]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
sit: add support of x-netns
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
2a0e047e 22#include <net/inet_connection_sock.h>
55682965
JB
23#include "core.h"
24#include "nl80211.h"
b2e1b302 25#include "reg.h"
e35e4d28 26#include "rdev-ops.h"
55682965 27
5fb628e9
JM
28static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
29 struct genl_info *info,
30 struct cfg80211_crypto_settings *settings,
31 int cipher_limit);
32
4c476991
JB
33static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
34 struct genl_info *info);
35static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
36 struct genl_info *info);
37
55682965
JB
38/* the netlink family */
39static struct genl_family nl80211_fam = {
fb4e1568
MH
40 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
41 .name = NL80211_GENL_NAME, /* have users key off the name instead */
42 .hdrsize = 0, /* no private header */
43 .version = 1, /* no particular meaning now */
55682965 44 .maxattr = NL80211_ATTR_MAX,
463d0183 45 .netnsok = true,
4c476991
JB
46 .pre_doit = nl80211_pre_doit,
47 .post_doit = nl80211_post_doit,
55682965
JB
48};
49
89a54e48
JB
50/* returns ERR_PTR values */
51static struct wireless_dev *
52__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 53{
89a54e48
JB
54 struct cfg80211_registered_device *rdev;
55 struct wireless_dev *result = NULL;
56 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
57 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
58 u64 wdev_id;
59 int wiphy_idx = -1;
60 int ifidx = -1;
55682965 61
5fe231e8 62 ASSERT_RTNL();
55682965 63
89a54e48
JB
64 if (!have_ifidx && !have_wdev_id)
65 return ERR_PTR(-EINVAL);
55682965 66
89a54e48
JB
67 if (have_ifidx)
68 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
69 if (have_wdev_id) {
70 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
71 wiphy_idx = wdev_id >> 32;
55682965
JB
72 }
73
89a54e48
JB
74 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
75 struct wireless_dev *wdev;
76
77 if (wiphy_net(&rdev->wiphy) != netns)
78 continue;
79
80 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
81 continue;
82
89a54e48
JB
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
89a54e48
JB
94
95 if (result)
96 break;
97 }
98
99 if (result)
100 return result;
101 return ERR_PTR(-ENODEV);
55682965
JB
102}
103
a9455408 104static struct cfg80211_registered_device *
878d9ec7 105__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 106{
7fee4778
JB
107 struct cfg80211_registered_device *rdev = NULL, *tmp;
108 struct net_device *netdev;
a9455408 109
5fe231e8 110 ASSERT_RTNL();
a9455408 111
878d9ec7 112 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
113 !attrs[NL80211_ATTR_IFINDEX] &&
114 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
115 return ERR_PTR(-EINVAL);
116
878d9ec7 117 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 118 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 119 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 120
89a54e48
JB
121 if (attrs[NL80211_ATTR_WDEV]) {
122 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
123 struct wireless_dev *wdev;
124 bool found = false;
125
126 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
127 if (tmp) {
128 /* make sure wdev exists */
89a54e48
JB
129 list_for_each_entry(wdev, &tmp->wdev_list, list) {
130 if (wdev->identifier != (u32)wdev_id)
131 continue;
132 found = true;
133 break;
134 }
89a54e48
JB
135
136 if (!found)
137 tmp = NULL;
138
139 if (rdev && tmp != rdev)
140 return ERR_PTR(-EINVAL);
141 rdev = tmp;
142 }
143 }
144
878d9ec7
JB
145 if (attrs[NL80211_ATTR_IFINDEX]) {
146 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 147 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
148 if (netdev) {
149 if (netdev->ieee80211_ptr)
150 tmp = wiphy_to_dev(
151 netdev->ieee80211_ptr->wiphy);
152 else
153 tmp = NULL;
154
155 dev_put(netdev);
156
157 /* not wireless device -- return error */
158 if (!tmp)
159 return ERR_PTR(-EINVAL);
160
161 /* mismatch -- return error */
162 if (rdev && tmp != rdev)
163 return ERR_PTR(-EINVAL);
164
165 rdev = tmp;
a9455408 166 }
a9455408 167 }
a9455408 168
4f7eff10
JB
169 if (!rdev)
170 return ERR_PTR(-ENODEV);
a9455408 171
4f7eff10
JB
172 if (netns != wiphy_net(&rdev->wiphy))
173 return ERR_PTR(-ENODEV);
174
175 return rdev;
a9455408
JB
176}
177
178/*
179 * This function returns a pointer to the driver
180 * that the genl_info item that is passed refers to.
a9455408
JB
181 *
182 * The result of this can be a PTR_ERR and hence must
183 * be checked with IS_ERR() for errors.
184 */
185static struct cfg80211_registered_device *
4f7eff10 186cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 187{
5fe231e8 188 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
189}
190
55682965 191/* policy for the attributes */
b54452b0 192static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
193 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
194 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 195 .len = 20-1 },
31888487 196 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 197
72bdcf34 198 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 199 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
200 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
201 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
202 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
203
b9a5f8ca
JM
204 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
205 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
206 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
207 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 208 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
209
210 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
211 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
212 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 213
e007b857
EP
214 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
215 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 216
b9454e83 217 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
218 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
219 .len = WLAN_MAX_KEY_LEN },
220 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
221 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
222 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 223 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 224 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
225
226 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
227 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
228 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
229 .len = IEEE80211_MAX_DATA_LEN },
230 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
231 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
232 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
233 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
234 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
235 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
236 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 237 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 238 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 239 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 240 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 241 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 242 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 243
b2e1b302
LR
244 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
245 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
246
9f1ba906
JM
247 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
248 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
249 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
250 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
251 .len = NL80211_MAX_SUPP_RATES },
50b12f59 252 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 253
24bdd9f4 254 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 255 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 256
6c739419 257 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
258
259 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
260 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
261 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
262 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
263 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
264
265 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
266 .len = IEEE80211_MAX_SSID_LEN },
267 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
268 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 269 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 270 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 271 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
272 [NL80211_ATTR_STA_FLAGS2] = {
273 .len = sizeof(struct nl80211_sta_flag_update),
274 },
3f77316c 275 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
276 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
277 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
278 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
279 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
280 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 281 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 282 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
283 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
284 .len = WLAN_PMKID_LEN },
9588bbd5
JM
285 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
286 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 287 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
288 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
289 .len = IEEE80211_MAX_DATA_LEN },
290 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 291 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 292 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 293 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 294 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
295 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
296 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 297 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
298 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
299 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 300 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 301 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 302 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 303 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 304 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 305 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 306 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 307 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 308 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
309 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
310 .len = IEEE80211_MAX_DATA_LEN },
311 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
312 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 313 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 314 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 315 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
316 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
317 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
318 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
319 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
320 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 321 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
322 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
323 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 324 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
325 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
326 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
327 .len = NL80211_HT_CAPABILITY_LEN
328 },
1d9d9213 329 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 330 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 331 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 332 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 333 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 334 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 335 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 336 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
337 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
338 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
339 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
340 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
341 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
342 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 343 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
344 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
345 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
346 .len = NL80211_VHT_CAPABILITY_LEN,
347 },
355199e0
JM
348 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
349 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
350 .len = IEEE80211_MAX_DATA_LEN },
5e4b6f56 351 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 },
55682965
JB
352};
353
e31b8213 354/* policy for the key attributes */
b54452b0 355static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 356 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
357 [NL80211_KEY_IDX] = { .type = NLA_U8 },
358 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 359 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
360 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
361 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 362 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
363 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
364};
365
366/* policy for the key default flags */
367static const struct nla_policy
368nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
369 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
370 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
371};
372
ff1b6e69
JB
373/* policy for WoWLAN attributes */
374static const struct nla_policy
375nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
376 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
377 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
378 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
379 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
380 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
381 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
382 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
383 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e
JB
384 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
385};
386
387static const struct nla_policy
388nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
389 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
390 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
391 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
392 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
393 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
394 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
395 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
396 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
397 },
398 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
399 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
400 },
401 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
402 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
403 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69
JB
404};
405
e5497d76
JB
406/* policy for GTK rekey offload attributes */
407static const struct nla_policy
408nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
409 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
410 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
411 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
412};
413
a1f1c21c
LC
414static const struct nla_policy
415nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 416 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 417 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 418 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
419};
420
97990a06
JB
421static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
422 struct netlink_callback *cb,
423 struct cfg80211_registered_device **rdev,
424 struct wireless_dev **wdev)
a043897a 425{
97990a06 426 int err;
a043897a 427
97990a06 428 rtnl_lock();
a043897a 429
97990a06
JB
430 if (!cb->args[0]) {
431 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
432 nl80211_fam.attrbuf, nl80211_fam.maxattr,
433 nl80211_policy);
434 if (err)
435 goto out_unlock;
67748893 436
97990a06
JB
437 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
438 nl80211_fam.attrbuf);
439 if (IS_ERR(*wdev)) {
440 err = PTR_ERR(*wdev);
441 goto out_unlock;
442 }
443 *rdev = wiphy_to_dev((*wdev)->wiphy);
444 cb->args[0] = (*rdev)->wiphy_idx;
445 cb->args[1] = (*wdev)->identifier;
446 } else {
447 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0]);
448 struct wireless_dev *tmp;
67748893 449
97990a06
JB
450 if (!wiphy) {
451 err = -ENODEV;
452 goto out_unlock;
453 }
454 *rdev = wiphy_to_dev(wiphy);
455 *wdev = NULL;
67748893 456
97990a06
JB
457 list_for_each_entry(tmp, &(*rdev)->wdev_list, list) {
458 if (tmp->identifier == cb->args[1]) {
459 *wdev = tmp;
460 break;
461 }
462 }
67748893 463
97990a06
JB
464 if (!*wdev) {
465 err = -ENODEV;
466 goto out_unlock;
467 }
67748893
JB
468 }
469
67748893 470 return 0;
97990a06 471 out_unlock:
67748893
JB
472 rtnl_unlock();
473 return err;
474}
475
97990a06 476static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev)
67748893 477{
67748893
JB
478 rtnl_unlock();
479}
480
f4a11bb0
JB
481/* IE validation */
482static bool is_valid_ie_attr(const struct nlattr *attr)
483{
484 const u8 *pos;
485 int len;
486
487 if (!attr)
488 return true;
489
490 pos = nla_data(attr);
491 len = nla_len(attr);
492
493 while (len) {
494 u8 elemlen;
495
496 if (len < 2)
497 return false;
498 len -= 2;
499
500 elemlen = pos[1];
501 if (elemlen > len)
502 return false;
503
504 len -= elemlen;
505 pos += 2 + elemlen;
506 }
507
508 return true;
509}
510
55682965 511/* message building helper */
15e47304 512static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
513 int flags, u8 cmd)
514{
515 /* since there is no private header just add the generic one */
15e47304 516 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
517}
518
5dab3b8a 519static int nl80211_msg_put_channel(struct sk_buff *msg,
cdc89b97
JB
520 struct ieee80211_channel *chan,
521 bool large)
5dab3b8a 522{
9360ffd1
DM
523 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
524 chan->center_freq))
525 goto nla_put_failure;
5dab3b8a 526
9360ffd1
DM
527 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
528 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
529 goto nla_put_failure;
530 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
531 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
532 goto nla_put_failure;
533 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
534 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
535 goto nla_put_failure;
cdc89b97
JB
536 if (chan->flags & IEEE80211_CHAN_RADAR) {
537 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
538 goto nla_put_failure;
539 if (large) {
540 u32 time;
541
542 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
543
544 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
545 chan->dfs_state))
546 goto nla_put_failure;
547 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
548 time))
549 goto nla_put_failure;
550 }
551 }
5dab3b8a 552
fe1abafd
JB
553 if (large) {
554 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
555 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
556 goto nla_put_failure;
557 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
558 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
559 goto nla_put_failure;
560 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
561 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
562 goto nla_put_failure;
563 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
564 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
565 goto nla_put_failure;
566 }
567
9360ffd1
DM
568 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
569 DBM_TO_MBM(chan->max_power)))
570 goto nla_put_failure;
5dab3b8a
LR
571
572 return 0;
573
574 nla_put_failure:
575 return -ENOBUFS;
576}
577
55682965
JB
578/* netlink command implementations */
579
b9454e83
JB
580struct key_parse {
581 struct key_params p;
582 int idx;
e31b8213 583 int type;
b9454e83 584 bool def, defmgmt;
dbd2fd65 585 bool def_uni, def_multi;
b9454e83
JB
586};
587
588static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
589{
590 struct nlattr *tb[NL80211_KEY_MAX + 1];
591 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
592 nl80211_key_policy);
593 if (err)
594 return err;
595
596 k->def = !!tb[NL80211_KEY_DEFAULT];
597 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
598
dbd2fd65
JB
599 if (k->def) {
600 k->def_uni = true;
601 k->def_multi = true;
602 }
603 if (k->defmgmt)
604 k->def_multi = true;
605
b9454e83
JB
606 if (tb[NL80211_KEY_IDX])
607 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
608
609 if (tb[NL80211_KEY_DATA]) {
610 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
611 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
612 }
613
614 if (tb[NL80211_KEY_SEQ]) {
615 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
616 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
617 }
618
619 if (tb[NL80211_KEY_CIPHER])
620 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
621
e31b8213
JB
622 if (tb[NL80211_KEY_TYPE]) {
623 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
624 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
625 return -EINVAL;
626 }
627
dbd2fd65
JB
628 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
629 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
630 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
631 tb[NL80211_KEY_DEFAULT_TYPES],
632 nl80211_key_default_policy);
dbd2fd65
JB
633 if (err)
634 return err;
635
636 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
637 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
638 }
639
b9454e83
JB
640 return 0;
641}
642
643static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
644{
645 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
646 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
647 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
648 }
649
650 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
651 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
652 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
653 }
654
655 if (info->attrs[NL80211_ATTR_KEY_IDX])
656 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
657
658 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
659 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
660
661 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
662 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
663
dbd2fd65
JB
664 if (k->def) {
665 k->def_uni = true;
666 k->def_multi = true;
667 }
668 if (k->defmgmt)
669 k->def_multi = true;
670
e31b8213
JB
671 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
672 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
673 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
674 return -EINVAL;
675 }
676
dbd2fd65
JB
677 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
678 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
679 int err = nla_parse_nested(
680 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
681 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
682 nl80211_key_default_policy);
683 if (err)
684 return err;
685
686 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
687 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
688 }
689
b9454e83
JB
690 return 0;
691}
692
693static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
694{
695 int err;
696
697 memset(k, 0, sizeof(*k));
698 k->idx = -1;
e31b8213 699 k->type = -1;
b9454e83
JB
700
701 if (info->attrs[NL80211_ATTR_KEY])
702 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
703 else
704 err = nl80211_parse_key_old(info, k);
705
706 if (err)
707 return err;
708
709 if (k->def && k->defmgmt)
710 return -EINVAL;
711
dbd2fd65
JB
712 if (k->defmgmt) {
713 if (k->def_uni || !k->def_multi)
714 return -EINVAL;
715 }
716
b9454e83
JB
717 if (k->idx != -1) {
718 if (k->defmgmt) {
719 if (k->idx < 4 || k->idx > 5)
720 return -EINVAL;
721 } else if (k->def) {
722 if (k->idx < 0 || k->idx > 3)
723 return -EINVAL;
724 } else {
725 if (k->idx < 0 || k->idx > 5)
726 return -EINVAL;
727 }
728 }
729
730 return 0;
731}
732
fffd0934
JB
733static struct cfg80211_cached_keys *
734nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 735 struct nlattr *keys, bool *no_ht)
fffd0934
JB
736{
737 struct key_parse parse;
738 struct nlattr *key;
739 struct cfg80211_cached_keys *result;
740 int rem, err, def = 0;
741
742 result = kzalloc(sizeof(*result), GFP_KERNEL);
743 if (!result)
744 return ERR_PTR(-ENOMEM);
745
746 result->def = -1;
747 result->defmgmt = -1;
748
749 nla_for_each_nested(key, keys, rem) {
750 memset(&parse, 0, sizeof(parse));
751 parse.idx = -1;
752
753 err = nl80211_parse_key_new(key, &parse);
754 if (err)
755 goto error;
756 err = -EINVAL;
757 if (!parse.p.key)
758 goto error;
759 if (parse.idx < 0 || parse.idx > 4)
760 goto error;
761 if (parse.def) {
762 if (def)
763 goto error;
764 def = 1;
765 result->def = parse.idx;
dbd2fd65
JB
766 if (!parse.def_uni || !parse.def_multi)
767 goto error;
fffd0934
JB
768 } else if (parse.defmgmt)
769 goto error;
770 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 771 parse.idx, false, NULL);
fffd0934
JB
772 if (err)
773 goto error;
774 result->params[parse.idx].cipher = parse.p.cipher;
775 result->params[parse.idx].key_len = parse.p.key_len;
776 result->params[parse.idx].key = result->data[parse.idx];
777 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
778
779 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
780 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
781 if (no_ht)
782 *no_ht = true;
783 }
fffd0934
JB
784 }
785
786 return result;
787 error:
788 kfree(result);
789 return ERR_PTR(err);
790}
791
792static int nl80211_key_allowed(struct wireless_dev *wdev)
793{
794 ASSERT_WDEV_LOCK(wdev);
795
fffd0934
JB
796 switch (wdev->iftype) {
797 case NL80211_IFTYPE_AP:
798 case NL80211_IFTYPE_AP_VLAN:
074ac8df 799 case NL80211_IFTYPE_P2P_GO:
ff973af7 800 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
801 break;
802 case NL80211_IFTYPE_ADHOC:
fffd0934 803 case NL80211_IFTYPE_STATION:
074ac8df 804 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 805 if (!wdev->current_bss)
fffd0934
JB
806 return -ENOLINK;
807 break;
808 default:
809 return -EINVAL;
810 }
811
812 return 0;
813}
814
7527a782
JB
815static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
816{
817 struct nlattr *nl_modes = nla_nest_start(msg, attr);
818 int i;
819
820 if (!nl_modes)
821 goto nla_put_failure;
822
823 i = 0;
824 while (ifmodes) {
9360ffd1
DM
825 if ((ifmodes & 1) && nla_put_flag(msg, i))
826 goto nla_put_failure;
7527a782
JB
827 ifmodes >>= 1;
828 i++;
829 }
830
831 nla_nest_end(msg, nl_modes);
832 return 0;
833
834nla_put_failure:
835 return -ENOBUFS;
836}
837
838static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
839 struct sk_buff *msg,
840 bool large)
7527a782
JB
841{
842 struct nlattr *nl_combis;
843 int i, j;
844
845 nl_combis = nla_nest_start(msg,
846 NL80211_ATTR_INTERFACE_COMBINATIONS);
847 if (!nl_combis)
848 goto nla_put_failure;
849
850 for (i = 0; i < wiphy->n_iface_combinations; i++) {
851 const struct ieee80211_iface_combination *c;
852 struct nlattr *nl_combi, *nl_limits;
853
854 c = &wiphy->iface_combinations[i];
855
856 nl_combi = nla_nest_start(msg, i + 1);
857 if (!nl_combi)
858 goto nla_put_failure;
859
860 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
861 if (!nl_limits)
862 goto nla_put_failure;
863
864 for (j = 0; j < c->n_limits; j++) {
865 struct nlattr *nl_limit;
866
867 nl_limit = nla_nest_start(msg, j + 1);
868 if (!nl_limit)
869 goto nla_put_failure;
9360ffd1
DM
870 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
871 c->limits[j].max))
872 goto nla_put_failure;
7527a782
JB
873 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
874 c->limits[j].types))
875 goto nla_put_failure;
876 nla_nest_end(msg, nl_limit);
877 }
878
879 nla_nest_end(msg, nl_limits);
880
9360ffd1
DM
881 if (c->beacon_int_infra_match &&
882 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
883 goto nla_put_failure;
884 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
885 c->num_different_channels) ||
886 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
887 c->max_interfaces))
888 goto nla_put_failure;
cdc89b97
JB
889 if (large &&
890 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
891 c->radar_detect_widths))
892 goto nla_put_failure;
7527a782
JB
893
894 nla_nest_end(msg, nl_combi);
895 }
896
897 nla_nest_end(msg, nl_combis);
898
899 return 0;
900nla_put_failure:
901 return -ENOBUFS;
902}
903
3713b4e3 904#ifdef CONFIG_PM
b56cf720
JB
905static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
906 struct sk_buff *msg)
907{
964dc9e2 908 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
909 struct nlattr *nl_tcp;
910
911 if (!tcp)
912 return 0;
913
914 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
915 if (!nl_tcp)
916 return -ENOBUFS;
917
918 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
919 tcp->data_payload_max))
920 return -ENOBUFS;
921
922 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
923 tcp->data_payload_max))
924 return -ENOBUFS;
925
926 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
927 return -ENOBUFS;
928
929 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
930 sizeof(*tcp->tok), tcp->tok))
931 return -ENOBUFS;
932
933 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
934 tcp->data_interval_max))
935 return -ENOBUFS;
936
937 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
938 tcp->wake_payload_max))
939 return -ENOBUFS;
940
941 nla_nest_end(msg, nl_tcp);
942 return 0;
943}
944
3713b4e3 945static int nl80211_send_wowlan(struct sk_buff *msg,
b56cf720
JB
946 struct cfg80211_registered_device *dev,
947 bool large)
55682965 948{
3713b4e3 949 struct nlattr *nl_wowlan;
55682965 950
964dc9e2 951 if (!dev->wiphy.wowlan)
3713b4e3 952 return 0;
55682965 953
3713b4e3
JB
954 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
955 if (!nl_wowlan)
956 return -ENOBUFS;
9360ffd1 957
964dc9e2 958 if (((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 959 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
964dc9e2 960 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 961 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
964dc9e2 962 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 963 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
964dc9e2 964 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 965 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
964dc9e2 966 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 967 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
964dc9e2 968 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 969 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
964dc9e2 970 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 971 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
964dc9e2 972 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
973 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
974 return -ENOBUFS;
9360ffd1 975
964dc9e2 976 if (dev->wiphy.wowlan->n_patterns) {
3713b4e3 977 struct nl80211_wowlan_pattern_support pat = {
964dc9e2
JB
978 .max_patterns = dev->wiphy.wowlan->n_patterns,
979 .min_pattern_len = dev->wiphy.wowlan->pattern_min_len,
980 .max_pattern_len = dev->wiphy.wowlan->pattern_max_len,
981 .max_pkt_offset = dev->wiphy.wowlan->max_pkt_offset,
3713b4e3 982 };
9360ffd1 983
3713b4e3
JB
984 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
985 sizeof(pat), &pat))
986 return -ENOBUFS;
987 }
9360ffd1 988
b56cf720
JB
989 if (large && nl80211_send_wowlan_tcp_caps(dev, msg))
990 return -ENOBUFS;
991
3713b4e3 992 nla_nest_end(msg, nl_wowlan);
9360ffd1 993
3713b4e3
JB
994 return 0;
995}
996#endif
9360ffd1 997
3713b4e3
JB
998static int nl80211_send_band_rateinfo(struct sk_buff *msg,
999 struct ieee80211_supported_band *sband)
1000{
1001 struct nlattr *nl_rates, *nl_rate;
1002 struct ieee80211_rate *rate;
1003 int i;
87bbbe22 1004
3713b4e3
JB
1005 /* add HT info */
1006 if (sband->ht_cap.ht_supported &&
1007 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1008 sizeof(sband->ht_cap.mcs),
1009 &sband->ht_cap.mcs) ||
1010 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1011 sband->ht_cap.cap) ||
1012 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1013 sband->ht_cap.ampdu_factor) ||
1014 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1015 sband->ht_cap.ampdu_density)))
1016 return -ENOBUFS;
afe0cbf8 1017
3713b4e3
JB
1018 /* add VHT info */
1019 if (sband->vht_cap.vht_supported &&
1020 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1021 sizeof(sband->vht_cap.vht_mcs),
1022 &sband->vht_cap.vht_mcs) ||
1023 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1024 sband->vht_cap.cap)))
1025 return -ENOBUFS;
f59ac048 1026
3713b4e3
JB
1027 /* add bitrates */
1028 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1029 if (!nl_rates)
1030 return -ENOBUFS;
ee688b00 1031
3713b4e3
JB
1032 for (i = 0; i < sband->n_bitrates; i++) {
1033 nl_rate = nla_nest_start(msg, i);
1034 if (!nl_rate)
1035 return -ENOBUFS;
ee688b00 1036
3713b4e3
JB
1037 rate = &sband->bitrates[i];
1038 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1039 rate->bitrate))
1040 return -ENOBUFS;
1041 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1042 nla_put_flag(msg,
1043 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1044 return -ENOBUFS;
ee688b00 1045
3713b4e3
JB
1046 nla_nest_end(msg, nl_rate);
1047 }
d51626df 1048
3713b4e3 1049 nla_nest_end(msg, nl_rates);
bf0c111e 1050
3713b4e3
JB
1051 return 0;
1052}
ee688b00 1053
3713b4e3
JB
1054static int
1055nl80211_send_mgmt_stypes(struct sk_buff *msg,
1056 const struct ieee80211_txrx_stypes *mgmt_stypes)
1057{
1058 u16 stypes;
1059 struct nlattr *nl_ftypes, *nl_ifs;
1060 enum nl80211_iftype ift;
1061 int i;
ee688b00 1062
3713b4e3
JB
1063 if (!mgmt_stypes)
1064 return 0;
5dab3b8a 1065
3713b4e3
JB
1066 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1067 if (!nl_ifs)
1068 return -ENOBUFS;
e2f367f2 1069
3713b4e3
JB
1070 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1071 nl_ftypes = nla_nest_start(msg, ift);
1072 if (!nl_ftypes)
1073 return -ENOBUFS;
1074 i = 0;
1075 stypes = mgmt_stypes[ift].tx;
1076 while (stypes) {
1077 if ((stypes & 1) &&
1078 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1079 (i << 4) | IEEE80211_FTYPE_MGMT))
1080 return -ENOBUFS;
1081 stypes >>= 1;
1082 i++;
ee688b00 1083 }
3713b4e3
JB
1084 nla_nest_end(msg, nl_ftypes);
1085 }
ee688b00 1086
3713b4e3 1087 nla_nest_end(msg, nl_ifs);
ee688b00 1088
3713b4e3
JB
1089 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1090 if (!nl_ifs)
1091 return -ENOBUFS;
ee688b00 1092
3713b4e3
JB
1093 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1094 nl_ftypes = nla_nest_start(msg, ift);
1095 if (!nl_ftypes)
1096 return -ENOBUFS;
1097 i = 0;
1098 stypes = mgmt_stypes[ift].rx;
1099 while (stypes) {
1100 if ((stypes & 1) &&
1101 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1102 (i << 4) | IEEE80211_FTYPE_MGMT))
1103 return -ENOBUFS;
1104 stypes >>= 1;
1105 i++;
1106 }
1107 nla_nest_end(msg, nl_ftypes);
1108 }
1109 nla_nest_end(msg, nl_ifs);
ee688b00 1110
3713b4e3
JB
1111 return 0;
1112}
ee688b00 1113
3713b4e3
JB
1114static int nl80211_send_wiphy(struct cfg80211_registered_device *dev,
1115 struct sk_buff *msg, u32 portid, u32 seq,
1116 int flags, bool split, long *split_start,
1117 long *band_start, long *chan_start)
1118{
1119 void *hdr;
1120 struct nlattr *nl_bands, *nl_band;
1121 struct nlattr *nl_freqs, *nl_freq;
1122 struct nlattr *nl_cmds;
1123 enum ieee80211_band band;
1124 struct ieee80211_channel *chan;
1125 int i;
1126 const struct ieee80211_txrx_stypes *mgmt_stypes =
1127 dev->wiphy.mgmt_stypes;
1128 long start = 0, start_chan = 0, start_band = 0;
fe1abafd 1129 u32 features;
ee688b00 1130
3713b4e3
JB
1131 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
1132 if (!hdr)
1133 return -ENOBUFS;
ee688b00 1134
3713b4e3
JB
1135 /* allow always using the variables */
1136 if (!split) {
1137 split_start = &start;
1138 band_start = &start_band;
1139 chan_start = &start_chan;
ee688b00 1140 }
ee688b00 1141
3713b4e3
JB
1142 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
1143 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1144 wiphy_name(&dev->wiphy)) ||
1145 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1146 cfg80211_rdev_list_generation))
8fdc621d
JB
1147 goto nla_put_failure;
1148
3713b4e3
JB
1149 switch (*split_start) {
1150 case 0:
1151 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1152 dev->wiphy.retry_short) ||
1153 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1154 dev->wiphy.retry_long) ||
1155 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1156 dev->wiphy.frag_threshold) ||
1157 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1158 dev->wiphy.rts_threshold) ||
1159 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1160 dev->wiphy.coverage_class) ||
1161 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1162 dev->wiphy.max_scan_ssids) ||
1163 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1164 dev->wiphy.max_sched_scan_ssids) ||
1165 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1166 dev->wiphy.max_scan_ie_len) ||
1167 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1168 dev->wiphy.max_sched_scan_ie_len) ||
1169 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
1170 dev->wiphy.max_match_sets))
9360ffd1 1171 goto nla_put_failure;
3713b4e3
JB
1172
1173 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
1174 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1175 goto nla_put_failure;
3713b4e3
JB
1176 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
1177 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1178 goto nla_put_failure;
1179 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
1180 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1181 goto nla_put_failure;
1182 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
1183 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1184 goto nla_put_failure;
1185 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
1186 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1187 goto nla_put_failure;
1188 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
1189 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1190 goto nla_put_failure;
8fdc621d 1191
3713b4e3
JB
1192 (*split_start)++;
1193 if (split)
1194 break;
1195 case 1:
1196 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1197 sizeof(u32) * dev->wiphy.n_cipher_suites,
1198 dev->wiphy.cipher_suites))
1199 goto nla_put_failure;
4745fc09 1200
3713b4e3
JB
1201 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1202 dev->wiphy.max_num_pmkids))
1203 goto nla_put_failure;
b23aa676 1204
3713b4e3
JB
1205 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
1206 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1207 goto nla_put_failure;
b23aa676 1208
3713b4e3
JB
1209 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1210 dev->wiphy.available_antennas_tx) ||
1211 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1212 dev->wiphy.available_antennas_rx))
9360ffd1 1213 goto nla_put_failure;
b23aa676 1214
3713b4e3
JB
1215 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
1216 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1217 dev->wiphy.probe_resp_offload))
1218 goto nla_put_failure;
8fdc621d 1219
3713b4e3
JB
1220 if ((dev->wiphy.available_antennas_tx ||
1221 dev->wiphy.available_antennas_rx) &&
1222 dev->ops->get_antenna) {
1223 u32 tx_ant = 0, rx_ant = 0;
1224 int res;
1225 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
1226 if (!res) {
1227 if (nla_put_u32(msg,
1228 NL80211_ATTR_WIPHY_ANTENNA_TX,
1229 tx_ant) ||
1230 nla_put_u32(msg,
1231 NL80211_ATTR_WIPHY_ANTENNA_RX,
1232 rx_ant))
1233 goto nla_put_failure;
1234 }
1235 }
a293911d 1236
3713b4e3
JB
1237 (*split_start)++;
1238 if (split)
1239 break;
1240 case 2:
1241 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1242 dev->wiphy.interface_modes))
1243 goto nla_put_failure;
1244 (*split_start)++;
1245 if (split)
1246 break;
1247 case 3:
1248 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1249 if (!nl_bands)
1250 goto nla_put_failure;
f7ca38df 1251
3713b4e3
JB
1252 for (band = *band_start; band < IEEE80211_NUM_BANDS; band++) {
1253 struct ieee80211_supported_band *sband;
2e161f78 1254
3713b4e3 1255 sband = dev->wiphy.bands[band];
2e161f78 1256
3713b4e3
JB
1257 if (!sband)
1258 continue;
1259
1260 nl_band = nla_nest_start(msg, band);
1261 if (!nl_band)
2e161f78 1262 goto nla_put_failure;
3713b4e3
JB
1263
1264 switch (*chan_start) {
1265 case 0:
1266 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 1267 goto nla_put_failure;
3713b4e3
JB
1268 (*chan_start)++;
1269 if (split)
1270 break;
1271 default:
1272 /* add frequencies */
1273 nl_freqs = nla_nest_start(
1274 msg, NL80211_BAND_ATTR_FREQS);
1275 if (!nl_freqs)
1276 goto nla_put_failure;
1277
1278 for (i = *chan_start - 1;
1279 i < sband->n_channels;
1280 i++) {
1281 nl_freq = nla_nest_start(msg, i);
1282 if (!nl_freq)
1283 goto nla_put_failure;
1284
1285 chan = &sband->channels[i];
1286
cdc89b97
JB
1287 if (nl80211_msg_put_channel(msg, chan,
1288 split))
3713b4e3
JB
1289 goto nla_put_failure;
1290
1291 nla_nest_end(msg, nl_freq);
1292 if (split)
1293 break;
1294 }
1295 if (i < sband->n_channels)
1296 *chan_start = i + 2;
1297 else
1298 *chan_start = 0;
1299 nla_nest_end(msg, nl_freqs);
1300 }
1301
1302 nla_nest_end(msg, nl_band);
1303
1304 if (split) {
1305 /* start again here */
1306 if (*chan_start)
1307 band--;
1308 break;
2e161f78 1309 }
2e161f78 1310 }
3713b4e3 1311 nla_nest_end(msg, nl_bands);
2e161f78 1312
3713b4e3
JB
1313 if (band < IEEE80211_NUM_BANDS)
1314 *band_start = band + 1;
1315 else
1316 *band_start = 0;
74b70a4e 1317
3713b4e3
JB
1318 /* if bands & channels are done, continue outside */
1319 if (*band_start == 0 && *chan_start == 0)
1320 (*split_start)++;
1321 if (split)
1322 break;
1323 case 4:
1324 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1325 if (!nl_cmds)
2e161f78
JB
1326 goto nla_put_failure;
1327
3713b4e3
JB
1328 i = 0;
1329#define CMD(op, n) \
1330 do { \
1331 if (dev->ops->op) { \
1332 i++; \
1333 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1334 goto nla_put_failure; \
1335 } \
1336 } while (0)
1337
1338 CMD(add_virtual_intf, NEW_INTERFACE);
1339 CMD(change_virtual_intf, SET_INTERFACE);
1340 CMD(add_key, NEW_KEY);
1341 CMD(start_ap, START_AP);
1342 CMD(add_station, NEW_STATION);
1343 CMD(add_mpath, NEW_MPATH);
1344 CMD(update_mesh_config, SET_MESH_CONFIG);
1345 CMD(change_bss, SET_BSS);
1346 CMD(auth, AUTHENTICATE);
1347 CMD(assoc, ASSOCIATE);
1348 CMD(deauth, DEAUTHENTICATE);
1349 CMD(disassoc, DISASSOCIATE);
1350 CMD(join_ibss, JOIN_IBSS);
1351 CMD(join_mesh, JOIN_MESH);
1352 CMD(set_pmksa, SET_PMKSA);
1353 CMD(del_pmksa, DEL_PMKSA);
1354 CMD(flush_pmksa, FLUSH_PMKSA);
1355 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1356 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1357 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1358 CMD(mgmt_tx, FRAME);
1359 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1360 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1361 i++;
1362 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
2e161f78 1363 goto nla_put_failure;
2e161f78 1364 }
3713b4e3
JB
1365 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
1366 dev->ops->join_mesh) {
1367 i++;
1368 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1369 goto nla_put_failure;
1370 }
1371 CMD(set_wds_peer, SET_WDS_PEER);
1372 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1373 CMD(tdls_mgmt, TDLS_MGMT);
1374 CMD(tdls_oper, TDLS_OPER);
1375 }
1376 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1377 CMD(sched_scan_start, START_SCHED_SCAN);
1378 CMD(probe_client, PROBE_CLIENT);
1379 CMD(set_noack_map, SET_NOACK_MAP);
1380 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1381 i++;
1382 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1383 goto nla_put_failure;
1384 }
1385 CMD(start_p2p_device, START_P2P_DEVICE);
1386 CMD(set_mcast_rate, SET_MCAST_RATE);
5de17984
AS
1387 if (split) {
1388 CMD(crit_proto_start, CRIT_PROTOCOL_START);
1389 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
1390 }
2e161f78 1391
3713b4e3
JB
1392#ifdef CONFIG_NL80211_TESTMODE
1393 CMD(testmode_cmd, TESTMODE);
1394#endif
ff1b6e69 1395
3713b4e3 1396#undef CMD
ff1b6e69 1397
3713b4e3
JB
1398 if (dev->ops->connect || dev->ops->auth) {
1399 i++;
1400 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
9360ffd1 1401 goto nla_put_failure;
ff1b6e69
JB
1402 }
1403
3713b4e3
JB
1404 if (dev->ops->disconnect || dev->ops->deauth) {
1405 i++;
1406 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1407 goto nla_put_failure;
1408 }
1409
1410 nla_nest_end(msg, nl_cmds);
1411 (*split_start)++;
1412 if (split)
1413 break;
1414 case 5:
1415 if (dev->ops->remain_on_channel &&
1416 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1417 nla_put_u32(msg,
1418 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1419 dev->wiphy.max_remain_on_channel_duration))
1420 goto nla_put_failure;
1421
1422 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1423 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1424 goto nla_put_failure;
1425
1426 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
1427 goto nla_put_failure;
1428 (*split_start)++;
1429 if (split)
1430 break;
1431 case 6:
1432#ifdef CONFIG_PM
b56cf720 1433 if (nl80211_send_wowlan(msg, dev, split))
3713b4e3
JB
1434 goto nla_put_failure;
1435 (*split_start)++;
1436 if (split)
1437 break;
1438#else
1439 (*split_start)++;
dfb89c56 1440#endif
3713b4e3
JB
1441 case 7:
1442 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1443 dev->wiphy.software_iftypes))
1444 goto nla_put_failure;
ff1b6e69 1445
cdc89b97 1446 if (nl80211_put_iface_combinations(&dev->wiphy, msg, split))
3713b4e3 1447 goto nla_put_failure;
7527a782 1448
3713b4e3
JB
1449 (*split_start)++;
1450 if (split)
1451 break;
1452 case 8:
1453 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1454 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1455 dev->wiphy.ap_sme_capa))
1456 goto nla_put_failure;
7527a782 1457
fe1abafd
JB
1458 features = dev->wiphy.features;
1459 /*
1460 * We can only add the per-channel limit information if the
1461 * dump is split, otherwise it makes it too big. Therefore
1462 * only advertise it in that case.
1463 */
1464 if (split)
1465 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
1466 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 1467 goto nla_put_failure;
562a7480 1468
3713b4e3
JB
1469 if (dev->wiphy.ht_capa_mod_mask &&
1470 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1471 sizeof(*dev->wiphy.ht_capa_mod_mask),
1472 dev->wiphy.ht_capa_mod_mask))
1473 goto nla_put_failure;
1f074bd8 1474
3713b4e3
JB
1475 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1476 dev->wiphy.max_acl_mac_addrs &&
1477 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1478 dev->wiphy.max_acl_mac_addrs))
1479 goto nla_put_failure;
7e7c8926 1480
3713b4e3
JB
1481 /*
1482 * Any information below this point is only available to
1483 * applications that can deal with it being split. This
1484 * helps ensure that newly added capabilities don't break
1485 * older tools by overrunning their buffers.
1486 *
1487 * We still increment split_start so that in the split
1488 * case we'll continue with more data in the next round,
1489 * but break unconditionally so unsplit data stops here.
1490 */
1491 (*split_start)++;
1492 break;
1493 case 9:
fe1abafd
JB
1494 if (dev->wiphy.extended_capabilities &&
1495 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1496 dev->wiphy.extended_capabilities_len,
1497 dev->wiphy.extended_capabilities) ||
1498 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1499 dev->wiphy.extended_capabilities_len,
1500 dev->wiphy.extended_capabilities_mask)))
1501 goto nla_put_failure;
a50df0c4 1502
ee2aca34
JB
1503 if (dev->wiphy.vht_capa_mod_mask &&
1504 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1505 sizeof(*dev->wiphy.vht_capa_mod_mask),
1506 dev->wiphy.vht_capa_mod_mask))
1507 goto nla_put_failure;
1508
3713b4e3
JB
1509 /* done */
1510 *split_start = 0;
1511 break;
1512 }
55682965
JB
1513 return genlmsg_end(msg, hdr);
1514
1515 nla_put_failure:
bc3ed28c
TG
1516 genlmsg_cancel(msg, hdr);
1517 return -EMSGSIZE;
55682965
JB
1518}
1519
1520static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1521{
645e77de 1522 int idx = 0, ret;
55682965
JB
1523 int start = cb->args[0];
1524 struct cfg80211_registered_device *dev;
3713b4e3
JB
1525 s64 filter_wiphy = -1;
1526 bool split = false;
3a5a423b 1527 struct nlattr **tb;
3713b4e3 1528 int res;
55682965 1529
3a5a423b
JB
1530 /* will be zeroed in nlmsg_parse() */
1531 tb = kmalloc(sizeof(*tb) * (NL80211_ATTR_MAX + 1), GFP_KERNEL);
1532 if (!tb)
1533 return -ENOMEM;
1534
5fe231e8 1535 rtnl_lock();
d98cae64 1536
3713b4e3 1537 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
3a5a423b 1538 tb, NL80211_ATTR_MAX, nl80211_policy);
3713b4e3
JB
1539 if (res == 0) {
1540 split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
1541 if (tb[NL80211_ATTR_WIPHY])
1542 filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
1543 if (tb[NL80211_ATTR_WDEV])
1544 filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
1545 if (tb[NL80211_ATTR_IFINDEX]) {
1546 struct net_device *netdev;
1547 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
1548
1549 netdev = dev_get_by_index(sock_net(skb->sk), ifidx);
1550 if (!netdev) {
d98cae64 1551 rtnl_unlock();
3a5a423b 1552 kfree(tb);
3713b4e3
JB
1553 return -ENODEV;
1554 }
1555 if (netdev->ieee80211_ptr) {
1556 dev = wiphy_to_dev(
1557 netdev->ieee80211_ptr->wiphy);
1558 filter_wiphy = dev->wiphy_idx;
1559 }
1560 dev_put(netdev);
1561 }
1562 }
3a5a423b 1563 kfree(tb);
3713b4e3 1564
79c97e97 1565 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1566 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1567 continue;
b4637271 1568 if (++idx <= start)
55682965 1569 continue;
3713b4e3
JB
1570 if (filter_wiphy != -1 && dev->wiphy_idx != filter_wiphy)
1571 continue;
1572 /* attempt to fit multiple wiphy data chunks into the skb */
1573 do {
1574 ret = nl80211_send_wiphy(dev, skb,
1575 NETLINK_CB(cb->skb).portid,
1576 cb->nlh->nlmsg_seq,
1577 NLM_F_MULTI,
1578 split, &cb->args[1],
1579 &cb->args[2],
1580 &cb->args[3]);
1581 if (ret < 0) {
1582 /*
1583 * If sending the wiphy data didn't fit (ENOBUFS
1584 * or EMSGSIZE returned), this SKB is still
1585 * empty (so it's not too big because another
1586 * wiphy dataset is already in the skb) and
1587 * we've not tried to adjust the dump allocation
1588 * yet ... then adjust the alloc size to be
1589 * bigger, and return 1 but with the empty skb.
1590 * This results in an empty message being RX'ed
1591 * in userspace, but that is ignored.
1592 *
1593 * We can then retry with the larger buffer.
1594 */
1595 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
1596 !skb->len &&
1597 cb->min_dump_alloc < 4096) {
1598 cb->min_dump_alloc = 4096;
d98cae64 1599 rtnl_unlock();
3713b4e3
JB
1600 return 1;
1601 }
1602 idx--;
1603 break;
645e77de 1604 }
3713b4e3
JB
1605 } while (cb->args[1] > 0);
1606 break;
55682965 1607 }
5fe231e8 1608 rtnl_unlock();
55682965
JB
1609
1610 cb->args[0] = idx;
1611
1612 return skb->len;
1613}
1614
1615static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1616{
1617 struct sk_buff *msg;
4c476991 1618 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1619
645e77de 1620 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 1621 if (!msg)
4c476991 1622 return -ENOMEM;
55682965 1623
3713b4e3
JB
1624 if (nl80211_send_wiphy(dev, msg, info->snd_portid, info->snd_seq, 0,
1625 false, NULL, NULL, NULL) < 0) {
4c476991
JB
1626 nlmsg_free(msg);
1627 return -ENOBUFS;
1628 }
55682965 1629
134e6375 1630 return genlmsg_reply(msg, info);
55682965
JB
1631}
1632
31888487
JM
1633static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1634 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1635 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1636 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1637 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1638 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1639};
1640
1641static int parse_txq_params(struct nlattr *tb[],
1642 struct ieee80211_txq_params *txq_params)
1643{
a3304b0a 1644 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1645 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1646 !tb[NL80211_TXQ_ATTR_AIFS])
1647 return -EINVAL;
1648
a3304b0a 1649 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1650 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1651 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1652 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1653 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1654
a3304b0a
JB
1655 if (txq_params->ac >= NL80211_NUM_ACS)
1656 return -EINVAL;
1657
31888487
JM
1658 return 0;
1659}
1660
f444de05
JB
1661static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1662{
1663 /*
cc1d2806
JB
1664 * You can only set the channel explicitly for WDS interfaces,
1665 * all others have their channel managed via their respective
1666 * "establish a connection" command (connect, join, ...)
1667 *
1668 * For AP/GO and mesh mode, the channel can be set with the
1669 * channel userspace API, but is only stored and passed to the
1670 * low-level driver when the AP starts or the mesh is joined.
1671 * This is for backward compatibility, userspace can also give
1672 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1673 *
1674 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1675 * whatever else is going on, so they have their own special
1676 * operation to set the monitor channel if possible.
f444de05
JB
1677 */
1678 return !wdev ||
1679 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1680 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1681 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1682 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1683}
1684
683b6d3b
JB
1685static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1686 struct genl_info *info,
1687 struct cfg80211_chan_def *chandef)
1688{
dbeca2ea 1689 u32 control_freq;
683b6d3b
JB
1690
1691 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1692 return -EINVAL;
1693
1694 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1695
1696 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1697 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1698 chandef->center_freq1 = control_freq;
1699 chandef->center_freq2 = 0;
683b6d3b
JB
1700
1701 /* Primary channel not allowed */
1702 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1703 return -EINVAL;
1704
3d9d1d66
JB
1705 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1706 enum nl80211_channel_type chantype;
1707
1708 chantype = nla_get_u32(
1709 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1710
1711 switch (chantype) {
1712 case NL80211_CHAN_NO_HT:
1713 case NL80211_CHAN_HT20:
1714 case NL80211_CHAN_HT40PLUS:
1715 case NL80211_CHAN_HT40MINUS:
1716 cfg80211_chandef_create(chandef, chandef->chan,
1717 chantype);
1718 break;
1719 default:
1720 return -EINVAL;
1721 }
1722 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1723 chandef->width =
1724 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1725 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1726 chandef->center_freq1 =
1727 nla_get_u32(
1728 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1729 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1730 chandef->center_freq2 =
1731 nla_get_u32(
1732 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1733 }
1734
9f5e8f6e 1735 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1736 return -EINVAL;
1737
9f5e8f6e
JB
1738 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1739 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1740 return -EINVAL;
1741
683b6d3b
JB
1742 return 0;
1743}
1744
f444de05
JB
1745static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1746 struct wireless_dev *wdev,
1747 struct genl_info *info)
1748{
683b6d3b 1749 struct cfg80211_chan_def chandef;
f444de05 1750 int result;
e8c9bd5b
JB
1751 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1752
1753 if (wdev)
1754 iftype = wdev->iftype;
f444de05 1755
f444de05
JB
1756 if (!nl80211_can_set_dev_channel(wdev))
1757 return -EOPNOTSUPP;
1758
683b6d3b
JB
1759 result = nl80211_parse_chandef(rdev, info, &chandef);
1760 if (result)
1761 return result;
f444de05 1762
e8c9bd5b 1763 switch (iftype) {
aa430da4
JB
1764 case NL80211_IFTYPE_AP:
1765 case NL80211_IFTYPE_P2P_GO:
1766 if (wdev->beacon_interval) {
1767 result = -EBUSY;
1768 break;
1769 }
683b6d3b 1770 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1771 result = -EINVAL;
1772 break;
1773 }
683b6d3b 1774 wdev->preset_chandef = chandef;
aa430da4
JB
1775 result = 0;
1776 break;
cc1d2806 1777 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1778 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1779 break;
e8c9bd5b 1780 case NL80211_IFTYPE_MONITOR:
683b6d3b 1781 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1782 break;
aa430da4 1783 default:
e8c9bd5b 1784 result = -EINVAL;
f444de05 1785 }
f444de05
JB
1786
1787 return result;
1788}
1789
1790static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1791{
4c476991
JB
1792 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1793 struct net_device *netdev = info->user_ptr[1];
f444de05 1794
4c476991 1795 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1796}
1797
e8347eba
BJ
1798static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1799{
43b19952
JB
1800 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1801 struct net_device *dev = info->user_ptr[1];
1802 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1803 const u8 *bssid;
e8347eba
BJ
1804
1805 if (!info->attrs[NL80211_ATTR_MAC])
1806 return -EINVAL;
1807
43b19952
JB
1808 if (netif_running(dev))
1809 return -EBUSY;
e8347eba 1810
43b19952
JB
1811 if (!rdev->ops->set_wds_peer)
1812 return -EOPNOTSUPP;
e8347eba 1813
43b19952
JB
1814 if (wdev->iftype != NL80211_IFTYPE_WDS)
1815 return -EOPNOTSUPP;
e8347eba
BJ
1816
1817 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1818 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1819}
1820
1821
55682965
JB
1822static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1823{
1824 struct cfg80211_registered_device *rdev;
f444de05
JB
1825 struct net_device *netdev = NULL;
1826 struct wireless_dev *wdev;
a1e567c8 1827 int result = 0, rem_txq_params = 0;
31888487 1828 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1829 u32 changed;
1830 u8 retry_short = 0, retry_long = 0;
1831 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1832 u8 coverage_class = 0;
55682965 1833
5fe231e8
JB
1834 ASSERT_RTNL();
1835
f444de05
JB
1836 /*
1837 * Try to find the wiphy and netdev. Normally this
1838 * function shouldn't need the netdev, but this is
1839 * done for backward compatibility -- previously
1840 * setting the channel was done per wiphy, but now
1841 * it is per netdev. Previous userland like hostapd
1842 * also passed a netdev to set_wiphy, so that it is
1843 * possible to let that go to the right netdev!
1844 */
4bbf4d56 1845
f444de05
JB
1846 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1847 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1848
1849 netdev = dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 1850 if (netdev && netdev->ieee80211_ptr)
f444de05 1851 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
5fe231e8 1852 else
f444de05 1853 netdev = NULL;
4bbf4d56
JB
1854 }
1855
f444de05 1856 if (!netdev) {
878d9ec7
JB
1857 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1858 info->attrs);
5fe231e8 1859 if (IS_ERR(rdev))
4c476991 1860 return PTR_ERR(rdev);
f444de05
JB
1861 wdev = NULL;
1862 netdev = NULL;
1863 result = 0;
71fe96bf 1864 } else
f444de05 1865 wdev = netdev->ieee80211_ptr;
f444de05
JB
1866
1867 /*
1868 * end workaround code, by now the rdev is available
1869 * and locked, and wdev may or may not be NULL.
1870 */
4bbf4d56
JB
1871
1872 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1873 result = cfg80211_dev_rename(
1874 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 1875
4bbf4d56
JB
1876 if (result)
1877 goto bad_res;
31888487
JM
1878
1879 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1880 struct ieee80211_txq_params txq_params;
1881 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1882
1883 if (!rdev->ops->set_txq_params) {
1884 result = -EOPNOTSUPP;
1885 goto bad_res;
1886 }
1887
f70f01c2
EP
1888 if (!netdev) {
1889 result = -EINVAL;
1890 goto bad_res;
1891 }
1892
133a3ff2
JB
1893 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1894 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1895 result = -EINVAL;
1896 goto bad_res;
1897 }
1898
2b5f8b0b
JB
1899 if (!netif_running(netdev)) {
1900 result = -ENETDOWN;
1901 goto bad_res;
1902 }
1903
31888487
JM
1904 nla_for_each_nested(nl_txq_params,
1905 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1906 rem_txq_params) {
1907 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1908 nla_data(nl_txq_params),
1909 nla_len(nl_txq_params),
1910 txq_params_policy);
1911 result = parse_txq_params(tb, &txq_params);
1912 if (result)
1913 goto bad_res;
1914
e35e4d28
HG
1915 result = rdev_set_txq_params(rdev, netdev,
1916 &txq_params);
31888487
JM
1917 if (result)
1918 goto bad_res;
1919 }
1920 }
55682965 1921
72bdcf34 1922 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1923 result = __nl80211_set_channel(rdev,
1924 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1925 info);
72bdcf34
JM
1926 if (result)
1927 goto bad_res;
1928 }
1929
98d2ff8b 1930 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 1931 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
1932 enum nl80211_tx_power_setting type;
1933 int idx, mbm = 0;
1934
c8442118
JB
1935 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
1936 txp_wdev = NULL;
1937
98d2ff8b 1938 if (!rdev->ops->set_tx_power) {
60ea385f 1939 result = -EOPNOTSUPP;
98d2ff8b
JO
1940 goto bad_res;
1941 }
1942
1943 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1944 type = nla_get_u32(info->attrs[idx]);
1945
1946 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1947 (type != NL80211_TX_POWER_AUTOMATIC)) {
1948 result = -EINVAL;
1949 goto bad_res;
1950 }
1951
1952 if (type != NL80211_TX_POWER_AUTOMATIC) {
1953 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1954 mbm = nla_get_u32(info->attrs[idx]);
1955 }
1956
c8442118 1957 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
1958 if (result)
1959 goto bad_res;
1960 }
1961
afe0cbf8
BR
1962 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1963 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1964 u32 tx_ant, rx_ant;
7f531e03
BR
1965 if ((!rdev->wiphy.available_antennas_tx &&
1966 !rdev->wiphy.available_antennas_rx) ||
1967 !rdev->ops->set_antenna) {
afe0cbf8
BR
1968 result = -EOPNOTSUPP;
1969 goto bad_res;
1970 }
1971
1972 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1973 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1974
a7ffac95 1975 /* reject antenna configurations which don't match the
7f531e03
BR
1976 * available antenna masks, except for the "all" mask */
1977 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1978 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1979 result = -EINVAL;
1980 goto bad_res;
1981 }
1982
7f531e03
BR
1983 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1984 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1985
e35e4d28 1986 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
1987 if (result)
1988 goto bad_res;
1989 }
1990
b9a5f8ca
JM
1991 changed = 0;
1992
1993 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1994 retry_short = nla_get_u8(
1995 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1996 if (retry_short == 0) {
1997 result = -EINVAL;
1998 goto bad_res;
1999 }
2000 changed |= WIPHY_PARAM_RETRY_SHORT;
2001 }
2002
2003 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2004 retry_long = nla_get_u8(
2005 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
2006 if (retry_long == 0) {
2007 result = -EINVAL;
2008 goto bad_res;
2009 }
2010 changed |= WIPHY_PARAM_RETRY_LONG;
2011 }
2012
2013 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2014 frag_threshold = nla_get_u32(
2015 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
2016 if (frag_threshold < 256) {
2017 result = -EINVAL;
2018 goto bad_res;
2019 }
2020 if (frag_threshold != (u32) -1) {
2021 /*
2022 * Fragments (apart from the last one) are required to
2023 * have even length. Make the fragmentation code
2024 * simpler by stripping LSB should someone try to use
2025 * odd threshold value.
2026 */
2027 frag_threshold &= ~0x1;
2028 }
2029 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2030 }
2031
2032 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2033 rts_threshold = nla_get_u32(
2034 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2035 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2036 }
2037
81077e82
LT
2038 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
2039 coverage_class = nla_get_u8(
2040 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2041 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2042 }
2043
b9a5f8ca
JM
2044 if (changed) {
2045 u8 old_retry_short, old_retry_long;
2046 u32 old_frag_threshold, old_rts_threshold;
81077e82 2047 u8 old_coverage_class;
b9a5f8ca
JM
2048
2049 if (!rdev->ops->set_wiphy_params) {
2050 result = -EOPNOTSUPP;
2051 goto bad_res;
2052 }
2053
2054 old_retry_short = rdev->wiphy.retry_short;
2055 old_retry_long = rdev->wiphy.retry_long;
2056 old_frag_threshold = rdev->wiphy.frag_threshold;
2057 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 2058 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
2059
2060 if (changed & WIPHY_PARAM_RETRY_SHORT)
2061 rdev->wiphy.retry_short = retry_short;
2062 if (changed & WIPHY_PARAM_RETRY_LONG)
2063 rdev->wiphy.retry_long = retry_long;
2064 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
2065 rdev->wiphy.frag_threshold = frag_threshold;
2066 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
2067 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
2068 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
2069 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 2070
e35e4d28 2071 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
2072 if (result) {
2073 rdev->wiphy.retry_short = old_retry_short;
2074 rdev->wiphy.retry_long = old_retry_long;
2075 rdev->wiphy.frag_threshold = old_frag_threshold;
2076 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 2077 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
2078 }
2079 }
72bdcf34 2080
306d6112 2081 bad_res:
f444de05
JB
2082 if (netdev)
2083 dev_put(netdev);
55682965
JB
2084 return result;
2085}
2086
71bbc994
JB
2087static inline u64 wdev_id(struct wireless_dev *wdev)
2088{
2089 return (u64)wdev->identifier |
2090 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
2091}
55682965 2092
683b6d3b
JB
2093static int nl80211_send_chandef(struct sk_buff *msg,
2094 struct cfg80211_chan_def *chandef)
2095{
9f5e8f6e 2096 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 2097
683b6d3b
JB
2098 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
2099 chandef->chan->center_freq))
2100 return -ENOBUFS;
3d9d1d66
JB
2101 switch (chandef->width) {
2102 case NL80211_CHAN_WIDTH_20_NOHT:
2103 case NL80211_CHAN_WIDTH_20:
2104 case NL80211_CHAN_WIDTH_40:
2105 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2106 cfg80211_get_chandef_type(chandef)))
2107 return -ENOBUFS;
2108 break;
2109 default:
2110 break;
2111 }
2112 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
2113 return -ENOBUFS;
2114 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
2115 return -ENOBUFS;
2116 if (chandef->center_freq2 &&
2117 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
2118 return -ENOBUFS;
2119 return 0;
2120}
2121
15e47304 2122static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 2123 struct cfg80211_registered_device *rdev,
72fb2abc 2124 struct wireless_dev *wdev)
55682965 2125{
72fb2abc 2126 struct net_device *dev = wdev->netdev;
55682965
JB
2127 void *hdr;
2128
15e47304 2129 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
2130 if (!hdr)
2131 return -1;
2132
72fb2abc
JB
2133 if (dev &&
2134 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 2135 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
2136 goto nla_put_failure;
2137
2138 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2139 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 2140 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 2141 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
2142 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2143 rdev->devlist_generation ^
2144 (cfg80211_rdev_list_generation << 2)))
2145 goto nla_put_failure;
f5ea9120 2146
5b7ccaf3 2147 if (rdev->ops->get_channel) {
683b6d3b
JB
2148 int ret;
2149 struct cfg80211_chan_def chandef;
2150
2151 ret = rdev_get_channel(rdev, wdev, &chandef);
2152 if (ret == 0) {
2153 if (nl80211_send_chandef(msg, &chandef))
2154 goto nla_put_failure;
2155 }
d91df0e3
PF
2156 }
2157
b84e7a05
AQ
2158 if (wdev->ssid_len) {
2159 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
2160 goto nla_put_failure;
2161 }
2162
55682965
JB
2163 return genlmsg_end(msg, hdr);
2164
2165 nla_put_failure:
bc3ed28c
TG
2166 genlmsg_cancel(msg, hdr);
2167 return -EMSGSIZE;
55682965
JB
2168}
2169
2170static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
2171{
2172 int wp_idx = 0;
2173 int if_idx = 0;
2174 int wp_start = cb->args[0];
2175 int if_start = cb->args[1];
f5ea9120 2176 struct cfg80211_registered_device *rdev;
55682965
JB
2177 struct wireless_dev *wdev;
2178
5fe231e8 2179 rtnl_lock();
f5ea9120
JB
2180 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2181 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2182 continue;
bba95fef
JB
2183 if (wp_idx < wp_start) {
2184 wp_idx++;
55682965 2185 continue;
bba95fef 2186 }
55682965
JB
2187 if_idx = 0;
2188
89a54e48 2189 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
2190 if (if_idx < if_start) {
2191 if_idx++;
55682965 2192 continue;
bba95fef 2193 }
15e47304 2194 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 2195 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 2196 rdev, wdev) < 0) {
bba95fef
JB
2197 goto out;
2198 }
2199 if_idx++;
55682965 2200 }
bba95fef
JB
2201
2202 wp_idx++;
55682965 2203 }
bba95fef 2204 out:
5fe231e8 2205 rtnl_unlock();
55682965
JB
2206
2207 cb->args[0] = wp_idx;
2208 cb->args[1] = if_idx;
2209
2210 return skb->len;
2211}
2212
2213static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
2214{
2215 struct sk_buff *msg;
4c476991 2216 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 2217 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2218
fd2120ca 2219 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 2220 if (!msg)
4c476991 2221 return -ENOMEM;
55682965 2222
15e47304 2223 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 2224 dev, wdev) < 0) {
4c476991
JB
2225 nlmsg_free(msg);
2226 return -ENOBUFS;
2227 }
55682965 2228
134e6375 2229 return genlmsg_reply(msg, info);
55682965
JB
2230}
2231
66f7ac50
MW
2232static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2233 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2234 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2235 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2236 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2237 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 2238 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
2239};
2240
2241static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2242{
2243 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2244 int flag;
2245
2246 *mntrflags = 0;
2247
2248 if (!nla)
2249 return -EINVAL;
2250
2251 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
2252 nla, mntr_flags_policy))
2253 return -EINVAL;
2254
2255 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2256 if (flags[flag])
2257 *mntrflags |= (1<<flag);
2258
2259 return 0;
2260}
2261
9bc383de 2262static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2263 struct net_device *netdev, u8 use_4addr,
2264 enum nl80211_iftype iftype)
9bc383de 2265{
ad4bb6f8 2266 if (!use_4addr) {
f350a0a8 2267 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2268 return -EBUSY;
9bc383de 2269 return 0;
ad4bb6f8 2270 }
9bc383de
JB
2271
2272 switch (iftype) {
2273 case NL80211_IFTYPE_AP_VLAN:
2274 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2275 return 0;
2276 break;
2277 case NL80211_IFTYPE_STATION:
2278 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2279 return 0;
2280 break;
2281 default:
2282 break;
2283 }
2284
2285 return -EOPNOTSUPP;
2286}
2287
55682965
JB
2288static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2289{
4c476991 2290 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2291 struct vif_params params;
e36d56b6 2292 int err;
04a773ad 2293 enum nl80211_iftype otype, ntype;
4c476991 2294 struct net_device *dev = info->user_ptr[1];
92ffe055 2295 u32 _flags, *flags = NULL;
ac7f9cfa 2296 bool change = false;
55682965 2297
2ec600d6
LCC
2298 memset(&params, 0, sizeof(params));
2299
04a773ad 2300 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2301
723b038d 2302 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2303 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2304 if (otype != ntype)
ac7f9cfa 2305 change = true;
4c476991
JB
2306 if (ntype > NL80211_IFTYPE_MAX)
2307 return -EINVAL;
723b038d
JB
2308 }
2309
92ffe055 2310 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2311 struct wireless_dev *wdev = dev->ieee80211_ptr;
2312
4c476991
JB
2313 if (ntype != NL80211_IFTYPE_MESH_POINT)
2314 return -EINVAL;
29cbe68c
JB
2315 if (netif_running(dev))
2316 return -EBUSY;
2317
2318 wdev_lock(wdev);
2319 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2320 IEEE80211_MAX_MESH_ID_LEN);
2321 wdev->mesh_id_up_len =
2322 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2323 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2324 wdev->mesh_id_up_len);
2325 wdev_unlock(wdev);
2ec600d6
LCC
2326 }
2327
8b787643
FF
2328 if (info->attrs[NL80211_ATTR_4ADDR]) {
2329 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2330 change = true;
ad4bb6f8 2331 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2332 if (err)
4c476991 2333 return err;
8b787643
FF
2334 } else {
2335 params.use_4addr = -1;
2336 }
2337
92ffe055 2338 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2339 if (ntype != NL80211_IFTYPE_MONITOR)
2340 return -EINVAL;
92ffe055
JB
2341 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2342 &_flags);
ac7f9cfa 2343 if (err)
4c476991 2344 return err;
ac7f9cfa
JB
2345
2346 flags = &_flags;
2347 change = true;
92ffe055 2348 }
3b85875a 2349
e057d3c3
FF
2350 if (flags && (*flags & NL80211_MNTR_FLAG_ACTIVE) &&
2351 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2352 return -EOPNOTSUPP;
2353
ac7f9cfa 2354 if (change)
3d54d255 2355 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2356 else
2357 err = 0;
60719ffd 2358
9bc383de
JB
2359 if (!err && params.use_4addr != -1)
2360 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2361
55682965
JB
2362 return err;
2363}
2364
2365static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2366{
4c476991 2367 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2368 struct vif_params params;
84efbb84 2369 struct wireless_dev *wdev;
1c90f9d4 2370 struct sk_buff *msg;
55682965
JB
2371 int err;
2372 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2373 u32 flags;
55682965 2374
2ec600d6
LCC
2375 memset(&params, 0, sizeof(params));
2376
55682965
JB
2377 if (!info->attrs[NL80211_ATTR_IFNAME])
2378 return -EINVAL;
2379
2380 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2381 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2382 if (type > NL80211_IFTYPE_MAX)
2383 return -EINVAL;
2384 }
2385
79c97e97 2386 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2387 !(rdev->wiphy.interface_modes & (1 << type)))
2388 return -EOPNOTSUPP;
55682965 2389
1c18f145
AS
2390 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2391 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2392 ETH_ALEN);
2393 if (!is_valid_ether_addr(params.macaddr))
2394 return -EADDRNOTAVAIL;
2395 }
2396
9bc383de 2397 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2398 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2399 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2400 if (err)
4c476991 2401 return err;
9bc383de 2402 }
8b787643 2403
1c90f9d4
JB
2404 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2405 if (!msg)
2406 return -ENOMEM;
2407
66f7ac50
MW
2408 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2409 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2410 &flags);
e057d3c3
FF
2411
2412 if (!err && (flags & NL80211_MNTR_FLAG_ACTIVE) &&
2413 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2414 return -EOPNOTSUPP;
2415
e35e4d28
HG
2416 wdev = rdev_add_virtual_intf(rdev,
2417 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2418 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2419 if (IS_ERR(wdev)) {
2420 nlmsg_free(msg);
84efbb84 2421 return PTR_ERR(wdev);
1c90f9d4 2422 }
2ec600d6 2423
98104fde
JB
2424 switch (type) {
2425 case NL80211_IFTYPE_MESH_POINT:
2426 if (!info->attrs[NL80211_ATTR_MESH_ID])
2427 break;
29cbe68c
JB
2428 wdev_lock(wdev);
2429 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2430 IEEE80211_MAX_MESH_ID_LEN);
2431 wdev->mesh_id_up_len =
2432 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2433 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2434 wdev->mesh_id_up_len);
2435 wdev_unlock(wdev);
98104fde
JB
2436 break;
2437 case NL80211_IFTYPE_P2P_DEVICE:
2438 /*
2439 * P2P Device doesn't have a netdev, so doesn't go
2440 * through the netdev notifier and must be added here
2441 */
2442 mutex_init(&wdev->mtx);
2443 INIT_LIST_HEAD(&wdev->event_list);
2444 spin_lock_init(&wdev->event_lock);
2445 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2446 spin_lock_init(&wdev->mgmt_registrations_lock);
2447
98104fde
JB
2448 wdev->identifier = ++rdev->wdev_id;
2449 list_add_rcu(&wdev->list, &rdev->wdev_list);
2450 rdev->devlist_generation++;
98104fde
JB
2451 break;
2452 default:
2453 break;
29cbe68c
JB
2454 }
2455
15e47304 2456 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2457 rdev, wdev) < 0) {
2458 nlmsg_free(msg);
2459 return -ENOBUFS;
2460 }
2461
2462 return genlmsg_reply(msg, info);
55682965
JB
2463}
2464
2465static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2466{
4c476991 2467 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2468 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2469
4c476991
JB
2470 if (!rdev->ops->del_virtual_intf)
2471 return -EOPNOTSUPP;
55682965 2472
84efbb84
JB
2473 /*
2474 * If we remove a wireless device without a netdev then clear
2475 * user_ptr[1] so that nl80211_post_doit won't dereference it
2476 * to check if it needs to do dev_put(). Otherwise it crashes
2477 * since the wdev has been freed, unlike with a netdev where
2478 * we need the dev_put() for the netdev to really be freed.
2479 */
2480 if (!wdev->netdev)
2481 info->user_ptr[1] = NULL;
2482
e35e4d28 2483 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2484}
2485
1d9d9213
SW
2486static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2487{
2488 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2489 struct net_device *dev = info->user_ptr[1];
2490 u16 noack_map;
2491
2492 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2493 return -EINVAL;
2494
2495 if (!rdev->ops->set_noack_map)
2496 return -EOPNOTSUPP;
2497
2498 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2499
e35e4d28 2500 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2501}
2502
41ade00f
JB
2503struct get_key_cookie {
2504 struct sk_buff *msg;
2505 int error;
b9454e83 2506 int idx;
41ade00f
JB
2507};
2508
2509static void get_key_callback(void *c, struct key_params *params)
2510{
b9454e83 2511 struct nlattr *key;
41ade00f
JB
2512 struct get_key_cookie *cookie = c;
2513
9360ffd1
DM
2514 if ((params->key &&
2515 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2516 params->key_len, params->key)) ||
2517 (params->seq &&
2518 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2519 params->seq_len, params->seq)) ||
2520 (params->cipher &&
2521 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2522 params->cipher)))
2523 goto nla_put_failure;
41ade00f 2524
b9454e83
JB
2525 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2526 if (!key)
2527 goto nla_put_failure;
2528
9360ffd1
DM
2529 if ((params->key &&
2530 nla_put(cookie->msg, NL80211_KEY_DATA,
2531 params->key_len, params->key)) ||
2532 (params->seq &&
2533 nla_put(cookie->msg, NL80211_KEY_SEQ,
2534 params->seq_len, params->seq)) ||
2535 (params->cipher &&
2536 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2537 params->cipher)))
2538 goto nla_put_failure;
b9454e83 2539
9360ffd1
DM
2540 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2541 goto nla_put_failure;
b9454e83
JB
2542
2543 nla_nest_end(cookie->msg, key);
2544
41ade00f
JB
2545 return;
2546 nla_put_failure:
2547 cookie->error = 1;
2548}
2549
2550static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2551{
4c476991 2552 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2553 int err;
4c476991 2554 struct net_device *dev = info->user_ptr[1];
41ade00f 2555 u8 key_idx = 0;
e31b8213
JB
2556 const u8 *mac_addr = NULL;
2557 bool pairwise;
41ade00f
JB
2558 struct get_key_cookie cookie = {
2559 .error = 0,
2560 };
2561 void *hdr;
2562 struct sk_buff *msg;
2563
2564 if (info->attrs[NL80211_ATTR_KEY_IDX])
2565 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2566
3cfcf6ac 2567 if (key_idx > 5)
41ade00f
JB
2568 return -EINVAL;
2569
2570 if (info->attrs[NL80211_ATTR_MAC])
2571 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2572
e31b8213
JB
2573 pairwise = !!mac_addr;
2574 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2575 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2576 if (kt >= NUM_NL80211_KEYTYPES)
2577 return -EINVAL;
2578 if (kt != NL80211_KEYTYPE_GROUP &&
2579 kt != NL80211_KEYTYPE_PAIRWISE)
2580 return -EINVAL;
2581 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2582 }
2583
4c476991
JB
2584 if (!rdev->ops->get_key)
2585 return -EOPNOTSUPP;
41ade00f 2586
fd2120ca 2587 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2588 if (!msg)
2589 return -ENOMEM;
41ade00f 2590
15e47304 2591 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2592 NL80211_CMD_NEW_KEY);
4c476991
JB
2593 if (IS_ERR(hdr))
2594 return PTR_ERR(hdr);
41ade00f
JB
2595
2596 cookie.msg = msg;
b9454e83 2597 cookie.idx = key_idx;
41ade00f 2598
9360ffd1
DM
2599 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2600 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2601 goto nla_put_failure;
2602 if (mac_addr &&
2603 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2604 goto nla_put_failure;
41ade00f 2605
e31b8213
JB
2606 if (pairwise && mac_addr &&
2607 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2608 return -ENOENT;
2609
e35e4d28
HG
2610 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2611 get_key_callback);
41ade00f
JB
2612
2613 if (err)
6c95e2a2 2614 goto free_msg;
41ade00f
JB
2615
2616 if (cookie.error)
2617 goto nla_put_failure;
2618
2619 genlmsg_end(msg, hdr);
4c476991 2620 return genlmsg_reply(msg, info);
41ade00f
JB
2621
2622 nla_put_failure:
2623 err = -ENOBUFS;
6c95e2a2 2624 free_msg:
41ade00f 2625 nlmsg_free(msg);
41ade00f
JB
2626 return err;
2627}
2628
2629static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2630{
4c476991 2631 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2632 struct key_parse key;
41ade00f 2633 int err;
4c476991 2634 struct net_device *dev = info->user_ptr[1];
41ade00f 2635
b9454e83
JB
2636 err = nl80211_parse_key(info, &key);
2637 if (err)
2638 return err;
41ade00f 2639
b9454e83 2640 if (key.idx < 0)
41ade00f
JB
2641 return -EINVAL;
2642
b9454e83
JB
2643 /* only support setting default key */
2644 if (!key.def && !key.defmgmt)
41ade00f
JB
2645 return -EINVAL;
2646
dbd2fd65 2647 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2648
dbd2fd65
JB
2649 if (key.def) {
2650 if (!rdev->ops->set_default_key) {
2651 err = -EOPNOTSUPP;
2652 goto out;
2653 }
41ade00f 2654
dbd2fd65
JB
2655 err = nl80211_key_allowed(dev->ieee80211_ptr);
2656 if (err)
2657 goto out;
2658
e35e4d28 2659 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2660 key.def_uni, key.def_multi);
2661
2662 if (err)
2663 goto out;
fffd0934 2664
3d23e349 2665#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2666 dev->ieee80211_ptr->wext.default_key = key.idx;
2667#endif
2668 } else {
2669 if (key.def_uni || !key.def_multi) {
2670 err = -EINVAL;
2671 goto out;
2672 }
2673
2674 if (!rdev->ops->set_default_mgmt_key) {
2675 err = -EOPNOTSUPP;
2676 goto out;
2677 }
2678
2679 err = nl80211_key_allowed(dev->ieee80211_ptr);
2680 if (err)
2681 goto out;
2682
e35e4d28 2683 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2684 if (err)
2685 goto out;
2686
2687#ifdef CONFIG_CFG80211_WEXT
2688 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2689#endif
dbd2fd65
JB
2690 }
2691
2692 out:
fffd0934 2693 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2694
41ade00f
JB
2695 return err;
2696}
2697
2698static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2699{
4c476991 2700 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2701 int err;
4c476991 2702 struct net_device *dev = info->user_ptr[1];
b9454e83 2703 struct key_parse key;
e31b8213 2704 const u8 *mac_addr = NULL;
41ade00f 2705
b9454e83
JB
2706 err = nl80211_parse_key(info, &key);
2707 if (err)
2708 return err;
41ade00f 2709
b9454e83 2710 if (!key.p.key)
41ade00f
JB
2711 return -EINVAL;
2712
41ade00f
JB
2713 if (info->attrs[NL80211_ATTR_MAC])
2714 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2715
e31b8213
JB
2716 if (key.type == -1) {
2717 if (mac_addr)
2718 key.type = NL80211_KEYTYPE_PAIRWISE;
2719 else
2720 key.type = NL80211_KEYTYPE_GROUP;
2721 }
2722
2723 /* for now */
2724 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2725 key.type != NL80211_KEYTYPE_GROUP)
2726 return -EINVAL;
2727
4c476991
JB
2728 if (!rdev->ops->add_key)
2729 return -EOPNOTSUPP;
25e47c18 2730
e31b8213
JB
2731 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2732 key.type == NL80211_KEYTYPE_PAIRWISE,
2733 mac_addr))
4c476991 2734 return -EINVAL;
41ade00f 2735
fffd0934
JB
2736 wdev_lock(dev->ieee80211_ptr);
2737 err = nl80211_key_allowed(dev->ieee80211_ptr);
2738 if (!err)
e35e4d28
HG
2739 err = rdev_add_key(rdev, dev, key.idx,
2740 key.type == NL80211_KEYTYPE_PAIRWISE,
2741 mac_addr, &key.p);
fffd0934 2742 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2743
41ade00f
JB
2744 return err;
2745}
2746
2747static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2748{
4c476991 2749 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2750 int err;
4c476991 2751 struct net_device *dev = info->user_ptr[1];
41ade00f 2752 u8 *mac_addr = NULL;
b9454e83 2753 struct key_parse key;
41ade00f 2754
b9454e83
JB
2755 err = nl80211_parse_key(info, &key);
2756 if (err)
2757 return err;
41ade00f
JB
2758
2759 if (info->attrs[NL80211_ATTR_MAC])
2760 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2761
e31b8213
JB
2762 if (key.type == -1) {
2763 if (mac_addr)
2764 key.type = NL80211_KEYTYPE_PAIRWISE;
2765 else
2766 key.type = NL80211_KEYTYPE_GROUP;
2767 }
2768
2769 /* for now */
2770 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2771 key.type != NL80211_KEYTYPE_GROUP)
2772 return -EINVAL;
2773
4c476991
JB
2774 if (!rdev->ops->del_key)
2775 return -EOPNOTSUPP;
41ade00f 2776
fffd0934
JB
2777 wdev_lock(dev->ieee80211_ptr);
2778 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2779
2780 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2781 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2782 err = -ENOENT;
2783
fffd0934 2784 if (!err)
e35e4d28
HG
2785 err = rdev_del_key(rdev, dev, key.idx,
2786 key.type == NL80211_KEYTYPE_PAIRWISE,
2787 mac_addr);
41ade00f 2788
3d23e349 2789#ifdef CONFIG_CFG80211_WEXT
08645126 2790 if (!err) {
b9454e83 2791 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2792 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2793 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2794 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2795 }
2796#endif
fffd0934 2797 wdev_unlock(dev->ieee80211_ptr);
08645126 2798
41ade00f
JB
2799 return err;
2800}
2801
77765eaf
VT
2802/* This function returns an error or the number of nested attributes */
2803static int validate_acl_mac_addrs(struct nlattr *nl_attr)
2804{
2805 struct nlattr *attr;
2806 int n_entries = 0, tmp;
2807
2808 nla_for_each_nested(attr, nl_attr, tmp) {
2809 if (nla_len(attr) != ETH_ALEN)
2810 return -EINVAL;
2811
2812 n_entries++;
2813 }
2814
2815 return n_entries;
2816}
2817
2818/*
2819 * This function parses ACL information and allocates memory for ACL data.
2820 * On successful return, the calling function is responsible to free the
2821 * ACL buffer returned by this function.
2822 */
2823static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
2824 struct genl_info *info)
2825{
2826 enum nl80211_acl_policy acl_policy;
2827 struct nlattr *attr;
2828 struct cfg80211_acl_data *acl;
2829 int i = 0, n_entries, tmp;
2830
2831 if (!wiphy->max_acl_mac_addrs)
2832 return ERR_PTR(-EOPNOTSUPP);
2833
2834 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
2835 return ERR_PTR(-EINVAL);
2836
2837 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
2838 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
2839 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
2840 return ERR_PTR(-EINVAL);
2841
2842 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
2843 return ERR_PTR(-EINVAL);
2844
2845 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
2846 if (n_entries < 0)
2847 return ERR_PTR(n_entries);
2848
2849 if (n_entries > wiphy->max_acl_mac_addrs)
2850 return ERR_PTR(-ENOTSUPP);
2851
2852 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
2853 GFP_KERNEL);
2854 if (!acl)
2855 return ERR_PTR(-ENOMEM);
2856
2857 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
2858 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
2859 i++;
2860 }
2861
2862 acl->n_acl_entries = n_entries;
2863 acl->acl_policy = acl_policy;
2864
2865 return acl;
2866}
2867
2868static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
2869{
2870 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2871 struct net_device *dev = info->user_ptr[1];
2872 struct cfg80211_acl_data *acl;
2873 int err;
2874
2875 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2876 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2877 return -EOPNOTSUPP;
2878
2879 if (!dev->ieee80211_ptr->beacon_interval)
2880 return -EINVAL;
2881
2882 acl = parse_acl_data(&rdev->wiphy, info);
2883 if (IS_ERR(acl))
2884 return PTR_ERR(acl);
2885
2886 err = rdev_set_mac_acl(rdev, dev, acl);
2887
2888 kfree(acl);
2889
2890 return err;
2891}
2892
8860020e
JB
2893static int nl80211_parse_beacon(struct genl_info *info,
2894 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2895{
8860020e 2896 bool haveinfo = false;
ed1b6cc7 2897
9946ecfb
JM
2898 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2899 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2900 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2901 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2902 return -EINVAL;
2903
8860020e 2904 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2905
ed1b6cc7 2906 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2907 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2908 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2909 if (!bcn->head_len)
2910 return -EINVAL;
2911 haveinfo = true;
ed1b6cc7
JB
2912 }
2913
2914 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2915 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2916 bcn->tail_len =
ed1b6cc7 2917 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2918 haveinfo = true;
ed1b6cc7
JB
2919 }
2920
4c476991
JB
2921 if (!haveinfo)
2922 return -EINVAL;
3b85875a 2923
9946ecfb 2924 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2925 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2926 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2927 }
2928
2929 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2930 bcn->proberesp_ies =
9946ecfb 2931 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2932 bcn->proberesp_ies_len =
9946ecfb
JM
2933 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2934 }
2935
2936 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2937 bcn->assocresp_ies =
9946ecfb 2938 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2939 bcn->assocresp_ies_len =
9946ecfb
JM
2940 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2941 }
2942
00f740e1 2943 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2944 bcn->probe_resp =
00f740e1 2945 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2946 bcn->probe_resp_len =
00f740e1
AN
2947 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2948 }
2949
8860020e
JB
2950 return 0;
2951}
2952
46c1dd0c
FF
2953static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2954 struct cfg80211_ap_settings *params)
2955{
2956 struct wireless_dev *wdev;
2957 bool ret = false;
2958
89a54e48 2959 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2960 if (wdev->iftype != NL80211_IFTYPE_AP &&
2961 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2962 continue;
2963
683b6d3b 2964 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
2965 continue;
2966
683b6d3b 2967 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
2968 ret = true;
2969 break;
2970 }
2971
46c1dd0c
FF
2972 return ret;
2973}
2974
e39e5b5e
JM
2975static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
2976 enum nl80211_auth_type auth_type,
2977 enum nl80211_commands cmd)
2978{
2979 if (auth_type > NL80211_AUTHTYPE_MAX)
2980 return false;
2981
2982 switch (cmd) {
2983 case NL80211_CMD_AUTHENTICATE:
2984 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
2985 auth_type == NL80211_AUTHTYPE_SAE)
2986 return false;
2987 return true;
2988 case NL80211_CMD_CONNECT:
2989 case NL80211_CMD_START_AP:
2990 /* SAE not supported yet */
2991 if (auth_type == NL80211_AUTHTYPE_SAE)
2992 return false;
2993 return true;
2994 default:
2995 return false;
2996 }
2997}
2998
8860020e
JB
2999static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
3000{
3001 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3002 struct net_device *dev = info->user_ptr[1];
3003 struct wireless_dev *wdev = dev->ieee80211_ptr;
3004 struct cfg80211_ap_settings params;
3005 int err;
04f39047 3006 u8 radar_detect_width = 0;
8860020e
JB
3007
3008 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3009 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3010 return -EOPNOTSUPP;
3011
3012 if (!rdev->ops->start_ap)
3013 return -EOPNOTSUPP;
3014
3015 if (wdev->beacon_interval)
3016 return -EALREADY;
3017
3018 memset(&params, 0, sizeof(params));
3019
3020 /* these are required for START_AP */
3021 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
3022 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
3023 !info->attrs[NL80211_ATTR_BEACON_HEAD])
3024 return -EINVAL;
3025
3026 err = nl80211_parse_beacon(info, &params.beacon);
3027 if (err)
3028 return err;
3029
3030 params.beacon_interval =
3031 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3032 params.dtim_period =
3033 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
3034
3035 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
3036 if (err)
3037 return err;
3038
3039 /*
3040 * In theory, some of these attributes should be required here
3041 * but since they were not used when the command was originally
3042 * added, keep them optional for old user space programs to let
3043 * them continue to work with drivers that do not need the
3044 * additional information -- drivers must check!
3045 */
3046 if (info->attrs[NL80211_ATTR_SSID]) {
3047 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3048 params.ssid_len =
3049 nla_len(info->attrs[NL80211_ATTR_SSID]);
3050 if (params.ssid_len == 0 ||
3051 params.ssid_len > IEEE80211_MAX_SSID_LEN)
3052 return -EINVAL;
3053 }
3054
3055 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
3056 params.hidden_ssid = nla_get_u32(
3057 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
3058 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
3059 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
3060 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
3061 return -EINVAL;
3062 }
3063
3064 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3065
3066 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3067 params.auth_type = nla_get_u32(
3068 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
3069 if (!nl80211_valid_auth_type(rdev, params.auth_type,
3070 NL80211_CMD_START_AP))
8860020e
JB
3071 return -EINVAL;
3072 } else
3073 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3074
3075 err = nl80211_crypto_settings(rdev, info, &params.crypto,
3076 NL80211_MAX_NR_CIPHER_SUITES);
3077 if (err)
3078 return err;
3079
1b658f11
VT
3080 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
3081 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
3082 return -EOPNOTSUPP;
3083 params.inactivity_timeout = nla_get_u16(
3084 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
3085 }
3086
53cabad7
JB
3087 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3088 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3089 return -EINVAL;
3090 params.p2p_ctwindow =
3091 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3092 if (params.p2p_ctwindow > 127)
3093 return -EINVAL;
3094 if (params.p2p_ctwindow != 0 &&
3095 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3096 return -EINVAL;
3097 }
3098
3099 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3100 u8 tmp;
3101
3102 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3103 return -EINVAL;
3104 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3105 if (tmp > 1)
3106 return -EINVAL;
3107 params.p2p_opp_ps = tmp;
3108 if (params.p2p_opp_ps != 0 &&
3109 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3110 return -EINVAL;
3111 }
3112
aa430da4 3113 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
3114 err = nl80211_parse_chandef(rdev, info, &params.chandef);
3115 if (err)
3116 return err;
3117 } else if (wdev->preset_chandef.chan) {
3118 params.chandef = wdev->preset_chandef;
46c1dd0c 3119 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
3120 return -EINVAL;
3121
683b6d3b 3122 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
3123 return -EINVAL;
3124
04f39047
SW
3125 err = cfg80211_chandef_dfs_required(wdev->wiphy, &params.chandef);
3126 if (err < 0)
3127 return err;
3128 if (err) {
3129 radar_detect_width = BIT(params.chandef.width);
3130 params.radar_required = true;
3131 }
3132
04f39047
SW
3133 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
3134 params.chandef.chan,
3135 CHAN_MODE_SHARED,
3136 radar_detect_width);
e4e32459
MK
3137 if (err)
3138 return err;
3139
77765eaf
VT
3140 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
3141 params.acl = parse_acl_data(&rdev->wiphy, info);
3142 if (IS_ERR(params.acl))
3143 return PTR_ERR(params.acl);
3144 }
3145
e35e4d28 3146 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 3147 if (!err) {
683b6d3b 3148 wdev->preset_chandef = params.chandef;
8860020e 3149 wdev->beacon_interval = params.beacon_interval;
683b6d3b 3150 wdev->channel = params.chandef.chan;
06e191e2
AQ
3151 wdev->ssid_len = params.ssid_len;
3152 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 3153 }
77765eaf
VT
3154
3155 kfree(params.acl);
3156
56d1893d 3157 return err;
ed1b6cc7
JB
3158}
3159
8860020e
JB
3160static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
3161{
3162 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3163 struct net_device *dev = info->user_ptr[1];
3164 struct wireless_dev *wdev = dev->ieee80211_ptr;
3165 struct cfg80211_beacon_data params;
3166 int err;
3167
3168 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3169 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3170 return -EOPNOTSUPP;
3171
3172 if (!rdev->ops->change_beacon)
3173 return -EOPNOTSUPP;
3174
3175 if (!wdev->beacon_interval)
3176 return -EINVAL;
3177
3178 err = nl80211_parse_beacon(info, &params);
3179 if (err)
3180 return err;
3181
e35e4d28 3182 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
3183}
3184
3185static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 3186{
4c476991
JB
3187 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3188 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 3189
60771780 3190 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
3191}
3192
5727ef1b
JB
3193static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
3194 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
3195 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
3196 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 3197 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 3198 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 3199 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
3200};
3201
eccb8e8f 3202static int parse_station_flags(struct genl_info *info,
bdd3ae3d 3203 enum nl80211_iftype iftype,
eccb8e8f 3204 struct station_parameters *params)
5727ef1b
JB
3205{
3206 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 3207 struct nlattr *nla;
5727ef1b
JB
3208 int flag;
3209
eccb8e8f
JB
3210 /*
3211 * Try parsing the new attribute first so userspace
3212 * can specify both for older kernels.
3213 */
3214 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
3215 if (nla) {
3216 struct nl80211_sta_flag_update *sta_flags;
3217
3218 sta_flags = nla_data(nla);
3219 params->sta_flags_mask = sta_flags->mask;
3220 params->sta_flags_set = sta_flags->set;
77ee7c89 3221 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
3222 if ((params->sta_flags_mask |
3223 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
3224 return -EINVAL;
3225 return 0;
3226 }
3227
3228 /* if present, parse the old attribute */
5727ef1b 3229
eccb8e8f 3230 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
3231 if (!nla)
3232 return 0;
3233
3234 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
3235 nla, sta_flags_policy))
3236 return -EINVAL;
3237
bdd3ae3d
JB
3238 /*
3239 * Only allow certain flags for interface types so that
3240 * other attributes are silently ignored. Remember that
3241 * this is backward compatibility code with old userspace
3242 * and shouldn't be hit in other cases anyway.
3243 */
3244 switch (iftype) {
3245 case NL80211_IFTYPE_AP:
3246 case NL80211_IFTYPE_AP_VLAN:
3247 case NL80211_IFTYPE_P2P_GO:
3248 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3249 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3250 BIT(NL80211_STA_FLAG_WME) |
3251 BIT(NL80211_STA_FLAG_MFP);
3252 break;
3253 case NL80211_IFTYPE_P2P_CLIENT:
3254 case NL80211_IFTYPE_STATION:
3255 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3256 BIT(NL80211_STA_FLAG_TDLS_PEER);
3257 break;
3258 case NL80211_IFTYPE_MESH_POINT:
3259 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3260 BIT(NL80211_STA_FLAG_MFP) |
3261 BIT(NL80211_STA_FLAG_AUTHORIZED);
3262 default:
3263 return -EINVAL;
3264 }
5727ef1b 3265
3383b5a6
JB
3266 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
3267 if (flags[flag]) {
eccb8e8f 3268 params->sta_flags_set |= (1<<flag);
5727ef1b 3269
3383b5a6
JB
3270 /* no longer support new API additions in old API */
3271 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
3272 return -EINVAL;
3273 }
3274 }
3275
5727ef1b
JB
3276 return 0;
3277}
3278
c8dcfd8a
FF
3279static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
3280 int attr)
3281{
3282 struct nlattr *rate;
8eb41c8d
VK
3283 u32 bitrate;
3284 u16 bitrate_compat;
c8dcfd8a
FF
3285
3286 rate = nla_nest_start(msg, attr);
3287 if (!rate)
db9c64cf 3288 return false;
c8dcfd8a
FF
3289
3290 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
3291 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
3292 /* report 16-bit bitrate only if we can */
3293 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
3294 if (bitrate > 0 &&
3295 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
3296 return false;
3297 if (bitrate_compat > 0 &&
3298 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
3299 return false;
3300
3301 if (info->flags & RATE_INFO_FLAGS_MCS) {
3302 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
3303 return false;
3304 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3305 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3306 return false;
3307 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3308 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3309 return false;
3310 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3311 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3312 return false;
3313 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3314 return false;
3315 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3316 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3317 return false;
3318 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
3319 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
3320 return false;
3321 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
3322 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
3323 return false;
3324 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
3325 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
3326 return false;
3327 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3328 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3329 return false;
3330 }
c8dcfd8a
FF
3331
3332 nla_nest_end(msg, rate);
3333 return true;
c8dcfd8a
FF
3334}
3335
119363c7
FF
3336static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
3337 int id)
3338{
3339 void *attr;
3340 int i = 0;
3341
3342 if (!mask)
3343 return true;
3344
3345 attr = nla_nest_start(msg, id);
3346 if (!attr)
3347 return false;
3348
3349 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
3350 if (!(mask & BIT(i)))
3351 continue;
3352
3353 if (nla_put_u8(msg, i, signal[i]))
3354 return false;
3355 }
3356
3357 nla_nest_end(msg, attr);
3358
3359 return true;
3360}
3361
15e47304 3362static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
3363 int flags,
3364 struct cfg80211_registered_device *rdev,
3365 struct net_device *dev,
98b62183 3366 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3367{
3368 void *hdr;
f4263c98 3369 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3370
15e47304 3371 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
3372 if (!hdr)
3373 return -1;
3374
9360ffd1
DM
3375 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3376 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3377 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3378 goto nla_put_failure;
f5ea9120 3379
2ec600d6
LCC
3380 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3381 if (!sinfoattr)
fd5b74dc 3382 goto nla_put_failure;
9360ffd1
DM
3383 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
3384 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
3385 sinfo->connected_time))
3386 goto nla_put_failure;
3387 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
3388 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
3389 sinfo->inactive_time))
3390 goto nla_put_failure;
42745e03
VK
3391 if ((sinfo->filled & (STATION_INFO_RX_BYTES |
3392 STATION_INFO_RX_BYTES64)) &&
9360ffd1 3393 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 3394 (u32)sinfo->rx_bytes))
9360ffd1 3395 goto nla_put_failure;
42745e03 3396 if ((sinfo->filled & (STATION_INFO_TX_BYTES |
4325d724 3397 STATION_INFO_TX_BYTES64)) &&
9360ffd1 3398 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
3399 (u32)sinfo->tx_bytes))
3400 goto nla_put_failure;
3401 if ((sinfo->filled & STATION_INFO_RX_BYTES64) &&
3402 nla_put_u64(msg, NL80211_STA_INFO_RX_BYTES64,
3403 sinfo->rx_bytes))
3404 goto nla_put_failure;
3405 if ((sinfo->filled & STATION_INFO_TX_BYTES64) &&
3406 nla_put_u64(msg, NL80211_STA_INFO_TX_BYTES64,
9360ffd1
DM
3407 sinfo->tx_bytes))
3408 goto nla_put_failure;
3409 if ((sinfo->filled & STATION_INFO_LLID) &&
3410 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
3411 goto nla_put_failure;
3412 if ((sinfo->filled & STATION_INFO_PLID) &&
3413 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
3414 goto nla_put_failure;
3415 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
3416 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
3417 sinfo->plink_state))
3418 goto nla_put_failure;
66266b3a
JL
3419 switch (rdev->wiphy.signal_type) {
3420 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
3421 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
3422 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
3423 sinfo->signal))
3424 goto nla_put_failure;
3425 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
3426 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
3427 sinfo->signal_avg))
3428 goto nla_put_failure;
66266b3a
JL
3429 break;
3430 default:
3431 break;
3432 }
119363c7
FF
3433 if (sinfo->filled & STATION_INFO_CHAIN_SIGNAL) {
3434 if (!nl80211_put_signal(msg, sinfo->chains,
3435 sinfo->chain_signal,
3436 NL80211_STA_INFO_CHAIN_SIGNAL))
3437 goto nla_put_failure;
3438 }
3439 if (sinfo->filled & STATION_INFO_CHAIN_SIGNAL_AVG) {
3440 if (!nl80211_put_signal(msg, sinfo->chains,
3441 sinfo->chain_signal_avg,
3442 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
3443 goto nla_put_failure;
3444 }
420e7fab 3445 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3446 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3447 NL80211_STA_INFO_TX_BITRATE))
3448 goto nla_put_failure;
3449 }
3450 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3451 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3452 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3453 goto nla_put_failure;
420e7fab 3454 }
9360ffd1
DM
3455 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3456 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3457 sinfo->rx_packets))
3458 goto nla_put_failure;
3459 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3460 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3461 sinfo->tx_packets))
3462 goto nla_put_failure;
3463 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3464 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3465 sinfo->tx_retries))
3466 goto nla_put_failure;
3467 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3468 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3469 sinfo->tx_failed))
3470 goto nla_put_failure;
3471 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3472 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3473 sinfo->beacon_loss_count))
3474 goto nla_put_failure;
3b1c5a53
MP
3475 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3476 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3477 sinfo->local_pm))
3478 goto nla_put_failure;
3479 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3480 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3481 sinfo->peer_pm))
3482 goto nla_put_failure;
3483 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3484 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3485 sinfo->nonpeer_pm))
3486 goto nla_put_failure;
f4263c98
PS
3487 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3488 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3489 if (!bss_param)
3490 goto nla_put_failure;
3491
9360ffd1
DM
3492 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3493 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3494 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3495 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3496 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3497 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3498 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3499 sinfo->bss_param.dtim_period) ||
3500 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3501 sinfo->bss_param.beacon_interval))
3502 goto nla_put_failure;
f4263c98
PS
3503
3504 nla_nest_end(msg, bss_param);
3505 }
9360ffd1
DM
3506 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3507 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3508 sizeof(struct nl80211_sta_flag_update),
3509 &sinfo->sta_flags))
3510 goto nla_put_failure;
7eab0f64
JL
3511 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3512 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3513 sinfo->t_offset))
3514 goto nla_put_failure;
2ec600d6 3515 nla_nest_end(msg, sinfoattr);
fd5b74dc 3516
9360ffd1
DM
3517 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3518 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3519 sinfo->assoc_req_ies))
3520 goto nla_put_failure;
50d3dfb7 3521
fd5b74dc
JB
3522 return genlmsg_end(msg, hdr);
3523
3524 nla_put_failure:
bc3ed28c
TG
3525 genlmsg_cancel(msg, hdr);
3526 return -EMSGSIZE;
fd5b74dc
JB
3527}
3528
2ec600d6 3529static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3530 struct netlink_callback *cb)
2ec600d6 3531{
2ec600d6
LCC
3532 struct station_info sinfo;
3533 struct cfg80211_registered_device *dev;
97990a06 3534 struct wireless_dev *wdev;
2ec600d6 3535 u8 mac_addr[ETH_ALEN];
97990a06 3536 int sta_idx = cb->args[2];
2ec600d6 3537 int err;
2ec600d6 3538
97990a06 3539 err = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
3540 if (err)
3541 return err;
bba95fef 3542
97990a06
JB
3543 if (!wdev->netdev) {
3544 err = -EINVAL;
3545 goto out_err;
3546 }
3547
bba95fef 3548 if (!dev->ops->dump_station) {
eec60b03 3549 err = -EOPNOTSUPP;
bba95fef
JB
3550 goto out_err;
3551 }
3552
bba95fef 3553 while (1) {
f612cedf 3554 memset(&sinfo, 0, sizeof(sinfo));
97990a06 3555 err = rdev_dump_station(dev, wdev->netdev, sta_idx,
e35e4d28 3556 mac_addr, &sinfo);
bba95fef
JB
3557 if (err == -ENOENT)
3558 break;
3559 if (err)
3b85875a 3560 goto out_err;
bba95fef
JB
3561
3562 if (nl80211_send_station(skb,
15e47304 3563 NETLINK_CB(cb->skb).portid,
bba95fef 3564 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 3565 dev, wdev->netdev, mac_addr,
bba95fef
JB
3566 &sinfo) < 0)
3567 goto out;
3568
3569 sta_idx++;
3570 }
3571
3572
3573 out:
97990a06 3574 cb->args[2] = sta_idx;
bba95fef 3575 err = skb->len;
bba95fef 3576 out_err:
97990a06 3577 nl80211_finish_wdev_dump(dev);
bba95fef
JB
3578
3579 return err;
2ec600d6 3580}
fd5b74dc 3581
5727ef1b
JB
3582static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3583{
4c476991
JB
3584 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3585 struct net_device *dev = info->user_ptr[1];
2ec600d6 3586 struct station_info sinfo;
fd5b74dc
JB
3587 struct sk_buff *msg;
3588 u8 *mac_addr = NULL;
4c476991 3589 int err;
fd5b74dc 3590
2ec600d6 3591 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3592
3593 if (!info->attrs[NL80211_ATTR_MAC])
3594 return -EINVAL;
3595
3596 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3597
4c476991
JB
3598 if (!rdev->ops->get_station)
3599 return -EOPNOTSUPP;
3b85875a 3600
e35e4d28 3601 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3602 if (err)
4c476991 3603 return err;
2ec600d6 3604
fd2120ca 3605 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3606 if (!msg)
4c476991 3607 return -ENOMEM;
fd5b74dc 3608
15e47304 3609 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3610 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3611 nlmsg_free(msg);
3612 return -ENOBUFS;
3613 }
3b85875a 3614
4c476991 3615 return genlmsg_reply(msg, info);
5727ef1b
JB
3616}
3617
77ee7c89
JB
3618int cfg80211_check_station_change(struct wiphy *wiphy,
3619 struct station_parameters *params,
3620 enum cfg80211_station_type statype)
3621{
3622 if (params->listen_interval != -1)
3623 return -EINVAL;
3624 if (params->aid)
3625 return -EINVAL;
3626
3627 /* When you run into this, adjust the code below for the new flag */
3628 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
3629
3630 switch (statype) {
eef941e6
TP
3631 case CFG80211_STA_MESH_PEER_KERNEL:
3632 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3633 /*
3634 * No ignoring the TDLS flag here -- the userspace mesh
3635 * code doesn't have the bug of including TDLS in the
3636 * mask everywhere.
3637 */
3638 if (params->sta_flags_mask &
3639 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3640 BIT(NL80211_STA_FLAG_MFP) |
3641 BIT(NL80211_STA_FLAG_AUTHORIZED)))
3642 return -EINVAL;
3643 break;
3644 case CFG80211_STA_TDLS_PEER_SETUP:
3645 case CFG80211_STA_TDLS_PEER_ACTIVE:
3646 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3647 return -EINVAL;
3648 /* ignore since it can't change */
3649 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3650 break;
3651 default:
3652 /* disallow mesh-specific things */
3653 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3654 return -EINVAL;
3655 if (params->local_pm)
3656 return -EINVAL;
3657 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3658 return -EINVAL;
3659 }
3660
3661 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
3662 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
3663 /* TDLS can't be set, ... */
3664 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3665 return -EINVAL;
3666 /*
3667 * ... but don't bother the driver with it. This works around
3668 * a hostapd/wpa_supplicant issue -- it always includes the
3669 * TLDS_PEER flag in the mask even for AP mode.
3670 */
3671 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3672 }
3673
3674 if (statype != CFG80211_STA_TDLS_PEER_SETUP) {
3675 /* reject other things that can't change */
3676 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
3677 return -EINVAL;
3678 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
3679 return -EINVAL;
3680 if (params->supported_rates)
3681 return -EINVAL;
3682 if (params->ext_capab || params->ht_capa || params->vht_capa)
3683 return -EINVAL;
3684 }
3685
3686 if (statype != CFG80211_STA_AP_CLIENT) {
3687 if (params->vlan)
3688 return -EINVAL;
3689 }
3690
3691 switch (statype) {
3692 case CFG80211_STA_AP_MLME_CLIENT:
3693 /* Use this only for authorizing/unauthorizing a station */
3694 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
3695 return -EOPNOTSUPP;
3696 break;
3697 case CFG80211_STA_AP_CLIENT:
3698 /* accept only the listed bits */
3699 if (params->sta_flags_mask &
3700 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3701 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3702 BIT(NL80211_STA_FLAG_ASSOCIATED) |
3703 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3704 BIT(NL80211_STA_FLAG_WME) |
3705 BIT(NL80211_STA_FLAG_MFP)))
3706 return -EINVAL;
3707
3708 /* but authenticated/associated only if driver handles it */
3709 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3710 params->sta_flags_mask &
3711 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3712 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3713 return -EINVAL;
3714 break;
3715 case CFG80211_STA_IBSS:
3716 case CFG80211_STA_AP_STA:
3717 /* reject any changes other than AUTHORIZED */
3718 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3719 return -EINVAL;
3720 break;
3721 case CFG80211_STA_TDLS_PEER_SETUP:
3722 /* reject any changes other than AUTHORIZED or WME */
3723 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3724 BIT(NL80211_STA_FLAG_WME)))
3725 return -EINVAL;
3726 /* force (at least) rates when authorizing */
3727 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
3728 !params->supported_rates)
3729 return -EINVAL;
3730 break;
3731 case CFG80211_STA_TDLS_PEER_ACTIVE:
3732 /* reject any changes */
3733 return -EINVAL;
eef941e6 3734 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
3735 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3736 return -EINVAL;
3737 break;
eef941e6 3738 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3739 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3740 return -EINVAL;
3741 break;
3742 }
3743
3744 return 0;
3745}
3746EXPORT_SYMBOL(cfg80211_check_station_change);
3747
5727ef1b 3748/*
c258d2de 3749 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3750 */
80b99899
JB
3751static struct net_device *get_vlan(struct genl_info *info,
3752 struct cfg80211_registered_device *rdev)
5727ef1b 3753{
463d0183 3754 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3755 struct net_device *v;
3756 int ret;
3757
3758 if (!vlanattr)
3759 return NULL;
3760
3761 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3762 if (!v)
3763 return ERR_PTR(-ENODEV);
3764
3765 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3766 ret = -EINVAL;
3767 goto error;
5727ef1b 3768 }
80b99899 3769
77ee7c89
JB
3770 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
3771 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3772 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
3773 ret = -EINVAL;
3774 goto error;
3775 }
3776
80b99899
JB
3777 if (!netif_running(v)) {
3778 ret = -ENETDOWN;
3779 goto error;
3780 }
3781
3782 return v;
3783 error:
3784 dev_put(v);
3785 return ERR_PTR(ret);
5727ef1b
JB
3786}
3787
df881293
JM
3788static struct nla_policy
3789nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3790 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3791 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3792};
3793
ff276691
JB
3794static int nl80211_parse_sta_wme(struct genl_info *info,
3795 struct station_parameters *params)
df881293 3796{
df881293
JM
3797 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3798 struct nlattr *nla;
3799 int err;
3800
df881293
JM
3801 /* parse WME attributes if present */
3802 if (!info->attrs[NL80211_ATTR_STA_WME])
3803 return 0;
3804
3805 nla = info->attrs[NL80211_ATTR_STA_WME];
3806 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3807 nl80211_sta_wme_policy);
3808 if (err)
3809 return err;
3810
3811 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3812 params->uapsd_queues = nla_get_u8(
3813 tb[NL80211_STA_WME_UAPSD_QUEUES]);
3814 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3815 return -EINVAL;
3816
3817 if (tb[NL80211_STA_WME_MAX_SP])
3818 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
3819
3820 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3821 return -EINVAL;
3822
3823 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3824
3825 return 0;
3826}
3827
ff276691
JB
3828static int nl80211_set_station_tdls(struct genl_info *info,
3829 struct station_parameters *params)
3830{
3831 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
3832 if (info->attrs[NL80211_ATTR_PEER_AID])
3833 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
3834 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3835 params->ht_capa =
3836 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
3837 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3838 params->vht_capa =
3839 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3840
3841 return nl80211_parse_sta_wme(info, params);
3842}
3843
5727ef1b
JB
3844static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3845{
4c476991 3846 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3847 struct net_device *dev = info->user_ptr[1];
5727ef1b 3848 struct station_parameters params;
77ee7c89
JB
3849 u8 *mac_addr;
3850 int err;
5727ef1b
JB
3851
3852 memset(&params, 0, sizeof(params));
3853
3854 params.listen_interval = -1;
3855
77ee7c89
JB
3856 if (!rdev->ops->change_station)
3857 return -EOPNOTSUPP;
3858
5727ef1b
JB
3859 if (info->attrs[NL80211_ATTR_STA_AID])
3860 return -EINVAL;
3861
3862 if (!info->attrs[NL80211_ATTR_MAC])
3863 return -EINVAL;
3864
3865 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3866
3867 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3868 params.supported_rates =
3869 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3870 params.supported_rates_len =
3871 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3872 }
3873
9d62a986
JM
3874 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
3875 params.capability =
3876 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
3877 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
3878 }
3879
3880 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
3881 params.ext_capab =
3882 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
3883 params.ext_capab_len =
3884 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
3885 }
3886
df881293 3887 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
ba23d206 3888 return -EINVAL;
36aedc90 3889
bdd3ae3d 3890 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3891 return -EINVAL;
3892
f8bacc21 3893 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
2ec600d6 3894 params.plink_action =
f8bacc21
JB
3895 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3896 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
3897 return -EINVAL;
3898 }
2ec600d6 3899
f8bacc21 3900 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 3901 params.plink_state =
f8bacc21
JB
3902 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3903 if (params.plink_state >= NUM_NL80211_PLINK_STATES)
3904 return -EINVAL;
3905 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
3906 }
9c3990aa 3907
3b1c5a53
MP
3908 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
3909 enum nl80211_mesh_power_mode pm = nla_get_u32(
3910 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
3911
3912 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
3913 pm > NL80211_MESH_POWER_MAX)
3914 return -EINVAL;
3915
3916 params.local_pm = pm;
3917 }
3918
77ee7c89
JB
3919 /* Include parameters for TDLS peer (will check later) */
3920 err = nl80211_set_station_tdls(info, &params);
3921 if (err)
3922 return err;
3923
3924 params.vlan = get_vlan(info, rdev);
3925 if (IS_ERR(params.vlan))
3926 return PTR_ERR(params.vlan);
3927
a97f4424
JB
3928 switch (dev->ieee80211_ptr->iftype) {
3929 case NL80211_IFTYPE_AP:
3930 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3931 case NL80211_IFTYPE_P2P_GO:
074ac8df 3932 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3933 case NL80211_IFTYPE_STATION:
267335d6 3934 case NL80211_IFTYPE_ADHOC:
a97f4424 3935 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
3936 break;
3937 default:
77ee7c89
JB
3938 err = -EOPNOTSUPP;
3939 goto out_put_vlan;
034d655e
JB
3940 }
3941
77ee7c89 3942 /* driver will call cfg80211_check_station_change() */
e35e4d28 3943 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 3944
77ee7c89 3945 out_put_vlan:
5727ef1b
JB
3946 if (params.vlan)
3947 dev_put(params.vlan);
3b85875a 3948
5727ef1b
JB
3949 return err;
3950}
3951
3952static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3953{
4c476991 3954 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3955 int err;
4c476991 3956 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3957 struct station_parameters params;
3958 u8 *mac_addr = NULL;
3959
3960 memset(&params, 0, sizeof(params));
3961
984c311b
JB
3962 if (!rdev->ops->add_station)
3963 return -EOPNOTSUPP;
3964
5727ef1b
JB
3965 if (!info->attrs[NL80211_ATTR_MAC])
3966 return -EINVAL;
3967
5727ef1b
JB
3968 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3969 return -EINVAL;
3970
3971 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3972 return -EINVAL;
3973
5e4b6f56
JM
3974 if (!info->attrs[NL80211_ATTR_STA_AID] &&
3975 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
3976 return -EINVAL;
3977
5727ef1b
JB
3978 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3979 params.supported_rates =
3980 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3981 params.supported_rates_len =
3982 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3983 params.listen_interval =
3984 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3985
3d124ea2 3986 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 3987 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
3988 else
3989 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
0e956c13
TLSC
3990 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3991 return -EINVAL;
51b50fbe 3992
9d62a986
JM
3993 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
3994 params.capability =
3995 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
3996 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
3997 }
3998
3999 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4000 params.ext_capab =
4001 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4002 params.ext_capab_len =
4003 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4004 }
4005
36aedc90
JM
4006 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4007 params.ht_capa =
4008 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 4009
f461be3e
MP
4010 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4011 params.vht_capa =
4012 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4013
f8bacc21 4014 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
96b78dff 4015 params.plink_action =
f8bacc21
JB
4016 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4017 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4018 return -EINVAL;
4019 }
96b78dff 4020
ff276691
JB
4021 err = nl80211_parse_sta_wme(info, &params);
4022 if (err)
4023 return err;
bdd90d5e 4024
bdd3ae3d 4025 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4026 return -EINVAL;
4027
77ee7c89
JB
4028 /* When you run into this, adjust the code below for the new flag */
4029 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
4030
bdd90d5e
JB
4031 switch (dev->ieee80211_ptr->iftype) {
4032 case NL80211_IFTYPE_AP:
4033 case NL80211_IFTYPE_AP_VLAN:
4034 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
4035 /* ignore WME attributes if iface/sta is not capable */
4036 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
4037 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
4038 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 4039
bdd90d5e 4040 /* TDLS peers cannot be added */
3d124ea2
JM
4041 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4042 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 4043 return -EINVAL;
bdd90d5e
JB
4044 /* but don't bother the driver with it */
4045 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 4046
d582cffb
JB
4047 /* allow authenticated/associated only if driver handles it */
4048 if (!(rdev->wiphy.features &
4049 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4050 params.sta_flags_mask &
4051 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4052 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4053 return -EINVAL;
4054
bdd90d5e
JB
4055 /* must be last in here for error handling */
4056 params.vlan = get_vlan(info, rdev);
4057 if (IS_ERR(params.vlan))
4058 return PTR_ERR(params.vlan);
4059 break;
4060 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
4061 /* ignore uAPSD data */
4062 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4063
d582cffb
JB
4064 /* associated is disallowed */
4065 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
4066 return -EINVAL;
bdd90d5e 4067 /* TDLS peers cannot be added */
3d124ea2
JM
4068 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4069 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
4070 return -EINVAL;
4071 break;
4072 case NL80211_IFTYPE_STATION:
93d08f0b 4073 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
4074 /* ignore uAPSD data */
4075 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4076
77ee7c89
JB
4077 /* these are disallowed */
4078 if (params.sta_flags_mask &
4079 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
4080 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 4081 return -EINVAL;
bdd90d5e
JB
4082 /* Only TDLS peers can be added */
4083 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
4084 return -EINVAL;
4085 /* Can only add if TDLS ... */
4086 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
4087 return -EOPNOTSUPP;
4088 /* ... with external setup is supported */
4089 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
4090 return -EOPNOTSUPP;
77ee7c89
JB
4091 /*
4092 * Older wpa_supplicant versions always mark the TDLS peer
4093 * as authorized, but it shouldn't yet be.
4094 */
4095 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
4096 break;
4097 default:
4098 return -EOPNOTSUPP;
c75786c9
EP
4099 }
4100
bdd90d5e 4101 /* be aware of params.vlan when changing code here */
5727ef1b 4102
e35e4d28 4103 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 4104
5727ef1b
JB
4105 if (params.vlan)
4106 dev_put(params.vlan);
5727ef1b
JB
4107 return err;
4108}
4109
4110static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
4111{
4c476991
JB
4112 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4113 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4114 u8 *mac_addr = NULL;
4115
4116 if (info->attrs[NL80211_ATTR_MAC])
4117 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4118
e80cf853 4119 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 4120 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 4121 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4122 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4123 return -EINVAL;
5727ef1b 4124
4c476991
JB
4125 if (!rdev->ops->del_station)
4126 return -EOPNOTSUPP;
3b85875a 4127
e35e4d28 4128 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
4129}
4130
15e47304 4131static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
4132 int flags, struct net_device *dev,
4133 u8 *dst, u8 *next_hop,
4134 struct mpath_info *pinfo)
4135{
4136 void *hdr;
4137 struct nlattr *pinfoattr;
4138
15e47304 4139 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
4140 if (!hdr)
4141 return -1;
4142
9360ffd1
DM
4143 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4144 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
4145 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
4146 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
4147 goto nla_put_failure;
f5ea9120 4148
2ec600d6
LCC
4149 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
4150 if (!pinfoattr)
4151 goto nla_put_failure;
9360ffd1
DM
4152 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
4153 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
4154 pinfo->frame_qlen))
4155 goto nla_put_failure;
4156 if (((pinfo->filled & MPATH_INFO_SN) &&
4157 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
4158 ((pinfo->filled & MPATH_INFO_METRIC) &&
4159 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
4160 pinfo->metric)) ||
4161 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
4162 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
4163 pinfo->exptime)) ||
4164 ((pinfo->filled & MPATH_INFO_FLAGS) &&
4165 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
4166 pinfo->flags)) ||
4167 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
4168 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
4169 pinfo->discovery_timeout)) ||
4170 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
4171 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
4172 pinfo->discovery_retries)))
4173 goto nla_put_failure;
2ec600d6
LCC
4174
4175 nla_nest_end(msg, pinfoattr);
4176
4177 return genlmsg_end(msg, hdr);
4178
4179 nla_put_failure:
bc3ed28c
TG
4180 genlmsg_cancel(msg, hdr);
4181 return -EMSGSIZE;
2ec600d6
LCC
4182}
4183
4184static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 4185 struct netlink_callback *cb)
2ec600d6 4186{
2ec600d6
LCC
4187 struct mpath_info pinfo;
4188 struct cfg80211_registered_device *dev;
97990a06 4189 struct wireless_dev *wdev;
2ec600d6
LCC
4190 u8 dst[ETH_ALEN];
4191 u8 next_hop[ETH_ALEN];
97990a06 4192 int path_idx = cb->args[2];
2ec600d6 4193 int err;
2ec600d6 4194
97990a06 4195 err = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
4196 if (err)
4197 return err;
bba95fef
JB
4198
4199 if (!dev->ops->dump_mpath) {
eec60b03 4200 err = -EOPNOTSUPP;
bba95fef
JB
4201 goto out_err;
4202 }
4203
97990a06 4204 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 4205 err = -EOPNOTSUPP;
0448b5fc 4206 goto out_err;
eec60b03
JM
4207 }
4208
bba95fef 4209 while (1) {
97990a06
JB
4210 err = rdev_dump_mpath(dev, wdev->netdev, path_idx, dst,
4211 next_hop, &pinfo);
bba95fef 4212 if (err == -ENOENT)
2ec600d6 4213 break;
bba95fef 4214 if (err)
3b85875a 4215 goto out_err;
2ec600d6 4216
15e47304 4217 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 4218 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 4219 wdev->netdev, dst, next_hop,
bba95fef
JB
4220 &pinfo) < 0)
4221 goto out;
2ec600d6 4222
bba95fef 4223 path_idx++;
2ec600d6 4224 }
2ec600d6 4225
2ec600d6 4226
bba95fef 4227 out:
97990a06 4228 cb->args[2] = path_idx;
bba95fef 4229 err = skb->len;
bba95fef 4230 out_err:
97990a06 4231 nl80211_finish_wdev_dump(dev);
bba95fef 4232 return err;
2ec600d6
LCC
4233}
4234
4235static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
4236{
4c476991 4237 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 4238 int err;
4c476991 4239 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4240 struct mpath_info pinfo;
4241 struct sk_buff *msg;
4242 u8 *dst = NULL;
4243 u8 next_hop[ETH_ALEN];
4244
4245 memset(&pinfo, 0, sizeof(pinfo));
4246
4247 if (!info->attrs[NL80211_ATTR_MAC])
4248 return -EINVAL;
4249
4250 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4251
4c476991
JB
4252 if (!rdev->ops->get_mpath)
4253 return -EOPNOTSUPP;
2ec600d6 4254
4c476991
JB
4255 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4256 return -EOPNOTSUPP;
eec60b03 4257
e35e4d28 4258 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 4259 if (err)
4c476991 4260 return err;
2ec600d6 4261
fd2120ca 4262 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 4263 if (!msg)
4c476991 4264 return -ENOMEM;
2ec600d6 4265
15e47304 4266 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
4267 dev, dst, next_hop, &pinfo) < 0) {
4268 nlmsg_free(msg);
4269 return -ENOBUFS;
4270 }
3b85875a 4271
4c476991 4272 return genlmsg_reply(msg, info);
2ec600d6
LCC
4273}
4274
4275static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
4276{
4c476991
JB
4277 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4278 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4279 u8 *dst = NULL;
4280 u8 *next_hop = NULL;
4281
4282 if (!info->attrs[NL80211_ATTR_MAC])
4283 return -EINVAL;
4284
4285 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4286 return -EINVAL;
4287
4288 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4289 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4290
4c476991
JB
4291 if (!rdev->ops->change_mpath)
4292 return -EOPNOTSUPP;
35a8efe1 4293
4c476991
JB
4294 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4295 return -EOPNOTSUPP;
2ec600d6 4296
e35e4d28 4297 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 4298}
4c476991 4299
2ec600d6
LCC
4300static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
4301{
4c476991
JB
4302 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4303 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4304 u8 *dst = NULL;
4305 u8 *next_hop = NULL;
4306
4307 if (!info->attrs[NL80211_ATTR_MAC])
4308 return -EINVAL;
4309
4310 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4311 return -EINVAL;
4312
4313 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4314 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4315
4c476991
JB
4316 if (!rdev->ops->add_mpath)
4317 return -EOPNOTSUPP;
35a8efe1 4318
4c476991
JB
4319 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4320 return -EOPNOTSUPP;
2ec600d6 4321
e35e4d28 4322 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
4323}
4324
4325static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
4326{
4c476991
JB
4327 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4328 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4329 u8 *dst = NULL;
4330
4331 if (info->attrs[NL80211_ATTR_MAC])
4332 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4333
4c476991
JB
4334 if (!rdev->ops->del_mpath)
4335 return -EOPNOTSUPP;
3b85875a 4336
e35e4d28 4337 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
4338}
4339
9f1ba906
JM
4340static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
4341{
4c476991
JB
4342 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4343 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
4344 struct bss_parameters params;
4345
4346 memset(&params, 0, sizeof(params));
4347 /* default to not changing parameters */
4348 params.use_cts_prot = -1;
4349 params.use_short_preamble = -1;
4350 params.use_short_slot_time = -1;
fd8aaaf3 4351 params.ap_isolate = -1;
50b12f59 4352 params.ht_opmode = -1;
53cabad7
JB
4353 params.p2p_ctwindow = -1;
4354 params.p2p_opp_ps = -1;
9f1ba906
JM
4355
4356 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
4357 params.use_cts_prot =
4358 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
4359 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
4360 params.use_short_preamble =
4361 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
4362 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
4363 params.use_short_slot_time =
4364 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
4365 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4366 params.basic_rates =
4367 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4368 params.basic_rates_len =
4369 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4370 }
fd8aaaf3
FF
4371 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
4372 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
4373 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
4374 params.ht_opmode =
4375 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 4376
53cabad7
JB
4377 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
4378 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4379 return -EINVAL;
4380 params.p2p_ctwindow =
4381 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
4382 if (params.p2p_ctwindow < 0)
4383 return -EINVAL;
4384 if (params.p2p_ctwindow != 0 &&
4385 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
4386 return -EINVAL;
4387 }
4388
4389 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
4390 u8 tmp;
4391
4392 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4393 return -EINVAL;
4394 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
4395 if (tmp > 1)
4396 return -EINVAL;
4397 params.p2p_opp_ps = tmp;
4398 if (params.p2p_opp_ps &&
4399 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
4400 return -EINVAL;
4401 }
4402
4c476991
JB
4403 if (!rdev->ops->change_bss)
4404 return -EOPNOTSUPP;
9f1ba906 4405
074ac8df 4406 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
4407 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4408 return -EOPNOTSUPP;
3b85875a 4409
e35e4d28 4410 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
4411}
4412
b54452b0 4413static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
4414 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
4415 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
4416 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
4417 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
4418 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
4419 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
4420};
4421
4422static int parse_reg_rule(struct nlattr *tb[],
4423 struct ieee80211_reg_rule *reg_rule)
4424{
4425 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
4426 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
4427
4428 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
4429 return -EINVAL;
4430 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
4431 return -EINVAL;
4432 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
4433 return -EINVAL;
4434 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
4435 return -EINVAL;
4436 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
4437 return -EINVAL;
4438
4439 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
4440
4441 freq_range->start_freq_khz =
4442 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
4443 freq_range->end_freq_khz =
4444 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
4445 freq_range->max_bandwidth_khz =
4446 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
4447
4448 power_rule->max_eirp =
4449 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
4450
4451 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
4452 power_rule->max_antenna_gain =
4453 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
4454
4455 return 0;
4456}
4457
4458static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
4459{
4460 int r;
4461 char *data = NULL;
57b5ce07 4462 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 4463
80778f18
LR
4464 /*
4465 * You should only get this when cfg80211 hasn't yet initialized
4466 * completely when built-in to the kernel right between the time
4467 * window between nl80211_init() and regulatory_init(), if that is
4468 * even possible.
4469 */
458f4f9e 4470 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 4471 return -EINPROGRESS;
80778f18 4472
fe33eb39
LR
4473 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4474 return -EINVAL;
b2e1b302
LR
4475
4476 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4477
57b5ce07
LR
4478 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
4479 user_reg_hint_type =
4480 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
4481 else
4482 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
4483
4484 switch (user_reg_hint_type) {
4485 case NL80211_USER_REG_HINT_USER:
4486 case NL80211_USER_REG_HINT_CELL_BASE:
4487 break;
4488 default:
4489 return -EINVAL;
4490 }
4491
4492 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 4493
b2e1b302
LR
4494 return r;
4495}
4496
24bdd9f4 4497static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 4498 struct genl_info *info)
93da9cc1 4499{
4c476991 4500 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4501 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
4502 struct wireless_dev *wdev = dev->ieee80211_ptr;
4503 struct mesh_config cur_params;
4504 int err = 0;
93da9cc1 4505 void *hdr;
4506 struct nlattr *pinfoattr;
4507 struct sk_buff *msg;
4508
29cbe68c
JB
4509 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4510 return -EOPNOTSUPP;
4511
24bdd9f4 4512 if (!rdev->ops->get_mesh_config)
4c476991 4513 return -EOPNOTSUPP;
f3f92586 4514
29cbe68c
JB
4515 wdev_lock(wdev);
4516 /* If not connected, get default parameters */
4517 if (!wdev->mesh_id_len)
4518 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
4519 else
e35e4d28 4520 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
4521 wdev_unlock(wdev);
4522
93da9cc1 4523 if (err)
4c476991 4524 return err;
93da9cc1 4525
4526 /* Draw up a netlink message to send back */
fd2120ca 4527 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4528 if (!msg)
4529 return -ENOMEM;
15e47304 4530 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 4531 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 4532 if (!hdr)
efe1cf0c 4533 goto out;
24bdd9f4 4534 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 4535 if (!pinfoattr)
4536 goto nla_put_failure;
9360ffd1
DM
4537 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4538 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
4539 cur_params.dot11MeshRetryTimeout) ||
4540 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4541 cur_params.dot11MeshConfirmTimeout) ||
4542 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
4543 cur_params.dot11MeshHoldingTimeout) ||
4544 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
4545 cur_params.dot11MeshMaxPeerLinks) ||
4546 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
4547 cur_params.dot11MeshMaxRetries) ||
4548 nla_put_u8(msg, NL80211_MESHCONF_TTL,
4549 cur_params.dot11MeshTTL) ||
4550 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
4551 cur_params.element_ttl) ||
4552 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4553 cur_params.auto_open_plinks) ||
7eab0f64
JL
4554 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4555 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
4556 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4557 cur_params.dot11MeshHWMPmaxPREQretries) ||
4558 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
4559 cur_params.path_refresh_time) ||
4560 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4561 cur_params.min_discovery_timeout) ||
4562 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4563 cur_params.dot11MeshHWMPactivePathTimeout) ||
4564 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4565 cur_params.dot11MeshHWMPpreqMinInterval) ||
4566 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4567 cur_params.dot11MeshHWMPperrMinInterval) ||
4568 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4569 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
4570 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
4571 cur_params.dot11MeshHWMPRootMode) ||
4572 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4573 cur_params.dot11MeshHWMPRannInterval) ||
4574 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4575 cur_params.dot11MeshGateAnnouncementProtocol) ||
4576 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
4577 cur_params.dot11MeshForwarding) ||
4578 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
4579 cur_params.rssi_threshold) ||
4580 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4581 cur_params.ht_opmode) ||
4582 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4583 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
4584 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4585 cur_params.dot11MeshHWMProotInterval) ||
4586 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
4587 cur_params.dot11MeshHWMPconfirmationInterval) ||
4588 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
4589 cur_params.power_mode) ||
4590 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
4591 cur_params.dot11MeshAwakeWindowDuration) ||
4592 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
4593 cur_params.plink_timeout))
9360ffd1 4594 goto nla_put_failure;
93da9cc1 4595 nla_nest_end(msg, pinfoattr);
4596 genlmsg_end(msg, hdr);
4c476991 4597 return genlmsg_reply(msg, info);
93da9cc1 4598
3b85875a 4599 nla_put_failure:
93da9cc1 4600 genlmsg_cancel(msg, hdr);
efe1cf0c 4601 out:
d080e275 4602 nlmsg_free(msg);
4c476991 4603 return -ENOBUFS;
93da9cc1 4604}
4605
b54452b0 4606static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 4607 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
4608 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
4609 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
4610 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
4611 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
4612 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 4613 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 4614 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 4615 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 4616 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
4617 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
4618 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
4619 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
4620 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 4621 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 4622 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 4623 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 4624 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 4625 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 4626 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4627 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4628 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4629 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4630 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4631 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4632 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4633 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 4634 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
93da9cc1 4635};
4636
c80d545d
JC
4637static const struct nla_policy
4638 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4639 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4640 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4641 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4642 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 4643 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 4644 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
581a8b0f 4645 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4646 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4647 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4648};
4649
24bdd9f4 4650static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4651 struct mesh_config *cfg,
4652 u32 *mask_out)
93da9cc1 4653{
93da9cc1 4654 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4655 u32 mask = 0;
93da9cc1 4656
ea54fba2
MP
4657#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4658do { \
4659 if (tb[attr]) { \
4660 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4661 return -EINVAL; \
4662 cfg->param = fn(tb[attr]); \
4663 mask |= (1 << (attr - 1)); \
4664 } \
4665} while (0)
bd90fdcc
JB
4666
4667
24bdd9f4 4668 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4669 return -EINVAL;
4670 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4671 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4672 nl80211_meshconf_params_policy))
93da9cc1 4673 return -EINVAL;
4674
93da9cc1 4675 /* This makes sure that there aren't more than 32 mesh config
4676 * parameters (otherwise our bitfield scheme would not work.) */
4677 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4678
4679 /* Fill in the params struct */
ea54fba2 4680 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4681 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4682 nla_get_u16);
ea54fba2 4683 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4684 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4685 nla_get_u16);
ea54fba2 4686 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4687 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4688 nla_get_u16);
ea54fba2 4689 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4690 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4691 nla_get_u16);
ea54fba2 4692 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4693 mask, NL80211_MESHCONF_MAX_RETRIES,
4694 nla_get_u8);
ea54fba2 4695 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4696 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4697 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4698 mask, NL80211_MESHCONF_ELEMENT_TTL,
4699 nla_get_u8);
ea54fba2 4700 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4701 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4702 nla_get_u8);
ea54fba2
MP
4703 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4704 1, 255, mask,
a4f606ea
CYY
4705 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4706 nla_get_u32);
ea54fba2 4707 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4708 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4709 nla_get_u8);
ea54fba2 4710 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4711 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4712 nla_get_u32);
ea54fba2 4713 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4714 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4715 nla_get_u16);
ea54fba2
MP
4716 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4717 1, 65535, mask,
a4f606ea
CYY
4718 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4719 nla_get_u32);
93da9cc1 4720 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4721 1, 65535, mask,
4722 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4723 nla_get_u16);
dca7e943 4724 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4725 1, 65535, mask,
4726 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4727 nla_get_u16);
93da9cc1 4728 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4729 dot11MeshHWMPnetDiameterTraversalTime,
4730 1, 65535, mask,
a4f606ea
CYY
4731 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4732 nla_get_u16);
ea54fba2
MP
4733 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4734 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4735 nla_get_u8);
4736 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4737 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4738 nla_get_u16);
63c5723b 4739 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4740 dot11MeshGateAnnouncementProtocol, 0, 1,
4741 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4742 nla_get_u8);
ea54fba2 4743 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4744 mask, NL80211_MESHCONF_FORWARDING,
4745 nla_get_u8);
ea54fba2 4746 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, 1, 255,
a4f606ea
CYY
4747 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
4748 nla_get_u32);
ea54fba2 4749 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4750 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4751 nla_get_u16);
4752 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4753 1, 65535, mask,
ac1073a6
CYY
4754 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4755 nla_get_u32);
ea54fba2 4756 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4757 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4758 nla_get_u16);
4759 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4760 dot11MeshHWMPconfirmationInterval,
4761 1, 65535, mask,
728b19e5 4762 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4763 nla_get_u16);
3b1c5a53
MP
4764 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4765 NL80211_MESH_POWER_ACTIVE,
4766 NL80211_MESH_POWER_MAX,
4767 mask, NL80211_MESHCONF_POWER_MODE,
4768 nla_get_u32);
4769 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4770 0, 65535, mask,
4771 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
8e7c0538
CT
4772 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 1, 0xffffffff,
4773 mask, NL80211_MESHCONF_PLINK_TIMEOUT,
4774 nla_get_u32);
bd90fdcc
JB
4775 if (mask_out)
4776 *mask_out = mask;
c80d545d 4777
bd90fdcc
JB
4778 return 0;
4779
4780#undef FILL_IN_MESH_PARAM_IF_SET
4781}
4782
c80d545d
JC
4783static int nl80211_parse_mesh_setup(struct genl_info *info,
4784 struct mesh_setup *setup)
4785{
bb2798d4 4786 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
4787 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4788
4789 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4790 return -EINVAL;
4791 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4792 info->attrs[NL80211_ATTR_MESH_SETUP],
4793 nl80211_mesh_setup_params_policy))
4794 return -EINVAL;
4795
d299a1f2
JC
4796 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4797 setup->sync_method =
4798 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4799 IEEE80211_SYNC_METHOD_VENDOR :
4800 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4801
c80d545d
JC
4802 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4803 setup->path_sel_proto =
4804 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4805 IEEE80211_PATH_PROTOCOL_VENDOR :
4806 IEEE80211_PATH_PROTOCOL_HWMP;
4807
4808 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4809 setup->path_metric =
4810 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4811 IEEE80211_PATH_METRIC_VENDOR :
4812 IEEE80211_PATH_METRIC_AIRTIME;
4813
581a8b0f
JC
4814
4815 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4816 struct nlattr *ieattr =
581a8b0f 4817 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4818 if (!is_valid_ie_attr(ieattr))
4819 return -EINVAL;
581a8b0f
JC
4820 setup->ie = nla_data(ieattr);
4821 setup->ie_len = nla_len(ieattr);
c80d545d 4822 }
bb2798d4
TP
4823 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
4824 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
4825 return -EINVAL;
4826 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
4827 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4828 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
4829 if (setup->is_secure)
4830 setup->user_mpm = true;
c80d545d 4831
6e16d90b
CT
4832 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
4833 if (!setup->user_mpm)
4834 return -EINVAL;
4835 setup->auth_id =
4836 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
4837 }
4838
c80d545d
JC
4839 return 0;
4840}
4841
24bdd9f4 4842static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4843 struct genl_info *info)
bd90fdcc
JB
4844{
4845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4846 struct net_device *dev = info->user_ptr[1];
29cbe68c 4847 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4848 struct mesh_config cfg;
4849 u32 mask;
4850 int err;
4851
29cbe68c
JB
4852 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4853 return -EOPNOTSUPP;
4854
24bdd9f4 4855 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4856 return -EOPNOTSUPP;
4857
24bdd9f4 4858 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4859 if (err)
4860 return err;
4861
29cbe68c
JB
4862 wdev_lock(wdev);
4863 if (!wdev->mesh_id_len)
4864 err = -ENOLINK;
4865
4866 if (!err)
e35e4d28 4867 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4868
4869 wdev_unlock(wdev);
4870
4871 return err;
93da9cc1 4872}
4873
f130347c
LR
4874static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4875{
458f4f9e 4876 const struct ieee80211_regdomain *regdom;
f130347c
LR
4877 struct sk_buff *msg;
4878 void *hdr = NULL;
4879 struct nlattr *nl_reg_rules;
4880 unsigned int i;
f130347c
LR
4881
4882 if (!cfg80211_regdomain)
5fe231e8 4883 return -EINVAL;
f130347c 4884
fd2120ca 4885 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5fe231e8
JB
4886 if (!msg)
4887 return -ENOBUFS;
f130347c 4888
15e47304 4889 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4890 NL80211_CMD_GET_REG);
4891 if (!hdr)
efe1cf0c 4892 goto put_failure;
f130347c 4893
57b5ce07
LR
4894 if (reg_last_request_cell_base() &&
4895 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4896 NL80211_USER_REG_HINT_CELL_BASE))
4897 goto nla_put_failure;
4898
458f4f9e
JB
4899 rcu_read_lock();
4900 regdom = rcu_dereference(cfg80211_regdomain);
4901
4902 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
4903 (regdom->dfs_region &&
4904 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
4905 goto nla_put_failure_rcu;
4906
f130347c
LR
4907 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4908 if (!nl_reg_rules)
458f4f9e 4909 goto nla_put_failure_rcu;
f130347c 4910
458f4f9e 4911 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
4912 struct nlattr *nl_reg_rule;
4913 const struct ieee80211_reg_rule *reg_rule;
4914 const struct ieee80211_freq_range *freq_range;
4915 const struct ieee80211_power_rule *power_rule;
4916
458f4f9e 4917 reg_rule = &regdom->reg_rules[i];
f130347c
LR
4918 freq_range = &reg_rule->freq_range;
4919 power_rule = &reg_rule->power_rule;
4920
4921 nl_reg_rule = nla_nest_start(msg, i);
4922 if (!nl_reg_rule)
458f4f9e 4923 goto nla_put_failure_rcu;
f130347c 4924
9360ffd1
DM
4925 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4926 reg_rule->flags) ||
4927 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4928 freq_range->start_freq_khz) ||
4929 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
4930 freq_range->end_freq_khz) ||
4931 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
4932 freq_range->max_bandwidth_khz) ||
4933 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
4934 power_rule->max_antenna_gain) ||
4935 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
4936 power_rule->max_eirp))
458f4f9e 4937 goto nla_put_failure_rcu;
f130347c
LR
4938
4939 nla_nest_end(msg, nl_reg_rule);
4940 }
458f4f9e 4941 rcu_read_unlock();
f130347c
LR
4942
4943 nla_nest_end(msg, nl_reg_rules);
4944
4945 genlmsg_end(msg, hdr);
5fe231e8 4946 return genlmsg_reply(msg, info);
f130347c 4947
458f4f9e
JB
4948nla_put_failure_rcu:
4949 rcu_read_unlock();
f130347c
LR
4950nla_put_failure:
4951 genlmsg_cancel(msg, hdr);
efe1cf0c 4952put_failure:
d080e275 4953 nlmsg_free(msg);
5fe231e8 4954 return -EMSGSIZE;
f130347c
LR
4955}
4956
b2e1b302
LR
4957static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
4958{
4959 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
4960 struct nlattr *nl_reg_rule;
4961 char *alpha2 = NULL;
4962 int rem_reg_rules = 0, r = 0;
4963 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4964 u8 dfs_region = 0;
b2e1b302
LR
4965 struct ieee80211_regdomain *rd = NULL;
4966
4967 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4968 return -EINVAL;
4969
4970 if (!info->attrs[NL80211_ATTR_REG_RULES])
4971 return -EINVAL;
4972
4973 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4974
8b60b078
LR
4975 if (info->attrs[NL80211_ATTR_DFS_REGION])
4976 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4977
b2e1b302 4978 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4979 rem_reg_rules) {
b2e1b302
LR
4980 num_rules++;
4981 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4982 return -EINVAL;
b2e1b302
LR
4983 }
4984
b2e1b302 4985 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 4986 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
4987
4988 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
4989 if (!rd)
4990 return -ENOMEM;
b2e1b302
LR
4991
4992 rd->n_reg_rules = num_rules;
4993 rd->alpha2[0] = alpha2[0];
4994 rd->alpha2[1] = alpha2[1];
4995
8b60b078
LR
4996 /*
4997 * Disable DFS master mode if the DFS region was
4998 * not supported or known on this kernel.
4999 */
5000 if (reg_supported_dfs_region(dfs_region))
5001 rd->dfs_region = dfs_region;
5002
b2e1b302 5003 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5004 rem_reg_rules) {
b2e1b302 5005 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
5006 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
5007 reg_rule_policy);
b2e1b302
LR
5008 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
5009 if (r)
5010 goto bad_reg;
5011
5012 rule_idx++;
5013
d0e18f83
LR
5014 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
5015 r = -EINVAL;
b2e1b302 5016 goto bad_reg;
d0e18f83 5017 }
b2e1b302
LR
5018 }
5019
b2e1b302 5020 r = set_regdom(rd);
6913b49a 5021 /* set_regdom took ownership */
1a919318 5022 rd = NULL;
b2e1b302 5023
d2372b31 5024 bad_reg:
b2e1b302 5025 kfree(rd);
d0e18f83 5026 return r;
b2e1b302
LR
5027}
5028
83f5e2cf
JB
5029static int validate_scan_freqs(struct nlattr *freqs)
5030{
5031 struct nlattr *attr1, *attr2;
5032 int n_channels = 0, tmp1, tmp2;
5033
5034 nla_for_each_nested(attr1, freqs, tmp1) {
5035 n_channels++;
5036 /*
5037 * Some hardware has a limited channel list for
5038 * scanning, and it is pretty much nonsensical
5039 * to scan for a channel twice, so disallow that
5040 * and don't require drivers to check that the
5041 * channel list they get isn't longer than what
5042 * they can scan, as long as they can scan all
5043 * the channels they registered at once.
5044 */
5045 nla_for_each_nested(attr2, freqs, tmp2)
5046 if (attr1 != attr2 &&
5047 nla_get_u32(attr1) == nla_get_u32(attr2))
5048 return 0;
5049 }
5050
5051 return n_channels;
5052}
5053
2a519311
JB
5054static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
5055{
4c476991 5056 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 5057 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 5058 struct cfg80211_scan_request *request;
2a519311
JB
5059 struct nlattr *attr;
5060 struct wiphy *wiphy;
83f5e2cf 5061 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 5062 size_t ie_len;
2a519311 5063
f4a11bb0
JB
5064 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5065 return -EINVAL;
5066
79c97e97 5067 wiphy = &rdev->wiphy;
2a519311 5068
4c476991
JB
5069 if (!rdev->ops->scan)
5070 return -EOPNOTSUPP;
2a519311 5071
f9f47529
JB
5072 if (rdev->scan_req) {
5073 err = -EBUSY;
5074 goto unlock;
5075 }
2a519311
JB
5076
5077 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
5078 n_channels = validate_scan_freqs(
5079 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
5080 if (!n_channels) {
5081 err = -EINVAL;
5082 goto unlock;
5083 }
2a519311 5084 } else {
34850ab2 5085 enum ieee80211_band band;
83f5e2cf
JB
5086 n_channels = 0;
5087
2a519311
JB
5088 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
5089 if (wiphy->bands[band])
5090 n_channels += wiphy->bands[band]->n_channels;
5091 }
5092
5093 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5094 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
5095 n_ssids++;
5096
f9f47529
JB
5097 if (n_ssids > wiphy->max_scan_ssids) {
5098 err = -EINVAL;
5099 goto unlock;
5100 }
2a519311 5101
70692ad2
JM
5102 if (info->attrs[NL80211_ATTR_IE])
5103 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5104 else
5105 ie_len = 0;
5106
f9f47529
JB
5107 if (ie_len > wiphy->max_scan_ie_len) {
5108 err = -EINVAL;
5109 goto unlock;
5110 }
18a83659 5111
2a519311 5112 request = kzalloc(sizeof(*request)
a2cd43c5
LC
5113 + sizeof(*request->ssids) * n_ssids
5114 + sizeof(*request->channels) * n_channels
70692ad2 5115 + ie_len, GFP_KERNEL);
f9f47529
JB
5116 if (!request) {
5117 err = -ENOMEM;
5118 goto unlock;
5119 }
2a519311 5120
2a519311 5121 if (n_ssids)
5ba63533 5122 request->ssids = (void *)&request->channels[n_channels];
2a519311 5123 request->n_ssids = n_ssids;
70692ad2
JM
5124 if (ie_len) {
5125 if (request->ssids)
5126 request->ie = (void *)(request->ssids + n_ssids);
5127 else
5128 request->ie = (void *)(request->channels + n_channels);
5129 }
2a519311 5130
584991dc 5131 i = 0;
2a519311
JB
5132 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5133 /* user specified, bail out if channel not found */
2a519311 5134 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
5135 struct ieee80211_channel *chan;
5136
5137 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5138
5139 if (!chan) {
2a519311
JB
5140 err = -EINVAL;
5141 goto out_free;
5142 }
584991dc
JB
5143
5144 /* ignore disabled channels */
5145 if (chan->flags & IEEE80211_CHAN_DISABLED)
5146 continue;
5147
5148 request->channels[i] = chan;
2a519311
JB
5149 i++;
5150 }
5151 } else {
34850ab2
JB
5152 enum ieee80211_band band;
5153
2a519311 5154 /* all channels */
2a519311
JB
5155 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5156 int j;
5157 if (!wiphy->bands[band])
5158 continue;
5159 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
5160 struct ieee80211_channel *chan;
5161
5162 chan = &wiphy->bands[band]->channels[j];
5163
5164 if (chan->flags & IEEE80211_CHAN_DISABLED)
5165 continue;
5166
5167 request->channels[i] = chan;
2a519311
JB
5168 i++;
5169 }
5170 }
5171 }
5172
584991dc
JB
5173 if (!i) {
5174 err = -EINVAL;
5175 goto out_free;
5176 }
5177
5178 request->n_channels = i;
5179
2a519311
JB
5180 i = 0;
5181 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
5182 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 5183 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
5184 err = -EINVAL;
5185 goto out_free;
5186 }
57a27e1d 5187 request->ssids[i].ssid_len = nla_len(attr);
2a519311 5188 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
5189 i++;
5190 }
5191 }
5192
70692ad2
JM
5193 if (info->attrs[NL80211_ATTR_IE]) {
5194 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
5195 memcpy((void *)request->ie,
5196 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
5197 request->ie_len);
5198 }
5199
34850ab2 5200 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
5201 if (wiphy->bands[i])
5202 request->rates[i] =
5203 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
5204
5205 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
5206 nla_for_each_nested(attr,
5207 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
5208 tmp) {
5209 enum ieee80211_band band = nla_type(attr);
5210
84404623 5211 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
5212 err = -EINVAL;
5213 goto out_free;
5214 }
5215 err = ieee80211_get_ratemask(wiphy->bands[band],
5216 nla_data(attr),
5217 nla_len(attr),
5218 &request->rates[band]);
5219 if (err)
5220 goto out_free;
5221 }
5222 }
5223
46856bbf 5224 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5225 request->flags = nla_get_u32(
5226 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
5227 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5228 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
5229 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
5230 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
5231 err = -EOPNOTSUPP;
5232 goto out_free;
5233 }
5234 }
ed473771 5235
e9f935e3
RM
5236 request->no_cck =
5237 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5238
fd014284 5239 request->wdev = wdev;
79c97e97 5240 request->wiphy = &rdev->wiphy;
15d6030b 5241 request->scan_start = jiffies;
2a519311 5242
79c97e97 5243 rdev->scan_req = request;
e35e4d28 5244 err = rdev_scan(rdev, request);
2a519311 5245
463d0183 5246 if (!err) {
fd014284
JB
5247 nl80211_send_scan_start(rdev, wdev);
5248 if (wdev->netdev)
5249 dev_hold(wdev->netdev);
4c476991 5250 } else {
2a519311 5251 out_free:
79c97e97 5252 rdev->scan_req = NULL;
2a519311
JB
5253 kfree(request);
5254 }
3b85875a 5255
f9f47529 5256 unlock:
2a519311
JB
5257 return err;
5258}
5259
807f8a8c
LC
5260static int nl80211_start_sched_scan(struct sk_buff *skb,
5261 struct genl_info *info)
5262{
5263 struct cfg80211_sched_scan_request *request;
5264 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5265 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
5266 struct nlattr *attr;
5267 struct wiphy *wiphy;
a1f1c21c 5268 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 5269 u32 interval;
807f8a8c
LC
5270 enum ieee80211_band band;
5271 size_t ie_len;
a1f1c21c 5272 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
5273
5274 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5275 !rdev->ops->sched_scan_start)
5276 return -EOPNOTSUPP;
5277
5278 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5279 return -EINVAL;
5280
bbe6ad6d
LC
5281 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
5282 return -EINVAL;
5283
5284 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
5285 if (interval == 0)
5286 return -EINVAL;
5287
807f8a8c
LC
5288 wiphy = &rdev->wiphy;
5289
5290 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5291 n_channels = validate_scan_freqs(
5292 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
5293 if (!n_channels)
5294 return -EINVAL;
5295 } else {
5296 n_channels = 0;
5297
5298 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
5299 if (wiphy->bands[band])
5300 n_channels += wiphy->bands[band]->n_channels;
5301 }
5302
5303 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5304 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
5305 tmp)
5306 n_ssids++;
5307
93b6aa69 5308 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
5309 return -EINVAL;
5310
a1f1c21c
LC
5311 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
5312 nla_for_each_nested(attr,
5313 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
5314 tmp)
5315 n_match_sets++;
5316
5317 if (n_match_sets > wiphy->max_match_sets)
5318 return -EINVAL;
5319
807f8a8c
LC
5320 if (info->attrs[NL80211_ATTR_IE])
5321 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5322 else
5323 ie_len = 0;
5324
5a865bad 5325 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
5326 return -EINVAL;
5327
c10841ca
LC
5328 if (rdev->sched_scan_req) {
5329 err = -EINPROGRESS;
5330 goto out;
5331 }
5332
807f8a8c 5333 request = kzalloc(sizeof(*request)
a2cd43c5 5334 + sizeof(*request->ssids) * n_ssids
a1f1c21c 5335 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 5336 + sizeof(*request->channels) * n_channels
807f8a8c 5337 + ie_len, GFP_KERNEL);
c10841ca
LC
5338 if (!request) {
5339 err = -ENOMEM;
5340 goto out;
5341 }
807f8a8c
LC
5342
5343 if (n_ssids)
5344 request->ssids = (void *)&request->channels[n_channels];
5345 request->n_ssids = n_ssids;
5346 if (ie_len) {
5347 if (request->ssids)
5348 request->ie = (void *)(request->ssids + n_ssids);
5349 else
5350 request->ie = (void *)(request->channels + n_channels);
5351 }
5352
a1f1c21c
LC
5353 if (n_match_sets) {
5354 if (request->ie)
5355 request->match_sets = (void *)(request->ie + ie_len);
5356 else if (request->ssids)
5357 request->match_sets =
5358 (void *)(request->ssids + n_ssids);
5359 else
5360 request->match_sets =
5361 (void *)(request->channels + n_channels);
5362 }
5363 request->n_match_sets = n_match_sets;
5364
807f8a8c
LC
5365 i = 0;
5366 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5367 /* user specified, bail out if channel not found */
5368 nla_for_each_nested(attr,
5369 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
5370 tmp) {
5371 struct ieee80211_channel *chan;
5372
5373 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5374
5375 if (!chan) {
5376 err = -EINVAL;
5377 goto out_free;
5378 }
5379
5380 /* ignore disabled channels */
5381 if (chan->flags & IEEE80211_CHAN_DISABLED)
5382 continue;
5383
5384 request->channels[i] = chan;
5385 i++;
5386 }
5387 } else {
5388 /* all channels */
5389 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5390 int j;
5391 if (!wiphy->bands[band])
5392 continue;
5393 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
5394 struct ieee80211_channel *chan;
5395
5396 chan = &wiphy->bands[band]->channels[j];
5397
5398 if (chan->flags & IEEE80211_CHAN_DISABLED)
5399 continue;
5400
5401 request->channels[i] = chan;
5402 i++;
5403 }
5404 }
5405 }
5406
5407 if (!i) {
5408 err = -EINVAL;
5409 goto out_free;
5410 }
5411
5412 request->n_channels = i;
5413
5414 i = 0;
5415 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
5416 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
5417 tmp) {
57a27e1d 5418 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
5419 err = -EINVAL;
5420 goto out_free;
5421 }
57a27e1d 5422 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
5423 memcpy(request->ssids[i].ssid, nla_data(attr),
5424 nla_len(attr));
807f8a8c
LC
5425 i++;
5426 }
5427 }
5428
a1f1c21c
LC
5429 i = 0;
5430 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
5431 nla_for_each_nested(attr,
5432 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
5433 tmp) {
88e920b4 5434 struct nlattr *ssid, *rssi;
a1f1c21c
LC
5435
5436 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
5437 nla_data(attr), nla_len(attr),
5438 nl80211_match_policy);
4a4ab0d7 5439 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
5440 if (ssid) {
5441 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
5442 err = -EINVAL;
5443 goto out_free;
5444 }
5445 memcpy(request->match_sets[i].ssid.ssid,
5446 nla_data(ssid), nla_len(ssid));
5447 request->match_sets[i].ssid.ssid_len =
5448 nla_len(ssid);
5449 }
88e920b4
TP
5450 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
5451 if (rssi)
5452 request->rssi_thold = nla_get_u32(rssi);
5453 else
5454 request->rssi_thold =
5455 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
5456 i++;
5457 }
5458 }
5459
807f8a8c
LC
5460 if (info->attrs[NL80211_ATTR_IE]) {
5461 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5462 memcpy((void *)request->ie,
5463 nla_data(info->attrs[NL80211_ATTR_IE]),
5464 request->ie_len);
5465 }
5466
46856bbf 5467 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5468 request->flags = nla_get_u32(
5469 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
5470 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5471 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
5472 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
5473 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
5474 err = -EOPNOTSUPP;
5475 goto out_free;
5476 }
5477 }
ed473771 5478
807f8a8c
LC
5479 request->dev = dev;
5480 request->wiphy = &rdev->wiphy;
bbe6ad6d 5481 request->interval = interval;
15d6030b 5482 request->scan_start = jiffies;
807f8a8c 5483
e35e4d28 5484 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
5485 if (!err) {
5486 rdev->sched_scan_req = request;
5487 nl80211_send_sched_scan(rdev, dev,
5488 NL80211_CMD_START_SCHED_SCAN);
5489 goto out;
5490 }
5491
5492out_free:
5493 kfree(request);
5494out:
5495 return err;
5496}
5497
5498static int nl80211_stop_sched_scan(struct sk_buff *skb,
5499 struct genl_info *info)
5500{
5501 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5502
5503 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5504 !rdev->ops->sched_scan_stop)
5505 return -EOPNOTSUPP;
5506
5fe231e8 5507 return __cfg80211_stop_sched_scan(rdev, false);
807f8a8c
LC
5508}
5509
04f39047
SW
5510static int nl80211_start_radar_detection(struct sk_buff *skb,
5511 struct genl_info *info)
5512{
5513 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5514 struct net_device *dev = info->user_ptr[1];
5515 struct wireless_dev *wdev = dev->ieee80211_ptr;
5516 struct cfg80211_chan_def chandef;
5517 int err;
5518
5519 err = nl80211_parse_chandef(rdev, info, &chandef);
5520 if (err)
5521 return err;
5522
5523 if (wdev->cac_started)
5524 return -EBUSY;
5525
5526 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef);
5527 if (err < 0)
5528 return err;
5529
5530 if (err == 0)
5531 return -EINVAL;
5532
5533 if (chandef.chan->dfs_state != NL80211_DFS_USABLE)
5534 return -EINVAL;
5535
5536 if (!rdev->ops->start_radar_detection)
5537 return -EOPNOTSUPP;
5538
04f39047
SW
5539 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
5540 chandef.chan, CHAN_MODE_SHARED,
5541 BIT(chandef.width));
5542 if (err)
5fe231e8 5543 return err;
04f39047
SW
5544
5545 err = rdev->ops->start_radar_detection(&rdev->wiphy, dev, &chandef);
5546 if (!err) {
5547 wdev->channel = chandef.chan;
5548 wdev->cac_started = true;
5549 wdev->cac_start_time = jiffies;
5550 }
04f39047
SW
5551 return err;
5552}
5553
9720bb3a
JB
5554static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
5555 u32 seq, int flags,
2a519311 5556 struct cfg80211_registered_device *rdev,
48ab905d
JB
5557 struct wireless_dev *wdev,
5558 struct cfg80211_internal_bss *intbss)
2a519311 5559{
48ab905d 5560 struct cfg80211_bss *res = &intbss->pub;
9caf0364 5561 const struct cfg80211_bss_ies *ies;
2a519311
JB
5562 void *hdr;
5563 struct nlattr *bss;
8cef2c9d 5564 bool tsf = false;
48ab905d
JB
5565
5566 ASSERT_WDEV_LOCK(wdev);
2a519311 5567
15e47304 5568 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
5569 NL80211_CMD_NEW_SCAN_RESULTS);
5570 if (!hdr)
5571 return -1;
5572
9720bb3a
JB
5573 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
5574
97990a06
JB
5575 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
5576 goto nla_put_failure;
5577 if (wdev->netdev &&
9360ffd1
DM
5578 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
5579 goto nla_put_failure;
97990a06
JB
5580 if (nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
5581 goto nla_put_failure;
2a519311
JB
5582
5583 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
5584 if (!bss)
5585 goto nla_put_failure;
9360ffd1 5586 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 5587 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 5588 goto nla_put_failure;
9caf0364
JB
5589
5590 rcu_read_lock();
5591 ies = rcu_dereference(res->ies);
8cef2c9d
JB
5592 if (ies) {
5593 if (nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5594 goto fail_unlock_rcu;
5595 tsf = true;
5596 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
5597 ies->len, ies->data))
5598 goto fail_unlock_rcu;
9caf0364
JB
5599 }
5600 ies = rcu_dereference(res->beacon_ies);
8cef2c9d
JB
5601 if (ies) {
5602 if (!tsf && nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5603 goto fail_unlock_rcu;
5604 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
5605 ies->len, ies->data))
5606 goto fail_unlock_rcu;
9caf0364
JB
5607 }
5608 rcu_read_unlock();
5609
9360ffd1
DM
5610 if (res->beacon_interval &&
5611 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
5612 goto nla_put_failure;
5613 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
5614 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
5615 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
5616 jiffies_to_msecs(jiffies - intbss->ts)))
5617 goto nla_put_failure;
2a519311 5618
77965c97 5619 switch (rdev->wiphy.signal_type) {
2a519311 5620 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
5621 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
5622 goto nla_put_failure;
2a519311
JB
5623 break;
5624 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
5625 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
5626 goto nla_put_failure;
2a519311
JB
5627 break;
5628 default:
5629 break;
5630 }
5631
48ab905d 5632 switch (wdev->iftype) {
074ac8df 5633 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 5634 case NL80211_IFTYPE_STATION:
9360ffd1
DM
5635 if (intbss == wdev->current_bss &&
5636 nla_put_u32(msg, NL80211_BSS_STATUS,
5637 NL80211_BSS_STATUS_ASSOCIATED))
5638 goto nla_put_failure;
48ab905d
JB
5639 break;
5640 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
5641 if (intbss == wdev->current_bss &&
5642 nla_put_u32(msg, NL80211_BSS_STATUS,
5643 NL80211_BSS_STATUS_IBSS_JOINED))
5644 goto nla_put_failure;
48ab905d
JB
5645 break;
5646 default:
5647 break;
5648 }
5649
2a519311
JB
5650 nla_nest_end(msg, bss);
5651
5652 return genlmsg_end(msg, hdr);
5653
8cef2c9d
JB
5654 fail_unlock_rcu:
5655 rcu_read_unlock();
2a519311
JB
5656 nla_put_failure:
5657 genlmsg_cancel(msg, hdr);
5658 return -EMSGSIZE;
5659}
5660
97990a06 5661static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 5662{
48ab905d 5663 struct cfg80211_registered_device *rdev;
2a519311 5664 struct cfg80211_internal_bss *scan;
48ab905d 5665 struct wireless_dev *wdev;
97990a06 5666 int start = cb->args[2], idx = 0;
2a519311
JB
5667 int err;
5668
97990a06 5669 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
5670 if (err)
5671 return err;
2a519311 5672
48ab905d
JB
5673 wdev_lock(wdev);
5674 spin_lock_bh(&rdev->bss_lock);
5675 cfg80211_bss_expire(rdev);
5676
9720bb3a
JB
5677 cb->seq = rdev->bss_generation;
5678
48ab905d 5679 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
5680 if (++idx <= start)
5681 continue;
9720bb3a 5682 if (nl80211_send_bss(skb, cb,
2a519311 5683 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 5684 rdev, wdev, scan) < 0) {
2a519311 5685 idx--;
67748893 5686 break;
2a519311
JB
5687 }
5688 }
5689
48ab905d
JB
5690 spin_unlock_bh(&rdev->bss_lock);
5691 wdev_unlock(wdev);
2a519311 5692
97990a06
JB
5693 cb->args[2] = idx;
5694 nl80211_finish_wdev_dump(rdev);
2a519311 5695
67748893 5696 return skb->len;
2a519311
JB
5697}
5698
15e47304 5699static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
5700 int flags, struct net_device *dev,
5701 struct survey_info *survey)
5702{
5703 void *hdr;
5704 struct nlattr *infoattr;
5705
15e47304 5706 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
5707 NL80211_CMD_NEW_SURVEY_RESULTS);
5708 if (!hdr)
5709 return -ENOMEM;
5710
9360ffd1
DM
5711 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
5712 goto nla_put_failure;
61fa713c
HS
5713
5714 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
5715 if (!infoattr)
5716 goto nla_put_failure;
5717
9360ffd1
DM
5718 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
5719 survey->channel->center_freq))
5720 goto nla_put_failure;
5721
5722 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
5723 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
5724 goto nla_put_failure;
5725 if ((survey->filled & SURVEY_INFO_IN_USE) &&
5726 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
5727 goto nla_put_failure;
5728 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
5729 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
5730 survey->channel_time))
5731 goto nla_put_failure;
5732 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
5733 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
5734 survey->channel_time_busy))
5735 goto nla_put_failure;
5736 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
5737 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5738 survey->channel_time_ext_busy))
5739 goto nla_put_failure;
5740 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5741 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5742 survey->channel_time_rx))
5743 goto nla_put_failure;
5744 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5745 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5746 survey->channel_time_tx))
5747 goto nla_put_failure;
61fa713c
HS
5748
5749 nla_nest_end(msg, infoattr);
5750
5751 return genlmsg_end(msg, hdr);
5752
5753 nla_put_failure:
5754 genlmsg_cancel(msg, hdr);
5755 return -EMSGSIZE;
5756}
5757
5758static int nl80211_dump_survey(struct sk_buff *skb,
5759 struct netlink_callback *cb)
5760{
5761 struct survey_info survey;
5762 struct cfg80211_registered_device *dev;
97990a06
JB
5763 struct wireless_dev *wdev;
5764 int survey_idx = cb->args[2];
61fa713c
HS
5765 int res;
5766
97990a06 5767 res = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
5768 if (res)
5769 return res;
61fa713c 5770
97990a06
JB
5771 if (!wdev->netdev) {
5772 res = -EINVAL;
5773 goto out_err;
5774 }
5775
61fa713c
HS
5776 if (!dev->ops->dump_survey) {
5777 res = -EOPNOTSUPP;
5778 goto out_err;
5779 }
5780
5781 while (1) {
180cdc79
LR
5782 struct ieee80211_channel *chan;
5783
97990a06 5784 res = rdev_dump_survey(dev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
5785 if (res == -ENOENT)
5786 break;
5787 if (res)
5788 goto out_err;
5789
180cdc79
LR
5790 /* Survey without a channel doesn't make sense */
5791 if (!survey.channel) {
5792 res = -EINVAL;
5793 goto out;
5794 }
5795
5796 chan = ieee80211_get_channel(&dev->wiphy,
5797 survey.channel->center_freq);
5798 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5799 survey_idx++;
5800 continue;
5801 }
5802
61fa713c 5803 if (nl80211_send_survey(skb,
15e47304 5804 NETLINK_CB(cb->skb).portid,
61fa713c 5805 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 5806 wdev->netdev, &survey) < 0)
61fa713c
HS
5807 goto out;
5808 survey_idx++;
5809 }
5810
5811 out:
97990a06 5812 cb->args[2] = survey_idx;
61fa713c
HS
5813 res = skb->len;
5814 out_err:
97990a06 5815 nl80211_finish_wdev_dump(dev);
61fa713c
HS
5816 return res;
5817}
5818
b23aa676
SO
5819static bool nl80211_valid_wpa_versions(u32 wpa_versions)
5820{
5821 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
5822 NL80211_WPA_VERSION_2));
5823}
5824
636a5d36
JM
5825static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
5826{
4c476991
JB
5827 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5828 struct net_device *dev = info->user_ptr[1];
19957bb3 5829 struct ieee80211_channel *chan;
e39e5b5e
JM
5830 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
5831 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 5832 enum nl80211_auth_type auth_type;
fffd0934 5833 struct key_parse key;
d5cdfacb 5834 bool local_state_change;
636a5d36 5835
f4a11bb0
JB
5836 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5837 return -EINVAL;
5838
5839 if (!info->attrs[NL80211_ATTR_MAC])
5840 return -EINVAL;
5841
1778092e
JM
5842 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
5843 return -EINVAL;
5844
19957bb3
JB
5845 if (!info->attrs[NL80211_ATTR_SSID])
5846 return -EINVAL;
5847
5848 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
5849 return -EINVAL;
5850
fffd0934
JB
5851 err = nl80211_parse_key(info, &key);
5852 if (err)
5853 return err;
5854
5855 if (key.idx >= 0) {
e31b8213
JB
5856 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
5857 return -EINVAL;
fffd0934
JB
5858 if (!key.p.key || !key.p.key_len)
5859 return -EINVAL;
5860 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
5861 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
5862 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
5863 key.p.key_len != WLAN_KEY_LEN_WEP104))
5864 return -EINVAL;
5865 if (key.idx > 4)
5866 return -EINVAL;
5867 } else {
5868 key.p.key_len = 0;
5869 key.p.key = NULL;
5870 }
5871
afea0b7a
JB
5872 if (key.idx >= 0) {
5873 int i;
5874 bool ok = false;
5875 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
5876 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
5877 ok = true;
5878 break;
5879 }
5880 }
4c476991
JB
5881 if (!ok)
5882 return -EINVAL;
afea0b7a
JB
5883 }
5884
4c476991
JB
5885 if (!rdev->ops->auth)
5886 return -EOPNOTSUPP;
636a5d36 5887
074ac8df 5888 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5889 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5890 return -EOPNOTSUPP;
eec60b03 5891
19957bb3 5892 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 5893 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 5894 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5895 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5896 return -EINVAL;
636a5d36 5897
19957bb3
JB
5898 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5899 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5900
5901 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5902 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5903 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5904 }
5905
19957bb3 5906 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 5907 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 5908 return -EINVAL;
636a5d36 5909
e39e5b5e
JM
5910 if (auth_type == NL80211_AUTHTYPE_SAE &&
5911 !info->attrs[NL80211_ATTR_SAE_DATA])
5912 return -EINVAL;
5913
5914 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
5915 if (auth_type != NL80211_AUTHTYPE_SAE)
5916 return -EINVAL;
5917 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
5918 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
5919 /* need to include at least Auth Transaction and Status Code */
5920 if (sae_data_len < 4)
5921 return -EINVAL;
5922 }
5923
d5cdfacb
JM
5924 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5925
95de817b
JB
5926 /*
5927 * Since we no longer track auth state, ignore
5928 * requests to only change local state.
5929 */
5930 if (local_state_change)
5931 return 0;
5932
91bf9b26
JB
5933 wdev_lock(dev->ieee80211_ptr);
5934 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
5935 ssid, ssid_len, ie, ie_len,
5936 key.p.key, key.p.key_len, key.idx,
5937 sae_data, sae_data_len);
5938 wdev_unlock(dev->ieee80211_ptr);
5939 return err;
636a5d36
JM
5940}
5941
c0692b8f
JB
5942static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
5943 struct genl_info *info,
3dc27d25
JB
5944 struct cfg80211_crypto_settings *settings,
5945 int cipher_limit)
b23aa676 5946{
c0b2bbd8
JB
5947 memset(settings, 0, sizeof(*settings));
5948
b23aa676
SO
5949 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
5950
c0692b8f
JB
5951 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
5952 u16 proto;
5953 proto = nla_get_u16(
5954 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
5955 settings->control_port_ethertype = cpu_to_be16(proto);
5956 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
5957 proto != ETH_P_PAE)
5958 return -EINVAL;
5959 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
5960 settings->control_port_no_encrypt = true;
5961 } else
5962 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
5963
b23aa676
SO
5964 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
5965 void *data;
5966 int len, i;
5967
5968 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5969 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5970 settings->n_ciphers_pairwise = len / sizeof(u32);
5971
5972 if (len % sizeof(u32))
5973 return -EINVAL;
5974
3dc27d25 5975 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
5976 return -EINVAL;
5977
5978 memcpy(settings->ciphers_pairwise, data, len);
5979
5980 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
5981 if (!cfg80211_supported_cipher_suite(
5982 &rdev->wiphy,
b23aa676
SO
5983 settings->ciphers_pairwise[i]))
5984 return -EINVAL;
5985 }
5986
5987 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
5988 settings->cipher_group =
5989 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
5990 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
5991 settings->cipher_group))
b23aa676
SO
5992 return -EINVAL;
5993 }
5994
5995 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
5996 settings->wpa_versions =
5997 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
5998 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
5999 return -EINVAL;
6000 }
6001
6002 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
6003 void *data;
6d30240e 6004 int len;
b23aa676
SO
6005
6006 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
6007 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
6008 settings->n_akm_suites = len / sizeof(u32);
6009
6010 if (len % sizeof(u32))
6011 return -EINVAL;
6012
1b9ca027
JM
6013 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
6014 return -EINVAL;
6015
b23aa676 6016 memcpy(settings->akm_suites, data, len);
b23aa676
SO
6017 }
6018
6019 return 0;
6020}
6021
636a5d36
JM
6022static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
6023{
4c476991
JB
6024 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6025 struct net_device *dev = info->user_ptr[1];
f444de05 6026 struct ieee80211_channel *chan;
f62fab73
JB
6027 struct cfg80211_assoc_request req = {};
6028 const u8 *bssid, *ssid;
6029 int err, ssid_len = 0;
636a5d36 6030
f4a11bb0
JB
6031 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6032 return -EINVAL;
6033
6034 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
6035 !info->attrs[NL80211_ATTR_SSID] ||
6036 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
6037 return -EINVAL;
6038
4c476991
JB
6039 if (!rdev->ops->assoc)
6040 return -EOPNOTSUPP;
636a5d36 6041
074ac8df 6042 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6043 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6044 return -EOPNOTSUPP;
eec60b03 6045
19957bb3 6046 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6047
19957bb3
JB
6048 chan = ieee80211_get_channel(&rdev->wiphy,
6049 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
6050 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
6051 return -EINVAL;
636a5d36 6052
19957bb3
JB
6053 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6054 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
6055
6056 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
6057 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6058 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6059 }
6060
dc6382ce 6061 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 6062 enum nl80211_mfp mfp =
dc6382ce 6063 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 6064 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 6065 req.use_mfp = true;
4c476991
JB
6066 else if (mfp != NL80211_MFP_NO)
6067 return -EINVAL;
dc6382ce
JM
6068 }
6069
3e5d7649 6070 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 6071 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 6072
7e7c8926 6073 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 6074 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
6075
6076 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
6077 memcpy(&req.ht_capa_mask,
6078 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6079 sizeof(req.ht_capa_mask));
7e7c8926
BG
6080
6081 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 6082 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 6083 return -EINVAL;
f62fab73
JB
6084 memcpy(&req.ht_capa,
6085 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6086 sizeof(req.ht_capa));
7e7c8926
BG
6087 }
6088
ee2aca34 6089 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 6090 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
6091
6092 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
6093 memcpy(&req.vht_capa_mask,
6094 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
6095 sizeof(req.vht_capa_mask));
ee2aca34
JB
6096
6097 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 6098 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 6099 return -EINVAL;
f62fab73
JB
6100 memcpy(&req.vht_capa,
6101 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
6102 sizeof(req.vht_capa));
ee2aca34
JB
6103 }
6104
f62fab73 6105 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
6106 if (!err) {
6107 wdev_lock(dev->ieee80211_ptr);
f62fab73
JB
6108 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
6109 ssid, ssid_len, &req);
91bf9b26
JB
6110 wdev_unlock(dev->ieee80211_ptr);
6111 }
636a5d36 6112
636a5d36
JM
6113 return err;
6114}
6115
6116static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
6117{
4c476991
JB
6118 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6119 struct net_device *dev = info->user_ptr[1];
19957bb3 6120 const u8 *ie = NULL, *bssid;
91bf9b26 6121 int ie_len = 0, err;
19957bb3 6122 u16 reason_code;
d5cdfacb 6123 bool local_state_change;
636a5d36 6124
f4a11bb0
JB
6125 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6126 return -EINVAL;
6127
6128 if (!info->attrs[NL80211_ATTR_MAC])
6129 return -EINVAL;
6130
6131 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6132 return -EINVAL;
6133
4c476991
JB
6134 if (!rdev->ops->deauth)
6135 return -EOPNOTSUPP;
636a5d36 6136
074ac8df 6137 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6138 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6139 return -EOPNOTSUPP;
eec60b03 6140
19957bb3 6141 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6142
19957bb3
JB
6143 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6144 if (reason_code == 0) {
f4a11bb0 6145 /* Reason Code 0 is reserved */
4c476991 6146 return -EINVAL;
255e737e 6147 }
636a5d36
JM
6148
6149 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6150 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6151 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6152 }
6153
d5cdfacb
JM
6154 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6155
91bf9b26
JB
6156 wdev_lock(dev->ieee80211_ptr);
6157 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
6158 local_state_change);
6159 wdev_unlock(dev->ieee80211_ptr);
6160 return err;
636a5d36
JM
6161}
6162
6163static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
6164{
4c476991
JB
6165 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6166 struct net_device *dev = info->user_ptr[1];
19957bb3 6167 const u8 *ie = NULL, *bssid;
91bf9b26 6168 int ie_len = 0, err;
19957bb3 6169 u16 reason_code;
d5cdfacb 6170 bool local_state_change;
636a5d36 6171
f4a11bb0
JB
6172 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6173 return -EINVAL;
6174
6175 if (!info->attrs[NL80211_ATTR_MAC])
6176 return -EINVAL;
6177
6178 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6179 return -EINVAL;
6180
4c476991
JB
6181 if (!rdev->ops->disassoc)
6182 return -EOPNOTSUPP;
636a5d36 6183
074ac8df 6184 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6185 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6186 return -EOPNOTSUPP;
eec60b03 6187
19957bb3 6188 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6189
19957bb3
JB
6190 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6191 if (reason_code == 0) {
f4a11bb0 6192 /* Reason Code 0 is reserved */
4c476991 6193 return -EINVAL;
255e737e 6194 }
636a5d36
JM
6195
6196 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6197 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6198 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6199 }
6200
d5cdfacb
JM
6201 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6202
91bf9b26
JB
6203 wdev_lock(dev->ieee80211_ptr);
6204 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
6205 local_state_change);
6206 wdev_unlock(dev->ieee80211_ptr);
6207 return err;
636a5d36
JM
6208}
6209
dd5b4cc7
FF
6210static bool
6211nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
6212 int mcast_rate[IEEE80211_NUM_BANDS],
6213 int rateval)
6214{
6215 struct wiphy *wiphy = &rdev->wiphy;
6216 bool found = false;
6217 int band, i;
6218
6219 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
6220 struct ieee80211_supported_band *sband;
6221
6222 sband = wiphy->bands[band];
6223 if (!sband)
6224 continue;
6225
6226 for (i = 0; i < sband->n_bitrates; i++) {
6227 if (sband->bitrates[i].bitrate == rateval) {
6228 mcast_rate[band] = i + 1;
6229 found = true;
6230 break;
6231 }
6232 }
6233 }
6234
6235 return found;
6236}
6237
04a773ad
JB
6238static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
6239{
4c476991
JB
6240 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6241 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
6242 struct cfg80211_ibss_params ibss;
6243 struct wiphy *wiphy;
fffd0934 6244 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
6245 int err;
6246
8e30bc55
JB
6247 memset(&ibss, 0, sizeof(ibss));
6248
04a773ad
JB
6249 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6250 return -EINVAL;
6251
683b6d3b 6252 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
6253 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6254 return -EINVAL;
6255
8e30bc55
JB
6256 ibss.beacon_interval = 100;
6257
6258 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6259 ibss.beacon_interval =
6260 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6261 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
6262 return -EINVAL;
6263 }
6264
4c476991
JB
6265 if (!rdev->ops->join_ibss)
6266 return -EOPNOTSUPP;
04a773ad 6267
4c476991
JB
6268 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
6269 return -EOPNOTSUPP;
04a773ad 6270
79c97e97 6271 wiphy = &rdev->wiphy;
04a773ad 6272
39193498 6273 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 6274 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
6275
6276 if (!is_valid_ether_addr(ibss.bssid))
6277 return -EINVAL;
6278 }
04a773ad
JB
6279 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6280 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6281
6282 if (info->attrs[NL80211_ATTR_IE]) {
6283 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6284 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6285 }
6286
683b6d3b
JB
6287 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
6288 if (err)
6289 return err;
04a773ad 6290
683b6d3b 6291 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
6292 return -EINVAL;
6293
db9c64cf
JB
6294 if (ibss.chandef.width > NL80211_CHAN_WIDTH_40)
6295 return -EINVAL;
6296 if (ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
6297 !(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
c04d6150 6298 return -EINVAL;
db9c64cf 6299
04a773ad 6300 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
6301 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
6302
fbd2c8dc
TP
6303 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
6304 u8 *rates =
6305 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6306 int n_rates =
6307 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6308 struct ieee80211_supported_band *sband =
683b6d3b 6309 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 6310
34850ab2
JB
6311 err = ieee80211_get_ratemask(sband, rates, n_rates,
6312 &ibss.basic_rates);
6313 if (err)
6314 return err;
fbd2c8dc 6315 }
dd5b4cc7
FF
6316
6317 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6318 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
6319 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6320 return -EINVAL;
fbd2c8dc 6321
4c476991 6322 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
6323 bool no_ht = false;
6324
4c476991 6325 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
6326 info->attrs[NL80211_ATTR_KEYS],
6327 &no_ht);
4c476991
JB
6328 if (IS_ERR(connkeys))
6329 return PTR_ERR(connkeys);
de7044ee 6330
3d9d1d66
JB
6331 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
6332 no_ht) {
de7044ee
SM
6333 kfree(connkeys);
6334 return -EINVAL;
6335 }
4c476991 6336 }
04a773ad 6337
267335d6
AQ
6338 ibss.control_port =
6339 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
6340
4c476991 6341 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
6342 if (err)
6343 kfree(connkeys);
04a773ad
JB
6344 return err;
6345}
6346
6347static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
6348{
4c476991
JB
6349 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6350 struct net_device *dev = info->user_ptr[1];
04a773ad 6351
4c476991
JB
6352 if (!rdev->ops->leave_ibss)
6353 return -EOPNOTSUPP;
04a773ad 6354
4c476991
JB
6355 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
6356 return -EOPNOTSUPP;
04a773ad 6357
4c476991 6358 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
6359}
6360
f4e583c8
AQ
6361static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
6362{
6363 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6364 struct net_device *dev = info->user_ptr[1];
6365 int mcast_rate[IEEE80211_NUM_BANDS];
6366 u32 nla_rate;
6367 int err;
6368
6369 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
6370 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6371 return -EOPNOTSUPP;
6372
6373 if (!rdev->ops->set_mcast_rate)
6374 return -EOPNOTSUPP;
6375
6376 memset(mcast_rate, 0, sizeof(mcast_rate));
6377
6378 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
6379 return -EINVAL;
6380
6381 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
6382 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
6383 return -EINVAL;
6384
6385 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
6386
6387 return err;
6388}
6389
6390
aff89a9b
JB
6391#ifdef CONFIG_NL80211_TESTMODE
6392static struct genl_multicast_group nl80211_testmode_mcgrp = {
6393 .name = "testmode",
6394};
6395
6396static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
6397{
4c476991 6398 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
6399 int err;
6400
6401 if (!info->attrs[NL80211_ATTR_TESTDATA])
6402 return -EINVAL;
6403
aff89a9b
JB
6404 err = -EOPNOTSUPP;
6405 if (rdev->ops->testmode_cmd) {
6406 rdev->testmode_info = info;
e35e4d28 6407 err = rdev_testmode_cmd(rdev,
aff89a9b
JB
6408 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
6409 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
6410 rdev->testmode_info = NULL;
6411 }
6412
aff89a9b
JB
6413 return err;
6414}
6415
71063f0e
WYG
6416static int nl80211_testmode_dump(struct sk_buff *skb,
6417 struct netlink_callback *cb)
6418{
00918d33 6419 struct cfg80211_registered_device *rdev;
71063f0e
WYG
6420 int err;
6421 long phy_idx;
6422 void *data = NULL;
6423 int data_len = 0;
6424
5fe231e8
JB
6425 rtnl_lock();
6426
71063f0e
WYG
6427 if (cb->args[0]) {
6428 /*
6429 * 0 is a valid index, but not valid for args[0],
6430 * so we need to offset by 1.
6431 */
6432 phy_idx = cb->args[0] - 1;
6433 } else {
6434 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
6435 nl80211_fam.attrbuf, nl80211_fam.maxattr,
6436 nl80211_policy);
6437 if (err)
5fe231e8 6438 goto out_err;
00918d33 6439
2bd7e35d
JB
6440 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
6441 nl80211_fam.attrbuf);
6442 if (IS_ERR(rdev)) {
5fe231e8
JB
6443 err = PTR_ERR(rdev);
6444 goto out_err;
00918d33 6445 }
2bd7e35d
JB
6446 phy_idx = rdev->wiphy_idx;
6447 rdev = NULL;
2bd7e35d 6448
71063f0e
WYG
6449 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
6450 cb->args[1] =
6451 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
6452 }
6453
6454 if (cb->args[1]) {
6455 data = nla_data((void *)cb->args[1]);
6456 data_len = nla_len((void *)cb->args[1]);
6457 }
6458
00918d33
JB
6459 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
6460 if (!rdev) {
5fe231e8
JB
6461 err = -ENOENT;
6462 goto out_err;
71063f0e 6463 }
71063f0e 6464
00918d33 6465 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
6466 err = -EOPNOTSUPP;
6467 goto out_err;
6468 }
6469
6470 while (1) {
15e47304 6471 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
6472 cb->nlh->nlmsg_seq, NLM_F_MULTI,
6473 NL80211_CMD_TESTMODE);
6474 struct nlattr *tmdata;
6475
9360ffd1 6476 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
6477 genlmsg_cancel(skb, hdr);
6478 break;
6479 }
6480
6481 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
6482 if (!tmdata) {
6483 genlmsg_cancel(skb, hdr);
6484 break;
6485 }
e35e4d28 6486 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
6487 nla_nest_end(skb, tmdata);
6488
6489 if (err == -ENOBUFS || err == -ENOENT) {
6490 genlmsg_cancel(skb, hdr);
6491 break;
6492 } else if (err) {
6493 genlmsg_cancel(skb, hdr);
6494 goto out_err;
6495 }
6496
6497 genlmsg_end(skb, hdr);
6498 }
6499
6500 err = skb->len;
6501 /* see above */
6502 cb->args[0] = phy_idx + 1;
6503 out_err:
5fe231e8 6504 rtnl_unlock();
71063f0e
WYG
6505 return err;
6506}
6507
aff89a9b
JB
6508static struct sk_buff *
6509__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 6510 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
6511{
6512 struct sk_buff *skb;
6513 void *hdr;
6514 struct nlattr *data;
6515
6516 skb = nlmsg_new(approxlen + 100, gfp);
6517 if (!skb)
6518 return NULL;
6519
15e47304 6520 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
6521 if (!hdr) {
6522 kfree_skb(skb);
6523 return NULL;
6524 }
6525
9360ffd1
DM
6526 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
6527 goto nla_put_failure;
aff89a9b
JB
6528 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
6529
6530 ((void **)skb->cb)[0] = rdev;
6531 ((void **)skb->cb)[1] = hdr;
6532 ((void **)skb->cb)[2] = data;
6533
6534 return skb;
6535
6536 nla_put_failure:
6537 kfree_skb(skb);
6538 return NULL;
6539}
6540
6541struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
6542 int approxlen)
6543{
6544 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6545
6546 if (WARN_ON(!rdev->testmode_info))
6547 return NULL;
6548
6549 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 6550 rdev->testmode_info->snd_portid,
aff89a9b
JB
6551 rdev->testmode_info->snd_seq,
6552 GFP_KERNEL);
6553}
6554EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
6555
6556int cfg80211_testmode_reply(struct sk_buff *skb)
6557{
6558 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
6559 void *hdr = ((void **)skb->cb)[1];
6560 struct nlattr *data = ((void **)skb->cb)[2];
6561
6562 if (WARN_ON(!rdev->testmode_info)) {
6563 kfree_skb(skb);
6564 return -EINVAL;
6565 }
6566
6567 nla_nest_end(skb, data);
6568 genlmsg_end(skb, hdr);
6569 return genlmsg_reply(skb, rdev->testmode_info);
6570}
6571EXPORT_SYMBOL(cfg80211_testmode_reply);
6572
6573struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
6574 int approxlen, gfp_t gfp)
6575{
6576 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6577
6578 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
6579}
6580EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
6581
6582void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
6583{
6584 void *hdr = ((void **)skb->cb)[1];
6585 struct nlattr *data = ((void **)skb->cb)[2];
6586
6587 nla_nest_end(skb, data);
6588 genlmsg_end(skb, hdr);
6589 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
6590}
6591EXPORT_SYMBOL(cfg80211_testmode_event);
6592#endif
6593
b23aa676
SO
6594static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
6595{
4c476991
JB
6596 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6597 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6598 struct cfg80211_connect_params connect;
6599 struct wiphy *wiphy;
fffd0934 6600 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
6601 int err;
6602
6603 memset(&connect, 0, sizeof(connect));
6604
6605 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6606 return -EINVAL;
6607
6608 if (!info->attrs[NL80211_ATTR_SSID] ||
6609 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6610 return -EINVAL;
6611
6612 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6613 connect.auth_type =
6614 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
6615 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
6616 NL80211_CMD_CONNECT))
b23aa676
SO
6617 return -EINVAL;
6618 } else
6619 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6620
6621 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
6622
c0692b8f 6623 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 6624 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
6625 if (err)
6626 return err;
b23aa676 6627
074ac8df 6628 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6629 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6630 return -EOPNOTSUPP;
b23aa676 6631
79c97e97 6632 wiphy = &rdev->wiphy;
b23aa676 6633
4486ea98
BS
6634 connect.bg_scan_period = -1;
6635 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
6636 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
6637 connect.bg_scan_period =
6638 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
6639 }
6640
b23aa676
SO
6641 if (info->attrs[NL80211_ATTR_MAC])
6642 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6643 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6644 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6645
6646 if (info->attrs[NL80211_ATTR_IE]) {
6647 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6648 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6649 }
6650
cee00a95
JM
6651 if (info->attrs[NL80211_ATTR_USE_MFP]) {
6652 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
6653 if (connect.mfp != NL80211_MFP_REQUIRED &&
6654 connect.mfp != NL80211_MFP_NO)
6655 return -EINVAL;
6656 } else {
6657 connect.mfp = NL80211_MFP_NO;
6658 }
6659
b23aa676
SO
6660 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6661 connect.channel =
6662 ieee80211_get_channel(wiphy,
6663 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
6664 if (!connect.channel ||
4c476991
JB
6665 connect.channel->flags & IEEE80211_CHAN_DISABLED)
6666 return -EINVAL;
b23aa676
SO
6667 }
6668
fffd0934
JB
6669 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
6670 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 6671 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
6672 if (IS_ERR(connkeys))
6673 return PTR_ERR(connkeys);
fffd0934
JB
6674 }
6675
7e7c8926
BG
6676 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
6677 connect.flags |= ASSOC_REQ_DISABLE_HT;
6678
6679 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6680 memcpy(&connect.ht_capa_mask,
6681 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6682 sizeof(connect.ht_capa_mask));
6683
6684 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
6685 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
6686 kfree(connkeys);
7e7c8926 6687 return -EINVAL;
b4e4f47e 6688 }
7e7c8926
BG
6689 memcpy(&connect.ht_capa,
6690 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6691 sizeof(connect.ht_capa));
6692 }
6693
ee2aca34
JB
6694 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
6695 connect.flags |= ASSOC_REQ_DISABLE_VHT;
6696
6697 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
6698 memcpy(&connect.vht_capa_mask,
6699 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
6700 sizeof(connect.vht_capa_mask));
6701
6702 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
6703 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
6704 kfree(connkeys);
6705 return -EINVAL;
6706 }
6707 memcpy(&connect.vht_capa,
6708 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
6709 sizeof(connect.vht_capa));
6710 }
6711
83739b03
JB
6712 wdev_lock(dev->ieee80211_ptr);
6713 err = cfg80211_connect(rdev, dev, &connect, connkeys, NULL);
6714 wdev_unlock(dev->ieee80211_ptr);
fffd0934
JB
6715 if (err)
6716 kfree(connkeys);
b23aa676
SO
6717 return err;
6718}
6719
6720static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
6721{
4c476991
JB
6722 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6723 struct net_device *dev = info->user_ptr[1];
b23aa676 6724 u16 reason;
83739b03 6725 int ret;
b23aa676
SO
6726
6727 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6728 reason = WLAN_REASON_DEAUTH_LEAVING;
6729 else
6730 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6731
6732 if (reason == 0)
6733 return -EINVAL;
6734
074ac8df 6735 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6736 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6737 return -EOPNOTSUPP;
b23aa676 6738
83739b03
JB
6739 wdev_lock(dev->ieee80211_ptr);
6740 ret = cfg80211_disconnect(rdev, dev, reason, true);
6741 wdev_unlock(dev->ieee80211_ptr);
6742 return ret;
b23aa676
SO
6743}
6744
463d0183
JB
6745static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
6746{
4c476991 6747 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
6748 struct net *net;
6749 int err;
6750 u32 pid;
6751
6752 if (!info->attrs[NL80211_ATTR_PID])
6753 return -EINVAL;
6754
6755 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
6756
463d0183 6757 net = get_net_ns_by_pid(pid);
4c476991
JB
6758 if (IS_ERR(net))
6759 return PTR_ERR(net);
463d0183
JB
6760
6761 err = 0;
6762
6763 /* check if anything to do */
4c476991
JB
6764 if (!net_eq(wiphy_net(&rdev->wiphy), net))
6765 err = cfg80211_switch_netns(rdev, net);
463d0183 6766
463d0183 6767 put_net(net);
463d0183
JB
6768 return err;
6769}
6770
67fbb16b
SO
6771static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
6772{
4c476991 6773 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
6774 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
6775 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 6776 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
6777 struct cfg80211_pmksa pmksa;
6778
6779 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
6780
6781 if (!info->attrs[NL80211_ATTR_MAC])
6782 return -EINVAL;
6783
6784 if (!info->attrs[NL80211_ATTR_PMKID])
6785 return -EINVAL;
6786
67fbb16b
SO
6787 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
6788 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6789
074ac8df 6790 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6791 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6792 return -EOPNOTSUPP;
67fbb16b
SO
6793
6794 switch (info->genlhdr->cmd) {
6795 case NL80211_CMD_SET_PMKSA:
6796 rdev_ops = rdev->ops->set_pmksa;
6797 break;
6798 case NL80211_CMD_DEL_PMKSA:
6799 rdev_ops = rdev->ops->del_pmksa;
6800 break;
6801 default:
6802 WARN_ON(1);
6803 break;
6804 }
6805
4c476991
JB
6806 if (!rdev_ops)
6807 return -EOPNOTSUPP;
67fbb16b 6808
4c476991 6809 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
6810}
6811
6812static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
6813{
4c476991
JB
6814 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6815 struct net_device *dev = info->user_ptr[1];
67fbb16b 6816
074ac8df 6817 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6818 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6819 return -EOPNOTSUPP;
67fbb16b 6820
4c476991
JB
6821 if (!rdev->ops->flush_pmksa)
6822 return -EOPNOTSUPP;
67fbb16b 6823
e35e4d28 6824 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
6825}
6826
109086ce
AN
6827static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
6828{
6829 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6830 struct net_device *dev = info->user_ptr[1];
6831 u8 action_code, dialog_token;
6832 u16 status_code;
6833 u8 *peer;
6834
6835 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6836 !rdev->ops->tdls_mgmt)
6837 return -EOPNOTSUPP;
6838
6839 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
6840 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
6841 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
6842 !info->attrs[NL80211_ATTR_IE] ||
6843 !info->attrs[NL80211_ATTR_MAC])
6844 return -EINVAL;
6845
6846 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6847 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
6848 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
6849 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
6850
e35e4d28
HG
6851 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
6852 dialog_token, status_code,
6853 nla_data(info->attrs[NL80211_ATTR_IE]),
6854 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
6855}
6856
6857static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
6858{
6859 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6860 struct net_device *dev = info->user_ptr[1];
6861 enum nl80211_tdls_operation operation;
6862 u8 *peer;
6863
6864 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6865 !rdev->ops->tdls_oper)
6866 return -EOPNOTSUPP;
6867
6868 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
6869 !info->attrs[NL80211_ATTR_MAC])
6870 return -EINVAL;
6871
6872 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
6873 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6874
e35e4d28 6875 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
6876}
6877
9588bbd5
JM
6878static int nl80211_remain_on_channel(struct sk_buff *skb,
6879 struct genl_info *info)
6880{
4c476991 6881 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6882 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6883 struct cfg80211_chan_def chandef;
9588bbd5
JM
6884 struct sk_buff *msg;
6885 void *hdr;
6886 u64 cookie;
683b6d3b 6887 u32 duration;
9588bbd5
JM
6888 int err;
6889
6890 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6891 !info->attrs[NL80211_ATTR_DURATION])
6892 return -EINVAL;
6893
6894 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
6895
ebf348fc
JB
6896 if (!rdev->ops->remain_on_channel ||
6897 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
6898 return -EOPNOTSUPP;
6899
9588bbd5 6900 /*
ebf348fc
JB
6901 * We should be on that channel for at least a minimum amount of
6902 * time (10ms) but no longer than the driver supports.
9588bbd5 6903 */
ebf348fc 6904 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 6905 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
6906 return -EINVAL;
6907
683b6d3b
JB
6908 err = nl80211_parse_chandef(rdev, info, &chandef);
6909 if (err)
6910 return err;
9588bbd5
JM
6911
6912 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6913 if (!msg)
6914 return -ENOMEM;
9588bbd5 6915
15e47304 6916 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5
JM
6917 NL80211_CMD_REMAIN_ON_CHANNEL);
6918
6919 if (IS_ERR(hdr)) {
6920 err = PTR_ERR(hdr);
6921 goto free_msg;
6922 }
6923
683b6d3b
JB
6924 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
6925 duration, &cookie);
9588bbd5
JM
6926
6927 if (err)
6928 goto free_msg;
6929
9360ffd1
DM
6930 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6931 goto nla_put_failure;
9588bbd5
JM
6932
6933 genlmsg_end(msg, hdr);
4c476991
JB
6934
6935 return genlmsg_reply(msg, info);
9588bbd5
JM
6936
6937 nla_put_failure:
6938 err = -ENOBUFS;
6939 free_msg:
6940 nlmsg_free(msg);
9588bbd5
JM
6941 return err;
6942}
6943
6944static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
6945 struct genl_info *info)
6946{
4c476991 6947 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6948 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 6949 u64 cookie;
9588bbd5
JM
6950
6951 if (!info->attrs[NL80211_ATTR_COOKIE])
6952 return -EINVAL;
6953
4c476991
JB
6954 if (!rdev->ops->cancel_remain_on_channel)
6955 return -EOPNOTSUPP;
9588bbd5 6956
9588bbd5
JM
6957 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6958
e35e4d28 6959 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
6960}
6961
13ae75b1
JM
6962static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
6963 u8 *rates, u8 rates_len)
6964{
6965 u8 i;
6966 u32 mask = 0;
6967
6968 for (i = 0; i < rates_len; i++) {
6969 int rate = (rates[i] & 0x7f) * 5;
6970 int ridx;
6971 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
6972 struct ieee80211_rate *srate =
6973 &sband->bitrates[ridx];
6974 if (rate == srate->bitrate) {
6975 mask |= 1 << ridx;
6976 break;
6977 }
6978 }
6979 if (ridx == sband->n_bitrates)
6980 return 0; /* rate not found */
6981 }
6982
6983 return mask;
6984}
6985
24db78c0
SW
6986static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
6987 u8 *rates, u8 rates_len,
6988 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
6989{
6990 u8 i;
6991
6992 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
6993
6994 for (i = 0; i < rates_len; i++) {
6995 int ridx, rbit;
6996
6997 ridx = rates[i] / 8;
6998 rbit = BIT(rates[i] % 8);
6999
7000 /* check validity */
910570b5 7001 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
7002 return false;
7003
7004 /* check availability */
7005 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
7006 mcs[ridx] |= rbit;
7007 else
7008 return false;
7009 }
7010
7011 return true;
7012}
7013
b54452b0 7014static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
7015 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
7016 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
7017 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
7018 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
7019};
7020
7021static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
7022 struct genl_info *info)
7023{
7024 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 7025 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 7026 struct cfg80211_bitrate_mask mask;
4c476991
JB
7027 int rem, i;
7028 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
7029 struct nlattr *tx_rates;
7030 struct ieee80211_supported_band *sband;
7031
7032 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
7033 return -EINVAL;
7034
4c476991
JB
7035 if (!rdev->ops->set_bitrate_mask)
7036 return -EOPNOTSUPP;
13ae75b1
JM
7037
7038 memset(&mask, 0, sizeof(mask));
7039 /* Default to all rates enabled */
7040 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
7041 sband = rdev->wiphy.bands[i];
7042 mask.control[i].legacy =
7043 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
7044 if (sband)
7045 memcpy(mask.control[i].mcs,
7046 sband->ht_cap.mcs.rx_mask,
7047 sizeof(mask.control[i].mcs));
7048 else
7049 memset(mask.control[i].mcs, 0,
7050 sizeof(mask.control[i].mcs));
13ae75b1
JM
7051 }
7052
7053 /*
7054 * The nested attribute uses enum nl80211_band as the index. This maps
7055 * directly to the enum ieee80211_band values used in cfg80211.
7056 */
24db78c0 7057 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
7058 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
7059 {
7060 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
7061 if (band < 0 || band >= IEEE80211_NUM_BANDS)
7062 return -EINVAL;
13ae75b1 7063 sband = rdev->wiphy.bands[band];
4c476991
JB
7064 if (sband == NULL)
7065 return -EINVAL;
13ae75b1
JM
7066 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
7067 nla_len(tx_rates), nl80211_txattr_policy);
7068 if (tb[NL80211_TXRATE_LEGACY]) {
7069 mask.control[band].legacy = rateset_to_mask(
7070 sband,
7071 nla_data(tb[NL80211_TXRATE_LEGACY]),
7072 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
7073 if ((mask.control[band].legacy == 0) &&
7074 nla_len(tb[NL80211_TXRATE_LEGACY]))
7075 return -EINVAL;
24db78c0
SW
7076 }
7077 if (tb[NL80211_TXRATE_MCS]) {
7078 if (!ht_rateset_to_mask(
7079 sband,
7080 nla_data(tb[NL80211_TXRATE_MCS]),
7081 nla_len(tb[NL80211_TXRATE_MCS]),
7082 mask.control[band].mcs))
7083 return -EINVAL;
7084 }
7085
7086 if (mask.control[band].legacy == 0) {
7087 /* don't allow empty legacy rates if HT
7088 * is not even supported. */
7089 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
7090 return -EINVAL;
7091
7092 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
7093 if (mask.control[band].mcs[i])
7094 break;
7095
7096 /* legacy and mcs rates may not be both empty */
7097 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 7098 return -EINVAL;
13ae75b1
JM
7099 }
7100 }
7101
e35e4d28 7102 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
7103}
7104
2e161f78 7105static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 7106{
4c476991 7107 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7108 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 7109 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
7110
7111 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
7112 return -EINVAL;
7113
2e161f78
JB
7114 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
7115 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 7116
71bbc994
JB
7117 switch (wdev->iftype) {
7118 case NL80211_IFTYPE_STATION:
7119 case NL80211_IFTYPE_ADHOC:
7120 case NL80211_IFTYPE_P2P_CLIENT:
7121 case NL80211_IFTYPE_AP:
7122 case NL80211_IFTYPE_AP_VLAN:
7123 case NL80211_IFTYPE_MESH_POINT:
7124 case NL80211_IFTYPE_P2P_GO:
98104fde 7125 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
7126 break;
7127 default:
4c476991 7128 return -EOPNOTSUPP;
71bbc994 7129 }
026331c4
JM
7130
7131 /* not much point in registering if we can't reply */
4c476991
JB
7132 if (!rdev->ops->mgmt_tx)
7133 return -EOPNOTSUPP;
026331c4 7134
15e47304 7135 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
7136 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
7137 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
7138}
7139
2e161f78 7140static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 7141{
4c476991 7142 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7143 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 7144 struct cfg80211_chan_def chandef;
026331c4 7145 int err;
d64d373f 7146 void *hdr = NULL;
026331c4 7147 u64 cookie;
e247bd90 7148 struct sk_buff *msg = NULL;
f7ca38df 7149 unsigned int wait = 0;
e247bd90
JB
7150 bool offchan, no_cck, dont_wait_for_ack;
7151
7152 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 7153
683b6d3b 7154 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
7155 return -EINVAL;
7156
4c476991
JB
7157 if (!rdev->ops->mgmt_tx)
7158 return -EOPNOTSUPP;
026331c4 7159
71bbc994 7160 switch (wdev->iftype) {
ea141b75
AQ
7161 case NL80211_IFTYPE_P2P_DEVICE:
7162 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
7163 return -EINVAL;
71bbc994
JB
7164 case NL80211_IFTYPE_STATION:
7165 case NL80211_IFTYPE_ADHOC:
7166 case NL80211_IFTYPE_P2P_CLIENT:
7167 case NL80211_IFTYPE_AP:
7168 case NL80211_IFTYPE_AP_VLAN:
7169 case NL80211_IFTYPE_MESH_POINT:
7170 case NL80211_IFTYPE_P2P_GO:
7171 break;
7172 default:
4c476991 7173 return -EOPNOTSUPP;
71bbc994 7174 }
026331c4 7175
f7ca38df 7176 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 7177 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
7178 return -EINVAL;
7179 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
7180
7181 /*
7182 * We should wait on the channel for at least a minimum amount
7183 * of time (10ms) but no longer than the driver supports.
7184 */
7185 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
7186 wait > rdev->wiphy.max_remain_on_channel_duration)
7187 return -EINVAL;
7188
f7ca38df
JB
7189 }
7190
f7ca38df
JB
7191 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
7192
7c4ef712
JB
7193 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7194 return -EINVAL;
7195
e9f935e3
RM
7196 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
7197
ea141b75
AQ
7198 /* get the channel if any has been specified, otherwise pass NULL to
7199 * the driver. The latter will use the current one
7200 */
7201 chandef.chan = NULL;
7202 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
7203 err = nl80211_parse_chandef(rdev, info, &chandef);
7204 if (err)
7205 return err;
7206 }
7207
7208 if (!chandef.chan && offchan)
7209 return -EINVAL;
026331c4 7210
e247bd90
JB
7211 if (!dont_wait_for_ack) {
7212 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7213 if (!msg)
7214 return -ENOMEM;
026331c4 7215
15e47304 7216 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 7217 NL80211_CMD_FRAME);
026331c4 7218
e247bd90
JB
7219 if (IS_ERR(hdr)) {
7220 err = PTR_ERR(hdr);
7221 goto free_msg;
7222 }
026331c4 7223 }
e247bd90 7224
683b6d3b 7225 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
7226 nla_data(info->attrs[NL80211_ATTR_FRAME]),
7227 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 7228 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
7229 if (err)
7230 goto free_msg;
7231
e247bd90 7232 if (msg) {
9360ffd1
DM
7233 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7234 goto nla_put_failure;
026331c4 7235
e247bd90
JB
7236 genlmsg_end(msg, hdr);
7237 return genlmsg_reply(msg, info);
7238 }
7239
7240 return 0;
026331c4
JM
7241
7242 nla_put_failure:
7243 err = -ENOBUFS;
7244 free_msg:
7245 nlmsg_free(msg);
026331c4
JM
7246 return err;
7247}
7248
f7ca38df
JB
7249static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
7250{
7251 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7252 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
7253 u64 cookie;
7254
7255 if (!info->attrs[NL80211_ATTR_COOKIE])
7256 return -EINVAL;
7257
7258 if (!rdev->ops->mgmt_tx_cancel_wait)
7259 return -EOPNOTSUPP;
7260
71bbc994
JB
7261 switch (wdev->iftype) {
7262 case NL80211_IFTYPE_STATION:
7263 case NL80211_IFTYPE_ADHOC:
7264 case NL80211_IFTYPE_P2P_CLIENT:
7265 case NL80211_IFTYPE_AP:
7266 case NL80211_IFTYPE_AP_VLAN:
7267 case NL80211_IFTYPE_P2P_GO:
98104fde 7268 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
7269 break;
7270 default:
f7ca38df 7271 return -EOPNOTSUPP;
71bbc994 7272 }
f7ca38df
JB
7273
7274 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
7275
e35e4d28 7276 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
7277}
7278
ffb9eb3d
KV
7279static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
7280{
4c476991 7281 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 7282 struct wireless_dev *wdev;
4c476991 7283 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
7284 u8 ps_state;
7285 bool state;
7286 int err;
7287
4c476991
JB
7288 if (!info->attrs[NL80211_ATTR_PS_STATE])
7289 return -EINVAL;
ffb9eb3d
KV
7290
7291 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
7292
4c476991
JB
7293 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
7294 return -EINVAL;
ffb9eb3d
KV
7295
7296 wdev = dev->ieee80211_ptr;
7297
4c476991
JB
7298 if (!rdev->ops->set_power_mgmt)
7299 return -EOPNOTSUPP;
ffb9eb3d
KV
7300
7301 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
7302
7303 if (state == wdev->ps)
4c476991 7304 return 0;
ffb9eb3d 7305
e35e4d28 7306 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
7307 if (!err)
7308 wdev->ps = state;
ffb9eb3d
KV
7309 return err;
7310}
7311
7312static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
7313{
4c476991 7314 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
7315 enum nl80211_ps_state ps_state;
7316 struct wireless_dev *wdev;
4c476991 7317 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
7318 struct sk_buff *msg;
7319 void *hdr;
7320 int err;
7321
ffb9eb3d
KV
7322 wdev = dev->ieee80211_ptr;
7323
4c476991
JB
7324 if (!rdev->ops->set_power_mgmt)
7325 return -EOPNOTSUPP;
ffb9eb3d
KV
7326
7327 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
7328 if (!msg)
7329 return -ENOMEM;
ffb9eb3d 7330
15e47304 7331 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
7332 NL80211_CMD_GET_POWER_SAVE);
7333 if (!hdr) {
4c476991 7334 err = -ENOBUFS;
ffb9eb3d
KV
7335 goto free_msg;
7336 }
7337
7338 if (wdev->ps)
7339 ps_state = NL80211_PS_ENABLED;
7340 else
7341 ps_state = NL80211_PS_DISABLED;
7342
9360ffd1
DM
7343 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
7344 goto nla_put_failure;
ffb9eb3d
KV
7345
7346 genlmsg_end(msg, hdr);
4c476991 7347 return genlmsg_reply(msg, info);
ffb9eb3d 7348
4c476991 7349 nla_put_failure:
ffb9eb3d 7350 err = -ENOBUFS;
4c476991 7351 free_msg:
ffb9eb3d 7352 nlmsg_free(msg);
ffb9eb3d
KV
7353 return err;
7354}
7355
d6dc1a38
JO
7356static struct nla_policy
7357nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
7358 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
7359 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
7360 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
7361 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
7362 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
7363 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
7364};
7365
84f10708 7366static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 7367 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
7368{
7369 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7370 struct wireless_dev *wdev;
7371 struct net_device *dev = info->user_ptr[1];
7372
d9d8b019 7373 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
7374 return -EINVAL;
7375
7376 wdev = dev->ieee80211_ptr;
7377
7378 if (!rdev->ops->set_cqm_txe_config)
7379 return -EOPNOTSUPP;
7380
7381 if (wdev->iftype != NL80211_IFTYPE_STATION &&
7382 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
7383 return -EOPNOTSUPP;
7384
e35e4d28 7385 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
7386}
7387
d6dc1a38
JO
7388static int nl80211_set_cqm_rssi(struct genl_info *info,
7389 s32 threshold, u32 hysteresis)
7390{
4c476991 7391 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 7392 struct wireless_dev *wdev;
4c476991 7393 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
7394
7395 if (threshold > 0)
7396 return -EINVAL;
7397
d6dc1a38
JO
7398 wdev = dev->ieee80211_ptr;
7399
4c476991
JB
7400 if (!rdev->ops->set_cqm_rssi_config)
7401 return -EOPNOTSUPP;
d6dc1a38 7402
074ac8df 7403 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7404 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
7405 return -EOPNOTSUPP;
d6dc1a38 7406
e35e4d28 7407 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
7408}
7409
7410static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
7411{
7412 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
7413 struct nlattr *cqm;
7414 int err;
7415
7416 cqm = info->attrs[NL80211_ATTR_CQM];
7417 if (!cqm) {
7418 err = -EINVAL;
7419 goto out;
7420 }
7421
7422 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
7423 nl80211_attr_cqm_policy);
7424 if (err)
7425 goto out;
7426
7427 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
7428 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
7429 s32 threshold;
7430 u32 hysteresis;
7431 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
7432 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
7433 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
84f10708
TP
7434 } else if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
7435 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
7436 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
7437 u32 rate, pkts, intvl;
7438 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
7439 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
7440 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
7441 err = nl80211_set_cqm_txe(info, rate, pkts, intvl);
d6dc1a38
JO
7442 } else
7443 err = -EINVAL;
7444
7445out:
7446 return err;
7447}
7448
29cbe68c
JB
7449static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
7450{
7451 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7452 struct net_device *dev = info->user_ptr[1];
7453 struct mesh_config cfg;
c80d545d 7454 struct mesh_setup setup;
29cbe68c
JB
7455 int err;
7456
7457 /* start with default */
7458 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 7459 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 7460
24bdd9f4 7461 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 7462 /* and parse parameters if given */
24bdd9f4 7463 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
7464 if (err)
7465 return err;
7466 }
7467
7468 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
7469 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
7470 return -EINVAL;
7471
c80d545d
JC
7472 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
7473 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
7474
4bb62344
CYY
7475 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
7476 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
7477 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
7478 return -EINVAL;
7479
9bdbf04d
MP
7480 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
7481 setup.beacon_interval =
7482 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
7483 if (setup.beacon_interval < 10 ||
7484 setup.beacon_interval > 10000)
7485 return -EINVAL;
7486 }
7487
7488 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
7489 setup.dtim_period =
7490 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
7491 if (setup.dtim_period < 1 || setup.dtim_period > 100)
7492 return -EINVAL;
7493 }
7494
c80d545d
JC
7495 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
7496 /* parse additional setup parameters if given */
7497 err = nl80211_parse_mesh_setup(info, &setup);
7498 if (err)
7499 return err;
7500 }
7501
d37bb18a
TP
7502 if (setup.user_mpm)
7503 cfg.auto_open_plinks = false;
7504
cc1d2806 7505 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
7506 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
7507 if (err)
7508 return err;
cc1d2806
JB
7509 } else {
7510 /* cfg80211_join_mesh() will sort it out */
683b6d3b 7511 setup.chandef.chan = NULL;
cc1d2806
JB
7512 }
7513
ffb3cf30
AN
7514 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
7515 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7516 int n_rates =
7517 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7518 struct ieee80211_supported_band *sband;
7519
7520 if (!setup.chandef.chan)
7521 return -EINVAL;
7522
7523 sband = rdev->wiphy.bands[setup.chandef.chan->band];
7524
7525 err = ieee80211_get_ratemask(sband, rates, n_rates,
7526 &setup.basic_rates);
7527 if (err)
7528 return err;
7529 }
7530
c80d545d 7531 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
7532}
7533
7534static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
7535{
7536 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7537 struct net_device *dev = info->user_ptr[1];
7538
7539 return cfg80211_leave_mesh(rdev, dev);
7540}
7541
dfb89c56 7542#ifdef CONFIG_PM
bb92d199
AK
7543static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
7544 struct cfg80211_registered_device *rdev)
7545{
6abb9cb9 7546 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
7547 struct nlattr *nl_pats, *nl_pat;
7548 int i, pat_len;
7549
6abb9cb9 7550 if (!wowlan->n_patterns)
bb92d199
AK
7551 return 0;
7552
7553 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
7554 if (!nl_pats)
7555 return -ENOBUFS;
7556
6abb9cb9 7557 for (i = 0; i < wowlan->n_patterns; i++) {
bb92d199
AK
7558 nl_pat = nla_nest_start(msg, i + 1);
7559 if (!nl_pat)
7560 return -ENOBUFS;
6abb9cb9 7561 pat_len = wowlan->patterns[i].pattern_len;
bb92d199
AK
7562 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
7563 DIV_ROUND_UP(pat_len, 8),
6abb9cb9 7564 wowlan->patterns[i].mask) ||
bb92d199 7565 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6abb9cb9 7566 pat_len, wowlan->patterns[i].pattern) ||
bb92d199 7567 nla_put_u32(msg, NL80211_WOWLAN_PKTPAT_OFFSET,
6abb9cb9 7568 wowlan->patterns[i].pkt_offset))
bb92d199
AK
7569 return -ENOBUFS;
7570 nla_nest_end(msg, nl_pat);
7571 }
7572 nla_nest_end(msg, nl_pats);
7573
7574 return 0;
7575}
7576
2a0e047e
JB
7577static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
7578 struct cfg80211_wowlan_tcp *tcp)
7579{
7580 struct nlattr *nl_tcp;
7581
7582 if (!tcp)
7583 return 0;
7584
7585 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
7586 if (!nl_tcp)
7587 return -ENOBUFS;
7588
7589 if (nla_put_be32(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
7590 nla_put_be32(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
7591 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
7592 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
7593 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
7594 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
7595 tcp->payload_len, tcp->payload) ||
7596 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
7597 tcp->data_interval) ||
7598 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
7599 tcp->wake_len, tcp->wake_data) ||
7600 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
7601 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
7602 return -ENOBUFS;
7603
7604 if (tcp->payload_seq.len &&
7605 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
7606 sizeof(tcp->payload_seq), &tcp->payload_seq))
7607 return -ENOBUFS;
7608
7609 if (tcp->payload_tok.len &&
7610 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
7611 sizeof(tcp->payload_tok) + tcp->tokens_size,
7612 &tcp->payload_tok))
7613 return -ENOBUFS;
7614
e248ad30
JB
7615 nla_nest_end(msg, nl_tcp);
7616
2a0e047e
JB
7617 return 0;
7618}
7619
ff1b6e69
JB
7620static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
7621{
7622 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7623 struct sk_buff *msg;
7624 void *hdr;
2a0e047e 7625 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 7626
964dc9e2 7627 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
7628 return -EOPNOTSUPP;
7629
6abb9cb9 7630 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 7631 /* adjust size to have room for all the data */
6abb9cb9
JB
7632 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
7633 rdev->wiphy.wowlan_config->tcp->payload_len +
7634 rdev->wiphy.wowlan_config->tcp->wake_len +
7635 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
7636 }
7637
7638 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
7639 if (!msg)
7640 return -ENOMEM;
7641
15e47304 7642 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
7643 NL80211_CMD_GET_WOWLAN);
7644 if (!hdr)
7645 goto nla_put_failure;
7646
6abb9cb9 7647 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
7648 struct nlattr *nl_wowlan;
7649
7650 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7651 if (!nl_wowlan)
7652 goto nla_put_failure;
7653
6abb9cb9 7654 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 7655 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 7656 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 7657 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 7658 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 7659 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 7660 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 7661 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 7662 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 7663 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 7664 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 7665 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 7666 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
7667 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
7668 goto nla_put_failure;
2a0e047e 7669
bb92d199
AK
7670 if (nl80211_send_wowlan_patterns(msg, rdev))
7671 goto nla_put_failure;
2a0e047e 7672
6abb9cb9
JB
7673 if (nl80211_send_wowlan_tcp(msg,
7674 rdev->wiphy.wowlan_config->tcp))
2a0e047e
JB
7675 goto nla_put_failure;
7676
ff1b6e69
JB
7677 nla_nest_end(msg, nl_wowlan);
7678 }
7679
7680 genlmsg_end(msg, hdr);
7681 return genlmsg_reply(msg, info);
7682
7683nla_put_failure:
7684 nlmsg_free(msg);
7685 return -ENOBUFS;
7686}
7687
2a0e047e
JB
7688static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
7689 struct nlattr *attr,
7690 struct cfg80211_wowlan *trig)
7691{
7692 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
7693 struct cfg80211_wowlan_tcp *cfg;
7694 struct nl80211_wowlan_tcp_data_token *tok = NULL;
7695 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
7696 u32 size;
7697 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
7698 int err, port;
7699
964dc9e2 7700 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
7701 return -EINVAL;
7702
7703 err = nla_parse(tb, MAX_NL80211_WOWLAN_TCP,
7704 nla_data(attr), nla_len(attr),
7705 nl80211_wowlan_tcp_policy);
7706 if (err)
7707 return err;
7708
7709 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
7710 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
7711 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
7712 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
7713 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
7714 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
7715 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
7716 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
7717 return -EINVAL;
7718
7719 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 7720 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
7721 return -EINVAL;
7722
7723 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 7724 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 7725 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
7726 return -EINVAL;
7727
7728 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 7729 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
7730 return -EINVAL;
7731
7732 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
7733 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
7734 return -EINVAL;
7735
7736 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
7737 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
7738
7739 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
7740 tokens_size = tokln - sizeof(*tok);
7741
7742 if (!tok->len || tokens_size % tok->len)
7743 return -EINVAL;
964dc9e2 7744 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 7745 return -EINVAL;
964dc9e2 7746 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 7747 return -EINVAL;
964dc9e2 7748 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 7749 return -EINVAL;
964dc9e2 7750 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
7751 return -EINVAL;
7752 if (tok->offset + tok->len > data_size)
7753 return -EINVAL;
7754 }
7755
7756 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
7757 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 7758 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
7759 return -EINVAL;
7760 if (seq->len == 0 || seq->len > 4)
7761 return -EINVAL;
7762 if (seq->len + seq->offset > data_size)
7763 return -EINVAL;
7764 }
7765
7766 size = sizeof(*cfg);
7767 size += data_size;
7768 size += wake_size + wake_mask_size;
7769 size += tokens_size;
7770
7771 cfg = kzalloc(size, GFP_KERNEL);
7772 if (!cfg)
7773 return -ENOMEM;
7774 cfg->src = nla_get_be32(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
7775 cfg->dst = nla_get_be32(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
7776 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
7777 ETH_ALEN);
7778 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
7779 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
7780 else
7781 port = 0;
7782#ifdef CONFIG_INET
7783 /* allocate a socket and port for it and use it */
7784 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
7785 IPPROTO_TCP, &cfg->sock, 1);
7786 if (err) {
7787 kfree(cfg);
7788 return err;
7789 }
7790 if (inet_csk_get_port(cfg->sock->sk, port)) {
7791 sock_release(cfg->sock);
7792 kfree(cfg);
7793 return -EADDRINUSE;
7794 }
7795 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
7796#else
7797 if (!port) {
7798 kfree(cfg);
7799 return -EINVAL;
7800 }
7801 cfg->src_port = port;
7802#endif
7803
7804 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
7805 cfg->payload_len = data_size;
7806 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
7807 memcpy((void *)cfg->payload,
7808 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
7809 data_size);
7810 if (seq)
7811 cfg->payload_seq = *seq;
7812 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
7813 cfg->wake_len = wake_size;
7814 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
7815 memcpy((void *)cfg->wake_data,
7816 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
7817 wake_size);
7818 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
7819 data_size + wake_size;
7820 memcpy((void *)cfg->wake_mask,
7821 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
7822 wake_mask_size);
7823 if (tok) {
7824 cfg->tokens_size = tokens_size;
7825 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
7826 }
7827
7828 trig->tcp = cfg;
7829
7830 return 0;
7831}
7832
ff1b6e69
JB
7833static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
7834{
7835 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7836 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 7837 struct cfg80211_wowlan new_triggers = {};
ae33bd81 7838 struct cfg80211_wowlan *ntrig;
964dc9e2 7839 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 7840 int err, i;
6abb9cb9 7841 bool prev_enabled = rdev->wiphy.wowlan_config;
ff1b6e69 7842
964dc9e2 7843 if (!wowlan)
ff1b6e69
JB
7844 return -EOPNOTSUPP;
7845
ae33bd81
JB
7846 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
7847 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 7848 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
7849 goto set_wakeup;
7850 }
ff1b6e69
JB
7851
7852 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
7853 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
7854 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
7855 nl80211_wowlan_policy);
7856 if (err)
7857 return err;
7858
7859 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
7860 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
7861 return -EINVAL;
7862 new_triggers.any = true;
7863 }
7864
7865 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
7866 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
7867 return -EINVAL;
7868 new_triggers.disconnect = true;
7869 }
7870
7871 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
7872 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
7873 return -EINVAL;
7874 new_triggers.magic_pkt = true;
7875 }
7876
77dbbb13
JB
7877 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
7878 return -EINVAL;
7879
7880 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
7881 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
7882 return -EINVAL;
7883 new_triggers.gtk_rekey_failure = true;
7884 }
7885
7886 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
7887 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
7888 return -EINVAL;
7889 new_triggers.eap_identity_req = true;
7890 }
7891
7892 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
7893 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
7894 return -EINVAL;
7895 new_triggers.four_way_handshake = true;
7896 }
7897
7898 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
7899 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
7900 return -EINVAL;
7901 new_triggers.rfkill_release = true;
7902 }
7903
ff1b6e69
JB
7904 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
7905 struct nlattr *pat;
7906 int n_patterns = 0;
bb92d199 7907 int rem, pat_len, mask_len, pkt_offset;
ff1b6e69
JB
7908 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
7909
7910 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7911 rem)
7912 n_patterns++;
7913 if (n_patterns > wowlan->n_patterns)
7914 return -EINVAL;
7915
7916 new_triggers.patterns = kcalloc(n_patterns,
7917 sizeof(new_triggers.patterns[0]),
7918 GFP_KERNEL);
7919 if (!new_triggers.patterns)
7920 return -ENOMEM;
7921
7922 new_triggers.n_patterns = n_patterns;
7923 i = 0;
7924
7925 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7926 rem) {
7927 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
7928 nla_data(pat), nla_len(pat), NULL);
7929 err = -EINVAL;
7930 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
7931 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
7932 goto error;
7933 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
7934 mask_len = DIV_ROUND_UP(pat_len, 8);
7935 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
7936 mask_len)
7937 goto error;
7938 if (pat_len > wowlan->pattern_max_len ||
7939 pat_len < wowlan->pattern_min_len)
7940 goto error;
7941
bb92d199
AK
7942 if (!pat_tb[NL80211_WOWLAN_PKTPAT_OFFSET])
7943 pkt_offset = 0;
7944 else
7945 pkt_offset = nla_get_u32(
7946 pat_tb[NL80211_WOWLAN_PKTPAT_OFFSET]);
7947 if (pkt_offset > wowlan->max_pkt_offset)
7948 goto error;
7949 new_triggers.patterns[i].pkt_offset = pkt_offset;
7950
ff1b6e69
JB
7951 new_triggers.patterns[i].mask =
7952 kmalloc(mask_len + pat_len, GFP_KERNEL);
7953 if (!new_triggers.patterns[i].mask) {
7954 err = -ENOMEM;
7955 goto error;
7956 }
7957 new_triggers.patterns[i].pattern =
7958 new_triggers.patterns[i].mask + mask_len;
7959 memcpy(new_triggers.patterns[i].mask,
7960 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
7961 mask_len);
7962 new_triggers.patterns[i].pattern_len = pat_len;
7963 memcpy(new_triggers.patterns[i].pattern,
7964 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
7965 pat_len);
7966 i++;
7967 }
7968 }
7969
2a0e047e
JB
7970 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
7971 err = nl80211_parse_wowlan_tcp(
7972 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
7973 &new_triggers);
7974 if (err)
7975 goto error;
7976 }
7977
ae33bd81
JB
7978 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
7979 if (!ntrig) {
7980 err = -ENOMEM;
7981 goto error;
ff1b6e69 7982 }
ae33bd81 7983 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 7984 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 7985
ae33bd81 7986 set_wakeup:
6abb9cb9
JB
7987 if (rdev->ops->set_wakeup &&
7988 prev_enabled != !!rdev->wiphy.wowlan_config)
7989 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 7990
ff1b6e69
JB
7991 return 0;
7992 error:
7993 for (i = 0; i < new_triggers.n_patterns; i++)
7994 kfree(new_triggers.patterns[i].mask);
7995 kfree(new_triggers.patterns);
2a0e047e
JB
7996 if (new_triggers.tcp && new_triggers.tcp->sock)
7997 sock_release(new_triggers.tcp->sock);
7998 kfree(new_triggers.tcp);
ff1b6e69
JB
7999 return err;
8000}
dfb89c56 8001#endif
ff1b6e69 8002
e5497d76
JB
8003static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
8004{
8005 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8006 struct net_device *dev = info->user_ptr[1];
8007 struct wireless_dev *wdev = dev->ieee80211_ptr;
8008 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
8009 struct cfg80211_gtk_rekey_data rekey_data;
8010 int err;
8011
8012 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
8013 return -EINVAL;
8014
8015 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
8016 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
8017 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
8018 nl80211_rekey_policy);
8019 if (err)
8020 return err;
8021
8022 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
8023 return -ERANGE;
8024 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
8025 return -ERANGE;
8026 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
8027 return -ERANGE;
8028
8029 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
8030 NL80211_KEK_LEN);
8031 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
8032 NL80211_KCK_LEN);
8033 memcpy(rekey_data.replay_ctr,
8034 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
8035 NL80211_REPLAY_CTR_LEN);
8036
8037 wdev_lock(wdev);
8038 if (!wdev->current_bss) {
8039 err = -ENOTCONN;
8040 goto out;
8041 }
8042
8043 if (!rdev->ops->set_rekey_data) {
8044 err = -EOPNOTSUPP;
8045 goto out;
8046 }
8047
e35e4d28 8048 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
8049 out:
8050 wdev_unlock(wdev);
8051 return err;
8052}
8053
28946da7
JB
8054static int nl80211_register_unexpected_frame(struct sk_buff *skb,
8055 struct genl_info *info)
8056{
8057 struct net_device *dev = info->user_ptr[1];
8058 struct wireless_dev *wdev = dev->ieee80211_ptr;
8059
8060 if (wdev->iftype != NL80211_IFTYPE_AP &&
8061 wdev->iftype != NL80211_IFTYPE_P2P_GO)
8062 return -EINVAL;
8063
15e47304 8064 if (wdev->ap_unexpected_nlportid)
28946da7
JB
8065 return -EBUSY;
8066
15e47304 8067 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
8068 return 0;
8069}
8070
7f6cf311
JB
8071static int nl80211_probe_client(struct sk_buff *skb,
8072 struct genl_info *info)
8073{
8074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8075 struct net_device *dev = info->user_ptr[1];
8076 struct wireless_dev *wdev = dev->ieee80211_ptr;
8077 struct sk_buff *msg;
8078 void *hdr;
8079 const u8 *addr;
8080 u64 cookie;
8081 int err;
8082
8083 if (wdev->iftype != NL80211_IFTYPE_AP &&
8084 wdev->iftype != NL80211_IFTYPE_P2P_GO)
8085 return -EOPNOTSUPP;
8086
8087 if (!info->attrs[NL80211_ATTR_MAC])
8088 return -EINVAL;
8089
8090 if (!rdev->ops->probe_client)
8091 return -EOPNOTSUPP;
8092
8093 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8094 if (!msg)
8095 return -ENOMEM;
8096
15e47304 8097 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311
JB
8098 NL80211_CMD_PROBE_CLIENT);
8099
8100 if (IS_ERR(hdr)) {
8101 err = PTR_ERR(hdr);
8102 goto free_msg;
8103 }
8104
8105 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
8106
e35e4d28 8107 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
8108 if (err)
8109 goto free_msg;
8110
9360ffd1
DM
8111 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8112 goto nla_put_failure;
7f6cf311
JB
8113
8114 genlmsg_end(msg, hdr);
8115
8116 return genlmsg_reply(msg, info);
8117
8118 nla_put_failure:
8119 err = -ENOBUFS;
8120 free_msg:
8121 nlmsg_free(msg);
8122 return err;
8123}
8124
5e760230
JB
8125static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
8126{
8127 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
8128 struct cfg80211_beacon_registration *reg, *nreg;
8129 int rv;
5e760230
JB
8130
8131 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
8132 return -EOPNOTSUPP;
8133
37c73b5f
BG
8134 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
8135 if (!nreg)
8136 return -ENOMEM;
8137
8138 /* First, check if already registered. */
8139 spin_lock_bh(&rdev->beacon_registrations_lock);
8140 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
8141 if (reg->nlportid == info->snd_portid) {
8142 rv = -EALREADY;
8143 goto out_err;
8144 }
8145 }
8146 /* Add it to the list */
8147 nreg->nlportid = info->snd_portid;
8148 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 8149
37c73b5f 8150 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
8151
8152 return 0;
37c73b5f
BG
8153out_err:
8154 spin_unlock_bh(&rdev->beacon_registrations_lock);
8155 kfree(nreg);
8156 return rv;
5e760230
JB
8157}
8158
98104fde
JB
8159static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
8160{
8161 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8162 struct wireless_dev *wdev = info->user_ptr[1];
8163 int err;
8164
8165 if (!rdev->ops->start_p2p_device)
8166 return -EOPNOTSUPP;
8167
8168 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
8169 return -EOPNOTSUPP;
8170
8171 if (wdev->p2p_started)
8172 return 0;
8173
98104fde 8174 err = cfg80211_can_add_interface(rdev, wdev->iftype);
98104fde
JB
8175 if (err)
8176 return err;
8177
eeb126e9 8178 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
8179 if (err)
8180 return err;
8181
8182 wdev->p2p_started = true;
98104fde 8183 rdev->opencount++;
98104fde
JB
8184
8185 return 0;
8186}
8187
8188static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
8189{
8190 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8191 struct wireless_dev *wdev = info->user_ptr[1];
8192
8193 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
8194 return -EOPNOTSUPP;
8195
8196 if (!rdev->ops->stop_p2p_device)
8197 return -EOPNOTSUPP;
8198
f9f47529 8199 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
8200
8201 return 0;
8202}
8203
3713b4e3
JB
8204static int nl80211_get_protocol_features(struct sk_buff *skb,
8205 struct genl_info *info)
8206{
8207 void *hdr;
8208 struct sk_buff *msg;
8209
8210 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8211 if (!msg)
8212 return -ENOMEM;
8213
8214 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8215 NL80211_CMD_GET_PROTOCOL_FEATURES);
8216 if (!hdr)
8217 goto nla_put_failure;
8218
8219 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
8220 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
8221 goto nla_put_failure;
8222
8223 genlmsg_end(msg, hdr);
8224 return genlmsg_reply(msg, info);
8225
8226 nla_put_failure:
8227 kfree_skb(msg);
8228 return -ENOBUFS;
8229}
8230
355199e0
JM
8231static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
8232{
8233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8234 struct cfg80211_update_ft_ies_params ft_params;
8235 struct net_device *dev = info->user_ptr[1];
8236
8237 if (!rdev->ops->update_ft_ies)
8238 return -EOPNOTSUPP;
8239
8240 if (!info->attrs[NL80211_ATTR_MDID] ||
8241 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8242 return -EINVAL;
8243
8244 memset(&ft_params, 0, sizeof(ft_params));
8245 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
8246 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8247 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
8248
8249 return rdev_update_ft_ies(rdev, dev, &ft_params);
8250}
8251
5de17984
AS
8252static int nl80211_crit_protocol_start(struct sk_buff *skb,
8253 struct genl_info *info)
8254{
8255 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8256 struct wireless_dev *wdev = info->user_ptr[1];
8257 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
8258 u16 duration;
8259 int ret;
8260
8261 if (!rdev->ops->crit_proto_start)
8262 return -EOPNOTSUPP;
8263
8264 if (WARN_ON(!rdev->ops->crit_proto_stop))
8265 return -EINVAL;
8266
8267 if (rdev->crit_proto_nlportid)
8268 return -EBUSY;
8269
8270 /* determine protocol if provided */
8271 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
8272 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
8273
8274 if (proto >= NUM_NL80211_CRIT_PROTO)
8275 return -EINVAL;
8276
8277 /* timeout must be provided */
8278 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
8279 return -EINVAL;
8280
8281 duration =
8282 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
8283
8284 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
8285 return -ERANGE;
8286
8287 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
8288 if (!ret)
8289 rdev->crit_proto_nlportid = info->snd_portid;
8290
8291 return ret;
8292}
8293
8294static int nl80211_crit_protocol_stop(struct sk_buff *skb,
8295 struct genl_info *info)
8296{
8297 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8298 struct wireless_dev *wdev = info->user_ptr[1];
8299
8300 if (!rdev->ops->crit_proto_stop)
8301 return -EOPNOTSUPP;
8302
8303 if (rdev->crit_proto_nlportid) {
8304 rdev->crit_proto_nlportid = 0;
8305 rdev_crit_proto_stop(rdev, wdev);
8306 }
8307 return 0;
8308}
8309
4c476991
JB
8310#define NL80211_FLAG_NEED_WIPHY 0x01
8311#define NL80211_FLAG_NEED_NETDEV 0x02
8312#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
8313#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
8314#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
8315 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 8316#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 8317/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
8318#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
8319 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
8320
8321static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
8322 struct genl_info *info)
8323{
8324 struct cfg80211_registered_device *rdev;
89a54e48 8325 struct wireless_dev *wdev;
4c476991 8326 struct net_device *dev;
4c476991
JB
8327 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
8328
8329 if (rtnl)
8330 rtnl_lock();
8331
8332 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 8333 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
8334 if (IS_ERR(rdev)) {
8335 if (rtnl)
8336 rtnl_unlock();
8337 return PTR_ERR(rdev);
8338 }
8339 info->user_ptr[0] = rdev;
1bf614ef
JB
8340 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
8341 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
8342 ASSERT_RTNL();
8343
89a54e48
JB
8344 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
8345 info->attrs);
8346 if (IS_ERR(wdev)) {
4c476991
JB
8347 if (rtnl)
8348 rtnl_unlock();
89a54e48 8349 return PTR_ERR(wdev);
4c476991 8350 }
89a54e48 8351
89a54e48
JB
8352 dev = wdev->netdev;
8353 rdev = wiphy_to_dev(wdev->wiphy);
8354
1bf614ef
JB
8355 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
8356 if (!dev) {
1bf614ef
JB
8357 if (rtnl)
8358 rtnl_unlock();
8359 return -EINVAL;
8360 }
8361
8362 info->user_ptr[1] = dev;
8363 } else {
8364 info->user_ptr[1] = wdev;
41265714 8365 }
1bf614ef
JB
8366
8367 if (dev) {
8368 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
8369 !netif_running(dev)) {
1bf614ef
JB
8370 if (rtnl)
8371 rtnl_unlock();
8372 return -ENETDOWN;
8373 }
8374
8375 dev_hold(dev);
98104fde
JB
8376 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
8377 if (!wdev->p2p_started) {
98104fde
JB
8378 if (rtnl)
8379 rtnl_unlock();
8380 return -ENETDOWN;
8381 }
41265714 8382 }
89a54e48 8383
4c476991 8384 info->user_ptr[0] = rdev;
4c476991
JB
8385 }
8386
8387 return 0;
8388}
8389
8390static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
8391 struct genl_info *info)
8392{
1bf614ef
JB
8393 if (info->user_ptr[1]) {
8394 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
8395 struct wireless_dev *wdev = info->user_ptr[1];
8396
8397 if (wdev->netdev)
8398 dev_put(wdev->netdev);
8399 } else {
8400 dev_put(info->user_ptr[1]);
8401 }
8402 }
4c476991
JB
8403 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
8404 rtnl_unlock();
8405}
8406
55682965
JB
8407static struct genl_ops nl80211_ops[] = {
8408 {
8409 .cmd = NL80211_CMD_GET_WIPHY,
8410 .doit = nl80211_get_wiphy,
8411 .dumpit = nl80211_dump_wiphy,
8412 .policy = nl80211_policy,
8413 /* can be retrieved by unprivileged users */
5fe231e8
JB
8414 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8415 NL80211_FLAG_NEED_RTNL,
55682965
JB
8416 },
8417 {
8418 .cmd = NL80211_CMD_SET_WIPHY,
8419 .doit = nl80211_set_wiphy,
8420 .policy = nl80211_policy,
8421 .flags = GENL_ADMIN_PERM,
4c476991 8422 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
8423 },
8424 {
8425 .cmd = NL80211_CMD_GET_INTERFACE,
8426 .doit = nl80211_get_interface,
8427 .dumpit = nl80211_dump_interface,
8428 .policy = nl80211_policy,
8429 /* can be retrieved by unprivileged users */
5fe231e8
JB
8430 .internal_flags = NL80211_FLAG_NEED_WDEV |
8431 NL80211_FLAG_NEED_RTNL,
55682965
JB
8432 },
8433 {
8434 .cmd = NL80211_CMD_SET_INTERFACE,
8435 .doit = nl80211_set_interface,
8436 .policy = nl80211_policy,
8437 .flags = GENL_ADMIN_PERM,
4c476991
JB
8438 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8439 NL80211_FLAG_NEED_RTNL,
55682965
JB
8440 },
8441 {
8442 .cmd = NL80211_CMD_NEW_INTERFACE,
8443 .doit = nl80211_new_interface,
8444 .policy = nl80211_policy,
8445 .flags = GENL_ADMIN_PERM,
4c476991
JB
8446 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8447 NL80211_FLAG_NEED_RTNL,
55682965
JB
8448 },
8449 {
8450 .cmd = NL80211_CMD_DEL_INTERFACE,
8451 .doit = nl80211_del_interface,
8452 .policy = nl80211_policy,
41ade00f 8453 .flags = GENL_ADMIN_PERM,
84efbb84 8454 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 8455 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8456 },
8457 {
8458 .cmd = NL80211_CMD_GET_KEY,
8459 .doit = nl80211_get_key,
8460 .policy = nl80211_policy,
8461 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8462 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8463 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8464 },
8465 {
8466 .cmd = NL80211_CMD_SET_KEY,
8467 .doit = nl80211_set_key,
8468 .policy = nl80211_policy,
8469 .flags = GENL_ADMIN_PERM,
41265714 8470 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8471 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8472 },
8473 {
8474 .cmd = NL80211_CMD_NEW_KEY,
8475 .doit = nl80211_new_key,
8476 .policy = nl80211_policy,
8477 .flags = GENL_ADMIN_PERM,
41265714 8478 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8479 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
8480 },
8481 {
8482 .cmd = NL80211_CMD_DEL_KEY,
8483 .doit = nl80211_del_key,
8484 .policy = nl80211_policy,
55682965 8485 .flags = GENL_ADMIN_PERM,
41265714 8486 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8487 NL80211_FLAG_NEED_RTNL,
55682965 8488 },
ed1b6cc7
JB
8489 {
8490 .cmd = NL80211_CMD_SET_BEACON,
8491 .policy = nl80211_policy,
8492 .flags = GENL_ADMIN_PERM,
8860020e 8493 .doit = nl80211_set_beacon,
2b5f8b0b 8494 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8495 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
8496 },
8497 {
8860020e 8498 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
8499 .policy = nl80211_policy,
8500 .flags = GENL_ADMIN_PERM,
8860020e 8501 .doit = nl80211_start_ap,
2b5f8b0b 8502 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8503 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
8504 },
8505 {
8860020e 8506 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
8507 .policy = nl80211_policy,
8508 .flags = GENL_ADMIN_PERM,
8860020e 8509 .doit = nl80211_stop_ap,
2b5f8b0b 8510 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8511 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 8512 },
5727ef1b
JB
8513 {
8514 .cmd = NL80211_CMD_GET_STATION,
8515 .doit = nl80211_get_station,
2ec600d6 8516 .dumpit = nl80211_dump_station,
5727ef1b 8517 .policy = nl80211_policy,
4c476991
JB
8518 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8519 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
8520 },
8521 {
8522 .cmd = NL80211_CMD_SET_STATION,
8523 .doit = nl80211_set_station,
8524 .policy = nl80211_policy,
8525 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8526 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8527 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
8528 },
8529 {
8530 .cmd = NL80211_CMD_NEW_STATION,
8531 .doit = nl80211_new_station,
8532 .policy = nl80211_policy,
8533 .flags = GENL_ADMIN_PERM,
41265714 8534 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8535 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
8536 },
8537 {
8538 .cmd = NL80211_CMD_DEL_STATION,
8539 .doit = nl80211_del_station,
8540 .policy = nl80211_policy,
2ec600d6 8541 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8542 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8543 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
8544 },
8545 {
8546 .cmd = NL80211_CMD_GET_MPATH,
8547 .doit = nl80211_get_mpath,
8548 .dumpit = nl80211_dump_mpath,
8549 .policy = nl80211_policy,
8550 .flags = GENL_ADMIN_PERM,
41265714 8551 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8552 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
8553 },
8554 {
8555 .cmd = NL80211_CMD_SET_MPATH,
8556 .doit = nl80211_set_mpath,
8557 .policy = nl80211_policy,
8558 .flags = GENL_ADMIN_PERM,
41265714 8559 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8560 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
8561 },
8562 {
8563 .cmd = NL80211_CMD_NEW_MPATH,
8564 .doit = nl80211_new_mpath,
8565 .policy = nl80211_policy,
8566 .flags = GENL_ADMIN_PERM,
41265714 8567 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8568 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
8569 },
8570 {
8571 .cmd = NL80211_CMD_DEL_MPATH,
8572 .doit = nl80211_del_mpath,
8573 .policy = nl80211_policy,
9f1ba906 8574 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8575 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8576 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
8577 },
8578 {
8579 .cmd = NL80211_CMD_SET_BSS,
8580 .doit = nl80211_set_bss,
8581 .policy = nl80211_policy,
b2e1b302 8582 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8583 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8584 NL80211_FLAG_NEED_RTNL,
b2e1b302 8585 },
f130347c
LR
8586 {
8587 .cmd = NL80211_CMD_GET_REG,
8588 .doit = nl80211_get_reg,
8589 .policy = nl80211_policy,
5fe231e8 8590 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
8591 /* can be retrieved by unprivileged users */
8592 },
b2e1b302
LR
8593 {
8594 .cmd = NL80211_CMD_SET_REG,
8595 .doit = nl80211_set_reg,
8596 .policy = nl80211_policy,
8597 .flags = GENL_ADMIN_PERM,
5fe231e8 8598 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302
LR
8599 },
8600 {
8601 .cmd = NL80211_CMD_REQ_SET_REG,
8602 .doit = nl80211_req_set_reg,
8603 .policy = nl80211_policy,
93da9cc1 8604 .flags = GENL_ADMIN_PERM,
8605 },
8606 {
24bdd9f4
JC
8607 .cmd = NL80211_CMD_GET_MESH_CONFIG,
8608 .doit = nl80211_get_mesh_config,
93da9cc1 8609 .policy = nl80211_policy,
8610 /* can be retrieved by unprivileged users */
2b5f8b0b 8611 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8612 NL80211_FLAG_NEED_RTNL,
93da9cc1 8613 },
8614 {
24bdd9f4
JC
8615 .cmd = NL80211_CMD_SET_MESH_CONFIG,
8616 .doit = nl80211_update_mesh_config,
93da9cc1 8617 .policy = nl80211_policy,
9aed3cc1 8618 .flags = GENL_ADMIN_PERM,
29cbe68c 8619 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8620 NL80211_FLAG_NEED_RTNL,
9aed3cc1 8621 },
2a519311
JB
8622 {
8623 .cmd = NL80211_CMD_TRIGGER_SCAN,
8624 .doit = nl80211_trigger_scan,
8625 .policy = nl80211_policy,
8626 .flags = GENL_ADMIN_PERM,
fd014284 8627 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8628 NL80211_FLAG_NEED_RTNL,
2a519311
JB
8629 },
8630 {
8631 .cmd = NL80211_CMD_GET_SCAN,
8632 .policy = nl80211_policy,
8633 .dumpit = nl80211_dump_scan,
8634 },
807f8a8c
LC
8635 {
8636 .cmd = NL80211_CMD_START_SCHED_SCAN,
8637 .doit = nl80211_start_sched_scan,
8638 .policy = nl80211_policy,
8639 .flags = GENL_ADMIN_PERM,
8640 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8641 NL80211_FLAG_NEED_RTNL,
8642 },
8643 {
8644 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
8645 .doit = nl80211_stop_sched_scan,
8646 .policy = nl80211_policy,
8647 .flags = GENL_ADMIN_PERM,
8648 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8649 NL80211_FLAG_NEED_RTNL,
8650 },
636a5d36
JM
8651 {
8652 .cmd = NL80211_CMD_AUTHENTICATE,
8653 .doit = nl80211_authenticate,
8654 .policy = nl80211_policy,
8655 .flags = GENL_ADMIN_PERM,
41265714 8656 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8657 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
8658 },
8659 {
8660 .cmd = NL80211_CMD_ASSOCIATE,
8661 .doit = nl80211_associate,
8662 .policy = nl80211_policy,
8663 .flags = GENL_ADMIN_PERM,
41265714 8664 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8665 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
8666 },
8667 {
8668 .cmd = NL80211_CMD_DEAUTHENTICATE,
8669 .doit = nl80211_deauthenticate,
8670 .policy = nl80211_policy,
8671 .flags = GENL_ADMIN_PERM,
41265714 8672 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8673 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
8674 },
8675 {
8676 .cmd = NL80211_CMD_DISASSOCIATE,
8677 .doit = nl80211_disassociate,
8678 .policy = nl80211_policy,
8679 .flags = GENL_ADMIN_PERM,
41265714 8680 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8681 NL80211_FLAG_NEED_RTNL,
636a5d36 8682 },
04a773ad
JB
8683 {
8684 .cmd = NL80211_CMD_JOIN_IBSS,
8685 .doit = nl80211_join_ibss,
8686 .policy = nl80211_policy,
8687 .flags = GENL_ADMIN_PERM,
41265714 8688 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8689 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
8690 },
8691 {
8692 .cmd = NL80211_CMD_LEAVE_IBSS,
8693 .doit = nl80211_leave_ibss,
8694 .policy = nl80211_policy,
8695 .flags = GENL_ADMIN_PERM,
41265714 8696 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8697 NL80211_FLAG_NEED_RTNL,
04a773ad 8698 },
aff89a9b
JB
8699#ifdef CONFIG_NL80211_TESTMODE
8700 {
8701 .cmd = NL80211_CMD_TESTMODE,
8702 .doit = nl80211_testmode_do,
71063f0e 8703 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
8704 .policy = nl80211_policy,
8705 .flags = GENL_ADMIN_PERM,
4c476991
JB
8706 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8707 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
8708 },
8709#endif
b23aa676
SO
8710 {
8711 .cmd = NL80211_CMD_CONNECT,
8712 .doit = nl80211_connect,
8713 .policy = nl80211_policy,
8714 .flags = GENL_ADMIN_PERM,
41265714 8715 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8716 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
8717 },
8718 {
8719 .cmd = NL80211_CMD_DISCONNECT,
8720 .doit = nl80211_disconnect,
8721 .policy = nl80211_policy,
8722 .flags = GENL_ADMIN_PERM,
41265714 8723 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8724 NL80211_FLAG_NEED_RTNL,
b23aa676 8725 },
463d0183
JB
8726 {
8727 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
8728 .doit = nl80211_wiphy_netns,
8729 .policy = nl80211_policy,
8730 .flags = GENL_ADMIN_PERM,
4c476991
JB
8731 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8732 NL80211_FLAG_NEED_RTNL,
463d0183 8733 },
61fa713c
HS
8734 {
8735 .cmd = NL80211_CMD_GET_SURVEY,
8736 .policy = nl80211_policy,
8737 .dumpit = nl80211_dump_survey,
8738 },
67fbb16b
SO
8739 {
8740 .cmd = NL80211_CMD_SET_PMKSA,
8741 .doit = nl80211_setdel_pmksa,
8742 .policy = nl80211_policy,
8743 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8744 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8745 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
8746 },
8747 {
8748 .cmd = NL80211_CMD_DEL_PMKSA,
8749 .doit = nl80211_setdel_pmksa,
8750 .policy = nl80211_policy,
8751 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8752 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8753 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
8754 },
8755 {
8756 .cmd = NL80211_CMD_FLUSH_PMKSA,
8757 .doit = nl80211_flush_pmksa,
8758 .policy = nl80211_policy,
8759 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8760 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8761 NL80211_FLAG_NEED_RTNL,
67fbb16b 8762 },
9588bbd5
JM
8763 {
8764 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
8765 .doit = nl80211_remain_on_channel,
8766 .policy = nl80211_policy,
8767 .flags = GENL_ADMIN_PERM,
71bbc994 8768 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8769 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
8770 },
8771 {
8772 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
8773 .doit = nl80211_cancel_remain_on_channel,
8774 .policy = nl80211_policy,
8775 .flags = GENL_ADMIN_PERM,
71bbc994 8776 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8777 NL80211_FLAG_NEED_RTNL,
9588bbd5 8778 },
13ae75b1
JM
8779 {
8780 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
8781 .doit = nl80211_set_tx_bitrate_mask,
8782 .policy = nl80211_policy,
8783 .flags = GENL_ADMIN_PERM,
4c476991
JB
8784 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8785 NL80211_FLAG_NEED_RTNL,
13ae75b1 8786 },
026331c4 8787 {
2e161f78
JB
8788 .cmd = NL80211_CMD_REGISTER_FRAME,
8789 .doit = nl80211_register_mgmt,
026331c4
JM
8790 .policy = nl80211_policy,
8791 .flags = GENL_ADMIN_PERM,
71bbc994 8792 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 8793 NL80211_FLAG_NEED_RTNL,
026331c4
JM
8794 },
8795 {
2e161f78
JB
8796 .cmd = NL80211_CMD_FRAME,
8797 .doit = nl80211_tx_mgmt,
026331c4 8798 .policy = nl80211_policy,
f7ca38df 8799 .flags = GENL_ADMIN_PERM,
71bbc994 8800 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
8801 NL80211_FLAG_NEED_RTNL,
8802 },
8803 {
8804 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
8805 .doit = nl80211_tx_mgmt_cancel_wait,
8806 .policy = nl80211_policy,
026331c4 8807 .flags = GENL_ADMIN_PERM,
71bbc994 8808 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8809 NL80211_FLAG_NEED_RTNL,
026331c4 8810 },
ffb9eb3d
KV
8811 {
8812 .cmd = NL80211_CMD_SET_POWER_SAVE,
8813 .doit = nl80211_set_power_save,
8814 .policy = nl80211_policy,
8815 .flags = GENL_ADMIN_PERM,
4c476991
JB
8816 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8817 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
8818 },
8819 {
8820 .cmd = NL80211_CMD_GET_POWER_SAVE,
8821 .doit = nl80211_get_power_save,
8822 .policy = nl80211_policy,
8823 /* can be retrieved by unprivileged users */
4c476991
JB
8824 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8825 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 8826 },
d6dc1a38
JO
8827 {
8828 .cmd = NL80211_CMD_SET_CQM,
8829 .doit = nl80211_set_cqm,
8830 .policy = nl80211_policy,
8831 .flags = GENL_ADMIN_PERM,
4c476991
JB
8832 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8833 NL80211_FLAG_NEED_RTNL,
d6dc1a38 8834 },
f444de05
JB
8835 {
8836 .cmd = NL80211_CMD_SET_CHANNEL,
8837 .doit = nl80211_set_channel,
8838 .policy = nl80211_policy,
8839 .flags = GENL_ADMIN_PERM,
4c476991
JB
8840 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8841 NL80211_FLAG_NEED_RTNL,
f444de05 8842 },
e8347eba
BJ
8843 {
8844 .cmd = NL80211_CMD_SET_WDS_PEER,
8845 .doit = nl80211_set_wds_peer,
8846 .policy = nl80211_policy,
8847 .flags = GENL_ADMIN_PERM,
43b19952
JB
8848 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8849 NL80211_FLAG_NEED_RTNL,
e8347eba 8850 },
29cbe68c
JB
8851 {
8852 .cmd = NL80211_CMD_JOIN_MESH,
8853 .doit = nl80211_join_mesh,
8854 .policy = nl80211_policy,
8855 .flags = GENL_ADMIN_PERM,
8856 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8857 NL80211_FLAG_NEED_RTNL,
8858 },
8859 {
8860 .cmd = NL80211_CMD_LEAVE_MESH,
8861 .doit = nl80211_leave_mesh,
8862 .policy = nl80211_policy,
8863 .flags = GENL_ADMIN_PERM,
8864 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8865 NL80211_FLAG_NEED_RTNL,
8866 },
dfb89c56 8867#ifdef CONFIG_PM
ff1b6e69
JB
8868 {
8869 .cmd = NL80211_CMD_GET_WOWLAN,
8870 .doit = nl80211_get_wowlan,
8871 .policy = nl80211_policy,
8872 /* can be retrieved by unprivileged users */
8873 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8874 NL80211_FLAG_NEED_RTNL,
8875 },
8876 {
8877 .cmd = NL80211_CMD_SET_WOWLAN,
8878 .doit = nl80211_set_wowlan,
8879 .policy = nl80211_policy,
8880 .flags = GENL_ADMIN_PERM,
8881 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8882 NL80211_FLAG_NEED_RTNL,
8883 },
dfb89c56 8884#endif
e5497d76
JB
8885 {
8886 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
8887 .doit = nl80211_set_rekey_data,
8888 .policy = nl80211_policy,
8889 .flags = GENL_ADMIN_PERM,
8890 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8891 NL80211_FLAG_NEED_RTNL,
8892 },
109086ce
AN
8893 {
8894 .cmd = NL80211_CMD_TDLS_MGMT,
8895 .doit = nl80211_tdls_mgmt,
8896 .policy = nl80211_policy,
8897 .flags = GENL_ADMIN_PERM,
8898 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8899 NL80211_FLAG_NEED_RTNL,
8900 },
8901 {
8902 .cmd = NL80211_CMD_TDLS_OPER,
8903 .doit = nl80211_tdls_oper,
8904 .policy = nl80211_policy,
8905 .flags = GENL_ADMIN_PERM,
8906 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8907 NL80211_FLAG_NEED_RTNL,
8908 },
28946da7
JB
8909 {
8910 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
8911 .doit = nl80211_register_unexpected_frame,
8912 .policy = nl80211_policy,
8913 .flags = GENL_ADMIN_PERM,
8914 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8915 NL80211_FLAG_NEED_RTNL,
8916 },
7f6cf311
JB
8917 {
8918 .cmd = NL80211_CMD_PROBE_CLIENT,
8919 .doit = nl80211_probe_client,
8920 .policy = nl80211_policy,
8921 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8922 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
8923 NL80211_FLAG_NEED_RTNL,
8924 },
5e760230
JB
8925 {
8926 .cmd = NL80211_CMD_REGISTER_BEACONS,
8927 .doit = nl80211_register_beacons,
8928 .policy = nl80211_policy,
8929 .flags = GENL_ADMIN_PERM,
8930 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8931 NL80211_FLAG_NEED_RTNL,
8932 },
1d9d9213
SW
8933 {
8934 .cmd = NL80211_CMD_SET_NOACK_MAP,
8935 .doit = nl80211_set_noack_map,
8936 .policy = nl80211_policy,
8937 .flags = GENL_ADMIN_PERM,
8938 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8939 NL80211_FLAG_NEED_RTNL,
8940 },
98104fde
JB
8941 {
8942 .cmd = NL80211_CMD_START_P2P_DEVICE,
8943 .doit = nl80211_start_p2p_device,
8944 .policy = nl80211_policy,
8945 .flags = GENL_ADMIN_PERM,
8946 .internal_flags = NL80211_FLAG_NEED_WDEV |
8947 NL80211_FLAG_NEED_RTNL,
8948 },
8949 {
8950 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
8951 .doit = nl80211_stop_p2p_device,
8952 .policy = nl80211_policy,
8953 .flags = GENL_ADMIN_PERM,
8954 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
8955 NL80211_FLAG_NEED_RTNL,
8956 },
f4e583c8
AQ
8957 {
8958 .cmd = NL80211_CMD_SET_MCAST_RATE,
8959 .doit = nl80211_set_mcast_rate,
77765eaf
VT
8960 .policy = nl80211_policy,
8961 .flags = GENL_ADMIN_PERM,
8962 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8963 NL80211_FLAG_NEED_RTNL,
8964 },
8965 {
8966 .cmd = NL80211_CMD_SET_MAC_ACL,
8967 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
8968 .policy = nl80211_policy,
8969 .flags = GENL_ADMIN_PERM,
8970 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8971 NL80211_FLAG_NEED_RTNL,
8972 },
04f39047
SW
8973 {
8974 .cmd = NL80211_CMD_RADAR_DETECT,
8975 .doit = nl80211_start_radar_detection,
8976 .policy = nl80211_policy,
8977 .flags = GENL_ADMIN_PERM,
8978 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8979 NL80211_FLAG_NEED_RTNL,
8980 },
3713b4e3
JB
8981 {
8982 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
8983 .doit = nl80211_get_protocol_features,
8984 .policy = nl80211_policy,
8985 },
355199e0
JM
8986 {
8987 .cmd = NL80211_CMD_UPDATE_FT_IES,
8988 .doit = nl80211_update_ft_ies,
8989 .policy = nl80211_policy,
8990 .flags = GENL_ADMIN_PERM,
8991 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8992 NL80211_FLAG_NEED_RTNL,
8993 },
5de17984
AS
8994 {
8995 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
8996 .doit = nl80211_crit_protocol_start,
8997 .policy = nl80211_policy,
8998 .flags = GENL_ADMIN_PERM,
8999 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9000 NL80211_FLAG_NEED_RTNL,
9001 },
9002 {
9003 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
9004 .doit = nl80211_crit_protocol_stop,
9005 .policy = nl80211_policy,
9006 .flags = GENL_ADMIN_PERM,
9007 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9008 NL80211_FLAG_NEED_RTNL,
9009 }
55682965 9010};
9588bbd5 9011
6039f6d2
JM
9012static struct genl_multicast_group nl80211_mlme_mcgrp = {
9013 .name = "mlme",
9014};
55682965
JB
9015
9016/* multicast groups */
9017static struct genl_multicast_group nl80211_config_mcgrp = {
9018 .name = "config",
9019};
2a519311
JB
9020static struct genl_multicast_group nl80211_scan_mcgrp = {
9021 .name = "scan",
9022};
73d54c9e
LR
9023static struct genl_multicast_group nl80211_regulatory_mcgrp = {
9024 .name = "regulatory",
9025};
55682965
JB
9026
9027/* notification functions */
9028
9029void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
9030{
9031 struct sk_buff *msg;
9032
fd2120ca 9033 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
9034 if (!msg)
9035 return;
9036
3713b4e3
JB
9037 if (nl80211_send_wiphy(rdev, msg, 0, 0, 0,
9038 false, NULL, NULL, NULL) < 0) {
55682965
JB
9039 nlmsg_free(msg);
9040 return;
9041 }
9042
463d0183
JB
9043 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9044 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
9045}
9046
362a415d
JB
9047static int nl80211_add_scan_req(struct sk_buff *msg,
9048 struct cfg80211_registered_device *rdev)
9049{
9050 struct cfg80211_scan_request *req = rdev->scan_req;
9051 struct nlattr *nest;
9052 int i;
9053
9054 if (WARN_ON(!req))
9055 return 0;
9056
9057 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
9058 if (!nest)
9059 goto nla_put_failure;
9360ffd1
DM
9060 for (i = 0; i < req->n_ssids; i++) {
9061 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
9062 goto nla_put_failure;
9063 }
362a415d
JB
9064 nla_nest_end(msg, nest);
9065
9066 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
9067 if (!nest)
9068 goto nla_put_failure;
9360ffd1
DM
9069 for (i = 0; i < req->n_channels; i++) {
9070 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
9071 goto nla_put_failure;
9072 }
362a415d
JB
9073 nla_nest_end(msg, nest);
9074
9360ffd1
DM
9075 if (req->ie &&
9076 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
9077 goto nla_put_failure;
362a415d 9078
ed473771
SL
9079 if (req->flags)
9080 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
9081
362a415d
JB
9082 return 0;
9083 nla_put_failure:
9084 return -ENOBUFS;
9085}
9086
a538e2d5
JB
9087static int nl80211_send_scan_msg(struct sk_buff *msg,
9088 struct cfg80211_registered_device *rdev,
fd014284 9089 struct wireless_dev *wdev,
15e47304 9090 u32 portid, u32 seq, int flags,
a538e2d5 9091 u32 cmd)
2a519311
JB
9092{
9093 void *hdr;
9094
15e47304 9095 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
9096 if (!hdr)
9097 return -1;
9098
9360ffd1 9099 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
9100 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9101 wdev->netdev->ifindex)) ||
9102 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 9103 goto nla_put_failure;
2a519311 9104
362a415d
JB
9105 /* ignore errors and send incomplete event anyway */
9106 nl80211_add_scan_req(msg, rdev);
2a519311
JB
9107
9108 return genlmsg_end(msg, hdr);
9109
9110 nla_put_failure:
9111 genlmsg_cancel(msg, hdr);
9112 return -EMSGSIZE;
9113}
9114
807f8a8c
LC
9115static int
9116nl80211_send_sched_scan_msg(struct sk_buff *msg,
9117 struct cfg80211_registered_device *rdev,
9118 struct net_device *netdev,
15e47304 9119 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
9120{
9121 void *hdr;
9122
15e47304 9123 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
9124 if (!hdr)
9125 return -1;
9126
9360ffd1
DM
9127 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9128 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9129 goto nla_put_failure;
807f8a8c
LC
9130
9131 return genlmsg_end(msg, hdr);
9132
9133 nla_put_failure:
9134 genlmsg_cancel(msg, hdr);
9135 return -EMSGSIZE;
9136}
9137
a538e2d5 9138void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 9139 struct wireless_dev *wdev)
a538e2d5
JB
9140{
9141 struct sk_buff *msg;
9142
58050fce 9143 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
9144 if (!msg)
9145 return;
9146
fd014284 9147 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
9148 NL80211_CMD_TRIGGER_SCAN) < 0) {
9149 nlmsg_free(msg);
9150 return;
9151 }
9152
463d0183
JB
9153 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9154 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
9155}
9156
2a519311 9157void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 9158 struct wireless_dev *wdev)
2a519311
JB
9159{
9160 struct sk_buff *msg;
9161
fd2120ca 9162 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
9163 if (!msg)
9164 return;
9165
fd014284 9166 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 9167 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
9168 nlmsg_free(msg);
9169 return;
9170 }
9171
463d0183
JB
9172 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9173 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
9174}
9175
9176void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 9177 struct wireless_dev *wdev)
2a519311
JB
9178{
9179 struct sk_buff *msg;
9180
fd2120ca 9181 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
9182 if (!msg)
9183 return;
9184
fd014284 9185 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 9186 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
9187 nlmsg_free(msg);
9188 return;
9189 }
9190
463d0183
JB
9191 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9192 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
9193}
9194
807f8a8c
LC
9195void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
9196 struct net_device *netdev)
9197{
9198 struct sk_buff *msg;
9199
9200 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9201 if (!msg)
9202 return;
9203
9204 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
9205 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
9206 nlmsg_free(msg);
9207 return;
9208 }
9209
9210 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9211 nl80211_scan_mcgrp.id, GFP_KERNEL);
9212}
9213
9214void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
9215 struct net_device *netdev, u32 cmd)
9216{
9217 struct sk_buff *msg;
9218
58050fce 9219 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
9220 if (!msg)
9221 return;
9222
9223 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
9224 nlmsg_free(msg);
9225 return;
9226 }
9227
9228 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9229 nl80211_scan_mcgrp.id, GFP_KERNEL);
9230}
9231
73d54c9e
LR
9232/*
9233 * This can happen on global regulatory changes or device specific settings
9234 * based on custom world regulatory domains.
9235 */
9236void nl80211_send_reg_change_event(struct regulatory_request *request)
9237{
9238 struct sk_buff *msg;
9239 void *hdr;
9240
fd2120ca 9241 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
9242 if (!msg)
9243 return;
9244
9245 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
9246 if (!hdr) {
9247 nlmsg_free(msg);
9248 return;
9249 }
9250
9251 /* Userspace can always count this one always being set */
9360ffd1
DM
9252 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
9253 goto nla_put_failure;
9254
9255 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
9256 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9257 NL80211_REGDOM_TYPE_WORLD))
9258 goto nla_put_failure;
9259 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
9260 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9261 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
9262 goto nla_put_failure;
9263 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
9264 request->intersect) {
9265 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9266 NL80211_REGDOM_TYPE_INTERSECTION))
9267 goto nla_put_failure;
9268 } else {
9269 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
9270 NL80211_REGDOM_TYPE_COUNTRY) ||
9271 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
9272 request->alpha2))
9273 goto nla_put_failure;
9274 }
9275
f4173766 9276 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
9277 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
9278 goto nla_put_failure;
73d54c9e 9279
3b7b72ee 9280 genlmsg_end(msg, hdr);
73d54c9e 9281
bc43b28c 9282 rcu_read_lock();
463d0183 9283 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
9284 GFP_ATOMIC);
9285 rcu_read_unlock();
73d54c9e
LR
9286
9287 return;
9288
9289nla_put_failure:
9290 genlmsg_cancel(msg, hdr);
9291 nlmsg_free(msg);
9292}
9293
6039f6d2
JM
9294static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
9295 struct net_device *netdev,
9296 const u8 *buf, size_t len,
e6d6e342 9297 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
9298{
9299 struct sk_buff *msg;
9300 void *hdr;
9301
e6d6e342 9302 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
9303 if (!msg)
9304 return;
9305
9306 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
9307 if (!hdr) {
9308 nlmsg_free(msg);
9309 return;
9310 }
9311
9360ffd1
DM
9312 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9313 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9314 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
9315 goto nla_put_failure;
6039f6d2 9316
3b7b72ee 9317 genlmsg_end(msg, hdr);
6039f6d2 9318
463d0183
JB
9319 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9320 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
9321 return;
9322
9323 nla_put_failure:
9324 genlmsg_cancel(msg, hdr);
9325 nlmsg_free(msg);
9326}
9327
9328void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9329 struct net_device *netdev, const u8 *buf,
9330 size_t len, gfp_t gfp)
6039f6d2
JM
9331{
9332 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 9333 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
9334}
9335
9336void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
9337 struct net_device *netdev, const u8 *buf,
e6d6e342 9338 size_t len, gfp_t gfp)
6039f6d2 9339{
e6d6e342
JB
9340 nl80211_send_mlme_event(rdev, netdev, buf, len,
9341 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
9342}
9343
53b46b84 9344void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9345 struct net_device *netdev, const u8 *buf,
9346 size_t len, gfp_t gfp)
6039f6d2
JM
9347{
9348 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 9349 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
9350}
9351
53b46b84
JM
9352void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
9353 struct net_device *netdev, const u8 *buf,
e6d6e342 9354 size_t len, gfp_t gfp)
6039f6d2
JM
9355{
9356 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 9357 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
9358}
9359
6ff57cf8
JB
9360void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
9361 size_t len)
cf4e594e 9362{
947add36
JB
9363 struct wireless_dev *wdev = dev->ieee80211_ptr;
9364 struct wiphy *wiphy = wdev->wiphy;
9365 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6ff57cf8
JB
9366 const struct ieee80211_mgmt *mgmt = (void *)buf;
9367 u32 cmd;
947add36 9368
6ff57cf8
JB
9369 if (WARN_ON(len < 2))
9370 return;
cf4e594e 9371
6ff57cf8
JB
9372 if (ieee80211_is_deauth(mgmt->frame_control))
9373 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
9374 else
9375 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 9376
6ff57cf8
JB
9377 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
9378 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC);
cf4e594e 9379}
6ff57cf8 9380EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 9381
1b06bb40
LR
9382static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
9383 struct net_device *netdev, int cmd,
e6d6e342 9384 const u8 *addr, gfp_t gfp)
1965c853
JM
9385{
9386 struct sk_buff *msg;
9387 void *hdr;
9388
e6d6e342 9389 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
9390 if (!msg)
9391 return;
9392
9393 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
9394 if (!hdr) {
9395 nlmsg_free(msg);
9396 return;
9397 }
9398
9360ffd1
DM
9399 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9400 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9401 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
9402 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
9403 goto nla_put_failure;
1965c853 9404
3b7b72ee 9405 genlmsg_end(msg, hdr);
1965c853 9406
463d0183
JB
9407 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9408 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
9409 return;
9410
9411 nla_put_failure:
9412 genlmsg_cancel(msg, hdr);
9413 nlmsg_free(msg);
9414}
9415
9416void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9417 struct net_device *netdev, const u8 *addr,
9418 gfp_t gfp)
1965c853
JM
9419{
9420 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 9421 addr, gfp);
1965c853
JM
9422}
9423
9424void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
9425 struct net_device *netdev, const u8 *addr,
9426 gfp_t gfp)
1965c853 9427{
e6d6e342
JB
9428 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
9429 addr, gfp);
1965c853
JM
9430}
9431
b23aa676
SO
9432void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
9433 struct net_device *netdev, const u8 *bssid,
9434 const u8 *req_ie, size_t req_ie_len,
9435 const u8 *resp_ie, size_t resp_ie_len,
9436 u16 status, gfp_t gfp)
9437{
9438 struct sk_buff *msg;
9439 void *hdr;
9440
58050fce 9441 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
9442 if (!msg)
9443 return;
9444
9445 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
9446 if (!hdr) {
9447 nlmsg_free(msg);
9448 return;
9449 }
9450
9360ffd1
DM
9451 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9452 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9453 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
9454 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
9455 (req_ie &&
9456 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
9457 (resp_ie &&
9458 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
9459 goto nla_put_failure;
b23aa676 9460
3b7b72ee 9461 genlmsg_end(msg, hdr);
b23aa676 9462
463d0183
JB
9463 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9464 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
9465 return;
9466
9467 nla_put_failure:
9468 genlmsg_cancel(msg, hdr);
9469 nlmsg_free(msg);
9470
9471}
9472
9473void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
9474 struct net_device *netdev, const u8 *bssid,
9475 const u8 *req_ie, size_t req_ie_len,
9476 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
9477{
9478 struct sk_buff *msg;
9479 void *hdr;
9480
58050fce 9481 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
9482 if (!msg)
9483 return;
9484
9485 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
9486 if (!hdr) {
9487 nlmsg_free(msg);
9488 return;
9489 }
9490
9360ffd1
DM
9491 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9492 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9493 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
9494 (req_ie &&
9495 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
9496 (resp_ie &&
9497 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
9498 goto nla_put_failure;
b23aa676 9499
3b7b72ee 9500 genlmsg_end(msg, hdr);
b23aa676 9501
463d0183
JB
9502 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9503 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
9504 return;
9505
9506 nla_put_failure:
9507 genlmsg_cancel(msg, hdr);
9508 nlmsg_free(msg);
9509
9510}
9511
9512void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
9513 struct net_device *netdev, u16 reason,
667503dd 9514 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
9515{
9516 struct sk_buff *msg;
9517 void *hdr;
9518
58050fce 9519 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
9520 if (!msg)
9521 return;
9522
9523 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
9524 if (!hdr) {
9525 nlmsg_free(msg);
9526 return;
9527 }
9528
9360ffd1
DM
9529 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9530 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9531 (from_ap && reason &&
9532 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
9533 (from_ap &&
9534 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
9535 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
9536 goto nla_put_failure;
b23aa676 9537
3b7b72ee 9538 genlmsg_end(msg, hdr);
b23aa676 9539
463d0183
JB
9540 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9541 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
9542 return;
9543
9544 nla_put_failure:
9545 genlmsg_cancel(msg, hdr);
9546 nlmsg_free(msg);
9547
9548}
9549
04a773ad
JB
9550void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
9551 struct net_device *netdev, const u8 *bssid,
9552 gfp_t gfp)
9553{
9554 struct sk_buff *msg;
9555 void *hdr;
9556
fd2120ca 9557 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
9558 if (!msg)
9559 return;
9560
9561 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
9562 if (!hdr) {
9563 nlmsg_free(msg);
9564 return;
9565 }
9566
9360ffd1
DM
9567 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9568 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9569 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
9570 goto nla_put_failure;
04a773ad 9571
3b7b72ee 9572 genlmsg_end(msg, hdr);
04a773ad 9573
463d0183
JB
9574 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9575 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
9576 return;
9577
9578 nla_put_failure:
9579 genlmsg_cancel(msg, hdr);
9580 nlmsg_free(msg);
9581}
9582
947add36
JB
9583void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
9584 const u8* ie, u8 ie_len, gfp_t gfp)
c93b5e71 9585{
947add36
JB
9586 struct wireless_dev *wdev = dev->ieee80211_ptr;
9587 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
c93b5e71
JC
9588 struct sk_buff *msg;
9589 void *hdr;
9590
947add36
JB
9591 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
9592 return;
9593
9594 trace_cfg80211_notify_new_peer_candidate(dev, addr);
9595
c93b5e71
JC
9596 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9597 if (!msg)
9598 return;
9599
9600 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
9601 if (!hdr) {
9602 nlmsg_free(msg);
9603 return;
9604 }
9605
9360ffd1 9606 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
9607 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9608 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1
DM
9609 (ie_len && ie &&
9610 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
9611 goto nla_put_failure;
c93b5e71 9612
3b7b72ee 9613 genlmsg_end(msg, hdr);
c93b5e71
JC
9614
9615 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9616 nl80211_mlme_mcgrp.id, gfp);
9617 return;
9618
9619 nla_put_failure:
9620 genlmsg_cancel(msg, hdr);
9621 nlmsg_free(msg);
9622}
947add36 9623EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 9624
a3b8b056
JM
9625void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
9626 struct net_device *netdev, const u8 *addr,
9627 enum nl80211_key_type key_type, int key_id,
e6d6e342 9628 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
9629{
9630 struct sk_buff *msg;
9631 void *hdr;
9632
e6d6e342 9633 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
9634 if (!msg)
9635 return;
9636
9637 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
9638 if (!hdr) {
9639 nlmsg_free(msg);
9640 return;
9641 }
9642
9360ffd1
DM
9643 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9644 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9645 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
9646 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
9647 (key_id != -1 &&
9648 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
9649 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
9650 goto nla_put_failure;
a3b8b056 9651
3b7b72ee 9652 genlmsg_end(msg, hdr);
a3b8b056 9653
463d0183
JB
9654 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9655 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
9656 return;
9657
9658 nla_put_failure:
9659 genlmsg_cancel(msg, hdr);
9660 nlmsg_free(msg);
9661}
9662
6bad8766
LR
9663void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
9664 struct ieee80211_channel *channel_before,
9665 struct ieee80211_channel *channel_after)
9666{
9667 struct sk_buff *msg;
9668 void *hdr;
9669 struct nlattr *nl_freq;
9670
fd2120ca 9671 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
9672 if (!msg)
9673 return;
9674
9675 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
9676 if (!hdr) {
9677 nlmsg_free(msg);
9678 return;
9679 }
9680
9681 /*
9682 * Since we are applying the beacon hint to a wiphy we know its
9683 * wiphy_idx is valid
9684 */
9360ffd1
DM
9685 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
9686 goto nla_put_failure;
6bad8766
LR
9687
9688 /* Before */
9689 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
9690 if (!nl_freq)
9691 goto nla_put_failure;
cdc89b97 9692 if (nl80211_msg_put_channel(msg, channel_before, false))
6bad8766
LR
9693 goto nla_put_failure;
9694 nla_nest_end(msg, nl_freq);
9695
9696 /* After */
9697 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
9698 if (!nl_freq)
9699 goto nla_put_failure;
cdc89b97 9700 if (nl80211_msg_put_channel(msg, channel_after, false))
6bad8766
LR
9701 goto nla_put_failure;
9702 nla_nest_end(msg, nl_freq);
9703
3b7b72ee 9704 genlmsg_end(msg, hdr);
6bad8766 9705
463d0183
JB
9706 rcu_read_lock();
9707 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
9708 GFP_ATOMIC);
9709 rcu_read_unlock();
6bad8766
LR
9710
9711 return;
9712
9713nla_put_failure:
9714 genlmsg_cancel(msg, hdr);
9715 nlmsg_free(msg);
9716}
9717
9588bbd5
JM
9718static void nl80211_send_remain_on_chan_event(
9719 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 9720 struct wireless_dev *wdev, u64 cookie,
9588bbd5 9721 struct ieee80211_channel *chan,
9588bbd5
JM
9722 unsigned int duration, gfp_t gfp)
9723{
9724 struct sk_buff *msg;
9725 void *hdr;
9726
9727 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9728 if (!msg)
9729 return;
9730
9731 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
9732 if (!hdr) {
9733 nlmsg_free(msg);
9734 return;
9735 }
9736
9360ffd1 9737 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
9738 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9739 wdev->netdev->ifindex)) ||
00f53350 9740 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 9741 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
9742 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
9743 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
9744 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
9745 goto nla_put_failure;
9588bbd5 9746
9360ffd1
DM
9747 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
9748 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
9749 goto nla_put_failure;
9588bbd5 9750
3b7b72ee 9751 genlmsg_end(msg, hdr);
9588bbd5
JM
9752
9753 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9754 nl80211_mlme_mcgrp.id, gfp);
9755 return;
9756
9757 nla_put_failure:
9758 genlmsg_cancel(msg, hdr);
9759 nlmsg_free(msg);
9760}
9761
947add36
JB
9762void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
9763 struct ieee80211_channel *chan,
9764 unsigned int duration, gfp_t gfp)
9588bbd5 9765{
947add36
JB
9766 struct wiphy *wiphy = wdev->wiphy;
9767 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9768
9769 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 9770 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 9771 rdev, wdev, cookie, chan,
42d97a59 9772 duration, gfp);
9588bbd5 9773}
947add36 9774EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 9775
947add36
JB
9776void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
9777 struct ieee80211_channel *chan,
9778 gfp_t gfp)
9588bbd5 9779{
947add36
JB
9780 struct wiphy *wiphy = wdev->wiphy;
9781 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9782
9783 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 9784 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 9785 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 9786}
947add36 9787EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 9788
947add36
JB
9789void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
9790 struct station_info *sinfo, gfp_t gfp)
98b62183 9791{
947add36
JB
9792 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
9793 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
98b62183
JB
9794 struct sk_buff *msg;
9795
947add36
JB
9796 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
9797
58050fce 9798 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
9799 if (!msg)
9800 return;
9801
66266b3a
JL
9802 if (nl80211_send_station(msg, 0, 0, 0,
9803 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
9804 nlmsg_free(msg);
9805 return;
9806 }
9807
9808 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9809 nl80211_mlme_mcgrp.id, gfp);
9810}
947add36 9811EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 9812
947add36 9813void cfg80211_del_sta(struct net_device *dev, const u8 *mac_addr, gfp_t gfp)
ec15e68b 9814{
947add36
JB
9815 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
9816 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
ec15e68b
JM
9817 struct sk_buff *msg;
9818 void *hdr;
9819
947add36
JB
9820 trace_cfg80211_del_sta(dev, mac_addr);
9821
58050fce 9822 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
9823 if (!msg)
9824 return;
9825
9826 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
9827 if (!hdr) {
9828 nlmsg_free(msg);
9829 return;
9830 }
9831
9360ffd1
DM
9832 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9833 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
9834 goto nla_put_failure;
ec15e68b 9835
3b7b72ee 9836 genlmsg_end(msg, hdr);
ec15e68b
JM
9837
9838 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9839 nl80211_mlme_mcgrp.id, gfp);
9840 return;
9841
9842 nla_put_failure:
9843 genlmsg_cancel(msg, hdr);
9844 nlmsg_free(msg);
9845}
947add36 9846EXPORT_SYMBOL(cfg80211_del_sta);
ec15e68b 9847
947add36
JB
9848void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
9849 enum nl80211_connect_failed_reason reason,
9850 gfp_t gfp)
ed44a951 9851{
947add36
JB
9852 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
9853 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
ed44a951
PP
9854 struct sk_buff *msg;
9855 void *hdr;
9856
9857 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
9858 if (!msg)
9859 return;
9860
9861 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
9862 if (!hdr) {
9863 nlmsg_free(msg);
9864 return;
9865 }
9866
9867 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9868 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
9869 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
9870 goto nla_put_failure;
9871
9872 genlmsg_end(msg, hdr);
9873
9874 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9875 nl80211_mlme_mcgrp.id, gfp);
9876 return;
9877
9878 nla_put_failure:
9879 genlmsg_cancel(msg, hdr);
9880 nlmsg_free(msg);
9881}
947add36 9882EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 9883
b92ab5d8
JB
9884static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
9885 const u8 *addr, gfp_t gfp)
28946da7
JB
9886{
9887 struct wireless_dev *wdev = dev->ieee80211_ptr;
9888 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9889 struct sk_buff *msg;
9890 void *hdr;
15e47304 9891 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 9892
15e47304 9893 if (!nlportid)
28946da7
JB
9894 return false;
9895
9896 msg = nlmsg_new(100, gfp);
9897 if (!msg)
9898 return true;
9899
b92ab5d8 9900 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
9901 if (!hdr) {
9902 nlmsg_free(msg);
9903 return true;
9904 }
9905
9360ffd1
DM
9906 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9907 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9908 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
9909 goto nla_put_failure;
28946da7 9910
9c90a9f6 9911 genlmsg_end(msg, hdr);
15e47304 9912 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
9913 return true;
9914
9915 nla_put_failure:
9916 genlmsg_cancel(msg, hdr);
9917 nlmsg_free(msg);
9918 return true;
9919}
9920
947add36
JB
9921bool cfg80211_rx_spurious_frame(struct net_device *dev,
9922 const u8 *addr, gfp_t gfp)
b92ab5d8 9923{
947add36
JB
9924 struct wireless_dev *wdev = dev->ieee80211_ptr;
9925 bool ret;
9926
9927 trace_cfg80211_rx_spurious_frame(dev, addr);
9928
9929 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
9930 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
9931 trace_cfg80211_return_bool(false);
9932 return false;
9933 }
9934 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
9935 addr, gfp);
9936 trace_cfg80211_return_bool(ret);
9937 return ret;
b92ab5d8 9938}
947add36 9939EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 9940
947add36
JB
9941bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
9942 const u8 *addr, gfp_t gfp)
b92ab5d8 9943{
947add36
JB
9944 struct wireless_dev *wdev = dev->ieee80211_ptr;
9945 bool ret;
9946
9947 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
9948
9949 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
9950 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
9951 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
9952 trace_cfg80211_return_bool(false);
9953 return false;
9954 }
9955 ret = __nl80211_unexpected_frame(dev,
9956 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
9957 addr, gfp);
9958 trace_cfg80211_return_bool(ret);
9959 return ret;
b92ab5d8 9960}
947add36 9961EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 9962
2e161f78 9963int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 9964 struct wireless_dev *wdev, u32 nlportid,
804483e9
JB
9965 int freq, int sig_dbm,
9966 const u8 *buf, size_t len, gfp_t gfp)
026331c4 9967{
71bbc994 9968 struct net_device *netdev = wdev->netdev;
026331c4
JM
9969 struct sk_buff *msg;
9970 void *hdr;
026331c4
JM
9971
9972 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9973 if (!msg)
9974 return -ENOMEM;
9975
2e161f78 9976 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
9977 if (!hdr) {
9978 nlmsg_free(msg);
9979 return -ENOMEM;
9980 }
9981
9360ffd1 9982 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
9983 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9984 netdev->ifindex)) ||
a838490b 9985 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
9986 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
9987 (sig_dbm &&
9988 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9989 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
9990 goto nla_put_failure;
026331c4 9991
3b7b72ee 9992 genlmsg_end(msg, hdr);
026331c4 9993
15e47304 9994 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
9995
9996 nla_put_failure:
9997 genlmsg_cancel(msg, hdr);
9998 nlmsg_free(msg);
9999 return -ENOBUFS;
10000}
10001
947add36
JB
10002void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
10003 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 10004{
947add36
JB
10005 struct wiphy *wiphy = wdev->wiphy;
10006 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
71bbc994 10007 struct net_device *netdev = wdev->netdev;
026331c4
JM
10008 struct sk_buff *msg;
10009 void *hdr;
10010
947add36
JB
10011 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
10012
026331c4
JM
10013 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10014 if (!msg)
10015 return;
10016
2e161f78 10017 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
10018 if (!hdr) {
10019 nlmsg_free(msg);
10020 return;
10021 }
10022
9360ffd1 10023 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10024 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10025 netdev->ifindex)) ||
a838490b 10026 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
10027 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
10028 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
10029 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
10030 goto nla_put_failure;
026331c4 10031
3b7b72ee 10032 genlmsg_end(msg, hdr);
026331c4
JM
10033
10034 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
10035 return;
10036
10037 nla_put_failure:
10038 genlmsg_cancel(msg, hdr);
10039 nlmsg_free(msg);
10040}
947add36 10041EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 10042
947add36
JB
10043void cfg80211_cqm_rssi_notify(struct net_device *dev,
10044 enum nl80211_cqm_rssi_threshold_event rssi_event,
10045 gfp_t gfp)
d6dc1a38 10046{
947add36
JB
10047 struct wireless_dev *wdev = dev->ieee80211_ptr;
10048 struct wiphy *wiphy = wdev->wiphy;
10049 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
d6dc1a38
JO
10050 struct sk_buff *msg;
10051 struct nlattr *pinfoattr;
10052 void *hdr;
10053
947add36
JB
10054 trace_cfg80211_cqm_rssi_notify(dev, rssi_event);
10055
58050fce 10056 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
10057 if (!msg)
10058 return;
10059
10060 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10061 if (!hdr) {
10062 nlmsg_free(msg);
10063 return;
10064 }
10065
9360ffd1 10066 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10067 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 10068 goto nla_put_failure;
d6dc1a38
JO
10069
10070 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10071 if (!pinfoattr)
10072 goto nla_put_failure;
10073
9360ffd1
DM
10074 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
10075 rssi_event))
10076 goto nla_put_failure;
d6dc1a38
JO
10077
10078 nla_nest_end(msg, pinfoattr);
10079
3b7b72ee 10080 genlmsg_end(msg, hdr);
d6dc1a38
JO
10081
10082 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10083 nl80211_mlme_mcgrp.id, gfp);
10084 return;
10085
10086 nla_put_failure:
10087 genlmsg_cancel(msg, hdr);
10088 nlmsg_free(msg);
10089}
947add36 10090EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 10091
947add36
JB
10092static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
10093 struct net_device *netdev, const u8 *bssid,
10094 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
10095{
10096 struct sk_buff *msg;
10097 struct nlattr *rekey_attr;
10098 void *hdr;
10099
58050fce 10100 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
10101 if (!msg)
10102 return;
10103
10104 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
10105 if (!hdr) {
10106 nlmsg_free(msg);
10107 return;
10108 }
10109
9360ffd1
DM
10110 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10111 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10112 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
10113 goto nla_put_failure;
e5497d76
JB
10114
10115 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
10116 if (!rekey_attr)
10117 goto nla_put_failure;
10118
9360ffd1
DM
10119 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
10120 NL80211_REPLAY_CTR_LEN, replay_ctr))
10121 goto nla_put_failure;
e5497d76
JB
10122
10123 nla_nest_end(msg, rekey_attr);
10124
3b7b72ee 10125 genlmsg_end(msg, hdr);
e5497d76
JB
10126
10127 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10128 nl80211_mlme_mcgrp.id, gfp);
10129 return;
10130
10131 nla_put_failure:
10132 genlmsg_cancel(msg, hdr);
10133 nlmsg_free(msg);
10134}
10135
947add36
JB
10136void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
10137 const u8 *replay_ctr, gfp_t gfp)
10138{
10139 struct wireless_dev *wdev = dev->ieee80211_ptr;
10140 struct wiphy *wiphy = wdev->wiphy;
10141 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10142
10143 trace_cfg80211_gtk_rekey_notify(dev, bssid);
10144 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
10145}
10146EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
10147
10148static void
10149nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
10150 struct net_device *netdev, int index,
10151 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
10152{
10153 struct sk_buff *msg;
10154 struct nlattr *attr;
10155 void *hdr;
10156
58050fce 10157 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
10158 if (!msg)
10159 return;
10160
10161 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
10162 if (!hdr) {
10163 nlmsg_free(msg);
10164 return;
10165 }
10166
9360ffd1
DM
10167 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10168 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
10169 goto nla_put_failure;
c9df56b4
JM
10170
10171 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
10172 if (!attr)
10173 goto nla_put_failure;
10174
9360ffd1
DM
10175 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
10176 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
10177 (preauth &&
10178 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
10179 goto nla_put_failure;
c9df56b4
JM
10180
10181 nla_nest_end(msg, attr);
10182
3b7b72ee 10183 genlmsg_end(msg, hdr);
c9df56b4
JM
10184
10185 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10186 nl80211_mlme_mcgrp.id, gfp);
10187 return;
10188
10189 nla_put_failure:
10190 genlmsg_cancel(msg, hdr);
10191 nlmsg_free(msg);
10192}
10193
947add36
JB
10194void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
10195 const u8 *bssid, bool preauth, gfp_t gfp)
10196{
10197 struct wireless_dev *wdev = dev->ieee80211_ptr;
10198 struct wiphy *wiphy = wdev->wiphy;
10199 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10200
10201 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
10202 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
10203}
10204EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
10205
10206static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
10207 struct net_device *netdev,
10208 struct cfg80211_chan_def *chandef,
10209 gfp_t gfp)
5314526b
TP
10210{
10211 struct sk_buff *msg;
10212 void *hdr;
10213
58050fce 10214 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
10215 if (!msg)
10216 return;
10217
10218 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
10219 if (!hdr) {
10220 nlmsg_free(msg);
10221 return;
10222 }
10223
683b6d3b
JB
10224 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
10225 goto nla_put_failure;
10226
10227 if (nl80211_send_chandef(msg, chandef))
7eab0f64 10228 goto nla_put_failure;
5314526b
TP
10229
10230 genlmsg_end(msg, hdr);
10231
10232 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10233 nl80211_mlme_mcgrp.id, gfp);
10234 return;
10235
10236 nla_put_failure:
10237 genlmsg_cancel(msg, hdr);
10238 nlmsg_free(msg);
10239}
10240
947add36
JB
10241void cfg80211_ch_switch_notify(struct net_device *dev,
10242 struct cfg80211_chan_def *chandef)
84f10708 10243{
947add36
JB
10244 struct wireless_dev *wdev = dev->ieee80211_ptr;
10245 struct wiphy *wiphy = wdev->wiphy;
10246 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10247
10248 trace_cfg80211_ch_switch_notify(dev, chandef);
10249
10250 wdev_lock(wdev);
10251
10252 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
10253 wdev->iftype != NL80211_IFTYPE_P2P_GO))
10254 goto out;
10255
10256 wdev->channel = chandef->chan;
10257 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL);
10258out:
10259 wdev_unlock(wdev);
10260 return;
10261}
10262EXPORT_SYMBOL(cfg80211_ch_switch_notify);
10263
10264void cfg80211_cqm_txe_notify(struct net_device *dev,
10265 const u8 *peer, u32 num_packets,
10266 u32 rate, u32 intvl, gfp_t gfp)
10267{
10268 struct wireless_dev *wdev = dev->ieee80211_ptr;
10269 struct wiphy *wiphy = wdev->wiphy;
10270 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
84f10708
TP
10271 struct sk_buff *msg;
10272 struct nlattr *pinfoattr;
10273 void *hdr;
10274
10275 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
10276 if (!msg)
10277 return;
10278
10279 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10280 if (!hdr) {
10281 nlmsg_free(msg);
10282 return;
10283 }
10284
10285 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10286 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
84f10708
TP
10287 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
10288 goto nla_put_failure;
10289
10290 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10291 if (!pinfoattr)
10292 goto nla_put_failure;
10293
10294 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
10295 goto nla_put_failure;
10296
10297 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
10298 goto nla_put_failure;
10299
10300 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
10301 goto nla_put_failure;
10302
10303 nla_nest_end(msg, pinfoattr);
10304
10305 genlmsg_end(msg, hdr);
10306
10307 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10308 nl80211_mlme_mcgrp.id, gfp);
10309 return;
10310
10311 nla_put_failure:
10312 genlmsg_cancel(msg, hdr);
10313 nlmsg_free(msg);
10314}
947add36 10315EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
84f10708 10316
04f39047
SW
10317void
10318nl80211_radar_notify(struct cfg80211_registered_device *rdev,
10319 struct cfg80211_chan_def *chandef,
10320 enum nl80211_radar_event event,
10321 struct net_device *netdev, gfp_t gfp)
10322{
10323 struct sk_buff *msg;
10324 void *hdr;
10325
10326 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10327 if (!msg)
10328 return;
10329
10330 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
10331 if (!hdr) {
10332 nlmsg_free(msg);
10333 return;
10334 }
10335
10336 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
10337 goto nla_put_failure;
10338
10339 /* NOP and radar events don't need a netdev parameter */
10340 if (netdev) {
10341 struct wireless_dev *wdev = netdev->ieee80211_ptr;
10342
10343 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10344 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
10345 goto nla_put_failure;
10346 }
10347
10348 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
10349 goto nla_put_failure;
10350
10351 if (nl80211_send_chandef(msg, chandef))
10352 goto nla_put_failure;
10353
9c90a9f6 10354 genlmsg_end(msg, hdr);
04f39047
SW
10355
10356 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10357 nl80211_mlme_mcgrp.id, gfp);
10358 return;
10359
10360 nla_put_failure:
10361 genlmsg_cancel(msg, hdr);
10362 nlmsg_free(msg);
10363}
10364
947add36
JB
10365void cfg80211_cqm_pktloss_notify(struct net_device *dev,
10366 const u8 *peer, u32 num_packets, gfp_t gfp)
c063dbf5 10367{
947add36
JB
10368 struct wireless_dev *wdev = dev->ieee80211_ptr;
10369 struct wiphy *wiphy = wdev->wiphy;
10370 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
c063dbf5
JB
10371 struct sk_buff *msg;
10372 struct nlattr *pinfoattr;
10373 void *hdr;
10374
947add36
JB
10375 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
10376
58050fce 10377 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
10378 if (!msg)
10379 return;
10380
10381 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10382 if (!hdr) {
10383 nlmsg_free(msg);
10384 return;
10385 }
10386
9360ffd1 10387 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10388 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9360ffd1
DM
10389 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
10390 goto nla_put_failure;
c063dbf5
JB
10391
10392 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10393 if (!pinfoattr)
10394 goto nla_put_failure;
10395
9360ffd1
DM
10396 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
10397 goto nla_put_failure;
c063dbf5
JB
10398
10399 nla_nest_end(msg, pinfoattr);
10400
3b7b72ee 10401 genlmsg_end(msg, hdr);
c063dbf5
JB
10402
10403 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10404 nl80211_mlme_mcgrp.id, gfp);
10405 return;
10406
10407 nla_put_failure:
10408 genlmsg_cancel(msg, hdr);
10409 nlmsg_free(msg);
10410}
947add36 10411EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
c063dbf5 10412
7f6cf311
JB
10413void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
10414 u64 cookie, bool acked, gfp_t gfp)
10415{
10416 struct wireless_dev *wdev = dev->ieee80211_ptr;
10417 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
10418 struct sk_buff *msg;
10419 void *hdr;
7f6cf311 10420
4ee3e063
BL
10421 trace_cfg80211_probe_status(dev, addr, cookie, acked);
10422
58050fce 10423 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 10424
7f6cf311
JB
10425 if (!msg)
10426 return;
10427
10428 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
10429 if (!hdr) {
10430 nlmsg_free(msg);
10431 return;
10432 }
10433
9360ffd1
DM
10434 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10435 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10436 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
10437 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
10438 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
10439 goto nla_put_failure;
7f6cf311 10440
9c90a9f6 10441 genlmsg_end(msg, hdr);
7f6cf311
JB
10442
10443 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10444 nl80211_mlme_mcgrp.id, gfp);
10445 return;
10446
10447 nla_put_failure:
10448 genlmsg_cancel(msg, hdr);
10449 nlmsg_free(msg);
10450}
10451EXPORT_SYMBOL(cfg80211_probe_status);
10452
5e760230
JB
10453void cfg80211_report_obss_beacon(struct wiphy *wiphy,
10454 const u8 *frame, size_t len,
37c73b5f 10455 int freq, int sig_dbm)
5e760230
JB
10456{
10457 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10458 struct sk_buff *msg;
10459 void *hdr;
37c73b5f 10460 struct cfg80211_beacon_registration *reg;
5e760230 10461
4ee3e063
BL
10462 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
10463
37c73b5f
BG
10464 spin_lock_bh(&rdev->beacon_registrations_lock);
10465 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
10466 msg = nlmsg_new(len + 100, GFP_ATOMIC);
10467 if (!msg) {
10468 spin_unlock_bh(&rdev->beacon_registrations_lock);
10469 return;
10470 }
5e760230 10471
37c73b5f
BG
10472 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
10473 if (!hdr)
10474 goto nla_put_failure;
5e760230 10475
37c73b5f
BG
10476 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10477 (freq &&
10478 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
10479 (sig_dbm &&
10480 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
10481 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
10482 goto nla_put_failure;
5e760230 10483
37c73b5f 10484 genlmsg_end(msg, hdr);
5e760230 10485
37c73b5f
BG
10486 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
10487 }
10488 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
10489 return;
10490
10491 nla_put_failure:
37c73b5f
BG
10492 spin_unlock_bh(&rdev->beacon_registrations_lock);
10493 if (hdr)
10494 genlmsg_cancel(msg, hdr);
5e760230
JB
10495 nlmsg_free(msg);
10496}
10497EXPORT_SYMBOL(cfg80211_report_obss_beacon);
10498
cd8f7cb4
JB
10499#ifdef CONFIG_PM
10500void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
10501 struct cfg80211_wowlan_wakeup *wakeup,
10502 gfp_t gfp)
10503{
10504 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
10505 struct sk_buff *msg;
10506 void *hdr;
9c90a9f6 10507 int size = 200;
cd8f7cb4
JB
10508
10509 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
10510
10511 if (wakeup)
10512 size += wakeup->packet_present_len;
10513
10514 msg = nlmsg_new(size, gfp);
10515 if (!msg)
10516 return;
10517
10518 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
10519 if (!hdr)
10520 goto free_msg;
10521
10522 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10523 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
10524 goto free_msg;
10525
10526 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10527 wdev->netdev->ifindex))
10528 goto free_msg;
10529
10530 if (wakeup) {
10531 struct nlattr *reasons;
10532
10533 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
10534
10535 if (wakeup->disconnect &&
10536 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
10537 goto free_msg;
10538 if (wakeup->magic_pkt &&
10539 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
10540 goto free_msg;
10541 if (wakeup->gtk_rekey_failure &&
10542 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
10543 goto free_msg;
10544 if (wakeup->eap_identity_req &&
10545 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
10546 goto free_msg;
10547 if (wakeup->four_way_handshake &&
10548 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
10549 goto free_msg;
10550 if (wakeup->rfkill_release &&
10551 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
10552 goto free_msg;
10553
10554 if (wakeup->pattern_idx >= 0 &&
10555 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
10556 wakeup->pattern_idx))
10557 goto free_msg;
10558
2a0e047e
JB
10559 if (wakeup->tcp_match)
10560 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH);
10561
10562 if (wakeup->tcp_connlost)
10563 nla_put_flag(msg,
10564 NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST);
10565
10566 if (wakeup->tcp_nomoretokens)
10567 nla_put_flag(msg,
10568 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS);
10569
cd8f7cb4
JB
10570 if (wakeup->packet) {
10571 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
10572 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
10573
10574 if (!wakeup->packet_80211) {
10575 pkt_attr =
10576 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
10577 len_attr =
10578 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
10579 }
10580
10581 if (wakeup->packet_len &&
10582 nla_put_u32(msg, len_attr, wakeup->packet_len))
10583 goto free_msg;
10584
10585 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
10586 wakeup->packet))
10587 goto free_msg;
10588 }
10589
10590 nla_nest_end(msg, reasons);
10591 }
10592
9c90a9f6 10593 genlmsg_end(msg, hdr);
cd8f7cb4
JB
10594
10595 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10596 nl80211_mlme_mcgrp.id, gfp);
10597 return;
10598
10599 free_msg:
10600 nlmsg_free(msg);
10601}
10602EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
10603#endif
10604
3475b094
JM
10605void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
10606 enum nl80211_tdls_operation oper,
10607 u16 reason_code, gfp_t gfp)
10608{
10609 struct wireless_dev *wdev = dev->ieee80211_ptr;
10610 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
10611 struct sk_buff *msg;
10612 void *hdr;
3475b094
JM
10613
10614 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
10615 reason_code);
10616
10617 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10618 if (!msg)
10619 return;
10620
10621 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
10622 if (!hdr) {
10623 nlmsg_free(msg);
10624 return;
10625 }
10626
10627 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10628 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10629 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
10630 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
10631 (reason_code > 0 &&
10632 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
10633 goto nla_put_failure;
10634
9c90a9f6 10635 genlmsg_end(msg, hdr);
3475b094
JM
10636
10637 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10638 nl80211_mlme_mcgrp.id, gfp);
10639 return;
10640
10641 nla_put_failure:
10642 genlmsg_cancel(msg, hdr);
10643 nlmsg_free(msg);
10644}
10645EXPORT_SYMBOL(cfg80211_tdls_oper_request);
10646
026331c4
JM
10647static int nl80211_netlink_notify(struct notifier_block * nb,
10648 unsigned long state,
10649 void *_notify)
10650{
10651 struct netlink_notify *notify = _notify;
10652 struct cfg80211_registered_device *rdev;
10653 struct wireless_dev *wdev;
37c73b5f 10654 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
10655
10656 if (state != NETLINK_URELEASE)
10657 return NOTIFY_DONE;
10658
10659 rcu_read_lock();
10660
5e760230 10661 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 10662 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 10663 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
10664
10665 spin_lock_bh(&rdev->beacon_registrations_lock);
10666 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
10667 list) {
10668 if (reg->nlportid == notify->portid) {
10669 list_del(&reg->list);
10670 kfree(reg);
10671 break;
10672 }
10673 }
10674 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 10675 }
026331c4
JM
10676
10677 rcu_read_unlock();
10678
10679 return NOTIFY_DONE;
10680}
10681
10682static struct notifier_block nl80211_netlink_notifier = {
10683 .notifier_call = nl80211_netlink_notify,
10684};
10685
355199e0
JM
10686void cfg80211_ft_event(struct net_device *netdev,
10687 struct cfg80211_ft_event_params *ft_event)
10688{
10689 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
10690 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10691 struct sk_buff *msg;
10692 void *hdr;
355199e0
JM
10693
10694 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
10695
10696 if (!ft_event->target_ap)
10697 return;
10698
10699 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10700 if (!msg)
10701 return;
10702
10703 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
10704 if (!hdr) {
10705 nlmsg_free(msg);
10706 return;
10707 }
10708
10709 nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
10710 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
10711 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap);
10712 if (ft_event->ies)
10713 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies);
10714 if (ft_event->ric_ies)
10715 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
10716 ft_event->ric_ies);
10717
9c90a9f6 10718 genlmsg_end(msg, hdr);
355199e0
JM
10719
10720 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
10721 nl80211_mlme_mcgrp.id, GFP_KERNEL);
10722}
10723EXPORT_SYMBOL(cfg80211_ft_event);
10724
5de17984
AS
10725void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
10726{
10727 struct cfg80211_registered_device *rdev;
10728 struct sk_buff *msg;
10729 void *hdr;
10730 u32 nlportid;
10731
10732 rdev = wiphy_to_dev(wdev->wiphy);
10733 if (!rdev->crit_proto_nlportid)
10734 return;
10735
10736 nlportid = rdev->crit_proto_nlportid;
10737 rdev->crit_proto_nlportid = 0;
10738
10739 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10740 if (!msg)
10741 return;
10742
10743 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
10744 if (!hdr)
10745 goto nla_put_failure;
10746
10747 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10748 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
10749 goto nla_put_failure;
10750
10751 genlmsg_end(msg, hdr);
10752
10753 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
10754 return;
10755
10756 nla_put_failure:
10757 if (hdr)
10758 genlmsg_cancel(msg, hdr);
10759 nlmsg_free(msg);
10760
10761}
10762EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
10763
55682965
JB
10764/* initialisation/exit functions */
10765
10766int nl80211_init(void)
10767{
0d63cbb5 10768 int err;
55682965 10769
0d63cbb5
MM
10770 err = genl_register_family_with_ops(&nl80211_fam,
10771 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
10772 if (err)
10773 return err;
10774
55682965
JB
10775 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
10776 if (err)
10777 goto err_out;
10778
2a519311
JB
10779 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
10780 if (err)
10781 goto err_out;
10782
73d54c9e
LR
10783 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
10784 if (err)
10785 goto err_out;
10786
6039f6d2
JM
10787 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
10788 if (err)
10789 goto err_out;
10790
aff89a9b
JB
10791#ifdef CONFIG_NL80211_TESTMODE
10792 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
10793 if (err)
10794 goto err_out;
10795#endif
10796
026331c4
JM
10797 err = netlink_register_notifier(&nl80211_netlink_notifier);
10798 if (err)
10799 goto err_out;
10800
55682965
JB
10801 return 0;
10802 err_out:
10803 genl_unregister_family(&nl80211_fam);
10804 return err;
10805}
10806
10807void nl80211_exit(void)
10808{
026331c4 10809 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
10810 genl_unregister_family(&nl80211_fam);
10811}