]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: cooperate more with network namespaces
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
08645126 4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
55682965
JB
10#include <linux/list.h>
11#include <linux/if_ether.h>
12#include <linux/ieee80211.h>
13#include <linux/nl80211.h>
14#include <linux/rtnetlink.h>
15#include <linux/netlink.h>
2a519311 16#include <linux/etherdevice.h>
55682965
JB
17#include <net/genetlink.h>
18#include <net/cfg80211.h>
19#include "core.h"
20#include "nl80211.h"
b2e1b302 21#include "reg.h"
55682965
JB
22
23/* the netlink family */
24static struct genl_family nl80211_fam = {
25 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
26 .name = "nl80211", /* have users key off the name instead */
27 .hdrsize = 0, /* no private header */
28 .version = 1, /* no particular meaning now */
29 .maxattr = NL80211_ATTR_MAX,
30};
31
79c97e97
JB
32/* internal helper: get rdev and dev */
33static int get_rdev_dev_by_info_ifindex(struct nlattr **attrs,
34 struct cfg80211_registered_device **rdev,
55682965
JB
35 struct net_device **dev)
36{
37 int ifindex;
38
bba95fef 39 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
40 return -EINVAL;
41
bba95fef 42 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
55682965
JB
43 *dev = dev_get_by_index(&init_net, ifindex);
44 if (!*dev)
45 return -ENODEV;
46
79c97e97
JB
47 *rdev = cfg80211_get_dev_from_ifindex(ifindex);
48 if (IS_ERR(*rdev)) {
55682965 49 dev_put(*dev);
79c97e97 50 return PTR_ERR(*rdev);
55682965
JB
51 }
52
53 return 0;
54}
55
56/* policy for the attributes */
57static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
58 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
59 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 60 .len = 20-1 },
31888487 61 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 62 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 63 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
64 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
65 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
66 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
67 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
55682965
JB
68
69 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
70 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
71 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
72
73 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 74 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 75
b9454e83 76 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
77 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
78 .len = WLAN_MAX_KEY_LEN },
79 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
80 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
81 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 82 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
83
84 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
85 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
86 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
87 .len = IEEE80211_MAX_DATA_LEN },
88 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
89 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
90 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
91 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
92 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
93 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
94 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 95 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 96 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 97 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
98 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
99 .len = IEEE80211_MAX_MESH_ID_LEN },
100 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 101
b2e1b302
LR
102 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
103 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
104
9f1ba906
JM
105 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
106 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
107 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
108 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
109 .len = NL80211_MAX_SUPP_RATES },
36aedc90 110
93da9cc1 111 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
112
36aedc90
JM
113 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
114 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
115
116 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
117 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
118 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
119 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
120 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
121
122 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
123 .len = IEEE80211_MAX_SSID_LEN },
124 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
125 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 126 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 127 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 128 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
129 [NL80211_ATTR_STA_FLAGS2] = {
130 .len = sizeof(struct nl80211_sta_flag_update),
131 },
3f77316c 132 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
133 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
134 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
135 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
55682965
JB
136};
137
b9454e83
JB
138/* policy for the attributes */
139static struct nla_policy
140nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
fffd0934 141 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
142 [NL80211_KEY_IDX] = { .type = NLA_U8 },
143 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
144 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
145 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
146 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
147};
148
f4a11bb0
JB
149/* IE validation */
150static bool is_valid_ie_attr(const struct nlattr *attr)
151{
152 const u8 *pos;
153 int len;
154
155 if (!attr)
156 return true;
157
158 pos = nla_data(attr);
159 len = nla_len(attr);
160
161 while (len) {
162 u8 elemlen;
163
164 if (len < 2)
165 return false;
166 len -= 2;
167
168 elemlen = pos[1];
169 if (elemlen > len)
170 return false;
171
172 len -= elemlen;
173 pos += 2 + elemlen;
174 }
175
176 return true;
177}
178
55682965
JB
179/* message building helper */
180static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
181 int flags, u8 cmd)
182{
183 /* since there is no private header just add the generic one */
184 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
185}
186
5dab3b8a
LR
187static int nl80211_msg_put_channel(struct sk_buff *msg,
188 struct ieee80211_channel *chan)
189{
190 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
191 chan->center_freq);
192
193 if (chan->flags & IEEE80211_CHAN_DISABLED)
194 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
195 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
196 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
197 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
198 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
199 if (chan->flags & IEEE80211_CHAN_RADAR)
200 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
201
202 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
203 DBM_TO_MBM(chan->max_power));
204
205 return 0;
206
207 nla_put_failure:
208 return -ENOBUFS;
209}
210
55682965
JB
211/* netlink command implementations */
212
b9454e83
JB
213struct key_parse {
214 struct key_params p;
215 int idx;
216 bool def, defmgmt;
217};
218
219static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
220{
221 struct nlattr *tb[NL80211_KEY_MAX + 1];
222 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
223 nl80211_key_policy);
224 if (err)
225 return err;
226
227 k->def = !!tb[NL80211_KEY_DEFAULT];
228 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
229
230 if (tb[NL80211_KEY_IDX])
231 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
232
233 if (tb[NL80211_KEY_DATA]) {
234 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
235 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
236 }
237
238 if (tb[NL80211_KEY_SEQ]) {
239 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
240 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
241 }
242
243 if (tb[NL80211_KEY_CIPHER])
244 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
245
246 return 0;
247}
248
249static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
250{
251 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
252 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
253 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
254 }
255
256 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
257 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
258 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
259 }
260
261 if (info->attrs[NL80211_ATTR_KEY_IDX])
262 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
263
264 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
265 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
266
267 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
268 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
269
270 return 0;
271}
272
273static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
274{
275 int err;
276
277 memset(k, 0, sizeof(*k));
278 k->idx = -1;
279
280 if (info->attrs[NL80211_ATTR_KEY])
281 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
282 else
283 err = nl80211_parse_key_old(info, k);
284
285 if (err)
286 return err;
287
288 if (k->def && k->defmgmt)
289 return -EINVAL;
290
291 if (k->idx != -1) {
292 if (k->defmgmt) {
293 if (k->idx < 4 || k->idx > 5)
294 return -EINVAL;
295 } else if (k->def) {
296 if (k->idx < 0 || k->idx > 3)
297 return -EINVAL;
298 } else {
299 if (k->idx < 0 || k->idx > 5)
300 return -EINVAL;
301 }
302 }
303
304 return 0;
305}
306
fffd0934
JB
307static struct cfg80211_cached_keys *
308nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
309 struct nlattr *keys)
310{
311 struct key_parse parse;
312 struct nlattr *key;
313 struct cfg80211_cached_keys *result;
314 int rem, err, def = 0;
315
316 result = kzalloc(sizeof(*result), GFP_KERNEL);
317 if (!result)
318 return ERR_PTR(-ENOMEM);
319
320 result->def = -1;
321 result->defmgmt = -1;
322
323 nla_for_each_nested(key, keys, rem) {
324 memset(&parse, 0, sizeof(parse));
325 parse.idx = -1;
326
327 err = nl80211_parse_key_new(key, &parse);
328 if (err)
329 goto error;
330 err = -EINVAL;
331 if (!parse.p.key)
332 goto error;
333 if (parse.idx < 0 || parse.idx > 4)
334 goto error;
335 if (parse.def) {
336 if (def)
337 goto error;
338 def = 1;
339 result->def = parse.idx;
340 } else if (parse.defmgmt)
341 goto error;
342 err = cfg80211_validate_key_settings(rdev, &parse.p,
343 parse.idx, NULL);
344 if (err)
345 goto error;
346 result->params[parse.idx].cipher = parse.p.cipher;
347 result->params[parse.idx].key_len = parse.p.key_len;
348 result->params[parse.idx].key = result->data[parse.idx];
349 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
350 }
351
352 return result;
353 error:
354 kfree(result);
355 return ERR_PTR(err);
356}
357
358static int nl80211_key_allowed(struct wireless_dev *wdev)
359{
360 ASSERT_WDEV_LOCK(wdev);
361
362 if (!netif_running(wdev->netdev))
363 return -ENETDOWN;
364
365 switch (wdev->iftype) {
366 case NL80211_IFTYPE_AP:
367 case NL80211_IFTYPE_AP_VLAN:
368 break;
369 case NL80211_IFTYPE_ADHOC:
370 if (!wdev->current_bss)
371 return -ENOLINK;
372 break;
373 case NL80211_IFTYPE_STATION:
374 if (wdev->sme_state != CFG80211_SME_CONNECTED)
375 return -ENOLINK;
376 break;
377 default:
378 return -EINVAL;
379 }
380
381 return 0;
382}
383
55682965
JB
384static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
385 struct cfg80211_registered_device *dev)
386{
387 void *hdr;
ee688b00
JB
388 struct nlattr *nl_bands, *nl_band;
389 struct nlattr *nl_freqs, *nl_freq;
390 struct nlattr *nl_rates, *nl_rate;
f59ac048 391 struct nlattr *nl_modes;
8fdc621d 392 struct nlattr *nl_cmds;
ee688b00
JB
393 enum ieee80211_band band;
394 struct ieee80211_channel *chan;
395 struct ieee80211_rate *rate;
396 int i;
f59ac048 397 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
398
399 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
400 if (!hdr)
401 return -1;
402
b5850a7a 403 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 404 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca
JM
405
406 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
407 dev->wiphy.retry_short);
408 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
409 dev->wiphy.retry_long);
410 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
411 dev->wiphy.frag_threshold);
412 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
413 dev->wiphy.rts_threshold);
414
2a519311
JB
415 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
416 dev->wiphy.max_scan_ssids);
18a83659
JB
417 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
418 dev->wiphy.max_scan_ie_len);
ee688b00 419
25e47c18
JB
420 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
421 sizeof(u32) * dev->wiphy.n_cipher_suites,
422 dev->wiphy.cipher_suites);
423
f59ac048
LR
424 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
425 if (!nl_modes)
426 goto nla_put_failure;
427
428 i = 0;
429 while (ifmodes) {
430 if (ifmodes & 1)
431 NLA_PUT_FLAG(msg, i);
432 ifmodes >>= 1;
433 i++;
434 }
435
436 nla_nest_end(msg, nl_modes);
437
ee688b00
JB
438 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
439 if (!nl_bands)
440 goto nla_put_failure;
441
442 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
443 if (!dev->wiphy.bands[band])
444 continue;
445
446 nl_band = nla_nest_start(msg, band);
447 if (!nl_band)
448 goto nla_put_failure;
449
d51626df
JB
450 /* add HT info */
451 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
452 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
453 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
454 &dev->wiphy.bands[band]->ht_cap.mcs);
455 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
456 dev->wiphy.bands[band]->ht_cap.cap);
457 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
458 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
459 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
460 dev->wiphy.bands[band]->ht_cap.ampdu_density);
461 }
462
ee688b00
JB
463 /* add frequencies */
464 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
465 if (!nl_freqs)
466 goto nla_put_failure;
467
468 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
469 nl_freq = nla_nest_start(msg, i);
470 if (!nl_freq)
471 goto nla_put_failure;
472
473 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
474
475 if (nl80211_msg_put_channel(msg, chan))
476 goto nla_put_failure;
e2f367f2 477
ee688b00
JB
478 nla_nest_end(msg, nl_freq);
479 }
480
481 nla_nest_end(msg, nl_freqs);
482
483 /* add bitrates */
484 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
485 if (!nl_rates)
486 goto nla_put_failure;
487
488 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
489 nl_rate = nla_nest_start(msg, i);
490 if (!nl_rate)
491 goto nla_put_failure;
492
493 rate = &dev->wiphy.bands[band]->bitrates[i];
494 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
495 rate->bitrate);
496 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
497 NLA_PUT_FLAG(msg,
498 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
499
500 nla_nest_end(msg, nl_rate);
501 }
502
503 nla_nest_end(msg, nl_rates);
504
505 nla_nest_end(msg, nl_band);
506 }
507 nla_nest_end(msg, nl_bands);
508
8fdc621d
JB
509 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
510 if (!nl_cmds)
511 goto nla_put_failure;
512
513 i = 0;
514#define CMD(op, n) \
515 do { \
516 if (dev->ops->op) { \
517 i++; \
518 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
519 } \
520 } while (0)
521
522 CMD(add_virtual_intf, NEW_INTERFACE);
523 CMD(change_virtual_intf, SET_INTERFACE);
524 CMD(add_key, NEW_KEY);
525 CMD(add_beacon, NEW_BEACON);
526 CMD(add_station, NEW_STATION);
527 CMD(add_mpath, NEW_MPATH);
528 CMD(set_mesh_params, SET_MESH_PARAMS);
529 CMD(change_bss, SET_BSS);
636a5d36
JM
530 CMD(auth, AUTHENTICATE);
531 CMD(assoc, ASSOCIATE);
532 CMD(deauth, DEAUTHENTICATE);
533 CMD(disassoc, DISASSOCIATE);
04a773ad 534 CMD(join_ibss, JOIN_IBSS);
8fdc621d
JB
535
536#undef CMD
b23aa676 537
6829c878 538 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
539 i++;
540 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
541 }
542
6829c878 543 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
544 i++;
545 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
546 }
547
8fdc621d
JB
548 nla_nest_end(msg, nl_cmds);
549
55682965
JB
550 return genlmsg_end(msg, hdr);
551
552 nla_put_failure:
bc3ed28c
TG
553 genlmsg_cancel(msg, hdr);
554 return -EMSGSIZE;
55682965
JB
555}
556
557static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
558{
559 int idx = 0;
560 int start = cb->args[0];
561 struct cfg80211_registered_device *dev;
562
a1794390 563 mutex_lock(&cfg80211_mutex);
79c97e97 564 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
b4637271 565 if (++idx <= start)
55682965
JB
566 continue;
567 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
568 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
569 dev) < 0) {
570 idx--;
55682965 571 break;
b4637271 572 }
55682965 573 }
a1794390 574 mutex_unlock(&cfg80211_mutex);
55682965
JB
575
576 cb->args[0] = idx;
577
578 return skb->len;
579}
580
581static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
582{
583 struct sk_buff *msg;
584 struct cfg80211_registered_device *dev;
585
586 dev = cfg80211_get_dev_from_info(info);
587 if (IS_ERR(dev))
588 return PTR_ERR(dev);
589
fd2120ca 590 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
591 if (!msg)
592 goto out_err;
593
594 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
595 goto out_free;
596
4d0c8aea 597 cfg80211_unlock_rdev(dev);
55682965 598
134e6375 599 return genlmsg_reply(msg, info);
55682965
JB
600
601 out_free:
602 nlmsg_free(msg);
603 out_err:
4d0c8aea 604 cfg80211_unlock_rdev(dev);
55682965
JB
605 return -ENOBUFS;
606}
607
31888487
JM
608static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
609 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
610 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
611 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
612 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
613 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
614};
615
616static int parse_txq_params(struct nlattr *tb[],
617 struct ieee80211_txq_params *txq_params)
618{
619 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
620 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
621 !tb[NL80211_TXQ_ATTR_AIFS])
622 return -EINVAL;
623
624 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
625 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
626 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
627 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
628 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
629
630 return 0;
631}
632
55682965
JB
633static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
634{
635 struct cfg80211_registered_device *rdev;
31888487
JM
636 int result = 0, rem_txq_params = 0;
637 struct nlattr *nl_txq_params;
b9a5f8ca
JM
638 u32 changed;
639 u8 retry_short = 0, retry_long = 0;
640 u32 frag_threshold = 0, rts_threshold = 0;
55682965 641
4bbf4d56 642 rtnl_lock();
55682965 643
4bbf4d56
JB
644 mutex_lock(&cfg80211_mutex);
645
79c97e97 646 rdev = __cfg80211_rdev_from_info(info);
4bbf4d56 647 if (IS_ERR(rdev)) {
1f5fc70a 648 mutex_unlock(&cfg80211_mutex);
4bbf4d56
JB
649 result = PTR_ERR(rdev);
650 goto unlock;
651 }
652
653 mutex_lock(&rdev->mtx);
654
655 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
656 result = cfg80211_dev_rename(
657 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
658
659 mutex_unlock(&cfg80211_mutex);
660
661 if (result)
662 goto bad_res;
31888487
JM
663
664 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
665 struct ieee80211_txq_params txq_params;
666 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
667
668 if (!rdev->ops->set_txq_params) {
669 result = -EOPNOTSUPP;
670 goto bad_res;
671 }
672
673 nla_for_each_nested(nl_txq_params,
674 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
675 rem_txq_params) {
676 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
677 nla_data(nl_txq_params),
678 nla_len(nl_txq_params),
679 txq_params_policy);
680 result = parse_txq_params(tb, &txq_params);
681 if (result)
682 goto bad_res;
683
684 result = rdev->ops->set_txq_params(&rdev->wiphy,
685 &txq_params);
686 if (result)
687 goto bad_res;
688 }
689 }
55682965 690
72bdcf34 691 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
094d05dc 692 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
72bdcf34 693 struct ieee80211_channel *chan;
306d6112 694 struct ieee80211_sta_ht_cap *ht_cap;
294196ab 695 u32 freq;
72bdcf34
JM
696
697 if (!rdev->ops->set_channel) {
698 result = -EOPNOTSUPP;
699 goto bad_res;
700 }
701
306d6112
JB
702 result = -EINVAL;
703
094d05dc
S
704 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
705 channel_type = nla_get_u32(info->attrs[
706 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
707 if (channel_type != NL80211_CHAN_NO_HT &&
708 channel_type != NL80211_CHAN_HT20 &&
709 channel_type != NL80211_CHAN_HT40PLUS &&
710 channel_type != NL80211_CHAN_HT40MINUS)
72bdcf34 711 goto bad_res;
72bdcf34
JM
712 }
713
714 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
715 chan = ieee80211_get_channel(&rdev->wiphy, freq);
306d6112
JB
716
717 /* Primary channel not allowed */
718 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
72bdcf34 719 goto bad_res;
306d6112 720
294196ab
LR
721 if (channel_type == NL80211_CHAN_HT40MINUS &&
722 (chan->flags & IEEE80211_CHAN_NO_HT40MINUS))
306d6112 723 goto bad_res;
294196ab
LR
724 else if (channel_type == NL80211_CHAN_HT40PLUS &&
725 (chan->flags & IEEE80211_CHAN_NO_HT40PLUS))
306d6112
JB
726 goto bad_res;
727
294196ab
LR
728 /*
729 * At this point we know if that if HT40 was requested
730 * we are allowed to use it and the extension channel
731 * exists.
732 */
306d6112 733
294196ab 734 ht_cap = &rdev->wiphy.bands[chan->band]->ht_cap;
306d6112 735
294196ab
LR
736 /* no HT capabilities or intolerant */
737 if (channel_type != NL80211_CHAN_NO_HT) {
738 if (!ht_cap->ht_supported)
739 goto bad_res;
306d6112
JB
740 if (!(ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) ||
741 (ht_cap->cap & IEEE80211_HT_CAP_40MHZ_INTOLERANT))
742 goto bad_res;
72bdcf34
JM
743 }
744
745 result = rdev->ops->set_channel(&rdev->wiphy, chan,
094d05dc 746 channel_type);
72bdcf34
JM
747 if (result)
748 goto bad_res;
749 }
750
b9a5f8ca
JM
751 changed = 0;
752
753 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
754 retry_short = nla_get_u8(
755 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
756 if (retry_short == 0) {
757 result = -EINVAL;
758 goto bad_res;
759 }
760 changed |= WIPHY_PARAM_RETRY_SHORT;
761 }
762
763 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
764 retry_long = nla_get_u8(
765 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
766 if (retry_long == 0) {
767 result = -EINVAL;
768 goto bad_res;
769 }
770 changed |= WIPHY_PARAM_RETRY_LONG;
771 }
772
773 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
774 frag_threshold = nla_get_u32(
775 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
776 if (frag_threshold < 256) {
777 result = -EINVAL;
778 goto bad_res;
779 }
780 if (frag_threshold != (u32) -1) {
781 /*
782 * Fragments (apart from the last one) are required to
783 * have even length. Make the fragmentation code
784 * simpler by stripping LSB should someone try to use
785 * odd threshold value.
786 */
787 frag_threshold &= ~0x1;
788 }
789 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
790 }
791
792 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
793 rts_threshold = nla_get_u32(
794 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
795 changed |= WIPHY_PARAM_RTS_THRESHOLD;
796 }
797
798 if (changed) {
799 u8 old_retry_short, old_retry_long;
800 u32 old_frag_threshold, old_rts_threshold;
801
802 if (!rdev->ops->set_wiphy_params) {
803 result = -EOPNOTSUPP;
804 goto bad_res;
805 }
806
807 old_retry_short = rdev->wiphy.retry_short;
808 old_retry_long = rdev->wiphy.retry_long;
809 old_frag_threshold = rdev->wiphy.frag_threshold;
810 old_rts_threshold = rdev->wiphy.rts_threshold;
811
812 if (changed & WIPHY_PARAM_RETRY_SHORT)
813 rdev->wiphy.retry_short = retry_short;
814 if (changed & WIPHY_PARAM_RETRY_LONG)
815 rdev->wiphy.retry_long = retry_long;
816 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
817 rdev->wiphy.frag_threshold = frag_threshold;
818 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
819 rdev->wiphy.rts_threshold = rts_threshold;
820
821 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
822 if (result) {
823 rdev->wiphy.retry_short = old_retry_short;
824 rdev->wiphy.retry_long = old_retry_long;
825 rdev->wiphy.frag_threshold = old_frag_threshold;
826 rdev->wiphy.rts_threshold = old_rts_threshold;
827 }
828 }
72bdcf34 829
306d6112 830 bad_res:
4bbf4d56
JB
831 mutex_unlock(&rdev->mtx);
832 unlock:
833 rtnl_unlock();
55682965
JB
834 return result;
835}
836
837
838static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 839 struct cfg80211_registered_device *rdev,
55682965
JB
840 struct net_device *dev)
841{
842 void *hdr;
843
844 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
845 if (!hdr)
846 return -1;
847
848 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 849 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 850 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 851 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
55682965
JB
852 return genlmsg_end(msg, hdr);
853
854 nla_put_failure:
bc3ed28c
TG
855 genlmsg_cancel(msg, hdr);
856 return -EMSGSIZE;
55682965
JB
857}
858
859static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
860{
861 int wp_idx = 0;
862 int if_idx = 0;
863 int wp_start = cb->args[0];
864 int if_start = cb->args[1];
865 struct cfg80211_registered_device *dev;
866 struct wireless_dev *wdev;
867
a1794390 868 mutex_lock(&cfg80211_mutex);
79c97e97 869 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
bba95fef
JB
870 if (wp_idx < wp_start) {
871 wp_idx++;
55682965 872 continue;
bba95fef 873 }
55682965
JB
874 if_idx = 0;
875
876 mutex_lock(&dev->devlist_mtx);
877 list_for_each_entry(wdev, &dev->netdev_list, list) {
bba95fef
JB
878 if (if_idx < if_start) {
879 if_idx++;
55682965 880 continue;
bba95fef 881 }
55682965
JB
882 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
883 cb->nlh->nlmsg_seq, NLM_F_MULTI,
d726405a 884 dev, wdev->netdev) < 0) {
bba95fef
JB
885 mutex_unlock(&dev->devlist_mtx);
886 goto out;
887 }
888 if_idx++;
55682965
JB
889 }
890 mutex_unlock(&dev->devlist_mtx);
bba95fef
JB
891
892 wp_idx++;
55682965 893 }
bba95fef 894 out:
a1794390 895 mutex_unlock(&cfg80211_mutex);
55682965
JB
896
897 cb->args[0] = wp_idx;
898 cb->args[1] = if_idx;
899
900 return skb->len;
901}
902
903static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
904{
905 struct sk_buff *msg;
906 struct cfg80211_registered_device *dev;
907 struct net_device *netdev;
908 int err;
909
79c97e97 910 err = get_rdev_dev_by_info_ifindex(info->attrs, &dev, &netdev);
55682965
JB
911 if (err)
912 return err;
913
fd2120ca 914 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
915 if (!msg)
916 goto out_err;
917
d726405a
JB
918 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
919 dev, netdev) < 0)
55682965
JB
920 goto out_free;
921
922 dev_put(netdev);
4d0c8aea 923 cfg80211_unlock_rdev(dev);
55682965 924
134e6375 925 return genlmsg_reply(msg, info);
55682965
JB
926
927 out_free:
928 nlmsg_free(msg);
929 out_err:
930 dev_put(netdev);
4d0c8aea 931 cfg80211_unlock_rdev(dev);
55682965
JB
932 return -ENOBUFS;
933}
934
66f7ac50
MW
935static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
936 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
937 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
938 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
939 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
940 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
941};
942
943static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
944{
945 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
946 int flag;
947
948 *mntrflags = 0;
949
950 if (!nla)
951 return -EINVAL;
952
953 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
954 nla, mntr_flags_policy))
955 return -EINVAL;
956
957 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
958 if (flags[flag])
959 *mntrflags |= (1<<flag);
960
961 return 0;
962}
963
55682965
JB
964static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
965{
79c97e97 966 struct cfg80211_registered_device *rdev;
2ec600d6 967 struct vif_params params;
e36d56b6 968 int err;
04a773ad 969 enum nl80211_iftype otype, ntype;
55682965 970 struct net_device *dev;
92ffe055 971 u32 _flags, *flags = NULL;
ac7f9cfa 972 bool change = false;
55682965 973
2ec600d6
LCC
974 memset(&params, 0, sizeof(params));
975
3b85875a
JB
976 rtnl_lock();
977
79c97e97 978 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
55682965 979 if (err)
3b85875a
JB
980 goto unlock_rtnl;
981
04a773ad 982 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 983
723b038d 984 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 985 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 986 if (otype != ntype)
ac7f9cfa 987 change = true;
04a773ad 988 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 989 err = -EINVAL;
723b038d 990 goto unlock;
ac7f9cfa 991 }
723b038d
JB
992 }
993
79c97e97
JB
994 if (!rdev->ops->change_virtual_intf ||
995 !(rdev->wiphy.interface_modes & (1 << ntype))) {
55682965
JB
996 err = -EOPNOTSUPP;
997 goto unlock;
998 }
999
92ffe055 1000 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1001 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1002 err = -EINVAL;
1003 goto unlock;
1004 }
2ec600d6
LCC
1005 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1006 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1007 change = true;
2ec600d6
LCC
1008 }
1009
92ffe055 1010 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1011 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1012 err = -EINVAL;
1013 goto unlock;
1014 }
1015 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1016 &_flags);
ac7f9cfa
JB
1017 if (err)
1018 goto unlock;
1019
1020 flags = &_flags;
1021 change = true;
92ffe055 1022 }
3b85875a 1023
ac7f9cfa 1024 if (change)
79c97e97 1025 err = rdev->ops->change_virtual_intf(&rdev->wiphy, dev,
04a773ad 1026 ntype, flags, &params);
ac7f9cfa
JB
1027 else
1028 err = 0;
60719ffd 1029
e36d56b6 1030 WARN_ON(!err && dev->ieee80211_ptr->iftype != ntype);
04a773ad 1031
e36d56b6 1032 if (!err && (ntype != otype)) {
04a773ad 1033 if (otype == NL80211_IFTYPE_ADHOC)
9d308429 1034 cfg80211_clear_ibss(dev, false);
04a773ad 1035 }
60719ffd 1036
55682965 1037 unlock:
e36d56b6 1038 dev_put(dev);
79c97e97 1039 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1040 unlock_rtnl:
1041 rtnl_unlock();
55682965
JB
1042 return err;
1043}
1044
1045static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1046{
79c97e97 1047 struct cfg80211_registered_device *rdev;
2ec600d6 1048 struct vif_params params;
55682965
JB
1049 int err;
1050 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1051 u32 flags;
55682965 1052
2ec600d6
LCC
1053 memset(&params, 0, sizeof(params));
1054
55682965
JB
1055 if (!info->attrs[NL80211_ATTR_IFNAME])
1056 return -EINVAL;
1057
1058 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1059 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1060 if (type > NL80211_IFTYPE_MAX)
1061 return -EINVAL;
1062 }
1063
3b85875a
JB
1064 rtnl_lock();
1065
79c97e97
JB
1066 rdev = cfg80211_get_dev_from_info(info);
1067 if (IS_ERR(rdev)) {
1068 err = PTR_ERR(rdev);
3b85875a
JB
1069 goto unlock_rtnl;
1070 }
55682965 1071
79c97e97
JB
1072 if (!rdev->ops->add_virtual_intf ||
1073 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1074 err = -EOPNOTSUPP;
1075 goto unlock;
1076 }
1077
2ec600d6
LCC
1078 if (type == NL80211_IFTYPE_MESH_POINT &&
1079 info->attrs[NL80211_ATTR_MESH_ID]) {
1080 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1081 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1082 }
1083
66f7ac50
MW
1084 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1085 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1086 &flags);
79c97e97 1087 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1088 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1089 type, err ? NULL : &flags, &params);
2ec600d6 1090
55682965 1091 unlock:
79c97e97 1092 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1093 unlock_rtnl:
1094 rtnl_unlock();
55682965
JB
1095 return err;
1096}
1097
1098static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1099{
79c97e97 1100 struct cfg80211_registered_device *rdev;
55682965
JB
1101 int ifindex, err;
1102 struct net_device *dev;
1103
3b85875a
JB
1104 rtnl_lock();
1105
79c97e97 1106 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
55682965 1107 if (err)
3b85875a 1108 goto unlock_rtnl;
55682965
JB
1109 ifindex = dev->ifindex;
1110 dev_put(dev);
1111
79c97e97 1112 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1113 err = -EOPNOTSUPP;
1114 goto out;
1115 }
1116
79c97e97 1117 err = rdev->ops->del_virtual_intf(&rdev->wiphy, ifindex);
55682965
JB
1118
1119 out:
79c97e97 1120 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1121 unlock_rtnl:
1122 rtnl_unlock();
55682965
JB
1123 return err;
1124}
1125
41ade00f
JB
1126struct get_key_cookie {
1127 struct sk_buff *msg;
1128 int error;
b9454e83 1129 int idx;
41ade00f
JB
1130};
1131
1132static void get_key_callback(void *c, struct key_params *params)
1133{
b9454e83 1134 struct nlattr *key;
41ade00f
JB
1135 struct get_key_cookie *cookie = c;
1136
1137 if (params->key)
1138 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1139 params->key_len, params->key);
1140
1141 if (params->seq)
1142 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1143 params->seq_len, params->seq);
1144
1145 if (params->cipher)
1146 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1147 params->cipher);
1148
b9454e83
JB
1149 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1150 if (!key)
1151 goto nla_put_failure;
1152
1153 if (params->key)
1154 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1155 params->key_len, params->key);
1156
1157 if (params->seq)
1158 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1159 params->seq_len, params->seq);
1160
1161 if (params->cipher)
1162 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1163 params->cipher);
1164
1165 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1166
1167 nla_nest_end(cookie->msg, key);
1168
41ade00f
JB
1169 return;
1170 nla_put_failure:
1171 cookie->error = 1;
1172}
1173
1174static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1175{
79c97e97 1176 struct cfg80211_registered_device *rdev;
41ade00f
JB
1177 int err;
1178 struct net_device *dev;
1179 u8 key_idx = 0;
1180 u8 *mac_addr = NULL;
1181 struct get_key_cookie cookie = {
1182 .error = 0,
1183 };
1184 void *hdr;
1185 struct sk_buff *msg;
1186
1187 if (info->attrs[NL80211_ATTR_KEY_IDX])
1188 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1189
3cfcf6ac 1190 if (key_idx > 5)
41ade00f
JB
1191 return -EINVAL;
1192
1193 if (info->attrs[NL80211_ATTR_MAC])
1194 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1195
3b85875a
JB
1196 rtnl_lock();
1197
79c97e97 1198 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
41ade00f 1199 if (err)
3b85875a 1200 goto unlock_rtnl;
41ade00f 1201
79c97e97 1202 if (!rdev->ops->get_key) {
41ade00f
JB
1203 err = -EOPNOTSUPP;
1204 goto out;
1205 }
1206
fd2120ca 1207 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1208 if (!msg) {
1209 err = -ENOMEM;
1210 goto out;
1211 }
1212
1213 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1214 NL80211_CMD_NEW_KEY);
1215
1216 if (IS_ERR(hdr)) {
1217 err = PTR_ERR(hdr);
6c95e2a2 1218 goto free_msg;
41ade00f
JB
1219 }
1220
1221 cookie.msg = msg;
b9454e83 1222 cookie.idx = key_idx;
41ade00f
JB
1223
1224 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1225 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1226 if (mac_addr)
1227 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1228
79c97e97 1229 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1230 &cookie, get_key_callback);
41ade00f
JB
1231
1232 if (err)
6c95e2a2 1233 goto free_msg;
41ade00f
JB
1234
1235 if (cookie.error)
1236 goto nla_put_failure;
1237
1238 genlmsg_end(msg, hdr);
134e6375 1239 err = genlmsg_reply(msg, info);
41ade00f
JB
1240 goto out;
1241
1242 nla_put_failure:
1243 err = -ENOBUFS;
6c95e2a2 1244 free_msg:
41ade00f
JB
1245 nlmsg_free(msg);
1246 out:
79c97e97 1247 cfg80211_unlock_rdev(rdev);
41ade00f 1248 dev_put(dev);
3b85875a
JB
1249 unlock_rtnl:
1250 rtnl_unlock();
1251
41ade00f
JB
1252 return err;
1253}
1254
1255static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1256{
79c97e97 1257 struct cfg80211_registered_device *rdev;
b9454e83 1258 struct key_parse key;
41ade00f
JB
1259 int err;
1260 struct net_device *dev;
3cfcf6ac
JM
1261 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1262 u8 key_index);
41ade00f 1263
b9454e83
JB
1264 err = nl80211_parse_key(info, &key);
1265 if (err)
1266 return err;
41ade00f 1267
b9454e83 1268 if (key.idx < 0)
41ade00f
JB
1269 return -EINVAL;
1270
b9454e83
JB
1271 /* only support setting default key */
1272 if (!key.def && !key.defmgmt)
41ade00f
JB
1273 return -EINVAL;
1274
3b85875a
JB
1275 rtnl_lock();
1276
79c97e97 1277 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
41ade00f 1278 if (err)
3b85875a 1279 goto unlock_rtnl;
41ade00f 1280
b9454e83 1281 if (key.def)
79c97e97 1282 func = rdev->ops->set_default_key;
3cfcf6ac 1283 else
79c97e97 1284 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1285
1286 if (!func) {
41ade00f
JB
1287 err = -EOPNOTSUPP;
1288 goto out;
1289 }
1290
fffd0934
JB
1291 wdev_lock(dev->ieee80211_ptr);
1292 err = nl80211_key_allowed(dev->ieee80211_ptr);
1293 if (!err)
1294 err = func(&rdev->wiphy, dev, key.idx);
1295
08645126
JB
1296#ifdef CONFIG_WIRELESS_EXT
1297 if (!err) {
79c97e97 1298 if (func == rdev->ops->set_default_key)
b9454e83 1299 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1300 else
b9454e83 1301 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1302 }
1303#endif
fffd0934 1304 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1305
1306 out:
79c97e97 1307 cfg80211_unlock_rdev(rdev);
41ade00f 1308 dev_put(dev);
3b85875a
JB
1309
1310 unlock_rtnl:
1311 rtnl_unlock();
1312
41ade00f
JB
1313 return err;
1314}
1315
1316static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1317{
79c97e97 1318 struct cfg80211_registered_device *rdev;
fffd0934 1319 int err;
41ade00f 1320 struct net_device *dev;
b9454e83 1321 struct key_parse key;
41ade00f
JB
1322 u8 *mac_addr = NULL;
1323
b9454e83
JB
1324 err = nl80211_parse_key(info, &key);
1325 if (err)
1326 return err;
41ade00f 1327
b9454e83 1328 if (!key.p.key)
41ade00f
JB
1329 return -EINVAL;
1330
41ade00f
JB
1331 if (info->attrs[NL80211_ATTR_MAC])
1332 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1333
3b85875a
JB
1334 rtnl_lock();
1335
79c97e97 1336 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
41ade00f 1337 if (err)
3b85875a 1338 goto unlock_rtnl;
41ade00f 1339
fffd0934
JB
1340 if (!rdev->ops->add_key) {
1341 err = -EOPNOTSUPP;
25e47c18
JB
1342 goto out;
1343 }
1344
fffd0934
JB
1345 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1346 err = -EINVAL;
41ade00f
JB
1347 goto out;
1348 }
1349
fffd0934
JB
1350 wdev_lock(dev->ieee80211_ptr);
1351 err = nl80211_key_allowed(dev->ieee80211_ptr);
1352 if (!err)
1353 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1354 mac_addr, &key.p);
1355 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1356
1357 out:
79c97e97 1358 cfg80211_unlock_rdev(rdev);
41ade00f 1359 dev_put(dev);
3b85875a
JB
1360 unlock_rtnl:
1361 rtnl_unlock();
1362
41ade00f
JB
1363 return err;
1364}
1365
1366static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1367{
79c97e97 1368 struct cfg80211_registered_device *rdev;
41ade00f
JB
1369 int err;
1370 struct net_device *dev;
41ade00f 1371 u8 *mac_addr = NULL;
b9454e83 1372 struct key_parse key;
41ade00f 1373
b9454e83
JB
1374 err = nl80211_parse_key(info, &key);
1375 if (err)
1376 return err;
41ade00f
JB
1377
1378 if (info->attrs[NL80211_ATTR_MAC])
1379 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1380
3b85875a
JB
1381 rtnl_lock();
1382
79c97e97 1383 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
41ade00f 1384 if (err)
3b85875a 1385 goto unlock_rtnl;
41ade00f 1386
79c97e97 1387 if (!rdev->ops->del_key) {
41ade00f
JB
1388 err = -EOPNOTSUPP;
1389 goto out;
1390 }
1391
fffd0934
JB
1392 wdev_lock(dev->ieee80211_ptr);
1393 err = nl80211_key_allowed(dev->ieee80211_ptr);
1394 if (!err)
1395 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1396
08645126
JB
1397#ifdef CONFIG_WIRELESS_EXT
1398 if (!err) {
b9454e83 1399 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1400 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1401 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1402 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1403 }
1404#endif
fffd0934 1405 wdev_unlock(dev->ieee80211_ptr);
08645126 1406
41ade00f 1407 out:
79c97e97 1408 cfg80211_unlock_rdev(rdev);
41ade00f 1409 dev_put(dev);
3b85875a
JB
1410
1411 unlock_rtnl:
1412 rtnl_unlock();
1413
41ade00f
JB
1414 return err;
1415}
1416
ed1b6cc7
JB
1417static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1418{
1419 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1420 struct beacon_parameters *info);
79c97e97 1421 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1422 int err;
1423 struct net_device *dev;
1424 struct beacon_parameters params;
1425 int haveinfo = 0;
1426
f4a11bb0
JB
1427 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1428 return -EINVAL;
1429
3b85875a
JB
1430 rtnl_lock();
1431
79c97e97 1432 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
ed1b6cc7 1433 if (err)
3b85875a 1434 goto unlock_rtnl;
ed1b6cc7 1435
eec60b03
JM
1436 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1437 err = -EOPNOTSUPP;
1438 goto out;
1439 }
1440
ed1b6cc7
JB
1441 switch (info->genlhdr->cmd) {
1442 case NL80211_CMD_NEW_BEACON:
1443 /* these are required for NEW_BEACON */
1444 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1445 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1446 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1447 err = -EINVAL;
1448 goto out;
1449 }
1450
79c97e97 1451 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1452 break;
1453 case NL80211_CMD_SET_BEACON:
79c97e97 1454 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1455 break;
1456 default:
1457 WARN_ON(1);
1458 err = -EOPNOTSUPP;
1459 goto out;
1460 }
1461
1462 if (!call) {
1463 err = -EOPNOTSUPP;
1464 goto out;
1465 }
1466
1467 memset(&params, 0, sizeof(params));
1468
1469 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1470 params.interval =
1471 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1472 haveinfo = 1;
1473 }
1474
1475 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1476 params.dtim_period =
1477 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1478 haveinfo = 1;
1479 }
1480
1481 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1482 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1483 params.head_len =
1484 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1485 haveinfo = 1;
1486 }
1487
1488 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1489 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1490 params.tail_len =
1491 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1492 haveinfo = 1;
1493 }
1494
1495 if (!haveinfo) {
1496 err = -EINVAL;
1497 goto out;
1498 }
1499
79c97e97 1500 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1501
1502 out:
79c97e97 1503 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1504 dev_put(dev);
3b85875a
JB
1505 unlock_rtnl:
1506 rtnl_unlock();
1507
ed1b6cc7
JB
1508 return err;
1509}
1510
1511static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1512{
79c97e97 1513 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1514 int err;
1515 struct net_device *dev;
1516
3b85875a
JB
1517 rtnl_lock();
1518
79c97e97 1519 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
ed1b6cc7 1520 if (err)
3b85875a 1521 goto unlock_rtnl;
ed1b6cc7 1522
79c97e97 1523 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1524 err = -EOPNOTSUPP;
1525 goto out;
1526 }
1527
eec60b03
JM
1528 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1529 err = -EOPNOTSUPP;
1530 goto out;
1531 }
79c97e97 1532 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1533
1534 out:
79c97e97 1535 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1536 dev_put(dev);
3b85875a
JB
1537 unlock_rtnl:
1538 rtnl_unlock();
1539
ed1b6cc7
JB
1540 return err;
1541}
1542
5727ef1b
JB
1543static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1544 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1545 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1546 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1547 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1548};
1549
eccb8e8f
JB
1550static int parse_station_flags(struct genl_info *info,
1551 struct station_parameters *params)
5727ef1b
JB
1552{
1553 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1554 struct nlattr *nla;
5727ef1b
JB
1555 int flag;
1556
eccb8e8f
JB
1557 /*
1558 * Try parsing the new attribute first so userspace
1559 * can specify both for older kernels.
1560 */
1561 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1562 if (nla) {
1563 struct nl80211_sta_flag_update *sta_flags;
1564
1565 sta_flags = nla_data(nla);
1566 params->sta_flags_mask = sta_flags->mask;
1567 params->sta_flags_set = sta_flags->set;
1568 if ((params->sta_flags_mask |
1569 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1570 return -EINVAL;
1571 return 0;
1572 }
1573
1574 /* if present, parse the old attribute */
5727ef1b 1575
eccb8e8f 1576 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1577 if (!nla)
1578 return 0;
1579
1580 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1581 nla, sta_flags_policy))
1582 return -EINVAL;
1583
eccb8e8f
JB
1584 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1585 params->sta_flags_mask &= ~1;
5727ef1b
JB
1586
1587 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1588 if (flags[flag])
eccb8e8f 1589 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1590
1591 return 0;
1592}
1593
420e7fab
HR
1594static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1595{
1596 int modulation, streams, bitrate;
1597
1598 if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1599 return rate->legacy;
1600
1601 /* the formula below does only work for MCS values smaller than 32 */
1602 if (rate->mcs >= 32)
1603 return 0;
1604
1605 modulation = rate->mcs & 7;
1606 streams = (rate->mcs >> 3) + 1;
1607
1608 bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1609 13500000 : 6500000;
1610
1611 if (modulation < 4)
1612 bitrate *= (modulation + 1);
1613 else if (modulation == 4)
1614 bitrate *= (modulation + 2);
1615 else
1616 bitrate *= (modulation + 3);
1617
1618 bitrate *= streams;
1619
1620 if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1621 bitrate = (bitrate / 9) * 10;
1622
1623 /* do NOT round down here */
1624 return (bitrate + 50000) / 100000;
1625}
1626
fd5b74dc
JB
1627static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1628 int flags, struct net_device *dev,
2ec600d6 1629 u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1630{
1631 void *hdr;
420e7fab
HR
1632 struct nlattr *sinfoattr, *txrate;
1633 u16 bitrate;
fd5b74dc
JB
1634
1635 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1636 if (!hdr)
1637 return -1;
1638
1639 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1640 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1641
2ec600d6
LCC
1642 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1643 if (!sinfoattr)
fd5b74dc 1644 goto nla_put_failure;
2ec600d6
LCC
1645 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1646 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1647 sinfo->inactive_time);
1648 if (sinfo->filled & STATION_INFO_RX_BYTES)
1649 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1650 sinfo->rx_bytes);
1651 if (sinfo->filled & STATION_INFO_TX_BYTES)
1652 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1653 sinfo->tx_bytes);
1654 if (sinfo->filled & STATION_INFO_LLID)
1655 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1656 sinfo->llid);
1657 if (sinfo->filled & STATION_INFO_PLID)
1658 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1659 sinfo->plid);
1660 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1661 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1662 sinfo->plink_state);
420e7fab
HR
1663 if (sinfo->filled & STATION_INFO_SIGNAL)
1664 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1665 sinfo->signal);
1666 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1667 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1668 if (!txrate)
1669 goto nla_put_failure;
1670
1671 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1672 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1673 if (bitrate > 0)
1674 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1675
420e7fab
HR
1676 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1677 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1678 sinfo->txrate.mcs);
1679 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1680 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1681 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1682 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1683
1684 nla_nest_end(msg, txrate);
1685 }
98c8a60a
JM
1686 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1687 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1688 sinfo->rx_packets);
1689 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1690 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1691 sinfo->tx_packets);
2ec600d6 1692 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1693
1694 return genlmsg_end(msg, hdr);
1695
1696 nla_put_failure:
bc3ed28c
TG
1697 genlmsg_cancel(msg, hdr);
1698 return -EMSGSIZE;
fd5b74dc
JB
1699}
1700
2ec600d6 1701static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1702 struct netlink_callback *cb)
2ec600d6 1703{
2ec600d6
LCC
1704 struct station_info sinfo;
1705 struct cfg80211_registered_device *dev;
bba95fef 1706 struct net_device *netdev;
2ec600d6 1707 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1708 int ifidx = cb->args[0];
1709 int sta_idx = cb->args[1];
2ec600d6 1710 int err;
2ec600d6 1711
bba95fef
JB
1712 if (!ifidx) {
1713 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1714 nl80211_fam.attrbuf, nl80211_fam.maxattr,
1715 nl80211_policy);
1716 if (err)
1717 return err;
2ec600d6 1718
bba95fef
JB
1719 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1720 return -EINVAL;
2ec600d6 1721
bba95fef
JB
1722 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1723 if (!ifidx)
1724 return -EINVAL;
2ec600d6 1725 }
2ec600d6 1726
3b85875a
JB
1727 rtnl_lock();
1728
1729 netdev = __dev_get_by_index(&init_net, ifidx);
1730 if (!netdev) {
1731 err = -ENODEV;
1732 goto out_rtnl;
1733 }
2ec600d6 1734
bba95fef
JB
1735 dev = cfg80211_get_dev_from_ifindex(ifidx);
1736 if (IS_ERR(dev)) {
1737 err = PTR_ERR(dev);
3b85875a 1738 goto out_rtnl;
bba95fef
JB
1739 }
1740
1741 if (!dev->ops->dump_station) {
eec60b03 1742 err = -EOPNOTSUPP;
bba95fef
JB
1743 goto out_err;
1744 }
1745
bba95fef
JB
1746 while (1) {
1747 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1748 mac_addr, &sinfo);
1749 if (err == -ENOENT)
1750 break;
1751 if (err)
3b85875a 1752 goto out_err;
bba95fef
JB
1753
1754 if (nl80211_send_station(skb,
1755 NETLINK_CB(cb->skb).pid,
1756 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1757 netdev, mac_addr,
1758 &sinfo) < 0)
1759 goto out;
1760
1761 sta_idx++;
1762 }
1763
1764
1765 out:
1766 cb->args[1] = sta_idx;
1767 err = skb->len;
bba95fef 1768 out_err:
4d0c8aea 1769 cfg80211_unlock_rdev(dev);
3b85875a
JB
1770 out_rtnl:
1771 rtnl_unlock();
bba95fef
JB
1772
1773 return err;
2ec600d6 1774}
fd5b74dc 1775
5727ef1b
JB
1776static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1777{
79c97e97 1778 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1779 int err;
1780 struct net_device *dev;
2ec600d6 1781 struct station_info sinfo;
fd5b74dc
JB
1782 struct sk_buff *msg;
1783 u8 *mac_addr = NULL;
1784
2ec600d6 1785 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1786
1787 if (!info->attrs[NL80211_ATTR_MAC])
1788 return -EINVAL;
1789
1790 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1791
3b85875a
JB
1792 rtnl_lock();
1793
79c97e97 1794 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
fd5b74dc 1795 if (err)
3b85875a 1796 goto out_rtnl;
fd5b74dc 1797
79c97e97 1798 if (!rdev->ops->get_station) {
fd5b74dc
JB
1799 err = -EOPNOTSUPP;
1800 goto out;
1801 }
1802
79c97e97 1803 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1804 if (err)
1805 goto out;
1806
fd2120ca 1807 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1808 if (!msg)
1809 goto out;
1810
1811 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1812 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1813 goto out_free;
1814
134e6375 1815 err = genlmsg_reply(msg, info);
fd5b74dc
JB
1816 goto out;
1817
1818 out_free:
1819 nlmsg_free(msg);
fd5b74dc 1820 out:
79c97e97 1821 cfg80211_unlock_rdev(rdev);
fd5b74dc 1822 dev_put(dev);
3b85875a
JB
1823 out_rtnl:
1824 rtnl_unlock();
1825
fd5b74dc 1826 return err;
5727ef1b
JB
1827}
1828
1829/*
1830 * Get vlan interface making sure it is on the right wiphy.
1831 */
1832static int get_vlan(struct nlattr *vlanattr,
1833 struct cfg80211_registered_device *rdev,
1834 struct net_device **vlan)
1835{
1836 *vlan = NULL;
1837
1838 if (vlanattr) {
1839 *vlan = dev_get_by_index(&init_net, nla_get_u32(vlanattr));
1840 if (!*vlan)
1841 return -ENODEV;
1842 if (!(*vlan)->ieee80211_ptr)
1843 return -EINVAL;
1844 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1845 return -EINVAL;
1846 }
1847 return 0;
1848}
1849
1850static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1851{
79c97e97 1852 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1853 int err;
1854 struct net_device *dev;
1855 struct station_parameters params;
1856 u8 *mac_addr = NULL;
1857
1858 memset(&params, 0, sizeof(params));
1859
1860 params.listen_interval = -1;
1861
1862 if (info->attrs[NL80211_ATTR_STA_AID])
1863 return -EINVAL;
1864
1865 if (!info->attrs[NL80211_ATTR_MAC])
1866 return -EINVAL;
1867
1868 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1869
1870 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1871 params.supported_rates =
1872 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1873 params.supported_rates_len =
1874 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1875 }
1876
1877 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1878 params.listen_interval =
1879 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1880
36aedc90
JM
1881 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1882 params.ht_capa =
1883 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1884
eccb8e8f 1885 if (parse_station_flags(info, &params))
5727ef1b
JB
1886 return -EINVAL;
1887
2ec600d6
LCC
1888 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1889 params.plink_action =
1890 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1891
3b85875a
JB
1892 rtnl_lock();
1893
79c97e97 1894 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
5727ef1b 1895 if (err)
3b85875a 1896 goto out_rtnl;
5727ef1b 1897
79c97e97 1898 err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], rdev, &params.vlan);
a97f4424 1899 if (err)
034d655e 1900 goto out;
a97f4424
JB
1901
1902 /* validate settings */
1903 err = 0;
1904
1905 switch (dev->ieee80211_ptr->iftype) {
1906 case NL80211_IFTYPE_AP:
1907 case NL80211_IFTYPE_AP_VLAN:
1908 /* disallow mesh-specific things */
1909 if (params.plink_action)
1910 err = -EINVAL;
1911 break;
1912 case NL80211_IFTYPE_STATION:
1913 /* disallow everything but AUTHORIZED flag */
1914 if (params.plink_action)
1915 err = -EINVAL;
1916 if (params.vlan)
1917 err = -EINVAL;
1918 if (params.supported_rates)
1919 err = -EINVAL;
1920 if (params.ht_capa)
1921 err = -EINVAL;
1922 if (params.listen_interval >= 0)
1923 err = -EINVAL;
1924 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1925 err = -EINVAL;
1926 break;
1927 case NL80211_IFTYPE_MESH_POINT:
1928 /* disallow things mesh doesn't support */
1929 if (params.vlan)
1930 err = -EINVAL;
1931 if (params.ht_capa)
1932 err = -EINVAL;
1933 if (params.listen_interval >= 0)
1934 err = -EINVAL;
1935 if (params.supported_rates)
1936 err = -EINVAL;
1937 if (params.sta_flags_mask)
1938 err = -EINVAL;
1939 break;
1940 default:
1941 err = -EINVAL;
034d655e
JB
1942 }
1943
5727ef1b
JB
1944 if (err)
1945 goto out;
1946
79c97e97 1947 if (!rdev->ops->change_station) {
5727ef1b
JB
1948 err = -EOPNOTSUPP;
1949 goto out;
1950 }
1951
79c97e97 1952 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
1953
1954 out:
1955 if (params.vlan)
1956 dev_put(params.vlan);
79c97e97 1957 cfg80211_unlock_rdev(rdev);
5727ef1b 1958 dev_put(dev);
3b85875a
JB
1959 out_rtnl:
1960 rtnl_unlock();
1961
5727ef1b
JB
1962 return err;
1963}
1964
1965static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1966{
79c97e97 1967 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1968 int err;
1969 struct net_device *dev;
1970 struct station_parameters params;
1971 u8 *mac_addr = NULL;
1972
1973 memset(&params, 0, sizeof(params));
1974
1975 if (!info->attrs[NL80211_ATTR_MAC])
1976 return -EINVAL;
1977
5727ef1b
JB
1978 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1979 return -EINVAL;
1980
1981 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1982 return -EINVAL;
1983
1984 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1985 params.supported_rates =
1986 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1987 params.supported_rates_len =
1988 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1989 params.listen_interval =
1990 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 1991
a97f4424
JB
1992 if (info->attrs[NL80211_ATTR_STA_AID]) {
1993 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1994 if (!params.aid || params.aid > IEEE80211_MAX_AID)
1995 return -EINVAL;
1996 }
51b50fbe 1997
36aedc90
JM
1998 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1999 params.ht_capa =
2000 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2001
eccb8e8f 2002 if (parse_station_flags(info, &params))
5727ef1b
JB
2003 return -EINVAL;
2004
3b85875a
JB
2005 rtnl_lock();
2006
79c97e97 2007 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
5727ef1b 2008 if (err)
3b85875a 2009 goto out_rtnl;
5727ef1b 2010
79c97e97 2011 err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], rdev, &params.vlan);
a97f4424 2012 if (err)
e80cf853 2013 goto out;
a97f4424
JB
2014
2015 /* validate settings */
2016 err = 0;
2017
2018 switch (dev->ieee80211_ptr->iftype) {
2019 case NL80211_IFTYPE_AP:
2020 case NL80211_IFTYPE_AP_VLAN:
2021 /* all ok but must have AID */
2022 if (!params.aid)
2023 err = -EINVAL;
2024 break;
2025 case NL80211_IFTYPE_MESH_POINT:
2026 /* disallow things mesh doesn't support */
2027 if (params.vlan)
2028 err = -EINVAL;
2029 if (params.aid)
2030 err = -EINVAL;
2031 if (params.ht_capa)
2032 err = -EINVAL;
2033 if (params.listen_interval >= 0)
2034 err = -EINVAL;
2035 if (params.supported_rates)
2036 err = -EINVAL;
2037 if (params.sta_flags_mask)
2038 err = -EINVAL;
2039 break;
2040 default:
2041 err = -EINVAL;
e80cf853
JB
2042 }
2043
5727ef1b
JB
2044 if (err)
2045 goto out;
2046
79c97e97 2047 if (!rdev->ops->add_station) {
5727ef1b
JB
2048 err = -EOPNOTSUPP;
2049 goto out;
2050 }
2051
35a8efe1
JM
2052 if (!netif_running(dev)) {
2053 err = -ENETDOWN;
2054 goto out;
2055 }
2056
79c97e97 2057 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2058
2059 out:
2060 if (params.vlan)
2061 dev_put(params.vlan);
79c97e97 2062 cfg80211_unlock_rdev(rdev);
5727ef1b 2063 dev_put(dev);
3b85875a
JB
2064 out_rtnl:
2065 rtnl_unlock();
2066
5727ef1b
JB
2067 return err;
2068}
2069
2070static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2071{
79c97e97 2072 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2073 int err;
2074 struct net_device *dev;
2075 u8 *mac_addr = NULL;
2076
2077 if (info->attrs[NL80211_ATTR_MAC])
2078 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2079
3b85875a
JB
2080 rtnl_lock();
2081
79c97e97 2082 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
5727ef1b 2083 if (err)
3b85875a 2084 goto out_rtnl;
5727ef1b 2085
e80cf853 2086 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
155cc9e4
AY
2087 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2088 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2089 err = -EINVAL;
2090 goto out;
2091 }
2092
79c97e97 2093 if (!rdev->ops->del_station) {
5727ef1b
JB
2094 err = -EOPNOTSUPP;
2095 goto out;
2096 }
2097
79c97e97 2098 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2099
2100 out:
79c97e97 2101 cfg80211_unlock_rdev(rdev);
5727ef1b 2102 dev_put(dev);
3b85875a
JB
2103 out_rtnl:
2104 rtnl_unlock();
2105
5727ef1b
JB
2106 return err;
2107}
2108
2ec600d6
LCC
2109static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2110 int flags, struct net_device *dev,
2111 u8 *dst, u8 *next_hop,
2112 struct mpath_info *pinfo)
2113{
2114 void *hdr;
2115 struct nlattr *pinfoattr;
2116
2117 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2118 if (!hdr)
2119 return -1;
2120
2121 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2122 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2123 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2124
2125 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2126 if (!pinfoattr)
2127 goto nla_put_failure;
2128 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2129 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2130 pinfo->frame_qlen);
2131 if (pinfo->filled & MPATH_INFO_DSN)
2132 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
2133 pinfo->dsn);
2134 if (pinfo->filled & MPATH_INFO_METRIC)
2135 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2136 pinfo->metric);
2137 if (pinfo->filled & MPATH_INFO_EXPTIME)
2138 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2139 pinfo->exptime);
2140 if (pinfo->filled & MPATH_INFO_FLAGS)
2141 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2142 pinfo->flags);
2143 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2144 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2145 pinfo->discovery_timeout);
2146 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2147 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2148 pinfo->discovery_retries);
2149
2150 nla_nest_end(msg, pinfoattr);
2151
2152 return genlmsg_end(msg, hdr);
2153
2154 nla_put_failure:
bc3ed28c
TG
2155 genlmsg_cancel(msg, hdr);
2156 return -EMSGSIZE;
2ec600d6
LCC
2157}
2158
2159static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2160 struct netlink_callback *cb)
2ec600d6 2161{
2ec600d6
LCC
2162 struct mpath_info pinfo;
2163 struct cfg80211_registered_device *dev;
bba95fef 2164 struct net_device *netdev;
2ec600d6
LCC
2165 u8 dst[ETH_ALEN];
2166 u8 next_hop[ETH_ALEN];
bba95fef
JB
2167 int ifidx = cb->args[0];
2168 int path_idx = cb->args[1];
2ec600d6 2169 int err;
2ec600d6 2170
bba95fef
JB
2171 if (!ifidx) {
2172 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2173 nl80211_fam.attrbuf, nl80211_fam.maxattr,
2174 nl80211_policy);
2175 if (err)
2176 return err;
2177
2178 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2179 return -EINVAL;
2180
2181 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2182 if (!ifidx)
2183 return -EINVAL;
2184 }
2185
3b85875a
JB
2186 rtnl_lock();
2187
2188 netdev = __dev_get_by_index(&init_net, ifidx);
2189 if (!netdev) {
2190 err = -ENODEV;
2191 goto out_rtnl;
2192 }
bba95fef
JB
2193
2194 dev = cfg80211_get_dev_from_ifindex(ifidx);
2195 if (IS_ERR(dev)) {
2196 err = PTR_ERR(dev);
3b85875a 2197 goto out_rtnl;
bba95fef
JB
2198 }
2199
2200 if (!dev->ops->dump_mpath) {
eec60b03 2201 err = -EOPNOTSUPP;
bba95fef
JB
2202 goto out_err;
2203 }
2204
eec60b03
JM
2205 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2206 err = -EOPNOTSUPP;
2207 goto out;
2208 }
2209
bba95fef
JB
2210 while (1) {
2211 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2212 dst, next_hop, &pinfo);
2213 if (err == -ENOENT)
2ec600d6 2214 break;
bba95fef 2215 if (err)
3b85875a 2216 goto out_err;
2ec600d6 2217
bba95fef
JB
2218 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2219 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2220 netdev, dst, next_hop,
2221 &pinfo) < 0)
2222 goto out;
2ec600d6 2223
bba95fef 2224 path_idx++;
2ec600d6 2225 }
2ec600d6 2226
2ec600d6 2227
bba95fef
JB
2228 out:
2229 cb->args[1] = path_idx;
2230 err = skb->len;
bba95fef 2231 out_err:
4d0c8aea 2232 cfg80211_unlock_rdev(dev);
3b85875a
JB
2233 out_rtnl:
2234 rtnl_unlock();
bba95fef
JB
2235
2236 return err;
2ec600d6
LCC
2237}
2238
2239static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2240{
79c97e97 2241 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2242 int err;
2243 struct net_device *dev;
2244 struct mpath_info pinfo;
2245 struct sk_buff *msg;
2246 u8 *dst = NULL;
2247 u8 next_hop[ETH_ALEN];
2248
2249 memset(&pinfo, 0, sizeof(pinfo));
2250
2251 if (!info->attrs[NL80211_ATTR_MAC])
2252 return -EINVAL;
2253
2254 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2255
3b85875a
JB
2256 rtnl_lock();
2257
79c97e97 2258 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
2ec600d6 2259 if (err)
3b85875a 2260 goto out_rtnl;
2ec600d6 2261
79c97e97 2262 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2263 err = -EOPNOTSUPP;
2264 goto out;
2265 }
2266
eec60b03
JM
2267 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2268 err = -EOPNOTSUPP;
2269 goto out;
2270 }
2271
79c97e97 2272 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2273 if (err)
2274 goto out;
2275
fd2120ca 2276 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2277 if (!msg)
2278 goto out;
2279
2280 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2281 dev, dst, next_hop, &pinfo) < 0)
2282 goto out_free;
2283
134e6375 2284 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2285 goto out;
2286
2287 out_free:
2288 nlmsg_free(msg);
2ec600d6 2289 out:
79c97e97 2290 cfg80211_unlock_rdev(rdev);
2ec600d6 2291 dev_put(dev);
3b85875a
JB
2292 out_rtnl:
2293 rtnl_unlock();
2294
2ec600d6
LCC
2295 return err;
2296}
2297
2298static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2299{
79c97e97 2300 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2301 int err;
2302 struct net_device *dev;
2303 u8 *dst = NULL;
2304 u8 *next_hop = NULL;
2305
2306 if (!info->attrs[NL80211_ATTR_MAC])
2307 return -EINVAL;
2308
2309 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2310 return -EINVAL;
2311
2312 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2313 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2314
3b85875a
JB
2315 rtnl_lock();
2316
79c97e97 2317 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
2ec600d6 2318 if (err)
3b85875a 2319 goto out_rtnl;
2ec600d6 2320
79c97e97 2321 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2322 err = -EOPNOTSUPP;
2323 goto out;
2324 }
2325
eec60b03
JM
2326 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2327 err = -EOPNOTSUPP;
2328 goto out;
2329 }
2330
35a8efe1
JM
2331 if (!netif_running(dev)) {
2332 err = -ENETDOWN;
2333 goto out;
2334 }
2335
79c97e97 2336 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2337
2338 out:
79c97e97 2339 cfg80211_unlock_rdev(rdev);
2ec600d6 2340 dev_put(dev);
3b85875a
JB
2341 out_rtnl:
2342 rtnl_unlock();
2343
2ec600d6
LCC
2344 return err;
2345}
2346static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2347{
79c97e97 2348 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2349 int err;
2350 struct net_device *dev;
2351 u8 *dst = NULL;
2352 u8 *next_hop = NULL;
2353
2354 if (!info->attrs[NL80211_ATTR_MAC])
2355 return -EINVAL;
2356
2357 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2358 return -EINVAL;
2359
2360 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2361 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2362
3b85875a
JB
2363 rtnl_lock();
2364
79c97e97 2365 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
2ec600d6 2366 if (err)
3b85875a 2367 goto out_rtnl;
2ec600d6 2368
79c97e97 2369 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2370 err = -EOPNOTSUPP;
2371 goto out;
2372 }
2373
eec60b03
JM
2374 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2375 err = -EOPNOTSUPP;
2376 goto out;
2377 }
2378
35a8efe1
JM
2379 if (!netif_running(dev)) {
2380 err = -ENETDOWN;
2381 goto out;
2382 }
2383
79c97e97 2384 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2385
2386 out:
79c97e97 2387 cfg80211_unlock_rdev(rdev);
2ec600d6 2388 dev_put(dev);
3b85875a
JB
2389 out_rtnl:
2390 rtnl_unlock();
2391
2ec600d6
LCC
2392 return err;
2393}
2394
2395static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2396{
79c97e97 2397 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2398 int err;
2399 struct net_device *dev;
2400 u8 *dst = NULL;
2401
2402 if (info->attrs[NL80211_ATTR_MAC])
2403 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2404
3b85875a
JB
2405 rtnl_lock();
2406
79c97e97 2407 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
2ec600d6 2408 if (err)
3b85875a 2409 goto out_rtnl;
2ec600d6 2410
79c97e97 2411 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2412 err = -EOPNOTSUPP;
2413 goto out;
2414 }
2415
79c97e97 2416 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2417
2418 out:
79c97e97 2419 cfg80211_unlock_rdev(rdev);
2ec600d6 2420 dev_put(dev);
3b85875a
JB
2421 out_rtnl:
2422 rtnl_unlock();
2423
2ec600d6
LCC
2424 return err;
2425}
2426
9f1ba906
JM
2427static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2428{
79c97e97 2429 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2430 int err;
2431 struct net_device *dev;
2432 struct bss_parameters params;
2433
2434 memset(&params, 0, sizeof(params));
2435 /* default to not changing parameters */
2436 params.use_cts_prot = -1;
2437 params.use_short_preamble = -1;
2438 params.use_short_slot_time = -1;
2439
2440 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2441 params.use_cts_prot =
2442 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2443 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2444 params.use_short_preamble =
2445 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2446 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2447 params.use_short_slot_time =
2448 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2449 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2450 params.basic_rates =
2451 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2452 params.basic_rates_len =
2453 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2454 }
9f1ba906 2455
3b85875a
JB
2456 rtnl_lock();
2457
79c97e97 2458 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
9f1ba906 2459 if (err)
3b85875a 2460 goto out_rtnl;
9f1ba906 2461
79c97e97 2462 if (!rdev->ops->change_bss) {
9f1ba906
JM
2463 err = -EOPNOTSUPP;
2464 goto out;
2465 }
2466
eec60b03
JM
2467 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2468 err = -EOPNOTSUPP;
2469 goto out;
2470 }
2471
79c97e97 2472 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2473
2474 out:
79c97e97 2475 cfg80211_unlock_rdev(rdev);
9f1ba906 2476 dev_put(dev);
3b85875a
JB
2477 out_rtnl:
2478 rtnl_unlock();
2479
9f1ba906
JM
2480 return err;
2481}
2482
b2e1b302
LR
2483static const struct nla_policy
2484 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2485 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2486 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2487 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2488 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2489 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2490 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2491};
2492
2493static int parse_reg_rule(struct nlattr *tb[],
2494 struct ieee80211_reg_rule *reg_rule)
2495{
2496 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2497 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2498
2499 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2500 return -EINVAL;
2501 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2502 return -EINVAL;
2503 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2504 return -EINVAL;
2505 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2506 return -EINVAL;
2507 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2508 return -EINVAL;
2509
2510 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2511
2512 freq_range->start_freq_khz =
2513 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2514 freq_range->end_freq_khz =
2515 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2516 freq_range->max_bandwidth_khz =
2517 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2518
2519 power_rule->max_eirp =
2520 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2521
2522 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2523 power_rule->max_antenna_gain =
2524 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2525
2526 return 0;
2527}
2528
2529static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2530{
2531 int r;
2532 char *data = NULL;
2533
80778f18
LR
2534 /*
2535 * You should only get this when cfg80211 hasn't yet initialized
2536 * completely when built-in to the kernel right between the time
2537 * window between nl80211_init() and regulatory_init(), if that is
2538 * even possible.
2539 */
2540 mutex_lock(&cfg80211_mutex);
2541 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2542 mutex_unlock(&cfg80211_mutex);
2543 return -EINPROGRESS;
80778f18 2544 }
fe33eb39 2545 mutex_unlock(&cfg80211_mutex);
80778f18 2546
fe33eb39
LR
2547 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2548 return -EINVAL;
b2e1b302
LR
2549
2550 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2551
2552#ifdef CONFIG_WIRELESS_OLD_REGULATORY
2553 /* We ignore world regdom requests with the old regdom setup */
fe33eb39
LR
2554 if (is_world_regdom(data))
2555 return -EINVAL;
b2e1b302 2556#endif
fe33eb39
LR
2557
2558 r = regulatory_hint_user(data);
2559
b2e1b302
LR
2560 return r;
2561}
2562
93da9cc1 2563static int nl80211_get_mesh_params(struct sk_buff *skb,
2564 struct genl_info *info)
2565{
79c97e97 2566 struct cfg80211_registered_device *rdev;
93da9cc1 2567 struct mesh_config cur_params;
2568 int err;
2569 struct net_device *dev;
2570 void *hdr;
2571 struct nlattr *pinfoattr;
2572 struct sk_buff *msg;
2573
3b85875a
JB
2574 rtnl_lock();
2575
93da9cc1 2576 /* Look up our device */
79c97e97 2577 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
93da9cc1 2578 if (err)
3b85875a 2579 goto out_rtnl;
93da9cc1 2580
79c97e97 2581 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2582 err = -EOPNOTSUPP;
2583 goto out;
2584 }
2585
93da9cc1 2586 /* Get the mesh params */
79c97e97 2587 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2588 if (err)
2589 goto out;
2590
2591 /* Draw up a netlink message to send back */
fd2120ca 2592 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2593 if (!msg) {
2594 err = -ENOBUFS;
2595 goto out;
2596 }
2597 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2598 NL80211_CMD_GET_MESH_PARAMS);
2599 if (!hdr)
2600 goto nla_put_failure;
2601 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2602 if (!pinfoattr)
2603 goto nla_put_failure;
2604 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2605 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2606 cur_params.dot11MeshRetryTimeout);
2607 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2608 cur_params.dot11MeshConfirmTimeout);
2609 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2610 cur_params.dot11MeshHoldingTimeout);
2611 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2612 cur_params.dot11MeshMaxPeerLinks);
2613 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2614 cur_params.dot11MeshMaxRetries);
2615 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2616 cur_params.dot11MeshTTL);
2617 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2618 cur_params.auto_open_plinks);
2619 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2620 cur_params.dot11MeshHWMPmaxPREQretries);
2621 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2622 cur_params.path_refresh_time);
2623 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2624 cur_params.min_discovery_timeout);
2625 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2626 cur_params.dot11MeshHWMPactivePathTimeout);
2627 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2628 cur_params.dot11MeshHWMPpreqMinInterval);
2629 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2630 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2631 nla_nest_end(msg, pinfoattr);
2632 genlmsg_end(msg, hdr);
134e6375 2633 err = genlmsg_reply(msg, info);
93da9cc1 2634 goto out;
2635
3b85875a 2636 nla_put_failure:
93da9cc1 2637 genlmsg_cancel(msg, hdr);
2638 err = -EMSGSIZE;
3b85875a 2639 out:
93da9cc1 2640 /* Cleanup */
79c97e97 2641 cfg80211_unlock_rdev(rdev);
93da9cc1 2642 dev_put(dev);
3b85875a
JB
2643 out_rtnl:
2644 rtnl_unlock();
2645
93da9cc1 2646 return err;
2647}
2648
2649#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2650do {\
2651 if (table[attr_num]) {\
2652 cfg.param = nla_fn(table[attr_num]); \
2653 mask |= (1 << (attr_num - 1)); \
2654 } \
2655} while (0);\
2656
2657static struct nla_policy
2658nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2659 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2660 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2661 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2662 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2663 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2664 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2665 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2666
2667 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2668 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2669 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2670 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2671 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2672 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2673};
2674
2675static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2676{
2677 int err;
2678 u32 mask;
79c97e97 2679 struct cfg80211_registered_device *rdev;
93da9cc1 2680 struct net_device *dev;
2681 struct mesh_config cfg;
2682 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2683 struct nlattr *parent_attr;
2684
2685 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2686 if (!parent_attr)
2687 return -EINVAL;
2688 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2689 parent_attr, nl80211_meshconf_params_policy))
2690 return -EINVAL;
2691
3b85875a
JB
2692 rtnl_lock();
2693
79c97e97 2694 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
93da9cc1 2695 if (err)
3b85875a 2696 goto out_rtnl;
93da9cc1 2697
79c97e97 2698 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2699 err = -EOPNOTSUPP;
2700 goto out;
2701 }
2702
93da9cc1 2703 /* This makes sure that there aren't more than 32 mesh config
2704 * parameters (otherwise our bitfield scheme would not work.) */
2705 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2706
2707 /* Fill in the params struct */
2708 mask = 0;
2709 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2710 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2711 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2712 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2713 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2714 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2715 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2716 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2717 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2718 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2719 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2720 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2721 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2722 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2723 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2724 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2725 nla_get_u8);
2726 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2727 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2728 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2729 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2730 nla_get_u16);
2731 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2732 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2733 nla_get_u32);
2734 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2735 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2736 nla_get_u16);
2737 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2738 dot11MeshHWMPnetDiameterTraversalTime,
2739 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2740 nla_get_u16);
2741
2742 /* Apply changes */
79c97e97 2743 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2744
f3f92586 2745 out:
93da9cc1 2746 /* cleanup */
79c97e97 2747 cfg80211_unlock_rdev(rdev);
93da9cc1 2748 dev_put(dev);
3b85875a
JB
2749 out_rtnl:
2750 rtnl_unlock();
2751
93da9cc1 2752 return err;
2753}
2754
2755#undef FILL_IN_MESH_PARAM_IF_SET
2756
f130347c
LR
2757static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2758{
2759 struct sk_buff *msg;
2760 void *hdr = NULL;
2761 struct nlattr *nl_reg_rules;
2762 unsigned int i;
2763 int err = -EINVAL;
2764
a1794390 2765 mutex_lock(&cfg80211_mutex);
f130347c
LR
2766
2767 if (!cfg80211_regdomain)
2768 goto out;
2769
fd2120ca 2770 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2771 if (!msg) {
2772 err = -ENOBUFS;
2773 goto out;
2774 }
2775
2776 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2777 NL80211_CMD_GET_REG);
2778 if (!hdr)
2779 goto nla_put_failure;
2780
2781 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2782 cfg80211_regdomain->alpha2);
2783
2784 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2785 if (!nl_reg_rules)
2786 goto nla_put_failure;
2787
2788 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2789 struct nlattr *nl_reg_rule;
2790 const struct ieee80211_reg_rule *reg_rule;
2791 const struct ieee80211_freq_range *freq_range;
2792 const struct ieee80211_power_rule *power_rule;
2793
2794 reg_rule = &cfg80211_regdomain->reg_rules[i];
2795 freq_range = &reg_rule->freq_range;
2796 power_rule = &reg_rule->power_rule;
2797
2798 nl_reg_rule = nla_nest_start(msg, i);
2799 if (!nl_reg_rule)
2800 goto nla_put_failure;
2801
2802 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2803 reg_rule->flags);
2804 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2805 freq_range->start_freq_khz);
2806 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2807 freq_range->end_freq_khz);
2808 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2809 freq_range->max_bandwidth_khz);
2810 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2811 power_rule->max_antenna_gain);
2812 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2813 power_rule->max_eirp);
2814
2815 nla_nest_end(msg, nl_reg_rule);
2816 }
2817
2818 nla_nest_end(msg, nl_reg_rules);
2819
2820 genlmsg_end(msg, hdr);
134e6375 2821 err = genlmsg_reply(msg, info);
f130347c
LR
2822 goto out;
2823
2824nla_put_failure:
2825 genlmsg_cancel(msg, hdr);
2826 err = -EMSGSIZE;
2827out:
a1794390 2828 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2829 return err;
2830}
2831
b2e1b302
LR
2832static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2833{
2834 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2835 struct nlattr *nl_reg_rule;
2836 char *alpha2 = NULL;
2837 int rem_reg_rules = 0, r = 0;
2838 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2839 struct ieee80211_regdomain *rd = NULL;
2840
2841 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2842 return -EINVAL;
2843
2844 if (!info->attrs[NL80211_ATTR_REG_RULES])
2845 return -EINVAL;
2846
2847 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2848
2849 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2850 rem_reg_rules) {
2851 num_rules++;
2852 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2853 return -EINVAL;
b2e1b302
LR
2854 }
2855
61405e97
LR
2856 mutex_lock(&cfg80211_mutex);
2857
d0e18f83
LR
2858 if (!reg_is_valid_request(alpha2)) {
2859 r = -EINVAL;
2860 goto bad_reg;
2861 }
b2e1b302
LR
2862
2863 size_of_regd = sizeof(struct ieee80211_regdomain) +
2864 (num_rules * sizeof(struct ieee80211_reg_rule));
2865
2866 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2867 if (!rd) {
2868 r = -ENOMEM;
2869 goto bad_reg;
2870 }
b2e1b302
LR
2871
2872 rd->n_reg_rules = num_rules;
2873 rd->alpha2[0] = alpha2[0];
2874 rd->alpha2[1] = alpha2[1];
2875
2876 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2877 rem_reg_rules) {
2878 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2879 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2880 reg_rule_policy);
2881 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2882 if (r)
2883 goto bad_reg;
2884
2885 rule_idx++;
2886
d0e18f83
LR
2887 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2888 r = -EINVAL;
b2e1b302 2889 goto bad_reg;
d0e18f83 2890 }
b2e1b302
LR
2891 }
2892
2893 BUG_ON(rule_idx != num_rules);
2894
b2e1b302 2895 r = set_regdom(rd);
61405e97 2896
a1794390 2897 mutex_unlock(&cfg80211_mutex);
d0e18f83 2898
b2e1b302
LR
2899 return r;
2900
d2372b31 2901 bad_reg:
61405e97 2902 mutex_unlock(&cfg80211_mutex);
b2e1b302 2903 kfree(rd);
d0e18f83 2904 return r;
b2e1b302
LR
2905}
2906
83f5e2cf
JB
2907static int validate_scan_freqs(struct nlattr *freqs)
2908{
2909 struct nlattr *attr1, *attr2;
2910 int n_channels = 0, tmp1, tmp2;
2911
2912 nla_for_each_nested(attr1, freqs, tmp1) {
2913 n_channels++;
2914 /*
2915 * Some hardware has a limited channel list for
2916 * scanning, and it is pretty much nonsensical
2917 * to scan for a channel twice, so disallow that
2918 * and don't require drivers to check that the
2919 * channel list they get isn't longer than what
2920 * they can scan, as long as they can scan all
2921 * the channels they registered at once.
2922 */
2923 nla_for_each_nested(attr2, freqs, tmp2)
2924 if (attr1 != attr2 &&
2925 nla_get_u32(attr1) == nla_get_u32(attr2))
2926 return 0;
2927 }
2928
2929 return n_channels;
2930}
2931
2a519311
JB
2932static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2933{
79c97e97 2934 struct cfg80211_registered_device *rdev;
2a519311
JB
2935 struct net_device *dev;
2936 struct cfg80211_scan_request *request;
2937 struct cfg80211_ssid *ssid;
2938 struct ieee80211_channel *channel;
2939 struct nlattr *attr;
2940 struct wiphy *wiphy;
83f5e2cf 2941 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 2942 enum ieee80211_band band;
70692ad2 2943 size_t ie_len;
2a519311 2944
f4a11bb0
JB
2945 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2946 return -EINVAL;
2947
3b85875a
JB
2948 rtnl_lock();
2949
79c97e97 2950 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
2a519311 2951 if (err)
3b85875a 2952 goto out_rtnl;
2a519311 2953
79c97e97 2954 wiphy = &rdev->wiphy;
2a519311 2955
79c97e97 2956 if (!rdev->ops->scan) {
2a519311
JB
2957 err = -EOPNOTSUPP;
2958 goto out;
2959 }
2960
35a8efe1
JM
2961 if (!netif_running(dev)) {
2962 err = -ENETDOWN;
2963 goto out;
2964 }
2965
79c97e97 2966 if (rdev->scan_req) {
2a519311 2967 err = -EBUSY;
3b85875a 2968 goto out;
2a519311
JB
2969 }
2970
2971 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
2972 n_channels = validate_scan_freqs(
2973 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
2974 if (!n_channels) {
2975 err = -EINVAL;
3b85875a 2976 goto out;
2a519311
JB
2977 }
2978 } else {
83f5e2cf
JB
2979 n_channels = 0;
2980
2a519311
JB
2981 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2982 if (wiphy->bands[band])
2983 n_channels += wiphy->bands[band]->n_channels;
2984 }
2985
2986 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2987 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2988 n_ssids++;
2989
2990 if (n_ssids > wiphy->max_scan_ssids) {
2991 err = -EINVAL;
3b85875a 2992 goto out;
2a519311
JB
2993 }
2994
70692ad2
JM
2995 if (info->attrs[NL80211_ATTR_IE])
2996 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2997 else
2998 ie_len = 0;
2999
18a83659
JB
3000 if (ie_len > wiphy->max_scan_ie_len) {
3001 err = -EINVAL;
3002 goto out;
3003 }
3004
2a519311
JB
3005 request = kzalloc(sizeof(*request)
3006 + sizeof(*ssid) * n_ssids
70692ad2
JM
3007 + sizeof(channel) * n_channels
3008 + ie_len, GFP_KERNEL);
2a519311
JB
3009 if (!request) {
3010 err = -ENOMEM;
3b85875a 3011 goto out;
2a519311
JB
3012 }
3013
3014 request->channels = (void *)((char *)request + sizeof(*request));
3015 request->n_channels = n_channels;
3016 if (n_ssids)
3017 request->ssids = (void *)(request->channels + n_channels);
3018 request->n_ssids = n_ssids;
70692ad2
JM
3019 if (ie_len) {
3020 if (request->ssids)
3021 request->ie = (void *)(request->ssids + n_ssids);
3022 else
3023 request->ie = (void *)(request->channels + n_channels);
3024 }
2a519311
JB
3025
3026 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3027 /* user specified, bail out if channel not found */
3028 request->n_channels = n_channels;
3029 i = 0;
3030 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3031 request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3032 if (!request->channels[i]) {
3033 err = -EINVAL;
3034 goto out_free;
3035 }
3036 i++;
3037 }
3038 } else {
3039 /* all channels */
3040 i = 0;
3041 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3042 int j;
3043 if (!wiphy->bands[band])
3044 continue;
3045 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3046 request->channels[i] = &wiphy->bands[band]->channels[j];
3047 i++;
3048 }
3049 }
3050 }
3051
3052 i = 0;
3053 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3054 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3055 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3056 err = -EINVAL;
3057 goto out_free;
3058 }
3059 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3060 request->ssids[i].ssid_len = nla_len(attr);
3061 i++;
3062 }
3063 }
3064
70692ad2
JM
3065 if (info->attrs[NL80211_ATTR_IE]) {
3066 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3067 memcpy((void *)request->ie,
3068 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3069 request->ie_len);
3070 }
3071
2a519311 3072 request->ifidx = dev->ifindex;
79c97e97 3073 request->wiphy = &rdev->wiphy;
2a519311 3074
79c97e97
JB
3075 rdev->scan_req = request;
3076 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3077
a538e2d5 3078 if (!err)
79c97e97 3079 nl80211_send_scan_start(rdev, dev);
a538e2d5 3080
2a519311
JB
3081 out_free:
3082 if (err) {
79c97e97 3083 rdev->scan_req = NULL;
2a519311
JB
3084 kfree(request);
3085 }
2a519311 3086 out:
79c97e97 3087 cfg80211_unlock_rdev(rdev);
2a519311 3088 dev_put(dev);
3b85875a
JB
3089 out_rtnl:
3090 rtnl_unlock();
3091
2a519311
JB
3092 return err;
3093}
3094
3095static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3096 struct cfg80211_registered_device *rdev,
48ab905d
JB
3097 struct wireless_dev *wdev,
3098 struct cfg80211_internal_bss *intbss)
2a519311 3099{
48ab905d 3100 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3101 void *hdr;
3102 struct nlattr *bss;
48ab905d
JB
3103 int i;
3104
3105 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3106
3107 hdr = nl80211hdr_put(msg, pid, seq, flags,
3108 NL80211_CMD_NEW_SCAN_RESULTS);
3109 if (!hdr)
3110 return -1;
3111
3112 NLA_PUT_U32(msg, NL80211_ATTR_SCAN_GENERATION,
3113 rdev->bss_generation);
48ab905d 3114 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3115
3116 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3117 if (!bss)
3118 goto nla_put_failure;
3119 if (!is_zero_ether_addr(res->bssid))
3120 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3121 if (res->information_elements && res->len_information_elements)
3122 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3123 res->len_information_elements,
3124 res->information_elements);
3125 if (res->tsf)
3126 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3127 if (res->beacon_interval)
3128 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3129 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3130 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3131
77965c97 3132 switch (rdev->wiphy.signal_type) {
2a519311
JB
3133 case CFG80211_SIGNAL_TYPE_MBM:
3134 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3135 break;
3136 case CFG80211_SIGNAL_TYPE_UNSPEC:
3137 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3138 break;
3139 default:
3140 break;
3141 }
3142
48ab905d
JB
3143 switch (wdev->iftype) {
3144 case NL80211_IFTYPE_STATION:
3145 if (intbss == wdev->current_bss)
3146 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3147 NL80211_BSS_STATUS_ASSOCIATED);
3148 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3149 if (intbss != wdev->auth_bsses[i])
3150 continue;
3151 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3152 NL80211_BSS_STATUS_AUTHENTICATED);
3153 break;
3154 }
3155 break;
3156 case NL80211_IFTYPE_ADHOC:
3157 if (intbss == wdev->current_bss)
3158 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3159 NL80211_BSS_STATUS_IBSS_JOINED);
3160 break;
3161 default:
3162 break;
3163 }
3164
2a519311
JB
3165 nla_nest_end(msg, bss);
3166
3167 return genlmsg_end(msg, hdr);
3168
3169 nla_put_failure:
3170 genlmsg_cancel(msg, hdr);
3171 return -EMSGSIZE;
3172}
3173
3174static int nl80211_dump_scan(struct sk_buff *skb,
3175 struct netlink_callback *cb)
3176{
48ab905d
JB
3177 struct cfg80211_registered_device *rdev;
3178 struct net_device *dev;
2a519311 3179 struct cfg80211_internal_bss *scan;
48ab905d 3180 struct wireless_dev *wdev;
2a519311
JB
3181 int ifidx = cb->args[0];
3182 int start = cb->args[1], idx = 0;
3183 int err;
3184
3185 if (!ifidx) {
3186 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
3187 nl80211_fam.attrbuf, nl80211_fam.maxattr,
3188 nl80211_policy);
3189 if (err)
3190 return err;
3191
3192 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
3193 return -EINVAL;
3194
3195 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
3196 if (!ifidx)
3197 return -EINVAL;
3198 cb->args[0] = ifidx;
3199 }
3200
48ab905d
JB
3201 dev = dev_get_by_index(&init_net, ifidx);
3202 if (!dev)
2a519311
JB
3203 return -ENODEV;
3204
48ab905d
JB
3205 rdev = cfg80211_get_dev_from_ifindex(ifidx);
3206 if (IS_ERR(rdev)) {
3207 err = PTR_ERR(rdev);
2a519311
JB
3208 goto out_put_netdev;
3209 }
3210
48ab905d 3211 wdev = dev->ieee80211_ptr;
2a519311 3212
48ab905d
JB
3213 wdev_lock(wdev);
3214 spin_lock_bh(&rdev->bss_lock);
3215 cfg80211_bss_expire(rdev);
3216
3217 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3218 if (++idx <= start)
3219 continue;
3220 if (nl80211_send_bss(skb,
3221 NETLINK_CB(cb->skb).pid,
3222 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3223 rdev, wdev, scan) < 0) {
2a519311
JB
3224 idx--;
3225 goto out;
3226 }
3227 }
3228
3229 out:
48ab905d
JB
3230 spin_unlock_bh(&rdev->bss_lock);
3231 wdev_unlock(wdev);
2a519311
JB
3232
3233 cb->args[1] = idx;
3234 err = skb->len;
48ab905d 3235 cfg80211_unlock_rdev(rdev);
2a519311 3236 out_put_netdev:
48ab905d 3237 dev_put(dev);
2a519311
JB
3238
3239 return err;
3240}
3241
255e737e
JM
3242static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3243{
b23aa676
SO
3244 return auth_type <= NL80211_AUTHTYPE_MAX;
3245}
3246
3247static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3248{
3249 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3250 NL80211_WPA_VERSION_2));
3251}
3252
3253static bool nl80211_valid_akm_suite(u32 akm)
3254{
3255 return akm == WLAN_AKM_SUITE_8021X ||
3256 akm == WLAN_AKM_SUITE_PSK;
3257}
3258
3259static bool nl80211_valid_cipher_suite(u32 cipher)
3260{
3261 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3262 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3263 cipher == WLAN_CIPHER_SUITE_TKIP ||
3264 cipher == WLAN_CIPHER_SUITE_CCMP ||
3265 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3266}
3267
b23aa676 3268
636a5d36
JM
3269static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3270{
79c97e97 3271 struct cfg80211_registered_device *rdev;
636a5d36 3272 struct net_device *dev;
19957bb3
JB
3273 struct ieee80211_channel *chan;
3274 const u8 *bssid, *ssid, *ie = NULL;
3275 int err, ssid_len, ie_len = 0;
3276 enum nl80211_auth_type auth_type;
fffd0934 3277 struct key_parse key;
636a5d36 3278
f4a11bb0
JB
3279 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3280 return -EINVAL;
3281
3282 if (!info->attrs[NL80211_ATTR_MAC])
3283 return -EINVAL;
3284
1778092e
JM
3285 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3286 return -EINVAL;
3287
19957bb3
JB
3288 if (!info->attrs[NL80211_ATTR_SSID])
3289 return -EINVAL;
3290
3291 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3292 return -EINVAL;
3293
fffd0934
JB
3294 err = nl80211_parse_key(info, &key);
3295 if (err)
3296 return err;
3297
3298 if (key.idx >= 0) {
3299 if (!key.p.key || !key.p.key_len)
3300 return -EINVAL;
3301 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3302 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3303 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3304 key.p.key_len != WLAN_KEY_LEN_WEP104))
3305 return -EINVAL;
3306 if (key.idx > 4)
3307 return -EINVAL;
3308 } else {
3309 key.p.key_len = 0;
3310 key.p.key = NULL;
3311 }
3312
636a5d36
JM
3313 rtnl_lock();
3314
79c97e97 3315 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
636a5d36
JM
3316 if (err)
3317 goto unlock_rtnl;
3318
79c97e97 3319 if (!rdev->ops->auth) {
636a5d36
JM
3320 err = -EOPNOTSUPP;
3321 goto out;
3322 }
3323
eec60b03
JM
3324 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3325 err = -EOPNOTSUPP;
3326 goto out;
3327 }
3328
35a8efe1
JM
3329 if (!netif_running(dev)) {
3330 err = -ENETDOWN;
3331 goto out;
3332 }
3333
19957bb3 3334 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3335 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3336 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3337 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3338 err = -EINVAL;
3339 goto out;
636a5d36
JM
3340 }
3341
19957bb3
JB
3342 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3343 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3344
3345 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3346 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3347 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3348 }
3349
19957bb3
JB
3350 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3351 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3352 err = -EINVAL;
3353 goto out;
636a5d36
JM
3354 }
3355
79c97e97 3356 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934
JB
3357 ssid, ssid_len, ie, ie_len,
3358 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
3359
3360out:
79c97e97 3361 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3362 dev_put(dev);
3363unlock_rtnl:
3364 rtnl_unlock();
3365 return err;
3366}
3367
b23aa676 3368static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3369 struct cfg80211_crypto_settings *settings,
3370 int cipher_limit)
b23aa676
SO
3371{
3372 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3373
3374 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3375 void *data;
3376 int len, i;
3377
3378 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3379 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3380 settings->n_ciphers_pairwise = len / sizeof(u32);
3381
3382 if (len % sizeof(u32))
3383 return -EINVAL;
3384
3dc27d25 3385 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3386 return -EINVAL;
3387
3388 memcpy(settings->ciphers_pairwise, data, len);
3389
3390 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3391 if (!nl80211_valid_cipher_suite(
3392 settings->ciphers_pairwise[i]))
3393 return -EINVAL;
3394 }
3395
3396 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3397 settings->cipher_group =
3398 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3399 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3400 return -EINVAL;
3401 }
3402
3403 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3404 settings->wpa_versions =
3405 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3406 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3407 return -EINVAL;
3408 }
3409
3410 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3411 void *data;
3412 int len, i;
3413
3414 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3415 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3416 settings->n_akm_suites = len / sizeof(u32);
3417
3418 if (len % sizeof(u32))
3419 return -EINVAL;
3420
3421 memcpy(settings->akm_suites, data, len);
3422
3423 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3424 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3425 return -EINVAL;
3426 }
3427
3428 return 0;
3429}
3430
636a5d36
JM
3431static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3432{
19957bb3 3433 struct cfg80211_registered_device *rdev;
636a5d36 3434 struct net_device *dev;
19957bb3
JB
3435 struct cfg80211_crypto_settings crypto;
3436 struct ieee80211_channel *chan;
3e5d7649 3437 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3438 int err, ssid_len, ie_len = 0;
3439 bool use_mfp = false;
636a5d36 3440
f4a11bb0
JB
3441 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3442 return -EINVAL;
3443
3444 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3445 !info->attrs[NL80211_ATTR_SSID] ||
3446 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3447 return -EINVAL;
3448
636a5d36
JM
3449 rtnl_lock();
3450
79c97e97 3451 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
636a5d36
JM
3452 if (err)
3453 goto unlock_rtnl;
3454
19957bb3 3455 if (!rdev->ops->assoc) {
636a5d36
JM
3456 err = -EOPNOTSUPP;
3457 goto out;
3458 }
3459
eec60b03
JM
3460 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3461 err = -EOPNOTSUPP;
3462 goto out;
3463 }
3464
35a8efe1
JM
3465 if (!netif_running(dev)) {
3466 err = -ENETDOWN;
3467 goto out;
3468 }
3469
19957bb3 3470 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3471
19957bb3
JB
3472 chan = ieee80211_get_channel(&rdev->wiphy,
3473 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3474 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3475 err = -EINVAL;
3476 goto out;
636a5d36
JM
3477 }
3478
19957bb3
JB
3479 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3480 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3481
3482 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3483 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3484 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3485 }
3486
dc6382ce 3487 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3488 enum nl80211_mfp mfp =
dc6382ce 3489 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3490 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3491 use_mfp = true;
4f5dadce 3492 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3493 err = -EINVAL;
3494 goto out;
3495 }
3496 }
3497
3e5d7649
JB
3498 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3499 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3500
3dc27d25 3501 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3502 if (!err)
3e5d7649
JB
3503 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3504 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3505 &crypto);
636a5d36
JM
3506
3507out:
4d0c8aea 3508 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3509 dev_put(dev);
3510unlock_rtnl:
3511 rtnl_unlock();
3512 return err;
3513}
3514
3515static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3516{
79c97e97 3517 struct cfg80211_registered_device *rdev;
636a5d36 3518 struct net_device *dev;
19957bb3
JB
3519 const u8 *ie = NULL, *bssid;
3520 int err, ie_len = 0;
3521 u16 reason_code;
636a5d36 3522
f4a11bb0
JB
3523 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3524 return -EINVAL;
3525
3526 if (!info->attrs[NL80211_ATTR_MAC])
3527 return -EINVAL;
3528
3529 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3530 return -EINVAL;
3531
636a5d36
JM
3532 rtnl_lock();
3533
79c97e97 3534 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
636a5d36
JM
3535 if (err)
3536 goto unlock_rtnl;
3537
79c97e97 3538 if (!rdev->ops->deauth) {
636a5d36
JM
3539 err = -EOPNOTSUPP;
3540 goto out;
3541 }
3542
eec60b03
JM
3543 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3544 err = -EOPNOTSUPP;
3545 goto out;
3546 }
3547
35a8efe1
JM
3548 if (!netif_running(dev)) {
3549 err = -ENETDOWN;
3550 goto out;
3551 }
3552
19957bb3 3553 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3554
19957bb3
JB
3555 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3556 if (reason_code == 0) {
f4a11bb0
JB
3557 /* Reason Code 0 is reserved */
3558 err = -EINVAL;
3559 goto out;
255e737e 3560 }
636a5d36
JM
3561
3562 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3563 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3564 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3565 }
3566
79c97e97 3567 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3568
3569out:
79c97e97 3570 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3571 dev_put(dev);
3572unlock_rtnl:
3573 rtnl_unlock();
3574 return err;
3575}
3576
3577static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3578{
79c97e97 3579 struct cfg80211_registered_device *rdev;
636a5d36 3580 struct net_device *dev;
19957bb3
JB
3581 const u8 *ie = NULL, *bssid;
3582 int err, ie_len = 0;
3583 u16 reason_code;
636a5d36 3584
f4a11bb0
JB
3585 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3586 return -EINVAL;
3587
3588 if (!info->attrs[NL80211_ATTR_MAC])
3589 return -EINVAL;
3590
3591 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3592 return -EINVAL;
3593
636a5d36
JM
3594 rtnl_lock();
3595
79c97e97 3596 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
636a5d36
JM
3597 if (err)
3598 goto unlock_rtnl;
3599
79c97e97 3600 if (!rdev->ops->disassoc) {
636a5d36
JM
3601 err = -EOPNOTSUPP;
3602 goto out;
3603 }
3604
eec60b03
JM
3605 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3606 err = -EOPNOTSUPP;
3607 goto out;
3608 }
3609
35a8efe1
JM
3610 if (!netif_running(dev)) {
3611 err = -ENETDOWN;
3612 goto out;
3613 }
3614
19957bb3 3615 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3616
19957bb3
JB
3617 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3618 if (reason_code == 0) {
f4a11bb0
JB
3619 /* Reason Code 0 is reserved */
3620 err = -EINVAL;
3621 goto out;
255e737e 3622 }
636a5d36
JM
3623
3624 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3625 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3626 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3627 }
3628
79c97e97 3629 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3630
3631out:
79c97e97 3632 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3633 dev_put(dev);
3634unlock_rtnl:
3635 rtnl_unlock();
3636 return err;
3637}
3638
04a773ad
JB
3639static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3640{
79c97e97 3641 struct cfg80211_registered_device *rdev;
04a773ad
JB
3642 struct net_device *dev;
3643 struct cfg80211_ibss_params ibss;
3644 struct wiphy *wiphy;
fffd0934 3645 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3646 int err;
3647
8e30bc55
JB
3648 memset(&ibss, 0, sizeof(ibss));
3649
04a773ad
JB
3650 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3651 return -EINVAL;
3652
3653 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3654 !info->attrs[NL80211_ATTR_SSID] ||
3655 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3656 return -EINVAL;
3657
8e30bc55
JB
3658 ibss.beacon_interval = 100;
3659
3660 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3661 ibss.beacon_interval =
3662 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3663 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3664 return -EINVAL;
3665 }
3666
04a773ad
JB
3667 rtnl_lock();
3668
79c97e97 3669 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
04a773ad
JB
3670 if (err)
3671 goto unlock_rtnl;
3672
79c97e97 3673 if (!rdev->ops->join_ibss) {
04a773ad
JB
3674 err = -EOPNOTSUPP;
3675 goto out;
3676 }
3677
3678 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3679 err = -EOPNOTSUPP;
3680 goto out;
3681 }
3682
3683 if (!netif_running(dev)) {
3684 err = -ENETDOWN;
3685 goto out;
3686 }
3687
79c97e97 3688 wiphy = &rdev->wiphy;
04a773ad
JB
3689
3690 if (info->attrs[NL80211_ATTR_MAC])
3691 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3692 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3693 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3694
3695 if (info->attrs[NL80211_ATTR_IE]) {
3696 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3697 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3698 }
3699
3700 ibss.channel = ieee80211_get_channel(wiphy,
3701 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3702 if (!ibss.channel ||
3703 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3704 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3705 err = -EINVAL;
3706 goto out;
3707 }
3708
3709 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3710 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3711
3712 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3713 connkeys = nl80211_parse_connkeys(rdev,
3714 info->attrs[NL80211_ATTR_KEYS]);
3715 if (IS_ERR(connkeys)) {
3716 err = PTR_ERR(connkeys);
3717 connkeys = NULL;
3718 goto out;
3719 }
3720 }
04a773ad 3721
fffd0934 3722 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
3723
3724out:
79c97e97 3725 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3726 dev_put(dev);
3727unlock_rtnl:
fffd0934
JB
3728 if (err)
3729 kfree(connkeys);
04a773ad
JB
3730 rtnl_unlock();
3731 return err;
3732}
3733
3734static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3735{
79c97e97 3736 struct cfg80211_registered_device *rdev;
04a773ad
JB
3737 struct net_device *dev;
3738 int err;
3739
3740 rtnl_lock();
3741
79c97e97 3742 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
04a773ad
JB
3743 if (err)
3744 goto unlock_rtnl;
3745
79c97e97 3746 if (!rdev->ops->leave_ibss) {
04a773ad
JB
3747 err = -EOPNOTSUPP;
3748 goto out;
3749 }
3750
3751 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3752 err = -EOPNOTSUPP;
3753 goto out;
3754 }
3755
3756 if (!netif_running(dev)) {
3757 err = -ENETDOWN;
3758 goto out;
3759 }
3760
79c97e97 3761 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3762
3763out:
79c97e97 3764 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3765 dev_put(dev);
3766unlock_rtnl:
3767 rtnl_unlock();
3768 return err;
3769}
3770
aff89a9b
JB
3771#ifdef CONFIG_NL80211_TESTMODE
3772static struct genl_multicast_group nl80211_testmode_mcgrp = {
3773 .name = "testmode",
3774};
3775
3776static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3777{
3778 struct cfg80211_registered_device *rdev;
3779 int err;
3780
3781 if (!info->attrs[NL80211_ATTR_TESTDATA])
3782 return -EINVAL;
3783
3784 rtnl_lock();
3785
3786 rdev = cfg80211_get_dev_from_info(info);
3787 if (IS_ERR(rdev)) {
3788 err = PTR_ERR(rdev);
3789 goto unlock_rtnl;
3790 }
3791
3792 err = -EOPNOTSUPP;
3793 if (rdev->ops->testmode_cmd) {
3794 rdev->testmode_info = info;
3795 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3796 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3797 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3798 rdev->testmode_info = NULL;
3799 }
3800
4d0c8aea 3801 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
3802
3803 unlock_rtnl:
3804 rtnl_unlock();
3805 return err;
3806}
3807
3808static struct sk_buff *
3809__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3810 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3811{
3812 struct sk_buff *skb;
3813 void *hdr;
3814 struct nlattr *data;
3815
3816 skb = nlmsg_new(approxlen + 100, gfp);
3817 if (!skb)
3818 return NULL;
3819
3820 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3821 if (!hdr) {
3822 kfree_skb(skb);
3823 return NULL;
3824 }
3825
3826 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3827 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3828
3829 ((void **)skb->cb)[0] = rdev;
3830 ((void **)skb->cb)[1] = hdr;
3831 ((void **)skb->cb)[2] = data;
3832
3833 return skb;
3834
3835 nla_put_failure:
3836 kfree_skb(skb);
3837 return NULL;
3838}
3839
3840struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3841 int approxlen)
3842{
3843 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3844
3845 if (WARN_ON(!rdev->testmode_info))
3846 return NULL;
3847
3848 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3849 rdev->testmode_info->snd_pid,
3850 rdev->testmode_info->snd_seq,
3851 GFP_KERNEL);
3852}
3853EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3854
3855int cfg80211_testmode_reply(struct sk_buff *skb)
3856{
3857 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3858 void *hdr = ((void **)skb->cb)[1];
3859 struct nlattr *data = ((void **)skb->cb)[2];
3860
3861 if (WARN_ON(!rdev->testmode_info)) {
3862 kfree_skb(skb);
3863 return -EINVAL;
3864 }
3865
3866 nla_nest_end(skb, data);
3867 genlmsg_end(skb, hdr);
3868 return genlmsg_reply(skb, rdev->testmode_info);
3869}
3870EXPORT_SYMBOL(cfg80211_testmode_reply);
3871
3872struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3873 int approxlen, gfp_t gfp)
3874{
3875 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3876
3877 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3878}
3879EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3880
3881void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3882{
3883 void *hdr = ((void **)skb->cb)[1];
3884 struct nlattr *data = ((void **)skb->cb)[2];
3885
3886 nla_nest_end(skb, data);
3887 genlmsg_end(skb, hdr);
3888 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3889}
3890EXPORT_SYMBOL(cfg80211_testmode_event);
3891#endif
3892
b23aa676
SO
3893static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3894{
79c97e97 3895 struct cfg80211_registered_device *rdev;
b23aa676
SO
3896 struct net_device *dev;
3897 struct cfg80211_connect_params connect;
3898 struct wiphy *wiphy;
fffd0934 3899 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
3900 int err;
3901
3902 memset(&connect, 0, sizeof(connect));
3903
3904 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3905 return -EINVAL;
3906
3907 if (!info->attrs[NL80211_ATTR_SSID] ||
3908 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3909 return -EINVAL;
3910
3911 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3912 connect.auth_type =
3913 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3914 if (!nl80211_valid_auth_type(connect.auth_type))
3915 return -EINVAL;
3916 } else
3917 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3918
3919 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3920
3dc27d25
JB
3921 err = nl80211_crypto_settings(info, &connect.crypto,
3922 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
3923 if (err)
3924 return err;
3925 rtnl_lock();
3926
79c97e97 3927 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
b23aa676
SO
3928 if (err)
3929 goto unlock_rtnl;
3930
3931 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3932 err = -EOPNOTSUPP;
3933 goto out;
3934 }
3935
3936 if (!netif_running(dev)) {
3937 err = -ENETDOWN;
3938 goto out;
3939 }
3940
79c97e97 3941 wiphy = &rdev->wiphy;
b23aa676 3942
b23aa676
SO
3943 if (info->attrs[NL80211_ATTR_MAC])
3944 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3945 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3946 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3947
3948 if (info->attrs[NL80211_ATTR_IE]) {
3949 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3950 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3951 }
3952
3953 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3954 connect.channel =
3955 ieee80211_get_channel(wiphy,
3956 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3957 if (!connect.channel ||
3958 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
3959 err = -EINVAL;
3960 goto out;
3961 }
3962 }
3963
fffd0934
JB
3964 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3965 connkeys = nl80211_parse_connkeys(rdev,
3966 info->attrs[NL80211_ATTR_KEYS]);
3967 if (IS_ERR(connkeys)) {
3968 err = PTR_ERR(connkeys);
3969 connkeys = NULL;
3970 goto out;
3971 }
3972 }
3973
3974 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
3975
3976out:
79c97e97 3977 cfg80211_unlock_rdev(rdev);
b23aa676
SO
3978 dev_put(dev);
3979unlock_rtnl:
fffd0934
JB
3980 if (err)
3981 kfree(connkeys);
b23aa676
SO
3982 rtnl_unlock();
3983 return err;
3984}
3985
3986static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
3987{
79c97e97 3988 struct cfg80211_registered_device *rdev;
b23aa676
SO
3989 struct net_device *dev;
3990 int err;
3991 u16 reason;
3992
3993 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3994 reason = WLAN_REASON_DEAUTH_LEAVING;
3995 else
3996 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3997
3998 if (reason == 0)
3999 return -EINVAL;
4000
4001 rtnl_lock();
4002
79c97e97 4003 err = get_rdev_dev_by_info_ifindex(info->attrs, &rdev, &dev);
b23aa676
SO
4004 if (err)
4005 goto unlock_rtnl;
4006
4007 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4008 err = -EOPNOTSUPP;
4009 goto out;
4010 }
4011
4012 if (!netif_running(dev)) {
4013 err = -ENETDOWN;
4014 goto out;
4015 }
4016
79c97e97 4017 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4018
4019out:
79c97e97 4020 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4021 dev_put(dev);
4022unlock_rtnl:
4023 rtnl_unlock();
4024 return err;
4025}
4026
55682965
JB
4027static struct genl_ops nl80211_ops[] = {
4028 {
4029 .cmd = NL80211_CMD_GET_WIPHY,
4030 .doit = nl80211_get_wiphy,
4031 .dumpit = nl80211_dump_wiphy,
4032 .policy = nl80211_policy,
4033 /* can be retrieved by unprivileged users */
4034 },
4035 {
4036 .cmd = NL80211_CMD_SET_WIPHY,
4037 .doit = nl80211_set_wiphy,
4038 .policy = nl80211_policy,
4039 .flags = GENL_ADMIN_PERM,
4040 },
4041 {
4042 .cmd = NL80211_CMD_GET_INTERFACE,
4043 .doit = nl80211_get_interface,
4044 .dumpit = nl80211_dump_interface,
4045 .policy = nl80211_policy,
4046 /* can be retrieved by unprivileged users */
4047 },
4048 {
4049 .cmd = NL80211_CMD_SET_INTERFACE,
4050 .doit = nl80211_set_interface,
4051 .policy = nl80211_policy,
4052 .flags = GENL_ADMIN_PERM,
4053 },
4054 {
4055 .cmd = NL80211_CMD_NEW_INTERFACE,
4056 .doit = nl80211_new_interface,
4057 .policy = nl80211_policy,
4058 .flags = GENL_ADMIN_PERM,
4059 },
4060 {
4061 .cmd = NL80211_CMD_DEL_INTERFACE,
4062 .doit = nl80211_del_interface,
4063 .policy = nl80211_policy,
41ade00f
JB
4064 .flags = GENL_ADMIN_PERM,
4065 },
4066 {
4067 .cmd = NL80211_CMD_GET_KEY,
4068 .doit = nl80211_get_key,
4069 .policy = nl80211_policy,
4070 .flags = GENL_ADMIN_PERM,
4071 },
4072 {
4073 .cmd = NL80211_CMD_SET_KEY,
4074 .doit = nl80211_set_key,
4075 .policy = nl80211_policy,
4076 .flags = GENL_ADMIN_PERM,
4077 },
4078 {
4079 .cmd = NL80211_CMD_NEW_KEY,
4080 .doit = nl80211_new_key,
4081 .policy = nl80211_policy,
4082 .flags = GENL_ADMIN_PERM,
4083 },
4084 {
4085 .cmd = NL80211_CMD_DEL_KEY,
4086 .doit = nl80211_del_key,
4087 .policy = nl80211_policy,
55682965
JB
4088 .flags = GENL_ADMIN_PERM,
4089 },
ed1b6cc7
JB
4090 {
4091 .cmd = NL80211_CMD_SET_BEACON,
4092 .policy = nl80211_policy,
4093 .flags = GENL_ADMIN_PERM,
4094 .doit = nl80211_addset_beacon,
4095 },
4096 {
4097 .cmd = NL80211_CMD_NEW_BEACON,
4098 .policy = nl80211_policy,
4099 .flags = GENL_ADMIN_PERM,
4100 .doit = nl80211_addset_beacon,
4101 },
4102 {
4103 .cmd = NL80211_CMD_DEL_BEACON,
4104 .policy = nl80211_policy,
4105 .flags = GENL_ADMIN_PERM,
4106 .doit = nl80211_del_beacon,
4107 },
5727ef1b
JB
4108 {
4109 .cmd = NL80211_CMD_GET_STATION,
4110 .doit = nl80211_get_station,
2ec600d6 4111 .dumpit = nl80211_dump_station,
5727ef1b 4112 .policy = nl80211_policy,
5727ef1b
JB
4113 },
4114 {
4115 .cmd = NL80211_CMD_SET_STATION,
4116 .doit = nl80211_set_station,
4117 .policy = nl80211_policy,
4118 .flags = GENL_ADMIN_PERM,
4119 },
4120 {
4121 .cmd = NL80211_CMD_NEW_STATION,
4122 .doit = nl80211_new_station,
4123 .policy = nl80211_policy,
4124 .flags = GENL_ADMIN_PERM,
4125 },
4126 {
4127 .cmd = NL80211_CMD_DEL_STATION,
4128 .doit = nl80211_del_station,
4129 .policy = nl80211_policy,
2ec600d6
LCC
4130 .flags = GENL_ADMIN_PERM,
4131 },
4132 {
4133 .cmd = NL80211_CMD_GET_MPATH,
4134 .doit = nl80211_get_mpath,
4135 .dumpit = nl80211_dump_mpath,
4136 .policy = nl80211_policy,
4137 .flags = GENL_ADMIN_PERM,
4138 },
4139 {
4140 .cmd = NL80211_CMD_SET_MPATH,
4141 .doit = nl80211_set_mpath,
4142 .policy = nl80211_policy,
4143 .flags = GENL_ADMIN_PERM,
4144 },
4145 {
4146 .cmd = NL80211_CMD_NEW_MPATH,
4147 .doit = nl80211_new_mpath,
4148 .policy = nl80211_policy,
4149 .flags = GENL_ADMIN_PERM,
4150 },
4151 {
4152 .cmd = NL80211_CMD_DEL_MPATH,
4153 .doit = nl80211_del_mpath,
4154 .policy = nl80211_policy,
9f1ba906
JM
4155 .flags = GENL_ADMIN_PERM,
4156 },
4157 {
4158 .cmd = NL80211_CMD_SET_BSS,
4159 .doit = nl80211_set_bss,
4160 .policy = nl80211_policy,
b2e1b302
LR
4161 .flags = GENL_ADMIN_PERM,
4162 },
f130347c
LR
4163 {
4164 .cmd = NL80211_CMD_GET_REG,
4165 .doit = nl80211_get_reg,
4166 .policy = nl80211_policy,
4167 /* can be retrieved by unprivileged users */
4168 },
b2e1b302
LR
4169 {
4170 .cmd = NL80211_CMD_SET_REG,
4171 .doit = nl80211_set_reg,
4172 .policy = nl80211_policy,
4173 .flags = GENL_ADMIN_PERM,
4174 },
4175 {
4176 .cmd = NL80211_CMD_REQ_SET_REG,
4177 .doit = nl80211_req_set_reg,
4178 .policy = nl80211_policy,
93da9cc1 4179 .flags = GENL_ADMIN_PERM,
4180 },
4181 {
4182 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4183 .doit = nl80211_get_mesh_params,
4184 .policy = nl80211_policy,
4185 /* can be retrieved by unprivileged users */
4186 },
4187 {
4188 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4189 .doit = nl80211_set_mesh_params,
4190 .policy = nl80211_policy,
9aed3cc1
JM
4191 .flags = GENL_ADMIN_PERM,
4192 },
2a519311
JB
4193 {
4194 .cmd = NL80211_CMD_TRIGGER_SCAN,
4195 .doit = nl80211_trigger_scan,
4196 .policy = nl80211_policy,
4197 .flags = GENL_ADMIN_PERM,
4198 },
4199 {
4200 .cmd = NL80211_CMD_GET_SCAN,
4201 .policy = nl80211_policy,
4202 .dumpit = nl80211_dump_scan,
4203 },
636a5d36
JM
4204 {
4205 .cmd = NL80211_CMD_AUTHENTICATE,
4206 .doit = nl80211_authenticate,
4207 .policy = nl80211_policy,
4208 .flags = GENL_ADMIN_PERM,
4209 },
4210 {
4211 .cmd = NL80211_CMD_ASSOCIATE,
4212 .doit = nl80211_associate,
4213 .policy = nl80211_policy,
4214 .flags = GENL_ADMIN_PERM,
4215 },
4216 {
4217 .cmd = NL80211_CMD_DEAUTHENTICATE,
4218 .doit = nl80211_deauthenticate,
4219 .policy = nl80211_policy,
4220 .flags = GENL_ADMIN_PERM,
4221 },
4222 {
4223 .cmd = NL80211_CMD_DISASSOCIATE,
4224 .doit = nl80211_disassociate,
4225 .policy = nl80211_policy,
4226 .flags = GENL_ADMIN_PERM,
4227 },
04a773ad
JB
4228 {
4229 .cmd = NL80211_CMD_JOIN_IBSS,
4230 .doit = nl80211_join_ibss,
4231 .policy = nl80211_policy,
4232 .flags = GENL_ADMIN_PERM,
4233 },
4234 {
4235 .cmd = NL80211_CMD_LEAVE_IBSS,
4236 .doit = nl80211_leave_ibss,
4237 .policy = nl80211_policy,
4238 .flags = GENL_ADMIN_PERM,
4239 },
aff89a9b
JB
4240#ifdef CONFIG_NL80211_TESTMODE
4241 {
4242 .cmd = NL80211_CMD_TESTMODE,
4243 .doit = nl80211_testmode_do,
4244 .policy = nl80211_policy,
4245 .flags = GENL_ADMIN_PERM,
4246 },
4247#endif
b23aa676
SO
4248 {
4249 .cmd = NL80211_CMD_CONNECT,
4250 .doit = nl80211_connect,
4251 .policy = nl80211_policy,
4252 .flags = GENL_ADMIN_PERM,
4253 },
4254 {
4255 .cmd = NL80211_CMD_DISCONNECT,
4256 .doit = nl80211_disconnect,
4257 .policy = nl80211_policy,
4258 .flags = GENL_ADMIN_PERM,
4259 },
55682965 4260};
6039f6d2
JM
4261static struct genl_multicast_group nl80211_mlme_mcgrp = {
4262 .name = "mlme",
4263};
55682965
JB
4264
4265/* multicast groups */
4266static struct genl_multicast_group nl80211_config_mcgrp = {
4267 .name = "config",
4268};
2a519311
JB
4269static struct genl_multicast_group nl80211_scan_mcgrp = {
4270 .name = "scan",
4271};
73d54c9e
LR
4272static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4273 .name = "regulatory",
4274};
55682965
JB
4275
4276/* notification functions */
4277
4278void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4279{
4280 struct sk_buff *msg;
4281
fd2120ca 4282 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
4283 if (!msg)
4284 return;
4285
4286 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4287 nlmsg_free(msg);
4288 return;
4289 }
4290
4291 genlmsg_multicast(msg, 0, nl80211_config_mcgrp.id, GFP_KERNEL);
4292}
4293
362a415d
JB
4294static int nl80211_add_scan_req(struct sk_buff *msg,
4295 struct cfg80211_registered_device *rdev)
4296{
4297 struct cfg80211_scan_request *req = rdev->scan_req;
4298 struct nlattr *nest;
4299 int i;
4300
667503dd
JB
4301 ASSERT_RDEV_LOCK(rdev);
4302
362a415d
JB
4303 if (WARN_ON(!req))
4304 return 0;
4305
4306 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4307 if (!nest)
4308 goto nla_put_failure;
4309 for (i = 0; i < req->n_ssids; i++)
4310 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4311 nla_nest_end(msg, nest);
4312
4313 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4314 if (!nest)
4315 goto nla_put_failure;
4316 for (i = 0; i < req->n_channels; i++)
4317 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4318 nla_nest_end(msg, nest);
4319
4320 if (req->ie)
4321 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4322
4323 return 0;
4324 nla_put_failure:
4325 return -ENOBUFS;
4326}
4327
a538e2d5
JB
4328static int nl80211_send_scan_msg(struct sk_buff *msg,
4329 struct cfg80211_registered_device *rdev,
4330 struct net_device *netdev,
4331 u32 pid, u32 seq, int flags,
4332 u32 cmd)
2a519311
JB
4333{
4334 void *hdr;
4335
4336 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4337 if (!hdr)
4338 return -1;
4339
b5850a7a 4340 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
4341 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4342
362a415d
JB
4343 /* ignore errors and send incomplete event anyway */
4344 nl80211_add_scan_req(msg, rdev);
2a519311
JB
4345
4346 return genlmsg_end(msg, hdr);
4347
4348 nla_put_failure:
4349 genlmsg_cancel(msg, hdr);
4350 return -EMSGSIZE;
4351}
4352
a538e2d5
JB
4353void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4354 struct net_device *netdev)
4355{
4356 struct sk_buff *msg;
4357
4358 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4359 if (!msg)
4360 return;
4361
4362 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4363 NL80211_CMD_TRIGGER_SCAN) < 0) {
4364 nlmsg_free(msg);
4365 return;
4366 }
4367
4368 genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
4369}
4370
2a519311
JB
4371void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4372 struct net_device *netdev)
4373{
4374 struct sk_buff *msg;
4375
fd2120ca 4376 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4377 if (!msg)
4378 return;
4379
a538e2d5
JB
4380 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4381 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
4382 nlmsg_free(msg);
4383 return;
4384 }
4385
4386 genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
4387}
4388
4389void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4390 struct net_device *netdev)
4391{
4392 struct sk_buff *msg;
4393
fd2120ca 4394 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4395 if (!msg)
4396 return;
4397
a538e2d5
JB
4398 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4399 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
4400 nlmsg_free(msg);
4401 return;
4402 }
4403
4404 genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
4405}
4406
73d54c9e
LR
4407/*
4408 * This can happen on global regulatory changes or device specific settings
4409 * based on custom world regulatory domains.
4410 */
4411void nl80211_send_reg_change_event(struct regulatory_request *request)
4412{
4413 struct sk_buff *msg;
4414 void *hdr;
4415
fd2120ca 4416 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
4417 if (!msg)
4418 return;
4419
4420 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4421 if (!hdr) {
4422 nlmsg_free(msg);
4423 return;
4424 }
4425
4426 /* Userspace can always count this one always being set */
4427 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4428
4429 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4430 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4431 NL80211_REGDOM_TYPE_WORLD);
4432 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4433 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4434 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4435 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4436 request->intersect)
4437 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4438 NL80211_REGDOM_TYPE_INTERSECTION);
4439 else {
4440 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4441 NL80211_REGDOM_TYPE_COUNTRY);
4442 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4443 }
4444
4445 if (wiphy_idx_valid(request->wiphy_idx))
4446 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4447
4448 if (genlmsg_end(msg, hdr) < 0) {
4449 nlmsg_free(msg);
4450 return;
4451 }
4452
4453 genlmsg_multicast(msg, 0, nl80211_regulatory_mcgrp.id, GFP_KERNEL);
4454
4455 return;
4456
4457nla_put_failure:
4458 genlmsg_cancel(msg, hdr);
4459 nlmsg_free(msg);
4460}
4461
6039f6d2
JM
4462static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4463 struct net_device *netdev,
4464 const u8 *buf, size_t len,
e6d6e342 4465 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
4466{
4467 struct sk_buff *msg;
4468 void *hdr;
4469
e6d6e342 4470 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
4471 if (!msg)
4472 return;
4473
4474 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4475 if (!hdr) {
4476 nlmsg_free(msg);
4477 return;
4478 }
4479
4480 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4481 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4482 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4483
4484 if (genlmsg_end(msg, hdr) < 0) {
4485 nlmsg_free(msg);
4486 return;
4487 }
4488
e6d6e342 4489 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
4490 return;
4491
4492 nla_put_failure:
4493 genlmsg_cancel(msg, hdr);
4494 nlmsg_free(msg);
4495}
4496
4497void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4498 struct net_device *netdev, const u8 *buf,
4499 size_t len, gfp_t gfp)
6039f6d2
JM
4500{
4501 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4502 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
4503}
4504
4505void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4506 struct net_device *netdev, const u8 *buf,
e6d6e342 4507 size_t len, gfp_t gfp)
6039f6d2 4508{
e6d6e342
JB
4509 nl80211_send_mlme_event(rdev, netdev, buf, len,
4510 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
4511}
4512
53b46b84 4513void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4514 struct net_device *netdev, const u8 *buf,
4515 size_t len, gfp_t gfp)
6039f6d2
JM
4516{
4517 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4518 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
4519}
4520
53b46b84
JM
4521void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4522 struct net_device *netdev, const u8 *buf,
e6d6e342 4523 size_t len, gfp_t gfp)
6039f6d2
JM
4524{
4525 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4526 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
4527}
4528
1b06bb40
LR
4529static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4530 struct net_device *netdev, int cmd,
e6d6e342 4531 const u8 *addr, gfp_t gfp)
1965c853
JM
4532{
4533 struct sk_buff *msg;
4534 void *hdr;
4535
e6d6e342 4536 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
4537 if (!msg)
4538 return;
4539
4540 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4541 if (!hdr) {
4542 nlmsg_free(msg);
4543 return;
4544 }
4545
4546 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4547 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4548 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4549 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4550
4551 if (genlmsg_end(msg, hdr) < 0) {
4552 nlmsg_free(msg);
4553 return;
4554 }
4555
e6d6e342 4556 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
4557 return;
4558
4559 nla_put_failure:
4560 genlmsg_cancel(msg, hdr);
4561 nlmsg_free(msg);
4562}
4563
4564void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4565 struct net_device *netdev, const u8 *addr,
4566 gfp_t gfp)
1965c853
JM
4567{
4568 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 4569 addr, gfp);
1965c853
JM
4570}
4571
4572void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4573 struct net_device *netdev, const u8 *addr,
4574 gfp_t gfp)
1965c853 4575{
e6d6e342
JB
4576 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4577 addr, gfp);
1965c853
JM
4578}
4579
b23aa676
SO
4580void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4581 struct net_device *netdev, const u8 *bssid,
4582 const u8 *req_ie, size_t req_ie_len,
4583 const u8 *resp_ie, size_t resp_ie_len,
4584 u16 status, gfp_t gfp)
4585{
4586 struct sk_buff *msg;
4587 void *hdr;
4588
4589 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4590 if (!msg)
4591 return;
4592
4593 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4594 if (!hdr) {
4595 nlmsg_free(msg);
4596 return;
4597 }
4598
4599 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4600 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4601 if (bssid)
4602 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4603 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4604 if (req_ie)
4605 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4606 if (resp_ie)
4607 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4608
4609 if (genlmsg_end(msg, hdr) < 0) {
4610 nlmsg_free(msg);
4611 return;
4612 }
4613
4614 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4615 return;
4616
4617 nla_put_failure:
4618 genlmsg_cancel(msg, hdr);
4619 nlmsg_free(msg);
4620
4621}
4622
4623void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4624 struct net_device *netdev, const u8 *bssid,
4625 const u8 *req_ie, size_t req_ie_len,
4626 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4627{
4628 struct sk_buff *msg;
4629 void *hdr;
4630
4631 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4632 if (!msg)
4633 return;
4634
4635 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4636 if (!hdr) {
4637 nlmsg_free(msg);
4638 return;
4639 }
4640
4641 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4642 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4643 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4644 if (req_ie)
4645 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4646 if (resp_ie)
4647 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4648
4649 if (genlmsg_end(msg, hdr) < 0) {
4650 nlmsg_free(msg);
4651 return;
4652 }
4653
4654 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4655 return;
4656
4657 nla_put_failure:
4658 genlmsg_cancel(msg, hdr);
4659 nlmsg_free(msg);
4660
4661}
4662
4663void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4664 struct net_device *netdev, u16 reason,
667503dd 4665 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
4666{
4667 struct sk_buff *msg;
4668 void *hdr;
4669
667503dd 4670 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
4671 if (!msg)
4672 return;
4673
4674 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4675 if (!hdr) {
4676 nlmsg_free(msg);
4677 return;
4678 }
4679
4680 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4681 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4682 if (from_ap && reason)
4683 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4684 if (from_ap)
4685 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4686 if (ie)
4687 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4688
4689 if (genlmsg_end(msg, hdr) < 0) {
4690 nlmsg_free(msg);
4691 return;
4692 }
4693
667503dd 4694 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
4695 return;
4696
4697 nla_put_failure:
4698 genlmsg_cancel(msg, hdr);
4699 nlmsg_free(msg);
4700
4701}
4702
04a773ad
JB
4703void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4704 struct net_device *netdev, const u8 *bssid,
4705 gfp_t gfp)
4706{
4707 struct sk_buff *msg;
4708 void *hdr;
4709
fd2120ca 4710 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
4711 if (!msg)
4712 return;
4713
4714 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4715 if (!hdr) {
4716 nlmsg_free(msg);
4717 return;
4718 }
4719
4720 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4721 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4722 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4723
4724 if (genlmsg_end(msg, hdr) < 0) {
4725 nlmsg_free(msg);
4726 return;
4727 }
4728
4729 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4730 return;
4731
4732 nla_put_failure:
4733 genlmsg_cancel(msg, hdr);
4734 nlmsg_free(msg);
4735}
4736
a3b8b056
JM
4737void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4738 struct net_device *netdev, const u8 *addr,
4739 enum nl80211_key_type key_type, int key_id,
e6d6e342 4740 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
4741{
4742 struct sk_buff *msg;
4743 void *hdr;
4744
e6d6e342 4745 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
4746 if (!msg)
4747 return;
4748
4749 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4750 if (!hdr) {
4751 nlmsg_free(msg);
4752 return;
4753 }
4754
4755 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4756 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4757 if (addr)
4758 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4759 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4760 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4761 if (tsc)
4762 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4763
4764 if (genlmsg_end(msg, hdr) < 0) {
4765 nlmsg_free(msg);
4766 return;
4767 }
4768
e6d6e342 4769 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
4770 return;
4771
4772 nla_put_failure:
4773 genlmsg_cancel(msg, hdr);
4774 nlmsg_free(msg);
4775}
4776
6bad8766
LR
4777void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
4778 struct ieee80211_channel *channel_before,
4779 struct ieee80211_channel *channel_after)
4780{
4781 struct sk_buff *msg;
4782 void *hdr;
4783 struct nlattr *nl_freq;
4784
fd2120ca 4785 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
4786 if (!msg)
4787 return;
4788
4789 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
4790 if (!hdr) {
4791 nlmsg_free(msg);
4792 return;
4793 }
4794
4795 /*
4796 * Since we are applying the beacon hint to a wiphy we know its
4797 * wiphy_idx is valid
4798 */
4799 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
4800
4801 /* Before */
4802 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
4803 if (!nl_freq)
4804 goto nla_put_failure;
4805 if (nl80211_msg_put_channel(msg, channel_before))
4806 goto nla_put_failure;
4807 nla_nest_end(msg, nl_freq);
4808
4809 /* After */
4810 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
4811 if (!nl_freq)
4812 goto nla_put_failure;
4813 if (nl80211_msg_put_channel(msg, channel_after))
4814 goto nla_put_failure;
4815 nla_nest_end(msg, nl_freq);
4816
4817 if (genlmsg_end(msg, hdr) < 0) {
4818 nlmsg_free(msg);
4819 return;
4820 }
4821
4822 genlmsg_multicast(msg, 0, nl80211_regulatory_mcgrp.id, GFP_ATOMIC);
4823
4824 return;
4825
4826nla_put_failure:
4827 genlmsg_cancel(msg, hdr);
4828 nlmsg_free(msg);
4829}
4830
55682965
JB
4831/* initialisation/exit functions */
4832
4833int nl80211_init(void)
4834{
0d63cbb5 4835 int err;
55682965 4836
0d63cbb5
MM
4837 err = genl_register_family_with_ops(&nl80211_fam,
4838 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
4839 if (err)
4840 return err;
4841
55682965
JB
4842 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
4843 if (err)
4844 goto err_out;
4845
2a519311
JB
4846 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
4847 if (err)
4848 goto err_out;
4849
73d54c9e
LR
4850 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
4851 if (err)
4852 goto err_out;
4853
6039f6d2
JM
4854 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
4855 if (err)
4856 goto err_out;
4857
aff89a9b
JB
4858#ifdef CONFIG_NL80211_TESTMODE
4859 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
4860 if (err)
4861 goto err_out;
4862#endif
4863
55682965
JB
4864 return 0;
4865 err_out:
4866 genl_unregister_family(&nl80211_fam);
4867 return err;
4868}
4869
4870void nl80211_exit(void)
4871{
4872 genl_unregister_family(&nl80211_fam);
4873}