]> git.proxmox.com Git - mirror_ubuntu-zesty-kernel.git/blame - net/wireless/nl80211.c
libertas: Add libertas_disablemesh module parameter to disable mesh interface
[mirror_ubuntu-zesty-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
e31b8213 96 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
97
98 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101 .len = IEEE80211_MAX_DATA_LEN },
102 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
104 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 109 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 110 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 111 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
112 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113 .len = IEEE80211_MAX_MESH_ID_LEN },
114 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 115
b2e1b302
LR
116 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
9f1ba906
JM
119 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
122 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123 .len = NL80211_MAX_SUPP_RATES },
50b12f59 124 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 125
24bdd9f4 126 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 127 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 128
36aedc90
JM
129 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
130 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
131
132 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
133 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
134 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
135 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
136 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
137
138 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_SSID_LEN },
140 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
141 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 142 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 143 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 144 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
145 [NL80211_ATTR_STA_FLAGS2] = {
146 .len = sizeof(struct nl80211_sta_flag_update),
147 },
3f77316c 148 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
149 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
150 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
151 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
152 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
153 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 154 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 155 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
156 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
157 .len = WLAN_PMKID_LEN },
9588bbd5
JM
158 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
159 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 160 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
161 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
162 .len = IEEE80211_MAX_DATA_LEN },
163 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 164 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 165 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 166 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 167 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
168 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
169 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 170 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
171 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
172 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 173 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 174 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 175 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 176 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 177 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
55682965
JB
178};
179
e31b8213 180/* policy for the key attributes */
b54452b0 181static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 182 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
183 [NL80211_KEY_IDX] = { .type = NLA_U8 },
184 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
185 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
186 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
187 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 188 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
189 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
190};
191
192/* policy for the key default flags */
193static const struct nla_policy
194nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
195 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
196 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
197};
198
ff1b6e69
JB
199/* policy for WoWLAN attributes */
200static const struct nla_policy
201nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
202 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
203 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
204 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
205 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
206};
207
a043897a
HS
208/* ifidx get helper */
209static int nl80211_get_ifidx(struct netlink_callback *cb)
210{
211 int res;
212
213 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
214 nl80211_fam.attrbuf, nl80211_fam.maxattr,
215 nl80211_policy);
216 if (res)
217 return res;
218
219 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
220 return -EINVAL;
221
222 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
223 if (!res)
224 return -EINVAL;
225 return res;
226}
227
67748893
JB
228static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
229 struct netlink_callback *cb,
230 struct cfg80211_registered_device **rdev,
231 struct net_device **dev)
232{
233 int ifidx = cb->args[0];
234 int err;
235
236 if (!ifidx)
237 ifidx = nl80211_get_ifidx(cb);
238 if (ifidx < 0)
239 return ifidx;
240
241 cb->args[0] = ifidx;
242
243 rtnl_lock();
244
245 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
246 if (!*dev) {
247 err = -ENODEV;
248 goto out_rtnl;
249 }
250
251 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
252 if (IS_ERR(*rdev)) {
253 err = PTR_ERR(*rdev);
67748893
JB
254 goto out_rtnl;
255 }
256
257 return 0;
258 out_rtnl:
259 rtnl_unlock();
260 return err;
261}
262
263static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
264{
265 cfg80211_unlock_rdev(rdev);
266 rtnl_unlock();
267}
268
f4a11bb0
JB
269/* IE validation */
270static bool is_valid_ie_attr(const struct nlattr *attr)
271{
272 const u8 *pos;
273 int len;
274
275 if (!attr)
276 return true;
277
278 pos = nla_data(attr);
279 len = nla_len(attr);
280
281 while (len) {
282 u8 elemlen;
283
284 if (len < 2)
285 return false;
286 len -= 2;
287
288 elemlen = pos[1];
289 if (elemlen > len)
290 return false;
291
292 len -= elemlen;
293 pos += 2 + elemlen;
294 }
295
296 return true;
297}
298
55682965
JB
299/* message building helper */
300static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
301 int flags, u8 cmd)
302{
303 /* since there is no private header just add the generic one */
304 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
305}
306
5dab3b8a
LR
307static int nl80211_msg_put_channel(struct sk_buff *msg,
308 struct ieee80211_channel *chan)
309{
310 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
311 chan->center_freq);
312
313 if (chan->flags & IEEE80211_CHAN_DISABLED)
314 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
315 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
316 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
317 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
318 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
319 if (chan->flags & IEEE80211_CHAN_RADAR)
320 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
321
322 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
323 DBM_TO_MBM(chan->max_power));
324
325 return 0;
326
327 nla_put_failure:
328 return -ENOBUFS;
329}
330
55682965
JB
331/* netlink command implementations */
332
b9454e83
JB
333struct key_parse {
334 struct key_params p;
335 int idx;
e31b8213 336 int type;
b9454e83 337 bool def, defmgmt;
dbd2fd65 338 bool def_uni, def_multi;
b9454e83
JB
339};
340
341static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
342{
343 struct nlattr *tb[NL80211_KEY_MAX + 1];
344 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
345 nl80211_key_policy);
346 if (err)
347 return err;
348
349 k->def = !!tb[NL80211_KEY_DEFAULT];
350 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
351
dbd2fd65
JB
352 if (k->def) {
353 k->def_uni = true;
354 k->def_multi = true;
355 }
356 if (k->defmgmt)
357 k->def_multi = true;
358
b9454e83
JB
359 if (tb[NL80211_KEY_IDX])
360 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
361
362 if (tb[NL80211_KEY_DATA]) {
363 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
364 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
365 }
366
367 if (tb[NL80211_KEY_SEQ]) {
368 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
369 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
370 }
371
372 if (tb[NL80211_KEY_CIPHER])
373 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
374
e31b8213
JB
375 if (tb[NL80211_KEY_TYPE]) {
376 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
377 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
378 return -EINVAL;
379 }
380
dbd2fd65
JB
381 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
382 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
383 int err = nla_parse_nested(kdt,
384 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
385 tb[NL80211_KEY_DEFAULT_TYPES],
386 nl80211_key_default_policy);
387 if (err)
388 return err;
389
390 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
391 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
392 }
393
b9454e83
JB
394 return 0;
395}
396
397static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
398{
399 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
400 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
401 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
402 }
403
404 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
405 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
406 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
407 }
408
409 if (info->attrs[NL80211_ATTR_KEY_IDX])
410 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
411
412 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
413 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
414
415 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
416 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
417
dbd2fd65
JB
418 if (k->def) {
419 k->def_uni = true;
420 k->def_multi = true;
421 }
422 if (k->defmgmt)
423 k->def_multi = true;
424
e31b8213
JB
425 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
426 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
427 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
428 return -EINVAL;
429 }
430
dbd2fd65
JB
431 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
432 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
433 int err = nla_parse_nested(
434 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
435 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
436 nl80211_key_default_policy);
437 if (err)
438 return err;
439
440 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
441 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
442 }
443
b9454e83
JB
444 return 0;
445}
446
447static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
448{
449 int err;
450
451 memset(k, 0, sizeof(*k));
452 k->idx = -1;
e31b8213 453 k->type = -1;
b9454e83
JB
454
455 if (info->attrs[NL80211_ATTR_KEY])
456 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
457 else
458 err = nl80211_parse_key_old(info, k);
459
460 if (err)
461 return err;
462
463 if (k->def && k->defmgmt)
464 return -EINVAL;
465
dbd2fd65
JB
466 if (k->defmgmt) {
467 if (k->def_uni || !k->def_multi)
468 return -EINVAL;
469 }
470
b9454e83
JB
471 if (k->idx != -1) {
472 if (k->defmgmt) {
473 if (k->idx < 4 || k->idx > 5)
474 return -EINVAL;
475 } else if (k->def) {
476 if (k->idx < 0 || k->idx > 3)
477 return -EINVAL;
478 } else {
479 if (k->idx < 0 || k->idx > 5)
480 return -EINVAL;
481 }
482 }
483
484 return 0;
485}
486
fffd0934
JB
487static struct cfg80211_cached_keys *
488nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
489 struct nlattr *keys)
490{
491 struct key_parse parse;
492 struct nlattr *key;
493 struct cfg80211_cached_keys *result;
494 int rem, err, def = 0;
495
496 result = kzalloc(sizeof(*result), GFP_KERNEL);
497 if (!result)
498 return ERR_PTR(-ENOMEM);
499
500 result->def = -1;
501 result->defmgmt = -1;
502
503 nla_for_each_nested(key, keys, rem) {
504 memset(&parse, 0, sizeof(parse));
505 parse.idx = -1;
506
507 err = nl80211_parse_key_new(key, &parse);
508 if (err)
509 goto error;
510 err = -EINVAL;
511 if (!parse.p.key)
512 goto error;
513 if (parse.idx < 0 || parse.idx > 4)
514 goto error;
515 if (parse.def) {
516 if (def)
517 goto error;
518 def = 1;
519 result->def = parse.idx;
dbd2fd65
JB
520 if (!parse.def_uni || !parse.def_multi)
521 goto error;
fffd0934
JB
522 } else if (parse.defmgmt)
523 goto error;
524 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 525 parse.idx, false, NULL);
fffd0934
JB
526 if (err)
527 goto error;
528 result->params[parse.idx].cipher = parse.p.cipher;
529 result->params[parse.idx].key_len = parse.p.key_len;
530 result->params[parse.idx].key = result->data[parse.idx];
531 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
532 }
533
534 return result;
535 error:
536 kfree(result);
537 return ERR_PTR(err);
538}
539
540static int nl80211_key_allowed(struct wireless_dev *wdev)
541{
542 ASSERT_WDEV_LOCK(wdev);
543
fffd0934
JB
544 switch (wdev->iftype) {
545 case NL80211_IFTYPE_AP:
546 case NL80211_IFTYPE_AP_VLAN:
074ac8df 547 case NL80211_IFTYPE_P2P_GO:
ff973af7 548 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
549 break;
550 case NL80211_IFTYPE_ADHOC:
551 if (!wdev->current_bss)
552 return -ENOLINK;
553 break;
554 case NL80211_IFTYPE_STATION:
074ac8df 555 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
556 if (wdev->sme_state != CFG80211_SME_CONNECTED)
557 return -ENOLINK;
558 break;
559 default:
560 return -EINVAL;
561 }
562
563 return 0;
564}
565
55682965
JB
566static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
567 struct cfg80211_registered_device *dev)
568{
569 void *hdr;
ee688b00
JB
570 struct nlattr *nl_bands, *nl_band;
571 struct nlattr *nl_freqs, *nl_freq;
572 struct nlattr *nl_rates, *nl_rate;
f59ac048 573 struct nlattr *nl_modes;
8fdc621d 574 struct nlattr *nl_cmds;
ee688b00
JB
575 enum ieee80211_band band;
576 struct ieee80211_channel *chan;
577 struct ieee80211_rate *rate;
578 int i;
f59ac048 579 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
580 const struct ieee80211_txrx_stypes *mgmt_stypes =
581 dev->wiphy.mgmt_stypes;
55682965
JB
582
583 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
584 if (!hdr)
585 return -1;
586
b5850a7a 587 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 588 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 589
f5ea9120
JB
590 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
591 cfg80211_rdev_list_generation);
592
b9a5f8ca
JM
593 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
594 dev->wiphy.retry_short);
595 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
596 dev->wiphy.retry_long);
597 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
598 dev->wiphy.frag_threshold);
599 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
600 dev->wiphy.rts_threshold);
81077e82
LT
601 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
602 dev->wiphy.coverage_class);
2a519311
JB
603 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
604 dev->wiphy.max_scan_ssids);
18a83659
JB
605 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
606 dev->wiphy.max_scan_ie_len);
ee688b00 607
e31b8213
JB
608 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
609 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
610 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
611 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
e31b8213 612
25e47c18
JB
613 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
614 sizeof(u32) * dev->wiphy.n_cipher_suites,
615 dev->wiphy.cipher_suites);
616
67fbb16b
SO
617 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
618 dev->wiphy.max_num_pmkids);
619
c0692b8f
JB
620 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
621 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
622
39fd5de4
BR
623 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
624 dev->wiphy.available_antennas_tx);
625 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
626 dev->wiphy.available_antennas_rx);
627
7f531e03
BR
628 if ((dev->wiphy.available_antennas_tx ||
629 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
630 u32 tx_ant = 0, rx_ant = 0;
631 int res;
632 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
633 if (!res) {
634 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
635 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
636 }
637 }
638
f59ac048
LR
639 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
640 if (!nl_modes)
641 goto nla_put_failure;
642
643 i = 0;
644 while (ifmodes) {
645 if (ifmodes & 1)
646 NLA_PUT_FLAG(msg, i);
647 ifmodes >>= 1;
648 i++;
649 }
650
651 nla_nest_end(msg, nl_modes);
652
ee688b00
JB
653 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
654 if (!nl_bands)
655 goto nla_put_failure;
656
657 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
658 if (!dev->wiphy.bands[band])
659 continue;
660
661 nl_band = nla_nest_start(msg, band);
662 if (!nl_band)
663 goto nla_put_failure;
664
d51626df
JB
665 /* add HT info */
666 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
667 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
668 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
669 &dev->wiphy.bands[band]->ht_cap.mcs);
670 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
671 dev->wiphy.bands[band]->ht_cap.cap);
672 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
673 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
674 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
675 dev->wiphy.bands[band]->ht_cap.ampdu_density);
676 }
677
ee688b00
JB
678 /* add frequencies */
679 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
680 if (!nl_freqs)
681 goto nla_put_failure;
682
683 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
684 nl_freq = nla_nest_start(msg, i);
685 if (!nl_freq)
686 goto nla_put_failure;
687
688 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
689
690 if (nl80211_msg_put_channel(msg, chan))
691 goto nla_put_failure;
e2f367f2 692
ee688b00
JB
693 nla_nest_end(msg, nl_freq);
694 }
695
696 nla_nest_end(msg, nl_freqs);
697
698 /* add bitrates */
699 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
700 if (!nl_rates)
701 goto nla_put_failure;
702
703 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
704 nl_rate = nla_nest_start(msg, i);
705 if (!nl_rate)
706 goto nla_put_failure;
707
708 rate = &dev->wiphy.bands[band]->bitrates[i];
709 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
710 rate->bitrate);
711 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
712 NLA_PUT_FLAG(msg,
713 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
714
715 nla_nest_end(msg, nl_rate);
716 }
717
718 nla_nest_end(msg, nl_rates);
719
720 nla_nest_end(msg, nl_band);
721 }
722 nla_nest_end(msg, nl_bands);
723
8fdc621d
JB
724 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
725 if (!nl_cmds)
726 goto nla_put_failure;
727
728 i = 0;
729#define CMD(op, n) \
730 do { \
731 if (dev->ops->op) { \
732 i++; \
733 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
734 } \
735 } while (0)
736
737 CMD(add_virtual_intf, NEW_INTERFACE);
738 CMD(change_virtual_intf, SET_INTERFACE);
739 CMD(add_key, NEW_KEY);
740 CMD(add_beacon, NEW_BEACON);
741 CMD(add_station, NEW_STATION);
742 CMD(add_mpath, NEW_MPATH);
24bdd9f4 743 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 744 CMD(change_bss, SET_BSS);
636a5d36
JM
745 CMD(auth, AUTHENTICATE);
746 CMD(assoc, ASSOCIATE);
747 CMD(deauth, DEAUTHENTICATE);
748 CMD(disassoc, DISASSOCIATE);
04a773ad 749 CMD(join_ibss, JOIN_IBSS);
29cbe68c 750 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
751 CMD(set_pmksa, SET_PMKSA);
752 CMD(del_pmksa, DEL_PMKSA);
753 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 754 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 755 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 756 CMD(mgmt_tx, FRAME);
f7ca38df 757 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 758 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
759 i++;
760 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
761 }
f444de05 762 CMD(set_channel, SET_CHANNEL);
e8347eba 763 CMD(set_wds_peer, SET_WDS_PEER);
8fdc621d
JB
764
765#undef CMD
b23aa676 766
6829c878 767 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
768 i++;
769 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
770 }
771
6829c878 772 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
773 i++;
774 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
775 }
776
8fdc621d
JB
777 nla_nest_end(msg, nl_cmds);
778
a293911d
JB
779 if (dev->ops->remain_on_channel)
780 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
781 dev->wiphy.max_remain_on_channel_duration);
782
f7ca38df
JB
783 /* for now at least assume all drivers have it */
784 if (dev->ops->mgmt_tx)
785 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
786
2e161f78
JB
787 if (mgmt_stypes) {
788 u16 stypes;
789 struct nlattr *nl_ftypes, *nl_ifs;
790 enum nl80211_iftype ift;
791
792 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
793 if (!nl_ifs)
794 goto nla_put_failure;
795
796 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
797 nl_ftypes = nla_nest_start(msg, ift);
798 if (!nl_ftypes)
799 goto nla_put_failure;
800 i = 0;
801 stypes = mgmt_stypes[ift].tx;
802 while (stypes) {
803 if (stypes & 1)
804 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
805 (i << 4) | IEEE80211_FTYPE_MGMT);
806 stypes >>= 1;
807 i++;
808 }
809 nla_nest_end(msg, nl_ftypes);
810 }
811
74b70a4e
JB
812 nla_nest_end(msg, nl_ifs);
813
2e161f78
JB
814 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
815 if (!nl_ifs)
816 goto nla_put_failure;
817
818 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
819 nl_ftypes = nla_nest_start(msg, ift);
820 if (!nl_ftypes)
821 goto nla_put_failure;
822 i = 0;
823 stypes = mgmt_stypes[ift].rx;
824 while (stypes) {
825 if (stypes & 1)
826 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
827 (i << 4) | IEEE80211_FTYPE_MGMT);
828 stypes >>= 1;
829 i++;
830 }
831 nla_nest_end(msg, nl_ftypes);
832 }
833 nla_nest_end(msg, nl_ifs);
834 }
835
ff1b6e69
JB
836 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
837 struct nlattr *nl_wowlan;
838
839 nl_wowlan = nla_nest_start(msg,
840 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
841 if (!nl_wowlan)
842 goto nla_put_failure;
843
844 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
845 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
846 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
847 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
848 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
849 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
850 if (dev->wiphy.wowlan.n_patterns) {
851 struct nl80211_wowlan_pattern_support pat = {
852 .max_patterns = dev->wiphy.wowlan.n_patterns,
853 .min_pattern_len =
854 dev->wiphy.wowlan.pattern_min_len,
855 .max_pattern_len =
856 dev->wiphy.wowlan.pattern_max_len,
857 };
858 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
859 sizeof(pat), &pat);
860 }
861
862 nla_nest_end(msg, nl_wowlan);
863 }
864
55682965
JB
865 return genlmsg_end(msg, hdr);
866
867 nla_put_failure:
bc3ed28c
TG
868 genlmsg_cancel(msg, hdr);
869 return -EMSGSIZE;
55682965
JB
870}
871
872static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
873{
874 int idx = 0;
875 int start = cb->args[0];
876 struct cfg80211_registered_device *dev;
877
a1794390 878 mutex_lock(&cfg80211_mutex);
79c97e97 879 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
880 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
881 continue;
b4637271 882 if (++idx <= start)
55682965
JB
883 continue;
884 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
885 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
886 dev) < 0) {
887 idx--;
55682965 888 break;
b4637271 889 }
55682965 890 }
a1794390 891 mutex_unlock(&cfg80211_mutex);
55682965
JB
892
893 cb->args[0] = idx;
894
895 return skb->len;
896}
897
898static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
899{
900 struct sk_buff *msg;
4c476991 901 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 902
fd2120ca 903 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 904 if (!msg)
4c476991 905 return -ENOMEM;
55682965 906
4c476991
JB
907 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
908 nlmsg_free(msg);
909 return -ENOBUFS;
910 }
55682965 911
134e6375 912 return genlmsg_reply(msg, info);
55682965
JB
913}
914
31888487
JM
915static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
916 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
917 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
918 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
919 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
920 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
921};
922
923static int parse_txq_params(struct nlattr *tb[],
924 struct ieee80211_txq_params *txq_params)
925{
926 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
927 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
928 !tb[NL80211_TXQ_ATTR_AIFS])
929 return -EINVAL;
930
931 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
932 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
933 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
934 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
935 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
936
937 return 0;
938}
939
f444de05
JB
940static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
941{
942 /*
943 * You can only set the channel explicitly for AP, mesh
944 * and WDS type interfaces; all others have their channel
945 * managed via their respective "establish a connection"
946 * command (connect, join, ...)
947 *
948 * Monitors are special as they are normally slaved to
949 * whatever else is going on, so they behave as though
950 * you tried setting the wiphy channel itself.
951 */
952 return !wdev ||
953 wdev->iftype == NL80211_IFTYPE_AP ||
954 wdev->iftype == NL80211_IFTYPE_WDS ||
955 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
956 wdev->iftype == NL80211_IFTYPE_MONITOR ||
957 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
958}
959
960static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
961 struct wireless_dev *wdev,
962 struct genl_info *info)
963{
964 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
965 u32 freq;
966 int result;
967
968 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
969 return -EINVAL;
970
971 if (!nl80211_can_set_dev_channel(wdev))
972 return -EOPNOTSUPP;
973
974 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
975 channel_type = nla_get_u32(info->attrs[
976 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
977 if (channel_type != NL80211_CHAN_NO_HT &&
978 channel_type != NL80211_CHAN_HT20 &&
979 channel_type != NL80211_CHAN_HT40PLUS &&
980 channel_type != NL80211_CHAN_HT40MINUS)
981 return -EINVAL;
982 }
983
984 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
985
986 mutex_lock(&rdev->devlist_mtx);
987 if (wdev) {
988 wdev_lock(wdev);
989 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
990 wdev_unlock(wdev);
991 } else {
992 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
993 }
994 mutex_unlock(&rdev->devlist_mtx);
995
996 return result;
997}
998
999static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1000{
4c476991
JB
1001 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1002 struct net_device *netdev = info->user_ptr[1];
f444de05 1003
4c476991 1004 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1005}
1006
e8347eba
BJ
1007static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1008{
43b19952
JB
1009 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1010 struct net_device *dev = info->user_ptr[1];
1011 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1012 const u8 *bssid;
e8347eba
BJ
1013
1014 if (!info->attrs[NL80211_ATTR_MAC])
1015 return -EINVAL;
1016
43b19952
JB
1017 if (netif_running(dev))
1018 return -EBUSY;
e8347eba 1019
43b19952
JB
1020 if (!rdev->ops->set_wds_peer)
1021 return -EOPNOTSUPP;
e8347eba 1022
43b19952
JB
1023 if (wdev->iftype != NL80211_IFTYPE_WDS)
1024 return -EOPNOTSUPP;
e8347eba
BJ
1025
1026 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1027 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1028}
1029
1030
55682965
JB
1031static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1032{
1033 struct cfg80211_registered_device *rdev;
f444de05
JB
1034 struct net_device *netdev = NULL;
1035 struct wireless_dev *wdev;
a1e567c8 1036 int result = 0, rem_txq_params = 0;
31888487 1037 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1038 u32 changed;
1039 u8 retry_short = 0, retry_long = 0;
1040 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1041 u8 coverage_class = 0;
55682965 1042
f444de05
JB
1043 /*
1044 * Try to find the wiphy and netdev. Normally this
1045 * function shouldn't need the netdev, but this is
1046 * done for backward compatibility -- previously
1047 * setting the channel was done per wiphy, but now
1048 * it is per netdev. Previous userland like hostapd
1049 * also passed a netdev to set_wiphy, so that it is
1050 * possible to let that go to the right netdev!
1051 */
4bbf4d56
JB
1052 mutex_lock(&cfg80211_mutex);
1053
f444de05
JB
1054 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1055 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1056
1057 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1058 if (netdev && netdev->ieee80211_ptr) {
1059 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1060 mutex_lock(&rdev->mtx);
1061 } else
1062 netdev = NULL;
4bbf4d56
JB
1063 }
1064
f444de05
JB
1065 if (!netdev) {
1066 rdev = __cfg80211_rdev_from_info(info);
1067 if (IS_ERR(rdev)) {
1068 mutex_unlock(&cfg80211_mutex);
4c476991 1069 return PTR_ERR(rdev);
f444de05
JB
1070 }
1071 wdev = NULL;
1072 netdev = NULL;
1073 result = 0;
1074
1075 mutex_lock(&rdev->mtx);
1076 } else if (netif_running(netdev) &&
1077 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1078 wdev = netdev->ieee80211_ptr;
1079 else
1080 wdev = NULL;
1081
1082 /*
1083 * end workaround code, by now the rdev is available
1084 * and locked, and wdev may or may not be NULL.
1085 */
4bbf4d56
JB
1086
1087 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1088 result = cfg80211_dev_rename(
1089 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1090
1091 mutex_unlock(&cfg80211_mutex);
1092
1093 if (result)
1094 goto bad_res;
31888487
JM
1095
1096 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1097 struct ieee80211_txq_params txq_params;
1098 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1099
1100 if (!rdev->ops->set_txq_params) {
1101 result = -EOPNOTSUPP;
1102 goto bad_res;
1103 }
1104
1105 nla_for_each_nested(nl_txq_params,
1106 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1107 rem_txq_params) {
1108 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1109 nla_data(nl_txq_params),
1110 nla_len(nl_txq_params),
1111 txq_params_policy);
1112 result = parse_txq_params(tb, &txq_params);
1113 if (result)
1114 goto bad_res;
1115
1116 result = rdev->ops->set_txq_params(&rdev->wiphy,
1117 &txq_params);
1118 if (result)
1119 goto bad_res;
1120 }
1121 }
55682965 1122
72bdcf34 1123 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1124 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1125 if (result)
1126 goto bad_res;
1127 }
1128
98d2ff8b
JO
1129 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1130 enum nl80211_tx_power_setting type;
1131 int idx, mbm = 0;
1132
1133 if (!rdev->ops->set_tx_power) {
60ea385f 1134 result = -EOPNOTSUPP;
98d2ff8b
JO
1135 goto bad_res;
1136 }
1137
1138 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1139 type = nla_get_u32(info->attrs[idx]);
1140
1141 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1142 (type != NL80211_TX_POWER_AUTOMATIC)) {
1143 result = -EINVAL;
1144 goto bad_res;
1145 }
1146
1147 if (type != NL80211_TX_POWER_AUTOMATIC) {
1148 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1149 mbm = nla_get_u32(info->attrs[idx]);
1150 }
1151
1152 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1153 if (result)
1154 goto bad_res;
1155 }
1156
afe0cbf8
BR
1157 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1158 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1159 u32 tx_ant, rx_ant;
7f531e03
BR
1160 if ((!rdev->wiphy.available_antennas_tx &&
1161 !rdev->wiphy.available_antennas_rx) ||
1162 !rdev->ops->set_antenna) {
afe0cbf8
BR
1163 result = -EOPNOTSUPP;
1164 goto bad_res;
1165 }
1166
1167 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1168 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1169
a7ffac95 1170 /* reject antenna configurations which don't match the
7f531e03
BR
1171 * available antenna masks, except for the "all" mask */
1172 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1173 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1174 result = -EINVAL;
1175 goto bad_res;
1176 }
1177
7f531e03
BR
1178 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1179 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1180
afe0cbf8
BR
1181 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1182 if (result)
1183 goto bad_res;
1184 }
1185
b9a5f8ca
JM
1186 changed = 0;
1187
1188 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1189 retry_short = nla_get_u8(
1190 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1191 if (retry_short == 0) {
1192 result = -EINVAL;
1193 goto bad_res;
1194 }
1195 changed |= WIPHY_PARAM_RETRY_SHORT;
1196 }
1197
1198 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1199 retry_long = nla_get_u8(
1200 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1201 if (retry_long == 0) {
1202 result = -EINVAL;
1203 goto bad_res;
1204 }
1205 changed |= WIPHY_PARAM_RETRY_LONG;
1206 }
1207
1208 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1209 frag_threshold = nla_get_u32(
1210 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1211 if (frag_threshold < 256) {
1212 result = -EINVAL;
1213 goto bad_res;
1214 }
1215 if (frag_threshold != (u32) -1) {
1216 /*
1217 * Fragments (apart from the last one) are required to
1218 * have even length. Make the fragmentation code
1219 * simpler by stripping LSB should someone try to use
1220 * odd threshold value.
1221 */
1222 frag_threshold &= ~0x1;
1223 }
1224 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1225 }
1226
1227 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1228 rts_threshold = nla_get_u32(
1229 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1230 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1231 }
1232
81077e82
LT
1233 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1234 coverage_class = nla_get_u8(
1235 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1236 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1237 }
1238
b9a5f8ca
JM
1239 if (changed) {
1240 u8 old_retry_short, old_retry_long;
1241 u32 old_frag_threshold, old_rts_threshold;
81077e82 1242 u8 old_coverage_class;
b9a5f8ca
JM
1243
1244 if (!rdev->ops->set_wiphy_params) {
1245 result = -EOPNOTSUPP;
1246 goto bad_res;
1247 }
1248
1249 old_retry_short = rdev->wiphy.retry_short;
1250 old_retry_long = rdev->wiphy.retry_long;
1251 old_frag_threshold = rdev->wiphy.frag_threshold;
1252 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1253 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1254
1255 if (changed & WIPHY_PARAM_RETRY_SHORT)
1256 rdev->wiphy.retry_short = retry_short;
1257 if (changed & WIPHY_PARAM_RETRY_LONG)
1258 rdev->wiphy.retry_long = retry_long;
1259 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1260 rdev->wiphy.frag_threshold = frag_threshold;
1261 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1262 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1263 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1264 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1265
1266 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1267 if (result) {
1268 rdev->wiphy.retry_short = old_retry_short;
1269 rdev->wiphy.retry_long = old_retry_long;
1270 rdev->wiphy.frag_threshold = old_frag_threshold;
1271 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1272 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1273 }
1274 }
72bdcf34 1275
306d6112 1276 bad_res:
4bbf4d56 1277 mutex_unlock(&rdev->mtx);
f444de05
JB
1278 if (netdev)
1279 dev_put(netdev);
55682965
JB
1280 return result;
1281}
1282
1283
1284static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1285 struct cfg80211_registered_device *rdev,
55682965
JB
1286 struct net_device *dev)
1287{
1288 void *hdr;
1289
1290 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1291 if (!hdr)
1292 return -1;
1293
1294 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1295 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1296 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1297 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1298
1299 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1300 rdev->devlist_generation ^
1301 (cfg80211_rdev_list_generation << 2));
1302
55682965
JB
1303 return genlmsg_end(msg, hdr);
1304
1305 nla_put_failure:
bc3ed28c
TG
1306 genlmsg_cancel(msg, hdr);
1307 return -EMSGSIZE;
55682965
JB
1308}
1309
1310static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1311{
1312 int wp_idx = 0;
1313 int if_idx = 0;
1314 int wp_start = cb->args[0];
1315 int if_start = cb->args[1];
f5ea9120 1316 struct cfg80211_registered_device *rdev;
55682965
JB
1317 struct wireless_dev *wdev;
1318
a1794390 1319 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1320 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1321 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1322 continue;
bba95fef
JB
1323 if (wp_idx < wp_start) {
1324 wp_idx++;
55682965 1325 continue;
bba95fef 1326 }
55682965
JB
1327 if_idx = 0;
1328
f5ea9120
JB
1329 mutex_lock(&rdev->devlist_mtx);
1330 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1331 if (if_idx < if_start) {
1332 if_idx++;
55682965 1333 continue;
bba95fef 1334 }
55682965
JB
1335 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1336 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1337 rdev, wdev->netdev) < 0) {
1338 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1339 goto out;
1340 }
1341 if_idx++;
55682965 1342 }
f5ea9120 1343 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1344
1345 wp_idx++;
55682965 1346 }
bba95fef 1347 out:
a1794390 1348 mutex_unlock(&cfg80211_mutex);
55682965
JB
1349
1350 cb->args[0] = wp_idx;
1351 cb->args[1] = if_idx;
1352
1353 return skb->len;
1354}
1355
1356static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1357{
1358 struct sk_buff *msg;
4c476991
JB
1359 struct cfg80211_registered_device *dev = info->user_ptr[0];
1360 struct net_device *netdev = info->user_ptr[1];
55682965 1361
fd2120ca 1362 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1363 if (!msg)
4c476991 1364 return -ENOMEM;
55682965 1365
d726405a 1366 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1367 dev, netdev) < 0) {
1368 nlmsg_free(msg);
1369 return -ENOBUFS;
1370 }
55682965 1371
134e6375 1372 return genlmsg_reply(msg, info);
55682965
JB
1373}
1374
66f7ac50
MW
1375static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1376 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1377 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1378 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1379 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1380 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1381};
1382
1383static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1384{
1385 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1386 int flag;
1387
1388 *mntrflags = 0;
1389
1390 if (!nla)
1391 return -EINVAL;
1392
1393 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1394 nla, mntr_flags_policy))
1395 return -EINVAL;
1396
1397 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1398 if (flags[flag])
1399 *mntrflags |= (1<<flag);
1400
1401 return 0;
1402}
1403
9bc383de 1404static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1405 struct net_device *netdev, u8 use_4addr,
1406 enum nl80211_iftype iftype)
9bc383de 1407{
ad4bb6f8 1408 if (!use_4addr) {
f350a0a8 1409 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1410 return -EBUSY;
9bc383de 1411 return 0;
ad4bb6f8 1412 }
9bc383de
JB
1413
1414 switch (iftype) {
1415 case NL80211_IFTYPE_AP_VLAN:
1416 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1417 return 0;
1418 break;
1419 case NL80211_IFTYPE_STATION:
1420 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1421 return 0;
1422 break;
1423 default:
1424 break;
1425 }
1426
1427 return -EOPNOTSUPP;
1428}
1429
55682965
JB
1430static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1431{
4c476991 1432 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1433 struct vif_params params;
e36d56b6 1434 int err;
04a773ad 1435 enum nl80211_iftype otype, ntype;
4c476991 1436 struct net_device *dev = info->user_ptr[1];
92ffe055 1437 u32 _flags, *flags = NULL;
ac7f9cfa 1438 bool change = false;
55682965 1439
2ec600d6
LCC
1440 memset(&params, 0, sizeof(params));
1441
04a773ad 1442 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1443
723b038d 1444 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1445 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1446 if (otype != ntype)
ac7f9cfa 1447 change = true;
4c476991
JB
1448 if (ntype > NL80211_IFTYPE_MAX)
1449 return -EINVAL;
723b038d
JB
1450 }
1451
92ffe055 1452 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1453 struct wireless_dev *wdev = dev->ieee80211_ptr;
1454
4c476991
JB
1455 if (ntype != NL80211_IFTYPE_MESH_POINT)
1456 return -EINVAL;
29cbe68c
JB
1457 if (netif_running(dev))
1458 return -EBUSY;
1459
1460 wdev_lock(wdev);
1461 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1462 IEEE80211_MAX_MESH_ID_LEN);
1463 wdev->mesh_id_up_len =
1464 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1465 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1466 wdev->mesh_id_up_len);
1467 wdev_unlock(wdev);
2ec600d6
LCC
1468 }
1469
8b787643
FF
1470 if (info->attrs[NL80211_ATTR_4ADDR]) {
1471 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1472 change = true;
ad4bb6f8 1473 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1474 if (err)
4c476991 1475 return err;
8b787643
FF
1476 } else {
1477 params.use_4addr = -1;
1478 }
1479
92ffe055 1480 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1481 if (ntype != NL80211_IFTYPE_MONITOR)
1482 return -EINVAL;
92ffe055
JB
1483 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1484 &_flags);
ac7f9cfa 1485 if (err)
4c476991 1486 return err;
ac7f9cfa
JB
1487
1488 flags = &_flags;
1489 change = true;
92ffe055 1490 }
3b85875a 1491
ac7f9cfa 1492 if (change)
3d54d255 1493 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1494 else
1495 err = 0;
60719ffd 1496
9bc383de
JB
1497 if (!err && params.use_4addr != -1)
1498 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1499
55682965
JB
1500 return err;
1501}
1502
1503static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1504{
4c476991 1505 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1506 struct vif_params params;
f9e10ce4 1507 struct net_device *dev;
55682965
JB
1508 int err;
1509 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1510 u32 flags;
55682965 1511
2ec600d6
LCC
1512 memset(&params, 0, sizeof(params));
1513
55682965
JB
1514 if (!info->attrs[NL80211_ATTR_IFNAME])
1515 return -EINVAL;
1516
1517 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1518 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1519 if (type > NL80211_IFTYPE_MAX)
1520 return -EINVAL;
1521 }
1522
79c97e97 1523 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1524 !(rdev->wiphy.interface_modes & (1 << type)))
1525 return -EOPNOTSUPP;
55682965 1526
9bc383de 1527 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1528 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1529 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1530 if (err)
4c476991 1531 return err;
9bc383de 1532 }
8b787643 1533
66f7ac50
MW
1534 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1535 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1536 &flags);
f9e10ce4 1537 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1538 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1539 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1540 if (IS_ERR(dev))
1541 return PTR_ERR(dev);
2ec600d6 1542
29cbe68c
JB
1543 if (type == NL80211_IFTYPE_MESH_POINT &&
1544 info->attrs[NL80211_ATTR_MESH_ID]) {
1545 struct wireless_dev *wdev = dev->ieee80211_ptr;
1546
1547 wdev_lock(wdev);
1548 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1549 IEEE80211_MAX_MESH_ID_LEN);
1550 wdev->mesh_id_up_len =
1551 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1552 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1553 wdev->mesh_id_up_len);
1554 wdev_unlock(wdev);
1555 }
1556
f9e10ce4 1557 return 0;
55682965
JB
1558}
1559
1560static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1561{
4c476991
JB
1562 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1563 struct net_device *dev = info->user_ptr[1];
55682965 1564
4c476991
JB
1565 if (!rdev->ops->del_virtual_intf)
1566 return -EOPNOTSUPP;
55682965 1567
4c476991 1568 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1569}
1570
41ade00f
JB
1571struct get_key_cookie {
1572 struct sk_buff *msg;
1573 int error;
b9454e83 1574 int idx;
41ade00f
JB
1575};
1576
1577static void get_key_callback(void *c, struct key_params *params)
1578{
b9454e83 1579 struct nlattr *key;
41ade00f
JB
1580 struct get_key_cookie *cookie = c;
1581
1582 if (params->key)
1583 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1584 params->key_len, params->key);
1585
1586 if (params->seq)
1587 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1588 params->seq_len, params->seq);
1589
1590 if (params->cipher)
1591 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1592 params->cipher);
1593
b9454e83
JB
1594 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1595 if (!key)
1596 goto nla_put_failure;
1597
1598 if (params->key)
1599 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1600 params->key_len, params->key);
1601
1602 if (params->seq)
1603 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1604 params->seq_len, params->seq);
1605
1606 if (params->cipher)
1607 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1608 params->cipher);
1609
1610 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1611
1612 nla_nest_end(cookie->msg, key);
1613
41ade00f
JB
1614 return;
1615 nla_put_failure:
1616 cookie->error = 1;
1617}
1618
1619static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1620{
4c476991 1621 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1622 int err;
4c476991 1623 struct net_device *dev = info->user_ptr[1];
41ade00f 1624 u8 key_idx = 0;
e31b8213
JB
1625 const u8 *mac_addr = NULL;
1626 bool pairwise;
41ade00f
JB
1627 struct get_key_cookie cookie = {
1628 .error = 0,
1629 };
1630 void *hdr;
1631 struct sk_buff *msg;
1632
1633 if (info->attrs[NL80211_ATTR_KEY_IDX])
1634 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1635
3cfcf6ac 1636 if (key_idx > 5)
41ade00f
JB
1637 return -EINVAL;
1638
1639 if (info->attrs[NL80211_ATTR_MAC])
1640 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1641
e31b8213
JB
1642 pairwise = !!mac_addr;
1643 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1644 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1645 if (kt >= NUM_NL80211_KEYTYPES)
1646 return -EINVAL;
1647 if (kt != NL80211_KEYTYPE_GROUP &&
1648 kt != NL80211_KEYTYPE_PAIRWISE)
1649 return -EINVAL;
1650 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1651 }
1652
4c476991
JB
1653 if (!rdev->ops->get_key)
1654 return -EOPNOTSUPP;
41ade00f 1655
fd2120ca 1656 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1657 if (!msg)
1658 return -ENOMEM;
41ade00f
JB
1659
1660 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1661 NL80211_CMD_NEW_KEY);
4c476991
JB
1662 if (IS_ERR(hdr))
1663 return PTR_ERR(hdr);
41ade00f
JB
1664
1665 cookie.msg = msg;
b9454e83 1666 cookie.idx = key_idx;
41ade00f
JB
1667
1668 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1669 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1670 if (mac_addr)
1671 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1672
e31b8213
JB
1673 if (pairwise && mac_addr &&
1674 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1675 return -ENOENT;
1676
1677 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1678 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1679
1680 if (err)
6c95e2a2 1681 goto free_msg;
41ade00f
JB
1682
1683 if (cookie.error)
1684 goto nla_put_failure;
1685
1686 genlmsg_end(msg, hdr);
4c476991 1687 return genlmsg_reply(msg, info);
41ade00f
JB
1688
1689 nla_put_failure:
1690 err = -ENOBUFS;
6c95e2a2 1691 free_msg:
41ade00f 1692 nlmsg_free(msg);
41ade00f
JB
1693 return err;
1694}
1695
1696static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1697{
4c476991 1698 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1699 struct key_parse key;
41ade00f 1700 int err;
4c476991 1701 struct net_device *dev = info->user_ptr[1];
41ade00f 1702
b9454e83
JB
1703 err = nl80211_parse_key(info, &key);
1704 if (err)
1705 return err;
41ade00f 1706
b9454e83 1707 if (key.idx < 0)
41ade00f
JB
1708 return -EINVAL;
1709
b9454e83
JB
1710 /* only support setting default key */
1711 if (!key.def && !key.defmgmt)
41ade00f
JB
1712 return -EINVAL;
1713
dbd2fd65 1714 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1715
dbd2fd65
JB
1716 if (key.def) {
1717 if (!rdev->ops->set_default_key) {
1718 err = -EOPNOTSUPP;
1719 goto out;
1720 }
41ade00f 1721
dbd2fd65
JB
1722 err = nl80211_key_allowed(dev->ieee80211_ptr);
1723 if (err)
1724 goto out;
1725
dbd2fd65
JB
1726 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1727 key.def_uni, key.def_multi);
1728
1729 if (err)
1730 goto out;
fffd0934 1731
3d23e349 1732#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1733 dev->ieee80211_ptr->wext.default_key = key.idx;
1734#endif
1735 } else {
1736 if (key.def_uni || !key.def_multi) {
1737 err = -EINVAL;
1738 goto out;
1739 }
1740
1741 if (!rdev->ops->set_default_mgmt_key) {
1742 err = -EOPNOTSUPP;
1743 goto out;
1744 }
1745
1746 err = nl80211_key_allowed(dev->ieee80211_ptr);
1747 if (err)
1748 goto out;
1749
1750 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1751 dev, key.idx);
1752 if (err)
1753 goto out;
1754
1755#ifdef CONFIG_CFG80211_WEXT
1756 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1757#endif
dbd2fd65
JB
1758 }
1759
1760 out:
fffd0934 1761 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1762
41ade00f
JB
1763 return err;
1764}
1765
1766static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1767{
4c476991 1768 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1769 int err;
4c476991 1770 struct net_device *dev = info->user_ptr[1];
b9454e83 1771 struct key_parse key;
e31b8213 1772 const u8 *mac_addr = NULL;
41ade00f 1773
b9454e83
JB
1774 err = nl80211_parse_key(info, &key);
1775 if (err)
1776 return err;
41ade00f 1777
b9454e83 1778 if (!key.p.key)
41ade00f
JB
1779 return -EINVAL;
1780
41ade00f
JB
1781 if (info->attrs[NL80211_ATTR_MAC])
1782 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1783
e31b8213
JB
1784 if (key.type == -1) {
1785 if (mac_addr)
1786 key.type = NL80211_KEYTYPE_PAIRWISE;
1787 else
1788 key.type = NL80211_KEYTYPE_GROUP;
1789 }
1790
1791 /* for now */
1792 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1793 key.type != NL80211_KEYTYPE_GROUP)
1794 return -EINVAL;
1795
4c476991
JB
1796 if (!rdev->ops->add_key)
1797 return -EOPNOTSUPP;
25e47c18 1798
e31b8213
JB
1799 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1800 key.type == NL80211_KEYTYPE_PAIRWISE,
1801 mac_addr))
4c476991 1802 return -EINVAL;
41ade00f 1803
fffd0934
JB
1804 wdev_lock(dev->ieee80211_ptr);
1805 err = nl80211_key_allowed(dev->ieee80211_ptr);
1806 if (!err)
1807 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1808 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1809 mac_addr, &key.p);
1810 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1811
41ade00f
JB
1812 return err;
1813}
1814
1815static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1816{
4c476991 1817 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1818 int err;
4c476991 1819 struct net_device *dev = info->user_ptr[1];
41ade00f 1820 u8 *mac_addr = NULL;
b9454e83 1821 struct key_parse key;
41ade00f 1822
b9454e83
JB
1823 err = nl80211_parse_key(info, &key);
1824 if (err)
1825 return err;
41ade00f
JB
1826
1827 if (info->attrs[NL80211_ATTR_MAC])
1828 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1829
e31b8213
JB
1830 if (key.type == -1) {
1831 if (mac_addr)
1832 key.type = NL80211_KEYTYPE_PAIRWISE;
1833 else
1834 key.type = NL80211_KEYTYPE_GROUP;
1835 }
1836
1837 /* for now */
1838 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1839 key.type != NL80211_KEYTYPE_GROUP)
1840 return -EINVAL;
1841
4c476991
JB
1842 if (!rdev->ops->del_key)
1843 return -EOPNOTSUPP;
41ade00f 1844
fffd0934
JB
1845 wdev_lock(dev->ieee80211_ptr);
1846 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
1847
1848 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1849 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1850 err = -ENOENT;
1851
fffd0934 1852 if (!err)
e31b8213
JB
1853 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1854 key.type == NL80211_KEYTYPE_PAIRWISE,
1855 mac_addr);
41ade00f 1856
3d23e349 1857#ifdef CONFIG_CFG80211_WEXT
08645126 1858 if (!err) {
b9454e83 1859 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1860 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1861 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1862 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1863 }
1864#endif
fffd0934 1865 wdev_unlock(dev->ieee80211_ptr);
08645126 1866
41ade00f
JB
1867 return err;
1868}
1869
ed1b6cc7
JB
1870static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1871{
1872 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1873 struct beacon_parameters *info);
4c476991
JB
1874 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1875 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1876 struct beacon_parameters params;
1877 int haveinfo = 0;
1878
f4a11bb0
JB
1879 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1880 return -EINVAL;
1881
074ac8df 1882 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1883 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1884 return -EOPNOTSUPP;
eec60b03 1885
ed1b6cc7
JB
1886 switch (info->genlhdr->cmd) {
1887 case NL80211_CMD_NEW_BEACON:
1888 /* these are required for NEW_BEACON */
1889 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1890 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1891 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1892 return -EINVAL;
ed1b6cc7 1893
79c97e97 1894 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1895 break;
1896 case NL80211_CMD_SET_BEACON:
79c97e97 1897 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1898 break;
1899 default:
1900 WARN_ON(1);
4c476991 1901 return -EOPNOTSUPP;
ed1b6cc7
JB
1902 }
1903
4c476991
JB
1904 if (!call)
1905 return -EOPNOTSUPP;
ed1b6cc7
JB
1906
1907 memset(&params, 0, sizeof(params));
1908
1909 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1910 params.interval =
1911 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1912 haveinfo = 1;
1913 }
1914
1915 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1916 params.dtim_period =
1917 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1918 haveinfo = 1;
1919 }
1920
1921 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1922 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1923 params.head_len =
1924 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1925 haveinfo = 1;
1926 }
1927
1928 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1929 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1930 params.tail_len =
1931 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1932 haveinfo = 1;
1933 }
1934
4c476991
JB
1935 if (!haveinfo)
1936 return -EINVAL;
3b85875a 1937
4c476991 1938 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1939}
1940
1941static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1942{
4c476991
JB
1943 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1944 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1945
4c476991
JB
1946 if (!rdev->ops->del_beacon)
1947 return -EOPNOTSUPP;
ed1b6cc7 1948
074ac8df 1949 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1950 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1951 return -EOPNOTSUPP;
3b85875a 1952
4c476991 1953 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1954}
1955
5727ef1b
JB
1956static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1957 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1958 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1959 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1960 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 1961 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
5727ef1b
JB
1962};
1963
eccb8e8f
JB
1964static int parse_station_flags(struct genl_info *info,
1965 struct station_parameters *params)
5727ef1b
JB
1966{
1967 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1968 struct nlattr *nla;
5727ef1b
JB
1969 int flag;
1970
eccb8e8f
JB
1971 /*
1972 * Try parsing the new attribute first so userspace
1973 * can specify both for older kernels.
1974 */
1975 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1976 if (nla) {
1977 struct nl80211_sta_flag_update *sta_flags;
1978
1979 sta_flags = nla_data(nla);
1980 params->sta_flags_mask = sta_flags->mask;
1981 params->sta_flags_set = sta_flags->set;
1982 if ((params->sta_flags_mask |
1983 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1984 return -EINVAL;
1985 return 0;
1986 }
1987
1988 /* if present, parse the old attribute */
5727ef1b 1989
eccb8e8f 1990 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1991 if (!nla)
1992 return 0;
1993
1994 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1995 nla, sta_flags_policy))
1996 return -EINVAL;
1997
eccb8e8f
JB
1998 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1999 params->sta_flags_mask &= ~1;
5727ef1b
JB
2000
2001 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2002 if (flags[flag])
eccb8e8f 2003 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2004
2005 return 0;
2006}
2007
c8dcfd8a
FF
2008static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2009 int attr)
2010{
2011 struct nlattr *rate;
2012 u16 bitrate;
2013
2014 rate = nla_nest_start(msg, attr);
2015 if (!rate)
2016 goto nla_put_failure;
2017
2018 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2019 bitrate = cfg80211_calculate_bitrate(info);
2020 if (bitrate > 0)
2021 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2022
2023 if (info->flags & RATE_INFO_FLAGS_MCS)
2024 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2025 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2026 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2027 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2028 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2029
2030 nla_nest_end(msg, rate);
2031 return true;
2032
2033nla_put_failure:
2034 return false;
2035}
2036
fd5b74dc
JB
2037static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2038 int flags, struct net_device *dev,
98b62183 2039 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2040{
2041 void *hdr;
f4263c98 2042 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2043
2044 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2045 if (!hdr)
2046 return -1;
2047
2048 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2049 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2050
f5ea9120
JB
2051 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2052
2ec600d6
LCC
2053 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2054 if (!sinfoattr)
fd5b74dc 2055 goto nla_put_failure;
ebe27c91
MSS
2056 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2057 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2058 sinfo->connected_time);
2ec600d6
LCC
2059 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2060 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2061 sinfo->inactive_time);
2062 if (sinfo->filled & STATION_INFO_RX_BYTES)
2063 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2064 sinfo->rx_bytes);
2065 if (sinfo->filled & STATION_INFO_TX_BYTES)
2066 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2067 sinfo->tx_bytes);
2068 if (sinfo->filled & STATION_INFO_LLID)
2069 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2070 sinfo->llid);
2071 if (sinfo->filled & STATION_INFO_PLID)
2072 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2073 sinfo->plid);
2074 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2075 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2076 sinfo->plink_state);
420e7fab
HR
2077 if (sinfo->filled & STATION_INFO_SIGNAL)
2078 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2079 sinfo->signal);
541a45a1
BR
2080 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2081 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2082 sinfo->signal_avg);
420e7fab 2083 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2084 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2085 NL80211_STA_INFO_TX_BITRATE))
2086 goto nla_put_failure;
2087 }
2088 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2089 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2090 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2091 goto nla_put_failure;
420e7fab 2092 }
98c8a60a
JM
2093 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2094 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2095 sinfo->rx_packets);
2096 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2097 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2098 sinfo->tx_packets);
b206b4ef
BR
2099 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2100 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2101 sinfo->tx_retries);
2102 if (sinfo->filled & STATION_INFO_TX_FAILED)
2103 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2104 sinfo->tx_failed);
f4263c98
PS
2105 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2106 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2107 if (!bss_param)
2108 goto nla_put_failure;
2109
2110 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2111 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2112 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2113 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2114 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2115 NLA_PUT_FLAG(msg,
2116 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2117 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2118 sinfo->bss_param.dtim_period);
2119 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2120 sinfo->bss_param.beacon_interval);
2121
2122 nla_nest_end(msg, bss_param);
2123 }
2ec600d6 2124 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
2125
2126 return genlmsg_end(msg, hdr);
2127
2128 nla_put_failure:
bc3ed28c
TG
2129 genlmsg_cancel(msg, hdr);
2130 return -EMSGSIZE;
fd5b74dc
JB
2131}
2132
2ec600d6 2133static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2134 struct netlink_callback *cb)
2ec600d6 2135{
2ec600d6
LCC
2136 struct station_info sinfo;
2137 struct cfg80211_registered_device *dev;
bba95fef 2138 struct net_device *netdev;
2ec600d6 2139 u8 mac_addr[ETH_ALEN];
bba95fef 2140 int sta_idx = cb->args[1];
2ec600d6 2141 int err;
2ec600d6 2142
67748893
JB
2143 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2144 if (err)
2145 return err;
bba95fef
JB
2146
2147 if (!dev->ops->dump_station) {
eec60b03 2148 err = -EOPNOTSUPP;
bba95fef
JB
2149 goto out_err;
2150 }
2151
bba95fef
JB
2152 while (1) {
2153 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2154 mac_addr, &sinfo);
2155 if (err == -ENOENT)
2156 break;
2157 if (err)
3b85875a 2158 goto out_err;
bba95fef
JB
2159
2160 if (nl80211_send_station(skb,
2161 NETLINK_CB(cb->skb).pid,
2162 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2163 netdev, mac_addr,
2164 &sinfo) < 0)
2165 goto out;
2166
2167 sta_idx++;
2168 }
2169
2170
2171 out:
2172 cb->args[1] = sta_idx;
2173 err = skb->len;
bba95fef 2174 out_err:
67748893 2175 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2176
2177 return err;
2ec600d6 2178}
fd5b74dc 2179
5727ef1b
JB
2180static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2181{
4c476991
JB
2182 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2183 struct net_device *dev = info->user_ptr[1];
2ec600d6 2184 struct station_info sinfo;
fd5b74dc
JB
2185 struct sk_buff *msg;
2186 u8 *mac_addr = NULL;
4c476991 2187 int err;
fd5b74dc 2188
2ec600d6 2189 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2190
2191 if (!info->attrs[NL80211_ATTR_MAC])
2192 return -EINVAL;
2193
2194 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2195
4c476991
JB
2196 if (!rdev->ops->get_station)
2197 return -EOPNOTSUPP;
3b85875a 2198
4c476991 2199 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2200 if (err)
4c476991 2201 return err;
2ec600d6 2202
fd2120ca 2203 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2204 if (!msg)
4c476991 2205 return -ENOMEM;
fd5b74dc
JB
2206
2207 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2208 dev, mac_addr, &sinfo) < 0) {
2209 nlmsg_free(msg);
2210 return -ENOBUFS;
2211 }
3b85875a 2212
4c476991 2213 return genlmsg_reply(msg, info);
5727ef1b
JB
2214}
2215
2216/*
c258d2de 2217 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2218 */
463d0183 2219static int get_vlan(struct genl_info *info,
5727ef1b
JB
2220 struct cfg80211_registered_device *rdev,
2221 struct net_device **vlan)
2222{
463d0183 2223 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2224 *vlan = NULL;
2225
2226 if (vlanattr) {
463d0183
JB
2227 *vlan = dev_get_by_index(genl_info_net(info),
2228 nla_get_u32(vlanattr));
5727ef1b
JB
2229 if (!*vlan)
2230 return -ENODEV;
2231 if (!(*vlan)->ieee80211_ptr)
2232 return -EINVAL;
2233 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2234 return -EINVAL;
c258d2de
FF
2235 if (!netif_running(*vlan))
2236 return -ENETDOWN;
5727ef1b
JB
2237 }
2238 return 0;
2239}
2240
2241static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2242{
4c476991 2243 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2244 int err;
4c476991 2245 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2246 struct station_parameters params;
2247 u8 *mac_addr = NULL;
2248
2249 memset(&params, 0, sizeof(params));
2250
2251 params.listen_interval = -1;
9c3990aa 2252 params.plink_state = PLINK_INVALID;
5727ef1b
JB
2253
2254 if (info->attrs[NL80211_ATTR_STA_AID])
2255 return -EINVAL;
2256
2257 if (!info->attrs[NL80211_ATTR_MAC])
2258 return -EINVAL;
2259
2260 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2261
2262 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2263 params.supported_rates =
2264 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2265 params.supported_rates_len =
2266 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2267 }
2268
2269 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2270 params.listen_interval =
2271 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2272
36aedc90
JM
2273 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2274 params.ht_capa =
2275 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2276
eccb8e8f 2277 if (parse_station_flags(info, &params))
5727ef1b
JB
2278 return -EINVAL;
2279
2ec600d6
LCC
2280 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2281 params.plink_action =
2282 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2283
9c3990aa
JC
2284 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2285 params.plink_state =
2286 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2287
463d0183 2288 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2289 if (err)
034d655e 2290 goto out;
a97f4424
JB
2291
2292 /* validate settings */
2293 err = 0;
2294
2295 switch (dev->ieee80211_ptr->iftype) {
2296 case NL80211_IFTYPE_AP:
2297 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2298 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2299 /* disallow mesh-specific things */
2300 if (params.plink_action)
2301 err = -EINVAL;
2302 break;
074ac8df 2303 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2304 case NL80211_IFTYPE_STATION:
2305 /* disallow everything but AUTHORIZED flag */
2306 if (params.plink_action)
2307 err = -EINVAL;
2308 if (params.vlan)
2309 err = -EINVAL;
2310 if (params.supported_rates)
2311 err = -EINVAL;
2312 if (params.ht_capa)
2313 err = -EINVAL;
2314 if (params.listen_interval >= 0)
2315 err = -EINVAL;
2316 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2317 err = -EINVAL;
2318 break;
2319 case NL80211_IFTYPE_MESH_POINT:
2320 /* disallow things mesh doesn't support */
2321 if (params.vlan)
2322 err = -EINVAL;
2323 if (params.ht_capa)
2324 err = -EINVAL;
2325 if (params.listen_interval >= 0)
2326 err = -EINVAL;
b39c48fa
JC
2327 if (params.sta_flags_mask &
2328 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2329 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2330 BIT(NL80211_STA_FLAG_AUTHORIZED)))
a97f4424
JB
2331 err = -EINVAL;
2332 break;
2333 default:
2334 err = -EINVAL;
034d655e
JB
2335 }
2336
5727ef1b
JB
2337 if (err)
2338 goto out;
2339
79c97e97 2340 if (!rdev->ops->change_station) {
5727ef1b
JB
2341 err = -EOPNOTSUPP;
2342 goto out;
2343 }
2344
79c97e97 2345 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2346
2347 out:
2348 if (params.vlan)
2349 dev_put(params.vlan);
3b85875a 2350
5727ef1b
JB
2351 return err;
2352}
2353
2354static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2355{
4c476991 2356 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2357 int err;
4c476991 2358 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2359 struct station_parameters params;
2360 u8 *mac_addr = NULL;
2361
2362 memset(&params, 0, sizeof(params));
2363
2364 if (!info->attrs[NL80211_ATTR_MAC])
2365 return -EINVAL;
2366
5727ef1b
JB
2367 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2368 return -EINVAL;
2369
2370 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2371 return -EINVAL;
2372
0e956c13
TLSC
2373 if (!info->attrs[NL80211_ATTR_STA_AID])
2374 return -EINVAL;
2375
5727ef1b
JB
2376 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2377 params.supported_rates =
2378 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2379 params.supported_rates_len =
2380 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2381 params.listen_interval =
2382 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2383
0e956c13
TLSC
2384 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2385 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2386 return -EINVAL;
51b50fbe 2387
36aedc90
JM
2388 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2389 params.ht_capa =
2390 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2391
96b78dff
JC
2392 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2393 params.plink_action =
2394 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2395
eccb8e8f 2396 if (parse_station_flags(info, &params))
5727ef1b
JB
2397 return -EINVAL;
2398
0e956c13 2399 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2400 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
96b78dff 2401 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2402 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2403 return -EINVAL;
0e956c13 2404
463d0183 2405 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2406 if (err)
e80cf853 2407 goto out;
a97f4424
JB
2408
2409 /* validate settings */
2410 err = 0;
2411
79c97e97 2412 if (!rdev->ops->add_station) {
5727ef1b
JB
2413 err = -EOPNOTSUPP;
2414 goto out;
2415 }
2416
79c97e97 2417 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2418
2419 out:
2420 if (params.vlan)
2421 dev_put(params.vlan);
5727ef1b
JB
2422 return err;
2423}
2424
2425static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2426{
4c476991
JB
2427 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2428 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2429 u8 *mac_addr = NULL;
2430
2431 if (info->attrs[NL80211_ATTR_MAC])
2432 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2433
e80cf853 2434 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2435 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2436 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2437 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2438 return -EINVAL;
5727ef1b 2439
4c476991
JB
2440 if (!rdev->ops->del_station)
2441 return -EOPNOTSUPP;
3b85875a 2442
4c476991 2443 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2444}
2445
2ec600d6
LCC
2446static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2447 int flags, struct net_device *dev,
2448 u8 *dst, u8 *next_hop,
2449 struct mpath_info *pinfo)
2450{
2451 void *hdr;
2452 struct nlattr *pinfoattr;
2453
2454 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2455 if (!hdr)
2456 return -1;
2457
2458 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2459 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2460 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2461
f5ea9120
JB
2462 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2463
2ec600d6
LCC
2464 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2465 if (!pinfoattr)
2466 goto nla_put_failure;
2467 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2468 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2469 pinfo->frame_qlen);
d19b3bf6
RP
2470 if (pinfo->filled & MPATH_INFO_SN)
2471 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2472 pinfo->sn);
2ec600d6
LCC
2473 if (pinfo->filled & MPATH_INFO_METRIC)
2474 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2475 pinfo->metric);
2476 if (pinfo->filled & MPATH_INFO_EXPTIME)
2477 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2478 pinfo->exptime);
2479 if (pinfo->filled & MPATH_INFO_FLAGS)
2480 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2481 pinfo->flags);
2482 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2483 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2484 pinfo->discovery_timeout);
2485 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2486 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2487 pinfo->discovery_retries);
2488
2489 nla_nest_end(msg, pinfoattr);
2490
2491 return genlmsg_end(msg, hdr);
2492
2493 nla_put_failure:
bc3ed28c
TG
2494 genlmsg_cancel(msg, hdr);
2495 return -EMSGSIZE;
2ec600d6
LCC
2496}
2497
2498static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2499 struct netlink_callback *cb)
2ec600d6 2500{
2ec600d6
LCC
2501 struct mpath_info pinfo;
2502 struct cfg80211_registered_device *dev;
bba95fef 2503 struct net_device *netdev;
2ec600d6
LCC
2504 u8 dst[ETH_ALEN];
2505 u8 next_hop[ETH_ALEN];
bba95fef 2506 int path_idx = cb->args[1];
2ec600d6 2507 int err;
2ec600d6 2508
67748893
JB
2509 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2510 if (err)
2511 return err;
bba95fef
JB
2512
2513 if (!dev->ops->dump_mpath) {
eec60b03 2514 err = -EOPNOTSUPP;
bba95fef
JB
2515 goto out_err;
2516 }
2517
eec60b03
JM
2518 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2519 err = -EOPNOTSUPP;
0448b5fc 2520 goto out_err;
eec60b03
JM
2521 }
2522
bba95fef
JB
2523 while (1) {
2524 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2525 dst, next_hop, &pinfo);
2526 if (err == -ENOENT)
2ec600d6 2527 break;
bba95fef 2528 if (err)
3b85875a 2529 goto out_err;
2ec600d6 2530
bba95fef
JB
2531 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2532 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2533 netdev, dst, next_hop,
2534 &pinfo) < 0)
2535 goto out;
2ec600d6 2536
bba95fef 2537 path_idx++;
2ec600d6 2538 }
2ec600d6 2539
2ec600d6 2540
bba95fef
JB
2541 out:
2542 cb->args[1] = path_idx;
2543 err = skb->len;
bba95fef 2544 out_err:
67748893 2545 nl80211_finish_netdev_dump(dev);
bba95fef 2546 return err;
2ec600d6
LCC
2547}
2548
2549static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2550{
4c476991 2551 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2552 int err;
4c476991 2553 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2554 struct mpath_info pinfo;
2555 struct sk_buff *msg;
2556 u8 *dst = NULL;
2557 u8 next_hop[ETH_ALEN];
2558
2559 memset(&pinfo, 0, sizeof(pinfo));
2560
2561 if (!info->attrs[NL80211_ATTR_MAC])
2562 return -EINVAL;
2563
2564 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2565
4c476991
JB
2566 if (!rdev->ops->get_mpath)
2567 return -EOPNOTSUPP;
2ec600d6 2568
4c476991
JB
2569 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2570 return -EOPNOTSUPP;
eec60b03 2571
79c97e97 2572 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2573 if (err)
4c476991 2574 return err;
2ec600d6 2575
fd2120ca 2576 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2577 if (!msg)
4c476991 2578 return -ENOMEM;
2ec600d6
LCC
2579
2580 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2581 dev, dst, next_hop, &pinfo) < 0) {
2582 nlmsg_free(msg);
2583 return -ENOBUFS;
2584 }
3b85875a 2585
4c476991 2586 return genlmsg_reply(msg, info);
2ec600d6
LCC
2587}
2588
2589static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2590{
4c476991
JB
2591 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2592 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2593 u8 *dst = NULL;
2594 u8 *next_hop = NULL;
2595
2596 if (!info->attrs[NL80211_ATTR_MAC])
2597 return -EINVAL;
2598
2599 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2600 return -EINVAL;
2601
2602 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2603 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2604
4c476991
JB
2605 if (!rdev->ops->change_mpath)
2606 return -EOPNOTSUPP;
35a8efe1 2607
4c476991
JB
2608 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2609 return -EOPNOTSUPP;
2ec600d6 2610
4c476991 2611 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2612}
4c476991 2613
2ec600d6
LCC
2614static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2615{
4c476991
JB
2616 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2617 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2618 u8 *dst = NULL;
2619 u8 *next_hop = NULL;
2620
2621 if (!info->attrs[NL80211_ATTR_MAC])
2622 return -EINVAL;
2623
2624 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2625 return -EINVAL;
2626
2627 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2628 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2629
4c476991
JB
2630 if (!rdev->ops->add_mpath)
2631 return -EOPNOTSUPP;
35a8efe1 2632
4c476991
JB
2633 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2634 return -EOPNOTSUPP;
2ec600d6 2635
4c476991 2636 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2637}
2638
2639static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2640{
4c476991
JB
2641 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2642 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2643 u8 *dst = NULL;
2644
2645 if (info->attrs[NL80211_ATTR_MAC])
2646 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2647
4c476991
JB
2648 if (!rdev->ops->del_mpath)
2649 return -EOPNOTSUPP;
3b85875a 2650
4c476991 2651 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2652}
2653
9f1ba906
JM
2654static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2655{
4c476991
JB
2656 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2657 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2658 struct bss_parameters params;
2659
2660 memset(&params, 0, sizeof(params));
2661 /* default to not changing parameters */
2662 params.use_cts_prot = -1;
2663 params.use_short_preamble = -1;
2664 params.use_short_slot_time = -1;
fd8aaaf3 2665 params.ap_isolate = -1;
50b12f59 2666 params.ht_opmode = -1;
9f1ba906
JM
2667
2668 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2669 params.use_cts_prot =
2670 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2671 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2672 params.use_short_preamble =
2673 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2674 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2675 params.use_short_slot_time =
2676 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2677 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2678 params.basic_rates =
2679 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2680 params.basic_rates_len =
2681 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2682 }
fd8aaaf3
FF
2683 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2684 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2685 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2686 params.ht_opmode =
2687 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2688
4c476991
JB
2689 if (!rdev->ops->change_bss)
2690 return -EOPNOTSUPP;
9f1ba906 2691
074ac8df 2692 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2693 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2694 return -EOPNOTSUPP;
3b85875a 2695
4c476991 2696 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2697}
2698
b54452b0 2699static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2700 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2701 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2702 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2703 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2704 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2705 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2706};
2707
2708static int parse_reg_rule(struct nlattr *tb[],
2709 struct ieee80211_reg_rule *reg_rule)
2710{
2711 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2712 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2713
2714 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2715 return -EINVAL;
2716 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2717 return -EINVAL;
2718 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2719 return -EINVAL;
2720 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2721 return -EINVAL;
2722 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2723 return -EINVAL;
2724
2725 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2726
2727 freq_range->start_freq_khz =
2728 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2729 freq_range->end_freq_khz =
2730 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2731 freq_range->max_bandwidth_khz =
2732 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2733
2734 power_rule->max_eirp =
2735 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2736
2737 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2738 power_rule->max_antenna_gain =
2739 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2740
2741 return 0;
2742}
2743
2744static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2745{
2746 int r;
2747 char *data = NULL;
2748
80778f18
LR
2749 /*
2750 * You should only get this when cfg80211 hasn't yet initialized
2751 * completely when built-in to the kernel right between the time
2752 * window between nl80211_init() and regulatory_init(), if that is
2753 * even possible.
2754 */
2755 mutex_lock(&cfg80211_mutex);
2756 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2757 mutex_unlock(&cfg80211_mutex);
2758 return -EINPROGRESS;
80778f18 2759 }
fe33eb39 2760 mutex_unlock(&cfg80211_mutex);
80778f18 2761
fe33eb39
LR
2762 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2763 return -EINVAL;
b2e1b302
LR
2764
2765 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2766
fe33eb39
LR
2767 r = regulatory_hint_user(data);
2768
b2e1b302
LR
2769 return r;
2770}
2771
24bdd9f4 2772static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 2773 struct genl_info *info)
93da9cc1 2774{
4c476991 2775 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 2776 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
2777 struct wireless_dev *wdev = dev->ieee80211_ptr;
2778 struct mesh_config cur_params;
2779 int err = 0;
93da9cc1 2780 void *hdr;
2781 struct nlattr *pinfoattr;
2782 struct sk_buff *msg;
2783
29cbe68c
JB
2784 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2785 return -EOPNOTSUPP;
2786
24bdd9f4 2787 if (!rdev->ops->get_mesh_config)
4c476991 2788 return -EOPNOTSUPP;
f3f92586 2789
29cbe68c
JB
2790 wdev_lock(wdev);
2791 /* If not connected, get default parameters */
2792 if (!wdev->mesh_id_len)
2793 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2794 else
24bdd9f4 2795 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2796 &cur_params);
2797 wdev_unlock(wdev);
2798
93da9cc1 2799 if (err)
4c476991 2800 return err;
93da9cc1 2801
2802 /* Draw up a netlink message to send back */
fd2120ca 2803 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2804 if (!msg)
2805 return -ENOMEM;
93da9cc1 2806 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 2807 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 2808 if (!hdr)
efe1cf0c 2809 goto out;
24bdd9f4 2810 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 2811 if (!pinfoattr)
2812 goto nla_put_failure;
2813 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2814 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2815 cur_params.dot11MeshRetryTimeout);
2816 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2817 cur_params.dot11MeshConfirmTimeout);
2818 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2819 cur_params.dot11MeshHoldingTimeout);
2820 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2821 cur_params.dot11MeshMaxPeerLinks);
2822 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2823 cur_params.dot11MeshMaxRetries);
2824 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2825 cur_params.dot11MeshTTL);
45904f21
JC
2826 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2827 cur_params.element_ttl);
93da9cc1 2828 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2829 cur_params.auto_open_plinks);
2830 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2831 cur_params.dot11MeshHWMPmaxPREQretries);
2832 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2833 cur_params.path_refresh_time);
2834 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2835 cur_params.min_discovery_timeout);
2836 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2837 cur_params.dot11MeshHWMPactivePathTimeout);
2838 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2839 cur_params.dot11MeshHWMPpreqMinInterval);
2840 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2841 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2842 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2843 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2844 nla_nest_end(msg, pinfoattr);
2845 genlmsg_end(msg, hdr);
4c476991 2846 return genlmsg_reply(msg, info);
93da9cc1 2847
3b85875a 2848 nla_put_failure:
93da9cc1 2849 genlmsg_cancel(msg, hdr);
efe1cf0c 2850 out:
d080e275 2851 nlmsg_free(msg);
4c476991 2852 return -ENOBUFS;
93da9cc1 2853}
2854
b54452b0 2855static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2856 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2857 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2858 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2859 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2860 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2861 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 2862 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 2863 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2864
2865 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2866 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2867 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2868 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2869 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2870 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2871};
2872
c80d545d
JC
2873static const struct nla_policy
2874 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2875 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2876 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 2877 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 2878 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 2879 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 2880 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
2881};
2882
24bdd9f4 2883static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
2884 struct mesh_config *cfg,
2885 u32 *mask_out)
93da9cc1 2886{
93da9cc1 2887 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 2888 u32 mask = 0;
93da9cc1 2889
bd90fdcc
JB
2890#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2891do {\
2892 if (table[attr_num]) {\
2893 cfg->param = nla_fn(table[attr_num]); \
2894 mask |= (1 << (attr_num - 1)); \
2895 } \
2896} while (0);\
2897
2898
24bdd9f4 2899 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 2900 return -EINVAL;
2901 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 2902 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 2903 nl80211_meshconf_params_policy))
93da9cc1 2904 return -EINVAL;
2905
93da9cc1 2906 /* This makes sure that there aren't more than 32 mesh config
2907 * parameters (otherwise our bitfield scheme would not work.) */
2908 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2909
2910 /* Fill in the params struct */
93da9cc1 2911 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2912 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2913 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2914 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2915 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2916 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2917 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2918 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2919 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2920 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2921 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2922 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
2923 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2924 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 2925 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2926 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2927 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2928 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2929 nla_get_u8);
2930 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2931 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2932 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2933 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2934 nla_get_u16);
2935 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2936 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2937 nla_get_u32);
2938 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2939 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2940 nla_get_u16);
2941 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2942 dot11MeshHWMPnetDiameterTraversalTime,
2943 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2944 nla_get_u16);
63c5723b
RP
2945 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2946 dot11MeshHWMPRootMode, mask,
2947 NL80211_MESHCONF_HWMP_ROOTMODE,
2948 nla_get_u8);
bd90fdcc
JB
2949 if (mask_out)
2950 *mask_out = mask;
c80d545d 2951
bd90fdcc
JB
2952 return 0;
2953
2954#undef FILL_IN_MESH_PARAM_IF_SET
2955}
2956
c80d545d
JC
2957static int nl80211_parse_mesh_setup(struct genl_info *info,
2958 struct mesh_setup *setup)
2959{
2960 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
2961
2962 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
2963 return -EINVAL;
2964 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
2965 info->attrs[NL80211_ATTR_MESH_SETUP],
2966 nl80211_mesh_setup_params_policy))
2967 return -EINVAL;
2968
2969 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
2970 setup->path_sel_proto =
2971 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
2972 IEEE80211_PATH_PROTOCOL_VENDOR :
2973 IEEE80211_PATH_PROTOCOL_HWMP;
2974
2975 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
2976 setup->path_metric =
2977 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
2978 IEEE80211_PATH_METRIC_VENDOR :
2979 IEEE80211_PATH_METRIC_AIRTIME;
2980
581a8b0f
JC
2981
2982 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 2983 struct nlattr *ieattr =
581a8b0f 2984 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
2985 if (!is_valid_ie_attr(ieattr))
2986 return -EINVAL;
581a8b0f
JC
2987 setup->ie = nla_data(ieattr);
2988 setup->ie_len = nla_len(ieattr);
c80d545d 2989 }
b130e5ce
JC
2990 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
2991 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
2992
2993 return 0;
2994}
2995
24bdd9f4 2996static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 2997 struct genl_info *info)
bd90fdcc
JB
2998{
2999 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3000 struct net_device *dev = info->user_ptr[1];
29cbe68c 3001 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3002 struct mesh_config cfg;
3003 u32 mask;
3004 int err;
3005
29cbe68c
JB
3006 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3007 return -EOPNOTSUPP;
3008
24bdd9f4 3009 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3010 return -EOPNOTSUPP;
3011
24bdd9f4 3012 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3013 if (err)
3014 return err;
3015
29cbe68c
JB
3016 wdev_lock(wdev);
3017 if (!wdev->mesh_id_len)
3018 err = -ENOLINK;
3019
3020 if (!err)
24bdd9f4 3021 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3022 mask, &cfg);
3023
3024 wdev_unlock(wdev);
3025
3026 return err;
93da9cc1 3027}
3028
f130347c
LR
3029static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3030{
3031 struct sk_buff *msg;
3032 void *hdr = NULL;
3033 struct nlattr *nl_reg_rules;
3034 unsigned int i;
3035 int err = -EINVAL;
3036
a1794390 3037 mutex_lock(&cfg80211_mutex);
f130347c
LR
3038
3039 if (!cfg80211_regdomain)
3040 goto out;
3041
fd2120ca 3042 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3043 if (!msg) {
3044 err = -ENOBUFS;
3045 goto out;
3046 }
3047
3048 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3049 NL80211_CMD_GET_REG);
3050 if (!hdr)
efe1cf0c 3051 goto put_failure;
f130347c
LR
3052
3053 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3054 cfg80211_regdomain->alpha2);
3055
3056 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3057 if (!nl_reg_rules)
3058 goto nla_put_failure;
3059
3060 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3061 struct nlattr *nl_reg_rule;
3062 const struct ieee80211_reg_rule *reg_rule;
3063 const struct ieee80211_freq_range *freq_range;
3064 const struct ieee80211_power_rule *power_rule;
3065
3066 reg_rule = &cfg80211_regdomain->reg_rules[i];
3067 freq_range = &reg_rule->freq_range;
3068 power_rule = &reg_rule->power_rule;
3069
3070 nl_reg_rule = nla_nest_start(msg, i);
3071 if (!nl_reg_rule)
3072 goto nla_put_failure;
3073
3074 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3075 reg_rule->flags);
3076 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3077 freq_range->start_freq_khz);
3078 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3079 freq_range->end_freq_khz);
3080 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3081 freq_range->max_bandwidth_khz);
3082 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3083 power_rule->max_antenna_gain);
3084 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3085 power_rule->max_eirp);
3086
3087 nla_nest_end(msg, nl_reg_rule);
3088 }
3089
3090 nla_nest_end(msg, nl_reg_rules);
3091
3092 genlmsg_end(msg, hdr);
134e6375 3093 err = genlmsg_reply(msg, info);
f130347c
LR
3094 goto out;
3095
3096nla_put_failure:
3097 genlmsg_cancel(msg, hdr);
efe1cf0c 3098put_failure:
d080e275 3099 nlmsg_free(msg);
f130347c
LR
3100 err = -EMSGSIZE;
3101out:
a1794390 3102 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3103 return err;
3104}
3105
b2e1b302
LR
3106static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3107{
3108 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3109 struct nlattr *nl_reg_rule;
3110 char *alpha2 = NULL;
3111 int rem_reg_rules = 0, r = 0;
3112 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3113 struct ieee80211_regdomain *rd = NULL;
3114
3115 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3116 return -EINVAL;
3117
3118 if (!info->attrs[NL80211_ATTR_REG_RULES])
3119 return -EINVAL;
3120
3121 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3122
3123 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3124 rem_reg_rules) {
3125 num_rules++;
3126 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3127 return -EINVAL;
b2e1b302
LR
3128 }
3129
61405e97
LR
3130 mutex_lock(&cfg80211_mutex);
3131
d0e18f83
LR
3132 if (!reg_is_valid_request(alpha2)) {
3133 r = -EINVAL;
3134 goto bad_reg;
3135 }
b2e1b302
LR
3136
3137 size_of_regd = sizeof(struct ieee80211_regdomain) +
3138 (num_rules * sizeof(struct ieee80211_reg_rule));
3139
3140 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3141 if (!rd) {
3142 r = -ENOMEM;
3143 goto bad_reg;
3144 }
b2e1b302
LR
3145
3146 rd->n_reg_rules = num_rules;
3147 rd->alpha2[0] = alpha2[0];
3148 rd->alpha2[1] = alpha2[1];
3149
3150 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3151 rem_reg_rules) {
3152 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3153 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3154 reg_rule_policy);
3155 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3156 if (r)
3157 goto bad_reg;
3158
3159 rule_idx++;
3160
d0e18f83
LR
3161 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3162 r = -EINVAL;
b2e1b302 3163 goto bad_reg;
d0e18f83 3164 }
b2e1b302
LR
3165 }
3166
3167 BUG_ON(rule_idx != num_rules);
3168
b2e1b302 3169 r = set_regdom(rd);
61405e97 3170
a1794390 3171 mutex_unlock(&cfg80211_mutex);
d0e18f83 3172
b2e1b302
LR
3173 return r;
3174
d2372b31 3175 bad_reg:
61405e97 3176 mutex_unlock(&cfg80211_mutex);
b2e1b302 3177 kfree(rd);
d0e18f83 3178 return r;
b2e1b302
LR
3179}
3180
83f5e2cf
JB
3181static int validate_scan_freqs(struct nlattr *freqs)
3182{
3183 struct nlattr *attr1, *attr2;
3184 int n_channels = 0, tmp1, tmp2;
3185
3186 nla_for_each_nested(attr1, freqs, tmp1) {
3187 n_channels++;
3188 /*
3189 * Some hardware has a limited channel list for
3190 * scanning, and it is pretty much nonsensical
3191 * to scan for a channel twice, so disallow that
3192 * and don't require drivers to check that the
3193 * channel list they get isn't longer than what
3194 * they can scan, as long as they can scan all
3195 * the channels they registered at once.
3196 */
3197 nla_for_each_nested(attr2, freqs, tmp2)
3198 if (attr1 != attr2 &&
3199 nla_get_u32(attr1) == nla_get_u32(attr2))
3200 return 0;
3201 }
3202
3203 return n_channels;
3204}
3205
2a519311
JB
3206static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3207{
4c476991
JB
3208 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3209 struct net_device *dev = info->user_ptr[1];
2a519311
JB
3210 struct cfg80211_scan_request *request;
3211 struct cfg80211_ssid *ssid;
3212 struct ieee80211_channel *channel;
3213 struct nlattr *attr;
3214 struct wiphy *wiphy;
83f5e2cf 3215 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3216 enum ieee80211_band band;
70692ad2 3217 size_t ie_len;
2a519311 3218
f4a11bb0
JB
3219 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3220 return -EINVAL;
3221
79c97e97 3222 wiphy = &rdev->wiphy;
2a519311 3223
4c476991
JB
3224 if (!rdev->ops->scan)
3225 return -EOPNOTSUPP;
2a519311 3226
4c476991
JB
3227 if (rdev->scan_req)
3228 return -EBUSY;
2a519311
JB
3229
3230 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3231 n_channels = validate_scan_freqs(
3232 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3233 if (!n_channels)
3234 return -EINVAL;
2a519311 3235 } else {
83f5e2cf
JB
3236 n_channels = 0;
3237
2a519311
JB
3238 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3239 if (wiphy->bands[band])
3240 n_channels += wiphy->bands[band]->n_channels;
3241 }
3242
3243 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3244 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3245 n_ssids++;
3246
4c476991
JB
3247 if (n_ssids > wiphy->max_scan_ssids)
3248 return -EINVAL;
2a519311 3249
70692ad2
JM
3250 if (info->attrs[NL80211_ATTR_IE])
3251 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3252 else
3253 ie_len = 0;
3254
4c476991
JB
3255 if (ie_len > wiphy->max_scan_ie_len)
3256 return -EINVAL;
18a83659 3257
2a519311
JB
3258 request = kzalloc(sizeof(*request)
3259 + sizeof(*ssid) * n_ssids
70692ad2
JM
3260 + sizeof(channel) * n_channels
3261 + ie_len, GFP_KERNEL);
4c476991
JB
3262 if (!request)
3263 return -ENOMEM;
2a519311 3264
2a519311 3265 if (n_ssids)
5ba63533 3266 request->ssids = (void *)&request->channels[n_channels];
2a519311 3267 request->n_ssids = n_ssids;
70692ad2
JM
3268 if (ie_len) {
3269 if (request->ssids)
3270 request->ie = (void *)(request->ssids + n_ssids);
3271 else
3272 request->ie = (void *)(request->channels + n_channels);
3273 }
2a519311 3274
584991dc 3275 i = 0;
2a519311
JB
3276 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3277 /* user specified, bail out if channel not found */
2a519311 3278 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3279 struct ieee80211_channel *chan;
3280
3281 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3282
3283 if (!chan) {
2a519311
JB
3284 err = -EINVAL;
3285 goto out_free;
3286 }
584991dc
JB
3287
3288 /* ignore disabled channels */
3289 if (chan->flags & IEEE80211_CHAN_DISABLED)
3290 continue;
3291
3292 request->channels[i] = chan;
2a519311
JB
3293 i++;
3294 }
3295 } else {
3296 /* all channels */
2a519311
JB
3297 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3298 int j;
3299 if (!wiphy->bands[band])
3300 continue;
3301 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3302 struct ieee80211_channel *chan;
3303
3304 chan = &wiphy->bands[band]->channels[j];
3305
3306 if (chan->flags & IEEE80211_CHAN_DISABLED)
3307 continue;
3308
3309 request->channels[i] = chan;
2a519311
JB
3310 i++;
3311 }
3312 }
3313 }
3314
584991dc
JB
3315 if (!i) {
3316 err = -EINVAL;
3317 goto out_free;
3318 }
3319
3320 request->n_channels = i;
3321
2a519311
JB
3322 i = 0;
3323 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3324 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3325 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3326 err = -EINVAL;
3327 goto out_free;
3328 }
3329 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3330 request->ssids[i].ssid_len = nla_len(attr);
3331 i++;
3332 }
3333 }
3334
70692ad2
JM
3335 if (info->attrs[NL80211_ATTR_IE]) {
3336 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3337 memcpy((void *)request->ie,
3338 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3339 request->ie_len);
3340 }
3341
463d0183 3342 request->dev = dev;
79c97e97 3343 request->wiphy = &rdev->wiphy;
2a519311 3344
79c97e97
JB
3345 rdev->scan_req = request;
3346 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3347
463d0183 3348 if (!err) {
79c97e97 3349 nl80211_send_scan_start(rdev, dev);
463d0183 3350 dev_hold(dev);
4c476991 3351 } else {
2a519311 3352 out_free:
79c97e97 3353 rdev->scan_req = NULL;
2a519311
JB
3354 kfree(request);
3355 }
3b85875a 3356
2a519311
JB
3357 return err;
3358}
3359
3360static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3361 struct cfg80211_registered_device *rdev,
48ab905d
JB
3362 struct wireless_dev *wdev,
3363 struct cfg80211_internal_bss *intbss)
2a519311 3364{
48ab905d 3365 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3366 void *hdr;
3367 struct nlattr *bss;
48ab905d
JB
3368 int i;
3369
3370 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3371
3372 hdr = nl80211hdr_put(msg, pid, seq, flags,
3373 NL80211_CMD_NEW_SCAN_RESULTS);
3374 if (!hdr)
3375 return -1;
3376
f5ea9120 3377 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3378 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3379
3380 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3381 if (!bss)
3382 goto nla_put_failure;
3383 if (!is_zero_ether_addr(res->bssid))
3384 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3385 if (res->information_elements && res->len_information_elements)
3386 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3387 res->len_information_elements,
3388 res->information_elements);
34a6eddb
JM
3389 if (res->beacon_ies && res->len_beacon_ies &&
3390 res->beacon_ies != res->information_elements)
3391 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3392 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3393 if (res->tsf)
3394 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3395 if (res->beacon_interval)
3396 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3397 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3398 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3399 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3400 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3401
77965c97 3402 switch (rdev->wiphy.signal_type) {
2a519311
JB
3403 case CFG80211_SIGNAL_TYPE_MBM:
3404 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3405 break;
3406 case CFG80211_SIGNAL_TYPE_UNSPEC:
3407 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3408 break;
3409 default:
3410 break;
3411 }
3412
48ab905d 3413 switch (wdev->iftype) {
074ac8df 3414 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3415 case NL80211_IFTYPE_STATION:
3416 if (intbss == wdev->current_bss)
3417 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3418 NL80211_BSS_STATUS_ASSOCIATED);
3419 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3420 if (intbss != wdev->auth_bsses[i])
3421 continue;
3422 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3423 NL80211_BSS_STATUS_AUTHENTICATED);
3424 break;
3425 }
3426 break;
3427 case NL80211_IFTYPE_ADHOC:
3428 if (intbss == wdev->current_bss)
3429 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3430 NL80211_BSS_STATUS_IBSS_JOINED);
3431 break;
3432 default:
3433 break;
3434 }
3435
2a519311
JB
3436 nla_nest_end(msg, bss);
3437
3438 return genlmsg_end(msg, hdr);
3439
3440 nla_put_failure:
3441 genlmsg_cancel(msg, hdr);
3442 return -EMSGSIZE;
3443}
3444
3445static int nl80211_dump_scan(struct sk_buff *skb,
3446 struct netlink_callback *cb)
3447{
48ab905d
JB
3448 struct cfg80211_registered_device *rdev;
3449 struct net_device *dev;
2a519311 3450 struct cfg80211_internal_bss *scan;
48ab905d 3451 struct wireless_dev *wdev;
2a519311
JB
3452 int start = cb->args[1], idx = 0;
3453 int err;
3454
67748893
JB
3455 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3456 if (err)
3457 return err;
2a519311 3458
48ab905d 3459 wdev = dev->ieee80211_ptr;
2a519311 3460
48ab905d
JB
3461 wdev_lock(wdev);
3462 spin_lock_bh(&rdev->bss_lock);
3463 cfg80211_bss_expire(rdev);
3464
3465 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3466 if (++idx <= start)
3467 continue;
3468 if (nl80211_send_bss(skb,
3469 NETLINK_CB(cb->skb).pid,
3470 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3471 rdev, wdev, scan) < 0) {
2a519311 3472 idx--;
67748893 3473 break;
2a519311
JB
3474 }
3475 }
3476
48ab905d
JB
3477 spin_unlock_bh(&rdev->bss_lock);
3478 wdev_unlock(wdev);
2a519311
JB
3479
3480 cb->args[1] = idx;
67748893 3481 nl80211_finish_netdev_dump(rdev);
2a519311 3482
67748893 3483 return skb->len;
2a519311
JB
3484}
3485
61fa713c
HS
3486static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3487 int flags, struct net_device *dev,
3488 struct survey_info *survey)
3489{
3490 void *hdr;
3491 struct nlattr *infoattr;
3492
3493 /* Survey without a channel doesn't make sense */
3494 if (!survey->channel)
3495 return -EINVAL;
3496
3497 hdr = nl80211hdr_put(msg, pid, seq, flags,
3498 NL80211_CMD_NEW_SURVEY_RESULTS);
3499 if (!hdr)
3500 return -ENOMEM;
3501
3502 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3503
3504 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3505 if (!infoattr)
3506 goto nla_put_failure;
3507
3508 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3509 survey->channel->center_freq);
3510 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3511 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3512 survey->noise);
17e5a808
FF
3513 if (survey->filled & SURVEY_INFO_IN_USE)
3514 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
3515 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3516 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3517 survey->channel_time);
3518 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3519 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3520 survey->channel_time_busy);
3521 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3522 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3523 survey->channel_time_ext_busy);
3524 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3525 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3526 survey->channel_time_rx);
3527 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3528 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3529 survey->channel_time_tx);
61fa713c
HS
3530
3531 nla_nest_end(msg, infoattr);
3532
3533 return genlmsg_end(msg, hdr);
3534
3535 nla_put_failure:
3536 genlmsg_cancel(msg, hdr);
3537 return -EMSGSIZE;
3538}
3539
3540static int nl80211_dump_survey(struct sk_buff *skb,
3541 struct netlink_callback *cb)
3542{
3543 struct survey_info survey;
3544 struct cfg80211_registered_device *dev;
3545 struct net_device *netdev;
61fa713c
HS
3546 int survey_idx = cb->args[1];
3547 int res;
3548
67748893
JB
3549 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3550 if (res)
3551 return res;
61fa713c
HS
3552
3553 if (!dev->ops->dump_survey) {
3554 res = -EOPNOTSUPP;
3555 goto out_err;
3556 }
3557
3558 while (1) {
3559 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3560 &survey);
3561 if (res == -ENOENT)
3562 break;
3563 if (res)
3564 goto out_err;
3565
3566 if (nl80211_send_survey(skb,
3567 NETLINK_CB(cb->skb).pid,
3568 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3569 netdev,
3570 &survey) < 0)
3571 goto out;
3572 survey_idx++;
3573 }
3574
3575 out:
3576 cb->args[1] = survey_idx;
3577 res = skb->len;
3578 out_err:
67748893 3579 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3580 return res;
3581}
3582
255e737e
JM
3583static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3584{
b23aa676
SO
3585 return auth_type <= NL80211_AUTHTYPE_MAX;
3586}
3587
3588static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3589{
3590 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3591 NL80211_WPA_VERSION_2));
3592}
3593
3594static bool nl80211_valid_akm_suite(u32 akm)
3595{
3596 return akm == WLAN_AKM_SUITE_8021X ||
3597 akm == WLAN_AKM_SUITE_PSK;
3598}
3599
3600static bool nl80211_valid_cipher_suite(u32 cipher)
3601{
3602 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3603 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3604 cipher == WLAN_CIPHER_SUITE_TKIP ||
3605 cipher == WLAN_CIPHER_SUITE_CCMP ||
3606 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3607}
3608
b23aa676 3609
636a5d36
JM
3610static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3611{
4c476991
JB
3612 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3613 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3614 struct ieee80211_channel *chan;
3615 const u8 *bssid, *ssid, *ie = NULL;
3616 int err, ssid_len, ie_len = 0;
3617 enum nl80211_auth_type auth_type;
fffd0934 3618 struct key_parse key;
d5cdfacb 3619 bool local_state_change;
636a5d36 3620
f4a11bb0
JB
3621 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3622 return -EINVAL;
3623
3624 if (!info->attrs[NL80211_ATTR_MAC])
3625 return -EINVAL;
3626
1778092e
JM
3627 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3628 return -EINVAL;
3629
19957bb3
JB
3630 if (!info->attrs[NL80211_ATTR_SSID])
3631 return -EINVAL;
3632
3633 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3634 return -EINVAL;
3635
fffd0934
JB
3636 err = nl80211_parse_key(info, &key);
3637 if (err)
3638 return err;
3639
3640 if (key.idx >= 0) {
e31b8213
JB
3641 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3642 return -EINVAL;
fffd0934
JB
3643 if (!key.p.key || !key.p.key_len)
3644 return -EINVAL;
3645 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3646 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3647 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3648 key.p.key_len != WLAN_KEY_LEN_WEP104))
3649 return -EINVAL;
3650 if (key.idx > 4)
3651 return -EINVAL;
3652 } else {
3653 key.p.key_len = 0;
3654 key.p.key = NULL;
3655 }
3656
afea0b7a
JB
3657 if (key.idx >= 0) {
3658 int i;
3659 bool ok = false;
3660 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3661 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3662 ok = true;
3663 break;
3664 }
3665 }
4c476991
JB
3666 if (!ok)
3667 return -EINVAL;
afea0b7a
JB
3668 }
3669
4c476991
JB
3670 if (!rdev->ops->auth)
3671 return -EOPNOTSUPP;
636a5d36 3672
074ac8df 3673 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3674 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3675 return -EOPNOTSUPP;
eec60b03 3676
19957bb3 3677 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3678 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3679 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3680 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3681 return -EINVAL;
636a5d36 3682
19957bb3
JB
3683 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3684 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3685
3686 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3687 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3688 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3689 }
3690
19957bb3 3691 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3692 if (!nl80211_valid_auth_type(auth_type))
3693 return -EINVAL;
636a5d36 3694
d5cdfacb
JM
3695 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3696
4c476991
JB
3697 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3698 ssid, ssid_len, ie, ie_len,
3699 key.p.key, key.p.key_len, key.idx,
3700 local_state_change);
636a5d36
JM
3701}
3702
c0692b8f
JB
3703static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3704 struct genl_info *info,
3dc27d25
JB
3705 struct cfg80211_crypto_settings *settings,
3706 int cipher_limit)
b23aa676 3707{
c0b2bbd8
JB
3708 memset(settings, 0, sizeof(*settings));
3709
b23aa676
SO
3710 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3711
c0692b8f
JB
3712 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3713 u16 proto;
3714 proto = nla_get_u16(
3715 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3716 settings->control_port_ethertype = cpu_to_be16(proto);
3717 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3718 proto != ETH_P_PAE)
3719 return -EINVAL;
3720 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3721 settings->control_port_no_encrypt = true;
3722 } else
3723 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3724
b23aa676
SO
3725 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3726 void *data;
3727 int len, i;
3728
3729 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3730 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3731 settings->n_ciphers_pairwise = len / sizeof(u32);
3732
3733 if (len % sizeof(u32))
3734 return -EINVAL;
3735
3dc27d25 3736 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3737 return -EINVAL;
3738
3739 memcpy(settings->ciphers_pairwise, data, len);
3740
3741 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3742 if (!nl80211_valid_cipher_suite(
3743 settings->ciphers_pairwise[i]))
3744 return -EINVAL;
3745 }
3746
3747 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3748 settings->cipher_group =
3749 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3750 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3751 return -EINVAL;
3752 }
3753
3754 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3755 settings->wpa_versions =
3756 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3757 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3758 return -EINVAL;
3759 }
3760
3761 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3762 void *data;
3763 int len, i;
3764
3765 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3766 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3767 settings->n_akm_suites = len / sizeof(u32);
3768
3769 if (len % sizeof(u32))
3770 return -EINVAL;
3771
3772 memcpy(settings->akm_suites, data, len);
3773
3774 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3775 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3776 return -EINVAL;
3777 }
3778
3779 return 0;
3780}
3781
636a5d36
JM
3782static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3783{
4c476991
JB
3784 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3785 struct net_device *dev = info->user_ptr[1];
19957bb3 3786 struct cfg80211_crypto_settings crypto;
f444de05 3787 struct ieee80211_channel *chan;
3e5d7649 3788 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3789 int err, ssid_len, ie_len = 0;
3790 bool use_mfp = false;
636a5d36 3791
f4a11bb0
JB
3792 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3793 return -EINVAL;
3794
3795 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3796 !info->attrs[NL80211_ATTR_SSID] ||
3797 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3798 return -EINVAL;
3799
4c476991
JB
3800 if (!rdev->ops->assoc)
3801 return -EOPNOTSUPP;
636a5d36 3802
074ac8df 3803 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3804 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3805 return -EOPNOTSUPP;
eec60b03 3806
19957bb3 3807 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3808
19957bb3
JB
3809 chan = ieee80211_get_channel(&rdev->wiphy,
3810 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3811 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3812 return -EINVAL;
636a5d36 3813
19957bb3
JB
3814 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3815 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3816
3817 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3818 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3819 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3820 }
3821
dc6382ce 3822 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3823 enum nl80211_mfp mfp =
dc6382ce 3824 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3825 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3826 use_mfp = true;
4c476991
JB
3827 else if (mfp != NL80211_MFP_NO)
3828 return -EINVAL;
dc6382ce
JM
3829 }
3830
3e5d7649
JB
3831 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3832 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3833
c0692b8f 3834 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3835 if (!err)
3e5d7649
JB
3836 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3837 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3838 &crypto);
636a5d36 3839
636a5d36
JM
3840 return err;
3841}
3842
3843static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3844{
4c476991
JB
3845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3846 struct net_device *dev = info->user_ptr[1];
19957bb3 3847 const u8 *ie = NULL, *bssid;
4c476991 3848 int ie_len = 0;
19957bb3 3849 u16 reason_code;
d5cdfacb 3850 bool local_state_change;
636a5d36 3851
f4a11bb0
JB
3852 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3853 return -EINVAL;
3854
3855 if (!info->attrs[NL80211_ATTR_MAC])
3856 return -EINVAL;
3857
3858 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3859 return -EINVAL;
3860
4c476991
JB
3861 if (!rdev->ops->deauth)
3862 return -EOPNOTSUPP;
636a5d36 3863
074ac8df 3864 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3865 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3866 return -EOPNOTSUPP;
eec60b03 3867
19957bb3 3868 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3869
19957bb3
JB
3870 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3871 if (reason_code == 0) {
f4a11bb0 3872 /* Reason Code 0 is reserved */
4c476991 3873 return -EINVAL;
255e737e 3874 }
636a5d36
JM
3875
3876 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3877 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3878 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3879 }
3880
d5cdfacb
JM
3881 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3882
4c476991
JB
3883 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3884 local_state_change);
636a5d36
JM
3885}
3886
3887static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3888{
4c476991
JB
3889 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3890 struct net_device *dev = info->user_ptr[1];
19957bb3 3891 const u8 *ie = NULL, *bssid;
4c476991 3892 int ie_len = 0;
19957bb3 3893 u16 reason_code;
d5cdfacb 3894 bool local_state_change;
636a5d36 3895
f4a11bb0
JB
3896 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3897 return -EINVAL;
3898
3899 if (!info->attrs[NL80211_ATTR_MAC])
3900 return -EINVAL;
3901
3902 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3903 return -EINVAL;
3904
4c476991
JB
3905 if (!rdev->ops->disassoc)
3906 return -EOPNOTSUPP;
636a5d36 3907
074ac8df 3908 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3909 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3910 return -EOPNOTSUPP;
eec60b03 3911
19957bb3 3912 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3913
19957bb3
JB
3914 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3915 if (reason_code == 0) {
f4a11bb0 3916 /* Reason Code 0 is reserved */
4c476991 3917 return -EINVAL;
255e737e 3918 }
636a5d36
JM
3919
3920 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3921 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3922 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3923 }
3924
d5cdfacb
JM
3925 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3926
4c476991
JB
3927 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3928 local_state_change);
636a5d36
JM
3929}
3930
dd5b4cc7
FF
3931static bool
3932nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3933 int mcast_rate[IEEE80211_NUM_BANDS],
3934 int rateval)
3935{
3936 struct wiphy *wiphy = &rdev->wiphy;
3937 bool found = false;
3938 int band, i;
3939
3940 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3941 struct ieee80211_supported_band *sband;
3942
3943 sband = wiphy->bands[band];
3944 if (!sband)
3945 continue;
3946
3947 for (i = 0; i < sband->n_bitrates; i++) {
3948 if (sband->bitrates[i].bitrate == rateval) {
3949 mcast_rate[band] = i + 1;
3950 found = true;
3951 break;
3952 }
3953 }
3954 }
3955
3956 return found;
3957}
3958
04a773ad
JB
3959static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3960{
4c476991
JB
3961 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3962 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
3963 struct cfg80211_ibss_params ibss;
3964 struct wiphy *wiphy;
fffd0934 3965 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3966 int err;
3967
8e30bc55
JB
3968 memset(&ibss, 0, sizeof(ibss));
3969
04a773ad
JB
3970 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3971 return -EINVAL;
3972
3973 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3974 !info->attrs[NL80211_ATTR_SSID] ||
3975 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3976 return -EINVAL;
3977
8e30bc55
JB
3978 ibss.beacon_interval = 100;
3979
3980 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3981 ibss.beacon_interval =
3982 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3983 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3984 return -EINVAL;
3985 }
3986
4c476991
JB
3987 if (!rdev->ops->join_ibss)
3988 return -EOPNOTSUPP;
04a773ad 3989
4c476991
JB
3990 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3991 return -EOPNOTSUPP;
04a773ad 3992
79c97e97 3993 wiphy = &rdev->wiphy;
04a773ad
JB
3994
3995 if (info->attrs[NL80211_ATTR_MAC])
3996 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3997 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3998 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3999
4000 if (info->attrs[NL80211_ATTR_IE]) {
4001 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4002 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4003 }
4004
4005 ibss.channel = ieee80211_get_channel(wiphy,
4006 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4007 if (!ibss.channel ||
4008 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4009 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4010 return -EINVAL;
04a773ad
JB
4011
4012 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4013 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4014
fbd2c8dc
TP
4015 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4016 u8 *rates =
4017 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4018 int n_rates =
4019 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4020 struct ieee80211_supported_band *sband =
4021 wiphy->bands[ibss.channel->band];
4022 int i, j;
4023
4c476991
JB
4024 if (n_rates == 0)
4025 return -EINVAL;
fbd2c8dc
TP
4026
4027 for (i = 0; i < n_rates; i++) {
4028 int rate = (rates[i] & 0x7f) * 5;
4029 bool found = false;
4030
4031 for (j = 0; j < sband->n_bitrates; j++) {
4032 if (sband->bitrates[j].bitrate == rate) {
4033 found = true;
4034 ibss.basic_rates |= BIT(j);
4035 break;
4036 }
4037 }
4c476991
JB
4038 if (!found)
4039 return -EINVAL;
fbd2c8dc 4040 }
fbd2c8dc 4041 }
dd5b4cc7
FF
4042
4043 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4044 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4045 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4046 return -EINVAL;
fbd2c8dc 4047
4c476991
JB
4048 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4049 connkeys = nl80211_parse_connkeys(rdev,
4050 info->attrs[NL80211_ATTR_KEYS]);
4051 if (IS_ERR(connkeys))
4052 return PTR_ERR(connkeys);
4053 }
04a773ad 4054
4c476991 4055 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4056 if (err)
4057 kfree(connkeys);
04a773ad
JB
4058 return err;
4059}
4060
4061static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4062{
4c476991
JB
4063 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4064 struct net_device *dev = info->user_ptr[1];
04a773ad 4065
4c476991
JB
4066 if (!rdev->ops->leave_ibss)
4067 return -EOPNOTSUPP;
04a773ad 4068
4c476991
JB
4069 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4070 return -EOPNOTSUPP;
04a773ad 4071
4c476991 4072 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4073}
4074
aff89a9b
JB
4075#ifdef CONFIG_NL80211_TESTMODE
4076static struct genl_multicast_group nl80211_testmode_mcgrp = {
4077 .name = "testmode",
4078};
4079
4080static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4081{
4c476991 4082 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4083 int err;
4084
4085 if (!info->attrs[NL80211_ATTR_TESTDATA])
4086 return -EINVAL;
4087
aff89a9b
JB
4088 err = -EOPNOTSUPP;
4089 if (rdev->ops->testmode_cmd) {
4090 rdev->testmode_info = info;
4091 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4092 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4093 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4094 rdev->testmode_info = NULL;
4095 }
4096
aff89a9b
JB
4097 return err;
4098}
4099
4100static struct sk_buff *
4101__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4102 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4103{
4104 struct sk_buff *skb;
4105 void *hdr;
4106 struct nlattr *data;
4107
4108 skb = nlmsg_new(approxlen + 100, gfp);
4109 if (!skb)
4110 return NULL;
4111
4112 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4113 if (!hdr) {
4114 kfree_skb(skb);
4115 return NULL;
4116 }
4117
4118 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4119 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4120
4121 ((void **)skb->cb)[0] = rdev;
4122 ((void **)skb->cb)[1] = hdr;
4123 ((void **)skb->cb)[2] = data;
4124
4125 return skb;
4126
4127 nla_put_failure:
4128 kfree_skb(skb);
4129 return NULL;
4130}
4131
4132struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4133 int approxlen)
4134{
4135 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4136
4137 if (WARN_ON(!rdev->testmode_info))
4138 return NULL;
4139
4140 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4141 rdev->testmode_info->snd_pid,
4142 rdev->testmode_info->snd_seq,
4143 GFP_KERNEL);
4144}
4145EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4146
4147int cfg80211_testmode_reply(struct sk_buff *skb)
4148{
4149 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4150 void *hdr = ((void **)skb->cb)[1];
4151 struct nlattr *data = ((void **)skb->cb)[2];
4152
4153 if (WARN_ON(!rdev->testmode_info)) {
4154 kfree_skb(skb);
4155 return -EINVAL;
4156 }
4157
4158 nla_nest_end(skb, data);
4159 genlmsg_end(skb, hdr);
4160 return genlmsg_reply(skb, rdev->testmode_info);
4161}
4162EXPORT_SYMBOL(cfg80211_testmode_reply);
4163
4164struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4165 int approxlen, gfp_t gfp)
4166{
4167 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4168
4169 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4170}
4171EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4172
4173void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4174{
4175 void *hdr = ((void **)skb->cb)[1];
4176 struct nlattr *data = ((void **)skb->cb)[2];
4177
4178 nla_nest_end(skb, data);
4179 genlmsg_end(skb, hdr);
4180 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4181}
4182EXPORT_SYMBOL(cfg80211_testmode_event);
4183#endif
4184
b23aa676
SO
4185static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4186{
4c476991
JB
4187 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4188 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4189 struct cfg80211_connect_params connect;
4190 struct wiphy *wiphy;
fffd0934 4191 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4192 int err;
4193
4194 memset(&connect, 0, sizeof(connect));
4195
4196 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4197 return -EINVAL;
4198
4199 if (!info->attrs[NL80211_ATTR_SSID] ||
4200 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4201 return -EINVAL;
4202
4203 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4204 connect.auth_type =
4205 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4206 if (!nl80211_valid_auth_type(connect.auth_type))
4207 return -EINVAL;
4208 } else
4209 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4210
4211 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4212
c0692b8f 4213 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4214 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4215 if (err)
4216 return err;
b23aa676 4217
074ac8df 4218 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4219 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4220 return -EOPNOTSUPP;
b23aa676 4221
79c97e97 4222 wiphy = &rdev->wiphy;
b23aa676 4223
b23aa676
SO
4224 if (info->attrs[NL80211_ATTR_MAC])
4225 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4226 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4227 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4228
4229 if (info->attrs[NL80211_ATTR_IE]) {
4230 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4231 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4232 }
4233
4234 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4235 connect.channel =
4236 ieee80211_get_channel(wiphy,
4237 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4238 if (!connect.channel ||
4c476991
JB
4239 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4240 return -EINVAL;
b23aa676
SO
4241 }
4242
fffd0934
JB
4243 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4244 connkeys = nl80211_parse_connkeys(rdev,
4245 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4246 if (IS_ERR(connkeys))
4247 return PTR_ERR(connkeys);
fffd0934
JB
4248 }
4249
4250 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4251 if (err)
4252 kfree(connkeys);
b23aa676
SO
4253 return err;
4254}
4255
4256static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4257{
4c476991
JB
4258 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4259 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4260 u16 reason;
4261
4262 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4263 reason = WLAN_REASON_DEAUTH_LEAVING;
4264 else
4265 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4266
4267 if (reason == 0)
4268 return -EINVAL;
4269
074ac8df 4270 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4271 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4272 return -EOPNOTSUPP;
b23aa676 4273
4c476991 4274 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4275}
4276
463d0183
JB
4277static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4278{
4c476991 4279 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4280 struct net *net;
4281 int err;
4282 u32 pid;
4283
4284 if (!info->attrs[NL80211_ATTR_PID])
4285 return -EINVAL;
4286
4287 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4288
463d0183 4289 net = get_net_ns_by_pid(pid);
4c476991
JB
4290 if (IS_ERR(net))
4291 return PTR_ERR(net);
463d0183
JB
4292
4293 err = 0;
4294
4295 /* check if anything to do */
4c476991
JB
4296 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4297 err = cfg80211_switch_netns(rdev, net);
463d0183 4298
463d0183 4299 put_net(net);
463d0183
JB
4300 return err;
4301}
4302
67fbb16b
SO
4303static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4304{
4c476991 4305 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4306 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4307 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4308 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4309 struct cfg80211_pmksa pmksa;
4310
4311 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4312
4313 if (!info->attrs[NL80211_ATTR_MAC])
4314 return -EINVAL;
4315
4316 if (!info->attrs[NL80211_ATTR_PMKID])
4317 return -EINVAL;
4318
67fbb16b
SO
4319 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4320 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4321
074ac8df 4322 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4323 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4324 return -EOPNOTSUPP;
67fbb16b
SO
4325
4326 switch (info->genlhdr->cmd) {
4327 case NL80211_CMD_SET_PMKSA:
4328 rdev_ops = rdev->ops->set_pmksa;
4329 break;
4330 case NL80211_CMD_DEL_PMKSA:
4331 rdev_ops = rdev->ops->del_pmksa;
4332 break;
4333 default:
4334 WARN_ON(1);
4335 break;
4336 }
4337
4c476991
JB
4338 if (!rdev_ops)
4339 return -EOPNOTSUPP;
67fbb16b 4340
4c476991 4341 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4342}
4343
4344static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4345{
4c476991
JB
4346 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4347 struct net_device *dev = info->user_ptr[1];
67fbb16b 4348
074ac8df 4349 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4350 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4351 return -EOPNOTSUPP;
67fbb16b 4352
4c476991
JB
4353 if (!rdev->ops->flush_pmksa)
4354 return -EOPNOTSUPP;
67fbb16b 4355
4c476991 4356 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
4357}
4358
9588bbd5
JM
4359static int nl80211_remain_on_channel(struct sk_buff *skb,
4360 struct genl_info *info)
4361{
4c476991
JB
4362 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4363 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
4364 struct ieee80211_channel *chan;
4365 struct sk_buff *msg;
4366 void *hdr;
4367 u64 cookie;
4368 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4369 u32 freq, duration;
4370 int err;
4371
4372 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4373 !info->attrs[NL80211_ATTR_DURATION])
4374 return -EINVAL;
4375
4376 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4377
4378 /*
4379 * We should be on that channel for at least one jiffie,
4380 * and more than 5 seconds seems excessive.
4381 */
a293911d
JB
4382 if (!duration || !msecs_to_jiffies(duration) ||
4383 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
4384 return -EINVAL;
4385
4c476991
JB
4386 if (!rdev->ops->remain_on_channel)
4387 return -EOPNOTSUPP;
9588bbd5 4388
9588bbd5
JM
4389 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4390 channel_type = nla_get_u32(
4391 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4392 if (channel_type != NL80211_CHAN_NO_HT &&
4393 channel_type != NL80211_CHAN_HT20 &&
4394 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4395 channel_type != NL80211_CHAN_HT40MINUS)
4396 return -EINVAL;
9588bbd5
JM
4397 }
4398
4399 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4400 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4401 if (chan == NULL)
4402 return -EINVAL;
9588bbd5
JM
4403
4404 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4405 if (!msg)
4406 return -ENOMEM;
9588bbd5
JM
4407
4408 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4409 NL80211_CMD_REMAIN_ON_CHANNEL);
4410
4411 if (IS_ERR(hdr)) {
4412 err = PTR_ERR(hdr);
4413 goto free_msg;
4414 }
4415
4416 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4417 channel_type, duration, &cookie);
4418
4419 if (err)
4420 goto free_msg;
4421
4422 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4423
4424 genlmsg_end(msg, hdr);
4c476991
JB
4425
4426 return genlmsg_reply(msg, info);
9588bbd5
JM
4427
4428 nla_put_failure:
4429 err = -ENOBUFS;
4430 free_msg:
4431 nlmsg_free(msg);
9588bbd5
JM
4432 return err;
4433}
4434
4435static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4436 struct genl_info *info)
4437{
4c476991
JB
4438 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4439 struct net_device *dev = info->user_ptr[1];
9588bbd5 4440 u64 cookie;
9588bbd5
JM
4441
4442 if (!info->attrs[NL80211_ATTR_COOKIE])
4443 return -EINVAL;
4444
4c476991
JB
4445 if (!rdev->ops->cancel_remain_on_channel)
4446 return -EOPNOTSUPP;
9588bbd5 4447
9588bbd5
JM
4448 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4449
4c476991 4450 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
4451}
4452
13ae75b1
JM
4453static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4454 u8 *rates, u8 rates_len)
4455{
4456 u8 i;
4457 u32 mask = 0;
4458
4459 for (i = 0; i < rates_len; i++) {
4460 int rate = (rates[i] & 0x7f) * 5;
4461 int ridx;
4462 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4463 struct ieee80211_rate *srate =
4464 &sband->bitrates[ridx];
4465 if (rate == srate->bitrate) {
4466 mask |= 1 << ridx;
4467 break;
4468 }
4469 }
4470 if (ridx == sband->n_bitrates)
4471 return 0; /* rate not found */
4472 }
4473
4474 return mask;
4475}
4476
b54452b0 4477static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4478 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4479 .len = NL80211_MAX_SUPP_RATES },
4480};
4481
4482static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4483 struct genl_info *info)
4484{
4485 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4486 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4487 struct cfg80211_bitrate_mask mask;
4c476991
JB
4488 int rem, i;
4489 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4490 struct nlattr *tx_rates;
4491 struct ieee80211_supported_band *sband;
4492
4493 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4494 return -EINVAL;
4495
4c476991
JB
4496 if (!rdev->ops->set_bitrate_mask)
4497 return -EOPNOTSUPP;
13ae75b1
JM
4498
4499 memset(&mask, 0, sizeof(mask));
4500 /* Default to all rates enabled */
4501 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4502 sband = rdev->wiphy.bands[i];
4503 mask.control[i].legacy =
4504 sband ? (1 << sband->n_bitrates) - 1 : 0;
4505 }
4506
4507 /*
4508 * The nested attribute uses enum nl80211_band as the index. This maps
4509 * directly to the enum ieee80211_band values used in cfg80211.
4510 */
4511 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4512 {
4513 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4514 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4515 return -EINVAL;
13ae75b1 4516 sband = rdev->wiphy.bands[band];
4c476991
JB
4517 if (sband == NULL)
4518 return -EINVAL;
13ae75b1
JM
4519 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4520 nla_len(tx_rates), nl80211_txattr_policy);
4521 if (tb[NL80211_TXRATE_LEGACY]) {
4522 mask.control[band].legacy = rateset_to_mask(
4523 sband,
4524 nla_data(tb[NL80211_TXRATE_LEGACY]),
4525 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4526 if (mask.control[band].legacy == 0)
4527 return -EINVAL;
13ae75b1
JM
4528 }
4529 }
4530
4c476991 4531 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4532}
4533
2e161f78 4534static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4535{
4c476991
JB
4536 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4537 struct net_device *dev = info->user_ptr[1];
2e161f78 4538 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4539
4540 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4541 return -EINVAL;
4542
2e161f78
JB
4543 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4544 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4545
9d38d85d 4546 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4547 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4548 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4549 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4550 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4551 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4552 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4553 return -EOPNOTSUPP;
026331c4
JM
4554
4555 /* not much point in registering if we can't reply */
4c476991
JB
4556 if (!rdev->ops->mgmt_tx)
4557 return -EOPNOTSUPP;
026331c4 4558
4c476991 4559 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4560 frame_type,
026331c4
JM
4561 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4562 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4563}
4564
2e161f78 4565static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4566{
4c476991
JB
4567 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4568 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4569 struct ieee80211_channel *chan;
4570 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4571 bool channel_type_valid = false;
026331c4
JM
4572 u32 freq;
4573 int err;
4574 void *hdr;
4575 u64 cookie;
4576 struct sk_buff *msg;
f7ca38df
JB
4577 unsigned int wait = 0;
4578 bool offchan;
026331c4
JM
4579
4580 if (!info->attrs[NL80211_ATTR_FRAME] ||
4581 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4582 return -EINVAL;
4583
4c476991
JB
4584 if (!rdev->ops->mgmt_tx)
4585 return -EOPNOTSUPP;
026331c4 4586
9d38d85d 4587 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4588 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4589 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4590 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4591 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4592 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4593 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4594 return -EOPNOTSUPP;
026331c4 4595
f7ca38df
JB
4596 if (info->attrs[NL80211_ATTR_DURATION]) {
4597 if (!rdev->ops->mgmt_tx_cancel_wait)
4598 return -EINVAL;
4599 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4600 }
4601
026331c4
JM
4602 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4603 channel_type = nla_get_u32(
4604 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4605 if (channel_type != NL80211_CHAN_NO_HT &&
4606 channel_type != NL80211_CHAN_HT20 &&
4607 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4608 channel_type != NL80211_CHAN_HT40MINUS)
4609 return -EINVAL;
252aa631 4610 channel_type_valid = true;
026331c4
JM
4611 }
4612
f7ca38df
JB
4613 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4614
026331c4
JM
4615 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4616 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4617 if (chan == NULL)
4618 return -EINVAL;
026331c4
JM
4619
4620 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4621 if (!msg)
4622 return -ENOMEM;
026331c4
JM
4623
4624 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4625 NL80211_CMD_FRAME);
026331c4
JM
4626
4627 if (IS_ERR(hdr)) {
4628 err = PTR_ERR(hdr);
4629 goto free_msg;
4630 }
f7ca38df
JB
4631 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4632 channel_type_valid, wait,
2e161f78
JB
4633 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4634 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4635 &cookie);
026331c4
JM
4636 if (err)
4637 goto free_msg;
4638
4639 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4640
4641 genlmsg_end(msg, hdr);
4c476991 4642 return genlmsg_reply(msg, info);
026331c4
JM
4643
4644 nla_put_failure:
4645 err = -ENOBUFS;
4646 free_msg:
4647 nlmsg_free(msg);
026331c4
JM
4648 return err;
4649}
4650
f7ca38df
JB
4651static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4652{
4653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4654 struct net_device *dev = info->user_ptr[1];
4655 u64 cookie;
4656
4657 if (!info->attrs[NL80211_ATTR_COOKIE])
4658 return -EINVAL;
4659
4660 if (!rdev->ops->mgmt_tx_cancel_wait)
4661 return -EOPNOTSUPP;
4662
4663 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4664 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4665 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4666 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4667 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4668 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4669 return -EOPNOTSUPP;
4670
4671 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4672
4673 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4674}
4675
ffb9eb3d
KV
4676static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4677{
4c476991 4678 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4679 struct wireless_dev *wdev;
4c476991 4680 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4681 u8 ps_state;
4682 bool state;
4683 int err;
4684
4c476991
JB
4685 if (!info->attrs[NL80211_ATTR_PS_STATE])
4686 return -EINVAL;
ffb9eb3d
KV
4687
4688 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4689
4c476991
JB
4690 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4691 return -EINVAL;
ffb9eb3d
KV
4692
4693 wdev = dev->ieee80211_ptr;
4694
4c476991
JB
4695 if (!rdev->ops->set_power_mgmt)
4696 return -EOPNOTSUPP;
ffb9eb3d
KV
4697
4698 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4699
4700 if (state == wdev->ps)
4c476991 4701 return 0;
ffb9eb3d 4702
4c476991
JB
4703 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4704 wdev->ps_timeout);
4705 if (!err)
4706 wdev->ps = state;
ffb9eb3d
KV
4707 return err;
4708}
4709
4710static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4711{
4c476991 4712 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4713 enum nl80211_ps_state ps_state;
4714 struct wireless_dev *wdev;
4c476991 4715 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4716 struct sk_buff *msg;
4717 void *hdr;
4718 int err;
4719
ffb9eb3d
KV
4720 wdev = dev->ieee80211_ptr;
4721
4c476991
JB
4722 if (!rdev->ops->set_power_mgmt)
4723 return -EOPNOTSUPP;
ffb9eb3d
KV
4724
4725 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4726 if (!msg)
4727 return -ENOMEM;
ffb9eb3d
KV
4728
4729 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4730 NL80211_CMD_GET_POWER_SAVE);
4731 if (!hdr) {
4c476991 4732 err = -ENOBUFS;
ffb9eb3d
KV
4733 goto free_msg;
4734 }
4735
4736 if (wdev->ps)
4737 ps_state = NL80211_PS_ENABLED;
4738 else
4739 ps_state = NL80211_PS_DISABLED;
4740
4741 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4742
4743 genlmsg_end(msg, hdr);
4c476991 4744 return genlmsg_reply(msg, info);
ffb9eb3d 4745
4c476991 4746 nla_put_failure:
ffb9eb3d 4747 err = -ENOBUFS;
4c476991 4748 free_msg:
ffb9eb3d 4749 nlmsg_free(msg);
ffb9eb3d
KV
4750 return err;
4751}
4752
d6dc1a38
JO
4753static struct nla_policy
4754nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4755 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4756 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4757 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4758};
4759
4760static int nl80211_set_cqm_rssi(struct genl_info *info,
4761 s32 threshold, u32 hysteresis)
4762{
4c476991 4763 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4764 struct wireless_dev *wdev;
4c476991 4765 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4766
4767 if (threshold > 0)
4768 return -EINVAL;
4769
d6dc1a38
JO
4770 wdev = dev->ieee80211_ptr;
4771
4c476991
JB
4772 if (!rdev->ops->set_cqm_rssi_config)
4773 return -EOPNOTSUPP;
d6dc1a38 4774
074ac8df 4775 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4776 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4777 return -EOPNOTSUPP;
d6dc1a38 4778
4c476991
JB
4779 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4780 threshold, hysteresis);
d6dc1a38
JO
4781}
4782
4783static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4784{
4785 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4786 struct nlattr *cqm;
4787 int err;
4788
4789 cqm = info->attrs[NL80211_ATTR_CQM];
4790 if (!cqm) {
4791 err = -EINVAL;
4792 goto out;
4793 }
4794
4795 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4796 nl80211_attr_cqm_policy);
4797 if (err)
4798 goto out;
4799
4800 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4801 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4802 s32 threshold;
4803 u32 hysteresis;
4804 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4805 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4806 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4807 } else
4808 err = -EINVAL;
4809
4810out:
4811 return err;
4812}
4813
29cbe68c
JB
4814static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
4815{
4816 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4817 struct net_device *dev = info->user_ptr[1];
4818 struct mesh_config cfg;
c80d545d 4819 struct mesh_setup setup;
29cbe68c
JB
4820 int err;
4821
4822 /* start with default */
4823 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 4824 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 4825
24bdd9f4 4826 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 4827 /* and parse parameters if given */
24bdd9f4 4828 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
4829 if (err)
4830 return err;
4831 }
4832
4833 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
4834 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
4835 return -EINVAL;
4836
c80d545d
JC
4837 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
4838 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4839
4840 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
4841 /* parse additional setup parameters if given */
4842 err = nl80211_parse_mesh_setup(info, &setup);
4843 if (err)
4844 return err;
4845 }
4846
4847 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
4848}
4849
4850static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
4851{
4852 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4853 struct net_device *dev = info->user_ptr[1];
4854
4855 return cfg80211_leave_mesh(rdev, dev);
4856}
4857
ff1b6e69
JB
4858static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
4859{
4860 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4861 struct sk_buff *msg;
4862 void *hdr;
4863
4864 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
4865 return -EOPNOTSUPP;
4866
4867 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4868 if (!msg)
4869 return -ENOMEM;
4870
4871 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4872 NL80211_CMD_GET_WOWLAN);
4873 if (!hdr)
4874 goto nla_put_failure;
4875
4876 if (rdev->wowlan) {
4877 struct nlattr *nl_wowlan;
4878
4879 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
4880 if (!nl_wowlan)
4881 goto nla_put_failure;
4882
4883 if (rdev->wowlan->any)
4884 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
4885 if (rdev->wowlan->disconnect)
4886 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
4887 if (rdev->wowlan->magic_pkt)
4888 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
4889 if (rdev->wowlan->n_patterns) {
4890 struct nlattr *nl_pats, *nl_pat;
4891 int i, pat_len;
4892
4893 nl_pats = nla_nest_start(msg,
4894 NL80211_WOWLAN_TRIG_PKT_PATTERN);
4895 if (!nl_pats)
4896 goto nla_put_failure;
4897
4898 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
4899 nl_pat = nla_nest_start(msg, i + 1);
4900 if (!nl_pat)
4901 goto nla_put_failure;
4902 pat_len = rdev->wowlan->patterns[i].pattern_len;
4903 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
4904 DIV_ROUND_UP(pat_len, 8),
4905 rdev->wowlan->patterns[i].mask);
4906 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
4907 pat_len,
4908 rdev->wowlan->patterns[i].pattern);
4909 nla_nest_end(msg, nl_pat);
4910 }
4911 nla_nest_end(msg, nl_pats);
4912 }
4913
4914 nla_nest_end(msg, nl_wowlan);
4915 }
4916
4917 genlmsg_end(msg, hdr);
4918 return genlmsg_reply(msg, info);
4919
4920nla_put_failure:
4921 nlmsg_free(msg);
4922 return -ENOBUFS;
4923}
4924
4925static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
4926{
4927 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4928 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
4929 struct cfg80211_wowlan no_triggers = {};
4930 struct cfg80211_wowlan new_triggers = {};
4931 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
4932 int err, i;
4933
4934 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
4935 return -EOPNOTSUPP;
4936
4937 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
4938 goto no_triggers;
4939
4940 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
4941 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
4942 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
4943 nl80211_wowlan_policy);
4944 if (err)
4945 return err;
4946
4947 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
4948 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
4949 return -EINVAL;
4950 new_triggers.any = true;
4951 }
4952
4953 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
4954 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
4955 return -EINVAL;
4956 new_triggers.disconnect = true;
4957 }
4958
4959 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
4960 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
4961 return -EINVAL;
4962 new_triggers.magic_pkt = true;
4963 }
4964
4965 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
4966 struct nlattr *pat;
4967 int n_patterns = 0;
4968 int rem, pat_len, mask_len;
4969 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
4970
4971 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
4972 rem)
4973 n_patterns++;
4974 if (n_patterns > wowlan->n_patterns)
4975 return -EINVAL;
4976
4977 new_triggers.patterns = kcalloc(n_patterns,
4978 sizeof(new_triggers.patterns[0]),
4979 GFP_KERNEL);
4980 if (!new_triggers.patterns)
4981 return -ENOMEM;
4982
4983 new_triggers.n_patterns = n_patterns;
4984 i = 0;
4985
4986 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
4987 rem) {
4988 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
4989 nla_data(pat), nla_len(pat), NULL);
4990 err = -EINVAL;
4991 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
4992 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
4993 goto error;
4994 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
4995 mask_len = DIV_ROUND_UP(pat_len, 8);
4996 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
4997 mask_len)
4998 goto error;
4999 if (pat_len > wowlan->pattern_max_len ||
5000 pat_len < wowlan->pattern_min_len)
5001 goto error;
5002
5003 new_triggers.patterns[i].mask =
5004 kmalloc(mask_len + pat_len, GFP_KERNEL);
5005 if (!new_triggers.patterns[i].mask) {
5006 err = -ENOMEM;
5007 goto error;
5008 }
5009 new_triggers.patterns[i].pattern =
5010 new_triggers.patterns[i].mask + mask_len;
5011 memcpy(new_triggers.patterns[i].mask,
5012 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
5013 mask_len);
5014 new_triggers.patterns[i].pattern_len = pat_len;
5015 memcpy(new_triggers.patterns[i].pattern,
5016 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
5017 pat_len);
5018 i++;
5019 }
5020 }
5021
5022 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
5023 struct cfg80211_wowlan *ntrig;
5024 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
5025 GFP_KERNEL);
5026 if (!ntrig) {
5027 err = -ENOMEM;
5028 goto error;
5029 }
5030 cfg80211_rdev_free_wowlan(rdev);
5031 rdev->wowlan = ntrig;
5032 } else {
5033 no_triggers:
5034 cfg80211_rdev_free_wowlan(rdev);
5035 rdev->wowlan = NULL;
5036 }
5037
5038 return 0;
5039 error:
5040 for (i = 0; i < new_triggers.n_patterns; i++)
5041 kfree(new_triggers.patterns[i].mask);
5042 kfree(new_triggers.patterns);
5043 return err;
5044}
5045
4c476991
JB
5046#define NL80211_FLAG_NEED_WIPHY 0x01
5047#define NL80211_FLAG_NEED_NETDEV 0x02
5048#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
5049#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
5050#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
5051 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
5052
5053static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
5054 struct genl_info *info)
5055{
5056 struct cfg80211_registered_device *rdev;
5057 struct net_device *dev;
5058 int err;
5059 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
5060
5061 if (rtnl)
5062 rtnl_lock();
5063
5064 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
5065 rdev = cfg80211_get_dev_from_info(info);
5066 if (IS_ERR(rdev)) {
5067 if (rtnl)
5068 rtnl_unlock();
5069 return PTR_ERR(rdev);
5070 }
5071 info->user_ptr[0] = rdev;
5072 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
5073 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5074 if (err) {
5075 if (rtnl)
5076 rtnl_unlock();
5077 return err;
5078 }
41265714
JB
5079 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
5080 !netif_running(dev)) {
d537f5fd
JB
5081 cfg80211_unlock_rdev(rdev);
5082 dev_put(dev);
41265714
JB
5083 if (rtnl)
5084 rtnl_unlock();
5085 return -ENETDOWN;
5086 }
4c476991
JB
5087 info->user_ptr[0] = rdev;
5088 info->user_ptr[1] = dev;
5089 }
5090
5091 return 0;
5092}
5093
5094static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
5095 struct genl_info *info)
5096{
5097 if (info->user_ptr[0])
5098 cfg80211_unlock_rdev(info->user_ptr[0]);
5099 if (info->user_ptr[1])
5100 dev_put(info->user_ptr[1]);
5101 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
5102 rtnl_unlock();
5103}
5104
55682965
JB
5105static struct genl_ops nl80211_ops[] = {
5106 {
5107 .cmd = NL80211_CMD_GET_WIPHY,
5108 .doit = nl80211_get_wiphy,
5109 .dumpit = nl80211_dump_wiphy,
5110 .policy = nl80211_policy,
5111 /* can be retrieved by unprivileged users */
4c476991 5112 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
5113 },
5114 {
5115 .cmd = NL80211_CMD_SET_WIPHY,
5116 .doit = nl80211_set_wiphy,
5117 .policy = nl80211_policy,
5118 .flags = GENL_ADMIN_PERM,
4c476991 5119 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
5120 },
5121 {
5122 .cmd = NL80211_CMD_GET_INTERFACE,
5123 .doit = nl80211_get_interface,
5124 .dumpit = nl80211_dump_interface,
5125 .policy = nl80211_policy,
5126 /* can be retrieved by unprivileged users */
4c476991 5127 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
5128 },
5129 {
5130 .cmd = NL80211_CMD_SET_INTERFACE,
5131 .doit = nl80211_set_interface,
5132 .policy = nl80211_policy,
5133 .flags = GENL_ADMIN_PERM,
4c476991
JB
5134 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5135 NL80211_FLAG_NEED_RTNL,
55682965
JB
5136 },
5137 {
5138 .cmd = NL80211_CMD_NEW_INTERFACE,
5139 .doit = nl80211_new_interface,
5140 .policy = nl80211_policy,
5141 .flags = GENL_ADMIN_PERM,
4c476991
JB
5142 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5143 NL80211_FLAG_NEED_RTNL,
55682965
JB
5144 },
5145 {
5146 .cmd = NL80211_CMD_DEL_INTERFACE,
5147 .doit = nl80211_del_interface,
5148 .policy = nl80211_policy,
41ade00f 5149 .flags = GENL_ADMIN_PERM,
4c476991
JB
5150 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5151 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5152 },
5153 {
5154 .cmd = NL80211_CMD_GET_KEY,
5155 .doit = nl80211_get_key,
5156 .policy = nl80211_policy,
5157 .flags = GENL_ADMIN_PERM,
4c476991
JB
5158 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5159 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5160 },
5161 {
5162 .cmd = NL80211_CMD_SET_KEY,
5163 .doit = nl80211_set_key,
5164 .policy = nl80211_policy,
5165 .flags = GENL_ADMIN_PERM,
41265714 5166 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5167 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5168 },
5169 {
5170 .cmd = NL80211_CMD_NEW_KEY,
5171 .doit = nl80211_new_key,
5172 .policy = nl80211_policy,
5173 .flags = GENL_ADMIN_PERM,
41265714 5174 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5175 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5176 },
5177 {
5178 .cmd = NL80211_CMD_DEL_KEY,
5179 .doit = nl80211_del_key,
5180 .policy = nl80211_policy,
55682965 5181 .flags = GENL_ADMIN_PERM,
41265714 5182 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5183 NL80211_FLAG_NEED_RTNL,
55682965 5184 },
ed1b6cc7
JB
5185 {
5186 .cmd = NL80211_CMD_SET_BEACON,
5187 .policy = nl80211_policy,
5188 .flags = GENL_ADMIN_PERM,
5189 .doit = nl80211_addset_beacon,
4c476991
JB
5190 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5191 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
5192 },
5193 {
5194 .cmd = NL80211_CMD_NEW_BEACON,
5195 .policy = nl80211_policy,
5196 .flags = GENL_ADMIN_PERM,
5197 .doit = nl80211_addset_beacon,
4c476991
JB
5198 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5199 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
5200 },
5201 {
5202 .cmd = NL80211_CMD_DEL_BEACON,
5203 .policy = nl80211_policy,
5204 .flags = GENL_ADMIN_PERM,
5205 .doit = nl80211_del_beacon,
4c476991
JB
5206 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5207 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 5208 },
5727ef1b
JB
5209 {
5210 .cmd = NL80211_CMD_GET_STATION,
5211 .doit = nl80211_get_station,
2ec600d6 5212 .dumpit = nl80211_dump_station,
5727ef1b 5213 .policy = nl80211_policy,
4c476991
JB
5214 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5215 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5216 },
5217 {
5218 .cmd = NL80211_CMD_SET_STATION,
5219 .doit = nl80211_set_station,
5220 .policy = nl80211_policy,
5221 .flags = GENL_ADMIN_PERM,
4c476991
JB
5222 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5223 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5224 },
5225 {
5226 .cmd = NL80211_CMD_NEW_STATION,
5227 .doit = nl80211_new_station,
5228 .policy = nl80211_policy,
5229 .flags = GENL_ADMIN_PERM,
41265714 5230 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5231 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5232 },
5233 {
5234 .cmd = NL80211_CMD_DEL_STATION,
5235 .doit = nl80211_del_station,
5236 .policy = nl80211_policy,
2ec600d6 5237 .flags = GENL_ADMIN_PERM,
4c476991
JB
5238 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5239 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5240 },
5241 {
5242 .cmd = NL80211_CMD_GET_MPATH,
5243 .doit = nl80211_get_mpath,
5244 .dumpit = nl80211_dump_mpath,
5245 .policy = nl80211_policy,
5246 .flags = GENL_ADMIN_PERM,
41265714 5247 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5248 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5249 },
5250 {
5251 .cmd = NL80211_CMD_SET_MPATH,
5252 .doit = nl80211_set_mpath,
5253 .policy = nl80211_policy,
5254 .flags = GENL_ADMIN_PERM,
41265714 5255 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5256 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5257 },
5258 {
5259 .cmd = NL80211_CMD_NEW_MPATH,
5260 .doit = nl80211_new_mpath,
5261 .policy = nl80211_policy,
5262 .flags = GENL_ADMIN_PERM,
41265714 5263 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5264 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5265 },
5266 {
5267 .cmd = NL80211_CMD_DEL_MPATH,
5268 .doit = nl80211_del_mpath,
5269 .policy = nl80211_policy,
9f1ba906 5270 .flags = GENL_ADMIN_PERM,
4c476991
JB
5271 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5272 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
5273 },
5274 {
5275 .cmd = NL80211_CMD_SET_BSS,
5276 .doit = nl80211_set_bss,
5277 .policy = nl80211_policy,
b2e1b302 5278 .flags = GENL_ADMIN_PERM,
4c476991
JB
5279 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5280 NL80211_FLAG_NEED_RTNL,
b2e1b302 5281 },
f130347c
LR
5282 {
5283 .cmd = NL80211_CMD_GET_REG,
5284 .doit = nl80211_get_reg,
5285 .policy = nl80211_policy,
5286 /* can be retrieved by unprivileged users */
5287 },
b2e1b302
LR
5288 {
5289 .cmd = NL80211_CMD_SET_REG,
5290 .doit = nl80211_set_reg,
5291 .policy = nl80211_policy,
5292 .flags = GENL_ADMIN_PERM,
5293 },
5294 {
5295 .cmd = NL80211_CMD_REQ_SET_REG,
5296 .doit = nl80211_req_set_reg,
5297 .policy = nl80211_policy,
93da9cc1 5298 .flags = GENL_ADMIN_PERM,
5299 },
5300 {
24bdd9f4
JC
5301 .cmd = NL80211_CMD_GET_MESH_CONFIG,
5302 .doit = nl80211_get_mesh_config,
93da9cc1 5303 .policy = nl80211_policy,
5304 /* can be retrieved by unprivileged users */
4c476991
JB
5305 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5306 NL80211_FLAG_NEED_RTNL,
93da9cc1 5307 },
5308 {
24bdd9f4
JC
5309 .cmd = NL80211_CMD_SET_MESH_CONFIG,
5310 .doit = nl80211_update_mesh_config,
93da9cc1 5311 .policy = nl80211_policy,
9aed3cc1 5312 .flags = GENL_ADMIN_PERM,
29cbe68c 5313 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5314 NL80211_FLAG_NEED_RTNL,
9aed3cc1 5315 },
2a519311
JB
5316 {
5317 .cmd = NL80211_CMD_TRIGGER_SCAN,
5318 .doit = nl80211_trigger_scan,
5319 .policy = nl80211_policy,
5320 .flags = GENL_ADMIN_PERM,
41265714 5321 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5322 NL80211_FLAG_NEED_RTNL,
2a519311
JB
5323 },
5324 {
5325 .cmd = NL80211_CMD_GET_SCAN,
5326 .policy = nl80211_policy,
5327 .dumpit = nl80211_dump_scan,
5328 },
636a5d36
JM
5329 {
5330 .cmd = NL80211_CMD_AUTHENTICATE,
5331 .doit = nl80211_authenticate,
5332 .policy = nl80211_policy,
5333 .flags = GENL_ADMIN_PERM,
41265714 5334 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5335 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5336 },
5337 {
5338 .cmd = NL80211_CMD_ASSOCIATE,
5339 .doit = nl80211_associate,
5340 .policy = nl80211_policy,
5341 .flags = GENL_ADMIN_PERM,
41265714 5342 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5343 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5344 },
5345 {
5346 .cmd = NL80211_CMD_DEAUTHENTICATE,
5347 .doit = nl80211_deauthenticate,
5348 .policy = nl80211_policy,
5349 .flags = GENL_ADMIN_PERM,
41265714 5350 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5351 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5352 },
5353 {
5354 .cmd = NL80211_CMD_DISASSOCIATE,
5355 .doit = nl80211_disassociate,
5356 .policy = nl80211_policy,
5357 .flags = GENL_ADMIN_PERM,
41265714 5358 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5359 NL80211_FLAG_NEED_RTNL,
636a5d36 5360 },
04a773ad
JB
5361 {
5362 .cmd = NL80211_CMD_JOIN_IBSS,
5363 .doit = nl80211_join_ibss,
5364 .policy = nl80211_policy,
5365 .flags = GENL_ADMIN_PERM,
41265714 5366 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5367 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
5368 },
5369 {
5370 .cmd = NL80211_CMD_LEAVE_IBSS,
5371 .doit = nl80211_leave_ibss,
5372 .policy = nl80211_policy,
5373 .flags = GENL_ADMIN_PERM,
41265714 5374 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5375 NL80211_FLAG_NEED_RTNL,
04a773ad 5376 },
aff89a9b
JB
5377#ifdef CONFIG_NL80211_TESTMODE
5378 {
5379 .cmd = NL80211_CMD_TESTMODE,
5380 .doit = nl80211_testmode_do,
5381 .policy = nl80211_policy,
5382 .flags = GENL_ADMIN_PERM,
4c476991
JB
5383 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5384 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
5385 },
5386#endif
b23aa676
SO
5387 {
5388 .cmd = NL80211_CMD_CONNECT,
5389 .doit = nl80211_connect,
5390 .policy = nl80211_policy,
5391 .flags = GENL_ADMIN_PERM,
41265714 5392 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5393 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
5394 },
5395 {
5396 .cmd = NL80211_CMD_DISCONNECT,
5397 .doit = nl80211_disconnect,
5398 .policy = nl80211_policy,
5399 .flags = GENL_ADMIN_PERM,
41265714 5400 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5401 NL80211_FLAG_NEED_RTNL,
b23aa676 5402 },
463d0183
JB
5403 {
5404 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5405 .doit = nl80211_wiphy_netns,
5406 .policy = nl80211_policy,
5407 .flags = GENL_ADMIN_PERM,
4c476991
JB
5408 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5409 NL80211_FLAG_NEED_RTNL,
463d0183 5410 },
61fa713c
HS
5411 {
5412 .cmd = NL80211_CMD_GET_SURVEY,
5413 .policy = nl80211_policy,
5414 .dumpit = nl80211_dump_survey,
5415 },
67fbb16b
SO
5416 {
5417 .cmd = NL80211_CMD_SET_PMKSA,
5418 .doit = nl80211_setdel_pmksa,
5419 .policy = nl80211_policy,
5420 .flags = GENL_ADMIN_PERM,
4c476991
JB
5421 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5422 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5423 },
5424 {
5425 .cmd = NL80211_CMD_DEL_PMKSA,
5426 .doit = nl80211_setdel_pmksa,
5427 .policy = nl80211_policy,
5428 .flags = GENL_ADMIN_PERM,
4c476991
JB
5429 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5430 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5431 },
5432 {
5433 .cmd = NL80211_CMD_FLUSH_PMKSA,
5434 .doit = nl80211_flush_pmksa,
5435 .policy = nl80211_policy,
5436 .flags = GENL_ADMIN_PERM,
4c476991
JB
5437 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5438 NL80211_FLAG_NEED_RTNL,
67fbb16b 5439 },
9588bbd5
JM
5440 {
5441 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5442 .doit = nl80211_remain_on_channel,
5443 .policy = nl80211_policy,
5444 .flags = GENL_ADMIN_PERM,
41265714 5445 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5446 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
5447 },
5448 {
5449 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5450 .doit = nl80211_cancel_remain_on_channel,
5451 .policy = nl80211_policy,
5452 .flags = GENL_ADMIN_PERM,
41265714 5453 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5454 NL80211_FLAG_NEED_RTNL,
9588bbd5 5455 },
13ae75b1
JM
5456 {
5457 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5458 .doit = nl80211_set_tx_bitrate_mask,
5459 .policy = nl80211_policy,
5460 .flags = GENL_ADMIN_PERM,
4c476991
JB
5461 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5462 NL80211_FLAG_NEED_RTNL,
13ae75b1 5463 },
026331c4 5464 {
2e161f78
JB
5465 .cmd = NL80211_CMD_REGISTER_FRAME,
5466 .doit = nl80211_register_mgmt,
026331c4
JM
5467 .policy = nl80211_policy,
5468 .flags = GENL_ADMIN_PERM,
4c476991
JB
5469 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5470 NL80211_FLAG_NEED_RTNL,
026331c4
JM
5471 },
5472 {
2e161f78
JB
5473 .cmd = NL80211_CMD_FRAME,
5474 .doit = nl80211_tx_mgmt,
026331c4 5475 .policy = nl80211_policy,
f7ca38df
JB
5476 .flags = GENL_ADMIN_PERM,
5477 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5478 NL80211_FLAG_NEED_RTNL,
5479 },
5480 {
5481 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5482 .doit = nl80211_tx_mgmt_cancel_wait,
5483 .policy = nl80211_policy,
026331c4 5484 .flags = GENL_ADMIN_PERM,
41265714 5485 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5486 NL80211_FLAG_NEED_RTNL,
026331c4 5487 },
ffb9eb3d
KV
5488 {
5489 .cmd = NL80211_CMD_SET_POWER_SAVE,
5490 .doit = nl80211_set_power_save,
5491 .policy = nl80211_policy,
5492 .flags = GENL_ADMIN_PERM,
4c476991
JB
5493 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5494 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
5495 },
5496 {
5497 .cmd = NL80211_CMD_GET_POWER_SAVE,
5498 .doit = nl80211_get_power_save,
5499 .policy = nl80211_policy,
5500 /* can be retrieved by unprivileged users */
4c476991
JB
5501 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5502 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 5503 },
d6dc1a38
JO
5504 {
5505 .cmd = NL80211_CMD_SET_CQM,
5506 .doit = nl80211_set_cqm,
5507 .policy = nl80211_policy,
5508 .flags = GENL_ADMIN_PERM,
4c476991
JB
5509 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5510 NL80211_FLAG_NEED_RTNL,
d6dc1a38 5511 },
f444de05
JB
5512 {
5513 .cmd = NL80211_CMD_SET_CHANNEL,
5514 .doit = nl80211_set_channel,
5515 .policy = nl80211_policy,
5516 .flags = GENL_ADMIN_PERM,
4c476991
JB
5517 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5518 NL80211_FLAG_NEED_RTNL,
f444de05 5519 },
e8347eba
BJ
5520 {
5521 .cmd = NL80211_CMD_SET_WDS_PEER,
5522 .doit = nl80211_set_wds_peer,
5523 .policy = nl80211_policy,
5524 .flags = GENL_ADMIN_PERM,
43b19952
JB
5525 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5526 NL80211_FLAG_NEED_RTNL,
e8347eba 5527 },
29cbe68c
JB
5528 {
5529 .cmd = NL80211_CMD_JOIN_MESH,
5530 .doit = nl80211_join_mesh,
5531 .policy = nl80211_policy,
5532 .flags = GENL_ADMIN_PERM,
5533 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5534 NL80211_FLAG_NEED_RTNL,
5535 },
5536 {
5537 .cmd = NL80211_CMD_LEAVE_MESH,
5538 .doit = nl80211_leave_mesh,
5539 .policy = nl80211_policy,
5540 .flags = GENL_ADMIN_PERM,
5541 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5542 NL80211_FLAG_NEED_RTNL,
5543 },
ff1b6e69
JB
5544 {
5545 .cmd = NL80211_CMD_GET_WOWLAN,
5546 .doit = nl80211_get_wowlan,
5547 .policy = nl80211_policy,
5548 /* can be retrieved by unprivileged users */
5549 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5550 NL80211_FLAG_NEED_RTNL,
5551 },
5552 {
5553 .cmd = NL80211_CMD_SET_WOWLAN,
5554 .doit = nl80211_set_wowlan,
5555 .policy = nl80211_policy,
5556 .flags = GENL_ADMIN_PERM,
5557 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5558 NL80211_FLAG_NEED_RTNL,
5559 },
55682965 5560};
9588bbd5 5561
6039f6d2
JM
5562static struct genl_multicast_group nl80211_mlme_mcgrp = {
5563 .name = "mlme",
5564};
55682965
JB
5565
5566/* multicast groups */
5567static struct genl_multicast_group nl80211_config_mcgrp = {
5568 .name = "config",
5569};
2a519311
JB
5570static struct genl_multicast_group nl80211_scan_mcgrp = {
5571 .name = "scan",
5572};
73d54c9e
LR
5573static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5574 .name = "regulatory",
5575};
55682965
JB
5576
5577/* notification functions */
5578
5579void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5580{
5581 struct sk_buff *msg;
5582
fd2120ca 5583 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5584 if (!msg)
5585 return;
5586
5587 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5588 nlmsg_free(msg);
5589 return;
5590 }
5591
463d0183
JB
5592 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5593 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5594}
5595
362a415d
JB
5596static int nl80211_add_scan_req(struct sk_buff *msg,
5597 struct cfg80211_registered_device *rdev)
5598{
5599 struct cfg80211_scan_request *req = rdev->scan_req;
5600 struct nlattr *nest;
5601 int i;
5602
667503dd
JB
5603 ASSERT_RDEV_LOCK(rdev);
5604
362a415d
JB
5605 if (WARN_ON(!req))
5606 return 0;
5607
5608 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5609 if (!nest)
5610 goto nla_put_failure;
5611 for (i = 0; i < req->n_ssids; i++)
5612 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5613 nla_nest_end(msg, nest);
5614
5615 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5616 if (!nest)
5617 goto nla_put_failure;
5618 for (i = 0; i < req->n_channels; i++)
5619 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5620 nla_nest_end(msg, nest);
5621
5622 if (req->ie)
5623 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5624
5625 return 0;
5626 nla_put_failure:
5627 return -ENOBUFS;
5628}
5629
a538e2d5
JB
5630static int nl80211_send_scan_msg(struct sk_buff *msg,
5631 struct cfg80211_registered_device *rdev,
5632 struct net_device *netdev,
5633 u32 pid, u32 seq, int flags,
5634 u32 cmd)
2a519311
JB
5635{
5636 void *hdr;
5637
5638 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5639 if (!hdr)
5640 return -1;
5641
b5850a7a 5642 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5643 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5644
362a415d
JB
5645 /* ignore errors and send incomplete event anyway */
5646 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5647
5648 return genlmsg_end(msg, hdr);
5649
5650 nla_put_failure:
5651 genlmsg_cancel(msg, hdr);
5652 return -EMSGSIZE;
5653}
5654
a538e2d5
JB
5655void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5656 struct net_device *netdev)
5657{
5658 struct sk_buff *msg;
5659
5660 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5661 if (!msg)
5662 return;
5663
5664 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5665 NL80211_CMD_TRIGGER_SCAN) < 0) {
5666 nlmsg_free(msg);
5667 return;
5668 }
5669
463d0183
JB
5670 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5671 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5672}
5673
2a519311
JB
5674void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5675 struct net_device *netdev)
5676{
5677 struct sk_buff *msg;
5678
fd2120ca 5679 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5680 if (!msg)
5681 return;
5682
a538e2d5
JB
5683 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5684 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5685 nlmsg_free(msg);
5686 return;
5687 }
5688
463d0183
JB
5689 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5690 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5691}
5692
5693void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5694 struct net_device *netdev)
5695{
5696 struct sk_buff *msg;
5697
fd2120ca 5698 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5699 if (!msg)
5700 return;
5701
a538e2d5
JB
5702 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5703 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5704 nlmsg_free(msg);
5705 return;
5706 }
5707
463d0183
JB
5708 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5709 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5710}
5711
73d54c9e
LR
5712/*
5713 * This can happen on global regulatory changes or device specific settings
5714 * based on custom world regulatory domains.
5715 */
5716void nl80211_send_reg_change_event(struct regulatory_request *request)
5717{
5718 struct sk_buff *msg;
5719 void *hdr;
5720
fd2120ca 5721 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5722 if (!msg)
5723 return;
5724
5725 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5726 if (!hdr) {
5727 nlmsg_free(msg);
5728 return;
5729 }
5730
5731 /* Userspace can always count this one always being set */
5732 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5733
5734 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5735 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5736 NL80211_REGDOM_TYPE_WORLD);
5737 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5738 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5739 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5740 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5741 request->intersect)
5742 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5743 NL80211_REGDOM_TYPE_INTERSECTION);
5744 else {
5745 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5746 NL80211_REGDOM_TYPE_COUNTRY);
5747 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5748 }
5749
5750 if (wiphy_idx_valid(request->wiphy_idx))
5751 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5752
5753 if (genlmsg_end(msg, hdr) < 0) {
5754 nlmsg_free(msg);
5755 return;
5756 }
5757
bc43b28c 5758 rcu_read_lock();
463d0183 5759 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5760 GFP_ATOMIC);
5761 rcu_read_unlock();
73d54c9e
LR
5762
5763 return;
5764
5765nla_put_failure:
5766 genlmsg_cancel(msg, hdr);
5767 nlmsg_free(msg);
5768}
5769
6039f6d2
JM
5770static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5771 struct net_device *netdev,
5772 const u8 *buf, size_t len,
e6d6e342 5773 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5774{
5775 struct sk_buff *msg;
5776 void *hdr;
5777
e6d6e342 5778 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5779 if (!msg)
5780 return;
5781
5782 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5783 if (!hdr) {
5784 nlmsg_free(msg);
5785 return;
5786 }
5787
5788 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5789 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5790 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5791
5792 if (genlmsg_end(msg, hdr) < 0) {
5793 nlmsg_free(msg);
5794 return;
5795 }
5796
463d0183
JB
5797 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5798 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5799 return;
5800
5801 nla_put_failure:
5802 genlmsg_cancel(msg, hdr);
5803 nlmsg_free(msg);
5804}
5805
5806void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5807 struct net_device *netdev, const u8 *buf,
5808 size_t len, gfp_t gfp)
6039f6d2
JM
5809{
5810 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5811 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5812}
5813
5814void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5815 struct net_device *netdev, const u8 *buf,
e6d6e342 5816 size_t len, gfp_t gfp)
6039f6d2 5817{
e6d6e342
JB
5818 nl80211_send_mlme_event(rdev, netdev, buf, len,
5819 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5820}
5821
53b46b84 5822void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5823 struct net_device *netdev, const u8 *buf,
5824 size_t len, gfp_t gfp)
6039f6d2
JM
5825{
5826 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5827 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5828}
5829
53b46b84
JM
5830void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5831 struct net_device *netdev, const u8 *buf,
e6d6e342 5832 size_t len, gfp_t gfp)
6039f6d2
JM
5833{
5834 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5835 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5836}
5837
cf4e594e
JM
5838void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
5839 struct net_device *netdev, const u8 *buf,
5840 size_t len, gfp_t gfp)
5841{
5842 nl80211_send_mlme_event(rdev, netdev, buf, len,
5843 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
5844}
5845
5846void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
5847 struct net_device *netdev, const u8 *buf,
5848 size_t len, gfp_t gfp)
5849{
5850 nl80211_send_mlme_event(rdev, netdev, buf, len,
5851 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
5852}
5853
1b06bb40
LR
5854static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5855 struct net_device *netdev, int cmd,
e6d6e342 5856 const u8 *addr, gfp_t gfp)
1965c853
JM
5857{
5858 struct sk_buff *msg;
5859 void *hdr;
5860
e6d6e342 5861 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5862 if (!msg)
5863 return;
5864
5865 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5866 if (!hdr) {
5867 nlmsg_free(msg);
5868 return;
5869 }
5870
5871 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5872 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5873 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5874 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5875
5876 if (genlmsg_end(msg, hdr) < 0) {
5877 nlmsg_free(msg);
5878 return;
5879 }
5880
463d0183
JB
5881 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5882 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5883 return;
5884
5885 nla_put_failure:
5886 genlmsg_cancel(msg, hdr);
5887 nlmsg_free(msg);
5888}
5889
5890void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5891 struct net_device *netdev, const u8 *addr,
5892 gfp_t gfp)
1965c853
JM
5893{
5894 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5895 addr, gfp);
1965c853
JM
5896}
5897
5898void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5899 struct net_device *netdev, const u8 *addr,
5900 gfp_t gfp)
1965c853 5901{
e6d6e342
JB
5902 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5903 addr, gfp);
1965c853
JM
5904}
5905
b23aa676
SO
5906void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5907 struct net_device *netdev, const u8 *bssid,
5908 const u8 *req_ie, size_t req_ie_len,
5909 const u8 *resp_ie, size_t resp_ie_len,
5910 u16 status, gfp_t gfp)
5911{
5912 struct sk_buff *msg;
5913 void *hdr;
5914
5915 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5916 if (!msg)
5917 return;
5918
5919 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5920 if (!hdr) {
5921 nlmsg_free(msg);
5922 return;
5923 }
5924
5925 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5926 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5927 if (bssid)
5928 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5929 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5930 if (req_ie)
5931 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5932 if (resp_ie)
5933 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5934
5935 if (genlmsg_end(msg, hdr) < 0) {
5936 nlmsg_free(msg);
5937 return;
5938 }
5939
463d0183
JB
5940 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5941 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5942 return;
5943
5944 nla_put_failure:
5945 genlmsg_cancel(msg, hdr);
5946 nlmsg_free(msg);
5947
5948}
5949
5950void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5951 struct net_device *netdev, const u8 *bssid,
5952 const u8 *req_ie, size_t req_ie_len,
5953 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5954{
5955 struct sk_buff *msg;
5956 void *hdr;
5957
5958 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5959 if (!msg)
5960 return;
5961
5962 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5963 if (!hdr) {
5964 nlmsg_free(msg);
5965 return;
5966 }
5967
5968 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5969 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5970 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5971 if (req_ie)
5972 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5973 if (resp_ie)
5974 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5975
5976 if (genlmsg_end(msg, hdr) < 0) {
5977 nlmsg_free(msg);
5978 return;
5979 }
5980
463d0183
JB
5981 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5982 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5983 return;
5984
5985 nla_put_failure:
5986 genlmsg_cancel(msg, hdr);
5987 nlmsg_free(msg);
5988
5989}
5990
5991void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5992 struct net_device *netdev, u16 reason,
667503dd 5993 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5994{
5995 struct sk_buff *msg;
5996 void *hdr;
5997
667503dd 5998 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5999 if (!msg)
6000 return;
6001
6002 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
6003 if (!hdr) {
6004 nlmsg_free(msg);
6005 return;
6006 }
6007
6008 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6009 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6010 if (from_ap && reason)
6011 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
6012 if (from_ap)
6013 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
6014 if (ie)
6015 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
6016
6017 if (genlmsg_end(msg, hdr) < 0) {
6018 nlmsg_free(msg);
6019 return;
6020 }
6021
463d0183
JB
6022 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6023 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
6024 return;
6025
6026 nla_put_failure:
6027 genlmsg_cancel(msg, hdr);
6028 nlmsg_free(msg);
6029
6030}
6031
04a773ad
JB
6032void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
6033 struct net_device *netdev, const u8 *bssid,
6034 gfp_t gfp)
6035{
6036 struct sk_buff *msg;
6037 void *hdr;
6038
fd2120ca 6039 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
6040 if (!msg)
6041 return;
6042
6043 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
6044 if (!hdr) {
6045 nlmsg_free(msg);
6046 return;
6047 }
6048
6049 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6050 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6051 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6052
6053 if (genlmsg_end(msg, hdr) < 0) {
6054 nlmsg_free(msg);
6055 return;
6056 }
6057
463d0183
JB
6058 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6059 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
6060 return;
6061
6062 nla_put_failure:
6063 genlmsg_cancel(msg, hdr);
6064 nlmsg_free(msg);
6065}
6066
c93b5e71
JC
6067void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
6068 struct net_device *netdev,
6069 const u8 *macaddr, const u8* ie, u8 ie_len,
6070 gfp_t gfp)
6071{
6072 struct sk_buff *msg;
6073 void *hdr;
6074
6075 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6076 if (!msg)
6077 return;
6078
6079 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
6080 if (!hdr) {
6081 nlmsg_free(msg);
6082 return;
6083 }
6084
6085 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6086 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6087 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
6088 if (ie_len && ie)
6089 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
6090
6091 if (genlmsg_end(msg, hdr) < 0) {
6092 nlmsg_free(msg);
6093 return;
6094 }
6095
6096 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6097 nl80211_mlme_mcgrp.id, gfp);
6098 return;
6099
6100 nla_put_failure:
6101 genlmsg_cancel(msg, hdr);
6102 nlmsg_free(msg);
6103}
6104
a3b8b056
JM
6105void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
6106 struct net_device *netdev, const u8 *addr,
6107 enum nl80211_key_type key_type, int key_id,
e6d6e342 6108 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
6109{
6110 struct sk_buff *msg;
6111 void *hdr;
6112
e6d6e342 6113 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
6114 if (!msg)
6115 return;
6116
6117 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
6118 if (!hdr) {
6119 nlmsg_free(msg);
6120 return;
6121 }
6122
6123 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6124 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6125 if (addr)
6126 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6127 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
6128 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
6129 if (tsc)
6130 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
6131
6132 if (genlmsg_end(msg, hdr) < 0) {
6133 nlmsg_free(msg);
6134 return;
6135 }
6136
463d0183
JB
6137 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6138 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
6139 return;
6140
6141 nla_put_failure:
6142 genlmsg_cancel(msg, hdr);
6143 nlmsg_free(msg);
6144}
6145
6bad8766
LR
6146void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
6147 struct ieee80211_channel *channel_before,
6148 struct ieee80211_channel *channel_after)
6149{
6150 struct sk_buff *msg;
6151 void *hdr;
6152 struct nlattr *nl_freq;
6153
fd2120ca 6154 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
6155 if (!msg)
6156 return;
6157
6158 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
6159 if (!hdr) {
6160 nlmsg_free(msg);
6161 return;
6162 }
6163
6164 /*
6165 * Since we are applying the beacon hint to a wiphy we know its
6166 * wiphy_idx is valid
6167 */
6168 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
6169
6170 /* Before */
6171 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
6172 if (!nl_freq)
6173 goto nla_put_failure;
6174 if (nl80211_msg_put_channel(msg, channel_before))
6175 goto nla_put_failure;
6176 nla_nest_end(msg, nl_freq);
6177
6178 /* After */
6179 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
6180 if (!nl_freq)
6181 goto nla_put_failure;
6182 if (nl80211_msg_put_channel(msg, channel_after))
6183 goto nla_put_failure;
6184 nla_nest_end(msg, nl_freq);
6185
6186 if (genlmsg_end(msg, hdr) < 0) {
6187 nlmsg_free(msg);
6188 return;
6189 }
6190
463d0183
JB
6191 rcu_read_lock();
6192 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6193 GFP_ATOMIC);
6194 rcu_read_unlock();
6bad8766
LR
6195
6196 return;
6197
6198nla_put_failure:
6199 genlmsg_cancel(msg, hdr);
6200 nlmsg_free(msg);
6201}
6202
9588bbd5
JM
6203static void nl80211_send_remain_on_chan_event(
6204 int cmd, struct cfg80211_registered_device *rdev,
6205 struct net_device *netdev, u64 cookie,
6206 struct ieee80211_channel *chan,
6207 enum nl80211_channel_type channel_type,
6208 unsigned int duration, gfp_t gfp)
6209{
6210 struct sk_buff *msg;
6211 void *hdr;
6212
6213 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6214 if (!msg)
6215 return;
6216
6217 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6218 if (!hdr) {
6219 nlmsg_free(msg);
6220 return;
6221 }
6222
6223 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6224 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6225 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
6226 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
6227 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6228
6229 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6230 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6231
6232 if (genlmsg_end(msg, hdr) < 0) {
6233 nlmsg_free(msg);
6234 return;
6235 }
6236
6237 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6238 nl80211_mlme_mcgrp.id, gfp);
6239 return;
6240
6241 nla_put_failure:
6242 genlmsg_cancel(msg, hdr);
6243 nlmsg_free(msg);
6244}
6245
6246void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6247 struct net_device *netdev, u64 cookie,
6248 struct ieee80211_channel *chan,
6249 enum nl80211_channel_type channel_type,
6250 unsigned int duration, gfp_t gfp)
6251{
6252 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6253 rdev, netdev, cookie, chan,
6254 channel_type, duration, gfp);
6255}
6256
6257void nl80211_send_remain_on_channel_cancel(
6258 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6259 u64 cookie, struct ieee80211_channel *chan,
6260 enum nl80211_channel_type channel_type, gfp_t gfp)
6261{
6262 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6263 rdev, netdev, cookie, chan,
6264 channel_type, 0, gfp);
6265}
6266
98b62183
JB
6267void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6268 struct net_device *dev, const u8 *mac_addr,
6269 struct station_info *sinfo, gfp_t gfp)
6270{
6271 struct sk_buff *msg;
6272
6273 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6274 if (!msg)
6275 return;
6276
6277 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6278 nlmsg_free(msg);
6279 return;
6280 }
6281
6282 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6283 nl80211_mlme_mcgrp.id, gfp);
6284}
6285
ec15e68b
JM
6286void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
6287 struct net_device *dev, const u8 *mac_addr,
6288 gfp_t gfp)
6289{
6290 struct sk_buff *msg;
6291 void *hdr;
6292
6293 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6294 if (!msg)
6295 return;
6296
6297 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
6298 if (!hdr) {
6299 nlmsg_free(msg);
6300 return;
6301 }
6302
6303 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
6304 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
6305
6306 if (genlmsg_end(msg, hdr) < 0) {
6307 nlmsg_free(msg);
6308 return;
6309 }
6310
6311 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6312 nl80211_mlme_mcgrp.id, gfp);
6313 return;
6314
6315 nla_put_failure:
6316 genlmsg_cancel(msg, hdr);
6317 nlmsg_free(msg);
6318}
6319
2e161f78
JB
6320int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6321 struct net_device *netdev, u32 nlpid,
6322 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
6323{
6324 struct sk_buff *msg;
6325 void *hdr;
6326 int err;
6327
6328 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6329 if (!msg)
6330 return -ENOMEM;
6331
2e161f78 6332 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
6333 if (!hdr) {
6334 nlmsg_free(msg);
6335 return -ENOMEM;
6336 }
6337
6338 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6339 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6340 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6341 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6342
6343 err = genlmsg_end(msg, hdr);
6344 if (err < 0) {
6345 nlmsg_free(msg);
6346 return err;
6347 }
6348
6349 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6350 if (err < 0)
6351 return err;
6352 return 0;
6353
6354 nla_put_failure:
6355 genlmsg_cancel(msg, hdr);
6356 nlmsg_free(msg);
6357 return -ENOBUFS;
6358}
6359
2e161f78
JB
6360void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6361 struct net_device *netdev, u64 cookie,
6362 const u8 *buf, size_t len, bool ack,
6363 gfp_t gfp)
026331c4
JM
6364{
6365 struct sk_buff *msg;
6366 void *hdr;
6367
6368 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6369 if (!msg)
6370 return;
6371
2e161f78 6372 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6373 if (!hdr) {
6374 nlmsg_free(msg);
6375 return;
6376 }
6377
6378 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6379 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6380 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6381 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6382 if (ack)
6383 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6384
6385 if (genlmsg_end(msg, hdr) < 0) {
6386 nlmsg_free(msg);
6387 return;
6388 }
6389
6390 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6391 return;
6392
6393 nla_put_failure:
6394 genlmsg_cancel(msg, hdr);
6395 nlmsg_free(msg);
6396}
6397
d6dc1a38
JO
6398void
6399nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6400 struct net_device *netdev,
6401 enum nl80211_cqm_rssi_threshold_event rssi_event,
6402 gfp_t gfp)
6403{
6404 struct sk_buff *msg;
6405 struct nlattr *pinfoattr;
6406 void *hdr;
6407
6408 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6409 if (!msg)
6410 return;
6411
6412 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6413 if (!hdr) {
6414 nlmsg_free(msg);
6415 return;
6416 }
6417
6418 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6419 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6420
6421 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6422 if (!pinfoattr)
6423 goto nla_put_failure;
6424
6425 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6426 rssi_event);
6427
6428 nla_nest_end(msg, pinfoattr);
6429
6430 if (genlmsg_end(msg, hdr) < 0) {
6431 nlmsg_free(msg);
6432 return;
6433 }
6434
6435 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6436 nl80211_mlme_mcgrp.id, gfp);
6437 return;
6438
6439 nla_put_failure:
6440 genlmsg_cancel(msg, hdr);
6441 nlmsg_free(msg);
6442}
6443
c063dbf5
JB
6444void
6445nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6446 struct net_device *netdev, const u8 *peer,
6447 u32 num_packets, gfp_t gfp)
6448{
6449 struct sk_buff *msg;
6450 struct nlattr *pinfoattr;
6451 void *hdr;
6452
6453 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6454 if (!msg)
6455 return;
6456
6457 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6458 if (!hdr) {
6459 nlmsg_free(msg);
6460 return;
6461 }
6462
6463 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6464 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6465 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6466
6467 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6468 if (!pinfoattr)
6469 goto nla_put_failure;
6470
6471 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6472
6473 nla_nest_end(msg, pinfoattr);
6474
6475 if (genlmsg_end(msg, hdr) < 0) {
6476 nlmsg_free(msg);
6477 return;
6478 }
6479
6480 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6481 nl80211_mlme_mcgrp.id, gfp);
6482 return;
6483
6484 nla_put_failure:
6485 genlmsg_cancel(msg, hdr);
6486 nlmsg_free(msg);
6487}
6488
026331c4
JM
6489static int nl80211_netlink_notify(struct notifier_block * nb,
6490 unsigned long state,
6491 void *_notify)
6492{
6493 struct netlink_notify *notify = _notify;
6494 struct cfg80211_registered_device *rdev;
6495 struct wireless_dev *wdev;
6496
6497 if (state != NETLINK_URELEASE)
6498 return NOTIFY_DONE;
6499
6500 rcu_read_lock();
6501
6502 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6503 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6504 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6505
6506 rcu_read_unlock();
6507
6508 return NOTIFY_DONE;
6509}
6510
6511static struct notifier_block nl80211_netlink_notifier = {
6512 .notifier_call = nl80211_netlink_notify,
6513};
6514
55682965
JB
6515/* initialisation/exit functions */
6516
6517int nl80211_init(void)
6518{
0d63cbb5 6519 int err;
55682965 6520
0d63cbb5
MM
6521 err = genl_register_family_with_ops(&nl80211_fam,
6522 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6523 if (err)
6524 return err;
6525
55682965
JB
6526 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6527 if (err)
6528 goto err_out;
6529
2a519311
JB
6530 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6531 if (err)
6532 goto err_out;
6533
73d54c9e
LR
6534 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6535 if (err)
6536 goto err_out;
6537
6039f6d2
JM
6538 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6539 if (err)
6540 goto err_out;
6541
aff89a9b
JB
6542#ifdef CONFIG_NL80211_TESTMODE
6543 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6544 if (err)
6545 goto err_out;
6546#endif
6547
026331c4
JM
6548 err = netlink_register_notifier(&nl80211_netlink_notifier);
6549 if (err)
6550 goto err_out;
6551
55682965
JB
6552 return 0;
6553 err_out:
6554 genl_unregister_family(&nl80211_fam);
6555 return err;
6556}
6557
6558void nl80211_exit(void)
6559{
026331c4 6560 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6561 genl_unregister_family(&nl80211_fam);
6562}