]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
cfg80211: Add Fast Initial Link Setup (FILS) auth algs
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
2740f0cf 5 * Copyright 2013-2014 Intel Mobile Communications GmbH
0c9ca11b 6 * Copyright 2015-2016 Intel Deutschland GmbH
55682965
JB
7 */
8
9#include <linux/if.h>
10#include <linux/module.h>
11#include <linux/err.h>
5a0e3ad6 12#include <linux/slab.h>
55682965
JB
13#include <linux/list.h>
14#include <linux/if_ether.h>
15#include <linux/ieee80211.h>
16#include <linux/nl80211.h>
17#include <linux/rtnetlink.h>
18#include <linux/netlink.h>
2a519311 19#include <linux/etherdevice.h>
463d0183 20#include <net/net_namespace.h>
55682965
JB
21#include <net/genetlink.h>
22#include <net/cfg80211.h>
463d0183 23#include <net/sock.h>
2a0e047e 24#include <net/inet_connection_sock.h>
55682965
JB
25#include "core.h"
26#include "nl80211.h"
b2e1b302 27#include "reg.h"
e35e4d28 28#include "rdev-ops.h"
55682965 29
5fb628e9
JM
30static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
31 struct genl_info *info,
32 struct cfg80211_crypto_settings *settings,
33 int cipher_limit);
34
f84f771d 35static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991 36 struct genl_info *info);
f84f771d 37static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
38 struct genl_info *info);
39
55682965
JB
40/* the netlink family */
41static struct genl_family nl80211_fam = {
fb4e1568
MH
42 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
43 .name = NL80211_GENL_NAME, /* have users key off the name instead */
44 .hdrsize = 0, /* no private header */
45 .version = 1, /* no particular meaning now */
55682965 46 .maxattr = NL80211_ATTR_MAX,
463d0183 47 .netnsok = true,
4c476991
JB
48 .pre_doit = nl80211_pre_doit,
49 .post_doit = nl80211_post_doit,
55682965
JB
50};
51
2a94fe48
JB
52/* multicast groups */
53enum nl80211_multicast_groups {
54 NL80211_MCGRP_CONFIG,
55 NL80211_MCGRP_SCAN,
56 NL80211_MCGRP_REGULATORY,
57 NL80211_MCGRP_MLME,
567ffc35 58 NL80211_MCGRP_VENDOR,
50bcd31d 59 NL80211_MCGRP_NAN,
2a94fe48
JB
60 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
61};
62
63static const struct genl_multicast_group nl80211_mcgrps[] = {
71b836ec
JB
64 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG },
65 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN },
66 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG },
67 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME },
68 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR },
50bcd31d 69 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN },
2a94fe48 70#ifdef CONFIG_NL80211_TESTMODE
71b836ec 71 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE }
2a94fe48
JB
72#endif
73};
74
89a54e48
JB
75/* returns ERR_PTR values */
76static struct wireless_dev *
77__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 78{
89a54e48
JB
79 struct cfg80211_registered_device *rdev;
80 struct wireless_dev *result = NULL;
81 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
82 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
83 u64 wdev_id;
84 int wiphy_idx = -1;
85 int ifidx = -1;
55682965 86
5fe231e8 87 ASSERT_RTNL();
55682965 88
89a54e48
JB
89 if (!have_ifidx && !have_wdev_id)
90 return ERR_PTR(-EINVAL);
55682965 91
89a54e48
JB
92 if (have_ifidx)
93 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
94 if (have_wdev_id) {
95 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
96 wiphy_idx = wdev_id >> 32;
55682965
JB
97 }
98
89a54e48
JB
99 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
100 struct wireless_dev *wdev;
101
102 if (wiphy_net(&rdev->wiphy) != netns)
103 continue;
104
105 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
106 continue;
107
53873f13 108 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
89a54e48
JB
109 if (have_ifidx && wdev->netdev &&
110 wdev->netdev->ifindex == ifidx) {
111 result = wdev;
112 break;
113 }
114 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
115 result = wdev;
116 break;
117 }
118 }
89a54e48
JB
119
120 if (result)
121 break;
122 }
123
124 if (result)
125 return result;
126 return ERR_PTR(-ENODEV);
55682965
JB
127}
128
a9455408 129static struct cfg80211_registered_device *
878d9ec7 130__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 131{
7fee4778
JB
132 struct cfg80211_registered_device *rdev = NULL, *tmp;
133 struct net_device *netdev;
a9455408 134
5fe231e8 135 ASSERT_RTNL();
a9455408 136
878d9ec7 137 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
138 !attrs[NL80211_ATTR_IFINDEX] &&
139 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
140 return ERR_PTR(-EINVAL);
141
878d9ec7 142 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 143 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 144 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 145
89a54e48
JB
146 if (attrs[NL80211_ATTR_WDEV]) {
147 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
148 struct wireless_dev *wdev;
149 bool found = false;
150
151 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
152 if (tmp) {
153 /* make sure wdev exists */
53873f13 154 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) {
89a54e48
JB
155 if (wdev->identifier != (u32)wdev_id)
156 continue;
157 found = true;
158 break;
159 }
89a54e48
JB
160
161 if (!found)
162 tmp = NULL;
163
164 if (rdev && tmp != rdev)
165 return ERR_PTR(-EINVAL);
166 rdev = tmp;
167 }
168 }
169
878d9ec7
JB
170 if (attrs[NL80211_ATTR_IFINDEX]) {
171 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
7a087e74 172
7f2b8562 173 netdev = __dev_get_by_index(netns, ifindex);
7fee4778
JB
174 if (netdev) {
175 if (netdev->ieee80211_ptr)
f26cbf40
ZG
176 tmp = wiphy_to_rdev(
177 netdev->ieee80211_ptr->wiphy);
7fee4778
JB
178 else
179 tmp = NULL;
180
7fee4778
JB
181 /* not wireless device -- return error */
182 if (!tmp)
183 return ERR_PTR(-EINVAL);
184
185 /* mismatch -- return error */
186 if (rdev && tmp != rdev)
187 return ERR_PTR(-EINVAL);
188
189 rdev = tmp;
a9455408 190 }
a9455408 191 }
a9455408 192
4f7eff10
JB
193 if (!rdev)
194 return ERR_PTR(-ENODEV);
a9455408 195
4f7eff10
JB
196 if (netns != wiphy_net(&rdev->wiphy))
197 return ERR_PTR(-ENODEV);
198
199 return rdev;
a9455408
JB
200}
201
202/*
203 * This function returns a pointer to the driver
204 * that the genl_info item that is passed refers to.
a9455408
JB
205 *
206 * The result of this can be a PTR_ERR and hence must
207 * be checked with IS_ERR() for errors.
208 */
209static struct cfg80211_registered_device *
4f7eff10 210cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 211{
5fe231e8 212 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
213}
214
55682965 215/* policy for the attributes */
8cd4d456 216static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
55682965
JB
217 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
218 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 219 .len = 20-1 },
31888487 220 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 221
72bdcf34 222 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 223 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
224 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
225 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
226 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
227
b9a5f8ca
JM
228 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
229 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
230 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
231 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 232 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
3057dbfd 233 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG },
55682965
JB
234
235 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
236 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
237 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 238
e007b857
EP
239 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
240 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 241
b9454e83 242 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
243 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
244 .len = WLAN_MAX_KEY_LEN },
245 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
246 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
247 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 248 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 249 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
250
251 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
252 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
253 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
254 .len = IEEE80211_MAX_DATA_LEN },
255 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
256 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
257 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
258 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
259 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
260 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
261 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 262 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 263 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 264 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 265 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 266 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 267 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 268
b2e1b302
LR
269 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
270 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
271
9f1ba906
JM
272 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
273 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
274 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
275 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
276 .len = NL80211_MAX_SUPP_RATES },
50b12f59 277 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 278
24bdd9f4 279 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 280 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 281
6c739419 282 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
283
284 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
285 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
286 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
287 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
288 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
289
290 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
291 .len = IEEE80211_MAX_SSID_LEN },
292 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
293 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 294 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 295 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 296 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
297 [NL80211_ATTR_STA_FLAGS2] = {
298 .len = sizeof(struct nl80211_sta_flag_update),
299 },
3f77316c 300 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
301 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
302 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
303 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
304 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
305 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 306 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 307 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
308 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
309 .len = WLAN_PMKID_LEN },
9588bbd5
JM
310 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
311 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 312 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
313 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
314 .len = IEEE80211_MAX_DATA_LEN },
315 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 316 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 317 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 318 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 319 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
320 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
321 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 322 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
323 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
324 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 325 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 326 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 327 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 328 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 329 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 330 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 331 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 332 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 333 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
334 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
335 .len = IEEE80211_MAX_DATA_LEN },
336 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
337 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 338 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 339 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 340 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
341 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
342 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
343 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
344 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
345 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
31fa97c5 346 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG },
e247bd90 347 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
348 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
349 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 350 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
351 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
352 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
353 .len = NL80211_HT_CAPABILITY_LEN
354 },
1d9d9213 355 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 356 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 357 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 358 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 359 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
11b6b5a4 360 [NL80211_ATTR_AUTH_DATA] = { .type = NLA_BINARY, },
f461be3e 361 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 362 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
363 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
364 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
365 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
366 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
367 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
368 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 369 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
370 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
371 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
372 .len = NL80211_VHT_CAPABILITY_LEN,
373 },
355199e0
JM
374 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
375 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
376 .len = IEEE80211_MAX_DATA_LEN },
5e4b6f56 377 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 },
16ef1fe2
SW
378 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
379 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
380 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
9a774c78
AO
381 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY },
382 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY },
c01fc9ad
SD
383 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY },
384 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY },
5336fa88 385 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
60f4a7b1 386 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
ad7e718c
JB
387 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
388 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
389 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
fa9ffc74
KP
390 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY,
391 .len = IEEE80211_QOS_MAP_LEN_MAX },
1df4a510
JM
392 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN },
393 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
df942e7b 394 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 },
18e5ca65 395 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG },
34d22ce2 396 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY },
bab5ab7d 397 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG },
960d01ac
JB
398 [NL80211_ATTR_TSID] = { .type = NLA_U8 },
399 [NL80211_ATTR_USER_PRIO] = { .type = NLA_U8 },
400 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 },
18998c38 401 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 },
ad2b26ab 402 [NL80211_ATTR_MAC_MASK] = { .len = ETH_ALEN },
1bdd716c 403 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG },
4b681c82 404 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 },
9c748934 405 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 },
05050753 406 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG },
34d50519 407 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG },
38de03d2 408 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED },
17b94247 409 [NL80211_ATTR_STA_SUPPORT_P2P_PS] = { .type = NLA_U8 },
c6e6a0c8
AE
410 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = {
411 .len = VHT_MUMIMO_GROUPS_DATA_LEN
412 },
413 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = { .len = ETH_ALEN },
cb3b7d87
AB
414 [NL80211_ATTR_NAN_MASTER_PREF] = { .type = NLA_U8 },
415 [NL80211_ATTR_NAN_DUAL] = { .type = NLA_U8 },
a442b761 416 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED },
55682965
JB
417};
418
e31b8213 419/* policy for the key attributes */
b54452b0 420static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 421 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
422 [NL80211_KEY_IDX] = { .type = NLA_U8 },
423 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 424 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
425 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
426 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 427 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
428 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
429};
430
431/* policy for the key default flags */
432static const struct nla_policy
433nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
434 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
435 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
436};
437
f83ace3b 438#ifdef CONFIG_PM
ff1b6e69
JB
439/* policy for WoWLAN attributes */
440static const struct nla_policy
441nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
442 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
443 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
444 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
445 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
446 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
447 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
448 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
449 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e 450 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
8cd4d456 451 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED },
2a0e047e
JB
452};
453
454static const struct nla_policy
455nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
456 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
457 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
458 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
459 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
460 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
461 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
462 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
463 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
464 },
465 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
466 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
467 },
468 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
469 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
470 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69 471};
f83ace3b 472#endif /* CONFIG_PM */
ff1b6e69 473
be29b99a
AK
474/* policy for coalesce rule attributes */
475static const struct nla_policy
476nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
477 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
478 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 },
479 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
480};
481
e5497d76
JB
482/* policy for GTK rekey offload attributes */
483static const struct nla_policy
484nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
485 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
486 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
487 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
488};
489
a1f1c21c
LC
490static const struct nla_policy
491nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 492 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 493 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 494 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
495};
496
3b06d277
AS
497static const struct nla_policy
498nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = {
499 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 },
500 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 },
501};
502
38de03d2
AS
503static const struct nla_policy
504nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = {
505 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG },
506 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 },
507 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = {
508 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
509 },
510};
511
a442b761
AB
512/* policy for NAN function attributes */
513static const struct nla_policy
514nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = {
515 [NL80211_NAN_FUNC_TYPE] = { .type = NLA_U8 },
516 [NL80211_NAN_FUNC_SERVICE_ID] = { .type = NLA_BINARY,
517 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN },
518 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 },
519 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG },
520 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG },
521 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 },
522 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 },
523 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = { .len = ETH_ALEN },
524 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG },
525 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 },
526 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY,
527 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN },
528 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED },
529 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED },
530 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED },
531 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 },
532 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 },
533};
534
535/* policy for Service Response Filter attributes */
536static const struct nla_policy
537nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = {
538 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG },
539 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY,
540 .len = NL80211_NAN_FUNC_SRF_MAX_LEN },
541 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 },
542 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED },
543};
544
97990a06
JB
545static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
546 struct netlink_callback *cb,
547 struct cfg80211_registered_device **rdev,
548 struct wireless_dev **wdev)
a043897a 549{
97990a06 550 int err;
a043897a 551
97990a06 552 rtnl_lock();
a043897a 553
97990a06
JB
554 if (!cb->args[0]) {
555 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
556 nl80211_fam.attrbuf, nl80211_fam.maxattr,
557 nl80211_policy);
558 if (err)
559 goto out_unlock;
67748893 560
97990a06
JB
561 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
562 nl80211_fam.attrbuf);
563 if (IS_ERR(*wdev)) {
564 err = PTR_ERR(*wdev);
565 goto out_unlock;
566 }
f26cbf40 567 *rdev = wiphy_to_rdev((*wdev)->wiphy);
c319d50b
JB
568 /* 0 is the first index - add 1 to parse only once */
569 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
570 cb->args[1] = (*wdev)->identifier;
571 } else {
c319d50b
JB
572 /* subtract the 1 again here */
573 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 574 struct wireless_dev *tmp;
67748893 575
97990a06
JB
576 if (!wiphy) {
577 err = -ENODEV;
578 goto out_unlock;
579 }
f26cbf40 580 *rdev = wiphy_to_rdev(wiphy);
97990a06 581 *wdev = NULL;
67748893 582
53873f13 583 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) {
97990a06
JB
584 if (tmp->identifier == cb->args[1]) {
585 *wdev = tmp;
586 break;
587 }
588 }
67748893 589
97990a06
JB
590 if (!*wdev) {
591 err = -ENODEV;
592 goto out_unlock;
593 }
67748893
JB
594 }
595
67748893 596 return 0;
97990a06 597 out_unlock:
67748893
JB
598 rtnl_unlock();
599 return err;
600}
601
97990a06 602static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev)
67748893 603{
67748893
JB
604 rtnl_unlock();
605}
606
f4a11bb0
JB
607/* IE validation */
608static bool is_valid_ie_attr(const struct nlattr *attr)
609{
610 const u8 *pos;
611 int len;
612
613 if (!attr)
614 return true;
615
616 pos = nla_data(attr);
617 len = nla_len(attr);
618
619 while (len) {
620 u8 elemlen;
621
622 if (len < 2)
623 return false;
624 len -= 2;
625
626 elemlen = pos[1];
627 if (elemlen > len)
628 return false;
629
630 len -= elemlen;
631 pos += 2 + elemlen;
632 }
633
634 return true;
635}
636
55682965 637/* message building helper */
15e47304 638static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
639 int flags, u8 cmd)
640{
641 /* since there is no private header just add the generic one */
15e47304 642 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
643}
644
5dab3b8a 645static int nl80211_msg_put_channel(struct sk_buff *msg,
cdc89b97
JB
646 struct ieee80211_channel *chan,
647 bool large)
5dab3b8a 648{
ea077c1c
RL
649 /* Some channels must be completely excluded from the
650 * list to protect old user-space tools from breaking
651 */
652 if (!large && chan->flags &
653 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ))
654 return 0;
655
9360ffd1
DM
656 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
657 chan->center_freq))
658 goto nla_put_failure;
5dab3b8a 659
9360ffd1
DM
660 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
661 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
662 goto nla_put_failure;
8fe02e16
LR
663 if (chan->flags & IEEE80211_CHAN_NO_IR) {
664 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
665 goto nla_put_failure;
666 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
667 goto nla_put_failure;
668 }
cdc89b97
JB
669 if (chan->flags & IEEE80211_CHAN_RADAR) {
670 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
671 goto nla_put_failure;
672 if (large) {
673 u32 time;
674
675 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
676
677 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
678 chan->dfs_state))
679 goto nla_put_failure;
680 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
681 time))
682 goto nla_put_failure;
089027e5
JD
683 if (nla_put_u32(msg,
684 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME,
685 chan->dfs_cac_ms))
686 goto nla_put_failure;
cdc89b97
JB
687 }
688 }
5dab3b8a 689
fe1abafd
JB
690 if (large) {
691 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
692 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
693 goto nla_put_failure;
694 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
695 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
696 goto nla_put_failure;
697 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
698 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
699 goto nla_put_failure;
700 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
701 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
702 goto nla_put_failure;
570dbde1
DS
703 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) &&
704 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY))
705 goto nla_put_failure;
06f207fc
AN
706 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) &&
707 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT))
570dbde1 708 goto nla_put_failure;
ea077c1c
RL
709 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) &&
710 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ))
711 goto nla_put_failure;
712 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) &&
713 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ))
714 goto nla_put_failure;
fe1abafd
JB
715 }
716
9360ffd1
DM
717 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
718 DBM_TO_MBM(chan->max_power)))
719 goto nla_put_failure;
5dab3b8a
LR
720
721 return 0;
722
723 nla_put_failure:
724 return -ENOBUFS;
725}
726
55682965
JB
727/* netlink command implementations */
728
b9454e83
JB
729struct key_parse {
730 struct key_params p;
731 int idx;
e31b8213 732 int type;
b9454e83 733 bool def, defmgmt;
dbd2fd65 734 bool def_uni, def_multi;
b9454e83
JB
735};
736
737static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
738{
739 struct nlattr *tb[NL80211_KEY_MAX + 1];
740 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
741 nl80211_key_policy);
742 if (err)
743 return err;
744
745 k->def = !!tb[NL80211_KEY_DEFAULT];
746 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
747
dbd2fd65
JB
748 if (k->def) {
749 k->def_uni = true;
750 k->def_multi = true;
751 }
752 if (k->defmgmt)
753 k->def_multi = true;
754
b9454e83
JB
755 if (tb[NL80211_KEY_IDX])
756 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
757
758 if (tb[NL80211_KEY_DATA]) {
759 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
760 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
761 }
762
763 if (tb[NL80211_KEY_SEQ]) {
764 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
765 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
766 }
767
768 if (tb[NL80211_KEY_CIPHER])
769 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
770
e31b8213
JB
771 if (tb[NL80211_KEY_TYPE]) {
772 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
773 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
774 return -EINVAL;
775 }
776
dbd2fd65
JB
777 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
778 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
7a087e74 779
2da8f419
JB
780 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
781 tb[NL80211_KEY_DEFAULT_TYPES],
782 nl80211_key_default_policy);
dbd2fd65
JB
783 if (err)
784 return err;
785
786 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
787 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
788 }
789
b9454e83
JB
790 return 0;
791}
792
793static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
794{
795 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
796 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
797 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
798 }
799
800 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
801 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
802 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
803 }
804
805 if (info->attrs[NL80211_ATTR_KEY_IDX])
806 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
807
808 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
809 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
810
811 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
812 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
813
dbd2fd65
JB
814 if (k->def) {
815 k->def_uni = true;
816 k->def_multi = true;
817 }
818 if (k->defmgmt)
819 k->def_multi = true;
820
e31b8213
JB
821 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
822 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
823 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
824 return -EINVAL;
825 }
826
dbd2fd65
JB
827 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
828 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
829 int err = nla_parse_nested(
830 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
831 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
832 nl80211_key_default_policy);
833 if (err)
834 return err;
835
836 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
837 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
838 }
839
b9454e83
JB
840 return 0;
841}
842
843static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
844{
845 int err;
846
847 memset(k, 0, sizeof(*k));
848 k->idx = -1;
e31b8213 849 k->type = -1;
b9454e83
JB
850
851 if (info->attrs[NL80211_ATTR_KEY])
852 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
853 else
854 err = nl80211_parse_key_old(info, k);
855
856 if (err)
857 return err;
858
859 if (k->def && k->defmgmt)
860 return -EINVAL;
861
dbd2fd65
JB
862 if (k->defmgmt) {
863 if (k->def_uni || !k->def_multi)
864 return -EINVAL;
865 }
866
b9454e83
JB
867 if (k->idx != -1) {
868 if (k->defmgmt) {
869 if (k->idx < 4 || k->idx > 5)
870 return -EINVAL;
871 } else if (k->def) {
872 if (k->idx < 0 || k->idx > 3)
873 return -EINVAL;
874 } else {
875 if (k->idx < 0 || k->idx > 5)
876 return -EINVAL;
877 }
878 }
879
880 return 0;
881}
882
fffd0934
JB
883static struct cfg80211_cached_keys *
884nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 885 struct nlattr *keys, bool *no_ht)
fffd0934
JB
886{
887 struct key_parse parse;
888 struct nlattr *key;
889 struct cfg80211_cached_keys *result;
890 int rem, err, def = 0;
f1c1f17a
JB
891 bool have_key = false;
892
893 nla_for_each_nested(key, keys, rem) {
894 have_key = true;
895 break;
896 }
897
898 if (!have_key)
899 return NULL;
fffd0934
JB
900
901 result = kzalloc(sizeof(*result), GFP_KERNEL);
902 if (!result)
903 return ERR_PTR(-ENOMEM);
904
905 result->def = -1;
fffd0934
JB
906
907 nla_for_each_nested(key, keys, rem) {
908 memset(&parse, 0, sizeof(parse));
909 parse.idx = -1;
910
911 err = nl80211_parse_key_new(key, &parse);
912 if (err)
913 goto error;
914 err = -EINVAL;
915 if (!parse.p.key)
916 goto error;
42ee231c 917 if (parse.idx < 0 || parse.idx > 3)
fffd0934
JB
918 goto error;
919 if (parse.def) {
920 if (def)
921 goto error;
922 def = 1;
923 result->def = parse.idx;
dbd2fd65
JB
924 if (!parse.def_uni || !parse.def_multi)
925 goto error;
fffd0934
JB
926 } else if (parse.defmgmt)
927 goto error;
928 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 929 parse.idx, false, NULL);
fffd0934
JB
930 if (err)
931 goto error;
386b1f27
JB
932 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 &&
933 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) {
934 err = -EINVAL;
935 goto error;
936 }
fffd0934
JB
937 result->params[parse.idx].cipher = parse.p.cipher;
938 result->params[parse.idx].key_len = parse.p.key_len;
939 result->params[parse.idx].key = result->data[parse.idx];
940 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee 941
386b1f27
JB
942 /* must be WEP key if we got here */
943 if (no_ht)
944 *no_ht = true;
fffd0934
JB
945 }
946
f1c1f17a
JB
947 if (result->def < 0) {
948 err = -EINVAL;
949 goto error;
950 }
951
fffd0934
JB
952 return result;
953 error:
954 kfree(result);
955 return ERR_PTR(err);
956}
957
958static int nl80211_key_allowed(struct wireless_dev *wdev)
959{
960 ASSERT_WDEV_LOCK(wdev);
961
fffd0934
JB
962 switch (wdev->iftype) {
963 case NL80211_IFTYPE_AP:
964 case NL80211_IFTYPE_AP_VLAN:
074ac8df 965 case NL80211_IFTYPE_P2P_GO:
ff973af7 966 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
967 break;
968 case NL80211_IFTYPE_ADHOC:
fffd0934 969 case NL80211_IFTYPE_STATION:
074ac8df 970 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 971 if (!wdev->current_bss)
fffd0934
JB
972 return -ENOLINK;
973 break;
de4fcbad 974 case NL80211_IFTYPE_UNSPECIFIED:
6e0bd6c3 975 case NL80211_IFTYPE_OCB:
de4fcbad 976 case NL80211_IFTYPE_MONITOR:
cb3b7d87 977 case NL80211_IFTYPE_NAN:
de4fcbad
JB
978 case NL80211_IFTYPE_P2P_DEVICE:
979 case NL80211_IFTYPE_WDS:
980 case NUM_NL80211_IFTYPES:
fffd0934
JB
981 return -EINVAL;
982 }
983
984 return 0;
985}
986
664834de
JM
987static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
988 struct nlattr *tb)
989{
990 struct ieee80211_channel *chan;
991
992 if (tb == NULL)
993 return NULL;
994 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb));
995 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
996 return NULL;
997 return chan;
998}
999
7527a782
JB
1000static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
1001{
1002 struct nlattr *nl_modes = nla_nest_start(msg, attr);
1003 int i;
1004
1005 if (!nl_modes)
1006 goto nla_put_failure;
1007
1008 i = 0;
1009 while (ifmodes) {
9360ffd1
DM
1010 if ((ifmodes & 1) && nla_put_flag(msg, i))
1011 goto nla_put_failure;
7527a782
JB
1012 ifmodes >>= 1;
1013 i++;
1014 }
1015
1016 nla_nest_end(msg, nl_modes);
1017 return 0;
1018
1019nla_put_failure:
1020 return -ENOBUFS;
1021}
1022
1023static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
1024 struct sk_buff *msg,
1025 bool large)
7527a782
JB
1026{
1027 struct nlattr *nl_combis;
1028 int i, j;
1029
1030 nl_combis = nla_nest_start(msg,
1031 NL80211_ATTR_INTERFACE_COMBINATIONS);
1032 if (!nl_combis)
1033 goto nla_put_failure;
1034
1035 for (i = 0; i < wiphy->n_iface_combinations; i++) {
1036 const struct ieee80211_iface_combination *c;
1037 struct nlattr *nl_combi, *nl_limits;
1038
1039 c = &wiphy->iface_combinations[i];
1040
1041 nl_combi = nla_nest_start(msg, i + 1);
1042 if (!nl_combi)
1043 goto nla_put_failure;
1044
1045 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
1046 if (!nl_limits)
1047 goto nla_put_failure;
1048
1049 for (j = 0; j < c->n_limits; j++) {
1050 struct nlattr *nl_limit;
1051
1052 nl_limit = nla_nest_start(msg, j + 1);
1053 if (!nl_limit)
1054 goto nla_put_failure;
9360ffd1
DM
1055 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
1056 c->limits[j].max))
1057 goto nla_put_failure;
7527a782
JB
1058 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
1059 c->limits[j].types))
1060 goto nla_put_failure;
1061 nla_nest_end(msg, nl_limit);
1062 }
1063
1064 nla_nest_end(msg, nl_limits);
1065
9360ffd1
DM
1066 if (c->beacon_int_infra_match &&
1067 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
1068 goto nla_put_failure;
1069 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
1070 c->num_different_channels) ||
1071 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
1072 c->max_interfaces))
1073 goto nla_put_failure;
cdc89b97 1074 if (large &&
8c48b50a
FF
1075 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
1076 c->radar_detect_widths) ||
1077 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS,
1078 c->radar_detect_regions)))
cdc89b97 1079 goto nla_put_failure;
0c317a02
PK
1080 if (c->beacon_int_min_gcd &&
1081 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD,
1082 c->beacon_int_min_gcd))
1083 goto nla_put_failure;
7527a782
JB
1084
1085 nla_nest_end(msg, nl_combi);
1086 }
1087
1088 nla_nest_end(msg, nl_combis);
1089
1090 return 0;
1091nla_put_failure:
1092 return -ENOBUFS;
1093}
1094
3713b4e3 1095#ifdef CONFIG_PM
b56cf720
JB
1096static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
1097 struct sk_buff *msg)
1098{
964dc9e2 1099 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
1100 struct nlattr *nl_tcp;
1101
1102 if (!tcp)
1103 return 0;
1104
1105 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
1106 if (!nl_tcp)
1107 return -ENOBUFS;
1108
1109 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1110 tcp->data_payload_max))
1111 return -ENOBUFS;
1112
1113 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1114 tcp->data_payload_max))
1115 return -ENOBUFS;
1116
1117 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
1118 return -ENOBUFS;
1119
1120 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
1121 sizeof(*tcp->tok), tcp->tok))
1122 return -ENOBUFS;
1123
1124 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
1125 tcp->data_interval_max))
1126 return -ENOBUFS;
1127
1128 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
1129 tcp->wake_payload_max))
1130 return -ENOBUFS;
1131
1132 nla_nest_end(msg, nl_tcp);
1133 return 0;
1134}
1135
3713b4e3 1136static int nl80211_send_wowlan(struct sk_buff *msg,
1b8ec87a 1137 struct cfg80211_registered_device *rdev,
b56cf720 1138 bool large)
55682965 1139{
3713b4e3 1140 struct nlattr *nl_wowlan;
55682965 1141
1b8ec87a 1142 if (!rdev->wiphy.wowlan)
3713b4e3 1143 return 0;
55682965 1144
3713b4e3
JB
1145 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1146 if (!nl_wowlan)
1147 return -ENOBUFS;
9360ffd1 1148
1b8ec87a 1149 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 1150 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1b8ec87a 1151 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 1152 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1b8ec87a 1153 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 1154 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1b8ec87a 1155 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 1156 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1b8ec87a 1157 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 1158 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1b8ec87a 1159 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 1160 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1b8ec87a 1161 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 1162 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1b8ec87a 1163 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
1164 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1165 return -ENOBUFS;
9360ffd1 1166
1b8ec87a 1167 if (rdev->wiphy.wowlan->n_patterns) {
50ac6607 1168 struct nl80211_pattern_support pat = {
1b8ec87a
ZG
1169 .max_patterns = rdev->wiphy.wowlan->n_patterns,
1170 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len,
1171 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len,
1172 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset,
3713b4e3 1173 };
9360ffd1 1174
3713b4e3
JB
1175 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1176 sizeof(pat), &pat))
1177 return -ENOBUFS;
1178 }
9360ffd1 1179
75453ccb
LC
1180 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) &&
1181 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT,
1182 rdev->wiphy.wowlan->max_nd_match_sets))
1183 return -ENOBUFS;
1184
1b8ec87a 1185 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg))
b56cf720
JB
1186 return -ENOBUFS;
1187
3713b4e3 1188 nla_nest_end(msg, nl_wowlan);
9360ffd1 1189
3713b4e3
JB
1190 return 0;
1191}
1192#endif
9360ffd1 1193
be29b99a 1194static int nl80211_send_coalesce(struct sk_buff *msg,
1b8ec87a 1195 struct cfg80211_registered_device *rdev)
be29b99a
AK
1196{
1197 struct nl80211_coalesce_rule_support rule;
1198
1b8ec87a 1199 if (!rdev->wiphy.coalesce)
be29b99a
AK
1200 return 0;
1201
1b8ec87a
ZG
1202 rule.max_rules = rdev->wiphy.coalesce->n_rules;
1203 rule.max_delay = rdev->wiphy.coalesce->max_delay;
1204 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns;
1205 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len;
1206 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len;
1207 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset;
be29b99a
AK
1208
1209 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1210 return -ENOBUFS;
1211
1212 return 0;
1213}
1214
3713b4e3
JB
1215static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1216 struct ieee80211_supported_band *sband)
1217{
1218 struct nlattr *nl_rates, *nl_rate;
1219 struct ieee80211_rate *rate;
1220 int i;
87bbbe22 1221
3713b4e3
JB
1222 /* add HT info */
1223 if (sband->ht_cap.ht_supported &&
1224 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1225 sizeof(sband->ht_cap.mcs),
1226 &sband->ht_cap.mcs) ||
1227 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1228 sband->ht_cap.cap) ||
1229 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1230 sband->ht_cap.ampdu_factor) ||
1231 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1232 sband->ht_cap.ampdu_density)))
1233 return -ENOBUFS;
afe0cbf8 1234
3713b4e3
JB
1235 /* add VHT info */
1236 if (sband->vht_cap.vht_supported &&
1237 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1238 sizeof(sband->vht_cap.vht_mcs),
1239 &sband->vht_cap.vht_mcs) ||
1240 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1241 sband->vht_cap.cap)))
1242 return -ENOBUFS;
f59ac048 1243
3713b4e3
JB
1244 /* add bitrates */
1245 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1246 if (!nl_rates)
1247 return -ENOBUFS;
ee688b00 1248
3713b4e3
JB
1249 for (i = 0; i < sband->n_bitrates; i++) {
1250 nl_rate = nla_nest_start(msg, i);
1251 if (!nl_rate)
1252 return -ENOBUFS;
ee688b00 1253
3713b4e3
JB
1254 rate = &sband->bitrates[i];
1255 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1256 rate->bitrate))
1257 return -ENOBUFS;
1258 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1259 nla_put_flag(msg,
1260 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1261 return -ENOBUFS;
ee688b00 1262
3713b4e3
JB
1263 nla_nest_end(msg, nl_rate);
1264 }
d51626df 1265
3713b4e3 1266 nla_nest_end(msg, nl_rates);
bf0c111e 1267
3713b4e3
JB
1268 return 0;
1269}
ee688b00 1270
3713b4e3
JB
1271static int
1272nl80211_send_mgmt_stypes(struct sk_buff *msg,
1273 const struct ieee80211_txrx_stypes *mgmt_stypes)
1274{
1275 u16 stypes;
1276 struct nlattr *nl_ftypes, *nl_ifs;
1277 enum nl80211_iftype ift;
1278 int i;
ee688b00 1279
3713b4e3
JB
1280 if (!mgmt_stypes)
1281 return 0;
5dab3b8a 1282
3713b4e3
JB
1283 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1284 if (!nl_ifs)
1285 return -ENOBUFS;
e2f367f2 1286
3713b4e3
JB
1287 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1288 nl_ftypes = nla_nest_start(msg, ift);
1289 if (!nl_ftypes)
1290 return -ENOBUFS;
1291 i = 0;
1292 stypes = mgmt_stypes[ift].tx;
1293 while (stypes) {
1294 if ((stypes & 1) &&
1295 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1296 (i << 4) | IEEE80211_FTYPE_MGMT))
1297 return -ENOBUFS;
1298 stypes >>= 1;
1299 i++;
ee688b00 1300 }
3713b4e3
JB
1301 nla_nest_end(msg, nl_ftypes);
1302 }
ee688b00 1303
3713b4e3 1304 nla_nest_end(msg, nl_ifs);
ee688b00 1305
3713b4e3
JB
1306 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1307 if (!nl_ifs)
1308 return -ENOBUFS;
ee688b00 1309
3713b4e3
JB
1310 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1311 nl_ftypes = nla_nest_start(msg, ift);
1312 if (!nl_ftypes)
1313 return -ENOBUFS;
1314 i = 0;
1315 stypes = mgmt_stypes[ift].rx;
1316 while (stypes) {
1317 if ((stypes & 1) &&
1318 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1319 (i << 4) | IEEE80211_FTYPE_MGMT))
1320 return -ENOBUFS;
1321 stypes >>= 1;
1322 i++;
1323 }
1324 nla_nest_end(msg, nl_ftypes);
1325 }
1326 nla_nest_end(msg, nl_ifs);
ee688b00 1327
3713b4e3
JB
1328 return 0;
1329}
ee688b00 1330
1794899e
JB
1331#define CMD(op, n) \
1332 do { \
1333 if (rdev->ops->op) { \
1334 i++; \
1335 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1336 goto nla_put_failure; \
1337 } \
1338 } while (0)
1339
1340static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev,
1341 struct sk_buff *msg)
1342{
1343 int i = 0;
1344
1345 /*
1346 * do *NOT* add anything into this function, new things need to be
1347 * advertised only to new versions of userspace that can deal with
1348 * the split (and they can't possibly care about new features...
1349 */
1350 CMD(add_virtual_intf, NEW_INTERFACE);
1351 CMD(change_virtual_intf, SET_INTERFACE);
1352 CMD(add_key, NEW_KEY);
1353 CMD(start_ap, START_AP);
1354 CMD(add_station, NEW_STATION);
1355 CMD(add_mpath, NEW_MPATH);
1356 CMD(update_mesh_config, SET_MESH_CONFIG);
1357 CMD(change_bss, SET_BSS);
1358 CMD(auth, AUTHENTICATE);
1359 CMD(assoc, ASSOCIATE);
1360 CMD(deauth, DEAUTHENTICATE);
1361 CMD(disassoc, DISASSOCIATE);
1362 CMD(join_ibss, JOIN_IBSS);
1363 CMD(join_mesh, JOIN_MESH);
1364 CMD(set_pmksa, SET_PMKSA);
1365 CMD(del_pmksa, DEL_PMKSA);
1366 CMD(flush_pmksa, FLUSH_PMKSA);
1367 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1368 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1369 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1370 CMD(mgmt_tx, FRAME);
1371 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1372 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1373 i++;
1374 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1375 goto nla_put_failure;
1376 }
1377 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap ||
1378 rdev->ops->join_mesh) {
1379 i++;
1380 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1381 goto nla_put_failure;
1382 }
1383 CMD(set_wds_peer, SET_WDS_PEER);
1384 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1385 CMD(tdls_mgmt, TDLS_MGMT);
1386 CMD(tdls_oper, TDLS_OPER);
1387 }
1388 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1389 CMD(sched_scan_start, START_SCHED_SCAN);
1390 CMD(probe_client, PROBE_CLIENT);
1391 CMD(set_noack_map, SET_NOACK_MAP);
1392 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1393 i++;
1394 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1395 goto nla_put_failure;
1396 }
1397 CMD(start_p2p_device, START_P2P_DEVICE);
1398 CMD(set_mcast_rate, SET_MCAST_RATE);
1399#ifdef CONFIG_NL80211_TESTMODE
1400 CMD(testmode_cmd, TESTMODE);
1401#endif
1402
1403 if (rdev->ops->connect || rdev->ops->auth) {
1404 i++;
1405 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1406 goto nla_put_failure;
1407 }
1408
1409 if (rdev->ops->disconnect || rdev->ops->deauth) {
1410 i++;
1411 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1412 goto nla_put_failure;
1413 }
1414
1415 return i;
1416 nla_put_failure:
1417 return -ENOBUFS;
1418}
1419
86e8cf98
JB
1420struct nl80211_dump_wiphy_state {
1421 s64 filter_wiphy;
1422 long start;
019ae3a9 1423 long split_start, band_start, chan_start, capa_start;
86e8cf98
JB
1424 bool split;
1425};
1426
1b8ec87a 1427static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev,
3bb20556 1428 enum nl80211_commands cmd,
3713b4e3 1429 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 1430 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
1431{
1432 void *hdr;
1433 struct nlattr *nl_bands, *nl_band;
1434 struct nlattr *nl_freqs, *nl_freq;
1435 struct nlattr *nl_cmds;
57fbcce3 1436 enum nl80211_band band;
3713b4e3
JB
1437 struct ieee80211_channel *chan;
1438 int i;
1439 const struct ieee80211_txrx_stypes *mgmt_stypes =
1b8ec87a 1440 rdev->wiphy.mgmt_stypes;
fe1abafd 1441 u32 features;
ee688b00 1442
3bb20556 1443 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
3713b4e3
JB
1444 if (!hdr)
1445 return -ENOBUFS;
ee688b00 1446
86e8cf98
JB
1447 if (WARN_ON(!state))
1448 return -EINVAL;
ee688b00 1449
1b8ec87a 1450 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3713b4e3 1451 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1b8ec87a 1452 wiphy_name(&rdev->wiphy)) ||
3713b4e3
JB
1453 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1454 cfg80211_rdev_list_generation))
8fdc621d
JB
1455 goto nla_put_failure;
1456
3bb20556
JB
1457 if (cmd != NL80211_CMD_NEW_WIPHY)
1458 goto finish;
1459
86e8cf98 1460 switch (state->split_start) {
3713b4e3
JB
1461 case 0:
1462 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1b8ec87a 1463 rdev->wiphy.retry_short) ||
3713b4e3 1464 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1b8ec87a 1465 rdev->wiphy.retry_long) ||
3713b4e3 1466 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1b8ec87a 1467 rdev->wiphy.frag_threshold) ||
3713b4e3 1468 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1b8ec87a 1469 rdev->wiphy.rts_threshold) ||
3713b4e3 1470 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1b8ec87a 1471 rdev->wiphy.coverage_class) ||
3713b4e3 1472 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1b8ec87a 1473 rdev->wiphy.max_scan_ssids) ||
3713b4e3 1474 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1b8ec87a 1475 rdev->wiphy.max_sched_scan_ssids) ||
3713b4e3 1476 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1b8ec87a 1477 rdev->wiphy.max_scan_ie_len) ||
3713b4e3 1478 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1b8ec87a 1479 rdev->wiphy.max_sched_scan_ie_len) ||
3713b4e3 1480 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
3b06d277
AS
1481 rdev->wiphy.max_match_sets) ||
1482 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS,
1483 rdev->wiphy.max_sched_scan_plans) ||
1484 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL,
1485 rdev->wiphy.max_sched_scan_plan_interval) ||
1486 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS,
1487 rdev->wiphy.max_sched_scan_plan_iterations))
9360ffd1 1488 goto nla_put_failure;
3713b4e3 1489
1b8ec87a 1490 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
3713b4e3 1491 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1492 goto nla_put_failure;
1b8ec87a 1493 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
3713b4e3
JB
1494 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1495 goto nla_put_failure;
1b8ec87a 1496 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3713b4e3
JB
1497 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1498 goto nla_put_failure;
1b8ec87a 1499 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
3713b4e3
JB
1500 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1501 goto nla_put_failure;
1b8ec87a 1502 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
3713b4e3
JB
1503 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1504 goto nla_put_failure;
1b8ec87a 1505 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
3713b4e3 1506 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1507 goto nla_put_failure;
86e8cf98
JB
1508 state->split_start++;
1509 if (state->split)
3713b4e3
JB
1510 break;
1511 case 1:
1512 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1b8ec87a
ZG
1513 sizeof(u32) * rdev->wiphy.n_cipher_suites,
1514 rdev->wiphy.cipher_suites))
3713b4e3 1515 goto nla_put_failure;
4745fc09 1516
3713b4e3 1517 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1b8ec87a 1518 rdev->wiphy.max_num_pmkids))
3713b4e3 1519 goto nla_put_failure;
b23aa676 1520
1b8ec87a 1521 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3713b4e3 1522 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1523 goto nla_put_failure;
b23aa676 1524
3713b4e3 1525 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1b8ec87a 1526 rdev->wiphy.available_antennas_tx) ||
3713b4e3 1527 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1b8ec87a 1528 rdev->wiphy.available_antennas_rx))
9360ffd1 1529 goto nla_put_failure;
b23aa676 1530
1b8ec87a 1531 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
3713b4e3 1532 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1b8ec87a 1533 rdev->wiphy.probe_resp_offload))
3713b4e3 1534 goto nla_put_failure;
8fdc621d 1535
1b8ec87a
ZG
1536 if ((rdev->wiphy.available_antennas_tx ||
1537 rdev->wiphy.available_antennas_rx) &&
1538 rdev->ops->get_antenna) {
3713b4e3
JB
1539 u32 tx_ant = 0, rx_ant = 0;
1540 int res;
7a087e74 1541
1b8ec87a 1542 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant);
3713b4e3
JB
1543 if (!res) {
1544 if (nla_put_u32(msg,
1545 NL80211_ATTR_WIPHY_ANTENNA_TX,
1546 tx_ant) ||
1547 nla_put_u32(msg,
1548 NL80211_ATTR_WIPHY_ANTENNA_RX,
1549 rx_ant))
1550 goto nla_put_failure;
1551 }
1552 }
a293911d 1553
86e8cf98
JB
1554 state->split_start++;
1555 if (state->split)
3713b4e3
JB
1556 break;
1557 case 2:
1558 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1b8ec87a 1559 rdev->wiphy.interface_modes))
3713b4e3 1560 goto nla_put_failure;
86e8cf98
JB
1561 state->split_start++;
1562 if (state->split)
3713b4e3
JB
1563 break;
1564 case 3:
1565 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1566 if (!nl_bands)
1567 goto nla_put_failure;
f7ca38df 1568
86e8cf98 1569 for (band = state->band_start;
57fbcce3 1570 band < NUM_NL80211_BANDS; band++) {
3713b4e3 1571 struct ieee80211_supported_band *sband;
2e161f78 1572
1b8ec87a 1573 sband = rdev->wiphy.bands[band];
2e161f78 1574
3713b4e3
JB
1575 if (!sband)
1576 continue;
1577
1578 nl_band = nla_nest_start(msg, band);
1579 if (!nl_band)
2e161f78 1580 goto nla_put_failure;
3713b4e3 1581
86e8cf98 1582 switch (state->chan_start) {
3713b4e3
JB
1583 case 0:
1584 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 1585 goto nla_put_failure;
86e8cf98
JB
1586 state->chan_start++;
1587 if (state->split)
3713b4e3
JB
1588 break;
1589 default:
1590 /* add frequencies */
1591 nl_freqs = nla_nest_start(
1592 msg, NL80211_BAND_ATTR_FREQS);
1593 if (!nl_freqs)
1594 goto nla_put_failure;
1595
86e8cf98 1596 for (i = state->chan_start - 1;
3713b4e3
JB
1597 i < sband->n_channels;
1598 i++) {
1599 nl_freq = nla_nest_start(msg, i);
1600 if (!nl_freq)
1601 goto nla_put_failure;
1602
1603 chan = &sband->channels[i];
1604
86e8cf98
JB
1605 if (nl80211_msg_put_channel(
1606 msg, chan,
1607 state->split))
3713b4e3
JB
1608 goto nla_put_failure;
1609
1610 nla_nest_end(msg, nl_freq);
86e8cf98 1611 if (state->split)
3713b4e3
JB
1612 break;
1613 }
1614 if (i < sband->n_channels)
86e8cf98 1615 state->chan_start = i + 2;
3713b4e3 1616 else
86e8cf98 1617 state->chan_start = 0;
3713b4e3
JB
1618 nla_nest_end(msg, nl_freqs);
1619 }
1620
1621 nla_nest_end(msg, nl_band);
1622
86e8cf98 1623 if (state->split) {
3713b4e3 1624 /* start again here */
86e8cf98 1625 if (state->chan_start)
3713b4e3
JB
1626 band--;
1627 break;
2e161f78 1628 }
2e161f78 1629 }
3713b4e3 1630 nla_nest_end(msg, nl_bands);
2e161f78 1631
57fbcce3 1632 if (band < NUM_NL80211_BANDS)
86e8cf98 1633 state->band_start = band + 1;
3713b4e3 1634 else
86e8cf98 1635 state->band_start = 0;
74b70a4e 1636
3713b4e3 1637 /* if bands & channels are done, continue outside */
86e8cf98
JB
1638 if (state->band_start == 0 && state->chan_start == 0)
1639 state->split_start++;
1640 if (state->split)
3713b4e3
JB
1641 break;
1642 case 4:
1643 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1644 if (!nl_cmds)
2e161f78
JB
1645 goto nla_put_failure;
1646
1794899e
JB
1647 i = nl80211_add_commands_unsplit(rdev, msg);
1648 if (i < 0)
1649 goto nla_put_failure;
86e8cf98 1650 if (state->split) {
5de17984
AS
1651 CMD(crit_proto_start, CRIT_PROTOCOL_START);
1652 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
1b8ec87a 1653 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
16ef1fe2 1654 CMD(channel_switch, CHANNEL_SWITCH);
02df00eb 1655 CMD(set_qos_map, SET_QOS_MAP);
723e73ac
JB
1656 if (rdev->wiphy.features &
1657 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)
960d01ac 1658 CMD(add_tx_ts, ADD_TX_TS);
5de17984 1659 }
3713b4e3 1660#undef CMD
ff1b6e69 1661
3713b4e3 1662 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
1663 state->split_start++;
1664 if (state->split)
3713b4e3
JB
1665 break;
1666 case 5:
1b8ec87a
ZG
1667 if (rdev->ops->remain_on_channel &&
1668 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
3713b4e3
JB
1669 nla_put_u32(msg,
1670 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1b8ec87a 1671 rdev->wiphy.max_remain_on_channel_duration))
3713b4e3
JB
1672 goto nla_put_failure;
1673
1b8ec87a 1674 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
3713b4e3
JB
1675 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1676 goto nla_put_failure;
1677
1678 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
1679 goto nla_put_failure;
86e8cf98
JB
1680 state->split_start++;
1681 if (state->split)
3713b4e3
JB
1682 break;
1683 case 6:
1684#ifdef CONFIG_PM
1b8ec87a 1685 if (nl80211_send_wowlan(msg, rdev, state->split))
3713b4e3 1686 goto nla_put_failure;
86e8cf98
JB
1687 state->split_start++;
1688 if (state->split)
3713b4e3
JB
1689 break;
1690#else
86e8cf98 1691 state->split_start++;
dfb89c56 1692#endif
3713b4e3
JB
1693 case 7:
1694 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1b8ec87a 1695 rdev->wiphy.software_iftypes))
3713b4e3 1696 goto nla_put_failure;
ff1b6e69 1697
1b8ec87a 1698 if (nl80211_put_iface_combinations(&rdev->wiphy, msg,
86e8cf98 1699 state->split))
3713b4e3 1700 goto nla_put_failure;
7527a782 1701
86e8cf98
JB
1702 state->split_start++;
1703 if (state->split)
3713b4e3
JB
1704 break;
1705 case 8:
1b8ec87a 1706 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
3713b4e3 1707 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1b8ec87a 1708 rdev->wiphy.ap_sme_capa))
3713b4e3 1709 goto nla_put_failure;
7527a782 1710
1b8ec87a 1711 features = rdev->wiphy.features;
fe1abafd
JB
1712 /*
1713 * We can only add the per-channel limit information if the
1714 * dump is split, otherwise it makes it too big. Therefore
1715 * only advertise it in that case.
1716 */
86e8cf98 1717 if (state->split)
fe1abafd
JB
1718 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
1719 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 1720 goto nla_put_failure;
562a7480 1721
1b8ec87a 1722 if (rdev->wiphy.ht_capa_mod_mask &&
3713b4e3 1723 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1b8ec87a
ZG
1724 sizeof(*rdev->wiphy.ht_capa_mod_mask),
1725 rdev->wiphy.ht_capa_mod_mask))
3713b4e3 1726 goto nla_put_failure;
1f074bd8 1727
1b8ec87a
ZG
1728 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1729 rdev->wiphy.max_acl_mac_addrs &&
3713b4e3 1730 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1b8ec87a 1731 rdev->wiphy.max_acl_mac_addrs))
3713b4e3 1732 goto nla_put_failure;
7e7c8926 1733
3713b4e3
JB
1734 /*
1735 * Any information below this point is only available to
1736 * applications that can deal with it being split. This
1737 * helps ensure that newly added capabilities don't break
1738 * older tools by overrunning their buffers.
1739 *
1740 * We still increment split_start so that in the split
1741 * case we'll continue with more data in the next round,
1742 * but break unconditionally so unsplit data stops here.
1743 */
86e8cf98 1744 state->split_start++;
3713b4e3
JB
1745 break;
1746 case 9:
1b8ec87a 1747 if (rdev->wiphy.extended_capabilities &&
fe1abafd 1748 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1b8ec87a
ZG
1749 rdev->wiphy.extended_capabilities_len,
1750 rdev->wiphy.extended_capabilities) ||
fe1abafd 1751 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1b8ec87a
ZG
1752 rdev->wiphy.extended_capabilities_len,
1753 rdev->wiphy.extended_capabilities_mask)))
fe1abafd 1754 goto nla_put_failure;
a50df0c4 1755
1b8ec87a 1756 if (rdev->wiphy.vht_capa_mod_mask &&
ee2aca34 1757 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1b8ec87a
ZG
1758 sizeof(*rdev->wiphy.vht_capa_mod_mask),
1759 rdev->wiphy.vht_capa_mod_mask))
ee2aca34
JB
1760 goto nla_put_failure;
1761
be29b99a
AK
1762 state->split_start++;
1763 break;
1764 case 10:
1b8ec87a 1765 if (nl80211_send_coalesce(msg, rdev))
be29b99a
AK
1766 goto nla_put_failure;
1767
1b8ec87a 1768 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
01e0daa4
FF
1769 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
1770 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
1771 goto nla_put_failure;
b43504cf 1772
1b8ec87a 1773 if (rdev->wiphy.max_ap_assoc_sta &&
b43504cf 1774 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
1b8ec87a 1775 rdev->wiphy.max_ap_assoc_sta))
b43504cf
JM
1776 goto nla_put_failure;
1777
ad7e718c
JB
1778 state->split_start++;
1779 break;
1780 case 11:
1b8ec87a 1781 if (rdev->wiphy.n_vendor_commands) {
567ffc35
JB
1782 const struct nl80211_vendor_cmd_info *info;
1783 struct nlattr *nested;
1784
1785 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA);
1786 if (!nested)
1787 goto nla_put_failure;
1788
1b8ec87a
ZG
1789 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
1790 info = &rdev->wiphy.vendor_commands[i].info;
567ffc35
JB
1791 if (nla_put(msg, i + 1, sizeof(*info), info))
1792 goto nla_put_failure;
1793 }
1794 nla_nest_end(msg, nested);
1795 }
1796
1b8ec87a 1797 if (rdev->wiphy.n_vendor_events) {
567ffc35
JB
1798 const struct nl80211_vendor_cmd_info *info;
1799 struct nlattr *nested;
ad7e718c 1800
567ffc35
JB
1801 nested = nla_nest_start(msg,
1802 NL80211_ATTR_VENDOR_EVENTS);
1803 if (!nested)
ad7e718c 1804 goto nla_put_failure;
567ffc35 1805
1b8ec87a
ZG
1806 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) {
1807 info = &rdev->wiphy.vendor_events[i];
567ffc35
JB
1808 if (nla_put(msg, i + 1, sizeof(*info), info))
1809 goto nla_put_failure;
1810 }
1811 nla_nest_end(msg, nested);
1812 }
9a774c78
AO
1813 state->split_start++;
1814 break;
1815 case 12:
1816 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH &&
1817 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS,
1818 rdev->wiphy.max_num_csa_counters))
1819 goto nla_put_failure;
01e0daa4 1820
1bdd716c
AN
1821 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
1822 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
1823 goto nla_put_failure;
1824
d75bb06b
GKS
1825 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES,
1826 sizeof(rdev->wiphy.ext_features),
1827 rdev->wiphy.ext_features))
1828 goto nla_put_failure;
1829
38de03d2
AS
1830 if (rdev->wiphy.bss_select_support) {
1831 struct nlattr *nested;
1832 u32 bss_select_support = rdev->wiphy.bss_select_support;
1833
1834 nested = nla_nest_start(msg, NL80211_ATTR_BSS_SELECT);
1835 if (!nested)
1836 goto nla_put_failure;
1837
1838 i = 0;
1839 while (bss_select_support) {
1840 if ((bss_select_support & 1) &&
1841 nla_put_flag(msg, i))
1842 goto nla_put_failure;
1843 i++;
1844 bss_select_support >>= 1;
1845 }
1846 nla_nest_end(msg, nested);
1847 }
1848
019ae3a9
KV
1849 state->split_start++;
1850 break;
1851 case 13:
1852 if (rdev->wiphy.num_iftype_ext_capab &&
1853 rdev->wiphy.iftype_ext_capab) {
1854 struct nlattr *nested_ext_capab, *nested;
1855
1856 nested = nla_nest_start(msg,
1857 NL80211_ATTR_IFTYPE_EXT_CAPA);
1858 if (!nested)
1859 goto nla_put_failure;
1860
1861 for (i = state->capa_start;
1862 i < rdev->wiphy.num_iftype_ext_capab; i++) {
1863 const struct wiphy_iftype_ext_capab *capab;
1864
1865 capab = &rdev->wiphy.iftype_ext_capab[i];
1866
1867 nested_ext_capab = nla_nest_start(msg, i);
1868 if (!nested_ext_capab ||
1869 nla_put_u32(msg, NL80211_ATTR_IFTYPE,
1870 capab->iftype) ||
1871 nla_put(msg, NL80211_ATTR_EXT_CAPA,
1872 capab->extended_capabilities_len,
1873 capab->extended_capabilities) ||
1874 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1875 capab->extended_capabilities_len,
1876 capab->extended_capabilities_mask))
1877 goto nla_put_failure;
1878
1879 nla_nest_end(msg, nested_ext_capab);
1880 if (state->split)
1881 break;
1882 }
1883 nla_nest_end(msg, nested);
1884 if (i < rdev->wiphy.num_iftype_ext_capab) {
1885 state->capa_start = i + 1;
1886 break;
1887 }
1888 }
1889
3713b4e3 1890 /* done */
86e8cf98 1891 state->split_start = 0;
3713b4e3
JB
1892 break;
1893 }
3bb20556 1894 finish:
053c095a
JB
1895 genlmsg_end(msg, hdr);
1896 return 0;
55682965
JB
1897
1898 nla_put_failure:
bc3ed28c
TG
1899 genlmsg_cancel(msg, hdr);
1900 return -EMSGSIZE;
55682965
JB
1901}
1902
86e8cf98
JB
1903static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
1904 struct netlink_callback *cb,
1905 struct nl80211_dump_wiphy_state *state)
1906{
1907 struct nlattr **tb = nl80211_fam.attrbuf;
1908 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1909 tb, nl80211_fam.maxattr, nl80211_policy);
1910 /* ignore parse errors for backward compatibility */
1911 if (ret)
1912 return 0;
1913
1914 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
1915 if (tb[NL80211_ATTR_WIPHY])
1916 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
1917 if (tb[NL80211_ATTR_WDEV])
1918 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
1919 if (tb[NL80211_ATTR_IFINDEX]) {
1920 struct net_device *netdev;
1921 struct cfg80211_registered_device *rdev;
1922 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
1923
7f2b8562 1924 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
86e8cf98
JB
1925 if (!netdev)
1926 return -ENODEV;
1927 if (netdev->ieee80211_ptr) {
f26cbf40 1928 rdev = wiphy_to_rdev(
86e8cf98
JB
1929 netdev->ieee80211_ptr->wiphy);
1930 state->filter_wiphy = rdev->wiphy_idx;
1931 }
86e8cf98
JB
1932 }
1933
1934 return 0;
1935}
1936
55682965
JB
1937static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1938{
645e77de 1939 int idx = 0, ret;
86e8cf98 1940 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
1b8ec87a 1941 struct cfg80211_registered_device *rdev;
3a5a423b 1942
5fe231e8 1943 rtnl_lock();
86e8cf98
JB
1944 if (!state) {
1945 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
1946 if (!state) {
1947 rtnl_unlock();
86e8cf98 1948 return -ENOMEM;
3713b4e3 1949 }
86e8cf98
JB
1950 state->filter_wiphy = -1;
1951 ret = nl80211_dump_wiphy_parse(skb, cb, state);
1952 if (ret) {
1953 kfree(state);
1954 rtnl_unlock();
1955 return ret;
3713b4e3 1956 }
86e8cf98 1957 cb->args[0] = (long)state;
3713b4e3
JB
1958 }
1959
1b8ec87a
ZG
1960 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1961 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1962 continue;
86e8cf98 1963 if (++idx <= state->start)
55682965 1964 continue;
86e8cf98 1965 if (state->filter_wiphy != -1 &&
1b8ec87a 1966 state->filter_wiphy != rdev->wiphy_idx)
3713b4e3
JB
1967 continue;
1968 /* attempt to fit multiple wiphy data chunks into the skb */
1969 do {
3bb20556
JB
1970 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY,
1971 skb,
3713b4e3
JB
1972 NETLINK_CB(cb->skb).portid,
1973 cb->nlh->nlmsg_seq,
86e8cf98 1974 NLM_F_MULTI, state);
3713b4e3
JB
1975 if (ret < 0) {
1976 /*
1977 * If sending the wiphy data didn't fit (ENOBUFS
1978 * or EMSGSIZE returned), this SKB is still
1979 * empty (so it's not too big because another
1980 * wiphy dataset is already in the skb) and
1981 * we've not tried to adjust the dump allocation
1982 * yet ... then adjust the alloc size to be
1983 * bigger, and return 1 but with the empty skb.
1984 * This results in an empty message being RX'ed
1985 * in userspace, but that is ignored.
1986 *
1987 * We can then retry with the larger buffer.
1988 */
1989 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
f12cb289 1990 !skb->len && !state->split &&
3713b4e3
JB
1991 cb->min_dump_alloc < 4096) {
1992 cb->min_dump_alloc = 4096;
f12cb289 1993 state->split_start = 0;
d98cae64 1994 rtnl_unlock();
3713b4e3
JB
1995 return 1;
1996 }
1997 idx--;
1998 break;
645e77de 1999 }
86e8cf98 2000 } while (state->split_start > 0);
3713b4e3 2001 break;
55682965 2002 }
5fe231e8 2003 rtnl_unlock();
55682965 2004
86e8cf98 2005 state->start = idx;
55682965
JB
2006
2007 return skb->len;
2008}
2009
86e8cf98
JB
2010static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
2011{
2012 kfree((void *)cb->args[0]);
2013 return 0;
2014}
2015
55682965
JB
2016static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
2017{
2018 struct sk_buff *msg;
1b8ec87a 2019 struct cfg80211_registered_device *rdev = info->user_ptr[0];
86e8cf98 2020 struct nl80211_dump_wiphy_state state = {};
55682965 2021
645e77de 2022 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 2023 if (!msg)
4c476991 2024 return -ENOMEM;
55682965 2025
3bb20556
JB
2026 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg,
2027 info->snd_portid, info->snd_seq, 0,
86e8cf98 2028 &state) < 0) {
4c476991
JB
2029 nlmsg_free(msg);
2030 return -ENOBUFS;
2031 }
55682965 2032
134e6375 2033 return genlmsg_reply(msg, info);
55682965
JB
2034}
2035
31888487
JM
2036static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
2037 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
2038 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
2039 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
2040 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
2041 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
2042};
2043
2044static int parse_txq_params(struct nlattr *tb[],
2045 struct ieee80211_txq_params *txq_params)
2046{
a3304b0a 2047 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
2048 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
2049 !tb[NL80211_TXQ_ATTR_AIFS])
2050 return -EINVAL;
2051
a3304b0a 2052 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
2053 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
2054 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
2055 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
2056 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
2057
a3304b0a
JB
2058 if (txq_params->ac >= NL80211_NUM_ACS)
2059 return -EINVAL;
2060
31888487
JM
2061 return 0;
2062}
2063
f444de05
JB
2064static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
2065{
2066 /*
cc1d2806
JB
2067 * You can only set the channel explicitly for WDS interfaces,
2068 * all others have their channel managed via their respective
2069 * "establish a connection" command (connect, join, ...)
2070 *
2071 * For AP/GO and mesh mode, the channel can be set with the
2072 * channel userspace API, but is only stored and passed to the
2073 * low-level driver when the AP starts or the mesh is joined.
2074 * This is for backward compatibility, userspace can also give
2075 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
2076 *
2077 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
2078 * whatever else is going on, so they have their own special
2079 * operation to set the monitor channel if possible.
f444de05
JB
2080 */
2081 return !wdev ||
2082 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 2083 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
2084 wdev->iftype == NL80211_IFTYPE_MONITOR ||
2085 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
2086}
2087
683b6d3b
JB
2088static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
2089 struct genl_info *info,
2090 struct cfg80211_chan_def *chandef)
2091{
dbeca2ea 2092 u32 control_freq;
683b6d3b
JB
2093
2094 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
2095 return -EINVAL;
2096
2097 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
2098
2099 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
2100 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
2101 chandef->center_freq1 = control_freq;
2102 chandef->center_freq2 = 0;
683b6d3b
JB
2103
2104 /* Primary channel not allowed */
2105 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
2106 return -EINVAL;
2107
3d9d1d66
JB
2108 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
2109 enum nl80211_channel_type chantype;
2110
2111 chantype = nla_get_u32(
2112 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
2113
2114 switch (chantype) {
2115 case NL80211_CHAN_NO_HT:
2116 case NL80211_CHAN_HT20:
2117 case NL80211_CHAN_HT40PLUS:
2118 case NL80211_CHAN_HT40MINUS:
2119 cfg80211_chandef_create(chandef, chandef->chan,
2120 chantype);
2121 break;
2122 default:
2123 return -EINVAL;
2124 }
2125 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
2126 chandef->width =
2127 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
2128 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
2129 chandef->center_freq1 =
2130 nla_get_u32(
2131 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
2132 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
2133 chandef->center_freq2 =
2134 nla_get_u32(
2135 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
2136 }
2137
9f5e8f6e 2138 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
2139 return -EINVAL;
2140
9f5e8f6e
JB
2141 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
2142 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
2143 return -EINVAL;
2144
2f301ab2
SW
2145 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
2146 chandef->width == NL80211_CHAN_WIDTH_10) &&
2147 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ))
2148 return -EINVAL;
2149
683b6d3b
JB
2150 return 0;
2151}
2152
f444de05 2153static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
e16821bc 2154 struct net_device *dev,
f444de05
JB
2155 struct genl_info *info)
2156{
683b6d3b 2157 struct cfg80211_chan_def chandef;
f444de05 2158 int result;
e8c9bd5b 2159 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
e16821bc 2160 struct wireless_dev *wdev = NULL;
e8c9bd5b 2161
e16821bc
JM
2162 if (dev)
2163 wdev = dev->ieee80211_ptr;
f444de05
JB
2164 if (!nl80211_can_set_dev_channel(wdev))
2165 return -EOPNOTSUPP;
e16821bc
JM
2166 if (wdev)
2167 iftype = wdev->iftype;
f444de05 2168
683b6d3b
JB
2169 result = nl80211_parse_chandef(rdev, info, &chandef);
2170 if (result)
2171 return result;
f444de05 2172
e8c9bd5b 2173 switch (iftype) {
aa430da4
JB
2174 case NL80211_IFTYPE_AP:
2175 case NL80211_IFTYPE_P2P_GO:
923b352f
AN
2176 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
2177 iftype)) {
aa430da4
JB
2178 result = -EINVAL;
2179 break;
2180 }
e16821bc
JM
2181 if (wdev->beacon_interval) {
2182 if (!dev || !rdev->ops->set_ap_chanwidth ||
2183 !(rdev->wiphy.features &
2184 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) {
2185 result = -EBUSY;
2186 break;
2187 }
2188
2189 /* Only allow dynamic channel width changes */
2190 if (chandef.chan != wdev->preset_chandef.chan) {
2191 result = -EBUSY;
2192 break;
2193 }
2194 result = rdev_set_ap_chanwidth(rdev, dev, &chandef);
2195 if (result)
2196 break;
2197 }
683b6d3b 2198 wdev->preset_chandef = chandef;
aa430da4
JB
2199 result = 0;
2200 break;
cc1d2806 2201 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 2202 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 2203 break;
e8c9bd5b 2204 case NL80211_IFTYPE_MONITOR:
683b6d3b 2205 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 2206 break;
aa430da4 2207 default:
e8c9bd5b 2208 result = -EINVAL;
f444de05 2209 }
f444de05
JB
2210
2211 return result;
2212}
2213
2214static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
2215{
4c476991
JB
2216 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2217 struct net_device *netdev = info->user_ptr[1];
f444de05 2218
e16821bc 2219 return __nl80211_set_channel(rdev, netdev, info);
f444de05
JB
2220}
2221
e8347eba
BJ
2222static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
2223{
43b19952
JB
2224 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2225 struct net_device *dev = info->user_ptr[1];
2226 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 2227 const u8 *bssid;
e8347eba
BJ
2228
2229 if (!info->attrs[NL80211_ATTR_MAC])
2230 return -EINVAL;
2231
43b19952
JB
2232 if (netif_running(dev))
2233 return -EBUSY;
e8347eba 2234
43b19952
JB
2235 if (!rdev->ops->set_wds_peer)
2236 return -EOPNOTSUPP;
e8347eba 2237
43b19952
JB
2238 if (wdev->iftype != NL80211_IFTYPE_WDS)
2239 return -EOPNOTSUPP;
e8347eba
BJ
2240
2241 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 2242 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
2243}
2244
55682965
JB
2245static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
2246{
2247 struct cfg80211_registered_device *rdev;
f444de05
JB
2248 struct net_device *netdev = NULL;
2249 struct wireless_dev *wdev;
a1e567c8 2250 int result = 0, rem_txq_params = 0;
31888487 2251 struct nlattr *nl_txq_params;
b9a5f8ca
JM
2252 u32 changed;
2253 u8 retry_short = 0, retry_long = 0;
2254 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 2255 u8 coverage_class = 0;
55682965 2256
5fe231e8
JB
2257 ASSERT_RTNL();
2258
f444de05
JB
2259 /*
2260 * Try to find the wiphy and netdev. Normally this
2261 * function shouldn't need the netdev, but this is
2262 * done for backward compatibility -- previously
2263 * setting the channel was done per wiphy, but now
2264 * it is per netdev. Previous userland like hostapd
2265 * also passed a netdev to set_wiphy, so that it is
2266 * possible to let that go to the right netdev!
2267 */
4bbf4d56 2268
f444de05
JB
2269 if (info->attrs[NL80211_ATTR_IFINDEX]) {
2270 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
2271
7f2b8562 2272 netdev = __dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 2273 if (netdev && netdev->ieee80211_ptr)
f26cbf40 2274 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy);
5fe231e8 2275 else
f444de05 2276 netdev = NULL;
4bbf4d56
JB
2277 }
2278
f444de05 2279 if (!netdev) {
878d9ec7
JB
2280 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
2281 info->attrs);
5fe231e8 2282 if (IS_ERR(rdev))
4c476991 2283 return PTR_ERR(rdev);
f444de05
JB
2284 wdev = NULL;
2285 netdev = NULL;
2286 result = 0;
71fe96bf 2287 } else
f444de05 2288 wdev = netdev->ieee80211_ptr;
f444de05
JB
2289
2290 /*
2291 * end workaround code, by now the rdev is available
2292 * and locked, and wdev may or may not be NULL.
2293 */
4bbf4d56
JB
2294
2295 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
2296 result = cfg80211_dev_rename(
2297 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 2298
4bbf4d56 2299 if (result)
7f2b8562 2300 return result;
31888487
JM
2301
2302 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
2303 struct ieee80211_txq_params txq_params;
2304 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
2305
7f2b8562
YX
2306 if (!rdev->ops->set_txq_params)
2307 return -EOPNOTSUPP;
31888487 2308
7f2b8562
YX
2309 if (!netdev)
2310 return -EINVAL;
f70f01c2 2311
133a3ff2 2312 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7f2b8562
YX
2313 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2314 return -EINVAL;
133a3ff2 2315
7f2b8562
YX
2316 if (!netif_running(netdev))
2317 return -ENETDOWN;
2b5f8b0b 2318
31888487
JM
2319 nla_for_each_nested(nl_txq_params,
2320 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
2321 rem_txq_params) {
bfe2c7b1
JB
2322 result = nla_parse_nested(tb, NL80211_TXQ_ATTR_MAX,
2323 nl_txq_params,
2324 txq_params_policy);
ae811e21
JB
2325 if (result)
2326 return result;
31888487
JM
2327 result = parse_txq_params(tb, &txq_params);
2328 if (result)
7f2b8562 2329 return result;
31888487 2330
e35e4d28
HG
2331 result = rdev_set_txq_params(rdev, netdev,
2332 &txq_params);
31888487 2333 if (result)
7f2b8562 2334 return result;
31888487
JM
2335 }
2336 }
55682965 2337
72bdcf34 2338 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
e16821bc
JM
2339 result = __nl80211_set_channel(
2340 rdev,
2341 nl80211_can_set_dev_channel(wdev) ? netdev : NULL,
2342 info);
72bdcf34 2343 if (result)
7f2b8562 2344 return result;
72bdcf34
JM
2345 }
2346
98d2ff8b 2347 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 2348 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
2349 enum nl80211_tx_power_setting type;
2350 int idx, mbm = 0;
2351
c8442118
JB
2352 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
2353 txp_wdev = NULL;
2354
7f2b8562
YX
2355 if (!rdev->ops->set_tx_power)
2356 return -EOPNOTSUPP;
98d2ff8b
JO
2357
2358 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
2359 type = nla_get_u32(info->attrs[idx]);
2360
2361 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
7f2b8562
YX
2362 (type != NL80211_TX_POWER_AUTOMATIC))
2363 return -EINVAL;
98d2ff8b
JO
2364
2365 if (type != NL80211_TX_POWER_AUTOMATIC) {
2366 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
2367 mbm = nla_get_u32(info->attrs[idx]);
2368 }
2369
c8442118 2370 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b 2371 if (result)
7f2b8562 2372 return result;
98d2ff8b
JO
2373 }
2374
afe0cbf8
BR
2375 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
2376 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
2377 u32 tx_ant, rx_ant;
7a087e74 2378
7f531e03
BR
2379 if ((!rdev->wiphy.available_antennas_tx &&
2380 !rdev->wiphy.available_antennas_rx) ||
7f2b8562
YX
2381 !rdev->ops->set_antenna)
2382 return -EOPNOTSUPP;
afe0cbf8
BR
2383
2384 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
2385 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
2386
a7ffac95 2387 /* reject antenna configurations which don't match the
7f531e03
BR
2388 * available antenna masks, except for the "all" mask */
2389 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
7f2b8562
YX
2390 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx)))
2391 return -EINVAL;
a7ffac95 2392
7f531e03
BR
2393 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
2394 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 2395
e35e4d28 2396 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8 2397 if (result)
7f2b8562 2398 return result;
afe0cbf8
BR
2399 }
2400
b9a5f8ca
JM
2401 changed = 0;
2402
2403 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
2404 retry_short = nla_get_u8(
2405 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
7f2b8562
YX
2406 if (retry_short == 0)
2407 return -EINVAL;
2408
b9a5f8ca
JM
2409 changed |= WIPHY_PARAM_RETRY_SHORT;
2410 }
2411
2412 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2413 retry_long = nla_get_u8(
2414 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
7f2b8562
YX
2415 if (retry_long == 0)
2416 return -EINVAL;
2417
b9a5f8ca
JM
2418 changed |= WIPHY_PARAM_RETRY_LONG;
2419 }
2420
2421 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2422 frag_threshold = nla_get_u32(
2423 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
7f2b8562
YX
2424 if (frag_threshold < 256)
2425 return -EINVAL;
2426
b9a5f8ca
JM
2427 if (frag_threshold != (u32) -1) {
2428 /*
2429 * Fragments (apart from the last one) are required to
2430 * have even length. Make the fragmentation code
2431 * simpler by stripping LSB should someone try to use
2432 * odd threshold value.
2433 */
2434 frag_threshold &= ~0x1;
2435 }
2436 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2437 }
2438
2439 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2440 rts_threshold = nla_get_u32(
2441 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2442 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2443 }
2444
81077e82 2445 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
3057dbfd
LB
2446 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK])
2447 return -EINVAL;
2448
81077e82
LT
2449 coverage_class = nla_get_u8(
2450 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2451 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2452 }
2453
3057dbfd
LB
2454 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
2455 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION))
2456 return -EOPNOTSUPP;
2457
2458 changed |= WIPHY_PARAM_DYN_ACK;
81077e82
LT
2459 }
2460
b9a5f8ca
JM
2461 if (changed) {
2462 u8 old_retry_short, old_retry_long;
2463 u32 old_frag_threshold, old_rts_threshold;
81077e82 2464 u8 old_coverage_class;
b9a5f8ca 2465
7f2b8562
YX
2466 if (!rdev->ops->set_wiphy_params)
2467 return -EOPNOTSUPP;
b9a5f8ca
JM
2468
2469 old_retry_short = rdev->wiphy.retry_short;
2470 old_retry_long = rdev->wiphy.retry_long;
2471 old_frag_threshold = rdev->wiphy.frag_threshold;
2472 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 2473 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
2474
2475 if (changed & WIPHY_PARAM_RETRY_SHORT)
2476 rdev->wiphy.retry_short = retry_short;
2477 if (changed & WIPHY_PARAM_RETRY_LONG)
2478 rdev->wiphy.retry_long = retry_long;
2479 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
2480 rdev->wiphy.frag_threshold = frag_threshold;
2481 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
2482 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
2483 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
2484 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 2485
e35e4d28 2486 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
2487 if (result) {
2488 rdev->wiphy.retry_short = old_retry_short;
2489 rdev->wiphy.retry_long = old_retry_long;
2490 rdev->wiphy.frag_threshold = old_frag_threshold;
2491 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 2492 rdev->wiphy.coverage_class = old_coverage_class;
9189ee31 2493 return result;
b9a5f8ca
JM
2494 }
2495 }
7f2b8562 2496 return 0;
55682965
JB
2497}
2498
71bbc994
JB
2499static inline u64 wdev_id(struct wireless_dev *wdev)
2500{
2501 return (u64)wdev->identifier |
f26cbf40 2502 ((u64)wiphy_to_rdev(wdev->wiphy)->wiphy_idx << 32);
71bbc994 2503}
55682965 2504
683b6d3b 2505static int nl80211_send_chandef(struct sk_buff *msg,
d2859df5 2506 const struct cfg80211_chan_def *chandef)
683b6d3b 2507{
601555cd
JB
2508 if (WARN_ON(!cfg80211_chandef_valid(chandef)))
2509 return -EINVAL;
3d9d1d66 2510
683b6d3b
JB
2511 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
2512 chandef->chan->center_freq))
2513 return -ENOBUFS;
3d9d1d66
JB
2514 switch (chandef->width) {
2515 case NL80211_CHAN_WIDTH_20_NOHT:
2516 case NL80211_CHAN_WIDTH_20:
2517 case NL80211_CHAN_WIDTH_40:
2518 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2519 cfg80211_get_chandef_type(chandef)))
2520 return -ENOBUFS;
2521 break;
2522 default:
2523 break;
2524 }
2525 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
2526 return -ENOBUFS;
2527 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
2528 return -ENOBUFS;
2529 if (chandef->center_freq2 &&
2530 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
2531 return -ENOBUFS;
2532 return 0;
2533}
2534
15e47304 2535static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 2536 struct cfg80211_registered_device *rdev,
8f894be2 2537 struct wireless_dev *wdev, bool removal)
55682965 2538{
72fb2abc 2539 struct net_device *dev = wdev->netdev;
8f894be2 2540 u8 cmd = NL80211_CMD_NEW_INTERFACE;
55682965
JB
2541 void *hdr;
2542
8f894be2
TB
2543 if (removal)
2544 cmd = NL80211_CMD_DEL_INTERFACE;
2545
2546 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
55682965
JB
2547 if (!hdr)
2548 return -1;
2549
72fb2abc
JB
2550 if (dev &&
2551 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 2552 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
2553 goto nla_put_failure;
2554
2555 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2556 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
2dad624e
ND
2557 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
2558 NL80211_ATTR_PAD) ||
98104fde 2559 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
2560 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2561 rdev->devlist_generation ^
2562 (cfg80211_rdev_list_generation << 2)))
2563 goto nla_put_failure;
f5ea9120 2564
5b7ccaf3 2565 if (rdev->ops->get_channel) {
683b6d3b
JB
2566 int ret;
2567 struct cfg80211_chan_def chandef;
2568
2569 ret = rdev_get_channel(rdev, wdev, &chandef);
2570 if (ret == 0) {
2571 if (nl80211_send_chandef(msg, &chandef))
2572 goto nla_put_failure;
2573 }
d91df0e3
PF
2574 }
2575
d55d0d59
RM
2576 if (rdev->ops->get_tx_power) {
2577 int dbm, ret;
2578
2579 ret = rdev_get_tx_power(rdev, wdev, &dbm);
2580 if (ret == 0 &&
2581 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL,
2582 DBM_TO_MBM(dbm)))
2583 goto nla_put_failure;
2584 }
2585
b84e7a05
AQ
2586 if (wdev->ssid_len) {
2587 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
2588 goto nla_put_failure;
2589 }
2590
053c095a
JB
2591 genlmsg_end(msg, hdr);
2592 return 0;
55682965
JB
2593
2594 nla_put_failure:
bc3ed28c
TG
2595 genlmsg_cancel(msg, hdr);
2596 return -EMSGSIZE;
55682965
JB
2597}
2598
2599static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
2600{
2601 int wp_idx = 0;
2602 int if_idx = 0;
2603 int wp_start = cb->args[0];
2604 int if_start = cb->args[1];
b7fb44da 2605 int filter_wiphy = -1;
f5ea9120 2606 struct cfg80211_registered_device *rdev;
55682965
JB
2607 struct wireless_dev *wdev;
2608
5fe231e8 2609 rtnl_lock();
b7fb44da
DK
2610 if (!cb->args[2]) {
2611 struct nl80211_dump_wiphy_state state = {
2612 .filter_wiphy = -1,
2613 };
2614 int ret;
2615
2616 ret = nl80211_dump_wiphy_parse(skb, cb, &state);
2617 if (ret)
2618 return ret;
2619
2620 filter_wiphy = state.filter_wiphy;
2621
2622 /*
2623 * if filtering, set cb->args[2] to +1 since 0 is the default
2624 * value needed to determine that parsing is necessary.
2625 */
2626 if (filter_wiphy >= 0)
2627 cb->args[2] = filter_wiphy + 1;
2628 else
2629 cb->args[2] = -1;
2630 } else if (cb->args[2] > 0) {
2631 filter_wiphy = cb->args[2] - 1;
2632 }
2633
f5ea9120
JB
2634 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2635 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2636 continue;
bba95fef
JB
2637 if (wp_idx < wp_start) {
2638 wp_idx++;
55682965 2639 continue;
bba95fef 2640 }
b7fb44da
DK
2641
2642 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx)
2643 continue;
2644
55682965
JB
2645 if_idx = 0;
2646
53873f13 2647 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
bba95fef
JB
2648 if (if_idx < if_start) {
2649 if_idx++;
55682965 2650 continue;
bba95fef 2651 }
15e47304 2652 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 2653 cb->nlh->nlmsg_seq, NLM_F_MULTI,
8f894be2 2654 rdev, wdev, false) < 0) {
bba95fef
JB
2655 goto out;
2656 }
2657 if_idx++;
55682965 2658 }
bba95fef
JB
2659
2660 wp_idx++;
55682965 2661 }
bba95fef 2662 out:
5fe231e8 2663 rtnl_unlock();
55682965
JB
2664
2665 cb->args[0] = wp_idx;
2666 cb->args[1] = if_idx;
2667
2668 return skb->len;
2669}
2670
2671static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
2672{
2673 struct sk_buff *msg;
1b8ec87a 2674 struct cfg80211_registered_device *rdev = info->user_ptr[0];
72fb2abc 2675 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2676
fd2120ca 2677 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 2678 if (!msg)
4c476991 2679 return -ENOMEM;
55682965 2680
15e47304 2681 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
8f894be2 2682 rdev, wdev, false) < 0) {
4c476991
JB
2683 nlmsg_free(msg);
2684 return -ENOBUFS;
2685 }
55682965 2686
134e6375 2687 return genlmsg_reply(msg, info);
55682965
JB
2688}
2689
66f7ac50
MW
2690static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2691 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2692 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2693 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2694 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2695 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 2696 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
2697};
2698
2699static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2700{
2701 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2702 int flag;
2703
2704 *mntrflags = 0;
2705
2706 if (!nla)
2707 return -EINVAL;
2708
2709 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
2710 nla, mntr_flags_policy))
2711 return -EINVAL;
2712
2713 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2714 if (flags[flag])
2715 *mntrflags |= (1<<flag);
2716
2717 return 0;
2718}
2719
9bc383de 2720static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2721 struct net_device *netdev, u8 use_4addr,
2722 enum nl80211_iftype iftype)
9bc383de 2723{
ad4bb6f8 2724 if (!use_4addr) {
f350a0a8 2725 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2726 return -EBUSY;
9bc383de 2727 return 0;
ad4bb6f8 2728 }
9bc383de
JB
2729
2730 switch (iftype) {
2731 case NL80211_IFTYPE_AP_VLAN:
2732 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2733 return 0;
2734 break;
2735 case NL80211_IFTYPE_STATION:
2736 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2737 return 0;
2738 break;
2739 default:
2740 break;
2741 }
2742
2743 return -EOPNOTSUPP;
2744}
2745
55682965
JB
2746static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2747{
4c476991 2748 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2749 struct vif_params params;
e36d56b6 2750 int err;
04a773ad 2751 enum nl80211_iftype otype, ntype;
4c476991 2752 struct net_device *dev = info->user_ptr[1];
92ffe055 2753 u32 _flags, *flags = NULL;
ac7f9cfa 2754 bool change = false;
55682965 2755
2ec600d6
LCC
2756 memset(&params, 0, sizeof(params));
2757
04a773ad 2758 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2759
723b038d 2760 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2761 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2762 if (otype != ntype)
ac7f9cfa 2763 change = true;
4c476991
JB
2764 if (ntype > NL80211_IFTYPE_MAX)
2765 return -EINVAL;
723b038d
JB
2766 }
2767
92ffe055 2768 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2769 struct wireless_dev *wdev = dev->ieee80211_ptr;
2770
4c476991
JB
2771 if (ntype != NL80211_IFTYPE_MESH_POINT)
2772 return -EINVAL;
29cbe68c
JB
2773 if (netif_running(dev))
2774 return -EBUSY;
2775
2776 wdev_lock(wdev);
2777 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2778 IEEE80211_MAX_MESH_ID_LEN);
2779 wdev->mesh_id_up_len =
2780 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2781 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2782 wdev->mesh_id_up_len);
2783 wdev_unlock(wdev);
2ec600d6
LCC
2784 }
2785
8b787643
FF
2786 if (info->attrs[NL80211_ATTR_4ADDR]) {
2787 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2788 change = true;
ad4bb6f8 2789 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2790 if (err)
4c476991 2791 return err;
8b787643
FF
2792 } else {
2793 params.use_4addr = -1;
2794 }
2795
92ffe055 2796 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2797 if (ntype != NL80211_IFTYPE_MONITOR)
2798 return -EINVAL;
92ffe055
JB
2799 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2800 &_flags);
ac7f9cfa 2801 if (err)
4c476991 2802 return err;
ac7f9cfa
JB
2803
2804 flags = &_flags;
2805 change = true;
92ffe055 2806 }
3b85875a 2807
c6e6a0c8
AE
2808 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) {
2809 const u8 *mumimo_groups;
2810 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
2811
2812 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
2813 return -EOPNOTSUPP;
2814
2815 mumimo_groups =
2816 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]);
2817
2818 /* bits 0 and 63 are reserved and must be zero */
2819 if ((mumimo_groups[0] & BIT(7)) ||
2820 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(0)))
2821 return -EINVAL;
2822
2823 memcpy(params.vht_mumimo_groups, mumimo_groups,
2824 VHT_MUMIMO_GROUPS_DATA_LEN);
2825 change = true;
2826 }
2827
2828 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) {
2829 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
2830
2831 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
2832 return -EOPNOTSUPP;
2833
2834 nla_memcpy(params.macaddr,
2835 info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR],
2836 ETH_ALEN);
2837 change = true;
2838 }
2839
18003297 2840 if (flags && (*flags & MONITOR_FLAG_ACTIVE) &&
e057d3c3
FF
2841 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2842 return -EOPNOTSUPP;
2843
ac7f9cfa 2844 if (change)
3d54d255 2845 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2846 else
2847 err = 0;
60719ffd 2848
9bc383de
JB
2849 if (!err && params.use_4addr != -1)
2850 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2851
55682965
JB
2852 return err;
2853}
2854
2855static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2856{
4c476991 2857 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2858 struct vif_params params;
84efbb84 2859 struct wireless_dev *wdev;
896ff063 2860 struct sk_buff *msg;
55682965
JB
2861 int err;
2862 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2863 u32 flags;
55682965 2864
78f22b6a
JB
2865 /* to avoid failing a new interface creation due to pending removal */
2866 cfg80211_destroy_ifaces(rdev);
2867
2ec600d6
LCC
2868 memset(&params, 0, sizeof(params));
2869
55682965
JB
2870 if (!info->attrs[NL80211_ATTR_IFNAME])
2871 return -EINVAL;
2872
2873 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2874 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2875 if (type > NL80211_IFTYPE_MAX)
2876 return -EINVAL;
2877 }
2878
79c97e97 2879 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2880 !(rdev->wiphy.interface_modes & (1 << type)))
2881 return -EOPNOTSUPP;
55682965 2882
cb3b7d87 2883 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN ||
e8f479b1
BG
2884 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) &&
2885 info->attrs[NL80211_ATTR_MAC]) {
1c18f145
AS
2886 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2887 ETH_ALEN);
2888 if (!is_valid_ether_addr(params.macaddr))
2889 return -EADDRNOTAVAIL;
2890 }
2891
9bc383de 2892 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2893 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2894 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2895 if (err)
4c476991 2896 return err;
9bc383de 2897 }
8b787643 2898
66f7ac50
MW
2899 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2900 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2901 &flags);
e057d3c3 2902
18003297 2903 if (!err && (flags & MONITOR_FLAG_ACTIVE) &&
e057d3c3
FF
2904 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2905 return -EOPNOTSUPP;
2906
a18c7192
JB
2907 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2908 if (!msg)
2909 return -ENOMEM;
2910
e35e4d28
HG
2911 wdev = rdev_add_virtual_intf(rdev,
2912 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
6bab2e19
TG
2913 NET_NAME_USER, type, err ? NULL : &flags,
2914 &params);
d687cbb7
RM
2915 if (WARN_ON(!wdev)) {
2916 nlmsg_free(msg);
2917 return -EPROTO;
2918 } else if (IS_ERR(wdev)) {
1c90f9d4 2919 nlmsg_free(msg);
84efbb84 2920 return PTR_ERR(wdev);
1c90f9d4 2921 }
2ec600d6 2922
18e5ca65 2923 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
78f22b6a
JB
2924 wdev->owner_nlportid = info->snd_portid;
2925
98104fde
JB
2926 switch (type) {
2927 case NL80211_IFTYPE_MESH_POINT:
2928 if (!info->attrs[NL80211_ATTR_MESH_ID])
2929 break;
29cbe68c
JB
2930 wdev_lock(wdev);
2931 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2932 IEEE80211_MAX_MESH_ID_LEN);
2933 wdev->mesh_id_up_len =
2934 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2935 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2936 wdev->mesh_id_up_len);
2937 wdev_unlock(wdev);
98104fde 2938 break;
cb3b7d87 2939 case NL80211_IFTYPE_NAN:
98104fde
JB
2940 case NL80211_IFTYPE_P2P_DEVICE:
2941 /*
cb3b7d87 2942 * P2P Device and NAN do not have a netdev, so don't go
98104fde
JB
2943 * through the netdev notifier and must be added here
2944 */
2945 mutex_init(&wdev->mtx);
2946 INIT_LIST_HEAD(&wdev->event_list);
2947 spin_lock_init(&wdev->event_lock);
2948 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2949 spin_lock_init(&wdev->mgmt_registrations_lock);
2950
98104fde 2951 wdev->identifier = ++rdev->wdev_id;
53873f13 2952 list_add_rcu(&wdev->list, &rdev->wiphy.wdev_list);
98104fde 2953 rdev->devlist_generation++;
98104fde
JB
2954 break;
2955 default:
2956 break;
29cbe68c
JB
2957 }
2958
15e47304 2959 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
8f894be2 2960 rdev, wdev, false) < 0) {
1c90f9d4
JB
2961 nlmsg_free(msg);
2962 return -ENOBUFS;
2963 }
2964
896ff063
DK
2965 /*
2966 * For wdevs which have no associated netdev object (e.g. of type
2967 * NL80211_IFTYPE_P2P_DEVICE), emit the NEW_INTERFACE event here.
2968 * For all other types, the event will be generated from the
2969 * netdev notifier
2970 */
2971 if (!wdev->netdev)
2972 nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE);
8f894be2 2973
1c90f9d4 2974 return genlmsg_reply(msg, info);
55682965
JB
2975}
2976
2977static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2978{
4c476991 2979 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2980 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2981
4c476991
JB
2982 if (!rdev->ops->del_virtual_intf)
2983 return -EOPNOTSUPP;
55682965 2984
84efbb84
JB
2985 /*
2986 * If we remove a wireless device without a netdev then clear
2987 * user_ptr[1] so that nl80211_post_doit won't dereference it
2988 * to check if it needs to do dev_put(). Otherwise it crashes
2989 * since the wdev has been freed, unlike with a netdev where
2990 * we need the dev_put() for the netdev to really be freed.
2991 */
2992 if (!wdev->netdev)
2993 info->user_ptr[1] = NULL;
2994
7f8ed01e 2995 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2996}
2997
1d9d9213
SW
2998static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2999{
3000 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3001 struct net_device *dev = info->user_ptr[1];
3002 u16 noack_map;
3003
3004 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
3005 return -EINVAL;
3006
3007 if (!rdev->ops->set_noack_map)
3008 return -EOPNOTSUPP;
3009
3010 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
3011
e35e4d28 3012 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
3013}
3014
41ade00f
JB
3015struct get_key_cookie {
3016 struct sk_buff *msg;
3017 int error;
b9454e83 3018 int idx;
41ade00f
JB
3019};
3020
3021static void get_key_callback(void *c, struct key_params *params)
3022{
b9454e83 3023 struct nlattr *key;
41ade00f
JB
3024 struct get_key_cookie *cookie = c;
3025
9360ffd1
DM
3026 if ((params->key &&
3027 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
3028 params->key_len, params->key)) ||
3029 (params->seq &&
3030 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
3031 params->seq_len, params->seq)) ||
3032 (params->cipher &&
3033 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
3034 params->cipher)))
3035 goto nla_put_failure;
41ade00f 3036
b9454e83
JB
3037 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
3038 if (!key)
3039 goto nla_put_failure;
3040
9360ffd1
DM
3041 if ((params->key &&
3042 nla_put(cookie->msg, NL80211_KEY_DATA,
3043 params->key_len, params->key)) ||
3044 (params->seq &&
3045 nla_put(cookie->msg, NL80211_KEY_SEQ,
3046 params->seq_len, params->seq)) ||
3047 (params->cipher &&
3048 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
3049 params->cipher)))
3050 goto nla_put_failure;
b9454e83 3051
9360ffd1
DM
3052 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
3053 goto nla_put_failure;
b9454e83
JB
3054
3055 nla_nest_end(cookie->msg, key);
3056
41ade00f
JB
3057 return;
3058 nla_put_failure:
3059 cookie->error = 1;
3060}
3061
3062static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
3063{
4c476991 3064 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3065 int err;
4c476991 3066 struct net_device *dev = info->user_ptr[1];
41ade00f 3067 u8 key_idx = 0;
e31b8213
JB
3068 const u8 *mac_addr = NULL;
3069 bool pairwise;
41ade00f
JB
3070 struct get_key_cookie cookie = {
3071 .error = 0,
3072 };
3073 void *hdr;
3074 struct sk_buff *msg;
3075
3076 if (info->attrs[NL80211_ATTR_KEY_IDX])
3077 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
3078
3cfcf6ac 3079 if (key_idx > 5)
41ade00f
JB
3080 return -EINVAL;
3081
3082 if (info->attrs[NL80211_ATTR_MAC])
3083 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3084
e31b8213
JB
3085 pairwise = !!mac_addr;
3086 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
3087 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
7a087e74 3088
e31b8213
JB
3089 if (kt >= NUM_NL80211_KEYTYPES)
3090 return -EINVAL;
3091 if (kt != NL80211_KEYTYPE_GROUP &&
3092 kt != NL80211_KEYTYPE_PAIRWISE)
3093 return -EINVAL;
3094 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
3095 }
3096
4c476991
JB
3097 if (!rdev->ops->get_key)
3098 return -EOPNOTSUPP;
41ade00f 3099
0fa7b391
JB
3100 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3101 return -ENOENT;
3102
fd2120ca 3103 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3104 if (!msg)
3105 return -ENOMEM;
41ade00f 3106
15e47304 3107 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 3108 NL80211_CMD_NEW_KEY);
cb35fba3 3109 if (!hdr)
9fe271af 3110 goto nla_put_failure;
41ade00f
JB
3111
3112 cookie.msg = msg;
b9454e83 3113 cookie.idx = key_idx;
41ade00f 3114
9360ffd1
DM
3115 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3116 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
3117 goto nla_put_failure;
3118 if (mac_addr &&
3119 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
3120 goto nla_put_failure;
41ade00f 3121
e35e4d28
HG
3122 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
3123 get_key_callback);
41ade00f
JB
3124
3125 if (err)
6c95e2a2 3126 goto free_msg;
41ade00f
JB
3127
3128 if (cookie.error)
3129 goto nla_put_failure;
3130
3131 genlmsg_end(msg, hdr);
4c476991 3132 return genlmsg_reply(msg, info);
41ade00f
JB
3133
3134 nla_put_failure:
3135 err = -ENOBUFS;
6c95e2a2 3136 free_msg:
41ade00f 3137 nlmsg_free(msg);
41ade00f
JB
3138 return err;
3139}
3140
3141static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
3142{
4c476991 3143 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 3144 struct key_parse key;
41ade00f 3145 int err;
4c476991 3146 struct net_device *dev = info->user_ptr[1];
41ade00f 3147
b9454e83
JB
3148 err = nl80211_parse_key(info, &key);
3149 if (err)
3150 return err;
41ade00f 3151
b9454e83 3152 if (key.idx < 0)
41ade00f
JB
3153 return -EINVAL;
3154
b9454e83
JB
3155 /* only support setting default key */
3156 if (!key.def && !key.defmgmt)
41ade00f
JB
3157 return -EINVAL;
3158
dbd2fd65 3159 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 3160
dbd2fd65
JB
3161 if (key.def) {
3162 if (!rdev->ops->set_default_key) {
3163 err = -EOPNOTSUPP;
3164 goto out;
3165 }
41ade00f 3166
dbd2fd65
JB
3167 err = nl80211_key_allowed(dev->ieee80211_ptr);
3168 if (err)
3169 goto out;
3170
e35e4d28 3171 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
3172 key.def_uni, key.def_multi);
3173
3174 if (err)
3175 goto out;
fffd0934 3176
3d23e349 3177#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
3178 dev->ieee80211_ptr->wext.default_key = key.idx;
3179#endif
3180 } else {
3181 if (key.def_uni || !key.def_multi) {
3182 err = -EINVAL;
3183 goto out;
3184 }
3185
3186 if (!rdev->ops->set_default_mgmt_key) {
3187 err = -EOPNOTSUPP;
3188 goto out;
3189 }
3190
3191 err = nl80211_key_allowed(dev->ieee80211_ptr);
3192 if (err)
3193 goto out;
3194
e35e4d28 3195 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
3196 if (err)
3197 goto out;
3198
3199#ifdef CONFIG_CFG80211_WEXT
3200 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 3201#endif
dbd2fd65
JB
3202 }
3203
3204 out:
fffd0934 3205 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3206
41ade00f
JB
3207 return err;
3208}
3209
3210static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
3211{
4c476991 3212 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 3213 int err;
4c476991 3214 struct net_device *dev = info->user_ptr[1];
b9454e83 3215 struct key_parse key;
e31b8213 3216 const u8 *mac_addr = NULL;
41ade00f 3217
b9454e83
JB
3218 err = nl80211_parse_key(info, &key);
3219 if (err)
3220 return err;
41ade00f 3221
b9454e83 3222 if (!key.p.key)
41ade00f
JB
3223 return -EINVAL;
3224
41ade00f
JB
3225 if (info->attrs[NL80211_ATTR_MAC])
3226 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3227
e31b8213
JB
3228 if (key.type == -1) {
3229 if (mac_addr)
3230 key.type = NL80211_KEYTYPE_PAIRWISE;
3231 else
3232 key.type = NL80211_KEYTYPE_GROUP;
3233 }
3234
3235 /* for now */
3236 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3237 key.type != NL80211_KEYTYPE_GROUP)
3238 return -EINVAL;
3239
4c476991
JB
3240 if (!rdev->ops->add_key)
3241 return -EOPNOTSUPP;
25e47c18 3242
e31b8213
JB
3243 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
3244 key.type == NL80211_KEYTYPE_PAIRWISE,
3245 mac_addr))
4c476991 3246 return -EINVAL;
41ade00f 3247
fffd0934
JB
3248 wdev_lock(dev->ieee80211_ptr);
3249 err = nl80211_key_allowed(dev->ieee80211_ptr);
3250 if (!err)
e35e4d28
HG
3251 err = rdev_add_key(rdev, dev, key.idx,
3252 key.type == NL80211_KEYTYPE_PAIRWISE,
3253 mac_addr, &key.p);
fffd0934 3254 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3255
41ade00f
JB
3256 return err;
3257}
3258
3259static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
3260{
4c476991 3261 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3262 int err;
4c476991 3263 struct net_device *dev = info->user_ptr[1];
41ade00f 3264 u8 *mac_addr = NULL;
b9454e83 3265 struct key_parse key;
41ade00f 3266
b9454e83
JB
3267 err = nl80211_parse_key(info, &key);
3268 if (err)
3269 return err;
41ade00f
JB
3270
3271 if (info->attrs[NL80211_ATTR_MAC])
3272 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3273
e31b8213
JB
3274 if (key.type == -1) {
3275 if (mac_addr)
3276 key.type = NL80211_KEYTYPE_PAIRWISE;
3277 else
3278 key.type = NL80211_KEYTYPE_GROUP;
3279 }
3280
3281 /* for now */
3282 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3283 key.type != NL80211_KEYTYPE_GROUP)
3284 return -EINVAL;
3285
4c476991
JB
3286 if (!rdev->ops->del_key)
3287 return -EOPNOTSUPP;
41ade00f 3288
fffd0934
JB
3289 wdev_lock(dev->ieee80211_ptr);
3290 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213 3291
0fa7b391 3292 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr &&
e31b8213
JB
3293 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3294 err = -ENOENT;
3295
fffd0934 3296 if (!err)
e35e4d28
HG
3297 err = rdev_del_key(rdev, dev, key.idx,
3298 key.type == NL80211_KEYTYPE_PAIRWISE,
3299 mac_addr);
41ade00f 3300
3d23e349 3301#ifdef CONFIG_CFG80211_WEXT
08645126 3302 if (!err) {
b9454e83 3303 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 3304 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 3305 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
3306 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
3307 }
3308#endif
fffd0934 3309 wdev_unlock(dev->ieee80211_ptr);
08645126 3310
41ade00f
JB
3311 return err;
3312}
3313
77765eaf
VT
3314/* This function returns an error or the number of nested attributes */
3315static int validate_acl_mac_addrs(struct nlattr *nl_attr)
3316{
3317 struct nlattr *attr;
3318 int n_entries = 0, tmp;
3319
3320 nla_for_each_nested(attr, nl_attr, tmp) {
3321 if (nla_len(attr) != ETH_ALEN)
3322 return -EINVAL;
3323
3324 n_entries++;
3325 }
3326
3327 return n_entries;
3328}
3329
3330/*
3331 * This function parses ACL information and allocates memory for ACL data.
3332 * On successful return, the calling function is responsible to free the
3333 * ACL buffer returned by this function.
3334 */
3335static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
3336 struct genl_info *info)
3337{
3338 enum nl80211_acl_policy acl_policy;
3339 struct nlattr *attr;
3340 struct cfg80211_acl_data *acl;
3341 int i = 0, n_entries, tmp;
3342
3343 if (!wiphy->max_acl_mac_addrs)
3344 return ERR_PTR(-EOPNOTSUPP);
3345
3346 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
3347 return ERR_PTR(-EINVAL);
3348
3349 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
3350 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
3351 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
3352 return ERR_PTR(-EINVAL);
3353
3354 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
3355 return ERR_PTR(-EINVAL);
3356
3357 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
3358 if (n_entries < 0)
3359 return ERR_PTR(n_entries);
3360
3361 if (n_entries > wiphy->max_acl_mac_addrs)
3362 return ERR_PTR(-ENOTSUPP);
3363
3364 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
3365 GFP_KERNEL);
3366 if (!acl)
3367 return ERR_PTR(-ENOMEM);
3368
3369 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
3370 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
3371 i++;
3372 }
3373
3374 acl->n_acl_entries = n_entries;
3375 acl->acl_policy = acl_policy;
3376
3377 return acl;
3378}
3379
3380static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
3381{
3382 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3383 struct net_device *dev = info->user_ptr[1];
3384 struct cfg80211_acl_data *acl;
3385 int err;
3386
3387 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3388 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3389 return -EOPNOTSUPP;
3390
3391 if (!dev->ieee80211_ptr->beacon_interval)
3392 return -EINVAL;
3393
3394 acl = parse_acl_data(&rdev->wiphy, info);
3395 if (IS_ERR(acl))
3396 return PTR_ERR(acl);
3397
3398 err = rdev_set_mac_acl(rdev, dev, acl);
3399
3400 kfree(acl);
3401
3402 return err;
3403}
3404
a7c7fbff
PK
3405static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
3406 u8 *rates, u8 rates_len)
3407{
3408 u8 i;
3409 u32 mask = 0;
3410
3411 for (i = 0; i < rates_len; i++) {
3412 int rate = (rates[i] & 0x7f) * 5;
3413 int ridx;
3414
3415 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
3416 struct ieee80211_rate *srate =
3417 &sband->bitrates[ridx];
3418 if (rate == srate->bitrate) {
3419 mask |= 1 << ridx;
3420 break;
3421 }
3422 }
3423 if (ridx == sband->n_bitrates)
3424 return 0; /* rate not found */
3425 }
3426
3427 return mask;
3428}
3429
3430static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
3431 u8 *rates, u8 rates_len,
3432 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
3433{
3434 u8 i;
3435
3436 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
3437
3438 for (i = 0; i < rates_len; i++) {
3439 int ridx, rbit;
3440
3441 ridx = rates[i] / 8;
3442 rbit = BIT(rates[i] % 8);
3443
3444 /* check validity */
3445 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
3446 return false;
3447
3448 /* check availability */
3449 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
3450 mcs[ridx] |= rbit;
3451 else
3452 return false;
3453 }
3454
3455 return true;
3456}
3457
3458static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
3459{
3460 u16 mcs_mask = 0;
3461
3462 switch (vht_mcs_map) {
3463 case IEEE80211_VHT_MCS_NOT_SUPPORTED:
3464 break;
3465 case IEEE80211_VHT_MCS_SUPPORT_0_7:
3466 mcs_mask = 0x00FF;
3467 break;
3468 case IEEE80211_VHT_MCS_SUPPORT_0_8:
3469 mcs_mask = 0x01FF;
3470 break;
3471 case IEEE80211_VHT_MCS_SUPPORT_0_9:
3472 mcs_mask = 0x03FF;
3473 break;
3474 default:
3475 break;
3476 }
3477
3478 return mcs_mask;
3479}
3480
3481static void vht_build_mcs_mask(u16 vht_mcs_map,
3482 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
3483{
3484 u8 nss;
3485
3486 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
3487 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
3488 vht_mcs_map >>= 2;
3489 }
3490}
3491
3492static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
3493 struct nl80211_txrate_vht *txrate,
3494 u16 mcs[NL80211_VHT_NSS_MAX])
3495{
3496 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
3497 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
3498 u8 i;
3499
3500 if (!sband->vht_cap.vht_supported)
3501 return false;
3502
3503 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
3504
3505 /* Build vht_mcs_mask from VHT capabilities */
3506 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
3507
3508 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
3509 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
3510 mcs[i] = txrate->mcs[i];
3511 else
3512 return false;
3513 }
3514
3515 return true;
3516}
3517
3518static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
3519 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
3520 .len = NL80211_MAX_SUPP_RATES },
3521 [NL80211_TXRATE_HT] = { .type = NLA_BINARY,
3522 .len = NL80211_MAX_SUPP_HT_RATES },
3523 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)},
3524 [NL80211_TXRATE_GI] = { .type = NLA_U8 },
3525};
3526
3527static int nl80211_parse_tx_bitrate_mask(struct genl_info *info,
3528 struct cfg80211_bitrate_mask *mask)
3529{
3530 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
3531 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3532 int rem, i;
3533 struct nlattr *tx_rates;
3534 struct ieee80211_supported_band *sband;
3535 u16 vht_tx_mcs_map;
3536
3537 memset(mask, 0, sizeof(*mask));
3538 /* Default to all rates enabled */
3539 for (i = 0; i < NUM_NL80211_BANDS; i++) {
3540 sband = rdev->wiphy.bands[i];
3541
3542 if (!sband)
3543 continue;
3544
3545 mask->control[i].legacy = (1 << sband->n_bitrates) - 1;
3546 memcpy(mask->control[i].ht_mcs,
3547 sband->ht_cap.mcs.rx_mask,
3548 sizeof(mask->control[i].ht_mcs));
3549
3550 if (!sband->vht_cap.vht_supported)
3551 continue;
3552
3553 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
3554 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs);
3555 }
3556
3557 /* if no rates are given set it back to the defaults */
3558 if (!info->attrs[NL80211_ATTR_TX_RATES])
3559 goto out;
3560
3561 /* The nested attribute uses enum nl80211_band as the index. This maps
3562 * directly to the enum nl80211_band values used in cfg80211.
3563 */
3564 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
3565 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) {
3566 enum nl80211_band band = nla_type(tx_rates);
3567 int err;
3568
3569 if (band < 0 || band >= NUM_NL80211_BANDS)
3570 return -EINVAL;
3571 sband = rdev->wiphy.bands[band];
3572 if (sband == NULL)
3573 return -EINVAL;
bfe2c7b1
JB
3574 err = nla_parse_nested(tb, NL80211_TXRATE_MAX, tx_rates,
3575 nl80211_txattr_policy);
a7c7fbff
PK
3576 if (err)
3577 return err;
3578 if (tb[NL80211_TXRATE_LEGACY]) {
3579 mask->control[band].legacy = rateset_to_mask(
3580 sband,
3581 nla_data(tb[NL80211_TXRATE_LEGACY]),
3582 nla_len(tb[NL80211_TXRATE_LEGACY]));
3583 if ((mask->control[band].legacy == 0) &&
3584 nla_len(tb[NL80211_TXRATE_LEGACY]))
3585 return -EINVAL;
3586 }
3587 if (tb[NL80211_TXRATE_HT]) {
3588 if (!ht_rateset_to_mask(
3589 sband,
3590 nla_data(tb[NL80211_TXRATE_HT]),
3591 nla_len(tb[NL80211_TXRATE_HT]),
3592 mask->control[band].ht_mcs))
3593 return -EINVAL;
3594 }
3595 if (tb[NL80211_TXRATE_VHT]) {
3596 if (!vht_set_mcs_mask(
3597 sband,
3598 nla_data(tb[NL80211_TXRATE_VHT]),
3599 mask->control[band].vht_mcs))
3600 return -EINVAL;
3601 }
3602 if (tb[NL80211_TXRATE_GI]) {
3603 mask->control[band].gi =
3604 nla_get_u8(tb[NL80211_TXRATE_GI]);
3605 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI)
3606 return -EINVAL;
3607 }
3608
3609 if (mask->control[band].legacy == 0) {
3610 /* don't allow empty legacy rates if HT or VHT
3611 * are not even supported.
3612 */
3613 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
3614 rdev->wiphy.bands[band]->vht_cap.vht_supported))
3615 return -EINVAL;
3616
3617 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
3618 if (mask->control[band].ht_mcs[i])
3619 goto out;
3620
3621 for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
3622 if (mask->control[band].vht_mcs[i])
3623 goto out;
3624
3625 /* legacy and mcs rates may not be both empty */
3626 return -EINVAL;
3627 }
3628 }
3629
3630out:
3631 return 0;
3632}
3633
8564e382
JB
3634static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev,
3635 enum nl80211_band band,
3636 struct cfg80211_bitrate_mask *beacon_rate)
a7c7fbff 3637{
8564e382
JB
3638 u32 count_ht, count_vht, i;
3639 u32 rate = beacon_rate->control[band].legacy;
a7c7fbff
PK
3640
3641 /* Allow only one rate */
3642 if (hweight32(rate) > 1)
3643 return -EINVAL;
3644
3645 count_ht = 0;
3646 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) {
8564e382 3647 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) {
a7c7fbff 3648 return -EINVAL;
8564e382 3649 } else if (beacon_rate->control[band].ht_mcs[i]) {
a7c7fbff
PK
3650 count_ht++;
3651 if (count_ht > 1)
3652 return -EINVAL;
3653 }
3654 if (count_ht && rate)
3655 return -EINVAL;
3656 }
3657
3658 count_vht = 0;
3659 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
8564e382 3660 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) {
a7c7fbff 3661 return -EINVAL;
8564e382 3662 } else if (beacon_rate->control[band].vht_mcs[i]) {
a7c7fbff
PK
3663 count_vht++;
3664 if (count_vht > 1)
3665 return -EINVAL;
3666 }
3667 if (count_vht && rate)
3668 return -EINVAL;
3669 }
3670
3671 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht))
3672 return -EINVAL;
3673
8564e382
JB
3674 if (rate &&
3675 !wiphy_ext_feature_isset(&rdev->wiphy,
3676 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY))
3677 return -EINVAL;
3678 if (count_ht &&
3679 !wiphy_ext_feature_isset(&rdev->wiphy,
3680 NL80211_EXT_FEATURE_BEACON_RATE_HT))
3681 return -EINVAL;
3682 if (count_vht &&
3683 !wiphy_ext_feature_isset(&rdev->wiphy,
3684 NL80211_EXT_FEATURE_BEACON_RATE_VHT))
3685 return -EINVAL;
3686
a7c7fbff
PK
3687 return 0;
3688}
3689
a1193be8 3690static int nl80211_parse_beacon(struct nlattr *attrs[],
8860020e 3691 struct cfg80211_beacon_data *bcn)
ed1b6cc7 3692{
8860020e 3693 bool haveinfo = false;
ed1b6cc7 3694
a1193be8
SW
3695 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) ||
3696 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) ||
3697 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
3698 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
3699 return -EINVAL;
3700
8860020e 3701 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 3702
a1193be8
SW
3703 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
3704 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
3705 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
3706 if (!bcn->head_len)
3707 return -EINVAL;
3708 haveinfo = true;
ed1b6cc7
JB
3709 }
3710
a1193be8
SW
3711 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
3712 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
3713 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 3714 haveinfo = true;
ed1b6cc7
JB
3715 }
3716
4c476991
JB
3717 if (!haveinfo)
3718 return -EINVAL;
3b85875a 3719
a1193be8
SW
3720 if (attrs[NL80211_ATTR_IE]) {
3721 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
3722 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
3723 }
3724
a1193be8 3725 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 3726 bcn->proberesp_ies =
a1193be8 3727 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 3728 bcn->proberesp_ies_len =
a1193be8 3729 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
3730 }
3731
a1193be8 3732 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 3733 bcn->assocresp_ies =
a1193be8 3734 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 3735 bcn->assocresp_ies_len =
a1193be8 3736 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
3737 }
3738
a1193be8
SW
3739 if (attrs[NL80211_ATTR_PROBE_RESP]) {
3740 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
3741 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
3742 }
3743
8860020e
JB
3744 return 0;
3745}
3746
46c1dd0c
FF
3747static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
3748 struct cfg80211_ap_settings *params)
3749{
3750 struct wireless_dev *wdev;
3751 bool ret = false;
3752
53873f13 3753 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
46c1dd0c
FF
3754 if (wdev->iftype != NL80211_IFTYPE_AP &&
3755 wdev->iftype != NL80211_IFTYPE_P2P_GO)
3756 continue;
3757
683b6d3b 3758 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
3759 continue;
3760
683b6d3b 3761 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
3762 ret = true;
3763 break;
3764 }
3765
46c1dd0c
FF
3766 return ret;
3767}
3768
e39e5b5e
JM
3769static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
3770 enum nl80211_auth_type auth_type,
3771 enum nl80211_commands cmd)
3772{
3773 if (auth_type > NL80211_AUTHTYPE_MAX)
3774 return false;
3775
3776 switch (cmd) {
3777 case NL80211_CMD_AUTHENTICATE:
3778 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
3779 auth_type == NL80211_AUTHTYPE_SAE)
3780 return false;
63181060
JM
3781 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3782 NL80211_EXT_FEATURE_FILS_STA) &&
3783 (auth_type == NL80211_AUTHTYPE_FILS_SK ||
3784 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
3785 auth_type == NL80211_AUTHTYPE_FILS_PK))
3786 return false;
e39e5b5e
JM
3787 return true;
3788 case NL80211_CMD_CONNECT:
3789 case NL80211_CMD_START_AP:
3790 /* SAE not supported yet */
3791 if (auth_type == NL80211_AUTHTYPE_SAE)
3792 return false;
63181060
JM
3793 /* FILS not supported yet */
3794 if (auth_type == NL80211_AUTHTYPE_FILS_SK ||
3795 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
3796 auth_type == NL80211_AUTHTYPE_FILS_PK)
3797 return false;
e39e5b5e
JM
3798 return true;
3799 default:
3800 return false;
3801 }
3802}
3803
8860020e
JB
3804static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
3805{
3806 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3807 struct net_device *dev = info->user_ptr[1];
3808 struct wireless_dev *wdev = dev->ieee80211_ptr;
3809 struct cfg80211_ap_settings params;
3810 int err;
3811
3812 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3813 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3814 return -EOPNOTSUPP;
3815
3816 if (!rdev->ops->start_ap)
3817 return -EOPNOTSUPP;
3818
3819 if (wdev->beacon_interval)
3820 return -EALREADY;
3821
3822 memset(&params, 0, sizeof(params));
3823
3824 /* these are required for START_AP */
3825 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
3826 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
3827 !info->attrs[NL80211_ATTR_BEACON_HEAD])
3828 return -EINVAL;
3829
a1193be8 3830 err = nl80211_parse_beacon(info->attrs, &params.beacon);
8860020e
JB
3831 if (err)
3832 return err;
3833
3834 params.beacon_interval =
3835 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3836 params.dtim_period =
3837 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
3838
0c317a02
PK
3839 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype,
3840 params.beacon_interval);
8860020e
JB
3841 if (err)
3842 return err;
3843
3844 /*
3845 * In theory, some of these attributes should be required here
3846 * but since they were not used when the command was originally
3847 * added, keep them optional for old user space programs to let
3848 * them continue to work with drivers that do not need the
3849 * additional information -- drivers must check!
3850 */
3851 if (info->attrs[NL80211_ATTR_SSID]) {
3852 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3853 params.ssid_len =
3854 nla_len(info->attrs[NL80211_ATTR_SSID]);
3855 if (params.ssid_len == 0 ||
3856 params.ssid_len > IEEE80211_MAX_SSID_LEN)
3857 return -EINVAL;
3858 }
3859
3860 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
3861 params.hidden_ssid = nla_get_u32(
3862 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
3863 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
3864 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
3865 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
3866 return -EINVAL;
3867 }
3868
3869 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3870
3871 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3872 params.auth_type = nla_get_u32(
3873 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
3874 if (!nl80211_valid_auth_type(rdev, params.auth_type,
3875 NL80211_CMD_START_AP))
8860020e
JB
3876 return -EINVAL;
3877 } else
3878 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3879
3880 err = nl80211_crypto_settings(rdev, info, &params.crypto,
3881 NL80211_MAX_NR_CIPHER_SUITES);
3882 if (err)
3883 return err;
3884
1b658f11
VT
3885 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
3886 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
3887 return -EOPNOTSUPP;
3888 params.inactivity_timeout = nla_get_u16(
3889 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
3890 }
3891
53cabad7
JB
3892 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3893 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3894 return -EINVAL;
3895 params.p2p_ctwindow =
3896 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3897 if (params.p2p_ctwindow > 127)
3898 return -EINVAL;
3899 if (params.p2p_ctwindow != 0 &&
3900 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3901 return -EINVAL;
3902 }
3903
3904 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3905 u8 tmp;
3906
3907 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3908 return -EINVAL;
3909 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3910 if (tmp > 1)
3911 return -EINVAL;
3912 params.p2p_opp_ps = tmp;
3913 if (params.p2p_opp_ps != 0 &&
3914 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3915 return -EINVAL;
3916 }
3917
aa430da4 3918 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
3919 err = nl80211_parse_chandef(rdev, info, &params.chandef);
3920 if (err)
3921 return err;
3922 } else if (wdev->preset_chandef.chan) {
3923 params.chandef = wdev->preset_chandef;
46c1dd0c 3924 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
3925 return -EINVAL;
3926
923b352f
AN
3927 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
3928 wdev->iftype))
aa430da4
JB
3929 return -EINVAL;
3930
a7c7fbff
PK
3931 if (info->attrs[NL80211_ATTR_TX_RATES]) {
3932 err = nl80211_parse_tx_bitrate_mask(info, &params.beacon_rate);
3933 if (err)
3934 return err;
3935
8564e382
JB
3936 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band,
3937 &params.beacon_rate);
a7c7fbff
PK
3938 if (err)
3939 return err;
3940 }
3941
18998c38
EP
3942 if (info->attrs[NL80211_ATTR_SMPS_MODE]) {
3943 params.smps_mode =
3944 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]);
3945 switch (params.smps_mode) {
3946 case NL80211_SMPS_OFF:
3947 break;
3948 case NL80211_SMPS_STATIC:
3949 if (!(rdev->wiphy.features &
3950 NL80211_FEATURE_STATIC_SMPS))
3951 return -EINVAL;
3952 break;
3953 case NL80211_SMPS_DYNAMIC:
3954 if (!(rdev->wiphy.features &
3955 NL80211_FEATURE_DYNAMIC_SMPS))
3956 return -EINVAL;
3957 break;
3958 default:
3959 return -EINVAL;
3960 }
3961 } else {
3962 params.smps_mode = NL80211_SMPS_OFF;
3963 }
3964
6e8ef842
PK
3965 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
3966 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ])
3967 return -EOPNOTSUPP;
3968
4baf6bea
OO
3969 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
3970 params.acl = parse_acl_data(&rdev->wiphy, info);
3971 if (IS_ERR(params.acl))
3972 return PTR_ERR(params.acl);
3973 }
3974
c56589ed 3975 wdev_lock(wdev);
e35e4d28 3976 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 3977 if (!err) {
683b6d3b 3978 wdev->preset_chandef = params.chandef;
8860020e 3979 wdev->beacon_interval = params.beacon_interval;
9e0e2961 3980 wdev->chandef = params.chandef;
06e191e2
AQ
3981 wdev->ssid_len = params.ssid_len;
3982 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 3983 }
c56589ed 3984 wdev_unlock(wdev);
77765eaf
VT
3985
3986 kfree(params.acl);
3987
56d1893d 3988 return err;
ed1b6cc7
JB
3989}
3990
8860020e
JB
3991static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
3992{
3993 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3994 struct net_device *dev = info->user_ptr[1];
3995 struct wireless_dev *wdev = dev->ieee80211_ptr;
3996 struct cfg80211_beacon_data params;
3997 int err;
3998
3999 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4000 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4001 return -EOPNOTSUPP;
4002
4003 if (!rdev->ops->change_beacon)
4004 return -EOPNOTSUPP;
4005
4006 if (!wdev->beacon_interval)
4007 return -EINVAL;
4008
a1193be8 4009 err = nl80211_parse_beacon(info->attrs, &params);
8860020e
JB
4010 if (err)
4011 return err;
4012
c56589ed
SW
4013 wdev_lock(wdev);
4014 err = rdev_change_beacon(rdev, dev, &params);
4015 wdev_unlock(wdev);
4016
4017 return err;
8860020e
JB
4018}
4019
4020static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 4021{
4c476991
JB
4022 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4023 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 4024
7c8d5e03 4025 return cfg80211_stop_ap(rdev, dev, false);
ed1b6cc7
JB
4026}
4027
5727ef1b
JB
4028static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
4029 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
4030 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
4031 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 4032 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 4033 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 4034 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
4035};
4036
eccb8e8f 4037static int parse_station_flags(struct genl_info *info,
bdd3ae3d 4038 enum nl80211_iftype iftype,
eccb8e8f 4039 struct station_parameters *params)
5727ef1b
JB
4040{
4041 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 4042 struct nlattr *nla;
5727ef1b
JB
4043 int flag;
4044
eccb8e8f
JB
4045 /*
4046 * Try parsing the new attribute first so userspace
4047 * can specify both for older kernels.
4048 */
4049 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
4050 if (nla) {
4051 struct nl80211_sta_flag_update *sta_flags;
4052
4053 sta_flags = nla_data(nla);
4054 params->sta_flags_mask = sta_flags->mask;
4055 params->sta_flags_set = sta_flags->set;
77ee7c89 4056 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
4057 if ((params->sta_flags_mask |
4058 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
4059 return -EINVAL;
4060 return 0;
4061 }
4062
4063 /* if present, parse the old attribute */
5727ef1b 4064
eccb8e8f 4065 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
4066 if (!nla)
4067 return 0;
4068
4069 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
4070 nla, sta_flags_policy))
4071 return -EINVAL;
4072
bdd3ae3d
JB
4073 /*
4074 * Only allow certain flags for interface types so that
4075 * other attributes are silently ignored. Remember that
4076 * this is backward compatibility code with old userspace
4077 * and shouldn't be hit in other cases anyway.
4078 */
4079 switch (iftype) {
4080 case NL80211_IFTYPE_AP:
4081 case NL80211_IFTYPE_AP_VLAN:
4082 case NL80211_IFTYPE_P2P_GO:
4083 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
4084 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
4085 BIT(NL80211_STA_FLAG_WME) |
4086 BIT(NL80211_STA_FLAG_MFP);
4087 break;
4088 case NL80211_IFTYPE_P2P_CLIENT:
4089 case NL80211_IFTYPE_STATION:
4090 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
4091 BIT(NL80211_STA_FLAG_TDLS_PEER);
4092 break;
4093 case NL80211_IFTYPE_MESH_POINT:
4094 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4095 BIT(NL80211_STA_FLAG_MFP) |
4096 BIT(NL80211_STA_FLAG_AUTHORIZED);
4097 default:
4098 return -EINVAL;
4099 }
5727ef1b 4100
3383b5a6
JB
4101 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
4102 if (flags[flag]) {
eccb8e8f 4103 params->sta_flags_set |= (1<<flag);
5727ef1b 4104
3383b5a6
JB
4105 /* no longer support new API additions in old API */
4106 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
4107 return -EINVAL;
4108 }
4109 }
4110
5727ef1b
JB
4111 return 0;
4112}
4113
c8dcfd8a
FF
4114static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
4115 int attr)
4116{
4117 struct nlattr *rate;
8eb41c8d
VK
4118 u32 bitrate;
4119 u16 bitrate_compat;
b51f3bee 4120 enum nl80211_attrs rate_flg;
c8dcfd8a
FF
4121
4122 rate = nla_nest_start(msg, attr);
4123 if (!rate)
db9c64cf 4124 return false;
c8dcfd8a
FF
4125
4126 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
4127 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
4128 /* report 16-bit bitrate only if we can */
4129 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
4130 if (bitrate > 0 &&
4131 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
4132 return false;
4133 if (bitrate_compat > 0 &&
4134 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
4135 return false;
4136
b51f3bee
JB
4137 switch (info->bw) {
4138 case RATE_INFO_BW_5:
4139 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH;
4140 break;
4141 case RATE_INFO_BW_10:
4142 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH;
4143 break;
4144 default:
4145 WARN_ON(1);
4146 /* fall through */
4147 case RATE_INFO_BW_20:
4148 rate_flg = 0;
4149 break;
4150 case RATE_INFO_BW_40:
4151 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH;
4152 break;
4153 case RATE_INFO_BW_80:
4154 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH;
4155 break;
4156 case RATE_INFO_BW_160:
4157 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH;
4158 break;
4159 }
4160
4161 if (rate_flg && nla_put_flag(msg, rate_flg))
4162 return false;
4163
db9c64cf
JB
4164 if (info->flags & RATE_INFO_FLAGS_MCS) {
4165 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
4166 return false;
db9c64cf
JB
4167 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
4168 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
4169 return false;
4170 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
4171 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
4172 return false;
4173 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
4174 return false;
db9c64cf
JB
4175 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
4176 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
4177 return false;
4178 }
c8dcfd8a
FF
4179
4180 nla_nest_end(msg, rate);
4181 return true;
c8dcfd8a
FF
4182}
4183
119363c7
FF
4184static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
4185 int id)
4186{
4187 void *attr;
4188 int i = 0;
4189
4190 if (!mask)
4191 return true;
4192
4193 attr = nla_nest_start(msg, id);
4194 if (!attr)
4195 return false;
4196
4197 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
4198 if (!(mask & BIT(i)))
4199 continue;
4200
4201 if (nla_put_u8(msg, i, signal[i]))
4202 return false;
4203 }
4204
4205 nla_nest_end(msg, attr);
4206
4207 return true;
4208}
4209
cf5ead82
JB
4210static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid,
4211 u32 seq, int flags,
66266b3a
JL
4212 struct cfg80211_registered_device *rdev,
4213 struct net_device *dev,
98b62183 4214 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
4215{
4216 void *hdr;
f4263c98 4217 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 4218
cf5ead82 4219 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
fd5b74dc
JB
4220 if (!hdr)
4221 return -1;
4222
9360ffd1
DM
4223 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4224 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
4225 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
4226 goto nla_put_failure;
f5ea9120 4227
2ec600d6
LCC
4228 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
4229 if (!sinfoattr)
fd5b74dc 4230 goto nla_put_failure;
319090bf
JB
4231
4232#define PUT_SINFO(attr, memb, type) do { \
d686b920 4233 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \
739960f1 4234 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \
319090bf
JB
4235 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \
4236 sinfo->memb)) \
4237 goto nla_put_failure; \
4238 } while (0)
d686b920
JB
4239#define PUT_SINFO_U64(attr, memb) do { \
4240 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \
4241 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \
4242 sinfo->memb, NL80211_STA_INFO_PAD)) \
4243 goto nla_put_failure; \
4244 } while (0)
319090bf
JB
4245
4246 PUT_SINFO(CONNECTED_TIME, connected_time, u32);
4247 PUT_SINFO(INACTIVE_TIME, inactive_time, u32);
4248
4249 if (sinfo->filled & (BIT(NL80211_STA_INFO_RX_BYTES) |
4250 BIT(NL80211_STA_INFO_RX_BYTES64)) &&
9360ffd1 4251 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 4252 (u32)sinfo->rx_bytes))
9360ffd1 4253 goto nla_put_failure;
319090bf
JB
4254
4255 if (sinfo->filled & (BIT(NL80211_STA_INFO_TX_BYTES) |
4256 BIT(NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 4257 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
4258 (u32)sinfo->tx_bytes))
4259 goto nla_put_failure;
319090bf 4260
d686b920
JB
4261 PUT_SINFO_U64(RX_BYTES64, rx_bytes);
4262 PUT_SINFO_U64(TX_BYTES64, tx_bytes);
319090bf
JB
4263 PUT_SINFO(LLID, llid, u16);
4264 PUT_SINFO(PLID, plid, u16);
4265 PUT_SINFO(PLINK_STATE, plink_state, u8);
d686b920 4266 PUT_SINFO_U64(RX_DURATION, rx_duration);
319090bf 4267
66266b3a
JL
4268 switch (rdev->wiphy.signal_type) {
4269 case CFG80211_SIGNAL_TYPE_MBM:
319090bf
JB
4270 PUT_SINFO(SIGNAL, signal, u8);
4271 PUT_SINFO(SIGNAL_AVG, signal_avg, u8);
66266b3a
JL
4272 break;
4273 default:
4274 break;
4275 }
319090bf 4276 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL)) {
119363c7
FF
4277 if (!nl80211_put_signal(msg, sinfo->chains,
4278 sinfo->chain_signal,
4279 NL80211_STA_INFO_CHAIN_SIGNAL))
4280 goto nla_put_failure;
4281 }
319090bf 4282 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) {
119363c7
FF
4283 if (!nl80211_put_signal(msg, sinfo->chains,
4284 sinfo->chain_signal_avg,
4285 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
4286 goto nla_put_failure;
4287 }
319090bf 4288 if (sinfo->filled & BIT(NL80211_STA_INFO_TX_BITRATE)) {
c8dcfd8a
FF
4289 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
4290 NL80211_STA_INFO_TX_BITRATE))
4291 goto nla_put_failure;
4292 }
319090bf 4293 if (sinfo->filled & BIT(NL80211_STA_INFO_RX_BITRATE)) {
c8dcfd8a
FF
4294 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
4295 NL80211_STA_INFO_RX_BITRATE))
420e7fab 4296 goto nla_put_failure;
420e7fab 4297 }
319090bf
JB
4298
4299 PUT_SINFO(RX_PACKETS, rx_packets, u32);
4300 PUT_SINFO(TX_PACKETS, tx_packets, u32);
4301 PUT_SINFO(TX_RETRIES, tx_retries, u32);
4302 PUT_SINFO(TX_FAILED, tx_failed, u32);
4303 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32);
4304 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32);
4305 PUT_SINFO(LOCAL_PM, local_pm, u32);
4306 PUT_SINFO(PEER_PM, peer_pm, u32);
4307 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32);
4308
4309 if (sinfo->filled & BIT(NL80211_STA_INFO_BSS_PARAM)) {
f4263c98
PS
4310 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
4311 if (!bss_param)
4312 goto nla_put_failure;
4313
9360ffd1
DM
4314 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
4315 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
4316 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
4317 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
4318 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
4319 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
4320 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
4321 sinfo->bss_param.dtim_period) ||
4322 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
4323 sinfo->bss_param.beacon_interval))
4324 goto nla_put_failure;
f4263c98
PS
4325
4326 nla_nest_end(msg, bss_param);
4327 }
319090bf 4328 if ((sinfo->filled & BIT(NL80211_STA_INFO_STA_FLAGS)) &&
9360ffd1
DM
4329 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
4330 sizeof(struct nl80211_sta_flag_update),
4331 &sinfo->sta_flags))
4332 goto nla_put_failure;
319090bf 4333
d686b920
JB
4334 PUT_SINFO_U64(T_OFFSET, t_offset);
4335 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc);
4336 PUT_SINFO_U64(BEACON_RX, rx_beacon);
a76b1942 4337 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8);
319090bf
JB
4338
4339#undef PUT_SINFO
d686b920 4340#undef PUT_SINFO_U64
6de39808
JB
4341
4342 if (sinfo->filled & BIT(NL80211_STA_INFO_TID_STATS)) {
4343 struct nlattr *tidsattr;
4344 int tid;
4345
4346 tidsattr = nla_nest_start(msg, NL80211_STA_INFO_TID_STATS);
4347 if (!tidsattr)
4348 goto nla_put_failure;
4349
4350 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) {
4351 struct cfg80211_tid_stats *tidstats;
4352 struct nlattr *tidattr;
4353
4354 tidstats = &sinfo->pertid[tid];
4355
4356 if (!tidstats->filled)
4357 continue;
4358
4359 tidattr = nla_nest_start(msg, tid + 1);
4360 if (!tidattr)
4361 goto nla_put_failure;
4362
d686b920 4363#define PUT_TIDVAL_U64(attr, memb) do { \
6de39808 4364 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \
d686b920
JB
4365 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \
4366 tidstats->memb, NL80211_TID_STATS_PAD)) \
6de39808
JB
4367 goto nla_put_failure; \
4368 } while (0)
4369
d686b920
JB
4370 PUT_TIDVAL_U64(RX_MSDU, rx_msdu);
4371 PUT_TIDVAL_U64(TX_MSDU, tx_msdu);
4372 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries);
4373 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed);
6de39808 4374
d686b920 4375#undef PUT_TIDVAL_U64
6de39808
JB
4376 nla_nest_end(msg, tidattr);
4377 }
4378
4379 nla_nest_end(msg, tidsattr);
4380 }
4381
2ec600d6 4382 nla_nest_end(msg, sinfoattr);
fd5b74dc 4383
319090bf 4384 if (sinfo->assoc_req_ies_len &&
9360ffd1
DM
4385 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
4386 sinfo->assoc_req_ies))
4387 goto nla_put_failure;
50d3dfb7 4388
053c095a
JB
4389 genlmsg_end(msg, hdr);
4390 return 0;
fd5b74dc
JB
4391
4392 nla_put_failure:
bc3ed28c
TG
4393 genlmsg_cancel(msg, hdr);
4394 return -EMSGSIZE;
fd5b74dc
JB
4395}
4396
2ec600d6 4397static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 4398 struct netlink_callback *cb)
2ec600d6 4399{
2ec600d6 4400 struct station_info sinfo;
1b8ec87a 4401 struct cfg80211_registered_device *rdev;
97990a06 4402 struct wireless_dev *wdev;
2ec600d6 4403 u8 mac_addr[ETH_ALEN];
97990a06 4404 int sta_idx = cb->args[2];
2ec600d6 4405 int err;
2ec600d6 4406
1b8ec87a 4407 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
4408 if (err)
4409 return err;
bba95fef 4410
97990a06
JB
4411 if (!wdev->netdev) {
4412 err = -EINVAL;
4413 goto out_err;
4414 }
4415
1b8ec87a 4416 if (!rdev->ops->dump_station) {
eec60b03 4417 err = -EOPNOTSUPP;
bba95fef
JB
4418 goto out_err;
4419 }
4420
bba95fef 4421 while (1) {
f612cedf 4422 memset(&sinfo, 0, sizeof(sinfo));
1b8ec87a 4423 err = rdev_dump_station(rdev, wdev->netdev, sta_idx,
e35e4d28 4424 mac_addr, &sinfo);
bba95fef
JB
4425 if (err == -ENOENT)
4426 break;
4427 if (err)
3b85875a 4428 goto out_err;
bba95fef 4429
cf5ead82 4430 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION,
15e47304 4431 NETLINK_CB(cb->skb).portid,
bba95fef 4432 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1b8ec87a 4433 rdev, wdev->netdev, mac_addr,
bba95fef
JB
4434 &sinfo) < 0)
4435 goto out;
4436
4437 sta_idx++;
4438 }
4439
bba95fef 4440 out:
97990a06 4441 cb->args[2] = sta_idx;
bba95fef 4442 err = skb->len;
bba95fef 4443 out_err:
1b8ec87a 4444 nl80211_finish_wdev_dump(rdev);
bba95fef
JB
4445
4446 return err;
2ec600d6 4447}
fd5b74dc 4448
5727ef1b
JB
4449static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
4450{
4c476991
JB
4451 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4452 struct net_device *dev = info->user_ptr[1];
2ec600d6 4453 struct station_info sinfo;
fd5b74dc
JB
4454 struct sk_buff *msg;
4455 u8 *mac_addr = NULL;
4c476991 4456 int err;
fd5b74dc 4457
2ec600d6 4458 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
4459
4460 if (!info->attrs[NL80211_ATTR_MAC])
4461 return -EINVAL;
4462
4463 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4464
4c476991
JB
4465 if (!rdev->ops->get_station)
4466 return -EOPNOTSUPP;
3b85875a 4467
e35e4d28 4468 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 4469 if (err)
4c476991 4470 return err;
2ec600d6 4471
fd2120ca 4472 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 4473 if (!msg)
4c476991 4474 return -ENOMEM;
fd5b74dc 4475
cf5ead82
JB
4476 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION,
4477 info->snd_portid, info->snd_seq, 0,
66266b3a 4478 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
4479 nlmsg_free(msg);
4480 return -ENOBUFS;
4481 }
3b85875a 4482
4c476991 4483 return genlmsg_reply(msg, info);
5727ef1b
JB
4484}
4485
77ee7c89
JB
4486int cfg80211_check_station_change(struct wiphy *wiphy,
4487 struct station_parameters *params,
4488 enum cfg80211_station_type statype)
4489{
e4208427
AB
4490 if (params->listen_interval != -1 &&
4491 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89 4492 return -EINVAL;
e4208427 4493
17b94247
AB
4494 if (params->support_p2p_ps != -1 &&
4495 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
4496 return -EINVAL;
4497
c72e1140 4498 if (params->aid &&
e4208427
AB
4499 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
4500 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89
JB
4501 return -EINVAL;
4502
4503 /* When you run into this, adjust the code below for the new flag */
4504 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
4505
4506 switch (statype) {
eef941e6
TP
4507 case CFG80211_STA_MESH_PEER_KERNEL:
4508 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
4509 /*
4510 * No ignoring the TDLS flag here -- the userspace mesh
4511 * code doesn't have the bug of including TDLS in the
4512 * mask everywhere.
4513 */
4514 if (params->sta_flags_mask &
4515 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4516 BIT(NL80211_STA_FLAG_MFP) |
4517 BIT(NL80211_STA_FLAG_AUTHORIZED)))
4518 return -EINVAL;
4519 break;
4520 case CFG80211_STA_TDLS_PEER_SETUP:
4521 case CFG80211_STA_TDLS_PEER_ACTIVE:
4522 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
4523 return -EINVAL;
4524 /* ignore since it can't change */
4525 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
4526 break;
4527 default:
4528 /* disallow mesh-specific things */
4529 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
4530 return -EINVAL;
4531 if (params->local_pm)
4532 return -EINVAL;
4533 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
4534 return -EINVAL;
4535 }
4536
4537 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
4538 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
4539 /* TDLS can't be set, ... */
4540 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4541 return -EINVAL;
4542 /*
4543 * ... but don't bother the driver with it. This works around
4544 * a hostapd/wpa_supplicant issue -- it always includes the
4545 * TLDS_PEER flag in the mask even for AP mode.
4546 */
4547 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
4548 }
4549
47edb11b
AB
4550 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
4551 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
4552 /* reject other things that can't change */
4553 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
4554 return -EINVAL;
4555 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
4556 return -EINVAL;
4557 if (params->supported_rates)
4558 return -EINVAL;
4559 if (params->ext_capab || params->ht_capa || params->vht_capa)
4560 return -EINVAL;
4561 }
4562
47edb11b
AB
4563 if (statype != CFG80211_STA_AP_CLIENT &&
4564 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
4565 if (params->vlan)
4566 return -EINVAL;
4567 }
4568
4569 switch (statype) {
4570 case CFG80211_STA_AP_MLME_CLIENT:
4571 /* Use this only for authorizing/unauthorizing a station */
4572 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
4573 return -EOPNOTSUPP;
4574 break;
4575 case CFG80211_STA_AP_CLIENT:
47edb11b 4576 case CFG80211_STA_AP_CLIENT_UNASSOC:
77ee7c89
JB
4577 /* accept only the listed bits */
4578 if (params->sta_flags_mask &
4579 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
4580 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4581 BIT(NL80211_STA_FLAG_ASSOCIATED) |
4582 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
4583 BIT(NL80211_STA_FLAG_WME) |
4584 BIT(NL80211_STA_FLAG_MFP)))
4585 return -EINVAL;
4586
4587 /* but authenticated/associated only if driver handles it */
4588 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4589 params->sta_flags_mask &
4590 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4591 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4592 return -EINVAL;
4593 break;
4594 case CFG80211_STA_IBSS:
4595 case CFG80211_STA_AP_STA:
4596 /* reject any changes other than AUTHORIZED */
4597 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
4598 return -EINVAL;
4599 break;
4600 case CFG80211_STA_TDLS_PEER_SETUP:
4601 /* reject any changes other than AUTHORIZED or WME */
4602 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
4603 BIT(NL80211_STA_FLAG_WME)))
4604 return -EINVAL;
4605 /* force (at least) rates when authorizing */
4606 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
4607 !params->supported_rates)
4608 return -EINVAL;
4609 break;
4610 case CFG80211_STA_TDLS_PEER_ACTIVE:
4611 /* reject any changes */
4612 return -EINVAL;
eef941e6 4613 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
4614 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
4615 return -EINVAL;
4616 break;
eef941e6 4617 case CFG80211_STA_MESH_PEER_USER:
42925040
CYY
4618 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION &&
4619 params->plink_action != NL80211_PLINK_ACTION_BLOCK)
77ee7c89
JB
4620 return -EINVAL;
4621 break;
4622 }
4623
4624 return 0;
4625}
4626EXPORT_SYMBOL(cfg80211_check_station_change);
4627
5727ef1b 4628/*
c258d2de 4629 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 4630 */
80b99899
JB
4631static struct net_device *get_vlan(struct genl_info *info,
4632 struct cfg80211_registered_device *rdev)
5727ef1b 4633{
463d0183 4634 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
4635 struct net_device *v;
4636 int ret;
4637
4638 if (!vlanattr)
4639 return NULL;
4640
4641 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
4642 if (!v)
4643 return ERR_PTR(-ENODEV);
4644
4645 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
4646 ret = -EINVAL;
4647 goto error;
5727ef1b 4648 }
80b99899 4649
77ee7c89
JB
4650 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4651 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4652 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
4653 ret = -EINVAL;
4654 goto error;
4655 }
4656
80b99899
JB
4657 if (!netif_running(v)) {
4658 ret = -ENETDOWN;
4659 goto error;
4660 }
4661
4662 return v;
4663 error:
4664 dev_put(v);
4665 return ERR_PTR(ret);
5727ef1b
JB
4666}
4667
94e860f1
JB
4668static const struct nla_policy
4669nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
df881293
JM
4670 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
4671 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
4672};
4673
ff276691
JB
4674static int nl80211_parse_sta_wme(struct genl_info *info,
4675 struct station_parameters *params)
df881293 4676{
df881293
JM
4677 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
4678 struct nlattr *nla;
4679 int err;
4680
df881293
JM
4681 /* parse WME attributes if present */
4682 if (!info->attrs[NL80211_ATTR_STA_WME])
4683 return 0;
4684
4685 nla = info->attrs[NL80211_ATTR_STA_WME];
4686 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
4687 nl80211_sta_wme_policy);
4688 if (err)
4689 return err;
4690
4691 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
4692 params->uapsd_queues = nla_get_u8(
4693 tb[NL80211_STA_WME_UAPSD_QUEUES]);
4694 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
4695 return -EINVAL;
4696
4697 if (tb[NL80211_STA_WME_MAX_SP])
4698 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
4699
4700 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
4701 return -EINVAL;
4702
4703 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
4704
4705 return 0;
4706}
4707
c01fc9ad
SD
4708static int nl80211_parse_sta_channel_info(struct genl_info *info,
4709 struct station_parameters *params)
4710{
4711 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
4712 params->supported_channels =
4713 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
4714 params->supported_channels_len =
4715 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
4716 /*
4717 * Need to include at least one (first channel, number of
4718 * channels) tuple for each subband, and must have proper
4719 * tuples for the rest of the data as well.
4720 */
4721 if (params->supported_channels_len < 2)
4722 return -EINVAL;
4723 if (params->supported_channels_len % 2)
4724 return -EINVAL;
4725 }
4726
4727 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
4728 params->supported_oper_classes =
4729 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
4730 params->supported_oper_classes_len =
4731 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
4732 /*
4733 * The value of the Length field of the Supported Operating
4734 * Classes element is between 2 and 253.
4735 */
4736 if (params->supported_oper_classes_len < 2 ||
4737 params->supported_oper_classes_len > 253)
4738 return -EINVAL;
4739 }
4740 return 0;
4741}
4742
ff276691
JB
4743static int nl80211_set_station_tdls(struct genl_info *info,
4744 struct station_parameters *params)
4745{
c01fc9ad 4746 int err;
ff276691 4747 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
4748 if (info->attrs[NL80211_ATTR_PEER_AID])
4749 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
4750 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4751 params->ht_capa =
4752 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4753 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4754 params->vht_capa =
4755 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4756
c01fc9ad
SD
4757 err = nl80211_parse_sta_channel_info(info, params);
4758 if (err)
4759 return err;
4760
ff276691
JB
4761 return nl80211_parse_sta_wme(info, params);
4762}
4763
5727ef1b
JB
4764static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
4765{
4c476991 4766 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4767 struct net_device *dev = info->user_ptr[1];
5727ef1b 4768 struct station_parameters params;
77ee7c89
JB
4769 u8 *mac_addr;
4770 int err;
5727ef1b
JB
4771
4772 memset(&params, 0, sizeof(params));
4773
77ee7c89
JB
4774 if (!rdev->ops->change_station)
4775 return -EOPNOTSUPP;
4776
e4208427
AB
4777 /*
4778 * AID and listen_interval properties can be set only for unassociated
4779 * station. Include these parameters here and will check them in
4780 * cfg80211_check_station_change().
4781 */
a9bc31e4
AB
4782 if (info->attrs[NL80211_ATTR_STA_AID])
4783 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
e4208427
AB
4784
4785 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
4786 params.listen_interval =
4787 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
4788 else
4789 params.listen_interval = -1;
5727ef1b 4790
17b94247
AB
4791 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
4792 u8 tmp;
4793
4794 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
4795 if (tmp >= NUM_NL80211_P2P_PS_STATUS)
4796 return -EINVAL;
4797
4798 params.support_p2p_ps = tmp;
4799 } else {
4800 params.support_p2p_ps = -1;
4801 }
4802
5727ef1b
JB
4803 if (!info->attrs[NL80211_ATTR_MAC])
4804 return -EINVAL;
4805
4806 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4807
4808 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
4809 params.supported_rates =
4810 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4811 params.supported_rates_len =
4812 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4813 }
4814
9d62a986
JM
4815 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4816 params.capability =
4817 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4818 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4819 }
4820
4821 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4822 params.ext_capab =
4823 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4824 params.ext_capab_len =
4825 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4826 }
4827
bdd3ae3d 4828 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4829 return -EINVAL;
4830
f8bacc21 4831 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
2ec600d6 4832 params.plink_action =
f8bacc21
JB
4833 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4834 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4835 return -EINVAL;
4836 }
2ec600d6 4837
f8bacc21 4838 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 4839 params.plink_state =
f8bacc21
JB
4840 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
4841 if (params.plink_state >= NUM_NL80211_PLINK_STATES)
4842 return -EINVAL;
7d27a0ba
MH
4843 if (info->attrs[NL80211_ATTR_MESH_PEER_AID]) {
4844 params.peer_aid = nla_get_u16(
4845 info->attrs[NL80211_ATTR_MESH_PEER_AID]);
4846 if (params.peer_aid > IEEE80211_MAX_AID)
4847 return -EINVAL;
4848 }
f8bacc21
JB
4849 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
4850 }
9c3990aa 4851
3b1c5a53
MP
4852 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
4853 enum nl80211_mesh_power_mode pm = nla_get_u32(
4854 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
4855
4856 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
4857 pm > NL80211_MESH_POWER_MAX)
4858 return -EINVAL;
4859
4860 params.local_pm = pm;
4861 }
4862
77ee7c89
JB
4863 /* Include parameters for TDLS peer (will check later) */
4864 err = nl80211_set_station_tdls(info, &params);
4865 if (err)
4866 return err;
4867
4868 params.vlan = get_vlan(info, rdev);
4869 if (IS_ERR(params.vlan))
4870 return PTR_ERR(params.vlan);
4871
a97f4424
JB
4872 switch (dev->ieee80211_ptr->iftype) {
4873 case NL80211_IFTYPE_AP:
4874 case NL80211_IFTYPE_AP_VLAN:
074ac8df 4875 case NL80211_IFTYPE_P2P_GO:
074ac8df 4876 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 4877 case NL80211_IFTYPE_STATION:
267335d6 4878 case NL80211_IFTYPE_ADHOC:
a97f4424 4879 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
4880 break;
4881 default:
77ee7c89
JB
4882 err = -EOPNOTSUPP;
4883 goto out_put_vlan;
034d655e
JB
4884 }
4885
77ee7c89 4886 /* driver will call cfg80211_check_station_change() */
e35e4d28 4887 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 4888
77ee7c89 4889 out_put_vlan:
5727ef1b
JB
4890 if (params.vlan)
4891 dev_put(params.vlan);
3b85875a 4892
5727ef1b
JB
4893 return err;
4894}
4895
4896static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
4897{
4c476991 4898 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 4899 int err;
4c476991 4900 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4901 struct station_parameters params;
4902 u8 *mac_addr = NULL;
bda95eb1
JB
4903 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4904 BIT(NL80211_STA_FLAG_ASSOCIATED);
5727ef1b
JB
4905
4906 memset(&params, 0, sizeof(params));
4907
984c311b
JB
4908 if (!rdev->ops->add_station)
4909 return -EOPNOTSUPP;
4910
5727ef1b
JB
4911 if (!info->attrs[NL80211_ATTR_MAC])
4912 return -EINVAL;
4913
5727ef1b
JB
4914 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
4915 return -EINVAL;
4916
4917 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
4918 return -EINVAL;
4919
5e4b6f56
JM
4920 if (!info->attrs[NL80211_ATTR_STA_AID] &&
4921 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
4922 return -EINVAL;
4923
5727ef1b
JB
4924 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4925 params.supported_rates =
4926 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4927 params.supported_rates_len =
4928 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4929 params.listen_interval =
4930 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 4931
17b94247
AB
4932 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
4933 u8 tmp;
4934
4935 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
4936 if (tmp >= NUM_NL80211_P2P_PS_STATUS)
4937 return -EINVAL;
4938
4939 params.support_p2p_ps = tmp;
4940 } else {
4941 /*
4942 * if not specified, assume it's supported for P2P GO interface,
4943 * and is NOT supported for AP interface
4944 */
4945 params.support_p2p_ps =
4946 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO;
4947 }
4948
3d124ea2 4949 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 4950 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
4951 else
4952 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
0e956c13
TLSC
4953 if (!params.aid || params.aid > IEEE80211_MAX_AID)
4954 return -EINVAL;
51b50fbe 4955
9d62a986
JM
4956 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4957 params.capability =
4958 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4959 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4960 }
4961
4962 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4963 params.ext_capab =
4964 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4965 params.ext_capab_len =
4966 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4967 }
4968
36aedc90
JM
4969 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4970 params.ht_capa =
4971 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 4972
f461be3e
MP
4973 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4974 params.vht_capa =
4975 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4976
60f4a7b1
MK
4977 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
4978 params.opmode_notif_used = true;
4979 params.opmode_notif =
4980 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
4981 }
4982
f8bacc21 4983 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
96b78dff 4984 params.plink_action =
f8bacc21
JB
4985 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4986 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4987 return -EINVAL;
4988 }
96b78dff 4989
c01fc9ad
SD
4990 err = nl80211_parse_sta_channel_info(info, &params);
4991 if (err)
4992 return err;
4993
ff276691
JB
4994 err = nl80211_parse_sta_wme(info, &params);
4995 if (err)
4996 return err;
bdd90d5e 4997
bdd3ae3d 4998 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4999 return -EINVAL;
5000
496fcc29
JB
5001 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT
5002 * as userspace might just pass through the capabilities from the IEs
5003 * directly, rather than enforcing this restriction and returning an
5004 * error in this case.
5005 */
5006 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) {
5007 params.ht_capa = NULL;
5008 params.vht_capa = NULL;
5009 }
5010
77ee7c89
JB
5011 /* When you run into this, adjust the code below for the new flag */
5012 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
5013
bdd90d5e
JB
5014 switch (dev->ieee80211_ptr->iftype) {
5015 case NL80211_IFTYPE_AP:
5016 case NL80211_IFTYPE_AP_VLAN:
5017 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
5018 /* ignore WME attributes if iface/sta is not capable */
5019 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
5020 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
5021 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 5022
bdd90d5e 5023 /* TDLS peers cannot be added */
3d124ea2
JM
5024 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
5025 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 5026 return -EINVAL;
bdd90d5e
JB
5027 /* but don't bother the driver with it */
5028 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 5029
d582cffb
JB
5030 /* allow authenticated/associated only if driver handles it */
5031 if (!(rdev->wiphy.features &
5032 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
bda95eb1 5033 params.sta_flags_mask & auth_assoc)
d582cffb
JB
5034 return -EINVAL;
5035
bda95eb1
JB
5036 /* Older userspace, or userspace wanting to be compatible with
5037 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth
5038 * and assoc flags in the mask, but assumes the station will be
5039 * added as associated anyway since this was the required driver
5040 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was
5041 * introduced.
5042 * In order to not bother drivers with this quirk in the API
5043 * set the flags in both the mask and set for new stations in
5044 * this case.
5045 */
5046 if (!(params.sta_flags_mask & auth_assoc)) {
5047 params.sta_flags_mask |= auth_assoc;
5048 params.sta_flags_set |= auth_assoc;
5049 }
5050
bdd90d5e
JB
5051 /* must be last in here for error handling */
5052 params.vlan = get_vlan(info, rdev);
5053 if (IS_ERR(params.vlan))
5054 return PTR_ERR(params.vlan);
5055 break;
5056 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
5057 /* ignore uAPSD data */
5058 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
5059
d582cffb
JB
5060 /* associated is disallowed */
5061 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
5062 return -EINVAL;
bdd90d5e 5063 /* TDLS peers cannot be added */
3d124ea2
JM
5064 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
5065 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
5066 return -EINVAL;
5067 break;
5068 case NL80211_IFTYPE_STATION:
93d08f0b 5069 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
5070 /* ignore uAPSD data */
5071 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
5072
77ee7c89
JB
5073 /* these are disallowed */
5074 if (params.sta_flags_mask &
5075 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
5076 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 5077 return -EINVAL;
bdd90d5e
JB
5078 /* Only TDLS peers can be added */
5079 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
5080 return -EINVAL;
5081 /* Can only add if TDLS ... */
5082 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
5083 return -EOPNOTSUPP;
5084 /* ... with external setup is supported */
5085 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
5086 return -EOPNOTSUPP;
77ee7c89
JB
5087 /*
5088 * Older wpa_supplicant versions always mark the TDLS peer
5089 * as authorized, but it shouldn't yet be.
5090 */
5091 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
5092 break;
5093 default:
5094 return -EOPNOTSUPP;
c75786c9
EP
5095 }
5096
bdd90d5e 5097 /* be aware of params.vlan when changing code here */
5727ef1b 5098
e35e4d28 5099 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 5100
5727ef1b
JB
5101 if (params.vlan)
5102 dev_put(params.vlan);
5727ef1b
JB
5103 return err;
5104}
5105
5106static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
5107{
4c476991
JB
5108 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5109 struct net_device *dev = info->user_ptr[1];
89c771e5
JM
5110 struct station_del_parameters params;
5111
5112 memset(&params, 0, sizeof(params));
5727ef1b
JB
5113
5114 if (info->attrs[NL80211_ATTR_MAC])
89c771e5 5115 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
5727ef1b 5116
e80cf853 5117 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 5118 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 5119 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5120 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5121 return -EINVAL;
5727ef1b 5122
4c476991
JB
5123 if (!rdev->ops->del_station)
5124 return -EOPNOTSUPP;
3b85875a 5125
98856866
JM
5126 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) {
5127 params.subtype =
5128 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
5129 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 &&
5130 params.subtype != IEEE80211_STYPE_DEAUTH >> 4)
5131 return -EINVAL;
5132 } else {
5133 /* Default to Deauthentication frame */
5134 params.subtype = IEEE80211_STYPE_DEAUTH >> 4;
5135 }
5136
5137 if (info->attrs[NL80211_ATTR_REASON_CODE]) {
5138 params.reason_code =
5139 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5140 if (params.reason_code == 0)
5141 return -EINVAL; /* 0 is reserved */
5142 } else {
5143 /* Default to reason code 2 */
5144 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID;
5145 }
5146
89c771e5 5147 return rdev_del_station(rdev, dev, &params);
5727ef1b
JB
5148}
5149
15e47304 5150static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
5151 int flags, struct net_device *dev,
5152 u8 *dst, u8 *next_hop,
5153 struct mpath_info *pinfo)
5154{
5155 void *hdr;
5156 struct nlattr *pinfoattr;
5157
1ef4c850 5158 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH);
2ec600d6
LCC
5159 if (!hdr)
5160 return -1;
5161
9360ffd1
DM
5162 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5163 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
5164 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
5165 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
5166 goto nla_put_failure;
f5ea9120 5167
2ec600d6
LCC
5168 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
5169 if (!pinfoattr)
5170 goto nla_put_failure;
9360ffd1
DM
5171 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
5172 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
5173 pinfo->frame_qlen))
5174 goto nla_put_failure;
5175 if (((pinfo->filled & MPATH_INFO_SN) &&
5176 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
5177 ((pinfo->filled & MPATH_INFO_METRIC) &&
5178 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
5179 pinfo->metric)) ||
5180 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
5181 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
5182 pinfo->exptime)) ||
5183 ((pinfo->filled & MPATH_INFO_FLAGS) &&
5184 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
5185 pinfo->flags)) ||
5186 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
5187 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
5188 pinfo->discovery_timeout)) ||
5189 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
5190 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
5191 pinfo->discovery_retries)))
5192 goto nla_put_failure;
2ec600d6
LCC
5193
5194 nla_nest_end(msg, pinfoattr);
5195
053c095a
JB
5196 genlmsg_end(msg, hdr);
5197 return 0;
2ec600d6
LCC
5198
5199 nla_put_failure:
bc3ed28c
TG
5200 genlmsg_cancel(msg, hdr);
5201 return -EMSGSIZE;
2ec600d6
LCC
5202}
5203
5204static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 5205 struct netlink_callback *cb)
2ec600d6 5206{
2ec600d6 5207 struct mpath_info pinfo;
1b8ec87a 5208 struct cfg80211_registered_device *rdev;
97990a06 5209 struct wireless_dev *wdev;
2ec600d6
LCC
5210 u8 dst[ETH_ALEN];
5211 u8 next_hop[ETH_ALEN];
97990a06 5212 int path_idx = cb->args[2];
2ec600d6 5213 int err;
2ec600d6 5214
1b8ec87a 5215 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
5216 if (err)
5217 return err;
bba95fef 5218
1b8ec87a 5219 if (!rdev->ops->dump_mpath) {
eec60b03 5220 err = -EOPNOTSUPP;
bba95fef
JB
5221 goto out_err;
5222 }
5223
97990a06 5224 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 5225 err = -EOPNOTSUPP;
0448b5fc 5226 goto out_err;
eec60b03
JM
5227 }
5228
bba95fef 5229 while (1) {
1b8ec87a 5230 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst,
97990a06 5231 next_hop, &pinfo);
bba95fef 5232 if (err == -ENOENT)
2ec600d6 5233 break;
bba95fef 5234 if (err)
3b85875a 5235 goto out_err;
2ec600d6 5236
15e47304 5237 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 5238 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 5239 wdev->netdev, dst, next_hop,
bba95fef
JB
5240 &pinfo) < 0)
5241 goto out;
2ec600d6 5242
bba95fef 5243 path_idx++;
2ec600d6 5244 }
2ec600d6 5245
bba95fef 5246 out:
97990a06 5247 cb->args[2] = path_idx;
bba95fef 5248 err = skb->len;
bba95fef 5249 out_err:
1b8ec87a 5250 nl80211_finish_wdev_dump(rdev);
bba95fef 5251 return err;
2ec600d6
LCC
5252}
5253
5254static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
5255{
4c476991 5256 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 5257 int err;
4c476991 5258 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5259 struct mpath_info pinfo;
5260 struct sk_buff *msg;
5261 u8 *dst = NULL;
5262 u8 next_hop[ETH_ALEN];
5263
5264 memset(&pinfo, 0, sizeof(pinfo));
5265
5266 if (!info->attrs[NL80211_ATTR_MAC])
5267 return -EINVAL;
5268
5269 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5270
4c476991
JB
5271 if (!rdev->ops->get_mpath)
5272 return -EOPNOTSUPP;
2ec600d6 5273
4c476991
JB
5274 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5275 return -EOPNOTSUPP;
eec60b03 5276
e35e4d28 5277 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 5278 if (err)
4c476991 5279 return err;
2ec600d6 5280
fd2120ca 5281 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 5282 if (!msg)
4c476991 5283 return -ENOMEM;
2ec600d6 5284
15e47304 5285 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
5286 dev, dst, next_hop, &pinfo) < 0) {
5287 nlmsg_free(msg);
5288 return -ENOBUFS;
5289 }
3b85875a 5290
4c476991 5291 return genlmsg_reply(msg, info);
2ec600d6
LCC
5292}
5293
5294static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
5295{
4c476991
JB
5296 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5297 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5298 u8 *dst = NULL;
5299 u8 *next_hop = NULL;
5300
5301 if (!info->attrs[NL80211_ATTR_MAC])
5302 return -EINVAL;
5303
5304 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
5305 return -EINVAL;
5306
5307 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5308 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
5309
4c476991
JB
5310 if (!rdev->ops->change_mpath)
5311 return -EOPNOTSUPP;
35a8efe1 5312
4c476991
JB
5313 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5314 return -EOPNOTSUPP;
2ec600d6 5315
e35e4d28 5316 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 5317}
4c476991 5318
2ec600d6
LCC
5319static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
5320{
4c476991
JB
5321 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5322 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5323 u8 *dst = NULL;
5324 u8 *next_hop = NULL;
5325
5326 if (!info->attrs[NL80211_ATTR_MAC])
5327 return -EINVAL;
5328
5329 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
5330 return -EINVAL;
5331
5332 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5333 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
5334
4c476991
JB
5335 if (!rdev->ops->add_mpath)
5336 return -EOPNOTSUPP;
35a8efe1 5337
4c476991
JB
5338 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5339 return -EOPNOTSUPP;
2ec600d6 5340
e35e4d28 5341 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
5342}
5343
5344static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
5345{
4c476991
JB
5346 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5347 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5348 u8 *dst = NULL;
5349
5350 if (info->attrs[NL80211_ATTR_MAC])
5351 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5352
4c476991
JB
5353 if (!rdev->ops->del_mpath)
5354 return -EOPNOTSUPP;
3b85875a 5355
e35e4d28 5356 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
5357}
5358
66be7d2b
HR
5359static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info)
5360{
5361 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5362 int err;
5363 struct net_device *dev = info->user_ptr[1];
5364 struct mpath_info pinfo;
5365 struct sk_buff *msg;
5366 u8 *dst = NULL;
5367 u8 mpp[ETH_ALEN];
5368
5369 memset(&pinfo, 0, sizeof(pinfo));
5370
5371 if (!info->attrs[NL80211_ATTR_MAC])
5372 return -EINVAL;
5373
5374 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5375
5376 if (!rdev->ops->get_mpp)
5377 return -EOPNOTSUPP;
5378
5379 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5380 return -EOPNOTSUPP;
5381
5382 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo);
5383 if (err)
5384 return err;
5385
5386 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5387 if (!msg)
5388 return -ENOMEM;
5389
5390 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
5391 dev, dst, mpp, &pinfo) < 0) {
5392 nlmsg_free(msg);
5393 return -ENOBUFS;
5394 }
5395
5396 return genlmsg_reply(msg, info);
5397}
5398
5399static int nl80211_dump_mpp(struct sk_buff *skb,
5400 struct netlink_callback *cb)
5401{
5402 struct mpath_info pinfo;
5403 struct cfg80211_registered_device *rdev;
5404 struct wireless_dev *wdev;
5405 u8 dst[ETH_ALEN];
5406 u8 mpp[ETH_ALEN];
5407 int path_idx = cb->args[2];
5408 int err;
5409
5410 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
5411 if (err)
5412 return err;
5413
5414 if (!rdev->ops->dump_mpp) {
5415 err = -EOPNOTSUPP;
5416 goto out_err;
5417 }
5418
5419 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
5420 err = -EOPNOTSUPP;
5421 goto out_err;
5422 }
5423
5424 while (1) {
5425 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst,
5426 mpp, &pinfo);
5427 if (err == -ENOENT)
5428 break;
5429 if (err)
5430 goto out_err;
5431
5432 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
5433 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5434 wdev->netdev, dst, mpp,
5435 &pinfo) < 0)
5436 goto out;
5437
5438 path_idx++;
5439 }
5440
5441 out:
5442 cb->args[2] = path_idx;
5443 err = skb->len;
5444 out_err:
5445 nl80211_finish_wdev_dump(rdev);
5446 return err;
5447}
5448
9f1ba906
JM
5449static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
5450{
4c476991
JB
5451 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5452 struct net_device *dev = info->user_ptr[1];
c56589ed 5453 struct wireless_dev *wdev = dev->ieee80211_ptr;
9f1ba906 5454 struct bss_parameters params;
c56589ed 5455 int err;
9f1ba906
JM
5456
5457 memset(&params, 0, sizeof(params));
5458 /* default to not changing parameters */
5459 params.use_cts_prot = -1;
5460 params.use_short_preamble = -1;
5461 params.use_short_slot_time = -1;
fd8aaaf3 5462 params.ap_isolate = -1;
50b12f59 5463 params.ht_opmode = -1;
53cabad7
JB
5464 params.p2p_ctwindow = -1;
5465 params.p2p_opp_ps = -1;
9f1ba906
JM
5466
5467 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
5468 params.use_cts_prot =
5469 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
5470 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
5471 params.use_short_preamble =
5472 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
5473 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
5474 params.use_short_slot_time =
5475 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
5476 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5477 params.basic_rates =
5478 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5479 params.basic_rates_len =
5480 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5481 }
fd8aaaf3
FF
5482 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
5483 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
5484 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
5485 params.ht_opmode =
5486 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 5487
53cabad7
JB
5488 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
5489 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5490 return -EINVAL;
5491 params.p2p_ctwindow =
5492 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
5493 if (params.p2p_ctwindow < 0)
5494 return -EINVAL;
5495 if (params.p2p_ctwindow != 0 &&
5496 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
5497 return -EINVAL;
5498 }
5499
5500 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
5501 u8 tmp;
5502
5503 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5504 return -EINVAL;
5505 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
5506 if (tmp > 1)
5507 return -EINVAL;
5508 params.p2p_opp_ps = tmp;
5509 if (params.p2p_opp_ps &&
5510 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
5511 return -EINVAL;
5512 }
5513
4c476991
JB
5514 if (!rdev->ops->change_bss)
5515 return -EOPNOTSUPP;
9f1ba906 5516
074ac8df 5517 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
5518 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5519 return -EOPNOTSUPP;
3b85875a 5520
c56589ed
SW
5521 wdev_lock(wdev);
5522 err = rdev_change_bss(rdev, dev, &params);
5523 wdev_unlock(wdev);
5524
5525 return err;
9f1ba906
JM
5526}
5527
b2e1b302
LR
5528static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
5529{
b2e1b302 5530 char *data = NULL;
05050753 5531 bool is_indoor;
57b5ce07 5532 enum nl80211_user_reg_hint_type user_reg_hint_type;
05050753
I
5533 u32 owner_nlportid;
5534
80778f18
LR
5535 /*
5536 * You should only get this when cfg80211 hasn't yet initialized
5537 * completely when built-in to the kernel right between the time
5538 * window between nl80211_init() and regulatory_init(), if that is
5539 * even possible.
5540 */
458f4f9e 5541 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 5542 return -EINPROGRESS;
80778f18 5543
57b5ce07
LR
5544 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
5545 user_reg_hint_type =
5546 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
5547 else
5548 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
5549
5550 switch (user_reg_hint_type) {
5551 case NL80211_USER_REG_HINT_USER:
5552 case NL80211_USER_REG_HINT_CELL_BASE:
52616f2b
IP
5553 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
5554 return -EINVAL;
5555
5556 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
5557 return regulatory_hint_user(data, user_reg_hint_type);
5558 case NL80211_USER_REG_HINT_INDOOR:
05050753
I
5559 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
5560 owner_nlportid = info->snd_portid;
5561 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR];
5562 } else {
5563 owner_nlportid = 0;
5564 is_indoor = true;
5565 }
5566
5567 return regulatory_hint_indoor(is_indoor, owner_nlportid);
57b5ce07
LR
5568 default:
5569 return -EINVAL;
5570 }
b2e1b302
LR
5571}
5572
24bdd9f4 5573static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 5574 struct genl_info *info)
93da9cc1 5575{
4c476991 5576 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 5577 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
5578 struct wireless_dev *wdev = dev->ieee80211_ptr;
5579 struct mesh_config cur_params;
5580 int err = 0;
93da9cc1 5581 void *hdr;
5582 struct nlattr *pinfoattr;
5583 struct sk_buff *msg;
5584
29cbe68c
JB
5585 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
5586 return -EOPNOTSUPP;
5587
24bdd9f4 5588 if (!rdev->ops->get_mesh_config)
4c476991 5589 return -EOPNOTSUPP;
f3f92586 5590
29cbe68c
JB
5591 wdev_lock(wdev);
5592 /* If not connected, get default parameters */
5593 if (!wdev->mesh_id_len)
5594 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
5595 else
e35e4d28 5596 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
5597 wdev_unlock(wdev);
5598
93da9cc1 5599 if (err)
4c476991 5600 return err;
93da9cc1 5601
5602 /* Draw up a netlink message to send back */
fd2120ca 5603 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5604 if (!msg)
5605 return -ENOMEM;
15e47304 5606 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 5607 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 5608 if (!hdr)
efe1cf0c 5609 goto out;
24bdd9f4 5610 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 5611 if (!pinfoattr)
5612 goto nla_put_failure;
9360ffd1
DM
5613 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5614 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
5615 cur_params.dot11MeshRetryTimeout) ||
5616 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
5617 cur_params.dot11MeshConfirmTimeout) ||
5618 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
5619 cur_params.dot11MeshHoldingTimeout) ||
5620 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
5621 cur_params.dot11MeshMaxPeerLinks) ||
5622 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
5623 cur_params.dot11MeshMaxRetries) ||
5624 nla_put_u8(msg, NL80211_MESHCONF_TTL,
5625 cur_params.dot11MeshTTL) ||
5626 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
5627 cur_params.element_ttl) ||
5628 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
5629 cur_params.auto_open_plinks) ||
7eab0f64
JL
5630 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
5631 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
5632 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
5633 cur_params.dot11MeshHWMPmaxPREQretries) ||
5634 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
5635 cur_params.path_refresh_time) ||
5636 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
5637 cur_params.min_discovery_timeout) ||
5638 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
5639 cur_params.dot11MeshHWMPactivePathTimeout) ||
5640 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
5641 cur_params.dot11MeshHWMPpreqMinInterval) ||
5642 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
5643 cur_params.dot11MeshHWMPperrMinInterval) ||
5644 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
5645 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
5646 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
5647 cur_params.dot11MeshHWMPRootMode) ||
5648 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
5649 cur_params.dot11MeshHWMPRannInterval) ||
5650 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
5651 cur_params.dot11MeshGateAnnouncementProtocol) ||
5652 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
5653 cur_params.dot11MeshForwarding) ||
5654 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
5655 cur_params.rssi_threshold) ||
5656 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
5657 cur_params.ht_opmode) ||
5658 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
5659 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
5660 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
5661 cur_params.dot11MeshHWMProotInterval) ||
5662 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
5663 cur_params.dot11MeshHWMPconfirmationInterval) ||
5664 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
5665 cur_params.power_mode) ||
5666 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
5667 cur_params.dot11MeshAwakeWindowDuration) ||
5668 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
5669 cur_params.plink_timeout))
9360ffd1 5670 goto nla_put_failure;
93da9cc1 5671 nla_nest_end(msg, pinfoattr);
5672 genlmsg_end(msg, hdr);
4c476991 5673 return genlmsg_reply(msg, info);
93da9cc1 5674
3b85875a 5675 nla_put_failure:
93da9cc1 5676 genlmsg_cancel(msg, hdr);
efe1cf0c 5677 out:
d080e275 5678 nlmsg_free(msg);
4c476991 5679 return -ENOBUFS;
93da9cc1 5680}
5681
b54452b0 5682static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 5683 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
5684 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
5685 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
5686 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
5687 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
5688 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 5689 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 5690 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 5691 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 5692 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
5693 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
5694 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
5695 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
5696 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 5697 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 5698 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 5699 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 5700 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 5701 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 5702 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
5703 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
5704 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
5705 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
5706 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 5707 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
5708 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
5709 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 5710 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
93da9cc1 5711};
5712
c80d545d
JC
5713static const struct nla_policy
5714 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 5715 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
5716 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
5717 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 5718 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 5719 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 5720 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
581a8b0f 5721 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 5722 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 5723 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
5724};
5725
f151d9db
AB
5726static int nl80211_check_bool(const struct nlattr *nla, u8 min, u8 max, bool *out)
5727{
5728 u8 val = nla_get_u8(nla);
5729 if (val < min || val > max)
5730 return -EINVAL;
5731 *out = val;
5732 return 0;
5733}
5734
5735static int nl80211_check_u8(const struct nlattr *nla, u8 min, u8 max, u8 *out)
5736{
5737 u8 val = nla_get_u8(nla);
5738 if (val < min || val > max)
5739 return -EINVAL;
5740 *out = val;
5741 return 0;
5742}
5743
5744static int nl80211_check_u16(const struct nlattr *nla, u16 min, u16 max, u16 *out)
5745{
5746 u16 val = nla_get_u16(nla);
5747 if (val < min || val > max)
5748 return -EINVAL;
5749 *out = val;
5750 return 0;
5751}
5752
5753static int nl80211_check_u32(const struct nlattr *nla, u32 min, u32 max, u32 *out)
5754{
5755 u32 val = nla_get_u32(nla);
5756 if (val < min || val > max)
5757 return -EINVAL;
5758 *out = val;
5759 return 0;
5760}
5761
5762static int nl80211_check_s32(const struct nlattr *nla, s32 min, s32 max, s32 *out)
5763{
5764 s32 val = nla_get_s32(nla);
5765 if (val < min || val > max)
5766 return -EINVAL;
5767 *out = val;
5768 return 0;
5769}
5770
ff9a71af
JB
5771static int nl80211_check_power_mode(const struct nlattr *nla,
5772 enum nl80211_mesh_power_mode min,
5773 enum nl80211_mesh_power_mode max,
5774 enum nl80211_mesh_power_mode *out)
5775{
5776 u32 val = nla_get_u32(nla);
5777 if (val < min || val > max)
5778 return -EINVAL;
5779 *out = val;
5780 return 0;
5781}
5782
24bdd9f4 5783static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
5784 struct mesh_config *cfg,
5785 u32 *mask_out)
93da9cc1 5786{
93da9cc1 5787 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 5788 u32 mask = 0;
9757235f 5789 u16 ht_opmode;
93da9cc1 5790
ea54fba2
MP
5791#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
5792do { \
5793 if (tb[attr]) { \
f151d9db 5794 if (fn(tb[attr], min, max, &cfg->param)) \
ea54fba2 5795 return -EINVAL; \
ea54fba2
MP
5796 mask |= (1 << (attr - 1)); \
5797 } \
5798} while (0)
bd90fdcc 5799
24bdd9f4 5800 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 5801 return -EINVAL;
5802 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 5803 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 5804 nl80211_meshconf_params_policy))
93da9cc1 5805 return -EINVAL;
5806
93da9cc1 5807 /* This makes sure that there aren't more than 32 mesh config
5808 * parameters (otherwise our bitfield scheme would not work.) */
5809 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
5810
5811 /* Fill in the params struct */
ea54fba2 5812 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea 5813 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
f151d9db 5814 nl80211_check_u16);
ea54fba2 5815 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea 5816 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
f151d9db 5817 nl80211_check_u16);
ea54fba2 5818 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea 5819 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
f151d9db 5820 nl80211_check_u16);
ea54fba2 5821 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea 5822 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
f151d9db 5823 nl80211_check_u16);
ea54fba2 5824 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea 5825 mask, NL80211_MESHCONF_MAX_RETRIES,
f151d9db 5826 nl80211_check_u8);
ea54fba2 5827 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
f151d9db 5828 mask, NL80211_MESHCONF_TTL, nl80211_check_u8);
ea54fba2 5829 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea 5830 mask, NL80211_MESHCONF_ELEMENT_TTL,
f151d9db 5831 nl80211_check_u8);
ea54fba2 5832 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea 5833 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
f151d9db 5834 nl80211_check_bool);
ea54fba2
MP
5835 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
5836 1, 255, mask,
a4f606ea 5837 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
f151d9db 5838 nl80211_check_u32);
ea54fba2 5839 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea 5840 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
f151d9db 5841 nl80211_check_u8);
ea54fba2 5842 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea 5843 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
f151d9db 5844 nl80211_check_u32);
ea54fba2 5845 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea 5846 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
f151d9db 5847 nl80211_check_u16);
ea54fba2
MP
5848 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
5849 1, 65535, mask,
a4f606ea 5850 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
f151d9db 5851 nl80211_check_u32);
93da9cc1 5852 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
5853 1, 65535, mask,
5854 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
f151d9db 5855 nl80211_check_u16);
dca7e943 5856 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
5857 1, 65535, mask,
5858 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
f151d9db 5859 nl80211_check_u16);
93da9cc1 5860 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
5861 dot11MeshHWMPnetDiameterTraversalTime,
5862 1, 65535, mask,
a4f606ea 5863 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
f151d9db 5864 nl80211_check_u16);
ea54fba2
MP
5865 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
5866 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
f151d9db 5867 nl80211_check_u8);
ea54fba2
MP
5868 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
5869 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
f151d9db 5870 nl80211_check_u16);
63c5723b 5871 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
5872 dot11MeshGateAnnouncementProtocol, 0, 1,
5873 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
f151d9db 5874 nl80211_check_bool);
ea54fba2 5875 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea 5876 mask, NL80211_MESHCONF_FORWARDING,
f151d9db 5877 nl80211_check_bool);
83374fe9 5878 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0,
a4f606ea 5879 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
f151d9db 5880 nl80211_check_s32);
9757235f
MH
5881 /*
5882 * Check HT operation mode based on
5883 * IEEE 802.11 2012 8.4.2.59 HT Operation element.
5884 */
5885 if (tb[NL80211_MESHCONF_HT_OPMODE]) {
5886 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]);
5887
5888 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION |
5889 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
5890 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
5891 return -EINVAL;
5892
5893 if ((ht_opmode & IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT) &&
5894 (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
5895 return -EINVAL;
5896
5897 switch (ht_opmode & IEEE80211_HT_OP_MODE_PROTECTION) {
5898 case IEEE80211_HT_OP_MODE_PROTECTION_NONE:
5899 case IEEE80211_HT_OP_MODE_PROTECTION_20MHZ:
5900 if (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)
5901 return -EINVAL;
5902 break;
5903 case IEEE80211_HT_OP_MODE_PROTECTION_NONMEMBER:
5904 case IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED:
5905 if (!(ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
5906 return -EINVAL;
5907 break;
5908 }
5909 cfg->ht_opmode = ht_opmode;
5910 }
ac1073a6 5911 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 5912 1, 65535, mask,
ac1073a6 5913 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
f151d9db 5914 nl80211_check_u32);
ea54fba2 5915 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 5916 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
f151d9db 5917 nl80211_check_u16);
728b19e5 5918 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
5919 dot11MeshHWMPconfirmationInterval,
5920 1, 65535, mask,
728b19e5 5921 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
f151d9db 5922 nl80211_check_u16);
3b1c5a53
MP
5923 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
5924 NL80211_MESH_POWER_ACTIVE,
5925 NL80211_MESH_POWER_MAX,
5926 mask, NL80211_MESHCONF_POWER_MODE,
ff9a71af 5927 nl80211_check_power_mode);
3b1c5a53
MP
5928 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
5929 0, 65535, mask,
f151d9db 5930 NL80211_MESHCONF_AWAKE_WINDOW, nl80211_check_u16);
31f909a2 5931 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 0, 0xffffffff,
8e7c0538 5932 mask, NL80211_MESHCONF_PLINK_TIMEOUT,
f151d9db 5933 nl80211_check_u32);
bd90fdcc
JB
5934 if (mask_out)
5935 *mask_out = mask;
c80d545d 5936
bd90fdcc
JB
5937 return 0;
5938
5939#undef FILL_IN_MESH_PARAM_IF_SET
5940}
5941
c80d545d
JC
5942static int nl80211_parse_mesh_setup(struct genl_info *info,
5943 struct mesh_setup *setup)
5944{
bb2798d4 5945 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
5946 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
5947
5948 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
5949 return -EINVAL;
5950 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
5951 info->attrs[NL80211_ATTR_MESH_SETUP],
5952 nl80211_mesh_setup_params_policy))
5953 return -EINVAL;
5954
d299a1f2
JC
5955 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
5956 setup->sync_method =
5957 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
5958 IEEE80211_SYNC_METHOD_VENDOR :
5959 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
5960
c80d545d
JC
5961 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
5962 setup->path_sel_proto =
5963 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
5964 IEEE80211_PATH_PROTOCOL_VENDOR :
5965 IEEE80211_PATH_PROTOCOL_HWMP;
5966
5967 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
5968 setup->path_metric =
5969 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
5970 IEEE80211_PATH_METRIC_VENDOR :
5971 IEEE80211_PATH_METRIC_AIRTIME;
5972
581a8b0f 5973 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 5974 struct nlattr *ieattr =
581a8b0f 5975 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
5976 if (!is_valid_ie_attr(ieattr))
5977 return -EINVAL;
581a8b0f
JC
5978 setup->ie = nla_data(ieattr);
5979 setup->ie_len = nla_len(ieattr);
c80d545d 5980 }
bb2798d4
TP
5981 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
5982 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
5983 return -EINVAL;
5984 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
5985 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
5986 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
5987 if (setup->is_secure)
5988 setup->user_mpm = true;
c80d545d 5989
6e16d90b
CT
5990 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
5991 if (!setup->user_mpm)
5992 return -EINVAL;
5993 setup->auth_id =
5994 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
5995 }
5996
c80d545d
JC
5997 return 0;
5998}
5999
24bdd9f4 6000static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 6001 struct genl_info *info)
bd90fdcc
JB
6002{
6003 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6004 struct net_device *dev = info->user_ptr[1];
29cbe68c 6005 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
6006 struct mesh_config cfg;
6007 u32 mask;
6008 int err;
6009
29cbe68c
JB
6010 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
6011 return -EOPNOTSUPP;
6012
24bdd9f4 6013 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
6014 return -EOPNOTSUPP;
6015
24bdd9f4 6016 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
6017 if (err)
6018 return err;
6019
29cbe68c
JB
6020 wdev_lock(wdev);
6021 if (!wdev->mesh_id_len)
6022 err = -ENOLINK;
6023
6024 if (!err)
e35e4d28 6025 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
6026
6027 wdev_unlock(wdev);
6028
6029 return err;
93da9cc1 6030}
6031
ad30ca2c
AN
6032static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom,
6033 struct sk_buff *msg)
f130347c 6034{
f130347c
LR
6035 struct nlattr *nl_reg_rules;
6036 unsigned int i;
f130347c 6037
458f4f9e
JB
6038 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
6039 (regdom->dfs_region &&
6040 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
ad30ca2c 6041 goto nla_put_failure;
458f4f9e 6042
f130347c
LR
6043 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
6044 if (!nl_reg_rules)
ad30ca2c 6045 goto nla_put_failure;
f130347c 6046
458f4f9e 6047 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
6048 struct nlattr *nl_reg_rule;
6049 const struct ieee80211_reg_rule *reg_rule;
6050 const struct ieee80211_freq_range *freq_range;
6051 const struct ieee80211_power_rule *power_rule;
97524820 6052 unsigned int max_bandwidth_khz;
f130347c 6053
458f4f9e 6054 reg_rule = &regdom->reg_rules[i];
f130347c
LR
6055 freq_range = &reg_rule->freq_range;
6056 power_rule = &reg_rule->power_rule;
6057
6058 nl_reg_rule = nla_nest_start(msg, i);
6059 if (!nl_reg_rule)
ad30ca2c 6060 goto nla_put_failure;
f130347c 6061
97524820
JD
6062 max_bandwidth_khz = freq_range->max_bandwidth_khz;
6063 if (!max_bandwidth_khz)
6064 max_bandwidth_khz = reg_get_max_bandwidth(regdom,
6065 reg_rule);
6066
9360ffd1
DM
6067 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
6068 reg_rule->flags) ||
6069 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
6070 freq_range->start_freq_khz) ||
6071 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
6072 freq_range->end_freq_khz) ||
6073 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
97524820 6074 max_bandwidth_khz) ||
9360ffd1
DM
6075 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
6076 power_rule->max_antenna_gain) ||
6077 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
089027e5
JD
6078 power_rule->max_eirp) ||
6079 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME,
6080 reg_rule->dfs_cac_ms))
ad30ca2c 6081 goto nla_put_failure;
f130347c
LR
6082
6083 nla_nest_end(msg, nl_reg_rule);
6084 }
6085
6086 nla_nest_end(msg, nl_reg_rules);
ad30ca2c
AN
6087 return 0;
6088
6089nla_put_failure:
6090 return -EMSGSIZE;
6091}
6092
6093static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info)
6094{
6095 const struct ieee80211_regdomain *regdom = NULL;
6096 struct cfg80211_registered_device *rdev;
6097 struct wiphy *wiphy = NULL;
6098 struct sk_buff *msg;
6099 void *hdr;
6100
6101 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6102 if (!msg)
6103 return -ENOBUFS;
6104
6105 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
6106 NL80211_CMD_GET_REG);
6107 if (!hdr)
6108 goto put_failure;
6109
6110 if (info->attrs[NL80211_ATTR_WIPHY]) {
1bdd716c
AN
6111 bool self_managed;
6112
ad30ca2c
AN
6113 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
6114 if (IS_ERR(rdev)) {
6115 nlmsg_free(msg);
6116 return PTR_ERR(rdev);
6117 }
6118
6119 wiphy = &rdev->wiphy;
1bdd716c
AN
6120 self_managed = wiphy->regulatory_flags &
6121 REGULATORY_WIPHY_SELF_MANAGED;
ad30ca2c
AN
6122 regdom = get_wiphy_regdom(wiphy);
6123
1bdd716c
AN
6124 /* a self-managed-reg device must have a private regdom */
6125 if (WARN_ON(!regdom && self_managed)) {
6126 nlmsg_free(msg);
6127 return -EINVAL;
6128 }
6129
ad30ca2c
AN
6130 if (regdom &&
6131 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
6132 goto nla_put_failure;
6133 }
6134
6135 if (!wiphy && reg_last_request_cell_base() &&
6136 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
6137 NL80211_USER_REG_HINT_CELL_BASE))
6138 goto nla_put_failure;
6139
6140 rcu_read_lock();
6141
6142 if (!regdom)
6143 regdom = rcu_dereference(cfg80211_regdomain);
6144
6145 if (nl80211_put_regdom(regdom, msg))
6146 goto nla_put_failure_rcu;
6147
6148 rcu_read_unlock();
f130347c
LR
6149
6150 genlmsg_end(msg, hdr);
5fe231e8 6151 return genlmsg_reply(msg, info);
f130347c 6152
458f4f9e
JB
6153nla_put_failure_rcu:
6154 rcu_read_unlock();
f130347c
LR
6155nla_put_failure:
6156 genlmsg_cancel(msg, hdr);
efe1cf0c 6157put_failure:
d080e275 6158 nlmsg_free(msg);
5fe231e8 6159 return -EMSGSIZE;
f130347c
LR
6160}
6161
ad30ca2c
AN
6162static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb,
6163 u32 seq, int flags, struct wiphy *wiphy,
6164 const struct ieee80211_regdomain *regdom)
6165{
6166 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
6167 NL80211_CMD_GET_REG);
6168
6169 if (!hdr)
6170 return -1;
6171
6172 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
6173
6174 if (nl80211_put_regdom(regdom, msg))
6175 goto nla_put_failure;
6176
6177 if (!wiphy && reg_last_request_cell_base() &&
6178 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
6179 NL80211_USER_REG_HINT_CELL_BASE))
6180 goto nla_put_failure;
6181
6182 if (wiphy &&
6183 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
6184 goto nla_put_failure;
6185
1bdd716c
AN
6186 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
6187 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
6188 goto nla_put_failure;
6189
053c095a
JB
6190 genlmsg_end(msg, hdr);
6191 return 0;
ad30ca2c
AN
6192
6193nla_put_failure:
6194 genlmsg_cancel(msg, hdr);
6195 return -EMSGSIZE;
6196}
6197
6198static int nl80211_get_reg_dump(struct sk_buff *skb,
6199 struct netlink_callback *cb)
6200{
6201 const struct ieee80211_regdomain *regdom = NULL;
6202 struct cfg80211_registered_device *rdev;
6203 int err, reg_idx, start = cb->args[2];
6204
6205 rtnl_lock();
6206
6207 if (cfg80211_regdomain && start == 0) {
6208 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
6209 NLM_F_MULTI, NULL,
6210 rtnl_dereference(cfg80211_regdomain));
6211 if (err < 0)
6212 goto out_err;
6213 }
6214
6215 /* the global regdom is idx 0 */
6216 reg_idx = 1;
6217 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
6218 regdom = get_wiphy_regdom(&rdev->wiphy);
6219 if (!regdom)
6220 continue;
6221
6222 if (++reg_idx <= start)
6223 continue;
6224
6225 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
6226 NLM_F_MULTI, &rdev->wiphy, regdom);
6227 if (err < 0) {
6228 reg_idx--;
6229 break;
6230 }
6231 }
6232
6233 cb->args[2] = reg_idx;
6234 err = skb->len;
6235out_err:
6236 rtnl_unlock();
6237 return err;
6238}
6239
b6863036
JB
6240#ifdef CONFIG_CFG80211_CRDA_SUPPORT
6241static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
6242 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
6243 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
6244 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
6245 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
6246 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
6247 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
6248 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 },
6249};
6250
6251static int parse_reg_rule(struct nlattr *tb[],
6252 struct ieee80211_reg_rule *reg_rule)
6253{
6254 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
6255 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
6256
6257 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
6258 return -EINVAL;
6259 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
6260 return -EINVAL;
6261 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
6262 return -EINVAL;
6263 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
6264 return -EINVAL;
6265 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
6266 return -EINVAL;
6267
6268 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
6269
6270 freq_range->start_freq_khz =
6271 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
6272 freq_range->end_freq_khz =
6273 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
6274 freq_range->max_bandwidth_khz =
6275 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
6276
6277 power_rule->max_eirp =
6278 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
6279
6280 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
6281 power_rule->max_antenna_gain =
6282 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
6283
6284 if (tb[NL80211_ATTR_DFS_CAC_TIME])
6285 reg_rule->dfs_cac_ms =
6286 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]);
6287
6288 return 0;
6289}
6290
b2e1b302
LR
6291static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
6292{
6293 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
6294 struct nlattr *nl_reg_rule;
ea372c54
JB
6295 char *alpha2;
6296 int rem_reg_rules, r;
b2e1b302 6297 u32 num_rules = 0, rule_idx = 0, size_of_regd;
4c7d3982 6298 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
ea372c54 6299 struct ieee80211_regdomain *rd;
b2e1b302
LR
6300
6301 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
6302 return -EINVAL;
6303
6304 if (!info->attrs[NL80211_ATTR_REG_RULES])
6305 return -EINVAL;
6306
6307 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
6308
8b60b078
LR
6309 if (info->attrs[NL80211_ATTR_DFS_REGION])
6310 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
6311
b2e1b302 6312 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 6313 rem_reg_rules) {
b2e1b302
LR
6314 num_rules++;
6315 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 6316 return -EINVAL;
b2e1b302
LR
6317 }
6318
e438768f
LR
6319 if (!reg_is_valid_request(alpha2))
6320 return -EINVAL;
6321
b2e1b302 6322 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 6323 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
6324
6325 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
6326 if (!rd)
6327 return -ENOMEM;
b2e1b302
LR
6328
6329 rd->n_reg_rules = num_rules;
6330 rd->alpha2[0] = alpha2[0];
6331 rd->alpha2[1] = alpha2[1];
6332
8b60b078
LR
6333 /*
6334 * Disable DFS master mode if the DFS region was
6335 * not supported or known on this kernel.
6336 */
6337 if (reg_supported_dfs_region(dfs_region))
6338 rd->dfs_region = dfs_region;
6339
b2e1b302 6340 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 6341 rem_reg_rules) {
bfe2c7b1
JB
6342 r = nla_parse_nested(tb, NL80211_REG_RULE_ATTR_MAX,
6343 nl_reg_rule, reg_rule_policy);
ae811e21
JB
6344 if (r)
6345 goto bad_reg;
b2e1b302
LR
6346 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
6347 if (r)
6348 goto bad_reg;
6349
6350 rule_idx++;
6351
d0e18f83
LR
6352 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
6353 r = -EINVAL;
b2e1b302 6354 goto bad_reg;
d0e18f83 6355 }
b2e1b302
LR
6356 }
6357
06627990
JB
6358 /* set_regdom takes ownership of rd */
6359 return set_regdom(rd, REGD_SOURCE_CRDA);
d2372b31 6360 bad_reg:
b2e1b302 6361 kfree(rd);
d0e18f83 6362 return r;
b2e1b302 6363}
b6863036 6364#endif /* CONFIG_CFG80211_CRDA_SUPPORT */
b2e1b302 6365
83f5e2cf
JB
6366static int validate_scan_freqs(struct nlattr *freqs)
6367{
6368 struct nlattr *attr1, *attr2;
6369 int n_channels = 0, tmp1, tmp2;
6370
6371 nla_for_each_nested(attr1, freqs, tmp1) {
6372 n_channels++;
6373 /*
6374 * Some hardware has a limited channel list for
6375 * scanning, and it is pretty much nonsensical
6376 * to scan for a channel twice, so disallow that
6377 * and don't require drivers to check that the
6378 * channel list they get isn't longer than what
6379 * they can scan, as long as they can scan all
6380 * the channels they registered at once.
6381 */
6382 nla_for_each_nested(attr2, freqs, tmp2)
6383 if (attr1 != attr2 &&
6384 nla_get_u32(attr1) == nla_get_u32(attr2))
6385 return 0;
6386 }
6387
6388 return n_channels;
6389}
6390
57fbcce3 6391static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b)
38de03d2 6392{
57fbcce3 6393 return b < NUM_NL80211_BANDS && wiphy->bands[b];
38de03d2
AS
6394}
6395
6396static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy,
6397 struct cfg80211_bss_selection *bss_select)
6398{
6399 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1];
6400 struct nlattr *nest;
6401 int err;
6402 bool found = false;
6403 int i;
6404
6405 /* only process one nested attribute */
6406 nest = nla_data(nla);
6407 if (!nla_ok(nest, nla_len(nest)))
6408 return -EINVAL;
6409
bfe2c7b1
JB
6410 err = nla_parse_nested(attr, NL80211_BSS_SELECT_ATTR_MAX, nest,
6411 nl80211_bss_select_policy);
38de03d2
AS
6412 if (err)
6413 return err;
6414
6415 /* only one attribute may be given */
6416 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) {
6417 if (attr[i]) {
6418 if (found)
6419 return -EINVAL;
6420 found = true;
6421 }
6422 }
6423
6424 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID;
6425
6426 if (attr[NL80211_BSS_SELECT_ATTR_RSSI])
6427 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI;
6428
6429 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) {
6430 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF;
6431 bss_select->param.band_pref =
6432 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]);
6433 if (!is_band_valid(wiphy, bss_select->param.band_pref))
6434 return -EINVAL;
6435 }
6436
6437 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) {
6438 struct nl80211_bss_select_rssi_adjust *adj_param;
6439
6440 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]);
6441 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST;
6442 bss_select->param.adjust.band = adj_param->band;
6443 bss_select->param.adjust.delta = adj_param->delta;
6444 if (!is_band_valid(wiphy, bss_select->param.adjust.band))
6445 return -EINVAL;
6446 }
6447
6448 /* user-space did not provide behaviour attribute */
6449 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID)
6450 return -EINVAL;
6451
6452 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour)))
6453 return -EINVAL;
6454
6455 return 0;
6456}
6457
ad2b26ab
JB
6458static int nl80211_parse_random_mac(struct nlattr **attrs,
6459 u8 *mac_addr, u8 *mac_addr_mask)
6460{
6461 int i;
6462
6463 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) {
d2beae10
JP
6464 eth_zero_addr(mac_addr);
6465 eth_zero_addr(mac_addr_mask);
ad2b26ab
JB
6466 mac_addr[0] = 0x2;
6467 mac_addr_mask[0] = 0x3;
6468
6469 return 0;
6470 }
6471
6472 /* need both or none */
6473 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK])
6474 return -EINVAL;
6475
6476 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN);
6477 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN);
6478
6479 /* don't allow or configure an mcast address */
6480 if (!is_multicast_ether_addr(mac_addr_mask) ||
6481 is_multicast_ether_addr(mac_addr))
6482 return -EINVAL;
6483
6484 /*
6485 * allow users to pass a MAC address that has bits set outside
6486 * of the mask, but don't bother drivers with having to deal
6487 * with such bits
6488 */
6489 for (i = 0; i < ETH_ALEN; i++)
6490 mac_addr[i] &= mac_addr_mask[i];
6491
6492 return 0;
6493}
6494
2a519311
JB
6495static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
6496{
4c476991 6497 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 6498 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 6499 struct cfg80211_scan_request *request;
2a519311
JB
6500 struct nlattr *attr;
6501 struct wiphy *wiphy;
83f5e2cf 6502 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 6503 size_t ie_len;
2a519311 6504
f4a11bb0
JB
6505 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6506 return -EINVAL;
6507
79c97e97 6508 wiphy = &rdev->wiphy;
2a519311 6509
cb3b7d87
AB
6510 if (wdev->iftype == NL80211_IFTYPE_NAN)
6511 return -EOPNOTSUPP;
6512
4c476991
JB
6513 if (!rdev->ops->scan)
6514 return -EOPNOTSUPP;
2a519311 6515
f9d15d16 6516 if (rdev->scan_req || rdev->scan_msg) {
f9f47529
JB
6517 err = -EBUSY;
6518 goto unlock;
6519 }
2a519311
JB
6520
6521 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
6522 n_channels = validate_scan_freqs(
6523 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
6524 if (!n_channels) {
6525 err = -EINVAL;
6526 goto unlock;
6527 }
2a519311 6528 } else {
bdfbec2d 6529 n_channels = ieee80211_get_num_supported_channels(wiphy);
2a519311
JB
6530 }
6531
6532 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
6533 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
6534 n_ssids++;
6535
f9f47529
JB
6536 if (n_ssids > wiphy->max_scan_ssids) {
6537 err = -EINVAL;
6538 goto unlock;
6539 }
2a519311 6540
70692ad2
JM
6541 if (info->attrs[NL80211_ATTR_IE])
6542 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6543 else
6544 ie_len = 0;
6545
f9f47529
JB
6546 if (ie_len > wiphy->max_scan_ie_len) {
6547 err = -EINVAL;
6548 goto unlock;
6549 }
18a83659 6550
2a519311 6551 request = kzalloc(sizeof(*request)
a2cd43c5
LC
6552 + sizeof(*request->ssids) * n_ssids
6553 + sizeof(*request->channels) * n_channels
70692ad2 6554 + ie_len, GFP_KERNEL);
f9f47529
JB
6555 if (!request) {
6556 err = -ENOMEM;
6557 goto unlock;
6558 }
2a519311 6559
2a519311 6560 if (n_ssids)
5ba63533 6561 request->ssids = (void *)&request->channels[n_channels];
2a519311 6562 request->n_ssids = n_ssids;
70692ad2 6563 if (ie_len) {
13874e4b 6564 if (n_ssids)
70692ad2
JM
6565 request->ie = (void *)(request->ssids + n_ssids);
6566 else
6567 request->ie = (void *)(request->channels + n_channels);
6568 }
2a519311 6569
584991dc 6570 i = 0;
2a519311
JB
6571 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
6572 /* user specified, bail out if channel not found */
2a519311 6573 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
6574 struct ieee80211_channel *chan;
6575
6576 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
6577
6578 if (!chan) {
2a519311
JB
6579 err = -EINVAL;
6580 goto out_free;
6581 }
584991dc
JB
6582
6583 /* ignore disabled channels */
6584 if (chan->flags & IEEE80211_CHAN_DISABLED)
6585 continue;
6586
6587 request->channels[i] = chan;
2a519311
JB
6588 i++;
6589 }
6590 } else {
57fbcce3 6591 enum nl80211_band band;
34850ab2 6592
2a519311 6593 /* all channels */
57fbcce3 6594 for (band = 0; band < NUM_NL80211_BANDS; band++) {
2a519311 6595 int j;
7a087e74 6596
2a519311
JB
6597 if (!wiphy->bands[band])
6598 continue;
6599 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
6600 struct ieee80211_channel *chan;
6601
6602 chan = &wiphy->bands[band]->channels[j];
6603
6604 if (chan->flags & IEEE80211_CHAN_DISABLED)
6605 continue;
6606
6607 request->channels[i] = chan;
2a519311
JB
6608 i++;
6609 }
6610 }
6611 }
6612
584991dc
JB
6613 if (!i) {
6614 err = -EINVAL;
6615 goto out_free;
6616 }
6617
6618 request->n_channels = i;
6619
2a519311 6620 i = 0;
13874e4b 6621 if (n_ssids) {
2a519311 6622 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 6623 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
6624 err = -EINVAL;
6625 goto out_free;
6626 }
57a27e1d 6627 request->ssids[i].ssid_len = nla_len(attr);
2a519311 6628 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
6629 i++;
6630 }
6631 }
6632
70692ad2
JM
6633 if (info->attrs[NL80211_ATTR_IE]) {
6634 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
6635 memcpy((void *)request->ie,
6636 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
6637 request->ie_len);
6638 }
6639
57fbcce3 6640 for (i = 0; i < NUM_NL80211_BANDS; i++)
a401d2bb
JB
6641 if (wiphy->bands[i])
6642 request->rates[i] =
6643 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
6644
6645 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
6646 nla_for_each_nested(attr,
6647 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
6648 tmp) {
57fbcce3 6649 enum nl80211_band band = nla_type(attr);
34850ab2 6650
57fbcce3 6651 if (band < 0 || band >= NUM_NL80211_BANDS) {
34850ab2
JB
6652 err = -EINVAL;
6653 goto out_free;
6654 }
1b09cd82
FF
6655
6656 if (!wiphy->bands[band])
6657 continue;
6658
34850ab2
JB
6659 err = ieee80211_get_ratemask(wiphy->bands[band],
6660 nla_data(attr),
6661 nla_len(attr),
6662 &request->rates[band]);
6663 if (err)
6664 goto out_free;
6665 }
6666 }
6667
1d76250b
AS
6668 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) {
6669 if (!wiphy_ext_feature_isset(wiphy,
6670 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) {
6671 err = -EOPNOTSUPP;
6672 goto out_free;
6673 }
6674
6675 request->duration =
6676 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]);
6677 request->duration_mandatory =
6678 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]);
6679 }
6680
46856bbf 6681 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
6682 request->flags = nla_get_u32(
6683 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
00c3a6ed
JB
6684 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
6685 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) {
46856bbf
SL
6686 err = -EOPNOTSUPP;
6687 goto out_free;
6688 }
ad2b26ab
JB
6689
6690 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
6691 if (!(wiphy->features &
6692 NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR)) {
6693 err = -EOPNOTSUPP;
6694 goto out_free;
6695 }
6696
6697 if (wdev->current_bss) {
6698 err = -EOPNOTSUPP;
6699 goto out_free;
6700 }
6701
6702 err = nl80211_parse_random_mac(info->attrs,
6703 request->mac_addr,
6704 request->mac_addr_mask);
6705 if (err)
6706 goto out_free;
6707 }
46856bbf 6708 }
ed473771 6709
e9f935e3
RM
6710 request->no_cck =
6711 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6712
818965d3
JM
6713 if (info->attrs[NL80211_ATTR_MAC])
6714 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]),
6715 ETH_ALEN);
6716 else
6717 eth_broadcast_addr(request->bssid);
6718
fd014284 6719 request->wdev = wdev;
79c97e97 6720 request->wiphy = &rdev->wiphy;
15d6030b 6721 request->scan_start = jiffies;
2a519311 6722
79c97e97 6723 rdev->scan_req = request;
e35e4d28 6724 err = rdev_scan(rdev, request);
2a519311 6725
463d0183 6726 if (!err) {
fd014284
JB
6727 nl80211_send_scan_start(rdev, wdev);
6728 if (wdev->netdev)
6729 dev_hold(wdev->netdev);
4c476991 6730 } else {
2a519311 6731 out_free:
79c97e97 6732 rdev->scan_req = NULL;
2a519311
JB
6733 kfree(request);
6734 }
3b85875a 6735
f9f47529 6736 unlock:
2a519311
JB
6737 return err;
6738}
6739
91d3ab46
VK
6740static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info)
6741{
6742 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6743 struct wireless_dev *wdev = info->user_ptr[1];
6744
6745 if (!rdev->ops->abort_scan)
6746 return -EOPNOTSUPP;
6747
6748 if (rdev->scan_msg)
6749 return 0;
6750
6751 if (!rdev->scan_req)
6752 return -ENOENT;
6753
6754 rdev_abort_scan(rdev, wdev);
6755 return 0;
6756}
6757
3b06d277
AS
6758static int
6759nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans,
6760 struct cfg80211_sched_scan_request *request,
6761 struct nlattr **attrs)
6762{
6763 int tmp, err, i = 0;
6764 struct nlattr *attr;
6765
6766 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
6767 u32 interval;
6768
6769 /*
6770 * If scan plans are not specified,
6771 * %NL80211_ATTR_SCHED_SCAN_INTERVAL must be specified. In this
6772 * case one scan plan will be set with the specified scan
6773 * interval and infinite number of iterations.
6774 */
6775 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
6776 return -EINVAL;
6777
6778 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
6779 if (!interval)
6780 return -EINVAL;
6781
6782 request->scan_plans[0].interval =
6783 DIV_ROUND_UP(interval, MSEC_PER_SEC);
6784 if (!request->scan_plans[0].interval)
6785 return -EINVAL;
6786
6787 if (request->scan_plans[0].interval >
6788 wiphy->max_sched_scan_plan_interval)
6789 request->scan_plans[0].interval =
6790 wiphy->max_sched_scan_plan_interval;
6791
6792 return 0;
6793 }
6794
6795 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) {
6796 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1];
6797
6798 if (WARN_ON(i >= n_plans))
6799 return -EINVAL;
6800
bfe2c7b1
JB
6801 err = nla_parse_nested(plan, NL80211_SCHED_SCAN_PLAN_MAX,
6802 attr, nl80211_plan_policy);
3b06d277
AS
6803 if (err)
6804 return err;
6805
6806 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL])
6807 return -EINVAL;
6808
6809 request->scan_plans[i].interval =
6810 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]);
6811 if (!request->scan_plans[i].interval ||
6812 request->scan_plans[i].interval >
6813 wiphy->max_sched_scan_plan_interval)
6814 return -EINVAL;
6815
6816 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) {
6817 request->scan_plans[i].iterations =
6818 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]);
6819 if (!request->scan_plans[i].iterations ||
6820 (request->scan_plans[i].iterations >
6821 wiphy->max_sched_scan_plan_iterations))
6822 return -EINVAL;
6823 } else if (i < n_plans - 1) {
6824 /*
6825 * All scan plans but the last one must specify
6826 * a finite number of iterations
6827 */
6828 return -EINVAL;
6829 }
6830
6831 i++;
6832 }
6833
6834 /*
6835 * The last scan plan must not specify the number of
6836 * iterations, it is supposed to run infinitely
6837 */
6838 if (request->scan_plans[n_plans - 1].iterations)
6839 return -EINVAL;
6840
6841 return 0;
6842}
6843
256da02d 6844static struct cfg80211_sched_scan_request *
ad2b26ab 6845nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev,
256da02d 6846 struct nlattr **attrs)
807f8a8c
LC
6847{
6848 struct cfg80211_sched_scan_request *request;
807f8a8c 6849 struct nlattr *attr;
3b06d277 6850 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0;
57fbcce3 6851 enum nl80211_band band;
807f8a8c 6852 size_t ie_len;
a1f1c21c 6853 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
ea73cbce 6854 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF;
807f8a8c 6855
256da02d
LC
6856 if (!is_valid_ie_attr(attrs[NL80211_ATTR_IE]))
6857 return ERR_PTR(-EINVAL);
807f8a8c 6858
256da02d 6859 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c 6860 n_channels = validate_scan_freqs(
256da02d 6861 attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
807f8a8c 6862 if (!n_channels)
256da02d 6863 return ERR_PTR(-EINVAL);
807f8a8c 6864 } else {
bdfbec2d 6865 n_channels = ieee80211_get_num_supported_channels(wiphy);
807f8a8c
LC
6866 }
6867
256da02d
LC
6868 if (attrs[NL80211_ATTR_SCAN_SSIDS])
6869 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c
LC
6870 tmp)
6871 n_ssids++;
6872
93b6aa69 6873 if (n_ssids > wiphy->max_sched_scan_ssids)
256da02d 6874 return ERR_PTR(-EINVAL);
807f8a8c 6875
ea73cbce
JB
6876 /*
6877 * First, count the number of 'real' matchsets. Due to an issue with
6878 * the old implementation, matchsets containing only the RSSI attribute
6879 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default'
6880 * RSSI for all matchsets, rather than their own matchset for reporting
6881 * all APs with a strong RSSI. This is needed to be compatible with
6882 * older userspace that treated a matchset with only the RSSI as the
6883 * global RSSI for all other matchsets - if there are other matchsets.
6884 */
256da02d 6885 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 6886 nla_for_each_nested(attr,
256da02d 6887 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
ea73cbce
JB
6888 tmp) {
6889 struct nlattr *rssi;
6890
bfe2c7b1
JB
6891 err = nla_parse_nested(tb,
6892 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
6893 attr, nl80211_match_policy);
ea73cbce 6894 if (err)
256da02d 6895 return ERR_PTR(err);
ea73cbce
JB
6896 /* add other standalone attributes here */
6897 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]) {
6898 n_match_sets++;
6899 continue;
6900 }
6901 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
6902 if (rssi)
6903 default_match_rssi = nla_get_s32(rssi);
6904 }
6905 }
6906
6907 /* However, if there's no other matchset, add the RSSI one */
6908 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF)
6909 n_match_sets = 1;
a1f1c21c
LC
6910
6911 if (n_match_sets > wiphy->max_match_sets)
256da02d 6912 return ERR_PTR(-EINVAL);
a1f1c21c 6913
256da02d
LC
6914 if (attrs[NL80211_ATTR_IE])
6915 ie_len = nla_len(attrs[NL80211_ATTR_IE]);
807f8a8c
LC
6916 else
6917 ie_len = 0;
6918
5a865bad 6919 if (ie_len > wiphy->max_sched_scan_ie_len)
256da02d 6920 return ERR_PTR(-EINVAL);
c10841ca 6921
3b06d277
AS
6922 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
6923 /*
6924 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since
6925 * each scan plan already specifies its own interval
6926 */
6927 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
6928 return ERR_PTR(-EINVAL);
6929
6930 nla_for_each_nested(attr,
6931 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp)
6932 n_plans++;
6933 } else {
6934 /*
6935 * The scan interval attribute is kept for backward
6936 * compatibility. If no scan plans are specified and sched scan
6937 * interval is specified, one scan plan will be set with this
6938 * scan interval and infinite number of iterations.
6939 */
6940 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
6941 return ERR_PTR(-EINVAL);
6942
6943 n_plans = 1;
6944 }
6945
6946 if (!n_plans || n_plans > wiphy->max_sched_scan_plans)
6947 return ERR_PTR(-EINVAL);
6948
807f8a8c 6949 request = kzalloc(sizeof(*request)
a2cd43c5 6950 + sizeof(*request->ssids) * n_ssids
a1f1c21c 6951 + sizeof(*request->match_sets) * n_match_sets
3b06d277 6952 + sizeof(*request->scan_plans) * n_plans
a2cd43c5 6953 + sizeof(*request->channels) * n_channels
807f8a8c 6954 + ie_len, GFP_KERNEL);
256da02d
LC
6955 if (!request)
6956 return ERR_PTR(-ENOMEM);
807f8a8c
LC
6957
6958 if (n_ssids)
6959 request->ssids = (void *)&request->channels[n_channels];
6960 request->n_ssids = n_ssids;
6961 if (ie_len) {
13874e4b 6962 if (n_ssids)
807f8a8c
LC
6963 request->ie = (void *)(request->ssids + n_ssids);
6964 else
6965 request->ie = (void *)(request->channels + n_channels);
6966 }
6967
a1f1c21c
LC
6968 if (n_match_sets) {
6969 if (request->ie)
6970 request->match_sets = (void *)(request->ie + ie_len);
13874e4b 6971 else if (n_ssids)
a1f1c21c
LC
6972 request->match_sets =
6973 (void *)(request->ssids + n_ssids);
6974 else
6975 request->match_sets =
6976 (void *)(request->channels + n_channels);
6977 }
6978 request->n_match_sets = n_match_sets;
6979
3b06d277
AS
6980 if (n_match_sets)
6981 request->scan_plans = (void *)(request->match_sets +
6982 n_match_sets);
6983 else if (request->ie)
6984 request->scan_plans = (void *)(request->ie + ie_len);
6985 else if (n_ssids)
6986 request->scan_plans = (void *)(request->ssids + n_ssids);
6987 else
6988 request->scan_plans = (void *)(request->channels + n_channels);
6989
6990 request->n_scan_plans = n_plans;
6991
807f8a8c 6992 i = 0;
256da02d 6993 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c
LC
6994 /* user specified, bail out if channel not found */
6995 nla_for_each_nested(attr,
256da02d 6996 attrs[NL80211_ATTR_SCAN_FREQUENCIES],
807f8a8c
LC
6997 tmp) {
6998 struct ieee80211_channel *chan;
6999
7000 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
7001
7002 if (!chan) {
7003 err = -EINVAL;
7004 goto out_free;
7005 }
7006
7007 /* ignore disabled channels */
7008 if (chan->flags & IEEE80211_CHAN_DISABLED)
7009 continue;
7010
7011 request->channels[i] = chan;
7012 i++;
7013 }
7014 } else {
7015 /* all channels */
57fbcce3 7016 for (band = 0; band < NUM_NL80211_BANDS; band++) {
807f8a8c 7017 int j;
7a087e74 7018
807f8a8c
LC
7019 if (!wiphy->bands[band])
7020 continue;
7021 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
7022 struct ieee80211_channel *chan;
7023
7024 chan = &wiphy->bands[band]->channels[j];
7025
7026 if (chan->flags & IEEE80211_CHAN_DISABLED)
7027 continue;
7028
7029 request->channels[i] = chan;
7030 i++;
7031 }
7032 }
7033 }
7034
7035 if (!i) {
7036 err = -EINVAL;
7037 goto out_free;
7038 }
7039
7040 request->n_channels = i;
7041
7042 i = 0;
13874e4b 7043 if (n_ssids) {
256da02d 7044 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c 7045 tmp) {
57a27e1d 7046 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
7047 err = -EINVAL;
7048 goto out_free;
7049 }
57a27e1d 7050 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
7051 memcpy(request->ssids[i].ssid, nla_data(attr),
7052 nla_len(attr));
807f8a8c
LC
7053 i++;
7054 }
7055 }
7056
a1f1c21c 7057 i = 0;
256da02d 7058 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 7059 nla_for_each_nested(attr,
256da02d 7060 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
a1f1c21c 7061 tmp) {
88e920b4 7062 struct nlattr *ssid, *rssi;
a1f1c21c 7063
bfe2c7b1
JB
7064 err = nla_parse_nested(tb,
7065 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
7066 attr, nl80211_match_policy);
ae811e21
JB
7067 if (err)
7068 goto out_free;
4a4ab0d7 7069 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c 7070 if (ssid) {
ea73cbce
JB
7071 if (WARN_ON(i >= n_match_sets)) {
7072 /* this indicates a programming error,
7073 * the loop above should have verified
7074 * things properly
7075 */
7076 err = -EINVAL;
7077 goto out_free;
7078 }
7079
a1f1c21c
LC
7080 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
7081 err = -EINVAL;
7082 goto out_free;
7083 }
7084 memcpy(request->match_sets[i].ssid.ssid,
7085 nla_data(ssid), nla_len(ssid));
7086 request->match_sets[i].ssid.ssid_len =
7087 nla_len(ssid);
56ab364f 7088 /* special attribute - old implementation w/a */
ea73cbce
JB
7089 request->match_sets[i].rssi_thold =
7090 default_match_rssi;
7091 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
7092 if (rssi)
7093 request->match_sets[i].rssi_thold =
7094 nla_get_s32(rssi);
a1f1c21c
LC
7095 }
7096 i++;
7097 }
ea73cbce
JB
7098
7099 /* there was no other matchset, so the RSSI one is alone */
f89f46cf 7100 if (i == 0 && n_match_sets)
ea73cbce
JB
7101 request->match_sets[0].rssi_thold = default_match_rssi;
7102
7103 request->min_rssi_thold = INT_MAX;
7104 for (i = 0; i < n_match_sets; i++)
7105 request->min_rssi_thold =
7106 min(request->match_sets[i].rssi_thold,
7107 request->min_rssi_thold);
7108 } else {
7109 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
7110 }
7111
9900e484
JB
7112 if (ie_len) {
7113 request->ie_len = ie_len;
807f8a8c 7114 memcpy((void *)request->ie,
256da02d 7115 nla_data(attrs[NL80211_ATTR_IE]),
807f8a8c
LC
7116 request->ie_len);
7117 }
7118
256da02d 7119 if (attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771 7120 request->flags = nla_get_u32(
256da02d 7121 attrs[NL80211_ATTR_SCAN_FLAGS]);
00c3a6ed
JB
7122 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
7123 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) {
46856bbf
SL
7124 err = -EOPNOTSUPP;
7125 goto out_free;
7126 }
ad2b26ab
JB
7127
7128 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
7129 u32 flg = NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR;
7130
7131 if (!wdev) /* must be net-detect */
7132 flg = NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
7133
7134 if (!(wiphy->features & flg)) {
7135 err = -EOPNOTSUPP;
7136 goto out_free;
7137 }
7138
7139 if (wdev && wdev->current_bss) {
7140 err = -EOPNOTSUPP;
7141 goto out_free;
7142 }
7143
7144 err = nl80211_parse_random_mac(attrs, request->mac_addr,
7145 request->mac_addr_mask);
7146 if (err)
7147 goto out_free;
7148 }
46856bbf 7149 }
ed473771 7150
9c748934
LC
7151 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY])
7152 request->delay =
7153 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]);
7154
3b06d277
AS
7155 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs);
7156 if (err)
7157 goto out_free;
7158
15d6030b 7159 request->scan_start = jiffies;
807f8a8c 7160
256da02d 7161 return request;
807f8a8c
LC
7162
7163out_free:
7164 kfree(request);
256da02d
LC
7165 return ERR_PTR(err);
7166}
7167
7168static int nl80211_start_sched_scan(struct sk_buff *skb,
7169 struct genl_info *info)
7170{
7171 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7172 struct net_device *dev = info->user_ptr[1];
ad2b26ab 7173 struct wireless_dev *wdev = dev->ieee80211_ptr;
31a60ed1 7174 struct cfg80211_sched_scan_request *sched_scan_req;
256da02d
LC
7175 int err;
7176
7177 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
7178 !rdev->ops->sched_scan_start)
7179 return -EOPNOTSUPP;
7180
7181 if (rdev->sched_scan_req)
7182 return -EINPROGRESS;
7183
31a60ed1
JR
7184 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev,
7185 info->attrs);
7186
7187 err = PTR_ERR_OR_ZERO(sched_scan_req);
256da02d
LC
7188 if (err)
7189 goto out_err;
7190
31a60ed1 7191 err = rdev_sched_scan_start(rdev, dev, sched_scan_req);
256da02d
LC
7192 if (err)
7193 goto out_free;
7194
31a60ed1
JR
7195 sched_scan_req->dev = dev;
7196 sched_scan_req->wiphy = &rdev->wiphy;
7197
93a1e86c
JR
7198 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
7199 sched_scan_req->owner_nlportid = info->snd_portid;
7200
31a60ed1 7201 rcu_assign_pointer(rdev->sched_scan_req, sched_scan_req);
256da02d
LC
7202
7203 nl80211_send_sched_scan(rdev, dev,
7204 NL80211_CMD_START_SCHED_SCAN);
7205 return 0;
7206
7207out_free:
31a60ed1 7208 kfree(sched_scan_req);
256da02d 7209out_err:
807f8a8c
LC
7210 return err;
7211}
7212
7213static int nl80211_stop_sched_scan(struct sk_buff *skb,
7214 struct genl_info *info)
7215{
7216 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7217
7218 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
7219 !rdev->ops->sched_scan_stop)
7220 return -EOPNOTSUPP;
7221
5fe231e8 7222 return __cfg80211_stop_sched_scan(rdev, false);
807f8a8c
LC
7223}
7224
04f39047
SW
7225static int nl80211_start_radar_detection(struct sk_buff *skb,
7226 struct genl_info *info)
7227{
7228 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7229 struct net_device *dev = info->user_ptr[1];
7230 struct wireless_dev *wdev = dev->ieee80211_ptr;
7231 struct cfg80211_chan_def chandef;
55f7435c 7232 enum nl80211_dfs_regions dfs_region;
31559f35 7233 unsigned int cac_time_ms;
04f39047
SW
7234 int err;
7235
55f7435c
LR
7236 dfs_region = reg_get_dfs_region(wdev->wiphy);
7237 if (dfs_region == NL80211_DFS_UNSET)
7238 return -EINVAL;
7239
04f39047
SW
7240 err = nl80211_parse_chandef(rdev, info, &chandef);
7241 if (err)
7242 return err;
7243
ff311bc1
SW
7244 if (netif_carrier_ok(dev))
7245 return -EBUSY;
7246
04f39047
SW
7247 if (wdev->cac_started)
7248 return -EBUSY;
7249
2beb6dab 7250 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef,
00ec75fc 7251 wdev->iftype);
04f39047
SW
7252 if (err < 0)
7253 return err;
7254
7255 if (err == 0)
7256 return -EINVAL;
7257
fe7c3a1f 7258 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef))
04f39047
SW
7259 return -EINVAL;
7260
7261 if (!rdev->ops->start_radar_detection)
7262 return -EOPNOTSUPP;
7263
31559f35
JD
7264 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef);
7265 if (WARN_ON(!cac_time_ms))
7266 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
7267
a1056b1b 7268 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms);
04f39047 7269 if (!err) {
9e0e2961 7270 wdev->chandef = chandef;
04f39047
SW
7271 wdev->cac_started = true;
7272 wdev->cac_start_time = jiffies;
31559f35 7273 wdev->cac_time_ms = cac_time_ms;
04f39047 7274 }
04f39047
SW
7275 return err;
7276}
7277
16ef1fe2
SW
7278static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
7279{
7280 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7281 struct net_device *dev = info->user_ptr[1];
7282 struct wireless_dev *wdev = dev->ieee80211_ptr;
7283 struct cfg80211_csa_settings params;
7284 /* csa_attrs is defined static to avoid waste of stack size - this
7285 * function is called under RTNL lock, so this should not be a problem.
7286 */
7287 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
16ef1fe2 7288 int err;
ee4bc9e7 7289 bool need_new_beacon = false;
9a774c78 7290 int len, i;
252e07ca 7291 u32 cs_count;
16ef1fe2
SW
7292
7293 if (!rdev->ops->channel_switch ||
7294 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
7295 return -EOPNOTSUPP;
7296
ee4bc9e7
SW
7297 switch (dev->ieee80211_ptr->iftype) {
7298 case NL80211_IFTYPE_AP:
7299 case NL80211_IFTYPE_P2P_GO:
7300 need_new_beacon = true;
7301
7302 /* useless if AP is not running */
7303 if (!wdev->beacon_interval)
1ff79dfa 7304 return -ENOTCONN;
ee4bc9e7
SW
7305 break;
7306 case NL80211_IFTYPE_ADHOC:
1ff79dfa
JB
7307 if (!wdev->ssid_len)
7308 return -ENOTCONN;
7309 break;
c6da674a 7310 case NL80211_IFTYPE_MESH_POINT:
1ff79dfa
JB
7311 if (!wdev->mesh_id_len)
7312 return -ENOTCONN;
ee4bc9e7
SW
7313 break;
7314 default:
16ef1fe2 7315 return -EOPNOTSUPP;
ee4bc9e7 7316 }
16ef1fe2
SW
7317
7318 memset(&params, 0, sizeof(params));
7319
7320 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
7321 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
7322 return -EINVAL;
7323
7324 /* only important for AP, IBSS and mesh create IEs internally */
d0a361a5 7325 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
16ef1fe2
SW
7326 return -EINVAL;
7327
252e07ca
LC
7328 /* Even though the attribute is u32, the specification says
7329 * u8, so let's make sure we don't overflow.
7330 */
7331 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
7332 if (cs_count > 255)
7333 return -EINVAL;
7334
7335 params.count = cs_count;
16ef1fe2 7336
ee4bc9e7
SW
7337 if (!need_new_beacon)
7338 goto skip_beacons;
7339
16ef1fe2
SW
7340 err = nl80211_parse_beacon(info->attrs, &params.beacon_after);
7341 if (err)
7342 return err;
7343
7344 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX,
7345 info->attrs[NL80211_ATTR_CSA_IES],
7346 nl80211_policy);
7347 if (err)
7348 return err;
7349
7350 err = nl80211_parse_beacon(csa_attrs, &params.beacon_csa);
7351 if (err)
7352 return err;
7353
7354 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
7355 return -EINVAL;
7356
9a774c78
AO
7357 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
7358 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
7359 return -EINVAL;
7360
9a774c78
AO
7361 params.n_counter_offsets_beacon = len / sizeof(u16);
7362 if (rdev->wiphy.max_num_csa_counters &&
7363 (params.n_counter_offsets_beacon >
7364 rdev->wiphy.max_num_csa_counters))
16ef1fe2
SW
7365 return -EINVAL;
7366
9a774c78
AO
7367 params.counter_offsets_beacon =
7368 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
7369
7370 /* sanity checks - counters should fit and be the same */
7371 for (i = 0; i < params.n_counter_offsets_beacon; i++) {
7372 u16 offset = params.counter_offsets_beacon[i];
7373
7374 if (offset >= params.beacon_csa.tail_len)
7375 return -EINVAL;
7376
7377 if (params.beacon_csa.tail[offset] != params.count)
7378 return -EINVAL;
7379 }
7380
16ef1fe2 7381 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
9a774c78
AO
7382 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
7383 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
7384 return -EINVAL;
7385
9a774c78
AO
7386 params.n_counter_offsets_presp = len / sizeof(u16);
7387 if (rdev->wiphy.max_num_csa_counters &&
ad5987b4 7388 (params.n_counter_offsets_presp >
9a774c78 7389 rdev->wiphy.max_num_csa_counters))
16ef1fe2 7390 return -EINVAL;
9a774c78
AO
7391
7392 params.counter_offsets_presp =
7393 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
7394
7395 /* sanity checks - counters should fit and be the same */
7396 for (i = 0; i < params.n_counter_offsets_presp; i++) {
7397 u16 offset = params.counter_offsets_presp[i];
7398
7399 if (offset >= params.beacon_csa.probe_resp_len)
7400 return -EINVAL;
7401
7402 if (params.beacon_csa.probe_resp[offset] !=
7403 params.count)
7404 return -EINVAL;
7405 }
16ef1fe2
SW
7406 }
7407
ee4bc9e7 7408skip_beacons:
16ef1fe2
SW
7409 err = nl80211_parse_chandef(rdev, info, &params.chandef);
7410 if (err)
7411 return err;
7412
923b352f
AN
7413 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
7414 wdev->iftype))
16ef1fe2
SW
7415 return -EINVAL;
7416
2beb6dab
LC
7417 err = cfg80211_chandef_dfs_required(wdev->wiphy,
7418 &params.chandef,
7419 wdev->iftype);
7420 if (err < 0)
7421 return err;
7422
dcc6c2f5 7423 if (err > 0)
2beb6dab 7424 params.radar_required = true;
16ef1fe2 7425
16ef1fe2
SW
7426 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
7427 params.block_tx = true;
7428
c56589ed
SW
7429 wdev_lock(wdev);
7430 err = rdev_channel_switch(rdev, dev, &params);
7431 wdev_unlock(wdev);
7432
7433 return err;
16ef1fe2
SW
7434}
7435
9720bb3a
JB
7436static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
7437 u32 seq, int flags,
2a519311 7438 struct cfg80211_registered_device *rdev,
48ab905d
JB
7439 struct wireless_dev *wdev,
7440 struct cfg80211_internal_bss *intbss)
2a519311 7441{
48ab905d 7442 struct cfg80211_bss *res = &intbss->pub;
9caf0364 7443 const struct cfg80211_bss_ies *ies;
2a519311
JB
7444 void *hdr;
7445 struct nlattr *bss;
48ab905d
JB
7446
7447 ASSERT_WDEV_LOCK(wdev);
2a519311 7448
15e47304 7449 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
7450 NL80211_CMD_NEW_SCAN_RESULTS);
7451 if (!hdr)
7452 return -1;
7453
9720bb3a
JB
7454 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
7455
97990a06
JB
7456 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
7457 goto nla_put_failure;
7458 if (wdev->netdev &&
9360ffd1
DM
7459 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
7460 goto nla_put_failure;
2dad624e
ND
7461 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
7462 NL80211_ATTR_PAD))
97990a06 7463 goto nla_put_failure;
2a519311
JB
7464
7465 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
7466 if (!bss)
7467 goto nla_put_failure;
9360ffd1 7468 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 7469 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 7470 goto nla_put_failure;
9caf0364
JB
7471
7472 rcu_read_lock();
0e227084
JB
7473 /* indicate whether we have probe response data or not */
7474 if (rcu_access_pointer(res->proberesp_ies) &&
7475 nla_put_flag(msg, NL80211_BSS_PRESP_DATA))
7476 goto fail_unlock_rcu;
7477
7478 /* this pointer prefers to be pointed to probe response data
7479 * but is always valid
7480 */
9caf0364 7481 ies = rcu_dereference(res->ies);
8cef2c9d 7482 if (ies) {
2dad624e
ND
7483 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf,
7484 NL80211_BSS_PAD))
8cef2c9d 7485 goto fail_unlock_rcu;
8cef2c9d
JB
7486 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
7487 ies->len, ies->data))
7488 goto fail_unlock_rcu;
9caf0364 7489 }
0e227084
JB
7490
7491 /* and this pointer is always (unless driver didn't know) beacon data */
9caf0364 7492 ies = rcu_dereference(res->beacon_ies);
0e227084 7493 if (ies && ies->from_beacon) {
2dad624e
ND
7494 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf,
7495 NL80211_BSS_PAD))
8cef2c9d
JB
7496 goto fail_unlock_rcu;
7497 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
7498 ies->len, ies->data))
7499 goto fail_unlock_rcu;
9caf0364
JB
7500 }
7501 rcu_read_unlock();
7502
9360ffd1
DM
7503 if (res->beacon_interval &&
7504 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
7505 goto nla_put_failure;
7506 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
7507 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
dcd6eac1 7508 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
7509 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
7510 jiffies_to_msecs(jiffies - intbss->ts)))
7511 goto nla_put_failure;
2a519311 7512
1d76250b
AS
7513 if (intbss->parent_tsf &&
7514 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF,
7515 intbss->parent_tsf, NL80211_BSS_PAD) ||
7516 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN,
7517 intbss->parent_bssid)))
7518 goto nla_put_failure;
7519
6e19bc4b 7520 if (intbss->ts_boottime &&
2dad624e
ND
7521 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME,
7522 intbss->ts_boottime, NL80211_BSS_PAD))
6e19bc4b
DS
7523 goto nla_put_failure;
7524
77965c97 7525 switch (rdev->wiphy.signal_type) {
2a519311 7526 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
7527 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
7528 goto nla_put_failure;
2a519311
JB
7529 break;
7530 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
7531 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
7532 goto nla_put_failure;
2a519311
JB
7533 break;
7534 default:
7535 break;
7536 }
7537
48ab905d 7538 switch (wdev->iftype) {
074ac8df 7539 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 7540 case NL80211_IFTYPE_STATION:
9360ffd1
DM
7541 if (intbss == wdev->current_bss &&
7542 nla_put_u32(msg, NL80211_BSS_STATUS,
7543 NL80211_BSS_STATUS_ASSOCIATED))
7544 goto nla_put_failure;
48ab905d
JB
7545 break;
7546 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
7547 if (intbss == wdev->current_bss &&
7548 nla_put_u32(msg, NL80211_BSS_STATUS,
7549 NL80211_BSS_STATUS_IBSS_JOINED))
7550 goto nla_put_failure;
48ab905d
JB
7551 break;
7552 default:
7553 break;
7554 }
7555
2a519311
JB
7556 nla_nest_end(msg, bss);
7557
053c095a
JB
7558 genlmsg_end(msg, hdr);
7559 return 0;
2a519311 7560
8cef2c9d
JB
7561 fail_unlock_rcu:
7562 rcu_read_unlock();
2a519311
JB
7563 nla_put_failure:
7564 genlmsg_cancel(msg, hdr);
7565 return -EMSGSIZE;
7566}
7567
97990a06 7568static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 7569{
48ab905d 7570 struct cfg80211_registered_device *rdev;
2a519311 7571 struct cfg80211_internal_bss *scan;
48ab905d 7572 struct wireless_dev *wdev;
97990a06 7573 int start = cb->args[2], idx = 0;
2a519311
JB
7574 int err;
7575
97990a06 7576 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
7577 if (err)
7578 return err;
2a519311 7579
48ab905d
JB
7580 wdev_lock(wdev);
7581 spin_lock_bh(&rdev->bss_lock);
7582 cfg80211_bss_expire(rdev);
7583
9720bb3a
JB
7584 cb->seq = rdev->bss_generation;
7585
48ab905d 7586 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
7587 if (++idx <= start)
7588 continue;
9720bb3a 7589 if (nl80211_send_bss(skb, cb,
2a519311 7590 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 7591 rdev, wdev, scan) < 0) {
2a519311 7592 idx--;
67748893 7593 break;
2a519311
JB
7594 }
7595 }
7596
48ab905d
JB
7597 spin_unlock_bh(&rdev->bss_lock);
7598 wdev_unlock(wdev);
2a519311 7599
97990a06
JB
7600 cb->args[2] = idx;
7601 nl80211_finish_wdev_dump(rdev);
2a519311 7602
67748893 7603 return skb->len;
2a519311
JB
7604}
7605
15e47304 7606static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
11f78ac3
JB
7607 int flags, struct net_device *dev,
7608 bool allow_radio_stats,
7609 struct survey_info *survey)
61fa713c
HS
7610{
7611 void *hdr;
7612 struct nlattr *infoattr;
7613
11f78ac3
JB
7614 /* skip radio stats if userspace didn't request them */
7615 if (!survey->channel && !allow_radio_stats)
7616 return 0;
7617
15e47304 7618 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
7619 NL80211_CMD_NEW_SURVEY_RESULTS);
7620 if (!hdr)
7621 return -ENOMEM;
7622
9360ffd1
DM
7623 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
7624 goto nla_put_failure;
61fa713c
HS
7625
7626 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
7627 if (!infoattr)
7628 goto nla_put_failure;
7629
11f78ac3
JB
7630 if (survey->channel &&
7631 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
9360ffd1
DM
7632 survey->channel->center_freq))
7633 goto nla_put_failure;
7634
7635 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
7636 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
7637 goto nla_put_failure;
7638 if ((survey->filled & SURVEY_INFO_IN_USE) &&
7639 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
7640 goto nla_put_failure;
4ed20beb 7641 if ((survey->filled & SURVEY_INFO_TIME) &&
2dad624e
ND
7642 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME,
7643 survey->time, NL80211_SURVEY_INFO_PAD))
9360ffd1 7644 goto nla_put_failure;
4ed20beb 7645 if ((survey->filled & SURVEY_INFO_TIME_BUSY) &&
2dad624e
ND
7646 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY,
7647 survey->time_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 7648 goto nla_put_failure;
4ed20beb 7649 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) &&
2dad624e
ND
7650 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY,
7651 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 7652 goto nla_put_failure;
4ed20beb 7653 if ((survey->filled & SURVEY_INFO_TIME_RX) &&
2dad624e
ND
7654 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX,
7655 survey->time_rx, NL80211_SURVEY_INFO_PAD))
9360ffd1 7656 goto nla_put_failure;
4ed20beb 7657 if ((survey->filled & SURVEY_INFO_TIME_TX) &&
2dad624e
ND
7658 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX,
7659 survey->time_tx, NL80211_SURVEY_INFO_PAD))
9360ffd1 7660 goto nla_put_failure;
052536ab 7661 if ((survey->filled & SURVEY_INFO_TIME_SCAN) &&
2dad624e
ND
7662 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN,
7663 survey->time_scan, NL80211_SURVEY_INFO_PAD))
052536ab 7664 goto nla_put_failure;
61fa713c
HS
7665
7666 nla_nest_end(msg, infoattr);
7667
053c095a
JB
7668 genlmsg_end(msg, hdr);
7669 return 0;
61fa713c
HS
7670
7671 nla_put_failure:
7672 genlmsg_cancel(msg, hdr);
7673 return -EMSGSIZE;
7674}
7675
11f78ac3 7676static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb)
61fa713c
HS
7677{
7678 struct survey_info survey;
1b8ec87a 7679 struct cfg80211_registered_device *rdev;
97990a06
JB
7680 struct wireless_dev *wdev;
7681 int survey_idx = cb->args[2];
61fa713c 7682 int res;
11f78ac3 7683 bool radio_stats;
61fa713c 7684
1b8ec87a 7685 res = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
7686 if (res)
7687 return res;
61fa713c 7688
11f78ac3
JB
7689 /* prepare_wdev_dump parsed the attributes */
7690 radio_stats = nl80211_fam.attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS];
7691
97990a06
JB
7692 if (!wdev->netdev) {
7693 res = -EINVAL;
7694 goto out_err;
7695 }
7696
1b8ec87a 7697 if (!rdev->ops->dump_survey) {
61fa713c
HS
7698 res = -EOPNOTSUPP;
7699 goto out_err;
7700 }
7701
7702 while (1) {
1b8ec87a 7703 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
7704 if (res == -ENOENT)
7705 break;
7706 if (res)
7707 goto out_err;
7708
11f78ac3
JB
7709 /* don't send disabled channels, but do send non-channel data */
7710 if (survey.channel &&
7711 survey.channel->flags & IEEE80211_CHAN_DISABLED) {
180cdc79
LR
7712 survey_idx++;
7713 continue;
7714 }
7715
61fa713c 7716 if (nl80211_send_survey(skb,
15e47304 7717 NETLINK_CB(cb->skb).portid,
61fa713c 7718 cb->nlh->nlmsg_seq, NLM_F_MULTI,
11f78ac3 7719 wdev->netdev, radio_stats, &survey) < 0)
61fa713c
HS
7720 goto out;
7721 survey_idx++;
7722 }
7723
7724 out:
97990a06 7725 cb->args[2] = survey_idx;
61fa713c
HS
7726 res = skb->len;
7727 out_err:
1b8ec87a 7728 nl80211_finish_wdev_dump(rdev);
61fa713c
HS
7729 return res;
7730}
7731
b23aa676
SO
7732static bool nl80211_valid_wpa_versions(u32 wpa_versions)
7733{
7734 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
7735 NL80211_WPA_VERSION_2));
7736}
7737
636a5d36
JM
7738static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
7739{
4c476991
JB
7740 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7741 struct net_device *dev = info->user_ptr[1];
19957bb3 7742 struct ieee80211_channel *chan;
11b6b5a4
JM
7743 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL;
7744 int err, ssid_len, ie_len = 0, auth_data_len = 0;
19957bb3 7745 enum nl80211_auth_type auth_type;
fffd0934 7746 struct key_parse key;
d5cdfacb 7747 bool local_state_change;
636a5d36 7748
f4a11bb0
JB
7749 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7750 return -EINVAL;
7751
7752 if (!info->attrs[NL80211_ATTR_MAC])
7753 return -EINVAL;
7754
1778092e
JM
7755 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
7756 return -EINVAL;
7757
19957bb3
JB
7758 if (!info->attrs[NL80211_ATTR_SSID])
7759 return -EINVAL;
7760
7761 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
7762 return -EINVAL;
7763
fffd0934
JB
7764 err = nl80211_parse_key(info, &key);
7765 if (err)
7766 return err;
7767
7768 if (key.idx >= 0) {
e31b8213
JB
7769 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
7770 return -EINVAL;
fffd0934
JB
7771 if (!key.p.key || !key.p.key_len)
7772 return -EINVAL;
7773 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
7774 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
7775 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
7776 key.p.key_len != WLAN_KEY_LEN_WEP104))
7777 return -EINVAL;
b6b5555b 7778 if (key.idx > 3)
fffd0934
JB
7779 return -EINVAL;
7780 } else {
7781 key.p.key_len = 0;
7782 key.p.key = NULL;
7783 }
7784
afea0b7a
JB
7785 if (key.idx >= 0) {
7786 int i;
7787 bool ok = false;
7a087e74 7788
afea0b7a
JB
7789 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
7790 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
7791 ok = true;
7792 break;
7793 }
7794 }
4c476991
JB
7795 if (!ok)
7796 return -EINVAL;
afea0b7a
JB
7797 }
7798
4c476991
JB
7799 if (!rdev->ops->auth)
7800 return -EOPNOTSUPP;
636a5d36 7801
074ac8df 7802 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7803 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7804 return -EOPNOTSUPP;
eec60b03 7805
19957bb3 7806 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
664834de
JM
7807 chan = nl80211_get_valid_chan(&rdev->wiphy,
7808 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
7809 if (!chan)
4c476991 7810 return -EINVAL;
636a5d36 7811
19957bb3
JB
7812 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
7813 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
7814
7815 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
7816 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7817 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
7818 }
7819
19957bb3 7820 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 7821 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 7822 return -EINVAL;
636a5d36 7823
63181060
JM
7824 if ((auth_type == NL80211_AUTHTYPE_SAE ||
7825 auth_type == NL80211_AUTHTYPE_FILS_SK ||
7826 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
7827 auth_type == NL80211_AUTHTYPE_FILS_PK) &&
11b6b5a4 7828 !info->attrs[NL80211_ATTR_AUTH_DATA])
e39e5b5e
JM
7829 return -EINVAL;
7830
11b6b5a4 7831 if (info->attrs[NL80211_ATTR_AUTH_DATA]) {
63181060
JM
7832 if (auth_type != NL80211_AUTHTYPE_SAE &&
7833 auth_type != NL80211_AUTHTYPE_FILS_SK &&
7834 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS &&
7835 auth_type != NL80211_AUTHTYPE_FILS_PK)
e39e5b5e 7836 return -EINVAL;
11b6b5a4
JM
7837 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]);
7838 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]);
e39e5b5e 7839 /* need to include at least Auth Transaction and Status Code */
11b6b5a4 7840 if (auth_data_len < 4)
e39e5b5e
JM
7841 return -EINVAL;
7842 }
7843
d5cdfacb
JM
7844 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
7845
95de817b
JB
7846 /*
7847 * Since we no longer track auth state, ignore
7848 * requests to only change local state.
7849 */
7850 if (local_state_change)
7851 return 0;
7852
91bf9b26
JB
7853 wdev_lock(dev->ieee80211_ptr);
7854 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
7855 ssid, ssid_len, ie, ie_len,
7856 key.p.key, key.p.key_len, key.idx,
11b6b5a4 7857 auth_data, auth_data_len);
91bf9b26
JB
7858 wdev_unlock(dev->ieee80211_ptr);
7859 return err;
636a5d36
JM
7860}
7861
c0692b8f
JB
7862static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
7863 struct genl_info *info,
3dc27d25
JB
7864 struct cfg80211_crypto_settings *settings,
7865 int cipher_limit)
b23aa676 7866{
c0b2bbd8
JB
7867 memset(settings, 0, sizeof(*settings));
7868
b23aa676
SO
7869 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
7870
c0692b8f
JB
7871 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
7872 u16 proto;
7a087e74 7873
c0692b8f
JB
7874 proto = nla_get_u16(
7875 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
7876 settings->control_port_ethertype = cpu_to_be16(proto);
7877 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
7878 proto != ETH_P_PAE)
7879 return -EINVAL;
7880 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
7881 settings->control_port_no_encrypt = true;
7882 } else
7883 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
7884
b23aa676
SO
7885 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
7886 void *data;
7887 int len, i;
7888
7889 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
7890 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
7891 settings->n_ciphers_pairwise = len / sizeof(u32);
7892
7893 if (len % sizeof(u32))
7894 return -EINVAL;
7895
3dc27d25 7896 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
7897 return -EINVAL;
7898
7899 memcpy(settings->ciphers_pairwise, data, len);
7900
7901 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
7902 if (!cfg80211_supported_cipher_suite(
7903 &rdev->wiphy,
b23aa676
SO
7904 settings->ciphers_pairwise[i]))
7905 return -EINVAL;
7906 }
7907
7908 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
7909 settings->cipher_group =
7910 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
7911 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
7912 settings->cipher_group))
b23aa676
SO
7913 return -EINVAL;
7914 }
7915
7916 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
7917 settings->wpa_versions =
7918 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
7919 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
7920 return -EINVAL;
7921 }
7922
7923 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
7924 void *data;
6d30240e 7925 int len;
b23aa676
SO
7926
7927 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
7928 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
7929 settings->n_akm_suites = len / sizeof(u32);
7930
7931 if (len % sizeof(u32))
7932 return -EINVAL;
7933
1b9ca027
JM
7934 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
7935 return -EINVAL;
7936
b23aa676 7937 memcpy(settings->akm_suites, data, len);
b23aa676
SO
7938 }
7939
7940 return 0;
7941}
7942
636a5d36
JM
7943static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
7944{
4c476991
JB
7945 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7946 struct net_device *dev = info->user_ptr[1];
f444de05 7947 struct ieee80211_channel *chan;
f62fab73
JB
7948 struct cfg80211_assoc_request req = {};
7949 const u8 *bssid, *ssid;
7950 int err, ssid_len = 0;
636a5d36 7951
f4a11bb0
JB
7952 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
7953 return -EINVAL;
7954
7955 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
7956 !info->attrs[NL80211_ATTR_SSID] ||
7957 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
7958 return -EINVAL;
7959
4c476991
JB
7960 if (!rdev->ops->assoc)
7961 return -EOPNOTSUPP;
636a5d36 7962
074ac8df 7963 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7964 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7965 return -EOPNOTSUPP;
eec60b03 7966
19957bb3 7967 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 7968
664834de
JM
7969 chan = nl80211_get_valid_chan(&rdev->wiphy,
7970 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
7971 if (!chan)
4c476991 7972 return -EINVAL;
636a5d36 7973
19957bb3
JB
7974 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
7975 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
7976
7977 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
7978 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7979 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
7980 }
7981
dc6382ce 7982 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 7983 enum nl80211_mfp mfp =
dc6382ce 7984 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 7985 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 7986 req.use_mfp = true;
4c476991
JB
7987 else if (mfp != NL80211_MFP_NO)
7988 return -EINVAL;
dc6382ce
JM
7989 }
7990
3e5d7649 7991 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 7992 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 7993
7e7c8926 7994 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 7995 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
7996
7997 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
7998 memcpy(&req.ht_capa_mask,
7999 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
8000 sizeof(req.ht_capa_mask));
7e7c8926
BG
8001
8002 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 8003 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 8004 return -EINVAL;
f62fab73
JB
8005 memcpy(&req.ht_capa,
8006 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
8007 sizeof(req.ht_capa));
7e7c8926
BG
8008 }
8009
ee2aca34 8010 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 8011 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
8012
8013 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
8014 memcpy(&req.vht_capa_mask,
8015 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
8016 sizeof(req.vht_capa_mask));
ee2aca34
JB
8017
8018 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 8019 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 8020 return -EINVAL;
f62fab73
JB
8021 memcpy(&req.vht_capa,
8022 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
8023 sizeof(req.vht_capa));
ee2aca34
JB
8024 }
8025
bab5ab7d 8026 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
8027 if (!((rdev->wiphy.features &
8028 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
8029 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
8030 !wiphy_ext_feature_isset(&rdev->wiphy,
8031 NL80211_EXT_FEATURE_RRM))
bab5ab7d
AK
8032 return -EINVAL;
8033 req.flags |= ASSOC_REQ_USE_RRM;
8034 }
8035
f62fab73 8036 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
8037 if (!err) {
8038 wdev_lock(dev->ieee80211_ptr);
f62fab73
JB
8039 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
8040 ssid, ssid_len, &req);
91bf9b26
JB
8041 wdev_unlock(dev->ieee80211_ptr);
8042 }
636a5d36 8043
636a5d36
JM
8044 return err;
8045}
8046
8047static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
8048{
4c476991
JB
8049 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8050 struct net_device *dev = info->user_ptr[1];
19957bb3 8051 const u8 *ie = NULL, *bssid;
91bf9b26 8052 int ie_len = 0, err;
19957bb3 8053 u16 reason_code;
d5cdfacb 8054 bool local_state_change;
636a5d36 8055
f4a11bb0
JB
8056 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8057 return -EINVAL;
8058
8059 if (!info->attrs[NL80211_ATTR_MAC])
8060 return -EINVAL;
8061
8062 if (!info->attrs[NL80211_ATTR_REASON_CODE])
8063 return -EINVAL;
8064
4c476991
JB
8065 if (!rdev->ops->deauth)
8066 return -EOPNOTSUPP;
636a5d36 8067
074ac8df 8068 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8069 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8070 return -EOPNOTSUPP;
eec60b03 8071
19957bb3 8072 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 8073
19957bb3
JB
8074 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
8075 if (reason_code == 0) {
f4a11bb0 8076 /* Reason Code 0 is reserved */
4c476991 8077 return -EINVAL;
255e737e 8078 }
636a5d36
JM
8079
8080 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
8081 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8082 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8083 }
8084
d5cdfacb
JM
8085 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
8086
91bf9b26
JB
8087 wdev_lock(dev->ieee80211_ptr);
8088 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
8089 local_state_change);
8090 wdev_unlock(dev->ieee80211_ptr);
8091 return err;
636a5d36
JM
8092}
8093
8094static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
8095{
4c476991
JB
8096 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8097 struct net_device *dev = info->user_ptr[1];
19957bb3 8098 const u8 *ie = NULL, *bssid;
91bf9b26 8099 int ie_len = 0, err;
19957bb3 8100 u16 reason_code;
d5cdfacb 8101 bool local_state_change;
636a5d36 8102
f4a11bb0
JB
8103 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8104 return -EINVAL;
8105
8106 if (!info->attrs[NL80211_ATTR_MAC])
8107 return -EINVAL;
8108
8109 if (!info->attrs[NL80211_ATTR_REASON_CODE])
8110 return -EINVAL;
8111
4c476991
JB
8112 if (!rdev->ops->disassoc)
8113 return -EOPNOTSUPP;
636a5d36 8114
074ac8df 8115 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8116 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8117 return -EOPNOTSUPP;
eec60b03 8118
19957bb3 8119 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 8120
19957bb3
JB
8121 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
8122 if (reason_code == 0) {
f4a11bb0 8123 /* Reason Code 0 is reserved */
4c476991 8124 return -EINVAL;
255e737e 8125 }
636a5d36
JM
8126
8127 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
8128 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8129 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8130 }
8131
d5cdfacb
JM
8132 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
8133
91bf9b26
JB
8134 wdev_lock(dev->ieee80211_ptr);
8135 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
8136 local_state_change);
8137 wdev_unlock(dev->ieee80211_ptr);
8138 return err;
636a5d36
JM
8139}
8140
dd5b4cc7
FF
8141static bool
8142nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
57fbcce3 8143 int mcast_rate[NUM_NL80211_BANDS],
dd5b4cc7
FF
8144 int rateval)
8145{
8146 struct wiphy *wiphy = &rdev->wiphy;
8147 bool found = false;
8148 int band, i;
8149
57fbcce3 8150 for (band = 0; band < NUM_NL80211_BANDS; band++) {
dd5b4cc7
FF
8151 struct ieee80211_supported_band *sband;
8152
8153 sband = wiphy->bands[band];
8154 if (!sband)
8155 continue;
8156
8157 for (i = 0; i < sband->n_bitrates; i++) {
8158 if (sband->bitrates[i].bitrate == rateval) {
8159 mcast_rate[band] = i + 1;
8160 found = true;
8161 break;
8162 }
8163 }
8164 }
8165
8166 return found;
8167}
8168
04a773ad
JB
8169static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
8170{
4c476991
JB
8171 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8172 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
8173 struct cfg80211_ibss_params ibss;
8174 struct wiphy *wiphy;
fffd0934 8175 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
8176 int err;
8177
8e30bc55
JB
8178 memset(&ibss, 0, sizeof(ibss));
8179
04a773ad
JB
8180 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8181 return -EINVAL;
8182
683b6d3b 8183 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
8184 !nla_len(info->attrs[NL80211_ATTR_SSID]))
8185 return -EINVAL;
8186
8e30bc55
JB
8187 ibss.beacon_interval = 100;
8188
12d20fc9 8189 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL])
8e30bc55
JB
8190 ibss.beacon_interval =
8191 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 8192
0c317a02
PK
8193 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC,
8194 ibss.beacon_interval);
12d20fc9
PK
8195 if (err)
8196 return err;
8e30bc55 8197
4c476991
JB
8198 if (!rdev->ops->join_ibss)
8199 return -EOPNOTSUPP;
04a773ad 8200
4c476991
JB
8201 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
8202 return -EOPNOTSUPP;
04a773ad 8203
79c97e97 8204 wiphy = &rdev->wiphy;
04a773ad 8205
39193498 8206 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 8207 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
8208
8209 if (!is_valid_ether_addr(ibss.bssid))
8210 return -EINVAL;
8211 }
04a773ad
JB
8212 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
8213 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
8214
8215 if (info->attrs[NL80211_ATTR_IE]) {
8216 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8217 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
8218 }
8219
683b6d3b
JB
8220 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
8221 if (err)
8222 return err;
04a773ad 8223
174e0cd2
IP
8224 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef,
8225 NL80211_IFTYPE_ADHOC))
54858ee5
AS
8226 return -EINVAL;
8227
2f301ab2 8228 switch (ibss.chandef.width) {
bf372645
SW
8229 case NL80211_CHAN_WIDTH_5:
8230 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
8231 case NL80211_CHAN_WIDTH_20_NOHT:
8232 break;
8233 case NL80211_CHAN_WIDTH_20:
8234 case NL80211_CHAN_WIDTH_40:
ffc11991
JD
8235 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
8236 return -EINVAL;
8237 break;
8238 case NL80211_CHAN_WIDTH_80:
8239 case NL80211_CHAN_WIDTH_80P80:
8240 case NL80211_CHAN_WIDTH_160:
8241 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
8242 return -EINVAL;
8243 if (!wiphy_ext_feature_isset(&rdev->wiphy,
8244 NL80211_EXT_FEATURE_VHT_IBSS))
8245 return -EINVAL;
8246 break;
2f301ab2 8247 default:
c04d6150 8248 return -EINVAL;
2f301ab2 8249 }
db9c64cf 8250
04a773ad 8251 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
8252 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
8253
fbd2c8dc
TP
8254 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
8255 u8 *rates =
8256 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8257 int n_rates =
8258 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8259 struct ieee80211_supported_band *sband =
683b6d3b 8260 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 8261
34850ab2
JB
8262 err = ieee80211_get_ratemask(sband, rates, n_rates,
8263 &ibss.basic_rates);
8264 if (err)
8265 return err;
fbd2c8dc 8266 }
dd5b4cc7 8267
803768f5
SW
8268 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
8269 memcpy(&ibss.ht_capa_mask,
8270 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
8271 sizeof(ibss.ht_capa_mask));
8272
8273 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
8274 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
8275 return -EINVAL;
8276 memcpy(&ibss.ht_capa,
8277 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
8278 sizeof(ibss.ht_capa));
8279 }
8280
dd5b4cc7
FF
8281 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
8282 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
8283 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
8284 return -EINVAL;
fbd2c8dc 8285
4c476991 8286 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
8287 bool no_ht = false;
8288
4c476991 8289 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
8290 info->attrs[NL80211_ATTR_KEYS],
8291 &no_ht);
4c476991
JB
8292 if (IS_ERR(connkeys))
8293 return PTR_ERR(connkeys);
de7044ee 8294
3d9d1d66
JB
8295 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
8296 no_ht) {
5e950a78 8297 kzfree(connkeys);
de7044ee
SM
8298 return -EINVAL;
8299 }
4c476991 8300 }
04a773ad 8301
267335d6
AQ
8302 ibss.control_port =
8303 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
8304
5336fa88
SW
8305 ibss.userspace_handles_dfs =
8306 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
8307
4c476991 8308 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934 8309 if (err)
b47f610b 8310 kzfree(connkeys);
04a773ad
JB
8311 return err;
8312}
8313
8314static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
8315{
4c476991
JB
8316 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8317 struct net_device *dev = info->user_ptr[1];
04a773ad 8318
4c476991
JB
8319 if (!rdev->ops->leave_ibss)
8320 return -EOPNOTSUPP;
04a773ad 8321
4c476991
JB
8322 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
8323 return -EOPNOTSUPP;
04a773ad 8324
4c476991 8325 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
8326}
8327
f4e583c8
AQ
8328static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
8329{
8330 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8331 struct net_device *dev = info->user_ptr[1];
57fbcce3 8332 int mcast_rate[NUM_NL80211_BANDS];
f4e583c8
AQ
8333 u32 nla_rate;
8334 int err;
8335
8336 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
876dc930
BVB
8337 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
8338 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB)
f4e583c8
AQ
8339 return -EOPNOTSUPP;
8340
8341 if (!rdev->ops->set_mcast_rate)
8342 return -EOPNOTSUPP;
8343
8344 memset(mcast_rate, 0, sizeof(mcast_rate));
8345
8346 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
8347 return -EINVAL;
8348
8349 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
8350 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
8351 return -EINVAL;
8352
a1056b1b 8353 err = rdev_set_mcast_rate(rdev, dev, mcast_rate);
f4e583c8
AQ
8354
8355 return err;
8356}
8357
ad7e718c
JB
8358static struct sk_buff *
8359__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
6c09e791
AK
8360 struct wireless_dev *wdev, int approxlen,
8361 u32 portid, u32 seq, enum nl80211_commands cmd,
567ffc35
JB
8362 enum nl80211_attrs attr,
8363 const struct nl80211_vendor_cmd_info *info,
8364 gfp_t gfp)
ad7e718c
JB
8365{
8366 struct sk_buff *skb;
8367 void *hdr;
8368 struct nlattr *data;
8369
8370 skb = nlmsg_new(approxlen + 100, gfp);
8371 if (!skb)
8372 return NULL;
8373
8374 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
8375 if (!hdr) {
8376 kfree_skb(skb);
8377 return NULL;
8378 }
8379
8380 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
8381 goto nla_put_failure;
567ffc35
JB
8382
8383 if (info) {
8384 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
8385 info->vendor_id))
8386 goto nla_put_failure;
8387 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
8388 info->subcmd))
8389 goto nla_put_failure;
8390 }
8391
6c09e791 8392 if (wdev) {
2dad624e
ND
8393 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
8394 wdev_id(wdev), NL80211_ATTR_PAD))
6c09e791
AK
8395 goto nla_put_failure;
8396 if (wdev->netdev &&
8397 nla_put_u32(skb, NL80211_ATTR_IFINDEX,
8398 wdev->netdev->ifindex))
8399 goto nla_put_failure;
8400 }
8401
ad7e718c 8402 data = nla_nest_start(skb, attr);
76e1fb4b
JB
8403 if (!data)
8404 goto nla_put_failure;
ad7e718c
JB
8405
8406 ((void **)skb->cb)[0] = rdev;
8407 ((void **)skb->cb)[1] = hdr;
8408 ((void **)skb->cb)[2] = data;
8409
8410 return skb;
8411
8412 nla_put_failure:
8413 kfree_skb(skb);
8414 return NULL;
8415}
f4e583c8 8416
e03ad6ea 8417struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
6c09e791 8418 struct wireless_dev *wdev,
e03ad6ea
JB
8419 enum nl80211_commands cmd,
8420 enum nl80211_attrs attr,
8421 int vendor_event_idx,
8422 int approxlen, gfp_t gfp)
8423{
f26cbf40 8424 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
e03ad6ea
JB
8425 const struct nl80211_vendor_cmd_info *info;
8426
8427 switch (cmd) {
8428 case NL80211_CMD_TESTMODE:
8429 if (WARN_ON(vendor_event_idx != -1))
8430 return NULL;
8431 info = NULL;
8432 break;
8433 case NL80211_CMD_VENDOR:
8434 if (WARN_ON(vendor_event_idx < 0 ||
8435 vendor_event_idx >= wiphy->n_vendor_events))
8436 return NULL;
8437 info = &wiphy->vendor_events[vendor_event_idx];
8438 break;
8439 default:
8440 WARN_ON(1);
8441 return NULL;
8442 }
8443
6c09e791 8444 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, 0, 0,
e03ad6ea
JB
8445 cmd, attr, info, gfp);
8446}
8447EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
8448
8449void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
8450{
8451 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
8452 void *hdr = ((void **)skb->cb)[1];
8453 struct nlattr *data = ((void **)skb->cb)[2];
8454 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
8455
bd8c78e7
JB
8456 /* clear CB data for netlink core to own from now on */
8457 memset(skb->cb, 0, sizeof(skb->cb));
8458
e03ad6ea
JB
8459 nla_nest_end(skb, data);
8460 genlmsg_end(skb, hdr);
8461
8462 if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
8463 mcgrp = NL80211_MCGRP_VENDOR;
8464
8465 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0,
8466 mcgrp, gfp);
8467}
8468EXPORT_SYMBOL(__cfg80211_send_event_skb);
8469
aff89a9b 8470#ifdef CONFIG_NL80211_TESTMODE
aff89a9b
JB
8471static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
8472{
4c476991 8473 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
8474 struct wireless_dev *wdev =
8475 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
8476 int err;
8477
fc73f11f
DS
8478 if (!rdev->ops->testmode_cmd)
8479 return -EOPNOTSUPP;
8480
8481 if (IS_ERR(wdev)) {
8482 err = PTR_ERR(wdev);
8483 if (err != -EINVAL)
8484 return err;
8485 wdev = NULL;
8486 } else if (wdev->wiphy != &rdev->wiphy) {
8487 return -EINVAL;
8488 }
8489
aff89a9b
JB
8490 if (!info->attrs[NL80211_ATTR_TESTDATA])
8491 return -EINVAL;
8492
ad7e718c 8493 rdev->cur_cmd_info = info;
fc73f11f 8494 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
8495 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
8496 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
ad7e718c 8497 rdev->cur_cmd_info = NULL;
aff89a9b 8498
aff89a9b
JB
8499 return err;
8500}
8501
71063f0e
WYG
8502static int nl80211_testmode_dump(struct sk_buff *skb,
8503 struct netlink_callback *cb)
8504{
00918d33 8505 struct cfg80211_registered_device *rdev;
71063f0e
WYG
8506 int err;
8507 long phy_idx;
8508 void *data = NULL;
8509 int data_len = 0;
8510
5fe231e8
JB
8511 rtnl_lock();
8512
71063f0e
WYG
8513 if (cb->args[0]) {
8514 /*
8515 * 0 is a valid index, but not valid for args[0],
8516 * so we need to offset by 1.
8517 */
8518 phy_idx = cb->args[0] - 1;
8519 } else {
8520 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
8521 nl80211_fam.attrbuf, nl80211_fam.maxattr,
8522 nl80211_policy);
8523 if (err)
5fe231e8 8524 goto out_err;
00918d33 8525
2bd7e35d
JB
8526 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
8527 nl80211_fam.attrbuf);
8528 if (IS_ERR(rdev)) {
5fe231e8
JB
8529 err = PTR_ERR(rdev);
8530 goto out_err;
00918d33 8531 }
2bd7e35d
JB
8532 phy_idx = rdev->wiphy_idx;
8533 rdev = NULL;
2bd7e35d 8534
71063f0e
WYG
8535 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
8536 cb->args[1] =
8537 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
8538 }
8539
8540 if (cb->args[1]) {
8541 data = nla_data((void *)cb->args[1]);
8542 data_len = nla_len((void *)cb->args[1]);
8543 }
8544
00918d33
JB
8545 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
8546 if (!rdev) {
5fe231e8
JB
8547 err = -ENOENT;
8548 goto out_err;
71063f0e 8549 }
71063f0e 8550
00918d33 8551 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
8552 err = -EOPNOTSUPP;
8553 goto out_err;
8554 }
8555
8556 while (1) {
15e47304 8557 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
8558 cb->nlh->nlmsg_seq, NLM_F_MULTI,
8559 NL80211_CMD_TESTMODE);
8560 struct nlattr *tmdata;
8561
cb35fba3
DC
8562 if (!hdr)
8563 break;
8564
9360ffd1 8565 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
8566 genlmsg_cancel(skb, hdr);
8567 break;
8568 }
8569
8570 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
8571 if (!tmdata) {
8572 genlmsg_cancel(skb, hdr);
8573 break;
8574 }
e35e4d28 8575 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
8576 nla_nest_end(skb, tmdata);
8577
8578 if (err == -ENOBUFS || err == -ENOENT) {
8579 genlmsg_cancel(skb, hdr);
8580 break;
8581 } else if (err) {
8582 genlmsg_cancel(skb, hdr);
8583 goto out_err;
8584 }
8585
8586 genlmsg_end(skb, hdr);
8587 }
8588
8589 err = skb->len;
8590 /* see above */
8591 cb->args[0] = phy_idx + 1;
8592 out_err:
5fe231e8 8593 rtnl_unlock();
71063f0e
WYG
8594 return err;
8595}
aff89a9b
JB
8596#endif
8597
b23aa676
SO
8598static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
8599{
4c476991
JB
8600 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8601 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
8602 struct cfg80211_connect_params connect;
8603 struct wiphy *wiphy;
fffd0934 8604 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
8605 int err;
8606
8607 memset(&connect, 0, sizeof(connect));
8608
8609 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8610 return -EINVAL;
8611
8612 if (!info->attrs[NL80211_ATTR_SSID] ||
8613 !nla_len(info->attrs[NL80211_ATTR_SSID]))
8614 return -EINVAL;
8615
8616 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
8617 connect.auth_type =
8618 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
8619 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
8620 NL80211_CMD_CONNECT))
b23aa676
SO
8621 return -EINVAL;
8622 } else
8623 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
8624
8625 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
8626
c0692b8f 8627 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 8628 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
8629 if (err)
8630 return err;
b23aa676 8631
074ac8df 8632 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8633 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8634 return -EOPNOTSUPP;
b23aa676 8635
79c97e97 8636 wiphy = &rdev->wiphy;
b23aa676 8637
4486ea98
BS
8638 connect.bg_scan_period = -1;
8639 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
8640 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
8641 connect.bg_scan_period =
8642 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
8643 }
8644
b23aa676
SO
8645 if (info->attrs[NL80211_ATTR_MAC])
8646 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1df4a510
JM
8647 else if (info->attrs[NL80211_ATTR_MAC_HINT])
8648 connect.bssid_hint =
8649 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
b23aa676
SO
8650 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
8651 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
8652
8653 if (info->attrs[NL80211_ATTR_IE]) {
8654 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8655 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
8656 }
8657
cee00a95
JM
8658 if (info->attrs[NL80211_ATTR_USE_MFP]) {
8659 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
8660 if (connect.mfp != NL80211_MFP_REQUIRED &&
8661 connect.mfp != NL80211_MFP_NO)
8662 return -EINVAL;
8663 } else {
8664 connect.mfp = NL80211_MFP_NO;
8665 }
8666
ba6fbacf
JM
8667 if (info->attrs[NL80211_ATTR_PREV_BSSID])
8668 connect.prev_bssid =
8669 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
8670
b23aa676 8671 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
664834de
JM
8672 connect.channel = nl80211_get_valid_chan(
8673 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]);
8674 if (!connect.channel)
1df4a510
JM
8675 return -EINVAL;
8676 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
664834de
JM
8677 connect.channel_hint = nl80211_get_valid_chan(
8678 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
8679 if (!connect.channel_hint)
4c476991 8680 return -EINVAL;
b23aa676
SO
8681 }
8682
fffd0934
JB
8683 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
8684 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 8685 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
8686 if (IS_ERR(connkeys))
8687 return PTR_ERR(connkeys);
fffd0934
JB
8688 }
8689
7e7c8926
BG
8690 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
8691 connect.flags |= ASSOC_REQ_DISABLE_HT;
8692
8693 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
8694 memcpy(&connect.ht_capa_mask,
8695 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
8696 sizeof(connect.ht_capa_mask));
8697
8698 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e 8699 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
b47f610b 8700 kzfree(connkeys);
7e7c8926 8701 return -EINVAL;
b4e4f47e 8702 }
7e7c8926
BG
8703 memcpy(&connect.ht_capa,
8704 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
8705 sizeof(connect.ht_capa));
8706 }
8707
ee2aca34
JB
8708 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
8709 connect.flags |= ASSOC_REQ_DISABLE_VHT;
8710
8711 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
8712 memcpy(&connect.vht_capa_mask,
8713 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
8714 sizeof(connect.vht_capa_mask));
8715
8716 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
8717 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
b47f610b 8718 kzfree(connkeys);
ee2aca34
JB
8719 return -EINVAL;
8720 }
8721 memcpy(&connect.vht_capa,
8722 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
8723 sizeof(connect.vht_capa));
8724 }
8725
bab5ab7d 8726 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
8727 if (!((rdev->wiphy.features &
8728 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
8729 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
8730 !wiphy_ext_feature_isset(&rdev->wiphy,
8731 NL80211_EXT_FEATURE_RRM)) {
707554b4 8732 kzfree(connkeys);
bab5ab7d 8733 return -EINVAL;
707554b4 8734 }
bab5ab7d
AK
8735 connect.flags |= ASSOC_REQ_USE_RRM;
8736 }
8737
34d50519 8738 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
57fbcce3 8739 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) {
34d50519
LD
8740 kzfree(connkeys);
8741 return -EOPNOTSUPP;
8742 }
8743
38de03d2
AS
8744 if (info->attrs[NL80211_ATTR_BSS_SELECT]) {
8745 /* bss selection makes no sense if bssid is set */
8746 if (connect.bssid) {
8747 kzfree(connkeys);
8748 return -EINVAL;
8749 }
8750
8751 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT],
8752 wiphy, &connect.bss_select);
8753 if (err) {
8754 kzfree(connkeys);
8755 return err;
8756 }
8757 }
8758
83739b03 8759 wdev_lock(dev->ieee80211_ptr);
4ce2bd9c
JM
8760 err = cfg80211_connect(rdev, dev, &connect, connkeys,
8761 connect.prev_bssid);
83739b03 8762 wdev_unlock(dev->ieee80211_ptr);
fffd0934 8763 if (err)
b47f610b 8764 kzfree(connkeys);
b23aa676
SO
8765 return err;
8766}
8767
8768static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
8769{
4c476991
JB
8770 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8771 struct net_device *dev = info->user_ptr[1];
b23aa676 8772 u16 reason;
83739b03 8773 int ret;
b23aa676
SO
8774
8775 if (!info->attrs[NL80211_ATTR_REASON_CODE])
8776 reason = WLAN_REASON_DEAUTH_LEAVING;
8777 else
8778 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
8779
8780 if (reason == 0)
8781 return -EINVAL;
8782
074ac8df 8783 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8784 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8785 return -EOPNOTSUPP;
b23aa676 8786
83739b03
JB
8787 wdev_lock(dev->ieee80211_ptr);
8788 ret = cfg80211_disconnect(rdev, dev, reason, true);
8789 wdev_unlock(dev->ieee80211_ptr);
8790 return ret;
b23aa676
SO
8791}
8792
463d0183
JB
8793static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
8794{
4c476991 8795 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
8796 struct net *net;
8797 int err;
463d0183 8798
4b681c82
VK
8799 if (info->attrs[NL80211_ATTR_PID]) {
8800 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
8801
8802 net = get_net_ns_by_pid(pid);
8803 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) {
8804 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]);
463d0183 8805
4b681c82
VK
8806 net = get_net_ns_by_fd(fd);
8807 } else {
8808 return -EINVAL;
8809 }
463d0183 8810
4c476991
JB
8811 if (IS_ERR(net))
8812 return PTR_ERR(net);
463d0183
JB
8813
8814 err = 0;
8815
8816 /* check if anything to do */
4c476991
JB
8817 if (!net_eq(wiphy_net(&rdev->wiphy), net))
8818 err = cfg80211_switch_netns(rdev, net);
463d0183 8819
463d0183 8820 put_net(net);
463d0183
JB
8821 return err;
8822}
8823
67fbb16b
SO
8824static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
8825{
4c476991 8826 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
8827 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
8828 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 8829 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
8830 struct cfg80211_pmksa pmksa;
8831
8832 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
8833
8834 if (!info->attrs[NL80211_ATTR_MAC])
8835 return -EINVAL;
8836
8837 if (!info->attrs[NL80211_ATTR_PMKID])
8838 return -EINVAL;
8839
67fbb16b
SO
8840 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
8841 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
8842
074ac8df 8843 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8844 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8845 return -EOPNOTSUPP;
67fbb16b
SO
8846
8847 switch (info->genlhdr->cmd) {
8848 case NL80211_CMD_SET_PMKSA:
8849 rdev_ops = rdev->ops->set_pmksa;
8850 break;
8851 case NL80211_CMD_DEL_PMKSA:
8852 rdev_ops = rdev->ops->del_pmksa;
8853 break;
8854 default:
8855 WARN_ON(1);
8856 break;
8857 }
8858
4c476991
JB
8859 if (!rdev_ops)
8860 return -EOPNOTSUPP;
67fbb16b 8861
4c476991 8862 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
8863}
8864
8865static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
8866{
4c476991
JB
8867 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8868 struct net_device *dev = info->user_ptr[1];
67fbb16b 8869
074ac8df 8870 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8871 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8872 return -EOPNOTSUPP;
67fbb16b 8873
4c476991
JB
8874 if (!rdev->ops->flush_pmksa)
8875 return -EOPNOTSUPP;
67fbb16b 8876
e35e4d28 8877 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
8878}
8879
109086ce
AN
8880static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
8881{
8882 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8883 struct net_device *dev = info->user_ptr[1];
8884 u8 action_code, dialog_token;
df942e7b 8885 u32 peer_capability = 0;
109086ce
AN
8886 u16 status_code;
8887 u8 *peer;
31fa97c5 8888 bool initiator;
109086ce
AN
8889
8890 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
8891 !rdev->ops->tdls_mgmt)
8892 return -EOPNOTSUPP;
8893
8894 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
8895 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
8896 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
8897 !info->attrs[NL80211_ATTR_IE] ||
8898 !info->attrs[NL80211_ATTR_MAC])
8899 return -EINVAL;
8900
8901 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
8902 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
8903 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
8904 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
31fa97c5 8905 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]);
df942e7b
SDU
8906 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
8907 peer_capability =
8908 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
109086ce 8909
e35e4d28 8910 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
df942e7b 8911 dialog_token, status_code, peer_capability,
31fa97c5 8912 initiator,
e35e4d28
HG
8913 nla_data(info->attrs[NL80211_ATTR_IE]),
8914 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
8915}
8916
8917static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
8918{
8919 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8920 struct net_device *dev = info->user_ptr[1];
8921 enum nl80211_tdls_operation operation;
8922 u8 *peer;
8923
8924 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
8925 !rdev->ops->tdls_oper)
8926 return -EOPNOTSUPP;
8927
8928 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
8929 !info->attrs[NL80211_ATTR_MAC])
8930 return -EINVAL;
8931
8932 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
8933 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
8934
e35e4d28 8935 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
8936}
8937
9588bbd5
JM
8938static int nl80211_remain_on_channel(struct sk_buff *skb,
8939 struct genl_info *info)
8940{
4c476991 8941 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 8942 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 8943 struct cfg80211_chan_def chandef;
9588bbd5
JM
8944 struct sk_buff *msg;
8945 void *hdr;
8946 u64 cookie;
683b6d3b 8947 u32 duration;
9588bbd5
JM
8948 int err;
8949
8950 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
8951 !info->attrs[NL80211_ATTR_DURATION])
8952 return -EINVAL;
8953
8954 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
8955
ebf348fc
JB
8956 if (!rdev->ops->remain_on_channel ||
8957 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
8958 return -EOPNOTSUPP;
8959
9588bbd5 8960 /*
ebf348fc
JB
8961 * We should be on that channel for at least a minimum amount of
8962 * time (10ms) but no longer than the driver supports.
9588bbd5 8963 */
ebf348fc 8964 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 8965 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
8966 return -EINVAL;
8967
683b6d3b
JB
8968 err = nl80211_parse_chandef(rdev, info, &chandef);
8969 if (err)
8970 return err;
9588bbd5
JM
8971
8972 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
8973 if (!msg)
8974 return -ENOMEM;
9588bbd5 8975
15e47304 8976 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 8977 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
8978 if (!hdr) {
8979 err = -ENOBUFS;
9588bbd5
JM
8980 goto free_msg;
8981 }
8982
683b6d3b
JB
8983 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
8984 duration, &cookie);
9588bbd5
JM
8985
8986 if (err)
8987 goto free_msg;
8988
2dad624e
ND
8989 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
8990 NL80211_ATTR_PAD))
9360ffd1 8991 goto nla_put_failure;
9588bbd5
JM
8992
8993 genlmsg_end(msg, hdr);
4c476991
JB
8994
8995 return genlmsg_reply(msg, info);
9588bbd5
JM
8996
8997 nla_put_failure:
8998 err = -ENOBUFS;
8999 free_msg:
9000 nlmsg_free(msg);
9588bbd5
JM
9001 return err;
9002}
9003
9004static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
9005 struct genl_info *info)
9006{
4c476991 9007 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9008 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 9009 u64 cookie;
9588bbd5
JM
9010
9011 if (!info->attrs[NL80211_ATTR_COOKIE])
9012 return -EINVAL;
9013
4c476991
JB
9014 if (!rdev->ops->cancel_remain_on_channel)
9015 return -EOPNOTSUPP;
9588bbd5 9016
9588bbd5
JM
9017 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
9018
e35e4d28 9019 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
9020}
9021
13ae75b1
JM
9022static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
9023 struct genl_info *info)
9024{
13ae75b1 9025 struct cfg80211_bitrate_mask mask;
a7c7fbff 9026 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 9027 struct net_device *dev = info->user_ptr[1];
a7c7fbff 9028 int err;
13ae75b1 9029
4c476991
JB
9030 if (!rdev->ops->set_bitrate_mask)
9031 return -EOPNOTSUPP;
13ae75b1 9032
a7c7fbff
PK
9033 err = nl80211_parse_tx_bitrate_mask(info, &mask);
9034 if (err)
9035 return err;
13ae75b1 9036
e35e4d28 9037 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
9038}
9039
2e161f78 9040static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 9041{
4c476991 9042 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9043 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 9044 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
9045
9046 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
9047 return -EINVAL;
9048
2e161f78
JB
9049 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
9050 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 9051
71bbc994
JB
9052 switch (wdev->iftype) {
9053 case NL80211_IFTYPE_STATION:
9054 case NL80211_IFTYPE_ADHOC:
9055 case NL80211_IFTYPE_P2P_CLIENT:
9056 case NL80211_IFTYPE_AP:
9057 case NL80211_IFTYPE_AP_VLAN:
9058 case NL80211_IFTYPE_MESH_POINT:
9059 case NL80211_IFTYPE_P2P_GO:
98104fde 9060 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 9061 break;
cb3b7d87 9062 case NL80211_IFTYPE_NAN:
71bbc994 9063 default:
4c476991 9064 return -EOPNOTSUPP;
71bbc994 9065 }
026331c4
JM
9066
9067 /* not much point in registering if we can't reply */
4c476991
JB
9068 if (!rdev->ops->mgmt_tx)
9069 return -EOPNOTSUPP;
026331c4 9070
15e47304 9071 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
9072 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
9073 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
9074}
9075
2e161f78 9076static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 9077{
4c476991 9078 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9079 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 9080 struct cfg80211_chan_def chandef;
026331c4 9081 int err;
d64d373f 9082 void *hdr = NULL;
026331c4 9083 u64 cookie;
e247bd90 9084 struct sk_buff *msg = NULL;
b176e629
AO
9085 struct cfg80211_mgmt_tx_params params = {
9086 .dont_wait_for_ack =
9087 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
9088 };
026331c4 9089
683b6d3b 9090 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
9091 return -EINVAL;
9092
4c476991
JB
9093 if (!rdev->ops->mgmt_tx)
9094 return -EOPNOTSUPP;
026331c4 9095
71bbc994 9096 switch (wdev->iftype) {
ea141b75
AQ
9097 case NL80211_IFTYPE_P2P_DEVICE:
9098 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
9099 return -EINVAL;
71bbc994
JB
9100 case NL80211_IFTYPE_STATION:
9101 case NL80211_IFTYPE_ADHOC:
9102 case NL80211_IFTYPE_P2P_CLIENT:
9103 case NL80211_IFTYPE_AP:
9104 case NL80211_IFTYPE_AP_VLAN:
9105 case NL80211_IFTYPE_MESH_POINT:
9106 case NL80211_IFTYPE_P2P_GO:
9107 break;
cb3b7d87 9108 case NL80211_IFTYPE_NAN:
71bbc994 9109 default:
4c476991 9110 return -EOPNOTSUPP;
71bbc994 9111 }
026331c4 9112
f7ca38df 9113 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 9114 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df 9115 return -EINVAL;
b176e629 9116 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
9117
9118 /*
9119 * We should wait on the channel for at least a minimum amount
9120 * of time (10ms) but no longer than the driver supports.
9121 */
b176e629
AO
9122 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
9123 params.wait > rdev->wiphy.max_remain_on_channel_duration)
ebf348fc 9124 return -EINVAL;
f7ca38df
JB
9125 }
9126
b176e629 9127 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
f7ca38df 9128
b176e629 9129 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7c4ef712
JB
9130 return -EINVAL;
9131
b176e629 9132 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
e9f935e3 9133
ea141b75
AQ
9134 /* get the channel if any has been specified, otherwise pass NULL to
9135 * the driver. The latter will use the current one
9136 */
9137 chandef.chan = NULL;
9138 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
9139 err = nl80211_parse_chandef(rdev, info, &chandef);
9140 if (err)
9141 return err;
9142 }
9143
b176e629 9144 if (!chandef.chan && params.offchan)
ea141b75 9145 return -EINVAL;
026331c4 9146
34d22ce2
AO
9147 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
9148 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
9149
9150 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) {
9151 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
9152 int i;
9153
9154 if (len % sizeof(u16))
9155 return -EINVAL;
9156
9157 params.n_csa_offsets = len / sizeof(u16);
9158 params.csa_offsets =
9159 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
9160
9161 /* check that all the offsets fit the frame */
9162 for (i = 0; i < params.n_csa_offsets; i++) {
9163 if (params.csa_offsets[i] >= params.len)
9164 return -EINVAL;
9165 }
9166 }
9167
b176e629 9168 if (!params.dont_wait_for_ack) {
e247bd90
JB
9169 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9170 if (!msg)
9171 return -ENOMEM;
026331c4 9172
15e47304 9173 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 9174 NL80211_CMD_FRAME);
cb35fba3
DC
9175 if (!hdr) {
9176 err = -ENOBUFS;
e247bd90
JB
9177 goto free_msg;
9178 }
026331c4 9179 }
e247bd90 9180
b176e629
AO
9181 params.chan = chandef.chan;
9182 err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
026331c4
JM
9183 if (err)
9184 goto free_msg;
9185
e247bd90 9186 if (msg) {
2dad624e
ND
9187 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
9188 NL80211_ATTR_PAD))
9360ffd1 9189 goto nla_put_failure;
026331c4 9190
e247bd90
JB
9191 genlmsg_end(msg, hdr);
9192 return genlmsg_reply(msg, info);
9193 }
9194
9195 return 0;
026331c4
JM
9196
9197 nla_put_failure:
9198 err = -ENOBUFS;
9199 free_msg:
9200 nlmsg_free(msg);
026331c4
JM
9201 return err;
9202}
9203
f7ca38df
JB
9204static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
9205{
9206 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9207 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
9208 u64 cookie;
9209
9210 if (!info->attrs[NL80211_ATTR_COOKIE])
9211 return -EINVAL;
9212
9213 if (!rdev->ops->mgmt_tx_cancel_wait)
9214 return -EOPNOTSUPP;
9215
71bbc994
JB
9216 switch (wdev->iftype) {
9217 case NL80211_IFTYPE_STATION:
9218 case NL80211_IFTYPE_ADHOC:
9219 case NL80211_IFTYPE_P2P_CLIENT:
9220 case NL80211_IFTYPE_AP:
9221 case NL80211_IFTYPE_AP_VLAN:
9222 case NL80211_IFTYPE_P2P_GO:
98104fde 9223 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 9224 break;
cb3b7d87 9225 case NL80211_IFTYPE_NAN:
71bbc994 9226 default:
f7ca38df 9227 return -EOPNOTSUPP;
71bbc994 9228 }
f7ca38df
JB
9229
9230 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
9231
e35e4d28 9232 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
9233}
9234
ffb9eb3d
KV
9235static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
9236{
4c476991 9237 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 9238 struct wireless_dev *wdev;
4c476991 9239 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
9240 u8 ps_state;
9241 bool state;
9242 int err;
9243
4c476991
JB
9244 if (!info->attrs[NL80211_ATTR_PS_STATE])
9245 return -EINVAL;
ffb9eb3d
KV
9246
9247 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
9248
4c476991
JB
9249 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
9250 return -EINVAL;
ffb9eb3d
KV
9251
9252 wdev = dev->ieee80211_ptr;
9253
4c476991
JB
9254 if (!rdev->ops->set_power_mgmt)
9255 return -EOPNOTSUPP;
ffb9eb3d
KV
9256
9257 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
9258
9259 if (state == wdev->ps)
4c476991 9260 return 0;
ffb9eb3d 9261
e35e4d28 9262 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
9263 if (!err)
9264 wdev->ps = state;
ffb9eb3d
KV
9265 return err;
9266}
9267
9268static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
9269{
4c476991 9270 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
9271 enum nl80211_ps_state ps_state;
9272 struct wireless_dev *wdev;
4c476991 9273 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
9274 struct sk_buff *msg;
9275 void *hdr;
9276 int err;
9277
ffb9eb3d
KV
9278 wdev = dev->ieee80211_ptr;
9279
4c476991
JB
9280 if (!rdev->ops->set_power_mgmt)
9281 return -EOPNOTSUPP;
ffb9eb3d
KV
9282
9283 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
9284 if (!msg)
9285 return -ENOMEM;
ffb9eb3d 9286
15e47304 9287 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
9288 NL80211_CMD_GET_POWER_SAVE);
9289 if (!hdr) {
4c476991 9290 err = -ENOBUFS;
ffb9eb3d
KV
9291 goto free_msg;
9292 }
9293
9294 if (wdev->ps)
9295 ps_state = NL80211_PS_ENABLED;
9296 else
9297 ps_state = NL80211_PS_DISABLED;
9298
9360ffd1
DM
9299 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
9300 goto nla_put_failure;
ffb9eb3d
KV
9301
9302 genlmsg_end(msg, hdr);
4c476991 9303 return genlmsg_reply(msg, info);
ffb9eb3d 9304
4c476991 9305 nla_put_failure:
ffb9eb3d 9306 err = -ENOBUFS;
4c476991 9307 free_msg:
ffb9eb3d 9308 nlmsg_free(msg);
ffb9eb3d
KV
9309 return err;
9310}
9311
94e860f1
JB
9312static const struct nla_policy
9313nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
d6dc1a38
JO
9314 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
9315 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
9316 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
9317 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
9318 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
9319 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
9320};
9321
84f10708 9322static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 9323 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
9324{
9325 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 9326 struct net_device *dev = info->user_ptr[1];
1da5fcc8 9327 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 9328
d9d8b019 9329 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
9330 return -EINVAL;
9331
84f10708
TP
9332 if (!rdev->ops->set_cqm_txe_config)
9333 return -EOPNOTSUPP;
9334
9335 if (wdev->iftype != NL80211_IFTYPE_STATION &&
9336 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
9337 return -EOPNOTSUPP;
9338
e35e4d28 9339 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
9340}
9341
d6dc1a38
JO
9342static int nl80211_set_cqm_rssi(struct genl_info *info,
9343 s32 threshold, u32 hysteresis)
9344{
4c476991 9345 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 9346 struct net_device *dev = info->user_ptr[1];
1da5fcc8 9347 struct wireless_dev *wdev = dev->ieee80211_ptr;
d6dc1a38
JO
9348
9349 if (threshold > 0)
9350 return -EINVAL;
9351
1da5fcc8
JB
9352 /* disabling - hysteresis should also be zero then */
9353 if (threshold == 0)
9354 hysteresis = 0;
d6dc1a38 9355
4c476991
JB
9356 if (!rdev->ops->set_cqm_rssi_config)
9357 return -EOPNOTSUPP;
d6dc1a38 9358
074ac8df 9359 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9360 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
9361 return -EOPNOTSUPP;
d6dc1a38 9362
e35e4d28 9363 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
9364}
9365
9366static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
9367{
9368 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
9369 struct nlattr *cqm;
9370 int err;
9371
9372 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
9373 if (!cqm)
9374 return -EINVAL;
d6dc1a38
JO
9375
9376 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
9377 nl80211_attr_cqm_policy);
9378 if (err)
1da5fcc8 9379 return err;
d6dc1a38
JO
9380
9381 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
9382 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
1da5fcc8
JB
9383 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
9384 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 9385
1da5fcc8
JB
9386 return nl80211_set_cqm_rssi(info, threshold, hysteresis);
9387 }
9388
9389 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
9390 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
9391 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
9392 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
9393 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
9394 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
9395
9396 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
9397 }
9398
9399 return -EINVAL;
d6dc1a38
JO
9400}
9401
6e0bd6c3
RL
9402static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
9403{
9404 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9405 struct net_device *dev = info->user_ptr[1];
9406 struct ocb_setup setup = {};
9407 int err;
9408
9409 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
9410 if (err)
9411 return err;
9412
9413 return cfg80211_join_ocb(rdev, dev, &setup);
9414}
9415
9416static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info)
9417{
9418 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9419 struct net_device *dev = info->user_ptr[1];
9420
9421 return cfg80211_leave_ocb(rdev, dev);
9422}
9423
29cbe68c
JB
9424static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
9425{
9426 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9427 struct net_device *dev = info->user_ptr[1];
9428 struct mesh_config cfg;
c80d545d 9429 struct mesh_setup setup;
29cbe68c
JB
9430 int err;
9431
9432 /* start with default */
9433 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 9434 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 9435
24bdd9f4 9436 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 9437 /* and parse parameters if given */
24bdd9f4 9438 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
9439 if (err)
9440 return err;
9441 }
9442
9443 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
9444 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
9445 return -EINVAL;
9446
c80d545d
JC
9447 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
9448 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
9449
4bb62344
CYY
9450 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
9451 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
9452 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
9453 return -EINVAL;
9454
9bdbf04d
MP
9455 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
9456 setup.beacon_interval =
9457 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 9458
0c317a02
PK
9459 err = cfg80211_validate_beacon_int(rdev,
9460 NL80211_IFTYPE_MESH_POINT,
9461 setup.beacon_interval);
12d20fc9
PK
9462 if (err)
9463 return err;
9bdbf04d
MP
9464 }
9465
9466 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
9467 setup.dtim_period =
9468 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
9469 if (setup.dtim_period < 1 || setup.dtim_period > 100)
9470 return -EINVAL;
9471 }
9472
c80d545d
JC
9473 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
9474 /* parse additional setup parameters if given */
9475 err = nl80211_parse_mesh_setup(info, &setup);
9476 if (err)
9477 return err;
9478 }
9479
d37bb18a
TP
9480 if (setup.user_mpm)
9481 cfg.auto_open_plinks = false;
9482
cc1d2806 9483 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
9484 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
9485 if (err)
9486 return err;
cc1d2806
JB
9487 } else {
9488 /* cfg80211_join_mesh() will sort it out */
683b6d3b 9489 setup.chandef.chan = NULL;
cc1d2806
JB
9490 }
9491
ffb3cf30
AN
9492 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
9493 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
9494 int n_rates =
9495 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
9496 struct ieee80211_supported_band *sband;
9497
9498 if (!setup.chandef.chan)
9499 return -EINVAL;
9500
9501 sband = rdev->wiphy.bands[setup.chandef.chan->band];
9502
9503 err = ieee80211_get_ratemask(sband, rates, n_rates,
9504 &setup.basic_rates);
9505 if (err)
9506 return err;
9507 }
9508
8564e382
JB
9509 if (info->attrs[NL80211_ATTR_TX_RATES]) {
9510 err = nl80211_parse_tx_bitrate_mask(info, &setup.beacon_rate);
9511 if (err)
9512 return err;
9513
9514 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band,
9515 &setup.beacon_rate);
9516 if (err)
9517 return err;
9518 }
9519
c80d545d 9520 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
9521}
9522
9523static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
9524{
9525 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9526 struct net_device *dev = info->user_ptr[1];
9527
9528 return cfg80211_leave_mesh(rdev, dev);
9529}
9530
dfb89c56 9531#ifdef CONFIG_PM
bb92d199
AK
9532static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
9533 struct cfg80211_registered_device *rdev)
9534{
6abb9cb9 9535 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
9536 struct nlattr *nl_pats, *nl_pat;
9537 int i, pat_len;
9538
6abb9cb9 9539 if (!wowlan->n_patterns)
bb92d199
AK
9540 return 0;
9541
9542 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
9543 if (!nl_pats)
9544 return -ENOBUFS;
9545
6abb9cb9 9546 for (i = 0; i < wowlan->n_patterns; i++) {
bb92d199
AK
9547 nl_pat = nla_nest_start(msg, i + 1);
9548 if (!nl_pat)
9549 return -ENOBUFS;
6abb9cb9 9550 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 9551 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 9552 wowlan->patterns[i].mask) ||
50ac6607
AK
9553 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
9554 wowlan->patterns[i].pattern) ||
9555 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 9556 wowlan->patterns[i].pkt_offset))
bb92d199
AK
9557 return -ENOBUFS;
9558 nla_nest_end(msg, nl_pat);
9559 }
9560 nla_nest_end(msg, nl_pats);
9561
9562 return 0;
9563}
9564
2a0e047e
JB
9565static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
9566 struct cfg80211_wowlan_tcp *tcp)
9567{
9568 struct nlattr *nl_tcp;
9569
9570 if (!tcp)
9571 return 0;
9572
9573 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
9574 if (!nl_tcp)
9575 return -ENOBUFS;
9576
930345ea
JB
9577 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
9578 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
2a0e047e
JB
9579 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
9580 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
9581 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
9582 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
9583 tcp->payload_len, tcp->payload) ||
9584 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
9585 tcp->data_interval) ||
9586 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
9587 tcp->wake_len, tcp->wake_data) ||
9588 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
9589 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
9590 return -ENOBUFS;
9591
9592 if (tcp->payload_seq.len &&
9593 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
9594 sizeof(tcp->payload_seq), &tcp->payload_seq))
9595 return -ENOBUFS;
9596
9597 if (tcp->payload_tok.len &&
9598 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
9599 sizeof(tcp->payload_tok) + tcp->tokens_size,
9600 &tcp->payload_tok))
9601 return -ENOBUFS;
9602
e248ad30
JB
9603 nla_nest_end(msg, nl_tcp);
9604
2a0e047e
JB
9605 return 0;
9606}
9607
75453ccb
LC
9608static int nl80211_send_wowlan_nd(struct sk_buff *msg,
9609 struct cfg80211_sched_scan_request *req)
9610{
3b06d277 9611 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan;
75453ccb
LC
9612 int i;
9613
9614 if (!req)
9615 return 0;
9616
9617 nd = nla_nest_start(msg, NL80211_WOWLAN_TRIG_NET_DETECT);
9618 if (!nd)
9619 return -ENOBUFS;
9620
3b06d277
AS
9621 if (req->n_scan_plans == 1 &&
9622 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL,
9623 req->scan_plans[0].interval * 1000))
75453ccb
LC
9624 return -ENOBUFS;
9625
21fea567
LC
9626 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay))
9627 return -ENOBUFS;
9628
75453ccb
LC
9629 freqs = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
9630 if (!freqs)
9631 return -ENOBUFS;
9632
53b18980
JB
9633 for (i = 0; i < req->n_channels; i++) {
9634 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
9635 return -ENOBUFS;
9636 }
75453ccb
LC
9637
9638 nla_nest_end(msg, freqs);
9639
9640 if (req->n_match_sets) {
9641 matches = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_MATCH);
76e1fb4b
JB
9642 if (!matches)
9643 return -ENOBUFS;
9644
75453ccb
LC
9645 for (i = 0; i < req->n_match_sets; i++) {
9646 match = nla_nest_start(msg, i);
76e1fb4b
JB
9647 if (!match)
9648 return -ENOBUFS;
9649
53b18980
JB
9650 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID,
9651 req->match_sets[i].ssid.ssid_len,
9652 req->match_sets[i].ssid.ssid))
9653 return -ENOBUFS;
75453ccb
LC
9654 nla_nest_end(msg, match);
9655 }
9656 nla_nest_end(msg, matches);
9657 }
9658
3b06d277
AS
9659 scan_plans = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_PLANS);
9660 if (!scan_plans)
9661 return -ENOBUFS;
9662
9663 for (i = 0; i < req->n_scan_plans; i++) {
9664 scan_plan = nla_nest_start(msg, i + 1);
76e1fb4b
JB
9665 if (!scan_plan)
9666 return -ENOBUFS;
9667
3b06d277
AS
9668 if (!scan_plan ||
9669 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL,
9670 req->scan_plans[i].interval) ||
9671 (req->scan_plans[i].iterations &&
9672 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS,
9673 req->scan_plans[i].iterations)))
9674 return -ENOBUFS;
9675 nla_nest_end(msg, scan_plan);
9676 }
9677 nla_nest_end(msg, scan_plans);
9678
75453ccb
LC
9679 nla_nest_end(msg, nd);
9680
9681 return 0;
9682}
9683
ff1b6e69
JB
9684static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
9685{
9686 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9687 struct sk_buff *msg;
9688 void *hdr;
2a0e047e 9689 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 9690
964dc9e2 9691 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
9692 return -EOPNOTSUPP;
9693
6abb9cb9 9694 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 9695 /* adjust size to have room for all the data */
6abb9cb9
JB
9696 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
9697 rdev->wiphy.wowlan_config->tcp->payload_len +
9698 rdev->wiphy.wowlan_config->tcp->wake_len +
9699 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
9700 }
9701
9702 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
9703 if (!msg)
9704 return -ENOMEM;
9705
15e47304 9706 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
9707 NL80211_CMD_GET_WOWLAN);
9708 if (!hdr)
9709 goto nla_put_failure;
9710
6abb9cb9 9711 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
9712 struct nlattr *nl_wowlan;
9713
9714 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
9715 if (!nl_wowlan)
9716 goto nla_put_failure;
9717
6abb9cb9 9718 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 9719 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 9720 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 9721 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 9722 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 9723 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 9724 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 9725 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 9726 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 9727 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 9728 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 9729 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 9730 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
9731 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
9732 goto nla_put_failure;
2a0e047e 9733
bb92d199
AK
9734 if (nl80211_send_wowlan_patterns(msg, rdev))
9735 goto nla_put_failure;
2a0e047e 9736
6abb9cb9
JB
9737 if (nl80211_send_wowlan_tcp(msg,
9738 rdev->wiphy.wowlan_config->tcp))
2a0e047e 9739 goto nla_put_failure;
75453ccb
LC
9740
9741 if (nl80211_send_wowlan_nd(
9742 msg,
9743 rdev->wiphy.wowlan_config->nd_config))
9744 goto nla_put_failure;
2a0e047e 9745
ff1b6e69
JB
9746 nla_nest_end(msg, nl_wowlan);
9747 }
9748
9749 genlmsg_end(msg, hdr);
9750 return genlmsg_reply(msg, info);
9751
9752nla_put_failure:
9753 nlmsg_free(msg);
9754 return -ENOBUFS;
9755}
9756
2a0e047e
JB
9757static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
9758 struct nlattr *attr,
9759 struct cfg80211_wowlan *trig)
9760{
9761 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
9762 struct cfg80211_wowlan_tcp *cfg;
9763 struct nl80211_wowlan_tcp_data_token *tok = NULL;
9764 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
9765 u32 size;
9766 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
9767 int err, port;
9768
964dc9e2 9769 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
9770 return -EINVAL;
9771
bfe2c7b1
JB
9772 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TCP, attr,
9773 nl80211_wowlan_tcp_policy);
2a0e047e
JB
9774 if (err)
9775 return err;
9776
9777 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
9778 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
9779 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
9780 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
9781 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
9782 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
9783 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
9784 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
9785 return -EINVAL;
9786
9787 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 9788 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
9789 return -EINVAL;
9790
9791 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 9792 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 9793 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
9794 return -EINVAL;
9795
9796 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 9797 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
9798 return -EINVAL;
9799
9800 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
9801 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
9802 return -EINVAL;
9803
9804 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
9805 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
9806
9807 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
9808 tokens_size = tokln - sizeof(*tok);
9809
9810 if (!tok->len || tokens_size % tok->len)
9811 return -EINVAL;
964dc9e2 9812 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 9813 return -EINVAL;
964dc9e2 9814 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 9815 return -EINVAL;
964dc9e2 9816 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 9817 return -EINVAL;
964dc9e2 9818 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
9819 return -EINVAL;
9820 if (tok->offset + tok->len > data_size)
9821 return -EINVAL;
9822 }
9823
9824 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
9825 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 9826 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
9827 return -EINVAL;
9828 if (seq->len == 0 || seq->len > 4)
9829 return -EINVAL;
9830 if (seq->len + seq->offset > data_size)
9831 return -EINVAL;
9832 }
9833
9834 size = sizeof(*cfg);
9835 size += data_size;
9836 size += wake_size + wake_mask_size;
9837 size += tokens_size;
9838
9839 cfg = kzalloc(size, GFP_KERNEL);
9840 if (!cfg)
9841 return -ENOMEM;
67b61f6c
JB
9842 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
9843 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
2a0e047e
JB
9844 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
9845 ETH_ALEN);
9846 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
9847 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
9848 else
9849 port = 0;
9850#ifdef CONFIG_INET
9851 /* allocate a socket and port for it and use it */
9852 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
9853 IPPROTO_TCP, &cfg->sock, 1);
9854 if (err) {
9855 kfree(cfg);
9856 return err;
9857 }
9858 if (inet_csk_get_port(cfg->sock->sk, port)) {
9859 sock_release(cfg->sock);
9860 kfree(cfg);
9861 return -EADDRINUSE;
9862 }
9863 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
9864#else
9865 if (!port) {
9866 kfree(cfg);
9867 return -EINVAL;
9868 }
9869 cfg->src_port = port;
9870#endif
9871
9872 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
9873 cfg->payload_len = data_size;
9874 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
9875 memcpy((void *)cfg->payload,
9876 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
9877 data_size);
9878 if (seq)
9879 cfg->payload_seq = *seq;
9880 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
9881 cfg->wake_len = wake_size;
9882 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
9883 memcpy((void *)cfg->wake_data,
9884 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
9885 wake_size);
9886 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
9887 data_size + wake_size;
9888 memcpy((void *)cfg->wake_mask,
9889 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
9890 wake_mask_size);
9891 if (tok) {
9892 cfg->tokens_size = tokens_size;
9893 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
9894 }
9895
9896 trig->tcp = cfg;
9897
9898 return 0;
9899}
9900
8cd4d456
LC
9901static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev,
9902 const struct wiphy_wowlan_support *wowlan,
9903 struct nlattr *attr,
9904 struct cfg80211_wowlan *trig)
9905{
9906 struct nlattr **tb;
9907 int err;
9908
9909 tb = kzalloc(NUM_NL80211_ATTR * sizeof(*tb), GFP_KERNEL);
9910 if (!tb)
9911 return -ENOMEM;
9912
9913 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) {
9914 err = -EOPNOTSUPP;
9915 goto out;
9916 }
9917
bfe2c7b1 9918 err = nla_parse_nested(tb, NL80211_ATTR_MAX, attr, nl80211_policy);
8cd4d456
LC
9919 if (err)
9920 goto out;
9921
ad2b26ab 9922 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb);
8cd4d456
LC
9923 err = PTR_ERR_OR_ZERO(trig->nd_config);
9924 if (err)
9925 trig->nd_config = NULL;
9926
9927out:
9928 kfree(tb);
9929 return err;
9930}
9931
ff1b6e69
JB
9932static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
9933{
9934 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9935 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 9936 struct cfg80211_wowlan new_triggers = {};
ae33bd81 9937 struct cfg80211_wowlan *ntrig;
964dc9e2 9938 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 9939 int err, i;
6abb9cb9 9940 bool prev_enabled = rdev->wiphy.wowlan_config;
98fc4386 9941 bool regular = false;
ff1b6e69 9942
964dc9e2 9943 if (!wowlan)
ff1b6e69
JB
9944 return -EOPNOTSUPP;
9945
ae33bd81
JB
9946 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
9947 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 9948 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
9949 goto set_wakeup;
9950 }
ff1b6e69 9951
bfe2c7b1
JB
9952 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TRIG,
9953 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS],
9954 nl80211_wowlan_policy);
ff1b6e69
JB
9955 if (err)
9956 return err;
9957
9958 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
9959 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
9960 return -EINVAL;
9961 new_triggers.any = true;
9962 }
9963
9964 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
9965 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
9966 return -EINVAL;
9967 new_triggers.disconnect = true;
98fc4386 9968 regular = true;
ff1b6e69
JB
9969 }
9970
9971 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
9972 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
9973 return -EINVAL;
9974 new_triggers.magic_pkt = true;
98fc4386 9975 regular = true;
ff1b6e69
JB
9976 }
9977
77dbbb13
JB
9978 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
9979 return -EINVAL;
9980
9981 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
9982 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
9983 return -EINVAL;
9984 new_triggers.gtk_rekey_failure = true;
98fc4386 9985 regular = true;
77dbbb13
JB
9986 }
9987
9988 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
9989 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
9990 return -EINVAL;
9991 new_triggers.eap_identity_req = true;
98fc4386 9992 regular = true;
77dbbb13
JB
9993 }
9994
9995 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
9996 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
9997 return -EINVAL;
9998 new_triggers.four_way_handshake = true;
98fc4386 9999 regular = true;
77dbbb13
JB
10000 }
10001
10002 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
10003 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
10004 return -EINVAL;
10005 new_triggers.rfkill_release = true;
98fc4386 10006 regular = true;
77dbbb13
JB
10007 }
10008
ff1b6e69
JB
10009 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
10010 struct nlattr *pat;
10011 int n_patterns = 0;
bb92d199 10012 int rem, pat_len, mask_len, pkt_offset;
50ac6607 10013 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69 10014
98fc4386
JB
10015 regular = true;
10016
ff1b6e69
JB
10017 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
10018 rem)
10019 n_patterns++;
10020 if (n_patterns > wowlan->n_patterns)
10021 return -EINVAL;
10022
10023 new_triggers.patterns = kcalloc(n_patterns,
10024 sizeof(new_triggers.patterns[0]),
10025 GFP_KERNEL);
10026 if (!new_triggers.patterns)
10027 return -ENOMEM;
10028
10029 new_triggers.n_patterns = n_patterns;
10030 i = 0;
10031
10032 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
10033 rem) {
922bd80f
JB
10034 u8 *mask_pat;
10035
bfe2c7b1
JB
10036 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat,
10037 NULL);
ff1b6e69 10038 err = -EINVAL;
50ac6607
AK
10039 if (!pat_tb[NL80211_PKTPAT_MASK] ||
10040 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 10041 goto error;
50ac6607 10042 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 10043 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 10044 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
10045 goto error;
10046 if (pat_len > wowlan->pattern_max_len ||
10047 pat_len < wowlan->pattern_min_len)
10048 goto error;
10049
50ac6607 10050 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
10051 pkt_offset = 0;
10052 else
10053 pkt_offset = nla_get_u32(
50ac6607 10054 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
10055 if (pkt_offset > wowlan->max_pkt_offset)
10056 goto error;
10057 new_triggers.patterns[i].pkt_offset = pkt_offset;
10058
922bd80f
JB
10059 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
10060 if (!mask_pat) {
ff1b6e69
JB
10061 err = -ENOMEM;
10062 goto error;
10063 }
922bd80f
JB
10064 new_triggers.patterns[i].mask = mask_pat;
10065 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69 10066 mask_len);
922bd80f
JB
10067 mask_pat += mask_len;
10068 new_triggers.patterns[i].pattern = mask_pat;
ff1b6e69 10069 new_triggers.patterns[i].pattern_len = pat_len;
922bd80f 10070 memcpy(mask_pat,
50ac6607 10071 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
10072 pat_len);
10073 i++;
10074 }
10075 }
10076
2a0e047e 10077 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
98fc4386 10078 regular = true;
2a0e047e
JB
10079 err = nl80211_parse_wowlan_tcp(
10080 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
10081 &new_triggers);
10082 if (err)
10083 goto error;
10084 }
10085
8cd4d456 10086 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) {
98fc4386 10087 regular = true;
8cd4d456
LC
10088 err = nl80211_parse_wowlan_nd(
10089 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT],
10090 &new_triggers);
10091 if (err)
10092 goto error;
10093 }
10094
98fc4386
JB
10095 /* The 'any' trigger means the device continues operating more or less
10096 * as in its normal operation mode and wakes up the host on most of the
10097 * normal interrupts (like packet RX, ...)
10098 * It therefore makes little sense to combine with the more constrained
10099 * wakeup trigger modes.
10100 */
10101 if (new_triggers.any && regular) {
10102 err = -EINVAL;
10103 goto error;
10104 }
10105
ae33bd81
JB
10106 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
10107 if (!ntrig) {
10108 err = -ENOMEM;
10109 goto error;
ff1b6e69 10110 }
ae33bd81 10111 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 10112 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 10113
ae33bd81 10114 set_wakeup:
6abb9cb9
JB
10115 if (rdev->ops->set_wakeup &&
10116 prev_enabled != !!rdev->wiphy.wowlan_config)
10117 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 10118
ff1b6e69
JB
10119 return 0;
10120 error:
10121 for (i = 0; i < new_triggers.n_patterns; i++)
10122 kfree(new_triggers.patterns[i].mask);
10123 kfree(new_triggers.patterns);
2a0e047e
JB
10124 if (new_triggers.tcp && new_triggers.tcp->sock)
10125 sock_release(new_triggers.tcp->sock);
10126 kfree(new_triggers.tcp);
e5dbe070 10127 kfree(new_triggers.nd_config);
ff1b6e69
JB
10128 return err;
10129}
dfb89c56 10130#endif
ff1b6e69 10131
be29b99a
AK
10132static int nl80211_send_coalesce_rules(struct sk_buff *msg,
10133 struct cfg80211_registered_device *rdev)
10134{
10135 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
10136 int i, j, pat_len;
10137 struct cfg80211_coalesce_rules *rule;
10138
10139 if (!rdev->coalesce->n_rules)
10140 return 0;
10141
10142 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE);
10143 if (!nl_rules)
10144 return -ENOBUFS;
10145
10146 for (i = 0; i < rdev->coalesce->n_rules; i++) {
10147 nl_rule = nla_nest_start(msg, i + 1);
10148 if (!nl_rule)
10149 return -ENOBUFS;
10150
10151 rule = &rdev->coalesce->rules[i];
10152 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
10153 rule->delay))
10154 return -ENOBUFS;
10155
10156 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
10157 rule->condition))
10158 return -ENOBUFS;
10159
10160 nl_pats = nla_nest_start(msg,
10161 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
10162 if (!nl_pats)
10163 return -ENOBUFS;
10164
10165 for (j = 0; j < rule->n_patterns; j++) {
10166 nl_pat = nla_nest_start(msg, j + 1);
10167 if (!nl_pat)
10168 return -ENOBUFS;
10169 pat_len = rule->patterns[j].pattern_len;
10170 if (nla_put(msg, NL80211_PKTPAT_MASK,
10171 DIV_ROUND_UP(pat_len, 8),
10172 rule->patterns[j].mask) ||
10173 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
10174 rule->patterns[j].pattern) ||
10175 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
10176 rule->patterns[j].pkt_offset))
10177 return -ENOBUFS;
10178 nla_nest_end(msg, nl_pat);
10179 }
10180 nla_nest_end(msg, nl_pats);
10181 nla_nest_end(msg, nl_rule);
10182 }
10183 nla_nest_end(msg, nl_rules);
10184
10185 return 0;
10186}
10187
10188static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
10189{
10190 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10191 struct sk_buff *msg;
10192 void *hdr;
10193
10194 if (!rdev->wiphy.coalesce)
10195 return -EOPNOTSUPP;
10196
10197 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10198 if (!msg)
10199 return -ENOMEM;
10200
10201 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
10202 NL80211_CMD_GET_COALESCE);
10203 if (!hdr)
10204 goto nla_put_failure;
10205
10206 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
10207 goto nla_put_failure;
10208
10209 genlmsg_end(msg, hdr);
10210 return genlmsg_reply(msg, info);
10211
10212nla_put_failure:
10213 nlmsg_free(msg);
10214 return -ENOBUFS;
10215}
10216
10217void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
10218{
10219 struct cfg80211_coalesce *coalesce = rdev->coalesce;
10220 int i, j;
10221 struct cfg80211_coalesce_rules *rule;
10222
10223 if (!coalesce)
10224 return;
10225
10226 for (i = 0; i < coalesce->n_rules; i++) {
10227 rule = &coalesce->rules[i];
10228 for (j = 0; j < rule->n_patterns; j++)
10229 kfree(rule->patterns[j].mask);
10230 kfree(rule->patterns);
10231 }
10232 kfree(coalesce->rules);
10233 kfree(coalesce);
10234 rdev->coalesce = NULL;
10235}
10236
10237static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
10238 struct nlattr *rule,
10239 struct cfg80211_coalesce_rules *new_rule)
10240{
10241 int err, i;
10242 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
10243 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
10244 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
10245 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
10246
bfe2c7b1
JB
10247 err = nla_parse_nested(tb, NL80211_ATTR_COALESCE_RULE_MAX, rule,
10248 nl80211_coalesce_policy);
be29b99a
AK
10249 if (err)
10250 return err;
10251
10252 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
10253 new_rule->delay =
10254 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
10255 if (new_rule->delay > coalesce->max_delay)
10256 return -EINVAL;
10257
10258 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
10259 new_rule->condition =
10260 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
10261 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH &&
10262 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH)
10263 return -EINVAL;
10264
10265 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
10266 return -EINVAL;
10267
10268 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
10269 rem)
10270 n_patterns++;
10271 if (n_patterns > coalesce->n_patterns)
10272 return -EINVAL;
10273
10274 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
10275 GFP_KERNEL);
10276 if (!new_rule->patterns)
10277 return -ENOMEM;
10278
10279 new_rule->n_patterns = n_patterns;
10280 i = 0;
10281
10282 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
10283 rem) {
922bd80f
JB
10284 u8 *mask_pat;
10285
bfe2c7b1 10286 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, NULL);
be29b99a
AK
10287 if (!pat_tb[NL80211_PKTPAT_MASK] ||
10288 !pat_tb[NL80211_PKTPAT_PATTERN])
10289 return -EINVAL;
10290 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
10291 mask_len = DIV_ROUND_UP(pat_len, 8);
10292 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
10293 return -EINVAL;
10294 if (pat_len > coalesce->pattern_max_len ||
10295 pat_len < coalesce->pattern_min_len)
10296 return -EINVAL;
10297
10298 if (!pat_tb[NL80211_PKTPAT_OFFSET])
10299 pkt_offset = 0;
10300 else
10301 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
10302 if (pkt_offset > coalesce->max_pkt_offset)
10303 return -EINVAL;
10304 new_rule->patterns[i].pkt_offset = pkt_offset;
10305
922bd80f
JB
10306 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
10307 if (!mask_pat)
be29b99a 10308 return -ENOMEM;
922bd80f
JB
10309
10310 new_rule->patterns[i].mask = mask_pat;
10311 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
10312 mask_len);
10313
10314 mask_pat += mask_len;
10315 new_rule->patterns[i].pattern = mask_pat;
be29b99a 10316 new_rule->patterns[i].pattern_len = pat_len;
922bd80f
JB
10317 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
10318 pat_len);
be29b99a
AK
10319 i++;
10320 }
10321
10322 return 0;
10323}
10324
10325static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
10326{
10327 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10328 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
10329 struct cfg80211_coalesce new_coalesce = {};
10330 struct cfg80211_coalesce *n_coalesce;
10331 int err, rem_rule, n_rules = 0, i, j;
10332 struct nlattr *rule;
10333 struct cfg80211_coalesce_rules *tmp_rule;
10334
10335 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
10336 return -EOPNOTSUPP;
10337
10338 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
10339 cfg80211_rdev_free_coalesce(rdev);
a1056b1b 10340 rdev_set_coalesce(rdev, NULL);
be29b99a
AK
10341 return 0;
10342 }
10343
10344 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
10345 rem_rule)
10346 n_rules++;
10347 if (n_rules > coalesce->n_rules)
10348 return -EINVAL;
10349
10350 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
10351 GFP_KERNEL);
10352 if (!new_coalesce.rules)
10353 return -ENOMEM;
10354
10355 new_coalesce.n_rules = n_rules;
10356 i = 0;
10357
10358 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
10359 rem_rule) {
10360 err = nl80211_parse_coalesce_rule(rdev, rule,
10361 &new_coalesce.rules[i]);
10362 if (err)
10363 goto error;
10364
10365 i++;
10366 }
10367
a1056b1b 10368 err = rdev_set_coalesce(rdev, &new_coalesce);
be29b99a
AK
10369 if (err)
10370 goto error;
10371
10372 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
10373 if (!n_coalesce) {
10374 err = -ENOMEM;
10375 goto error;
10376 }
10377 cfg80211_rdev_free_coalesce(rdev);
10378 rdev->coalesce = n_coalesce;
10379
10380 return 0;
10381error:
10382 for (i = 0; i < new_coalesce.n_rules; i++) {
10383 tmp_rule = &new_coalesce.rules[i];
10384 for (j = 0; j < tmp_rule->n_patterns; j++)
10385 kfree(tmp_rule->patterns[j].mask);
10386 kfree(tmp_rule->patterns);
10387 }
10388 kfree(new_coalesce.rules);
10389
10390 return err;
10391}
10392
e5497d76
JB
10393static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
10394{
10395 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10396 struct net_device *dev = info->user_ptr[1];
10397 struct wireless_dev *wdev = dev->ieee80211_ptr;
10398 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
10399 struct cfg80211_gtk_rekey_data rekey_data;
10400 int err;
10401
10402 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
10403 return -EINVAL;
10404
bfe2c7b1
JB
10405 err = nla_parse_nested(tb, MAX_NL80211_REKEY_DATA,
10406 info->attrs[NL80211_ATTR_REKEY_DATA],
10407 nl80211_rekey_policy);
e5497d76
JB
10408 if (err)
10409 return err;
10410
10411 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
10412 return -ERANGE;
10413 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
10414 return -ERANGE;
10415 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
10416 return -ERANGE;
10417
78f686ca
JB
10418 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]);
10419 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]);
10420 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]);
e5497d76
JB
10421
10422 wdev_lock(wdev);
10423 if (!wdev->current_bss) {
10424 err = -ENOTCONN;
10425 goto out;
10426 }
10427
10428 if (!rdev->ops->set_rekey_data) {
10429 err = -EOPNOTSUPP;
10430 goto out;
10431 }
10432
e35e4d28 10433 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
10434 out:
10435 wdev_unlock(wdev);
10436 return err;
10437}
10438
28946da7
JB
10439static int nl80211_register_unexpected_frame(struct sk_buff *skb,
10440 struct genl_info *info)
10441{
10442 struct net_device *dev = info->user_ptr[1];
10443 struct wireless_dev *wdev = dev->ieee80211_ptr;
10444
10445 if (wdev->iftype != NL80211_IFTYPE_AP &&
10446 wdev->iftype != NL80211_IFTYPE_P2P_GO)
10447 return -EINVAL;
10448
15e47304 10449 if (wdev->ap_unexpected_nlportid)
28946da7
JB
10450 return -EBUSY;
10451
15e47304 10452 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
10453 return 0;
10454}
10455
7f6cf311
JB
10456static int nl80211_probe_client(struct sk_buff *skb,
10457 struct genl_info *info)
10458{
10459 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10460 struct net_device *dev = info->user_ptr[1];
10461 struct wireless_dev *wdev = dev->ieee80211_ptr;
10462 struct sk_buff *msg;
10463 void *hdr;
10464 const u8 *addr;
10465 u64 cookie;
10466 int err;
10467
10468 if (wdev->iftype != NL80211_IFTYPE_AP &&
10469 wdev->iftype != NL80211_IFTYPE_P2P_GO)
10470 return -EOPNOTSUPP;
10471
10472 if (!info->attrs[NL80211_ATTR_MAC])
10473 return -EINVAL;
10474
10475 if (!rdev->ops->probe_client)
10476 return -EOPNOTSUPP;
10477
10478 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10479 if (!msg)
10480 return -ENOMEM;
10481
15e47304 10482 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 10483 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
10484 if (!hdr) {
10485 err = -ENOBUFS;
7f6cf311
JB
10486 goto free_msg;
10487 }
10488
10489 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
10490
e35e4d28 10491 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
10492 if (err)
10493 goto free_msg;
10494
2dad624e
ND
10495 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
10496 NL80211_ATTR_PAD))
9360ffd1 10497 goto nla_put_failure;
7f6cf311
JB
10498
10499 genlmsg_end(msg, hdr);
10500
10501 return genlmsg_reply(msg, info);
10502
10503 nla_put_failure:
10504 err = -ENOBUFS;
10505 free_msg:
10506 nlmsg_free(msg);
10507 return err;
10508}
10509
5e760230
JB
10510static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
10511{
10512 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
10513 struct cfg80211_beacon_registration *reg, *nreg;
10514 int rv;
5e760230
JB
10515
10516 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
10517 return -EOPNOTSUPP;
10518
37c73b5f
BG
10519 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
10520 if (!nreg)
10521 return -ENOMEM;
10522
10523 /* First, check if already registered. */
10524 spin_lock_bh(&rdev->beacon_registrations_lock);
10525 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
10526 if (reg->nlportid == info->snd_portid) {
10527 rv = -EALREADY;
10528 goto out_err;
10529 }
10530 }
10531 /* Add it to the list */
10532 nreg->nlportid = info->snd_portid;
10533 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 10534
37c73b5f 10535 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
10536
10537 return 0;
37c73b5f
BG
10538out_err:
10539 spin_unlock_bh(&rdev->beacon_registrations_lock);
10540 kfree(nreg);
10541 return rv;
5e760230
JB
10542}
10543
98104fde
JB
10544static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
10545{
10546 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10547 struct wireless_dev *wdev = info->user_ptr[1];
10548 int err;
10549
10550 if (!rdev->ops->start_p2p_device)
10551 return -EOPNOTSUPP;
10552
10553 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
10554 return -EOPNOTSUPP;
10555
73c7da3d 10556 if (wdev_running(wdev))
98104fde
JB
10557 return 0;
10558
b6a55015
LC
10559 if (rfkill_blocked(rdev->rfkill))
10560 return -ERFKILL;
98104fde 10561
eeb126e9 10562 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
10563 if (err)
10564 return err;
10565
73c7da3d 10566 wdev->is_running = true;
98104fde 10567 rdev->opencount++;
98104fde
JB
10568
10569 return 0;
10570}
10571
10572static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
10573{
10574 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10575 struct wireless_dev *wdev = info->user_ptr[1];
10576
10577 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
10578 return -EOPNOTSUPP;
10579
10580 if (!rdev->ops->stop_p2p_device)
10581 return -EOPNOTSUPP;
10582
f9f47529 10583 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
10584
10585 return 0;
10586}
10587
cb3b7d87
AB
10588static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info)
10589{
10590 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10591 struct wireless_dev *wdev = info->user_ptr[1];
10592 struct cfg80211_nan_conf conf = {};
10593 int err;
10594
10595 if (wdev->iftype != NL80211_IFTYPE_NAN)
10596 return -EOPNOTSUPP;
10597
73c7da3d 10598 if (!wdev_running(wdev))
cb3b7d87
AB
10599 return -EEXIST;
10600
10601 if (rfkill_blocked(rdev->rfkill))
10602 return -ERFKILL;
10603
10604 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF])
10605 return -EINVAL;
10606
10607 if (!info->attrs[NL80211_ATTR_NAN_DUAL])
10608 return -EINVAL;
10609
10610 conf.master_pref =
10611 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
10612 if (!conf.master_pref)
10613 return -EINVAL;
10614
10615 conf.dual = nla_get_u8(info->attrs[NL80211_ATTR_NAN_DUAL]);
10616
10617 err = rdev_start_nan(rdev, wdev, &conf);
10618 if (err)
10619 return err;
10620
73c7da3d 10621 wdev->is_running = true;
cb3b7d87
AB
10622 rdev->opencount++;
10623
10624 return 0;
10625}
10626
10627static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info)
10628{
10629 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10630 struct wireless_dev *wdev = info->user_ptr[1];
10631
10632 if (wdev->iftype != NL80211_IFTYPE_NAN)
10633 return -EOPNOTSUPP;
10634
10635 cfg80211_stop_nan(rdev, wdev);
10636
10637 return 0;
10638}
10639
a442b761
AB
10640static int validate_nan_filter(struct nlattr *filter_attr)
10641{
10642 struct nlattr *attr;
10643 int len = 0, n_entries = 0, rem;
10644
10645 nla_for_each_nested(attr, filter_attr, rem) {
10646 len += nla_len(attr);
10647 n_entries++;
10648 }
10649
10650 if (len >= U8_MAX)
10651 return -EINVAL;
10652
10653 return n_entries;
10654}
10655
10656static int handle_nan_filter(struct nlattr *attr_filter,
10657 struct cfg80211_nan_func *func,
10658 bool tx)
10659{
10660 struct nlattr *attr;
10661 int n_entries, rem, i;
10662 struct cfg80211_nan_func_filter *filter;
10663
10664 n_entries = validate_nan_filter(attr_filter);
10665 if (n_entries < 0)
10666 return n_entries;
10667
10668 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters));
10669
10670 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL);
10671 if (!filter)
10672 return -ENOMEM;
10673
10674 i = 0;
10675 nla_for_each_nested(attr, attr_filter, rem) {
10676 filter[i].filter = kmemdup(nla_data(attr), nla_len(attr),
10677 GFP_KERNEL);
10678 filter[i].len = nla_len(attr);
10679 i++;
10680 }
10681 if (tx) {
10682 func->num_tx_filters = n_entries;
10683 func->tx_filters = filter;
10684 } else {
10685 func->num_rx_filters = n_entries;
10686 func->rx_filters = filter;
10687 }
10688
10689 return 0;
10690}
10691
10692static int nl80211_nan_add_func(struct sk_buff *skb,
10693 struct genl_info *info)
10694{
10695 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10696 struct wireless_dev *wdev = info->user_ptr[1];
10697 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr;
10698 struct cfg80211_nan_func *func;
10699 struct sk_buff *msg = NULL;
10700 void *hdr = NULL;
10701 int err = 0;
10702
10703 if (wdev->iftype != NL80211_IFTYPE_NAN)
10704 return -EOPNOTSUPP;
10705
73c7da3d 10706 if (!wdev_running(wdev))
a442b761
AB
10707 return -ENOTCONN;
10708
10709 if (!info->attrs[NL80211_ATTR_NAN_FUNC])
10710 return -EINVAL;
10711
10712 if (wdev->owner_nlportid &&
10713 wdev->owner_nlportid != info->snd_portid)
10714 return -ENOTCONN;
10715
bfe2c7b1
JB
10716 err = nla_parse_nested(tb, NL80211_NAN_FUNC_ATTR_MAX,
10717 info->attrs[NL80211_ATTR_NAN_FUNC],
10718 nl80211_nan_func_policy);
a442b761
AB
10719 if (err)
10720 return err;
10721
10722 func = kzalloc(sizeof(*func), GFP_KERNEL);
10723 if (!func)
10724 return -ENOMEM;
10725
10726 func->cookie = wdev->wiphy->cookie_counter++;
10727
10728 if (!tb[NL80211_NAN_FUNC_TYPE] ||
10729 nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]) > NL80211_NAN_FUNC_MAX_TYPE) {
10730 err = -EINVAL;
10731 goto out;
10732 }
10733
10734
10735 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]);
10736
10737 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) {
10738 err = -EINVAL;
10739 goto out;
10740 }
10741
10742 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]),
10743 sizeof(func->service_id));
10744
10745 func->close_range =
10746 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]);
10747
10748 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) {
10749 func->serv_spec_info_len =
10750 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]);
10751 func->serv_spec_info =
10752 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]),
10753 func->serv_spec_info_len,
10754 GFP_KERNEL);
10755 if (!func->serv_spec_info) {
10756 err = -ENOMEM;
10757 goto out;
10758 }
10759 }
10760
10761 if (tb[NL80211_NAN_FUNC_TTL])
10762 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]);
10763
10764 switch (func->type) {
10765 case NL80211_NAN_FUNC_PUBLISH:
10766 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) {
10767 err = -EINVAL;
10768 goto out;
10769 }
10770
10771 func->publish_type =
10772 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]);
10773 func->publish_bcast =
10774 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]);
10775
10776 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) &&
10777 func->publish_bcast) {
10778 err = -EINVAL;
10779 goto out;
10780 }
10781 break;
10782 case NL80211_NAN_FUNC_SUBSCRIBE:
10783 func->subscribe_active =
10784 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]);
10785 break;
10786 case NL80211_NAN_FUNC_FOLLOW_UP:
10787 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] ||
10788 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]) {
10789 err = -EINVAL;
10790 goto out;
10791 }
10792
10793 func->followup_id =
10794 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]);
10795 func->followup_reqid =
10796 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]);
10797 memcpy(func->followup_dest.addr,
10798 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]),
10799 sizeof(func->followup_dest.addr));
10800 if (func->ttl) {
10801 err = -EINVAL;
10802 goto out;
10803 }
10804 break;
10805 default:
10806 err = -EINVAL;
10807 goto out;
10808 }
10809
10810 if (tb[NL80211_NAN_FUNC_SRF]) {
10811 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR];
10812
bfe2c7b1
JB
10813 err = nla_parse_nested(srf_tb, NL80211_NAN_SRF_ATTR_MAX,
10814 tb[NL80211_NAN_FUNC_SRF],
10815 nl80211_nan_srf_policy);
a442b761
AB
10816 if (err)
10817 goto out;
10818
10819 func->srf_include =
10820 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]);
10821
10822 if (srf_tb[NL80211_NAN_SRF_BF]) {
10823 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] ||
10824 !srf_tb[NL80211_NAN_SRF_BF_IDX]) {
10825 err = -EINVAL;
10826 goto out;
10827 }
10828
10829 func->srf_bf_len =
10830 nla_len(srf_tb[NL80211_NAN_SRF_BF]);
10831 func->srf_bf =
10832 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]),
10833 func->srf_bf_len, GFP_KERNEL);
10834 if (!func->srf_bf) {
10835 err = -ENOMEM;
10836 goto out;
10837 }
10838
10839 func->srf_bf_idx =
10840 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]);
10841 } else {
10842 struct nlattr *attr, *mac_attr =
10843 srf_tb[NL80211_NAN_SRF_MAC_ADDRS];
10844 int n_entries, rem, i = 0;
10845
10846 if (!mac_attr) {
10847 err = -EINVAL;
10848 goto out;
10849 }
10850
10851 n_entries = validate_acl_mac_addrs(mac_attr);
10852 if (n_entries <= 0) {
10853 err = -EINVAL;
10854 goto out;
10855 }
10856
10857 func->srf_num_macs = n_entries;
10858 func->srf_macs =
10859 kzalloc(sizeof(*func->srf_macs) * n_entries,
10860 GFP_KERNEL);
10861 if (!func->srf_macs) {
10862 err = -ENOMEM;
10863 goto out;
10864 }
10865
10866 nla_for_each_nested(attr, mac_attr, rem)
10867 memcpy(func->srf_macs[i++].addr, nla_data(attr),
10868 sizeof(*func->srf_macs));
10869 }
10870 }
10871
10872 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) {
10873 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER],
10874 func, true);
10875 if (err)
10876 goto out;
10877 }
10878
10879 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) {
10880 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER],
10881 func, false);
10882 if (err)
10883 goto out;
10884 }
10885
10886 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10887 if (!msg) {
10888 err = -ENOMEM;
10889 goto out;
10890 }
10891
10892 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
10893 NL80211_CMD_ADD_NAN_FUNCTION);
10894 /* This can't really happen - we just allocated 4KB */
10895 if (WARN_ON(!hdr)) {
10896 err = -ENOMEM;
10897 goto out;
10898 }
10899
10900 err = rdev_add_nan_func(rdev, wdev, func);
10901out:
10902 if (err < 0) {
10903 cfg80211_free_nan_func(func);
10904 nlmsg_free(msg);
10905 return err;
10906 }
10907
10908 /* propagate the instance id and cookie to userspace */
10909 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie,
10910 NL80211_ATTR_PAD))
10911 goto nla_put_failure;
10912
10913 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC);
10914 if (!func_attr)
10915 goto nla_put_failure;
10916
10917 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID,
10918 func->instance_id))
10919 goto nla_put_failure;
10920
10921 nla_nest_end(msg, func_attr);
10922
10923 genlmsg_end(msg, hdr);
10924 return genlmsg_reply(msg, info);
10925
10926nla_put_failure:
10927 nlmsg_free(msg);
10928 return -ENOBUFS;
10929}
10930
10931static int nl80211_nan_del_func(struct sk_buff *skb,
10932 struct genl_info *info)
10933{
10934 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10935 struct wireless_dev *wdev = info->user_ptr[1];
10936 u64 cookie;
10937
10938 if (wdev->iftype != NL80211_IFTYPE_NAN)
10939 return -EOPNOTSUPP;
10940
73c7da3d 10941 if (!wdev_running(wdev))
a442b761
AB
10942 return -ENOTCONN;
10943
10944 if (!info->attrs[NL80211_ATTR_COOKIE])
10945 return -EINVAL;
10946
10947 if (wdev->owner_nlportid &&
10948 wdev->owner_nlportid != info->snd_portid)
10949 return -ENOTCONN;
10950
10951 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
10952
10953 rdev_del_nan_func(rdev, wdev, cookie);
10954
10955 return 0;
10956}
10957
a5a9dcf2
AB
10958static int nl80211_nan_change_config(struct sk_buff *skb,
10959 struct genl_info *info)
10960{
10961 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10962 struct wireless_dev *wdev = info->user_ptr[1];
10963 struct cfg80211_nan_conf conf = {};
10964 u32 changed = 0;
10965
10966 if (wdev->iftype != NL80211_IFTYPE_NAN)
10967 return -EOPNOTSUPP;
10968
73c7da3d 10969 if (!wdev_running(wdev))
a5a9dcf2
AB
10970 return -ENOTCONN;
10971
10972 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) {
10973 conf.master_pref =
10974 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
10975 if (conf.master_pref <= 1 || conf.master_pref == 255)
10976 return -EINVAL;
10977
10978 changed |= CFG80211_NAN_CONF_CHANGED_PREF;
10979 }
10980
10981 if (info->attrs[NL80211_ATTR_NAN_DUAL]) {
10982 conf.dual = nla_get_u8(info->attrs[NL80211_ATTR_NAN_DUAL]);
10983 changed |= CFG80211_NAN_CONF_CHANGED_DUAL;
10984 }
10985
10986 if (!changed)
10987 return -EINVAL;
10988
10989 return rdev_nan_change_conf(rdev, wdev, &conf, changed);
10990}
10991
50bcd31d
AB
10992void cfg80211_nan_match(struct wireless_dev *wdev,
10993 struct cfg80211_nan_match_params *match, gfp_t gfp)
10994{
10995 struct wiphy *wiphy = wdev->wiphy;
10996 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
10997 struct nlattr *match_attr, *local_func_attr, *peer_func_attr;
10998 struct sk_buff *msg;
10999 void *hdr;
11000
11001 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr))
11002 return;
11003
11004 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11005 if (!msg)
11006 return;
11007
11008 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH);
11009 if (!hdr) {
11010 nlmsg_free(msg);
11011 return;
11012 }
11013
11014 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11015 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11016 wdev->netdev->ifindex)) ||
11017 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
11018 NL80211_ATTR_PAD))
11019 goto nla_put_failure;
11020
11021 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie,
11022 NL80211_ATTR_PAD) ||
11023 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr))
11024 goto nla_put_failure;
11025
11026 match_attr = nla_nest_start(msg, NL80211_ATTR_NAN_MATCH);
11027 if (!match_attr)
11028 goto nla_put_failure;
11029
11030 local_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_LOCAL);
11031 if (!local_func_attr)
11032 goto nla_put_failure;
11033
11034 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id))
11035 goto nla_put_failure;
11036
11037 nla_nest_end(msg, local_func_attr);
11038
11039 peer_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_PEER);
11040 if (!peer_func_attr)
11041 goto nla_put_failure;
11042
11043 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) ||
11044 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id))
11045 goto nla_put_failure;
11046
11047 if (match->info && match->info_len &&
11048 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len,
11049 match->info))
11050 goto nla_put_failure;
11051
11052 nla_nest_end(msg, peer_func_attr);
11053 nla_nest_end(msg, match_attr);
11054 genlmsg_end(msg, hdr);
11055
11056 if (!wdev->owner_nlportid)
11057 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
11058 msg, 0, NL80211_MCGRP_NAN, gfp);
11059 else
11060 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
11061 wdev->owner_nlportid);
11062
11063 return;
11064
11065nla_put_failure:
11066 nlmsg_free(msg);
11067}
11068EXPORT_SYMBOL(cfg80211_nan_match);
11069
368e5a7b
AB
11070void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
11071 u8 inst_id,
11072 enum nl80211_nan_func_term_reason reason,
11073 u64 cookie, gfp_t gfp)
11074{
11075 struct wiphy *wiphy = wdev->wiphy;
11076 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
11077 struct sk_buff *msg;
11078 struct nlattr *func_attr;
11079 void *hdr;
11080
11081 if (WARN_ON(!inst_id))
11082 return;
11083
11084 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11085 if (!msg)
11086 return;
11087
11088 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION);
11089 if (!hdr) {
11090 nlmsg_free(msg);
11091 return;
11092 }
11093
11094 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11095 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11096 wdev->netdev->ifindex)) ||
11097 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
11098 NL80211_ATTR_PAD))
11099 goto nla_put_failure;
11100
11101 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
11102 NL80211_ATTR_PAD))
11103 goto nla_put_failure;
11104
11105 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC);
11106 if (!func_attr)
11107 goto nla_put_failure;
11108
11109 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) ||
11110 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason))
11111 goto nla_put_failure;
11112
11113 nla_nest_end(msg, func_attr);
11114 genlmsg_end(msg, hdr);
11115
11116 if (!wdev->owner_nlportid)
11117 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
11118 msg, 0, NL80211_MCGRP_NAN, gfp);
11119 else
11120 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
11121 wdev->owner_nlportid);
11122
11123 return;
11124
11125nla_put_failure:
11126 nlmsg_free(msg);
11127}
11128EXPORT_SYMBOL(cfg80211_nan_func_terminated);
11129
3713b4e3
JB
11130static int nl80211_get_protocol_features(struct sk_buff *skb,
11131 struct genl_info *info)
11132{
11133 void *hdr;
11134 struct sk_buff *msg;
11135
11136 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11137 if (!msg)
11138 return -ENOMEM;
11139
11140 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
11141 NL80211_CMD_GET_PROTOCOL_FEATURES);
11142 if (!hdr)
11143 goto nla_put_failure;
11144
11145 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
11146 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
11147 goto nla_put_failure;
11148
11149 genlmsg_end(msg, hdr);
11150 return genlmsg_reply(msg, info);
11151
11152 nla_put_failure:
11153 kfree_skb(msg);
11154 return -ENOBUFS;
11155}
11156
355199e0
JM
11157static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
11158{
11159 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11160 struct cfg80211_update_ft_ies_params ft_params;
11161 struct net_device *dev = info->user_ptr[1];
11162
11163 if (!rdev->ops->update_ft_ies)
11164 return -EOPNOTSUPP;
11165
11166 if (!info->attrs[NL80211_ATTR_MDID] ||
11167 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
11168 return -EINVAL;
11169
11170 memset(&ft_params, 0, sizeof(ft_params));
11171 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
11172 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11173 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11174
11175 return rdev_update_ft_ies(rdev, dev, &ft_params);
11176}
11177
5de17984
AS
11178static int nl80211_crit_protocol_start(struct sk_buff *skb,
11179 struct genl_info *info)
11180{
11181 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11182 struct wireless_dev *wdev = info->user_ptr[1];
11183 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
11184 u16 duration;
11185 int ret;
11186
11187 if (!rdev->ops->crit_proto_start)
11188 return -EOPNOTSUPP;
11189
11190 if (WARN_ON(!rdev->ops->crit_proto_stop))
11191 return -EINVAL;
11192
11193 if (rdev->crit_proto_nlportid)
11194 return -EBUSY;
11195
11196 /* determine protocol if provided */
11197 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
11198 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
11199
11200 if (proto >= NUM_NL80211_CRIT_PROTO)
11201 return -EINVAL;
11202
11203 /* timeout must be provided */
11204 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
11205 return -EINVAL;
11206
11207 duration =
11208 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
11209
11210 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
11211 return -ERANGE;
11212
11213 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
11214 if (!ret)
11215 rdev->crit_proto_nlportid = info->snd_portid;
11216
11217 return ret;
11218}
11219
11220static int nl80211_crit_protocol_stop(struct sk_buff *skb,
11221 struct genl_info *info)
11222{
11223 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11224 struct wireless_dev *wdev = info->user_ptr[1];
11225
11226 if (!rdev->ops->crit_proto_stop)
11227 return -EOPNOTSUPP;
11228
11229 if (rdev->crit_proto_nlportid) {
11230 rdev->crit_proto_nlportid = 0;
11231 rdev_crit_proto_stop(rdev, wdev);
11232 }
11233 return 0;
11234}
11235
ad7e718c
JB
11236static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
11237{
11238 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11239 struct wireless_dev *wdev =
11240 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
11241 int i, err;
11242 u32 vid, subcmd;
11243
11244 if (!rdev->wiphy.vendor_commands)
11245 return -EOPNOTSUPP;
11246
11247 if (IS_ERR(wdev)) {
11248 err = PTR_ERR(wdev);
11249 if (err != -EINVAL)
11250 return err;
11251 wdev = NULL;
11252 } else if (wdev->wiphy != &rdev->wiphy) {
11253 return -EINVAL;
11254 }
11255
11256 if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
11257 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
11258 return -EINVAL;
11259
11260 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
11261 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
11262 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
11263 const struct wiphy_vendor_command *vcmd;
11264 void *data = NULL;
11265 int len = 0;
11266
11267 vcmd = &rdev->wiphy.vendor_commands[i];
11268
11269 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
11270 continue;
11271
11272 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
11273 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
11274 if (!wdev)
11275 return -EINVAL;
11276 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
11277 !wdev->netdev)
11278 return -EINVAL;
11279
11280 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
73c7da3d 11281 if (!wdev_running(wdev))
ad7e718c
JB
11282 return -ENETDOWN;
11283 }
7bdbe400
JB
11284
11285 if (!vcmd->doit)
11286 return -EOPNOTSUPP;
ad7e718c
JB
11287 } else {
11288 wdev = NULL;
11289 }
11290
11291 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
11292 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
11293 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
11294 }
11295
11296 rdev->cur_cmd_info = info;
11297 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev,
11298 data, len);
11299 rdev->cur_cmd_info = NULL;
11300 return err;
11301 }
11302
11303 return -EOPNOTSUPP;
11304}
11305
7bdbe400
JB
11306static int nl80211_prepare_vendor_dump(struct sk_buff *skb,
11307 struct netlink_callback *cb,
11308 struct cfg80211_registered_device **rdev,
11309 struct wireless_dev **wdev)
11310{
11311 u32 vid, subcmd;
11312 unsigned int i;
11313 int vcmd_idx = -1;
11314 int err;
11315 void *data = NULL;
11316 unsigned int data_len = 0;
11317
11318 rtnl_lock();
11319
11320 if (cb->args[0]) {
11321 /* subtract the 1 again here */
11322 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
11323 struct wireless_dev *tmp;
11324
11325 if (!wiphy) {
11326 err = -ENODEV;
11327 goto out_unlock;
11328 }
11329 *rdev = wiphy_to_rdev(wiphy);
11330 *wdev = NULL;
11331
11332 if (cb->args[1]) {
53873f13 11333 list_for_each_entry(tmp, &wiphy->wdev_list, list) {
7bdbe400
JB
11334 if (tmp->identifier == cb->args[1] - 1) {
11335 *wdev = tmp;
11336 break;
11337 }
11338 }
11339 }
11340
11341 /* keep rtnl locked in successful case */
11342 return 0;
11343 }
11344
11345 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
11346 nl80211_fam.attrbuf, nl80211_fam.maxattr,
11347 nl80211_policy);
11348 if (err)
11349 goto out_unlock;
11350
11351 if (!nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_ID] ||
11352 !nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) {
11353 err = -EINVAL;
11354 goto out_unlock;
11355 }
11356
11357 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
11358 nl80211_fam.attrbuf);
11359 if (IS_ERR(*wdev))
11360 *wdev = NULL;
11361
11362 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
11363 nl80211_fam.attrbuf);
11364 if (IS_ERR(*rdev)) {
11365 err = PTR_ERR(*rdev);
11366 goto out_unlock;
11367 }
11368
11369 vid = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_ID]);
11370 subcmd = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_SUBCMD]);
11371
11372 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) {
11373 const struct wiphy_vendor_command *vcmd;
11374
11375 vcmd = &(*rdev)->wiphy.vendor_commands[i];
11376
11377 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
11378 continue;
11379
11380 if (!vcmd->dumpit) {
11381 err = -EOPNOTSUPP;
11382 goto out_unlock;
11383 }
11384
11385 vcmd_idx = i;
11386 break;
11387 }
11388
11389 if (vcmd_idx < 0) {
11390 err = -EOPNOTSUPP;
11391 goto out_unlock;
11392 }
11393
11394 if (nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_DATA]) {
11395 data = nla_data(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_DATA]);
11396 data_len = nla_len(nl80211_fam.attrbuf[NL80211_ATTR_VENDOR_DATA]);
11397 }
11398
11399 /* 0 is the first index - add 1 to parse only once */
11400 cb->args[0] = (*rdev)->wiphy_idx + 1;
11401 /* add 1 to know if it was NULL */
11402 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0;
11403 cb->args[2] = vcmd_idx;
11404 cb->args[3] = (unsigned long)data;
11405 cb->args[4] = data_len;
11406
11407 /* keep rtnl locked in successful case */
11408 return 0;
11409 out_unlock:
11410 rtnl_unlock();
11411 return err;
11412}
11413
11414static int nl80211_vendor_cmd_dump(struct sk_buff *skb,
11415 struct netlink_callback *cb)
11416{
11417 struct cfg80211_registered_device *rdev;
11418 struct wireless_dev *wdev;
11419 unsigned int vcmd_idx;
11420 const struct wiphy_vendor_command *vcmd;
11421 void *data;
11422 int data_len;
11423 int err;
11424 struct nlattr *vendor_data;
11425
11426 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev);
11427 if (err)
11428 return err;
11429
11430 vcmd_idx = cb->args[2];
11431 data = (void *)cb->args[3];
11432 data_len = cb->args[4];
11433 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx];
11434
11435 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
11436 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
11437 if (!wdev)
11438 return -EINVAL;
11439 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
11440 !wdev->netdev)
11441 return -EINVAL;
11442
11443 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
73c7da3d 11444 if (!wdev_running(wdev))
7bdbe400
JB
11445 return -ENETDOWN;
11446 }
11447 }
11448
11449 while (1) {
11450 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
11451 cb->nlh->nlmsg_seq, NLM_F_MULTI,
11452 NL80211_CMD_VENDOR);
11453 if (!hdr)
11454 break;
11455
11456 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
11457 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
11458 wdev_id(wdev),
11459 NL80211_ATTR_PAD))) {
7bdbe400
JB
11460 genlmsg_cancel(skb, hdr);
11461 break;
11462 }
11463
11464 vendor_data = nla_nest_start(skb, NL80211_ATTR_VENDOR_DATA);
11465 if (!vendor_data) {
11466 genlmsg_cancel(skb, hdr);
11467 break;
11468 }
11469
11470 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len,
11471 (unsigned long *)&cb->args[5]);
11472 nla_nest_end(skb, vendor_data);
11473
11474 if (err == -ENOBUFS || err == -ENOENT) {
11475 genlmsg_cancel(skb, hdr);
11476 break;
11477 } else if (err) {
11478 genlmsg_cancel(skb, hdr);
11479 goto out;
11480 }
11481
11482 genlmsg_end(skb, hdr);
11483 }
11484
11485 err = skb->len;
11486 out:
11487 rtnl_unlock();
11488 return err;
11489}
11490
ad7e718c
JB
11491struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
11492 enum nl80211_commands cmd,
11493 enum nl80211_attrs attr,
11494 int approxlen)
11495{
f26cbf40 11496 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ad7e718c
JB
11497
11498 if (WARN_ON(!rdev->cur_cmd_info))
11499 return NULL;
11500
6c09e791 11501 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen,
ad7e718c
JB
11502 rdev->cur_cmd_info->snd_portid,
11503 rdev->cur_cmd_info->snd_seq,
567ffc35 11504 cmd, attr, NULL, GFP_KERNEL);
ad7e718c
JB
11505}
11506EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
11507
11508int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
11509{
11510 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
11511 void *hdr = ((void **)skb->cb)[1];
11512 struct nlattr *data = ((void **)skb->cb)[2];
11513
bd8c78e7
JB
11514 /* clear CB data for netlink core to own from now on */
11515 memset(skb->cb, 0, sizeof(skb->cb));
11516
ad7e718c
JB
11517 if (WARN_ON(!rdev->cur_cmd_info)) {
11518 kfree_skb(skb);
11519 return -EINVAL;
11520 }
11521
11522 nla_nest_end(skb, data);
11523 genlmsg_end(skb, hdr);
11524 return genlmsg_reply(skb, rdev->cur_cmd_info);
11525}
11526EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
11527
fa9ffc74
KP
11528static int nl80211_set_qos_map(struct sk_buff *skb,
11529 struct genl_info *info)
11530{
11531 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11532 struct cfg80211_qos_map *qos_map = NULL;
11533 struct net_device *dev = info->user_ptr[1];
11534 u8 *pos, len, num_des, des_len, des;
11535 int ret;
11536
11537 if (!rdev->ops->set_qos_map)
11538 return -EOPNOTSUPP;
11539
11540 if (info->attrs[NL80211_ATTR_QOS_MAP]) {
11541 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
11542 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
11543
11544 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN ||
11545 len > IEEE80211_QOS_MAP_LEN_MAX)
11546 return -EINVAL;
11547
11548 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
11549 if (!qos_map)
11550 return -ENOMEM;
11551
11552 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
11553 if (num_des) {
11554 des_len = num_des *
11555 sizeof(struct cfg80211_dscp_exception);
11556 memcpy(qos_map->dscp_exception, pos, des_len);
11557 qos_map->num_des = num_des;
11558 for (des = 0; des < num_des; des++) {
11559 if (qos_map->dscp_exception[des].up > 7) {
11560 kfree(qos_map);
11561 return -EINVAL;
11562 }
11563 }
11564 pos += des_len;
11565 }
11566 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
11567 }
11568
11569 wdev_lock(dev->ieee80211_ptr);
11570 ret = nl80211_key_allowed(dev->ieee80211_ptr);
11571 if (!ret)
11572 ret = rdev_set_qos_map(rdev, dev, qos_map);
11573 wdev_unlock(dev->ieee80211_ptr);
11574
11575 kfree(qos_map);
11576 return ret;
11577}
11578
960d01ac
JB
11579static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info)
11580{
11581 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11582 struct net_device *dev = info->user_ptr[1];
11583 struct wireless_dev *wdev = dev->ieee80211_ptr;
11584 const u8 *peer;
11585 u8 tsid, up;
11586 u16 admitted_time = 0;
11587 int err;
11588
723e73ac 11589 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION))
960d01ac
JB
11590 return -EOPNOTSUPP;
11591
11592 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] ||
11593 !info->attrs[NL80211_ATTR_USER_PRIO])
11594 return -EINVAL;
11595
11596 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
11597 if (tsid >= IEEE80211_NUM_TIDS)
11598 return -EINVAL;
11599
11600 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]);
11601 if (up >= IEEE80211_NUM_UPS)
11602 return -EINVAL;
11603
11604 /* WMM uses TIDs 0-7 even for TSPEC */
723e73ac 11605 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) {
960d01ac 11606 /* TODO: handle 802.11 TSPEC/admission control
723e73ac
JB
11607 * need more attributes for that (e.g. BA session requirement);
11608 * change the WMM adminssion test above to allow both then
960d01ac
JB
11609 */
11610 return -EINVAL;
11611 }
11612
11613 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
11614
11615 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) {
11616 admitted_time =
11617 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]);
11618 if (!admitted_time)
11619 return -EINVAL;
11620 }
11621
11622 wdev_lock(wdev);
11623 switch (wdev->iftype) {
11624 case NL80211_IFTYPE_STATION:
11625 case NL80211_IFTYPE_P2P_CLIENT:
11626 if (wdev->current_bss)
11627 break;
11628 err = -ENOTCONN;
11629 goto out;
11630 default:
11631 err = -EOPNOTSUPP;
11632 goto out;
11633 }
11634
11635 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time);
11636
11637 out:
11638 wdev_unlock(wdev);
11639 return err;
11640}
11641
11642static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info)
11643{
11644 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11645 struct net_device *dev = info->user_ptr[1];
11646 struct wireless_dev *wdev = dev->ieee80211_ptr;
11647 const u8 *peer;
11648 u8 tsid;
11649 int err;
11650
11651 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC])
11652 return -EINVAL;
11653
11654 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
11655 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
11656
11657 wdev_lock(wdev);
11658 err = rdev_del_tx_ts(rdev, dev, tsid, peer);
11659 wdev_unlock(wdev);
11660
11661 return err;
11662}
11663
1057d35e
AN
11664static int nl80211_tdls_channel_switch(struct sk_buff *skb,
11665 struct genl_info *info)
11666{
11667 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11668 struct net_device *dev = info->user_ptr[1];
11669 struct wireless_dev *wdev = dev->ieee80211_ptr;
11670 struct cfg80211_chan_def chandef = {};
11671 const u8 *addr;
11672 u8 oper_class;
11673 int err;
11674
11675 if (!rdev->ops->tdls_channel_switch ||
11676 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
11677 return -EOPNOTSUPP;
11678
11679 switch (dev->ieee80211_ptr->iftype) {
11680 case NL80211_IFTYPE_STATION:
11681 case NL80211_IFTYPE_P2P_CLIENT:
11682 break;
11683 default:
11684 return -EOPNOTSUPP;
11685 }
11686
11687 if (!info->attrs[NL80211_ATTR_MAC] ||
11688 !info->attrs[NL80211_ATTR_OPER_CLASS])
11689 return -EINVAL;
11690
11691 err = nl80211_parse_chandef(rdev, info, &chandef);
11692 if (err)
11693 return err;
11694
11695 /*
11696 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012
11697 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the
11698 * specification is not defined for them.
11699 */
57fbcce3 11700 if (chandef.chan->band == NL80211_BAND_2GHZ &&
1057d35e
AN
11701 chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
11702 chandef.width != NL80211_CHAN_WIDTH_20)
11703 return -EINVAL;
11704
11705 /* we will be active on the TDLS link */
923b352f
AN
11706 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
11707 wdev->iftype))
1057d35e
AN
11708 return -EINVAL;
11709
11710 /* don't allow switching to DFS channels */
11711 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype))
11712 return -EINVAL;
11713
11714 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
11715 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]);
11716
11717 wdev_lock(wdev);
11718 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef);
11719 wdev_unlock(wdev);
11720
11721 return err;
11722}
11723
11724static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb,
11725 struct genl_info *info)
11726{
11727 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11728 struct net_device *dev = info->user_ptr[1];
11729 struct wireless_dev *wdev = dev->ieee80211_ptr;
11730 const u8 *addr;
11731
11732 if (!rdev->ops->tdls_channel_switch ||
11733 !rdev->ops->tdls_cancel_channel_switch ||
11734 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
11735 return -EOPNOTSUPP;
11736
11737 switch (dev->ieee80211_ptr->iftype) {
11738 case NL80211_IFTYPE_STATION:
11739 case NL80211_IFTYPE_P2P_CLIENT:
11740 break;
11741 default:
11742 return -EOPNOTSUPP;
11743 }
11744
11745 if (!info->attrs[NL80211_ATTR_MAC])
11746 return -EINVAL;
11747
11748 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
11749
11750 wdev_lock(wdev);
11751 rdev_tdls_cancel_channel_switch(rdev, dev, addr);
11752 wdev_unlock(wdev);
11753
11754 return 0;
11755}
11756
4c476991
JB
11757#define NL80211_FLAG_NEED_WIPHY 0x01
11758#define NL80211_FLAG_NEED_NETDEV 0x02
11759#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
11760#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
11761#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
11762 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 11763#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 11764/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
11765#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
11766 NL80211_FLAG_CHECK_NETDEV_UP)
5393b917 11767#define NL80211_FLAG_CLEAR_SKB 0x20
4c476991 11768
f84f771d 11769static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
11770 struct genl_info *info)
11771{
11772 struct cfg80211_registered_device *rdev;
89a54e48 11773 struct wireless_dev *wdev;
4c476991 11774 struct net_device *dev;
4c476991
JB
11775 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
11776
11777 if (rtnl)
11778 rtnl_lock();
11779
11780 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 11781 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
11782 if (IS_ERR(rdev)) {
11783 if (rtnl)
11784 rtnl_unlock();
11785 return PTR_ERR(rdev);
11786 }
11787 info->user_ptr[0] = rdev;
1bf614ef
JB
11788 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
11789 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
11790 ASSERT_RTNL();
11791
89a54e48
JB
11792 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
11793 info->attrs);
11794 if (IS_ERR(wdev)) {
4c476991
JB
11795 if (rtnl)
11796 rtnl_unlock();
89a54e48 11797 return PTR_ERR(wdev);
4c476991 11798 }
89a54e48 11799
89a54e48 11800 dev = wdev->netdev;
f26cbf40 11801 rdev = wiphy_to_rdev(wdev->wiphy);
89a54e48 11802
1bf614ef
JB
11803 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
11804 if (!dev) {
1bf614ef
JB
11805 if (rtnl)
11806 rtnl_unlock();
11807 return -EINVAL;
11808 }
11809
11810 info->user_ptr[1] = dev;
11811 } else {
11812 info->user_ptr[1] = wdev;
41265714 11813 }
1bf614ef 11814
73c7da3d
AVS
11815 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
11816 !wdev_running(wdev)) {
11817 if (rtnl)
11818 rtnl_unlock();
11819 return -ENETDOWN;
11820 }
1bf614ef 11821
73c7da3d 11822 if (dev)
1bf614ef 11823 dev_hold(dev);
89a54e48 11824
4c476991 11825 info->user_ptr[0] = rdev;
4c476991
JB
11826 }
11827
11828 return 0;
11829}
11830
f84f771d 11831static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
11832 struct genl_info *info)
11833{
1bf614ef
JB
11834 if (info->user_ptr[1]) {
11835 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
11836 struct wireless_dev *wdev = info->user_ptr[1];
11837
11838 if (wdev->netdev)
11839 dev_put(wdev->netdev);
11840 } else {
11841 dev_put(info->user_ptr[1]);
11842 }
11843 }
5393b917 11844
4c476991
JB
11845 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
11846 rtnl_unlock();
5393b917
JB
11847
11848 /* If needed, clear the netlink message payload from the SKB
11849 * as it might contain key data that shouldn't stick around on
11850 * the heap after the SKB is freed. The netlink message header
11851 * is still needed for further processing, so leave it intact.
11852 */
11853 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) {
11854 struct nlmsghdr *nlh = nlmsg_hdr(skb);
11855
11856 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh));
11857 }
4c476991
JB
11858}
11859
4534de83 11860static const struct genl_ops nl80211_ops[] = {
55682965
JB
11861 {
11862 .cmd = NL80211_CMD_GET_WIPHY,
11863 .doit = nl80211_get_wiphy,
11864 .dumpit = nl80211_dump_wiphy,
86e8cf98 11865 .done = nl80211_dump_wiphy_done,
55682965
JB
11866 .policy = nl80211_policy,
11867 /* can be retrieved by unprivileged users */
5fe231e8
JB
11868 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11869 NL80211_FLAG_NEED_RTNL,
55682965
JB
11870 },
11871 {
11872 .cmd = NL80211_CMD_SET_WIPHY,
11873 .doit = nl80211_set_wiphy,
11874 .policy = nl80211_policy,
5617c6cd 11875 .flags = GENL_UNS_ADMIN_PERM,
4c476991 11876 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
11877 },
11878 {
11879 .cmd = NL80211_CMD_GET_INTERFACE,
11880 .doit = nl80211_get_interface,
11881 .dumpit = nl80211_dump_interface,
11882 .policy = nl80211_policy,
11883 /* can be retrieved by unprivileged users */
5fe231e8
JB
11884 .internal_flags = NL80211_FLAG_NEED_WDEV |
11885 NL80211_FLAG_NEED_RTNL,
55682965
JB
11886 },
11887 {
11888 .cmd = NL80211_CMD_SET_INTERFACE,
11889 .doit = nl80211_set_interface,
11890 .policy = nl80211_policy,
5617c6cd 11891 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
11892 .internal_flags = NL80211_FLAG_NEED_NETDEV |
11893 NL80211_FLAG_NEED_RTNL,
55682965
JB
11894 },
11895 {
11896 .cmd = NL80211_CMD_NEW_INTERFACE,
11897 .doit = nl80211_new_interface,
11898 .policy = nl80211_policy,
5617c6cd 11899 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
11900 .internal_flags = NL80211_FLAG_NEED_WIPHY |
11901 NL80211_FLAG_NEED_RTNL,
55682965
JB
11902 },
11903 {
11904 .cmd = NL80211_CMD_DEL_INTERFACE,
11905 .doit = nl80211_del_interface,
11906 .policy = nl80211_policy,
5617c6cd 11907 .flags = GENL_UNS_ADMIN_PERM,
84efbb84 11908 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 11909 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
11910 },
11911 {
11912 .cmd = NL80211_CMD_GET_KEY,
11913 .doit = nl80211_get_key,
11914 .policy = nl80211_policy,
5617c6cd 11915 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 11916 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11917 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
11918 },
11919 {
11920 .cmd = NL80211_CMD_SET_KEY,
11921 .doit = nl80211_set_key,
11922 .policy = nl80211_policy,
5617c6cd 11923 .flags = GENL_UNS_ADMIN_PERM,
41265714 11924 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
11925 NL80211_FLAG_NEED_RTNL |
11926 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
11927 },
11928 {
11929 .cmd = NL80211_CMD_NEW_KEY,
11930 .doit = nl80211_new_key,
11931 .policy = nl80211_policy,
5617c6cd 11932 .flags = GENL_UNS_ADMIN_PERM,
41265714 11933 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
11934 NL80211_FLAG_NEED_RTNL |
11935 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
11936 },
11937 {
11938 .cmd = NL80211_CMD_DEL_KEY,
11939 .doit = nl80211_del_key,
11940 .policy = nl80211_policy,
5617c6cd 11941 .flags = GENL_UNS_ADMIN_PERM,
41265714 11942 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11943 NL80211_FLAG_NEED_RTNL,
55682965 11944 },
ed1b6cc7
JB
11945 {
11946 .cmd = NL80211_CMD_SET_BEACON,
11947 .policy = nl80211_policy,
5617c6cd 11948 .flags = GENL_UNS_ADMIN_PERM,
8860020e 11949 .doit = nl80211_set_beacon,
2b5f8b0b 11950 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11951 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
11952 },
11953 {
8860020e 11954 .cmd = NL80211_CMD_START_AP,
ed1b6cc7 11955 .policy = nl80211_policy,
5617c6cd 11956 .flags = GENL_UNS_ADMIN_PERM,
8860020e 11957 .doit = nl80211_start_ap,
2b5f8b0b 11958 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11959 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
11960 },
11961 {
8860020e 11962 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7 11963 .policy = nl80211_policy,
5617c6cd 11964 .flags = GENL_UNS_ADMIN_PERM,
8860020e 11965 .doit = nl80211_stop_ap,
2b5f8b0b 11966 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11967 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 11968 },
5727ef1b
JB
11969 {
11970 .cmd = NL80211_CMD_GET_STATION,
11971 .doit = nl80211_get_station,
2ec600d6 11972 .dumpit = nl80211_dump_station,
5727ef1b 11973 .policy = nl80211_policy,
4c476991
JB
11974 .internal_flags = NL80211_FLAG_NEED_NETDEV |
11975 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
11976 },
11977 {
11978 .cmd = NL80211_CMD_SET_STATION,
11979 .doit = nl80211_set_station,
11980 .policy = nl80211_policy,
5617c6cd 11981 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 11982 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11983 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
11984 },
11985 {
11986 .cmd = NL80211_CMD_NEW_STATION,
11987 .doit = nl80211_new_station,
11988 .policy = nl80211_policy,
5617c6cd 11989 .flags = GENL_UNS_ADMIN_PERM,
41265714 11990 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11991 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
11992 },
11993 {
11994 .cmd = NL80211_CMD_DEL_STATION,
11995 .doit = nl80211_del_station,
11996 .policy = nl80211_policy,
5617c6cd 11997 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 11998 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 11999 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
12000 },
12001 {
12002 .cmd = NL80211_CMD_GET_MPATH,
12003 .doit = nl80211_get_mpath,
12004 .dumpit = nl80211_dump_mpath,
12005 .policy = nl80211_policy,
5617c6cd 12006 .flags = GENL_UNS_ADMIN_PERM,
41265714 12007 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12008 NL80211_FLAG_NEED_RTNL,
2ec600d6 12009 },
66be7d2b
HR
12010 {
12011 .cmd = NL80211_CMD_GET_MPP,
12012 .doit = nl80211_get_mpp,
12013 .dumpit = nl80211_dump_mpp,
12014 .policy = nl80211_policy,
5617c6cd 12015 .flags = GENL_UNS_ADMIN_PERM,
66be7d2b
HR
12016 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12017 NL80211_FLAG_NEED_RTNL,
12018 },
2ec600d6
LCC
12019 {
12020 .cmd = NL80211_CMD_SET_MPATH,
12021 .doit = nl80211_set_mpath,
12022 .policy = nl80211_policy,
5617c6cd 12023 .flags = GENL_UNS_ADMIN_PERM,
41265714 12024 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12025 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
12026 },
12027 {
12028 .cmd = NL80211_CMD_NEW_MPATH,
12029 .doit = nl80211_new_mpath,
12030 .policy = nl80211_policy,
5617c6cd 12031 .flags = GENL_UNS_ADMIN_PERM,
41265714 12032 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12033 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
12034 },
12035 {
12036 .cmd = NL80211_CMD_DEL_MPATH,
12037 .doit = nl80211_del_mpath,
12038 .policy = nl80211_policy,
5617c6cd 12039 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12040 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12041 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
12042 },
12043 {
12044 .cmd = NL80211_CMD_SET_BSS,
12045 .doit = nl80211_set_bss,
12046 .policy = nl80211_policy,
5617c6cd 12047 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12048 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12049 NL80211_FLAG_NEED_RTNL,
b2e1b302 12050 },
f130347c
LR
12051 {
12052 .cmd = NL80211_CMD_GET_REG,
ad30ca2c
AN
12053 .doit = nl80211_get_reg_do,
12054 .dumpit = nl80211_get_reg_dump,
f130347c 12055 .policy = nl80211_policy,
5fe231e8 12056 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
12057 /* can be retrieved by unprivileged users */
12058 },
b6863036 12059#ifdef CONFIG_CFG80211_CRDA_SUPPORT
b2e1b302
LR
12060 {
12061 .cmd = NL80211_CMD_SET_REG,
12062 .doit = nl80211_set_reg,
12063 .policy = nl80211_policy,
12064 .flags = GENL_ADMIN_PERM,
5fe231e8 12065 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302 12066 },
b6863036 12067#endif
b2e1b302
LR
12068 {
12069 .cmd = NL80211_CMD_REQ_SET_REG,
12070 .doit = nl80211_req_set_reg,
12071 .policy = nl80211_policy,
93da9cc1 12072 .flags = GENL_ADMIN_PERM,
12073 },
12074 {
24bdd9f4
JC
12075 .cmd = NL80211_CMD_GET_MESH_CONFIG,
12076 .doit = nl80211_get_mesh_config,
93da9cc1 12077 .policy = nl80211_policy,
12078 /* can be retrieved by unprivileged users */
2b5f8b0b 12079 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12080 NL80211_FLAG_NEED_RTNL,
93da9cc1 12081 },
12082 {
24bdd9f4
JC
12083 .cmd = NL80211_CMD_SET_MESH_CONFIG,
12084 .doit = nl80211_update_mesh_config,
93da9cc1 12085 .policy = nl80211_policy,
5617c6cd 12086 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c 12087 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12088 NL80211_FLAG_NEED_RTNL,
9aed3cc1 12089 },
2a519311
JB
12090 {
12091 .cmd = NL80211_CMD_TRIGGER_SCAN,
12092 .doit = nl80211_trigger_scan,
12093 .policy = nl80211_policy,
5617c6cd 12094 .flags = GENL_UNS_ADMIN_PERM,
fd014284 12095 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 12096 NL80211_FLAG_NEED_RTNL,
2a519311 12097 },
91d3ab46
VK
12098 {
12099 .cmd = NL80211_CMD_ABORT_SCAN,
12100 .doit = nl80211_abort_scan,
12101 .policy = nl80211_policy,
5617c6cd 12102 .flags = GENL_UNS_ADMIN_PERM,
91d3ab46
VK
12103 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12104 NL80211_FLAG_NEED_RTNL,
12105 },
2a519311
JB
12106 {
12107 .cmd = NL80211_CMD_GET_SCAN,
12108 .policy = nl80211_policy,
12109 .dumpit = nl80211_dump_scan,
12110 },
807f8a8c
LC
12111 {
12112 .cmd = NL80211_CMD_START_SCHED_SCAN,
12113 .doit = nl80211_start_sched_scan,
12114 .policy = nl80211_policy,
5617c6cd 12115 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
12116 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12117 NL80211_FLAG_NEED_RTNL,
12118 },
12119 {
12120 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
12121 .doit = nl80211_stop_sched_scan,
12122 .policy = nl80211_policy,
5617c6cd 12123 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
12124 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12125 NL80211_FLAG_NEED_RTNL,
12126 },
636a5d36
JM
12127 {
12128 .cmd = NL80211_CMD_AUTHENTICATE,
12129 .doit = nl80211_authenticate,
12130 .policy = nl80211_policy,
5617c6cd 12131 .flags = GENL_UNS_ADMIN_PERM,
41265714 12132 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
12133 NL80211_FLAG_NEED_RTNL |
12134 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
12135 },
12136 {
12137 .cmd = NL80211_CMD_ASSOCIATE,
12138 .doit = nl80211_associate,
12139 .policy = nl80211_policy,
5617c6cd 12140 .flags = GENL_UNS_ADMIN_PERM,
41265714 12141 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12142 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
12143 },
12144 {
12145 .cmd = NL80211_CMD_DEAUTHENTICATE,
12146 .doit = nl80211_deauthenticate,
12147 .policy = nl80211_policy,
5617c6cd 12148 .flags = GENL_UNS_ADMIN_PERM,
41265714 12149 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12150 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
12151 },
12152 {
12153 .cmd = NL80211_CMD_DISASSOCIATE,
12154 .doit = nl80211_disassociate,
12155 .policy = nl80211_policy,
5617c6cd 12156 .flags = GENL_UNS_ADMIN_PERM,
41265714 12157 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12158 NL80211_FLAG_NEED_RTNL,
636a5d36 12159 },
04a773ad
JB
12160 {
12161 .cmd = NL80211_CMD_JOIN_IBSS,
12162 .doit = nl80211_join_ibss,
12163 .policy = nl80211_policy,
5617c6cd 12164 .flags = GENL_UNS_ADMIN_PERM,
41265714 12165 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12166 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
12167 },
12168 {
12169 .cmd = NL80211_CMD_LEAVE_IBSS,
12170 .doit = nl80211_leave_ibss,
12171 .policy = nl80211_policy,
5617c6cd 12172 .flags = GENL_UNS_ADMIN_PERM,
41265714 12173 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12174 NL80211_FLAG_NEED_RTNL,
04a773ad 12175 },
aff89a9b
JB
12176#ifdef CONFIG_NL80211_TESTMODE
12177 {
12178 .cmd = NL80211_CMD_TESTMODE,
12179 .doit = nl80211_testmode_do,
71063f0e 12180 .dumpit = nl80211_testmode_dump,
aff89a9b 12181 .policy = nl80211_policy,
5617c6cd 12182 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12183 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12184 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
12185 },
12186#endif
b23aa676
SO
12187 {
12188 .cmd = NL80211_CMD_CONNECT,
12189 .doit = nl80211_connect,
12190 .policy = nl80211_policy,
5617c6cd 12191 .flags = GENL_UNS_ADMIN_PERM,
41265714 12192 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12193 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
12194 },
12195 {
12196 .cmd = NL80211_CMD_DISCONNECT,
12197 .doit = nl80211_disconnect,
12198 .policy = nl80211_policy,
5617c6cd 12199 .flags = GENL_UNS_ADMIN_PERM,
41265714 12200 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12201 NL80211_FLAG_NEED_RTNL,
b23aa676 12202 },
463d0183
JB
12203 {
12204 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
12205 .doit = nl80211_wiphy_netns,
12206 .policy = nl80211_policy,
5617c6cd 12207 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12208 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12209 NL80211_FLAG_NEED_RTNL,
463d0183 12210 },
61fa713c
HS
12211 {
12212 .cmd = NL80211_CMD_GET_SURVEY,
12213 .policy = nl80211_policy,
12214 .dumpit = nl80211_dump_survey,
12215 },
67fbb16b
SO
12216 {
12217 .cmd = NL80211_CMD_SET_PMKSA,
12218 .doit = nl80211_setdel_pmksa,
12219 .policy = nl80211_policy,
5617c6cd 12220 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12221 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12222 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
12223 },
12224 {
12225 .cmd = NL80211_CMD_DEL_PMKSA,
12226 .doit = nl80211_setdel_pmksa,
12227 .policy = nl80211_policy,
5617c6cd 12228 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12229 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12230 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
12231 },
12232 {
12233 .cmd = NL80211_CMD_FLUSH_PMKSA,
12234 .doit = nl80211_flush_pmksa,
12235 .policy = nl80211_policy,
5617c6cd 12236 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12237 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12238 NL80211_FLAG_NEED_RTNL,
67fbb16b 12239 },
9588bbd5
JM
12240 {
12241 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
12242 .doit = nl80211_remain_on_channel,
12243 .policy = nl80211_policy,
5617c6cd 12244 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 12245 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 12246 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
12247 },
12248 {
12249 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
12250 .doit = nl80211_cancel_remain_on_channel,
12251 .policy = nl80211_policy,
5617c6cd 12252 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 12253 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 12254 NL80211_FLAG_NEED_RTNL,
9588bbd5 12255 },
13ae75b1
JM
12256 {
12257 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
12258 .doit = nl80211_set_tx_bitrate_mask,
12259 .policy = nl80211_policy,
5617c6cd 12260 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12261 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12262 NL80211_FLAG_NEED_RTNL,
13ae75b1 12263 },
026331c4 12264 {
2e161f78
JB
12265 .cmd = NL80211_CMD_REGISTER_FRAME,
12266 .doit = nl80211_register_mgmt,
026331c4 12267 .policy = nl80211_policy,
5617c6cd 12268 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 12269 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 12270 NL80211_FLAG_NEED_RTNL,
026331c4
JM
12271 },
12272 {
2e161f78
JB
12273 .cmd = NL80211_CMD_FRAME,
12274 .doit = nl80211_tx_mgmt,
026331c4 12275 .policy = nl80211_policy,
5617c6cd 12276 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 12277 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
12278 NL80211_FLAG_NEED_RTNL,
12279 },
12280 {
12281 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
12282 .doit = nl80211_tx_mgmt_cancel_wait,
12283 .policy = nl80211_policy,
5617c6cd 12284 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 12285 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 12286 NL80211_FLAG_NEED_RTNL,
026331c4 12287 },
ffb9eb3d
KV
12288 {
12289 .cmd = NL80211_CMD_SET_POWER_SAVE,
12290 .doit = nl80211_set_power_save,
12291 .policy = nl80211_policy,
5617c6cd 12292 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12293 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12294 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
12295 },
12296 {
12297 .cmd = NL80211_CMD_GET_POWER_SAVE,
12298 .doit = nl80211_get_power_save,
12299 .policy = nl80211_policy,
12300 /* can be retrieved by unprivileged users */
4c476991
JB
12301 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12302 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 12303 },
d6dc1a38
JO
12304 {
12305 .cmd = NL80211_CMD_SET_CQM,
12306 .doit = nl80211_set_cqm,
12307 .policy = nl80211_policy,
5617c6cd 12308 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12309 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12310 NL80211_FLAG_NEED_RTNL,
d6dc1a38 12311 },
f444de05
JB
12312 {
12313 .cmd = NL80211_CMD_SET_CHANNEL,
12314 .doit = nl80211_set_channel,
12315 .policy = nl80211_policy,
5617c6cd 12316 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12317 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12318 NL80211_FLAG_NEED_RTNL,
f444de05 12319 },
e8347eba
BJ
12320 {
12321 .cmd = NL80211_CMD_SET_WDS_PEER,
12322 .doit = nl80211_set_wds_peer,
12323 .policy = nl80211_policy,
5617c6cd 12324 .flags = GENL_UNS_ADMIN_PERM,
43b19952
JB
12325 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12326 NL80211_FLAG_NEED_RTNL,
e8347eba 12327 },
29cbe68c
JB
12328 {
12329 .cmd = NL80211_CMD_JOIN_MESH,
12330 .doit = nl80211_join_mesh,
12331 .policy = nl80211_policy,
5617c6cd 12332 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
12333 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12334 NL80211_FLAG_NEED_RTNL,
12335 },
12336 {
12337 .cmd = NL80211_CMD_LEAVE_MESH,
12338 .doit = nl80211_leave_mesh,
12339 .policy = nl80211_policy,
5617c6cd 12340 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
12341 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12342 NL80211_FLAG_NEED_RTNL,
12343 },
6e0bd6c3
RL
12344 {
12345 .cmd = NL80211_CMD_JOIN_OCB,
12346 .doit = nl80211_join_ocb,
12347 .policy = nl80211_policy,
5617c6cd 12348 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
12349 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12350 NL80211_FLAG_NEED_RTNL,
12351 },
12352 {
12353 .cmd = NL80211_CMD_LEAVE_OCB,
12354 .doit = nl80211_leave_ocb,
12355 .policy = nl80211_policy,
5617c6cd 12356 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
12357 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12358 NL80211_FLAG_NEED_RTNL,
12359 },
dfb89c56 12360#ifdef CONFIG_PM
ff1b6e69
JB
12361 {
12362 .cmd = NL80211_CMD_GET_WOWLAN,
12363 .doit = nl80211_get_wowlan,
12364 .policy = nl80211_policy,
12365 /* can be retrieved by unprivileged users */
12366 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12367 NL80211_FLAG_NEED_RTNL,
12368 },
12369 {
12370 .cmd = NL80211_CMD_SET_WOWLAN,
12371 .doit = nl80211_set_wowlan,
12372 .policy = nl80211_policy,
5617c6cd 12373 .flags = GENL_UNS_ADMIN_PERM,
ff1b6e69
JB
12374 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12375 NL80211_FLAG_NEED_RTNL,
12376 },
dfb89c56 12377#endif
e5497d76
JB
12378 {
12379 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
12380 .doit = nl80211_set_rekey_data,
12381 .policy = nl80211_policy,
5617c6cd 12382 .flags = GENL_UNS_ADMIN_PERM,
e5497d76 12383 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
12384 NL80211_FLAG_NEED_RTNL |
12385 NL80211_FLAG_CLEAR_SKB,
e5497d76 12386 },
109086ce
AN
12387 {
12388 .cmd = NL80211_CMD_TDLS_MGMT,
12389 .doit = nl80211_tdls_mgmt,
12390 .policy = nl80211_policy,
5617c6cd 12391 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
12392 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12393 NL80211_FLAG_NEED_RTNL,
12394 },
12395 {
12396 .cmd = NL80211_CMD_TDLS_OPER,
12397 .doit = nl80211_tdls_oper,
12398 .policy = nl80211_policy,
5617c6cd 12399 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
12400 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12401 NL80211_FLAG_NEED_RTNL,
12402 },
28946da7
JB
12403 {
12404 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
12405 .doit = nl80211_register_unexpected_frame,
12406 .policy = nl80211_policy,
5617c6cd 12407 .flags = GENL_UNS_ADMIN_PERM,
28946da7
JB
12408 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12409 NL80211_FLAG_NEED_RTNL,
12410 },
7f6cf311
JB
12411 {
12412 .cmd = NL80211_CMD_PROBE_CLIENT,
12413 .doit = nl80211_probe_client,
12414 .policy = nl80211_policy,
5617c6cd 12415 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12416 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
12417 NL80211_FLAG_NEED_RTNL,
12418 },
5e760230
JB
12419 {
12420 .cmd = NL80211_CMD_REGISTER_BEACONS,
12421 .doit = nl80211_register_beacons,
12422 .policy = nl80211_policy,
5617c6cd 12423 .flags = GENL_UNS_ADMIN_PERM,
5e760230
JB
12424 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12425 NL80211_FLAG_NEED_RTNL,
12426 },
1d9d9213
SW
12427 {
12428 .cmd = NL80211_CMD_SET_NOACK_MAP,
12429 .doit = nl80211_set_noack_map,
12430 .policy = nl80211_policy,
5617c6cd 12431 .flags = GENL_UNS_ADMIN_PERM,
1d9d9213
SW
12432 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12433 NL80211_FLAG_NEED_RTNL,
12434 },
98104fde
JB
12435 {
12436 .cmd = NL80211_CMD_START_P2P_DEVICE,
12437 .doit = nl80211_start_p2p_device,
12438 .policy = nl80211_policy,
5617c6cd 12439 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
12440 .internal_flags = NL80211_FLAG_NEED_WDEV |
12441 NL80211_FLAG_NEED_RTNL,
12442 },
12443 {
12444 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
12445 .doit = nl80211_stop_p2p_device,
12446 .policy = nl80211_policy,
5617c6cd 12447 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
12448 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12449 NL80211_FLAG_NEED_RTNL,
cb3b7d87
AB
12450 },
12451 {
12452 .cmd = NL80211_CMD_START_NAN,
12453 .doit = nl80211_start_nan,
12454 .policy = nl80211_policy,
12455 .flags = GENL_ADMIN_PERM,
12456 .internal_flags = NL80211_FLAG_NEED_WDEV |
12457 NL80211_FLAG_NEED_RTNL,
12458 },
12459 {
12460 .cmd = NL80211_CMD_STOP_NAN,
12461 .doit = nl80211_stop_nan,
12462 .policy = nl80211_policy,
12463 .flags = GENL_ADMIN_PERM,
12464 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12465 NL80211_FLAG_NEED_RTNL,
a442b761
AB
12466 },
12467 {
12468 .cmd = NL80211_CMD_ADD_NAN_FUNCTION,
12469 .doit = nl80211_nan_add_func,
12470 .policy = nl80211_policy,
12471 .flags = GENL_ADMIN_PERM,
12472 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12473 NL80211_FLAG_NEED_RTNL,
12474 },
12475 {
12476 .cmd = NL80211_CMD_DEL_NAN_FUNCTION,
12477 .doit = nl80211_nan_del_func,
12478 .policy = nl80211_policy,
12479 .flags = GENL_ADMIN_PERM,
12480 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12481 NL80211_FLAG_NEED_RTNL,
a5a9dcf2
AB
12482 },
12483 {
12484 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG,
12485 .doit = nl80211_nan_change_config,
12486 .policy = nl80211_policy,
12487 .flags = GENL_ADMIN_PERM,
12488 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12489 NL80211_FLAG_NEED_RTNL,
98104fde 12490 },
f4e583c8
AQ
12491 {
12492 .cmd = NL80211_CMD_SET_MCAST_RATE,
12493 .doit = nl80211_set_mcast_rate,
77765eaf 12494 .policy = nl80211_policy,
5617c6cd 12495 .flags = GENL_UNS_ADMIN_PERM,
77765eaf
VT
12496 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12497 NL80211_FLAG_NEED_RTNL,
12498 },
12499 {
12500 .cmd = NL80211_CMD_SET_MAC_ACL,
12501 .doit = nl80211_set_mac_acl,
f4e583c8 12502 .policy = nl80211_policy,
5617c6cd 12503 .flags = GENL_UNS_ADMIN_PERM,
f4e583c8
AQ
12504 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12505 NL80211_FLAG_NEED_RTNL,
12506 },
04f39047
SW
12507 {
12508 .cmd = NL80211_CMD_RADAR_DETECT,
12509 .doit = nl80211_start_radar_detection,
12510 .policy = nl80211_policy,
5617c6cd 12511 .flags = GENL_UNS_ADMIN_PERM,
04f39047
SW
12512 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12513 NL80211_FLAG_NEED_RTNL,
12514 },
3713b4e3
JB
12515 {
12516 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
12517 .doit = nl80211_get_protocol_features,
12518 .policy = nl80211_policy,
12519 },
355199e0
JM
12520 {
12521 .cmd = NL80211_CMD_UPDATE_FT_IES,
12522 .doit = nl80211_update_ft_ies,
12523 .policy = nl80211_policy,
5617c6cd 12524 .flags = GENL_UNS_ADMIN_PERM,
355199e0
JM
12525 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12526 NL80211_FLAG_NEED_RTNL,
12527 },
5de17984
AS
12528 {
12529 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
12530 .doit = nl80211_crit_protocol_start,
12531 .policy = nl80211_policy,
5617c6cd 12532 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
12533 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12534 NL80211_FLAG_NEED_RTNL,
12535 },
12536 {
12537 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
12538 .doit = nl80211_crit_protocol_stop,
12539 .policy = nl80211_policy,
5617c6cd 12540 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
12541 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12542 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
12543 },
12544 {
12545 .cmd = NL80211_CMD_GET_COALESCE,
12546 .doit = nl80211_get_coalesce,
12547 .policy = nl80211_policy,
12548 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12549 NL80211_FLAG_NEED_RTNL,
12550 },
12551 {
12552 .cmd = NL80211_CMD_SET_COALESCE,
12553 .doit = nl80211_set_coalesce,
12554 .policy = nl80211_policy,
5617c6cd 12555 .flags = GENL_UNS_ADMIN_PERM,
be29b99a
AK
12556 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12557 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
12558 },
12559 {
12560 .cmd = NL80211_CMD_CHANNEL_SWITCH,
12561 .doit = nl80211_channel_switch,
12562 .policy = nl80211_policy,
5617c6cd 12563 .flags = GENL_UNS_ADMIN_PERM,
16ef1fe2
SW
12564 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12565 NL80211_FLAG_NEED_RTNL,
12566 },
ad7e718c
JB
12567 {
12568 .cmd = NL80211_CMD_VENDOR,
12569 .doit = nl80211_vendor_cmd,
7bdbe400 12570 .dumpit = nl80211_vendor_cmd_dump,
ad7e718c 12571 .policy = nl80211_policy,
5617c6cd 12572 .flags = GENL_UNS_ADMIN_PERM,
ad7e718c
JB
12573 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12574 NL80211_FLAG_NEED_RTNL,
12575 },
fa9ffc74
KP
12576 {
12577 .cmd = NL80211_CMD_SET_QOS_MAP,
12578 .doit = nl80211_set_qos_map,
12579 .policy = nl80211_policy,
5617c6cd 12580 .flags = GENL_UNS_ADMIN_PERM,
fa9ffc74
KP
12581 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12582 NL80211_FLAG_NEED_RTNL,
12583 },
960d01ac
JB
12584 {
12585 .cmd = NL80211_CMD_ADD_TX_TS,
12586 .doit = nl80211_add_tx_ts,
12587 .policy = nl80211_policy,
5617c6cd 12588 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
12589 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12590 NL80211_FLAG_NEED_RTNL,
12591 },
12592 {
12593 .cmd = NL80211_CMD_DEL_TX_TS,
12594 .doit = nl80211_del_tx_ts,
12595 .policy = nl80211_policy,
5617c6cd 12596 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
12597 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12598 NL80211_FLAG_NEED_RTNL,
12599 },
1057d35e
AN
12600 {
12601 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH,
12602 .doit = nl80211_tdls_channel_switch,
12603 .policy = nl80211_policy,
5617c6cd 12604 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
12605 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12606 NL80211_FLAG_NEED_RTNL,
12607 },
12608 {
12609 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH,
12610 .doit = nl80211_tdls_cancel_channel_switch,
12611 .policy = nl80211_policy,
5617c6cd 12612 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
12613 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12614 NL80211_FLAG_NEED_RTNL,
12615 },
55682965 12616};
9588bbd5 12617
55682965
JB
12618/* notification functions */
12619
3bb20556
JB
12620void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev,
12621 enum nl80211_commands cmd)
55682965
JB
12622{
12623 struct sk_buff *msg;
86e8cf98 12624 struct nl80211_dump_wiphy_state state = {};
55682965 12625
3bb20556
JB
12626 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY &&
12627 cmd != NL80211_CMD_DEL_WIPHY);
12628
fd2120ca 12629 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
12630 if (!msg)
12631 return;
12632
3bb20556 12633 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) {
55682965
JB
12634 nlmsg_free(msg);
12635 return;
12636 }
12637
68eb5503 12638 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12639 NL80211_MCGRP_CONFIG, GFP_KERNEL);
55682965
JB
12640}
12641
896ff063
DK
12642void nl80211_notify_iface(struct cfg80211_registered_device *rdev,
12643 struct wireless_dev *wdev,
12644 enum nl80211_commands cmd)
12645{
12646 struct sk_buff *msg;
12647
12648 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE &&
12649 cmd != NL80211_CMD_DEL_INTERFACE);
12650
12651 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12652 if (!msg)
12653 return;
12654
12655 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev,
12656 cmd == NL80211_CMD_DEL_INTERFACE) < 0) {
12657 nlmsg_free(msg);
12658 return;
12659 }
12660
12661 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
12662 NL80211_MCGRP_CONFIG, GFP_KERNEL);
12663}
12664
362a415d
JB
12665static int nl80211_add_scan_req(struct sk_buff *msg,
12666 struct cfg80211_registered_device *rdev)
12667{
12668 struct cfg80211_scan_request *req = rdev->scan_req;
12669 struct nlattr *nest;
12670 int i;
12671
12672 if (WARN_ON(!req))
12673 return 0;
12674
12675 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
12676 if (!nest)
12677 goto nla_put_failure;
9360ffd1
DM
12678 for (i = 0; i < req->n_ssids; i++) {
12679 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
12680 goto nla_put_failure;
12681 }
362a415d
JB
12682 nla_nest_end(msg, nest);
12683
12684 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
12685 if (!nest)
12686 goto nla_put_failure;
9360ffd1
DM
12687 for (i = 0; i < req->n_channels; i++) {
12688 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
12689 goto nla_put_failure;
12690 }
362a415d
JB
12691 nla_nest_end(msg, nest);
12692
9360ffd1
DM
12693 if (req->ie &&
12694 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
12695 goto nla_put_failure;
362a415d 12696
ae917c9f
JB
12697 if (req->flags &&
12698 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
12699 goto nla_put_failure;
ed473771 12700
1d76250b
AS
12701 if (req->info.scan_start_tsf &&
12702 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF,
12703 req->info.scan_start_tsf, NL80211_BSS_PAD) ||
12704 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN,
12705 req->info.tsf_bssid)))
12706 goto nla_put_failure;
12707
362a415d
JB
12708 return 0;
12709 nla_put_failure:
12710 return -ENOBUFS;
12711}
12712
a538e2d5
JB
12713static int nl80211_send_scan_msg(struct sk_buff *msg,
12714 struct cfg80211_registered_device *rdev,
fd014284 12715 struct wireless_dev *wdev,
15e47304 12716 u32 portid, u32 seq, int flags,
a538e2d5 12717 u32 cmd)
2a519311
JB
12718{
12719 void *hdr;
12720
15e47304 12721 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
12722 if (!hdr)
12723 return -1;
12724
9360ffd1 12725 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
12726 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
12727 wdev->netdev->ifindex)) ||
2dad624e
ND
12728 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
12729 NL80211_ATTR_PAD))
9360ffd1 12730 goto nla_put_failure;
2a519311 12731
362a415d
JB
12732 /* ignore errors and send incomplete event anyway */
12733 nl80211_add_scan_req(msg, rdev);
2a519311 12734
053c095a
JB
12735 genlmsg_end(msg, hdr);
12736 return 0;
2a519311
JB
12737
12738 nla_put_failure:
12739 genlmsg_cancel(msg, hdr);
12740 return -EMSGSIZE;
12741}
12742
807f8a8c
LC
12743static int
12744nl80211_send_sched_scan_msg(struct sk_buff *msg,
12745 struct cfg80211_registered_device *rdev,
12746 struct net_device *netdev,
15e47304 12747 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
12748{
12749 void *hdr;
12750
15e47304 12751 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
12752 if (!hdr)
12753 return -1;
12754
9360ffd1
DM
12755 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12756 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
12757 goto nla_put_failure;
807f8a8c 12758
053c095a
JB
12759 genlmsg_end(msg, hdr);
12760 return 0;
807f8a8c
LC
12761
12762 nla_put_failure:
12763 genlmsg_cancel(msg, hdr);
12764 return -EMSGSIZE;
12765}
12766
a538e2d5 12767void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 12768 struct wireless_dev *wdev)
a538e2d5
JB
12769{
12770 struct sk_buff *msg;
12771
58050fce 12772 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
12773 if (!msg)
12774 return;
12775
fd014284 12776 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
12777 NL80211_CMD_TRIGGER_SCAN) < 0) {
12778 nlmsg_free(msg);
12779 return;
12780 }
12781
68eb5503 12782 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12783 NL80211_MCGRP_SCAN, GFP_KERNEL);
a538e2d5
JB
12784}
12785
f9d15d16
JB
12786struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev,
12787 struct wireless_dev *wdev, bool aborted)
2a519311
JB
12788{
12789 struct sk_buff *msg;
12790
fd2120ca 12791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311 12792 if (!msg)
f9d15d16 12793 return NULL;
2a519311 12794
fd014284 12795 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
f9d15d16
JB
12796 aborted ? NL80211_CMD_SCAN_ABORTED :
12797 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311 12798 nlmsg_free(msg);
f9d15d16 12799 return NULL;
2a519311
JB
12800 }
12801
f9d15d16 12802 return msg;
2a519311
JB
12803}
12804
f9d15d16
JB
12805void nl80211_send_scan_result(struct cfg80211_registered_device *rdev,
12806 struct sk_buff *msg)
2a519311 12807{
2a519311
JB
12808 if (!msg)
12809 return;
12810
68eb5503 12811 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12812 NL80211_MCGRP_SCAN, GFP_KERNEL);
2a519311
JB
12813}
12814
807f8a8c
LC
12815void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
12816 struct net_device *netdev)
12817{
12818 struct sk_buff *msg;
12819
12820 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12821 if (!msg)
12822 return;
12823
12824 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
12825 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
12826 nlmsg_free(msg);
12827 return;
12828 }
12829
68eb5503 12830 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12831 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
12832}
12833
12834void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
12835 struct net_device *netdev, u32 cmd)
12836{
12837 struct sk_buff *msg;
12838
58050fce 12839 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
12840 if (!msg)
12841 return;
12842
12843 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
12844 nlmsg_free(msg);
12845 return;
12846 }
12847
68eb5503 12848 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12849 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
12850}
12851
b0d7aa59
JD
12852static bool nl80211_reg_change_event_fill(struct sk_buff *msg,
12853 struct regulatory_request *request)
73d54c9e 12854{
73d54c9e 12855 /* Userspace can always count this one always being set */
9360ffd1
DM
12856 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
12857 goto nla_put_failure;
12858
12859 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
12860 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
12861 NL80211_REGDOM_TYPE_WORLD))
12862 goto nla_put_failure;
12863 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
12864 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
12865 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
12866 goto nla_put_failure;
12867 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
12868 request->intersect) {
12869 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
12870 NL80211_REGDOM_TYPE_INTERSECTION))
12871 goto nla_put_failure;
12872 } else {
12873 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
12874 NL80211_REGDOM_TYPE_COUNTRY) ||
12875 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
12876 request->alpha2))
12877 goto nla_put_failure;
12878 }
12879
ad30ca2c
AN
12880 if (request->wiphy_idx != WIPHY_IDX_INVALID) {
12881 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx);
12882
12883 if (wiphy &&
12884 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
12885 goto nla_put_failure;
1bdd716c
AN
12886
12887 if (wiphy &&
12888 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
12889 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
12890 goto nla_put_failure;
ad30ca2c 12891 }
73d54c9e 12892
b0d7aa59
JD
12893 return true;
12894
12895nla_put_failure:
12896 return false;
12897}
12898
12899/*
12900 * This can happen on global regulatory changes or device specific settings
12901 * based on custom regulatory domains.
12902 */
12903void nl80211_common_reg_change_event(enum nl80211_commands cmd_id,
12904 struct regulatory_request *request)
12905{
12906 struct sk_buff *msg;
12907 void *hdr;
12908
12909 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12910 if (!msg)
12911 return;
12912
12913 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id);
12914 if (!hdr) {
12915 nlmsg_free(msg);
12916 return;
12917 }
12918
12919 if (nl80211_reg_change_event_fill(msg, request) == false)
12920 goto nla_put_failure;
12921
3b7b72ee 12922 genlmsg_end(msg, hdr);
73d54c9e 12923
bc43b28c 12924 rcu_read_lock();
68eb5503 12925 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 12926 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
bc43b28c 12927 rcu_read_unlock();
73d54c9e
LR
12928
12929 return;
12930
12931nla_put_failure:
12932 genlmsg_cancel(msg, hdr);
12933 nlmsg_free(msg);
12934}
12935
6039f6d2
JM
12936static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
12937 struct net_device *netdev,
12938 const u8 *buf, size_t len,
b0b6aa2c
EP
12939 enum nl80211_commands cmd, gfp_t gfp,
12940 int uapsd_queues)
6039f6d2
JM
12941{
12942 struct sk_buff *msg;
12943 void *hdr;
12944
e6d6e342 12945 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
12946 if (!msg)
12947 return;
12948
12949 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
12950 if (!hdr) {
12951 nlmsg_free(msg);
12952 return;
12953 }
12954
9360ffd1
DM
12955 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12956 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
12957 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
12958 goto nla_put_failure;
6039f6d2 12959
b0b6aa2c
EP
12960 if (uapsd_queues >= 0) {
12961 struct nlattr *nla_wmm =
12962 nla_nest_start(msg, NL80211_ATTR_STA_WME);
12963 if (!nla_wmm)
12964 goto nla_put_failure;
12965
12966 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
12967 uapsd_queues))
12968 goto nla_put_failure;
12969
12970 nla_nest_end(msg, nla_wmm);
12971 }
12972
3b7b72ee 12973 genlmsg_end(msg, hdr);
6039f6d2 12974
68eb5503 12975 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 12976 NL80211_MCGRP_MLME, gfp);
6039f6d2
JM
12977 return;
12978
12979 nla_put_failure:
12980 genlmsg_cancel(msg, hdr);
12981 nlmsg_free(msg);
12982}
12983
12984void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
12985 struct net_device *netdev, const u8 *buf,
12986 size_t len, gfp_t gfp)
6039f6d2
JM
12987{
12988 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 12989 NL80211_CMD_AUTHENTICATE, gfp, -1);
6039f6d2
JM
12990}
12991
12992void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
12993 struct net_device *netdev, const u8 *buf,
b0b6aa2c 12994 size_t len, gfp_t gfp, int uapsd_queues)
6039f6d2 12995{
e6d6e342 12996 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 12997 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues);
6039f6d2
JM
12998}
12999
53b46b84 13000void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13001 struct net_device *netdev, const u8 *buf,
13002 size_t len, gfp_t gfp)
6039f6d2
JM
13003{
13004 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 13005 NL80211_CMD_DEAUTHENTICATE, gfp, -1);
6039f6d2
JM
13006}
13007
53b46b84
JM
13008void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
13009 struct net_device *netdev, const u8 *buf,
e6d6e342 13010 size_t len, gfp_t gfp)
6039f6d2
JM
13011{
13012 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 13013 NL80211_CMD_DISASSOCIATE, gfp, -1);
6039f6d2
JM
13014}
13015
6ff57cf8
JB
13016void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
13017 size_t len)
cf4e594e 13018{
947add36
JB
13019 struct wireless_dev *wdev = dev->ieee80211_ptr;
13020 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13021 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
6ff57cf8
JB
13022 const struct ieee80211_mgmt *mgmt = (void *)buf;
13023 u32 cmd;
947add36 13024
6ff57cf8
JB
13025 if (WARN_ON(len < 2))
13026 return;
cf4e594e 13027
6ff57cf8
JB
13028 if (ieee80211_is_deauth(mgmt->frame_control))
13029 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
13030 else
13031 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 13032
6ff57cf8 13033 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
b0b6aa2c 13034 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1);
cf4e594e 13035}
6ff57cf8 13036EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 13037
1b06bb40
LR
13038static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
13039 struct net_device *netdev, int cmd,
e6d6e342 13040 const u8 *addr, gfp_t gfp)
1965c853
JM
13041{
13042 struct sk_buff *msg;
13043 void *hdr;
13044
e6d6e342 13045 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
13046 if (!msg)
13047 return;
13048
13049 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
13050 if (!hdr) {
13051 nlmsg_free(msg);
13052 return;
13053 }
13054
9360ffd1
DM
13055 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13056 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13057 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
13058 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
13059 goto nla_put_failure;
1965c853 13060
3b7b72ee 13061 genlmsg_end(msg, hdr);
1965c853 13062
68eb5503 13063 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13064 NL80211_MCGRP_MLME, gfp);
1965c853
JM
13065 return;
13066
13067 nla_put_failure:
13068 genlmsg_cancel(msg, hdr);
13069 nlmsg_free(msg);
13070}
13071
13072void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13073 struct net_device *netdev, const u8 *addr,
13074 gfp_t gfp)
1965c853
JM
13075{
13076 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 13077 addr, gfp);
1965c853
JM
13078}
13079
13080void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13081 struct net_device *netdev, const u8 *addr,
13082 gfp_t gfp)
1965c853 13083{
e6d6e342
JB
13084 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
13085 addr, gfp);
1965c853
JM
13086}
13087
b23aa676
SO
13088void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
13089 struct net_device *netdev, const u8 *bssid,
13090 const u8 *req_ie, size_t req_ie_len,
13091 const u8 *resp_ie, size_t resp_ie_len,
bf1ecd21 13092 int status, gfp_t gfp)
b23aa676
SO
13093{
13094 struct sk_buff *msg;
13095 void *hdr;
13096
58050fce 13097 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
13098 if (!msg)
13099 return;
13100
13101 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
13102 if (!hdr) {
13103 nlmsg_free(msg);
13104 return;
13105 }
13106
9360ffd1
DM
13107 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13108 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13109 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
bf1ecd21
JM
13110 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE,
13111 status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE :
13112 status) ||
13113 (status < 0 && nla_put_flag(msg, NL80211_ATTR_TIMED_OUT)) ||
9360ffd1
DM
13114 (req_ie &&
13115 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
13116 (resp_ie &&
13117 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
13118 goto nla_put_failure;
b23aa676 13119
3b7b72ee 13120 genlmsg_end(msg, hdr);
b23aa676 13121
68eb5503 13122 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13123 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
13124 return;
13125
13126 nla_put_failure:
13127 genlmsg_cancel(msg, hdr);
13128 nlmsg_free(msg);
b23aa676
SO
13129}
13130
13131void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
13132 struct net_device *netdev, const u8 *bssid,
13133 const u8 *req_ie, size_t req_ie_len,
13134 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
13135{
13136 struct sk_buff *msg;
13137 void *hdr;
13138
58050fce 13139 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
13140 if (!msg)
13141 return;
13142
13143 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
13144 if (!hdr) {
13145 nlmsg_free(msg);
13146 return;
13147 }
13148
9360ffd1
DM
13149 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13150 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13151 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
13152 (req_ie &&
13153 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
13154 (resp_ie &&
13155 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
13156 goto nla_put_failure;
b23aa676 13157
3b7b72ee 13158 genlmsg_end(msg, hdr);
b23aa676 13159
68eb5503 13160 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13161 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
13162 return;
13163
13164 nla_put_failure:
13165 genlmsg_cancel(msg, hdr);
13166 nlmsg_free(msg);
b23aa676
SO
13167}
13168
13169void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
13170 struct net_device *netdev, u16 reason,
667503dd 13171 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
13172{
13173 struct sk_buff *msg;
13174 void *hdr;
13175
58050fce 13176 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
13177 if (!msg)
13178 return;
13179
13180 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
13181 if (!hdr) {
13182 nlmsg_free(msg);
13183 return;
13184 }
13185
9360ffd1
DM
13186 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13187 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13188 (from_ap && reason &&
13189 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
13190 (from_ap &&
13191 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
13192 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
13193 goto nla_put_failure;
b23aa676 13194
3b7b72ee 13195 genlmsg_end(msg, hdr);
b23aa676 13196
68eb5503 13197 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13198 NL80211_MCGRP_MLME, GFP_KERNEL);
b23aa676
SO
13199 return;
13200
13201 nla_put_failure:
13202 genlmsg_cancel(msg, hdr);
13203 nlmsg_free(msg);
b23aa676
SO
13204}
13205
04a773ad
JB
13206void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
13207 struct net_device *netdev, const u8 *bssid,
13208 gfp_t gfp)
13209{
13210 struct sk_buff *msg;
13211 void *hdr;
13212
fd2120ca 13213 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
13214 if (!msg)
13215 return;
13216
13217 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
13218 if (!hdr) {
13219 nlmsg_free(msg);
13220 return;
13221 }
13222
9360ffd1
DM
13223 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13224 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13225 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
13226 goto nla_put_failure;
04a773ad 13227
3b7b72ee 13228 genlmsg_end(msg, hdr);
04a773ad 13229
68eb5503 13230 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13231 NL80211_MCGRP_MLME, gfp);
04a773ad
JB
13232 return;
13233
13234 nla_put_failure:
13235 genlmsg_cancel(msg, hdr);
13236 nlmsg_free(msg);
13237}
13238
947add36
JB
13239void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
13240 const u8* ie, u8 ie_len, gfp_t gfp)
c93b5e71 13241{
947add36 13242 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 13243 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
c93b5e71
JC
13244 struct sk_buff *msg;
13245 void *hdr;
13246
947add36
JB
13247 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
13248 return;
13249
13250 trace_cfg80211_notify_new_peer_candidate(dev, addr);
13251
c93b5e71
JC
13252 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13253 if (!msg)
13254 return;
13255
13256 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
13257 if (!hdr) {
13258 nlmsg_free(msg);
13259 return;
13260 }
13261
9360ffd1 13262 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
13263 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
13264 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1
DM
13265 (ie_len && ie &&
13266 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
13267 goto nla_put_failure;
c93b5e71 13268
3b7b72ee 13269 genlmsg_end(msg, hdr);
c93b5e71 13270
68eb5503 13271 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13272 NL80211_MCGRP_MLME, gfp);
c93b5e71
JC
13273 return;
13274
13275 nla_put_failure:
13276 genlmsg_cancel(msg, hdr);
13277 nlmsg_free(msg);
13278}
947add36 13279EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 13280
a3b8b056
JM
13281void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
13282 struct net_device *netdev, const u8 *addr,
13283 enum nl80211_key_type key_type, int key_id,
e6d6e342 13284 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
13285{
13286 struct sk_buff *msg;
13287 void *hdr;
13288
e6d6e342 13289 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
13290 if (!msg)
13291 return;
13292
13293 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
13294 if (!hdr) {
13295 nlmsg_free(msg);
13296 return;
13297 }
13298
9360ffd1
DM
13299 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13300 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13301 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
13302 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
13303 (key_id != -1 &&
13304 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
13305 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
13306 goto nla_put_failure;
a3b8b056 13307
3b7b72ee 13308 genlmsg_end(msg, hdr);
a3b8b056 13309
68eb5503 13310 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13311 NL80211_MCGRP_MLME, gfp);
a3b8b056
JM
13312 return;
13313
13314 nla_put_failure:
13315 genlmsg_cancel(msg, hdr);
13316 nlmsg_free(msg);
13317}
13318
6bad8766
LR
13319void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
13320 struct ieee80211_channel *channel_before,
13321 struct ieee80211_channel *channel_after)
13322{
13323 struct sk_buff *msg;
13324 void *hdr;
13325 struct nlattr *nl_freq;
13326
fd2120ca 13327 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
13328 if (!msg)
13329 return;
13330
13331 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
13332 if (!hdr) {
13333 nlmsg_free(msg);
13334 return;
13335 }
13336
13337 /*
13338 * Since we are applying the beacon hint to a wiphy we know its
13339 * wiphy_idx is valid
13340 */
9360ffd1
DM
13341 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
13342 goto nla_put_failure;
6bad8766
LR
13343
13344 /* Before */
13345 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
13346 if (!nl_freq)
13347 goto nla_put_failure;
cdc89b97 13348 if (nl80211_msg_put_channel(msg, channel_before, false))
6bad8766
LR
13349 goto nla_put_failure;
13350 nla_nest_end(msg, nl_freq);
13351
13352 /* After */
13353 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
13354 if (!nl_freq)
13355 goto nla_put_failure;
cdc89b97 13356 if (nl80211_msg_put_channel(msg, channel_after, false))
6bad8766
LR
13357 goto nla_put_failure;
13358 nla_nest_end(msg, nl_freq);
13359
3b7b72ee 13360 genlmsg_end(msg, hdr);
6bad8766 13361
463d0183 13362 rcu_read_lock();
68eb5503 13363 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 13364 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
463d0183 13365 rcu_read_unlock();
6bad8766
LR
13366
13367 return;
13368
13369nla_put_failure:
13370 genlmsg_cancel(msg, hdr);
13371 nlmsg_free(msg);
13372}
13373
9588bbd5
JM
13374static void nl80211_send_remain_on_chan_event(
13375 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 13376 struct wireless_dev *wdev, u64 cookie,
9588bbd5 13377 struct ieee80211_channel *chan,
9588bbd5
JM
13378 unsigned int duration, gfp_t gfp)
13379{
13380 struct sk_buff *msg;
13381 void *hdr;
13382
13383 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13384 if (!msg)
13385 return;
13386
13387 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
13388 if (!hdr) {
13389 nlmsg_free(msg);
13390 return;
13391 }
13392
9360ffd1 13393 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
13394 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
13395 wdev->netdev->ifindex)) ||
2dad624e
ND
13396 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
13397 NL80211_ATTR_PAD) ||
9360ffd1 13398 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
13399 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
13400 NL80211_CHAN_NO_HT) ||
2dad624e
ND
13401 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
13402 NL80211_ATTR_PAD))
9360ffd1 13403 goto nla_put_failure;
9588bbd5 13404
9360ffd1
DM
13405 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
13406 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
13407 goto nla_put_failure;
9588bbd5 13408
3b7b72ee 13409 genlmsg_end(msg, hdr);
9588bbd5 13410
68eb5503 13411 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13412 NL80211_MCGRP_MLME, gfp);
9588bbd5
JM
13413 return;
13414
13415 nla_put_failure:
13416 genlmsg_cancel(msg, hdr);
13417 nlmsg_free(msg);
13418}
13419
947add36
JB
13420void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
13421 struct ieee80211_channel *chan,
13422 unsigned int duration, gfp_t gfp)
9588bbd5 13423{
947add36 13424 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13425 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
13426
13427 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 13428 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 13429 rdev, wdev, cookie, chan,
42d97a59 13430 duration, gfp);
9588bbd5 13431}
947add36 13432EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 13433
947add36
JB
13434void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
13435 struct ieee80211_channel *chan,
13436 gfp_t gfp)
9588bbd5 13437{
947add36 13438 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13439 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
13440
13441 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 13442 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 13443 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 13444}
947add36 13445EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 13446
947add36
JB
13447void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
13448 struct station_info *sinfo, gfp_t gfp)
98b62183 13449{
947add36 13450 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 13451 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
98b62183
JB
13452 struct sk_buff *msg;
13453
947add36
JB
13454 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
13455
58050fce 13456 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
13457 if (!msg)
13458 return;
13459
cf5ead82 13460 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0,
66266b3a 13461 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
13462 nlmsg_free(msg);
13463 return;
13464 }
13465
68eb5503 13466 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13467 NL80211_MCGRP_MLME, gfp);
98b62183 13468}
947add36 13469EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 13470
cf5ead82
JB
13471void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr,
13472 struct station_info *sinfo, gfp_t gfp)
ec15e68b 13473{
947add36 13474 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 13475 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ec15e68b 13476 struct sk_buff *msg;
cf5ead82
JB
13477 struct station_info empty_sinfo = {};
13478
13479 if (!sinfo)
13480 sinfo = &empty_sinfo;
ec15e68b 13481
947add36
JB
13482 trace_cfg80211_del_sta(dev, mac_addr);
13483
58050fce 13484 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
13485 if (!msg)
13486 return;
13487
cf5ead82 13488 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0,
57007121 13489 rdev, dev, mac_addr, sinfo) < 0) {
ec15e68b
JM
13490 nlmsg_free(msg);
13491 return;
13492 }
13493
68eb5503 13494 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13495 NL80211_MCGRP_MLME, gfp);
ec15e68b 13496}
cf5ead82 13497EXPORT_SYMBOL(cfg80211_del_sta_sinfo);
ec15e68b 13498
947add36
JB
13499void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
13500 enum nl80211_connect_failed_reason reason,
13501 gfp_t gfp)
ed44a951 13502{
947add36 13503 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 13504 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ed44a951
PP
13505 struct sk_buff *msg;
13506 void *hdr;
13507
13508 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
13509 if (!msg)
13510 return;
13511
13512 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
13513 if (!hdr) {
13514 nlmsg_free(msg);
13515 return;
13516 }
13517
13518 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
13519 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
13520 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
13521 goto nla_put_failure;
13522
13523 genlmsg_end(msg, hdr);
13524
68eb5503 13525 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13526 NL80211_MCGRP_MLME, gfp);
ed44a951
PP
13527 return;
13528
13529 nla_put_failure:
13530 genlmsg_cancel(msg, hdr);
13531 nlmsg_free(msg);
13532}
947add36 13533EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 13534
b92ab5d8
JB
13535static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
13536 const u8 *addr, gfp_t gfp)
28946da7
JB
13537{
13538 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 13539 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
28946da7
JB
13540 struct sk_buff *msg;
13541 void *hdr;
15e47304 13542 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 13543
15e47304 13544 if (!nlportid)
28946da7
JB
13545 return false;
13546
13547 msg = nlmsg_new(100, gfp);
13548 if (!msg)
13549 return true;
13550
b92ab5d8 13551 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
13552 if (!hdr) {
13553 nlmsg_free(msg);
13554 return true;
13555 }
13556
9360ffd1
DM
13557 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13558 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
13559 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
13560 goto nla_put_failure;
28946da7 13561
9c90a9f6 13562 genlmsg_end(msg, hdr);
15e47304 13563 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
13564 return true;
13565
13566 nla_put_failure:
13567 genlmsg_cancel(msg, hdr);
13568 nlmsg_free(msg);
13569 return true;
13570}
13571
947add36
JB
13572bool cfg80211_rx_spurious_frame(struct net_device *dev,
13573 const u8 *addr, gfp_t gfp)
b92ab5d8 13574{
947add36
JB
13575 struct wireless_dev *wdev = dev->ieee80211_ptr;
13576 bool ret;
13577
13578 trace_cfg80211_rx_spurious_frame(dev, addr);
13579
13580 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
13581 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
13582 trace_cfg80211_return_bool(false);
13583 return false;
13584 }
13585 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
13586 addr, gfp);
13587 trace_cfg80211_return_bool(ret);
13588 return ret;
b92ab5d8 13589}
947add36 13590EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 13591
947add36
JB
13592bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
13593 const u8 *addr, gfp_t gfp)
b92ab5d8 13594{
947add36
JB
13595 struct wireless_dev *wdev = dev->ieee80211_ptr;
13596 bool ret;
13597
13598 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
13599
13600 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
13601 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
13602 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
13603 trace_cfg80211_return_bool(false);
13604 return false;
13605 }
13606 ret = __nl80211_unexpected_frame(dev,
13607 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
13608 addr, gfp);
13609 trace_cfg80211_return_bool(ret);
13610 return ret;
b92ab5d8 13611}
947add36 13612EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 13613
2e161f78 13614int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 13615 struct wireless_dev *wdev, u32 nlportid,
804483e9 13616 int freq, int sig_dbm,
19504cf5 13617 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 13618{
71bbc994 13619 struct net_device *netdev = wdev->netdev;
026331c4
JM
13620 struct sk_buff *msg;
13621 void *hdr;
026331c4
JM
13622
13623 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13624 if (!msg)
13625 return -ENOMEM;
13626
2e161f78 13627 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
13628 if (!hdr) {
13629 nlmsg_free(msg);
13630 return -ENOMEM;
13631 }
13632
9360ffd1 13633 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
13634 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
13635 netdev->ifindex)) ||
2dad624e
ND
13636 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
13637 NL80211_ATTR_PAD) ||
9360ffd1
DM
13638 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
13639 (sig_dbm &&
13640 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
13641 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
13642 (flags &&
13643 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 13644 goto nla_put_failure;
026331c4 13645
3b7b72ee 13646 genlmsg_end(msg, hdr);
026331c4 13647
15e47304 13648 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
13649
13650 nla_put_failure:
13651 genlmsg_cancel(msg, hdr);
13652 nlmsg_free(msg);
13653 return -ENOBUFS;
13654}
13655
947add36
JB
13656void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
13657 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 13658{
947add36 13659 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13660 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
71bbc994 13661 struct net_device *netdev = wdev->netdev;
026331c4
JM
13662 struct sk_buff *msg;
13663 void *hdr;
13664
947add36
JB
13665 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
13666
026331c4
JM
13667 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13668 if (!msg)
13669 return;
13670
2e161f78 13671 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
13672 if (!hdr) {
13673 nlmsg_free(msg);
13674 return;
13675 }
13676
9360ffd1 13677 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
13678 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
13679 netdev->ifindex)) ||
2dad624e
ND
13680 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
13681 NL80211_ATTR_PAD) ||
9360ffd1 13682 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
2dad624e
ND
13683 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
13684 NL80211_ATTR_PAD) ||
9360ffd1
DM
13685 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
13686 goto nla_put_failure;
026331c4 13687
3b7b72ee 13688 genlmsg_end(msg, hdr);
026331c4 13689
68eb5503 13690 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13691 NL80211_MCGRP_MLME, gfp);
026331c4
JM
13692 return;
13693
13694 nla_put_failure:
13695 genlmsg_cancel(msg, hdr);
13696 nlmsg_free(msg);
13697}
947add36 13698EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 13699
5b97f49d
JB
13700static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev,
13701 const char *mac, gfp_t gfp)
d6dc1a38 13702{
947add36 13703 struct wireless_dev *wdev = dev->ieee80211_ptr;
5b97f49d
JB
13704 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
13705 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13706 void **cb;
947add36 13707
d6dc1a38 13708 if (!msg)
5b97f49d 13709 return NULL;
d6dc1a38 13710
5b97f49d
JB
13711 cb = (void **)msg->cb;
13712
13713 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
13714 if (!cb[0]) {
d6dc1a38 13715 nlmsg_free(msg);
5b97f49d 13716 return NULL;
d6dc1a38
JO
13717 }
13718
9360ffd1 13719 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 13720 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 13721 goto nla_put_failure;
d6dc1a38 13722
5b97f49d 13723 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
d6dc1a38
JO
13724 goto nla_put_failure;
13725
5b97f49d
JB
13726 cb[1] = nla_nest_start(msg, NL80211_ATTR_CQM);
13727 if (!cb[1])
9360ffd1 13728 goto nla_put_failure;
d6dc1a38 13729
5b97f49d 13730 cb[2] = rdev;
d6dc1a38 13731
5b97f49d
JB
13732 return msg;
13733 nla_put_failure:
13734 nlmsg_free(msg);
13735 return NULL;
13736}
13737
13738static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp)
13739{
13740 void **cb = (void **)msg->cb;
13741 struct cfg80211_registered_device *rdev = cb[2];
13742
13743 nla_nest_end(msg, cb[1]);
13744 genlmsg_end(msg, cb[0]);
13745
13746 memset(msg->cb, 0, sizeof(msg->cb));
d6dc1a38 13747
68eb5503 13748 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13749 NL80211_MCGRP_MLME, gfp);
5b97f49d
JB
13750}
13751
13752void cfg80211_cqm_rssi_notify(struct net_device *dev,
13753 enum nl80211_cqm_rssi_threshold_event rssi_event,
13754 gfp_t gfp)
13755{
13756 struct sk_buff *msg;
13757
13758 trace_cfg80211_cqm_rssi_notify(dev, rssi_event);
13759
98f03342
JB
13760 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW &&
13761 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH))
13762 return;
13763
5b97f49d
JB
13764 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
13765 if (!msg)
13766 return;
13767
13768 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
13769 rssi_event))
13770 goto nla_put_failure;
13771
13772 cfg80211_send_cqm(msg, gfp);
13773
d6dc1a38
JO
13774 return;
13775
13776 nla_put_failure:
d6dc1a38
JO
13777 nlmsg_free(msg);
13778}
947add36 13779EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 13780
5b97f49d
JB
13781void cfg80211_cqm_txe_notify(struct net_device *dev,
13782 const u8 *peer, u32 num_packets,
13783 u32 rate, u32 intvl, gfp_t gfp)
13784{
13785 struct sk_buff *msg;
13786
13787 msg = cfg80211_prepare_cqm(dev, peer, gfp);
13788 if (!msg)
13789 return;
13790
13791 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
13792 goto nla_put_failure;
13793
13794 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
13795 goto nla_put_failure;
13796
13797 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
13798 goto nla_put_failure;
13799
13800 cfg80211_send_cqm(msg, gfp);
13801 return;
13802
13803 nla_put_failure:
13804 nlmsg_free(msg);
13805}
13806EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
13807
13808void cfg80211_cqm_pktloss_notify(struct net_device *dev,
13809 const u8 *peer, u32 num_packets, gfp_t gfp)
13810{
13811 struct sk_buff *msg;
13812
13813 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
13814
13815 msg = cfg80211_prepare_cqm(dev, peer, gfp);
13816 if (!msg)
13817 return;
13818
13819 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
13820 goto nla_put_failure;
13821
13822 cfg80211_send_cqm(msg, gfp);
13823 return;
13824
13825 nla_put_failure:
13826 nlmsg_free(msg);
13827}
13828EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
13829
98f03342
JB
13830void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp)
13831{
13832 struct sk_buff *msg;
13833
13834 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
13835 if (!msg)
13836 return;
13837
13838 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT))
13839 goto nla_put_failure;
13840
13841 cfg80211_send_cqm(msg, gfp);
13842 return;
13843
13844 nla_put_failure:
13845 nlmsg_free(msg);
13846}
13847EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify);
13848
947add36
JB
13849static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
13850 struct net_device *netdev, const u8 *bssid,
13851 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
13852{
13853 struct sk_buff *msg;
13854 struct nlattr *rekey_attr;
13855 void *hdr;
13856
58050fce 13857 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
13858 if (!msg)
13859 return;
13860
13861 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
13862 if (!hdr) {
13863 nlmsg_free(msg);
13864 return;
13865 }
13866
9360ffd1
DM
13867 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13868 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13869 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
13870 goto nla_put_failure;
e5497d76
JB
13871
13872 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
13873 if (!rekey_attr)
13874 goto nla_put_failure;
13875
9360ffd1
DM
13876 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
13877 NL80211_REPLAY_CTR_LEN, replay_ctr))
13878 goto nla_put_failure;
e5497d76
JB
13879
13880 nla_nest_end(msg, rekey_attr);
13881
3b7b72ee 13882 genlmsg_end(msg, hdr);
e5497d76 13883
68eb5503 13884 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13885 NL80211_MCGRP_MLME, gfp);
e5497d76
JB
13886 return;
13887
13888 nla_put_failure:
13889 genlmsg_cancel(msg, hdr);
13890 nlmsg_free(msg);
13891}
13892
947add36
JB
13893void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
13894 const u8 *replay_ctr, gfp_t gfp)
13895{
13896 struct wireless_dev *wdev = dev->ieee80211_ptr;
13897 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13898 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
13899
13900 trace_cfg80211_gtk_rekey_notify(dev, bssid);
13901 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
13902}
13903EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
13904
13905static void
13906nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
13907 struct net_device *netdev, int index,
13908 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
13909{
13910 struct sk_buff *msg;
13911 struct nlattr *attr;
13912 void *hdr;
13913
58050fce 13914 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
13915 if (!msg)
13916 return;
13917
13918 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
13919 if (!hdr) {
13920 nlmsg_free(msg);
13921 return;
13922 }
13923
9360ffd1
DM
13924 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13925 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
13926 goto nla_put_failure;
c9df56b4
JM
13927
13928 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
13929 if (!attr)
13930 goto nla_put_failure;
13931
9360ffd1
DM
13932 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
13933 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
13934 (preauth &&
13935 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
13936 goto nla_put_failure;
c9df56b4
JM
13937
13938 nla_nest_end(msg, attr);
13939
3b7b72ee 13940 genlmsg_end(msg, hdr);
c9df56b4 13941
68eb5503 13942 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13943 NL80211_MCGRP_MLME, gfp);
c9df56b4
JM
13944 return;
13945
13946 nla_put_failure:
13947 genlmsg_cancel(msg, hdr);
13948 nlmsg_free(msg);
13949}
13950
947add36
JB
13951void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
13952 const u8 *bssid, bool preauth, gfp_t gfp)
13953{
13954 struct wireless_dev *wdev = dev->ieee80211_ptr;
13955 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13956 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
13957
13958 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
13959 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
13960}
13961EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
13962
13963static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
13964 struct net_device *netdev,
13965 struct cfg80211_chan_def *chandef,
f8d7552e
LC
13966 gfp_t gfp,
13967 enum nl80211_commands notif,
13968 u8 count)
5314526b
TP
13969{
13970 struct sk_buff *msg;
13971 void *hdr;
13972
58050fce 13973 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
13974 if (!msg)
13975 return;
13976
f8d7552e 13977 hdr = nl80211hdr_put(msg, 0, 0, 0, notif);
5314526b
TP
13978 if (!hdr) {
13979 nlmsg_free(msg);
13980 return;
13981 }
13982
683b6d3b
JB
13983 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
13984 goto nla_put_failure;
13985
13986 if (nl80211_send_chandef(msg, chandef))
7eab0f64 13987 goto nla_put_failure;
5314526b 13988
f8d7552e
LC
13989 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) &&
13990 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count)))
13991 goto nla_put_failure;
13992
5314526b
TP
13993 genlmsg_end(msg, hdr);
13994
68eb5503 13995 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13996 NL80211_MCGRP_MLME, gfp);
5314526b
TP
13997 return;
13998
13999 nla_put_failure:
14000 genlmsg_cancel(msg, hdr);
14001 nlmsg_free(msg);
14002}
14003
947add36
JB
14004void cfg80211_ch_switch_notify(struct net_device *dev,
14005 struct cfg80211_chan_def *chandef)
84f10708 14006{
947add36
JB
14007 struct wireless_dev *wdev = dev->ieee80211_ptr;
14008 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14009 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36 14010
e487eaeb 14011 ASSERT_WDEV_LOCK(wdev);
947add36 14012
e487eaeb 14013 trace_cfg80211_ch_switch_notify(dev, chandef);
947add36 14014
9e0e2961 14015 wdev->chandef = *chandef;
96f55f12 14016 wdev->preset_chandef = *chandef;
f8d7552e
LC
14017 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
14018 NL80211_CMD_CH_SWITCH_NOTIFY, 0);
947add36
JB
14019}
14020EXPORT_SYMBOL(cfg80211_ch_switch_notify);
14021
f8d7552e
LC
14022void cfg80211_ch_switch_started_notify(struct net_device *dev,
14023 struct cfg80211_chan_def *chandef,
14024 u8 count)
14025{
14026 struct wireless_dev *wdev = dev->ieee80211_ptr;
14027 struct wiphy *wiphy = wdev->wiphy;
14028 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
14029
14030 trace_cfg80211_ch_switch_started_notify(dev, chandef);
14031
14032 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
14033 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count);
14034}
14035EXPORT_SYMBOL(cfg80211_ch_switch_started_notify);
14036
04f39047
SW
14037void
14038nl80211_radar_notify(struct cfg80211_registered_device *rdev,
d2859df5 14039 const struct cfg80211_chan_def *chandef,
04f39047
SW
14040 enum nl80211_radar_event event,
14041 struct net_device *netdev, gfp_t gfp)
14042{
14043 struct sk_buff *msg;
14044 void *hdr;
14045
14046 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14047 if (!msg)
14048 return;
14049
14050 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
14051 if (!hdr) {
14052 nlmsg_free(msg);
14053 return;
14054 }
14055
14056 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
14057 goto nla_put_failure;
14058
14059 /* NOP and radar events don't need a netdev parameter */
14060 if (netdev) {
14061 struct wireless_dev *wdev = netdev->ieee80211_ptr;
14062
14063 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
2dad624e
ND
14064 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14065 NL80211_ATTR_PAD))
04f39047
SW
14066 goto nla_put_failure;
14067 }
14068
14069 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
14070 goto nla_put_failure;
14071
14072 if (nl80211_send_chandef(msg, chandef))
14073 goto nla_put_failure;
14074
9c90a9f6 14075 genlmsg_end(msg, hdr);
04f39047 14076
68eb5503 14077 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14078 NL80211_MCGRP_MLME, gfp);
04f39047
SW
14079 return;
14080
14081 nla_put_failure:
14082 genlmsg_cancel(msg, hdr);
14083 nlmsg_free(msg);
14084}
14085
7f6cf311
JB
14086void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
14087 u64 cookie, bool acked, gfp_t gfp)
14088{
14089 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 14090 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
7f6cf311
JB
14091 struct sk_buff *msg;
14092 void *hdr;
7f6cf311 14093
4ee3e063
BL
14094 trace_cfg80211_probe_status(dev, addr, cookie, acked);
14095
58050fce 14096 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 14097
7f6cf311
JB
14098 if (!msg)
14099 return;
14100
14101 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
14102 if (!hdr) {
14103 nlmsg_free(msg);
14104 return;
14105 }
14106
9360ffd1
DM
14107 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14108 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
14109 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
2dad624e
ND
14110 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
14111 NL80211_ATTR_PAD) ||
9360ffd1
DM
14112 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
14113 goto nla_put_failure;
7f6cf311 14114
9c90a9f6 14115 genlmsg_end(msg, hdr);
7f6cf311 14116
68eb5503 14117 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14118 NL80211_MCGRP_MLME, gfp);
7f6cf311
JB
14119 return;
14120
14121 nla_put_failure:
14122 genlmsg_cancel(msg, hdr);
14123 nlmsg_free(msg);
14124}
14125EXPORT_SYMBOL(cfg80211_probe_status);
14126
5e760230
JB
14127void cfg80211_report_obss_beacon(struct wiphy *wiphy,
14128 const u8 *frame, size_t len,
37c73b5f 14129 int freq, int sig_dbm)
5e760230 14130{
f26cbf40 14131 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
5e760230
JB
14132 struct sk_buff *msg;
14133 void *hdr;
37c73b5f 14134 struct cfg80211_beacon_registration *reg;
5e760230 14135
4ee3e063
BL
14136 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
14137
37c73b5f
BG
14138 spin_lock_bh(&rdev->beacon_registrations_lock);
14139 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
14140 msg = nlmsg_new(len + 100, GFP_ATOMIC);
14141 if (!msg) {
14142 spin_unlock_bh(&rdev->beacon_registrations_lock);
14143 return;
14144 }
5e760230 14145
37c73b5f
BG
14146 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
14147 if (!hdr)
14148 goto nla_put_failure;
5e760230 14149
37c73b5f
BG
14150 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14151 (freq &&
14152 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
14153 (sig_dbm &&
14154 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
14155 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
14156 goto nla_put_failure;
5e760230 14157
37c73b5f 14158 genlmsg_end(msg, hdr);
5e760230 14159
37c73b5f
BG
14160 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
14161 }
14162 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
14163 return;
14164
14165 nla_put_failure:
37c73b5f
BG
14166 spin_unlock_bh(&rdev->beacon_registrations_lock);
14167 if (hdr)
14168 genlmsg_cancel(msg, hdr);
5e760230
JB
14169 nlmsg_free(msg);
14170}
14171EXPORT_SYMBOL(cfg80211_report_obss_beacon);
14172
cd8f7cb4 14173#ifdef CONFIG_PM
8cd4d456
LC
14174static int cfg80211_net_detect_results(struct sk_buff *msg,
14175 struct cfg80211_wowlan_wakeup *wakeup)
14176{
14177 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect;
14178 struct nlattr *nl_results, *nl_match, *nl_freqs;
14179 int i, j;
14180
14181 nl_results = nla_nest_start(
14182 msg, NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS);
14183 if (!nl_results)
14184 return -EMSGSIZE;
14185
14186 for (i = 0; i < nd->n_matches; i++) {
14187 struct cfg80211_wowlan_nd_match *match = nd->matches[i];
14188
14189 nl_match = nla_nest_start(msg, i);
14190 if (!nl_match)
14191 break;
14192
14193 /* The SSID attribute is optional in nl80211, but for
14194 * simplicity reasons it's always present in the
14195 * cfg80211 structure. If a driver can't pass the
14196 * SSID, that needs to be changed. A zero length SSID
14197 * is still a valid SSID (wildcard), so it cannot be
14198 * used for this purpose.
14199 */
14200 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len,
14201 match->ssid.ssid)) {
14202 nla_nest_cancel(msg, nl_match);
14203 goto out;
14204 }
14205
14206 if (match->n_channels) {
14207 nl_freqs = nla_nest_start(
14208 msg, NL80211_ATTR_SCAN_FREQUENCIES);
14209 if (!nl_freqs) {
14210 nla_nest_cancel(msg, nl_match);
14211 goto out;
14212 }
14213
14214 for (j = 0; j < match->n_channels; j++) {
5528fae8 14215 if (nla_put_u32(msg, j, match->channels[j])) {
8cd4d456
LC
14216 nla_nest_cancel(msg, nl_freqs);
14217 nla_nest_cancel(msg, nl_match);
14218 goto out;
14219 }
14220 }
14221
14222 nla_nest_end(msg, nl_freqs);
14223 }
14224
14225 nla_nest_end(msg, nl_match);
14226 }
14227
14228out:
14229 nla_nest_end(msg, nl_results);
14230 return 0;
14231}
14232
cd8f7cb4
JB
14233void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
14234 struct cfg80211_wowlan_wakeup *wakeup,
14235 gfp_t gfp)
14236{
f26cbf40 14237 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
cd8f7cb4
JB
14238 struct sk_buff *msg;
14239 void *hdr;
9c90a9f6 14240 int size = 200;
cd8f7cb4
JB
14241
14242 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
14243
14244 if (wakeup)
14245 size += wakeup->packet_present_len;
14246
14247 msg = nlmsg_new(size, gfp);
14248 if (!msg)
14249 return;
14250
14251 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
14252 if (!hdr)
14253 goto free_msg;
14254
14255 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
14256 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14257 NL80211_ATTR_PAD))
cd8f7cb4
JB
14258 goto free_msg;
14259
14260 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14261 wdev->netdev->ifindex))
14262 goto free_msg;
14263
14264 if (wakeup) {
14265 struct nlattr *reasons;
14266
14267 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7fa322c8
JB
14268 if (!reasons)
14269 goto free_msg;
cd8f7cb4
JB
14270
14271 if (wakeup->disconnect &&
14272 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
14273 goto free_msg;
14274 if (wakeup->magic_pkt &&
14275 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
14276 goto free_msg;
14277 if (wakeup->gtk_rekey_failure &&
14278 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
14279 goto free_msg;
14280 if (wakeup->eap_identity_req &&
14281 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
14282 goto free_msg;
14283 if (wakeup->four_way_handshake &&
14284 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
14285 goto free_msg;
14286 if (wakeup->rfkill_release &&
14287 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
14288 goto free_msg;
14289
14290 if (wakeup->pattern_idx >= 0 &&
14291 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
14292 wakeup->pattern_idx))
14293 goto free_msg;
14294
ae917c9f
JB
14295 if (wakeup->tcp_match &&
14296 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
14297 goto free_msg;
2a0e047e 14298
ae917c9f
JB
14299 if (wakeup->tcp_connlost &&
14300 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
14301 goto free_msg;
2a0e047e 14302
ae917c9f
JB
14303 if (wakeup->tcp_nomoretokens &&
14304 nla_put_flag(msg,
14305 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
14306 goto free_msg;
2a0e047e 14307
cd8f7cb4
JB
14308 if (wakeup->packet) {
14309 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
14310 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
14311
14312 if (!wakeup->packet_80211) {
14313 pkt_attr =
14314 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
14315 len_attr =
14316 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
14317 }
14318
14319 if (wakeup->packet_len &&
14320 nla_put_u32(msg, len_attr, wakeup->packet_len))
14321 goto free_msg;
14322
14323 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
14324 wakeup->packet))
14325 goto free_msg;
14326 }
14327
8cd4d456
LC
14328 if (wakeup->net_detect &&
14329 cfg80211_net_detect_results(msg, wakeup))
14330 goto free_msg;
14331
cd8f7cb4
JB
14332 nla_nest_end(msg, reasons);
14333 }
14334
9c90a9f6 14335 genlmsg_end(msg, hdr);
cd8f7cb4 14336
68eb5503 14337 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14338 NL80211_MCGRP_MLME, gfp);
cd8f7cb4
JB
14339 return;
14340
14341 free_msg:
14342 nlmsg_free(msg);
14343}
14344EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
14345#endif
14346
3475b094
JM
14347void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
14348 enum nl80211_tdls_operation oper,
14349 u16 reason_code, gfp_t gfp)
14350{
14351 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 14352 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
3475b094
JM
14353 struct sk_buff *msg;
14354 void *hdr;
3475b094
JM
14355
14356 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
14357 reason_code);
14358
14359 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14360 if (!msg)
14361 return;
14362
14363 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
14364 if (!hdr) {
14365 nlmsg_free(msg);
14366 return;
14367 }
14368
14369 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14370 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
14371 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
14372 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
14373 (reason_code > 0 &&
14374 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
14375 goto nla_put_failure;
14376
9c90a9f6 14377 genlmsg_end(msg, hdr);
3475b094 14378
68eb5503 14379 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14380 NL80211_MCGRP_MLME, gfp);
3475b094
JM
14381 return;
14382
14383 nla_put_failure:
14384 genlmsg_cancel(msg, hdr);
14385 nlmsg_free(msg);
14386}
14387EXPORT_SYMBOL(cfg80211_tdls_oper_request);
14388
026331c4
JM
14389static int nl80211_netlink_notify(struct notifier_block * nb,
14390 unsigned long state,
14391 void *_notify)
14392{
14393 struct netlink_notify *notify = _notify;
14394 struct cfg80211_registered_device *rdev;
14395 struct wireless_dev *wdev;
37c73b5f 14396 struct cfg80211_beacon_registration *reg, *tmp;
026331c4 14397
8f815cdd 14398 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
026331c4
JM
14399 return NOTIFY_DONE;
14400
14401 rcu_read_lock();
14402
5e760230 14403 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
78f22b6a 14404 bool schedule_destroy_work = false;
93a1e86c
JR
14405 bool schedule_scan_stop = false;
14406 struct cfg80211_sched_scan_request *sched_scan_req =
14407 rcu_dereference(rdev->sched_scan_req);
14408
14409 if (sched_scan_req && notify->portid &&
14410 sched_scan_req->owner_nlportid == notify->portid)
14411 schedule_scan_stop = true;
78f22b6a 14412
53873f13 14413 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) {
15e47304 14414 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f 14415
78f22b6a
JB
14416 if (wdev->owner_nlportid == notify->portid)
14417 schedule_destroy_work = true;
14418 }
14419
37c73b5f
BG
14420 spin_lock_bh(&rdev->beacon_registrations_lock);
14421 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
14422 list) {
14423 if (reg->nlportid == notify->portid) {
14424 list_del(&reg->list);
14425 kfree(reg);
14426 break;
14427 }
14428 }
14429 spin_unlock_bh(&rdev->beacon_registrations_lock);
78f22b6a
JB
14430
14431 if (schedule_destroy_work) {
14432 struct cfg80211_iface_destroy *destroy;
14433
14434 destroy = kzalloc(sizeof(*destroy), GFP_ATOMIC);
14435 if (destroy) {
14436 destroy->nlportid = notify->portid;
14437 spin_lock(&rdev->destroy_list_lock);
14438 list_add(&destroy->list, &rdev->destroy_list);
14439 spin_unlock(&rdev->destroy_list_lock);
14440 schedule_work(&rdev->destroy_work);
14441 }
93a1e86c
JR
14442 } else if (schedule_scan_stop) {
14443 sched_scan_req->owner_nlportid = 0;
14444
14445 if (rdev->ops->sched_scan_stop &&
14446 rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
14447 schedule_work(&rdev->sched_scan_stop_wk);
78f22b6a 14448 }
5e760230 14449 }
026331c4
JM
14450
14451 rcu_read_unlock();
14452
05050753
I
14453 /*
14454 * It is possible that the user space process that is controlling the
14455 * indoor setting disappeared, so notify the regulatory core.
14456 */
14457 regulatory_netlink_notify(notify->portid);
6784c7db 14458 return NOTIFY_OK;
026331c4
JM
14459}
14460
14461static struct notifier_block nl80211_netlink_notifier = {
14462 .notifier_call = nl80211_netlink_notify,
14463};
14464
355199e0
JM
14465void cfg80211_ft_event(struct net_device *netdev,
14466 struct cfg80211_ft_event_params *ft_event)
14467{
14468 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
f26cbf40 14469 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
355199e0
JM
14470 struct sk_buff *msg;
14471 void *hdr;
355199e0
JM
14472
14473 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
14474
14475 if (!ft_event->target_ap)
14476 return;
14477
14478 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14479 if (!msg)
14480 return;
14481
14482 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
ae917c9f
JB
14483 if (!hdr)
14484 goto out;
355199e0 14485
ae917c9f
JB
14486 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14487 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
14488 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
14489 goto out;
355199e0 14490
ae917c9f
JB
14491 if (ft_event->ies &&
14492 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
14493 goto out;
14494 if (ft_event->ric_ies &&
14495 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
14496 ft_event->ric_ies))
14497 goto out;
355199e0 14498
9c90a9f6 14499 genlmsg_end(msg, hdr);
355199e0 14500
68eb5503 14501 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14502 NL80211_MCGRP_MLME, GFP_KERNEL);
ae917c9f
JB
14503 return;
14504 out:
14505 nlmsg_free(msg);
355199e0
JM
14506}
14507EXPORT_SYMBOL(cfg80211_ft_event);
14508
5de17984
AS
14509void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
14510{
14511 struct cfg80211_registered_device *rdev;
14512 struct sk_buff *msg;
14513 void *hdr;
14514 u32 nlportid;
14515
f26cbf40 14516 rdev = wiphy_to_rdev(wdev->wiphy);
5de17984
AS
14517 if (!rdev->crit_proto_nlportid)
14518 return;
14519
14520 nlportid = rdev->crit_proto_nlportid;
14521 rdev->crit_proto_nlportid = 0;
14522
14523 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14524 if (!msg)
14525 return;
14526
14527 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
14528 if (!hdr)
14529 goto nla_put_failure;
14530
14531 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
14532 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14533 NL80211_ATTR_PAD))
5de17984
AS
14534 goto nla_put_failure;
14535
14536 genlmsg_end(msg, hdr);
14537
14538 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
14539 return;
14540
14541 nla_put_failure:
14542 if (hdr)
14543 genlmsg_cancel(msg, hdr);
14544 nlmsg_free(msg);
5de17984
AS
14545}
14546EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
14547
348baf0e
JB
14548void nl80211_send_ap_stopped(struct wireless_dev *wdev)
14549{
14550 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14551 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
348baf0e
JB
14552 struct sk_buff *msg;
14553 void *hdr;
14554
14555 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14556 if (!msg)
14557 return;
14558
14559 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP);
14560 if (!hdr)
14561 goto out;
14562
14563 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14564 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
2dad624e
ND
14565 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14566 NL80211_ATTR_PAD))
348baf0e
JB
14567 goto out;
14568
14569 genlmsg_end(msg, hdr);
14570
14571 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
14572 NL80211_MCGRP_MLME, GFP_KERNEL);
14573 return;
14574 out:
14575 nlmsg_free(msg);
14576}
14577
55682965
JB
14578/* initialisation/exit functions */
14579
14580int nl80211_init(void)
14581{
0d63cbb5 14582 int err;
55682965 14583
2a94fe48
JB
14584 err = genl_register_family_with_ops_groups(&nl80211_fam, nl80211_ops,
14585 nl80211_mcgrps);
55682965
JB
14586 if (err)
14587 return err;
14588
026331c4
JM
14589 err = netlink_register_notifier(&nl80211_netlink_notifier);
14590 if (err)
14591 goto err_out;
14592
55682965
JB
14593 return 0;
14594 err_out:
14595 genl_unregister_family(&nl80211_fam);
14596 return err;
14597}
14598
14599void nl80211_exit(void)
14600{
026331c4 14601 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
14602 genl_unregister_family(&nl80211_fam);
14603}