]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
cfg80211: assimilate and export ieee80211_bss_get_ie
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
08645126 4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
55682965
JB
10#include <linux/list.h>
11#include <linux/if_ether.h>
12#include <linux/ieee80211.h>
13#include <linux/nl80211.h>
14#include <linux/rtnetlink.h>
15#include <linux/netlink.h>
2a519311 16#include <linux/etherdevice.h>
55682965
JB
17#include <net/genetlink.h>
18#include <net/cfg80211.h>
19#include "core.h"
20#include "nl80211.h"
b2e1b302 21#include "reg.h"
55682965
JB
22
23/* the netlink family */
24static struct genl_family nl80211_fam = {
25 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
26 .name = "nl80211", /* have users key off the name instead */
27 .hdrsize = 0, /* no private header */
28 .version = 1, /* no particular meaning now */
29 .maxattr = NL80211_ATTR_MAX,
30};
31
32/* internal helper: get drv and dev */
bba95fef 33static int get_drv_dev_by_info_ifindex(struct nlattr **attrs,
55682965
JB
34 struct cfg80211_registered_device **drv,
35 struct net_device **dev)
36{
37 int ifindex;
38
bba95fef 39 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
40 return -EINVAL;
41
bba95fef 42 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
55682965
JB
43 *dev = dev_get_by_index(&init_net, ifindex);
44 if (!*dev)
45 return -ENODEV;
46
47 *drv = cfg80211_get_dev_from_ifindex(ifindex);
48 if (IS_ERR(*drv)) {
49 dev_put(*dev);
50 return PTR_ERR(*drv);
51 }
52
53 return 0;
54}
55
56/* policy for the attributes */
57static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
58 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
59 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 60 .len = 20-1 },
31888487 61 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 62 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 63 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
64 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
65 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
66 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
67 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
55682965
JB
68
69 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
70 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
71 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
72
73 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
74
75 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
76 .len = WLAN_MAX_KEY_LEN },
77 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
78 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
79 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 80 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
81
82 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
83 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
84 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
85 .len = IEEE80211_MAX_DATA_LEN },
86 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
87 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
88 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
89 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
90 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
91 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
92 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 93 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 94 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 95 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
96 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
97 .len = IEEE80211_MAX_MESH_ID_LEN },
98 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 99
b2e1b302
LR
100 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
101 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
102
9f1ba906
JM
103 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
104 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
105 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
106 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
107 .len = NL80211_MAX_SUPP_RATES },
36aedc90 108
93da9cc1 109 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
110
36aedc90
JM
111 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
112 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
113
114 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
115 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
116 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
117 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
118 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
119
120 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
121 .len = IEEE80211_MAX_SSID_LEN },
122 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
123 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 124 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 125 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 126 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
127 [NL80211_ATTR_STA_FLAGS2] = {
128 .len = sizeof(struct nl80211_sta_flag_update),
129 },
3f77316c 130 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
131 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
132 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
133 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
55682965
JB
134};
135
f4a11bb0
JB
136/* IE validation */
137static bool is_valid_ie_attr(const struct nlattr *attr)
138{
139 const u8 *pos;
140 int len;
141
142 if (!attr)
143 return true;
144
145 pos = nla_data(attr);
146 len = nla_len(attr);
147
148 while (len) {
149 u8 elemlen;
150
151 if (len < 2)
152 return false;
153 len -= 2;
154
155 elemlen = pos[1];
156 if (elemlen > len)
157 return false;
158
159 len -= elemlen;
160 pos += 2 + elemlen;
161 }
162
163 return true;
164}
165
55682965
JB
166/* message building helper */
167static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
168 int flags, u8 cmd)
169{
170 /* since there is no private header just add the generic one */
171 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
172}
173
5dab3b8a
LR
174static int nl80211_msg_put_channel(struct sk_buff *msg,
175 struct ieee80211_channel *chan)
176{
177 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
178 chan->center_freq);
179
180 if (chan->flags & IEEE80211_CHAN_DISABLED)
181 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
182 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
183 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
184 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
185 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
186 if (chan->flags & IEEE80211_CHAN_RADAR)
187 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
188
189 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
190 DBM_TO_MBM(chan->max_power));
191
192 return 0;
193
194 nla_put_failure:
195 return -ENOBUFS;
196}
197
55682965
JB
198/* netlink command implementations */
199
200static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
201 struct cfg80211_registered_device *dev)
202{
203 void *hdr;
ee688b00
JB
204 struct nlattr *nl_bands, *nl_band;
205 struct nlattr *nl_freqs, *nl_freq;
206 struct nlattr *nl_rates, *nl_rate;
f59ac048 207 struct nlattr *nl_modes;
8fdc621d 208 struct nlattr *nl_cmds;
ee688b00
JB
209 enum ieee80211_band band;
210 struct ieee80211_channel *chan;
211 struct ieee80211_rate *rate;
212 int i;
f59ac048 213 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
214
215 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
216 if (!hdr)
217 return -1;
218
b5850a7a 219 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 220 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca
JM
221
222 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
223 dev->wiphy.retry_short);
224 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
225 dev->wiphy.retry_long);
226 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
227 dev->wiphy.frag_threshold);
228 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
229 dev->wiphy.rts_threshold);
230
2a519311
JB
231 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
232 dev->wiphy.max_scan_ssids);
18a83659
JB
233 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
234 dev->wiphy.max_scan_ie_len);
ee688b00 235
25e47c18
JB
236 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
237 sizeof(u32) * dev->wiphy.n_cipher_suites,
238 dev->wiphy.cipher_suites);
239
f59ac048
LR
240 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
241 if (!nl_modes)
242 goto nla_put_failure;
243
244 i = 0;
245 while (ifmodes) {
246 if (ifmodes & 1)
247 NLA_PUT_FLAG(msg, i);
248 ifmodes >>= 1;
249 i++;
250 }
251
252 nla_nest_end(msg, nl_modes);
253
ee688b00
JB
254 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
255 if (!nl_bands)
256 goto nla_put_failure;
257
258 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
259 if (!dev->wiphy.bands[band])
260 continue;
261
262 nl_band = nla_nest_start(msg, band);
263 if (!nl_band)
264 goto nla_put_failure;
265
d51626df
JB
266 /* add HT info */
267 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
268 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
269 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
270 &dev->wiphy.bands[band]->ht_cap.mcs);
271 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
272 dev->wiphy.bands[band]->ht_cap.cap);
273 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
274 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
275 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
276 dev->wiphy.bands[band]->ht_cap.ampdu_density);
277 }
278
ee688b00
JB
279 /* add frequencies */
280 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
281 if (!nl_freqs)
282 goto nla_put_failure;
283
284 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
285 nl_freq = nla_nest_start(msg, i);
286 if (!nl_freq)
287 goto nla_put_failure;
288
289 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
290
291 if (nl80211_msg_put_channel(msg, chan))
292 goto nla_put_failure;
e2f367f2 293
ee688b00
JB
294 nla_nest_end(msg, nl_freq);
295 }
296
297 nla_nest_end(msg, nl_freqs);
298
299 /* add bitrates */
300 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
301 if (!nl_rates)
302 goto nla_put_failure;
303
304 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
305 nl_rate = nla_nest_start(msg, i);
306 if (!nl_rate)
307 goto nla_put_failure;
308
309 rate = &dev->wiphy.bands[band]->bitrates[i];
310 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
311 rate->bitrate);
312 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
313 NLA_PUT_FLAG(msg,
314 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
315
316 nla_nest_end(msg, nl_rate);
317 }
318
319 nla_nest_end(msg, nl_rates);
320
321 nla_nest_end(msg, nl_band);
322 }
323 nla_nest_end(msg, nl_bands);
324
8fdc621d
JB
325 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
326 if (!nl_cmds)
327 goto nla_put_failure;
328
329 i = 0;
330#define CMD(op, n) \
331 do { \
332 if (dev->ops->op) { \
333 i++; \
334 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
335 } \
336 } while (0)
337
338 CMD(add_virtual_intf, NEW_INTERFACE);
339 CMD(change_virtual_intf, SET_INTERFACE);
340 CMD(add_key, NEW_KEY);
341 CMD(add_beacon, NEW_BEACON);
342 CMD(add_station, NEW_STATION);
343 CMD(add_mpath, NEW_MPATH);
344 CMD(set_mesh_params, SET_MESH_PARAMS);
345 CMD(change_bss, SET_BSS);
636a5d36
JM
346 CMD(auth, AUTHENTICATE);
347 CMD(assoc, ASSOCIATE);
348 CMD(deauth, DEAUTHENTICATE);
349 CMD(disassoc, DISASSOCIATE);
04a773ad 350 CMD(join_ibss, JOIN_IBSS);
8fdc621d
JB
351
352#undef CMD
b23aa676 353
6829c878 354 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
355 i++;
356 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
357 }
358
6829c878 359 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
360 i++;
361 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
362 }
363
8fdc621d
JB
364 nla_nest_end(msg, nl_cmds);
365
55682965
JB
366 return genlmsg_end(msg, hdr);
367
368 nla_put_failure:
bc3ed28c
TG
369 genlmsg_cancel(msg, hdr);
370 return -EMSGSIZE;
55682965
JB
371}
372
373static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
374{
375 int idx = 0;
376 int start = cb->args[0];
377 struct cfg80211_registered_device *dev;
378
a1794390 379 mutex_lock(&cfg80211_mutex);
55682965 380 list_for_each_entry(dev, &cfg80211_drv_list, list) {
b4637271 381 if (++idx <= start)
55682965
JB
382 continue;
383 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
384 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
385 dev) < 0) {
386 idx--;
55682965 387 break;
b4637271 388 }
55682965 389 }
a1794390 390 mutex_unlock(&cfg80211_mutex);
55682965
JB
391
392 cb->args[0] = idx;
393
394 return skb->len;
395}
396
397static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
398{
399 struct sk_buff *msg;
400 struct cfg80211_registered_device *dev;
401
402 dev = cfg80211_get_dev_from_info(info);
403 if (IS_ERR(dev))
404 return PTR_ERR(dev);
405
fd2120ca 406 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
407 if (!msg)
408 goto out_err;
409
410 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
411 goto out_free;
412
413 cfg80211_put_dev(dev);
414
415 return genlmsg_unicast(msg, info->snd_pid);
416
417 out_free:
418 nlmsg_free(msg);
419 out_err:
420 cfg80211_put_dev(dev);
421 return -ENOBUFS;
422}
423
31888487
JM
424static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
425 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
426 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
427 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
428 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
429 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
430};
431
432static int parse_txq_params(struct nlattr *tb[],
433 struct ieee80211_txq_params *txq_params)
434{
435 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
436 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
437 !tb[NL80211_TXQ_ATTR_AIFS])
438 return -EINVAL;
439
440 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
441 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
442 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
443 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
444 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
445
446 return 0;
447}
448
55682965
JB
449static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
450{
451 struct cfg80211_registered_device *rdev;
31888487
JM
452 int result = 0, rem_txq_params = 0;
453 struct nlattr *nl_txq_params;
b9a5f8ca
JM
454 u32 changed;
455 u8 retry_short = 0, retry_long = 0;
456 u32 frag_threshold = 0, rts_threshold = 0;
55682965 457
4bbf4d56 458 rtnl_lock();
55682965 459
4bbf4d56
JB
460 mutex_lock(&cfg80211_mutex);
461
462 rdev = __cfg80211_drv_from_info(info);
463 if (IS_ERR(rdev)) {
1f5fc70a 464 mutex_unlock(&cfg80211_mutex);
4bbf4d56
JB
465 result = PTR_ERR(rdev);
466 goto unlock;
467 }
468
469 mutex_lock(&rdev->mtx);
470
471 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
472 result = cfg80211_dev_rename(
473 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
474
475 mutex_unlock(&cfg80211_mutex);
476
477 if (result)
478 goto bad_res;
31888487
JM
479
480 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
481 struct ieee80211_txq_params txq_params;
482 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
483
484 if (!rdev->ops->set_txq_params) {
485 result = -EOPNOTSUPP;
486 goto bad_res;
487 }
488
489 nla_for_each_nested(nl_txq_params,
490 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
491 rem_txq_params) {
492 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
493 nla_data(nl_txq_params),
494 nla_len(nl_txq_params),
495 txq_params_policy);
496 result = parse_txq_params(tb, &txq_params);
497 if (result)
498 goto bad_res;
499
500 result = rdev->ops->set_txq_params(&rdev->wiphy,
501 &txq_params);
502 if (result)
503 goto bad_res;
504 }
505 }
55682965 506
72bdcf34 507 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
094d05dc 508 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
72bdcf34 509 struct ieee80211_channel *chan;
306d6112 510 struct ieee80211_sta_ht_cap *ht_cap;
294196ab 511 u32 freq;
72bdcf34
JM
512
513 if (!rdev->ops->set_channel) {
514 result = -EOPNOTSUPP;
515 goto bad_res;
516 }
517
306d6112
JB
518 result = -EINVAL;
519
094d05dc
S
520 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
521 channel_type = nla_get_u32(info->attrs[
522 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
523 if (channel_type != NL80211_CHAN_NO_HT &&
524 channel_type != NL80211_CHAN_HT20 &&
525 channel_type != NL80211_CHAN_HT40PLUS &&
526 channel_type != NL80211_CHAN_HT40MINUS)
72bdcf34 527 goto bad_res;
72bdcf34
JM
528 }
529
530 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
531 chan = ieee80211_get_channel(&rdev->wiphy, freq);
306d6112
JB
532
533 /* Primary channel not allowed */
534 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
72bdcf34 535 goto bad_res;
306d6112 536
294196ab
LR
537 if (channel_type == NL80211_CHAN_HT40MINUS &&
538 (chan->flags & IEEE80211_CHAN_NO_HT40MINUS))
306d6112 539 goto bad_res;
294196ab
LR
540 else if (channel_type == NL80211_CHAN_HT40PLUS &&
541 (chan->flags & IEEE80211_CHAN_NO_HT40PLUS))
306d6112
JB
542 goto bad_res;
543
294196ab
LR
544 /*
545 * At this point we know if that if HT40 was requested
546 * we are allowed to use it and the extension channel
547 * exists.
548 */
306d6112 549
294196ab 550 ht_cap = &rdev->wiphy.bands[chan->band]->ht_cap;
306d6112 551
294196ab
LR
552 /* no HT capabilities or intolerant */
553 if (channel_type != NL80211_CHAN_NO_HT) {
554 if (!ht_cap->ht_supported)
555 goto bad_res;
306d6112
JB
556 if (!(ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) ||
557 (ht_cap->cap & IEEE80211_HT_CAP_40MHZ_INTOLERANT))
558 goto bad_res;
72bdcf34
JM
559 }
560
561 result = rdev->ops->set_channel(&rdev->wiphy, chan,
094d05dc 562 channel_type);
72bdcf34
JM
563 if (result)
564 goto bad_res;
565 }
566
b9a5f8ca
JM
567 changed = 0;
568
569 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
570 retry_short = nla_get_u8(
571 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
572 if (retry_short == 0) {
573 result = -EINVAL;
574 goto bad_res;
575 }
576 changed |= WIPHY_PARAM_RETRY_SHORT;
577 }
578
579 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
580 retry_long = nla_get_u8(
581 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
582 if (retry_long == 0) {
583 result = -EINVAL;
584 goto bad_res;
585 }
586 changed |= WIPHY_PARAM_RETRY_LONG;
587 }
588
589 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
590 frag_threshold = nla_get_u32(
591 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
592 if (frag_threshold < 256) {
593 result = -EINVAL;
594 goto bad_res;
595 }
596 if (frag_threshold != (u32) -1) {
597 /*
598 * Fragments (apart from the last one) are required to
599 * have even length. Make the fragmentation code
600 * simpler by stripping LSB should someone try to use
601 * odd threshold value.
602 */
603 frag_threshold &= ~0x1;
604 }
605 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
606 }
607
608 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
609 rts_threshold = nla_get_u32(
610 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
611 changed |= WIPHY_PARAM_RTS_THRESHOLD;
612 }
613
614 if (changed) {
615 u8 old_retry_short, old_retry_long;
616 u32 old_frag_threshold, old_rts_threshold;
617
618 if (!rdev->ops->set_wiphy_params) {
619 result = -EOPNOTSUPP;
620 goto bad_res;
621 }
622
623 old_retry_short = rdev->wiphy.retry_short;
624 old_retry_long = rdev->wiphy.retry_long;
625 old_frag_threshold = rdev->wiphy.frag_threshold;
626 old_rts_threshold = rdev->wiphy.rts_threshold;
627
628 if (changed & WIPHY_PARAM_RETRY_SHORT)
629 rdev->wiphy.retry_short = retry_short;
630 if (changed & WIPHY_PARAM_RETRY_LONG)
631 rdev->wiphy.retry_long = retry_long;
632 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
633 rdev->wiphy.frag_threshold = frag_threshold;
634 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
635 rdev->wiphy.rts_threshold = rts_threshold;
636
637 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
638 if (result) {
639 rdev->wiphy.retry_short = old_retry_short;
640 rdev->wiphy.retry_long = old_retry_long;
641 rdev->wiphy.frag_threshold = old_frag_threshold;
642 rdev->wiphy.rts_threshold = old_rts_threshold;
643 }
644 }
72bdcf34 645
306d6112 646 bad_res:
4bbf4d56
JB
647 mutex_unlock(&rdev->mtx);
648 unlock:
649 rtnl_unlock();
55682965
JB
650 return result;
651}
652
653
654static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 655 struct cfg80211_registered_device *rdev,
55682965
JB
656 struct net_device *dev)
657{
658 void *hdr;
659
660 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
661 if (!hdr)
662 return -1;
663
664 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 665 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 666 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 667 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
55682965
JB
668 return genlmsg_end(msg, hdr);
669
670 nla_put_failure:
bc3ed28c
TG
671 genlmsg_cancel(msg, hdr);
672 return -EMSGSIZE;
55682965
JB
673}
674
675static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
676{
677 int wp_idx = 0;
678 int if_idx = 0;
679 int wp_start = cb->args[0];
680 int if_start = cb->args[1];
681 struct cfg80211_registered_device *dev;
682 struct wireless_dev *wdev;
683
a1794390 684 mutex_lock(&cfg80211_mutex);
55682965 685 list_for_each_entry(dev, &cfg80211_drv_list, list) {
bba95fef
JB
686 if (wp_idx < wp_start) {
687 wp_idx++;
55682965 688 continue;
bba95fef 689 }
55682965
JB
690 if_idx = 0;
691
692 mutex_lock(&dev->devlist_mtx);
693 list_for_each_entry(wdev, &dev->netdev_list, list) {
bba95fef
JB
694 if (if_idx < if_start) {
695 if_idx++;
55682965 696 continue;
bba95fef 697 }
55682965
JB
698 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
699 cb->nlh->nlmsg_seq, NLM_F_MULTI,
d726405a 700 dev, wdev->netdev) < 0) {
bba95fef
JB
701 mutex_unlock(&dev->devlist_mtx);
702 goto out;
703 }
704 if_idx++;
55682965
JB
705 }
706 mutex_unlock(&dev->devlist_mtx);
bba95fef
JB
707
708 wp_idx++;
55682965 709 }
bba95fef 710 out:
a1794390 711 mutex_unlock(&cfg80211_mutex);
55682965
JB
712
713 cb->args[0] = wp_idx;
714 cb->args[1] = if_idx;
715
716 return skb->len;
717}
718
719static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
720{
721 struct sk_buff *msg;
722 struct cfg80211_registered_device *dev;
723 struct net_device *netdev;
724 int err;
725
bba95fef 726 err = get_drv_dev_by_info_ifindex(info->attrs, &dev, &netdev);
55682965
JB
727 if (err)
728 return err;
729
fd2120ca 730 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
731 if (!msg)
732 goto out_err;
733
d726405a
JB
734 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
735 dev, netdev) < 0)
55682965
JB
736 goto out_free;
737
738 dev_put(netdev);
739 cfg80211_put_dev(dev);
740
741 return genlmsg_unicast(msg, info->snd_pid);
742
743 out_free:
744 nlmsg_free(msg);
745 out_err:
746 dev_put(netdev);
747 cfg80211_put_dev(dev);
748 return -ENOBUFS;
749}
750
66f7ac50
MW
751static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
752 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
753 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
754 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
755 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
756 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
757};
758
759static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
760{
761 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
762 int flag;
763
764 *mntrflags = 0;
765
766 if (!nla)
767 return -EINVAL;
768
769 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
770 nla, mntr_flags_policy))
771 return -EINVAL;
772
773 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
774 if (flags[flag])
775 *mntrflags |= (1<<flag);
776
777 return 0;
778}
779
55682965
JB
780static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
781{
782 struct cfg80211_registered_device *drv;
2ec600d6 783 struct vif_params params;
e36d56b6 784 int err;
04a773ad 785 enum nl80211_iftype otype, ntype;
55682965 786 struct net_device *dev;
92ffe055 787 u32 _flags, *flags = NULL;
ac7f9cfa 788 bool change = false;
55682965 789
2ec600d6
LCC
790 memset(&params, 0, sizeof(params));
791
3b85875a
JB
792 rtnl_lock();
793
bba95fef 794 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
55682965 795 if (err)
3b85875a
JB
796 goto unlock_rtnl;
797
04a773ad 798 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 799
723b038d 800 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 801 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 802 if (otype != ntype)
ac7f9cfa 803 change = true;
04a773ad 804 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 805 err = -EINVAL;
723b038d 806 goto unlock;
ac7f9cfa 807 }
723b038d
JB
808 }
809
f59ac048 810 if (!drv->ops->change_virtual_intf ||
04a773ad 811 !(drv->wiphy.interface_modes & (1 << ntype))) {
55682965
JB
812 err = -EOPNOTSUPP;
813 goto unlock;
814 }
815
92ffe055 816 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 817 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
818 err = -EINVAL;
819 goto unlock;
820 }
2ec600d6
LCC
821 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
822 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 823 change = true;
2ec600d6
LCC
824 }
825
92ffe055 826 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 827 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
828 err = -EINVAL;
829 goto unlock;
830 }
831 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
832 &_flags);
ac7f9cfa
JB
833 if (err)
834 goto unlock;
835
836 flags = &_flags;
837 change = true;
92ffe055 838 }
3b85875a 839
ac7f9cfa 840 if (change)
e36d56b6 841 err = drv->ops->change_virtual_intf(&drv->wiphy, dev,
04a773ad 842 ntype, flags, &params);
ac7f9cfa
JB
843 else
844 err = 0;
60719ffd 845
e36d56b6 846 WARN_ON(!err && dev->ieee80211_ptr->iftype != ntype);
04a773ad 847
e36d56b6 848 if (!err && (ntype != otype)) {
04a773ad 849 if (otype == NL80211_IFTYPE_ADHOC)
9d308429 850 cfg80211_clear_ibss(dev, false);
04a773ad 851 }
60719ffd 852
55682965 853 unlock:
e36d56b6 854 dev_put(dev);
55682965 855 cfg80211_put_dev(drv);
3b85875a
JB
856 unlock_rtnl:
857 rtnl_unlock();
55682965
JB
858 return err;
859}
860
861static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
862{
863 struct cfg80211_registered_device *drv;
2ec600d6 864 struct vif_params params;
55682965
JB
865 int err;
866 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 867 u32 flags;
55682965 868
2ec600d6
LCC
869 memset(&params, 0, sizeof(params));
870
55682965
JB
871 if (!info->attrs[NL80211_ATTR_IFNAME])
872 return -EINVAL;
873
874 if (info->attrs[NL80211_ATTR_IFTYPE]) {
875 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
876 if (type > NL80211_IFTYPE_MAX)
877 return -EINVAL;
878 }
879
3b85875a
JB
880 rtnl_lock();
881
55682965 882 drv = cfg80211_get_dev_from_info(info);
3b85875a
JB
883 if (IS_ERR(drv)) {
884 err = PTR_ERR(drv);
885 goto unlock_rtnl;
886 }
55682965 887
f59ac048
LR
888 if (!drv->ops->add_virtual_intf ||
889 !(drv->wiphy.interface_modes & (1 << type))) {
55682965
JB
890 err = -EOPNOTSUPP;
891 goto unlock;
892 }
893
2ec600d6
LCC
894 if (type == NL80211_IFTYPE_MESH_POINT &&
895 info->attrs[NL80211_ATTR_MESH_ID]) {
896 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
897 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
898 }
899
66f7ac50
MW
900 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
901 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
902 &flags);
55682965 903 err = drv->ops->add_virtual_intf(&drv->wiphy,
66f7ac50 904 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 905 type, err ? NULL : &flags, &params);
2ec600d6 906
55682965
JB
907 unlock:
908 cfg80211_put_dev(drv);
3b85875a
JB
909 unlock_rtnl:
910 rtnl_unlock();
55682965
JB
911 return err;
912}
913
914static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
915{
916 struct cfg80211_registered_device *drv;
917 int ifindex, err;
918 struct net_device *dev;
919
3b85875a
JB
920 rtnl_lock();
921
bba95fef 922 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
55682965 923 if (err)
3b85875a 924 goto unlock_rtnl;
55682965
JB
925 ifindex = dev->ifindex;
926 dev_put(dev);
927
928 if (!drv->ops->del_virtual_intf) {
929 err = -EOPNOTSUPP;
930 goto out;
931 }
932
55682965 933 err = drv->ops->del_virtual_intf(&drv->wiphy, ifindex);
55682965
JB
934
935 out:
936 cfg80211_put_dev(drv);
3b85875a
JB
937 unlock_rtnl:
938 rtnl_unlock();
55682965
JB
939 return err;
940}
941
41ade00f
JB
942struct get_key_cookie {
943 struct sk_buff *msg;
944 int error;
945};
946
947static void get_key_callback(void *c, struct key_params *params)
948{
949 struct get_key_cookie *cookie = c;
950
951 if (params->key)
952 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
953 params->key_len, params->key);
954
955 if (params->seq)
956 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
957 params->seq_len, params->seq);
958
959 if (params->cipher)
960 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
961 params->cipher);
962
963 return;
964 nla_put_failure:
965 cookie->error = 1;
966}
967
968static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
969{
970 struct cfg80211_registered_device *drv;
971 int err;
972 struct net_device *dev;
973 u8 key_idx = 0;
974 u8 *mac_addr = NULL;
975 struct get_key_cookie cookie = {
976 .error = 0,
977 };
978 void *hdr;
979 struct sk_buff *msg;
980
981 if (info->attrs[NL80211_ATTR_KEY_IDX])
982 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
983
3cfcf6ac 984 if (key_idx > 5)
41ade00f
JB
985 return -EINVAL;
986
987 if (info->attrs[NL80211_ATTR_MAC])
988 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
989
3b85875a
JB
990 rtnl_lock();
991
bba95fef 992 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
41ade00f 993 if (err)
3b85875a 994 goto unlock_rtnl;
41ade00f
JB
995
996 if (!drv->ops->get_key) {
997 err = -EOPNOTSUPP;
998 goto out;
999 }
1000
fd2120ca 1001 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1002 if (!msg) {
1003 err = -ENOMEM;
1004 goto out;
1005 }
1006
1007 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1008 NL80211_CMD_NEW_KEY);
1009
1010 if (IS_ERR(hdr)) {
1011 err = PTR_ERR(hdr);
1012 goto out;
1013 }
1014
1015 cookie.msg = msg;
1016
1017 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1018 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1019 if (mac_addr)
1020 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1021
41ade00f
JB
1022 err = drv->ops->get_key(&drv->wiphy, dev, key_idx, mac_addr,
1023 &cookie, get_key_callback);
41ade00f
JB
1024
1025 if (err)
1026 goto out;
1027
1028 if (cookie.error)
1029 goto nla_put_failure;
1030
1031 genlmsg_end(msg, hdr);
1032 err = genlmsg_unicast(msg, info->snd_pid);
1033 goto out;
1034
1035 nla_put_failure:
1036 err = -ENOBUFS;
1037 nlmsg_free(msg);
1038 out:
1039 cfg80211_put_dev(drv);
1040 dev_put(dev);
3b85875a
JB
1041 unlock_rtnl:
1042 rtnl_unlock();
1043
41ade00f
JB
1044 return err;
1045}
1046
1047static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1048{
1049 struct cfg80211_registered_device *drv;
1050 int err;
1051 struct net_device *dev;
1052 u8 key_idx;
3cfcf6ac
JM
1053 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1054 u8 key_index);
41ade00f
JB
1055
1056 if (!info->attrs[NL80211_ATTR_KEY_IDX])
1057 return -EINVAL;
1058
1059 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1060
3cfcf6ac
JM
1061 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]) {
1062 if (key_idx < 4 || key_idx > 5)
1063 return -EINVAL;
1064 } else if (key_idx > 3)
41ade00f
JB
1065 return -EINVAL;
1066
1067 /* currently only support setting default key */
3cfcf6ac
JM
1068 if (!info->attrs[NL80211_ATTR_KEY_DEFAULT] &&
1069 !info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT])
41ade00f
JB
1070 return -EINVAL;
1071
3b85875a
JB
1072 rtnl_lock();
1073
bba95fef 1074 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
41ade00f 1075 if (err)
3b85875a 1076 goto unlock_rtnl;
41ade00f 1077
3cfcf6ac
JM
1078 if (info->attrs[NL80211_ATTR_KEY_DEFAULT])
1079 func = drv->ops->set_default_key;
1080 else
1081 func = drv->ops->set_default_mgmt_key;
1082
1083 if (!func) {
41ade00f
JB
1084 err = -EOPNOTSUPP;
1085 goto out;
1086 }
1087
3cfcf6ac 1088 err = func(&drv->wiphy, dev, key_idx);
08645126
JB
1089#ifdef CONFIG_WIRELESS_EXT
1090 if (!err) {
1091 if (func == drv->ops->set_default_key)
1092 dev->ieee80211_ptr->wext.default_key = key_idx;
1093 else
1094 dev->ieee80211_ptr->wext.default_mgmt_key = key_idx;
1095 }
1096#endif
41ade00f
JB
1097
1098 out:
1099 cfg80211_put_dev(drv);
1100 dev_put(dev);
3b85875a
JB
1101
1102 unlock_rtnl:
1103 rtnl_unlock();
1104
41ade00f
JB
1105 return err;
1106}
1107
1108static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1109{
1110 struct cfg80211_registered_device *drv;
25e47c18 1111 int err, i;
41ade00f
JB
1112 struct net_device *dev;
1113 struct key_params params;
1114 u8 key_idx = 0;
1115 u8 *mac_addr = NULL;
1116
1117 memset(&params, 0, sizeof(params));
1118
1119 if (!info->attrs[NL80211_ATTR_KEY_CIPHER])
1120 return -EINVAL;
1121
1122 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
1123 params.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
1124 params.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
1125 }
1126
faa8fdc8
JM
1127 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
1128 params.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
1129 params.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
1130 }
1131
41ade00f
JB
1132 if (info->attrs[NL80211_ATTR_KEY_IDX])
1133 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1134
1135 params.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
1136
1137 if (info->attrs[NL80211_ATTR_MAC])
1138 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1139
08645126 1140 if (cfg80211_validate_key_settings(&params, key_idx, mac_addr))
41ade00f
JB
1141 return -EINVAL;
1142
3b85875a
JB
1143 rtnl_lock();
1144
bba95fef 1145 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
41ade00f 1146 if (err)
3b85875a 1147 goto unlock_rtnl;
41ade00f 1148
25e47c18
JB
1149 for (i = 0; i < drv->wiphy.n_cipher_suites; i++)
1150 if (params.cipher == drv->wiphy.cipher_suites[i])
1151 break;
1152 if (i == drv->wiphy.n_cipher_suites) {
1153 err = -EINVAL;
1154 goto out;
1155 }
1156
41ade00f
JB
1157 if (!drv->ops->add_key) {
1158 err = -EOPNOTSUPP;
1159 goto out;
1160 }
1161
41ade00f 1162 err = drv->ops->add_key(&drv->wiphy, dev, key_idx, mac_addr, &params);
41ade00f
JB
1163
1164 out:
1165 cfg80211_put_dev(drv);
1166 dev_put(dev);
3b85875a
JB
1167 unlock_rtnl:
1168 rtnl_unlock();
1169
41ade00f
JB
1170 return err;
1171}
1172
1173static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1174{
1175 struct cfg80211_registered_device *drv;
1176 int err;
1177 struct net_device *dev;
1178 u8 key_idx = 0;
1179 u8 *mac_addr = NULL;
1180
1181 if (info->attrs[NL80211_ATTR_KEY_IDX])
1182 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1183
3cfcf6ac 1184 if (key_idx > 5)
41ade00f
JB
1185 return -EINVAL;
1186
1187 if (info->attrs[NL80211_ATTR_MAC])
1188 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1189
3b85875a
JB
1190 rtnl_lock();
1191
bba95fef 1192 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
41ade00f 1193 if (err)
3b85875a 1194 goto unlock_rtnl;
41ade00f
JB
1195
1196 if (!drv->ops->del_key) {
1197 err = -EOPNOTSUPP;
1198 goto out;
1199 }
1200
41ade00f 1201 err = drv->ops->del_key(&drv->wiphy, dev, key_idx, mac_addr);
41ade00f 1202
08645126
JB
1203#ifdef CONFIG_WIRELESS_EXT
1204 if (!err) {
1205 if (key_idx == dev->ieee80211_ptr->wext.default_key)
1206 dev->ieee80211_ptr->wext.default_key = -1;
1207 else if (key_idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1208 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1209 }
1210#endif
1211
41ade00f
JB
1212 out:
1213 cfg80211_put_dev(drv);
1214 dev_put(dev);
3b85875a
JB
1215
1216 unlock_rtnl:
1217 rtnl_unlock();
1218
41ade00f
JB
1219 return err;
1220}
1221
ed1b6cc7
JB
1222static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1223{
1224 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1225 struct beacon_parameters *info);
1226 struct cfg80211_registered_device *drv;
1227 int err;
1228 struct net_device *dev;
1229 struct beacon_parameters params;
1230 int haveinfo = 0;
1231
f4a11bb0
JB
1232 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1233 return -EINVAL;
1234
3b85875a
JB
1235 rtnl_lock();
1236
bba95fef 1237 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
ed1b6cc7 1238 if (err)
3b85875a 1239 goto unlock_rtnl;
ed1b6cc7 1240
eec60b03
JM
1241 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1242 err = -EOPNOTSUPP;
1243 goto out;
1244 }
1245
ed1b6cc7
JB
1246 switch (info->genlhdr->cmd) {
1247 case NL80211_CMD_NEW_BEACON:
1248 /* these are required for NEW_BEACON */
1249 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1250 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1251 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1252 err = -EINVAL;
1253 goto out;
1254 }
1255
1256 call = drv->ops->add_beacon;
1257 break;
1258 case NL80211_CMD_SET_BEACON:
1259 call = drv->ops->set_beacon;
1260 break;
1261 default:
1262 WARN_ON(1);
1263 err = -EOPNOTSUPP;
1264 goto out;
1265 }
1266
1267 if (!call) {
1268 err = -EOPNOTSUPP;
1269 goto out;
1270 }
1271
1272 memset(&params, 0, sizeof(params));
1273
1274 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1275 params.interval =
1276 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1277 haveinfo = 1;
1278 }
1279
1280 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1281 params.dtim_period =
1282 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1283 haveinfo = 1;
1284 }
1285
1286 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1287 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1288 params.head_len =
1289 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1290 haveinfo = 1;
1291 }
1292
1293 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1294 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1295 params.tail_len =
1296 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1297 haveinfo = 1;
1298 }
1299
1300 if (!haveinfo) {
1301 err = -EINVAL;
1302 goto out;
1303 }
1304
ed1b6cc7 1305 err = call(&drv->wiphy, dev, &params);
ed1b6cc7
JB
1306
1307 out:
1308 cfg80211_put_dev(drv);
1309 dev_put(dev);
3b85875a
JB
1310 unlock_rtnl:
1311 rtnl_unlock();
1312
ed1b6cc7
JB
1313 return err;
1314}
1315
1316static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1317{
1318 struct cfg80211_registered_device *drv;
1319 int err;
1320 struct net_device *dev;
1321
3b85875a
JB
1322 rtnl_lock();
1323
bba95fef 1324 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
ed1b6cc7 1325 if (err)
3b85875a 1326 goto unlock_rtnl;
ed1b6cc7
JB
1327
1328 if (!drv->ops->del_beacon) {
1329 err = -EOPNOTSUPP;
1330 goto out;
1331 }
1332
eec60b03
JM
1333 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1334 err = -EOPNOTSUPP;
1335 goto out;
1336 }
ed1b6cc7 1337 err = drv->ops->del_beacon(&drv->wiphy, dev);
ed1b6cc7
JB
1338
1339 out:
1340 cfg80211_put_dev(drv);
1341 dev_put(dev);
3b85875a
JB
1342 unlock_rtnl:
1343 rtnl_unlock();
1344
ed1b6cc7
JB
1345 return err;
1346}
1347
5727ef1b
JB
1348static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1349 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1350 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1351 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1352 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1353};
1354
eccb8e8f
JB
1355static int parse_station_flags(struct genl_info *info,
1356 struct station_parameters *params)
5727ef1b
JB
1357{
1358 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1359 struct nlattr *nla;
5727ef1b
JB
1360 int flag;
1361
eccb8e8f
JB
1362 /*
1363 * Try parsing the new attribute first so userspace
1364 * can specify both for older kernels.
1365 */
1366 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1367 if (nla) {
1368 struct nl80211_sta_flag_update *sta_flags;
1369
1370 sta_flags = nla_data(nla);
1371 params->sta_flags_mask = sta_flags->mask;
1372 params->sta_flags_set = sta_flags->set;
1373 if ((params->sta_flags_mask |
1374 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1375 return -EINVAL;
1376 return 0;
1377 }
1378
1379 /* if present, parse the old attribute */
5727ef1b 1380
eccb8e8f 1381 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1382 if (!nla)
1383 return 0;
1384
1385 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1386 nla, sta_flags_policy))
1387 return -EINVAL;
1388
eccb8e8f
JB
1389 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1390 params->sta_flags_mask &= ~1;
5727ef1b
JB
1391
1392 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1393 if (flags[flag])
eccb8e8f 1394 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1395
1396 return 0;
1397}
1398
420e7fab
HR
1399static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1400{
1401 int modulation, streams, bitrate;
1402
1403 if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1404 return rate->legacy;
1405
1406 /* the formula below does only work for MCS values smaller than 32 */
1407 if (rate->mcs >= 32)
1408 return 0;
1409
1410 modulation = rate->mcs & 7;
1411 streams = (rate->mcs >> 3) + 1;
1412
1413 bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1414 13500000 : 6500000;
1415
1416 if (modulation < 4)
1417 bitrate *= (modulation + 1);
1418 else if (modulation == 4)
1419 bitrate *= (modulation + 2);
1420 else
1421 bitrate *= (modulation + 3);
1422
1423 bitrate *= streams;
1424
1425 if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1426 bitrate = (bitrate / 9) * 10;
1427
1428 /* do NOT round down here */
1429 return (bitrate + 50000) / 100000;
1430}
1431
fd5b74dc
JB
1432static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1433 int flags, struct net_device *dev,
2ec600d6 1434 u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1435{
1436 void *hdr;
420e7fab
HR
1437 struct nlattr *sinfoattr, *txrate;
1438 u16 bitrate;
fd5b74dc
JB
1439
1440 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1441 if (!hdr)
1442 return -1;
1443
1444 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1445 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1446
2ec600d6
LCC
1447 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1448 if (!sinfoattr)
fd5b74dc 1449 goto nla_put_failure;
2ec600d6
LCC
1450 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1451 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1452 sinfo->inactive_time);
1453 if (sinfo->filled & STATION_INFO_RX_BYTES)
1454 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1455 sinfo->rx_bytes);
1456 if (sinfo->filled & STATION_INFO_TX_BYTES)
1457 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1458 sinfo->tx_bytes);
1459 if (sinfo->filled & STATION_INFO_LLID)
1460 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1461 sinfo->llid);
1462 if (sinfo->filled & STATION_INFO_PLID)
1463 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1464 sinfo->plid);
1465 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1466 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1467 sinfo->plink_state);
420e7fab
HR
1468 if (sinfo->filled & STATION_INFO_SIGNAL)
1469 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1470 sinfo->signal);
1471 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1472 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1473 if (!txrate)
1474 goto nla_put_failure;
1475
1476 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1477 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1478 if (bitrate > 0)
1479 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1480
420e7fab
HR
1481 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1482 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1483 sinfo->txrate.mcs);
1484 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1485 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1486 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1487 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1488
1489 nla_nest_end(msg, txrate);
1490 }
98c8a60a
JM
1491 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1492 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1493 sinfo->rx_packets);
1494 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1495 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1496 sinfo->tx_packets);
2ec600d6 1497 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1498
1499 return genlmsg_end(msg, hdr);
1500
1501 nla_put_failure:
bc3ed28c
TG
1502 genlmsg_cancel(msg, hdr);
1503 return -EMSGSIZE;
fd5b74dc
JB
1504}
1505
2ec600d6 1506static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1507 struct netlink_callback *cb)
2ec600d6 1508{
2ec600d6
LCC
1509 struct station_info sinfo;
1510 struct cfg80211_registered_device *dev;
bba95fef 1511 struct net_device *netdev;
2ec600d6 1512 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1513 int ifidx = cb->args[0];
1514 int sta_idx = cb->args[1];
2ec600d6 1515 int err;
2ec600d6 1516
bba95fef
JB
1517 if (!ifidx) {
1518 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1519 nl80211_fam.attrbuf, nl80211_fam.maxattr,
1520 nl80211_policy);
1521 if (err)
1522 return err;
2ec600d6 1523
bba95fef
JB
1524 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1525 return -EINVAL;
2ec600d6 1526
bba95fef
JB
1527 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1528 if (!ifidx)
1529 return -EINVAL;
2ec600d6 1530 }
2ec600d6 1531
3b85875a
JB
1532 rtnl_lock();
1533
1534 netdev = __dev_get_by_index(&init_net, ifidx);
1535 if (!netdev) {
1536 err = -ENODEV;
1537 goto out_rtnl;
1538 }
2ec600d6 1539
bba95fef
JB
1540 dev = cfg80211_get_dev_from_ifindex(ifidx);
1541 if (IS_ERR(dev)) {
1542 err = PTR_ERR(dev);
3b85875a 1543 goto out_rtnl;
bba95fef
JB
1544 }
1545
1546 if (!dev->ops->dump_station) {
eec60b03 1547 err = -EOPNOTSUPP;
bba95fef
JB
1548 goto out_err;
1549 }
1550
bba95fef
JB
1551 while (1) {
1552 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1553 mac_addr, &sinfo);
1554 if (err == -ENOENT)
1555 break;
1556 if (err)
3b85875a 1557 goto out_err;
bba95fef
JB
1558
1559 if (nl80211_send_station(skb,
1560 NETLINK_CB(cb->skb).pid,
1561 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1562 netdev, mac_addr,
1563 &sinfo) < 0)
1564 goto out;
1565
1566 sta_idx++;
1567 }
1568
1569
1570 out:
1571 cb->args[1] = sta_idx;
1572 err = skb->len;
bba95fef
JB
1573 out_err:
1574 cfg80211_put_dev(dev);
3b85875a
JB
1575 out_rtnl:
1576 rtnl_unlock();
bba95fef
JB
1577
1578 return err;
2ec600d6 1579}
fd5b74dc 1580
5727ef1b
JB
1581static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1582{
fd5b74dc
JB
1583 struct cfg80211_registered_device *drv;
1584 int err;
1585 struct net_device *dev;
2ec600d6 1586 struct station_info sinfo;
fd5b74dc
JB
1587 struct sk_buff *msg;
1588 u8 *mac_addr = NULL;
1589
2ec600d6 1590 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1591
1592 if (!info->attrs[NL80211_ATTR_MAC])
1593 return -EINVAL;
1594
1595 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1596
3b85875a
JB
1597 rtnl_lock();
1598
bba95fef 1599 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
fd5b74dc 1600 if (err)
3b85875a 1601 goto out_rtnl;
fd5b74dc
JB
1602
1603 if (!drv->ops->get_station) {
1604 err = -EOPNOTSUPP;
1605 goto out;
1606 }
1607
2ec600d6 1608 err = drv->ops->get_station(&drv->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1609 if (err)
1610 goto out;
1611
fd2120ca 1612 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1613 if (!msg)
1614 goto out;
1615
1616 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1617 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1618 goto out_free;
1619
1620 err = genlmsg_unicast(msg, info->snd_pid);
1621 goto out;
1622
1623 out_free:
1624 nlmsg_free(msg);
fd5b74dc
JB
1625 out:
1626 cfg80211_put_dev(drv);
1627 dev_put(dev);
3b85875a
JB
1628 out_rtnl:
1629 rtnl_unlock();
1630
fd5b74dc 1631 return err;
5727ef1b
JB
1632}
1633
1634/*
1635 * Get vlan interface making sure it is on the right wiphy.
1636 */
1637static int get_vlan(struct nlattr *vlanattr,
1638 struct cfg80211_registered_device *rdev,
1639 struct net_device **vlan)
1640{
1641 *vlan = NULL;
1642
1643 if (vlanattr) {
1644 *vlan = dev_get_by_index(&init_net, nla_get_u32(vlanattr));
1645 if (!*vlan)
1646 return -ENODEV;
1647 if (!(*vlan)->ieee80211_ptr)
1648 return -EINVAL;
1649 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1650 return -EINVAL;
1651 }
1652 return 0;
1653}
1654
1655static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1656{
1657 struct cfg80211_registered_device *drv;
1658 int err;
1659 struct net_device *dev;
1660 struct station_parameters params;
1661 u8 *mac_addr = NULL;
1662
1663 memset(&params, 0, sizeof(params));
1664
1665 params.listen_interval = -1;
1666
1667 if (info->attrs[NL80211_ATTR_STA_AID])
1668 return -EINVAL;
1669
1670 if (!info->attrs[NL80211_ATTR_MAC])
1671 return -EINVAL;
1672
1673 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1674
1675 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1676 params.supported_rates =
1677 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1678 params.supported_rates_len =
1679 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1680 }
1681
1682 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1683 params.listen_interval =
1684 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1685
36aedc90
JM
1686 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1687 params.ht_capa =
1688 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1689
eccb8e8f 1690 if (parse_station_flags(info, &params))
5727ef1b
JB
1691 return -EINVAL;
1692
2ec600d6
LCC
1693 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1694 params.plink_action =
1695 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1696
3b85875a
JB
1697 rtnl_lock();
1698
bba95fef 1699 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
5727ef1b 1700 if (err)
3b85875a 1701 goto out_rtnl;
5727ef1b 1702
a97f4424
JB
1703 err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1704 if (err)
034d655e 1705 goto out;
a97f4424
JB
1706
1707 /* validate settings */
1708 err = 0;
1709
1710 switch (dev->ieee80211_ptr->iftype) {
1711 case NL80211_IFTYPE_AP:
1712 case NL80211_IFTYPE_AP_VLAN:
1713 /* disallow mesh-specific things */
1714 if (params.plink_action)
1715 err = -EINVAL;
1716 break;
1717 case NL80211_IFTYPE_STATION:
1718 /* disallow everything but AUTHORIZED flag */
1719 if (params.plink_action)
1720 err = -EINVAL;
1721 if (params.vlan)
1722 err = -EINVAL;
1723 if (params.supported_rates)
1724 err = -EINVAL;
1725 if (params.ht_capa)
1726 err = -EINVAL;
1727 if (params.listen_interval >= 0)
1728 err = -EINVAL;
1729 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1730 err = -EINVAL;
1731 break;
1732 case NL80211_IFTYPE_MESH_POINT:
1733 /* disallow things mesh doesn't support */
1734 if (params.vlan)
1735 err = -EINVAL;
1736 if (params.ht_capa)
1737 err = -EINVAL;
1738 if (params.listen_interval >= 0)
1739 err = -EINVAL;
1740 if (params.supported_rates)
1741 err = -EINVAL;
1742 if (params.sta_flags_mask)
1743 err = -EINVAL;
1744 break;
1745 default:
1746 err = -EINVAL;
034d655e
JB
1747 }
1748
5727ef1b
JB
1749 if (err)
1750 goto out;
1751
1752 if (!drv->ops->change_station) {
1753 err = -EOPNOTSUPP;
1754 goto out;
1755 }
1756
5727ef1b 1757 err = drv->ops->change_station(&drv->wiphy, dev, mac_addr, &params);
5727ef1b
JB
1758
1759 out:
1760 if (params.vlan)
1761 dev_put(params.vlan);
1762 cfg80211_put_dev(drv);
1763 dev_put(dev);
3b85875a
JB
1764 out_rtnl:
1765 rtnl_unlock();
1766
5727ef1b
JB
1767 return err;
1768}
1769
1770static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1771{
1772 struct cfg80211_registered_device *drv;
1773 int err;
1774 struct net_device *dev;
1775 struct station_parameters params;
1776 u8 *mac_addr = NULL;
1777
1778 memset(&params, 0, sizeof(params));
1779
1780 if (!info->attrs[NL80211_ATTR_MAC])
1781 return -EINVAL;
1782
5727ef1b
JB
1783 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1784 return -EINVAL;
1785
1786 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1787 return -EINVAL;
1788
1789 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1790 params.supported_rates =
1791 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1792 params.supported_rates_len =
1793 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1794 params.listen_interval =
1795 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 1796
a97f4424
JB
1797 if (info->attrs[NL80211_ATTR_STA_AID]) {
1798 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1799 if (!params.aid || params.aid > IEEE80211_MAX_AID)
1800 return -EINVAL;
1801 }
51b50fbe 1802
36aedc90
JM
1803 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1804 params.ht_capa =
1805 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 1806
eccb8e8f 1807 if (parse_station_flags(info, &params))
5727ef1b
JB
1808 return -EINVAL;
1809
3b85875a
JB
1810 rtnl_lock();
1811
bba95fef 1812 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
5727ef1b 1813 if (err)
3b85875a 1814 goto out_rtnl;
5727ef1b 1815
a97f4424
JB
1816 err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1817 if (err)
e80cf853 1818 goto out;
a97f4424
JB
1819
1820 /* validate settings */
1821 err = 0;
1822
1823 switch (dev->ieee80211_ptr->iftype) {
1824 case NL80211_IFTYPE_AP:
1825 case NL80211_IFTYPE_AP_VLAN:
1826 /* all ok but must have AID */
1827 if (!params.aid)
1828 err = -EINVAL;
1829 break;
1830 case NL80211_IFTYPE_MESH_POINT:
1831 /* disallow things mesh doesn't support */
1832 if (params.vlan)
1833 err = -EINVAL;
1834 if (params.aid)
1835 err = -EINVAL;
1836 if (params.ht_capa)
1837 err = -EINVAL;
1838 if (params.listen_interval >= 0)
1839 err = -EINVAL;
1840 if (params.supported_rates)
1841 err = -EINVAL;
1842 if (params.sta_flags_mask)
1843 err = -EINVAL;
1844 break;
1845 default:
1846 err = -EINVAL;
e80cf853
JB
1847 }
1848
5727ef1b
JB
1849 if (err)
1850 goto out;
1851
1852 if (!drv->ops->add_station) {
1853 err = -EOPNOTSUPP;
1854 goto out;
1855 }
1856
35a8efe1
JM
1857 if (!netif_running(dev)) {
1858 err = -ENETDOWN;
1859 goto out;
1860 }
1861
5727ef1b 1862 err = drv->ops->add_station(&drv->wiphy, dev, mac_addr, &params);
5727ef1b
JB
1863
1864 out:
1865 if (params.vlan)
1866 dev_put(params.vlan);
1867 cfg80211_put_dev(drv);
1868 dev_put(dev);
3b85875a
JB
1869 out_rtnl:
1870 rtnl_unlock();
1871
5727ef1b
JB
1872 return err;
1873}
1874
1875static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
1876{
1877 struct cfg80211_registered_device *drv;
1878 int err;
1879 struct net_device *dev;
1880 u8 *mac_addr = NULL;
1881
1882 if (info->attrs[NL80211_ATTR_MAC])
1883 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1884
3b85875a
JB
1885 rtnl_lock();
1886
bba95fef 1887 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
5727ef1b 1888 if (err)
3b85875a 1889 goto out_rtnl;
5727ef1b 1890
e80cf853 1891 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
155cc9e4
AY
1892 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
1893 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
1894 err = -EINVAL;
1895 goto out;
1896 }
1897
5727ef1b
JB
1898 if (!drv->ops->del_station) {
1899 err = -EOPNOTSUPP;
1900 goto out;
1901 }
1902
5727ef1b 1903 err = drv->ops->del_station(&drv->wiphy, dev, mac_addr);
5727ef1b
JB
1904
1905 out:
1906 cfg80211_put_dev(drv);
1907 dev_put(dev);
3b85875a
JB
1908 out_rtnl:
1909 rtnl_unlock();
1910
5727ef1b
JB
1911 return err;
1912}
1913
2ec600d6
LCC
1914static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
1915 int flags, struct net_device *dev,
1916 u8 *dst, u8 *next_hop,
1917 struct mpath_info *pinfo)
1918{
1919 void *hdr;
1920 struct nlattr *pinfoattr;
1921
1922 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1923 if (!hdr)
1924 return -1;
1925
1926 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1927 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
1928 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
1929
1930 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
1931 if (!pinfoattr)
1932 goto nla_put_failure;
1933 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
1934 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
1935 pinfo->frame_qlen);
1936 if (pinfo->filled & MPATH_INFO_DSN)
1937 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
1938 pinfo->dsn);
1939 if (pinfo->filled & MPATH_INFO_METRIC)
1940 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
1941 pinfo->metric);
1942 if (pinfo->filled & MPATH_INFO_EXPTIME)
1943 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
1944 pinfo->exptime);
1945 if (pinfo->filled & MPATH_INFO_FLAGS)
1946 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
1947 pinfo->flags);
1948 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
1949 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
1950 pinfo->discovery_timeout);
1951 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
1952 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
1953 pinfo->discovery_retries);
1954
1955 nla_nest_end(msg, pinfoattr);
1956
1957 return genlmsg_end(msg, hdr);
1958
1959 nla_put_failure:
bc3ed28c
TG
1960 genlmsg_cancel(msg, hdr);
1961 return -EMSGSIZE;
2ec600d6
LCC
1962}
1963
1964static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 1965 struct netlink_callback *cb)
2ec600d6 1966{
2ec600d6
LCC
1967 struct mpath_info pinfo;
1968 struct cfg80211_registered_device *dev;
bba95fef 1969 struct net_device *netdev;
2ec600d6
LCC
1970 u8 dst[ETH_ALEN];
1971 u8 next_hop[ETH_ALEN];
bba95fef
JB
1972 int ifidx = cb->args[0];
1973 int path_idx = cb->args[1];
2ec600d6 1974 int err;
2ec600d6 1975
bba95fef
JB
1976 if (!ifidx) {
1977 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1978 nl80211_fam.attrbuf, nl80211_fam.maxattr,
1979 nl80211_policy);
1980 if (err)
1981 return err;
1982
1983 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1984 return -EINVAL;
1985
1986 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1987 if (!ifidx)
1988 return -EINVAL;
1989 }
1990
3b85875a
JB
1991 rtnl_lock();
1992
1993 netdev = __dev_get_by_index(&init_net, ifidx);
1994 if (!netdev) {
1995 err = -ENODEV;
1996 goto out_rtnl;
1997 }
bba95fef
JB
1998
1999 dev = cfg80211_get_dev_from_ifindex(ifidx);
2000 if (IS_ERR(dev)) {
2001 err = PTR_ERR(dev);
3b85875a 2002 goto out_rtnl;
bba95fef
JB
2003 }
2004
2005 if (!dev->ops->dump_mpath) {
eec60b03 2006 err = -EOPNOTSUPP;
bba95fef
JB
2007 goto out_err;
2008 }
2009
eec60b03
JM
2010 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2011 err = -EOPNOTSUPP;
2012 goto out;
2013 }
2014
bba95fef
JB
2015 while (1) {
2016 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2017 dst, next_hop, &pinfo);
2018 if (err == -ENOENT)
2ec600d6 2019 break;
bba95fef 2020 if (err)
3b85875a 2021 goto out_err;
2ec600d6 2022
bba95fef
JB
2023 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2024 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2025 netdev, dst, next_hop,
2026 &pinfo) < 0)
2027 goto out;
2ec600d6 2028
bba95fef 2029 path_idx++;
2ec600d6 2030 }
2ec600d6 2031
2ec600d6 2032
bba95fef
JB
2033 out:
2034 cb->args[1] = path_idx;
2035 err = skb->len;
bba95fef
JB
2036 out_err:
2037 cfg80211_put_dev(dev);
3b85875a
JB
2038 out_rtnl:
2039 rtnl_unlock();
bba95fef
JB
2040
2041 return err;
2ec600d6
LCC
2042}
2043
2044static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2045{
2046 struct cfg80211_registered_device *drv;
2047 int err;
2048 struct net_device *dev;
2049 struct mpath_info pinfo;
2050 struct sk_buff *msg;
2051 u8 *dst = NULL;
2052 u8 next_hop[ETH_ALEN];
2053
2054 memset(&pinfo, 0, sizeof(pinfo));
2055
2056 if (!info->attrs[NL80211_ATTR_MAC])
2057 return -EINVAL;
2058
2059 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2060
3b85875a
JB
2061 rtnl_lock();
2062
bba95fef 2063 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2ec600d6 2064 if (err)
3b85875a 2065 goto out_rtnl;
2ec600d6
LCC
2066
2067 if (!drv->ops->get_mpath) {
2068 err = -EOPNOTSUPP;
2069 goto out;
2070 }
2071
eec60b03
JM
2072 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2073 err = -EOPNOTSUPP;
2074 goto out;
2075 }
2076
2ec600d6 2077 err = drv->ops->get_mpath(&drv->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2078 if (err)
2079 goto out;
2080
fd2120ca 2081 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2082 if (!msg)
2083 goto out;
2084
2085 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2086 dev, dst, next_hop, &pinfo) < 0)
2087 goto out_free;
2088
2089 err = genlmsg_unicast(msg, info->snd_pid);
2090 goto out;
2091
2092 out_free:
2093 nlmsg_free(msg);
2ec600d6
LCC
2094 out:
2095 cfg80211_put_dev(drv);
2096 dev_put(dev);
3b85875a
JB
2097 out_rtnl:
2098 rtnl_unlock();
2099
2ec600d6
LCC
2100 return err;
2101}
2102
2103static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2104{
2105 struct cfg80211_registered_device *drv;
2106 int err;
2107 struct net_device *dev;
2108 u8 *dst = NULL;
2109 u8 *next_hop = NULL;
2110
2111 if (!info->attrs[NL80211_ATTR_MAC])
2112 return -EINVAL;
2113
2114 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2115 return -EINVAL;
2116
2117 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2118 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2119
3b85875a
JB
2120 rtnl_lock();
2121
bba95fef 2122 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2ec600d6 2123 if (err)
3b85875a 2124 goto out_rtnl;
2ec600d6
LCC
2125
2126 if (!drv->ops->change_mpath) {
2127 err = -EOPNOTSUPP;
2128 goto out;
2129 }
2130
eec60b03
JM
2131 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2132 err = -EOPNOTSUPP;
2133 goto out;
2134 }
2135
35a8efe1
JM
2136 if (!netif_running(dev)) {
2137 err = -ENETDOWN;
2138 goto out;
2139 }
2140
2ec600d6 2141 err = drv->ops->change_mpath(&drv->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2142
2143 out:
2144 cfg80211_put_dev(drv);
2145 dev_put(dev);
3b85875a
JB
2146 out_rtnl:
2147 rtnl_unlock();
2148
2ec600d6
LCC
2149 return err;
2150}
2151static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2152{
2153 struct cfg80211_registered_device *drv;
2154 int err;
2155 struct net_device *dev;
2156 u8 *dst = NULL;
2157 u8 *next_hop = NULL;
2158
2159 if (!info->attrs[NL80211_ATTR_MAC])
2160 return -EINVAL;
2161
2162 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2163 return -EINVAL;
2164
2165 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2166 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2167
3b85875a
JB
2168 rtnl_lock();
2169
bba95fef 2170 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2ec600d6 2171 if (err)
3b85875a 2172 goto out_rtnl;
2ec600d6
LCC
2173
2174 if (!drv->ops->add_mpath) {
2175 err = -EOPNOTSUPP;
2176 goto out;
2177 }
2178
eec60b03
JM
2179 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2180 err = -EOPNOTSUPP;
2181 goto out;
2182 }
2183
35a8efe1
JM
2184 if (!netif_running(dev)) {
2185 err = -ENETDOWN;
2186 goto out;
2187 }
2188
2ec600d6 2189 err = drv->ops->add_mpath(&drv->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2190
2191 out:
2192 cfg80211_put_dev(drv);
2193 dev_put(dev);
3b85875a
JB
2194 out_rtnl:
2195 rtnl_unlock();
2196
2ec600d6
LCC
2197 return err;
2198}
2199
2200static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2201{
2202 struct cfg80211_registered_device *drv;
2203 int err;
2204 struct net_device *dev;
2205 u8 *dst = NULL;
2206
2207 if (info->attrs[NL80211_ATTR_MAC])
2208 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2209
3b85875a
JB
2210 rtnl_lock();
2211
bba95fef 2212 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2ec600d6 2213 if (err)
3b85875a 2214 goto out_rtnl;
2ec600d6
LCC
2215
2216 if (!drv->ops->del_mpath) {
2217 err = -EOPNOTSUPP;
2218 goto out;
2219 }
2220
2ec600d6 2221 err = drv->ops->del_mpath(&drv->wiphy, dev, dst);
2ec600d6
LCC
2222
2223 out:
2224 cfg80211_put_dev(drv);
2225 dev_put(dev);
3b85875a
JB
2226 out_rtnl:
2227 rtnl_unlock();
2228
2ec600d6
LCC
2229 return err;
2230}
2231
9f1ba906
JM
2232static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2233{
2234 struct cfg80211_registered_device *drv;
2235 int err;
2236 struct net_device *dev;
2237 struct bss_parameters params;
2238
2239 memset(&params, 0, sizeof(params));
2240 /* default to not changing parameters */
2241 params.use_cts_prot = -1;
2242 params.use_short_preamble = -1;
2243 params.use_short_slot_time = -1;
2244
2245 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2246 params.use_cts_prot =
2247 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2248 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2249 params.use_short_preamble =
2250 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2251 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2252 params.use_short_slot_time =
2253 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2254 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2255 params.basic_rates =
2256 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2257 params.basic_rates_len =
2258 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2259 }
9f1ba906 2260
3b85875a
JB
2261 rtnl_lock();
2262
9f1ba906
JM
2263 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2264 if (err)
3b85875a 2265 goto out_rtnl;
9f1ba906
JM
2266
2267 if (!drv->ops->change_bss) {
2268 err = -EOPNOTSUPP;
2269 goto out;
2270 }
2271
eec60b03
JM
2272 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2273 err = -EOPNOTSUPP;
2274 goto out;
2275 }
2276
9f1ba906 2277 err = drv->ops->change_bss(&drv->wiphy, dev, &params);
9f1ba906
JM
2278
2279 out:
2280 cfg80211_put_dev(drv);
2281 dev_put(dev);
3b85875a
JB
2282 out_rtnl:
2283 rtnl_unlock();
2284
9f1ba906
JM
2285 return err;
2286}
2287
b2e1b302
LR
2288static const struct nla_policy
2289 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2290 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2291 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2292 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2293 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2294 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2295 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2296};
2297
2298static int parse_reg_rule(struct nlattr *tb[],
2299 struct ieee80211_reg_rule *reg_rule)
2300{
2301 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2302 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2303
2304 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2305 return -EINVAL;
2306 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2307 return -EINVAL;
2308 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2309 return -EINVAL;
2310 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2311 return -EINVAL;
2312 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2313 return -EINVAL;
2314
2315 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2316
2317 freq_range->start_freq_khz =
2318 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2319 freq_range->end_freq_khz =
2320 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2321 freq_range->max_bandwidth_khz =
2322 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2323
2324 power_rule->max_eirp =
2325 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2326
2327 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2328 power_rule->max_antenna_gain =
2329 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2330
2331 return 0;
2332}
2333
2334static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2335{
2336 int r;
2337 char *data = NULL;
2338
80778f18
LR
2339 /*
2340 * You should only get this when cfg80211 hasn't yet initialized
2341 * completely when built-in to the kernel right between the time
2342 * window between nl80211_init() and regulatory_init(), if that is
2343 * even possible.
2344 */
2345 mutex_lock(&cfg80211_mutex);
2346 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2347 mutex_unlock(&cfg80211_mutex);
2348 return -EINPROGRESS;
80778f18 2349 }
fe33eb39 2350 mutex_unlock(&cfg80211_mutex);
80778f18 2351
fe33eb39
LR
2352 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2353 return -EINVAL;
b2e1b302
LR
2354
2355 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2356
2357#ifdef CONFIG_WIRELESS_OLD_REGULATORY
2358 /* We ignore world regdom requests with the old regdom setup */
fe33eb39
LR
2359 if (is_world_regdom(data))
2360 return -EINVAL;
b2e1b302 2361#endif
fe33eb39
LR
2362
2363 r = regulatory_hint_user(data);
2364
b2e1b302
LR
2365 return r;
2366}
2367
93da9cc1 2368static int nl80211_get_mesh_params(struct sk_buff *skb,
2369 struct genl_info *info)
2370{
2371 struct cfg80211_registered_device *drv;
2372 struct mesh_config cur_params;
2373 int err;
2374 struct net_device *dev;
2375 void *hdr;
2376 struct nlattr *pinfoattr;
2377 struct sk_buff *msg;
2378
3b85875a
JB
2379 rtnl_lock();
2380
93da9cc1 2381 /* Look up our device */
2382 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2383 if (err)
3b85875a 2384 goto out_rtnl;
93da9cc1 2385
f3f92586
JM
2386 if (!drv->ops->get_mesh_params) {
2387 err = -EOPNOTSUPP;
2388 goto out;
2389 }
2390
93da9cc1 2391 /* Get the mesh params */
93da9cc1 2392 err = drv->ops->get_mesh_params(&drv->wiphy, dev, &cur_params);
93da9cc1 2393 if (err)
2394 goto out;
2395
2396 /* Draw up a netlink message to send back */
fd2120ca 2397 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2398 if (!msg) {
2399 err = -ENOBUFS;
2400 goto out;
2401 }
2402 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2403 NL80211_CMD_GET_MESH_PARAMS);
2404 if (!hdr)
2405 goto nla_put_failure;
2406 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2407 if (!pinfoattr)
2408 goto nla_put_failure;
2409 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2410 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2411 cur_params.dot11MeshRetryTimeout);
2412 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2413 cur_params.dot11MeshConfirmTimeout);
2414 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2415 cur_params.dot11MeshHoldingTimeout);
2416 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2417 cur_params.dot11MeshMaxPeerLinks);
2418 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2419 cur_params.dot11MeshMaxRetries);
2420 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2421 cur_params.dot11MeshTTL);
2422 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2423 cur_params.auto_open_plinks);
2424 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2425 cur_params.dot11MeshHWMPmaxPREQretries);
2426 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2427 cur_params.path_refresh_time);
2428 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2429 cur_params.min_discovery_timeout);
2430 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2431 cur_params.dot11MeshHWMPactivePathTimeout);
2432 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2433 cur_params.dot11MeshHWMPpreqMinInterval);
2434 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2435 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2436 nla_nest_end(msg, pinfoattr);
2437 genlmsg_end(msg, hdr);
2438 err = genlmsg_unicast(msg, info->snd_pid);
2439 goto out;
2440
3b85875a 2441 nla_put_failure:
93da9cc1 2442 genlmsg_cancel(msg, hdr);
2443 err = -EMSGSIZE;
3b85875a 2444 out:
93da9cc1 2445 /* Cleanup */
2446 cfg80211_put_dev(drv);
2447 dev_put(dev);
3b85875a
JB
2448 out_rtnl:
2449 rtnl_unlock();
2450
93da9cc1 2451 return err;
2452}
2453
2454#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2455do {\
2456 if (table[attr_num]) {\
2457 cfg.param = nla_fn(table[attr_num]); \
2458 mask |= (1 << (attr_num - 1)); \
2459 } \
2460} while (0);\
2461
2462static struct nla_policy
2463nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2464 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2465 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2466 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2467 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2468 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2469 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2470 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2471
2472 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2473 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2474 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2475 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2476 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2477 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2478};
2479
2480static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2481{
2482 int err;
2483 u32 mask;
2484 struct cfg80211_registered_device *drv;
2485 struct net_device *dev;
2486 struct mesh_config cfg;
2487 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2488 struct nlattr *parent_attr;
2489
2490 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2491 if (!parent_attr)
2492 return -EINVAL;
2493 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2494 parent_attr, nl80211_meshconf_params_policy))
2495 return -EINVAL;
2496
3b85875a
JB
2497 rtnl_lock();
2498
93da9cc1 2499 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2500 if (err)
3b85875a 2501 goto out_rtnl;
93da9cc1 2502
f3f92586
JM
2503 if (!drv->ops->set_mesh_params) {
2504 err = -EOPNOTSUPP;
2505 goto out;
2506 }
2507
93da9cc1 2508 /* This makes sure that there aren't more than 32 mesh config
2509 * parameters (otherwise our bitfield scheme would not work.) */
2510 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2511
2512 /* Fill in the params struct */
2513 mask = 0;
2514 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2515 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2516 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2517 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2518 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2519 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2520 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2521 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2522 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2523 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2524 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2525 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2526 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2527 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2528 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2529 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2530 nla_get_u8);
2531 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2532 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2533 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2534 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2535 nla_get_u16);
2536 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2537 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2538 nla_get_u32);
2539 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2540 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2541 nla_get_u16);
2542 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2543 dot11MeshHWMPnetDiameterTraversalTime,
2544 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2545 nla_get_u16);
2546
2547 /* Apply changes */
93da9cc1 2548 err = drv->ops->set_mesh_params(&drv->wiphy, dev, &cfg, mask);
93da9cc1 2549
f3f92586 2550 out:
93da9cc1 2551 /* cleanup */
2552 cfg80211_put_dev(drv);
2553 dev_put(dev);
3b85875a
JB
2554 out_rtnl:
2555 rtnl_unlock();
2556
93da9cc1 2557 return err;
2558}
2559
2560#undef FILL_IN_MESH_PARAM_IF_SET
2561
f130347c
LR
2562static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2563{
2564 struct sk_buff *msg;
2565 void *hdr = NULL;
2566 struct nlattr *nl_reg_rules;
2567 unsigned int i;
2568 int err = -EINVAL;
2569
a1794390 2570 mutex_lock(&cfg80211_mutex);
f130347c
LR
2571
2572 if (!cfg80211_regdomain)
2573 goto out;
2574
fd2120ca 2575 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2576 if (!msg) {
2577 err = -ENOBUFS;
2578 goto out;
2579 }
2580
2581 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2582 NL80211_CMD_GET_REG);
2583 if (!hdr)
2584 goto nla_put_failure;
2585
2586 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2587 cfg80211_regdomain->alpha2);
2588
2589 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2590 if (!nl_reg_rules)
2591 goto nla_put_failure;
2592
2593 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2594 struct nlattr *nl_reg_rule;
2595 const struct ieee80211_reg_rule *reg_rule;
2596 const struct ieee80211_freq_range *freq_range;
2597 const struct ieee80211_power_rule *power_rule;
2598
2599 reg_rule = &cfg80211_regdomain->reg_rules[i];
2600 freq_range = &reg_rule->freq_range;
2601 power_rule = &reg_rule->power_rule;
2602
2603 nl_reg_rule = nla_nest_start(msg, i);
2604 if (!nl_reg_rule)
2605 goto nla_put_failure;
2606
2607 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2608 reg_rule->flags);
2609 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2610 freq_range->start_freq_khz);
2611 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2612 freq_range->end_freq_khz);
2613 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2614 freq_range->max_bandwidth_khz);
2615 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2616 power_rule->max_antenna_gain);
2617 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2618 power_rule->max_eirp);
2619
2620 nla_nest_end(msg, nl_reg_rule);
2621 }
2622
2623 nla_nest_end(msg, nl_reg_rules);
2624
2625 genlmsg_end(msg, hdr);
2626 err = genlmsg_unicast(msg, info->snd_pid);
2627 goto out;
2628
2629nla_put_failure:
2630 genlmsg_cancel(msg, hdr);
2631 err = -EMSGSIZE;
2632out:
a1794390 2633 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2634 return err;
2635}
2636
b2e1b302
LR
2637static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2638{
2639 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2640 struct nlattr *nl_reg_rule;
2641 char *alpha2 = NULL;
2642 int rem_reg_rules = 0, r = 0;
2643 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2644 struct ieee80211_regdomain *rd = NULL;
2645
2646 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2647 return -EINVAL;
2648
2649 if (!info->attrs[NL80211_ATTR_REG_RULES])
2650 return -EINVAL;
2651
2652 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2653
2654 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2655 rem_reg_rules) {
2656 num_rules++;
2657 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2658 return -EINVAL;
b2e1b302
LR
2659 }
2660
61405e97
LR
2661 mutex_lock(&cfg80211_mutex);
2662
d0e18f83
LR
2663 if (!reg_is_valid_request(alpha2)) {
2664 r = -EINVAL;
2665 goto bad_reg;
2666 }
b2e1b302
LR
2667
2668 size_of_regd = sizeof(struct ieee80211_regdomain) +
2669 (num_rules * sizeof(struct ieee80211_reg_rule));
2670
2671 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2672 if (!rd) {
2673 r = -ENOMEM;
2674 goto bad_reg;
2675 }
b2e1b302
LR
2676
2677 rd->n_reg_rules = num_rules;
2678 rd->alpha2[0] = alpha2[0];
2679 rd->alpha2[1] = alpha2[1];
2680
2681 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2682 rem_reg_rules) {
2683 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2684 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2685 reg_rule_policy);
2686 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2687 if (r)
2688 goto bad_reg;
2689
2690 rule_idx++;
2691
d0e18f83
LR
2692 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2693 r = -EINVAL;
b2e1b302 2694 goto bad_reg;
d0e18f83 2695 }
b2e1b302
LR
2696 }
2697
2698 BUG_ON(rule_idx != num_rules);
2699
b2e1b302 2700 r = set_regdom(rd);
61405e97 2701
a1794390 2702 mutex_unlock(&cfg80211_mutex);
d0e18f83 2703
b2e1b302
LR
2704 return r;
2705
d2372b31 2706 bad_reg:
61405e97 2707 mutex_unlock(&cfg80211_mutex);
b2e1b302 2708 kfree(rd);
d0e18f83 2709 return r;
b2e1b302
LR
2710}
2711
83f5e2cf
JB
2712static int validate_scan_freqs(struct nlattr *freqs)
2713{
2714 struct nlattr *attr1, *attr2;
2715 int n_channels = 0, tmp1, tmp2;
2716
2717 nla_for_each_nested(attr1, freqs, tmp1) {
2718 n_channels++;
2719 /*
2720 * Some hardware has a limited channel list for
2721 * scanning, and it is pretty much nonsensical
2722 * to scan for a channel twice, so disallow that
2723 * and don't require drivers to check that the
2724 * channel list they get isn't longer than what
2725 * they can scan, as long as they can scan all
2726 * the channels they registered at once.
2727 */
2728 nla_for_each_nested(attr2, freqs, tmp2)
2729 if (attr1 != attr2 &&
2730 nla_get_u32(attr1) == nla_get_u32(attr2))
2731 return 0;
2732 }
2733
2734 return n_channels;
2735}
2736
2a519311
JB
2737static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2738{
2739 struct cfg80211_registered_device *drv;
2740 struct net_device *dev;
2741 struct cfg80211_scan_request *request;
2742 struct cfg80211_ssid *ssid;
2743 struct ieee80211_channel *channel;
2744 struct nlattr *attr;
2745 struct wiphy *wiphy;
83f5e2cf 2746 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 2747 enum ieee80211_band band;
70692ad2 2748 size_t ie_len;
2a519311 2749
f4a11bb0
JB
2750 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2751 return -EINVAL;
2752
3b85875a
JB
2753 rtnl_lock();
2754
2a519311
JB
2755 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2756 if (err)
3b85875a 2757 goto out_rtnl;
2a519311
JB
2758
2759 wiphy = &drv->wiphy;
2760
2761 if (!drv->ops->scan) {
2762 err = -EOPNOTSUPP;
2763 goto out;
2764 }
2765
35a8efe1
JM
2766 if (!netif_running(dev)) {
2767 err = -ENETDOWN;
2768 goto out;
2769 }
2770
2a519311
JB
2771 if (drv->scan_req) {
2772 err = -EBUSY;
3b85875a 2773 goto out;
2a519311
JB
2774 }
2775
2776 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
2777 n_channels = validate_scan_freqs(
2778 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
2779 if (!n_channels) {
2780 err = -EINVAL;
3b85875a 2781 goto out;
2a519311
JB
2782 }
2783 } else {
83f5e2cf
JB
2784 n_channels = 0;
2785
2a519311
JB
2786 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2787 if (wiphy->bands[band])
2788 n_channels += wiphy->bands[band]->n_channels;
2789 }
2790
2791 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2792 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2793 n_ssids++;
2794
2795 if (n_ssids > wiphy->max_scan_ssids) {
2796 err = -EINVAL;
3b85875a 2797 goto out;
2a519311
JB
2798 }
2799
70692ad2
JM
2800 if (info->attrs[NL80211_ATTR_IE])
2801 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2802 else
2803 ie_len = 0;
2804
18a83659
JB
2805 if (ie_len > wiphy->max_scan_ie_len) {
2806 err = -EINVAL;
2807 goto out;
2808 }
2809
2a519311
JB
2810 request = kzalloc(sizeof(*request)
2811 + sizeof(*ssid) * n_ssids
70692ad2
JM
2812 + sizeof(channel) * n_channels
2813 + ie_len, GFP_KERNEL);
2a519311
JB
2814 if (!request) {
2815 err = -ENOMEM;
3b85875a 2816 goto out;
2a519311
JB
2817 }
2818
2819 request->channels = (void *)((char *)request + sizeof(*request));
2820 request->n_channels = n_channels;
2821 if (n_ssids)
2822 request->ssids = (void *)(request->channels + n_channels);
2823 request->n_ssids = n_ssids;
70692ad2
JM
2824 if (ie_len) {
2825 if (request->ssids)
2826 request->ie = (void *)(request->ssids + n_ssids);
2827 else
2828 request->ie = (void *)(request->channels + n_channels);
2829 }
2a519311
JB
2830
2831 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2832 /* user specified, bail out if channel not found */
2833 request->n_channels = n_channels;
2834 i = 0;
2835 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
2836 request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2837 if (!request->channels[i]) {
2838 err = -EINVAL;
2839 goto out_free;
2840 }
2841 i++;
2842 }
2843 } else {
2844 /* all channels */
2845 i = 0;
2846 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2847 int j;
2848 if (!wiphy->bands[band])
2849 continue;
2850 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
2851 request->channels[i] = &wiphy->bands[band]->channels[j];
2852 i++;
2853 }
2854 }
2855 }
2856
2857 i = 0;
2858 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
2859 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
2860 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
2861 err = -EINVAL;
2862 goto out_free;
2863 }
2864 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2865 request->ssids[i].ssid_len = nla_len(attr);
2866 i++;
2867 }
2868 }
2869
70692ad2
JM
2870 if (info->attrs[NL80211_ATTR_IE]) {
2871 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
2872 memcpy((void *)request->ie,
2873 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
2874 request->ie_len);
2875 }
2876
2a519311
JB
2877 request->ifidx = dev->ifindex;
2878 request->wiphy = &drv->wiphy;
2879
2880 drv->scan_req = request;
2881 err = drv->ops->scan(&drv->wiphy, dev, request);
2882
a538e2d5
JB
2883 if (!err)
2884 nl80211_send_scan_start(drv, dev);
2885
2a519311
JB
2886 out_free:
2887 if (err) {
2888 drv->scan_req = NULL;
2889 kfree(request);
2890 }
2a519311
JB
2891 out:
2892 cfg80211_put_dev(drv);
2893 dev_put(dev);
3b85875a
JB
2894 out_rtnl:
2895 rtnl_unlock();
2896
2a519311
JB
2897 return err;
2898}
2899
2900static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
2901 struct cfg80211_registered_device *rdev,
2902 struct net_device *dev,
2903 struct cfg80211_bss *res)
2904{
2905 void *hdr;
2906 struct nlattr *bss;
2907
2908 hdr = nl80211hdr_put(msg, pid, seq, flags,
2909 NL80211_CMD_NEW_SCAN_RESULTS);
2910 if (!hdr)
2911 return -1;
2912
2913 NLA_PUT_U32(msg, NL80211_ATTR_SCAN_GENERATION,
2914 rdev->bss_generation);
2915 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2916
2917 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
2918 if (!bss)
2919 goto nla_put_failure;
2920 if (!is_zero_ether_addr(res->bssid))
2921 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
2922 if (res->information_elements && res->len_information_elements)
2923 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
2924 res->len_information_elements,
2925 res->information_elements);
2926 if (res->tsf)
2927 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
2928 if (res->beacon_interval)
2929 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
2930 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
2931 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
2932
77965c97 2933 switch (rdev->wiphy.signal_type) {
2a519311
JB
2934 case CFG80211_SIGNAL_TYPE_MBM:
2935 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
2936 break;
2937 case CFG80211_SIGNAL_TYPE_UNSPEC:
2938 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
2939 break;
2940 default:
2941 break;
2942 }
2943
2944 nla_nest_end(msg, bss);
2945
2946 return genlmsg_end(msg, hdr);
2947
2948 nla_put_failure:
2949 genlmsg_cancel(msg, hdr);
2950 return -EMSGSIZE;
2951}
2952
2953static int nl80211_dump_scan(struct sk_buff *skb,
2954 struct netlink_callback *cb)
2955{
2956 struct cfg80211_registered_device *dev;
2957 struct net_device *netdev;
2958 struct cfg80211_internal_bss *scan;
2959 int ifidx = cb->args[0];
2960 int start = cb->args[1], idx = 0;
2961 int err;
2962
2963 if (!ifidx) {
2964 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2965 nl80211_fam.attrbuf, nl80211_fam.maxattr,
2966 nl80211_policy);
2967 if (err)
2968 return err;
2969
2970 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2971 return -EINVAL;
2972
2973 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2974 if (!ifidx)
2975 return -EINVAL;
2976 cb->args[0] = ifidx;
2977 }
2978
2979 netdev = dev_get_by_index(&init_net, ifidx);
2980 if (!netdev)
2981 return -ENODEV;
2982
2983 dev = cfg80211_get_dev_from_ifindex(ifidx);
2984 if (IS_ERR(dev)) {
2985 err = PTR_ERR(dev);
2986 goto out_put_netdev;
2987 }
2988
2989 spin_lock_bh(&dev->bss_lock);
2990 cfg80211_bss_expire(dev);
2991
2992 list_for_each_entry(scan, &dev->bss_list, list) {
2993 if (++idx <= start)
2994 continue;
2995 if (nl80211_send_bss(skb,
2996 NETLINK_CB(cb->skb).pid,
2997 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2998 dev, netdev, &scan->pub) < 0) {
2999 idx--;
3000 goto out;
3001 }
3002 }
3003
3004 out:
3005 spin_unlock_bh(&dev->bss_lock);
3006
3007 cb->args[1] = idx;
3008 err = skb->len;
3009 cfg80211_put_dev(dev);
3010 out_put_netdev:
3011 dev_put(netdev);
3012
3013 return err;
3014}
3015
255e737e
JM
3016static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3017{
b23aa676
SO
3018 return auth_type <= NL80211_AUTHTYPE_MAX;
3019}
3020
3021static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3022{
3023 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3024 NL80211_WPA_VERSION_2));
3025}
3026
3027static bool nl80211_valid_akm_suite(u32 akm)
3028{
3029 return akm == WLAN_AKM_SUITE_8021X ||
3030 akm == WLAN_AKM_SUITE_PSK;
3031}
3032
3033static bool nl80211_valid_cipher_suite(u32 cipher)
3034{
3035 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3036 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3037 cipher == WLAN_CIPHER_SUITE_TKIP ||
3038 cipher == WLAN_CIPHER_SUITE_CCMP ||
3039 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3040}
3041
b23aa676 3042
636a5d36
JM
3043static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3044{
3045 struct cfg80211_registered_device *drv;
3046 struct net_device *dev;
3047 struct cfg80211_auth_request req;
3048 struct wiphy *wiphy;
3049 int err;
3050
f4a11bb0
JB
3051 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3052 return -EINVAL;
3053
3054 if (!info->attrs[NL80211_ATTR_MAC])
3055 return -EINVAL;
3056
1778092e
JM
3057 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3058 return -EINVAL;
3059
636a5d36
JM
3060 rtnl_lock();
3061
3062 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3063 if (err)
3064 goto unlock_rtnl;
3065
3066 if (!drv->ops->auth) {
3067 err = -EOPNOTSUPP;
3068 goto out;
3069 }
3070
eec60b03
JM
3071 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3072 err = -EOPNOTSUPP;
3073 goto out;
3074 }
3075
35a8efe1
JM
3076 if (!netif_running(dev)) {
3077 err = -ENETDOWN;
3078 goto out;
3079 }
3080
636a5d36
JM
3081 wiphy = &drv->wiphy;
3082 memset(&req, 0, sizeof(req));
3083
3084 req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3085
3086 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3087 req.chan = ieee80211_get_channel(
3088 wiphy,
3089 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3090 if (!req.chan) {
3091 err = -EINVAL;
3092 goto out;
3093 }
3094 }
3095
3096 if (info->attrs[NL80211_ATTR_SSID]) {
3097 req.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3098 req.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3099 }
3100
3101 if (info->attrs[NL80211_ATTR_IE]) {
3102 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3103 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3104 }
3105
1778092e
JM
3106 req.auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3107 if (!nl80211_valid_auth_type(req.auth_type)) {
3108 err = -EINVAL;
3109 goto out;
636a5d36
JM
3110 }
3111
3112 err = drv->ops->auth(&drv->wiphy, dev, &req);
3113
3114out:
3115 cfg80211_put_dev(drv);
3116 dev_put(dev);
3117unlock_rtnl:
3118 rtnl_unlock();
3119 return err;
3120}
3121
b23aa676
SO
3122static int nl80211_crypto_settings(struct genl_info *info,
3123 struct cfg80211_crypto_settings *settings)
3124{
3125 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3126
3127 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3128 void *data;
3129 int len, i;
3130
3131 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3132 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3133 settings->n_ciphers_pairwise = len / sizeof(u32);
3134
3135 if (len % sizeof(u32))
3136 return -EINVAL;
3137
3138 if (settings->n_ciphers_pairwise > NL80211_MAX_NR_CIPHER_SUITES)
3139 return -EINVAL;
3140
3141 memcpy(settings->ciphers_pairwise, data, len);
3142
3143 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3144 if (!nl80211_valid_cipher_suite(
3145 settings->ciphers_pairwise[i]))
3146 return -EINVAL;
3147 }
3148
3149 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3150 settings->cipher_group =
3151 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3152 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3153 return -EINVAL;
3154 }
3155
3156 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3157 settings->wpa_versions =
3158 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3159 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3160 return -EINVAL;
3161 }
3162
3163 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3164 void *data;
3165 int len, i;
3166
3167 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3168 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3169 settings->n_akm_suites = len / sizeof(u32);
3170
3171 if (len % sizeof(u32))
3172 return -EINVAL;
3173
3174 memcpy(settings->akm_suites, data, len);
3175
3176 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3177 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3178 return -EINVAL;
3179 }
3180
3181 return 0;
3182}
3183
636a5d36
JM
3184static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3185{
3186 struct cfg80211_registered_device *drv;
3187 struct net_device *dev;
3188 struct cfg80211_assoc_request req;
3189 struct wiphy *wiphy;
3190 int err;
3191
f4a11bb0
JB
3192 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3193 return -EINVAL;
3194
3195 if (!info->attrs[NL80211_ATTR_MAC] ||
3196 !info->attrs[NL80211_ATTR_SSID])
3197 return -EINVAL;
3198
636a5d36
JM
3199 rtnl_lock();
3200
3201 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3202 if (err)
3203 goto unlock_rtnl;
3204
3205 if (!drv->ops->assoc) {
3206 err = -EOPNOTSUPP;
3207 goto out;
3208 }
3209
eec60b03
JM
3210 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3211 err = -EOPNOTSUPP;
3212 goto out;
3213 }
3214
35a8efe1
JM
3215 if (!netif_running(dev)) {
3216 err = -ENETDOWN;
3217 goto out;
3218 }
3219
636a5d36
JM
3220 wiphy = &drv->wiphy;
3221 memset(&req, 0, sizeof(req));
3222
3223 req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3224
3225 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3226 req.chan = ieee80211_get_channel(
3227 wiphy,
3228 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3229 if (!req.chan) {
3230 err = -EINVAL;
3231 goto out;
3232 }
3233 }
3234
636a5d36
JM
3235 req.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3236 req.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3237
3238 if (info->attrs[NL80211_ATTR_IE]) {
3239 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3240 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3241 }
3242
dc6382ce
JM
3243 if (info->attrs[NL80211_ATTR_USE_MFP]) {
3244 enum nl80211_mfp use_mfp =
3245 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3246 if (use_mfp == NL80211_MFP_REQUIRED)
3247 req.use_mfp = true;
3248 else if (use_mfp != NL80211_MFP_NO) {
3249 err = -EINVAL;
3250 goto out;
3251 }
3252 }
3253
b23aa676
SO
3254 err = nl80211_crypto_settings(info, &req.crypto);
3255 if (!err)
3256 err = drv->ops->assoc(&drv->wiphy, dev, &req);
636a5d36
JM
3257
3258out:
3259 cfg80211_put_dev(drv);
3260 dev_put(dev);
3261unlock_rtnl:
3262 rtnl_unlock();
3263 return err;
3264}
3265
3266static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3267{
3268 struct cfg80211_registered_device *drv;
3269 struct net_device *dev;
3270 struct cfg80211_deauth_request req;
3271 struct wiphy *wiphy;
3272 int err;
3273
f4a11bb0
JB
3274 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3275 return -EINVAL;
3276
3277 if (!info->attrs[NL80211_ATTR_MAC])
3278 return -EINVAL;
3279
3280 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3281 return -EINVAL;
3282
636a5d36
JM
3283 rtnl_lock();
3284
3285 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3286 if (err)
3287 goto unlock_rtnl;
3288
3289 if (!drv->ops->deauth) {
3290 err = -EOPNOTSUPP;
3291 goto out;
3292 }
3293
eec60b03
JM
3294 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3295 err = -EOPNOTSUPP;
3296 goto out;
3297 }
3298
35a8efe1
JM
3299 if (!netif_running(dev)) {
3300 err = -ENETDOWN;
3301 goto out;
3302 }
3303
636a5d36
JM
3304 wiphy = &drv->wiphy;
3305 memset(&req, 0, sizeof(req));
3306
3307 req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3308
f4a11bb0
JB
3309 req.reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3310 if (req.reason_code == 0) {
3311 /* Reason Code 0 is reserved */
3312 err = -EINVAL;
3313 goto out;
255e737e 3314 }
636a5d36
JM
3315
3316 if (info->attrs[NL80211_ATTR_IE]) {
3317 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3318 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3319 }
3320
3321 err = drv->ops->deauth(&drv->wiphy, dev, &req);
3322
3323out:
3324 cfg80211_put_dev(drv);
3325 dev_put(dev);
3326unlock_rtnl:
3327 rtnl_unlock();
3328 return err;
3329}
3330
3331static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3332{
3333 struct cfg80211_registered_device *drv;
3334 struct net_device *dev;
3335 struct cfg80211_disassoc_request req;
3336 struct wiphy *wiphy;
3337 int err;
3338
f4a11bb0
JB
3339 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3340 return -EINVAL;
3341
3342 if (!info->attrs[NL80211_ATTR_MAC])
3343 return -EINVAL;
3344
3345 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3346 return -EINVAL;
3347
636a5d36
JM
3348 rtnl_lock();
3349
3350 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3351 if (err)
3352 goto unlock_rtnl;
3353
3354 if (!drv->ops->disassoc) {
3355 err = -EOPNOTSUPP;
3356 goto out;
3357 }
3358
eec60b03
JM
3359 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3360 err = -EOPNOTSUPP;
3361 goto out;
3362 }
3363
35a8efe1
JM
3364 if (!netif_running(dev)) {
3365 err = -ENETDOWN;
3366 goto out;
3367 }
3368
636a5d36
JM
3369 wiphy = &drv->wiphy;
3370 memset(&req, 0, sizeof(req));
3371
3372 req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3373
f4a11bb0
JB
3374 req.reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3375 if (req.reason_code == 0) {
3376 /* Reason Code 0 is reserved */
3377 err = -EINVAL;
3378 goto out;
255e737e 3379 }
636a5d36
JM
3380
3381 if (info->attrs[NL80211_ATTR_IE]) {
3382 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3383 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3384 }
3385
3386 err = drv->ops->disassoc(&drv->wiphy, dev, &req);
3387
3388out:
3389 cfg80211_put_dev(drv);
3390 dev_put(dev);
3391unlock_rtnl:
3392 rtnl_unlock();
3393 return err;
3394}
3395
04a773ad
JB
3396static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3397{
3398 struct cfg80211_registered_device *drv;
3399 struct net_device *dev;
3400 struct cfg80211_ibss_params ibss;
3401 struct wiphy *wiphy;
3402 int err;
3403
8e30bc55
JB
3404 memset(&ibss, 0, sizeof(ibss));
3405
04a773ad
JB
3406 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3407 return -EINVAL;
3408
3409 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3410 !info->attrs[NL80211_ATTR_SSID] ||
3411 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3412 return -EINVAL;
3413
8e30bc55
JB
3414 ibss.beacon_interval = 100;
3415
3416 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3417 ibss.beacon_interval =
3418 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3419 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3420 return -EINVAL;
3421 }
3422
04a773ad
JB
3423 rtnl_lock();
3424
3425 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3426 if (err)
3427 goto unlock_rtnl;
3428
3429 if (!drv->ops->join_ibss) {
3430 err = -EOPNOTSUPP;
3431 goto out;
3432 }
3433
3434 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3435 err = -EOPNOTSUPP;
3436 goto out;
3437 }
3438
3439 if (!netif_running(dev)) {
3440 err = -ENETDOWN;
3441 goto out;
3442 }
3443
3444 wiphy = &drv->wiphy;
04a773ad
JB
3445
3446 if (info->attrs[NL80211_ATTR_MAC])
3447 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3448 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3449 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3450
3451 if (info->attrs[NL80211_ATTR_IE]) {
3452 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3453 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3454 }
3455
3456 ibss.channel = ieee80211_get_channel(wiphy,
3457 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3458 if (!ibss.channel ||
3459 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3460 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3461 err = -EINVAL;
3462 goto out;
3463 }
3464
3465 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3466
3467 err = cfg80211_join_ibss(drv, dev, &ibss);
3468
3469out:
3470 cfg80211_put_dev(drv);
3471 dev_put(dev);
3472unlock_rtnl:
3473 rtnl_unlock();
3474 return err;
3475}
3476
3477static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3478{
3479 struct cfg80211_registered_device *drv;
3480 struct net_device *dev;
3481 int err;
3482
3483 rtnl_lock();
3484
3485 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3486 if (err)
3487 goto unlock_rtnl;
3488
3489 if (!drv->ops->leave_ibss) {
3490 err = -EOPNOTSUPP;
3491 goto out;
3492 }
3493
3494 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3495 err = -EOPNOTSUPP;
3496 goto out;
3497 }
3498
3499 if (!netif_running(dev)) {
3500 err = -ENETDOWN;
3501 goto out;
3502 }
3503
9d308429 3504 err = cfg80211_leave_ibss(drv, dev, false);
04a773ad
JB
3505
3506out:
3507 cfg80211_put_dev(drv);
3508 dev_put(dev);
3509unlock_rtnl:
3510 rtnl_unlock();
3511 return err;
3512}
3513
aff89a9b
JB
3514#ifdef CONFIG_NL80211_TESTMODE
3515static struct genl_multicast_group nl80211_testmode_mcgrp = {
3516 .name = "testmode",
3517};
3518
3519static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3520{
3521 struct cfg80211_registered_device *rdev;
3522 int err;
3523
3524 if (!info->attrs[NL80211_ATTR_TESTDATA])
3525 return -EINVAL;
3526
3527 rtnl_lock();
3528
3529 rdev = cfg80211_get_dev_from_info(info);
3530 if (IS_ERR(rdev)) {
3531 err = PTR_ERR(rdev);
3532 goto unlock_rtnl;
3533 }
3534
3535 err = -EOPNOTSUPP;
3536 if (rdev->ops->testmode_cmd) {
3537 rdev->testmode_info = info;
3538 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3539 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3540 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3541 rdev->testmode_info = NULL;
3542 }
3543
3544 cfg80211_put_dev(rdev);
3545
3546 unlock_rtnl:
3547 rtnl_unlock();
3548 return err;
3549}
3550
3551static struct sk_buff *
3552__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3553 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3554{
3555 struct sk_buff *skb;
3556 void *hdr;
3557 struct nlattr *data;
3558
3559 skb = nlmsg_new(approxlen + 100, gfp);
3560 if (!skb)
3561 return NULL;
3562
3563 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3564 if (!hdr) {
3565 kfree_skb(skb);
3566 return NULL;
3567 }
3568
3569 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3570 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3571
3572 ((void **)skb->cb)[0] = rdev;
3573 ((void **)skb->cb)[1] = hdr;
3574 ((void **)skb->cb)[2] = data;
3575
3576 return skb;
3577
3578 nla_put_failure:
3579 kfree_skb(skb);
3580 return NULL;
3581}
3582
3583struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3584 int approxlen)
3585{
3586 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3587
3588 if (WARN_ON(!rdev->testmode_info))
3589 return NULL;
3590
3591 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3592 rdev->testmode_info->snd_pid,
3593 rdev->testmode_info->snd_seq,
3594 GFP_KERNEL);
3595}
3596EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3597
3598int cfg80211_testmode_reply(struct sk_buff *skb)
3599{
3600 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3601 void *hdr = ((void **)skb->cb)[1];
3602 struct nlattr *data = ((void **)skb->cb)[2];
3603
3604 if (WARN_ON(!rdev->testmode_info)) {
3605 kfree_skb(skb);
3606 return -EINVAL;
3607 }
3608
3609 nla_nest_end(skb, data);
3610 genlmsg_end(skb, hdr);
3611 return genlmsg_reply(skb, rdev->testmode_info);
3612}
3613EXPORT_SYMBOL(cfg80211_testmode_reply);
3614
3615struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3616 int approxlen, gfp_t gfp)
3617{
3618 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3619
3620 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3621}
3622EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3623
3624void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3625{
3626 void *hdr = ((void **)skb->cb)[1];
3627 struct nlattr *data = ((void **)skb->cb)[2];
3628
3629 nla_nest_end(skb, data);
3630 genlmsg_end(skb, hdr);
3631 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3632}
3633EXPORT_SYMBOL(cfg80211_testmode_event);
3634#endif
3635
b23aa676
SO
3636static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3637{
3638 struct cfg80211_registered_device *drv;
3639 struct net_device *dev;
3640 struct cfg80211_connect_params connect;
3641 struct wiphy *wiphy;
3642 int err;
3643
3644 memset(&connect, 0, sizeof(connect));
3645
3646 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3647 return -EINVAL;
3648
3649 if (!info->attrs[NL80211_ATTR_SSID] ||
3650 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3651 return -EINVAL;
3652
3653 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3654 connect.auth_type =
3655 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3656 if (!nl80211_valid_auth_type(connect.auth_type))
3657 return -EINVAL;
3658 } else
3659 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3660
3661 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3662
3663 err = nl80211_crypto_settings(info, &connect.crypto);
3664 if (err)
3665 return err;
3666 rtnl_lock();
3667
3668 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3669 if (err)
3670 goto unlock_rtnl;
3671
3672 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3673 err = -EOPNOTSUPP;
3674 goto out;
3675 }
3676
3677 if (!netif_running(dev)) {
3678 err = -ENETDOWN;
3679 goto out;
3680 }
3681
3682 wiphy = &drv->wiphy;
3683
3684 connect.bssid = NULL;
3685 connect.channel = NULL;
3686 connect.auth_type = NL80211_AUTHTYPE_OPEN_SYSTEM;
3687
3688 if (info->attrs[NL80211_ATTR_MAC])
3689 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3690 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3691 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3692
3693 if (info->attrs[NL80211_ATTR_IE]) {
3694 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3695 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3696 }
3697
3698 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3699 connect.channel =
3700 ieee80211_get_channel(wiphy,
3701 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3702 if (!connect.channel ||
3703 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
3704 err = -EINVAL;
3705 goto out;
3706 }
3707 }
3708
3709 err = cfg80211_connect(drv, dev, &connect);
3710
3711out:
3712 cfg80211_put_dev(drv);
3713 dev_put(dev);
3714unlock_rtnl:
3715 rtnl_unlock();
3716 return err;
3717}
3718
3719static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
3720{
3721 struct cfg80211_registered_device *drv;
3722 struct net_device *dev;
3723 int err;
3724 u16 reason;
3725
3726 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3727 reason = WLAN_REASON_DEAUTH_LEAVING;
3728 else
3729 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3730
3731 if (reason == 0)
3732 return -EINVAL;
3733
3734 rtnl_lock();
3735
3736 err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3737 if (err)
3738 goto unlock_rtnl;
3739
3740 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3741 err = -EOPNOTSUPP;
3742 goto out;
3743 }
3744
3745 if (!netif_running(dev)) {
3746 err = -ENETDOWN;
3747 goto out;
3748 }
3749
f2129354 3750 err = cfg80211_disconnect(drv, dev, reason, true);
b23aa676
SO
3751
3752out:
3753 cfg80211_put_dev(drv);
3754 dev_put(dev);
3755unlock_rtnl:
3756 rtnl_unlock();
3757 return err;
3758}
3759
55682965
JB
3760static struct genl_ops nl80211_ops[] = {
3761 {
3762 .cmd = NL80211_CMD_GET_WIPHY,
3763 .doit = nl80211_get_wiphy,
3764 .dumpit = nl80211_dump_wiphy,
3765 .policy = nl80211_policy,
3766 /* can be retrieved by unprivileged users */
3767 },
3768 {
3769 .cmd = NL80211_CMD_SET_WIPHY,
3770 .doit = nl80211_set_wiphy,
3771 .policy = nl80211_policy,
3772 .flags = GENL_ADMIN_PERM,
3773 },
3774 {
3775 .cmd = NL80211_CMD_GET_INTERFACE,
3776 .doit = nl80211_get_interface,
3777 .dumpit = nl80211_dump_interface,
3778 .policy = nl80211_policy,
3779 /* can be retrieved by unprivileged users */
3780 },
3781 {
3782 .cmd = NL80211_CMD_SET_INTERFACE,
3783 .doit = nl80211_set_interface,
3784 .policy = nl80211_policy,
3785 .flags = GENL_ADMIN_PERM,
3786 },
3787 {
3788 .cmd = NL80211_CMD_NEW_INTERFACE,
3789 .doit = nl80211_new_interface,
3790 .policy = nl80211_policy,
3791 .flags = GENL_ADMIN_PERM,
3792 },
3793 {
3794 .cmd = NL80211_CMD_DEL_INTERFACE,
3795 .doit = nl80211_del_interface,
3796 .policy = nl80211_policy,
41ade00f
JB
3797 .flags = GENL_ADMIN_PERM,
3798 },
3799 {
3800 .cmd = NL80211_CMD_GET_KEY,
3801 .doit = nl80211_get_key,
3802 .policy = nl80211_policy,
3803 .flags = GENL_ADMIN_PERM,
3804 },
3805 {
3806 .cmd = NL80211_CMD_SET_KEY,
3807 .doit = nl80211_set_key,
3808 .policy = nl80211_policy,
3809 .flags = GENL_ADMIN_PERM,
3810 },
3811 {
3812 .cmd = NL80211_CMD_NEW_KEY,
3813 .doit = nl80211_new_key,
3814 .policy = nl80211_policy,
3815 .flags = GENL_ADMIN_PERM,
3816 },
3817 {
3818 .cmd = NL80211_CMD_DEL_KEY,
3819 .doit = nl80211_del_key,
3820 .policy = nl80211_policy,
55682965
JB
3821 .flags = GENL_ADMIN_PERM,
3822 },
ed1b6cc7
JB
3823 {
3824 .cmd = NL80211_CMD_SET_BEACON,
3825 .policy = nl80211_policy,
3826 .flags = GENL_ADMIN_PERM,
3827 .doit = nl80211_addset_beacon,
3828 },
3829 {
3830 .cmd = NL80211_CMD_NEW_BEACON,
3831 .policy = nl80211_policy,
3832 .flags = GENL_ADMIN_PERM,
3833 .doit = nl80211_addset_beacon,
3834 },
3835 {
3836 .cmd = NL80211_CMD_DEL_BEACON,
3837 .policy = nl80211_policy,
3838 .flags = GENL_ADMIN_PERM,
3839 .doit = nl80211_del_beacon,
3840 },
5727ef1b
JB
3841 {
3842 .cmd = NL80211_CMD_GET_STATION,
3843 .doit = nl80211_get_station,
2ec600d6 3844 .dumpit = nl80211_dump_station,
5727ef1b 3845 .policy = nl80211_policy,
5727ef1b
JB
3846 },
3847 {
3848 .cmd = NL80211_CMD_SET_STATION,
3849 .doit = nl80211_set_station,
3850 .policy = nl80211_policy,
3851 .flags = GENL_ADMIN_PERM,
3852 },
3853 {
3854 .cmd = NL80211_CMD_NEW_STATION,
3855 .doit = nl80211_new_station,
3856 .policy = nl80211_policy,
3857 .flags = GENL_ADMIN_PERM,
3858 },
3859 {
3860 .cmd = NL80211_CMD_DEL_STATION,
3861 .doit = nl80211_del_station,
3862 .policy = nl80211_policy,
2ec600d6
LCC
3863 .flags = GENL_ADMIN_PERM,
3864 },
3865 {
3866 .cmd = NL80211_CMD_GET_MPATH,
3867 .doit = nl80211_get_mpath,
3868 .dumpit = nl80211_dump_mpath,
3869 .policy = nl80211_policy,
3870 .flags = GENL_ADMIN_PERM,
3871 },
3872 {
3873 .cmd = NL80211_CMD_SET_MPATH,
3874 .doit = nl80211_set_mpath,
3875 .policy = nl80211_policy,
3876 .flags = GENL_ADMIN_PERM,
3877 },
3878 {
3879 .cmd = NL80211_CMD_NEW_MPATH,
3880 .doit = nl80211_new_mpath,
3881 .policy = nl80211_policy,
3882 .flags = GENL_ADMIN_PERM,
3883 },
3884 {
3885 .cmd = NL80211_CMD_DEL_MPATH,
3886 .doit = nl80211_del_mpath,
3887 .policy = nl80211_policy,
9f1ba906
JM
3888 .flags = GENL_ADMIN_PERM,
3889 },
3890 {
3891 .cmd = NL80211_CMD_SET_BSS,
3892 .doit = nl80211_set_bss,
3893 .policy = nl80211_policy,
b2e1b302
LR
3894 .flags = GENL_ADMIN_PERM,
3895 },
f130347c
LR
3896 {
3897 .cmd = NL80211_CMD_GET_REG,
3898 .doit = nl80211_get_reg,
3899 .policy = nl80211_policy,
3900 /* can be retrieved by unprivileged users */
3901 },
b2e1b302
LR
3902 {
3903 .cmd = NL80211_CMD_SET_REG,
3904 .doit = nl80211_set_reg,
3905 .policy = nl80211_policy,
3906 .flags = GENL_ADMIN_PERM,
3907 },
3908 {
3909 .cmd = NL80211_CMD_REQ_SET_REG,
3910 .doit = nl80211_req_set_reg,
3911 .policy = nl80211_policy,
93da9cc1 3912 .flags = GENL_ADMIN_PERM,
3913 },
3914 {
3915 .cmd = NL80211_CMD_GET_MESH_PARAMS,
3916 .doit = nl80211_get_mesh_params,
3917 .policy = nl80211_policy,
3918 /* can be retrieved by unprivileged users */
3919 },
3920 {
3921 .cmd = NL80211_CMD_SET_MESH_PARAMS,
3922 .doit = nl80211_set_mesh_params,
3923 .policy = nl80211_policy,
9aed3cc1
JM
3924 .flags = GENL_ADMIN_PERM,
3925 },
2a519311
JB
3926 {
3927 .cmd = NL80211_CMD_TRIGGER_SCAN,
3928 .doit = nl80211_trigger_scan,
3929 .policy = nl80211_policy,
3930 .flags = GENL_ADMIN_PERM,
3931 },
3932 {
3933 .cmd = NL80211_CMD_GET_SCAN,
3934 .policy = nl80211_policy,
3935 .dumpit = nl80211_dump_scan,
3936 },
636a5d36
JM
3937 {
3938 .cmd = NL80211_CMD_AUTHENTICATE,
3939 .doit = nl80211_authenticate,
3940 .policy = nl80211_policy,
3941 .flags = GENL_ADMIN_PERM,
3942 },
3943 {
3944 .cmd = NL80211_CMD_ASSOCIATE,
3945 .doit = nl80211_associate,
3946 .policy = nl80211_policy,
3947 .flags = GENL_ADMIN_PERM,
3948 },
3949 {
3950 .cmd = NL80211_CMD_DEAUTHENTICATE,
3951 .doit = nl80211_deauthenticate,
3952 .policy = nl80211_policy,
3953 .flags = GENL_ADMIN_PERM,
3954 },
3955 {
3956 .cmd = NL80211_CMD_DISASSOCIATE,
3957 .doit = nl80211_disassociate,
3958 .policy = nl80211_policy,
3959 .flags = GENL_ADMIN_PERM,
3960 },
04a773ad
JB
3961 {
3962 .cmd = NL80211_CMD_JOIN_IBSS,
3963 .doit = nl80211_join_ibss,
3964 .policy = nl80211_policy,
3965 .flags = GENL_ADMIN_PERM,
3966 },
3967 {
3968 .cmd = NL80211_CMD_LEAVE_IBSS,
3969 .doit = nl80211_leave_ibss,
3970 .policy = nl80211_policy,
3971 .flags = GENL_ADMIN_PERM,
3972 },
aff89a9b
JB
3973#ifdef CONFIG_NL80211_TESTMODE
3974 {
3975 .cmd = NL80211_CMD_TESTMODE,
3976 .doit = nl80211_testmode_do,
3977 .policy = nl80211_policy,
3978 .flags = GENL_ADMIN_PERM,
3979 },
3980#endif
b23aa676
SO
3981 {
3982 .cmd = NL80211_CMD_CONNECT,
3983 .doit = nl80211_connect,
3984 .policy = nl80211_policy,
3985 .flags = GENL_ADMIN_PERM,
3986 },
3987 {
3988 .cmd = NL80211_CMD_DISCONNECT,
3989 .doit = nl80211_disconnect,
3990 .policy = nl80211_policy,
3991 .flags = GENL_ADMIN_PERM,
3992 },
55682965 3993};
6039f6d2
JM
3994static struct genl_multicast_group nl80211_mlme_mcgrp = {
3995 .name = "mlme",
3996};
55682965
JB
3997
3998/* multicast groups */
3999static struct genl_multicast_group nl80211_config_mcgrp = {
4000 .name = "config",
4001};
2a519311
JB
4002static struct genl_multicast_group nl80211_scan_mcgrp = {
4003 .name = "scan",
4004};
73d54c9e
LR
4005static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4006 .name = "regulatory",
4007};
55682965
JB
4008
4009/* notification functions */
4010
4011void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4012{
4013 struct sk_buff *msg;
4014
fd2120ca 4015 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
4016 if (!msg)
4017 return;
4018
4019 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4020 nlmsg_free(msg);
4021 return;
4022 }
4023
4024 genlmsg_multicast(msg, 0, nl80211_config_mcgrp.id, GFP_KERNEL);
4025}
4026
362a415d
JB
4027static int nl80211_add_scan_req(struct sk_buff *msg,
4028 struct cfg80211_registered_device *rdev)
4029{
4030 struct cfg80211_scan_request *req = rdev->scan_req;
4031 struct nlattr *nest;
4032 int i;
4033
4034 if (WARN_ON(!req))
4035 return 0;
4036
4037 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4038 if (!nest)
4039 goto nla_put_failure;
4040 for (i = 0; i < req->n_ssids; i++)
4041 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4042 nla_nest_end(msg, nest);
4043
4044 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4045 if (!nest)
4046 goto nla_put_failure;
4047 for (i = 0; i < req->n_channels; i++)
4048 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4049 nla_nest_end(msg, nest);
4050
4051 if (req->ie)
4052 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4053
4054 return 0;
4055 nla_put_failure:
4056 return -ENOBUFS;
4057}
4058
a538e2d5
JB
4059static int nl80211_send_scan_msg(struct sk_buff *msg,
4060 struct cfg80211_registered_device *rdev,
4061 struct net_device *netdev,
4062 u32 pid, u32 seq, int flags,
4063 u32 cmd)
2a519311
JB
4064{
4065 void *hdr;
4066
4067 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4068 if (!hdr)
4069 return -1;
4070
b5850a7a 4071 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
4072 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4073
362a415d
JB
4074 /* ignore errors and send incomplete event anyway */
4075 nl80211_add_scan_req(msg, rdev);
2a519311
JB
4076
4077 return genlmsg_end(msg, hdr);
4078
4079 nla_put_failure:
4080 genlmsg_cancel(msg, hdr);
4081 return -EMSGSIZE;
4082}
4083
a538e2d5
JB
4084void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4085 struct net_device *netdev)
4086{
4087 struct sk_buff *msg;
4088
4089 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4090 if (!msg)
4091 return;
4092
4093 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4094 NL80211_CMD_TRIGGER_SCAN) < 0) {
4095 nlmsg_free(msg);
4096 return;
4097 }
4098
4099 genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
4100}
4101
2a519311
JB
4102void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4103 struct net_device *netdev)
4104{
4105 struct sk_buff *msg;
4106
fd2120ca 4107 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4108 if (!msg)
4109 return;
4110
a538e2d5
JB
4111 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4112 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
4113 nlmsg_free(msg);
4114 return;
4115 }
4116
4117 genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
4118}
4119
4120void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4121 struct net_device *netdev)
4122{
4123 struct sk_buff *msg;
4124
fd2120ca 4125 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4126 if (!msg)
4127 return;
4128
a538e2d5
JB
4129 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4130 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
4131 nlmsg_free(msg);
4132 return;
4133 }
4134
4135 genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
4136}
4137
73d54c9e
LR
4138/*
4139 * This can happen on global regulatory changes or device specific settings
4140 * based on custom world regulatory domains.
4141 */
4142void nl80211_send_reg_change_event(struct regulatory_request *request)
4143{
4144 struct sk_buff *msg;
4145 void *hdr;
4146
fd2120ca 4147 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
4148 if (!msg)
4149 return;
4150
4151 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4152 if (!hdr) {
4153 nlmsg_free(msg);
4154 return;
4155 }
4156
4157 /* Userspace can always count this one always being set */
4158 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4159
4160 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4161 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4162 NL80211_REGDOM_TYPE_WORLD);
4163 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4164 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4165 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4166 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4167 request->intersect)
4168 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4169 NL80211_REGDOM_TYPE_INTERSECTION);
4170 else {
4171 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4172 NL80211_REGDOM_TYPE_COUNTRY);
4173 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4174 }
4175
4176 if (wiphy_idx_valid(request->wiphy_idx))
4177 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4178
4179 if (genlmsg_end(msg, hdr) < 0) {
4180 nlmsg_free(msg);
4181 return;
4182 }
4183
4184 genlmsg_multicast(msg, 0, nl80211_regulatory_mcgrp.id, GFP_KERNEL);
4185
4186 return;
4187
4188nla_put_failure:
4189 genlmsg_cancel(msg, hdr);
4190 nlmsg_free(msg);
4191}
4192
6039f6d2
JM
4193static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4194 struct net_device *netdev,
4195 const u8 *buf, size_t len,
e6d6e342 4196 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
4197{
4198 struct sk_buff *msg;
4199 void *hdr;
4200
e6d6e342 4201 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
4202 if (!msg)
4203 return;
4204
4205 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4206 if (!hdr) {
4207 nlmsg_free(msg);
4208 return;
4209 }
4210
4211 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4212 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4213 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4214
4215 if (genlmsg_end(msg, hdr) < 0) {
4216 nlmsg_free(msg);
4217 return;
4218 }
4219
e6d6e342 4220 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
4221 return;
4222
4223 nla_put_failure:
4224 genlmsg_cancel(msg, hdr);
4225 nlmsg_free(msg);
4226}
4227
4228void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4229 struct net_device *netdev, const u8 *buf,
4230 size_t len, gfp_t gfp)
6039f6d2
JM
4231{
4232 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4233 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
4234}
4235
4236void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4237 struct net_device *netdev, const u8 *buf,
e6d6e342 4238 size_t len, gfp_t gfp)
6039f6d2 4239{
e6d6e342
JB
4240 nl80211_send_mlme_event(rdev, netdev, buf, len,
4241 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
4242}
4243
53b46b84 4244void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4245 struct net_device *netdev, const u8 *buf,
4246 size_t len, gfp_t gfp)
6039f6d2
JM
4247{
4248 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4249 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
4250}
4251
53b46b84
JM
4252void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4253 struct net_device *netdev, const u8 *buf,
e6d6e342 4254 size_t len, gfp_t gfp)
6039f6d2
JM
4255{
4256 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4257 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
4258}
4259
1b06bb40
LR
4260static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4261 struct net_device *netdev, int cmd,
e6d6e342 4262 const u8 *addr, gfp_t gfp)
1965c853
JM
4263{
4264 struct sk_buff *msg;
4265 void *hdr;
4266
e6d6e342 4267 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
4268 if (!msg)
4269 return;
4270
4271 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4272 if (!hdr) {
4273 nlmsg_free(msg);
4274 return;
4275 }
4276
4277 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4278 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4279 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4280 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4281
4282 if (genlmsg_end(msg, hdr) < 0) {
4283 nlmsg_free(msg);
4284 return;
4285 }
4286
e6d6e342 4287 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
4288 return;
4289
4290 nla_put_failure:
4291 genlmsg_cancel(msg, hdr);
4292 nlmsg_free(msg);
4293}
4294
4295void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4296 struct net_device *netdev, const u8 *addr,
4297 gfp_t gfp)
1965c853
JM
4298{
4299 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 4300 addr, gfp);
1965c853
JM
4301}
4302
4303void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4304 struct net_device *netdev, const u8 *addr,
4305 gfp_t gfp)
1965c853 4306{
e6d6e342
JB
4307 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4308 addr, gfp);
1965c853
JM
4309}
4310
b23aa676
SO
4311void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4312 struct net_device *netdev, const u8 *bssid,
4313 const u8 *req_ie, size_t req_ie_len,
4314 const u8 *resp_ie, size_t resp_ie_len,
4315 u16 status, gfp_t gfp)
4316{
4317 struct sk_buff *msg;
4318 void *hdr;
4319
4320 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4321 if (!msg)
4322 return;
4323
4324 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4325 if (!hdr) {
4326 nlmsg_free(msg);
4327 return;
4328 }
4329
4330 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4331 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4332 if (bssid)
4333 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4334 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4335 if (req_ie)
4336 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4337 if (resp_ie)
4338 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4339
4340 if (genlmsg_end(msg, hdr) < 0) {
4341 nlmsg_free(msg);
4342 return;
4343 }
4344
4345 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4346 return;
4347
4348 nla_put_failure:
4349 genlmsg_cancel(msg, hdr);
4350 nlmsg_free(msg);
4351
4352}
4353
4354void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4355 struct net_device *netdev, const u8 *bssid,
4356 const u8 *req_ie, size_t req_ie_len,
4357 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4358{
4359 struct sk_buff *msg;
4360 void *hdr;
4361
4362 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4363 if (!msg)
4364 return;
4365
4366 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4367 if (!hdr) {
4368 nlmsg_free(msg);
4369 return;
4370 }
4371
4372 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4373 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4374 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4375 if (req_ie)
4376 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4377 if (resp_ie)
4378 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4379
4380 if (genlmsg_end(msg, hdr) < 0) {
4381 nlmsg_free(msg);
4382 return;
4383 }
4384
4385 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4386 return;
4387
4388 nla_put_failure:
4389 genlmsg_cancel(msg, hdr);
4390 nlmsg_free(msg);
4391
4392}
4393
4394void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4395 struct net_device *netdev, u16 reason,
4396 u8 *ie, size_t ie_len, bool from_ap, gfp_t gfp)
4397{
4398 struct sk_buff *msg;
4399 void *hdr;
4400
4401 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4402 if (!msg)
4403 return;
4404
4405 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4406 if (!hdr) {
4407 nlmsg_free(msg);
4408 return;
4409 }
4410
4411 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4412 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4413 if (from_ap && reason)
4414 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4415 if (from_ap)
4416 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4417 if (ie)
4418 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4419
4420 if (genlmsg_end(msg, hdr) < 0) {
4421 nlmsg_free(msg);
4422 return;
4423 }
4424
4425 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4426 return;
4427
4428 nla_put_failure:
4429 genlmsg_cancel(msg, hdr);
4430 nlmsg_free(msg);
4431
4432}
4433
04a773ad
JB
4434void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4435 struct net_device *netdev, const u8 *bssid,
4436 gfp_t gfp)
4437{
4438 struct sk_buff *msg;
4439 void *hdr;
4440
fd2120ca 4441 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
4442 if (!msg)
4443 return;
4444
4445 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4446 if (!hdr) {
4447 nlmsg_free(msg);
4448 return;
4449 }
4450
4451 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4452 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4453 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4454
4455 if (genlmsg_end(msg, hdr) < 0) {
4456 nlmsg_free(msg);
4457 return;
4458 }
4459
4460 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
4461 return;
4462
4463 nla_put_failure:
4464 genlmsg_cancel(msg, hdr);
4465 nlmsg_free(msg);
4466}
4467
a3b8b056
JM
4468void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4469 struct net_device *netdev, const u8 *addr,
4470 enum nl80211_key_type key_type, int key_id,
e6d6e342 4471 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
4472{
4473 struct sk_buff *msg;
4474 void *hdr;
4475
e6d6e342 4476 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
4477 if (!msg)
4478 return;
4479
4480 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4481 if (!hdr) {
4482 nlmsg_free(msg);
4483 return;
4484 }
4485
4486 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4487 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4488 if (addr)
4489 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4490 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4491 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4492 if (tsc)
4493 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4494
4495 if (genlmsg_end(msg, hdr) < 0) {
4496 nlmsg_free(msg);
4497 return;
4498 }
4499
e6d6e342 4500 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
4501 return;
4502
4503 nla_put_failure:
4504 genlmsg_cancel(msg, hdr);
4505 nlmsg_free(msg);
4506}
4507
6bad8766
LR
4508void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
4509 struct ieee80211_channel *channel_before,
4510 struct ieee80211_channel *channel_after)
4511{
4512 struct sk_buff *msg;
4513 void *hdr;
4514 struct nlattr *nl_freq;
4515
fd2120ca 4516 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
4517 if (!msg)
4518 return;
4519
4520 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
4521 if (!hdr) {
4522 nlmsg_free(msg);
4523 return;
4524 }
4525
4526 /*
4527 * Since we are applying the beacon hint to a wiphy we know its
4528 * wiphy_idx is valid
4529 */
4530 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
4531
4532 /* Before */
4533 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
4534 if (!nl_freq)
4535 goto nla_put_failure;
4536 if (nl80211_msg_put_channel(msg, channel_before))
4537 goto nla_put_failure;
4538 nla_nest_end(msg, nl_freq);
4539
4540 /* After */
4541 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
4542 if (!nl_freq)
4543 goto nla_put_failure;
4544 if (nl80211_msg_put_channel(msg, channel_after))
4545 goto nla_put_failure;
4546 nla_nest_end(msg, nl_freq);
4547
4548 if (genlmsg_end(msg, hdr) < 0) {
4549 nlmsg_free(msg);
4550 return;
4551 }
4552
4553 genlmsg_multicast(msg, 0, nl80211_regulatory_mcgrp.id, GFP_ATOMIC);
4554
4555 return;
4556
4557nla_put_failure:
4558 genlmsg_cancel(msg, hdr);
4559 nlmsg_free(msg);
4560}
4561
55682965
JB
4562/* initialisation/exit functions */
4563
4564int nl80211_init(void)
4565{
0d63cbb5 4566 int err;
55682965 4567
0d63cbb5
MM
4568 err = genl_register_family_with_ops(&nl80211_fam,
4569 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
4570 if (err)
4571 return err;
4572
55682965
JB
4573 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
4574 if (err)
4575 goto err_out;
4576
2a519311
JB
4577 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
4578 if (err)
4579 goto err_out;
4580
73d54c9e
LR
4581 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
4582 if (err)
4583 goto err_out;
4584
6039f6d2
JM
4585 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
4586 if (err)
4587 goto err_out;
4588
aff89a9b
JB
4589#ifdef CONFIG_NL80211_TESTMODE
4590 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
4591 if (err)
4592 goto err_out;
4593#endif
4594
55682965
JB
4595 return 0;
4596 err_out:
4597 genl_unregister_family(&nl80211_fam);
4598 return err;
4599}
4600
4601void nl80211_exit(void)
4602{
4603 genl_unregister_family(&nl80211_fam);
4604}