]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: avoid transmitting delBA to old AP
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
96
97 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
98 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
99 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
100 .len = IEEE80211_MAX_DATA_LEN },
101 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
102 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
103 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
104 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
105 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
106 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
107 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 108 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 109 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 110 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
111 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
112 .len = IEEE80211_MAX_MESH_ID_LEN },
113 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 114
b2e1b302
LR
115 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
116 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
117
9f1ba906
JM
118 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
119 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
121 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
122 .len = NL80211_MAX_SUPP_RATES },
36aedc90 123
93da9cc1 124 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
125
36aedc90
JM
126 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
127 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
128
129 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
130 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
131 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
132 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
133 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
134
135 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
136 .len = IEEE80211_MAX_SSID_LEN },
137 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
138 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 139 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 140 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 141 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
142 [NL80211_ATTR_STA_FLAGS2] = {
143 .len = sizeof(struct nl80211_sta_flag_update),
144 },
3f77316c 145 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
146 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
147 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
148 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
149 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
150 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 151 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 152 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
153 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
154 .len = WLAN_PMKID_LEN },
9588bbd5
JM
155 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
156 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 157 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
158 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
159 .len = IEEE80211_MAX_DATA_LEN },
160 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 161 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 162 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 163 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 164 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
165
166 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
167 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 168 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
55682965
JB
169};
170
b9454e83 171/* policy for the attributes */
b54452b0 172static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 173 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
174 [NL80211_KEY_IDX] = { .type = NLA_U8 },
175 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
176 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
177 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
178 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
179};
180
a043897a
HS
181/* ifidx get helper */
182static int nl80211_get_ifidx(struct netlink_callback *cb)
183{
184 int res;
185
186 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
187 nl80211_fam.attrbuf, nl80211_fam.maxattr,
188 nl80211_policy);
189 if (res)
190 return res;
191
192 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
193 return -EINVAL;
194
195 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
196 if (!res)
197 return -EINVAL;
198 return res;
199}
200
67748893
JB
201static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
202 struct netlink_callback *cb,
203 struct cfg80211_registered_device **rdev,
204 struct net_device **dev)
205{
206 int ifidx = cb->args[0];
207 int err;
208
209 if (!ifidx)
210 ifidx = nl80211_get_ifidx(cb);
211 if (ifidx < 0)
212 return ifidx;
213
214 cb->args[0] = ifidx;
215
216 rtnl_lock();
217
218 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
219 if (!*dev) {
220 err = -ENODEV;
221 goto out_rtnl;
222 }
223
224 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
225 if (IS_ERR(dev)) {
226 err = PTR_ERR(dev);
227 goto out_rtnl;
228 }
229
230 return 0;
231 out_rtnl:
232 rtnl_unlock();
233 return err;
234}
235
236static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
237{
238 cfg80211_unlock_rdev(rdev);
239 rtnl_unlock();
240}
241
f4a11bb0
JB
242/* IE validation */
243static bool is_valid_ie_attr(const struct nlattr *attr)
244{
245 const u8 *pos;
246 int len;
247
248 if (!attr)
249 return true;
250
251 pos = nla_data(attr);
252 len = nla_len(attr);
253
254 while (len) {
255 u8 elemlen;
256
257 if (len < 2)
258 return false;
259 len -= 2;
260
261 elemlen = pos[1];
262 if (elemlen > len)
263 return false;
264
265 len -= elemlen;
266 pos += 2 + elemlen;
267 }
268
269 return true;
270}
271
55682965
JB
272/* message building helper */
273static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
274 int flags, u8 cmd)
275{
276 /* since there is no private header just add the generic one */
277 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
278}
279
5dab3b8a
LR
280static int nl80211_msg_put_channel(struct sk_buff *msg,
281 struct ieee80211_channel *chan)
282{
283 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
284 chan->center_freq);
285
286 if (chan->flags & IEEE80211_CHAN_DISABLED)
287 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
288 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
289 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
290 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
291 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
292 if (chan->flags & IEEE80211_CHAN_RADAR)
293 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
294
295 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
296 DBM_TO_MBM(chan->max_power));
297
298 return 0;
299
300 nla_put_failure:
301 return -ENOBUFS;
302}
303
55682965
JB
304/* netlink command implementations */
305
b9454e83
JB
306struct key_parse {
307 struct key_params p;
308 int idx;
309 bool def, defmgmt;
310};
311
312static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
313{
314 struct nlattr *tb[NL80211_KEY_MAX + 1];
315 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
316 nl80211_key_policy);
317 if (err)
318 return err;
319
320 k->def = !!tb[NL80211_KEY_DEFAULT];
321 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
322
323 if (tb[NL80211_KEY_IDX])
324 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
325
326 if (tb[NL80211_KEY_DATA]) {
327 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
328 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
329 }
330
331 if (tb[NL80211_KEY_SEQ]) {
332 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
333 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
334 }
335
336 if (tb[NL80211_KEY_CIPHER])
337 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
338
339 return 0;
340}
341
342static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
343{
344 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
345 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
346 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
347 }
348
349 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
350 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
351 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
352 }
353
354 if (info->attrs[NL80211_ATTR_KEY_IDX])
355 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
356
357 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
358 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
359
360 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
361 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
362
363 return 0;
364}
365
366static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
367{
368 int err;
369
370 memset(k, 0, sizeof(*k));
371 k->idx = -1;
372
373 if (info->attrs[NL80211_ATTR_KEY])
374 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
375 else
376 err = nl80211_parse_key_old(info, k);
377
378 if (err)
379 return err;
380
381 if (k->def && k->defmgmt)
382 return -EINVAL;
383
384 if (k->idx != -1) {
385 if (k->defmgmt) {
386 if (k->idx < 4 || k->idx > 5)
387 return -EINVAL;
388 } else if (k->def) {
389 if (k->idx < 0 || k->idx > 3)
390 return -EINVAL;
391 } else {
392 if (k->idx < 0 || k->idx > 5)
393 return -EINVAL;
394 }
395 }
396
397 return 0;
398}
399
fffd0934
JB
400static struct cfg80211_cached_keys *
401nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
402 struct nlattr *keys)
403{
404 struct key_parse parse;
405 struct nlattr *key;
406 struct cfg80211_cached_keys *result;
407 int rem, err, def = 0;
408
409 result = kzalloc(sizeof(*result), GFP_KERNEL);
410 if (!result)
411 return ERR_PTR(-ENOMEM);
412
413 result->def = -1;
414 result->defmgmt = -1;
415
416 nla_for_each_nested(key, keys, rem) {
417 memset(&parse, 0, sizeof(parse));
418 parse.idx = -1;
419
420 err = nl80211_parse_key_new(key, &parse);
421 if (err)
422 goto error;
423 err = -EINVAL;
424 if (!parse.p.key)
425 goto error;
426 if (parse.idx < 0 || parse.idx > 4)
427 goto error;
428 if (parse.def) {
429 if (def)
430 goto error;
431 def = 1;
432 result->def = parse.idx;
433 } else if (parse.defmgmt)
434 goto error;
435 err = cfg80211_validate_key_settings(rdev, &parse.p,
436 parse.idx, NULL);
437 if (err)
438 goto error;
439 result->params[parse.idx].cipher = parse.p.cipher;
440 result->params[parse.idx].key_len = parse.p.key_len;
441 result->params[parse.idx].key = result->data[parse.idx];
442 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
443 }
444
445 return result;
446 error:
447 kfree(result);
448 return ERR_PTR(err);
449}
450
451static int nl80211_key_allowed(struct wireless_dev *wdev)
452{
453 ASSERT_WDEV_LOCK(wdev);
454
fffd0934
JB
455 switch (wdev->iftype) {
456 case NL80211_IFTYPE_AP:
457 case NL80211_IFTYPE_AP_VLAN:
074ac8df 458 case NL80211_IFTYPE_P2P_GO:
fffd0934
JB
459 break;
460 case NL80211_IFTYPE_ADHOC:
461 if (!wdev->current_bss)
462 return -ENOLINK;
463 break;
464 case NL80211_IFTYPE_STATION:
074ac8df 465 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
466 if (wdev->sme_state != CFG80211_SME_CONNECTED)
467 return -ENOLINK;
468 break;
469 default:
470 return -EINVAL;
471 }
472
473 return 0;
474}
475
55682965
JB
476static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
477 struct cfg80211_registered_device *dev)
478{
479 void *hdr;
ee688b00
JB
480 struct nlattr *nl_bands, *nl_band;
481 struct nlattr *nl_freqs, *nl_freq;
482 struct nlattr *nl_rates, *nl_rate;
f59ac048 483 struct nlattr *nl_modes;
8fdc621d 484 struct nlattr *nl_cmds;
ee688b00
JB
485 enum ieee80211_band band;
486 struct ieee80211_channel *chan;
487 struct ieee80211_rate *rate;
488 int i;
f59ac048 489 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
490 const struct ieee80211_txrx_stypes *mgmt_stypes =
491 dev->wiphy.mgmt_stypes;
55682965
JB
492
493 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
494 if (!hdr)
495 return -1;
496
b5850a7a 497 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 498 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 499
f5ea9120
JB
500 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
501 cfg80211_rdev_list_generation);
502
b9a5f8ca
JM
503 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
504 dev->wiphy.retry_short);
505 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
506 dev->wiphy.retry_long);
507 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
508 dev->wiphy.frag_threshold);
509 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
510 dev->wiphy.rts_threshold);
81077e82
LT
511 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
512 dev->wiphy.coverage_class);
b9a5f8ca 513
2a519311
JB
514 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
515 dev->wiphy.max_scan_ssids);
18a83659
JB
516 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
517 dev->wiphy.max_scan_ie_len);
ee688b00 518
25e47c18
JB
519 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
520 sizeof(u32) * dev->wiphy.n_cipher_suites,
521 dev->wiphy.cipher_suites);
522
67fbb16b
SO
523 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
524 dev->wiphy.max_num_pmkids);
525
c0692b8f
JB
526 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
527 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
528
f59ac048
LR
529 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
530 if (!nl_modes)
531 goto nla_put_failure;
532
533 i = 0;
534 while (ifmodes) {
535 if (ifmodes & 1)
536 NLA_PUT_FLAG(msg, i);
537 ifmodes >>= 1;
538 i++;
539 }
540
541 nla_nest_end(msg, nl_modes);
542
ee688b00
JB
543 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
544 if (!nl_bands)
545 goto nla_put_failure;
546
547 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
548 if (!dev->wiphy.bands[band])
549 continue;
550
551 nl_band = nla_nest_start(msg, band);
552 if (!nl_band)
553 goto nla_put_failure;
554
d51626df
JB
555 /* add HT info */
556 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
557 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
558 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
559 &dev->wiphy.bands[band]->ht_cap.mcs);
560 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
561 dev->wiphy.bands[band]->ht_cap.cap);
562 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
563 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
564 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
565 dev->wiphy.bands[band]->ht_cap.ampdu_density);
566 }
567
ee688b00
JB
568 /* add frequencies */
569 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
570 if (!nl_freqs)
571 goto nla_put_failure;
572
573 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
574 nl_freq = nla_nest_start(msg, i);
575 if (!nl_freq)
576 goto nla_put_failure;
577
578 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
579
580 if (nl80211_msg_put_channel(msg, chan))
581 goto nla_put_failure;
e2f367f2 582
ee688b00
JB
583 nla_nest_end(msg, nl_freq);
584 }
585
586 nla_nest_end(msg, nl_freqs);
587
588 /* add bitrates */
589 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
590 if (!nl_rates)
591 goto nla_put_failure;
592
593 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
594 nl_rate = nla_nest_start(msg, i);
595 if (!nl_rate)
596 goto nla_put_failure;
597
598 rate = &dev->wiphy.bands[band]->bitrates[i];
599 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
600 rate->bitrate);
601 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
602 NLA_PUT_FLAG(msg,
603 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
604
605 nla_nest_end(msg, nl_rate);
606 }
607
608 nla_nest_end(msg, nl_rates);
609
610 nla_nest_end(msg, nl_band);
611 }
612 nla_nest_end(msg, nl_bands);
613
8fdc621d
JB
614 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
615 if (!nl_cmds)
616 goto nla_put_failure;
617
618 i = 0;
619#define CMD(op, n) \
620 do { \
621 if (dev->ops->op) { \
622 i++; \
623 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
624 } \
625 } while (0)
626
627 CMD(add_virtual_intf, NEW_INTERFACE);
628 CMD(change_virtual_intf, SET_INTERFACE);
629 CMD(add_key, NEW_KEY);
630 CMD(add_beacon, NEW_BEACON);
631 CMD(add_station, NEW_STATION);
632 CMD(add_mpath, NEW_MPATH);
633 CMD(set_mesh_params, SET_MESH_PARAMS);
634 CMD(change_bss, SET_BSS);
636a5d36
JM
635 CMD(auth, AUTHENTICATE);
636 CMD(assoc, ASSOCIATE);
637 CMD(deauth, DEAUTHENTICATE);
638 CMD(disassoc, DISASSOCIATE);
04a773ad 639 CMD(join_ibss, JOIN_IBSS);
67fbb16b
SO
640 CMD(set_pmksa, SET_PMKSA);
641 CMD(del_pmksa, DEL_PMKSA);
642 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 643 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 644 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 645 CMD(mgmt_tx, FRAME);
5be83de5 646 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
647 i++;
648 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
649 }
f444de05 650 CMD(set_channel, SET_CHANNEL);
e8347eba 651 CMD(set_wds_peer, SET_WDS_PEER);
8fdc621d
JB
652
653#undef CMD
b23aa676 654
6829c878 655 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
656 i++;
657 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
658 }
659
6829c878 660 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
661 i++;
662 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
663 }
664
8fdc621d
JB
665 nla_nest_end(msg, nl_cmds);
666
2e161f78
JB
667 if (mgmt_stypes) {
668 u16 stypes;
669 struct nlattr *nl_ftypes, *nl_ifs;
670 enum nl80211_iftype ift;
671
672 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
673 if (!nl_ifs)
674 goto nla_put_failure;
675
676 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
677 nl_ftypes = nla_nest_start(msg, ift);
678 if (!nl_ftypes)
679 goto nla_put_failure;
680 i = 0;
681 stypes = mgmt_stypes[ift].tx;
682 while (stypes) {
683 if (stypes & 1)
684 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
685 (i << 4) | IEEE80211_FTYPE_MGMT);
686 stypes >>= 1;
687 i++;
688 }
689 nla_nest_end(msg, nl_ftypes);
690 }
691
74b70a4e
JB
692 nla_nest_end(msg, nl_ifs);
693
2e161f78
JB
694 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
695 if (!nl_ifs)
696 goto nla_put_failure;
697
698 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
699 nl_ftypes = nla_nest_start(msg, ift);
700 if (!nl_ftypes)
701 goto nla_put_failure;
702 i = 0;
703 stypes = mgmt_stypes[ift].rx;
704 while (stypes) {
705 if (stypes & 1)
706 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
707 (i << 4) | IEEE80211_FTYPE_MGMT);
708 stypes >>= 1;
709 i++;
710 }
711 nla_nest_end(msg, nl_ftypes);
712 }
713 nla_nest_end(msg, nl_ifs);
714 }
715
55682965
JB
716 return genlmsg_end(msg, hdr);
717
718 nla_put_failure:
bc3ed28c
TG
719 genlmsg_cancel(msg, hdr);
720 return -EMSGSIZE;
55682965
JB
721}
722
723static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
724{
725 int idx = 0;
726 int start = cb->args[0];
727 struct cfg80211_registered_device *dev;
728
a1794390 729 mutex_lock(&cfg80211_mutex);
79c97e97 730 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
731 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
732 continue;
b4637271 733 if (++idx <= start)
55682965
JB
734 continue;
735 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
736 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
737 dev) < 0) {
738 idx--;
55682965 739 break;
b4637271 740 }
55682965 741 }
a1794390 742 mutex_unlock(&cfg80211_mutex);
55682965
JB
743
744 cb->args[0] = idx;
745
746 return skb->len;
747}
748
749static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
750{
751 struct sk_buff *msg;
4c476991 752 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 753
fd2120ca 754 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 755 if (!msg)
4c476991 756 return -ENOMEM;
55682965 757
4c476991
JB
758 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
759 nlmsg_free(msg);
760 return -ENOBUFS;
761 }
55682965 762
134e6375 763 return genlmsg_reply(msg, info);
55682965
JB
764}
765
31888487
JM
766static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
767 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
768 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
769 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
770 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
771 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
772};
773
774static int parse_txq_params(struct nlattr *tb[],
775 struct ieee80211_txq_params *txq_params)
776{
777 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
778 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
779 !tb[NL80211_TXQ_ATTR_AIFS])
780 return -EINVAL;
781
782 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
783 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
784 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
785 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
786 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
787
788 return 0;
789}
790
f444de05
JB
791static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
792{
793 /*
794 * You can only set the channel explicitly for AP, mesh
795 * and WDS type interfaces; all others have their channel
796 * managed via their respective "establish a connection"
797 * command (connect, join, ...)
798 *
799 * Monitors are special as they are normally slaved to
800 * whatever else is going on, so they behave as though
801 * you tried setting the wiphy channel itself.
802 */
803 return !wdev ||
804 wdev->iftype == NL80211_IFTYPE_AP ||
805 wdev->iftype == NL80211_IFTYPE_WDS ||
806 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
807 wdev->iftype == NL80211_IFTYPE_MONITOR ||
808 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
809}
810
811static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
812 struct wireless_dev *wdev,
813 struct genl_info *info)
814{
815 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
816 u32 freq;
817 int result;
818
819 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
820 return -EINVAL;
821
822 if (!nl80211_can_set_dev_channel(wdev))
823 return -EOPNOTSUPP;
824
825 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
826 channel_type = nla_get_u32(info->attrs[
827 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
828 if (channel_type != NL80211_CHAN_NO_HT &&
829 channel_type != NL80211_CHAN_HT20 &&
830 channel_type != NL80211_CHAN_HT40PLUS &&
831 channel_type != NL80211_CHAN_HT40MINUS)
832 return -EINVAL;
833 }
834
835 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
836
837 mutex_lock(&rdev->devlist_mtx);
838 if (wdev) {
839 wdev_lock(wdev);
840 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
841 wdev_unlock(wdev);
842 } else {
843 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
844 }
845 mutex_unlock(&rdev->devlist_mtx);
846
847 return result;
848}
849
850static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
851{
4c476991
JB
852 struct cfg80211_registered_device *rdev = info->user_ptr[0];
853 struct net_device *netdev = info->user_ptr[1];
f444de05 854
4c476991 855 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
856}
857
e8347eba
BJ
858static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
859{
860 struct cfg80211_registered_device *rdev;
861 struct wireless_dev *wdev;
862 struct net_device *dev;
863 u8 *bssid;
864 int err;
865
866 if (!info->attrs[NL80211_ATTR_MAC])
867 return -EINVAL;
868
869 rtnl_lock();
870
871 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
872 if (err)
873 goto unlock_rtnl;
874
875 wdev = dev->ieee80211_ptr;
876
877 if (netif_running(dev)) {
878 err = -EBUSY;
879 goto out;
880 }
881
882 if (!rdev->ops->set_wds_peer) {
883 err = -EOPNOTSUPP;
884 goto out;
885 }
886
887 if (wdev->iftype != NL80211_IFTYPE_WDS) {
888 err = -EOPNOTSUPP;
889 goto out;
890 }
891
892 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
893 err = rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
894
895out:
896 cfg80211_unlock_rdev(rdev);
897 dev_put(dev);
898unlock_rtnl:
899 rtnl_unlock();
900
901 return err;
902}
903
904
55682965
JB
905static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
906{
907 struct cfg80211_registered_device *rdev;
f444de05
JB
908 struct net_device *netdev = NULL;
909 struct wireless_dev *wdev;
a1e567c8 910 int result = 0, rem_txq_params = 0;
31888487 911 struct nlattr *nl_txq_params;
b9a5f8ca
JM
912 u32 changed;
913 u8 retry_short = 0, retry_long = 0;
914 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 915 u8 coverage_class = 0;
55682965 916
f444de05
JB
917 /*
918 * Try to find the wiphy and netdev. Normally this
919 * function shouldn't need the netdev, but this is
920 * done for backward compatibility -- previously
921 * setting the channel was done per wiphy, but now
922 * it is per netdev. Previous userland like hostapd
923 * also passed a netdev to set_wiphy, so that it is
924 * possible to let that go to the right netdev!
925 */
4bbf4d56
JB
926 mutex_lock(&cfg80211_mutex);
927
f444de05
JB
928 if (info->attrs[NL80211_ATTR_IFINDEX]) {
929 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
930
931 netdev = dev_get_by_index(genl_info_net(info), ifindex);
932 if (netdev && netdev->ieee80211_ptr) {
933 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
934 mutex_lock(&rdev->mtx);
935 } else
936 netdev = NULL;
4bbf4d56
JB
937 }
938
f444de05
JB
939 if (!netdev) {
940 rdev = __cfg80211_rdev_from_info(info);
941 if (IS_ERR(rdev)) {
942 mutex_unlock(&cfg80211_mutex);
4c476991 943 return PTR_ERR(rdev);
f444de05
JB
944 }
945 wdev = NULL;
946 netdev = NULL;
947 result = 0;
948
949 mutex_lock(&rdev->mtx);
950 } else if (netif_running(netdev) &&
951 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
952 wdev = netdev->ieee80211_ptr;
953 else
954 wdev = NULL;
955
956 /*
957 * end workaround code, by now the rdev is available
958 * and locked, and wdev may or may not be NULL.
959 */
4bbf4d56
JB
960
961 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
962 result = cfg80211_dev_rename(
963 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
964
965 mutex_unlock(&cfg80211_mutex);
966
967 if (result)
968 goto bad_res;
31888487
JM
969
970 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
971 struct ieee80211_txq_params txq_params;
972 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
973
974 if (!rdev->ops->set_txq_params) {
975 result = -EOPNOTSUPP;
976 goto bad_res;
977 }
978
979 nla_for_each_nested(nl_txq_params,
980 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
981 rem_txq_params) {
982 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
983 nla_data(nl_txq_params),
984 nla_len(nl_txq_params),
985 txq_params_policy);
986 result = parse_txq_params(tb, &txq_params);
987 if (result)
988 goto bad_res;
989
990 result = rdev->ops->set_txq_params(&rdev->wiphy,
991 &txq_params);
992 if (result)
993 goto bad_res;
994 }
995 }
55682965 996
72bdcf34 997 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 998 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
999 if (result)
1000 goto bad_res;
1001 }
1002
98d2ff8b
JO
1003 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1004 enum nl80211_tx_power_setting type;
1005 int idx, mbm = 0;
1006
1007 if (!rdev->ops->set_tx_power) {
60ea385f 1008 result = -EOPNOTSUPP;
98d2ff8b
JO
1009 goto bad_res;
1010 }
1011
1012 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1013 type = nla_get_u32(info->attrs[idx]);
1014
1015 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1016 (type != NL80211_TX_POWER_AUTOMATIC)) {
1017 result = -EINVAL;
1018 goto bad_res;
1019 }
1020
1021 if (type != NL80211_TX_POWER_AUTOMATIC) {
1022 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1023 mbm = nla_get_u32(info->attrs[idx]);
1024 }
1025
1026 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1027 if (result)
1028 goto bad_res;
1029 }
1030
b9a5f8ca
JM
1031 changed = 0;
1032
1033 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1034 retry_short = nla_get_u8(
1035 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1036 if (retry_short == 0) {
1037 result = -EINVAL;
1038 goto bad_res;
1039 }
1040 changed |= WIPHY_PARAM_RETRY_SHORT;
1041 }
1042
1043 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1044 retry_long = nla_get_u8(
1045 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1046 if (retry_long == 0) {
1047 result = -EINVAL;
1048 goto bad_res;
1049 }
1050 changed |= WIPHY_PARAM_RETRY_LONG;
1051 }
1052
1053 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1054 frag_threshold = nla_get_u32(
1055 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1056 if (frag_threshold < 256) {
1057 result = -EINVAL;
1058 goto bad_res;
1059 }
1060 if (frag_threshold != (u32) -1) {
1061 /*
1062 * Fragments (apart from the last one) are required to
1063 * have even length. Make the fragmentation code
1064 * simpler by stripping LSB should someone try to use
1065 * odd threshold value.
1066 */
1067 frag_threshold &= ~0x1;
1068 }
1069 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1070 }
1071
1072 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1073 rts_threshold = nla_get_u32(
1074 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1075 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1076 }
1077
81077e82
LT
1078 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1079 coverage_class = nla_get_u8(
1080 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1081 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1082 }
1083
b9a5f8ca
JM
1084 if (changed) {
1085 u8 old_retry_short, old_retry_long;
1086 u32 old_frag_threshold, old_rts_threshold;
81077e82 1087 u8 old_coverage_class;
b9a5f8ca
JM
1088
1089 if (!rdev->ops->set_wiphy_params) {
1090 result = -EOPNOTSUPP;
1091 goto bad_res;
1092 }
1093
1094 old_retry_short = rdev->wiphy.retry_short;
1095 old_retry_long = rdev->wiphy.retry_long;
1096 old_frag_threshold = rdev->wiphy.frag_threshold;
1097 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1098 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1099
1100 if (changed & WIPHY_PARAM_RETRY_SHORT)
1101 rdev->wiphy.retry_short = retry_short;
1102 if (changed & WIPHY_PARAM_RETRY_LONG)
1103 rdev->wiphy.retry_long = retry_long;
1104 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1105 rdev->wiphy.frag_threshold = frag_threshold;
1106 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1107 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1108 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1109 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1110
1111 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1112 if (result) {
1113 rdev->wiphy.retry_short = old_retry_short;
1114 rdev->wiphy.retry_long = old_retry_long;
1115 rdev->wiphy.frag_threshold = old_frag_threshold;
1116 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1117 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1118 }
1119 }
72bdcf34 1120
306d6112 1121 bad_res:
4bbf4d56 1122 mutex_unlock(&rdev->mtx);
f444de05
JB
1123 if (netdev)
1124 dev_put(netdev);
55682965
JB
1125 return result;
1126}
1127
1128
1129static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1130 struct cfg80211_registered_device *rdev,
55682965
JB
1131 struct net_device *dev)
1132{
1133 void *hdr;
1134
1135 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1136 if (!hdr)
1137 return -1;
1138
1139 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1140 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1141 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1142 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1143
1144 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1145 rdev->devlist_generation ^
1146 (cfg80211_rdev_list_generation << 2));
1147
55682965
JB
1148 return genlmsg_end(msg, hdr);
1149
1150 nla_put_failure:
bc3ed28c
TG
1151 genlmsg_cancel(msg, hdr);
1152 return -EMSGSIZE;
55682965
JB
1153}
1154
1155static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1156{
1157 int wp_idx = 0;
1158 int if_idx = 0;
1159 int wp_start = cb->args[0];
1160 int if_start = cb->args[1];
f5ea9120 1161 struct cfg80211_registered_device *rdev;
55682965
JB
1162 struct wireless_dev *wdev;
1163
a1794390 1164 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1165 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1166 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1167 continue;
bba95fef
JB
1168 if (wp_idx < wp_start) {
1169 wp_idx++;
55682965 1170 continue;
bba95fef 1171 }
55682965
JB
1172 if_idx = 0;
1173
f5ea9120
JB
1174 mutex_lock(&rdev->devlist_mtx);
1175 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1176 if (if_idx < if_start) {
1177 if_idx++;
55682965 1178 continue;
bba95fef 1179 }
55682965
JB
1180 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1181 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1182 rdev, wdev->netdev) < 0) {
1183 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1184 goto out;
1185 }
1186 if_idx++;
55682965 1187 }
f5ea9120 1188 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1189
1190 wp_idx++;
55682965 1191 }
bba95fef 1192 out:
a1794390 1193 mutex_unlock(&cfg80211_mutex);
55682965
JB
1194
1195 cb->args[0] = wp_idx;
1196 cb->args[1] = if_idx;
1197
1198 return skb->len;
1199}
1200
1201static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1202{
1203 struct sk_buff *msg;
4c476991
JB
1204 struct cfg80211_registered_device *dev = info->user_ptr[0];
1205 struct net_device *netdev = info->user_ptr[1];
55682965 1206
fd2120ca 1207 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1208 if (!msg)
4c476991 1209 return -ENOMEM;
55682965 1210
d726405a 1211 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1212 dev, netdev) < 0) {
1213 nlmsg_free(msg);
1214 return -ENOBUFS;
1215 }
55682965 1216
134e6375 1217 return genlmsg_reply(msg, info);
55682965
JB
1218}
1219
66f7ac50
MW
1220static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1221 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1222 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1223 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1224 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1225 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1226};
1227
1228static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1229{
1230 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1231 int flag;
1232
1233 *mntrflags = 0;
1234
1235 if (!nla)
1236 return -EINVAL;
1237
1238 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1239 nla, mntr_flags_policy))
1240 return -EINVAL;
1241
1242 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1243 if (flags[flag])
1244 *mntrflags |= (1<<flag);
1245
1246 return 0;
1247}
1248
9bc383de 1249static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1250 struct net_device *netdev, u8 use_4addr,
1251 enum nl80211_iftype iftype)
9bc383de 1252{
ad4bb6f8 1253 if (!use_4addr) {
f350a0a8 1254 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1255 return -EBUSY;
9bc383de 1256 return 0;
ad4bb6f8 1257 }
9bc383de
JB
1258
1259 switch (iftype) {
1260 case NL80211_IFTYPE_AP_VLAN:
1261 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1262 return 0;
1263 break;
1264 case NL80211_IFTYPE_STATION:
1265 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1266 return 0;
1267 break;
1268 default:
1269 break;
1270 }
1271
1272 return -EOPNOTSUPP;
1273}
1274
55682965
JB
1275static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1276{
4c476991 1277 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1278 struct vif_params params;
e36d56b6 1279 int err;
04a773ad 1280 enum nl80211_iftype otype, ntype;
4c476991 1281 struct net_device *dev = info->user_ptr[1];
92ffe055 1282 u32 _flags, *flags = NULL;
ac7f9cfa 1283 bool change = false;
55682965 1284
2ec600d6
LCC
1285 memset(&params, 0, sizeof(params));
1286
04a773ad 1287 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1288
723b038d 1289 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1290 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1291 if (otype != ntype)
ac7f9cfa 1292 change = true;
4c476991
JB
1293 if (ntype > NL80211_IFTYPE_MAX)
1294 return -EINVAL;
723b038d
JB
1295 }
1296
92ffe055 1297 if (info->attrs[NL80211_ATTR_MESH_ID]) {
4c476991
JB
1298 if (ntype != NL80211_IFTYPE_MESH_POINT)
1299 return -EINVAL;
2ec600d6
LCC
1300 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1301 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1302 change = true;
2ec600d6
LCC
1303 }
1304
8b787643
FF
1305 if (info->attrs[NL80211_ATTR_4ADDR]) {
1306 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1307 change = true;
ad4bb6f8 1308 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1309 if (err)
4c476991 1310 return err;
8b787643
FF
1311 } else {
1312 params.use_4addr = -1;
1313 }
1314
92ffe055 1315 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1316 if (ntype != NL80211_IFTYPE_MONITOR)
1317 return -EINVAL;
92ffe055
JB
1318 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1319 &_flags);
ac7f9cfa 1320 if (err)
4c476991 1321 return err;
ac7f9cfa
JB
1322
1323 flags = &_flags;
1324 change = true;
92ffe055 1325 }
3b85875a 1326
ac7f9cfa 1327 if (change)
3d54d255 1328 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1329 else
1330 err = 0;
60719ffd 1331
9bc383de
JB
1332 if (!err && params.use_4addr != -1)
1333 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1334
55682965
JB
1335 return err;
1336}
1337
1338static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1339{
4c476991 1340 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1341 struct vif_params params;
55682965
JB
1342 int err;
1343 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1344 u32 flags;
55682965 1345
2ec600d6
LCC
1346 memset(&params, 0, sizeof(params));
1347
55682965
JB
1348 if (!info->attrs[NL80211_ATTR_IFNAME])
1349 return -EINVAL;
1350
1351 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1352 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1353 if (type > NL80211_IFTYPE_MAX)
1354 return -EINVAL;
1355 }
1356
79c97e97 1357 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1358 !(rdev->wiphy.interface_modes & (1 << type)))
1359 return -EOPNOTSUPP;
55682965 1360
2ec600d6
LCC
1361 if (type == NL80211_IFTYPE_MESH_POINT &&
1362 info->attrs[NL80211_ATTR_MESH_ID]) {
1363 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1364 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1365 }
1366
9bc383de 1367 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1368 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1369 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1370 if (err)
4c476991 1371 return err;
9bc383de 1372 }
8b787643 1373
66f7ac50
MW
1374 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1375 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1376 &flags);
79c97e97 1377 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1378 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1379 type, err ? NULL : &flags, &params);
2ec600d6 1380
55682965
JB
1381 return err;
1382}
1383
1384static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1385{
4c476991
JB
1386 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1387 struct net_device *dev = info->user_ptr[1];
55682965 1388
4c476991
JB
1389 if (!rdev->ops->del_virtual_intf)
1390 return -EOPNOTSUPP;
55682965 1391
4c476991 1392 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1393}
1394
41ade00f
JB
1395struct get_key_cookie {
1396 struct sk_buff *msg;
1397 int error;
b9454e83 1398 int idx;
41ade00f
JB
1399};
1400
1401static void get_key_callback(void *c, struct key_params *params)
1402{
b9454e83 1403 struct nlattr *key;
41ade00f
JB
1404 struct get_key_cookie *cookie = c;
1405
1406 if (params->key)
1407 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1408 params->key_len, params->key);
1409
1410 if (params->seq)
1411 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1412 params->seq_len, params->seq);
1413
1414 if (params->cipher)
1415 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1416 params->cipher);
1417
b9454e83
JB
1418 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1419 if (!key)
1420 goto nla_put_failure;
1421
1422 if (params->key)
1423 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1424 params->key_len, params->key);
1425
1426 if (params->seq)
1427 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1428 params->seq_len, params->seq);
1429
1430 if (params->cipher)
1431 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1432 params->cipher);
1433
1434 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1435
1436 nla_nest_end(cookie->msg, key);
1437
41ade00f
JB
1438 return;
1439 nla_put_failure:
1440 cookie->error = 1;
1441}
1442
1443static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1444{
4c476991 1445 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1446 int err;
4c476991 1447 struct net_device *dev = info->user_ptr[1];
41ade00f
JB
1448 u8 key_idx = 0;
1449 u8 *mac_addr = NULL;
1450 struct get_key_cookie cookie = {
1451 .error = 0,
1452 };
1453 void *hdr;
1454 struct sk_buff *msg;
1455
1456 if (info->attrs[NL80211_ATTR_KEY_IDX])
1457 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1458
3cfcf6ac 1459 if (key_idx > 5)
41ade00f
JB
1460 return -EINVAL;
1461
1462 if (info->attrs[NL80211_ATTR_MAC])
1463 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1464
4c476991
JB
1465 if (!rdev->ops->get_key)
1466 return -EOPNOTSUPP;
41ade00f 1467
fd2120ca 1468 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1469 if (!msg)
1470 return -ENOMEM;
41ade00f
JB
1471
1472 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1473 NL80211_CMD_NEW_KEY);
4c476991
JB
1474 if (IS_ERR(hdr))
1475 return PTR_ERR(hdr);
41ade00f
JB
1476
1477 cookie.msg = msg;
b9454e83 1478 cookie.idx = key_idx;
41ade00f
JB
1479
1480 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1481 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1482 if (mac_addr)
1483 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1484
79c97e97 1485 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1486 &cookie, get_key_callback);
41ade00f
JB
1487
1488 if (err)
6c95e2a2 1489 goto free_msg;
41ade00f
JB
1490
1491 if (cookie.error)
1492 goto nla_put_failure;
1493
1494 genlmsg_end(msg, hdr);
4c476991 1495 return genlmsg_reply(msg, info);
41ade00f
JB
1496
1497 nla_put_failure:
1498 err = -ENOBUFS;
6c95e2a2 1499 free_msg:
41ade00f 1500 nlmsg_free(msg);
41ade00f
JB
1501 return err;
1502}
1503
1504static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1505{
4c476991 1506 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1507 struct key_parse key;
41ade00f 1508 int err;
4c476991 1509 struct net_device *dev = info->user_ptr[1];
3cfcf6ac
JM
1510 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1511 u8 key_index);
41ade00f 1512
b9454e83
JB
1513 err = nl80211_parse_key(info, &key);
1514 if (err)
1515 return err;
41ade00f 1516
b9454e83 1517 if (key.idx < 0)
41ade00f
JB
1518 return -EINVAL;
1519
b9454e83
JB
1520 /* only support setting default key */
1521 if (!key.def && !key.defmgmt)
41ade00f
JB
1522 return -EINVAL;
1523
b9454e83 1524 if (key.def)
79c97e97 1525 func = rdev->ops->set_default_key;
3cfcf6ac 1526 else
79c97e97 1527 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac 1528
4c476991
JB
1529 if (!func)
1530 return -EOPNOTSUPP;
41ade00f 1531
fffd0934
JB
1532 wdev_lock(dev->ieee80211_ptr);
1533 err = nl80211_key_allowed(dev->ieee80211_ptr);
1534 if (!err)
1535 err = func(&rdev->wiphy, dev, key.idx);
1536
3d23e349 1537#ifdef CONFIG_CFG80211_WEXT
08645126 1538 if (!err) {
79c97e97 1539 if (func == rdev->ops->set_default_key)
b9454e83 1540 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1541 else
b9454e83 1542 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1543 }
1544#endif
fffd0934 1545 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1546
41ade00f
JB
1547 return err;
1548}
1549
1550static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1551{
4c476991 1552 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1553 int err;
4c476991 1554 struct net_device *dev = info->user_ptr[1];
b9454e83 1555 struct key_parse key;
41ade00f
JB
1556 u8 *mac_addr = NULL;
1557
b9454e83
JB
1558 err = nl80211_parse_key(info, &key);
1559 if (err)
1560 return err;
41ade00f 1561
b9454e83 1562 if (!key.p.key)
41ade00f
JB
1563 return -EINVAL;
1564
41ade00f
JB
1565 if (info->attrs[NL80211_ATTR_MAC])
1566 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1567
4c476991
JB
1568 if (!rdev->ops->add_key)
1569 return -EOPNOTSUPP;
25e47c18 1570
4c476991
JB
1571 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr))
1572 return -EINVAL;
41ade00f 1573
fffd0934
JB
1574 wdev_lock(dev->ieee80211_ptr);
1575 err = nl80211_key_allowed(dev->ieee80211_ptr);
1576 if (!err)
1577 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1578 mac_addr, &key.p);
1579 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1580
41ade00f
JB
1581 return err;
1582}
1583
1584static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1585{
4c476991 1586 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1587 int err;
4c476991 1588 struct net_device *dev = info->user_ptr[1];
41ade00f 1589 u8 *mac_addr = NULL;
b9454e83 1590 struct key_parse key;
41ade00f 1591
b9454e83
JB
1592 err = nl80211_parse_key(info, &key);
1593 if (err)
1594 return err;
41ade00f
JB
1595
1596 if (info->attrs[NL80211_ATTR_MAC])
1597 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1598
4c476991
JB
1599 if (!rdev->ops->del_key)
1600 return -EOPNOTSUPP;
41ade00f 1601
fffd0934
JB
1602 wdev_lock(dev->ieee80211_ptr);
1603 err = nl80211_key_allowed(dev->ieee80211_ptr);
1604 if (!err)
1605 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1606
3d23e349 1607#ifdef CONFIG_CFG80211_WEXT
08645126 1608 if (!err) {
b9454e83 1609 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1610 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1611 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1612 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1613 }
1614#endif
fffd0934 1615 wdev_unlock(dev->ieee80211_ptr);
08645126 1616
41ade00f
JB
1617 return err;
1618}
1619
ed1b6cc7
JB
1620static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1621{
1622 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1623 struct beacon_parameters *info);
4c476991
JB
1624 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1625 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1626 struct beacon_parameters params;
1627 int haveinfo = 0;
1628
f4a11bb0
JB
1629 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1630 return -EINVAL;
1631
074ac8df 1632 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1633 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1634 return -EOPNOTSUPP;
eec60b03 1635
ed1b6cc7
JB
1636 switch (info->genlhdr->cmd) {
1637 case NL80211_CMD_NEW_BEACON:
1638 /* these are required for NEW_BEACON */
1639 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1640 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1641 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1642 return -EINVAL;
ed1b6cc7 1643
79c97e97 1644 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1645 break;
1646 case NL80211_CMD_SET_BEACON:
79c97e97 1647 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1648 break;
1649 default:
1650 WARN_ON(1);
4c476991 1651 return -EOPNOTSUPP;
ed1b6cc7
JB
1652 }
1653
4c476991
JB
1654 if (!call)
1655 return -EOPNOTSUPP;
ed1b6cc7
JB
1656
1657 memset(&params, 0, sizeof(params));
1658
1659 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1660 params.interval =
1661 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1662 haveinfo = 1;
1663 }
1664
1665 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1666 params.dtim_period =
1667 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1668 haveinfo = 1;
1669 }
1670
1671 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1672 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1673 params.head_len =
1674 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1675 haveinfo = 1;
1676 }
1677
1678 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1679 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1680 params.tail_len =
1681 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1682 haveinfo = 1;
1683 }
1684
4c476991
JB
1685 if (!haveinfo)
1686 return -EINVAL;
3b85875a 1687
4c476991 1688 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1689}
1690
1691static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1692{
4c476991
JB
1693 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1694 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1695
4c476991
JB
1696 if (!rdev->ops->del_beacon)
1697 return -EOPNOTSUPP;
ed1b6cc7 1698
074ac8df 1699 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1700 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1701 return -EOPNOTSUPP;
3b85875a 1702
4c476991 1703 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1704}
1705
5727ef1b
JB
1706static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1707 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1708 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1709 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1710 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1711};
1712
eccb8e8f
JB
1713static int parse_station_flags(struct genl_info *info,
1714 struct station_parameters *params)
5727ef1b
JB
1715{
1716 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1717 struct nlattr *nla;
5727ef1b
JB
1718 int flag;
1719
eccb8e8f
JB
1720 /*
1721 * Try parsing the new attribute first so userspace
1722 * can specify both for older kernels.
1723 */
1724 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1725 if (nla) {
1726 struct nl80211_sta_flag_update *sta_flags;
1727
1728 sta_flags = nla_data(nla);
1729 params->sta_flags_mask = sta_flags->mask;
1730 params->sta_flags_set = sta_flags->set;
1731 if ((params->sta_flags_mask |
1732 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1733 return -EINVAL;
1734 return 0;
1735 }
1736
1737 /* if present, parse the old attribute */
5727ef1b 1738
eccb8e8f 1739 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1740 if (!nla)
1741 return 0;
1742
1743 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1744 nla, sta_flags_policy))
1745 return -EINVAL;
1746
eccb8e8f
JB
1747 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1748 params->sta_flags_mask &= ~1;
5727ef1b
JB
1749
1750 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1751 if (flags[flag])
eccb8e8f 1752 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1753
1754 return 0;
1755}
1756
fd5b74dc
JB
1757static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1758 int flags, struct net_device *dev,
98b62183 1759 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1760{
1761 void *hdr;
420e7fab
HR
1762 struct nlattr *sinfoattr, *txrate;
1763 u16 bitrate;
fd5b74dc
JB
1764
1765 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1766 if (!hdr)
1767 return -1;
1768
1769 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1770 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1771
f5ea9120
JB
1772 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1773
2ec600d6
LCC
1774 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1775 if (!sinfoattr)
fd5b74dc 1776 goto nla_put_failure;
2ec600d6
LCC
1777 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1778 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1779 sinfo->inactive_time);
1780 if (sinfo->filled & STATION_INFO_RX_BYTES)
1781 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1782 sinfo->rx_bytes);
1783 if (sinfo->filled & STATION_INFO_TX_BYTES)
1784 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1785 sinfo->tx_bytes);
1786 if (sinfo->filled & STATION_INFO_LLID)
1787 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1788 sinfo->llid);
1789 if (sinfo->filled & STATION_INFO_PLID)
1790 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1791 sinfo->plid);
1792 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1793 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1794 sinfo->plink_state);
420e7fab
HR
1795 if (sinfo->filled & STATION_INFO_SIGNAL)
1796 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1797 sinfo->signal);
1798 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1799 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1800 if (!txrate)
1801 goto nla_put_failure;
1802
254416aa
JL
1803 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1804 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
1805 if (bitrate > 0)
1806 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1807
420e7fab
HR
1808 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1809 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1810 sinfo->txrate.mcs);
1811 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1812 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1813 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1814 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1815
1816 nla_nest_end(msg, txrate);
1817 }
98c8a60a
JM
1818 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1819 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1820 sinfo->rx_packets);
1821 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1822 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1823 sinfo->tx_packets);
2ec600d6 1824 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1825
1826 return genlmsg_end(msg, hdr);
1827
1828 nla_put_failure:
bc3ed28c
TG
1829 genlmsg_cancel(msg, hdr);
1830 return -EMSGSIZE;
fd5b74dc
JB
1831}
1832
2ec600d6 1833static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1834 struct netlink_callback *cb)
2ec600d6 1835{
2ec600d6
LCC
1836 struct station_info sinfo;
1837 struct cfg80211_registered_device *dev;
bba95fef 1838 struct net_device *netdev;
2ec600d6 1839 u8 mac_addr[ETH_ALEN];
bba95fef 1840 int sta_idx = cb->args[1];
2ec600d6 1841 int err;
2ec600d6 1842
67748893
JB
1843 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
1844 if (err)
1845 return err;
bba95fef
JB
1846
1847 if (!dev->ops->dump_station) {
eec60b03 1848 err = -EOPNOTSUPP;
bba95fef
JB
1849 goto out_err;
1850 }
1851
bba95fef
JB
1852 while (1) {
1853 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1854 mac_addr, &sinfo);
1855 if (err == -ENOENT)
1856 break;
1857 if (err)
3b85875a 1858 goto out_err;
bba95fef
JB
1859
1860 if (nl80211_send_station(skb,
1861 NETLINK_CB(cb->skb).pid,
1862 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1863 netdev, mac_addr,
1864 &sinfo) < 0)
1865 goto out;
1866
1867 sta_idx++;
1868 }
1869
1870
1871 out:
1872 cb->args[1] = sta_idx;
1873 err = skb->len;
bba95fef 1874 out_err:
67748893 1875 nl80211_finish_netdev_dump(dev);
bba95fef
JB
1876
1877 return err;
2ec600d6 1878}
fd5b74dc 1879
5727ef1b
JB
1880static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1881{
4c476991
JB
1882 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1883 struct net_device *dev = info->user_ptr[1];
2ec600d6 1884 struct station_info sinfo;
fd5b74dc
JB
1885 struct sk_buff *msg;
1886 u8 *mac_addr = NULL;
4c476991 1887 int err;
fd5b74dc 1888
2ec600d6 1889 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1890
1891 if (!info->attrs[NL80211_ATTR_MAC])
1892 return -EINVAL;
1893
1894 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1895
4c476991
JB
1896 if (!rdev->ops->get_station)
1897 return -EOPNOTSUPP;
3b85875a 1898
4c476991 1899 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 1900 if (err)
4c476991 1901 return err;
2ec600d6 1902
fd2120ca 1903 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 1904 if (!msg)
4c476991 1905 return -ENOMEM;
fd5b74dc
JB
1906
1907 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1908 dev, mac_addr, &sinfo) < 0) {
1909 nlmsg_free(msg);
1910 return -ENOBUFS;
1911 }
3b85875a 1912
4c476991 1913 return genlmsg_reply(msg, info);
5727ef1b
JB
1914}
1915
1916/*
c258d2de 1917 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 1918 */
463d0183 1919static int get_vlan(struct genl_info *info,
5727ef1b
JB
1920 struct cfg80211_registered_device *rdev,
1921 struct net_device **vlan)
1922{
463d0183 1923 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
1924 *vlan = NULL;
1925
1926 if (vlanattr) {
463d0183
JB
1927 *vlan = dev_get_by_index(genl_info_net(info),
1928 nla_get_u32(vlanattr));
5727ef1b
JB
1929 if (!*vlan)
1930 return -ENODEV;
1931 if (!(*vlan)->ieee80211_ptr)
1932 return -EINVAL;
1933 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1934 return -EINVAL;
c258d2de
FF
1935 if (!netif_running(*vlan))
1936 return -ENETDOWN;
5727ef1b
JB
1937 }
1938 return 0;
1939}
1940
1941static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1942{
4c476991 1943 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 1944 int err;
4c476991 1945 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
1946 struct station_parameters params;
1947 u8 *mac_addr = NULL;
1948
1949 memset(&params, 0, sizeof(params));
1950
1951 params.listen_interval = -1;
1952
1953 if (info->attrs[NL80211_ATTR_STA_AID])
1954 return -EINVAL;
1955
1956 if (!info->attrs[NL80211_ATTR_MAC])
1957 return -EINVAL;
1958
1959 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1960
1961 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1962 params.supported_rates =
1963 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1964 params.supported_rates_len =
1965 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1966 }
1967
1968 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1969 params.listen_interval =
1970 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1971
36aedc90
JM
1972 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1973 params.ht_capa =
1974 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1975
eccb8e8f 1976 if (parse_station_flags(info, &params))
5727ef1b
JB
1977 return -EINVAL;
1978
2ec600d6
LCC
1979 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1980 params.plink_action =
1981 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1982
463d0183 1983 err = get_vlan(info, rdev, &params.vlan);
a97f4424 1984 if (err)
034d655e 1985 goto out;
a97f4424
JB
1986
1987 /* validate settings */
1988 err = 0;
1989
1990 switch (dev->ieee80211_ptr->iftype) {
1991 case NL80211_IFTYPE_AP:
1992 case NL80211_IFTYPE_AP_VLAN:
074ac8df 1993 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
1994 /* disallow mesh-specific things */
1995 if (params.plink_action)
1996 err = -EINVAL;
1997 break;
074ac8df 1998 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
1999 case NL80211_IFTYPE_STATION:
2000 /* disallow everything but AUTHORIZED flag */
2001 if (params.plink_action)
2002 err = -EINVAL;
2003 if (params.vlan)
2004 err = -EINVAL;
2005 if (params.supported_rates)
2006 err = -EINVAL;
2007 if (params.ht_capa)
2008 err = -EINVAL;
2009 if (params.listen_interval >= 0)
2010 err = -EINVAL;
2011 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2012 err = -EINVAL;
2013 break;
2014 case NL80211_IFTYPE_MESH_POINT:
2015 /* disallow things mesh doesn't support */
2016 if (params.vlan)
2017 err = -EINVAL;
2018 if (params.ht_capa)
2019 err = -EINVAL;
2020 if (params.listen_interval >= 0)
2021 err = -EINVAL;
2022 if (params.supported_rates)
2023 err = -EINVAL;
2024 if (params.sta_flags_mask)
2025 err = -EINVAL;
2026 break;
2027 default:
2028 err = -EINVAL;
034d655e
JB
2029 }
2030
5727ef1b
JB
2031 if (err)
2032 goto out;
2033
79c97e97 2034 if (!rdev->ops->change_station) {
5727ef1b
JB
2035 err = -EOPNOTSUPP;
2036 goto out;
2037 }
2038
79c97e97 2039 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2040
2041 out:
2042 if (params.vlan)
2043 dev_put(params.vlan);
3b85875a 2044
5727ef1b
JB
2045 return err;
2046}
2047
2048static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2049{
4c476991 2050 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2051 int err;
4c476991 2052 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2053 struct station_parameters params;
2054 u8 *mac_addr = NULL;
2055
2056 memset(&params, 0, sizeof(params));
2057
2058 if (!info->attrs[NL80211_ATTR_MAC])
2059 return -EINVAL;
2060
5727ef1b
JB
2061 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2062 return -EINVAL;
2063
2064 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2065 return -EINVAL;
2066
0e956c13
TLSC
2067 if (!info->attrs[NL80211_ATTR_STA_AID])
2068 return -EINVAL;
2069
5727ef1b
JB
2070 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2071 params.supported_rates =
2072 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2073 params.supported_rates_len =
2074 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2075 params.listen_interval =
2076 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2077
0e956c13
TLSC
2078 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2079 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2080 return -EINVAL;
51b50fbe 2081
36aedc90
JM
2082 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2083 params.ht_capa =
2084 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2085
eccb8e8f 2086 if (parse_station_flags(info, &params))
5727ef1b
JB
2087 return -EINVAL;
2088
0e956c13 2089 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2090 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4c476991
JB
2091 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2092 return -EINVAL;
0e956c13 2093
463d0183 2094 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2095 if (err)
e80cf853 2096 goto out;
a97f4424
JB
2097
2098 /* validate settings */
2099 err = 0;
2100
79c97e97 2101 if (!rdev->ops->add_station) {
5727ef1b
JB
2102 err = -EOPNOTSUPP;
2103 goto out;
2104 }
2105
79c97e97 2106 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2107
2108 out:
2109 if (params.vlan)
2110 dev_put(params.vlan);
5727ef1b
JB
2111 return err;
2112}
2113
2114static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2115{
4c476991
JB
2116 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2117 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2118 u8 *mac_addr = NULL;
2119
2120 if (info->attrs[NL80211_ATTR_MAC])
2121 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2122
e80cf853 2123 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2124 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2125 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2126 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2127 return -EINVAL;
5727ef1b 2128
4c476991
JB
2129 if (!rdev->ops->del_station)
2130 return -EOPNOTSUPP;
3b85875a 2131
4c476991 2132 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2133}
2134
2ec600d6
LCC
2135static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2136 int flags, struct net_device *dev,
2137 u8 *dst, u8 *next_hop,
2138 struct mpath_info *pinfo)
2139{
2140 void *hdr;
2141 struct nlattr *pinfoattr;
2142
2143 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2144 if (!hdr)
2145 return -1;
2146
2147 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2148 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2149 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2150
f5ea9120
JB
2151 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2152
2ec600d6
LCC
2153 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2154 if (!pinfoattr)
2155 goto nla_put_failure;
2156 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2157 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2158 pinfo->frame_qlen);
d19b3bf6
RP
2159 if (pinfo->filled & MPATH_INFO_SN)
2160 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2161 pinfo->sn);
2ec600d6
LCC
2162 if (pinfo->filled & MPATH_INFO_METRIC)
2163 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2164 pinfo->metric);
2165 if (pinfo->filled & MPATH_INFO_EXPTIME)
2166 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2167 pinfo->exptime);
2168 if (pinfo->filled & MPATH_INFO_FLAGS)
2169 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2170 pinfo->flags);
2171 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2172 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2173 pinfo->discovery_timeout);
2174 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2175 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2176 pinfo->discovery_retries);
2177
2178 nla_nest_end(msg, pinfoattr);
2179
2180 return genlmsg_end(msg, hdr);
2181
2182 nla_put_failure:
bc3ed28c
TG
2183 genlmsg_cancel(msg, hdr);
2184 return -EMSGSIZE;
2ec600d6
LCC
2185}
2186
2187static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2188 struct netlink_callback *cb)
2ec600d6 2189{
2ec600d6
LCC
2190 struct mpath_info pinfo;
2191 struct cfg80211_registered_device *dev;
bba95fef 2192 struct net_device *netdev;
2ec600d6
LCC
2193 u8 dst[ETH_ALEN];
2194 u8 next_hop[ETH_ALEN];
bba95fef 2195 int path_idx = cb->args[1];
2ec600d6 2196 int err;
2ec600d6 2197
67748893
JB
2198 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2199 if (err)
2200 return err;
bba95fef
JB
2201
2202 if (!dev->ops->dump_mpath) {
eec60b03 2203 err = -EOPNOTSUPP;
bba95fef
JB
2204 goto out_err;
2205 }
2206
eec60b03
JM
2207 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2208 err = -EOPNOTSUPP;
0448b5fc 2209 goto out_err;
eec60b03
JM
2210 }
2211
bba95fef
JB
2212 while (1) {
2213 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2214 dst, next_hop, &pinfo);
2215 if (err == -ENOENT)
2ec600d6 2216 break;
bba95fef 2217 if (err)
3b85875a 2218 goto out_err;
2ec600d6 2219
bba95fef
JB
2220 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2221 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2222 netdev, dst, next_hop,
2223 &pinfo) < 0)
2224 goto out;
2ec600d6 2225
bba95fef 2226 path_idx++;
2ec600d6 2227 }
2ec600d6 2228
2ec600d6 2229
bba95fef
JB
2230 out:
2231 cb->args[1] = path_idx;
2232 err = skb->len;
bba95fef 2233 out_err:
67748893 2234 nl80211_finish_netdev_dump(dev);
bba95fef 2235 return err;
2ec600d6
LCC
2236}
2237
2238static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2239{
4c476991 2240 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2241 int err;
4c476991 2242 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2243 struct mpath_info pinfo;
2244 struct sk_buff *msg;
2245 u8 *dst = NULL;
2246 u8 next_hop[ETH_ALEN];
2247
2248 memset(&pinfo, 0, sizeof(pinfo));
2249
2250 if (!info->attrs[NL80211_ATTR_MAC])
2251 return -EINVAL;
2252
2253 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2254
4c476991
JB
2255 if (!rdev->ops->get_mpath)
2256 return -EOPNOTSUPP;
2ec600d6 2257
4c476991
JB
2258 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2259 return -EOPNOTSUPP;
eec60b03 2260
79c97e97 2261 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2262 if (err)
4c476991 2263 return err;
2ec600d6 2264
fd2120ca 2265 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2266 if (!msg)
4c476991 2267 return -ENOMEM;
2ec600d6
LCC
2268
2269 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2270 dev, dst, next_hop, &pinfo) < 0) {
2271 nlmsg_free(msg);
2272 return -ENOBUFS;
2273 }
3b85875a 2274
4c476991 2275 return genlmsg_reply(msg, info);
2ec600d6
LCC
2276}
2277
2278static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2279{
4c476991
JB
2280 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2281 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2282 u8 *dst = NULL;
2283 u8 *next_hop = NULL;
2284
2285 if (!info->attrs[NL80211_ATTR_MAC])
2286 return -EINVAL;
2287
2288 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2289 return -EINVAL;
2290
2291 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2292 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2293
4c476991
JB
2294 if (!rdev->ops->change_mpath)
2295 return -EOPNOTSUPP;
35a8efe1 2296
4c476991
JB
2297 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2298 return -EOPNOTSUPP;
2ec600d6 2299
4c476991 2300 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2301}
4c476991 2302
2ec600d6
LCC
2303static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2304{
4c476991
JB
2305 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2306 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2307 u8 *dst = NULL;
2308 u8 *next_hop = NULL;
2309
2310 if (!info->attrs[NL80211_ATTR_MAC])
2311 return -EINVAL;
2312
2313 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2314 return -EINVAL;
2315
2316 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2317 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2318
4c476991
JB
2319 if (!rdev->ops->add_mpath)
2320 return -EOPNOTSUPP;
35a8efe1 2321
4c476991
JB
2322 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2323 return -EOPNOTSUPP;
2ec600d6 2324
4c476991 2325 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2326}
2327
2328static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2329{
4c476991
JB
2330 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2331 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2332 u8 *dst = NULL;
2333
2334 if (info->attrs[NL80211_ATTR_MAC])
2335 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2336
4c476991
JB
2337 if (!rdev->ops->del_mpath)
2338 return -EOPNOTSUPP;
3b85875a 2339
4c476991 2340 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2341}
2342
9f1ba906
JM
2343static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2344{
4c476991
JB
2345 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2346 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2347 struct bss_parameters params;
2348
2349 memset(&params, 0, sizeof(params));
2350 /* default to not changing parameters */
2351 params.use_cts_prot = -1;
2352 params.use_short_preamble = -1;
2353 params.use_short_slot_time = -1;
fd8aaaf3 2354 params.ap_isolate = -1;
9f1ba906
JM
2355
2356 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2357 params.use_cts_prot =
2358 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2359 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2360 params.use_short_preamble =
2361 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2362 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2363 params.use_short_slot_time =
2364 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2365 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2366 params.basic_rates =
2367 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2368 params.basic_rates_len =
2369 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2370 }
fd8aaaf3
FF
2371 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2372 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
9f1ba906 2373
4c476991
JB
2374 if (!rdev->ops->change_bss)
2375 return -EOPNOTSUPP;
9f1ba906 2376
074ac8df 2377 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2378 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2379 return -EOPNOTSUPP;
3b85875a 2380
4c476991 2381 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2382}
2383
b54452b0 2384static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2385 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2386 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2387 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2388 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2389 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2390 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2391};
2392
2393static int parse_reg_rule(struct nlattr *tb[],
2394 struct ieee80211_reg_rule *reg_rule)
2395{
2396 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2397 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2398
2399 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2400 return -EINVAL;
2401 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2402 return -EINVAL;
2403 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2404 return -EINVAL;
2405 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2406 return -EINVAL;
2407 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2408 return -EINVAL;
2409
2410 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2411
2412 freq_range->start_freq_khz =
2413 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2414 freq_range->end_freq_khz =
2415 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2416 freq_range->max_bandwidth_khz =
2417 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2418
2419 power_rule->max_eirp =
2420 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2421
2422 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2423 power_rule->max_antenna_gain =
2424 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2425
2426 return 0;
2427}
2428
2429static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2430{
2431 int r;
2432 char *data = NULL;
2433
80778f18
LR
2434 /*
2435 * You should only get this when cfg80211 hasn't yet initialized
2436 * completely when built-in to the kernel right between the time
2437 * window between nl80211_init() and regulatory_init(), if that is
2438 * even possible.
2439 */
2440 mutex_lock(&cfg80211_mutex);
2441 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2442 mutex_unlock(&cfg80211_mutex);
2443 return -EINPROGRESS;
80778f18 2444 }
fe33eb39 2445 mutex_unlock(&cfg80211_mutex);
80778f18 2446
fe33eb39
LR
2447 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2448 return -EINVAL;
b2e1b302
LR
2449
2450 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2451
fe33eb39
LR
2452 r = regulatory_hint_user(data);
2453
b2e1b302
LR
2454 return r;
2455}
2456
93da9cc1 2457static int nl80211_get_mesh_params(struct sk_buff *skb,
2458 struct genl_info *info)
2459{
4c476991 2460 struct cfg80211_registered_device *rdev = info->user_ptr[0];
93da9cc1 2461 struct mesh_config cur_params;
2462 int err;
4c476991 2463 struct net_device *dev = info->user_ptr[1];
93da9cc1 2464 void *hdr;
2465 struct nlattr *pinfoattr;
2466 struct sk_buff *msg;
2467
4c476991
JB
2468 if (!rdev->ops->get_mesh_params)
2469 return -EOPNOTSUPP;
f3f92586 2470
93da9cc1 2471 /* Get the mesh params */
79c97e97 2472 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2473 if (err)
4c476991 2474 return err;
93da9cc1 2475
2476 /* Draw up a netlink message to send back */
fd2120ca 2477 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2478 if (!msg)
2479 return -ENOMEM;
93da9cc1 2480 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2481 NL80211_CMD_GET_MESH_PARAMS);
2482 if (!hdr)
2483 goto nla_put_failure;
2484 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2485 if (!pinfoattr)
2486 goto nla_put_failure;
2487 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2488 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2489 cur_params.dot11MeshRetryTimeout);
2490 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2491 cur_params.dot11MeshConfirmTimeout);
2492 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2493 cur_params.dot11MeshHoldingTimeout);
2494 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2495 cur_params.dot11MeshMaxPeerLinks);
2496 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2497 cur_params.dot11MeshMaxRetries);
2498 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2499 cur_params.dot11MeshTTL);
2500 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2501 cur_params.auto_open_plinks);
2502 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2503 cur_params.dot11MeshHWMPmaxPREQretries);
2504 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2505 cur_params.path_refresh_time);
2506 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2507 cur_params.min_discovery_timeout);
2508 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2509 cur_params.dot11MeshHWMPactivePathTimeout);
2510 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2511 cur_params.dot11MeshHWMPpreqMinInterval);
2512 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2513 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2514 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2515 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2516 nla_nest_end(msg, pinfoattr);
2517 genlmsg_end(msg, hdr);
4c476991 2518 return genlmsg_reply(msg, info);
93da9cc1 2519
3b85875a 2520 nla_put_failure:
93da9cc1 2521 genlmsg_cancel(msg, hdr);
d080e275 2522 nlmsg_free(msg);
4c476991 2523 return -ENOBUFS;
93da9cc1 2524}
2525
2526#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2527do {\
2528 if (table[attr_num]) {\
2529 cfg.param = nla_fn(table[attr_num]); \
2530 mask |= (1 << (attr_num - 1)); \
2531 } \
2532} while (0);\
2533
b54452b0 2534static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2535 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2536 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2537 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2538 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2539 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2540 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2541 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2542
2543 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2544 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2545 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2546 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2547 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2548 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2549};
2550
2551static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2552{
93da9cc1 2553 u32 mask;
4c476991
JB
2554 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2555 struct net_device *dev = info->user_ptr[1];
93da9cc1 2556 struct mesh_config cfg;
2557 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2558 struct nlattr *parent_attr;
2559
2560 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2561 if (!parent_attr)
2562 return -EINVAL;
2563 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2564 parent_attr, nl80211_meshconf_params_policy))
2565 return -EINVAL;
2566
4c476991
JB
2567 if (!rdev->ops->set_mesh_params)
2568 return -EOPNOTSUPP;
f3f92586 2569
93da9cc1 2570 /* This makes sure that there aren't more than 32 mesh config
2571 * parameters (otherwise our bitfield scheme would not work.) */
2572 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2573
2574 /* Fill in the params struct */
2575 mask = 0;
2576 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2577 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2578 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2579 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2580 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2581 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2582 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2583 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2584 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2585 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2586 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2587 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2588 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2589 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2590 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2591 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2592 nla_get_u8);
2593 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2594 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2595 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2596 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2597 nla_get_u16);
2598 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2599 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2600 nla_get_u32);
2601 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2602 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2603 nla_get_u16);
2604 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2605 dot11MeshHWMPnetDiameterTraversalTime,
2606 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2607 nla_get_u16);
63c5723b
RP
2608 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2609 dot11MeshHWMPRootMode, mask,
2610 NL80211_MESHCONF_HWMP_ROOTMODE,
2611 nla_get_u8);
93da9cc1 2612
2613 /* Apply changes */
4c476991 2614 return rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2615}
2616
2617#undef FILL_IN_MESH_PARAM_IF_SET
2618
f130347c
LR
2619static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2620{
2621 struct sk_buff *msg;
2622 void *hdr = NULL;
2623 struct nlattr *nl_reg_rules;
2624 unsigned int i;
2625 int err = -EINVAL;
2626
a1794390 2627 mutex_lock(&cfg80211_mutex);
f130347c
LR
2628
2629 if (!cfg80211_regdomain)
2630 goto out;
2631
fd2120ca 2632 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2633 if (!msg) {
2634 err = -ENOBUFS;
2635 goto out;
2636 }
2637
2638 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2639 NL80211_CMD_GET_REG);
2640 if (!hdr)
2641 goto nla_put_failure;
2642
2643 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2644 cfg80211_regdomain->alpha2);
2645
2646 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2647 if (!nl_reg_rules)
2648 goto nla_put_failure;
2649
2650 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2651 struct nlattr *nl_reg_rule;
2652 const struct ieee80211_reg_rule *reg_rule;
2653 const struct ieee80211_freq_range *freq_range;
2654 const struct ieee80211_power_rule *power_rule;
2655
2656 reg_rule = &cfg80211_regdomain->reg_rules[i];
2657 freq_range = &reg_rule->freq_range;
2658 power_rule = &reg_rule->power_rule;
2659
2660 nl_reg_rule = nla_nest_start(msg, i);
2661 if (!nl_reg_rule)
2662 goto nla_put_failure;
2663
2664 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2665 reg_rule->flags);
2666 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2667 freq_range->start_freq_khz);
2668 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2669 freq_range->end_freq_khz);
2670 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2671 freq_range->max_bandwidth_khz);
2672 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2673 power_rule->max_antenna_gain);
2674 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2675 power_rule->max_eirp);
2676
2677 nla_nest_end(msg, nl_reg_rule);
2678 }
2679
2680 nla_nest_end(msg, nl_reg_rules);
2681
2682 genlmsg_end(msg, hdr);
134e6375 2683 err = genlmsg_reply(msg, info);
f130347c
LR
2684 goto out;
2685
2686nla_put_failure:
2687 genlmsg_cancel(msg, hdr);
d080e275 2688 nlmsg_free(msg);
f130347c
LR
2689 err = -EMSGSIZE;
2690out:
a1794390 2691 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2692 return err;
2693}
2694
b2e1b302
LR
2695static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2696{
2697 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2698 struct nlattr *nl_reg_rule;
2699 char *alpha2 = NULL;
2700 int rem_reg_rules = 0, r = 0;
2701 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2702 struct ieee80211_regdomain *rd = NULL;
2703
2704 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2705 return -EINVAL;
2706
2707 if (!info->attrs[NL80211_ATTR_REG_RULES])
2708 return -EINVAL;
2709
2710 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2711
2712 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2713 rem_reg_rules) {
2714 num_rules++;
2715 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2716 return -EINVAL;
b2e1b302
LR
2717 }
2718
61405e97
LR
2719 mutex_lock(&cfg80211_mutex);
2720
d0e18f83
LR
2721 if (!reg_is_valid_request(alpha2)) {
2722 r = -EINVAL;
2723 goto bad_reg;
2724 }
b2e1b302
LR
2725
2726 size_of_regd = sizeof(struct ieee80211_regdomain) +
2727 (num_rules * sizeof(struct ieee80211_reg_rule));
2728
2729 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2730 if (!rd) {
2731 r = -ENOMEM;
2732 goto bad_reg;
2733 }
b2e1b302
LR
2734
2735 rd->n_reg_rules = num_rules;
2736 rd->alpha2[0] = alpha2[0];
2737 rd->alpha2[1] = alpha2[1];
2738
2739 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2740 rem_reg_rules) {
2741 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2742 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2743 reg_rule_policy);
2744 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2745 if (r)
2746 goto bad_reg;
2747
2748 rule_idx++;
2749
d0e18f83
LR
2750 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2751 r = -EINVAL;
b2e1b302 2752 goto bad_reg;
d0e18f83 2753 }
b2e1b302
LR
2754 }
2755
2756 BUG_ON(rule_idx != num_rules);
2757
b2e1b302 2758 r = set_regdom(rd);
61405e97 2759
a1794390 2760 mutex_unlock(&cfg80211_mutex);
d0e18f83 2761
b2e1b302
LR
2762 return r;
2763
d2372b31 2764 bad_reg:
61405e97 2765 mutex_unlock(&cfg80211_mutex);
b2e1b302 2766 kfree(rd);
d0e18f83 2767 return r;
b2e1b302
LR
2768}
2769
83f5e2cf
JB
2770static int validate_scan_freqs(struct nlattr *freqs)
2771{
2772 struct nlattr *attr1, *attr2;
2773 int n_channels = 0, tmp1, tmp2;
2774
2775 nla_for_each_nested(attr1, freqs, tmp1) {
2776 n_channels++;
2777 /*
2778 * Some hardware has a limited channel list for
2779 * scanning, and it is pretty much nonsensical
2780 * to scan for a channel twice, so disallow that
2781 * and don't require drivers to check that the
2782 * channel list they get isn't longer than what
2783 * they can scan, as long as they can scan all
2784 * the channels they registered at once.
2785 */
2786 nla_for_each_nested(attr2, freqs, tmp2)
2787 if (attr1 != attr2 &&
2788 nla_get_u32(attr1) == nla_get_u32(attr2))
2789 return 0;
2790 }
2791
2792 return n_channels;
2793}
2794
2a519311
JB
2795static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2796{
4c476991
JB
2797 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2798 struct net_device *dev = info->user_ptr[1];
2a519311
JB
2799 struct cfg80211_scan_request *request;
2800 struct cfg80211_ssid *ssid;
2801 struct ieee80211_channel *channel;
2802 struct nlattr *attr;
2803 struct wiphy *wiphy;
83f5e2cf 2804 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 2805 enum ieee80211_band band;
70692ad2 2806 size_t ie_len;
2a519311 2807
f4a11bb0
JB
2808 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2809 return -EINVAL;
2810
79c97e97 2811 wiphy = &rdev->wiphy;
2a519311 2812
4c476991
JB
2813 if (!rdev->ops->scan)
2814 return -EOPNOTSUPP;
2a519311 2815
4c476991
JB
2816 if (rdev->scan_req)
2817 return -EBUSY;
2a519311
JB
2818
2819 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
2820 n_channels = validate_scan_freqs(
2821 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
2822 if (!n_channels)
2823 return -EINVAL;
2a519311 2824 } else {
83f5e2cf
JB
2825 n_channels = 0;
2826
2a519311
JB
2827 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2828 if (wiphy->bands[band])
2829 n_channels += wiphy->bands[band]->n_channels;
2830 }
2831
2832 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2833 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2834 n_ssids++;
2835
4c476991
JB
2836 if (n_ssids > wiphy->max_scan_ssids)
2837 return -EINVAL;
2a519311 2838
70692ad2
JM
2839 if (info->attrs[NL80211_ATTR_IE])
2840 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2841 else
2842 ie_len = 0;
2843
4c476991
JB
2844 if (ie_len > wiphy->max_scan_ie_len)
2845 return -EINVAL;
18a83659 2846
2a519311
JB
2847 request = kzalloc(sizeof(*request)
2848 + sizeof(*ssid) * n_ssids
70692ad2
JM
2849 + sizeof(channel) * n_channels
2850 + ie_len, GFP_KERNEL);
4c476991
JB
2851 if (!request)
2852 return -ENOMEM;
2a519311 2853
2a519311 2854 if (n_ssids)
5ba63533 2855 request->ssids = (void *)&request->channels[n_channels];
2a519311 2856 request->n_ssids = n_ssids;
70692ad2
JM
2857 if (ie_len) {
2858 if (request->ssids)
2859 request->ie = (void *)(request->ssids + n_ssids);
2860 else
2861 request->ie = (void *)(request->channels + n_channels);
2862 }
2a519311 2863
584991dc 2864 i = 0;
2a519311
JB
2865 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2866 /* user specified, bail out if channel not found */
2a519311 2867 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
2868 struct ieee80211_channel *chan;
2869
2870 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2871
2872 if (!chan) {
2a519311
JB
2873 err = -EINVAL;
2874 goto out_free;
2875 }
584991dc
JB
2876
2877 /* ignore disabled channels */
2878 if (chan->flags & IEEE80211_CHAN_DISABLED)
2879 continue;
2880
2881 request->channels[i] = chan;
2a519311
JB
2882 i++;
2883 }
2884 } else {
2885 /* all channels */
2a519311
JB
2886 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2887 int j;
2888 if (!wiphy->bands[band])
2889 continue;
2890 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
2891 struct ieee80211_channel *chan;
2892
2893 chan = &wiphy->bands[band]->channels[j];
2894
2895 if (chan->flags & IEEE80211_CHAN_DISABLED)
2896 continue;
2897
2898 request->channels[i] = chan;
2a519311
JB
2899 i++;
2900 }
2901 }
2902 }
2903
584991dc
JB
2904 if (!i) {
2905 err = -EINVAL;
2906 goto out_free;
2907 }
2908
2909 request->n_channels = i;
2910
2a519311
JB
2911 i = 0;
2912 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
2913 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
2914 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
2915 err = -EINVAL;
2916 goto out_free;
2917 }
2918 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2919 request->ssids[i].ssid_len = nla_len(attr);
2920 i++;
2921 }
2922 }
2923
70692ad2
JM
2924 if (info->attrs[NL80211_ATTR_IE]) {
2925 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
2926 memcpy((void *)request->ie,
2927 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
2928 request->ie_len);
2929 }
2930
463d0183 2931 request->dev = dev;
79c97e97 2932 request->wiphy = &rdev->wiphy;
2a519311 2933
79c97e97
JB
2934 rdev->scan_req = request;
2935 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 2936
463d0183 2937 if (!err) {
79c97e97 2938 nl80211_send_scan_start(rdev, dev);
463d0183 2939 dev_hold(dev);
4c476991 2940 } else {
2a519311 2941 out_free:
79c97e97 2942 rdev->scan_req = NULL;
2a519311
JB
2943 kfree(request);
2944 }
3b85875a 2945
2a519311
JB
2946 return err;
2947}
2948
2949static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
2950 struct cfg80211_registered_device *rdev,
48ab905d
JB
2951 struct wireless_dev *wdev,
2952 struct cfg80211_internal_bss *intbss)
2a519311 2953{
48ab905d 2954 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
2955 void *hdr;
2956 struct nlattr *bss;
48ab905d
JB
2957 int i;
2958
2959 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
2960
2961 hdr = nl80211hdr_put(msg, pid, seq, flags,
2962 NL80211_CMD_NEW_SCAN_RESULTS);
2963 if (!hdr)
2964 return -1;
2965
f5ea9120 2966 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 2967 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
2968
2969 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
2970 if (!bss)
2971 goto nla_put_failure;
2972 if (!is_zero_ether_addr(res->bssid))
2973 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
2974 if (res->information_elements && res->len_information_elements)
2975 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
2976 res->len_information_elements,
2977 res->information_elements);
34a6eddb
JM
2978 if (res->beacon_ies && res->len_beacon_ies &&
2979 res->beacon_ies != res->information_elements)
2980 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
2981 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
2982 if (res->tsf)
2983 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
2984 if (res->beacon_interval)
2985 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
2986 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
2987 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
2988 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
2989 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 2990
77965c97 2991 switch (rdev->wiphy.signal_type) {
2a519311
JB
2992 case CFG80211_SIGNAL_TYPE_MBM:
2993 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
2994 break;
2995 case CFG80211_SIGNAL_TYPE_UNSPEC:
2996 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
2997 break;
2998 default:
2999 break;
3000 }
3001
48ab905d 3002 switch (wdev->iftype) {
074ac8df 3003 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3004 case NL80211_IFTYPE_STATION:
3005 if (intbss == wdev->current_bss)
3006 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3007 NL80211_BSS_STATUS_ASSOCIATED);
3008 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3009 if (intbss != wdev->auth_bsses[i])
3010 continue;
3011 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3012 NL80211_BSS_STATUS_AUTHENTICATED);
3013 break;
3014 }
3015 break;
3016 case NL80211_IFTYPE_ADHOC:
3017 if (intbss == wdev->current_bss)
3018 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3019 NL80211_BSS_STATUS_IBSS_JOINED);
3020 break;
3021 default:
3022 break;
3023 }
3024
2a519311
JB
3025 nla_nest_end(msg, bss);
3026
3027 return genlmsg_end(msg, hdr);
3028
3029 nla_put_failure:
3030 genlmsg_cancel(msg, hdr);
3031 return -EMSGSIZE;
3032}
3033
3034static int nl80211_dump_scan(struct sk_buff *skb,
3035 struct netlink_callback *cb)
3036{
48ab905d
JB
3037 struct cfg80211_registered_device *rdev;
3038 struct net_device *dev;
2a519311 3039 struct cfg80211_internal_bss *scan;
48ab905d 3040 struct wireless_dev *wdev;
2a519311
JB
3041 int start = cb->args[1], idx = 0;
3042 int err;
3043
67748893
JB
3044 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3045 if (err)
3046 return err;
2a519311 3047
48ab905d 3048 wdev = dev->ieee80211_ptr;
2a519311 3049
48ab905d
JB
3050 wdev_lock(wdev);
3051 spin_lock_bh(&rdev->bss_lock);
3052 cfg80211_bss_expire(rdev);
3053
3054 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3055 if (++idx <= start)
3056 continue;
3057 if (nl80211_send_bss(skb,
3058 NETLINK_CB(cb->skb).pid,
3059 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3060 rdev, wdev, scan) < 0) {
2a519311 3061 idx--;
67748893 3062 break;
2a519311
JB
3063 }
3064 }
3065
48ab905d
JB
3066 spin_unlock_bh(&rdev->bss_lock);
3067 wdev_unlock(wdev);
2a519311
JB
3068
3069 cb->args[1] = idx;
67748893 3070 nl80211_finish_netdev_dump(rdev);
2a519311 3071
67748893 3072 return skb->len;
2a519311
JB
3073}
3074
61fa713c
HS
3075static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3076 int flags, struct net_device *dev,
3077 struct survey_info *survey)
3078{
3079 void *hdr;
3080 struct nlattr *infoattr;
3081
3082 /* Survey without a channel doesn't make sense */
3083 if (!survey->channel)
3084 return -EINVAL;
3085
3086 hdr = nl80211hdr_put(msg, pid, seq, flags,
3087 NL80211_CMD_NEW_SURVEY_RESULTS);
3088 if (!hdr)
3089 return -ENOMEM;
3090
3091 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3092
3093 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3094 if (!infoattr)
3095 goto nla_put_failure;
3096
3097 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3098 survey->channel->center_freq);
3099 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3100 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3101 survey->noise);
17e5a808
FF
3102 if (survey->filled & SURVEY_INFO_IN_USE)
3103 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
61fa713c
HS
3104
3105 nla_nest_end(msg, infoattr);
3106
3107 return genlmsg_end(msg, hdr);
3108
3109 nla_put_failure:
3110 genlmsg_cancel(msg, hdr);
3111 return -EMSGSIZE;
3112}
3113
3114static int nl80211_dump_survey(struct sk_buff *skb,
3115 struct netlink_callback *cb)
3116{
3117 struct survey_info survey;
3118 struct cfg80211_registered_device *dev;
3119 struct net_device *netdev;
61fa713c
HS
3120 int survey_idx = cb->args[1];
3121 int res;
3122
67748893
JB
3123 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3124 if (res)
3125 return res;
61fa713c
HS
3126
3127 if (!dev->ops->dump_survey) {
3128 res = -EOPNOTSUPP;
3129 goto out_err;
3130 }
3131
3132 while (1) {
3133 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3134 &survey);
3135 if (res == -ENOENT)
3136 break;
3137 if (res)
3138 goto out_err;
3139
3140 if (nl80211_send_survey(skb,
3141 NETLINK_CB(cb->skb).pid,
3142 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3143 netdev,
3144 &survey) < 0)
3145 goto out;
3146 survey_idx++;
3147 }
3148
3149 out:
3150 cb->args[1] = survey_idx;
3151 res = skb->len;
3152 out_err:
67748893 3153 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3154 return res;
3155}
3156
255e737e
JM
3157static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3158{
b23aa676
SO
3159 return auth_type <= NL80211_AUTHTYPE_MAX;
3160}
3161
3162static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3163{
3164 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3165 NL80211_WPA_VERSION_2));
3166}
3167
3168static bool nl80211_valid_akm_suite(u32 akm)
3169{
3170 return akm == WLAN_AKM_SUITE_8021X ||
3171 akm == WLAN_AKM_SUITE_PSK;
3172}
3173
3174static bool nl80211_valid_cipher_suite(u32 cipher)
3175{
3176 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3177 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3178 cipher == WLAN_CIPHER_SUITE_TKIP ||
3179 cipher == WLAN_CIPHER_SUITE_CCMP ||
3180 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3181}
3182
b23aa676 3183
636a5d36
JM
3184static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3185{
4c476991
JB
3186 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3187 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3188 struct ieee80211_channel *chan;
3189 const u8 *bssid, *ssid, *ie = NULL;
3190 int err, ssid_len, ie_len = 0;
3191 enum nl80211_auth_type auth_type;
fffd0934 3192 struct key_parse key;
d5cdfacb 3193 bool local_state_change;
636a5d36 3194
f4a11bb0
JB
3195 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3196 return -EINVAL;
3197
3198 if (!info->attrs[NL80211_ATTR_MAC])
3199 return -EINVAL;
3200
1778092e
JM
3201 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3202 return -EINVAL;
3203
19957bb3
JB
3204 if (!info->attrs[NL80211_ATTR_SSID])
3205 return -EINVAL;
3206
3207 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3208 return -EINVAL;
3209
fffd0934
JB
3210 err = nl80211_parse_key(info, &key);
3211 if (err)
3212 return err;
3213
3214 if (key.idx >= 0) {
3215 if (!key.p.key || !key.p.key_len)
3216 return -EINVAL;
3217 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3218 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3219 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3220 key.p.key_len != WLAN_KEY_LEN_WEP104))
3221 return -EINVAL;
3222 if (key.idx > 4)
3223 return -EINVAL;
3224 } else {
3225 key.p.key_len = 0;
3226 key.p.key = NULL;
3227 }
3228
afea0b7a
JB
3229 if (key.idx >= 0) {
3230 int i;
3231 bool ok = false;
3232 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3233 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3234 ok = true;
3235 break;
3236 }
3237 }
4c476991
JB
3238 if (!ok)
3239 return -EINVAL;
afea0b7a
JB
3240 }
3241
4c476991
JB
3242 if (!rdev->ops->auth)
3243 return -EOPNOTSUPP;
636a5d36 3244
074ac8df 3245 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3246 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3247 return -EOPNOTSUPP;
eec60b03 3248
19957bb3 3249 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3250 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3251 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3252 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3253 return -EINVAL;
636a5d36 3254
19957bb3
JB
3255 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3256 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3257
3258 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3259 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3260 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3261 }
3262
19957bb3 3263 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3264 if (!nl80211_valid_auth_type(auth_type))
3265 return -EINVAL;
636a5d36 3266
d5cdfacb
JM
3267 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3268
4c476991
JB
3269 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3270 ssid, ssid_len, ie, ie_len,
3271 key.p.key, key.p.key_len, key.idx,
3272 local_state_change);
636a5d36
JM
3273}
3274
c0692b8f
JB
3275static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3276 struct genl_info *info,
3dc27d25
JB
3277 struct cfg80211_crypto_settings *settings,
3278 int cipher_limit)
b23aa676 3279{
c0b2bbd8
JB
3280 memset(settings, 0, sizeof(*settings));
3281
b23aa676
SO
3282 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3283
c0692b8f
JB
3284 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3285 u16 proto;
3286 proto = nla_get_u16(
3287 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3288 settings->control_port_ethertype = cpu_to_be16(proto);
3289 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3290 proto != ETH_P_PAE)
3291 return -EINVAL;
3292 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3293 settings->control_port_no_encrypt = true;
3294 } else
3295 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3296
b23aa676
SO
3297 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3298 void *data;
3299 int len, i;
3300
3301 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3302 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3303 settings->n_ciphers_pairwise = len / sizeof(u32);
3304
3305 if (len % sizeof(u32))
3306 return -EINVAL;
3307
3dc27d25 3308 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3309 return -EINVAL;
3310
3311 memcpy(settings->ciphers_pairwise, data, len);
3312
3313 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3314 if (!nl80211_valid_cipher_suite(
3315 settings->ciphers_pairwise[i]))
3316 return -EINVAL;
3317 }
3318
3319 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3320 settings->cipher_group =
3321 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3322 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3323 return -EINVAL;
3324 }
3325
3326 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3327 settings->wpa_versions =
3328 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3329 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3330 return -EINVAL;
3331 }
3332
3333 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3334 void *data;
3335 int len, i;
3336
3337 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3338 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3339 settings->n_akm_suites = len / sizeof(u32);
3340
3341 if (len % sizeof(u32))
3342 return -EINVAL;
3343
3344 memcpy(settings->akm_suites, data, len);
3345
3346 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3347 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3348 return -EINVAL;
3349 }
3350
3351 return 0;
3352}
3353
636a5d36
JM
3354static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3355{
4c476991
JB
3356 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3357 struct net_device *dev = info->user_ptr[1];
19957bb3 3358 struct cfg80211_crypto_settings crypto;
f444de05 3359 struct ieee80211_channel *chan;
3e5d7649 3360 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3361 int err, ssid_len, ie_len = 0;
3362 bool use_mfp = false;
636a5d36 3363
f4a11bb0
JB
3364 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3365 return -EINVAL;
3366
3367 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3368 !info->attrs[NL80211_ATTR_SSID] ||
3369 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3370 return -EINVAL;
3371
4c476991
JB
3372 if (!rdev->ops->assoc)
3373 return -EOPNOTSUPP;
636a5d36 3374
074ac8df 3375 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3376 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3377 return -EOPNOTSUPP;
eec60b03 3378
19957bb3 3379 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3380
19957bb3
JB
3381 chan = ieee80211_get_channel(&rdev->wiphy,
3382 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3383 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3384 return -EINVAL;
636a5d36 3385
19957bb3
JB
3386 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3387 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3388
3389 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3390 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3391 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3392 }
3393
dc6382ce 3394 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3395 enum nl80211_mfp mfp =
dc6382ce 3396 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3397 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3398 use_mfp = true;
4c476991
JB
3399 else if (mfp != NL80211_MFP_NO)
3400 return -EINVAL;
dc6382ce
JM
3401 }
3402
3e5d7649
JB
3403 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3404 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3405
c0692b8f 3406 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3407 if (!err)
3e5d7649
JB
3408 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3409 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3410 &crypto);
636a5d36 3411
636a5d36
JM
3412 return err;
3413}
3414
3415static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3416{
4c476991
JB
3417 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3418 struct net_device *dev = info->user_ptr[1];
19957bb3 3419 const u8 *ie = NULL, *bssid;
4c476991 3420 int ie_len = 0;
19957bb3 3421 u16 reason_code;
d5cdfacb 3422 bool local_state_change;
636a5d36 3423
f4a11bb0
JB
3424 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3425 return -EINVAL;
3426
3427 if (!info->attrs[NL80211_ATTR_MAC])
3428 return -EINVAL;
3429
3430 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3431 return -EINVAL;
3432
4c476991
JB
3433 if (!rdev->ops->deauth)
3434 return -EOPNOTSUPP;
636a5d36 3435
074ac8df 3436 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3437 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3438 return -EOPNOTSUPP;
eec60b03 3439
19957bb3 3440 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3441
19957bb3
JB
3442 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3443 if (reason_code == 0) {
f4a11bb0 3444 /* Reason Code 0 is reserved */
4c476991 3445 return -EINVAL;
255e737e 3446 }
636a5d36
JM
3447
3448 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3449 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3450 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3451 }
3452
d5cdfacb
JM
3453 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3454
4c476991
JB
3455 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3456 local_state_change);
636a5d36
JM
3457}
3458
3459static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3460{
4c476991
JB
3461 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3462 struct net_device *dev = info->user_ptr[1];
19957bb3 3463 const u8 *ie = NULL, *bssid;
4c476991 3464 int ie_len = 0;
19957bb3 3465 u16 reason_code;
d5cdfacb 3466 bool local_state_change;
636a5d36 3467
f4a11bb0
JB
3468 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3469 return -EINVAL;
3470
3471 if (!info->attrs[NL80211_ATTR_MAC])
3472 return -EINVAL;
3473
3474 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3475 return -EINVAL;
3476
4c476991
JB
3477 if (!rdev->ops->disassoc)
3478 return -EOPNOTSUPP;
636a5d36 3479
074ac8df 3480 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3481 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3482 return -EOPNOTSUPP;
eec60b03 3483
19957bb3 3484 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3485
19957bb3
JB
3486 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3487 if (reason_code == 0) {
f4a11bb0 3488 /* Reason Code 0 is reserved */
4c476991 3489 return -EINVAL;
255e737e 3490 }
636a5d36
JM
3491
3492 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3493 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3494 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3495 }
3496
d5cdfacb
JM
3497 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3498
4c476991
JB
3499 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3500 local_state_change);
636a5d36
JM
3501}
3502
04a773ad
JB
3503static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3504{
4c476991
JB
3505 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3506 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
3507 struct cfg80211_ibss_params ibss;
3508 struct wiphy *wiphy;
fffd0934 3509 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3510 int err;
3511
8e30bc55
JB
3512 memset(&ibss, 0, sizeof(ibss));
3513
04a773ad
JB
3514 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3515 return -EINVAL;
3516
3517 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3518 !info->attrs[NL80211_ATTR_SSID] ||
3519 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3520 return -EINVAL;
3521
8e30bc55
JB
3522 ibss.beacon_interval = 100;
3523
3524 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3525 ibss.beacon_interval =
3526 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3527 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3528 return -EINVAL;
3529 }
3530
4c476991
JB
3531 if (!rdev->ops->join_ibss)
3532 return -EOPNOTSUPP;
04a773ad 3533
4c476991
JB
3534 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3535 return -EOPNOTSUPP;
04a773ad 3536
79c97e97 3537 wiphy = &rdev->wiphy;
04a773ad
JB
3538
3539 if (info->attrs[NL80211_ATTR_MAC])
3540 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3541 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3542 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3543
3544 if (info->attrs[NL80211_ATTR_IE]) {
3545 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3546 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3547 }
3548
3549 ibss.channel = ieee80211_get_channel(wiphy,
3550 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3551 if (!ibss.channel ||
3552 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
3553 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
3554 return -EINVAL;
04a773ad
JB
3555
3556 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3557 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3558
fbd2c8dc
TP
3559 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3560 u8 *rates =
3561 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3562 int n_rates =
3563 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3564 struct ieee80211_supported_band *sband =
3565 wiphy->bands[ibss.channel->band];
3566 int i, j;
3567
4c476991
JB
3568 if (n_rates == 0)
3569 return -EINVAL;
fbd2c8dc
TP
3570
3571 for (i = 0; i < n_rates; i++) {
3572 int rate = (rates[i] & 0x7f) * 5;
3573 bool found = false;
3574
3575 for (j = 0; j < sband->n_bitrates; j++) {
3576 if (sband->bitrates[j].bitrate == rate) {
3577 found = true;
3578 ibss.basic_rates |= BIT(j);
3579 break;
3580 }
3581 }
4c476991
JB
3582 if (!found)
3583 return -EINVAL;
fbd2c8dc 3584 }
fbd2c8dc
TP
3585 }
3586
4c476991
JB
3587 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3588 connkeys = nl80211_parse_connkeys(rdev,
3589 info->attrs[NL80211_ATTR_KEYS]);
3590 if (IS_ERR(connkeys))
3591 return PTR_ERR(connkeys);
3592 }
04a773ad 3593
4c476991 3594 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
3595 if (err)
3596 kfree(connkeys);
04a773ad
JB
3597 return err;
3598}
3599
3600static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3601{
4c476991
JB
3602 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3603 struct net_device *dev = info->user_ptr[1];
04a773ad 3604
4c476991
JB
3605 if (!rdev->ops->leave_ibss)
3606 return -EOPNOTSUPP;
04a773ad 3607
4c476991
JB
3608 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3609 return -EOPNOTSUPP;
04a773ad 3610
4c476991 3611 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3612}
3613
aff89a9b
JB
3614#ifdef CONFIG_NL80211_TESTMODE
3615static struct genl_multicast_group nl80211_testmode_mcgrp = {
3616 .name = "testmode",
3617};
3618
3619static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3620{
4c476991 3621 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
3622 int err;
3623
3624 if (!info->attrs[NL80211_ATTR_TESTDATA])
3625 return -EINVAL;
3626
aff89a9b
JB
3627 err = -EOPNOTSUPP;
3628 if (rdev->ops->testmode_cmd) {
3629 rdev->testmode_info = info;
3630 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3631 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3632 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3633 rdev->testmode_info = NULL;
3634 }
3635
aff89a9b
JB
3636 return err;
3637}
3638
3639static struct sk_buff *
3640__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3641 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3642{
3643 struct sk_buff *skb;
3644 void *hdr;
3645 struct nlattr *data;
3646
3647 skb = nlmsg_new(approxlen + 100, gfp);
3648 if (!skb)
3649 return NULL;
3650
3651 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3652 if (!hdr) {
3653 kfree_skb(skb);
3654 return NULL;
3655 }
3656
3657 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3658 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3659
3660 ((void **)skb->cb)[0] = rdev;
3661 ((void **)skb->cb)[1] = hdr;
3662 ((void **)skb->cb)[2] = data;
3663
3664 return skb;
3665
3666 nla_put_failure:
3667 kfree_skb(skb);
3668 return NULL;
3669}
3670
3671struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3672 int approxlen)
3673{
3674 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3675
3676 if (WARN_ON(!rdev->testmode_info))
3677 return NULL;
3678
3679 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3680 rdev->testmode_info->snd_pid,
3681 rdev->testmode_info->snd_seq,
3682 GFP_KERNEL);
3683}
3684EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3685
3686int cfg80211_testmode_reply(struct sk_buff *skb)
3687{
3688 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3689 void *hdr = ((void **)skb->cb)[1];
3690 struct nlattr *data = ((void **)skb->cb)[2];
3691
3692 if (WARN_ON(!rdev->testmode_info)) {
3693 kfree_skb(skb);
3694 return -EINVAL;
3695 }
3696
3697 nla_nest_end(skb, data);
3698 genlmsg_end(skb, hdr);
3699 return genlmsg_reply(skb, rdev->testmode_info);
3700}
3701EXPORT_SYMBOL(cfg80211_testmode_reply);
3702
3703struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3704 int approxlen, gfp_t gfp)
3705{
3706 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3707
3708 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3709}
3710EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3711
3712void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3713{
3714 void *hdr = ((void **)skb->cb)[1];
3715 struct nlattr *data = ((void **)skb->cb)[2];
3716
3717 nla_nest_end(skb, data);
3718 genlmsg_end(skb, hdr);
3719 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3720}
3721EXPORT_SYMBOL(cfg80211_testmode_event);
3722#endif
3723
b23aa676
SO
3724static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3725{
4c476991
JB
3726 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3727 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
3728 struct cfg80211_connect_params connect;
3729 struct wiphy *wiphy;
fffd0934 3730 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
3731 int err;
3732
3733 memset(&connect, 0, sizeof(connect));
3734
3735 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3736 return -EINVAL;
3737
3738 if (!info->attrs[NL80211_ATTR_SSID] ||
3739 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3740 return -EINVAL;
3741
3742 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3743 connect.auth_type =
3744 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3745 if (!nl80211_valid_auth_type(connect.auth_type))
3746 return -EINVAL;
3747 } else
3748 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3749
3750 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3751
c0692b8f 3752 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 3753 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
3754 if (err)
3755 return err;
b23aa676 3756
074ac8df 3757 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3758 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3759 return -EOPNOTSUPP;
b23aa676 3760
79c97e97 3761 wiphy = &rdev->wiphy;
b23aa676 3762
b23aa676
SO
3763 if (info->attrs[NL80211_ATTR_MAC])
3764 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3765 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3766 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3767
3768 if (info->attrs[NL80211_ATTR_IE]) {
3769 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3770 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3771 }
3772
3773 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3774 connect.channel =
3775 ieee80211_get_channel(wiphy,
3776 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3777 if (!connect.channel ||
4c476991
JB
3778 connect.channel->flags & IEEE80211_CHAN_DISABLED)
3779 return -EINVAL;
b23aa676
SO
3780 }
3781
fffd0934
JB
3782 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3783 connkeys = nl80211_parse_connkeys(rdev,
3784 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
3785 if (IS_ERR(connkeys))
3786 return PTR_ERR(connkeys);
fffd0934
JB
3787 }
3788
3789 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
3790 if (err)
3791 kfree(connkeys);
b23aa676
SO
3792 return err;
3793}
3794
3795static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
3796{
4c476991
JB
3797 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3798 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
3799 u16 reason;
3800
3801 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3802 reason = WLAN_REASON_DEAUTH_LEAVING;
3803 else
3804 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3805
3806 if (reason == 0)
3807 return -EINVAL;
3808
074ac8df 3809 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3810 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3811 return -EOPNOTSUPP;
b23aa676 3812
4c476991 3813 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
3814}
3815
463d0183
JB
3816static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
3817{
4c476991 3818 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
3819 struct net *net;
3820 int err;
3821 u32 pid;
3822
3823 if (!info->attrs[NL80211_ATTR_PID])
3824 return -EINVAL;
3825
3826 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
3827
463d0183 3828 net = get_net_ns_by_pid(pid);
4c476991
JB
3829 if (IS_ERR(net))
3830 return PTR_ERR(net);
463d0183
JB
3831
3832 err = 0;
3833
3834 /* check if anything to do */
4c476991
JB
3835 if (!net_eq(wiphy_net(&rdev->wiphy), net))
3836 err = cfg80211_switch_netns(rdev, net);
463d0183 3837
463d0183 3838 put_net(net);
463d0183
JB
3839 return err;
3840}
3841
67fbb16b
SO
3842static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
3843{
4c476991 3844 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
3845 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
3846 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 3847 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
3848 struct cfg80211_pmksa pmksa;
3849
3850 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
3851
3852 if (!info->attrs[NL80211_ATTR_MAC])
3853 return -EINVAL;
3854
3855 if (!info->attrs[NL80211_ATTR_PMKID])
3856 return -EINVAL;
3857
67fbb16b
SO
3858 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
3859 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3860
074ac8df 3861 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3862 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3863 return -EOPNOTSUPP;
67fbb16b
SO
3864
3865 switch (info->genlhdr->cmd) {
3866 case NL80211_CMD_SET_PMKSA:
3867 rdev_ops = rdev->ops->set_pmksa;
3868 break;
3869 case NL80211_CMD_DEL_PMKSA:
3870 rdev_ops = rdev->ops->del_pmksa;
3871 break;
3872 default:
3873 WARN_ON(1);
3874 break;
3875 }
3876
4c476991
JB
3877 if (!rdev_ops)
3878 return -EOPNOTSUPP;
67fbb16b 3879
4c476991 3880 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
3881}
3882
3883static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
3884{
4c476991
JB
3885 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3886 struct net_device *dev = info->user_ptr[1];
67fbb16b 3887
074ac8df 3888 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3889 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3890 return -EOPNOTSUPP;
67fbb16b 3891
4c476991
JB
3892 if (!rdev->ops->flush_pmksa)
3893 return -EOPNOTSUPP;
67fbb16b 3894
4c476991 3895 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
3896}
3897
9588bbd5
JM
3898static int nl80211_remain_on_channel(struct sk_buff *skb,
3899 struct genl_info *info)
3900{
4c476991
JB
3901 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3902 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
3903 struct ieee80211_channel *chan;
3904 struct sk_buff *msg;
3905 void *hdr;
3906 u64 cookie;
3907 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
3908 u32 freq, duration;
3909 int err;
3910
3911 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3912 !info->attrs[NL80211_ATTR_DURATION])
3913 return -EINVAL;
3914
3915 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
3916
3917 /*
3918 * We should be on that channel for at least one jiffie,
3919 * and more than 5 seconds seems excessive.
3920 */
3921 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
3922 return -EINVAL;
3923
4c476991
JB
3924 if (!rdev->ops->remain_on_channel)
3925 return -EOPNOTSUPP;
9588bbd5 3926
9588bbd5
JM
3927 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
3928 channel_type = nla_get_u32(
3929 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
3930 if (channel_type != NL80211_CHAN_NO_HT &&
3931 channel_type != NL80211_CHAN_HT20 &&
3932 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
3933 channel_type != NL80211_CHAN_HT40MINUS)
3934 return -EINVAL;
9588bbd5
JM
3935 }
3936
3937 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
3938 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
3939 if (chan == NULL)
3940 return -EINVAL;
9588bbd5
JM
3941
3942 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3943 if (!msg)
3944 return -ENOMEM;
9588bbd5
JM
3945
3946 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3947 NL80211_CMD_REMAIN_ON_CHANNEL);
3948
3949 if (IS_ERR(hdr)) {
3950 err = PTR_ERR(hdr);
3951 goto free_msg;
3952 }
3953
3954 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
3955 channel_type, duration, &cookie);
3956
3957 if (err)
3958 goto free_msg;
3959
3960 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
3961
3962 genlmsg_end(msg, hdr);
4c476991
JB
3963
3964 return genlmsg_reply(msg, info);
9588bbd5
JM
3965
3966 nla_put_failure:
3967 err = -ENOBUFS;
3968 free_msg:
3969 nlmsg_free(msg);
9588bbd5
JM
3970 return err;
3971}
3972
3973static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
3974 struct genl_info *info)
3975{
4c476991
JB
3976 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3977 struct net_device *dev = info->user_ptr[1];
9588bbd5 3978 u64 cookie;
9588bbd5
JM
3979
3980 if (!info->attrs[NL80211_ATTR_COOKIE])
3981 return -EINVAL;
3982
4c476991
JB
3983 if (!rdev->ops->cancel_remain_on_channel)
3984 return -EOPNOTSUPP;
9588bbd5 3985
9588bbd5
JM
3986 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
3987
4c476991 3988 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
3989}
3990
13ae75b1
JM
3991static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
3992 u8 *rates, u8 rates_len)
3993{
3994 u8 i;
3995 u32 mask = 0;
3996
3997 for (i = 0; i < rates_len; i++) {
3998 int rate = (rates[i] & 0x7f) * 5;
3999 int ridx;
4000 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4001 struct ieee80211_rate *srate =
4002 &sband->bitrates[ridx];
4003 if (rate == srate->bitrate) {
4004 mask |= 1 << ridx;
4005 break;
4006 }
4007 }
4008 if (ridx == sband->n_bitrates)
4009 return 0; /* rate not found */
4010 }
4011
4012 return mask;
4013}
4014
b54452b0 4015static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4016 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4017 .len = NL80211_MAX_SUPP_RATES },
4018};
4019
4020static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4021 struct genl_info *info)
4022{
4023 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4024 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4025 struct cfg80211_bitrate_mask mask;
4c476991
JB
4026 int rem, i;
4027 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4028 struct nlattr *tx_rates;
4029 struct ieee80211_supported_band *sband;
4030
4031 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4032 return -EINVAL;
4033
4c476991
JB
4034 if (!rdev->ops->set_bitrate_mask)
4035 return -EOPNOTSUPP;
13ae75b1
JM
4036
4037 memset(&mask, 0, sizeof(mask));
4038 /* Default to all rates enabled */
4039 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4040 sband = rdev->wiphy.bands[i];
4041 mask.control[i].legacy =
4042 sband ? (1 << sband->n_bitrates) - 1 : 0;
4043 }
4044
4045 /*
4046 * The nested attribute uses enum nl80211_band as the index. This maps
4047 * directly to the enum ieee80211_band values used in cfg80211.
4048 */
4049 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4050 {
4051 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4052 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4053 return -EINVAL;
13ae75b1 4054 sband = rdev->wiphy.bands[band];
4c476991
JB
4055 if (sband == NULL)
4056 return -EINVAL;
13ae75b1
JM
4057 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4058 nla_len(tx_rates), nl80211_txattr_policy);
4059 if (tb[NL80211_TXRATE_LEGACY]) {
4060 mask.control[band].legacy = rateset_to_mask(
4061 sband,
4062 nla_data(tb[NL80211_TXRATE_LEGACY]),
4063 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4064 if (mask.control[band].legacy == 0)
4065 return -EINVAL;
13ae75b1
JM
4066 }
4067 }
4068
4c476991 4069 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4070}
4071
2e161f78 4072static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4073{
4c476991
JB
4074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4075 struct net_device *dev = info->user_ptr[1];
2e161f78 4076 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4077
4078 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4079 return -EINVAL;
4080
2e161f78
JB
4081 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4082 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4083
9d38d85d 4084 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4085 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4086 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4087 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4088 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4c476991
JB
4089 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4090 return -EOPNOTSUPP;
026331c4
JM
4091
4092 /* not much point in registering if we can't reply */
4c476991
JB
4093 if (!rdev->ops->mgmt_tx)
4094 return -EOPNOTSUPP;
026331c4 4095
4c476991 4096 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4097 frame_type,
026331c4
JM
4098 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4099 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4100}
4101
2e161f78 4102static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4103{
4c476991
JB
4104 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4105 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4106 struct ieee80211_channel *chan;
4107 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4108 bool channel_type_valid = false;
026331c4
JM
4109 u32 freq;
4110 int err;
4111 void *hdr;
4112 u64 cookie;
4113 struct sk_buff *msg;
4114
4115 if (!info->attrs[NL80211_ATTR_FRAME] ||
4116 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4117 return -EINVAL;
4118
4c476991
JB
4119 if (!rdev->ops->mgmt_tx)
4120 return -EOPNOTSUPP;
026331c4 4121
9d38d85d 4122 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4123 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4124 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4125 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4126 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4c476991
JB
4127 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4128 return -EOPNOTSUPP;
026331c4 4129
026331c4
JM
4130 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4131 channel_type = nla_get_u32(
4132 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4133 if (channel_type != NL80211_CHAN_NO_HT &&
4134 channel_type != NL80211_CHAN_HT20 &&
4135 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4136 channel_type != NL80211_CHAN_HT40MINUS)
4137 return -EINVAL;
252aa631 4138 channel_type_valid = true;
026331c4
JM
4139 }
4140
4141 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4142 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4143 if (chan == NULL)
4144 return -EINVAL;
026331c4
JM
4145
4146 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4147 if (!msg)
4148 return -ENOMEM;
026331c4
JM
4149
4150 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4151 NL80211_CMD_FRAME);
026331c4
JM
4152
4153 if (IS_ERR(hdr)) {
4154 err = PTR_ERR(hdr);
4155 goto free_msg;
4156 }
2e161f78
JB
4157 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, channel_type,
4158 channel_type_valid,
4159 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4160 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4161 &cookie);
026331c4
JM
4162 if (err)
4163 goto free_msg;
4164
4165 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4166
4167 genlmsg_end(msg, hdr);
4c476991 4168 return genlmsg_reply(msg, info);
026331c4
JM
4169
4170 nla_put_failure:
4171 err = -ENOBUFS;
4172 free_msg:
4173 nlmsg_free(msg);
026331c4
JM
4174 return err;
4175}
4176
ffb9eb3d
KV
4177static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4178{
4c476991 4179 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4180 struct wireless_dev *wdev;
4c476991 4181 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4182 u8 ps_state;
4183 bool state;
4184 int err;
4185
4c476991
JB
4186 if (!info->attrs[NL80211_ATTR_PS_STATE])
4187 return -EINVAL;
ffb9eb3d
KV
4188
4189 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4190
4c476991
JB
4191 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4192 return -EINVAL;
ffb9eb3d
KV
4193
4194 wdev = dev->ieee80211_ptr;
4195
4c476991
JB
4196 if (!rdev->ops->set_power_mgmt)
4197 return -EOPNOTSUPP;
ffb9eb3d
KV
4198
4199 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4200
4201 if (state == wdev->ps)
4c476991 4202 return 0;
ffb9eb3d 4203
4c476991
JB
4204 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4205 wdev->ps_timeout);
4206 if (!err)
4207 wdev->ps = state;
ffb9eb3d
KV
4208 return err;
4209}
4210
4211static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4212{
4c476991 4213 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4214 enum nl80211_ps_state ps_state;
4215 struct wireless_dev *wdev;
4c476991 4216 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4217 struct sk_buff *msg;
4218 void *hdr;
4219 int err;
4220
ffb9eb3d
KV
4221 wdev = dev->ieee80211_ptr;
4222
4c476991
JB
4223 if (!rdev->ops->set_power_mgmt)
4224 return -EOPNOTSUPP;
ffb9eb3d
KV
4225
4226 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4227 if (!msg)
4228 return -ENOMEM;
ffb9eb3d
KV
4229
4230 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4231 NL80211_CMD_GET_POWER_SAVE);
4232 if (!hdr) {
4c476991 4233 err = -ENOBUFS;
ffb9eb3d
KV
4234 goto free_msg;
4235 }
4236
4237 if (wdev->ps)
4238 ps_state = NL80211_PS_ENABLED;
4239 else
4240 ps_state = NL80211_PS_DISABLED;
4241
4242 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4243
4244 genlmsg_end(msg, hdr);
4c476991 4245 return genlmsg_reply(msg, info);
ffb9eb3d 4246
4c476991 4247 nla_put_failure:
ffb9eb3d 4248 err = -ENOBUFS;
4c476991 4249 free_msg:
ffb9eb3d 4250 nlmsg_free(msg);
ffb9eb3d
KV
4251 return err;
4252}
4253
d6dc1a38
JO
4254static struct nla_policy
4255nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4256 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4257 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4258 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4259};
4260
4261static int nl80211_set_cqm_rssi(struct genl_info *info,
4262 s32 threshold, u32 hysteresis)
4263{
4c476991 4264 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4265 struct wireless_dev *wdev;
4c476991 4266 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4267
4268 if (threshold > 0)
4269 return -EINVAL;
4270
d6dc1a38
JO
4271 wdev = dev->ieee80211_ptr;
4272
4c476991
JB
4273 if (!rdev->ops->set_cqm_rssi_config)
4274 return -EOPNOTSUPP;
d6dc1a38 4275
074ac8df 4276 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4277 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4278 return -EOPNOTSUPP;
d6dc1a38 4279
4c476991
JB
4280 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4281 threshold, hysteresis);
d6dc1a38
JO
4282}
4283
4284static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4285{
4286 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4287 struct nlattr *cqm;
4288 int err;
4289
4290 cqm = info->attrs[NL80211_ATTR_CQM];
4291 if (!cqm) {
4292 err = -EINVAL;
4293 goto out;
4294 }
4295
4296 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4297 nl80211_attr_cqm_policy);
4298 if (err)
4299 goto out;
4300
4301 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4302 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4303 s32 threshold;
4304 u32 hysteresis;
4305 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4306 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4307 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4308 } else
4309 err = -EINVAL;
4310
4311out:
4312 return err;
4313}
4314
4c476991
JB
4315#define NL80211_FLAG_NEED_WIPHY 0x01
4316#define NL80211_FLAG_NEED_NETDEV 0x02
4317#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
4318#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
4319#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
4320 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
4321
4322static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
4323 struct genl_info *info)
4324{
4325 struct cfg80211_registered_device *rdev;
4326 struct net_device *dev;
4327 int err;
4328 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
4329
4330 if (rtnl)
4331 rtnl_lock();
4332
4333 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4334 rdev = cfg80211_get_dev_from_info(info);
4335 if (IS_ERR(rdev)) {
4336 if (rtnl)
4337 rtnl_unlock();
4338 return PTR_ERR(rdev);
4339 }
4340 info->user_ptr[0] = rdev;
4341 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
4342 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4343 if (err) {
4344 if (rtnl)
4345 rtnl_unlock();
4346 return err;
4347 }
41265714
JB
4348 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
4349 !netif_running(dev)) {
4350 if (rtnl)
4351 rtnl_unlock();
4352 return -ENETDOWN;
4353 }
4c476991
JB
4354 info->user_ptr[0] = rdev;
4355 info->user_ptr[1] = dev;
4356 }
4357
4358 return 0;
4359}
4360
4361static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
4362 struct genl_info *info)
4363{
4364 if (info->user_ptr[0])
4365 cfg80211_unlock_rdev(info->user_ptr[0]);
4366 if (info->user_ptr[1])
4367 dev_put(info->user_ptr[1]);
4368 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
4369 rtnl_unlock();
4370}
4371
55682965
JB
4372static struct genl_ops nl80211_ops[] = {
4373 {
4374 .cmd = NL80211_CMD_GET_WIPHY,
4375 .doit = nl80211_get_wiphy,
4376 .dumpit = nl80211_dump_wiphy,
4377 .policy = nl80211_policy,
4378 /* can be retrieved by unprivileged users */
4c476991 4379 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
4380 },
4381 {
4382 .cmd = NL80211_CMD_SET_WIPHY,
4383 .doit = nl80211_set_wiphy,
4384 .policy = nl80211_policy,
4385 .flags = GENL_ADMIN_PERM,
4c476991 4386 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
4387 },
4388 {
4389 .cmd = NL80211_CMD_GET_INTERFACE,
4390 .doit = nl80211_get_interface,
4391 .dumpit = nl80211_dump_interface,
4392 .policy = nl80211_policy,
4393 /* can be retrieved by unprivileged users */
4c476991 4394 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
4395 },
4396 {
4397 .cmd = NL80211_CMD_SET_INTERFACE,
4398 .doit = nl80211_set_interface,
4399 .policy = nl80211_policy,
4400 .flags = GENL_ADMIN_PERM,
4c476991
JB
4401 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4402 NL80211_FLAG_NEED_RTNL,
55682965
JB
4403 },
4404 {
4405 .cmd = NL80211_CMD_NEW_INTERFACE,
4406 .doit = nl80211_new_interface,
4407 .policy = nl80211_policy,
4408 .flags = GENL_ADMIN_PERM,
4c476991
JB
4409 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4410 NL80211_FLAG_NEED_RTNL,
55682965
JB
4411 },
4412 {
4413 .cmd = NL80211_CMD_DEL_INTERFACE,
4414 .doit = nl80211_del_interface,
4415 .policy = nl80211_policy,
41ade00f 4416 .flags = GENL_ADMIN_PERM,
4c476991
JB
4417 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4418 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4419 },
4420 {
4421 .cmd = NL80211_CMD_GET_KEY,
4422 .doit = nl80211_get_key,
4423 .policy = nl80211_policy,
4424 .flags = GENL_ADMIN_PERM,
4c476991
JB
4425 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4426 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4427 },
4428 {
4429 .cmd = NL80211_CMD_SET_KEY,
4430 .doit = nl80211_set_key,
4431 .policy = nl80211_policy,
4432 .flags = GENL_ADMIN_PERM,
41265714 4433 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4434 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4435 },
4436 {
4437 .cmd = NL80211_CMD_NEW_KEY,
4438 .doit = nl80211_new_key,
4439 .policy = nl80211_policy,
4440 .flags = GENL_ADMIN_PERM,
41265714 4441 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4442 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4443 },
4444 {
4445 .cmd = NL80211_CMD_DEL_KEY,
4446 .doit = nl80211_del_key,
4447 .policy = nl80211_policy,
55682965 4448 .flags = GENL_ADMIN_PERM,
41265714 4449 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4450 NL80211_FLAG_NEED_RTNL,
55682965 4451 },
ed1b6cc7
JB
4452 {
4453 .cmd = NL80211_CMD_SET_BEACON,
4454 .policy = nl80211_policy,
4455 .flags = GENL_ADMIN_PERM,
4456 .doit = nl80211_addset_beacon,
4c476991
JB
4457 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4458 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4459 },
4460 {
4461 .cmd = NL80211_CMD_NEW_BEACON,
4462 .policy = nl80211_policy,
4463 .flags = GENL_ADMIN_PERM,
4464 .doit = nl80211_addset_beacon,
4c476991
JB
4465 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4466 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4467 },
4468 {
4469 .cmd = NL80211_CMD_DEL_BEACON,
4470 .policy = nl80211_policy,
4471 .flags = GENL_ADMIN_PERM,
4472 .doit = nl80211_del_beacon,
4c476991
JB
4473 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4474 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 4475 },
5727ef1b
JB
4476 {
4477 .cmd = NL80211_CMD_GET_STATION,
4478 .doit = nl80211_get_station,
2ec600d6 4479 .dumpit = nl80211_dump_station,
5727ef1b 4480 .policy = nl80211_policy,
4c476991
JB
4481 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4482 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4483 },
4484 {
4485 .cmd = NL80211_CMD_SET_STATION,
4486 .doit = nl80211_set_station,
4487 .policy = nl80211_policy,
4488 .flags = GENL_ADMIN_PERM,
4c476991
JB
4489 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4490 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4491 },
4492 {
4493 .cmd = NL80211_CMD_NEW_STATION,
4494 .doit = nl80211_new_station,
4495 .policy = nl80211_policy,
4496 .flags = GENL_ADMIN_PERM,
41265714 4497 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4498 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4499 },
4500 {
4501 .cmd = NL80211_CMD_DEL_STATION,
4502 .doit = nl80211_del_station,
4503 .policy = nl80211_policy,
2ec600d6 4504 .flags = GENL_ADMIN_PERM,
4c476991
JB
4505 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4506 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4507 },
4508 {
4509 .cmd = NL80211_CMD_GET_MPATH,
4510 .doit = nl80211_get_mpath,
4511 .dumpit = nl80211_dump_mpath,
4512 .policy = nl80211_policy,
4513 .flags = GENL_ADMIN_PERM,
41265714 4514 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4515 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4516 },
4517 {
4518 .cmd = NL80211_CMD_SET_MPATH,
4519 .doit = nl80211_set_mpath,
4520 .policy = nl80211_policy,
4521 .flags = GENL_ADMIN_PERM,
41265714 4522 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4523 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4524 },
4525 {
4526 .cmd = NL80211_CMD_NEW_MPATH,
4527 .doit = nl80211_new_mpath,
4528 .policy = nl80211_policy,
4529 .flags = GENL_ADMIN_PERM,
41265714 4530 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4531 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4532 },
4533 {
4534 .cmd = NL80211_CMD_DEL_MPATH,
4535 .doit = nl80211_del_mpath,
4536 .policy = nl80211_policy,
9f1ba906 4537 .flags = GENL_ADMIN_PERM,
4c476991
JB
4538 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4539 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
4540 },
4541 {
4542 .cmd = NL80211_CMD_SET_BSS,
4543 .doit = nl80211_set_bss,
4544 .policy = nl80211_policy,
b2e1b302 4545 .flags = GENL_ADMIN_PERM,
4c476991
JB
4546 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4547 NL80211_FLAG_NEED_RTNL,
b2e1b302 4548 },
f130347c
LR
4549 {
4550 .cmd = NL80211_CMD_GET_REG,
4551 .doit = nl80211_get_reg,
4552 .policy = nl80211_policy,
4553 /* can be retrieved by unprivileged users */
4554 },
b2e1b302
LR
4555 {
4556 .cmd = NL80211_CMD_SET_REG,
4557 .doit = nl80211_set_reg,
4558 .policy = nl80211_policy,
4559 .flags = GENL_ADMIN_PERM,
4560 },
4561 {
4562 .cmd = NL80211_CMD_REQ_SET_REG,
4563 .doit = nl80211_req_set_reg,
4564 .policy = nl80211_policy,
93da9cc1 4565 .flags = GENL_ADMIN_PERM,
4566 },
4567 {
4568 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4569 .doit = nl80211_get_mesh_params,
4570 .policy = nl80211_policy,
4571 /* can be retrieved by unprivileged users */
4c476991
JB
4572 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4573 NL80211_FLAG_NEED_RTNL,
93da9cc1 4574 },
4575 {
4576 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4577 .doit = nl80211_set_mesh_params,
4578 .policy = nl80211_policy,
9aed3cc1 4579 .flags = GENL_ADMIN_PERM,
4c476991
JB
4580 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4581 NL80211_FLAG_NEED_RTNL,
9aed3cc1 4582 },
2a519311
JB
4583 {
4584 .cmd = NL80211_CMD_TRIGGER_SCAN,
4585 .doit = nl80211_trigger_scan,
4586 .policy = nl80211_policy,
4587 .flags = GENL_ADMIN_PERM,
41265714 4588 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4589 NL80211_FLAG_NEED_RTNL,
2a519311
JB
4590 },
4591 {
4592 .cmd = NL80211_CMD_GET_SCAN,
4593 .policy = nl80211_policy,
4594 .dumpit = nl80211_dump_scan,
4595 },
636a5d36
JM
4596 {
4597 .cmd = NL80211_CMD_AUTHENTICATE,
4598 .doit = nl80211_authenticate,
4599 .policy = nl80211_policy,
4600 .flags = GENL_ADMIN_PERM,
41265714 4601 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4602 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
4603 },
4604 {
4605 .cmd = NL80211_CMD_ASSOCIATE,
4606 .doit = nl80211_associate,
4607 .policy = nl80211_policy,
4608 .flags = GENL_ADMIN_PERM,
41265714 4609 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4610 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
4611 },
4612 {
4613 .cmd = NL80211_CMD_DEAUTHENTICATE,
4614 .doit = nl80211_deauthenticate,
4615 .policy = nl80211_policy,
4616 .flags = GENL_ADMIN_PERM,
41265714 4617 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4618 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
4619 },
4620 {
4621 .cmd = NL80211_CMD_DISASSOCIATE,
4622 .doit = nl80211_disassociate,
4623 .policy = nl80211_policy,
4624 .flags = GENL_ADMIN_PERM,
41265714 4625 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4626 NL80211_FLAG_NEED_RTNL,
636a5d36 4627 },
04a773ad
JB
4628 {
4629 .cmd = NL80211_CMD_JOIN_IBSS,
4630 .doit = nl80211_join_ibss,
4631 .policy = nl80211_policy,
4632 .flags = GENL_ADMIN_PERM,
41265714 4633 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4634 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
4635 },
4636 {
4637 .cmd = NL80211_CMD_LEAVE_IBSS,
4638 .doit = nl80211_leave_ibss,
4639 .policy = nl80211_policy,
4640 .flags = GENL_ADMIN_PERM,
41265714 4641 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4642 NL80211_FLAG_NEED_RTNL,
04a773ad 4643 },
aff89a9b
JB
4644#ifdef CONFIG_NL80211_TESTMODE
4645 {
4646 .cmd = NL80211_CMD_TESTMODE,
4647 .doit = nl80211_testmode_do,
4648 .policy = nl80211_policy,
4649 .flags = GENL_ADMIN_PERM,
4c476991
JB
4650 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4651 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
4652 },
4653#endif
b23aa676
SO
4654 {
4655 .cmd = NL80211_CMD_CONNECT,
4656 .doit = nl80211_connect,
4657 .policy = nl80211_policy,
4658 .flags = GENL_ADMIN_PERM,
41265714 4659 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4660 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
4661 },
4662 {
4663 .cmd = NL80211_CMD_DISCONNECT,
4664 .doit = nl80211_disconnect,
4665 .policy = nl80211_policy,
4666 .flags = GENL_ADMIN_PERM,
41265714 4667 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4668 NL80211_FLAG_NEED_RTNL,
b23aa676 4669 },
463d0183
JB
4670 {
4671 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4672 .doit = nl80211_wiphy_netns,
4673 .policy = nl80211_policy,
4674 .flags = GENL_ADMIN_PERM,
4c476991
JB
4675 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4676 NL80211_FLAG_NEED_RTNL,
463d0183 4677 },
61fa713c
HS
4678 {
4679 .cmd = NL80211_CMD_GET_SURVEY,
4680 .policy = nl80211_policy,
4681 .dumpit = nl80211_dump_survey,
4682 },
67fbb16b
SO
4683 {
4684 .cmd = NL80211_CMD_SET_PMKSA,
4685 .doit = nl80211_setdel_pmksa,
4686 .policy = nl80211_policy,
4687 .flags = GENL_ADMIN_PERM,
4c476991
JB
4688 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4689 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
4690 },
4691 {
4692 .cmd = NL80211_CMD_DEL_PMKSA,
4693 .doit = nl80211_setdel_pmksa,
4694 .policy = nl80211_policy,
4695 .flags = GENL_ADMIN_PERM,
4c476991
JB
4696 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4697 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
4698 },
4699 {
4700 .cmd = NL80211_CMD_FLUSH_PMKSA,
4701 .doit = nl80211_flush_pmksa,
4702 .policy = nl80211_policy,
4703 .flags = GENL_ADMIN_PERM,
4c476991
JB
4704 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4705 NL80211_FLAG_NEED_RTNL,
67fbb16b 4706 },
9588bbd5
JM
4707 {
4708 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
4709 .doit = nl80211_remain_on_channel,
4710 .policy = nl80211_policy,
4711 .flags = GENL_ADMIN_PERM,
41265714 4712 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4713 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
4714 },
4715 {
4716 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
4717 .doit = nl80211_cancel_remain_on_channel,
4718 .policy = nl80211_policy,
4719 .flags = GENL_ADMIN_PERM,
41265714 4720 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4721 NL80211_FLAG_NEED_RTNL,
9588bbd5 4722 },
13ae75b1
JM
4723 {
4724 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
4725 .doit = nl80211_set_tx_bitrate_mask,
4726 .policy = nl80211_policy,
4727 .flags = GENL_ADMIN_PERM,
4c476991
JB
4728 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4729 NL80211_FLAG_NEED_RTNL,
13ae75b1 4730 },
026331c4 4731 {
2e161f78
JB
4732 .cmd = NL80211_CMD_REGISTER_FRAME,
4733 .doit = nl80211_register_mgmt,
026331c4
JM
4734 .policy = nl80211_policy,
4735 .flags = GENL_ADMIN_PERM,
4c476991
JB
4736 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4737 NL80211_FLAG_NEED_RTNL,
026331c4
JM
4738 },
4739 {
2e161f78
JB
4740 .cmd = NL80211_CMD_FRAME,
4741 .doit = nl80211_tx_mgmt,
026331c4
JM
4742 .policy = nl80211_policy,
4743 .flags = GENL_ADMIN_PERM,
41265714 4744 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4745 NL80211_FLAG_NEED_RTNL,
026331c4 4746 },
ffb9eb3d
KV
4747 {
4748 .cmd = NL80211_CMD_SET_POWER_SAVE,
4749 .doit = nl80211_set_power_save,
4750 .policy = nl80211_policy,
4751 .flags = GENL_ADMIN_PERM,
4c476991
JB
4752 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4753 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
4754 },
4755 {
4756 .cmd = NL80211_CMD_GET_POWER_SAVE,
4757 .doit = nl80211_get_power_save,
4758 .policy = nl80211_policy,
4759 /* can be retrieved by unprivileged users */
4c476991
JB
4760 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4761 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 4762 },
d6dc1a38
JO
4763 {
4764 .cmd = NL80211_CMD_SET_CQM,
4765 .doit = nl80211_set_cqm,
4766 .policy = nl80211_policy,
4767 .flags = GENL_ADMIN_PERM,
4c476991
JB
4768 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4769 NL80211_FLAG_NEED_RTNL,
d6dc1a38 4770 },
f444de05
JB
4771 {
4772 .cmd = NL80211_CMD_SET_CHANNEL,
4773 .doit = nl80211_set_channel,
4774 .policy = nl80211_policy,
4775 .flags = GENL_ADMIN_PERM,
4c476991
JB
4776 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4777 NL80211_FLAG_NEED_RTNL,
f444de05 4778 },
e8347eba
BJ
4779 {
4780 .cmd = NL80211_CMD_SET_WDS_PEER,
4781 .doit = nl80211_set_wds_peer,
4782 .policy = nl80211_policy,
4783 .flags = GENL_ADMIN_PERM,
4784 },
55682965 4785};
9588bbd5 4786
6039f6d2
JM
4787static struct genl_multicast_group nl80211_mlme_mcgrp = {
4788 .name = "mlme",
4789};
55682965
JB
4790
4791/* multicast groups */
4792static struct genl_multicast_group nl80211_config_mcgrp = {
4793 .name = "config",
4794};
2a519311
JB
4795static struct genl_multicast_group nl80211_scan_mcgrp = {
4796 .name = "scan",
4797};
73d54c9e
LR
4798static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4799 .name = "regulatory",
4800};
55682965
JB
4801
4802/* notification functions */
4803
4804void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4805{
4806 struct sk_buff *msg;
4807
fd2120ca 4808 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
4809 if (!msg)
4810 return;
4811
4812 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4813 nlmsg_free(msg);
4814 return;
4815 }
4816
463d0183
JB
4817 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4818 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
4819}
4820
362a415d
JB
4821static int nl80211_add_scan_req(struct sk_buff *msg,
4822 struct cfg80211_registered_device *rdev)
4823{
4824 struct cfg80211_scan_request *req = rdev->scan_req;
4825 struct nlattr *nest;
4826 int i;
4827
667503dd
JB
4828 ASSERT_RDEV_LOCK(rdev);
4829
362a415d
JB
4830 if (WARN_ON(!req))
4831 return 0;
4832
4833 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4834 if (!nest)
4835 goto nla_put_failure;
4836 for (i = 0; i < req->n_ssids; i++)
4837 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4838 nla_nest_end(msg, nest);
4839
4840 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4841 if (!nest)
4842 goto nla_put_failure;
4843 for (i = 0; i < req->n_channels; i++)
4844 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4845 nla_nest_end(msg, nest);
4846
4847 if (req->ie)
4848 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4849
4850 return 0;
4851 nla_put_failure:
4852 return -ENOBUFS;
4853}
4854
a538e2d5
JB
4855static int nl80211_send_scan_msg(struct sk_buff *msg,
4856 struct cfg80211_registered_device *rdev,
4857 struct net_device *netdev,
4858 u32 pid, u32 seq, int flags,
4859 u32 cmd)
2a519311
JB
4860{
4861 void *hdr;
4862
4863 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4864 if (!hdr)
4865 return -1;
4866
b5850a7a 4867 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
4868 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4869
362a415d
JB
4870 /* ignore errors and send incomplete event anyway */
4871 nl80211_add_scan_req(msg, rdev);
2a519311
JB
4872
4873 return genlmsg_end(msg, hdr);
4874
4875 nla_put_failure:
4876 genlmsg_cancel(msg, hdr);
4877 return -EMSGSIZE;
4878}
4879
a538e2d5
JB
4880void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4881 struct net_device *netdev)
4882{
4883 struct sk_buff *msg;
4884
4885 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4886 if (!msg)
4887 return;
4888
4889 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4890 NL80211_CMD_TRIGGER_SCAN) < 0) {
4891 nlmsg_free(msg);
4892 return;
4893 }
4894
463d0183
JB
4895 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4896 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
4897}
4898
2a519311
JB
4899void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4900 struct net_device *netdev)
4901{
4902 struct sk_buff *msg;
4903
fd2120ca 4904 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4905 if (!msg)
4906 return;
4907
a538e2d5
JB
4908 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4909 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
4910 nlmsg_free(msg);
4911 return;
4912 }
4913
463d0183
JB
4914 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4915 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4916}
4917
4918void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4919 struct net_device *netdev)
4920{
4921 struct sk_buff *msg;
4922
fd2120ca 4923 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4924 if (!msg)
4925 return;
4926
a538e2d5
JB
4927 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4928 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
4929 nlmsg_free(msg);
4930 return;
4931 }
4932
463d0183
JB
4933 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4934 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4935}
4936
73d54c9e
LR
4937/*
4938 * This can happen on global regulatory changes or device specific settings
4939 * based on custom world regulatory domains.
4940 */
4941void nl80211_send_reg_change_event(struct regulatory_request *request)
4942{
4943 struct sk_buff *msg;
4944 void *hdr;
4945
fd2120ca 4946 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
4947 if (!msg)
4948 return;
4949
4950 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4951 if (!hdr) {
4952 nlmsg_free(msg);
4953 return;
4954 }
4955
4956 /* Userspace can always count this one always being set */
4957 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4958
4959 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4960 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4961 NL80211_REGDOM_TYPE_WORLD);
4962 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4963 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4964 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4965 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4966 request->intersect)
4967 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4968 NL80211_REGDOM_TYPE_INTERSECTION);
4969 else {
4970 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4971 NL80211_REGDOM_TYPE_COUNTRY);
4972 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4973 }
4974
4975 if (wiphy_idx_valid(request->wiphy_idx))
4976 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4977
4978 if (genlmsg_end(msg, hdr) < 0) {
4979 nlmsg_free(msg);
4980 return;
4981 }
4982
bc43b28c 4983 rcu_read_lock();
463d0183 4984 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
4985 GFP_ATOMIC);
4986 rcu_read_unlock();
73d54c9e
LR
4987
4988 return;
4989
4990nla_put_failure:
4991 genlmsg_cancel(msg, hdr);
4992 nlmsg_free(msg);
4993}
4994
6039f6d2
JM
4995static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4996 struct net_device *netdev,
4997 const u8 *buf, size_t len,
e6d6e342 4998 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
4999{
5000 struct sk_buff *msg;
5001 void *hdr;
5002
e6d6e342 5003 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5004 if (!msg)
5005 return;
5006
5007 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5008 if (!hdr) {
5009 nlmsg_free(msg);
5010 return;
5011 }
5012
5013 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5014 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5015 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5016
5017 if (genlmsg_end(msg, hdr) < 0) {
5018 nlmsg_free(msg);
5019 return;
5020 }
5021
463d0183
JB
5022 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5023 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5024 return;
5025
5026 nla_put_failure:
5027 genlmsg_cancel(msg, hdr);
5028 nlmsg_free(msg);
5029}
5030
5031void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5032 struct net_device *netdev, const u8 *buf,
5033 size_t len, gfp_t gfp)
6039f6d2
JM
5034{
5035 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5036 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5037}
5038
5039void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5040 struct net_device *netdev, const u8 *buf,
e6d6e342 5041 size_t len, gfp_t gfp)
6039f6d2 5042{
e6d6e342
JB
5043 nl80211_send_mlme_event(rdev, netdev, buf, len,
5044 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5045}
5046
53b46b84 5047void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5048 struct net_device *netdev, const u8 *buf,
5049 size_t len, gfp_t gfp)
6039f6d2
JM
5050{
5051 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5052 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5053}
5054
53b46b84
JM
5055void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5056 struct net_device *netdev, const u8 *buf,
e6d6e342 5057 size_t len, gfp_t gfp)
6039f6d2
JM
5058{
5059 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5060 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5061}
5062
1b06bb40
LR
5063static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5064 struct net_device *netdev, int cmd,
e6d6e342 5065 const u8 *addr, gfp_t gfp)
1965c853
JM
5066{
5067 struct sk_buff *msg;
5068 void *hdr;
5069
e6d6e342 5070 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5071 if (!msg)
5072 return;
5073
5074 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5075 if (!hdr) {
5076 nlmsg_free(msg);
5077 return;
5078 }
5079
5080 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5081 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5082 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5083 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5084
5085 if (genlmsg_end(msg, hdr) < 0) {
5086 nlmsg_free(msg);
5087 return;
5088 }
5089
463d0183
JB
5090 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5091 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5092 return;
5093
5094 nla_put_failure:
5095 genlmsg_cancel(msg, hdr);
5096 nlmsg_free(msg);
5097}
5098
5099void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5100 struct net_device *netdev, const u8 *addr,
5101 gfp_t gfp)
1965c853
JM
5102{
5103 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5104 addr, gfp);
1965c853
JM
5105}
5106
5107void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5108 struct net_device *netdev, const u8 *addr,
5109 gfp_t gfp)
1965c853 5110{
e6d6e342
JB
5111 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5112 addr, gfp);
1965c853
JM
5113}
5114
b23aa676
SO
5115void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5116 struct net_device *netdev, const u8 *bssid,
5117 const u8 *req_ie, size_t req_ie_len,
5118 const u8 *resp_ie, size_t resp_ie_len,
5119 u16 status, gfp_t gfp)
5120{
5121 struct sk_buff *msg;
5122 void *hdr;
5123
5124 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5125 if (!msg)
5126 return;
5127
5128 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5129 if (!hdr) {
5130 nlmsg_free(msg);
5131 return;
5132 }
5133
5134 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5135 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5136 if (bssid)
5137 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5138 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5139 if (req_ie)
5140 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5141 if (resp_ie)
5142 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5143
5144 if (genlmsg_end(msg, hdr) < 0) {
5145 nlmsg_free(msg);
5146 return;
5147 }
5148
463d0183
JB
5149 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5150 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5151 return;
5152
5153 nla_put_failure:
5154 genlmsg_cancel(msg, hdr);
5155 nlmsg_free(msg);
5156
5157}
5158
5159void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5160 struct net_device *netdev, const u8 *bssid,
5161 const u8 *req_ie, size_t req_ie_len,
5162 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5163{
5164 struct sk_buff *msg;
5165 void *hdr;
5166
5167 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5168 if (!msg)
5169 return;
5170
5171 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5172 if (!hdr) {
5173 nlmsg_free(msg);
5174 return;
5175 }
5176
5177 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5178 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5179 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5180 if (req_ie)
5181 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5182 if (resp_ie)
5183 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5184
5185 if (genlmsg_end(msg, hdr) < 0) {
5186 nlmsg_free(msg);
5187 return;
5188 }
5189
463d0183
JB
5190 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5191 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5192 return;
5193
5194 nla_put_failure:
5195 genlmsg_cancel(msg, hdr);
5196 nlmsg_free(msg);
5197
5198}
5199
5200void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5201 struct net_device *netdev, u16 reason,
667503dd 5202 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5203{
5204 struct sk_buff *msg;
5205 void *hdr;
5206
667503dd 5207 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5208 if (!msg)
5209 return;
5210
5211 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5212 if (!hdr) {
5213 nlmsg_free(msg);
5214 return;
5215 }
5216
5217 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5218 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5219 if (from_ap && reason)
5220 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5221 if (from_ap)
5222 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5223 if (ie)
5224 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5225
5226 if (genlmsg_end(msg, hdr) < 0) {
5227 nlmsg_free(msg);
5228 return;
5229 }
5230
463d0183
JB
5231 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5232 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5233 return;
5234
5235 nla_put_failure:
5236 genlmsg_cancel(msg, hdr);
5237 nlmsg_free(msg);
5238
5239}
5240
04a773ad
JB
5241void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5242 struct net_device *netdev, const u8 *bssid,
5243 gfp_t gfp)
5244{
5245 struct sk_buff *msg;
5246 void *hdr;
5247
fd2120ca 5248 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5249 if (!msg)
5250 return;
5251
5252 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5253 if (!hdr) {
5254 nlmsg_free(msg);
5255 return;
5256 }
5257
5258 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5259 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5260 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5261
5262 if (genlmsg_end(msg, hdr) < 0) {
5263 nlmsg_free(msg);
5264 return;
5265 }
5266
463d0183
JB
5267 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5268 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5269 return;
5270
5271 nla_put_failure:
5272 genlmsg_cancel(msg, hdr);
5273 nlmsg_free(msg);
5274}
5275
a3b8b056
JM
5276void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5277 struct net_device *netdev, const u8 *addr,
5278 enum nl80211_key_type key_type, int key_id,
e6d6e342 5279 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5280{
5281 struct sk_buff *msg;
5282 void *hdr;
5283
e6d6e342 5284 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5285 if (!msg)
5286 return;
5287
5288 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5289 if (!hdr) {
5290 nlmsg_free(msg);
5291 return;
5292 }
5293
5294 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5295 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5296 if (addr)
5297 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5298 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5299 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5300 if (tsc)
5301 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5302
5303 if (genlmsg_end(msg, hdr) < 0) {
5304 nlmsg_free(msg);
5305 return;
5306 }
5307
463d0183
JB
5308 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5309 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5310 return;
5311
5312 nla_put_failure:
5313 genlmsg_cancel(msg, hdr);
5314 nlmsg_free(msg);
5315}
5316
6bad8766
LR
5317void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5318 struct ieee80211_channel *channel_before,
5319 struct ieee80211_channel *channel_after)
5320{
5321 struct sk_buff *msg;
5322 void *hdr;
5323 struct nlattr *nl_freq;
5324
fd2120ca 5325 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5326 if (!msg)
5327 return;
5328
5329 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5330 if (!hdr) {
5331 nlmsg_free(msg);
5332 return;
5333 }
5334
5335 /*
5336 * Since we are applying the beacon hint to a wiphy we know its
5337 * wiphy_idx is valid
5338 */
5339 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5340
5341 /* Before */
5342 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5343 if (!nl_freq)
5344 goto nla_put_failure;
5345 if (nl80211_msg_put_channel(msg, channel_before))
5346 goto nla_put_failure;
5347 nla_nest_end(msg, nl_freq);
5348
5349 /* After */
5350 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5351 if (!nl_freq)
5352 goto nla_put_failure;
5353 if (nl80211_msg_put_channel(msg, channel_after))
5354 goto nla_put_failure;
5355 nla_nest_end(msg, nl_freq);
5356
5357 if (genlmsg_end(msg, hdr) < 0) {
5358 nlmsg_free(msg);
5359 return;
5360 }
5361
463d0183
JB
5362 rcu_read_lock();
5363 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5364 GFP_ATOMIC);
5365 rcu_read_unlock();
6bad8766
LR
5366
5367 return;
5368
5369nla_put_failure:
5370 genlmsg_cancel(msg, hdr);
5371 nlmsg_free(msg);
5372}
5373
9588bbd5
JM
5374static void nl80211_send_remain_on_chan_event(
5375 int cmd, struct cfg80211_registered_device *rdev,
5376 struct net_device *netdev, u64 cookie,
5377 struct ieee80211_channel *chan,
5378 enum nl80211_channel_type channel_type,
5379 unsigned int duration, gfp_t gfp)
5380{
5381 struct sk_buff *msg;
5382 void *hdr;
5383
5384 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5385 if (!msg)
5386 return;
5387
5388 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5389 if (!hdr) {
5390 nlmsg_free(msg);
5391 return;
5392 }
5393
5394 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5395 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5396 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5397 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5398 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5399
5400 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5401 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5402
5403 if (genlmsg_end(msg, hdr) < 0) {
5404 nlmsg_free(msg);
5405 return;
5406 }
5407
5408 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5409 nl80211_mlme_mcgrp.id, gfp);
5410 return;
5411
5412 nla_put_failure:
5413 genlmsg_cancel(msg, hdr);
5414 nlmsg_free(msg);
5415}
5416
5417void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5418 struct net_device *netdev, u64 cookie,
5419 struct ieee80211_channel *chan,
5420 enum nl80211_channel_type channel_type,
5421 unsigned int duration, gfp_t gfp)
5422{
5423 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5424 rdev, netdev, cookie, chan,
5425 channel_type, duration, gfp);
5426}
5427
5428void nl80211_send_remain_on_channel_cancel(
5429 struct cfg80211_registered_device *rdev, struct net_device *netdev,
5430 u64 cookie, struct ieee80211_channel *chan,
5431 enum nl80211_channel_type channel_type, gfp_t gfp)
5432{
5433 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5434 rdev, netdev, cookie, chan,
5435 channel_type, 0, gfp);
5436}
5437
98b62183
JB
5438void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5439 struct net_device *dev, const u8 *mac_addr,
5440 struct station_info *sinfo, gfp_t gfp)
5441{
5442 struct sk_buff *msg;
5443
5444 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5445 if (!msg)
5446 return;
5447
5448 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5449 nlmsg_free(msg);
5450 return;
5451 }
5452
5453 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5454 nl80211_mlme_mcgrp.id, gfp);
5455}
5456
2e161f78
JB
5457int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
5458 struct net_device *netdev, u32 nlpid,
5459 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
5460{
5461 struct sk_buff *msg;
5462 void *hdr;
5463 int err;
5464
5465 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5466 if (!msg)
5467 return -ENOMEM;
5468
2e161f78 5469 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
5470 if (!hdr) {
5471 nlmsg_free(msg);
5472 return -ENOMEM;
5473 }
5474
5475 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5476 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5477 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
5478 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5479
5480 err = genlmsg_end(msg, hdr);
5481 if (err < 0) {
5482 nlmsg_free(msg);
5483 return err;
5484 }
5485
5486 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
5487 if (err < 0)
5488 return err;
5489 return 0;
5490
5491 nla_put_failure:
5492 genlmsg_cancel(msg, hdr);
5493 nlmsg_free(msg);
5494 return -ENOBUFS;
5495}
5496
2e161f78
JB
5497void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
5498 struct net_device *netdev, u64 cookie,
5499 const u8 *buf, size_t len, bool ack,
5500 gfp_t gfp)
026331c4
JM
5501{
5502 struct sk_buff *msg;
5503 void *hdr;
5504
5505 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5506 if (!msg)
5507 return;
5508
2e161f78 5509 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
5510 if (!hdr) {
5511 nlmsg_free(msg);
5512 return;
5513 }
5514
5515 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5516 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5517 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5518 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5519 if (ack)
5520 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
5521
5522 if (genlmsg_end(msg, hdr) < 0) {
5523 nlmsg_free(msg);
5524 return;
5525 }
5526
5527 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
5528 return;
5529
5530 nla_put_failure:
5531 genlmsg_cancel(msg, hdr);
5532 nlmsg_free(msg);
5533}
5534
d6dc1a38
JO
5535void
5536nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
5537 struct net_device *netdev,
5538 enum nl80211_cqm_rssi_threshold_event rssi_event,
5539 gfp_t gfp)
5540{
5541 struct sk_buff *msg;
5542 struct nlattr *pinfoattr;
5543 void *hdr;
5544
5545 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5546 if (!msg)
5547 return;
5548
5549 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
5550 if (!hdr) {
5551 nlmsg_free(msg);
5552 return;
5553 }
5554
5555 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5556 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5557
5558 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
5559 if (!pinfoattr)
5560 goto nla_put_failure;
5561
5562 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
5563 rssi_event);
5564
5565 nla_nest_end(msg, pinfoattr);
5566
5567 if (genlmsg_end(msg, hdr) < 0) {
5568 nlmsg_free(msg);
5569 return;
5570 }
5571
5572 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5573 nl80211_mlme_mcgrp.id, gfp);
5574 return;
5575
5576 nla_put_failure:
5577 genlmsg_cancel(msg, hdr);
5578 nlmsg_free(msg);
5579}
5580
026331c4
JM
5581static int nl80211_netlink_notify(struct notifier_block * nb,
5582 unsigned long state,
5583 void *_notify)
5584{
5585 struct netlink_notify *notify = _notify;
5586 struct cfg80211_registered_device *rdev;
5587 struct wireless_dev *wdev;
5588
5589 if (state != NETLINK_URELEASE)
5590 return NOTIFY_DONE;
5591
5592 rcu_read_lock();
5593
5594 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
5595 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 5596 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
5597
5598 rcu_read_unlock();
5599
5600 return NOTIFY_DONE;
5601}
5602
5603static struct notifier_block nl80211_netlink_notifier = {
5604 .notifier_call = nl80211_netlink_notify,
5605};
5606
55682965
JB
5607/* initialisation/exit functions */
5608
5609int nl80211_init(void)
5610{
0d63cbb5 5611 int err;
55682965 5612
0d63cbb5
MM
5613 err = genl_register_family_with_ops(&nl80211_fam,
5614 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
5615 if (err)
5616 return err;
5617
55682965
JB
5618 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
5619 if (err)
5620 goto err_out;
5621
2a519311
JB
5622 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
5623 if (err)
5624 goto err_out;
5625
73d54c9e
LR
5626 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
5627 if (err)
5628 goto err_out;
5629
6039f6d2
JM
5630 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
5631 if (err)
5632 goto err_out;
5633
aff89a9b
JB
5634#ifdef CONFIG_NL80211_TESTMODE
5635 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
5636 if (err)
5637 goto err_out;
5638#endif
5639
026331c4
JM
5640 err = netlink_register_notifier(&nl80211_netlink_notifier);
5641 if (err)
5642 goto err_out;
5643
55682965
JB
5644 return 0;
5645 err_out:
5646 genl_unregister_family(&nl80211_fam);
5647 return err;
5648}
5649
5650void nl80211_exit(void)
5651{
026331c4 5652 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
5653 genl_unregister_family(&nl80211_fam);
5654}