]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/blame - net/wireless/nl80211.c
mac80211: allow vendor specific cipher suites
[mirror_ubuntu-focal-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965
JB
25
26/* the netlink family */
27static struct genl_family nl80211_fam = {
28 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
29 .name = "nl80211", /* have users key off the name instead */
30 .hdrsize = 0, /* no private header */
31 .version = 1, /* no particular meaning now */
32 .maxattr = NL80211_ATTR_MAX,
463d0183 33 .netnsok = true,
55682965
JB
34};
35
79c97e97 36/* internal helper: get rdev and dev */
463d0183 37static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 38 struct cfg80211_registered_device **rdev,
55682965
JB
39 struct net_device **dev)
40{
463d0183 41 struct nlattr **attrs = info->attrs;
55682965
JB
42 int ifindex;
43
bba95fef 44 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
45 return -EINVAL;
46
bba95fef 47 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 48 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
49 if (!*dev)
50 return -ENODEV;
51
463d0183 52 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 53 if (IS_ERR(*rdev)) {
55682965 54 dev_put(*dev);
79c97e97 55 return PTR_ERR(*rdev);
55682965
JB
56 }
57
58 return 0;
59}
60
61/* policy for the attributes */
b54452b0 62static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
63 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
64 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 65 .len = 20-1 },
31888487 66 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 67 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 68 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
69 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
71 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
72 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 73 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
74
75 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
76 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
77 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
78
79 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 80 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 81
b9454e83 82 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
83 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
84 .len = WLAN_MAX_KEY_LEN },
85 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
86 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
87 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 88 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
89
90 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
91 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
92 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
95 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
96 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
98 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
99 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
100 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 101 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 102 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 103 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
104 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
105 .len = IEEE80211_MAX_MESH_ID_LEN },
106 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 107
b2e1b302
LR
108 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
109 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
110
9f1ba906
JM
111 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
113 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
114 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
115 .len = NL80211_MAX_SUPP_RATES },
36aedc90 116
93da9cc1 117 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
118
36aedc90
JM
119 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
120 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
121
122 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
123 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
124 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
125 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
126 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
127
128 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
129 .len = IEEE80211_MAX_SSID_LEN },
130 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
131 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 132 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 133 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 134 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
135 [NL80211_ATTR_STA_FLAGS2] = {
136 .len = sizeof(struct nl80211_sta_flag_update),
137 },
3f77316c 138 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
139 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
140 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
141 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 142 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 143 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
144 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
145 .len = WLAN_PMKID_LEN },
9588bbd5
JM
146 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
147 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 148 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
149 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
150 .len = IEEE80211_MAX_DATA_LEN },
151 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 152 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 153 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 154 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 155 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
156
157 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
158 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 159 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
55682965
JB
160};
161
b9454e83 162/* policy for the attributes */
b54452b0 163static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 164 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
165 [NL80211_KEY_IDX] = { .type = NLA_U8 },
166 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
167 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
168 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
169 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
170};
171
a043897a
HS
172/* ifidx get helper */
173static int nl80211_get_ifidx(struct netlink_callback *cb)
174{
175 int res;
176
177 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
178 nl80211_fam.attrbuf, nl80211_fam.maxattr,
179 nl80211_policy);
180 if (res)
181 return res;
182
183 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
184 return -EINVAL;
185
186 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
187 if (!res)
188 return -EINVAL;
189 return res;
190}
191
f4a11bb0
JB
192/* IE validation */
193static bool is_valid_ie_attr(const struct nlattr *attr)
194{
195 const u8 *pos;
196 int len;
197
198 if (!attr)
199 return true;
200
201 pos = nla_data(attr);
202 len = nla_len(attr);
203
204 while (len) {
205 u8 elemlen;
206
207 if (len < 2)
208 return false;
209 len -= 2;
210
211 elemlen = pos[1];
212 if (elemlen > len)
213 return false;
214
215 len -= elemlen;
216 pos += 2 + elemlen;
217 }
218
219 return true;
220}
221
55682965
JB
222/* message building helper */
223static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
224 int flags, u8 cmd)
225{
226 /* since there is no private header just add the generic one */
227 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
228}
229
5dab3b8a
LR
230static int nl80211_msg_put_channel(struct sk_buff *msg,
231 struct ieee80211_channel *chan)
232{
233 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
234 chan->center_freq);
235
236 if (chan->flags & IEEE80211_CHAN_DISABLED)
237 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
238 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
239 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
240 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
241 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
242 if (chan->flags & IEEE80211_CHAN_RADAR)
243 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
244
245 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
246 DBM_TO_MBM(chan->max_power));
247
248 return 0;
249
250 nla_put_failure:
251 return -ENOBUFS;
252}
253
55682965
JB
254/* netlink command implementations */
255
b9454e83
JB
256struct key_parse {
257 struct key_params p;
258 int idx;
259 bool def, defmgmt;
260};
261
262static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
263{
264 struct nlattr *tb[NL80211_KEY_MAX + 1];
265 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
266 nl80211_key_policy);
267 if (err)
268 return err;
269
270 k->def = !!tb[NL80211_KEY_DEFAULT];
271 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
272
273 if (tb[NL80211_KEY_IDX])
274 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
275
276 if (tb[NL80211_KEY_DATA]) {
277 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
278 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
279 }
280
281 if (tb[NL80211_KEY_SEQ]) {
282 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
283 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
284 }
285
286 if (tb[NL80211_KEY_CIPHER])
287 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
288
289 return 0;
290}
291
292static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
293{
294 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
295 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
296 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
297 }
298
299 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
300 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
301 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
302 }
303
304 if (info->attrs[NL80211_ATTR_KEY_IDX])
305 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
306
307 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
308 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
309
310 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
311 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
312
313 return 0;
314}
315
316static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
317{
318 int err;
319
320 memset(k, 0, sizeof(*k));
321 k->idx = -1;
322
323 if (info->attrs[NL80211_ATTR_KEY])
324 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
325 else
326 err = nl80211_parse_key_old(info, k);
327
328 if (err)
329 return err;
330
331 if (k->def && k->defmgmt)
332 return -EINVAL;
333
334 if (k->idx != -1) {
335 if (k->defmgmt) {
336 if (k->idx < 4 || k->idx > 5)
337 return -EINVAL;
338 } else if (k->def) {
339 if (k->idx < 0 || k->idx > 3)
340 return -EINVAL;
341 } else {
342 if (k->idx < 0 || k->idx > 5)
343 return -EINVAL;
344 }
345 }
346
347 return 0;
348}
349
fffd0934
JB
350static struct cfg80211_cached_keys *
351nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
352 struct nlattr *keys)
353{
354 struct key_parse parse;
355 struct nlattr *key;
356 struct cfg80211_cached_keys *result;
357 int rem, err, def = 0;
358
359 result = kzalloc(sizeof(*result), GFP_KERNEL);
360 if (!result)
361 return ERR_PTR(-ENOMEM);
362
363 result->def = -1;
364 result->defmgmt = -1;
365
366 nla_for_each_nested(key, keys, rem) {
367 memset(&parse, 0, sizeof(parse));
368 parse.idx = -1;
369
370 err = nl80211_parse_key_new(key, &parse);
371 if (err)
372 goto error;
373 err = -EINVAL;
374 if (!parse.p.key)
375 goto error;
376 if (parse.idx < 0 || parse.idx > 4)
377 goto error;
378 if (parse.def) {
379 if (def)
380 goto error;
381 def = 1;
382 result->def = parse.idx;
383 } else if (parse.defmgmt)
384 goto error;
385 err = cfg80211_validate_key_settings(rdev, &parse.p,
386 parse.idx, NULL);
387 if (err)
388 goto error;
389 result->params[parse.idx].cipher = parse.p.cipher;
390 result->params[parse.idx].key_len = parse.p.key_len;
391 result->params[parse.idx].key = result->data[parse.idx];
392 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
393 }
394
395 return result;
396 error:
397 kfree(result);
398 return ERR_PTR(err);
399}
400
401static int nl80211_key_allowed(struct wireless_dev *wdev)
402{
403 ASSERT_WDEV_LOCK(wdev);
404
405 if (!netif_running(wdev->netdev))
406 return -ENETDOWN;
407
408 switch (wdev->iftype) {
409 case NL80211_IFTYPE_AP:
410 case NL80211_IFTYPE_AP_VLAN:
411 break;
412 case NL80211_IFTYPE_ADHOC:
413 if (!wdev->current_bss)
414 return -ENOLINK;
415 break;
416 case NL80211_IFTYPE_STATION:
417 if (wdev->sme_state != CFG80211_SME_CONNECTED)
418 return -ENOLINK;
419 break;
420 default:
421 return -EINVAL;
422 }
423
424 return 0;
425}
426
55682965
JB
427static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
428 struct cfg80211_registered_device *dev)
429{
430 void *hdr;
ee688b00
JB
431 struct nlattr *nl_bands, *nl_band;
432 struct nlattr *nl_freqs, *nl_freq;
433 struct nlattr *nl_rates, *nl_rate;
f59ac048 434 struct nlattr *nl_modes;
8fdc621d 435 struct nlattr *nl_cmds;
ee688b00
JB
436 enum ieee80211_band band;
437 struct ieee80211_channel *chan;
438 struct ieee80211_rate *rate;
439 int i;
f59ac048 440 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
441 const struct ieee80211_txrx_stypes *mgmt_stypes =
442 dev->wiphy.mgmt_stypes;
55682965
JB
443
444 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
445 if (!hdr)
446 return -1;
447
b5850a7a 448 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 449 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 450
f5ea9120
JB
451 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
452 cfg80211_rdev_list_generation);
453
b9a5f8ca
JM
454 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
455 dev->wiphy.retry_short);
456 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
457 dev->wiphy.retry_long);
458 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
459 dev->wiphy.frag_threshold);
460 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
461 dev->wiphy.rts_threshold);
81077e82
LT
462 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
463 dev->wiphy.coverage_class);
b9a5f8ca 464
2a519311
JB
465 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
466 dev->wiphy.max_scan_ssids);
18a83659
JB
467 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
468 dev->wiphy.max_scan_ie_len);
ee688b00 469
25e47c18
JB
470 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
471 sizeof(u32) * dev->wiphy.n_cipher_suites,
472 dev->wiphy.cipher_suites);
473
67fbb16b
SO
474 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
475 dev->wiphy.max_num_pmkids);
476
f59ac048
LR
477 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
478 if (!nl_modes)
479 goto nla_put_failure;
480
481 i = 0;
482 while (ifmodes) {
483 if (ifmodes & 1)
484 NLA_PUT_FLAG(msg, i);
485 ifmodes >>= 1;
486 i++;
487 }
488
489 nla_nest_end(msg, nl_modes);
490
ee688b00
JB
491 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
492 if (!nl_bands)
493 goto nla_put_failure;
494
495 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
496 if (!dev->wiphy.bands[band])
497 continue;
498
499 nl_band = nla_nest_start(msg, band);
500 if (!nl_band)
501 goto nla_put_failure;
502
d51626df
JB
503 /* add HT info */
504 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
505 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
506 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
507 &dev->wiphy.bands[band]->ht_cap.mcs);
508 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
509 dev->wiphy.bands[band]->ht_cap.cap);
510 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
511 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
512 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
513 dev->wiphy.bands[band]->ht_cap.ampdu_density);
514 }
515
ee688b00
JB
516 /* add frequencies */
517 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
518 if (!nl_freqs)
519 goto nla_put_failure;
520
521 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
522 nl_freq = nla_nest_start(msg, i);
523 if (!nl_freq)
524 goto nla_put_failure;
525
526 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
527
528 if (nl80211_msg_put_channel(msg, chan))
529 goto nla_put_failure;
e2f367f2 530
ee688b00
JB
531 nla_nest_end(msg, nl_freq);
532 }
533
534 nla_nest_end(msg, nl_freqs);
535
536 /* add bitrates */
537 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
538 if (!nl_rates)
539 goto nla_put_failure;
540
541 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
542 nl_rate = nla_nest_start(msg, i);
543 if (!nl_rate)
544 goto nla_put_failure;
545
546 rate = &dev->wiphy.bands[band]->bitrates[i];
547 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
548 rate->bitrate);
549 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
550 NLA_PUT_FLAG(msg,
551 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
552
553 nla_nest_end(msg, nl_rate);
554 }
555
556 nla_nest_end(msg, nl_rates);
557
558 nla_nest_end(msg, nl_band);
559 }
560 nla_nest_end(msg, nl_bands);
561
8fdc621d
JB
562 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
563 if (!nl_cmds)
564 goto nla_put_failure;
565
566 i = 0;
567#define CMD(op, n) \
568 do { \
569 if (dev->ops->op) { \
570 i++; \
571 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
572 } \
573 } while (0)
574
575 CMD(add_virtual_intf, NEW_INTERFACE);
576 CMD(change_virtual_intf, SET_INTERFACE);
577 CMD(add_key, NEW_KEY);
578 CMD(add_beacon, NEW_BEACON);
579 CMD(add_station, NEW_STATION);
580 CMD(add_mpath, NEW_MPATH);
581 CMD(set_mesh_params, SET_MESH_PARAMS);
582 CMD(change_bss, SET_BSS);
636a5d36
JM
583 CMD(auth, AUTHENTICATE);
584 CMD(assoc, ASSOCIATE);
585 CMD(deauth, DEAUTHENTICATE);
586 CMD(disassoc, DISASSOCIATE);
04a773ad 587 CMD(join_ibss, JOIN_IBSS);
67fbb16b
SO
588 CMD(set_pmksa, SET_PMKSA);
589 CMD(del_pmksa, DEL_PMKSA);
590 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 591 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 592 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 593 CMD(mgmt_tx, FRAME);
5be83de5 594 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
595 i++;
596 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
597 }
f444de05 598 CMD(set_channel, SET_CHANNEL);
8fdc621d
JB
599
600#undef CMD
b23aa676 601
6829c878 602 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
603 i++;
604 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
605 }
606
6829c878 607 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
608 i++;
609 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
610 }
611
8fdc621d
JB
612 nla_nest_end(msg, nl_cmds);
613
2e161f78
JB
614 if (mgmt_stypes) {
615 u16 stypes;
616 struct nlattr *nl_ftypes, *nl_ifs;
617 enum nl80211_iftype ift;
618
619 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
620 if (!nl_ifs)
621 goto nla_put_failure;
622
623 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
624 nl_ftypes = nla_nest_start(msg, ift);
625 if (!nl_ftypes)
626 goto nla_put_failure;
627 i = 0;
628 stypes = mgmt_stypes[ift].tx;
629 while (stypes) {
630 if (stypes & 1)
631 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
632 (i << 4) | IEEE80211_FTYPE_MGMT);
633 stypes >>= 1;
634 i++;
635 }
636 nla_nest_end(msg, nl_ftypes);
637 }
638
74b70a4e
JB
639 nla_nest_end(msg, nl_ifs);
640
2e161f78
JB
641 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
642 if (!nl_ifs)
643 goto nla_put_failure;
644
645 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
646 nl_ftypes = nla_nest_start(msg, ift);
647 if (!nl_ftypes)
648 goto nla_put_failure;
649 i = 0;
650 stypes = mgmt_stypes[ift].rx;
651 while (stypes) {
652 if (stypes & 1)
653 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
654 (i << 4) | IEEE80211_FTYPE_MGMT);
655 stypes >>= 1;
656 i++;
657 }
658 nla_nest_end(msg, nl_ftypes);
659 }
660 nla_nest_end(msg, nl_ifs);
661 }
662
55682965
JB
663 return genlmsg_end(msg, hdr);
664
665 nla_put_failure:
bc3ed28c
TG
666 genlmsg_cancel(msg, hdr);
667 return -EMSGSIZE;
55682965
JB
668}
669
670static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
671{
672 int idx = 0;
673 int start = cb->args[0];
674 struct cfg80211_registered_device *dev;
675
a1794390 676 mutex_lock(&cfg80211_mutex);
79c97e97 677 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
678 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
679 continue;
b4637271 680 if (++idx <= start)
55682965
JB
681 continue;
682 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
683 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
684 dev) < 0) {
685 idx--;
55682965 686 break;
b4637271 687 }
55682965 688 }
a1794390 689 mutex_unlock(&cfg80211_mutex);
55682965
JB
690
691 cb->args[0] = idx;
692
693 return skb->len;
694}
695
696static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
697{
698 struct sk_buff *msg;
699 struct cfg80211_registered_device *dev;
700
701 dev = cfg80211_get_dev_from_info(info);
702 if (IS_ERR(dev))
703 return PTR_ERR(dev);
704
fd2120ca 705 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
706 if (!msg)
707 goto out_err;
708
709 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
710 goto out_free;
711
4d0c8aea 712 cfg80211_unlock_rdev(dev);
55682965 713
134e6375 714 return genlmsg_reply(msg, info);
55682965
JB
715
716 out_free:
717 nlmsg_free(msg);
718 out_err:
4d0c8aea 719 cfg80211_unlock_rdev(dev);
55682965
JB
720 return -ENOBUFS;
721}
722
31888487
JM
723static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
724 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
725 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
726 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
727 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
728 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
729};
730
731static int parse_txq_params(struct nlattr *tb[],
732 struct ieee80211_txq_params *txq_params)
733{
734 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
735 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
736 !tb[NL80211_TXQ_ATTR_AIFS])
737 return -EINVAL;
738
739 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
740 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
741 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
742 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
743 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
744
745 return 0;
746}
747
f444de05
JB
748static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
749{
750 /*
751 * You can only set the channel explicitly for AP, mesh
752 * and WDS type interfaces; all others have their channel
753 * managed via their respective "establish a connection"
754 * command (connect, join, ...)
755 *
756 * Monitors are special as they are normally slaved to
757 * whatever else is going on, so they behave as though
758 * you tried setting the wiphy channel itself.
759 */
760 return !wdev ||
761 wdev->iftype == NL80211_IFTYPE_AP ||
762 wdev->iftype == NL80211_IFTYPE_WDS ||
763 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
764 wdev->iftype == NL80211_IFTYPE_MONITOR;
765}
766
767static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
768 struct wireless_dev *wdev,
769 struct genl_info *info)
770{
771 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
772 u32 freq;
773 int result;
774
775 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
776 return -EINVAL;
777
778 if (!nl80211_can_set_dev_channel(wdev))
779 return -EOPNOTSUPP;
780
781 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
782 channel_type = nla_get_u32(info->attrs[
783 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
784 if (channel_type != NL80211_CHAN_NO_HT &&
785 channel_type != NL80211_CHAN_HT20 &&
786 channel_type != NL80211_CHAN_HT40PLUS &&
787 channel_type != NL80211_CHAN_HT40MINUS)
788 return -EINVAL;
789 }
790
791 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
792
793 mutex_lock(&rdev->devlist_mtx);
794 if (wdev) {
795 wdev_lock(wdev);
796 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
797 wdev_unlock(wdev);
798 } else {
799 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
800 }
801 mutex_unlock(&rdev->devlist_mtx);
802
803 return result;
804}
805
806static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
807{
808 struct cfg80211_registered_device *rdev;
809 struct net_device *netdev;
810 int result;
811
812 rtnl_lock();
813
814 result = get_rdev_dev_by_info_ifindex(info, &rdev, &netdev);
815 if (result)
816 goto unlock;
817
818 result = __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
819
820 unlock:
821 rtnl_unlock();
822
823 return result;
824}
825
55682965
JB
826static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
827{
828 struct cfg80211_registered_device *rdev;
f444de05
JB
829 struct net_device *netdev = NULL;
830 struct wireless_dev *wdev;
831 int result, rem_txq_params = 0;
31888487 832 struct nlattr *nl_txq_params;
b9a5f8ca
JM
833 u32 changed;
834 u8 retry_short = 0, retry_long = 0;
835 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 836 u8 coverage_class = 0;
55682965 837
4bbf4d56 838 rtnl_lock();
55682965 839
f444de05
JB
840 /*
841 * Try to find the wiphy and netdev. Normally this
842 * function shouldn't need the netdev, but this is
843 * done for backward compatibility -- previously
844 * setting the channel was done per wiphy, but now
845 * it is per netdev. Previous userland like hostapd
846 * also passed a netdev to set_wiphy, so that it is
847 * possible to let that go to the right netdev!
848 */
4bbf4d56
JB
849 mutex_lock(&cfg80211_mutex);
850
f444de05
JB
851 if (info->attrs[NL80211_ATTR_IFINDEX]) {
852 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
853
854 netdev = dev_get_by_index(genl_info_net(info), ifindex);
855 if (netdev && netdev->ieee80211_ptr) {
856 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
857 mutex_lock(&rdev->mtx);
858 } else
859 netdev = NULL;
4bbf4d56
JB
860 }
861
f444de05
JB
862 if (!netdev) {
863 rdev = __cfg80211_rdev_from_info(info);
864 if (IS_ERR(rdev)) {
865 mutex_unlock(&cfg80211_mutex);
866 result = PTR_ERR(rdev);
867 goto unlock;
868 }
869 wdev = NULL;
870 netdev = NULL;
871 result = 0;
872
873 mutex_lock(&rdev->mtx);
874 } else if (netif_running(netdev) &&
875 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
876 wdev = netdev->ieee80211_ptr;
877 else
878 wdev = NULL;
879
880 /*
881 * end workaround code, by now the rdev is available
882 * and locked, and wdev may or may not be NULL.
883 */
4bbf4d56
JB
884
885 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
886 result = cfg80211_dev_rename(
887 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
888
889 mutex_unlock(&cfg80211_mutex);
890
891 if (result)
892 goto bad_res;
31888487
JM
893
894 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
895 struct ieee80211_txq_params txq_params;
896 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
897
898 if (!rdev->ops->set_txq_params) {
899 result = -EOPNOTSUPP;
900 goto bad_res;
901 }
902
903 nla_for_each_nested(nl_txq_params,
904 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
905 rem_txq_params) {
906 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
907 nla_data(nl_txq_params),
908 nla_len(nl_txq_params),
909 txq_params_policy);
910 result = parse_txq_params(tb, &txq_params);
911 if (result)
912 goto bad_res;
913
914 result = rdev->ops->set_txq_params(&rdev->wiphy,
915 &txq_params);
916 if (result)
917 goto bad_res;
918 }
919 }
55682965 920
72bdcf34 921 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 922 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
923 if (result)
924 goto bad_res;
925 }
926
98d2ff8b
JO
927 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
928 enum nl80211_tx_power_setting type;
929 int idx, mbm = 0;
930
931 if (!rdev->ops->set_tx_power) {
60ea385f 932 result = -EOPNOTSUPP;
98d2ff8b
JO
933 goto bad_res;
934 }
935
936 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
937 type = nla_get_u32(info->attrs[idx]);
938
939 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
940 (type != NL80211_TX_POWER_AUTOMATIC)) {
941 result = -EINVAL;
942 goto bad_res;
943 }
944
945 if (type != NL80211_TX_POWER_AUTOMATIC) {
946 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
947 mbm = nla_get_u32(info->attrs[idx]);
948 }
949
950 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
951 if (result)
952 goto bad_res;
953 }
954
b9a5f8ca
JM
955 changed = 0;
956
957 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
958 retry_short = nla_get_u8(
959 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
960 if (retry_short == 0) {
961 result = -EINVAL;
962 goto bad_res;
963 }
964 changed |= WIPHY_PARAM_RETRY_SHORT;
965 }
966
967 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
968 retry_long = nla_get_u8(
969 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
970 if (retry_long == 0) {
971 result = -EINVAL;
972 goto bad_res;
973 }
974 changed |= WIPHY_PARAM_RETRY_LONG;
975 }
976
977 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
978 frag_threshold = nla_get_u32(
979 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
980 if (frag_threshold < 256) {
981 result = -EINVAL;
982 goto bad_res;
983 }
984 if (frag_threshold != (u32) -1) {
985 /*
986 * Fragments (apart from the last one) are required to
987 * have even length. Make the fragmentation code
988 * simpler by stripping LSB should someone try to use
989 * odd threshold value.
990 */
991 frag_threshold &= ~0x1;
992 }
993 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
994 }
995
996 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
997 rts_threshold = nla_get_u32(
998 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
999 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1000 }
1001
81077e82
LT
1002 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1003 coverage_class = nla_get_u8(
1004 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1005 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1006 }
1007
b9a5f8ca
JM
1008 if (changed) {
1009 u8 old_retry_short, old_retry_long;
1010 u32 old_frag_threshold, old_rts_threshold;
81077e82 1011 u8 old_coverage_class;
b9a5f8ca
JM
1012
1013 if (!rdev->ops->set_wiphy_params) {
1014 result = -EOPNOTSUPP;
1015 goto bad_res;
1016 }
1017
1018 old_retry_short = rdev->wiphy.retry_short;
1019 old_retry_long = rdev->wiphy.retry_long;
1020 old_frag_threshold = rdev->wiphy.frag_threshold;
1021 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1022 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1023
1024 if (changed & WIPHY_PARAM_RETRY_SHORT)
1025 rdev->wiphy.retry_short = retry_short;
1026 if (changed & WIPHY_PARAM_RETRY_LONG)
1027 rdev->wiphy.retry_long = retry_long;
1028 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1029 rdev->wiphy.frag_threshold = frag_threshold;
1030 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1031 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1032 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1033 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1034
1035 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1036 if (result) {
1037 rdev->wiphy.retry_short = old_retry_short;
1038 rdev->wiphy.retry_long = old_retry_long;
1039 rdev->wiphy.frag_threshold = old_frag_threshold;
1040 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1041 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1042 }
1043 }
72bdcf34 1044
306d6112 1045 bad_res:
4bbf4d56 1046 mutex_unlock(&rdev->mtx);
f444de05
JB
1047 if (netdev)
1048 dev_put(netdev);
4bbf4d56
JB
1049 unlock:
1050 rtnl_unlock();
55682965
JB
1051 return result;
1052}
1053
1054
1055static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1056 struct cfg80211_registered_device *rdev,
55682965
JB
1057 struct net_device *dev)
1058{
1059 void *hdr;
1060
1061 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1062 if (!hdr)
1063 return -1;
1064
1065 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1066 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1067 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1068 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1069
1070 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1071 rdev->devlist_generation ^
1072 (cfg80211_rdev_list_generation << 2));
1073
55682965
JB
1074 return genlmsg_end(msg, hdr);
1075
1076 nla_put_failure:
bc3ed28c
TG
1077 genlmsg_cancel(msg, hdr);
1078 return -EMSGSIZE;
55682965
JB
1079}
1080
1081static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1082{
1083 int wp_idx = 0;
1084 int if_idx = 0;
1085 int wp_start = cb->args[0];
1086 int if_start = cb->args[1];
f5ea9120 1087 struct cfg80211_registered_device *rdev;
55682965
JB
1088 struct wireless_dev *wdev;
1089
a1794390 1090 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1091 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1092 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1093 continue;
bba95fef
JB
1094 if (wp_idx < wp_start) {
1095 wp_idx++;
55682965 1096 continue;
bba95fef 1097 }
55682965
JB
1098 if_idx = 0;
1099
f5ea9120
JB
1100 mutex_lock(&rdev->devlist_mtx);
1101 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1102 if (if_idx < if_start) {
1103 if_idx++;
55682965 1104 continue;
bba95fef 1105 }
55682965
JB
1106 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1107 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1108 rdev, wdev->netdev) < 0) {
1109 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1110 goto out;
1111 }
1112 if_idx++;
55682965 1113 }
f5ea9120 1114 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1115
1116 wp_idx++;
55682965 1117 }
bba95fef 1118 out:
a1794390 1119 mutex_unlock(&cfg80211_mutex);
55682965
JB
1120
1121 cb->args[0] = wp_idx;
1122 cb->args[1] = if_idx;
1123
1124 return skb->len;
1125}
1126
1127static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1128{
1129 struct sk_buff *msg;
1130 struct cfg80211_registered_device *dev;
1131 struct net_device *netdev;
1132 int err;
1133
463d0183 1134 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
1135 if (err)
1136 return err;
1137
fd2120ca 1138 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
1139 if (!msg)
1140 goto out_err;
1141
d726405a
JB
1142 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1143 dev, netdev) < 0)
55682965
JB
1144 goto out_free;
1145
1146 dev_put(netdev);
4d0c8aea 1147 cfg80211_unlock_rdev(dev);
55682965 1148
134e6375 1149 return genlmsg_reply(msg, info);
55682965
JB
1150
1151 out_free:
1152 nlmsg_free(msg);
1153 out_err:
1154 dev_put(netdev);
4d0c8aea 1155 cfg80211_unlock_rdev(dev);
55682965
JB
1156 return -ENOBUFS;
1157}
1158
66f7ac50
MW
1159static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1160 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1161 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1162 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1163 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1164 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1165};
1166
1167static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1168{
1169 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1170 int flag;
1171
1172 *mntrflags = 0;
1173
1174 if (!nla)
1175 return -EINVAL;
1176
1177 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1178 nla, mntr_flags_policy))
1179 return -EINVAL;
1180
1181 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1182 if (flags[flag])
1183 *mntrflags |= (1<<flag);
1184
1185 return 0;
1186}
1187
9bc383de 1188static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1189 struct net_device *netdev, u8 use_4addr,
1190 enum nl80211_iftype iftype)
9bc383de 1191{
ad4bb6f8 1192 if (!use_4addr) {
f350a0a8 1193 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1194 return -EBUSY;
9bc383de 1195 return 0;
ad4bb6f8 1196 }
9bc383de
JB
1197
1198 switch (iftype) {
1199 case NL80211_IFTYPE_AP_VLAN:
1200 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1201 return 0;
1202 break;
1203 case NL80211_IFTYPE_STATION:
1204 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1205 return 0;
1206 break;
1207 default:
1208 break;
1209 }
1210
1211 return -EOPNOTSUPP;
1212}
1213
55682965
JB
1214static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1215{
79c97e97 1216 struct cfg80211_registered_device *rdev;
2ec600d6 1217 struct vif_params params;
e36d56b6 1218 int err;
04a773ad 1219 enum nl80211_iftype otype, ntype;
55682965 1220 struct net_device *dev;
92ffe055 1221 u32 _flags, *flags = NULL;
ac7f9cfa 1222 bool change = false;
55682965 1223
2ec600d6
LCC
1224 memset(&params, 0, sizeof(params));
1225
3b85875a
JB
1226 rtnl_lock();
1227
463d0183 1228 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1229 if (err)
3b85875a
JB
1230 goto unlock_rtnl;
1231
04a773ad 1232 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1233
723b038d 1234 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1235 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1236 if (otype != ntype)
ac7f9cfa 1237 change = true;
04a773ad 1238 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 1239 err = -EINVAL;
723b038d 1240 goto unlock;
ac7f9cfa 1241 }
723b038d
JB
1242 }
1243
92ffe055 1244 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1245 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1246 err = -EINVAL;
1247 goto unlock;
1248 }
2ec600d6
LCC
1249 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1250 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1251 change = true;
2ec600d6
LCC
1252 }
1253
8b787643
FF
1254 if (info->attrs[NL80211_ATTR_4ADDR]) {
1255 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1256 change = true;
ad4bb6f8 1257 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de
JB
1258 if (err)
1259 goto unlock;
8b787643
FF
1260 } else {
1261 params.use_4addr = -1;
1262 }
1263
92ffe055 1264 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1265 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1266 err = -EINVAL;
1267 goto unlock;
1268 }
1269 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1270 &_flags);
ac7f9cfa
JB
1271 if (err)
1272 goto unlock;
1273
1274 flags = &_flags;
1275 change = true;
92ffe055 1276 }
3b85875a 1277
ac7f9cfa 1278 if (change)
3d54d255 1279 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1280 else
1281 err = 0;
60719ffd 1282
9bc383de
JB
1283 if (!err && params.use_4addr != -1)
1284 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1285
55682965 1286 unlock:
e36d56b6 1287 dev_put(dev);
79c97e97 1288 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1289 unlock_rtnl:
1290 rtnl_unlock();
55682965
JB
1291 return err;
1292}
1293
1294static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1295{
79c97e97 1296 struct cfg80211_registered_device *rdev;
2ec600d6 1297 struct vif_params params;
55682965
JB
1298 int err;
1299 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1300 u32 flags;
55682965 1301
2ec600d6
LCC
1302 memset(&params, 0, sizeof(params));
1303
55682965
JB
1304 if (!info->attrs[NL80211_ATTR_IFNAME])
1305 return -EINVAL;
1306
1307 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1308 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1309 if (type > NL80211_IFTYPE_MAX)
1310 return -EINVAL;
1311 }
1312
3b85875a
JB
1313 rtnl_lock();
1314
79c97e97
JB
1315 rdev = cfg80211_get_dev_from_info(info);
1316 if (IS_ERR(rdev)) {
1317 err = PTR_ERR(rdev);
3b85875a
JB
1318 goto unlock_rtnl;
1319 }
55682965 1320
79c97e97
JB
1321 if (!rdev->ops->add_virtual_intf ||
1322 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1323 err = -EOPNOTSUPP;
1324 goto unlock;
1325 }
1326
2ec600d6
LCC
1327 if (type == NL80211_IFTYPE_MESH_POINT &&
1328 info->attrs[NL80211_ATTR_MESH_ID]) {
1329 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1330 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1331 }
1332
9bc383de 1333 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1334 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1335 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de
JB
1336 if (err)
1337 goto unlock;
1338 }
8b787643 1339
66f7ac50
MW
1340 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1341 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1342 &flags);
79c97e97 1343 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1344 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1345 type, err ? NULL : &flags, &params);
2ec600d6 1346
55682965 1347 unlock:
79c97e97 1348 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1349 unlock_rtnl:
1350 rtnl_unlock();
55682965
JB
1351 return err;
1352}
1353
1354static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1355{
79c97e97 1356 struct cfg80211_registered_device *rdev;
463d0183 1357 int err;
55682965
JB
1358 struct net_device *dev;
1359
3b85875a
JB
1360 rtnl_lock();
1361
463d0183 1362 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1363 if (err)
3b85875a 1364 goto unlock_rtnl;
55682965 1365
79c97e97 1366 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1367 err = -EOPNOTSUPP;
1368 goto out;
1369 }
1370
463d0183 1371 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1372
1373 out:
79c97e97 1374 cfg80211_unlock_rdev(rdev);
463d0183 1375 dev_put(dev);
3b85875a
JB
1376 unlock_rtnl:
1377 rtnl_unlock();
55682965
JB
1378 return err;
1379}
1380
41ade00f
JB
1381struct get_key_cookie {
1382 struct sk_buff *msg;
1383 int error;
b9454e83 1384 int idx;
41ade00f
JB
1385};
1386
1387static void get_key_callback(void *c, struct key_params *params)
1388{
b9454e83 1389 struct nlattr *key;
41ade00f
JB
1390 struct get_key_cookie *cookie = c;
1391
1392 if (params->key)
1393 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1394 params->key_len, params->key);
1395
1396 if (params->seq)
1397 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1398 params->seq_len, params->seq);
1399
1400 if (params->cipher)
1401 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1402 params->cipher);
1403
b9454e83
JB
1404 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1405 if (!key)
1406 goto nla_put_failure;
1407
1408 if (params->key)
1409 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1410 params->key_len, params->key);
1411
1412 if (params->seq)
1413 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1414 params->seq_len, params->seq);
1415
1416 if (params->cipher)
1417 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1418 params->cipher);
1419
1420 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1421
1422 nla_nest_end(cookie->msg, key);
1423
41ade00f
JB
1424 return;
1425 nla_put_failure:
1426 cookie->error = 1;
1427}
1428
1429static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1430{
79c97e97 1431 struct cfg80211_registered_device *rdev;
41ade00f
JB
1432 int err;
1433 struct net_device *dev;
1434 u8 key_idx = 0;
1435 u8 *mac_addr = NULL;
1436 struct get_key_cookie cookie = {
1437 .error = 0,
1438 };
1439 void *hdr;
1440 struct sk_buff *msg;
1441
1442 if (info->attrs[NL80211_ATTR_KEY_IDX])
1443 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1444
3cfcf6ac 1445 if (key_idx > 5)
41ade00f
JB
1446 return -EINVAL;
1447
1448 if (info->attrs[NL80211_ATTR_MAC])
1449 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1450
3b85875a
JB
1451 rtnl_lock();
1452
463d0183 1453 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1454 if (err)
3b85875a 1455 goto unlock_rtnl;
41ade00f 1456
79c97e97 1457 if (!rdev->ops->get_key) {
41ade00f
JB
1458 err = -EOPNOTSUPP;
1459 goto out;
1460 }
1461
fd2120ca 1462 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1463 if (!msg) {
1464 err = -ENOMEM;
1465 goto out;
1466 }
1467
1468 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1469 NL80211_CMD_NEW_KEY);
1470
1471 if (IS_ERR(hdr)) {
1472 err = PTR_ERR(hdr);
6c95e2a2 1473 goto free_msg;
41ade00f
JB
1474 }
1475
1476 cookie.msg = msg;
b9454e83 1477 cookie.idx = key_idx;
41ade00f
JB
1478
1479 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1480 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1481 if (mac_addr)
1482 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1483
79c97e97 1484 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1485 &cookie, get_key_callback);
41ade00f
JB
1486
1487 if (err)
6c95e2a2 1488 goto free_msg;
41ade00f
JB
1489
1490 if (cookie.error)
1491 goto nla_put_failure;
1492
1493 genlmsg_end(msg, hdr);
134e6375 1494 err = genlmsg_reply(msg, info);
41ade00f
JB
1495 goto out;
1496
1497 nla_put_failure:
1498 err = -ENOBUFS;
6c95e2a2 1499 free_msg:
41ade00f
JB
1500 nlmsg_free(msg);
1501 out:
79c97e97 1502 cfg80211_unlock_rdev(rdev);
41ade00f 1503 dev_put(dev);
3b85875a
JB
1504 unlock_rtnl:
1505 rtnl_unlock();
1506
41ade00f
JB
1507 return err;
1508}
1509
1510static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1511{
79c97e97 1512 struct cfg80211_registered_device *rdev;
b9454e83 1513 struct key_parse key;
41ade00f
JB
1514 int err;
1515 struct net_device *dev;
3cfcf6ac
JM
1516 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1517 u8 key_index);
41ade00f 1518
b9454e83
JB
1519 err = nl80211_parse_key(info, &key);
1520 if (err)
1521 return err;
41ade00f 1522
b9454e83 1523 if (key.idx < 0)
41ade00f
JB
1524 return -EINVAL;
1525
b9454e83
JB
1526 /* only support setting default key */
1527 if (!key.def && !key.defmgmt)
41ade00f
JB
1528 return -EINVAL;
1529
3b85875a
JB
1530 rtnl_lock();
1531
463d0183 1532 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1533 if (err)
3b85875a 1534 goto unlock_rtnl;
41ade00f 1535
b9454e83 1536 if (key.def)
79c97e97 1537 func = rdev->ops->set_default_key;
3cfcf6ac 1538 else
79c97e97 1539 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1540
1541 if (!func) {
41ade00f
JB
1542 err = -EOPNOTSUPP;
1543 goto out;
1544 }
1545
fffd0934
JB
1546 wdev_lock(dev->ieee80211_ptr);
1547 err = nl80211_key_allowed(dev->ieee80211_ptr);
1548 if (!err)
1549 err = func(&rdev->wiphy, dev, key.idx);
1550
3d23e349 1551#ifdef CONFIG_CFG80211_WEXT
08645126 1552 if (!err) {
79c97e97 1553 if (func == rdev->ops->set_default_key)
b9454e83 1554 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1555 else
b9454e83 1556 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1557 }
1558#endif
fffd0934 1559 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1560
1561 out:
79c97e97 1562 cfg80211_unlock_rdev(rdev);
41ade00f 1563 dev_put(dev);
3b85875a
JB
1564
1565 unlock_rtnl:
1566 rtnl_unlock();
1567
41ade00f
JB
1568 return err;
1569}
1570
1571static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1572{
79c97e97 1573 struct cfg80211_registered_device *rdev;
fffd0934 1574 int err;
41ade00f 1575 struct net_device *dev;
b9454e83 1576 struct key_parse key;
41ade00f
JB
1577 u8 *mac_addr = NULL;
1578
b9454e83
JB
1579 err = nl80211_parse_key(info, &key);
1580 if (err)
1581 return err;
41ade00f 1582
b9454e83 1583 if (!key.p.key)
41ade00f
JB
1584 return -EINVAL;
1585
41ade00f
JB
1586 if (info->attrs[NL80211_ATTR_MAC])
1587 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1588
3b85875a
JB
1589 rtnl_lock();
1590
463d0183 1591 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1592 if (err)
3b85875a 1593 goto unlock_rtnl;
41ade00f 1594
fffd0934
JB
1595 if (!rdev->ops->add_key) {
1596 err = -EOPNOTSUPP;
25e47c18
JB
1597 goto out;
1598 }
1599
fffd0934
JB
1600 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1601 err = -EINVAL;
41ade00f
JB
1602 goto out;
1603 }
1604
fffd0934
JB
1605 wdev_lock(dev->ieee80211_ptr);
1606 err = nl80211_key_allowed(dev->ieee80211_ptr);
1607 if (!err)
1608 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1609 mac_addr, &key.p);
1610 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1611
1612 out:
79c97e97 1613 cfg80211_unlock_rdev(rdev);
41ade00f 1614 dev_put(dev);
3b85875a
JB
1615 unlock_rtnl:
1616 rtnl_unlock();
1617
41ade00f
JB
1618 return err;
1619}
1620
1621static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1622{
79c97e97 1623 struct cfg80211_registered_device *rdev;
41ade00f
JB
1624 int err;
1625 struct net_device *dev;
41ade00f 1626 u8 *mac_addr = NULL;
b9454e83 1627 struct key_parse key;
41ade00f 1628
b9454e83
JB
1629 err = nl80211_parse_key(info, &key);
1630 if (err)
1631 return err;
41ade00f
JB
1632
1633 if (info->attrs[NL80211_ATTR_MAC])
1634 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1635
3b85875a
JB
1636 rtnl_lock();
1637
463d0183 1638 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1639 if (err)
3b85875a 1640 goto unlock_rtnl;
41ade00f 1641
79c97e97 1642 if (!rdev->ops->del_key) {
41ade00f
JB
1643 err = -EOPNOTSUPP;
1644 goto out;
1645 }
1646
fffd0934
JB
1647 wdev_lock(dev->ieee80211_ptr);
1648 err = nl80211_key_allowed(dev->ieee80211_ptr);
1649 if (!err)
1650 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1651
3d23e349 1652#ifdef CONFIG_CFG80211_WEXT
08645126 1653 if (!err) {
b9454e83 1654 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1655 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1656 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1657 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1658 }
1659#endif
fffd0934 1660 wdev_unlock(dev->ieee80211_ptr);
08645126 1661
41ade00f 1662 out:
79c97e97 1663 cfg80211_unlock_rdev(rdev);
41ade00f 1664 dev_put(dev);
3b85875a
JB
1665
1666 unlock_rtnl:
1667 rtnl_unlock();
1668
41ade00f
JB
1669 return err;
1670}
1671
ed1b6cc7
JB
1672static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1673{
1674 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1675 struct beacon_parameters *info);
79c97e97 1676 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1677 int err;
1678 struct net_device *dev;
1679 struct beacon_parameters params;
1680 int haveinfo = 0;
1681
f4a11bb0
JB
1682 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1683 return -EINVAL;
1684
3b85875a
JB
1685 rtnl_lock();
1686
463d0183 1687 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1688 if (err)
3b85875a 1689 goto unlock_rtnl;
ed1b6cc7 1690
eec60b03
JM
1691 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1692 err = -EOPNOTSUPP;
1693 goto out;
1694 }
1695
ed1b6cc7
JB
1696 switch (info->genlhdr->cmd) {
1697 case NL80211_CMD_NEW_BEACON:
1698 /* these are required for NEW_BEACON */
1699 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1700 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1701 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1702 err = -EINVAL;
1703 goto out;
1704 }
1705
79c97e97 1706 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1707 break;
1708 case NL80211_CMD_SET_BEACON:
79c97e97 1709 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1710 break;
1711 default:
1712 WARN_ON(1);
1713 err = -EOPNOTSUPP;
1714 goto out;
1715 }
1716
1717 if (!call) {
1718 err = -EOPNOTSUPP;
1719 goto out;
1720 }
1721
1722 memset(&params, 0, sizeof(params));
1723
1724 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1725 params.interval =
1726 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1727 haveinfo = 1;
1728 }
1729
1730 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1731 params.dtim_period =
1732 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1733 haveinfo = 1;
1734 }
1735
1736 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1737 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1738 params.head_len =
1739 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1740 haveinfo = 1;
1741 }
1742
1743 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1744 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1745 params.tail_len =
1746 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1747 haveinfo = 1;
1748 }
1749
1750 if (!haveinfo) {
1751 err = -EINVAL;
1752 goto out;
1753 }
1754
79c97e97 1755 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1756
1757 out:
79c97e97 1758 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1759 dev_put(dev);
3b85875a
JB
1760 unlock_rtnl:
1761 rtnl_unlock();
1762
ed1b6cc7
JB
1763 return err;
1764}
1765
1766static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1767{
79c97e97 1768 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1769 int err;
1770 struct net_device *dev;
1771
3b85875a
JB
1772 rtnl_lock();
1773
463d0183 1774 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1775 if (err)
3b85875a 1776 goto unlock_rtnl;
ed1b6cc7 1777
79c97e97 1778 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1779 err = -EOPNOTSUPP;
1780 goto out;
1781 }
1782
eec60b03
JM
1783 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1784 err = -EOPNOTSUPP;
1785 goto out;
1786 }
79c97e97 1787 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1788
1789 out:
79c97e97 1790 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1791 dev_put(dev);
3b85875a
JB
1792 unlock_rtnl:
1793 rtnl_unlock();
1794
ed1b6cc7
JB
1795 return err;
1796}
1797
5727ef1b
JB
1798static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1799 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1800 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1801 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1802 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1803};
1804
eccb8e8f
JB
1805static int parse_station_flags(struct genl_info *info,
1806 struct station_parameters *params)
5727ef1b
JB
1807{
1808 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1809 struct nlattr *nla;
5727ef1b
JB
1810 int flag;
1811
eccb8e8f
JB
1812 /*
1813 * Try parsing the new attribute first so userspace
1814 * can specify both for older kernels.
1815 */
1816 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1817 if (nla) {
1818 struct nl80211_sta_flag_update *sta_flags;
1819
1820 sta_flags = nla_data(nla);
1821 params->sta_flags_mask = sta_flags->mask;
1822 params->sta_flags_set = sta_flags->set;
1823 if ((params->sta_flags_mask |
1824 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1825 return -EINVAL;
1826 return 0;
1827 }
1828
1829 /* if present, parse the old attribute */
5727ef1b 1830
eccb8e8f 1831 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1832 if (!nla)
1833 return 0;
1834
1835 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1836 nla, sta_flags_policy))
1837 return -EINVAL;
1838
eccb8e8f
JB
1839 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1840 params->sta_flags_mask &= ~1;
5727ef1b
JB
1841
1842 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1843 if (flags[flag])
eccb8e8f 1844 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1845
1846 return 0;
1847}
1848
fd5b74dc
JB
1849static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1850 int flags, struct net_device *dev,
98b62183 1851 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1852{
1853 void *hdr;
420e7fab
HR
1854 struct nlattr *sinfoattr, *txrate;
1855 u16 bitrate;
fd5b74dc
JB
1856
1857 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1858 if (!hdr)
1859 return -1;
1860
1861 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1862 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1863
f5ea9120
JB
1864 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1865
2ec600d6
LCC
1866 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1867 if (!sinfoattr)
fd5b74dc 1868 goto nla_put_failure;
2ec600d6
LCC
1869 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1870 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1871 sinfo->inactive_time);
1872 if (sinfo->filled & STATION_INFO_RX_BYTES)
1873 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1874 sinfo->rx_bytes);
1875 if (sinfo->filled & STATION_INFO_TX_BYTES)
1876 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1877 sinfo->tx_bytes);
1878 if (sinfo->filled & STATION_INFO_LLID)
1879 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1880 sinfo->llid);
1881 if (sinfo->filled & STATION_INFO_PLID)
1882 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1883 sinfo->plid);
1884 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1885 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1886 sinfo->plink_state);
420e7fab
HR
1887 if (sinfo->filled & STATION_INFO_SIGNAL)
1888 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1889 sinfo->signal);
1890 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1891 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1892 if (!txrate)
1893 goto nla_put_failure;
1894
254416aa
JL
1895 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1896 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
1897 if (bitrate > 0)
1898 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1899
420e7fab
HR
1900 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1901 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1902 sinfo->txrate.mcs);
1903 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1904 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1905 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1906 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1907
1908 nla_nest_end(msg, txrate);
1909 }
98c8a60a
JM
1910 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1911 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1912 sinfo->rx_packets);
1913 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1914 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1915 sinfo->tx_packets);
2ec600d6 1916 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1917
1918 return genlmsg_end(msg, hdr);
1919
1920 nla_put_failure:
bc3ed28c
TG
1921 genlmsg_cancel(msg, hdr);
1922 return -EMSGSIZE;
fd5b74dc
JB
1923}
1924
2ec600d6 1925static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1926 struct netlink_callback *cb)
2ec600d6 1927{
2ec600d6
LCC
1928 struct station_info sinfo;
1929 struct cfg80211_registered_device *dev;
bba95fef 1930 struct net_device *netdev;
2ec600d6 1931 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1932 int ifidx = cb->args[0];
1933 int sta_idx = cb->args[1];
2ec600d6 1934 int err;
2ec600d6 1935
a043897a
HS
1936 if (!ifidx)
1937 ifidx = nl80211_get_ifidx(cb);
1938 if (ifidx < 0)
1939 return ifidx;
2ec600d6 1940
3b85875a
JB
1941 rtnl_lock();
1942
463d0183 1943 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1944 if (!netdev) {
1945 err = -ENODEV;
1946 goto out_rtnl;
1947 }
2ec600d6 1948
463d0183 1949 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1950 if (IS_ERR(dev)) {
1951 err = PTR_ERR(dev);
3b85875a 1952 goto out_rtnl;
bba95fef
JB
1953 }
1954
1955 if (!dev->ops->dump_station) {
eec60b03 1956 err = -EOPNOTSUPP;
bba95fef
JB
1957 goto out_err;
1958 }
1959
bba95fef
JB
1960 while (1) {
1961 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1962 mac_addr, &sinfo);
1963 if (err == -ENOENT)
1964 break;
1965 if (err)
3b85875a 1966 goto out_err;
bba95fef
JB
1967
1968 if (nl80211_send_station(skb,
1969 NETLINK_CB(cb->skb).pid,
1970 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1971 netdev, mac_addr,
1972 &sinfo) < 0)
1973 goto out;
1974
1975 sta_idx++;
1976 }
1977
1978
1979 out:
1980 cb->args[1] = sta_idx;
1981 err = skb->len;
bba95fef 1982 out_err:
4d0c8aea 1983 cfg80211_unlock_rdev(dev);
3b85875a
JB
1984 out_rtnl:
1985 rtnl_unlock();
bba95fef
JB
1986
1987 return err;
2ec600d6 1988}
fd5b74dc 1989
5727ef1b
JB
1990static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1991{
79c97e97 1992 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1993 int err;
1994 struct net_device *dev;
2ec600d6 1995 struct station_info sinfo;
fd5b74dc
JB
1996 struct sk_buff *msg;
1997 u8 *mac_addr = NULL;
1998
2ec600d6 1999 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2000
2001 if (!info->attrs[NL80211_ATTR_MAC])
2002 return -EINVAL;
2003
2004 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2005
3b85875a
JB
2006 rtnl_lock();
2007
463d0183 2008 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 2009 if (err)
3b85875a 2010 goto out_rtnl;
fd5b74dc 2011
79c97e97 2012 if (!rdev->ops->get_station) {
fd5b74dc
JB
2013 err = -EOPNOTSUPP;
2014 goto out;
2015 }
2016
79c97e97 2017 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
2018 if (err)
2019 goto out;
2020
fd2120ca 2021 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
2022 if (!msg)
2023 goto out;
2024
2025 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 2026 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
2027 goto out_free;
2028
134e6375 2029 err = genlmsg_reply(msg, info);
fd5b74dc
JB
2030 goto out;
2031
2032 out_free:
2033 nlmsg_free(msg);
fd5b74dc 2034 out:
79c97e97 2035 cfg80211_unlock_rdev(rdev);
fd5b74dc 2036 dev_put(dev);
3b85875a
JB
2037 out_rtnl:
2038 rtnl_unlock();
2039
fd5b74dc 2040 return err;
5727ef1b
JB
2041}
2042
2043/*
c258d2de 2044 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2045 */
463d0183 2046static int get_vlan(struct genl_info *info,
5727ef1b
JB
2047 struct cfg80211_registered_device *rdev,
2048 struct net_device **vlan)
2049{
463d0183 2050 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2051 *vlan = NULL;
2052
2053 if (vlanattr) {
463d0183
JB
2054 *vlan = dev_get_by_index(genl_info_net(info),
2055 nla_get_u32(vlanattr));
5727ef1b
JB
2056 if (!*vlan)
2057 return -ENODEV;
2058 if (!(*vlan)->ieee80211_ptr)
2059 return -EINVAL;
2060 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2061 return -EINVAL;
c258d2de
FF
2062 if (!netif_running(*vlan))
2063 return -ENETDOWN;
5727ef1b
JB
2064 }
2065 return 0;
2066}
2067
2068static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2069{
79c97e97 2070 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2071 int err;
2072 struct net_device *dev;
2073 struct station_parameters params;
2074 u8 *mac_addr = NULL;
2075
2076 memset(&params, 0, sizeof(params));
2077
2078 params.listen_interval = -1;
2079
2080 if (info->attrs[NL80211_ATTR_STA_AID])
2081 return -EINVAL;
2082
2083 if (!info->attrs[NL80211_ATTR_MAC])
2084 return -EINVAL;
2085
2086 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2087
2088 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2089 params.supported_rates =
2090 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2091 params.supported_rates_len =
2092 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2093 }
2094
2095 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2096 params.listen_interval =
2097 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2098
36aedc90
JM
2099 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2100 params.ht_capa =
2101 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2102
eccb8e8f 2103 if (parse_station_flags(info, &params))
5727ef1b
JB
2104 return -EINVAL;
2105
2ec600d6
LCC
2106 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2107 params.plink_action =
2108 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2109
3b85875a
JB
2110 rtnl_lock();
2111
463d0183 2112 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2113 if (err)
3b85875a 2114 goto out_rtnl;
5727ef1b 2115
463d0183 2116 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2117 if (err)
034d655e 2118 goto out;
a97f4424
JB
2119
2120 /* validate settings */
2121 err = 0;
2122
2123 switch (dev->ieee80211_ptr->iftype) {
2124 case NL80211_IFTYPE_AP:
2125 case NL80211_IFTYPE_AP_VLAN:
2126 /* disallow mesh-specific things */
2127 if (params.plink_action)
2128 err = -EINVAL;
2129 break;
2130 case NL80211_IFTYPE_STATION:
2131 /* disallow everything but AUTHORIZED flag */
2132 if (params.plink_action)
2133 err = -EINVAL;
2134 if (params.vlan)
2135 err = -EINVAL;
2136 if (params.supported_rates)
2137 err = -EINVAL;
2138 if (params.ht_capa)
2139 err = -EINVAL;
2140 if (params.listen_interval >= 0)
2141 err = -EINVAL;
2142 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2143 err = -EINVAL;
2144 break;
2145 case NL80211_IFTYPE_MESH_POINT:
2146 /* disallow things mesh doesn't support */
2147 if (params.vlan)
2148 err = -EINVAL;
2149 if (params.ht_capa)
2150 err = -EINVAL;
2151 if (params.listen_interval >= 0)
2152 err = -EINVAL;
2153 if (params.supported_rates)
2154 err = -EINVAL;
2155 if (params.sta_flags_mask)
2156 err = -EINVAL;
2157 break;
2158 default:
2159 err = -EINVAL;
034d655e
JB
2160 }
2161
5727ef1b
JB
2162 if (err)
2163 goto out;
2164
79c97e97 2165 if (!rdev->ops->change_station) {
5727ef1b
JB
2166 err = -EOPNOTSUPP;
2167 goto out;
2168 }
2169
79c97e97 2170 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2171
2172 out:
2173 if (params.vlan)
2174 dev_put(params.vlan);
79c97e97 2175 cfg80211_unlock_rdev(rdev);
5727ef1b 2176 dev_put(dev);
3b85875a
JB
2177 out_rtnl:
2178 rtnl_unlock();
2179
5727ef1b
JB
2180 return err;
2181}
2182
2183static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2184{
79c97e97 2185 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2186 int err;
2187 struct net_device *dev;
2188 struct station_parameters params;
2189 u8 *mac_addr = NULL;
2190
2191 memset(&params, 0, sizeof(params));
2192
2193 if (!info->attrs[NL80211_ATTR_MAC])
2194 return -EINVAL;
2195
5727ef1b
JB
2196 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2197 return -EINVAL;
2198
2199 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2200 return -EINVAL;
2201
0e956c13
TLSC
2202 if (!info->attrs[NL80211_ATTR_STA_AID])
2203 return -EINVAL;
2204
5727ef1b
JB
2205 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2206 params.supported_rates =
2207 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2208 params.supported_rates_len =
2209 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2210 params.listen_interval =
2211 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2212
0e956c13
TLSC
2213 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2214 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2215 return -EINVAL;
51b50fbe 2216
36aedc90
JM
2217 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2218 params.ht_capa =
2219 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2220
eccb8e8f 2221 if (parse_station_flags(info, &params))
5727ef1b
JB
2222 return -EINVAL;
2223
3b85875a
JB
2224 rtnl_lock();
2225
463d0183 2226 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2227 if (err)
3b85875a 2228 goto out_rtnl;
5727ef1b 2229
0e956c13
TLSC
2230 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2231 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN) {
2232 err = -EINVAL;
2233 goto out;
2234 }
2235
463d0183 2236 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2237 if (err)
e80cf853 2238 goto out;
a97f4424
JB
2239
2240 /* validate settings */
2241 err = 0;
2242
79c97e97 2243 if (!rdev->ops->add_station) {
5727ef1b
JB
2244 err = -EOPNOTSUPP;
2245 goto out;
2246 }
2247
35a8efe1
JM
2248 if (!netif_running(dev)) {
2249 err = -ENETDOWN;
2250 goto out;
2251 }
2252
79c97e97 2253 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2254
2255 out:
2256 if (params.vlan)
2257 dev_put(params.vlan);
79c97e97 2258 cfg80211_unlock_rdev(rdev);
5727ef1b 2259 dev_put(dev);
3b85875a
JB
2260 out_rtnl:
2261 rtnl_unlock();
2262
5727ef1b
JB
2263 return err;
2264}
2265
2266static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2267{
79c97e97 2268 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2269 int err;
2270 struct net_device *dev;
2271 u8 *mac_addr = NULL;
2272
2273 if (info->attrs[NL80211_ATTR_MAC])
2274 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2275
3b85875a
JB
2276 rtnl_lock();
2277
463d0183 2278 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2279 if (err)
3b85875a 2280 goto out_rtnl;
5727ef1b 2281
e80cf853 2282 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02
MP
2283 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2284 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2285 err = -EINVAL;
2286 goto out;
2287 }
2288
79c97e97 2289 if (!rdev->ops->del_station) {
5727ef1b
JB
2290 err = -EOPNOTSUPP;
2291 goto out;
2292 }
2293
79c97e97 2294 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2295
2296 out:
79c97e97 2297 cfg80211_unlock_rdev(rdev);
5727ef1b 2298 dev_put(dev);
3b85875a
JB
2299 out_rtnl:
2300 rtnl_unlock();
2301
5727ef1b
JB
2302 return err;
2303}
2304
2ec600d6
LCC
2305static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2306 int flags, struct net_device *dev,
2307 u8 *dst, u8 *next_hop,
2308 struct mpath_info *pinfo)
2309{
2310 void *hdr;
2311 struct nlattr *pinfoattr;
2312
2313 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2314 if (!hdr)
2315 return -1;
2316
2317 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2318 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2319 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2320
f5ea9120
JB
2321 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2322
2ec600d6
LCC
2323 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2324 if (!pinfoattr)
2325 goto nla_put_failure;
2326 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2327 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2328 pinfo->frame_qlen);
d19b3bf6
RP
2329 if (pinfo->filled & MPATH_INFO_SN)
2330 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2331 pinfo->sn);
2ec600d6
LCC
2332 if (pinfo->filled & MPATH_INFO_METRIC)
2333 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2334 pinfo->metric);
2335 if (pinfo->filled & MPATH_INFO_EXPTIME)
2336 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2337 pinfo->exptime);
2338 if (pinfo->filled & MPATH_INFO_FLAGS)
2339 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2340 pinfo->flags);
2341 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2342 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2343 pinfo->discovery_timeout);
2344 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2345 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2346 pinfo->discovery_retries);
2347
2348 nla_nest_end(msg, pinfoattr);
2349
2350 return genlmsg_end(msg, hdr);
2351
2352 nla_put_failure:
bc3ed28c
TG
2353 genlmsg_cancel(msg, hdr);
2354 return -EMSGSIZE;
2ec600d6
LCC
2355}
2356
2357static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2358 struct netlink_callback *cb)
2ec600d6 2359{
2ec600d6
LCC
2360 struct mpath_info pinfo;
2361 struct cfg80211_registered_device *dev;
bba95fef 2362 struct net_device *netdev;
2ec600d6
LCC
2363 u8 dst[ETH_ALEN];
2364 u8 next_hop[ETH_ALEN];
bba95fef
JB
2365 int ifidx = cb->args[0];
2366 int path_idx = cb->args[1];
2ec600d6 2367 int err;
2ec600d6 2368
a043897a
HS
2369 if (!ifidx)
2370 ifidx = nl80211_get_ifidx(cb);
2371 if (ifidx < 0)
2372 return ifidx;
bba95fef 2373
3b85875a
JB
2374 rtnl_lock();
2375
463d0183 2376 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2377 if (!netdev) {
2378 err = -ENODEV;
2379 goto out_rtnl;
2380 }
bba95fef 2381
463d0183 2382 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2383 if (IS_ERR(dev)) {
2384 err = PTR_ERR(dev);
3b85875a 2385 goto out_rtnl;
bba95fef
JB
2386 }
2387
2388 if (!dev->ops->dump_mpath) {
eec60b03 2389 err = -EOPNOTSUPP;
bba95fef
JB
2390 goto out_err;
2391 }
2392
eec60b03
JM
2393 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2394 err = -EOPNOTSUPP;
0448b5fc 2395 goto out_err;
eec60b03
JM
2396 }
2397
bba95fef
JB
2398 while (1) {
2399 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2400 dst, next_hop, &pinfo);
2401 if (err == -ENOENT)
2ec600d6 2402 break;
bba95fef 2403 if (err)
3b85875a 2404 goto out_err;
2ec600d6 2405
bba95fef
JB
2406 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2407 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2408 netdev, dst, next_hop,
2409 &pinfo) < 0)
2410 goto out;
2ec600d6 2411
bba95fef 2412 path_idx++;
2ec600d6 2413 }
2ec600d6 2414
2ec600d6 2415
bba95fef
JB
2416 out:
2417 cb->args[1] = path_idx;
2418 err = skb->len;
bba95fef 2419 out_err:
4d0c8aea 2420 cfg80211_unlock_rdev(dev);
3b85875a
JB
2421 out_rtnl:
2422 rtnl_unlock();
bba95fef
JB
2423
2424 return err;
2ec600d6
LCC
2425}
2426
2427static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2428{
79c97e97 2429 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2430 int err;
2431 struct net_device *dev;
2432 struct mpath_info pinfo;
2433 struct sk_buff *msg;
2434 u8 *dst = NULL;
2435 u8 next_hop[ETH_ALEN];
2436
2437 memset(&pinfo, 0, sizeof(pinfo));
2438
2439 if (!info->attrs[NL80211_ATTR_MAC])
2440 return -EINVAL;
2441
2442 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2443
3b85875a
JB
2444 rtnl_lock();
2445
463d0183 2446 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2447 if (err)
3b85875a 2448 goto out_rtnl;
2ec600d6 2449
79c97e97 2450 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2451 err = -EOPNOTSUPP;
2452 goto out;
2453 }
2454
eec60b03
JM
2455 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2456 err = -EOPNOTSUPP;
2457 goto out;
2458 }
2459
79c97e97 2460 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2461 if (err)
2462 goto out;
2463
fd2120ca 2464 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2465 if (!msg)
2466 goto out;
2467
2468 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2469 dev, dst, next_hop, &pinfo) < 0)
2470 goto out_free;
2471
134e6375 2472 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2473 goto out;
2474
2475 out_free:
2476 nlmsg_free(msg);
2ec600d6 2477 out:
79c97e97 2478 cfg80211_unlock_rdev(rdev);
2ec600d6 2479 dev_put(dev);
3b85875a
JB
2480 out_rtnl:
2481 rtnl_unlock();
2482
2ec600d6
LCC
2483 return err;
2484}
2485
2486static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2487{
79c97e97 2488 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2489 int err;
2490 struct net_device *dev;
2491 u8 *dst = NULL;
2492 u8 *next_hop = NULL;
2493
2494 if (!info->attrs[NL80211_ATTR_MAC])
2495 return -EINVAL;
2496
2497 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2498 return -EINVAL;
2499
2500 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2501 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2502
3b85875a
JB
2503 rtnl_lock();
2504
463d0183 2505 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2506 if (err)
3b85875a 2507 goto out_rtnl;
2ec600d6 2508
79c97e97 2509 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2510 err = -EOPNOTSUPP;
2511 goto out;
2512 }
2513
eec60b03
JM
2514 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2515 err = -EOPNOTSUPP;
2516 goto out;
2517 }
2518
35a8efe1
JM
2519 if (!netif_running(dev)) {
2520 err = -ENETDOWN;
2521 goto out;
2522 }
2523
79c97e97 2524 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2525
2526 out:
79c97e97 2527 cfg80211_unlock_rdev(rdev);
2ec600d6 2528 dev_put(dev);
3b85875a
JB
2529 out_rtnl:
2530 rtnl_unlock();
2531
2ec600d6
LCC
2532 return err;
2533}
2534static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2535{
79c97e97 2536 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2537 int err;
2538 struct net_device *dev;
2539 u8 *dst = NULL;
2540 u8 *next_hop = NULL;
2541
2542 if (!info->attrs[NL80211_ATTR_MAC])
2543 return -EINVAL;
2544
2545 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2546 return -EINVAL;
2547
2548 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2549 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2550
3b85875a
JB
2551 rtnl_lock();
2552
463d0183 2553 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2554 if (err)
3b85875a 2555 goto out_rtnl;
2ec600d6 2556
79c97e97 2557 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2558 err = -EOPNOTSUPP;
2559 goto out;
2560 }
2561
eec60b03
JM
2562 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2563 err = -EOPNOTSUPP;
2564 goto out;
2565 }
2566
35a8efe1
JM
2567 if (!netif_running(dev)) {
2568 err = -ENETDOWN;
2569 goto out;
2570 }
2571
79c97e97 2572 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2573
2574 out:
79c97e97 2575 cfg80211_unlock_rdev(rdev);
2ec600d6 2576 dev_put(dev);
3b85875a
JB
2577 out_rtnl:
2578 rtnl_unlock();
2579
2ec600d6
LCC
2580 return err;
2581}
2582
2583static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2584{
79c97e97 2585 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2586 int err;
2587 struct net_device *dev;
2588 u8 *dst = NULL;
2589
2590 if (info->attrs[NL80211_ATTR_MAC])
2591 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2592
3b85875a
JB
2593 rtnl_lock();
2594
463d0183 2595 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2596 if (err)
3b85875a 2597 goto out_rtnl;
2ec600d6 2598
79c97e97 2599 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2600 err = -EOPNOTSUPP;
2601 goto out;
2602 }
2603
79c97e97 2604 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2605
2606 out:
79c97e97 2607 cfg80211_unlock_rdev(rdev);
2ec600d6 2608 dev_put(dev);
3b85875a
JB
2609 out_rtnl:
2610 rtnl_unlock();
2611
2ec600d6
LCC
2612 return err;
2613}
2614
9f1ba906
JM
2615static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2616{
79c97e97 2617 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2618 int err;
2619 struct net_device *dev;
2620 struct bss_parameters params;
2621
2622 memset(&params, 0, sizeof(params));
2623 /* default to not changing parameters */
2624 params.use_cts_prot = -1;
2625 params.use_short_preamble = -1;
2626 params.use_short_slot_time = -1;
fd8aaaf3 2627 params.ap_isolate = -1;
9f1ba906
JM
2628
2629 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2630 params.use_cts_prot =
2631 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2632 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2633 params.use_short_preamble =
2634 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2635 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2636 params.use_short_slot_time =
2637 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2638 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2639 params.basic_rates =
2640 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2641 params.basic_rates_len =
2642 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2643 }
fd8aaaf3
FF
2644 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2645 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
9f1ba906 2646
3b85875a
JB
2647 rtnl_lock();
2648
463d0183 2649 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2650 if (err)
3b85875a 2651 goto out_rtnl;
9f1ba906 2652
79c97e97 2653 if (!rdev->ops->change_bss) {
9f1ba906
JM
2654 err = -EOPNOTSUPP;
2655 goto out;
2656 }
2657
eec60b03
JM
2658 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2659 err = -EOPNOTSUPP;
2660 goto out;
2661 }
2662
79c97e97 2663 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2664
2665 out:
79c97e97 2666 cfg80211_unlock_rdev(rdev);
9f1ba906 2667 dev_put(dev);
3b85875a
JB
2668 out_rtnl:
2669 rtnl_unlock();
2670
9f1ba906
JM
2671 return err;
2672}
2673
b54452b0 2674static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2675 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2676 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2677 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2678 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2679 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2680 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2681};
2682
2683static int parse_reg_rule(struct nlattr *tb[],
2684 struct ieee80211_reg_rule *reg_rule)
2685{
2686 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2687 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2688
2689 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2690 return -EINVAL;
2691 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2692 return -EINVAL;
2693 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2694 return -EINVAL;
2695 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2696 return -EINVAL;
2697 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2698 return -EINVAL;
2699
2700 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2701
2702 freq_range->start_freq_khz =
2703 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2704 freq_range->end_freq_khz =
2705 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2706 freq_range->max_bandwidth_khz =
2707 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2708
2709 power_rule->max_eirp =
2710 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2711
2712 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2713 power_rule->max_antenna_gain =
2714 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2715
2716 return 0;
2717}
2718
2719static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2720{
2721 int r;
2722 char *data = NULL;
2723
80778f18
LR
2724 /*
2725 * You should only get this when cfg80211 hasn't yet initialized
2726 * completely when built-in to the kernel right between the time
2727 * window between nl80211_init() and regulatory_init(), if that is
2728 * even possible.
2729 */
2730 mutex_lock(&cfg80211_mutex);
2731 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2732 mutex_unlock(&cfg80211_mutex);
2733 return -EINPROGRESS;
80778f18 2734 }
fe33eb39 2735 mutex_unlock(&cfg80211_mutex);
80778f18 2736
fe33eb39
LR
2737 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2738 return -EINVAL;
b2e1b302
LR
2739
2740 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2741
fe33eb39
LR
2742 r = regulatory_hint_user(data);
2743
b2e1b302
LR
2744 return r;
2745}
2746
93da9cc1 2747static int nl80211_get_mesh_params(struct sk_buff *skb,
2748 struct genl_info *info)
2749{
79c97e97 2750 struct cfg80211_registered_device *rdev;
93da9cc1 2751 struct mesh_config cur_params;
2752 int err;
2753 struct net_device *dev;
2754 void *hdr;
2755 struct nlattr *pinfoattr;
2756 struct sk_buff *msg;
2757
3b85875a
JB
2758 rtnl_lock();
2759
93da9cc1 2760 /* Look up our device */
463d0183 2761 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2762 if (err)
3b85875a 2763 goto out_rtnl;
93da9cc1 2764
79c97e97 2765 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2766 err = -EOPNOTSUPP;
2767 goto out;
2768 }
2769
93da9cc1 2770 /* Get the mesh params */
79c97e97 2771 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2772 if (err)
2773 goto out;
2774
2775 /* Draw up a netlink message to send back */
fd2120ca 2776 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2777 if (!msg) {
2778 err = -ENOBUFS;
2779 goto out;
2780 }
2781 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2782 NL80211_CMD_GET_MESH_PARAMS);
2783 if (!hdr)
2784 goto nla_put_failure;
2785 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2786 if (!pinfoattr)
2787 goto nla_put_failure;
2788 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2789 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2790 cur_params.dot11MeshRetryTimeout);
2791 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2792 cur_params.dot11MeshConfirmTimeout);
2793 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2794 cur_params.dot11MeshHoldingTimeout);
2795 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2796 cur_params.dot11MeshMaxPeerLinks);
2797 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2798 cur_params.dot11MeshMaxRetries);
2799 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2800 cur_params.dot11MeshTTL);
2801 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2802 cur_params.auto_open_plinks);
2803 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2804 cur_params.dot11MeshHWMPmaxPREQretries);
2805 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2806 cur_params.path_refresh_time);
2807 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2808 cur_params.min_discovery_timeout);
2809 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2810 cur_params.dot11MeshHWMPactivePathTimeout);
2811 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2812 cur_params.dot11MeshHWMPpreqMinInterval);
2813 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2814 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2815 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2816 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2817 nla_nest_end(msg, pinfoattr);
2818 genlmsg_end(msg, hdr);
134e6375 2819 err = genlmsg_reply(msg, info);
93da9cc1 2820 goto out;
2821
3b85875a 2822 nla_put_failure:
93da9cc1 2823 genlmsg_cancel(msg, hdr);
d080e275 2824 nlmsg_free(msg);
93da9cc1 2825 err = -EMSGSIZE;
3b85875a 2826 out:
93da9cc1 2827 /* Cleanup */
79c97e97 2828 cfg80211_unlock_rdev(rdev);
93da9cc1 2829 dev_put(dev);
3b85875a
JB
2830 out_rtnl:
2831 rtnl_unlock();
2832
93da9cc1 2833 return err;
2834}
2835
2836#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2837do {\
2838 if (table[attr_num]) {\
2839 cfg.param = nla_fn(table[attr_num]); \
2840 mask |= (1 << (attr_num - 1)); \
2841 } \
2842} while (0);\
2843
b54452b0 2844static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2845 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2846 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2847 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2848 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2849 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2850 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2851 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2852
2853 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2854 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2855 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2856 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2857 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2858 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2859};
2860
2861static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2862{
2863 int err;
2864 u32 mask;
79c97e97 2865 struct cfg80211_registered_device *rdev;
93da9cc1 2866 struct net_device *dev;
2867 struct mesh_config cfg;
2868 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2869 struct nlattr *parent_attr;
2870
2871 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2872 if (!parent_attr)
2873 return -EINVAL;
2874 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2875 parent_attr, nl80211_meshconf_params_policy))
2876 return -EINVAL;
2877
3b85875a
JB
2878 rtnl_lock();
2879
463d0183 2880 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2881 if (err)
3b85875a 2882 goto out_rtnl;
93da9cc1 2883
79c97e97 2884 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2885 err = -EOPNOTSUPP;
2886 goto out;
2887 }
2888
93da9cc1 2889 /* This makes sure that there aren't more than 32 mesh config
2890 * parameters (otherwise our bitfield scheme would not work.) */
2891 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2892
2893 /* Fill in the params struct */
2894 mask = 0;
2895 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2896 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2897 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2898 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2899 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2900 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2901 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2902 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2903 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2904 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2905 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2906 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2907 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2908 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2909 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2910 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2911 nla_get_u8);
2912 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2913 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2914 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2915 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2916 nla_get_u16);
2917 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2918 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2919 nla_get_u32);
2920 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2921 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2922 nla_get_u16);
2923 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2924 dot11MeshHWMPnetDiameterTraversalTime,
2925 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2926 nla_get_u16);
63c5723b
RP
2927 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2928 dot11MeshHWMPRootMode, mask,
2929 NL80211_MESHCONF_HWMP_ROOTMODE,
2930 nla_get_u8);
93da9cc1 2931
2932 /* Apply changes */
79c97e97 2933 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2934
f3f92586 2935 out:
93da9cc1 2936 /* cleanup */
79c97e97 2937 cfg80211_unlock_rdev(rdev);
93da9cc1 2938 dev_put(dev);
3b85875a
JB
2939 out_rtnl:
2940 rtnl_unlock();
2941
93da9cc1 2942 return err;
2943}
2944
2945#undef FILL_IN_MESH_PARAM_IF_SET
2946
f130347c
LR
2947static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2948{
2949 struct sk_buff *msg;
2950 void *hdr = NULL;
2951 struct nlattr *nl_reg_rules;
2952 unsigned int i;
2953 int err = -EINVAL;
2954
a1794390 2955 mutex_lock(&cfg80211_mutex);
f130347c
LR
2956
2957 if (!cfg80211_regdomain)
2958 goto out;
2959
fd2120ca 2960 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2961 if (!msg) {
2962 err = -ENOBUFS;
2963 goto out;
2964 }
2965
2966 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2967 NL80211_CMD_GET_REG);
2968 if (!hdr)
2969 goto nla_put_failure;
2970
2971 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2972 cfg80211_regdomain->alpha2);
2973
2974 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2975 if (!nl_reg_rules)
2976 goto nla_put_failure;
2977
2978 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2979 struct nlattr *nl_reg_rule;
2980 const struct ieee80211_reg_rule *reg_rule;
2981 const struct ieee80211_freq_range *freq_range;
2982 const struct ieee80211_power_rule *power_rule;
2983
2984 reg_rule = &cfg80211_regdomain->reg_rules[i];
2985 freq_range = &reg_rule->freq_range;
2986 power_rule = &reg_rule->power_rule;
2987
2988 nl_reg_rule = nla_nest_start(msg, i);
2989 if (!nl_reg_rule)
2990 goto nla_put_failure;
2991
2992 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2993 reg_rule->flags);
2994 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2995 freq_range->start_freq_khz);
2996 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2997 freq_range->end_freq_khz);
2998 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2999 freq_range->max_bandwidth_khz);
3000 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3001 power_rule->max_antenna_gain);
3002 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3003 power_rule->max_eirp);
3004
3005 nla_nest_end(msg, nl_reg_rule);
3006 }
3007
3008 nla_nest_end(msg, nl_reg_rules);
3009
3010 genlmsg_end(msg, hdr);
134e6375 3011 err = genlmsg_reply(msg, info);
f130347c
LR
3012 goto out;
3013
3014nla_put_failure:
3015 genlmsg_cancel(msg, hdr);
d080e275 3016 nlmsg_free(msg);
f130347c
LR
3017 err = -EMSGSIZE;
3018out:
a1794390 3019 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3020 return err;
3021}
3022
b2e1b302
LR
3023static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3024{
3025 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3026 struct nlattr *nl_reg_rule;
3027 char *alpha2 = NULL;
3028 int rem_reg_rules = 0, r = 0;
3029 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3030 struct ieee80211_regdomain *rd = NULL;
3031
3032 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3033 return -EINVAL;
3034
3035 if (!info->attrs[NL80211_ATTR_REG_RULES])
3036 return -EINVAL;
3037
3038 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3039
3040 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3041 rem_reg_rules) {
3042 num_rules++;
3043 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3044 return -EINVAL;
b2e1b302
LR
3045 }
3046
61405e97
LR
3047 mutex_lock(&cfg80211_mutex);
3048
d0e18f83
LR
3049 if (!reg_is_valid_request(alpha2)) {
3050 r = -EINVAL;
3051 goto bad_reg;
3052 }
b2e1b302
LR
3053
3054 size_of_regd = sizeof(struct ieee80211_regdomain) +
3055 (num_rules * sizeof(struct ieee80211_reg_rule));
3056
3057 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3058 if (!rd) {
3059 r = -ENOMEM;
3060 goto bad_reg;
3061 }
b2e1b302
LR
3062
3063 rd->n_reg_rules = num_rules;
3064 rd->alpha2[0] = alpha2[0];
3065 rd->alpha2[1] = alpha2[1];
3066
3067 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3068 rem_reg_rules) {
3069 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3070 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3071 reg_rule_policy);
3072 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3073 if (r)
3074 goto bad_reg;
3075
3076 rule_idx++;
3077
d0e18f83
LR
3078 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3079 r = -EINVAL;
b2e1b302 3080 goto bad_reg;
d0e18f83 3081 }
b2e1b302
LR
3082 }
3083
3084 BUG_ON(rule_idx != num_rules);
3085
b2e1b302 3086 r = set_regdom(rd);
61405e97 3087
a1794390 3088 mutex_unlock(&cfg80211_mutex);
d0e18f83 3089
b2e1b302
LR
3090 return r;
3091
d2372b31 3092 bad_reg:
61405e97 3093 mutex_unlock(&cfg80211_mutex);
b2e1b302 3094 kfree(rd);
d0e18f83 3095 return r;
b2e1b302
LR
3096}
3097
83f5e2cf
JB
3098static int validate_scan_freqs(struct nlattr *freqs)
3099{
3100 struct nlattr *attr1, *attr2;
3101 int n_channels = 0, tmp1, tmp2;
3102
3103 nla_for_each_nested(attr1, freqs, tmp1) {
3104 n_channels++;
3105 /*
3106 * Some hardware has a limited channel list for
3107 * scanning, and it is pretty much nonsensical
3108 * to scan for a channel twice, so disallow that
3109 * and don't require drivers to check that the
3110 * channel list they get isn't longer than what
3111 * they can scan, as long as they can scan all
3112 * the channels they registered at once.
3113 */
3114 nla_for_each_nested(attr2, freqs, tmp2)
3115 if (attr1 != attr2 &&
3116 nla_get_u32(attr1) == nla_get_u32(attr2))
3117 return 0;
3118 }
3119
3120 return n_channels;
3121}
3122
2a519311
JB
3123static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3124{
79c97e97 3125 struct cfg80211_registered_device *rdev;
2a519311
JB
3126 struct net_device *dev;
3127 struct cfg80211_scan_request *request;
3128 struct cfg80211_ssid *ssid;
3129 struct ieee80211_channel *channel;
3130 struct nlattr *attr;
3131 struct wiphy *wiphy;
83f5e2cf 3132 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3133 enum ieee80211_band band;
70692ad2 3134 size_t ie_len;
2a519311 3135
f4a11bb0
JB
3136 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3137 return -EINVAL;
3138
3b85875a
JB
3139 rtnl_lock();
3140
463d0183 3141 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 3142 if (err)
3b85875a 3143 goto out_rtnl;
2a519311 3144
79c97e97 3145 wiphy = &rdev->wiphy;
2a519311 3146
79c97e97 3147 if (!rdev->ops->scan) {
2a519311
JB
3148 err = -EOPNOTSUPP;
3149 goto out;
3150 }
3151
35a8efe1
JM
3152 if (!netif_running(dev)) {
3153 err = -ENETDOWN;
3154 goto out;
3155 }
3156
79c97e97 3157 if (rdev->scan_req) {
2a519311 3158 err = -EBUSY;
3b85875a 3159 goto out;
2a519311
JB
3160 }
3161
3162 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3163 n_channels = validate_scan_freqs(
3164 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
3165 if (!n_channels) {
3166 err = -EINVAL;
3b85875a 3167 goto out;
2a519311
JB
3168 }
3169 } else {
83f5e2cf
JB
3170 n_channels = 0;
3171
2a519311
JB
3172 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3173 if (wiphy->bands[band])
3174 n_channels += wiphy->bands[band]->n_channels;
3175 }
3176
3177 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3178 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3179 n_ssids++;
3180
3181 if (n_ssids > wiphy->max_scan_ssids) {
3182 err = -EINVAL;
3b85875a 3183 goto out;
2a519311
JB
3184 }
3185
70692ad2
JM
3186 if (info->attrs[NL80211_ATTR_IE])
3187 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3188 else
3189 ie_len = 0;
3190
18a83659
JB
3191 if (ie_len > wiphy->max_scan_ie_len) {
3192 err = -EINVAL;
3193 goto out;
3194 }
3195
2a519311
JB
3196 request = kzalloc(sizeof(*request)
3197 + sizeof(*ssid) * n_ssids
70692ad2
JM
3198 + sizeof(channel) * n_channels
3199 + ie_len, GFP_KERNEL);
2a519311
JB
3200 if (!request) {
3201 err = -ENOMEM;
3b85875a 3202 goto out;
2a519311
JB
3203 }
3204
2a519311 3205 if (n_ssids)
5ba63533 3206 request->ssids = (void *)&request->channels[n_channels];
2a519311 3207 request->n_ssids = n_ssids;
70692ad2
JM
3208 if (ie_len) {
3209 if (request->ssids)
3210 request->ie = (void *)(request->ssids + n_ssids);
3211 else
3212 request->ie = (void *)(request->channels + n_channels);
3213 }
2a519311 3214
584991dc 3215 i = 0;
2a519311
JB
3216 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3217 /* user specified, bail out if channel not found */
2a519311 3218 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3219 struct ieee80211_channel *chan;
3220
3221 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3222
3223 if (!chan) {
2a519311
JB
3224 err = -EINVAL;
3225 goto out_free;
3226 }
584991dc
JB
3227
3228 /* ignore disabled channels */
3229 if (chan->flags & IEEE80211_CHAN_DISABLED)
3230 continue;
3231
3232 request->channels[i] = chan;
2a519311
JB
3233 i++;
3234 }
3235 } else {
3236 /* all channels */
2a519311
JB
3237 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3238 int j;
3239 if (!wiphy->bands[band])
3240 continue;
3241 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3242 struct ieee80211_channel *chan;
3243
3244 chan = &wiphy->bands[band]->channels[j];
3245
3246 if (chan->flags & IEEE80211_CHAN_DISABLED)
3247 continue;
3248
3249 request->channels[i] = chan;
2a519311
JB
3250 i++;
3251 }
3252 }
3253 }
3254
584991dc
JB
3255 if (!i) {
3256 err = -EINVAL;
3257 goto out_free;
3258 }
3259
3260 request->n_channels = i;
3261
2a519311
JB
3262 i = 0;
3263 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3264 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3265 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3266 err = -EINVAL;
3267 goto out_free;
3268 }
3269 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3270 request->ssids[i].ssid_len = nla_len(attr);
3271 i++;
3272 }
3273 }
3274
70692ad2
JM
3275 if (info->attrs[NL80211_ATTR_IE]) {
3276 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3277 memcpy((void *)request->ie,
3278 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3279 request->ie_len);
3280 }
3281
463d0183 3282 request->dev = dev;
79c97e97 3283 request->wiphy = &rdev->wiphy;
2a519311 3284
79c97e97
JB
3285 rdev->scan_req = request;
3286 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3287
463d0183 3288 if (!err) {
79c97e97 3289 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3290 dev_hold(dev);
3291 }
a538e2d5 3292
2a519311
JB
3293 out_free:
3294 if (err) {
79c97e97 3295 rdev->scan_req = NULL;
2a519311
JB
3296 kfree(request);
3297 }
2a519311 3298 out:
79c97e97 3299 cfg80211_unlock_rdev(rdev);
2a519311 3300 dev_put(dev);
3b85875a
JB
3301 out_rtnl:
3302 rtnl_unlock();
3303
2a519311
JB
3304 return err;
3305}
3306
3307static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3308 struct cfg80211_registered_device *rdev,
48ab905d
JB
3309 struct wireless_dev *wdev,
3310 struct cfg80211_internal_bss *intbss)
2a519311 3311{
48ab905d 3312 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3313 void *hdr;
3314 struct nlattr *bss;
48ab905d
JB
3315 int i;
3316
3317 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3318
3319 hdr = nl80211hdr_put(msg, pid, seq, flags,
3320 NL80211_CMD_NEW_SCAN_RESULTS);
3321 if (!hdr)
3322 return -1;
3323
f5ea9120 3324 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3325 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3326
3327 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3328 if (!bss)
3329 goto nla_put_failure;
3330 if (!is_zero_ether_addr(res->bssid))
3331 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3332 if (res->information_elements && res->len_information_elements)
3333 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3334 res->len_information_elements,
3335 res->information_elements);
34a6eddb
JM
3336 if (res->beacon_ies && res->len_beacon_ies &&
3337 res->beacon_ies != res->information_elements)
3338 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3339 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3340 if (res->tsf)
3341 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3342 if (res->beacon_interval)
3343 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3344 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3345 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3346 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3347 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3348
77965c97 3349 switch (rdev->wiphy.signal_type) {
2a519311
JB
3350 case CFG80211_SIGNAL_TYPE_MBM:
3351 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3352 break;
3353 case CFG80211_SIGNAL_TYPE_UNSPEC:
3354 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3355 break;
3356 default:
3357 break;
3358 }
3359
48ab905d
JB
3360 switch (wdev->iftype) {
3361 case NL80211_IFTYPE_STATION:
3362 if (intbss == wdev->current_bss)
3363 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3364 NL80211_BSS_STATUS_ASSOCIATED);
3365 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3366 if (intbss != wdev->auth_bsses[i])
3367 continue;
3368 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3369 NL80211_BSS_STATUS_AUTHENTICATED);
3370 break;
3371 }
3372 break;
3373 case NL80211_IFTYPE_ADHOC:
3374 if (intbss == wdev->current_bss)
3375 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3376 NL80211_BSS_STATUS_IBSS_JOINED);
3377 break;
3378 default:
3379 break;
3380 }
3381
2a519311
JB
3382 nla_nest_end(msg, bss);
3383
3384 return genlmsg_end(msg, hdr);
3385
3386 nla_put_failure:
3387 genlmsg_cancel(msg, hdr);
3388 return -EMSGSIZE;
3389}
3390
3391static int nl80211_dump_scan(struct sk_buff *skb,
3392 struct netlink_callback *cb)
3393{
48ab905d
JB
3394 struct cfg80211_registered_device *rdev;
3395 struct net_device *dev;
2a519311 3396 struct cfg80211_internal_bss *scan;
48ab905d 3397 struct wireless_dev *wdev;
2a519311
JB
3398 int ifidx = cb->args[0];
3399 int start = cb->args[1], idx = 0;
3400 int err;
3401
a043897a
HS
3402 if (!ifidx)
3403 ifidx = nl80211_get_ifidx(cb);
3404 if (ifidx < 0)
3405 return ifidx;
3406 cb->args[0] = ifidx;
2a519311 3407
463d0183 3408 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3409 if (!dev)
2a519311
JB
3410 return -ENODEV;
3411
463d0183 3412 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3413 if (IS_ERR(rdev)) {
3414 err = PTR_ERR(rdev);
2a519311
JB
3415 goto out_put_netdev;
3416 }
3417
48ab905d 3418 wdev = dev->ieee80211_ptr;
2a519311 3419
48ab905d
JB
3420 wdev_lock(wdev);
3421 spin_lock_bh(&rdev->bss_lock);
3422 cfg80211_bss_expire(rdev);
3423
3424 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3425 if (++idx <= start)
3426 continue;
3427 if (nl80211_send_bss(skb,
3428 NETLINK_CB(cb->skb).pid,
3429 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3430 rdev, wdev, scan) < 0) {
2a519311
JB
3431 idx--;
3432 goto out;
3433 }
3434 }
3435
3436 out:
48ab905d
JB
3437 spin_unlock_bh(&rdev->bss_lock);
3438 wdev_unlock(wdev);
2a519311
JB
3439
3440 cb->args[1] = idx;
3441 err = skb->len;
48ab905d 3442 cfg80211_unlock_rdev(rdev);
2a519311 3443 out_put_netdev:
48ab905d 3444 dev_put(dev);
2a519311
JB
3445
3446 return err;
3447}
3448
61fa713c
HS
3449static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3450 int flags, struct net_device *dev,
3451 struct survey_info *survey)
3452{
3453 void *hdr;
3454 struct nlattr *infoattr;
3455
3456 /* Survey without a channel doesn't make sense */
3457 if (!survey->channel)
3458 return -EINVAL;
3459
3460 hdr = nl80211hdr_put(msg, pid, seq, flags,
3461 NL80211_CMD_NEW_SURVEY_RESULTS);
3462 if (!hdr)
3463 return -ENOMEM;
3464
3465 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3466
3467 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3468 if (!infoattr)
3469 goto nla_put_failure;
3470
3471 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3472 survey->channel->center_freq);
3473 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3474 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3475 survey->noise);
3476
3477 nla_nest_end(msg, infoattr);
3478
3479 return genlmsg_end(msg, hdr);
3480
3481 nla_put_failure:
3482 genlmsg_cancel(msg, hdr);
3483 return -EMSGSIZE;
3484}
3485
3486static int nl80211_dump_survey(struct sk_buff *skb,
3487 struct netlink_callback *cb)
3488{
3489 struct survey_info survey;
3490 struct cfg80211_registered_device *dev;
3491 struct net_device *netdev;
3492 int ifidx = cb->args[0];
3493 int survey_idx = cb->args[1];
3494 int res;
3495
3496 if (!ifidx)
3497 ifidx = nl80211_get_ifidx(cb);
3498 if (ifidx < 0)
3499 return ifidx;
3500 cb->args[0] = ifidx;
3501
3502 rtnl_lock();
3503
3504 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3505 if (!netdev) {
3506 res = -ENODEV;
3507 goto out_rtnl;
3508 }
3509
3510 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3511 if (IS_ERR(dev)) {
3512 res = PTR_ERR(dev);
3513 goto out_rtnl;
3514 }
3515
3516 if (!dev->ops->dump_survey) {
3517 res = -EOPNOTSUPP;
3518 goto out_err;
3519 }
3520
3521 while (1) {
3522 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3523 &survey);
3524 if (res == -ENOENT)
3525 break;
3526 if (res)
3527 goto out_err;
3528
3529 if (nl80211_send_survey(skb,
3530 NETLINK_CB(cb->skb).pid,
3531 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3532 netdev,
3533 &survey) < 0)
3534 goto out;
3535 survey_idx++;
3536 }
3537
3538 out:
3539 cb->args[1] = survey_idx;
3540 res = skb->len;
3541 out_err:
3542 cfg80211_unlock_rdev(dev);
3543 out_rtnl:
3544 rtnl_unlock();
3545
3546 return res;
3547}
3548
255e737e
JM
3549static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3550{
b23aa676
SO
3551 return auth_type <= NL80211_AUTHTYPE_MAX;
3552}
3553
3554static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3555{
3556 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3557 NL80211_WPA_VERSION_2));
3558}
3559
3560static bool nl80211_valid_akm_suite(u32 akm)
3561{
3562 return akm == WLAN_AKM_SUITE_8021X ||
3563 akm == WLAN_AKM_SUITE_PSK;
3564}
3565
3566static bool nl80211_valid_cipher_suite(u32 cipher)
3567{
3568 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3569 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3570 cipher == WLAN_CIPHER_SUITE_TKIP ||
3571 cipher == WLAN_CIPHER_SUITE_CCMP ||
3572 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3573}
3574
b23aa676 3575
636a5d36
JM
3576static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3577{
79c97e97 3578 struct cfg80211_registered_device *rdev;
636a5d36 3579 struct net_device *dev;
19957bb3
JB
3580 struct ieee80211_channel *chan;
3581 const u8 *bssid, *ssid, *ie = NULL;
3582 int err, ssid_len, ie_len = 0;
3583 enum nl80211_auth_type auth_type;
fffd0934 3584 struct key_parse key;
d5cdfacb 3585 bool local_state_change;
636a5d36 3586
f4a11bb0
JB
3587 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3588 return -EINVAL;
3589
3590 if (!info->attrs[NL80211_ATTR_MAC])
3591 return -EINVAL;
3592
1778092e
JM
3593 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3594 return -EINVAL;
3595
19957bb3
JB
3596 if (!info->attrs[NL80211_ATTR_SSID])
3597 return -EINVAL;
3598
3599 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3600 return -EINVAL;
3601
fffd0934
JB
3602 err = nl80211_parse_key(info, &key);
3603 if (err)
3604 return err;
3605
3606 if (key.idx >= 0) {
3607 if (!key.p.key || !key.p.key_len)
3608 return -EINVAL;
3609 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3610 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3611 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3612 key.p.key_len != WLAN_KEY_LEN_WEP104))
3613 return -EINVAL;
3614 if (key.idx > 4)
3615 return -EINVAL;
3616 } else {
3617 key.p.key_len = 0;
3618 key.p.key = NULL;
3619 }
3620
636a5d36
JM
3621 rtnl_lock();
3622
463d0183 3623 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3624 if (err)
3625 goto unlock_rtnl;
3626
afea0b7a
JB
3627 if (key.idx >= 0) {
3628 int i;
3629 bool ok = false;
3630 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3631 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3632 ok = true;
3633 break;
3634 }
3635 }
3636 if (!ok) {
3637 err = -EINVAL;
3638 goto out;
3639 }
3640 }
3641
79c97e97 3642 if (!rdev->ops->auth) {
636a5d36
JM
3643 err = -EOPNOTSUPP;
3644 goto out;
3645 }
3646
eec60b03
JM
3647 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3648 err = -EOPNOTSUPP;
3649 goto out;
3650 }
3651
35a8efe1
JM
3652 if (!netif_running(dev)) {
3653 err = -ENETDOWN;
3654 goto out;
3655 }
3656
19957bb3 3657 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3658 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3659 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3660 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3661 err = -EINVAL;
3662 goto out;
636a5d36
JM
3663 }
3664
19957bb3
JB
3665 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3666 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3667
3668 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3669 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3670 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3671 }
3672
19957bb3
JB
3673 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3674 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3675 err = -EINVAL;
3676 goto out;
636a5d36
JM
3677 }
3678
d5cdfacb
JM
3679 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3680
79c97e97 3681 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934 3682 ssid, ssid_len, ie, ie_len,
d5cdfacb
JM
3683 key.p.key, key.p.key_len, key.idx,
3684 local_state_change);
636a5d36
JM
3685
3686out:
79c97e97 3687 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3688 dev_put(dev);
3689unlock_rtnl:
3690 rtnl_unlock();
3691 return err;
3692}
3693
b23aa676 3694static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3695 struct cfg80211_crypto_settings *settings,
3696 int cipher_limit)
b23aa676 3697{
c0b2bbd8
JB
3698 memset(settings, 0, sizeof(*settings));
3699
b23aa676
SO
3700 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3701
3702 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3703 void *data;
3704 int len, i;
3705
3706 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3707 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3708 settings->n_ciphers_pairwise = len / sizeof(u32);
3709
3710 if (len % sizeof(u32))
3711 return -EINVAL;
3712
3dc27d25 3713 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3714 return -EINVAL;
3715
3716 memcpy(settings->ciphers_pairwise, data, len);
3717
3718 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3719 if (!nl80211_valid_cipher_suite(
3720 settings->ciphers_pairwise[i]))
3721 return -EINVAL;
3722 }
3723
3724 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3725 settings->cipher_group =
3726 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3727 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3728 return -EINVAL;
3729 }
3730
3731 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3732 settings->wpa_versions =
3733 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3734 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3735 return -EINVAL;
3736 }
3737
3738 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3739 void *data;
3740 int len, i;
3741
3742 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3743 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3744 settings->n_akm_suites = len / sizeof(u32);
3745
3746 if (len % sizeof(u32))
3747 return -EINVAL;
3748
3749 memcpy(settings->akm_suites, data, len);
3750
3751 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3752 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3753 return -EINVAL;
3754 }
3755
3756 return 0;
3757}
3758
636a5d36
JM
3759static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3760{
19957bb3 3761 struct cfg80211_registered_device *rdev;
636a5d36 3762 struct net_device *dev;
19957bb3 3763 struct cfg80211_crypto_settings crypto;
f444de05 3764 struct ieee80211_channel *chan;
3e5d7649 3765 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3766 int err, ssid_len, ie_len = 0;
3767 bool use_mfp = false;
636a5d36 3768
f4a11bb0
JB
3769 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3770 return -EINVAL;
3771
3772 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3773 !info->attrs[NL80211_ATTR_SSID] ||
3774 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3775 return -EINVAL;
3776
636a5d36
JM
3777 rtnl_lock();
3778
463d0183 3779 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3780 if (err)
3781 goto unlock_rtnl;
3782
19957bb3 3783 if (!rdev->ops->assoc) {
636a5d36
JM
3784 err = -EOPNOTSUPP;
3785 goto out;
3786 }
3787
eec60b03
JM
3788 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3789 err = -EOPNOTSUPP;
3790 goto out;
3791 }
3792
35a8efe1
JM
3793 if (!netif_running(dev)) {
3794 err = -ENETDOWN;
3795 goto out;
3796 }
3797
19957bb3 3798 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3799
19957bb3
JB
3800 chan = ieee80211_get_channel(&rdev->wiphy,
3801 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3802 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3803 err = -EINVAL;
3804 goto out;
636a5d36
JM
3805 }
3806
19957bb3
JB
3807 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3808 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3809
3810 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3811 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3812 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3813 }
3814
dc6382ce 3815 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3816 enum nl80211_mfp mfp =
dc6382ce 3817 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3818 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3819 use_mfp = true;
4f5dadce 3820 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3821 err = -EINVAL;
3822 goto out;
3823 }
3824 }
3825
3e5d7649
JB
3826 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3827 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3828
3dc27d25 3829 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3830 if (!err)
3e5d7649
JB
3831 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3832 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3833 &crypto);
636a5d36
JM
3834
3835out:
4d0c8aea 3836 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3837 dev_put(dev);
3838unlock_rtnl:
3839 rtnl_unlock();
3840 return err;
3841}
3842
3843static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3844{
79c97e97 3845 struct cfg80211_registered_device *rdev;
636a5d36 3846 struct net_device *dev;
19957bb3
JB
3847 const u8 *ie = NULL, *bssid;
3848 int err, ie_len = 0;
3849 u16 reason_code;
d5cdfacb 3850 bool local_state_change;
636a5d36 3851
f4a11bb0
JB
3852 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3853 return -EINVAL;
3854
3855 if (!info->attrs[NL80211_ATTR_MAC])
3856 return -EINVAL;
3857
3858 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3859 return -EINVAL;
3860
636a5d36
JM
3861 rtnl_lock();
3862
463d0183 3863 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3864 if (err)
3865 goto unlock_rtnl;
3866
79c97e97 3867 if (!rdev->ops->deauth) {
636a5d36
JM
3868 err = -EOPNOTSUPP;
3869 goto out;
3870 }
3871
eec60b03
JM
3872 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3873 err = -EOPNOTSUPP;
3874 goto out;
3875 }
3876
35a8efe1
JM
3877 if (!netif_running(dev)) {
3878 err = -ENETDOWN;
3879 goto out;
3880 }
3881
19957bb3 3882 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3883
19957bb3
JB
3884 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3885 if (reason_code == 0) {
f4a11bb0
JB
3886 /* Reason Code 0 is reserved */
3887 err = -EINVAL;
3888 goto out;
255e737e 3889 }
636a5d36
JM
3890
3891 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3892 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3893 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3894 }
3895
d5cdfacb
JM
3896 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3897
3898 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3899 local_state_change);
636a5d36
JM
3900
3901out:
79c97e97 3902 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3903 dev_put(dev);
3904unlock_rtnl:
3905 rtnl_unlock();
3906 return err;
3907}
3908
3909static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3910{
79c97e97 3911 struct cfg80211_registered_device *rdev;
636a5d36 3912 struct net_device *dev;
19957bb3
JB
3913 const u8 *ie = NULL, *bssid;
3914 int err, ie_len = 0;
3915 u16 reason_code;
d5cdfacb 3916 bool local_state_change;
636a5d36 3917
f4a11bb0
JB
3918 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3919 return -EINVAL;
3920
3921 if (!info->attrs[NL80211_ATTR_MAC])
3922 return -EINVAL;
3923
3924 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3925 return -EINVAL;
3926
636a5d36
JM
3927 rtnl_lock();
3928
463d0183 3929 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3930 if (err)
3931 goto unlock_rtnl;
3932
79c97e97 3933 if (!rdev->ops->disassoc) {
636a5d36
JM
3934 err = -EOPNOTSUPP;
3935 goto out;
3936 }
3937
eec60b03
JM
3938 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3939 err = -EOPNOTSUPP;
3940 goto out;
3941 }
3942
35a8efe1
JM
3943 if (!netif_running(dev)) {
3944 err = -ENETDOWN;
3945 goto out;
3946 }
3947
19957bb3 3948 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3949
19957bb3
JB
3950 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3951 if (reason_code == 0) {
f4a11bb0
JB
3952 /* Reason Code 0 is reserved */
3953 err = -EINVAL;
3954 goto out;
255e737e 3955 }
636a5d36
JM
3956
3957 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3958 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3959 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3960 }
3961
d5cdfacb
JM
3962 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3963
3964 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3965 local_state_change);
636a5d36
JM
3966
3967out:
79c97e97 3968 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3969 dev_put(dev);
3970unlock_rtnl:
3971 rtnl_unlock();
3972 return err;
3973}
3974
04a773ad
JB
3975static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3976{
79c97e97 3977 struct cfg80211_registered_device *rdev;
04a773ad
JB
3978 struct net_device *dev;
3979 struct cfg80211_ibss_params ibss;
3980 struct wiphy *wiphy;
fffd0934 3981 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3982 int err;
3983
8e30bc55
JB
3984 memset(&ibss, 0, sizeof(ibss));
3985
04a773ad
JB
3986 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3987 return -EINVAL;
3988
3989 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3990 !info->attrs[NL80211_ATTR_SSID] ||
3991 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3992 return -EINVAL;
3993
8e30bc55
JB
3994 ibss.beacon_interval = 100;
3995
3996 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3997 ibss.beacon_interval =
3998 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3999 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4000 return -EINVAL;
4001 }
4002
04a773ad
JB
4003 rtnl_lock();
4004
463d0183 4005 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
4006 if (err)
4007 goto unlock_rtnl;
4008
79c97e97 4009 if (!rdev->ops->join_ibss) {
04a773ad
JB
4010 err = -EOPNOTSUPP;
4011 goto out;
4012 }
4013
4014 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4015 err = -EOPNOTSUPP;
4016 goto out;
4017 }
4018
4019 if (!netif_running(dev)) {
4020 err = -ENETDOWN;
4021 goto out;
4022 }
4023
79c97e97 4024 wiphy = &rdev->wiphy;
04a773ad
JB
4025
4026 if (info->attrs[NL80211_ATTR_MAC])
4027 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4028 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4029 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4030
4031 if (info->attrs[NL80211_ATTR_IE]) {
4032 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4033 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4034 }
4035
4036 ibss.channel = ieee80211_get_channel(wiphy,
4037 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4038 if (!ibss.channel ||
4039 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4040 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
4041 err = -EINVAL;
4042 goto out;
4043 }
4044
4045 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4046 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4047
4048 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4049 connkeys = nl80211_parse_connkeys(rdev,
4050 info->attrs[NL80211_ATTR_KEYS]);
4051 if (IS_ERR(connkeys)) {
4052 err = PTR_ERR(connkeys);
4053 connkeys = NULL;
4054 goto out;
4055 }
4056 }
04a773ad 4057
fbd2c8dc
TP
4058 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4059 u8 *rates =
4060 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4061 int n_rates =
4062 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4063 struct ieee80211_supported_band *sband =
4064 wiphy->bands[ibss.channel->band];
4065 int i, j;
4066
4067 if (n_rates == 0) {
4068 err = -EINVAL;
4069 goto out;
4070 }
4071
4072 for (i = 0; i < n_rates; i++) {
4073 int rate = (rates[i] & 0x7f) * 5;
4074 bool found = false;
4075
4076 for (j = 0; j < sband->n_bitrates; j++) {
4077 if (sband->bitrates[j].bitrate == rate) {
4078 found = true;
4079 ibss.basic_rates |= BIT(j);
4080 break;
4081 }
4082 }
4083 if (!found) {
4084 err = -EINVAL;
4085 goto out;
4086 }
4087 }
4088 } else {
4089 /*
4090 * If no rates were explicitly configured,
4091 * use the mandatory rate set for 11b or
4092 * 11a for maximum compatibility.
4093 */
4094 struct ieee80211_supported_band *sband =
4095 wiphy->bands[ibss.channel->band];
4096 int j;
4097 u32 flag = ibss.channel->band == IEEE80211_BAND_5GHZ ?
4098 IEEE80211_RATE_MANDATORY_A :
4099 IEEE80211_RATE_MANDATORY_B;
4100
4101 for (j = 0; j < sband->n_bitrates; j++) {
4102 if (sband->bitrates[j].flags & flag)
4103 ibss.basic_rates |= BIT(j);
4104 }
4105 }
4106
fffd0934 4107 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
4108
4109out:
79c97e97 4110 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4111 dev_put(dev);
4112unlock_rtnl:
fffd0934
JB
4113 if (err)
4114 kfree(connkeys);
04a773ad
JB
4115 rtnl_unlock();
4116 return err;
4117}
4118
4119static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4120{
79c97e97 4121 struct cfg80211_registered_device *rdev;
04a773ad
JB
4122 struct net_device *dev;
4123 int err;
4124
4125 rtnl_lock();
4126
463d0183 4127 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
4128 if (err)
4129 goto unlock_rtnl;
4130
79c97e97 4131 if (!rdev->ops->leave_ibss) {
04a773ad
JB
4132 err = -EOPNOTSUPP;
4133 goto out;
4134 }
4135
4136 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4137 err = -EOPNOTSUPP;
4138 goto out;
4139 }
4140
4141 if (!netif_running(dev)) {
4142 err = -ENETDOWN;
4143 goto out;
4144 }
4145
79c97e97 4146 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4147
4148out:
79c97e97 4149 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4150 dev_put(dev);
4151unlock_rtnl:
4152 rtnl_unlock();
4153 return err;
4154}
4155
aff89a9b
JB
4156#ifdef CONFIG_NL80211_TESTMODE
4157static struct genl_multicast_group nl80211_testmode_mcgrp = {
4158 .name = "testmode",
4159};
4160
4161static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4162{
4163 struct cfg80211_registered_device *rdev;
4164 int err;
4165
4166 if (!info->attrs[NL80211_ATTR_TESTDATA])
4167 return -EINVAL;
4168
4169 rtnl_lock();
4170
4171 rdev = cfg80211_get_dev_from_info(info);
4172 if (IS_ERR(rdev)) {
4173 err = PTR_ERR(rdev);
4174 goto unlock_rtnl;
4175 }
4176
4177 err = -EOPNOTSUPP;
4178 if (rdev->ops->testmode_cmd) {
4179 rdev->testmode_info = info;
4180 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4181 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4182 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4183 rdev->testmode_info = NULL;
4184 }
4185
4d0c8aea 4186 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
4187
4188 unlock_rtnl:
4189 rtnl_unlock();
4190 return err;
4191}
4192
4193static struct sk_buff *
4194__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4195 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4196{
4197 struct sk_buff *skb;
4198 void *hdr;
4199 struct nlattr *data;
4200
4201 skb = nlmsg_new(approxlen + 100, gfp);
4202 if (!skb)
4203 return NULL;
4204
4205 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4206 if (!hdr) {
4207 kfree_skb(skb);
4208 return NULL;
4209 }
4210
4211 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4212 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4213
4214 ((void **)skb->cb)[0] = rdev;
4215 ((void **)skb->cb)[1] = hdr;
4216 ((void **)skb->cb)[2] = data;
4217
4218 return skb;
4219
4220 nla_put_failure:
4221 kfree_skb(skb);
4222 return NULL;
4223}
4224
4225struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4226 int approxlen)
4227{
4228 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4229
4230 if (WARN_ON(!rdev->testmode_info))
4231 return NULL;
4232
4233 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4234 rdev->testmode_info->snd_pid,
4235 rdev->testmode_info->snd_seq,
4236 GFP_KERNEL);
4237}
4238EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4239
4240int cfg80211_testmode_reply(struct sk_buff *skb)
4241{
4242 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4243 void *hdr = ((void **)skb->cb)[1];
4244 struct nlattr *data = ((void **)skb->cb)[2];
4245
4246 if (WARN_ON(!rdev->testmode_info)) {
4247 kfree_skb(skb);
4248 return -EINVAL;
4249 }
4250
4251 nla_nest_end(skb, data);
4252 genlmsg_end(skb, hdr);
4253 return genlmsg_reply(skb, rdev->testmode_info);
4254}
4255EXPORT_SYMBOL(cfg80211_testmode_reply);
4256
4257struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4258 int approxlen, gfp_t gfp)
4259{
4260 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4261
4262 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4263}
4264EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4265
4266void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4267{
4268 void *hdr = ((void **)skb->cb)[1];
4269 struct nlattr *data = ((void **)skb->cb)[2];
4270
4271 nla_nest_end(skb, data);
4272 genlmsg_end(skb, hdr);
4273 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4274}
4275EXPORT_SYMBOL(cfg80211_testmode_event);
4276#endif
4277
b23aa676
SO
4278static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4279{
79c97e97 4280 struct cfg80211_registered_device *rdev;
b23aa676
SO
4281 struct net_device *dev;
4282 struct cfg80211_connect_params connect;
4283 struct wiphy *wiphy;
fffd0934 4284 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4285 int err;
4286
4287 memset(&connect, 0, sizeof(connect));
4288
4289 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4290 return -EINVAL;
4291
4292 if (!info->attrs[NL80211_ATTR_SSID] ||
4293 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4294 return -EINVAL;
4295
4296 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4297 connect.auth_type =
4298 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4299 if (!nl80211_valid_auth_type(connect.auth_type))
4300 return -EINVAL;
4301 } else
4302 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4303
4304 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4305
3dc27d25
JB
4306 err = nl80211_crypto_settings(info, &connect.crypto,
4307 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4308 if (err)
4309 return err;
4310 rtnl_lock();
4311
463d0183 4312 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4313 if (err)
4314 goto unlock_rtnl;
4315
4316 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4317 err = -EOPNOTSUPP;
4318 goto out;
4319 }
4320
4321 if (!netif_running(dev)) {
4322 err = -ENETDOWN;
4323 goto out;
4324 }
4325
79c97e97 4326 wiphy = &rdev->wiphy;
b23aa676 4327
b23aa676
SO
4328 if (info->attrs[NL80211_ATTR_MAC])
4329 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4330 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4331 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4332
4333 if (info->attrs[NL80211_ATTR_IE]) {
4334 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4335 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4336 }
4337
4338 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4339 connect.channel =
4340 ieee80211_get_channel(wiphy,
4341 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4342 if (!connect.channel ||
4343 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4344 err = -EINVAL;
4345 goto out;
4346 }
4347 }
4348
fffd0934
JB
4349 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4350 connkeys = nl80211_parse_connkeys(rdev,
4351 info->attrs[NL80211_ATTR_KEYS]);
4352 if (IS_ERR(connkeys)) {
4353 err = PTR_ERR(connkeys);
4354 connkeys = NULL;
4355 goto out;
4356 }
4357 }
4358
4359 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
4360
4361out:
79c97e97 4362 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4363 dev_put(dev);
4364unlock_rtnl:
fffd0934
JB
4365 if (err)
4366 kfree(connkeys);
b23aa676
SO
4367 rtnl_unlock();
4368 return err;
4369}
4370
4371static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4372{
79c97e97 4373 struct cfg80211_registered_device *rdev;
b23aa676
SO
4374 struct net_device *dev;
4375 int err;
4376 u16 reason;
4377
4378 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4379 reason = WLAN_REASON_DEAUTH_LEAVING;
4380 else
4381 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4382
4383 if (reason == 0)
4384 return -EINVAL;
4385
4386 rtnl_lock();
4387
463d0183 4388 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4389 if (err)
4390 goto unlock_rtnl;
4391
4392 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4393 err = -EOPNOTSUPP;
4394 goto out;
4395 }
4396
4397 if (!netif_running(dev)) {
4398 err = -ENETDOWN;
4399 goto out;
4400 }
4401
79c97e97 4402 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4403
4404out:
79c97e97 4405 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4406 dev_put(dev);
4407unlock_rtnl:
4408 rtnl_unlock();
4409 return err;
4410}
4411
463d0183
JB
4412static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4413{
4414 struct cfg80211_registered_device *rdev;
4415 struct net *net;
4416 int err;
4417 u32 pid;
4418
4419 if (!info->attrs[NL80211_ATTR_PID])
4420 return -EINVAL;
4421
4422 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4423
4424 rtnl_lock();
4425
4426 rdev = cfg80211_get_dev_from_info(info);
4427 if (IS_ERR(rdev)) {
4428 err = PTR_ERR(rdev);
8a8e05e5 4429 goto out_rtnl;
463d0183
JB
4430 }
4431
4432 net = get_net_ns_by_pid(pid);
4433 if (IS_ERR(net)) {
4434 err = PTR_ERR(net);
4435 goto out;
4436 }
4437
4438 err = 0;
4439
4440 /* check if anything to do */
4441 if (net_eq(wiphy_net(&rdev->wiphy), net))
4442 goto out_put_net;
4443
4444 err = cfg80211_switch_netns(rdev, net);
4445 out_put_net:
4446 put_net(net);
4447 out:
4448 cfg80211_unlock_rdev(rdev);
8a8e05e5 4449 out_rtnl:
463d0183
JB
4450 rtnl_unlock();
4451 return err;
4452}
4453
67fbb16b
SO
4454static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4455{
4456 struct cfg80211_registered_device *rdev;
4457 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4458 struct cfg80211_pmksa *pmksa) = NULL;
4459 int err;
4460 struct net_device *dev;
4461 struct cfg80211_pmksa pmksa;
4462
4463 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4464
4465 if (!info->attrs[NL80211_ATTR_MAC])
4466 return -EINVAL;
4467
4468 if (!info->attrs[NL80211_ATTR_PMKID])
4469 return -EINVAL;
4470
4471 rtnl_lock();
4472
4473 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4474 if (err)
4475 goto out_rtnl;
4476
4477 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4478 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4479
4480 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4481 err = -EOPNOTSUPP;
4482 goto out;
4483 }
4484
4485 switch (info->genlhdr->cmd) {
4486 case NL80211_CMD_SET_PMKSA:
4487 rdev_ops = rdev->ops->set_pmksa;
4488 break;
4489 case NL80211_CMD_DEL_PMKSA:
4490 rdev_ops = rdev->ops->del_pmksa;
4491 break;
4492 default:
4493 WARN_ON(1);
4494 break;
4495 }
4496
4497 if (!rdev_ops) {
4498 err = -EOPNOTSUPP;
4499 goto out;
4500 }
4501
4502 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4503
4504 out:
4505 cfg80211_unlock_rdev(rdev);
4506 dev_put(dev);
4507 out_rtnl:
4508 rtnl_unlock();
4509
4510 return err;
4511}
4512
4513static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4514{
4515 struct cfg80211_registered_device *rdev;
4516 int err;
4517 struct net_device *dev;
4518
4519 rtnl_lock();
4520
4521 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4522 if (err)
4523 goto out_rtnl;
4524
4525 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4526 err = -EOPNOTSUPP;
4527 goto out;
4528 }
4529
4530 if (!rdev->ops->flush_pmksa) {
4531 err = -EOPNOTSUPP;
4532 goto out;
4533 }
4534
4535 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4536
4537 out:
4538 cfg80211_unlock_rdev(rdev);
4539 dev_put(dev);
4540 out_rtnl:
4541 rtnl_unlock();
4542
4543 return err;
4544
4545}
4546
9588bbd5
JM
4547static int nl80211_remain_on_channel(struct sk_buff *skb,
4548 struct genl_info *info)
4549{
4550 struct cfg80211_registered_device *rdev;
4551 struct net_device *dev;
4552 struct ieee80211_channel *chan;
4553 struct sk_buff *msg;
4554 void *hdr;
4555 u64 cookie;
4556 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4557 u32 freq, duration;
4558 int err;
4559
4560 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4561 !info->attrs[NL80211_ATTR_DURATION])
4562 return -EINVAL;
4563
4564 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4565
4566 /*
4567 * We should be on that channel for at least one jiffie,
4568 * and more than 5 seconds seems excessive.
4569 */
4570 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4571 return -EINVAL;
4572
4573 rtnl_lock();
4574
4575 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4576 if (err)
4577 goto unlock_rtnl;
4578
4579 if (!rdev->ops->remain_on_channel) {
4580 err = -EOPNOTSUPP;
4581 goto out;
4582 }
4583
4584 if (!netif_running(dev)) {
4585 err = -ENETDOWN;
4586 goto out;
4587 }
4588
4589 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4590 channel_type = nla_get_u32(
4591 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4592 if (channel_type != NL80211_CHAN_NO_HT &&
4593 channel_type != NL80211_CHAN_HT20 &&
4594 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4595 channel_type != NL80211_CHAN_HT40MINUS) {
9588bbd5
JM
4596 err = -EINVAL;
4597 goto out;
579d7534 4598 }
9588bbd5
JM
4599 }
4600
4601 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4602 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4603 if (chan == NULL) {
4604 err = -EINVAL;
4605 goto out;
4606 }
4607
4608 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4609 if (!msg) {
4610 err = -ENOMEM;
4611 goto out;
4612 }
4613
4614 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4615 NL80211_CMD_REMAIN_ON_CHANNEL);
4616
4617 if (IS_ERR(hdr)) {
4618 err = PTR_ERR(hdr);
4619 goto free_msg;
4620 }
4621
4622 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4623 channel_type, duration, &cookie);
4624
4625 if (err)
4626 goto free_msg;
4627
4628 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4629
4630 genlmsg_end(msg, hdr);
4631 err = genlmsg_reply(msg, info);
4632 goto out;
4633
4634 nla_put_failure:
4635 err = -ENOBUFS;
4636 free_msg:
4637 nlmsg_free(msg);
4638 out:
4639 cfg80211_unlock_rdev(rdev);
4640 dev_put(dev);
4641 unlock_rtnl:
4642 rtnl_unlock();
4643 return err;
4644}
4645
4646static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4647 struct genl_info *info)
4648{
4649 struct cfg80211_registered_device *rdev;
4650 struct net_device *dev;
4651 u64 cookie;
4652 int err;
4653
4654 if (!info->attrs[NL80211_ATTR_COOKIE])
4655 return -EINVAL;
4656
4657 rtnl_lock();
4658
4659 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4660 if (err)
4661 goto unlock_rtnl;
4662
4663 if (!rdev->ops->cancel_remain_on_channel) {
4664 err = -EOPNOTSUPP;
4665 goto out;
4666 }
4667
4668 if (!netif_running(dev)) {
4669 err = -ENETDOWN;
4670 goto out;
4671 }
4672
4673 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4674
4675 err = rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4676
4677 out:
4678 cfg80211_unlock_rdev(rdev);
4679 dev_put(dev);
4680 unlock_rtnl:
4681 rtnl_unlock();
4682 return err;
4683}
4684
13ae75b1
JM
4685static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4686 u8 *rates, u8 rates_len)
4687{
4688 u8 i;
4689 u32 mask = 0;
4690
4691 for (i = 0; i < rates_len; i++) {
4692 int rate = (rates[i] & 0x7f) * 5;
4693 int ridx;
4694 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4695 struct ieee80211_rate *srate =
4696 &sband->bitrates[ridx];
4697 if (rate == srate->bitrate) {
4698 mask |= 1 << ridx;
4699 break;
4700 }
4701 }
4702 if (ridx == sband->n_bitrates)
4703 return 0; /* rate not found */
4704 }
4705
4706 return mask;
4707}
4708
b54452b0 4709static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4710 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4711 .len = NL80211_MAX_SUPP_RATES },
4712};
4713
4714static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4715 struct genl_info *info)
4716{
4717 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4718 struct cfg80211_registered_device *rdev;
4719 struct cfg80211_bitrate_mask mask;
4720 int err, rem, i;
4721 struct net_device *dev;
4722 struct nlattr *tx_rates;
4723 struct ieee80211_supported_band *sband;
4724
4725 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4726 return -EINVAL;
4727
4728 rtnl_lock();
4729
4730 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4731 if (err)
4732 goto unlock_rtnl;
4733
4734 if (!rdev->ops->set_bitrate_mask) {
4735 err = -EOPNOTSUPP;
4736 goto unlock;
4737 }
4738
4739 memset(&mask, 0, sizeof(mask));
4740 /* Default to all rates enabled */
4741 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4742 sband = rdev->wiphy.bands[i];
4743 mask.control[i].legacy =
4744 sband ? (1 << sband->n_bitrates) - 1 : 0;
4745 }
4746
4747 /*
4748 * The nested attribute uses enum nl80211_band as the index. This maps
4749 * directly to the enum ieee80211_band values used in cfg80211.
4750 */
4751 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4752 {
4753 enum ieee80211_band band = nla_type(tx_rates);
4754 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
4755 err = -EINVAL;
4756 goto unlock;
4757 }
4758 sband = rdev->wiphy.bands[band];
4759 if (sband == NULL) {
4760 err = -EINVAL;
4761 goto unlock;
4762 }
4763 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4764 nla_len(tx_rates), nl80211_txattr_policy);
4765 if (tb[NL80211_TXRATE_LEGACY]) {
4766 mask.control[band].legacy = rateset_to_mask(
4767 sband,
4768 nla_data(tb[NL80211_TXRATE_LEGACY]),
4769 nla_len(tb[NL80211_TXRATE_LEGACY]));
4770 if (mask.control[band].legacy == 0) {
4771 err = -EINVAL;
4772 goto unlock;
4773 }
4774 }
4775 }
4776
4777 err = rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4778
4779 unlock:
4780 dev_put(dev);
4781 cfg80211_unlock_rdev(rdev);
4782 unlock_rtnl:
4783 rtnl_unlock();
4784 return err;
4785}
4786
2e161f78 4787static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4
JM
4788{
4789 struct cfg80211_registered_device *rdev;
4790 struct net_device *dev;
2e161f78 4791 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4792 int err;
4793
4794 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4795 return -EINVAL;
4796
2e161f78
JB
4797 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4798 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4
JM
4799
4800 rtnl_lock();
4801
4802 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4803 if (err)
4804 goto unlock_rtnl;
4805
9d38d85d
JB
4806 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4807 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
026331c4
JM
4808 err = -EOPNOTSUPP;
4809 goto out;
4810 }
4811
4812 /* not much point in registering if we can't reply */
2e161f78 4813 if (!rdev->ops->mgmt_tx) {
026331c4
JM
4814 err = -EOPNOTSUPP;
4815 goto out;
4816 }
4817
2e161f78
JB
4818 err = cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
4819 frame_type,
026331c4
JM
4820 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4821 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4822 out:
4823 cfg80211_unlock_rdev(rdev);
4824 dev_put(dev);
4825 unlock_rtnl:
4826 rtnl_unlock();
4827 return err;
4828}
4829
2e161f78 4830static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4
JM
4831{
4832 struct cfg80211_registered_device *rdev;
4833 struct net_device *dev;
4834 struct ieee80211_channel *chan;
4835 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4836 bool channel_type_valid = false;
026331c4
JM
4837 u32 freq;
4838 int err;
4839 void *hdr;
4840 u64 cookie;
4841 struct sk_buff *msg;
4842
4843 if (!info->attrs[NL80211_ATTR_FRAME] ||
4844 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4845 return -EINVAL;
4846
4847 rtnl_lock();
4848
4849 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4850 if (err)
4851 goto unlock_rtnl;
4852
2e161f78 4853 if (!rdev->ops->mgmt_tx) {
026331c4
JM
4854 err = -EOPNOTSUPP;
4855 goto out;
4856 }
4857
9d38d85d
JB
4858 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4859 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
026331c4
JM
4860 err = -EOPNOTSUPP;
4861 goto out;
4862 }
4863
4864 if (!netif_running(dev)) {
4865 err = -ENETDOWN;
4866 goto out;
4867 }
4868
4869 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4870 channel_type = nla_get_u32(
4871 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4872 if (channel_type != NL80211_CHAN_NO_HT &&
4873 channel_type != NL80211_CHAN_HT20 &&
4874 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4875 channel_type != NL80211_CHAN_HT40MINUS) {
026331c4
JM
4876 err = -EINVAL;
4877 goto out;
579d7534 4878 }
252aa631 4879 channel_type_valid = true;
026331c4
JM
4880 }
4881
4882 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4883 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4884 if (chan == NULL) {
4885 err = -EINVAL;
4886 goto out;
4887 }
4888
4889 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4890 if (!msg) {
4891 err = -ENOMEM;
4892 goto out;
4893 }
4894
4895 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4896 NL80211_CMD_FRAME);
026331c4
JM
4897
4898 if (IS_ERR(hdr)) {
4899 err = PTR_ERR(hdr);
4900 goto free_msg;
4901 }
2e161f78
JB
4902 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, channel_type,
4903 channel_type_valid,
4904 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4905 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4906 &cookie);
026331c4
JM
4907 if (err)
4908 goto free_msg;
4909
4910 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4911
4912 genlmsg_end(msg, hdr);
4913 err = genlmsg_reply(msg, info);
4914 goto out;
4915
4916 nla_put_failure:
4917 err = -ENOBUFS;
4918 free_msg:
4919 nlmsg_free(msg);
4920 out:
4921 cfg80211_unlock_rdev(rdev);
4922 dev_put(dev);
4923unlock_rtnl:
4924 rtnl_unlock();
4925 return err;
4926}
4927
ffb9eb3d
KV
4928static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4929{
4930 struct cfg80211_registered_device *rdev;
4931 struct wireless_dev *wdev;
4932 struct net_device *dev;
4933 u8 ps_state;
4934 bool state;
4935 int err;
4936
4937 if (!info->attrs[NL80211_ATTR_PS_STATE]) {
4938 err = -EINVAL;
4939 goto out;
4940 }
4941
4942 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4943
4944 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) {
4945 err = -EINVAL;
4946 goto out;
4947 }
4948
4949 rtnl_lock();
4950
4951 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4952 if (err)
4953 goto unlock_rdev;
4954
4955 wdev = dev->ieee80211_ptr;
4956
4957 if (!rdev->ops->set_power_mgmt) {
4958 err = -EOPNOTSUPP;
4959 goto unlock_rdev;
4960 }
4961
4962 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4963
4964 if (state == wdev->ps)
4965 goto unlock_rdev;
4966
4967 wdev->ps = state;
4968
4969 if (rdev->ops->set_power_mgmt(wdev->wiphy, dev, wdev->ps,
4970 wdev->ps_timeout))
4971 /* assume this means it's off */
4972 wdev->ps = false;
4973
4974unlock_rdev:
4975 cfg80211_unlock_rdev(rdev);
4976 dev_put(dev);
4977 rtnl_unlock();
4978
4979out:
4980 return err;
4981}
4982
4983static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4984{
4985 struct cfg80211_registered_device *rdev;
4986 enum nl80211_ps_state ps_state;
4987 struct wireless_dev *wdev;
4988 struct net_device *dev;
4989 struct sk_buff *msg;
4990 void *hdr;
4991 int err;
4992
4993 rtnl_lock();
4994
4995 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4996 if (err)
4997 goto unlock_rtnl;
4998
4999 wdev = dev->ieee80211_ptr;
5000
5001 if (!rdev->ops->set_power_mgmt) {
5002 err = -EOPNOTSUPP;
5003 goto out;
5004 }
5005
5006 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5007 if (!msg) {
5008 err = -ENOMEM;
5009 goto out;
5010 }
5011
5012 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5013 NL80211_CMD_GET_POWER_SAVE);
5014 if (!hdr) {
5015 err = -ENOMEM;
5016 goto free_msg;
5017 }
5018
5019 if (wdev->ps)
5020 ps_state = NL80211_PS_ENABLED;
5021 else
5022 ps_state = NL80211_PS_DISABLED;
5023
5024 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5025
5026 genlmsg_end(msg, hdr);
5027 err = genlmsg_reply(msg, info);
5028 goto out;
5029
5030nla_put_failure:
5031 err = -ENOBUFS;
5032
5033free_msg:
5034 nlmsg_free(msg);
5035
5036out:
5037 cfg80211_unlock_rdev(rdev);
5038 dev_put(dev);
5039
5040unlock_rtnl:
5041 rtnl_unlock();
5042
5043 return err;
5044}
5045
d6dc1a38
JO
5046static struct nla_policy
5047nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5048 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5049 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5050 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5051};
5052
5053static int nl80211_set_cqm_rssi(struct genl_info *info,
5054 s32 threshold, u32 hysteresis)
5055{
5056 struct cfg80211_registered_device *rdev;
5057 struct wireless_dev *wdev;
5058 struct net_device *dev;
5059 int err;
5060
5061 if (threshold > 0)
5062 return -EINVAL;
5063
5064 rtnl_lock();
5065
5066 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5067 if (err)
5068 goto unlock_rdev;
5069
5070 wdev = dev->ieee80211_ptr;
5071
5072 if (!rdev->ops->set_cqm_rssi_config) {
5073 err = -EOPNOTSUPP;
5074 goto unlock_rdev;
5075 }
5076
5077 if (wdev->iftype != NL80211_IFTYPE_STATION) {
5078 err = -EOPNOTSUPP;
5079 goto unlock_rdev;
5080 }
5081
5082 err = rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5083 threshold, hysteresis);
5084
5085unlock_rdev:
5086 cfg80211_unlock_rdev(rdev);
5087 dev_put(dev);
5088 rtnl_unlock();
5089
5090 return err;
5091}
5092
5093static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5094{
5095 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5096 struct nlattr *cqm;
5097 int err;
5098
5099 cqm = info->attrs[NL80211_ATTR_CQM];
5100 if (!cqm) {
5101 err = -EINVAL;
5102 goto out;
5103 }
5104
5105 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5106 nl80211_attr_cqm_policy);
5107 if (err)
5108 goto out;
5109
5110 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5111 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5112 s32 threshold;
5113 u32 hysteresis;
5114 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5115 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5116 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5117 } else
5118 err = -EINVAL;
5119
5120out:
5121 return err;
5122}
5123
55682965
JB
5124static struct genl_ops nl80211_ops[] = {
5125 {
5126 .cmd = NL80211_CMD_GET_WIPHY,
5127 .doit = nl80211_get_wiphy,
5128 .dumpit = nl80211_dump_wiphy,
5129 .policy = nl80211_policy,
5130 /* can be retrieved by unprivileged users */
5131 },
5132 {
5133 .cmd = NL80211_CMD_SET_WIPHY,
5134 .doit = nl80211_set_wiphy,
5135 .policy = nl80211_policy,
5136 .flags = GENL_ADMIN_PERM,
5137 },
5138 {
5139 .cmd = NL80211_CMD_GET_INTERFACE,
5140 .doit = nl80211_get_interface,
5141 .dumpit = nl80211_dump_interface,
5142 .policy = nl80211_policy,
5143 /* can be retrieved by unprivileged users */
5144 },
5145 {
5146 .cmd = NL80211_CMD_SET_INTERFACE,
5147 .doit = nl80211_set_interface,
5148 .policy = nl80211_policy,
5149 .flags = GENL_ADMIN_PERM,
5150 },
5151 {
5152 .cmd = NL80211_CMD_NEW_INTERFACE,
5153 .doit = nl80211_new_interface,
5154 .policy = nl80211_policy,
5155 .flags = GENL_ADMIN_PERM,
5156 },
5157 {
5158 .cmd = NL80211_CMD_DEL_INTERFACE,
5159 .doit = nl80211_del_interface,
5160 .policy = nl80211_policy,
41ade00f
JB
5161 .flags = GENL_ADMIN_PERM,
5162 },
5163 {
5164 .cmd = NL80211_CMD_GET_KEY,
5165 .doit = nl80211_get_key,
5166 .policy = nl80211_policy,
5167 .flags = GENL_ADMIN_PERM,
5168 },
5169 {
5170 .cmd = NL80211_CMD_SET_KEY,
5171 .doit = nl80211_set_key,
5172 .policy = nl80211_policy,
5173 .flags = GENL_ADMIN_PERM,
5174 },
5175 {
5176 .cmd = NL80211_CMD_NEW_KEY,
5177 .doit = nl80211_new_key,
5178 .policy = nl80211_policy,
5179 .flags = GENL_ADMIN_PERM,
5180 },
5181 {
5182 .cmd = NL80211_CMD_DEL_KEY,
5183 .doit = nl80211_del_key,
5184 .policy = nl80211_policy,
55682965
JB
5185 .flags = GENL_ADMIN_PERM,
5186 },
ed1b6cc7
JB
5187 {
5188 .cmd = NL80211_CMD_SET_BEACON,
5189 .policy = nl80211_policy,
5190 .flags = GENL_ADMIN_PERM,
5191 .doit = nl80211_addset_beacon,
5192 },
5193 {
5194 .cmd = NL80211_CMD_NEW_BEACON,
5195 .policy = nl80211_policy,
5196 .flags = GENL_ADMIN_PERM,
5197 .doit = nl80211_addset_beacon,
5198 },
5199 {
5200 .cmd = NL80211_CMD_DEL_BEACON,
5201 .policy = nl80211_policy,
5202 .flags = GENL_ADMIN_PERM,
5203 .doit = nl80211_del_beacon,
5204 },
5727ef1b
JB
5205 {
5206 .cmd = NL80211_CMD_GET_STATION,
5207 .doit = nl80211_get_station,
2ec600d6 5208 .dumpit = nl80211_dump_station,
5727ef1b 5209 .policy = nl80211_policy,
5727ef1b
JB
5210 },
5211 {
5212 .cmd = NL80211_CMD_SET_STATION,
5213 .doit = nl80211_set_station,
5214 .policy = nl80211_policy,
5215 .flags = GENL_ADMIN_PERM,
5216 },
5217 {
5218 .cmd = NL80211_CMD_NEW_STATION,
5219 .doit = nl80211_new_station,
5220 .policy = nl80211_policy,
5221 .flags = GENL_ADMIN_PERM,
5222 },
5223 {
5224 .cmd = NL80211_CMD_DEL_STATION,
5225 .doit = nl80211_del_station,
5226 .policy = nl80211_policy,
2ec600d6
LCC
5227 .flags = GENL_ADMIN_PERM,
5228 },
5229 {
5230 .cmd = NL80211_CMD_GET_MPATH,
5231 .doit = nl80211_get_mpath,
5232 .dumpit = nl80211_dump_mpath,
5233 .policy = nl80211_policy,
5234 .flags = GENL_ADMIN_PERM,
5235 },
5236 {
5237 .cmd = NL80211_CMD_SET_MPATH,
5238 .doit = nl80211_set_mpath,
5239 .policy = nl80211_policy,
5240 .flags = GENL_ADMIN_PERM,
5241 },
5242 {
5243 .cmd = NL80211_CMD_NEW_MPATH,
5244 .doit = nl80211_new_mpath,
5245 .policy = nl80211_policy,
5246 .flags = GENL_ADMIN_PERM,
5247 },
5248 {
5249 .cmd = NL80211_CMD_DEL_MPATH,
5250 .doit = nl80211_del_mpath,
5251 .policy = nl80211_policy,
9f1ba906
JM
5252 .flags = GENL_ADMIN_PERM,
5253 },
5254 {
5255 .cmd = NL80211_CMD_SET_BSS,
5256 .doit = nl80211_set_bss,
5257 .policy = nl80211_policy,
b2e1b302
LR
5258 .flags = GENL_ADMIN_PERM,
5259 },
f130347c
LR
5260 {
5261 .cmd = NL80211_CMD_GET_REG,
5262 .doit = nl80211_get_reg,
5263 .policy = nl80211_policy,
5264 /* can be retrieved by unprivileged users */
5265 },
b2e1b302
LR
5266 {
5267 .cmd = NL80211_CMD_SET_REG,
5268 .doit = nl80211_set_reg,
5269 .policy = nl80211_policy,
5270 .flags = GENL_ADMIN_PERM,
5271 },
5272 {
5273 .cmd = NL80211_CMD_REQ_SET_REG,
5274 .doit = nl80211_req_set_reg,
5275 .policy = nl80211_policy,
93da9cc1 5276 .flags = GENL_ADMIN_PERM,
5277 },
5278 {
5279 .cmd = NL80211_CMD_GET_MESH_PARAMS,
5280 .doit = nl80211_get_mesh_params,
5281 .policy = nl80211_policy,
5282 /* can be retrieved by unprivileged users */
5283 },
5284 {
5285 .cmd = NL80211_CMD_SET_MESH_PARAMS,
5286 .doit = nl80211_set_mesh_params,
5287 .policy = nl80211_policy,
9aed3cc1
JM
5288 .flags = GENL_ADMIN_PERM,
5289 },
2a519311
JB
5290 {
5291 .cmd = NL80211_CMD_TRIGGER_SCAN,
5292 .doit = nl80211_trigger_scan,
5293 .policy = nl80211_policy,
5294 .flags = GENL_ADMIN_PERM,
5295 },
5296 {
5297 .cmd = NL80211_CMD_GET_SCAN,
5298 .policy = nl80211_policy,
5299 .dumpit = nl80211_dump_scan,
5300 },
636a5d36
JM
5301 {
5302 .cmd = NL80211_CMD_AUTHENTICATE,
5303 .doit = nl80211_authenticate,
5304 .policy = nl80211_policy,
5305 .flags = GENL_ADMIN_PERM,
5306 },
5307 {
5308 .cmd = NL80211_CMD_ASSOCIATE,
5309 .doit = nl80211_associate,
5310 .policy = nl80211_policy,
5311 .flags = GENL_ADMIN_PERM,
5312 },
5313 {
5314 .cmd = NL80211_CMD_DEAUTHENTICATE,
5315 .doit = nl80211_deauthenticate,
5316 .policy = nl80211_policy,
5317 .flags = GENL_ADMIN_PERM,
5318 },
5319 {
5320 .cmd = NL80211_CMD_DISASSOCIATE,
5321 .doit = nl80211_disassociate,
5322 .policy = nl80211_policy,
5323 .flags = GENL_ADMIN_PERM,
5324 },
04a773ad
JB
5325 {
5326 .cmd = NL80211_CMD_JOIN_IBSS,
5327 .doit = nl80211_join_ibss,
5328 .policy = nl80211_policy,
5329 .flags = GENL_ADMIN_PERM,
5330 },
5331 {
5332 .cmd = NL80211_CMD_LEAVE_IBSS,
5333 .doit = nl80211_leave_ibss,
5334 .policy = nl80211_policy,
5335 .flags = GENL_ADMIN_PERM,
5336 },
aff89a9b
JB
5337#ifdef CONFIG_NL80211_TESTMODE
5338 {
5339 .cmd = NL80211_CMD_TESTMODE,
5340 .doit = nl80211_testmode_do,
5341 .policy = nl80211_policy,
5342 .flags = GENL_ADMIN_PERM,
5343 },
5344#endif
b23aa676
SO
5345 {
5346 .cmd = NL80211_CMD_CONNECT,
5347 .doit = nl80211_connect,
5348 .policy = nl80211_policy,
5349 .flags = GENL_ADMIN_PERM,
5350 },
5351 {
5352 .cmd = NL80211_CMD_DISCONNECT,
5353 .doit = nl80211_disconnect,
5354 .policy = nl80211_policy,
5355 .flags = GENL_ADMIN_PERM,
5356 },
463d0183
JB
5357 {
5358 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5359 .doit = nl80211_wiphy_netns,
5360 .policy = nl80211_policy,
5361 .flags = GENL_ADMIN_PERM,
5362 },
61fa713c
HS
5363 {
5364 .cmd = NL80211_CMD_GET_SURVEY,
5365 .policy = nl80211_policy,
5366 .dumpit = nl80211_dump_survey,
5367 },
67fbb16b
SO
5368 {
5369 .cmd = NL80211_CMD_SET_PMKSA,
5370 .doit = nl80211_setdel_pmksa,
5371 .policy = nl80211_policy,
5372 .flags = GENL_ADMIN_PERM,
5373 },
5374 {
5375 .cmd = NL80211_CMD_DEL_PMKSA,
5376 .doit = nl80211_setdel_pmksa,
5377 .policy = nl80211_policy,
5378 .flags = GENL_ADMIN_PERM,
5379 },
5380 {
5381 .cmd = NL80211_CMD_FLUSH_PMKSA,
5382 .doit = nl80211_flush_pmksa,
5383 .policy = nl80211_policy,
5384 .flags = GENL_ADMIN_PERM,
5385 },
9588bbd5
JM
5386 {
5387 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5388 .doit = nl80211_remain_on_channel,
5389 .policy = nl80211_policy,
5390 .flags = GENL_ADMIN_PERM,
5391 },
5392 {
5393 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5394 .doit = nl80211_cancel_remain_on_channel,
5395 .policy = nl80211_policy,
5396 .flags = GENL_ADMIN_PERM,
5397 },
13ae75b1
JM
5398 {
5399 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5400 .doit = nl80211_set_tx_bitrate_mask,
5401 .policy = nl80211_policy,
5402 .flags = GENL_ADMIN_PERM,
5403 },
026331c4 5404 {
2e161f78
JB
5405 .cmd = NL80211_CMD_REGISTER_FRAME,
5406 .doit = nl80211_register_mgmt,
026331c4
JM
5407 .policy = nl80211_policy,
5408 .flags = GENL_ADMIN_PERM,
5409 },
5410 {
2e161f78
JB
5411 .cmd = NL80211_CMD_FRAME,
5412 .doit = nl80211_tx_mgmt,
026331c4
JM
5413 .policy = nl80211_policy,
5414 .flags = GENL_ADMIN_PERM,
5415 },
ffb9eb3d
KV
5416 {
5417 .cmd = NL80211_CMD_SET_POWER_SAVE,
5418 .doit = nl80211_set_power_save,
5419 .policy = nl80211_policy,
5420 .flags = GENL_ADMIN_PERM,
5421 },
5422 {
5423 .cmd = NL80211_CMD_GET_POWER_SAVE,
5424 .doit = nl80211_get_power_save,
5425 .policy = nl80211_policy,
5426 /* can be retrieved by unprivileged users */
5427 },
d6dc1a38
JO
5428 {
5429 .cmd = NL80211_CMD_SET_CQM,
5430 .doit = nl80211_set_cqm,
5431 .policy = nl80211_policy,
5432 .flags = GENL_ADMIN_PERM,
5433 },
f444de05
JB
5434 {
5435 .cmd = NL80211_CMD_SET_CHANNEL,
5436 .doit = nl80211_set_channel,
5437 .policy = nl80211_policy,
5438 .flags = GENL_ADMIN_PERM,
5439 },
55682965 5440};
9588bbd5 5441
6039f6d2
JM
5442static struct genl_multicast_group nl80211_mlme_mcgrp = {
5443 .name = "mlme",
5444};
55682965
JB
5445
5446/* multicast groups */
5447static struct genl_multicast_group nl80211_config_mcgrp = {
5448 .name = "config",
5449};
2a519311
JB
5450static struct genl_multicast_group nl80211_scan_mcgrp = {
5451 .name = "scan",
5452};
73d54c9e
LR
5453static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5454 .name = "regulatory",
5455};
55682965
JB
5456
5457/* notification functions */
5458
5459void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5460{
5461 struct sk_buff *msg;
5462
fd2120ca 5463 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5464 if (!msg)
5465 return;
5466
5467 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5468 nlmsg_free(msg);
5469 return;
5470 }
5471
463d0183
JB
5472 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5473 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5474}
5475
362a415d
JB
5476static int nl80211_add_scan_req(struct sk_buff *msg,
5477 struct cfg80211_registered_device *rdev)
5478{
5479 struct cfg80211_scan_request *req = rdev->scan_req;
5480 struct nlattr *nest;
5481 int i;
5482
667503dd
JB
5483 ASSERT_RDEV_LOCK(rdev);
5484
362a415d
JB
5485 if (WARN_ON(!req))
5486 return 0;
5487
5488 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5489 if (!nest)
5490 goto nla_put_failure;
5491 for (i = 0; i < req->n_ssids; i++)
5492 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5493 nla_nest_end(msg, nest);
5494
5495 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5496 if (!nest)
5497 goto nla_put_failure;
5498 for (i = 0; i < req->n_channels; i++)
5499 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5500 nla_nest_end(msg, nest);
5501
5502 if (req->ie)
5503 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5504
5505 return 0;
5506 nla_put_failure:
5507 return -ENOBUFS;
5508}
5509
a538e2d5
JB
5510static int nl80211_send_scan_msg(struct sk_buff *msg,
5511 struct cfg80211_registered_device *rdev,
5512 struct net_device *netdev,
5513 u32 pid, u32 seq, int flags,
5514 u32 cmd)
2a519311
JB
5515{
5516 void *hdr;
5517
5518 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5519 if (!hdr)
5520 return -1;
5521
b5850a7a 5522 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5523 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5524
362a415d
JB
5525 /* ignore errors and send incomplete event anyway */
5526 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5527
5528 return genlmsg_end(msg, hdr);
5529
5530 nla_put_failure:
5531 genlmsg_cancel(msg, hdr);
5532 return -EMSGSIZE;
5533}
5534
a538e2d5
JB
5535void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5536 struct net_device *netdev)
5537{
5538 struct sk_buff *msg;
5539
5540 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5541 if (!msg)
5542 return;
5543
5544 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5545 NL80211_CMD_TRIGGER_SCAN) < 0) {
5546 nlmsg_free(msg);
5547 return;
5548 }
5549
463d0183
JB
5550 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5551 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5552}
5553
2a519311
JB
5554void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5555 struct net_device *netdev)
5556{
5557 struct sk_buff *msg;
5558
fd2120ca 5559 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5560 if (!msg)
5561 return;
5562
a538e2d5
JB
5563 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5564 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5565 nlmsg_free(msg);
5566 return;
5567 }
5568
463d0183
JB
5569 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5570 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5571}
5572
5573void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5574 struct net_device *netdev)
5575{
5576 struct sk_buff *msg;
5577
fd2120ca 5578 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5579 if (!msg)
5580 return;
5581
a538e2d5
JB
5582 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5583 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5584 nlmsg_free(msg);
5585 return;
5586 }
5587
463d0183
JB
5588 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5589 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5590}
5591
73d54c9e
LR
5592/*
5593 * This can happen on global regulatory changes or device specific settings
5594 * based on custom world regulatory domains.
5595 */
5596void nl80211_send_reg_change_event(struct regulatory_request *request)
5597{
5598 struct sk_buff *msg;
5599 void *hdr;
5600
fd2120ca 5601 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5602 if (!msg)
5603 return;
5604
5605 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5606 if (!hdr) {
5607 nlmsg_free(msg);
5608 return;
5609 }
5610
5611 /* Userspace can always count this one always being set */
5612 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5613
5614 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5615 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5616 NL80211_REGDOM_TYPE_WORLD);
5617 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5618 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5619 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5620 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5621 request->intersect)
5622 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5623 NL80211_REGDOM_TYPE_INTERSECTION);
5624 else {
5625 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5626 NL80211_REGDOM_TYPE_COUNTRY);
5627 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5628 }
5629
5630 if (wiphy_idx_valid(request->wiphy_idx))
5631 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5632
5633 if (genlmsg_end(msg, hdr) < 0) {
5634 nlmsg_free(msg);
5635 return;
5636 }
5637
bc43b28c 5638 rcu_read_lock();
463d0183 5639 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5640 GFP_ATOMIC);
5641 rcu_read_unlock();
73d54c9e
LR
5642
5643 return;
5644
5645nla_put_failure:
5646 genlmsg_cancel(msg, hdr);
5647 nlmsg_free(msg);
5648}
5649
6039f6d2
JM
5650static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5651 struct net_device *netdev,
5652 const u8 *buf, size_t len,
e6d6e342 5653 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5654{
5655 struct sk_buff *msg;
5656 void *hdr;
5657
e6d6e342 5658 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5659 if (!msg)
5660 return;
5661
5662 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5663 if (!hdr) {
5664 nlmsg_free(msg);
5665 return;
5666 }
5667
5668 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5669 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5670 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5671
5672 if (genlmsg_end(msg, hdr) < 0) {
5673 nlmsg_free(msg);
5674 return;
5675 }
5676
463d0183
JB
5677 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5678 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5679 return;
5680
5681 nla_put_failure:
5682 genlmsg_cancel(msg, hdr);
5683 nlmsg_free(msg);
5684}
5685
5686void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5687 struct net_device *netdev, const u8 *buf,
5688 size_t len, gfp_t gfp)
6039f6d2
JM
5689{
5690 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5691 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5692}
5693
5694void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5695 struct net_device *netdev, const u8 *buf,
e6d6e342 5696 size_t len, gfp_t gfp)
6039f6d2 5697{
e6d6e342
JB
5698 nl80211_send_mlme_event(rdev, netdev, buf, len,
5699 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5700}
5701
53b46b84 5702void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5703 struct net_device *netdev, const u8 *buf,
5704 size_t len, gfp_t gfp)
6039f6d2
JM
5705{
5706 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5707 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5708}
5709
53b46b84
JM
5710void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5711 struct net_device *netdev, const u8 *buf,
e6d6e342 5712 size_t len, gfp_t gfp)
6039f6d2
JM
5713{
5714 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5715 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5716}
5717
1b06bb40
LR
5718static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5719 struct net_device *netdev, int cmd,
e6d6e342 5720 const u8 *addr, gfp_t gfp)
1965c853
JM
5721{
5722 struct sk_buff *msg;
5723 void *hdr;
5724
e6d6e342 5725 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5726 if (!msg)
5727 return;
5728
5729 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5730 if (!hdr) {
5731 nlmsg_free(msg);
5732 return;
5733 }
5734
5735 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5736 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5737 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5738 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5739
5740 if (genlmsg_end(msg, hdr) < 0) {
5741 nlmsg_free(msg);
5742 return;
5743 }
5744
463d0183
JB
5745 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5746 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5747 return;
5748
5749 nla_put_failure:
5750 genlmsg_cancel(msg, hdr);
5751 nlmsg_free(msg);
5752}
5753
5754void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5755 struct net_device *netdev, const u8 *addr,
5756 gfp_t gfp)
1965c853
JM
5757{
5758 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5759 addr, gfp);
1965c853
JM
5760}
5761
5762void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5763 struct net_device *netdev, const u8 *addr,
5764 gfp_t gfp)
1965c853 5765{
e6d6e342
JB
5766 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5767 addr, gfp);
1965c853
JM
5768}
5769
b23aa676
SO
5770void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5771 struct net_device *netdev, const u8 *bssid,
5772 const u8 *req_ie, size_t req_ie_len,
5773 const u8 *resp_ie, size_t resp_ie_len,
5774 u16 status, gfp_t gfp)
5775{
5776 struct sk_buff *msg;
5777 void *hdr;
5778
5779 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5780 if (!msg)
5781 return;
5782
5783 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5784 if (!hdr) {
5785 nlmsg_free(msg);
5786 return;
5787 }
5788
5789 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5790 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5791 if (bssid)
5792 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5793 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5794 if (req_ie)
5795 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5796 if (resp_ie)
5797 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5798
5799 if (genlmsg_end(msg, hdr) < 0) {
5800 nlmsg_free(msg);
5801 return;
5802 }
5803
463d0183
JB
5804 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5805 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5806 return;
5807
5808 nla_put_failure:
5809 genlmsg_cancel(msg, hdr);
5810 nlmsg_free(msg);
5811
5812}
5813
5814void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5815 struct net_device *netdev, const u8 *bssid,
5816 const u8 *req_ie, size_t req_ie_len,
5817 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5818{
5819 struct sk_buff *msg;
5820 void *hdr;
5821
5822 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5823 if (!msg)
5824 return;
5825
5826 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5827 if (!hdr) {
5828 nlmsg_free(msg);
5829 return;
5830 }
5831
5832 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5833 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5834 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5835 if (req_ie)
5836 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5837 if (resp_ie)
5838 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5839
5840 if (genlmsg_end(msg, hdr) < 0) {
5841 nlmsg_free(msg);
5842 return;
5843 }
5844
463d0183
JB
5845 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5846 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5847 return;
5848
5849 nla_put_failure:
5850 genlmsg_cancel(msg, hdr);
5851 nlmsg_free(msg);
5852
5853}
5854
5855void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5856 struct net_device *netdev, u16 reason,
667503dd 5857 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5858{
5859 struct sk_buff *msg;
5860 void *hdr;
5861
667503dd 5862 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5863 if (!msg)
5864 return;
5865
5866 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5867 if (!hdr) {
5868 nlmsg_free(msg);
5869 return;
5870 }
5871
5872 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5873 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5874 if (from_ap && reason)
5875 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5876 if (from_ap)
5877 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5878 if (ie)
5879 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5880
5881 if (genlmsg_end(msg, hdr) < 0) {
5882 nlmsg_free(msg);
5883 return;
5884 }
5885
463d0183
JB
5886 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5887 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5888 return;
5889
5890 nla_put_failure:
5891 genlmsg_cancel(msg, hdr);
5892 nlmsg_free(msg);
5893
5894}
5895
04a773ad
JB
5896void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5897 struct net_device *netdev, const u8 *bssid,
5898 gfp_t gfp)
5899{
5900 struct sk_buff *msg;
5901 void *hdr;
5902
fd2120ca 5903 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5904 if (!msg)
5905 return;
5906
5907 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5908 if (!hdr) {
5909 nlmsg_free(msg);
5910 return;
5911 }
5912
5913 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5914 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5915 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5916
5917 if (genlmsg_end(msg, hdr) < 0) {
5918 nlmsg_free(msg);
5919 return;
5920 }
5921
463d0183
JB
5922 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5923 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5924 return;
5925
5926 nla_put_failure:
5927 genlmsg_cancel(msg, hdr);
5928 nlmsg_free(msg);
5929}
5930
a3b8b056
JM
5931void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5932 struct net_device *netdev, const u8 *addr,
5933 enum nl80211_key_type key_type, int key_id,
e6d6e342 5934 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5935{
5936 struct sk_buff *msg;
5937 void *hdr;
5938
e6d6e342 5939 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5940 if (!msg)
5941 return;
5942
5943 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5944 if (!hdr) {
5945 nlmsg_free(msg);
5946 return;
5947 }
5948
5949 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5950 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5951 if (addr)
5952 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5953 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5954 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5955 if (tsc)
5956 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5957
5958 if (genlmsg_end(msg, hdr) < 0) {
5959 nlmsg_free(msg);
5960 return;
5961 }
5962
463d0183
JB
5963 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5964 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5965 return;
5966
5967 nla_put_failure:
5968 genlmsg_cancel(msg, hdr);
5969 nlmsg_free(msg);
5970}
5971
6bad8766
LR
5972void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5973 struct ieee80211_channel *channel_before,
5974 struct ieee80211_channel *channel_after)
5975{
5976 struct sk_buff *msg;
5977 void *hdr;
5978 struct nlattr *nl_freq;
5979
fd2120ca 5980 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5981 if (!msg)
5982 return;
5983
5984 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5985 if (!hdr) {
5986 nlmsg_free(msg);
5987 return;
5988 }
5989
5990 /*
5991 * Since we are applying the beacon hint to a wiphy we know its
5992 * wiphy_idx is valid
5993 */
5994 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5995
5996 /* Before */
5997 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5998 if (!nl_freq)
5999 goto nla_put_failure;
6000 if (nl80211_msg_put_channel(msg, channel_before))
6001 goto nla_put_failure;
6002 nla_nest_end(msg, nl_freq);
6003
6004 /* After */
6005 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
6006 if (!nl_freq)
6007 goto nla_put_failure;
6008 if (nl80211_msg_put_channel(msg, channel_after))
6009 goto nla_put_failure;
6010 nla_nest_end(msg, nl_freq);
6011
6012 if (genlmsg_end(msg, hdr) < 0) {
6013 nlmsg_free(msg);
6014 return;
6015 }
6016
463d0183
JB
6017 rcu_read_lock();
6018 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6019 GFP_ATOMIC);
6020 rcu_read_unlock();
6bad8766
LR
6021
6022 return;
6023
6024nla_put_failure:
6025 genlmsg_cancel(msg, hdr);
6026 nlmsg_free(msg);
6027}
6028
9588bbd5
JM
6029static void nl80211_send_remain_on_chan_event(
6030 int cmd, struct cfg80211_registered_device *rdev,
6031 struct net_device *netdev, u64 cookie,
6032 struct ieee80211_channel *chan,
6033 enum nl80211_channel_type channel_type,
6034 unsigned int duration, gfp_t gfp)
6035{
6036 struct sk_buff *msg;
6037 void *hdr;
6038
6039 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6040 if (!msg)
6041 return;
6042
6043 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6044 if (!hdr) {
6045 nlmsg_free(msg);
6046 return;
6047 }
6048
6049 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6050 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6051 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
6052 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
6053 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6054
6055 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6056 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6057
6058 if (genlmsg_end(msg, hdr) < 0) {
6059 nlmsg_free(msg);
6060 return;
6061 }
6062
6063 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6064 nl80211_mlme_mcgrp.id, gfp);
6065 return;
6066
6067 nla_put_failure:
6068 genlmsg_cancel(msg, hdr);
6069 nlmsg_free(msg);
6070}
6071
6072void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6073 struct net_device *netdev, u64 cookie,
6074 struct ieee80211_channel *chan,
6075 enum nl80211_channel_type channel_type,
6076 unsigned int duration, gfp_t gfp)
6077{
6078 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6079 rdev, netdev, cookie, chan,
6080 channel_type, duration, gfp);
6081}
6082
6083void nl80211_send_remain_on_channel_cancel(
6084 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6085 u64 cookie, struct ieee80211_channel *chan,
6086 enum nl80211_channel_type channel_type, gfp_t gfp)
6087{
6088 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6089 rdev, netdev, cookie, chan,
6090 channel_type, 0, gfp);
6091}
6092
98b62183
JB
6093void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6094 struct net_device *dev, const u8 *mac_addr,
6095 struct station_info *sinfo, gfp_t gfp)
6096{
6097 struct sk_buff *msg;
6098
6099 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6100 if (!msg)
6101 return;
6102
6103 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6104 nlmsg_free(msg);
6105 return;
6106 }
6107
6108 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6109 nl80211_mlme_mcgrp.id, gfp);
6110}
6111
2e161f78
JB
6112int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6113 struct net_device *netdev, u32 nlpid,
6114 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
6115{
6116 struct sk_buff *msg;
6117 void *hdr;
6118 int err;
6119
6120 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6121 if (!msg)
6122 return -ENOMEM;
6123
2e161f78 6124 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
6125 if (!hdr) {
6126 nlmsg_free(msg);
6127 return -ENOMEM;
6128 }
6129
6130 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6131 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6132 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6133 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6134
6135 err = genlmsg_end(msg, hdr);
6136 if (err < 0) {
6137 nlmsg_free(msg);
6138 return err;
6139 }
6140
6141 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6142 if (err < 0)
6143 return err;
6144 return 0;
6145
6146 nla_put_failure:
6147 genlmsg_cancel(msg, hdr);
6148 nlmsg_free(msg);
6149 return -ENOBUFS;
6150}
6151
2e161f78
JB
6152void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6153 struct net_device *netdev, u64 cookie,
6154 const u8 *buf, size_t len, bool ack,
6155 gfp_t gfp)
026331c4
JM
6156{
6157 struct sk_buff *msg;
6158 void *hdr;
6159
6160 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6161 if (!msg)
6162 return;
6163
2e161f78 6164 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6165 if (!hdr) {
6166 nlmsg_free(msg);
6167 return;
6168 }
6169
6170 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6171 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6172 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6173 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6174 if (ack)
6175 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6176
6177 if (genlmsg_end(msg, hdr) < 0) {
6178 nlmsg_free(msg);
6179 return;
6180 }
6181
6182 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6183 return;
6184
6185 nla_put_failure:
6186 genlmsg_cancel(msg, hdr);
6187 nlmsg_free(msg);
6188}
6189
d6dc1a38
JO
6190void
6191nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6192 struct net_device *netdev,
6193 enum nl80211_cqm_rssi_threshold_event rssi_event,
6194 gfp_t gfp)
6195{
6196 struct sk_buff *msg;
6197 struct nlattr *pinfoattr;
6198 void *hdr;
6199
6200 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6201 if (!msg)
6202 return;
6203
6204 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6205 if (!hdr) {
6206 nlmsg_free(msg);
6207 return;
6208 }
6209
6210 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6211 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6212
6213 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6214 if (!pinfoattr)
6215 goto nla_put_failure;
6216
6217 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6218 rssi_event);
6219
6220 nla_nest_end(msg, pinfoattr);
6221
6222 if (genlmsg_end(msg, hdr) < 0) {
6223 nlmsg_free(msg);
6224 return;
6225 }
6226
6227 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6228 nl80211_mlme_mcgrp.id, gfp);
6229 return;
6230
6231 nla_put_failure:
6232 genlmsg_cancel(msg, hdr);
6233 nlmsg_free(msg);
6234}
6235
026331c4
JM
6236static int nl80211_netlink_notify(struct notifier_block * nb,
6237 unsigned long state,
6238 void *_notify)
6239{
6240 struct netlink_notify *notify = _notify;
6241 struct cfg80211_registered_device *rdev;
6242 struct wireless_dev *wdev;
6243
6244 if (state != NETLINK_URELEASE)
6245 return NOTIFY_DONE;
6246
6247 rcu_read_lock();
6248
6249 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6250 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6251 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6252
6253 rcu_read_unlock();
6254
6255 return NOTIFY_DONE;
6256}
6257
6258static struct notifier_block nl80211_netlink_notifier = {
6259 .notifier_call = nl80211_netlink_notify,
6260};
6261
55682965
JB
6262/* initialisation/exit functions */
6263
6264int nl80211_init(void)
6265{
0d63cbb5 6266 int err;
55682965 6267
0d63cbb5
MM
6268 err = genl_register_family_with_ops(&nl80211_fam,
6269 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6270 if (err)
6271 return err;
6272
55682965
JB
6273 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6274 if (err)
6275 goto err_out;
6276
2a519311
JB
6277 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6278 if (err)
6279 goto err_out;
6280
73d54c9e
LR
6281 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6282 if (err)
6283 goto err_out;
6284
6039f6d2
JM
6285 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6286 if (err)
6287 goto err_out;
6288
aff89a9b
JB
6289#ifdef CONFIG_NL80211_TESTMODE
6290 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6291 if (err)
6292 goto err_out;
6293#endif
6294
026331c4
JM
6295 err = netlink_register_notifier(&nl80211_netlink_notifier);
6296 if (err)
6297 goto err_out;
6298
55682965
JB
6299 return 0;
6300 err_out:
6301 genl_unregister_family(&nl80211_fam);
6302 return err;
6303}
6304
6305void nl80211_exit(void)
6306{
026331c4 6307 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6308 genl_unregister_family(&nl80211_fam);
6309}