743 if (key.def_uni || !key.def_multi) {
2744 err = -EINVAL;
2745 goto out;
2746 }
2747
2748 if (!rdev->ops->set_default_mgmt_key) {
2749 err = -EOPNOTSUPP;
2750 goto out;
2751 }
2752
2753 err = nl80211_key_allowed(dev->ieee80211_ptr);
2754 if (err)
2755 goto out;
2756
e35e4d28 2757 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2758 if (err)
2759 goto out;
2760
2761#ifdef CONFIG_CFG80211_WEXT
2762 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2763#endif
dbd2fd65
JB
2764 }
2765
2766 out:
fffd0934 2767 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2768
41ade00f
JB
2769 return err;
2770}
2771
2772static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2773{
4c476991 2774 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2775 int err;
4c476991 2776 struct net_device *dev = info->user_ptr[1];
b9454e83 2777 struct key_parse key;
e31b8213 2778 const u8 *mac_addr = NULL;
41ade00f 2779
b9454e83
JB
2780 err = nl80211_parse_key(info, &key);
2781 if (err)
2782 return err;
41ade00f 2783
b9454e83 2784 if (!key.p.key)
41ade00f
JB
2785 return -EINVAL;
2786
41ade00f
JB
2787 if (info->attrs[NL80211_ATTR_MAC])
2788 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2789
e31b8213
JB
2790 if (key.type == -1) {
2791 if (mac_addr)
2792 key.type = NL80211_KEYTYPE_PAIRWISE;
2793 else
2794 key.type = NL80211_KEYTYPE_GROUP;
2795 }
2796
2797 /* for now */
2798 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2799 key.type != NL80211_KEYTYPE_GROUP)
2800 return -EINVAL;
2801
4c476991
JB
2802 if (!rdev->ops->add_key)
2803 return -EOPNOTSUPP;
25e47c18 2804
e31b8213
JB
2805 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2806 key.type == NL80211_KEYTYPE_PAIRWISE,
2807 mac_addr))
4c476991 2808 return -EINVAL;
41ade00f 2809
fffd0934
JB
2810 wdev_lock(dev->ieee80211_ptr);
2811 err = nl80211_key_allowed(dev->ieee80211_ptr);
2812 if (!err)
e35e4d28
HG
2813 err = rdev_add_key(rdev, dev, key.idx,
2814 key.type == NL80211_KEYTYPE_PAIRWISE,
2815 mac_addr, &key.p);
fffd0934 2816 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2817
41ade00f
JB
2818 return err;
2819}
2820
2821static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2822{
4c476991 2823 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2824 int err;
4c476991 2825 struct net_device *dev = info->user_ptr[1];
41ade00f 2826 u8 *mac_addr = NULL;
b9454e83 2827 struct key_parse key;
41ade00f 2828
b9454e83
JB
2829 err = nl80211_parse_key(info, &key);
2830 if (err)
2831 return err;
41ade00f
JB
2832
2833 if (info->attrs[NL80211_ATTR_MAC])
2834 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2835
e31b8213
JB
2836 if (key.type == -1) {
2837 if (mac_addr)
2838 key.type = NL80211_KEYTYPE_PAIRWISE;
2839 else
2840 key.type = NL80211_KEYTYPE_GROUP;
2841 }
2842
2843 /* for now */
2844 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2845 key.type != NL80211_KEYTYPE_GROUP)
2846 return -EINVAL;
2847
4c476991
JB
2848 if (!rdev->ops->del_key)
2849 return -EOPNOTSUPP;
41ade00f 2850
fffd0934
JB
2851 wdev_lock(dev->ieee80211_ptr);
2852 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2853
2854 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2855 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2856 err = -ENOENT;
2857
fffd0934 2858 if (!err)
e35e4d28
HG
2859 err = rdev_del_key(rdev, dev, key.idx,
2860 key.type == NL80211_KEYTYPE_PAIRWISE,
2861 mac_addr);
41ade00f 2862
3d23e349 2863#ifdef CONFIG_CFG80211_WEXT
08645126 2864 if (!err) {
b9454e83 2865 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2866 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2867 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2868 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2869 }
2870#endif
fffd0934 2871 wdev_unlock(dev->ieee80211_ptr);
08645126 2872
41ade00f
JB
2873 return err;
2874}
2875
77765eaf
VT
2876/* This function returns an error or the number of nested attributes */
2877static int validate_acl_mac_addrs(struct nlattr *nl_attr)
2878{
2879 struct nlattr *attr;
2880 int n_entries = 0, tmp;
2881
2882 nla_for_each_nested(attr, nl_attr, tmp) {
2883 if (nla_len(attr) != ETH_ALEN)
2884 return -EINVAL;
2885
2886 n_entries++;
2887 }
2888
2889 return n_entries;
2890}
2891
2892/*
2893 * This function parses ACL information and allocates memory for ACL data.
2894 * On successful return, the calling function is responsible to free the
2895 * ACL buffer returned by this function.
2896 */
2897static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
2898 struct genl_info *info)
2899{
2900 enum nl80211_acl_policy acl_policy;
2901 struct nlattr *attr;
2902 struct cfg80211_acl_data *acl;
2903 int i = 0, n_entries, tmp;
2904
2905 if (!wiphy->max_acl_mac_addrs)
2906 return ERR_PTR(-EOPNOTSUPP);
2907
2908 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
2909 return ERR_PTR(-EINVAL);
2910
2911 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
2912 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
2913 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
2914 return ERR_PTR(-EINVAL);
2915
2916 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
2917 return ERR_PTR(-EINVAL);
2918
2919 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
2920 if (n_entries < 0)
2921 return ERR_PTR(n_entries);
2922
2923 if (n_entries > wiphy->max_acl_mac_addrs)
2924 return ERR_PTR(-ENOTSUPP);
2925
2926 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
2927 GFP_KERNEL);
2928 if (!acl)
2929 return ERR_PTR(-ENOMEM);
2930
2931 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
2932 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
2933 i++;
2934 }
2935
2936 acl->n_acl_entries = n_entries;
2937 acl->acl_policy = acl_policy;
2938
2939 return acl;
2940}
2941
2942static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
2943{
2944 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2945 struct net_device *dev = info->user_ptr[1];
2946 struct cfg80211_acl_data *acl;
2947 int err;
2948
2949 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2950 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2951 return -EOPNOTSUPP;
2952
2953 if (!dev->ieee80211_ptr->beacon_interval)
2954 return -EINVAL;
2955
2956 acl = parse_acl_data(&rdev->wiphy, info);
2957 if (IS_ERR(acl))
2958 return PTR_ERR(acl);
2959
2960 err = rdev_set_mac_acl(rdev, dev, acl);
2961
2962 kfree(acl);
2963
2964 return err;
2965}
2966
a1193be8 2967static int nl80211_parse_beacon(struct nlattr *attrs[],
8860020e 2968 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2969{
8860020e 2970 bool haveinfo = false;
ed1b6cc7 2971
a1193be8
SW
2972 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) ||
2973 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) ||
2974 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2975 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2976 return -EINVAL;
2977
8860020e 2978 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2979
a1193be8
SW
2980 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
2981 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
2982 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
2983 if (!bcn->head_len)
2984 return -EINVAL;
2985 haveinfo = true;
ed1b6cc7
JB
2986 }
2987
a1193be8
SW
2988 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
2989 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
2990 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2991 haveinfo = true;
ed1b6cc7
JB
2992 }
2993
4c476991
JB
2994 if (!haveinfo)
2995 return -EINVAL;
3b85875a 2996
a1193be8
SW
2997 if (attrs[NL80211_ATTR_IE]) {
2998 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
2999 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
3000 }
3001
a1193be8 3002 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 3003 bcn->proberesp_ies =
a1193be8 3004 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 3005 bcn->proberesp_ies_len =
a1193be8 3006 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
3007 }
3008
a1193be8 3009 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 3010 bcn->assocresp_ies =
a1193be8 3011 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 3012 bcn->assocresp_ies_len =
a1193be8 3013 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
3014 }
3015
a1193be8
SW
3016 if (attrs[NL80211_ATTR_PROBE_RESP]) {
3017 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
3018 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
3019 }
3020
8860020e
JB
3021 return 0;
3022}
3023
46c1dd0c
FF
3024static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
3025 struct cfg80211_ap_settings *params)
3026{
3027 struct wireless_dev *wdev;
3028 bool ret = false;
3029
89a54e48 3030 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
3031 if (wdev->iftype != NL80211_IFTYPE_AP &&
3032 wdev->iftype != NL80211_IFTYPE_P2P_GO)
3033 continue;
3034
683b6d3b 3035 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
3036 continue;
3037
683b6d3b 3038 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
3039 ret = true;
3040 break;
3041 }
3042
46c1dd0c
FF
3043 return ret;
3044}
3045
e39e5b5e
JM
3046static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
3047 enum nl80211_auth_type auth_type,
3048 enum nl80211_commands cmd)
3049{
3050 if (auth_type > NL80211_AUTHTYPE_MAX)
3051 return false;
3052
3053 switch (cmd) {
3054 case NL80211_CMD_AUTHENTICATE:
3055 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
3056 auth_type == NL80211_AUTHTYPE_SAE)
3057 return false;
3058 return true;
3059 case NL80211_CMD_CONNECT:
3060 case NL80211_CMD_START_AP:
3061 /* SAE not supported yet */
3062 if (auth_type == NL80211_AUTHTYPE_SAE)
3063 return false;
3064 return true;
3065 default:
3066 return false;
3067 }
3068}
3069
8860020e
JB
3070static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
3071{
3072 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3073 struct net_device *dev = info->user_ptr[1];
3074 struct wireless_dev *wdev = dev->ieee80211_ptr;
3075 struct cfg80211_ap_settings params;
3076 int err;
04f39047 3077 u8 radar_detect_width = 0;
8860020e
JB
3078
3079 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3080 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3081 return -EOPNOTSUPP;
3082
3083 if (!rdev->ops->start_ap)
3084 return -EOPNOTSUPP;
3085
3086 if (wdev->beacon_interval)
3087 return -EALREADY;
3088
3089 memset(&params, 0, sizeof(params));
3090
3091 /* these are required for START_AP */
3092 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
3093 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
3094 !info->attrs[NL80211_ATTR_BEACON_HEAD])
3095 return -EINVAL;
3096
a1193be8 3097 err = nl80211_parse_beacon(info->attrs, &params.beacon);
8860020e
JB
3098 if (err)
3099 return err;
3100
3101 params.beacon_interval =
3102 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3103 params.dtim_period =
3104 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
3105
3106 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
3107 if (err)
3108 return err;
3109
3110 /*
3111 * In theory, some of these attributes should be required here
3112 * but since they were not used when the command was originally
3113 * added, keep them optional for old user space programs to let
3114 * them continue to work with drivers that do not need the
3115 * additional information -- drivers must check!
3116 */
3117 if (info->attrs[NL80211_ATTR_SSID]) {
3118 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3119 params.ssid_len =
3120 nla_len(info->attrs[NL80211_ATTR_SSID]);
3121 if (params.ssid_len == 0 ||
3122 params.ssid_len > IEEE80211_MAX_SSID_LEN)
3123 return -EINVAL;
3124 }
3125
3126 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
3127 params.hidden_ssid = nla_get_u32(
3128 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
3129 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
3130 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
3131 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
3132 return -EINVAL;
3133 }
3134
3135 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3136
3137 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3138 params.auth_type = nla_get_u32(
3139 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
3140 if (!nl80211_valid_auth_type(rdev, params.auth_type,
3141 NL80211_CMD_START_AP))
8860020e
JB
3142 return -EINVAL;
3143 } else
3144 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3145
3146 err = nl80211_crypto_settings(rdev, info, &params.crypto,
3147 NL80211_MAX_NR_CIPHER_SUITES);
3148 if (err)
3149 return err;
3150
1b658f11
VT
3151 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
3152 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
3153 return -EOPNOTSUPP;
3154 params.inactivity_timeout = nla_get_u16(
3155 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
3156 }
3157
53cabad7
JB
3158 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3159 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3160 return -EINVAL;
3161 params.p2p_ctwindow =
3162 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3163 if (params.p2p_ctwindow > 127)
3164 return -EINVAL;
3165 if (params.p2p_ctwindow != 0 &&
3166 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3167 return -EINVAL;
3168 }
3169
3170 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3171 u8 tmp;
3172
3173 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3174 return -EINVAL;
3175 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3176 if (tmp > 1)
3177 return -EINVAL;
3178 params.p2p_opp_ps = tmp;
3179 if (params.p2p_opp_ps != 0 &&
3180 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3181 return -EINVAL;
3182 }
3183
aa430da4 3184 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
3185 err = nl80211_parse_chandef(rdev, info, &params.chandef);
3186 if (err)
3187 return err;
3188 } else if (wdev->preset_chandef.chan) {
3189 params.chandef = wdev->preset_chandef;
46c1dd0c 3190 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
3191 return -EINVAL;
3192
683b6d3b 3193 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
3194 return -EINVAL;
3195
04f39047
SW
3196 err = cfg80211_chandef_dfs_required(wdev->wiphy, &params.chandef);
3197 if (err < 0)
3198 return err;
3199 if (err) {
3200 radar_detect_width = BIT(params.chandef.width);
3201 params.radar_required = true;
3202 }
3203
04f39047
SW
3204 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
3205 params.chandef.chan,
3206 CHAN_MODE_SHARED,
3207 radar_detect_width);
e4e32459
MK
3208 if (err)
3209 return err;
3210
77765eaf
VT
3211 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
3212 params.acl = parse_acl_data(&rdev->wiphy, info);
3213 if (IS_ERR(params.acl))
3214 return PTR_ERR(params.acl);
3215 }
3216
e35e4d28 3217 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 3218 if (!err) {
683b6d3b 3219 wdev->preset_chandef = params.chandef;
8860020e 3220 wdev->beacon_interval = params.beacon_interval;
683b6d3b 3221 wdev->channel = params.chandef.chan;
06e191e2
AQ
3222 wdev->ssid_len = params.ssid_len;
3223 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 3224 }
77765eaf
VT
3225
3226 kfree(params.acl);
3227
56d1893d 3228 return err;
ed1b6cc7
JB
3229}
3230
8860020e
JB
3231static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
3232{
3233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3234 struct net_device *dev = info->user_ptr[1];
3235 struct wireless_dev *wdev = dev->ieee80211_ptr;
3236 struct cfg80211_beacon_data params;
3237 int err;
3238
3239 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3240 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3241 return -EOPNOTSUPP;
3242
3243 if (!rdev->ops->change_beacon)
3244 return -EOPNOTSUPP;
3245
3246 if (!wdev->beacon_interval)
3247 return -EINVAL;
3248
a1193be8 3249 err = nl80211_parse_beacon(info->attrs, &params);
8860020e
JB
3250 if (err)
3251 return err;
3252
e35e4d28 3253 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
3254}
3255
3256static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 3257{
4c476991
JB
3258 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3259 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 3260
60771780 3261 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
3262}
3263
5727ef1b
JB
3264static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
3265 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
3266 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
3267 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 3268 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 3269 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 3270 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
3271};
3272
eccb8e8f 3273static int parse_station_flags(struct genl_info *info,
bdd3ae3d 3274 enum nl80211_iftype iftype,
eccb8e8f 3275 struct station_parameters *params)
5727ef1b
JB
3276{
3277 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 3278 struct nlattr *nla;
5727ef1b
JB
3279 int flag;
3280
eccb8e8f
JB
3281 /*
3282 * Try parsing the new attribute first so userspace
3283 * can specify both for older kernels.
3284 */
3285 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
3286 if (nla) {
3287 struct nl80211_sta_flag_update *sta_flags;
3288
3289 sta_flags = nla_data(nla);
3290 params->sta_flags_mask = sta_flags->mask;
3291 params->sta_flags_set = sta_flags->set;
77ee7c89 3292 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
3293 if ((params->sta_flags_mask |
3294 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
3295 return -EINVAL;
3296 return 0;
3297 }
3298
3299 /* if present, parse the old attribute */
5727ef1b 3300
eccb8e8f 3301 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
3302 if (!nla)
3303 return 0;
3304
3305 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
3306 nla, sta_flags_policy))
3307 return -EINVAL;
3308
bdd3ae3d
JB
3309 /*
3310 * Only allow certain flags for interface types so that
3311 * other attributes are silently ignored. Remember that
3312 * this is backward compatibility code with old userspace
3313 * and shouldn't be hit in other cases anyway.
3314 */
3315 switch (iftype) {
3316 case NL80211_IFTYPE_AP:
3317 case NL80211_IFTYPE_AP_VLAN:
3318 case NL80211_IFTYPE_P2P_GO:
3319 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3320 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3321 BIT(NL80211_STA_FLAG_WME) |
3322 BIT(NL80211_STA_FLAG_MFP);
3323 break;
3324 case NL80211_IFTYPE_P2P_CLIENT:
3325 case NL80211_IFTYPE_STATION:
3326 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3327 BIT(NL80211_STA_FLAG_TDLS_PEER);
3328 break;
3329 case NL80211_IFTYPE_MESH_POINT:
3330 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3331 BIT(NL80211_STA_FLAG_MFP) |
3332 BIT(NL80211_STA_FLAG_AUTHORIZED);
3333 default:
3334 return -EINVAL;
3335 }
5727ef1b 3336
3383b5a6
JB
3337 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
3338 if (flags[flag]) {
eccb8e8f 3339 params->sta_flags_set |= (1<<flag);
5727ef1b 3340
3383b5a6
JB
3341 /* no longer support new API additions in old API */
3342 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
3343 return -EINVAL;
3344 }
3345 }
3346
5727ef1b
JB
3347 return 0;
3348}
3349
c8dcfd8a
FF
3350static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
3351 int attr)
3352{
3353 struct nlattr *rate;
8eb41c8d
VK
3354 u32 bitrate;
3355 u16 bitrate_compat;
c8dcfd8a
FF
3356
3357 rate = nla_nest_start(msg, attr);
3358 if (!rate)
db9c64cf 3359 return false;
c8dcfd8a
FF
3360
3361 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
3362 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
3363 /* report 16-bit bitrate only if we can */
3364 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
3365 if (bitrate > 0 &&
3366 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
3367 return false;
3368 if (bitrate_compat > 0 &&
3369 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
3370 return false;
3371
3372 if (info->flags & RATE_INFO_FLAGS_MCS) {
3373 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
3374 return false;
3375 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3376 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3377 return false;
3378 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3379 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3380 return false;
3381 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3382 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3383 return false;
3384 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3385 return false;
3386 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3387 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3388 return false;
3389 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
3390 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
3391 return false;
3392 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
3393 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
3394 return false;
3395 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
3396 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
3397 return false;
3398 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3399 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3400 return false;
3401 }
c8dcfd8a
FF
3402
3403 nla_nest_end(msg, rate);
3404 return true;
c8dcfd8a
FF
3405}
3406
119363c7
FF
3407static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
3408 int id)
3409{
3410 void *attr;
3411 int i = 0;
3412
3413 if (!mask)
3414 return true;
3415
3416 attr = nla_nest_start(msg, id);
3417 if (!attr)
3418 return false;
3419
3420 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
3421 if (!(mask & BIT(i)))
3422 continue;
3423
3424 if (nla_put_u8(msg, i, signal[i]))
3425 return false;
3426 }
3427
3428 nla_nest_end(msg, attr);
3429
3430 return true;
3431}
3432
15e47304 3433static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
3434 int flags,
3435 struct cfg80211_registered_device *rdev,
3436 struct net_device *dev,
98b62183 3437 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3438{
3439 void *hdr;
f4263c98 3440 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3441
15e47304 3442 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
3443 if (!hdr)
3444 return -1;
3445
9360ffd1
DM
3446 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3447 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3448 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3449 goto nla_put_failure;
f5ea9120 3450
2ec600d6
LCC
3451 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3452 if (!sinfoattr)
fd5b74dc 3453 goto nla_put_failure;
9360ffd1
DM
3454 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
3455 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
3456 sinfo->connected_time))
3457 goto nla_put_failure;
3458 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
3459 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
3460 sinfo->inactive_time))
3461 goto nla_put_failure;
42745e03
VK
3462 if ((sinfo->filled & (STATION_INFO_RX_BYTES |
3463 STATION_INFO_RX_BYTES64)) &&
9360ffd1 3464 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 3465 (u32)sinfo->rx_bytes))
9360ffd1 3466 goto nla_put_failure;
42745e03 3467 if ((sinfo->filled & (STATION_INFO_TX_BYTES |
4325d724 3468 STATION_INFO_TX_BYTES64)) &&
9360ffd1 3469 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
3470 (u32)sinfo->tx_bytes))
3471 goto nla_put_failure;
3472 if ((sinfo->filled & STATION_INFO_RX_BYTES64) &&
3473 nla_put_u64(msg, NL80211_STA_INFO_RX_BYTES64,
3474 sinfo->rx_bytes))
3475 goto nla_put_failure;
3476 if ((sinfo->filled & STATION_INFO_TX_BYTES64) &&
3477 nla_put_u64(msg, NL80211_STA_INFO_TX_BYTES64,
9360ffd1
DM
3478 sinfo->tx_bytes))
3479 goto nla_put_failure;
3480 if ((sinfo->filled & STATION_INFO_LLID) &&
3481 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
3482 goto nla_put_failure;
3483 if ((sinfo->filled & STATION_INFO_PLID) &&
3484 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
3485 goto nla_put_failure;
3486 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
3487 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
3488 sinfo->plink_state))
3489 goto nla_put_failure;
66266b3a
JL
3490 switch (rdev->wiphy.signal_type) {
3491 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
3492 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
3493 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
3494 sinfo->signal))
3495 goto nla_put_failure;
3496 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
3497 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
3498 sinfo->signal_avg))
3499 goto nla_put_failure;
66266b3a
JL
3500 break;
3501 default:
3502 break;
3503 }
119363c7
FF
3504 if (sinfo->filled & STATION_INFO_CHAIN_SIGNAL) {
3505 if (!nl80211_put_signal(msg, sinfo->chains,
3506 sinfo->chain_signal,
3507 NL80211_STA_INFO_CHAIN_SIGNAL))
3508 goto nla_put_failure;
3509 }
3510 if (sinfo->filled & STATION_INFO_CHAIN_SIGNAL_AVG) {
3511 if (!nl80211_put_signal(msg, sinfo->chains,
3512 sinfo->chain_signal_avg,
3513 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
3514 goto nla_put_failure;
3515 }
420e7fab 3516 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3517 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3518 NL80211_STA_INFO_TX_BITRATE))
3519 goto nla_put_failure;
3520 }
3521 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3522 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3523 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3524 goto nla_put_failure;
420e7fab 3525 }
9360ffd1
DM
3526 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3527 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3528 sinfo->rx_packets))
3529 goto nla_put_failure;
3530 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3531 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3532 sinfo->tx_packets))
3533 goto nla_put_failure;
3534 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3535 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3536 sinfo->tx_retries))
3537 goto nla_put_failure;
3538 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3539 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3540 sinfo->tx_failed))
3541 goto nla_put_failure;
3542 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3543 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3544 sinfo->beacon_loss_count))
3545 goto nla_put_failure;
3b1c5a53
MP
3546 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3547 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3548 sinfo->local_pm))
3549 goto nla_put_failure;
3550 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3551 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3552 sinfo->peer_pm))
3553 goto nla_put_failure;
3554 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3555 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3556 sinfo->nonpeer_pm))
3557 goto nla_put_failure;
f4263c98
PS
3558 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3559 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3560 if (!bss_param)
3561 goto nla_put_failure;
3562
9360ffd1
DM
3563 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3564 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3565 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3566 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3567 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3568 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3569 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3570 sinfo->bss_param.dtim_period) ||
3571 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3572 sinfo->bss_param.beacon_interval))
3573 goto nla_put_failure;
f4263c98
PS
3574
3575 nla_nest_end(msg, bss_param);
3576 }
9360ffd1
DM
3577 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3578 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3579 sizeof(struct nl80211_sta_flag_update),
3580 &sinfo->sta_flags))
3581 goto nla_put_failure;
7eab0f64
JL
3582 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3583 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3584 sinfo->t_offset))
3585 goto nla_put_failure;
2ec600d6 3586 nla_nest_end(msg, sinfoattr);
fd5b74dc 3587
9360ffd1
DM
3588 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3589 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3590 sinfo->assoc_req_ies))
3591 goto nla_put_failure;
50d3dfb7 3592
fd5b74dc
JB
3593 return genlmsg_end(msg, hdr);
3594
3595 nla_put_failure:
bc3ed28c
TG
3596 genlmsg_cancel(msg, hdr);
3597 return -EMSGSIZE;
fd5b74dc
JB
3598}
3599
2ec600d6 3600static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3601 struct netlink_callback *cb)
2ec600d6 3602{
2ec600d6
LCC
3603 struct station_info sinfo;
3604 struct cfg80211_registered_device *dev;
97990a06 3605 struct wireless_dev *wdev;
2ec600d6 3606 u8 mac_addr[ETH_ALEN];
97990a06 3607 int sta_idx = cb->args[2];
2ec600d6 3608 int err;
2ec600d6 3609
97990a06 3610 err = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
3611 if (err)
3612 return err;
bba95fef 3613
97990a06
JB
3614 if (!wdev->netdev) {
3615 err = -EINVAL;
3616 goto out_err;
3617 }
3618
bba95fef 3619 if (!dev->ops->dump_station) {
eec60b03 3620 err = -EOPNOTSUPP;
bba95fef
JB
3621 goto out_err;
3622 }
3623
bba95fef 3624 while (1) {
f612cedf 3625 memset(&sinfo, 0, sizeof(sinfo));
97990a06 3626 err = rdev_dump_station(dev, wdev->netdev, sta_idx,
e35e4d28 3627 mac_addr, &sinfo);
bba95fef
JB
3628 if (err == -ENOENT)
3629 break;
3630 if (err)
3b85875a 3631 goto out_err;
bba95fef
JB
3632
3633 if (nl80211_send_station(skb,
15e47304 3634 NETLINK_CB(cb->skb).portid,
bba95fef 3635 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 3636 dev, wdev->netdev, mac_addr,
bba95fef
JB
3637 &sinfo) < 0)
3638 goto out;
3639
3640 sta_idx++;
3641 }
3642
3643
3644 out:
97990a06 3645 cb->args[2] = sta_idx;
bba95fef 3646 err = skb->len;
bba95fef 3647 out_err:
97990a06 3648 nl80211_finish_wdev_dump(dev);
bba95fef
JB
3649
3650 return err;
2ec600d6 3651}
fd5b74dc 3652
5727ef1b
JB
3653static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3654{
4c476991
JB
3655 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3656 struct net_device *dev = info->user_ptr[1];
2ec600d6 3657 struct station_info sinfo;
fd5b74dc
JB
3658 struct sk_buff *msg;
3659 u8 *mac_addr = NULL;
4c476991 3660 int err;
fd5b74dc 3661
2ec600d6 3662 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3663
3664 if (!info->attrs[NL80211_ATTR_MAC])
3665 return -EINVAL;
3666
3667 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3668
4c476991
JB
3669 if (!rdev->ops->get_station)
3670 return -EOPNOTSUPP;
3b85875a 3671
e35e4d28 3672 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3673 if (err)
4c476991 3674 return err;
2ec600d6 3675
fd2120ca 3676 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3677 if (!msg)
4c476991 3678 return -ENOMEM;
fd5b74dc 3679
15e47304 3680 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3681 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3682 nlmsg_free(msg);
3683 return -ENOBUFS;
3684 }
3b85875a 3685
4c476991 3686 return genlmsg_reply(msg, info);
5727ef1b
JB
3687}
3688
77ee7c89
JB
3689int cfg80211_check_station_change(struct wiphy *wiphy,
3690 struct station_parameters *params,
3691 enum cfg80211_station_type statype)
3692{
3693 if (params->listen_interval != -1)
3694 return -EINVAL;
3695 if (params->aid)
3696 return -EINVAL;
3697
3698 /* When you run into this, adjust the code below for the new flag */
3699 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
3700
3701 switch (statype) {
eef941e6
TP
3702 case CFG80211_STA_MESH_PEER_KERNEL:
3703 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3704 /*
3705 * No ignoring the TDLS flag here -- the userspace mesh
3706 * code doesn't have the bug of including TDLS in the
3707 * mask everywhere.
3708 */
3709 if (params->sta_flags_mask &
3710 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3711 BIT(NL80211_STA_FLAG_MFP) |
3712 BIT(NL80211_STA_FLAG_AUTHORIZED)))
3713 return -EINVAL;
3714 break;
3715 case CFG80211_STA_TDLS_PEER_SETUP:
3716 case CFG80211_STA_TDLS_PEER_ACTIVE:
3717 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3718 return -EINVAL;
3719 /* ignore since it can't change */
3720 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3721 break;
3722 default:
3723 /* disallow mesh-specific things */
3724 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3725 return -EINVAL;
3726 if (params->local_pm)
3727 return -EINVAL;
3728 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3729 return -EINVAL;
3730 }
3731
3732 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
3733 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
3734 /* TDLS can't be set, ... */
3735 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3736 return -EINVAL;
3737 /*
3738 * ... but don't bother the driver with it. This works around
3739 * a hostapd/wpa_supplicant issue -- it always includes the
3740 * TLDS_PEER flag in the mask even for AP mode.
3741 */
3742 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3743 }
3744
3745 if (statype != CFG80211_STA_TDLS_PEER_SETUP) {
3746 /* reject other things that can't change */
3747 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
3748 return -EINVAL;
3749 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
3750 return -EINVAL;
3751 if (params->supported_rates)
3752 return -EINVAL;
3753 if (params->ext_capab || params->ht_capa || params->vht_capa)
3754 return -EINVAL;
3755 }
3756
3757 if (statype != CFG80211_STA_AP_CLIENT) {
3758 if (params->vlan)
3759 return -EINVAL;
3760 }
3761
3762 switch (statype) {
3763 case CFG80211_STA_AP_MLME_CLIENT:
3764 /* Use this only for authorizing/unauthorizing a station */
3765 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
3766 return -EOPNOTSUPP;
3767 break;
3768 case CFG80211_STA_AP_CLIENT:
3769 /* accept only the listed bits */
3770 if (params->sta_flags_mask &
3771 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3772 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3773 BIT(NL80211_STA_FLAG_ASSOCIATED) |
3774 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3775 BIT(NL80211_STA_FLAG_WME) |
3776 BIT(NL80211_STA_FLAG_MFP)))
3777 return -EINVAL;
3778
3779 /* but authenticated/associated only if driver handles it */
3780 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3781 params->sta_flags_mask &
3782 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3783 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3784 return -EINVAL;
3785 break;
3786 case CFG80211_STA_IBSS:
3787 case CFG80211_STA_AP_STA:
3788 /* reject any changes other than AUTHORIZED */
3789 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3790 return -EINVAL;
3791 break;
3792 case CFG80211_STA_TDLS_PEER_SETUP:
3793 /* reject any changes other than AUTHORIZED or WME */
3794 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3795 BIT(NL80211_STA_FLAG_WME)))
3796 return -EINVAL;
3797 /* force (at least) rates when authorizing */
3798 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
3799 !params->supported_rates)
3800 return -EINVAL;
3801 break;
3802 case CFG80211_STA_TDLS_PEER_ACTIVE:
3803 /* reject any changes */
3804 return -EINVAL;
eef941e6 3805 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
3806 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3807 return -EINVAL;
3808 break;
eef941e6 3809 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3810 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3811 return -EINVAL;
3812 break;
3813 }
3814
3815 return 0;
3816}
3817EXPORT_SYMBOL(cfg80211_check_station_change);
3818
5727ef1b 3819/*
c258d2de 3820 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3821 */
80b99899
JB
3822static struct net_device *get_vlan(struct genl_info *info,
3823 struct cfg80211_registered_device *rdev)
5727ef1b 3824{
463d0183 3825 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3826 struct net_device *v;
3827 int ret;
3828
3829 if (!vlanattr)
3830 return NULL;
3831
3832 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3833 if (!v)
3834 return ERR_PTR(-ENODEV);
3835
3836 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3837 ret = -EINVAL;
3838 goto error;
5727ef1b 3839 }
80b99899 3840
77ee7c89
JB
3841 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
3842 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3843 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
3844 ret = -EINVAL;
3845 goto error;
3846 }
3847
80b99899
JB
3848 if (!netif_running(v)) {
3849 ret = -ENETDOWN;
3850 goto error;
3851 }
3852
3853 return v;
3854 error:
3855 dev_put(v);
3856 return ERR_PTR(ret);
5727ef1b
JB
3857}
3858
df881293
JM
3859static struct nla_policy
3860nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3861 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3862 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3863};
3864
ff276691
JB
3865static int nl80211_parse_sta_wme(struct genl_info *info,
3866 struct station_parameters *params)
df881293 3867{
df881293
JM
3868 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3869 struct nlattr *nla;
3870 int err;
3871
df881293
JM
3872 /* parse WME attributes if present */
3873 if (!info->attrs[NL80211_ATTR_STA_WME])
3874 return 0;
3875
3876 nla = info->attrs[NL80211_ATTR_STA_WME];
3877 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3878 nl80211_sta_wme_policy);
3879 if (err)
3880 return err;
3881
3882 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3883 params->uapsd_queues = nla_get_u8(
3884 tb[NL80211_STA_WME_UAPSD_QUEUES]);
3885 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3886 return -EINVAL;
3887
3888 if (tb[NL80211_STA_WME_MAX_SP])
3889 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
3890
3891 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3892 return -EINVAL;
3893
3894 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3895
3896 return 0;
3897}
3898
ff276691
JB
3899static int nl80211_set_station_tdls(struct genl_info *info,
3900 struct station_parameters *params)
3901{
3902 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
3903 if (info->attrs[NL80211_ATTR_PEER_AID])
3904 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
3905 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3906 params->ht_capa =
3907 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
3908 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3909 params->vht_capa =
3910 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3911
3912 return nl80211_parse_sta_wme(info, params);
3913}
3914
5727ef1b
JB
3915static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3916{
4c476991 3917 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3918 struct net_device *dev = info->user_ptr[1];
5727ef1b 3919 struct station_parameters params;
77ee7c89
JB
3920 u8 *mac_addr;
3921 int err;
5727ef1b
JB
3922
3923 memset(&params, 0, sizeof(params));
3924
3925 params.listen_interval = -1;
3926
77ee7c89
JB
3927 if (!rdev->ops->change_station)
3928 return -EOPNOTSUPP;
3929
5727ef1b
JB
3930 if (info->attrs[NL80211_ATTR_STA_AID])
3931 return -EINVAL;
3932
3933 if (!info->attrs[NL80211_ATTR_MAC])
3934 return -EINVAL;
3935
3936 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3937
3938 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3939 params.supported_rates =
3940 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3941 params.supported_rates_len =
3942 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3943 }
3944
9d62a986
JM
3945 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
3946 params.capability =
3947 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
3948 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
3949 }
3950
3951 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
3952 params.ext_capab =
3953 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
3954 params.ext_capab_len =
3955 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
3956 }
3957
df881293 3958 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
ba23d206 3959 return -EINVAL;
36aedc90 3960
bdd3ae3d 3961 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3962 return -EINVAL;
3963
f8bacc21 3964 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
2ec600d6 3965 params.plink_action =
f8bacc21
JB
3966 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3967 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
3968 return -EINVAL;
3969 }
2ec600d6 3970
f8bacc21 3971 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 3972 params.plink_state =
f8bacc21
JB
3973 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3974 if (params.plink_state >= NUM_NL80211_PLINK_STATES)
3975 return -EINVAL;
3976 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
3977 }
9c3990aa 3978
3b1c5a53
MP
3979 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
3980 enum nl80211_mesh_power_mode pm = nla_get_u32(
3981 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
3982
3983 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
3984 pm > NL80211_MESH_POWER_MAX)
3985 return -EINVAL;
3986
3987 params.local_pm = pm;
3988 }
3989
77ee7c89
JB
3990 /* Include parameters for TDLS peer (will check later) */
3991 err = nl80211_set_station_tdls(info, &params);
3992 if (err)
3993 return err;
3994
3995 params.vlan = get_vlan(info, rdev);
3996 if (IS_ERR(params.vlan))
3997 return PTR_ERR(params.vlan);
3998
a97f4424
JB
3999 switch (dev->ieee80211_ptr->iftype) {
4000 case NL80211_IFTYPE_AP:
4001 case NL80211_IFTYPE_AP_VLAN:
074ac8df 4002 case NL80211_IFTYPE_P2P_GO:
074ac8df 4003 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 4004 case NL80211_IFTYPE_STATION:
267335d6 4005 case NL80211_IFTYPE_ADHOC:
a97f4424 4006 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
4007 break;
4008 default:
77ee7c89
JB
4009 err = -EOPNOTSUPP;
4010 goto out_put_vlan;
034d655e
JB
4011 }
4012
77ee7c89 4013 /* driver will call cfg80211_check_station_change() */
e35e4d28 4014 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 4015
77ee7c89 4016 out_put_vlan:
5727ef1b
JB
4017 if (params.vlan)
4018 dev_put(params.vlan);
3b85875a 4019
5727ef1b
JB
4020 return err;
4021}
4022
4023static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
4024{
4c476991 4025 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 4026 int err;
4c476991 4027 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4028 struct station_parameters params;
4029 u8 *mac_addr = NULL;
4030
4031 memset(&params, 0, sizeof(params));
4032
984c311b
JB
4033 if (!rdev->ops->add_station)
4034 return -EOPNOTSUPP;
4035
5727ef1b
JB
4036 if (!info->attrs[NL80211_ATTR_MAC])
4037 return -EINVAL;
4038
5727ef1b
JB
4039 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
4040 return -EINVAL;
4041
4042 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
4043 return -EINVAL;
4044
5e4b6f56
JM
4045 if (!info->attrs[NL80211_ATTR_STA_AID] &&
4046 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
4047 return -EINVAL;
4048
5727ef1b
JB
4049 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4050 params.supported_rates =
4051 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4052 params.supported_rates_len =
4053 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4054 params.listen_interval =
4055 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 4056
3d124ea2 4057 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 4058 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
4059 else
4060 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
0e956c13
TLSC
4061 if (!params.aid || params.aid > IEEE80211_MAX_AID)
4062 return -EINVAL;
51b50fbe 4063
9d62a986
JM
4064 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4065 params.capability =
4066 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4067 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4068 }
4069
4070 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4071 params.ext_capab =
4072 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4073 params.ext_capab_len =
4074 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4075 }
4076
36aedc90
JM
4077 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4078 params.ht_capa =
4079 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 4080
f461be3e
MP
4081 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4082 params.vht_capa =
4083 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4084
f8bacc21 4085 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
96b78dff 4086 params.plink_action =
f8bacc21
JB
4087 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4088 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4089 return -EINVAL;
4090 }
96b78dff 4091
ff276691
JB
4092 err = nl80211_parse_sta_wme(info, &params);
4093 if (err)
4094 return err;
bdd90d5e 4095
bdd3ae3d 4096 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4097 return -EINVAL;
4098
77ee7c89
JB
4099 /* When you run into this, adjust the code below for the new flag */
4100 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
4101
bdd90d5e
JB
4102 switch (dev->ieee80211_ptr->iftype) {
4103 case NL80211_IFTYPE_AP:
4104 case NL80211_IFTYPE_AP_VLAN:
4105 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
4106 /* ignore WME attributes if iface/sta is not capable */
4107 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
4108 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
4109 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 4110
bdd90d5e 4111 /* TDLS peers cannot be added */
3d124ea2
JM
4112 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4113 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 4114 return -EINVAL;
bdd90d5e
JB
4115 /* but don't bother the driver with it */
4116 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 4117
d582cffb
JB
4118 /* allow authenticated/associated only if driver handles it */
4119 if (!(rdev->wiphy.features &
4120 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4121 params.sta_flags_mask &
4122 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4123 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4124 return -EINVAL;
4125
bdd90d5e
JB
4126 /* must be last in here for error handling */
4127 params.vlan = get_vlan(info, rdev);
4128 if (IS_ERR(params.vlan))
4129 return PTR_ERR(params.vlan);
4130 break;
4131 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
4132 /* ignore uAPSD data */
4133 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4134
d582cffb
JB
4135 /* associated is disallowed */
4136 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
4137 return -EINVAL;
bdd90d5e 4138 /* TDLS peers cannot be added */
3d124ea2
JM
4139 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4140 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
4141 return -EINVAL;
4142 break;
4143 case NL80211_IFTYPE_STATION:
93d08f0b 4144 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
4145 /* ignore uAPSD data */
4146 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4147
77ee7c89
JB
4148 /* these are disallowed */
4149 if (params.sta_flags_mask &
4150 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
4151 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 4152 return -EINVAL;
bdd90d5e
JB
4153 /* Only TDLS peers can be added */
4154 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
4155 return -EINVAL;
4156 /* Can only add if TDLS ... */
4157 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
4158 return -EOPNOTSUPP;
4159 /* ... with external setup is supported */
4160 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
4161 return -EOPNOTSUPP;
77ee7c89
JB
4162 /*
4163 * Older wpa_supplicant versions always mark the TDLS peer
4164 * as authorized, but it shouldn't yet be.
4165 */
4166 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
4167 break;
4168 default:
4169 return -EOPNOTSUPP;
c75786c9
EP
4170 }
4171
bdd90d5e 4172 /* be aware of params.vlan when changing code here */
5727ef1b 4173
e35e4d28 4174 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 4175
5727ef1b
JB
4176 if (params.vlan)
4177 dev_put(params.vlan);
5727ef1b
JB
4178 return err;
4179}
4180
4181static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
4182{
4c476991
JB
4183 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4184 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4185 u8 *mac_addr = NULL;
4186
4187 if (info->attrs[NL80211_ATTR_MAC])
4188 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4189
e80cf853 4190 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 4191 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 4192 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4193 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4194 return -EINVAL;
5727ef1b 4195
4c476991
JB
4196 if (!rdev->ops->del_station)
4197 return -EOPNOTSUPP;
3b85875a 4198
e35e4d28 4199 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
4200}
4201
15e47304 4202static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
4203 int flags, struct net_device *dev,
4204 u8 *dst, u8 *next_hop,
4205 struct mpath_info *pinfo)
4206{
4207 void *hdr;
4208 struct nlattr *pinfoattr;
4209
15e47304 4210 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
4211 if (!hdr)
4212 return -1;
4213
9360ffd1
DM
4214 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4215 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
4216 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
4217 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
4218 goto nla_put_failure;
f5ea9120 4219
2ec600d6
LCC
4220 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
4221 if (!pinfoattr)
4222 goto nla_put_failure;
9360ffd1
DM
4223 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
4224 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
4225 pinfo->frame_qlen))
4226 goto nla_put_failure;
4227 if (((pinfo->filled & MPATH_INFO_SN) &&
4228 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
4229 ((pinfo->filled & MPATH_INFO_METRIC) &&
4230 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
4231 pinfo->metric)) ||
4232 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
4233 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
4234 pinfo->exptime)) ||
4235 ((pinfo->filled & MPATH_INFO_FLAGS) &&
4236 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
4237 pinfo->flags)) ||
4238 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
4239 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
4240 pinfo->discovery_timeout)) ||
4241 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
4242 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
4243 pinfo->discovery_retries)))
4244 goto nla_put_failure;
2ec600d6
LCC
4245
4246 nla_nest_end(msg, pinfoattr);
4247
4248 return genlmsg_end(msg, hdr);
4249
4250 nla_put_failure:
bc3ed28c
TG
4251 genlmsg_cancel(msg, hdr);
4252 return -EMSGSIZE;
2ec600d6
LCC
4253}
4254
4255static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 4256 struct netlink_callback *cb)
2ec600d6 4257{
2ec600d6
LCC
4258 struct mpath_info pinfo;
4259 struct cfg80211_registered_device *dev;
97990a06 4260 struct wireless_dev *wdev;
2ec600d6
LCC
4261 u8 dst[ETH_ALEN];
4262 u8 next_hop[ETH_ALEN];
97990a06 4263 int path_idx = cb->args[2];
2ec600d6 4264 int err;
2ec600d6 4265
97990a06 4266 err = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
4267 if (err)
4268 return err;
bba95fef
JB
4269
4270 if (!dev->ops->dump_mpath) {
eec60b03 4271 err = -EOPNOTSUPP;
bba95fef
JB
4272 goto out_err;
4273 }
4274
97990a06 4275 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 4276 err = -EOPNOTSUPP;
0448b5fc 4277 goto out_err;
eec60b03
JM
4278 }
4279
bba95fef 4280 while (1) {
97990a06
JB
4281 err = rdev_dump_mpath(dev, wdev->netdev, path_idx, dst,
4282 next_hop, &pinfo);
bba95fef 4283 if (err == -ENOENT)
2ec600d6 4284 break;
bba95fef 4285 if (err)
3b85875a 4286 goto out_err;
2ec600d6 4287
15e47304 4288 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 4289 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 4290 wdev->netdev, dst, next_hop,
bba95fef
JB
4291 &pinfo) < 0)
4292 goto out;
2ec600d6 4293
bba95fef 4294 path_idx++;
2ec600d6 4295 }
2ec600d6 4296
2ec600d6 4297
bba95fef 4298 out:
97990a06 4299 cb->args[2] = path_idx;
bba95fef 4300 err = skb->len;
bba95fef 4301 out_err:
97990a06 4302 nl80211_finish_wdev_dump(dev);
bba95fef 4303 return err;
2ec600d6
LCC
4304}
4305
4306static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
4307{
4c476991 4308 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 4309 int err;
4c476991 4310 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4311 struct mpath_info pinfo;
4312 struct sk_buff *msg;
4313 u8 *dst = NULL;
4314 u8 next_hop[ETH_ALEN];
4315
4316 memset(&pinfo, 0, sizeof(pinfo));
4317
4318 if (!info->attrs[NL80211_ATTR_MAC])
4319 return -EINVAL;
4320
4321 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4322
4c476991
JB
4323 if (!rdev->ops->get_mpath)
4324 return -EOPNOTSUPP;
2ec600d6 4325
4c476991
JB
4326 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4327 return -EOPNOTSUPP;
eec60b03 4328
e35e4d28 4329 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 4330 if (err)
4c476991 4331 return err;
2ec600d6 4332
fd2120ca 4333 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 4334 if (!msg)
4c476991 4335 return -ENOMEM;
2ec600d6 4336
15e47304 4337 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
4338 dev, dst, next_hop, &pinfo) < 0) {
4339 nlmsg_free(msg);
4340 return -ENOBUFS;
4341 }
3b85875a 4342
4c476991 4343 return genlmsg_reply(msg, info);
2ec600d6
LCC
4344}
4345
4346static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
4347{
4c476991
JB
4348 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4349 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4350 u8 *dst = NULL;
4351 u8 *next_hop = NULL;
4352
4353 if (!info->attrs[NL80211_ATTR_MAC])
4354 return -EINVAL;
4355
4356 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4357 return -EINVAL;
4358
4359 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4360 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4361
4c476991
JB
4362 if (!rdev->ops->change_mpath)
4363 return -EOPNOTSUPP;
35a8efe1 4364
4c476991
JB
4365 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4366 return -EOPNOTSUPP;
2ec600d6 4367
e35e4d28 4368 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 4369}
4c476991 4370
2ec600d6
LCC
4371static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
4372{
4c476991
JB
4373 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4374 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4375 u8 *dst = NULL;
4376 u8 *next_hop = NULL;
4377
4378 if (!info->attrs[NL80211_ATTR_MAC])
4379 return -EINVAL;
4380
4381 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4382 return -EINVAL;
4383
4384 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4385 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4386
4c476991
JB
4387 if (!rdev->ops->add_mpath)
4388 return -EOPNOTSUPP;
35a8efe1 4389
4c476991
JB
4390 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4391 return -EOPNOTSUPP;
2ec600d6 4392
e35e4d28 4393 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
4394}
4395
4396static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
4397{
4c476991
JB
4398 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4399 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4400 u8 *dst = NULL;
4401
4402 if (info->attrs[NL80211_ATTR_MAC])
4403 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4404
4c476991
JB
4405 if (!rdev->ops->del_mpath)
4406 return -EOPNOTSUPP;
3b85875a 4407
e35e4d28 4408 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
4409}
4410
9f1ba906
JM
4411static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
4412{
4c476991
JB
4413 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4414 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
4415 struct bss_parameters params;
4416
4417 memset(&params, 0, sizeof(params));
4418 /* default to not changing parameters */
4419 params.use_cts_prot = -1;
4420 params.use_short_preamble = -1;
4421 params.use_short_slot_time = -1;
fd8aaaf3 4422 params.ap_isolate = -1;
50b12f59 4423 params.ht_opmode = -1;
53cabad7
JB
4424 params.p2p_ctwindow = -1;
4425 params.p2p_opp_ps = -1;
9f1ba906
JM
4426
4427 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
4428 params.use_cts_prot =
4429 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
4430 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
4431 params.use_short_preamble =
4432 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
4433 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
4434 params.use_short_slot_time =
4435 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
4436 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4437 params.basic_rates =
4438 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4439 params.basic_rates_len =
4440 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4441 }
fd8aaaf3
FF
4442 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
4443 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
4444 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
4445 params.ht_opmode =
4446 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 4447
53cabad7
JB
4448 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
4449 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4450 return -EINVAL;
4451 params.p2p_ctwindow =
4452 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
4453 if (params.p2p_ctwindow < 0)
4454 return -EINVAL;
4455 if (params.p2p_ctwindow != 0 &&
4456 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
4457 return -EINVAL;
4458 }
4459
4460 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
4461 u8 tmp;
4462
4463 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4464 return -EINVAL;
4465 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
4466 if (tmp > 1)
4467 return -EINVAL;
4468 params.p2p_opp_ps = tmp;
4469 if (params.p2p_opp_ps &&
4470 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
4471 return -EINVAL;
4472 }
4473
4c476991
JB
4474 if (!rdev->ops->change_bss)
4475 return -EOPNOTSUPP;
9f1ba906 4476
074ac8df 4477 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
4478 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4479 return -EOPNOTSUPP;
3b85875a 4480
e35e4d28 4481 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
4482}
4483
b54452b0 4484static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
4485 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
4486 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
4487 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
4488 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
4489 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
4490 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
4491};
4492
4493static int parse_reg_rule(struct nlattr *tb[],
4494 struct ieee80211_reg_rule *reg_rule)
4495{
4496 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
4497 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
4498
4499 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
4500 return -EINVAL;
4501 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
4502 return -EINVAL;
4503 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
4504 return -EINVAL;
4505 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
4506 return -EINVAL;
4507 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
4508 return -EINVAL;
4509
4510 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
4511
4512 freq_range->start_freq_khz =
4513 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
4514 freq_range->end_freq_khz =
4515 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
4516 freq_range->max_bandwidth_khz =
4517 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
4518
4519 power_rule->max_eirp =
4520 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
4521
4522 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
4523 power_rule->max_antenna_gain =
4524 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
4525
4526 return 0;
4527}
4528
4529static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
4530{
4531 int r;
4532 char *data = NULL;
57b5ce07 4533 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 4534
80778f18
LR
4535 /*
4536 * You should only get this when cfg80211 hasn't yet initialized
4537 * completely when built-in to the kernel right between the time
4538 * window between nl80211_init() and regulatory_init(), if that is
4539 * even possible.
4540 */
458f4f9e 4541 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 4542 return -EINPROGRESS;
80778f18 4543
fe33eb39
LR
4544 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4545 return -EINVAL;
b2e1b302
LR
4546
4547 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4548
57b5ce07
LR
4549 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
4550 user_reg_hint_type =
4551 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
4552 else
4553 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
4554
4555 switch (user_reg_hint_type) {
4556 case NL80211_USER_REG_HINT_USER:
4557 case NL80211_USER_REG_HINT_CELL_BASE:
4558 break;
4559 default:
4560 return -EINVAL;
4561 }
4562
4563 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 4564
b2e1b302
LR
4565 return r;
4566}
4567
24bdd9f4 4568static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 4569 struct genl_info *info)
93da9cc1 4570{
4c476991 4571 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4572 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
4573 struct wireless_dev *wdev = dev->ieee80211_ptr;
4574 struct mesh_config cur_params;
4575 int err = 0;
93da9cc1 4576 void *hdr;
4577 struct nlattr *pinfoattr;
4578 struct sk_buff *msg;
4579
29cbe68c
JB
4580 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4581 return -EOPNOTSUPP;
4582
24bdd9f4 4583 if (!rdev->ops->get_mesh_config)
4c476991 4584 return -EOPNOTSUPP;
f3f92586 4585
29cbe68c
JB
4586 wdev_lock(wdev);
4587 /* If not connected, get default parameters */
4588 if (!wdev->mesh_id_len)
4589 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
4590 else
e35e4d28 4591 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
4592 wdev_unlock(wdev);
4593
93da9cc1 4594 if (err)
4c476991 4595 return err;
93da9cc1 4596
4597 /* Draw up a netlink message to send back */
fd2120ca 4598 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4599 if (!msg)
4600 return -ENOMEM;
15e47304 4601 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 4602 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 4603 if (!hdr)
efe1cf0c 4604 goto out;
24bdd9f4 4605 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 4606 if (!pinfoattr)
4607 goto nla_put_failure;
9360ffd1
DM
4608 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4609 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
4610 cur_params.dot11MeshRetryTimeout) ||
4611 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4612 cur_params.dot11MeshConfirmTimeout) ||
4613 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
4614 cur_params.dot11MeshHoldingTimeout) ||
4615 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
4616 cur_params.dot11MeshMaxPeerLinks) ||
4617 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
4618 cur_params.dot11MeshMaxRetries) ||
4619 nla_put_u8(msg, NL80211_MESHCONF_TTL,
4620 cur_params.dot11MeshTTL) ||
4621 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
4622 cur_params.element_ttl) ||
4623 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4624 cur_params.auto_open_plinks) ||
7eab0f64
JL
4625 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4626 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
4627 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4628 cur_params.dot11MeshHWMPmaxPREQretries) ||
4629 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
4630 cur_params.path_refresh_time) ||
4631 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4632 cur_params.min_discovery_timeout) ||
4633 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4634 cur_params.dot11MeshHWMPactivePathTimeout) ||
4635 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4636 cur_params.dot11MeshHWMPpreqMinInterval) ||
4637 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4638 cur_params.dot11MeshHWMPperrMinInterval) ||
4639 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4640 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
4641 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
4642 cur_params.dot11MeshHWMPRootMode) ||
4643 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4644 cur_params.dot11MeshHWMPRannInterval) ||
4645 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4646 cur_params.dot11MeshGateAnnouncementProtocol) ||
4647 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
4648 cur_params.dot11MeshForwarding) ||
4649 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
4650 cur_params.rssi_threshold) ||
4651 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4652 cur_params.ht_opmode) ||
4653 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4654 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
4655 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4656 cur_params.dot11MeshHWMProotInterval) ||
4657 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
4658 cur_params.dot11MeshHWMPconfirmationInterval) ||
4659 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
4660 cur_params.power_mode) ||
4661 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
4662 cur_params.dot11MeshAwakeWindowDuration) ||
4663 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
4664 cur_params.plink_timeout))
9360ffd1 4665 goto nla_put_failure;
93da9cc1 4666 nla_nest_end(msg, pinfoattr);
4667 genlmsg_end(msg, hdr);
4c476991 4668 return genlmsg_reply(msg, info);
93da9cc1 4669
3b85875a 4670 nla_put_failure:
93da9cc1 4671 genlmsg_cancel(msg, hdr);
efe1cf0c 4672 out:
d080e275 4673 nlmsg_free(msg);
4c476991 4674 return -ENOBUFS;
93da9cc1 4675}
4676
b54452b0 4677static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 4678 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
4679 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
4680 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
4681 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
4682 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
4683 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 4684 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 4685 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 4686 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 4687 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
4688 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
4689 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
4690 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
4691 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 4692 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 4693 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 4694 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 4695 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 4696 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 4697 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4698 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4699 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4700 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4701 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4702 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4703 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4704 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 4705 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
93da9cc1 4706};
4707
c80d545d
JC
4708static const struct nla_policy
4709 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4710 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4711 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4712 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4713 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 4714 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 4715 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
581a8b0f 4716 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4717 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4718 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4719};
4720
24bdd9f4 4721static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4722 struct mesh_config *cfg,
4723 u32 *mask_out)
93da9cc1 4724{
93da9cc1 4725 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4726 u32 mask = 0;
93da9cc1 4727
ea54fba2
MP
4728#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4729do { \
4730 if (tb[attr]) { \
4731 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4732 return -EINVAL; \
4733 cfg->param = fn(tb[attr]); \
4734 mask |= (1 << (attr - 1)); \
4735 } \
4736} while (0)
bd90fdcc
JB
4737
4738
24bdd9f4 4739 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4740 return -EINVAL;
4741 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4742 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4743 nl80211_meshconf_params_policy))
93da9cc1 4744 return -EINVAL;
4745
93da9cc1 4746 /* This makes sure that there aren't more than 32 mesh config
4747 * parameters (otherwise our bitfield scheme would not work.) */
4748 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4749
4750 /* Fill in the params struct */
ea54fba2 4751 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4752 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4753 nla_get_u16);
ea54fba2 4754 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4755 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4756 nla_get_u16);
ea54fba2 4757 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4758 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4759 nla_get_u16);
ea54fba2 4760 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4761 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4762 nla_get_u16);
ea54fba2 4763 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4764 mask, NL80211_MESHCONF_MAX_RETRIES,
4765 nla_get_u8);
ea54fba2 4766 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4767 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4768 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4769 mask, NL80211_MESHCONF_ELEMENT_TTL,
4770 nla_get_u8);
ea54fba2 4771 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4772 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4773 nla_get_u8);
ea54fba2
MP
4774 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4775 1, 255, mask,
a4f606ea
CYY
4776 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4777 nla_get_u32);
ea54fba2 4778 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4779 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4780 nla_get_u8);
ea54fba2 4781 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4782 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4783 nla_get_u32);
ea54fba2 4784 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4785 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4786 nla_get_u16);
ea54fba2
MP
4787 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4788 1, 65535, mask,
a4f606ea
CYY
4789 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4790 nla_get_u32);
93da9cc1 4791 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4792 1, 65535, mask,
4793 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4794 nla_get_u16);
dca7e943 4795 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4796 1, 65535, mask,
4797 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4798 nla_get_u16);
93da9cc1 4799 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4800 dot11MeshHWMPnetDiameterTraversalTime,
4801 1, 65535, mask,
a4f606ea
CYY
4802 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4803 nla_get_u16);
ea54fba2
MP
4804 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4805 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4806 nla_get_u8);
4807 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4808 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4809 nla_get_u16);
63c5723b 4810 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4811 dot11MeshGateAnnouncementProtocol, 0, 1,
4812 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4813 nla_get_u8);
ea54fba2 4814 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4815 mask, NL80211_MESHCONF_FORWARDING,
4816 nla_get_u8);
83374fe9 4817 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0,
a4f606ea 4818 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
83374fe9 4819 nla_get_s32);
ea54fba2 4820 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4821 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4822 nla_get_u16);
4823 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4824 1, 65535, mask,
ac1073a6
CYY
4825 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4826 nla_get_u32);
ea54fba2 4827 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4828 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4829 nla_get_u16);
4830 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4831 dot11MeshHWMPconfirmationInterval,
4832 1, 65535, mask,
728b19e5 4833 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4834 nla_get_u16);
3b1c5a53
MP
4835 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4836 NL80211_MESH_POWER_ACTIVE,
4837 NL80211_MESH_POWER_MAX,
4838 mask, NL80211_MESHCONF_POWER_MODE,
4839 nla_get_u32);
4840 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4841 0, 65535, mask,
4842 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
8e7c0538
CT
4843 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 1, 0xffffffff,
4844 mask, NL80211_MESHCONF_PLINK_TIMEOUT,
4845 nla_get_u32);
bd90fdcc
JB
4846 if (mask_out)
4847 *mask_out = mask;
c80d545d 4848
bd90fdcc
JB
4849 return 0;
4850
4851#undef FILL_IN_MESH_PARAM_IF_SET
4852}
4853
c80d545d
JC
4854static int nl80211_parse_mesh_setup(struct genl_info *info,
4855 struct mesh_setup *setup)
4856{
bb2798d4 4857 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
4858 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4859
4860 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4861 return -EINVAL;
4862 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4863 info->attrs[NL80211_ATTR_MESH_SETUP],
4864 nl80211_mesh_setup_params_policy))
4865 return -EINVAL;
4866
d299a1f2
JC
4867 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4868 setup->sync_method =
4869 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4870 IEEE80211_SYNC_METHOD_VENDOR :
4871 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4872
c80d545d
JC
4873 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4874 setup->path_sel_proto =
4875 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4876 IEEE80211_PATH_PROTOCOL_VENDOR :
4877 IEEE80211_PATH_PROTOCOL_HWMP;
4878
4879 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4880 setup->path_metric =
4881 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4882 IEEE80211_PATH_METRIC_VENDOR :
4883 IEEE80211_PATH_METRIC_AIRTIME;
4884
581a8b0f
JC
4885
4886 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4887 struct nlattr *ieattr =
581a8b0f 4888 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4889 if (!is_valid_ie_attr(ieattr))
4890 return -EINVAL;
581a8b0f
JC
4891 setup->ie = nla_data(ieattr);
4892 setup->ie_len = nla_len(ieattr);
c80d545d 4893 }
bb2798d4
TP
4894 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
4895 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
4896 return -EINVAL;
4897 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
4898 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4899 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
4900 if (setup->is_secure)
4901 setup->user_mpm = true;
c80d545d 4902
6e16d90b
CT
4903 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
4904 if (!setup->user_mpm)
4905 return -EINVAL;
4906 setup->auth_id =
4907 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
4908 }
4909
c80d545d
JC
4910 return 0;
4911}
4912
24bdd9f4 4913static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4914 struct genl_info *info)
bd90fdcc
JB
4915{
4916 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4917 struct net_device *dev = info->user_ptr[1];
29cbe68c 4918 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4919 struct mesh_config cfg;
4920 u32 mask;
4921 int err;
4922
29cbe68c
JB
4923 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4924 return -EOPNOTSUPP;
4925
24bdd9f4 4926 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4927 return -EOPNOTSUPP;
4928
24bdd9f4 4929 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4930 if (err)
4931 return err;
4932
29cbe68c
JB
4933 wdev_lock(wdev);
4934 if (!wdev->mesh_id_len)
4935 err = -ENOLINK;
4936
4937 if (!err)
e35e4d28 4938 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4939
4940 wdev_unlock(wdev);
4941
4942 return err;
93da9cc1 4943}
4944
f130347c
LR
4945static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4946{
458f4f9e 4947 const struct ieee80211_regdomain *regdom;
f130347c
LR
4948 struct sk_buff *msg;
4949 void *hdr = NULL;
4950 struct nlattr *nl_reg_rules;
4951 unsigned int i;
f130347c
LR
4952
4953 if (!cfg80211_regdomain)
5fe231e8 4954 return -EINVAL;
f130347c 4955
fd2120ca 4956 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5fe231e8
JB
4957 if (!msg)
4958 return -ENOBUFS;
f130347c 4959
15e47304 4960 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4961 NL80211_CMD_GET_REG);
4962 if (!hdr)
efe1cf0c 4963 goto put_failure;
f130347c 4964
57b5ce07
LR
4965 if (reg_last_request_cell_base() &&
4966 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4967 NL80211_USER_REG_HINT_CELL_BASE))
4968 goto nla_put_failure;
4969
458f4f9e
JB
4970 rcu_read_lock();
4971 regdom = rcu_dereference(cfg80211_regdomain);
4972
4973 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
4974 (regdom->dfs_region &&
4975 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
4976 goto nla_put_failure_rcu;
4977
f130347c
LR
4978 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4979 if (!nl_reg_rules)
458f4f9e 4980 goto nla_put_failure_rcu;
f130347c 4981
458f4f9e 4982 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
4983 struct nlattr *nl_reg_rule;
4984 const struct ieee80211_reg_rule *reg_rule;
4985 const struct ieee80211_freq_range *freq_range;
4986 const struct ieee80211_power_rule *power_rule;
4987
458f4f9e 4988 reg_rule = &regdom->reg_rules[i];
f130347c
LR
4989 freq_range = &reg_rule->freq_range;
4990 power_rule = &reg_rule->power_rule;
4991
4992 nl_reg_rule = nla_nest_start(msg, i);
4993 if (!nl_reg_rule)
458f4f9e 4994 goto nla_put_failure_rcu;
f130347c 4995
9360ffd1
DM
4996 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4997 reg_rule->flags) ||
4998 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4999 freq_range->start_freq_khz) ||
5000 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
5001 freq_range->end_freq_khz) ||
5002 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
5003 freq_range->max_bandwidth_khz) ||
5004 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
5005 power_rule->max_antenna_gain) ||
5006 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
5007 power_rule->max_eirp))
458f4f9e 5008 goto nla_put_failure_rcu;
f130347c
LR
5009
5010 nla_nest_end(msg, nl_reg_rule);
5011 }
458f4f9e 5012 rcu_read_unlock();
f130347c
LR
5013
5014 nla_nest_end(msg, nl_reg_rules);
5015
5016 genlmsg_end(msg, hdr);
5fe231e8 5017 return genlmsg_reply(msg, info);
f130347c 5018
458f4f9e
JB
5019nla_put_failure_rcu:
5020 rcu_read_unlock();
f130347c
LR
5021nla_put_failure:
5022 genlmsg_cancel(msg, hdr);
efe1cf0c 5023put_failure:
d080e275 5024 nlmsg_free(msg);
5fe231e8 5025 return -EMSGSIZE;
f130347c
LR
5026}
5027
b2e1b302
LR
5028static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
5029{
5030 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
5031 struct nlattr *nl_reg_rule;
5032 char *alpha2 = NULL;
5033 int rem_reg_rules = 0, r = 0;
5034 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 5035 u8 dfs_region = 0;
b2e1b302
LR
5036 struct ieee80211_regdomain *rd = NULL;
5037
5038 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
5039 return -EINVAL;
5040
5041 if (!info->attrs[NL80211_ATTR_REG_RULES])
5042 return -EINVAL;
5043
5044 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
5045
8b60b078
LR
5046 if (info->attrs[NL80211_ATTR_DFS_REGION])
5047 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
5048
b2e1b302 5049 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5050 rem_reg_rules) {
b2e1b302
LR
5051 num_rules++;
5052 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 5053 return -EINVAL;
b2e1b302
LR
5054 }
5055
b2e1b302 5056 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 5057 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
5058
5059 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
5060 if (!rd)
5061 return -ENOMEM;
b2e1b302
LR
5062
5063 rd->n_reg_rules = num_rules;
5064 rd->alpha2[0] = alpha2[0];
5065 rd->alpha2[1] = alpha2[1];
5066
8b60b078
LR
5067 /*
5068 * Disable DFS master mode if the DFS region was
5069 * not supported or known on this kernel.
5070 */
5071 if (reg_supported_dfs_region(dfs_region))
5072 rd->dfs_region = dfs_region;
5073
b2e1b302 5074 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5075 rem_reg_rules) {
b2e1b302 5076 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
5077 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
5078 reg_rule_policy);
b2e1b302
LR
5079 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
5080 if (r)
5081 goto bad_reg;
5082
5083 rule_idx++;
5084
d0e18f83
LR
5085 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
5086 r = -EINVAL;
b2e1b302 5087 goto bad_reg;
d0e18f83 5088 }
b2e1b302
LR
5089 }
5090
b2e1b302 5091 r = set_regdom(rd);
6913b49a 5092 /* set_regdom took ownership */
1a919318 5093 rd = NULL;
b2e1b302 5094
d2372b31 5095 bad_reg:
b2e1b302 5096 kfree(rd);
d0e18f83 5097 return r;
b2e1b302
LR
5098}
5099
83f5e2cf
JB
5100static int validate_scan_freqs(struct nlattr *freqs)
5101{
5102 struct nlattr *attr1, *attr2;
5103 int n_channels = 0, tmp1, tmp2;
5104
5105 nla_for_each_nested(attr1, freqs, tmp1) {
5106 n_channels++;
5107 /*
5108 * Some hardware has a limited channel list for
5109 * scanning, and it is pretty much nonsensical
5110 * to scan for a channel twice, so disallow that
5111 * and don't require drivers to check that the
5112 * channel list they get isn't longer than what
5113 * they can scan, as long as they can scan all
5114 * the channels they registered at once.
5115 */
5116 nla_for_each_nested(attr2, freqs, tmp2)
5117 if (attr1 != attr2 &&
5118 nla_get_u32(attr1) == nla_get_u32(attr2))
5119 return 0;
5120 }
5121
5122 return n_channels;
5123}
5124
2a519311
JB
5125static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
5126{
4c476991 5127 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 5128 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 5129 struct cfg80211_scan_request *request;
2a519311
JB
5130 struct nlattr *attr;
5131 struct wiphy *wiphy;
83f5e2cf 5132 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 5133 size_t ie_len;
2a519311 5134
f4a11bb0
JB
5135 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5136 return -EINVAL;
5137
79c97e97 5138 wiphy = &rdev->wiphy;
2a519311 5139
4c476991
JB
5140 if (!rdev->ops->scan)
5141 return -EOPNOTSUPP;
2a519311 5142
f9f47529
JB
5143 if (rdev->scan_req) {
5144 err = -EBUSY;
5145 goto unlock;
5146 }
2a519311
JB
5147
5148 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
5149 n_channels = validate_scan_freqs(
5150 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
5151 if (!n_channels) {
5152 err = -EINVAL;
5153 goto unlock;
5154 }
2a519311 5155 } else {
34850ab2 5156 enum ieee80211_band band;
83f5e2cf
JB
5157 n_channels = 0;
5158
2a519311
JB
5159 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
5160 if (wiphy->bands[band])
5161 n_channels += wiphy->bands[band]->n_channels;
5162 }
5163
5164 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5165 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
5166 n_ssids++;
5167
f9f47529
JB
5168 if (n_ssids > wiphy->max_scan_ssids) {
5169 err = -EINVAL;
5170 goto unlock;
5171 }
2a519311 5172
70692ad2
JM
5173 if (info->attrs[NL80211_ATTR_IE])
5174 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5175 else
5176 ie_len = 0;
5177
f9f47529
JB
5178 if (ie_len > wiphy->max_scan_ie_len) {
5179 err = -EINVAL;
5180 goto unlock;
5181 }
18a83659 5182
2a519311 5183 request = kzalloc(sizeof(*request)
a2cd43c5
LC
5184 + sizeof(*request->ssids) * n_ssids
5185 + sizeof(*request->channels) * n_channels
70692ad2 5186 + ie_len, GFP_KERNEL);
f9f47529
JB
5187 if (!request) {
5188 err = -ENOMEM;
5189 goto unlock;
5190 }
2a519311 5191
2a519311 5192 if (n_ssids)
5ba63533 5193 request->ssids = (void *)&request->channels[n_channels];
2a519311 5194 request->n_ssids = n_ssids;
70692ad2
JM
5195 if (ie_len) {
5196 if (request->ssids)
5197 request->ie = (void *)(request->ssids + n_ssids);
5198 else
5199 request->ie = (void *)(request->channels + n_channels);
5200 }
2a519311 5201
584991dc 5202 i = 0;
2a519311
JB
5203 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5204 /* user specified, bail out if channel not found */
2a519311 5205 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
5206 struct ieee80211_channel *chan;
5207
5208 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5209
5210 if (!chan) {
2a519311
JB
5211 err = -EINVAL;
5212 goto out_free;
5213 }
584991dc
JB
5214
5215 /* ignore disabled channels */
5216 if (chan->flags & IEEE80211_CHAN_DISABLED)
5217 continue;
5218
5219 request->channels[i] = chan;
2a519311
JB
5220 i++;
5221 }
5222 } else {
34850ab2
JB
5223 enum ieee80211_band band;
5224
2a519311 5225 /* all channels */
2a519311
JB
5226 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5227 int j;
5228 if (!wiphy->bands[band])
5229 continue;
5230 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
5231 struct ieee80211_channel *chan;
5232
5233 chan = &wiphy->bands[band]->channels[j];
5234
5235 if (chan->flags & IEEE80211_CHAN_DISABLED)
5236 continue;
5237
5238 request->channels[i] = chan;
2a519311
JB
5239 i++;
5240 }
5241 }
5242 }
5243
584991dc
JB
5244 if (!i) {
5245 err = -EINVAL;
5246 goto out_free;
5247 }
5248
5249 request->n_channels = i;
5250
2a519311
JB
5251 i = 0;
5252 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
5253 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 5254 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
5255 err = -EINVAL;
5256 goto out_free;
5257 }
57a27e1d 5258 request->ssids[i].ssid_len = nla_len(attr);
2a519311 5259 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
5260 i++;
5261 }
5262 }
5263
70692ad2
JM
5264 if (info->attrs[NL80211_ATTR_IE]) {
5265 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
5266 memcpy((void *)request->ie,
5267 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
5268 request->ie_len);
5269 }
5270
34850ab2 5271 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
5272 if (wiphy->bands[i])
5273 request->rates[i] =
5274 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
5275
5276 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
5277 nla_for_each_nested(attr,
5278 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
5279 tmp) {
5280 enum ieee80211_band band = nla_type(attr);
5281
84404623 5282 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
5283 err = -EINVAL;
5284 goto out_free;
5285 }
5286 err = ieee80211_get_ratemask(wiphy->bands[band],
5287 nla_data(attr),
5288 nla_len(attr),
5289 &request->rates[band]);
5290 if (err)
5291 goto out_free;
5292 }
5293 }
5294
46856bbf 5295 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5296 request->flags = nla_get_u32(
5297 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
5298 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5299 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
5300 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
5301 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
5302 err = -EOPNOTSUPP;
5303 goto out_free;
5304 }
5305 }
ed473771 5306
e9f935e3
RM
5307 request->no_cck =
5308 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5309
fd014284 5310 request->wdev = wdev;
79c97e97 5311 request->wiphy = &rdev->wiphy;
15d6030b 5312 request->scan_start = jiffies;
2a519311 5313
79c97e97 5314 rdev->scan_req = request;
e35e4d28 5315 err = rdev_scan(rdev, request);
2a519311 5316
463d0183 5317 if (!err) {
fd014284
JB
5318 nl80211_send_scan_start(rdev, wdev);
5319 if (wdev->netdev)
5320 dev_hold(wdev->netdev);
4c476991 5321 } else {
2a519311 5322 out_free:
79c97e97 5323 rdev->scan_req = NULL;
2a519311
JB
5324 kfree(request);
5325 }
3b85875a 5326
f9f47529 5327 unlock:
2a519311
JB
5328 return err;
5329}
5330
807f8a8c
LC
5331static int nl80211_start_sched_scan(struct sk_buff *skb,
5332 struct genl_info *info)
5333{
5334 struct cfg80211_sched_scan_request *request;
5335 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5336 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
5337 struct nlattr *attr;
5338 struct wiphy *wiphy;
a1f1c21c 5339 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 5340 u32 interval;
807f8a8c
LC
5341 enum ieee80211_band band;
5342 size_t ie_len;
a1f1c21c 5343 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
5344
5345 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5346 !rdev->ops->sched_scan_start)
5347 return -EOPNOTSUPP;
5348
5349 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5350 return -EINVAL;
5351
bbe6ad6d
LC
5352 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
5353 return -EINVAL;
5354
5355 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
5356 if (interval == 0)
5357 return -EINVAL;
5358
807f8a8c
LC
5359 wiphy = &rdev->wiphy;
5360
5361 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5362 n_channels = validate_scan_freqs(
5363 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
5364 if (!n_channels)
5365 return -EINVAL;
5366 } else {
5367 n_channels = 0;
5368
5369 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
5370 if (wiphy->bands[band])
5371 n_channels += wiphy->bands[band]->n_channels;
5372 }
5373
5374 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5375 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
5376 tmp)
5377 n_ssids++;
5378
93b6aa69 5379 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
5380 return -EINVAL;
5381
a1f1c21c
LC
5382 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
5383 nla_for_each_nested(attr,
5384 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
5385 tmp)
5386 n_match_sets++;
5387
5388 if (n_match_sets > wiphy->max_match_sets)
5389 return -EINVAL;
5390
807f8a8c
LC
5391 if (info->attrs[NL80211_ATTR_IE])
5392 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5393 else
5394 ie_len = 0;
5395
5a865bad 5396 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
5397 return -EINVAL;
5398
c10841ca
LC
5399 if (rdev->sched_scan_req) {
5400 err = -EINPROGRESS;
5401 goto out;
5402 }
5403
807f8a8c 5404 request = kzalloc(sizeof(*request)
a2cd43c5 5405 + sizeof(*request->ssids) * n_ssids
a1f1c21c 5406 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 5407 + sizeof(*request->channels) * n_channels
807f8a8c 5408 + ie_len, GFP_KERNEL);
c10841ca
LC
5409 if (!request) {
5410 err = -ENOMEM;
5411 goto out;
5412 }
807f8a8c
LC
5413
5414 if (n_ssids)
5415 request->ssids = (void *)&request->channels[n_channels];
5416 request->n_ssids = n_ssids;
5417 if (ie_len) {
5418 if (request->ssids)
5419 request->ie = (void *)(request->ssids + n_ssids);
5420 else
5421 request->ie = (void *)(request->channels + n_channels);
5422 }
5423
a1f1c21c
LC
5424 if (n_match_sets) {
5425 if (request->ie)
5426 request->match_sets = (void *)(request->ie + ie_len);
5427 else if (request->ssids)
5428 request->match_sets =
5429 (void *)(request->ssids + n_ssids);
5430 else
5431 request->match_sets =
5432 (void *)(request->channels + n_channels);
5433 }
5434 request->n_match_sets = n_match_sets;
5435
807f8a8c
LC
5436 i = 0;
5437 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5438 /* user specified, bail out if channel not found */
5439 nla_for_each_nested(attr,
5440 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
5441 tmp) {
5442 struct ieee80211_channel *chan;
5443
5444 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5445
5446 if (!chan) {
5447 err = -EINVAL;
5448 goto out_free;
5449 }
5450
5451 /* ignore disabled channels */
5452 if (chan->flags & IEEE80211_CHAN_DISABLED)
5453 continue;
5454
5455 request->channels[i] = chan;
5456 i++;
5457 }
5458 } else {
5459 /* all channels */
5460 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5461 int j;
5462 if (!wiphy->bands[band])
5463 continue;
5464 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
5465 struct ieee80211_channel *chan;
5466
5467 chan = &wiphy->bands[band]->channels[j];
5468
5469 if (chan->flags & IEEE80211_CHAN_DISABLED)
5470 continue;
5471
5472 request->channels[i] = chan;
5473 i++;
5474 }
5475 }
5476 }
5477
5478 if (!i) {
5479 err = -EINVAL;
5480 goto out_free;
5481 }
5482
5483 request->n_channels = i;
5484
5485 i = 0;
5486 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
5487 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
5488 tmp) {
57a27e1d 5489 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
5490 err = -EINVAL;
5491 goto out_free;
5492 }
57a27e1d 5493 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
5494 memcpy(request->ssids[i].ssid, nla_data(attr),
5495 nla_len(attr));
807f8a8c
LC
5496 i++;
5497 }
5498 }
5499
a1f1c21c
LC
5500 i = 0;
5501 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
5502 nla_for_each_nested(attr,
5503 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
5504 tmp) {
88e920b4 5505 struct nlattr *ssid, *rssi;
a1f1c21c
LC
5506
5507 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
5508 nla_data(attr), nla_len(attr),
5509 nl80211_match_policy);
4a4ab0d7 5510 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
5511 if (ssid) {
5512 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
5513 err = -EINVAL;
5514 goto out_free;
5515 }
5516 memcpy(request->match_sets[i].ssid.ssid,
5517 nla_data(ssid), nla_len(ssid));
5518 request->match_sets[i].ssid.ssid_len =
5519 nla_len(ssid);
5520 }
88e920b4
TP
5521 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
5522 if (rssi)
5523 request->rssi_thold = nla_get_u32(rssi);
5524 else
5525 request->rssi_thold =
5526 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
5527 i++;
5528 }
5529 }
5530
807f8a8c
LC
5531 if (info->attrs[NL80211_ATTR_IE]) {
5532 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5533 memcpy((void *)request->ie,
5534 nla_data(info->attrs[NL80211_ATTR_IE]),
5535 request->ie_len);
5536 }
5537
46856bbf 5538 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5539 request->flags = nla_get_u32(
5540 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
5541 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5542 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
5543 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
5544 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
5545 err = -EOPNOTSUPP;
5546 goto out_free;
5547 }
5548 }
ed473771 5549
807f8a8c
LC
5550 request->dev = dev;
5551 request->wiphy = &rdev->wiphy;
bbe6ad6d 5552 request->interval = interval;
15d6030b 5553 request->scan_start = jiffies;
807f8a8c 5554
e35e4d28 5555 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
5556 if (!err) {
5557 rdev->sched_scan_req = request;
5558 nl80211_send_sched_scan(rdev, dev,
5559 NL80211_CMD_START_SCHED_SCAN);
5560 goto out;
5561 }
5562
5563out_free:
5564 kfree(request);
5565out:
5566 return err;
5567}
5568
5569static int nl80211_stop_sched_scan(struct sk_buff *skb,
5570 struct genl_info *info)
5571{
5572 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5573
5574 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5575 !rdev->ops->sched_scan_stop)
5576 return -EOPNOTSUPP;
5577
5fe231e8 5578 return __cfg80211_stop_sched_scan(rdev, false);
807f8a8c
LC
5579}
5580
04f39047
SW
5581static int nl80211_start_radar_detection(struct sk_buff *skb,
5582 struct genl_info *info)
5583{
5584 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5585 struct net_device *dev = info->user_ptr[1];
5586 struct wireless_dev *wdev = dev->ieee80211_ptr;
5587 struct cfg80211_chan_def chandef;
5588 int err;
5589
5590 err = nl80211_parse_chandef(rdev, info, &chandef);
5591 if (err)
5592 return err;
5593
5594 if (wdev->cac_started)
5595 return -EBUSY;
5596
5597 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef);
5598 if (err < 0)
5599 return err;
5600
5601 if (err == 0)
5602 return -EINVAL;
5603
5604 if (chandef.chan->dfs_state != NL80211_DFS_USABLE)
5605 return -EINVAL;
5606
5607 if (!rdev->ops->start_radar_detection)
5608 return -EOPNOTSUPP;
5609
04f39047
SW
5610 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
5611 chandef.chan, CHAN_MODE_SHARED,
5612 BIT(chandef.width));
5613 if (err)
5fe231e8 5614 return err;
04f39047
SW
5615
5616 err = rdev->ops->start_radar_detection(&rdev->wiphy, dev, &chandef);
5617 if (!err) {
5618 wdev->channel = chandef.chan;
5619 wdev->cac_started = true;
5620 wdev->cac_start_time = jiffies;
5621 }
04f39047
SW
5622 return err;
5623}
5624
16ef1fe2
SW
5625static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
5626{
5627 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5628 struct net_device *dev = info->user_ptr[1];
5629 struct wireless_dev *wdev = dev->ieee80211_ptr;
5630 struct cfg80211_csa_settings params;
5631 /* csa_attrs is defined static to avoid waste of stack size - this
5632 * function is called under RTNL lock, so this should not be a problem.
5633 */
5634 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
5635 u8 radar_detect_width = 0;
5636 int err;
ee4bc9e7 5637 bool need_new_beacon = false;
16ef1fe2
SW
5638
5639 if (!rdev->ops->channel_switch ||
5640 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
5641 return -EOPNOTSUPP;
5642
ee4bc9e7
SW
5643 switch (dev->ieee80211_ptr->iftype) {
5644 case NL80211_IFTYPE_AP:
5645 case NL80211_IFTYPE_P2P_GO:
5646 need_new_beacon = true;
5647
5648 /* useless if AP is not running */
5649 if (!wdev->beacon_interval)
5650 return -EINVAL;
5651 break;
5652 case NL80211_IFTYPE_ADHOC:
5653 break;
5654 default:
16ef1fe2 5655 return -EOPNOTSUPP;
ee4bc9e7 5656 }
16ef1fe2
SW
5657
5658 memset(&params, 0, sizeof(params));
5659
5660 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5661 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
5662 return -EINVAL;
5663
5664 /* only important for AP, IBSS and mesh create IEs internally */
ee4bc9e7
SW
5665 if (need_new_beacon &&
5666 (!info->attrs[NL80211_ATTR_CSA_IES] ||
5667 !info->attrs[NL80211_ATTR_CSA_C_OFF_BEACON]))
16ef1fe2
SW
5668 return -EINVAL;
5669
5670 params.count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
5671
ee4bc9e7
SW
5672 if (!need_new_beacon)
5673 goto skip_beacons;
5674
16ef1fe2
SW
5675 err = nl80211_parse_beacon(info->attrs, &params.beacon_after);
5676 if (err)
5677 return err;
5678
5679 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX,
5680 info->attrs[NL80211_ATTR_CSA_IES],
5681 nl80211_policy);
5682 if (err)
5683 return err;
5684
5685 err = nl80211_parse_beacon(csa_attrs, &params.beacon_csa);
5686 if (err)
5687 return err;
5688
5689 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
5690 return -EINVAL;
5691
5692 params.counter_offset_beacon =
5693 nla_get_u16(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
5694 if (params.counter_offset_beacon >= params.beacon_csa.tail_len)
5695 return -EINVAL;
5696
5697 /* sanity check - counters should be the same */
5698 if (params.beacon_csa.tail[params.counter_offset_beacon] !=
5699 params.count)
5700 return -EINVAL;
5701
5702 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
5703 params.counter_offset_presp =
5704 nla_get_u16(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
5705 if (params.counter_offset_presp >=
5706 params.beacon_csa.probe_resp_len)
5707 return -EINVAL;
5708
5709 if (params.beacon_csa.probe_resp[params.counter_offset_presp] !=
5710 params.count)
5711 return -EINVAL;
5712 }
5713
ee4bc9e7 5714skip_beacons:
16ef1fe2
SW
5715 err = nl80211_parse_chandef(rdev, info, &params.chandef);
5716 if (err)
5717 return err;
5718
5719 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
5720 return -EINVAL;
5721
ee4bc9e7
SW
5722 /* DFS channels are only supported for AP/P2P GO ... for now. */
5723 if (dev->ieee80211_ptr->iftype == NL80211_IFTYPE_AP ||
5724 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO) {
5725 err = cfg80211_chandef_dfs_required(wdev->wiphy,
5726 &params.chandef);
5727 if (err < 0) {
5728 return err;
5729 } else if (err) {
5730 radar_detect_width = BIT(params.chandef.width);
5731 params.radar_required = true;
5732 }
16ef1fe2
SW
5733 }
5734
5735 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
5736 params.chandef.chan,
5737 CHAN_MODE_SHARED,
5738 radar_detect_width);
5739 if (err)
5740 return err;
5741
5742 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
5743 params.block_tx = true;
5744
5745 return rdev_channel_switch(rdev, dev, &params);
5746}
5747
9720bb3a
JB
5748static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
5749 u32 seq, int flags,
2a519311 5750 struct cfg80211_registered_device *rdev,
48ab905d
JB
5751 struct wireless_dev *wdev,
5752 struct cfg80211_internal_bss *intbss)
2a519311 5753{
48ab905d 5754 struct cfg80211_bss *res = &intbss->pub;
9caf0364 5755 const struct cfg80211_bss_ies *ies;
2a519311
JB
5756 void *hdr;
5757 struct nlattr *bss;
8cef2c9d 5758 bool tsf = false;
48ab905d
JB
5759
5760 ASSERT_WDEV_LOCK(wdev);
2a519311 5761
15e47304 5762 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
5763 NL80211_CMD_NEW_SCAN_RESULTS);
5764 if (!hdr)
5765 return -1;
5766
9720bb3a
JB
5767 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
5768
97990a06
JB
5769 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
5770 goto nla_put_failure;
5771 if (wdev->netdev &&
9360ffd1
DM
5772 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
5773 goto nla_put_failure;
97990a06
JB
5774 if (nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
5775 goto nla_put_failure;
2a519311
JB
5776
5777 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
5778 if (!bss)
5779 goto nla_put_failure;
9360ffd1 5780 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 5781 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 5782 goto nla_put_failure;
9caf0364
JB
5783
5784 rcu_read_lock();
5785 ies = rcu_dereference(res->ies);
8cef2c9d
JB
5786 if (ies) {
5787 if (nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5788 goto fail_unlock_rcu;
5789 tsf = true;
5790 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
5791 ies->len, ies->data))
5792 goto fail_unlock_rcu;
9caf0364
JB
5793 }
5794 ies = rcu_dereference(res->beacon_ies);
8cef2c9d
JB
5795 if (ies) {
5796 if (!tsf && nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5797 goto fail_unlock_rcu;
5798 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
5799 ies->len, ies->data))
5800 goto fail_unlock_rcu;
9caf0364
JB
5801 }
5802 rcu_read_unlock();
5803
9360ffd1
DM
5804 if (res->beacon_interval &&
5805 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
5806 goto nla_put_failure;
5807 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
5808 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
dcd6eac1 5809 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
5810 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
5811 jiffies_to_msecs(jiffies - intbss->ts)))
5812 goto nla_put_failure;
2a519311 5813
77965c97 5814 switch (rdev->wiphy.signal_type) {
2a519311 5815 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
5816 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
5817 goto nla_put_failure;
2a519311
JB
5818 break;
5819 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
5820 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
5821 goto nla_put_failure;
2a519311
JB
5822 break;
5823 default:
5824 break;
5825 }
5826
48ab905d 5827 switch (wdev->iftype) {
074ac8df 5828 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 5829 case NL80211_IFTYPE_STATION:
9360ffd1
DM
5830 if (intbss == wdev->current_bss &&
5831 nla_put_u32(msg, NL80211_BSS_STATUS,
5832 NL80211_BSS_STATUS_ASSOCIATED))
5833 goto nla_put_failure;
48ab905d
JB
5834 break;
5835 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
5836 if (intbss == wdev->current_bss &&
5837 nla_put_u32(msg, NL80211_BSS_STATUS,
5838 NL80211_BSS_STATUS_IBSS_JOINED))
5839 goto nla_put_failure;
48ab905d
JB
5840 break;
5841 default:
5842 break;
5843 }
5844
2a519311
JB
5845 nla_nest_end(msg, bss);
5846
5847 return genlmsg_end(msg, hdr);
5848
8cef2c9d
JB
5849 fail_unlock_rcu:
5850 rcu_read_unlock();
2a519311
JB
5851 nla_put_failure:
5852 genlmsg_cancel(msg, hdr);
5853 return -EMSGSIZE;
5854}
5855
97990a06 5856static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 5857{
48ab905d 5858 struct cfg80211_registered_device *rdev;
2a519311 5859 struct cfg80211_internal_bss *scan;
48ab905d 5860 struct wireless_dev *wdev;
97990a06 5861 int start = cb->args[2], idx = 0;
2a519311
JB
5862 int err;
5863
97990a06 5864 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
5865 if (err)
5866 return err;
2a519311 5867
48ab905d
JB
5868 wdev_lock(wdev);
5869 spin_lock_bh(&rdev->bss_lock);
5870 cfg80211_bss_expire(rdev);
5871
9720bb3a
JB
5872 cb->seq = rdev->bss_generation;
5873
48ab905d 5874 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
5875 if (++idx <= start)
5876 continue;
9720bb3a 5877 if (nl80211_send_bss(skb, cb,
2a519311 5878 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 5879 rdev, wdev, scan) < 0) {
2a519311 5880 idx--;
67748893 5881 break;
2a519311
JB
5882 }
5883 }
5884
48ab905d
JB
5885 spin_unlock_bh(&rdev->bss_lock);
5886 wdev_unlock(wdev);
2a519311 5887
97990a06
JB
5888 cb->args[2] = idx;
5889 nl80211_finish_wdev_dump(rdev);
2a519311 5890
67748893 5891 return skb->len;
2a519311
JB
5892}
5893
15e47304 5894static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
5895 int flags, struct net_device *dev,
5896 struct survey_info *survey)
5897{
5898 void *hdr;
5899 struct nlattr *infoattr;
5900
15e47304 5901 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
5902 NL80211_CMD_NEW_SURVEY_RESULTS);
5903 if (!hdr)
5904 return -ENOMEM;
5905
9360ffd1
DM
5906 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
5907 goto nla_put_failure;
61fa713c
HS
5908
5909 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
5910 if (!infoattr)
5911 goto nla_put_failure;
5912
9360ffd1
DM
5913 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
5914 survey->channel->center_freq))
5915 goto nla_put_failure;
5916
5917 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
5918 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
5919 goto nla_put_failure;
5920 if ((survey->filled & SURVEY_INFO_IN_USE) &&
5921 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
5922 goto nla_put_failure;
5923 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
5924 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
5925 survey->channel_time))
5926 goto nla_put_failure;
5927 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
5928 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
5929 survey->channel_time_busy))
5930 goto nla_put_failure;
5931 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
5932 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5933 survey->channel_time_ext_busy))
5934 goto nla_put_failure;
5935 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5936 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5937 survey->channel_time_rx))
5938 goto nla_put_failure;
5939 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5940 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5941 survey->channel_time_tx))
5942 goto nla_put_failure;
61fa713c
HS
5943
5944 nla_nest_end(msg, infoattr);
5945
5946 return genlmsg_end(msg, hdr);
5947
5948 nla_put_failure:
5949 genlmsg_cancel(msg, hdr);
5950 return -EMSGSIZE;
5951}
5952
5953static int nl80211_dump_survey(struct sk_buff *skb,
5954 struct netlink_callback *cb)
5955{
5956 struct survey_info survey;
5957 struct cfg80211_registered_device *dev;
97990a06
JB
5958 struct wireless_dev *wdev;
5959 int survey_idx = cb->args[2];
61fa713c
HS
5960 int res;
5961
97990a06 5962 res = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
5963 if (res)
5964 return res;
61fa713c 5965
97990a06
JB
5966 if (!wdev->netdev) {
5967 res = -EINVAL;
5968 goto out_err;
5969 }
5970
61fa713c
HS
5971 if (!dev->ops->dump_survey) {
5972 res = -EOPNOTSUPP;
5973 goto out_err;
5974 }
5975
5976 while (1) {
180cdc79
LR
5977 struct ieee80211_channel *chan;
5978
97990a06 5979 res = rdev_dump_survey(dev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
5980 if (res == -ENOENT)
5981 break;
5982 if (res)
5983 goto out_err;
5984
180cdc79
LR
5985 /* Survey without a channel doesn't make sense */
5986 if (!survey.channel) {
5987 res = -EINVAL;
5988 goto out;
5989 }
5990
5991 chan = ieee80211_get_channel(&dev->wiphy,
5992 survey.channel->center_freq);
5993 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5994 survey_idx++;
5995 continue;
5996 }
5997
61fa713c 5998 if (nl80211_send_survey(skb,
15e47304 5999 NETLINK_CB(cb->skb).portid,
61fa713c 6000 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 6001 wdev->netdev, &survey) < 0)
61fa713c
HS
6002 goto out;
6003 survey_idx++;
6004 }
6005
6006 out:
97990a06 6007 cb->args[2] = survey_idx;
61fa713c
HS
6008 res = skb->len;
6009 out_err:
97990a06 6010 nl80211_finish_wdev_dump(dev);
61fa713c
HS
6011 return res;
6012}
6013
b23aa676
SO
6014static bool nl80211_valid_wpa_versions(u32 wpa_versions)
6015{
6016 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
6017 NL80211_WPA_VERSION_2));
6018}
6019
636a5d36
JM
6020static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
6021{
4c476991
JB
6022 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6023 struct net_device *dev = info->user_ptr[1];
19957bb3 6024 struct ieee80211_channel *chan;
e39e5b5e
JM
6025 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
6026 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 6027 enum nl80211_auth_type auth_type;
fffd0934 6028 struct key_parse key;
d5cdfacb 6029 bool local_state_change;
636a5d36 6030
f4a11bb0
JB
6031 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6032 return -EINVAL;
6033
6034 if (!info->attrs[NL80211_ATTR_MAC])
6035 return -EINVAL;
6036
1778092e
JM
6037 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
6038 return -EINVAL;
6039
19957bb3
JB
6040 if (!info->attrs[NL80211_ATTR_SSID])
6041 return -EINVAL;
6042
6043 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
6044 return -EINVAL;
6045
fffd0934
JB
6046 err = nl80211_parse_key(info, &key);
6047 if (err)
6048 return err;
6049
6050 if (key.idx >= 0) {
e31b8213
JB
6051 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
6052 return -EINVAL;
fffd0934
JB
6053 if (!key.p.key || !key.p.key_len)
6054 return -EINVAL;
6055 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
6056 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
6057 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
6058 key.p.key_len != WLAN_KEY_LEN_WEP104))
6059 return -EINVAL;
6060 if (key.idx > 4)
6061 return -EINVAL;
6062 } else {
6063 key.p.key_len = 0;
6064 key.p.key = NULL;
6065 }
6066
afea0b7a
JB
6067 if (key.idx >= 0) {
6068 int i;
6069 bool ok = false;
6070 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
6071 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
6072 ok = true;
6073 break;
6074 }
6075 }
4c476991
JB
6076 if (!ok)
6077 return -EINVAL;
afea0b7a
JB
6078 }
6079
4c476991
JB
6080 if (!rdev->ops->auth)
6081 return -EOPNOTSUPP;
636a5d36 6082
074ac8df 6083 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6084 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6085 return -EOPNOTSUPP;
eec60b03 6086
19957bb3 6087 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 6088 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 6089 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
6090 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
6091 return -EINVAL;
636a5d36 6092
19957bb3
JB
6093 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6094 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
6095
6096 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6097 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6098 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6099 }
6100
19957bb3 6101 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 6102 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 6103 return -EINVAL;
636a5d36 6104
e39e5b5e
JM
6105 if (auth_type == NL80211_AUTHTYPE_SAE &&
6106 !info->attrs[NL80211_ATTR_SAE_DATA])
6107 return -EINVAL;
6108
6109 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
6110 if (auth_type != NL80211_AUTHTYPE_SAE)
6111 return -EINVAL;
6112 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
6113 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
6114 /* need to include at least Auth Transaction and Status Code */
6115 if (sae_data_len < 4)
6116 return -EINVAL;
6117 }
6118
d5cdfacb
JM
6119 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6120
95de817b
JB
6121 /*
6122 * Since we no longer track auth state, ignore
6123 * requests to only change local state.
6124 */
6125 if (local_state_change)
6126 return 0;
6127
91bf9b26
JB
6128 wdev_lock(dev->ieee80211_ptr);
6129 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
6130 ssid, ssid_len, ie, ie_len,
6131 key.p.key, key.p.key_len, key.idx,
6132 sae_data, sae_data_len);
6133 wdev_unlock(dev->ieee80211_ptr);
6134 return err;
636a5d36
JM
6135}
6136
c0692b8f
JB
6137static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
6138 struct genl_info *info,
3dc27d25
JB
6139 struct cfg80211_crypto_settings *settings,
6140 int cipher_limit)
b23aa676 6141{
c0b2bbd8
JB
6142 memset(settings, 0, sizeof(*settings));
6143
b23aa676
SO
6144 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
6145
c0692b8f
JB
6146 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
6147 u16 proto;
6148 proto = nla_get_u16(
6149 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
6150 settings->control_port_ethertype = cpu_to_be16(proto);
6151 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
6152 proto != ETH_P_PAE)
6153 return -EINVAL;
6154 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
6155 settings->control_port_no_encrypt = true;
6156 } else
6157 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
6158
b23aa676
SO
6159 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
6160 void *data;
6161 int len, i;
6162
6163 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
6164 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
6165 settings->n_ciphers_pairwise = len / sizeof(u32);
6166
6167 if (len % sizeof(u32))
6168 return -EINVAL;
6169
3dc27d25 6170 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
6171 return -EINVAL;
6172
6173 memcpy(settings->ciphers_pairwise, data, len);
6174
6175 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
6176 if (!cfg80211_supported_cipher_suite(
6177 &rdev->wiphy,
b23aa676
SO
6178 settings->ciphers_pairwise[i]))
6179 return -EINVAL;
6180 }
6181
6182 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
6183 settings->cipher_group =
6184 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
6185 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
6186 settings->cipher_group))
b23aa676
SO
6187 return -EINVAL;
6188 }
6189
6190 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
6191 settings->wpa_versions =
6192 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
6193 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
6194 return -EINVAL;
6195 }
6196
6197 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
6198 void *data;
6d30240e 6199 int len;
b23aa676
SO
6200
6201 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
6202 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
6203 settings->n_akm_suites = len / sizeof(u32);
6204
6205 if (len % sizeof(u32))
6206 return -EINVAL;
6207
1b9ca027
JM
6208 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
6209 return -EINVAL;
6210
b23aa676 6211 memcpy(settings->akm_suites, data, len);
b23aa676
SO
6212 }
6213
6214 return 0;
6215}
6216
636a5d36
JM
6217static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
6218{
4c476991
JB
6219 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6220 struct net_device *dev = info->user_ptr[1];
f444de05 6221 struct ieee80211_channel *chan;
f62fab73
JB
6222 struct cfg80211_assoc_request req = {};
6223 const u8 *bssid, *ssid;
6224 int err, ssid_len = 0;
636a5d36 6225
f4a11bb0
JB
6226 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6227 return -EINVAL;
6228
6229 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
6230 !info->attrs[NL80211_ATTR_SSID] ||
6231 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
6232 return -EINVAL;
6233
4c476991
JB
6234 if (!rdev->ops->assoc)
6235 return -EOPNOTSUPP;
636a5d36 6236
074ac8df 6237 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6238 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6239 return -EOPNOTSUPP;
eec60b03 6240
19957bb3 6241 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6242
19957bb3
JB
6243 chan = ieee80211_get_channel(&rdev->wiphy,
6244 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
6245 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
6246 return -EINVAL;
636a5d36 6247
19957bb3
JB
6248 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6249 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
6250
6251 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
6252 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6253 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6254 }
6255
dc6382ce 6256 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 6257 enum nl80211_mfp mfp =
dc6382ce 6258 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 6259 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 6260 req.use_mfp = true;
4c476991
JB
6261 else if (mfp != NL80211_MFP_NO)
6262 return -EINVAL;
dc6382ce
JM
6263 }
6264
3e5d7649 6265 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 6266 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 6267
7e7c8926 6268 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 6269 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
6270
6271 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
6272 memcpy(&req.ht_capa_mask,
6273 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6274 sizeof(req.ht_capa_mask));
7e7c8926
BG
6275
6276 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 6277 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 6278 return -EINVAL;
f62fab73
JB
6279 memcpy(&req.ht_capa,
6280 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6281 sizeof(req.ht_capa));
7e7c8926
BG
6282 }
6283
ee2aca34 6284 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 6285 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
6286
6287 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
6288 memcpy(&req.vht_capa_mask,
6289 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
6290 sizeof(req.vht_capa_mask));
ee2aca34
JB
6291
6292 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 6293 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 6294 return -EINVAL;
f62fab73
JB
6295 memcpy(&req.vht_capa,
6296 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
6297 sizeof(req.vht_capa));
ee2aca34
JB
6298 }
6299
f62fab73 6300 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
6301 if (!err) {
6302 wdev_lock(dev->ieee80211_ptr);
f62fab73
JB
6303 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
6304 ssid, ssid_len, &req);
91bf9b26
JB
6305 wdev_unlock(dev->ieee80211_ptr);
6306 }
636a5d36 6307
636a5d36
JM
6308 return err;
6309}
6310
6311static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
6312{
4c476991
JB
6313 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6314 struct net_device *dev = info->user_ptr[1];
19957bb3 6315 const u8 *ie = NULL, *bssid;
91bf9b26 6316 int ie_len = 0, err;
19957bb3 6317 u16 reason_code;
d5cdfacb 6318 bool local_state_change;
636a5d36 6319
f4a11bb0
JB
6320 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6321 return -EINVAL;
6322
6323 if (!info->attrs[NL80211_ATTR_MAC])
6324 return -EINVAL;
6325
6326 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6327 return -EINVAL;
6328
4c476991
JB
6329 if (!rdev->ops->deauth)
6330 return -EOPNOTSUPP;
636a5d36 6331
074ac8df 6332 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6333 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6334 return -EOPNOTSUPP;
eec60b03 6335
19957bb3 6336 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6337
19957bb3
JB
6338 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6339 if (reason_code == 0) {
f4a11bb0 6340 /* Reason Code 0 is reserved */
4c476991 6341 return -EINVAL;
255e737e 6342 }
636a5d36
JM
6343
6344 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6345 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6346 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6347 }
6348
d5cdfacb
JM
6349 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6350
91bf9b26
JB
6351 wdev_lock(dev->ieee80211_ptr);
6352 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
6353 local_state_change);
6354 wdev_unlock(dev->ieee80211_ptr);
6355 return err;
636a5d36
JM
6356}
6357
6358static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
6359{
4c476991
JB
6360 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6361 struct net_device *dev = info->user_ptr[1];
19957bb3 6362 const u8 *ie = NULL, *bssid;
91bf9b26 6363 int ie_len = 0, err;
19957bb3 6364 u16 reason_code;
d5cdfacb 6365 bool local_state_change;
636a5d36 6366
f4a11bb0
JB
6367 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6368 return -EINVAL;
6369
6370 if (!info->attrs[NL80211_ATTR_MAC])
6371 return -EINVAL;
6372
6373 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6374 return -EINVAL;
6375
4c476991
JB
6376 if (!rdev->ops->disassoc)
6377 return -EOPNOTSUPP;
636a5d36 6378
074ac8df 6379 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6380 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6381 return -EOPNOTSUPP;
eec60b03 6382
19957bb3 6383 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6384
19957bb3
JB
6385 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6386 if (reason_code == 0) {
f4a11bb0 6387 /* Reason Code 0 is reserved */
4c476991 6388 return -EINVAL;
255e737e 6389 }
636a5d36
JM
6390
6391 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6392 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6393 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6394 }
6395
d5cdfacb
JM
6396 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6397
91bf9b26
JB
6398 wdev_lock(dev->ieee80211_ptr);
6399 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
6400 local_state_change);
6401 wdev_unlock(dev->ieee80211_ptr);
6402 return err;
636a5d36
JM
6403}
6404
dd5b4cc7
FF
6405static bool
6406nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
6407 int mcast_rate[IEEE80211_NUM_BANDS],
6408 int rateval)
6409{
6410 struct wiphy *wiphy = &rdev->wiphy;
6411 bool found = false;
6412 int band, i;
6413
6414 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
6415 struct ieee80211_supported_band *sband;
6416
6417 sband = wiphy->bands[band];
6418 if (!sband)
6419 continue;
6420
6421 for (i = 0; i < sband->n_bitrates; i++) {
6422 if (sband->bitrates[i].bitrate == rateval) {
6423 mcast_rate[band] = i + 1;
6424 found = true;
6425 break;
6426 }
6427 }
6428 }
6429
6430 return found;
6431}
6432
04a773ad
JB
6433static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
6434{
4c476991
JB
6435 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6436 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
6437 struct cfg80211_ibss_params ibss;
6438 struct wiphy *wiphy;
fffd0934 6439 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
6440 int err;
6441
8e30bc55
JB
6442 memset(&ibss, 0, sizeof(ibss));
6443
04a773ad
JB
6444 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6445 return -EINVAL;
6446
683b6d3b 6447 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
6448 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6449 return -EINVAL;
6450
8e30bc55
JB
6451 ibss.beacon_interval = 100;
6452
6453 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6454 ibss.beacon_interval =
6455 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6456 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
6457 return -EINVAL;
6458 }
6459
4c476991
JB
6460 if (!rdev->ops->join_ibss)
6461 return -EOPNOTSUPP;
04a773ad 6462
4c476991
JB
6463 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
6464 return -EOPNOTSUPP;
04a773ad 6465
79c97e97 6466 wiphy = &rdev->wiphy;
04a773ad 6467
39193498 6468 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 6469 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
6470
6471 if (!is_valid_ether_addr(ibss.bssid))
6472 return -EINVAL;
6473 }
04a773ad
JB
6474 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6475 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6476
6477 if (info->attrs[NL80211_ATTR_IE]) {
6478 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6479 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6480 }
6481
683b6d3b
JB
6482 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
6483 if (err)
6484 return err;
04a773ad 6485
683b6d3b 6486 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
6487 return -EINVAL;
6488
2f301ab2 6489 switch (ibss.chandef.width) {
bf372645
SW
6490 case NL80211_CHAN_WIDTH_5:
6491 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
6492 case NL80211_CHAN_WIDTH_20_NOHT:
6493 break;
6494 case NL80211_CHAN_WIDTH_20:
6495 case NL80211_CHAN_WIDTH_40:
6496 if (rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)
6497 break;
6498 default:
c04d6150 6499 return -EINVAL;
2f301ab2 6500 }
db9c64cf 6501
04a773ad 6502 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
6503 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
6504
fbd2c8dc
TP
6505 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
6506 u8 *rates =
6507 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6508 int n_rates =
6509 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6510 struct ieee80211_supported_band *sband =
683b6d3b 6511 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 6512
34850ab2
JB
6513 err = ieee80211_get_ratemask(sband, rates, n_rates,
6514 &ibss.basic_rates);
6515 if (err)
6516 return err;
fbd2c8dc 6517 }
dd5b4cc7 6518
803768f5
SW
6519 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6520 memcpy(&ibss.ht_capa_mask,
6521 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6522 sizeof(ibss.ht_capa_mask));
6523
6524 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
6525 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6526 return -EINVAL;
6527 memcpy(&ibss.ht_capa,
6528 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6529 sizeof(ibss.ht_capa));
6530 }
6531
dd5b4cc7
FF
6532 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6533 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
6534 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6535 return -EINVAL;
fbd2c8dc 6536
4c476991 6537 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
6538 bool no_ht = false;
6539
4c476991 6540 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
6541 info->attrs[NL80211_ATTR_KEYS],
6542 &no_ht);
4c476991
JB
6543 if (IS_ERR(connkeys))
6544 return PTR_ERR(connkeys);
de7044ee 6545
3d9d1d66
JB
6546 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
6547 no_ht) {
de7044ee
SM
6548 kfree(connkeys);
6549 return -EINVAL;
6550 }
4c476991 6551 }
04a773ad 6552
267335d6
AQ
6553 ibss.control_port =
6554 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
6555
4c476991 6556 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
6557 if (err)
6558 kfree(connkeys);
04a773ad
JB
6559 return err;
6560}
6561
6562static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
6563{
4c476991
JB
6564 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6565 struct net_device *dev = info->user_ptr[1];
04a773ad 6566
4c476991
JB
6567 if (!rdev->ops->leave_ibss)
6568 return -EOPNOTSUPP;
04a773ad 6569
4c476991
JB
6570 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
6571 return -EOPNOTSUPP;
04a773ad 6572
4c476991 6573 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
6574}
6575
f4e583c8
AQ
6576static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
6577{
6578 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6579 struct net_device *dev = info->user_ptr[1];
6580 int mcast_rate[IEEE80211_NUM_BANDS];
6581 u32 nla_rate;
6582 int err;
6583
6584 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
6585 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6586 return -EOPNOTSUPP;
6587
6588 if (!rdev->ops->set_mcast_rate)
6589 return -EOPNOTSUPP;
6590
6591 memset(mcast_rate, 0, sizeof(mcast_rate));
6592
6593 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
6594 return -EINVAL;
6595
6596 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
6597 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
6598 return -EINVAL;
6599
6600 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
6601
6602 return err;
6603}
6604
6605
aff89a9b
JB
6606#ifdef CONFIG_NL80211_TESTMODE
6607static struct genl_multicast_group nl80211_testmode_mcgrp = {
6608 .name = "testmode",
6609};
6610
6611static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
6612{
4c476991 6613 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
6614 struct wireless_dev *wdev =
6615 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
6616 int err;
6617
fc73f11f
DS
6618 if (!rdev->ops->testmode_cmd)
6619 return -EOPNOTSUPP;
6620
6621 if (IS_ERR(wdev)) {
6622 err = PTR_ERR(wdev);
6623 if (err != -EINVAL)
6624 return err;
6625 wdev = NULL;
6626 } else if (wdev->wiphy != &rdev->wiphy) {
6627 return -EINVAL;
6628 }
6629
aff89a9b
JB
6630 if (!info->attrs[NL80211_ATTR_TESTDATA])
6631 return -EINVAL;
6632
fc73f11f
DS
6633 rdev->testmode_info = info;
6634 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
6635 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
6636 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
fc73f11f 6637 rdev->testmode_info = NULL;
aff89a9b 6638
aff89a9b
JB
6639 return err;
6640}
6641
71063f0e
WYG
6642static int nl80211_testmode_dump(struct sk_buff *skb,
6643 struct netlink_callback *cb)
6644{
00918d33 6645 struct cfg80211_registered_device *rdev;
71063f0e
WYG
6646 int err;
6647 long phy_idx;
6648 void *data = NULL;
6649 int data_len = 0;
6650
5fe231e8
JB
6651 rtnl_lock();
6652
71063f0e
WYG
6653 if (cb->args[0]) {
6654 /*
6655 * 0 is a valid index, but not valid for args[0],
6656 * so we need to offset by 1.
6657 */
6658 phy_idx = cb->args[0] - 1;
6659 } else {
6660 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
6661 nl80211_fam.attrbuf, nl80211_fam.maxattr,
6662 nl80211_policy);
6663 if (err)
5fe231e8 6664 goto out_err;
00918d33 6665
2bd7e35d
JB
6666 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
6667 nl80211_fam.attrbuf);
6668 if (IS_ERR(rdev)) {
5fe231e8
JB
6669 err = PTR_ERR(rdev);
6670 goto out_err;
00918d33 6671 }
2bd7e35d
JB
6672 phy_idx = rdev->wiphy_idx;
6673 rdev = NULL;
2bd7e35d 6674
71063f0e
WYG
6675 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
6676 cb->args[1] =
6677 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
6678 }
6679
6680 if (cb->args[1]) {
6681 data = nla_data((void *)cb->args[1]);
6682 data_len = nla_len((void *)cb->args[1]);
6683 }
6684
00918d33
JB
6685 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
6686 if (!rdev) {
5fe231e8
JB
6687 err = -ENOENT;
6688 goto out_err;
71063f0e 6689 }
71063f0e 6690
00918d33 6691 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
6692 err = -EOPNOTSUPP;
6693 goto out_err;
6694 }
6695
6696 while (1) {
15e47304 6697 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
6698 cb->nlh->nlmsg_seq, NLM_F_MULTI,
6699 NL80211_CMD_TESTMODE);
6700 struct nlattr *tmdata;
6701
cb35fba3
DC
6702 if (!hdr)
6703 break;
6704
9360ffd1 6705 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
6706 genlmsg_cancel(skb, hdr);
6707 break;
6708 }
6709
6710 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
6711 if (!tmdata) {
6712 genlmsg_cancel(skb, hdr);
6713 break;
6714 }
e35e4d28 6715 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
6716 nla_nest_end(skb, tmdata);
6717
6718 if (err == -ENOBUFS || err == -ENOENT) {
6719 genlmsg_cancel(skb, hdr);
6720 break;
6721 } else if (err) {
6722 genlmsg_cancel(skb, hdr);
6723 goto out_err;
6724 }
6725
6726 genlmsg_end(skb, hdr);
6727 }
6728
6729 err = skb->len;
6730 /* see above */
6731 cb->args[0] = phy_idx + 1;
6732 out_err:
5fe231e8 6733 rtnl_unlock();
71063f0e
WYG
6734 return err;
6735}
6736
aff89a9b
JB
6737static struct sk_buff *
6738__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 6739 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
6740{
6741 struct sk_buff *skb;
6742 void *hdr;
6743 struct nlattr *data;
6744
6745 skb = nlmsg_new(approxlen + 100, gfp);
6746 if (!skb)
6747 return NULL;
6748
15e47304 6749 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
6750 if (!hdr) {
6751 kfree_skb(skb);
6752 return NULL;
6753 }
6754
9360ffd1
DM
6755 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
6756 goto nla_put_failure;
aff89a9b
JB
6757 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
6758
6759 ((void **)skb->cb)[0] = rdev;
6760 ((void **)skb->cb)[1] = hdr;
6761 ((void **)skb->cb)[2] = data;
6762
6763 return skb;
6764
6765 nla_put_failure:
6766 kfree_skb(skb);
6767 return NULL;
6768}
6769
6770struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
6771 int approxlen)
6772{
6773 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6774
6775 if (WARN_ON(!rdev->testmode_info))
6776 return NULL;
6777
6778 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 6779 rdev->testmode_info->snd_portid,
aff89a9b
JB
6780 rdev->testmode_info->snd_seq,
6781 GFP_KERNEL);
6782}
6783EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
6784
6785int cfg80211_testmode_reply(struct sk_buff *skb)
6786{
6787 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
6788 void *hdr = ((void **)skb->cb)[1];
6789 struct nlattr *data = ((void **)skb->cb)[2];
6790
6791 if (WARN_ON(!rdev->testmode_info)) {
6792 kfree_skb(skb);
6793 return -EINVAL;
6794 }
6795
6796 nla_nest_end(skb, data);
6797 genlmsg_end(skb, hdr);
6798 return genlmsg_reply(skb, rdev->testmode_info);
6799}
6800EXPORT_SYMBOL(cfg80211_testmode_reply);
6801
6802struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
6803 int approxlen, gfp_t gfp)
6804{
6805 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6806
6807 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
6808}
6809EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
6810
6811void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
6812{
a0ec570f 6813 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
aff89a9b
JB
6814 void *hdr = ((void **)skb->cb)[1];
6815 struct nlattr *data = ((void **)skb->cb)[2];
6816
6817 nla_nest_end(skb, data);
6818 genlmsg_end(skb, hdr);
a0ec570f
MK
6819 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), skb, 0,
6820 nl80211_testmode_mcgrp.id, gfp);
aff89a9b
JB
6821}
6822EXPORT_SYMBOL(cfg80211_testmode_event);
6823#endif
6824
b23aa676
SO
6825static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
6826{
4c476991
JB
6827 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6828 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6829 struct cfg80211_connect_params connect;
6830 struct wiphy *wiphy;
fffd0934 6831 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
6832 int err;
6833
6834 memset(&connect, 0, sizeof(connect));
6835
6836 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6837 return -EINVAL;
6838
6839 if (!info->attrs[NL80211_ATTR_SSID] ||
6840 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6841 return -EINVAL;
6842
6843 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6844 connect.auth_type =
6845 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
6846 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
6847 NL80211_CMD_CONNECT))
b23aa676
SO
6848 return -EINVAL;
6849 } else
6850 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6851
6852 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
6853
c0692b8f 6854 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 6855 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
6856 if (err)
6857 return err;
b23aa676 6858
074ac8df 6859 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6860 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6861 return -EOPNOTSUPP;
b23aa676 6862
79c97e97 6863 wiphy = &rdev->wiphy;
b23aa676 6864
4486ea98
BS
6865 connect.bg_scan_period = -1;
6866 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
6867 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
6868 connect.bg_scan_period =
6869 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
6870 }
6871
b23aa676
SO
6872 if (info->attrs[NL80211_ATTR_MAC])
6873 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6874 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6875 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6876
6877 if (info->attrs[NL80211_ATTR_IE]) {
6878 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6879 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6880 }
6881
cee00a95
JM
6882 if (info->attrs[NL80211_ATTR_USE_MFP]) {
6883 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
6884 if (connect.mfp != NL80211_MFP_REQUIRED &&
6885 connect.mfp != NL80211_MFP_NO)
6886 return -EINVAL;
6887 } else {
6888 connect.mfp = NL80211_MFP_NO;
6889 }
6890
b23aa676
SO
6891 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6892 connect.channel =
6893 ieee80211_get_channel(wiphy,
6894 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
6895 if (!connect.channel ||
4c476991
JB
6896 connect.channel->flags & IEEE80211_CHAN_DISABLED)
6897 return -EINVAL;
b23aa676
SO
6898 }
6899
fffd0934
JB
6900 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
6901 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 6902 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
6903 if (IS_ERR(connkeys))
6904 return PTR_ERR(connkeys);
fffd0934
JB
6905 }
6906
7e7c8926
BG
6907 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
6908 connect.flags |= ASSOC_REQ_DISABLE_HT;
6909
6910 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6911 memcpy(&connect.ht_capa_mask,
6912 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6913 sizeof(connect.ht_capa_mask));
6914
6915 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
6916 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
6917 kfree(connkeys);
7e7c8926 6918 return -EINVAL;
b4e4f47e 6919 }
7e7c8926
BG
6920 memcpy(&connect.ht_capa,
6921 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6922 sizeof(connect.ht_capa));
6923 }
6924
ee2aca34
JB
6925 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
6926 connect.flags |= ASSOC_REQ_DISABLE_VHT;
6927
6928 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
6929 memcpy(&connect.vht_capa_mask,
6930 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
6931 sizeof(connect.vht_capa_mask));
6932
6933 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
6934 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
6935 kfree(connkeys);
6936 return -EINVAL;
6937 }
6938 memcpy(&connect.vht_capa,
6939 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
6940 sizeof(connect.vht_capa));
6941 }
6942
83739b03
JB
6943 wdev_lock(dev->ieee80211_ptr);
6944 err = cfg80211_connect(rdev, dev, &connect, connkeys, NULL);
6945 wdev_unlock(dev->ieee80211_ptr);
fffd0934
JB
6946 if (err)
6947 kfree(connkeys);
b23aa676
SO
6948 return err;
6949}
6950
6951static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
6952{
4c476991
JB
6953 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6954 struct net_device *dev = info->user_ptr[1];
b23aa676 6955 u16 reason;
83739b03 6956 int ret;
b23aa676
SO
6957
6958 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6959 reason = WLAN_REASON_DEAUTH_LEAVING;
6960 else
6961 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6962
6963 if (reason == 0)
6964 return -EINVAL;
6965
074ac8df 6966 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6967 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6968 return -EOPNOTSUPP;
b23aa676 6969
83739b03
JB
6970 wdev_lock(dev->ieee80211_ptr);
6971 ret = cfg80211_disconnect(rdev, dev, reason, true);
6972 wdev_unlock(dev->ieee80211_ptr);
6973 return ret;
b23aa676
SO
6974}
6975
463d0183
JB
6976static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
6977{
4c476991 6978 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
6979 struct net *net;
6980 int err;
6981 u32 pid;
6982
6983 if (!info->attrs[NL80211_ATTR_PID])
6984 return -EINVAL;
6985
6986 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
6987
463d0183 6988 net = get_net_ns_by_pid(pid);
4c476991
JB
6989 if (IS_ERR(net))
6990 return PTR_ERR(net);
463d0183
JB
6991
6992 err = 0;
6993
6994 /* check if anything to do */
4c476991
JB
6995 if (!net_eq(wiphy_net(&rdev->wiphy), net))
6996 err = cfg80211_switch_netns(rdev, net);
463d0183 6997
463d0183 6998 put_net(net);
463d0183
JB
6999 return err;
7000}
7001
67fbb16b
SO
7002static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
7003{
4c476991 7004 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
7005 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
7006 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 7007 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
7008 struct cfg80211_pmksa pmksa;
7009
7010 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
7011
7012 if (!info->attrs[NL80211_ATTR_MAC])
7013 return -EINVAL;
7014
7015 if (!info->attrs[NL80211_ATTR_PMKID])
7016 return -EINVAL;
7017
67fbb16b
SO
7018 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
7019 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
7020
074ac8df 7021 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7022 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7023 return -EOPNOTSUPP;
67fbb16b
SO
7024
7025 switch (info->genlhdr->cmd) {
7026 case NL80211_CMD_SET_PMKSA:
7027 rdev_ops = rdev->ops->set_pmksa;
7028 break;
7029 case NL80211_CMD_DEL_PMKSA:
7030 rdev_ops = rdev->ops->del_pmksa;
7031 break;
7032 default:
7033 WARN_ON(1);
7034 break;
7035 }
7036
4c476991
JB
7037 if (!rdev_ops)
7038 return -EOPNOTSUPP;
67fbb16b 7039
4c476991 7040 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
7041}
7042
7043static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
7044{
4c476991
JB
7045 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7046 struct net_device *dev = info->user_ptr[1];
67fbb16b 7047
074ac8df 7048 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7049 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7050 return -EOPNOTSUPP;
67fbb16b 7051
4c476991
JB
7052 if (!rdev->ops->flush_pmksa)
7053 return -EOPNOTSUPP;
67fbb16b 7054
e35e4d28 7055 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
7056}
7057
109086ce
AN
7058static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
7059{
7060 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7061 struct net_device *dev = info->user_ptr[1];
7062 u8 action_code, dialog_token;
7063 u16 status_code;
7064 u8 *peer;
7065
7066 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
7067 !rdev->ops->tdls_mgmt)
7068 return -EOPNOTSUPP;
7069
7070 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
7071 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
7072 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
7073 !info->attrs[NL80211_ATTR_IE] ||
7074 !info->attrs[NL80211_ATTR_MAC])
7075 return -EINVAL;
7076
7077 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
7078 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
7079 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
7080 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
7081
e35e4d28
HG
7082 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
7083 dialog_token, status_code,
7084 nla_data(info->attrs[NL80211_ATTR_IE]),
7085 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
7086}
7087
7088static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
7089{
7090 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7091 struct net_device *dev = info->user_ptr[1];
7092 enum nl80211_tdls_operation operation;
7093 u8 *peer;
7094
7095 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
7096 !rdev->ops->tdls_oper)
7097 return -EOPNOTSUPP;
7098
7099 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
7100 !info->attrs[NL80211_ATTR_MAC])
7101 return -EINVAL;
7102
7103 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
7104 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
7105
e35e4d28 7106 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
7107}
7108
9588bbd5
JM
7109static int nl80211_remain_on_channel(struct sk_buff *skb,
7110 struct genl_info *info)
7111{
4c476991 7112 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7113 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 7114 struct cfg80211_chan_def chandef;
9588bbd5
JM
7115 struct sk_buff *msg;
7116 void *hdr;
7117 u64 cookie;
683b6d3b 7118 u32 duration;
9588bbd5
JM
7119 int err;
7120
7121 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
7122 !info->attrs[NL80211_ATTR_DURATION])
7123 return -EINVAL;
7124
7125 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
7126
ebf348fc
JB
7127 if (!rdev->ops->remain_on_channel ||
7128 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
7129 return -EOPNOTSUPP;
7130
9588bbd5 7131 /*
ebf348fc
JB
7132 * We should be on that channel for at least a minimum amount of
7133 * time (10ms) but no longer than the driver supports.
9588bbd5 7134 */
ebf348fc 7135 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 7136 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
7137 return -EINVAL;
7138
683b6d3b
JB
7139 err = nl80211_parse_chandef(rdev, info, &chandef);
7140 if (err)
7141 return err;
9588bbd5
JM
7142
7143 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
7144 if (!msg)
7145 return -ENOMEM;
9588bbd5 7146
15e47304 7147 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 7148 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
7149 if (!hdr) {
7150 err = -ENOBUFS;
9588bbd5
JM
7151 goto free_msg;
7152 }
7153
683b6d3b
JB
7154 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
7155 duration, &cookie);
9588bbd5
JM
7156
7157 if (err)
7158 goto free_msg;
7159
9360ffd1
DM
7160 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7161 goto nla_put_failure;
9588bbd5
JM
7162
7163 genlmsg_end(msg, hdr);
4c476991
JB
7164
7165 return genlmsg_reply(msg, info);
9588bbd5
JM
7166
7167 nla_put_failure:
7168 err = -ENOBUFS;
7169 free_msg:
7170 nlmsg_free(msg);
9588bbd5
JM
7171 return err;
7172}
7173
7174static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
7175 struct genl_info *info)
7176{
4c476991 7177 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7178 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 7179 u64 cookie;
9588bbd5
JM
7180
7181 if (!info->attrs[NL80211_ATTR_COOKIE])
7182 return -EINVAL;
7183
4c476991
JB
7184 if (!rdev->ops->cancel_remain_on_channel)
7185 return -EOPNOTSUPP;
9588bbd5 7186
9588bbd5
JM
7187 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
7188
e35e4d28 7189 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
7190}
7191
13ae75b1
JM
7192static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
7193 u8 *rates, u8 rates_len)
7194{
7195 u8 i;
7196 u32 mask = 0;
7197
7198 for (i = 0; i < rates_len; i++) {
7199 int rate = (rates[i] & 0x7f) * 5;
7200 int ridx;
7201 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
7202 struct ieee80211_rate *srate =
7203 &sband->bitrates[ridx];
7204 if (rate == srate->bitrate) {
7205 mask |= 1 << ridx;
7206 break;
7207 }
7208 }
7209 if (ridx == sband->n_bitrates)
7210 return 0; /* rate not found */
7211 }
7212
7213 return mask;
7214}
7215
24db78c0
SW
7216static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
7217 u8 *rates, u8 rates_len,
7218 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
7219{
7220 u8 i;
7221
7222 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
7223
7224 for (i = 0; i < rates_len; i++) {
7225 int ridx, rbit;
7226
7227 ridx = rates[i] / 8;
7228 rbit = BIT(rates[i] % 8);
7229
7230 /* check validity */
910570b5 7231 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
7232 return false;
7233
7234 /* check availability */
7235 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
7236 mcs[ridx] |= rbit;
7237 else
7238 return false;
7239 }
7240
7241 return true;
7242}
7243
b54452b0 7244static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
7245 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
7246 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
7247 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
7248 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
7249};
7250
7251static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
7252 struct genl_info *info)
7253{
7254 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 7255 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 7256 struct cfg80211_bitrate_mask mask;
4c476991
JB
7257 int rem, i;
7258 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
7259 struct nlattr *tx_rates;
7260 struct ieee80211_supported_band *sband;
7261
7262 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
7263 return -EINVAL;
7264
4c476991
JB
7265 if (!rdev->ops->set_bitrate_mask)
7266 return -EOPNOTSUPP;
13ae75b1
JM
7267
7268 memset(&mask, 0, sizeof(mask));
7269 /* Default to all rates enabled */
7270 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
7271 sband = rdev->wiphy.bands[i];
7272 mask.control[i].legacy =
7273 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
7274 if (sband)
7275 memcpy(mask.control[i].mcs,
7276 sband->ht_cap.mcs.rx_mask,
7277 sizeof(mask.control[i].mcs));
7278 else
7279 memset(mask.control[i].mcs, 0,
7280 sizeof(mask.control[i].mcs));
13ae75b1
JM
7281 }
7282
7283 /*
7284 * The nested attribute uses enum nl80211_band as the index. This maps
7285 * directly to the enum ieee80211_band values used in cfg80211.
7286 */
24db78c0 7287 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
7288 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
7289 {
7290 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
7291 if (band < 0 || band >= IEEE80211_NUM_BANDS)
7292 return -EINVAL;
13ae75b1 7293 sband = rdev->wiphy.bands[band];
4c476991
JB
7294 if (sband == NULL)
7295 return -EINVAL;
13ae75b1
JM
7296 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
7297 nla_len(tx_rates), nl80211_txattr_policy);
7298 if (tb[NL80211_TXRATE_LEGACY]) {
7299 mask.control[band].legacy = rateset_to_mask(
7300 sband,
7301 nla_data(tb[NL80211_TXRATE_LEGACY]),
7302 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
7303 if ((mask.control[band].legacy == 0) &&
7304 nla_len(tb[NL80211_TXRATE_LEGACY]))
7305 return -EINVAL;
24db78c0
SW
7306 }
7307 if (tb[NL80211_TXRATE_MCS]) {
7308 if (!ht_rateset_to_mask(
7309 sband,
7310 nla_data(tb[NL80211_TXRATE_MCS]),
7311 nla_len(tb[NL80211_TXRATE_MCS]),
7312 mask.control[band].mcs))
7313 return -EINVAL;
7314 }
7315
7316 if (mask.control[band].legacy == 0) {
7317 /* don't allow empty legacy rates if HT
7318 * is not even supported. */
7319 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
7320 return -EINVAL;
7321
7322 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
7323 if (mask.control[band].mcs[i])
7324 break;
7325
7326 /* legacy and mcs rates may not be both empty */
7327 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 7328 return -EINVAL;
13ae75b1
JM
7329 }
7330 }
7331
e35e4d28 7332 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
7333}
7334
2e161f78 7335static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 7336{
4c476991 7337 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7338 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 7339 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
7340
7341 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
7342 return -EINVAL;
7343
2e161f78
JB
7344 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
7345 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 7346
71bbc994
JB
7347 switch (wdev->iftype) {
7348 case NL80211_IFTYPE_STATION:
7349 case NL80211_IFTYPE_ADHOC:
7350 case NL80211_IFTYPE_P2P_CLIENT:
7351 case NL80211_IFTYPE_AP:
7352 case NL80211_IFTYPE_AP_VLAN:
7353 case NL80211_IFTYPE_MESH_POINT:
7354 case NL80211_IFTYPE_P2P_GO:
98104fde 7355 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
7356 break;
7357 default:
4c476991 7358 return -EOPNOTSUPP;
71bbc994 7359 }
026331c4
JM
7360
7361 /* not much point in registering if we can't reply */
4c476991
JB
7362 if (!rdev->ops->mgmt_tx)
7363 return -EOPNOTSUPP;
026331c4 7364
15e47304 7365 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
7366 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
7367 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
7368}
7369
2e161f78 7370static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 7371{
4c476991 7372 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7373 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 7374 struct cfg80211_chan_def chandef;
026331c4 7375 int err;
d64d373f 7376 void *hdr = NULL;
026331c4 7377 u64 cookie;
e247bd90 7378 struct sk_buff *msg = NULL;
f7ca38df 7379 unsigned int wait = 0;
e247bd90
JB
7380 bool offchan, no_cck, dont_wait_for_ack;
7381
7382 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 7383
683b6d3b 7384 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
7385 return -EINVAL;
7386
4c476991
JB
7387 if (!rdev->ops->mgmt_tx)
7388 return -EOPNOTSUPP;
026331c4 7389
71bbc994 7390 switch (wdev->iftype) {
ea141b75
AQ
7391 case NL80211_IFTYPE_P2P_DEVICE:
7392 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
7393 return -EINVAL;
71bbc994
JB
7394 case NL80211_IFTYPE_STATION:
7395 case NL80211_IFTYPE_ADHOC:
7396 case NL80211_IFTYPE_P2P_CLIENT:
7397 case NL80211_IFTYPE_AP:
7398 case NL80211_IFTYPE_AP_VLAN:
7399 case NL80211_IFTYPE_MESH_POINT:
7400 case NL80211_IFTYPE_P2P_GO:
7401 break;
7402 default:
4c476991 7403 return -EOPNOTSUPP;
71bbc994 7404 }
026331c4 7405
f7ca38df 7406 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 7407 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
7408 return -EINVAL;
7409 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
7410
7411 /*
7412 * We should wait on the channel for at least a minimum amount
7413 * of time (10ms) but no longer than the driver supports.
7414 */
7415 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
7416 wait > rdev->wiphy.max_remain_on_channel_duration)
7417 return -EINVAL;
7418
f7ca38df
JB
7419 }
7420
f7ca38df
JB
7421 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
7422
7c4ef712
JB
7423 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7424 return -EINVAL;
7425
e9f935e3
RM
7426 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
7427
ea141b75
AQ
7428 /* get the channel if any has been specified, otherwise pass NULL to
7429 * the driver. The latter will use the current one
7430 */
7431 chandef.chan = NULL;
7432 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
7433 err = nl80211_parse_chandef(rdev, info, &chandef);
7434 if (err)
7435 return err;
7436 }
7437
7438 if (!chandef.chan && offchan)
7439 return -EINVAL;
026331c4 7440
e247bd90
JB
7441 if (!dont_wait_for_ack) {
7442 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7443 if (!msg)
7444 return -ENOMEM;
026331c4 7445
15e47304 7446 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 7447 NL80211_CMD_FRAME);
cb35fba3
DC
7448 if (!hdr) {
7449 err = -ENOBUFS;
e247bd90
JB
7450 goto free_msg;
7451 }
026331c4 7452 }
e247bd90 7453
683b6d3b 7454 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
7455 nla_data(info->attrs[NL80211_ATTR_FRAME]),
7456 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 7457 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
7458 if (err)
7459 goto free_msg;
7460
e247bd90 7461 if (msg) {
9360ffd1
DM
7462 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7463 goto nla_put_failure;
026331c4 7464
e247bd90
JB
7465 genlmsg_end(msg, hdr);
7466 return genlmsg_reply(msg, info);
7467 }
7468
7469 return 0;
026331c4
JM
7470
7471 nla_put_failure:
7472 err = -ENOBUFS;
7473 free_msg:
7474 nlmsg_free(msg);
026331c4
JM
7475 return err;
7476}
7477
f7ca38df
JB
7478static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
7479{
7480 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7481 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
7482 u64 cookie;
7483
7484 if (!info->attrs[NL80211_ATTR_COOKIE])
7485 return -EINVAL;
7486
7487 if (!rdev->ops->mgmt_tx_cancel_wait)
7488 return -EOPNOTSUPP;
7489
71bbc994
JB
7490 switch (wdev->iftype) {
7491 case NL80211_IFTYPE_STATION:
7492 case NL80211_IFTYPE_ADHOC:
7493 case NL80211_IFTYPE_P2P_CLIENT:
7494 case NL80211_IFTYPE_AP:
7495 case NL80211_IFTYPE_AP_VLAN:
7496 case NL80211_IFTYPE_P2P_GO:
98104fde 7497 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
7498 break;
7499 default:
f7ca38df 7500 return -EOPNOTSUPP;
71bbc994 7501 }
f7ca38df
JB
7502
7503 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
7504
e35e4d28 7505 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
7506}
7507
ffb9eb3d
KV
7508static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
7509{
4c476991 7510 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 7511 struct wireless_dev *wdev;
4c476991 7512 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
7513 u8 ps_state;
7514 bool state;
7515 int err;
7516
4c476991
JB
7517 if (!info->attrs[NL80211_ATTR_PS_STATE])
7518 return -EINVAL;
ffb9eb3d
KV
7519
7520 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
7521
4c476991
JB
7522 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
7523 return -EINVAL;
ffb9eb3d
KV
7524
7525 wdev = dev->ieee80211_ptr;
7526
4c476991
JB
7527 if (!rdev->ops->set_power_mgmt)
7528 return -EOPNOTSUPP;
ffb9eb3d
KV
7529
7530 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
7531
7532 if (state == wdev->ps)
4c476991 7533 return 0;
ffb9eb3d 7534
e35e4d28 7535 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
7536 if (!err)
7537 wdev->ps = state;
ffb9eb3d
KV
7538 return err;
7539}
7540
7541static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
7542{
4c476991 7543 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
7544 enum nl80211_ps_state ps_state;
7545 struct wireless_dev *wdev;
4c476991 7546 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
7547 struct sk_buff *msg;
7548 void *hdr;
7549 int err;
7550
ffb9eb3d
KV
7551 wdev = dev->ieee80211_ptr;
7552
4c476991
JB
7553 if (!rdev->ops->set_power_mgmt)
7554 return -EOPNOTSUPP;
ffb9eb3d
KV
7555
7556 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
7557 if (!msg)
7558 return -ENOMEM;
ffb9eb3d 7559
15e47304 7560 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
7561 NL80211_CMD_GET_POWER_SAVE);
7562 if (!hdr) {
4c476991 7563 err = -ENOBUFS;
ffb9eb3d
KV
7564 goto free_msg;
7565 }
7566
7567 if (wdev->ps)
7568 ps_state = NL80211_PS_ENABLED;
7569 else
7570 ps_state = NL80211_PS_DISABLED;
7571
9360ffd1
DM
7572 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
7573 goto nla_put_failure;
ffb9eb3d
KV
7574
7575 genlmsg_end(msg, hdr);
4c476991 7576 return genlmsg_reply(msg, info);
ffb9eb3d 7577
4c476991 7578 nla_put_failure:
ffb9eb3d 7579 err = -ENOBUFS;
4c476991 7580 free_msg:
ffb9eb3d 7581 nlmsg_free(msg);
ffb9eb3d
KV
7582 return err;
7583}
7584
d6dc1a38
JO
7585static struct nla_policy
7586nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
7587 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
7588 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
7589 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
7590 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
7591 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
7592 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
7593};
7594
84f10708 7595static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 7596 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
7597{
7598 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 7599 struct net_device *dev = info->user_ptr[1];
1da5fcc8 7600 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 7601
d9d8b019 7602 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
7603 return -EINVAL;
7604
84f10708
TP
7605 if (!rdev->ops->set_cqm_txe_config)
7606 return -EOPNOTSUPP;
7607
7608 if (wdev->iftype != NL80211_IFTYPE_STATION &&
7609 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
7610 return -EOPNOTSUPP;
7611
e35e4d28 7612 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
7613}
7614
d6dc1a38
JO
7615static int nl80211_set_cqm_rssi(struct genl_info *info,
7616 s32 threshold, u32 hysteresis)
7617{
4c476991 7618 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 7619 struct net_device *dev = info->user_ptr[1];
1da5fcc8 7620 struct wireless_dev *wdev = dev->ieee80211_ptr;
d6dc1a38
JO
7621
7622 if (threshold > 0)
7623 return -EINVAL;
7624
1da5fcc8
JB
7625 /* disabling - hysteresis should also be zero then */
7626 if (threshold == 0)
7627 hysteresis = 0;
d6dc1a38 7628
4c476991
JB
7629 if (!rdev->ops->set_cqm_rssi_config)
7630 return -EOPNOTSUPP;
d6dc1a38 7631
074ac8df 7632 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7633 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
7634 return -EOPNOTSUPP;
d6dc1a38 7635
e35e4d28 7636 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
7637}
7638
7639static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
7640{
7641 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
7642 struct nlattr *cqm;
7643 int err;
7644
7645 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
7646 if (!cqm)
7647 return -EINVAL;
d6dc1a38
JO
7648
7649 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
7650 nl80211_attr_cqm_policy);
7651 if (err)
1da5fcc8 7652 return err;
d6dc1a38
JO
7653
7654 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
7655 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
1da5fcc8
JB
7656 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
7657 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 7658
1da5fcc8
JB
7659 return nl80211_set_cqm_rssi(info, threshold, hysteresis);
7660 }
7661
7662 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
7663 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
7664 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
7665 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
7666 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
7667 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
7668
7669 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
7670 }
7671
7672 return -EINVAL;
d6dc1a38
JO
7673}
7674
29cbe68c
JB
7675static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
7676{
7677 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7678 struct net_device *dev = info->user_ptr[1];
7679 struct mesh_config cfg;
c80d545d 7680 struct mesh_setup setup;
29cbe68c
JB
7681 int err;
7682
7683 /* start with default */
7684 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 7685 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 7686
24bdd9f4 7687 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 7688 /* and parse parameters if given */
24bdd9f4 7689 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
7690 if (err)
7691 return err;
7692 }
7693
7694 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
7695 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
7696 return -EINVAL;
7697
c80d545d
JC
7698 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
7699 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
7700
4bb62344
CYY
7701 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
7702 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
7703 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
7704 return -EINVAL;
7705
9bdbf04d
MP
7706 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
7707 setup.beacon_interval =
7708 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
7709 if (setup.beacon_interval < 10 ||
7710 setup.beacon_interval > 10000)
7711 return -EINVAL;
7712 }
7713
7714 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
7715 setup.dtim_period =
7716 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
7717 if (setup.dtim_period < 1 || setup.dtim_period > 100)
7718 return -EINVAL;
7719 }
7720
c80d545d
JC
7721 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
7722 /* parse additional setup parameters if given */
7723 err = nl80211_parse_mesh_setup(info, &setup);
7724 if (err)
7725 return err;
7726 }
7727
d37bb18a
TP
7728 if (setup.user_mpm)
7729 cfg.auto_open_plinks = false;
7730
cc1d2806 7731 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
7732 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
7733 if (err)
7734 return err;
cc1d2806
JB
7735 } else {
7736 /* cfg80211_join_mesh() will sort it out */
683b6d3b 7737 setup.chandef.chan = NULL;
cc1d2806
JB
7738 }
7739
ffb3cf30
AN
7740 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
7741 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7742 int n_rates =
7743 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7744 struct ieee80211_supported_band *sband;
7745
7746 if (!setup.chandef.chan)
7747 return -EINVAL;
7748
7749 sband = rdev->wiphy.bands[setup.chandef.chan->band];
7750
7751 err = ieee80211_get_ratemask(sband, rates, n_rates,
7752 &setup.basic_rates);
7753 if (err)
7754 return err;
7755 }
7756
c80d545d 7757 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
7758}
7759
7760static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
7761{
7762 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7763 struct net_device *dev = info->user_ptr[1];
7764
7765 return cfg80211_leave_mesh(rdev, dev);
7766}
7767
dfb89c56 7768#ifdef CONFIG_PM
bb92d199
AK
7769static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
7770 struct cfg80211_registered_device *rdev)
7771{
6abb9cb9 7772 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
7773 struct nlattr *nl_pats, *nl_pat;
7774 int i, pat_len;
7775
6abb9cb9 7776 if (!wowlan->n_patterns)
bb92d199
AK
7777 return 0;
7778
7779 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
7780 if (!nl_pats)
7781 return -ENOBUFS;
7782
6abb9cb9 7783 for (i = 0; i < wowlan->n_patterns; i++) {
bb92d199
AK
7784 nl_pat = nla_nest_start(msg, i + 1);
7785 if (!nl_pat)
7786 return -ENOBUFS;
6abb9cb9 7787 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 7788 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 7789 wowlan->patterns[i].mask) ||
50ac6607
AK
7790 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
7791 wowlan->patterns[i].pattern) ||
7792 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 7793 wowlan->patterns[i].pkt_offset))
bb92d199
AK
7794 return -ENOBUFS;
7795 nla_nest_end(msg, nl_pat);
7796 }
7797 nla_nest_end(msg, nl_pats);
7798
7799 return 0;
7800}
7801
2a0e047e
JB
7802static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
7803 struct cfg80211_wowlan_tcp *tcp)
7804{
7805 struct nlattr *nl_tcp;
7806
7807 if (!tcp)
7808 return 0;
7809
7810 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
7811 if (!nl_tcp)
7812 return -ENOBUFS;
7813
7814 if (nla_put_be32(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
7815 nla_put_be32(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
7816 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
7817 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
7818 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
7819 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
7820 tcp->payload_len, tcp->payload) ||
7821 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
7822 tcp->data_interval) ||
7823 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
7824 tcp->wake_len, tcp->wake_data) ||
7825 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
7826 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
7827 return -ENOBUFS;
7828
7829 if (tcp->payload_seq.len &&
7830 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
7831 sizeof(tcp->payload_seq), &tcp->payload_seq))
7832 return -ENOBUFS;
7833
7834 if (tcp->payload_tok.len &&
7835 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
7836 sizeof(tcp->payload_tok) + tcp->tokens_size,
7837 &tcp->payload_tok))
7838 return -ENOBUFS;
7839
e248ad30
JB
7840 nla_nest_end(msg, nl_tcp);
7841
2a0e047e
JB
7842 return 0;
7843}
7844
ff1b6e69
JB
7845static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
7846{
7847 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7848 struct sk_buff *msg;
7849 void *hdr;
2a0e047e 7850 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 7851
964dc9e2 7852 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
7853 return -EOPNOTSUPP;
7854
6abb9cb9 7855 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 7856 /* adjust size to have room for all the data */
6abb9cb9
JB
7857 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
7858 rdev->wiphy.wowlan_config->tcp->payload_len +
7859 rdev->wiphy.wowlan_config->tcp->wake_len +
7860 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
7861 }
7862
7863 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
7864 if (!msg)
7865 return -ENOMEM;
7866
15e47304 7867 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
7868 NL80211_CMD_GET_WOWLAN);
7869 if (!hdr)
7870 goto nla_put_failure;
7871
6abb9cb9 7872 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
7873 struct nlattr *nl_wowlan;
7874
7875 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7876 if (!nl_wowlan)
7877 goto nla_put_failure;
7878
6abb9cb9 7879 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 7880 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 7881 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 7882 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 7883 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 7884 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 7885 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 7886 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 7887 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 7888 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 7889 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 7890 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 7891 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
7892 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
7893 goto nla_put_failure;
2a0e047e 7894
bb92d199
AK
7895 if (nl80211_send_wowlan_patterns(msg, rdev))
7896 goto nla_put_failure;
2a0e047e 7897
6abb9cb9
JB
7898 if (nl80211_send_wowlan_tcp(msg,
7899 rdev->wiphy.wowlan_config->tcp))
2a0e047e
JB
7900 goto nla_put_failure;
7901
ff1b6e69
JB
7902 nla_nest_end(msg, nl_wowlan);
7903 }
7904
7905 genlmsg_end(msg, hdr);
7906 return genlmsg_reply(msg, info);
7907
7908nla_put_failure:
7909 nlmsg_free(msg);
7910 return -ENOBUFS;
7911}
7912
2a0e047e
JB
7913static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
7914 struct nlattr *attr,
7915 struct cfg80211_wowlan *trig)
7916{
7917 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
7918 struct cfg80211_wowlan_tcp *cfg;
7919 struct nl80211_wowlan_tcp_data_token *tok = NULL;
7920 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
7921 u32 size;
7922 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
7923 int err, port;
7924
964dc9e2 7925 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
7926 return -EINVAL;
7927
7928 err = nla_parse(tb, MAX_NL80211_WOWLAN_TCP,
7929 nla_data(attr), nla_len(attr),
7930 nl80211_wowlan_tcp_policy);
7931 if (err)
7932 return err;
7933
7934 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
7935 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
7936 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
7937 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
7938 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
7939 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
7940 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
7941 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
7942 return -EINVAL;
7943
7944 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 7945 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
7946 return -EINVAL;
7947
7948 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 7949 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 7950 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
7951 return -EINVAL;
7952
7953 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 7954 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
7955 return -EINVAL;
7956
7957 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
7958 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
7959 return -EINVAL;
7960
7961 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
7962 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
7963
7964 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
7965 tokens_size = tokln - sizeof(*tok);
7966
7967 if (!tok->len || tokens_size % tok->len)
7968 return -EINVAL;
964dc9e2 7969 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 7970 return -EINVAL;
964dc9e2 7971 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 7972 return -EINVAL;
964dc9e2 7973 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 7974 return -EINVAL;
964dc9e2 7975 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
7976 return -EINVAL;
7977 if (tok->offset + tok->len > data_size)
7978 return -EINVAL;
7979 }
7980
7981 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
7982 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 7983 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
7984 return -EINVAL;
7985 if (seq->len == 0 || seq->len > 4)
7986 return -EINVAL;
7987 if (seq->len + seq->offset > data_size)
7988 return -EINVAL;
7989 }
7990
7991 size = sizeof(*cfg);
7992 size += data_size;
7993 size += wake_size + wake_mask_size;
7994 size += tokens_size;
7995
7996 cfg = kzalloc(size, GFP_KERNEL);
7997 if (!cfg)
7998 return -ENOMEM;
7999 cfg->src = nla_get_be32(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
8000 cfg->dst = nla_get_be32(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
8001 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
8002 ETH_ALEN);
8003 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
8004 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
8005 else
8006 port = 0;
8007#ifdef CONFIG_INET
8008 /* allocate a socket and port for it and use it */
8009 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
8010 IPPROTO_TCP, &cfg->sock, 1);
8011 if (err) {
8012 kfree(cfg);
8013 return err;
8014 }
8015 if (inet_csk_get_port(cfg->sock->sk, port)) {
8016 sock_release(cfg->sock);
8017 kfree(cfg);
8018 return -EADDRINUSE;
8019 }
8020 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
8021#else
8022 if (!port) {
8023 kfree(cfg);
8024 return -EINVAL;
8025 }
8026 cfg->src_port = port;
8027#endif
8028
8029 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
8030 cfg->payload_len = data_size;
8031 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
8032 memcpy((void *)cfg->payload,
8033 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
8034 data_size);
8035 if (seq)
8036 cfg->payload_seq = *seq;
8037 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
8038 cfg->wake_len = wake_size;
8039 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
8040 memcpy((void *)cfg->wake_data,
8041 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
8042 wake_size);
8043 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
8044 data_size + wake_size;
8045 memcpy((void *)cfg->wake_mask,
8046 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
8047 wake_mask_size);
8048 if (tok) {
8049 cfg->tokens_size = tokens_size;
8050 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
8051 }
8052
8053 trig->tcp = cfg;
8054
8055 return 0;
8056}
8057
ff1b6e69
JB
8058static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
8059{
8060 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8061 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 8062 struct cfg80211_wowlan new_triggers = {};
ae33bd81 8063 struct cfg80211_wowlan *ntrig;
964dc9e2 8064 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 8065 int err, i;
6abb9cb9 8066 bool prev_enabled = rdev->wiphy.wowlan_config;
ff1b6e69 8067
964dc9e2 8068 if (!wowlan)
ff1b6e69
JB
8069 return -EOPNOTSUPP;
8070
ae33bd81
JB
8071 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
8072 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 8073 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
8074 goto set_wakeup;
8075 }
ff1b6e69
JB
8076
8077 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
8078 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
8079 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
8080 nl80211_wowlan_policy);
8081 if (err)
8082 return err;
8083
8084 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
8085 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
8086 return -EINVAL;
8087 new_triggers.any = true;
8088 }
8089
8090 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
8091 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
8092 return -EINVAL;
8093 new_triggers.disconnect = true;
8094 }
8095
8096 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
8097 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
8098 return -EINVAL;
8099 new_triggers.magic_pkt = true;
8100 }
8101
77dbbb13
JB
8102 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
8103 return -EINVAL;
8104
8105 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
8106 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
8107 return -EINVAL;
8108 new_triggers.gtk_rekey_failure = true;
8109 }
8110
8111 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
8112 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
8113 return -EINVAL;
8114 new_triggers.eap_identity_req = true;
8115 }
8116
8117 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
8118 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
8119 return -EINVAL;
8120 new_triggers.four_way_handshake = true;
8121 }
8122
8123 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
8124 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
8125 return -EINVAL;
8126 new_triggers.rfkill_release = true;
8127 }
8128
ff1b6e69
JB
8129 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
8130 struct nlattr *pat;
8131 int n_patterns = 0;
bb92d199 8132 int rem, pat_len, mask_len, pkt_offset;
50ac6607 8133 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69
JB
8134
8135 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
8136 rem)
8137 n_patterns++;
8138 if (n_patterns > wowlan->n_patterns)
8139 return -EINVAL;
8140
8141 new_triggers.patterns = kcalloc(n_patterns,
8142 sizeof(new_triggers.patterns[0]),
8143 GFP_KERNEL);
8144 if (!new_triggers.patterns)
8145 return -ENOMEM;
8146
8147 new_triggers.n_patterns = n_patterns;
8148 i = 0;
8149
8150 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
8151 rem) {
50ac6607
AK
8152 nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
8153 nla_len(pat), NULL);
ff1b6e69 8154 err = -EINVAL;
50ac6607
AK
8155 if (!pat_tb[NL80211_PKTPAT_MASK] ||
8156 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 8157 goto error;
50ac6607 8158 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 8159 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 8160 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
8161 goto error;
8162 if (pat_len > wowlan->pattern_max_len ||
8163 pat_len < wowlan->pattern_min_len)
8164 goto error;
8165
50ac6607 8166 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
8167 pkt_offset = 0;
8168 else
8169 pkt_offset = nla_get_u32(
50ac6607 8170 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
8171 if (pkt_offset > wowlan->max_pkt_offset)
8172 goto error;
8173 new_triggers.patterns[i].pkt_offset = pkt_offset;
8174
ff1b6e69
JB
8175 new_triggers.patterns[i].mask =
8176 kmalloc(mask_len + pat_len, GFP_KERNEL);
8177 if (!new_triggers.patterns[i].mask) {
8178 err = -ENOMEM;
8179 goto error;
8180 }
8181 new_triggers.patterns[i].pattern =
8182 new_triggers.patterns[i].mask + mask_len;
8183 memcpy(new_triggers.patterns[i].mask,
50ac6607 8184 nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69
JB
8185 mask_len);
8186 new_triggers.patterns[i].pattern_len = pat_len;
8187 memcpy(new_triggers.patterns[i].pattern,
50ac6607 8188 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
8189 pat_len);
8190 i++;
8191 }
8192 }
8193
2a0e047e
JB
8194 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
8195 err = nl80211_parse_wowlan_tcp(
8196 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
8197 &new_triggers);
8198 if (err)
8199 goto error;
8200 }
8201
ae33bd81
JB
8202 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
8203 if (!ntrig) {
8204 err = -ENOMEM;
8205 goto error;
ff1b6e69 8206 }
ae33bd81 8207 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 8208 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 8209
ae33bd81 8210 set_wakeup:
6abb9cb9
JB
8211 if (rdev->ops->set_wakeup &&
8212 prev_enabled != !!rdev->wiphy.wowlan_config)
8213 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 8214
ff1b6e69
JB
8215 return 0;
8216 error:
8217 for (i = 0; i < new_triggers.n_patterns; i++)
8218 kfree(new_triggers.patterns[i].mask);
8219 kfree(new_triggers.patterns);
2a0e047e
JB
8220 if (new_triggers.tcp && new_triggers.tcp->sock)
8221 sock_release(new_triggers.tcp->sock);
8222 kfree(new_triggers.tcp);
ff1b6e69
JB
8223 return err;
8224}
dfb89c56 8225#endif
ff1b6e69 8226
be29b99a
AK
8227static int nl80211_send_coalesce_rules(struct sk_buff *msg,
8228 struct cfg80211_registered_device *rdev)
8229{
8230 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
8231 int i, j, pat_len;
8232 struct cfg80211_coalesce_rules *rule;
8233
8234 if (!rdev->coalesce->n_rules)
8235 return 0;
8236
8237 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE);
8238 if (!nl_rules)
8239 return -ENOBUFS;
8240
8241 for (i = 0; i < rdev->coalesce->n_rules; i++) {
8242 nl_rule = nla_nest_start(msg, i + 1);
8243 if (!nl_rule)
8244 return -ENOBUFS;
8245
8246 rule = &rdev->coalesce->rules[i];
8247 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
8248 rule->delay))
8249 return -ENOBUFS;
8250
8251 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
8252 rule->condition))
8253 return -ENOBUFS;
8254
8255 nl_pats = nla_nest_start(msg,
8256 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
8257 if (!nl_pats)
8258 return -ENOBUFS;
8259
8260 for (j = 0; j < rule->n_patterns; j++) {
8261 nl_pat = nla_nest_start(msg, j + 1);
8262 if (!nl_pat)
8263 return -ENOBUFS;
8264 pat_len = rule->patterns[j].pattern_len;
8265 if (nla_put(msg, NL80211_PKTPAT_MASK,
8266 DIV_ROUND_UP(pat_len, 8),
8267 rule->patterns[j].mask) ||
8268 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
8269 rule->patterns[j].pattern) ||
8270 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
8271 rule->patterns[j].pkt_offset))
8272 return -ENOBUFS;
8273 nla_nest_end(msg, nl_pat);
8274 }
8275 nla_nest_end(msg, nl_pats);
8276 nla_nest_end(msg, nl_rule);
8277 }
8278 nla_nest_end(msg, nl_rules);
8279
8280 return 0;
8281}
8282
8283static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
8284{
8285 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8286 struct sk_buff *msg;
8287 void *hdr;
8288
8289 if (!rdev->wiphy.coalesce)
8290 return -EOPNOTSUPP;
8291
8292 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8293 if (!msg)
8294 return -ENOMEM;
8295
8296 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8297 NL80211_CMD_GET_COALESCE);
8298 if (!hdr)
8299 goto nla_put_failure;
8300
8301 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
8302 goto nla_put_failure;
8303
8304 genlmsg_end(msg, hdr);
8305 return genlmsg_reply(msg, info);
8306
8307nla_put_failure:
8308 nlmsg_free(msg);
8309 return -ENOBUFS;
8310}
8311
8312void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
8313{
8314 struct cfg80211_coalesce *coalesce = rdev->coalesce;
8315 int i, j;
8316 struct cfg80211_coalesce_rules *rule;
8317
8318 if (!coalesce)
8319 return;
8320
8321 for (i = 0; i < coalesce->n_rules; i++) {
8322 rule = &coalesce->rules[i];
8323 for (j = 0; j < rule->n_patterns; j++)
8324 kfree(rule->patterns[j].mask);
8325 kfree(rule->patterns);
8326 }
8327 kfree(coalesce->rules);
8328 kfree(coalesce);
8329 rdev->coalesce = NULL;
8330}
8331
8332static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
8333 struct nlattr *rule,
8334 struct cfg80211_coalesce_rules *new_rule)
8335{
8336 int err, i;
8337 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
8338 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
8339 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
8340 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
8341
8342 err = nla_parse(tb, NL80211_ATTR_COALESCE_RULE_MAX, nla_data(rule),
8343 nla_len(rule), nl80211_coalesce_policy);
8344 if (err)
8345 return err;
8346
8347 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
8348 new_rule->delay =
8349 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
8350 if (new_rule->delay > coalesce->max_delay)
8351 return -EINVAL;
8352
8353 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
8354 new_rule->condition =
8355 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
8356 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH &&
8357 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH)
8358 return -EINVAL;
8359
8360 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
8361 return -EINVAL;
8362
8363 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
8364 rem)
8365 n_patterns++;
8366 if (n_patterns > coalesce->n_patterns)
8367 return -EINVAL;
8368
8369 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
8370 GFP_KERNEL);
8371 if (!new_rule->patterns)
8372 return -ENOMEM;
8373
8374 new_rule->n_patterns = n_patterns;
8375 i = 0;
8376
8377 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
8378 rem) {
8379 nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
8380 nla_len(pat), NULL);
8381 if (!pat_tb[NL80211_PKTPAT_MASK] ||
8382 !pat_tb[NL80211_PKTPAT_PATTERN])
8383 return -EINVAL;
8384 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
8385 mask_len = DIV_ROUND_UP(pat_len, 8);
8386 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
8387 return -EINVAL;
8388 if (pat_len > coalesce->pattern_max_len ||
8389 pat_len < coalesce->pattern_min_len)
8390 return -EINVAL;
8391
8392 if (!pat_tb[NL80211_PKTPAT_OFFSET])
8393 pkt_offset = 0;
8394 else
8395 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
8396 if (pkt_offset > coalesce->max_pkt_offset)
8397 return -EINVAL;
8398 new_rule->patterns[i].pkt_offset = pkt_offset;
8399
8400 new_rule->patterns[i].mask =
8401 kmalloc(mask_len + pat_len, GFP_KERNEL);
8402 if (!new_rule->patterns[i].mask)
8403 return -ENOMEM;
8404 new_rule->patterns[i].pattern =
8405 new_rule->patterns[i].mask + mask_len;
8406 memcpy(new_rule->patterns[i].mask,
8407 nla_data(pat_tb[NL80211_PKTPAT_MASK]), mask_len);
8408 new_rule->patterns[i].pattern_len = pat_len;
8409 memcpy(new_rule->patterns[i].pattern,
8410 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), pat_len);
8411 i++;
8412 }
8413
8414 return 0;
8415}
8416
8417static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
8418{
8419 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8420 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
8421 struct cfg80211_coalesce new_coalesce = {};
8422 struct cfg80211_coalesce *n_coalesce;
8423 int err, rem_rule, n_rules = 0, i, j;
8424 struct nlattr *rule;
8425 struct cfg80211_coalesce_rules *tmp_rule;
8426
8427 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
8428 return -EOPNOTSUPP;
8429
8430 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
8431 cfg80211_rdev_free_coalesce(rdev);
8432 rdev->ops->set_coalesce(&rdev->wiphy, NULL);
8433 return 0;
8434 }
8435
8436 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
8437 rem_rule)
8438 n_rules++;
8439 if (n_rules > coalesce->n_rules)
8440 return -EINVAL;
8441
8442 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
8443 GFP_KERNEL);
8444 if (!new_coalesce.rules)
8445 return -ENOMEM;
8446
8447 new_coalesce.n_rules = n_rules;
8448 i = 0;
8449
8450 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
8451 rem_rule) {
8452 err = nl80211_parse_coalesce_rule(rdev, rule,
8453 &new_coalesce.rules[i]);
8454 if (err)
8455 goto error;
8456
8457 i++;
8458 }
8459
8460 err = rdev->ops->set_coalesce(&rdev->wiphy, &new_coalesce);
8461 if (err)
8462 goto error;
8463
8464 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
8465 if (!n_coalesce) {
8466 err = -ENOMEM;
8467 goto error;
8468 }
8469 cfg80211_rdev_free_coalesce(rdev);
8470 rdev->coalesce = n_coalesce;
8471
8472 return 0;
8473error:
8474 for (i = 0; i < new_coalesce.n_rules; i++) {
8475 tmp_rule = &new_coalesce.rules[i];
8476 for (j = 0; j < tmp_rule->n_patterns; j++)
8477 kfree(tmp_rule->patterns[j].mask);
8478 kfree(tmp_rule->patterns);
8479 }
8480 kfree(new_coalesce.rules);
8481
8482 return err;
8483}
8484
e5497d76
JB
8485static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
8486{
8487 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8488 struct net_device *dev = info->user_ptr[1];
8489 struct wireless_dev *wdev = dev->ieee80211_ptr;
8490 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
8491 struct cfg80211_gtk_rekey_data rekey_data;
8492 int err;
8493
8494 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
8495 return -EINVAL;
8496
8497 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
8498 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
8499 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
8500 nl80211_rekey_policy);
8501 if (err)
8502 return err;
8503
8504 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
8505 return -ERANGE;
8506 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
8507 return -ERANGE;
8508 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
8509 return -ERANGE;
8510
8511 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
8512 NL80211_KEK_LEN);
8513 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
8514 NL80211_KCK_LEN);
8515 memcpy(rekey_data.replay_ctr,
8516 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
8517 NL80211_REPLAY_CTR_LEN);
8518
8519 wdev_lock(wdev);
8520 if (!wdev->current_bss) {
8521 err = -ENOTCONN;
8522 goto out;
8523 }
8524
8525 if (!rdev->ops->set_rekey_data) {
8526 err = -EOPNOTSUPP;
8527 goto out;
8528 }
8529
e35e4d28 8530 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
8531 out:
8532 wdev_unlock(wdev);
8533 return err;
8534}
8535
28946da7
JB
8536static int nl80211_register_unexpected_frame(struct sk_buff *skb,
8537 struct genl_info *info)
8538{
8539 struct net_device *dev = info->user_ptr[1];
8540 struct wireless_dev *wdev = dev->ieee80211_ptr;
8541
8542 if (wdev->iftype != NL80211_IFTYPE_AP &&
8543 wdev->iftype != NL80211_IFTYPE_P2P_GO)
8544 return -EINVAL;
8545
15e47304 8546 if (wdev->ap_unexpected_nlportid)
28946da7
JB
8547 return -EBUSY;
8548
15e47304 8549 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
8550 return 0;
8551}
8552
7f6cf311
JB
8553static int nl80211_probe_client(struct sk_buff *skb,
8554 struct genl_info *info)
8555{
8556 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8557 struct net_device *dev = info->user_ptr[1];
8558 struct wireless_dev *wdev = dev->ieee80211_ptr;
8559 struct sk_buff *msg;
8560 void *hdr;
8561 const u8 *addr;
8562 u64 cookie;
8563 int err;
8564
8565 if (wdev->iftype != NL80211_IFTYPE_AP &&
8566 wdev->iftype != NL80211_IFTYPE_P2P_GO)
8567 return -EOPNOTSUPP;
8568
8569 if (!info->attrs[NL80211_ATTR_MAC])
8570 return -EINVAL;
8571
8572 if (!rdev->ops->probe_client)
8573 return -EOPNOTSUPP;
8574
8575 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8576 if (!msg)
8577 return -ENOMEM;
8578
15e47304 8579 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 8580 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
8581 if (!hdr) {
8582 err = -ENOBUFS;
7f6cf311
JB
8583 goto free_msg;
8584 }
8585
8586 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
8587
e35e4d28 8588 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
8589 if (err)
8590 goto free_msg;
8591
9360ffd1
DM
8592 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8593 goto nla_put_failure;
7f6cf311
JB
8594
8595 genlmsg_end(msg, hdr);
8596
8597 return genlmsg_reply(msg, info);
8598
8599 nla_put_failure:
8600 err = -ENOBUFS;
8601 free_msg:
8602 nlmsg_free(msg);
8603 return err;
8604}
8605
5e760230
JB
8606static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
8607{
8608 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
8609 struct cfg80211_beacon_registration *reg, *nreg;
8610 int rv;
5e760230
JB
8611
8612 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
8613 return -EOPNOTSUPP;
8614
37c73b5f
BG
8615 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
8616 if (!nreg)
8617 return -ENOMEM;
8618
8619 /* First, check if already registered. */
8620 spin_lock_bh(&rdev->beacon_registrations_lock);
8621 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
8622 if (reg->nlportid == info->snd_portid) {
8623 rv = -EALREADY;
8624 goto out_err;
8625 }
8626 }
8627 /* Add it to the list */
8628 nreg->nlportid = info->snd_portid;
8629 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 8630
37c73b5f 8631 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
8632
8633 return 0;
37c73b5f
BG
8634out_err:
8635 spin_unlock_bh(&rdev->beacon_registrations_lock);
8636 kfree(nreg);
8637 return rv;
5e760230
JB
8638}
8639
98104fde
JB
8640static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
8641{
8642 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8643 struct wireless_dev *wdev = info->user_ptr[1];
8644 int err;
8645
8646 if (!rdev->ops->start_p2p_device)
8647 return -EOPNOTSUPP;
8648
8649 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
8650 return -EOPNOTSUPP;
8651
8652 if (wdev->p2p_started)
8653 return 0;
8654
98104fde 8655 err = cfg80211_can_add_interface(rdev, wdev->iftype);
98104fde
JB
8656 if (err)
8657 return err;
8658
eeb126e9 8659 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
8660 if (err)
8661 return err;
8662
8663 wdev->p2p_started = true;
98104fde 8664 rdev->opencount++;
98104fde
JB
8665
8666 return 0;
8667}
8668
8669static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
8670{
8671 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8672 struct wireless_dev *wdev = info->user_ptr[1];
8673
8674 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
8675 return -EOPNOTSUPP;
8676
8677 if (!rdev->ops->stop_p2p_device)
8678 return -EOPNOTSUPP;
8679
f9f47529 8680 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
8681
8682 return 0;
8683}
8684
3713b4e3
JB
8685static int nl80211_get_protocol_features(struct sk_buff *skb,
8686 struct genl_info *info)
8687{
8688 void *hdr;
8689 struct sk_buff *msg;
8690
8691 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8692 if (!msg)
8693 return -ENOMEM;
8694
8695 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8696 NL80211_CMD_GET_PROTOCOL_FEATURES);
8697 if (!hdr)
8698 goto nla_put_failure;
8699
8700 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
8701 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
8702 goto nla_put_failure;
8703
8704 genlmsg_end(msg, hdr);
8705 return genlmsg_reply(msg, info);
8706
8707 nla_put_failure:
8708 kfree_skb(msg);
8709 return -ENOBUFS;
8710}
8711
355199e0
JM
8712static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
8713{
8714 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8715 struct cfg80211_update_ft_ies_params ft_params;
8716 struct net_device *dev = info->user_ptr[1];
8717
8718 if (!rdev->ops->update_ft_ies)
8719 return -EOPNOTSUPP;
8720
8721 if (!info->attrs[NL80211_ATTR_MDID] ||
8722 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8723 return -EINVAL;
8724
8725 memset(&ft_params, 0, sizeof(ft_params));
8726 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
8727 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8728 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
8729
8730 return rdev_update_ft_ies(rdev, dev, &ft_params);
8731}
8732
5de17984
AS
8733static int nl80211_crit_protocol_start(struct sk_buff *skb,
8734 struct genl_info *info)
8735{
8736 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8737 struct wireless_dev *wdev = info->user_ptr[1];
8738 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
8739 u16 duration;
8740 int ret;
8741
8742 if (!rdev->ops->crit_proto_start)
8743 return -EOPNOTSUPP;
8744
8745 if (WARN_ON(!rdev->ops->crit_proto_stop))
8746 return -EINVAL;
8747
8748 if (rdev->crit_proto_nlportid)
8749 return -EBUSY;
8750
8751 /* determine protocol if provided */
8752 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
8753 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
8754
8755 if (proto >= NUM_NL80211_CRIT_PROTO)
8756 return -EINVAL;
8757
8758 /* timeout must be provided */
8759 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
8760 return -EINVAL;
8761
8762 duration =
8763 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
8764
8765 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
8766 return -ERANGE;
8767
8768 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
8769 if (!ret)
8770 rdev->crit_proto_nlportid = info->snd_portid;
8771
8772 return ret;
8773}
8774
8775static int nl80211_crit_protocol_stop(struct sk_buff *skb,
8776 struct genl_info *info)
8777{
8778 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8779 struct wireless_dev *wdev = info->user_ptr[1];
8780
8781 if (!rdev->ops->crit_proto_stop)
8782 return -EOPNOTSUPP;
8783
8784 if (rdev->crit_proto_nlportid) {
8785 rdev->crit_proto_nlportid = 0;
8786 rdev_crit_proto_stop(rdev, wdev);
8787 }
8788 return 0;
8789}
8790
4c476991
JB
8791#define NL80211_FLAG_NEED_WIPHY 0x01
8792#define NL80211_FLAG_NEED_NETDEV 0x02
8793#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
8794#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
8795#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
8796 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 8797#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 8798/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
8799#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
8800 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
8801
8802static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
8803 struct genl_info *info)
8804{
8805 struct cfg80211_registered_device *rdev;
89a54e48 8806 struct wireless_dev *wdev;
4c476991 8807 struct net_device *dev;
4c476991
JB
8808 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
8809
8810 if (rtnl)
8811 rtnl_lock();
8812
8813 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 8814 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
8815 if (IS_ERR(rdev)) {
8816 if (rtnl)
8817 rtnl_unlock();
8818 return PTR_ERR(rdev);
8819 }
8820 info->user_ptr[0] = rdev;
1bf614ef
JB
8821 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
8822 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
8823 ASSERT_RTNL();
8824
89a54e48
JB
8825 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
8826 info->attrs);
8827 if (IS_ERR(wdev)) {
4c476991
JB
8828 if (rtnl)
8829 rtnl_unlock();
89a54e48 8830 return PTR_ERR(wdev);
4c476991 8831 }
89a54e48 8832
89a54e48
JB
8833 dev = wdev->netdev;
8834 rdev = wiphy_to_dev(wdev->wiphy);
8835
1bf614ef
JB
8836 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
8837 if (!dev) {
1bf614ef
JB
8838 if (rtnl)
8839 rtnl_unlock();
8840 return -EINVAL;
8841 }
8842
8843 info->user_ptr[1] = dev;
8844 } else {
8845 info->user_ptr[1] = wdev;
41265714 8846 }
1bf614ef
JB
8847
8848 if (dev) {
8849 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
8850 !netif_running(dev)) {
1bf614ef
JB
8851 if (rtnl)
8852 rtnl_unlock();
8853 return -ENETDOWN;
8854 }
8855
8856 dev_hold(dev);
98104fde
JB
8857 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
8858 if (!wdev->p2p_started) {
98104fde
JB
8859 if (rtnl)
8860 rtnl_unlock();
8861 return -ENETDOWN;
8862 }
41265714 8863 }
89a54e48 8864
4c476991 8865 info->user_ptr[0] = rdev;
4c476991
JB
8866 }
8867
8868 return 0;
8869}
8870
8871static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
8872 struct genl_info *info)
8873{
1bf614ef
JB
8874 if (info->user_ptr[1]) {
8875 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
8876 struct wireless_dev *wdev = info->user_ptr[1];
8877
8878 if (wdev->netdev)
8879 dev_put(wdev->netdev);
8880 } else {
8881 dev_put(info->user_ptr[1]);
8882 }
8883 }
4c476991
JB
8884 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
8885 rtnl_unlock();
8886}
8887
55682965
JB
8888static struct genl_ops nl80211_ops[] = {
8889 {
8890 .cmd = NL80211_CMD_GET_WIPHY,
8891 .doit = nl80211_get_wiphy,
8892 .dumpit = nl80211_dump_wiphy,
86e8cf98 8893 .done = nl80211_dump_wiphy_done,
55682965
JB
8894 .policy = nl80211_policy,
8895 /* can be retrieved by unprivileged users */
5fe231e8
JB
8896 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8897 NL80211_FLAG_NEED_RTNL,
55682965
JB
8898 },
8899 {
8900 .cmd = NL80211_CMD_SET_WIPHY,
8901 .doit = nl80211_set_wiphy,
8902 .policy = nl80211_policy,
8903 .flags = GENL_ADMIN_PERM,
4c476991 8904 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
8905 },
8906 {
8907 .cmd = NL80211_CMD_GET_INTERFACE,
8908 .doit = nl80211_get_interface,
8909 .dumpit = nl80211_dump_interface,
8910 .policy = nl80211_policy,
8911 /* can be retrieved by unprivileged users */
5fe231e8
JB
8912 .internal_flags = NL80211_FLAG_NEED_WDEV |
8913 NL80211_FLAG_NEED_RTNL,
55682965
JB
8914 },
8915 {
8916 .cmd = NL80211_CMD_SET_INTERFACE,
8917 .doit = nl80211_set_interface,
8918 .policy = nl80211_policy,
8919 .flags = GENL_ADMIN_PERM,
4c476991
JB
8920 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8921 NL80211_FLAG_NEED_RTNL,
55682965
JB
8922 },
8923 {
8924 .cmd = NL80211_CMD_NEW_INTERFACE,
8925 .doit = nl80211_new_interface,
8926 .policy = nl80211_policy,
8927 .flags = GENL_ADMIN_PERM,
4c476991
JB
8928 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8929 NL80211_FLAG_NEED_RTNL,
55682965
JB
8930 },
8931 {
8932 .cmd = NL80211_CMD_DEL_INTERFACE,
8933 .doit = nl80211_del_interface,
8934 .policy = nl80211_policy,
41ade00f 8935 .flags = GENL_ADMIN_PERM,
84efbb84 8936 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 8937 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8938 },
8939 {
8940 .cmd = NL80211_CMD_GET_KEY,
8941 .doit = nl80211_get_key,
8942 .policy = nl80211_policy,
8943 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8944 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8945 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8946 },
8947 {
8948 .cmd = NL80211_CMD_SET_KEY,
8949 .doit = nl80211_set_key,
8950 .policy = nl80211_policy,
8951 .flags = GENL_ADMIN_PERM,
41265714 8952 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8953 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8954 },
8955 {
8956 .cmd = NL80211_CMD_NEW_KEY,
8957 .doit = nl80211_new_key,
8958 .policy = nl80211_policy,
8959 .flags = GENL_ADMIN_PERM,
41265714 8960 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8961 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8962 },
8963 {
8964 .cmd = NL80211_CMD_DEL_KEY,
8965 .doit = nl80211_del_key,
8966 .policy = nl80211_policy,
55682965 8967 .flags = GENL_ADMIN_PERM,
41265714 8968 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8969 NL80211_FLAG_NEED_RTNL,
55682965 8970 },
ed1b6cc7
JB
8971 {
8972 .cmd = NL80211_CMD_SET_BEACON,
8973 .policy = nl80211_policy,
8974 .flags = GENL_ADMIN_PERM,
8860020e 8975 .doit = nl80211_set_beacon,
2b5f8b0b 8976 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8977 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
8978 },
8979 {
8860020e 8980 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
8981 .policy = nl80211_policy,
8982 .flags = GENL_ADMIN_PERM,
8860020e 8983 .doit = nl80211_start_ap,
2b5f8b0b 8984 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8985 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
8986 },
8987 {
8860020e 8988 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
8989 .policy = nl80211_policy,
8990 .flags = GENL_ADMIN_PERM,
8860020e 8991 .doit = nl80211_stop_ap,
2b5f8b0b 8992 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8993 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 8994 },
5727ef1b
JB
8995 {
8996 .cmd = NL80211_CMD_GET_STATION,
8997 .doit = nl80211_get_station,
2ec600d6 8998 .dumpit = nl80211_dump_station,
5727ef1b 8999 .policy = nl80211_policy,
4c476991
JB
9000 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9001 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
9002 },
9003 {
9004 .cmd = NL80211_CMD_SET_STATION,
9005 .doit = nl80211_set_station,
9006 .policy = nl80211_policy,
9007 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9008 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9009 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
9010 },
9011 {
9012 .cmd = NL80211_CMD_NEW_STATION,
9013 .doit = nl80211_new_station,
9014 .policy = nl80211_policy,
9015 .flags = GENL_ADMIN_PERM,
41265714 9016 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9017 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
9018 },
9019 {
9020 .cmd = NL80211_CMD_DEL_STATION,
9021 .doit = nl80211_del_station,
9022 .policy = nl80211_policy,
2ec600d6 9023 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9024 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9025 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9026 },
9027 {
9028 .cmd = NL80211_CMD_GET_MPATH,
9029 .doit = nl80211_get_mpath,
9030 .dumpit = nl80211_dump_mpath,
9031 .policy = nl80211_policy,
9032 .flags = GENL_ADMIN_PERM,
41265714 9033 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9034 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9035 },
9036 {
9037 .cmd = NL80211_CMD_SET_MPATH,
9038 .doit = nl80211_set_mpath,
9039 .policy = nl80211_policy,
9040 .flags = GENL_ADMIN_PERM,
41265714 9041 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9042 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9043 },
9044 {
9045 .cmd = NL80211_CMD_NEW_MPATH,
9046 .doit = nl80211_new_mpath,
9047 .policy = nl80211_policy,
9048 .flags = GENL_ADMIN_PERM,
41265714 9049 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9050 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9051 },
9052 {
9053 .cmd = NL80211_CMD_DEL_MPATH,
9054 .doit = nl80211_del_mpath,
9055 .policy = nl80211_policy,
9f1ba906 9056 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9057 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9058 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
9059 },
9060 {
9061 .cmd = NL80211_CMD_SET_BSS,
9062 .doit = nl80211_set_bss,
9063 .policy = nl80211_policy,
b2e1b302 9064 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9065 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9066 NL80211_FLAG_NEED_RTNL,
b2e1b302 9067 },
f130347c
LR
9068 {
9069 .cmd = NL80211_CMD_GET_REG,
9070 .doit = nl80211_get_reg,
9071 .policy = nl80211_policy,
5fe231e8 9072 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
9073 /* can be retrieved by unprivileged users */
9074 },
b2e1b302
LR
9075 {
9076 .cmd = NL80211_CMD_SET_REG,
9077 .doit = nl80211_set_reg,
9078 .policy = nl80211_policy,
9079 .flags = GENL_ADMIN_PERM,
5fe231e8 9080 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302
LR
9081 },
9082 {
9083 .cmd = NL80211_CMD_REQ_SET_REG,
9084 .doit = nl80211_req_set_reg,
9085 .policy = nl80211_policy,
93da9cc1 9086 .flags = GENL_ADMIN_PERM,
9087 },
9088 {
24bdd9f4
JC
9089 .cmd = NL80211_CMD_GET_MESH_CONFIG,
9090 .doit = nl80211_get_mesh_config,
93da9cc1 9091 .policy = nl80211_policy,
9092 /* can be retrieved by unprivileged users */
2b5f8b0b 9093 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9094 NL80211_FLAG_NEED_RTNL,
93da9cc1 9095 },
9096 {
24bdd9f4
JC
9097 .cmd = NL80211_CMD_SET_MESH_CONFIG,
9098 .doit = nl80211_update_mesh_config,
93da9cc1 9099 .policy = nl80211_policy,
9aed3cc1 9100 .flags = GENL_ADMIN_PERM,
29cbe68c 9101 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9102 NL80211_FLAG_NEED_RTNL,
9aed3cc1 9103 },
2a519311
JB
9104 {
9105 .cmd = NL80211_CMD_TRIGGER_SCAN,
9106 .doit = nl80211_trigger_scan,
9107 .policy = nl80211_policy,
9108 .flags = GENL_ADMIN_PERM,
fd014284 9109 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9110 NL80211_FLAG_NEED_RTNL,
2a519311
JB
9111 },
9112 {
9113 .cmd = NL80211_CMD_GET_SCAN,
9114 .policy = nl80211_policy,
9115 .dumpit = nl80211_dump_scan,
9116 },
807f8a8c
LC
9117 {
9118 .cmd = NL80211_CMD_START_SCHED_SCAN,
9119 .doit = nl80211_start_sched_scan,
9120 .policy = nl80211_policy,
9121 .flags = GENL_ADMIN_PERM,
9122 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9123 NL80211_FLAG_NEED_RTNL,
9124 },
9125 {
9126 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
9127 .doit = nl80211_stop_sched_scan,
9128 .policy = nl80211_policy,
9129 .flags = GENL_ADMIN_PERM,
9130 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9131 NL80211_FLAG_NEED_RTNL,
9132 },
636a5d36
JM
9133 {
9134 .cmd = NL80211_CMD_AUTHENTICATE,
9135 .doit = nl80211_authenticate,
9136 .policy = nl80211_policy,
9137 .flags = GENL_ADMIN_PERM,
41265714 9138 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9139 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
9140 },
9141 {
9142 .cmd = NL80211_CMD_ASSOCIATE,
9143 .doit = nl80211_associate,
9144 .policy = nl80211_policy,
9145 .flags = GENL_ADMIN_PERM,
41265714 9146 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9147 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
9148 },
9149 {
9150 .cmd = NL80211_CMD_DEAUTHENTICATE,
9151 .doit = nl80211_deauthenticate,
9152 .policy = nl80211_policy,
9153 .flags = GENL_ADMIN_PERM,
41265714 9154 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9155 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
9156 },
9157 {
9158 .cmd = NL80211_CMD_DISASSOCIATE,
9159 .doit = nl80211_disassociate,
9160 .policy = nl80211_policy,
9161 .flags = GENL_ADMIN_PERM,
41265714 9162 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9163 NL80211_FLAG_NEED_RTNL,
636a5d36 9164 },
04a773ad
JB
9165 {
9166 .cmd = NL80211_CMD_JOIN_IBSS,
9167 .doit = nl80211_join_ibss,
9168 .policy = nl80211_policy,
9169 .flags = GENL_ADMIN_PERM,
41265714 9170 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9171 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
9172 },
9173 {
9174 .cmd = NL80211_CMD_LEAVE_IBSS,
9175 .doit = nl80211_leave_ibss,
9176 .policy = nl80211_policy,
9177 .flags = GENL_ADMIN_PERM,
41265714 9178 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9179 NL80211_FLAG_NEED_RTNL,
04a773ad 9180 },
aff89a9b
JB
9181#ifdef CONFIG_NL80211_TESTMODE
9182 {
9183 .cmd = NL80211_CMD_TESTMODE,
9184 .doit = nl80211_testmode_do,
71063f0e 9185 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
9186 .policy = nl80211_policy,
9187 .flags = GENL_ADMIN_PERM,
4c476991
JB
9188 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9189 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
9190 },
9191#endif
b23aa676
SO
9192 {
9193 .cmd = NL80211_CMD_CONNECT,
9194 .doit = nl80211_connect,
9195 .policy = nl80211_policy,
9196 .flags = GENL_ADMIN_PERM,
41265714 9197 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9198 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
9199 },
9200 {
9201 .cmd = NL80211_CMD_DISCONNECT,
9202 .doit = nl80211_disconnect,
9203 .policy = nl80211_policy,
9204 .flags = GENL_ADMIN_PERM,
41265714 9205 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9206 NL80211_FLAG_NEED_RTNL,
b23aa676 9207 },
463d0183
JB
9208 {
9209 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
9210 .doit = nl80211_wiphy_netns,
9211 .policy = nl80211_policy,
9212 .flags = GENL_ADMIN_PERM,
4c476991
JB
9213 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9214 NL80211_FLAG_NEED_RTNL,
463d0183 9215 },
61fa713c
HS
9216 {
9217 .cmd = NL80211_CMD_GET_SURVEY,
9218 .policy = nl80211_policy,
9219 .dumpit = nl80211_dump_survey,
9220 },
67fbb16b
SO
9221 {
9222 .cmd = NL80211_CMD_SET_PMKSA,
9223 .doit = nl80211_setdel_pmksa,
9224 .policy = nl80211_policy,
9225 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9226 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9227 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
9228 },
9229 {
9230 .cmd = NL80211_CMD_DEL_PMKSA,
9231 .doit = nl80211_setdel_pmksa,
9232 .policy = nl80211_policy,
9233 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9234 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9235 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
9236 },
9237 {
9238 .cmd = NL80211_CMD_FLUSH_PMKSA,
9239 .doit = nl80211_flush_pmksa,
9240 .policy = nl80211_policy,
9241 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9242 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9243 NL80211_FLAG_NEED_RTNL,
67fbb16b 9244 },
9588bbd5
JM
9245 {
9246 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
9247 .doit = nl80211_remain_on_channel,
9248 .policy = nl80211_policy,
9249 .flags = GENL_ADMIN_PERM,
71bbc994 9250 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9251 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
9252 },
9253 {
9254 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
9255 .doit = nl80211_cancel_remain_on_channel,
9256 .policy = nl80211_policy,
9257 .flags = GENL_ADMIN_PERM,
71bbc994 9258 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9259 NL80211_FLAG_NEED_RTNL,
9588bbd5 9260 },
13ae75b1
JM
9261 {
9262 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
9263 .doit = nl80211_set_tx_bitrate_mask,
9264 .policy = nl80211_policy,
9265 .flags = GENL_ADMIN_PERM,
4c476991
JB
9266 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9267 NL80211_FLAG_NEED_RTNL,
13ae75b1 9268 },
026331c4 9269 {
2e161f78
JB
9270 .cmd = NL80211_CMD_REGISTER_FRAME,
9271 .doit = nl80211_register_mgmt,
026331c4
JM
9272 .policy = nl80211_policy,
9273 .flags = GENL_ADMIN_PERM,
71bbc994 9274 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 9275 NL80211_FLAG_NEED_RTNL,
026331c4
JM
9276 },
9277 {
2e161f78
JB
9278 .cmd = NL80211_CMD_FRAME,
9279 .doit = nl80211_tx_mgmt,
026331c4 9280 .policy = nl80211_policy,
f7ca38df 9281 .flags = GENL_ADMIN_PERM,
71bbc994 9282 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
9283 NL80211_FLAG_NEED_RTNL,
9284 },
9285 {
9286 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
9287 .doit = nl80211_tx_mgmt_cancel_wait,
9288 .policy = nl80211_policy,
026331c4 9289 .flags = GENL_ADMIN_PERM,
71bbc994 9290 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9291 NL80211_FLAG_NEED_RTNL,
026331c4 9292 },
ffb9eb3d
KV
9293 {
9294 .cmd = NL80211_CMD_SET_POWER_SAVE,
9295 .doit = nl80211_set_power_save,
9296 .policy = nl80211_policy,
9297 .flags = GENL_ADMIN_PERM,
4c476991
JB
9298 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9299 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
9300 },
9301 {
9302 .cmd = NL80211_CMD_GET_POWER_SAVE,
9303 .doit = nl80211_get_power_save,
9304 .policy = nl80211_policy,
9305 /* can be retrieved by unprivileged users */
4c476991
JB
9306 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9307 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 9308 },
d6dc1a38
JO
9309 {
9310 .cmd = NL80211_CMD_SET_CQM,
9311 .doit = nl80211_set_cqm,
9312 .policy = nl80211_policy,
9313 .flags = GENL_ADMIN_PERM,
4c476991
JB
9314 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9315 NL80211_FLAG_NEED_RTNL,
d6dc1a38 9316 },
f444de05
JB
9317 {
9318 .cmd = NL80211_CMD_SET_CHANNEL,
9319 .doit = nl80211_set_channel,
9320 .policy = nl80211_policy,
9321 .flags = GENL_ADMIN_PERM,
4c476991
JB
9322 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9323 NL80211_FLAG_NEED_RTNL,
f444de05 9324 },
e8347eba
BJ
9325 {
9326 .cmd = NL80211_CMD_SET_WDS_PEER,
9327 .doit = nl80211_set_wds_peer,
9328 .policy = nl80211_policy,
9329 .flags = GENL_ADMIN_PERM,
43b19952
JB
9330 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9331 NL80211_FLAG_NEED_RTNL,
e8347eba 9332 },
29cbe68c
JB
9333 {
9334 .cmd = NL80211_CMD_JOIN_MESH,
9335 .doit = nl80211_join_mesh,
9336 .policy = nl80211_policy,
9337 .flags = GENL_ADMIN_PERM,
9338 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9339 NL80211_FLAG_NEED_RTNL,
9340 },
9341 {
9342 .cmd = NL80211_CMD_LEAVE_MESH,
9343 .doit = nl80211_leave_mesh,
9344 .policy = nl80211_policy,
9345 .flags = GENL_ADMIN_PERM,
9346 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9347 NL80211_FLAG_NEED_RTNL,
9348 },
dfb89c56 9349#ifdef CONFIG_PM
ff1b6e69
JB
9350 {
9351 .cmd = NL80211_CMD_GET_WOWLAN,
9352 .doit = nl80211_get_wowlan,
9353 .policy = nl80211_policy,
9354 /* can be retrieved by unprivileged users */
9355 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9356 NL80211_FLAG_NEED_RTNL,
9357 },
9358 {
9359 .cmd = NL80211_CMD_SET_WOWLAN,
9360 .doit = nl80211_set_wowlan,
9361 .policy = nl80211_policy,
9362 .flags = GENL_ADMIN_PERM,
9363 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9364 NL80211_FLAG_NEED_RTNL,
9365 },
dfb89c56 9366#endif
e5497d76
JB
9367 {
9368 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
9369 .doit = nl80211_set_rekey_data,
9370 .policy = nl80211_policy,
9371 .flags = GENL_ADMIN_PERM,
9372 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9373 NL80211_FLAG_NEED_RTNL,
9374 },
109086ce
AN
9375 {
9376 .cmd = NL80211_CMD_TDLS_MGMT,
9377 .doit = nl80211_tdls_mgmt,
9378 .policy = nl80211_policy,
9379 .flags = GENL_ADMIN_PERM,
9380 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9381 NL80211_FLAG_NEED_RTNL,
9382 },
9383 {
9384 .cmd = NL80211_CMD_TDLS_OPER,
9385 .doit = nl80211_tdls_oper,
9386 .policy = nl80211_policy,
9387 .flags = GENL_ADMIN_PERM,
9388 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9389 NL80211_FLAG_NEED_RTNL,
9390 },
28946da7
JB
9391 {
9392 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
9393 .doit = nl80211_register_unexpected_frame,
9394 .policy = nl80211_policy,
9395 .flags = GENL_ADMIN_PERM,
9396 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9397 NL80211_FLAG_NEED_RTNL,
9398 },
7f6cf311
JB
9399 {
9400 .cmd = NL80211_CMD_PROBE_CLIENT,
9401 .doit = nl80211_probe_client,
9402 .policy = nl80211_policy,
9403 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9404 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
9405 NL80211_FLAG_NEED_RTNL,
9406 },
5e760230
JB
9407 {
9408 .cmd = NL80211_CMD_REGISTER_BEACONS,
9409 .doit = nl80211_register_beacons,
9410 .policy = nl80211_policy,
9411 .flags = GENL_ADMIN_PERM,
9412 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9413 NL80211_FLAG_NEED_RTNL,
9414 },
1d9d9213
SW
9415 {
9416 .cmd = NL80211_CMD_SET_NOACK_MAP,
9417 .doit = nl80211_set_noack_map,
9418 .policy = nl80211_policy,
9419 .flags = GENL_ADMIN_PERM,
9420 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9421 NL80211_FLAG_NEED_RTNL,
9422 },
98104fde
JB
9423 {
9424 .cmd = NL80211_CMD_START_P2P_DEVICE,
9425 .doit = nl80211_start_p2p_device,
9426 .policy = nl80211_policy,
9427 .flags = GENL_ADMIN_PERM,
9428 .internal_flags = NL80211_FLAG_NEED_WDEV |
9429 NL80211_FLAG_NEED_RTNL,
9430 },
9431 {
9432 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
9433 .doit = nl80211_stop_p2p_device,
9434 .policy = nl80211_policy,
9435 .flags = GENL_ADMIN_PERM,
9436 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9437 NL80211_FLAG_NEED_RTNL,
9438 },
f4e583c8
AQ
9439 {
9440 .cmd = NL80211_CMD_SET_MCAST_RATE,
9441 .doit = nl80211_set_mcast_rate,
77765eaf
VT
9442 .policy = nl80211_policy,
9443 .flags = GENL_ADMIN_PERM,
9444 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9445 NL80211_FLAG_NEED_RTNL,
9446 },
9447 {
9448 .cmd = NL80211_CMD_SET_MAC_ACL,
9449 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
9450 .policy = nl80211_policy,
9451 .flags = GENL_ADMIN_PERM,
9452 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9453 NL80211_FLAG_NEED_RTNL,
9454 },
04f39047
SW
9455 {
9456 .cmd = NL80211_CMD_RADAR_DETECT,
9457 .doit = nl80211_start_radar_detection,
9458 .policy = nl80211_policy,
9459 .flags = GENL_ADMIN_PERM,
9460 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9461 NL80211_FLAG_NEED_RTNL,
9462 },
3713b4e3
JB
9463 {
9464 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
9465 .doit = nl80211_get_protocol_features,
9466 .policy = nl80211_policy,
9467 },
355199e0
JM
9468 {
9469 .cmd = NL80211_CMD_UPDATE_FT_IES,
9470 .doit = nl80211_update_ft_ies,
9471 .policy = nl80211_policy,
9472 .flags = GENL_ADMIN_PERM,
9473 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9474 NL80211_FLAG_NEED_RTNL,
9475 },
5de17984
AS
9476 {
9477 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
9478 .doit = nl80211_crit_protocol_start,
9479 .policy = nl80211_policy,
9480 .flags = GENL_ADMIN_PERM,
9481 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9482 NL80211_FLAG_NEED_RTNL,
9483 },
9484 {
9485 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
9486 .doit = nl80211_crit_protocol_stop,
9487 .policy = nl80211_policy,
9488 .flags = GENL_ADMIN_PERM,
9489 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9490 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
9491 },
9492 {
9493 .cmd = NL80211_CMD_GET_COALESCE,
9494 .doit = nl80211_get_coalesce,
9495 .policy = nl80211_policy,
9496 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9497 NL80211_FLAG_NEED_RTNL,
9498 },
9499 {
9500 .cmd = NL80211_CMD_SET_COALESCE,
9501 .doit = nl80211_set_coalesce,
9502 .policy = nl80211_policy,
9503 .flags = GENL_ADMIN_PERM,
9504 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9505 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
9506 },
9507 {
9508 .cmd = NL80211_CMD_CHANNEL_SWITCH,
9509 .doit = nl80211_channel_switch,
9510 .policy = nl80211_policy,
9511 .flags = GENL_ADMIN_PERM,
9512 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9513 NL80211_FLAG_NEED_RTNL,
9514 },
55682965 9515};
9588bbd5 9516
6039f6d2
JM
9517static struct genl_multicast_group nl80211_mlme_mcgrp = {
9518 .name = "mlme",
9519};
55682965
JB
9520
9521/* multicast groups */
9522static struct genl_multicast_group nl80211_config_mcgrp = {
9523 .name = "config",
9524};
2a519311
JB
9525static struct genl_multicast_group nl80211_scan_mcgrp = {
9526 .name = "scan",
9527};
73d54c9e
LR
9528static struct genl_multicast_group nl80211_regulatory_mcgrp = {
9529 .name = "regulatory",
9530};
55682965
JB
9531
9532/* notification functions */
9533
9534void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
9535{
9536 struct sk_buff *msg;
86e8cf98 9537 struct nl80211_dump_wiphy_state state = {};
55682965 9538
fd2120ca 9539 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
9540 if (!msg)
9541 return;
9542
86e8cf98 9543 if (nl80211_send_wiphy(rdev, msg, 0, 0, 0, &state) < 0) {
55682965
JB
9544 nlmsg_free(msg);
9545 return;
9546 }
9547
463d0183
JB
9548 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9549 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
9550}
9551
362a415d
JB
9552static int nl80211_add_scan_req(struct sk_buff *msg,
9553 struct cfg80211_registered_device *rdev)
9554{
9555 struct cfg80211_scan_request *req = rdev->scan_req;
9556 struct nlattr *nest;
9557 int i;
9558
9559 if (WARN_ON(!req))
9560 return 0;
9561
9562 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
9563 if (!nest)
9564 goto nla_put_failure;
9360ffd1
DM
9565 for (i = 0; i < req->n_ssids; i++) {
9566 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
9567 goto nla_put_failure;
9568 }
362a415d
JB
9569 nla_nest_end(msg, nest);
9570
9571 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
9572 if (!nest)
9573 goto nla_put_failure;
9360ffd1
DM
9574 for (i = 0; i < req->n_channels; i++) {
9575 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
9576 goto nla_put_failure;
9577 }
362a415d
JB
9578 nla_nest_end(msg, nest);
9579
9360ffd1
DM
9580 if (req->ie &&
9581 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
9582 goto nla_put_failure;
362a415d 9583
ed473771
SL
9584 if (req->flags)
9585 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
9586
362a415d
JB
9587 return 0;
9588 nla_put_failure:
9589 return -ENOBUFS;
9590}
9591
a538e2d5
JB
9592static int nl80211_send_scan_msg(struct sk_buff *msg,
9593 struct cfg80211_registered_device *rdev,
fd014284 9594 struct wireless_dev *wdev,
15e47304 9595 u32 portid, u32 seq, int flags,
a538e2d5 9596 u32 cmd)
2a519311
JB
9597{
9598 void *hdr;
9599
15e47304 9600 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
9601 if (!hdr)
9602 return -1;
9603
9360ffd1 9604 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
9605 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9606 wdev->netdev->ifindex)) ||
9607 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 9608 goto nla_put_failure;
2a519311 9609
362a415d
JB
9610 /* ignore errors and send incomplete event anyway */
9611 nl80211_add_scan_req(msg, rdev);
2a519311
JB
9612
9613 return genlmsg_end(msg, hdr);
9614
9615 nla_put_failure:
9616 genlmsg_cancel(msg, hdr);
9617 return -EMSGSIZE;
9618}
9619
807f8a8c
LC
9620static int
9621nl80211_send_sched_scan_msg(struct sk_buff *msg,
9622 struct cfg80211_registered_device *rdev,
9623 struct net_device *netdev,
15e47304 9624 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
9625{
9626 void *hdr;
9627
15e47304 9628 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
9629 if (!hdr)
9630 return -1;
9631
9360ffd1
DM
9632 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9633 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9634 goto nla_put_failure;
807f8a8c
LC
9635
9636 return genlmsg_end(msg, hdr);
9637
9638 nla_put_failure:
9639 genlmsg_cancel(msg, hdr);
9640 return -EMSGSIZE;
9641}
9642
a538e2d5 9643void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 9644 struct wireless_dev *wdev)
a538e2d5
JB
9645{
9646 struct sk_buff *msg;
9647
58050fce 9648 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
9649 if (!msg)
9650 return;
9651
fd014284 9652 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
9653 NL80211_CMD_TRIGGER_SCAN) < 0) {
9654 nlmsg_free(msg);
9655 return;
9656 }
9657
463d0183
JB
9658 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9659 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
9660}
9661
2a519311 9662void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 9663 struct wireless_dev *wdev)
2a519311
JB
9664{
9665 struct sk_buff *msg;
9666
fd2120ca 9667 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
9668 if (!msg)
9669 return;
9670
fd014284 9671 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 9672 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
9673 nlmsg_free(msg);
9674 return;
9675 }
9676
463d0183
JB
9677 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9678 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
9679}
9680
9681void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 9682 struct wireless_dev *wdev)
2a519311
JB
9683{
9684 struct sk_buff *msg;
9685
fd2120ca 9686 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
9687 if (!msg)
9688 return;
9689
fd014284 9690 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 9691 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
9692 nlmsg_free(msg);
9693 return;
9694 }
9695
463d0183
JB
9696 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9697 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
9698}
9699
807f8a8c
LC
9700void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
9701 struct net_device *netdev)
9702{
9703 struct sk_buff *msg;
9704
9705 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9706 if (!msg)
9707 return;
9708
9709 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
9710 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
9711 nlmsg_free(msg);
9712 return;
9713 }
9714
9715 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9716 nl80211_scan_mcgrp.id, GFP_KERNEL);
9717}
9718
9719void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
9720 struct net_device *netdev, u32 cmd)
9721{
9722 struct sk_buff *msg;
9723
58050fce 9724 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
9725 if (!msg)
9726 return;
9727
9728 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
9729 nlmsg_free(msg);
9730 return;
9731 }
9732
9733 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9734 nl80211_scan_mcgrp.id, GFP_KERNEL);
9735}
9736
73d54c9e
LR
9737/*
9738 * This can happen on global regulatory changes or device specific settings
9739 * based on custom world regulatory domains.
9740 */
9741void nl80211_send_reg_change_event(struct regulatory_request *request)
9742{
9743 struct sk_buff *msg;
9744 void *hdr;
9745
fd2120ca 9746 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
9747 if (!msg)
9748 return;
9749
9750 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
9751 if (!hdr) {
9752 nlmsg_free(msg);
9753 return;
9754 }
9755
9756 /* Userspace can always count this one always being set */
9360ffd1
DM
9757 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
9758 goto nla_put_failure;
9759
9760 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
9761 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9762 NL80211_REGDOM_TYPE_WORLD))
9763 goto nla_put_failure;
9764 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
9765 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9766 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
9767 goto nla_put_failure;
9768 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
9769 request->intersect) {
9770 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9771 NL80211_REGDOM_TYPE_INTERSECTION))
9772 goto nla_put_failure;
9773 } else {
9774 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9775 NL80211_REGDOM_TYPE_COUNTRY) ||
9776 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
9777 request->alpha2))
9778 goto nla_put_failure;
9779 }
9780
f4173766 9781 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
9782 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
9783 goto nla_put_failure;
73d54c9e 9784
3b7b72ee 9785 genlmsg_end(msg, hdr);
73d54c9e 9786
bc43b28c 9787 rcu_read_lock();
463d0183 9788 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
9789 GFP_ATOMIC);
9790 rcu_read_unlock();
73d54c9e
LR
9791
9792 return;
9793
9794nla_put_failure:
9795 genlmsg_cancel(msg, hdr);
9796 nlmsg_free(msg);
9797}
9798
6039f6d2
JM
9799static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
9800 struct net_device *netdev,
9801 const u8 *buf, size_t len,
e6d6e342 9802 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
9803{
9804 struct sk_buff *msg;
9805 void *hdr;
9806
e6d6e342 9807 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
9808 if (!msg)
9809 return;
9810
9811 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
9812 if (!hdr) {
9813 nlmsg_free(msg);
9814 return;
9815 }
9816
9360ffd1
DM
9817 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9818 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9819 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
9820 goto nla_put_failure;
6039f6d2 9821
3b7b72ee 9822 genlmsg_end(msg, hdr);
6039f6d2 9823
463d0183
JB
9824 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9825 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
9826 return;
9827
9828 nla_put_failure:
9829 genlmsg_cancel(msg, hdr);
9830 nlmsg_free(msg);
9831}
9832
9833void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9834 struct net_device *netdev, const u8 *buf,
9835 size_t len, gfp_t gfp)
6039f6d2
JM
9836{
9837 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 9838 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
9839}
9840
9841void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
9842 struct net_device *netdev, const u8 *buf,
e6d6e342 9843 size_t len, gfp_t gfp)
6039f6d2 9844{
e6d6e342
JB
9845 nl80211_send_mlme_event(rdev, netdev, buf, len,
9846 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
9847}
9848
53b46b84 9849void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9850 struct net_device *netdev, const u8 *buf,
9851 size_t len, gfp_t gfp)
6039f6d2
JM
9852{
9853 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 9854 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
9855}
9856
53b46b84
JM
9857void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
9858 struct net_device *netdev, const u8 *buf,
e6d6e342 9859 size_t len, gfp_t gfp)
6039f6d2
JM
9860{
9861 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 9862 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
9863}
9864
6ff57cf8
JB
9865void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
9866 size_t len)
cf4e594e 9867{
947add36
JB
9868 struct wireless_dev *wdev = dev->ieee80211_ptr;
9869 struct wiphy *wiphy = wdev->wiphy;
9870 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6ff57cf8
JB
9871 const struct ieee80211_mgmt *mgmt = (void *)buf;
9872 u32 cmd;
947add36 9873
6ff57cf8
JB
9874 if (WARN_ON(len < 2))
9875 return;
cf4e594e 9876
6ff57cf8
JB
9877 if (ieee80211_is_deauth(mgmt->frame_control))
9878 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
9879 else
9880 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 9881
6ff57cf8
JB
9882 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
9883 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC);
cf4e594e 9884}
6ff57cf8 9885EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 9886
1b06bb40
LR
9887static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
9888 struct net_device *netdev, int cmd,
e6d6e342 9889 const u8 *addr, gfp_t gfp)
1965c853
JM
9890{
9891 struct sk_buff *msg;
9892 void *hdr;
9893
e6d6e342 9894 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
9895 if (!msg)
9896 return;
9897
9898 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
9899 if (!hdr) {
9900 nlmsg_free(msg);
9901 return;
9902 }
9903
9360ffd1
DM
9904 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9905 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9906 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
9907 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
9908 goto nla_put_failure;
1965c853 9909
3b7b72ee 9910 genlmsg_end(msg, hdr);
1965c853 9911
463d0183
JB
9912 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9913 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
9914 return;
9915
9916 nla_put_failure:
9917 genlmsg_cancel(msg, hdr);
9918 nlmsg_free(msg);
9919}
9920
9921void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9922 struct net_device *netdev, const u8 *addr,
9923 gfp_t gfp)
1965c853
JM
9924{
9925 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 9926 addr, gfp);
1965c853
JM
9927}
9928
9929void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9930 struct net_device *netdev, const u8 *addr,
9931 gfp_t gfp)
1965c853 9932{
e6d6e342
JB
9933 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
9934 addr, gfp);
1965c853
JM
9935}
9936
b23aa676
SO
9937void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
9938 struct net_device *netdev, const u8 *bssid,
9939 const u8 *req_ie, size_t req_ie_len,
9940 const u8 *resp_ie, size_t resp_ie_len,
9941 u16 status, gfp_t gfp)
9942{
9943 struct sk_buff *msg;
9944 void *hdr;
9945
58050fce 9946 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
9947 if (!msg)
9948 return;
9949
9950 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
9951 if (!hdr) {
9952 nlmsg_free(msg);
9953 return;
9954 }
9955
9360ffd1
DM
9956 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9957 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9958 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
9959 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
9960 (req_ie &&
9961 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
9962 (resp_ie &&
9963 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
9964 goto nla_put_failure;
b23aa676 9965
3b7b72ee 9966 genlmsg_end(msg, hdr);
b23aa676 9967
463d0183
JB
9968 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9969 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
9970 return;
9971
9972 nla_put_failure:
9973 genlmsg_cancel(msg, hdr);
9974 nlmsg_free(msg);
9975
9976}
9977
9978void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
9979 struct net_device *netdev, const u8 *bssid,
9980 const u8 *req_ie, size_t req_ie_len,
9981 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
9982{
9983 struct sk_buff *msg;
9984 void *hdr;
9985
58050fce 9986 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
9987 if (!msg)
9988 return;
9989
9990 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
9991 if (!hdr) {
9992 nlmsg_free(msg);
9993 return;
9994 }
9995
9360ffd1
DM
9996 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9997 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9998 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
9999 (req_ie &&
10000 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
10001 (resp_ie &&
10002 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
10003 goto nla_put_failure;
b23aa676 10004
3b7b72ee 10005 genlmsg_end(msg, hdr);
b23aa676 10006
463d0183
JB
10007 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10008 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
10009 return;
10010
10011 nla_put_failure:
10012 genlmsg_cancel(msg, hdr);
10013 nlmsg_free(msg);
10014
10015}
10016
10017void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
10018 struct net_device *netdev, u16 reason,
667503dd 10019 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
10020{
10021 struct sk_buff *msg;
10022 void *hdr;
10023
58050fce 10024 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
10025 if (!msg)
10026 return;
10027
10028 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
10029 if (!hdr) {
10030 nlmsg_free(msg);
10031 return;
10032 }
10033
9360ffd1
DM
10034 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10035 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10036 (from_ap && reason &&
10037 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
10038 (from_ap &&
10039 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
10040 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
10041 goto nla_put_failure;
b23aa676 10042
3b7b72ee 10043 genlmsg_end(msg, hdr);
b23aa676 10044
463d0183
JB
10045 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10046 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
10047 return;
10048
10049 nla_put_failure:
10050 genlmsg_cancel(msg, hdr);
10051 nlmsg_free(msg);
10052
10053}
10054
04a773ad
JB
10055void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
10056 struct net_device *netdev, const u8 *bssid,
10057 gfp_t gfp)
10058{
10059 struct sk_buff *msg;
10060 void *hdr;
10061
fd2120ca 10062 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
10063 if (!msg)
10064 return;
10065
10066 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
10067 if (!hdr) {
10068 nlmsg_free(msg);
10069 return;
10070 }
10071
9360ffd1
DM
10072 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10073 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10074 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
10075 goto nla_put_failure;
04a773ad 10076
3b7b72ee 10077 genlmsg_end(msg, hdr);
04a773ad 10078
463d0183
JB
10079 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10080 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
10081 return;
10082
10083 nla_put_failure:
10084 genlmsg_cancel(msg, hdr);
10085 nlmsg_free(msg);
10086}
10087
947add36
JB
10088void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
10089 const u8* ie, u8 ie_len, gfp_t gfp)
c93b5e71 10090{
947add36
JB
10091 struct wireless_dev *wdev = dev->ieee80211_ptr;
10092 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
c93b5e71
JC
10093 struct sk_buff *msg;
10094 void *hdr;
10095
947add36
JB
10096 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
10097 return;
10098
10099 trace_cfg80211_notify_new_peer_candidate(dev, addr);
10100
c93b5e71
JC
10101 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10102 if (!msg)
10103 return;
10104
10105 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
10106 if (!hdr) {
10107 nlmsg_free(msg);
10108 return;
10109 }
10110
9360ffd1 10111 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
10112 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10113 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1
DM
10114 (ie_len && ie &&
10115 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
10116 goto nla_put_failure;
c93b5e71 10117
3b7b72ee 10118 genlmsg_end(msg, hdr);
c93b5e71
JC
10119
10120 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10121 nl80211_mlme_mcgrp.id, gfp);
10122 return;
10123
10124 nla_put_failure:
10125 genlmsg_cancel(msg, hdr);
10126 nlmsg_free(msg);
10127}
947add36 10128EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 10129
a3b8b056
JM
10130void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
10131 struct net_device *netdev, const u8 *addr,
10132 enum nl80211_key_type key_type, int key_id,
e6d6e342 10133 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
10134{
10135 struct sk_buff *msg;
10136 void *hdr;
10137
e6d6e342 10138 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
10139 if (!msg)
10140 return;
10141
10142 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
10143 if (!hdr) {
10144 nlmsg_free(msg);
10145 return;
10146 }
10147
9360ffd1
DM
10148 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10149 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10150 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
10151 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
10152 (key_id != -1 &&
10153 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
10154 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
10155 goto nla_put_failure;
a3b8b056 10156
3b7b72ee 10157 genlmsg_end(msg, hdr);
a3b8b056 10158
463d0183
JB
10159 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10160 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
10161 return;
10162
10163 nla_put_failure:
10164 genlmsg_cancel(msg, hdr);
10165 nlmsg_free(msg);
10166}
10167
6bad8766
LR
10168void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
10169 struct ieee80211_channel *channel_before,
10170 struct ieee80211_channel *channel_after)
10171{
10172 struct sk_buff *msg;
10173 void *hdr;
10174 struct nlattr *nl_freq;
10175
fd2120ca 10176 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
10177 if (!msg)
10178 return;
10179
10180 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
10181 if (!hdr) {
10182 nlmsg_free(msg);
10183 return;
10184 }
10185
10186 /*
10187 * Since we are applying the beacon hint to a wiphy we know its
10188 * wiphy_idx is valid
10189 */
9360ffd1
DM
10190 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
10191 goto nla_put_failure;
6bad8766
LR
10192
10193 /* Before */
10194 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
10195 if (!nl_freq)
10196 goto nla_put_failure;
cdc89b97 10197 if (nl80211_msg_put_channel(msg, channel_before, false))
6bad8766
LR
10198 goto nla_put_failure;
10199 nla_nest_end(msg, nl_freq);
10200
10201 /* After */
10202 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
10203 if (!nl_freq)
10204 goto nla_put_failure;
cdc89b97 10205 if (nl80211_msg_put_channel(msg, channel_after, false))
6bad8766
LR
10206 goto nla_put_failure;
10207 nla_nest_end(msg, nl_freq);
10208
3b7b72ee 10209 genlmsg_end(msg, hdr);
6bad8766 10210
463d0183
JB
10211 rcu_read_lock();
10212 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
10213 GFP_ATOMIC);
10214 rcu_read_unlock();
6bad8766
LR
10215
10216 return;
10217
10218nla_put_failure:
10219 genlmsg_cancel(msg, hdr);
10220 nlmsg_free(msg);
10221}
10222
9588bbd5
JM
10223static void nl80211_send_remain_on_chan_event(
10224 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 10225 struct wireless_dev *wdev, u64 cookie,
9588bbd5 10226 struct ieee80211_channel *chan,
9588bbd5
JM
10227 unsigned int duration, gfp_t gfp)
10228{
10229 struct sk_buff *msg;
10230 void *hdr;
10231
10232 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10233 if (!msg)
10234 return;
10235
10236 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
10237 if (!hdr) {
10238 nlmsg_free(msg);
10239 return;
10240 }
10241
9360ffd1 10242 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10243 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10244 wdev->netdev->ifindex)) ||
00f53350 10245 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 10246 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
10247 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
10248 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
10249 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
10250 goto nla_put_failure;
9588bbd5 10251
9360ffd1
DM
10252 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
10253 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
10254 goto nla_put_failure;
9588bbd5 10255
3b7b72ee 10256 genlmsg_end(msg, hdr);
9588bbd5
JM
10257
10258 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10259 nl80211_mlme_mcgrp.id, gfp);
10260 return;
10261
10262 nla_put_failure:
10263 genlmsg_cancel(msg, hdr);
10264 nlmsg_free(msg);
10265}
10266
947add36
JB
10267void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
10268 struct ieee80211_channel *chan,
10269 unsigned int duration, gfp_t gfp)
9588bbd5 10270{
947add36
JB
10271 struct wiphy *wiphy = wdev->wiphy;
10272 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10273
10274 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 10275 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 10276 rdev, wdev, cookie, chan,
42d97a59 10277 duration, gfp);
9588bbd5 10278}
947add36 10279EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 10280
947add36
JB
10281void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
10282 struct ieee80211_channel *chan,
10283 gfp_t gfp)
9588bbd5 10284{
947add36
JB
10285 struct wiphy *wiphy = wdev->wiphy;
10286 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10287
10288 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 10289 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 10290 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 10291}
947add36 10292EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 10293
947add36
JB
10294void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
10295 struct station_info *sinfo, gfp_t gfp)
98b62183 10296{
947add36
JB
10297 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
10298 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
98b62183
JB
10299 struct sk_buff *msg;
10300
947add36
JB
10301 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
10302
58050fce 10303 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
10304 if (!msg)
10305 return;
10306
66266b3a
JL
10307 if (nl80211_send_station(msg, 0, 0, 0,
10308 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
10309 nlmsg_free(msg);
10310 return;
10311 }
10312
10313 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10314 nl80211_mlme_mcgrp.id, gfp);
10315}
947add36 10316EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 10317
947add36 10318void cfg80211_del_sta(struct net_device *dev, const u8 *mac_addr, gfp_t gfp)
ec15e68b 10319{
947add36
JB
10320 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
10321 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
ec15e68b
JM
10322 struct sk_buff *msg;
10323 void *hdr;
10324
947add36
JB
10325 trace_cfg80211_del_sta(dev, mac_addr);
10326
58050fce 10327 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
10328 if (!msg)
10329 return;
10330
10331 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
10332 if (!hdr) {
10333 nlmsg_free(msg);
10334 return;
10335 }
10336
9360ffd1
DM
10337 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10338 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
10339 goto nla_put_failure;
ec15e68b 10340
3b7b72ee 10341 genlmsg_end(msg, hdr);
ec15e68b
JM
10342
10343 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10344 nl80211_mlme_mcgrp.id, gfp);
10345 return;
10346
10347 nla_put_failure:
10348 genlmsg_cancel(msg, hdr);
10349 nlmsg_free(msg);
10350}
947add36 10351EXPORT_SYMBOL(cfg80211_del_sta);
ec15e68b 10352
947add36
JB
10353void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
10354 enum nl80211_connect_failed_reason reason,
10355 gfp_t gfp)
ed44a951 10356{
947add36
JB
10357 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
10358 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
ed44a951
PP
10359 struct sk_buff *msg;
10360 void *hdr;
10361
10362 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
10363 if (!msg)
10364 return;
10365
10366 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
10367 if (!hdr) {
10368 nlmsg_free(msg);
10369 return;
10370 }
10371
10372 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10373 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
10374 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
10375 goto nla_put_failure;
10376
10377 genlmsg_end(msg, hdr);
10378
10379 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10380 nl80211_mlme_mcgrp.id, gfp);
10381 return;
10382
10383 nla_put_failure:
10384 genlmsg_cancel(msg, hdr);
10385 nlmsg_free(msg);
10386}
947add36 10387EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 10388
b92ab5d8
JB
10389static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
10390 const u8 *addr, gfp_t gfp)
28946da7
JB
10391{
10392 struct wireless_dev *wdev = dev->ieee80211_ptr;
10393 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
10394 struct sk_buff *msg;
10395 void *hdr;
15e47304 10396 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 10397
15e47304 10398 if (!nlportid)
28946da7
JB
10399 return false;
10400
10401 msg = nlmsg_new(100, gfp);
10402 if (!msg)
10403 return true;
10404
b92ab5d8 10405 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
10406 if (!hdr) {
10407 nlmsg_free(msg);
10408 return true;
10409 }
10410
9360ffd1
DM
10411 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10412 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10413 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
10414 goto nla_put_failure;
28946da7 10415
9c90a9f6 10416 genlmsg_end(msg, hdr);
15e47304 10417 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
10418 return true;
10419
10420 nla_put_failure:
10421 genlmsg_cancel(msg, hdr);
10422 nlmsg_free(msg);
10423 return true;
10424}
10425
947add36
JB
10426bool cfg80211_rx_spurious_frame(struct net_device *dev,
10427 const u8 *addr, gfp_t gfp)
b92ab5d8 10428{
947add36
JB
10429 struct wireless_dev *wdev = dev->ieee80211_ptr;
10430 bool ret;
10431
10432 trace_cfg80211_rx_spurious_frame(dev, addr);
10433
10434 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
10435 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
10436 trace_cfg80211_return_bool(false);
10437 return false;
10438 }
10439 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
10440 addr, gfp);
10441 trace_cfg80211_return_bool(ret);
10442 return ret;
b92ab5d8 10443}
947add36 10444EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 10445
947add36
JB
10446bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
10447 const u8 *addr, gfp_t gfp)
b92ab5d8 10448{
947add36
JB
10449 struct wireless_dev *wdev = dev->ieee80211_ptr;
10450 bool ret;
10451
10452 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
10453
10454 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
10455 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
10456 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
10457 trace_cfg80211_return_bool(false);
10458 return false;
10459 }
10460 ret = __nl80211_unexpected_frame(dev,
10461 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
10462 addr, gfp);
10463 trace_cfg80211_return_bool(ret);
10464 return ret;
b92ab5d8 10465}
947add36 10466EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 10467
2e161f78 10468int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 10469 struct wireless_dev *wdev, u32 nlportid,
804483e9 10470 int freq, int sig_dbm,
19504cf5 10471 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 10472{
71bbc994 10473 struct net_device *netdev = wdev->netdev;
026331c4
JM
10474 struct sk_buff *msg;
10475 void *hdr;
026331c4
JM
10476
10477 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10478 if (!msg)
10479 return -ENOMEM;
10480
2e161f78 10481 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
10482 if (!hdr) {
10483 nlmsg_free(msg);
10484 return -ENOMEM;
10485 }
10486
9360ffd1 10487 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10488 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10489 netdev->ifindex)) ||
a838490b 10490 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
10491 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
10492 (sig_dbm &&
10493 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
10494 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
10495 (flags &&
10496 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 10497 goto nla_put_failure;
026331c4 10498
3b7b72ee 10499 genlmsg_end(msg, hdr);
026331c4 10500
15e47304 10501 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
10502
10503 nla_put_failure:
10504 genlmsg_cancel(msg, hdr);
10505 nlmsg_free(msg);
10506 return -ENOBUFS;
10507}
10508
947add36
JB
10509void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
10510 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 10511{
947add36
JB
10512 struct wiphy *wiphy = wdev->wiphy;
10513 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
71bbc994 10514 struct net_device *netdev = wdev->netdev;
026331c4
JM
10515 struct sk_buff *msg;
10516 void *hdr;
10517
947add36
JB
10518 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
10519
026331c4
JM
10520 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10521 if (!msg)
10522 return;
10523
2e161f78 10524 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
10525 if (!hdr) {
10526 nlmsg_free(msg);
10527 return;
10528 }
10529
9360ffd1 10530 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10531 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10532 netdev->ifindex)) ||
a838490b 10533 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
10534 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
10535 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
10536 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
10537 goto nla_put_failure;
026331c4 10538
3b7b72ee 10539 genlmsg_end(msg, hdr);
026331c4 10540
a0ec570f
MK
10541 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10542 nl80211_mlme_mcgrp.id, gfp);
026331c4
JM
10543 return;
10544
10545 nla_put_failure:
10546 genlmsg_cancel(msg, hdr);
10547 nlmsg_free(msg);
10548}
947add36 10549EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 10550
947add36
JB
10551void cfg80211_cqm_rssi_notify(struct net_device *dev,
10552 enum nl80211_cqm_rssi_threshold_event rssi_event,
10553 gfp_t gfp)
d6dc1a38 10554{
947add36
JB
10555 struct wireless_dev *wdev = dev->ieee80211_ptr;
10556 struct wiphy *wiphy = wdev->wiphy;
10557 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
d6dc1a38
JO
10558 struct sk_buff *msg;
10559 struct nlattr *pinfoattr;
10560 void *hdr;
10561
947add36
JB
10562 trace_cfg80211_cqm_rssi_notify(dev, rssi_event);
10563
58050fce 10564 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
10565 if (!msg)
10566 return;
10567
10568 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10569 if (!hdr) {
10570 nlmsg_free(msg);
10571 return;
10572 }
10573
9360ffd1 10574 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10575 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 10576 goto nla_put_failure;
d6dc1a38
JO
10577
10578 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10579 if (!pinfoattr)
10580 goto nla_put_failure;
10581
9360ffd1
DM
10582 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
10583 rssi_event))
10584 goto nla_put_failure;
d6dc1a38
JO
10585
10586 nla_nest_end(msg, pinfoattr);
10587
3b7b72ee 10588 genlmsg_end(msg, hdr);
d6dc1a38
JO
10589
10590 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10591 nl80211_mlme_mcgrp.id, gfp);
10592 return;
10593
10594 nla_put_failure:
10595 genlmsg_cancel(msg, hdr);
10596 nlmsg_free(msg);
10597}
947add36 10598EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 10599
947add36
JB
10600static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
10601 struct net_device *netdev, const u8 *bssid,
10602 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
10603{
10604 struct sk_buff *msg;
10605 struct nlattr *rekey_attr;
10606 void *hdr;
10607
58050fce 10608 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
10609 if (!msg)
10610 return;
10611
10612 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
10613 if (!hdr) {
10614 nlmsg_free(msg);
10615 return;
10616 }
10617
9360ffd1
DM
10618 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10619 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10620 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
10621 goto nla_put_failure;
e5497d76
JB
10622
10623 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
10624 if (!rekey_attr)
10625 goto nla_put_failure;
10626
9360ffd1
DM
10627 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
10628 NL80211_REPLAY_CTR_LEN, replay_ctr))
10629 goto nla_put_failure;
e5497d76
JB
10630
10631 nla_nest_end(msg, rekey_attr);
10632
3b7b72ee 10633 genlmsg_end(msg, hdr);
e5497d76
JB
10634
10635 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10636 nl80211_mlme_mcgrp.id, gfp);
10637 return;
10638
10639 nla_put_failure:
10640 genlmsg_cancel(msg, hdr);
10641 nlmsg_free(msg);
10642}
10643
947add36
JB
10644void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
10645 const u8 *replay_ctr, gfp_t gfp)
10646{
10647 struct wireless_dev *wdev = dev->ieee80211_ptr;
10648 struct wiphy *wiphy = wdev->wiphy;
10649 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10650
10651 trace_cfg80211_gtk_rekey_notify(dev, bssid);
10652 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
10653}
10654EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
10655
10656static void
10657nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
10658 struct net_device *netdev, int index,
10659 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
10660{
10661 struct sk_buff *msg;
10662 struct nlattr *attr;
10663 void *hdr;
10664
58050fce 10665 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
10666 if (!msg)
10667 return;
10668
10669 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
10670 if (!hdr) {
10671 nlmsg_free(msg);
10672 return;
10673 }
10674
9360ffd1
DM
10675 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10676 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
10677 goto nla_put_failure;
c9df56b4
JM
10678
10679 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
10680 if (!attr)
10681 goto nla_put_failure;
10682
9360ffd1
DM
10683 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
10684 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
10685 (preauth &&
10686 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
10687 goto nla_put_failure;
c9df56b4
JM
10688
10689 nla_nest_end(msg, attr);
10690
3b7b72ee 10691 genlmsg_end(msg, hdr);
c9df56b4
JM
10692
10693 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10694 nl80211_mlme_mcgrp.id, gfp);
10695 return;
10696
10697 nla_put_failure:
10698 genlmsg_cancel(msg, hdr);
10699 nlmsg_free(msg);
10700}
10701
947add36
JB
10702void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
10703 const u8 *bssid, bool preauth, gfp_t gfp)
10704{
10705 struct wireless_dev *wdev = dev->ieee80211_ptr;
10706 struct wiphy *wiphy = wdev->wiphy;
10707 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10708
10709 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
10710 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
10711}
10712EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
10713
10714static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
10715 struct net_device *netdev,
10716 struct cfg80211_chan_def *chandef,
10717 gfp_t gfp)
5314526b
TP
10718{
10719 struct sk_buff *msg;
10720 void *hdr;
10721
58050fce 10722 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
10723 if (!msg)
10724 return;
10725
10726 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
10727 if (!hdr) {
10728 nlmsg_free(msg);
10729 return;
10730 }
10731
683b6d3b
JB
10732 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
10733 goto nla_put_failure;
10734
10735 if (nl80211_send_chandef(msg, chandef))
7eab0f64 10736 goto nla_put_failure;
5314526b
TP
10737
10738 genlmsg_end(msg, hdr);
10739
10740 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10741 nl80211_mlme_mcgrp.id, gfp);
10742 return;
10743
10744 nla_put_failure:
10745 genlmsg_cancel(msg, hdr);
10746 nlmsg_free(msg);
10747}
10748
947add36
JB
10749void cfg80211_ch_switch_notify(struct net_device *dev,
10750 struct cfg80211_chan_def *chandef)
84f10708 10751{
947add36
JB
10752 struct wireless_dev *wdev = dev->ieee80211_ptr;
10753 struct wiphy *wiphy = wdev->wiphy;
10754 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10755
10756 trace_cfg80211_ch_switch_notify(dev, chandef);
10757
10758 wdev_lock(wdev);
10759
10760 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
ee4bc9e7
SW
10761 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
10762 wdev->iftype != NL80211_IFTYPE_ADHOC))
947add36
JB
10763 goto out;
10764
10765 wdev->channel = chandef->chan;
10766 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL);
10767out:
10768 wdev_unlock(wdev);
10769 return;
10770}
10771EXPORT_SYMBOL(cfg80211_ch_switch_notify);
10772
10773void cfg80211_cqm_txe_notify(struct net_device *dev,
10774 const u8 *peer, u32 num_packets,
10775 u32 rate, u32 intvl, gfp_t gfp)
10776{
10777 struct wireless_dev *wdev = dev->ieee80211_ptr;
10778 struct wiphy *wiphy = wdev->wiphy;
10779 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
84f10708
TP
10780 struct sk_buff *msg;
10781 struct nlattr *pinfoattr;
10782 void *hdr;
10783
10784 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
10785 if (!msg)
10786 return;
10787
10788 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10789 if (!hdr) {
10790 nlmsg_free(msg);
10791 return;
10792 }
10793
10794 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10795 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
84f10708
TP
10796 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
10797 goto nla_put_failure;
10798
10799 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10800 if (!pinfoattr)
10801 goto nla_put_failure;
10802
10803 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
10804 goto nla_put_failure;
10805
10806 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
10807 goto nla_put_failure;
10808
10809 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
10810 goto nla_put_failure;
10811
10812 nla_nest_end(msg, pinfoattr);
10813
10814 genlmsg_end(msg, hdr);
10815
10816 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10817 nl80211_mlme_mcgrp.id, gfp);
10818 return;
10819
10820 nla_put_failure:
10821 genlmsg_cancel(msg, hdr);
10822 nlmsg_free(msg);
10823}
947add36 10824EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
84f10708 10825
04f39047
SW
10826void
10827nl80211_radar_notify(struct cfg80211_registered_device *rdev,
10828 struct cfg80211_chan_def *chandef,
10829 enum nl80211_radar_event event,
10830 struct net_device *netdev, gfp_t gfp)
10831{
10832 struct sk_buff *msg;
10833 void *hdr;
10834
10835 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10836 if (!msg)
10837 return;
10838
10839 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
10840 if (!hdr) {
10841 nlmsg_free(msg);
10842 return;
10843 }
10844
10845 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
10846 goto nla_put_failure;
10847
10848 /* NOP and radar events don't need a netdev parameter */
10849 if (netdev) {
10850 struct wireless_dev *wdev = netdev->ieee80211_ptr;
10851
10852 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10853 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
10854 goto nla_put_failure;
10855 }
10856
10857 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
10858 goto nla_put_failure;
10859
10860 if (nl80211_send_chandef(msg, chandef))
10861 goto nla_put_failure;
10862
9c90a9f6 10863 genlmsg_end(msg, hdr);
04f39047
SW
10864
10865 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10866 nl80211_mlme_mcgrp.id, gfp);
10867 return;
10868
10869 nla_put_failure:
10870 genlmsg_cancel(msg, hdr);
10871 nlmsg_free(msg);
10872}
10873
947add36
JB
10874void cfg80211_cqm_pktloss_notify(struct net_device *dev,
10875 const u8 *peer, u32 num_packets, gfp_t gfp)
c063dbf5 10876{
947add36
JB
10877 struct wireless_dev *wdev = dev->ieee80211_ptr;
10878 struct wiphy *wiphy = wdev->wiphy;
10879 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
c063dbf5
JB
10880 struct sk_buff *msg;
10881 struct nlattr *pinfoattr;
10882 void *hdr;
10883
947add36
JB
10884 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
10885
58050fce 10886 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
10887 if (!msg)
10888 return;
10889
10890 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10891 if (!hdr) {
10892 nlmsg_free(msg);
10893 return;
10894 }
10895
9360ffd1 10896 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10897 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9360ffd1
DM
10898 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
10899 goto nla_put_failure;
c063dbf5
JB
10900
10901 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10902 if (!pinfoattr)
10903 goto nla_put_failure;
10904
9360ffd1
DM
10905 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
10906 goto nla_put_failure;
c063dbf5
JB
10907
10908 nla_nest_end(msg, pinfoattr);
10909
3b7b72ee 10910 genlmsg_end(msg, hdr);
c063dbf5
JB
10911
10912 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10913 nl80211_mlme_mcgrp.id, gfp);
10914 return;
10915
10916 nla_put_failure:
10917 genlmsg_cancel(msg, hdr);
10918 nlmsg_free(msg);
10919}
947add36 10920EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
c063dbf5 10921
7f6cf311
JB
10922void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
10923 u64 cookie, bool acked, gfp_t gfp)
10924{
10925 struct wireless_dev *wdev = dev->ieee80211_ptr;
10926 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
10927 struct sk_buff *msg;
10928 void *hdr;
7f6cf311 10929
4ee3e063
BL
10930 trace_cfg80211_probe_status(dev, addr, cookie, acked);
10931
58050fce 10932 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 10933
7f6cf311
JB
10934 if (!msg)
10935 return;
10936
10937 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
10938 if (!hdr) {
10939 nlmsg_free(msg);
10940 return;
10941 }
10942
9360ffd1
DM
10943 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10944 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10945 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
10946 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
10947 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
10948 goto nla_put_failure;
7f6cf311 10949
9c90a9f6 10950 genlmsg_end(msg, hdr);
7f6cf311
JB
10951
10952 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10953 nl80211_mlme_mcgrp.id, gfp);
10954 return;
10955
10956 nla_put_failure:
10957 genlmsg_cancel(msg, hdr);
10958 nlmsg_free(msg);
10959}
10960EXPORT_SYMBOL(cfg80211_probe_status);
10961
5e760230
JB
10962void cfg80211_report_obss_beacon(struct wiphy *wiphy,
10963 const u8 *frame, size_t len,
37c73b5f 10964 int freq, int sig_dbm)
5e760230
JB
10965{
10966 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10967 struct sk_buff *msg;
10968 void *hdr;
37c73b5f 10969 struct cfg80211_beacon_registration *reg;
5e760230 10970
4ee3e063
BL
10971 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
10972
37c73b5f
BG
10973 spin_lock_bh(&rdev->beacon_registrations_lock);
10974 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
10975 msg = nlmsg_new(len + 100, GFP_ATOMIC);
10976 if (!msg) {
10977 spin_unlock_bh(&rdev->beacon_registrations_lock);
10978 return;
10979 }
5e760230 10980
37c73b5f
BG
10981 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
10982 if (!hdr)
10983 goto nla_put_failure;
5e760230 10984
37c73b5f
BG
10985 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10986 (freq &&
10987 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
10988 (sig_dbm &&
10989 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
10990 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
10991 goto nla_put_failure;
5e760230 10992
37c73b5f 10993 genlmsg_end(msg, hdr);
5e760230 10994
37c73b5f
BG
10995 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
10996 }
10997 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
10998 return;
10999
11000 nla_put_failure:
37c73b5f
BG
11001 spin_unlock_bh(&rdev->beacon_registrations_lock);
11002 if (hdr)
11003 genlmsg_cancel(msg, hdr);
5e760230
JB
11004 nlmsg_free(msg);
11005}
11006EXPORT_SYMBOL(cfg80211_report_obss_beacon);
11007
cd8f7cb4
JB
11008#ifdef CONFIG_PM
11009void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
11010 struct cfg80211_wowlan_wakeup *wakeup,
11011 gfp_t gfp)
11012{
11013 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
11014 struct sk_buff *msg;
11015 void *hdr;
9c90a9f6 11016 int size = 200;
cd8f7cb4
JB
11017
11018 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
11019
11020 if (wakeup)
11021 size += wakeup->packet_present_len;
11022
11023 msg = nlmsg_new(size, gfp);
11024 if (!msg)
11025 return;
11026
11027 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
11028 if (!hdr)
11029 goto free_msg;
11030
11031 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11032 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
11033 goto free_msg;
11034
11035 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11036 wdev->netdev->ifindex))
11037 goto free_msg;
11038
11039 if (wakeup) {
11040 struct nlattr *reasons;
11041
11042 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
11043
11044 if (wakeup->disconnect &&
11045 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
11046 goto free_msg;
11047 if (wakeup->magic_pkt &&
11048 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
11049 goto free_msg;
11050 if (wakeup->gtk_rekey_failure &&
11051 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
11052 goto free_msg;
11053 if (wakeup->eap_identity_req &&
11054 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
11055 goto free_msg;
11056 if (wakeup->four_way_handshake &&
11057 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
11058 goto free_msg;
11059 if (wakeup->rfkill_release &&
11060 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
11061 goto free_msg;
11062
11063 if (wakeup->pattern_idx >= 0 &&
11064 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
11065 wakeup->pattern_idx))
11066 goto free_msg;
11067
2a0e047e
JB
11068 if (wakeup->tcp_match)
11069 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH);
11070
11071 if (wakeup->tcp_connlost)
11072 nla_put_flag(msg,
11073 NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST);
11074
11075 if (wakeup->tcp_nomoretokens)
11076 nla_put_flag(msg,
11077 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS);
11078
cd8f7cb4
JB
11079 if (wakeup->packet) {
11080 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
11081 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
11082
11083 if (!wakeup->packet_80211) {
11084 pkt_attr =
11085 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
11086 len_attr =
11087 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
11088 }
11089
11090 if (wakeup->packet_len &&
11091 nla_put_u32(msg, len_attr, wakeup->packet_len))
11092 goto free_msg;
11093
11094 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
11095 wakeup->packet))
11096 goto free_msg;
11097 }
11098
11099 nla_nest_end(msg, reasons);
11100 }
11101
9c90a9f6 11102 genlmsg_end(msg, hdr);
cd8f7cb4
JB
11103
11104 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
11105 nl80211_mlme_mcgrp.id, gfp);
11106 return;
11107
11108 free_msg:
11109 nlmsg_free(msg);
11110}
11111EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
11112#endif
11113
3475b094
JM
11114void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
11115 enum nl80211_tdls_operation oper,
11116 u16 reason_code, gfp_t gfp)
11117{
11118 struct wireless_dev *wdev = dev->ieee80211_ptr;
11119 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
11120 struct sk_buff *msg;
11121 void *hdr;
3475b094
JM
11122
11123 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
11124 reason_code);
11125
11126 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11127 if (!msg)
11128 return;
11129
11130 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
11131 if (!hdr) {
11132 nlmsg_free(msg);
11133 return;
11134 }
11135
11136 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11137 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
11138 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
11139 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
11140 (reason_code > 0 &&
11141 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
11142 goto nla_put_failure;
11143
9c90a9f6 11144 genlmsg_end(msg, hdr);
3475b094
JM
11145
11146 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
11147 nl80211_mlme_mcgrp.id, gfp);
11148 return;
11149
11150 nla_put_failure:
11151 genlmsg_cancel(msg, hdr);
11152 nlmsg_free(msg);
11153}
11154EXPORT_SYMBOL(cfg80211_tdls_oper_request);
11155
026331c4
JM
11156static int nl80211_netlink_notify(struct notifier_block * nb,
11157 unsigned long state,
11158 void *_notify)
11159{
11160 struct netlink_notify *notify = _notify;
11161 struct cfg80211_registered_device *rdev;
11162 struct wireless_dev *wdev;
37c73b5f 11163 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
11164
11165 if (state != NETLINK_URELEASE)
11166 return NOTIFY_DONE;
11167
11168 rcu_read_lock();
11169
5e760230 11170 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 11171 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 11172 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
11173
11174 spin_lock_bh(&rdev->beacon_registrations_lock);
11175 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
11176 list) {
11177 if (reg->nlportid == notify->portid) {
11178 list_del(&reg->list);
11179 kfree(reg);
11180 break;
11181 }
11182 }
11183 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 11184 }
026331c4
JM
11185
11186 rcu_read_unlock();
11187
11188 return NOTIFY_DONE;
11189}
11190
11191static struct notifier_block nl80211_netlink_notifier = {
11192 .notifier_call = nl80211_netlink_notify,
11193};
11194
355199e0
JM
11195void cfg80211_ft_event(struct net_device *netdev,
11196 struct cfg80211_ft_event_params *ft_event)
11197{
11198 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
11199 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
11200 struct sk_buff *msg;
11201 void *hdr;
355199e0
JM
11202
11203 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
11204
11205 if (!ft_event->target_ap)
11206 return;
11207
11208 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11209 if (!msg)
11210 return;
11211
11212 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
11213 if (!hdr) {
11214 nlmsg_free(msg);
11215 return;
11216 }
11217
11218 nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
11219 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
11220 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap);
11221 if (ft_event->ies)
11222 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies);
11223 if (ft_event->ric_ies)
11224 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
11225 ft_event->ric_ies);
11226
9c90a9f6 11227 genlmsg_end(msg, hdr);
355199e0
JM
11228
11229 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
11230 nl80211_mlme_mcgrp.id, GFP_KERNEL);
11231}
11232EXPORT_SYMBOL(cfg80211_ft_event);
11233
5de17984
AS
11234void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
11235{
11236 struct cfg80211_registered_device *rdev;
11237 struct sk_buff *msg;
11238 void *hdr;
11239 u32 nlportid;
11240
11241 rdev = wiphy_to_dev(wdev->wiphy);
11242 if (!rdev->crit_proto_nlportid)
11243 return;
11244
11245 nlportid = rdev->crit_proto_nlportid;
11246 rdev->crit_proto_nlportid = 0;
11247
11248 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11249 if (!msg)
11250 return;
11251
11252 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
11253 if (!hdr)
11254 goto nla_put_failure;
11255
11256 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11257 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
11258 goto nla_put_failure;
11259
11260 genlmsg_end(msg, hdr);
11261
11262 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
11263 return;
11264
11265 nla_put_failure:
11266 if (hdr)
11267 genlmsg_cancel(msg, hdr);
11268 nlmsg_free(msg);
11269
11270}
11271EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
11272
55682965
JB
11273/* initialisation/exit functions */
11274
11275int nl80211_init(void)
11276{
0d63cbb5 11277 int err;
55682965 11278
0d63cbb5
MM
11279 err = genl_register_family_with_ops(&nl80211_fam,
11280 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
11281 if (err)
11282 return err;
11283
55682965
JB
11284 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
11285 if (err)
11286 goto err_out;
11287
2a519311
JB
11288 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
11289 if (err)
11290 goto err_out;
11291
73d54c9e
LR
11292 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
11293 if (err)
11294 goto err_out;
11295
6039f6d2
JM
11296 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
11297 if (err)
11298 goto err_out;
11299
aff89a9b
JB
11300#ifdef CONFIG_NL80211_TESTMODE
11301 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
11302 if (err)
11303 goto err_out;
11304#endif
11305
026331c4
JM
11306 err = netlink_register_notifier(&nl80211_netlink_notifier);
11307 if (err)
11308 goto err_out;
11309
55682965
JB
11310 return 0;
11311 err_out:
11312 genl_unregister_family(&nl80211_fam);
11313 return err;
11314}
11315
11316void nl80211_exit(void)
11317{
026331c4 11318 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
11319 genl_unregister_family(&nl80211_fam);
11320}