]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
cfg80211: Move the definition of struct mac_address up
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
e35e4d28 25#include "rdev-ops.h"
55682965 26
5fb628e9
JM
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
89a54e48
JB
49/* returns ERR_PTR values */
50static struct wireless_dev *
51__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 52{
89a54e48
JB
53 struct cfg80211_registered_device *rdev;
54 struct wireless_dev *result = NULL;
55 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
56 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
57 u64 wdev_id;
58 int wiphy_idx = -1;
59 int ifidx = -1;
55682965 60
89a54e48 61 assert_cfg80211_lock();
55682965 62
89a54e48
JB
63 if (!have_ifidx && !have_wdev_id)
64 return ERR_PTR(-EINVAL);
55682965 65
89a54e48
JB
66 if (have_ifidx)
67 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
68 if (have_wdev_id) {
69 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
70 wiphy_idx = wdev_id >> 32;
55682965
JB
71 }
72
89a54e48
JB
73 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
74 struct wireless_dev *wdev;
75
76 if (wiphy_net(&rdev->wiphy) != netns)
77 continue;
78
79 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
80 continue;
81
82 mutex_lock(&rdev->devlist_mtx);
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
94 mutex_unlock(&rdev->devlist_mtx);
95
96 if (result)
97 break;
98 }
99
100 if (result)
101 return result;
102 return ERR_PTR(-ENODEV);
55682965
JB
103}
104
a9455408 105static struct cfg80211_registered_device *
878d9ec7 106__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 107{
7fee4778
JB
108 struct cfg80211_registered_device *rdev = NULL, *tmp;
109 struct net_device *netdev;
a9455408
JB
110
111 assert_cfg80211_lock();
112
878d9ec7 113 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
114 !attrs[NL80211_ATTR_IFINDEX] &&
115 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
116 return ERR_PTR(-EINVAL);
117
878d9ec7 118 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 119 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 120 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 121
89a54e48
JB
122 if (attrs[NL80211_ATTR_WDEV]) {
123 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
124 struct wireless_dev *wdev;
125 bool found = false;
126
127 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
128 if (tmp) {
129 /* make sure wdev exists */
130 mutex_lock(&tmp->devlist_mtx);
131 list_for_each_entry(wdev, &tmp->wdev_list, list) {
132 if (wdev->identifier != (u32)wdev_id)
133 continue;
134 found = true;
135 break;
136 }
137 mutex_unlock(&tmp->devlist_mtx);
138
139 if (!found)
140 tmp = NULL;
141
142 if (rdev && tmp != rdev)
143 return ERR_PTR(-EINVAL);
144 rdev = tmp;
145 }
146 }
147
878d9ec7
JB
148 if (attrs[NL80211_ATTR_IFINDEX]) {
149 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 150 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
151 if (netdev) {
152 if (netdev->ieee80211_ptr)
153 tmp = wiphy_to_dev(
154 netdev->ieee80211_ptr->wiphy);
155 else
156 tmp = NULL;
157
158 dev_put(netdev);
159
160 /* not wireless device -- return error */
161 if (!tmp)
162 return ERR_PTR(-EINVAL);
163
164 /* mismatch -- return error */
165 if (rdev && tmp != rdev)
166 return ERR_PTR(-EINVAL);
167
168 rdev = tmp;
a9455408 169 }
a9455408 170 }
a9455408 171
4f7eff10
JB
172 if (!rdev)
173 return ERR_PTR(-ENODEV);
a9455408 174
4f7eff10
JB
175 if (netns != wiphy_net(&rdev->wiphy))
176 return ERR_PTR(-ENODEV);
177
178 return rdev;
a9455408
JB
179}
180
181/*
182 * This function returns a pointer to the driver
183 * that the genl_info item that is passed refers to.
184 * If successful, it returns non-NULL and also locks
185 * the driver's mutex!
186 *
187 * This means that you need to call cfg80211_unlock_rdev()
188 * before being allowed to acquire &cfg80211_mutex!
189 *
190 * This is necessary because we need to lock the global
191 * mutex to get an item off the list safely, and then
192 * we lock the rdev mutex so it doesn't go away under us.
193 *
194 * We don't want to keep cfg80211_mutex locked
195 * for all the time in order to allow requests on
196 * other interfaces to go through at the same time.
197 *
198 * The result of this can be a PTR_ERR and hence must
199 * be checked with IS_ERR() for errors.
200 */
201static struct cfg80211_registered_device *
4f7eff10 202cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408
JB
203{
204 struct cfg80211_registered_device *rdev;
205
206 mutex_lock(&cfg80211_mutex);
878d9ec7 207 rdev = __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
208
209 /* if it is not an error we grab the lock on
210 * it to assure it won't be going away while
211 * we operate on it */
212 if (!IS_ERR(rdev))
213 mutex_lock(&rdev->mtx);
214
215 mutex_unlock(&cfg80211_mutex);
216
217 return rdev;
218}
219
55682965 220/* policy for the attributes */
b54452b0 221static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
222 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
223 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 224 .len = 20-1 },
31888487 225 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 226
72bdcf34 227 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 228 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
229 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
230 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
231 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
232
b9a5f8ca
JM
233 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
234 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
235 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
236 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 237 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
238
239 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
240 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
241 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 242
e007b857
EP
243 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
244 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 245
b9454e83 246 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
247 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
248 .len = WLAN_MAX_KEY_LEN },
249 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
250 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
251 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 252 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 253 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
254
255 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
256 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
257 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
258 .len = IEEE80211_MAX_DATA_LEN },
259 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
260 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
261 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
262 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
263 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
264 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
265 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 266 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 267 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 268 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 269 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 270 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 271 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 272
b2e1b302
LR
273 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
274 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
275
9f1ba906
JM
276 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
277 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
278 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
279 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
280 .len = NL80211_MAX_SUPP_RATES },
50b12f59 281 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 282
24bdd9f4 283 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 284 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 285
6c739419 286 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
287
288 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
289 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
290 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
291 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
292 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
293
294 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
295 .len = IEEE80211_MAX_SSID_LEN },
296 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
297 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 298 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 299 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 300 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
301 [NL80211_ATTR_STA_FLAGS2] = {
302 .len = sizeof(struct nl80211_sta_flag_update),
303 },
3f77316c 304 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
305 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
306 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
307 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
308 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
309 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 310 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 311 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
312 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
313 .len = WLAN_PMKID_LEN },
9588bbd5
JM
314 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
315 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 316 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
317 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
318 .len = IEEE80211_MAX_DATA_LEN },
319 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 320 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 321 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 322 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 323 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
324 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
325 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 326 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
327 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
328 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 329 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 330 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 331 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 332 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 333 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 334 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 335 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 336 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 337 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
338 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
339 .len = IEEE80211_MAX_DATA_LEN },
340 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
341 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 342 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 343 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 344 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
345 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
346 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
347 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
348 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
349 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 350 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
351 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
352 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 353 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
354 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
355 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
356 .len = NL80211_HT_CAPABILITY_LEN
357 },
1d9d9213 358 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 359 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 360 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 361 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 362 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 363 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 364 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 365 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
366 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
367 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
55682965
JB
368};
369
e31b8213 370/* policy for the key attributes */
b54452b0 371static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 372 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
373 [NL80211_KEY_IDX] = { .type = NLA_U8 },
374 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 375 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
376 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
377 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 378 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
379 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
380};
381
382/* policy for the key default flags */
383static const struct nla_policy
384nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
385 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
386 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
387};
388
ff1b6e69
JB
389/* policy for WoWLAN attributes */
390static const struct nla_policy
391nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
392 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
393 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
394 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
395 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
396 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
397 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
398 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
399 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
400};
401
e5497d76
JB
402/* policy for GTK rekey offload attributes */
403static const struct nla_policy
404nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
405 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
406 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
407 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
408};
409
a1f1c21c
LC
410static const struct nla_policy
411nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 412 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 413 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 414 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
415};
416
a043897a
HS
417/* ifidx get helper */
418static int nl80211_get_ifidx(struct netlink_callback *cb)
419{
420 int res;
421
422 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
423 nl80211_fam.attrbuf, nl80211_fam.maxattr,
424 nl80211_policy);
425 if (res)
426 return res;
427
428 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
429 return -EINVAL;
430
431 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
432 if (!res)
433 return -EINVAL;
434 return res;
435}
436
67748893
JB
437static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
438 struct netlink_callback *cb,
439 struct cfg80211_registered_device **rdev,
440 struct net_device **dev)
441{
442 int ifidx = cb->args[0];
443 int err;
444
445 if (!ifidx)
446 ifidx = nl80211_get_ifidx(cb);
447 if (ifidx < 0)
448 return ifidx;
449
450 cb->args[0] = ifidx;
451
452 rtnl_lock();
453
454 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
455 if (!*dev) {
456 err = -ENODEV;
457 goto out_rtnl;
458 }
459
460 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
461 if (IS_ERR(*rdev)) {
462 err = PTR_ERR(*rdev);
67748893
JB
463 goto out_rtnl;
464 }
465
466 return 0;
467 out_rtnl:
468 rtnl_unlock();
469 return err;
470}
471
472static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
473{
474 cfg80211_unlock_rdev(rdev);
475 rtnl_unlock();
476}
477
f4a11bb0
JB
478/* IE validation */
479static bool is_valid_ie_attr(const struct nlattr *attr)
480{
481 const u8 *pos;
482 int len;
483
484 if (!attr)
485 return true;
486
487 pos = nla_data(attr);
488 len = nla_len(attr);
489
490 while (len) {
491 u8 elemlen;
492
493 if (len < 2)
494 return false;
495 len -= 2;
496
497 elemlen = pos[1];
498 if (elemlen > len)
499 return false;
500
501 len -= elemlen;
502 pos += 2 + elemlen;
503 }
504
505 return true;
506}
507
55682965 508/* message building helper */
15e47304 509static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
510 int flags, u8 cmd)
511{
512 /* since there is no private header just add the generic one */
15e47304 513 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
514}
515
5dab3b8a
LR
516static int nl80211_msg_put_channel(struct sk_buff *msg,
517 struct ieee80211_channel *chan)
518{
9360ffd1
DM
519 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
520 chan->center_freq))
521 goto nla_put_failure;
5dab3b8a 522
9360ffd1
DM
523 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
524 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
525 goto nla_put_failure;
526 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
527 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
528 goto nla_put_failure;
529 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
530 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
531 goto nla_put_failure;
532 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
533 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
534 goto nla_put_failure;
5dab3b8a 535
9360ffd1
DM
536 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
537 DBM_TO_MBM(chan->max_power)))
538 goto nla_put_failure;
5dab3b8a
LR
539
540 return 0;
541
542 nla_put_failure:
543 return -ENOBUFS;
544}
545
55682965
JB
546/* netlink command implementations */
547
b9454e83
JB
548struct key_parse {
549 struct key_params p;
550 int idx;
e31b8213 551 int type;
b9454e83 552 bool def, defmgmt;
dbd2fd65 553 bool def_uni, def_multi;
b9454e83
JB
554};
555
556static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
557{
558 struct nlattr *tb[NL80211_KEY_MAX + 1];
559 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
560 nl80211_key_policy);
561 if (err)
562 return err;
563
564 k->def = !!tb[NL80211_KEY_DEFAULT];
565 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
566
dbd2fd65
JB
567 if (k->def) {
568 k->def_uni = true;
569 k->def_multi = true;
570 }
571 if (k->defmgmt)
572 k->def_multi = true;
573
b9454e83
JB
574 if (tb[NL80211_KEY_IDX])
575 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
576
577 if (tb[NL80211_KEY_DATA]) {
578 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
579 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
580 }
581
582 if (tb[NL80211_KEY_SEQ]) {
583 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
584 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
585 }
586
587 if (tb[NL80211_KEY_CIPHER])
588 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
589
e31b8213
JB
590 if (tb[NL80211_KEY_TYPE]) {
591 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
592 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
593 return -EINVAL;
594 }
595
dbd2fd65
JB
596 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
597 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
598 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
599 tb[NL80211_KEY_DEFAULT_TYPES],
600 nl80211_key_default_policy);
dbd2fd65
JB
601 if (err)
602 return err;
603
604 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
605 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
606 }
607
b9454e83
JB
608 return 0;
609}
610
611static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
612{
613 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
614 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
615 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
616 }
617
618 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
619 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
620 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
621 }
622
623 if (info->attrs[NL80211_ATTR_KEY_IDX])
624 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
625
626 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
627 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
628
629 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
630 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
631
dbd2fd65
JB
632 if (k->def) {
633 k->def_uni = true;
634 k->def_multi = true;
635 }
636 if (k->defmgmt)
637 k->def_multi = true;
638
e31b8213
JB
639 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
640 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
641 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
642 return -EINVAL;
643 }
644
dbd2fd65
JB
645 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
646 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
647 int err = nla_parse_nested(
648 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
649 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
650 nl80211_key_default_policy);
651 if (err)
652 return err;
653
654 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
655 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
656 }
657
b9454e83
JB
658 return 0;
659}
660
661static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
662{
663 int err;
664
665 memset(k, 0, sizeof(*k));
666 k->idx = -1;
e31b8213 667 k->type = -1;
b9454e83
JB
668
669 if (info->attrs[NL80211_ATTR_KEY])
670 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
671 else
672 err = nl80211_parse_key_old(info, k);
673
674 if (err)
675 return err;
676
677 if (k->def && k->defmgmt)
678 return -EINVAL;
679
dbd2fd65
JB
680 if (k->defmgmt) {
681 if (k->def_uni || !k->def_multi)
682 return -EINVAL;
683 }
684
b9454e83
JB
685 if (k->idx != -1) {
686 if (k->defmgmt) {
687 if (k->idx < 4 || k->idx > 5)
688 return -EINVAL;
689 } else if (k->def) {
690 if (k->idx < 0 || k->idx > 3)
691 return -EINVAL;
692 } else {
693 if (k->idx < 0 || k->idx > 5)
694 return -EINVAL;
695 }
696 }
697
698 return 0;
699}
700
fffd0934
JB
701static struct cfg80211_cached_keys *
702nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 703 struct nlattr *keys, bool *no_ht)
fffd0934
JB
704{
705 struct key_parse parse;
706 struct nlattr *key;
707 struct cfg80211_cached_keys *result;
708 int rem, err, def = 0;
709
710 result = kzalloc(sizeof(*result), GFP_KERNEL);
711 if (!result)
712 return ERR_PTR(-ENOMEM);
713
714 result->def = -1;
715 result->defmgmt = -1;
716
717 nla_for_each_nested(key, keys, rem) {
718 memset(&parse, 0, sizeof(parse));
719 parse.idx = -1;
720
721 err = nl80211_parse_key_new(key, &parse);
722 if (err)
723 goto error;
724 err = -EINVAL;
725 if (!parse.p.key)
726 goto error;
727 if (parse.idx < 0 || parse.idx > 4)
728 goto error;
729 if (parse.def) {
730 if (def)
731 goto error;
732 def = 1;
733 result->def = parse.idx;
dbd2fd65
JB
734 if (!parse.def_uni || !parse.def_multi)
735 goto error;
fffd0934
JB
736 } else if (parse.defmgmt)
737 goto error;
738 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 739 parse.idx, false, NULL);
fffd0934
JB
740 if (err)
741 goto error;
742 result->params[parse.idx].cipher = parse.p.cipher;
743 result->params[parse.idx].key_len = parse.p.key_len;
744 result->params[parse.idx].key = result->data[parse.idx];
745 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
746
747 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
748 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
749 if (no_ht)
750 *no_ht = true;
751 }
fffd0934
JB
752 }
753
754 return result;
755 error:
756 kfree(result);
757 return ERR_PTR(err);
758}
759
760static int nl80211_key_allowed(struct wireless_dev *wdev)
761{
762 ASSERT_WDEV_LOCK(wdev);
763
fffd0934
JB
764 switch (wdev->iftype) {
765 case NL80211_IFTYPE_AP:
766 case NL80211_IFTYPE_AP_VLAN:
074ac8df 767 case NL80211_IFTYPE_P2P_GO:
ff973af7 768 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
769 break;
770 case NL80211_IFTYPE_ADHOC:
771 if (!wdev->current_bss)
772 return -ENOLINK;
773 break;
774 case NL80211_IFTYPE_STATION:
074ac8df 775 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
776 if (wdev->sme_state != CFG80211_SME_CONNECTED)
777 return -ENOLINK;
778 break;
779 default:
780 return -EINVAL;
781 }
782
783 return 0;
784}
785
7527a782
JB
786static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
787{
788 struct nlattr *nl_modes = nla_nest_start(msg, attr);
789 int i;
790
791 if (!nl_modes)
792 goto nla_put_failure;
793
794 i = 0;
795 while (ifmodes) {
9360ffd1
DM
796 if ((ifmodes & 1) && nla_put_flag(msg, i))
797 goto nla_put_failure;
7527a782
JB
798 ifmodes >>= 1;
799 i++;
800 }
801
802 nla_nest_end(msg, nl_modes);
803 return 0;
804
805nla_put_failure:
806 return -ENOBUFS;
807}
808
809static int nl80211_put_iface_combinations(struct wiphy *wiphy,
810 struct sk_buff *msg)
811{
812 struct nlattr *nl_combis;
813 int i, j;
814
815 nl_combis = nla_nest_start(msg,
816 NL80211_ATTR_INTERFACE_COMBINATIONS);
817 if (!nl_combis)
818 goto nla_put_failure;
819
820 for (i = 0; i < wiphy->n_iface_combinations; i++) {
821 const struct ieee80211_iface_combination *c;
822 struct nlattr *nl_combi, *nl_limits;
823
824 c = &wiphy->iface_combinations[i];
825
826 nl_combi = nla_nest_start(msg, i + 1);
827 if (!nl_combi)
828 goto nla_put_failure;
829
830 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
831 if (!nl_limits)
832 goto nla_put_failure;
833
834 for (j = 0; j < c->n_limits; j++) {
835 struct nlattr *nl_limit;
836
837 nl_limit = nla_nest_start(msg, j + 1);
838 if (!nl_limit)
839 goto nla_put_failure;
9360ffd1
DM
840 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
841 c->limits[j].max))
842 goto nla_put_failure;
7527a782
JB
843 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
844 c->limits[j].types))
845 goto nla_put_failure;
846 nla_nest_end(msg, nl_limit);
847 }
848
849 nla_nest_end(msg, nl_limits);
850
9360ffd1
DM
851 if (c->beacon_int_infra_match &&
852 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
853 goto nla_put_failure;
854 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
855 c->num_different_channels) ||
856 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
857 c->max_interfaces))
858 goto nla_put_failure;
11c4a075
SW
859 if (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
860 c->radar_detect_widths))
861 goto nla_put_failure;
7527a782
JB
862
863 nla_nest_end(msg, nl_combi);
864 }
865
866 nla_nest_end(msg, nl_combis);
867
868 return 0;
869nla_put_failure:
870 return -ENOBUFS;
871}
872
15e47304 873static int nl80211_send_wiphy(struct sk_buff *msg, u32 portid, u32 seq, int flags,
55682965
JB
874 struct cfg80211_registered_device *dev)
875{
876 void *hdr;
ee688b00
JB
877 struct nlattr *nl_bands, *nl_band;
878 struct nlattr *nl_freqs, *nl_freq;
879 struct nlattr *nl_rates, *nl_rate;
8fdc621d 880 struct nlattr *nl_cmds;
ee688b00
JB
881 enum ieee80211_band band;
882 struct ieee80211_channel *chan;
883 struct ieee80211_rate *rate;
884 int i;
2e161f78
JB
885 const struct ieee80211_txrx_stypes *mgmt_stypes =
886 dev->wiphy.mgmt_stypes;
55682965 887
15e47304 888 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
55682965
JB
889 if (!hdr)
890 return -1;
891
9360ffd1
DM
892 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
893 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
894 nla_put_u32(msg, NL80211_ATTR_GENERATION,
895 cfg80211_rdev_list_generation) ||
896 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
897 dev->wiphy.retry_short) ||
898 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
899 dev->wiphy.retry_long) ||
900 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
901 dev->wiphy.frag_threshold) ||
902 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
903 dev->wiphy.rts_threshold) ||
904 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
905 dev->wiphy.coverage_class) ||
906 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
907 dev->wiphy.max_scan_ssids) ||
908 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
909 dev->wiphy.max_sched_scan_ssids) ||
910 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
911 dev->wiphy.max_scan_ie_len) ||
912 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
913 dev->wiphy.max_sched_scan_ie_len) ||
914 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
915 dev->wiphy.max_match_sets))
916 goto nla_put_failure;
917
918 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
919 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
920 goto nla_put_failure;
921 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
922 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
923 goto nla_put_failure;
924 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
925 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
926 goto nla_put_failure;
927 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
928 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
929 goto nla_put_failure;
930 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
931 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
932 goto nla_put_failure;
933 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
934 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
935 goto nla_put_failure;
936
937 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
938 sizeof(u32) * dev->wiphy.n_cipher_suites,
939 dev->wiphy.cipher_suites))
940 goto nla_put_failure;
941
942 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
943 dev->wiphy.max_num_pmkids))
944 goto nla_put_failure;
945
946 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
947 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
948 goto nla_put_failure;
949
950 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
951 dev->wiphy.available_antennas_tx) ||
952 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
953 dev->wiphy.available_antennas_rx))
954 goto nla_put_failure;
955
956 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
957 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
958 dev->wiphy.probe_resp_offload))
959 goto nla_put_failure;
87bbbe22 960
7f531e03
BR
961 if ((dev->wiphy.available_antennas_tx ||
962 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
963 u32 tx_ant = 0, rx_ant = 0;
964 int res;
e35e4d28 965 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
afe0cbf8 966 if (!res) {
9360ffd1
DM
967 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
968 tx_ant) ||
969 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
970 rx_ant))
971 goto nla_put_failure;
afe0cbf8
BR
972 }
973 }
974
7527a782
JB
975 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
976 dev->wiphy.interface_modes))
f59ac048
LR
977 goto nla_put_failure;
978
ee688b00
JB
979 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
980 if (!nl_bands)
981 goto nla_put_failure;
982
983 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
984 if (!dev->wiphy.bands[band])
985 continue;
986
987 nl_band = nla_nest_start(msg, band);
988 if (!nl_band)
989 goto nla_put_failure;
990
d51626df 991 /* add HT info */
9360ffd1
DM
992 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
993 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
994 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
995 &dev->wiphy.bands[band]->ht_cap.mcs) ||
996 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
997 dev->wiphy.bands[band]->ht_cap.cap) ||
998 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
999 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
1000 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1001 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
1002 goto nla_put_failure;
d51626df 1003
bf0c111e
MP
1004 /* add VHT info */
1005 if (dev->wiphy.bands[band]->vht_cap.vht_supported &&
1006 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1007 sizeof(dev->wiphy.bands[band]->vht_cap.vht_mcs),
1008 &dev->wiphy.bands[band]->vht_cap.vht_mcs) ||
1009 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1010 dev->wiphy.bands[band]->vht_cap.cap)))
1011 goto nla_put_failure;
1012
ee688b00
JB
1013 /* add frequencies */
1014 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
1015 if (!nl_freqs)
1016 goto nla_put_failure;
1017
1018 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
1019 nl_freq = nla_nest_start(msg, i);
1020 if (!nl_freq)
1021 goto nla_put_failure;
1022
1023 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
1024
1025 if (nl80211_msg_put_channel(msg, chan))
1026 goto nla_put_failure;
e2f367f2 1027
ee688b00
JB
1028 nla_nest_end(msg, nl_freq);
1029 }
1030
1031 nla_nest_end(msg, nl_freqs);
1032
1033 /* add bitrates */
1034 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1035 if (!nl_rates)
1036 goto nla_put_failure;
1037
1038 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
1039 nl_rate = nla_nest_start(msg, i);
1040 if (!nl_rate)
1041 goto nla_put_failure;
1042
1043 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
1044 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1045 rate->bitrate))
1046 goto nla_put_failure;
1047 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1048 nla_put_flag(msg,
1049 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1050 goto nla_put_failure;
ee688b00
JB
1051
1052 nla_nest_end(msg, nl_rate);
1053 }
1054
1055 nla_nest_end(msg, nl_rates);
1056
1057 nla_nest_end(msg, nl_band);
1058 }
1059 nla_nest_end(msg, nl_bands);
1060
8fdc621d
JB
1061 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1062 if (!nl_cmds)
1063 goto nla_put_failure;
1064
1065 i = 0;
1066#define CMD(op, n) \
1067 do { \
1068 if (dev->ops->op) { \
1069 i++; \
9360ffd1
DM
1070 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1071 goto nla_put_failure; \
8fdc621d
JB
1072 } \
1073 } while (0)
1074
1075 CMD(add_virtual_intf, NEW_INTERFACE);
1076 CMD(change_virtual_intf, SET_INTERFACE);
1077 CMD(add_key, NEW_KEY);
8860020e 1078 CMD(start_ap, START_AP);
8fdc621d
JB
1079 CMD(add_station, NEW_STATION);
1080 CMD(add_mpath, NEW_MPATH);
24bdd9f4 1081 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 1082 CMD(change_bss, SET_BSS);
636a5d36
JM
1083 CMD(auth, AUTHENTICATE);
1084 CMD(assoc, ASSOCIATE);
1085 CMD(deauth, DEAUTHENTICATE);
1086 CMD(disassoc, DISASSOCIATE);
04a773ad 1087 CMD(join_ibss, JOIN_IBSS);
29cbe68c 1088 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
1089 CMD(set_pmksa, SET_PMKSA);
1090 CMD(del_pmksa, DEL_PMKSA);
1091 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
1092 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1093 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 1094 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 1095 CMD(mgmt_tx, FRAME);
f7ca38df 1096 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 1097 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 1098 i++;
9360ffd1
DM
1099 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1100 goto nla_put_failure;
463d0183 1101 }
e8c9bd5b 1102 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 1103 dev->ops->join_mesh) {
aa430da4
JB
1104 i++;
1105 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1106 goto nla_put_failure;
1107 }
e8347eba 1108 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
1109 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1110 CMD(tdls_mgmt, TDLS_MGMT);
1111 CMD(tdls_oper, TDLS_OPER);
1112 }
807f8a8c
LC
1113 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1114 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 1115 CMD(probe_client, PROBE_CLIENT);
1d9d9213 1116 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
1117 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1118 i++;
9360ffd1
DM
1119 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1120 goto nla_put_failure;
5e760230 1121 }
98104fde 1122 CMD(start_p2p_device, START_P2P_DEVICE);
f4e583c8 1123 CMD(set_mcast_rate, SET_MCAST_RATE);
8fdc621d 1124
4745fc09
KV
1125#ifdef CONFIG_NL80211_TESTMODE
1126 CMD(testmode_cmd, TESTMODE);
1127#endif
1128
8fdc621d 1129#undef CMD
b23aa676 1130
6829c878 1131 if (dev->ops->connect || dev->ops->auth) {
b23aa676 1132 i++;
9360ffd1
DM
1133 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1134 goto nla_put_failure;
b23aa676
SO
1135 }
1136
6829c878 1137 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 1138 i++;
9360ffd1
DM
1139 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1140 goto nla_put_failure;
b23aa676
SO
1141 }
1142
8fdc621d
JB
1143 nla_nest_end(msg, nl_cmds);
1144
7c4ef712 1145 if (dev->ops->remain_on_channel &&
9360ffd1
DM
1146 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1147 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1148 dev->wiphy.max_remain_on_channel_duration))
1149 goto nla_put_failure;
a293911d 1150
9360ffd1
DM
1151 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1152 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1153 goto nla_put_failure;
f7ca38df 1154
2e161f78
JB
1155 if (mgmt_stypes) {
1156 u16 stypes;
1157 struct nlattr *nl_ftypes, *nl_ifs;
1158 enum nl80211_iftype ift;
1159
1160 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1161 if (!nl_ifs)
1162 goto nla_put_failure;
1163
1164 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1165 nl_ftypes = nla_nest_start(msg, ift);
1166 if (!nl_ftypes)
1167 goto nla_put_failure;
1168 i = 0;
1169 stypes = mgmt_stypes[ift].tx;
1170 while (stypes) {
9360ffd1
DM
1171 if ((stypes & 1) &&
1172 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1173 (i << 4) | IEEE80211_FTYPE_MGMT))
1174 goto nla_put_failure;
2e161f78
JB
1175 stypes >>= 1;
1176 i++;
1177 }
1178 nla_nest_end(msg, nl_ftypes);
1179 }
1180
74b70a4e
JB
1181 nla_nest_end(msg, nl_ifs);
1182
2e161f78
JB
1183 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1184 if (!nl_ifs)
1185 goto nla_put_failure;
1186
1187 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1188 nl_ftypes = nla_nest_start(msg, ift);
1189 if (!nl_ftypes)
1190 goto nla_put_failure;
1191 i = 0;
1192 stypes = mgmt_stypes[ift].rx;
1193 while (stypes) {
9360ffd1
DM
1194 if ((stypes & 1) &&
1195 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1196 (i << 4) | IEEE80211_FTYPE_MGMT))
1197 goto nla_put_failure;
2e161f78
JB
1198 stypes >>= 1;
1199 i++;
1200 }
1201 nla_nest_end(msg, nl_ftypes);
1202 }
1203 nla_nest_end(msg, nl_ifs);
1204 }
1205
dfb89c56 1206#ifdef CONFIG_PM
ff1b6e69
JB
1207 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1208 struct nlattr *nl_wowlan;
1209
1210 nl_wowlan = nla_nest_start(msg,
1211 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1212 if (!nl_wowlan)
1213 goto nla_put_failure;
1214
9360ffd1
DM
1215 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1216 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1217 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1218 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1219 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1220 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1221 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1222 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1223 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1224 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1225 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1226 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1227 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1228 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1229 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1230 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1231 goto nla_put_failure;
ff1b6e69
JB
1232 if (dev->wiphy.wowlan.n_patterns) {
1233 struct nl80211_wowlan_pattern_support pat = {
1234 .max_patterns = dev->wiphy.wowlan.n_patterns,
1235 .min_pattern_len =
1236 dev->wiphy.wowlan.pattern_min_len,
1237 .max_pattern_len =
1238 dev->wiphy.wowlan.pattern_max_len,
1239 };
9360ffd1
DM
1240 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1241 sizeof(pat), &pat))
1242 goto nla_put_failure;
ff1b6e69
JB
1243 }
1244
1245 nla_nest_end(msg, nl_wowlan);
1246 }
dfb89c56 1247#endif
ff1b6e69 1248
7527a782
JB
1249 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1250 dev->wiphy.software_iftypes))
1251 goto nla_put_failure;
1252
1253 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1254 goto nla_put_failure;
1255
9360ffd1
DM
1256 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1257 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1258 dev->wiphy.ap_sme_capa))
1259 goto nla_put_failure;
562a7480 1260
9360ffd1
DM
1261 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1262 dev->wiphy.features))
1263 goto nla_put_failure;
1f074bd8 1264
9360ffd1
DM
1265 if (dev->wiphy.ht_capa_mod_mask &&
1266 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1267 sizeof(*dev->wiphy.ht_capa_mod_mask),
1268 dev->wiphy.ht_capa_mod_mask))
1269 goto nla_put_failure;
7e7c8926 1270
55682965
JB
1271 return genlmsg_end(msg, hdr);
1272
1273 nla_put_failure:
bc3ed28c
TG
1274 genlmsg_cancel(msg, hdr);
1275 return -EMSGSIZE;
55682965
JB
1276}
1277
1278static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1279{
1280 int idx = 0;
1281 int start = cb->args[0];
1282 struct cfg80211_registered_device *dev;
1283
a1794390 1284 mutex_lock(&cfg80211_mutex);
79c97e97 1285 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1286 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1287 continue;
b4637271 1288 if (++idx <= start)
55682965 1289 continue;
15e47304 1290 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).portid,
55682965 1291 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1292 dev) < 0) {
1293 idx--;
55682965 1294 break;
b4637271 1295 }
55682965 1296 }
a1794390 1297 mutex_unlock(&cfg80211_mutex);
55682965
JB
1298
1299 cb->args[0] = idx;
1300
1301 return skb->len;
1302}
1303
1304static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1305{
1306 struct sk_buff *msg;
4c476991 1307 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1308
fd2120ca 1309 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1310 if (!msg)
4c476991 1311 return -ENOMEM;
55682965 1312
15e47304 1313 if (nl80211_send_wiphy(msg, info->snd_portid, info->snd_seq, 0, dev) < 0) {
4c476991
JB
1314 nlmsg_free(msg);
1315 return -ENOBUFS;
1316 }
55682965 1317
134e6375 1318 return genlmsg_reply(msg, info);
55682965
JB
1319}
1320
31888487
JM
1321static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1322 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1323 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1324 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1325 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1326 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1327};
1328
1329static int parse_txq_params(struct nlattr *tb[],
1330 struct ieee80211_txq_params *txq_params)
1331{
a3304b0a 1332 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1333 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1334 !tb[NL80211_TXQ_ATTR_AIFS])
1335 return -EINVAL;
1336
a3304b0a 1337 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1338 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1339 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1340 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1341 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1342
a3304b0a
JB
1343 if (txq_params->ac >= NL80211_NUM_ACS)
1344 return -EINVAL;
1345
31888487
JM
1346 return 0;
1347}
1348
f444de05
JB
1349static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1350{
1351 /*
cc1d2806
JB
1352 * You can only set the channel explicitly for WDS interfaces,
1353 * all others have their channel managed via their respective
1354 * "establish a connection" command (connect, join, ...)
1355 *
1356 * For AP/GO and mesh mode, the channel can be set with the
1357 * channel userspace API, but is only stored and passed to the
1358 * low-level driver when the AP starts or the mesh is joined.
1359 * This is for backward compatibility, userspace can also give
1360 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1361 *
1362 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1363 * whatever else is going on, so they have their own special
1364 * operation to set the monitor channel if possible.
f444de05
JB
1365 */
1366 return !wdev ||
1367 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1368 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1369 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1370 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1371}
1372
683b6d3b
JB
1373static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1374 struct genl_info *info,
1375 struct cfg80211_chan_def *chandef)
1376{
dbeca2ea 1377 u32 control_freq;
683b6d3b
JB
1378
1379 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1380 return -EINVAL;
1381
1382 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1383
1384 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1385 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1386 chandef->center_freq1 = control_freq;
1387 chandef->center_freq2 = 0;
683b6d3b
JB
1388
1389 /* Primary channel not allowed */
1390 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1391 return -EINVAL;
1392
3d9d1d66
JB
1393 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1394 enum nl80211_channel_type chantype;
1395
1396 chantype = nla_get_u32(
1397 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1398
1399 switch (chantype) {
1400 case NL80211_CHAN_NO_HT:
1401 case NL80211_CHAN_HT20:
1402 case NL80211_CHAN_HT40PLUS:
1403 case NL80211_CHAN_HT40MINUS:
1404 cfg80211_chandef_create(chandef, chandef->chan,
1405 chantype);
1406 break;
1407 default:
1408 return -EINVAL;
1409 }
1410 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1411 chandef->width =
1412 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1413 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1414 chandef->center_freq1 =
1415 nla_get_u32(
1416 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1417 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1418 chandef->center_freq2 =
1419 nla_get_u32(
1420 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1421 }
1422
9f5e8f6e 1423 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1424 return -EINVAL;
1425
9f5e8f6e
JB
1426 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1427 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1428 return -EINVAL;
1429
683b6d3b
JB
1430 return 0;
1431}
1432
f444de05
JB
1433static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1434 struct wireless_dev *wdev,
1435 struct genl_info *info)
1436{
683b6d3b 1437 struct cfg80211_chan_def chandef;
f444de05 1438 int result;
e8c9bd5b
JB
1439 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1440
1441 if (wdev)
1442 iftype = wdev->iftype;
f444de05 1443
f444de05
JB
1444 if (!nl80211_can_set_dev_channel(wdev))
1445 return -EOPNOTSUPP;
1446
683b6d3b
JB
1447 result = nl80211_parse_chandef(rdev, info, &chandef);
1448 if (result)
1449 return result;
f444de05
JB
1450
1451 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1452 switch (iftype) {
aa430da4
JB
1453 case NL80211_IFTYPE_AP:
1454 case NL80211_IFTYPE_P2P_GO:
1455 if (wdev->beacon_interval) {
1456 result = -EBUSY;
1457 break;
1458 }
683b6d3b 1459 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1460 result = -EINVAL;
1461 break;
1462 }
683b6d3b 1463 wdev->preset_chandef = chandef;
aa430da4
JB
1464 result = 0;
1465 break;
cc1d2806 1466 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1467 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1468 break;
e8c9bd5b 1469 case NL80211_IFTYPE_MONITOR:
683b6d3b 1470 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1471 break;
aa430da4 1472 default:
e8c9bd5b 1473 result = -EINVAL;
f444de05
JB
1474 }
1475 mutex_unlock(&rdev->devlist_mtx);
1476
1477 return result;
1478}
1479
1480static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1481{
4c476991
JB
1482 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1483 struct net_device *netdev = info->user_ptr[1];
f444de05 1484
4c476991 1485 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1486}
1487
e8347eba
BJ
1488static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1489{
43b19952
JB
1490 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1491 struct net_device *dev = info->user_ptr[1];
1492 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1493 const u8 *bssid;
e8347eba
BJ
1494
1495 if (!info->attrs[NL80211_ATTR_MAC])
1496 return -EINVAL;
1497
43b19952
JB
1498 if (netif_running(dev))
1499 return -EBUSY;
e8347eba 1500
43b19952
JB
1501 if (!rdev->ops->set_wds_peer)
1502 return -EOPNOTSUPP;
e8347eba 1503
43b19952
JB
1504 if (wdev->iftype != NL80211_IFTYPE_WDS)
1505 return -EOPNOTSUPP;
e8347eba
BJ
1506
1507 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1508 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1509}
1510
1511
55682965
JB
1512static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1513{
1514 struct cfg80211_registered_device *rdev;
f444de05
JB
1515 struct net_device *netdev = NULL;
1516 struct wireless_dev *wdev;
a1e567c8 1517 int result = 0, rem_txq_params = 0;
31888487 1518 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1519 u32 changed;
1520 u8 retry_short = 0, retry_long = 0;
1521 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1522 u8 coverage_class = 0;
55682965 1523
f444de05
JB
1524 /*
1525 * Try to find the wiphy and netdev. Normally this
1526 * function shouldn't need the netdev, but this is
1527 * done for backward compatibility -- previously
1528 * setting the channel was done per wiphy, but now
1529 * it is per netdev. Previous userland like hostapd
1530 * also passed a netdev to set_wiphy, so that it is
1531 * possible to let that go to the right netdev!
1532 */
4bbf4d56
JB
1533 mutex_lock(&cfg80211_mutex);
1534
f444de05
JB
1535 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1536 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1537
1538 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1539 if (netdev && netdev->ieee80211_ptr) {
1540 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1541 mutex_lock(&rdev->mtx);
1542 } else
1543 netdev = NULL;
4bbf4d56
JB
1544 }
1545
f444de05 1546 if (!netdev) {
878d9ec7
JB
1547 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1548 info->attrs);
f444de05
JB
1549 if (IS_ERR(rdev)) {
1550 mutex_unlock(&cfg80211_mutex);
4c476991 1551 return PTR_ERR(rdev);
f444de05
JB
1552 }
1553 wdev = NULL;
1554 netdev = NULL;
1555 result = 0;
1556
1557 mutex_lock(&rdev->mtx);
71fe96bf 1558 } else
f444de05 1559 wdev = netdev->ieee80211_ptr;
f444de05
JB
1560
1561 /*
1562 * end workaround code, by now the rdev is available
1563 * and locked, and wdev may or may not be NULL.
1564 */
4bbf4d56
JB
1565
1566 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1567 result = cfg80211_dev_rename(
1568 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1569
1570 mutex_unlock(&cfg80211_mutex);
1571
1572 if (result)
1573 goto bad_res;
31888487
JM
1574
1575 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1576 struct ieee80211_txq_params txq_params;
1577 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1578
1579 if (!rdev->ops->set_txq_params) {
1580 result = -EOPNOTSUPP;
1581 goto bad_res;
1582 }
1583
f70f01c2
EP
1584 if (!netdev) {
1585 result = -EINVAL;
1586 goto bad_res;
1587 }
1588
133a3ff2
JB
1589 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1590 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1591 result = -EINVAL;
1592 goto bad_res;
1593 }
1594
2b5f8b0b
JB
1595 if (!netif_running(netdev)) {
1596 result = -ENETDOWN;
1597 goto bad_res;
1598 }
1599
31888487
JM
1600 nla_for_each_nested(nl_txq_params,
1601 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1602 rem_txq_params) {
1603 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1604 nla_data(nl_txq_params),
1605 nla_len(nl_txq_params),
1606 txq_params_policy);
1607 result = parse_txq_params(tb, &txq_params);
1608 if (result)
1609 goto bad_res;
1610
e35e4d28
HG
1611 result = rdev_set_txq_params(rdev, netdev,
1612 &txq_params);
31888487
JM
1613 if (result)
1614 goto bad_res;
1615 }
1616 }
55682965 1617
72bdcf34 1618 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1619 result = __nl80211_set_channel(rdev,
1620 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1621 info);
72bdcf34
JM
1622 if (result)
1623 goto bad_res;
1624 }
1625
98d2ff8b 1626 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 1627 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
1628 enum nl80211_tx_power_setting type;
1629 int idx, mbm = 0;
1630
c8442118
JB
1631 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
1632 txp_wdev = NULL;
1633
98d2ff8b 1634 if (!rdev->ops->set_tx_power) {
60ea385f 1635 result = -EOPNOTSUPP;
98d2ff8b
JO
1636 goto bad_res;
1637 }
1638
1639 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1640 type = nla_get_u32(info->attrs[idx]);
1641
1642 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1643 (type != NL80211_TX_POWER_AUTOMATIC)) {
1644 result = -EINVAL;
1645 goto bad_res;
1646 }
1647
1648 if (type != NL80211_TX_POWER_AUTOMATIC) {
1649 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1650 mbm = nla_get_u32(info->attrs[idx]);
1651 }
1652
c8442118 1653 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
1654 if (result)
1655 goto bad_res;
1656 }
1657
afe0cbf8
BR
1658 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1659 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1660 u32 tx_ant, rx_ant;
7f531e03
BR
1661 if ((!rdev->wiphy.available_antennas_tx &&
1662 !rdev->wiphy.available_antennas_rx) ||
1663 !rdev->ops->set_antenna) {
afe0cbf8
BR
1664 result = -EOPNOTSUPP;
1665 goto bad_res;
1666 }
1667
1668 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1669 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1670
a7ffac95 1671 /* reject antenna configurations which don't match the
7f531e03
BR
1672 * available antenna masks, except for the "all" mask */
1673 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1674 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1675 result = -EINVAL;
1676 goto bad_res;
1677 }
1678
7f531e03
BR
1679 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1680 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1681
e35e4d28 1682 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
1683 if (result)
1684 goto bad_res;
1685 }
1686
b9a5f8ca
JM
1687 changed = 0;
1688
1689 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1690 retry_short = nla_get_u8(
1691 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1692 if (retry_short == 0) {
1693 result = -EINVAL;
1694 goto bad_res;
1695 }
1696 changed |= WIPHY_PARAM_RETRY_SHORT;
1697 }
1698
1699 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1700 retry_long = nla_get_u8(
1701 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1702 if (retry_long == 0) {
1703 result = -EINVAL;
1704 goto bad_res;
1705 }
1706 changed |= WIPHY_PARAM_RETRY_LONG;
1707 }
1708
1709 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1710 frag_threshold = nla_get_u32(
1711 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1712 if (frag_threshold < 256) {
1713 result = -EINVAL;
1714 goto bad_res;
1715 }
1716 if (frag_threshold != (u32) -1) {
1717 /*
1718 * Fragments (apart from the last one) are required to
1719 * have even length. Make the fragmentation code
1720 * simpler by stripping LSB should someone try to use
1721 * odd threshold value.
1722 */
1723 frag_threshold &= ~0x1;
1724 }
1725 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1726 }
1727
1728 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1729 rts_threshold = nla_get_u32(
1730 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1731 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1732 }
1733
81077e82
LT
1734 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1735 coverage_class = nla_get_u8(
1736 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1737 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1738 }
1739
b9a5f8ca
JM
1740 if (changed) {
1741 u8 old_retry_short, old_retry_long;
1742 u32 old_frag_threshold, old_rts_threshold;
81077e82 1743 u8 old_coverage_class;
b9a5f8ca
JM
1744
1745 if (!rdev->ops->set_wiphy_params) {
1746 result = -EOPNOTSUPP;
1747 goto bad_res;
1748 }
1749
1750 old_retry_short = rdev->wiphy.retry_short;
1751 old_retry_long = rdev->wiphy.retry_long;
1752 old_frag_threshold = rdev->wiphy.frag_threshold;
1753 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1754 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1755
1756 if (changed & WIPHY_PARAM_RETRY_SHORT)
1757 rdev->wiphy.retry_short = retry_short;
1758 if (changed & WIPHY_PARAM_RETRY_LONG)
1759 rdev->wiphy.retry_long = retry_long;
1760 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1761 rdev->wiphy.frag_threshold = frag_threshold;
1762 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1763 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1764 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1765 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 1766
e35e4d28 1767 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
1768 if (result) {
1769 rdev->wiphy.retry_short = old_retry_short;
1770 rdev->wiphy.retry_long = old_retry_long;
1771 rdev->wiphy.frag_threshold = old_frag_threshold;
1772 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1773 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1774 }
1775 }
72bdcf34 1776
306d6112 1777 bad_res:
4bbf4d56 1778 mutex_unlock(&rdev->mtx);
f444de05
JB
1779 if (netdev)
1780 dev_put(netdev);
55682965
JB
1781 return result;
1782}
1783
71bbc994
JB
1784static inline u64 wdev_id(struct wireless_dev *wdev)
1785{
1786 return (u64)wdev->identifier |
1787 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
1788}
55682965 1789
683b6d3b
JB
1790static int nl80211_send_chandef(struct sk_buff *msg,
1791 struct cfg80211_chan_def *chandef)
1792{
9f5e8f6e 1793 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 1794
683b6d3b
JB
1795 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1796 chandef->chan->center_freq))
1797 return -ENOBUFS;
3d9d1d66
JB
1798 switch (chandef->width) {
1799 case NL80211_CHAN_WIDTH_20_NOHT:
1800 case NL80211_CHAN_WIDTH_20:
1801 case NL80211_CHAN_WIDTH_40:
1802 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1803 cfg80211_get_chandef_type(chandef)))
1804 return -ENOBUFS;
1805 break;
1806 default:
1807 break;
1808 }
1809 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
1810 return -ENOBUFS;
1811 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
1812 return -ENOBUFS;
1813 if (chandef->center_freq2 &&
1814 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
1815 return -ENOBUFS;
1816 return 0;
1817}
1818
15e47304 1819static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 1820 struct cfg80211_registered_device *rdev,
72fb2abc 1821 struct wireless_dev *wdev)
55682965 1822{
72fb2abc 1823 struct net_device *dev = wdev->netdev;
55682965
JB
1824 void *hdr;
1825
15e47304 1826 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
1827 if (!hdr)
1828 return -1;
1829
72fb2abc
JB
1830 if (dev &&
1831 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 1832 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
1833 goto nla_put_failure;
1834
1835 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1836 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 1837 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 1838 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
1839 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1840 rdev->devlist_generation ^
1841 (cfg80211_rdev_list_generation << 2)))
1842 goto nla_put_failure;
f5ea9120 1843
5b7ccaf3 1844 if (rdev->ops->get_channel) {
683b6d3b
JB
1845 int ret;
1846 struct cfg80211_chan_def chandef;
1847
1848 ret = rdev_get_channel(rdev, wdev, &chandef);
1849 if (ret == 0) {
1850 if (nl80211_send_chandef(msg, &chandef))
1851 goto nla_put_failure;
1852 }
d91df0e3
PF
1853 }
1854
b84e7a05
AQ
1855 if (wdev->ssid_len) {
1856 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
1857 goto nla_put_failure;
1858 }
1859
55682965
JB
1860 return genlmsg_end(msg, hdr);
1861
1862 nla_put_failure:
bc3ed28c
TG
1863 genlmsg_cancel(msg, hdr);
1864 return -EMSGSIZE;
55682965
JB
1865}
1866
1867static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1868{
1869 int wp_idx = 0;
1870 int if_idx = 0;
1871 int wp_start = cb->args[0];
1872 int if_start = cb->args[1];
f5ea9120 1873 struct cfg80211_registered_device *rdev;
55682965
JB
1874 struct wireless_dev *wdev;
1875
a1794390 1876 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1877 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1878 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1879 continue;
bba95fef
JB
1880 if (wp_idx < wp_start) {
1881 wp_idx++;
55682965 1882 continue;
bba95fef 1883 }
55682965
JB
1884 if_idx = 0;
1885
f5ea9120 1886 mutex_lock(&rdev->devlist_mtx);
89a54e48 1887 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
1888 if (if_idx < if_start) {
1889 if_idx++;
55682965 1890 continue;
bba95fef 1891 }
15e47304 1892 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 1893 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 1894 rdev, wdev) < 0) {
f5ea9120 1895 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1896 goto out;
1897 }
1898 if_idx++;
55682965 1899 }
f5ea9120 1900 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1901
1902 wp_idx++;
55682965 1903 }
bba95fef 1904 out:
a1794390 1905 mutex_unlock(&cfg80211_mutex);
55682965
JB
1906
1907 cb->args[0] = wp_idx;
1908 cb->args[1] = if_idx;
1909
1910 return skb->len;
1911}
1912
1913static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1914{
1915 struct sk_buff *msg;
4c476991 1916 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 1917 struct wireless_dev *wdev = info->user_ptr[1];
55682965 1918
fd2120ca 1919 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1920 if (!msg)
4c476991 1921 return -ENOMEM;
55682965 1922
15e47304 1923 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 1924 dev, wdev) < 0) {
4c476991
JB
1925 nlmsg_free(msg);
1926 return -ENOBUFS;
1927 }
55682965 1928
134e6375 1929 return genlmsg_reply(msg, info);
55682965
JB
1930}
1931
66f7ac50
MW
1932static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1933 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1934 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1935 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1936 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1937 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1938};
1939
1940static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1941{
1942 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1943 int flag;
1944
1945 *mntrflags = 0;
1946
1947 if (!nla)
1948 return -EINVAL;
1949
1950 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1951 nla, mntr_flags_policy))
1952 return -EINVAL;
1953
1954 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1955 if (flags[flag])
1956 *mntrflags |= (1<<flag);
1957
1958 return 0;
1959}
1960
9bc383de 1961static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1962 struct net_device *netdev, u8 use_4addr,
1963 enum nl80211_iftype iftype)
9bc383de 1964{
ad4bb6f8 1965 if (!use_4addr) {
f350a0a8 1966 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1967 return -EBUSY;
9bc383de 1968 return 0;
ad4bb6f8 1969 }
9bc383de
JB
1970
1971 switch (iftype) {
1972 case NL80211_IFTYPE_AP_VLAN:
1973 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1974 return 0;
1975 break;
1976 case NL80211_IFTYPE_STATION:
1977 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1978 return 0;
1979 break;
1980 default:
1981 break;
1982 }
1983
1984 return -EOPNOTSUPP;
1985}
1986
55682965
JB
1987static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1988{
4c476991 1989 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1990 struct vif_params params;
e36d56b6 1991 int err;
04a773ad 1992 enum nl80211_iftype otype, ntype;
4c476991 1993 struct net_device *dev = info->user_ptr[1];
92ffe055 1994 u32 _flags, *flags = NULL;
ac7f9cfa 1995 bool change = false;
55682965 1996
2ec600d6
LCC
1997 memset(&params, 0, sizeof(params));
1998
04a773ad 1999 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2000
723b038d 2001 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2002 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2003 if (otype != ntype)
ac7f9cfa 2004 change = true;
4c476991
JB
2005 if (ntype > NL80211_IFTYPE_MAX)
2006 return -EINVAL;
723b038d
JB
2007 }
2008
92ffe055 2009 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2010 struct wireless_dev *wdev = dev->ieee80211_ptr;
2011
4c476991
JB
2012 if (ntype != NL80211_IFTYPE_MESH_POINT)
2013 return -EINVAL;
29cbe68c
JB
2014 if (netif_running(dev))
2015 return -EBUSY;
2016
2017 wdev_lock(wdev);
2018 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2019 IEEE80211_MAX_MESH_ID_LEN);
2020 wdev->mesh_id_up_len =
2021 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2022 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2023 wdev->mesh_id_up_len);
2024 wdev_unlock(wdev);
2ec600d6
LCC
2025 }
2026
8b787643
FF
2027 if (info->attrs[NL80211_ATTR_4ADDR]) {
2028 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2029 change = true;
ad4bb6f8 2030 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2031 if (err)
4c476991 2032 return err;
8b787643
FF
2033 } else {
2034 params.use_4addr = -1;
2035 }
2036
92ffe055 2037 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2038 if (ntype != NL80211_IFTYPE_MONITOR)
2039 return -EINVAL;
92ffe055
JB
2040 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2041 &_flags);
ac7f9cfa 2042 if (err)
4c476991 2043 return err;
ac7f9cfa
JB
2044
2045 flags = &_flags;
2046 change = true;
92ffe055 2047 }
3b85875a 2048
ac7f9cfa 2049 if (change)
3d54d255 2050 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2051 else
2052 err = 0;
60719ffd 2053
9bc383de
JB
2054 if (!err && params.use_4addr != -1)
2055 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2056
55682965
JB
2057 return err;
2058}
2059
2060static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2061{
4c476991 2062 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2063 struct vif_params params;
84efbb84 2064 struct wireless_dev *wdev;
1c90f9d4 2065 struct sk_buff *msg;
55682965
JB
2066 int err;
2067 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2068 u32 flags;
55682965 2069
2ec600d6
LCC
2070 memset(&params, 0, sizeof(params));
2071
55682965
JB
2072 if (!info->attrs[NL80211_ATTR_IFNAME])
2073 return -EINVAL;
2074
2075 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2076 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2077 if (type > NL80211_IFTYPE_MAX)
2078 return -EINVAL;
2079 }
2080
79c97e97 2081 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2082 !(rdev->wiphy.interface_modes & (1 << type)))
2083 return -EOPNOTSUPP;
55682965 2084
1c18f145
AS
2085 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2086 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2087 ETH_ALEN);
2088 if (!is_valid_ether_addr(params.macaddr))
2089 return -EADDRNOTAVAIL;
2090 }
2091
9bc383de 2092 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2093 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2094 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2095 if (err)
4c476991 2096 return err;
9bc383de 2097 }
8b787643 2098
1c90f9d4
JB
2099 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2100 if (!msg)
2101 return -ENOMEM;
2102
66f7ac50
MW
2103 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2104 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2105 &flags);
e35e4d28
HG
2106 wdev = rdev_add_virtual_intf(rdev,
2107 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2108 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2109 if (IS_ERR(wdev)) {
2110 nlmsg_free(msg);
84efbb84 2111 return PTR_ERR(wdev);
1c90f9d4 2112 }
2ec600d6 2113
98104fde
JB
2114 switch (type) {
2115 case NL80211_IFTYPE_MESH_POINT:
2116 if (!info->attrs[NL80211_ATTR_MESH_ID])
2117 break;
29cbe68c
JB
2118 wdev_lock(wdev);
2119 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2120 IEEE80211_MAX_MESH_ID_LEN);
2121 wdev->mesh_id_up_len =
2122 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2123 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2124 wdev->mesh_id_up_len);
2125 wdev_unlock(wdev);
98104fde
JB
2126 break;
2127 case NL80211_IFTYPE_P2P_DEVICE:
2128 /*
2129 * P2P Device doesn't have a netdev, so doesn't go
2130 * through the netdev notifier and must be added here
2131 */
2132 mutex_init(&wdev->mtx);
2133 INIT_LIST_HEAD(&wdev->event_list);
2134 spin_lock_init(&wdev->event_lock);
2135 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2136 spin_lock_init(&wdev->mgmt_registrations_lock);
2137
2138 mutex_lock(&rdev->devlist_mtx);
2139 wdev->identifier = ++rdev->wdev_id;
2140 list_add_rcu(&wdev->list, &rdev->wdev_list);
2141 rdev->devlist_generation++;
2142 mutex_unlock(&rdev->devlist_mtx);
2143 break;
2144 default:
2145 break;
29cbe68c
JB
2146 }
2147
15e47304 2148 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2149 rdev, wdev) < 0) {
2150 nlmsg_free(msg);
2151 return -ENOBUFS;
2152 }
2153
2154 return genlmsg_reply(msg, info);
55682965
JB
2155}
2156
2157static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2158{
4c476991 2159 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2160 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2161
4c476991
JB
2162 if (!rdev->ops->del_virtual_intf)
2163 return -EOPNOTSUPP;
55682965 2164
84efbb84
JB
2165 /*
2166 * If we remove a wireless device without a netdev then clear
2167 * user_ptr[1] so that nl80211_post_doit won't dereference it
2168 * to check if it needs to do dev_put(). Otherwise it crashes
2169 * since the wdev has been freed, unlike with a netdev where
2170 * we need the dev_put() for the netdev to really be freed.
2171 */
2172 if (!wdev->netdev)
2173 info->user_ptr[1] = NULL;
2174
e35e4d28 2175 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2176}
2177
1d9d9213
SW
2178static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2179{
2180 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2181 struct net_device *dev = info->user_ptr[1];
2182 u16 noack_map;
2183
2184 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2185 return -EINVAL;
2186
2187 if (!rdev->ops->set_noack_map)
2188 return -EOPNOTSUPP;
2189
2190 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2191
e35e4d28 2192 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2193}
2194
41ade00f
JB
2195struct get_key_cookie {
2196 struct sk_buff *msg;
2197 int error;
b9454e83 2198 int idx;
41ade00f
JB
2199};
2200
2201static void get_key_callback(void *c, struct key_params *params)
2202{
b9454e83 2203 struct nlattr *key;
41ade00f
JB
2204 struct get_key_cookie *cookie = c;
2205
9360ffd1
DM
2206 if ((params->key &&
2207 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2208 params->key_len, params->key)) ||
2209 (params->seq &&
2210 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2211 params->seq_len, params->seq)) ||
2212 (params->cipher &&
2213 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2214 params->cipher)))
2215 goto nla_put_failure;
41ade00f 2216
b9454e83
JB
2217 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2218 if (!key)
2219 goto nla_put_failure;
2220
9360ffd1
DM
2221 if ((params->key &&
2222 nla_put(cookie->msg, NL80211_KEY_DATA,
2223 params->key_len, params->key)) ||
2224 (params->seq &&
2225 nla_put(cookie->msg, NL80211_KEY_SEQ,
2226 params->seq_len, params->seq)) ||
2227 (params->cipher &&
2228 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2229 params->cipher)))
2230 goto nla_put_failure;
b9454e83 2231
9360ffd1
DM
2232 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2233 goto nla_put_failure;
b9454e83
JB
2234
2235 nla_nest_end(cookie->msg, key);
2236
41ade00f
JB
2237 return;
2238 nla_put_failure:
2239 cookie->error = 1;
2240}
2241
2242static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2243{
4c476991 2244 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2245 int err;
4c476991 2246 struct net_device *dev = info->user_ptr[1];
41ade00f 2247 u8 key_idx = 0;
e31b8213
JB
2248 const u8 *mac_addr = NULL;
2249 bool pairwise;
41ade00f
JB
2250 struct get_key_cookie cookie = {
2251 .error = 0,
2252 };
2253 void *hdr;
2254 struct sk_buff *msg;
2255
2256 if (info->attrs[NL80211_ATTR_KEY_IDX])
2257 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2258
3cfcf6ac 2259 if (key_idx > 5)
41ade00f
JB
2260 return -EINVAL;
2261
2262 if (info->attrs[NL80211_ATTR_MAC])
2263 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2264
e31b8213
JB
2265 pairwise = !!mac_addr;
2266 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2267 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2268 if (kt >= NUM_NL80211_KEYTYPES)
2269 return -EINVAL;
2270 if (kt != NL80211_KEYTYPE_GROUP &&
2271 kt != NL80211_KEYTYPE_PAIRWISE)
2272 return -EINVAL;
2273 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2274 }
2275
4c476991
JB
2276 if (!rdev->ops->get_key)
2277 return -EOPNOTSUPP;
41ade00f 2278
fd2120ca 2279 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2280 if (!msg)
2281 return -ENOMEM;
41ade00f 2282
15e47304 2283 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2284 NL80211_CMD_NEW_KEY);
4c476991
JB
2285 if (IS_ERR(hdr))
2286 return PTR_ERR(hdr);
41ade00f
JB
2287
2288 cookie.msg = msg;
b9454e83 2289 cookie.idx = key_idx;
41ade00f 2290
9360ffd1
DM
2291 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2292 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2293 goto nla_put_failure;
2294 if (mac_addr &&
2295 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2296 goto nla_put_failure;
41ade00f 2297
e31b8213
JB
2298 if (pairwise && mac_addr &&
2299 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2300 return -ENOENT;
2301
e35e4d28
HG
2302 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2303 get_key_callback);
41ade00f
JB
2304
2305 if (err)
6c95e2a2 2306 goto free_msg;
41ade00f
JB
2307
2308 if (cookie.error)
2309 goto nla_put_failure;
2310
2311 genlmsg_end(msg, hdr);
4c476991 2312 return genlmsg_reply(msg, info);
41ade00f
JB
2313
2314 nla_put_failure:
2315 err = -ENOBUFS;
6c95e2a2 2316 free_msg:
41ade00f 2317 nlmsg_free(msg);
41ade00f
JB
2318 return err;
2319}
2320
2321static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2322{
4c476991 2323 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2324 struct key_parse key;
41ade00f 2325 int err;
4c476991 2326 struct net_device *dev = info->user_ptr[1];
41ade00f 2327
b9454e83
JB
2328 err = nl80211_parse_key(info, &key);
2329 if (err)
2330 return err;
41ade00f 2331
b9454e83 2332 if (key.idx < 0)
41ade00f
JB
2333 return -EINVAL;
2334
b9454e83
JB
2335 /* only support setting default key */
2336 if (!key.def && !key.defmgmt)
41ade00f
JB
2337 return -EINVAL;
2338
dbd2fd65 2339 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2340
dbd2fd65
JB
2341 if (key.def) {
2342 if (!rdev->ops->set_default_key) {
2343 err = -EOPNOTSUPP;
2344 goto out;
2345 }
41ade00f 2346
dbd2fd65
JB
2347 err = nl80211_key_allowed(dev->ieee80211_ptr);
2348 if (err)
2349 goto out;
2350
e35e4d28 2351 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2352 key.def_uni, key.def_multi);
2353
2354 if (err)
2355 goto out;
fffd0934 2356
3d23e349 2357#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2358 dev->ieee80211_ptr->wext.default_key = key.idx;
2359#endif
2360 } else {
2361 if (key.def_uni || !key.def_multi) {
2362 err = -EINVAL;
2363 goto out;
2364 }
2365
2366 if (!rdev->ops->set_default_mgmt_key) {
2367 err = -EOPNOTSUPP;
2368 goto out;
2369 }
2370
2371 err = nl80211_key_allowed(dev->ieee80211_ptr);
2372 if (err)
2373 goto out;
2374
e35e4d28 2375 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2376 if (err)
2377 goto out;
2378
2379#ifdef CONFIG_CFG80211_WEXT
2380 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2381#endif
dbd2fd65
JB
2382 }
2383
2384 out:
fffd0934 2385 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2386
41ade00f
JB
2387 return err;
2388}
2389
2390static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2391{
4c476991 2392 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2393 int err;
4c476991 2394 struct net_device *dev = info->user_ptr[1];
b9454e83 2395 struct key_parse key;
e31b8213 2396 const u8 *mac_addr = NULL;
41ade00f 2397
b9454e83
JB
2398 err = nl80211_parse_key(info, &key);
2399 if (err)
2400 return err;
41ade00f 2401
b9454e83 2402 if (!key.p.key)
41ade00f
JB
2403 return -EINVAL;
2404
41ade00f
JB
2405 if (info->attrs[NL80211_ATTR_MAC])
2406 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2407
e31b8213
JB
2408 if (key.type == -1) {
2409 if (mac_addr)
2410 key.type = NL80211_KEYTYPE_PAIRWISE;
2411 else
2412 key.type = NL80211_KEYTYPE_GROUP;
2413 }
2414
2415 /* for now */
2416 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2417 key.type != NL80211_KEYTYPE_GROUP)
2418 return -EINVAL;
2419
4c476991
JB
2420 if (!rdev->ops->add_key)
2421 return -EOPNOTSUPP;
25e47c18 2422
e31b8213
JB
2423 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2424 key.type == NL80211_KEYTYPE_PAIRWISE,
2425 mac_addr))
4c476991 2426 return -EINVAL;
41ade00f 2427
fffd0934
JB
2428 wdev_lock(dev->ieee80211_ptr);
2429 err = nl80211_key_allowed(dev->ieee80211_ptr);
2430 if (!err)
e35e4d28
HG
2431 err = rdev_add_key(rdev, dev, key.idx,
2432 key.type == NL80211_KEYTYPE_PAIRWISE,
2433 mac_addr, &key.p);
fffd0934 2434 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2435
41ade00f
JB
2436 return err;
2437}
2438
2439static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2440{
4c476991 2441 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2442 int err;
4c476991 2443 struct net_device *dev = info->user_ptr[1];
41ade00f 2444 u8 *mac_addr = NULL;
b9454e83 2445 struct key_parse key;
41ade00f 2446
b9454e83
JB
2447 err = nl80211_parse_key(info, &key);
2448 if (err)
2449 return err;
41ade00f
JB
2450
2451 if (info->attrs[NL80211_ATTR_MAC])
2452 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2453
e31b8213
JB
2454 if (key.type == -1) {
2455 if (mac_addr)
2456 key.type = NL80211_KEYTYPE_PAIRWISE;
2457 else
2458 key.type = NL80211_KEYTYPE_GROUP;
2459 }
2460
2461 /* for now */
2462 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2463 key.type != NL80211_KEYTYPE_GROUP)
2464 return -EINVAL;
2465
4c476991
JB
2466 if (!rdev->ops->del_key)
2467 return -EOPNOTSUPP;
41ade00f 2468
fffd0934
JB
2469 wdev_lock(dev->ieee80211_ptr);
2470 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2471
2472 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2473 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2474 err = -ENOENT;
2475
fffd0934 2476 if (!err)
e35e4d28
HG
2477 err = rdev_del_key(rdev, dev, key.idx,
2478 key.type == NL80211_KEYTYPE_PAIRWISE,
2479 mac_addr);
41ade00f 2480
3d23e349 2481#ifdef CONFIG_CFG80211_WEXT
08645126 2482 if (!err) {
b9454e83 2483 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2484 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2485 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2486 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2487 }
2488#endif
fffd0934 2489 wdev_unlock(dev->ieee80211_ptr);
08645126 2490
41ade00f
JB
2491 return err;
2492}
2493
8860020e
JB
2494static int nl80211_parse_beacon(struct genl_info *info,
2495 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2496{
8860020e 2497 bool haveinfo = false;
ed1b6cc7 2498
9946ecfb
JM
2499 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2500 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2501 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2502 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2503 return -EINVAL;
2504
8860020e 2505 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2506
ed1b6cc7 2507 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2508 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2509 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2510 if (!bcn->head_len)
2511 return -EINVAL;
2512 haveinfo = true;
ed1b6cc7
JB
2513 }
2514
2515 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2516 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2517 bcn->tail_len =
ed1b6cc7 2518 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2519 haveinfo = true;
ed1b6cc7
JB
2520 }
2521
4c476991
JB
2522 if (!haveinfo)
2523 return -EINVAL;
3b85875a 2524
9946ecfb 2525 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2526 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2527 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2528 }
2529
2530 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2531 bcn->proberesp_ies =
9946ecfb 2532 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2533 bcn->proberesp_ies_len =
9946ecfb
JM
2534 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2535 }
2536
2537 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2538 bcn->assocresp_ies =
9946ecfb 2539 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2540 bcn->assocresp_ies_len =
9946ecfb
JM
2541 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2542 }
2543
00f740e1 2544 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2545 bcn->probe_resp =
00f740e1 2546 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2547 bcn->probe_resp_len =
00f740e1
AN
2548 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2549 }
2550
8860020e
JB
2551 return 0;
2552}
2553
46c1dd0c
FF
2554static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2555 struct cfg80211_ap_settings *params)
2556{
2557 struct wireless_dev *wdev;
2558 bool ret = false;
2559
2560 mutex_lock(&rdev->devlist_mtx);
2561
89a54e48 2562 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2563 if (wdev->iftype != NL80211_IFTYPE_AP &&
2564 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2565 continue;
2566
683b6d3b 2567 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
2568 continue;
2569
683b6d3b 2570 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
2571 ret = true;
2572 break;
2573 }
2574
2575 mutex_unlock(&rdev->devlist_mtx);
2576
2577 return ret;
2578}
2579
e39e5b5e
JM
2580static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
2581 enum nl80211_auth_type auth_type,
2582 enum nl80211_commands cmd)
2583{
2584 if (auth_type > NL80211_AUTHTYPE_MAX)
2585 return false;
2586
2587 switch (cmd) {
2588 case NL80211_CMD_AUTHENTICATE:
2589 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
2590 auth_type == NL80211_AUTHTYPE_SAE)
2591 return false;
2592 return true;
2593 case NL80211_CMD_CONNECT:
2594 case NL80211_CMD_START_AP:
2595 /* SAE not supported yet */
2596 if (auth_type == NL80211_AUTHTYPE_SAE)
2597 return false;
2598 return true;
2599 default:
2600 return false;
2601 }
2602}
2603
8860020e
JB
2604static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2605{
2606 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2607 struct net_device *dev = info->user_ptr[1];
2608 struct wireless_dev *wdev = dev->ieee80211_ptr;
2609 struct cfg80211_ap_settings params;
2610 int err;
2611
2612 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2613 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2614 return -EOPNOTSUPP;
2615
2616 if (!rdev->ops->start_ap)
2617 return -EOPNOTSUPP;
2618
2619 if (wdev->beacon_interval)
2620 return -EALREADY;
2621
2622 memset(&params, 0, sizeof(params));
2623
2624 /* these are required for START_AP */
2625 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2626 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2627 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2628 return -EINVAL;
2629
2630 err = nl80211_parse_beacon(info, &params.beacon);
2631 if (err)
2632 return err;
2633
2634 params.beacon_interval =
2635 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2636 params.dtim_period =
2637 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2638
2639 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2640 if (err)
2641 return err;
2642
2643 /*
2644 * In theory, some of these attributes should be required here
2645 * but since they were not used when the command was originally
2646 * added, keep them optional for old user space programs to let
2647 * them continue to work with drivers that do not need the
2648 * additional information -- drivers must check!
2649 */
2650 if (info->attrs[NL80211_ATTR_SSID]) {
2651 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2652 params.ssid_len =
2653 nla_len(info->attrs[NL80211_ATTR_SSID]);
2654 if (params.ssid_len == 0 ||
2655 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2656 return -EINVAL;
2657 }
2658
2659 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2660 params.hidden_ssid = nla_get_u32(
2661 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2662 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2663 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2664 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2665 return -EINVAL;
2666 }
2667
2668 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2669
2670 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2671 params.auth_type = nla_get_u32(
2672 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
2673 if (!nl80211_valid_auth_type(rdev, params.auth_type,
2674 NL80211_CMD_START_AP))
8860020e
JB
2675 return -EINVAL;
2676 } else
2677 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2678
2679 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2680 NL80211_MAX_NR_CIPHER_SUITES);
2681 if (err)
2682 return err;
2683
1b658f11
VT
2684 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2685 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2686 return -EOPNOTSUPP;
2687 params.inactivity_timeout = nla_get_u16(
2688 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2689 }
2690
53cabad7
JB
2691 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
2692 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2693 return -EINVAL;
2694 params.p2p_ctwindow =
2695 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
2696 if (params.p2p_ctwindow > 127)
2697 return -EINVAL;
2698 if (params.p2p_ctwindow != 0 &&
2699 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
2700 return -EINVAL;
2701 }
2702
2703 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
2704 u8 tmp;
2705
2706 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2707 return -EINVAL;
2708 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
2709 if (tmp > 1)
2710 return -EINVAL;
2711 params.p2p_opp_ps = tmp;
2712 if (params.p2p_opp_ps != 0 &&
2713 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
2714 return -EINVAL;
2715 }
2716
aa430da4 2717 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
2718 err = nl80211_parse_chandef(rdev, info, &params.chandef);
2719 if (err)
2720 return err;
2721 } else if (wdev->preset_chandef.chan) {
2722 params.chandef = wdev->preset_chandef;
46c1dd0c 2723 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
2724 return -EINVAL;
2725
683b6d3b 2726 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
2727 return -EINVAL;
2728
e4e32459 2729 mutex_lock(&rdev->devlist_mtx);
683b6d3b 2730 err = cfg80211_can_use_chan(rdev, wdev, params.chandef.chan,
e4e32459
MK
2731 CHAN_MODE_SHARED);
2732 mutex_unlock(&rdev->devlist_mtx);
2733
2734 if (err)
2735 return err;
2736
e35e4d28 2737 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 2738 if (!err) {
683b6d3b 2739 wdev->preset_chandef = params.chandef;
8860020e 2740 wdev->beacon_interval = params.beacon_interval;
683b6d3b 2741 wdev->channel = params.chandef.chan;
06e191e2
AQ
2742 wdev->ssid_len = params.ssid_len;
2743 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 2744 }
56d1893d 2745 return err;
ed1b6cc7
JB
2746}
2747
8860020e
JB
2748static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2749{
2750 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2751 struct net_device *dev = info->user_ptr[1];
2752 struct wireless_dev *wdev = dev->ieee80211_ptr;
2753 struct cfg80211_beacon_data params;
2754 int err;
2755
2756 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2757 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2758 return -EOPNOTSUPP;
2759
2760 if (!rdev->ops->change_beacon)
2761 return -EOPNOTSUPP;
2762
2763 if (!wdev->beacon_interval)
2764 return -EINVAL;
2765
2766 err = nl80211_parse_beacon(info, &params);
2767 if (err)
2768 return err;
2769
e35e4d28 2770 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
2771}
2772
2773static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2774{
4c476991
JB
2775 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2776 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 2777
60771780 2778 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
2779}
2780
5727ef1b
JB
2781static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2782 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2783 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2784 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2785 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2786 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2787 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2788};
2789
eccb8e8f 2790static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2791 enum nl80211_iftype iftype,
eccb8e8f 2792 struct station_parameters *params)
5727ef1b
JB
2793{
2794 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2795 struct nlattr *nla;
5727ef1b
JB
2796 int flag;
2797
eccb8e8f
JB
2798 /*
2799 * Try parsing the new attribute first so userspace
2800 * can specify both for older kernels.
2801 */
2802 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2803 if (nla) {
2804 struct nl80211_sta_flag_update *sta_flags;
2805
2806 sta_flags = nla_data(nla);
2807 params->sta_flags_mask = sta_flags->mask;
2808 params->sta_flags_set = sta_flags->set;
2809 if ((params->sta_flags_mask |
2810 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2811 return -EINVAL;
2812 return 0;
2813 }
2814
2815 /* if present, parse the old attribute */
5727ef1b 2816
eccb8e8f 2817 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2818 if (!nla)
2819 return 0;
2820
2821 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2822 nla, sta_flags_policy))
2823 return -EINVAL;
2824
bdd3ae3d
JB
2825 /*
2826 * Only allow certain flags for interface types so that
2827 * other attributes are silently ignored. Remember that
2828 * this is backward compatibility code with old userspace
2829 * and shouldn't be hit in other cases anyway.
2830 */
2831 switch (iftype) {
2832 case NL80211_IFTYPE_AP:
2833 case NL80211_IFTYPE_AP_VLAN:
2834 case NL80211_IFTYPE_P2P_GO:
2835 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2836 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2837 BIT(NL80211_STA_FLAG_WME) |
2838 BIT(NL80211_STA_FLAG_MFP);
2839 break;
2840 case NL80211_IFTYPE_P2P_CLIENT:
2841 case NL80211_IFTYPE_STATION:
2842 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2843 BIT(NL80211_STA_FLAG_TDLS_PEER);
2844 break;
2845 case NL80211_IFTYPE_MESH_POINT:
2846 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2847 BIT(NL80211_STA_FLAG_MFP) |
2848 BIT(NL80211_STA_FLAG_AUTHORIZED);
2849 default:
2850 return -EINVAL;
2851 }
5727ef1b 2852
3383b5a6
JB
2853 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2854 if (flags[flag]) {
eccb8e8f 2855 params->sta_flags_set |= (1<<flag);
5727ef1b 2856
3383b5a6
JB
2857 /* no longer support new API additions in old API */
2858 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2859 return -EINVAL;
2860 }
2861 }
2862
5727ef1b
JB
2863 return 0;
2864}
2865
c8dcfd8a
FF
2866static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2867 int attr)
2868{
2869 struct nlattr *rate;
8eb41c8d
VK
2870 u32 bitrate;
2871 u16 bitrate_compat;
c8dcfd8a
FF
2872
2873 rate = nla_nest_start(msg, attr);
2874 if (!rate)
db9c64cf 2875 return false;
c8dcfd8a
FF
2876
2877 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2878 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
2879 /* report 16-bit bitrate only if we can */
2880 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
2881 if (bitrate > 0 &&
2882 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
2883 return false;
2884 if (bitrate_compat > 0 &&
2885 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
2886 return false;
2887
2888 if (info->flags & RATE_INFO_FLAGS_MCS) {
2889 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
2890 return false;
2891 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
2892 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
2893 return false;
2894 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
2895 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
2896 return false;
2897 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
2898 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
2899 return false;
2900 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
2901 return false;
2902 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
2903 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
2904 return false;
2905 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
2906 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
2907 return false;
2908 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
2909 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
2910 return false;
2911 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
2912 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
2913 return false;
2914 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
2915 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
2916 return false;
2917 }
c8dcfd8a
FF
2918
2919 nla_nest_end(msg, rate);
2920 return true;
c8dcfd8a
FF
2921}
2922
15e47304 2923static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
2924 int flags,
2925 struct cfg80211_registered_device *rdev,
2926 struct net_device *dev,
98b62183 2927 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2928{
2929 void *hdr;
f4263c98 2930 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 2931
15e47304 2932 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
2933 if (!hdr)
2934 return -1;
2935
9360ffd1
DM
2936 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2937 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
2938 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
2939 goto nla_put_failure;
f5ea9120 2940
2ec600d6
LCC
2941 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2942 if (!sinfoattr)
fd5b74dc 2943 goto nla_put_failure;
9360ffd1
DM
2944 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
2945 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2946 sinfo->connected_time))
2947 goto nla_put_failure;
2948 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
2949 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2950 sinfo->inactive_time))
2951 goto nla_put_failure;
2952 if ((sinfo->filled & STATION_INFO_RX_BYTES) &&
2953 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
2954 sinfo->rx_bytes))
2955 goto nla_put_failure;
2956 if ((sinfo->filled & STATION_INFO_TX_BYTES) &&
2957 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
2958 sinfo->tx_bytes))
2959 goto nla_put_failure;
2960 if ((sinfo->filled & STATION_INFO_LLID) &&
2961 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
2962 goto nla_put_failure;
2963 if ((sinfo->filled & STATION_INFO_PLID) &&
2964 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
2965 goto nla_put_failure;
2966 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
2967 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
2968 sinfo->plink_state))
2969 goto nla_put_failure;
66266b3a
JL
2970 switch (rdev->wiphy.signal_type) {
2971 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
2972 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
2973 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
2974 sinfo->signal))
2975 goto nla_put_failure;
2976 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
2977 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2978 sinfo->signal_avg))
2979 goto nla_put_failure;
66266b3a
JL
2980 break;
2981 default:
2982 break;
2983 }
420e7fab 2984 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2985 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2986 NL80211_STA_INFO_TX_BITRATE))
2987 goto nla_put_failure;
2988 }
2989 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2990 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2991 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2992 goto nla_put_failure;
420e7fab 2993 }
9360ffd1
DM
2994 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
2995 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
2996 sinfo->rx_packets))
2997 goto nla_put_failure;
2998 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
2999 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3000 sinfo->tx_packets))
3001 goto nla_put_failure;
3002 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3003 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3004 sinfo->tx_retries))
3005 goto nla_put_failure;
3006 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3007 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3008 sinfo->tx_failed))
3009 goto nla_put_failure;
3010 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3011 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3012 sinfo->beacon_loss_count))
3013 goto nla_put_failure;
3b1c5a53
MP
3014 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3015 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3016 sinfo->local_pm))
3017 goto nla_put_failure;
3018 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3019 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3020 sinfo->peer_pm))
3021 goto nla_put_failure;
3022 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3023 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3024 sinfo->nonpeer_pm))
3025 goto nla_put_failure;
f4263c98
PS
3026 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3027 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3028 if (!bss_param)
3029 goto nla_put_failure;
3030
9360ffd1
DM
3031 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3032 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3033 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3034 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3035 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3036 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3037 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3038 sinfo->bss_param.dtim_period) ||
3039 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3040 sinfo->bss_param.beacon_interval))
3041 goto nla_put_failure;
f4263c98
PS
3042
3043 nla_nest_end(msg, bss_param);
3044 }
9360ffd1
DM
3045 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3046 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3047 sizeof(struct nl80211_sta_flag_update),
3048 &sinfo->sta_flags))
3049 goto nla_put_failure;
7eab0f64
JL
3050 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3051 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3052 sinfo->t_offset))
3053 goto nla_put_failure;
2ec600d6 3054 nla_nest_end(msg, sinfoattr);
fd5b74dc 3055
9360ffd1
DM
3056 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3057 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3058 sinfo->assoc_req_ies))
3059 goto nla_put_failure;
50d3dfb7 3060
fd5b74dc
JB
3061 return genlmsg_end(msg, hdr);
3062
3063 nla_put_failure:
bc3ed28c
TG
3064 genlmsg_cancel(msg, hdr);
3065 return -EMSGSIZE;
fd5b74dc
JB
3066}
3067
2ec600d6 3068static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3069 struct netlink_callback *cb)
2ec600d6 3070{
2ec600d6
LCC
3071 struct station_info sinfo;
3072 struct cfg80211_registered_device *dev;
bba95fef 3073 struct net_device *netdev;
2ec600d6 3074 u8 mac_addr[ETH_ALEN];
bba95fef 3075 int sta_idx = cb->args[1];
2ec600d6 3076 int err;
2ec600d6 3077
67748893
JB
3078 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3079 if (err)
3080 return err;
bba95fef
JB
3081
3082 if (!dev->ops->dump_station) {
eec60b03 3083 err = -EOPNOTSUPP;
bba95fef
JB
3084 goto out_err;
3085 }
3086
bba95fef 3087 while (1) {
f612cedf 3088 memset(&sinfo, 0, sizeof(sinfo));
e35e4d28
HG
3089 err = rdev_dump_station(dev, netdev, sta_idx,
3090 mac_addr, &sinfo);
bba95fef
JB
3091 if (err == -ENOENT)
3092 break;
3093 if (err)
3b85875a 3094 goto out_err;
bba95fef
JB
3095
3096 if (nl80211_send_station(skb,
15e47304 3097 NETLINK_CB(cb->skb).portid,
bba95fef 3098 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 3099 dev, netdev, mac_addr,
bba95fef
JB
3100 &sinfo) < 0)
3101 goto out;
3102
3103 sta_idx++;
3104 }
3105
3106
3107 out:
3108 cb->args[1] = sta_idx;
3109 err = skb->len;
bba95fef 3110 out_err:
67748893 3111 nl80211_finish_netdev_dump(dev);
bba95fef
JB
3112
3113 return err;
2ec600d6 3114}
fd5b74dc 3115
5727ef1b
JB
3116static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3117{
4c476991
JB
3118 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3119 struct net_device *dev = info->user_ptr[1];
2ec600d6 3120 struct station_info sinfo;
fd5b74dc
JB
3121 struct sk_buff *msg;
3122 u8 *mac_addr = NULL;
4c476991 3123 int err;
fd5b74dc 3124
2ec600d6 3125 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3126
3127 if (!info->attrs[NL80211_ATTR_MAC])
3128 return -EINVAL;
3129
3130 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3131
4c476991
JB
3132 if (!rdev->ops->get_station)
3133 return -EOPNOTSUPP;
3b85875a 3134
e35e4d28 3135 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3136 if (err)
4c476991 3137 return err;
2ec600d6 3138
fd2120ca 3139 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3140 if (!msg)
4c476991 3141 return -ENOMEM;
fd5b74dc 3142
15e47304 3143 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3144 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3145 nlmsg_free(msg);
3146 return -ENOBUFS;
3147 }
3b85875a 3148
4c476991 3149 return genlmsg_reply(msg, info);
5727ef1b
JB
3150}
3151
3152/*
c258d2de 3153 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3154 */
80b99899
JB
3155static struct net_device *get_vlan(struct genl_info *info,
3156 struct cfg80211_registered_device *rdev)
5727ef1b 3157{
463d0183 3158 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3159 struct net_device *v;
3160 int ret;
3161
3162 if (!vlanattr)
3163 return NULL;
3164
3165 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3166 if (!v)
3167 return ERR_PTR(-ENODEV);
3168
3169 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3170 ret = -EINVAL;
3171 goto error;
5727ef1b 3172 }
80b99899
JB
3173
3174 if (!netif_running(v)) {
3175 ret = -ENETDOWN;
3176 goto error;
3177 }
3178
3179 return v;
3180 error:
3181 dev_put(v);
3182 return ERR_PTR(ret);
5727ef1b
JB
3183}
3184
3185static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3186{
4c476991 3187 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3188 int err;
4c476991 3189 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3190 struct station_parameters params;
3191 u8 *mac_addr = NULL;
3192
3193 memset(&params, 0, sizeof(params));
3194
3195 params.listen_interval = -1;
57cf8043 3196 params.plink_state = -1;
5727ef1b
JB
3197
3198 if (info->attrs[NL80211_ATTR_STA_AID])
3199 return -EINVAL;
3200
3201 if (!info->attrs[NL80211_ATTR_MAC])
3202 return -EINVAL;
3203
3204 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3205
3206 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3207 params.supported_rates =
3208 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3209 params.supported_rates_len =
3210 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3211 }
3212
ba23d206
JB
3213 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL] ||
3214 info->attrs[NL80211_ATTR_HT_CAPABILITY])
3215 return -EINVAL;
36aedc90 3216
bdd90d5e
JB
3217 if (!rdev->ops->change_station)
3218 return -EOPNOTSUPP;
3219
bdd3ae3d 3220 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3221 return -EINVAL;
3222
2ec600d6
LCC
3223 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3224 params.plink_action =
3225 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3226
9c3990aa
JC
3227 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
3228 params.plink_state =
3229 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3230
3b1c5a53
MP
3231 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
3232 enum nl80211_mesh_power_mode pm = nla_get_u32(
3233 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
3234
3235 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
3236 pm > NL80211_MESH_POWER_MAX)
3237 return -EINVAL;
3238
3239 params.local_pm = pm;
3240 }
3241
a97f4424
JB
3242 switch (dev->ieee80211_ptr->iftype) {
3243 case NL80211_IFTYPE_AP:
3244 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3245 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
3246 /* disallow mesh-specific things */
3247 if (params.plink_action)
bdd90d5e 3248 return -EINVAL;
3b1c5a53
MP
3249 if (params.local_pm)
3250 return -EINVAL;
bdd90d5e
JB
3251
3252 /* TDLS can't be set, ... */
3253 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3254 return -EINVAL;
3255 /*
3256 * ... but don't bother the driver with it. This works around
3257 * a hostapd/wpa_supplicant issue -- it always includes the
3258 * TLDS_PEER flag in the mask even for AP mode.
3259 */
3260 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3261
3262 /* accept only the listed bits */
3263 if (params.sta_flags_mask &
3264 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
d582cffb
JB
3265 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3266 BIT(NL80211_STA_FLAG_ASSOCIATED) |
bdd90d5e
JB
3267 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3268 BIT(NL80211_STA_FLAG_WME) |
3269 BIT(NL80211_STA_FLAG_MFP)))
3270 return -EINVAL;
3271
d582cffb
JB
3272 /* but authenticated/associated only if driver handles it */
3273 if (!(rdev->wiphy.features &
3274 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3275 params.sta_flags_mask &
3276 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3277 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3278 return -EINVAL;
3279
ba23d206
JB
3280 /* reject other things that can't change */
3281 if (params.supported_rates)
3282 return -EINVAL;
3283
bdd90d5e
JB
3284 /* must be last in here for error handling */
3285 params.vlan = get_vlan(info, rdev);
3286 if (IS_ERR(params.vlan))
3287 return PTR_ERR(params.vlan);
a97f4424 3288 break;
074ac8df 3289 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3290 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
3291 /*
3292 * Don't allow userspace to change the TDLS_PEER flag,
3293 * but silently ignore attempts to change it since we
3294 * don't have state here to verify that it doesn't try
3295 * to change the flag.
3296 */
3297 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
3298 /* fall through */
3299 case NL80211_IFTYPE_ADHOC:
3300 /* disallow things sta doesn't support */
3301 if (params.plink_action)
3302 return -EINVAL;
3b1c5a53
MP
3303 if (params.local_pm)
3304 return -EINVAL;
bdd90d5e
JB
3305 /* reject any changes other than AUTHORIZED */
3306 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3307 return -EINVAL;
a97f4424
JB
3308 break;
3309 case NL80211_IFTYPE_MESH_POINT:
3310 /* disallow things mesh doesn't support */
3311 if (params.vlan)
bdd90d5e 3312 return -EINVAL;
ba23d206 3313 if (params.supported_rates)
bdd90d5e
JB
3314 return -EINVAL;
3315 /*
3316 * No special handling for TDLS here -- the userspace
3317 * mesh code doesn't have this bug.
3318 */
b39c48fa
JC
3319 if (params.sta_flags_mask &
3320 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 3321 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 3322 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 3323 return -EINVAL;
a97f4424
JB
3324 break;
3325 default:
bdd90d5e 3326 return -EOPNOTSUPP;
034d655e
JB
3327 }
3328
bdd90d5e 3329 /* be aware of params.vlan when changing code here */
5727ef1b 3330
e35e4d28 3331 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 3332
5727ef1b
JB
3333 if (params.vlan)
3334 dev_put(params.vlan);
3b85875a 3335
5727ef1b
JB
3336 return err;
3337}
3338
c75786c9
EP
3339static struct nla_policy
3340nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3341 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3342 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3343};
3344
5727ef1b
JB
3345static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3346{
4c476991 3347 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3348 int err;
4c476991 3349 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3350 struct station_parameters params;
3351 u8 *mac_addr = NULL;
3352
3353 memset(&params, 0, sizeof(params));
3354
3355 if (!info->attrs[NL80211_ATTR_MAC])
3356 return -EINVAL;
3357
5727ef1b
JB
3358 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3359 return -EINVAL;
3360
3361 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3362 return -EINVAL;
3363
0e956c13
TLSC
3364 if (!info->attrs[NL80211_ATTR_STA_AID])
3365 return -EINVAL;
3366
5727ef1b
JB
3367 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3368 params.supported_rates =
3369 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3370 params.supported_rates_len =
3371 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3372 params.listen_interval =
3373 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3374
0e956c13
TLSC
3375 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
3376 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3377 return -EINVAL;
51b50fbe 3378
36aedc90
JM
3379 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3380 params.ht_capa =
3381 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 3382
f461be3e
MP
3383 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3384 params.vht_capa =
3385 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3386
96b78dff
JC
3387 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3388 params.plink_action =
3389 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3390
bdd90d5e
JB
3391 if (!rdev->ops->add_station)
3392 return -EOPNOTSUPP;
3393
bdd3ae3d 3394 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3395 return -EINVAL;
3396
bdd90d5e
JB
3397 switch (dev->ieee80211_ptr->iftype) {
3398 case NL80211_IFTYPE_AP:
3399 case NL80211_IFTYPE_AP_VLAN:
3400 case NL80211_IFTYPE_P2P_GO:
3401 /* parse WME attributes if sta is WME capable */
3402 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3403 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
3404 info->attrs[NL80211_ATTR_STA_WME]) {
3405 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3406 struct nlattr *nla;
3407
3408 nla = info->attrs[NL80211_ATTR_STA_WME];
3409 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3410 nl80211_sta_wme_policy);
3411 if (err)
3412 return err;
3413
3414 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3415 params.uapsd_queues =
3416 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
3417 if (params.uapsd_queues &
3418 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3419 return -EINVAL;
c75786c9 3420
bdd90d5e
JB
3421 if (tb[NL80211_STA_WME_MAX_SP])
3422 params.max_sp =
3423 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 3424
bdd90d5e
JB
3425 if (params.max_sp &
3426 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3427 return -EINVAL;
4319e193 3428
bdd90d5e
JB
3429 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3430 }
3431 /* TDLS peers cannot be added */
3432 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3433 return -EINVAL;
bdd90d5e
JB
3434 /* but don't bother the driver with it */
3435 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3436
d582cffb
JB
3437 /* allow authenticated/associated only if driver handles it */
3438 if (!(rdev->wiphy.features &
3439 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3440 params.sta_flags_mask &
3441 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3442 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3443 return -EINVAL;
3444
bdd90d5e
JB
3445 /* must be last in here for error handling */
3446 params.vlan = get_vlan(info, rdev);
3447 if (IS_ERR(params.vlan))
3448 return PTR_ERR(params.vlan);
3449 break;
3450 case NL80211_IFTYPE_MESH_POINT:
d582cffb
JB
3451 /* associated is disallowed */
3452 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3453 return -EINVAL;
bdd90d5e
JB
3454 /* TDLS peers cannot be added */
3455 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3456 return -EINVAL;
3457 break;
3458 case NL80211_IFTYPE_STATION:
d582cffb
JB
3459 /* associated is disallowed */
3460 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3461 return -EINVAL;
bdd90d5e
JB
3462 /* Only TDLS peers can be added */
3463 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3464 return -EINVAL;
3465 /* Can only add if TDLS ... */
3466 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3467 return -EOPNOTSUPP;
3468 /* ... with external setup is supported */
3469 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3470 return -EOPNOTSUPP;
3471 break;
3472 default:
3473 return -EOPNOTSUPP;
c75786c9
EP
3474 }
3475
bdd90d5e 3476 /* be aware of params.vlan when changing code here */
5727ef1b 3477
e35e4d28 3478 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 3479
5727ef1b
JB
3480 if (params.vlan)
3481 dev_put(params.vlan);
5727ef1b
JB
3482 return err;
3483}
3484
3485static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3486{
4c476991
JB
3487 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3488 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3489 u8 *mac_addr = NULL;
3490
3491 if (info->attrs[NL80211_ATTR_MAC])
3492 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3493
e80cf853 3494 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3495 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3496 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3497 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3498 return -EINVAL;
5727ef1b 3499
4c476991
JB
3500 if (!rdev->ops->del_station)
3501 return -EOPNOTSUPP;
3b85875a 3502
e35e4d28 3503 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
3504}
3505
15e47304 3506static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
3507 int flags, struct net_device *dev,
3508 u8 *dst, u8 *next_hop,
3509 struct mpath_info *pinfo)
3510{
3511 void *hdr;
3512 struct nlattr *pinfoattr;
3513
15e47304 3514 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
3515 if (!hdr)
3516 return -1;
3517
9360ffd1
DM
3518 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3519 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3520 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3521 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3522 goto nla_put_failure;
f5ea9120 3523
2ec600d6
LCC
3524 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3525 if (!pinfoattr)
3526 goto nla_put_failure;
9360ffd1
DM
3527 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3528 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3529 pinfo->frame_qlen))
3530 goto nla_put_failure;
3531 if (((pinfo->filled & MPATH_INFO_SN) &&
3532 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3533 ((pinfo->filled & MPATH_INFO_METRIC) &&
3534 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3535 pinfo->metric)) ||
3536 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3537 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3538 pinfo->exptime)) ||
3539 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3540 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3541 pinfo->flags)) ||
3542 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3543 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3544 pinfo->discovery_timeout)) ||
3545 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3546 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3547 pinfo->discovery_retries)))
3548 goto nla_put_failure;
2ec600d6
LCC
3549
3550 nla_nest_end(msg, pinfoattr);
3551
3552 return genlmsg_end(msg, hdr);
3553
3554 nla_put_failure:
bc3ed28c
TG
3555 genlmsg_cancel(msg, hdr);
3556 return -EMSGSIZE;
2ec600d6
LCC
3557}
3558
3559static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3560 struct netlink_callback *cb)
2ec600d6 3561{
2ec600d6
LCC
3562 struct mpath_info pinfo;
3563 struct cfg80211_registered_device *dev;
bba95fef 3564 struct net_device *netdev;
2ec600d6
LCC
3565 u8 dst[ETH_ALEN];
3566 u8 next_hop[ETH_ALEN];
bba95fef 3567 int path_idx = cb->args[1];
2ec600d6 3568 int err;
2ec600d6 3569
67748893
JB
3570 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3571 if (err)
3572 return err;
bba95fef
JB
3573
3574 if (!dev->ops->dump_mpath) {
eec60b03 3575 err = -EOPNOTSUPP;
bba95fef
JB
3576 goto out_err;
3577 }
3578
eec60b03
JM
3579 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3580 err = -EOPNOTSUPP;
0448b5fc 3581 goto out_err;
eec60b03
JM
3582 }
3583
bba95fef 3584 while (1) {
e35e4d28
HG
3585 err = rdev_dump_mpath(dev, netdev, path_idx, dst, next_hop,
3586 &pinfo);
bba95fef 3587 if (err == -ENOENT)
2ec600d6 3588 break;
bba95fef 3589 if (err)
3b85875a 3590 goto out_err;
2ec600d6 3591
15e47304 3592 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef
JB
3593 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3594 netdev, dst, next_hop,
3595 &pinfo) < 0)
3596 goto out;
2ec600d6 3597
bba95fef 3598 path_idx++;
2ec600d6 3599 }
2ec600d6 3600
2ec600d6 3601
bba95fef
JB
3602 out:
3603 cb->args[1] = path_idx;
3604 err = skb->len;
bba95fef 3605 out_err:
67748893 3606 nl80211_finish_netdev_dump(dev);
bba95fef 3607 return err;
2ec600d6
LCC
3608}
3609
3610static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3611{
4c476991 3612 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3613 int err;
4c476991 3614 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3615 struct mpath_info pinfo;
3616 struct sk_buff *msg;
3617 u8 *dst = NULL;
3618 u8 next_hop[ETH_ALEN];
3619
3620 memset(&pinfo, 0, sizeof(pinfo));
3621
3622 if (!info->attrs[NL80211_ATTR_MAC])
3623 return -EINVAL;
3624
3625 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3626
4c476991
JB
3627 if (!rdev->ops->get_mpath)
3628 return -EOPNOTSUPP;
2ec600d6 3629
4c476991
JB
3630 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3631 return -EOPNOTSUPP;
eec60b03 3632
e35e4d28 3633 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 3634 if (err)
4c476991 3635 return err;
2ec600d6 3636
fd2120ca 3637 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3638 if (!msg)
4c476991 3639 return -ENOMEM;
2ec600d6 3640
15e47304 3641 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
3642 dev, dst, next_hop, &pinfo) < 0) {
3643 nlmsg_free(msg);
3644 return -ENOBUFS;
3645 }
3b85875a 3646
4c476991 3647 return genlmsg_reply(msg, info);
2ec600d6
LCC
3648}
3649
3650static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3651{
4c476991
JB
3652 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3653 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3654 u8 *dst = NULL;
3655 u8 *next_hop = NULL;
3656
3657 if (!info->attrs[NL80211_ATTR_MAC])
3658 return -EINVAL;
3659
3660 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3661 return -EINVAL;
3662
3663 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3664 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3665
4c476991
JB
3666 if (!rdev->ops->change_mpath)
3667 return -EOPNOTSUPP;
35a8efe1 3668
4c476991
JB
3669 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3670 return -EOPNOTSUPP;
2ec600d6 3671
e35e4d28 3672 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 3673}
4c476991 3674
2ec600d6
LCC
3675static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3676{
4c476991
JB
3677 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3678 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3679 u8 *dst = NULL;
3680 u8 *next_hop = NULL;
3681
3682 if (!info->attrs[NL80211_ATTR_MAC])
3683 return -EINVAL;
3684
3685 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3686 return -EINVAL;
3687
3688 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3689 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3690
4c476991
JB
3691 if (!rdev->ops->add_mpath)
3692 return -EOPNOTSUPP;
35a8efe1 3693
4c476991
JB
3694 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3695 return -EOPNOTSUPP;
2ec600d6 3696
e35e4d28 3697 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
3698}
3699
3700static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3701{
4c476991
JB
3702 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3703 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3704 u8 *dst = NULL;
3705
3706 if (info->attrs[NL80211_ATTR_MAC])
3707 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3708
4c476991
JB
3709 if (!rdev->ops->del_mpath)
3710 return -EOPNOTSUPP;
3b85875a 3711
e35e4d28 3712 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
3713}
3714
9f1ba906
JM
3715static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3716{
4c476991
JB
3717 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3718 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3719 struct bss_parameters params;
3720
3721 memset(&params, 0, sizeof(params));
3722 /* default to not changing parameters */
3723 params.use_cts_prot = -1;
3724 params.use_short_preamble = -1;
3725 params.use_short_slot_time = -1;
fd8aaaf3 3726 params.ap_isolate = -1;
50b12f59 3727 params.ht_opmode = -1;
53cabad7
JB
3728 params.p2p_ctwindow = -1;
3729 params.p2p_opp_ps = -1;
9f1ba906
JM
3730
3731 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3732 params.use_cts_prot =
3733 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3734 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3735 params.use_short_preamble =
3736 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3737 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3738 params.use_short_slot_time =
3739 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3740 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3741 params.basic_rates =
3742 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3743 params.basic_rates_len =
3744 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3745 }
fd8aaaf3
FF
3746 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3747 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3748 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3749 params.ht_opmode =
3750 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3751
53cabad7
JB
3752 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3753 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3754 return -EINVAL;
3755 params.p2p_ctwindow =
3756 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3757 if (params.p2p_ctwindow < 0)
3758 return -EINVAL;
3759 if (params.p2p_ctwindow != 0 &&
3760 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3761 return -EINVAL;
3762 }
3763
3764 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3765 u8 tmp;
3766
3767 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3768 return -EINVAL;
3769 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3770 if (tmp > 1)
3771 return -EINVAL;
3772 params.p2p_opp_ps = tmp;
3773 if (params.p2p_opp_ps &&
3774 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3775 return -EINVAL;
3776 }
3777
4c476991
JB
3778 if (!rdev->ops->change_bss)
3779 return -EOPNOTSUPP;
9f1ba906 3780
074ac8df 3781 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3782 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3783 return -EOPNOTSUPP;
3b85875a 3784
e35e4d28 3785 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
3786}
3787
b54452b0 3788static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3789 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3790 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3791 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3792 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3793 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3794 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3795};
3796
3797static int parse_reg_rule(struct nlattr *tb[],
3798 struct ieee80211_reg_rule *reg_rule)
3799{
3800 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3801 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3802
3803 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3804 return -EINVAL;
3805 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3806 return -EINVAL;
3807 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3808 return -EINVAL;
3809 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3810 return -EINVAL;
3811 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3812 return -EINVAL;
3813
3814 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3815
3816 freq_range->start_freq_khz =
3817 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3818 freq_range->end_freq_khz =
3819 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3820 freq_range->max_bandwidth_khz =
3821 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3822
3823 power_rule->max_eirp =
3824 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3825
3826 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3827 power_rule->max_antenna_gain =
3828 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3829
3830 return 0;
3831}
3832
3833static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3834{
3835 int r;
3836 char *data = NULL;
57b5ce07 3837 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 3838
80778f18
LR
3839 /*
3840 * You should only get this when cfg80211 hasn't yet initialized
3841 * completely when built-in to the kernel right between the time
3842 * window between nl80211_init() and regulatory_init(), if that is
3843 * even possible.
3844 */
458f4f9e 3845 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 3846 return -EINPROGRESS;
80778f18 3847
fe33eb39
LR
3848 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3849 return -EINVAL;
b2e1b302
LR
3850
3851 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3852
57b5ce07
LR
3853 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
3854 user_reg_hint_type =
3855 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
3856 else
3857 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
3858
3859 switch (user_reg_hint_type) {
3860 case NL80211_USER_REG_HINT_USER:
3861 case NL80211_USER_REG_HINT_CELL_BASE:
3862 break;
3863 default:
3864 return -EINVAL;
3865 }
3866
3867 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 3868
b2e1b302
LR
3869 return r;
3870}
3871
24bdd9f4 3872static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3873 struct genl_info *info)
93da9cc1 3874{
4c476991 3875 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3876 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3877 struct wireless_dev *wdev = dev->ieee80211_ptr;
3878 struct mesh_config cur_params;
3879 int err = 0;
93da9cc1 3880 void *hdr;
3881 struct nlattr *pinfoattr;
3882 struct sk_buff *msg;
3883
29cbe68c
JB
3884 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3885 return -EOPNOTSUPP;
3886
24bdd9f4 3887 if (!rdev->ops->get_mesh_config)
4c476991 3888 return -EOPNOTSUPP;
f3f92586 3889
29cbe68c
JB
3890 wdev_lock(wdev);
3891 /* If not connected, get default parameters */
3892 if (!wdev->mesh_id_len)
3893 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3894 else
e35e4d28 3895 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
3896 wdev_unlock(wdev);
3897
93da9cc1 3898 if (err)
4c476991 3899 return err;
93da9cc1 3900
3901 /* Draw up a netlink message to send back */
fd2120ca 3902 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3903 if (!msg)
3904 return -ENOMEM;
15e47304 3905 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 3906 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3907 if (!hdr)
efe1cf0c 3908 goto out;
24bdd9f4 3909 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3910 if (!pinfoattr)
3911 goto nla_put_failure;
9360ffd1
DM
3912 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3913 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3914 cur_params.dot11MeshRetryTimeout) ||
3915 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3916 cur_params.dot11MeshConfirmTimeout) ||
3917 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3918 cur_params.dot11MeshHoldingTimeout) ||
3919 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3920 cur_params.dot11MeshMaxPeerLinks) ||
3921 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
3922 cur_params.dot11MeshMaxRetries) ||
3923 nla_put_u8(msg, NL80211_MESHCONF_TTL,
3924 cur_params.dot11MeshTTL) ||
3925 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3926 cur_params.element_ttl) ||
3927 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3928 cur_params.auto_open_plinks) ||
7eab0f64
JL
3929 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3930 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
3931 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3932 cur_params.dot11MeshHWMPmaxPREQretries) ||
3933 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3934 cur_params.path_refresh_time) ||
3935 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3936 cur_params.min_discovery_timeout) ||
3937 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3938 cur_params.dot11MeshHWMPactivePathTimeout) ||
3939 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3940 cur_params.dot11MeshHWMPpreqMinInterval) ||
3941 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3942 cur_params.dot11MeshHWMPperrMinInterval) ||
3943 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3944 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
3945 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3946 cur_params.dot11MeshHWMPRootMode) ||
3947 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3948 cur_params.dot11MeshHWMPRannInterval) ||
3949 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3950 cur_params.dot11MeshGateAnnouncementProtocol) ||
3951 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
3952 cur_params.dot11MeshForwarding) ||
3953 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
3954 cur_params.rssi_threshold) ||
3955 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
3956 cur_params.ht_opmode) ||
3957 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
3958 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
3959 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
3960 cur_params.dot11MeshHWMProotInterval) ||
3961 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
3962 cur_params.dot11MeshHWMPconfirmationInterval) ||
3963 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
3964 cur_params.power_mode) ||
3965 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
3966 cur_params.dot11MeshAwakeWindowDuration))
9360ffd1 3967 goto nla_put_failure;
93da9cc1 3968 nla_nest_end(msg, pinfoattr);
3969 genlmsg_end(msg, hdr);
4c476991 3970 return genlmsg_reply(msg, info);
93da9cc1 3971
3b85875a 3972 nla_put_failure:
93da9cc1 3973 genlmsg_cancel(msg, hdr);
efe1cf0c 3974 out:
d080e275 3975 nlmsg_free(msg);
4c476991 3976 return -ENOBUFS;
93da9cc1 3977}
3978
b54452b0 3979static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3980 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3981 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3982 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3983 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3984 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3985 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3986 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3987 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 3988 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 3989 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3990 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3991 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3992 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3993 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3994 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3995 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3996 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3997 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3998 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3999 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4000 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4001 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4002 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4003 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4004 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4005 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4006 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
93da9cc1 4007};
4008
c80d545d
JC
4009static const struct nla_policy
4010 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4011 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4012 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4013 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4014 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 4015 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4016 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4017 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4018};
4019
24bdd9f4 4020static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4021 struct mesh_config *cfg,
4022 u32 *mask_out)
93da9cc1 4023{
93da9cc1 4024 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4025 u32 mask = 0;
93da9cc1 4026
ea54fba2
MP
4027#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4028do { \
4029 if (tb[attr]) { \
4030 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4031 return -EINVAL; \
4032 cfg->param = fn(tb[attr]); \
4033 mask |= (1 << (attr - 1)); \
4034 } \
4035} while (0)
bd90fdcc
JB
4036
4037
24bdd9f4 4038 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4039 return -EINVAL;
4040 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4041 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4042 nl80211_meshconf_params_policy))
93da9cc1 4043 return -EINVAL;
4044
93da9cc1 4045 /* This makes sure that there aren't more than 32 mesh config
4046 * parameters (otherwise our bitfield scheme would not work.) */
4047 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4048
4049 /* Fill in the params struct */
ea54fba2 4050 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4051 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4052 nla_get_u16);
ea54fba2 4053 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4054 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4055 nla_get_u16);
ea54fba2 4056 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4057 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4058 nla_get_u16);
ea54fba2 4059 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4060 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4061 nla_get_u16);
ea54fba2 4062 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4063 mask, NL80211_MESHCONF_MAX_RETRIES,
4064 nla_get_u8);
ea54fba2 4065 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4066 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4067 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4068 mask, NL80211_MESHCONF_ELEMENT_TTL,
4069 nla_get_u8);
ea54fba2 4070 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4071 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4072 nla_get_u8);
ea54fba2
MP
4073 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4074 1, 255, mask,
a4f606ea
CYY
4075 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4076 nla_get_u32);
ea54fba2 4077 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4078 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4079 nla_get_u8);
ea54fba2 4080 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4081 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4082 nla_get_u32);
ea54fba2 4083 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4084 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4085 nla_get_u16);
ea54fba2
MP
4086 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4087 1, 65535, mask,
a4f606ea
CYY
4088 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4089 nla_get_u32);
93da9cc1 4090 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4091 1, 65535, mask,
4092 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4093 nla_get_u16);
dca7e943 4094 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4095 1, 65535, mask,
4096 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4097 nla_get_u16);
93da9cc1 4098 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4099 dot11MeshHWMPnetDiameterTraversalTime,
4100 1, 65535, mask,
a4f606ea
CYY
4101 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4102 nla_get_u16);
ea54fba2
MP
4103 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4104 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4105 nla_get_u8);
4106 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4107 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4108 nla_get_u16);
63c5723b 4109 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4110 dot11MeshGateAnnouncementProtocol, 0, 1,
4111 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4112 nla_get_u8);
ea54fba2 4113 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4114 mask, NL80211_MESHCONF_FORWARDING,
4115 nla_get_u8);
ea54fba2 4116 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, 1, 255,
a4f606ea
CYY
4117 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
4118 nla_get_u32);
ea54fba2 4119 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4120 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4121 nla_get_u16);
4122 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4123 1, 65535, mask,
ac1073a6
CYY
4124 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4125 nla_get_u32);
ea54fba2 4126 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4127 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4128 nla_get_u16);
4129 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4130 dot11MeshHWMPconfirmationInterval,
4131 1, 65535, mask,
728b19e5 4132 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4133 nla_get_u16);
3b1c5a53
MP
4134 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4135 NL80211_MESH_POWER_ACTIVE,
4136 NL80211_MESH_POWER_MAX,
4137 mask, NL80211_MESHCONF_POWER_MODE,
4138 nla_get_u32);
4139 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4140 0, 65535, mask,
4141 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
bd90fdcc
JB
4142 if (mask_out)
4143 *mask_out = mask;
c80d545d 4144
bd90fdcc
JB
4145 return 0;
4146
4147#undef FILL_IN_MESH_PARAM_IF_SET
4148}
4149
c80d545d
JC
4150static int nl80211_parse_mesh_setup(struct genl_info *info,
4151 struct mesh_setup *setup)
4152{
4153 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4154
4155 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4156 return -EINVAL;
4157 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4158 info->attrs[NL80211_ATTR_MESH_SETUP],
4159 nl80211_mesh_setup_params_policy))
4160 return -EINVAL;
4161
d299a1f2
JC
4162 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4163 setup->sync_method =
4164 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4165 IEEE80211_SYNC_METHOD_VENDOR :
4166 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4167
c80d545d
JC
4168 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4169 setup->path_sel_proto =
4170 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4171 IEEE80211_PATH_PROTOCOL_VENDOR :
4172 IEEE80211_PATH_PROTOCOL_HWMP;
4173
4174 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4175 setup->path_metric =
4176 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4177 IEEE80211_PATH_METRIC_VENDOR :
4178 IEEE80211_PATH_METRIC_AIRTIME;
4179
581a8b0f
JC
4180
4181 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4182 struct nlattr *ieattr =
581a8b0f 4183 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4184 if (!is_valid_ie_attr(ieattr))
4185 return -EINVAL;
581a8b0f
JC
4186 setup->ie = nla_data(ieattr);
4187 setup->ie_len = nla_len(ieattr);
c80d545d 4188 }
b130e5ce
JC
4189 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4190 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
4191
4192 return 0;
4193}
4194
24bdd9f4 4195static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4196 struct genl_info *info)
bd90fdcc
JB
4197{
4198 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4199 struct net_device *dev = info->user_ptr[1];
29cbe68c 4200 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4201 struct mesh_config cfg;
4202 u32 mask;
4203 int err;
4204
29cbe68c
JB
4205 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4206 return -EOPNOTSUPP;
4207
24bdd9f4 4208 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4209 return -EOPNOTSUPP;
4210
24bdd9f4 4211 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4212 if (err)
4213 return err;
4214
29cbe68c
JB
4215 wdev_lock(wdev);
4216 if (!wdev->mesh_id_len)
4217 err = -ENOLINK;
4218
4219 if (!err)
e35e4d28 4220 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4221
4222 wdev_unlock(wdev);
4223
4224 return err;
93da9cc1 4225}
4226
f130347c
LR
4227static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4228{
458f4f9e 4229 const struct ieee80211_regdomain *regdom;
f130347c
LR
4230 struct sk_buff *msg;
4231 void *hdr = NULL;
4232 struct nlattr *nl_reg_rules;
4233 unsigned int i;
4234 int err = -EINVAL;
4235
a1794390 4236 mutex_lock(&cfg80211_mutex);
f130347c
LR
4237
4238 if (!cfg80211_regdomain)
4239 goto out;
4240
fd2120ca 4241 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
4242 if (!msg) {
4243 err = -ENOBUFS;
4244 goto out;
4245 }
4246
15e47304 4247 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4248 NL80211_CMD_GET_REG);
4249 if (!hdr)
efe1cf0c 4250 goto put_failure;
f130347c 4251
57b5ce07
LR
4252 if (reg_last_request_cell_base() &&
4253 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4254 NL80211_USER_REG_HINT_CELL_BASE))
4255 goto nla_put_failure;
4256
458f4f9e
JB
4257 rcu_read_lock();
4258 regdom = rcu_dereference(cfg80211_regdomain);
4259
4260 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
4261 (regdom->dfs_region &&
4262 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
4263 goto nla_put_failure_rcu;
4264
f130347c
LR
4265 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4266 if (!nl_reg_rules)
458f4f9e 4267 goto nla_put_failure_rcu;
f130347c 4268
458f4f9e 4269 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
4270 struct nlattr *nl_reg_rule;
4271 const struct ieee80211_reg_rule *reg_rule;
4272 const struct ieee80211_freq_range *freq_range;
4273 const struct ieee80211_power_rule *power_rule;
4274
458f4f9e 4275 reg_rule = &regdom->reg_rules[i];
f130347c
LR
4276 freq_range = &reg_rule->freq_range;
4277 power_rule = &reg_rule->power_rule;
4278
4279 nl_reg_rule = nla_nest_start(msg, i);
4280 if (!nl_reg_rule)
458f4f9e 4281 goto nla_put_failure_rcu;
f130347c 4282
9360ffd1
DM
4283 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4284 reg_rule->flags) ||
4285 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4286 freq_range->start_freq_khz) ||
4287 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
4288 freq_range->end_freq_khz) ||
4289 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
4290 freq_range->max_bandwidth_khz) ||
4291 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
4292 power_rule->max_antenna_gain) ||
4293 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
4294 power_rule->max_eirp))
458f4f9e 4295 goto nla_put_failure_rcu;
f130347c
LR
4296
4297 nla_nest_end(msg, nl_reg_rule);
4298 }
458f4f9e 4299 rcu_read_unlock();
f130347c
LR
4300
4301 nla_nest_end(msg, nl_reg_rules);
4302
4303 genlmsg_end(msg, hdr);
134e6375 4304 err = genlmsg_reply(msg, info);
f130347c
LR
4305 goto out;
4306
458f4f9e
JB
4307nla_put_failure_rcu:
4308 rcu_read_unlock();
f130347c
LR
4309nla_put_failure:
4310 genlmsg_cancel(msg, hdr);
efe1cf0c 4311put_failure:
d080e275 4312 nlmsg_free(msg);
f130347c
LR
4313 err = -EMSGSIZE;
4314out:
a1794390 4315 mutex_unlock(&cfg80211_mutex);
f130347c
LR
4316 return err;
4317}
4318
b2e1b302
LR
4319static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
4320{
4321 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
4322 struct nlattr *nl_reg_rule;
4323 char *alpha2 = NULL;
4324 int rem_reg_rules = 0, r = 0;
4325 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4326 u8 dfs_region = 0;
b2e1b302
LR
4327 struct ieee80211_regdomain *rd = NULL;
4328
4329 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4330 return -EINVAL;
4331
4332 if (!info->attrs[NL80211_ATTR_REG_RULES])
4333 return -EINVAL;
4334
4335 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4336
8b60b078
LR
4337 if (info->attrs[NL80211_ATTR_DFS_REGION])
4338 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4339
b2e1b302 4340 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4341 rem_reg_rules) {
b2e1b302
LR
4342 num_rules++;
4343 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4344 return -EINVAL;
b2e1b302
LR
4345 }
4346
b2e1b302 4347 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 4348 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
4349
4350 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
4351 if (!rd)
4352 return -ENOMEM;
b2e1b302
LR
4353
4354 rd->n_reg_rules = num_rules;
4355 rd->alpha2[0] = alpha2[0];
4356 rd->alpha2[1] = alpha2[1];
4357
8b60b078
LR
4358 /*
4359 * Disable DFS master mode if the DFS region was
4360 * not supported or known on this kernel.
4361 */
4362 if (reg_supported_dfs_region(dfs_region))
4363 rd->dfs_region = dfs_region;
4364
b2e1b302 4365 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4366 rem_reg_rules) {
b2e1b302 4367 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
4368 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
4369 reg_rule_policy);
b2e1b302
LR
4370 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
4371 if (r)
4372 goto bad_reg;
4373
4374 rule_idx++;
4375
d0e18f83
LR
4376 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
4377 r = -EINVAL;
b2e1b302 4378 goto bad_reg;
d0e18f83 4379 }
b2e1b302
LR
4380 }
4381
6913b49a
JB
4382 mutex_lock(&cfg80211_mutex);
4383
b2e1b302 4384 r = set_regdom(rd);
6913b49a 4385 /* set_regdom took ownership */
1a919318 4386 rd = NULL;
6913b49a 4387 mutex_unlock(&cfg80211_mutex);
b2e1b302 4388
d2372b31 4389 bad_reg:
b2e1b302 4390 kfree(rd);
d0e18f83 4391 return r;
b2e1b302
LR
4392}
4393
83f5e2cf
JB
4394static int validate_scan_freqs(struct nlattr *freqs)
4395{
4396 struct nlattr *attr1, *attr2;
4397 int n_channels = 0, tmp1, tmp2;
4398
4399 nla_for_each_nested(attr1, freqs, tmp1) {
4400 n_channels++;
4401 /*
4402 * Some hardware has a limited channel list for
4403 * scanning, and it is pretty much nonsensical
4404 * to scan for a channel twice, so disallow that
4405 * and don't require drivers to check that the
4406 * channel list they get isn't longer than what
4407 * they can scan, as long as they can scan all
4408 * the channels they registered at once.
4409 */
4410 nla_for_each_nested(attr2, freqs, tmp2)
4411 if (attr1 != attr2 &&
4412 nla_get_u32(attr1) == nla_get_u32(attr2))
4413 return 0;
4414 }
4415
4416 return n_channels;
4417}
4418
2a519311
JB
4419static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
4420{
4c476991 4421 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 4422 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 4423 struct cfg80211_scan_request *request;
2a519311
JB
4424 struct nlattr *attr;
4425 struct wiphy *wiphy;
83f5e2cf 4426 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 4427 size_t ie_len;
2a519311 4428
f4a11bb0
JB
4429 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4430 return -EINVAL;
4431
79c97e97 4432 wiphy = &rdev->wiphy;
2a519311 4433
4c476991
JB
4434 if (!rdev->ops->scan)
4435 return -EOPNOTSUPP;
2a519311 4436
4c476991
JB
4437 if (rdev->scan_req)
4438 return -EBUSY;
2a519311
JB
4439
4440 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
4441 n_channels = validate_scan_freqs(
4442 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
4443 if (!n_channels)
4444 return -EINVAL;
2a519311 4445 } else {
34850ab2 4446 enum ieee80211_band band;
83f5e2cf
JB
4447 n_channels = 0;
4448
2a519311
JB
4449 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4450 if (wiphy->bands[band])
4451 n_channels += wiphy->bands[band]->n_channels;
4452 }
4453
4454 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4455 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
4456 n_ssids++;
4457
4c476991
JB
4458 if (n_ssids > wiphy->max_scan_ssids)
4459 return -EINVAL;
2a519311 4460
70692ad2
JM
4461 if (info->attrs[NL80211_ATTR_IE])
4462 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4463 else
4464 ie_len = 0;
4465
4c476991
JB
4466 if (ie_len > wiphy->max_scan_ie_len)
4467 return -EINVAL;
18a83659 4468
2a519311 4469 request = kzalloc(sizeof(*request)
a2cd43c5
LC
4470 + sizeof(*request->ssids) * n_ssids
4471 + sizeof(*request->channels) * n_channels
70692ad2 4472 + ie_len, GFP_KERNEL);
4c476991
JB
4473 if (!request)
4474 return -ENOMEM;
2a519311 4475
2a519311 4476 if (n_ssids)
5ba63533 4477 request->ssids = (void *)&request->channels[n_channels];
2a519311 4478 request->n_ssids = n_ssids;
70692ad2
JM
4479 if (ie_len) {
4480 if (request->ssids)
4481 request->ie = (void *)(request->ssids + n_ssids);
4482 else
4483 request->ie = (void *)(request->channels + n_channels);
4484 }
2a519311 4485
584991dc 4486 i = 0;
2a519311
JB
4487 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4488 /* user specified, bail out if channel not found */
2a519311 4489 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
4490 struct ieee80211_channel *chan;
4491
4492 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4493
4494 if (!chan) {
2a519311
JB
4495 err = -EINVAL;
4496 goto out_free;
4497 }
584991dc
JB
4498
4499 /* ignore disabled channels */
4500 if (chan->flags & IEEE80211_CHAN_DISABLED)
4501 continue;
4502
4503 request->channels[i] = chan;
2a519311
JB
4504 i++;
4505 }
4506 } else {
34850ab2
JB
4507 enum ieee80211_band band;
4508
2a519311 4509 /* all channels */
2a519311
JB
4510 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4511 int j;
4512 if (!wiphy->bands[band])
4513 continue;
4514 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4515 struct ieee80211_channel *chan;
4516
4517 chan = &wiphy->bands[band]->channels[j];
4518
4519 if (chan->flags & IEEE80211_CHAN_DISABLED)
4520 continue;
4521
4522 request->channels[i] = chan;
2a519311
JB
4523 i++;
4524 }
4525 }
4526 }
4527
584991dc
JB
4528 if (!i) {
4529 err = -EINVAL;
4530 goto out_free;
4531 }
4532
4533 request->n_channels = i;
4534
2a519311
JB
4535 i = 0;
4536 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4537 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4538 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4539 err = -EINVAL;
4540 goto out_free;
4541 }
57a27e1d 4542 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4543 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4544 i++;
4545 }
4546 }
4547
70692ad2
JM
4548 if (info->attrs[NL80211_ATTR_IE]) {
4549 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4550 memcpy((void *)request->ie,
4551 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4552 request->ie_len);
4553 }
4554
34850ab2 4555 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4556 if (wiphy->bands[i])
4557 request->rates[i] =
4558 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4559
4560 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4561 nla_for_each_nested(attr,
4562 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4563 tmp) {
4564 enum ieee80211_band band = nla_type(attr);
4565
84404623 4566 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4567 err = -EINVAL;
4568 goto out_free;
4569 }
4570 err = ieee80211_get_ratemask(wiphy->bands[band],
4571 nla_data(attr),
4572 nla_len(attr),
4573 &request->rates[band]);
4574 if (err)
4575 goto out_free;
4576 }
4577 }
4578
46856bbf 4579 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4580 request->flags = nla_get_u32(
4581 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4582 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4583 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4584 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4585 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4586 err = -EOPNOTSUPP;
4587 goto out_free;
4588 }
4589 }
ed473771 4590
e9f935e3
RM
4591 request->no_cck =
4592 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4593
fd014284 4594 request->wdev = wdev;
79c97e97 4595 request->wiphy = &rdev->wiphy;
15d6030b 4596 request->scan_start = jiffies;
2a519311 4597
79c97e97 4598 rdev->scan_req = request;
e35e4d28 4599 err = rdev_scan(rdev, request);
2a519311 4600
463d0183 4601 if (!err) {
fd014284
JB
4602 nl80211_send_scan_start(rdev, wdev);
4603 if (wdev->netdev)
4604 dev_hold(wdev->netdev);
4c476991 4605 } else {
2a519311 4606 out_free:
79c97e97 4607 rdev->scan_req = NULL;
2a519311
JB
4608 kfree(request);
4609 }
3b85875a 4610
2a519311
JB
4611 return err;
4612}
4613
807f8a8c
LC
4614static int nl80211_start_sched_scan(struct sk_buff *skb,
4615 struct genl_info *info)
4616{
4617 struct cfg80211_sched_scan_request *request;
4618 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4619 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4620 struct nlattr *attr;
4621 struct wiphy *wiphy;
a1f1c21c 4622 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4623 u32 interval;
807f8a8c
LC
4624 enum ieee80211_band band;
4625 size_t ie_len;
a1f1c21c 4626 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4627
4628 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4629 !rdev->ops->sched_scan_start)
4630 return -EOPNOTSUPP;
4631
4632 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4633 return -EINVAL;
4634
bbe6ad6d
LC
4635 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4636 return -EINVAL;
4637
4638 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4639 if (interval == 0)
4640 return -EINVAL;
4641
807f8a8c
LC
4642 wiphy = &rdev->wiphy;
4643
4644 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4645 n_channels = validate_scan_freqs(
4646 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4647 if (!n_channels)
4648 return -EINVAL;
4649 } else {
4650 n_channels = 0;
4651
4652 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4653 if (wiphy->bands[band])
4654 n_channels += wiphy->bands[band]->n_channels;
4655 }
4656
4657 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4658 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4659 tmp)
4660 n_ssids++;
4661
93b6aa69 4662 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4663 return -EINVAL;
4664
a1f1c21c
LC
4665 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4666 nla_for_each_nested(attr,
4667 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4668 tmp)
4669 n_match_sets++;
4670
4671 if (n_match_sets > wiphy->max_match_sets)
4672 return -EINVAL;
4673
807f8a8c
LC
4674 if (info->attrs[NL80211_ATTR_IE])
4675 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4676 else
4677 ie_len = 0;
4678
5a865bad 4679 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4680 return -EINVAL;
4681
c10841ca
LC
4682 mutex_lock(&rdev->sched_scan_mtx);
4683
4684 if (rdev->sched_scan_req) {
4685 err = -EINPROGRESS;
4686 goto out;
4687 }
4688
807f8a8c 4689 request = kzalloc(sizeof(*request)
a2cd43c5 4690 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4691 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4692 + sizeof(*request->channels) * n_channels
807f8a8c 4693 + ie_len, GFP_KERNEL);
c10841ca
LC
4694 if (!request) {
4695 err = -ENOMEM;
4696 goto out;
4697 }
807f8a8c
LC
4698
4699 if (n_ssids)
4700 request->ssids = (void *)&request->channels[n_channels];
4701 request->n_ssids = n_ssids;
4702 if (ie_len) {
4703 if (request->ssids)
4704 request->ie = (void *)(request->ssids + n_ssids);
4705 else
4706 request->ie = (void *)(request->channels + n_channels);
4707 }
4708
a1f1c21c
LC
4709 if (n_match_sets) {
4710 if (request->ie)
4711 request->match_sets = (void *)(request->ie + ie_len);
4712 else if (request->ssids)
4713 request->match_sets =
4714 (void *)(request->ssids + n_ssids);
4715 else
4716 request->match_sets =
4717 (void *)(request->channels + n_channels);
4718 }
4719 request->n_match_sets = n_match_sets;
4720
807f8a8c
LC
4721 i = 0;
4722 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4723 /* user specified, bail out if channel not found */
4724 nla_for_each_nested(attr,
4725 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4726 tmp) {
4727 struct ieee80211_channel *chan;
4728
4729 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4730
4731 if (!chan) {
4732 err = -EINVAL;
4733 goto out_free;
4734 }
4735
4736 /* ignore disabled channels */
4737 if (chan->flags & IEEE80211_CHAN_DISABLED)
4738 continue;
4739
4740 request->channels[i] = chan;
4741 i++;
4742 }
4743 } else {
4744 /* all channels */
4745 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4746 int j;
4747 if (!wiphy->bands[band])
4748 continue;
4749 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4750 struct ieee80211_channel *chan;
4751
4752 chan = &wiphy->bands[band]->channels[j];
4753
4754 if (chan->flags & IEEE80211_CHAN_DISABLED)
4755 continue;
4756
4757 request->channels[i] = chan;
4758 i++;
4759 }
4760 }
4761 }
4762
4763 if (!i) {
4764 err = -EINVAL;
4765 goto out_free;
4766 }
4767
4768 request->n_channels = i;
4769
4770 i = 0;
4771 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4772 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4773 tmp) {
57a27e1d 4774 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4775 err = -EINVAL;
4776 goto out_free;
4777 }
57a27e1d 4778 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4779 memcpy(request->ssids[i].ssid, nla_data(attr),
4780 nla_len(attr));
807f8a8c
LC
4781 i++;
4782 }
4783 }
4784
a1f1c21c
LC
4785 i = 0;
4786 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4787 nla_for_each_nested(attr,
4788 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4789 tmp) {
88e920b4 4790 struct nlattr *ssid, *rssi;
a1f1c21c
LC
4791
4792 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4793 nla_data(attr), nla_len(attr),
4794 nl80211_match_policy);
4a4ab0d7 4795 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4796 if (ssid) {
4797 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4798 err = -EINVAL;
4799 goto out_free;
4800 }
4801 memcpy(request->match_sets[i].ssid.ssid,
4802 nla_data(ssid), nla_len(ssid));
4803 request->match_sets[i].ssid.ssid_len =
4804 nla_len(ssid);
4805 }
88e920b4
TP
4806 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
4807 if (rssi)
4808 request->rssi_thold = nla_get_u32(rssi);
4809 else
4810 request->rssi_thold =
4811 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
4812 i++;
4813 }
4814 }
4815
807f8a8c
LC
4816 if (info->attrs[NL80211_ATTR_IE]) {
4817 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4818 memcpy((void *)request->ie,
4819 nla_data(info->attrs[NL80211_ATTR_IE]),
4820 request->ie_len);
4821 }
4822
46856bbf 4823 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4824 request->flags = nla_get_u32(
4825 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4826 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4827 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4828 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4829 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4830 err = -EOPNOTSUPP;
4831 goto out_free;
4832 }
4833 }
ed473771 4834
807f8a8c
LC
4835 request->dev = dev;
4836 request->wiphy = &rdev->wiphy;
bbe6ad6d 4837 request->interval = interval;
15d6030b 4838 request->scan_start = jiffies;
807f8a8c 4839
e35e4d28 4840 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
4841 if (!err) {
4842 rdev->sched_scan_req = request;
4843 nl80211_send_sched_scan(rdev, dev,
4844 NL80211_CMD_START_SCHED_SCAN);
4845 goto out;
4846 }
4847
4848out_free:
4849 kfree(request);
4850out:
c10841ca 4851 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4852 return err;
4853}
4854
4855static int nl80211_stop_sched_scan(struct sk_buff *skb,
4856 struct genl_info *info)
4857{
4858 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4859 int err;
807f8a8c
LC
4860
4861 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4862 !rdev->ops->sched_scan_stop)
4863 return -EOPNOTSUPP;
4864
c10841ca
LC
4865 mutex_lock(&rdev->sched_scan_mtx);
4866 err = __cfg80211_stop_sched_scan(rdev, false);
4867 mutex_unlock(&rdev->sched_scan_mtx);
4868
4869 return err;
807f8a8c
LC
4870}
4871
9720bb3a
JB
4872static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4873 u32 seq, int flags,
2a519311 4874 struct cfg80211_registered_device *rdev,
48ab905d
JB
4875 struct wireless_dev *wdev,
4876 struct cfg80211_internal_bss *intbss)
2a519311 4877{
48ab905d 4878 struct cfg80211_bss *res = &intbss->pub;
9caf0364 4879 const struct cfg80211_bss_ies *ies;
2a519311
JB
4880 void *hdr;
4881 struct nlattr *bss;
48ab905d
JB
4882
4883 ASSERT_WDEV_LOCK(wdev);
2a519311 4884
15e47304 4885 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
4886 NL80211_CMD_NEW_SCAN_RESULTS);
4887 if (!hdr)
4888 return -1;
4889
9720bb3a
JB
4890 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4891
9360ffd1
DM
4892 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
4893 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
4894 goto nla_put_failure;
2a519311
JB
4895
4896 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4897 if (!bss)
4898 goto nla_put_failure;
9360ffd1 4899 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 4900 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 4901 goto nla_put_failure;
9caf0364
JB
4902
4903 rcu_read_lock();
4904 ies = rcu_dereference(res->ies);
4905 if (ies && ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4906 ies->len, ies->data)) {
4907 rcu_read_unlock();
4908 goto nla_put_failure;
4909 }
4910 ies = rcu_dereference(res->beacon_ies);
4911 if (ies && ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
4912 ies->len, ies->data)) {
4913 rcu_read_unlock();
4914 goto nla_put_failure;
4915 }
4916 rcu_read_unlock();
4917
9360ffd1
DM
4918 if (res->tsf &&
4919 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
4920 goto nla_put_failure;
4921 if (res->beacon_interval &&
4922 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
4923 goto nla_put_failure;
4924 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
4925 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
4926 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
4927 jiffies_to_msecs(jiffies - intbss->ts)))
4928 goto nla_put_failure;
2a519311 4929
77965c97 4930 switch (rdev->wiphy.signal_type) {
2a519311 4931 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
4932 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
4933 goto nla_put_failure;
2a519311
JB
4934 break;
4935 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
4936 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
4937 goto nla_put_failure;
2a519311
JB
4938 break;
4939 default:
4940 break;
4941 }
4942
48ab905d 4943 switch (wdev->iftype) {
074ac8df 4944 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 4945 case NL80211_IFTYPE_STATION:
9360ffd1
DM
4946 if (intbss == wdev->current_bss &&
4947 nla_put_u32(msg, NL80211_BSS_STATUS,
4948 NL80211_BSS_STATUS_ASSOCIATED))
4949 goto nla_put_failure;
48ab905d
JB
4950 break;
4951 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
4952 if (intbss == wdev->current_bss &&
4953 nla_put_u32(msg, NL80211_BSS_STATUS,
4954 NL80211_BSS_STATUS_IBSS_JOINED))
4955 goto nla_put_failure;
48ab905d
JB
4956 break;
4957 default:
4958 break;
4959 }
4960
2a519311
JB
4961 nla_nest_end(msg, bss);
4962
4963 return genlmsg_end(msg, hdr);
4964
4965 nla_put_failure:
4966 genlmsg_cancel(msg, hdr);
4967 return -EMSGSIZE;
4968}
4969
4970static int nl80211_dump_scan(struct sk_buff *skb,
4971 struct netlink_callback *cb)
4972{
48ab905d
JB
4973 struct cfg80211_registered_device *rdev;
4974 struct net_device *dev;
2a519311 4975 struct cfg80211_internal_bss *scan;
48ab905d 4976 struct wireless_dev *wdev;
2a519311
JB
4977 int start = cb->args[1], idx = 0;
4978 int err;
4979
67748893
JB
4980 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4981 if (err)
4982 return err;
2a519311 4983
48ab905d 4984 wdev = dev->ieee80211_ptr;
2a519311 4985
48ab905d
JB
4986 wdev_lock(wdev);
4987 spin_lock_bh(&rdev->bss_lock);
4988 cfg80211_bss_expire(rdev);
4989
9720bb3a
JB
4990 cb->seq = rdev->bss_generation;
4991
48ab905d 4992 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4993 if (++idx <= start)
4994 continue;
9720bb3a 4995 if (nl80211_send_bss(skb, cb,
2a519311 4996 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4997 rdev, wdev, scan) < 0) {
2a519311 4998 idx--;
67748893 4999 break;
2a519311
JB
5000 }
5001 }
5002
48ab905d
JB
5003 spin_unlock_bh(&rdev->bss_lock);
5004 wdev_unlock(wdev);
2a519311
JB
5005
5006 cb->args[1] = idx;
67748893 5007 nl80211_finish_netdev_dump(rdev);
2a519311 5008
67748893 5009 return skb->len;
2a519311
JB
5010}
5011
15e47304 5012static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
5013 int flags, struct net_device *dev,
5014 struct survey_info *survey)
5015{
5016 void *hdr;
5017 struct nlattr *infoattr;
5018
15e47304 5019 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
5020 NL80211_CMD_NEW_SURVEY_RESULTS);
5021 if (!hdr)
5022 return -ENOMEM;
5023
9360ffd1
DM
5024 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
5025 goto nla_put_failure;
61fa713c
HS
5026
5027 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
5028 if (!infoattr)
5029 goto nla_put_failure;
5030
9360ffd1
DM
5031 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
5032 survey->channel->center_freq))
5033 goto nla_put_failure;
5034
5035 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
5036 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
5037 goto nla_put_failure;
5038 if ((survey->filled & SURVEY_INFO_IN_USE) &&
5039 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
5040 goto nla_put_failure;
5041 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
5042 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
5043 survey->channel_time))
5044 goto nla_put_failure;
5045 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
5046 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
5047 survey->channel_time_busy))
5048 goto nla_put_failure;
5049 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
5050 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5051 survey->channel_time_ext_busy))
5052 goto nla_put_failure;
5053 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5054 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5055 survey->channel_time_rx))
5056 goto nla_put_failure;
5057 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5058 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5059 survey->channel_time_tx))
5060 goto nla_put_failure;
61fa713c
HS
5061
5062 nla_nest_end(msg, infoattr);
5063
5064 return genlmsg_end(msg, hdr);
5065
5066 nla_put_failure:
5067 genlmsg_cancel(msg, hdr);
5068 return -EMSGSIZE;
5069}
5070
5071static int nl80211_dump_survey(struct sk_buff *skb,
5072 struct netlink_callback *cb)
5073{
5074 struct survey_info survey;
5075 struct cfg80211_registered_device *dev;
5076 struct net_device *netdev;
61fa713c
HS
5077 int survey_idx = cb->args[1];
5078 int res;
5079
67748893
JB
5080 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
5081 if (res)
5082 return res;
61fa713c
HS
5083
5084 if (!dev->ops->dump_survey) {
5085 res = -EOPNOTSUPP;
5086 goto out_err;
5087 }
5088
5089 while (1) {
180cdc79
LR
5090 struct ieee80211_channel *chan;
5091
e35e4d28 5092 res = rdev_dump_survey(dev, netdev, survey_idx, &survey);
61fa713c
HS
5093 if (res == -ENOENT)
5094 break;
5095 if (res)
5096 goto out_err;
5097
180cdc79
LR
5098 /* Survey without a channel doesn't make sense */
5099 if (!survey.channel) {
5100 res = -EINVAL;
5101 goto out;
5102 }
5103
5104 chan = ieee80211_get_channel(&dev->wiphy,
5105 survey.channel->center_freq);
5106 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5107 survey_idx++;
5108 continue;
5109 }
5110
61fa713c 5111 if (nl80211_send_survey(skb,
15e47304 5112 NETLINK_CB(cb->skb).portid,
61fa713c
HS
5113 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5114 netdev,
5115 &survey) < 0)
5116 goto out;
5117 survey_idx++;
5118 }
5119
5120 out:
5121 cb->args[1] = survey_idx;
5122 res = skb->len;
5123 out_err:
67748893 5124 nl80211_finish_netdev_dump(dev);
61fa713c
HS
5125 return res;
5126}
5127
b23aa676
SO
5128static bool nl80211_valid_wpa_versions(u32 wpa_versions)
5129{
5130 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
5131 NL80211_WPA_VERSION_2));
5132}
5133
636a5d36
JM
5134static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
5135{
4c476991
JB
5136 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5137 struct net_device *dev = info->user_ptr[1];
19957bb3 5138 struct ieee80211_channel *chan;
e39e5b5e
JM
5139 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
5140 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 5141 enum nl80211_auth_type auth_type;
fffd0934 5142 struct key_parse key;
d5cdfacb 5143 bool local_state_change;
636a5d36 5144
f4a11bb0
JB
5145 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5146 return -EINVAL;
5147
5148 if (!info->attrs[NL80211_ATTR_MAC])
5149 return -EINVAL;
5150
1778092e
JM
5151 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
5152 return -EINVAL;
5153
19957bb3
JB
5154 if (!info->attrs[NL80211_ATTR_SSID])
5155 return -EINVAL;
5156
5157 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
5158 return -EINVAL;
5159
fffd0934
JB
5160 err = nl80211_parse_key(info, &key);
5161 if (err)
5162 return err;
5163
5164 if (key.idx >= 0) {
e31b8213
JB
5165 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
5166 return -EINVAL;
fffd0934
JB
5167 if (!key.p.key || !key.p.key_len)
5168 return -EINVAL;
5169 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
5170 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
5171 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
5172 key.p.key_len != WLAN_KEY_LEN_WEP104))
5173 return -EINVAL;
5174 if (key.idx > 4)
5175 return -EINVAL;
5176 } else {
5177 key.p.key_len = 0;
5178 key.p.key = NULL;
5179 }
5180
afea0b7a
JB
5181 if (key.idx >= 0) {
5182 int i;
5183 bool ok = false;
5184 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
5185 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
5186 ok = true;
5187 break;
5188 }
5189 }
4c476991
JB
5190 if (!ok)
5191 return -EINVAL;
afea0b7a
JB
5192 }
5193
4c476991
JB
5194 if (!rdev->ops->auth)
5195 return -EOPNOTSUPP;
636a5d36 5196
074ac8df 5197 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5198 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5199 return -EOPNOTSUPP;
eec60b03 5200
19957bb3 5201 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 5202 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 5203 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5204 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5205 return -EINVAL;
636a5d36 5206
19957bb3
JB
5207 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5208 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5209
5210 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5211 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5212 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5213 }
5214
19957bb3 5215 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 5216 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 5217 return -EINVAL;
636a5d36 5218
e39e5b5e
JM
5219 if (auth_type == NL80211_AUTHTYPE_SAE &&
5220 !info->attrs[NL80211_ATTR_SAE_DATA])
5221 return -EINVAL;
5222
5223 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
5224 if (auth_type != NL80211_AUTHTYPE_SAE)
5225 return -EINVAL;
5226 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
5227 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
5228 /* need to include at least Auth Transaction and Status Code */
5229 if (sae_data_len < 4)
5230 return -EINVAL;
5231 }
5232
d5cdfacb
JM
5233 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5234
95de817b
JB
5235 /*
5236 * Since we no longer track auth state, ignore
5237 * requests to only change local state.
5238 */
5239 if (local_state_change)
5240 return 0;
5241
4c476991
JB
5242 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
5243 ssid, ssid_len, ie, ie_len,
e39e5b5e
JM
5244 key.p.key, key.p.key_len, key.idx,
5245 sae_data, sae_data_len);
636a5d36
JM
5246}
5247
c0692b8f
JB
5248static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
5249 struct genl_info *info,
3dc27d25
JB
5250 struct cfg80211_crypto_settings *settings,
5251 int cipher_limit)
b23aa676 5252{
c0b2bbd8
JB
5253 memset(settings, 0, sizeof(*settings));
5254
b23aa676
SO
5255 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
5256
c0692b8f
JB
5257 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
5258 u16 proto;
5259 proto = nla_get_u16(
5260 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
5261 settings->control_port_ethertype = cpu_to_be16(proto);
5262 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
5263 proto != ETH_P_PAE)
5264 return -EINVAL;
5265 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
5266 settings->control_port_no_encrypt = true;
5267 } else
5268 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
5269
b23aa676
SO
5270 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
5271 void *data;
5272 int len, i;
5273
5274 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5275 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5276 settings->n_ciphers_pairwise = len / sizeof(u32);
5277
5278 if (len % sizeof(u32))
5279 return -EINVAL;
5280
3dc27d25 5281 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
5282 return -EINVAL;
5283
5284 memcpy(settings->ciphers_pairwise, data, len);
5285
5286 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
5287 if (!cfg80211_supported_cipher_suite(
5288 &rdev->wiphy,
b23aa676
SO
5289 settings->ciphers_pairwise[i]))
5290 return -EINVAL;
5291 }
5292
5293 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
5294 settings->cipher_group =
5295 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
5296 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
5297 settings->cipher_group))
b23aa676
SO
5298 return -EINVAL;
5299 }
5300
5301 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
5302 settings->wpa_versions =
5303 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
5304 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
5305 return -EINVAL;
5306 }
5307
5308 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
5309 void *data;
6d30240e 5310 int len;
b23aa676
SO
5311
5312 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
5313 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
5314 settings->n_akm_suites = len / sizeof(u32);
5315
5316 if (len % sizeof(u32))
5317 return -EINVAL;
5318
1b9ca027
JM
5319 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
5320 return -EINVAL;
5321
b23aa676 5322 memcpy(settings->akm_suites, data, len);
b23aa676
SO
5323 }
5324
5325 return 0;
5326}
5327
636a5d36
JM
5328static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
5329{
4c476991
JB
5330 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5331 struct net_device *dev = info->user_ptr[1];
19957bb3 5332 struct cfg80211_crypto_settings crypto;
f444de05 5333 struct ieee80211_channel *chan;
3e5d7649 5334 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
5335 int err, ssid_len, ie_len = 0;
5336 bool use_mfp = false;
7e7c8926
BG
5337 u32 flags = 0;
5338 struct ieee80211_ht_cap *ht_capa = NULL;
5339 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 5340
f4a11bb0
JB
5341 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5342 return -EINVAL;
5343
5344 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
5345 !info->attrs[NL80211_ATTR_SSID] ||
5346 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
5347 return -EINVAL;
5348
4c476991
JB
5349 if (!rdev->ops->assoc)
5350 return -EOPNOTSUPP;
636a5d36 5351
074ac8df 5352 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5353 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5354 return -EOPNOTSUPP;
eec60b03 5355
19957bb3 5356 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5357
19957bb3
JB
5358 chan = ieee80211_get_channel(&rdev->wiphy,
5359 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5360 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5361 return -EINVAL;
636a5d36 5362
19957bb3
JB
5363 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5364 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5365
5366 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5367 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5368 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5369 }
5370
dc6382ce 5371 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 5372 enum nl80211_mfp mfp =
dc6382ce 5373 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 5374 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 5375 use_mfp = true;
4c476991
JB
5376 else if (mfp != NL80211_MFP_NO)
5377 return -EINVAL;
dc6382ce
JM
5378 }
5379
3e5d7649
JB
5380 if (info->attrs[NL80211_ATTR_PREV_BSSID])
5381 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
5382
7e7c8926
BG
5383 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5384 flags |= ASSOC_REQ_DISABLE_HT;
5385
5386 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5387 ht_capa_mask =
5388 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
5389
5390 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5391 if (!ht_capa_mask)
5392 return -EINVAL;
5393 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5394 }
5395
c0692b8f 5396 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 5397 if (!err)
3e5d7649
JB
5398 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
5399 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
5400 &crypto, flags, ht_capa,
5401 ht_capa_mask);
636a5d36 5402
636a5d36
JM
5403 return err;
5404}
5405
5406static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
5407{
4c476991
JB
5408 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5409 struct net_device *dev = info->user_ptr[1];
19957bb3 5410 const u8 *ie = NULL, *bssid;
4c476991 5411 int ie_len = 0;
19957bb3 5412 u16 reason_code;
d5cdfacb 5413 bool local_state_change;
636a5d36 5414
f4a11bb0
JB
5415 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5416 return -EINVAL;
5417
5418 if (!info->attrs[NL80211_ATTR_MAC])
5419 return -EINVAL;
5420
5421 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5422 return -EINVAL;
5423
4c476991
JB
5424 if (!rdev->ops->deauth)
5425 return -EOPNOTSUPP;
636a5d36 5426
074ac8df 5427 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5428 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5429 return -EOPNOTSUPP;
eec60b03 5430
19957bb3 5431 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5432
19957bb3
JB
5433 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5434 if (reason_code == 0) {
f4a11bb0 5435 /* Reason Code 0 is reserved */
4c476991 5436 return -EINVAL;
255e737e 5437 }
636a5d36
JM
5438
5439 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5440 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5441 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5442 }
5443
d5cdfacb
JM
5444 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5445
4c476991
JB
5446 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
5447 local_state_change);
636a5d36
JM
5448}
5449
5450static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
5451{
4c476991
JB
5452 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5453 struct net_device *dev = info->user_ptr[1];
19957bb3 5454 const u8 *ie = NULL, *bssid;
4c476991 5455 int ie_len = 0;
19957bb3 5456 u16 reason_code;
d5cdfacb 5457 bool local_state_change;
636a5d36 5458
f4a11bb0
JB
5459 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5460 return -EINVAL;
5461
5462 if (!info->attrs[NL80211_ATTR_MAC])
5463 return -EINVAL;
5464
5465 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5466 return -EINVAL;
5467
4c476991
JB
5468 if (!rdev->ops->disassoc)
5469 return -EOPNOTSUPP;
636a5d36 5470
074ac8df 5471 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5472 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5473 return -EOPNOTSUPP;
eec60b03 5474
19957bb3 5475 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5476
19957bb3
JB
5477 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5478 if (reason_code == 0) {
f4a11bb0 5479 /* Reason Code 0 is reserved */
4c476991 5480 return -EINVAL;
255e737e 5481 }
636a5d36
JM
5482
5483 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5484 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5485 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5486 }
5487
d5cdfacb
JM
5488 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5489
4c476991
JB
5490 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
5491 local_state_change);
636a5d36
JM
5492}
5493
dd5b4cc7
FF
5494static bool
5495nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
5496 int mcast_rate[IEEE80211_NUM_BANDS],
5497 int rateval)
5498{
5499 struct wiphy *wiphy = &rdev->wiphy;
5500 bool found = false;
5501 int band, i;
5502
5503 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5504 struct ieee80211_supported_band *sband;
5505
5506 sband = wiphy->bands[band];
5507 if (!sband)
5508 continue;
5509
5510 for (i = 0; i < sband->n_bitrates; i++) {
5511 if (sband->bitrates[i].bitrate == rateval) {
5512 mcast_rate[band] = i + 1;
5513 found = true;
5514 break;
5515 }
5516 }
5517 }
5518
5519 return found;
5520}
5521
04a773ad
JB
5522static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
5523{
4c476991
JB
5524 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5525 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
5526 struct cfg80211_ibss_params ibss;
5527 struct wiphy *wiphy;
fffd0934 5528 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
5529 int err;
5530
8e30bc55
JB
5531 memset(&ibss, 0, sizeof(ibss));
5532
04a773ad
JB
5533 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5534 return -EINVAL;
5535
683b6d3b 5536 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
5537 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5538 return -EINVAL;
5539
8e30bc55
JB
5540 ibss.beacon_interval = 100;
5541
5542 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
5543 ibss.beacon_interval =
5544 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5545 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
5546 return -EINVAL;
5547 }
5548
4c476991
JB
5549 if (!rdev->ops->join_ibss)
5550 return -EOPNOTSUPP;
04a773ad 5551
4c476991
JB
5552 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5553 return -EOPNOTSUPP;
04a773ad 5554
79c97e97 5555 wiphy = &rdev->wiphy;
04a773ad 5556
39193498 5557 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 5558 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
5559
5560 if (!is_valid_ether_addr(ibss.bssid))
5561 return -EINVAL;
5562 }
04a773ad
JB
5563 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5564 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5565
5566 if (info->attrs[NL80211_ATTR_IE]) {
5567 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5568 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5569 }
5570
683b6d3b
JB
5571 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
5572 if (err)
5573 return err;
04a773ad 5574
683b6d3b 5575 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
5576 return -EINVAL;
5577
db9c64cf
JB
5578 if (ibss.chandef.width > NL80211_CHAN_WIDTH_40)
5579 return -EINVAL;
5580 if (ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
5581 !(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
c04d6150 5582 return -EINVAL;
db9c64cf 5583
04a773ad 5584 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5585 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5586
fbd2c8dc
TP
5587 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5588 u8 *rates =
5589 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5590 int n_rates =
5591 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5592 struct ieee80211_supported_band *sband =
683b6d3b 5593 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 5594
34850ab2
JB
5595 err = ieee80211_get_ratemask(sband, rates, n_rates,
5596 &ibss.basic_rates);
5597 if (err)
5598 return err;
fbd2c8dc 5599 }
dd5b4cc7
FF
5600
5601 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5602 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5603 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5604 return -EINVAL;
fbd2c8dc 5605
4c476991 5606 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
5607 bool no_ht = false;
5608
4c476991 5609 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
5610 info->attrs[NL80211_ATTR_KEYS],
5611 &no_ht);
4c476991
JB
5612 if (IS_ERR(connkeys))
5613 return PTR_ERR(connkeys);
de7044ee 5614
3d9d1d66
JB
5615 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
5616 no_ht) {
de7044ee
SM
5617 kfree(connkeys);
5618 return -EINVAL;
5619 }
4c476991 5620 }
04a773ad 5621
267335d6
AQ
5622 ibss.control_port =
5623 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5624
4c476991 5625 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5626 if (err)
5627 kfree(connkeys);
04a773ad
JB
5628 return err;
5629}
5630
5631static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5632{
4c476991
JB
5633 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5634 struct net_device *dev = info->user_ptr[1];
04a773ad 5635
4c476991
JB
5636 if (!rdev->ops->leave_ibss)
5637 return -EOPNOTSUPP;
04a773ad 5638
4c476991
JB
5639 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5640 return -EOPNOTSUPP;
04a773ad 5641
4c476991 5642 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5643}
5644
f4e583c8
AQ
5645static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
5646{
5647 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5648 struct net_device *dev = info->user_ptr[1];
5649 int mcast_rate[IEEE80211_NUM_BANDS];
5650 u32 nla_rate;
5651 int err;
5652
5653 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5654 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5655 return -EOPNOTSUPP;
5656
5657 if (!rdev->ops->set_mcast_rate)
5658 return -EOPNOTSUPP;
5659
5660 memset(mcast_rate, 0, sizeof(mcast_rate));
5661
5662 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
5663 return -EINVAL;
5664
5665 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
5666 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
5667 return -EINVAL;
5668
5669 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
5670
5671 return err;
5672}
5673
5674
aff89a9b
JB
5675#ifdef CONFIG_NL80211_TESTMODE
5676static struct genl_multicast_group nl80211_testmode_mcgrp = {
5677 .name = "testmode",
5678};
5679
5680static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5681{
4c476991 5682 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5683 int err;
5684
5685 if (!info->attrs[NL80211_ATTR_TESTDATA])
5686 return -EINVAL;
5687
aff89a9b
JB
5688 err = -EOPNOTSUPP;
5689 if (rdev->ops->testmode_cmd) {
5690 rdev->testmode_info = info;
e35e4d28 5691 err = rdev_testmode_cmd(rdev,
aff89a9b
JB
5692 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5693 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5694 rdev->testmode_info = NULL;
5695 }
5696
aff89a9b
JB
5697 return err;
5698}
5699
71063f0e
WYG
5700static int nl80211_testmode_dump(struct sk_buff *skb,
5701 struct netlink_callback *cb)
5702{
00918d33 5703 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5704 int err;
5705 long phy_idx;
5706 void *data = NULL;
5707 int data_len = 0;
5708
5709 if (cb->args[0]) {
5710 /*
5711 * 0 is a valid index, but not valid for args[0],
5712 * so we need to offset by 1.
5713 */
5714 phy_idx = cb->args[0] - 1;
5715 } else {
5716 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5717 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5718 nl80211_policy);
5719 if (err)
5720 return err;
00918d33 5721
2bd7e35d
JB
5722 mutex_lock(&cfg80211_mutex);
5723 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
5724 nl80211_fam.attrbuf);
5725 if (IS_ERR(rdev)) {
5726 mutex_unlock(&cfg80211_mutex);
5727 return PTR_ERR(rdev);
00918d33 5728 }
2bd7e35d
JB
5729 phy_idx = rdev->wiphy_idx;
5730 rdev = NULL;
5731 mutex_unlock(&cfg80211_mutex);
5732
71063f0e
WYG
5733 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5734 cb->args[1] =
5735 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5736 }
5737
5738 if (cb->args[1]) {
5739 data = nla_data((void *)cb->args[1]);
5740 data_len = nla_len((void *)cb->args[1]);
5741 }
5742
5743 mutex_lock(&cfg80211_mutex);
00918d33
JB
5744 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5745 if (!rdev) {
71063f0e
WYG
5746 mutex_unlock(&cfg80211_mutex);
5747 return -ENOENT;
5748 }
00918d33 5749 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5750 mutex_unlock(&cfg80211_mutex);
5751
00918d33 5752 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5753 err = -EOPNOTSUPP;
5754 goto out_err;
5755 }
5756
5757 while (1) {
15e47304 5758 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
5759 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5760 NL80211_CMD_TESTMODE);
5761 struct nlattr *tmdata;
5762
9360ffd1 5763 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5764 genlmsg_cancel(skb, hdr);
5765 break;
5766 }
5767
5768 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5769 if (!tmdata) {
5770 genlmsg_cancel(skb, hdr);
5771 break;
5772 }
e35e4d28 5773 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
5774 nla_nest_end(skb, tmdata);
5775
5776 if (err == -ENOBUFS || err == -ENOENT) {
5777 genlmsg_cancel(skb, hdr);
5778 break;
5779 } else if (err) {
5780 genlmsg_cancel(skb, hdr);
5781 goto out_err;
5782 }
5783
5784 genlmsg_end(skb, hdr);
5785 }
5786
5787 err = skb->len;
5788 /* see above */
5789 cb->args[0] = phy_idx + 1;
5790 out_err:
00918d33 5791 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5792 return err;
5793}
5794
aff89a9b
JB
5795static struct sk_buff *
5796__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 5797 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
5798{
5799 struct sk_buff *skb;
5800 void *hdr;
5801 struct nlattr *data;
5802
5803 skb = nlmsg_new(approxlen + 100, gfp);
5804 if (!skb)
5805 return NULL;
5806
15e47304 5807 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
5808 if (!hdr) {
5809 kfree_skb(skb);
5810 return NULL;
5811 }
5812
9360ffd1
DM
5813 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5814 goto nla_put_failure;
aff89a9b
JB
5815 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5816
5817 ((void **)skb->cb)[0] = rdev;
5818 ((void **)skb->cb)[1] = hdr;
5819 ((void **)skb->cb)[2] = data;
5820
5821 return skb;
5822
5823 nla_put_failure:
5824 kfree_skb(skb);
5825 return NULL;
5826}
5827
5828struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5829 int approxlen)
5830{
5831 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5832
5833 if (WARN_ON(!rdev->testmode_info))
5834 return NULL;
5835
5836 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 5837 rdev->testmode_info->snd_portid,
aff89a9b
JB
5838 rdev->testmode_info->snd_seq,
5839 GFP_KERNEL);
5840}
5841EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5842
5843int cfg80211_testmode_reply(struct sk_buff *skb)
5844{
5845 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5846 void *hdr = ((void **)skb->cb)[1];
5847 struct nlattr *data = ((void **)skb->cb)[2];
5848
5849 if (WARN_ON(!rdev->testmode_info)) {
5850 kfree_skb(skb);
5851 return -EINVAL;
5852 }
5853
5854 nla_nest_end(skb, data);
5855 genlmsg_end(skb, hdr);
5856 return genlmsg_reply(skb, rdev->testmode_info);
5857}
5858EXPORT_SYMBOL(cfg80211_testmode_reply);
5859
5860struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5861 int approxlen, gfp_t gfp)
5862{
5863 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5864
5865 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5866}
5867EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5868
5869void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5870{
5871 void *hdr = ((void **)skb->cb)[1];
5872 struct nlattr *data = ((void **)skb->cb)[2];
5873
5874 nla_nest_end(skb, data);
5875 genlmsg_end(skb, hdr);
5876 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5877}
5878EXPORT_SYMBOL(cfg80211_testmode_event);
5879#endif
5880
b23aa676
SO
5881static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5882{
4c476991
JB
5883 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5884 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5885 struct cfg80211_connect_params connect;
5886 struct wiphy *wiphy;
fffd0934 5887 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5888 int err;
5889
5890 memset(&connect, 0, sizeof(connect));
5891
5892 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5893 return -EINVAL;
5894
5895 if (!info->attrs[NL80211_ATTR_SSID] ||
5896 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5897 return -EINVAL;
5898
5899 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5900 connect.auth_type =
5901 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
5902 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
5903 NL80211_CMD_CONNECT))
b23aa676
SO
5904 return -EINVAL;
5905 } else
5906 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5907
5908 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5909
c0692b8f 5910 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5911 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5912 if (err)
5913 return err;
b23aa676 5914
074ac8df 5915 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5916 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5917 return -EOPNOTSUPP;
b23aa676 5918
79c97e97 5919 wiphy = &rdev->wiphy;
b23aa676 5920
4486ea98
BS
5921 connect.bg_scan_period = -1;
5922 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5923 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5924 connect.bg_scan_period =
5925 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5926 }
5927
b23aa676
SO
5928 if (info->attrs[NL80211_ATTR_MAC])
5929 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5930 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5931 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5932
5933 if (info->attrs[NL80211_ATTR_IE]) {
5934 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5935 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5936 }
5937
cee00a95
JM
5938 if (info->attrs[NL80211_ATTR_USE_MFP]) {
5939 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
5940 if (connect.mfp != NL80211_MFP_REQUIRED &&
5941 connect.mfp != NL80211_MFP_NO)
5942 return -EINVAL;
5943 } else {
5944 connect.mfp = NL80211_MFP_NO;
5945 }
5946
b23aa676
SO
5947 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5948 connect.channel =
5949 ieee80211_get_channel(wiphy,
5950 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5951 if (!connect.channel ||
4c476991
JB
5952 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5953 return -EINVAL;
b23aa676
SO
5954 }
5955
fffd0934
JB
5956 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5957 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 5958 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
5959 if (IS_ERR(connkeys))
5960 return PTR_ERR(connkeys);
fffd0934
JB
5961 }
5962
7e7c8926
BG
5963 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5964 connect.flags |= ASSOC_REQ_DISABLE_HT;
5965
5966 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5967 memcpy(&connect.ht_capa_mask,
5968 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5969 sizeof(connect.ht_capa_mask));
5970
5971 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
5972 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
5973 kfree(connkeys);
7e7c8926 5974 return -EINVAL;
b4e4f47e 5975 }
7e7c8926
BG
5976 memcpy(&connect.ht_capa,
5977 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5978 sizeof(connect.ht_capa));
5979 }
5980
fffd0934 5981 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5982 if (err)
5983 kfree(connkeys);
b23aa676
SO
5984 return err;
5985}
5986
5987static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5988{
4c476991
JB
5989 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5990 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5991 u16 reason;
5992
5993 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5994 reason = WLAN_REASON_DEAUTH_LEAVING;
5995 else
5996 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5997
5998 if (reason == 0)
5999 return -EINVAL;
6000
074ac8df 6001 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6002 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6003 return -EOPNOTSUPP;
b23aa676 6004
4c476991 6005 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
6006}
6007
463d0183
JB
6008static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
6009{
4c476991 6010 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
6011 struct net *net;
6012 int err;
6013 u32 pid;
6014
6015 if (!info->attrs[NL80211_ATTR_PID])
6016 return -EINVAL;
6017
6018 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
6019
463d0183 6020 net = get_net_ns_by_pid(pid);
4c476991
JB
6021 if (IS_ERR(net))
6022 return PTR_ERR(net);
463d0183
JB
6023
6024 err = 0;
6025
6026 /* check if anything to do */
4c476991
JB
6027 if (!net_eq(wiphy_net(&rdev->wiphy), net))
6028 err = cfg80211_switch_netns(rdev, net);
463d0183 6029
463d0183 6030 put_net(net);
463d0183
JB
6031 return err;
6032}
6033
67fbb16b
SO
6034static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
6035{
4c476991 6036 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
6037 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
6038 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 6039 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
6040 struct cfg80211_pmksa pmksa;
6041
6042 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
6043
6044 if (!info->attrs[NL80211_ATTR_MAC])
6045 return -EINVAL;
6046
6047 if (!info->attrs[NL80211_ATTR_PMKID])
6048 return -EINVAL;
6049
67fbb16b
SO
6050 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
6051 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6052
074ac8df 6053 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6054 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6055 return -EOPNOTSUPP;
67fbb16b
SO
6056
6057 switch (info->genlhdr->cmd) {
6058 case NL80211_CMD_SET_PMKSA:
6059 rdev_ops = rdev->ops->set_pmksa;
6060 break;
6061 case NL80211_CMD_DEL_PMKSA:
6062 rdev_ops = rdev->ops->del_pmksa;
6063 break;
6064 default:
6065 WARN_ON(1);
6066 break;
6067 }
6068
4c476991
JB
6069 if (!rdev_ops)
6070 return -EOPNOTSUPP;
67fbb16b 6071
4c476991 6072 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
6073}
6074
6075static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
6076{
4c476991
JB
6077 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6078 struct net_device *dev = info->user_ptr[1];
67fbb16b 6079
074ac8df 6080 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6081 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6082 return -EOPNOTSUPP;
67fbb16b 6083
4c476991
JB
6084 if (!rdev->ops->flush_pmksa)
6085 return -EOPNOTSUPP;
67fbb16b 6086
e35e4d28 6087 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
6088}
6089
109086ce
AN
6090static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
6091{
6092 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6093 struct net_device *dev = info->user_ptr[1];
6094 u8 action_code, dialog_token;
6095 u16 status_code;
6096 u8 *peer;
6097
6098 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6099 !rdev->ops->tdls_mgmt)
6100 return -EOPNOTSUPP;
6101
6102 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
6103 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
6104 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
6105 !info->attrs[NL80211_ATTR_IE] ||
6106 !info->attrs[NL80211_ATTR_MAC])
6107 return -EINVAL;
6108
6109 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6110 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
6111 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
6112 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
6113
e35e4d28
HG
6114 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
6115 dialog_token, status_code,
6116 nla_data(info->attrs[NL80211_ATTR_IE]),
6117 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
6118}
6119
6120static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
6121{
6122 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6123 struct net_device *dev = info->user_ptr[1];
6124 enum nl80211_tdls_operation operation;
6125 u8 *peer;
6126
6127 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6128 !rdev->ops->tdls_oper)
6129 return -EOPNOTSUPP;
6130
6131 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
6132 !info->attrs[NL80211_ATTR_MAC])
6133 return -EINVAL;
6134
6135 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
6136 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6137
e35e4d28 6138 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
6139}
6140
9588bbd5
JM
6141static int nl80211_remain_on_channel(struct sk_buff *skb,
6142 struct genl_info *info)
6143{
4c476991 6144 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6145 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6146 struct cfg80211_chan_def chandef;
9588bbd5
JM
6147 struct sk_buff *msg;
6148 void *hdr;
6149 u64 cookie;
683b6d3b 6150 u32 duration;
9588bbd5
JM
6151 int err;
6152
6153 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6154 !info->attrs[NL80211_ATTR_DURATION])
6155 return -EINVAL;
6156
6157 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
6158
ebf348fc
JB
6159 if (!rdev->ops->remain_on_channel ||
6160 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
6161 return -EOPNOTSUPP;
6162
9588bbd5 6163 /*
ebf348fc
JB
6164 * We should be on that channel for at least a minimum amount of
6165 * time (10ms) but no longer than the driver supports.
9588bbd5 6166 */
ebf348fc 6167 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 6168 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
6169 return -EINVAL;
6170
683b6d3b
JB
6171 err = nl80211_parse_chandef(rdev, info, &chandef);
6172 if (err)
6173 return err;
9588bbd5
JM
6174
6175 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6176 if (!msg)
6177 return -ENOMEM;
9588bbd5 6178
15e47304 6179 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5
JM
6180 NL80211_CMD_REMAIN_ON_CHANNEL);
6181
6182 if (IS_ERR(hdr)) {
6183 err = PTR_ERR(hdr);
6184 goto free_msg;
6185 }
6186
683b6d3b
JB
6187 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
6188 duration, &cookie);
9588bbd5
JM
6189
6190 if (err)
6191 goto free_msg;
6192
9360ffd1
DM
6193 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6194 goto nla_put_failure;
9588bbd5
JM
6195
6196 genlmsg_end(msg, hdr);
4c476991
JB
6197
6198 return genlmsg_reply(msg, info);
9588bbd5
JM
6199
6200 nla_put_failure:
6201 err = -ENOBUFS;
6202 free_msg:
6203 nlmsg_free(msg);
9588bbd5
JM
6204 return err;
6205}
6206
6207static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
6208 struct genl_info *info)
6209{
4c476991 6210 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6211 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 6212 u64 cookie;
9588bbd5
JM
6213
6214 if (!info->attrs[NL80211_ATTR_COOKIE])
6215 return -EINVAL;
6216
4c476991
JB
6217 if (!rdev->ops->cancel_remain_on_channel)
6218 return -EOPNOTSUPP;
9588bbd5 6219
9588bbd5
JM
6220 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6221
e35e4d28 6222 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
6223}
6224
13ae75b1
JM
6225static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
6226 u8 *rates, u8 rates_len)
6227{
6228 u8 i;
6229 u32 mask = 0;
6230
6231 for (i = 0; i < rates_len; i++) {
6232 int rate = (rates[i] & 0x7f) * 5;
6233 int ridx;
6234 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
6235 struct ieee80211_rate *srate =
6236 &sband->bitrates[ridx];
6237 if (rate == srate->bitrate) {
6238 mask |= 1 << ridx;
6239 break;
6240 }
6241 }
6242 if (ridx == sband->n_bitrates)
6243 return 0; /* rate not found */
6244 }
6245
6246 return mask;
6247}
6248
24db78c0
SW
6249static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
6250 u8 *rates, u8 rates_len,
6251 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
6252{
6253 u8 i;
6254
6255 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
6256
6257 for (i = 0; i < rates_len; i++) {
6258 int ridx, rbit;
6259
6260 ridx = rates[i] / 8;
6261 rbit = BIT(rates[i] % 8);
6262
6263 /* check validity */
910570b5 6264 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
6265 return false;
6266
6267 /* check availability */
6268 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
6269 mcs[ridx] |= rbit;
6270 else
6271 return false;
6272 }
6273
6274 return true;
6275}
6276
b54452b0 6277static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
6278 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
6279 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
6280 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
6281 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
6282};
6283
6284static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
6285 struct genl_info *info)
6286{
6287 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 6288 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 6289 struct cfg80211_bitrate_mask mask;
4c476991
JB
6290 int rem, i;
6291 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
6292 struct nlattr *tx_rates;
6293 struct ieee80211_supported_band *sband;
6294
6295 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
6296 return -EINVAL;
6297
4c476991
JB
6298 if (!rdev->ops->set_bitrate_mask)
6299 return -EOPNOTSUPP;
13ae75b1
JM
6300
6301 memset(&mask, 0, sizeof(mask));
6302 /* Default to all rates enabled */
6303 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
6304 sband = rdev->wiphy.bands[i];
6305 mask.control[i].legacy =
6306 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
6307 if (sband)
6308 memcpy(mask.control[i].mcs,
6309 sband->ht_cap.mcs.rx_mask,
6310 sizeof(mask.control[i].mcs));
6311 else
6312 memset(mask.control[i].mcs, 0,
6313 sizeof(mask.control[i].mcs));
13ae75b1
JM
6314 }
6315
6316 /*
6317 * The nested attribute uses enum nl80211_band as the index. This maps
6318 * directly to the enum ieee80211_band values used in cfg80211.
6319 */
24db78c0 6320 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
6321 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
6322 {
6323 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
6324 if (band < 0 || band >= IEEE80211_NUM_BANDS)
6325 return -EINVAL;
13ae75b1 6326 sband = rdev->wiphy.bands[band];
4c476991
JB
6327 if (sband == NULL)
6328 return -EINVAL;
13ae75b1
JM
6329 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
6330 nla_len(tx_rates), nl80211_txattr_policy);
6331 if (tb[NL80211_TXRATE_LEGACY]) {
6332 mask.control[band].legacy = rateset_to_mask(
6333 sband,
6334 nla_data(tb[NL80211_TXRATE_LEGACY]),
6335 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
6336 if ((mask.control[band].legacy == 0) &&
6337 nla_len(tb[NL80211_TXRATE_LEGACY]))
6338 return -EINVAL;
24db78c0
SW
6339 }
6340 if (tb[NL80211_TXRATE_MCS]) {
6341 if (!ht_rateset_to_mask(
6342 sband,
6343 nla_data(tb[NL80211_TXRATE_MCS]),
6344 nla_len(tb[NL80211_TXRATE_MCS]),
6345 mask.control[band].mcs))
6346 return -EINVAL;
6347 }
6348
6349 if (mask.control[band].legacy == 0) {
6350 /* don't allow empty legacy rates if HT
6351 * is not even supported. */
6352 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
6353 return -EINVAL;
6354
6355 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
6356 if (mask.control[band].mcs[i])
6357 break;
6358
6359 /* legacy and mcs rates may not be both empty */
6360 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 6361 return -EINVAL;
13ae75b1
JM
6362 }
6363 }
6364
e35e4d28 6365 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
6366}
6367
2e161f78 6368static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6369{
4c476991 6370 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6371 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 6372 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
6373
6374 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
6375 return -EINVAL;
6376
2e161f78
JB
6377 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
6378 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 6379
71bbc994
JB
6380 switch (wdev->iftype) {
6381 case NL80211_IFTYPE_STATION:
6382 case NL80211_IFTYPE_ADHOC:
6383 case NL80211_IFTYPE_P2P_CLIENT:
6384 case NL80211_IFTYPE_AP:
6385 case NL80211_IFTYPE_AP_VLAN:
6386 case NL80211_IFTYPE_MESH_POINT:
6387 case NL80211_IFTYPE_P2P_GO:
98104fde 6388 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6389 break;
6390 default:
4c476991 6391 return -EOPNOTSUPP;
71bbc994 6392 }
026331c4
JM
6393
6394 /* not much point in registering if we can't reply */
4c476991
JB
6395 if (!rdev->ops->mgmt_tx)
6396 return -EOPNOTSUPP;
026331c4 6397
15e47304 6398 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
6399 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
6400 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
6401}
6402
2e161f78 6403static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6404{
4c476991 6405 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6406 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6407 struct cfg80211_chan_def chandef;
026331c4 6408 int err;
d64d373f 6409 void *hdr = NULL;
026331c4 6410 u64 cookie;
e247bd90 6411 struct sk_buff *msg = NULL;
f7ca38df 6412 unsigned int wait = 0;
e247bd90
JB
6413 bool offchan, no_cck, dont_wait_for_ack;
6414
6415 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 6416
683b6d3b 6417 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
6418 return -EINVAL;
6419
4c476991
JB
6420 if (!rdev->ops->mgmt_tx)
6421 return -EOPNOTSUPP;
026331c4 6422
71bbc994
JB
6423 switch (wdev->iftype) {
6424 case NL80211_IFTYPE_STATION:
6425 case NL80211_IFTYPE_ADHOC:
6426 case NL80211_IFTYPE_P2P_CLIENT:
6427 case NL80211_IFTYPE_AP:
6428 case NL80211_IFTYPE_AP_VLAN:
6429 case NL80211_IFTYPE_MESH_POINT:
6430 case NL80211_IFTYPE_P2P_GO:
98104fde 6431 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6432 break;
6433 default:
4c476991 6434 return -EOPNOTSUPP;
71bbc994 6435 }
026331c4 6436
f7ca38df 6437 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 6438 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
6439 return -EINVAL;
6440 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
6441
6442 /*
6443 * We should wait on the channel for at least a minimum amount
6444 * of time (10ms) but no longer than the driver supports.
6445 */
6446 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
6447 wait > rdev->wiphy.max_remain_on_channel_duration)
6448 return -EINVAL;
6449
f7ca38df
JB
6450 }
6451
f7ca38df
JB
6452 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
6453
7c4ef712
JB
6454 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
6455 return -EINVAL;
6456
e9f935e3
RM
6457 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6458
683b6d3b
JB
6459 err = nl80211_parse_chandef(rdev, info, &chandef);
6460 if (err)
6461 return err;
026331c4 6462
e247bd90
JB
6463 if (!dont_wait_for_ack) {
6464 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6465 if (!msg)
6466 return -ENOMEM;
026331c4 6467
15e47304 6468 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 6469 NL80211_CMD_FRAME);
026331c4 6470
e247bd90
JB
6471 if (IS_ERR(hdr)) {
6472 err = PTR_ERR(hdr);
6473 goto free_msg;
6474 }
026331c4 6475 }
e247bd90 6476
683b6d3b 6477 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
6478 nla_data(info->attrs[NL80211_ATTR_FRAME]),
6479 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 6480 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
6481 if (err)
6482 goto free_msg;
6483
e247bd90 6484 if (msg) {
9360ffd1
DM
6485 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6486 goto nla_put_failure;
026331c4 6487
e247bd90
JB
6488 genlmsg_end(msg, hdr);
6489 return genlmsg_reply(msg, info);
6490 }
6491
6492 return 0;
026331c4
JM
6493
6494 nla_put_failure:
6495 err = -ENOBUFS;
6496 free_msg:
6497 nlmsg_free(msg);
026331c4
JM
6498 return err;
6499}
6500
f7ca38df
JB
6501static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
6502{
6503 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6504 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
6505 u64 cookie;
6506
6507 if (!info->attrs[NL80211_ATTR_COOKIE])
6508 return -EINVAL;
6509
6510 if (!rdev->ops->mgmt_tx_cancel_wait)
6511 return -EOPNOTSUPP;
6512
71bbc994
JB
6513 switch (wdev->iftype) {
6514 case NL80211_IFTYPE_STATION:
6515 case NL80211_IFTYPE_ADHOC:
6516 case NL80211_IFTYPE_P2P_CLIENT:
6517 case NL80211_IFTYPE_AP:
6518 case NL80211_IFTYPE_AP_VLAN:
6519 case NL80211_IFTYPE_P2P_GO:
98104fde 6520 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6521 break;
6522 default:
f7ca38df 6523 return -EOPNOTSUPP;
71bbc994 6524 }
f7ca38df
JB
6525
6526 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6527
e35e4d28 6528 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
6529}
6530
ffb9eb3d
KV
6531static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
6532{
4c476991 6533 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 6534 struct wireless_dev *wdev;
4c476991 6535 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6536 u8 ps_state;
6537 bool state;
6538 int err;
6539
4c476991
JB
6540 if (!info->attrs[NL80211_ATTR_PS_STATE])
6541 return -EINVAL;
ffb9eb3d
KV
6542
6543 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
6544
4c476991
JB
6545 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
6546 return -EINVAL;
ffb9eb3d
KV
6547
6548 wdev = dev->ieee80211_ptr;
6549
4c476991
JB
6550 if (!rdev->ops->set_power_mgmt)
6551 return -EOPNOTSUPP;
ffb9eb3d
KV
6552
6553 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
6554
6555 if (state == wdev->ps)
4c476991 6556 return 0;
ffb9eb3d 6557
e35e4d28 6558 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
6559 if (!err)
6560 wdev->ps = state;
ffb9eb3d
KV
6561 return err;
6562}
6563
6564static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
6565{
4c476991 6566 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
6567 enum nl80211_ps_state ps_state;
6568 struct wireless_dev *wdev;
4c476991 6569 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6570 struct sk_buff *msg;
6571 void *hdr;
6572 int err;
6573
ffb9eb3d
KV
6574 wdev = dev->ieee80211_ptr;
6575
4c476991
JB
6576 if (!rdev->ops->set_power_mgmt)
6577 return -EOPNOTSUPP;
ffb9eb3d
KV
6578
6579 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6580 if (!msg)
6581 return -ENOMEM;
ffb9eb3d 6582
15e47304 6583 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
6584 NL80211_CMD_GET_POWER_SAVE);
6585 if (!hdr) {
4c476991 6586 err = -ENOBUFS;
ffb9eb3d
KV
6587 goto free_msg;
6588 }
6589
6590 if (wdev->ps)
6591 ps_state = NL80211_PS_ENABLED;
6592 else
6593 ps_state = NL80211_PS_DISABLED;
6594
9360ffd1
DM
6595 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6596 goto nla_put_failure;
ffb9eb3d
KV
6597
6598 genlmsg_end(msg, hdr);
4c476991 6599 return genlmsg_reply(msg, info);
ffb9eb3d 6600
4c476991 6601 nla_put_failure:
ffb9eb3d 6602 err = -ENOBUFS;
4c476991 6603 free_msg:
ffb9eb3d 6604 nlmsg_free(msg);
ffb9eb3d
KV
6605 return err;
6606}
6607
d6dc1a38
JO
6608static struct nla_policy
6609nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6610 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6611 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6612 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
6613 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
6614 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
6615 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
6616};
6617
84f10708 6618static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 6619 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
6620{
6621 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6622 struct wireless_dev *wdev;
6623 struct net_device *dev = info->user_ptr[1];
6624
d9d8b019 6625 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
6626 return -EINVAL;
6627
6628 wdev = dev->ieee80211_ptr;
6629
6630 if (!rdev->ops->set_cqm_txe_config)
6631 return -EOPNOTSUPP;
6632
6633 if (wdev->iftype != NL80211_IFTYPE_STATION &&
6634 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6635 return -EOPNOTSUPP;
6636
e35e4d28 6637 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
6638}
6639
d6dc1a38
JO
6640static int nl80211_set_cqm_rssi(struct genl_info *info,
6641 s32 threshold, u32 hysteresis)
6642{
4c476991 6643 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6644 struct wireless_dev *wdev;
4c476991 6645 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6646
6647 if (threshold > 0)
6648 return -EINVAL;
6649
d6dc1a38
JO
6650 wdev = dev->ieee80211_ptr;
6651
4c476991
JB
6652 if (!rdev->ops->set_cqm_rssi_config)
6653 return -EOPNOTSUPP;
d6dc1a38 6654
074ac8df 6655 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6656 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6657 return -EOPNOTSUPP;
d6dc1a38 6658
e35e4d28 6659 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
6660}
6661
6662static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6663{
6664 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6665 struct nlattr *cqm;
6666 int err;
6667
6668 cqm = info->attrs[NL80211_ATTR_CQM];
6669 if (!cqm) {
6670 err = -EINVAL;
6671 goto out;
6672 }
6673
6674 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6675 nl80211_attr_cqm_policy);
6676 if (err)
6677 goto out;
6678
6679 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6680 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6681 s32 threshold;
6682 u32 hysteresis;
6683 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6684 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6685 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
84f10708
TP
6686 } else if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
6687 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
6688 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
6689 u32 rate, pkts, intvl;
6690 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
6691 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
6692 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
6693 err = nl80211_set_cqm_txe(info, rate, pkts, intvl);
d6dc1a38
JO
6694 } else
6695 err = -EINVAL;
6696
6697out:
6698 return err;
6699}
6700
29cbe68c
JB
6701static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6702{
6703 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6704 struct net_device *dev = info->user_ptr[1];
6705 struct mesh_config cfg;
c80d545d 6706 struct mesh_setup setup;
29cbe68c
JB
6707 int err;
6708
6709 /* start with default */
6710 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6711 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6712
24bdd9f4 6713 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6714 /* and parse parameters if given */
24bdd9f4 6715 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6716 if (err)
6717 return err;
6718 }
6719
6720 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6721 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6722 return -EINVAL;
6723
c80d545d
JC
6724 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6725 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6726
4bb62344
CYY
6727 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6728 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6729 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6730 return -EINVAL;
6731
9bdbf04d
MP
6732 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6733 setup.beacon_interval =
6734 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6735 if (setup.beacon_interval < 10 ||
6736 setup.beacon_interval > 10000)
6737 return -EINVAL;
6738 }
6739
6740 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
6741 setup.dtim_period =
6742 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
6743 if (setup.dtim_period < 1 || setup.dtim_period > 100)
6744 return -EINVAL;
6745 }
6746
c80d545d
JC
6747 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6748 /* parse additional setup parameters if given */
6749 err = nl80211_parse_mesh_setup(info, &setup);
6750 if (err)
6751 return err;
6752 }
6753
cc1d2806 6754 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
6755 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
6756 if (err)
6757 return err;
cc1d2806
JB
6758 } else {
6759 /* cfg80211_join_mesh() will sort it out */
683b6d3b 6760 setup.chandef.chan = NULL;
cc1d2806
JB
6761 }
6762
c80d545d 6763 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6764}
6765
6766static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6767{
6768 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6769 struct net_device *dev = info->user_ptr[1];
6770
6771 return cfg80211_leave_mesh(rdev, dev);
6772}
6773
dfb89c56 6774#ifdef CONFIG_PM
ff1b6e69
JB
6775static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6776{
6777 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6778 struct sk_buff *msg;
6779 void *hdr;
6780
6781 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6782 return -EOPNOTSUPP;
6783
6784 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6785 if (!msg)
6786 return -ENOMEM;
6787
15e47304 6788 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
6789 NL80211_CMD_GET_WOWLAN);
6790 if (!hdr)
6791 goto nla_put_failure;
6792
6793 if (rdev->wowlan) {
6794 struct nlattr *nl_wowlan;
6795
6796 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6797 if (!nl_wowlan)
6798 goto nla_put_failure;
6799
9360ffd1
DM
6800 if ((rdev->wowlan->any &&
6801 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6802 (rdev->wowlan->disconnect &&
6803 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6804 (rdev->wowlan->magic_pkt &&
6805 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6806 (rdev->wowlan->gtk_rekey_failure &&
6807 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6808 (rdev->wowlan->eap_identity_req &&
6809 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6810 (rdev->wowlan->four_way_handshake &&
6811 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6812 (rdev->wowlan->rfkill_release &&
6813 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6814 goto nla_put_failure;
ff1b6e69
JB
6815 if (rdev->wowlan->n_patterns) {
6816 struct nlattr *nl_pats, *nl_pat;
6817 int i, pat_len;
6818
6819 nl_pats = nla_nest_start(msg,
6820 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6821 if (!nl_pats)
6822 goto nla_put_failure;
6823
6824 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6825 nl_pat = nla_nest_start(msg, i + 1);
6826 if (!nl_pat)
6827 goto nla_put_failure;
6828 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6829 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6830 DIV_ROUND_UP(pat_len, 8),
6831 rdev->wowlan->patterns[i].mask) ||
6832 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6833 pat_len,
6834 rdev->wowlan->patterns[i].pattern))
6835 goto nla_put_failure;
ff1b6e69
JB
6836 nla_nest_end(msg, nl_pat);
6837 }
6838 nla_nest_end(msg, nl_pats);
6839 }
6840
6841 nla_nest_end(msg, nl_wowlan);
6842 }
6843
6844 genlmsg_end(msg, hdr);
6845 return genlmsg_reply(msg, info);
6846
6847nla_put_failure:
6848 nlmsg_free(msg);
6849 return -ENOBUFS;
6850}
6851
6852static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6853{
6854 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6855 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 6856 struct cfg80211_wowlan new_triggers = {};
ae33bd81 6857 struct cfg80211_wowlan *ntrig;
ff1b6e69
JB
6858 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6859 int err, i;
6d52563f 6860 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6861
6862 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6863 return -EOPNOTSUPP;
6864
ae33bd81
JB
6865 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
6866 cfg80211_rdev_free_wowlan(rdev);
6867 rdev->wowlan = NULL;
6868 goto set_wakeup;
6869 }
ff1b6e69
JB
6870
6871 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6872 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6873 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6874 nl80211_wowlan_policy);
6875 if (err)
6876 return err;
6877
6878 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6879 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6880 return -EINVAL;
6881 new_triggers.any = true;
6882 }
6883
6884 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6885 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6886 return -EINVAL;
6887 new_triggers.disconnect = true;
6888 }
6889
6890 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6891 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6892 return -EINVAL;
6893 new_triggers.magic_pkt = true;
6894 }
6895
77dbbb13
JB
6896 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6897 return -EINVAL;
6898
6899 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6900 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6901 return -EINVAL;
6902 new_triggers.gtk_rekey_failure = true;
6903 }
6904
6905 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6906 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6907 return -EINVAL;
6908 new_triggers.eap_identity_req = true;
6909 }
6910
6911 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6912 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6913 return -EINVAL;
6914 new_triggers.four_way_handshake = true;
6915 }
6916
6917 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6918 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6919 return -EINVAL;
6920 new_triggers.rfkill_release = true;
6921 }
6922
ff1b6e69
JB
6923 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6924 struct nlattr *pat;
6925 int n_patterns = 0;
6926 int rem, pat_len, mask_len;
6927 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6928
6929 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6930 rem)
6931 n_patterns++;
6932 if (n_patterns > wowlan->n_patterns)
6933 return -EINVAL;
6934
6935 new_triggers.patterns = kcalloc(n_patterns,
6936 sizeof(new_triggers.patterns[0]),
6937 GFP_KERNEL);
6938 if (!new_triggers.patterns)
6939 return -ENOMEM;
6940
6941 new_triggers.n_patterns = n_patterns;
6942 i = 0;
6943
6944 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6945 rem) {
6946 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6947 nla_data(pat), nla_len(pat), NULL);
6948 err = -EINVAL;
6949 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6950 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6951 goto error;
6952 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6953 mask_len = DIV_ROUND_UP(pat_len, 8);
6954 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6955 mask_len)
6956 goto error;
6957 if (pat_len > wowlan->pattern_max_len ||
6958 pat_len < wowlan->pattern_min_len)
6959 goto error;
6960
6961 new_triggers.patterns[i].mask =
6962 kmalloc(mask_len + pat_len, GFP_KERNEL);
6963 if (!new_triggers.patterns[i].mask) {
6964 err = -ENOMEM;
6965 goto error;
6966 }
6967 new_triggers.patterns[i].pattern =
6968 new_triggers.patterns[i].mask + mask_len;
6969 memcpy(new_triggers.patterns[i].mask,
6970 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6971 mask_len);
6972 new_triggers.patterns[i].pattern_len = pat_len;
6973 memcpy(new_triggers.patterns[i].pattern,
6974 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6975 pat_len);
6976 i++;
6977 }
6978 }
6979
ae33bd81
JB
6980 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
6981 if (!ntrig) {
6982 err = -ENOMEM;
6983 goto error;
ff1b6e69 6984 }
ae33bd81
JB
6985 cfg80211_rdev_free_wowlan(rdev);
6986 rdev->wowlan = ntrig;
ff1b6e69 6987
ae33bd81 6988 set_wakeup:
6d52563f 6989 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
e35e4d28 6990 rdev_set_wakeup(rdev, rdev->wowlan);
6d52563f 6991
ff1b6e69
JB
6992 return 0;
6993 error:
6994 for (i = 0; i < new_triggers.n_patterns; i++)
6995 kfree(new_triggers.patterns[i].mask);
6996 kfree(new_triggers.patterns);
6997 return err;
6998}
dfb89c56 6999#endif
ff1b6e69 7000
e5497d76
JB
7001static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
7002{
7003 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7004 struct net_device *dev = info->user_ptr[1];
7005 struct wireless_dev *wdev = dev->ieee80211_ptr;
7006 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
7007 struct cfg80211_gtk_rekey_data rekey_data;
7008 int err;
7009
7010 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
7011 return -EINVAL;
7012
7013 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
7014 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
7015 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
7016 nl80211_rekey_policy);
7017 if (err)
7018 return err;
7019
7020 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
7021 return -ERANGE;
7022 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
7023 return -ERANGE;
7024 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
7025 return -ERANGE;
7026
7027 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
7028 NL80211_KEK_LEN);
7029 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
7030 NL80211_KCK_LEN);
7031 memcpy(rekey_data.replay_ctr,
7032 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
7033 NL80211_REPLAY_CTR_LEN);
7034
7035 wdev_lock(wdev);
7036 if (!wdev->current_bss) {
7037 err = -ENOTCONN;
7038 goto out;
7039 }
7040
7041 if (!rdev->ops->set_rekey_data) {
7042 err = -EOPNOTSUPP;
7043 goto out;
7044 }
7045
e35e4d28 7046 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
7047 out:
7048 wdev_unlock(wdev);
7049 return err;
7050}
7051
28946da7
JB
7052static int nl80211_register_unexpected_frame(struct sk_buff *skb,
7053 struct genl_info *info)
7054{
7055 struct net_device *dev = info->user_ptr[1];
7056 struct wireless_dev *wdev = dev->ieee80211_ptr;
7057
7058 if (wdev->iftype != NL80211_IFTYPE_AP &&
7059 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7060 return -EINVAL;
7061
15e47304 7062 if (wdev->ap_unexpected_nlportid)
28946da7
JB
7063 return -EBUSY;
7064
15e47304 7065 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
7066 return 0;
7067}
7068
7f6cf311
JB
7069static int nl80211_probe_client(struct sk_buff *skb,
7070 struct genl_info *info)
7071{
7072 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7073 struct net_device *dev = info->user_ptr[1];
7074 struct wireless_dev *wdev = dev->ieee80211_ptr;
7075 struct sk_buff *msg;
7076 void *hdr;
7077 const u8 *addr;
7078 u64 cookie;
7079 int err;
7080
7081 if (wdev->iftype != NL80211_IFTYPE_AP &&
7082 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7083 return -EOPNOTSUPP;
7084
7085 if (!info->attrs[NL80211_ATTR_MAC])
7086 return -EINVAL;
7087
7088 if (!rdev->ops->probe_client)
7089 return -EOPNOTSUPP;
7090
7091 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7092 if (!msg)
7093 return -ENOMEM;
7094
15e47304 7095 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311
JB
7096 NL80211_CMD_PROBE_CLIENT);
7097
7098 if (IS_ERR(hdr)) {
7099 err = PTR_ERR(hdr);
7100 goto free_msg;
7101 }
7102
7103 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7104
e35e4d28 7105 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
7106 if (err)
7107 goto free_msg;
7108
9360ffd1
DM
7109 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7110 goto nla_put_failure;
7f6cf311
JB
7111
7112 genlmsg_end(msg, hdr);
7113
7114 return genlmsg_reply(msg, info);
7115
7116 nla_put_failure:
7117 err = -ENOBUFS;
7118 free_msg:
7119 nlmsg_free(msg);
7120 return err;
7121}
7122
5e760230
JB
7123static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
7124{
7125 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
7126 struct cfg80211_beacon_registration *reg, *nreg;
7127 int rv;
5e760230
JB
7128
7129 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
7130 return -EOPNOTSUPP;
7131
37c73b5f
BG
7132 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
7133 if (!nreg)
7134 return -ENOMEM;
7135
7136 /* First, check if already registered. */
7137 spin_lock_bh(&rdev->beacon_registrations_lock);
7138 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
7139 if (reg->nlportid == info->snd_portid) {
7140 rv = -EALREADY;
7141 goto out_err;
7142 }
7143 }
7144 /* Add it to the list */
7145 nreg->nlportid = info->snd_portid;
7146 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 7147
37c73b5f 7148 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
7149
7150 return 0;
37c73b5f
BG
7151out_err:
7152 spin_unlock_bh(&rdev->beacon_registrations_lock);
7153 kfree(nreg);
7154 return rv;
5e760230
JB
7155}
7156
98104fde
JB
7157static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
7158{
7159 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7160 struct wireless_dev *wdev = info->user_ptr[1];
7161 int err;
7162
7163 if (!rdev->ops->start_p2p_device)
7164 return -EOPNOTSUPP;
7165
7166 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7167 return -EOPNOTSUPP;
7168
7169 if (wdev->p2p_started)
7170 return 0;
7171
7172 mutex_lock(&rdev->devlist_mtx);
7173 err = cfg80211_can_add_interface(rdev, wdev->iftype);
7174 mutex_unlock(&rdev->devlist_mtx);
7175 if (err)
7176 return err;
7177
eeb126e9 7178 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
7179 if (err)
7180 return err;
7181
7182 wdev->p2p_started = true;
7183 mutex_lock(&rdev->devlist_mtx);
7184 rdev->opencount++;
7185 mutex_unlock(&rdev->devlist_mtx);
7186
7187 return 0;
7188}
7189
7190static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
7191{
7192 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7193 struct wireless_dev *wdev = info->user_ptr[1];
7194
7195 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7196 return -EOPNOTSUPP;
7197
7198 if (!rdev->ops->stop_p2p_device)
7199 return -EOPNOTSUPP;
7200
7201 if (!wdev->p2p_started)
7202 return 0;
7203
eeb126e9 7204 rdev_stop_p2p_device(rdev, wdev);
98104fde
JB
7205 wdev->p2p_started = false;
7206
7207 mutex_lock(&rdev->devlist_mtx);
7208 rdev->opencount--;
7209 mutex_unlock(&rdev->devlist_mtx);
7210
7211 if (WARN_ON(rdev->scan_req && rdev->scan_req->wdev == wdev)) {
7212 rdev->scan_req->aborted = true;
7213 ___cfg80211_scan_done(rdev, true);
7214 }
7215
7216 return 0;
7217}
7218
4c476991
JB
7219#define NL80211_FLAG_NEED_WIPHY 0x01
7220#define NL80211_FLAG_NEED_NETDEV 0x02
7221#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
7222#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
7223#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
7224 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 7225#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 7226/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
7227#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
7228 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
7229
7230static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
7231 struct genl_info *info)
7232{
7233 struct cfg80211_registered_device *rdev;
89a54e48 7234 struct wireless_dev *wdev;
4c476991 7235 struct net_device *dev;
4c476991
JB
7236 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
7237
7238 if (rtnl)
7239 rtnl_lock();
7240
7241 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 7242 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
7243 if (IS_ERR(rdev)) {
7244 if (rtnl)
7245 rtnl_unlock();
7246 return PTR_ERR(rdev);
7247 }
7248 info->user_ptr[0] = rdev;
1bf614ef
JB
7249 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
7250 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
89a54e48
JB
7251 mutex_lock(&cfg80211_mutex);
7252 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
7253 info->attrs);
7254 if (IS_ERR(wdev)) {
7255 mutex_unlock(&cfg80211_mutex);
4c476991
JB
7256 if (rtnl)
7257 rtnl_unlock();
89a54e48 7258 return PTR_ERR(wdev);
4c476991 7259 }
89a54e48 7260
89a54e48
JB
7261 dev = wdev->netdev;
7262 rdev = wiphy_to_dev(wdev->wiphy);
7263
1bf614ef
JB
7264 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
7265 if (!dev) {
7266 mutex_unlock(&cfg80211_mutex);
7267 if (rtnl)
7268 rtnl_unlock();
7269 return -EINVAL;
7270 }
7271
7272 info->user_ptr[1] = dev;
7273 } else {
7274 info->user_ptr[1] = wdev;
41265714 7275 }
1bf614ef
JB
7276
7277 if (dev) {
7278 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
7279 !netif_running(dev)) {
7280 mutex_unlock(&cfg80211_mutex);
7281 if (rtnl)
7282 rtnl_unlock();
7283 return -ENETDOWN;
7284 }
7285
7286 dev_hold(dev);
98104fde
JB
7287 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
7288 if (!wdev->p2p_started) {
7289 mutex_unlock(&cfg80211_mutex);
7290 if (rtnl)
7291 rtnl_unlock();
7292 return -ENETDOWN;
7293 }
41265714 7294 }
89a54e48 7295
89a54e48
JB
7296 cfg80211_lock_rdev(rdev);
7297
7298 mutex_unlock(&cfg80211_mutex);
7299
4c476991 7300 info->user_ptr[0] = rdev;
4c476991
JB
7301 }
7302
7303 return 0;
7304}
7305
7306static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
7307 struct genl_info *info)
7308{
7309 if (info->user_ptr[0])
7310 cfg80211_unlock_rdev(info->user_ptr[0]);
1bf614ef
JB
7311 if (info->user_ptr[1]) {
7312 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
7313 struct wireless_dev *wdev = info->user_ptr[1];
7314
7315 if (wdev->netdev)
7316 dev_put(wdev->netdev);
7317 } else {
7318 dev_put(info->user_ptr[1]);
7319 }
7320 }
4c476991
JB
7321 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
7322 rtnl_unlock();
7323}
7324
55682965
JB
7325static struct genl_ops nl80211_ops[] = {
7326 {
7327 .cmd = NL80211_CMD_GET_WIPHY,
7328 .doit = nl80211_get_wiphy,
7329 .dumpit = nl80211_dump_wiphy,
7330 .policy = nl80211_policy,
7331 /* can be retrieved by unprivileged users */
4c476991 7332 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
7333 },
7334 {
7335 .cmd = NL80211_CMD_SET_WIPHY,
7336 .doit = nl80211_set_wiphy,
7337 .policy = nl80211_policy,
7338 .flags = GENL_ADMIN_PERM,
4c476991 7339 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
7340 },
7341 {
7342 .cmd = NL80211_CMD_GET_INTERFACE,
7343 .doit = nl80211_get_interface,
7344 .dumpit = nl80211_dump_interface,
7345 .policy = nl80211_policy,
7346 /* can be retrieved by unprivileged users */
72fb2abc 7347 .internal_flags = NL80211_FLAG_NEED_WDEV,
55682965
JB
7348 },
7349 {
7350 .cmd = NL80211_CMD_SET_INTERFACE,
7351 .doit = nl80211_set_interface,
7352 .policy = nl80211_policy,
7353 .flags = GENL_ADMIN_PERM,
4c476991
JB
7354 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7355 NL80211_FLAG_NEED_RTNL,
55682965
JB
7356 },
7357 {
7358 .cmd = NL80211_CMD_NEW_INTERFACE,
7359 .doit = nl80211_new_interface,
7360 .policy = nl80211_policy,
7361 .flags = GENL_ADMIN_PERM,
4c476991
JB
7362 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7363 NL80211_FLAG_NEED_RTNL,
55682965
JB
7364 },
7365 {
7366 .cmd = NL80211_CMD_DEL_INTERFACE,
7367 .doit = nl80211_del_interface,
7368 .policy = nl80211_policy,
41ade00f 7369 .flags = GENL_ADMIN_PERM,
84efbb84 7370 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7371 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7372 },
7373 {
7374 .cmd = NL80211_CMD_GET_KEY,
7375 .doit = nl80211_get_key,
7376 .policy = nl80211_policy,
7377 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7378 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7379 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7380 },
7381 {
7382 .cmd = NL80211_CMD_SET_KEY,
7383 .doit = nl80211_set_key,
7384 .policy = nl80211_policy,
7385 .flags = GENL_ADMIN_PERM,
41265714 7386 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7387 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7388 },
7389 {
7390 .cmd = NL80211_CMD_NEW_KEY,
7391 .doit = nl80211_new_key,
7392 .policy = nl80211_policy,
7393 .flags = GENL_ADMIN_PERM,
41265714 7394 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7395 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7396 },
7397 {
7398 .cmd = NL80211_CMD_DEL_KEY,
7399 .doit = nl80211_del_key,
7400 .policy = nl80211_policy,
55682965 7401 .flags = GENL_ADMIN_PERM,
41265714 7402 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7403 NL80211_FLAG_NEED_RTNL,
55682965 7404 },
ed1b6cc7
JB
7405 {
7406 .cmd = NL80211_CMD_SET_BEACON,
7407 .policy = nl80211_policy,
7408 .flags = GENL_ADMIN_PERM,
8860020e 7409 .doit = nl80211_set_beacon,
2b5f8b0b 7410 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7411 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7412 },
7413 {
8860020e 7414 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
7415 .policy = nl80211_policy,
7416 .flags = GENL_ADMIN_PERM,
8860020e 7417 .doit = nl80211_start_ap,
2b5f8b0b 7418 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7419 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7420 },
7421 {
8860020e 7422 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
7423 .policy = nl80211_policy,
7424 .flags = GENL_ADMIN_PERM,
8860020e 7425 .doit = nl80211_stop_ap,
2b5f8b0b 7426 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7427 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 7428 },
5727ef1b
JB
7429 {
7430 .cmd = NL80211_CMD_GET_STATION,
7431 .doit = nl80211_get_station,
2ec600d6 7432 .dumpit = nl80211_dump_station,
5727ef1b 7433 .policy = nl80211_policy,
4c476991
JB
7434 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7435 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7436 },
7437 {
7438 .cmd = NL80211_CMD_SET_STATION,
7439 .doit = nl80211_set_station,
7440 .policy = nl80211_policy,
7441 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7442 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7443 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7444 },
7445 {
7446 .cmd = NL80211_CMD_NEW_STATION,
7447 .doit = nl80211_new_station,
7448 .policy = nl80211_policy,
7449 .flags = GENL_ADMIN_PERM,
41265714 7450 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7451 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7452 },
7453 {
7454 .cmd = NL80211_CMD_DEL_STATION,
7455 .doit = nl80211_del_station,
7456 .policy = nl80211_policy,
2ec600d6 7457 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7458 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7459 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7460 },
7461 {
7462 .cmd = NL80211_CMD_GET_MPATH,
7463 .doit = nl80211_get_mpath,
7464 .dumpit = nl80211_dump_mpath,
7465 .policy = nl80211_policy,
7466 .flags = GENL_ADMIN_PERM,
41265714 7467 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7468 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7469 },
7470 {
7471 .cmd = NL80211_CMD_SET_MPATH,
7472 .doit = nl80211_set_mpath,
7473 .policy = nl80211_policy,
7474 .flags = GENL_ADMIN_PERM,
41265714 7475 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7476 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7477 },
7478 {
7479 .cmd = NL80211_CMD_NEW_MPATH,
7480 .doit = nl80211_new_mpath,
7481 .policy = nl80211_policy,
7482 .flags = GENL_ADMIN_PERM,
41265714 7483 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7484 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7485 },
7486 {
7487 .cmd = NL80211_CMD_DEL_MPATH,
7488 .doit = nl80211_del_mpath,
7489 .policy = nl80211_policy,
9f1ba906 7490 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7491 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7492 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
7493 },
7494 {
7495 .cmd = NL80211_CMD_SET_BSS,
7496 .doit = nl80211_set_bss,
7497 .policy = nl80211_policy,
b2e1b302 7498 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7499 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7500 NL80211_FLAG_NEED_RTNL,
b2e1b302 7501 },
f130347c
LR
7502 {
7503 .cmd = NL80211_CMD_GET_REG,
7504 .doit = nl80211_get_reg,
7505 .policy = nl80211_policy,
7506 /* can be retrieved by unprivileged users */
7507 },
b2e1b302
LR
7508 {
7509 .cmd = NL80211_CMD_SET_REG,
7510 .doit = nl80211_set_reg,
7511 .policy = nl80211_policy,
7512 .flags = GENL_ADMIN_PERM,
7513 },
7514 {
7515 .cmd = NL80211_CMD_REQ_SET_REG,
7516 .doit = nl80211_req_set_reg,
7517 .policy = nl80211_policy,
93da9cc1 7518 .flags = GENL_ADMIN_PERM,
7519 },
7520 {
24bdd9f4
JC
7521 .cmd = NL80211_CMD_GET_MESH_CONFIG,
7522 .doit = nl80211_get_mesh_config,
93da9cc1 7523 .policy = nl80211_policy,
7524 /* can be retrieved by unprivileged users */
2b5f8b0b 7525 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7526 NL80211_FLAG_NEED_RTNL,
93da9cc1 7527 },
7528 {
24bdd9f4
JC
7529 .cmd = NL80211_CMD_SET_MESH_CONFIG,
7530 .doit = nl80211_update_mesh_config,
93da9cc1 7531 .policy = nl80211_policy,
9aed3cc1 7532 .flags = GENL_ADMIN_PERM,
29cbe68c 7533 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7534 NL80211_FLAG_NEED_RTNL,
9aed3cc1 7535 },
2a519311
JB
7536 {
7537 .cmd = NL80211_CMD_TRIGGER_SCAN,
7538 .doit = nl80211_trigger_scan,
7539 .policy = nl80211_policy,
7540 .flags = GENL_ADMIN_PERM,
fd014284 7541 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7542 NL80211_FLAG_NEED_RTNL,
2a519311
JB
7543 },
7544 {
7545 .cmd = NL80211_CMD_GET_SCAN,
7546 .policy = nl80211_policy,
7547 .dumpit = nl80211_dump_scan,
7548 },
807f8a8c
LC
7549 {
7550 .cmd = NL80211_CMD_START_SCHED_SCAN,
7551 .doit = nl80211_start_sched_scan,
7552 .policy = nl80211_policy,
7553 .flags = GENL_ADMIN_PERM,
7554 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7555 NL80211_FLAG_NEED_RTNL,
7556 },
7557 {
7558 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
7559 .doit = nl80211_stop_sched_scan,
7560 .policy = nl80211_policy,
7561 .flags = GENL_ADMIN_PERM,
7562 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7563 NL80211_FLAG_NEED_RTNL,
7564 },
636a5d36
JM
7565 {
7566 .cmd = NL80211_CMD_AUTHENTICATE,
7567 .doit = nl80211_authenticate,
7568 .policy = nl80211_policy,
7569 .flags = GENL_ADMIN_PERM,
41265714 7570 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7571 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7572 },
7573 {
7574 .cmd = NL80211_CMD_ASSOCIATE,
7575 .doit = nl80211_associate,
7576 .policy = nl80211_policy,
7577 .flags = GENL_ADMIN_PERM,
41265714 7578 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7579 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7580 },
7581 {
7582 .cmd = NL80211_CMD_DEAUTHENTICATE,
7583 .doit = nl80211_deauthenticate,
7584 .policy = nl80211_policy,
7585 .flags = GENL_ADMIN_PERM,
41265714 7586 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7587 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7588 },
7589 {
7590 .cmd = NL80211_CMD_DISASSOCIATE,
7591 .doit = nl80211_disassociate,
7592 .policy = nl80211_policy,
7593 .flags = GENL_ADMIN_PERM,
41265714 7594 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7595 NL80211_FLAG_NEED_RTNL,
636a5d36 7596 },
04a773ad
JB
7597 {
7598 .cmd = NL80211_CMD_JOIN_IBSS,
7599 .doit = nl80211_join_ibss,
7600 .policy = nl80211_policy,
7601 .flags = GENL_ADMIN_PERM,
41265714 7602 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7603 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
7604 },
7605 {
7606 .cmd = NL80211_CMD_LEAVE_IBSS,
7607 .doit = nl80211_leave_ibss,
7608 .policy = nl80211_policy,
7609 .flags = GENL_ADMIN_PERM,
41265714 7610 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7611 NL80211_FLAG_NEED_RTNL,
04a773ad 7612 },
aff89a9b
JB
7613#ifdef CONFIG_NL80211_TESTMODE
7614 {
7615 .cmd = NL80211_CMD_TESTMODE,
7616 .doit = nl80211_testmode_do,
71063f0e 7617 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
7618 .policy = nl80211_policy,
7619 .flags = GENL_ADMIN_PERM,
4c476991
JB
7620 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7621 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
7622 },
7623#endif
b23aa676
SO
7624 {
7625 .cmd = NL80211_CMD_CONNECT,
7626 .doit = nl80211_connect,
7627 .policy = nl80211_policy,
7628 .flags = GENL_ADMIN_PERM,
41265714 7629 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7630 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
7631 },
7632 {
7633 .cmd = NL80211_CMD_DISCONNECT,
7634 .doit = nl80211_disconnect,
7635 .policy = nl80211_policy,
7636 .flags = GENL_ADMIN_PERM,
41265714 7637 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7638 NL80211_FLAG_NEED_RTNL,
b23aa676 7639 },
463d0183
JB
7640 {
7641 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
7642 .doit = nl80211_wiphy_netns,
7643 .policy = nl80211_policy,
7644 .flags = GENL_ADMIN_PERM,
4c476991
JB
7645 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7646 NL80211_FLAG_NEED_RTNL,
463d0183 7647 },
61fa713c
HS
7648 {
7649 .cmd = NL80211_CMD_GET_SURVEY,
7650 .policy = nl80211_policy,
7651 .dumpit = nl80211_dump_survey,
7652 },
67fbb16b
SO
7653 {
7654 .cmd = NL80211_CMD_SET_PMKSA,
7655 .doit = nl80211_setdel_pmksa,
7656 .policy = nl80211_policy,
7657 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7658 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7659 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7660 },
7661 {
7662 .cmd = NL80211_CMD_DEL_PMKSA,
7663 .doit = nl80211_setdel_pmksa,
7664 .policy = nl80211_policy,
7665 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7666 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7667 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7668 },
7669 {
7670 .cmd = NL80211_CMD_FLUSH_PMKSA,
7671 .doit = nl80211_flush_pmksa,
7672 .policy = nl80211_policy,
7673 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7674 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7675 NL80211_FLAG_NEED_RTNL,
67fbb16b 7676 },
9588bbd5
JM
7677 {
7678 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
7679 .doit = nl80211_remain_on_channel,
7680 .policy = nl80211_policy,
7681 .flags = GENL_ADMIN_PERM,
71bbc994 7682 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7683 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
7684 },
7685 {
7686 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7687 .doit = nl80211_cancel_remain_on_channel,
7688 .policy = nl80211_policy,
7689 .flags = GENL_ADMIN_PERM,
71bbc994 7690 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7691 NL80211_FLAG_NEED_RTNL,
9588bbd5 7692 },
13ae75b1
JM
7693 {
7694 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
7695 .doit = nl80211_set_tx_bitrate_mask,
7696 .policy = nl80211_policy,
7697 .flags = GENL_ADMIN_PERM,
4c476991
JB
7698 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7699 NL80211_FLAG_NEED_RTNL,
13ae75b1 7700 },
026331c4 7701 {
2e161f78
JB
7702 .cmd = NL80211_CMD_REGISTER_FRAME,
7703 .doit = nl80211_register_mgmt,
026331c4
JM
7704 .policy = nl80211_policy,
7705 .flags = GENL_ADMIN_PERM,
71bbc994 7706 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7707 NL80211_FLAG_NEED_RTNL,
026331c4
JM
7708 },
7709 {
2e161f78
JB
7710 .cmd = NL80211_CMD_FRAME,
7711 .doit = nl80211_tx_mgmt,
026331c4 7712 .policy = nl80211_policy,
f7ca38df 7713 .flags = GENL_ADMIN_PERM,
71bbc994 7714 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
7715 NL80211_FLAG_NEED_RTNL,
7716 },
7717 {
7718 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
7719 .doit = nl80211_tx_mgmt_cancel_wait,
7720 .policy = nl80211_policy,
026331c4 7721 .flags = GENL_ADMIN_PERM,
71bbc994 7722 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7723 NL80211_FLAG_NEED_RTNL,
026331c4 7724 },
ffb9eb3d
KV
7725 {
7726 .cmd = NL80211_CMD_SET_POWER_SAVE,
7727 .doit = nl80211_set_power_save,
7728 .policy = nl80211_policy,
7729 .flags = GENL_ADMIN_PERM,
4c476991
JB
7730 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7731 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
7732 },
7733 {
7734 .cmd = NL80211_CMD_GET_POWER_SAVE,
7735 .doit = nl80211_get_power_save,
7736 .policy = nl80211_policy,
7737 /* can be retrieved by unprivileged users */
4c476991
JB
7738 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7739 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 7740 },
d6dc1a38
JO
7741 {
7742 .cmd = NL80211_CMD_SET_CQM,
7743 .doit = nl80211_set_cqm,
7744 .policy = nl80211_policy,
7745 .flags = GENL_ADMIN_PERM,
4c476991
JB
7746 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7747 NL80211_FLAG_NEED_RTNL,
d6dc1a38 7748 },
f444de05
JB
7749 {
7750 .cmd = NL80211_CMD_SET_CHANNEL,
7751 .doit = nl80211_set_channel,
7752 .policy = nl80211_policy,
7753 .flags = GENL_ADMIN_PERM,
4c476991
JB
7754 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7755 NL80211_FLAG_NEED_RTNL,
f444de05 7756 },
e8347eba
BJ
7757 {
7758 .cmd = NL80211_CMD_SET_WDS_PEER,
7759 .doit = nl80211_set_wds_peer,
7760 .policy = nl80211_policy,
7761 .flags = GENL_ADMIN_PERM,
43b19952
JB
7762 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7763 NL80211_FLAG_NEED_RTNL,
e8347eba 7764 },
29cbe68c
JB
7765 {
7766 .cmd = NL80211_CMD_JOIN_MESH,
7767 .doit = nl80211_join_mesh,
7768 .policy = nl80211_policy,
7769 .flags = GENL_ADMIN_PERM,
7770 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7771 NL80211_FLAG_NEED_RTNL,
7772 },
7773 {
7774 .cmd = NL80211_CMD_LEAVE_MESH,
7775 .doit = nl80211_leave_mesh,
7776 .policy = nl80211_policy,
7777 .flags = GENL_ADMIN_PERM,
7778 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7779 NL80211_FLAG_NEED_RTNL,
7780 },
dfb89c56 7781#ifdef CONFIG_PM
ff1b6e69
JB
7782 {
7783 .cmd = NL80211_CMD_GET_WOWLAN,
7784 .doit = nl80211_get_wowlan,
7785 .policy = nl80211_policy,
7786 /* can be retrieved by unprivileged users */
7787 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7788 NL80211_FLAG_NEED_RTNL,
7789 },
7790 {
7791 .cmd = NL80211_CMD_SET_WOWLAN,
7792 .doit = nl80211_set_wowlan,
7793 .policy = nl80211_policy,
7794 .flags = GENL_ADMIN_PERM,
7795 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7796 NL80211_FLAG_NEED_RTNL,
7797 },
dfb89c56 7798#endif
e5497d76
JB
7799 {
7800 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7801 .doit = nl80211_set_rekey_data,
7802 .policy = nl80211_policy,
7803 .flags = GENL_ADMIN_PERM,
7804 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7805 NL80211_FLAG_NEED_RTNL,
7806 },
109086ce
AN
7807 {
7808 .cmd = NL80211_CMD_TDLS_MGMT,
7809 .doit = nl80211_tdls_mgmt,
7810 .policy = nl80211_policy,
7811 .flags = GENL_ADMIN_PERM,
7812 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7813 NL80211_FLAG_NEED_RTNL,
7814 },
7815 {
7816 .cmd = NL80211_CMD_TDLS_OPER,
7817 .doit = nl80211_tdls_oper,
7818 .policy = nl80211_policy,
7819 .flags = GENL_ADMIN_PERM,
7820 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7821 NL80211_FLAG_NEED_RTNL,
7822 },
28946da7
JB
7823 {
7824 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7825 .doit = nl80211_register_unexpected_frame,
7826 .policy = nl80211_policy,
7827 .flags = GENL_ADMIN_PERM,
7828 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7829 NL80211_FLAG_NEED_RTNL,
7830 },
7f6cf311
JB
7831 {
7832 .cmd = NL80211_CMD_PROBE_CLIENT,
7833 .doit = nl80211_probe_client,
7834 .policy = nl80211_policy,
7835 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7836 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7837 NL80211_FLAG_NEED_RTNL,
7838 },
5e760230
JB
7839 {
7840 .cmd = NL80211_CMD_REGISTER_BEACONS,
7841 .doit = nl80211_register_beacons,
7842 .policy = nl80211_policy,
7843 .flags = GENL_ADMIN_PERM,
7844 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7845 NL80211_FLAG_NEED_RTNL,
7846 },
1d9d9213
SW
7847 {
7848 .cmd = NL80211_CMD_SET_NOACK_MAP,
7849 .doit = nl80211_set_noack_map,
7850 .policy = nl80211_policy,
7851 .flags = GENL_ADMIN_PERM,
7852 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7853 NL80211_FLAG_NEED_RTNL,
7854 },
98104fde
JB
7855 {
7856 .cmd = NL80211_CMD_START_P2P_DEVICE,
7857 .doit = nl80211_start_p2p_device,
7858 .policy = nl80211_policy,
7859 .flags = GENL_ADMIN_PERM,
7860 .internal_flags = NL80211_FLAG_NEED_WDEV |
7861 NL80211_FLAG_NEED_RTNL,
7862 },
7863 {
7864 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
7865 .doit = nl80211_stop_p2p_device,
7866 .policy = nl80211_policy,
7867 .flags = GENL_ADMIN_PERM,
7868 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
7869 NL80211_FLAG_NEED_RTNL,
7870 },
f4e583c8
AQ
7871 {
7872 .cmd = NL80211_CMD_SET_MCAST_RATE,
7873 .doit = nl80211_set_mcast_rate,
7874 .policy = nl80211_policy,
7875 .flags = GENL_ADMIN_PERM,
7876 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7877 NL80211_FLAG_NEED_RTNL,
7878 },
55682965 7879};
9588bbd5 7880
6039f6d2
JM
7881static struct genl_multicast_group nl80211_mlme_mcgrp = {
7882 .name = "mlme",
7883};
55682965
JB
7884
7885/* multicast groups */
7886static struct genl_multicast_group nl80211_config_mcgrp = {
7887 .name = "config",
7888};
2a519311
JB
7889static struct genl_multicast_group nl80211_scan_mcgrp = {
7890 .name = "scan",
7891};
73d54c9e
LR
7892static struct genl_multicast_group nl80211_regulatory_mcgrp = {
7893 .name = "regulatory",
7894};
55682965
JB
7895
7896/* notification functions */
7897
7898void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
7899{
7900 struct sk_buff *msg;
7901
fd2120ca 7902 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
7903 if (!msg)
7904 return;
7905
7906 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
7907 nlmsg_free(msg);
7908 return;
7909 }
7910
463d0183
JB
7911 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7912 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
7913}
7914
362a415d
JB
7915static int nl80211_add_scan_req(struct sk_buff *msg,
7916 struct cfg80211_registered_device *rdev)
7917{
7918 struct cfg80211_scan_request *req = rdev->scan_req;
7919 struct nlattr *nest;
7920 int i;
7921
667503dd
JB
7922 ASSERT_RDEV_LOCK(rdev);
7923
362a415d
JB
7924 if (WARN_ON(!req))
7925 return 0;
7926
7927 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
7928 if (!nest)
7929 goto nla_put_failure;
9360ffd1
DM
7930 for (i = 0; i < req->n_ssids; i++) {
7931 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
7932 goto nla_put_failure;
7933 }
362a415d
JB
7934 nla_nest_end(msg, nest);
7935
7936 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
7937 if (!nest)
7938 goto nla_put_failure;
9360ffd1
DM
7939 for (i = 0; i < req->n_channels; i++) {
7940 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
7941 goto nla_put_failure;
7942 }
362a415d
JB
7943 nla_nest_end(msg, nest);
7944
9360ffd1
DM
7945 if (req->ie &&
7946 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
7947 goto nla_put_failure;
362a415d 7948
ed473771
SL
7949 if (req->flags)
7950 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
7951
362a415d
JB
7952 return 0;
7953 nla_put_failure:
7954 return -ENOBUFS;
7955}
7956
a538e2d5
JB
7957static int nl80211_send_scan_msg(struct sk_buff *msg,
7958 struct cfg80211_registered_device *rdev,
fd014284 7959 struct wireless_dev *wdev,
15e47304 7960 u32 portid, u32 seq, int flags,
a538e2d5 7961 u32 cmd)
2a519311
JB
7962{
7963 void *hdr;
7964
15e47304 7965 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
7966 if (!hdr)
7967 return -1;
7968
9360ffd1 7969 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
7970 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
7971 wdev->netdev->ifindex)) ||
7972 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 7973 goto nla_put_failure;
2a519311 7974
362a415d
JB
7975 /* ignore errors and send incomplete event anyway */
7976 nl80211_add_scan_req(msg, rdev);
2a519311
JB
7977
7978 return genlmsg_end(msg, hdr);
7979
7980 nla_put_failure:
7981 genlmsg_cancel(msg, hdr);
7982 return -EMSGSIZE;
7983}
7984
807f8a8c
LC
7985static int
7986nl80211_send_sched_scan_msg(struct sk_buff *msg,
7987 struct cfg80211_registered_device *rdev,
7988 struct net_device *netdev,
15e47304 7989 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
7990{
7991 void *hdr;
7992
15e47304 7993 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
7994 if (!hdr)
7995 return -1;
7996
9360ffd1
DM
7997 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7998 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7999 goto nla_put_failure;
807f8a8c
LC
8000
8001 return genlmsg_end(msg, hdr);
8002
8003 nla_put_failure:
8004 genlmsg_cancel(msg, hdr);
8005 return -EMSGSIZE;
8006}
8007
a538e2d5 8008void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 8009 struct wireless_dev *wdev)
a538e2d5
JB
8010{
8011 struct sk_buff *msg;
8012
58050fce 8013 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
8014 if (!msg)
8015 return;
8016
fd014284 8017 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
8018 NL80211_CMD_TRIGGER_SCAN) < 0) {
8019 nlmsg_free(msg);
8020 return;
8021 }
8022
463d0183
JB
8023 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8024 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
8025}
8026
2a519311 8027void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 8028 struct wireless_dev *wdev)
2a519311
JB
8029{
8030 struct sk_buff *msg;
8031
fd2120ca 8032 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8033 if (!msg)
8034 return;
8035
fd014284 8036 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8037 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
8038 nlmsg_free(msg);
8039 return;
8040 }
8041
463d0183
JB
8042 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8043 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8044}
8045
8046void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 8047 struct wireless_dev *wdev)
2a519311
JB
8048{
8049 struct sk_buff *msg;
8050
fd2120ca 8051 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8052 if (!msg)
8053 return;
8054
fd014284 8055 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8056 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
8057 nlmsg_free(msg);
8058 return;
8059 }
8060
463d0183
JB
8061 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8062 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8063}
8064
807f8a8c
LC
8065void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
8066 struct net_device *netdev)
8067{
8068 struct sk_buff *msg;
8069
8070 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8071 if (!msg)
8072 return;
8073
8074 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
8075 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
8076 nlmsg_free(msg);
8077 return;
8078 }
8079
8080 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8081 nl80211_scan_mcgrp.id, GFP_KERNEL);
8082}
8083
8084void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
8085 struct net_device *netdev, u32 cmd)
8086{
8087 struct sk_buff *msg;
8088
58050fce 8089 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
8090 if (!msg)
8091 return;
8092
8093 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
8094 nlmsg_free(msg);
8095 return;
8096 }
8097
8098 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8099 nl80211_scan_mcgrp.id, GFP_KERNEL);
8100}
8101
73d54c9e
LR
8102/*
8103 * This can happen on global regulatory changes or device specific settings
8104 * based on custom world regulatory domains.
8105 */
8106void nl80211_send_reg_change_event(struct regulatory_request *request)
8107{
8108 struct sk_buff *msg;
8109 void *hdr;
8110
fd2120ca 8111 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
8112 if (!msg)
8113 return;
8114
8115 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
8116 if (!hdr) {
8117 nlmsg_free(msg);
8118 return;
8119 }
8120
8121 /* Userspace can always count this one always being set */
9360ffd1
DM
8122 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
8123 goto nla_put_failure;
8124
8125 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
8126 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8127 NL80211_REGDOM_TYPE_WORLD))
8128 goto nla_put_failure;
8129 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
8130 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8131 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
8132 goto nla_put_failure;
8133 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
8134 request->intersect) {
8135 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8136 NL80211_REGDOM_TYPE_INTERSECTION))
8137 goto nla_put_failure;
8138 } else {
8139 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8140 NL80211_REGDOM_TYPE_COUNTRY) ||
8141 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
8142 request->alpha2))
8143 goto nla_put_failure;
8144 }
8145
f4173766 8146 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
8147 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
8148 goto nla_put_failure;
73d54c9e 8149
3b7b72ee 8150 genlmsg_end(msg, hdr);
73d54c9e 8151
bc43b28c 8152 rcu_read_lock();
463d0183 8153 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
8154 GFP_ATOMIC);
8155 rcu_read_unlock();
73d54c9e
LR
8156
8157 return;
8158
8159nla_put_failure:
8160 genlmsg_cancel(msg, hdr);
8161 nlmsg_free(msg);
8162}
8163
6039f6d2
JM
8164static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
8165 struct net_device *netdev,
8166 const u8 *buf, size_t len,
e6d6e342 8167 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
8168{
8169 struct sk_buff *msg;
8170 void *hdr;
8171
e6d6e342 8172 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
8173 if (!msg)
8174 return;
8175
8176 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8177 if (!hdr) {
8178 nlmsg_free(msg);
8179 return;
8180 }
8181
9360ffd1
DM
8182 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8183 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8184 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8185 goto nla_put_failure;
6039f6d2 8186
3b7b72ee 8187 genlmsg_end(msg, hdr);
6039f6d2 8188
463d0183
JB
8189 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8190 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
8191 return;
8192
8193 nla_put_failure:
8194 genlmsg_cancel(msg, hdr);
8195 nlmsg_free(msg);
8196}
8197
8198void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8199 struct net_device *netdev, const u8 *buf,
8200 size_t len, gfp_t gfp)
6039f6d2
JM
8201{
8202 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8203 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
8204}
8205
8206void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
8207 struct net_device *netdev, const u8 *buf,
e6d6e342 8208 size_t len, gfp_t gfp)
6039f6d2 8209{
e6d6e342
JB
8210 nl80211_send_mlme_event(rdev, netdev, buf, len,
8211 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
8212}
8213
53b46b84 8214void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8215 struct net_device *netdev, const u8 *buf,
8216 size_t len, gfp_t gfp)
6039f6d2
JM
8217{
8218 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8219 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
8220}
8221
53b46b84
JM
8222void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
8223 struct net_device *netdev, const u8 *buf,
e6d6e342 8224 size_t len, gfp_t gfp)
6039f6d2
JM
8225{
8226 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8227 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
8228}
8229
cf4e594e
JM
8230void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
8231 struct net_device *netdev, const u8 *buf,
8232 size_t len, gfp_t gfp)
8233{
8234 nl80211_send_mlme_event(rdev, netdev, buf, len,
8235 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
8236}
8237
8238void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
8239 struct net_device *netdev, const u8 *buf,
8240 size_t len, gfp_t gfp)
8241{
8242 nl80211_send_mlme_event(rdev, netdev, buf, len,
8243 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
8244}
8245
1b06bb40
LR
8246static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
8247 struct net_device *netdev, int cmd,
e6d6e342 8248 const u8 *addr, gfp_t gfp)
1965c853
JM
8249{
8250 struct sk_buff *msg;
8251 void *hdr;
8252
e6d6e342 8253 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
8254 if (!msg)
8255 return;
8256
8257 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8258 if (!hdr) {
8259 nlmsg_free(msg);
8260 return;
8261 }
8262
9360ffd1
DM
8263 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8264 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8265 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
8266 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8267 goto nla_put_failure;
1965c853 8268
3b7b72ee 8269 genlmsg_end(msg, hdr);
1965c853 8270
463d0183
JB
8271 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8272 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
8273 return;
8274
8275 nla_put_failure:
8276 genlmsg_cancel(msg, hdr);
8277 nlmsg_free(msg);
8278}
8279
8280void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8281 struct net_device *netdev, const u8 *addr,
8282 gfp_t gfp)
1965c853
JM
8283{
8284 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 8285 addr, gfp);
1965c853
JM
8286}
8287
8288void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8289 struct net_device *netdev, const u8 *addr,
8290 gfp_t gfp)
1965c853 8291{
e6d6e342
JB
8292 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
8293 addr, gfp);
1965c853
JM
8294}
8295
b23aa676
SO
8296void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
8297 struct net_device *netdev, const u8 *bssid,
8298 const u8 *req_ie, size_t req_ie_len,
8299 const u8 *resp_ie, size_t resp_ie_len,
8300 u16 status, gfp_t gfp)
8301{
8302 struct sk_buff *msg;
8303 void *hdr;
8304
58050fce 8305 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8306 if (!msg)
8307 return;
8308
8309 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
8310 if (!hdr) {
8311 nlmsg_free(msg);
8312 return;
8313 }
8314
9360ffd1
DM
8315 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8316 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8317 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
8318 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
8319 (req_ie &&
8320 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8321 (resp_ie &&
8322 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8323 goto nla_put_failure;
b23aa676 8324
3b7b72ee 8325 genlmsg_end(msg, hdr);
b23aa676 8326
463d0183
JB
8327 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8328 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8329 return;
8330
8331 nla_put_failure:
8332 genlmsg_cancel(msg, hdr);
8333 nlmsg_free(msg);
8334
8335}
8336
8337void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
8338 struct net_device *netdev, const u8 *bssid,
8339 const u8 *req_ie, size_t req_ie_len,
8340 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
8341{
8342 struct sk_buff *msg;
8343 void *hdr;
8344
58050fce 8345 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8346 if (!msg)
8347 return;
8348
8349 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
8350 if (!hdr) {
8351 nlmsg_free(msg);
8352 return;
8353 }
8354
9360ffd1
DM
8355 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8356 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8357 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
8358 (req_ie &&
8359 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8360 (resp_ie &&
8361 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8362 goto nla_put_failure;
b23aa676 8363
3b7b72ee 8364 genlmsg_end(msg, hdr);
b23aa676 8365
463d0183
JB
8366 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8367 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8368 return;
8369
8370 nla_put_failure:
8371 genlmsg_cancel(msg, hdr);
8372 nlmsg_free(msg);
8373
8374}
8375
8376void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
8377 struct net_device *netdev, u16 reason,
667503dd 8378 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
8379{
8380 struct sk_buff *msg;
8381 void *hdr;
8382
58050fce 8383 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
8384 if (!msg)
8385 return;
8386
8387 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
8388 if (!hdr) {
8389 nlmsg_free(msg);
8390 return;
8391 }
8392
9360ffd1
DM
8393 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8394 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8395 (from_ap && reason &&
8396 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
8397 (from_ap &&
8398 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
8399 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
8400 goto nla_put_failure;
b23aa676 8401
3b7b72ee 8402 genlmsg_end(msg, hdr);
b23aa676 8403
463d0183
JB
8404 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8405 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
8406 return;
8407
8408 nla_put_failure:
8409 genlmsg_cancel(msg, hdr);
8410 nlmsg_free(msg);
8411
8412}
8413
04a773ad
JB
8414void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
8415 struct net_device *netdev, const u8 *bssid,
8416 gfp_t gfp)
8417{
8418 struct sk_buff *msg;
8419 void *hdr;
8420
fd2120ca 8421 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
8422 if (!msg)
8423 return;
8424
8425 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
8426 if (!hdr) {
8427 nlmsg_free(msg);
8428 return;
8429 }
8430
9360ffd1
DM
8431 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8432 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8433 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8434 goto nla_put_failure;
04a773ad 8435
3b7b72ee 8436 genlmsg_end(msg, hdr);
04a773ad 8437
463d0183
JB
8438 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8439 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
8440 return;
8441
8442 nla_put_failure:
8443 genlmsg_cancel(msg, hdr);
8444 nlmsg_free(msg);
8445}
8446
c93b5e71
JC
8447void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
8448 struct net_device *netdev,
8449 const u8 *macaddr, const u8* ie, u8 ie_len,
8450 gfp_t gfp)
8451{
8452 struct sk_buff *msg;
8453 void *hdr;
8454
8455 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8456 if (!msg)
8457 return;
8458
8459 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
8460 if (!hdr) {
8461 nlmsg_free(msg);
8462 return;
8463 }
8464
9360ffd1
DM
8465 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8466 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8467 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
8468 (ie_len && ie &&
8469 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
8470 goto nla_put_failure;
c93b5e71 8471
3b7b72ee 8472 genlmsg_end(msg, hdr);
c93b5e71
JC
8473
8474 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8475 nl80211_mlme_mcgrp.id, gfp);
8476 return;
8477
8478 nla_put_failure:
8479 genlmsg_cancel(msg, hdr);
8480 nlmsg_free(msg);
8481}
8482
a3b8b056
JM
8483void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
8484 struct net_device *netdev, const u8 *addr,
8485 enum nl80211_key_type key_type, int key_id,
e6d6e342 8486 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
8487{
8488 struct sk_buff *msg;
8489 void *hdr;
8490
e6d6e342 8491 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
8492 if (!msg)
8493 return;
8494
8495 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
8496 if (!hdr) {
8497 nlmsg_free(msg);
8498 return;
8499 }
8500
9360ffd1
DM
8501 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8502 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8503 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
8504 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
8505 (key_id != -1 &&
8506 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
8507 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
8508 goto nla_put_failure;
a3b8b056 8509
3b7b72ee 8510 genlmsg_end(msg, hdr);
a3b8b056 8511
463d0183
JB
8512 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8513 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
8514 return;
8515
8516 nla_put_failure:
8517 genlmsg_cancel(msg, hdr);
8518 nlmsg_free(msg);
8519}
8520
6bad8766
LR
8521void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
8522 struct ieee80211_channel *channel_before,
8523 struct ieee80211_channel *channel_after)
8524{
8525 struct sk_buff *msg;
8526 void *hdr;
8527 struct nlattr *nl_freq;
8528
fd2120ca 8529 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
8530 if (!msg)
8531 return;
8532
8533 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
8534 if (!hdr) {
8535 nlmsg_free(msg);
8536 return;
8537 }
8538
8539 /*
8540 * Since we are applying the beacon hint to a wiphy we know its
8541 * wiphy_idx is valid
8542 */
9360ffd1
DM
8543 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8544 goto nla_put_failure;
6bad8766
LR
8545
8546 /* Before */
8547 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
8548 if (!nl_freq)
8549 goto nla_put_failure;
8550 if (nl80211_msg_put_channel(msg, channel_before))
8551 goto nla_put_failure;
8552 nla_nest_end(msg, nl_freq);
8553
8554 /* After */
8555 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
8556 if (!nl_freq)
8557 goto nla_put_failure;
8558 if (nl80211_msg_put_channel(msg, channel_after))
8559 goto nla_put_failure;
8560 nla_nest_end(msg, nl_freq);
8561
3b7b72ee 8562 genlmsg_end(msg, hdr);
6bad8766 8563
463d0183
JB
8564 rcu_read_lock();
8565 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
8566 GFP_ATOMIC);
8567 rcu_read_unlock();
6bad8766
LR
8568
8569 return;
8570
8571nla_put_failure:
8572 genlmsg_cancel(msg, hdr);
8573 nlmsg_free(msg);
8574}
8575
9588bbd5
JM
8576static void nl80211_send_remain_on_chan_event(
8577 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 8578 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8579 struct ieee80211_channel *chan,
9588bbd5
JM
8580 unsigned int duration, gfp_t gfp)
8581{
8582 struct sk_buff *msg;
8583 void *hdr;
8584
8585 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8586 if (!msg)
8587 return;
8588
8589 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8590 if (!hdr) {
8591 nlmsg_free(msg);
8592 return;
8593 }
8594
9360ffd1 8595 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8596 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8597 wdev->netdev->ifindex)) ||
00f53350 8598 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 8599 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
8600 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
8601 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
8602 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8603 goto nla_put_failure;
9588bbd5 8604
9360ffd1
DM
8605 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
8606 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
8607 goto nla_put_failure;
9588bbd5 8608
3b7b72ee 8609 genlmsg_end(msg, hdr);
9588bbd5
JM
8610
8611 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8612 nl80211_mlme_mcgrp.id, gfp);
8613 return;
8614
8615 nla_put_failure:
8616 genlmsg_cancel(msg, hdr);
8617 nlmsg_free(msg);
8618}
8619
8620void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
71bbc994 8621 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8622 struct ieee80211_channel *chan,
9588bbd5
JM
8623 unsigned int duration, gfp_t gfp)
8624{
8625 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 8626 rdev, wdev, cookie, chan,
42d97a59 8627 duration, gfp);
9588bbd5
JM
8628}
8629
8630void nl80211_send_remain_on_channel_cancel(
71bbc994
JB
8631 struct cfg80211_registered_device *rdev,
8632 struct wireless_dev *wdev,
42d97a59 8633 u64 cookie, struct ieee80211_channel *chan, gfp_t gfp)
9588bbd5
JM
8634{
8635 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 8636 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5
JM
8637}
8638
98b62183
JB
8639void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
8640 struct net_device *dev, const u8 *mac_addr,
8641 struct station_info *sinfo, gfp_t gfp)
8642{
8643 struct sk_buff *msg;
8644
58050fce 8645 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
8646 if (!msg)
8647 return;
8648
66266b3a
JL
8649 if (nl80211_send_station(msg, 0, 0, 0,
8650 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
8651 nlmsg_free(msg);
8652 return;
8653 }
8654
8655 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8656 nl80211_mlme_mcgrp.id, gfp);
8657}
8658
ec15e68b
JM
8659void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
8660 struct net_device *dev, const u8 *mac_addr,
8661 gfp_t gfp)
8662{
8663 struct sk_buff *msg;
8664 void *hdr;
8665
58050fce 8666 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
8667 if (!msg)
8668 return;
8669
8670 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
8671 if (!hdr) {
8672 nlmsg_free(msg);
8673 return;
8674 }
8675
9360ffd1
DM
8676 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8677 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
8678 goto nla_put_failure;
ec15e68b 8679
3b7b72ee 8680 genlmsg_end(msg, hdr);
ec15e68b
JM
8681
8682 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8683 nl80211_mlme_mcgrp.id, gfp);
8684 return;
8685
8686 nla_put_failure:
8687 genlmsg_cancel(msg, hdr);
8688 nlmsg_free(msg);
8689}
8690
ed44a951
PP
8691void nl80211_send_conn_failed_event(struct cfg80211_registered_device *rdev,
8692 struct net_device *dev, const u8 *mac_addr,
8693 enum nl80211_connect_failed_reason reason,
8694 gfp_t gfp)
8695{
8696 struct sk_buff *msg;
8697 void *hdr;
8698
8699 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8700 if (!msg)
8701 return;
8702
8703 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
8704 if (!hdr) {
8705 nlmsg_free(msg);
8706 return;
8707 }
8708
8709 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8710 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
8711 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
8712 goto nla_put_failure;
8713
8714 genlmsg_end(msg, hdr);
8715
8716 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8717 nl80211_mlme_mcgrp.id, gfp);
8718 return;
8719
8720 nla_put_failure:
8721 genlmsg_cancel(msg, hdr);
8722 nlmsg_free(msg);
8723}
8724
b92ab5d8
JB
8725static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
8726 const u8 *addr, gfp_t gfp)
28946da7
JB
8727{
8728 struct wireless_dev *wdev = dev->ieee80211_ptr;
8729 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8730 struct sk_buff *msg;
8731 void *hdr;
8732 int err;
15e47304 8733 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 8734
15e47304 8735 if (!nlportid)
28946da7
JB
8736 return false;
8737
8738 msg = nlmsg_new(100, gfp);
8739 if (!msg)
8740 return true;
8741
b92ab5d8 8742 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
8743 if (!hdr) {
8744 nlmsg_free(msg);
8745 return true;
8746 }
8747
9360ffd1
DM
8748 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8749 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8750 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8751 goto nla_put_failure;
28946da7
JB
8752
8753 err = genlmsg_end(msg, hdr);
8754 if (err < 0) {
8755 nlmsg_free(msg);
8756 return true;
8757 }
8758
15e47304 8759 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
8760 return true;
8761
8762 nla_put_failure:
8763 genlmsg_cancel(msg, hdr);
8764 nlmsg_free(msg);
8765 return true;
8766}
8767
b92ab5d8
JB
8768bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
8769{
8770 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
8771 addr, gfp);
8772}
8773
8774bool nl80211_unexpected_4addr_frame(struct net_device *dev,
8775 const u8 *addr, gfp_t gfp)
8776{
8777 return __nl80211_unexpected_frame(dev,
8778 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
8779 addr, gfp);
8780}
8781
2e161f78 8782int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 8783 struct wireless_dev *wdev, u32 nlportid,
804483e9
JB
8784 int freq, int sig_dbm,
8785 const u8 *buf, size_t len, gfp_t gfp)
026331c4 8786{
71bbc994 8787 struct net_device *netdev = wdev->netdev;
026331c4
JM
8788 struct sk_buff *msg;
8789 void *hdr;
026331c4
JM
8790
8791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8792 if (!msg)
8793 return -ENOMEM;
8794
2e161f78 8795 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
8796 if (!hdr) {
8797 nlmsg_free(msg);
8798 return -ENOMEM;
8799 }
8800
9360ffd1 8801 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8802 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8803 netdev->ifindex)) ||
9360ffd1
DM
8804 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8805 (sig_dbm &&
8806 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8807 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8808 goto nla_put_failure;
026331c4 8809
3b7b72ee 8810 genlmsg_end(msg, hdr);
026331c4 8811
15e47304 8812 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
8813
8814 nla_put_failure:
8815 genlmsg_cancel(msg, hdr);
8816 nlmsg_free(msg);
8817 return -ENOBUFS;
8818}
8819
2e161f78 8820void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
71bbc994 8821 struct wireless_dev *wdev, u64 cookie,
2e161f78
JB
8822 const u8 *buf, size_t len, bool ack,
8823 gfp_t gfp)
026331c4 8824{
71bbc994 8825 struct net_device *netdev = wdev->netdev;
026331c4
JM
8826 struct sk_buff *msg;
8827 void *hdr;
8828
8829 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8830 if (!msg)
8831 return;
8832
2e161f78 8833 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8834 if (!hdr) {
8835 nlmsg_free(msg);
8836 return;
8837 }
8838
9360ffd1 8839 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8840 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8841 netdev->ifindex)) ||
9360ffd1
DM
8842 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8843 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8844 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8845 goto nla_put_failure;
026331c4 8846
3b7b72ee 8847 genlmsg_end(msg, hdr);
026331c4
JM
8848
8849 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8850 return;
8851
8852 nla_put_failure:
8853 genlmsg_cancel(msg, hdr);
8854 nlmsg_free(msg);
8855}
8856
d6dc1a38
JO
8857void
8858nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8859 struct net_device *netdev,
8860 enum nl80211_cqm_rssi_threshold_event rssi_event,
8861 gfp_t gfp)
8862{
8863 struct sk_buff *msg;
8864 struct nlattr *pinfoattr;
8865 void *hdr;
8866
58050fce 8867 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
8868 if (!msg)
8869 return;
8870
8871 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8872 if (!hdr) {
8873 nlmsg_free(msg);
8874 return;
8875 }
8876
9360ffd1
DM
8877 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8878 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8879 goto nla_put_failure;
d6dc1a38
JO
8880
8881 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8882 if (!pinfoattr)
8883 goto nla_put_failure;
8884
9360ffd1
DM
8885 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
8886 rssi_event))
8887 goto nla_put_failure;
d6dc1a38
JO
8888
8889 nla_nest_end(msg, pinfoattr);
8890
3b7b72ee 8891 genlmsg_end(msg, hdr);
d6dc1a38
JO
8892
8893 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8894 nl80211_mlme_mcgrp.id, gfp);
8895 return;
8896
8897 nla_put_failure:
8898 genlmsg_cancel(msg, hdr);
8899 nlmsg_free(msg);
8900}
8901
e5497d76
JB
8902void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
8903 struct net_device *netdev, const u8 *bssid,
8904 const u8 *replay_ctr, gfp_t gfp)
8905{
8906 struct sk_buff *msg;
8907 struct nlattr *rekey_attr;
8908 void *hdr;
8909
58050fce 8910 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
8911 if (!msg)
8912 return;
8913
8914 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
8915 if (!hdr) {
8916 nlmsg_free(msg);
8917 return;
8918 }
8919
9360ffd1
DM
8920 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8921 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8922 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8923 goto nla_put_failure;
e5497d76
JB
8924
8925 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
8926 if (!rekey_attr)
8927 goto nla_put_failure;
8928
9360ffd1
DM
8929 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
8930 NL80211_REPLAY_CTR_LEN, replay_ctr))
8931 goto nla_put_failure;
e5497d76
JB
8932
8933 nla_nest_end(msg, rekey_attr);
8934
3b7b72ee 8935 genlmsg_end(msg, hdr);
e5497d76
JB
8936
8937 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8938 nl80211_mlme_mcgrp.id, gfp);
8939 return;
8940
8941 nla_put_failure:
8942 genlmsg_cancel(msg, hdr);
8943 nlmsg_free(msg);
8944}
8945
c9df56b4
JM
8946void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
8947 struct net_device *netdev, int index,
8948 const u8 *bssid, bool preauth, gfp_t gfp)
8949{
8950 struct sk_buff *msg;
8951 struct nlattr *attr;
8952 void *hdr;
8953
58050fce 8954 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
8955 if (!msg)
8956 return;
8957
8958 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
8959 if (!hdr) {
8960 nlmsg_free(msg);
8961 return;
8962 }
8963
9360ffd1
DM
8964 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8965 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8966 goto nla_put_failure;
c9df56b4
JM
8967
8968 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
8969 if (!attr)
8970 goto nla_put_failure;
8971
9360ffd1
DM
8972 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
8973 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
8974 (preauth &&
8975 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
8976 goto nla_put_failure;
c9df56b4
JM
8977
8978 nla_nest_end(msg, attr);
8979
3b7b72ee 8980 genlmsg_end(msg, hdr);
c9df56b4
JM
8981
8982 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8983 nl80211_mlme_mcgrp.id, gfp);
8984 return;
8985
8986 nla_put_failure:
8987 genlmsg_cancel(msg, hdr);
8988 nlmsg_free(msg);
8989}
8990
5314526b 8991void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
683b6d3b
JB
8992 struct net_device *netdev,
8993 struct cfg80211_chan_def *chandef, gfp_t gfp)
5314526b
TP
8994{
8995 struct sk_buff *msg;
8996 void *hdr;
8997
58050fce 8998 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
8999 if (!msg)
9000 return;
9001
9002 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
9003 if (!hdr) {
9004 nlmsg_free(msg);
9005 return;
9006 }
9007
683b6d3b
JB
9008 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9009 goto nla_put_failure;
9010
9011 if (nl80211_send_chandef(msg, chandef))
7eab0f64 9012 goto nla_put_failure;
5314526b
TP
9013
9014 genlmsg_end(msg, hdr);
9015
9016 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9017 nl80211_mlme_mcgrp.id, gfp);
9018 return;
9019
9020 nla_put_failure:
9021 genlmsg_cancel(msg, hdr);
9022 nlmsg_free(msg);
9023}
9024
84f10708
TP
9025void
9026nl80211_send_cqm_txe_notify(struct cfg80211_registered_device *rdev,
9027 struct net_device *netdev, const u8 *peer,
9028 u32 num_packets, u32 rate, u32 intvl, gfp_t gfp)
9029{
9030 struct sk_buff *msg;
9031 struct nlattr *pinfoattr;
9032 void *hdr;
9033
9034 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
9035 if (!msg)
9036 return;
9037
9038 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9039 if (!hdr) {
9040 nlmsg_free(msg);
9041 return;
9042 }
9043
9044 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9045 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9046 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9047 goto nla_put_failure;
9048
9049 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9050 if (!pinfoattr)
9051 goto nla_put_failure;
9052
9053 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
9054 goto nla_put_failure;
9055
9056 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
9057 goto nla_put_failure;
9058
9059 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
9060 goto nla_put_failure;
9061
9062 nla_nest_end(msg, pinfoattr);
9063
9064 genlmsg_end(msg, hdr);
9065
9066 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9067 nl80211_mlme_mcgrp.id, gfp);
9068 return;
9069
9070 nla_put_failure:
9071 genlmsg_cancel(msg, hdr);
9072 nlmsg_free(msg);
9073}
9074
c063dbf5
JB
9075void
9076nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
9077 struct net_device *netdev, const u8 *peer,
9078 u32 num_packets, gfp_t gfp)
9079{
9080 struct sk_buff *msg;
9081 struct nlattr *pinfoattr;
9082 void *hdr;
9083
58050fce 9084 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
9085 if (!msg)
9086 return;
9087
9088 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9089 if (!hdr) {
9090 nlmsg_free(msg);
9091 return;
9092 }
9093
9360ffd1
DM
9094 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9095 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9096 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9097 goto nla_put_failure;
c063dbf5
JB
9098
9099 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9100 if (!pinfoattr)
9101 goto nla_put_failure;
9102
9360ffd1
DM
9103 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
9104 goto nla_put_failure;
c063dbf5
JB
9105
9106 nla_nest_end(msg, pinfoattr);
9107
3b7b72ee 9108 genlmsg_end(msg, hdr);
c063dbf5
JB
9109
9110 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9111 nl80211_mlme_mcgrp.id, gfp);
9112 return;
9113
9114 nla_put_failure:
9115 genlmsg_cancel(msg, hdr);
9116 nlmsg_free(msg);
9117}
9118
7f6cf311
JB
9119void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
9120 u64 cookie, bool acked, gfp_t gfp)
9121{
9122 struct wireless_dev *wdev = dev->ieee80211_ptr;
9123 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9124 struct sk_buff *msg;
9125 void *hdr;
9126 int err;
9127
4ee3e063
BL
9128 trace_cfg80211_probe_status(dev, addr, cookie, acked);
9129
58050fce 9130 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 9131
7f6cf311
JB
9132 if (!msg)
9133 return;
9134
9135 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
9136 if (!hdr) {
9137 nlmsg_free(msg);
9138 return;
9139 }
9140
9360ffd1
DM
9141 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9142 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9143 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9144 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
9145 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
9146 goto nla_put_failure;
7f6cf311
JB
9147
9148 err = genlmsg_end(msg, hdr);
9149 if (err < 0) {
9150 nlmsg_free(msg);
9151 return;
9152 }
9153
9154 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9155 nl80211_mlme_mcgrp.id, gfp);
9156 return;
9157
9158 nla_put_failure:
9159 genlmsg_cancel(msg, hdr);
9160 nlmsg_free(msg);
9161}
9162EXPORT_SYMBOL(cfg80211_probe_status);
9163
5e760230
JB
9164void cfg80211_report_obss_beacon(struct wiphy *wiphy,
9165 const u8 *frame, size_t len,
37c73b5f 9166 int freq, int sig_dbm)
5e760230
JB
9167{
9168 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9169 struct sk_buff *msg;
9170 void *hdr;
37c73b5f 9171 struct cfg80211_beacon_registration *reg;
5e760230 9172
4ee3e063
BL
9173 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
9174
37c73b5f
BG
9175 spin_lock_bh(&rdev->beacon_registrations_lock);
9176 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
9177 msg = nlmsg_new(len + 100, GFP_ATOMIC);
9178 if (!msg) {
9179 spin_unlock_bh(&rdev->beacon_registrations_lock);
9180 return;
9181 }
5e760230 9182
37c73b5f
BG
9183 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
9184 if (!hdr)
9185 goto nla_put_failure;
5e760230 9186
37c73b5f
BG
9187 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9188 (freq &&
9189 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
9190 (sig_dbm &&
9191 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9192 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
9193 goto nla_put_failure;
5e760230 9194
37c73b5f 9195 genlmsg_end(msg, hdr);
5e760230 9196
37c73b5f
BG
9197 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
9198 }
9199 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
9200 return;
9201
9202 nla_put_failure:
37c73b5f
BG
9203 spin_unlock_bh(&rdev->beacon_registrations_lock);
9204 if (hdr)
9205 genlmsg_cancel(msg, hdr);
5e760230
JB
9206 nlmsg_free(msg);
9207}
9208EXPORT_SYMBOL(cfg80211_report_obss_beacon);
9209
3475b094
JM
9210void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
9211 enum nl80211_tdls_operation oper,
9212 u16 reason_code, gfp_t gfp)
9213{
9214 struct wireless_dev *wdev = dev->ieee80211_ptr;
9215 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9216 struct sk_buff *msg;
9217 void *hdr;
9218 int err;
9219
9220 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
9221 reason_code);
9222
9223 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9224 if (!msg)
9225 return;
9226
9227 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
9228 if (!hdr) {
9229 nlmsg_free(msg);
9230 return;
9231 }
9232
9233 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9234 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9235 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
9236 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
9237 (reason_code > 0 &&
9238 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
9239 goto nla_put_failure;
9240
9241 err = genlmsg_end(msg, hdr);
9242 if (err < 0) {
9243 nlmsg_free(msg);
9244 return;
9245 }
9246
9247 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9248 nl80211_mlme_mcgrp.id, gfp);
9249 return;
9250
9251 nla_put_failure:
9252 genlmsg_cancel(msg, hdr);
9253 nlmsg_free(msg);
9254}
9255EXPORT_SYMBOL(cfg80211_tdls_oper_request);
9256
026331c4
JM
9257static int nl80211_netlink_notify(struct notifier_block * nb,
9258 unsigned long state,
9259 void *_notify)
9260{
9261 struct netlink_notify *notify = _notify;
9262 struct cfg80211_registered_device *rdev;
9263 struct wireless_dev *wdev;
37c73b5f 9264 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
9265
9266 if (state != NETLINK_URELEASE)
9267 return NOTIFY_DONE;
9268
9269 rcu_read_lock();
9270
5e760230 9271 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 9272 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 9273 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
9274
9275 spin_lock_bh(&rdev->beacon_registrations_lock);
9276 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
9277 list) {
9278 if (reg->nlportid == notify->portid) {
9279 list_del(&reg->list);
9280 kfree(reg);
9281 break;
9282 }
9283 }
9284 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 9285 }
026331c4
JM
9286
9287 rcu_read_unlock();
9288
9289 return NOTIFY_DONE;
9290}
9291
9292static struct notifier_block nl80211_netlink_notifier = {
9293 .notifier_call = nl80211_netlink_notify,
9294};
9295
55682965
JB
9296/* initialisation/exit functions */
9297
9298int nl80211_init(void)
9299{
0d63cbb5 9300 int err;
55682965 9301
0d63cbb5
MM
9302 err = genl_register_family_with_ops(&nl80211_fam,
9303 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
9304 if (err)
9305 return err;
9306
55682965
JB
9307 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
9308 if (err)
9309 goto err_out;
9310
2a519311
JB
9311 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
9312 if (err)
9313 goto err_out;
9314
73d54c9e
LR
9315 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
9316 if (err)
9317 goto err_out;
9318
6039f6d2
JM
9319 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
9320 if (err)
9321 goto err_out;
9322
aff89a9b
JB
9323#ifdef CONFIG_NL80211_TESTMODE
9324 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
9325 if (err)
9326 goto err_out;
9327#endif
9328
026331c4
JM
9329 err = netlink_register_notifier(&nl80211_netlink_notifier);
9330 if (err)
9331 goto err_out;
9332
55682965
JB
9333 return 0;
9334 err_out:
9335 genl_unregister_family(&nl80211_fam);
9336 return err;
9337}
9338
9339void nl80211_exit(void)
9340{
026331c4 9341 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
9342 genl_unregister_family(&nl80211_fam);
9343}