]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
iwlwifi: change WARN_ON to IWL_WARN in iwl_mac_add_interface
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965
JB
25
26/* the netlink family */
27static struct genl_family nl80211_fam = {
28 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
29 .name = "nl80211", /* have users key off the name instead */
30 .hdrsize = 0, /* no private header */
31 .version = 1, /* no particular meaning now */
32 .maxattr = NL80211_ATTR_MAX,
463d0183 33 .netnsok = true,
55682965
JB
34};
35
79c97e97 36/* internal helper: get rdev and dev */
463d0183 37static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 38 struct cfg80211_registered_device **rdev,
55682965
JB
39 struct net_device **dev)
40{
463d0183 41 struct nlattr **attrs = info->attrs;
55682965
JB
42 int ifindex;
43
bba95fef 44 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
45 return -EINVAL;
46
bba95fef 47 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 48 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
49 if (!*dev)
50 return -ENODEV;
51
463d0183 52 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 53 if (IS_ERR(*rdev)) {
55682965 54 dev_put(*dev);
79c97e97 55 return PTR_ERR(*rdev);
55682965
JB
56 }
57
58 return 0;
59}
60
61/* policy for the attributes */
b54452b0 62static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
63 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
64 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 65 .len = 20-1 },
31888487 66 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 67 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 68 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
69 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
71 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
72 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 73 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
74
75 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
76 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
77 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
78
79 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 80 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 81
b9454e83 82 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
83 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
84 .len = WLAN_MAX_KEY_LEN },
85 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
86 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
87 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 88 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
89
90 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
91 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
92 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
95 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
96 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
98 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
99 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
100 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 101 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 102 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 103 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
104 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
105 .len = IEEE80211_MAX_MESH_ID_LEN },
106 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 107
b2e1b302
LR
108 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
109 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
110
9f1ba906
JM
111 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
113 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
114 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
115 .len = NL80211_MAX_SUPP_RATES },
36aedc90 116
93da9cc1 117 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
118
36aedc90
JM
119 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
120 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
121
122 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
123 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
124 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
125 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
126 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
127
128 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
129 .len = IEEE80211_MAX_SSID_LEN },
130 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
131 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 132 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 133 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 134 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
135 [NL80211_ATTR_STA_FLAGS2] = {
136 .len = sizeof(struct nl80211_sta_flag_update),
137 },
3f77316c 138 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
139 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
140 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
141 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
142 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
143 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 144 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 145 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
146 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
147 .len = WLAN_PMKID_LEN },
9588bbd5
JM
148 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
149 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 150 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
151 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
152 .len = IEEE80211_MAX_DATA_LEN },
153 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 154 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 155 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 156 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 157 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
158
159 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
160 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 161 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
55682965
JB
162};
163
b9454e83 164/* policy for the attributes */
b54452b0 165static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 166 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
167 [NL80211_KEY_IDX] = { .type = NLA_U8 },
168 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
169 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
170 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
171 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
172};
173
a043897a
HS
174/* ifidx get helper */
175static int nl80211_get_ifidx(struct netlink_callback *cb)
176{
177 int res;
178
179 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
180 nl80211_fam.attrbuf, nl80211_fam.maxattr,
181 nl80211_policy);
182 if (res)
183 return res;
184
185 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
186 return -EINVAL;
187
188 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
189 if (!res)
190 return -EINVAL;
191 return res;
192}
193
f4a11bb0
JB
194/* IE validation */
195static bool is_valid_ie_attr(const struct nlattr *attr)
196{
197 const u8 *pos;
198 int len;
199
200 if (!attr)
201 return true;
202
203 pos = nla_data(attr);
204 len = nla_len(attr);
205
206 while (len) {
207 u8 elemlen;
208
209 if (len < 2)
210 return false;
211 len -= 2;
212
213 elemlen = pos[1];
214 if (elemlen > len)
215 return false;
216
217 len -= elemlen;
218 pos += 2 + elemlen;
219 }
220
221 return true;
222}
223
55682965
JB
224/* message building helper */
225static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
226 int flags, u8 cmd)
227{
228 /* since there is no private header just add the generic one */
229 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
230}
231
5dab3b8a
LR
232static int nl80211_msg_put_channel(struct sk_buff *msg,
233 struct ieee80211_channel *chan)
234{
235 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
236 chan->center_freq);
237
238 if (chan->flags & IEEE80211_CHAN_DISABLED)
239 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
240 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
241 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
242 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
243 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
244 if (chan->flags & IEEE80211_CHAN_RADAR)
245 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
246
247 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
248 DBM_TO_MBM(chan->max_power));
249
250 return 0;
251
252 nla_put_failure:
253 return -ENOBUFS;
254}
255
55682965
JB
256/* netlink command implementations */
257
b9454e83
JB
258struct key_parse {
259 struct key_params p;
260 int idx;
261 bool def, defmgmt;
262};
263
264static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
265{
266 struct nlattr *tb[NL80211_KEY_MAX + 1];
267 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
268 nl80211_key_policy);
269 if (err)
270 return err;
271
272 k->def = !!tb[NL80211_KEY_DEFAULT];
273 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
274
275 if (tb[NL80211_KEY_IDX])
276 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
277
278 if (tb[NL80211_KEY_DATA]) {
279 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
280 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
281 }
282
283 if (tb[NL80211_KEY_SEQ]) {
284 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
285 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
286 }
287
288 if (tb[NL80211_KEY_CIPHER])
289 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
290
291 return 0;
292}
293
294static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
295{
296 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
297 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
298 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
299 }
300
301 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
302 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
303 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
304 }
305
306 if (info->attrs[NL80211_ATTR_KEY_IDX])
307 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
308
309 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
310 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
311
312 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
313 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
314
315 return 0;
316}
317
318static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
319{
320 int err;
321
322 memset(k, 0, sizeof(*k));
323 k->idx = -1;
324
325 if (info->attrs[NL80211_ATTR_KEY])
326 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
327 else
328 err = nl80211_parse_key_old(info, k);
329
330 if (err)
331 return err;
332
333 if (k->def && k->defmgmt)
334 return -EINVAL;
335
336 if (k->idx != -1) {
337 if (k->defmgmt) {
338 if (k->idx < 4 || k->idx > 5)
339 return -EINVAL;
340 } else if (k->def) {
341 if (k->idx < 0 || k->idx > 3)
342 return -EINVAL;
343 } else {
344 if (k->idx < 0 || k->idx > 5)
345 return -EINVAL;
346 }
347 }
348
349 return 0;
350}
351
fffd0934
JB
352static struct cfg80211_cached_keys *
353nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
354 struct nlattr *keys)
355{
356 struct key_parse parse;
357 struct nlattr *key;
358 struct cfg80211_cached_keys *result;
359 int rem, err, def = 0;
360
361 result = kzalloc(sizeof(*result), GFP_KERNEL);
362 if (!result)
363 return ERR_PTR(-ENOMEM);
364
365 result->def = -1;
366 result->defmgmt = -1;
367
368 nla_for_each_nested(key, keys, rem) {
369 memset(&parse, 0, sizeof(parse));
370 parse.idx = -1;
371
372 err = nl80211_parse_key_new(key, &parse);
373 if (err)
374 goto error;
375 err = -EINVAL;
376 if (!parse.p.key)
377 goto error;
378 if (parse.idx < 0 || parse.idx > 4)
379 goto error;
380 if (parse.def) {
381 if (def)
382 goto error;
383 def = 1;
384 result->def = parse.idx;
385 } else if (parse.defmgmt)
386 goto error;
387 err = cfg80211_validate_key_settings(rdev, &parse.p,
388 parse.idx, NULL);
389 if (err)
390 goto error;
391 result->params[parse.idx].cipher = parse.p.cipher;
392 result->params[parse.idx].key_len = parse.p.key_len;
393 result->params[parse.idx].key = result->data[parse.idx];
394 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
395 }
396
397 return result;
398 error:
399 kfree(result);
400 return ERR_PTR(err);
401}
402
403static int nl80211_key_allowed(struct wireless_dev *wdev)
404{
405 ASSERT_WDEV_LOCK(wdev);
406
407 if (!netif_running(wdev->netdev))
408 return -ENETDOWN;
409
410 switch (wdev->iftype) {
411 case NL80211_IFTYPE_AP:
412 case NL80211_IFTYPE_AP_VLAN:
074ac8df 413 case NL80211_IFTYPE_P2P_GO:
fffd0934
JB
414 break;
415 case NL80211_IFTYPE_ADHOC:
416 if (!wdev->current_bss)
417 return -ENOLINK;
418 break;
419 case NL80211_IFTYPE_STATION:
074ac8df 420 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
421 if (wdev->sme_state != CFG80211_SME_CONNECTED)
422 return -ENOLINK;
423 break;
424 default:
425 return -EINVAL;
426 }
427
428 return 0;
429}
430
55682965
JB
431static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
432 struct cfg80211_registered_device *dev)
433{
434 void *hdr;
ee688b00
JB
435 struct nlattr *nl_bands, *nl_band;
436 struct nlattr *nl_freqs, *nl_freq;
437 struct nlattr *nl_rates, *nl_rate;
f59ac048 438 struct nlattr *nl_modes;
8fdc621d 439 struct nlattr *nl_cmds;
ee688b00
JB
440 enum ieee80211_band band;
441 struct ieee80211_channel *chan;
442 struct ieee80211_rate *rate;
443 int i;
f59ac048 444 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
445 const struct ieee80211_txrx_stypes *mgmt_stypes =
446 dev->wiphy.mgmt_stypes;
55682965
JB
447
448 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
449 if (!hdr)
450 return -1;
451
b5850a7a 452 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 453 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 454
f5ea9120
JB
455 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
456 cfg80211_rdev_list_generation);
457
b9a5f8ca
JM
458 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
459 dev->wiphy.retry_short);
460 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
461 dev->wiphy.retry_long);
462 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
463 dev->wiphy.frag_threshold);
464 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
465 dev->wiphy.rts_threshold);
81077e82
LT
466 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
467 dev->wiphy.coverage_class);
b9a5f8ca 468
2a519311
JB
469 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
470 dev->wiphy.max_scan_ssids);
18a83659
JB
471 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
472 dev->wiphy.max_scan_ie_len);
ee688b00 473
25e47c18
JB
474 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
475 sizeof(u32) * dev->wiphy.n_cipher_suites,
476 dev->wiphy.cipher_suites);
477
67fbb16b
SO
478 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
479 dev->wiphy.max_num_pmkids);
480
c0692b8f
JB
481 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
482 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
483
f59ac048
LR
484 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
485 if (!nl_modes)
486 goto nla_put_failure;
487
488 i = 0;
489 while (ifmodes) {
490 if (ifmodes & 1)
491 NLA_PUT_FLAG(msg, i);
492 ifmodes >>= 1;
493 i++;
494 }
495
496 nla_nest_end(msg, nl_modes);
497
ee688b00
JB
498 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
499 if (!nl_bands)
500 goto nla_put_failure;
501
502 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
503 if (!dev->wiphy.bands[band])
504 continue;
505
506 nl_band = nla_nest_start(msg, band);
507 if (!nl_band)
508 goto nla_put_failure;
509
d51626df
JB
510 /* add HT info */
511 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
512 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
513 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
514 &dev->wiphy.bands[band]->ht_cap.mcs);
515 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
516 dev->wiphy.bands[band]->ht_cap.cap);
517 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
518 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
519 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
520 dev->wiphy.bands[band]->ht_cap.ampdu_density);
521 }
522
ee688b00
JB
523 /* add frequencies */
524 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
525 if (!nl_freqs)
526 goto nla_put_failure;
527
528 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
529 nl_freq = nla_nest_start(msg, i);
530 if (!nl_freq)
531 goto nla_put_failure;
532
533 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
534
535 if (nl80211_msg_put_channel(msg, chan))
536 goto nla_put_failure;
e2f367f2 537
ee688b00
JB
538 nla_nest_end(msg, nl_freq);
539 }
540
541 nla_nest_end(msg, nl_freqs);
542
543 /* add bitrates */
544 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
545 if (!nl_rates)
546 goto nla_put_failure;
547
548 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
549 nl_rate = nla_nest_start(msg, i);
550 if (!nl_rate)
551 goto nla_put_failure;
552
553 rate = &dev->wiphy.bands[band]->bitrates[i];
554 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
555 rate->bitrate);
556 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
557 NLA_PUT_FLAG(msg,
558 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
559
560 nla_nest_end(msg, nl_rate);
561 }
562
563 nla_nest_end(msg, nl_rates);
564
565 nla_nest_end(msg, nl_band);
566 }
567 nla_nest_end(msg, nl_bands);
568
8fdc621d
JB
569 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
570 if (!nl_cmds)
571 goto nla_put_failure;
572
573 i = 0;
574#define CMD(op, n) \
575 do { \
576 if (dev->ops->op) { \
577 i++; \
578 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
579 } \
580 } while (0)
581
582 CMD(add_virtual_intf, NEW_INTERFACE);
583 CMD(change_virtual_intf, SET_INTERFACE);
584 CMD(add_key, NEW_KEY);
585 CMD(add_beacon, NEW_BEACON);
586 CMD(add_station, NEW_STATION);
587 CMD(add_mpath, NEW_MPATH);
588 CMD(set_mesh_params, SET_MESH_PARAMS);
589 CMD(change_bss, SET_BSS);
636a5d36
JM
590 CMD(auth, AUTHENTICATE);
591 CMD(assoc, ASSOCIATE);
592 CMD(deauth, DEAUTHENTICATE);
593 CMD(disassoc, DISASSOCIATE);
04a773ad 594 CMD(join_ibss, JOIN_IBSS);
67fbb16b
SO
595 CMD(set_pmksa, SET_PMKSA);
596 CMD(del_pmksa, DEL_PMKSA);
597 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 598 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 599 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 600 CMD(mgmt_tx, FRAME);
5be83de5 601 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
602 i++;
603 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
604 }
f444de05 605 CMD(set_channel, SET_CHANNEL);
8fdc621d
JB
606
607#undef CMD
b23aa676 608
6829c878 609 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
610 i++;
611 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
612 }
613
6829c878 614 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
615 i++;
616 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
617 }
618
8fdc621d
JB
619 nla_nest_end(msg, nl_cmds);
620
2e161f78
JB
621 if (mgmt_stypes) {
622 u16 stypes;
623 struct nlattr *nl_ftypes, *nl_ifs;
624 enum nl80211_iftype ift;
625
626 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
627 if (!nl_ifs)
628 goto nla_put_failure;
629
630 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
631 nl_ftypes = nla_nest_start(msg, ift);
632 if (!nl_ftypes)
633 goto nla_put_failure;
634 i = 0;
635 stypes = mgmt_stypes[ift].tx;
636 while (stypes) {
637 if (stypes & 1)
638 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
639 (i << 4) | IEEE80211_FTYPE_MGMT);
640 stypes >>= 1;
641 i++;
642 }
643 nla_nest_end(msg, nl_ftypes);
644 }
645
74b70a4e
JB
646 nla_nest_end(msg, nl_ifs);
647
2e161f78
JB
648 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
649 if (!nl_ifs)
650 goto nla_put_failure;
651
652 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
653 nl_ftypes = nla_nest_start(msg, ift);
654 if (!nl_ftypes)
655 goto nla_put_failure;
656 i = 0;
657 stypes = mgmt_stypes[ift].rx;
658 while (stypes) {
659 if (stypes & 1)
660 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
661 (i << 4) | IEEE80211_FTYPE_MGMT);
662 stypes >>= 1;
663 i++;
664 }
665 nla_nest_end(msg, nl_ftypes);
666 }
667 nla_nest_end(msg, nl_ifs);
668 }
669
55682965
JB
670 return genlmsg_end(msg, hdr);
671
672 nla_put_failure:
bc3ed28c
TG
673 genlmsg_cancel(msg, hdr);
674 return -EMSGSIZE;
55682965
JB
675}
676
677static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
678{
679 int idx = 0;
680 int start = cb->args[0];
681 struct cfg80211_registered_device *dev;
682
a1794390 683 mutex_lock(&cfg80211_mutex);
79c97e97 684 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
685 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
686 continue;
b4637271 687 if (++idx <= start)
55682965
JB
688 continue;
689 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
690 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
691 dev) < 0) {
692 idx--;
55682965 693 break;
b4637271 694 }
55682965 695 }
a1794390 696 mutex_unlock(&cfg80211_mutex);
55682965
JB
697
698 cb->args[0] = idx;
699
700 return skb->len;
701}
702
703static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
704{
705 struct sk_buff *msg;
706 struct cfg80211_registered_device *dev;
707
708 dev = cfg80211_get_dev_from_info(info);
709 if (IS_ERR(dev))
710 return PTR_ERR(dev);
711
fd2120ca 712 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
713 if (!msg)
714 goto out_err;
715
716 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
717 goto out_free;
718
4d0c8aea 719 cfg80211_unlock_rdev(dev);
55682965 720
134e6375 721 return genlmsg_reply(msg, info);
55682965
JB
722
723 out_free:
724 nlmsg_free(msg);
725 out_err:
4d0c8aea 726 cfg80211_unlock_rdev(dev);
55682965
JB
727 return -ENOBUFS;
728}
729
31888487
JM
730static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
731 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
732 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
733 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
734 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
735 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
736};
737
738static int parse_txq_params(struct nlattr *tb[],
739 struct ieee80211_txq_params *txq_params)
740{
741 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
742 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
743 !tb[NL80211_TXQ_ATTR_AIFS])
744 return -EINVAL;
745
746 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
747 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
748 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
749 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
750 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
751
752 return 0;
753}
754
f444de05
JB
755static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
756{
757 /*
758 * You can only set the channel explicitly for AP, mesh
759 * and WDS type interfaces; all others have their channel
760 * managed via their respective "establish a connection"
761 * command (connect, join, ...)
762 *
763 * Monitors are special as they are normally slaved to
764 * whatever else is going on, so they behave as though
765 * you tried setting the wiphy channel itself.
766 */
767 return !wdev ||
768 wdev->iftype == NL80211_IFTYPE_AP ||
769 wdev->iftype == NL80211_IFTYPE_WDS ||
770 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
771 wdev->iftype == NL80211_IFTYPE_MONITOR ||
772 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
773}
774
775static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
776 struct wireless_dev *wdev,
777 struct genl_info *info)
778{
779 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
780 u32 freq;
781 int result;
782
783 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
784 return -EINVAL;
785
786 if (!nl80211_can_set_dev_channel(wdev))
787 return -EOPNOTSUPP;
788
789 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
790 channel_type = nla_get_u32(info->attrs[
791 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
792 if (channel_type != NL80211_CHAN_NO_HT &&
793 channel_type != NL80211_CHAN_HT20 &&
794 channel_type != NL80211_CHAN_HT40PLUS &&
795 channel_type != NL80211_CHAN_HT40MINUS)
796 return -EINVAL;
797 }
798
799 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
800
801 mutex_lock(&rdev->devlist_mtx);
802 if (wdev) {
803 wdev_lock(wdev);
804 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
805 wdev_unlock(wdev);
806 } else {
807 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
808 }
809 mutex_unlock(&rdev->devlist_mtx);
810
811 return result;
812}
813
814static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
815{
816 struct cfg80211_registered_device *rdev;
817 struct net_device *netdev;
818 int result;
819
820 rtnl_lock();
821
822 result = get_rdev_dev_by_info_ifindex(info, &rdev, &netdev);
823 if (result)
824 goto unlock;
825
826 result = __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
827
828 unlock:
829 rtnl_unlock();
830
831 return result;
832}
833
55682965
JB
834static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
835{
836 struct cfg80211_registered_device *rdev;
f444de05
JB
837 struct net_device *netdev = NULL;
838 struct wireless_dev *wdev;
a1e567c8 839 int result = 0, rem_txq_params = 0;
31888487 840 struct nlattr *nl_txq_params;
b9a5f8ca
JM
841 u32 changed;
842 u8 retry_short = 0, retry_long = 0;
843 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 844 u8 coverage_class = 0;
55682965 845
4bbf4d56 846 rtnl_lock();
55682965 847
f444de05
JB
848 /*
849 * Try to find the wiphy and netdev. Normally this
850 * function shouldn't need the netdev, but this is
851 * done for backward compatibility -- previously
852 * setting the channel was done per wiphy, but now
853 * it is per netdev. Previous userland like hostapd
854 * also passed a netdev to set_wiphy, so that it is
855 * possible to let that go to the right netdev!
856 */
4bbf4d56
JB
857 mutex_lock(&cfg80211_mutex);
858
f444de05
JB
859 if (info->attrs[NL80211_ATTR_IFINDEX]) {
860 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
861
862 netdev = dev_get_by_index(genl_info_net(info), ifindex);
863 if (netdev && netdev->ieee80211_ptr) {
864 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
865 mutex_lock(&rdev->mtx);
866 } else
867 netdev = NULL;
4bbf4d56
JB
868 }
869
f444de05
JB
870 if (!netdev) {
871 rdev = __cfg80211_rdev_from_info(info);
872 if (IS_ERR(rdev)) {
873 mutex_unlock(&cfg80211_mutex);
874 result = PTR_ERR(rdev);
875 goto unlock;
876 }
877 wdev = NULL;
878 netdev = NULL;
879 result = 0;
880
881 mutex_lock(&rdev->mtx);
882 } else if (netif_running(netdev) &&
883 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
884 wdev = netdev->ieee80211_ptr;
885 else
886 wdev = NULL;
887
888 /*
889 * end workaround code, by now the rdev is available
890 * and locked, and wdev may or may not be NULL.
891 */
4bbf4d56
JB
892
893 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
894 result = cfg80211_dev_rename(
895 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
896
897 mutex_unlock(&cfg80211_mutex);
898
899 if (result)
900 goto bad_res;
31888487
JM
901
902 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
903 struct ieee80211_txq_params txq_params;
904 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
905
906 if (!rdev->ops->set_txq_params) {
907 result = -EOPNOTSUPP;
908 goto bad_res;
909 }
910
911 nla_for_each_nested(nl_txq_params,
912 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
913 rem_txq_params) {
914 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
915 nla_data(nl_txq_params),
916 nla_len(nl_txq_params),
917 txq_params_policy);
918 result = parse_txq_params(tb, &txq_params);
919 if (result)
920 goto bad_res;
921
922 result = rdev->ops->set_txq_params(&rdev->wiphy,
923 &txq_params);
924 if (result)
925 goto bad_res;
926 }
927 }
55682965 928
72bdcf34 929 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 930 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
931 if (result)
932 goto bad_res;
933 }
934
98d2ff8b
JO
935 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
936 enum nl80211_tx_power_setting type;
937 int idx, mbm = 0;
938
939 if (!rdev->ops->set_tx_power) {
60ea385f 940 result = -EOPNOTSUPP;
98d2ff8b
JO
941 goto bad_res;
942 }
943
944 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
945 type = nla_get_u32(info->attrs[idx]);
946
947 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
948 (type != NL80211_TX_POWER_AUTOMATIC)) {
949 result = -EINVAL;
950 goto bad_res;
951 }
952
953 if (type != NL80211_TX_POWER_AUTOMATIC) {
954 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
955 mbm = nla_get_u32(info->attrs[idx]);
956 }
957
958 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
959 if (result)
960 goto bad_res;
961 }
962
b9a5f8ca
JM
963 changed = 0;
964
965 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
966 retry_short = nla_get_u8(
967 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
968 if (retry_short == 0) {
969 result = -EINVAL;
970 goto bad_res;
971 }
972 changed |= WIPHY_PARAM_RETRY_SHORT;
973 }
974
975 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
976 retry_long = nla_get_u8(
977 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
978 if (retry_long == 0) {
979 result = -EINVAL;
980 goto bad_res;
981 }
982 changed |= WIPHY_PARAM_RETRY_LONG;
983 }
984
985 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
986 frag_threshold = nla_get_u32(
987 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
988 if (frag_threshold < 256) {
989 result = -EINVAL;
990 goto bad_res;
991 }
992 if (frag_threshold != (u32) -1) {
993 /*
994 * Fragments (apart from the last one) are required to
995 * have even length. Make the fragmentation code
996 * simpler by stripping LSB should someone try to use
997 * odd threshold value.
998 */
999 frag_threshold &= ~0x1;
1000 }
1001 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1002 }
1003
1004 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1005 rts_threshold = nla_get_u32(
1006 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1007 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1008 }
1009
81077e82
LT
1010 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1011 coverage_class = nla_get_u8(
1012 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1013 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1014 }
1015
b9a5f8ca
JM
1016 if (changed) {
1017 u8 old_retry_short, old_retry_long;
1018 u32 old_frag_threshold, old_rts_threshold;
81077e82 1019 u8 old_coverage_class;
b9a5f8ca
JM
1020
1021 if (!rdev->ops->set_wiphy_params) {
1022 result = -EOPNOTSUPP;
1023 goto bad_res;
1024 }
1025
1026 old_retry_short = rdev->wiphy.retry_short;
1027 old_retry_long = rdev->wiphy.retry_long;
1028 old_frag_threshold = rdev->wiphy.frag_threshold;
1029 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1030 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1031
1032 if (changed & WIPHY_PARAM_RETRY_SHORT)
1033 rdev->wiphy.retry_short = retry_short;
1034 if (changed & WIPHY_PARAM_RETRY_LONG)
1035 rdev->wiphy.retry_long = retry_long;
1036 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1037 rdev->wiphy.frag_threshold = frag_threshold;
1038 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1039 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1040 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1041 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1042
1043 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1044 if (result) {
1045 rdev->wiphy.retry_short = old_retry_short;
1046 rdev->wiphy.retry_long = old_retry_long;
1047 rdev->wiphy.frag_threshold = old_frag_threshold;
1048 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1049 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1050 }
1051 }
72bdcf34 1052
306d6112 1053 bad_res:
4bbf4d56 1054 mutex_unlock(&rdev->mtx);
f444de05
JB
1055 if (netdev)
1056 dev_put(netdev);
4bbf4d56
JB
1057 unlock:
1058 rtnl_unlock();
55682965
JB
1059 return result;
1060}
1061
1062
1063static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1064 struct cfg80211_registered_device *rdev,
55682965
JB
1065 struct net_device *dev)
1066{
1067 void *hdr;
1068
1069 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1070 if (!hdr)
1071 return -1;
1072
1073 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1074 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1075 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1076 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1077
1078 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1079 rdev->devlist_generation ^
1080 (cfg80211_rdev_list_generation << 2));
1081
55682965
JB
1082 return genlmsg_end(msg, hdr);
1083
1084 nla_put_failure:
bc3ed28c
TG
1085 genlmsg_cancel(msg, hdr);
1086 return -EMSGSIZE;
55682965
JB
1087}
1088
1089static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1090{
1091 int wp_idx = 0;
1092 int if_idx = 0;
1093 int wp_start = cb->args[0];
1094 int if_start = cb->args[1];
f5ea9120 1095 struct cfg80211_registered_device *rdev;
55682965
JB
1096 struct wireless_dev *wdev;
1097
a1794390 1098 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1099 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1100 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1101 continue;
bba95fef
JB
1102 if (wp_idx < wp_start) {
1103 wp_idx++;
55682965 1104 continue;
bba95fef 1105 }
55682965
JB
1106 if_idx = 0;
1107
f5ea9120
JB
1108 mutex_lock(&rdev->devlist_mtx);
1109 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1110 if (if_idx < if_start) {
1111 if_idx++;
55682965 1112 continue;
bba95fef 1113 }
55682965
JB
1114 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1115 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1116 rdev, wdev->netdev) < 0) {
1117 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1118 goto out;
1119 }
1120 if_idx++;
55682965 1121 }
f5ea9120 1122 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1123
1124 wp_idx++;
55682965 1125 }
bba95fef 1126 out:
a1794390 1127 mutex_unlock(&cfg80211_mutex);
55682965
JB
1128
1129 cb->args[0] = wp_idx;
1130 cb->args[1] = if_idx;
1131
1132 return skb->len;
1133}
1134
1135static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1136{
1137 struct sk_buff *msg;
1138 struct cfg80211_registered_device *dev;
1139 struct net_device *netdev;
1140 int err;
1141
463d0183 1142 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
1143 if (err)
1144 return err;
1145
fd2120ca 1146 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
1147 if (!msg)
1148 goto out_err;
1149
d726405a
JB
1150 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1151 dev, netdev) < 0)
55682965
JB
1152 goto out_free;
1153
1154 dev_put(netdev);
4d0c8aea 1155 cfg80211_unlock_rdev(dev);
55682965 1156
134e6375 1157 return genlmsg_reply(msg, info);
55682965
JB
1158
1159 out_free:
1160 nlmsg_free(msg);
1161 out_err:
1162 dev_put(netdev);
4d0c8aea 1163 cfg80211_unlock_rdev(dev);
55682965
JB
1164 return -ENOBUFS;
1165}
1166
66f7ac50
MW
1167static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1168 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1169 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1170 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1171 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1172 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1173};
1174
1175static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1176{
1177 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1178 int flag;
1179
1180 *mntrflags = 0;
1181
1182 if (!nla)
1183 return -EINVAL;
1184
1185 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1186 nla, mntr_flags_policy))
1187 return -EINVAL;
1188
1189 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1190 if (flags[flag])
1191 *mntrflags |= (1<<flag);
1192
1193 return 0;
1194}
1195
9bc383de 1196static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1197 struct net_device *netdev, u8 use_4addr,
1198 enum nl80211_iftype iftype)
9bc383de 1199{
ad4bb6f8 1200 if (!use_4addr) {
f350a0a8 1201 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1202 return -EBUSY;
9bc383de 1203 return 0;
ad4bb6f8 1204 }
9bc383de
JB
1205
1206 switch (iftype) {
1207 case NL80211_IFTYPE_AP_VLAN:
1208 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1209 return 0;
1210 break;
1211 case NL80211_IFTYPE_STATION:
1212 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1213 return 0;
1214 break;
1215 default:
1216 break;
1217 }
1218
1219 return -EOPNOTSUPP;
1220}
1221
55682965
JB
1222static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1223{
79c97e97 1224 struct cfg80211_registered_device *rdev;
2ec600d6 1225 struct vif_params params;
e36d56b6 1226 int err;
04a773ad 1227 enum nl80211_iftype otype, ntype;
55682965 1228 struct net_device *dev;
92ffe055 1229 u32 _flags, *flags = NULL;
ac7f9cfa 1230 bool change = false;
55682965 1231
2ec600d6
LCC
1232 memset(&params, 0, sizeof(params));
1233
3b85875a
JB
1234 rtnl_lock();
1235
463d0183 1236 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1237 if (err)
3b85875a
JB
1238 goto unlock_rtnl;
1239
04a773ad 1240 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1241
723b038d 1242 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1243 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1244 if (otype != ntype)
ac7f9cfa 1245 change = true;
04a773ad 1246 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 1247 err = -EINVAL;
723b038d 1248 goto unlock;
ac7f9cfa 1249 }
723b038d
JB
1250 }
1251
92ffe055 1252 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1253 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1254 err = -EINVAL;
1255 goto unlock;
1256 }
2ec600d6
LCC
1257 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1258 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1259 change = true;
2ec600d6
LCC
1260 }
1261
8b787643
FF
1262 if (info->attrs[NL80211_ATTR_4ADDR]) {
1263 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1264 change = true;
ad4bb6f8 1265 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de
JB
1266 if (err)
1267 goto unlock;
8b787643
FF
1268 } else {
1269 params.use_4addr = -1;
1270 }
1271
92ffe055 1272 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1273 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1274 err = -EINVAL;
1275 goto unlock;
1276 }
1277 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1278 &_flags);
ac7f9cfa
JB
1279 if (err)
1280 goto unlock;
1281
1282 flags = &_flags;
1283 change = true;
92ffe055 1284 }
3b85875a 1285
ac7f9cfa 1286 if (change)
3d54d255 1287 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1288 else
1289 err = 0;
60719ffd 1290
9bc383de
JB
1291 if (!err && params.use_4addr != -1)
1292 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1293
55682965 1294 unlock:
e36d56b6 1295 dev_put(dev);
79c97e97 1296 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1297 unlock_rtnl:
1298 rtnl_unlock();
55682965
JB
1299 return err;
1300}
1301
1302static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1303{
79c97e97 1304 struct cfg80211_registered_device *rdev;
2ec600d6 1305 struct vif_params params;
55682965
JB
1306 int err;
1307 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1308 u32 flags;
55682965 1309
2ec600d6
LCC
1310 memset(&params, 0, sizeof(params));
1311
55682965
JB
1312 if (!info->attrs[NL80211_ATTR_IFNAME])
1313 return -EINVAL;
1314
1315 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1316 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1317 if (type > NL80211_IFTYPE_MAX)
1318 return -EINVAL;
1319 }
1320
3b85875a
JB
1321 rtnl_lock();
1322
79c97e97
JB
1323 rdev = cfg80211_get_dev_from_info(info);
1324 if (IS_ERR(rdev)) {
1325 err = PTR_ERR(rdev);
3b85875a
JB
1326 goto unlock_rtnl;
1327 }
55682965 1328
79c97e97
JB
1329 if (!rdev->ops->add_virtual_intf ||
1330 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1331 err = -EOPNOTSUPP;
1332 goto unlock;
1333 }
1334
2ec600d6
LCC
1335 if (type == NL80211_IFTYPE_MESH_POINT &&
1336 info->attrs[NL80211_ATTR_MESH_ID]) {
1337 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1338 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1339 }
1340
9bc383de 1341 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1342 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1343 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de
JB
1344 if (err)
1345 goto unlock;
1346 }
8b787643 1347
66f7ac50
MW
1348 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1349 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1350 &flags);
79c97e97 1351 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1352 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1353 type, err ? NULL : &flags, &params);
2ec600d6 1354
55682965 1355 unlock:
79c97e97 1356 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1357 unlock_rtnl:
1358 rtnl_unlock();
55682965
JB
1359 return err;
1360}
1361
1362static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1363{
79c97e97 1364 struct cfg80211_registered_device *rdev;
463d0183 1365 int err;
55682965
JB
1366 struct net_device *dev;
1367
3b85875a
JB
1368 rtnl_lock();
1369
463d0183 1370 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1371 if (err)
3b85875a 1372 goto unlock_rtnl;
55682965 1373
79c97e97 1374 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1375 err = -EOPNOTSUPP;
1376 goto out;
1377 }
1378
463d0183 1379 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1380
1381 out:
79c97e97 1382 cfg80211_unlock_rdev(rdev);
463d0183 1383 dev_put(dev);
3b85875a
JB
1384 unlock_rtnl:
1385 rtnl_unlock();
55682965
JB
1386 return err;
1387}
1388
41ade00f
JB
1389struct get_key_cookie {
1390 struct sk_buff *msg;
1391 int error;
b9454e83 1392 int idx;
41ade00f
JB
1393};
1394
1395static void get_key_callback(void *c, struct key_params *params)
1396{
b9454e83 1397 struct nlattr *key;
41ade00f
JB
1398 struct get_key_cookie *cookie = c;
1399
1400 if (params->key)
1401 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1402 params->key_len, params->key);
1403
1404 if (params->seq)
1405 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1406 params->seq_len, params->seq);
1407
1408 if (params->cipher)
1409 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1410 params->cipher);
1411
b9454e83
JB
1412 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1413 if (!key)
1414 goto nla_put_failure;
1415
1416 if (params->key)
1417 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1418 params->key_len, params->key);
1419
1420 if (params->seq)
1421 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1422 params->seq_len, params->seq);
1423
1424 if (params->cipher)
1425 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1426 params->cipher);
1427
1428 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1429
1430 nla_nest_end(cookie->msg, key);
1431
41ade00f
JB
1432 return;
1433 nla_put_failure:
1434 cookie->error = 1;
1435}
1436
1437static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1438{
79c97e97 1439 struct cfg80211_registered_device *rdev;
41ade00f
JB
1440 int err;
1441 struct net_device *dev;
1442 u8 key_idx = 0;
1443 u8 *mac_addr = NULL;
1444 struct get_key_cookie cookie = {
1445 .error = 0,
1446 };
1447 void *hdr;
1448 struct sk_buff *msg;
1449
1450 if (info->attrs[NL80211_ATTR_KEY_IDX])
1451 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1452
3cfcf6ac 1453 if (key_idx > 5)
41ade00f
JB
1454 return -EINVAL;
1455
1456 if (info->attrs[NL80211_ATTR_MAC])
1457 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1458
3b85875a
JB
1459 rtnl_lock();
1460
463d0183 1461 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1462 if (err)
3b85875a 1463 goto unlock_rtnl;
41ade00f 1464
79c97e97 1465 if (!rdev->ops->get_key) {
41ade00f
JB
1466 err = -EOPNOTSUPP;
1467 goto out;
1468 }
1469
fd2120ca 1470 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1471 if (!msg) {
1472 err = -ENOMEM;
1473 goto out;
1474 }
1475
1476 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1477 NL80211_CMD_NEW_KEY);
1478
1479 if (IS_ERR(hdr)) {
1480 err = PTR_ERR(hdr);
6c95e2a2 1481 goto free_msg;
41ade00f
JB
1482 }
1483
1484 cookie.msg = msg;
b9454e83 1485 cookie.idx = key_idx;
41ade00f
JB
1486
1487 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1488 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1489 if (mac_addr)
1490 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1491
79c97e97 1492 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1493 &cookie, get_key_callback);
41ade00f
JB
1494
1495 if (err)
6c95e2a2 1496 goto free_msg;
41ade00f
JB
1497
1498 if (cookie.error)
1499 goto nla_put_failure;
1500
1501 genlmsg_end(msg, hdr);
134e6375 1502 err = genlmsg_reply(msg, info);
41ade00f
JB
1503 goto out;
1504
1505 nla_put_failure:
1506 err = -ENOBUFS;
6c95e2a2 1507 free_msg:
41ade00f
JB
1508 nlmsg_free(msg);
1509 out:
79c97e97 1510 cfg80211_unlock_rdev(rdev);
41ade00f 1511 dev_put(dev);
3b85875a
JB
1512 unlock_rtnl:
1513 rtnl_unlock();
1514
41ade00f
JB
1515 return err;
1516}
1517
1518static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1519{
79c97e97 1520 struct cfg80211_registered_device *rdev;
b9454e83 1521 struct key_parse key;
41ade00f
JB
1522 int err;
1523 struct net_device *dev;
3cfcf6ac
JM
1524 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1525 u8 key_index);
41ade00f 1526
b9454e83
JB
1527 err = nl80211_parse_key(info, &key);
1528 if (err)
1529 return err;
41ade00f 1530
b9454e83 1531 if (key.idx < 0)
41ade00f
JB
1532 return -EINVAL;
1533
b9454e83
JB
1534 /* only support setting default key */
1535 if (!key.def && !key.defmgmt)
41ade00f
JB
1536 return -EINVAL;
1537
3b85875a
JB
1538 rtnl_lock();
1539
463d0183 1540 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1541 if (err)
3b85875a 1542 goto unlock_rtnl;
41ade00f 1543
b9454e83 1544 if (key.def)
79c97e97 1545 func = rdev->ops->set_default_key;
3cfcf6ac 1546 else
79c97e97 1547 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1548
1549 if (!func) {
41ade00f
JB
1550 err = -EOPNOTSUPP;
1551 goto out;
1552 }
1553
fffd0934
JB
1554 wdev_lock(dev->ieee80211_ptr);
1555 err = nl80211_key_allowed(dev->ieee80211_ptr);
1556 if (!err)
1557 err = func(&rdev->wiphy, dev, key.idx);
1558
3d23e349 1559#ifdef CONFIG_CFG80211_WEXT
08645126 1560 if (!err) {
79c97e97 1561 if (func == rdev->ops->set_default_key)
b9454e83 1562 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1563 else
b9454e83 1564 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1565 }
1566#endif
fffd0934 1567 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1568
1569 out:
79c97e97 1570 cfg80211_unlock_rdev(rdev);
41ade00f 1571 dev_put(dev);
3b85875a
JB
1572
1573 unlock_rtnl:
1574 rtnl_unlock();
1575
41ade00f
JB
1576 return err;
1577}
1578
1579static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1580{
79c97e97 1581 struct cfg80211_registered_device *rdev;
fffd0934 1582 int err;
41ade00f 1583 struct net_device *dev;
b9454e83 1584 struct key_parse key;
41ade00f
JB
1585 u8 *mac_addr = NULL;
1586
b9454e83
JB
1587 err = nl80211_parse_key(info, &key);
1588 if (err)
1589 return err;
41ade00f 1590
b9454e83 1591 if (!key.p.key)
41ade00f
JB
1592 return -EINVAL;
1593
41ade00f
JB
1594 if (info->attrs[NL80211_ATTR_MAC])
1595 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1596
3b85875a
JB
1597 rtnl_lock();
1598
463d0183 1599 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1600 if (err)
3b85875a 1601 goto unlock_rtnl;
41ade00f 1602
fffd0934
JB
1603 if (!rdev->ops->add_key) {
1604 err = -EOPNOTSUPP;
25e47c18
JB
1605 goto out;
1606 }
1607
fffd0934
JB
1608 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1609 err = -EINVAL;
41ade00f
JB
1610 goto out;
1611 }
1612
fffd0934
JB
1613 wdev_lock(dev->ieee80211_ptr);
1614 err = nl80211_key_allowed(dev->ieee80211_ptr);
1615 if (!err)
1616 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1617 mac_addr, &key.p);
1618 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1619
1620 out:
79c97e97 1621 cfg80211_unlock_rdev(rdev);
41ade00f 1622 dev_put(dev);
3b85875a
JB
1623 unlock_rtnl:
1624 rtnl_unlock();
1625
41ade00f
JB
1626 return err;
1627}
1628
1629static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1630{
79c97e97 1631 struct cfg80211_registered_device *rdev;
41ade00f
JB
1632 int err;
1633 struct net_device *dev;
41ade00f 1634 u8 *mac_addr = NULL;
b9454e83 1635 struct key_parse key;
41ade00f 1636
b9454e83
JB
1637 err = nl80211_parse_key(info, &key);
1638 if (err)
1639 return err;
41ade00f
JB
1640
1641 if (info->attrs[NL80211_ATTR_MAC])
1642 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1643
3b85875a
JB
1644 rtnl_lock();
1645
463d0183 1646 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1647 if (err)
3b85875a 1648 goto unlock_rtnl;
41ade00f 1649
79c97e97 1650 if (!rdev->ops->del_key) {
41ade00f
JB
1651 err = -EOPNOTSUPP;
1652 goto out;
1653 }
1654
fffd0934
JB
1655 wdev_lock(dev->ieee80211_ptr);
1656 err = nl80211_key_allowed(dev->ieee80211_ptr);
1657 if (!err)
1658 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1659
3d23e349 1660#ifdef CONFIG_CFG80211_WEXT
08645126 1661 if (!err) {
b9454e83 1662 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1663 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1664 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1665 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1666 }
1667#endif
fffd0934 1668 wdev_unlock(dev->ieee80211_ptr);
08645126 1669
41ade00f 1670 out:
79c97e97 1671 cfg80211_unlock_rdev(rdev);
41ade00f 1672 dev_put(dev);
3b85875a
JB
1673
1674 unlock_rtnl:
1675 rtnl_unlock();
1676
41ade00f
JB
1677 return err;
1678}
1679
ed1b6cc7
JB
1680static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1681{
1682 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1683 struct beacon_parameters *info);
79c97e97 1684 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1685 int err;
1686 struct net_device *dev;
1687 struct beacon_parameters params;
1688 int haveinfo = 0;
1689
f4a11bb0
JB
1690 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1691 return -EINVAL;
1692
3b85875a
JB
1693 rtnl_lock();
1694
463d0183 1695 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1696 if (err)
3b85875a 1697 goto unlock_rtnl;
ed1b6cc7 1698
074ac8df
JB
1699 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1700 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
eec60b03
JM
1701 err = -EOPNOTSUPP;
1702 goto out;
1703 }
1704
ed1b6cc7
JB
1705 switch (info->genlhdr->cmd) {
1706 case NL80211_CMD_NEW_BEACON:
1707 /* these are required for NEW_BEACON */
1708 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1709 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1710 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1711 err = -EINVAL;
1712 goto out;
1713 }
1714
79c97e97 1715 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1716 break;
1717 case NL80211_CMD_SET_BEACON:
79c97e97 1718 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1719 break;
1720 default:
1721 WARN_ON(1);
1722 err = -EOPNOTSUPP;
1723 goto out;
1724 }
1725
1726 if (!call) {
1727 err = -EOPNOTSUPP;
1728 goto out;
1729 }
1730
1731 memset(&params, 0, sizeof(params));
1732
1733 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1734 params.interval =
1735 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1736 haveinfo = 1;
1737 }
1738
1739 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1740 params.dtim_period =
1741 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1742 haveinfo = 1;
1743 }
1744
1745 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1746 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1747 params.head_len =
1748 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1749 haveinfo = 1;
1750 }
1751
1752 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1753 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1754 params.tail_len =
1755 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1756 haveinfo = 1;
1757 }
1758
1759 if (!haveinfo) {
1760 err = -EINVAL;
1761 goto out;
1762 }
1763
79c97e97 1764 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1765
1766 out:
79c97e97 1767 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1768 dev_put(dev);
3b85875a
JB
1769 unlock_rtnl:
1770 rtnl_unlock();
1771
ed1b6cc7
JB
1772 return err;
1773}
1774
1775static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1776{
79c97e97 1777 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1778 int err;
1779 struct net_device *dev;
1780
3b85875a
JB
1781 rtnl_lock();
1782
463d0183 1783 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1784 if (err)
3b85875a 1785 goto unlock_rtnl;
ed1b6cc7 1786
79c97e97 1787 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1788 err = -EOPNOTSUPP;
1789 goto out;
1790 }
1791
074ac8df
JB
1792 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1793 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
eec60b03
JM
1794 err = -EOPNOTSUPP;
1795 goto out;
1796 }
79c97e97 1797 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1798
1799 out:
79c97e97 1800 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1801 dev_put(dev);
3b85875a
JB
1802 unlock_rtnl:
1803 rtnl_unlock();
1804
ed1b6cc7
JB
1805 return err;
1806}
1807
5727ef1b
JB
1808static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1809 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1810 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1811 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1812 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1813};
1814
eccb8e8f
JB
1815static int parse_station_flags(struct genl_info *info,
1816 struct station_parameters *params)
5727ef1b
JB
1817{
1818 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1819 struct nlattr *nla;
5727ef1b
JB
1820 int flag;
1821
eccb8e8f
JB
1822 /*
1823 * Try parsing the new attribute first so userspace
1824 * can specify both for older kernels.
1825 */
1826 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1827 if (nla) {
1828 struct nl80211_sta_flag_update *sta_flags;
1829
1830 sta_flags = nla_data(nla);
1831 params->sta_flags_mask = sta_flags->mask;
1832 params->sta_flags_set = sta_flags->set;
1833 if ((params->sta_flags_mask |
1834 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1835 return -EINVAL;
1836 return 0;
1837 }
1838
1839 /* if present, parse the old attribute */
5727ef1b 1840
eccb8e8f 1841 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1842 if (!nla)
1843 return 0;
1844
1845 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1846 nla, sta_flags_policy))
1847 return -EINVAL;
1848
eccb8e8f
JB
1849 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1850 params->sta_flags_mask &= ~1;
5727ef1b
JB
1851
1852 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1853 if (flags[flag])
eccb8e8f 1854 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1855
1856 return 0;
1857}
1858
fd5b74dc
JB
1859static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1860 int flags, struct net_device *dev,
98b62183 1861 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1862{
1863 void *hdr;
420e7fab
HR
1864 struct nlattr *sinfoattr, *txrate;
1865 u16 bitrate;
fd5b74dc
JB
1866
1867 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1868 if (!hdr)
1869 return -1;
1870
1871 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1872 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1873
f5ea9120
JB
1874 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1875
2ec600d6
LCC
1876 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1877 if (!sinfoattr)
fd5b74dc 1878 goto nla_put_failure;
2ec600d6
LCC
1879 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1880 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1881 sinfo->inactive_time);
1882 if (sinfo->filled & STATION_INFO_RX_BYTES)
1883 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1884 sinfo->rx_bytes);
1885 if (sinfo->filled & STATION_INFO_TX_BYTES)
1886 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1887 sinfo->tx_bytes);
1888 if (sinfo->filled & STATION_INFO_LLID)
1889 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1890 sinfo->llid);
1891 if (sinfo->filled & STATION_INFO_PLID)
1892 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1893 sinfo->plid);
1894 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1895 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1896 sinfo->plink_state);
420e7fab
HR
1897 if (sinfo->filled & STATION_INFO_SIGNAL)
1898 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1899 sinfo->signal);
1900 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1901 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1902 if (!txrate)
1903 goto nla_put_failure;
1904
254416aa
JL
1905 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1906 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
1907 if (bitrate > 0)
1908 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1909
420e7fab
HR
1910 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1911 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1912 sinfo->txrate.mcs);
1913 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1914 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1915 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1916 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1917
1918 nla_nest_end(msg, txrate);
1919 }
98c8a60a
JM
1920 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1921 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1922 sinfo->rx_packets);
1923 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1924 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1925 sinfo->tx_packets);
2ec600d6 1926 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1927
1928 return genlmsg_end(msg, hdr);
1929
1930 nla_put_failure:
bc3ed28c
TG
1931 genlmsg_cancel(msg, hdr);
1932 return -EMSGSIZE;
fd5b74dc
JB
1933}
1934
2ec600d6 1935static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1936 struct netlink_callback *cb)
2ec600d6 1937{
2ec600d6
LCC
1938 struct station_info sinfo;
1939 struct cfg80211_registered_device *dev;
bba95fef 1940 struct net_device *netdev;
2ec600d6 1941 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1942 int ifidx = cb->args[0];
1943 int sta_idx = cb->args[1];
2ec600d6 1944 int err;
2ec600d6 1945
a043897a
HS
1946 if (!ifidx)
1947 ifidx = nl80211_get_ifidx(cb);
1948 if (ifidx < 0)
1949 return ifidx;
2ec600d6 1950
3b85875a
JB
1951 rtnl_lock();
1952
463d0183 1953 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1954 if (!netdev) {
1955 err = -ENODEV;
1956 goto out_rtnl;
1957 }
2ec600d6 1958
463d0183 1959 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1960 if (IS_ERR(dev)) {
1961 err = PTR_ERR(dev);
3b85875a 1962 goto out_rtnl;
bba95fef
JB
1963 }
1964
1965 if (!dev->ops->dump_station) {
eec60b03 1966 err = -EOPNOTSUPP;
bba95fef
JB
1967 goto out_err;
1968 }
1969
bba95fef
JB
1970 while (1) {
1971 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1972 mac_addr, &sinfo);
1973 if (err == -ENOENT)
1974 break;
1975 if (err)
3b85875a 1976 goto out_err;
bba95fef
JB
1977
1978 if (nl80211_send_station(skb,
1979 NETLINK_CB(cb->skb).pid,
1980 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1981 netdev, mac_addr,
1982 &sinfo) < 0)
1983 goto out;
1984
1985 sta_idx++;
1986 }
1987
1988
1989 out:
1990 cb->args[1] = sta_idx;
1991 err = skb->len;
bba95fef 1992 out_err:
4d0c8aea 1993 cfg80211_unlock_rdev(dev);
3b85875a
JB
1994 out_rtnl:
1995 rtnl_unlock();
bba95fef
JB
1996
1997 return err;
2ec600d6 1998}
fd5b74dc 1999
5727ef1b
JB
2000static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2001{
79c97e97 2002 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
2003 int err;
2004 struct net_device *dev;
2ec600d6 2005 struct station_info sinfo;
fd5b74dc
JB
2006 struct sk_buff *msg;
2007 u8 *mac_addr = NULL;
2008
2ec600d6 2009 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2010
2011 if (!info->attrs[NL80211_ATTR_MAC])
2012 return -EINVAL;
2013
2014 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2015
3b85875a
JB
2016 rtnl_lock();
2017
463d0183 2018 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 2019 if (err)
3b85875a 2020 goto out_rtnl;
fd5b74dc 2021
79c97e97 2022 if (!rdev->ops->get_station) {
fd5b74dc
JB
2023 err = -EOPNOTSUPP;
2024 goto out;
2025 }
2026
79c97e97 2027 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
2028 if (err)
2029 goto out;
2030
fd2120ca 2031 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
2032 if (!msg)
2033 goto out;
2034
2035 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 2036 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
2037 goto out_free;
2038
134e6375 2039 err = genlmsg_reply(msg, info);
fd5b74dc
JB
2040 goto out;
2041
2042 out_free:
2043 nlmsg_free(msg);
fd5b74dc 2044 out:
79c97e97 2045 cfg80211_unlock_rdev(rdev);
fd5b74dc 2046 dev_put(dev);
3b85875a
JB
2047 out_rtnl:
2048 rtnl_unlock();
2049
fd5b74dc 2050 return err;
5727ef1b
JB
2051}
2052
2053/*
c258d2de 2054 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2055 */
463d0183 2056static int get_vlan(struct genl_info *info,
5727ef1b
JB
2057 struct cfg80211_registered_device *rdev,
2058 struct net_device **vlan)
2059{
463d0183 2060 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2061 *vlan = NULL;
2062
2063 if (vlanattr) {
463d0183
JB
2064 *vlan = dev_get_by_index(genl_info_net(info),
2065 nla_get_u32(vlanattr));
5727ef1b
JB
2066 if (!*vlan)
2067 return -ENODEV;
2068 if (!(*vlan)->ieee80211_ptr)
2069 return -EINVAL;
2070 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2071 return -EINVAL;
c258d2de
FF
2072 if (!netif_running(*vlan))
2073 return -ENETDOWN;
5727ef1b
JB
2074 }
2075 return 0;
2076}
2077
2078static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2079{
79c97e97 2080 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2081 int err;
2082 struct net_device *dev;
2083 struct station_parameters params;
2084 u8 *mac_addr = NULL;
2085
2086 memset(&params, 0, sizeof(params));
2087
2088 params.listen_interval = -1;
2089
2090 if (info->attrs[NL80211_ATTR_STA_AID])
2091 return -EINVAL;
2092
2093 if (!info->attrs[NL80211_ATTR_MAC])
2094 return -EINVAL;
2095
2096 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2097
2098 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2099 params.supported_rates =
2100 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2101 params.supported_rates_len =
2102 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2103 }
2104
2105 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2106 params.listen_interval =
2107 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2108
36aedc90
JM
2109 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2110 params.ht_capa =
2111 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2112
eccb8e8f 2113 if (parse_station_flags(info, &params))
5727ef1b
JB
2114 return -EINVAL;
2115
2ec600d6
LCC
2116 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2117 params.plink_action =
2118 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2119
3b85875a
JB
2120 rtnl_lock();
2121
463d0183 2122 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2123 if (err)
3b85875a 2124 goto out_rtnl;
5727ef1b 2125
463d0183 2126 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2127 if (err)
034d655e 2128 goto out;
a97f4424
JB
2129
2130 /* validate settings */
2131 err = 0;
2132
2133 switch (dev->ieee80211_ptr->iftype) {
2134 case NL80211_IFTYPE_AP:
2135 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2136 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2137 /* disallow mesh-specific things */
2138 if (params.plink_action)
2139 err = -EINVAL;
2140 break;
074ac8df 2141 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2142 case NL80211_IFTYPE_STATION:
2143 /* disallow everything but AUTHORIZED flag */
2144 if (params.plink_action)
2145 err = -EINVAL;
2146 if (params.vlan)
2147 err = -EINVAL;
2148 if (params.supported_rates)
2149 err = -EINVAL;
2150 if (params.ht_capa)
2151 err = -EINVAL;
2152 if (params.listen_interval >= 0)
2153 err = -EINVAL;
2154 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2155 err = -EINVAL;
2156 break;
2157 case NL80211_IFTYPE_MESH_POINT:
2158 /* disallow things mesh doesn't support */
2159 if (params.vlan)
2160 err = -EINVAL;
2161 if (params.ht_capa)
2162 err = -EINVAL;
2163 if (params.listen_interval >= 0)
2164 err = -EINVAL;
2165 if (params.supported_rates)
2166 err = -EINVAL;
2167 if (params.sta_flags_mask)
2168 err = -EINVAL;
2169 break;
2170 default:
2171 err = -EINVAL;
034d655e
JB
2172 }
2173
5727ef1b
JB
2174 if (err)
2175 goto out;
2176
79c97e97 2177 if (!rdev->ops->change_station) {
5727ef1b
JB
2178 err = -EOPNOTSUPP;
2179 goto out;
2180 }
2181
79c97e97 2182 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2183
2184 out:
2185 if (params.vlan)
2186 dev_put(params.vlan);
79c97e97 2187 cfg80211_unlock_rdev(rdev);
5727ef1b 2188 dev_put(dev);
3b85875a
JB
2189 out_rtnl:
2190 rtnl_unlock();
2191
5727ef1b
JB
2192 return err;
2193}
2194
2195static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2196{
79c97e97 2197 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2198 int err;
2199 struct net_device *dev;
2200 struct station_parameters params;
2201 u8 *mac_addr = NULL;
2202
2203 memset(&params, 0, sizeof(params));
2204
2205 if (!info->attrs[NL80211_ATTR_MAC])
2206 return -EINVAL;
2207
5727ef1b
JB
2208 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2209 return -EINVAL;
2210
2211 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2212 return -EINVAL;
2213
0e956c13
TLSC
2214 if (!info->attrs[NL80211_ATTR_STA_AID])
2215 return -EINVAL;
2216
5727ef1b
JB
2217 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2218 params.supported_rates =
2219 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2220 params.supported_rates_len =
2221 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2222 params.listen_interval =
2223 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2224
0e956c13
TLSC
2225 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2226 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2227 return -EINVAL;
51b50fbe 2228
36aedc90
JM
2229 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2230 params.ht_capa =
2231 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2232
eccb8e8f 2233 if (parse_station_flags(info, &params))
5727ef1b
JB
2234 return -EINVAL;
2235
3b85875a
JB
2236 rtnl_lock();
2237
463d0183 2238 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2239 if (err)
3b85875a 2240 goto out_rtnl;
5727ef1b 2241
0e956c13 2242 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df
JB
2243 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2244 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
0e956c13
TLSC
2245 err = -EINVAL;
2246 goto out;
2247 }
2248
463d0183 2249 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2250 if (err)
e80cf853 2251 goto out;
a97f4424
JB
2252
2253 /* validate settings */
2254 err = 0;
2255
79c97e97 2256 if (!rdev->ops->add_station) {
5727ef1b
JB
2257 err = -EOPNOTSUPP;
2258 goto out;
2259 }
2260
35a8efe1
JM
2261 if (!netif_running(dev)) {
2262 err = -ENETDOWN;
2263 goto out;
2264 }
2265
79c97e97 2266 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2267
2268 out:
2269 if (params.vlan)
2270 dev_put(params.vlan);
79c97e97 2271 cfg80211_unlock_rdev(rdev);
5727ef1b 2272 dev_put(dev);
3b85875a
JB
2273 out_rtnl:
2274 rtnl_unlock();
2275
5727ef1b
JB
2276 return err;
2277}
2278
2279static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2280{
79c97e97 2281 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2282 int err;
2283 struct net_device *dev;
2284 u8 *mac_addr = NULL;
2285
2286 if (info->attrs[NL80211_ATTR_MAC])
2287 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2288
3b85875a
JB
2289 rtnl_lock();
2290
463d0183 2291 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2292 if (err)
3b85875a 2293 goto out_rtnl;
5727ef1b 2294
e80cf853 2295 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2296 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df
JB
2297 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2298 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
e80cf853
JB
2299 err = -EINVAL;
2300 goto out;
2301 }
2302
79c97e97 2303 if (!rdev->ops->del_station) {
5727ef1b
JB
2304 err = -EOPNOTSUPP;
2305 goto out;
2306 }
2307
79c97e97 2308 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2309
2310 out:
79c97e97 2311 cfg80211_unlock_rdev(rdev);
5727ef1b 2312 dev_put(dev);
3b85875a
JB
2313 out_rtnl:
2314 rtnl_unlock();
2315
5727ef1b
JB
2316 return err;
2317}
2318
2ec600d6
LCC
2319static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2320 int flags, struct net_device *dev,
2321 u8 *dst, u8 *next_hop,
2322 struct mpath_info *pinfo)
2323{
2324 void *hdr;
2325 struct nlattr *pinfoattr;
2326
2327 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2328 if (!hdr)
2329 return -1;
2330
2331 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2332 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2333 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2334
f5ea9120
JB
2335 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2336
2ec600d6
LCC
2337 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2338 if (!pinfoattr)
2339 goto nla_put_failure;
2340 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2341 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2342 pinfo->frame_qlen);
d19b3bf6
RP
2343 if (pinfo->filled & MPATH_INFO_SN)
2344 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2345 pinfo->sn);
2ec600d6
LCC
2346 if (pinfo->filled & MPATH_INFO_METRIC)
2347 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2348 pinfo->metric);
2349 if (pinfo->filled & MPATH_INFO_EXPTIME)
2350 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2351 pinfo->exptime);
2352 if (pinfo->filled & MPATH_INFO_FLAGS)
2353 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2354 pinfo->flags);
2355 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2356 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2357 pinfo->discovery_timeout);
2358 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2359 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2360 pinfo->discovery_retries);
2361
2362 nla_nest_end(msg, pinfoattr);
2363
2364 return genlmsg_end(msg, hdr);
2365
2366 nla_put_failure:
bc3ed28c
TG
2367 genlmsg_cancel(msg, hdr);
2368 return -EMSGSIZE;
2ec600d6
LCC
2369}
2370
2371static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2372 struct netlink_callback *cb)
2ec600d6 2373{
2ec600d6
LCC
2374 struct mpath_info pinfo;
2375 struct cfg80211_registered_device *dev;
bba95fef 2376 struct net_device *netdev;
2ec600d6
LCC
2377 u8 dst[ETH_ALEN];
2378 u8 next_hop[ETH_ALEN];
bba95fef
JB
2379 int ifidx = cb->args[0];
2380 int path_idx = cb->args[1];
2ec600d6 2381 int err;
2ec600d6 2382
a043897a
HS
2383 if (!ifidx)
2384 ifidx = nl80211_get_ifidx(cb);
2385 if (ifidx < 0)
2386 return ifidx;
bba95fef 2387
3b85875a
JB
2388 rtnl_lock();
2389
463d0183 2390 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2391 if (!netdev) {
2392 err = -ENODEV;
2393 goto out_rtnl;
2394 }
bba95fef 2395
463d0183 2396 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2397 if (IS_ERR(dev)) {
2398 err = PTR_ERR(dev);
3b85875a 2399 goto out_rtnl;
bba95fef
JB
2400 }
2401
2402 if (!dev->ops->dump_mpath) {
eec60b03 2403 err = -EOPNOTSUPP;
bba95fef
JB
2404 goto out_err;
2405 }
2406
eec60b03
JM
2407 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2408 err = -EOPNOTSUPP;
0448b5fc 2409 goto out_err;
eec60b03
JM
2410 }
2411
bba95fef
JB
2412 while (1) {
2413 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2414 dst, next_hop, &pinfo);
2415 if (err == -ENOENT)
2ec600d6 2416 break;
bba95fef 2417 if (err)
3b85875a 2418 goto out_err;
2ec600d6 2419
bba95fef
JB
2420 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2421 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2422 netdev, dst, next_hop,
2423 &pinfo) < 0)
2424 goto out;
2ec600d6 2425
bba95fef 2426 path_idx++;
2ec600d6 2427 }
2ec600d6 2428
2ec600d6 2429
bba95fef
JB
2430 out:
2431 cb->args[1] = path_idx;
2432 err = skb->len;
bba95fef 2433 out_err:
4d0c8aea 2434 cfg80211_unlock_rdev(dev);
3b85875a
JB
2435 out_rtnl:
2436 rtnl_unlock();
bba95fef
JB
2437
2438 return err;
2ec600d6
LCC
2439}
2440
2441static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2442{
79c97e97 2443 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2444 int err;
2445 struct net_device *dev;
2446 struct mpath_info pinfo;
2447 struct sk_buff *msg;
2448 u8 *dst = NULL;
2449 u8 next_hop[ETH_ALEN];
2450
2451 memset(&pinfo, 0, sizeof(pinfo));
2452
2453 if (!info->attrs[NL80211_ATTR_MAC])
2454 return -EINVAL;
2455
2456 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2457
3b85875a
JB
2458 rtnl_lock();
2459
463d0183 2460 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2461 if (err)
3b85875a 2462 goto out_rtnl;
2ec600d6 2463
79c97e97 2464 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2465 err = -EOPNOTSUPP;
2466 goto out;
2467 }
2468
eec60b03
JM
2469 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2470 err = -EOPNOTSUPP;
2471 goto out;
2472 }
2473
79c97e97 2474 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2475 if (err)
2476 goto out;
2477
fd2120ca 2478 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2479 if (!msg)
2480 goto out;
2481
2482 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2483 dev, dst, next_hop, &pinfo) < 0)
2484 goto out_free;
2485
134e6375 2486 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2487 goto out;
2488
2489 out_free:
2490 nlmsg_free(msg);
2ec600d6 2491 out:
79c97e97 2492 cfg80211_unlock_rdev(rdev);
2ec600d6 2493 dev_put(dev);
3b85875a
JB
2494 out_rtnl:
2495 rtnl_unlock();
2496
2ec600d6
LCC
2497 return err;
2498}
2499
2500static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2501{
79c97e97 2502 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2503 int err;
2504 struct net_device *dev;
2505 u8 *dst = NULL;
2506 u8 *next_hop = NULL;
2507
2508 if (!info->attrs[NL80211_ATTR_MAC])
2509 return -EINVAL;
2510
2511 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2512 return -EINVAL;
2513
2514 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2515 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2516
3b85875a
JB
2517 rtnl_lock();
2518
463d0183 2519 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2520 if (err)
3b85875a 2521 goto out_rtnl;
2ec600d6 2522
79c97e97 2523 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2524 err = -EOPNOTSUPP;
2525 goto out;
2526 }
2527
eec60b03
JM
2528 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2529 err = -EOPNOTSUPP;
2530 goto out;
2531 }
2532
35a8efe1
JM
2533 if (!netif_running(dev)) {
2534 err = -ENETDOWN;
2535 goto out;
2536 }
2537
79c97e97 2538 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2539
2540 out:
79c97e97 2541 cfg80211_unlock_rdev(rdev);
2ec600d6 2542 dev_put(dev);
3b85875a
JB
2543 out_rtnl:
2544 rtnl_unlock();
2545
2ec600d6
LCC
2546 return err;
2547}
2548static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2549{
79c97e97 2550 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2551 int err;
2552 struct net_device *dev;
2553 u8 *dst = NULL;
2554 u8 *next_hop = NULL;
2555
2556 if (!info->attrs[NL80211_ATTR_MAC])
2557 return -EINVAL;
2558
2559 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2560 return -EINVAL;
2561
2562 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2563 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2564
3b85875a
JB
2565 rtnl_lock();
2566
463d0183 2567 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2568 if (err)
3b85875a 2569 goto out_rtnl;
2ec600d6 2570
79c97e97 2571 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2572 err = -EOPNOTSUPP;
2573 goto out;
2574 }
2575
eec60b03
JM
2576 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2577 err = -EOPNOTSUPP;
2578 goto out;
2579 }
2580
35a8efe1
JM
2581 if (!netif_running(dev)) {
2582 err = -ENETDOWN;
2583 goto out;
2584 }
2585
79c97e97 2586 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2587
2588 out:
79c97e97 2589 cfg80211_unlock_rdev(rdev);
2ec600d6 2590 dev_put(dev);
3b85875a
JB
2591 out_rtnl:
2592 rtnl_unlock();
2593
2ec600d6
LCC
2594 return err;
2595}
2596
2597static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2598{
79c97e97 2599 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2600 int err;
2601 struct net_device *dev;
2602 u8 *dst = NULL;
2603
2604 if (info->attrs[NL80211_ATTR_MAC])
2605 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2606
3b85875a
JB
2607 rtnl_lock();
2608
463d0183 2609 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2610 if (err)
3b85875a 2611 goto out_rtnl;
2ec600d6 2612
79c97e97 2613 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2614 err = -EOPNOTSUPP;
2615 goto out;
2616 }
2617
79c97e97 2618 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2619
2620 out:
79c97e97 2621 cfg80211_unlock_rdev(rdev);
2ec600d6 2622 dev_put(dev);
3b85875a
JB
2623 out_rtnl:
2624 rtnl_unlock();
2625
2ec600d6
LCC
2626 return err;
2627}
2628
9f1ba906
JM
2629static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2630{
79c97e97 2631 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2632 int err;
2633 struct net_device *dev;
2634 struct bss_parameters params;
2635
2636 memset(&params, 0, sizeof(params));
2637 /* default to not changing parameters */
2638 params.use_cts_prot = -1;
2639 params.use_short_preamble = -1;
2640 params.use_short_slot_time = -1;
fd8aaaf3 2641 params.ap_isolate = -1;
9f1ba906
JM
2642
2643 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2644 params.use_cts_prot =
2645 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2646 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2647 params.use_short_preamble =
2648 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2649 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2650 params.use_short_slot_time =
2651 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2652 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2653 params.basic_rates =
2654 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2655 params.basic_rates_len =
2656 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2657 }
fd8aaaf3
FF
2658 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2659 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
9f1ba906 2660
3b85875a
JB
2661 rtnl_lock();
2662
463d0183 2663 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2664 if (err)
3b85875a 2665 goto out_rtnl;
9f1ba906 2666
79c97e97 2667 if (!rdev->ops->change_bss) {
9f1ba906
JM
2668 err = -EOPNOTSUPP;
2669 goto out;
2670 }
2671
074ac8df
JB
2672 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2673 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
eec60b03
JM
2674 err = -EOPNOTSUPP;
2675 goto out;
2676 }
2677
79c97e97 2678 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2679
2680 out:
79c97e97 2681 cfg80211_unlock_rdev(rdev);
9f1ba906 2682 dev_put(dev);
3b85875a
JB
2683 out_rtnl:
2684 rtnl_unlock();
2685
9f1ba906
JM
2686 return err;
2687}
2688
b54452b0 2689static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2690 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2691 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2692 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2693 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2694 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2695 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2696};
2697
2698static int parse_reg_rule(struct nlattr *tb[],
2699 struct ieee80211_reg_rule *reg_rule)
2700{
2701 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2702 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2703
2704 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2705 return -EINVAL;
2706 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2707 return -EINVAL;
2708 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2709 return -EINVAL;
2710 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2711 return -EINVAL;
2712 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2713 return -EINVAL;
2714
2715 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2716
2717 freq_range->start_freq_khz =
2718 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2719 freq_range->end_freq_khz =
2720 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2721 freq_range->max_bandwidth_khz =
2722 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2723
2724 power_rule->max_eirp =
2725 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2726
2727 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2728 power_rule->max_antenna_gain =
2729 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2730
2731 return 0;
2732}
2733
2734static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2735{
2736 int r;
2737 char *data = NULL;
2738
80778f18
LR
2739 /*
2740 * You should only get this when cfg80211 hasn't yet initialized
2741 * completely when built-in to the kernel right between the time
2742 * window between nl80211_init() and regulatory_init(), if that is
2743 * even possible.
2744 */
2745 mutex_lock(&cfg80211_mutex);
2746 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2747 mutex_unlock(&cfg80211_mutex);
2748 return -EINPROGRESS;
80778f18 2749 }
fe33eb39 2750 mutex_unlock(&cfg80211_mutex);
80778f18 2751
fe33eb39
LR
2752 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2753 return -EINVAL;
b2e1b302
LR
2754
2755 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2756
fe33eb39
LR
2757 r = regulatory_hint_user(data);
2758
b2e1b302
LR
2759 return r;
2760}
2761
93da9cc1 2762static int nl80211_get_mesh_params(struct sk_buff *skb,
2763 struct genl_info *info)
2764{
79c97e97 2765 struct cfg80211_registered_device *rdev;
93da9cc1 2766 struct mesh_config cur_params;
2767 int err;
2768 struct net_device *dev;
2769 void *hdr;
2770 struct nlattr *pinfoattr;
2771 struct sk_buff *msg;
2772
3b85875a
JB
2773 rtnl_lock();
2774
93da9cc1 2775 /* Look up our device */
463d0183 2776 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2777 if (err)
3b85875a 2778 goto out_rtnl;
93da9cc1 2779
79c97e97 2780 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2781 err = -EOPNOTSUPP;
2782 goto out;
2783 }
2784
93da9cc1 2785 /* Get the mesh params */
79c97e97 2786 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2787 if (err)
2788 goto out;
2789
2790 /* Draw up a netlink message to send back */
fd2120ca 2791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2792 if (!msg) {
2793 err = -ENOBUFS;
2794 goto out;
2795 }
2796 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2797 NL80211_CMD_GET_MESH_PARAMS);
2798 if (!hdr)
2799 goto nla_put_failure;
2800 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2801 if (!pinfoattr)
2802 goto nla_put_failure;
2803 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2804 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2805 cur_params.dot11MeshRetryTimeout);
2806 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2807 cur_params.dot11MeshConfirmTimeout);
2808 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2809 cur_params.dot11MeshHoldingTimeout);
2810 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2811 cur_params.dot11MeshMaxPeerLinks);
2812 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2813 cur_params.dot11MeshMaxRetries);
2814 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2815 cur_params.dot11MeshTTL);
2816 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2817 cur_params.auto_open_plinks);
2818 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2819 cur_params.dot11MeshHWMPmaxPREQretries);
2820 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2821 cur_params.path_refresh_time);
2822 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2823 cur_params.min_discovery_timeout);
2824 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2825 cur_params.dot11MeshHWMPactivePathTimeout);
2826 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2827 cur_params.dot11MeshHWMPpreqMinInterval);
2828 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2829 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2830 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2831 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2832 nla_nest_end(msg, pinfoattr);
2833 genlmsg_end(msg, hdr);
134e6375 2834 err = genlmsg_reply(msg, info);
93da9cc1 2835 goto out;
2836
3b85875a 2837 nla_put_failure:
93da9cc1 2838 genlmsg_cancel(msg, hdr);
d080e275 2839 nlmsg_free(msg);
93da9cc1 2840 err = -EMSGSIZE;
3b85875a 2841 out:
93da9cc1 2842 /* Cleanup */
79c97e97 2843 cfg80211_unlock_rdev(rdev);
93da9cc1 2844 dev_put(dev);
3b85875a
JB
2845 out_rtnl:
2846 rtnl_unlock();
2847
93da9cc1 2848 return err;
2849}
2850
2851#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2852do {\
2853 if (table[attr_num]) {\
2854 cfg.param = nla_fn(table[attr_num]); \
2855 mask |= (1 << (attr_num - 1)); \
2856 } \
2857} while (0);\
2858
b54452b0 2859static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2860 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2861 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2862 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2863 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2864 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2865 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2866 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2867
2868 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2869 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2870 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2871 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2872 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2873 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2874};
2875
2876static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2877{
2878 int err;
2879 u32 mask;
79c97e97 2880 struct cfg80211_registered_device *rdev;
93da9cc1 2881 struct net_device *dev;
2882 struct mesh_config cfg;
2883 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2884 struct nlattr *parent_attr;
2885
2886 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2887 if (!parent_attr)
2888 return -EINVAL;
2889 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2890 parent_attr, nl80211_meshconf_params_policy))
2891 return -EINVAL;
2892
3b85875a
JB
2893 rtnl_lock();
2894
463d0183 2895 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2896 if (err)
3b85875a 2897 goto out_rtnl;
93da9cc1 2898
79c97e97 2899 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2900 err = -EOPNOTSUPP;
2901 goto out;
2902 }
2903
93da9cc1 2904 /* This makes sure that there aren't more than 32 mesh config
2905 * parameters (otherwise our bitfield scheme would not work.) */
2906 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2907
2908 /* Fill in the params struct */
2909 mask = 0;
2910 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2911 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2912 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2913 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2914 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2915 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2916 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2917 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2918 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2919 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2920 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2921 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2922 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2923 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2924 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2925 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2926 nla_get_u8);
2927 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2928 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2929 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2930 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2931 nla_get_u16);
2932 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2933 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2934 nla_get_u32);
2935 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2936 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2937 nla_get_u16);
2938 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2939 dot11MeshHWMPnetDiameterTraversalTime,
2940 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2941 nla_get_u16);
63c5723b
RP
2942 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2943 dot11MeshHWMPRootMode, mask,
2944 NL80211_MESHCONF_HWMP_ROOTMODE,
2945 nla_get_u8);
93da9cc1 2946
2947 /* Apply changes */
79c97e97 2948 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2949
f3f92586 2950 out:
93da9cc1 2951 /* cleanup */
79c97e97 2952 cfg80211_unlock_rdev(rdev);
93da9cc1 2953 dev_put(dev);
3b85875a
JB
2954 out_rtnl:
2955 rtnl_unlock();
2956
93da9cc1 2957 return err;
2958}
2959
2960#undef FILL_IN_MESH_PARAM_IF_SET
2961
f130347c
LR
2962static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2963{
2964 struct sk_buff *msg;
2965 void *hdr = NULL;
2966 struct nlattr *nl_reg_rules;
2967 unsigned int i;
2968 int err = -EINVAL;
2969
a1794390 2970 mutex_lock(&cfg80211_mutex);
f130347c
LR
2971
2972 if (!cfg80211_regdomain)
2973 goto out;
2974
fd2120ca 2975 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2976 if (!msg) {
2977 err = -ENOBUFS;
2978 goto out;
2979 }
2980
2981 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2982 NL80211_CMD_GET_REG);
2983 if (!hdr)
2984 goto nla_put_failure;
2985
2986 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2987 cfg80211_regdomain->alpha2);
2988
2989 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2990 if (!nl_reg_rules)
2991 goto nla_put_failure;
2992
2993 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2994 struct nlattr *nl_reg_rule;
2995 const struct ieee80211_reg_rule *reg_rule;
2996 const struct ieee80211_freq_range *freq_range;
2997 const struct ieee80211_power_rule *power_rule;
2998
2999 reg_rule = &cfg80211_regdomain->reg_rules[i];
3000 freq_range = &reg_rule->freq_range;
3001 power_rule = &reg_rule->power_rule;
3002
3003 nl_reg_rule = nla_nest_start(msg, i);
3004 if (!nl_reg_rule)
3005 goto nla_put_failure;
3006
3007 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3008 reg_rule->flags);
3009 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3010 freq_range->start_freq_khz);
3011 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3012 freq_range->end_freq_khz);
3013 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3014 freq_range->max_bandwidth_khz);
3015 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3016 power_rule->max_antenna_gain);
3017 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3018 power_rule->max_eirp);
3019
3020 nla_nest_end(msg, nl_reg_rule);
3021 }
3022
3023 nla_nest_end(msg, nl_reg_rules);
3024
3025 genlmsg_end(msg, hdr);
134e6375 3026 err = genlmsg_reply(msg, info);
f130347c
LR
3027 goto out;
3028
3029nla_put_failure:
3030 genlmsg_cancel(msg, hdr);
d080e275 3031 nlmsg_free(msg);
f130347c
LR
3032 err = -EMSGSIZE;
3033out:
a1794390 3034 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3035 return err;
3036}
3037
b2e1b302
LR
3038static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3039{
3040 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3041 struct nlattr *nl_reg_rule;
3042 char *alpha2 = NULL;
3043 int rem_reg_rules = 0, r = 0;
3044 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3045 struct ieee80211_regdomain *rd = NULL;
3046
3047 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3048 return -EINVAL;
3049
3050 if (!info->attrs[NL80211_ATTR_REG_RULES])
3051 return -EINVAL;
3052
3053 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3054
3055 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3056 rem_reg_rules) {
3057 num_rules++;
3058 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3059 return -EINVAL;
b2e1b302
LR
3060 }
3061
61405e97
LR
3062 mutex_lock(&cfg80211_mutex);
3063
d0e18f83
LR
3064 if (!reg_is_valid_request(alpha2)) {
3065 r = -EINVAL;
3066 goto bad_reg;
3067 }
b2e1b302
LR
3068
3069 size_of_regd = sizeof(struct ieee80211_regdomain) +
3070 (num_rules * sizeof(struct ieee80211_reg_rule));
3071
3072 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3073 if (!rd) {
3074 r = -ENOMEM;
3075 goto bad_reg;
3076 }
b2e1b302
LR
3077
3078 rd->n_reg_rules = num_rules;
3079 rd->alpha2[0] = alpha2[0];
3080 rd->alpha2[1] = alpha2[1];
3081
3082 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3083 rem_reg_rules) {
3084 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3085 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3086 reg_rule_policy);
3087 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3088 if (r)
3089 goto bad_reg;
3090
3091 rule_idx++;
3092
d0e18f83
LR
3093 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3094 r = -EINVAL;
b2e1b302 3095 goto bad_reg;
d0e18f83 3096 }
b2e1b302
LR
3097 }
3098
3099 BUG_ON(rule_idx != num_rules);
3100
b2e1b302 3101 r = set_regdom(rd);
61405e97 3102
a1794390 3103 mutex_unlock(&cfg80211_mutex);
d0e18f83 3104
b2e1b302
LR
3105 return r;
3106
d2372b31 3107 bad_reg:
61405e97 3108 mutex_unlock(&cfg80211_mutex);
b2e1b302 3109 kfree(rd);
d0e18f83 3110 return r;
b2e1b302
LR
3111}
3112
83f5e2cf
JB
3113static int validate_scan_freqs(struct nlattr *freqs)
3114{
3115 struct nlattr *attr1, *attr2;
3116 int n_channels = 0, tmp1, tmp2;
3117
3118 nla_for_each_nested(attr1, freqs, tmp1) {
3119 n_channels++;
3120 /*
3121 * Some hardware has a limited channel list for
3122 * scanning, and it is pretty much nonsensical
3123 * to scan for a channel twice, so disallow that
3124 * and don't require drivers to check that the
3125 * channel list they get isn't longer than what
3126 * they can scan, as long as they can scan all
3127 * the channels they registered at once.
3128 */
3129 nla_for_each_nested(attr2, freqs, tmp2)
3130 if (attr1 != attr2 &&
3131 nla_get_u32(attr1) == nla_get_u32(attr2))
3132 return 0;
3133 }
3134
3135 return n_channels;
3136}
3137
2a519311
JB
3138static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3139{
79c97e97 3140 struct cfg80211_registered_device *rdev;
2a519311
JB
3141 struct net_device *dev;
3142 struct cfg80211_scan_request *request;
3143 struct cfg80211_ssid *ssid;
3144 struct ieee80211_channel *channel;
3145 struct nlattr *attr;
3146 struct wiphy *wiphy;
83f5e2cf 3147 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3148 enum ieee80211_band band;
70692ad2 3149 size_t ie_len;
2a519311 3150
f4a11bb0
JB
3151 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3152 return -EINVAL;
3153
3b85875a
JB
3154 rtnl_lock();
3155
463d0183 3156 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 3157 if (err)
3b85875a 3158 goto out_rtnl;
2a519311 3159
79c97e97 3160 wiphy = &rdev->wiphy;
2a519311 3161
79c97e97 3162 if (!rdev->ops->scan) {
2a519311
JB
3163 err = -EOPNOTSUPP;
3164 goto out;
3165 }
3166
35a8efe1
JM
3167 if (!netif_running(dev)) {
3168 err = -ENETDOWN;
3169 goto out;
3170 }
3171
79c97e97 3172 if (rdev->scan_req) {
2a519311 3173 err = -EBUSY;
3b85875a 3174 goto out;
2a519311
JB
3175 }
3176
3177 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3178 n_channels = validate_scan_freqs(
3179 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
3180 if (!n_channels) {
3181 err = -EINVAL;
3b85875a 3182 goto out;
2a519311
JB
3183 }
3184 } else {
83f5e2cf
JB
3185 n_channels = 0;
3186
2a519311
JB
3187 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3188 if (wiphy->bands[band])
3189 n_channels += wiphy->bands[band]->n_channels;
3190 }
3191
3192 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3193 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3194 n_ssids++;
3195
3196 if (n_ssids > wiphy->max_scan_ssids) {
3197 err = -EINVAL;
3b85875a 3198 goto out;
2a519311
JB
3199 }
3200
70692ad2
JM
3201 if (info->attrs[NL80211_ATTR_IE])
3202 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3203 else
3204 ie_len = 0;
3205
18a83659
JB
3206 if (ie_len > wiphy->max_scan_ie_len) {
3207 err = -EINVAL;
3208 goto out;
3209 }
3210
2a519311
JB
3211 request = kzalloc(sizeof(*request)
3212 + sizeof(*ssid) * n_ssids
70692ad2
JM
3213 + sizeof(channel) * n_channels
3214 + ie_len, GFP_KERNEL);
2a519311
JB
3215 if (!request) {
3216 err = -ENOMEM;
3b85875a 3217 goto out;
2a519311
JB
3218 }
3219
2a519311 3220 if (n_ssids)
5ba63533 3221 request->ssids = (void *)&request->channels[n_channels];
2a519311 3222 request->n_ssids = n_ssids;
70692ad2
JM
3223 if (ie_len) {
3224 if (request->ssids)
3225 request->ie = (void *)(request->ssids + n_ssids);
3226 else
3227 request->ie = (void *)(request->channels + n_channels);
3228 }
2a519311 3229
584991dc 3230 i = 0;
2a519311
JB
3231 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3232 /* user specified, bail out if channel not found */
2a519311 3233 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3234 struct ieee80211_channel *chan;
3235
3236 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3237
3238 if (!chan) {
2a519311
JB
3239 err = -EINVAL;
3240 goto out_free;
3241 }
584991dc
JB
3242
3243 /* ignore disabled channels */
3244 if (chan->flags & IEEE80211_CHAN_DISABLED)
3245 continue;
3246
3247 request->channels[i] = chan;
2a519311
JB
3248 i++;
3249 }
3250 } else {
3251 /* all channels */
2a519311
JB
3252 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3253 int j;
3254 if (!wiphy->bands[band])
3255 continue;
3256 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3257 struct ieee80211_channel *chan;
3258
3259 chan = &wiphy->bands[band]->channels[j];
3260
3261 if (chan->flags & IEEE80211_CHAN_DISABLED)
3262 continue;
3263
3264 request->channels[i] = chan;
2a519311
JB
3265 i++;
3266 }
3267 }
3268 }
3269
584991dc
JB
3270 if (!i) {
3271 err = -EINVAL;
3272 goto out_free;
3273 }
3274
3275 request->n_channels = i;
3276
2a519311
JB
3277 i = 0;
3278 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3279 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3280 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3281 err = -EINVAL;
3282 goto out_free;
3283 }
3284 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3285 request->ssids[i].ssid_len = nla_len(attr);
3286 i++;
3287 }
3288 }
3289
70692ad2
JM
3290 if (info->attrs[NL80211_ATTR_IE]) {
3291 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3292 memcpy((void *)request->ie,
3293 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3294 request->ie_len);
3295 }
3296
463d0183 3297 request->dev = dev;
79c97e97 3298 request->wiphy = &rdev->wiphy;
2a519311 3299
79c97e97
JB
3300 rdev->scan_req = request;
3301 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3302
463d0183 3303 if (!err) {
79c97e97 3304 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3305 dev_hold(dev);
3306 }
a538e2d5 3307
2a519311
JB
3308 out_free:
3309 if (err) {
79c97e97 3310 rdev->scan_req = NULL;
2a519311
JB
3311 kfree(request);
3312 }
2a519311 3313 out:
79c97e97 3314 cfg80211_unlock_rdev(rdev);
2a519311 3315 dev_put(dev);
3b85875a
JB
3316 out_rtnl:
3317 rtnl_unlock();
3318
2a519311
JB
3319 return err;
3320}
3321
3322static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3323 struct cfg80211_registered_device *rdev,
48ab905d
JB
3324 struct wireless_dev *wdev,
3325 struct cfg80211_internal_bss *intbss)
2a519311 3326{
48ab905d 3327 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3328 void *hdr;
3329 struct nlattr *bss;
48ab905d
JB
3330 int i;
3331
3332 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3333
3334 hdr = nl80211hdr_put(msg, pid, seq, flags,
3335 NL80211_CMD_NEW_SCAN_RESULTS);
3336 if (!hdr)
3337 return -1;
3338
f5ea9120 3339 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3340 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3341
3342 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3343 if (!bss)
3344 goto nla_put_failure;
3345 if (!is_zero_ether_addr(res->bssid))
3346 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3347 if (res->information_elements && res->len_information_elements)
3348 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3349 res->len_information_elements,
3350 res->information_elements);
34a6eddb
JM
3351 if (res->beacon_ies && res->len_beacon_ies &&
3352 res->beacon_ies != res->information_elements)
3353 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3354 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3355 if (res->tsf)
3356 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3357 if (res->beacon_interval)
3358 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3359 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3360 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3361 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3362 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3363
77965c97 3364 switch (rdev->wiphy.signal_type) {
2a519311
JB
3365 case CFG80211_SIGNAL_TYPE_MBM:
3366 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3367 break;
3368 case CFG80211_SIGNAL_TYPE_UNSPEC:
3369 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3370 break;
3371 default:
3372 break;
3373 }
3374
48ab905d 3375 switch (wdev->iftype) {
074ac8df 3376 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3377 case NL80211_IFTYPE_STATION:
3378 if (intbss == wdev->current_bss)
3379 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3380 NL80211_BSS_STATUS_ASSOCIATED);
3381 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3382 if (intbss != wdev->auth_bsses[i])
3383 continue;
3384 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3385 NL80211_BSS_STATUS_AUTHENTICATED);
3386 break;
3387 }
3388 break;
3389 case NL80211_IFTYPE_ADHOC:
3390 if (intbss == wdev->current_bss)
3391 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3392 NL80211_BSS_STATUS_IBSS_JOINED);
3393 break;
3394 default:
3395 break;
3396 }
3397
2a519311
JB
3398 nla_nest_end(msg, bss);
3399
3400 return genlmsg_end(msg, hdr);
3401
3402 nla_put_failure:
3403 genlmsg_cancel(msg, hdr);
3404 return -EMSGSIZE;
3405}
3406
3407static int nl80211_dump_scan(struct sk_buff *skb,
3408 struct netlink_callback *cb)
3409{
48ab905d
JB
3410 struct cfg80211_registered_device *rdev;
3411 struct net_device *dev;
2a519311 3412 struct cfg80211_internal_bss *scan;
48ab905d 3413 struct wireless_dev *wdev;
2a519311
JB
3414 int ifidx = cb->args[0];
3415 int start = cb->args[1], idx = 0;
3416 int err;
3417
a043897a
HS
3418 if (!ifidx)
3419 ifidx = nl80211_get_ifidx(cb);
3420 if (ifidx < 0)
3421 return ifidx;
3422 cb->args[0] = ifidx;
2a519311 3423
463d0183 3424 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3425 if (!dev)
2a519311
JB
3426 return -ENODEV;
3427
463d0183 3428 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3429 if (IS_ERR(rdev)) {
3430 err = PTR_ERR(rdev);
2a519311
JB
3431 goto out_put_netdev;
3432 }
3433
48ab905d 3434 wdev = dev->ieee80211_ptr;
2a519311 3435
48ab905d
JB
3436 wdev_lock(wdev);
3437 spin_lock_bh(&rdev->bss_lock);
3438 cfg80211_bss_expire(rdev);
3439
3440 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3441 if (++idx <= start)
3442 continue;
3443 if (nl80211_send_bss(skb,
3444 NETLINK_CB(cb->skb).pid,
3445 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3446 rdev, wdev, scan) < 0) {
2a519311
JB
3447 idx--;
3448 goto out;
3449 }
3450 }
3451
3452 out:
48ab905d
JB
3453 spin_unlock_bh(&rdev->bss_lock);
3454 wdev_unlock(wdev);
2a519311
JB
3455
3456 cb->args[1] = idx;
3457 err = skb->len;
48ab905d 3458 cfg80211_unlock_rdev(rdev);
2a519311 3459 out_put_netdev:
48ab905d 3460 dev_put(dev);
2a519311
JB
3461
3462 return err;
3463}
3464
61fa713c
HS
3465static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3466 int flags, struct net_device *dev,
3467 struct survey_info *survey)
3468{
3469 void *hdr;
3470 struct nlattr *infoattr;
3471
3472 /* Survey without a channel doesn't make sense */
3473 if (!survey->channel)
3474 return -EINVAL;
3475
3476 hdr = nl80211hdr_put(msg, pid, seq, flags,
3477 NL80211_CMD_NEW_SURVEY_RESULTS);
3478 if (!hdr)
3479 return -ENOMEM;
3480
3481 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3482
3483 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3484 if (!infoattr)
3485 goto nla_put_failure;
3486
3487 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3488 survey->channel->center_freq);
3489 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3490 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3491 survey->noise);
17e5a808
FF
3492 if (survey->filled & SURVEY_INFO_IN_USE)
3493 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
61fa713c
HS
3494
3495 nla_nest_end(msg, infoattr);
3496
3497 return genlmsg_end(msg, hdr);
3498
3499 nla_put_failure:
3500 genlmsg_cancel(msg, hdr);
3501 return -EMSGSIZE;
3502}
3503
3504static int nl80211_dump_survey(struct sk_buff *skb,
3505 struct netlink_callback *cb)
3506{
3507 struct survey_info survey;
3508 struct cfg80211_registered_device *dev;
3509 struct net_device *netdev;
3510 int ifidx = cb->args[0];
3511 int survey_idx = cb->args[1];
3512 int res;
3513
3514 if (!ifidx)
3515 ifidx = nl80211_get_ifidx(cb);
3516 if (ifidx < 0)
3517 return ifidx;
3518 cb->args[0] = ifidx;
3519
3520 rtnl_lock();
3521
3522 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3523 if (!netdev) {
3524 res = -ENODEV;
3525 goto out_rtnl;
3526 }
3527
3528 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3529 if (IS_ERR(dev)) {
3530 res = PTR_ERR(dev);
3531 goto out_rtnl;
3532 }
3533
3534 if (!dev->ops->dump_survey) {
3535 res = -EOPNOTSUPP;
3536 goto out_err;
3537 }
3538
3539 while (1) {
3540 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3541 &survey);
3542 if (res == -ENOENT)
3543 break;
3544 if (res)
3545 goto out_err;
3546
3547 if (nl80211_send_survey(skb,
3548 NETLINK_CB(cb->skb).pid,
3549 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3550 netdev,
3551 &survey) < 0)
3552 goto out;
3553 survey_idx++;
3554 }
3555
3556 out:
3557 cb->args[1] = survey_idx;
3558 res = skb->len;
3559 out_err:
3560 cfg80211_unlock_rdev(dev);
3561 out_rtnl:
3562 rtnl_unlock();
3563
3564 return res;
3565}
3566
255e737e
JM
3567static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3568{
b23aa676
SO
3569 return auth_type <= NL80211_AUTHTYPE_MAX;
3570}
3571
3572static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3573{
3574 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3575 NL80211_WPA_VERSION_2));
3576}
3577
3578static bool nl80211_valid_akm_suite(u32 akm)
3579{
3580 return akm == WLAN_AKM_SUITE_8021X ||
3581 akm == WLAN_AKM_SUITE_PSK;
3582}
3583
3584static bool nl80211_valid_cipher_suite(u32 cipher)
3585{
3586 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3587 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3588 cipher == WLAN_CIPHER_SUITE_TKIP ||
3589 cipher == WLAN_CIPHER_SUITE_CCMP ||
3590 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3591}
3592
b23aa676 3593
636a5d36
JM
3594static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3595{
79c97e97 3596 struct cfg80211_registered_device *rdev;
636a5d36 3597 struct net_device *dev;
19957bb3
JB
3598 struct ieee80211_channel *chan;
3599 const u8 *bssid, *ssid, *ie = NULL;
3600 int err, ssid_len, ie_len = 0;
3601 enum nl80211_auth_type auth_type;
fffd0934 3602 struct key_parse key;
d5cdfacb 3603 bool local_state_change;
636a5d36 3604
f4a11bb0
JB
3605 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3606 return -EINVAL;
3607
3608 if (!info->attrs[NL80211_ATTR_MAC])
3609 return -EINVAL;
3610
1778092e
JM
3611 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3612 return -EINVAL;
3613
19957bb3
JB
3614 if (!info->attrs[NL80211_ATTR_SSID])
3615 return -EINVAL;
3616
3617 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3618 return -EINVAL;
3619
fffd0934
JB
3620 err = nl80211_parse_key(info, &key);
3621 if (err)
3622 return err;
3623
3624 if (key.idx >= 0) {
3625 if (!key.p.key || !key.p.key_len)
3626 return -EINVAL;
3627 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3628 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3629 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3630 key.p.key_len != WLAN_KEY_LEN_WEP104))
3631 return -EINVAL;
3632 if (key.idx > 4)
3633 return -EINVAL;
3634 } else {
3635 key.p.key_len = 0;
3636 key.p.key = NULL;
3637 }
3638
636a5d36
JM
3639 rtnl_lock();
3640
463d0183 3641 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3642 if (err)
3643 goto unlock_rtnl;
3644
afea0b7a
JB
3645 if (key.idx >= 0) {
3646 int i;
3647 bool ok = false;
3648 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3649 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3650 ok = true;
3651 break;
3652 }
3653 }
3654 if (!ok) {
3655 err = -EINVAL;
3656 goto out;
3657 }
3658 }
3659
79c97e97 3660 if (!rdev->ops->auth) {
636a5d36
JM
3661 err = -EOPNOTSUPP;
3662 goto out;
3663 }
3664
074ac8df
JB
3665 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3666 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
eec60b03
JM
3667 err = -EOPNOTSUPP;
3668 goto out;
3669 }
3670
35a8efe1
JM
3671 if (!netif_running(dev)) {
3672 err = -ENETDOWN;
3673 goto out;
3674 }
3675
19957bb3 3676 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3677 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3678 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3679 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3680 err = -EINVAL;
3681 goto out;
636a5d36
JM
3682 }
3683
19957bb3
JB
3684 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3685 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3686
3687 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3688 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3689 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3690 }
3691
19957bb3
JB
3692 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3693 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3694 err = -EINVAL;
3695 goto out;
636a5d36
JM
3696 }
3697
d5cdfacb
JM
3698 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3699
79c97e97 3700 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934 3701 ssid, ssid_len, ie, ie_len,
d5cdfacb
JM
3702 key.p.key, key.p.key_len, key.idx,
3703 local_state_change);
636a5d36
JM
3704
3705out:
79c97e97 3706 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3707 dev_put(dev);
3708unlock_rtnl:
3709 rtnl_unlock();
3710 return err;
3711}
3712
c0692b8f
JB
3713static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3714 struct genl_info *info,
3dc27d25
JB
3715 struct cfg80211_crypto_settings *settings,
3716 int cipher_limit)
b23aa676 3717{
c0b2bbd8
JB
3718 memset(settings, 0, sizeof(*settings));
3719
b23aa676
SO
3720 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3721
c0692b8f
JB
3722 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3723 u16 proto;
3724 proto = nla_get_u16(
3725 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3726 settings->control_port_ethertype = cpu_to_be16(proto);
3727 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3728 proto != ETH_P_PAE)
3729 return -EINVAL;
3730 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3731 settings->control_port_no_encrypt = true;
3732 } else
3733 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3734
b23aa676
SO
3735 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3736 void *data;
3737 int len, i;
3738
3739 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3740 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3741 settings->n_ciphers_pairwise = len / sizeof(u32);
3742
3743 if (len % sizeof(u32))
3744 return -EINVAL;
3745
3dc27d25 3746 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3747 return -EINVAL;
3748
3749 memcpy(settings->ciphers_pairwise, data, len);
3750
3751 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3752 if (!nl80211_valid_cipher_suite(
3753 settings->ciphers_pairwise[i]))
3754 return -EINVAL;
3755 }
3756
3757 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3758 settings->cipher_group =
3759 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3760 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3761 return -EINVAL;
3762 }
3763
3764 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3765 settings->wpa_versions =
3766 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3767 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3768 return -EINVAL;
3769 }
3770
3771 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3772 void *data;
3773 int len, i;
3774
3775 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3776 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3777 settings->n_akm_suites = len / sizeof(u32);
3778
3779 if (len % sizeof(u32))
3780 return -EINVAL;
3781
3782 memcpy(settings->akm_suites, data, len);
3783
3784 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3785 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3786 return -EINVAL;
3787 }
3788
3789 return 0;
3790}
3791
636a5d36
JM
3792static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3793{
19957bb3 3794 struct cfg80211_registered_device *rdev;
636a5d36 3795 struct net_device *dev;
19957bb3 3796 struct cfg80211_crypto_settings crypto;
f444de05 3797 struct ieee80211_channel *chan;
3e5d7649 3798 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3799 int err, ssid_len, ie_len = 0;
3800 bool use_mfp = false;
636a5d36 3801
f4a11bb0
JB
3802 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3803 return -EINVAL;
3804
3805 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3806 !info->attrs[NL80211_ATTR_SSID] ||
3807 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3808 return -EINVAL;
3809
636a5d36
JM
3810 rtnl_lock();
3811
463d0183 3812 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3813 if (err)
3814 goto unlock_rtnl;
3815
19957bb3 3816 if (!rdev->ops->assoc) {
636a5d36
JM
3817 err = -EOPNOTSUPP;
3818 goto out;
3819 }
3820
074ac8df
JB
3821 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3822 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
eec60b03
JM
3823 err = -EOPNOTSUPP;
3824 goto out;
3825 }
3826
35a8efe1
JM
3827 if (!netif_running(dev)) {
3828 err = -ENETDOWN;
3829 goto out;
3830 }
3831
19957bb3 3832 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3833
19957bb3
JB
3834 chan = ieee80211_get_channel(&rdev->wiphy,
3835 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3836 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3837 err = -EINVAL;
3838 goto out;
636a5d36
JM
3839 }
3840
19957bb3
JB
3841 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3842 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3843
3844 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3845 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3846 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3847 }
3848
dc6382ce 3849 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3850 enum nl80211_mfp mfp =
dc6382ce 3851 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3852 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3853 use_mfp = true;
4f5dadce 3854 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3855 err = -EINVAL;
3856 goto out;
3857 }
3858 }
3859
3e5d7649
JB
3860 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3861 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3862
c0692b8f 3863 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3864 if (!err)
3e5d7649
JB
3865 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3866 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3867 &crypto);
636a5d36
JM
3868
3869out:
4d0c8aea 3870 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3871 dev_put(dev);
3872unlock_rtnl:
3873 rtnl_unlock();
3874 return err;
3875}
3876
3877static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3878{
79c97e97 3879 struct cfg80211_registered_device *rdev;
636a5d36 3880 struct net_device *dev;
19957bb3
JB
3881 const u8 *ie = NULL, *bssid;
3882 int err, ie_len = 0;
3883 u16 reason_code;
d5cdfacb 3884 bool local_state_change;
636a5d36 3885
f4a11bb0
JB
3886 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3887 return -EINVAL;
3888
3889 if (!info->attrs[NL80211_ATTR_MAC])
3890 return -EINVAL;
3891
3892 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3893 return -EINVAL;
3894
636a5d36
JM
3895 rtnl_lock();
3896
463d0183 3897 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3898 if (err)
3899 goto unlock_rtnl;
3900
79c97e97 3901 if (!rdev->ops->deauth) {
636a5d36
JM
3902 err = -EOPNOTSUPP;
3903 goto out;
3904 }
3905
074ac8df
JB
3906 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3907 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
eec60b03
JM
3908 err = -EOPNOTSUPP;
3909 goto out;
3910 }
3911
35a8efe1
JM
3912 if (!netif_running(dev)) {
3913 err = -ENETDOWN;
3914 goto out;
3915 }
3916
19957bb3 3917 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3918
19957bb3
JB
3919 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3920 if (reason_code == 0) {
f4a11bb0
JB
3921 /* Reason Code 0 is reserved */
3922 err = -EINVAL;
3923 goto out;
255e737e 3924 }
636a5d36
JM
3925
3926 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3927 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3928 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3929 }
3930
d5cdfacb
JM
3931 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3932
3933 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3934 local_state_change);
636a5d36
JM
3935
3936out:
79c97e97 3937 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3938 dev_put(dev);
3939unlock_rtnl:
3940 rtnl_unlock();
3941 return err;
3942}
3943
3944static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3945{
79c97e97 3946 struct cfg80211_registered_device *rdev;
636a5d36 3947 struct net_device *dev;
19957bb3
JB
3948 const u8 *ie = NULL, *bssid;
3949 int err, ie_len = 0;
3950 u16 reason_code;
d5cdfacb 3951 bool local_state_change;
636a5d36 3952
f4a11bb0
JB
3953 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3954 return -EINVAL;
3955
3956 if (!info->attrs[NL80211_ATTR_MAC])
3957 return -EINVAL;
3958
3959 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3960 return -EINVAL;
3961
636a5d36
JM
3962 rtnl_lock();
3963
463d0183 3964 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3965 if (err)
3966 goto unlock_rtnl;
3967
79c97e97 3968 if (!rdev->ops->disassoc) {
636a5d36
JM
3969 err = -EOPNOTSUPP;
3970 goto out;
3971 }
3972
074ac8df
JB
3973 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3974 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
eec60b03
JM
3975 err = -EOPNOTSUPP;
3976 goto out;
3977 }
3978
35a8efe1
JM
3979 if (!netif_running(dev)) {
3980 err = -ENETDOWN;
3981 goto out;
3982 }
3983
19957bb3 3984 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3985
19957bb3
JB
3986 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3987 if (reason_code == 0) {
f4a11bb0
JB
3988 /* Reason Code 0 is reserved */
3989 err = -EINVAL;
3990 goto out;
255e737e 3991 }
636a5d36
JM
3992
3993 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3994 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3995 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3996 }
3997
d5cdfacb
JM
3998 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3999
4000 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4001 local_state_change);
636a5d36
JM
4002
4003out:
79c97e97 4004 cfg80211_unlock_rdev(rdev);
636a5d36
JM
4005 dev_put(dev);
4006unlock_rtnl:
4007 rtnl_unlock();
4008 return err;
4009}
4010
04a773ad
JB
4011static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4012{
79c97e97 4013 struct cfg80211_registered_device *rdev;
04a773ad
JB
4014 struct net_device *dev;
4015 struct cfg80211_ibss_params ibss;
4016 struct wiphy *wiphy;
fffd0934 4017 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4018 int err;
4019
8e30bc55
JB
4020 memset(&ibss, 0, sizeof(ibss));
4021
04a773ad
JB
4022 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4023 return -EINVAL;
4024
4025 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4026 !info->attrs[NL80211_ATTR_SSID] ||
4027 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4028 return -EINVAL;
4029
8e30bc55
JB
4030 ibss.beacon_interval = 100;
4031
4032 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4033 ibss.beacon_interval =
4034 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4035 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4036 return -EINVAL;
4037 }
4038
04a773ad
JB
4039 rtnl_lock();
4040
463d0183 4041 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
4042 if (err)
4043 goto unlock_rtnl;
4044
79c97e97 4045 if (!rdev->ops->join_ibss) {
04a773ad
JB
4046 err = -EOPNOTSUPP;
4047 goto out;
4048 }
4049
4050 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4051 err = -EOPNOTSUPP;
4052 goto out;
4053 }
4054
4055 if (!netif_running(dev)) {
4056 err = -ENETDOWN;
4057 goto out;
4058 }
4059
79c97e97 4060 wiphy = &rdev->wiphy;
04a773ad
JB
4061
4062 if (info->attrs[NL80211_ATTR_MAC])
4063 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4064 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4065 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4066
4067 if (info->attrs[NL80211_ATTR_IE]) {
4068 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4069 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4070 }
4071
4072 ibss.channel = ieee80211_get_channel(wiphy,
4073 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4074 if (!ibss.channel ||
4075 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4076 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
4077 err = -EINVAL;
4078 goto out;
4079 }
4080
4081 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4082 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4083
4084 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4085 connkeys = nl80211_parse_connkeys(rdev,
4086 info->attrs[NL80211_ATTR_KEYS]);
4087 if (IS_ERR(connkeys)) {
4088 err = PTR_ERR(connkeys);
4089 connkeys = NULL;
4090 goto out;
4091 }
4092 }
04a773ad 4093
fbd2c8dc
TP
4094 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4095 u8 *rates =
4096 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4097 int n_rates =
4098 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4099 struct ieee80211_supported_band *sband =
4100 wiphy->bands[ibss.channel->band];
4101 int i, j;
4102
4103 if (n_rates == 0) {
4104 err = -EINVAL;
4105 goto out;
4106 }
4107
4108 for (i = 0; i < n_rates; i++) {
4109 int rate = (rates[i] & 0x7f) * 5;
4110 bool found = false;
4111
4112 for (j = 0; j < sband->n_bitrates; j++) {
4113 if (sband->bitrates[j].bitrate == rate) {
4114 found = true;
4115 ibss.basic_rates |= BIT(j);
4116 break;
4117 }
4118 }
4119 if (!found) {
4120 err = -EINVAL;
4121 goto out;
4122 }
4123 }
fbd2c8dc
TP
4124 }
4125
fffd0934 4126 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
4127
4128out:
79c97e97 4129 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4130 dev_put(dev);
4131unlock_rtnl:
fffd0934
JB
4132 if (err)
4133 kfree(connkeys);
04a773ad
JB
4134 rtnl_unlock();
4135 return err;
4136}
4137
4138static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4139{
79c97e97 4140 struct cfg80211_registered_device *rdev;
04a773ad
JB
4141 struct net_device *dev;
4142 int err;
4143
4144 rtnl_lock();
4145
463d0183 4146 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
4147 if (err)
4148 goto unlock_rtnl;
4149
79c97e97 4150 if (!rdev->ops->leave_ibss) {
04a773ad
JB
4151 err = -EOPNOTSUPP;
4152 goto out;
4153 }
4154
4155 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4156 err = -EOPNOTSUPP;
4157 goto out;
4158 }
4159
4160 if (!netif_running(dev)) {
4161 err = -ENETDOWN;
4162 goto out;
4163 }
4164
79c97e97 4165 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4166
4167out:
79c97e97 4168 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4169 dev_put(dev);
4170unlock_rtnl:
4171 rtnl_unlock();
4172 return err;
4173}
4174
aff89a9b
JB
4175#ifdef CONFIG_NL80211_TESTMODE
4176static struct genl_multicast_group nl80211_testmode_mcgrp = {
4177 .name = "testmode",
4178};
4179
4180static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4181{
4182 struct cfg80211_registered_device *rdev;
4183 int err;
4184
4185 if (!info->attrs[NL80211_ATTR_TESTDATA])
4186 return -EINVAL;
4187
4188 rtnl_lock();
4189
4190 rdev = cfg80211_get_dev_from_info(info);
4191 if (IS_ERR(rdev)) {
4192 err = PTR_ERR(rdev);
4193 goto unlock_rtnl;
4194 }
4195
4196 err = -EOPNOTSUPP;
4197 if (rdev->ops->testmode_cmd) {
4198 rdev->testmode_info = info;
4199 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4200 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4201 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4202 rdev->testmode_info = NULL;
4203 }
4204
4d0c8aea 4205 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
4206
4207 unlock_rtnl:
4208 rtnl_unlock();
4209 return err;
4210}
4211
4212static struct sk_buff *
4213__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4214 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4215{
4216 struct sk_buff *skb;
4217 void *hdr;
4218 struct nlattr *data;
4219
4220 skb = nlmsg_new(approxlen + 100, gfp);
4221 if (!skb)
4222 return NULL;
4223
4224 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4225 if (!hdr) {
4226 kfree_skb(skb);
4227 return NULL;
4228 }
4229
4230 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4231 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4232
4233 ((void **)skb->cb)[0] = rdev;
4234 ((void **)skb->cb)[1] = hdr;
4235 ((void **)skb->cb)[2] = data;
4236
4237 return skb;
4238
4239 nla_put_failure:
4240 kfree_skb(skb);
4241 return NULL;
4242}
4243
4244struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4245 int approxlen)
4246{
4247 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4248
4249 if (WARN_ON(!rdev->testmode_info))
4250 return NULL;
4251
4252 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4253 rdev->testmode_info->snd_pid,
4254 rdev->testmode_info->snd_seq,
4255 GFP_KERNEL);
4256}
4257EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4258
4259int cfg80211_testmode_reply(struct sk_buff *skb)
4260{
4261 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4262 void *hdr = ((void **)skb->cb)[1];
4263 struct nlattr *data = ((void **)skb->cb)[2];
4264
4265 if (WARN_ON(!rdev->testmode_info)) {
4266 kfree_skb(skb);
4267 return -EINVAL;
4268 }
4269
4270 nla_nest_end(skb, data);
4271 genlmsg_end(skb, hdr);
4272 return genlmsg_reply(skb, rdev->testmode_info);
4273}
4274EXPORT_SYMBOL(cfg80211_testmode_reply);
4275
4276struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4277 int approxlen, gfp_t gfp)
4278{
4279 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4280
4281 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4282}
4283EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4284
4285void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4286{
4287 void *hdr = ((void **)skb->cb)[1];
4288 struct nlattr *data = ((void **)skb->cb)[2];
4289
4290 nla_nest_end(skb, data);
4291 genlmsg_end(skb, hdr);
4292 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4293}
4294EXPORT_SYMBOL(cfg80211_testmode_event);
4295#endif
4296
b23aa676
SO
4297static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4298{
79c97e97 4299 struct cfg80211_registered_device *rdev;
b23aa676
SO
4300 struct net_device *dev;
4301 struct cfg80211_connect_params connect;
4302 struct wiphy *wiphy;
fffd0934 4303 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4304 int err;
4305
4306 memset(&connect, 0, sizeof(connect));
4307
4308 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4309 return -EINVAL;
4310
4311 if (!info->attrs[NL80211_ATTR_SSID] ||
4312 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4313 return -EINVAL;
4314
4315 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4316 connect.auth_type =
4317 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4318 if (!nl80211_valid_auth_type(connect.auth_type))
4319 return -EINVAL;
4320 } else
4321 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4322
4323 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4324
c0692b8f 4325 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4326 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4327 if (err)
4328 return err;
4329 rtnl_lock();
4330
463d0183 4331 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4332 if (err)
4333 goto unlock_rtnl;
4334
074ac8df
JB
4335 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4336 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
b23aa676
SO
4337 err = -EOPNOTSUPP;
4338 goto out;
4339 }
4340
4341 if (!netif_running(dev)) {
4342 err = -ENETDOWN;
4343 goto out;
4344 }
4345
79c97e97 4346 wiphy = &rdev->wiphy;
b23aa676 4347
b23aa676
SO
4348 if (info->attrs[NL80211_ATTR_MAC])
4349 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4350 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4351 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4352
4353 if (info->attrs[NL80211_ATTR_IE]) {
4354 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4355 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4356 }
4357
4358 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4359 connect.channel =
4360 ieee80211_get_channel(wiphy,
4361 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4362 if (!connect.channel ||
4363 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4364 err = -EINVAL;
4365 goto out;
4366 }
4367 }
4368
fffd0934
JB
4369 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4370 connkeys = nl80211_parse_connkeys(rdev,
4371 info->attrs[NL80211_ATTR_KEYS]);
4372 if (IS_ERR(connkeys)) {
4373 err = PTR_ERR(connkeys);
4374 connkeys = NULL;
4375 goto out;
4376 }
4377 }
4378
4379 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
4380
4381out:
79c97e97 4382 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4383 dev_put(dev);
4384unlock_rtnl:
fffd0934
JB
4385 if (err)
4386 kfree(connkeys);
b23aa676
SO
4387 rtnl_unlock();
4388 return err;
4389}
4390
4391static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4392{
79c97e97 4393 struct cfg80211_registered_device *rdev;
b23aa676
SO
4394 struct net_device *dev;
4395 int err;
4396 u16 reason;
4397
4398 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4399 reason = WLAN_REASON_DEAUTH_LEAVING;
4400 else
4401 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4402
4403 if (reason == 0)
4404 return -EINVAL;
4405
4406 rtnl_lock();
4407
463d0183 4408 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4409 if (err)
4410 goto unlock_rtnl;
4411
074ac8df
JB
4412 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4413 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
b23aa676
SO
4414 err = -EOPNOTSUPP;
4415 goto out;
4416 }
4417
4418 if (!netif_running(dev)) {
4419 err = -ENETDOWN;
4420 goto out;
4421 }
4422
79c97e97 4423 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4424
4425out:
79c97e97 4426 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4427 dev_put(dev);
4428unlock_rtnl:
4429 rtnl_unlock();
4430 return err;
4431}
4432
463d0183
JB
4433static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4434{
4435 struct cfg80211_registered_device *rdev;
4436 struct net *net;
4437 int err;
4438 u32 pid;
4439
4440 if (!info->attrs[NL80211_ATTR_PID])
4441 return -EINVAL;
4442
4443 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4444
4445 rtnl_lock();
4446
4447 rdev = cfg80211_get_dev_from_info(info);
4448 if (IS_ERR(rdev)) {
4449 err = PTR_ERR(rdev);
8a8e05e5 4450 goto out_rtnl;
463d0183
JB
4451 }
4452
4453 net = get_net_ns_by_pid(pid);
4454 if (IS_ERR(net)) {
4455 err = PTR_ERR(net);
4456 goto out;
4457 }
4458
4459 err = 0;
4460
4461 /* check if anything to do */
4462 if (net_eq(wiphy_net(&rdev->wiphy), net))
4463 goto out_put_net;
4464
4465 err = cfg80211_switch_netns(rdev, net);
4466 out_put_net:
4467 put_net(net);
4468 out:
4469 cfg80211_unlock_rdev(rdev);
8a8e05e5 4470 out_rtnl:
463d0183
JB
4471 rtnl_unlock();
4472 return err;
4473}
4474
67fbb16b
SO
4475static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4476{
4477 struct cfg80211_registered_device *rdev;
4478 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4479 struct cfg80211_pmksa *pmksa) = NULL;
4480 int err;
4481 struct net_device *dev;
4482 struct cfg80211_pmksa pmksa;
4483
4484 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4485
4486 if (!info->attrs[NL80211_ATTR_MAC])
4487 return -EINVAL;
4488
4489 if (!info->attrs[NL80211_ATTR_PMKID])
4490 return -EINVAL;
4491
4492 rtnl_lock();
4493
4494 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4495 if (err)
4496 goto out_rtnl;
4497
4498 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4499 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4500
074ac8df
JB
4501 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4502 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
67fbb16b
SO
4503 err = -EOPNOTSUPP;
4504 goto out;
4505 }
4506
4507 switch (info->genlhdr->cmd) {
4508 case NL80211_CMD_SET_PMKSA:
4509 rdev_ops = rdev->ops->set_pmksa;
4510 break;
4511 case NL80211_CMD_DEL_PMKSA:
4512 rdev_ops = rdev->ops->del_pmksa;
4513 break;
4514 default:
4515 WARN_ON(1);
4516 break;
4517 }
4518
4519 if (!rdev_ops) {
4520 err = -EOPNOTSUPP;
4521 goto out;
4522 }
4523
4524 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4525
4526 out:
4527 cfg80211_unlock_rdev(rdev);
4528 dev_put(dev);
4529 out_rtnl:
4530 rtnl_unlock();
4531
4532 return err;
4533}
4534
4535static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4536{
4537 struct cfg80211_registered_device *rdev;
4538 int err;
4539 struct net_device *dev;
4540
4541 rtnl_lock();
4542
4543 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4544 if (err)
4545 goto out_rtnl;
4546
074ac8df
JB
4547 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4548 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
67fbb16b
SO
4549 err = -EOPNOTSUPP;
4550 goto out;
4551 }
4552
4553 if (!rdev->ops->flush_pmksa) {
4554 err = -EOPNOTSUPP;
4555 goto out;
4556 }
4557
4558 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4559
4560 out:
4561 cfg80211_unlock_rdev(rdev);
4562 dev_put(dev);
4563 out_rtnl:
4564 rtnl_unlock();
4565
4566 return err;
4567
4568}
4569
9588bbd5
JM
4570static int nl80211_remain_on_channel(struct sk_buff *skb,
4571 struct genl_info *info)
4572{
4573 struct cfg80211_registered_device *rdev;
4574 struct net_device *dev;
4575 struct ieee80211_channel *chan;
4576 struct sk_buff *msg;
4577 void *hdr;
4578 u64 cookie;
4579 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4580 u32 freq, duration;
4581 int err;
4582
4583 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4584 !info->attrs[NL80211_ATTR_DURATION])
4585 return -EINVAL;
4586
4587 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4588
4589 /*
4590 * We should be on that channel for at least one jiffie,
4591 * and more than 5 seconds seems excessive.
4592 */
4593 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4594 return -EINVAL;
4595
4596 rtnl_lock();
4597
4598 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4599 if (err)
4600 goto unlock_rtnl;
4601
4602 if (!rdev->ops->remain_on_channel) {
4603 err = -EOPNOTSUPP;
4604 goto out;
4605 }
4606
4607 if (!netif_running(dev)) {
4608 err = -ENETDOWN;
4609 goto out;
4610 }
4611
4612 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4613 channel_type = nla_get_u32(
4614 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4615 if (channel_type != NL80211_CHAN_NO_HT &&
4616 channel_type != NL80211_CHAN_HT20 &&
4617 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4618 channel_type != NL80211_CHAN_HT40MINUS) {
9588bbd5
JM
4619 err = -EINVAL;
4620 goto out;
579d7534 4621 }
9588bbd5
JM
4622 }
4623
4624 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4625 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4626 if (chan == NULL) {
4627 err = -EINVAL;
4628 goto out;
4629 }
4630
4631 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4632 if (!msg) {
4633 err = -ENOMEM;
4634 goto out;
4635 }
4636
4637 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4638 NL80211_CMD_REMAIN_ON_CHANNEL);
4639
4640 if (IS_ERR(hdr)) {
4641 err = PTR_ERR(hdr);
4642 goto free_msg;
4643 }
4644
4645 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4646 channel_type, duration, &cookie);
4647
4648 if (err)
4649 goto free_msg;
4650
4651 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4652
4653 genlmsg_end(msg, hdr);
4654 err = genlmsg_reply(msg, info);
4655 goto out;
4656
4657 nla_put_failure:
4658 err = -ENOBUFS;
4659 free_msg:
4660 nlmsg_free(msg);
4661 out:
4662 cfg80211_unlock_rdev(rdev);
4663 dev_put(dev);
4664 unlock_rtnl:
4665 rtnl_unlock();
4666 return err;
4667}
4668
4669static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4670 struct genl_info *info)
4671{
4672 struct cfg80211_registered_device *rdev;
4673 struct net_device *dev;
4674 u64 cookie;
4675 int err;
4676
4677 if (!info->attrs[NL80211_ATTR_COOKIE])
4678 return -EINVAL;
4679
4680 rtnl_lock();
4681
4682 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4683 if (err)
4684 goto unlock_rtnl;
4685
4686 if (!rdev->ops->cancel_remain_on_channel) {
4687 err = -EOPNOTSUPP;
4688 goto out;
4689 }
4690
4691 if (!netif_running(dev)) {
4692 err = -ENETDOWN;
4693 goto out;
4694 }
4695
4696 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4697
4698 err = rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4699
4700 out:
4701 cfg80211_unlock_rdev(rdev);
4702 dev_put(dev);
4703 unlock_rtnl:
4704 rtnl_unlock();
4705 return err;
4706}
4707
13ae75b1
JM
4708static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4709 u8 *rates, u8 rates_len)
4710{
4711 u8 i;
4712 u32 mask = 0;
4713
4714 for (i = 0; i < rates_len; i++) {
4715 int rate = (rates[i] & 0x7f) * 5;
4716 int ridx;
4717 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4718 struct ieee80211_rate *srate =
4719 &sband->bitrates[ridx];
4720 if (rate == srate->bitrate) {
4721 mask |= 1 << ridx;
4722 break;
4723 }
4724 }
4725 if (ridx == sband->n_bitrates)
4726 return 0; /* rate not found */
4727 }
4728
4729 return mask;
4730}
4731
b54452b0 4732static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4733 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4734 .len = NL80211_MAX_SUPP_RATES },
4735};
4736
4737static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4738 struct genl_info *info)
4739{
4740 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4741 struct cfg80211_registered_device *rdev;
4742 struct cfg80211_bitrate_mask mask;
4743 int err, rem, i;
4744 struct net_device *dev;
4745 struct nlattr *tx_rates;
4746 struct ieee80211_supported_band *sband;
4747
4748 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4749 return -EINVAL;
4750
4751 rtnl_lock();
4752
4753 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4754 if (err)
4755 goto unlock_rtnl;
4756
4757 if (!rdev->ops->set_bitrate_mask) {
4758 err = -EOPNOTSUPP;
4759 goto unlock;
4760 }
4761
4762 memset(&mask, 0, sizeof(mask));
4763 /* Default to all rates enabled */
4764 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4765 sband = rdev->wiphy.bands[i];
4766 mask.control[i].legacy =
4767 sband ? (1 << sband->n_bitrates) - 1 : 0;
4768 }
4769
4770 /*
4771 * The nested attribute uses enum nl80211_band as the index. This maps
4772 * directly to the enum ieee80211_band values used in cfg80211.
4773 */
4774 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4775 {
4776 enum ieee80211_band band = nla_type(tx_rates);
4777 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
4778 err = -EINVAL;
4779 goto unlock;
4780 }
4781 sband = rdev->wiphy.bands[band];
4782 if (sband == NULL) {
4783 err = -EINVAL;
4784 goto unlock;
4785 }
4786 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4787 nla_len(tx_rates), nl80211_txattr_policy);
4788 if (tb[NL80211_TXRATE_LEGACY]) {
4789 mask.control[band].legacy = rateset_to_mask(
4790 sband,
4791 nla_data(tb[NL80211_TXRATE_LEGACY]),
4792 nla_len(tb[NL80211_TXRATE_LEGACY]));
4793 if (mask.control[band].legacy == 0) {
4794 err = -EINVAL;
4795 goto unlock;
4796 }
4797 }
4798 }
4799
4800 err = rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4801
4802 unlock:
4803 dev_put(dev);
4804 cfg80211_unlock_rdev(rdev);
4805 unlock_rtnl:
4806 rtnl_unlock();
4807 return err;
4808}
4809
2e161f78 4810static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4
JM
4811{
4812 struct cfg80211_registered_device *rdev;
4813 struct net_device *dev;
2e161f78 4814 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4815 int err;
4816
4817 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4818 return -EINVAL;
4819
2e161f78
JB
4820 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4821 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4
JM
4822
4823 rtnl_lock();
4824
4825 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4826 if (err)
4827 goto unlock_rtnl;
4828
9d38d85d 4829 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df
JB
4830 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4831 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
026331c4
JM
4832 err = -EOPNOTSUPP;
4833 goto out;
4834 }
4835
4836 /* not much point in registering if we can't reply */
2e161f78 4837 if (!rdev->ops->mgmt_tx) {
026331c4
JM
4838 err = -EOPNOTSUPP;
4839 goto out;
4840 }
4841
2e161f78
JB
4842 err = cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
4843 frame_type,
026331c4
JM
4844 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4845 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4846 out:
4847 cfg80211_unlock_rdev(rdev);
4848 dev_put(dev);
4849 unlock_rtnl:
4850 rtnl_unlock();
4851 return err;
4852}
4853
2e161f78 4854static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4
JM
4855{
4856 struct cfg80211_registered_device *rdev;
4857 struct net_device *dev;
4858 struct ieee80211_channel *chan;
4859 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4860 bool channel_type_valid = false;
026331c4
JM
4861 u32 freq;
4862 int err;
4863 void *hdr;
4864 u64 cookie;
4865 struct sk_buff *msg;
4866
4867 if (!info->attrs[NL80211_ATTR_FRAME] ||
4868 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4869 return -EINVAL;
4870
4871 rtnl_lock();
4872
4873 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4874 if (err)
4875 goto unlock_rtnl;
4876
2e161f78 4877 if (!rdev->ops->mgmt_tx) {
026331c4
JM
4878 err = -EOPNOTSUPP;
4879 goto out;
4880 }
4881
9d38d85d 4882 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df
JB
4883 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4884 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) {
026331c4
JM
4885 err = -EOPNOTSUPP;
4886 goto out;
4887 }
4888
4889 if (!netif_running(dev)) {
4890 err = -ENETDOWN;
4891 goto out;
4892 }
4893
4894 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4895 channel_type = nla_get_u32(
4896 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4897 if (channel_type != NL80211_CHAN_NO_HT &&
4898 channel_type != NL80211_CHAN_HT20 &&
4899 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4900 channel_type != NL80211_CHAN_HT40MINUS) {
026331c4
JM
4901 err = -EINVAL;
4902 goto out;
579d7534 4903 }
252aa631 4904 channel_type_valid = true;
026331c4
JM
4905 }
4906
4907 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4908 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4909 if (chan == NULL) {
4910 err = -EINVAL;
4911 goto out;
4912 }
4913
4914 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4915 if (!msg) {
4916 err = -ENOMEM;
4917 goto out;
4918 }
4919
4920 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4921 NL80211_CMD_FRAME);
026331c4
JM
4922
4923 if (IS_ERR(hdr)) {
4924 err = PTR_ERR(hdr);
4925 goto free_msg;
4926 }
2e161f78
JB
4927 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, channel_type,
4928 channel_type_valid,
4929 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4930 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4931 &cookie);
026331c4
JM
4932 if (err)
4933 goto free_msg;
4934
4935 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4936
4937 genlmsg_end(msg, hdr);
4938 err = genlmsg_reply(msg, info);
4939 goto out;
4940
4941 nla_put_failure:
4942 err = -ENOBUFS;
4943 free_msg:
4944 nlmsg_free(msg);
4945 out:
4946 cfg80211_unlock_rdev(rdev);
4947 dev_put(dev);
4948unlock_rtnl:
4949 rtnl_unlock();
4950 return err;
4951}
4952
ffb9eb3d
KV
4953static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4954{
4955 struct cfg80211_registered_device *rdev;
4956 struct wireless_dev *wdev;
4957 struct net_device *dev;
4958 u8 ps_state;
4959 bool state;
4960 int err;
4961
4962 if (!info->attrs[NL80211_ATTR_PS_STATE]) {
4963 err = -EINVAL;
4964 goto out;
4965 }
4966
4967 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4968
4969 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) {
4970 err = -EINVAL;
4971 goto out;
4972 }
4973
4974 rtnl_lock();
4975
4976 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4977 if (err)
92e44948 4978 goto unlock_rtnl;
ffb9eb3d
KV
4979
4980 wdev = dev->ieee80211_ptr;
4981
4982 if (!rdev->ops->set_power_mgmt) {
4983 err = -EOPNOTSUPP;
4984 goto unlock_rdev;
4985 }
4986
4987 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4988
4989 if (state == wdev->ps)
4990 goto unlock_rdev;
4991
4992 wdev->ps = state;
4993
4994 if (rdev->ops->set_power_mgmt(wdev->wiphy, dev, wdev->ps,
4995 wdev->ps_timeout))
4996 /* assume this means it's off */
4997 wdev->ps = false;
4998
4999unlock_rdev:
5000 cfg80211_unlock_rdev(rdev);
5001 dev_put(dev);
92e44948 5002unlock_rtnl:
ffb9eb3d
KV
5003 rtnl_unlock();
5004
5005out:
5006 return err;
5007}
5008
5009static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5010{
5011 struct cfg80211_registered_device *rdev;
5012 enum nl80211_ps_state ps_state;
5013 struct wireless_dev *wdev;
5014 struct net_device *dev;
5015 struct sk_buff *msg;
5016 void *hdr;
5017 int err;
5018
5019 rtnl_lock();
5020
5021 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5022 if (err)
5023 goto unlock_rtnl;
5024
5025 wdev = dev->ieee80211_ptr;
5026
5027 if (!rdev->ops->set_power_mgmt) {
5028 err = -EOPNOTSUPP;
5029 goto out;
5030 }
5031
5032 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5033 if (!msg) {
5034 err = -ENOMEM;
5035 goto out;
5036 }
5037
5038 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5039 NL80211_CMD_GET_POWER_SAVE);
5040 if (!hdr) {
5041 err = -ENOMEM;
5042 goto free_msg;
5043 }
5044
5045 if (wdev->ps)
5046 ps_state = NL80211_PS_ENABLED;
5047 else
5048 ps_state = NL80211_PS_DISABLED;
5049
5050 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5051
5052 genlmsg_end(msg, hdr);
5053 err = genlmsg_reply(msg, info);
5054 goto out;
5055
5056nla_put_failure:
5057 err = -ENOBUFS;
5058
5059free_msg:
5060 nlmsg_free(msg);
5061
5062out:
5063 cfg80211_unlock_rdev(rdev);
5064 dev_put(dev);
5065
5066unlock_rtnl:
5067 rtnl_unlock();
5068
5069 return err;
5070}
5071
d6dc1a38
JO
5072static struct nla_policy
5073nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5074 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5075 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5076 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5077};
5078
5079static int nl80211_set_cqm_rssi(struct genl_info *info,
5080 s32 threshold, u32 hysteresis)
5081{
5082 struct cfg80211_registered_device *rdev;
5083 struct wireless_dev *wdev;
5084 struct net_device *dev;
5085 int err;
5086
5087 if (threshold > 0)
5088 return -EINVAL;
5089
5090 rtnl_lock();
5091
5092 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5093 if (err)
5094 goto unlock_rdev;
5095
5096 wdev = dev->ieee80211_ptr;
5097
5098 if (!rdev->ops->set_cqm_rssi_config) {
5099 err = -EOPNOTSUPP;
5100 goto unlock_rdev;
5101 }
5102
074ac8df
JB
5103 if (wdev->iftype != NL80211_IFTYPE_STATION &&
5104 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) {
d6dc1a38
JO
5105 err = -EOPNOTSUPP;
5106 goto unlock_rdev;
5107 }
5108
5109 err = rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5110 threshold, hysteresis);
5111
5112unlock_rdev:
5113 cfg80211_unlock_rdev(rdev);
5114 dev_put(dev);
5115 rtnl_unlock();
5116
5117 return err;
5118}
5119
5120static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5121{
5122 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5123 struct nlattr *cqm;
5124 int err;
5125
5126 cqm = info->attrs[NL80211_ATTR_CQM];
5127 if (!cqm) {
5128 err = -EINVAL;
5129 goto out;
5130 }
5131
5132 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5133 nl80211_attr_cqm_policy);
5134 if (err)
5135 goto out;
5136
5137 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5138 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5139 s32 threshold;
5140 u32 hysteresis;
5141 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5142 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5143 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5144 } else
5145 err = -EINVAL;
5146
5147out:
5148 return err;
5149}
5150
55682965
JB
5151static struct genl_ops nl80211_ops[] = {
5152 {
5153 .cmd = NL80211_CMD_GET_WIPHY,
5154 .doit = nl80211_get_wiphy,
5155 .dumpit = nl80211_dump_wiphy,
5156 .policy = nl80211_policy,
5157 /* can be retrieved by unprivileged users */
5158 },
5159 {
5160 .cmd = NL80211_CMD_SET_WIPHY,
5161 .doit = nl80211_set_wiphy,
5162 .policy = nl80211_policy,
5163 .flags = GENL_ADMIN_PERM,
5164 },
5165 {
5166 .cmd = NL80211_CMD_GET_INTERFACE,
5167 .doit = nl80211_get_interface,
5168 .dumpit = nl80211_dump_interface,
5169 .policy = nl80211_policy,
5170 /* can be retrieved by unprivileged users */
5171 },
5172 {
5173 .cmd = NL80211_CMD_SET_INTERFACE,
5174 .doit = nl80211_set_interface,
5175 .policy = nl80211_policy,
5176 .flags = GENL_ADMIN_PERM,
5177 },
5178 {
5179 .cmd = NL80211_CMD_NEW_INTERFACE,
5180 .doit = nl80211_new_interface,
5181 .policy = nl80211_policy,
5182 .flags = GENL_ADMIN_PERM,
5183 },
5184 {
5185 .cmd = NL80211_CMD_DEL_INTERFACE,
5186 .doit = nl80211_del_interface,
5187 .policy = nl80211_policy,
41ade00f
JB
5188 .flags = GENL_ADMIN_PERM,
5189 },
5190 {
5191 .cmd = NL80211_CMD_GET_KEY,
5192 .doit = nl80211_get_key,
5193 .policy = nl80211_policy,
5194 .flags = GENL_ADMIN_PERM,
5195 },
5196 {
5197 .cmd = NL80211_CMD_SET_KEY,
5198 .doit = nl80211_set_key,
5199 .policy = nl80211_policy,
5200 .flags = GENL_ADMIN_PERM,
5201 },
5202 {
5203 .cmd = NL80211_CMD_NEW_KEY,
5204 .doit = nl80211_new_key,
5205 .policy = nl80211_policy,
5206 .flags = GENL_ADMIN_PERM,
5207 },
5208 {
5209 .cmd = NL80211_CMD_DEL_KEY,
5210 .doit = nl80211_del_key,
5211 .policy = nl80211_policy,
55682965
JB
5212 .flags = GENL_ADMIN_PERM,
5213 },
ed1b6cc7
JB
5214 {
5215 .cmd = NL80211_CMD_SET_BEACON,
5216 .policy = nl80211_policy,
5217 .flags = GENL_ADMIN_PERM,
5218 .doit = nl80211_addset_beacon,
5219 },
5220 {
5221 .cmd = NL80211_CMD_NEW_BEACON,
5222 .policy = nl80211_policy,
5223 .flags = GENL_ADMIN_PERM,
5224 .doit = nl80211_addset_beacon,
5225 },
5226 {
5227 .cmd = NL80211_CMD_DEL_BEACON,
5228 .policy = nl80211_policy,
5229 .flags = GENL_ADMIN_PERM,
5230 .doit = nl80211_del_beacon,
5231 },
5727ef1b
JB
5232 {
5233 .cmd = NL80211_CMD_GET_STATION,
5234 .doit = nl80211_get_station,
2ec600d6 5235 .dumpit = nl80211_dump_station,
5727ef1b 5236 .policy = nl80211_policy,
5727ef1b
JB
5237 },
5238 {
5239 .cmd = NL80211_CMD_SET_STATION,
5240 .doit = nl80211_set_station,
5241 .policy = nl80211_policy,
5242 .flags = GENL_ADMIN_PERM,
5243 },
5244 {
5245 .cmd = NL80211_CMD_NEW_STATION,
5246 .doit = nl80211_new_station,
5247 .policy = nl80211_policy,
5248 .flags = GENL_ADMIN_PERM,
5249 },
5250 {
5251 .cmd = NL80211_CMD_DEL_STATION,
5252 .doit = nl80211_del_station,
5253 .policy = nl80211_policy,
2ec600d6
LCC
5254 .flags = GENL_ADMIN_PERM,
5255 },
5256 {
5257 .cmd = NL80211_CMD_GET_MPATH,
5258 .doit = nl80211_get_mpath,
5259 .dumpit = nl80211_dump_mpath,
5260 .policy = nl80211_policy,
5261 .flags = GENL_ADMIN_PERM,
5262 },
5263 {
5264 .cmd = NL80211_CMD_SET_MPATH,
5265 .doit = nl80211_set_mpath,
5266 .policy = nl80211_policy,
5267 .flags = GENL_ADMIN_PERM,
5268 },
5269 {
5270 .cmd = NL80211_CMD_NEW_MPATH,
5271 .doit = nl80211_new_mpath,
5272 .policy = nl80211_policy,
5273 .flags = GENL_ADMIN_PERM,
5274 },
5275 {
5276 .cmd = NL80211_CMD_DEL_MPATH,
5277 .doit = nl80211_del_mpath,
5278 .policy = nl80211_policy,
9f1ba906
JM
5279 .flags = GENL_ADMIN_PERM,
5280 },
5281 {
5282 .cmd = NL80211_CMD_SET_BSS,
5283 .doit = nl80211_set_bss,
5284 .policy = nl80211_policy,
b2e1b302
LR
5285 .flags = GENL_ADMIN_PERM,
5286 },
f130347c
LR
5287 {
5288 .cmd = NL80211_CMD_GET_REG,
5289 .doit = nl80211_get_reg,
5290 .policy = nl80211_policy,
5291 /* can be retrieved by unprivileged users */
5292 },
b2e1b302
LR
5293 {
5294 .cmd = NL80211_CMD_SET_REG,
5295 .doit = nl80211_set_reg,
5296 .policy = nl80211_policy,
5297 .flags = GENL_ADMIN_PERM,
5298 },
5299 {
5300 .cmd = NL80211_CMD_REQ_SET_REG,
5301 .doit = nl80211_req_set_reg,
5302 .policy = nl80211_policy,
93da9cc1 5303 .flags = GENL_ADMIN_PERM,
5304 },
5305 {
5306 .cmd = NL80211_CMD_GET_MESH_PARAMS,
5307 .doit = nl80211_get_mesh_params,
5308 .policy = nl80211_policy,
5309 /* can be retrieved by unprivileged users */
5310 },
5311 {
5312 .cmd = NL80211_CMD_SET_MESH_PARAMS,
5313 .doit = nl80211_set_mesh_params,
5314 .policy = nl80211_policy,
9aed3cc1
JM
5315 .flags = GENL_ADMIN_PERM,
5316 },
2a519311
JB
5317 {
5318 .cmd = NL80211_CMD_TRIGGER_SCAN,
5319 .doit = nl80211_trigger_scan,
5320 .policy = nl80211_policy,
5321 .flags = GENL_ADMIN_PERM,
5322 },
5323 {
5324 .cmd = NL80211_CMD_GET_SCAN,
5325 .policy = nl80211_policy,
5326 .dumpit = nl80211_dump_scan,
5327 },
636a5d36
JM
5328 {
5329 .cmd = NL80211_CMD_AUTHENTICATE,
5330 .doit = nl80211_authenticate,
5331 .policy = nl80211_policy,
5332 .flags = GENL_ADMIN_PERM,
5333 },
5334 {
5335 .cmd = NL80211_CMD_ASSOCIATE,
5336 .doit = nl80211_associate,
5337 .policy = nl80211_policy,
5338 .flags = GENL_ADMIN_PERM,
5339 },
5340 {
5341 .cmd = NL80211_CMD_DEAUTHENTICATE,
5342 .doit = nl80211_deauthenticate,
5343 .policy = nl80211_policy,
5344 .flags = GENL_ADMIN_PERM,
5345 },
5346 {
5347 .cmd = NL80211_CMD_DISASSOCIATE,
5348 .doit = nl80211_disassociate,
5349 .policy = nl80211_policy,
5350 .flags = GENL_ADMIN_PERM,
5351 },
04a773ad
JB
5352 {
5353 .cmd = NL80211_CMD_JOIN_IBSS,
5354 .doit = nl80211_join_ibss,
5355 .policy = nl80211_policy,
5356 .flags = GENL_ADMIN_PERM,
5357 },
5358 {
5359 .cmd = NL80211_CMD_LEAVE_IBSS,
5360 .doit = nl80211_leave_ibss,
5361 .policy = nl80211_policy,
5362 .flags = GENL_ADMIN_PERM,
5363 },
aff89a9b
JB
5364#ifdef CONFIG_NL80211_TESTMODE
5365 {
5366 .cmd = NL80211_CMD_TESTMODE,
5367 .doit = nl80211_testmode_do,
5368 .policy = nl80211_policy,
5369 .flags = GENL_ADMIN_PERM,
5370 },
5371#endif
b23aa676
SO
5372 {
5373 .cmd = NL80211_CMD_CONNECT,
5374 .doit = nl80211_connect,
5375 .policy = nl80211_policy,
5376 .flags = GENL_ADMIN_PERM,
5377 },
5378 {
5379 .cmd = NL80211_CMD_DISCONNECT,
5380 .doit = nl80211_disconnect,
5381 .policy = nl80211_policy,
5382 .flags = GENL_ADMIN_PERM,
5383 },
463d0183
JB
5384 {
5385 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5386 .doit = nl80211_wiphy_netns,
5387 .policy = nl80211_policy,
5388 .flags = GENL_ADMIN_PERM,
5389 },
61fa713c
HS
5390 {
5391 .cmd = NL80211_CMD_GET_SURVEY,
5392 .policy = nl80211_policy,
5393 .dumpit = nl80211_dump_survey,
5394 },
67fbb16b
SO
5395 {
5396 .cmd = NL80211_CMD_SET_PMKSA,
5397 .doit = nl80211_setdel_pmksa,
5398 .policy = nl80211_policy,
5399 .flags = GENL_ADMIN_PERM,
5400 },
5401 {
5402 .cmd = NL80211_CMD_DEL_PMKSA,
5403 .doit = nl80211_setdel_pmksa,
5404 .policy = nl80211_policy,
5405 .flags = GENL_ADMIN_PERM,
5406 },
5407 {
5408 .cmd = NL80211_CMD_FLUSH_PMKSA,
5409 .doit = nl80211_flush_pmksa,
5410 .policy = nl80211_policy,
5411 .flags = GENL_ADMIN_PERM,
5412 },
9588bbd5
JM
5413 {
5414 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5415 .doit = nl80211_remain_on_channel,
5416 .policy = nl80211_policy,
5417 .flags = GENL_ADMIN_PERM,
5418 },
5419 {
5420 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5421 .doit = nl80211_cancel_remain_on_channel,
5422 .policy = nl80211_policy,
5423 .flags = GENL_ADMIN_PERM,
5424 },
13ae75b1
JM
5425 {
5426 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5427 .doit = nl80211_set_tx_bitrate_mask,
5428 .policy = nl80211_policy,
5429 .flags = GENL_ADMIN_PERM,
5430 },
026331c4 5431 {
2e161f78
JB
5432 .cmd = NL80211_CMD_REGISTER_FRAME,
5433 .doit = nl80211_register_mgmt,
026331c4
JM
5434 .policy = nl80211_policy,
5435 .flags = GENL_ADMIN_PERM,
5436 },
5437 {
2e161f78
JB
5438 .cmd = NL80211_CMD_FRAME,
5439 .doit = nl80211_tx_mgmt,
026331c4
JM
5440 .policy = nl80211_policy,
5441 .flags = GENL_ADMIN_PERM,
5442 },
ffb9eb3d
KV
5443 {
5444 .cmd = NL80211_CMD_SET_POWER_SAVE,
5445 .doit = nl80211_set_power_save,
5446 .policy = nl80211_policy,
5447 .flags = GENL_ADMIN_PERM,
5448 },
5449 {
5450 .cmd = NL80211_CMD_GET_POWER_SAVE,
5451 .doit = nl80211_get_power_save,
5452 .policy = nl80211_policy,
5453 /* can be retrieved by unprivileged users */
5454 },
d6dc1a38
JO
5455 {
5456 .cmd = NL80211_CMD_SET_CQM,
5457 .doit = nl80211_set_cqm,
5458 .policy = nl80211_policy,
5459 .flags = GENL_ADMIN_PERM,
5460 },
f444de05
JB
5461 {
5462 .cmd = NL80211_CMD_SET_CHANNEL,
5463 .doit = nl80211_set_channel,
5464 .policy = nl80211_policy,
5465 .flags = GENL_ADMIN_PERM,
5466 },
55682965 5467};
9588bbd5 5468
6039f6d2
JM
5469static struct genl_multicast_group nl80211_mlme_mcgrp = {
5470 .name = "mlme",
5471};
55682965
JB
5472
5473/* multicast groups */
5474static struct genl_multicast_group nl80211_config_mcgrp = {
5475 .name = "config",
5476};
2a519311
JB
5477static struct genl_multicast_group nl80211_scan_mcgrp = {
5478 .name = "scan",
5479};
73d54c9e
LR
5480static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5481 .name = "regulatory",
5482};
55682965
JB
5483
5484/* notification functions */
5485
5486void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5487{
5488 struct sk_buff *msg;
5489
fd2120ca 5490 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5491 if (!msg)
5492 return;
5493
5494 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5495 nlmsg_free(msg);
5496 return;
5497 }
5498
463d0183
JB
5499 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5500 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5501}
5502
362a415d
JB
5503static int nl80211_add_scan_req(struct sk_buff *msg,
5504 struct cfg80211_registered_device *rdev)
5505{
5506 struct cfg80211_scan_request *req = rdev->scan_req;
5507 struct nlattr *nest;
5508 int i;
5509
667503dd
JB
5510 ASSERT_RDEV_LOCK(rdev);
5511
362a415d
JB
5512 if (WARN_ON(!req))
5513 return 0;
5514
5515 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5516 if (!nest)
5517 goto nla_put_failure;
5518 for (i = 0; i < req->n_ssids; i++)
5519 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5520 nla_nest_end(msg, nest);
5521
5522 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5523 if (!nest)
5524 goto nla_put_failure;
5525 for (i = 0; i < req->n_channels; i++)
5526 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5527 nla_nest_end(msg, nest);
5528
5529 if (req->ie)
5530 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5531
5532 return 0;
5533 nla_put_failure:
5534 return -ENOBUFS;
5535}
5536
a538e2d5
JB
5537static int nl80211_send_scan_msg(struct sk_buff *msg,
5538 struct cfg80211_registered_device *rdev,
5539 struct net_device *netdev,
5540 u32 pid, u32 seq, int flags,
5541 u32 cmd)
2a519311
JB
5542{
5543 void *hdr;
5544
5545 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5546 if (!hdr)
5547 return -1;
5548
b5850a7a 5549 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5550 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5551
362a415d
JB
5552 /* ignore errors and send incomplete event anyway */
5553 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5554
5555 return genlmsg_end(msg, hdr);
5556
5557 nla_put_failure:
5558 genlmsg_cancel(msg, hdr);
5559 return -EMSGSIZE;
5560}
5561
a538e2d5
JB
5562void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5563 struct net_device *netdev)
5564{
5565 struct sk_buff *msg;
5566
5567 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5568 if (!msg)
5569 return;
5570
5571 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5572 NL80211_CMD_TRIGGER_SCAN) < 0) {
5573 nlmsg_free(msg);
5574 return;
5575 }
5576
463d0183
JB
5577 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5578 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5579}
5580
2a519311
JB
5581void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5582 struct net_device *netdev)
5583{
5584 struct sk_buff *msg;
5585
fd2120ca 5586 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5587 if (!msg)
5588 return;
5589
a538e2d5
JB
5590 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5591 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5592 nlmsg_free(msg);
5593 return;
5594 }
5595
463d0183
JB
5596 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5597 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5598}
5599
5600void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5601 struct net_device *netdev)
5602{
5603 struct sk_buff *msg;
5604
fd2120ca 5605 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5606 if (!msg)
5607 return;
5608
a538e2d5
JB
5609 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5610 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5611 nlmsg_free(msg);
5612 return;
5613 }
5614
463d0183
JB
5615 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5616 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5617}
5618
73d54c9e
LR
5619/*
5620 * This can happen on global regulatory changes or device specific settings
5621 * based on custom world regulatory domains.
5622 */
5623void nl80211_send_reg_change_event(struct regulatory_request *request)
5624{
5625 struct sk_buff *msg;
5626 void *hdr;
5627
fd2120ca 5628 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5629 if (!msg)
5630 return;
5631
5632 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5633 if (!hdr) {
5634 nlmsg_free(msg);
5635 return;
5636 }
5637
5638 /* Userspace can always count this one always being set */
5639 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5640
5641 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5642 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5643 NL80211_REGDOM_TYPE_WORLD);
5644 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5645 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5646 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5647 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5648 request->intersect)
5649 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5650 NL80211_REGDOM_TYPE_INTERSECTION);
5651 else {
5652 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5653 NL80211_REGDOM_TYPE_COUNTRY);
5654 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5655 }
5656
5657 if (wiphy_idx_valid(request->wiphy_idx))
5658 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5659
5660 if (genlmsg_end(msg, hdr) < 0) {
5661 nlmsg_free(msg);
5662 return;
5663 }
5664
bc43b28c 5665 rcu_read_lock();
463d0183 5666 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5667 GFP_ATOMIC);
5668 rcu_read_unlock();
73d54c9e
LR
5669
5670 return;
5671
5672nla_put_failure:
5673 genlmsg_cancel(msg, hdr);
5674 nlmsg_free(msg);
5675}
5676
6039f6d2
JM
5677static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5678 struct net_device *netdev,
5679 const u8 *buf, size_t len,
e6d6e342 5680 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5681{
5682 struct sk_buff *msg;
5683 void *hdr;
5684
e6d6e342 5685 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5686 if (!msg)
5687 return;
5688
5689 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5690 if (!hdr) {
5691 nlmsg_free(msg);
5692 return;
5693 }
5694
5695 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5696 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5697 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5698
5699 if (genlmsg_end(msg, hdr) < 0) {
5700 nlmsg_free(msg);
5701 return;
5702 }
5703
463d0183
JB
5704 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5705 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5706 return;
5707
5708 nla_put_failure:
5709 genlmsg_cancel(msg, hdr);
5710 nlmsg_free(msg);
5711}
5712
5713void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5714 struct net_device *netdev, const u8 *buf,
5715 size_t len, gfp_t gfp)
6039f6d2
JM
5716{
5717 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5718 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5719}
5720
5721void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5722 struct net_device *netdev, const u8 *buf,
e6d6e342 5723 size_t len, gfp_t gfp)
6039f6d2 5724{
e6d6e342
JB
5725 nl80211_send_mlme_event(rdev, netdev, buf, len,
5726 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5727}
5728
53b46b84 5729void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5730 struct net_device *netdev, const u8 *buf,
5731 size_t len, gfp_t gfp)
6039f6d2
JM
5732{
5733 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5734 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5735}
5736
53b46b84
JM
5737void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5738 struct net_device *netdev, const u8 *buf,
e6d6e342 5739 size_t len, gfp_t gfp)
6039f6d2
JM
5740{
5741 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5742 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5743}
5744
1b06bb40
LR
5745static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5746 struct net_device *netdev, int cmd,
e6d6e342 5747 const u8 *addr, gfp_t gfp)
1965c853
JM
5748{
5749 struct sk_buff *msg;
5750 void *hdr;
5751
e6d6e342 5752 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5753 if (!msg)
5754 return;
5755
5756 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5757 if (!hdr) {
5758 nlmsg_free(msg);
5759 return;
5760 }
5761
5762 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5763 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5764 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5765 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5766
5767 if (genlmsg_end(msg, hdr) < 0) {
5768 nlmsg_free(msg);
5769 return;
5770 }
5771
463d0183
JB
5772 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5773 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5774 return;
5775
5776 nla_put_failure:
5777 genlmsg_cancel(msg, hdr);
5778 nlmsg_free(msg);
5779}
5780
5781void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5782 struct net_device *netdev, const u8 *addr,
5783 gfp_t gfp)
1965c853
JM
5784{
5785 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5786 addr, gfp);
1965c853
JM
5787}
5788
5789void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5790 struct net_device *netdev, const u8 *addr,
5791 gfp_t gfp)
1965c853 5792{
e6d6e342
JB
5793 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5794 addr, gfp);
1965c853
JM
5795}
5796
b23aa676
SO
5797void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5798 struct net_device *netdev, const u8 *bssid,
5799 const u8 *req_ie, size_t req_ie_len,
5800 const u8 *resp_ie, size_t resp_ie_len,
5801 u16 status, gfp_t gfp)
5802{
5803 struct sk_buff *msg;
5804 void *hdr;
5805
5806 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5807 if (!msg)
5808 return;
5809
5810 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5811 if (!hdr) {
5812 nlmsg_free(msg);
5813 return;
5814 }
5815
5816 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5817 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5818 if (bssid)
5819 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5820 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5821 if (req_ie)
5822 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5823 if (resp_ie)
5824 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5825
5826 if (genlmsg_end(msg, hdr) < 0) {
5827 nlmsg_free(msg);
5828 return;
5829 }
5830
463d0183
JB
5831 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5832 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5833 return;
5834
5835 nla_put_failure:
5836 genlmsg_cancel(msg, hdr);
5837 nlmsg_free(msg);
5838
5839}
5840
5841void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5842 struct net_device *netdev, const u8 *bssid,
5843 const u8 *req_ie, size_t req_ie_len,
5844 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5845{
5846 struct sk_buff *msg;
5847 void *hdr;
5848
5849 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5850 if (!msg)
5851 return;
5852
5853 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5854 if (!hdr) {
5855 nlmsg_free(msg);
5856 return;
5857 }
5858
5859 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5860 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5861 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5862 if (req_ie)
5863 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5864 if (resp_ie)
5865 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5866
5867 if (genlmsg_end(msg, hdr) < 0) {
5868 nlmsg_free(msg);
5869 return;
5870 }
5871
463d0183
JB
5872 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5873 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5874 return;
5875
5876 nla_put_failure:
5877 genlmsg_cancel(msg, hdr);
5878 nlmsg_free(msg);
5879
5880}
5881
5882void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5883 struct net_device *netdev, u16 reason,
667503dd 5884 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5885{
5886 struct sk_buff *msg;
5887 void *hdr;
5888
667503dd 5889 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5890 if (!msg)
5891 return;
5892
5893 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5894 if (!hdr) {
5895 nlmsg_free(msg);
5896 return;
5897 }
5898
5899 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5900 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5901 if (from_ap && reason)
5902 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5903 if (from_ap)
5904 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5905 if (ie)
5906 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5907
5908 if (genlmsg_end(msg, hdr) < 0) {
5909 nlmsg_free(msg);
5910 return;
5911 }
5912
463d0183
JB
5913 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5914 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5915 return;
5916
5917 nla_put_failure:
5918 genlmsg_cancel(msg, hdr);
5919 nlmsg_free(msg);
5920
5921}
5922
04a773ad
JB
5923void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5924 struct net_device *netdev, const u8 *bssid,
5925 gfp_t gfp)
5926{
5927 struct sk_buff *msg;
5928 void *hdr;
5929
fd2120ca 5930 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5931 if (!msg)
5932 return;
5933
5934 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5935 if (!hdr) {
5936 nlmsg_free(msg);
5937 return;
5938 }
5939
5940 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5941 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5942 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5943
5944 if (genlmsg_end(msg, hdr) < 0) {
5945 nlmsg_free(msg);
5946 return;
5947 }
5948
463d0183
JB
5949 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5950 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5951 return;
5952
5953 nla_put_failure:
5954 genlmsg_cancel(msg, hdr);
5955 nlmsg_free(msg);
5956}
5957
a3b8b056
JM
5958void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5959 struct net_device *netdev, const u8 *addr,
5960 enum nl80211_key_type key_type, int key_id,
e6d6e342 5961 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5962{
5963 struct sk_buff *msg;
5964 void *hdr;
5965
e6d6e342 5966 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5967 if (!msg)
5968 return;
5969
5970 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5971 if (!hdr) {
5972 nlmsg_free(msg);
5973 return;
5974 }
5975
5976 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5977 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5978 if (addr)
5979 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5980 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5981 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5982 if (tsc)
5983 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5984
5985 if (genlmsg_end(msg, hdr) < 0) {
5986 nlmsg_free(msg);
5987 return;
5988 }
5989
463d0183
JB
5990 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5991 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5992 return;
5993
5994 nla_put_failure:
5995 genlmsg_cancel(msg, hdr);
5996 nlmsg_free(msg);
5997}
5998
6bad8766
LR
5999void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
6000 struct ieee80211_channel *channel_before,
6001 struct ieee80211_channel *channel_after)
6002{
6003 struct sk_buff *msg;
6004 void *hdr;
6005 struct nlattr *nl_freq;
6006
fd2120ca 6007 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
6008 if (!msg)
6009 return;
6010
6011 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
6012 if (!hdr) {
6013 nlmsg_free(msg);
6014 return;
6015 }
6016
6017 /*
6018 * Since we are applying the beacon hint to a wiphy we know its
6019 * wiphy_idx is valid
6020 */
6021 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
6022
6023 /* Before */
6024 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
6025 if (!nl_freq)
6026 goto nla_put_failure;
6027 if (nl80211_msg_put_channel(msg, channel_before))
6028 goto nla_put_failure;
6029 nla_nest_end(msg, nl_freq);
6030
6031 /* After */
6032 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
6033 if (!nl_freq)
6034 goto nla_put_failure;
6035 if (nl80211_msg_put_channel(msg, channel_after))
6036 goto nla_put_failure;
6037 nla_nest_end(msg, nl_freq);
6038
6039 if (genlmsg_end(msg, hdr) < 0) {
6040 nlmsg_free(msg);
6041 return;
6042 }
6043
463d0183
JB
6044 rcu_read_lock();
6045 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6046 GFP_ATOMIC);
6047 rcu_read_unlock();
6bad8766
LR
6048
6049 return;
6050
6051nla_put_failure:
6052 genlmsg_cancel(msg, hdr);
6053 nlmsg_free(msg);
6054}
6055
9588bbd5
JM
6056static void nl80211_send_remain_on_chan_event(
6057 int cmd, struct cfg80211_registered_device *rdev,
6058 struct net_device *netdev, u64 cookie,
6059 struct ieee80211_channel *chan,
6060 enum nl80211_channel_type channel_type,
6061 unsigned int duration, gfp_t gfp)
6062{
6063 struct sk_buff *msg;
6064 void *hdr;
6065
6066 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6067 if (!msg)
6068 return;
6069
6070 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6071 if (!hdr) {
6072 nlmsg_free(msg);
6073 return;
6074 }
6075
6076 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6077 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6078 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
6079 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
6080 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6081
6082 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6083 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6084
6085 if (genlmsg_end(msg, hdr) < 0) {
6086 nlmsg_free(msg);
6087 return;
6088 }
6089
6090 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6091 nl80211_mlme_mcgrp.id, gfp);
6092 return;
6093
6094 nla_put_failure:
6095 genlmsg_cancel(msg, hdr);
6096 nlmsg_free(msg);
6097}
6098
6099void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6100 struct net_device *netdev, u64 cookie,
6101 struct ieee80211_channel *chan,
6102 enum nl80211_channel_type channel_type,
6103 unsigned int duration, gfp_t gfp)
6104{
6105 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6106 rdev, netdev, cookie, chan,
6107 channel_type, duration, gfp);
6108}
6109
6110void nl80211_send_remain_on_channel_cancel(
6111 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6112 u64 cookie, struct ieee80211_channel *chan,
6113 enum nl80211_channel_type channel_type, gfp_t gfp)
6114{
6115 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6116 rdev, netdev, cookie, chan,
6117 channel_type, 0, gfp);
6118}
6119
98b62183
JB
6120void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6121 struct net_device *dev, const u8 *mac_addr,
6122 struct station_info *sinfo, gfp_t gfp)
6123{
6124 struct sk_buff *msg;
6125
6126 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6127 if (!msg)
6128 return;
6129
6130 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6131 nlmsg_free(msg);
6132 return;
6133 }
6134
6135 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6136 nl80211_mlme_mcgrp.id, gfp);
6137}
6138
2e161f78
JB
6139int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6140 struct net_device *netdev, u32 nlpid,
6141 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
6142{
6143 struct sk_buff *msg;
6144 void *hdr;
6145 int err;
6146
6147 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6148 if (!msg)
6149 return -ENOMEM;
6150
2e161f78 6151 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
6152 if (!hdr) {
6153 nlmsg_free(msg);
6154 return -ENOMEM;
6155 }
6156
6157 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6158 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6159 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6160 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6161
6162 err = genlmsg_end(msg, hdr);
6163 if (err < 0) {
6164 nlmsg_free(msg);
6165 return err;
6166 }
6167
6168 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6169 if (err < 0)
6170 return err;
6171 return 0;
6172
6173 nla_put_failure:
6174 genlmsg_cancel(msg, hdr);
6175 nlmsg_free(msg);
6176 return -ENOBUFS;
6177}
6178
2e161f78
JB
6179void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6180 struct net_device *netdev, u64 cookie,
6181 const u8 *buf, size_t len, bool ack,
6182 gfp_t gfp)
026331c4
JM
6183{
6184 struct sk_buff *msg;
6185 void *hdr;
6186
6187 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6188 if (!msg)
6189 return;
6190
2e161f78 6191 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6192 if (!hdr) {
6193 nlmsg_free(msg);
6194 return;
6195 }
6196
6197 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6198 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6199 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6200 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6201 if (ack)
6202 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6203
6204 if (genlmsg_end(msg, hdr) < 0) {
6205 nlmsg_free(msg);
6206 return;
6207 }
6208
6209 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6210 return;
6211
6212 nla_put_failure:
6213 genlmsg_cancel(msg, hdr);
6214 nlmsg_free(msg);
6215}
6216
d6dc1a38
JO
6217void
6218nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6219 struct net_device *netdev,
6220 enum nl80211_cqm_rssi_threshold_event rssi_event,
6221 gfp_t gfp)
6222{
6223 struct sk_buff *msg;
6224 struct nlattr *pinfoattr;
6225 void *hdr;
6226
6227 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6228 if (!msg)
6229 return;
6230
6231 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6232 if (!hdr) {
6233 nlmsg_free(msg);
6234 return;
6235 }
6236
6237 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6238 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6239
6240 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6241 if (!pinfoattr)
6242 goto nla_put_failure;
6243
6244 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6245 rssi_event);
6246
6247 nla_nest_end(msg, pinfoattr);
6248
6249 if (genlmsg_end(msg, hdr) < 0) {
6250 nlmsg_free(msg);
6251 return;
6252 }
6253
6254 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6255 nl80211_mlme_mcgrp.id, gfp);
6256 return;
6257
6258 nla_put_failure:
6259 genlmsg_cancel(msg, hdr);
6260 nlmsg_free(msg);
6261}
6262
026331c4
JM
6263static int nl80211_netlink_notify(struct notifier_block * nb,
6264 unsigned long state,
6265 void *_notify)
6266{
6267 struct netlink_notify *notify = _notify;
6268 struct cfg80211_registered_device *rdev;
6269 struct wireless_dev *wdev;
6270
6271 if (state != NETLINK_URELEASE)
6272 return NOTIFY_DONE;
6273
6274 rcu_read_lock();
6275
6276 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6277 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6278 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6279
6280 rcu_read_unlock();
6281
6282 return NOTIFY_DONE;
6283}
6284
6285static struct notifier_block nl80211_netlink_notifier = {
6286 .notifier_call = nl80211_netlink_notify,
6287};
6288
55682965
JB
6289/* initialisation/exit functions */
6290
6291int nl80211_init(void)
6292{
0d63cbb5 6293 int err;
55682965 6294
0d63cbb5
MM
6295 err = genl_register_family_with_ops(&nl80211_fam,
6296 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6297 if (err)
6298 return err;
6299
55682965
JB
6300 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6301 if (err)
6302 goto err_out;
6303
2a519311
JB
6304 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6305 if (err)
6306 goto err_out;
6307
73d54c9e
LR
6308 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6309 if (err)
6310 goto err_out;
6311
6039f6d2
JM
6312 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6313 if (err)
6314 goto err_out;
6315
aff89a9b
JB
6316#ifdef CONFIG_NL80211_TESTMODE
6317 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6318 if (err)
6319 goto err_out;
6320#endif
6321
026331c4
JM
6322 err = netlink_register_notifier(&nl80211_netlink_notifier);
6323 if (err)
6324 goto err_out;
6325
55682965
JB
6326 return 0;
6327 err_out:
6328 genl_unregister_family(&nl80211_fam);
6329 return err;
6330}
6331
6332void nl80211_exit(void)
6333{
026331c4 6334 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6335 genl_unregister_family(&nl80211_fam);
6336}