]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/blame - net/wireless/nl80211.c
rt2800: zero registers of unused TX rings
[mirror_ubuntu-focal-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
79c97e97 49/* internal helper: get rdev and dev */
00918d33
JB
50static int get_rdev_dev_by_ifindex(struct net *netns, struct nlattr **attrs,
51 struct cfg80211_registered_device **rdev,
52 struct net_device **dev)
55682965
JB
53{
54 int ifindex;
55
bba95fef 56 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
57 return -EINVAL;
58
bba95fef 59 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
00918d33 60 *dev = dev_get_by_index(netns, ifindex);
55682965
JB
61 if (!*dev)
62 return -ENODEV;
63
00918d33 64 *rdev = cfg80211_get_dev_from_ifindex(netns, ifindex);
79c97e97 65 if (IS_ERR(*rdev)) {
55682965 66 dev_put(*dev);
79c97e97 67 return PTR_ERR(*rdev);
55682965
JB
68 }
69
70 return 0;
71}
72
73/* policy for the attributes */
b54452b0 74static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
75 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
76 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 77 .len = 20-1 },
31888487 78 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 79 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 80 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
81 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
82 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
84 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 85 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
86
87 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
88 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 90
e007b857
EP
91 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
92 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 93
b9454e83 94 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
95 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
96 .len = WLAN_MAX_KEY_LEN },
97 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
98 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
99 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 100 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 101 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
102
103 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
104 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
105 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
106 .len = IEEE80211_MAX_DATA_LEN },
107 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
108 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
109 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
110 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
111 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
112 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 114 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 115 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 116 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
117 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
118 .len = IEEE80211_MAX_MESH_ID_LEN },
119 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 120
b2e1b302
LR
121 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
122 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
123
9f1ba906
JM
124 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
125 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
127 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
128 .len = NL80211_MAX_SUPP_RATES },
50b12f59 129 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 130
24bdd9f4 131 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 132 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 133
6c739419 134 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
135
136 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
137 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
138 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
139 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
140 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
141
142 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
143 .len = IEEE80211_MAX_SSID_LEN },
144 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
145 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 146 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 147 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 148 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
149 [NL80211_ATTR_STA_FLAGS2] = {
150 .len = sizeof(struct nl80211_sta_flag_update),
151 },
3f77316c 152 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
153 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
154 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
155 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
156 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
157 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 158 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 159 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
160 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
161 .len = WLAN_PMKID_LEN },
9588bbd5
JM
162 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
163 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 164 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
165 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
166 .len = IEEE80211_MAX_DATA_LEN },
167 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 168 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 169 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 170 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 171 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
172 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
173 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 174 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
175 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
176 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 177 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 178 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 179 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 180 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 181 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 182 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 183 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 184 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 185 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
186 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
187 .len = IEEE80211_MAX_DATA_LEN },
188 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
189 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 190 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 191 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 192 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
193 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
194 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
197 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 198 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
199 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
200 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 201 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
202 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
203 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
204 .len = NL80211_HT_CAPABILITY_LEN
205 },
1d9d9213 206 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 207 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 208 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
55682965
JB
209};
210
e31b8213 211/* policy for the key attributes */
b54452b0 212static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 213 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
214 [NL80211_KEY_IDX] = { .type = NLA_U8 },
215 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 216 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
217 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
218 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 219 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
220 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
221};
222
223/* policy for the key default flags */
224static const struct nla_policy
225nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
226 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
227 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
228};
229
ff1b6e69
JB
230/* policy for WoWLAN attributes */
231static const struct nla_policy
232nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
233 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
234 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
235 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
236 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
237 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
238 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
239 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
240 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
241};
242
e5497d76
JB
243/* policy for GTK rekey offload attributes */
244static const struct nla_policy
245nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
246 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
247 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
248 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
249};
250
a1f1c21c
LC
251static const struct nla_policy
252nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
253 [NL80211_ATTR_SCHED_SCAN_MATCH_SSID] = { .type = NLA_BINARY,
254 .len = IEEE80211_MAX_SSID_LEN },
255};
256
a043897a
HS
257/* ifidx get helper */
258static int nl80211_get_ifidx(struct netlink_callback *cb)
259{
260 int res;
261
262 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
263 nl80211_fam.attrbuf, nl80211_fam.maxattr,
264 nl80211_policy);
265 if (res)
266 return res;
267
268 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
269 return -EINVAL;
270
271 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
272 if (!res)
273 return -EINVAL;
274 return res;
275}
276
67748893
JB
277static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
278 struct netlink_callback *cb,
279 struct cfg80211_registered_device **rdev,
280 struct net_device **dev)
281{
282 int ifidx = cb->args[0];
283 int err;
284
285 if (!ifidx)
286 ifidx = nl80211_get_ifidx(cb);
287 if (ifidx < 0)
288 return ifidx;
289
290 cb->args[0] = ifidx;
291
292 rtnl_lock();
293
294 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
295 if (!*dev) {
296 err = -ENODEV;
297 goto out_rtnl;
298 }
299
300 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
301 if (IS_ERR(*rdev)) {
302 err = PTR_ERR(*rdev);
67748893
JB
303 goto out_rtnl;
304 }
305
306 return 0;
307 out_rtnl:
308 rtnl_unlock();
309 return err;
310}
311
312static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
313{
314 cfg80211_unlock_rdev(rdev);
315 rtnl_unlock();
316}
317
f4a11bb0
JB
318/* IE validation */
319static bool is_valid_ie_attr(const struct nlattr *attr)
320{
321 const u8 *pos;
322 int len;
323
324 if (!attr)
325 return true;
326
327 pos = nla_data(attr);
328 len = nla_len(attr);
329
330 while (len) {
331 u8 elemlen;
332
333 if (len < 2)
334 return false;
335 len -= 2;
336
337 elemlen = pos[1];
338 if (elemlen > len)
339 return false;
340
341 len -= elemlen;
342 pos += 2 + elemlen;
343 }
344
345 return true;
346}
347
55682965
JB
348/* message building helper */
349static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
350 int flags, u8 cmd)
351{
352 /* since there is no private header just add the generic one */
353 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
354}
355
5dab3b8a
LR
356static int nl80211_msg_put_channel(struct sk_buff *msg,
357 struct ieee80211_channel *chan)
358{
359 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
360 chan->center_freq);
361
362 if (chan->flags & IEEE80211_CHAN_DISABLED)
363 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
364 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
365 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
366 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
367 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
368 if (chan->flags & IEEE80211_CHAN_RADAR)
369 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
370
371 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
372 DBM_TO_MBM(chan->max_power));
373
374 return 0;
375
376 nla_put_failure:
377 return -ENOBUFS;
378}
379
55682965
JB
380/* netlink command implementations */
381
b9454e83
JB
382struct key_parse {
383 struct key_params p;
384 int idx;
e31b8213 385 int type;
b9454e83 386 bool def, defmgmt;
dbd2fd65 387 bool def_uni, def_multi;
b9454e83
JB
388};
389
390static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
391{
392 struct nlattr *tb[NL80211_KEY_MAX + 1];
393 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
394 nl80211_key_policy);
395 if (err)
396 return err;
397
398 k->def = !!tb[NL80211_KEY_DEFAULT];
399 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
400
dbd2fd65
JB
401 if (k->def) {
402 k->def_uni = true;
403 k->def_multi = true;
404 }
405 if (k->defmgmt)
406 k->def_multi = true;
407
b9454e83
JB
408 if (tb[NL80211_KEY_IDX])
409 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
410
411 if (tb[NL80211_KEY_DATA]) {
412 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
413 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
414 }
415
416 if (tb[NL80211_KEY_SEQ]) {
417 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
418 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
419 }
420
421 if (tb[NL80211_KEY_CIPHER])
422 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
423
e31b8213
JB
424 if (tb[NL80211_KEY_TYPE]) {
425 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
426 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
427 return -EINVAL;
428 }
429
dbd2fd65
JB
430 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
431 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
432 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
433 tb[NL80211_KEY_DEFAULT_TYPES],
434 nl80211_key_default_policy);
dbd2fd65
JB
435 if (err)
436 return err;
437
438 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
439 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
440 }
441
b9454e83
JB
442 return 0;
443}
444
445static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
446{
447 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
448 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
449 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
450 }
451
452 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
453 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
454 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
455 }
456
457 if (info->attrs[NL80211_ATTR_KEY_IDX])
458 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
459
460 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
461 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
462
463 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
464 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
465
dbd2fd65
JB
466 if (k->def) {
467 k->def_uni = true;
468 k->def_multi = true;
469 }
470 if (k->defmgmt)
471 k->def_multi = true;
472
e31b8213
JB
473 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
474 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
475 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
476 return -EINVAL;
477 }
478
dbd2fd65
JB
479 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
480 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
481 int err = nla_parse_nested(
482 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
483 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
484 nl80211_key_default_policy);
485 if (err)
486 return err;
487
488 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
489 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
490 }
491
b9454e83
JB
492 return 0;
493}
494
495static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
496{
497 int err;
498
499 memset(k, 0, sizeof(*k));
500 k->idx = -1;
e31b8213 501 k->type = -1;
b9454e83
JB
502
503 if (info->attrs[NL80211_ATTR_KEY])
504 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
505 else
506 err = nl80211_parse_key_old(info, k);
507
508 if (err)
509 return err;
510
511 if (k->def && k->defmgmt)
512 return -EINVAL;
513
dbd2fd65
JB
514 if (k->defmgmt) {
515 if (k->def_uni || !k->def_multi)
516 return -EINVAL;
517 }
518
b9454e83
JB
519 if (k->idx != -1) {
520 if (k->defmgmt) {
521 if (k->idx < 4 || k->idx > 5)
522 return -EINVAL;
523 } else if (k->def) {
524 if (k->idx < 0 || k->idx > 3)
525 return -EINVAL;
526 } else {
527 if (k->idx < 0 || k->idx > 5)
528 return -EINVAL;
529 }
530 }
531
532 return 0;
533}
534
fffd0934
JB
535static struct cfg80211_cached_keys *
536nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
537 struct nlattr *keys)
538{
539 struct key_parse parse;
540 struct nlattr *key;
541 struct cfg80211_cached_keys *result;
542 int rem, err, def = 0;
543
544 result = kzalloc(sizeof(*result), GFP_KERNEL);
545 if (!result)
546 return ERR_PTR(-ENOMEM);
547
548 result->def = -1;
549 result->defmgmt = -1;
550
551 nla_for_each_nested(key, keys, rem) {
552 memset(&parse, 0, sizeof(parse));
553 parse.idx = -1;
554
555 err = nl80211_parse_key_new(key, &parse);
556 if (err)
557 goto error;
558 err = -EINVAL;
559 if (!parse.p.key)
560 goto error;
561 if (parse.idx < 0 || parse.idx > 4)
562 goto error;
563 if (parse.def) {
564 if (def)
565 goto error;
566 def = 1;
567 result->def = parse.idx;
dbd2fd65
JB
568 if (!parse.def_uni || !parse.def_multi)
569 goto error;
fffd0934
JB
570 } else if (parse.defmgmt)
571 goto error;
572 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 573 parse.idx, false, NULL);
fffd0934
JB
574 if (err)
575 goto error;
576 result->params[parse.idx].cipher = parse.p.cipher;
577 result->params[parse.idx].key_len = parse.p.key_len;
578 result->params[parse.idx].key = result->data[parse.idx];
579 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
580 }
581
582 return result;
583 error:
584 kfree(result);
585 return ERR_PTR(err);
586}
587
588static int nl80211_key_allowed(struct wireless_dev *wdev)
589{
590 ASSERT_WDEV_LOCK(wdev);
591
fffd0934
JB
592 switch (wdev->iftype) {
593 case NL80211_IFTYPE_AP:
594 case NL80211_IFTYPE_AP_VLAN:
074ac8df 595 case NL80211_IFTYPE_P2P_GO:
ff973af7 596 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
597 break;
598 case NL80211_IFTYPE_ADHOC:
599 if (!wdev->current_bss)
600 return -ENOLINK;
601 break;
602 case NL80211_IFTYPE_STATION:
074ac8df 603 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
604 if (wdev->sme_state != CFG80211_SME_CONNECTED)
605 return -ENOLINK;
606 break;
607 default:
608 return -EINVAL;
609 }
610
611 return 0;
612}
613
7527a782
JB
614static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
615{
616 struct nlattr *nl_modes = nla_nest_start(msg, attr);
617 int i;
618
619 if (!nl_modes)
620 goto nla_put_failure;
621
622 i = 0;
623 while (ifmodes) {
624 if (ifmodes & 1)
625 NLA_PUT_FLAG(msg, i);
626 ifmodes >>= 1;
627 i++;
628 }
629
630 nla_nest_end(msg, nl_modes);
631 return 0;
632
633nla_put_failure:
634 return -ENOBUFS;
635}
636
637static int nl80211_put_iface_combinations(struct wiphy *wiphy,
638 struct sk_buff *msg)
639{
640 struct nlattr *nl_combis;
641 int i, j;
642
643 nl_combis = nla_nest_start(msg,
644 NL80211_ATTR_INTERFACE_COMBINATIONS);
645 if (!nl_combis)
646 goto nla_put_failure;
647
648 for (i = 0; i < wiphy->n_iface_combinations; i++) {
649 const struct ieee80211_iface_combination *c;
650 struct nlattr *nl_combi, *nl_limits;
651
652 c = &wiphy->iface_combinations[i];
653
654 nl_combi = nla_nest_start(msg, i + 1);
655 if (!nl_combi)
656 goto nla_put_failure;
657
658 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
659 if (!nl_limits)
660 goto nla_put_failure;
661
662 for (j = 0; j < c->n_limits; j++) {
663 struct nlattr *nl_limit;
664
665 nl_limit = nla_nest_start(msg, j + 1);
666 if (!nl_limit)
667 goto nla_put_failure;
668 NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
669 c->limits[j].max);
670 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
671 c->limits[j].types))
672 goto nla_put_failure;
673 nla_nest_end(msg, nl_limit);
674 }
675
676 nla_nest_end(msg, nl_limits);
677
678 if (c->beacon_int_infra_match)
679 NLA_PUT_FLAG(msg,
680 NL80211_IFACE_COMB_STA_AP_BI_MATCH);
681 NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
682 c->num_different_channels);
683 NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
684 c->max_interfaces);
685
686 nla_nest_end(msg, nl_combi);
687 }
688
689 nla_nest_end(msg, nl_combis);
690
691 return 0;
692nla_put_failure:
693 return -ENOBUFS;
694}
695
55682965
JB
696static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
697 struct cfg80211_registered_device *dev)
698{
699 void *hdr;
ee688b00
JB
700 struct nlattr *nl_bands, *nl_band;
701 struct nlattr *nl_freqs, *nl_freq;
702 struct nlattr *nl_rates, *nl_rate;
8fdc621d 703 struct nlattr *nl_cmds;
ee688b00
JB
704 enum ieee80211_band band;
705 struct ieee80211_channel *chan;
706 struct ieee80211_rate *rate;
707 int i;
2e161f78
JB
708 const struct ieee80211_txrx_stypes *mgmt_stypes =
709 dev->wiphy.mgmt_stypes;
55682965
JB
710
711 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
712 if (!hdr)
713 return -1;
714
b5850a7a 715 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 716 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 717
f5ea9120
JB
718 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
719 cfg80211_rdev_list_generation);
720
b9a5f8ca
JM
721 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
722 dev->wiphy.retry_short);
723 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
724 dev->wiphy.retry_long);
725 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
726 dev->wiphy.frag_threshold);
727 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
728 dev->wiphy.rts_threshold);
81077e82
LT
729 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
730 dev->wiphy.coverage_class);
2a519311
JB
731 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
732 dev->wiphy.max_scan_ssids);
93b6aa69
LC
733 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
734 dev->wiphy.max_sched_scan_ssids);
18a83659
JB
735 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
736 dev->wiphy.max_scan_ie_len);
5a865bad
LC
737 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
738 dev->wiphy.max_sched_scan_ie_len);
a1f1c21c
LC
739 NLA_PUT_U8(msg, NL80211_ATTR_MAX_MATCH_SETS,
740 dev->wiphy.max_match_sets);
ee688b00 741
e31b8213
JB
742 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
743 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
744 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
745 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
cedb5412
EP
746 if (dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD)
747 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_AP_UAPSD);
f4b34b55
VN
748 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)
749 NLA_PUT_FLAG(msg, NL80211_ATTR_ROAM_SUPPORT);
109086ce
AN
750 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)
751 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_SUPPORT);
752 if (dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)
753 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP);
f4b34b55 754
25e47c18
JB
755 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
756 sizeof(u32) * dev->wiphy.n_cipher_suites,
757 dev->wiphy.cipher_suites);
758
67fbb16b
SO
759 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
760 dev->wiphy.max_num_pmkids);
761
c0692b8f
JB
762 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
763 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
764
39fd5de4
BR
765 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
766 dev->wiphy.available_antennas_tx);
767 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
768 dev->wiphy.available_antennas_rx);
769
87bbbe22
AN
770 if (dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD)
771 NLA_PUT_U32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
772 dev->wiphy.probe_resp_offload);
773
7f531e03
BR
774 if ((dev->wiphy.available_antennas_tx ||
775 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
776 u32 tx_ant = 0, rx_ant = 0;
777 int res;
778 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
779 if (!res) {
780 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
781 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
782 }
783 }
784
7527a782
JB
785 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
786 dev->wiphy.interface_modes))
f59ac048
LR
787 goto nla_put_failure;
788
ee688b00
JB
789 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
790 if (!nl_bands)
791 goto nla_put_failure;
792
793 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
794 if (!dev->wiphy.bands[band])
795 continue;
796
797 nl_band = nla_nest_start(msg, band);
798 if (!nl_band)
799 goto nla_put_failure;
800
d51626df
JB
801 /* add HT info */
802 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
803 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
804 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
805 &dev->wiphy.bands[band]->ht_cap.mcs);
806 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
807 dev->wiphy.bands[band]->ht_cap.cap);
808 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
809 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
810 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
811 dev->wiphy.bands[band]->ht_cap.ampdu_density);
812 }
813
ee688b00
JB
814 /* add frequencies */
815 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
816 if (!nl_freqs)
817 goto nla_put_failure;
818
819 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
820 nl_freq = nla_nest_start(msg, i);
821 if (!nl_freq)
822 goto nla_put_failure;
823
824 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
825
826 if (nl80211_msg_put_channel(msg, chan))
827 goto nla_put_failure;
e2f367f2 828
ee688b00
JB
829 nla_nest_end(msg, nl_freq);
830 }
831
832 nla_nest_end(msg, nl_freqs);
833
834 /* add bitrates */
835 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
836 if (!nl_rates)
837 goto nla_put_failure;
838
839 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
840 nl_rate = nla_nest_start(msg, i);
841 if (!nl_rate)
842 goto nla_put_failure;
843
844 rate = &dev->wiphy.bands[band]->bitrates[i];
845 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
846 rate->bitrate);
847 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
848 NLA_PUT_FLAG(msg,
849 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
850
851 nla_nest_end(msg, nl_rate);
852 }
853
854 nla_nest_end(msg, nl_rates);
855
856 nla_nest_end(msg, nl_band);
857 }
858 nla_nest_end(msg, nl_bands);
859
8fdc621d
JB
860 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
861 if (!nl_cmds)
862 goto nla_put_failure;
863
864 i = 0;
865#define CMD(op, n) \
866 do { \
867 if (dev->ops->op) { \
868 i++; \
869 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
870 } \
871 } while (0)
872
873 CMD(add_virtual_intf, NEW_INTERFACE);
874 CMD(change_virtual_intf, SET_INTERFACE);
875 CMD(add_key, NEW_KEY);
8860020e 876 CMD(start_ap, START_AP);
8fdc621d
JB
877 CMD(add_station, NEW_STATION);
878 CMD(add_mpath, NEW_MPATH);
24bdd9f4 879 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 880 CMD(change_bss, SET_BSS);
636a5d36
JM
881 CMD(auth, AUTHENTICATE);
882 CMD(assoc, ASSOCIATE);
883 CMD(deauth, DEAUTHENTICATE);
884 CMD(disassoc, DISASSOCIATE);
04a773ad 885 CMD(join_ibss, JOIN_IBSS);
29cbe68c 886 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
887 CMD(set_pmksa, SET_PMKSA);
888 CMD(del_pmksa, DEL_PMKSA);
889 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
890 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
891 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 892 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 893 CMD(mgmt_tx, FRAME);
f7ca38df 894 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 895 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
896 i++;
897 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
898 }
f444de05 899 CMD(set_channel, SET_CHANNEL);
e8347eba 900 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
901 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
902 CMD(tdls_mgmt, TDLS_MGMT);
903 CMD(tdls_oper, TDLS_OPER);
904 }
807f8a8c
LC
905 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
906 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 907 CMD(probe_client, PROBE_CLIENT);
1d9d9213 908 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
909 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
910 i++;
911 NLA_PUT_U32(msg, i, NL80211_CMD_REGISTER_BEACONS);
912 }
8fdc621d 913
4745fc09
KV
914#ifdef CONFIG_NL80211_TESTMODE
915 CMD(testmode_cmd, TESTMODE);
916#endif
917
8fdc621d 918#undef CMD
b23aa676 919
6829c878 920 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
921 i++;
922 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
923 }
924
6829c878 925 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
926 i++;
927 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
928 }
929
8fdc621d
JB
930 nla_nest_end(msg, nl_cmds);
931
7c4ef712
JB
932 if (dev->ops->remain_on_channel &&
933 dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
a293911d
JB
934 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
935 dev->wiphy.max_remain_on_channel_duration);
936
7c4ef712 937 if (dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)
f7ca38df
JB
938 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
939
2e161f78
JB
940 if (mgmt_stypes) {
941 u16 stypes;
942 struct nlattr *nl_ftypes, *nl_ifs;
943 enum nl80211_iftype ift;
944
945 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
946 if (!nl_ifs)
947 goto nla_put_failure;
948
949 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
950 nl_ftypes = nla_nest_start(msg, ift);
951 if (!nl_ftypes)
952 goto nla_put_failure;
953 i = 0;
954 stypes = mgmt_stypes[ift].tx;
955 while (stypes) {
956 if (stypes & 1)
957 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
958 (i << 4) | IEEE80211_FTYPE_MGMT);
959 stypes >>= 1;
960 i++;
961 }
962 nla_nest_end(msg, nl_ftypes);
963 }
964
74b70a4e
JB
965 nla_nest_end(msg, nl_ifs);
966
2e161f78
JB
967 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
968 if (!nl_ifs)
969 goto nla_put_failure;
970
971 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
972 nl_ftypes = nla_nest_start(msg, ift);
973 if (!nl_ftypes)
974 goto nla_put_failure;
975 i = 0;
976 stypes = mgmt_stypes[ift].rx;
977 while (stypes) {
978 if (stypes & 1)
979 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
980 (i << 4) | IEEE80211_FTYPE_MGMT);
981 stypes >>= 1;
982 i++;
983 }
984 nla_nest_end(msg, nl_ftypes);
985 }
986 nla_nest_end(msg, nl_ifs);
987 }
988
ff1b6e69
JB
989 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
990 struct nlattr *nl_wowlan;
991
992 nl_wowlan = nla_nest_start(msg,
993 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
994 if (!nl_wowlan)
995 goto nla_put_failure;
996
997 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
998 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
999 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
1000 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
1001 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
1002 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
1003 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
1004 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
1005 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
1006 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
1007 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
1008 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
1009 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
1010 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
1011 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
1012 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
1013 if (dev->wiphy.wowlan.n_patterns) {
1014 struct nl80211_wowlan_pattern_support pat = {
1015 .max_patterns = dev->wiphy.wowlan.n_patterns,
1016 .min_pattern_len =
1017 dev->wiphy.wowlan.pattern_min_len,
1018 .max_pattern_len =
1019 dev->wiphy.wowlan.pattern_max_len,
1020 };
1021 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1022 sizeof(pat), &pat);
1023 }
1024
1025 nla_nest_end(msg, nl_wowlan);
1026 }
1027
7527a782
JB
1028 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1029 dev->wiphy.software_iftypes))
1030 goto nla_put_failure;
1031
1032 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1033 goto nla_put_failure;
1034
562a7480
JB
1035 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME)
1036 NLA_PUT_U32(msg, NL80211_ATTR_DEVICE_AP_SME,
1037 dev->wiphy.ap_sme_capa);
1038
1f074bd8
JB
1039 NLA_PUT_U32(msg, NL80211_ATTR_FEATURE_FLAGS, dev->wiphy.features);
1040
7e7c8926
BG
1041 if (dev->wiphy.ht_capa_mod_mask)
1042 NLA_PUT(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1043 sizeof(*dev->wiphy.ht_capa_mod_mask),
1044 dev->wiphy.ht_capa_mod_mask);
1045
55682965
JB
1046 return genlmsg_end(msg, hdr);
1047
1048 nla_put_failure:
bc3ed28c
TG
1049 genlmsg_cancel(msg, hdr);
1050 return -EMSGSIZE;
55682965
JB
1051}
1052
1053static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1054{
1055 int idx = 0;
1056 int start = cb->args[0];
1057 struct cfg80211_registered_device *dev;
1058
a1794390 1059 mutex_lock(&cfg80211_mutex);
79c97e97 1060 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1061 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1062 continue;
b4637271 1063 if (++idx <= start)
55682965
JB
1064 continue;
1065 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1066 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1067 dev) < 0) {
1068 idx--;
55682965 1069 break;
b4637271 1070 }
55682965 1071 }
a1794390 1072 mutex_unlock(&cfg80211_mutex);
55682965
JB
1073
1074 cb->args[0] = idx;
1075
1076 return skb->len;
1077}
1078
1079static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1080{
1081 struct sk_buff *msg;
4c476991 1082 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1083
fd2120ca 1084 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1085 if (!msg)
4c476991 1086 return -ENOMEM;
55682965 1087
4c476991
JB
1088 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1089 nlmsg_free(msg);
1090 return -ENOBUFS;
1091 }
55682965 1092
134e6375 1093 return genlmsg_reply(msg, info);
55682965
JB
1094}
1095
31888487
JM
1096static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1097 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1098 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1099 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1100 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1101 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1102};
1103
1104static int parse_txq_params(struct nlattr *tb[],
1105 struct ieee80211_txq_params *txq_params)
1106{
a3304b0a 1107 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1108 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1109 !tb[NL80211_TXQ_ATTR_AIFS])
1110 return -EINVAL;
1111
a3304b0a 1112 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1113 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1114 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1115 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1116 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1117
a3304b0a
JB
1118 if (txq_params->ac >= NL80211_NUM_ACS)
1119 return -EINVAL;
1120
31888487
JM
1121 return 0;
1122}
1123
f444de05
JB
1124static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1125{
1126 /*
1127 * You can only set the channel explicitly for AP, mesh
1128 * and WDS type interfaces; all others have their channel
1129 * managed via their respective "establish a connection"
1130 * command (connect, join, ...)
1131 *
1132 * Monitors are special as they are normally slaved to
1133 * whatever else is going on, so they behave as though
1134 * you tried setting the wiphy channel itself.
1135 */
1136 return !wdev ||
1137 wdev->iftype == NL80211_IFTYPE_AP ||
1138 wdev->iftype == NL80211_IFTYPE_WDS ||
1139 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1140 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1141 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1142}
1143
1144static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1145 struct wireless_dev *wdev,
1146 struct genl_info *info)
1147{
1148 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1149 u32 freq;
1150 int result;
1151
1152 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1153 return -EINVAL;
1154
1155 if (!nl80211_can_set_dev_channel(wdev))
1156 return -EOPNOTSUPP;
1157
1158 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1159 channel_type = nla_get_u32(info->attrs[
1160 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1161 if (channel_type != NL80211_CHAN_NO_HT &&
1162 channel_type != NL80211_CHAN_HT20 &&
1163 channel_type != NL80211_CHAN_HT40PLUS &&
1164 channel_type != NL80211_CHAN_HT40MINUS)
1165 return -EINVAL;
1166 }
1167
1168 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1169
1170 mutex_lock(&rdev->devlist_mtx);
1171 if (wdev) {
1172 wdev_lock(wdev);
1173 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1174 wdev_unlock(wdev);
1175 } else {
1176 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1177 }
1178 mutex_unlock(&rdev->devlist_mtx);
1179
1180 return result;
1181}
1182
1183static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1184{
4c476991
JB
1185 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1186 struct net_device *netdev = info->user_ptr[1];
f444de05 1187
4c476991 1188 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1189}
1190
e8347eba
BJ
1191static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1192{
43b19952
JB
1193 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1194 struct net_device *dev = info->user_ptr[1];
1195 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1196 const u8 *bssid;
e8347eba
BJ
1197
1198 if (!info->attrs[NL80211_ATTR_MAC])
1199 return -EINVAL;
1200
43b19952
JB
1201 if (netif_running(dev))
1202 return -EBUSY;
e8347eba 1203
43b19952
JB
1204 if (!rdev->ops->set_wds_peer)
1205 return -EOPNOTSUPP;
e8347eba 1206
43b19952
JB
1207 if (wdev->iftype != NL80211_IFTYPE_WDS)
1208 return -EOPNOTSUPP;
e8347eba
BJ
1209
1210 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1211 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1212}
1213
1214
55682965
JB
1215static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1216{
1217 struct cfg80211_registered_device *rdev;
f444de05
JB
1218 struct net_device *netdev = NULL;
1219 struct wireless_dev *wdev;
a1e567c8 1220 int result = 0, rem_txq_params = 0;
31888487 1221 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1222 u32 changed;
1223 u8 retry_short = 0, retry_long = 0;
1224 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1225 u8 coverage_class = 0;
55682965 1226
f444de05
JB
1227 /*
1228 * Try to find the wiphy and netdev. Normally this
1229 * function shouldn't need the netdev, but this is
1230 * done for backward compatibility -- previously
1231 * setting the channel was done per wiphy, but now
1232 * it is per netdev. Previous userland like hostapd
1233 * also passed a netdev to set_wiphy, so that it is
1234 * possible to let that go to the right netdev!
1235 */
4bbf4d56
JB
1236 mutex_lock(&cfg80211_mutex);
1237
f444de05
JB
1238 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1239 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1240
1241 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1242 if (netdev && netdev->ieee80211_ptr) {
1243 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1244 mutex_lock(&rdev->mtx);
1245 } else
1246 netdev = NULL;
4bbf4d56
JB
1247 }
1248
f444de05
JB
1249 if (!netdev) {
1250 rdev = __cfg80211_rdev_from_info(info);
1251 if (IS_ERR(rdev)) {
1252 mutex_unlock(&cfg80211_mutex);
4c476991 1253 return PTR_ERR(rdev);
f444de05
JB
1254 }
1255 wdev = NULL;
1256 netdev = NULL;
1257 result = 0;
1258
1259 mutex_lock(&rdev->mtx);
1260 } else if (netif_running(netdev) &&
1261 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1262 wdev = netdev->ieee80211_ptr;
1263 else
1264 wdev = NULL;
1265
1266 /*
1267 * end workaround code, by now the rdev is available
1268 * and locked, and wdev may or may not be NULL.
1269 */
4bbf4d56
JB
1270
1271 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1272 result = cfg80211_dev_rename(
1273 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1274
1275 mutex_unlock(&cfg80211_mutex);
1276
1277 if (result)
1278 goto bad_res;
31888487
JM
1279
1280 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1281 struct ieee80211_txq_params txq_params;
1282 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1283
1284 if (!rdev->ops->set_txq_params) {
1285 result = -EOPNOTSUPP;
1286 goto bad_res;
1287 }
1288
f70f01c2
EP
1289 if (!netdev) {
1290 result = -EINVAL;
1291 goto bad_res;
1292 }
1293
133a3ff2
JB
1294 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1295 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1296 result = -EINVAL;
1297 goto bad_res;
1298 }
1299
2b5f8b0b
JB
1300 if (!netif_running(netdev)) {
1301 result = -ENETDOWN;
1302 goto bad_res;
1303 }
1304
31888487
JM
1305 nla_for_each_nested(nl_txq_params,
1306 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1307 rem_txq_params) {
1308 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1309 nla_data(nl_txq_params),
1310 nla_len(nl_txq_params),
1311 txq_params_policy);
1312 result = parse_txq_params(tb, &txq_params);
1313 if (result)
1314 goto bad_res;
1315
1316 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1317 netdev,
31888487
JM
1318 &txq_params);
1319 if (result)
1320 goto bad_res;
1321 }
1322 }
55682965 1323
72bdcf34 1324 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1325 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1326 if (result)
1327 goto bad_res;
1328 }
1329
98d2ff8b
JO
1330 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1331 enum nl80211_tx_power_setting type;
1332 int idx, mbm = 0;
1333
1334 if (!rdev->ops->set_tx_power) {
60ea385f 1335 result = -EOPNOTSUPP;
98d2ff8b
JO
1336 goto bad_res;
1337 }
1338
1339 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1340 type = nla_get_u32(info->attrs[idx]);
1341
1342 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1343 (type != NL80211_TX_POWER_AUTOMATIC)) {
1344 result = -EINVAL;
1345 goto bad_res;
1346 }
1347
1348 if (type != NL80211_TX_POWER_AUTOMATIC) {
1349 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1350 mbm = nla_get_u32(info->attrs[idx]);
1351 }
1352
1353 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1354 if (result)
1355 goto bad_res;
1356 }
1357
afe0cbf8
BR
1358 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1359 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1360 u32 tx_ant, rx_ant;
7f531e03
BR
1361 if ((!rdev->wiphy.available_antennas_tx &&
1362 !rdev->wiphy.available_antennas_rx) ||
1363 !rdev->ops->set_antenna) {
afe0cbf8
BR
1364 result = -EOPNOTSUPP;
1365 goto bad_res;
1366 }
1367
1368 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1369 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1370
a7ffac95 1371 /* reject antenna configurations which don't match the
7f531e03
BR
1372 * available antenna masks, except for the "all" mask */
1373 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1374 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1375 result = -EINVAL;
1376 goto bad_res;
1377 }
1378
7f531e03
BR
1379 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1380 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1381
afe0cbf8
BR
1382 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1383 if (result)
1384 goto bad_res;
1385 }
1386
b9a5f8ca
JM
1387 changed = 0;
1388
1389 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1390 retry_short = nla_get_u8(
1391 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1392 if (retry_short == 0) {
1393 result = -EINVAL;
1394 goto bad_res;
1395 }
1396 changed |= WIPHY_PARAM_RETRY_SHORT;
1397 }
1398
1399 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1400 retry_long = nla_get_u8(
1401 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1402 if (retry_long == 0) {
1403 result = -EINVAL;
1404 goto bad_res;
1405 }
1406 changed |= WIPHY_PARAM_RETRY_LONG;
1407 }
1408
1409 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1410 frag_threshold = nla_get_u32(
1411 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1412 if (frag_threshold < 256) {
1413 result = -EINVAL;
1414 goto bad_res;
1415 }
1416 if (frag_threshold != (u32) -1) {
1417 /*
1418 * Fragments (apart from the last one) are required to
1419 * have even length. Make the fragmentation code
1420 * simpler by stripping LSB should someone try to use
1421 * odd threshold value.
1422 */
1423 frag_threshold &= ~0x1;
1424 }
1425 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1426 }
1427
1428 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1429 rts_threshold = nla_get_u32(
1430 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1431 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1432 }
1433
81077e82
LT
1434 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1435 coverage_class = nla_get_u8(
1436 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1437 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1438 }
1439
b9a5f8ca
JM
1440 if (changed) {
1441 u8 old_retry_short, old_retry_long;
1442 u32 old_frag_threshold, old_rts_threshold;
81077e82 1443 u8 old_coverage_class;
b9a5f8ca
JM
1444
1445 if (!rdev->ops->set_wiphy_params) {
1446 result = -EOPNOTSUPP;
1447 goto bad_res;
1448 }
1449
1450 old_retry_short = rdev->wiphy.retry_short;
1451 old_retry_long = rdev->wiphy.retry_long;
1452 old_frag_threshold = rdev->wiphy.frag_threshold;
1453 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1454 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1455
1456 if (changed & WIPHY_PARAM_RETRY_SHORT)
1457 rdev->wiphy.retry_short = retry_short;
1458 if (changed & WIPHY_PARAM_RETRY_LONG)
1459 rdev->wiphy.retry_long = retry_long;
1460 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1461 rdev->wiphy.frag_threshold = frag_threshold;
1462 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1463 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1464 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1465 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1466
1467 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1468 if (result) {
1469 rdev->wiphy.retry_short = old_retry_short;
1470 rdev->wiphy.retry_long = old_retry_long;
1471 rdev->wiphy.frag_threshold = old_frag_threshold;
1472 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1473 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1474 }
1475 }
72bdcf34 1476
306d6112 1477 bad_res:
4bbf4d56 1478 mutex_unlock(&rdev->mtx);
f444de05
JB
1479 if (netdev)
1480 dev_put(netdev);
55682965
JB
1481 return result;
1482}
1483
1484
1485static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1486 struct cfg80211_registered_device *rdev,
55682965
JB
1487 struct net_device *dev)
1488{
1489 void *hdr;
1490
1491 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1492 if (!hdr)
1493 return -1;
1494
1495 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1496 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1497 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1498 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1499
1500 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1501 rdev->devlist_generation ^
1502 (cfg80211_rdev_list_generation << 2));
1503
55682965
JB
1504 return genlmsg_end(msg, hdr);
1505
1506 nla_put_failure:
bc3ed28c
TG
1507 genlmsg_cancel(msg, hdr);
1508 return -EMSGSIZE;
55682965
JB
1509}
1510
1511static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1512{
1513 int wp_idx = 0;
1514 int if_idx = 0;
1515 int wp_start = cb->args[0];
1516 int if_start = cb->args[1];
f5ea9120 1517 struct cfg80211_registered_device *rdev;
55682965
JB
1518 struct wireless_dev *wdev;
1519
a1794390 1520 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1521 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1522 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1523 continue;
bba95fef
JB
1524 if (wp_idx < wp_start) {
1525 wp_idx++;
55682965 1526 continue;
bba95fef 1527 }
55682965
JB
1528 if_idx = 0;
1529
f5ea9120
JB
1530 mutex_lock(&rdev->devlist_mtx);
1531 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1532 if (if_idx < if_start) {
1533 if_idx++;
55682965 1534 continue;
bba95fef 1535 }
55682965
JB
1536 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1537 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1538 rdev, wdev->netdev) < 0) {
1539 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1540 goto out;
1541 }
1542 if_idx++;
55682965 1543 }
f5ea9120 1544 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1545
1546 wp_idx++;
55682965 1547 }
bba95fef 1548 out:
a1794390 1549 mutex_unlock(&cfg80211_mutex);
55682965
JB
1550
1551 cb->args[0] = wp_idx;
1552 cb->args[1] = if_idx;
1553
1554 return skb->len;
1555}
1556
1557static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1558{
1559 struct sk_buff *msg;
4c476991
JB
1560 struct cfg80211_registered_device *dev = info->user_ptr[0];
1561 struct net_device *netdev = info->user_ptr[1];
55682965 1562
fd2120ca 1563 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1564 if (!msg)
4c476991 1565 return -ENOMEM;
55682965 1566
d726405a 1567 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1568 dev, netdev) < 0) {
1569 nlmsg_free(msg);
1570 return -ENOBUFS;
1571 }
55682965 1572
134e6375 1573 return genlmsg_reply(msg, info);
55682965
JB
1574}
1575
66f7ac50
MW
1576static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1577 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1578 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1579 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1580 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1581 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1582};
1583
1584static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1585{
1586 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1587 int flag;
1588
1589 *mntrflags = 0;
1590
1591 if (!nla)
1592 return -EINVAL;
1593
1594 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1595 nla, mntr_flags_policy))
1596 return -EINVAL;
1597
1598 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1599 if (flags[flag])
1600 *mntrflags |= (1<<flag);
1601
1602 return 0;
1603}
1604
9bc383de 1605static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1606 struct net_device *netdev, u8 use_4addr,
1607 enum nl80211_iftype iftype)
9bc383de 1608{
ad4bb6f8 1609 if (!use_4addr) {
f350a0a8 1610 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1611 return -EBUSY;
9bc383de 1612 return 0;
ad4bb6f8 1613 }
9bc383de
JB
1614
1615 switch (iftype) {
1616 case NL80211_IFTYPE_AP_VLAN:
1617 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1618 return 0;
1619 break;
1620 case NL80211_IFTYPE_STATION:
1621 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1622 return 0;
1623 break;
1624 default:
1625 break;
1626 }
1627
1628 return -EOPNOTSUPP;
1629}
1630
55682965
JB
1631static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1632{
4c476991 1633 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1634 struct vif_params params;
e36d56b6 1635 int err;
04a773ad 1636 enum nl80211_iftype otype, ntype;
4c476991 1637 struct net_device *dev = info->user_ptr[1];
92ffe055 1638 u32 _flags, *flags = NULL;
ac7f9cfa 1639 bool change = false;
55682965 1640
2ec600d6
LCC
1641 memset(&params, 0, sizeof(params));
1642
04a773ad 1643 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1644
723b038d 1645 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1646 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1647 if (otype != ntype)
ac7f9cfa 1648 change = true;
4c476991
JB
1649 if (ntype > NL80211_IFTYPE_MAX)
1650 return -EINVAL;
723b038d
JB
1651 }
1652
92ffe055 1653 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1654 struct wireless_dev *wdev = dev->ieee80211_ptr;
1655
4c476991
JB
1656 if (ntype != NL80211_IFTYPE_MESH_POINT)
1657 return -EINVAL;
29cbe68c
JB
1658 if (netif_running(dev))
1659 return -EBUSY;
1660
1661 wdev_lock(wdev);
1662 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1663 IEEE80211_MAX_MESH_ID_LEN);
1664 wdev->mesh_id_up_len =
1665 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1666 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1667 wdev->mesh_id_up_len);
1668 wdev_unlock(wdev);
2ec600d6
LCC
1669 }
1670
8b787643
FF
1671 if (info->attrs[NL80211_ATTR_4ADDR]) {
1672 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1673 change = true;
ad4bb6f8 1674 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1675 if (err)
4c476991 1676 return err;
8b787643
FF
1677 } else {
1678 params.use_4addr = -1;
1679 }
1680
92ffe055 1681 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1682 if (ntype != NL80211_IFTYPE_MONITOR)
1683 return -EINVAL;
92ffe055
JB
1684 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1685 &_flags);
ac7f9cfa 1686 if (err)
4c476991 1687 return err;
ac7f9cfa
JB
1688
1689 flags = &_flags;
1690 change = true;
92ffe055 1691 }
3b85875a 1692
ac7f9cfa 1693 if (change)
3d54d255 1694 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1695 else
1696 err = 0;
60719ffd 1697
9bc383de
JB
1698 if (!err && params.use_4addr != -1)
1699 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1700
55682965
JB
1701 return err;
1702}
1703
1704static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1705{
4c476991 1706 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1707 struct vif_params params;
f9e10ce4 1708 struct net_device *dev;
55682965
JB
1709 int err;
1710 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1711 u32 flags;
55682965 1712
2ec600d6
LCC
1713 memset(&params, 0, sizeof(params));
1714
55682965
JB
1715 if (!info->attrs[NL80211_ATTR_IFNAME])
1716 return -EINVAL;
1717
1718 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1719 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1720 if (type > NL80211_IFTYPE_MAX)
1721 return -EINVAL;
1722 }
1723
79c97e97 1724 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1725 !(rdev->wiphy.interface_modes & (1 << type)))
1726 return -EOPNOTSUPP;
55682965 1727
9bc383de 1728 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1729 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1730 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1731 if (err)
4c476991 1732 return err;
9bc383de 1733 }
8b787643 1734
66f7ac50
MW
1735 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1736 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1737 &flags);
f9e10ce4 1738 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1739 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1740 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1741 if (IS_ERR(dev))
1742 return PTR_ERR(dev);
2ec600d6 1743
29cbe68c
JB
1744 if (type == NL80211_IFTYPE_MESH_POINT &&
1745 info->attrs[NL80211_ATTR_MESH_ID]) {
1746 struct wireless_dev *wdev = dev->ieee80211_ptr;
1747
1748 wdev_lock(wdev);
1749 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1750 IEEE80211_MAX_MESH_ID_LEN);
1751 wdev->mesh_id_up_len =
1752 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1753 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1754 wdev->mesh_id_up_len);
1755 wdev_unlock(wdev);
1756 }
1757
f9e10ce4 1758 return 0;
55682965
JB
1759}
1760
1761static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1762{
4c476991
JB
1763 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1764 struct net_device *dev = info->user_ptr[1];
55682965 1765
4c476991
JB
1766 if (!rdev->ops->del_virtual_intf)
1767 return -EOPNOTSUPP;
55682965 1768
4c476991 1769 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1770}
1771
1d9d9213
SW
1772static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
1773{
1774 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1775 struct net_device *dev = info->user_ptr[1];
1776 u16 noack_map;
1777
1778 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
1779 return -EINVAL;
1780
1781 if (!rdev->ops->set_noack_map)
1782 return -EOPNOTSUPP;
1783
1784 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
1785
1786 return rdev->ops->set_noack_map(&rdev->wiphy, dev, noack_map);
1787}
1788
41ade00f
JB
1789struct get_key_cookie {
1790 struct sk_buff *msg;
1791 int error;
b9454e83 1792 int idx;
41ade00f
JB
1793};
1794
1795static void get_key_callback(void *c, struct key_params *params)
1796{
b9454e83 1797 struct nlattr *key;
41ade00f
JB
1798 struct get_key_cookie *cookie = c;
1799
1800 if (params->key)
1801 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1802 params->key_len, params->key);
1803
1804 if (params->seq)
1805 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1806 params->seq_len, params->seq);
1807
1808 if (params->cipher)
1809 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1810 params->cipher);
1811
b9454e83
JB
1812 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1813 if (!key)
1814 goto nla_put_failure;
1815
1816 if (params->key)
1817 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1818 params->key_len, params->key);
1819
1820 if (params->seq)
1821 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1822 params->seq_len, params->seq);
1823
1824 if (params->cipher)
1825 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1826 params->cipher);
1827
1828 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1829
1830 nla_nest_end(cookie->msg, key);
1831
41ade00f
JB
1832 return;
1833 nla_put_failure:
1834 cookie->error = 1;
1835}
1836
1837static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1838{
4c476991 1839 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1840 int err;
4c476991 1841 struct net_device *dev = info->user_ptr[1];
41ade00f 1842 u8 key_idx = 0;
e31b8213
JB
1843 const u8 *mac_addr = NULL;
1844 bool pairwise;
41ade00f
JB
1845 struct get_key_cookie cookie = {
1846 .error = 0,
1847 };
1848 void *hdr;
1849 struct sk_buff *msg;
1850
1851 if (info->attrs[NL80211_ATTR_KEY_IDX])
1852 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1853
3cfcf6ac 1854 if (key_idx > 5)
41ade00f
JB
1855 return -EINVAL;
1856
1857 if (info->attrs[NL80211_ATTR_MAC])
1858 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1859
e31b8213
JB
1860 pairwise = !!mac_addr;
1861 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1862 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1863 if (kt >= NUM_NL80211_KEYTYPES)
1864 return -EINVAL;
1865 if (kt != NL80211_KEYTYPE_GROUP &&
1866 kt != NL80211_KEYTYPE_PAIRWISE)
1867 return -EINVAL;
1868 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1869 }
1870
4c476991
JB
1871 if (!rdev->ops->get_key)
1872 return -EOPNOTSUPP;
41ade00f 1873
fd2120ca 1874 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1875 if (!msg)
1876 return -ENOMEM;
41ade00f
JB
1877
1878 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1879 NL80211_CMD_NEW_KEY);
4c476991
JB
1880 if (IS_ERR(hdr))
1881 return PTR_ERR(hdr);
41ade00f
JB
1882
1883 cookie.msg = msg;
b9454e83 1884 cookie.idx = key_idx;
41ade00f
JB
1885
1886 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1887 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1888 if (mac_addr)
1889 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1890
e31b8213
JB
1891 if (pairwise && mac_addr &&
1892 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1893 return -ENOENT;
1894
1895 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1896 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1897
1898 if (err)
6c95e2a2 1899 goto free_msg;
41ade00f
JB
1900
1901 if (cookie.error)
1902 goto nla_put_failure;
1903
1904 genlmsg_end(msg, hdr);
4c476991 1905 return genlmsg_reply(msg, info);
41ade00f
JB
1906
1907 nla_put_failure:
1908 err = -ENOBUFS;
6c95e2a2 1909 free_msg:
41ade00f 1910 nlmsg_free(msg);
41ade00f
JB
1911 return err;
1912}
1913
1914static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1915{
4c476991 1916 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1917 struct key_parse key;
41ade00f 1918 int err;
4c476991 1919 struct net_device *dev = info->user_ptr[1];
41ade00f 1920
b9454e83
JB
1921 err = nl80211_parse_key(info, &key);
1922 if (err)
1923 return err;
41ade00f 1924
b9454e83 1925 if (key.idx < 0)
41ade00f
JB
1926 return -EINVAL;
1927
b9454e83
JB
1928 /* only support setting default key */
1929 if (!key.def && !key.defmgmt)
41ade00f
JB
1930 return -EINVAL;
1931
dbd2fd65 1932 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1933
dbd2fd65
JB
1934 if (key.def) {
1935 if (!rdev->ops->set_default_key) {
1936 err = -EOPNOTSUPP;
1937 goto out;
1938 }
41ade00f 1939
dbd2fd65
JB
1940 err = nl80211_key_allowed(dev->ieee80211_ptr);
1941 if (err)
1942 goto out;
1943
dbd2fd65
JB
1944 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1945 key.def_uni, key.def_multi);
1946
1947 if (err)
1948 goto out;
fffd0934 1949
3d23e349 1950#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1951 dev->ieee80211_ptr->wext.default_key = key.idx;
1952#endif
1953 } else {
1954 if (key.def_uni || !key.def_multi) {
1955 err = -EINVAL;
1956 goto out;
1957 }
1958
1959 if (!rdev->ops->set_default_mgmt_key) {
1960 err = -EOPNOTSUPP;
1961 goto out;
1962 }
1963
1964 err = nl80211_key_allowed(dev->ieee80211_ptr);
1965 if (err)
1966 goto out;
1967
1968 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1969 dev, key.idx);
1970 if (err)
1971 goto out;
1972
1973#ifdef CONFIG_CFG80211_WEXT
1974 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1975#endif
dbd2fd65
JB
1976 }
1977
1978 out:
fffd0934 1979 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1980
41ade00f
JB
1981 return err;
1982}
1983
1984static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1985{
4c476991 1986 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1987 int err;
4c476991 1988 struct net_device *dev = info->user_ptr[1];
b9454e83 1989 struct key_parse key;
e31b8213 1990 const u8 *mac_addr = NULL;
41ade00f 1991
b9454e83
JB
1992 err = nl80211_parse_key(info, &key);
1993 if (err)
1994 return err;
41ade00f 1995
b9454e83 1996 if (!key.p.key)
41ade00f
JB
1997 return -EINVAL;
1998
41ade00f
JB
1999 if (info->attrs[NL80211_ATTR_MAC])
2000 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2001
e31b8213
JB
2002 if (key.type == -1) {
2003 if (mac_addr)
2004 key.type = NL80211_KEYTYPE_PAIRWISE;
2005 else
2006 key.type = NL80211_KEYTYPE_GROUP;
2007 }
2008
2009 /* for now */
2010 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2011 key.type != NL80211_KEYTYPE_GROUP)
2012 return -EINVAL;
2013
4c476991
JB
2014 if (!rdev->ops->add_key)
2015 return -EOPNOTSUPP;
25e47c18 2016
e31b8213
JB
2017 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2018 key.type == NL80211_KEYTYPE_PAIRWISE,
2019 mac_addr))
4c476991 2020 return -EINVAL;
41ade00f 2021
fffd0934
JB
2022 wdev_lock(dev->ieee80211_ptr);
2023 err = nl80211_key_allowed(dev->ieee80211_ptr);
2024 if (!err)
2025 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 2026 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
2027 mac_addr, &key.p);
2028 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2029
41ade00f
JB
2030 return err;
2031}
2032
2033static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2034{
4c476991 2035 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2036 int err;
4c476991 2037 struct net_device *dev = info->user_ptr[1];
41ade00f 2038 u8 *mac_addr = NULL;
b9454e83 2039 struct key_parse key;
41ade00f 2040
b9454e83
JB
2041 err = nl80211_parse_key(info, &key);
2042 if (err)
2043 return err;
41ade00f
JB
2044
2045 if (info->attrs[NL80211_ATTR_MAC])
2046 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2047
e31b8213
JB
2048 if (key.type == -1) {
2049 if (mac_addr)
2050 key.type = NL80211_KEYTYPE_PAIRWISE;
2051 else
2052 key.type = NL80211_KEYTYPE_GROUP;
2053 }
2054
2055 /* for now */
2056 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2057 key.type != NL80211_KEYTYPE_GROUP)
2058 return -EINVAL;
2059
4c476991
JB
2060 if (!rdev->ops->del_key)
2061 return -EOPNOTSUPP;
41ade00f 2062
fffd0934
JB
2063 wdev_lock(dev->ieee80211_ptr);
2064 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2065
2066 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2067 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2068 err = -ENOENT;
2069
fffd0934 2070 if (!err)
e31b8213
JB
2071 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2072 key.type == NL80211_KEYTYPE_PAIRWISE,
2073 mac_addr);
41ade00f 2074
3d23e349 2075#ifdef CONFIG_CFG80211_WEXT
08645126 2076 if (!err) {
b9454e83 2077 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2078 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2079 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2080 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2081 }
2082#endif
fffd0934 2083 wdev_unlock(dev->ieee80211_ptr);
08645126 2084
41ade00f
JB
2085 return err;
2086}
2087
8860020e
JB
2088static int nl80211_parse_beacon(struct genl_info *info,
2089 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2090{
8860020e 2091 bool haveinfo = false;
ed1b6cc7 2092
9946ecfb
JM
2093 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2094 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2095 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2096 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2097 return -EINVAL;
2098
8860020e 2099 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2100
ed1b6cc7 2101 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2102 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2103 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2104 if (!bcn->head_len)
2105 return -EINVAL;
2106 haveinfo = true;
ed1b6cc7
JB
2107 }
2108
2109 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2110 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2111 bcn->tail_len =
ed1b6cc7 2112 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2113 haveinfo = true;
ed1b6cc7
JB
2114 }
2115
4c476991
JB
2116 if (!haveinfo)
2117 return -EINVAL;
3b85875a 2118
9946ecfb 2119 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2120 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2121 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2122 }
2123
2124 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2125 bcn->proberesp_ies =
9946ecfb 2126 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2127 bcn->proberesp_ies_len =
9946ecfb
JM
2128 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2129 }
2130
2131 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2132 bcn->assocresp_ies =
9946ecfb 2133 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2134 bcn->assocresp_ies_len =
9946ecfb
JM
2135 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2136 }
2137
00f740e1 2138 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2139 bcn->probe_resp =
00f740e1 2140 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2141 bcn->probe_resp_len =
00f740e1
AN
2142 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2143 }
2144
8860020e
JB
2145 return 0;
2146}
2147
2148static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2149{
2150 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2151 struct net_device *dev = info->user_ptr[1];
2152 struct wireless_dev *wdev = dev->ieee80211_ptr;
2153 struct cfg80211_ap_settings params;
2154 int err;
2155
2156 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2157 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2158 return -EOPNOTSUPP;
2159
2160 if (!rdev->ops->start_ap)
2161 return -EOPNOTSUPP;
2162
2163 if (wdev->beacon_interval)
2164 return -EALREADY;
2165
2166 memset(&params, 0, sizeof(params));
2167
2168 /* these are required for START_AP */
2169 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2170 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2171 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2172 return -EINVAL;
2173
2174 err = nl80211_parse_beacon(info, &params.beacon);
2175 if (err)
2176 return err;
2177
2178 params.beacon_interval =
2179 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2180 params.dtim_period =
2181 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2182
2183 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2184 if (err)
2185 return err;
2186
2187 /*
2188 * In theory, some of these attributes should be required here
2189 * but since they were not used when the command was originally
2190 * added, keep them optional for old user space programs to let
2191 * them continue to work with drivers that do not need the
2192 * additional information -- drivers must check!
2193 */
2194 if (info->attrs[NL80211_ATTR_SSID]) {
2195 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2196 params.ssid_len =
2197 nla_len(info->attrs[NL80211_ATTR_SSID]);
2198 if (params.ssid_len == 0 ||
2199 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2200 return -EINVAL;
2201 }
2202
2203 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2204 params.hidden_ssid = nla_get_u32(
2205 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2206 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2207 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2208 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2209 return -EINVAL;
2210 }
2211
2212 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2213
2214 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2215 params.auth_type = nla_get_u32(
2216 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2217 if (!nl80211_valid_auth_type(params.auth_type))
2218 return -EINVAL;
2219 } else
2220 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2221
2222 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2223 NL80211_MAX_NR_CIPHER_SUITES);
2224 if (err)
2225 return err;
2226
1b658f11
VT
2227 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2228 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2229 return -EOPNOTSUPP;
2230 params.inactivity_timeout = nla_get_u16(
2231 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2232 }
2233
8860020e
JB
2234 err = rdev->ops->start_ap(&rdev->wiphy, dev, &params);
2235 if (!err)
2236 wdev->beacon_interval = params.beacon_interval;
56d1893d 2237 return err;
ed1b6cc7
JB
2238}
2239
8860020e
JB
2240static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2241{
2242 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2243 struct net_device *dev = info->user_ptr[1];
2244 struct wireless_dev *wdev = dev->ieee80211_ptr;
2245 struct cfg80211_beacon_data params;
2246 int err;
2247
2248 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2249 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2250 return -EOPNOTSUPP;
2251
2252 if (!rdev->ops->change_beacon)
2253 return -EOPNOTSUPP;
2254
2255 if (!wdev->beacon_interval)
2256 return -EINVAL;
2257
2258 err = nl80211_parse_beacon(info, &params);
2259 if (err)
2260 return err;
2261
2262 return rdev->ops->change_beacon(&rdev->wiphy, dev, &params);
2263}
2264
2265static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2266{
4c476991
JB
2267 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2268 struct net_device *dev = info->user_ptr[1];
56d1893d
JB
2269 struct wireless_dev *wdev = dev->ieee80211_ptr;
2270 int err;
ed1b6cc7 2271
8860020e 2272 if (!rdev->ops->stop_ap)
4c476991 2273 return -EOPNOTSUPP;
ed1b6cc7 2274
074ac8df 2275 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2276 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2277 return -EOPNOTSUPP;
3b85875a 2278
8860020e
JB
2279 if (!wdev->beacon_interval)
2280 return -ENOENT;
2281
2282 err = rdev->ops->stop_ap(&rdev->wiphy, dev);
56d1893d
JB
2283 if (!err)
2284 wdev->beacon_interval = 0;
2285 return err;
ed1b6cc7
JB
2286}
2287
5727ef1b
JB
2288static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2289 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2290 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2291 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2292 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2293 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2294 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2295};
2296
eccb8e8f 2297static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2298 enum nl80211_iftype iftype,
eccb8e8f 2299 struct station_parameters *params)
5727ef1b
JB
2300{
2301 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2302 struct nlattr *nla;
5727ef1b
JB
2303 int flag;
2304
eccb8e8f
JB
2305 /*
2306 * Try parsing the new attribute first so userspace
2307 * can specify both for older kernels.
2308 */
2309 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2310 if (nla) {
2311 struct nl80211_sta_flag_update *sta_flags;
2312
2313 sta_flags = nla_data(nla);
2314 params->sta_flags_mask = sta_flags->mask;
2315 params->sta_flags_set = sta_flags->set;
2316 if ((params->sta_flags_mask |
2317 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2318 return -EINVAL;
2319 return 0;
2320 }
2321
2322 /* if present, parse the old attribute */
5727ef1b 2323
eccb8e8f 2324 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2325 if (!nla)
2326 return 0;
2327
2328 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2329 nla, sta_flags_policy))
2330 return -EINVAL;
2331
bdd3ae3d
JB
2332 /*
2333 * Only allow certain flags for interface types so that
2334 * other attributes are silently ignored. Remember that
2335 * this is backward compatibility code with old userspace
2336 * and shouldn't be hit in other cases anyway.
2337 */
2338 switch (iftype) {
2339 case NL80211_IFTYPE_AP:
2340 case NL80211_IFTYPE_AP_VLAN:
2341 case NL80211_IFTYPE_P2P_GO:
2342 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2343 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2344 BIT(NL80211_STA_FLAG_WME) |
2345 BIT(NL80211_STA_FLAG_MFP);
2346 break;
2347 case NL80211_IFTYPE_P2P_CLIENT:
2348 case NL80211_IFTYPE_STATION:
2349 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2350 BIT(NL80211_STA_FLAG_TDLS_PEER);
2351 break;
2352 case NL80211_IFTYPE_MESH_POINT:
2353 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2354 BIT(NL80211_STA_FLAG_MFP) |
2355 BIT(NL80211_STA_FLAG_AUTHORIZED);
2356 default:
2357 return -EINVAL;
2358 }
5727ef1b
JB
2359
2360 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2361 if (flags[flag])
eccb8e8f 2362 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2363
2364 return 0;
2365}
2366
c8dcfd8a
FF
2367static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2368 int attr)
2369{
2370 struct nlattr *rate;
2371 u16 bitrate;
2372
2373 rate = nla_nest_start(msg, attr);
2374 if (!rate)
2375 goto nla_put_failure;
2376
2377 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2378 bitrate = cfg80211_calculate_bitrate(info);
2379 if (bitrate > 0)
2380 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2381
2382 if (info->flags & RATE_INFO_FLAGS_MCS)
2383 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2384 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2385 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2386 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2387 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2388
2389 nla_nest_end(msg, rate);
2390 return true;
2391
2392nla_put_failure:
2393 return false;
2394}
2395
fd5b74dc 2396static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
66266b3a
JL
2397 int flags,
2398 struct cfg80211_registered_device *rdev,
2399 struct net_device *dev,
98b62183 2400 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2401{
2402 void *hdr;
f4263c98 2403 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2404
2405 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2406 if (!hdr)
2407 return -1;
2408
2409 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2410 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2411
f5ea9120
JB
2412 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2413
2ec600d6
LCC
2414 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2415 if (!sinfoattr)
fd5b74dc 2416 goto nla_put_failure;
ebe27c91
MSS
2417 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2418 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2419 sinfo->connected_time);
2ec600d6
LCC
2420 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2421 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2422 sinfo->inactive_time);
2423 if (sinfo->filled & STATION_INFO_RX_BYTES)
2424 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2425 sinfo->rx_bytes);
2426 if (sinfo->filled & STATION_INFO_TX_BYTES)
2427 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2428 sinfo->tx_bytes);
2429 if (sinfo->filled & STATION_INFO_LLID)
2430 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2431 sinfo->llid);
2432 if (sinfo->filled & STATION_INFO_PLID)
2433 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2434 sinfo->plid);
2435 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2436 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2437 sinfo->plink_state);
66266b3a
JL
2438 switch (rdev->wiphy.signal_type) {
2439 case CFG80211_SIGNAL_TYPE_MBM:
2440 if (sinfo->filled & STATION_INFO_SIGNAL)
2441 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2442 sinfo->signal);
2443 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2444 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2445 sinfo->signal_avg);
2446 break;
2447 default:
2448 break;
2449 }
420e7fab 2450 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2451 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2452 NL80211_STA_INFO_TX_BITRATE))
2453 goto nla_put_failure;
2454 }
2455 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2456 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2457 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2458 goto nla_put_failure;
420e7fab 2459 }
98c8a60a
JM
2460 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2461 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2462 sinfo->rx_packets);
2463 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2464 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2465 sinfo->tx_packets);
b206b4ef
BR
2466 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2467 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2468 sinfo->tx_retries);
2469 if (sinfo->filled & STATION_INFO_TX_FAILED)
2470 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2471 sinfo->tx_failed);
a85e1d55
PS
2472 if (sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT)
2473 NLA_PUT_U32(msg, NL80211_STA_INFO_BEACON_LOSS,
2474 sinfo->beacon_loss_count);
f4263c98
PS
2475 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2476 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2477 if (!bss_param)
2478 goto nla_put_failure;
2479
2480 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2481 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2482 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2483 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2484 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2485 NLA_PUT_FLAG(msg,
2486 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2487 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2488 sinfo->bss_param.dtim_period);
2489 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2490 sinfo->bss_param.beacon_interval);
2491
2492 nla_nest_end(msg, bss_param);
2493 }
bb6e753e
HS
2494 if (sinfo->filled & STATION_INFO_STA_FLAGS)
2495 NLA_PUT(msg, NL80211_STA_INFO_STA_FLAGS,
2496 sizeof(struct nl80211_sta_flag_update),
2497 &sinfo->sta_flags);
d299a1f2
JC
2498 if (sinfo->filled & STATION_INFO_T_OFFSET)
2499 NLA_PUT_U64(msg, NL80211_STA_INFO_T_OFFSET,
2500 sinfo->t_offset);
2ec600d6 2501 nla_nest_end(msg, sinfoattr);
fd5b74dc 2502
040bdf71 2503 if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
50d3dfb7
JM
2504 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2505 sinfo->assoc_req_ies);
2506
fd5b74dc
JB
2507 return genlmsg_end(msg, hdr);
2508
2509 nla_put_failure:
bc3ed28c
TG
2510 genlmsg_cancel(msg, hdr);
2511 return -EMSGSIZE;
fd5b74dc
JB
2512}
2513
2ec600d6 2514static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2515 struct netlink_callback *cb)
2ec600d6 2516{
2ec600d6
LCC
2517 struct station_info sinfo;
2518 struct cfg80211_registered_device *dev;
bba95fef 2519 struct net_device *netdev;
2ec600d6 2520 u8 mac_addr[ETH_ALEN];
bba95fef 2521 int sta_idx = cb->args[1];
2ec600d6 2522 int err;
2ec600d6 2523
67748893
JB
2524 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2525 if (err)
2526 return err;
bba95fef
JB
2527
2528 if (!dev->ops->dump_station) {
eec60b03 2529 err = -EOPNOTSUPP;
bba95fef
JB
2530 goto out_err;
2531 }
2532
bba95fef 2533 while (1) {
f612cedf 2534 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2535 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2536 mac_addr, &sinfo);
2537 if (err == -ENOENT)
2538 break;
2539 if (err)
3b85875a 2540 goto out_err;
bba95fef
JB
2541
2542 if (nl80211_send_station(skb,
2543 NETLINK_CB(cb->skb).pid,
2544 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 2545 dev, netdev, mac_addr,
bba95fef
JB
2546 &sinfo) < 0)
2547 goto out;
2548
2549 sta_idx++;
2550 }
2551
2552
2553 out:
2554 cb->args[1] = sta_idx;
2555 err = skb->len;
bba95fef 2556 out_err:
67748893 2557 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2558
2559 return err;
2ec600d6 2560}
fd5b74dc 2561
5727ef1b
JB
2562static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2563{
4c476991
JB
2564 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2565 struct net_device *dev = info->user_ptr[1];
2ec600d6 2566 struct station_info sinfo;
fd5b74dc
JB
2567 struct sk_buff *msg;
2568 u8 *mac_addr = NULL;
4c476991 2569 int err;
fd5b74dc 2570
2ec600d6 2571 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2572
2573 if (!info->attrs[NL80211_ATTR_MAC])
2574 return -EINVAL;
2575
2576 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2577
4c476991
JB
2578 if (!rdev->ops->get_station)
2579 return -EOPNOTSUPP;
3b85875a 2580
4c476991 2581 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2582 if (err)
4c476991 2583 return err;
2ec600d6 2584
fd2120ca 2585 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2586 if (!msg)
4c476991 2587 return -ENOMEM;
fd5b74dc
JB
2588
2589 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
66266b3a 2590 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
2591 nlmsg_free(msg);
2592 return -ENOBUFS;
2593 }
3b85875a 2594
4c476991 2595 return genlmsg_reply(msg, info);
5727ef1b
JB
2596}
2597
2598/*
c258d2de 2599 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2600 */
80b99899
JB
2601static struct net_device *get_vlan(struct genl_info *info,
2602 struct cfg80211_registered_device *rdev)
5727ef1b 2603{
463d0183 2604 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
2605 struct net_device *v;
2606 int ret;
2607
2608 if (!vlanattr)
2609 return NULL;
2610
2611 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
2612 if (!v)
2613 return ERR_PTR(-ENODEV);
2614
2615 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
2616 ret = -EINVAL;
2617 goto error;
5727ef1b 2618 }
80b99899
JB
2619
2620 if (!netif_running(v)) {
2621 ret = -ENETDOWN;
2622 goto error;
2623 }
2624
2625 return v;
2626 error:
2627 dev_put(v);
2628 return ERR_PTR(ret);
5727ef1b
JB
2629}
2630
2631static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2632{
4c476991 2633 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2634 int err;
4c476991 2635 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2636 struct station_parameters params;
2637 u8 *mac_addr = NULL;
2638
2639 memset(&params, 0, sizeof(params));
2640
2641 params.listen_interval = -1;
57cf8043 2642 params.plink_state = -1;
5727ef1b
JB
2643
2644 if (info->attrs[NL80211_ATTR_STA_AID])
2645 return -EINVAL;
2646
2647 if (!info->attrs[NL80211_ATTR_MAC])
2648 return -EINVAL;
2649
2650 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2651
2652 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2653 params.supported_rates =
2654 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2655 params.supported_rates_len =
2656 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2657 }
2658
2659 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2660 params.listen_interval =
2661 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2662
36aedc90
JM
2663 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2664 params.ht_capa =
2665 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2666
bdd90d5e
JB
2667 if (!rdev->ops->change_station)
2668 return -EOPNOTSUPP;
2669
bdd3ae3d 2670 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2671 return -EINVAL;
2672
2ec600d6
LCC
2673 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2674 params.plink_action =
2675 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2676
9c3990aa
JC
2677 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2678 params.plink_state =
2679 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2680
a97f4424
JB
2681 switch (dev->ieee80211_ptr->iftype) {
2682 case NL80211_IFTYPE_AP:
2683 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2684 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2685 /* disallow mesh-specific things */
2686 if (params.plink_action)
bdd90d5e
JB
2687 return -EINVAL;
2688
2689 /* TDLS can't be set, ... */
2690 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2691 return -EINVAL;
2692 /*
2693 * ... but don't bother the driver with it. This works around
2694 * a hostapd/wpa_supplicant issue -- it always includes the
2695 * TLDS_PEER flag in the mask even for AP mode.
2696 */
2697 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2698
2699 /* accept only the listed bits */
2700 if (params.sta_flags_mask &
2701 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2702 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2703 BIT(NL80211_STA_FLAG_WME) |
2704 BIT(NL80211_STA_FLAG_MFP)))
2705 return -EINVAL;
2706
2707 /* must be last in here for error handling */
2708 params.vlan = get_vlan(info, rdev);
2709 if (IS_ERR(params.vlan))
2710 return PTR_ERR(params.vlan);
a97f4424 2711 break;
074ac8df 2712 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 2713 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
2714 /*
2715 * Don't allow userspace to change the TDLS_PEER flag,
2716 * but silently ignore attempts to change it since we
2717 * don't have state here to verify that it doesn't try
2718 * to change the flag.
2719 */
2720 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
2721 /* fall through */
2722 case NL80211_IFTYPE_ADHOC:
2723 /* disallow things sta doesn't support */
2724 if (params.plink_action)
2725 return -EINVAL;
2726 if (params.ht_capa)
2727 return -EINVAL;
2728 if (params.listen_interval >= 0)
2729 return -EINVAL;
bdd90d5e
JB
2730 /* reject any changes other than AUTHORIZED */
2731 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2732 return -EINVAL;
a97f4424
JB
2733 break;
2734 case NL80211_IFTYPE_MESH_POINT:
2735 /* disallow things mesh doesn't support */
2736 if (params.vlan)
bdd90d5e 2737 return -EINVAL;
a97f4424 2738 if (params.ht_capa)
bdd90d5e 2739 return -EINVAL;
a97f4424 2740 if (params.listen_interval >= 0)
bdd90d5e
JB
2741 return -EINVAL;
2742 /*
2743 * No special handling for TDLS here -- the userspace
2744 * mesh code doesn't have this bug.
2745 */
b39c48fa
JC
2746 if (params.sta_flags_mask &
2747 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2748 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2749 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 2750 return -EINVAL;
a97f4424
JB
2751 break;
2752 default:
bdd90d5e 2753 return -EOPNOTSUPP;
034d655e
JB
2754 }
2755
bdd90d5e 2756 /* be aware of params.vlan when changing code here */
5727ef1b 2757
79c97e97 2758 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 2759
5727ef1b
JB
2760 if (params.vlan)
2761 dev_put(params.vlan);
3b85875a 2762
5727ef1b
JB
2763 return err;
2764}
2765
c75786c9
EP
2766static struct nla_policy
2767nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2768 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2769 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2770};
2771
5727ef1b
JB
2772static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2773{
4c476991 2774 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2775 int err;
4c476991 2776 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2777 struct station_parameters params;
2778 u8 *mac_addr = NULL;
2779
2780 memset(&params, 0, sizeof(params));
2781
2782 if (!info->attrs[NL80211_ATTR_MAC])
2783 return -EINVAL;
2784
5727ef1b
JB
2785 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2786 return -EINVAL;
2787
2788 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2789 return -EINVAL;
2790
0e956c13
TLSC
2791 if (!info->attrs[NL80211_ATTR_STA_AID])
2792 return -EINVAL;
2793
5727ef1b
JB
2794 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2795 params.supported_rates =
2796 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2797 params.supported_rates_len =
2798 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2799 params.listen_interval =
2800 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2801
0e956c13
TLSC
2802 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2803 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2804 return -EINVAL;
51b50fbe 2805
36aedc90
JM
2806 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2807 params.ht_capa =
2808 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2809
96b78dff
JC
2810 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2811 params.plink_action =
2812 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2813
bdd90d5e
JB
2814 if (!rdev->ops->add_station)
2815 return -EOPNOTSUPP;
2816
bdd3ae3d 2817 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2818 return -EINVAL;
2819
bdd90d5e
JB
2820 switch (dev->ieee80211_ptr->iftype) {
2821 case NL80211_IFTYPE_AP:
2822 case NL80211_IFTYPE_AP_VLAN:
2823 case NL80211_IFTYPE_P2P_GO:
2824 /* parse WME attributes if sta is WME capable */
2825 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2826 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
2827 info->attrs[NL80211_ATTR_STA_WME]) {
2828 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2829 struct nlattr *nla;
2830
2831 nla = info->attrs[NL80211_ATTR_STA_WME];
2832 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2833 nl80211_sta_wme_policy);
2834 if (err)
2835 return err;
2836
2837 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2838 params.uapsd_queues =
2839 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
2840 if (params.uapsd_queues &
2841 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2842 return -EINVAL;
c75786c9 2843
bdd90d5e
JB
2844 if (tb[NL80211_STA_WME_MAX_SP])
2845 params.max_sp =
2846 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 2847
bdd90d5e
JB
2848 if (params.max_sp &
2849 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2850 return -EINVAL;
4319e193 2851
bdd90d5e
JB
2852 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
2853 }
2854 /* TDLS peers cannot be added */
2855 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 2856 return -EINVAL;
bdd90d5e
JB
2857 /* but don't bother the driver with it */
2858 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 2859
bdd90d5e
JB
2860 /* must be last in here for error handling */
2861 params.vlan = get_vlan(info, rdev);
2862 if (IS_ERR(params.vlan))
2863 return PTR_ERR(params.vlan);
2864 break;
2865 case NL80211_IFTYPE_MESH_POINT:
2866 /* TDLS peers cannot be added */
2867 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2868 return -EINVAL;
2869 break;
2870 case NL80211_IFTYPE_STATION:
2871 /* Only TDLS peers can be added */
2872 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
2873 return -EINVAL;
2874 /* Can only add if TDLS ... */
2875 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
2876 return -EOPNOTSUPP;
2877 /* ... with external setup is supported */
2878 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
2879 return -EOPNOTSUPP;
2880 break;
2881 default:
2882 return -EOPNOTSUPP;
c75786c9
EP
2883 }
2884
bdd90d5e 2885 /* be aware of params.vlan when changing code here */
5727ef1b 2886
79c97e97 2887 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 2888
5727ef1b
JB
2889 if (params.vlan)
2890 dev_put(params.vlan);
5727ef1b
JB
2891 return err;
2892}
2893
2894static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2895{
4c476991
JB
2896 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2897 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2898 u8 *mac_addr = NULL;
2899
2900 if (info->attrs[NL80211_ATTR_MAC])
2901 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2902
e80cf853 2903 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2904 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2905 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2906 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2907 return -EINVAL;
5727ef1b 2908
4c476991
JB
2909 if (!rdev->ops->del_station)
2910 return -EOPNOTSUPP;
3b85875a 2911
4c476991 2912 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2913}
2914
2ec600d6
LCC
2915static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2916 int flags, struct net_device *dev,
2917 u8 *dst, u8 *next_hop,
2918 struct mpath_info *pinfo)
2919{
2920 void *hdr;
2921 struct nlattr *pinfoattr;
2922
2923 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2924 if (!hdr)
2925 return -1;
2926
2927 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2928 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2929 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2930
f5ea9120
JB
2931 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2932
2ec600d6
LCC
2933 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2934 if (!pinfoattr)
2935 goto nla_put_failure;
2936 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2937 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2938 pinfo->frame_qlen);
d19b3bf6
RP
2939 if (pinfo->filled & MPATH_INFO_SN)
2940 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2941 pinfo->sn);
2ec600d6
LCC
2942 if (pinfo->filled & MPATH_INFO_METRIC)
2943 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2944 pinfo->metric);
2945 if (pinfo->filled & MPATH_INFO_EXPTIME)
2946 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2947 pinfo->exptime);
2948 if (pinfo->filled & MPATH_INFO_FLAGS)
2949 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2950 pinfo->flags);
2951 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2952 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2953 pinfo->discovery_timeout);
2954 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2955 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2956 pinfo->discovery_retries);
2957
2958 nla_nest_end(msg, pinfoattr);
2959
2960 return genlmsg_end(msg, hdr);
2961
2962 nla_put_failure:
bc3ed28c
TG
2963 genlmsg_cancel(msg, hdr);
2964 return -EMSGSIZE;
2ec600d6
LCC
2965}
2966
2967static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2968 struct netlink_callback *cb)
2ec600d6 2969{
2ec600d6
LCC
2970 struct mpath_info pinfo;
2971 struct cfg80211_registered_device *dev;
bba95fef 2972 struct net_device *netdev;
2ec600d6
LCC
2973 u8 dst[ETH_ALEN];
2974 u8 next_hop[ETH_ALEN];
bba95fef 2975 int path_idx = cb->args[1];
2ec600d6 2976 int err;
2ec600d6 2977
67748893
JB
2978 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2979 if (err)
2980 return err;
bba95fef
JB
2981
2982 if (!dev->ops->dump_mpath) {
eec60b03 2983 err = -EOPNOTSUPP;
bba95fef
JB
2984 goto out_err;
2985 }
2986
eec60b03
JM
2987 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2988 err = -EOPNOTSUPP;
0448b5fc 2989 goto out_err;
eec60b03
JM
2990 }
2991
bba95fef
JB
2992 while (1) {
2993 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2994 dst, next_hop, &pinfo);
2995 if (err == -ENOENT)
2ec600d6 2996 break;
bba95fef 2997 if (err)
3b85875a 2998 goto out_err;
2ec600d6 2999
bba95fef
JB
3000 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
3001 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3002 netdev, dst, next_hop,
3003 &pinfo) < 0)
3004 goto out;
2ec600d6 3005
bba95fef 3006 path_idx++;
2ec600d6 3007 }
2ec600d6 3008
2ec600d6 3009
bba95fef
JB
3010 out:
3011 cb->args[1] = path_idx;
3012 err = skb->len;
bba95fef 3013 out_err:
67748893 3014 nl80211_finish_netdev_dump(dev);
bba95fef 3015 return err;
2ec600d6
LCC
3016}
3017
3018static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3019{
4c476991 3020 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3021 int err;
4c476991 3022 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3023 struct mpath_info pinfo;
3024 struct sk_buff *msg;
3025 u8 *dst = NULL;
3026 u8 next_hop[ETH_ALEN];
3027
3028 memset(&pinfo, 0, sizeof(pinfo));
3029
3030 if (!info->attrs[NL80211_ATTR_MAC])
3031 return -EINVAL;
3032
3033 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3034
4c476991
JB
3035 if (!rdev->ops->get_mpath)
3036 return -EOPNOTSUPP;
2ec600d6 3037
4c476991
JB
3038 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3039 return -EOPNOTSUPP;
eec60b03 3040
79c97e97 3041 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 3042 if (err)
4c476991 3043 return err;
2ec600d6 3044
fd2120ca 3045 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3046 if (!msg)
4c476991 3047 return -ENOMEM;
2ec600d6
LCC
3048
3049 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
3050 dev, dst, next_hop, &pinfo) < 0) {
3051 nlmsg_free(msg);
3052 return -ENOBUFS;
3053 }
3b85875a 3054
4c476991 3055 return genlmsg_reply(msg, info);
2ec600d6
LCC
3056}
3057
3058static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3059{
4c476991
JB
3060 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3061 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3062 u8 *dst = NULL;
3063 u8 *next_hop = NULL;
3064
3065 if (!info->attrs[NL80211_ATTR_MAC])
3066 return -EINVAL;
3067
3068 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3069 return -EINVAL;
3070
3071 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3072 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3073
4c476991
JB
3074 if (!rdev->ops->change_mpath)
3075 return -EOPNOTSUPP;
35a8efe1 3076
4c476991
JB
3077 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3078 return -EOPNOTSUPP;
2ec600d6 3079
4c476991 3080 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 3081}
4c476991 3082
2ec600d6
LCC
3083static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3084{
4c476991
JB
3085 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3086 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3087 u8 *dst = NULL;
3088 u8 *next_hop = NULL;
3089
3090 if (!info->attrs[NL80211_ATTR_MAC])
3091 return -EINVAL;
3092
3093 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3094 return -EINVAL;
3095
3096 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3097 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3098
4c476991
JB
3099 if (!rdev->ops->add_mpath)
3100 return -EOPNOTSUPP;
35a8efe1 3101
4c476991
JB
3102 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3103 return -EOPNOTSUPP;
2ec600d6 3104
4c476991 3105 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
3106}
3107
3108static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3109{
4c476991
JB
3110 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3111 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3112 u8 *dst = NULL;
3113
3114 if (info->attrs[NL80211_ATTR_MAC])
3115 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3116
4c476991
JB
3117 if (!rdev->ops->del_mpath)
3118 return -EOPNOTSUPP;
3b85875a 3119
4c476991 3120 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
3121}
3122
9f1ba906
JM
3123static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3124{
4c476991
JB
3125 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3126 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3127 struct bss_parameters params;
3128
3129 memset(&params, 0, sizeof(params));
3130 /* default to not changing parameters */
3131 params.use_cts_prot = -1;
3132 params.use_short_preamble = -1;
3133 params.use_short_slot_time = -1;
fd8aaaf3 3134 params.ap_isolate = -1;
50b12f59 3135 params.ht_opmode = -1;
9f1ba906
JM
3136
3137 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3138 params.use_cts_prot =
3139 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3140 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3141 params.use_short_preamble =
3142 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3143 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3144 params.use_short_slot_time =
3145 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3146 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3147 params.basic_rates =
3148 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3149 params.basic_rates_len =
3150 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3151 }
fd8aaaf3
FF
3152 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3153 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3154 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3155 params.ht_opmode =
3156 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3157
4c476991
JB
3158 if (!rdev->ops->change_bss)
3159 return -EOPNOTSUPP;
9f1ba906 3160
074ac8df 3161 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3162 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3163 return -EOPNOTSUPP;
3b85875a 3164
4c476991 3165 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
3166}
3167
b54452b0 3168static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3169 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3170 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3171 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3172 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3173 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3174 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3175};
3176
3177static int parse_reg_rule(struct nlattr *tb[],
3178 struct ieee80211_reg_rule *reg_rule)
3179{
3180 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3181 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3182
3183 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3184 return -EINVAL;
3185 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3186 return -EINVAL;
3187 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3188 return -EINVAL;
3189 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3190 return -EINVAL;
3191 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3192 return -EINVAL;
3193
3194 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3195
3196 freq_range->start_freq_khz =
3197 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3198 freq_range->end_freq_khz =
3199 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3200 freq_range->max_bandwidth_khz =
3201 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3202
3203 power_rule->max_eirp =
3204 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3205
3206 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3207 power_rule->max_antenna_gain =
3208 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3209
3210 return 0;
3211}
3212
3213static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3214{
3215 int r;
3216 char *data = NULL;
3217
80778f18
LR
3218 /*
3219 * You should only get this when cfg80211 hasn't yet initialized
3220 * completely when built-in to the kernel right between the time
3221 * window between nl80211_init() and regulatory_init(), if that is
3222 * even possible.
3223 */
3224 mutex_lock(&cfg80211_mutex);
3225 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3226 mutex_unlock(&cfg80211_mutex);
3227 return -EINPROGRESS;
80778f18 3228 }
fe33eb39 3229 mutex_unlock(&cfg80211_mutex);
80778f18 3230
fe33eb39
LR
3231 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3232 return -EINVAL;
b2e1b302
LR
3233
3234 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3235
fe33eb39
LR
3236 r = regulatory_hint_user(data);
3237
b2e1b302
LR
3238 return r;
3239}
3240
24bdd9f4 3241static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3242 struct genl_info *info)
93da9cc1 3243{
4c476991 3244 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3245 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3246 struct wireless_dev *wdev = dev->ieee80211_ptr;
3247 struct mesh_config cur_params;
3248 int err = 0;
93da9cc1 3249 void *hdr;
3250 struct nlattr *pinfoattr;
3251 struct sk_buff *msg;
3252
29cbe68c
JB
3253 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3254 return -EOPNOTSUPP;
3255
24bdd9f4 3256 if (!rdev->ops->get_mesh_config)
4c476991 3257 return -EOPNOTSUPP;
f3f92586 3258
29cbe68c
JB
3259 wdev_lock(wdev);
3260 /* If not connected, get default parameters */
3261 if (!wdev->mesh_id_len)
3262 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3263 else
24bdd9f4 3264 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3265 &cur_params);
3266 wdev_unlock(wdev);
3267
93da9cc1 3268 if (err)
4c476991 3269 return err;
93da9cc1 3270
3271 /* Draw up a netlink message to send back */
fd2120ca 3272 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3273 if (!msg)
3274 return -ENOMEM;
93da9cc1 3275 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3276 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3277 if (!hdr)
efe1cf0c 3278 goto out;
24bdd9f4 3279 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3280 if (!pinfoattr)
3281 goto nla_put_failure;
3282 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3283 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3284 cur_params.dot11MeshRetryTimeout);
3285 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3286 cur_params.dot11MeshConfirmTimeout);
3287 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3288 cur_params.dot11MeshHoldingTimeout);
3289 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3290 cur_params.dot11MeshMaxPeerLinks);
3291 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
3292 cur_params.dot11MeshMaxRetries);
3293 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
3294 cur_params.dot11MeshTTL);
45904f21
JC
3295 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3296 cur_params.element_ttl);
93da9cc1 3297 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3298 cur_params.auto_open_plinks);
d299a1f2
JC
3299 NLA_PUT_U32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3300 cur_params.dot11MeshNbrOffsetMaxNeighbor);
93da9cc1 3301 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3302 cur_params.dot11MeshHWMPmaxPREQretries);
3303 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3304 cur_params.path_refresh_time);
3305 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3306 cur_params.min_discovery_timeout);
3307 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3308 cur_params.dot11MeshHWMPactivePathTimeout);
3309 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3310 cur_params.dot11MeshHWMPpreqMinInterval);
dca7e943
TP
3311 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3312 cur_params.dot11MeshHWMPperrMinInterval);
93da9cc1 3313 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3314 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
3315 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3316 cur_params.dot11MeshHWMPRootMode);
0507e159
JC
3317 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3318 cur_params.dot11MeshHWMPRannInterval);
16dd7267
JC
3319 NLA_PUT_U8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3320 cur_params.dot11MeshGateAnnouncementProtocol);
94f90656
CYY
3321 NLA_PUT_U8(msg, NL80211_MESHCONF_FORWARDING,
3322 cur_params.dot11MeshForwarding);
55335137
AN
3323 NLA_PUT_U32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
3324 cur_params.rssi_threshold);
93da9cc1 3325 nla_nest_end(msg, pinfoattr);
3326 genlmsg_end(msg, hdr);
4c476991 3327 return genlmsg_reply(msg, info);
93da9cc1 3328
3b85875a 3329 nla_put_failure:
93da9cc1 3330 genlmsg_cancel(msg, hdr);
efe1cf0c 3331 out:
d080e275 3332 nlmsg_free(msg);
4c476991 3333 return -ENOBUFS;
93da9cc1 3334}
3335
b54452b0 3336static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3337 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3338 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3339 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3340 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3341 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3342 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3343 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3344 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 3345 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 3346
3347 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3348 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3349 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3350 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3351 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3352 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3353 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3354 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3355 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3356 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3357 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
55335137 3358 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32},
93da9cc1 3359};
3360
c80d545d
JC
3361static const struct nla_policy
3362 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 3363 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
3364 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3365 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3366 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3367 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 3368 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3369 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3370};
3371
24bdd9f4 3372static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3373 struct mesh_config *cfg,
3374 u32 *mask_out)
93da9cc1 3375{
93da9cc1 3376 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3377 u32 mask = 0;
93da9cc1 3378
bd90fdcc
JB
3379#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3380do {\
3381 if (table[attr_num]) {\
3382 cfg->param = nla_fn(table[attr_num]); \
3383 mask |= (1 << (attr_num - 1)); \
3384 } \
3385} while (0);\
3386
3387
24bdd9f4 3388 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3389 return -EINVAL;
3390 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3391 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3392 nl80211_meshconf_params_policy))
93da9cc1 3393 return -EINVAL;
3394
93da9cc1 3395 /* This makes sure that there aren't more than 32 mesh config
3396 * parameters (otherwise our bitfield scheme would not work.) */
3397 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3398
3399 /* Fill in the params struct */
93da9cc1 3400 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3401 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3402 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3403 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3404 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3405 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3406 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3407 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3408 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3409 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3410 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3411 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
3412 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3413 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 3414 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3415 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
d299a1f2
JC
3416 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
3417 mask, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3418 nla_get_u32);
93da9cc1 3419 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3420 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3421 nla_get_u8);
3422 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3423 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3424 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3425 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3426 nla_get_u16);
3427 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3428 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3429 nla_get_u32);
3430 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3431 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3432 nla_get_u16);
dca7e943
TP
3433 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
3434 mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3435 nla_get_u16);
93da9cc1 3436 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3437 dot11MeshHWMPnetDiameterTraversalTime,
3438 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3439 nla_get_u16);
63c5723b
RP
3440 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3441 dot11MeshHWMPRootMode, mask,
3442 NL80211_MESHCONF_HWMP_ROOTMODE,
3443 nla_get_u8);
0507e159
JC
3444 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3445 dot11MeshHWMPRannInterval, mask,
3446 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3447 nla_get_u16);
16dd7267
JC
3448 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3449 dot11MeshGateAnnouncementProtocol, mask,
3450 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3451 nla_get_u8);
94f90656
CYY
3452 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
3453 mask, NL80211_MESHCONF_FORWARDING, nla_get_u8);
55335137
AN
3454 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
3455 mask, NL80211_MESHCONF_RSSI_THRESHOLD, nla_get_u32);
bd90fdcc
JB
3456 if (mask_out)
3457 *mask_out = mask;
c80d545d 3458
bd90fdcc
JB
3459 return 0;
3460
3461#undef FILL_IN_MESH_PARAM_IF_SET
3462}
3463
c80d545d
JC
3464static int nl80211_parse_mesh_setup(struct genl_info *info,
3465 struct mesh_setup *setup)
3466{
3467 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3468
3469 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3470 return -EINVAL;
3471 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3472 info->attrs[NL80211_ATTR_MESH_SETUP],
3473 nl80211_mesh_setup_params_policy))
3474 return -EINVAL;
3475
d299a1f2
JC
3476 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
3477 setup->sync_method =
3478 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
3479 IEEE80211_SYNC_METHOD_VENDOR :
3480 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
3481
c80d545d
JC
3482 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3483 setup->path_sel_proto =
3484 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3485 IEEE80211_PATH_PROTOCOL_VENDOR :
3486 IEEE80211_PATH_PROTOCOL_HWMP;
3487
3488 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3489 setup->path_metric =
3490 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3491 IEEE80211_PATH_METRIC_VENDOR :
3492 IEEE80211_PATH_METRIC_AIRTIME;
3493
581a8b0f
JC
3494
3495 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3496 struct nlattr *ieattr =
581a8b0f 3497 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3498 if (!is_valid_ie_attr(ieattr))
3499 return -EINVAL;
581a8b0f
JC
3500 setup->ie = nla_data(ieattr);
3501 setup->ie_len = nla_len(ieattr);
c80d545d 3502 }
b130e5ce
JC
3503 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3504 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3505
3506 return 0;
3507}
3508
24bdd9f4 3509static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3510 struct genl_info *info)
bd90fdcc
JB
3511{
3512 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3513 struct net_device *dev = info->user_ptr[1];
29cbe68c 3514 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3515 struct mesh_config cfg;
3516 u32 mask;
3517 int err;
3518
29cbe68c
JB
3519 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3520 return -EOPNOTSUPP;
3521
24bdd9f4 3522 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3523 return -EOPNOTSUPP;
3524
24bdd9f4 3525 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3526 if (err)
3527 return err;
3528
29cbe68c
JB
3529 wdev_lock(wdev);
3530 if (!wdev->mesh_id_len)
3531 err = -ENOLINK;
3532
3533 if (!err)
24bdd9f4 3534 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3535 mask, &cfg);
3536
3537 wdev_unlock(wdev);
3538
3539 return err;
93da9cc1 3540}
3541
f130347c
LR
3542static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3543{
3544 struct sk_buff *msg;
3545 void *hdr = NULL;
3546 struct nlattr *nl_reg_rules;
3547 unsigned int i;
3548 int err = -EINVAL;
3549
a1794390 3550 mutex_lock(&cfg80211_mutex);
f130347c
LR
3551
3552 if (!cfg80211_regdomain)
3553 goto out;
3554
fd2120ca 3555 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3556 if (!msg) {
3557 err = -ENOBUFS;
3558 goto out;
3559 }
3560
3561 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3562 NL80211_CMD_GET_REG);
3563 if (!hdr)
efe1cf0c 3564 goto put_failure;
f130347c
LR
3565
3566 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3567 cfg80211_regdomain->alpha2);
8b60b078
LR
3568 if (cfg80211_regdomain->dfs_region)
3569 NLA_PUT_U8(msg, NL80211_ATTR_DFS_REGION,
3570 cfg80211_regdomain->dfs_region);
f130347c
LR
3571
3572 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3573 if (!nl_reg_rules)
3574 goto nla_put_failure;
3575
3576 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3577 struct nlattr *nl_reg_rule;
3578 const struct ieee80211_reg_rule *reg_rule;
3579 const struct ieee80211_freq_range *freq_range;
3580 const struct ieee80211_power_rule *power_rule;
3581
3582 reg_rule = &cfg80211_regdomain->reg_rules[i];
3583 freq_range = &reg_rule->freq_range;
3584 power_rule = &reg_rule->power_rule;
3585
3586 nl_reg_rule = nla_nest_start(msg, i);
3587 if (!nl_reg_rule)
3588 goto nla_put_failure;
3589
3590 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3591 reg_rule->flags);
3592 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3593 freq_range->start_freq_khz);
3594 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3595 freq_range->end_freq_khz);
3596 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3597 freq_range->max_bandwidth_khz);
3598 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3599 power_rule->max_antenna_gain);
3600 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3601 power_rule->max_eirp);
3602
3603 nla_nest_end(msg, nl_reg_rule);
3604 }
3605
3606 nla_nest_end(msg, nl_reg_rules);
3607
3608 genlmsg_end(msg, hdr);
134e6375 3609 err = genlmsg_reply(msg, info);
f130347c
LR
3610 goto out;
3611
3612nla_put_failure:
3613 genlmsg_cancel(msg, hdr);
efe1cf0c 3614put_failure:
d080e275 3615 nlmsg_free(msg);
f130347c
LR
3616 err = -EMSGSIZE;
3617out:
a1794390 3618 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3619 return err;
3620}
3621
b2e1b302
LR
3622static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3623{
3624 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3625 struct nlattr *nl_reg_rule;
3626 char *alpha2 = NULL;
3627 int rem_reg_rules = 0, r = 0;
3628 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 3629 u8 dfs_region = 0;
b2e1b302
LR
3630 struct ieee80211_regdomain *rd = NULL;
3631
3632 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3633 return -EINVAL;
3634
3635 if (!info->attrs[NL80211_ATTR_REG_RULES])
3636 return -EINVAL;
3637
3638 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3639
8b60b078
LR
3640 if (info->attrs[NL80211_ATTR_DFS_REGION])
3641 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
3642
b2e1b302
LR
3643 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3644 rem_reg_rules) {
3645 num_rules++;
3646 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3647 return -EINVAL;
b2e1b302
LR
3648 }
3649
61405e97
LR
3650 mutex_lock(&cfg80211_mutex);
3651
d0e18f83
LR
3652 if (!reg_is_valid_request(alpha2)) {
3653 r = -EINVAL;
3654 goto bad_reg;
3655 }
b2e1b302
LR
3656
3657 size_of_regd = sizeof(struct ieee80211_regdomain) +
3658 (num_rules * sizeof(struct ieee80211_reg_rule));
3659
3660 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3661 if (!rd) {
3662 r = -ENOMEM;
3663 goto bad_reg;
3664 }
b2e1b302
LR
3665
3666 rd->n_reg_rules = num_rules;
3667 rd->alpha2[0] = alpha2[0];
3668 rd->alpha2[1] = alpha2[1];
3669
8b60b078
LR
3670 /*
3671 * Disable DFS master mode if the DFS region was
3672 * not supported or known on this kernel.
3673 */
3674 if (reg_supported_dfs_region(dfs_region))
3675 rd->dfs_region = dfs_region;
3676
b2e1b302
LR
3677 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3678 rem_reg_rules) {
3679 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3680 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3681 reg_rule_policy);
3682 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3683 if (r)
3684 goto bad_reg;
3685
3686 rule_idx++;
3687
d0e18f83
LR
3688 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3689 r = -EINVAL;
b2e1b302 3690 goto bad_reg;
d0e18f83 3691 }
b2e1b302
LR
3692 }
3693
3694 BUG_ON(rule_idx != num_rules);
3695
b2e1b302 3696 r = set_regdom(rd);
61405e97 3697
a1794390 3698 mutex_unlock(&cfg80211_mutex);
d0e18f83 3699
b2e1b302
LR
3700 return r;
3701
d2372b31 3702 bad_reg:
61405e97 3703 mutex_unlock(&cfg80211_mutex);
b2e1b302 3704 kfree(rd);
d0e18f83 3705 return r;
b2e1b302
LR
3706}
3707
83f5e2cf
JB
3708static int validate_scan_freqs(struct nlattr *freqs)
3709{
3710 struct nlattr *attr1, *attr2;
3711 int n_channels = 0, tmp1, tmp2;
3712
3713 nla_for_each_nested(attr1, freqs, tmp1) {
3714 n_channels++;
3715 /*
3716 * Some hardware has a limited channel list for
3717 * scanning, and it is pretty much nonsensical
3718 * to scan for a channel twice, so disallow that
3719 * and don't require drivers to check that the
3720 * channel list they get isn't longer than what
3721 * they can scan, as long as they can scan all
3722 * the channels they registered at once.
3723 */
3724 nla_for_each_nested(attr2, freqs, tmp2)
3725 if (attr1 != attr2 &&
3726 nla_get_u32(attr1) == nla_get_u32(attr2))
3727 return 0;
3728 }
3729
3730 return n_channels;
3731}
3732
2a519311
JB
3733static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3734{
4c476991
JB
3735 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3736 struct net_device *dev = info->user_ptr[1];
2a519311 3737 struct cfg80211_scan_request *request;
2a519311
JB
3738 struct nlattr *attr;
3739 struct wiphy *wiphy;
83f5e2cf 3740 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 3741 size_t ie_len;
2a519311 3742
f4a11bb0
JB
3743 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3744 return -EINVAL;
3745
79c97e97 3746 wiphy = &rdev->wiphy;
2a519311 3747
4c476991
JB
3748 if (!rdev->ops->scan)
3749 return -EOPNOTSUPP;
2a519311 3750
4c476991
JB
3751 if (rdev->scan_req)
3752 return -EBUSY;
2a519311
JB
3753
3754 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3755 n_channels = validate_scan_freqs(
3756 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3757 if (!n_channels)
3758 return -EINVAL;
2a519311 3759 } else {
34850ab2 3760 enum ieee80211_band band;
83f5e2cf
JB
3761 n_channels = 0;
3762
2a519311
JB
3763 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3764 if (wiphy->bands[band])
3765 n_channels += wiphy->bands[band]->n_channels;
3766 }
3767
3768 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3769 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3770 n_ssids++;
3771
4c476991
JB
3772 if (n_ssids > wiphy->max_scan_ssids)
3773 return -EINVAL;
2a519311 3774
70692ad2
JM
3775 if (info->attrs[NL80211_ATTR_IE])
3776 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3777 else
3778 ie_len = 0;
3779
4c476991
JB
3780 if (ie_len > wiphy->max_scan_ie_len)
3781 return -EINVAL;
18a83659 3782
2a519311 3783 request = kzalloc(sizeof(*request)
a2cd43c5
LC
3784 + sizeof(*request->ssids) * n_ssids
3785 + sizeof(*request->channels) * n_channels
70692ad2 3786 + ie_len, GFP_KERNEL);
4c476991
JB
3787 if (!request)
3788 return -ENOMEM;
2a519311 3789
2a519311 3790 if (n_ssids)
5ba63533 3791 request->ssids = (void *)&request->channels[n_channels];
2a519311 3792 request->n_ssids = n_ssids;
70692ad2
JM
3793 if (ie_len) {
3794 if (request->ssids)
3795 request->ie = (void *)(request->ssids + n_ssids);
3796 else
3797 request->ie = (void *)(request->channels + n_channels);
3798 }
2a519311 3799
584991dc 3800 i = 0;
2a519311
JB
3801 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3802 /* user specified, bail out if channel not found */
2a519311 3803 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3804 struct ieee80211_channel *chan;
3805
3806 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3807
3808 if (!chan) {
2a519311
JB
3809 err = -EINVAL;
3810 goto out_free;
3811 }
584991dc
JB
3812
3813 /* ignore disabled channels */
3814 if (chan->flags & IEEE80211_CHAN_DISABLED)
3815 continue;
3816
3817 request->channels[i] = chan;
2a519311
JB
3818 i++;
3819 }
3820 } else {
34850ab2
JB
3821 enum ieee80211_band band;
3822
2a519311 3823 /* all channels */
2a519311
JB
3824 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3825 int j;
3826 if (!wiphy->bands[band])
3827 continue;
3828 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3829 struct ieee80211_channel *chan;
3830
3831 chan = &wiphy->bands[band]->channels[j];
3832
3833 if (chan->flags & IEEE80211_CHAN_DISABLED)
3834 continue;
3835
3836 request->channels[i] = chan;
2a519311
JB
3837 i++;
3838 }
3839 }
3840 }
3841
584991dc
JB
3842 if (!i) {
3843 err = -EINVAL;
3844 goto out_free;
3845 }
3846
3847 request->n_channels = i;
3848
2a519311
JB
3849 i = 0;
3850 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3851 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 3852 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
3853 err = -EINVAL;
3854 goto out_free;
3855 }
57a27e1d 3856 request->ssids[i].ssid_len = nla_len(attr);
2a519311 3857 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
3858 i++;
3859 }
3860 }
3861
70692ad2
JM
3862 if (info->attrs[NL80211_ATTR_IE]) {
3863 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3864 memcpy((void *)request->ie,
3865 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3866 request->ie_len);
3867 }
3868
34850ab2 3869 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
3870 if (wiphy->bands[i])
3871 request->rates[i] =
3872 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
3873
3874 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
3875 nla_for_each_nested(attr,
3876 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
3877 tmp) {
3878 enum ieee80211_band band = nla_type(attr);
3879
84404623 3880 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
3881 err = -EINVAL;
3882 goto out_free;
3883 }
3884 err = ieee80211_get_ratemask(wiphy->bands[band],
3885 nla_data(attr),
3886 nla_len(attr),
3887 &request->rates[band]);
3888 if (err)
3889 goto out_free;
3890 }
3891 }
3892
e9f935e3
RM
3893 request->no_cck =
3894 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
3895
463d0183 3896 request->dev = dev;
79c97e97 3897 request->wiphy = &rdev->wiphy;
2a519311 3898
79c97e97
JB
3899 rdev->scan_req = request;
3900 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3901
463d0183 3902 if (!err) {
79c97e97 3903 nl80211_send_scan_start(rdev, dev);
463d0183 3904 dev_hold(dev);
4c476991 3905 } else {
2a519311 3906 out_free:
79c97e97 3907 rdev->scan_req = NULL;
2a519311
JB
3908 kfree(request);
3909 }
3b85875a 3910
2a519311
JB
3911 return err;
3912}
3913
807f8a8c
LC
3914static int nl80211_start_sched_scan(struct sk_buff *skb,
3915 struct genl_info *info)
3916{
3917 struct cfg80211_sched_scan_request *request;
3918 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3919 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
3920 struct nlattr *attr;
3921 struct wiphy *wiphy;
a1f1c21c 3922 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 3923 u32 interval;
807f8a8c
LC
3924 enum ieee80211_band band;
3925 size_t ie_len;
a1f1c21c 3926 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
3927
3928 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3929 !rdev->ops->sched_scan_start)
3930 return -EOPNOTSUPP;
3931
3932 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3933 return -EINVAL;
3934
bbe6ad6d
LC
3935 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3936 return -EINVAL;
3937
3938 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3939 if (interval == 0)
3940 return -EINVAL;
3941
807f8a8c
LC
3942 wiphy = &rdev->wiphy;
3943
3944 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3945 n_channels = validate_scan_freqs(
3946 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3947 if (!n_channels)
3948 return -EINVAL;
3949 } else {
3950 n_channels = 0;
3951
3952 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3953 if (wiphy->bands[band])
3954 n_channels += wiphy->bands[band]->n_channels;
3955 }
3956
3957 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3958 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3959 tmp)
3960 n_ssids++;
3961
93b6aa69 3962 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
3963 return -EINVAL;
3964
a1f1c21c
LC
3965 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
3966 nla_for_each_nested(attr,
3967 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3968 tmp)
3969 n_match_sets++;
3970
3971 if (n_match_sets > wiphy->max_match_sets)
3972 return -EINVAL;
3973
807f8a8c
LC
3974 if (info->attrs[NL80211_ATTR_IE])
3975 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3976 else
3977 ie_len = 0;
3978
5a865bad 3979 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
3980 return -EINVAL;
3981
c10841ca
LC
3982 mutex_lock(&rdev->sched_scan_mtx);
3983
3984 if (rdev->sched_scan_req) {
3985 err = -EINPROGRESS;
3986 goto out;
3987 }
3988
807f8a8c 3989 request = kzalloc(sizeof(*request)
a2cd43c5 3990 + sizeof(*request->ssids) * n_ssids
a1f1c21c 3991 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 3992 + sizeof(*request->channels) * n_channels
807f8a8c 3993 + ie_len, GFP_KERNEL);
c10841ca
LC
3994 if (!request) {
3995 err = -ENOMEM;
3996 goto out;
3997 }
807f8a8c
LC
3998
3999 if (n_ssids)
4000 request->ssids = (void *)&request->channels[n_channels];
4001 request->n_ssids = n_ssids;
4002 if (ie_len) {
4003 if (request->ssids)
4004 request->ie = (void *)(request->ssids + n_ssids);
4005 else
4006 request->ie = (void *)(request->channels + n_channels);
4007 }
4008
a1f1c21c
LC
4009 if (n_match_sets) {
4010 if (request->ie)
4011 request->match_sets = (void *)(request->ie + ie_len);
4012 else if (request->ssids)
4013 request->match_sets =
4014 (void *)(request->ssids + n_ssids);
4015 else
4016 request->match_sets =
4017 (void *)(request->channels + n_channels);
4018 }
4019 request->n_match_sets = n_match_sets;
4020
807f8a8c
LC
4021 i = 0;
4022 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4023 /* user specified, bail out if channel not found */
4024 nla_for_each_nested(attr,
4025 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4026 tmp) {
4027 struct ieee80211_channel *chan;
4028
4029 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4030
4031 if (!chan) {
4032 err = -EINVAL;
4033 goto out_free;
4034 }
4035
4036 /* ignore disabled channels */
4037 if (chan->flags & IEEE80211_CHAN_DISABLED)
4038 continue;
4039
4040 request->channels[i] = chan;
4041 i++;
4042 }
4043 } else {
4044 /* all channels */
4045 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4046 int j;
4047 if (!wiphy->bands[band])
4048 continue;
4049 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4050 struct ieee80211_channel *chan;
4051
4052 chan = &wiphy->bands[band]->channels[j];
4053
4054 if (chan->flags & IEEE80211_CHAN_DISABLED)
4055 continue;
4056
4057 request->channels[i] = chan;
4058 i++;
4059 }
4060 }
4061 }
4062
4063 if (!i) {
4064 err = -EINVAL;
4065 goto out_free;
4066 }
4067
4068 request->n_channels = i;
4069
4070 i = 0;
4071 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4072 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4073 tmp) {
57a27e1d 4074 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4075 err = -EINVAL;
4076 goto out_free;
4077 }
57a27e1d 4078 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4079 memcpy(request->ssids[i].ssid, nla_data(attr),
4080 nla_len(attr));
807f8a8c
LC
4081 i++;
4082 }
4083 }
4084
a1f1c21c
LC
4085 i = 0;
4086 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4087 nla_for_each_nested(attr,
4088 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4089 tmp) {
4090 struct nlattr *ssid;
4091
4092 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4093 nla_data(attr), nla_len(attr),
4094 nl80211_match_policy);
4095 ssid = tb[NL80211_ATTR_SCHED_SCAN_MATCH_SSID];
4096 if (ssid) {
4097 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4098 err = -EINVAL;
4099 goto out_free;
4100 }
4101 memcpy(request->match_sets[i].ssid.ssid,
4102 nla_data(ssid), nla_len(ssid));
4103 request->match_sets[i].ssid.ssid_len =
4104 nla_len(ssid);
4105 }
4106 i++;
4107 }
4108 }
4109
807f8a8c
LC
4110 if (info->attrs[NL80211_ATTR_IE]) {
4111 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4112 memcpy((void *)request->ie,
4113 nla_data(info->attrs[NL80211_ATTR_IE]),
4114 request->ie_len);
4115 }
4116
4117 request->dev = dev;
4118 request->wiphy = &rdev->wiphy;
bbe6ad6d 4119 request->interval = interval;
807f8a8c
LC
4120
4121 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
4122 if (!err) {
4123 rdev->sched_scan_req = request;
4124 nl80211_send_sched_scan(rdev, dev,
4125 NL80211_CMD_START_SCHED_SCAN);
4126 goto out;
4127 }
4128
4129out_free:
4130 kfree(request);
4131out:
c10841ca 4132 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4133 return err;
4134}
4135
4136static int nl80211_stop_sched_scan(struct sk_buff *skb,
4137 struct genl_info *info)
4138{
4139 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4140 int err;
807f8a8c
LC
4141
4142 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4143 !rdev->ops->sched_scan_stop)
4144 return -EOPNOTSUPP;
4145
c10841ca
LC
4146 mutex_lock(&rdev->sched_scan_mtx);
4147 err = __cfg80211_stop_sched_scan(rdev, false);
4148 mutex_unlock(&rdev->sched_scan_mtx);
4149
4150 return err;
807f8a8c
LC
4151}
4152
9720bb3a
JB
4153static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4154 u32 seq, int flags,
2a519311 4155 struct cfg80211_registered_device *rdev,
48ab905d
JB
4156 struct wireless_dev *wdev,
4157 struct cfg80211_internal_bss *intbss)
2a519311 4158{
48ab905d 4159 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
4160 void *hdr;
4161 struct nlattr *bss;
48ab905d
JB
4162
4163 ASSERT_WDEV_LOCK(wdev);
2a519311 4164
9720bb3a 4165 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
4166 NL80211_CMD_NEW_SCAN_RESULTS);
4167 if (!hdr)
4168 return -1;
4169
9720bb3a
JB
4170 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4171
f5ea9120 4172 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 4173 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
4174
4175 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4176 if (!bss)
4177 goto nla_put_failure;
4178 if (!is_zero_ether_addr(res->bssid))
4179 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
4180 if (res->information_elements && res->len_information_elements)
4181 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4182 res->len_information_elements,
4183 res->information_elements);
34a6eddb
JM
4184 if (res->beacon_ies && res->len_beacon_ies &&
4185 res->beacon_ies != res->information_elements)
4186 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
4187 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
4188 if (res->tsf)
4189 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
4190 if (res->beacon_interval)
4191 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
4192 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
4193 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
4194 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
4195 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 4196
77965c97 4197 switch (rdev->wiphy.signal_type) {
2a519311
JB
4198 case CFG80211_SIGNAL_TYPE_MBM:
4199 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
4200 break;
4201 case CFG80211_SIGNAL_TYPE_UNSPEC:
4202 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
4203 break;
4204 default:
4205 break;
4206 }
4207
48ab905d 4208 switch (wdev->iftype) {
074ac8df 4209 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
4210 case NL80211_IFTYPE_STATION:
4211 if (intbss == wdev->current_bss)
4212 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4213 NL80211_BSS_STATUS_ASSOCIATED);
48ab905d
JB
4214 break;
4215 case NL80211_IFTYPE_ADHOC:
4216 if (intbss == wdev->current_bss)
4217 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4218 NL80211_BSS_STATUS_IBSS_JOINED);
4219 break;
4220 default:
4221 break;
4222 }
4223
2a519311
JB
4224 nla_nest_end(msg, bss);
4225
4226 return genlmsg_end(msg, hdr);
4227
4228 nla_put_failure:
4229 genlmsg_cancel(msg, hdr);
4230 return -EMSGSIZE;
4231}
4232
4233static int nl80211_dump_scan(struct sk_buff *skb,
4234 struct netlink_callback *cb)
4235{
48ab905d
JB
4236 struct cfg80211_registered_device *rdev;
4237 struct net_device *dev;
2a519311 4238 struct cfg80211_internal_bss *scan;
48ab905d 4239 struct wireless_dev *wdev;
2a519311
JB
4240 int start = cb->args[1], idx = 0;
4241 int err;
4242
67748893
JB
4243 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4244 if (err)
4245 return err;
2a519311 4246
48ab905d 4247 wdev = dev->ieee80211_ptr;
2a519311 4248
48ab905d
JB
4249 wdev_lock(wdev);
4250 spin_lock_bh(&rdev->bss_lock);
4251 cfg80211_bss_expire(rdev);
4252
9720bb3a
JB
4253 cb->seq = rdev->bss_generation;
4254
48ab905d 4255 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4256 if (++idx <= start)
4257 continue;
9720bb3a 4258 if (nl80211_send_bss(skb, cb,
2a519311 4259 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4260 rdev, wdev, scan) < 0) {
2a519311 4261 idx--;
67748893 4262 break;
2a519311
JB
4263 }
4264 }
4265
48ab905d
JB
4266 spin_unlock_bh(&rdev->bss_lock);
4267 wdev_unlock(wdev);
2a519311
JB
4268
4269 cb->args[1] = idx;
67748893 4270 nl80211_finish_netdev_dump(rdev);
2a519311 4271
67748893 4272 return skb->len;
2a519311
JB
4273}
4274
61fa713c
HS
4275static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4276 int flags, struct net_device *dev,
4277 struct survey_info *survey)
4278{
4279 void *hdr;
4280 struct nlattr *infoattr;
4281
61fa713c
HS
4282 hdr = nl80211hdr_put(msg, pid, seq, flags,
4283 NL80211_CMD_NEW_SURVEY_RESULTS);
4284 if (!hdr)
4285 return -ENOMEM;
4286
4287 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
4288
4289 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4290 if (!infoattr)
4291 goto nla_put_failure;
4292
4293 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4294 survey->channel->center_freq);
4295 if (survey->filled & SURVEY_INFO_NOISE_DBM)
4296 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
4297 survey->noise);
17e5a808
FF
4298 if (survey->filled & SURVEY_INFO_IN_USE)
4299 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
4300 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
4301 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4302 survey->channel_time);
4303 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
4304 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4305 survey->channel_time_busy);
4306 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
4307 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4308 survey->channel_time_ext_busy);
4309 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
4310 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4311 survey->channel_time_rx);
4312 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
4313 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4314 survey->channel_time_tx);
61fa713c
HS
4315
4316 nla_nest_end(msg, infoattr);
4317
4318 return genlmsg_end(msg, hdr);
4319
4320 nla_put_failure:
4321 genlmsg_cancel(msg, hdr);
4322 return -EMSGSIZE;
4323}
4324
4325static int nl80211_dump_survey(struct sk_buff *skb,
4326 struct netlink_callback *cb)
4327{
4328 struct survey_info survey;
4329 struct cfg80211_registered_device *dev;
4330 struct net_device *netdev;
61fa713c
HS
4331 int survey_idx = cb->args[1];
4332 int res;
4333
67748893
JB
4334 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4335 if (res)
4336 return res;
61fa713c
HS
4337
4338 if (!dev->ops->dump_survey) {
4339 res = -EOPNOTSUPP;
4340 goto out_err;
4341 }
4342
4343 while (1) {
180cdc79
LR
4344 struct ieee80211_channel *chan;
4345
61fa713c
HS
4346 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4347 &survey);
4348 if (res == -ENOENT)
4349 break;
4350 if (res)
4351 goto out_err;
4352
180cdc79
LR
4353 /* Survey without a channel doesn't make sense */
4354 if (!survey.channel) {
4355 res = -EINVAL;
4356 goto out;
4357 }
4358
4359 chan = ieee80211_get_channel(&dev->wiphy,
4360 survey.channel->center_freq);
4361 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4362 survey_idx++;
4363 continue;
4364 }
4365
61fa713c
HS
4366 if (nl80211_send_survey(skb,
4367 NETLINK_CB(cb->skb).pid,
4368 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4369 netdev,
4370 &survey) < 0)
4371 goto out;
4372 survey_idx++;
4373 }
4374
4375 out:
4376 cb->args[1] = survey_idx;
4377 res = skb->len;
4378 out_err:
67748893 4379 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4380 return res;
4381}
4382
255e737e
JM
4383static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4384{
b23aa676
SO
4385 return auth_type <= NL80211_AUTHTYPE_MAX;
4386}
4387
4388static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4389{
4390 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4391 NL80211_WPA_VERSION_2));
4392}
4393
636a5d36
JM
4394static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4395{
4c476991
JB
4396 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4397 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4398 struct ieee80211_channel *chan;
4399 const u8 *bssid, *ssid, *ie = NULL;
4400 int err, ssid_len, ie_len = 0;
4401 enum nl80211_auth_type auth_type;
fffd0934 4402 struct key_parse key;
d5cdfacb 4403 bool local_state_change;
636a5d36 4404
f4a11bb0
JB
4405 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4406 return -EINVAL;
4407
4408 if (!info->attrs[NL80211_ATTR_MAC])
4409 return -EINVAL;
4410
1778092e
JM
4411 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4412 return -EINVAL;
4413
19957bb3
JB
4414 if (!info->attrs[NL80211_ATTR_SSID])
4415 return -EINVAL;
4416
4417 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4418 return -EINVAL;
4419
fffd0934
JB
4420 err = nl80211_parse_key(info, &key);
4421 if (err)
4422 return err;
4423
4424 if (key.idx >= 0) {
e31b8213
JB
4425 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4426 return -EINVAL;
fffd0934
JB
4427 if (!key.p.key || !key.p.key_len)
4428 return -EINVAL;
4429 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4430 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4431 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4432 key.p.key_len != WLAN_KEY_LEN_WEP104))
4433 return -EINVAL;
4434 if (key.idx > 4)
4435 return -EINVAL;
4436 } else {
4437 key.p.key_len = 0;
4438 key.p.key = NULL;
4439 }
4440
afea0b7a
JB
4441 if (key.idx >= 0) {
4442 int i;
4443 bool ok = false;
4444 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4445 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4446 ok = true;
4447 break;
4448 }
4449 }
4c476991
JB
4450 if (!ok)
4451 return -EINVAL;
afea0b7a
JB
4452 }
4453
4c476991
JB
4454 if (!rdev->ops->auth)
4455 return -EOPNOTSUPP;
636a5d36 4456
074ac8df 4457 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4458 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4459 return -EOPNOTSUPP;
eec60b03 4460
19957bb3 4461 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4462 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4463 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4464 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4465 return -EINVAL;
636a5d36 4466
19957bb3
JB
4467 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4468 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4469
4470 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4471 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4472 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4473 }
4474
19957bb3 4475 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4476 if (!nl80211_valid_auth_type(auth_type))
4477 return -EINVAL;
636a5d36 4478
d5cdfacb
JM
4479 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4480
95de817b
JB
4481 /*
4482 * Since we no longer track auth state, ignore
4483 * requests to only change local state.
4484 */
4485 if (local_state_change)
4486 return 0;
4487
4c476991
JB
4488 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4489 ssid, ssid_len, ie, ie_len,
95de817b 4490 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
4491}
4492
c0692b8f
JB
4493static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4494 struct genl_info *info,
3dc27d25
JB
4495 struct cfg80211_crypto_settings *settings,
4496 int cipher_limit)
b23aa676 4497{
c0b2bbd8
JB
4498 memset(settings, 0, sizeof(*settings));
4499
b23aa676
SO
4500 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4501
c0692b8f
JB
4502 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4503 u16 proto;
4504 proto = nla_get_u16(
4505 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4506 settings->control_port_ethertype = cpu_to_be16(proto);
4507 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4508 proto != ETH_P_PAE)
4509 return -EINVAL;
4510 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4511 settings->control_port_no_encrypt = true;
4512 } else
4513 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4514
b23aa676
SO
4515 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4516 void *data;
4517 int len, i;
4518
4519 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4520 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4521 settings->n_ciphers_pairwise = len / sizeof(u32);
4522
4523 if (len % sizeof(u32))
4524 return -EINVAL;
4525
3dc27d25 4526 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4527 return -EINVAL;
4528
4529 memcpy(settings->ciphers_pairwise, data, len);
4530
4531 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4532 if (!cfg80211_supported_cipher_suite(
4533 &rdev->wiphy,
b23aa676
SO
4534 settings->ciphers_pairwise[i]))
4535 return -EINVAL;
4536 }
4537
4538 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4539 settings->cipher_group =
4540 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4541 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4542 settings->cipher_group))
b23aa676
SO
4543 return -EINVAL;
4544 }
4545
4546 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4547 settings->wpa_versions =
4548 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4549 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4550 return -EINVAL;
4551 }
4552
4553 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4554 void *data;
6d30240e 4555 int len;
b23aa676
SO
4556
4557 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4558 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4559 settings->n_akm_suites = len / sizeof(u32);
4560
4561 if (len % sizeof(u32))
4562 return -EINVAL;
4563
1b9ca027
JM
4564 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4565 return -EINVAL;
4566
b23aa676 4567 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4568 }
4569
4570 return 0;
4571}
4572
636a5d36
JM
4573static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4574{
4c476991
JB
4575 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4576 struct net_device *dev = info->user_ptr[1];
19957bb3 4577 struct cfg80211_crypto_settings crypto;
f444de05 4578 struct ieee80211_channel *chan;
3e5d7649 4579 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4580 int err, ssid_len, ie_len = 0;
4581 bool use_mfp = false;
7e7c8926
BG
4582 u32 flags = 0;
4583 struct ieee80211_ht_cap *ht_capa = NULL;
4584 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 4585
f4a11bb0
JB
4586 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4587 return -EINVAL;
4588
4589 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4590 !info->attrs[NL80211_ATTR_SSID] ||
4591 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4592 return -EINVAL;
4593
4c476991
JB
4594 if (!rdev->ops->assoc)
4595 return -EOPNOTSUPP;
636a5d36 4596
074ac8df 4597 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4598 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4599 return -EOPNOTSUPP;
eec60b03 4600
19957bb3 4601 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4602
19957bb3
JB
4603 chan = ieee80211_get_channel(&rdev->wiphy,
4604 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4605 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4606 return -EINVAL;
636a5d36 4607
19957bb3
JB
4608 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4609 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4610
4611 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4612 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4613 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4614 }
4615
dc6382ce 4616 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4617 enum nl80211_mfp mfp =
dc6382ce 4618 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4619 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4620 use_mfp = true;
4c476991
JB
4621 else if (mfp != NL80211_MFP_NO)
4622 return -EINVAL;
dc6382ce
JM
4623 }
4624
3e5d7649
JB
4625 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4626 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4627
7e7c8926
BG
4628 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
4629 flags |= ASSOC_REQ_DISABLE_HT;
4630
4631 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
4632 ht_capa_mask =
4633 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
4634
4635 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
4636 if (!ht_capa_mask)
4637 return -EINVAL;
4638 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4639 }
4640
c0692b8f 4641 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4642 if (!err)
3e5d7649
JB
4643 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4644 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
4645 &crypto, flags, ht_capa,
4646 ht_capa_mask);
636a5d36 4647
636a5d36
JM
4648 return err;
4649}
4650
4651static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4652{
4c476991
JB
4653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4654 struct net_device *dev = info->user_ptr[1];
19957bb3 4655 const u8 *ie = NULL, *bssid;
4c476991 4656 int ie_len = 0;
19957bb3 4657 u16 reason_code;
d5cdfacb 4658 bool local_state_change;
636a5d36 4659
f4a11bb0
JB
4660 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4661 return -EINVAL;
4662
4663 if (!info->attrs[NL80211_ATTR_MAC])
4664 return -EINVAL;
4665
4666 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4667 return -EINVAL;
4668
4c476991
JB
4669 if (!rdev->ops->deauth)
4670 return -EOPNOTSUPP;
636a5d36 4671
074ac8df 4672 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4673 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4674 return -EOPNOTSUPP;
eec60b03 4675
19957bb3 4676 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4677
19957bb3
JB
4678 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4679 if (reason_code == 0) {
f4a11bb0 4680 /* Reason Code 0 is reserved */
4c476991 4681 return -EINVAL;
255e737e 4682 }
636a5d36
JM
4683
4684 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4685 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4686 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4687 }
4688
d5cdfacb
JM
4689 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4690
4c476991
JB
4691 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4692 local_state_change);
636a5d36
JM
4693}
4694
4695static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4696{
4c476991
JB
4697 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4698 struct net_device *dev = info->user_ptr[1];
19957bb3 4699 const u8 *ie = NULL, *bssid;
4c476991 4700 int ie_len = 0;
19957bb3 4701 u16 reason_code;
d5cdfacb 4702 bool local_state_change;
636a5d36 4703
f4a11bb0
JB
4704 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4705 return -EINVAL;
4706
4707 if (!info->attrs[NL80211_ATTR_MAC])
4708 return -EINVAL;
4709
4710 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4711 return -EINVAL;
4712
4c476991
JB
4713 if (!rdev->ops->disassoc)
4714 return -EOPNOTSUPP;
636a5d36 4715
074ac8df 4716 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4717 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4718 return -EOPNOTSUPP;
eec60b03 4719
19957bb3 4720 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4721
19957bb3
JB
4722 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4723 if (reason_code == 0) {
f4a11bb0 4724 /* Reason Code 0 is reserved */
4c476991 4725 return -EINVAL;
255e737e 4726 }
636a5d36
JM
4727
4728 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4729 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4730 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4731 }
4732
d5cdfacb
JM
4733 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4734
4c476991
JB
4735 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4736 local_state_change);
636a5d36
JM
4737}
4738
dd5b4cc7
FF
4739static bool
4740nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4741 int mcast_rate[IEEE80211_NUM_BANDS],
4742 int rateval)
4743{
4744 struct wiphy *wiphy = &rdev->wiphy;
4745 bool found = false;
4746 int band, i;
4747
4748 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4749 struct ieee80211_supported_band *sband;
4750
4751 sband = wiphy->bands[band];
4752 if (!sband)
4753 continue;
4754
4755 for (i = 0; i < sband->n_bitrates; i++) {
4756 if (sband->bitrates[i].bitrate == rateval) {
4757 mcast_rate[band] = i + 1;
4758 found = true;
4759 break;
4760 }
4761 }
4762 }
4763
4764 return found;
4765}
4766
04a773ad
JB
4767static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4768{
4c476991
JB
4769 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4770 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4771 struct cfg80211_ibss_params ibss;
4772 struct wiphy *wiphy;
fffd0934 4773 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4774 int err;
4775
8e30bc55
JB
4776 memset(&ibss, 0, sizeof(ibss));
4777
04a773ad
JB
4778 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4779 return -EINVAL;
4780
4781 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4782 !info->attrs[NL80211_ATTR_SSID] ||
4783 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4784 return -EINVAL;
4785
8e30bc55
JB
4786 ibss.beacon_interval = 100;
4787
4788 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4789 ibss.beacon_interval =
4790 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4791 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4792 return -EINVAL;
4793 }
4794
4c476991
JB
4795 if (!rdev->ops->join_ibss)
4796 return -EOPNOTSUPP;
04a773ad 4797
4c476991
JB
4798 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4799 return -EOPNOTSUPP;
04a773ad 4800
79c97e97 4801 wiphy = &rdev->wiphy;
04a773ad 4802
39193498 4803 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 4804 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
4805
4806 if (!is_valid_ether_addr(ibss.bssid))
4807 return -EINVAL;
4808 }
04a773ad
JB
4809 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4810 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4811
4812 if (info->attrs[NL80211_ATTR_IE]) {
4813 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4814 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4815 }
4816
54858ee5
AS
4817 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4818 enum nl80211_channel_type channel_type;
4819
4820 channel_type = nla_get_u32(
4821 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4822 if (channel_type != NL80211_CHAN_NO_HT &&
4823 channel_type != NL80211_CHAN_HT20 &&
4824 channel_type != NL80211_CHAN_HT40MINUS &&
4825 channel_type != NL80211_CHAN_HT40PLUS)
4826 return -EINVAL;
4827
4828 if (channel_type != NL80211_CHAN_NO_HT &&
4829 !(wiphy->features & NL80211_FEATURE_HT_IBSS))
4830 return -EINVAL;
4831
4832 ibss.channel_type = channel_type;
4833 } else {
4834 ibss.channel_type = NL80211_CHAN_NO_HT;
4835 }
4836
4837 ibss.channel = rdev_freq_to_chan(rdev,
4838 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
4839 ibss.channel_type);
04a773ad
JB
4840 if (!ibss.channel ||
4841 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4842 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4843 return -EINVAL;
04a773ad 4844
54858ee5
AS
4845 /* Both channels should be able to initiate communication */
4846 if ((ibss.channel_type == NL80211_CHAN_HT40PLUS ||
4847 ibss.channel_type == NL80211_CHAN_HT40MINUS) &&
4848 !cfg80211_can_beacon_sec_chan(&rdev->wiphy, ibss.channel,
4849 ibss.channel_type))
4850 return -EINVAL;
4851
04a773ad 4852 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4853 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4854
fbd2c8dc
TP
4855 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4856 u8 *rates =
4857 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4858 int n_rates =
4859 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4860 struct ieee80211_supported_band *sband =
4861 wiphy->bands[ibss.channel->band];
fbd2c8dc 4862
34850ab2
JB
4863 err = ieee80211_get_ratemask(sband, rates, n_rates,
4864 &ibss.basic_rates);
4865 if (err)
4866 return err;
fbd2c8dc 4867 }
dd5b4cc7
FF
4868
4869 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4870 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4871 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4872 return -EINVAL;
fbd2c8dc 4873
4c476991
JB
4874 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4875 connkeys = nl80211_parse_connkeys(rdev,
4876 info->attrs[NL80211_ATTR_KEYS]);
4877 if (IS_ERR(connkeys))
4878 return PTR_ERR(connkeys);
4879 }
04a773ad 4880
267335d6
AQ
4881 ibss.control_port =
4882 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
4883
4c476991 4884 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4885 if (err)
4886 kfree(connkeys);
04a773ad
JB
4887 return err;
4888}
4889
4890static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4891{
4c476991
JB
4892 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4893 struct net_device *dev = info->user_ptr[1];
04a773ad 4894
4c476991
JB
4895 if (!rdev->ops->leave_ibss)
4896 return -EOPNOTSUPP;
04a773ad 4897
4c476991
JB
4898 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4899 return -EOPNOTSUPP;
04a773ad 4900
4c476991 4901 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4902}
4903
aff89a9b
JB
4904#ifdef CONFIG_NL80211_TESTMODE
4905static struct genl_multicast_group nl80211_testmode_mcgrp = {
4906 .name = "testmode",
4907};
4908
4909static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4910{
4c476991 4911 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4912 int err;
4913
4914 if (!info->attrs[NL80211_ATTR_TESTDATA])
4915 return -EINVAL;
4916
aff89a9b
JB
4917 err = -EOPNOTSUPP;
4918 if (rdev->ops->testmode_cmd) {
4919 rdev->testmode_info = info;
4920 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4921 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4922 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4923 rdev->testmode_info = NULL;
4924 }
4925
aff89a9b
JB
4926 return err;
4927}
4928
71063f0e
WYG
4929static int nl80211_testmode_dump(struct sk_buff *skb,
4930 struct netlink_callback *cb)
4931{
00918d33 4932 struct cfg80211_registered_device *rdev;
71063f0e
WYG
4933 int err;
4934 long phy_idx;
4935 void *data = NULL;
4936 int data_len = 0;
4937
4938 if (cb->args[0]) {
4939 /*
4940 * 0 is a valid index, but not valid for args[0],
4941 * so we need to offset by 1.
4942 */
4943 phy_idx = cb->args[0] - 1;
4944 } else {
4945 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
4946 nl80211_fam.attrbuf, nl80211_fam.maxattr,
4947 nl80211_policy);
4948 if (err)
4949 return err;
00918d33
JB
4950 if (nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]) {
4951 phy_idx = nla_get_u32(
4952 nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
4953 } else {
4954 struct net_device *netdev;
4955
4956 err = get_rdev_dev_by_ifindex(sock_net(skb->sk),
4957 nl80211_fam.attrbuf,
4958 &rdev, &netdev);
4959 if (err)
4960 return err;
4961 dev_put(netdev);
4962 phy_idx = rdev->wiphy_idx;
4963 cfg80211_unlock_rdev(rdev);
4964 }
71063f0e
WYG
4965 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
4966 cb->args[1] =
4967 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
4968 }
4969
4970 if (cb->args[1]) {
4971 data = nla_data((void *)cb->args[1]);
4972 data_len = nla_len((void *)cb->args[1]);
4973 }
4974
4975 mutex_lock(&cfg80211_mutex);
00918d33
JB
4976 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
4977 if (!rdev) {
71063f0e
WYG
4978 mutex_unlock(&cfg80211_mutex);
4979 return -ENOENT;
4980 }
00918d33 4981 cfg80211_lock_rdev(rdev);
71063f0e
WYG
4982 mutex_unlock(&cfg80211_mutex);
4983
00918d33 4984 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
4985 err = -EOPNOTSUPP;
4986 goto out_err;
4987 }
4988
4989 while (1) {
4990 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
4991 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4992 NL80211_CMD_TESTMODE);
4993 struct nlattr *tmdata;
4994
00918d33 4995 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx) < 0) {
71063f0e
WYG
4996 genlmsg_cancel(skb, hdr);
4997 break;
4998 }
4999
5000 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5001 if (!tmdata) {
5002 genlmsg_cancel(skb, hdr);
5003 break;
5004 }
00918d33
JB
5005 err = rdev->ops->testmode_dump(&rdev->wiphy, skb, cb,
5006 data, data_len);
71063f0e
WYG
5007 nla_nest_end(skb, tmdata);
5008
5009 if (err == -ENOBUFS || err == -ENOENT) {
5010 genlmsg_cancel(skb, hdr);
5011 break;
5012 } else if (err) {
5013 genlmsg_cancel(skb, hdr);
5014 goto out_err;
5015 }
5016
5017 genlmsg_end(skb, hdr);
5018 }
5019
5020 err = skb->len;
5021 /* see above */
5022 cb->args[0] = phy_idx + 1;
5023 out_err:
00918d33 5024 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5025 return err;
5026}
5027
aff89a9b
JB
5028static struct sk_buff *
5029__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
5030 int approxlen, u32 pid, u32 seq, gfp_t gfp)
5031{
5032 struct sk_buff *skb;
5033 void *hdr;
5034 struct nlattr *data;
5035
5036 skb = nlmsg_new(approxlen + 100, gfp);
5037 if (!skb)
5038 return NULL;
5039
5040 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
5041 if (!hdr) {
5042 kfree_skb(skb);
5043 return NULL;
5044 }
5045
5046 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5047 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5048
5049 ((void **)skb->cb)[0] = rdev;
5050 ((void **)skb->cb)[1] = hdr;
5051 ((void **)skb->cb)[2] = data;
5052
5053 return skb;
5054
5055 nla_put_failure:
5056 kfree_skb(skb);
5057 return NULL;
5058}
5059
5060struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5061 int approxlen)
5062{
5063 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5064
5065 if (WARN_ON(!rdev->testmode_info))
5066 return NULL;
5067
5068 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
5069 rdev->testmode_info->snd_pid,
5070 rdev->testmode_info->snd_seq,
5071 GFP_KERNEL);
5072}
5073EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5074
5075int cfg80211_testmode_reply(struct sk_buff *skb)
5076{
5077 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5078 void *hdr = ((void **)skb->cb)[1];
5079 struct nlattr *data = ((void **)skb->cb)[2];
5080
5081 if (WARN_ON(!rdev->testmode_info)) {
5082 kfree_skb(skb);
5083 return -EINVAL;
5084 }
5085
5086 nla_nest_end(skb, data);
5087 genlmsg_end(skb, hdr);
5088 return genlmsg_reply(skb, rdev->testmode_info);
5089}
5090EXPORT_SYMBOL(cfg80211_testmode_reply);
5091
5092struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5093 int approxlen, gfp_t gfp)
5094{
5095 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5096
5097 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5098}
5099EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5100
5101void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5102{
5103 void *hdr = ((void **)skb->cb)[1];
5104 struct nlattr *data = ((void **)skb->cb)[2];
5105
5106 nla_nest_end(skb, data);
5107 genlmsg_end(skb, hdr);
5108 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5109}
5110EXPORT_SYMBOL(cfg80211_testmode_event);
5111#endif
5112
b23aa676
SO
5113static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5114{
4c476991
JB
5115 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5116 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5117 struct cfg80211_connect_params connect;
5118 struct wiphy *wiphy;
fffd0934 5119 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5120 int err;
5121
5122 memset(&connect, 0, sizeof(connect));
5123
5124 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5125 return -EINVAL;
5126
5127 if (!info->attrs[NL80211_ATTR_SSID] ||
5128 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5129 return -EINVAL;
5130
5131 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5132 connect.auth_type =
5133 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
5134 if (!nl80211_valid_auth_type(connect.auth_type))
5135 return -EINVAL;
5136 } else
5137 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5138
5139 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5140
c0692b8f 5141 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5142 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5143 if (err)
5144 return err;
b23aa676 5145
074ac8df 5146 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5147 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5148 return -EOPNOTSUPP;
b23aa676 5149
79c97e97 5150 wiphy = &rdev->wiphy;
b23aa676 5151
4486ea98
BS
5152 connect.bg_scan_period = -1;
5153 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5154 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5155 connect.bg_scan_period =
5156 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5157 }
5158
b23aa676
SO
5159 if (info->attrs[NL80211_ATTR_MAC])
5160 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5161 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5162 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5163
5164 if (info->attrs[NL80211_ATTR_IE]) {
5165 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5166 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5167 }
5168
5169 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5170 connect.channel =
5171 ieee80211_get_channel(wiphy,
5172 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5173 if (!connect.channel ||
4c476991
JB
5174 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5175 return -EINVAL;
b23aa676
SO
5176 }
5177
fffd0934
JB
5178 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5179 connkeys = nl80211_parse_connkeys(rdev,
5180 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
5181 if (IS_ERR(connkeys))
5182 return PTR_ERR(connkeys);
fffd0934
JB
5183 }
5184
7e7c8926
BG
5185 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5186 connect.flags |= ASSOC_REQ_DISABLE_HT;
5187
5188 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5189 memcpy(&connect.ht_capa_mask,
5190 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5191 sizeof(connect.ht_capa_mask));
5192
5193 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5194 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5195 return -EINVAL;
5196 memcpy(&connect.ht_capa,
5197 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5198 sizeof(connect.ht_capa));
5199 }
5200
fffd0934 5201 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5202 if (err)
5203 kfree(connkeys);
b23aa676
SO
5204 return err;
5205}
5206
5207static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5208{
4c476991
JB
5209 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5210 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5211 u16 reason;
5212
5213 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5214 reason = WLAN_REASON_DEAUTH_LEAVING;
5215 else
5216 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5217
5218 if (reason == 0)
5219 return -EINVAL;
5220
074ac8df 5221 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5222 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5223 return -EOPNOTSUPP;
b23aa676 5224
4c476991 5225 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
5226}
5227
463d0183
JB
5228static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5229{
4c476991 5230 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
5231 struct net *net;
5232 int err;
5233 u32 pid;
5234
5235 if (!info->attrs[NL80211_ATTR_PID])
5236 return -EINVAL;
5237
5238 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5239
463d0183 5240 net = get_net_ns_by_pid(pid);
4c476991
JB
5241 if (IS_ERR(net))
5242 return PTR_ERR(net);
463d0183
JB
5243
5244 err = 0;
5245
5246 /* check if anything to do */
4c476991
JB
5247 if (!net_eq(wiphy_net(&rdev->wiphy), net))
5248 err = cfg80211_switch_netns(rdev, net);
463d0183 5249
463d0183 5250 put_net(net);
463d0183
JB
5251 return err;
5252}
5253
67fbb16b
SO
5254static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5255{
4c476991 5256 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
5257 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5258 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 5259 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
5260 struct cfg80211_pmksa pmksa;
5261
5262 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5263
5264 if (!info->attrs[NL80211_ATTR_MAC])
5265 return -EINVAL;
5266
5267 if (!info->attrs[NL80211_ATTR_PMKID])
5268 return -EINVAL;
5269
67fbb16b
SO
5270 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5271 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5272
074ac8df 5273 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5274 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5275 return -EOPNOTSUPP;
67fbb16b
SO
5276
5277 switch (info->genlhdr->cmd) {
5278 case NL80211_CMD_SET_PMKSA:
5279 rdev_ops = rdev->ops->set_pmksa;
5280 break;
5281 case NL80211_CMD_DEL_PMKSA:
5282 rdev_ops = rdev->ops->del_pmksa;
5283 break;
5284 default:
5285 WARN_ON(1);
5286 break;
5287 }
5288
4c476991
JB
5289 if (!rdev_ops)
5290 return -EOPNOTSUPP;
67fbb16b 5291
4c476991 5292 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
5293}
5294
5295static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5296{
4c476991
JB
5297 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5298 struct net_device *dev = info->user_ptr[1];
67fbb16b 5299
074ac8df 5300 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5301 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5302 return -EOPNOTSUPP;
67fbb16b 5303
4c476991
JB
5304 if (!rdev->ops->flush_pmksa)
5305 return -EOPNOTSUPP;
67fbb16b 5306
4c476991 5307 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5308}
5309
109086ce
AN
5310static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5311{
5312 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5313 struct net_device *dev = info->user_ptr[1];
5314 u8 action_code, dialog_token;
5315 u16 status_code;
5316 u8 *peer;
5317
5318 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5319 !rdev->ops->tdls_mgmt)
5320 return -EOPNOTSUPP;
5321
5322 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5323 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5324 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5325 !info->attrs[NL80211_ATTR_IE] ||
5326 !info->attrs[NL80211_ATTR_MAC])
5327 return -EINVAL;
5328
5329 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5330 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5331 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5332 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5333
5334 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5335 dialog_token, status_code,
5336 nla_data(info->attrs[NL80211_ATTR_IE]),
5337 nla_len(info->attrs[NL80211_ATTR_IE]));
5338}
5339
5340static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5341{
5342 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5343 struct net_device *dev = info->user_ptr[1];
5344 enum nl80211_tdls_operation operation;
5345 u8 *peer;
5346
5347 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5348 !rdev->ops->tdls_oper)
5349 return -EOPNOTSUPP;
5350
5351 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5352 !info->attrs[NL80211_ATTR_MAC])
5353 return -EINVAL;
5354
5355 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5356 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5357
5358 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5359}
5360
9588bbd5
JM
5361static int nl80211_remain_on_channel(struct sk_buff *skb,
5362 struct genl_info *info)
5363{
4c476991
JB
5364 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5365 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5366 struct ieee80211_channel *chan;
5367 struct sk_buff *msg;
5368 void *hdr;
5369 u64 cookie;
5370 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5371 u32 freq, duration;
5372 int err;
5373
5374 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5375 !info->attrs[NL80211_ATTR_DURATION])
5376 return -EINVAL;
5377
5378 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5379
5380 /*
5381 * We should be on that channel for at least one jiffie,
5382 * and more than 5 seconds seems excessive.
5383 */
a293911d
JB
5384 if (!duration || !msecs_to_jiffies(duration) ||
5385 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5386 return -EINVAL;
5387
7c4ef712
JB
5388 if (!rdev->ops->remain_on_channel ||
5389 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
4c476991 5390 return -EOPNOTSUPP;
9588bbd5 5391
9588bbd5
JM
5392 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5393 channel_type = nla_get_u32(
5394 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5395 if (channel_type != NL80211_CHAN_NO_HT &&
5396 channel_type != NL80211_CHAN_HT20 &&
5397 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5398 channel_type != NL80211_CHAN_HT40MINUS)
5399 return -EINVAL;
9588bbd5
JM
5400 }
5401
5402 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5403 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5404 if (chan == NULL)
5405 return -EINVAL;
9588bbd5
JM
5406
5407 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5408 if (!msg)
5409 return -ENOMEM;
9588bbd5
JM
5410
5411 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5412 NL80211_CMD_REMAIN_ON_CHANNEL);
5413
5414 if (IS_ERR(hdr)) {
5415 err = PTR_ERR(hdr);
5416 goto free_msg;
5417 }
5418
5419 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5420 channel_type, duration, &cookie);
5421
5422 if (err)
5423 goto free_msg;
5424
5425 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5426
5427 genlmsg_end(msg, hdr);
4c476991
JB
5428
5429 return genlmsg_reply(msg, info);
9588bbd5
JM
5430
5431 nla_put_failure:
5432 err = -ENOBUFS;
5433 free_msg:
5434 nlmsg_free(msg);
9588bbd5
JM
5435 return err;
5436}
5437
5438static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5439 struct genl_info *info)
5440{
4c476991
JB
5441 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5442 struct net_device *dev = info->user_ptr[1];
9588bbd5 5443 u64 cookie;
9588bbd5
JM
5444
5445 if (!info->attrs[NL80211_ATTR_COOKIE])
5446 return -EINVAL;
5447
4c476991
JB
5448 if (!rdev->ops->cancel_remain_on_channel)
5449 return -EOPNOTSUPP;
9588bbd5 5450
9588bbd5
JM
5451 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5452
4c476991 5453 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5454}
5455
13ae75b1
JM
5456static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5457 u8 *rates, u8 rates_len)
5458{
5459 u8 i;
5460 u32 mask = 0;
5461
5462 for (i = 0; i < rates_len; i++) {
5463 int rate = (rates[i] & 0x7f) * 5;
5464 int ridx;
5465 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5466 struct ieee80211_rate *srate =
5467 &sband->bitrates[ridx];
5468 if (rate == srate->bitrate) {
5469 mask |= 1 << ridx;
5470 break;
5471 }
5472 }
5473 if (ridx == sband->n_bitrates)
5474 return 0; /* rate not found */
5475 }
5476
5477 return mask;
5478}
5479
24db78c0
SW
5480static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
5481 u8 *rates, u8 rates_len,
5482 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
5483{
5484 u8 i;
5485
5486 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
5487
5488 for (i = 0; i < rates_len; i++) {
5489 int ridx, rbit;
5490
5491 ridx = rates[i] / 8;
5492 rbit = BIT(rates[i] % 8);
5493
5494 /* check validity */
910570b5 5495 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
5496 return false;
5497
5498 /* check availability */
5499 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5500 mcs[ridx] |= rbit;
5501 else
5502 return false;
5503 }
5504
5505 return true;
5506}
5507
b54452b0 5508static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5509 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5510 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
5511 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
5512 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
5513};
5514
5515static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5516 struct genl_info *info)
5517{
5518 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5519 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5520 struct cfg80211_bitrate_mask mask;
4c476991
JB
5521 int rem, i;
5522 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5523 struct nlattr *tx_rates;
5524 struct ieee80211_supported_band *sband;
5525
5526 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5527 return -EINVAL;
5528
4c476991
JB
5529 if (!rdev->ops->set_bitrate_mask)
5530 return -EOPNOTSUPP;
13ae75b1
JM
5531
5532 memset(&mask, 0, sizeof(mask));
5533 /* Default to all rates enabled */
5534 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5535 sband = rdev->wiphy.bands[i];
5536 mask.control[i].legacy =
5537 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
5538 if (sband)
5539 memcpy(mask.control[i].mcs,
5540 sband->ht_cap.mcs.rx_mask,
5541 sizeof(mask.control[i].mcs));
5542 else
5543 memset(mask.control[i].mcs, 0,
5544 sizeof(mask.control[i].mcs));
13ae75b1
JM
5545 }
5546
5547 /*
5548 * The nested attribute uses enum nl80211_band as the index. This maps
5549 * directly to the enum ieee80211_band values used in cfg80211.
5550 */
24db78c0 5551 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
5552 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5553 {
5554 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5555 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5556 return -EINVAL;
13ae75b1 5557 sband = rdev->wiphy.bands[band];
4c476991
JB
5558 if (sband == NULL)
5559 return -EINVAL;
13ae75b1
JM
5560 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5561 nla_len(tx_rates), nl80211_txattr_policy);
5562 if (tb[NL80211_TXRATE_LEGACY]) {
5563 mask.control[band].legacy = rateset_to_mask(
5564 sband,
5565 nla_data(tb[NL80211_TXRATE_LEGACY]),
5566 nla_len(tb[NL80211_TXRATE_LEGACY]));
24db78c0
SW
5567 }
5568 if (tb[NL80211_TXRATE_MCS]) {
5569 if (!ht_rateset_to_mask(
5570 sband,
5571 nla_data(tb[NL80211_TXRATE_MCS]),
5572 nla_len(tb[NL80211_TXRATE_MCS]),
5573 mask.control[band].mcs))
5574 return -EINVAL;
5575 }
5576
5577 if (mask.control[band].legacy == 0) {
5578 /* don't allow empty legacy rates if HT
5579 * is not even supported. */
5580 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
5581 return -EINVAL;
5582
5583 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5584 if (mask.control[band].mcs[i])
5585 break;
5586
5587 /* legacy and mcs rates may not be both empty */
5588 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 5589 return -EINVAL;
13ae75b1
JM
5590 }
5591 }
5592
4c476991 5593 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5594}
5595
2e161f78 5596static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5597{
4c476991
JB
5598 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5599 struct net_device *dev = info->user_ptr[1];
2e161f78 5600 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5601
5602 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5603 return -EINVAL;
5604
2e161f78
JB
5605 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5606 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5607
9d38d85d 5608 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5609 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5610 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5611 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5612 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5613 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5614 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5615 return -EOPNOTSUPP;
026331c4
JM
5616
5617 /* not much point in registering if we can't reply */
4c476991
JB
5618 if (!rdev->ops->mgmt_tx)
5619 return -EOPNOTSUPP;
026331c4 5620
4c476991 5621 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 5622 frame_type,
026331c4
JM
5623 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5624 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
5625}
5626
2e161f78 5627static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5628{
4c476991
JB
5629 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5630 struct net_device *dev = info->user_ptr[1];
026331c4
JM
5631 struct ieee80211_channel *chan;
5632 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 5633 bool channel_type_valid = false;
026331c4
JM
5634 u32 freq;
5635 int err;
d64d373f 5636 void *hdr = NULL;
026331c4 5637 u64 cookie;
e247bd90 5638 struct sk_buff *msg = NULL;
f7ca38df 5639 unsigned int wait = 0;
e247bd90
JB
5640 bool offchan, no_cck, dont_wait_for_ack;
5641
5642 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4
JM
5643
5644 if (!info->attrs[NL80211_ATTR_FRAME] ||
5645 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5646 return -EINVAL;
5647
4c476991
JB
5648 if (!rdev->ops->mgmt_tx)
5649 return -EOPNOTSUPP;
026331c4 5650
9d38d85d 5651 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5652 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5653 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5654 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5655 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5656 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5657 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5658 return -EOPNOTSUPP;
026331c4 5659
f7ca38df 5660 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 5661 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
5662 return -EINVAL;
5663 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5664 }
5665
026331c4
JM
5666 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5667 channel_type = nla_get_u32(
5668 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5669 if (channel_type != NL80211_CHAN_NO_HT &&
5670 channel_type != NL80211_CHAN_HT20 &&
5671 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5672 channel_type != NL80211_CHAN_HT40MINUS)
5673 return -EINVAL;
252aa631 5674 channel_type_valid = true;
026331c4
JM
5675 }
5676
f7ca38df
JB
5677 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5678
7c4ef712
JB
5679 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
5680 return -EINVAL;
5681
e9f935e3
RM
5682 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5683
026331c4
JM
5684 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5685 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5686 if (chan == NULL)
5687 return -EINVAL;
026331c4 5688
e247bd90
JB
5689 if (!dont_wait_for_ack) {
5690 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5691 if (!msg)
5692 return -ENOMEM;
026331c4 5693
e247bd90
JB
5694 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5695 NL80211_CMD_FRAME);
026331c4 5696
e247bd90
JB
5697 if (IS_ERR(hdr)) {
5698 err = PTR_ERR(hdr);
5699 goto free_msg;
5700 }
026331c4 5701 }
e247bd90 5702
f7ca38df
JB
5703 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5704 channel_type_valid, wait,
2e161f78
JB
5705 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5706 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 5707 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
5708 if (err)
5709 goto free_msg;
5710
e247bd90
JB
5711 if (msg) {
5712 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
026331c4 5713
e247bd90
JB
5714 genlmsg_end(msg, hdr);
5715 return genlmsg_reply(msg, info);
5716 }
5717
5718 return 0;
026331c4
JM
5719
5720 nla_put_failure:
5721 err = -ENOBUFS;
5722 free_msg:
5723 nlmsg_free(msg);
026331c4
JM
5724 return err;
5725}
5726
f7ca38df
JB
5727static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5728{
5729 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5730 struct net_device *dev = info->user_ptr[1];
5731 u64 cookie;
5732
5733 if (!info->attrs[NL80211_ATTR_COOKIE])
5734 return -EINVAL;
5735
5736 if (!rdev->ops->mgmt_tx_cancel_wait)
5737 return -EOPNOTSUPP;
5738
5739 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5740 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5741 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5742 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5743 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5744 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5745 return -EOPNOTSUPP;
5746
5747 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5748
5749 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5750}
5751
ffb9eb3d
KV
5752static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5753{
4c476991 5754 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 5755 struct wireless_dev *wdev;
4c476991 5756 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5757 u8 ps_state;
5758 bool state;
5759 int err;
5760
4c476991
JB
5761 if (!info->attrs[NL80211_ATTR_PS_STATE])
5762 return -EINVAL;
ffb9eb3d
KV
5763
5764 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5765
4c476991
JB
5766 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5767 return -EINVAL;
ffb9eb3d
KV
5768
5769 wdev = dev->ieee80211_ptr;
5770
4c476991
JB
5771 if (!rdev->ops->set_power_mgmt)
5772 return -EOPNOTSUPP;
ffb9eb3d
KV
5773
5774 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5775
5776 if (state == wdev->ps)
4c476991 5777 return 0;
ffb9eb3d 5778
4c476991
JB
5779 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5780 wdev->ps_timeout);
5781 if (!err)
5782 wdev->ps = state;
ffb9eb3d
KV
5783 return err;
5784}
5785
5786static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5787{
4c476991 5788 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
5789 enum nl80211_ps_state ps_state;
5790 struct wireless_dev *wdev;
4c476991 5791 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5792 struct sk_buff *msg;
5793 void *hdr;
5794 int err;
5795
ffb9eb3d
KV
5796 wdev = dev->ieee80211_ptr;
5797
4c476991
JB
5798 if (!rdev->ops->set_power_mgmt)
5799 return -EOPNOTSUPP;
ffb9eb3d
KV
5800
5801 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5802 if (!msg)
5803 return -ENOMEM;
ffb9eb3d
KV
5804
5805 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5806 NL80211_CMD_GET_POWER_SAVE);
5807 if (!hdr) {
4c476991 5808 err = -ENOBUFS;
ffb9eb3d
KV
5809 goto free_msg;
5810 }
5811
5812 if (wdev->ps)
5813 ps_state = NL80211_PS_ENABLED;
5814 else
5815 ps_state = NL80211_PS_DISABLED;
5816
5817 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5818
5819 genlmsg_end(msg, hdr);
4c476991 5820 return genlmsg_reply(msg, info);
ffb9eb3d 5821
4c476991 5822 nla_put_failure:
ffb9eb3d 5823 err = -ENOBUFS;
4c476991 5824 free_msg:
ffb9eb3d 5825 nlmsg_free(msg);
ffb9eb3d
KV
5826 return err;
5827}
5828
d6dc1a38
JO
5829static struct nla_policy
5830nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5831 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5832 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5833 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5834};
5835
5836static int nl80211_set_cqm_rssi(struct genl_info *info,
5837 s32 threshold, u32 hysteresis)
5838{
4c476991 5839 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 5840 struct wireless_dev *wdev;
4c476991 5841 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
5842
5843 if (threshold > 0)
5844 return -EINVAL;
5845
d6dc1a38
JO
5846 wdev = dev->ieee80211_ptr;
5847
4c476991
JB
5848 if (!rdev->ops->set_cqm_rssi_config)
5849 return -EOPNOTSUPP;
d6dc1a38 5850
074ac8df 5851 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5852 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
5853 return -EOPNOTSUPP;
d6dc1a38 5854
4c476991
JB
5855 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5856 threshold, hysteresis);
d6dc1a38
JO
5857}
5858
5859static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5860{
5861 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5862 struct nlattr *cqm;
5863 int err;
5864
5865 cqm = info->attrs[NL80211_ATTR_CQM];
5866 if (!cqm) {
5867 err = -EINVAL;
5868 goto out;
5869 }
5870
5871 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5872 nl80211_attr_cqm_policy);
5873 if (err)
5874 goto out;
5875
5876 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5877 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5878 s32 threshold;
5879 u32 hysteresis;
5880 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5881 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5882 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5883 } else
5884 err = -EINVAL;
5885
5886out:
5887 return err;
5888}
5889
29cbe68c
JB
5890static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5891{
5892 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5893 struct net_device *dev = info->user_ptr[1];
5894 struct mesh_config cfg;
c80d545d 5895 struct mesh_setup setup;
29cbe68c
JB
5896 int err;
5897
5898 /* start with default */
5899 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 5900 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 5901
24bdd9f4 5902 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 5903 /* and parse parameters if given */
24bdd9f4 5904 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
5905 if (err)
5906 return err;
5907 }
5908
5909 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5910 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5911 return -EINVAL;
5912
c80d545d
JC
5913 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5914 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5915
4bb62344
CYY
5916 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5917 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
5918 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5919 return -EINVAL;
5920
c80d545d
JC
5921 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5922 /* parse additional setup parameters if given */
5923 err = nl80211_parse_mesh_setup(info, &setup);
5924 if (err)
5925 return err;
5926 }
5927
5928 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
5929}
5930
5931static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5932{
5933 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5934 struct net_device *dev = info->user_ptr[1];
5935
5936 return cfg80211_leave_mesh(rdev, dev);
5937}
5938
ff1b6e69
JB
5939static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5940{
5941 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5942 struct sk_buff *msg;
5943 void *hdr;
5944
5945 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5946 return -EOPNOTSUPP;
5947
5948 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5949 if (!msg)
5950 return -ENOMEM;
5951
5952 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5953 NL80211_CMD_GET_WOWLAN);
5954 if (!hdr)
5955 goto nla_put_failure;
5956
5957 if (rdev->wowlan) {
5958 struct nlattr *nl_wowlan;
5959
5960 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5961 if (!nl_wowlan)
5962 goto nla_put_failure;
5963
5964 if (rdev->wowlan->any)
5965 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5966 if (rdev->wowlan->disconnect)
5967 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5968 if (rdev->wowlan->magic_pkt)
5969 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
5970 if (rdev->wowlan->gtk_rekey_failure)
5971 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
5972 if (rdev->wowlan->eap_identity_req)
5973 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
5974 if (rdev->wowlan->four_way_handshake)
5975 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
5976 if (rdev->wowlan->rfkill_release)
5977 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
5978 if (rdev->wowlan->n_patterns) {
5979 struct nlattr *nl_pats, *nl_pat;
5980 int i, pat_len;
5981
5982 nl_pats = nla_nest_start(msg,
5983 NL80211_WOWLAN_TRIG_PKT_PATTERN);
5984 if (!nl_pats)
5985 goto nla_put_failure;
5986
5987 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5988 nl_pat = nla_nest_start(msg, i + 1);
5989 if (!nl_pat)
5990 goto nla_put_failure;
5991 pat_len = rdev->wowlan->patterns[i].pattern_len;
5992 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5993 DIV_ROUND_UP(pat_len, 8),
5994 rdev->wowlan->patterns[i].mask);
5995 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5996 pat_len,
5997 rdev->wowlan->patterns[i].pattern);
5998 nla_nest_end(msg, nl_pat);
5999 }
6000 nla_nest_end(msg, nl_pats);
6001 }
6002
6003 nla_nest_end(msg, nl_wowlan);
6004 }
6005
6006 genlmsg_end(msg, hdr);
6007 return genlmsg_reply(msg, info);
6008
6009nla_put_failure:
6010 nlmsg_free(msg);
6011 return -ENOBUFS;
6012}
6013
6014static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6015{
6016 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6017 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
6018 struct cfg80211_wowlan no_triggers = {};
6019 struct cfg80211_wowlan new_triggers = {};
6020 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6021 int err, i;
6d52563f 6022 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6023
6024 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6025 return -EOPNOTSUPP;
6026
6027 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
6028 goto no_triggers;
6029
6030 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6031 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6032 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6033 nl80211_wowlan_policy);
6034 if (err)
6035 return err;
6036
6037 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6038 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6039 return -EINVAL;
6040 new_triggers.any = true;
6041 }
6042
6043 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6044 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6045 return -EINVAL;
6046 new_triggers.disconnect = true;
6047 }
6048
6049 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6050 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6051 return -EINVAL;
6052 new_triggers.magic_pkt = true;
6053 }
6054
77dbbb13
JB
6055 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6056 return -EINVAL;
6057
6058 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6059 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6060 return -EINVAL;
6061 new_triggers.gtk_rekey_failure = true;
6062 }
6063
6064 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6065 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6066 return -EINVAL;
6067 new_triggers.eap_identity_req = true;
6068 }
6069
6070 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6071 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6072 return -EINVAL;
6073 new_triggers.four_way_handshake = true;
6074 }
6075
6076 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6077 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6078 return -EINVAL;
6079 new_triggers.rfkill_release = true;
6080 }
6081
ff1b6e69
JB
6082 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6083 struct nlattr *pat;
6084 int n_patterns = 0;
6085 int rem, pat_len, mask_len;
6086 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6087
6088 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6089 rem)
6090 n_patterns++;
6091 if (n_patterns > wowlan->n_patterns)
6092 return -EINVAL;
6093
6094 new_triggers.patterns = kcalloc(n_patterns,
6095 sizeof(new_triggers.patterns[0]),
6096 GFP_KERNEL);
6097 if (!new_triggers.patterns)
6098 return -ENOMEM;
6099
6100 new_triggers.n_patterns = n_patterns;
6101 i = 0;
6102
6103 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6104 rem) {
6105 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6106 nla_data(pat), nla_len(pat), NULL);
6107 err = -EINVAL;
6108 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6109 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6110 goto error;
6111 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6112 mask_len = DIV_ROUND_UP(pat_len, 8);
6113 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6114 mask_len)
6115 goto error;
6116 if (pat_len > wowlan->pattern_max_len ||
6117 pat_len < wowlan->pattern_min_len)
6118 goto error;
6119
6120 new_triggers.patterns[i].mask =
6121 kmalloc(mask_len + pat_len, GFP_KERNEL);
6122 if (!new_triggers.patterns[i].mask) {
6123 err = -ENOMEM;
6124 goto error;
6125 }
6126 new_triggers.patterns[i].pattern =
6127 new_triggers.patterns[i].mask + mask_len;
6128 memcpy(new_triggers.patterns[i].mask,
6129 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6130 mask_len);
6131 new_triggers.patterns[i].pattern_len = pat_len;
6132 memcpy(new_triggers.patterns[i].pattern,
6133 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6134 pat_len);
6135 i++;
6136 }
6137 }
6138
6139 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
6140 struct cfg80211_wowlan *ntrig;
6141 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
6142 GFP_KERNEL);
6143 if (!ntrig) {
6144 err = -ENOMEM;
6145 goto error;
6146 }
6147 cfg80211_rdev_free_wowlan(rdev);
6148 rdev->wowlan = ntrig;
6149 } else {
6150 no_triggers:
6151 cfg80211_rdev_free_wowlan(rdev);
6152 rdev->wowlan = NULL;
6153 }
6154
6d52563f
JB
6155 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
6156 rdev->ops->set_wakeup(&rdev->wiphy, rdev->wowlan);
6157
ff1b6e69
JB
6158 return 0;
6159 error:
6160 for (i = 0; i < new_triggers.n_patterns; i++)
6161 kfree(new_triggers.patterns[i].mask);
6162 kfree(new_triggers.patterns);
6163 return err;
6164}
6165
e5497d76
JB
6166static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6167{
6168 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6169 struct net_device *dev = info->user_ptr[1];
6170 struct wireless_dev *wdev = dev->ieee80211_ptr;
6171 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6172 struct cfg80211_gtk_rekey_data rekey_data;
6173 int err;
6174
6175 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6176 return -EINVAL;
6177
6178 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6179 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6180 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6181 nl80211_rekey_policy);
6182 if (err)
6183 return err;
6184
6185 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6186 return -ERANGE;
6187 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6188 return -ERANGE;
6189 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6190 return -ERANGE;
6191
6192 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6193 NL80211_KEK_LEN);
6194 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6195 NL80211_KCK_LEN);
6196 memcpy(rekey_data.replay_ctr,
6197 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6198 NL80211_REPLAY_CTR_LEN);
6199
6200 wdev_lock(wdev);
6201 if (!wdev->current_bss) {
6202 err = -ENOTCONN;
6203 goto out;
6204 }
6205
6206 if (!rdev->ops->set_rekey_data) {
6207 err = -EOPNOTSUPP;
6208 goto out;
6209 }
6210
6211 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
6212 out:
6213 wdev_unlock(wdev);
6214 return err;
6215}
6216
28946da7
JB
6217static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6218 struct genl_info *info)
6219{
6220 struct net_device *dev = info->user_ptr[1];
6221 struct wireless_dev *wdev = dev->ieee80211_ptr;
6222
6223 if (wdev->iftype != NL80211_IFTYPE_AP &&
6224 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6225 return -EINVAL;
6226
6227 if (wdev->ap_unexpected_nlpid)
6228 return -EBUSY;
6229
6230 wdev->ap_unexpected_nlpid = info->snd_pid;
6231 return 0;
6232}
6233
7f6cf311
JB
6234static int nl80211_probe_client(struct sk_buff *skb,
6235 struct genl_info *info)
6236{
6237 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6238 struct net_device *dev = info->user_ptr[1];
6239 struct wireless_dev *wdev = dev->ieee80211_ptr;
6240 struct sk_buff *msg;
6241 void *hdr;
6242 const u8 *addr;
6243 u64 cookie;
6244 int err;
6245
6246 if (wdev->iftype != NL80211_IFTYPE_AP &&
6247 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6248 return -EOPNOTSUPP;
6249
6250 if (!info->attrs[NL80211_ATTR_MAC])
6251 return -EINVAL;
6252
6253 if (!rdev->ops->probe_client)
6254 return -EOPNOTSUPP;
6255
6256 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6257 if (!msg)
6258 return -ENOMEM;
6259
6260 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6261 NL80211_CMD_PROBE_CLIENT);
6262
6263 if (IS_ERR(hdr)) {
6264 err = PTR_ERR(hdr);
6265 goto free_msg;
6266 }
6267
6268 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6269
6270 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
6271 if (err)
6272 goto free_msg;
6273
6274 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6275
6276 genlmsg_end(msg, hdr);
6277
6278 return genlmsg_reply(msg, info);
6279
6280 nla_put_failure:
6281 err = -ENOBUFS;
6282 free_msg:
6283 nlmsg_free(msg);
6284 return err;
6285}
6286
5e760230
JB
6287static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
6288{
6289 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6290
6291 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
6292 return -EOPNOTSUPP;
6293
6294 if (rdev->ap_beacons_nlpid)
6295 return -EBUSY;
6296
6297 rdev->ap_beacons_nlpid = info->snd_pid;
6298
6299 return 0;
6300}
6301
4c476991
JB
6302#define NL80211_FLAG_NEED_WIPHY 0x01
6303#define NL80211_FLAG_NEED_NETDEV 0x02
6304#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
6305#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
6306#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
6307 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
6308
6309static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
6310 struct genl_info *info)
6311{
6312 struct cfg80211_registered_device *rdev;
6313 struct net_device *dev;
6314 int err;
6315 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
6316
6317 if (rtnl)
6318 rtnl_lock();
6319
6320 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
6321 rdev = cfg80211_get_dev_from_info(info);
6322 if (IS_ERR(rdev)) {
6323 if (rtnl)
6324 rtnl_unlock();
6325 return PTR_ERR(rdev);
6326 }
6327 info->user_ptr[0] = rdev;
6328 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
00918d33
JB
6329 err = get_rdev_dev_by_ifindex(genl_info_net(info), info->attrs,
6330 &rdev, &dev);
4c476991
JB
6331 if (err) {
6332 if (rtnl)
6333 rtnl_unlock();
6334 return err;
6335 }
41265714
JB
6336 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
6337 !netif_running(dev)) {
d537f5fd
JB
6338 cfg80211_unlock_rdev(rdev);
6339 dev_put(dev);
41265714
JB
6340 if (rtnl)
6341 rtnl_unlock();
6342 return -ENETDOWN;
6343 }
4c476991
JB
6344 info->user_ptr[0] = rdev;
6345 info->user_ptr[1] = dev;
6346 }
6347
6348 return 0;
6349}
6350
6351static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
6352 struct genl_info *info)
6353{
6354 if (info->user_ptr[0])
6355 cfg80211_unlock_rdev(info->user_ptr[0]);
6356 if (info->user_ptr[1])
6357 dev_put(info->user_ptr[1]);
6358 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
6359 rtnl_unlock();
6360}
6361
55682965
JB
6362static struct genl_ops nl80211_ops[] = {
6363 {
6364 .cmd = NL80211_CMD_GET_WIPHY,
6365 .doit = nl80211_get_wiphy,
6366 .dumpit = nl80211_dump_wiphy,
6367 .policy = nl80211_policy,
6368 /* can be retrieved by unprivileged users */
4c476991 6369 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
6370 },
6371 {
6372 .cmd = NL80211_CMD_SET_WIPHY,
6373 .doit = nl80211_set_wiphy,
6374 .policy = nl80211_policy,
6375 .flags = GENL_ADMIN_PERM,
4c476991 6376 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
6377 },
6378 {
6379 .cmd = NL80211_CMD_GET_INTERFACE,
6380 .doit = nl80211_get_interface,
6381 .dumpit = nl80211_dump_interface,
6382 .policy = nl80211_policy,
6383 /* can be retrieved by unprivileged users */
4c476991 6384 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
6385 },
6386 {
6387 .cmd = NL80211_CMD_SET_INTERFACE,
6388 .doit = nl80211_set_interface,
6389 .policy = nl80211_policy,
6390 .flags = GENL_ADMIN_PERM,
4c476991
JB
6391 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6392 NL80211_FLAG_NEED_RTNL,
55682965
JB
6393 },
6394 {
6395 .cmd = NL80211_CMD_NEW_INTERFACE,
6396 .doit = nl80211_new_interface,
6397 .policy = nl80211_policy,
6398 .flags = GENL_ADMIN_PERM,
4c476991
JB
6399 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6400 NL80211_FLAG_NEED_RTNL,
55682965
JB
6401 },
6402 {
6403 .cmd = NL80211_CMD_DEL_INTERFACE,
6404 .doit = nl80211_del_interface,
6405 .policy = nl80211_policy,
41ade00f 6406 .flags = GENL_ADMIN_PERM,
4c476991
JB
6407 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6408 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6409 },
6410 {
6411 .cmd = NL80211_CMD_GET_KEY,
6412 .doit = nl80211_get_key,
6413 .policy = nl80211_policy,
6414 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6415 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6416 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6417 },
6418 {
6419 .cmd = NL80211_CMD_SET_KEY,
6420 .doit = nl80211_set_key,
6421 .policy = nl80211_policy,
6422 .flags = GENL_ADMIN_PERM,
41265714 6423 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6424 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6425 },
6426 {
6427 .cmd = NL80211_CMD_NEW_KEY,
6428 .doit = nl80211_new_key,
6429 .policy = nl80211_policy,
6430 .flags = GENL_ADMIN_PERM,
41265714 6431 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6432 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6433 },
6434 {
6435 .cmd = NL80211_CMD_DEL_KEY,
6436 .doit = nl80211_del_key,
6437 .policy = nl80211_policy,
55682965 6438 .flags = GENL_ADMIN_PERM,
41265714 6439 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6440 NL80211_FLAG_NEED_RTNL,
55682965 6441 },
ed1b6cc7
JB
6442 {
6443 .cmd = NL80211_CMD_SET_BEACON,
6444 .policy = nl80211_policy,
6445 .flags = GENL_ADMIN_PERM,
8860020e 6446 .doit = nl80211_set_beacon,
2b5f8b0b 6447 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6448 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6449 },
6450 {
8860020e 6451 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
6452 .policy = nl80211_policy,
6453 .flags = GENL_ADMIN_PERM,
8860020e 6454 .doit = nl80211_start_ap,
2b5f8b0b 6455 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6456 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6457 },
6458 {
8860020e 6459 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
6460 .policy = nl80211_policy,
6461 .flags = GENL_ADMIN_PERM,
8860020e 6462 .doit = nl80211_stop_ap,
2b5f8b0b 6463 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6464 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6465 },
5727ef1b
JB
6466 {
6467 .cmd = NL80211_CMD_GET_STATION,
6468 .doit = nl80211_get_station,
2ec600d6 6469 .dumpit = nl80211_dump_station,
5727ef1b 6470 .policy = nl80211_policy,
4c476991
JB
6471 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6472 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6473 },
6474 {
6475 .cmd = NL80211_CMD_SET_STATION,
6476 .doit = nl80211_set_station,
6477 .policy = nl80211_policy,
6478 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6479 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6480 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6481 },
6482 {
6483 .cmd = NL80211_CMD_NEW_STATION,
6484 .doit = nl80211_new_station,
6485 .policy = nl80211_policy,
6486 .flags = GENL_ADMIN_PERM,
41265714 6487 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6488 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6489 },
6490 {
6491 .cmd = NL80211_CMD_DEL_STATION,
6492 .doit = nl80211_del_station,
6493 .policy = nl80211_policy,
2ec600d6 6494 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6495 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6496 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6497 },
6498 {
6499 .cmd = NL80211_CMD_GET_MPATH,
6500 .doit = nl80211_get_mpath,
6501 .dumpit = nl80211_dump_mpath,
6502 .policy = nl80211_policy,
6503 .flags = GENL_ADMIN_PERM,
41265714 6504 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6505 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6506 },
6507 {
6508 .cmd = NL80211_CMD_SET_MPATH,
6509 .doit = nl80211_set_mpath,
6510 .policy = nl80211_policy,
6511 .flags = GENL_ADMIN_PERM,
41265714 6512 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6513 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6514 },
6515 {
6516 .cmd = NL80211_CMD_NEW_MPATH,
6517 .doit = nl80211_new_mpath,
6518 .policy = nl80211_policy,
6519 .flags = GENL_ADMIN_PERM,
41265714 6520 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6521 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6522 },
6523 {
6524 .cmd = NL80211_CMD_DEL_MPATH,
6525 .doit = nl80211_del_mpath,
6526 .policy = nl80211_policy,
9f1ba906 6527 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6528 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6529 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6530 },
6531 {
6532 .cmd = NL80211_CMD_SET_BSS,
6533 .doit = nl80211_set_bss,
6534 .policy = nl80211_policy,
b2e1b302 6535 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6536 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6537 NL80211_FLAG_NEED_RTNL,
b2e1b302 6538 },
f130347c
LR
6539 {
6540 .cmd = NL80211_CMD_GET_REG,
6541 .doit = nl80211_get_reg,
6542 .policy = nl80211_policy,
6543 /* can be retrieved by unprivileged users */
6544 },
b2e1b302
LR
6545 {
6546 .cmd = NL80211_CMD_SET_REG,
6547 .doit = nl80211_set_reg,
6548 .policy = nl80211_policy,
6549 .flags = GENL_ADMIN_PERM,
6550 },
6551 {
6552 .cmd = NL80211_CMD_REQ_SET_REG,
6553 .doit = nl80211_req_set_reg,
6554 .policy = nl80211_policy,
93da9cc1 6555 .flags = GENL_ADMIN_PERM,
6556 },
6557 {
24bdd9f4
JC
6558 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6559 .doit = nl80211_get_mesh_config,
93da9cc1 6560 .policy = nl80211_policy,
6561 /* can be retrieved by unprivileged users */
2b5f8b0b 6562 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6563 NL80211_FLAG_NEED_RTNL,
93da9cc1 6564 },
6565 {
24bdd9f4
JC
6566 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6567 .doit = nl80211_update_mesh_config,
93da9cc1 6568 .policy = nl80211_policy,
9aed3cc1 6569 .flags = GENL_ADMIN_PERM,
29cbe68c 6570 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6571 NL80211_FLAG_NEED_RTNL,
9aed3cc1 6572 },
2a519311
JB
6573 {
6574 .cmd = NL80211_CMD_TRIGGER_SCAN,
6575 .doit = nl80211_trigger_scan,
6576 .policy = nl80211_policy,
6577 .flags = GENL_ADMIN_PERM,
41265714 6578 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6579 NL80211_FLAG_NEED_RTNL,
2a519311
JB
6580 },
6581 {
6582 .cmd = NL80211_CMD_GET_SCAN,
6583 .policy = nl80211_policy,
6584 .dumpit = nl80211_dump_scan,
6585 },
807f8a8c
LC
6586 {
6587 .cmd = NL80211_CMD_START_SCHED_SCAN,
6588 .doit = nl80211_start_sched_scan,
6589 .policy = nl80211_policy,
6590 .flags = GENL_ADMIN_PERM,
6591 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6592 NL80211_FLAG_NEED_RTNL,
6593 },
6594 {
6595 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6596 .doit = nl80211_stop_sched_scan,
6597 .policy = nl80211_policy,
6598 .flags = GENL_ADMIN_PERM,
6599 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6600 NL80211_FLAG_NEED_RTNL,
6601 },
636a5d36
JM
6602 {
6603 .cmd = NL80211_CMD_AUTHENTICATE,
6604 .doit = nl80211_authenticate,
6605 .policy = nl80211_policy,
6606 .flags = GENL_ADMIN_PERM,
41265714 6607 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6608 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6609 },
6610 {
6611 .cmd = NL80211_CMD_ASSOCIATE,
6612 .doit = nl80211_associate,
6613 .policy = nl80211_policy,
6614 .flags = GENL_ADMIN_PERM,
41265714 6615 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6616 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6617 },
6618 {
6619 .cmd = NL80211_CMD_DEAUTHENTICATE,
6620 .doit = nl80211_deauthenticate,
6621 .policy = nl80211_policy,
6622 .flags = GENL_ADMIN_PERM,
41265714 6623 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6624 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6625 },
6626 {
6627 .cmd = NL80211_CMD_DISASSOCIATE,
6628 .doit = nl80211_disassociate,
6629 .policy = nl80211_policy,
6630 .flags = GENL_ADMIN_PERM,
41265714 6631 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6632 NL80211_FLAG_NEED_RTNL,
636a5d36 6633 },
04a773ad
JB
6634 {
6635 .cmd = NL80211_CMD_JOIN_IBSS,
6636 .doit = nl80211_join_ibss,
6637 .policy = nl80211_policy,
6638 .flags = GENL_ADMIN_PERM,
41265714 6639 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6640 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
6641 },
6642 {
6643 .cmd = NL80211_CMD_LEAVE_IBSS,
6644 .doit = nl80211_leave_ibss,
6645 .policy = nl80211_policy,
6646 .flags = GENL_ADMIN_PERM,
41265714 6647 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6648 NL80211_FLAG_NEED_RTNL,
04a773ad 6649 },
aff89a9b
JB
6650#ifdef CONFIG_NL80211_TESTMODE
6651 {
6652 .cmd = NL80211_CMD_TESTMODE,
6653 .doit = nl80211_testmode_do,
71063f0e 6654 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
6655 .policy = nl80211_policy,
6656 .flags = GENL_ADMIN_PERM,
4c476991
JB
6657 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6658 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
6659 },
6660#endif
b23aa676
SO
6661 {
6662 .cmd = NL80211_CMD_CONNECT,
6663 .doit = nl80211_connect,
6664 .policy = nl80211_policy,
6665 .flags = GENL_ADMIN_PERM,
41265714 6666 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6667 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
6668 },
6669 {
6670 .cmd = NL80211_CMD_DISCONNECT,
6671 .doit = nl80211_disconnect,
6672 .policy = nl80211_policy,
6673 .flags = GENL_ADMIN_PERM,
41265714 6674 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6675 NL80211_FLAG_NEED_RTNL,
b23aa676 6676 },
463d0183
JB
6677 {
6678 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6679 .doit = nl80211_wiphy_netns,
6680 .policy = nl80211_policy,
6681 .flags = GENL_ADMIN_PERM,
4c476991
JB
6682 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6683 NL80211_FLAG_NEED_RTNL,
463d0183 6684 },
61fa713c
HS
6685 {
6686 .cmd = NL80211_CMD_GET_SURVEY,
6687 .policy = nl80211_policy,
6688 .dumpit = nl80211_dump_survey,
6689 },
67fbb16b
SO
6690 {
6691 .cmd = NL80211_CMD_SET_PMKSA,
6692 .doit = nl80211_setdel_pmksa,
6693 .policy = nl80211_policy,
6694 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6695 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6696 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6697 },
6698 {
6699 .cmd = NL80211_CMD_DEL_PMKSA,
6700 .doit = nl80211_setdel_pmksa,
6701 .policy = nl80211_policy,
6702 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6703 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6704 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6705 },
6706 {
6707 .cmd = NL80211_CMD_FLUSH_PMKSA,
6708 .doit = nl80211_flush_pmksa,
6709 .policy = nl80211_policy,
6710 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6711 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6712 NL80211_FLAG_NEED_RTNL,
67fbb16b 6713 },
9588bbd5
JM
6714 {
6715 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6716 .doit = nl80211_remain_on_channel,
6717 .policy = nl80211_policy,
6718 .flags = GENL_ADMIN_PERM,
41265714 6719 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6720 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
6721 },
6722 {
6723 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6724 .doit = nl80211_cancel_remain_on_channel,
6725 .policy = nl80211_policy,
6726 .flags = GENL_ADMIN_PERM,
41265714 6727 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6728 NL80211_FLAG_NEED_RTNL,
9588bbd5 6729 },
13ae75b1
JM
6730 {
6731 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6732 .doit = nl80211_set_tx_bitrate_mask,
6733 .policy = nl80211_policy,
6734 .flags = GENL_ADMIN_PERM,
4c476991
JB
6735 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6736 NL80211_FLAG_NEED_RTNL,
13ae75b1 6737 },
026331c4 6738 {
2e161f78
JB
6739 .cmd = NL80211_CMD_REGISTER_FRAME,
6740 .doit = nl80211_register_mgmt,
026331c4
JM
6741 .policy = nl80211_policy,
6742 .flags = GENL_ADMIN_PERM,
4c476991
JB
6743 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6744 NL80211_FLAG_NEED_RTNL,
026331c4
JM
6745 },
6746 {
2e161f78
JB
6747 .cmd = NL80211_CMD_FRAME,
6748 .doit = nl80211_tx_mgmt,
026331c4 6749 .policy = nl80211_policy,
f7ca38df
JB
6750 .flags = GENL_ADMIN_PERM,
6751 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6752 NL80211_FLAG_NEED_RTNL,
6753 },
6754 {
6755 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6756 .doit = nl80211_tx_mgmt_cancel_wait,
6757 .policy = nl80211_policy,
026331c4 6758 .flags = GENL_ADMIN_PERM,
41265714 6759 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6760 NL80211_FLAG_NEED_RTNL,
026331c4 6761 },
ffb9eb3d
KV
6762 {
6763 .cmd = NL80211_CMD_SET_POWER_SAVE,
6764 .doit = nl80211_set_power_save,
6765 .policy = nl80211_policy,
6766 .flags = GENL_ADMIN_PERM,
4c476991
JB
6767 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6768 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
6769 },
6770 {
6771 .cmd = NL80211_CMD_GET_POWER_SAVE,
6772 .doit = nl80211_get_power_save,
6773 .policy = nl80211_policy,
6774 /* can be retrieved by unprivileged users */
4c476991
JB
6775 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6776 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 6777 },
d6dc1a38
JO
6778 {
6779 .cmd = NL80211_CMD_SET_CQM,
6780 .doit = nl80211_set_cqm,
6781 .policy = nl80211_policy,
6782 .flags = GENL_ADMIN_PERM,
4c476991
JB
6783 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6784 NL80211_FLAG_NEED_RTNL,
d6dc1a38 6785 },
f444de05
JB
6786 {
6787 .cmd = NL80211_CMD_SET_CHANNEL,
6788 .doit = nl80211_set_channel,
6789 .policy = nl80211_policy,
6790 .flags = GENL_ADMIN_PERM,
4c476991
JB
6791 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6792 NL80211_FLAG_NEED_RTNL,
f444de05 6793 },
e8347eba
BJ
6794 {
6795 .cmd = NL80211_CMD_SET_WDS_PEER,
6796 .doit = nl80211_set_wds_peer,
6797 .policy = nl80211_policy,
6798 .flags = GENL_ADMIN_PERM,
43b19952
JB
6799 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6800 NL80211_FLAG_NEED_RTNL,
e8347eba 6801 },
29cbe68c
JB
6802 {
6803 .cmd = NL80211_CMD_JOIN_MESH,
6804 .doit = nl80211_join_mesh,
6805 .policy = nl80211_policy,
6806 .flags = GENL_ADMIN_PERM,
6807 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6808 NL80211_FLAG_NEED_RTNL,
6809 },
6810 {
6811 .cmd = NL80211_CMD_LEAVE_MESH,
6812 .doit = nl80211_leave_mesh,
6813 .policy = nl80211_policy,
6814 .flags = GENL_ADMIN_PERM,
6815 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6816 NL80211_FLAG_NEED_RTNL,
6817 },
ff1b6e69
JB
6818 {
6819 .cmd = NL80211_CMD_GET_WOWLAN,
6820 .doit = nl80211_get_wowlan,
6821 .policy = nl80211_policy,
6822 /* can be retrieved by unprivileged users */
6823 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6824 NL80211_FLAG_NEED_RTNL,
6825 },
6826 {
6827 .cmd = NL80211_CMD_SET_WOWLAN,
6828 .doit = nl80211_set_wowlan,
6829 .policy = nl80211_policy,
6830 .flags = GENL_ADMIN_PERM,
6831 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6832 NL80211_FLAG_NEED_RTNL,
6833 },
e5497d76
JB
6834 {
6835 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
6836 .doit = nl80211_set_rekey_data,
6837 .policy = nl80211_policy,
6838 .flags = GENL_ADMIN_PERM,
6839 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6840 NL80211_FLAG_NEED_RTNL,
6841 },
109086ce
AN
6842 {
6843 .cmd = NL80211_CMD_TDLS_MGMT,
6844 .doit = nl80211_tdls_mgmt,
6845 .policy = nl80211_policy,
6846 .flags = GENL_ADMIN_PERM,
6847 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6848 NL80211_FLAG_NEED_RTNL,
6849 },
6850 {
6851 .cmd = NL80211_CMD_TDLS_OPER,
6852 .doit = nl80211_tdls_oper,
6853 .policy = nl80211_policy,
6854 .flags = GENL_ADMIN_PERM,
6855 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6856 NL80211_FLAG_NEED_RTNL,
6857 },
28946da7
JB
6858 {
6859 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
6860 .doit = nl80211_register_unexpected_frame,
6861 .policy = nl80211_policy,
6862 .flags = GENL_ADMIN_PERM,
6863 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6864 NL80211_FLAG_NEED_RTNL,
6865 },
7f6cf311
JB
6866 {
6867 .cmd = NL80211_CMD_PROBE_CLIENT,
6868 .doit = nl80211_probe_client,
6869 .policy = nl80211_policy,
6870 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6871 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
6872 NL80211_FLAG_NEED_RTNL,
6873 },
5e760230
JB
6874 {
6875 .cmd = NL80211_CMD_REGISTER_BEACONS,
6876 .doit = nl80211_register_beacons,
6877 .policy = nl80211_policy,
6878 .flags = GENL_ADMIN_PERM,
6879 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6880 NL80211_FLAG_NEED_RTNL,
6881 },
1d9d9213
SW
6882 {
6883 .cmd = NL80211_CMD_SET_NOACK_MAP,
6884 .doit = nl80211_set_noack_map,
6885 .policy = nl80211_policy,
6886 .flags = GENL_ADMIN_PERM,
6887 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6888 NL80211_FLAG_NEED_RTNL,
6889 },
6890
55682965 6891};
9588bbd5 6892
6039f6d2
JM
6893static struct genl_multicast_group nl80211_mlme_mcgrp = {
6894 .name = "mlme",
6895};
55682965
JB
6896
6897/* multicast groups */
6898static struct genl_multicast_group nl80211_config_mcgrp = {
6899 .name = "config",
6900};
2a519311
JB
6901static struct genl_multicast_group nl80211_scan_mcgrp = {
6902 .name = "scan",
6903};
73d54c9e
LR
6904static struct genl_multicast_group nl80211_regulatory_mcgrp = {
6905 .name = "regulatory",
6906};
55682965
JB
6907
6908/* notification functions */
6909
6910void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
6911{
6912 struct sk_buff *msg;
6913
fd2120ca 6914 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
6915 if (!msg)
6916 return;
6917
6918 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
6919 nlmsg_free(msg);
6920 return;
6921 }
6922
463d0183
JB
6923 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6924 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
6925}
6926
362a415d
JB
6927static int nl80211_add_scan_req(struct sk_buff *msg,
6928 struct cfg80211_registered_device *rdev)
6929{
6930 struct cfg80211_scan_request *req = rdev->scan_req;
6931 struct nlattr *nest;
6932 int i;
6933
667503dd
JB
6934 ASSERT_RDEV_LOCK(rdev);
6935
362a415d
JB
6936 if (WARN_ON(!req))
6937 return 0;
6938
6939 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
6940 if (!nest)
6941 goto nla_put_failure;
6942 for (i = 0; i < req->n_ssids; i++)
6943 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
6944 nla_nest_end(msg, nest);
6945
6946 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
6947 if (!nest)
6948 goto nla_put_failure;
6949 for (i = 0; i < req->n_channels; i++)
6950 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
6951 nla_nest_end(msg, nest);
6952
6953 if (req->ie)
6954 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
6955
6956 return 0;
6957 nla_put_failure:
6958 return -ENOBUFS;
6959}
6960
a538e2d5
JB
6961static int nl80211_send_scan_msg(struct sk_buff *msg,
6962 struct cfg80211_registered_device *rdev,
6963 struct net_device *netdev,
6964 u32 pid, u32 seq, int flags,
6965 u32 cmd)
2a519311
JB
6966{
6967 void *hdr;
6968
6969 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6970 if (!hdr)
6971 return -1;
6972
b5850a7a 6973 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
6974 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6975
362a415d
JB
6976 /* ignore errors and send incomplete event anyway */
6977 nl80211_add_scan_req(msg, rdev);
2a519311
JB
6978
6979 return genlmsg_end(msg, hdr);
6980
6981 nla_put_failure:
6982 genlmsg_cancel(msg, hdr);
6983 return -EMSGSIZE;
6984}
6985
807f8a8c
LC
6986static int
6987nl80211_send_sched_scan_msg(struct sk_buff *msg,
6988 struct cfg80211_registered_device *rdev,
6989 struct net_device *netdev,
6990 u32 pid, u32 seq, int flags, u32 cmd)
6991{
6992 void *hdr;
6993
6994 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6995 if (!hdr)
6996 return -1;
6997
6998 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6999 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7000
7001 return genlmsg_end(msg, hdr);
7002
7003 nla_put_failure:
7004 genlmsg_cancel(msg, hdr);
7005 return -EMSGSIZE;
7006}
7007
a538e2d5
JB
7008void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
7009 struct net_device *netdev)
7010{
7011 struct sk_buff *msg;
7012
7013 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7014 if (!msg)
7015 return;
7016
7017 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7018 NL80211_CMD_TRIGGER_SCAN) < 0) {
7019 nlmsg_free(msg);
7020 return;
7021 }
7022
463d0183
JB
7023 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7024 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
7025}
7026
2a519311
JB
7027void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
7028 struct net_device *netdev)
7029{
7030 struct sk_buff *msg;
7031
fd2120ca 7032 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7033 if (!msg)
7034 return;
7035
a538e2d5
JB
7036 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7037 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
7038 nlmsg_free(msg);
7039 return;
7040 }
7041
463d0183
JB
7042 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7043 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7044}
7045
7046void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
7047 struct net_device *netdev)
7048{
7049 struct sk_buff *msg;
7050
fd2120ca 7051 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7052 if (!msg)
7053 return;
7054
a538e2d5
JB
7055 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7056 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
7057 nlmsg_free(msg);
7058 return;
7059 }
7060
463d0183
JB
7061 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7062 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7063}
7064
807f8a8c
LC
7065void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7066 struct net_device *netdev)
7067{
7068 struct sk_buff *msg;
7069
7070 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7071 if (!msg)
7072 return;
7073
7074 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7075 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
7076 nlmsg_free(msg);
7077 return;
7078 }
7079
7080 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7081 nl80211_scan_mcgrp.id, GFP_KERNEL);
7082}
7083
7084void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
7085 struct net_device *netdev, u32 cmd)
7086{
7087 struct sk_buff *msg;
7088
7089 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7090 if (!msg)
7091 return;
7092
7093 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
7094 nlmsg_free(msg);
7095 return;
7096 }
7097
7098 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7099 nl80211_scan_mcgrp.id, GFP_KERNEL);
7100}
7101
73d54c9e
LR
7102/*
7103 * This can happen on global regulatory changes or device specific settings
7104 * based on custom world regulatory domains.
7105 */
7106void nl80211_send_reg_change_event(struct regulatory_request *request)
7107{
7108 struct sk_buff *msg;
7109 void *hdr;
7110
fd2120ca 7111 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
7112 if (!msg)
7113 return;
7114
7115 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
7116 if (!hdr) {
7117 nlmsg_free(msg);
7118 return;
7119 }
7120
7121 /* Userspace can always count this one always being set */
7122 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
7123
7124 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
7125 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7126 NL80211_REGDOM_TYPE_WORLD);
7127 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
7128 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7129 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
7130 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
7131 request->intersect)
7132 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7133 NL80211_REGDOM_TYPE_INTERSECTION);
7134 else {
7135 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7136 NL80211_REGDOM_TYPE_COUNTRY);
7137 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
7138 }
7139
7140 if (wiphy_idx_valid(request->wiphy_idx))
7141 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
7142
3b7b72ee 7143 genlmsg_end(msg, hdr);
73d54c9e 7144
bc43b28c 7145 rcu_read_lock();
463d0183 7146 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
7147 GFP_ATOMIC);
7148 rcu_read_unlock();
73d54c9e
LR
7149
7150 return;
7151
7152nla_put_failure:
7153 genlmsg_cancel(msg, hdr);
7154 nlmsg_free(msg);
7155}
7156
6039f6d2
JM
7157static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
7158 struct net_device *netdev,
7159 const u8 *buf, size_t len,
e6d6e342 7160 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
7161{
7162 struct sk_buff *msg;
7163 void *hdr;
7164
e6d6e342 7165 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
7166 if (!msg)
7167 return;
7168
7169 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7170 if (!hdr) {
7171 nlmsg_free(msg);
7172 return;
7173 }
7174
7175 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7176 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7177 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7178
3b7b72ee 7179 genlmsg_end(msg, hdr);
6039f6d2 7180
463d0183
JB
7181 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7182 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
7183 return;
7184
7185 nla_put_failure:
7186 genlmsg_cancel(msg, hdr);
7187 nlmsg_free(msg);
7188}
7189
7190void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7191 struct net_device *netdev, const u8 *buf,
7192 size_t len, gfp_t gfp)
6039f6d2
JM
7193{
7194 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7195 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
7196}
7197
7198void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
7199 struct net_device *netdev, const u8 *buf,
e6d6e342 7200 size_t len, gfp_t gfp)
6039f6d2 7201{
e6d6e342
JB
7202 nl80211_send_mlme_event(rdev, netdev, buf, len,
7203 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
7204}
7205
53b46b84 7206void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7207 struct net_device *netdev, const u8 *buf,
7208 size_t len, gfp_t gfp)
6039f6d2
JM
7209{
7210 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7211 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
7212}
7213
53b46b84
JM
7214void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
7215 struct net_device *netdev, const u8 *buf,
e6d6e342 7216 size_t len, gfp_t gfp)
6039f6d2
JM
7217{
7218 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7219 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
7220}
7221
cf4e594e
JM
7222void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
7223 struct net_device *netdev, const u8 *buf,
7224 size_t len, gfp_t gfp)
7225{
7226 nl80211_send_mlme_event(rdev, netdev, buf, len,
7227 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
7228}
7229
7230void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
7231 struct net_device *netdev, const u8 *buf,
7232 size_t len, gfp_t gfp)
7233{
7234 nl80211_send_mlme_event(rdev, netdev, buf, len,
7235 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
7236}
7237
1b06bb40
LR
7238static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
7239 struct net_device *netdev, int cmd,
e6d6e342 7240 const u8 *addr, gfp_t gfp)
1965c853
JM
7241{
7242 struct sk_buff *msg;
7243 void *hdr;
7244
e6d6e342 7245 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
7246 if (!msg)
7247 return;
7248
7249 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7250 if (!hdr) {
7251 nlmsg_free(msg);
7252 return;
7253 }
7254
7255 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7256 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7257 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
7258 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7259
3b7b72ee 7260 genlmsg_end(msg, hdr);
1965c853 7261
463d0183
JB
7262 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7263 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
7264 return;
7265
7266 nla_put_failure:
7267 genlmsg_cancel(msg, hdr);
7268 nlmsg_free(msg);
7269}
7270
7271void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7272 struct net_device *netdev, const u8 *addr,
7273 gfp_t gfp)
1965c853
JM
7274{
7275 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 7276 addr, gfp);
1965c853
JM
7277}
7278
7279void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7280 struct net_device *netdev, const u8 *addr,
7281 gfp_t gfp)
1965c853 7282{
e6d6e342
JB
7283 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
7284 addr, gfp);
1965c853
JM
7285}
7286
b23aa676
SO
7287void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
7288 struct net_device *netdev, const u8 *bssid,
7289 const u8 *req_ie, size_t req_ie_len,
7290 const u8 *resp_ie, size_t resp_ie_len,
7291 u16 status, gfp_t gfp)
7292{
7293 struct sk_buff *msg;
7294 void *hdr;
7295
7296 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7297 if (!msg)
7298 return;
7299
7300 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
7301 if (!hdr) {
7302 nlmsg_free(msg);
7303 return;
7304 }
7305
7306 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7307 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7308 if (bssid)
7309 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7310 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
7311 if (req_ie)
7312 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
7313 if (resp_ie)
7314 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
7315
3b7b72ee 7316 genlmsg_end(msg, hdr);
b23aa676 7317
463d0183
JB
7318 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7319 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7320 return;
7321
7322 nla_put_failure:
7323 genlmsg_cancel(msg, hdr);
7324 nlmsg_free(msg);
7325
7326}
7327
7328void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
7329 struct net_device *netdev, const u8 *bssid,
7330 const u8 *req_ie, size_t req_ie_len,
7331 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
7332{
7333 struct sk_buff *msg;
7334 void *hdr;
7335
7336 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7337 if (!msg)
7338 return;
7339
7340 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
7341 if (!hdr) {
7342 nlmsg_free(msg);
7343 return;
7344 }
7345
7346 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7347 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7348 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7349 if (req_ie)
7350 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
7351 if (resp_ie)
7352 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
7353
3b7b72ee 7354 genlmsg_end(msg, hdr);
b23aa676 7355
463d0183
JB
7356 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7357 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7358 return;
7359
7360 nla_put_failure:
7361 genlmsg_cancel(msg, hdr);
7362 nlmsg_free(msg);
7363
7364}
7365
7366void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
7367 struct net_device *netdev, u16 reason,
667503dd 7368 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
7369{
7370 struct sk_buff *msg;
7371 void *hdr;
7372
667503dd 7373 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
7374 if (!msg)
7375 return;
7376
7377 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
7378 if (!hdr) {
7379 nlmsg_free(msg);
7380 return;
7381 }
7382
7383 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7384 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7385 if (from_ap && reason)
7386 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
7387 if (from_ap)
7388 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
7389 if (ie)
7390 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
7391
3b7b72ee 7392 genlmsg_end(msg, hdr);
b23aa676 7393
463d0183
JB
7394 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7395 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
7396 return;
7397
7398 nla_put_failure:
7399 genlmsg_cancel(msg, hdr);
7400 nlmsg_free(msg);
7401
7402}
7403
04a773ad
JB
7404void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7405 struct net_device *netdev, const u8 *bssid,
7406 gfp_t gfp)
7407{
7408 struct sk_buff *msg;
7409 void *hdr;
7410
fd2120ca 7411 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7412 if (!msg)
7413 return;
7414
7415 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7416 if (!hdr) {
7417 nlmsg_free(msg);
7418 return;
7419 }
7420
7421 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7422 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7423 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7424
3b7b72ee 7425 genlmsg_end(msg, hdr);
04a773ad 7426
463d0183
JB
7427 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7428 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7429 return;
7430
7431 nla_put_failure:
7432 genlmsg_cancel(msg, hdr);
7433 nlmsg_free(msg);
7434}
7435
c93b5e71
JC
7436void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7437 struct net_device *netdev,
7438 const u8 *macaddr, const u8* ie, u8 ie_len,
7439 gfp_t gfp)
7440{
7441 struct sk_buff *msg;
7442 void *hdr;
7443
7444 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7445 if (!msg)
7446 return;
7447
7448 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7449 if (!hdr) {
7450 nlmsg_free(msg);
7451 return;
7452 }
7453
7454 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7455 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7456 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
7457 if (ie_len && ie)
7458 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
7459
3b7b72ee 7460 genlmsg_end(msg, hdr);
c93b5e71
JC
7461
7462 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7463 nl80211_mlme_mcgrp.id, gfp);
7464 return;
7465
7466 nla_put_failure:
7467 genlmsg_cancel(msg, hdr);
7468 nlmsg_free(msg);
7469}
7470
a3b8b056
JM
7471void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7472 struct net_device *netdev, const u8 *addr,
7473 enum nl80211_key_type key_type, int key_id,
e6d6e342 7474 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7475{
7476 struct sk_buff *msg;
7477 void *hdr;
7478
e6d6e342 7479 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7480 if (!msg)
7481 return;
7482
7483 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7484 if (!hdr) {
7485 nlmsg_free(msg);
7486 return;
7487 }
7488
7489 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7490 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7491 if (addr)
7492 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7493 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
a66b98db
AN
7494 if (key_id != -1)
7495 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
a3b8b056
JM
7496 if (tsc)
7497 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
7498
3b7b72ee 7499 genlmsg_end(msg, hdr);
a3b8b056 7500
463d0183
JB
7501 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7502 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7503 return;
7504
7505 nla_put_failure:
7506 genlmsg_cancel(msg, hdr);
7507 nlmsg_free(msg);
7508}
7509
6bad8766
LR
7510void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7511 struct ieee80211_channel *channel_before,
7512 struct ieee80211_channel *channel_after)
7513{
7514 struct sk_buff *msg;
7515 void *hdr;
7516 struct nlattr *nl_freq;
7517
fd2120ca 7518 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7519 if (!msg)
7520 return;
7521
7522 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7523 if (!hdr) {
7524 nlmsg_free(msg);
7525 return;
7526 }
7527
7528 /*
7529 * Since we are applying the beacon hint to a wiphy we know its
7530 * wiphy_idx is valid
7531 */
7532 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
7533
7534 /* Before */
7535 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7536 if (!nl_freq)
7537 goto nla_put_failure;
7538 if (nl80211_msg_put_channel(msg, channel_before))
7539 goto nla_put_failure;
7540 nla_nest_end(msg, nl_freq);
7541
7542 /* After */
7543 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7544 if (!nl_freq)
7545 goto nla_put_failure;
7546 if (nl80211_msg_put_channel(msg, channel_after))
7547 goto nla_put_failure;
7548 nla_nest_end(msg, nl_freq);
7549
3b7b72ee 7550 genlmsg_end(msg, hdr);
6bad8766 7551
463d0183
JB
7552 rcu_read_lock();
7553 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7554 GFP_ATOMIC);
7555 rcu_read_unlock();
6bad8766
LR
7556
7557 return;
7558
7559nla_put_failure:
7560 genlmsg_cancel(msg, hdr);
7561 nlmsg_free(msg);
7562}
7563
9588bbd5
JM
7564static void nl80211_send_remain_on_chan_event(
7565 int cmd, struct cfg80211_registered_device *rdev,
7566 struct net_device *netdev, u64 cookie,
7567 struct ieee80211_channel *chan,
7568 enum nl80211_channel_type channel_type,
7569 unsigned int duration, gfp_t gfp)
7570{
7571 struct sk_buff *msg;
7572 void *hdr;
7573
7574 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7575 if (!msg)
7576 return;
7577
7578 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7579 if (!hdr) {
7580 nlmsg_free(msg);
7581 return;
7582 }
7583
7584 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7585 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7586 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
7587 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
7588 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7589
7590 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
7591 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
7592
3b7b72ee 7593 genlmsg_end(msg, hdr);
9588bbd5
JM
7594
7595 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7596 nl80211_mlme_mcgrp.id, gfp);
7597 return;
7598
7599 nla_put_failure:
7600 genlmsg_cancel(msg, hdr);
7601 nlmsg_free(msg);
7602}
7603
7604void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7605 struct net_device *netdev, u64 cookie,
7606 struct ieee80211_channel *chan,
7607 enum nl80211_channel_type channel_type,
7608 unsigned int duration, gfp_t gfp)
7609{
7610 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7611 rdev, netdev, cookie, chan,
7612 channel_type, duration, gfp);
7613}
7614
7615void nl80211_send_remain_on_channel_cancel(
7616 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7617 u64 cookie, struct ieee80211_channel *chan,
7618 enum nl80211_channel_type channel_type, gfp_t gfp)
7619{
7620 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7621 rdev, netdev, cookie, chan,
7622 channel_type, 0, gfp);
7623}
7624
98b62183
JB
7625void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7626 struct net_device *dev, const u8 *mac_addr,
7627 struct station_info *sinfo, gfp_t gfp)
7628{
7629 struct sk_buff *msg;
7630
7631 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7632 if (!msg)
7633 return;
7634
66266b3a
JL
7635 if (nl80211_send_station(msg, 0, 0, 0,
7636 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
7637 nlmsg_free(msg);
7638 return;
7639 }
7640
7641 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7642 nl80211_mlme_mcgrp.id, gfp);
7643}
7644
ec15e68b
JM
7645void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7646 struct net_device *dev, const u8 *mac_addr,
7647 gfp_t gfp)
7648{
7649 struct sk_buff *msg;
7650 void *hdr;
7651
7652 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7653 if (!msg)
7654 return;
7655
7656 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7657 if (!hdr) {
7658 nlmsg_free(msg);
7659 return;
7660 }
7661
7662 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7663 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
7664
3b7b72ee 7665 genlmsg_end(msg, hdr);
ec15e68b
JM
7666
7667 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7668 nl80211_mlme_mcgrp.id, gfp);
7669 return;
7670
7671 nla_put_failure:
7672 genlmsg_cancel(msg, hdr);
7673 nlmsg_free(msg);
7674}
7675
b92ab5d8
JB
7676static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
7677 const u8 *addr, gfp_t gfp)
28946da7
JB
7678{
7679 struct wireless_dev *wdev = dev->ieee80211_ptr;
7680 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7681 struct sk_buff *msg;
7682 void *hdr;
7683 int err;
7684 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7685
7686 if (!nlpid)
7687 return false;
7688
7689 msg = nlmsg_new(100, gfp);
7690 if (!msg)
7691 return true;
7692
b92ab5d8 7693 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
7694 if (!hdr) {
7695 nlmsg_free(msg);
7696 return true;
7697 }
7698
7699 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7700 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7701 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7702
7703 err = genlmsg_end(msg, hdr);
7704 if (err < 0) {
7705 nlmsg_free(msg);
7706 return true;
7707 }
7708
7709 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7710 return true;
7711
7712 nla_put_failure:
7713 genlmsg_cancel(msg, hdr);
7714 nlmsg_free(msg);
7715 return true;
7716}
7717
b92ab5d8
JB
7718bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7719{
7720 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
7721 addr, gfp);
7722}
7723
7724bool nl80211_unexpected_4addr_frame(struct net_device *dev,
7725 const u8 *addr, gfp_t gfp)
7726{
7727 return __nl80211_unexpected_frame(dev,
7728 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
7729 addr, gfp);
7730}
7731
2e161f78
JB
7732int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7733 struct net_device *netdev, u32 nlpid,
804483e9
JB
7734 int freq, int sig_dbm,
7735 const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
7736{
7737 struct sk_buff *msg;
7738 void *hdr;
026331c4
JM
7739
7740 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7741 if (!msg)
7742 return -ENOMEM;
7743
2e161f78 7744 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
7745 if (!hdr) {
7746 nlmsg_free(msg);
7747 return -ENOMEM;
7748 }
7749
7750 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7751 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7752 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
804483e9
JB
7753 if (sig_dbm)
7754 NLA_PUT_U32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm);
026331c4
JM
7755 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7756
3b7b72ee 7757 genlmsg_end(msg, hdr);
026331c4 7758
3b7b72ee 7759 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
7760
7761 nla_put_failure:
7762 genlmsg_cancel(msg, hdr);
7763 nlmsg_free(msg);
7764 return -ENOBUFS;
7765}
7766
2e161f78
JB
7767void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7768 struct net_device *netdev, u64 cookie,
7769 const u8 *buf, size_t len, bool ack,
7770 gfp_t gfp)
026331c4
JM
7771{
7772 struct sk_buff *msg;
7773 void *hdr;
7774
7775 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7776 if (!msg)
7777 return;
7778
2e161f78 7779 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
7780 if (!hdr) {
7781 nlmsg_free(msg);
7782 return;
7783 }
7784
7785 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7786 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7787 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7788 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7789 if (ack)
7790 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7791
3b7b72ee 7792 genlmsg_end(msg, hdr);
026331c4
JM
7793
7794 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
7795 return;
7796
7797 nla_put_failure:
7798 genlmsg_cancel(msg, hdr);
7799 nlmsg_free(msg);
7800}
7801
d6dc1a38
JO
7802void
7803nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
7804 struct net_device *netdev,
7805 enum nl80211_cqm_rssi_threshold_event rssi_event,
7806 gfp_t gfp)
7807{
7808 struct sk_buff *msg;
7809 struct nlattr *pinfoattr;
7810 void *hdr;
7811
7812 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7813 if (!msg)
7814 return;
7815
7816 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7817 if (!hdr) {
7818 nlmsg_free(msg);
7819 return;
7820 }
7821
7822 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7823 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7824
7825 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7826 if (!pinfoattr)
7827 goto nla_put_failure;
7828
7829 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
7830 rssi_event);
7831
7832 nla_nest_end(msg, pinfoattr);
7833
3b7b72ee 7834 genlmsg_end(msg, hdr);
d6dc1a38
JO
7835
7836 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7837 nl80211_mlme_mcgrp.id, gfp);
7838 return;
7839
7840 nla_put_failure:
7841 genlmsg_cancel(msg, hdr);
7842 nlmsg_free(msg);
7843}
7844
e5497d76
JB
7845void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
7846 struct net_device *netdev, const u8 *bssid,
7847 const u8 *replay_ctr, gfp_t gfp)
7848{
7849 struct sk_buff *msg;
7850 struct nlattr *rekey_attr;
7851 void *hdr;
7852
7853 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7854 if (!msg)
7855 return;
7856
7857 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
7858 if (!hdr) {
7859 nlmsg_free(msg);
7860 return;
7861 }
7862
7863 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7864 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7865 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7866
7867 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
7868 if (!rekey_attr)
7869 goto nla_put_failure;
7870
7871 NLA_PUT(msg, NL80211_REKEY_DATA_REPLAY_CTR,
7872 NL80211_REPLAY_CTR_LEN, replay_ctr);
7873
7874 nla_nest_end(msg, rekey_attr);
7875
3b7b72ee 7876 genlmsg_end(msg, hdr);
e5497d76
JB
7877
7878 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7879 nl80211_mlme_mcgrp.id, gfp);
7880 return;
7881
7882 nla_put_failure:
7883 genlmsg_cancel(msg, hdr);
7884 nlmsg_free(msg);
7885}
7886
c9df56b4
JM
7887void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
7888 struct net_device *netdev, int index,
7889 const u8 *bssid, bool preauth, gfp_t gfp)
7890{
7891 struct sk_buff *msg;
7892 struct nlattr *attr;
7893 void *hdr;
7894
7895 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7896 if (!msg)
7897 return;
7898
7899 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
7900 if (!hdr) {
7901 nlmsg_free(msg);
7902 return;
7903 }
7904
7905 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7906 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7907
7908 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
7909 if (!attr)
7910 goto nla_put_failure;
7911
7912 NLA_PUT_U32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index);
7913 NLA_PUT(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid);
7914 if (preauth)
7915 NLA_PUT_FLAG(msg, NL80211_PMKSA_CANDIDATE_PREAUTH);
7916
7917 nla_nest_end(msg, attr);
7918
3b7b72ee 7919 genlmsg_end(msg, hdr);
c9df56b4
JM
7920
7921 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7922 nl80211_mlme_mcgrp.id, gfp);
7923 return;
7924
7925 nla_put_failure:
7926 genlmsg_cancel(msg, hdr);
7927 nlmsg_free(msg);
7928}
7929
5314526b
TP
7930void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
7931 struct net_device *netdev, int freq,
7932 enum nl80211_channel_type type, gfp_t gfp)
7933{
7934 struct sk_buff *msg;
7935 void *hdr;
7936
7937 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7938 if (!msg)
7939 return;
7940
7941 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
7942 if (!hdr) {
7943 nlmsg_free(msg);
7944 return;
7945 }
7946
7947 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7948 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7949 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, type);
7950
7951 genlmsg_end(msg, hdr);
7952
7953 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7954 nl80211_mlme_mcgrp.id, gfp);
7955 return;
7956
7957 nla_put_failure:
7958 genlmsg_cancel(msg, hdr);
7959 nlmsg_free(msg);
7960}
7961
c063dbf5
JB
7962void
7963nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
7964 struct net_device *netdev, const u8 *peer,
7965 u32 num_packets, gfp_t gfp)
7966{
7967 struct sk_buff *msg;
7968 struct nlattr *pinfoattr;
7969 void *hdr;
7970
7971 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7972 if (!msg)
7973 return;
7974
7975 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7976 if (!hdr) {
7977 nlmsg_free(msg);
7978 return;
7979 }
7980
7981 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7982 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7983 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
7984
7985 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7986 if (!pinfoattr)
7987 goto nla_put_failure;
7988
7989 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
7990
7991 nla_nest_end(msg, pinfoattr);
7992
3b7b72ee 7993 genlmsg_end(msg, hdr);
c063dbf5
JB
7994
7995 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7996 nl80211_mlme_mcgrp.id, gfp);
7997 return;
7998
7999 nla_put_failure:
8000 genlmsg_cancel(msg, hdr);
8001 nlmsg_free(msg);
8002}
8003
7f6cf311
JB
8004void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
8005 u64 cookie, bool acked, gfp_t gfp)
8006{
8007 struct wireless_dev *wdev = dev->ieee80211_ptr;
8008 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8009 struct sk_buff *msg;
8010 void *hdr;
8011 int err;
8012
8013 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8014 if (!msg)
8015 return;
8016
8017 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
8018 if (!hdr) {
8019 nlmsg_free(msg);
8020 return;
8021 }
8022
8023 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
8024 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
8025 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
8026 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
8027 if (acked)
8028 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
8029
8030 err = genlmsg_end(msg, hdr);
8031 if (err < 0) {
8032 nlmsg_free(msg);
8033 return;
8034 }
8035
8036 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8037 nl80211_mlme_mcgrp.id, gfp);
8038 return;
8039
8040 nla_put_failure:
8041 genlmsg_cancel(msg, hdr);
8042 nlmsg_free(msg);
8043}
8044EXPORT_SYMBOL(cfg80211_probe_status);
8045
5e760230
JB
8046void cfg80211_report_obss_beacon(struct wiphy *wiphy,
8047 const u8 *frame, size_t len,
804483e9 8048 int freq, int sig_dbm, gfp_t gfp)
5e760230
JB
8049{
8050 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
8051 struct sk_buff *msg;
8052 void *hdr;
8053 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
8054
8055 if (!nlpid)
8056 return;
8057
8058 msg = nlmsg_new(len + 100, gfp);
8059 if (!msg)
8060 return;
8061
8062 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
8063 if (!hdr) {
8064 nlmsg_free(msg);
8065 return;
8066 }
8067
8068 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
8069 if (freq)
8070 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
804483e9
JB
8071 if (sig_dbm)
8072 NLA_PUT_U32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm);
5e760230
JB
8073 NLA_PUT(msg, NL80211_ATTR_FRAME, len, frame);
8074
8075 genlmsg_end(msg, hdr);
8076
8077 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
8078 return;
8079
8080 nla_put_failure:
8081 genlmsg_cancel(msg, hdr);
8082 nlmsg_free(msg);
8083}
8084EXPORT_SYMBOL(cfg80211_report_obss_beacon);
8085
026331c4
JM
8086static int nl80211_netlink_notify(struct notifier_block * nb,
8087 unsigned long state,
8088 void *_notify)
8089{
8090 struct netlink_notify *notify = _notify;
8091 struct cfg80211_registered_device *rdev;
8092 struct wireless_dev *wdev;
8093
8094 if (state != NETLINK_URELEASE)
8095 return NOTIFY_DONE;
8096
8097 rcu_read_lock();
8098
5e760230 8099 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
026331c4 8100 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 8101 cfg80211_mlme_unregister_socket(wdev, notify->pid);
5e760230
JB
8102 if (rdev->ap_beacons_nlpid == notify->pid)
8103 rdev->ap_beacons_nlpid = 0;
8104 }
026331c4
JM
8105
8106 rcu_read_unlock();
8107
8108 return NOTIFY_DONE;
8109}
8110
8111static struct notifier_block nl80211_netlink_notifier = {
8112 .notifier_call = nl80211_netlink_notify,
8113};
8114
55682965
JB
8115/* initialisation/exit functions */
8116
8117int nl80211_init(void)
8118{
0d63cbb5 8119 int err;
55682965 8120
0d63cbb5
MM
8121 err = genl_register_family_with_ops(&nl80211_fam,
8122 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
8123 if (err)
8124 return err;
8125
55682965
JB
8126 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
8127 if (err)
8128 goto err_out;
8129
2a519311
JB
8130 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
8131 if (err)
8132 goto err_out;
8133
73d54c9e
LR
8134 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
8135 if (err)
8136 goto err_out;
8137
6039f6d2
JM
8138 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
8139 if (err)
8140 goto err_out;
8141
aff89a9b
JB
8142#ifdef CONFIG_NL80211_TESTMODE
8143 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
8144 if (err)
8145 goto err_out;
8146#endif
8147
026331c4
JM
8148 err = netlink_register_notifier(&nl80211_netlink_notifier);
8149 if (err)
8150 goto err_out;
8151
55682965
JB
8152 return 0;
8153 err_out:
8154 genl_unregister_family(&nl80211_fam);
8155 return err;
8156}
8157
8158void nl80211_exit(void)
8159{
026331c4 8160 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
8161 genl_unregister_family(&nl80211_fam);
8162}