]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: always allow calling ieee80211_connection_loss()
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
e35e4d28 25#include "rdev-ops.h"
55682965 26
5fb628e9
JM
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
89a54e48
JB
49/* returns ERR_PTR values */
50static struct wireless_dev *
51__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 52{
89a54e48
JB
53 struct cfg80211_registered_device *rdev;
54 struct wireless_dev *result = NULL;
55 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
56 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
57 u64 wdev_id;
58 int wiphy_idx = -1;
59 int ifidx = -1;
55682965 60
89a54e48 61 assert_cfg80211_lock();
55682965 62
89a54e48
JB
63 if (!have_ifidx && !have_wdev_id)
64 return ERR_PTR(-EINVAL);
55682965 65
89a54e48
JB
66 if (have_ifidx)
67 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
68 if (have_wdev_id) {
69 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
70 wiphy_idx = wdev_id >> 32;
55682965
JB
71 }
72
89a54e48
JB
73 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
74 struct wireless_dev *wdev;
75
76 if (wiphy_net(&rdev->wiphy) != netns)
77 continue;
78
79 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
80 continue;
81
82 mutex_lock(&rdev->devlist_mtx);
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
94 mutex_unlock(&rdev->devlist_mtx);
95
96 if (result)
97 break;
98 }
99
100 if (result)
101 return result;
102 return ERR_PTR(-ENODEV);
55682965
JB
103}
104
a9455408 105static struct cfg80211_registered_device *
878d9ec7 106__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 107{
7fee4778
JB
108 struct cfg80211_registered_device *rdev = NULL, *tmp;
109 struct net_device *netdev;
a9455408
JB
110
111 assert_cfg80211_lock();
112
878d9ec7 113 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
114 !attrs[NL80211_ATTR_IFINDEX] &&
115 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
116 return ERR_PTR(-EINVAL);
117
878d9ec7 118 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 119 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 120 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 121
89a54e48
JB
122 if (attrs[NL80211_ATTR_WDEV]) {
123 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
124 struct wireless_dev *wdev;
125 bool found = false;
126
127 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
128 if (tmp) {
129 /* make sure wdev exists */
130 mutex_lock(&tmp->devlist_mtx);
131 list_for_each_entry(wdev, &tmp->wdev_list, list) {
132 if (wdev->identifier != (u32)wdev_id)
133 continue;
134 found = true;
135 break;
136 }
137 mutex_unlock(&tmp->devlist_mtx);
138
139 if (!found)
140 tmp = NULL;
141
142 if (rdev && tmp != rdev)
143 return ERR_PTR(-EINVAL);
144 rdev = tmp;
145 }
146 }
147
878d9ec7
JB
148 if (attrs[NL80211_ATTR_IFINDEX]) {
149 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 150 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
151 if (netdev) {
152 if (netdev->ieee80211_ptr)
153 tmp = wiphy_to_dev(
154 netdev->ieee80211_ptr->wiphy);
155 else
156 tmp = NULL;
157
158 dev_put(netdev);
159
160 /* not wireless device -- return error */
161 if (!tmp)
162 return ERR_PTR(-EINVAL);
163
164 /* mismatch -- return error */
165 if (rdev && tmp != rdev)
166 return ERR_PTR(-EINVAL);
167
168 rdev = tmp;
a9455408 169 }
a9455408 170 }
a9455408 171
4f7eff10
JB
172 if (!rdev)
173 return ERR_PTR(-ENODEV);
a9455408 174
4f7eff10
JB
175 if (netns != wiphy_net(&rdev->wiphy))
176 return ERR_PTR(-ENODEV);
177
178 return rdev;
a9455408
JB
179}
180
181/*
182 * This function returns a pointer to the driver
183 * that the genl_info item that is passed refers to.
184 * If successful, it returns non-NULL and also locks
185 * the driver's mutex!
186 *
187 * This means that you need to call cfg80211_unlock_rdev()
188 * before being allowed to acquire &cfg80211_mutex!
189 *
190 * This is necessary because we need to lock the global
191 * mutex to get an item off the list safely, and then
192 * we lock the rdev mutex so it doesn't go away under us.
193 *
194 * We don't want to keep cfg80211_mutex locked
195 * for all the time in order to allow requests on
196 * other interfaces to go through at the same time.
197 *
198 * The result of this can be a PTR_ERR and hence must
199 * be checked with IS_ERR() for errors.
200 */
201static struct cfg80211_registered_device *
4f7eff10 202cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408
JB
203{
204 struct cfg80211_registered_device *rdev;
205
206 mutex_lock(&cfg80211_mutex);
878d9ec7 207 rdev = __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
208
209 /* if it is not an error we grab the lock on
210 * it to assure it won't be going away while
211 * we operate on it */
212 if (!IS_ERR(rdev))
213 mutex_lock(&rdev->mtx);
214
215 mutex_unlock(&cfg80211_mutex);
216
217 return rdev;
218}
219
55682965 220/* policy for the attributes */
b54452b0 221static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
222 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
223 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 224 .len = 20-1 },
31888487 225 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 226
72bdcf34 227 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 228 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
229 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
230 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
231 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
232
b9a5f8ca
JM
233 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
234 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
235 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
236 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 237 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
238
239 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
240 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
241 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 242
e007b857
EP
243 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
244 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 245
b9454e83 246 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
247 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
248 .len = WLAN_MAX_KEY_LEN },
249 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
250 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
251 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 252 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 253 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
254
255 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
256 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
257 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
258 .len = IEEE80211_MAX_DATA_LEN },
259 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
260 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
261 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
262 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
263 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
264 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
265 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 266 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 267 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 268 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 269 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 270 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 271 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 272
b2e1b302
LR
273 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
274 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
275
9f1ba906
JM
276 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
277 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
278 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
279 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
280 .len = NL80211_MAX_SUPP_RATES },
50b12f59 281 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 282
24bdd9f4 283 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 284 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 285
6c739419 286 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
287
288 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
289 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
290 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
291 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
292 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
293
294 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
295 .len = IEEE80211_MAX_SSID_LEN },
296 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
297 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 298 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 299 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 300 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
301 [NL80211_ATTR_STA_FLAGS2] = {
302 .len = sizeof(struct nl80211_sta_flag_update),
303 },
3f77316c 304 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
305 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
306 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
307 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
308 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
309 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 310 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 311 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
312 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
313 .len = WLAN_PMKID_LEN },
9588bbd5
JM
314 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
315 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 316 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
317 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
318 .len = IEEE80211_MAX_DATA_LEN },
319 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 320 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 321 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 322 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 323 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
324 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
325 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 326 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
327 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
328 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 329 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 330 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 331 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 332 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 333 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 334 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 335 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 336 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 337 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
338 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
339 .len = IEEE80211_MAX_DATA_LEN },
340 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
341 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 342 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 343 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 344 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
345 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
346 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
347 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
348 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
349 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 350 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
351 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
352 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 353 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
354 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
355 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
356 .len = NL80211_HT_CAPABILITY_LEN
357 },
1d9d9213 358 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 359 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 360 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 361 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 362 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 363 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 364 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 365 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
366 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
367 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
368 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
369 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
55682965
JB
370};
371
e31b8213 372/* policy for the key attributes */
b54452b0 373static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 374 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
375 [NL80211_KEY_IDX] = { .type = NLA_U8 },
376 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 377 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
378 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
379 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 380 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
381 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
382};
383
384/* policy for the key default flags */
385static const struct nla_policy
386nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
387 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
388 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
389};
390
ff1b6e69
JB
391/* policy for WoWLAN attributes */
392static const struct nla_policy
393nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
394 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
395 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
396 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
397 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
398 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
399 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
400 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
401 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
402};
403
e5497d76
JB
404/* policy for GTK rekey offload attributes */
405static const struct nla_policy
406nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
407 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
408 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
409 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
410};
411
a1f1c21c
LC
412static const struct nla_policy
413nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 414 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 415 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 416 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
417};
418
a043897a
HS
419/* ifidx get helper */
420static int nl80211_get_ifidx(struct netlink_callback *cb)
421{
422 int res;
423
424 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
425 nl80211_fam.attrbuf, nl80211_fam.maxattr,
426 nl80211_policy);
427 if (res)
428 return res;
429
430 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
431 return -EINVAL;
432
433 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
434 if (!res)
435 return -EINVAL;
436 return res;
437}
438
67748893
JB
439static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
440 struct netlink_callback *cb,
441 struct cfg80211_registered_device **rdev,
442 struct net_device **dev)
443{
444 int ifidx = cb->args[0];
445 int err;
446
447 if (!ifidx)
448 ifidx = nl80211_get_ifidx(cb);
449 if (ifidx < 0)
450 return ifidx;
451
452 cb->args[0] = ifidx;
453
454 rtnl_lock();
455
456 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
457 if (!*dev) {
458 err = -ENODEV;
459 goto out_rtnl;
460 }
461
462 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
463 if (IS_ERR(*rdev)) {
464 err = PTR_ERR(*rdev);
67748893
JB
465 goto out_rtnl;
466 }
467
468 return 0;
469 out_rtnl:
470 rtnl_unlock();
471 return err;
472}
473
474static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
475{
476 cfg80211_unlock_rdev(rdev);
477 rtnl_unlock();
478}
479
f4a11bb0
JB
480/* IE validation */
481static bool is_valid_ie_attr(const struct nlattr *attr)
482{
483 const u8 *pos;
484 int len;
485
486 if (!attr)
487 return true;
488
489 pos = nla_data(attr);
490 len = nla_len(attr);
491
492 while (len) {
493 u8 elemlen;
494
495 if (len < 2)
496 return false;
497 len -= 2;
498
499 elemlen = pos[1];
500 if (elemlen > len)
501 return false;
502
503 len -= elemlen;
504 pos += 2 + elemlen;
505 }
506
507 return true;
508}
509
55682965 510/* message building helper */
15e47304 511static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
512 int flags, u8 cmd)
513{
514 /* since there is no private header just add the generic one */
15e47304 515 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
516}
517
5dab3b8a
LR
518static int nl80211_msg_put_channel(struct sk_buff *msg,
519 struct ieee80211_channel *chan)
520{
9360ffd1
DM
521 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
522 chan->center_freq))
523 goto nla_put_failure;
5dab3b8a 524
9360ffd1
DM
525 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
526 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
527 goto nla_put_failure;
528 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
529 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
530 goto nla_put_failure;
531 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
532 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
533 goto nla_put_failure;
534 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
535 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
536 goto nla_put_failure;
5dab3b8a 537
9360ffd1
DM
538 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
539 DBM_TO_MBM(chan->max_power)))
540 goto nla_put_failure;
5dab3b8a
LR
541
542 return 0;
543
544 nla_put_failure:
545 return -ENOBUFS;
546}
547
55682965
JB
548/* netlink command implementations */
549
b9454e83
JB
550struct key_parse {
551 struct key_params p;
552 int idx;
e31b8213 553 int type;
b9454e83 554 bool def, defmgmt;
dbd2fd65 555 bool def_uni, def_multi;
b9454e83
JB
556};
557
558static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
559{
560 struct nlattr *tb[NL80211_KEY_MAX + 1];
561 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
562 nl80211_key_policy);
563 if (err)
564 return err;
565
566 k->def = !!tb[NL80211_KEY_DEFAULT];
567 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
568
dbd2fd65
JB
569 if (k->def) {
570 k->def_uni = true;
571 k->def_multi = true;
572 }
573 if (k->defmgmt)
574 k->def_multi = true;
575
b9454e83
JB
576 if (tb[NL80211_KEY_IDX])
577 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
578
579 if (tb[NL80211_KEY_DATA]) {
580 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
581 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
582 }
583
584 if (tb[NL80211_KEY_SEQ]) {
585 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
586 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
587 }
588
589 if (tb[NL80211_KEY_CIPHER])
590 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
591
e31b8213
JB
592 if (tb[NL80211_KEY_TYPE]) {
593 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
594 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
595 return -EINVAL;
596 }
597
dbd2fd65
JB
598 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
599 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
600 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
601 tb[NL80211_KEY_DEFAULT_TYPES],
602 nl80211_key_default_policy);
dbd2fd65
JB
603 if (err)
604 return err;
605
606 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
607 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
608 }
609
b9454e83
JB
610 return 0;
611}
612
613static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
614{
615 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
616 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
617 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
618 }
619
620 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
621 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
622 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
623 }
624
625 if (info->attrs[NL80211_ATTR_KEY_IDX])
626 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
627
628 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
629 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
630
631 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
632 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
633
dbd2fd65
JB
634 if (k->def) {
635 k->def_uni = true;
636 k->def_multi = true;
637 }
638 if (k->defmgmt)
639 k->def_multi = true;
640
e31b8213
JB
641 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
642 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
643 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
644 return -EINVAL;
645 }
646
dbd2fd65
JB
647 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
648 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
649 int err = nla_parse_nested(
650 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
651 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
652 nl80211_key_default_policy);
653 if (err)
654 return err;
655
656 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
657 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
658 }
659
b9454e83
JB
660 return 0;
661}
662
663static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
664{
665 int err;
666
667 memset(k, 0, sizeof(*k));
668 k->idx = -1;
e31b8213 669 k->type = -1;
b9454e83
JB
670
671 if (info->attrs[NL80211_ATTR_KEY])
672 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
673 else
674 err = nl80211_parse_key_old(info, k);
675
676 if (err)
677 return err;
678
679 if (k->def && k->defmgmt)
680 return -EINVAL;
681
dbd2fd65
JB
682 if (k->defmgmt) {
683 if (k->def_uni || !k->def_multi)
684 return -EINVAL;
685 }
686
b9454e83
JB
687 if (k->idx != -1) {
688 if (k->defmgmt) {
689 if (k->idx < 4 || k->idx > 5)
690 return -EINVAL;
691 } else if (k->def) {
692 if (k->idx < 0 || k->idx > 3)
693 return -EINVAL;
694 } else {
695 if (k->idx < 0 || k->idx > 5)
696 return -EINVAL;
697 }
698 }
699
700 return 0;
701}
702
fffd0934
JB
703static struct cfg80211_cached_keys *
704nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 705 struct nlattr *keys, bool *no_ht)
fffd0934
JB
706{
707 struct key_parse parse;
708 struct nlattr *key;
709 struct cfg80211_cached_keys *result;
710 int rem, err, def = 0;
711
712 result = kzalloc(sizeof(*result), GFP_KERNEL);
713 if (!result)
714 return ERR_PTR(-ENOMEM);
715
716 result->def = -1;
717 result->defmgmt = -1;
718
719 nla_for_each_nested(key, keys, rem) {
720 memset(&parse, 0, sizeof(parse));
721 parse.idx = -1;
722
723 err = nl80211_parse_key_new(key, &parse);
724 if (err)
725 goto error;
726 err = -EINVAL;
727 if (!parse.p.key)
728 goto error;
729 if (parse.idx < 0 || parse.idx > 4)
730 goto error;
731 if (parse.def) {
732 if (def)
733 goto error;
734 def = 1;
735 result->def = parse.idx;
dbd2fd65
JB
736 if (!parse.def_uni || !parse.def_multi)
737 goto error;
fffd0934
JB
738 } else if (parse.defmgmt)
739 goto error;
740 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 741 parse.idx, false, NULL);
fffd0934
JB
742 if (err)
743 goto error;
744 result->params[parse.idx].cipher = parse.p.cipher;
745 result->params[parse.idx].key_len = parse.p.key_len;
746 result->params[parse.idx].key = result->data[parse.idx];
747 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
748
749 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
750 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
751 if (no_ht)
752 *no_ht = true;
753 }
fffd0934
JB
754 }
755
756 return result;
757 error:
758 kfree(result);
759 return ERR_PTR(err);
760}
761
762static int nl80211_key_allowed(struct wireless_dev *wdev)
763{
764 ASSERT_WDEV_LOCK(wdev);
765
fffd0934
JB
766 switch (wdev->iftype) {
767 case NL80211_IFTYPE_AP:
768 case NL80211_IFTYPE_AP_VLAN:
074ac8df 769 case NL80211_IFTYPE_P2P_GO:
ff973af7 770 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
771 break;
772 case NL80211_IFTYPE_ADHOC:
773 if (!wdev->current_bss)
774 return -ENOLINK;
775 break;
776 case NL80211_IFTYPE_STATION:
074ac8df 777 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
778 if (wdev->sme_state != CFG80211_SME_CONNECTED)
779 return -ENOLINK;
780 break;
781 default:
782 return -EINVAL;
783 }
784
785 return 0;
786}
787
7527a782
JB
788static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
789{
790 struct nlattr *nl_modes = nla_nest_start(msg, attr);
791 int i;
792
793 if (!nl_modes)
794 goto nla_put_failure;
795
796 i = 0;
797 while (ifmodes) {
9360ffd1
DM
798 if ((ifmodes & 1) && nla_put_flag(msg, i))
799 goto nla_put_failure;
7527a782
JB
800 ifmodes >>= 1;
801 i++;
802 }
803
804 nla_nest_end(msg, nl_modes);
805 return 0;
806
807nla_put_failure:
808 return -ENOBUFS;
809}
810
811static int nl80211_put_iface_combinations(struct wiphy *wiphy,
812 struct sk_buff *msg)
813{
814 struct nlattr *nl_combis;
815 int i, j;
816
817 nl_combis = nla_nest_start(msg,
818 NL80211_ATTR_INTERFACE_COMBINATIONS);
819 if (!nl_combis)
820 goto nla_put_failure;
821
822 for (i = 0; i < wiphy->n_iface_combinations; i++) {
823 const struct ieee80211_iface_combination *c;
824 struct nlattr *nl_combi, *nl_limits;
825
826 c = &wiphy->iface_combinations[i];
827
828 nl_combi = nla_nest_start(msg, i + 1);
829 if (!nl_combi)
830 goto nla_put_failure;
831
832 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
833 if (!nl_limits)
834 goto nla_put_failure;
835
836 for (j = 0; j < c->n_limits; j++) {
837 struct nlattr *nl_limit;
838
839 nl_limit = nla_nest_start(msg, j + 1);
840 if (!nl_limit)
841 goto nla_put_failure;
9360ffd1
DM
842 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
843 c->limits[j].max))
844 goto nla_put_failure;
7527a782
JB
845 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
846 c->limits[j].types))
847 goto nla_put_failure;
848 nla_nest_end(msg, nl_limit);
849 }
850
851 nla_nest_end(msg, nl_limits);
852
9360ffd1
DM
853 if (c->beacon_int_infra_match &&
854 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
855 goto nla_put_failure;
856 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
857 c->num_different_channels) ||
858 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
859 c->max_interfaces))
860 goto nla_put_failure;
11c4a075
SW
861 if (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
862 c->radar_detect_widths))
863 goto nla_put_failure;
7527a782
JB
864
865 nla_nest_end(msg, nl_combi);
866 }
867
868 nla_nest_end(msg, nl_combis);
869
870 return 0;
871nla_put_failure:
872 return -ENOBUFS;
873}
874
15e47304 875static int nl80211_send_wiphy(struct sk_buff *msg, u32 portid, u32 seq, int flags,
55682965
JB
876 struct cfg80211_registered_device *dev)
877{
878 void *hdr;
ee688b00
JB
879 struct nlattr *nl_bands, *nl_band;
880 struct nlattr *nl_freqs, *nl_freq;
881 struct nlattr *nl_rates, *nl_rate;
8fdc621d 882 struct nlattr *nl_cmds;
ee688b00
JB
883 enum ieee80211_band band;
884 struct ieee80211_channel *chan;
885 struct ieee80211_rate *rate;
886 int i;
2e161f78
JB
887 const struct ieee80211_txrx_stypes *mgmt_stypes =
888 dev->wiphy.mgmt_stypes;
55682965 889
15e47304 890 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
55682965
JB
891 if (!hdr)
892 return -1;
893
9360ffd1
DM
894 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
895 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
896 nla_put_u32(msg, NL80211_ATTR_GENERATION,
897 cfg80211_rdev_list_generation) ||
898 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
899 dev->wiphy.retry_short) ||
900 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
901 dev->wiphy.retry_long) ||
902 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
903 dev->wiphy.frag_threshold) ||
904 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
905 dev->wiphy.rts_threshold) ||
906 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
907 dev->wiphy.coverage_class) ||
908 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
909 dev->wiphy.max_scan_ssids) ||
910 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
911 dev->wiphy.max_sched_scan_ssids) ||
912 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
913 dev->wiphy.max_scan_ie_len) ||
914 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
915 dev->wiphy.max_sched_scan_ie_len) ||
916 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
917 dev->wiphy.max_match_sets))
918 goto nla_put_failure;
919
920 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
921 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
922 goto nla_put_failure;
923 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
924 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
925 goto nla_put_failure;
926 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
927 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
928 goto nla_put_failure;
929 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
930 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
931 goto nla_put_failure;
932 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
933 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
934 goto nla_put_failure;
935 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
936 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
937 goto nla_put_failure;
938
939 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
940 sizeof(u32) * dev->wiphy.n_cipher_suites,
941 dev->wiphy.cipher_suites))
942 goto nla_put_failure;
943
944 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
945 dev->wiphy.max_num_pmkids))
946 goto nla_put_failure;
947
948 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
949 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
950 goto nla_put_failure;
951
952 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
953 dev->wiphy.available_antennas_tx) ||
954 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
955 dev->wiphy.available_antennas_rx))
956 goto nla_put_failure;
957
958 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
959 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
960 dev->wiphy.probe_resp_offload))
961 goto nla_put_failure;
87bbbe22 962
7f531e03
BR
963 if ((dev->wiphy.available_antennas_tx ||
964 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
965 u32 tx_ant = 0, rx_ant = 0;
966 int res;
e35e4d28 967 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
afe0cbf8 968 if (!res) {
9360ffd1
DM
969 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
970 tx_ant) ||
971 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
972 rx_ant))
973 goto nla_put_failure;
afe0cbf8
BR
974 }
975 }
976
7527a782
JB
977 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
978 dev->wiphy.interface_modes))
f59ac048
LR
979 goto nla_put_failure;
980
ee688b00
JB
981 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
982 if (!nl_bands)
983 goto nla_put_failure;
984
985 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
986 if (!dev->wiphy.bands[band])
987 continue;
988
989 nl_band = nla_nest_start(msg, band);
990 if (!nl_band)
991 goto nla_put_failure;
992
d51626df 993 /* add HT info */
9360ffd1
DM
994 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
995 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
996 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
997 &dev->wiphy.bands[band]->ht_cap.mcs) ||
998 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
999 dev->wiphy.bands[band]->ht_cap.cap) ||
1000 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1001 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
1002 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1003 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
1004 goto nla_put_failure;
d51626df 1005
bf0c111e
MP
1006 /* add VHT info */
1007 if (dev->wiphy.bands[band]->vht_cap.vht_supported &&
1008 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1009 sizeof(dev->wiphy.bands[band]->vht_cap.vht_mcs),
1010 &dev->wiphy.bands[band]->vht_cap.vht_mcs) ||
1011 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1012 dev->wiphy.bands[band]->vht_cap.cap)))
1013 goto nla_put_failure;
1014
ee688b00
JB
1015 /* add frequencies */
1016 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
1017 if (!nl_freqs)
1018 goto nla_put_failure;
1019
1020 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
1021 nl_freq = nla_nest_start(msg, i);
1022 if (!nl_freq)
1023 goto nla_put_failure;
1024
1025 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
1026
1027 if (nl80211_msg_put_channel(msg, chan))
1028 goto nla_put_failure;
e2f367f2 1029
ee688b00
JB
1030 nla_nest_end(msg, nl_freq);
1031 }
1032
1033 nla_nest_end(msg, nl_freqs);
1034
1035 /* add bitrates */
1036 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1037 if (!nl_rates)
1038 goto nla_put_failure;
1039
1040 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
1041 nl_rate = nla_nest_start(msg, i);
1042 if (!nl_rate)
1043 goto nla_put_failure;
1044
1045 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
1046 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1047 rate->bitrate))
1048 goto nla_put_failure;
1049 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1050 nla_put_flag(msg,
1051 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1052 goto nla_put_failure;
ee688b00
JB
1053
1054 nla_nest_end(msg, nl_rate);
1055 }
1056
1057 nla_nest_end(msg, nl_rates);
1058
1059 nla_nest_end(msg, nl_band);
1060 }
1061 nla_nest_end(msg, nl_bands);
1062
8fdc621d
JB
1063 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1064 if (!nl_cmds)
1065 goto nla_put_failure;
1066
1067 i = 0;
1068#define CMD(op, n) \
1069 do { \
1070 if (dev->ops->op) { \
1071 i++; \
9360ffd1
DM
1072 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1073 goto nla_put_failure; \
8fdc621d
JB
1074 } \
1075 } while (0)
1076
1077 CMD(add_virtual_intf, NEW_INTERFACE);
1078 CMD(change_virtual_intf, SET_INTERFACE);
1079 CMD(add_key, NEW_KEY);
8860020e 1080 CMD(start_ap, START_AP);
8fdc621d
JB
1081 CMD(add_station, NEW_STATION);
1082 CMD(add_mpath, NEW_MPATH);
24bdd9f4 1083 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 1084 CMD(change_bss, SET_BSS);
636a5d36
JM
1085 CMD(auth, AUTHENTICATE);
1086 CMD(assoc, ASSOCIATE);
1087 CMD(deauth, DEAUTHENTICATE);
1088 CMD(disassoc, DISASSOCIATE);
04a773ad 1089 CMD(join_ibss, JOIN_IBSS);
29cbe68c 1090 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
1091 CMD(set_pmksa, SET_PMKSA);
1092 CMD(del_pmksa, DEL_PMKSA);
1093 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
1094 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1095 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 1096 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 1097 CMD(mgmt_tx, FRAME);
f7ca38df 1098 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 1099 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 1100 i++;
9360ffd1
DM
1101 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1102 goto nla_put_failure;
463d0183 1103 }
e8c9bd5b 1104 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 1105 dev->ops->join_mesh) {
aa430da4
JB
1106 i++;
1107 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1108 goto nla_put_failure;
1109 }
e8347eba 1110 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
1111 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1112 CMD(tdls_mgmt, TDLS_MGMT);
1113 CMD(tdls_oper, TDLS_OPER);
1114 }
807f8a8c
LC
1115 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1116 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 1117 CMD(probe_client, PROBE_CLIENT);
1d9d9213 1118 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
1119 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1120 i++;
9360ffd1
DM
1121 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1122 goto nla_put_failure;
5e760230 1123 }
98104fde 1124 CMD(start_p2p_device, START_P2P_DEVICE);
f4e583c8 1125 CMD(set_mcast_rate, SET_MCAST_RATE);
8fdc621d 1126
4745fc09
KV
1127#ifdef CONFIG_NL80211_TESTMODE
1128 CMD(testmode_cmd, TESTMODE);
1129#endif
1130
8fdc621d 1131#undef CMD
b23aa676 1132
6829c878 1133 if (dev->ops->connect || dev->ops->auth) {
b23aa676 1134 i++;
9360ffd1
DM
1135 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1136 goto nla_put_failure;
b23aa676
SO
1137 }
1138
6829c878 1139 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 1140 i++;
9360ffd1
DM
1141 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1142 goto nla_put_failure;
b23aa676
SO
1143 }
1144
8fdc621d
JB
1145 nla_nest_end(msg, nl_cmds);
1146
7c4ef712 1147 if (dev->ops->remain_on_channel &&
9360ffd1
DM
1148 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1149 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1150 dev->wiphy.max_remain_on_channel_duration))
1151 goto nla_put_failure;
a293911d 1152
9360ffd1
DM
1153 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1154 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1155 goto nla_put_failure;
f7ca38df 1156
2e161f78
JB
1157 if (mgmt_stypes) {
1158 u16 stypes;
1159 struct nlattr *nl_ftypes, *nl_ifs;
1160 enum nl80211_iftype ift;
1161
1162 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1163 if (!nl_ifs)
1164 goto nla_put_failure;
1165
1166 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1167 nl_ftypes = nla_nest_start(msg, ift);
1168 if (!nl_ftypes)
1169 goto nla_put_failure;
1170 i = 0;
1171 stypes = mgmt_stypes[ift].tx;
1172 while (stypes) {
9360ffd1
DM
1173 if ((stypes & 1) &&
1174 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1175 (i << 4) | IEEE80211_FTYPE_MGMT))
1176 goto nla_put_failure;
2e161f78
JB
1177 stypes >>= 1;
1178 i++;
1179 }
1180 nla_nest_end(msg, nl_ftypes);
1181 }
1182
74b70a4e
JB
1183 nla_nest_end(msg, nl_ifs);
1184
2e161f78
JB
1185 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1186 if (!nl_ifs)
1187 goto nla_put_failure;
1188
1189 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1190 nl_ftypes = nla_nest_start(msg, ift);
1191 if (!nl_ftypes)
1192 goto nla_put_failure;
1193 i = 0;
1194 stypes = mgmt_stypes[ift].rx;
1195 while (stypes) {
9360ffd1
DM
1196 if ((stypes & 1) &&
1197 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1198 (i << 4) | IEEE80211_FTYPE_MGMT))
1199 goto nla_put_failure;
2e161f78
JB
1200 stypes >>= 1;
1201 i++;
1202 }
1203 nla_nest_end(msg, nl_ftypes);
1204 }
1205 nla_nest_end(msg, nl_ifs);
1206 }
1207
dfb89c56 1208#ifdef CONFIG_PM
ff1b6e69
JB
1209 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1210 struct nlattr *nl_wowlan;
1211
1212 nl_wowlan = nla_nest_start(msg,
1213 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1214 if (!nl_wowlan)
1215 goto nla_put_failure;
1216
9360ffd1
DM
1217 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1218 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1219 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1220 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1221 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1222 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1223 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1224 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1225 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1226 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1227 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1228 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1229 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1230 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1231 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1232 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1233 goto nla_put_failure;
ff1b6e69
JB
1234 if (dev->wiphy.wowlan.n_patterns) {
1235 struct nl80211_wowlan_pattern_support pat = {
1236 .max_patterns = dev->wiphy.wowlan.n_patterns,
1237 .min_pattern_len =
1238 dev->wiphy.wowlan.pattern_min_len,
1239 .max_pattern_len =
1240 dev->wiphy.wowlan.pattern_max_len,
1241 };
9360ffd1
DM
1242 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1243 sizeof(pat), &pat))
1244 goto nla_put_failure;
ff1b6e69
JB
1245 }
1246
1247 nla_nest_end(msg, nl_wowlan);
1248 }
dfb89c56 1249#endif
ff1b6e69 1250
7527a782
JB
1251 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1252 dev->wiphy.software_iftypes))
1253 goto nla_put_failure;
1254
1255 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1256 goto nla_put_failure;
1257
9360ffd1
DM
1258 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1259 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1260 dev->wiphy.ap_sme_capa))
1261 goto nla_put_failure;
562a7480 1262
9360ffd1
DM
1263 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1264 dev->wiphy.features))
1265 goto nla_put_failure;
1f074bd8 1266
9360ffd1
DM
1267 if (dev->wiphy.ht_capa_mod_mask &&
1268 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1269 sizeof(*dev->wiphy.ht_capa_mod_mask),
1270 dev->wiphy.ht_capa_mod_mask))
1271 goto nla_put_failure;
7e7c8926 1272
77765eaf
VT
1273 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1274 dev->wiphy.max_acl_mac_addrs &&
1275 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1276 dev->wiphy.max_acl_mac_addrs))
1277 goto nla_put_failure;
1278
55682965
JB
1279 return genlmsg_end(msg, hdr);
1280
1281 nla_put_failure:
bc3ed28c
TG
1282 genlmsg_cancel(msg, hdr);
1283 return -EMSGSIZE;
55682965
JB
1284}
1285
1286static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1287{
1288 int idx = 0;
1289 int start = cb->args[0];
1290 struct cfg80211_registered_device *dev;
1291
a1794390 1292 mutex_lock(&cfg80211_mutex);
79c97e97 1293 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1294 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1295 continue;
b4637271 1296 if (++idx <= start)
55682965 1297 continue;
15e47304 1298 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).portid,
55682965 1299 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1300 dev) < 0) {
1301 idx--;
55682965 1302 break;
b4637271 1303 }
55682965 1304 }
a1794390 1305 mutex_unlock(&cfg80211_mutex);
55682965
JB
1306
1307 cb->args[0] = idx;
1308
1309 return skb->len;
1310}
1311
1312static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1313{
1314 struct sk_buff *msg;
4c476991 1315 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1316
fd2120ca 1317 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1318 if (!msg)
4c476991 1319 return -ENOMEM;
55682965 1320
15e47304 1321 if (nl80211_send_wiphy(msg, info->snd_portid, info->snd_seq, 0, dev) < 0) {
4c476991
JB
1322 nlmsg_free(msg);
1323 return -ENOBUFS;
1324 }
55682965 1325
134e6375 1326 return genlmsg_reply(msg, info);
55682965
JB
1327}
1328
31888487
JM
1329static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1330 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1331 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1332 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1333 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1334 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1335};
1336
1337static int parse_txq_params(struct nlattr *tb[],
1338 struct ieee80211_txq_params *txq_params)
1339{
a3304b0a 1340 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1341 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1342 !tb[NL80211_TXQ_ATTR_AIFS])
1343 return -EINVAL;
1344
a3304b0a 1345 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1346 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1347 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1348 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1349 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1350
a3304b0a
JB
1351 if (txq_params->ac >= NL80211_NUM_ACS)
1352 return -EINVAL;
1353
31888487
JM
1354 return 0;
1355}
1356
f444de05
JB
1357static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1358{
1359 /*
cc1d2806
JB
1360 * You can only set the channel explicitly for WDS interfaces,
1361 * all others have their channel managed via their respective
1362 * "establish a connection" command (connect, join, ...)
1363 *
1364 * For AP/GO and mesh mode, the channel can be set with the
1365 * channel userspace API, but is only stored and passed to the
1366 * low-level driver when the AP starts or the mesh is joined.
1367 * This is for backward compatibility, userspace can also give
1368 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1369 *
1370 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1371 * whatever else is going on, so they have their own special
1372 * operation to set the monitor channel if possible.
f444de05
JB
1373 */
1374 return !wdev ||
1375 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1376 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1377 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1378 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1379}
1380
683b6d3b
JB
1381static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1382 struct genl_info *info,
1383 struct cfg80211_chan_def *chandef)
1384{
dbeca2ea 1385 u32 control_freq;
683b6d3b
JB
1386
1387 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1388 return -EINVAL;
1389
1390 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1391
1392 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1393 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1394 chandef->center_freq1 = control_freq;
1395 chandef->center_freq2 = 0;
683b6d3b
JB
1396
1397 /* Primary channel not allowed */
1398 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1399 return -EINVAL;
1400
3d9d1d66
JB
1401 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1402 enum nl80211_channel_type chantype;
1403
1404 chantype = nla_get_u32(
1405 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1406
1407 switch (chantype) {
1408 case NL80211_CHAN_NO_HT:
1409 case NL80211_CHAN_HT20:
1410 case NL80211_CHAN_HT40PLUS:
1411 case NL80211_CHAN_HT40MINUS:
1412 cfg80211_chandef_create(chandef, chandef->chan,
1413 chantype);
1414 break;
1415 default:
1416 return -EINVAL;
1417 }
1418 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1419 chandef->width =
1420 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1421 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1422 chandef->center_freq1 =
1423 nla_get_u32(
1424 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1425 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1426 chandef->center_freq2 =
1427 nla_get_u32(
1428 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1429 }
1430
9f5e8f6e 1431 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1432 return -EINVAL;
1433
9f5e8f6e
JB
1434 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1435 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1436 return -EINVAL;
1437
683b6d3b
JB
1438 return 0;
1439}
1440
f444de05
JB
1441static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1442 struct wireless_dev *wdev,
1443 struct genl_info *info)
1444{
683b6d3b 1445 struct cfg80211_chan_def chandef;
f444de05 1446 int result;
e8c9bd5b
JB
1447 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1448
1449 if (wdev)
1450 iftype = wdev->iftype;
f444de05 1451
f444de05
JB
1452 if (!nl80211_can_set_dev_channel(wdev))
1453 return -EOPNOTSUPP;
1454
683b6d3b
JB
1455 result = nl80211_parse_chandef(rdev, info, &chandef);
1456 if (result)
1457 return result;
f444de05
JB
1458
1459 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1460 switch (iftype) {
aa430da4
JB
1461 case NL80211_IFTYPE_AP:
1462 case NL80211_IFTYPE_P2P_GO:
1463 if (wdev->beacon_interval) {
1464 result = -EBUSY;
1465 break;
1466 }
683b6d3b 1467 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1468 result = -EINVAL;
1469 break;
1470 }
683b6d3b 1471 wdev->preset_chandef = chandef;
aa430da4
JB
1472 result = 0;
1473 break;
cc1d2806 1474 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1475 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1476 break;
e8c9bd5b 1477 case NL80211_IFTYPE_MONITOR:
683b6d3b 1478 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1479 break;
aa430da4 1480 default:
e8c9bd5b 1481 result = -EINVAL;
f444de05
JB
1482 }
1483 mutex_unlock(&rdev->devlist_mtx);
1484
1485 return result;
1486}
1487
1488static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1489{
4c476991
JB
1490 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1491 struct net_device *netdev = info->user_ptr[1];
f444de05 1492
4c476991 1493 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1494}
1495
e8347eba
BJ
1496static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1497{
43b19952
JB
1498 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1499 struct net_device *dev = info->user_ptr[1];
1500 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1501 const u8 *bssid;
e8347eba
BJ
1502
1503 if (!info->attrs[NL80211_ATTR_MAC])
1504 return -EINVAL;
1505
43b19952
JB
1506 if (netif_running(dev))
1507 return -EBUSY;
e8347eba 1508
43b19952
JB
1509 if (!rdev->ops->set_wds_peer)
1510 return -EOPNOTSUPP;
e8347eba 1511
43b19952
JB
1512 if (wdev->iftype != NL80211_IFTYPE_WDS)
1513 return -EOPNOTSUPP;
e8347eba
BJ
1514
1515 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1516 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1517}
1518
1519
55682965
JB
1520static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1521{
1522 struct cfg80211_registered_device *rdev;
f444de05
JB
1523 struct net_device *netdev = NULL;
1524 struct wireless_dev *wdev;
a1e567c8 1525 int result = 0, rem_txq_params = 0;
31888487 1526 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1527 u32 changed;
1528 u8 retry_short = 0, retry_long = 0;
1529 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1530 u8 coverage_class = 0;
55682965 1531
f444de05
JB
1532 /*
1533 * Try to find the wiphy and netdev. Normally this
1534 * function shouldn't need the netdev, but this is
1535 * done for backward compatibility -- previously
1536 * setting the channel was done per wiphy, but now
1537 * it is per netdev. Previous userland like hostapd
1538 * also passed a netdev to set_wiphy, so that it is
1539 * possible to let that go to the right netdev!
1540 */
4bbf4d56
JB
1541 mutex_lock(&cfg80211_mutex);
1542
f444de05
JB
1543 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1544 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1545
1546 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1547 if (netdev && netdev->ieee80211_ptr) {
1548 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1549 mutex_lock(&rdev->mtx);
1550 } else
1551 netdev = NULL;
4bbf4d56
JB
1552 }
1553
f444de05 1554 if (!netdev) {
878d9ec7
JB
1555 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1556 info->attrs);
f444de05
JB
1557 if (IS_ERR(rdev)) {
1558 mutex_unlock(&cfg80211_mutex);
4c476991 1559 return PTR_ERR(rdev);
f444de05
JB
1560 }
1561 wdev = NULL;
1562 netdev = NULL;
1563 result = 0;
1564
1565 mutex_lock(&rdev->mtx);
71fe96bf 1566 } else
f444de05 1567 wdev = netdev->ieee80211_ptr;
f444de05
JB
1568
1569 /*
1570 * end workaround code, by now the rdev is available
1571 * and locked, and wdev may or may not be NULL.
1572 */
4bbf4d56
JB
1573
1574 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1575 result = cfg80211_dev_rename(
1576 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1577
1578 mutex_unlock(&cfg80211_mutex);
1579
1580 if (result)
1581 goto bad_res;
31888487
JM
1582
1583 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1584 struct ieee80211_txq_params txq_params;
1585 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1586
1587 if (!rdev->ops->set_txq_params) {
1588 result = -EOPNOTSUPP;
1589 goto bad_res;
1590 }
1591
f70f01c2
EP
1592 if (!netdev) {
1593 result = -EINVAL;
1594 goto bad_res;
1595 }
1596
133a3ff2
JB
1597 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1598 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1599 result = -EINVAL;
1600 goto bad_res;
1601 }
1602
2b5f8b0b
JB
1603 if (!netif_running(netdev)) {
1604 result = -ENETDOWN;
1605 goto bad_res;
1606 }
1607
31888487
JM
1608 nla_for_each_nested(nl_txq_params,
1609 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1610 rem_txq_params) {
1611 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1612 nla_data(nl_txq_params),
1613 nla_len(nl_txq_params),
1614 txq_params_policy);
1615 result = parse_txq_params(tb, &txq_params);
1616 if (result)
1617 goto bad_res;
1618
e35e4d28
HG
1619 result = rdev_set_txq_params(rdev, netdev,
1620 &txq_params);
31888487
JM
1621 if (result)
1622 goto bad_res;
1623 }
1624 }
55682965 1625
72bdcf34 1626 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1627 result = __nl80211_set_channel(rdev,
1628 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1629 info);
72bdcf34
JM
1630 if (result)
1631 goto bad_res;
1632 }
1633
98d2ff8b 1634 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 1635 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
1636 enum nl80211_tx_power_setting type;
1637 int idx, mbm = 0;
1638
c8442118
JB
1639 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
1640 txp_wdev = NULL;
1641
98d2ff8b 1642 if (!rdev->ops->set_tx_power) {
60ea385f 1643 result = -EOPNOTSUPP;
98d2ff8b
JO
1644 goto bad_res;
1645 }
1646
1647 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1648 type = nla_get_u32(info->attrs[idx]);
1649
1650 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1651 (type != NL80211_TX_POWER_AUTOMATIC)) {
1652 result = -EINVAL;
1653 goto bad_res;
1654 }
1655
1656 if (type != NL80211_TX_POWER_AUTOMATIC) {
1657 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1658 mbm = nla_get_u32(info->attrs[idx]);
1659 }
1660
c8442118 1661 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
1662 if (result)
1663 goto bad_res;
1664 }
1665
afe0cbf8
BR
1666 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1667 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1668 u32 tx_ant, rx_ant;
7f531e03
BR
1669 if ((!rdev->wiphy.available_antennas_tx &&
1670 !rdev->wiphy.available_antennas_rx) ||
1671 !rdev->ops->set_antenna) {
afe0cbf8
BR
1672 result = -EOPNOTSUPP;
1673 goto bad_res;
1674 }
1675
1676 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1677 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1678
a7ffac95 1679 /* reject antenna configurations which don't match the
7f531e03
BR
1680 * available antenna masks, except for the "all" mask */
1681 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1682 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1683 result = -EINVAL;
1684 goto bad_res;
1685 }
1686
7f531e03
BR
1687 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1688 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1689
e35e4d28 1690 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
1691 if (result)
1692 goto bad_res;
1693 }
1694
b9a5f8ca
JM
1695 changed = 0;
1696
1697 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1698 retry_short = nla_get_u8(
1699 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1700 if (retry_short == 0) {
1701 result = -EINVAL;
1702 goto bad_res;
1703 }
1704 changed |= WIPHY_PARAM_RETRY_SHORT;
1705 }
1706
1707 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1708 retry_long = nla_get_u8(
1709 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1710 if (retry_long == 0) {
1711 result = -EINVAL;
1712 goto bad_res;
1713 }
1714 changed |= WIPHY_PARAM_RETRY_LONG;
1715 }
1716
1717 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1718 frag_threshold = nla_get_u32(
1719 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1720 if (frag_threshold < 256) {
1721 result = -EINVAL;
1722 goto bad_res;
1723 }
1724 if (frag_threshold != (u32) -1) {
1725 /*
1726 * Fragments (apart from the last one) are required to
1727 * have even length. Make the fragmentation code
1728 * simpler by stripping LSB should someone try to use
1729 * odd threshold value.
1730 */
1731 frag_threshold &= ~0x1;
1732 }
1733 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1734 }
1735
1736 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1737 rts_threshold = nla_get_u32(
1738 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1739 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1740 }
1741
81077e82
LT
1742 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1743 coverage_class = nla_get_u8(
1744 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1745 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1746 }
1747
b9a5f8ca
JM
1748 if (changed) {
1749 u8 old_retry_short, old_retry_long;
1750 u32 old_frag_threshold, old_rts_threshold;
81077e82 1751 u8 old_coverage_class;
b9a5f8ca
JM
1752
1753 if (!rdev->ops->set_wiphy_params) {
1754 result = -EOPNOTSUPP;
1755 goto bad_res;
1756 }
1757
1758 old_retry_short = rdev->wiphy.retry_short;
1759 old_retry_long = rdev->wiphy.retry_long;
1760 old_frag_threshold = rdev->wiphy.frag_threshold;
1761 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1762 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1763
1764 if (changed & WIPHY_PARAM_RETRY_SHORT)
1765 rdev->wiphy.retry_short = retry_short;
1766 if (changed & WIPHY_PARAM_RETRY_LONG)
1767 rdev->wiphy.retry_long = retry_long;
1768 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1769 rdev->wiphy.frag_threshold = frag_threshold;
1770 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1771 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1772 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1773 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 1774
e35e4d28 1775 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
1776 if (result) {
1777 rdev->wiphy.retry_short = old_retry_short;
1778 rdev->wiphy.retry_long = old_retry_long;
1779 rdev->wiphy.frag_threshold = old_frag_threshold;
1780 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1781 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1782 }
1783 }
72bdcf34 1784
306d6112 1785 bad_res:
4bbf4d56 1786 mutex_unlock(&rdev->mtx);
f444de05
JB
1787 if (netdev)
1788 dev_put(netdev);
55682965
JB
1789 return result;
1790}
1791
71bbc994
JB
1792static inline u64 wdev_id(struct wireless_dev *wdev)
1793{
1794 return (u64)wdev->identifier |
1795 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
1796}
55682965 1797
683b6d3b
JB
1798static int nl80211_send_chandef(struct sk_buff *msg,
1799 struct cfg80211_chan_def *chandef)
1800{
9f5e8f6e 1801 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 1802
683b6d3b
JB
1803 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1804 chandef->chan->center_freq))
1805 return -ENOBUFS;
3d9d1d66
JB
1806 switch (chandef->width) {
1807 case NL80211_CHAN_WIDTH_20_NOHT:
1808 case NL80211_CHAN_WIDTH_20:
1809 case NL80211_CHAN_WIDTH_40:
1810 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1811 cfg80211_get_chandef_type(chandef)))
1812 return -ENOBUFS;
1813 break;
1814 default:
1815 break;
1816 }
1817 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
1818 return -ENOBUFS;
1819 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
1820 return -ENOBUFS;
1821 if (chandef->center_freq2 &&
1822 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
1823 return -ENOBUFS;
1824 return 0;
1825}
1826
15e47304 1827static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 1828 struct cfg80211_registered_device *rdev,
72fb2abc 1829 struct wireless_dev *wdev)
55682965 1830{
72fb2abc 1831 struct net_device *dev = wdev->netdev;
55682965
JB
1832 void *hdr;
1833
15e47304 1834 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
1835 if (!hdr)
1836 return -1;
1837
72fb2abc
JB
1838 if (dev &&
1839 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 1840 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
1841 goto nla_put_failure;
1842
1843 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1844 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 1845 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 1846 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
1847 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1848 rdev->devlist_generation ^
1849 (cfg80211_rdev_list_generation << 2)))
1850 goto nla_put_failure;
f5ea9120 1851
5b7ccaf3 1852 if (rdev->ops->get_channel) {
683b6d3b
JB
1853 int ret;
1854 struct cfg80211_chan_def chandef;
1855
1856 ret = rdev_get_channel(rdev, wdev, &chandef);
1857 if (ret == 0) {
1858 if (nl80211_send_chandef(msg, &chandef))
1859 goto nla_put_failure;
1860 }
d91df0e3
PF
1861 }
1862
b84e7a05
AQ
1863 if (wdev->ssid_len) {
1864 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
1865 goto nla_put_failure;
1866 }
1867
55682965
JB
1868 return genlmsg_end(msg, hdr);
1869
1870 nla_put_failure:
bc3ed28c
TG
1871 genlmsg_cancel(msg, hdr);
1872 return -EMSGSIZE;
55682965
JB
1873}
1874
1875static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1876{
1877 int wp_idx = 0;
1878 int if_idx = 0;
1879 int wp_start = cb->args[0];
1880 int if_start = cb->args[1];
f5ea9120 1881 struct cfg80211_registered_device *rdev;
55682965
JB
1882 struct wireless_dev *wdev;
1883
a1794390 1884 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1885 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1886 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1887 continue;
bba95fef
JB
1888 if (wp_idx < wp_start) {
1889 wp_idx++;
55682965 1890 continue;
bba95fef 1891 }
55682965
JB
1892 if_idx = 0;
1893
f5ea9120 1894 mutex_lock(&rdev->devlist_mtx);
89a54e48 1895 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
1896 if (if_idx < if_start) {
1897 if_idx++;
55682965 1898 continue;
bba95fef 1899 }
15e47304 1900 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 1901 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 1902 rdev, wdev) < 0) {
f5ea9120 1903 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1904 goto out;
1905 }
1906 if_idx++;
55682965 1907 }
f5ea9120 1908 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1909
1910 wp_idx++;
55682965 1911 }
bba95fef 1912 out:
a1794390 1913 mutex_unlock(&cfg80211_mutex);
55682965
JB
1914
1915 cb->args[0] = wp_idx;
1916 cb->args[1] = if_idx;
1917
1918 return skb->len;
1919}
1920
1921static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1922{
1923 struct sk_buff *msg;
4c476991 1924 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 1925 struct wireless_dev *wdev = info->user_ptr[1];
55682965 1926
fd2120ca 1927 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1928 if (!msg)
4c476991 1929 return -ENOMEM;
55682965 1930
15e47304 1931 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 1932 dev, wdev) < 0) {
4c476991
JB
1933 nlmsg_free(msg);
1934 return -ENOBUFS;
1935 }
55682965 1936
134e6375 1937 return genlmsg_reply(msg, info);
55682965
JB
1938}
1939
66f7ac50
MW
1940static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1941 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1942 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1943 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1944 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1945 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1946};
1947
1948static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1949{
1950 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1951 int flag;
1952
1953 *mntrflags = 0;
1954
1955 if (!nla)
1956 return -EINVAL;
1957
1958 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1959 nla, mntr_flags_policy))
1960 return -EINVAL;
1961
1962 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1963 if (flags[flag])
1964 *mntrflags |= (1<<flag);
1965
1966 return 0;
1967}
1968
9bc383de 1969static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1970 struct net_device *netdev, u8 use_4addr,
1971 enum nl80211_iftype iftype)
9bc383de 1972{
ad4bb6f8 1973 if (!use_4addr) {
f350a0a8 1974 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1975 return -EBUSY;
9bc383de 1976 return 0;
ad4bb6f8 1977 }
9bc383de
JB
1978
1979 switch (iftype) {
1980 case NL80211_IFTYPE_AP_VLAN:
1981 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1982 return 0;
1983 break;
1984 case NL80211_IFTYPE_STATION:
1985 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1986 return 0;
1987 break;
1988 default:
1989 break;
1990 }
1991
1992 return -EOPNOTSUPP;
1993}
1994
55682965
JB
1995static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1996{
4c476991 1997 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1998 struct vif_params params;
e36d56b6 1999 int err;
04a773ad 2000 enum nl80211_iftype otype, ntype;
4c476991 2001 struct net_device *dev = info->user_ptr[1];
92ffe055 2002 u32 _flags, *flags = NULL;
ac7f9cfa 2003 bool change = false;
55682965 2004
2ec600d6
LCC
2005 memset(&params, 0, sizeof(params));
2006
04a773ad 2007 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2008
723b038d 2009 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2010 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2011 if (otype != ntype)
ac7f9cfa 2012 change = true;
4c476991
JB
2013 if (ntype > NL80211_IFTYPE_MAX)
2014 return -EINVAL;
723b038d
JB
2015 }
2016
92ffe055 2017 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2018 struct wireless_dev *wdev = dev->ieee80211_ptr;
2019
4c476991
JB
2020 if (ntype != NL80211_IFTYPE_MESH_POINT)
2021 return -EINVAL;
29cbe68c
JB
2022 if (netif_running(dev))
2023 return -EBUSY;
2024
2025 wdev_lock(wdev);
2026 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2027 IEEE80211_MAX_MESH_ID_LEN);
2028 wdev->mesh_id_up_len =
2029 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2030 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2031 wdev->mesh_id_up_len);
2032 wdev_unlock(wdev);
2ec600d6
LCC
2033 }
2034
8b787643
FF
2035 if (info->attrs[NL80211_ATTR_4ADDR]) {
2036 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2037 change = true;
ad4bb6f8 2038 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2039 if (err)
4c476991 2040 return err;
8b787643
FF
2041 } else {
2042 params.use_4addr = -1;
2043 }
2044
92ffe055 2045 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2046 if (ntype != NL80211_IFTYPE_MONITOR)
2047 return -EINVAL;
92ffe055
JB
2048 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2049 &_flags);
ac7f9cfa 2050 if (err)
4c476991 2051 return err;
ac7f9cfa
JB
2052
2053 flags = &_flags;
2054 change = true;
92ffe055 2055 }
3b85875a 2056
ac7f9cfa 2057 if (change)
3d54d255 2058 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2059 else
2060 err = 0;
60719ffd 2061
9bc383de
JB
2062 if (!err && params.use_4addr != -1)
2063 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2064
55682965
JB
2065 return err;
2066}
2067
2068static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2069{
4c476991 2070 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2071 struct vif_params params;
84efbb84 2072 struct wireless_dev *wdev;
1c90f9d4 2073 struct sk_buff *msg;
55682965
JB
2074 int err;
2075 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2076 u32 flags;
55682965 2077
2ec600d6
LCC
2078 memset(&params, 0, sizeof(params));
2079
55682965
JB
2080 if (!info->attrs[NL80211_ATTR_IFNAME])
2081 return -EINVAL;
2082
2083 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2084 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2085 if (type > NL80211_IFTYPE_MAX)
2086 return -EINVAL;
2087 }
2088
79c97e97 2089 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2090 !(rdev->wiphy.interface_modes & (1 << type)))
2091 return -EOPNOTSUPP;
55682965 2092
1c18f145
AS
2093 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2094 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2095 ETH_ALEN);
2096 if (!is_valid_ether_addr(params.macaddr))
2097 return -EADDRNOTAVAIL;
2098 }
2099
9bc383de 2100 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2101 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2102 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2103 if (err)
4c476991 2104 return err;
9bc383de 2105 }
8b787643 2106
1c90f9d4
JB
2107 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2108 if (!msg)
2109 return -ENOMEM;
2110
66f7ac50
MW
2111 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2112 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2113 &flags);
e35e4d28
HG
2114 wdev = rdev_add_virtual_intf(rdev,
2115 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2116 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2117 if (IS_ERR(wdev)) {
2118 nlmsg_free(msg);
84efbb84 2119 return PTR_ERR(wdev);
1c90f9d4 2120 }
2ec600d6 2121
98104fde
JB
2122 switch (type) {
2123 case NL80211_IFTYPE_MESH_POINT:
2124 if (!info->attrs[NL80211_ATTR_MESH_ID])
2125 break;
29cbe68c
JB
2126 wdev_lock(wdev);
2127 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2128 IEEE80211_MAX_MESH_ID_LEN);
2129 wdev->mesh_id_up_len =
2130 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2131 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2132 wdev->mesh_id_up_len);
2133 wdev_unlock(wdev);
98104fde
JB
2134 break;
2135 case NL80211_IFTYPE_P2P_DEVICE:
2136 /*
2137 * P2P Device doesn't have a netdev, so doesn't go
2138 * through the netdev notifier and must be added here
2139 */
2140 mutex_init(&wdev->mtx);
2141 INIT_LIST_HEAD(&wdev->event_list);
2142 spin_lock_init(&wdev->event_lock);
2143 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2144 spin_lock_init(&wdev->mgmt_registrations_lock);
2145
2146 mutex_lock(&rdev->devlist_mtx);
2147 wdev->identifier = ++rdev->wdev_id;
2148 list_add_rcu(&wdev->list, &rdev->wdev_list);
2149 rdev->devlist_generation++;
2150 mutex_unlock(&rdev->devlist_mtx);
2151 break;
2152 default:
2153 break;
29cbe68c
JB
2154 }
2155
15e47304 2156 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2157 rdev, wdev) < 0) {
2158 nlmsg_free(msg);
2159 return -ENOBUFS;
2160 }
2161
2162 return genlmsg_reply(msg, info);
55682965
JB
2163}
2164
2165static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2166{
4c476991 2167 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2168 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2169
4c476991
JB
2170 if (!rdev->ops->del_virtual_intf)
2171 return -EOPNOTSUPP;
55682965 2172
84efbb84
JB
2173 /*
2174 * If we remove a wireless device without a netdev then clear
2175 * user_ptr[1] so that nl80211_post_doit won't dereference it
2176 * to check if it needs to do dev_put(). Otherwise it crashes
2177 * since the wdev has been freed, unlike with a netdev where
2178 * we need the dev_put() for the netdev to really be freed.
2179 */
2180 if (!wdev->netdev)
2181 info->user_ptr[1] = NULL;
2182
e35e4d28 2183 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2184}
2185
1d9d9213
SW
2186static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2187{
2188 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2189 struct net_device *dev = info->user_ptr[1];
2190 u16 noack_map;
2191
2192 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2193 return -EINVAL;
2194
2195 if (!rdev->ops->set_noack_map)
2196 return -EOPNOTSUPP;
2197
2198 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2199
e35e4d28 2200 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2201}
2202
41ade00f
JB
2203struct get_key_cookie {
2204 struct sk_buff *msg;
2205 int error;
b9454e83 2206 int idx;
41ade00f
JB
2207};
2208
2209static void get_key_callback(void *c, struct key_params *params)
2210{
b9454e83 2211 struct nlattr *key;
41ade00f
JB
2212 struct get_key_cookie *cookie = c;
2213
9360ffd1
DM
2214 if ((params->key &&
2215 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2216 params->key_len, params->key)) ||
2217 (params->seq &&
2218 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2219 params->seq_len, params->seq)) ||
2220 (params->cipher &&
2221 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2222 params->cipher)))
2223 goto nla_put_failure;
41ade00f 2224
b9454e83
JB
2225 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2226 if (!key)
2227 goto nla_put_failure;
2228
9360ffd1
DM
2229 if ((params->key &&
2230 nla_put(cookie->msg, NL80211_KEY_DATA,
2231 params->key_len, params->key)) ||
2232 (params->seq &&
2233 nla_put(cookie->msg, NL80211_KEY_SEQ,
2234 params->seq_len, params->seq)) ||
2235 (params->cipher &&
2236 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2237 params->cipher)))
2238 goto nla_put_failure;
b9454e83 2239
9360ffd1
DM
2240 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2241 goto nla_put_failure;
b9454e83
JB
2242
2243 nla_nest_end(cookie->msg, key);
2244
41ade00f
JB
2245 return;
2246 nla_put_failure:
2247 cookie->error = 1;
2248}
2249
2250static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2251{
4c476991 2252 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2253 int err;
4c476991 2254 struct net_device *dev = info->user_ptr[1];
41ade00f 2255 u8 key_idx = 0;
e31b8213
JB
2256 const u8 *mac_addr = NULL;
2257 bool pairwise;
41ade00f
JB
2258 struct get_key_cookie cookie = {
2259 .error = 0,
2260 };
2261 void *hdr;
2262 struct sk_buff *msg;
2263
2264 if (info->attrs[NL80211_ATTR_KEY_IDX])
2265 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2266
3cfcf6ac 2267 if (key_idx > 5)
41ade00f
JB
2268 return -EINVAL;
2269
2270 if (info->attrs[NL80211_ATTR_MAC])
2271 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2272
e31b8213
JB
2273 pairwise = !!mac_addr;
2274 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2275 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2276 if (kt >= NUM_NL80211_KEYTYPES)
2277 return -EINVAL;
2278 if (kt != NL80211_KEYTYPE_GROUP &&
2279 kt != NL80211_KEYTYPE_PAIRWISE)
2280 return -EINVAL;
2281 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2282 }
2283
4c476991
JB
2284 if (!rdev->ops->get_key)
2285 return -EOPNOTSUPP;
41ade00f 2286
fd2120ca 2287 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2288 if (!msg)
2289 return -ENOMEM;
41ade00f 2290
15e47304 2291 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2292 NL80211_CMD_NEW_KEY);
4c476991
JB
2293 if (IS_ERR(hdr))
2294 return PTR_ERR(hdr);
41ade00f
JB
2295
2296 cookie.msg = msg;
b9454e83 2297 cookie.idx = key_idx;
41ade00f 2298
9360ffd1
DM
2299 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2300 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2301 goto nla_put_failure;
2302 if (mac_addr &&
2303 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2304 goto nla_put_failure;
41ade00f 2305
e31b8213
JB
2306 if (pairwise && mac_addr &&
2307 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2308 return -ENOENT;
2309
e35e4d28
HG
2310 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2311 get_key_callback);
41ade00f
JB
2312
2313 if (err)
6c95e2a2 2314 goto free_msg;
41ade00f
JB
2315
2316 if (cookie.error)
2317 goto nla_put_failure;
2318
2319 genlmsg_end(msg, hdr);
4c476991 2320 return genlmsg_reply(msg, info);
41ade00f
JB
2321
2322 nla_put_failure:
2323 err = -ENOBUFS;
6c95e2a2 2324 free_msg:
41ade00f 2325 nlmsg_free(msg);
41ade00f
JB
2326 return err;
2327}
2328
2329static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2330{
4c476991 2331 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2332 struct key_parse key;
41ade00f 2333 int err;
4c476991 2334 struct net_device *dev = info->user_ptr[1];
41ade00f 2335
b9454e83
JB
2336 err = nl80211_parse_key(info, &key);
2337 if (err)
2338 return err;
41ade00f 2339
b9454e83 2340 if (key.idx < 0)
41ade00f
JB
2341 return -EINVAL;
2342
b9454e83
JB
2343 /* only support setting default key */
2344 if (!key.def && !key.defmgmt)
41ade00f
JB
2345 return -EINVAL;
2346
dbd2fd65 2347 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2348
dbd2fd65
JB
2349 if (key.def) {
2350 if (!rdev->ops->set_default_key) {
2351 err = -EOPNOTSUPP;
2352 goto out;
2353 }
41ade00f 2354
dbd2fd65
JB
2355 err = nl80211_key_allowed(dev->ieee80211_ptr);
2356 if (err)
2357 goto out;
2358
e35e4d28 2359 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2360 key.def_uni, key.def_multi);
2361
2362 if (err)
2363 goto out;
fffd0934 2364
3d23e349 2365#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2366 dev->ieee80211_ptr->wext.default_key = key.idx;
2367#endif
2368 } else {
2369 if (key.def_uni || !key.def_multi) {
2370 err = -EINVAL;
2371 goto out;
2372 }
2373
2374 if (!rdev->ops->set_default_mgmt_key) {
2375 err = -EOPNOTSUPP;
2376 goto out;
2377 }
2378
2379 err = nl80211_key_allowed(dev->ieee80211_ptr);
2380 if (err)
2381 goto out;
2382
e35e4d28 2383 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2384 if (err)
2385 goto out;
2386
2387#ifdef CONFIG_CFG80211_WEXT
2388 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2389#endif
dbd2fd65
JB
2390 }
2391
2392 out:
fffd0934 2393 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2394
41ade00f
JB
2395 return err;
2396}
2397
2398static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2399{
4c476991 2400 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2401 int err;
4c476991 2402 struct net_device *dev = info->user_ptr[1];
b9454e83 2403 struct key_parse key;
e31b8213 2404 const u8 *mac_addr = NULL;
41ade00f 2405
b9454e83
JB
2406 err = nl80211_parse_key(info, &key);
2407 if (err)
2408 return err;
41ade00f 2409
b9454e83 2410 if (!key.p.key)
41ade00f
JB
2411 return -EINVAL;
2412
41ade00f
JB
2413 if (info->attrs[NL80211_ATTR_MAC])
2414 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2415
e31b8213
JB
2416 if (key.type == -1) {
2417 if (mac_addr)
2418 key.type = NL80211_KEYTYPE_PAIRWISE;
2419 else
2420 key.type = NL80211_KEYTYPE_GROUP;
2421 }
2422
2423 /* for now */
2424 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2425 key.type != NL80211_KEYTYPE_GROUP)
2426 return -EINVAL;
2427
4c476991
JB
2428 if (!rdev->ops->add_key)
2429 return -EOPNOTSUPP;
25e47c18 2430
e31b8213
JB
2431 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2432 key.type == NL80211_KEYTYPE_PAIRWISE,
2433 mac_addr))
4c476991 2434 return -EINVAL;
41ade00f 2435
fffd0934
JB
2436 wdev_lock(dev->ieee80211_ptr);
2437 err = nl80211_key_allowed(dev->ieee80211_ptr);
2438 if (!err)
e35e4d28
HG
2439 err = rdev_add_key(rdev, dev, key.idx,
2440 key.type == NL80211_KEYTYPE_PAIRWISE,
2441 mac_addr, &key.p);
fffd0934 2442 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2443
41ade00f
JB
2444 return err;
2445}
2446
2447static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2448{
4c476991 2449 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2450 int err;
4c476991 2451 struct net_device *dev = info->user_ptr[1];
41ade00f 2452 u8 *mac_addr = NULL;
b9454e83 2453 struct key_parse key;
41ade00f 2454
b9454e83
JB
2455 err = nl80211_parse_key(info, &key);
2456 if (err)
2457 return err;
41ade00f
JB
2458
2459 if (info->attrs[NL80211_ATTR_MAC])
2460 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2461
e31b8213
JB
2462 if (key.type == -1) {
2463 if (mac_addr)
2464 key.type = NL80211_KEYTYPE_PAIRWISE;
2465 else
2466 key.type = NL80211_KEYTYPE_GROUP;
2467 }
2468
2469 /* for now */
2470 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2471 key.type != NL80211_KEYTYPE_GROUP)
2472 return -EINVAL;
2473
4c476991
JB
2474 if (!rdev->ops->del_key)
2475 return -EOPNOTSUPP;
41ade00f 2476
fffd0934
JB
2477 wdev_lock(dev->ieee80211_ptr);
2478 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2479
2480 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2481 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2482 err = -ENOENT;
2483
fffd0934 2484 if (!err)
e35e4d28
HG
2485 err = rdev_del_key(rdev, dev, key.idx,
2486 key.type == NL80211_KEYTYPE_PAIRWISE,
2487 mac_addr);
41ade00f 2488
3d23e349 2489#ifdef CONFIG_CFG80211_WEXT
08645126 2490 if (!err) {
b9454e83 2491 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2492 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2493 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2494 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2495 }
2496#endif
fffd0934 2497 wdev_unlock(dev->ieee80211_ptr);
08645126 2498
41ade00f
JB
2499 return err;
2500}
2501
77765eaf
VT
2502/* This function returns an error or the number of nested attributes */
2503static int validate_acl_mac_addrs(struct nlattr *nl_attr)
2504{
2505 struct nlattr *attr;
2506 int n_entries = 0, tmp;
2507
2508 nla_for_each_nested(attr, nl_attr, tmp) {
2509 if (nla_len(attr) != ETH_ALEN)
2510 return -EINVAL;
2511
2512 n_entries++;
2513 }
2514
2515 return n_entries;
2516}
2517
2518/*
2519 * This function parses ACL information and allocates memory for ACL data.
2520 * On successful return, the calling function is responsible to free the
2521 * ACL buffer returned by this function.
2522 */
2523static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
2524 struct genl_info *info)
2525{
2526 enum nl80211_acl_policy acl_policy;
2527 struct nlattr *attr;
2528 struct cfg80211_acl_data *acl;
2529 int i = 0, n_entries, tmp;
2530
2531 if (!wiphy->max_acl_mac_addrs)
2532 return ERR_PTR(-EOPNOTSUPP);
2533
2534 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
2535 return ERR_PTR(-EINVAL);
2536
2537 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
2538 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
2539 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
2540 return ERR_PTR(-EINVAL);
2541
2542 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
2543 return ERR_PTR(-EINVAL);
2544
2545 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
2546 if (n_entries < 0)
2547 return ERR_PTR(n_entries);
2548
2549 if (n_entries > wiphy->max_acl_mac_addrs)
2550 return ERR_PTR(-ENOTSUPP);
2551
2552 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
2553 GFP_KERNEL);
2554 if (!acl)
2555 return ERR_PTR(-ENOMEM);
2556
2557 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
2558 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
2559 i++;
2560 }
2561
2562 acl->n_acl_entries = n_entries;
2563 acl->acl_policy = acl_policy;
2564
2565 return acl;
2566}
2567
2568static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
2569{
2570 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2571 struct net_device *dev = info->user_ptr[1];
2572 struct cfg80211_acl_data *acl;
2573 int err;
2574
2575 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2576 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2577 return -EOPNOTSUPP;
2578
2579 if (!dev->ieee80211_ptr->beacon_interval)
2580 return -EINVAL;
2581
2582 acl = parse_acl_data(&rdev->wiphy, info);
2583 if (IS_ERR(acl))
2584 return PTR_ERR(acl);
2585
2586 err = rdev_set_mac_acl(rdev, dev, acl);
2587
2588 kfree(acl);
2589
2590 return err;
2591}
2592
8860020e
JB
2593static int nl80211_parse_beacon(struct genl_info *info,
2594 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2595{
8860020e 2596 bool haveinfo = false;
ed1b6cc7 2597
9946ecfb
JM
2598 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2599 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2600 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2601 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2602 return -EINVAL;
2603
8860020e 2604 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2605
ed1b6cc7 2606 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2607 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2608 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2609 if (!bcn->head_len)
2610 return -EINVAL;
2611 haveinfo = true;
ed1b6cc7
JB
2612 }
2613
2614 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2615 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2616 bcn->tail_len =
ed1b6cc7 2617 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2618 haveinfo = true;
ed1b6cc7
JB
2619 }
2620
4c476991
JB
2621 if (!haveinfo)
2622 return -EINVAL;
3b85875a 2623
9946ecfb 2624 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2625 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2626 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2627 }
2628
2629 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2630 bcn->proberesp_ies =
9946ecfb 2631 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2632 bcn->proberesp_ies_len =
9946ecfb
JM
2633 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2634 }
2635
2636 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2637 bcn->assocresp_ies =
9946ecfb 2638 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2639 bcn->assocresp_ies_len =
9946ecfb
JM
2640 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2641 }
2642
00f740e1 2643 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2644 bcn->probe_resp =
00f740e1 2645 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2646 bcn->probe_resp_len =
00f740e1
AN
2647 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2648 }
2649
8860020e
JB
2650 return 0;
2651}
2652
46c1dd0c
FF
2653static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2654 struct cfg80211_ap_settings *params)
2655{
2656 struct wireless_dev *wdev;
2657 bool ret = false;
2658
2659 mutex_lock(&rdev->devlist_mtx);
2660
89a54e48 2661 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2662 if (wdev->iftype != NL80211_IFTYPE_AP &&
2663 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2664 continue;
2665
683b6d3b 2666 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
2667 continue;
2668
683b6d3b 2669 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
2670 ret = true;
2671 break;
2672 }
2673
2674 mutex_unlock(&rdev->devlist_mtx);
2675
2676 return ret;
2677}
2678
e39e5b5e
JM
2679static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
2680 enum nl80211_auth_type auth_type,
2681 enum nl80211_commands cmd)
2682{
2683 if (auth_type > NL80211_AUTHTYPE_MAX)
2684 return false;
2685
2686 switch (cmd) {
2687 case NL80211_CMD_AUTHENTICATE:
2688 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
2689 auth_type == NL80211_AUTHTYPE_SAE)
2690 return false;
2691 return true;
2692 case NL80211_CMD_CONNECT:
2693 case NL80211_CMD_START_AP:
2694 /* SAE not supported yet */
2695 if (auth_type == NL80211_AUTHTYPE_SAE)
2696 return false;
2697 return true;
2698 default:
2699 return false;
2700 }
2701}
2702
8860020e
JB
2703static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2704{
2705 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2706 struct net_device *dev = info->user_ptr[1];
2707 struct wireless_dev *wdev = dev->ieee80211_ptr;
2708 struct cfg80211_ap_settings params;
2709 int err;
2710
2711 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2712 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2713 return -EOPNOTSUPP;
2714
2715 if (!rdev->ops->start_ap)
2716 return -EOPNOTSUPP;
2717
2718 if (wdev->beacon_interval)
2719 return -EALREADY;
2720
2721 memset(&params, 0, sizeof(params));
2722
2723 /* these are required for START_AP */
2724 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2725 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2726 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2727 return -EINVAL;
2728
2729 err = nl80211_parse_beacon(info, &params.beacon);
2730 if (err)
2731 return err;
2732
2733 params.beacon_interval =
2734 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2735 params.dtim_period =
2736 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2737
2738 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2739 if (err)
2740 return err;
2741
2742 /*
2743 * In theory, some of these attributes should be required here
2744 * but since they were not used when the command was originally
2745 * added, keep them optional for old user space programs to let
2746 * them continue to work with drivers that do not need the
2747 * additional information -- drivers must check!
2748 */
2749 if (info->attrs[NL80211_ATTR_SSID]) {
2750 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2751 params.ssid_len =
2752 nla_len(info->attrs[NL80211_ATTR_SSID]);
2753 if (params.ssid_len == 0 ||
2754 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2755 return -EINVAL;
2756 }
2757
2758 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2759 params.hidden_ssid = nla_get_u32(
2760 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2761 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2762 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2763 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2764 return -EINVAL;
2765 }
2766
2767 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2768
2769 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2770 params.auth_type = nla_get_u32(
2771 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
2772 if (!nl80211_valid_auth_type(rdev, params.auth_type,
2773 NL80211_CMD_START_AP))
8860020e
JB
2774 return -EINVAL;
2775 } else
2776 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2777
2778 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2779 NL80211_MAX_NR_CIPHER_SUITES);
2780 if (err)
2781 return err;
2782
1b658f11
VT
2783 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2784 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2785 return -EOPNOTSUPP;
2786 params.inactivity_timeout = nla_get_u16(
2787 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2788 }
2789
53cabad7
JB
2790 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
2791 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2792 return -EINVAL;
2793 params.p2p_ctwindow =
2794 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
2795 if (params.p2p_ctwindow > 127)
2796 return -EINVAL;
2797 if (params.p2p_ctwindow != 0 &&
2798 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
2799 return -EINVAL;
2800 }
2801
2802 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
2803 u8 tmp;
2804
2805 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2806 return -EINVAL;
2807 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
2808 if (tmp > 1)
2809 return -EINVAL;
2810 params.p2p_opp_ps = tmp;
2811 if (params.p2p_opp_ps != 0 &&
2812 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
2813 return -EINVAL;
2814 }
2815
aa430da4 2816 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
2817 err = nl80211_parse_chandef(rdev, info, &params.chandef);
2818 if (err)
2819 return err;
2820 } else if (wdev->preset_chandef.chan) {
2821 params.chandef = wdev->preset_chandef;
46c1dd0c 2822 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
2823 return -EINVAL;
2824
683b6d3b 2825 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
2826 return -EINVAL;
2827
e4e32459 2828 mutex_lock(&rdev->devlist_mtx);
683b6d3b 2829 err = cfg80211_can_use_chan(rdev, wdev, params.chandef.chan,
e4e32459
MK
2830 CHAN_MODE_SHARED);
2831 mutex_unlock(&rdev->devlist_mtx);
2832
2833 if (err)
2834 return err;
2835
77765eaf
VT
2836 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
2837 params.acl = parse_acl_data(&rdev->wiphy, info);
2838 if (IS_ERR(params.acl))
2839 return PTR_ERR(params.acl);
2840 }
2841
e35e4d28 2842 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 2843 if (!err) {
683b6d3b 2844 wdev->preset_chandef = params.chandef;
8860020e 2845 wdev->beacon_interval = params.beacon_interval;
683b6d3b 2846 wdev->channel = params.chandef.chan;
06e191e2
AQ
2847 wdev->ssid_len = params.ssid_len;
2848 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 2849 }
77765eaf
VT
2850
2851 kfree(params.acl);
2852
56d1893d 2853 return err;
ed1b6cc7
JB
2854}
2855
8860020e
JB
2856static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2857{
2858 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2859 struct net_device *dev = info->user_ptr[1];
2860 struct wireless_dev *wdev = dev->ieee80211_ptr;
2861 struct cfg80211_beacon_data params;
2862 int err;
2863
2864 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2865 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2866 return -EOPNOTSUPP;
2867
2868 if (!rdev->ops->change_beacon)
2869 return -EOPNOTSUPP;
2870
2871 if (!wdev->beacon_interval)
2872 return -EINVAL;
2873
2874 err = nl80211_parse_beacon(info, &params);
2875 if (err)
2876 return err;
2877
e35e4d28 2878 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
2879}
2880
2881static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2882{
4c476991
JB
2883 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2884 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 2885
60771780 2886 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
2887}
2888
5727ef1b
JB
2889static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2890 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2891 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2892 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2893 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2894 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2895 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2896};
2897
eccb8e8f 2898static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2899 enum nl80211_iftype iftype,
eccb8e8f 2900 struct station_parameters *params)
5727ef1b
JB
2901{
2902 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2903 struct nlattr *nla;
5727ef1b
JB
2904 int flag;
2905
eccb8e8f
JB
2906 /*
2907 * Try parsing the new attribute first so userspace
2908 * can specify both for older kernels.
2909 */
2910 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2911 if (nla) {
2912 struct nl80211_sta_flag_update *sta_flags;
2913
2914 sta_flags = nla_data(nla);
2915 params->sta_flags_mask = sta_flags->mask;
2916 params->sta_flags_set = sta_flags->set;
2917 if ((params->sta_flags_mask |
2918 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2919 return -EINVAL;
2920 return 0;
2921 }
2922
2923 /* if present, parse the old attribute */
5727ef1b 2924
eccb8e8f 2925 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2926 if (!nla)
2927 return 0;
2928
2929 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2930 nla, sta_flags_policy))
2931 return -EINVAL;
2932
bdd3ae3d
JB
2933 /*
2934 * Only allow certain flags for interface types so that
2935 * other attributes are silently ignored. Remember that
2936 * this is backward compatibility code with old userspace
2937 * and shouldn't be hit in other cases anyway.
2938 */
2939 switch (iftype) {
2940 case NL80211_IFTYPE_AP:
2941 case NL80211_IFTYPE_AP_VLAN:
2942 case NL80211_IFTYPE_P2P_GO:
2943 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2944 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2945 BIT(NL80211_STA_FLAG_WME) |
2946 BIT(NL80211_STA_FLAG_MFP);
2947 break;
2948 case NL80211_IFTYPE_P2P_CLIENT:
2949 case NL80211_IFTYPE_STATION:
2950 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2951 BIT(NL80211_STA_FLAG_TDLS_PEER);
2952 break;
2953 case NL80211_IFTYPE_MESH_POINT:
2954 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2955 BIT(NL80211_STA_FLAG_MFP) |
2956 BIT(NL80211_STA_FLAG_AUTHORIZED);
2957 default:
2958 return -EINVAL;
2959 }
5727ef1b 2960
3383b5a6
JB
2961 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2962 if (flags[flag]) {
eccb8e8f 2963 params->sta_flags_set |= (1<<flag);
5727ef1b 2964
3383b5a6
JB
2965 /* no longer support new API additions in old API */
2966 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2967 return -EINVAL;
2968 }
2969 }
2970
5727ef1b
JB
2971 return 0;
2972}
2973
c8dcfd8a
FF
2974static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2975 int attr)
2976{
2977 struct nlattr *rate;
8eb41c8d
VK
2978 u32 bitrate;
2979 u16 bitrate_compat;
c8dcfd8a
FF
2980
2981 rate = nla_nest_start(msg, attr);
2982 if (!rate)
db9c64cf 2983 return false;
c8dcfd8a
FF
2984
2985 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2986 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
2987 /* report 16-bit bitrate only if we can */
2988 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
2989 if (bitrate > 0 &&
2990 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
2991 return false;
2992 if (bitrate_compat > 0 &&
2993 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
2994 return false;
2995
2996 if (info->flags & RATE_INFO_FLAGS_MCS) {
2997 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
2998 return false;
2999 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3000 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3001 return false;
3002 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3003 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3004 return false;
3005 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3006 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3007 return false;
3008 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3009 return false;
3010 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3011 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3012 return false;
3013 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
3014 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
3015 return false;
3016 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
3017 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
3018 return false;
3019 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
3020 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
3021 return false;
3022 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3023 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3024 return false;
3025 }
c8dcfd8a
FF
3026
3027 nla_nest_end(msg, rate);
3028 return true;
c8dcfd8a
FF
3029}
3030
15e47304 3031static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
3032 int flags,
3033 struct cfg80211_registered_device *rdev,
3034 struct net_device *dev,
98b62183 3035 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3036{
3037 void *hdr;
f4263c98 3038 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3039
15e47304 3040 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
3041 if (!hdr)
3042 return -1;
3043
9360ffd1
DM
3044 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3045 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3046 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3047 goto nla_put_failure;
f5ea9120 3048
2ec600d6
LCC
3049 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3050 if (!sinfoattr)
fd5b74dc 3051 goto nla_put_failure;
9360ffd1
DM
3052 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
3053 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
3054 sinfo->connected_time))
3055 goto nla_put_failure;
3056 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
3057 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
3058 sinfo->inactive_time))
3059 goto nla_put_failure;
3060 if ((sinfo->filled & STATION_INFO_RX_BYTES) &&
3061 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
3062 sinfo->rx_bytes))
3063 goto nla_put_failure;
3064 if ((sinfo->filled & STATION_INFO_TX_BYTES) &&
3065 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
3066 sinfo->tx_bytes))
3067 goto nla_put_failure;
3068 if ((sinfo->filled & STATION_INFO_LLID) &&
3069 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
3070 goto nla_put_failure;
3071 if ((sinfo->filled & STATION_INFO_PLID) &&
3072 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
3073 goto nla_put_failure;
3074 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
3075 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
3076 sinfo->plink_state))
3077 goto nla_put_failure;
66266b3a
JL
3078 switch (rdev->wiphy.signal_type) {
3079 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
3080 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
3081 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
3082 sinfo->signal))
3083 goto nla_put_failure;
3084 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
3085 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
3086 sinfo->signal_avg))
3087 goto nla_put_failure;
66266b3a
JL
3088 break;
3089 default:
3090 break;
3091 }
420e7fab 3092 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3093 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3094 NL80211_STA_INFO_TX_BITRATE))
3095 goto nla_put_failure;
3096 }
3097 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3098 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3099 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3100 goto nla_put_failure;
420e7fab 3101 }
9360ffd1
DM
3102 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3103 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3104 sinfo->rx_packets))
3105 goto nla_put_failure;
3106 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3107 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3108 sinfo->tx_packets))
3109 goto nla_put_failure;
3110 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3111 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3112 sinfo->tx_retries))
3113 goto nla_put_failure;
3114 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3115 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3116 sinfo->tx_failed))
3117 goto nla_put_failure;
3118 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3119 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3120 sinfo->beacon_loss_count))
3121 goto nla_put_failure;
3b1c5a53
MP
3122 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3123 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3124 sinfo->local_pm))
3125 goto nla_put_failure;
3126 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3127 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3128 sinfo->peer_pm))
3129 goto nla_put_failure;
3130 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3131 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3132 sinfo->nonpeer_pm))
3133 goto nla_put_failure;
f4263c98
PS
3134 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3135 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3136 if (!bss_param)
3137 goto nla_put_failure;
3138
9360ffd1
DM
3139 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3140 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3141 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3142 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3143 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3144 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3145 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3146 sinfo->bss_param.dtim_period) ||
3147 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3148 sinfo->bss_param.beacon_interval))
3149 goto nla_put_failure;
f4263c98
PS
3150
3151 nla_nest_end(msg, bss_param);
3152 }
9360ffd1
DM
3153 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3154 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3155 sizeof(struct nl80211_sta_flag_update),
3156 &sinfo->sta_flags))
3157 goto nla_put_failure;
7eab0f64
JL
3158 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3159 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3160 sinfo->t_offset))
3161 goto nla_put_failure;
2ec600d6 3162 nla_nest_end(msg, sinfoattr);
fd5b74dc 3163
9360ffd1
DM
3164 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3165 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3166 sinfo->assoc_req_ies))
3167 goto nla_put_failure;
50d3dfb7 3168
fd5b74dc
JB
3169 return genlmsg_end(msg, hdr);
3170
3171 nla_put_failure:
bc3ed28c
TG
3172 genlmsg_cancel(msg, hdr);
3173 return -EMSGSIZE;
fd5b74dc
JB
3174}
3175
2ec600d6 3176static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3177 struct netlink_callback *cb)
2ec600d6 3178{
2ec600d6
LCC
3179 struct station_info sinfo;
3180 struct cfg80211_registered_device *dev;
bba95fef 3181 struct net_device *netdev;
2ec600d6 3182 u8 mac_addr[ETH_ALEN];
bba95fef 3183 int sta_idx = cb->args[1];
2ec600d6 3184 int err;
2ec600d6 3185
67748893
JB
3186 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3187 if (err)
3188 return err;
bba95fef
JB
3189
3190 if (!dev->ops->dump_station) {
eec60b03 3191 err = -EOPNOTSUPP;
bba95fef
JB
3192 goto out_err;
3193 }
3194
bba95fef 3195 while (1) {
f612cedf 3196 memset(&sinfo, 0, sizeof(sinfo));
e35e4d28
HG
3197 err = rdev_dump_station(dev, netdev, sta_idx,
3198 mac_addr, &sinfo);
bba95fef
JB
3199 if (err == -ENOENT)
3200 break;
3201 if (err)
3b85875a 3202 goto out_err;
bba95fef
JB
3203
3204 if (nl80211_send_station(skb,
15e47304 3205 NETLINK_CB(cb->skb).portid,
bba95fef 3206 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 3207 dev, netdev, mac_addr,
bba95fef
JB
3208 &sinfo) < 0)
3209 goto out;
3210
3211 sta_idx++;
3212 }
3213
3214
3215 out:
3216 cb->args[1] = sta_idx;
3217 err = skb->len;
bba95fef 3218 out_err:
67748893 3219 nl80211_finish_netdev_dump(dev);
bba95fef
JB
3220
3221 return err;
2ec600d6 3222}
fd5b74dc 3223
5727ef1b
JB
3224static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3225{
4c476991
JB
3226 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3227 struct net_device *dev = info->user_ptr[1];
2ec600d6 3228 struct station_info sinfo;
fd5b74dc
JB
3229 struct sk_buff *msg;
3230 u8 *mac_addr = NULL;
4c476991 3231 int err;
fd5b74dc 3232
2ec600d6 3233 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3234
3235 if (!info->attrs[NL80211_ATTR_MAC])
3236 return -EINVAL;
3237
3238 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3239
4c476991
JB
3240 if (!rdev->ops->get_station)
3241 return -EOPNOTSUPP;
3b85875a 3242
e35e4d28 3243 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3244 if (err)
4c476991 3245 return err;
2ec600d6 3246
fd2120ca 3247 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3248 if (!msg)
4c476991 3249 return -ENOMEM;
fd5b74dc 3250
15e47304 3251 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3252 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3253 nlmsg_free(msg);
3254 return -ENOBUFS;
3255 }
3b85875a 3256
4c476991 3257 return genlmsg_reply(msg, info);
5727ef1b
JB
3258}
3259
3260/*
c258d2de 3261 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3262 */
80b99899
JB
3263static struct net_device *get_vlan(struct genl_info *info,
3264 struct cfg80211_registered_device *rdev)
5727ef1b 3265{
463d0183 3266 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3267 struct net_device *v;
3268 int ret;
3269
3270 if (!vlanattr)
3271 return NULL;
3272
3273 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3274 if (!v)
3275 return ERR_PTR(-ENODEV);
3276
3277 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3278 ret = -EINVAL;
3279 goto error;
5727ef1b 3280 }
80b99899
JB
3281
3282 if (!netif_running(v)) {
3283 ret = -ENETDOWN;
3284 goto error;
3285 }
3286
3287 return v;
3288 error:
3289 dev_put(v);
3290 return ERR_PTR(ret);
5727ef1b
JB
3291}
3292
3293static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3294{
4c476991 3295 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3296 int err;
4c476991 3297 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3298 struct station_parameters params;
3299 u8 *mac_addr = NULL;
3300
3301 memset(&params, 0, sizeof(params));
3302
3303 params.listen_interval = -1;
57cf8043 3304 params.plink_state = -1;
5727ef1b
JB
3305
3306 if (info->attrs[NL80211_ATTR_STA_AID])
3307 return -EINVAL;
3308
3309 if (!info->attrs[NL80211_ATTR_MAC])
3310 return -EINVAL;
3311
3312 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3313
3314 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3315 params.supported_rates =
3316 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3317 params.supported_rates_len =
3318 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3319 }
3320
ba23d206
JB
3321 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL] ||
3322 info->attrs[NL80211_ATTR_HT_CAPABILITY])
3323 return -EINVAL;
36aedc90 3324
bdd90d5e
JB
3325 if (!rdev->ops->change_station)
3326 return -EOPNOTSUPP;
3327
bdd3ae3d 3328 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3329 return -EINVAL;
3330
2ec600d6
LCC
3331 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3332 params.plink_action =
3333 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3334
9c3990aa
JC
3335 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
3336 params.plink_state =
3337 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3338
3b1c5a53
MP
3339 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
3340 enum nl80211_mesh_power_mode pm = nla_get_u32(
3341 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
3342
3343 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
3344 pm > NL80211_MESH_POWER_MAX)
3345 return -EINVAL;
3346
3347 params.local_pm = pm;
3348 }
3349
a97f4424
JB
3350 switch (dev->ieee80211_ptr->iftype) {
3351 case NL80211_IFTYPE_AP:
3352 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3353 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
3354 /* disallow mesh-specific things */
3355 if (params.plink_action)
bdd90d5e 3356 return -EINVAL;
3b1c5a53
MP
3357 if (params.local_pm)
3358 return -EINVAL;
bdd90d5e
JB
3359
3360 /* TDLS can't be set, ... */
3361 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3362 return -EINVAL;
3363 /*
3364 * ... but don't bother the driver with it. This works around
3365 * a hostapd/wpa_supplicant issue -- it always includes the
3366 * TLDS_PEER flag in the mask even for AP mode.
3367 */
3368 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3369
3370 /* accept only the listed bits */
3371 if (params.sta_flags_mask &
3372 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
d582cffb
JB
3373 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3374 BIT(NL80211_STA_FLAG_ASSOCIATED) |
bdd90d5e
JB
3375 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3376 BIT(NL80211_STA_FLAG_WME) |
3377 BIT(NL80211_STA_FLAG_MFP)))
3378 return -EINVAL;
3379
d582cffb
JB
3380 /* but authenticated/associated only if driver handles it */
3381 if (!(rdev->wiphy.features &
3382 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3383 params.sta_flags_mask &
3384 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3385 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3386 return -EINVAL;
3387
ba23d206
JB
3388 /* reject other things that can't change */
3389 if (params.supported_rates)
3390 return -EINVAL;
3391
bdd90d5e
JB
3392 /* must be last in here for error handling */
3393 params.vlan = get_vlan(info, rdev);
3394 if (IS_ERR(params.vlan))
3395 return PTR_ERR(params.vlan);
a97f4424 3396 break;
074ac8df 3397 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3398 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
3399 /*
3400 * Don't allow userspace to change the TDLS_PEER flag,
3401 * but silently ignore attempts to change it since we
3402 * don't have state here to verify that it doesn't try
3403 * to change the flag.
3404 */
3405 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
3406 /* fall through */
3407 case NL80211_IFTYPE_ADHOC:
3408 /* disallow things sta doesn't support */
3409 if (params.plink_action)
3410 return -EINVAL;
3b1c5a53
MP
3411 if (params.local_pm)
3412 return -EINVAL;
bdd90d5e
JB
3413 /* reject any changes other than AUTHORIZED */
3414 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3415 return -EINVAL;
a97f4424
JB
3416 break;
3417 case NL80211_IFTYPE_MESH_POINT:
3418 /* disallow things mesh doesn't support */
3419 if (params.vlan)
bdd90d5e 3420 return -EINVAL;
ba23d206 3421 if (params.supported_rates)
bdd90d5e
JB
3422 return -EINVAL;
3423 /*
3424 * No special handling for TDLS here -- the userspace
3425 * mesh code doesn't have this bug.
3426 */
b39c48fa
JC
3427 if (params.sta_flags_mask &
3428 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 3429 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 3430 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 3431 return -EINVAL;
a97f4424
JB
3432 break;
3433 default:
bdd90d5e 3434 return -EOPNOTSUPP;
034d655e
JB
3435 }
3436
bdd90d5e 3437 /* be aware of params.vlan when changing code here */
5727ef1b 3438
e35e4d28 3439 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 3440
5727ef1b
JB
3441 if (params.vlan)
3442 dev_put(params.vlan);
3b85875a 3443
5727ef1b
JB
3444 return err;
3445}
3446
c75786c9
EP
3447static struct nla_policy
3448nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3449 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3450 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3451};
3452
5727ef1b
JB
3453static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3454{
4c476991 3455 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3456 int err;
4c476991 3457 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3458 struct station_parameters params;
3459 u8 *mac_addr = NULL;
3460
3461 memset(&params, 0, sizeof(params));
3462
3463 if (!info->attrs[NL80211_ATTR_MAC])
3464 return -EINVAL;
3465
5727ef1b
JB
3466 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3467 return -EINVAL;
3468
3469 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3470 return -EINVAL;
3471
0e956c13
TLSC
3472 if (!info->attrs[NL80211_ATTR_STA_AID])
3473 return -EINVAL;
3474
5727ef1b
JB
3475 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3476 params.supported_rates =
3477 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3478 params.supported_rates_len =
3479 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3480 params.listen_interval =
3481 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3482
0e956c13
TLSC
3483 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
3484 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3485 return -EINVAL;
51b50fbe 3486
36aedc90
JM
3487 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3488 params.ht_capa =
3489 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 3490
f461be3e
MP
3491 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3492 params.vht_capa =
3493 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3494
96b78dff
JC
3495 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3496 params.plink_action =
3497 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3498
bdd90d5e
JB
3499 if (!rdev->ops->add_station)
3500 return -EOPNOTSUPP;
3501
bdd3ae3d 3502 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3503 return -EINVAL;
3504
bdd90d5e
JB
3505 switch (dev->ieee80211_ptr->iftype) {
3506 case NL80211_IFTYPE_AP:
3507 case NL80211_IFTYPE_AP_VLAN:
3508 case NL80211_IFTYPE_P2P_GO:
3509 /* parse WME attributes if sta is WME capable */
3510 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3511 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
3512 info->attrs[NL80211_ATTR_STA_WME]) {
3513 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3514 struct nlattr *nla;
3515
3516 nla = info->attrs[NL80211_ATTR_STA_WME];
3517 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3518 nl80211_sta_wme_policy);
3519 if (err)
3520 return err;
3521
3522 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3523 params.uapsd_queues =
3524 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
3525 if (params.uapsd_queues &
3526 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3527 return -EINVAL;
c75786c9 3528
bdd90d5e
JB
3529 if (tb[NL80211_STA_WME_MAX_SP])
3530 params.max_sp =
3531 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 3532
bdd90d5e
JB
3533 if (params.max_sp &
3534 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3535 return -EINVAL;
4319e193 3536
bdd90d5e
JB
3537 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3538 }
3539 /* TDLS peers cannot be added */
3540 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3541 return -EINVAL;
bdd90d5e
JB
3542 /* but don't bother the driver with it */
3543 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3544
d582cffb
JB
3545 /* allow authenticated/associated only if driver handles it */
3546 if (!(rdev->wiphy.features &
3547 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3548 params.sta_flags_mask &
3549 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3550 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3551 return -EINVAL;
3552
bdd90d5e
JB
3553 /* must be last in here for error handling */
3554 params.vlan = get_vlan(info, rdev);
3555 if (IS_ERR(params.vlan))
3556 return PTR_ERR(params.vlan);
3557 break;
3558 case NL80211_IFTYPE_MESH_POINT:
d582cffb
JB
3559 /* associated is disallowed */
3560 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3561 return -EINVAL;
bdd90d5e
JB
3562 /* TDLS peers cannot be added */
3563 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3564 return -EINVAL;
3565 break;
3566 case NL80211_IFTYPE_STATION:
d582cffb
JB
3567 /* associated is disallowed */
3568 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3569 return -EINVAL;
bdd90d5e
JB
3570 /* Only TDLS peers can be added */
3571 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3572 return -EINVAL;
3573 /* Can only add if TDLS ... */
3574 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3575 return -EOPNOTSUPP;
3576 /* ... with external setup is supported */
3577 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3578 return -EOPNOTSUPP;
3579 break;
3580 default:
3581 return -EOPNOTSUPP;
c75786c9
EP
3582 }
3583
bdd90d5e 3584 /* be aware of params.vlan when changing code here */
5727ef1b 3585
e35e4d28 3586 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 3587
5727ef1b
JB
3588 if (params.vlan)
3589 dev_put(params.vlan);
5727ef1b
JB
3590 return err;
3591}
3592
3593static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3594{
4c476991
JB
3595 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3596 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3597 u8 *mac_addr = NULL;
3598
3599 if (info->attrs[NL80211_ATTR_MAC])
3600 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3601
e80cf853 3602 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3603 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3604 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3605 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3606 return -EINVAL;
5727ef1b 3607
4c476991
JB
3608 if (!rdev->ops->del_station)
3609 return -EOPNOTSUPP;
3b85875a 3610
e35e4d28 3611 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
3612}
3613
15e47304 3614static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
3615 int flags, struct net_device *dev,
3616 u8 *dst, u8 *next_hop,
3617 struct mpath_info *pinfo)
3618{
3619 void *hdr;
3620 struct nlattr *pinfoattr;
3621
15e47304 3622 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
3623 if (!hdr)
3624 return -1;
3625
9360ffd1
DM
3626 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3627 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3628 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3629 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3630 goto nla_put_failure;
f5ea9120 3631
2ec600d6
LCC
3632 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3633 if (!pinfoattr)
3634 goto nla_put_failure;
9360ffd1
DM
3635 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3636 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3637 pinfo->frame_qlen))
3638 goto nla_put_failure;
3639 if (((pinfo->filled & MPATH_INFO_SN) &&
3640 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3641 ((pinfo->filled & MPATH_INFO_METRIC) &&
3642 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3643 pinfo->metric)) ||
3644 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3645 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3646 pinfo->exptime)) ||
3647 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3648 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3649 pinfo->flags)) ||
3650 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3651 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3652 pinfo->discovery_timeout)) ||
3653 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3654 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3655 pinfo->discovery_retries)))
3656 goto nla_put_failure;
2ec600d6
LCC
3657
3658 nla_nest_end(msg, pinfoattr);
3659
3660 return genlmsg_end(msg, hdr);
3661
3662 nla_put_failure:
bc3ed28c
TG
3663 genlmsg_cancel(msg, hdr);
3664 return -EMSGSIZE;
2ec600d6
LCC
3665}
3666
3667static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3668 struct netlink_callback *cb)
2ec600d6 3669{
2ec600d6
LCC
3670 struct mpath_info pinfo;
3671 struct cfg80211_registered_device *dev;
bba95fef 3672 struct net_device *netdev;
2ec600d6
LCC
3673 u8 dst[ETH_ALEN];
3674 u8 next_hop[ETH_ALEN];
bba95fef 3675 int path_idx = cb->args[1];
2ec600d6 3676 int err;
2ec600d6 3677
67748893
JB
3678 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3679 if (err)
3680 return err;
bba95fef
JB
3681
3682 if (!dev->ops->dump_mpath) {
eec60b03 3683 err = -EOPNOTSUPP;
bba95fef
JB
3684 goto out_err;
3685 }
3686
eec60b03
JM
3687 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3688 err = -EOPNOTSUPP;
0448b5fc 3689 goto out_err;
eec60b03
JM
3690 }
3691
bba95fef 3692 while (1) {
e35e4d28
HG
3693 err = rdev_dump_mpath(dev, netdev, path_idx, dst, next_hop,
3694 &pinfo);
bba95fef 3695 if (err == -ENOENT)
2ec600d6 3696 break;
bba95fef 3697 if (err)
3b85875a 3698 goto out_err;
2ec600d6 3699
15e47304 3700 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef
JB
3701 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3702 netdev, dst, next_hop,
3703 &pinfo) < 0)
3704 goto out;
2ec600d6 3705
bba95fef 3706 path_idx++;
2ec600d6 3707 }
2ec600d6 3708
2ec600d6 3709
bba95fef
JB
3710 out:
3711 cb->args[1] = path_idx;
3712 err = skb->len;
bba95fef 3713 out_err:
67748893 3714 nl80211_finish_netdev_dump(dev);
bba95fef 3715 return err;
2ec600d6
LCC
3716}
3717
3718static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3719{
4c476991 3720 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3721 int err;
4c476991 3722 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3723 struct mpath_info pinfo;
3724 struct sk_buff *msg;
3725 u8 *dst = NULL;
3726 u8 next_hop[ETH_ALEN];
3727
3728 memset(&pinfo, 0, sizeof(pinfo));
3729
3730 if (!info->attrs[NL80211_ATTR_MAC])
3731 return -EINVAL;
3732
3733 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3734
4c476991
JB
3735 if (!rdev->ops->get_mpath)
3736 return -EOPNOTSUPP;
2ec600d6 3737
4c476991
JB
3738 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3739 return -EOPNOTSUPP;
eec60b03 3740
e35e4d28 3741 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 3742 if (err)
4c476991 3743 return err;
2ec600d6 3744
fd2120ca 3745 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3746 if (!msg)
4c476991 3747 return -ENOMEM;
2ec600d6 3748
15e47304 3749 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
3750 dev, dst, next_hop, &pinfo) < 0) {
3751 nlmsg_free(msg);
3752 return -ENOBUFS;
3753 }
3b85875a 3754
4c476991 3755 return genlmsg_reply(msg, info);
2ec600d6
LCC
3756}
3757
3758static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3759{
4c476991
JB
3760 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3761 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3762 u8 *dst = NULL;
3763 u8 *next_hop = NULL;
3764
3765 if (!info->attrs[NL80211_ATTR_MAC])
3766 return -EINVAL;
3767
3768 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3769 return -EINVAL;
3770
3771 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3772 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3773
4c476991
JB
3774 if (!rdev->ops->change_mpath)
3775 return -EOPNOTSUPP;
35a8efe1 3776
4c476991
JB
3777 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3778 return -EOPNOTSUPP;
2ec600d6 3779
e35e4d28 3780 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 3781}
4c476991 3782
2ec600d6
LCC
3783static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3784{
4c476991
JB
3785 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3786 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3787 u8 *dst = NULL;
3788 u8 *next_hop = NULL;
3789
3790 if (!info->attrs[NL80211_ATTR_MAC])
3791 return -EINVAL;
3792
3793 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3794 return -EINVAL;
3795
3796 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3797 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3798
4c476991
JB
3799 if (!rdev->ops->add_mpath)
3800 return -EOPNOTSUPP;
35a8efe1 3801
4c476991
JB
3802 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3803 return -EOPNOTSUPP;
2ec600d6 3804
e35e4d28 3805 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
3806}
3807
3808static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3809{
4c476991
JB
3810 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3811 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3812 u8 *dst = NULL;
3813
3814 if (info->attrs[NL80211_ATTR_MAC])
3815 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3816
4c476991
JB
3817 if (!rdev->ops->del_mpath)
3818 return -EOPNOTSUPP;
3b85875a 3819
e35e4d28 3820 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
3821}
3822
9f1ba906
JM
3823static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3824{
4c476991
JB
3825 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3826 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3827 struct bss_parameters params;
3828
3829 memset(&params, 0, sizeof(params));
3830 /* default to not changing parameters */
3831 params.use_cts_prot = -1;
3832 params.use_short_preamble = -1;
3833 params.use_short_slot_time = -1;
fd8aaaf3 3834 params.ap_isolate = -1;
50b12f59 3835 params.ht_opmode = -1;
53cabad7
JB
3836 params.p2p_ctwindow = -1;
3837 params.p2p_opp_ps = -1;
9f1ba906
JM
3838
3839 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3840 params.use_cts_prot =
3841 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3842 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3843 params.use_short_preamble =
3844 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3845 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3846 params.use_short_slot_time =
3847 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3848 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3849 params.basic_rates =
3850 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3851 params.basic_rates_len =
3852 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3853 }
fd8aaaf3
FF
3854 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3855 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3856 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3857 params.ht_opmode =
3858 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3859
53cabad7
JB
3860 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3861 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3862 return -EINVAL;
3863 params.p2p_ctwindow =
3864 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3865 if (params.p2p_ctwindow < 0)
3866 return -EINVAL;
3867 if (params.p2p_ctwindow != 0 &&
3868 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3869 return -EINVAL;
3870 }
3871
3872 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3873 u8 tmp;
3874
3875 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3876 return -EINVAL;
3877 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3878 if (tmp > 1)
3879 return -EINVAL;
3880 params.p2p_opp_ps = tmp;
3881 if (params.p2p_opp_ps &&
3882 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3883 return -EINVAL;
3884 }
3885
4c476991
JB
3886 if (!rdev->ops->change_bss)
3887 return -EOPNOTSUPP;
9f1ba906 3888
074ac8df 3889 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3890 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3891 return -EOPNOTSUPP;
3b85875a 3892
e35e4d28 3893 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
3894}
3895
b54452b0 3896static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3897 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3898 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3899 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3900 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3901 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3902 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3903};
3904
3905static int parse_reg_rule(struct nlattr *tb[],
3906 struct ieee80211_reg_rule *reg_rule)
3907{
3908 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3909 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3910
3911 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3912 return -EINVAL;
3913 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3914 return -EINVAL;
3915 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3916 return -EINVAL;
3917 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3918 return -EINVAL;
3919 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3920 return -EINVAL;
3921
3922 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3923
3924 freq_range->start_freq_khz =
3925 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3926 freq_range->end_freq_khz =
3927 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3928 freq_range->max_bandwidth_khz =
3929 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3930
3931 power_rule->max_eirp =
3932 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3933
3934 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3935 power_rule->max_antenna_gain =
3936 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3937
3938 return 0;
3939}
3940
3941static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3942{
3943 int r;
3944 char *data = NULL;
57b5ce07 3945 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 3946
80778f18
LR
3947 /*
3948 * You should only get this when cfg80211 hasn't yet initialized
3949 * completely when built-in to the kernel right between the time
3950 * window between nl80211_init() and regulatory_init(), if that is
3951 * even possible.
3952 */
458f4f9e 3953 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 3954 return -EINPROGRESS;
80778f18 3955
fe33eb39
LR
3956 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3957 return -EINVAL;
b2e1b302
LR
3958
3959 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3960
57b5ce07
LR
3961 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
3962 user_reg_hint_type =
3963 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
3964 else
3965 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
3966
3967 switch (user_reg_hint_type) {
3968 case NL80211_USER_REG_HINT_USER:
3969 case NL80211_USER_REG_HINT_CELL_BASE:
3970 break;
3971 default:
3972 return -EINVAL;
3973 }
3974
3975 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 3976
b2e1b302
LR
3977 return r;
3978}
3979
24bdd9f4 3980static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3981 struct genl_info *info)
93da9cc1 3982{
4c476991 3983 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3984 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3985 struct wireless_dev *wdev = dev->ieee80211_ptr;
3986 struct mesh_config cur_params;
3987 int err = 0;
93da9cc1 3988 void *hdr;
3989 struct nlattr *pinfoattr;
3990 struct sk_buff *msg;
3991
29cbe68c
JB
3992 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3993 return -EOPNOTSUPP;
3994
24bdd9f4 3995 if (!rdev->ops->get_mesh_config)
4c476991 3996 return -EOPNOTSUPP;
f3f92586 3997
29cbe68c
JB
3998 wdev_lock(wdev);
3999 /* If not connected, get default parameters */
4000 if (!wdev->mesh_id_len)
4001 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
4002 else
e35e4d28 4003 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
4004 wdev_unlock(wdev);
4005
93da9cc1 4006 if (err)
4c476991 4007 return err;
93da9cc1 4008
4009 /* Draw up a netlink message to send back */
fd2120ca 4010 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4011 if (!msg)
4012 return -ENOMEM;
15e47304 4013 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 4014 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 4015 if (!hdr)
efe1cf0c 4016 goto out;
24bdd9f4 4017 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 4018 if (!pinfoattr)
4019 goto nla_put_failure;
9360ffd1
DM
4020 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4021 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
4022 cur_params.dot11MeshRetryTimeout) ||
4023 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4024 cur_params.dot11MeshConfirmTimeout) ||
4025 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
4026 cur_params.dot11MeshHoldingTimeout) ||
4027 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
4028 cur_params.dot11MeshMaxPeerLinks) ||
4029 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
4030 cur_params.dot11MeshMaxRetries) ||
4031 nla_put_u8(msg, NL80211_MESHCONF_TTL,
4032 cur_params.dot11MeshTTL) ||
4033 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
4034 cur_params.element_ttl) ||
4035 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4036 cur_params.auto_open_plinks) ||
7eab0f64
JL
4037 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4038 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
4039 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4040 cur_params.dot11MeshHWMPmaxPREQretries) ||
4041 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
4042 cur_params.path_refresh_time) ||
4043 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4044 cur_params.min_discovery_timeout) ||
4045 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4046 cur_params.dot11MeshHWMPactivePathTimeout) ||
4047 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4048 cur_params.dot11MeshHWMPpreqMinInterval) ||
4049 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4050 cur_params.dot11MeshHWMPperrMinInterval) ||
4051 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4052 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
4053 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
4054 cur_params.dot11MeshHWMPRootMode) ||
4055 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4056 cur_params.dot11MeshHWMPRannInterval) ||
4057 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4058 cur_params.dot11MeshGateAnnouncementProtocol) ||
4059 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
4060 cur_params.dot11MeshForwarding) ||
4061 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
4062 cur_params.rssi_threshold) ||
4063 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4064 cur_params.ht_opmode) ||
4065 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4066 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
4067 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4068 cur_params.dot11MeshHWMProotInterval) ||
4069 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
4070 cur_params.dot11MeshHWMPconfirmationInterval) ||
4071 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
4072 cur_params.power_mode) ||
4073 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
4074 cur_params.dot11MeshAwakeWindowDuration))
9360ffd1 4075 goto nla_put_failure;
93da9cc1 4076 nla_nest_end(msg, pinfoattr);
4077 genlmsg_end(msg, hdr);
4c476991 4078 return genlmsg_reply(msg, info);
93da9cc1 4079
3b85875a 4080 nla_put_failure:
93da9cc1 4081 genlmsg_cancel(msg, hdr);
efe1cf0c 4082 out:
d080e275 4083 nlmsg_free(msg);
4c476991 4084 return -ENOBUFS;
93da9cc1 4085}
4086
b54452b0 4087static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 4088 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
4089 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
4090 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
4091 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
4092 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
4093 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 4094 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 4095 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 4096 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 4097 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
4098 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
4099 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
4100 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
4101 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 4102 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 4103 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 4104 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 4105 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 4106 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 4107 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4108 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4109 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4110 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4111 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4112 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4113 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4114 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
93da9cc1 4115};
4116
c80d545d
JC
4117static const struct nla_policy
4118 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4119 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4120 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4121 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4122 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 4123 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4124 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4125 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4126};
4127
24bdd9f4 4128static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4129 struct mesh_config *cfg,
4130 u32 *mask_out)
93da9cc1 4131{
93da9cc1 4132 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4133 u32 mask = 0;
93da9cc1 4134
ea54fba2
MP
4135#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4136do { \
4137 if (tb[attr]) { \
4138 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4139 return -EINVAL; \
4140 cfg->param = fn(tb[attr]); \
4141 mask |= (1 << (attr - 1)); \
4142 } \
4143} while (0)
bd90fdcc
JB
4144
4145
24bdd9f4 4146 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4147 return -EINVAL;
4148 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4149 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4150 nl80211_meshconf_params_policy))
93da9cc1 4151 return -EINVAL;
4152
93da9cc1 4153 /* This makes sure that there aren't more than 32 mesh config
4154 * parameters (otherwise our bitfield scheme would not work.) */
4155 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4156
4157 /* Fill in the params struct */
ea54fba2 4158 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4159 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4160 nla_get_u16);
ea54fba2 4161 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4162 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4163 nla_get_u16);
ea54fba2 4164 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4165 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4166 nla_get_u16);
ea54fba2 4167 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4168 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4169 nla_get_u16);
ea54fba2 4170 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4171 mask, NL80211_MESHCONF_MAX_RETRIES,
4172 nla_get_u8);
ea54fba2 4173 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4174 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4175 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4176 mask, NL80211_MESHCONF_ELEMENT_TTL,
4177 nla_get_u8);
ea54fba2 4178 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4179 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4180 nla_get_u8);
ea54fba2
MP
4181 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4182 1, 255, mask,
a4f606ea
CYY
4183 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4184 nla_get_u32);
ea54fba2 4185 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4186 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4187 nla_get_u8);
ea54fba2 4188 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4189 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4190 nla_get_u32);
ea54fba2 4191 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4192 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4193 nla_get_u16);
ea54fba2
MP
4194 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4195 1, 65535, mask,
a4f606ea
CYY
4196 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4197 nla_get_u32);
93da9cc1 4198 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4199 1, 65535, mask,
4200 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4201 nla_get_u16);
dca7e943 4202 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4203 1, 65535, mask,
4204 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4205 nla_get_u16);
93da9cc1 4206 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4207 dot11MeshHWMPnetDiameterTraversalTime,
4208 1, 65535, mask,
a4f606ea
CYY
4209 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4210 nla_get_u16);
ea54fba2
MP
4211 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4212 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4213 nla_get_u8);
4214 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4215 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4216 nla_get_u16);
63c5723b 4217 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4218 dot11MeshGateAnnouncementProtocol, 0, 1,
4219 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4220 nla_get_u8);
ea54fba2 4221 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4222 mask, NL80211_MESHCONF_FORWARDING,
4223 nla_get_u8);
ea54fba2 4224 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, 1, 255,
a4f606ea
CYY
4225 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
4226 nla_get_u32);
ea54fba2 4227 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4228 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4229 nla_get_u16);
4230 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4231 1, 65535, mask,
ac1073a6
CYY
4232 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4233 nla_get_u32);
ea54fba2 4234 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4235 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4236 nla_get_u16);
4237 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4238 dot11MeshHWMPconfirmationInterval,
4239 1, 65535, mask,
728b19e5 4240 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4241 nla_get_u16);
3b1c5a53
MP
4242 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4243 NL80211_MESH_POWER_ACTIVE,
4244 NL80211_MESH_POWER_MAX,
4245 mask, NL80211_MESHCONF_POWER_MODE,
4246 nla_get_u32);
4247 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4248 0, 65535, mask,
4249 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
bd90fdcc
JB
4250 if (mask_out)
4251 *mask_out = mask;
c80d545d 4252
bd90fdcc
JB
4253 return 0;
4254
4255#undef FILL_IN_MESH_PARAM_IF_SET
4256}
4257
c80d545d
JC
4258static int nl80211_parse_mesh_setup(struct genl_info *info,
4259 struct mesh_setup *setup)
4260{
4261 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4262
4263 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4264 return -EINVAL;
4265 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4266 info->attrs[NL80211_ATTR_MESH_SETUP],
4267 nl80211_mesh_setup_params_policy))
4268 return -EINVAL;
4269
d299a1f2
JC
4270 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4271 setup->sync_method =
4272 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4273 IEEE80211_SYNC_METHOD_VENDOR :
4274 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4275
c80d545d
JC
4276 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4277 setup->path_sel_proto =
4278 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4279 IEEE80211_PATH_PROTOCOL_VENDOR :
4280 IEEE80211_PATH_PROTOCOL_HWMP;
4281
4282 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4283 setup->path_metric =
4284 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4285 IEEE80211_PATH_METRIC_VENDOR :
4286 IEEE80211_PATH_METRIC_AIRTIME;
4287
581a8b0f
JC
4288
4289 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4290 struct nlattr *ieattr =
581a8b0f 4291 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4292 if (!is_valid_ie_attr(ieattr))
4293 return -EINVAL;
581a8b0f
JC
4294 setup->ie = nla_data(ieattr);
4295 setup->ie_len = nla_len(ieattr);
c80d545d 4296 }
b130e5ce
JC
4297 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4298 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
4299
4300 return 0;
4301}
4302
24bdd9f4 4303static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4304 struct genl_info *info)
bd90fdcc
JB
4305{
4306 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4307 struct net_device *dev = info->user_ptr[1];
29cbe68c 4308 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4309 struct mesh_config cfg;
4310 u32 mask;
4311 int err;
4312
29cbe68c
JB
4313 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4314 return -EOPNOTSUPP;
4315
24bdd9f4 4316 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4317 return -EOPNOTSUPP;
4318
24bdd9f4 4319 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4320 if (err)
4321 return err;
4322
29cbe68c
JB
4323 wdev_lock(wdev);
4324 if (!wdev->mesh_id_len)
4325 err = -ENOLINK;
4326
4327 if (!err)
e35e4d28 4328 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4329
4330 wdev_unlock(wdev);
4331
4332 return err;
93da9cc1 4333}
4334
f130347c
LR
4335static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4336{
458f4f9e 4337 const struct ieee80211_regdomain *regdom;
f130347c
LR
4338 struct sk_buff *msg;
4339 void *hdr = NULL;
4340 struct nlattr *nl_reg_rules;
4341 unsigned int i;
4342 int err = -EINVAL;
4343
a1794390 4344 mutex_lock(&cfg80211_mutex);
f130347c
LR
4345
4346 if (!cfg80211_regdomain)
4347 goto out;
4348
fd2120ca 4349 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
4350 if (!msg) {
4351 err = -ENOBUFS;
4352 goto out;
4353 }
4354
15e47304 4355 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4356 NL80211_CMD_GET_REG);
4357 if (!hdr)
efe1cf0c 4358 goto put_failure;
f130347c 4359
57b5ce07
LR
4360 if (reg_last_request_cell_base() &&
4361 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4362 NL80211_USER_REG_HINT_CELL_BASE))
4363 goto nla_put_failure;
4364
458f4f9e
JB
4365 rcu_read_lock();
4366 regdom = rcu_dereference(cfg80211_regdomain);
4367
4368 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
4369 (regdom->dfs_region &&
4370 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
4371 goto nla_put_failure_rcu;
4372
f130347c
LR
4373 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4374 if (!nl_reg_rules)
458f4f9e 4375 goto nla_put_failure_rcu;
f130347c 4376
458f4f9e 4377 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
4378 struct nlattr *nl_reg_rule;
4379 const struct ieee80211_reg_rule *reg_rule;
4380 const struct ieee80211_freq_range *freq_range;
4381 const struct ieee80211_power_rule *power_rule;
4382
458f4f9e 4383 reg_rule = &regdom->reg_rules[i];
f130347c
LR
4384 freq_range = &reg_rule->freq_range;
4385 power_rule = &reg_rule->power_rule;
4386
4387 nl_reg_rule = nla_nest_start(msg, i);
4388 if (!nl_reg_rule)
458f4f9e 4389 goto nla_put_failure_rcu;
f130347c 4390
9360ffd1
DM
4391 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4392 reg_rule->flags) ||
4393 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4394 freq_range->start_freq_khz) ||
4395 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
4396 freq_range->end_freq_khz) ||
4397 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
4398 freq_range->max_bandwidth_khz) ||
4399 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
4400 power_rule->max_antenna_gain) ||
4401 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
4402 power_rule->max_eirp))
458f4f9e 4403 goto nla_put_failure_rcu;
f130347c
LR
4404
4405 nla_nest_end(msg, nl_reg_rule);
4406 }
458f4f9e 4407 rcu_read_unlock();
f130347c
LR
4408
4409 nla_nest_end(msg, nl_reg_rules);
4410
4411 genlmsg_end(msg, hdr);
134e6375 4412 err = genlmsg_reply(msg, info);
f130347c
LR
4413 goto out;
4414
458f4f9e
JB
4415nla_put_failure_rcu:
4416 rcu_read_unlock();
f130347c
LR
4417nla_put_failure:
4418 genlmsg_cancel(msg, hdr);
efe1cf0c 4419put_failure:
d080e275 4420 nlmsg_free(msg);
f130347c
LR
4421 err = -EMSGSIZE;
4422out:
a1794390 4423 mutex_unlock(&cfg80211_mutex);
f130347c
LR
4424 return err;
4425}
4426
b2e1b302
LR
4427static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
4428{
4429 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
4430 struct nlattr *nl_reg_rule;
4431 char *alpha2 = NULL;
4432 int rem_reg_rules = 0, r = 0;
4433 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4434 u8 dfs_region = 0;
b2e1b302
LR
4435 struct ieee80211_regdomain *rd = NULL;
4436
4437 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4438 return -EINVAL;
4439
4440 if (!info->attrs[NL80211_ATTR_REG_RULES])
4441 return -EINVAL;
4442
4443 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4444
8b60b078
LR
4445 if (info->attrs[NL80211_ATTR_DFS_REGION])
4446 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4447
b2e1b302 4448 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4449 rem_reg_rules) {
b2e1b302
LR
4450 num_rules++;
4451 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4452 return -EINVAL;
b2e1b302
LR
4453 }
4454
b2e1b302 4455 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 4456 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
4457
4458 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
4459 if (!rd)
4460 return -ENOMEM;
b2e1b302
LR
4461
4462 rd->n_reg_rules = num_rules;
4463 rd->alpha2[0] = alpha2[0];
4464 rd->alpha2[1] = alpha2[1];
4465
8b60b078
LR
4466 /*
4467 * Disable DFS master mode if the DFS region was
4468 * not supported or known on this kernel.
4469 */
4470 if (reg_supported_dfs_region(dfs_region))
4471 rd->dfs_region = dfs_region;
4472
b2e1b302 4473 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4474 rem_reg_rules) {
b2e1b302 4475 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
4476 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
4477 reg_rule_policy);
b2e1b302
LR
4478 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
4479 if (r)
4480 goto bad_reg;
4481
4482 rule_idx++;
4483
d0e18f83
LR
4484 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
4485 r = -EINVAL;
b2e1b302 4486 goto bad_reg;
d0e18f83 4487 }
b2e1b302
LR
4488 }
4489
6913b49a
JB
4490 mutex_lock(&cfg80211_mutex);
4491
b2e1b302 4492 r = set_regdom(rd);
6913b49a 4493 /* set_regdom took ownership */
1a919318 4494 rd = NULL;
6913b49a 4495 mutex_unlock(&cfg80211_mutex);
b2e1b302 4496
d2372b31 4497 bad_reg:
b2e1b302 4498 kfree(rd);
d0e18f83 4499 return r;
b2e1b302
LR
4500}
4501
83f5e2cf
JB
4502static int validate_scan_freqs(struct nlattr *freqs)
4503{
4504 struct nlattr *attr1, *attr2;
4505 int n_channels = 0, tmp1, tmp2;
4506
4507 nla_for_each_nested(attr1, freqs, tmp1) {
4508 n_channels++;
4509 /*
4510 * Some hardware has a limited channel list for
4511 * scanning, and it is pretty much nonsensical
4512 * to scan for a channel twice, so disallow that
4513 * and don't require drivers to check that the
4514 * channel list they get isn't longer than what
4515 * they can scan, as long as they can scan all
4516 * the channels they registered at once.
4517 */
4518 nla_for_each_nested(attr2, freqs, tmp2)
4519 if (attr1 != attr2 &&
4520 nla_get_u32(attr1) == nla_get_u32(attr2))
4521 return 0;
4522 }
4523
4524 return n_channels;
4525}
4526
2a519311
JB
4527static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
4528{
4c476991 4529 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 4530 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 4531 struct cfg80211_scan_request *request;
2a519311
JB
4532 struct nlattr *attr;
4533 struct wiphy *wiphy;
83f5e2cf 4534 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 4535 size_t ie_len;
2a519311 4536
f4a11bb0
JB
4537 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4538 return -EINVAL;
4539
79c97e97 4540 wiphy = &rdev->wiphy;
2a519311 4541
4c476991
JB
4542 if (!rdev->ops->scan)
4543 return -EOPNOTSUPP;
2a519311 4544
4c476991
JB
4545 if (rdev->scan_req)
4546 return -EBUSY;
2a519311
JB
4547
4548 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
4549 n_channels = validate_scan_freqs(
4550 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
4551 if (!n_channels)
4552 return -EINVAL;
2a519311 4553 } else {
34850ab2 4554 enum ieee80211_band band;
83f5e2cf
JB
4555 n_channels = 0;
4556
2a519311
JB
4557 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4558 if (wiphy->bands[band])
4559 n_channels += wiphy->bands[band]->n_channels;
4560 }
4561
4562 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4563 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
4564 n_ssids++;
4565
4c476991
JB
4566 if (n_ssids > wiphy->max_scan_ssids)
4567 return -EINVAL;
2a519311 4568
70692ad2
JM
4569 if (info->attrs[NL80211_ATTR_IE])
4570 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4571 else
4572 ie_len = 0;
4573
4c476991
JB
4574 if (ie_len > wiphy->max_scan_ie_len)
4575 return -EINVAL;
18a83659 4576
2a519311 4577 request = kzalloc(sizeof(*request)
a2cd43c5
LC
4578 + sizeof(*request->ssids) * n_ssids
4579 + sizeof(*request->channels) * n_channels
70692ad2 4580 + ie_len, GFP_KERNEL);
4c476991
JB
4581 if (!request)
4582 return -ENOMEM;
2a519311 4583
2a519311 4584 if (n_ssids)
5ba63533 4585 request->ssids = (void *)&request->channels[n_channels];
2a519311 4586 request->n_ssids = n_ssids;
70692ad2
JM
4587 if (ie_len) {
4588 if (request->ssids)
4589 request->ie = (void *)(request->ssids + n_ssids);
4590 else
4591 request->ie = (void *)(request->channels + n_channels);
4592 }
2a519311 4593
584991dc 4594 i = 0;
2a519311
JB
4595 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4596 /* user specified, bail out if channel not found */
2a519311 4597 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
4598 struct ieee80211_channel *chan;
4599
4600 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4601
4602 if (!chan) {
2a519311
JB
4603 err = -EINVAL;
4604 goto out_free;
4605 }
584991dc
JB
4606
4607 /* ignore disabled channels */
4608 if (chan->flags & IEEE80211_CHAN_DISABLED)
4609 continue;
4610
4611 request->channels[i] = chan;
2a519311
JB
4612 i++;
4613 }
4614 } else {
34850ab2
JB
4615 enum ieee80211_band band;
4616
2a519311 4617 /* all channels */
2a519311
JB
4618 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4619 int j;
4620 if (!wiphy->bands[band])
4621 continue;
4622 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4623 struct ieee80211_channel *chan;
4624
4625 chan = &wiphy->bands[band]->channels[j];
4626
4627 if (chan->flags & IEEE80211_CHAN_DISABLED)
4628 continue;
4629
4630 request->channels[i] = chan;
2a519311
JB
4631 i++;
4632 }
4633 }
4634 }
4635
584991dc
JB
4636 if (!i) {
4637 err = -EINVAL;
4638 goto out_free;
4639 }
4640
4641 request->n_channels = i;
4642
2a519311
JB
4643 i = 0;
4644 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4645 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4646 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4647 err = -EINVAL;
4648 goto out_free;
4649 }
57a27e1d 4650 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4651 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4652 i++;
4653 }
4654 }
4655
70692ad2
JM
4656 if (info->attrs[NL80211_ATTR_IE]) {
4657 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4658 memcpy((void *)request->ie,
4659 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4660 request->ie_len);
4661 }
4662
34850ab2 4663 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4664 if (wiphy->bands[i])
4665 request->rates[i] =
4666 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4667
4668 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4669 nla_for_each_nested(attr,
4670 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4671 tmp) {
4672 enum ieee80211_band band = nla_type(attr);
4673
84404623 4674 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4675 err = -EINVAL;
4676 goto out_free;
4677 }
4678 err = ieee80211_get_ratemask(wiphy->bands[band],
4679 nla_data(attr),
4680 nla_len(attr),
4681 &request->rates[band]);
4682 if (err)
4683 goto out_free;
4684 }
4685 }
4686
46856bbf 4687 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4688 request->flags = nla_get_u32(
4689 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4690 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4691 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4692 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4693 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4694 err = -EOPNOTSUPP;
4695 goto out_free;
4696 }
4697 }
ed473771 4698
e9f935e3
RM
4699 request->no_cck =
4700 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4701
fd014284 4702 request->wdev = wdev;
79c97e97 4703 request->wiphy = &rdev->wiphy;
15d6030b 4704 request->scan_start = jiffies;
2a519311 4705
79c97e97 4706 rdev->scan_req = request;
e35e4d28 4707 err = rdev_scan(rdev, request);
2a519311 4708
463d0183 4709 if (!err) {
fd014284
JB
4710 nl80211_send_scan_start(rdev, wdev);
4711 if (wdev->netdev)
4712 dev_hold(wdev->netdev);
4c476991 4713 } else {
2a519311 4714 out_free:
79c97e97 4715 rdev->scan_req = NULL;
2a519311
JB
4716 kfree(request);
4717 }
3b85875a 4718
2a519311
JB
4719 return err;
4720}
4721
807f8a8c
LC
4722static int nl80211_start_sched_scan(struct sk_buff *skb,
4723 struct genl_info *info)
4724{
4725 struct cfg80211_sched_scan_request *request;
4726 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4727 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4728 struct nlattr *attr;
4729 struct wiphy *wiphy;
a1f1c21c 4730 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4731 u32 interval;
807f8a8c
LC
4732 enum ieee80211_band band;
4733 size_t ie_len;
a1f1c21c 4734 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4735
4736 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4737 !rdev->ops->sched_scan_start)
4738 return -EOPNOTSUPP;
4739
4740 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4741 return -EINVAL;
4742
bbe6ad6d
LC
4743 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4744 return -EINVAL;
4745
4746 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4747 if (interval == 0)
4748 return -EINVAL;
4749
807f8a8c
LC
4750 wiphy = &rdev->wiphy;
4751
4752 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4753 n_channels = validate_scan_freqs(
4754 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4755 if (!n_channels)
4756 return -EINVAL;
4757 } else {
4758 n_channels = 0;
4759
4760 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4761 if (wiphy->bands[band])
4762 n_channels += wiphy->bands[band]->n_channels;
4763 }
4764
4765 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4766 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4767 tmp)
4768 n_ssids++;
4769
93b6aa69 4770 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4771 return -EINVAL;
4772
a1f1c21c
LC
4773 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4774 nla_for_each_nested(attr,
4775 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4776 tmp)
4777 n_match_sets++;
4778
4779 if (n_match_sets > wiphy->max_match_sets)
4780 return -EINVAL;
4781
807f8a8c
LC
4782 if (info->attrs[NL80211_ATTR_IE])
4783 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4784 else
4785 ie_len = 0;
4786
5a865bad 4787 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4788 return -EINVAL;
4789
c10841ca
LC
4790 mutex_lock(&rdev->sched_scan_mtx);
4791
4792 if (rdev->sched_scan_req) {
4793 err = -EINPROGRESS;
4794 goto out;
4795 }
4796
807f8a8c 4797 request = kzalloc(sizeof(*request)
a2cd43c5 4798 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4799 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4800 + sizeof(*request->channels) * n_channels
807f8a8c 4801 + ie_len, GFP_KERNEL);
c10841ca
LC
4802 if (!request) {
4803 err = -ENOMEM;
4804 goto out;
4805 }
807f8a8c
LC
4806
4807 if (n_ssids)
4808 request->ssids = (void *)&request->channels[n_channels];
4809 request->n_ssids = n_ssids;
4810 if (ie_len) {
4811 if (request->ssids)
4812 request->ie = (void *)(request->ssids + n_ssids);
4813 else
4814 request->ie = (void *)(request->channels + n_channels);
4815 }
4816
a1f1c21c
LC
4817 if (n_match_sets) {
4818 if (request->ie)
4819 request->match_sets = (void *)(request->ie + ie_len);
4820 else if (request->ssids)
4821 request->match_sets =
4822 (void *)(request->ssids + n_ssids);
4823 else
4824 request->match_sets =
4825 (void *)(request->channels + n_channels);
4826 }
4827 request->n_match_sets = n_match_sets;
4828
807f8a8c
LC
4829 i = 0;
4830 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4831 /* user specified, bail out if channel not found */
4832 nla_for_each_nested(attr,
4833 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4834 tmp) {
4835 struct ieee80211_channel *chan;
4836
4837 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4838
4839 if (!chan) {
4840 err = -EINVAL;
4841 goto out_free;
4842 }
4843
4844 /* ignore disabled channels */
4845 if (chan->flags & IEEE80211_CHAN_DISABLED)
4846 continue;
4847
4848 request->channels[i] = chan;
4849 i++;
4850 }
4851 } else {
4852 /* all channels */
4853 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4854 int j;
4855 if (!wiphy->bands[band])
4856 continue;
4857 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4858 struct ieee80211_channel *chan;
4859
4860 chan = &wiphy->bands[band]->channels[j];
4861
4862 if (chan->flags & IEEE80211_CHAN_DISABLED)
4863 continue;
4864
4865 request->channels[i] = chan;
4866 i++;
4867 }
4868 }
4869 }
4870
4871 if (!i) {
4872 err = -EINVAL;
4873 goto out_free;
4874 }
4875
4876 request->n_channels = i;
4877
4878 i = 0;
4879 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4880 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4881 tmp) {
57a27e1d 4882 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4883 err = -EINVAL;
4884 goto out_free;
4885 }
57a27e1d 4886 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4887 memcpy(request->ssids[i].ssid, nla_data(attr),
4888 nla_len(attr));
807f8a8c
LC
4889 i++;
4890 }
4891 }
4892
a1f1c21c
LC
4893 i = 0;
4894 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4895 nla_for_each_nested(attr,
4896 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4897 tmp) {
88e920b4 4898 struct nlattr *ssid, *rssi;
a1f1c21c
LC
4899
4900 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4901 nla_data(attr), nla_len(attr),
4902 nl80211_match_policy);
4a4ab0d7 4903 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4904 if (ssid) {
4905 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4906 err = -EINVAL;
4907 goto out_free;
4908 }
4909 memcpy(request->match_sets[i].ssid.ssid,
4910 nla_data(ssid), nla_len(ssid));
4911 request->match_sets[i].ssid.ssid_len =
4912 nla_len(ssid);
4913 }
88e920b4
TP
4914 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
4915 if (rssi)
4916 request->rssi_thold = nla_get_u32(rssi);
4917 else
4918 request->rssi_thold =
4919 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
4920 i++;
4921 }
4922 }
4923
807f8a8c
LC
4924 if (info->attrs[NL80211_ATTR_IE]) {
4925 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4926 memcpy((void *)request->ie,
4927 nla_data(info->attrs[NL80211_ATTR_IE]),
4928 request->ie_len);
4929 }
4930
46856bbf 4931 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4932 request->flags = nla_get_u32(
4933 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4934 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4935 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4936 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4937 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4938 err = -EOPNOTSUPP;
4939 goto out_free;
4940 }
4941 }
ed473771 4942
807f8a8c
LC
4943 request->dev = dev;
4944 request->wiphy = &rdev->wiphy;
bbe6ad6d 4945 request->interval = interval;
15d6030b 4946 request->scan_start = jiffies;
807f8a8c 4947
e35e4d28 4948 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
4949 if (!err) {
4950 rdev->sched_scan_req = request;
4951 nl80211_send_sched_scan(rdev, dev,
4952 NL80211_CMD_START_SCHED_SCAN);
4953 goto out;
4954 }
4955
4956out_free:
4957 kfree(request);
4958out:
c10841ca 4959 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4960 return err;
4961}
4962
4963static int nl80211_stop_sched_scan(struct sk_buff *skb,
4964 struct genl_info *info)
4965{
4966 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4967 int err;
807f8a8c
LC
4968
4969 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4970 !rdev->ops->sched_scan_stop)
4971 return -EOPNOTSUPP;
4972
c10841ca
LC
4973 mutex_lock(&rdev->sched_scan_mtx);
4974 err = __cfg80211_stop_sched_scan(rdev, false);
4975 mutex_unlock(&rdev->sched_scan_mtx);
4976
4977 return err;
807f8a8c
LC
4978}
4979
9720bb3a
JB
4980static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4981 u32 seq, int flags,
2a519311 4982 struct cfg80211_registered_device *rdev,
48ab905d
JB
4983 struct wireless_dev *wdev,
4984 struct cfg80211_internal_bss *intbss)
2a519311 4985{
48ab905d 4986 struct cfg80211_bss *res = &intbss->pub;
9caf0364 4987 const struct cfg80211_bss_ies *ies;
2a519311
JB
4988 void *hdr;
4989 struct nlattr *bss;
48ab905d
JB
4990
4991 ASSERT_WDEV_LOCK(wdev);
2a519311 4992
15e47304 4993 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
4994 NL80211_CMD_NEW_SCAN_RESULTS);
4995 if (!hdr)
4996 return -1;
4997
9720bb3a
JB
4998 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4999
9360ffd1
DM
5000 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
5001 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
5002 goto nla_put_failure;
2a519311
JB
5003
5004 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
5005 if (!bss)
5006 goto nla_put_failure;
9360ffd1 5007 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 5008 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 5009 goto nla_put_failure;
9caf0364
JB
5010
5011 rcu_read_lock();
5012 ies = rcu_dereference(res->ies);
5013 if (ies && ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
5014 ies->len, ies->data)) {
5015 rcu_read_unlock();
5016 goto nla_put_failure;
5017 }
5018 ies = rcu_dereference(res->beacon_ies);
5019 if (ies && ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
5020 ies->len, ies->data)) {
5021 rcu_read_unlock();
5022 goto nla_put_failure;
5023 }
5024 rcu_read_unlock();
5025
9360ffd1
DM
5026 if (res->tsf &&
5027 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
5028 goto nla_put_failure;
5029 if (res->beacon_interval &&
5030 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
5031 goto nla_put_failure;
5032 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
5033 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
5034 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
5035 jiffies_to_msecs(jiffies - intbss->ts)))
5036 goto nla_put_failure;
2a519311 5037
77965c97 5038 switch (rdev->wiphy.signal_type) {
2a519311 5039 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
5040 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
5041 goto nla_put_failure;
2a519311
JB
5042 break;
5043 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
5044 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
5045 goto nla_put_failure;
2a519311
JB
5046 break;
5047 default:
5048 break;
5049 }
5050
48ab905d 5051 switch (wdev->iftype) {
074ac8df 5052 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 5053 case NL80211_IFTYPE_STATION:
9360ffd1
DM
5054 if (intbss == wdev->current_bss &&
5055 nla_put_u32(msg, NL80211_BSS_STATUS,
5056 NL80211_BSS_STATUS_ASSOCIATED))
5057 goto nla_put_failure;
48ab905d
JB
5058 break;
5059 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
5060 if (intbss == wdev->current_bss &&
5061 nla_put_u32(msg, NL80211_BSS_STATUS,
5062 NL80211_BSS_STATUS_IBSS_JOINED))
5063 goto nla_put_failure;
48ab905d
JB
5064 break;
5065 default:
5066 break;
5067 }
5068
2a519311
JB
5069 nla_nest_end(msg, bss);
5070
5071 return genlmsg_end(msg, hdr);
5072
5073 nla_put_failure:
5074 genlmsg_cancel(msg, hdr);
5075 return -EMSGSIZE;
5076}
5077
5078static int nl80211_dump_scan(struct sk_buff *skb,
5079 struct netlink_callback *cb)
5080{
48ab905d
JB
5081 struct cfg80211_registered_device *rdev;
5082 struct net_device *dev;
2a519311 5083 struct cfg80211_internal_bss *scan;
48ab905d 5084 struct wireless_dev *wdev;
2a519311
JB
5085 int start = cb->args[1], idx = 0;
5086 int err;
5087
67748893
JB
5088 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
5089 if (err)
5090 return err;
2a519311 5091
48ab905d 5092 wdev = dev->ieee80211_ptr;
2a519311 5093
48ab905d
JB
5094 wdev_lock(wdev);
5095 spin_lock_bh(&rdev->bss_lock);
5096 cfg80211_bss_expire(rdev);
5097
9720bb3a
JB
5098 cb->seq = rdev->bss_generation;
5099
48ab905d 5100 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
5101 if (++idx <= start)
5102 continue;
9720bb3a 5103 if (nl80211_send_bss(skb, cb,
2a519311 5104 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 5105 rdev, wdev, scan) < 0) {
2a519311 5106 idx--;
67748893 5107 break;
2a519311
JB
5108 }
5109 }
5110
48ab905d
JB
5111 spin_unlock_bh(&rdev->bss_lock);
5112 wdev_unlock(wdev);
2a519311
JB
5113
5114 cb->args[1] = idx;
67748893 5115 nl80211_finish_netdev_dump(rdev);
2a519311 5116
67748893 5117 return skb->len;
2a519311
JB
5118}
5119
15e47304 5120static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
5121 int flags, struct net_device *dev,
5122 struct survey_info *survey)
5123{
5124 void *hdr;
5125 struct nlattr *infoattr;
5126
15e47304 5127 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
5128 NL80211_CMD_NEW_SURVEY_RESULTS);
5129 if (!hdr)
5130 return -ENOMEM;
5131
9360ffd1
DM
5132 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
5133 goto nla_put_failure;
61fa713c
HS
5134
5135 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
5136 if (!infoattr)
5137 goto nla_put_failure;
5138
9360ffd1
DM
5139 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
5140 survey->channel->center_freq))
5141 goto nla_put_failure;
5142
5143 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
5144 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
5145 goto nla_put_failure;
5146 if ((survey->filled & SURVEY_INFO_IN_USE) &&
5147 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
5148 goto nla_put_failure;
5149 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
5150 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
5151 survey->channel_time))
5152 goto nla_put_failure;
5153 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
5154 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
5155 survey->channel_time_busy))
5156 goto nla_put_failure;
5157 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
5158 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5159 survey->channel_time_ext_busy))
5160 goto nla_put_failure;
5161 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5162 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5163 survey->channel_time_rx))
5164 goto nla_put_failure;
5165 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5166 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5167 survey->channel_time_tx))
5168 goto nla_put_failure;
61fa713c
HS
5169
5170 nla_nest_end(msg, infoattr);
5171
5172 return genlmsg_end(msg, hdr);
5173
5174 nla_put_failure:
5175 genlmsg_cancel(msg, hdr);
5176 return -EMSGSIZE;
5177}
5178
5179static int nl80211_dump_survey(struct sk_buff *skb,
5180 struct netlink_callback *cb)
5181{
5182 struct survey_info survey;
5183 struct cfg80211_registered_device *dev;
5184 struct net_device *netdev;
61fa713c
HS
5185 int survey_idx = cb->args[1];
5186 int res;
5187
67748893
JB
5188 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
5189 if (res)
5190 return res;
61fa713c
HS
5191
5192 if (!dev->ops->dump_survey) {
5193 res = -EOPNOTSUPP;
5194 goto out_err;
5195 }
5196
5197 while (1) {
180cdc79
LR
5198 struct ieee80211_channel *chan;
5199
e35e4d28 5200 res = rdev_dump_survey(dev, netdev, survey_idx, &survey);
61fa713c
HS
5201 if (res == -ENOENT)
5202 break;
5203 if (res)
5204 goto out_err;
5205
180cdc79
LR
5206 /* Survey without a channel doesn't make sense */
5207 if (!survey.channel) {
5208 res = -EINVAL;
5209 goto out;
5210 }
5211
5212 chan = ieee80211_get_channel(&dev->wiphy,
5213 survey.channel->center_freq);
5214 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5215 survey_idx++;
5216 continue;
5217 }
5218
61fa713c 5219 if (nl80211_send_survey(skb,
15e47304 5220 NETLINK_CB(cb->skb).portid,
61fa713c
HS
5221 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5222 netdev,
5223 &survey) < 0)
5224 goto out;
5225 survey_idx++;
5226 }
5227
5228 out:
5229 cb->args[1] = survey_idx;
5230 res = skb->len;
5231 out_err:
67748893 5232 nl80211_finish_netdev_dump(dev);
61fa713c
HS
5233 return res;
5234}
5235
b23aa676
SO
5236static bool nl80211_valid_wpa_versions(u32 wpa_versions)
5237{
5238 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
5239 NL80211_WPA_VERSION_2));
5240}
5241
636a5d36
JM
5242static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
5243{
4c476991
JB
5244 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5245 struct net_device *dev = info->user_ptr[1];
19957bb3 5246 struct ieee80211_channel *chan;
e39e5b5e
JM
5247 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
5248 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 5249 enum nl80211_auth_type auth_type;
fffd0934 5250 struct key_parse key;
d5cdfacb 5251 bool local_state_change;
636a5d36 5252
f4a11bb0
JB
5253 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5254 return -EINVAL;
5255
5256 if (!info->attrs[NL80211_ATTR_MAC])
5257 return -EINVAL;
5258
1778092e
JM
5259 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
5260 return -EINVAL;
5261
19957bb3
JB
5262 if (!info->attrs[NL80211_ATTR_SSID])
5263 return -EINVAL;
5264
5265 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
5266 return -EINVAL;
5267
fffd0934
JB
5268 err = nl80211_parse_key(info, &key);
5269 if (err)
5270 return err;
5271
5272 if (key.idx >= 0) {
e31b8213
JB
5273 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
5274 return -EINVAL;
fffd0934
JB
5275 if (!key.p.key || !key.p.key_len)
5276 return -EINVAL;
5277 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
5278 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
5279 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
5280 key.p.key_len != WLAN_KEY_LEN_WEP104))
5281 return -EINVAL;
5282 if (key.idx > 4)
5283 return -EINVAL;
5284 } else {
5285 key.p.key_len = 0;
5286 key.p.key = NULL;
5287 }
5288
afea0b7a
JB
5289 if (key.idx >= 0) {
5290 int i;
5291 bool ok = false;
5292 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
5293 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
5294 ok = true;
5295 break;
5296 }
5297 }
4c476991
JB
5298 if (!ok)
5299 return -EINVAL;
afea0b7a
JB
5300 }
5301
4c476991
JB
5302 if (!rdev->ops->auth)
5303 return -EOPNOTSUPP;
636a5d36 5304
074ac8df 5305 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5306 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5307 return -EOPNOTSUPP;
eec60b03 5308
19957bb3 5309 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 5310 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 5311 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5312 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5313 return -EINVAL;
636a5d36 5314
19957bb3
JB
5315 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5316 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5317
5318 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5319 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5320 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5321 }
5322
19957bb3 5323 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 5324 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 5325 return -EINVAL;
636a5d36 5326
e39e5b5e
JM
5327 if (auth_type == NL80211_AUTHTYPE_SAE &&
5328 !info->attrs[NL80211_ATTR_SAE_DATA])
5329 return -EINVAL;
5330
5331 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
5332 if (auth_type != NL80211_AUTHTYPE_SAE)
5333 return -EINVAL;
5334 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
5335 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
5336 /* need to include at least Auth Transaction and Status Code */
5337 if (sae_data_len < 4)
5338 return -EINVAL;
5339 }
5340
d5cdfacb
JM
5341 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5342
95de817b
JB
5343 /*
5344 * Since we no longer track auth state, ignore
5345 * requests to only change local state.
5346 */
5347 if (local_state_change)
5348 return 0;
5349
4c476991
JB
5350 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
5351 ssid, ssid_len, ie, ie_len,
e39e5b5e
JM
5352 key.p.key, key.p.key_len, key.idx,
5353 sae_data, sae_data_len);
636a5d36
JM
5354}
5355
c0692b8f
JB
5356static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
5357 struct genl_info *info,
3dc27d25
JB
5358 struct cfg80211_crypto_settings *settings,
5359 int cipher_limit)
b23aa676 5360{
c0b2bbd8
JB
5361 memset(settings, 0, sizeof(*settings));
5362
b23aa676
SO
5363 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
5364
c0692b8f
JB
5365 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
5366 u16 proto;
5367 proto = nla_get_u16(
5368 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
5369 settings->control_port_ethertype = cpu_to_be16(proto);
5370 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
5371 proto != ETH_P_PAE)
5372 return -EINVAL;
5373 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
5374 settings->control_port_no_encrypt = true;
5375 } else
5376 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
5377
b23aa676
SO
5378 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
5379 void *data;
5380 int len, i;
5381
5382 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5383 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5384 settings->n_ciphers_pairwise = len / sizeof(u32);
5385
5386 if (len % sizeof(u32))
5387 return -EINVAL;
5388
3dc27d25 5389 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
5390 return -EINVAL;
5391
5392 memcpy(settings->ciphers_pairwise, data, len);
5393
5394 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
5395 if (!cfg80211_supported_cipher_suite(
5396 &rdev->wiphy,
b23aa676
SO
5397 settings->ciphers_pairwise[i]))
5398 return -EINVAL;
5399 }
5400
5401 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
5402 settings->cipher_group =
5403 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
5404 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
5405 settings->cipher_group))
b23aa676
SO
5406 return -EINVAL;
5407 }
5408
5409 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
5410 settings->wpa_versions =
5411 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
5412 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
5413 return -EINVAL;
5414 }
5415
5416 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
5417 void *data;
6d30240e 5418 int len;
b23aa676
SO
5419
5420 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
5421 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
5422 settings->n_akm_suites = len / sizeof(u32);
5423
5424 if (len % sizeof(u32))
5425 return -EINVAL;
5426
1b9ca027
JM
5427 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
5428 return -EINVAL;
5429
b23aa676 5430 memcpy(settings->akm_suites, data, len);
b23aa676
SO
5431 }
5432
5433 return 0;
5434}
5435
636a5d36
JM
5436static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
5437{
4c476991
JB
5438 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5439 struct net_device *dev = info->user_ptr[1];
19957bb3 5440 struct cfg80211_crypto_settings crypto;
f444de05 5441 struct ieee80211_channel *chan;
3e5d7649 5442 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
5443 int err, ssid_len, ie_len = 0;
5444 bool use_mfp = false;
7e7c8926
BG
5445 u32 flags = 0;
5446 struct ieee80211_ht_cap *ht_capa = NULL;
5447 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 5448
f4a11bb0
JB
5449 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5450 return -EINVAL;
5451
5452 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
5453 !info->attrs[NL80211_ATTR_SSID] ||
5454 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
5455 return -EINVAL;
5456
4c476991
JB
5457 if (!rdev->ops->assoc)
5458 return -EOPNOTSUPP;
636a5d36 5459
074ac8df 5460 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5461 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5462 return -EOPNOTSUPP;
eec60b03 5463
19957bb3 5464 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5465
19957bb3
JB
5466 chan = ieee80211_get_channel(&rdev->wiphy,
5467 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5468 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5469 return -EINVAL;
636a5d36 5470
19957bb3
JB
5471 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5472 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5473
5474 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5475 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5476 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5477 }
5478
dc6382ce 5479 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 5480 enum nl80211_mfp mfp =
dc6382ce 5481 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 5482 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 5483 use_mfp = true;
4c476991
JB
5484 else if (mfp != NL80211_MFP_NO)
5485 return -EINVAL;
dc6382ce
JM
5486 }
5487
3e5d7649
JB
5488 if (info->attrs[NL80211_ATTR_PREV_BSSID])
5489 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
5490
7e7c8926
BG
5491 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5492 flags |= ASSOC_REQ_DISABLE_HT;
5493
5494 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5495 ht_capa_mask =
5496 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
5497
5498 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5499 if (!ht_capa_mask)
5500 return -EINVAL;
5501 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5502 }
5503
c0692b8f 5504 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 5505 if (!err)
3e5d7649
JB
5506 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
5507 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
5508 &crypto, flags, ht_capa,
5509 ht_capa_mask);
636a5d36 5510
636a5d36
JM
5511 return err;
5512}
5513
5514static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
5515{
4c476991
JB
5516 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5517 struct net_device *dev = info->user_ptr[1];
19957bb3 5518 const u8 *ie = NULL, *bssid;
4c476991 5519 int ie_len = 0;
19957bb3 5520 u16 reason_code;
d5cdfacb 5521 bool local_state_change;
636a5d36 5522
f4a11bb0
JB
5523 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5524 return -EINVAL;
5525
5526 if (!info->attrs[NL80211_ATTR_MAC])
5527 return -EINVAL;
5528
5529 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5530 return -EINVAL;
5531
4c476991
JB
5532 if (!rdev->ops->deauth)
5533 return -EOPNOTSUPP;
636a5d36 5534
074ac8df 5535 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5536 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5537 return -EOPNOTSUPP;
eec60b03 5538
19957bb3 5539 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5540
19957bb3
JB
5541 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5542 if (reason_code == 0) {
f4a11bb0 5543 /* Reason Code 0 is reserved */
4c476991 5544 return -EINVAL;
255e737e 5545 }
636a5d36
JM
5546
5547 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5548 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5549 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5550 }
5551
d5cdfacb
JM
5552 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5553
4c476991
JB
5554 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
5555 local_state_change);
636a5d36
JM
5556}
5557
5558static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
5559{
4c476991
JB
5560 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5561 struct net_device *dev = info->user_ptr[1];
19957bb3 5562 const u8 *ie = NULL, *bssid;
4c476991 5563 int ie_len = 0;
19957bb3 5564 u16 reason_code;
d5cdfacb 5565 bool local_state_change;
636a5d36 5566
f4a11bb0
JB
5567 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5568 return -EINVAL;
5569
5570 if (!info->attrs[NL80211_ATTR_MAC])
5571 return -EINVAL;
5572
5573 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5574 return -EINVAL;
5575
4c476991
JB
5576 if (!rdev->ops->disassoc)
5577 return -EOPNOTSUPP;
636a5d36 5578
074ac8df 5579 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5580 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5581 return -EOPNOTSUPP;
eec60b03 5582
19957bb3 5583 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5584
19957bb3
JB
5585 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5586 if (reason_code == 0) {
f4a11bb0 5587 /* Reason Code 0 is reserved */
4c476991 5588 return -EINVAL;
255e737e 5589 }
636a5d36
JM
5590
5591 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5592 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5593 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5594 }
5595
d5cdfacb
JM
5596 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5597
4c476991
JB
5598 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
5599 local_state_change);
636a5d36
JM
5600}
5601
dd5b4cc7
FF
5602static bool
5603nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
5604 int mcast_rate[IEEE80211_NUM_BANDS],
5605 int rateval)
5606{
5607 struct wiphy *wiphy = &rdev->wiphy;
5608 bool found = false;
5609 int band, i;
5610
5611 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5612 struct ieee80211_supported_band *sband;
5613
5614 sband = wiphy->bands[band];
5615 if (!sband)
5616 continue;
5617
5618 for (i = 0; i < sband->n_bitrates; i++) {
5619 if (sband->bitrates[i].bitrate == rateval) {
5620 mcast_rate[band] = i + 1;
5621 found = true;
5622 break;
5623 }
5624 }
5625 }
5626
5627 return found;
5628}
5629
04a773ad
JB
5630static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
5631{
4c476991
JB
5632 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5633 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
5634 struct cfg80211_ibss_params ibss;
5635 struct wiphy *wiphy;
fffd0934 5636 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
5637 int err;
5638
8e30bc55
JB
5639 memset(&ibss, 0, sizeof(ibss));
5640
04a773ad
JB
5641 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5642 return -EINVAL;
5643
683b6d3b 5644 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
5645 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5646 return -EINVAL;
5647
8e30bc55
JB
5648 ibss.beacon_interval = 100;
5649
5650 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
5651 ibss.beacon_interval =
5652 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5653 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
5654 return -EINVAL;
5655 }
5656
4c476991
JB
5657 if (!rdev->ops->join_ibss)
5658 return -EOPNOTSUPP;
04a773ad 5659
4c476991
JB
5660 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5661 return -EOPNOTSUPP;
04a773ad 5662
79c97e97 5663 wiphy = &rdev->wiphy;
04a773ad 5664
39193498 5665 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 5666 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
5667
5668 if (!is_valid_ether_addr(ibss.bssid))
5669 return -EINVAL;
5670 }
04a773ad
JB
5671 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5672 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5673
5674 if (info->attrs[NL80211_ATTR_IE]) {
5675 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5676 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5677 }
5678
683b6d3b
JB
5679 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
5680 if (err)
5681 return err;
04a773ad 5682
683b6d3b 5683 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
5684 return -EINVAL;
5685
db9c64cf
JB
5686 if (ibss.chandef.width > NL80211_CHAN_WIDTH_40)
5687 return -EINVAL;
5688 if (ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
5689 !(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
c04d6150 5690 return -EINVAL;
db9c64cf 5691
04a773ad 5692 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5693 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5694
fbd2c8dc
TP
5695 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5696 u8 *rates =
5697 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5698 int n_rates =
5699 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5700 struct ieee80211_supported_band *sband =
683b6d3b 5701 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 5702
34850ab2
JB
5703 err = ieee80211_get_ratemask(sband, rates, n_rates,
5704 &ibss.basic_rates);
5705 if (err)
5706 return err;
fbd2c8dc 5707 }
dd5b4cc7
FF
5708
5709 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5710 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5711 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5712 return -EINVAL;
fbd2c8dc 5713
4c476991 5714 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
5715 bool no_ht = false;
5716
4c476991 5717 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
5718 info->attrs[NL80211_ATTR_KEYS],
5719 &no_ht);
4c476991
JB
5720 if (IS_ERR(connkeys))
5721 return PTR_ERR(connkeys);
de7044ee 5722
3d9d1d66
JB
5723 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
5724 no_ht) {
de7044ee
SM
5725 kfree(connkeys);
5726 return -EINVAL;
5727 }
4c476991 5728 }
04a773ad 5729
267335d6
AQ
5730 ibss.control_port =
5731 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5732
4c476991 5733 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5734 if (err)
5735 kfree(connkeys);
04a773ad
JB
5736 return err;
5737}
5738
5739static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5740{
4c476991
JB
5741 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5742 struct net_device *dev = info->user_ptr[1];
04a773ad 5743
4c476991
JB
5744 if (!rdev->ops->leave_ibss)
5745 return -EOPNOTSUPP;
04a773ad 5746
4c476991
JB
5747 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5748 return -EOPNOTSUPP;
04a773ad 5749
4c476991 5750 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5751}
5752
f4e583c8
AQ
5753static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
5754{
5755 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5756 struct net_device *dev = info->user_ptr[1];
5757 int mcast_rate[IEEE80211_NUM_BANDS];
5758 u32 nla_rate;
5759 int err;
5760
5761 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5762 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5763 return -EOPNOTSUPP;
5764
5765 if (!rdev->ops->set_mcast_rate)
5766 return -EOPNOTSUPP;
5767
5768 memset(mcast_rate, 0, sizeof(mcast_rate));
5769
5770 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
5771 return -EINVAL;
5772
5773 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
5774 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
5775 return -EINVAL;
5776
5777 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
5778
5779 return err;
5780}
5781
5782
aff89a9b
JB
5783#ifdef CONFIG_NL80211_TESTMODE
5784static struct genl_multicast_group nl80211_testmode_mcgrp = {
5785 .name = "testmode",
5786};
5787
5788static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5789{
4c476991 5790 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5791 int err;
5792
5793 if (!info->attrs[NL80211_ATTR_TESTDATA])
5794 return -EINVAL;
5795
aff89a9b
JB
5796 err = -EOPNOTSUPP;
5797 if (rdev->ops->testmode_cmd) {
5798 rdev->testmode_info = info;
e35e4d28 5799 err = rdev_testmode_cmd(rdev,
aff89a9b
JB
5800 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5801 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5802 rdev->testmode_info = NULL;
5803 }
5804
aff89a9b
JB
5805 return err;
5806}
5807
71063f0e
WYG
5808static int nl80211_testmode_dump(struct sk_buff *skb,
5809 struct netlink_callback *cb)
5810{
00918d33 5811 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5812 int err;
5813 long phy_idx;
5814 void *data = NULL;
5815 int data_len = 0;
5816
5817 if (cb->args[0]) {
5818 /*
5819 * 0 is a valid index, but not valid for args[0],
5820 * so we need to offset by 1.
5821 */
5822 phy_idx = cb->args[0] - 1;
5823 } else {
5824 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5825 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5826 nl80211_policy);
5827 if (err)
5828 return err;
00918d33 5829
2bd7e35d
JB
5830 mutex_lock(&cfg80211_mutex);
5831 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
5832 nl80211_fam.attrbuf);
5833 if (IS_ERR(rdev)) {
5834 mutex_unlock(&cfg80211_mutex);
5835 return PTR_ERR(rdev);
00918d33 5836 }
2bd7e35d
JB
5837 phy_idx = rdev->wiphy_idx;
5838 rdev = NULL;
5839 mutex_unlock(&cfg80211_mutex);
5840
71063f0e
WYG
5841 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5842 cb->args[1] =
5843 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5844 }
5845
5846 if (cb->args[1]) {
5847 data = nla_data((void *)cb->args[1]);
5848 data_len = nla_len((void *)cb->args[1]);
5849 }
5850
5851 mutex_lock(&cfg80211_mutex);
00918d33
JB
5852 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5853 if (!rdev) {
71063f0e
WYG
5854 mutex_unlock(&cfg80211_mutex);
5855 return -ENOENT;
5856 }
00918d33 5857 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5858 mutex_unlock(&cfg80211_mutex);
5859
00918d33 5860 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5861 err = -EOPNOTSUPP;
5862 goto out_err;
5863 }
5864
5865 while (1) {
15e47304 5866 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
5867 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5868 NL80211_CMD_TESTMODE);
5869 struct nlattr *tmdata;
5870
9360ffd1 5871 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5872 genlmsg_cancel(skb, hdr);
5873 break;
5874 }
5875
5876 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5877 if (!tmdata) {
5878 genlmsg_cancel(skb, hdr);
5879 break;
5880 }
e35e4d28 5881 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
5882 nla_nest_end(skb, tmdata);
5883
5884 if (err == -ENOBUFS || err == -ENOENT) {
5885 genlmsg_cancel(skb, hdr);
5886 break;
5887 } else if (err) {
5888 genlmsg_cancel(skb, hdr);
5889 goto out_err;
5890 }
5891
5892 genlmsg_end(skb, hdr);
5893 }
5894
5895 err = skb->len;
5896 /* see above */
5897 cb->args[0] = phy_idx + 1;
5898 out_err:
00918d33 5899 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5900 return err;
5901}
5902
aff89a9b
JB
5903static struct sk_buff *
5904__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 5905 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
5906{
5907 struct sk_buff *skb;
5908 void *hdr;
5909 struct nlattr *data;
5910
5911 skb = nlmsg_new(approxlen + 100, gfp);
5912 if (!skb)
5913 return NULL;
5914
15e47304 5915 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
5916 if (!hdr) {
5917 kfree_skb(skb);
5918 return NULL;
5919 }
5920
9360ffd1
DM
5921 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5922 goto nla_put_failure;
aff89a9b
JB
5923 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5924
5925 ((void **)skb->cb)[0] = rdev;
5926 ((void **)skb->cb)[1] = hdr;
5927 ((void **)skb->cb)[2] = data;
5928
5929 return skb;
5930
5931 nla_put_failure:
5932 kfree_skb(skb);
5933 return NULL;
5934}
5935
5936struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5937 int approxlen)
5938{
5939 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5940
5941 if (WARN_ON(!rdev->testmode_info))
5942 return NULL;
5943
5944 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 5945 rdev->testmode_info->snd_portid,
aff89a9b
JB
5946 rdev->testmode_info->snd_seq,
5947 GFP_KERNEL);
5948}
5949EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5950
5951int cfg80211_testmode_reply(struct sk_buff *skb)
5952{
5953 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5954 void *hdr = ((void **)skb->cb)[1];
5955 struct nlattr *data = ((void **)skb->cb)[2];
5956
5957 if (WARN_ON(!rdev->testmode_info)) {
5958 kfree_skb(skb);
5959 return -EINVAL;
5960 }
5961
5962 nla_nest_end(skb, data);
5963 genlmsg_end(skb, hdr);
5964 return genlmsg_reply(skb, rdev->testmode_info);
5965}
5966EXPORT_SYMBOL(cfg80211_testmode_reply);
5967
5968struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5969 int approxlen, gfp_t gfp)
5970{
5971 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5972
5973 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5974}
5975EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5976
5977void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5978{
5979 void *hdr = ((void **)skb->cb)[1];
5980 struct nlattr *data = ((void **)skb->cb)[2];
5981
5982 nla_nest_end(skb, data);
5983 genlmsg_end(skb, hdr);
5984 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5985}
5986EXPORT_SYMBOL(cfg80211_testmode_event);
5987#endif
5988
b23aa676
SO
5989static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5990{
4c476991
JB
5991 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5992 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5993 struct cfg80211_connect_params connect;
5994 struct wiphy *wiphy;
fffd0934 5995 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5996 int err;
5997
5998 memset(&connect, 0, sizeof(connect));
5999
6000 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6001 return -EINVAL;
6002
6003 if (!info->attrs[NL80211_ATTR_SSID] ||
6004 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6005 return -EINVAL;
6006
6007 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6008 connect.auth_type =
6009 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
6010 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
6011 NL80211_CMD_CONNECT))
b23aa676
SO
6012 return -EINVAL;
6013 } else
6014 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6015
6016 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
6017
c0692b8f 6018 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 6019 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
6020 if (err)
6021 return err;
b23aa676 6022
074ac8df 6023 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6024 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6025 return -EOPNOTSUPP;
b23aa676 6026
79c97e97 6027 wiphy = &rdev->wiphy;
b23aa676 6028
4486ea98
BS
6029 connect.bg_scan_period = -1;
6030 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
6031 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
6032 connect.bg_scan_period =
6033 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
6034 }
6035
b23aa676
SO
6036 if (info->attrs[NL80211_ATTR_MAC])
6037 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6038 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6039 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6040
6041 if (info->attrs[NL80211_ATTR_IE]) {
6042 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6043 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6044 }
6045
cee00a95
JM
6046 if (info->attrs[NL80211_ATTR_USE_MFP]) {
6047 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
6048 if (connect.mfp != NL80211_MFP_REQUIRED &&
6049 connect.mfp != NL80211_MFP_NO)
6050 return -EINVAL;
6051 } else {
6052 connect.mfp = NL80211_MFP_NO;
6053 }
6054
b23aa676
SO
6055 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6056 connect.channel =
6057 ieee80211_get_channel(wiphy,
6058 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
6059 if (!connect.channel ||
4c476991
JB
6060 connect.channel->flags & IEEE80211_CHAN_DISABLED)
6061 return -EINVAL;
b23aa676
SO
6062 }
6063
fffd0934
JB
6064 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
6065 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 6066 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
6067 if (IS_ERR(connkeys))
6068 return PTR_ERR(connkeys);
fffd0934
JB
6069 }
6070
7e7c8926
BG
6071 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
6072 connect.flags |= ASSOC_REQ_DISABLE_HT;
6073
6074 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6075 memcpy(&connect.ht_capa_mask,
6076 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6077 sizeof(connect.ht_capa_mask));
6078
6079 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
6080 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
6081 kfree(connkeys);
7e7c8926 6082 return -EINVAL;
b4e4f47e 6083 }
7e7c8926
BG
6084 memcpy(&connect.ht_capa,
6085 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6086 sizeof(connect.ht_capa));
6087 }
6088
fffd0934 6089 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
6090 if (err)
6091 kfree(connkeys);
b23aa676
SO
6092 return err;
6093}
6094
6095static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
6096{
4c476991
JB
6097 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6098 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6099 u16 reason;
6100
6101 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6102 reason = WLAN_REASON_DEAUTH_LEAVING;
6103 else
6104 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6105
6106 if (reason == 0)
6107 return -EINVAL;
6108
074ac8df 6109 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6110 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6111 return -EOPNOTSUPP;
b23aa676 6112
4c476991 6113 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
6114}
6115
463d0183
JB
6116static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
6117{
4c476991 6118 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
6119 struct net *net;
6120 int err;
6121 u32 pid;
6122
6123 if (!info->attrs[NL80211_ATTR_PID])
6124 return -EINVAL;
6125
6126 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
6127
463d0183 6128 net = get_net_ns_by_pid(pid);
4c476991
JB
6129 if (IS_ERR(net))
6130 return PTR_ERR(net);
463d0183
JB
6131
6132 err = 0;
6133
6134 /* check if anything to do */
4c476991
JB
6135 if (!net_eq(wiphy_net(&rdev->wiphy), net))
6136 err = cfg80211_switch_netns(rdev, net);
463d0183 6137
463d0183 6138 put_net(net);
463d0183
JB
6139 return err;
6140}
6141
67fbb16b
SO
6142static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
6143{
4c476991 6144 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
6145 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
6146 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 6147 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
6148 struct cfg80211_pmksa pmksa;
6149
6150 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
6151
6152 if (!info->attrs[NL80211_ATTR_MAC])
6153 return -EINVAL;
6154
6155 if (!info->attrs[NL80211_ATTR_PMKID])
6156 return -EINVAL;
6157
67fbb16b
SO
6158 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
6159 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6160
074ac8df 6161 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6162 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6163 return -EOPNOTSUPP;
67fbb16b
SO
6164
6165 switch (info->genlhdr->cmd) {
6166 case NL80211_CMD_SET_PMKSA:
6167 rdev_ops = rdev->ops->set_pmksa;
6168 break;
6169 case NL80211_CMD_DEL_PMKSA:
6170 rdev_ops = rdev->ops->del_pmksa;
6171 break;
6172 default:
6173 WARN_ON(1);
6174 break;
6175 }
6176
4c476991
JB
6177 if (!rdev_ops)
6178 return -EOPNOTSUPP;
67fbb16b 6179
4c476991 6180 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
6181}
6182
6183static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
6184{
4c476991
JB
6185 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6186 struct net_device *dev = info->user_ptr[1];
67fbb16b 6187
074ac8df 6188 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6189 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6190 return -EOPNOTSUPP;
67fbb16b 6191
4c476991
JB
6192 if (!rdev->ops->flush_pmksa)
6193 return -EOPNOTSUPP;
67fbb16b 6194
e35e4d28 6195 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
6196}
6197
109086ce
AN
6198static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
6199{
6200 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6201 struct net_device *dev = info->user_ptr[1];
6202 u8 action_code, dialog_token;
6203 u16 status_code;
6204 u8 *peer;
6205
6206 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6207 !rdev->ops->tdls_mgmt)
6208 return -EOPNOTSUPP;
6209
6210 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
6211 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
6212 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
6213 !info->attrs[NL80211_ATTR_IE] ||
6214 !info->attrs[NL80211_ATTR_MAC])
6215 return -EINVAL;
6216
6217 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6218 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
6219 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
6220 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
6221
e35e4d28
HG
6222 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
6223 dialog_token, status_code,
6224 nla_data(info->attrs[NL80211_ATTR_IE]),
6225 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
6226}
6227
6228static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
6229{
6230 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6231 struct net_device *dev = info->user_ptr[1];
6232 enum nl80211_tdls_operation operation;
6233 u8 *peer;
6234
6235 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6236 !rdev->ops->tdls_oper)
6237 return -EOPNOTSUPP;
6238
6239 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
6240 !info->attrs[NL80211_ATTR_MAC])
6241 return -EINVAL;
6242
6243 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
6244 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6245
e35e4d28 6246 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
6247}
6248
9588bbd5
JM
6249static int nl80211_remain_on_channel(struct sk_buff *skb,
6250 struct genl_info *info)
6251{
4c476991 6252 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6253 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6254 struct cfg80211_chan_def chandef;
9588bbd5
JM
6255 struct sk_buff *msg;
6256 void *hdr;
6257 u64 cookie;
683b6d3b 6258 u32 duration;
9588bbd5
JM
6259 int err;
6260
6261 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6262 !info->attrs[NL80211_ATTR_DURATION])
6263 return -EINVAL;
6264
6265 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
6266
ebf348fc
JB
6267 if (!rdev->ops->remain_on_channel ||
6268 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
6269 return -EOPNOTSUPP;
6270
9588bbd5 6271 /*
ebf348fc
JB
6272 * We should be on that channel for at least a minimum amount of
6273 * time (10ms) but no longer than the driver supports.
9588bbd5 6274 */
ebf348fc 6275 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 6276 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
6277 return -EINVAL;
6278
683b6d3b
JB
6279 err = nl80211_parse_chandef(rdev, info, &chandef);
6280 if (err)
6281 return err;
9588bbd5
JM
6282
6283 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6284 if (!msg)
6285 return -ENOMEM;
9588bbd5 6286
15e47304 6287 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5
JM
6288 NL80211_CMD_REMAIN_ON_CHANNEL);
6289
6290 if (IS_ERR(hdr)) {
6291 err = PTR_ERR(hdr);
6292 goto free_msg;
6293 }
6294
683b6d3b
JB
6295 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
6296 duration, &cookie);
9588bbd5
JM
6297
6298 if (err)
6299 goto free_msg;
6300
9360ffd1
DM
6301 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6302 goto nla_put_failure;
9588bbd5
JM
6303
6304 genlmsg_end(msg, hdr);
4c476991
JB
6305
6306 return genlmsg_reply(msg, info);
9588bbd5
JM
6307
6308 nla_put_failure:
6309 err = -ENOBUFS;
6310 free_msg:
6311 nlmsg_free(msg);
9588bbd5
JM
6312 return err;
6313}
6314
6315static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
6316 struct genl_info *info)
6317{
4c476991 6318 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6319 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 6320 u64 cookie;
9588bbd5
JM
6321
6322 if (!info->attrs[NL80211_ATTR_COOKIE])
6323 return -EINVAL;
6324
4c476991
JB
6325 if (!rdev->ops->cancel_remain_on_channel)
6326 return -EOPNOTSUPP;
9588bbd5 6327
9588bbd5
JM
6328 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6329
e35e4d28 6330 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
6331}
6332
13ae75b1
JM
6333static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
6334 u8 *rates, u8 rates_len)
6335{
6336 u8 i;
6337 u32 mask = 0;
6338
6339 for (i = 0; i < rates_len; i++) {
6340 int rate = (rates[i] & 0x7f) * 5;
6341 int ridx;
6342 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
6343 struct ieee80211_rate *srate =
6344 &sband->bitrates[ridx];
6345 if (rate == srate->bitrate) {
6346 mask |= 1 << ridx;
6347 break;
6348 }
6349 }
6350 if (ridx == sband->n_bitrates)
6351 return 0; /* rate not found */
6352 }
6353
6354 return mask;
6355}
6356
24db78c0
SW
6357static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
6358 u8 *rates, u8 rates_len,
6359 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
6360{
6361 u8 i;
6362
6363 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
6364
6365 for (i = 0; i < rates_len; i++) {
6366 int ridx, rbit;
6367
6368 ridx = rates[i] / 8;
6369 rbit = BIT(rates[i] % 8);
6370
6371 /* check validity */
910570b5 6372 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
6373 return false;
6374
6375 /* check availability */
6376 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
6377 mcs[ridx] |= rbit;
6378 else
6379 return false;
6380 }
6381
6382 return true;
6383}
6384
b54452b0 6385static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
6386 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
6387 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
6388 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
6389 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
6390};
6391
6392static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
6393 struct genl_info *info)
6394{
6395 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 6396 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 6397 struct cfg80211_bitrate_mask mask;
4c476991
JB
6398 int rem, i;
6399 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
6400 struct nlattr *tx_rates;
6401 struct ieee80211_supported_band *sband;
6402
6403 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
6404 return -EINVAL;
6405
4c476991
JB
6406 if (!rdev->ops->set_bitrate_mask)
6407 return -EOPNOTSUPP;
13ae75b1
JM
6408
6409 memset(&mask, 0, sizeof(mask));
6410 /* Default to all rates enabled */
6411 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
6412 sband = rdev->wiphy.bands[i];
6413 mask.control[i].legacy =
6414 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
6415 if (sband)
6416 memcpy(mask.control[i].mcs,
6417 sband->ht_cap.mcs.rx_mask,
6418 sizeof(mask.control[i].mcs));
6419 else
6420 memset(mask.control[i].mcs, 0,
6421 sizeof(mask.control[i].mcs));
13ae75b1
JM
6422 }
6423
6424 /*
6425 * The nested attribute uses enum nl80211_band as the index. This maps
6426 * directly to the enum ieee80211_band values used in cfg80211.
6427 */
24db78c0 6428 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
6429 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
6430 {
6431 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
6432 if (band < 0 || band >= IEEE80211_NUM_BANDS)
6433 return -EINVAL;
13ae75b1 6434 sband = rdev->wiphy.bands[band];
4c476991
JB
6435 if (sband == NULL)
6436 return -EINVAL;
13ae75b1
JM
6437 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
6438 nla_len(tx_rates), nl80211_txattr_policy);
6439 if (tb[NL80211_TXRATE_LEGACY]) {
6440 mask.control[band].legacy = rateset_to_mask(
6441 sband,
6442 nla_data(tb[NL80211_TXRATE_LEGACY]),
6443 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
6444 if ((mask.control[band].legacy == 0) &&
6445 nla_len(tb[NL80211_TXRATE_LEGACY]))
6446 return -EINVAL;
24db78c0
SW
6447 }
6448 if (tb[NL80211_TXRATE_MCS]) {
6449 if (!ht_rateset_to_mask(
6450 sband,
6451 nla_data(tb[NL80211_TXRATE_MCS]),
6452 nla_len(tb[NL80211_TXRATE_MCS]),
6453 mask.control[band].mcs))
6454 return -EINVAL;
6455 }
6456
6457 if (mask.control[band].legacy == 0) {
6458 /* don't allow empty legacy rates if HT
6459 * is not even supported. */
6460 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
6461 return -EINVAL;
6462
6463 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
6464 if (mask.control[band].mcs[i])
6465 break;
6466
6467 /* legacy and mcs rates may not be both empty */
6468 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 6469 return -EINVAL;
13ae75b1
JM
6470 }
6471 }
6472
e35e4d28 6473 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
6474}
6475
2e161f78 6476static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6477{
4c476991 6478 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6479 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 6480 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
6481
6482 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
6483 return -EINVAL;
6484
2e161f78
JB
6485 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
6486 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 6487
71bbc994
JB
6488 switch (wdev->iftype) {
6489 case NL80211_IFTYPE_STATION:
6490 case NL80211_IFTYPE_ADHOC:
6491 case NL80211_IFTYPE_P2P_CLIENT:
6492 case NL80211_IFTYPE_AP:
6493 case NL80211_IFTYPE_AP_VLAN:
6494 case NL80211_IFTYPE_MESH_POINT:
6495 case NL80211_IFTYPE_P2P_GO:
98104fde 6496 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6497 break;
6498 default:
4c476991 6499 return -EOPNOTSUPP;
71bbc994 6500 }
026331c4
JM
6501
6502 /* not much point in registering if we can't reply */
4c476991
JB
6503 if (!rdev->ops->mgmt_tx)
6504 return -EOPNOTSUPP;
026331c4 6505
15e47304 6506 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
6507 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
6508 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
6509}
6510
2e161f78 6511static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6512{
4c476991 6513 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6514 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6515 struct cfg80211_chan_def chandef;
026331c4 6516 int err;
d64d373f 6517 void *hdr = NULL;
026331c4 6518 u64 cookie;
e247bd90 6519 struct sk_buff *msg = NULL;
f7ca38df 6520 unsigned int wait = 0;
e247bd90
JB
6521 bool offchan, no_cck, dont_wait_for_ack;
6522
6523 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 6524
683b6d3b 6525 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
6526 return -EINVAL;
6527
4c476991
JB
6528 if (!rdev->ops->mgmt_tx)
6529 return -EOPNOTSUPP;
026331c4 6530
71bbc994
JB
6531 switch (wdev->iftype) {
6532 case NL80211_IFTYPE_STATION:
6533 case NL80211_IFTYPE_ADHOC:
6534 case NL80211_IFTYPE_P2P_CLIENT:
6535 case NL80211_IFTYPE_AP:
6536 case NL80211_IFTYPE_AP_VLAN:
6537 case NL80211_IFTYPE_MESH_POINT:
6538 case NL80211_IFTYPE_P2P_GO:
98104fde 6539 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6540 break;
6541 default:
4c476991 6542 return -EOPNOTSUPP;
71bbc994 6543 }
026331c4 6544
f7ca38df 6545 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 6546 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
6547 return -EINVAL;
6548 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
6549
6550 /*
6551 * We should wait on the channel for at least a minimum amount
6552 * of time (10ms) but no longer than the driver supports.
6553 */
6554 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
6555 wait > rdev->wiphy.max_remain_on_channel_duration)
6556 return -EINVAL;
6557
f7ca38df
JB
6558 }
6559
f7ca38df
JB
6560 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
6561
7c4ef712
JB
6562 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
6563 return -EINVAL;
6564
e9f935e3
RM
6565 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6566
683b6d3b
JB
6567 err = nl80211_parse_chandef(rdev, info, &chandef);
6568 if (err)
6569 return err;
026331c4 6570
e247bd90
JB
6571 if (!dont_wait_for_ack) {
6572 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6573 if (!msg)
6574 return -ENOMEM;
026331c4 6575
15e47304 6576 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 6577 NL80211_CMD_FRAME);
026331c4 6578
e247bd90
JB
6579 if (IS_ERR(hdr)) {
6580 err = PTR_ERR(hdr);
6581 goto free_msg;
6582 }
026331c4 6583 }
e247bd90 6584
683b6d3b 6585 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
6586 nla_data(info->attrs[NL80211_ATTR_FRAME]),
6587 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 6588 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
6589 if (err)
6590 goto free_msg;
6591
e247bd90 6592 if (msg) {
9360ffd1
DM
6593 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6594 goto nla_put_failure;
026331c4 6595
e247bd90
JB
6596 genlmsg_end(msg, hdr);
6597 return genlmsg_reply(msg, info);
6598 }
6599
6600 return 0;
026331c4
JM
6601
6602 nla_put_failure:
6603 err = -ENOBUFS;
6604 free_msg:
6605 nlmsg_free(msg);
026331c4
JM
6606 return err;
6607}
6608
f7ca38df
JB
6609static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
6610{
6611 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6612 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
6613 u64 cookie;
6614
6615 if (!info->attrs[NL80211_ATTR_COOKIE])
6616 return -EINVAL;
6617
6618 if (!rdev->ops->mgmt_tx_cancel_wait)
6619 return -EOPNOTSUPP;
6620
71bbc994
JB
6621 switch (wdev->iftype) {
6622 case NL80211_IFTYPE_STATION:
6623 case NL80211_IFTYPE_ADHOC:
6624 case NL80211_IFTYPE_P2P_CLIENT:
6625 case NL80211_IFTYPE_AP:
6626 case NL80211_IFTYPE_AP_VLAN:
6627 case NL80211_IFTYPE_P2P_GO:
98104fde 6628 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6629 break;
6630 default:
f7ca38df 6631 return -EOPNOTSUPP;
71bbc994 6632 }
f7ca38df
JB
6633
6634 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6635
e35e4d28 6636 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
6637}
6638
ffb9eb3d
KV
6639static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
6640{
4c476991 6641 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 6642 struct wireless_dev *wdev;
4c476991 6643 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6644 u8 ps_state;
6645 bool state;
6646 int err;
6647
4c476991
JB
6648 if (!info->attrs[NL80211_ATTR_PS_STATE])
6649 return -EINVAL;
ffb9eb3d
KV
6650
6651 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
6652
4c476991
JB
6653 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
6654 return -EINVAL;
ffb9eb3d
KV
6655
6656 wdev = dev->ieee80211_ptr;
6657
4c476991
JB
6658 if (!rdev->ops->set_power_mgmt)
6659 return -EOPNOTSUPP;
ffb9eb3d
KV
6660
6661 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
6662
6663 if (state == wdev->ps)
4c476991 6664 return 0;
ffb9eb3d 6665
e35e4d28 6666 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
6667 if (!err)
6668 wdev->ps = state;
ffb9eb3d
KV
6669 return err;
6670}
6671
6672static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
6673{
4c476991 6674 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
6675 enum nl80211_ps_state ps_state;
6676 struct wireless_dev *wdev;
4c476991 6677 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6678 struct sk_buff *msg;
6679 void *hdr;
6680 int err;
6681
ffb9eb3d
KV
6682 wdev = dev->ieee80211_ptr;
6683
4c476991
JB
6684 if (!rdev->ops->set_power_mgmt)
6685 return -EOPNOTSUPP;
ffb9eb3d
KV
6686
6687 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6688 if (!msg)
6689 return -ENOMEM;
ffb9eb3d 6690
15e47304 6691 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
6692 NL80211_CMD_GET_POWER_SAVE);
6693 if (!hdr) {
4c476991 6694 err = -ENOBUFS;
ffb9eb3d
KV
6695 goto free_msg;
6696 }
6697
6698 if (wdev->ps)
6699 ps_state = NL80211_PS_ENABLED;
6700 else
6701 ps_state = NL80211_PS_DISABLED;
6702
9360ffd1
DM
6703 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6704 goto nla_put_failure;
ffb9eb3d
KV
6705
6706 genlmsg_end(msg, hdr);
4c476991 6707 return genlmsg_reply(msg, info);
ffb9eb3d 6708
4c476991 6709 nla_put_failure:
ffb9eb3d 6710 err = -ENOBUFS;
4c476991 6711 free_msg:
ffb9eb3d 6712 nlmsg_free(msg);
ffb9eb3d
KV
6713 return err;
6714}
6715
d6dc1a38
JO
6716static struct nla_policy
6717nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6718 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6719 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6720 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
6721 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
6722 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
6723 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
6724};
6725
84f10708 6726static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 6727 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
6728{
6729 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6730 struct wireless_dev *wdev;
6731 struct net_device *dev = info->user_ptr[1];
6732
d9d8b019 6733 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
6734 return -EINVAL;
6735
6736 wdev = dev->ieee80211_ptr;
6737
6738 if (!rdev->ops->set_cqm_txe_config)
6739 return -EOPNOTSUPP;
6740
6741 if (wdev->iftype != NL80211_IFTYPE_STATION &&
6742 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6743 return -EOPNOTSUPP;
6744
e35e4d28 6745 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
6746}
6747
d6dc1a38
JO
6748static int nl80211_set_cqm_rssi(struct genl_info *info,
6749 s32 threshold, u32 hysteresis)
6750{
4c476991 6751 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6752 struct wireless_dev *wdev;
4c476991 6753 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6754
6755 if (threshold > 0)
6756 return -EINVAL;
6757
d6dc1a38
JO
6758 wdev = dev->ieee80211_ptr;
6759
4c476991
JB
6760 if (!rdev->ops->set_cqm_rssi_config)
6761 return -EOPNOTSUPP;
d6dc1a38 6762
074ac8df 6763 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6764 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6765 return -EOPNOTSUPP;
d6dc1a38 6766
e35e4d28 6767 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
6768}
6769
6770static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6771{
6772 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6773 struct nlattr *cqm;
6774 int err;
6775
6776 cqm = info->attrs[NL80211_ATTR_CQM];
6777 if (!cqm) {
6778 err = -EINVAL;
6779 goto out;
6780 }
6781
6782 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6783 nl80211_attr_cqm_policy);
6784 if (err)
6785 goto out;
6786
6787 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6788 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6789 s32 threshold;
6790 u32 hysteresis;
6791 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6792 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6793 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
84f10708
TP
6794 } else if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
6795 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
6796 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
6797 u32 rate, pkts, intvl;
6798 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
6799 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
6800 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
6801 err = nl80211_set_cqm_txe(info, rate, pkts, intvl);
d6dc1a38
JO
6802 } else
6803 err = -EINVAL;
6804
6805out:
6806 return err;
6807}
6808
29cbe68c
JB
6809static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6810{
6811 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6812 struct net_device *dev = info->user_ptr[1];
6813 struct mesh_config cfg;
c80d545d 6814 struct mesh_setup setup;
29cbe68c
JB
6815 int err;
6816
6817 /* start with default */
6818 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6819 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6820
24bdd9f4 6821 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6822 /* and parse parameters if given */
24bdd9f4 6823 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6824 if (err)
6825 return err;
6826 }
6827
6828 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6829 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6830 return -EINVAL;
6831
c80d545d
JC
6832 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6833 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6834
4bb62344
CYY
6835 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6836 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6837 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6838 return -EINVAL;
6839
9bdbf04d
MP
6840 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6841 setup.beacon_interval =
6842 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6843 if (setup.beacon_interval < 10 ||
6844 setup.beacon_interval > 10000)
6845 return -EINVAL;
6846 }
6847
6848 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
6849 setup.dtim_period =
6850 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
6851 if (setup.dtim_period < 1 || setup.dtim_period > 100)
6852 return -EINVAL;
6853 }
6854
c80d545d
JC
6855 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6856 /* parse additional setup parameters if given */
6857 err = nl80211_parse_mesh_setup(info, &setup);
6858 if (err)
6859 return err;
6860 }
6861
cc1d2806 6862 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
6863 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
6864 if (err)
6865 return err;
cc1d2806
JB
6866 } else {
6867 /* cfg80211_join_mesh() will sort it out */
683b6d3b 6868 setup.chandef.chan = NULL;
cc1d2806
JB
6869 }
6870
c80d545d 6871 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6872}
6873
6874static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6875{
6876 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6877 struct net_device *dev = info->user_ptr[1];
6878
6879 return cfg80211_leave_mesh(rdev, dev);
6880}
6881
dfb89c56 6882#ifdef CONFIG_PM
ff1b6e69
JB
6883static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6884{
6885 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6886 struct sk_buff *msg;
6887 void *hdr;
6888
6889 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6890 return -EOPNOTSUPP;
6891
6892 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6893 if (!msg)
6894 return -ENOMEM;
6895
15e47304 6896 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
6897 NL80211_CMD_GET_WOWLAN);
6898 if (!hdr)
6899 goto nla_put_failure;
6900
6901 if (rdev->wowlan) {
6902 struct nlattr *nl_wowlan;
6903
6904 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6905 if (!nl_wowlan)
6906 goto nla_put_failure;
6907
9360ffd1
DM
6908 if ((rdev->wowlan->any &&
6909 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6910 (rdev->wowlan->disconnect &&
6911 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6912 (rdev->wowlan->magic_pkt &&
6913 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6914 (rdev->wowlan->gtk_rekey_failure &&
6915 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6916 (rdev->wowlan->eap_identity_req &&
6917 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6918 (rdev->wowlan->four_way_handshake &&
6919 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6920 (rdev->wowlan->rfkill_release &&
6921 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6922 goto nla_put_failure;
ff1b6e69
JB
6923 if (rdev->wowlan->n_patterns) {
6924 struct nlattr *nl_pats, *nl_pat;
6925 int i, pat_len;
6926
6927 nl_pats = nla_nest_start(msg,
6928 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6929 if (!nl_pats)
6930 goto nla_put_failure;
6931
6932 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6933 nl_pat = nla_nest_start(msg, i + 1);
6934 if (!nl_pat)
6935 goto nla_put_failure;
6936 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6937 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6938 DIV_ROUND_UP(pat_len, 8),
6939 rdev->wowlan->patterns[i].mask) ||
6940 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6941 pat_len,
6942 rdev->wowlan->patterns[i].pattern))
6943 goto nla_put_failure;
ff1b6e69
JB
6944 nla_nest_end(msg, nl_pat);
6945 }
6946 nla_nest_end(msg, nl_pats);
6947 }
6948
6949 nla_nest_end(msg, nl_wowlan);
6950 }
6951
6952 genlmsg_end(msg, hdr);
6953 return genlmsg_reply(msg, info);
6954
6955nla_put_failure:
6956 nlmsg_free(msg);
6957 return -ENOBUFS;
6958}
6959
6960static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6961{
6962 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6963 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 6964 struct cfg80211_wowlan new_triggers = {};
ae33bd81 6965 struct cfg80211_wowlan *ntrig;
ff1b6e69
JB
6966 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6967 int err, i;
6d52563f 6968 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6969
6970 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6971 return -EOPNOTSUPP;
6972
ae33bd81
JB
6973 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
6974 cfg80211_rdev_free_wowlan(rdev);
6975 rdev->wowlan = NULL;
6976 goto set_wakeup;
6977 }
ff1b6e69
JB
6978
6979 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6980 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6981 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6982 nl80211_wowlan_policy);
6983 if (err)
6984 return err;
6985
6986 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6987 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6988 return -EINVAL;
6989 new_triggers.any = true;
6990 }
6991
6992 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6993 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6994 return -EINVAL;
6995 new_triggers.disconnect = true;
6996 }
6997
6998 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6999 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
7000 return -EINVAL;
7001 new_triggers.magic_pkt = true;
7002 }
7003
77dbbb13
JB
7004 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
7005 return -EINVAL;
7006
7007 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
7008 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
7009 return -EINVAL;
7010 new_triggers.gtk_rekey_failure = true;
7011 }
7012
7013 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
7014 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
7015 return -EINVAL;
7016 new_triggers.eap_identity_req = true;
7017 }
7018
7019 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
7020 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
7021 return -EINVAL;
7022 new_triggers.four_way_handshake = true;
7023 }
7024
7025 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
7026 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
7027 return -EINVAL;
7028 new_triggers.rfkill_release = true;
7029 }
7030
ff1b6e69
JB
7031 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
7032 struct nlattr *pat;
7033 int n_patterns = 0;
7034 int rem, pat_len, mask_len;
7035 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
7036
7037 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7038 rem)
7039 n_patterns++;
7040 if (n_patterns > wowlan->n_patterns)
7041 return -EINVAL;
7042
7043 new_triggers.patterns = kcalloc(n_patterns,
7044 sizeof(new_triggers.patterns[0]),
7045 GFP_KERNEL);
7046 if (!new_triggers.patterns)
7047 return -ENOMEM;
7048
7049 new_triggers.n_patterns = n_patterns;
7050 i = 0;
7051
7052 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7053 rem) {
7054 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
7055 nla_data(pat), nla_len(pat), NULL);
7056 err = -EINVAL;
7057 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
7058 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
7059 goto error;
7060 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
7061 mask_len = DIV_ROUND_UP(pat_len, 8);
7062 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
7063 mask_len)
7064 goto error;
7065 if (pat_len > wowlan->pattern_max_len ||
7066 pat_len < wowlan->pattern_min_len)
7067 goto error;
7068
7069 new_triggers.patterns[i].mask =
7070 kmalloc(mask_len + pat_len, GFP_KERNEL);
7071 if (!new_triggers.patterns[i].mask) {
7072 err = -ENOMEM;
7073 goto error;
7074 }
7075 new_triggers.patterns[i].pattern =
7076 new_triggers.patterns[i].mask + mask_len;
7077 memcpy(new_triggers.patterns[i].mask,
7078 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
7079 mask_len);
7080 new_triggers.patterns[i].pattern_len = pat_len;
7081 memcpy(new_triggers.patterns[i].pattern,
7082 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
7083 pat_len);
7084 i++;
7085 }
7086 }
7087
ae33bd81
JB
7088 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
7089 if (!ntrig) {
7090 err = -ENOMEM;
7091 goto error;
ff1b6e69 7092 }
ae33bd81
JB
7093 cfg80211_rdev_free_wowlan(rdev);
7094 rdev->wowlan = ntrig;
ff1b6e69 7095
ae33bd81 7096 set_wakeup:
6d52563f 7097 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
e35e4d28 7098 rdev_set_wakeup(rdev, rdev->wowlan);
6d52563f 7099
ff1b6e69
JB
7100 return 0;
7101 error:
7102 for (i = 0; i < new_triggers.n_patterns; i++)
7103 kfree(new_triggers.patterns[i].mask);
7104 kfree(new_triggers.patterns);
7105 return err;
7106}
dfb89c56 7107#endif
ff1b6e69 7108
e5497d76
JB
7109static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
7110{
7111 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7112 struct net_device *dev = info->user_ptr[1];
7113 struct wireless_dev *wdev = dev->ieee80211_ptr;
7114 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
7115 struct cfg80211_gtk_rekey_data rekey_data;
7116 int err;
7117
7118 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
7119 return -EINVAL;
7120
7121 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
7122 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
7123 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
7124 nl80211_rekey_policy);
7125 if (err)
7126 return err;
7127
7128 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
7129 return -ERANGE;
7130 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
7131 return -ERANGE;
7132 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
7133 return -ERANGE;
7134
7135 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
7136 NL80211_KEK_LEN);
7137 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
7138 NL80211_KCK_LEN);
7139 memcpy(rekey_data.replay_ctr,
7140 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
7141 NL80211_REPLAY_CTR_LEN);
7142
7143 wdev_lock(wdev);
7144 if (!wdev->current_bss) {
7145 err = -ENOTCONN;
7146 goto out;
7147 }
7148
7149 if (!rdev->ops->set_rekey_data) {
7150 err = -EOPNOTSUPP;
7151 goto out;
7152 }
7153
e35e4d28 7154 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
7155 out:
7156 wdev_unlock(wdev);
7157 return err;
7158}
7159
28946da7
JB
7160static int nl80211_register_unexpected_frame(struct sk_buff *skb,
7161 struct genl_info *info)
7162{
7163 struct net_device *dev = info->user_ptr[1];
7164 struct wireless_dev *wdev = dev->ieee80211_ptr;
7165
7166 if (wdev->iftype != NL80211_IFTYPE_AP &&
7167 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7168 return -EINVAL;
7169
15e47304 7170 if (wdev->ap_unexpected_nlportid)
28946da7
JB
7171 return -EBUSY;
7172
15e47304 7173 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
7174 return 0;
7175}
7176
7f6cf311
JB
7177static int nl80211_probe_client(struct sk_buff *skb,
7178 struct genl_info *info)
7179{
7180 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7181 struct net_device *dev = info->user_ptr[1];
7182 struct wireless_dev *wdev = dev->ieee80211_ptr;
7183 struct sk_buff *msg;
7184 void *hdr;
7185 const u8 *addr;
7186 u64 cookie;
7187 int err;
7188
7189 if (wdev->iftype != NL80211_IFTYPE_AP &&
7190 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7191 return -EOPNOTSUPP;
7192
7193 if (!info->attrs[NL80211_ATTR_MAC])
7194 return -EINVAL;
7195
7196 if (!rdev->ops->probe_client)
7197 return -EOPNOTSUPP;
7198
7199 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7200 if (!msg)
7201 return -ENOMEM;
7202
15e47304 7203 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311
JB
7204 NL80211_CMD_PROBE_CLIENT);
7205
7206 if (IS_ERR(hdr)) {
7207 err = PTR_ERR(hdr);
7208 goto free_msg;
7209 }
7210
7211 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7212
e35e4d28 7213 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
7214 if (err)
7215 goto free_msg;
7216
9360ffd1
DM
7217 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7218 goto nla_put_failure;
7f6cf311
JB
7219
7220 genlmsg_end(msg, hdr);
7221
7222 return genlmsg_reply(msg, info);
7223
7224 nla_put_failure:
7225 err = -ENOBUFS;
7226 free_msg:
7227 nlmsg_free(msg);
7228 return err;
7229}
7230
5e760230
JB
7231static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
7232{
7233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
7234 struct cfg80211_beacon_registration *reg, *nreg;
7235 int rv;
5e760230
JB
7236
7237 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
7238 return -EOPNOTSUPP;
7239
37c73b5f
BG
7240 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
7241 if (!nreg)
7242 return -ENOMEM;
7243
7244 /* First, check if already registered. */
7245 spin_lock_bh(&rdev->beacon_registrations_lock);
7246 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
7247 if (reg->nlportid == info->snd_portid) {
7248 rv = -EALREADY;
7249 goto out_err;
7250 }
7251 }
7252 /* Add it to the list */
7253 nreg->nlportid = info->snd_portid;
7254 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 7255
37c73b5f 7256 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
7257
7258 return 0;
37c73b5f
BG
7259out_err:
7260 spin_unlock_bh(&rdev->beacon_registrations_lock);
7261 kfree(nreg);
7262 return rv;
5e760230
JB
7263}
7264
98104fde
JB
7265static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
7266{
7267 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7268 struct wireless_dev *wdev = info->user_ptr[1];
7269 int err;
7270
7271 if (!rdev->ops->start_p2p_device)
7272 return -EOPNOTSUPP;
7273
7274 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7275 return -EOPNOTSUPP;
7276
7277 if (wdev->p2p_started)
7278 return 0;
7279
7280 mutex_lock(&rdev->devlist_mtx);
7281 err = cfg80211_can_add_interface(rdev, wdev->iftype);
7282 mutex_unlock(&rdev->devlist_mtx);
7283 if (err)
7284 return err;
7285
eeb126e9 7286 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
7287 if (err)
7288 return err;
7289
7290 wdev->p2p_started = true;
7291 mutex_lock(&rdev->devlist_mtx);
7292 rdev->opencount++;
7293 mutex_unlock(&rdev->devlist_mtx);
7294
7295 return 0;
7296}
7297
7298static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
7299{
7300 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7301 struct wireless_dev *wdev = info->user_ptr[1];
7302
7303 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7304 return -EOPNOTSUPP;
7305
7306 if (!rdev->ops->stop_p2p_device)
7307 return -EOPNOTSUPP;
7308
7309 if (!wdev->p2p_started)
7310 return 0;
7311
eeb126e9 7312 rdev_stop_p2p_device(rdev, wdev);
98104fde
JB
7313 wdev->p2p_started = false;
7314
7315 mutex_lock(&rdev->devlist_mtx);
7316 rdev->opencount--;
7317 mutex_unlock(&rdev->devlist_mtx);
7318
7319 if (WARN_ON(rdev->scan_req && rdev->scan_req->wdev == wdev)) {
7320 rdev->scan_req->aborted = true;
7321 ___cfg80211_scan_done(rdev, true);
7322 }
7323
7324 return 0;
7325}
7326
4c476991
JB
7327#define NL80211_FLAG_NEED_WIPHY 0x01
7328#define NL80211_FLAG_NEED_NETDEV 0x02
7329#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
7330#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
7331#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
7332 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 7333#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 7334/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
7335#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
7336 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
7337
7338static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
7339 struct genl_info *info)
7340{
7341 struct cfg80211_registered_device *rdev;
89a54e48 7342 struct wireless_dev *wdev;
4c476991 7343 struct net_device *dev;
4c476991
JB
7344 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
7345
7346 if (rtnl)
7347 rtnl_lock();
7348
7349 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 7350 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
7351 if (IS_ERR(rdev)) {
7352 if (rtnl)
7353 rtnl_unlock();
7354 return PTR_ERR(rdev);
7355 }
7356 info->user_ptr[0] = rdev;
1bf614ef
JB
7357 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
7358 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
89a54e48
JB
7359 mutex_lock(&cfg80211_mutex);
7360 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
7361 info->attrs);
7362 if (IS_ERR(wdev)) {
7363 mutex_unlock(&cfg80211_mutex);
4c476991
JB
7364 if (rtnl)
7365 rtnl_unlock();
89a54e48 7366 return PTR_ERR(wdev);
4c476991 7367 }
89a54e48 7368
89a54e48
JB
7369 dev = wdev->netdev;
7370 rdev = wiphy_to_dev(wdev->wiphy);
7371
1bf614ef
JB
7372 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
7373 if (!dev) {
7374 mutex_unlock(&cfg80211_mutex);
7375 if (rtnl)
7376 rtnl_unlock();
7377 return -EINVAL;
7378 }
7379
7380 info->user_ptr[1] = dev;
7381 } else {
7382 info->user_ptr[1] = wdev;
41265714 7383 }
1bf614ef
JB
7384
7385 if (dev) {
7386 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
7387 !netif_running(dev)) {
7388 mutex_unlock(&cfg80211_mutex);
7389 if (rtnl)
7390 rtnl_unlock();
7391 return -ENETDOWN;
7392 }
7393
7394 dev_hold(dev);
98104fde
JB
7395 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
7396 if (!wdev->p2p_started) {
7397 mutex_unlock(&cfg80211_mutex);
7398 if (rtnl)
7399 rtnl_unlock();
7400 return -ENETDOWN;
7401 }
41265714 7402 }
89a54e48 7403
89a54e48
JB
7404 cfg80211_lock_rdev(rdev);
7405
7406 mutex_unlock(&cfg80211_mutex);
7407
4c476991 7408 info->user_ptr[0] = rdev;
4c476991
JB
7409 }
7410
7411 return 0;
7412}
7413
7414static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
7415 struct genl_info *info)
7416{
7417 if (info->user_ptr[0])
7418 cfg80211_unlock_rdev(info->user_ptr[0]);
1bf614ef
JB
7419 if (info->user_ptr[1]) {
7420 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
7421 struct wireless_dev *wdev = info->user_ptr[1];
7422
7423 if (wdev->netdev)
7424 dev_put(wdev->netdev);
7425 } else {
7426 dev_put(info->user_ptr[1]);
7427 }
7428 }
4c476991
JB
7429 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
7430 rtnl_unlock();
7431}
7432
55682965
JB
7433static struct genl_ops nl80211_ops[] = {
7434 {
7435 .cmd = NL80211_CMD_GET_WIPHY,
7436 .doit = nl80211_get_wiphy,
7437 .dumpit = nl80211_dump_wiphy,
7438 .policy = nl80211_policy,
7439 /* can be retrieved by unprivileged users */
4c476991 7440 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
7441 },
7442 {
7443 .cmd = NL80211_CMD_SET_WIPHY,
7444 .doit = nl80211_set_wiphy,
7445 .policy = nl80211_policy,
7446 .flags = GENL_ADMIN_PERM,
4c476991 7447 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
7448 },
7449 {
7450 .cmd = NL80211_CMD_GET_INTERFACE,
7451 .doit = nl80211_get_interface,
7452 .dumpit = nl80211_dump_interface,
7453 .policy = nl80211_policy,
7454 /* can be retrieved by unprivileged users */
72fb2abc 7455 .internal_flags = NL80211_FLAG_NEED_WDEV,
55682965
JB
7456 },
7457 {
7458 .cmd = NL80211_CMD_SET_INTERFACE,
7459 .doit = nl80211_set_interface,
7460 .policy = nl80211_policy,
7461 .flags = GENL_ADMIN_PERM,
4c476991
JB
7462 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7463 NL80211_FLAG_NEED_RTNL,
55682965
JB
7464 },
7465 {
7466 .cmd = NL80211_CMD_NEW_INTERFACE,
7467 .doit = nl80211_new_interface,
7468 .policy = nl80211_policy,
7469 .flags = GENL_ADMIN_PERM,
4c476991
JB
7470 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7471 NL80211_FLAG_NEED_RTNL,
55682965
JB
7472 },
7473 {
7474 .cmd = NL80211_CMD_DEL_INTERFACE,
7475 .doit = nl80211_del_interface,
7476 .policy = nl80211_policy,
41ade00f 7477 .flags = GENL_ADMIN_PERM,
84efbb84 7478 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7479 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7480 },
7481 {
7482 .cmd = NL80211_CMD_GET_KEY,
7483 .doit = nl80211_get_key,
7484 .policy = nl80211_policy,
7485 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7486 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7487 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7488 },
7489 {
7490 .cmd = NL80211_CMD_SET_KEY,
7491 .doit = nl80211_set_key,
7492 .policy = nl80211_policy,
7493 .flags = GENL_ADMIN_PERM,
41265714 7494 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7495 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7496 },
7497 {
7498 .cmd = NL80211_CMD_NEW_KEY,
7499 .doit = nl80211_new_key,
7500 .policy = nl80211_policy,
7501 .flags = GENL_ADMIN_PERM,
41265714 7502 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7503 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7504 },
7505 {
7506 .cmd = NL80211_CMD_DEL_KEY,
7507 .doit = nl80211_del_key,
7508 .policy = nl80211_policy,
55682965 7509 .flags = GENL_ADMIN_PERM,
41265714 7510 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7511 NL80211_FLAG_NEED_RTNL,
55682965 7512 },
ed1b6cc7
JB
7513 {
7514 .cmd = NL80211_CMD_SET_BEACON,
7515 .policy = nl80211_policy,
7516 .flags = GENL_ADMIN_PERM,
8860020e 7517 .doit = nl80211_set_beacon,
2b5f8b0b 7518 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7519 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7520 },
7521 {
8860020e 7522 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
7523 .policy = nl80211_policy,
7524 .flags = GENL_ADMIN_PERM,
8860020e 7525 .doit = nl80211_start_ap,
2b5f8b0b 7526 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7527 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7528 },
7529 {
8860020e 7530 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
7531 .policy = nl80211_policy,
7532 .flags = GENL_ADMIN_PERM,
8860020e 7533 .doit = nl80211_stop_ap,
2b5f8b0b 7534 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7535 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 7536 },
5727ef1b
JB
7537 {
7538 .cmd = NL80211_CMD_GET_STATION,
7539 .doit = nl80211_get_station,
2ec600d6 7540 .dumpit = nl80211_dump_station,
5727ef1b 7541 .policy = nl80211_policy,
4c476991
JB
7542 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7543 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7544 },
7545 {
7546 .cmd = NL80211_CMD_SET_STATION,
7547 .doit = nl80211_set_station,
7548 .policy = nl80211_policy,
7549 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7550 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7551 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7552 },
7553 {
7554 .cmd = NL80211_CMD_NEW_STATION,
7555 .doit = nl80211_new_station,
7556 .policy = nl80211_policy,
7557 .flags = GENL_ADMIN_PERM,
41265714 7558 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7559 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7560 },
7561 {
7562 .cmd = NL80211_CMD_DEL_STATION,
7563 .doit = nl80211_del_station,
7564 .policy = nl80211_policy,
2ec600d6 7565 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7566 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7567 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7568 },
7569 {
7570 .cmd = NL80211_CMD_GET_MPATH,
7571 .doit = nl80211_get_mpath,
7572 .dumpit = nl80211_dump_mpath,
7573 .policy = nl80211_policy,
7574 .flags = GENL_ADMIN_PERM,
41265714 7575 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7576 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7577 },
7578 {
7579 .cmd = NL80211_CMD_SET_MPATH,
7580 .doit = nl80211_set_mpath,
7581 .policy = nl80211_policy,
7582 .flags = GENL_ADMIN_PERM,
41265714 7583 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7584 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7585 },
7586 {
7587 .cmd = NL80211_CMD_NEW_MPATH,
7588 .doit = nl80211_new_mpath,
7589 .policy = nl80211_policy,
7590 .flags = GENL_ADMIN_PERM,
41265714 7591 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7592 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7593 },
7594 {
7595 .cmd = NL80211_CMD_DEL_MPATH,
7596 .doit = nl80211_del_mpath,
7597 .policy = nl80211_policy,
9f1ba906 7598 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7599 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7600 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
7601 },
7602 {
7603 .cmd = NL80211_CMD_SET_BSS,
7604 .doit = nl80211_set_bss,
7605 .policy = nl80211_policy,
b2e1b302 7606 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7607 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7608 NL80211_FLAG_NEED_RTNL,
b2e1b302 7609 },
f130347c
LR
7610 {
7611 .cmd = NL80211_CMD_GET_REG,
7612 .doit = nl80211_get_reg,
7613 .policy = nl80211_policy,
7614 /* can be retrieved by unprivileged users */
7615 },
b2e1b302
LR
7616 {
7617 .cmd = NL80211_CMD_SET_REG,
7618 .doit = nl80211_set_reg,
7619 .policy = nl80211_policy,
7620 .flags = GENL_ADMIN_PERM,
7621 },
7622 {
7623 .cmd = NL80211_CMD_REQ_SET_REG,
7624 .doit = nl80211_req_set_reg,
7625 .policy = nl80211_policy,
93da9cc1 7626 .flags = GENL_ADMIN_PERM,
7627 },
7628 {
24bdd9f4
JC
7629 .cmd = NL80211_CMD_GET_MESH_CONFIG,
7630 .doit = nl80211_get_mesh_config,
93da9cc1 7631 .policy = nl80211_policy,
7632 /* can be retrieved by unprivileged users */
2b5f8b0b 7633 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7634 NL80211_FLAG_NEED_RTNL,
93da9cc1 7635 },
7636 {
24bdd9f4
JC
7637 .cmd = NL80211_CMD_SET_MESH_CONFIG,
7638 .doit = nl80211_update_mesh_config,
93da9cc1 7639 .policy = nl80211_policy,
9aed3cc1 7640 .flags = GENL_ADMIN_PERM,
29cbe68c 7641 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7642 NL80211_FLAG_NEED_RTNL,
9aed3cc1 7643 },
2a519311
JB
7644 {
7645 .cmd = NL80211_CMD_TRIGGER_SCAN,
7646 .doit = nl80211_trigger_scan,
7647 .policy = nl80211_policy,
7648 .flags = GENL_ADMIN_PERM,
fd014284 7649 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7650 NL80211_FLAG_NEED_RTNL,
2a519311
JB
7651 },
7652 {
7653 .cmd = NL80211_CMD_GET_SCAN,
7654 .policy = nl80211_policy,
7655 .dumpit = nl80211_dump_scan,
7656 },
807f8a8c
LC
7657 {
7658 .cmd = NL80211_CMD_START_SCHED_SCAN,
7659 .doit = nl80211_start_sched_scan,
7660 .policy = nl80211_policy,
7661 .flags = GENL_ADMIN_PERM,
7662 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7663 NL80211_FLAG_NEED_RTNL,
7664 },
7665 {
7666 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
7667 .doit = nl80211_stop_sched_scan,
7668 .policy = nl80211_policy,
7669 .flags = GENL_ADMIN_PERM,
7670 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7671 NL80211_FLAG_NEED_RTNL,
7672 },
636a5d36
JM
7673 {
7674 .cmd = NL80211_CMD_AUTHENTICATE,
7675 .doit = nl80211_authenticate,
7676 .policy = nl80211_policy,
7677 .flags = GENL_ADMIN_PERM,
41265714 7678 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7679 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7680 },
7681 {
7682 .cmd = NL80211_CMD_ASSOCIATE,
7683 .doit = nl80211_associate,
7684 .policy = nl80211_policy,
7685 .flags = GENL_ADMIN_PERM,
41265714 7686 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7687 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7688 },
7689 {
7690 .cmd = NL80211_CMD_DEAUTHENTICATE,
7691 .doit = nl80211_deauthenticate,
7692 .policy = nl80211_policy,
7693 .flags = GENL_ADMIN_PERM,
41265714 7694 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7695 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7696 },
7697 {
7698 .cmd = NL80211_CMD_DISASSOCIATE,
7699 .doit = nl80211_disassociate,
7700 .policy = nl80211_policy,
7701 .flags = GENL_ADMIN_PERM,
41265714 7702 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7703 NL80211_FLAG_NEED_RTNL,
636a5d36 7704 },
04a773ad
JB
7705 {
7706 .cmd = NL80211_CMD_JOIN_IBSS,
7707 .doit = nl80211_join_ibss,
7708 .policy = nl80211_policy,
7709 .flags = GENL_ADMIN_PERM,
41265714 7710 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7711 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
7712 },
7713 {
7714 .cmd = NL80211_CMD_LEAVE_IBSS,
7715 .doit = nl80211_leave_ibss,
7716 .policy = nl80211_policy,
7717 .flags = GENL_ADMIN_PERM,
41265714 7718 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7719 NL80211_FLAG_NEED_RTNL,
04a773ad 7720 },
aff89a9b
JB
7721#ifdef CONFIG_NL80211_TESTMODE
7722 {
7723 .cmd = NL80211_CMD_TESTMODE,
7724 .doit = nl80211_testmode_do,
71063f0e 7725 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
7726 .policy = nl80211_policy,
7727 .flags = GENL_ADMIN_PERM,
4c476991
JB
7728 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7729 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
7730 },
7731#endif
b23aa676
SO
7732 {
7733 .cmd = NL80211_CMD_CONNECT,
7734 .doit = nl80211_connect,
7735 .policy = nl80211_policy,
7736 .flags = GENL_ADMIN_PERM,
41265714 7737 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7738 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
7739 },
7740 {
7741 .cmd = NL80211_CMD_DISCONNECT,
7742 .doit = nl80211_disconnect,
7743 .policy = nl80211_policy,
7744 .flags = GENL_ADMIN_PERM,
41265714 7745 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7746 NL80211_FLAG_NEED_RTNL,
b23aa676 7747 },
463d0183
JB
7748 {
7749 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
7750 .doit = nl80211_wiphy_netns,
7751 .policy = nl80211_policy,
7752 .flags = GENL_ADMIN_PERM,
4c476991
JB
7753 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7754 NL80211_FLAG_NEED_RTNL,
463d0183 7755 },
61fa713c
HS
7756 {
7757 .cmd = NL80211_CMD_GET_SURVEY,
7758 .policy = nl80211_policy,
7759 .dumpit = nl80211_dump_survey,
7760 },
67fbb16b
SO
7761 {
7762 .cmd = NL80211_CMD_SET_PMKSA,
7763 .doit = nl80211_setdel_pmksa,
7764 .policy = nl80211_policy,
7765 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7766 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7767 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7768 },
7769 {
7770 .cmd = NL80211_CMD_DEL_PMKSA,
7771 .doit = nl80211_setdel_pmksa,
7772 .policy = nl80211_policy,
7773 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7774 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7775 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7776 },
7777 {
7778 .cmd = NL80211_CMD_FLUSH_PMKSA,
7779 .doit = nl80211_flush_pmksa,
7780 .policy = nl80211_policy,
7781 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7782 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7783 NL80211_FLAG_NEED_RTNL,
67fbb16b 7784 },
9588bbd5
JM
7785 {
7786 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
7787 .doit = nl80211_remain_on_channel,
7788 .policy = nl80211_policy,
7789 .flags = GENL_ADMIN_PERM,
71bbc994 7790 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7791 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
7792 },
7793 {
7794 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7795 .doit = nl80211_cancel_remain_on_channel,
7796 .policy = nl80211_policy,
7797 .flags = GENL_ADMIN_PERM,
71bbc994 7798 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7799 NL80211_FLAG_NEED_RTNL,
9588bbd5 7800 },
13ae75b1
JM
7801 {
7802 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
7803 .doit = nl80211_set_tx_bitrate_mask,
7804 .policy = nl80211_policy,
7805 .flags = GENL_ADMIN_PERM,
4c476991
JB
7806 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7807 NL80211_FLAG_NEED_RTNL,
13ae75b1 7808 },
026331c4 7809 {
2e161f78
JB
7810 .cmd = NL80211_CMD_REGISTER_FRAME,
7811 .doit = nl80211_register_mgmt,
026331c4
JM
7812 .policy = nl80211_policy,
7813 .flags = GENL_ADMIN_PERM,
71bbc994 7814 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7815 NL80211_FLAG_NEED_RTNL,
026331c4
JM
7816 },
7817 {
2e161f78
JB
7818 .cmd = NL80211_CMD_FRAME,
7819 .doit = nl80211_tx_mgmt,
026331c4 7820 .policy = nl80211_policy,
f7ca38df 7821 .flags = GENL_ADMIN_PERM,
71bbc994 7822 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
7823 NL80211_FLAG_NEED_RTNL,
7824 },
7825 {
7826 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
7827 .doit = nl80211_tx_mgmt_cancel_wait,
7828 .policy = nl80211_policy,
026331c4 7829 .flags = GENL_ADMIN_PERM,
71bbc994 7830 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7831 NL80211_FLAG_NEED_RTNL,
026331c4 7832 },
ffb9eb3d
KV
7833 {
7834 .cmd = NL80211_CMD_SET_POWER_SAVE,
7835 .doit = nl80211_set_power_save,
7836 .policy = nl80211_policy,
7837 .flags = GENL_ADMIN_PERM,
4c476991
JB
7838 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7839 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
7840 },
7841 {
7842 .cmd = NL80211_CMD_GET_POWER_SAVE,
7843 .doit = nl80211_get_power_save,
7844 .policy = nl80211_policy,
7845 /* can be retrieved by unprivileged users */
4c476991
JB
7846 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7847 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 7848 },
d6dc1a38
JO
7849 {
7850 .cmd = NL80211_CMD_SET_CQM,
7851 .doit = nl80211_set_cqm,
7852 .policy = nl80211_policy,
7853 .flags = GENL_ADMIN_PERM,
4c476991
JB
7854 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7855 NL80211_FLAG_NEED_RTNL,
d6dc1a38 7856 },
f444de05
JB
7857 {
7858 .cmd = NL80211_CMD_SET_CHANNEL,
7859 .doit = nl80211_set_channel,
7860 .policy = nl80211_policy,
7861 .flags = GENL_ADMIN_PERM,
4c476991
JB
7862 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7863 NL80211_FLAG_NEED_RTNL,
f444de05 7864 },
e8347eba
BJ
7865 {
7866 .cmd = NL80211_CMD_SET_WDS_PEER,
7867 .doit = nl80211_set_wds_peer,
7868 .policy = nl80211_policy,
7869 .flags = GENL_ADMIN_PERM,
43b19952
JB
7870 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7871 NL80211_FLAG_NEED_RTNL,
e8347eba 7872 },
29cbe68c
JB
7873 {
7874 .cmd = NL80211_CMD_JOIN_MESH,
7875 .doit = nl80211_join_mesh,
7876 .policy = nl80211_policy,
7877 .flags = GENL_ADMIN_PERM,
7878 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7879 NL80211_FLAG_NEED_RTNL,
7880 },
7881 {
7882 .cmd = NL80211_CMD_LEAVE_MESH,
7883 .doit = nl80211_leave_mesh,
7884 .policy = nl80211_policy,
7885 .flags = GENL_ADMIN_PERM,
7886 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7887 NL80211_FLAG_NEED_RTNL,
7888 },
dfb89c56 7889#ifdef CONFIG_PM
ff1b6e69
JB
7890 {
7891 .cmd = NL80211_CMD_GET_WOWLAN,
7892 .doit = nl80211_get_wowlan,
7893 .policy = nl80211_policy,
7894 /* can be retrieved by unprivileged users */
7895 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7896 NL80211_FLAG_NEED_RTNL,
7897 },
7898 {
7899 .cmd = NL80211_CMD_SET_WOWLAN,
7900 .doit = nl80211_set_wowlan,
7901 .policy = nl80211_policy,
7902 .flags = GENL_ADMIN_PERM,
7903 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7904 NL80211_FLAG_NEED_RTNL,
7905 },
dfb89c56 7906#endif
e5497d76
JB
7907 {
7908 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7909 .doit = nl80211_set_rekey_data,
7910 .policy = nl80211_policy,
7911 .flags = GENL_ADMIN_PERM,
7912 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7913 NL80211_FLAG_NEED_RTNL,
7914 },
109086ce
AN
7915 {
7916 .cmd = NL80211_CMD_TDLS_MGMT,
7917 .doit = nl80211_tdls_mgmt,
7918 .policy = nl80211_policy,
7919 .flags = GENL_ADMIN_PERM,
7920 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7921 NL80211_FLAG_NEED_RTNL,
7922 },
7923 {
7924 .cmd = NL80211_CMD_TDLS_OPER,
7925 .doit = nl80211_tdls_oper,
7926 .policy = nl80211_policy,
7927 .flags = GENL_ADMIN_PERM,
7928 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7929 NL80211_FLAG_NEED_RTNL,
7930 },
28946da7
JB
7931 {
7932 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7933 .doit = nl80211_register_unexpected_frame,
7934 .policy = nl80211_policy,
7935 .flags = GENL_ADMIN_PERM,
7936 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7937 NL80211_FLAG_NEED_RTNL,
7938 },
7f6cf311
JB
7939 {
7940 .cmd = NL80211_CMD_PROBE_CLIENT,
7941 .doit = nl80211_probe_client,
7942 .policy = nl80211_policy,
7943 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7944 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7945 NL80211_FLAG_NEED_RTNL,
7946 },
5e760230
JB
7947 {
7948 .cmd = NL80211_CMD_REGISTER_BEACONS,
7949 .doit = nl80211_register_beacons,
7950 .policy = nl80211_policy,
7951 .flags = GENL_ADMIN_PERM,
7952 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7953 NL80211_FLAG_NEED_RTNL,
7954 },
1d9d9213
SW
7955 {
7956 .cmd = NL80211_CMD_SET_NOACK_MAP,
7957 .doit = nl80211_set_noack_map,
7958 .policy = nl80211_policy,
7959 .flags = GENL_ADMIN_PERM,
7960 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7961 NL80211_FLAG_NEED_RTNL,
7962 },
98104fde
JB
7963 {
7964 .cmd = NL80211_CMD_START_P2P_DEVICE,
7965 .doit = nl80211_start_p2p_device,
7966 .policy = nl80211_policy,
7967 .flags = GENL_ADMIN_PERM,
7968 .internal_flags = NL80211_FLAG_NEED_WDEV |
7969 NL80211_FLAG_NEED_RTNL,
7970 },
7971 {
7972 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
7973 .doit = nl80211_stop_p2p_device,
7974 .policy = nl80211_policy,
7975 .flags = GENL_ADMIN_PERM,
7976 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
7977 NL80211_FLAG_NEED_RTNL,
7978 },
f4e583c8
AQ
7979 {
7980 .cmd = NL80211_CMD_SET_MCAST_RATE,
7981 .doit = nl80211_set_mcast_rate,
77765eaf
VT
7982 .policy = nl80211_policy,
7983 .flags = GENL_ADMIN_PERM,
7984 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7985 NL80211_FLAG_NEED_RTNL,
7986 },
7987 {
7988 .cmd = NL80211_CMD_SET_MAC_ACL,
7989 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
7990 .policy = nl80211_policy,
7991 .flags = GENL_ADMIN_PERM,
7992 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7993 NL80211_FLAG_NEED_RTNL,
7994 },
55682965 7995};
9588bbd5 7996
6039f6d2
JM
7997static struct genl_multicast_group nl80211_mlme_mcgrp = {
7998 .name = "mlme",
7999};
55682965
JB
8000
8001/* multicast groups */
8002static struct genl_multicast_group nl80211_config_mcgrp = {
8003 .name = "config",
8004};
2a519311
JB
8005static struct genl_multicast_group nl80211_scan_mcgrp = {
8006 .name = "scan",
8007};
73d54c9e
LR
8008static struct genl_multicast_group nl80211_regulatory_mcgrp = {
8009 .name = "regulatory",
8010};
55682965
JB
8011
8012/* notification functions */
8013
8014void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
8015{
8016 struct sk_buff *msg;
8017
fd2120ca 8018 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
8019 if (!msg)
8020 return;
8021
8022 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
8023 nlmsg_free(msg);
8024 return;
8025 }
8026
463d0183
JB
8027 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8028 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
8029}
8030
362a415d
JB
8031static int nl80211_add_scan_req(struct sk_buff *msg,
8032 struct cfg80211_registered_device *rdev)
8033{
8034 struct cfg80211_scan_request *req = rdev->scan_req;
8035 struct nlattr *nest;
8036 int i;
8037
667503dd
JB
8038 ASSERT_RDEV_LOCK(rdev);
8039
362a415d
JB
8040 if (WARN_ON(!req))
8041 return 0;
8042
8043 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
8044 if (!nest)
8045 goto nla_put_failure;
9360ffd1
DM
8046 for (i = 0; i < req->n_ssids; i++) {
8047 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
8048 goto nla_put_failure;
8049 }
362a415d
JB
8050 nla_nest_end(msg, nest);
8051
8052 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
8053 if (!nest)
8054 goto nla_put_failure;
9360ffd1
DM
8055 for (i = 0; i < req->n_channels; i++) {
8056 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
8057 goto nla_put_failure;
8058 }
362a415d
JB
8059 nla_nest_end(msg, nest);
8060
9360ffd1
DM
8061 if (req->ie &&
8062 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
8063 goto nla_put_failure;
362a415d 8064
ed473771
SL
8065 if (req->flags)
8066 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
8067
362a415d
JB
8068 return 0;
8069 nla_put_failure:
8070 return -ENOBUFS;
8071}
8072
a538e2d5
JB
8073static int nl80211_send_scan_msg(struct sk_buff *msg,
8074 struct cfg80211_registered_device *rdev,
fd014284 8075 struct wireless_dev *wdev,
15e47304 8076 u32 portid, u32 seq, int flags,
a538e2d5 8077 u32 cmd)
2a519311
JB
8078{
8079 void *hdr;
8080
15e47304 8081 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
8082 if (!hdr)
8083 return -1;
8084
9360ffd1 8085 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
8086 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8087 wdev->netdev->ifindex)) ||
8088 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 8089 goto nla_put_failure;
2a519311 8090
362a415d
JB
8091 /* ignore errors and send incomplete event anyway */
8092 nl80211_add_scan_req(msg, rdev);
2a519311
JB
8093
8094 return genlmsg_end(msg, hdr);
8095
8096 nla_put_failure:
8097 genlmsg_cancel(msg, hdr);
8098 return -EMSGSIZE;
8099}
8100
807f8a8c
LC
8101static int
8102nl80211_send_sched_scan_msg(struct sk_buff *msg,
8103 struct cfg80211_registered_device *rdev,
8104 struct net_device *netdev,
15e47304 8105 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
8106{
8107 void *hdr;
8108
15e47304 8109 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
8110 if (!hdr)
8111 return -1;
8112
9360ffd1
DM
8113 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8114 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8115 goto nla_put_failure;
807f8a8c
LC
8116
8117 return genlmsg_end(msg, hdr);
8118
8119 nla_put_failure:
8120 genlmsg_cancel(msg, hdr);
8121 return -EMSGSIZE;
8122}
8123
a538e2d5 8124void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 8125 struct wireless_dev *wdev)
a538e2d5
JB
8126{
8127 struct sk_buff *msg;
8128
58050fce 8129 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
8130 if (!msg)
8131 return;
8132
fd014284 8133 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
8134 NL80211_CMD_TRIGGER_SCAN) < 0) {
8135 nlmsg_free(msg);
8136 return;
8137 }
8138
463d0183
JB
8139 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8140 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
8141}
8142
2a519311 8143void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 8144 struct wireless_dev *wdev)
2a519311
JB
8145{
8146 struct sk_buff *msg;
8147
fd2120ca 8148 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8149 if (!msg)
8150 return;
8151
fd014284 8152 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8153 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
8154 nlmsg_free(msg);
8155 return;
8156 }
8157
463d0183
JB
8158 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8159 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8160}
8161
8162void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 8163 struct wireless_dev *wdev)
2a519311
JB
8164{
8165 struct sk_buff *msg;
8166
fd2120ca 8167 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8168 if (!msg)
8169 return;
8170
fd014284 8171 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8172 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
8173 nlmsg_free(msg);
8174 return;
8175 }
8176
463d0183
JB
8177 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8178 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8179}
8180
807f8a8c
LC
8181void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
8182 struct net_device *netdev)
8183{
8184 struct sk_buff *msg;
8185
8186 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8187 if (!msg)
8188 return;
8189
8190 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
8191 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
8192 nlmsg_free(msg);
8193 return;
8194 }
8195
8196 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8197 nl80211_scan_mcgrp.id, GFP_KERNEL);
8198}
8199
8200void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
8201 struct net_device *netdev, u32 cmd)
8202{
8203 struct sk_buff *msg;
8204
58050fce 8205 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
8206 if (!msg)
8207 return;
8208
8209 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
8210 nlmsg_free(msg);
8211 return;
8212 }
8213
8214 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8215 nl80211_scan_mcgrp.id, GFP_KERNEL);
8216}
8217
73d54c9e
LR
8218/*
8219 * This can happen on global regulatory changes or device specific settings
8220 * based on custom world regulatory domains.
8221 */
8222void nl80211_send_reg_change_event(struct regulatory_request *request)
8223{
8224 struct sk_buff *msg;
8225 void *hdr;
8226
fd2120ca 8227 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
8228 if (!msg)
8229 return;
8230
8231 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
8232 if (!hdr) {
8233 nlmsg_free(msg);
8234 return;
8235 }
8236
8237 /* Userspace can always count this one always being set */
9360ffd1
DM
8238 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
8239 goto nla_put_failure;
8240
8241 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
8242 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8243 NL80211_REGDOM_TYPE_WORLD))
8244 goto nla_put_failure;
8245 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
8246 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8247 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
8248 goto nla_put_failure;
8249 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
8250 request->intersect) {
8251 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8252 NL80211_REGDOM_TYPE_INTERSECTION))
8253 goto nla_put_failure;
8254 } else {
8255 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8256 NL80211_REGDOM_TYPE_COUNTRY) ||
8257 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
8258 request->alpha2))
8259 goto nla_put_failure;
8260 }
8261
f4173766 8262 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
8263 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
8264 goto nla_put_failure;
73d54c9e 8265
3b7b72ee 8266 genlmsg_end(msg, hdr);
73d54c9e 8267
bc43b28c 8268 rcu_read_lock();
463d0183 8269 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
8270 GFP_ATOMIC);
8271 rcu_read_unlock();
73d54c9e
LR
8272
8273 return;
8274
8275nla_put_failure:
8276 genlmsg_cancel(msg, hdr);
8277 nlmsg_free(msg);
8278}
8279
6039f6d2
JM
8280static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
8281 struct net_device *netdev,
8282 const u8 *buf, size_t len,
e6d6e342 8283 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
8284{
8285 struct sk_buff *msg;
8286 void *hdr;
8287
e6d6e342 8288 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
8289 if (!msg)
8290 return;
8291
8292 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8293 if (!hdr) {
8294 nlmsg_free(msg);
8295 return;
8296 }
8297
9360ffd1
DM
8298 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8299 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8300 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8301 goto nla_put_failure;
6039f6d2 8302
3b7b72ee 8303 genlmsg_end(msg, hdr);
6039f6d2 8304
463d0183
JB
8305 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8306 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
8307 return;
8308
8309 nla_put_failure:
8310 genlmsg_cancel(msg, hdr);
8311 nlmsg_free(msg);
8312}
8313
8314void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8315 struct net_device *netdev, const u8 *buf,
8316 size_t len, gfp_t gfp)
6039f6d2
JM
8317{
8318 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8319 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
8320}
8321
8322void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
8323 struct net_device *netdev, const u8 *buf,
e6d6e342 8324 size_t len, gfp_t gfp)
6039f6d2 8325{
e6d6e342
JB
8326 nl80211_send_mlme_event(rdev, netdev, buf, len,
8327 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
8328}
8329
53b46b84 8330void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8331 struct net_device *netdev, const u8 *buf,
8332 size_t len, gfp_t gfp)
6039f6d2
JM
8333{
8334 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8335 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
8336}
8337
53b46b84
JM
8338void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
8339 struct net_device *netdev, const u8 *buf,
e6d6e342 8340 size_t len, gfp_t gfp)
6039f6d2
JM
8341{
8342 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8343 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
8344}
8345
cf4e594e
JM
8346void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
8347 struct net_device *netdev, const u8 *buf,
8348 size_t len, gfp_t gfp)
8349{
8350 nl80211_send_mlme_event(rdev, netdev, buf, len,
8351 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
8352}
8353
8354void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
8355 struct net_device *netdev, const u8 *buf,
8356 size_t len, gfp_t gfp)
8357{
8358 nl80211_send_mlme_event(rdev, netdev, buf, len,
8359 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
8360}
8361
1b06bb40
LR
8362static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
8363 struct net_device *netdev, int cmd,
e6d6e342 8364 const u8 *addr, gfp_t gfp)
1965c853
JM
8365{
8366 struct sk_buff *msg;
8367 void *hdr;
8368
e6d6e342 8369 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
8370 if (!msg)
8371 return;
8372
8373 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8374 if (!hdr) {
8375 nlmsg_free(msg);
8376 return;
8377 }
8378
9360ffd1
DM
8379 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8380 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8381 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
8382 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8383 goto nla_put_failure;
1965c853 8384
3b7b72ee 8385 genlmsg_end(msg, hdr);
1965c853 8386
463d0183
JB
8387 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8388 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
8389 return;
8390
8391 nla_put_failure:
8392 genlmsg_cancel(msg, hdr);
8393 nlmsg_free(msg);
8394}
8395
8396void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8397 struct net_device *netdev, const u8 *addr,
8398 gfp_t gfp)
1965c853
JM
8399{
8400 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 8401 addr, gfp);
1965c853
JM
8402}
8403
8404void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8405 struct net_device *netdev, const u8 *addr,
8406 gfp_t gfp)
1965c853 8407{
e6d6e342
JB
8408 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
8409 addr, gfp);
1965c853
JM
8410}
8411
b23aa676
SO
8412void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
8413 struct net_device *netdev, const u8 *bssid,
8414 const u8 *req_ie, size_t req_ie_len,
8415 const u8 *resp_ie, size_t resp_ie_len,
8416 u16 status, gfp_t gfp)
8417{
8418 struct sk_buff *msg;
8419 void *hdr;
8420
58050fce 8421 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8422 if (!msg)
8423 return;
8424
8425 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
8426 if (!hdr) {
8427 nlmsg_free(msg);
8428 return;
8429 }
8430
9360ffd1
DM
8431 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8432 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8433 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
8434 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
8435 (req_ie &&
8436 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8437 (resp_ie &&
8438 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8439 goto nla_put_failure;
b23aa676 8440
3b7b72ee 8441 genlmsg_end(msg, hdr);
b23aa676 8442
463d0183
JB
8443 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8444 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8445 return;
8446
8447 nla_put_failure:
8448 genlmsg_cancel(msg, hdr);
8449 nlmsg_free(msg);
8450
8451}
8452
8453void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
8454 struct net_device *netdev, const u8 *bssid,
8455 const u8 *req_ie, size_t req_ie_len,
8456 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
8457{
8458 struct sk_buff *msg;
8459 void *hdr;
8460
58050fce 8461 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8462 if (!msg)
8463 return;
8464
8465 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
8466 if (!hdr) {
8467 nlmsg_free(msg);
8468 return;
8469 }
8470
9360ffd1
DM
8471 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8472 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8473 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
8474 (req_ie &&
8475 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8476 (resp_ie &&
8477 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8478 goto nla_put_failure;
b23aa676 8479
3b7b72ee 8480 genlmsg_end(msg, hdr);
b23aa676 8481
463d0183
JB
8482 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8483 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8484 return;
8485
8486 nla_put_failure:
8487 genlmsg_cancel(msg, hdr);
8488 nlmsg_free(msg);
8489
8490}
8491
8492void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
8493 struct net_device *netdev, u16 reason,
667503dd 8494 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
8495{
8496 struct sk_buff *msg;
8497 void *hdr;
8498
58050fce 8499 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
8500 if (!msg)
8501 return;
8502
8503 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
8504 if (!hdr) {
8505 nlmsg_free(msg);
8506 return;
8507 }
8508
9360ffd1
DM
8509 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8510 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8511 (from_ap && reason &&
8512 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
8513 (from_ap &&
8514 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
8515 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
8516 goto nla_put_failure;
b23aa676 8517
3b7b72ee 8518 genlmsg_end(msg, hdr);
b23aa676 8519
463d0183
JB
8520 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8521 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
8522 return;
8523
8524 nla_put_failure:
8525 genlmsg_cancel(msg, hdr);
8526 nlmsg_free(msg);
8527
8528}
8529
04a773ad
JB
8530void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
8531 struct net_device *netdev, const u8 *bssid,
8532 gfp_t gfp)
8533{
8534 struct sk_buff *msg;
8535 void *hdr;
8536
fd2120ca 8537 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
8538 if (!msg)
8539 return;
8540
8541 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
8542 if (!hdr) {
8543 nlmsg_free(msg);
8544 return;
8545 }
8546
9360ffd1
DM
8547 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8548 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8549 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8550 goto nla_put_failure;
04a773ad 8551
3b7b72ee 8552 genlmsg_end(msg, hdr);
04a773ad 8553
463d0183
JB
8554 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8555 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
8556 return;
8557
8558 nla_put_failure:
8559 genlmsg_cancel(msg, hdr);
8560 nlmsg_free(msg);
8561}
8562
c93b5e71
JC
8563void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
8564 struct net_device *netdev,
8565 const u8 *macaddr, const u8* ie, u8 ie_len,
8566 gfp_t gfp)
8567{
8568 struct sk_buff *msg;
8569 void *hdr;
8570
8571 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8572 if (!msg)
8573 return;
8574
8575 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
8576 if (!hdr) {
8577 nlmsg_free(msg);
8578 return;
8579 }
8580
9360ffd1
DM
8581 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8582 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8583 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
8584 (ie_len && ie &&
8585 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
8586 goto nla_put_failure;
c93b5e71 8587
3b7b72ee 8588 genlmsg_end(msg, hdr);
c93b5e71
JC
8589
8590 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8591 nl80211_mlme_mcgrp.id, gfp);
8592 return;
8593
8594 nla_put_failure:
8595 genlmsg_cancel(msg, hdr);
8596 nlmsg_free(msg);
8597}
8598
a3b8b056
JM
8599void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
8600 struct net_device *netdev, const u8 *addr,
8601 enum nl80211_key_type key_type, int key_id,
e6d6e342 8602 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
8603{
8604 struct sk_buff *msg;
8605 void *hdr;
8606
e6d6e342 8607 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
8608 if (!msg)
8609 return;
8610
8611 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
8612 if (!hdr) {
8613 nlmsg_free(msg);
8614 return;
8615 }
8616
9360ffd1
DM
8617 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8618 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8619 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
8620 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
8621 (key_id != -1 &&
8622 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
8623 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
8624 goto nla_put_failure;
a3b8b056 8625
3b7b72ee 8626 genlmsg_end(msg, hdr);
a3b8b056 8627
463d0183
JB
8628 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8629 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
8630 return;
8631
8632 nla_put_failure:
8633 genlmsg_cancel(msg, hdr);
8634 nlmsg_free(msg);
8635}
8636
6bad8766
LR
8637void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
8638 struct ieee80211_channel *channel_before,
8639 struct ieee80211_channel *channel_after)
8640{
8641 struct sk_buff *msg;
8642 void *hdr;
8643 struct nlattr *nl_freq;
8644
fd2120ca 8645 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
8646 if (!msg)
8647 return;
8648
8649 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
8650 if (!hdr) {
8651 nlmsg_free(msg);
8652 return;
8653 }
8654
8655 /*
8656 * Since we are applying the beacon hint to a wiphy we know its
8657 * wiphy_idx is valid
8658 */
9360ffd1
DM
8659 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8660 goto nla_put_failure;
6bad8766
LR
8661
8662 /* Before */
8663 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
8664 if (!nl_freq)
8665 goto nla_put_failure;
8666 if (nl80211_msg_put_channel(msg, channel_before))
8667 goto nla_put_failure;
8668 nla_nest_end(msg, nl_freq);
8669
8670 /* After */
8671 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
8672 if (!nl_freq)
8673 goto nla_put_failure;
8674 if (nl80211_msg_put_channel(msg, channel_after))
8675 goto nla_put_failure;
8676 nla_nest_end(msg, nl_freq);
8677
3b7b72ee 8678 genlmsg_end(msg, hdr);
6bad8766 8679
463d0183
JB
8680 rcu_read_lock();
8681 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
8682 GFP_ATOMIC);
8683 rcu_read_unlock();
6bad8766
LR
8684
8685 return;
8686
8687nla_put_failure:
8688 genlmsg_cancel(msg, hdr);
8689 nlmsg_free(msg);
8690}
8691
9588bbd5
JM
8692static void nl80211_send_remain_on_chan_event(
8693 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 8694 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8695 struct ieee80211_channel *chan,
9588bbd5
JM
8696 unsigned int duration, gfp_t gfp)
8697{
8698 struct sk_buff *msg;
8699 void *hdr;
8700
8701 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8702 if (!msg)
8703 return;
8704
8705 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8706 if (!hdr) {
8707 nlmsg_free(msg);
8708 return;
8709 }
8710
9360ffd1 8711 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8712 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8713 wdev->netdev->ifindex)) ||
00f53350 8714 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 8715 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
8716 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
8717 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
8718 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8719 goto nla_put_failure;
9588bbd5 8720
9360ffd1
DM
8721 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
8722 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
8723 goto nla_put_failure;
9588bbd5 8724
3b7b72ee 8725 genlmsg_end(msg, hdr);
9588bbd5
JM
8726
8727 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8728 nl80211_mlme_mcgrp.id, gfp);
8729 return;
8730
8731 nla_put_failure:
8732 genlmsg_cancel(msg, hdr);
8733 nlmsg_free(msg);
8734}
8735
8736void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
71bbc994 8737 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8738 struct ieee80211_channel *chan,
9588bbd5
JM
8739 unsigned int duration, gfp_t gfp)
8740{
8741 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 8742 rdev, wdev, cookie, chan,
42d97a59 8743 duration, gfp);
9588bbd5
JM
8744}
8745
8746void nl80211_send_remain_on_channel_cancel(
71bbc994
JB
8747 struct cfg80211_registered_device *rdev,
8748 struct wireless_dev *wdev,
42d97a59 8749 u64 cookie, struct ieee80211_channel *chan, gfp_t gfp)
9588bbd5
JM
8750{
8751 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 8752 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5
JM
8753}
8754
98b62183
JB
8755void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
8756 struct net_device *dev, const u8 *mac_addr,
8757 struct station_info *sinfo, gfp_t gfp)
8758{
8759 struct sk_buff *msg;
8760
58050fce 8761 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
8762 if (!msg)
8763 return;
8764
66266b3a
JL
8765 if (nl80211_send_station(msg, 0, 0, 0,
8766 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
8767 nlmsg_free(msg);
8768 return;
8769 }
8770
8771 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8772 nl80211_mlme_mcgrp.id, gfp);
8773}
8774
ec15e68b
JM
8775void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
8776 struct net_device *dev, const u8 *mac_addr,
8777 gfp_t gfp)
8778{
8779 struct sk_buff *msg;
8780 void *hdr;
8781
58050fce 8782 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
8783 if (!msg)
8784 return;
8785
8786 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
8787 if (!hdr) {
8788 nlmsg_free(msg);
8789 return;
8790 }
8791
9360ffd1
DM
8792 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8793 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
8794 goto nla_put_failure;
ec15e68b 8795
3b7b72ee 8796 genlmsg_end(msg, hdr);
ec15e68b
JM
8797
8798 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8799 nl80211_mlme_mcgrp.id, gfp);
8800 return;
8801
8802 nla_put_failure:
8803 genlmsg_cancel(msg, hdr);
8804 nlmsg_free(msg);
8805}
8806
ed44a951
PP
8807void nl80211_send_conn_failed_event(struct cfg80211_registered_device *rdev,
8808 struct net_device *dev, const u8 *mac_addr,
8809 enum nl80211_connect_failed_reason reason,
8810 gfp_t gfp)
8811{
8812 struct sk_buff *msg;
8813 void *hdr;
8814
8815 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8816 if (!msg)
8817 return;
8818
8819 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
8820 if (!hdr) {
8821 nlmsg_free(msg);
8822 return;
8823 }
8824
8825 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8826 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
8827 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
8828 goto nla_put_failure;
8829
8830 genlmsg_end(msg, hdr);
8831
8832 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8833 nl80211_mlme_mcgrp.id, gfp);
8834 return;
8835
8836 nla_put_failure:
8837 genlmsg_cancel(msg, hdr);
8838 nlmsg_free(msg);
8839}
8840
b92ab5d8
JB
8841static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
8842 const u8 *addr, gfp_t gfp)
28946da7
JB
8843{
8844 struct wireless_dev *wdev = dev->ieee80211_ptr;
8845 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8846 struct sk_buff *msg;
8847 void *hdr;
8848 int err;
15e47304 8849 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 8850
15e47304 8851 if (!nlportid)
28946da7
JB
8852 return false;
8853
8854 msg = nlmsg_new(100, gfp);
8855 if (!msg)
8856 return true;
8857
b92ab5d8 8858 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
8859 if (!hdr) {
8860 nlmsg_free(msg);
8861 return true;
8862 }
8863
9360ffd1
DM
8864 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8865 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8866 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8867 goto nla_put_failure;
28946da7
JB
8868
8869 err = genlmsg_end(msg, hdr);
8870 if (err < 0) {
8871 nlmsg_free(msg);
8872 return true;
8873 }
8874
15e47304 8875 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
8876 return true;
8877
8878 nla_put_failure:
8879 genlmsg_cancel(msg, hdr);
8880 nlmsg_free(msg);
8881 return true;
8882}
8883
b92ab5d8
JB
8884bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
8885{
8886 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
8887 addr, gfp);
8888}
8889
8890bool nl80211_unexpected_4addr_frame(struct net_device *dev,
8891 const u8 *addr, gfp_t gfp)
8892{
8893 return __nl80211_unexpected_frame(dev,
8894 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
8895 addr, gfp);
8896}
8897
2e161f78 8898int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 8899 struct wireless_dev *wdev, u32 nlportid,
804483e9
JB
8900 int freq, int sig_dbm,
8901 const u8 *buf, size_t len, gfp_t gfp)
026331c4 8902{
71bbc994 8903 struct net_device *netdev = wdev->netdev;
026331c4
JM
8904 struct sk_buff *msg;
8905 void *hdr;
026331c4
JM
8906
8907 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8908 if (!msg)
8909 return -ENOMEM;
8910
2e161f78 8911 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
8912 if (!hdr) {
8913 nlmsg_free(msg);
8914 return -ENOMEM;
8915 }
8916
9360ffd1 8917 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8918 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8919 netdev->ifindex)) ||
9360ffd1
DM
8920 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8921 (sig_dbm &&
8922 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8923 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8924 goto nla_put_failure;
026331c4 8925
3b7b72ee 8926 genlmsg_end(msg, hdr);
026331c4 8927
15e47304 8928 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
8929
8930 nla_put_failure:
8931 genlmsg_cancel(msg, hdr);
8932 nlmsg_free(msg);
8933 return -ENOBUFS;
8934}
8935
2e161f78 8936void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
71bbc994 8937 struct wireless_dev *wdev, u64 cookie,
2e161f78
JB
8938 const u8 *buf, size_t len, bool ack,
8939 gfp_t gfp)
026331c4 8940{
71bbc994 8941 struct net_device *netdev = wdev->netdev;
026331c4
JM
8942 struct sk_buff *msg;
8943 void *hdr;
8944
8945 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8946 if (!msg)
8947 return;
8948
2e161f78 8949 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8950 if (!hdr) {
8951 nlmsg_free(msg);
8952 return;
8953 }
8954
9360ffd1 8955 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8956 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8957 netdev->ifindex)) ||
9360ffd1
DM
8958 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8959 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8960 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8961 goto nla_put_failure;
026331c4 8962
3b7b72ee 8963 genlmsg_end(msg, hdr);
026331c4
JM
8964
8965 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8966 return;
8967
8968 nla_put_failure:
8969 genlmsg_cancel(msg, hdr);
8970 nlmsg_free(msg);
8971}
8972
d6dc1a38
JO
8973void
8974nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8975 struct net_device *netdev,
8976 enum nl80211_cqm_rssi_threshold_event rssi_event,
8977 gfp_t gfp)
8978{
8979 struct sk_buff *msg;
8980 struct nlattr *pinfoattr;
8981 void *hdr;
8982
58050fce 8983 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
8984 if (!msg)
8985 return;
8986
8987 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8988 if (!hdr) {
8989 nlmsg_free(msg);
8990 return;
8991 }
8992
9360ffd1
DM
8993 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8994 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8995 goto nla_put_failure;
d6dc1a38
JO
8996
8997 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8998 if (!pinfoattr)
8999 goto nla_put_failure;
9000
9360ffd1
DM
9001 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
9002 rssi_event))
9003 goto nla_put_failure;
d6dc1a38
JO
9004
9005 nla_nest_end(msg, pinfoattr);
9006
3b7b72ee 9007 genlmsg_end(msg, hdr);
d6dc1a38
JO
9008
9009 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9010 nl80211_mlme_mcgrp.id, gfp);
9011 return;
9012
9013 nla_put_failure:
9014 genlmsg_cancel(msg, hdr);
9015 nlmsg_free(msg);
9016}
9017
e5497d76
JB
9018void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
9019 struct net_device *netdev, const u8 *bssid,
9020 const u8 *replay_ctr, gfp_t gfp)
9021{
9022 struct sk_buff *msg;
9023 struct nlattr *rekey_attr;
9024 void *hdr;
9025
58050fce 9026 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
9027 if (!msg)
9028 return;
9029
9030 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
9031 if (!hdr) {
9032 nlmsg_free(msg);
9033 return;
9034 }
9035
9360ffd1
DM
9036 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9037 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9038 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
9039 goto nla_put_failure;
e5497d76
JB
9040
9041 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
9042 if (!rekey_attr)
9043 goto nla_put_failure;
9044
9360ffd1
DM
9045 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
9046 NL80211_REPLAY_CTR_LEN, replay_ctr))
9047 goto nla_put_failure;
e5497d76
JB
9048
9049 nla_nest_end(msg, rekey_attr);
9050
3b7b72ee 9051 genlmsg_end(msg, hdr);
e5497d76
JB
9052
9053 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9054 nl80211_mlme_mcgrp.id, gfp);
9055 return;
9056
9057 nla_put_failure:
9058 genlmsg_cancel(msg, hdr);
9059 nlmsg_free(msg);
9060}
9061
c9df56b4
JM
9062void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
9063 struct net_device *netdev, int index,
9064 const u8 *bssid, bool preauth, gfp_t gfp)
9065{
9066 struct sk_buff *msg;
9067 struct nlattr *attr;
9068 void *hdr;
9069
58050fce 9070 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
9071 if (!msg)
9072 return;
9073
9074 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
9075 if (!hdr) {
9076 nlmsg_free(msg);
9077 return;
9078 }
9079
9360ffd1
DM
9080 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9081 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9082 goto nla_put_failure;
c9df56b4
JM
9083
9084 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
9085 if (!attr)
9086 goto nla_put_failure;
9087
9360ffd1
DM
9088 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
9089 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
9090 (preauth &&
9091 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
9092 goto nla_put_failure;
c9df56b4
JM
9093
9094 nla_nest_end(msg, attr);
9095
3b7b72ee 9096 genlmsg_end(msg, hdr);
c9df56b4
JM
9097
9098 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9099 nl80211_mlme_mcgrp.id, gfp);
9100 return;
9101
9102 nla_put_failure:
9103 genlmsg_cancel(msg, hdr);
9104 nlmsg_free(msg);
9105}
9106
5314526b 9107void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
683b6d3b
JB
9108 struct net_device *netdev,
9109 struct cfg80211_chan_def *chandef, gfp_t gfp)
5314526b
TP
9110{
9111 struct sk_buff *msg;
9112 void *hdr;
9113
58050fce 9114 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
9115 if (!msg)
9116 return;
9117
9118 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
9119 if (!hdr) {
9120 nlmsg_free(msg);
9121 return;
9122 }
9123
683b6d3b
JB
9124 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9125 goto nla_put_failure;
9126
9127 if (nl80211_send_chandef(msg, chandef))
7eab0f64 9128 goto nla_put_failure;
5314526b
TP
9129
9130 genlmsg_end(msg, hdr);
9131
9132 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9133 nl80211_mlme_mcgrp.id, gfp);
9134 return;
9135
9136 nla_put_failure:
9137 genlmsg_cancel(msg, hdr);
9138 nlmsg_free(msg);
9139}
9140
84f10708
TP
9141void
9142nl80211_send_cqm_txe_notify(struct cfg80211_registered_device *rdev,
9143 struct net_device *netdev, const u8 *peer,
9144 u32 num_packets, u32 rate, u32 intvl, gfp_t gfp)
9145{
9146 struct sk_buff *msg;
9147 struct nlattr *pinfoattr;
9148 void *hdr;
9149
9150 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
9151 if (!msg)
9152 return;
9153
9154 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9155 if (!hdr) {
9156 nlmsg_free(msg);
9157 return;
9158 }
9159
9160 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9161 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9162 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9163 goto nla_put_failure;
9164
9165 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9166 if (!pinfoattr)
9167 goto nla_put_failure;
9168
9169 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
9170 goto nla_put_failure;
9171
9172 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
9173 goto nla_put_failure;
9174
9175 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
9176 goto nla_put_failure;
9177
9178 nla_nest_end(msg, pinfoattr);
9179
9180 genlmsg_end(msg, hdr);
9181
9182 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9183 nl80211_mlme_mcgrp.id, gfp);
9184 return;
9185
9186 nla_put_failure:
9187 genlmsg_cancel(msg, hdr);
9188 nlmsg_free(msg);
9189}
9190
c063dbf5
JB
9191void
9192nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
9193 struct net_device *netdev, const u8 *peer,
9194 u32 num_packets, gfp_t gfp)
9195{
9196 struct sk_buff *msg;
9197 struct nlattr *pinfoattr;
9198 void *hdr;
9199
58050fce 9200 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
9201 if (!msg)
9202 return;
9203
9204 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9205 if (!hdr) {
9206 nlmsg_free(msg);
9207 return;
9208 }
9209
9360ffd1
DM
9210 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9211 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9212 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9213 goto nla_put_failure;
c063dbf5
JB
9214
9215 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9216 if (!pinfoattr)
9217 goto nla_put_failure;
9218
9360ffd1
DM
9219 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
9220 goto nla_put_failure;
c063dbf5
JB
9221
9222 nla_nest_end(msg, pinfoattr);
9223
3b7b72ee 9224 genlmsg_end(msg, hdr);
c063dbf5
JB
9225
9226 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9227 nl80211_mlme_mcgrp.id, gfp);
9228 return;
9229
9230 nla_put_failure:
9231 genlmsg_cancel(msg, hdr);
9232 nlmsg_free(msg);
9233}
9234
7f6cf311
JB
9235void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
9236 u64 cookie, bool acked, gfp_t gfp)
9237{
9238 struct wireless_dev *wdev = dev->ieee80211_ptr;
9239 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9240 struct sk_buff *msg;
9241 void *hdr;
9242 int err;
9243
4ee3e063
BL
9244 trace_cfg80211_probe_status(dev, addr, cookie, acked);
9245
58050fce 9246 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 9247
7f6cf311
JB
9248 if (!msg)
9249 return;
9250
9251 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
9252 if (!hdr) {
9253 nlmsg_free(msg);
9254 return;
9255 }
9256
9360ffd1
DM
9257 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9258 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9259 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9260 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
9261 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
9262 goto nla_put_failure;
7f6cf311
JB
9263
9264 err = genlmsg_end(msg, hdr);
9265 if (err < 0) {
9266 nlmsg_free(msg);
9267 return;
9268 }
9269
9270 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9271 nl80211_mlme_mcgrp.id, gfp);
9272 return;
9273
9274 nla_put_failure:
9275 genlmsg_cancel(msg, hdr);
9276 nlmsg_free(msg);
9277}
9278EXPORT_SYMBOL(cfg80211_probe_status);
9279
5e760230
JB
9280void cfg80211_report_obss_beacon(struct wiphy *wiphy,
9281 const u8 *frame, size_t len,
37c73b5f 9282 int freq, int sig_dbm)
5e760230
JB
9283{
9284 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9285 struct sk_buff *msg;
9286 void *hdr;
37c73b5f 9287 struct cfg80211_beacon_registration *reg;
5e760230 9288
4ee3e063
BL
9289 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
9290
37c73b5f
BG
9291 spin_lock_bh(&rdev->beacon_registrations_lock);
9292 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
9293 msg = nlmsg_new(len + 100, GFP_ATOMIC);
9294 if (!msg) {
9295 spin_unlock_bh(&rdev->beacon_registrations_lock);
9296 return;
9297 }
5e760230 9298
37c73b5f
BG
9299 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
9300 if (!hdr)
9301 goto nla_put_failure;
5e760230 9302
37c73b5f
BG
9303 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9304 (freq &&
9305 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
9306 (sig_dbm &&
9307 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9308 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
9309 goto nla_put_failure;
5e760230 9310
37c73b5f 9311 genlmsg_end(msg, hdr);
5e760230 9312
37c73b5f
BG
9313 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
9314 }
9315 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
9316 return;
9317
9318 nla_put_failure:
37c73b5f
BG
9319 spin_unlock_bh(&rdev->beacon_registrations_lock);
9320 if (hdr)
9321 genlmsg_cancel(msg, hdr);
5e760230
JB
9322 nlmsg_free(msg);
9323}
9324EXPORT_SYMBOL(cfg80211_report_obss_beacon);
9325
cd8f7cb4
JB
9326#ifdef CONFIG_PM
9327void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
9328 struct cfg80211_wowlan_wakeup *wakeup,
9329 gfp_t gfp)
9330{
9331 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9332 struct sk_buff *msg;
9333 void *hdr;
9334 int err, size = 200;
9335
9336 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
9337
9338 if (wakeup)
9339 size += wakeup->packet_present_len;
9340
9341 msg = nlmsg_new(size, gfp);
9342 if (!msg)
9343 return;
9344
9345 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
9346 if (!hdr)
9347 goto free_msg;
9348
9349 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9350 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9351 goto free_msg;
9352
9353 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9354 wdev->netdev->ifindex))
9355 goto free_msg;
9356
9357 if (wakeup) {
9358 struct nlattr *reasons;
9359
9360 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
9361
9362 if (wakeup->disconnect &&
9363 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
9364 goto free_msg;
9365 if (wakeup->magic_pkt &&
9366 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
9367 goto free_msg;
9368 if (wakeup->gtk_rekey_failure &&
9369 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
9370 goto free_msg;
9371 if (wakeup->eap_identity_req &&
9372 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
9373 goto free_msg;
9374 if (wakeup->four_way_handshake &&
9375 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
9376 goto free_msg;
9377 if (wakeup->rfkill_release &&
9378 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
9379 goto free_msg;
9380
9381 if (wakeup->pattern_idx >= 0 &&
9382 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
9383 wakeup->pattern_idx))
9384 goto free_msg;
9385
9386 if (wakeup->packet) {
9387 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
9388 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
9389
9390 if (!wakeup->packet_80211) {
9391 pkt_attr =
9392 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
9393 len_attr =
9394 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
9395 }
9396
9397 if (wakeup->packet_len &&
9398 nla_put_u32(msg, len_attr, wakeup->packet_len))
9399 goto free_msg;
9400
9401 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
9402 wakeup->packet))
9403 goto free_msg;
9404 }
9405
9406 nla_nest_end(msg, reasons);
9407 }
9408
9409 err = genlmsg_end(msg, hdr);
9410 if (err < 0)
9411 goto free_msg;
9412
9413 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9414 nl80211_mlme_mcgrp.id, gfp);
9415 return;
9416
9417 free_msg:
9418 nlmsg_free(msg);
9419}
9420EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
9421#endif
9422
3475b094
JM
9423void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
9424 enum nl80211_tdls_operation oper,
9425 u16 reason_code, gfp_t gfp)
9426{
9427 struct wireless_dev *wdev = dev->ieee80211_ptr;
9428 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9429 struct sk_buff *msg;
9430 void *hdr;
9431 int err;
9432
9433 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
9434 reason_code);
9435
9436 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9437 if (!msg)
9438 return;
9439
9440 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
9441 if (!hdr) {
9442 nlmsg_free(msg);
9443 return;
9444 }
9445
9446 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9447 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9448 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
9449 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
9450 (reason_code > 0 &&
9451 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
9452 goto nla_put_failure;
9453
9454 err = genlmsg_end(msg, hdr);
9455 if (err < 0) {
9456 nlmsg_free(msg);
9457 return;
9458 }
9459
9460 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9461 nl80211_mlme_mcgrp.id, gfp);
9462 return;
9463
9464 nla_put_failure:
9465 genlmsg_cancel(msg, hdr);
9466 nlmsg_free(msg);
9467}
9468EXPORT_SYMBOL(cfg80211_tdls_oper_request);
9469
026331c4
JM
9470static int nl80211_netlink_notify(struct notifier_block * nb,
9471 unsigned long state,
9472 void *_notify)
9473{
9474 struct netlink_notify *notify = _notify;
9475 struct cfg80211_registered_device *rdev;
9476 struct wireless_dev *wdev;
37c73b5f 9477 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
9478
9479 if (state != NETLINK_URELEASE)
9480 return NOTIFY_DONE;
9481
9482 rcu_read_lock();
9483
5e760230 9484 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 9485 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 9486 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
9487
9488 spin_lock_bh(&rdev->beacon_registrations_lock);
9489 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
9490 list) {
9491 if (reg->nlportid == notify->portid) {
9492 list_del(&reg->list);
9493 kfree(reg);
9494 break;
9495 }
9496 }
9497 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 9498 }
026331c4
JM
9499
9500 rcu_read_unlock();
9501
9502 return NOTIFY_DONE;
9503}
9504
9505static struct notifier_block nl80211_netlink_notifier = {
9506 .notifier_call = nl80211_netlink_notify,
9507};
9508
55682965
JB
9509/* initialisation/exit functions */
9510
9511int nl80211_init(void)
9512{
0d63cbb5 9513 int err;
55682965 9514
0d63cbb5
MM
9515 err = genl_register_family_with_ops(&nl80211_fam,
9516 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
9517 if (err)
9518 return err;
9519
55682965
JB
9520 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
9521 if (err)
9522 goto err_out;
9523
2a519311
JB
9524 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
9525 if (err)
9526 goto err_out;
9527
73d54c9e
LR
9528 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
9529 if (err)
9530 goto err_out;
9531
6039f6d2
JM
9532 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
9533 if (err)
9534 goto err_out;
9535
aff89a9b
JB
9536#ifdef CONFIG_NL80211_TESTMODE
9537 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
9538 if (err)
9539 goto err_out;
9540#endif
9541
026331c4
JM
9542 err = netlink_register_notifier(&nl80211_netlink_notifier);
9543 if (err)
9544 goto err_out;
9545
55682965
JB
9546 return 0;
9547 err_out:
9548 genl_unregister_family(&nl80211_fam);
9549 return err;
9550}
9551
9552void nl80211_exit(void)
9553{
026331c4 9554 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
9555 genl_unregister_family(&nl80211_fam);
9556}