]> git.proxmox.com Git - mirror_ubuntu-hirsute-kernel.git/blame - net/wireless/nl80211.c
mac80211: don't reinit rate control when mesh sta exists
[mirror_ubuntu-hirsute-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
e35e4d28 25#include "rdev-ops.h"
55682965 26
5fb628e9
JM
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
89a54e48
JB
49/* returns ERR_PTR values */
50static struct wireless_dev *
51__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 52{
89a54e48
JB
53 struct cfg80211_registered_device *rdev;
54 struct wireless_dev *result = NULL;
55 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
56 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
57 u64 wdev_id;
58 int wiphy_idx = -1;
59 int ifidx = -1;
55682965 60
89a54e48 61 assert_cfg80211_lock();
55682965 62
89a54e48
JB
63 if (!have_ifidx && !have_wdev_id)
64 return ERR_PTR(-EINVAL);
55682965 65
89a54e48
JB
66 if (have_ifidx)
67 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
68 if (have_wdev_id) {
69 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
70 wiphy_idx = wdev_id >> 32;
55682965
JB
71 }
72
89a54e48
JB
73 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
74 struct wireless_dev *wdev;
75
76 if (wiphy_net(&rdev->wiphy) != netns)
77 continue;
78
79 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
80 continue;
81
82 mutex_lock(&rdev->devlist_mtx);
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
94 mutex_unlock(&rdev->devlist_mtx);
95
96 if (result)
97 break;
98 }
99
100 if (result)
101 return result;
102 return ERR_PTR(-ENODEV);
55682965
JB
103}
104
a9455408 105static struct cfg80211_registered_device *
878d9ec7 106__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 107{
7fee4778
JB
108 struct cfg80211_registered_device *rdev = NULL, *tmp;
109 struct net_device *netdev;
a9455408
JB
110
111 assert_cfg80211_lock();
112
878d9ec7 113 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
114 !attrs[NL80211_ATTR_IFINDEX] &&
115 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
116 return ERR_PTR(-EINVAL);
117
878d9ec7 118 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 119 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 120 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 121
89a54e48
JB
122 if (attrs[NL80211_ATTR_WDEV]) {
123 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
124 struct wireless_dev *wdev;
125 bool found = false;
126
127 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
128 if (tmp) {
129 /* make sure wdev exists */
130 mutex_lock(&tmp->devlist_mtx);
131 list_for_each_entry(wdev, &tmp->wdev_list, list) {
132 if (wdev->identifier != (u32)wdev_id)
133 continue;
134 found = true;
135 break;
136 }
137 mutex_unlock(&tmp->devlist_mtx);
138
139 if (!found)
140 tmp = NULL;
141
142 if (rdev && tmp != rdev)
143 return ERR_PTR(-EINVAL);
144 rdev = tmp;
145 }
146 }
147
878d9ec7
JB
148 if (attrs[NL80211_ATTR_IFINDEX]) {
149 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 150 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
151 if (netdev) {
152 if (netdev->ieee80211_ptr)
153 tmp = wiphy_to_dev(
154 netdev->ieee80211_ptr->wiphy);
155 else
156 tmp = NULL;
157
158 dev_put(netdev);
159
160 /* not wireless device -- return error */
161 if (!tmp)
162 return ERR_PTR(-EINVAL);
163
164 /* mismatch -- return error */
165 if (rdev && tmp != rdev)
166 return ERR_PTR(-EINVAL);
167
168 rdev = tmp;
a9455408 169 }
a9455408 170 }
a9455408 171
4f7eff10
JB
172 if (!rdev)
173 return ERR_PTR(-ENODEV);
a9455408 174
4f7eff10
JB
175 if (netns != wiphy_net(&rdev->wiphy))
176 return ERR_PTR(-ENODEV);
177
178 return rdev;
a9455408
JB
179}
180
181/*
182 * This function returns a pointer to the driver
183 * that the genl_info item that is passed refers to.
184 * If successful, it returns non-NULL and also locks
185 * the driver's mutex!
186 *
187 * This means that you need to call cfg80211_unlock_rdev()
188 * before being allowed to acquire &cfg80211_mutex!
189 *
190 * This is necessary because we need to lock the global
191 * mutex to get an item off the list safely, and then
192 * we lock the rdev mutex so it doesn't go away under us.
193 *
194 * We don't want to keep cfg80211_mutex locked
195 * for all the time in order to allow requests on
196 * other interfaces to go through at the same time.
197 *
198 * The result of this can be a PTR_ERR and hence must
199 * be checked with IS_ERR() for errors.
200 */
201static struct cfg80211_registered_device *
4f7eff10 202cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408
JB
203{
204 struct cfg80211_registered_device *rdev;
205
206 mutex_lock(&cfg80211_mutex);
878d9ec7 207 rdev = __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
208
209 /* if it is not an error we grab the lock on
210 * it to assure it won't be going away while
211 * we operate on it */
212 if (!IS_ERR(rdev))
213 mutex_lock(&rdev->mtx);
214
215 mutex_unlock(&cfg80211_mutex);
216
217 return rdev;
218}
219
55682965 220/* policy for the attributes */
b54452b0 221static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
222 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
223 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 224 .len = 20-1 },
31888487 225 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 226
72bdcf34 227 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 228 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
229 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
230 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
231 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
232
b9a5f8ca
JM
233 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
234 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
235 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
236 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 237 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
238
239 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
240 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
241 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 242
e007b857
EP
243 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
244 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 245
b9454e83 246 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
247 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
248 .len = WLAN_MAX_KEY_LEN },
249 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
250 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
251 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 252 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 253 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
254
255 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
256 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
257 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
258 .len = IEEE80211_MAX_DATA_LEN },
259 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
260 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
261 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
262 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
263 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
264 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
265 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 266 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 267 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 268 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 269 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 270 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 271 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 272
b2e1b302
LR
273 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
274 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
275
9f1ba906
JM
276 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
277 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
278 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
279 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
280 .len = NL80211_MAX_SUPP_RATES },
50b12f59 281 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 282
24bdd9f4 283 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 284 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 285
6c739419 286 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
287
288 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
289 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
290 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
291 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
292 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
293
294 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
295 .len = IEEE80211_MAX_SSID_LEN },
296 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
297 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 298 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 299 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 300 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
301 [NL80211_ATTR_STA_FLAGS2] = {
302 .len = sizeof(struct nl80211_sta_flag_update),
303 },
3f77316c 304 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
305 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
306 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
307 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
308 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
309 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 310 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 311 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
312 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
313 .len = WLAN_PMKID_LEN },
9588bbd5
JM
314 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
315 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 316 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
317 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
318 .len = IEEE80211_MAX_DATA_LEN },
319 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 320 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 321 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 322 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 323 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
324 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
325 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 326 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
327 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
328 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 329 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 330 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 331 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 332 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 333 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 334 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 335 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 336 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 337 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
338 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
339 .len = IEEE80211_MAX_DATA_LEN },
340 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
341 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 342 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 343 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 344 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
345 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
346 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
347 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
348 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
349 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 350 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
351 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
352 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 353 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
354 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
355 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
356 .len = NL80211_HT_CAPABILITY_LEN
357 },
1d9d9213 358 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 359 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 360 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 361 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 362 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 363 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 364 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 365 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
366 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
367 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
55682965
JB
368};
369
e31b8213 370/* policy for the key attributes */
b54452b0 371static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 372 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
373 [NL80211_KEY_IDX] = { .type = NLA_U8 },
374 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 375 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
376 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
377 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 378 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
379 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
380};
381
382/* policy for the key default flags */
383static const struct nla_policy
384nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
385 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
386 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
387};
388
ff1b6e69
JB
389/* policy for WoWLAN attributes */
390static const struct nla_policy
391nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
392 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
393 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
394 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
395 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
396 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
397 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
398 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
399 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
400};
401
e5497d76
JB
402/* policy for GTK rekey offload attributes */
403static const struct nla_policy
404nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
405 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
406 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
407 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
408};
409
a1f1c21c
LC
410static const struct nla_policy
411nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 412 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 413 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 414 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
415};
416
a043897a
HS
417/* ifidx get helper */
418static int nl80211_get_ifidx(struct netlink_callback *cb)
419{
420 int res;
421
422 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
423 nl80211_fam.attrbuf, nl80211_fam.maxattr,
424 nl80211_policy);
425 if (res)
426 return res;
427
428 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
429 return -EINVAL;
430
431 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
432 if (!res)
433 return -EINVAL;
434 return res;
435}
436
67748893
JB
437static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
438 struct netlink_callback *cb,
439 struct cfg80211_registered_device **rdev,
440 struct net_device **dev)
441{
442 int ifidx = cb->args[0];
443 int err;
444
445 if (!ifidx)
446 ifidx = nl80211_get_ifidx(cb);
447 if (ifidx < 0)
448 return ifidx;
449
450 cb->args[0] = ifidx;
451
452 rtnl_lock();
453
454 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
455 if (!*dev) {
456 err = -ENODEV;
457 goto out_rtnl;
458 }
459
460 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
461 if (IS_ERR(*rdev)) {
462 err = PTR_ERR(*rdev);
67748893
JB
463 goto out_rtnl;
464 }
465
466 return 0;
467 out_rtnl:
468 rtnl_unlock();
469 return err;
470}
471
472static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
473{
474 cfg80211_unlock_rdev(rdev);
475 rtnl_unlock();
476}
477
f4a11bb0
JB
478/* IE validation */
479static bool is_valid_ie_attr(const struct nlattr *attr)
480{
481 const u8 *pos;
482 int len;
483
484 if (!attr)
485 return true;
486
487 pos = nla_data(attr);
488 len = nla_len(attr);
489
490 while (len) {
491 u8 elemlen;
492
493 if (len < 2)
494 return false;
495 len -= 2;
496
497 elemlen = pos[1];
498 if (elemlen > len)
499 return false;
500
501 len -= elemlen;
502 pos += 2 + elemlen;
503 }
504
505 return true;
506}
507
55682965 508/* message building helper */
15e47304 509static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
510 int flags, u8 cmd)
511{
512 /* since there is no private header just add the generic one */
15e47304 513 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
514}
515
5dab3b8a
LR
516static int nl80211_msg_put_channel(struct sk_buff *msg,
517 struct ieee80211_channel *chan)
518{
9360ffd1
DM
519 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
520 chan->center_freq))
521 goto nla_put_failure;
5dab3b8a 522
9360ffd1
DM
523 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
524 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
525 goto nla_put_failure;
526 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
527 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
528 goto nla_put_failure;
529 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
530 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
531 goto nla_put_failure;
532 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
533 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
534 goto nla_put_failure;
5dab3b8a 535
9360ffd1
DM
536 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
537 DBM_TO_MBM(chan->max_power)))
538 goto nla_put_failure;
5dab3b8a
LR
539
540 return 0;
541
542 nla_put_failure:
543 return -ENOBUFS;
544}
545
55682965
JB
546/* netlink command implementations */
547
b9454e83
JB
548struct key_parse {
549 struct key_params p;
550 int idx;
e31b8213 551 int type;
b9454e83 552 bool def, defmgmt;
dbd2fd65 553 bool def_uni, def_multi;
b9454e83
JB
554};
555
556static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
557{
558 struct nlattr *tb[NL80211_KEY_MAX + 1];
559 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
560 nl80211_key_policy);
561 if (err)
562 return err;
563
564 k->def = !!tb[NL80211_KEY_DEFAULT];
565 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
566
dbd2fd65
JB
567 if (k->def) {
568 k->def_uni = true;
569 k->def_multi = true;
570 }
571 if (k->defmgmt)
572 k->def_multi = true;
573
b9454e83
JB
574 if (tb[NL80211_KEY_IDX])
575 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
576
577 if (tb[NL80211_KEY_DATA]) {
578 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
579 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
580 }
581
582 if (tb[NL80211_KEY_SEQ]) {
583 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
584 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
585 }
586
587 if (tb[NL80211_KEY_CIPHER])
588 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
589
e31b8213
JB
590 if (tb[NL80211_KEY_TYPE]) {
591 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
592 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
593 return -EINVAL;
594 }
595
dbd2fd65
JB
596 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
597 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
598 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
599 tb[NL80211_KEY_DEFAULT_TYPES],
600 nl80211_key_default_policy);
dbd2fd65
JB
601 if (err)
602 return err;
603
604 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
605 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
606 }
607
b9454e83
JB
608 return 0;
609}
610
611static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
612{
613 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
614 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
615 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
616 }
617
618 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
619 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
620 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
621 }
622
623 if (info->attrs[NL80211_ATTR_KEY_IDX])
624 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
625
626 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
627 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
628
629 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
630 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
631
dbd2fd65
JB
632 if (k->def) {
633 k->def_uni = true;
634 k->def_multi = true;
635 }
636 if (k->defmgmt)
637 k->def_multi = true;
638
e31b8213
JB
639 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
640 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
641 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
642 return -EINVAL;
643 }
644
dbd2fd65
JB
645 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
646 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
647 int err = nla_parse_nested(
648 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
649 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
650 nl80211_key_default_policy);
651 if (err)
652 return err;
653
654 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
655 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
656 }
657
b9454e83
JB
658 return 0;
659}
660
661static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
662{
663 int err;
664
665 memset(k, 0, sizeof(*k));
666 k->idx = -1;
e31b8213 667 k->type = -1;
b9454e83
JB
668
669 if (info->attrs[NL80211_ATTR_KEY])
670 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
671 else
672 err = nl80211_parse_key_old(info, k);
673
674 if (err)
675 return err;
676
677 if (k->def && k->defmgmt)
678 return -EINVAL;
679
dbd2fd65
JB
680 if (k->defmgmt) {
681 if (k->def_uni || !k->def_multi)
682 return -EINVAL;
683 }
684
b9454e83
JB
685 if (k->idx != -1) {
686 if (k->defmgmt) {
687 if (k->idx < 4 || k->idx > 5)
688 return -EINVAL;
689 } else if (k->def) {
690 if (k->idx < 0 || k->idx > 3)
691 return -EINVAL;
692 } else {
693 if (k->idx < 0 || k->idx > 5)
694 return -EINVAL;
695 }
696 }
697
698 return 0;
699}
700
fffd0934
JB
701static struct cfg80211_cached_keys *
702nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 703 struct nlattr *keys, bool *no_ht)
fffd0934
JB
704{
705 struct key_parse parse;
706 struct nlattr *key;
707 struct cfg80211_cached_keys *result;
708 int rem, err, def = 0;
709
710 result = kzalloc(sizeof(*result), GFP_KERNEL);
711 if (!result)
712 return ERR_PTR(-ENOMEM);
713
714 result->def = -1;
715 result->defmgmt = -1;
716
717 nla_for_each_nested(key, keys, rem) {
718 memset(&parse, 0, sizeof(parse));
719 parse.idx = -1;
720
721 err = nl80211_parse_key_new(key, &parse);
722 if (err)
723 goto error;
724 err = -EINVAL;
725 if (!parse.p.key)
726 goto error;
727 if (parse.idx < 0 || parse.idx > 4)
728 goto error;
729 if (parse.def) {
730 if (def)
731 goto error;
732 def = 1;
733 result->def = parse.idx;
dbd2fd65
JB
734 if (!parse.def_uni || !parse.def_multi)
735 goto error;
fffd0934
JB
736 } else if (parse.defmgmt)
737 goto error;
738 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 739 parse.idx, false, NULL);
fffd0934
JB
740 if (err)
741 goto error;
742 result->params[parse.idx].cipher = parse.p.cipher;
743 result->params[parse.idx].key_len = parse.p.key_len;
744 result->params[parse.idx].key = result->data[parse.idx];
745 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
746
747 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
748 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
749 if (no_ht)
750 *no_ht = true;
751 }
fffd0934
JB
752 }
753
754 return result;
755 error:
756 kfree(result);
757 return ERR_PTR(err);
758}
759
760static int nl80211_key_allowed(struct wireless_dev *wdev)
761{
762 ASSERT_WDEV_LOCK(wdev);
763
fffd0934
JB
764 switch (wdev->iftype) {
765 case NL80211_IFTYPE_AP:
766 case NL80211_IFTYPE_AP_VLAN:
074ac8df 767 case NL80211_IFTYPE_P2P_GO:
ff973af7 768 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
769 break;
770 case NL80211_IFTYPE_ADHOC:
771 if (!wdev->current_bss)
772 return -ENOLINK;
773 break;
774 case NL80211_IFTYPE_STATION:
074ac8df 775 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
776 if (wdev->sme_state != CFG80211_SME_CONNECTED)
777 return -ENOLINK;
778 break;
779 default:
780 return -EINVAL;
781 }
782
783 return 0;
784}
785
7527a782
JB
786static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
787{
788 struct nlattr *nl_modes = nla_nest_start(msg, attr);
789 int i;
790
791 if (!nl_modes)
792 goto nla_put_failure;
793
794 i = 0;
795 while (ifmodes) {
9360ffd1
DM
796 if ((ifmodes & 1) && nla_put_flag(msg, i))
797 goto nla_put_failure;
7527a782
JB
798 ifmodes >>= 1;
799 i++;
800 }
801
802 nla_nest_end(msg, nl_modes);
803 return 0;
804
805nla_put_failure:
806 return -ENOBUFS;
807}
808
809static int nl80211_put_iface_combinations(struct wiphy *wiphy,
810 struct sk_buff *msg)
811{
812 struct nlattr *nl_combis;
813 int i, j;
814
815 nl_combis = nla_nest_start(msg,
816 NL80211_ATTR_INTERFACE_COMBINATIONS);
817 if (!nl_combis)
818 goto nla_put_failure;
819
820 for (i = 0; i < wiphy->n_iface_combinations; i++) {
821 const struct ieee80211_iface_combination *c;
822 struct nlattr *nl_combi, *nl_limits;
823
824 c = &wiphy->iface_combinations[i];
825
826 nl_combi = nla_nest_start(msg, i + 1);
827 if (!nl_combi)
828 goto nla_put_failure;
829
830 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
831 if (!nl_limits)
832 goto nla_put_failure;
833
834 for (j = 0; j < c->n_limits; j++) {
835 struct nlattr *nl_limit;
836
837 nl_limit = nla_nest_start(msg, j + 1);
838 if (!nl_limit)
839 goto nla_put_failure;
9360ffd1
DM
840 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
841 c->limits[j].max))
842 goto nla_put_failure;
7527a782
JB
843 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
844 c->limits[j].types))
845 goto nla_put_failure;
846 nla_nest_end(msg, nl_limit);
847 }
848
849 nla_nest_end(msg, nl_limits);
850
9360ffd1
DM
851 if (c->beacon_int_infra_match &&
852 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
853 goto nla_put_failure;
854 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
855 c->num_different_channels) ||
856 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
857 c->max_interfaces))
858 goto nla_put_failure;
7527a782
JB
859
860 nla_nest_end(msg, nl_combi);
861 }
862
863 nla_nest_end(msg, nl_combis);
864
865 return 0;
866nla_put_failure:
867 return -ENOBUFS;
868}
869
15e47304 870static int nl80211_send_wiphy(struct sk_buff *msg, u32 portid, u32 seq, int flags,
55682965
JB
871 struct cfg80211_registered_device *dev)
872{
873 void *hdr;
ee688b00
JB
874 struct nlattr *nl_bands, *nl_band;
875 struct nlattr *nl_freqs, *nl_freq;
876 struct nlattr *nl_rates, *nl_rate;
8fdc621d 877 struct nlattr *nl_cmds;
ee688b00
JB
878 enum ieee80211_band band;
879 struct ieee80211_channel *chan;
880 struct ieee80211_rate *rate;
881 int i;
2e161f78
JB
882 const struct ieee80211_txrx_stypes *mgmt_stypes =
883 dev->wiphy.mgmt_stypes;
55682965 884
15e47304 885 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
55682965
JB
886 if (!hdr)
887 return -1;
888
9360ffd1
DM
889 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
890 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
891 nla_put_u32(msg, NL80211_ATTR_GENERATION,
892 cfg80211_rdev_list_generation) ||
893 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
894 dev->wiphy.retry_short) ||
895 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
896 dev->wiphy.retry_long) ||
897 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
898 dev->wiphy.frag_threshold) ||
899 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
900 dev->wiphy.rts_threshold) ||
901 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
902 dev->wiphy.coverage_class) ||
903 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
904 dev->wiphy.max_scan_ssids) ||
905 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
906 dev->wiphy.max_sched_scan_ssids) ||
907 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
908 dev->wiphy.max_scan_ie_len) ||
909 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
910 dev->wiphy.max_sched_scan_ie_len) ||
911 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
912 dev->wiphy.max_match_sets))
913 goto nla_put_failure;
914
915 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
916 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
917 goto nla_put_failure;
918 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
919 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
920 goto nla_put_failure;
921 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
922 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
923 goto nla_put_failure;
924 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
925 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
926 goto nla_put_failure;
927 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
928 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
929 goto nla_put_failure;
930 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
931 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
932 goto nla_put_failure;
933
934 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
935 sizeof(u32) * dev->wiphy.n_cipher_suites,
936 dev->wiphy.cipher_suites))
937 goto nla_put_failure;
938
939 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
940 dev->wiphy.max_num_pmkids))
941 goto nla_put_failure;
942
943 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
944 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
945 goto nla_put_failure;
946
947 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
948 dev->wiphy.available_antennas_tx) ||
949 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
950 dev->wiphy.available_antennas_rx))
951 goto nla_put_failure;
952
953 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
954 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
955 dev->wiphy.probe_resp_offload))
956 goto nla_put_failure;
87bbbe22 957
7f531e03
BR
958 if ((dev->wiphy.available_antennas_tx ||
959 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
960 u32 tx_ant = 0, rx_ant = 0;
961 int res;
e35e4d28 962 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
afe0cbf8 963 if (!res) {
9360ffd1
DM
964 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
965 tx_ant) ||
966 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
967 rx_ant))
968 goto nla_put_failure;
afe0cbf8
BR
969 }
970 }
971
7527a782
JB
972 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
973 dev->wiphy.interface_modes))
f59ac048
LR
974 goto nla_put_failure;
975
ee688b00
JB
976 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
977 if (!nl_bands)
978 goto nla_put_failure;
979
980 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
981 if (!dev->wiphy.bands[band])
982 continue;
983
984 nl_band = nla_nest_start(msg, band);
985 if (!nl_band)
986 goto nla_put_failure;
987
d51626df 988 /* add HT info */
9360ffd1
DM
989 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
990 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
991 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
992 &dev->wiphy.bands[band]->ht_cap.mcs) ||
993 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
994 dev->wiphy.bands[band]->ht_cap.cap) ||
995 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
996 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
997 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
998 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
999 goto nla_put_failure;
d51626df 1000
bf0c111e
MP
1001 /* add VHT info */
1002 if (dev->wiphy.bands[band]->vht_cap.vht_supported &&
1003 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1004 sizeof(dev->wiphy.bands[band]->vht_cap.vht_mcs),
1005 &dev->wiphy.bands[band]->vht_cap.vht_mcs) ||
1006 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1007 dev->wiphy.bands[band]->vht_cap.cap)))
1008 goto nla_put_failure;
1009
ee688b00
JB
1010 /* add frequencies */
1011 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
1012 if (!nl_freqs)
1013 goto nla_put_failure;
1014
1015 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
1016 nl_freq = nla_nest_start(msg, i);
1017 if (!nl_freq)
1018 goto nla_put_failure;
1019
1020 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
1021
1022 if (nl80211_msg_put_channel(msg, chan))
1023 goto nla_put_failure;
e2f367f2 1024
ee688b00
JB
1025 nla_nest_end(msg, nl_freq);
1026 }
1027
1028 nla_nest_end(msg, nl_freqs);
1029
1030 /* add bitrates */
1031 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1032 if (!nl_rates)
1033 goto nla_put_failure;
1034
1035 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
1036 nl_rate = nla_nest_start(msg, i);
1037 if (!nl_rate)
1038 goto nla_put_failure;
1039
1040 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
1041 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1042 rate->bitrate))
1043 goto nla_put_failure;
1044 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1045 nla_put_flag(msg,
1046 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1047 goto nla_put_failure;
ee688b00
JB
1048
1049 nla_nest_end(msg, nl_rate);
1050 }
1051
1052 nla_nest_end(msg, nl_rates);
1053
1054 nla_nest_end(msg, nl_band);
1055 }
1056 nla_nest_end(msg, nl_bands);
1057
8fdc621d
JB
1058 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1059 if (!nl_cmds)
1060 goto nla_put_failure;
1061
1062 i = 0;
1063#define CMD(op, n) \
1064 do { \
1065 if (dev->ops->op) { \
1066 i++; \
9360ffd1
DM
1067 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1068 goto nla_put_failure; \
8fdc621d
JB
1069 } \
1070 } while (0)
1071
1072 CMD(add_virtual_intf, NEW_INTERFACE);
1073 CMD(change_virtual_intf, SET_INTERFACE);
1074 CMD(add_key, NEW_KEY);
8860020e 1075 CMD(start_ap, START_AP);
8fdc621d
JB
1076 CMD(add_station, NEW_STATION);
1077 CMD(add_mpath, NEW_MPATH);
24bdd9f4 1078 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 1079 CMD(change_bss, SET_BSS);
636a5d36
JM
1080 CMD(auth, AUTHENTICATE);
1081 CMD(assoc, ASSOCIATE);
1082 CMD(deauth, DEAUTHENTICATE);
1083 CMD(disassoc, DISASSOCIATE);
04a773ad 1084 CMD(join_ibss, JOIN_IBSS);
29cbe68c 1085 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
1086 CMD(set_pmksa, SET_PMKSA);
1087 CMD(del_pmksa, DEL_PMKSA);
1088 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
1089 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1090 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 1091 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 1092 CMD(mgmt_tx, FRAME);
f7ca38df 1093 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 1094 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 1095 i++;
9360ffd1
DM
1096 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1097 goto nla_put_failure;
463d0183 1098 }
e8c9bd5b 1099 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 1100 dev->ops->join_mesh) {
aa430da4
JB
1101 i++;
1102 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1103 goto nla_put_failure;
1104 }
e8347eba 1105 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
1106 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1107 CMD(tdls_mgmt, TDLS_MGMT);
1108 CMD(tdls_oper, TDLS_OPER);
1109 }
807f8a8c
LC
1110 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1111 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 1112 CMD(probe_client, PROBE_CLIENT);
1d9d9213 1113 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
1114 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1115 i++;
9360ffd1
DM
1116 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1117 goto nla_put_failure;
5e760230 1118 }
98104fde 1119 CMD(start_p2p_device, START_P2P_DEVICE);
f4e583c8 1120 CMD(set_mcast_rate, SET_MCAST_RATE);
8fdc621d 1121
4745fc09
KV
1122#ifdef CONFIG_NL80211_TESTMODE
1123 CMD(testmode_cmd, TESTMODE);
1124#endif
1125
8fdc621d 1126#undef CMD
b23aa676 1127
6829c878 1128 if (dev->ops->connect || dev->ops->auth) {
b23aa676 1129 i++;
9360ffd1
DM
1130 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1131 goto nla_put_failure;
b23aa676
SO
1132 }
1133
6829c878 1134 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 1135 i++;
9360ffd1
DM
1136 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1137 goto nla_put_failure;
b23aa676
SO
1138 }
1139
8fdc621d
JB
1140 nla_nest_end(msg, nl_cmds);
1141
7c4ef712 1142 if (dev->ops->remain_on_channel &&
9360ffd1
DM
1143 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1144 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1145 dev->wiphy.max_remain_on_channel_duration))
1146 goto nla_put_failure;
a293911d 1147
9360ffd1
DM
1148 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1149 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1150 goto nla_put_failure;
f7ca38df 1151
2e161f78
JB
1152 if (mgmt_stypes) {
1153 u16 stypes;
1154 struct nlattr *nl_ftypes, *nl_ifs;
1155 enum nl80211_iftype ift;
1156
1157 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1158 if (!nl_ifs)
1159 goto nla_put_failure;
1160
1161 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1162 nl_ftypes = nla_nest_start(msg, ift);
1163 if (!nl_ftypes)
1164 goto nla_put_failure;
1165 i = 0;
1166 stypes = mgmt_stypes[ift].tx;
1167 while (stypes) {
9360ffd1
DM
1168 if ((stypes & 1) &&
1169 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1170 (i << 4) | IEEE80211_FTYPE_MGMT))
1171 goto nla_put_failure;
2e161f78
JB
1172 stypes >>= 1;
1173 i++;
1174 }
1175 nla_nest_end(msg, nl_ftypes);
1176 }
1177
74b70a4e
JB
1178 nla_nest_end(msg, nl_ifs);
1179
2e161f78
JB
1180 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1181 if (!nl_ifs)
1182 goto nla_put_failure;
1183
1184 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1185 nl_ftypes = nla_nest_start(msg, ift);
1186 if (!nl_ftypes)
1187 goto nla_put_failure;
1188 i = 0;
1189 stypes = mgmt_stypes[ift].rx;
1190 while (stypes) {
9360ffd1
DM
1191 if ((stypes & 1) &&
1192 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1193 (i << 4) | IEEE80211_FTYPE_MGMT))
1194 goto nla_put_failure;
2e161f78
JB
1195 stypes >>= 1;
1196 i++;
1197 }
1198 nla_nest_end(msg, nl_ftypes);
1199 }
1200 nla_nest_end(msg, nl_ifs);
1201 }
1202
dfb89c56 1203#ifdef CONFIG_PM
ff1b6e69
JB
1204 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1205 struct nlattr *nl_wowlan;
1206
1207 nl_wowlan = nla_nest_start(msg,
1208 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1209 if (!nl_wowlan)
1210 goto nla_put_failure;
1211
9360ffd1
DM
1212 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1213 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1214 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1215 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1216 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1217 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1218 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1219 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1220 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1221 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1222 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1223 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1224 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1225 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1226 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1227 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1228 goto nla_put_failure;
ff1b6e69
JB
1229 if (dev->wiphy.wowlan.n_patterns) {
1230 struct nl80211_wowlan_pattern_support pat = {
1231 .max_patterns = dev->wiphy.wowlan.n_patterns,
1232 .min_pattern_len =
1233 dev->wiphy.wowlan.pattern_min_len,
1234 .max_pattern_len =
1235 dev->wiphy.wowlan.pattern_max_len,
1236 };
9360ffd1
DM
1237 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1238 sizeof(pat), &pat))
1239 goto nla_put_failure;
ff1b6e69
JB
1240 }
1241
1242 nla_nest_end(msg, nl_wowlan);
1243 }
dfb89c56 1244#endif
ff1b6e69 1245
7527a782
JB
1246 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1247 dev->wiphy.software_iftypes))
1248 goto nla_put_failure;
1249
1250 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1251 goto nla_put_failure;
1252
9360ffd1
DM
1253 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1254 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1255 dev->wiphy.ap_sme_capa))
1256 goto nla_put_failure;
562a7480 1257
9360ffd1
DM
1258 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1259 dev->wiphy.features))
1260 goto nla_put_failure;
1f074bd8 1261
9360ffd1
DM
1262 if (dev->wiphy.ht_capa_mod_mask &&
1263 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1264 sizeof(*dev->wiphy.ht_capa_mod_mask),
1265 dev->wiphy.ht_capa_mod_mask))
1266 goto nla_put_failure;
7e7c8926 1267
55682965
JB
1268 return genlmsg_end(msg, hdr);
1269
1270 nla_put_failure:
bc3ed28c
TG
1271 genlmsg_cancel(msg, hdr);
1272 return -EMSGSIZE;
55682965
JB
1273}
1274
1275static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1276{
1277 int idx = 0;
1278 int start = cb->args[0];
1279 struct cfg80211_registered_device *dev;
1280
a1794390 1281 mutex_lock(&cfg80211_mutex);
79c97e97 1282 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1283 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1284 continue;
b4637271 1285 if (++idx <= start)
55682965 1286 continue;
15e47304 1287 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).portid,
55682965 1288 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1289 dev) < 0) {
1290 idx--;
55682965 1291 break;
b4637271 1292 }
55682965 1293 }
a1794390 1294 mutex_unlock(&cfg80211_mutex);
55682965
JB
1295
1296 cb->args[0] = idx;
1297
1298 return skb->len;
1299}
1300
1301static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1302{
1303 struct sk_buff *msg;
4c476991 1304 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1305
fd2120ca 1306 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1307 if (!msg)
4c476991 1308 return -ENOMEM;
55682965 1309
15e47304 1310 if (nl80211_send_wiphy(msg, info->snd_portid, info->snd_seq, 0, dev) < 0) {
4c476991
JB
1311 nlmsg_free(msg);
1312 return -ENOBUFS;
1313 }
55682965 1314
134e6375 1315 return genlmsg_reply(msg, info);
55682965
JB
1316}
1317
31888487
JM
1318static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1319 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1320 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1321 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1322 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1323 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1324};
1325
1326static int parse_txq_params(struct nlattr *tb[],
1327 struct ieee80211_txq_params *txq_params)
1328{
a3304b0a 1329 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1330 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1331 !tb[NL80211_TXQ_ATTR_AIFS])
1332 return -EINVAL;
1333
a3304b0a 1334 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1335 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1336 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1337 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1338 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1339
a3304b0a
JB
1340 if (txq_params->ac >= NL80211_NUM_ACS)
1341 return -EINVAL;
1342
31888487
JM
1343 return 0;
1344}
1345
f444de05
JB
1346static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1347{
1348 /*
cc1d2806
JB
1349 * You can only set the channel explicitly for WDS interfaces,
1350 * all others have their channel managed via their respective
1351 * "establish a connection" command (connect, join, ...)
1352 *
1353 * For AP/GO and mesh mode, the channel can be set with the
1354 * channel userspace API, but is only stored and passed to the
1355 * low-level driver when the AP starts or the mesh is joined.
1356 * This is for backward compatibility, userspace can also give
1357 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1358 *
1359 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1360 * whatever else is going on, so they have their own special
1361 * operation to set the monitor channel if possible.
f444de05
JB
1362 */
1363 return !wdev ||
1364 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1365 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1366 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1367 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1368}
1369
683b6d3b
JB
1370static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1371 struct genl_info *info,
1372 struct cfg80211_chan_def *chandef)
1373{
1374 struct ieee80211_sta_ht_cap *ht_cap;
3d9d1d66
JB
1375 struct ieee80211_sta_vht_cap *vht_cap;
1376 u32 control_freq, width;
683b6d3b
JB
1377
1378 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1379 return -EINVAL;
1380
1381 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1382
1383 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1384 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1385 chandef->center_freq1 = control_freq;
1386 chandef->center_freq2 = 0;
683b6d3b
JB
1387
1388 /* Primary channel not allowed */
1389 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1390 return -EINVAL;
1391
3d9d1d66
JB
1392 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1393 enum nl80211_channel_type chantype;
1394
1395 chantype = nla_get_u32(
1396 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1397
1398 switch (chantype) {
1399 case NL80211_CHAN_NO_HT:
1400 case NL80211_CHAN_HT20:
1401 case NL80211_CHAN_HT40PLUS:
1402 case NL80211_CHAN_HT40MINUS:
1403 cfg80211_chandef_create(chandef, chandef->chan,
1404 chantype);
1405 break;
1406 default:
1407 return -EINVAL;
1408 }
1409 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1410 chandef->width =
1411 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1412 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1413 chandef->center_freq1 =
1414 nla_get_u32(
1415 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1416 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1417 chandef->center_freq2 =
1418 nla_get_u32(
1419 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1420 }
1421
683b6d3b 1422 ht_cap = &rdev->wiphy.bands[chandef->chan->band]->ht_cap;
3d9d1d66 1423 vht_cap = &rdev->wiphy.bands[chandef->chan->band]->vht_cap;
683b6d3b 1424
9f5e8f6e 1425 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1426 return -EINVAL;
1427
1428 switch (chandef->width) {
1429 case NL80211_CHAN_WIDTH_20:
3d9d1d66
JB
1430 case NL80211_CHAN_WIDTH_20_NOHT:
1431 width = 20;
683b6d3b 1432 break;
3d9d1d66
JB
1433 case NL80211_CHAN_WIDTH_40:
1434 width = 40;
3d9d1d66
JB
1435 break;
1436 case NL80211_CHAN_WIDTH_80:
1437 width = 80;
3d9d1d66
JB
1438 break;
1439 case NL80211_CHAN_WIDTH_80P80:
1440 width = 80;
3d9d1d66
JB
1441 break;
1442 case NL80211_CHAN_WIDTH_160:
1443 width = 160;
683b6d3b 1444 break;
3d9d1d66
JB
1445 default:
1446 return -EINVAL;
683b6d3b
JB
1447 }
1448
9f5e8f6e
JB
1449 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1450 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1451 return -EINVAL;
1452
683b6d3b
JB
1453 return 0;
1454}
1455
f444de05
JB
1456static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1457 struct wireless_dev *wdev,
1458 struct genl_info *info)
1459{
683b6d3b 1460 struct cfg80211_chan_def chandef;
f444de05 1461 int result;
e8c9bd5b
JB
1462 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1463
1464 if (wdev)
1465 iftype = wdev->iftype;
f444de05 1466
f444de05
JB
1467 if (!nl80211_can_set_dev_channel(wdev))
1468 return -EOPNOTSUPP;
1469
683b6d3b
JB
1470 result = nl80211_parse_chandef(rdev, info, &chandef);
1471 if (result)
1472 return result;
f444de05
JB
1473
1474 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1475 switch (iftype) {
aa430da4
JB
1476 case NL80211_IFTYPE_AP:
1477 case NL80211_IFTYPE_P2P_GO:
1478 if (wdev->beacon_interval) {
1479 result = -EBUSY;
1480 break;
1481 }
683b6d3b 1482 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1483 result = -EINVAL;
1484 break;
1485 }
683b6d3b 1486 wdev->preset_chandef = chandef;
aa430da4
JB
1487 result = 0;
1488 break;
cc1d2806 1489 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1490 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1491 break;
e8c9bd5b 1492 case NL80211_IFTYPE_MONITOR:
683b6d3b 1493 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1494 break;
aa430da4 1495 default:
e8c9bd5b 1496 result = -EINVAL;
f444de05
JB
1497 }
1498 mutex_unlock(&rdev->devlist_mtx);
1499
1500 return result;
1501}
1502
1503static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1504{
4c476991
JB
1505 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1506 struct net_device *netdev = info->user_ptr[1];
f444de05 1507
4c476991 1508 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1509}
1510
e8347eba
BJ
1511static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1512{
43b19952
JB
1513 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1514 struct net_device *dev = info->user_ptr[1];
1515 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1516 const u8 *bssid;
e8347eba
BJ
1517
1518 if (!info->attrs[NL80211_ATTR_MAC])
1519 return -EINVAL;
1520
43b19952
JB
1521 if (netif_running(dev))
1522 return -EBUSY;
e8347eba 1523
43b19952
JB
1524 if (!rdev->ops->set_wds_peer)
1525 return -EOPNOTSUPP;
e8347eba 1526
43b19952
JB
1527 if (wdev->iftype != NL80211_IFTYPE_WDS)
1528 return -EOPNOTSUPP;
e8347eba
BJ
1529
1530 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1531 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1532}
1533
1534
55682965
JB
1535static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1536{
1537 struct cfg80211_registered_device *rdev;
f444de05
JB
1538 struct net_device *netdev = NULL;
1539 struct wireless_dev *wdev;
a1e567c8 1540 int result = 0, rem_txq_params = 0;
31888487 1541 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1542 u32 changed;
1543 u8 retry_short = 0, retry_long = 0;
1544 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1545 u8 coverage_class = 0;
55682965 1546
f444de05
JB
1547 /*
1548 * Try to find the wiphy and netdev. Normally this
1549 * function shouldn't need the netdev, but this is
1550 * done for backward compatibility -- previously
1551 * setting the channel was done per wiphy, but now
1552 * it is per netdev. Previous userland like hostapd
1553 * also passed a netdev to set_wiphy, so that it is
1554 * possible to let that go to the right netdev!
1555 */
4bbf4d56
JB
1556 mutex_lock(&cfg80211_mutex);
1557
f444de05
JB
1558 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1559 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1560
1561 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1562 if (netdev && netdev->ieee80211_ptr) {
1563 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1564 mutex_lock(&rdev->mtx);
1565 } else
1566 netdev = NULL;
4bbf4d56
JB
1567 }
1568
f444de05 1569 if (!netdev) {
878d9ec7
JB
1570 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1571 info->attrs);
f444de05
JB
1572 if (IS_ERR(rdev)) {
1573 mutex_unlock(&cfg80211_mutex);
4c476991 1574 return PTR_ERR(rdev);
f444de05
JB
1575 }
1576 wdev = NULL;
1577 netdev = NULL;
1578 result = 0;
1579
1580 mutex_lock(&rdev->mtx);
71fe96bf 1581 } else
f444de05 1582 wdev = netdev->ieee80211_ptr;
f444de05
JB
1583
1584 /*
1585 * end workaround code, by now the rdev is available
1586 * and locked, and wdev may or may not be NULL.
1587 */
4bbf4d56
JB
1588
1589 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1590 result = cfg80211_dev_rename(
1591 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1592
1593 mutex_unlock(&cfg80211_mutex);
1594
1595 if (result)
1596 goto bad_res;
31888487
JM
1597
1598 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1599 struct ieee80211_txq_params txq_params;
1600 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1601
1602 if (!rdev->ops->set_txq_params) {
1603 result = -EOPNOTSUPP;
1604 goto bad_res;
1605 }
1606
f70f01c2
EP
1607 if (!netdev) {
1608 result = -EINVAL;
1609 goto bad_res;
1610 }
1611
133a3ff2
JB
1612 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1613 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1614 result = -EINVAL;
1615 goto bad_res;
1616 }
1617
2b5f8b0b
JB
1618 if (!netif_running(netdev)) {
1619 result = -ENETDOWN;
1620 goto bad_res;
1621 }
1622
31888487
JM
1623 nla_for_each_nested(nl_txq_params,
1624 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1625 rem_txq_params) {
1626 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1627 nla_data(nl_txq_params),
1628 nla_len(nl_txq_params),
1629 txq_params_policy);
1630 result = parse_txq_params(tb, &txq_params);
1631 if (result)
1632 goto bad_res;
1633
e35e4d28
HG
1634 result = rdev_set_txq_params(rdev, netdev,
1635 &txq_params);
31888487
JM
1636 if (result)
1637 goto bad_res;
1638 }
1639 }
55682965 1640
72bdcf34 1641 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1642 result = __nl80211_set_channel(rdev,
1643 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1644 info);
72bdcf34
JM
1645 if (result)
1646 goto bad_res;
1647 }
1648
98d2ff8b 1649 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 1650 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
1651 enum nl80211_tx_power_setting type;
1652 int idx, mbm = 0;
1653
c8442118
JB
1654 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
1655 txp_wdev = NULL;
1656
98d2ff8b 1657 if (!rdev->ops->set_tx_power) {
60ea385f 1658 result = -EOPNOTSUPP;
98d2ff8b
JO
1659 goto bad_res;
1660 }
1661
1662 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1663 type = nla_get_u32(info->attrs[idx]);
1664
1665 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1666 (type != NL80211_TX_POWER_AUTOMATIC)) {
1667 result = -EINVAL;
1668 goto bad_res;
1669 }
1670
1671 if (type != NL80211_TX_POWER_AUTOMATIC) {
1672 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1673 mbm = nla_get_u32(info->attrs[idx]);
1674 }
1675
c8442118 1676 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
1677 if (result)
1678 goto bad_res;
1679 }
1680
afe0cbf8
BR
1681 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1682 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1683 u32 tx_ant, rx_ant;
7f531e03
BR
1684 if ((!rdev->wiphy.available_antennas_tx &&
1685 !rdev->wiphy.available_antennas_rx) ||
1686 !rdev->ops->set_antenna) {
afe0cbf8
BR
1687 result = -EOPNOTSUPP;
1688 goto bad_res;
1689 }
1690
1691 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1692 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1693
a7ffac95 1694 /* reject antenna configurations which don't match the
7f531e03
BR
1695 * available antenna masks, except for the "all" mask */
1696 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1697 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1698 result = -EINVAL;
1699 goto bad_res;
1700 }
1701
7f531e03
BR
1702 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1703 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1704
e35e4d28 1705 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
1706 if (result)
1707 goto bad_res;
1708 }
1709
b9a5f8ca
JM
1710 changed = 0;
1711
1712 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1713 retry_short = nla_get_u8(
1714 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1715 if (retry_short == 0) {
1716 result = -EINVAL;
1717 goto bad_res;
1718 }
1719 changed |= WIPHY_PARAM_RETRY_SHORT;
1720 }
1721
1722 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1723 retry_long = nla_get_u8(
1724 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1725 if (retry_long == 0) {
1726 result = -EINVAL;
1727 goto bad_res;
1728 }
1729 changed |= WIPHY_PARAM_RETRY_LONG;
1730 }
1731
1732 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1733 frag_threshold = nla_get_u32(
1734 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1735 if (frag_threshold < 256) {
1736 result = -EINVAL;
1737 goto bad_res;
1738 }
1739 if (frag_threshold != (u32) -1) {
1740 /*
1741 * Fragments (apart from the last one) are required to
1742 * have even length. Make the fragmentation code
1743 * simpler by stripping LSB should someone try to use
1744 * odd threshold value.
1745 */
1746 frag_threshold &= ~0x1;
1747 }
1748 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1749 }
1750
1751 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1752 rts_threshold = nla_get_u32(
1753 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1754 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1755 }
1756
81077e82
LT
1757 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1758 coverage_class = nla_get_u8(
1759 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1760 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1761 }
1762
b9a5f8ca
JM
1763 if (changed) {
1764 u8 old_retry_short, old_retry_long;
1765 u32 old_frag_threshold, old_rts_threshold;
81077e82 1766 u8 old_coverage_class;
b9a5f8ca
JM
1767
1768 if (!rdev->ops->set_wiphy_params) {
1769 result = -EOPNOTSUPP;
1770 goto bad_res;
1771 }
1772
1773 old_retry_short = rdev->wiphy.retry_short;
1774 old_retry_long = rdev->wiphy.retry_long;
1775 old_frag_threshold = rdev->wiphy.frag_threshold;
1776 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1777 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1778
1779 if (changed & WIPHY_PARAM_RETRY_SHORT)
1780 rdev->wiphy.retry_short = retry_short;
1781 if (changed & WIPHY_PARAM_RETRY_LONG)
1782 rdev->wiphy.retry_long = retry_long;
1783 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1784 rdev->wiphy.frag_threshold = frag_threshold;
1785 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1786 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1787 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1788 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 1789
e35e4d28 1790 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
1791 if (result) {
1792 rdev->wiphy.retry_short = old_retry_short;
1793 rdev->wiphy.retry_long = old_retry_long;
1794 rdev->wiphy.frag_threshold = old_frag_threshold;
1795 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1796 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1797 }
1798 }
72bdcf34 1799
306d6112 1800 bad_res:
4bbf4d56 1801 mutex_unlock(&rdev->mtx);
f444de05
JB
1802 if (netdev)
1803 dev_put(netdev);
55682965
JB
1804 return result;
1805}
1806
71bbc994
JB
1807static inline u64 wdev_id(struct wireless_dev *wdev)
1808{
1809 return (u64)wdev->identifier |
1810 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
1811}
55682965 1812
683b6d3b
JB
1813static int nl80211_send_chandef(struct sk_buff *msg,
1814 struct cfg80211_chan_def *chandef)
1815{
9f5e8f6e 1816 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 1817
683b6d3b
JB
1818 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1819 chandef->chan->center_freq))
1820 return -ENOBUFS;
3d9d1d66
JB
1821 switch (chandef->width) {
1822 case NL80211_CHAN_WIDTH_20_NOHT:
1823 case NL80211_CHAN_WIDTH_20:
1824 case NL80211_CHAN_WIDTH_40:
1825 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1826 cfg80211_get_chandef_type(chandef)))
1827 return -ENOBUFS;
1828 break;
1829 default:
1830 break;
1831 }
1832 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
1833 return -ENOBUFS;
1834 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
1835 return -ENOBUFS;
1836 if (chandef->center_freq2 &&
1837 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
1838 return -ENOBUFS;
1839 return 0;
1840}
1841
15e47304 1842static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 1843 struct cfg80211_registered_device *rdev,
72fb2abc 1844 struct wireless_dev *wdev)
55682965 1845{
72fb2abc 1846 struct net_device *dev = wdev->netdev;
55682965
JB
1847 void *hdr;
1848
15e47304 1849 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
1850 if (!hdr)
1851 return -1;
1852
72fb2abc
JB
1853 if (dev &&
1854 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 1855 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
1856 goto nla_put_failure;
1857
1858 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1859 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 1860 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 1861 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
1862 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1863 rdev->devlist_generation ^
1864 (cfg80211_rdev_list_generation << 2)))
1865 goto nla_put_failure;
f5ea9120 1866
5b7ccaf3 1867 if (rdev->ops->get_channel) {
683b6d3b
JB
1868 int ret;
1869 struct cfg80211_chan_def chandef;
1870
1871 ret = rdev_get_channel(rdev, wdev, &chandef);
1872 if (ret == 0) {
1873 if (nl80211_send_chandef(msg, &chandef))
1874 goto nla_put_failure;
1875 }
d91df0e3
PF
1876 }
1877
b84e7a05
AQ
1878 if (wdev->ssid_len) {
1879 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
1880 goto nla_put_failure;
1881 }
1882
55682965
JB
1883 return genlmsg_end(msg, hdr);
1884
1885 nla_put_failure:
bc3ed28c
TG
1886 genlmsg_cancel(msg, hdr);
1887 return -EMSGSIZE;
55682965
JB
1888}
1889
1890static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1891{
1892 int wp_idx = 0;
1893 int if_idx = 0;
1894 int wp_start = cb->args[0];
1895 int if_start = cb->args[1];
f5ea9120 1896 struct cfg80211_registered_device *rdev;
55682965
JB
1897 struct wireless_dev *wdev;
1898
a1794390 1899 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1900 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1901 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1902 continue;
bba95fef
JB
1903 if (wp_idx < wp_start) {
1904 wp_idx++;
55682965 1905 continue;
bba95fef 1906 }
55682965
JB
1907 if_idx = 0;
1908
f5ea9120 1909 mutex_lock(&rdev->devlist_mtx);
89a54e48 1910 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
1911 if (if_idx < if_start) {
1912 if_idx++;
55682965 1913 continue;
bba95fef 1914 }
15e47304 1915 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 1916 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 1917 rdev, wdev) < 0) {
f5ea9120 1918 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1919 goto out;
1920 }
1921 if_idx++;
55682965 1922 }
f5ea9120 1923 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1924
1925 wp_idx++;
55682965 1926 }
bba95fef 1927 out:
a1794390 1928 mutex_unlock(&cfg80211_mutex);
55682965
JB
1929
1930 cb->args[0] = wp_idx;
1931 cb->args[1] = if_idx;
1932
1933 return skb->len;
1934}
1935
1936static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1937{
1938 struct sk_buff *msg;
4c476991 1939 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 1940 struct wireless_dev *wdev = info->user_ptr[1];
55682965 1941
fd2120ca 1942 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1943 if (!msg)
4c476991 1944 return -ENOMEM;
55682965 1945
15e47304 1946 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 1947 dev, wdev) < 0) {
4c476991
JB
1948 nlmsg_free(msg);
1949 return -ENOBUFS;
1950 }
55682965 1951
134e6375 1952 return genlmsg_reply(msg, info);
55682965
JB
1953}
1954
66f7ac50
MW
1955static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1956 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1957 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1958 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1959 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1960 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1961};
1962
1963static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1964{
1965 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1966 int flag;
1967
1968 *mntrflags = 0;
1969
1970 if (!nla)
1971 return -EINVAL;
1972
1973 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1974 nla, mntr_flags_policy))
1975 return -EINVAL;
1976
1977 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1978 if (flags[flag])
1979 *mntrflags |= (1<<flag);
1980
1981 return 0;
1982}
1983
9bc383de 1984static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1985 struct net_device *netdev, u8 use_4addr,
1986 enum nl80211_iftype iftype)
9bc383de 1987{
ad4bb6f8 1988 if (!use_4addr) {
f350a0a8 1989 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1990 return -EBUSY;
9bc383de 1991 return 0;
ad4bb6f8 1992 }
9bc383de
JB
1993
1994 switch (iftype) {
1995 case NL80211_IFTYPE_AP_VLAN:
1996 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1997 return 0;
1998 break;
1999 case NL80211_IFTYPE_STATION:
2000 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2001 return 0;
2002 break;
2003 default:
2004 break;
2005 }
2006
2007 return -EOPNOTSUPP;
2008}
2009
55682965
JB
2010static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2011{
4c476991 2012 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2013 struct vif_params params;
e36d56b6 2014 int err;
04a773ad 2015 enum nl80211_iftype otype, ntype;
4c476991 2016 struct net_device *dev = info->user_ptr[1];
92ffe055 2017 u32 _flags, *flags = NULL;
ac7f9cfa 2018 bool change = false;
55682965 2019
2ec600d6
LCC
2020 memset(&params, 0, sizeof(params));
2021
04a773ad 2022 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2023
723b038d 2024 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2025 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2026 if (otype != ntype)
ac7f9cfa 2027 change = true;
4c476991
JB
2028 if (ntype > NL80211_IFTYPE_MAX)
2029 return -EINVAL;
723b038d
JB
2030 }
2031
92ffe055 2032 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2033 struct wireless_dev *wdev = dev->ieee80211_ptr;
2034
4c476991
JB
2035 if (ntype != NL80211_IFTYPE_MESH_POINT)
2036 return -EINVAL;
29cbe68c
JB
2037 if (netif_running(dev))
2038 return -EBUSY;
2039
2040 wdev_lock(wdev);
2041 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2042 IEEE80211_MAX_MESH_ID_LEN);
2043 wdev->mesh_id_up_len =
2044 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2045 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2046 wdev->mesh_id_up_len);
2047 wdev_unlock(wdev);
2ec600d6
LCC
2048 }
2049
8b787643
FF
2050 if (info->attrs[NL80211_ATTR_4ADDR]) {
2051 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2052 change = true;
ad4bb6f8 2053 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2054 if (err)
4c476991 2055 return err;
8b787643
FF
2056 } else {
2057 params.use_4addr = -1;
2058 }
2059
92ffe055 2060 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2061 if (ntype != NL80211_IFTYPE_MONITOR)
2062 return -EINVAL;
92ffe055
JB
2063 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2064 &_flags);
ac7f9cfa 2065 if (err)
4c476991 2066 return err;
ac7f9cfa
JB
2067
2068 flags = &_flags;
2069 change = true;
92ffe055 2070 }
3b85875a 2071
ac7f9cfa 2072 if (change)
3d54d255 2073 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2074 else
2075 err = 0;
60719ffd 2076
9bc383de
JB
2077 if (!err && params.use_4addr != -1)
2078 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2079
55682965
JB
2080 return err;
2081}
2082
2083static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2084{
4c476991 2085 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2086 struct vif_params params;
84efbb84 2087 struct wireless_dev *wdev;
1c90f9d4 2088 struct sk_buff *msg;
55682965
JB
2089 int err;
2090 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2091 u32 flags;
55682965 2092
2ec600d6
LCC
2093 memset(&params, 0, sizeof(params));
2094
55682965
JB
2095 if (!info->attrs[NL80211_ATTR_IFNAME])
2096 return -EINVAL;
2097
2098 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2099 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2100 if (type > NL80211_IFTYPE_MAX)
2101 return -EINVAL;
2102 }
2103
79c97e97 2104 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2105 !(rdev->wiphy.interface_modes & (1 << type)))
2106 return -EOPNOTSUPP;
55682965 2107
9bc383de 2108 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2109 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2110 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2111 if (err)
4c476991 2112 return err;
9bc383de 2113 }
8b787643 2114
1c90f9d4
JB
2115 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2116 if (!msg)
2117 return -ENOMEM;
2118
66f7ac50
MW
2119 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2120 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2121 &flags);
e35e4d28
HG
2122 wdev = rdev_add_virtual_intf(rdev,
2123 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2124 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2125 if (IS_ERR(wdev)) {
2126 nlmsg_free(msg);
84efbb84 2127 return PTR_ERR(wdev);
1c90f9d4 2128 }
2ec600d6 2129
98104fde
JB
2130 switch (type) {
2131 case NL80211_IFTYPE_MESH_POINT:
2132 if (!info->attrs[NL80211_ATTR_MESH_ID])
2133 break;
29cbe68c
JB
2134 wdev_lock(wdev);
2135 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2136 IEEE80211_MAX_MESH_ID_LEN);
2137 wdev->mesh_id_up_len =
2138 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2139 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2140 wdev->mesh_id_up_len);
2141 wdev_unlock(wdev);
98104fde
JB
2142 break;
2143 case NL80211_IFTYPE_P2P_DEVICE:
2144 /*
2145 * P2P Device doesn't have a netdev, so doesn't go
2146 * through the netdev notifier and must be added here
2147 */
2148 mutex_init(&wdev->mtx);
2149 INIT_LIST_HEAD(&wdev->event_list);
2150 spin_lock_init(&wdev->event_lock);
2151 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2152 spin_lock_init(&wdev->mgmt_registrations_lock);
2153
2154 mutex_lock(&rdev->devlist_mtx);
2155 wdev->identifier = ++rdev->wdev_id;
2156 list_add_rcu(&wdev->list, &rdev->wdev_list);
2157 rdev->devlist_generation++;
2158 mutex_unlock(&rdev->devlist_mtx);
2159 break;
2160 default:
2161 break;
29cbe68c
JB
2162 }
2163
15e47304 2164 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2165 rdev, wdev) < 0) {
2166 nlmsg_free(msg);
2167 return -ENOBUFS;
2168 }
2169
2170 return genlmsg_reply(msg, info);
55682965
JB
2171}
2172
2173static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2174{
4c476991 2175 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2176 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2177
4c476991
JB
2178 if (!rdev->ops->del_virtual_intf)
2179 return -EOPNOTSUPP;
55682965 2180
84efbb84
JB
2181 /*
2182 * If we remove a wireless device without a netdev then clear
2183 * user_ptr[1] so that nl80211_post_doit won't dereference it
2184 * to check if it needs to do dev_put(). Otherwise it crashes
2185 * since the wdev has been freed, unlike with a netdev where
2186 * we need the dev_put() for the netdev to really be freed.
2187 */
2188 if (!wdev->netdev)
2189 info->user_ptr[1] = NULL;
2190
e35e4d28 2191 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2192}
2193
1d9d9213
SW
2194static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2195{
2196 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2197 struct net_device *dev = info->user_ptr[1];
2198 u16 noack_map;
2199
2200 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2201 return -EINVAL;
2202
2203 if (!rdev->ops->set_noack_map)
2204 return -EOPNOTSUPP;
2205
2206 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2207
e35e4d28 2208 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2209}
2210
41ade00f
JB
2211struct get_key_cookie {
2212 struct sk_buff *msg;
2213 int error;
b9454e83 2214 int idx;
41ade00f
JB
2215};
2216
2217static void get_key_callback(void *c, struct key_params *params)
2218{
b9454e83 2219 struct nlattr *key;
41ade00f
JB
2220 struct get_key_cookie *cookie = c;
2221
9360ffd1
DM
2222 if ((params->key &&
2223 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2224 params->key_len, params->key)) ||
2225 (params->seq &&
2226 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2227 params->seq_len, params->seq)) ||
2228 (params->cipher &&
2229 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2230 params->cipher)))
2231 goto nla_put_failure;
41ade00f 2232
b9454e83
JB
2233 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2234 if (!key)
2235 goto nla_put_failure;
2236
9360ffd1
DM
2237 if ((params->key &&
2238 nla_put(cookie->msg, NL80211_KEY_DATA,
2239 params->key_len, params->key)) ||
2240 (params->seq &&
2241 nla_put(cookie->msg, NL80211_KEY_SEQ,
2242 params->seq_len, params->seq)) ||
2243 (params->cipher &&
2244 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2245 params->cipher)))
2246 goto nla_put_failure;
b9454e83 2247
9360ffd1
DM
2248 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2249 goto nla_put_failure;
b9454e83
JB
2250
2251 nla_nest_end(cookie->msg, key);
2252
41ade00f
JB
2253 return;
2254 nla_put_failure:
2255 cookie->error = 1;
2256}
2257
2258static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2259{
4c476991 2260 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2261 int err;
4c476991 2262 struct net_device *dev = info->user_ptr[1];
41ade00f 2263 u8 key_idx = 0;
e31b8213
JB
2264 const u8 *mac_addr = NULL;
2265 bool pairwise;
41ade00f
JB
2266 struct get_key_cookie cookie = {
2267 .error = 0,
2268 };
2269 void *hdr;
2270 struct sk_buff *msg;
2271
2272 if (info->attrs[NL80211_ATTR_KEY_IDX])
2273 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2274
3cfcf6ac 2275 if (key_idx > 5)
41ade00f
JB
2276 return -EINVAL;
2277
2278 if (info->attrs[NL80211_ATTR_MAC])
2279 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2280
e31b8213
JB
2281 pairwise = !!mac_addr;
2282 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2283 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2284 if (kt >= NUM_NL80211_KEYTYPES)
2285 return -EINVAL;
2286 if (kt != NL80211_KEYTYPE_GROUP &&
2287 kt != NL80211_KEYTYPE_PAIRWISE)
2288 return -EINVAL;
2289 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2290 }
2291
4c476991
JB
2292 if (!rdev->ops->get_key)
2293 return -EOPNOTSUPP;
41ade00f 2294
fd2120ca 2295 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2296 if (!msg)
2297 return -ENOMEM;
41ade00f 2298
15e47304 2299 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2300 NL80211_CMD_NEW_KEY);
4c476991
JB
2301 if (IS_ERR(hdr))
2302 return PTR_ERR(hdr);
41ade00f
JB
2303
2304 cookie.msg = msg;
b9454e83 2305 cookie.idx = key_idx;
41ade00f 2306
9360ffd1
DM
2307 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2308 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2309 goto nla_put_failure;
2310 if (mac_addr &&
2311 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2312 goto nla_put_failure;
41ade00f 2313
e31b8213
JB
2314 if (pairwise && mac_addr &&
2315 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2316 return -ENOENT;
2317
e35e4d28
HG
2318 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2319 get_key_callback);
41ade00f
JB
2320
2321 if (err)
6c95e2a2 2322 goto free_msg;
41ade00f
JB
2323
2324 if (cookie.error)
2325 goto nla_put_failure;
2326
2327 genlmsg_end(msg, hdr);
4c476991 2328 return genlmsg_reply(msg, info);
41ade00f
JB
2329
2330 nla_put_failure:
2331 err = -ENOBUFS;
6c95e2a2 2332 free_msg:
41ade00f 2333 nlmsg_free(msg);
41ade00f
JB
2334 return err;
2335}
2336
2337static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2338{
4c476991 2339 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2340 struct key_parse key;
41ade00f 2341 int err;
4c476991 2342 struct net_device *dev = info->user_ptr[1];
41ade00f 2343
b9454e83
JB
2344 err = nl80211_parse_key(info, &key);
2345 if (err)
2346 return err;
41ade00f 2347
b9454e83 2348 if (key.idx < 0)
41ade00f
JB
2349 return -EINVAL;
2350
b9454e83
JB
2351 /* only support setting default key */
2352 if (!key.def && !key.defmgmt)
41ade00f
JB
2353 return -EINVAL;
2354
dbd2fd65 2355 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2356
dbd2fd65
JB
2357 if (key.def) {
2358 if (!rdev->ops->set_default_key) {
2359 err = -EOPNOTSUPP;
2360 goto out;
2361 }
41ade00f 2362
dbd2fd65
JB
2363 err = nl80211_key_allowed(dev->ieee80211_ptr);
2364 if (err)
2365 goto out;
2366
e35e4d28 2367 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2368 key.def_uni, key.def_multi);
2369
2370 if (err)
2371 goto out;
fffd0934 2372
3d23e349 2373#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2374 dev->ieee80211_ptr->wext.default_key = key.idx;
2375#endif
2376 } else {
2377 if (key.def_uni || !key.def_multi) {
2378 err = -EINVAL;
2379 goto out;
2380 }
2381
2382 if (!rdev->ops->set_default_mgmt_key) {
2383 err = -EOPNOTSUPP;
2384 goto out;
2385 }
2386
2387 err = nl80211_key_allowed(dev->ieee80211_ptr);
2388 if (err)
2389 goto out;
2390
e35e4d28 2391 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2392 if (err)
2393 goto out;
2394
2395#ifdef CONFIG_CFG80211_WEXT
2396 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2397#endif
dbd2fd65
JB
2398 }
2399
2400 out:
fffd0934 2401 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2402
41ade00f
JB
2403 return err;
2404}
2405
2406static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2407{
4c476991 2408 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2409 int err;
4c476991 2410 struct net_device *dev = info->user_ptr[1];
b9454e83 2411 struct key_parse key;
e31b8213 2412 const u8 *mac_addr = NULL;
41ade00f 2413
b9454e83
JB
2414 err = nl80211_parse_key(info, &key);
2415 if (err)
2416 return err;
41ade00f 2417
b9454e83 2418 if (!key.p.key)
41ade00f
JB
2419 return -EINVAL;
2420
41ade00f
JB
2421 if (info->attrs[NL80211_ATTR_MAC])
2422 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2423
e31b8213
JB
2424 if (key.type == -1) {
2425 if (mac_addr)
2426 key.type = NL80211_KEYTYPE_PAIRWISE;
2427 else
2428 key.type = NL80211_KEYTYPE_GROUP;
2429 }
2430
2431 /* for now */
2432 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2433 key.type != NL80211_KEYTYPE_GROUP)
2434 return -EINVAL;
2435
4c476991
JB
2436 if (!rdev->ops->add_key)
2437 return -EOPNOTSUPP;
25e47c18 2438
e31b8213
JB
2439 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2440 key.type == NL80211_KEYTYPE_PAIRWISE,
2441 mac_addr))
4c476991 2442 return -EINVAL;
41ade00f 2443
fffd0934
JB
2444 wdev_lock(dev->ieee80211_ptr);
2445 err = nl80211_key_allowed(dev->ieee80211_ptr);
2446 if (!err)
e35e4d28
HG
2447 err = rdev_add_key(rdev, dev, key.idx,
2448 key.type == NL80211_KEYTYPE_PAIRWISE,
2449 mac_addr, &key.p);
fffd0934 2450 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2451
41ade00f
JB
2452 return err;
2453}
2454
2455static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2456{
4c476991 2457 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2458 int err;
4c476991 2459 struct net_device *dev = info->user_ptr[1];
41ade00f 2460 u8 *mac_addr = NULL;
b9454e83 2461 struct key_parse key;
41ade00f 2462
b9454e83
JB
2463 err = nl80211_parse_key(info, &key);
2464 if (err)
2465 return err;
41ade00f
JB
2466
2467 if (info->attrs[NL80211_ATTR_MAC])
2468 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2469
e31b8213
JB
2470 if (key.type == -1) {
2471 if (mac_addr)
2472 key.type = NL80211_KEYTYPE_PAIRWISE;
2473 else
2474 key.type = NL80211_KEYTYPE_GROUP;
2475 }
2476
2477 /* for now */
2478 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2479 key.type != NL80211_KEYTYPE_GROUP)
2480 return -EINVAL;
2481
4c476991
JB
2482 if (!rdev->ops->del_key)
2483 return -EOPNOTSUPP;
41ade00f 2484
fffd0934
JB
2485 wdev_lock(dev->ieee80211_ptr);
2486 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2487
2488 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2489 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2490 err = -ENOENT;
2491
fffd0934 2492 if (!err)
e35e4d28
HG
2493 err = rdev_del_key(rdev, dev, key.idx,
2494 key.type == NL80211_KEYTYPE_PAIRWISE,
2495 mac_addr);
41ade00f 2496
3d23e349 2497#ifdef CONFIG_CFG80211_WEXT
08645126 2498 if (!err) {
b9454e83 2499 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2500 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2501 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2502 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2503 }
2504#endif
fffd0934 2505 wdev_unlock(dev->ieee80211_ptr);
08645126 2506
41ade00f
JB
2507 return err;
2508}
2509
8860020e
JB
2510static int nl80211_parse_beacon(struct genl_info *info,
2511 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2512{
8860020e 2513 bool haveinfo = false;
ed1b6cc7 2514
9946ecfb
JM
2515 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2516 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2517 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2518 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2519 return -EINVAL;
2520
8860020e 2521 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2522
ed1b6cc7 2523 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2524 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2525 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2526 if (!bcn->head_len)
2527 return -EINVAL;
2528 haveinfo = true;
ed1b6cc7
JB
2529 }
2530
2531 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2532 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2533 bcn->tail_len =
ed1b6cc7 2534 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2535 haveinfo = true;
ed1b6cc7
JB
2536 }
2537
4c476991
JB
2538 if (!haveinfo)
2539 return -EINVAL;
3b85875a 2540
9946ecfb 2541 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2542 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2543 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2544 }
2545
2546 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2547 bcn->proberesp_ies =
9946ecfb 2548 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2549 bcn->proberesp_ies_len =
9946ecfb
JM
2550 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2551 }
2552
2553 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2554 bcn->assocresp_ies =
9946ecfb 2555 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2556 bcn->assocresp_ies_len =
9946ecfb
JM
2557 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2558 }
2559
00f740e1 2560 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2561 bcn->probe_resp =
00f740e1 2562 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2563 bcn->probe_resp_len =
00f740e1
AN
2564 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2565 }
2566
8860020e
JB
2567 return 0;
2568}
2569
46c1dd0c
FF
2570static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2571 struct cfg80211_ap_settings *params)
2572{
2573 struct wireless_dev *wdev;
2574 bool ret = false;
2575
2576 mutex_lock(&rdev->devlist_mtx);
2577
89a54e48 2578 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2579 if (wdev->iftype != NL80211_IFTYPE_AP &&
2580 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2581 continue;
2582
683b6d3b 2583 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
2584 continue;
2585
683b6d3b 2586 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
2587 ret = true;
2588 break;
2589 }
2590
2591 mutex_unlock(&rdev->devlist_mtx);
2592
2593 return ret;
2594}
2595
e39e5b5e
JM
2596static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
2597 enum nl80211_auth_type auth_type,
2598 enum nl80211_commands cmd)
2599{
2600 if (auth_type > NL80211_AUTHTYPE_MAX)
2601 return false;
2602
2603 switch (cmd) {
2604 case NL80211_CMD_AUTHENTICATE:
2605 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
2606 auth_type == NL80211_AUTHTYPE_SAE)
2607 return false;
2608 return true;
2609 case NL80211_CMD_CONNECT:
2610 case NL80211_CMD_START_AP:
2611 /* SAE not supported yet */
2612 if (auth_type == NL80211_AUTHTYPE_SAE)
2613 return false;
2614 return true;
2615 default:
2616 return false;
2617 }
2618}
2619
8860020e
JB
2620static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2621{
2622 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2623 struct net_device *dev = info->user_ptr[1];
2624 struct wireless_dev *wdev = dev->ieee80211_ptr;
2625 struct cfg80211_ap_settings params;
2626 int err;
2627
2628 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2629 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2630 return -EOPNOTSUPP;
2631
2632 if (!rdev->ops->start_ap)
2633 return -EOPNOTSUPP;
2634
2635 if (wdev->beacon_interval)
2636 return -EALREADY;
2637
2638 memset(&params, 0, sizeof(params));
2639
2640 /* these are required for START_AP */
2641 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2642 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2643 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2644 return -EINVAL;
2645
2646 err = nl80211_parse_beacon(info, &params.beacon);
2647 if (err)
2648 return err;
2649
2650 params.beacon_interval =
2651 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2652 params.dtim_period =
2653 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2654
2655 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2656 if (err)
2657 return err;
2658
2659 /*
2660 * In theory, some of these attributes should be required here
2661 * but since they were not used when the command was originally
2662 * added, keep them optional for old user space programs to let
2663 * them continue to work with drivers that do not need the
2664 * additional information -- drivers must check!
2665 */
2666 if (info->attrs[NL80211_ATTR_SSID]) {
2667 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2668 params.ssid_len =
2669 nla_len(info->attrs[NL80211_ATTR_SSID]);
2670 if (params.ssid_len == 0 ||
2671 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2672 return -EINVAL;
2673 }
2674
2675 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2676 params.hidden_ssid = nla_get_u32(
2677 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2678 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2679 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2680 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2681 return -EINVAL;
2682 }
2683
2684 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2685
2686 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2687 params.auth_type = nla_get_u32(
2688 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
2689 if (!nl80211_valid_auth_type(rdev, params.auth_type,
2690 NL80211_CMD_START_AP))
8860020e
JB
2691 return -EINVAL;
2692 } else
2693 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2694
2695 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2696 NL80211_MAX_NR_CIPHER_SUITES);
2697 if (err)
2698 return err;
2699
1b658f11
VT
2700 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2701 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2702 return -EOPNOTSUPP;
2703 params.inactivity_timeout = nla_get_u16(
2704 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2705 }
2706
53cabad7
JB
2707 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
2708 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2709 return -EINVAL;
2710 params.p2p_ctwindow =
2711 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
2712 if (params.p2p_ctwindow > 127)
2713 return -EINVAL;
2714 if (params.p2p_ctwindow != 0 &&
2715 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
2716 return -EINVAL;
2717 }
2718
2719 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
2720 u8 tmp;
2721
2722 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2723 return -EINVAL;
2724 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
2725 if (tmp > 1)
2726 return -EINVAL;
2727 params.p2p_opp_ps = tmp;
2728 if (params.p2p_opp_ps != 0 &&
2729 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
2730 return -EINVAL;
2731 }
2732
aa430da4 2733 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
2734 err = nl80211_parse_chandef(rdev, info, &params.chandef);
2735 if (err)
2736 return err;
2737 } else if (wdev->preset_chandef.chan) {
2738 params.chandef = wdev->preset_chandef;
46c1dd0c 2739 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
2740 return -EINVAL;
2741
683b6d3b 2742 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
2743 return -EINVAL;
2744
e4e32459 2745 mutex_lock(&rdev->devlist_mtx);
683b6d3b 2746 err = cfg80211_can_use_chan(rdev, wdev, params.chandef.chan,
e4e32459
MK
2747 CHAN_MODE_SHARED);
2748 mutex_unlock(&rdev->devlist_mtx);
2749
2750 if (err)
2751 return err;
2752
e35e4d28 2753 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 2754 if (!err) {
683b6d3b 2755 wdev->preset_chandef = params.chandef;
8860020e 2756 wdev->beacon_interval = params.beacon_interval;
683b6d3b 2757 wdev->channel = params.chandef.chan;
06e191e2
AQ
2758 wdev->ssid_len = params.ssid_len;
2759 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 2760 }
56d1893d 2761 return err;
ed1b6cc7
JB
2762}
2763
8860020e
JB
2764static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2765{
2766 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2767 struct net_device *dev = info->user_ptr[1];
2768 struct wireless_dev *wdev = dev->ieee80211_ptr;
2769 struct cfg80211_beacon_data params;
2770 int err;
2771
2772 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2773 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2774 return -EOPNOTSUPP;
2775
2776 if (!rdev->ops->change_beacon)
2777 return -EOPNOTSUPP;
2778
2779 if (!wdev->beacon_interval)
2780 return -EINVAL;
2781
2782 err = nl80211_parse_beacon(info, &params);
2783 if (err)
2784 return err;
2785
e35e4d28 2786 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
2787}
2788
2789static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2790{
4c476991
JB
2791 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2792 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 2793
60771780 2794 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
2795}
2796
5727ef1b
JB
2797static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2798 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2799 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2800 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2801 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2802 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2803 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2804};
2805
eccb8e8f 2806static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2807 enum nl80211_iftype iftype,
eccb8e8f 2808 struct station_parameters *params)
5727ef1b
JB
2809{
2810 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2811 struct nlattr *nla;
5727ef1b
JB
2812 int flag;
2813
eccb8e8f
JB
2814 /*
2815 * Try parsing the new attribute first so userspace
2816 * can specify both for older kernels.
2817 */
2818 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2819 if (nla) {
2820 struct nl80211_sta_flag_update *sta_flags;
2821
2822 sta_flags = nla_data(nla);
2823 params->sta_flags_mask = sta_flags->mask;
2824 params->sta_flags_set = sta_flags->set;
2825 if ((params->sta_flags_mask |
2826 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2827 return -EINVAL;
2828 return 0;
2829 }
2830
2831 /* if present, parse the old attribute */
5727ef1b 2832
eccb8e8f 2833 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2834 if (!nla)
2835 return 0;
2836
2837 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2838 nla, sta_flags_policy))
2839 return -EINVAL;
2840
bdd3ae3d
JB
2841 /*
2842 * Only allow certain flags for interface types so that
2843 * other attributes are silently ignored. Remember that
2844 * this is backward compatibility code with old userspace
2845 * and shouldn't be hit in other cases anyway.
2846 */
2847 switch (iftype) {
2848 case NL80211_IFTYPE_AP:
2849 case NL80211_IFTYPE_AP_VLAN:
2850 case NL80211_IFTYPE_P2P_GO:
2851 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2852 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2853 BIT(NL80211_STA_FLAG_WME) |
2854 BIT(NL80211_STA_FLAG_MFP);
2855 break;
2856 case NL80211_IFTYPE_P2P_CLIENT:
2857 case NL80211_IFTYPE_STATION:
2858 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2859 BIT(NL80211_STA_FLAG_TDLS_PEER);
2860 break;
2861 case NL80211_IFTYPE_MESH_POINT:
2862 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2863 BIT(NL80211_STA_FLAG_MFP) |
2864 BIT(NL80211_STA_FLAG_AUTHORIZED);
2865 default:
2866 return -EINVAL;
2867 }
5727ef1b 2868
3383b5a6
JB
2869 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2870 if (flags[flag]) {
eccb8e8f 2871 params->sta_flags_set |= (1<<flag);
5727ef1b 2872
3383b5a6
JB
2873 /* no longer support new API additions in old API */
2874 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2875 return -EINVAL;
2876 }
2877 }
2878
5727ef1b
JB
2879 return 0;
2880}
2881
c8dcfd8a
FF
2882static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2883 int attr)
2884{
2885 struct nlattr *rate;
8eb41c8d
VK
2886 u32 bitrate;
2887 u16 bitrate_compat;
c8dcfd8a
FF
2888
2889 rate = nla_nest_start(msg, attr);
2890 if (!rate)
db9c64cf 2891 return false;
c8dcfd8a
FF
2892
2893 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2894 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
2895 /* report 16-bit bitrate only if we can */
2896 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
2897 if (bitrate > 0 &&
2898 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
2899 return false;
2900 if (bitrate_compat > 0 &&
2901 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
2902 return false;
2903
2904 if (info->flags & RATE_INFO_FLAGS_MCS) {
2905 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
2906 return false;
2907 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
2908 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
2909 return false;
2910 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
2911 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
2912 return false;
2913 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
2914 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
2915 return false;
2916 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
2917 return false;
2918 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
2919 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
2920 return false;
2921 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
2922 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
2923 return false;
2924 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
2925 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
2926 return false;
2927 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
2928 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
2929 return false;
2930 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
2931 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
2932 return false;
2933 }
c8dcfd8a
FF
2934
2935 nla_nest_end(msg, rate);
2936 return true;
c8dcfd8a
FF
2937}
2938
15e47304 2939static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
2940 int flags,
2941 struct cfg80211_registered_device *rdev,
2942 struct net_device *dev,
98b62183 2943 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2944{
2945 void *hdr;
f4263c98 2946 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 2947
15e47304 2948 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
2949 if (!hdr)
2950 return -1;
2951
9360ffd1
DM
2952 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2953 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
2954 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
2955 goto nla_put_failure;
f5ea9120 2956
2ec600d6
LCC
2957 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2958 if (!sinfoattr)
fd5b74dc 2959 goto nla_put_failure;
9360ffd1
DM
2960 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
2961 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2962 sinfo->connected_time))
2963 goto nla_put_failure;
2964 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
2965 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2966 sinfo->inactive_time))
2967 goto nla_put_failure;
2968 if ((sinfo->filled & STATION_INFO_RX_BYTES) &&
2969 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
2970 sinfo->rx_bytes))
2971 goto nla_put_failure;
2972 if ((sinfo->filled & STATION_INFO_TX_BYTES) &&
2973 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
2974 sinfo->tx_bytes))
2975 goto nla_put_failure;
2976 if ((sinfo->filled & STATION_INFO_LLID) &&
2977 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
2978 goto nla_put_failure;
2979 if ((sinfo->filled & STATION_INFO_PLID) &&
2980 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
2981 goto nla_put_failure;
2982 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
2983 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
2984 sinfo->plink_state))
2985 goto nla_put_failure;
66266b3a
JL
2986 switch (rdev->wiphy.signal_type) {
2987 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
2988 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
2989 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
2990 sinfo->signal))
2991 goto nla_put_failure;
2992 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
2993 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2994 sinfo->signal_avg))
2995 goto nla_put_failure;
66266b3a
JL
2996 break;
2997 default:
2998 break;
2999 }
420e7fab 3000 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3001 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3002 NL80211_STA_INFO_TX_BITRATE))
3003 goto nla_put_failure;
3004 }
3005 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3006 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3007 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3008 goto nla_put_failure;
420e7fab 3009 }
9360ffd1
DM
3010 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3011 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3012 sinfo->rx_packets))
3013 goto nla_put_failure;
3014 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3015 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3016 sinfo->tx_packets))
3017 goto nla_put_failure;
3018 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3019 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3020 sinfo->tx_retries))
3021 goto nla_put_failure;
3022 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3023 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3024 sinfo->tx_failed))
3025 goto nla_put_failure;
3026 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3027 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3028 sinfo->beacon_loss_count))
3029 goto nla_put_failure;
f4263c98
PS
3030 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3031 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3032 if (!bss_param)
3033 goto nla_put_failure;
3034
9360ffd1
DM
3035 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3036 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3037 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3038 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3039 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3040 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3041 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3042 sinfo->bss_param.dtim_period) ||
3043 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3044 sinfo->bss_param.beacon_interval))
3045 goto nla_put_failure;
f4263c98
PS
3046
3047 nla_nest_end(msg, bss_param);
3048 }
9360ffd1
DM
3049 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3050 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3051 sizeof(struct nl80211_sta_flag_update),
3052 &sinfo->sta_flags))
3053 goto nla_put_failure;
7eab0f64
JL
3054 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3055 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3056 sinfo->t_offset))
3057 goto nla_put_failure;
2ec600d6 3058 nla_nest_end(msg, sinfoattr);
fd5b74dc 3059
9360ffd1
DM
3060 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3061 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3062 sinfo->assoc_req_ies))
3063 goto nla_put_failure;
50d3dfb7 3064
fd5b74dc
JB
3065 return genlmsg_end(msg, hdr);
3066
3067 nla_put_failure:
bc3ed28c
TG
3068 genlmsg_cancel(msg, hdr);
3069 return -EMSGSIZE;
fd5b74dc
JB
3070}
3071
2ec600d6 3072static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3073 struct netlink_callback *cb)
2ec600d6 3074{
2ec600d6
LCC
3075 struct station_info sinfo;
3076 struct cfg80211_registered_device *dev;
bba95fef 3077 struct net_device *netdev;
2ec600d6 3078 u8 mac_addr[ETH_ALEN];
bba95fef 3079 int sta_idx = cb->args[1];
2ec600d6 3080 int err;
2ec600d6 3081
67748893
JB
3082 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3083 if (err)
3084 return err;
bba95fef
JB
3085
3086 if (!dev->ops->dump_station) {
eec60b03 3087 err = -EOPNOTSUPP;
bba95fef
JB
3088 goto out_err;
3089 }
3090
bba95fef 3091 while (1) {
f612cedf 3092 memset(&sinfo, 0, sizeof(sinfo));
e35e4d28
HG
3093 err = rdev_dump_station(dev, netdev, sta_idx,
3094 mac_addr, &sinfo);
bba95fef
JB
3095 if (err == -ENOENT)
3096 break;
3097 if (err)
3b85875a 3098 goto out_err;
bba95fef
JB
3099
3100 if (nl80211_send_station(skb,
15e47304 3101 NETLINK_CB(cb->skb).portid,
bba95fef 3102 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 3103 dev, netdev, mac_addr,
bba95fef
JB
3104 &sinfo) < 0)
3105 goto out;
3106
3107 sta_idx++;
3108 }
3109
3110
3111 out:
3112 cb->args[1] = sta_idx;
3113 err = skb->len;
bba95fef 3114 out_err:
67748893 3115 nl80211_finish_netdev_dump(dev);
bba95fef
JB
3116
3117 return err;
2ec600d6 3118}
fd5b74dc 3119
5727ef1b
JB
3120static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3121{
4c476991
JB
3122 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3123 struct net_device *dev = info->user_ptr[1];
2ec600d6 3124 struct station_info sinfo;
fd5b74dc
JB
3125 struct sk_buff *msg;
3126 u8 *mac_addr = NULL;
4c476991 3127 int err;
fd5b74dc 3128
2ec600d6 3129 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3130
3131 if (!info->attrs[NL80211_ATTR_MAC])
3132 return -EINVAL;
3133
3134 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3135
4c476991
JB
3136 if (!rdev->ops->get_station)
3137 return -EOPNOTSUPP;
3b85875a 3138
e35e4d28 3139 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3140 if (err)
4c476991 3141 return err;
2ec600d6 3142
fd2120ca 3143 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3144 if (!msg)
4c476991 3145 return -ENOMEM;
fd5b74dc 3146
15e47304 3147 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3148 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3149 nlmsg_free(msg);
3150 return -ENOBUFS;
3151 }
3b85875a 3152
4c476991 3153 return genlmsg_reply(msg, info);
5727ef1b
JB
3154}
3155
3156/*
c258d2de 3157 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3158 */
80b99899
JB
3159static struct net_device *get_vlan(struct genl_info *info,
3160 struct cfg80211_registered_device *rdev)
5727ef1b 3161{
463d0183 3162 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3163 struct net_device *v;
3164 int ret;
3165
3166 if (!vlanattr)
3167 return NULL;
3168
3169 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3170 if (!v)
3171 return ERR_PTR(-ENODEV);
3172
3173 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3174 ret = -EINVAL;
3175 goto error;
5727ef1b 3176 }
80b99899
JB
3177
3178 if (!netif_running(v)) {
3179 ret = -ENETDOWN;
3180 goto error;
3181 }
3182
3183 return v;
3184 error:
3185 dev_put(v);
3186 return ERR_PTR(ret);
5727ef1b
JB
3187}
3188
3189static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3190{
4c476991 3191 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3192 int err;
4c476991 3193 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3194 struct station_parameters params;
3195 u8 *mac_addr = NULL;
3196
3197 memset(&params, 0, sizeof(params));
3198
3199 params.listen_interval = -1;
57cf8043 3200 params.plink_state = -1;
5727ef1b
JB
3201
3202 if (info->attrs[NL80211_ATTR_STA_AID])
3203 return -EINVAL;
3204
3205 if (!info->attrs[NL80211_ATTR_MAC])
3206 return -EINVAL;
3207
3208 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3209
3210 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3211 params.supported_rates =
3212 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3213 params.supported_rates_len =
3214 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3215 }
3216
3217 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3218 params.listen_interval =
3219 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
3220
36aedc90
JM
3221 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3222 params.ht_capa =
3223 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
3224
bdd90d5e
JB
3225 if (!rdev->ops->change_station)
3226 return -EOPNOTSUPP;
3227
bdd3ae3d 3228 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3229 return -EINVAL;
3230
2ec600d6
LCC
3231 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3232 params.plink_action =
3233 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3234
9c3990aa
JC
3235 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
3236 params.plink_state =
3237 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3238
a97f4424
JB
3239 switch (dev->ieee80211_ptr->iftype) {
3240 case NL80211_IFTYPE_AP:
3241 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3242 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
3243 /* disallow mesh-specific things */
3244 if (params.plink_action)
bdd90d5e
JB
3245 return -EINVAL;
3246
3247 /* TDLS can't be set, ... */
3248 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3249 return -EINVAL;
3250 /*
3251 * ... but don't bother the driver with it. This works around
3252 * a hostapd/wpa_supplicant issue -- it always includes the
3253 * TLDS_PEER flag in the mask even for AP mode.
3254 */
3255 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3256
3257 /* accept only the listed bits */
3258 if (params.sta_flags_mask &
3259 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3260 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3261 BIT(NL80211_STA_FLAG_WME) |
3262 BIT(NL80211_STA_FLAG_MFP)))
3263 return -EINVAL;
3264
3265 /* must be last in here for error handling */
3266 params.vlan = get_vlan(info, rdev);
3267 if (IS_ERR(params.vlan))
3268 return PTR_ERR(params.vlan);
a97f4424 3269 break;
074ac8df 3270 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3271 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
3272 /*
3273 * Don't allow userspace to change the TDLS_PEER flag,
3274 * but silently ignore attempts to change it since we
3275 * don't have state here to verify that it doesn't try
3276 * to change the flag.
3277 */
3278 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
3279 /* fall through */
3280 case NL80211_IFTYPE_ADHOC:
3281 /* disallow things sta doesn't support */
3282 if (params.plink_action)
3283 return -EINVAL;
3284 if (params.ht_capa)
3285 return -EINVAL;
3286 if (params.listen_interval >= 0)
3287 return -EINVAL;
bdd90d5e
JB
3288 /* reject any changes other than AUTHORIZED */
3289 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3290 return -EINVAL;
a97f4424
JB
3291 break;
3292 case NL80211_IFTYPE_MESH_POINT:
3293 /* disallow things mesh doesn't support */
3294 if (params.vlan)
bdd90d5e 3295 return -EINVAL;
a97f4424 3296 if (params.ht_capa)
bdd90d5e 3297 return -EINVAL;
a97f4424 3298 if (params.listen_interval >= 0)
bdd90d5e
JB
3299 return -EINVAL;
3300 /*
3301 * No special handling for TDLS here -- the userspace
3302 * mesh code doesn't have this bug.
3303 */
b39c48fa
JC
3304 if (params.sta_flags_mask &
3305 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 3306 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 3307 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 3308 return -EINVAL;
a97f4424
JB
3309 break;
3310 default:
bdd90d5e 3311 return -EOPNOTSUPP;
034d655e
JB
3312 }
3313
bdd90d5e 3314 /* be aware of params.vlan when changing code here */
5727ef1b 3315
e35e4d28 3316 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 3317
5727ef1b
JB
3318 if (params.vlan)
3319 dev_put(params.vlan);
3b85875a 3320
5727ef1b
JB
3321 return err;
3322}
3323
c75786c9
EP
3324static struct nla_policy
3325nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3326 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3327 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3328};
3329
5727ef1b
JB
3330static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3331{
4c476991 3332 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3333 int err;
4c476991 3334 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3335 struct station_parameters params;
3336 u8 *mac_addr = NULL;
3337
3338 memset(&params, 0, sizeof(params));
3339
3340 if (!info->attrs[NL80211_ATTR_MAC])
3341 return -EINVAL;
3342
5727ef1b
JB
3343 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3344 return -EINVAL;
3345
3346 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3347 return -EINVAL;
3348
0e956c13
TLSC
3349 if (!info->attrs[NL80211_ATTR_STA_AID])
3350 return -EINVAL;
3351
5727ef1b
JB
3352 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3353 params.supported_rates =
3354 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3355 params.supported_rates_len =
3356 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3357 params.listen_interval =
3358 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3359
0e956c13
TLSC
3360 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
3361 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3362 return -EINVAL;
51b50fbe 3363
36aedc90
JM
3364 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3365 params.ht_capa =
3366 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 3367
f461be3e
MP
3368 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3369 params.vht_capa =
3370 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3371
96b78dff
JC
3372 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3373 params.plink_action =
3374 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3375
bdd90d5e
JB
3376 if (!rdev->ops->add_station)
3377 return -EOPNOTSUPP;
3378
bdd3ae3d 3379 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3380 return -EINVAL;
3381
bdd90d5e
JB
3382 switch (dev->ieee80211_ptr->iftype) {
3383 case NL80211_IFTYPE_AP:
3384 case NL80211_IFTYPE_AP_VLAN:
3385 case NL80211_IFTYPE_P2P_GO:
3386 /* parse WME attributes if sta is WME capable */
3387 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3388 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
3389 info->attrs[NL80211_ATTR_STA_WME]) {
3390 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3391 struct nlattr *nla;
3392
3393 nla = info->attrs[NL80211_ATTR_STA_WME];
3394 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3395 nl80211_sta_wme_policy);
3396 if (err)
3397 return err;
3398
3399 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3400 params.uapsd_queues =
3401 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
3402 if (params.uapsd_queues &
3403 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3404 return -EINVAL;
c75786c9 3405
bdd90d5e
JB
3406 if (tb[NL80211_STA_WME_MAX_SP])
3407 params.max_sp =
3408 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 3409
bdd90d5e
JB
3410 if (params.max_sp &
3411 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3412 return -EINVAL;
4319e193 3413
bdd90d5e
JB
3414 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3415 }
3416 /* TDLS peers cannot be added */
3417 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3418 return -EINVAL;
bdd90d5e
JB
3419 /* but don't bother the driver with it */
3420 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3421
bdd90d5e
JB
3422 /* must be last in here for error handling */
3423 params.vlan = get_vlan(info, rdev);
3424 if (IS_ERR(params.vlan))
3425 return PTR_ERR(params.vlan);
3426 break;
3427 case NL80211_IFTYPE_MESH_POINT:
3428 /* TDLS peers cannot be added */
3429 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3430 return -EINVAL;
3431 break;
3432 case NL80211_IFTYPE_STATION:
3433 /* Only TDLS peers can be added */
3434 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3435 return -EINVAL;
3436 /* Can only add if TDLS ... */
3437 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3438 return -EOPNOTSUPP;
3439 /* ... with external setup is supported */
3440 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3441 return -EOPNOTSUPP;
3442 break;
3443 default:
3444 return -EOPNOTSUPP;
c75786c9
EP
3445 }
3446
bdd90d5e 3447 /* be aware of params.vlan when changing code here */
5727ef1b 3448
e35e4d28 3449 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 3450
5727ef1b
JB
3451 if (params.vlan)
3452 dev_put(params.vlan);
5727ef1b
JB
3453 return err;
3454}
3455
3456static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3457{
4c476991
JB
3458 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3459 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3460 u8 *mac_addr = NULL;
3461
3462 if (info->attrs[NL80211_ATTR_MAC])
3463 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3464
e80cf853 3465 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3466 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3467 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3468 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3469 return -EINVAL;
5727ef1b 3470
4c476991
JB
3471 if (!rdev->ops->del_station)
3472 return -EOPNOTSUPP;
3b85875a 3473
e35e4d28 3474 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
3475}
3476
15e47304 3477static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
3478 int flags, struct net_device *dev,
3479 u8 *dst, u8 *next_hop,
3480 struct mpath_info *pinfo)
3481{
3482 void *hdr;
3483 struct nlattr *pinfoattr;
3484
15e47304 3485 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
3486 if (!hdr)
3487 return -1;
3488
9360ffd1
DM
3489 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3490 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3491 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3492 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3493 goto nla_put_failure;
f5ea9120 3494
2ec600d6
LCC
3495 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3496 if (!pinfoattr)
3497 goto nla_put_failure;
9360ffd1
DM
3498 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3499 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3500 pinfo->frame_qlen))
3501 goto nla_put_failure;
3502 if (((pinfo->filled & MPATH_INFO_SN) &&
3503 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3504 ((pinfo->filled & MPATH_INFO_METRIC) &&
3505 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3506 pinfo->metric)) ||
3507 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3508 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3509 pinfo->exptime)) ||
3510 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3511 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3512 pinfo->flags)) ||
3513 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3514 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3515 pinfo->discovery_timeout)) ||
3516 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3517 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3518 pinfo->discovery_retries)))
3519 goto nla_put_failure;
2ec600d6
LCC
3520
3521 nla_nest_end(msg, pinfoattr);
3522
3523 return genlmsg_end(msg, hdr);
3524
3525 nla_put_failure:
bc3ed28c
TG
3526 genlmsg_cancel(msg, hdr);
3527 return -EMSGSIZE;
2ec600d6
LCC
3528}
3529
3530static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3531 struct netlink_callback *cb)
2ec600d6 3532{
2ec600d6
LCC
3533 struct mpath_info pinfo;
3534 struct cfg80211_registered_device *dev;
bba95fef 3535 struct net_device *netdev;
2ec600d6
LCC
3536 u8 dst[ETH_ALEN];
3537 u8 next_hop[ETH_ALEN];
bba95fef 3538 int path_idx = cb->args[1];
2ec600d6 3539 int err;
2ec600d6 3540
67748893
JB
3541 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3542 if (err)
3543 return err;
bba95fef
JB
3544
3545 if (!dev->ops->dump_mpath) {
eec60b03 3546 err = -EOPNOTSUPP;
bba95fef
JB
3547 goto out_err;
3548 }
3549
eec60b03
JM
3550 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3551 err = -EOPNOTSUPP;
0448b5fc 3552 goto out_err;
eec60b03
JM
3553 }
3554
bba95fef 3555 while (1) {
e35e4d28
HG
3556 err = rdev_dump_mpath(dev, netdev, path_idx, dst, next_hop,
3557 &pinfo);
bba95fef 3558 if (err == -ENOENT)
2ec600d6 3559 break;
bba95fef 3560 if (err)
3b85875a 3561 goto out_err;
2ec600d6 3562
15e47304 3563 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef
JB
3564 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3565 netdev, dst, next_hop,
3566 &pinfo) < 0)
3567 goto out;
2ec600d6 3568
bba95fef 3569 path_idx++;
2ec600d6 3570 }
2ec600d6 3571
2ec600d6 3572
bba95fef
JB
3573 out:
3574 cb->args[1] = path_idx;
3575 err = skb->len;
bba95fef 3576 out_err:
67748893 3577 nl80211_finish_netdev_dump(dev);
bba95fef 3578 return err;
2ec600d6
LCC
3579}
3580
3581static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3582{
4c476991 3583 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3584 int err;
4c476991 3585 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3586 struct mpath_info pinfo;
3587 struct sk_buff *msg;
3588 u8 *dst = NULL;
3589 u8 next_hop[ETH_ALEN];
3590
3591 memset(&pinfo, 0, sizeof(pinfo));
3592
3593 if (!info->attrs[NL80211_ATTR_MAC])
3594 return -EINVAL;
3595
3596 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3597
4c476991
JB
3598 if (!rdev->ops->get_mpath)
3599 return -EOPNOTSUPP;
2ec600d6 3600
4c476991
JB
3601 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3602 return -EOPNOTSUPP;
eec60b03 3603
e35e4d28 3604 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 3605 if (err)
4c476991 3606 return err;
2ec600d6 3607
fd2120ca 3608 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3609 if (!msg)
4c476991 3610 return -ENOMEM;
2ec600d6 3611
15e47304 3612 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
3613 dev, dst, next_hop, &pinfo) < 0) {
3614 nlmsg_free(msg);
3615 return -ENOBUFS;
3616 }
3b85875a 3617
4c476991 3618 return genlmsg_reply(msg, info);
2ec600d6
LCC
3619}
3620
3621static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3622{
4c476991
JB
3623 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3624 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3625 u8 *dst = NULL;
3626 u8 *next_hop = NULL;
3627
3628 if (!info->attrs[NL80211_ATTR_MAC])
3629 return -EINVAL;
3630
3631 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3632 return -EINVAL;
3633
3634 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3635 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3636
4c476991
JB
3637 if (!rdev->ops->change_mpath)
3638 return -EOPNOTSUPP;
35a8efe1 3639
4c476991
JB
3640 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3641 return -EOPNOTSUPP;
2ec600d6 3642
e35e4d28 3643 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 3644}
4c476991 3645
2ec600d6
LCC
3646static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3647{
4c476991
JB
3648 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3649 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3650 u8 *dst = NULL;
3651 u8 *next_hop = NULL;
3652
3653 if (!info->attrs[NL80211_ATTR_MAC])
3654 return -EINVAL;
3655
3656 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3657 return -EINVAL;
3658
3659 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3660 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3661
4c476991
JB
3662 if (!rdev->ops->add_mpath)
3663 return -EOPNOTSUPP;
35a8efe1 3664
4c476991
JB
3665 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3666 return -EOPNOTSUPP;
2ec600d6 3667
e35e4d28 3668 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
3669}
3670
3671static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3672{
4c476991
JB
3673 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3674 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3675 u8 *dst = NULL;
3676
3677 if (info->attrs[NL80211_ATTR_MAC])
3678 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3679
4c476991
JB
3680 if (!rdev->ops->del_mpath)
3681 return -EOPNOTSUPP;
3b85875a 3682
e35e4d28 3683 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
3684}
3685
9f1ba906
JM
3686static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3687{
4c476991
JB
3688 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3689 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3690 struct bss_parameters params;
3691
3692 memset(&params, 0, sizeof(params));
3693 /* default to not changing parameters */
3694 params.use_cts_prot = -1;
3695 params.use_short_preamble = -1;
3696 params.use_short_slot_time = -1;
fd8aaaf3 3697 params.ap_isolate = -1;
50b12f59 3698 params.ht_opmode = -1;
53cabad7
JB
3699 params.p2p_ctwindow = -1;
3700 params.p2p_opp_ps = -1;
9f1ba906
JM
3701
3702 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3703 params.use_cts_prot =
3704 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3705 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3706 params.use_short_preamble =
3707 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3708 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3709 params.use_short_slot_time =
3710 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3711 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3712 params.basic_rates =
3713 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3714 params.basic_rates_len =
3715 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3716 }
fd8aaaf3
FF
3717 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3718 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3719 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3720 params.ht_opmode =
3721 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3722
53cabad7
JB
3723 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3724 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3725 return -EINVAL;
3726 params.p2p_ctwindow =
3727 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3728 if (params.p2p_ctwindow < 0)
3729 return -EINVAL;
3730 if (params.p2p_ctwindow != 0 &&
3731 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3732 return -EINVAL;
3733 }
3734
3735 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3736 u8 tmp;
3737
3738 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3739 return -EINVAL;
3740 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3741 if (tmp > 1)
3742 return -EINVAL;
3743 params.p2p_opp_ps = tmp;
3744 if (params.p2p_opp_ps &&
3745 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3746 return -EINVAL;
3747 }
3748
4c476991
JB
3749 if (!rdev->ops->change_bss)
3750 return -EOPNOTSUPP;
9f1ba906 3751
074ac8df 3752 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3753 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3754 return -EOPNOTSUPP;
3b85875a 3755
e35e4d28 3756 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
3757}
3758
b54452b0 3759static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3760 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3761 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3762 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3763 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3764 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3765 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3766};
3767
3768static int parse_reg_rule(struct nlattr *tb[],
3769 struct ieee80211_reg_rule *reg_rule)
3770{
3771 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3772 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3773
3774 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3775 return -EINVAL;
3776 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3777 return -EINVAL;
3778 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3779 return -EINVAL;
3780 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3781 return -EINVAL;
3782 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3783 return -EINVAL;
3784
3785 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3786
3787 freq_range->start_freq_khz =
3788 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3789 freq_range->end_freq_khz =
3790 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3791 freq_range->max_bandwidth_khz =
3792 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3793
3794 power_rule->max_eirp =
3795 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3796
3797 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3798 power_rule->max_antenna_gain =
3799 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3800
3801 return 0;
3802}
3803
3804static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3805{
3806 int r;
3807 char *data = NULL;
57b5ce07 3808 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 3809
80778f18
LR
3810 /*
3811 * You should only get this when cfg80211 hasn't yet initialized
3812 * completely when built-in to the kernel right between the time
3813 * window between nl80211_init() and regulatory_init(), if that is
3814 * even possible.
3815 */
3816 mutex_lock(&cfg80211_mutex);
3817 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3818 mutex_unlock(&cfg80211_mutex);
3819 return -EINPROGRESS;
80778f18 3820 }
fe33eb39 3821 mutex_unlock(&cfg80211_mutex);
80778f18 3822
fe33eb39
LR
3823 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3824 return -EINVAL;
b2e1b302
LR
3825
3826 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3827
57b5ce07
LR
3828 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
3829 user_reg_hint_type =
3830 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
3831 else
3832 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
3833
3834 switch (user_reg_hint_type) {
3835 case NL80211_USER_REG_HINT_USER:
3836 case NL80211_USER_REG_HINT_CELL_BASE:
3837 break;
3838 default:
3839 return -EINVAL;
3840 }
3841
3842 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 3843
b2e1b302
LR
3844 return r;
3845}
3846
24bdd9f4 3847static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3848 struct genl_info *info)
93da9cc1 3849{
4c476991 3850 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3851 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3852 struct wireless_dev *wdev = dev->ieee80211_ptr;
3853 struct mesh_config cur_params;
3854 int err = 0;
93da9cc1 3855 void *hdr;
3856 struct nlattr *pinfoattr;
3857 struct sk_buff *msg;
3858
29cbe68c
JB
3859 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3860 return -EOPNOTSUPP;
3861
24bdd9f4 3862 if (!rdev->ops->get_mesh_config)
4c476991 3863 return -EOPNOTSUPP;
f3f92586 3864
29cbe68c
JB
3865 wdev_lock(wdev);
3866 /* If not connected, get default parameters */
3867 if (!wdev->mesh_id_len)
3868 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3869 else
e35e4d28 3870 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
3871 wdev_unlock(wdev);
3872
93da9cc1 3873 if (err)
4c476991 3874 return err;
93da9cc1 3875
3876 /* Draw up a netlink message to send back */
fd2120ca 3877 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3878 if (!msg)
3879 return -ENOMEM;
15e47304 3880 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 3881 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3882 if (!hdr)
efe1cf0c 3883 goto out;
24bdd9f4 3884 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3885 if (!pinfoattr)
3886 goto nla_put_failure;
9360ffd1
DM
3887 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3888 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3889 cur_params.dot11MeshRetryTimeout) ||
3890 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3891 cur_params.dot11MeshConfirmTimeout) ||
3892 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3893 cur_params.dot11MeshHoldingTimeout) ||
3894 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3895 cur_params.dot11MeshMaxPeerLinks) ||
3896 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
3897 cur_params.dot11MeshMaxRetries) ||
3898 nla_put_u8(msg, NL80211_MESHCONF_TTL,
3899 cur_params.dot11MeshTTL) ||
3900 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3901 cur_params.element_ttl) ||
3902 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3903 cur_params.auto_open_plinks) ||
7eab0f64
JL
3904 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3905 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
3906 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3907 cur_params.dot11MeshHWMPmaxPREQretries) ||
3908 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3909 cur_params.path_refresh_time) ||
3910 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3911 cur_params.min_discovery_timeout) ||
3912 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3913 cur_params.dot11MeshHWMPactivePathTimeout) ||
3914 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3915 cur_params.dot11MeshHWMPpreqMinInterval) ||
3916 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3917 cur_params.dot11MeshHWMPperrMinInterval) ||
3918 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3919 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
3920 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3921 cur_params.dot11MeshHWMPRootMode) ||
3922 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3923 cur_params.dot11MeshHWMPRannInterval) ||
3924 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3925 cur_params.dot11MeshGateAnnouncementProtocol) ||
3926 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
3927 cur_params.dot11MeshForwarding) ||
3928 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
3929 cur_params.rssi_threshold) ||
3930 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
3931 cur_params.ht_opmode) ||
3932 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
3933 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
3934 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
3935 cur_params.dot11MeshHWMProotInterval) ||
3936 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3937 cur_params.dot11MeshHWMPconfirmationInterval))
9360ffd1 3938 goto nla_put_failure;
93da9cc1 3939 nla_nest_end(msg, pinfoattr);
3940 genlmsg_end(msg, hdr);
4c476991 3941 return genlmsg_reply(msg, info);
93da9cc1 3942
3b85875a 3943 nla_put_failure:
93da9cc1 3944 genlmsg_cancel(msg, hdr);
efe1cf0c 3945 out:
d080e275 3946 nlmsg_free(msg);
4c476991 3947 return -ENOBUFS;
93da9cc1 3948}
3949
b54452b0 3950static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3951 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3952 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3953 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3954 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3955 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3956 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3957 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3958 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 3959 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 3960 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3961 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3962 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3963 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3964 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3965 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3966 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3967 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3968 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3969 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3970 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
3971 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
3972 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
3973 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
3974 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 3975 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3976};
3977
c80d545d
JC
3978static const struct nla_policy
3979 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 3980 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
3981 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3982 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3983 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3984 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 3985 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3986 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3987};
3988
24bdd9f4 3989static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3990 struct mesh_config *cfg,
3991 u32 *mask_out)
93da9cc1 3992{
93da9cc1 3993 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3994 u32 mask = 0;
93da9cc1 3995
bd90fdcc
JB
3996#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3997do {\
3998 if (table[attr_num]) {\
3999 cfg->param = nla_fn(table[attr_num]); \
4000 mask |= (1 << (attr_num - 1)); \
4001 } \
4002} while (0);\
4003
4004
24bdd9f4 4005 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4006 return -EINVAL;
4007 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4008 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4009 nl80211_meshconf_params_policy))
93da9cc1 4010 return -EINVAL;
4011
93da9cc1 4012 /* This makes sure that there aren't more than 32 mesh config
4013 * parameters (otherwise our bitfield scheme would not work.) */
4014 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4015
4016 /* Fill in the params struct */
93da9cc1 4017 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
a4f606ea
CYY
4018 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4019 nla_get_u16);
93da9cc1 4020 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
a4f606ea
CYY
4021 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4022 nla_get_u16);
93da9cc1 4023 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
a4f606ea
CYY
4024 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4025 nla_get_u16);
93da9cc1 4026 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
a4f606ea
CYY
4027 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4028 nla_get_u16);
93da9cc1 4029 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
a4f606ea
CYY
4030 mask, NL80211_MESHCONF_MAX_RETRIES,
4031 nla_get_u8);
93da9cc1 4032 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
a4f606ea 4033 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21 4034 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
a4f606ea
CYY
4035 mask, NL80211_MESHCONF_ELEMENT_TTL,
4036 nla_get_u8);
93da9cc1 4037 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
a4f606ea
CYY
4038 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4039 nla_get_u8);
4040 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, mask,
4041 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4042 nla_get_u32);
93da9cc1 4043 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
a4f606ea
CYY
4044 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4045 nla_get_u8);
93da9cc1 4046 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
a4f606ea
CYY
4047 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4048 nla_get_u32);
93da9cc1 4049 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
a4f606ea
CYY
4050 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4051 nla_get_u16);
4052 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, mask,
4053 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4054 nla_get_u32);
93da9cc1 4055 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
a4f606ea
CYY
4056 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4057 nla_get_u16);
dca7e943 4058 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
a4f606ea
CYY
4059 mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4060 nla_get_u16);
93da9cc1 4061 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
4062 dot11MeshHWMPnetDiameterTraversalTime, mask,
4063 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4064 nla_get_u16);
4065 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
4066 NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
4067 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
4068 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4069 nla_get_u16);
63c5723b 4070 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
4071 dot11MeshGateAnnouncementProtocol, mask,
4072 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4073 nla_get_u8);
94f90656 4074 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
a4f606ea
CYY
4075 mask, NL80211_MESHCONF_FORWARDING,
4076 nla_get_u8);
55335137 4077 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
a4f606ea
CYY
4078 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
4079 nla_get_u32);
70c33eaa 4080 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode,
a4f606ea 4081 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4082 nla_get_u16);
4083 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
4084 mask,
4085 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4086 nla_get_u32);
4087 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval,
4088 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4089 nla_get_u16);
4090 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
4091 dot11MeshHWMPconfirmationInterval, mask,
4092 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4093 nla_get_u16);
bd90fdcc
JB
4094 if (mask_out)
4095 *mask_out = mask;
c80d545d 4096
bd90fdcc
JB
4097 return 0;
4098
4099#undef FILL_IN_MESH_PARAM_IF_SET
4100}
4101
c80d545d
JC
4102static int nl80211_parse_mesh_setup(struct genl_info *info,
4103 struct mesh_setup *setup)
4104{
4105 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4106
4107 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4108 return -EINVAL;
4109 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4110 info->attrs[NL80211_ATTR_MESH_SETUP],
4111 nl80211_mesh_setup_params_policy))
4112 return -EINVAL;
4113
d299a1f2
JC
4114 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4115 setup->sync_method =
4116 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4117 IEEE80211_SYNC_METHOD_VENDOR :
4118 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4119
c80d545d
JC
4120 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4121 setup->path_sel_proto =
4122 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4123 IEEE80211_PATH_PROTOCOL_VENDOR :
4124 IEEE80211_PATH_PROTOCOL_HWMP;
4125
4126 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4127 setup->path_metric =
4128 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4129 IEEE80211_PATH_METRIC_VENDOR :
4130 IEEE80211_PATH_METRIC_AIRTIME;
4131
581a8b0f
JC
4132
4133 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4134 struct nlattr *ieattr =
581a8b0f 4135 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4136 if (!is_valid_ie_attr(ieattr))
4137 return -EINVAL;
581a8b0f
JC
4138 setup->ie = nla_data(ieattr);
4139 setup->ie_len = nla_len(ieattr);
c80d545d 4140 }
b130e5ce
JC
4141 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4142 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
4143
4144 return 0;
4145}
4146
24bdd9f4 4147static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4148 struct genl_info *info)
bd90fdcc
JB
4149{
4150 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4151 struct net_device *dev = info->user_ptr[1];
29cbe68c 4152 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4153 struct mesh_config cfg;
4154 u32 mask;
4155 int err;
4156
29cbe68c
JB
4157 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4158 return -EOPNOTSUPP;
4159
24bdd9f4 4160 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4161 return -EOPNOTSUPP;
4162
24bdd9f4 4163 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4164 if (err)
4165 return err;
4166
29cbe68c
JB
4167 wdev_lock(wdev);
4168 if (!wdev->mesh_id_len)
4169 err = -ENOLINK;
4170
4171 if (!err)
e35e4d28 4172 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4173
4174 wdev_unlock(wdev);
4175
4176 return err;
93da9cc1 4177}
4178
f130347c
LR
4179static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4180{
4181 struct sk_buff *msg;
4182 void *hdr = NULL;
4183 struct nlattr *nl_reg_rules;
4184 unsigned int i;
4185 int err = -EINVAL;
4186
a1794390 4187 mutex_lock(&cfg80211_mutex);
f130347c
LR
4188
4189 if (!cfg80211_regdomain)
4190 goto out;
4191
fd2120ca 4192 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
4193 if (!msg) {
4194 err = -ENOBUFS;
4195 goto out;
4196 }
4197
15e47304 4198 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4199 NL80211_CMD_GET_REG);
4200 if (!hdr)
efe1cf0c 4201 goto put_failure;
f130347c 4202
9360ffd1
DM
4203 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
4204 cfg80211_regdomain->alpha2) ||
4205 (cfg80211_regdomain->dfs_region &&
4206 nla_put_u8(msg, NL80211_ATTR_DFS_REGION,
4207 cfg80211_regdomain->dfs_region)))
4208 goto nla_put_failure;
f130347c 4209
57b5ce07
LR
4210 if (reg_last_request_cell_base() &&
4211 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4212 NL80211_USER_REG_HINT_CELL_BASE))
4213 goto nla_put_failure;
4214
f130347c
LR
4215 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4216 if (!nl_reg_rules)
4217 goto nla_put_failure;
4218
4219 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
4220 struct nlattr *nl_reg_rule;
4221 const struct ieee80211_reg_rule *reg_rule;
4222 const struct ieee80211_freq_range *freq_range;
4223 const struct ieee80211_power_rule *power_rule;
4224
4225 reg_rule = &cfg80211_regdomain->reg_rules[i];
4226 freq_range = &reg_rule->freq_range;
4227 power_rule = &reg_rule->power_rule;
4228
4229 nl_reg_rule = nla_nest_start(msg, i);
4230 if (!nl_reg_rule)
4231 goto nla_put_failure;
4232
9360ffd1
DM
4233 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4234 reg_rule->flags) ||
4235 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4236 freq_range->start_freq_khz) ||
4237 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
4238 freq_range->end_freq_khz) ||
4239 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
4240 freq_range->max_bandwidth_khz) ||
4241 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
4242 power_rule->max_antenna_gain) ||
4243 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
4244 power_rule->max_eirp))
4245 goto nla_put_failure;
f130347c
LR
4246
4247 nla_nest_end(msg, nl_reg_rule);
4248 }
4249
4250 nla_nest_end(msg, nl_reg_rules);
4251
4252 genlmsg_end(msg, hdr);
134e6375 4253 err = genlmsg_reply(msg, info);
f130347c
LR
4254 goto out;
4255
4256nla_put_failure:
4257 genlmsg_cancel(msg, hdr);
efe1cf0c 4258put_failure:
d080e275 4259 nlmsg_free(msg);
f130347c
LR
4260 err = -EMSGSIZE;
4261out:
a1794390 4262 mutex_unlock(&cfg80211_mutex);
f130347c
LR
4263 return err;
4264}
4265
b2e1b302
LR
4266static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
4267{
4268 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
4269 struct nlattr *nl_reg_rule;
4270 char *alpha2 = NULL;
4271 int rem_reg_rules = 0, r = 0;
4272 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4273 u8 dfs_region = 0;
b2e1b302
LR
4274 struct ieee80211_regdomain *rd = NULL;
4275
4276 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4277 return -EINVAL;
4278
4279 if (!info->attrs[NL80211_ATTR_REG_RULES])
4280 return -EINVAL;
4281
4282 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4283
8b60b078
LR
4284 if (info->attrs[NL80211_ATTR_DFS_REGION])
4285 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4286
b2e1b302
LR
4287 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
4288 rem_reg_rules) {
4289 num_rules++;
4290 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4291 return -EINVAL;
b2e1b302
LR
4292 }
4293
61405e97
LR
4294 mutex_lock(&cfg80211_mutex);
4295
d0e18f83
LR
4296 if (!reg_is_valid_request(alpha2)) {
4297 r = -EINVAL;
4298 goto bad_reg;
4299 }
b2e1b302
LR
4300
4301 size_of_regd = sizeof(struct ieee80211_regdomain) +
4302 (num_rules * sizeof(struct ieee80211_reg_rule));
4303
4304 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
4305 if (!rd) {
4306 r = -ENOMEM;
4307 goto bad_reg;
4308 }
b2e1b302
LR
4309
4310 rd->n_reg_rules = num_rules;
4311 rd->alpha2[0] = alpha2[0];
4312 rd->alpha2[1] = alpha2[1];
4313
8b60b078
LR
4314 /*
4315 * Disable DFS master mode if the DFS region was
4316 * not supported or known on this kernel.
4317 */
4318 if (reg_supported_dfs_region(dfs_region))
4319 rd->dfs_region = dfs_region;
4320
b2e1b302
LR
4321 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
4322 rem_reg_rules) {
4323 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
4324 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
4325 reg_rule_policy);
4326 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
4327 if (r)
4328 goto bad_reg;
4329
4330 rule_idx++;
4331
d0e18f83
LR
4332 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
4333 r = -EINVAL;
b2e1b302 4334 goto bad_reg;
d0e18f83 4335 }
b2e1b302
LR
4336 }
4337
4338 BUG_ON(rule_idx != num_rules);
4339
b2e1b302 4340 r = set_regdom(rd);
61405e97 4341
a1794390 4342 mutex_unlock(&cfg80211_mutex);
d0e18f83 4343
b2e1b302
LR
4344 return r;
4345
d2372b31 4346 bad_reg:
61405e97 4347 mutex_unlock(&cfg80211_mutex);
b2e1b302 4348 kfree(rd);
d0e18f83 4349 return r;
b2e1b302
LR
4350}
4351
83f5e2cf
JB
4352static int validate_scan_freqs(struct nlattr *freqs)
4353{
4354 struct nlattr *attr1, *attr2;
4355 int n_channels = 0, tmp1, tmp2;
4356
4357 nla_for_each_nested(attr1, freqs, tmp1) {
4358 n_channels++;
4359 /*
4360 * Some hardware has a limited channel list for
4361 * scanning, and it is pretty much nonsensical
4362 * to scan for a channel twice, so disallow that
4363 * and don't require drivers to check that the
4364 * channel list they get isn't longer than what
4365 * they can scan, as long as they can scan all
4366 * the channels they registered at once.
4367 */
4368 nla_for_each_nested(attr2, freqs, tmp2)
4369 if (attr1 != attr2 &&
4370 nla_get_u32(attr1) == nla_get_u32(attr2))
4371 return 0;
4372 }
4373
4374 return n_channels;
4375}
4376
2a519311
JB
4377static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
4378{
4c476991 4379 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 4380 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 4381 struct cfg80211_scan_request *request;
2a519311
JB
4382 struct nlattr *attr;
4383 struct wiphy *wiphy;
83f5e2cf 4384 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 4385 size_t ie_len;
2a519311 4386
f4a11bb0
JB
4387 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4388 return -EINVAL;
4389
79c97e97 4390 wiphy = &rdev->wiphy;
2a519311 4391
4c476991
JB
4392 if (!rdev->ops->scan)
4393 return -EOPNOTSUPP;
2a519311 4394
4c476991
JB
4395 if (rdev->scan_req)
4396 return -EBUSY;
2a519311
JB
4397
4398 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
4399 n_channels = validate_scan_freqs(
4400 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
4401 if (!n_channels)
4402 return -EINVAL;
2a519311 4403 } else {
34850ab2 4404 enum ieee80211_band band;
83f5e2cf
JB
4405 n_channels = 0;
4406
2a519311
JB
4407 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4408 if (wiphy->bands[band])
4409 n_channels += wiphy->bands[band]->n_channels;
4410 }
4411
4412 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4413 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
4414 n_ssids++;
4415
4c476991
JB
4416 if (n_ssids > wiphy->max_scan_ssids)
4417 return -EINVAL;
2a519311 4418
70692ad2
JM
4419 if (info->attrs[NL80211_ATTR_IE])
4420 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4421 else
4422 ie_len = 0;
4423
4c476991
JB
4424 if (ie_len > wiphy->max_scan_ie_len)
4425 return -EINVAL;
18a83659 4426
2a519311 4427 request = kzalloc(sizeof(*request)
a2cd43c5
LC
4428 + sizeof(*request->ssids) * n_ssids
4429 + sizeof(*request->channels) * n_channels
70692ad2 4430 + ie_len, GFP_KERNEL);
4c476991
JB
4431 if (!request)
4432 return -ENOMEM;
2a519311 4433
2a519311 4434 if (n_ssids)
5ba63533 4435 request->ssids = (void *)&request->channels[n_channels];
2a519311 4436 request->n_ssids = n_ssids;
70692ad2
JM
4437 if (ie_len) {
4438 if (request->ssids)
4439 request->ie = (void *)(request->ssids + n_ssids);
4440 else
4441 request->ie = (void *)(request->channels + n_channels);
4442 }
2a519311 4443
584991dc 4444 i = 0;
2a519311
JB
4445 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4446 /* user specified, bail out if channel not found */
2a519311 4447 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
4448 struct ieee80211_channel *chan;
4449
4450 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4451
4452 if (!chan) {
2a519311
JB
4453 err = -EINVAL;
4454 goto out_free;
4455 }
584991dc
JB
4456
4457 /* ignore disabled channels */
4458 if (chan->flags & IEEE80211_CHAN_DISABLED)
4459 continue;
4460
4461 request->channels[i] = chan;
2a519311
JB
4462 i++;
4463 }
4464 } else {
34850ab2
JB
4465 enum ieee80211_band band;
4466
2a519311 4467 /* all channels */
2a519311
JB
4468 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4469 int j;
4470 if (!wiphy->bands[band])
4471 continue;
4472 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4473 struct ieee80211_channel *chan;
4474
4475 chan = &wiphy->bands[band]->channels[j];
4476
4477 if (chan->flags & IEEE80211_CHAN_DISABLED)
4478 continue;
4479
4480 request->channels[i] = chan;
2a519311
JB
4481 i++;
4482 }
4483 }
4484 }
4485
584991dc
JB
4486 if (!i) {
4487 err = -EINVAL;
4488 goto out_free;
4489 }
4490
4491 request->n_channels = i;
4492
2a519311
JB
4493 i = 0;
4494 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4495 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4496 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4497 err = -EINVAL;
4498 goto out_free;
4499 }
57a27e1d 4500 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4501 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4502 i++;
4503 }
4504 }
4505
70692ad2
JM
4506 if (info->attrs[NL80211_ATTR_IE]) {
4507 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4508 memcpy((void *)request->ie,
4509 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4510 request->ie_len);
4511 }
4512
34850ab2 4513 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4514 if (wiphy->bands[i])
4515 request->rates[i] =
4516 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4517
4518 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4519 nla_for_each_nested(attr,
4520 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4521 tmp) {
4522 enum ieee80211_band band = nla_type(attr);
4523
84404623 4524 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4525 err = -EINVAL;
4526 goto out_free;
4527 }
4528 err = ieee80211_get_ratemask(wiphy->bands[band],
4529 nla_data(attr),
4530 nla_len(attr),
4531 &request->rates[band]);
4532 if (err)
4533 goto out_free;
4534 }
4535 }
4536
46856bbf 4537 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4538 request->flags = nla_get_u32(
4539 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4540 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4541 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4542 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4543 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4544 err = -EOPNOTSUPP;
4545 goto out_free;
4546 }
4547 }
ed473771 4548
e9f935e3
RM
4549 request->no_cck =
4550 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4551
fd014284 4552 request->wdev = wdev;
79c97e97 4553 request->wiphy = &rdev->wiphy;
15d6030b 4554 request->scan_start = jiffies;
2a519311 4555
79c97e97 4556 rdev->scan_req = request;
e35e4d28 4557 err = rdev_scan(rdev, request);
2a519311 4558
463d0183 4559 if (!err) {
fd014284
JB
4560 nl80211_send_scan_start(rdev, wdev);
4561 if (wdev->netdev)
4562 dev_hold(wdev->netdev);
4c476991 4563 } else {
2a519311 4564 out_free:
79c97e97 4565 rdev->scan_req = NULL;
2a519311
JB
4566 kfree(request);
4567 }
3b85875a 4568
2a519311
JB
4569 return err;
4570}
4571
807f8a8c
LC
4572static int nl80211_start_sched_scan(struct sk_buff *skb,
4573 struct genl_info *info)
4574{
4575 struct cfg80211_sched_scan_request *request;
4576 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4577 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4578 struct nlattr *attr;
4579 struct wiphy *wiphy;
a1f1c21c 4580 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4581 u32 interval;
807f8a8c
LC
4582 enum ieee80211_band band;
4583 size_t ie_len;
a1f1c21c 4584 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4585
4586 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4587 !rdev->ops->sched_scan_start)
4588 return -EOPNOTSUPP;
4589
4590 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4591 return -EINVAL;
4592
bbe6ad6d
LC
4593 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4594 return -EINVAL;
4595
4596 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4597 if (interval == 0)
4598 return -EINVAL;
4599
807f8a8c
LC
4600 wiphy = &rdev->wiphy;
4601
4602 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4603 n_channels = validate_scan_freqs(
4604 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4605 if (!n_channels)
4606 return -EINVAL;
4607 } else {
4608 n_channels = 0;
4609
4610 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4611 if (wiphy->bands[band])
4612 n_channels += wiphy->bands[band]->n_channels;
4613 }
4614
4615 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4616 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4617 tmp)
4618 n_ssids++;
4619
93b6aa69 4620 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4621 return -EINVAL;
4622
a1f1c21c
LC
4623 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4624 nla_for_each_nested(attr,
4625 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4626 tmp)
4627 n_match_sets++;
4628
4629 if (n_match_sets > wiphy->max_match_sets)
4630 return -EINVAL;
4631
807f8a8c
LC
4632 if (info->attrs[NL80211_ATTR_IE])
4633 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4634 else
4635 ie_len = 0;
4636
5a865bad 4637 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4638 return -EINVAL;
4639
c10841ca
LC
4640 mutex_lock(&rdev->sched_scan_mtx);
4641
4642 if (rdev->sched_scan_req) {
4643 err = -EINPROGRESS;
4644 goto out;
4645 }
4646
807f8a8c 4647 request = kzalloc(sizeof(*request)
a2cd43c5 4648 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4649 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4650 + sizeof(*request->channels) * n_channels
807f8a8c 4651 + ie_len, GFP_KERNEL);
c10841ca
LC
4652 if (!request) {
4653 err = -ENOMEM;
4654 goto out;
4655 }
807f8a8c
LC
4656
4657 if (n_ssids)
4658 request->ssids = (void *)&request->channels[n_channels];
4659 request->n_ssids = n_ssids;
4660 if (ie_len) {
4661 if (request->ssids)
4662 request->ie = (void *)(request->ssids + n_ssids);
4663 else
4664 request->ie = (void *)(request->channels + n_channels);
4665 }
4666
a1f1c21c
LC
4667 if (n_match_sets) {
4668 if (request->ie)
4669 request->match_sets = (void *)(request->ie + ie_len);
4670 else if (request->ssids)
4671 request->match_sets =
4672 (void *)(request->ssids + n_ssids);
4673 else
4674 request->match_sets =
4675 (void *)(request->channels + n_channels);
4676 }
4677 request->n_match_sets = n_match_sets;
4678
807f8a8c
LC
4679 i = 0;
4680 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4681 /* user specified, bail out if channel not found */
4682 nla_for_each_nested(attr,
4683 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4684 tmp) {
4685 struct ieee80211_channel *chan;
4686
4687 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4688
4689 if (!chan) {
4690 err = -EINVAL;
4691 goto out_free;
4692 }
4693
4694 /* ignore disabled channels */
4695 if (chan->flags & IEEE80211_CHAN_DISABLED)
4696 continue;
4697
4698 request->channels[i] = chan;
4699 i++;
4700 }
4701 } else {
4702 /* all channels */
4703 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4704 int j;
4705 if (!wiphy->bands[band])
4706 continue;
4707 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4708 struct ieee80211_channel *chan;
4709
4710 chan = &wiphy->bands[band]->channels[j];
4711
4712 if (chan->flags & IEEE80211_CHAN_DISABLED)
4713 continue;
4714
4715 request->channels[i] = chan;
4716 i++;
4717 }
4718 }
4719 }
4720
4721 if (!i) {
4722 err = -EINVAL;
4723 goto out_free;
4724 }
4725
4726 request->n_channels = i;
4727
4728 i = 0;
4729 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4730 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4731 tmp) {
57a27e1d 4732 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4733 err = -EINVAL;
4734 goto out_free;
4735 }
57a27e1d 4736 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4737 memcpy(request->ssids[i].ssid, nla_data(attr),
4738 nla_len(attr));
807f8a8c
LC
4739 i++;
4740 }
4741 }
4742
a1f1c21c
LC
4743 i = 0;
4744 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4745 nla_for_each_nested(attr,
4746 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4747 tmp) {
88e920b4 4748 struct nlattr *ssid, *rssi;
a1f1c21c
LC
4749
4750 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4751 nla_data(attr), nla_len(attr),
4752 nl80211_match_policy);
4a4ab0d7 4753 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4754 if (ssid) {
4755 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4756 err = -EINVAL;
4757 goto out_free;
4758 }
4759 memcpy(request->match_sets[i].ssid.ssid,
4760 nla_data(ssid), nla_len(ssid));
4761 request->match_sets[i].ssid.ssid_len =
4762 nla_len(ssid);
4763 }
88e920b4
TP
4764 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
4765 if (rssi)
4766 request->rssi_thold = nla_get_u32(rssi);
4767 else
4768 request->rssi_thold =
4769 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
4770 i++;
4771 }
4772 }
4773
807f8a8c
LC
4774 if (info->attrs[NL80211_ATTR_IE]) {
4775 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4776 memcpy((void *)request->ie,
4777 nla_data(info->attrs[NL80211_ATTR_IE]),
4778 request->ie_len);
4779 }
4780
46856bbf 4781 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4782 request->flags = nla_get_u32(
4783 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4784 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4785 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4786 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4787 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4788 err = -EOPNOTSUPP;
4789 goto out_free;
4790 }
4791 }
ed473771 4792
807f8a8c
LC
4793 request->dev = dev;
4794 request->wiphy = &rdev->wiphy;
bbe6ad6d 4795 request->interval = interval;
15d6030b 4796 request->scan_start = jiffies;
807f8a8c 4797
e35e4d28 4798 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
4799 if (!err) {
4800 rdev->sched_scan_req = request;
4801 nl80211_send_sched_scan(rdev, dev,
4802 NL80211_CMD_START_SCHED_SCAN);
4803 goto out;
4804 }
4805
4806out_free:
4807 kfree(request);
4808out:
c10841ca 4809 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4810 return err;
4811}
4812
4813static int nl80211_stop_sched_scan(struct sk_buff *skb,
4814 struct genl_info *info)
4815{
4816 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4817 int err;
807f8a8c
LC
4818
4819 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4820 !rdev->ops->sched_scan_stop)
4821 return -EOPNOTSUPP;
4822
c10841ca
LC
4823 mutex_lock(&rdev->sched_scan_mtx);
4824 err = __cfg80211_stop_sched_scan(rdev, false);
4825 mutex_unlock(&rdev->sched_scan_mtx);
4826
4827 return err;
807f8a8c
LC
4828}
4829
9720bb3a
JB
4830static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4831 u32 seq, int flags,
2a519311 4832 struct cfg80211_registered_device *rdev,
48ab905d
JB
4833 struct wireless_dev *wdev,
4834 struct cfg80211_internal_bss *intbss)
2a519311 4835{
48ab905d 4836 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
4837 void *hdr;
4838 struct nlattr *bss;
48ab905d
JB
4839
4840 ASSERT_WDEV_LOCK(wdev);
2a519311 4841
15e47304 4842 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
4843 NL80211_CMD_NEW_SCAN_RESULTS);
4844 if (!hdr)
4845 return -1;
4846
9720bb3a
JB
4847 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4848
9360ffd1
DM
4849 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
4850 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
4851 goto nla_put_failure;
2a519311
JB
4852
4853 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4854 if (!bss)
4855 goto nla_put_failure;
9360ffd1
DM
4856 if ((!is_zero_ether_addr(res->bssid) &&
4857 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)) ||
4858 (res->information_elements && res->len_information_elements &&
4859 nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4860 res->len_information_elements,
4861 res->information_elements)) ||
4862 (res->beacon_ies && res->len_beacon_ies &&
4863 res->beacon_ies != res->information_elements &&
4864 nla_put(msg, NL80211_BSS_BEACON_IES,
4865 res->len_beacon_ies, res->beacon_ies)))
4866 goto nla_put_failure;
4867 if (res->tsf &&
4868 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
4869 goto nla_put_failure;
4870 if (res->beacon_interval &&
4871 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
4872 goto nla_put_failure;
4873 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
4874 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
4875 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
4876 jiffies_to_msecs(jiffies - intbss->ts)))
4877 goto nla_put_failure;
2a519311 4878
77965c97 4879 switch (rdev->wiphy.signal_type) {
2a519311 4880 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
4881 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
4882 goto nla_put_failure;
2a519311
JB
4883 break;
4884 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
4885 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
4886 goto nla_put_failure;
2a519311
JB
4887 break;
4888 default:
4889 break;
4890 }
4891
48ab905d 4892 switch (wdev->iftype) {
074ac8df 4893 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 4894 case NL80211_IFTYPE_STATION:
9360ffd1
DM
4895 if (intbss == wdev->current_bss &&
4896 nla_put_u32(msg, NL80211_BSS_STATUS,
4897 NL80211_BSS_STATUS_ASSOCIATED))
4898 goto nla_put_failure;
48ab905d
JB
4899 break;
4900 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
4901 if (intbss == wdev->current_bss &&
4902 nla_put_u32(msg, NL80211_BSS_STATUS,
4903 NL80211_BSS_STATUS_IBSS_JOINED))
4904 goto nla_put_failure;
48ab905d
JB
4905 break;
4906 default:
4907 break;
4908 }
4909
2a519311
JB
4910 nla_nest_end(msg, bss);
4911
4912 return genlmsg_end(msg, hdr);
4913
4914 nla_put_failure:
4915 genlmsg_cancel(msg, hdr);
4916 return -EMSGSIZE;
4917}
4918
4919static int nl80211_dump_scan(struct sk_buff *skb,
4920 struct netlink_callback *cb)
4921{
48ab905d
JB
4922 struct cfg80211_registered_device *rdev;
4923 struct net_device *dev;
2a519311 4924 struct cfg80211_internal_bss *scan;
48ab905d 4925 struct wireless_dev *wdev;
2a519311
JB
4926 int start = cb->args[1], idx = 0;
4927 int err;
4928
67748893
JB
4929 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4930 if (err)
4931 return err;
2a519311 4932
48ab905d 4933 wdev = dev->ieee80211_ptr;
2a519311 4934
48ab905d
JB
4935 wdev_lock(wdev);
4936 spin_lock_bh(&rdev->bss_lock);
4937 cfg80211_bss_expire(rdev);
4938
9720bb3a
JB
4939 cb->seq = rdev->bss_generation;
4940
48ab905d 4941 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4942 if (++idx <= start)
4943 continue;
9720bb3a 4944 if (nl80211_send_bss(skb, cb,
2a519311 4945 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4946 rdev, wdev, scan) < 0) {
2a519311 4947 idx--;
67748893 4948 break;
2a519311
JB
4949 }
4950 }
4951
48ab905d
JB
4952 spin_unlock_bh(&rdev->bss_lock);
4953 wdev_unlock(wdev);
2a519311
JB
4954
4955 cb->args[1] = idx;
67748893 4956 nl80211_finish_netdev_dump(rdev);
2a519311 4957
67748893 4958 return skb->len;
2a519311
JB
4959}
4960
15e47304 4961static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
4962 int flags, struct net_device *dev,
4963 struct survey_info *survey)
4964{
4965 void *hdr;
4966 struct nlattr *infoattr;
4967
15e47304 4968 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
4969 NL80211_CMD_NEW_SURVEY_RESULTS);
4970 if (!hdr)
4971 return -ENOMEM;
4972
9360ffd1
DM
4973 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
4974 goto nla_put_failure;
61fa713c
HS
4975
4976 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4977 if (!infoattr)
4978 goto nla_put_failure;
4979
9360ffd1
DM
4980 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4981 survey->channel->center_freq))
4982 goto nla_put_failure;
4983
4984 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
4985 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
4986 goto nla_put_failure;
4987 if ((survey->filled & SURVEY_INFO_IN_USE) &&
4988 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
4989 goto nla_put_failure;
4990 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
4991 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4992 survey->channel_time))
4993 goto nla_put_failure;
4994 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
4995 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4996 survey->channel_time_busy))
4997 goto nla_put_failure;
4998 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
4999 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5000 survey->channel_time_ext_busy))
5001 goto nla_put_failure;
5002 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5003 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5004 survey->channel_time_rx))
5005 goto nla_put_failure;
5006 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5007 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5008 survey->channel_time_tx))
5009 goto nla_put_failure;
61fa713c
HS
5010
5011 nla_nest_end(msg, infoattr);
5012
5013 return genlmsg_end(msg, hdr);
5014
5015 nla_put_failure:
5016 genlmsg_cancel(msg, hdr);
5017 return -EMSGSIZE;
5018}
5019
5020static int nl80211_dump_survey(struct sk_buff *skb,
5021 struct netlink_callback *cb)
5022{
5023 struct survey_info survey;
5024 struct cfg80211_registered_device *dev;
5025 struct net_device *netdev;
61fa713c
HS
5026 int survey_idx = cb->args[1];
5027 int res;
5028
67748893
JB
5029 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
5030 if (res)
5031 return res;
61fa713c
HS
5032
5033 if (!dev->ops->dump_survey) {
5034 res = -EOPNOTSUPP;
5035 goto out_err;
5036 }
5037
5038 while (1) {
180cdc79
LR
5039 struct ieee80211_channel *chan;
5040
e35e4d28 5041 res = rdev_dump_survey(dev, netdev, survey_idx, &survey);
61fa713c
HS
5042 if (res == -ENOENT)
5043 break;
5044 if (res)
5045 goto out_err;
5046
180cdc79
LR
5047 /* Survey without a channel doesn't make sense */
5048 if (!survey.channel) {
5049 res = -EINVAL;
5050 goto out;
5051 }
5052
5053 chan = ieee80211_get_channel(&dev->wiphy,
5054 survey.channel->center_freq);
5055 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5056 survey_idx++;
5057 continue;
5058 }
5059
61fa713c 5060 if (nl80211_send_survey(skb,
15e47304 5061 NETLINK_CB(cb->skb).portid,
61fa713c
HS
5062 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5063 netdev,
5064 &survey) < 0)
5065 goto out;
5066 survey_idx++;
5067 }
5068
5069 out:
5070 cb->args[1] = survey_idx;
5071 res = skb->len;
5072 out_err:
67748893 5073 nl80211_finish_netdev_dump(dev);
61fa713c
HS
5074 return res;
5075}
5076
b23aa676
SO
5077static bool nl80211_valid_wpa_versions(u32 wpa_versions)
5078{
5079 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
5080 NL80211_WPA_VERSION_2));
5081}
5082
636a5d36
JM
5083static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
5084{
4c476991
JB
5085 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5086 struct net_device *dev = info->user_ptr[1];
19957bb3 5087 struct ieee80211_channel *chan;
e39e5b5e
JM
5088 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
5089 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 5090 enum nl80211_auth_type auth_type;
fffd0934 5091 struct key_parse key;
d5cdfacb 5092 bool local_state_change;
636a5d36 5093
f4a11bb0
JB
5094 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5095 return -EINVAL;
5096
5097 if (!info->attrs[NL80211_ATTR_MAC])
5098 return -EINVAL;
5099
1778092e
JM
5100 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
5101 return -EINVAL;
5102
19957bb3
JB
5103 if (!info->attrs[NL80211_ATTR_SSID])
5104 return -EINVAL;
5105
5106 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
5107 return -EINVAL;
5108
fffd0934
JB
5109 err = nl80211_parse_key(info, &key);
5110 if (err)
5111 return err;
5112
5113 if (key.idx >= 0) {
e31b8213
JB
5114 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
5115 return -EINVAL;
fffd0934
JB
5116 if (!key.p.key || !key.p.key_len)
5117 return -EINVAL;
5118 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
5119 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
5120 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
5121 key.p.key_len != WLAN_KEY_LEN_WEP104))
5122 return -EINVAL;
5123 if (key.idx > 4)
5124 return -EINVAL;
5125 } else {
5126 key.p.key_len = 0;
5127 key.p.key = NULL;
5128 }
5129
afea0b7a
JB
5130 if (key.idx >= 0) {
5131 int i;
5132 bool ok = false;
5133 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
5134 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
5135 ok = true;
5136 break;
5137 }
5138 }
4c476991
JB
5139 if (!ok)
5140 return -EINVAL;
afea0b7a
JB
5141 }
5142
4c476991
JB
5143 if (!rdev->ops->auth)
5144 return -EOPNOTSUPP;
636a5d36 5145
074ac8df 5146 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5147 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5148 return -EOPNOTSUPP;
eec60b03 5149
19957bb3 5150 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 5151 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 5152 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5153 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5154 return -EINVAL;
636a5d36 5155
19957bb3
JB
5156 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5157 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5158
5159 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5160 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5161 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5162 }
5163
19957bb3 5164 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 5165 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 5166 return -EINVAL;
636a5d36 5167
e39e5b5e
JM
5168 if (auth_type == NL80211_AUTHTYPE_SAE &&
5169 !info->attrs[NL80211_ATTR_SAE_DATA])
5170 return -EINVAL;
5171
5172 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
5173 if (auth_type != NL80211_AUTHTYPE_SAE)
5174 return -EINVAL;
5175 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
5176 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
5177 /* need to include at least Auth Transaction and Status Code */
5178 if (sae_data_len < 4)
5179 return -EINVAL;
5180 }
5181
d5cdfacb
JM
5182 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5183
95de817b
JB
5184 /*
5185 * Since we no longer track auth state, ignore
5186 * requests to only change local state.
5187 */
5188 if (local_state_change)
5189 return 0;
5190
4c476991
JB
5191 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
5192 ssid, ssid_len, ie, ie_len,
e39e5b5e
JM
5193 key.p.key, key.p.key_len, key.idx,
5194 sae_data, sae_data_len);
636a5d36
JM
5195}
5196
c0692b8f
JB
5197static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
5198 struct genl_info *info,
3dc27d25
JB
5199 struct cfg80211_crypto_settings *settings,
5200 int cipher_limit)
b23aa676 5201{
c0b2bbd8
JB
5202 memset(settings, 0, sizeof(*settings));
5203
b23aa676
SO
5204 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
5205
c0692b8f
JB
5206 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
5207 u16 proto;
5208 proto = nla_get_u16(
5209 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
5210 settings->control_port_ethertype = cpu_to_be16(proto);
5211 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
5212 proto != ETH_P_PAE)
5213 return -EINVAL;
5214 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
5215 settings->control_port_no_encrypt = true;
5216 } else
5217 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
5218
b23aa676
SO
5219 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
5220 void *data;
5221 int len, i;
5222
5223 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5224 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5225 settings->n_ciphers_pairwise = len / sizeof(u32);
5226
5227 if (len % sizeof(u32))
5228 return -EINVAL;
5229
3dc27d25 5230 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
5231 return -EINVAL;
5232
5233 memcpy(settings->ciphers_pairwise, data, len);
5234
5235 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
5236 if (!cfg80211_supported_cipher_suite(
5237 &rdev->wiphy,
b23aa676
SO
5238 settings->ciphers_pairwise[i]))
5239 return -EINVAL;
5240 }
5241
5242 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
5243 settings->cipher_group =
5244 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
5245 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
5246 settings->cipher_group))
b23aa676
SO
5247 return -EINVAL;
5248 }
5249
5250 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
5251 settings->wpa_versions =
5252 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
5253 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
5254 return -EINVAL;
5255 }
5256
5257 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
5258 void *data;
6d30240e 5259 int len;
b23aa676
SO
5260
5261 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
5262 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
5263 settings->n_akm_suites = len / sizeof(u32);
5264
5265 if (len % sizeof(u32))
5266 return -EINVAL;
5267
1b9ca027
JM
5268 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
5269 return -EINVAL;
5270
b23aa676 5271 memcpy(settings->akm_suites, data, len);
b23aa676
SO
5272 }
5273
5274 return 0;
5275}
5276
636a5d36
JM
5277static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
5278{
4c476991
JB
5279 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5280 struct net_device *dev = info->user_ptr[1];
19957bb3 5281 struct cfg80211_crypto_settings crypto;
f444de05 5282 struct ieee80211_channel *chan;
3e5d7649 5283 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
5284 int err, ssid_len, ie_len = 0;
5285 bool use_mfp = false;
7e7c8926
BG
5286 u32 flags = 0;
5287 struct ieee80211_ht_cap *ht_capa = NULL;
5288 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 5289
f4a11bb0
JB
5290 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5291 return -EINVAL;
5292
5293 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
5294 !info->attrs[NL80211_ATTR_SSID] ||
5295 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
5296 return -EINVAL;
5297
4c476991
JB
5298 if (!rdev->ops->assoc)
5299 return -EOPNOTSUPP;
636a5d36 5300
074ac8df 5301 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5302 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5303 return -EOPNOTSUPP;
eec60b03 5304
19957bb3 5305 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5306
19957bb3
JB
5307 chan = ieee80211_get_channel(&rdev->wiphy,
5308 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5309 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5310 return -EINVAL;
636a5d36 5311
19957bb3
JB
5312 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5313 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5314
5315 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5316 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5317 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5318 }
5319
dc6382ce 5320 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 5321 enum nl80211_mfp mfp =
dc6382ce 5322 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 5323 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 5324 use_mfp = true;
4c476991
JB
5325 else if (mfp != NL80211_MFP_NO)
5326 return -EINVAL;
dc6382ce
JM
5327 }
5328
3e5d7649
JB
5329 if (info->attrs[NL80211_ATTR_PREV_BSSID])
5330 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
5331
7e7c8926
BG
5332 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5333 flags |= ASSOC_REQ_DISABLE_HT;
5334
5335 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5336 ht_capa_mask =
5337 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
5338
5339 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5340 if (!ht_capa_mask)
5341 return -EINVAL;
5342 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5343 }
5344
c0692b8f 5345 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 5346 if (!err)
3e5d7649
JB
5347 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
5348 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
5349 &crypto, flags, ht_capa,
5350 ht_capa_mask);
636a5d36 5351
636a5d36
JM
5352 return err;
5353}
5354
5355static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
5356{
4c476991
JB
5357 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5358 struct net_device *dev = info->user_ptr[1];
19957bb3 5359 const u8 *ie = NULL, *bssid;
4c476991 5360 int ie_len = 0;
19957bb3 5361 u16 reason_code;
d5cdfacb 5362 bool local_state_change;
636a5d36 5363
f4a11bb0
JB
5364 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5365 return -EINVAL;
5366
5367 if (!info->attrs[NL80211_ATTR_MAC])
5368 return -EINVAL;
5369
5370 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5371 return -EINVAL;
5372
4c476991
JB
5373 if (!rdev->ops->deauth)
5374 return -EOPNOTSUPP;
636a5d36 5375
074ac8df 5376 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5377 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5378 return -EOPNOTSUPP;
eec60b03 5379
19957bb3 5380 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5381
19957bb3
JB
5382 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5383 if (reason_code == 0) {
f4a11bb0 5384 /* Reason Code 0 is reserved */
4c476991 5385 return -EINVAL;
255e737e 5386 }
636a5d36
JM
5387
5388 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5389 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5390 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5391 }
5392
d5cdfacb
JM
5393 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5394
4c476991
JB
5395 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
5396 local_state_change);
636a5d36
JM
5397}
5398
5399static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
5400{
4c476991
JB
5401 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5402 struct net_device *dev = info->user_ptr[1];
19957bb3 5403 const u8 *ie = NULL, *bssid;
4c476991 5404 int ie_len = 0;
19957bb3 5405 u16 reason_code;
d5cdfacb 5406 bool local_state_change;
636a5d36 5407
f4a11bb0
JB
5408 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5409 return -EINVAL;
5410
5411 if (!info->attrs[NL80211_ATTR_MAC])
5412 return -EINVAL;
5413
5414 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5415 return -EINVAL;
5416
4c476991
JB
5417 if (!rdev->ops->disassoc)
5418 return -EOPNOTSUPP;
636a5d36 5419
074ac8df 5420 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5421 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5422 return -EOPNOTSUPP;
eec60b03 5423
19957bb3 5424 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5425
19957bb3
JB
5426 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5427 if (reason_code == 0) {
f4a11bb0 5428 /* Reason Code 0 is reserved */
4c476991 5429 return -EINVAL;
255e737e 5430 }
636a5d36
JM
5431
5432 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5433 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5434 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5435 }
5436
d5cdfacb
JM
5437 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5438
4c476991
JB
5439 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
5440 local_state_change);
636a5d36
JM
5441}
5442
dd5b4cc7
FF
5443static bool
5444nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
5445 int mcast_rate[IEEE80211_NUM_BANDS],
5446 int rateval)
5447{
5448 struct wiphy *wiphy = &rdev->wiphy;
5449 bool found = false;
5450 int band, i;
5451
5452 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5453 struct ieee80211_supported_band *sband;
5454
5455 sband = wiphy->bands[band];
5456 if (!sband)
5457 continue;
5458
5459 for (i = 0; i < sband->n_bitrates; i++) {
5460 if (sband->bitrates[i].bitrate == rateval) {
5461 mcast_rate[band] = i + 1;
5462 found = true;
5463 break;
5464 }
5465 }
5466 }
5467
5468 return found;
5469}
5470
04a773ad
JB
5471static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
5472{
4c476991
JB
5473 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5474 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
5475 struct cfg80211_ibss_params ibss;
5476 struct wiphy *wiphy;
fffd0934 5477 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
5478 int err;
5479
8e30bc55
JB
5480 memset(&ibss, 0, sizeof(ibss));
5481
04a773ad
JB
5482 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5483 return -EINVAL;
5484
683b6d3b 5485 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
5486 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5487 return -EINVAL;
5488
8e30bc55
JB
5489 ibss.beacon_interval = 100;
5490
5491 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
5492 ibss.beacon_interval =
5493 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5494 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
5495 return -EINVAL;
5496 }
5497
4c476991
JB
5498 if (!rdev->ops->join_ibss)
5499 return -EOPNOTSUPP;
04a773ad 5500
4c476991
JB
5501 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5502 return -EOPNOTSUPP;
04a773ad 5503
79c97e97 5504 wiphy = &rdev->wiphy;
04a773ad 5505
39193498 5506 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 5507 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
5508
5509 if (!is_valid_ether_addr(ibss.bssid))
5510 return -EINVAL;
5511 }
04a773ad
JB
5512 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5513 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5514
5515 if (info->attrs[NL80211_ATTR_IE]) {
5516 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5517 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5518 }
5519
683b6d3b
JB
5520 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
5521 if (err)
5522 return err;
04a773ad 5523
683b6d3b 5524 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
5525 return -EINVAL;
5526
db9c64cf
JB
5527 if (ibss.chandef.width > NL80211_CHAN_WIDTH_40)
5528 return -EINVAL;
5529 if (ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
5530 !(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
5531
04a773ad 5532 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5533 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5534
fbd2c8dc
TP
5535 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5536 u8 *rates =
5537 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5538 int n_rates =
5539 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5540 struct ieee80211_supported_band *sband =
683b6d3b 5541 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 5542
34850ab2
JB
5543 err = ieee80211_get_ratemask(sband, rates, n_rates,
5544 &ibss.basic_rates);
5545 if (err)
5546 return err;
fbd2c8dc 5547 }
dd5b4cc7
FF
5548
5549 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5550 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5551 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5552 return -EINVAL;
fbd2c8dc 5553
4c476991 5554 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
5555 bool no_ht = false;
5556
4c476991 5557 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
5558 info->attrs[NL80211_ATTR_KEYS],
5559 &no_ht);
4c476991
JB
5560 if (IS_ERR(connkeys))
5561 return PTR_ERR(connkeys);
de7044ee 5562
3d9d1d66
JB
5563 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
5564 no_ht) {
de7044ee
SM
5565 kfree(connkeys);
5566 return -EINVAL;
5567 }
4c476991 5568 }
04a773ad 5569
267335d6
AQ
5570 ibss.control_port =
5571 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5572
4c476991 5573 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5574 if (err)
5575 kfree(connkeys);
04a773ad
JB
5576 return err;
5577}
5578
5579static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5580{
4c476991
JB
5581 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5582 struct net_device *dev = info->user_ptr[1];
04a773ad 5583
4c476991
JB
5584 if (!rdev->ops->leave_ibss)
5585 return -EOPNOTSUPP;
04a773ad 5586
4c476991
JB
5587 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5588 return -EOPNOTSUPP;
04a773ad 5589
4c476991 5590 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5591}
5592
f4e583c8
AQ
5593static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
5594{
5595 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5596 struct net_device *dev = info->user_ptr[1];
5597 int mcast_rate[IEEE80211_NUM_BANDS];
5598 u32 nla_rate;
5599 int err;
5600
5601 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5602 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5603 return -EOPNOTSUPP;
5604
5605 if (!rdev->ops->set_mcast_rate)
5606 return -EOPNOTSUPP;
5607
5608 memset(mcast_rate, 0, sizeof(mcast_rate));
5609
5610 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
5611 return -EINVAL;
5612
5613 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
5614 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
5615 return -EINVAL;
5616
5617 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
5618
5619 return err;
5620}
5621
5622
aff89a9b
JB
5623#ifdef CONFIG_NL80211_TESTMODE
5624static struct genl_multicast_group nl80211_testmode_mcgrp = {
5625 .name = "testmode",
5626};
5627
5628static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5629{
4c476991 5630 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5631 int err;
5632
5633 if (!info->attrs[NL80211_ATTR_TESTDATA])
5634 return -EINVAL;
5635
aff89a9b
JB
5636 err = -EOPNOTSUPP;
5637 if (rdev->ops->testmode_cmd) {
5638 rdev->testmode_info = info;
e35e4d28 5639 err = rdev_testmode_cmd(rdev,
aff89a9b
JB
5640 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5641 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5642 rdev->testmode_info = NULL;
5643 }
5644
aff89a9b
JB
5645 return err;
5646}
5647
71063f0e
WYG
5648static int nl80211_testmode_dump(struct sk_buff *skb,
5649 struct netlink_callback *cb)
5650{
00918d33 5651 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5652 int err;
5653 long phy_idx;
5654 void *data = NULL;
5655 int data_len = 0;
5656
5657 if (cb->args[0]) {
5658 /*
5659 * 0 is a valid index, but not valid for args[0],
5660 * so we need to offset by 1.
5661 */
5662 phy_idx = cb->args[0] - 1;
5663 } else {
5664 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5665 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5666 nl80211_policy);
5667 if (err)
5668 return err;
00918d33 5669
2bd7e35d
JB
5670 mutex_lock(&cfg80211_mutex);
5671 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
5672 nl80211_fam.attrbuf);
5673 if (IS_ERR(rdev)) {
5674 mutex_unlock(&cfg80211_mutex);
5675 return PTR_ERR(rdev);
00918d33 5676 }
2bd7e35d
JB
5677 phy_idx = rdev->wiphy_idx;
5678 rdev = NULL;
5679 mutex_unlock(&cfg80211_mutex);
5680
71063f0e
WYG
5681 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5682 cb->args[1] =
5683 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5684 }
5685
5686 if (cb->args[1]) {
5687 data = nla_data((void *)cb->args[1]);
5688 data_len = nla_len((void *)cb->args[1]);
5689 }
5690
5691 mutex_lock(&cfg80211_mutex);
00918d33
JB
5692 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5693 if (!rdev) {
71063f0e
WYG
5694 mutex_unlock(&cfg80211_mutex);
5695 return -ENOENT;
5696 }
00918d33 5697 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5698 mutex_unlock(&cfg80211_mutex);
5699
00918d33 5700 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5701 err = -EOPNOTSUPP;
5702 goto out_err;
5703 }
5704
5705 while (1) {
15e47304 5706 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
5707 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5708 NL80211_CMD_TESTMODE);
5709 struct nlattr *tmdata;
5710
9360ffd1 5711 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5712 genlmsg_cancel(skb, hdr);
5713 break;
5714 }
5715
5716 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5717 if (!tmdata) {
5718 genlmsg_cancel(skb, hdr);
5719 break;
5720 }
e35e4d28 5721 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
5722 nla_nest_end(skb, tmdata);
5723
5724 if (err == -ENOBUFS || err == -ENOENT) {
5725 genlmsg_cancel(skb, hdr);
5726 break;
5727 } else if (err) {
5728 genlmsg_cancel(skb, hdr);
5729 goto out_err;
5730 }
5731
5732 genlmsg_end(skb, hdr);
5733 }
5734
5735 err = skb->len;
5736 /* see above */
5737 cb->args[0] = phy_idx + 1;
5738 out_err:
00918d33 5739 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5740 return err;
5741}
5742
aff89a9b
JB
5743static struct sk_buff *
5744__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 5745 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
5746{
5747 struct sk_buff *skb;
5748 void *hdr;
5749 struct nlattr *data;
5750
5751 skb = nlmsg_new(approxlen + 100, gfp);
5752 if (!skb)
5753 return NULL;
5754
15e47304 5755 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
5756 if (!hdr) {
5757 kfree_skb(skb);
5758 return NULL;
5759 }
5760
9360ffd1
DM
5761 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5762 goto nla_put_failure;
aff89a9b
JB
5763 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5764
5765 ((void **)skb->cb)[0] = rdev;
5766 ((void **)skb->cb)[1] = hdr;
5767 ((void **)skb->cb)[2] = data;
5768
5769 return skb;
5770
5771 nla_put_failure:
5772 kfree_skb(skb);
5773 return NULL;
5774}
5775
5776struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5777 int approxlen)
5778{
5779 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5780
5781 if (WARN_ON(!rdev->testmode_info))
5782 return NULL;
5783
5784 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 5785 rdev->testmode_info->snd_portid,
aff89a9b
JB
5786 rdev->testmode_info->snd_seq,
5787 GFP_KERNEL);
5788}
5789EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5790
5791int cfg80211_testmode_reply(struct sk_buff *skb)
5792{
5793 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5794 void *hdr = ((void **)skb->cb)[1];
5795 struct nlattr *data = ((void **)skb->cb)[2];
5796
5797 if (WARN_ON(!rdev->testmode_info)) {
5798 kfree_skb(skb);
5799 return -EINVAL;
5800 }
5801
5802 nla_nest_end(skb, data);
5803 genlmsg_end(skb, hdr);
5804 return genlmsg_reply(skb, rdev->testmode_info);
5805}
5806EXPORT_SYMBOL(cfg80211_testmode_reply);
5807
5808struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5809 int approxlen, gfp_t gfp)
5810{
5811 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5812
5813 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5814}
5815EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5816
5817void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5818{
5819 void *hdr = ((void **)skb->cb)[1];
5820 struct nlattr *data = ((void **)skb->cb)[2];
5821
5822 nla_nest_end(skb, data);
5823 genlmsg_end(skb, hdr);
5824 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5825}
5826EXPORT_SYMBOL(cfg80211_testmode_event);
5827#endif
5828
b23aa676
SO
5829static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5830{
4c476991
JB
5831 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5832 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5833 struct cfg80211_connect_params connect;
5834 struct wiphy *wiphy;
fffd0934 5835 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5836 int err;
5837
5838 memset(&connect, 0, sizeof(connect));
5839
5840 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5841 return -EINVAL;
5842
5843 if (!info->attrs[NL80211_ATTR_SSID] ||
5844 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5845 return -EINVAL;
5846
5847 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5848 connect.auth_type =
5849 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
5850 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
5851 NL80211_CMD_CONNECT))
b23aa676
SO
5852 return -EINVAL;
5853 } else
5854 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5855
5856 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5857
c0692b8f 5858 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5859 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5860 if (err)
5861 return err;
b23aa676 5862
074ac8df 5863 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5864 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5865 return -EOPNOTSUPP;
b23aa676 5866
79c97e97 5867 wiphy = &rdev->wiphy;
b23aa676 5868
4486ea98
BS
5869 connect.bg_scan_period = -1;
5870 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5871 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5872 connect.bg_scan_period =
5873 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5874 }
5875
b23aa676
SO
5876 if (info->attrs[NL80211_ATTR_MAC])
5877 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5878 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5879 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5880
5881 if (info->attrs[NL80211_ATTR_IE]) {
5882 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5883 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5884 }
5885
5886 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5887 connect.channel =
5888 ieee80211_get_channel(wiphy,
5889 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5890 if (!connect.channel ||
4c476991
JB
5891 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5892 return -EINVAL;
b23aa676
SO
5893 }
5894
fffd0934
JB
5895 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5896 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 5897 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
5898 if (IS_ERR(connkeys))
5899 return PTR_ERR(connkeys);
fffd0934
JB
5900 }
5901
7e7c8926
BG
5902 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5903 connect.flags |= ASSOC_REQ_DISABLE_HT;
5904
5905 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5906 memcpy(&connect.ht_capa_mask,
5907 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5908 sizeof(connect.ht_capa_mask));
5909
5910 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
5911 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
5912 kfree(connkeys);
7e7c8926 5913 return -EINVAL;
b4e4f47e 5914 }
7e7c8926
BG
5915 memcpy(&connect.ht_capa,
5916 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5917 sizeof(connect.ht_capa));
5918 }
5919
fffd0934 5920 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5921 if (err)
5922 kfree(connkeys);
b23aa676
SO
5923 return err;
5924}
5925
5926static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5927{
4c476991
JB
5928 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5929 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5930 u16 reason;
5931
5932 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5933 reason = WLAN_REASON_DEAUTH_LEAVING;
5934 else
5935 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5936
5937 if (reason == 0)
5938 return -EINVAL;
5939
074ac8df 5940 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5941 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5942 return -EOPNOTSUPP;
b23aa676 5943
4c476991 5944 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
5945}
5946
463d0183
JB
5947static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5948{
4c476991 5949 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
5950 struct net *net;
5951 int err;
5952 u32 pid;
5953
5954 if (!info->attrs[NL80211_ATTR_PID])
5955 return -EINVAL;
5956
5957 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5958
463d0183 5959 net = get_net_ns_by_pid(pid);
4c476991
JB
5960 if (IS_ERR(net))
5961 return PTR_ERR(net);
463d0183
JB
5962
5963 err = 0;
5964
5965 /* check if anything to do */
4c476991
JB
5966 if (!net_eq(wiphy_net(&rdev->wiphy), net))
5967 err = cfg80211_switch_netns(rdev, net);
463d0183 5968
463d0183 5969 put_net(net);
463d0183
JB
5970 return err;
5971}
5972
67fbb16b
SO
5973static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5974{
4c476991 5975 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
5976 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5977 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 5978 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
5979 struct cfg80211_pmksa pmksa;
5980
5981 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5982
5983 if (!info->attrs[NL80211_ATTR_MAC])
5984 return -EINVAL;
5985
5986 if (!info->attrs[NL80211_ATTR_PMKID])
5987 return -EINVAL;
5988
67fbb16b
SO
5989 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5990 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5991
074ac8df 5992 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5993 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5994 return -EOPNOTSUPP;
67fbb16b
SO
5995
5996 switch (info->genlhdr->cmd) {
5997 case NL80211_CMD_SET_PMKSA:
5998 rdev_ops = rdev->ops->set_pmksa;
5999 break;
6000 case NL80211_CMD_DEL_PMKSA:
6001 rdev_ops = rdev->ops->del_pmksa;
6002 break;
6003 default:
6004 WARN_ON(1);
6005 break;
6006 }
6007
4c476991
JB
6008 if (!rdev_ops)
6009 return -EOPNOTSUPP;
67fbb16b 6010
4c476991 6011 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
6012}
6013
6014static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
6015{
4c476991
JB
6016 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6017 struct net_device *dev = info->user_ptr[1];
67fbb16b 6018
074ac8df 6019 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6020 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6021 return -EOPNOTSUPP;
67fbb16b 6022
4c476991
JB
6023 if (!rdev->ops->flush_pmksa)
6024 return -EOPNOTSUPP;
67fbb16b 6025
e35e4d28 6026 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
6027}
6028
109086ce
AN
6029static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
6030{
6031 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6032 struct net_device *dev = info->user_ptr[1];
6033 u8 action_code, dialog_token;
6034 u16 status_code;
6035 u8 *peer;
6036
6037 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6038 !rdev->ops->tdls_mgmt)
6039 return -EOPNOTSUPP;
6040
6041 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
6042 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
6043 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
6044 !info->attrs[NL80211_ATTR_IE] ||
6045 !info->attrs[NL80211_ATTR_MAC])
6046 return -EINVAL;
6047
6048 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6049 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
6050 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
6051 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
6052
e35e4d28
HG
6053 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
6054 dialog_token, status_code,
6055 nla_data(info->attrs[NL80211_ATTR_IE]),
6056 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
6057}
6058
6059static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
6060{
6061 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6062 struct net_device *dev = info->user_ptr[1];
6063 enum nl80211_tdls_operation operation;
6064 u8 *peer;
6065
6066 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6067 !rdev->ops->tdls_oper)
6068 return -EOPNOTSUPP;
6069
6070 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
6071 !info->attrs[NL80211_ATTR_MAC])
6072 return -EINVAL;
6073
6074 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
6075 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6076
e35e4d28 6077 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
6078}
6079
9588bbd5
JM
6080static int nl80211_remain_on_channel(struct sk_buff *skb,
6081 struct genl_info *info)
6082{
4c476991 6083 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6084 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6085 struct cfg80211_chan_def chandef;
9588bbd5
JM
6086 struct sk_buff *msg;
6087 void *hdr;
6088 u64 cookie;
683b6d3b 6089 u32 duration;
9588bbd5
JM
6090 int err;
6091
6092 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6093 !info->attrs[NL80211_ATTR_DURATION])
6094 return -EINVAL;
6095
6096 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
6097
ebf348fc
JB
6098 if (!rdev->ops->remain_on_channel ||
6099 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
6100 return -EOPNOTSUPP;
6101
9588bbd5 6102 /*
ebf348fc
JB
6103 * We should be on that channel for at least a minimum amount of
6104 * time (10ms) but no longer than the driver supports.
9588bbd5 6105 */
ebf348fc 6106 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 6107 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
6108 return -EINVAL;
6109
683b6d3b
JB
6110 err = nl80211_parse_chandef(rdev, info, &chandef);
6111 if (err)
6112 return err;
9588bbd5
JM
6113
6114 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6115 if (!msg)
6116 return -ENOMEM;
9588bbd5 6117
15e47304 6118 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5
JM
6119 NL80211_CMD_REMAIN_ON_CHANNEL);
6120
6121 if (IS_ERR(hdr)) {
6122 err = PTR_ERR(hdr);
6123 goto free_msg;
6124 }
6125
683b6d3b
JB
6126 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
6127 duration, &cookie);
9588bbd5
JM
6128
6129 if (err)
6130 goto free_msg;
6131
9360ffd1
DM
6132 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6133 goto nla_put_failure;
9588bbd5
JM
6134
6135 genlmsg_end(msg, hdr);
4c476991
JB
6136
6137 return genlmsg_reply(msg, info);
9588bbd5
JM
6138
6139 nla_put_failure:
6140 err = -ENOBUFS;
6141 free_msg:
6142 nlmsg_free(msg);
9588bbd5
JM
6143 return err;
6144}
6145
6146static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
6147 struct genl_info *info)
6148{
4c476991 6149 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6150 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 6151 u64 cookie;
9588bbd5
JM
6152
6153 if (!info->attrs[NL80211_ATTR_COOKIE])
6154 return -EINVAL;
6155
4c476991
JB
6156 if (!rdev->ops->cancel_remain_on_channel)
6157 return -EOPNOTSUPP;
9588bbd5 6158
9588bbd5
JM
6159 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6160
e35e4d28 6161 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
6162}
6163
13ae75b1
JM
6164static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
6165 u8 *rates, u8 rates_len)
6166{
6167 u8 i;
6168 u32 mask = 0;
6169
6170 for (i = 0; i < rates_len; i++) {
6171 int rate = (rates[i] & 0x7f) * 5;
6172 int ridx;
6173 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
6174 struct ieee80211_rate *srate =
6175 &sband->bitrates[ridx];
6176 if (rate == srate->bitrate) {
6177 mask |= 1 << ridx;
6178 break;
6179 }
6180 }
6181 if (ridx == sband->n_bitrates)
6182 return 0; /* rate not found */
6183 }
6184
6185 return mask;
6186}
6187
24db78c0
SW
6188static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
6189 u8 *rates, u8 rates_len,
6190 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
6191{
6192 u8 i;
6193
6194 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
6195
6196 for (i = 0; i < rates_len; i++) {
6197 int ridx, rbit;
6198
6199 ridx = rates[i] / 8;
6200 rbit = BIT(rates[i] % 8);
6201
6202 /* check validity */
910570b5 6203 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
6204 return false;
6205
6206 /* check availability */
6207 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
6208 mcs[ridx] |= rbit;
6209 else
6210 return false;
6211 }
6212
6213 return true;
6214}
6215
b54452b0 6216static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
6217 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
6218 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
6219 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
6220 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
6221};
6222
6223static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
6224 struct genl_info *info)
6225{
6226 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 6227 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 6228 struct cfg80211_bitrate_mask mask;
4c476991
JB
6229 int rem, i;
6230 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
6231 struct nlattr *tx_rates;
6232 struct ieee80211_supported_band *sband;
6233
6234 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
6235 return -EINVAL;
6236
4c476991
JB
6237 if (!rdev->ops->set_bitrate_mask)
6238 return -EOPNOTSUPP;
13ae75b1
JM
6239
6240 memset(&mask, 0, sizeof(mask));
6241 /* Default to all rates enabled */
6242 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
6243 sband = rdev->wiphy.bands[i];
6244 mask.control[i].legacy =
6245 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
6246 if (sband)
6247 memcpy(mask.control[i].mcs,
6248 sband->ht_cap.mcs.rx_mask,
6249 sizeof(mask.control[i].mcs));
6250 else
6251 memset(mask.control[i].mcs, 0,
6252 sizeof(mask.control[i].mcs));
13ae75b1
JM
6253 }
6254
6255 /*
6256 * The nested attribute uses enum nl80211_band as the index. This maps
6257 * directly to the enum ieee80211_band values used in cfg80211.
6258 */
24db78c0 6259 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
6260 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
6261 {
6262 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
6263 if (band < 0 || band >= IEEE80211_NUM_BANDS)
6264 return -EINVAL;
13ae75b1 6265 sband = rdev->wiphy.bands[band];
4c476991
JB
6266 if (sband == NULL)
6267 return -EINVAL;
13ae75b1
JM
6268 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
6269 nla_len(tx_rates), nl80211_txattr_policy);
6270 if (tb[NL80211_TXRATE_LEGACY]) {
6271 mask.control[band].legacy = rateset_to_mask(
6272 sband,
6273 nla_data(tb[NL80211_TXRATE_LEGACY]),
6274 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
6275 if ((mask.control[band].legacy == 0) &&
6276 nla_len(tb[NL80211_TXRATE_LEGACY]))
6277 return -EINVAL;
24db78c0
SW
6278 }
6279 if (tb[NL80211_TXRATE_MCS]) {
6280 if (!ht_rateset_to_mask(
6281 sband,
6282 nla_data(tb[NL80211_TXRATE_MCS]),
6283 nla_len(tb[NL80211_TXRATE_MCS]),
6284 mask.control[band].mcs))
6285 return -EINVAL;
6286 }
6287
6288 if (mask.control[band].legacy == 0) {
6289 /* don't allow empty legacy rates if HT
6290 * is not even supported. */
6291 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
6292 return -EINVAL;
6293
6294 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
6295 if (mask.control[band].mcs[i])
6296 break;
6297
6298 /* legacy and mcs rates may not be both empty */
6299 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 6300 return -EINVAL;
13ae75b1
JM
6301 }
6302 }
6303
e35e4d28 6304 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
6305}
6306
2e161f78 6307static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6308{
4c476991 6309 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6310 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 6311 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
6312
6313 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
6314 return -EINVAL;
6315
2e161f78
JB
6316 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
6317 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 6318
71bbc994
JB
6319 switch (wdev->iftype) {
6320 case NL80211_IFTYPE_STATION:
6321 case NL80211_IFTYPE_ADHOC:
6322 case NL80211_IFTYPE_P2P_CLIENT:
6323 case NL80211_IFTYPE_AP:
6324 case NL80211_IFTYPE_AP_VLAN:
6325 case NL80211_IFTYPE_MESH_POINT:
6326 case NL80211_IFTYPE_P2P_GO:
98104fde 6327 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6328 break;
6329 default:
4c476991 6330 return -EOPNOTSUPP;
71bbc994 6331 }
026331c4
JM
6332
6333 /* not much point in registering if we can't reply */
4c476991
JB
6334 if (!rdev->ops->mgmt_tx)
6335 return -EOPNOTSUPP;
026331c4 6336
15e47304 6337 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
6338 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
6339 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
6340}
6341
2e161f78 6342static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6343{
4c476991 6344 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6345 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6346 struct cfg80211_chan_def chandef;
026331c4 6347 int err;
d64d373f 6348 void *hdr = NULL;
026331c4 6349 u64 cookie;
e247bd90 6350 struct sk_buff *msg = NULL;
f7ca38df 6351 unsigned int wait = 0;
e247bd90
JB
6352 bool offchan, no_cck, dont_wait_for_ack;
6353
6354 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 6355
683b6d3b 6356 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
6357 return -EINVAL;
6358
4c476991
JB
6359 if (!rdev->ops->mgmt_tx)
6360 return -EOPNOTSUPP;
026331c4 6361
71bbc994
JB
6362 switch (wdev->iftype) {
6363 case NL80211_IFTYPE_STATION:
6364 case NL80211_IFTYPE_ADHOC:
6365 case NL80211_IFTYPE_P2P_CLIENT:
6366 case NL80211_IFTYPE_AP:
6367 case NL80211_IFTYPE_AP_VLAN:
6368 case NL80211_IFTYPE_MESH_POINT:
6369 case NL80211_IFTYPE_P2P_GO:
98104fde 6370 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6371 break;
6372 default:
4c476991 6373 return -EOPNOTSUPP;
71bbc994 6374 }
026331c4 6375
f7ca38df 6376 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 6377 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
6378 return -EINVAL;
6379 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
6380
6381 /*
6382 * We should wait on the channel for at least a minimum amount
6383 * of time (10ms) but no longer than the driver supports.
6384 */
6385 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
6386 wait > rdev->wiphy.max_remain_on_channel_duration)
6387 return -EINVAL;
6388
f7ca38df
JB
6389 }
6390
f7ca38df
JB
6391 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
6392
7c4ef712
JB
6393 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
6394 return -EINVAL;
6395
e9f935e3
RM
6396 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6397
683b6d3b
JB
6398 err = nl80211_parse_chandef(rdev, info, &chandef);
6399 if (err)
6400 return err;
026331c4 6401
e247bd90
JB
6402 if (!dont_wait_for_ack) {
6403 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6404 if (!msg)
6405 return -ENOMEM;
026331c4 6406
15e47304 6407 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 6408 NL80211_CMD_FRAME);
026331c4 6409
e247bd90
JB
6410 if (IS_ERR(hdr)) {
6411 err = PTR_ERR(hdr);
6412 goto free_msg;
6413 }
026331c4 6414 }
e247bd90 6415
683b6d3b 6416 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
6417 nla_data(info->attrs[NL80211_ATTR_FRAME]),
6418 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 6419 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
6420 if (err)
6421 goto free_msg;
6422
e247bd90 6423 if (msg) {
9360ffd1
DM
6424 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6425 goto nla_put_failure;
026331c4 6426
e247bd90
JB
6427 genlmsg_end(msg, hdr);
6428 return genlmsg_reply(msg, info);
6429 }
6430
6431 return 0;
026331c4
JM
6432
6433 nla_put_failure:
6434 err = -ENOBUFS;
6435 free_msg:
6436 nlmsg_free(msg);
026331c4
JM
6437 return err;
6438}
6439
f7ca38df
JB
6440static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
6441{
6442 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6443 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
6444 u64 cookie;
6445
6446 if (!info->attrs[NL80211_ATTR_COOKIE])
6447 return -EINVAL;
6448
6449 if (!rdev->ops->mgmt_tx_cancel_wait)
6450 return -EOPNOTSUPP;
6451
71bbc994
JB
6452 switch (wdev->iftype) {
6453 case NL80211_IFTYPE_STATION:
6454 case NL80211_IFTYPE_ADHOC:
6455 case NL80211_IFTYPE_P2P_CLIENT:
6456 case NL80211_IFTYPE_AP:
6457 case NL80211_IFTYPE_AP_VLAN:
6458 case NL80211_IFTYPE_P2P_GO:
98104fde 6459 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6460 break;
6461 default:
f7ca38df 6462 return -EOPNOTSUPP;
71bbc994 6463 }
f7ca38df
JB
6464
6465 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6466
e35e4d28 6467 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
6468}
6469
ffb9eb3d
KV
6470static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
6471{
4c476991 6472 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 6473 struct wireless_dev *wdev;
4c476991 6474 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6475 u8 ps_state;
6476 bool state;
6477 int err;
6478
4c476991
JB
6479 if (!info->attrs[NL80211_ATTR_PS_STATE])
6480 return -EINVAL;
ffb9eb3d
KV
6481
6482 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
6483
4c476991
JB
6484 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
6485 return -EINVAL;
ffb9eb3d
KV
6486
6487 wdev = dev->ieee80211_ptr;
6488
4c476991
JB
6489 if (!rdev->ops->set_power_mgmt)
6490 return -EOPNOTSUPP;
ffb9eb3d
KV
6491
6492 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
6493
6494 if (state == wdev->ps)
4c476991 6495 return 0;
ffb9eb3d 6496
e35e4d28 6497 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
6498 if (!err)
6499 wdev->ps = state;
ffb9eb3d
KV
6500 return err;
6501}
6502
6503static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
6504{
4c476991 6505 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
6506 enum nl80211_ps_state ps_state;
6507 struct wireless_dev *wdev;
4c476991 6508 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6509 struct sk_buff *msg;
6510 void *hdr;
6511 int err;
6512
ffb9eb3d
KV
6513 wdev = dev->ieee80211_ptr;
6514
4c476991
JB
6515 if (!rdev->ops->set_power_mgmt)
6516 return -EOPNOTSUPP;
ffb9eb3d
KV
6517
6518 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6519 if (!msg)
6520 return -ENOMEM;
ffb9eb3d 6521
15e47304 6522 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
6523 NL80211_CMD_GET_POWER_SAVE);
6524 if (!hdr) {
4c476991 6525 err = -ENOBUFS;
ffb9eb3d
KV
6526 goto free_msg;
6527 }
6528
6529 if (wdev->ps)
6530 ps_state = NL80211_PS_ENABLED;
6531 else
6532 ps_state = NL80211_PS_DISABLED;
6533
9360ffd1
DM
6534 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6535 goto nla_put_failure;
ffb9eb3d
KV
6536
6537 genlmsg_end(msg, hdr);
4c476991 6538 return genlmsg_reply(msg, info);
ffb9eb3d 6539
4c476991 6540 nla_put_failure:
ffb9eb3d 6541 err = -ENOBUFS;
4c476991 6542 free_msg:
ffb9eb3d 6543 nlmsg_free(msg);
ffb9eb3d
KV
6544 return err;
6545}
6546
d6dc1a38
JO
6547static struct nla_policy
6548nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6549 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6550 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6551 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
6552 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
6553 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
6554 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
6555};
6556
84f10708 6557static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 6558 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
6559{
6560 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6561 struct wireless_dev *wdev;
6562 struct net_device *dev = info->user_ptr[1];
6563
d9d8b019 6564 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
6565 return -EINVAL;
6566
6567 wdev = dev->ieee80211_ptr;
6568
6569 if (!rdev->ops->set_cqm_txe_config)
6570 return -EOPNOTSUPP;
6571
6572 if (wdev->iftype != NL80211_IFTYPE_STATION &&
6573 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6574 return -EOPNOTSUPP;
6575
e35e4d28 6576 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
6577}
6578
d6dc1a38
JO
6579static int nl80211_set_cqm_rssi(struct genl_info *info,
6580 s32 threshold, u32 hysteresis)
6581{
4c476991 6582 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6583 struct wireless_dev *wdev;
4c476991 6584 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6585
6586 if (threshold > 0)
6587 return -EINVAL;
6588
d6dc1a38
JO
6589 wdev = dev->ieee80211_ptr;
6590
4c476991
JB
6591 if (!rdev->ops->set_cqm_rssi_config)
6592 return -EOPNOTSUPP;
d6dc1a38 6593
074ac8df 6594 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6595 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6596 return -EOPNOTSUPP;
d6dc1a38 6597
e35e4d28 6598 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
6599}
6600
6601static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6602{
6603 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6604 struct nlattr *cqm;
6605 int err;
6606
6607 cqm = info->attrs[NL80211_ATTR_CQM];
6608 if (!cqm) {
6609 err = -EINVAL;
6610 goto out;
6611 }
6612
6613 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6614 nl80211_attr_cqm_policy);
6615 if (err)
6616 goto out;
6617
6618 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6619 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6620 s32 threshold;
6621 u32 hysteresis;
6622 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6623 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6624 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
84f10708
TP
6625 } else if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
6626 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
6627 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
6628 u32 rate, pkts, intvl;
6629 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
6630 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
6631 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
6632 err = nl80211_set_cqm_txe(info, rate, pkts, intvl);
d6dc1a38
JO
6633 } else
6634 err = -EINVAL;
6635
6636out:
6637 return err;
6638}
6639
29cbe68c
JB
6640static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6641{
6642 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6643 struct net_device *dev = info->user_ptr[1];
6644 struct mesh_config cfg;
c80d545d 6645 struct mesh_setup setup;
29cbe68c
JB
6646 int err;
6647
6648 /* start with default */
6649 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6650 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6651
24bdd9f4 6652 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6653 /* and parse parameters if given */
24bdd9f4 6654 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6655 if (err)
6656 return err;
6657 }
6658
6659 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6660 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6661 return -EINVAL;
6662
c80d545d
JC
6663 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6664 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6665
4bb62344
CYY
6666 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6667 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6668 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6669 return -EINVAL;
6670
c80d545d
JC
6671 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6672 /* parse additional setup parameters if given */
6673 err = nl80211_parse_mesh_setup(info, &setup);
6674 if (err)
6675 return err;
6676 }
6677
cc1d2806 6678 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
6679 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
6680 if (err)
6681 return err;
cc1d2806
JB
6682 } else {
6683 /* cfg80211_join_mesh() will sort it out */
683b6d3b 6684 setup.chandef.chan = NULL;
cc1d2806
JB
6685 }
6686
c80d545d 6687 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6688}
6689
6690static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6691{
6692 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6693 struct net_device *dev = info->user_ptr[1];
6694
6695 return cfg80211_leave_mesh(rdev, dev);
6696}
6697
dfb89c56 6698#ifdef CONFIG_PM
ff1b6e69
JB
6699static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6700{
6701 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6702 struct sk_buff *msg;
6703 void *hdr;
6704
6705 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6706 return -EOPNOTSUPP;
6707
6708 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6709 if (!msg)
6710 return -ENOMEM;
6711
15e47304 6712 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
6713 NL80211_CMD_GET_WOWLAN);
6714 if (!hdr)
6715 goto nla_put_failure;
6716
6717 if (rdev->wowlan) {
6718 struct nlattr *nl_wowlan;
6719
6720 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6721 if (!nl_wowlan)
6722 goto nla_put_failure;
6723
9360ffd1
DM
6724 if ((rdev->wowlan->any &&
6725 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6726 (rdev->wowlan->disconnect &&
6727 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6728 (rdev->wowlan->magic_pkt &&
6729 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6730 (rdev->wowlan->gtk_rekey_failure &&
6731 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6732 (rdev->wowlan->eap_identity_req &&
6733 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6734 (rdev->wowlan->four_way_handshake &&
6735 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6736 (rdev->wowlan->rfkill_release &&
6737 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6738 goto nla_put_failure;
ff1b6e69
JB
6739 if (rdev->wowlan->n_patterns) {
6740 struct nlattr *nl_pats, *nl_pat;
6741 int i, pat_len;
6742
6743 nl_pats = nla_nest_start(msg,
6744 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6745 if (!nl_pats)
6746 goto nla_put_failure;
6747
6748 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6749 nl_pat = nla_nest_start(msg, i + 1);
6750 if (!nl_pat)
6751 goto nla_put_failure;
6752 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6753 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6754 DIV_ROUND_UP(pat_len, 8),
6755 rdev->wowlan->patterns[i].mask) ||
6756 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6757 pat_len,
6758 rdev->wowlan->patterns[i].pattern))
6759 goto nla_put_failure;
ff1b6e69
JB
6760 nla_nest_end(msg, nl_pat);
6761 }
6762 nla_nest_end(msg, nl_pats);
6763 }
6764
6765 nla_nest_end(msg, nl_wowlan);
6766 }
6767
6768 genlmsg_end(msg, hdr);
6769 return genlmsg_reply(msg, info);
6770
6771nla_put_failure:
6772 nlmsg_free(msg);
6773 return -ENOBUFS;
6774}
6775
6776static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6777{
6778 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6779 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 6780 struct cfg80211_wowlan new_triggers = {};
ae33bd81 6781 struct cfg80211_wowlan *ntrig;
ff1b6e69
JB
6782 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6783 int err, i;
6d52563f 6784 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6785
6786 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6787 return -EOPNOTSUPP;
6788
ae33bd81
JB
6789 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
6790 cfg80211_rdev_free_wowlan(rdev);
6791 rdev->wowlan = NULL;
6792 goto set_wakeup;
6793 }
ff1b6e69
JB
6794
6795 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6796 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6797 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6798 nl80211_wowlan_policy);
6799 if (err)
6800 return err;
6801
6802 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6803 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6804 return -EINVAL;
6805 new_triggers.any = true;
6806 }
6807
6808 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6809 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6810 return -EINVAL;
6811 new_triggers.disconnect = true;
6812 }
6813
6814 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6815 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6816 return -EINVAL;
6817 new_triggers.magic_pkt = true;
6818 }
6819
77dbbb13
JB
6820 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6821 return -EINVAL;
6822
6823 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6824 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6825 return -EINVAL;
6826 new_triggers.gtk_rekey_failure = true;
6827 }
6828
6829 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6830 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6831 return -EINVAL;
6832 new_triggers.eap_identity_req = true;
6833 }
6834
6835 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6836 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6837 return -EINVAL;
6838 new_triggers.four_way_handshake = true;
6839 }
6840
6841 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6842 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6843 return -EINVAL;
6844 new_triggers.rfkill_release = true;
6845 }
6846
ff1b6e69
JB
6847 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6848 struct nlattr *pat;
6849 int n_patterns = 0;
6850 int rem, pat_len, mask_len;
6851 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6852
6853 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6854 rem)
6855 n_patterns++;
6856 if (n_patterns > wowlan->n_patterns)
6857 return -EINVAL;
6858
6859 new_triggers.patterns = kcalloc(n_patterns,
6860 sizeof(new_triggers.patterns[0]),
6861 GFP_KERNEL);
6862 if (!new_triggers.patterns)
6863 return -ENOMEM;
6864
6865 new_triggers.n_patterns = n_patterns;
6866 i = 0;
6867
6868 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6869 rem) {
6870 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6871 nla_data(pat), nla_len(pat), NULL);
6872 err = -EINVAL;
6873 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6874 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6875 goto error;
6876 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6877 mask_len = DIV_ROUND_UP(pat_len, 8);
6878 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6879 mask_len)
6880 goto error;
6881 if (pat_len > wowlan->pattern_max_len ||
6882 pat_len < wowlan->pattern_min_len)
6883 goto error;
6884
6885 new_triggers.patterns[i].mask =
6886 kmalloc(mask_len + pat_len, GFP_KERNEL);
6887 if (!new_triggers.patterns[i].mask) {
6888 err = -ENOMEM;
6889 goto error;
6890 }
6891 new_triggers.patterns[i].pattern =
6892 new_triggers.patterns[i].mask + mask_len;
6893 memcpy(new_triggers.patterns[i].mask,
6894 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6895 mask_len);
6896 new_triggers.patterns[i].pattern_len = pat_len;
6897 memcpy(new_triggers.patterns[i].pattern,
6898 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6899 pat_len);
6900 i++;
6901 }
6902 }
6903
ae33bd81
JB
6904 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
6905 if (!ntrig) {
6906 err = -ENOMEM;
6907 goto error;
ff1b6e69 6908 }
ae33bd81
JB
6909 cfg80211_rdev_free_wowlan(rdev);
6910 rdev->wowlan = ntrig;
ff1b6e69 6911
ae33bd81 6912 set_wakeup:
6d52563f 6913 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
e35e4d28 6914 rdev_set_wakeup(rdev, rdev->wowlan);
6d52563f 6915
ff1b6e69
JB
6916 return 0;
6917 error:
6918 for (i = 0; i < new_triggers.n_patterns; i++)
6919 kfree(new_triggers.patterns[i].mask);
6920 kfree(new_triggers.patterns);
6921 return err;
6922}
dfb89c56 6923#endif
ff1b6e69 6924
e5497d76
JB
6925static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6926{
6927 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6928 struct net_device *dev = info->user_ptr[1];
6929 struct wireless_dev *wdev = dev->ieee80211_ptr;
6930 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6931 struct cfg80211_gtk_rekey_data rekey_data;
6932 int err;
6933
6934 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6935 return -EINVAL;
6936
6937 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6938 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6939 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6940 nl80211_rekey_policy);
6941 if (err)
6942 return err;
6943
6944 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6945 return -ERANGE;
6946 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6947 return -ERANGE;
6948 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6949 return -ERANGE;
6950
6951 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6952 NL80211_KEK_LEN);
6953 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6954 NL80211_KCK_LEN);
6955 memcpy(rekey_data.replay_ctr,
6956 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6957 NL80211_REPLAY_CTR_LEN);
6958
6959 wdev_lock(wdev);
6960 if (!wdev->current_bss) {
6961 err = -ENOTCONN;
6962 goto out;
6963 }
6964
6965 if (!rdev->ops->set_rekey_data) {
6966 err = -EOPNOTSUPP;
6967 goto out;
6968 }
6969
e35e4d28 6970 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
6971 out:
6972 wdev_unlock(wdev);
6973 return err;
6974}
6975
28946da7
JB
6976static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6977 struct genl_info *info)
6978{
6979 struct net_device *dev = info->user_ptr[1];
6980 struct wireless_dev *wdev = dev->ieee80211_ptr;
6981
6982 if (wdev->iftype != NL80211_IFTYPE_AP &&
6983 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6984 return -EINVAL;
6985
15e47304 6986 if (wdev->ap_unexpected_nlportid)
28946da7
JB
6987 return -EBUSY;
6988
15e47304 6989 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
6990 return 0;
6991}
6992
7f6cf311
JB
6993static int nl80211_probe_client(struct sk_buff *skb,
6994 struct genl_info *info)
6995{
6996 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6997 struct net_device *dev = info->user_ptr[1];
6998 struct wireless_dev *wdev = dev->ieee80211_ptr;
6999 struct sk_buff *msg;
7000 void *hdr;
7001 const u8 *addr;
7002 u64 cookie;
7003 int err;
7004
7005 if (wdev->iftype != NL80211_IFTYPE_AP &&
7006 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7007 return -EOPNOTSUPP;
7008
7009 if (!info->attrs[NL80211_ATTR_MAC])
7010 return -EINVAL;
7011
7012 if (!rdev->ops->probe_client)
7013 return -EOPNOTSUPP;
7014
7015 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7016 if (!msg)
7017 return -ENOMEM;
7018
15e47304 7019 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311
JB
7020 NL80211_CMD_PROBE_CLIENT);
7021
7022 if (IS_ERR(hdr)) {
7023 err = PTR_ERR(hdr);
7024 goto free_msg;
7025 }
7026
7027 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7028
e35e4d28 7029 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
7030 if (err)
7031 goto free_msg;
7032
9360ffd1
DM
7033 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7034 goto nla_put_failure;
7f6cf311
JB
7035
7036 genlmsg_end(msg, hdr);
7037
7038 return genlmsg_reply(msg, info);
7039
7040 nla_put_failure:
7041 err = -ENOBUFS;
7042 free_msg:
7043 nlmsg_free(msg);
7044 return err;
7045}
7046
5e760230
JB
7047static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
7048{
7049 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
7050 struct cfg80211_beacon_registration *reg, *nreg;
7051 int rv;
5e760230
JB
7052
7053 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
7054 return -EOPNOTSUPP;
7055
37c73b5f
BG
7056 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
7057 if (!nreg)
7058 return -ENOMEM;
7059
7060 /* First, check if already registered. */
7061 spin_lock_bh(&rdev->beacon_registrations_lock);
7062 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
7063 if (reg->nlportid == info->snd_portid) {
7064 rv = -EALREADY;
7065 goto out_err;
7066 }
7067 }
7068 /* Add it to the list */
7069 nreg->nlportid = info->snd_portid;
7070 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 7071
37c73b5f 7072 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
7073
7074 return 0;
37c73b5f
BG
7075out_err:
7076 spin_unlock_bh(&rdev->beacon_registrations_lock);
7077 kfree(nreg);
7078 return rv;
5e760230
JB
7079}
7080
98104fde
JB
7081static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
7082{
7083 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7084 struct wireless_dev *wdev = info->user_ptr[1];
7085 int err;
7086
7087 if (!rdev->ops->start_p2p_device)
7088 return -EOPNOTSUPP;
7089
7090 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7091 return -EOPNOTSUPP;
7092
7093 if (wdev->p2p_started)
7094 return 0;
7095
7096 mutex_lock(&rdev->devlist_mtx);
7097 err = cfg80211_can_add_interface(rdev, wdev->iftype);
7098 mutex_unlock(&rdev->devlist_mtx);
7099 if (err)
7100 return err;
7101
eeb126e9 7102 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
7103 if (err)
7104 return err;
7105
7106 wdev->p2p_started = true;
7107 mutex_lock(&rdev->devlist_mtx);
7108 rdev->opencount++;
7109 mutex_unlock(&rdev->devlist_mtx);
7110
7111 return 0;
7112}
7113
7114static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
7115{
7116 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7117 struct wireless_dev *wdev = info->user_ptr[1];
7118
7119 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7120 return -EOPNOTSUPP;
7121
7122 if (!rdev->ops->stop_p2p_device)
7123 return -EOPNOTSUPP;
7124
7125 if (!wdev->p2p_started)
7126 return 0;
7127
eeb126e9 7128 rdev_stop_p2p_device(rdev, wdev);
98104fde
JB
7129 wdev->p2p_started = false;
7130
7131 mutex_lock(&rdev->devlist_mtx);
7132 rdev->opencount--;
7133 mutex_unlock(&rdev->devlist_mtx);
7134
7135 if (WARN_ON(rdev->scan_req && rdev->scan_req->wdev == wdev)) {
7136 rdev->scan_req->aborted = true;
7137 ___cfg80211_scan_done(rdev, true);
7138 }
7139
7140 return 0;
7141}
7142
4c476991
JB
7143#define NL80211_FLAG_NEED_WIPHY 0x01
7144#define NL80211_FLAG_NEED_NETDEV 0x02
7145#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
7146#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
7147#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
7148 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 7149#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 7150/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
7151#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
7152 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
7153
7154static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
7155 struct genl_info *info)
7156{
7157 struct cfg80211_registered_device *rdev;
89a54e48 7158 struct wireless_dev *wdev;
4c476991 7159 struct net_device *dev;
4c476991
JB
7160 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
7161
7162 if (rtnl)
7163 rtnl_lock();
7164
7165 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 7166 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
7167 if (IS_ERR(rdev)) {
7168 if (rtnl)
7169 rtnl_unlock();
7170 return PTR_ERR(rdev);
7171 }
7172 info->user_ptr[0] = rdev;
1bf614ef
JB
7173 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
7174 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
89a54e48
JB
7175 mutex_lock(&cfg80211_mutex);
7176 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
7177 info->attrs);
7178 if (IS_ERR(wdev)) {
7179 mutex_unlock(&cfg80211_mutex);
4c476991
JB
7180 if (rtnl)
7181 rtnl_unlock();
89a54e48 7182 return PTR_ERR(wdev);
4c476991 7183 }
89a54e48 7184
89a54e48
JB
7185 dev = wdev->netdev;
7186 rdev = wiphy_to_dev(wdev->wiphy);
7187
1bf614ef
JB
7188 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
7189 if (!dev) {
7190 mutex_unlock(&cfg80211_mutex);
7191 if (rtnl)
7192 rtnl_unlock();
7193 return -EINVAL;
7194 }
7195
7196 info->user_ptr[1] = dev;
7197 } else {
7198 info->user_ptr[1] = wdev;
41265714 7199 }
1bf614ef
JB
7200
7201 if (dev) {
7202 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
7203 !netif_running(dev)) {
7204 mutex_unlock(&cfg80211_mutex);
7205 if (rtnl)
7206 rtnl_unlock();
7207 return -ENETDOWN;
7208 }
7209
7210 dev_hold(dev);
98104fde
JB
7211 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
7212 if (!wdev->p2p_started) {
7213 mutex_unlock(&cfg80211_mutex);
7214 if (rtnl)
7215 rtnl_unlock();
7216 return -ENETDOWN;
7217 }
41265714 7218 }
89a54e48 7219
89a54e48
JB
7220 cfg80211_lock_rdev(rdev);
7221
7222 mutex_unlock(&cfg80211_mutex);
7223
4c476991 7224 info->user_ptr[0] = rdev;
4c476991
JB
7225 }
7226
7227 return 0;
7228}
7229
7230static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
7231 struct genl_info *info)
7232{
7233 if (info->user_ptr[0])
7234 cfg80211_unlock_rdev(info->user_ptr[0]);
1bf614ef
JB
7235 if (info->user_ptr[1]) {
7236 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
7237 struct wireless_dev *wdev = info->user_ptr[1];
7238
7239 if (wdev->netdev)
7240 dev_put(wdev->netdev);
7241 } else {
7242 dev_put(info->user_ptr[1]);
7243 }
7244 }
4c476991
JB
7245 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
7246 rtnl_unlock();
7247}
7248
55682965
JB
7249static struct genl_ops nl80211_ops[] = {
7250 {
7251 .cmd = NL80211_CMD_GET_WIPHY,
7252 .doit = nl80211_get_wiphy,
7253 .dumpit = nl80211_dump_wiphy,
7254 .policy = nl80211_policy,
7255 /* can be retrieved by unprivileged users */
4c476991 7256 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
7257 },
7258 {
7259 .cmd = NL80211_CMD_SET_WIPHY,
7260 .doit = nl80211_set_wiphy,
7261 .policy = nl80211_policy,
7262 .flags = GENL_ADMIN_PERM,
4c476991 7263 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
7264 },
7265 {
7266 .cmd = NL80211_CMD_GET_INTERFACE,
7267 .doit = nl80211_get_interface,
7268 .dumpit = nl80211_dump_interface,
7269 .policy = nl80211_policy,
7270 /* can be retrieved by unprivileged users */
72fb2abc 7271 .internal_flags = NL80211_FLAG_NEED_WDEV,
55682965
JB
7272 },
7273 {
7274 .cmd = NL80211_CMD_SET_INTERFACE,
7275 .doit = nl80211_set_interface,
7276 .policy = nl80211_policy,
7277 .flags = GENL_ADMIN_PERM,
4c476991
JB
7278 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7279 NL80211_FLAG_NEED_RTNL,
55682965
JB
7280 },
7281 {
7282 .cmd = NL80211_CMD_NEW_INTERFACE,
7283 .doit = nl80211_new_interface,
7284 .policy = nl80211_policy,
7285 .flags = GENL_ADMIN_PERM,
4c476991
JB
7286 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7287 NL80211_FLAG_NEED_RTNL,
55682965
JB
7288 },
7289 {
7290 .cmd = NL80211_CMD_DEL_INTERFACE,
7291 .doit = nl80211_del_interface,
7292 .policy = nl80211_policy,
41ade00f 7293 .flags = GENL_ADMIN_PERM,
84efbb84 7294 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7295 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7296 },
7297 {
7298 .cmd = NL80211_CMD_GET_KEY,
7299 .doit = nl80211_get_key,
7300 .policy = nl80211_policy,
7301 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7302 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7303 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7304 },
7305 {
7306 .cmd = NL80211_CMD_SET_KEY,
7307 .doit = nl80211_set_key,
7308 .policy = nl80211_policy,
7309 .flags = GENL_ADMIN_PERM,
41265714 7310 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7311 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7312 },
7313 {
7314 .cmd = NL80211_CMD_NEW_KEY,
7315 .doit = nl80211_new_key,
7316 .policy = nl80211_policy,
7317 .flags = GENL_ADMIN_PERM,
41265714 7318 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7319 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7320 },
7321 {
7322 .cmd = NL80211_CMD_DEL_KEY,
7323 .doit = nl80211_del_key,
7324 .policy = nl80211_policy,
55682965 7325 .flags = GENL_ADMIN_PERM,
41265714 7326 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7327 NL80211_FLAG_NEED_RTNL,
55682965 7328 },
ed1b6cc7
JB
7329 {
7330 .cmd = NL80211_CMD_SET_BEACON,
7331 .policy = nl80211_policy,
7332 .flags = GENL_ADMIN_PERM,
8860020e 7333 .doit = nl80211_set_beacon,
2b5f8b0b 7334 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7335 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7336 },
7337 {
8860020e 7338 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
7339 .policy = nl80211_policy,
7340 .flags = GENL_ADMIN_PERM,
8860020e 7341 .doit = nl80211_start_ap,
2b5f8b0b 7342 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7343 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7344 },
7345 {
8860020e 7346 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
7347 .policy = nl80211_policy,
7348 .flags = GENL_ADMIN_PERM,
8860020e 7349 .doit = nl80211_stop_ap,
2b5f8b0b 7350 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7351 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 7352 },
5727ef1b
JB
7353 {
7354 .cmd = NL80211_CMD_GET_STATION,
7355 .doit = nl80211_get_station,
2ec600d6 7356 .dumpit = nl80211_dump_station,
5727ef1b 7357 .policy = nl80211_policy,
4c476991
JB
7358 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7359 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7360 },
7361 {
7362 .cmd = NL80211_CMD_SET_STATION,
7363 .doit = nl80211_set_station,
7364 .policy = nl80211_policy,
7365 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7366 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7367 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7368 },
7369 {
7370 .cmd = NL80211_CMD_NEW_STATION,
7371 .doit = nl80211_new_station,
7372 .policy = nl80211_policy,
7373 .flags = GENL_ADMIN_PERM,
41265714 7374 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7375 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7376 },
7377 {
7378 .cmd = NL80211_CMD_DEL_STATION,
7379 .doit = nl80211_del_station,
7380 .policy = nl80211_policy,
2ec600d6 7381 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7382 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7383 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7384 },
7385 {
7386 .cmd = NL80211_CMD_GET_MPATH,
7387 .doit = nl80211_get_mpath,
7388 .dumpit = nl80211_dump_mpath,
7389 .policy = nl80211_policy,
7390 .flags = GENL_ADMIN_PERM,
41265714 7391 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7392 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7393 },
7394 {
7395 .cmd = NL80211_CMD_SET_MPATH,
7396 .doit = nl80211_set_mpath,
7397 .policy = nl80211_policy,
7398 .flags = GENL_ADMIN_PERM,
41265714 7399 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7400 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7401 },
7402 {
7403 .cmd = NL80211_CMD_NEW_MPATH,
7404 .doit = nl80211_new_mpath,
7405 .policy = nl80211_policy,
7406 .flags = GENL_ADMIN_PERM,
41265714 7407 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7408 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7409 },
7410 {
7411 .cmd = NL80211_CMD_DEL_MPATH,
7412 .doit = nl80211_del_mpath,
7413 .policy = nl80211_policy,
9f1ba906 7414 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7415 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7416 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
7417 },
7418 {
7419 .cmd = NL80211_CMD_SET_BSS,
7420 .doit = nl80211_set_bss,
7421 .policy = nl80211_policy,
b2e1b302 7422 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7423 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7424 NL80211_FLAG_NEED_RTNL,
b2e1b302 7425 },
f130347c
LR
7426 {
7427 .cmd = NL80211_CMD_GET_REG,
7428 .doit = nl80211_get_reg,
7429 .policy = nl80211_policy,
7430 /* can be retrieved by unprivileged users */
7431 },
b2e1b302
LR
7432 {
7433 .cmd = NL80211_CMD_SET_REG,
7434 .doit = nl80211_set_reg,
7435 .policy = nl80211_policy,
7436 .flags = GENL_ADMIN_PERM,
7437 },
7438 {
7439 .cmd = NL80211_CMD_REQ_SET_REG,
7440 .doit = nl80211_req_set_reg,
7441 .policy = nl80211_policy,
93da9cc1 7442 .flags = GENL_ADMIN_PERM,
7443 },
7444 {
24bdd9f4
JC
7445 .cmd = NL80211_CMD_GET_MESH_CONFIG,
7446 .doit = nl80211_get_mesh_config,
93da9cc1 7447 .policy = nl80211_policy,
7448 /* can be retrieved by unprivileged users */
2b5f8b0b 7449 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7450 NL80211_FLAG_NEED_RTNL,
93da9cc1 7451 },
7452 {
24bdd9f4
JC
7453 .cmd = NL80211_CMD_SET_MESH_CONFIG,
7454 .doit = nl80211_update_mesh_config,
93da9cc1 7455 .policy = nl80211_policy,
9aed3cc1 7456 .flags = GENL_ADMIN_PERM,
29cbe68c 7457 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7458 NL80211_FLAG_NEED_RTNL,
9aed3cc1 7459 },
2a519311
JB
7460 {
7461 .cmd = NL80211_CMD_TRIGGER_SCAN,
7462 .doit = nl80211_trigger_scan,
7463 .policy = nl80211_policy,
7464 .flags = GENL_ADMIN_PERM,
fd014284 7465 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7466 NL80211_FLAG_NEED_RTNL,
2a519311
JB
7467 },
7468 {
7469 .cmd = NL80211_CMD_GET_SCAN,
7470 .policy = nl80211_policy,
7471 .dumpit = nl80211_dump_scan,
7472 },
807f8a8c
LC
7473 {
7474 .cmd = NL80211_CMD_START_SCHED_SCAN,
7475 .doit = nl80211_start_sched_scan,
7476 .policy = nl80211_policy,
7477 .flags = GENL_ADMIN_PERM,
7478 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7479 NL80211_FLAG_NEED_RTNL,
7480 },
7481 {
7482 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
7483 .doit = nl80211_stop_sched_scan,
7484 .policy = nl80211_policy,
7485 .flags = GENL_ADMIN_PERM,
7486 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7487 NL80211_FLAG_NEED_RTNL,
7488 },
636a5d36
JM
7489 {
7490 .cmd = NL80211_CMD_AUTHENTICATE,
7491 .doit = nl80211_authenticate,
7492 .policy = nl80211_policy,
7493 .flags = GENL_ADMIN_PERM,
41265714 7494 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7495 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7496 },
7497 {
7498 .cmd = NL80211_CMD_ASSOCIATE,
7499 .doit = nl80211_associate,
7500 .policy = nl80211_policy,
7501 .flags = GENL_ADMIN_PERM,
41265714 7502 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7503 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7504 },
7505 {
7506 .cmd = NL80211_CMD_DEAUTHENTICATE,
7507 .doit = nl80211_deauthenticate,
7508 .policy = nl80211_policy,
7509 .flags = GENL_ADMIN_PERM,
41265714 7510 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7511 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7512 },
7513 {
7514 .cmd = NL80211_CMD_DISASSOCIATE,
7515 .doit = nl80211_disassociate,
7516 .policy = nl80211_policy,
7517 .flags = GENL_ADMIN_PERM,
41265714 7518 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7519 NL80211_FLAG_NEED_RTNL,
636a5d36 7520 },
04a773ad
JB
7521 {
7522 .cmd = NL80211_CMD_JOIN_IBSS,
7523 .doit = nl80211_join_ibss,
7524 .policy = nl80211_policy,
7525 .flags = GENL_ADMIN_PERM,
41265714 7526 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7527 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
7528 },
7529 {
7530 .cmd = NL80211_CMD_LEAVE_IBSS,
7531 .doit = nl80211_leave_ibss,
7532 .policy = nl80211_policy,
7533 .flags = GENL_ADMIN_PERM,
41265714 7534 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7535 NL80211_FLAG_NEED_RTNL,
04a773ad 7536 },
aff89a9b
JB
7537#ifdef CONFIG_NL80211_TESTMODE
7538 {
7539 .cmd = NL80211_CMD_TESTMODE,
7540 .doit = nl80211_testmode_do,
71063f0e 7541 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
7542 .policy = nl80211_policy,
7543 .flags = GENL_ADMIN_PERM,
4c476991
JB
7544 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7545 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
7546 },
7547#endif
b23aa676
SO
7548 {
7549 .cmd = NL80211_CMD_CONNECT,
7550 .doit = nl80211_connect,
7551 .policy = nl80211_policy,
7552 .flags = GENL_ADMIN_PERM,
41265714 7553 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7554 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
7555 },
7556 {
7557 .cmd = NL80211_CMD_DISCONNECT,
7558 .doit = nl80211_disconnect,
7559 .policy = nl80211_policy,
7560 .flags = GENL_ADMIN_PERM,
41265714 7561 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7562 NL80211_FLAG_NEED_RTNL,
b23aa676 7563 },
463d0183
JB
7564 {
7565 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
7566 .doit = nl80211_wiphy_netns,
7567 .policy = nl80211_policy,
7568 .flags = GENL_ADMIN_PERM,
4c476991
JB
7569 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7570 NL80211_FLAG_NEED_RTNL,
463d0183 7571 },
61fa713c
HS
7572 {
7573 .cmd = NL80211_CMD_GET_SURVEY,
7574 .policy = nl80211_policy,
7575 .dumpit = nl80211_dump_survey,
7576 },
67fbb16b
SO
7577 {
7578 .cmd = NL80211_CMD_SET_PMKSA,
7579 .doit = nl80211_setdel_pmksa,
7580 .policy = nl80211_policy,
7581 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7582 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7583 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7584 },
7585 {
7586 .cmd = NL80211_CMD_DEL_PMKSA,
7587 .doit = nl80211_setdel_pmksa,
7588 .policy = nl80211_policy,
7589 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7590 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7591 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7592 },
7593 {
7594 .cmd = NL80211_CMD_FLUSH_PMKSA,
7595 .doit = nl80211_flush_pmksa,
7596 .policy = nl80211_policy,
7597 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7598 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7599 NL80211_FLAG_NEED_RTNL,
67fbb16b 7600 },
9588bbd5
JM
7601 {
7602 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
7603 .doit = nl80211_remain_on_channel,
7604 .policy = nl80211_policy,
7605 .flags = GENL_ADMIN_PERM,
71bbc994 7606 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7607 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
7608 },
7609 {
7610 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7611 .doit = nl80211_cancel_remain_on_channel,
7612 .policy = nl80211_policy,
7613 .flags = GENL_ADMIN_PERM,
71bbc994 7614 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7615 NL80211_FLAG_NEED_RTNL,
9588bbd5 7616 },
13ae75b1
JM
7617 {
7618 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
7619 .doit = nl80211_set_tx_bitrate_mask,
7620 .policy = nl80211_policy,
7621 .flags = GENL_ADMIN_PERM,
4c476991
JB
7622 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7623 NL80211_FLAG_NEED_RTNL,
13ae75b1 7624 },
026331c4 7625 {
2e161f78
JB
7626 .cmd = NL80211_CMD_REGISTER_FRAME,
7627 .doit = nl80211_register_mgmt,
026331c4
JM
7628 .policy = nl80211_policy,
7629 .flags = GENL_ADMIN_PERM,
71bbc994 7630 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7631 NL80211_FLAG_NEED_RTNL,
026331c4
JM
7632 },
7633 {
2e161f78
JB
7634 .cmd = NL80211_CMD_FRAME,
7635 .doit = nl80211_tx_mgmt,
026331c4 7636 .policy = nl80211_policy,
f7ca38df 7637 .flags = GENL_ADMIN_PERM,
71bbc994 7638 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
7639 NL80211_FLAG_NEED_RTNL,
7640 },
7641 {
7642 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
7643 .doit = nl80211_tx_mgmt_cancel_wait,
7644 .policy = nl80211_policy,
026331c4 7645 .flags = GENL_ADMIN_PERM,
71bbc994 7646 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7647 NL80211_FLAG_NEED_RTNL,
026331c4 7648 },
ffb9eb3d
KV
7649 {
7650 .cmd = NL80211_CMD_SET_POWER_SAVE,
7651 .doit = nl80211_set_power_save,
7652 .policy = nl80211_policy,
7653 .flags = GENL_ADMIN_PERM,
4c476991
JB
7654 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7655 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
7656 },
7657 {
7658 .cmd = NL80211_CMD_GET_POWER_SAVE,
7659 .doit = nl80211_get_power_save,
7660 .policy = nl80211_policy,
7661 /* can be retrieved by unprivileged users */
4c476991
JB
7662 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7663 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 7664 },
d6dc1a38
JO
7665 {
7666 .cmd = NL80211_CMD_SET_CQM,
7667 .doit = nl80211_set_cqm,
7668 .policy = nl80211_policy,
7669 .flags = GENL_ADMIN_PERM,
4c476991
JB
7670 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7671 NL80211_FLAG_NEED_RTNL,
d6dc1a38 7672 },
f444de05
JB
7673 {
7674 .cmd = NL80211_CMD_SET_CHANNEL,
7675 .doit = nl80211_set_channel,
7676 .policy = nl80211_policy,
7677 .flags = GENL_ADMIN_PERM,
4c476991
JB
7678 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7679 NL80211_FLAG_NEED_RTNL,
f444de05 7680 },
e8347eba
BJ
7681 {
7682 .cmd = NL80211_CMD_SET_WDS_PEER,
7683 .doit = nl80211_set_wds_peer,
7684 .policy = nl80211_policy,
7685 .flags = GENL_ADMIN_PERM,
43b19952
JB
7686 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7687 NL80211_FLAG_NEED_RTNL,
e8347eba 7688 },
29cbe68c
JB
7689 {
7690 .cmd = NL80211_CMD_JOIN_MESH,
7691 .doit = nl80211_join_mesh,
7692 .policy = nl80211_policy,
7693 .flags = GENL_ADMIN_PERM,
7694 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7695 NL80211_FLAG_NEED_RTNL,
7696 },
7697 {
7698 .cmd = NL80211_CMD_LEAVE_MESH,
7699 .doit = nl80211_leave_mesh,
7700 .policy = nl80211_policy,
7701 .flags = GENL_ADMIN_PERM,
7702 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7703 NL80211_FLAG_NEED_RTNL,
7704 },
dfb89c56 7705#ifdef CONFIG_PM
ff1b6e69
JB
7706 {
7707 .cmd = NL80211_CMD_GET_WOWLAN,
7708 .doit = nl80211_get_wowlan,
7709 .policy = nl80211_policy,
7710 /* can be retrieved by unprivileged users */
7711 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7712 NL80211_FLAG_NEED_RTNL,
7713 },
7714 {
7715 .cmd = NL80211_CMD_SET_WOWLAN,
7716 .doit = nl80211_set_wowlan,
7717 .policy = nl80211_policy,
7718 .flags = GENL_ADMIN_PERM,
7719 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7720 NL80211_FLAG_NEED_RTNL,
7721 },
dfb89c56 7722#endif
e5497d76
JB
7723 {
7724 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7725 .doit = nl80211_set_rekey_data,
7726 .policy = nl80211_policy,
7727 .flags = GENL_ADMIN_PERM,
7728 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7729 NL80211_FLAG_NEED_RTNL,
7730 },
109086ce
AN
7731 {
7732 .cmd = NL80211_CMD_TDLS_MGMT,
7733 .doit = nl80211_tdls_mgmt,
7734 .policy = nl80211_policy,
7735 .flags = GENL_ADMIN_PERM,
7736 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7737 NL80211_FLAG_NEED_RTNL,
7738 },
7739 {
7740 .cmd = NL80211_CMD_TDLS_OPER,
7741 .doit = nl80211_tdls_oper,
7742 .policy = nl80211_policy,
7743 .flags = GENL_ADMIN_PERM,
7744 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7745 NL80211_FLAG_NEED_RTNL,
7746 },
28946da7
JB
7747 {
7748 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7749 .doit = nl80211_register_unexpected_frame,
7750 .policy = nl80211_policy,
7751 .flags = GENL_ADMIN_PERM,
7752 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7753 NL80211_FLAG_NEED_RTNL,
7754 },
7f6cf311
JB
7755 {
7756 .cmd = NL80211_CMD_PROBE_CLIENT,
7757 .doit = nl80211_probe_client,
7758 .policy = nl80211_policy,
7759 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7760 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7761 NL80211_FLAG_NEED_RTNL,
7762 },
5e760230
JB
7763 {
7764 .cmd = NL80211_CMD_REGISTER_BEACONS,
7765 .doit = nl80211_register_beacons,
7766 .policy = nl80211_policy,
7767 .flags = GENL_ADMIN_PERM,
7768 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7769 NL80211_FLAG_NEED_RTNL,
7770 },
1d9d9213
SW
7771 {
7772 .cmd = NL80211_CMD_SET_NOACK_MAP,
7773 .doit = nl80211_set_noack_map,
7774 .policy = nl80211_policy,
7775 .flags = GENL_ADMIN_PERM,
7776 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7777 NL80211_FLAG_NEED_RTNL,
7778 },
98104fde
JB
7779 {
7780 .cmd = NL80211_CMD_START_P2P_DEVICE,
7781 .doit = nl80211_start_p2p_device,
7782 .policy = nl80211_policy,
7783 .flags = GENL_ADMIN_PERM,
7784 .internal_flags = NL80211_FLAG_NEED_WDEV |
7785 NL80211_FLAG_NEED_RTNL,
7786 },
7787 {
7788 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
7789 .doit = nl80211_stop_p2p_device,
7790 .policy = nl80211_policy,
7791 .flags = GENL_ADMIN_PERM,
7792 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
7793 NL80211_FLAG_NEED_RTNL,
7794 },
f4e583c8
AQ
7795 {
7796 .cmd = NL80211_CMD_SET_MCAST_RATE,
7797 .doit = nl80211_set_mcast_rate,
7798 .policy = nl80211_policy,
7799 .flags = GENL_ADMIN_PERM,
7800 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7801 NL80211_FLAG_NEED_RTNL,
7802 },
55682965 7803};
9588bbd5 7804
6039f6d2
JM
7805static struct genl_multicast_group nl80211_mlme_mcgrp = {
7806 .name = "mlme",
7807};
55682965
JB
7808
7809/* multicast groups */
7810static struct genl_multicast_group nl80211_config_mcgrp = {
7811 .name = "config",
7812};
2a519311
JB
7813static struct genl_multicast_group nl80211_scan_mcgrp = {
7814 .name = "scan",
7815};
73d54c9e
LR
7816static struct genl_multicast_group nl80211_regulatory_mcgrp = {
7817 .name = "regulatory",
7818};
55682965
JB
7819
7820/* notification functions */
7821
7822void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
7823{
7824 struct sk_buff *msg;
7825
fd2120ca 7826 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
7827 if (!msg)
7828 return;
7829
7830 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
7831 nlmsg_free(msg);
7832 return;
7833 }
7834
463d0183
JB
7835 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7836 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
7837}
7838
362a415d
JB
7839static int nl80211_add_scan_req(struct sk_buff *msg,
7840 struct cfg80211_registered_device *rdev)
7841{
7842 struct cfg80211_scan_request *req = rdev->scan_req;
7843 struct nlattr *nest;
7844 int i;
7845
667503dd
JB
7846 ASSERT_RDEV_LOCK(rdev);
7847
362a415d
JB
7848 if (WARN_ON(!req))
7849 return 0;
7850
7851 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
7852 if (!nest)
7853 goto nla_put_failure;
9360ffd1
DM
7854 for (i = 0; i < req->n_ssids; i++) {
7855 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
7856 goto nla_put_failure;
7857 }
362a415d
JB
7858 nla_nest_end(msg, nest);
7859
7860 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
7861 if (!nest)
7862 goto nla_put_failure;
9360ffd1
DM
7863 for (i = 0; i < req->n_channels; i++) {
7864 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
7865 goto nla_put_failure;
7866 }
362a415d
JB
7867 nla_nest_end(msg, nest);
7868
9360ffd1
DM
7869 if (req->ie &&
7870 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
7871 goto nla_put_failure;
362a415d 7872
ed473771
SL
7873 if (req->flags)
7874 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
7875
362a415d
JB
7876 return 0;
7877 nla_put_failure:
7878 return -ENOBUFS;
7879}
7880
a538e2d5
JB
7881static int nl80211_send_scan_msg(struct sk_buff *msg,
7882 struct cfg80211_registered_device *rdev,
fd014284 7883 struct wireless_dev *wdev,
15e47304 7884 u32 portid, u32 seq, int flags,
a538e2d5 7885 u32 cmd)
2a519311
JB
7886{
7887 void *hdr;
7888
15e47304 7889 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
7890 if (!hdr)
7891 return -1;
7892
9360ffd1 7893 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
7894 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
7895 wdev->netdev->ifindex)) ||
7896 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 7897 goto nla_put_failure;
2a519311 7898
362a415d
JB
7899 /* ignore errors and send incomplete event anyway */
7900 nl80211_add_scan_req(msg, rdev);
2a519311
JB
7901
7902 return genlmsg_end(msg, hdr);
7903
7904 nla_put_failure:
7905 genlmsg_cancel(msg, hdr);
7906 return -EMSGSIZE;
7907}
7908
807f8a8c
LC
7909static int
7910nl80211_send_sched_scan_msg(struct sk_buff *msg,
7911 struct cfg80211_registered_device *rdev,
7912 struct net_device *netdev,
15e47304 7913 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
7914{
7915 void *hdr;
7916
15e47304 7917 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
7918 if (!hdr)
7919 return -1;
7920
9360ffd1
DM
7921 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7922 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7923 goto nla_put_failure;
807f8a8c
LC
7924
7925 return genlmsg_end(msg, hdr);
7926
7927 nla_put_failure:
7928 genlmsg_cancel(msg, hdr);
7929 return -EMSGSIZE;
7930}
7931
a538e2d5 7932void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 7933 struct wireless_dev *wdev)
a538e2d5
JB
7934{
7935 struct sk_buff *msg;
7936
58050fce 7937 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
7938 if (!msg)
7939 return;
7940
fd014284 7941 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
7942 NL80211_CMD_TRIGGER_SCAN) < 0) {
7943 nlmsg_free(msg);
7944 return;
7945 }
7946
463d0183
JB
7947 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7948 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
7949}
7950
2a519311 7951void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 7952 struct wireless_dev *wdev)
2a519311
JB
7953{
7954 struct sk_buff *msg;
7955
fd2120ca 7956 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7957 if (!msg)
7958 return;
7959
fd014284 7960 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 7961 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
7962 nlmsg_free(msg);
7963 return;
7964 }
7965
463d0183
JB
7966 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7967 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7968}
7969
7970void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 7971 struct wireless_dev *wdev)
2a519311
JB
7972{
7973 struct sk_buff *msg;
7974
fd2120ca 7975 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7976 if (!msg)
7977 return;
7978
fd014284 7979 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 7980 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
7981 nlmsg_free(msg);
7982 return;
7983 }
7984
463d0183
JB
7985 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7986 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7987}
7988
807f8a8c
LC
7989void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7990 struct net_device *netdev)
7991{
7992 struct sk_buff *msg;
7993
7994 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7995 if (!msg)
7996 return;
7997
7998 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7999 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
8000 nlmsg_free(msg);
8001 return;
8002 }
8003
8004 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8005 nl80211_scan_mcgrp.id, GFP_KERNEL);
8006}
8007
8008void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
8009 struct net_device *netdev, u32 cmd)
8010{
8011 struct sk_buff *msg;
8012
58050fce 8013 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
8014 if (!msg)
8015 return;
8016
8017 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
8018 nlmsg_free(msg);
8019 return;
8020 }
8021
8022 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8023 nl80211_scan_mcgrp.id, GFP_KERNEL);
8024}
8025
73d54c9e
LR
8026/*
8027 * This can happen on global regulatory changes or device specific settings
8028 * based on custom world regulatory domains.
8029 */
8030void nl80211_send_reg_change_event(struct regulatory_request *request)
8031{
8032 struct sk_buff *msg;
8033 void *hdr;
8034
fd2120ca 8035 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
8036 if (!msg)
8037 return;
8038
8039 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
8040 if (!hdr) {
8041 nlmsg_free(msg);
8042 return;
8043 }
8044
8045 /* Userspace can always count this one always being set */
9360ffd1
DM
8046 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
8047 goto nla_put_failure;
8048
8049 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
8050 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8051 NL80211_REGDOM_TYPE_WORLD))
8052 goto nla_put_failure;
8053 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
8054 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8055 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
8056 goto nla_put_failure;
8057 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
8058 request->intersect) {
8059 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8060 NL80211_REGDOM_TYPE_INTERSECTION))
8061 goto nla_put_failure;
8062 } else {
8063 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8064 NL80211_REGDOM_TYPE_COUNTRY) ||
8065 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
8066 request->alpha2))
8067 goto nla_put_failure;
8068 }
8069
8070 if (wiphy_idx_valid(request->wiphy_idx) &&
8071 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
8072 goto nla_put_failure;
73d54c9e 8073
3b7b72ee 8074 genlmsg_end(msg, hdr);
73d54c9e 8075
bc43b28c 8076 rcu_read_lock();
463d0183 8077 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
8078 GFP_ATOMIC);
8079 rcu_read_unlock();
73d54c9e
LR
8080
8081 return;
8082
8083nla_put_failure:
8084 genlmsg_cancel(msg, hdr);
8085 nlmsg_free(msg);
8086}
8087
6039f6d2
JM
8088static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
8089 struct net_device *netdev,
8090 const u8 *buf, size_t len,
e6d6e342 8091 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
8092{
8093 struct sk_buff *msg;
8094 void *hdr;
8095
e6d6e342 8096 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
8097 if (!msg)
8098 return;
8099
8100 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8101 if (!hdr) {
8102 nlmsg_free(msg);
8103 return;
8104 }
8105
9360ffd1
DM
8106 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8107 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8108 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8109 goto nla_put_failure;
6039f6d2 8110
3b7b72ee 8111 genlmsg_end(msg, hdr);
6039f6d2 8112
463d0183
JB
8113 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8114 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
8115 return;
8116
8117 nla_put_failure:
8118 genlmsg_cancel(msg, hdr);
8119 nlmsg_free(msg);
8120}
8121
8122void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8123 struct net_device *netdev, const u8 *buf,
8124 size_t len, gfp_t gfp)
6039f6d2
JM
8125{
8126 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8127 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
8128}
8129
8130void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
8131 struct net_device *netdev, const u8 *buf,
e6d6e342 8132 size_t len, gfp_t gfp)
6039f6d2 8133{
e6d6e342
JB
8134 nl80211_send_mlme_event(rdev, netdev, buf, len,
8135 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
8136}
8137
53b46b84 8138void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8139 struct net_device *netdev, const u8 *buf,
8140 size_t len, gfp_t gfp)
6039f6d2
JM
8141{
8142 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8143 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
8144}
8145
53b46b84
JM
8146void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
8147 struct net_device *netdev, const u8 *buf,
e6d6e342 8148 size_t len, gfp_t gfp)
6039f6d2
JM
8149{
8150 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8151 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
8152}
8153
cf4e594e
JM
8154void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
8155 struct net_device *netdev, const u8 *buf,
8156 size_t len, gfp_t gfp)
8157{
8158 nl80211_send_mlme_event(rdev, netdev, buf, len,
8159 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
8160}
8161
8162void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
8163 struct net_device *netdev, const u8 *buf,
8164 size_t len, gfp_t gfp)
8165{
8166 nl80211_send_mlme_event(rdev, netdev, buf, len,
8167 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
8168}
8169
1b06bb40
LR
8170static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
8171 struct net_device *netdev, int cmd,
e6d6e342 8172 const u8 *addr, gfp_t gfp)
1965c853
JM
8173{
8174 struct sk_buff *msg;
8175 void *hdr;
8176
e6d6e342 8177 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
8178 if (!msg)
8179 return;
8180
8181 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8182 if (!hdr) {
8183 nlmsg_free(msg);
8184 return;
8185 }
8186
9360ffd1
DM
8187 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8188 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8189 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
8190 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8191 goto nla_put_failure;
1965c853 8192
3b7b72ee 8193 genlmsg_end(msg, hdr);
1965c853 8194
463d0183
JB
8195 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8196 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
8197 return;
8198
8199 nla_put_failure:
8200 genlmsg_cancel(msg, hdr);
8201 nlmsg_free(msg);
8202}
8203
8204void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8205 struct net_device *netdev, const u8 *addr,
8206 gfp_t gfp)
1965c853
JM
8207{
8208 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 8209 addr, gfp);
1965c853
JM
8210}
8211
8212void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8213 struct net_device *netdev, const u8 *addr,
8214 gfp_t gfp)
1965c853 8215{
e6d6e342
JB
8216 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
8217 addr, gfp);
1965c853
JM
8218}
8219
b23aa676
SO
8220void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
8221 struct net_device *netdev, const u8 *bssid,
8222 const u8 *req_ie, size_t req_ie_len,
8223 const u8 *resp_ie, size_t resp_ie_len,
8224 u16 status, gfp_t gfp)
8225{
8226 struct sk_buff *msg;
8227 void *hdr;
8228
58050fce 8229 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8230 if (!msg)
8231 return;
8232
8233 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
8234 if (!hdr) {
8235 nlmsg_free(msg);
8236 return;
8237 }
8238
9360ffd1
DM
8239 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8240 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8241 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
8242 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
8243 (req_ie &&
8244 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8245 (resp_ie &&
8246 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8247 goto nla_put_failure;
b23aa676 8248
3b7b72ee 8249 genlmsg_end(msg, hdr);
b23aa676 8250
463d0183
JB
8251 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8252 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8253 return;
8254
8255 nla_put_failure:
8256 genlmsg_cancel(msg, hdr);
8257 nlmsg_free(msg);
8258
8259}
8260
8261void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
8262 struct net_device *netdev, const u8 *bssid,
8263 const u8 *req_ie, size_t req_ie_len,
8264 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
8265{
8266 struct sk_buff *msg;
8267 void *hdr;
8268
58050fce 8269 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8270 if (!msg)
8271 return;
8272
8273 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
8274 if (!hdr) {
8275 nlmsg_free(msg);
8276 return;
8277 }
8278
9360ffd1
DM
8279 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8280 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8281 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
8282 (req_ie &&
8283 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8284 (resp_ie &&
8285 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8286 goto nla_put_failure;
b23aa676 8287
3b7b72ee 8288 genlmsg_end(msg, hdr);
b23aa676 8289
463d0183
JB
8290 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8291 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8292 return;
8293
8294 nla_put_failure:
8295 genlmsg_cancel(msg, hdr);
8296 nlmsg_free(msg);
8297
8298}
8299
8300void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
8301 struct net_device *netdev, u16 reason,
667503dd 8302 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
8303{
8304 struct sk_buff *msg;
8305 void *hdr;
8306
58050fce 8307 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
8308 if (!msg)
8309 return;
8310
8311 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
8312 if (!hdr) {
8313 nlmsg_free(msg);
8314 return;
8315 }
8316
9360ffd1
DM
8317 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8318 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8319 (from_ap && reason &&
8320 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
8321 (from_ap &&
8322 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
8323 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
8324 goto nla_put_failure;
b23aa676 8325
3b7b72ee 8326 genlmsg_end(msg, hdr);
b23aa676 8327
463d0183
JB
8328 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8329 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
8330 return;
8331
8332 nla_put_failure:
8333 genlmsg_cancel(msg, hdr);
8334 nlmsg_free(msg);
8335
8336}
8337
04a773ad
JB
8338void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
8339 struct net_device *netdev, const u8 *bssid,
8340 gfp_t gfp)
8341{
8342 struct sk_buff *msg;
8343 void *hdr;
8344
fd2120ca 8345 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
8346 if (!msg)
8347 return;
8348
8349 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
8350 if (!hdr) {
8351 nlmsg_free(msg);
8352 return;
8353 }
8354
9360ffd1
DM
8355 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8356 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8357 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8358 goto nla_put_failure;
04a773ad 8359
3b7b72ee 8360 genlmsg_end(msg, hdr);
04a773ad 8361
463d0183
JB
8362 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8363 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
8364 return;
8365
8366 nla_put_failure:
8367 genlmsg_cancel(msg, hdr);
8368 nlmsg_free(msg);
8369}
8370
c93b5e71
JC
8371void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
8372 struct net_device *netdev,
8373 const u8 *macaddr, const u8* ie, u8 ie_len,
8374 gfp_t gfp)
8375{
8376 struct sk_buff *msg;
8377 void *hdr;
8378
8379 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8380 if (!msg)
8381 return;
8382
8383 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
8384 if (!hdr) {
8385 nlmsg_free(msg);
8386 return;
8387 }
8388
9360ffd1
DM
8389 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8390 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8391 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
8392 (ie_len && ie &&
8393 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
8394 goto nla_put_failure;
c93b5e71 8395
3b7b72ee 8396 genlmsg_end(msg, hdr);
c93b5e71
JC
8397
8398 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8399 nl80211_mlme_mcgrp.id, gfp);
8400 return;
8401
8402 nla_put_failure:
8403 genlmsg_cancel(msg, hdr);
8404 nlmsg_free(msg);
8405}
8406
a3b8b056
JM
8407void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
8408 struct net_device *netdev, const u8 *addr,
8409 enum nl80211_key_type key_type, int key_id,
e6d6e342 8410 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
8411{
8412 struct sk_buff *msg;
8413 void *hdr;
8414
e6d6e342 8415 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
8416 if (!msg)
8417 return;
8418
8419 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
8420 if (!hdr) {
8421 nlmsg_free(msg);
8422 return;
8423 }
8424
9360ffd1
DM
8425 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8426 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8427 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
8428 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
8429 (key_id != -1 &&
8430 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
8431 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
8432 goto nla_put_failure;
a3b8b056 8433
3b7b72ee 8434 genlmsg_end(msg, hdr);
a3b8b056 8435
463d0183
JB
8436 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8437 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
8438 return;
8439
8440 nla_put_failure:
8441 genlmsg_cancel(msg, hdr);
8442 nlmsg_free(msg);
8443}
8444
6bad8766
LR
8445void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
8446 struct ieee80211_channel *channel_before,
8447 struct ieee80211_channel *channel_after)
8448{
8449 struct sk_buff *msg;
8450 void *hdr;
8451 struct nlattr *nl_freq;
8452
fd2120ca 8453 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
8454 if (!msg)
8455 return;
8456
8457 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
8458 if (!hdr) {
8459 nlmsg_free(msg);
8460 return;
8461 }
8462
8463 /*
8464 * Since we are applying the beacon hint to a wiphy we know its
8465 * wiphy_idx is valid
8466 */
9360ffd1
DM
8467 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8468 goto nla_put_failure;
6bad8766
LR
8469
8470 /* Before */
8471 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
8472 if (!nl_freq)
8473 goto nla_put_failure;
8474 if (nl80211_msg_put_channel(msg, channel_before))
8475 goto nla_put_failure;
8476 nla_nest_end(msg, nl_freq);
8477
8478 /* After */
8479 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
8480 if (!nl_freq)
8481 goto nla_put_failure;
8482 if (nl80211_msg_put_channel(msg, channel_after))
8483 goto nla_put_failure;
8484 nla_nest_end(msg, nl_freq);
8485
3b7b72ee 8486 genlmsg_end(msg, hdr);
6bad8766 8487
463d0183
JB
8488 rcu_read_lock();
8489 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
8490 GFP_ATOMIC);
8491 rcu_read_unlock();
6bad8766
LR
8492
8493 return;
8494
8495nla_put_failure:
8496 genlmsg_cancel(msg, hdr);
8497 nlmsg_free(msg);
8498}
8499
9588bbd5
JM
8500static void nl80211_send_remain_on_chan_event(
8501 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 8502 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8503 struct ieee80211_channel *chan,
9588bbd5
JM
8504 unsigned int duration, gfp_t gfp)
8505{
8506 struct sk_buff *msg;
8507 void *hdr;
8508
8509 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8510 if (!msg)
8511 return;
8512
8513 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8514 if (!hdr) {
8515 nlmsg_free(msg);
8516 return;
8517 }
8518
9360ffd1 8519 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8520 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8521 wdev->netdev->ifindex)) ||
00f53350 8522 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 8523 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
8524 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
8525 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
8526 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8527 goto nla_put_failure;
9588bbd5 8528
9360ffd1
DM
8529 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
8530 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
8531 goto nla_put_failure;
9588bbd5 8532
3b7b72ee 8533 genlmsg_end(msg, hdr);
9588bbd5
JM
8534
8535 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8536 nl80211_mlme_mcgrp.id, gfp);
8537 return;
8538
8539 nla_put_failure:
8540 genlmsg_cancel(msg, hdr);
8541 nlmsg_free(msg);
8542}
8543
8544void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
71bbc994 8545 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8546 struct ieee80211_channel *chan,
9588bbd5
JM
8547 unsigned int duration, gfp_t gfp)
8548{
8549 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 8550 rdev, wdev, cookie, chan,
42d97a59 8551 duration, gfp);
9588bbd5
JM
8552}
8553
8554void nl80211_send_remain_on_channel_cancel(
71bbc994
JB
8555 struct cfg80211_registered_device *rdev,
8556 struct wireless_dev *wdev,
42d97a59 8557 u64 cookie, struct ieee80211_channel *chan, gfp_t gfp)
9588bbd5
JM
8558{
8559 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 8560 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5
JM
8561}
8562
98b62183
JB
8563void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
8564 struct net_device *dev, const u8 *mac_addr,
8565 struct station_info *sinfo, gfp_t gfp)
8566{
8567 struct sk_buff *msg;
8568
58050fce 8569 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
8570 if (!msg)
8571 return;
8572
66266b3a
JL
8573 if (nl80211_send_station(msg, 0, 0, 0,
8574 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
8575 nlmsg_free(msg);
8576 return;
8577 }
8578
8579 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8580 nl80211_mlme_mcgrp.id, gfp);
8581}
8582
ec15e68b
JM
8583void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
8584 struct net_device *dev, const u8 *mac_addr,
8585 gfp_t gfp)
8586{
8587 struct sk_buff *msg;
8588 void *hdr;
8589
58050fce 8590 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
8591 if (!msg)
8592 return;
8593
8594 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
8595 if (!hdr) {
8596 nlmsg_free(msg);
8597 return;
8598 }
8599
9360ffd1
DM
8600 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8601 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
8602 goto nla_put_failure;
ec15e68b 8603
3b7b72ee 8604 genlmsg_end(msg, hdr);
ec15e68b
JM
8605
8606 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8607 nl80211_mlme_mcgrp.id, gfp);
8608 return;
8609
8610 nla_put_failure:
8611 genlmsg_cancel(msg, hdr);
8612 nlmsg_free(msg);
8613}
8614
ed44a951
PP
8615void nl80211_send_conn_failed_event(struct cfg80211_registered_device *rdev,
8616 struct net_device *dev, const u8 *mac_addr,
8617 enum nl80211_connect_failed_reason reason,
8618 gfp_t gfp)
8619{
8620 struct sk_buff *msg;
8621 void *hdr;
8622
8623 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8624 if (!msg)
8625 return;
8626
8627 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
8628 if (!hdr) {
8629 nlmsg_free(msg);
8630 return;
8631 }
8632
8633 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8634 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
8635 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
8636 goto nla_put_failure;
8637
8638 genlmsg_end(msg, hdr);
8639
8640 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8641 nl80211_mlme_mcgrp.id, gfp);
8642 return;
8643
8644 nla_put_failure:
8645 genlmsg_cancel(msg, hdr);
8646 nlmsg_free(msg);
8647}
8648
b92ab5d8
JB
8649static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
8650 const u8 *addr, gfp_t gfp)
28946da7
JB
8651{
8652 struct wireless_dev *wdev = dev->ieee80211_ptr;
8653 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8654 struct sk_buff *msg;
8655 void *hdr;
8656 int err;
15e47304 8657 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 8658
15e47304 8659 if (!nlportid)
28946da7
JB
8660 return false;
8661
8662 msg = nlmsg_new(100, gfp);
8663 if (!msg)
8664 return true;
8665
b92ab5d8 8666 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
8667 if (!hdr) {
8668 nlmsg_free(msg);
8669 return true;
8670 }
8671
9360ffd1
DM
8672 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8673 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8674 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8675 goto nla_put_failure;
28946da7
JB
8676
8677 err = genlmsg_end(msg, hdr);
8678 if (err < 0) {
8679 nlmsg_free(msg);
8680 return true;
8681 }
8682
15e47304 8683 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
8684 return true;
8685
8686 nla_put_failure:
8687 genlmsg_cancel(msg, hdr);
8688 nlmsg_free(msg);
8689 return true;
8690}
8691
b92ab5d8
JB
8692bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
8693{
8694 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
8695 addr, gfp);
8696}
8697
8698bool nl80211_unexpected_4addr_frame(struct net_device *dev,
8699 const u8 *addr, gfp_t gfp)
8700{
8701 return __nl80211_unexpected_frame(dev,
8702 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
8703 addr, gfp);
8704}
8705
2e161f78 8706int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 8707 struct wireless_dev *wdev, u32 nlportid,
804483e9
JB
8708 int freq, int sig_dbm,
8709 const u8 *buf, size_t len, gfp_t gfp)
026331c4 8710{
71bbc994 8711 struct net_device *netdev = wdev->netdev;
026331c4
JM
8712 struct sk_buff *msg;
8713 void *hdr;
026331c4
JM
8714
8715 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8716 if (!msg)
8717 return -ENOMEM;
8718
2e161f78 8719 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
8720 if (!hdr) {
8721 nlmsg_free(msg);
8722 return -ENOMEM;
8723 }
8724
9360ffd1 8725 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8726 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8727 netdev->ifindex)) ||
9360ffd1
DM
8728 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8729 (sig_dbm &&
8730 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8731 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8732 goto nla_put_failure;
026331c4 8733
3b7b72ee 8734 genlmsg_end(msg, hdr);
026331c4 8735
15e47304 8736 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
8737
8738 nla_put_failure:
8739 genlmsg_cancel(msg, hdr);
8740 nlmsg_free(msg);
8741 return -ENOBUFS;
8742}
8743
2e161f78 8744void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
71bbc994 8745 struct wireless_dev *wdev, u64 cookie,
2e161f78
JB
8746 const u8 *buf, size_t len, bool ack,
8747 gfp_t gfp)
026331c4 8748{
71bbc994 8749 struct net_device *netdev = wdev->netdev;
026331c4
JM
8750 struct sk_buff *msg;
8751 void *hdr;
8752
8753 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8754 if (!msg)
8755 return;
8756
2e161f78 8757 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8758 if (!hdr) {
8759 nlmsg_free(msg);
8760 return;
8761 }
8762
9360ffd1 8763 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8764 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8765 netdev->ifindex)) ||
9360ffd1
DM
8766 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8767 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8768 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8769 goto nla_put_failure;
026331c4 8770
3b7b72ee 8771 genlmsg_end(msg, hdr);
026331c4
JM
8772
8773 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8774 return;
8775
8776 nla_put_failure:
8777 genlmsg_cancel(msg, hdr);
8778 nlmsg_free(msg);
8779}
8780
d6dc1a38
JO
8781void
8782nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8783 struct net_device *netdev,
8784 enum nl80211_cqm_rssi_threshold_event rssi_event,
8785 gfp_t gfp)
8786{
8787 struct sk_buff *msg;
8788 struct nlattr *pinfoattr;
8789 void *hdr;
8790
58050fce 8791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
8792 if (!msg)
8793 return;
8794
8795 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8796 if (!hdr) {
8797 nlmsg_free(msg);
8798 return;
8799 }
8800
9360ffd1
DM
8801 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8802 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8803 goto nla_put_failure;
d6dc1a38
JO
8804
8805 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8806 if (!pinfoattr)
8807 goto nla_put_failure;
8808
9360ffd1
DM
8809 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
8810 rssi_event))
8811 goto nla_put_failure;
d6dc1a38
JO
8812
8813 nla_nest_end(msg, pinfoattr);
8814
3b7b72ee 8815 genlmsg_end(msg, hdr);
d6dc1a38
JO
8816
8817 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8818 nl80211_mlme_mcgrp.id, gfp);
8819 return;
8820
8821 nla_put_failure:
8822 genlmsg_cancel(msg, hdr);
8823 nlmsg_free(msg);
8824}
8825
e5497d76
JB
8826void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
8827 struct net_device *netdev, const u8 *bssid,
8828 const u8 *replay_ctr, gfp_t gfp)
8829{
8830 struct sk_buff *msg;
8831 struct nlattr *rekey_attr;
8832 void *hdr;
8833
58050fce 8834 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
8835 if (!msg)
8836 return;
8837
8838 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
8839 if (!hdr) {
8840 nlmsg_free(msg);
8841 return;
8842 }
8843
9360ffd1
DM
8844 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8845 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8846 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8847 goto nla_put_failure;
e5497d76
JB
8848
8849 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
8850 if (!rekey_attr)
8851 goto nla_put_failure;
8852
9360ffd1
DM
8853 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
8854 NL80211_REPLAY_CTR_LEN, replay_ctr))
8855 goto nla_put_failure;
e5497d76
JB
8856
8857 nla_nest_end(msg, rekey_attr);
8858
3b7b72ee 8859 genlmsg_end(msg, hdr);
e5497d76
JB
8860
8861 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8862 nl80211_mlme_mcgrp.id, gfp);
8863 return;
8864
8865 nla_put_failure:
8866 genlmsg_cancel(msg, hdr);
8867 nlmsg_free(msg);
8868}
8869
c9df56b4
JM
8870void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
8871 struct net_device *netdev, int index,
8872 const u8 *bssid, bool preauth, gfp_t gfp)
8873{
8874 struct sk_buff *msg;
8875 struct nlattr *attr;
8876 void *hdr;
8877
58050fce 8878 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
8879 if (!msg)
8880 return;
8881
8882 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
8883 if (!hdr) {
8884 nlmsg_free(msg);
8885 return;
8886 }
8887
9360ffd1
DM
8888 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8889 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8890 goto nla_put_failure;
c9df56b4
JM
8891
8892 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
8893 if (!attr)
8894 goto nla_put_failure;
8895
9360ffd1
DM
8896 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
8897 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
8898 (preauth &&
8899 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
8900 goto nla_put_failure;
c9df56b4
JM
8901
8902 nla_nest_end(msg, attr);
8903
3b7b72ee 8904 genlmsg_end(msg, hdr);
c9df56b4
JM
8905
8906 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8907 nl80211_mlme_mcgrp.id, gfp);
8908 return;
8909
8910 nla_put_failure:
8911 genlmsg_cancel(msg, hdr);
8912 nlmsg_free(msg);
8913}
8914
5314526b 8915void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
683b6d3b
JB
8916 struct net_device *netdev,
8917 struct cfg80211_chan_def *chandef, gfp_t gfp)
5314526b
TP
8918{
8919 struct sk_buff *msg;
8920 void *hdr;
8921
58050fce 8922 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
8923 if (!msg)
8924 return;
8925
8926 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
8927 if (!hdr) {
8928 nlmsg_free(msg);
8929 return;
8930 }
8931
683b6d3b
JB
8932 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8933 goto nla_put_failure;
8934
8935 if (nl80211_send_chandef(msg, chandef))
7eab0f64 8936 goto nla_put_failure;
5314526b
TP
8937
8938 genlmsg_end(msg, hdr);
8939
8940 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8941 nl80211_mlme_mcgrp.id, gfp);
8942 return;
8943
8944 nla_put_failure:
8945 genlmsg_cancel(msg, hdr);
8946 nlmsg_free(msg);
8947}
8948
84f10708
TP
8949void
8950nl80211_send_cqm_txe_notify(struct cfg80211_registered_device *rdev,
8951 struct net_device *netdev, const u8 *peer,
8952 u32 num_packets, u32 rate, u32 intvl, gfp_t gfp)
8953{
8954 struct sk_buff *msg;
8955 struct nlattr *pinfoattr;
8956 void *hdr;
8957
8958 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8959 if (!msg)
8960 return;
8961
8962 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8963 if (!hdr) {
8964 nlmsg_free(msg);
8965 return;
8966 }
8967
8968 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8969 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8970 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
8971 goto nla_put_failure;
8972
8973 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8974 if (!pinfoattr)
8975 goto nla_put_failure;
8976
8977 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
8978 goto nla_put_failure;
8979
8980 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
8981 goto nla_put_failure;
8982
8983 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
8984 goto nla_put_failure;
8985
8986 nla_nest_end(msg, pinfoattr);
8987
8988 genlmsg_end(msg, hdr);
8989
8990 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8991 nl80211_mlme_mcgrp.id, gfp);
8992 return;
8993
8994 nla_put_failure:
8995 genlmsg_cancel(msg, hdr);
8996 nlmsg_free(msg);
8997}
8998
c063dbf5
JB
8999void
9000nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
9001 struct net_device *netdev, const u8 *peer,
9002 u32 num_packets, gfp_t gfp)
9003{
9004 struct sk_buff *msg;
9005 struct nlattr *pinfoattr;
9006 void *hdr;
9007
58050fce 9008 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
9009 if (!msg)
9010 return;
9011
9012 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9013 if (!hdr) {
9014 nlmsg_free(msg);
9015 return;
9016 }
9017
9360ffd1
DM
9018 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9019 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9020 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9021 goto nla_put_failure;
c063dbf5
JB
9022
9023 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9024 if (!pinfoattr)
9025 goto nla_put_failure;
9026
9360ffd1
DM
9027 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
9028 goto nla_put_failure;
c063dbf5
JB
9029
9030 nla_nest_end(msg, pinfoattr);
9031
3b7b72ee 9032 genlmsg_end(msg, hdr);
c063dbf5
JB
9033
9034 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9035 nl80211_mlme_mcgrp.id, gfp);
9036 return;
9037
9038 nla_put_failure:
9039 genlmsg_cancel(msg, hdr);
9040 nlmsg_free(msg);
9041}
9042
7f6cf311
JB
9043void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
9044 u64 cookie, bool acked, gfp_t gfp)
9045{
9046 struct wireless_dev *wdev = dev->ieee80211_ptr;
9047 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9048 struct sk_buff *msg;
9049 void *hdr;
9050 int err;
9051
4ee3e063
BL
9052 trace_cfg80211_probe_status(dev, addr, cookie, acked);
9053
58050fce 9054 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 9055
7f6cf311
JB
9056 if (!msg)
9057 return;
9058
9059 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
9060 if (!hdr) {
9061 nlmsg_free(msg);
9062 return;
9063 }
9064
9360ffd1
DM
9065 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9066 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9067 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9068 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
9069 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
9070 goto nla_put_failure;
7f6cf311
JB
9071
9072 err = genlmsg_end(msg, hdr);
9073 if (err < 0) {
9074 nlmsg_free(msg);
9075 return;
9076 }
9077
9078 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9079 nl80211_mlme_mcgrp.id, gfp);
9080 return;
9081
9082 nla_put_failure:
9083 genlmsg_cancel(msg, hdr);
9084 nlmsg_free(msg);
9085}
9086EXPORT_SYMBOL(cfg80211_probe_status);
9087
5e760230
JB
9088void cfg80211_report_obss_beacon(struct wiphy *wiphy,
9089 const u8 *frame, size_t len,
37c73b5f 9090 int freq, int sig_dbm)
5e760230
JB
9091{
9092 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9093 struct sk_buff *msg;
9094 void *hdr;
37c73b5f 9095 struct cfg80211_beacon_registration *reg;
5e760230 9096
4ee3e063
BL
9097 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
9098
37c73b5f
BG
9099 spin_lock_bh(&rdev->beacon_registrations_lock);
9100 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
9101 msg = nlmsg_new(len + 100, GFP_ATOMIC);
9102 if (!msg) {
9103 spin_unlock_bh(&rdev->beacon_registrations_lock);
9104 return;
9105 }
5e760230 9106
37c73b5f
BG
9107 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
9108 if (!hdr)
9109 goto nla_put_failure;
5e760230 9110
37c73b5f
BG
9111 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9112 (freq &&
9113 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
9114 (sig_dbm &&
9115 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9116 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
9117 goto nla_put_failure;
5e760230 9118
37c73b5f 9119 genlmsg_end(msg, hdr);
5e760230 9120
37c73b5f
BG
9121 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
9122 }
9123 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
9124 return;
9125
9126 nla_put_failure:
37c73b5f
BG
9127 spin_unlock_bh(&rdev->beacon_registrations_lock);
9128 if (hdr)
9129 genlmsg_cancel(msg, hdr);
5e760230
JB
9130 nlmsg_free(msg);
9131}
9132EXPORT_SYMBOL(cfg80211_report_obss_beacon);
9133
3475b094
JM
9134void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
9135 enum nl80211_tdls_operation oper,
9136 u16 reason_code, gfp_t gfp)
9137{
9138 struct wireless_dev *wdev = dev->ieee80211_ptr;
9139 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9140 struct sk_buff *msg;
9141 void *hdr;
9142 int err;
9143
9144 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
9145 reason_code);
9146
9147 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9148 if (!msg)
9149 return;
9150
9151 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
9152 if (!hdr) {
9153 nlmsg_free(msg);
9154 return;
9155 }
9156
9157 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9158 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9159 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
9160 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
9161 (reason_code > 0 &&
9162 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
9163 goto nla_put_failure;
9164
9165 err = genlmsg_end(msg, hdr);
9166 if (err < 0) {
9167 nlmsg_free(msg);
9168 return;
9169 }
9170
9171 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9172 nl80211_mlme_mcgrp.id, gfp);
9173 return;
9174
9175 nla_put_failure:
9176 genlmsg_cancel(msg, hdr);
9177 nlmsg_free(msg);
9178}
9179EXPORT_SYMBOL(cfg80211_tdls_oper_request);
9180
026331c4
JM
9181static int nl80211_netlink_notify(struct notifier_block * nb,
9182 unsigned long state,
9183 void *_notify)
9184{
9185 struct netlink_notify *notify = _notify;
9186 struct cfg80211_registered_device *rdev;
9187 struct wireless_dev *wdev;
37c73b5f 9188 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
9189
9190 if (state != NETLINK_URELEASE)
9191 return NOTIFY_DONE;
9192
9193 rcu_read_lock();
9194
5e760230 9195 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 9196 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 9197 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
9198
9199 spin_lock_bh(&rdev->beacon_registrations_lock);
9200 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
9201 list) {
9202 if (reg->nlportid == notify->portid) {
9203 list_del(&reg->list);
9204 kfree(reg);
9205 break;
9206 }
9207 }
9208 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 9209 }
026331c4
JM
9210
9211 rcu_read_unlock();
9212
9213 return NOTIFY_DONE;
9214}
9215
9216static struct notifier_block nl80211_netlink_notifier = {
9217 .notifier_call = nl80211_netlink_notify,
9218};
9219
55682965
JB
9220/* initialisation/exit functions */
9221
9222int nl80211_init(void)
9223{
0d63cbb5 9224 int err;
55682965 9225
0d63cbb5
MM
9226 err = genl_register_family_with_ops(&nl80211_fam,
9227 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
9228 if (err)
9229 return err;
9230
55682965
JB
9231 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
9232 if (err)
9233 goto err_out;
9234
2a519311
JB
9235 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
9236 if (err)
9237 goto err_out;
9238
73d54c9e
LR
9239 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
9240 if (err)
9241 goto err_out;
9242
6039f6d2
JM
9243 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
9244 if (err)
9245 goto err_out;
9246
aff89a9b
JB
9247#ifdef CONFIG_NL80211_TESTMODE
9248 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
9249 if (err)
9250 goto err_out;
9251#endif
9252
026331c4
JM
9253 err = netlink_register_notifier(&nl80211_netlink_notifier);
9254 if (err)
9255 goto err_out;
9256
55682965
JB
9257 return 0;
9258 err_out:
9259 genl_unregister_family(&nl80211_fam);
9260 return err;
9261}
9262
9263void nl80211_exit(void)
9264{
026331c4 9265 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
9266 genl_unregister_family(&nl80211_fam);
9267}