]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
cfg80211/nl80211: fix kernel-doc
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
79c97e97 49/* internal helper: get rdev and dev */
00918d33
JB
50static int get_rdev_dev_by_ifindex(struct net *netns, struct nlattr **attrs,
51 struct cfg80211_registered_device **rdev,
52 struct net_device **dev)
55682965
JB
53{
54 int ifindex;
55
bba95fef 56 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
57 return -EINVAL;
58
bba95fef 59 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
00918d33 60 *dev = dev_get_by_index(netns, ifindex);
55682965
JB
61 if (!*dev)
62 return -ENODEV;
63
00918d33 64 *rdev = cfg80211_get_dev_from_ifindex(netns, ifindex);
79c97e97 65 if (IS_ERR(*rdev)) {
55682965 66 dev_put(*dev);
79c97e97 67 return PTR_ERR(*rdev);
55682965
JB
68 }
69
70 return 0;
71}
72
73/* policy for the attributes */
b54452b0 74static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
75 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
76 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 77 .len = 20-1 },
31888487 78 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 79 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 80 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
81 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
82 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
84 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 85 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
86
87 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
88 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 90
e007b857
EP
91 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
92 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 93
b9454e83 94 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
95 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
96 .len = WLAN_MAX_KEY_LEN },
97 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
98 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
99 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 100 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 101 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
102
103 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
104 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
105 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
106 .len = IEEE80211_MAX_DATA_LEN },
107 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
108 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
109 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
110 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
111 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
112 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 114 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 115 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 116 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 117 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 118 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 119 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 120
b2e1b302
LR
121 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
122 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
123
9f1ba906
JM
124 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
125 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
127 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
128 .len = NL80211_MAX_SUPP_RATES },
50b12f59 129 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 130
24bdd9f4 131 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 132 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 133
6c739419 134 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
135
136 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
137 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
138 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
139 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
140 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
141
142 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
143 .len = IEEE80211_MAX_SSID_LEN },
144 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
145 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 146 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 147 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 148 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
149 [NL80211_ATTR_STA_FLAGS2] = {
150 .len = sizeof(struct nl80211_sta_flag_update),
151 },
3f77316c 152 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
153 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
154 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
155 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
156 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
157 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 158 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 159 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
160 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
161 .len = WLAN_PMKID_LEN },
9588bbd5
JM
162 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
163 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 164 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
165 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
166 .len = IEEE80211_MAX_DATA_LEN },
167 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 168 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 169 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 170 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 171 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
172 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
173 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 174 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
175 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
176 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 177 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 178 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 179 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 180 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 181 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 182 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 183 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 184 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 185 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
186 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
187 .len = IEEE80211_MAX_DATA_LEN },
188 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
189 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 190 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 191 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 192 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
193 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
194 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
197 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 198 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
199 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
200 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 201 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
202 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
203 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
204 .len = NL80211_HT_CAPABILITY_LEN
205 },
1d9d9213 206 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 207 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 208 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
55682965
JB
209};
210
e31b8213 211/* policy for the key attributes */
b54452b0 212static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 213 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
214 [NL80211_KEY_IDX] = { .type = NLA_U8 },
215 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 216 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
217 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
218 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 219 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
220 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
221};
222
223/* policy for the key default flags */
224static const struct nla_policy
225nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
226 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
227 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
228};
229
ff1b6e69
JB
230/* policy for WoWLAN attributes */
231static const struct nla_policy
232nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
233 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
234 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
235 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
236 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
237 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
238 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
239 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
240 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
241};
242
e5497d76
JB
243/* policy for GTK rekey offload attributes */
244static const struct nla_policy
245nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
246 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
247 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
248 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
249};
250
a1f1c21c
LC
251static const struct nla_policy
252nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 253 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c
LC
254 .len = IEEE80211_MAX_SSID_LEN },
255};
256
a043897a
HS
257/* ifidx get helper */
258static int nl80211_get_ifidx(struct netlink_callback *cb)
259{
260 int res;
261
262 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
263 nl80211_fam.attrbuf, nl80211_fam.maxattr,
264 nl80211_policy);
265 if (res)
266 return res;
267
268 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
269 return -EINVAL;
270
271 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
272 if (!res)
273 return -EINVAL;
274 return res;
275}
276
67748893
JB
277static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
278 struct netlink_callback *cb,
279 struct cfg80211_registered_device **rdev,
280 struct net_device **dev)
281{
282 int ifidx = cb->args[0];
283 int err;
284
285 if (!ifidx)
286 ifidx = nl80211_get_ifidx(cb);
287 if (ifidx < 0)
288 return ifidx;
289
290 cb->args[0] = ifidx;
291
292 rtnl_lock();
293
294 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
295 if (!*dev) {
296 err = -ENODEV;
297 goto out_rtnl;
298 }
299
300 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
301 if (IS_ERR(*rdev)) {
302 err = PTR_ERR(*rdev);
67748893
JB
303 goto out_rtnl;
304 }
305
306 return 0;
307 out_rtnl:
308 rtnl_unlock();
309 return err;
310}
311
312static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
313{
314 cfg80211_unlock_rdev(rdev);
315 rtnl_unlock();
316}
317
f4a11bb0
JB
318/* IE validation */
319static bool is_valid_ie_attr(const struct nlattr *attr)
320{
321 const u8 *pos;
322 int len;
323
324 if (!attr)
325 return true;
326
327 pos = nla_data(attr);
328 len = nla_len(attr);
329
330 while (len) {
331 u8 elemlen;
332
333 if (len < 2)
334 return false;
335 len -= 2;
336
337 elemlen = pos[1];
338 if (elemlen > len)
339 return false;
340
341 len -= elemlen;
342 pos += 2 + elemlen;
343 }
344
345 return true;
346}
347
55682965
JB
348/* message building helper */
349static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
350 int flags, u8 cmd)
351{
352 /* since there is no private header just add the generic one */
353 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
354}
355
5dab3b8a
LR
356static int nl80211_msg_put_channel(struct sk_buff *msg,
357 struct ieee80211_channel *chan)
358{
9360ffd1
DM
359 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
360 chan->center_freq))
361 goto nla_put_failure;
5dab3b8a 362
9360ffd1
DM
363 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
364 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
365 goto nla_put_failure;
366 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
367 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
368 goto nla_put_failure;
369 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
370 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
371 goto nla_put_failure;
372 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
373 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
374 goto nla_put_failure;
5dab3b8a 375
9360ffd1
DM
376 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
377 DBM_TO_MBM(chan->max_power)))
378 goto nla_put_failure;
5dab3b8a
LR
379
380 return 0;
381
382 nla_put_failure:
383 return -ENOBUFS;
384}
385
55682965
JB
386/* netlink command implementations */
387
b9454e83
JB
388struct key_parse {
389 struct key_params p;
390 int idx;
e31b8213 391 int type;
b9454e83 392 bool def, defmgmt;
dbd2fd65 393 bool def_uni, def_multi;
b9454e83
JB
394};
395
396static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
397{
398 struct nlattr *tb[NL80211_KEY_MAX + 1];
399 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
400 nl80211_key_policy);
401 if (err)
402 return err;
403
404 k->def = !!tb[NL80211_KEY_DEFAULT];
405 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
406
dbd2fd65
JB
407 if (k->def) {
408 k->def_uni = true;
409 k->def_multi = true;
410 }
411 if (k->defmgmt)
412 k->def_multi = true;
413
b9454e83
JB
414 if (tb[NL80211_KEY_IDX])
415 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
416
417 if (tb[NL80211_KEY_DATA]) {
418 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
419 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
420 }
421
422 if (tb[NL80211_KEY_SEQ]) {
423 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
424 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
425 }
426
427 if (tb[NL80211_KEY_CIPHER])
428 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
429
e31b8213
JB
430 if (tb[NL80211_KEY_TYPE]) {
431 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
432 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
433 return -EINVAL;
434 }
435
dbd2fd65
JB
436 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
437 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
438 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
439 tb[NL80211_KEY_DEFAULT_TYPES],
440 nl80211_key_default_policy);
dbd2fd65
JB
441 if (err)
442 return err;
443
444 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
445 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
446 }
447
b9454e83
JB
448 return 0;
449}
450
451static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
452{
453 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
454 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
455 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
456 }
457
458 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
459 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
460 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
461 }
462
463 if (info->attrs[NL80211_ATTR_KEY_IDX])
464 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
465
466 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
467 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
468
469 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
470 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
471
dbd2fd65
JB
472 if (k->def) {
473 k->def_uni = true;
474 k->def_multi = true;
475 }
476 if (k->defmgmt)
477 k->def_multi = true;
478
e31b8213
JB
479 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
480 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
481 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
482 return -EINVAL;
483 }
484
dbd2fd65
JB
485 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
486 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
487 int err = nla_parse_nested(
488 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
489 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
490 nl80211_key_default_policy);
491 if (err)
492 return err;
493
494 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
495 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
496 }
497
b9454e83
JB
498 return 0;
499}
500
501static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
502{
503 int err;
504
505 memset(k, 0, sizeof(*k));
506 k->idx = -1;
e31b8213 507 k->type = -1;
b9454e83
JB
508
509 if (info->attrs[NL80211_ATTR_KEY])
510 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
511 else
512 err = nl80211_parse_key_old(info, k);
513
514 if (err)
515 return err;
516
517 if (k->def && k->defmgmt)
518 return -EINVAL;
519
dbd2fd65
JB
520 if (k->defmgmt) {
521 if (k->def_uni || !k->def_multi)
522 return -EINVAL;
523 }
524
b9454e83
JB
525 if (k->idx != -1) {
526 if (k->defmgmt) {
527 if (k->idx < 4 || k->idx > 5)
528 return -EINVAL;
529 } else if (k->def) {
530 if (k->idx < 0 || k->idx > 3)
531 return -EINVAL;
532 } else {
533 if (k->idx < 0 || k->idx > 5)
534 return -EINVAL;
535 }
536 }
537
538 return 0;
539}
540
fffd0934
JB
541static struct cfg80211_cached_keys *
542nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
543 struct nlattr *keys)
544{
545 struct key_parse parse;
546 struct nlattr *key;
547 struct cfg80211_cached_keys *result;
548 int rem, err, def = 0;
549
550 result = kzalloc(sizeof(*result), GFP_KERNEL);
551 if (!result)
552 return ERR_PTR(-ENOMEM);
553
554 result->def = -1;
555 result->defmgmt = -1;
556
557 nla_for_each_nested(key, keys, rem) {
558 memset(&parse, 0, sizeof(parse));
559 parse.idx = -1;
560
561 err = nl80211_parse_key_new(key, &parse);
562 if (err)
563 goto error;
564 err = -EINVAL;
565 if (!parse.p.key)
566 goto error;
567 if (parse.idx < 0 || parse.idx > 4)
568 goto error;
569 if (parse.def) {
570 if (def)
571 goto error;
572 def = 1;
573 result->def = parse.idx;
dbd2fd65
JB
574 if (!parse.def_uni || !parse.def_multi)
575 goto error;
fffd0934
JB
576 } else if (parse.defmgmt)
577 goto error;
578 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 579 parse.idx, false, NULL);
fffd0934
JB
580 if (err)
581 goto error;
582 result->params[parse.idx].cipher = parse.p.cipher;
583 result->params[parse.idx].key_len = parse.p.key_len;
584 result->params[parse.idx].key = result->data[parse.idx];
585 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
586 }
587
588 return result;
589 error:
590 kfree(result);
591 return ERR_PTR(err);
592}
593
594static int nl80211_key_allowed(struct wireless_dev *wdev)
595{
596 ASSERT_WDEV_LOCK(wdev);
597
fffd0934
JB
598 switch (wdev->iftype) {
599 case NL80211_IFTYPE_AP:
600 case NL80211_IFTYPE_AP_VLAN:
074ac8df 601 case NL80211_IFTYPE_P2P_GO:
ff973af7 602 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
603 break;
604 case NL80211_IFTYPE_ADHOC:
605 if (!wdev->current_bss)
606 return -ENOLINK;
607 break;
608 case NL80211_IFTYPE_STATION:
074ac8df 609 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
610 if (wdev->sme_state != CFG80211_SME_CONNECTED)
611 return -ENOLINK;
612 break;
613 default:
614 return -EINVAL;
615 }
616
617 return 0;
618}
619
7527a782
JB
620static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
621{
622 struct nlattr *nl_modes = nla_nest_start(msg, attr);
623 int i;
624
625 if (!nl_modes)
626 goto nla_put_failure;
627
628 i = 0;
629 while (ifmodes) {
9360ffd1
DM
630 if ((ifmodes & 1) && nla_put_flag(msg, i))
631 goto nla_put_failure;
7527a782
JB
632 ifmodes >>= 1;
633 i++;
634 }
635
636 nla_nest_end(msg, nl_modes);
637 return 0;
638
639nla_put_failure:
640 return -ENOBUFS;
641}
642
643static int nl80211_put_iface_combinations(struct wiphy *wiphy,
644 struct sk_buff *msg)
645{
646 struct nlattr *nl_combis;
647 int i, j;
648
649 nl_combis = nla_nest_start(msg,
650 NL80211_ATTR_INTERFACE_COMBINATIONS);
651 if (!nl_combis)
652 goto nla_put_failure;
653
654 for (i = 0; i < wiphy->n_iface_combinations; i++) {
655 const struct ieee80211_iface_combination *c;
656 struct nlattr *nl_combi, *nl_limits;
657
658 c = &wiphy->iface_combinations[i];
659
660 nl_combi = nla_nest_start(msg, i + 1);
661 if (!nl_combi)
662 goto nla_put_failure;
663
664 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
665 if (!nl_limits)
666 goto nla_put_failure;
667
668 for (j = 0; j < c->n_limits; j++) {
669 struct nlattr *nl_limit;
670
671 nl_limit = nla_nest_start(msg, j + 1);
672 if (!nl_limit)
673 goto nla_put_failure;
9360ffd1
DM
674 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
675 c->limits[j].max))
676 goto nla_put_failure;
7527a782
JB
677 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
678 c->limits[j].types))
679 goto nla_put_failure;
680 nla_nest_end(msg, nl_limit);
681 }
682
683 nla_nest_end(msg, nl_limits);
684
9360ffd1
DM
685 if (c->beacon_int_infra_match &&
686 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
687 goto nla_put_failure;
688 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
689 c->num_different_channels) ||
690 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
691 c->max_interfaces))
692 goto nla_put_failure;
7527a782
JB
693
694 nla_nest_end(msg, nl_combi);
695 }
696
697 nla_nest_end(msg, nl_combis);
698
699 return 0;
700nla_put_failure:
701 return -ENOBUFS;
702}
703
55682965
JB
704static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
705 struct cfg80211_registered_device *dev)
706{
707 void *hdr;
ee688b00
JB
708 struct nlattr *nl_bands, *nl_band;
709 struct nlattr *nl_freqs, *nl_freq;
710 struct nlattr *nl_rates, *nl_rate;
8fdc621d 711 struct nlattr *nl_cmds;
ee688b00
JB
712 enum ieee80211_band band;
713 struct ieee80211_channel *chan;
714 struct ieee80211_rate *rate;
715 int i;
2e161f78
JB
716 const struct ieee80211_txrx_stypes *mgmt_stypes =
717 dev->wiphy.mgmt_stypes;
55682965
JB
718
719 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
720 if (!hdr)
721 return -1;
722
9360ffd1
DM
723 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
724 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
725 nla_put_u32(msg, NL80211_ATTR_GENERATION,
726 cfg80211_rdev_list_generation) ||
727 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
728 dev->wiphy.retry_short) ||
729 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
730 dev->wiphy.retry_long) ||
731 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
732 dev->wiphy.frag_threshold) ||
733 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
734 dev->wiphy.rts_threshold) ||
735 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
736 dev->wiphy.coverage_class) ||
737 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
738 dev->wiphy.max_scan_ssids) ||
739 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
740 dev->wiphy.max_sched_scan_ssids) ||
741 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
742 dev->wiphy.max_scan_ie_len) ||
743 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
744 dev->wiphy.max_sched_scan_ie_len) ||
745 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
746 dev->wiphy.max_match_sets))
747 goto nla_put_failure;
748
749 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
750 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
751 goto nla_put_failure;
752 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
753 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
754 goto nla_put_failure;
755 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
756 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
757 goto nla_put_failure;
758 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
759 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
760 goto nla_put_failure;
761 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
762 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
763 goto nla_put_failure;
764 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
765 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
766 goto nla_put_failure;
767
768 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
769 sizeof(u32) * dev->wiphy.n_cipher_suites,
770 dev->wiphy.cipher_suites))
771 goto nla_put_failure;
772
773 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
774 dev->wiphy.max_num_pmkids))
775 goto nla_put_failure;
776
777 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
778 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
779 goto nla_put_failure;
780
781 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
782 dev->wiphy.available_antennas_tx) ||
783 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
784 dev->wiphy.available_antennas_rx))
785 goto nla_put_failure;
786
787 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
788 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
789 dev->wiphy.probe_resp_offload))
790 goto nla_put_failure;
87bbbe22 791
7f531e03
BR
792 if ((dev->wiphy.available_antennas_tx ||
793 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
794 u32 tx_ant = 0, rx_ant = 0;
795 int res;
796 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
797 if (!res) {
9360ffd1
DM
798 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
799 tx_ant) ||
800 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
801 rx_ant))
802 goto nla_put_failure;
afe0cbf8
BR
803 }
804 }
805
7527a782
JB
806 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
807 dev->wiphy.interface_modes))
f59ac048
LR
808 goto nla_put_failure;
809
ee688b00
JB
810 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
811 if (!nl_bands)
812 goto nla_put_failure;
813
814 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
815 if (!dev->wiphy.bands[band])
816 continue;
817
818 nl_band = nla_nest_start(msg, band);
819 if (!nl_band)
820 goto nla_put_failure;
821
d51626df 822 /* add HT info */
9360ffd1
DM
823 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
824 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
825 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
826 &dev->wiphy.bands[band]->ht_cap.mcs) ||
827 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
828 dev->wiphy.bands[band]->ht_cap.cap) ||
829 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
830 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
831 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
832 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
833 goto nla_put_failure;
d51626df 834
ee688b00
JB
835 /* add frequencies */
836 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
837 if (!nl_freqs)
838 goto nla_put_failure;
839
840 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
841 nl_freq = nla_nest_start(msg, i);
842 if (!nl_freq)
843 goto nla_put_failure;
844
845 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
846
847 if (nl80211_msg_put_channel(msg, chan))
848 goto nla_put_failure;
e2f367f2 849
ee688b00
JB
850 nla_nest_end(msg, nl_freq);
851 }
852
853 nla_nest_end(msg, nl_freqs);
854
855 /* add bitrates */
856 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
857 if (!nl_rates)
858 goto nla_put_failure;
859
860 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
861 nl_rate = nla_nest_start(msg, i);
862 if (!nl_rate)
863 goto nla_put_failure;
864
865 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
866 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
867 rate->bitrate))
868 goto nla_put_failure;
869 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
870 nla_put_flag(msg,
871 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
872 goto nla_put_failure;
ee688b00
JB
873
874 nla_nest_end(msg, nl_rate);
875 }
876
877 nla_nest_end(msg, nl_rates);
878
879 nla_nest_end(msg, nl_band);
880 }
881 nla_nest_end(msg, nl_bands);
882
8fdc621d
JB
883 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
884 if (!nl_cmds)
885 goto nla_put_failure;
886
887 i = 0;
888#define CMD(op, n) \
889 do { \
890 if (dev->ops->op) { \
891 i++; \
9360ffd1
DM
892 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
893 goto nla_put_failure; \
8fdc621d
JB
894 } \
895 } while (0)
896
897 CMD(add_virtual_intf, NEW_INTERFACE);
898 CMD(change_virtual_intf, SET_INTERFACE);
899 CMD(add_key, NEW_KEY);
8860020e 900 CMD(start_ap, START_AP);
8fdc621d
JB
901 CMD(add_station, NEW_STATION);
902 CMD(add_mpath, NEW_MPATH);
24bdd9f4 903 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 904 CMD(change_bss, SET_BSS);
636a5d36
JM
905 CMD(auth, AUTHENTICATE);
906 CMD(assoc, ASSOCIATE);
907 CMD(deauth, DEAUTHENTICATE);
908 CMD(disassoc, DISASSOCIATE);
04a773ad 909 CMD(join_ibss, JOIN_IBSS);
29cbe68c 910 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
911 CMD(set_pmksa, SET_PMKSA);
912 CMD(del_pmksa, DEL_PMKSA);
913 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
914 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
915 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 916 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 917 CMD(mgmt_tx, FRAME);
f7ca38df 918 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 919 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 920 i++;
9360ffd1
DM
921 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
922 goto nla_put_failure;
463d0183 923 }
e8c9bd5b 924 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 925 dev->ops->join_mesh) {
aa430da4
JB
926 i++;
927 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
928 goto nla_put_failure;
929 }
e8347eba 930 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
931 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
932 CMD(tdls_mgmt, TDLS_MGMT);
933 CMD(tdls_oper, TDLS_OPER);
934 }
807f8a8c
LC
935 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
936 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 937 CMD(probe_client, PROBE_CLIENT);
1d9d9213 938 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
939 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
940 i++;
9360ffd1
DM
941 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
942 goto nla_put_failure;
5e760230 943 }
8fdc621d 944
4745fc09
KV
945#ifdef CONFIG_NL80211_TESTMODE
946 CMD(testmode_cmd, TESTMODE);
947#endif
948
8fdc621d 949#undef CMD
b23aa676 950
6829c878 951 if (dev->ops->connect || dev->ops->auth) {
b23aa676 952 i++;
9360ffd1
DM
953 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
954 goto nla_put_failure;
b23aa676
SO
955 }
956
6829c878 957 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 958 i++;
9360ffd1
DM
959 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
960 goto nla_put_failure;
b23aa676
SO
961 }
962
8fdc621d
JB
963 nla_nest_end(msg, nl_cmds);
964
7c4ef712 965 if (dev->ops->remain_on_channel &&
9360ffd1
DM
966 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
967 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
968 dev->wiphy.max_remain_on_channel_duration))
969 goto nla_put_failure;
a293911d 970
9360ffd1
DM
971 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
972 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
973 goto nla_put_failure;
f7ca38df 974
2e161f78
JB
975 if (mgmt_stypes) {
976 u16 stypes;
977 struct nlattr *nl_ftypes, *nl_ifs;
978 enum nl80211_iftype ift;
979
980 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
981 if (!nl_ifs)
982 goto nla_put_failure;
983
984 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
985 nl_ftypes = nla_nest_start(msg, ift);
986 if (!nl_ftypes)
987 goto nla_put_failure;
988 i = 0;
989 stypes = mgmt_stypes[ift].tx;
990 while (stypes) {
9360ffd1
DM
991 if ((stypes & 1) &&
992 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
993 (i << 4) | IEEE80211_FTYPE_MGMT))
994 goto nla_put_failure;
2e161f78
JB
995 stypes >>= 1;
996 i++;
997 }
998 nla_nest_end(msg, nl_ftypes);
999 }
1000
74b70a4e
JB
1001 nla_nest_end(msg, nl_ifs);
1002
2e161f78
JB
1003 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1004 if (!nl_ifs)
1005 goto nla_put_failure;
1006
1007 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1008 nl_ftypes = nla_nest_start(msg, ift);
1009 if (!nl_ftypes)
1010 goto nla_put_failure;
1011 i = 0;
1012 stypes = mgmt_stypes[ift].rx;
1013 while (stypes) {
9360ffd1
DM
1014 if ((stypes & 1) &&
1015 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1016 (i << 4) | IEEE80211_FTYPE_MGMT))
1017 goto nla_put_failure;
2e161f78
JB
1018 stypes >>= 1;
1019 i++;
1020 }
1021 nla_nest_end(msg, nl_ftypes);
1022 }
1023 nla_nest_end(msg, nl_ifs);
1024 }
1025
ff1b6e69
JB
1026 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1027 struct nlattr *nl_wowlan;
1028
1029 nl_wowlan = nla_nest_start(msg,
1030 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1031 if (!nl_wowlan)
1032 goto nla_put_failure;
1033
9360ffd1
DM
1034 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1035 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1036 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1037 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1038 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1039 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1040 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1041 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1042 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1043 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1044 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1045 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1046 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1047 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1048 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1049 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1050 goto nla_put_failure;
ff1b6e69
JB
1051 if (dev->wiphy.wowlan.n_patterns) {
1052 struct nl80211_wowlan_pattern_support pat = {
1053 .max_patterns = dev->wiphy.wowlan.n_patterns,
1054 .min_pattern_len =
1055 dev->wiphy.wowlan.pattern_min_len,
1056 .max_pattern_len =
1057 dev->wiphy.wowlan.pattern_max_len,
1058 };
9360ffd1
DM
1059 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1060 sizeof(pat), &pat))
1061 goto nla_put_failure;
ff1b6e69
JB
1062 }
1063
1064 nla_nest_end(msg, nl_wowlan);
1065 }
1066
7527a782
JB
1067 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1068 dev->wiphy.software_iftypes))
1069 goto nla_put_failure;
1070
1071 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1072 goto nla_put_failure;
1073
9360ffd1
DM
1074 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1075 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1076 dev->wiphy.ap_sme_capa))
1077 goto nla_put_failure;
562a7480 1078
9360ffd1
DM
1079 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1080 dev->wiphy.features))
1081 goto nla_put_failure;
1f074bd8 1082
9360ffd1
DM
1083 if (dev->wiphy.ht_capa_mod_mask &&
1084 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1085 sizeof(*dev->wiphy.ht_capa_mod_mask),
1086 dev->wiphy.ht_capa_mod_mask))
1087 goto nla_put_failure;
7e7c8926 1088
55682965
JB
1089 return genlmsg_end(msg, hdr);
1090
1091 nla_put_failure:
bc3ed28c
TG
1092 genlmsg_cancel(msg, hdr);
1093 return -EMSGSIZE;
55682965
JB
1094}
1095
1096static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1097{
1098 int idx = 0;
1099 int start = cb->args[0];
1100 struct cfg80211_registered_device *dev;
1101
a1794390 1102 mutex_lock(&cfg80211_mutex);
79c97e97 1103 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1104 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1105 continue;
b4637271 1106 if (++idx <= start)
55682965
JB
1107 continue;
1108 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1109 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1110 dev) < 0) {
1111 idx--;
55682965 1112 break;
b4637271 1113 }
55682965 1114 }
a1794390 1115 mutex_unlock(&cfg80211_mutex);
55682965
JB
1116
1117 cb->args[0] = idx;
1118
1119 return skb->len;
1120}
1121
1122static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1123{
1124 struct sk_buff *msg;
4c476991 1125 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1126
fd2120ca 1127 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1128 if (!msg)
4c476991 1129 return -ENOMEM;
55682965 1130
4c476991
JB
1131 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1132 nlmsg_free(msg);
1133 return -ENOBUFS;
1134 }
55682965 1135
134e6375 1136 return genlmsg_reply(msg, info);
55682965
JB
1137}
1138
31888487
JM
1139static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1140 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1141 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1142 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1143 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1144 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1145};
1146
1147static int parse_txq_params(struct nlattr *tb[],
1148 struct ieee80211_txq_params *txq_params)
1149{
a3304b0a 1150 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1151 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1152 !tb[NL80211_TXQ_ATTR_AIFS])
1153 return -EINVAL;
1154
a3304b0a 1155 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1156 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1157 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1158 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1159 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1160
a3304b0a
JB
1161 if (txq_params->ac >= NL80211_NUM_ACS)
1162 return -EINVAL;
1163
31888487
JM
1164 return 0;
1165}
1166
f444de05
JB
1167static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1168{
1169 /*
cc1d2806
JB
1170 * You can only set the channel explicitly for WDS interfaces,
1171 * all others have their channel managed via their respective
1172 * "establish a connection" command (connect, join, ...)
1173 *
1174 * For AP/GO and mesh mode, the channel can be set with the
1175 * channel userspace API, but is only stored and passed to the
1176 * low-level driver when the AP starts or the mesh is joined.
1177 * This is for backward compatibility, userspace can also give
1178 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1179 *
1180 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1181 * whatever else is going on, so they have their own special
1182 * operation to set the monitor channel if possible.
f444de05
JB
1183 */
1184 return !wdev ||
1185 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1186 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1187 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1188 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1189}
1190
cd6c6598
JB
1191static bool nl80211_valid_channel_type(struct genl_info *info,
1192 enum nl80211_channel_type *channel_type)
1193{
1194 enum nl80211_channel_type tmp;
1195
1196 if (!info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE])
1197 return false;
1198
1199 tmp = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1200 if (tmp != NL80211_CHAN_NO_HT &&
1201 tmp != NL80211_CHAN_HT20 &&
1202 tmp != NL80211_CHAN_HT40PLUS &&
1203 tmp != NL80211_CHAN_HT40MINUS)
1204 return false;
1205
1206 if (channel_type)
1207 *channel_type = tmp;
1208
1209 return true;
1210}
1211
f444de05
JB
1212static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1213 struct wireless_dev *wdev,
1214 struct genl_info *info)
1215{
aa430da4 1216 struct ieee80211_channel *channel;
f444de05
JB
1217 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1218 u32 freq;
1219 int result;
e8c9bd5b
JB
1220 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1221
1222 if (wdev)
1223 iftype = wdev->iftype;
f444de05
JB
1224
1225 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1226 return -EINVAL;
1227
1228 if (!nl80211_can_set_dev_channel(wdev))
1229 return -EOPNOTSUPP;
1230
cd6c6598
JB
1231 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
1232 !nl80211_valid_channel_type(info, &channel_type))
1233 return -EINVAL;
f444de05
JB
1234
1235 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1236
1237 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1238 switch (iftype) {
aa430da4
JB
1239 case NL80211_IFTYPE_AP:
1240 case NL80211_IFTYPE_P2P_GO:
1241 if (wdev->beacon_interval) {
1242 result = -EBUSY;
1243 break;
1244 }
1245 channel = rdev_freq_to_chan(rdev, freq, channel_type);
1246 if (!channel || !cfg80211_can_beacon_sec_chan(&rdev->wiphy,
1247 channel,
1248 channel_type)) {
1249 result = -EINVAL;
1250 break;
1251 }
1252 wdev->preset_chan = channel;
1253 wdev->preset_chantype = channel_type;
1254 result = 0;
1255 break;
cc1d2806
JB
1256 case NL80211_IFTYPE_MESH_POINT:
1257 result = cfg80211_set_mesh_freq(rdev, wdev, freq, channel_type);
1258 break;
e8c9bd5b
JB
1259 case NL80211_IFTYPE_MONITOR:
1260 result = cfg80211_set_monitor_channel(rdev, freq, channel_type);
1261 break;
aa430da4 1262 default:
e8c9bd5b 1263 result = -EINVAL;
f444de05
JB
1264 }
1265 mutex_unlock(&rdev->devlist_mtx);
1266
1267 return result;
1268}
1269
1270static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1271{
4c476991
JB
1272 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1273 struct net_device *netdev = info->user_ptr[1];
f444de05 1274
4c476991 1275 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1276}
1277
e8347eba
BJ
1278static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1279{
43b19952
JB
1280 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1281 struct net_device *dev = info->user_ptr[1];
1282 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1283 const u8 *bssid;
e8347eba
BJ
1284
1285 if (!info->attrs[NL80211_ATTR_MAC])
1286 return -EINVAL;
1287
43b19952
JB
1288 if (netif_running(dev))
1289 return -EBUSY;
e8347eba 1290
43b19952
JB
1291 if (!rdev->ops->set_wds_peer)
1292 return -EOPNOTSUPP;
e8347eba 1293
43b19952
JB
1294 if (wdev->iftype != NL80211_IFTYPE_WDS)
1295 return -EOPNOTSUPP;
e8347eba
BJ
1296
1297 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1298 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1299}
1300
1301
55682965
JB
1302static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1303{
1304 struct cfg80211_registered_device *rdev;
f444de05
JB
1305 struct net_device *netdev = NULL;
1306 struct wireless_dev *wdev;
a1e567c8 1307 int result = 0, rem_txq_params = 0;
31888487 1308 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1309 u32 changed;
1310 u8 retry_short = 0, retry_long = 0;
1311 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1312 u8 coverage_class = 0;
55682965 1313
f444de05
JB
1314 /*
1315 * Try to find the wiphy and netdev. Normally this
1316 * function shouldn't need the netdev, but this is
1317 * done for backward compatibility -- previously
1318 * setting the channel was done per wiphy, but now
1319 * it is per netdev. Previous userland like hostapd
1320 * also passed a netdev to set_wiphy, so that it is
1321 * possible to let that go to the right netdev!
1322 */
4bbf4d56
JB
1323 mutex_lock(&cfg80211_mutex);
1324
f444de05
JB
1325 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1326 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1327
1328 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1329 if (netdev && netdev->ieee80211_ptr) {
1330 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1331 mutex_lock(&rdev->mtx);
1332 } else
1333 netdev = NULL;
4bbf4d56
JB
1334 }
1335
f444de05
JB
1336 if (!netdev) {
1337 rdev = __cfg80211_rdev_from_info(info);
1338 if (IS_ERR(rdev)) {
1339 mutex_unlock(&cfg80211_mutex);
4c476991 1340 return PTR_ERR(rdev);
f444de05
JB
1341 }
1342 wdev = NULL;
1343 netdev = NULL;
1344 result = 0;
1345
1346 mutex_lock(&rdev->mtx);
cc1d2806 1347 } else if (nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
f444de05
JB
1348 wdev = netdev->ieee80211_ptr;
1349 else
1350 wdev = NULL;
1351
1352 /*
1353 * end workaround code, by now the rdev is available
1354 * and locked, and wdev may or may not be NULL.
1355 */
4bbf4d56
JB
1356
1357 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1358 result = cfg80211_dev_rename(
1359 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1360
1361 mutex_unlock(&cfg80211_mutex);
1362
1363 if (result)
1364 goto bad_res;
31888487
JM
1365
1366 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1367 struct ieee80211_txq_params txq_params;
1368 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1369
1370 if (!rdev->ops->set_txq_params) {
1371 result = -EOPNOTSUPP;
1372 goto bad_res;
1373 }
1374
f70f01c2
EP
1375 if (!netdev) {
1376 result = -EINVAL;
1377 goto bad_res;
1378 }
1379
133a3ff2
JB
1380 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1381 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1382 result = -EINVAL;
1383 goto bad_res;
1384 }
1385
2b5f8b0b
JB
1386 if (!netif_running(netdev)) {
1387 result = -ENETDOWN;
1388 goto bad_res;
1389 }
1390
31888487
JM
1391 nla_for_each_nested(nl_txq_params,
1392 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1393 rem_txq_params) {
1394 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1395 nla_data(nl_txq_params),
1396 nla_len(nl_txq_params),
1397 txq_params_policy);
1398 result = parse_txq_params(tb, &txq_params);
1399 if (result)
1400 goto bad_res;
1401
1402 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1403 netdev,
31888487
JM
1404 &txq_params);
1405 if (result)
1406 goto bad_res;
1407 }
1408 }
55682965 1409
72bdcf34 1410 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1411 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1412 if (result)
1413 goto bad_res;
1414 }
1415
98d2ff8b
JO
1416 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1417 enum nl80211_tx_power_setting type;
1418 int idx, mbm = 0;
1419
1420 if (!rdev->ops->set_tx_power) {
60ea385f 1421 result = -EOPNOTSUPP;
98d2ff8b
JO
1422 goto bad_res;
1423 }
1424
1425 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1426 type = nla_get_u32(info->attrs[idx]);
1427
1428 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1429 (type != NL80211_TX_POWER_AUTOMATIC)) {
1430 result = -EINVAL;
1431 goto bad_res;
1432 }
1433
1434 if (type != NL80211_TX_POWER_AUTOMATIC) {
1435 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1436 mbm = nla_get_u32(info->attrs[idx]);
1437 }
1438
1439 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1440 if (result)
1441 goto bad_res;
1442 }
1443
afe0cbf8
BR
1444 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1445 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1446 u32 tx_ant, rx_ant;
7f531e03
BR
1447 if ((!rdev->wiphy.available_antennas_tx &&
1448 !rdev->wiphy.available_antennas_rx) ||
1449 !rdev->ops->set_antenna) {
afe0cbf8
BR
1450 result = -EOPNOTSUPP;
1451 goto bad_res;
1452 }
1453
1454 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1455 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1456
a7ffac95 1457 /* reject antenna configurations which don't match the
7f531e03
BR
1458 * available antenna masks, except for the "all" mask */
1459 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1460 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1461 result = -EINVAL;
1462 goto bad_res;
1463 }
1464
7f531e03
BR
1465 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1466 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1467
afe0cbf8
BR
1468 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1469 if (result)
1470 goto bad_res;
1471 }
1472
b9a5f8ca
JM
1473 changed = 0;
1474
1475 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1476 retry_short = nla_get_u8(
1477 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1478 if (retry_short == 0) {
1479 result = -EINVAL;
1480 goto bad_res;
1481 }
1482 changed |= WIPHY_PARAM_RETRY_SHORT;
1483 }
1484
1485 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1486 retry_long = nla_get_u8(
1487 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1488 if (retry_long == 0) {
1489 result = -EINVAL;
1490 goto bad_res;
1491 }
1492 changed |= WIPHY_PARAM_RETRY_LONG;
1493 }
1494
1495 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1496 frag_threshold = nla_get_u32(
1497 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1498 if (frag_threshold < 256) {
1499 result = -EINVAL;
1500 goto bad_res;
1501 }
1502 if (frag_threshold != (u32) -1) {
1503 /*
1504 * Fragments (apart from the last one) are required to
1505 * have even length. Make the fragmentation code
1506 * simpler by stripping LSB should someone try to use
1507 * odd threshold value.
1508 */
1509 frag_threshold &= ~0x1;
1510 }
1511 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1512 }
1513
1514 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1515 rts_threshold = nla_get_u32(
1516 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1517 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1518 }
1519
81077e82
LT
1520 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1521 coverage_class = nla_get_u8(
1522 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1523 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1524 }
1525
b9a5f8ca
JM
1526 if (changed) {
1527 u8 old_retry_short, old_retry_long;
1528 u32 old_frag_threshold, old_rts_threshold;
81077e82 1529 u8 old_coverage_class;
b9a5f8ca
JM
1530
1531 if (!rdev->ops->set_wiphy_params) {
1532 result = -EOPNOTSUPP;
1533 goto bad_res;
1534 }
1535
1536 old_retry_short = rdev->wiphy.retry_short;
1537 old_retry_long = rdev->wiphy.retry_long;
1538 old_frag_threshold = rdev->wiphy.frag_threshold;
1539 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1540 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1541
1542 if (changed & WIPHY_PARAM_RETRY_SHORT)
1543 rdev->wiphy.retry_short = retry_short;
1544 if (changed & WIPHY_PARAM_RETRY_LONG)
1545 rdev->wiphy.retry_long = retry_long;
1546 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1547 rdev->wiphy.frag_threshold = frag_threshold;
1548 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1549 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1550 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1551 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1552
1553 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1554 if (result) {
1555 rdev->wiphy.retry_short = old_retry_short;
1556 rdev->wiphy.retry_long = old_retry_long;
1557 rdev->wiphy.frag_threshold = old_frag_threshold;
1558 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1559 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1560 }
1561 }
72bdcf34 1562
306d6112 1563 bad_res:
4bbf4d56 1564 mutex_unlock(&rdev->mtx);
f444de05
JB
1565 if (netdev)
1566 dev_put(netdev);
55682965
JB
1567 return result;
1568}
1569
1570
1571static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1572 struct cfg80211_registered_device *rdev,
55682965
JB
1573 struct net_device *dev)
1574{
1575 void *hdr;
1576
1577 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1578 if (!hdr)
1579 return -1;
1580
9360ffd1
DM
1581 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
1582 nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1583 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name) ||
1584 nla_put_u32(msg, NL80211_ATTR_IFTYPE,
1585 dev->ieee80211_ptr->iftype) ||
1586 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1587 rdev->devlist_generation ^
1588 (cfg80211_rdev_list_generation << 2)))
1589 goto nla_put_failure;
f5ea9120 1590
d91df0e3
PF
1591 if (rdev->ops->get_channel) {
1592 struct ieee80211_channel *chan;
1593 enum nl80211_channel_type channel_type;
1594
1595 chan = rdev->ops->get_channel(&rdev->wiphy, &channel_type);
59ef43e6
JL
1596 if (chan &&
1597 (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1598 chan->center_freq) ||
1599 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1600 channel_type)))
1601 goto nla_put_failure;
d91df0e3
PF
1602 }
1603
55682965
JB
1604 return genlmsg_end(msg, hdr);
1605
1606 nla_put_failure:
bc3ed28c
TG
1607 genlmsg_cancel(msg, hdr);
1608 return -EMSGSIZE;
55682965
JB
1609}
1610
1611static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1612{
1613 int wp_idx = 0;
1614 int if_idx = 0;
1615 int wp_start = cb->args[0];
1616 int if_start = cb->args[1];
f5ea9120 1617 struct cfg80211_registered_device *rdev;
55682965
JB
1618 struct wireless_dev *wdev;
1619
a1794390 1620 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1621 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1622 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1623 continue;
bba95fef
JB
1624 if (wp_idx < wp_start) {
1625 wp_idx++;
55682965 1626 continue;
bba95fef 1627 }
55682965
JB
1628 if_idx = 0;
1629
f5ea9120
JB
1630 mutex_lock(&rdev->devlist_mtx);
1631 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1632 if (if_idx < if_start) {
1633 if_idx++;
55682965 1634 continue;
bba95fef 1635 }
55682965
JB
1636 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1637 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1638 rdev, wdev->netdev) < 0) {
1639 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1640 goto out;
1641 }
1642 if_idx++;
55682965 1643 }
f5ea9120 1644 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1645
1646 wp_idx++;
55682965 1647 }
bba95fef 1648 out:
a1794390 1649 mutex_unlock(&cfg80211_mutex);
55682965
JB
1650
1651 cb->args[0] = wp_idx;
1652 cb->args[1] = if_idx;
1653
1654 return skb->len;
1655}
1656
1657static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1658{
1659 struct sk_buff *msg;
4c476991
JB
1660 struct cfg80211_registered_device *dev = info->user_ptr[0];
1661 struct net_device *netdev = info->user_ptr[1];
55682965 1662
fd2120ca 1663 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1664 if (!msg)
4c476991 1665 return -ENOMEM;
55682965 1666
d726405a 1667 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1668 dev, netdev) < 0) {
1669 nlmsg_free(msg);
1670 return -ENOBUFS;
1671 }
55682965 1672
134e6375 1673 return genlmsg_reply(msg, info);
55682965
JB
1674}
1675
66f7ac50
MW
1676static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1677 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1678 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1679 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1680 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1681 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1682};
1683
1684static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1685{
1686 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1687 int flag;
1688
1689 *mntrflags = 0;
1690
1691 if (!nla)
1692 return -EINVAL;
1693
1694 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1695 nla, mntr_flags_policy))
1696 return -EINVAL;
1697
1698 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1699 if (flags[flag])
1700 *mntrflags |= (1<<flag);
1701
1702 return 0;
1703}
1704
9bc383de 1705static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1706 struct net_device *netdev, u8 use_4addr,
1707 enum nl80211_iftype iftype)
9bc383de 1708{
ad4bb6f8 1709 if (!use_4addr) {
f350a0a8 1710 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1711 return -EBUSY;
9bc383de 1712 return 0;
ad4bb6f8 1713 }
9bc383de
JB
1714
1715 switch (iftype) {
1716 case NL80211_IFTYPE_AP_VLAN:
1717 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1718 return 0;
1719 break;
1720 case NL80211_IFTYPE_STATION:
1721 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1722 return 0;
1723 break;
1724 default:
1725 break;
1726 }
1727
1728 return -EOPNOTSUPP;
1729}
1730
55682965
JB
1731static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1732{
4c476991 1733 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1734 struct vif_params params;
e36d56b6 1735 int err;
04a773ad 1736 enum nl80211_iftype otype, ntype;
4c476991 1737 struct net_device *dev = info->user_ptr[1];
92ffe055 1738 u32 _flags, *flags = NULL;
ac7f9cfa 1739 bool change = false;
55682965 1740
2ec600d6
LCC
1741 memset(&params, 0, sizeof(params));
1742
04a773ad 1743 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1744
723b038d 1745 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1746 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1747 if (otype != ntype)
ac7f9cfa 1748 change = true;
4c476991
JB
1749 if (ntype > NL80211_IFTYPE_MAX)
1750 return -EINVAL;
723b038d
JB
1751 }
1752
92ffe055 1753 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1754 struct wireless_dev *wdev = dev->ieee80211_ptr;
1755
4c476991
JB
1756 if (ntype != NL80211_IFTYPE_MESH_POINT)
1757 return -EINVAL;
29cbe68c
JB
1758 if (netif_running(dev))
1759 return -EBUSY;
1760
1761 wdev_lock(wdev);
1762 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1763 IEEE80211_MAX_MESH_ID_LEN);
1764 wdev->mesh_id_up_len =
1765 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1766 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1767 wdev->mesh_id_up_len);
1768 wdev_unlock(wdev);
2ec600d6
LCC
1769 }
1770
8b787643
FF
1771 if (info->attrs[NL80211_ATTR_4ADDR]) {
1772 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1773 change = true;
ad4bb6f8 1774 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1775 if (err)
4c476991 1776 return err;
8b787643
FF
1777 } else {
1778 params.use_4addr = -1;
1779 }
1780
92ffe055 1781 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1782 if (ntype != NL80211_IFTYPE_MONITOR)
1783 return -EINVAL;
92ffe055
JB
1784 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1785 &_flags);
ac7f9cfa 1786 if (err)
4c476991 1787 return err;
ac7f9cfa
JB
1788
1789 flags = &_flags;
1790 change = true;
92ffe055 1791 }
3b85875a 1792
ac7f9cfa 1793 if (change)
3d54d255 1794 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1795 else
1796 err = 0;
60719ffd 1797
9bc383de
JB
1798 if (!err && params.use_4addr != -1)
1799 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1800
55682965
JB
1801 return err;
1802}
1803
1804static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1805{
4c476991 1806 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1807 struct vif_params params;
f9e10ce4 1808 struct net_device *dev;
55682965
JB
1809 int err;
1810 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1811 u32 flags;
55682965 1812
2ec600d6
LCC
1813 memset(&params, 0, sizeof(params));
1814
55682965
JB
1815 if (!info->attrs[NL80211_ATTR_IFNAME])
1816 return -EINVAL;
1817
1818 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1819 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1820 if (type > NL80211_IFTYPE_MAX)
1821 return -EINVAL;
1822 }
1823
79c97e97 1824 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1825 !(rdev->wiphy.interface_modes & (1 << type)))
1826 return -EOPNOTSUPP;
55682965 1827
9bc383de 1828 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1829 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1830 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1831 if (err)
4c476991 1832 return err;
9bc383de 1833 }
8b787643 1834
66f7ac50
MW
1835 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1836 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1837 &flags);
f9e10ce4 1838 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1839 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1840 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1841 if (IS_ERR(dev))
1842 return PTR_ERR(dev);
2ec600d6 1843
29cbe68c
JB
1844 if (type == NL80211_IFTYPE_MESH_POINT &&
1845 info->attrs[NL80211_ATTR_MESH_ID]) {
1846 struct wireless_dev *wdev = dev->ieee80211_ptr;
1847
1848 wdev_lock(wdev);
1849 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1850 IEEE80211_MAX_MESH_ID_LEN);
1851 wdev->mesh_id_up_len =
1852 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1853 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1854 wdev->mesh_id_up_len);
1855 wdev_unlock(wdev);
1856 }
1857
f9e10ce4 1858 return 0;
55682965
JB
1859}
1860
1861static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1862{
4c476991
JB
1863 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1864 struct net_device *dev = info->user_ptr[1];
55682965 1865
4c476991
JB
1866 if (!rdev->ops->del_virtual_intf)
1867 return -EOPNOTSUPP;
55682965 1868
4c476991 1869 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1870}
1871
1d9d9213
SW
1872static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
1873{
1874 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1875 struct net_device *dev = info->user_ptr[1];
1876 u16 noack_map;
1877
1878 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
1879 return -EINVAL;
1880
1881 if (!rdev->ops->set_noack_map)
1882 return -EOPNOTSUPP;
1883
1884 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
1885
1886 return rdev->ops->set_noack_map(&rdev->wiphy, dev, noack_map);
1887}
1888
41ade00f
JB
1889struct get_key_cookie {
1890 struct sk_buff *msg;
1891 int error;
b9454e83 1892 int idx;
41ade00f
JB
1893};
1894
1895static void get_key_callback(void *c, struct key_params *params)
1896{
b9454e83 1897 struct nlattr *key;
41ade00f
JB
1898 struct get_key_cookie *cookie = c;
1899
9360ffd1
DM
1900 if ((params->key &&
1901 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
1902 params->key_len, params->key)) ||
1903 (params->seq &&
1904 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
1905 params->seq_len, params->seq)) ||
1906 (params->cipher &&
1907 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1908 params->cipher)))
1909 goto nla_put_failure;
41ade00f 1910
b9454e83
JB
1911 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1912 if (!key)
1913 goto nla_put_failure;
1914
9360ffd1
DM
1915 if ((params->key &&
1916 nla_put(cookie->msg, NL80211_KEY_DATA,
1917 params->key_len, params->key)) ||
1918 (params->seq &&
1919 nla_put(cookie->msg, NL80211_KEY_SEQ,
1920 params->seq_len, params->seq)) ||
1921 (params->cipher &&
1922 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
1923 params->cipher)))
1924 goto nla_put_failure;
b9454e83 1925
9360ffd1
DM
1926 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
1927 goto nla_put_failure;
b9454e83
JB
1928
1929 nla_nest_end(cookie->msg, key);
1930
41ade00f
JB
1931 return;
1932 nla_put_failure:
1933 cookie->error = 1;
1934}
1935
1936static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1937{
4c476991 1938 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1939 int err;
4c476991 1940 struct net_device *dev = info->user_ptr[1];
41ade00f 1941 u8 key_idx = 0;
e31b8213
JB
1942 const u8 *mac_addr = NULL;
1943 bool pairwise;
41ade00f
JB
1944 struct get_key_cookie cookie = {
1945 .error = 0,
1946 };
1947 void *hdr;
1948 struct sk_buff *msg;
1949
1950 if (info->attrs[NL80211_ATTR_KEY_IDX])
1951 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1952
3cfcf6ac 1953 if (key_idx > 5)
41ade00f
JB
1954 return -EINVAL;
1955
1956 if (info->attrs[NL80211_ATTR_MAC])
1957 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1958
e31b8213
JB
1959 pairwise = !!mac_addr;
1960 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1961 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1962 if (kt >= NUM_NL80211_KEYTYPES)
1963 return -EINVAL;
1964 if (kt != NL80211_KEYTYPE_GROUP &&
1965 kt != NL80211_KEYTYPE_PAIRWISE)
1966 return -EINVAL;
1967 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1968 }
1969
4c476991
JB
1970 if (!rdev->ops->get_key)
1971 return -EOPNOTSUPP;
41ade00f 1972
fd2120ca 1973 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1974 if (!msg)
1975 return -ENOMEM;
41ade00f
JB
1976
1977 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1978 NL80211_CMD_NEW_KEY);
4c476991
JB
1979 if (IS_ERR(hdr))
1980 return PTR_ERR(hdr);
41ade00f
JB
1981
1982 cookie.msg = msg;
b9454e83 1983 cookie.idx = key_idx;
41ade00f 1984
9360ffd1
DM
1985 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
1986 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
1987 goto nla_put_failure;
1988 if (mac_addr &&
1989 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
1990 goto nla_put_failure;
41ade00f 1991
e31b8213
JB
1992 if (pairwise && mac_addr &&
1993 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1994 return -ENOENT;
1995
1996 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1997 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1998
1999 if (err)
6c95e2a2 2000 goto free_msg;
41ade00f
JB
2001
2002 if (cookie.error)
2003 goto nla_put_failure;
2004
2005 genlmsg_end(msg, hdr);
4c476991 2006 return genlmsg_reply(msg, info);
41ade00f
JB
2007
2008 nla_put_failure:
2009 err = -ENOBUFS;
6c95e2a2 2010 free_msg:
41ade00f 2011 nlmsg_free(msg);
41ade00f
JB
2012 return err;
2013}
2014
2015static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2016{
4c476991 2017 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2018 struct key_parse key;
41ade00f 2019 int err;
4c476991 2020 struct net_device *dev = info->user_ptr[1];
41ade00f 2021
b9454e83
JB
2022 err = nl80211_parse_key(info, &key);
2023 if (err)
2024 return err;
41ade00f 2025
b9454e83 2026 if (key.idx < 0)
41ade00f
JB
2027 return -EINVAL;
2028
b9454e83
JB
2029 /* only support setting default key */
2030 if (!key.def && !key.defmgmt)
41ade00f
JB
2031 return -EINVAL;
2032
dbd2fd65 2033 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2034
dbd2fd65
JB
2035 if (key.def) {
2036 if (!rdev->ops->set_default_key) {
2037 err = -EOPNOTSUPP;
2038 goto out;
2039 }
41ade00f 2040
dbd2fd65
JB
2041 err = nl80211_key_allowed(dev->ieee80211_ptr);
2042 if (err)
2043 goto out;
2044
dbd2fd65
JB
2045 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
2046 key.def_uni, key.def_multi);
2047
2048 if (err)
2049 goto out;
fffd0934 2050
3d23e349 2051#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2052 dev->ieee80211_ptr->wext.default_key = key.idx;
2053#endif
2054 } else {
2055 if (key.def_uni || !key.def_multi) {
2056 err = -EINVAL;
2057 goto out;
2058 }
2059
2060 if (!rdev->ops->set_default_mgmt_key) {
2061 err = -EOPNOTSUPP;
2062 goto out;
2063 }
2064
2065 err = nl80211_key_allowed(dev->ieee80211_ptr);
2066 if (err)
2067 goto out;
2068
2069 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
2070 dev, key.idx);
2071 if (err)
2072 goto out;
2073
2074#ifdef CONFIG_CFG80211_WEXT
2075 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2076#endif
dbd2fd65
JB
2077 }
2078
2079 out:
fffd0934 2080 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2081
41ade00f
JB
2082 return err;
2083}
2084
2085static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2086{
4c476991 2087 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2088 int err;
4c476991 2089 struct net_device *dev = info->user_ptr[1];
b9454e83 2090 struct key_parse key;
e31b8213 2091 const u8 *mac_addr = NULL;
41ade00f 2092
b9454e83
JB
2093 err = nl80211_parse_key(info, &key);
2094 if (err)
2095 return err;
41ade00f 2096
b9454e83 2097 if (!key.p.key)
41ade00f
JB
2098 return -EINVAL;
2099
41ade00f
JB
2100 if (info->attrs[NL80211_ATTR_MAC])
2101 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2102
e31b8213
JB
2103 if (key.type == -1) {
2104 if (mac_addr)
2105 key.type = NL80211_KEYTYPE_PAIRWISE;
2106 else
2107 key.type = NL80211_KEYTYPE_GROUP;
2108 }
2109
2110 /* for now */
2111 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2112 key.type != NL80211_KEYTYPE_GROUP)
2113 return -EINVAL;
2114
4c476991
JB
2115 if (!rdev->ops->add_key)
2116 return -EOPNOTSUPP;
25e47c18 2117
e31b8213
JB
2118 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2119 key.type == NL80211_KEYTYPE_PAIRWISE,
2120 mac_addr))
4c476991 2121 return -EINVAL;
41ade00f 2122
fffd0934
JB
2123 wdev_lock(dev->ieee80211_ptr);
2124 err = nl80211_key_allowed(dev->ieee80211_ptr);
2125 if (!err)
2126 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 2127 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
2128 mac_addr, &key.p);
2129 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2130
41ade00f
JB
2131 return err;
2132}
2133
2134static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2135{
4c476991 2136 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2137 int err;
4c476991 2138 struct net_device *dev = info->user_ptr[1];
41ade00f 2139 u8 *mac_addr = NULL;
b9454e83 2140 struct key_parse key;
41ade00f 2141
b9454e83
JB
2142 err = nl80211_parse_key(info, &key);
2143 if (err)
2144 return err;
41ade00f
JB
2145
2146 if (info->attrs[NL80211_ATTR_MAC])
2147 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2148
e31b8213
JB
2149 if (key.type == -1) {
2150 if (mac_addr)
2151 key.type = NL80211_KEYTYPE_PAIRWISE;
2152 else
2153 key.type = NL80211_KEYTYPE_GROUP;
2154 }
2155
2156 /* for now */
2157 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2158 key.type != NL80211_KEYTYPE_GROUP)
2159 return -EINVAL;
2160
4c476991
JB
2161 if (!rdev->ops->del_key)
2162 return -EOPNOTSUPP;
41ade00f 2163
fffd0934
JB
2164 wdev_lock(dev->ieee80211_ptr);
2165 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2166
2167 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2168 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2169 err = -ENOENT;
2170
fffd0934 2171 if (!err)
e31b8213
JB
2172 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2173 key.type == NL80211_KEYTYPE_PAIRWISE,
2174 mac_addr);
41ade00f 2175
3d23e349 2176#ifdef CONFIG_CFG80211_WEXT
08645126 2177 if (!err) {
b9454e83 2178 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2179 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2180 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2181 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2182 }
2183#endif
fffd0934 2184 wdev_unlock(dev->ieee80211_ptr);
08645126 2185
41ade00f
JB
2186 return err;
2187}
2188
8860020e
JB
2189static int nl80211_parse_beacon(struct genl_info *info,
2190 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2191{
8860020e 2192 bool haveinfo = false;
ed1b6cc7 2193
9946ecfb
JM
2194 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2195 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2196 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2197 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2198 return -EINVAL;
2199
8860020e 2200 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2201
ed1b6cc7 2202 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2203 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2204 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2205 if (!bcn->head_len)
2206 return -EINVAL;
2207 haveinfo = true;
ed1b6cc7
JB
2208 }
2209
2210 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2211 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2212 bcn->tail_len =
ed1b6cc7 2213 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2214 haveinfo = true;
ed1b6cc7
JB
2215 }
2216
4c476991
JB
2217 if (!haveinfo)
2218 return -EINVAL;
3b85875a 2219
9946ecfb 2220 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2221 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2222 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2223 }
2224
2225 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2226 bcn->proberesp_ies =
9946ecfb 2227 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2228 bcn->proberesp_ies_len =
9946ecfb
JM
2229 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2230 }
2231
2232 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2233 bcn->assocresp_ies =
9946ecfb 2234 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2235 bcn->assocresp_ies_len =
9946ecfb
JM
2236 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2237 }
2238
00f740e1 2239 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2240 bcn->probe_resp =
00f740e1 2241 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2242 bcn->probe_resp_len =
00f740e1
AN
2243 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2244 }
2245
8860020e
JB
2246 return 0;
2247}
2248
2249static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2250{
2251 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2252 struct net_device *dev = info->user_ptr[1];
2253 struct wireless_dev *wdev = dev->ieee80211_ptr;
2254 struct cfg80211_ap_settings params;
2255 int err;
2256
2257 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2258 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2259 return -EOPNOTSUPP;
2260
2261 if (!rdev->ops->start_ap)
2262 return -EOPNOTSUPP;
2263
2264 if (wdev->beacon_interval)
2265 return -EALREADY;
2266
2267 memset(&params, 0, sizeof(params));
2268
2269 /* these are required for START_AP */
2270 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2271 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2272 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2273 return -EINVAL;
2274
2275 err = nl80211_parse_beacon(info, &params.beacon);
2276 if (err)
2277 return err;
2278
2279 params.beacon_interval =
2280 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2281 params.dtim_period =
2282 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2283
2284 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2285 if (err)
2286 return err;
2287
2288 /*
2289 * In theory, some of these attributes should be required here
2290 * but since they were not used when the command was originally
2291 * added, keep them optional for old user space programs to let
2292 * them continue to work with drivers that do not need the
2293 * additional information -- drivers must check!
2294 */
2295 if (info->attrs[NL80211_ATTR_SSID]) {
2296 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2297 params.ssid_len =
2298 nla_len(info->attrs[NL80211_ATTR_SSID]);
2299 if (params.ssid_len == 0 ||
2300 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2301 return -EINVAL;
2302 }
2303
2304 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2305 params.hidden_ssid = nla_get_u32(
2306 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2307 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2308 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2309 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2310 return -EINVAL;
2311 }
2312
2313 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2314
2315 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2316 params.auth_type = nla_get_u32(
2317 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2318 if (!nl80211_valid_auth_type(params.auth_type))
2319 return -EINVAL;
2320 } else
2321 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2322
2323 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2324 NL80211_MAX_NR_CIPHER_SUITES);
2325 if (err)
2326 return err;
2327
1b658f11
VT
2328 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2329 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2330 return -EOPNOTSUPP;
2331 params.inactivity_timeout = nla_get_u16(
2332 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2333 }
2334
aa430da4
JB
2335 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
2336 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
2337
2338 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
2339 !nl80211_valid_channel_type(info, &channel_type))
2340 return -EINVAL;
2341
2342 params.channel = rdev_freq_to_chan(rdev,
2343 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
2344 channel_type);
2345 if (!params.channel)
2346 return -EINVAL;
2347 params.channel_type = channel_type;
2348 } else if (wdev->preset_chan) {
2349 params.channel = wdev->preset_chan;
2350 params.channel_type = wdev->preset_chantype;
2351 } else
2352 return -EINVAL;
2353
2354 if (!cfg80211_can_beacon_sec_chan(&rdev->wiphy, params.channel,
2355 params.channel_type))
2356 return -EINVAL;
2357
8860020e
JB
2358 err = rdev->ops->start_ap(&rdev->wiphy, dev, &params);
2359 if (!err)
2360 wdev->beacon_interval = params.beacon_interval;
56d1893d 2361 return err;
ed1b6cc7
JB
2362}
2363
8860020e
JB
2364static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2365{
2366 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2367 struct net_device *dev = info->user_ptr[1];
2368 struct wireless_dev *wdev = dev->ieee80211_ptr;
2369 struct cfg80211_beacon_data params;
2370 int err;
2371
2372 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2373 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2374 return -EOPNOTSUPP;
2375
2376 if (!rdev->ops->change_beacon)
2377 return -EOPNOTSUPP;
2378
2379 if (!wdev->beacon_interval)
2380 return -EINVAL;
2381
2382 err = nl80211_parse_beacon(info, &params);
2383 if (err)
2384 return err;
2385
2386 return rdev->ops->change_beacon(&rdev->wiphy, dev, &params);
2387}
2388
2389static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2390{
4c476991
JB
2391 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2392 struct net_device *dev = info->user_ptr[1];
56d1893d
JB
2393 struct wireless_dev *wdev = dev->ieee80211_ptr;
2394 int err;
ed1b6cc7 2395
8860020e 2396 if (!rdev->ops->stop_ap)
4c476991 2397 return -EOPNOTSUPP;
ed1b6cc7 2398
074ac8df 2399 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2400 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2401 return -EOPNOTSUPP;
3b85875a 2402
8860020e
JB
2403 if (!wdev->beacon_interval)
2404 return -ENOENT;
2405
2406 err = rdev->ops->stop_ap(&rdev->wiphy, dev);
56d1893d
JB
2407 if (!err)
2408 wdev->beacon_interval = 0;
2409 return err;
ed1b6cc7
JB
2410}
2411
5727ef1b
JB
2412static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2413 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2414 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2415 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2416 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2417 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2418 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2419};
2420
eccb8e8f 2421static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2422 enum nl80211_iftype iftype,
eccb8e8f 2423 struct station_parameters *params)
5727ef1b
JB
2424{
2425 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2426 struct nlattr *nla;
5727ef1b
JB
2427 int flag;
2428
eccb8e8f
JB
2429 /*
2430 * Try parsing the new attribute first so userspace
2431 * can specify both for older kernels.
2432 */
2433 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2434 if (nla) {
2435 struct nl80211_sta_flag_update *sta_flags;
2436
2437 sta_flags = nla_data(nla);
2438 params->sta_flags_mask = sta_flags->mask;
2439 params->sta_flags_set = sta_flags->set;
2440 if ((params->sta_flags_mask |
2441 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2442 return -EINVAL;
2443 return 0;
2444 }
2445
2446 /* if present, parse the old attribute */
5727ef1b 2447
eccb8e8f 2448 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2449 if (!nla)
2450 return 0;
2451
2452 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2453 nla, sta_flags_policy))
2454 return -EINVAL;
2455
bdd3ae3d
JB
2456 /*
2457 * Only allow certain flags for interface types so that
2458 * other attributes are silently ignored. Remember that
2459 * this is backward compatibility code with old userspace
2460 * and shouldn't be hit in other cases anyway.
2461 */
2462 switch (iftype) {
2463 case NL80211_IFTYPE_AP:
2464 case NL80211_IFTYPE_AP_VLAN:
2465 case NL80211_IFTYPE_P2P_GO:
2466 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2467 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2468 BIT(NL80211_STA_FLAG_WME) |
2469 BIT(NL80211_STA_FLAG_MFP);
2470 break;
2471 case NL80211_IFTYPE_P2P_CLIENT:
2472 case NL80211_IFTYPE_STATION:
2473 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2474 BIT(NL80211_STA_FLAG_TDLS_PEER);
2475 break;
2476 case NL80211_IFTYPE_MESH_POINT:
2477 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2478 BIT(NL80211_STA_FLAG_MFP) |
2479 BIT(NL80211_STA_FLAG_AUTHORIZED);
2480 default:
2481 return -EINVAL;
2482 }
5727ef1b 2483
3383b5a6
JB
2484 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2485 if (flags[flag]) {
eccb8e8f 2486 params->sta_flags_set |= (1<<flag);
5727ef1b 2487
3383b5a6
JB
2488 /* no longer support new API additions in old API */
2489 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2490 return -EINVAL;
2491 }
2492 }
2493
5727ef1b
JB
2494 return 0;
2495}
2496
c8dcfd8a
FF
2497static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2498 int attr)
2499{
2500 struct nlattr *rate;
2501 u16 bitrate;
2502
2503 rate = nla_nest_start(msg, attr);
2504 if (!rate)
2505 goto nla_put_failure;
2506
2507 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2508 bitrate = cfg80211_calculate_bitrate(info);
9360ffd1
DM
2509 if ((bitrate > 0 &&
2510 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate)) ||
2511 ((info->flags & RATE_INFO_FLAGS_MCS) &&
2512 nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs)) ||
2513 ((info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) &&
2514 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH)) ||
2515 ((info->flags & RATE_INFO_FLAGS_SHORT_GI) &&
2516 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)))
2517 goto nla_put_failure;
c8dcfd8a
FF
2518
2519 nla_nest_end(msg, rate);
2520 return true;
2521
2522nla_put_failure:
2523 return false;
2524}
2525
fd5b74dc 2526static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
66266b3a
JL
2527 int flags,
2528 struct cfg80211_registered_device *rdev,
2529 struct net_device *dev,
98b62183 2530 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2531{
2532 void *hdr;
f4263c98 2533 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2534
2535 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2536 if (!hdr)
2537 return -1;
2538
9360ffd1
DM
2539 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2540 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
2541 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
2542 goto nla_put_failure;
f5ea9120 2543
2ec600d6
LCC
2544 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2545 if (!sinfoattr)
fd5b74dc 2546 goto nla_put_failure;
9360ffd1
DM
2547 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
2548 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2549 sinfo->connected_time))
2550 goto nla_put_failure;
2551 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
2552 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2553 sinfo->inactive_time))
2554 goto nla_put_failure;
2555 if ((sinfo->filled & STATION_INFO_RX_BYTES) &&
2556 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
2557 sinfo->rx_bytes))
2558 goto nla_put_failure;
2559 if ((sinfo->filled & STATION_INFO_TX_BYTES) &&
2560 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
2561 sinfo->tx_bytes))
2562 goto nla_put_failure;
2563 if ((sinfo->filled & STATION_INFO_LLID) &&
2564 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
2565 goto nla_put_failure;
2566 if ((sinfo->filled & STATION_INFO_PLID) &&
2567 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
2568 goto nla_put_failure;
2569 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
2570 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
2571 sinfo->plink_state))
2572 goto nla_put_failure;
66266b3a
JL
2573 switch (rdev->wiphy.signal_type) {
2574 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
2575 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
2576 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
2577 sinfo->signal))
2578 goto nla_put_failure;
2579 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
2580 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2581 sinfo->signal_avg))
2582 goto nla_put_failure;
66266b3a
JL
2583 break;
2584 default:
2585 break;
2586 }
420e7fab 2587 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2588 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2589 NL80211_STA_INFO_TX_BITRATE))
2590 goto nla_put_failure;
2591 }
2592 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2593 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2594 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2595 goto nla_put_failure;
420e7fab 2596 }
9360ffd1
DM
2597 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
2598 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
2599 sinfo->rx_packets))
2600 goto nla_put_failure;
2601 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
2602 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
2603 sinfo->tx_packets))
2604 goto nla_put_failure;
2605 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
2606 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
2607 sinfo->tx_retries))
2608 goto nla_put_failure;
2609 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
2610 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
2611 sinfo->tx_failed))
2612 goto nla_put_failure;
2613 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
2614 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
2615 sinfo->beacon_loss_count))
2616 goto nla_put_failure;
f4263c98
PS
2617 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2618 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2619 if (!bss_param)
2620 goto nla_put_failure;
2621
9360ffd1
DM
2622 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
2623 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
2624 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
2625 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
2626 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
2627 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
2628 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2629 sinfo->bss_param.dtim_period) ||
2630 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2631 sinfo->bss_param.beacon_interval))
2632 goto nla_put_failure;
f4263c98
PS
2633
2634 nla_nest_end(msg, bss_param);
2635 }
9360ffd1
DM
2636 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
2637 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
2638 sizeof(struct nl80211_sta_flag_update),
2639 &sinfo->sta_flags))
2640 goto nla_put_failure;
7eab0f64
JL
2641 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
2642 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
2643 sinfo->t_offset))
2644 goto nla_put_failure;
2ec600d6 2645 nla_nest_end(msg, sinfoattr);
fd5b74dc 2646
9360ffd1
DM
2647 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
2648 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2649 sinfo->assoc_req_ies))
2650 goto nla_put_failure;
50d3dfb7 2651
fd5b74dc
JB
2652 return genlmsg_end(msg, hdr);
2653
2654 nla_put_failure:
bc3ed28c
TG
2655 genlmsg_cancel(msg, hdr);
2656 return -EMSGSIZE;
fd5b74dc
JB
2657}
2658
2ec600d6 2659static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2660 struct netlink_callback *cb)
2ec600d6 2661{
2ec600d6
LCC
2662 struct station_info sinfo;
2663 struct cfg80211_registered_device *dev;
bba95fef 2664 struct net_device *netdev;
2ec600d6 2665 u8 mac_addr[ETH_ALEN];
bba95fef 2666 int sta_idx = cb->args[1];
2ec600d6 2667 int err;
2ec600d6 2668
67748893
JB
2669 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2670 if (err)
2671 return err;
bba95fef
JB
2672
2673 if (!dev->ops->dump_station) {
eec60b03 2674 err = -EOPNOTSUPP;
bba95fef
JB
2675 goto out_err;
2676 }
2677
bba95fef 2678 while (1) {
f612cedf 2679 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2680 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2681 mac_addr, &sinfo);
2682 if (err == -ENOENT)
2683 break;
2684 if (err)
3b85875a 2685 goto out_err;
bba95fef
JB
2686
2687 if (nl80211_send_station(skb,
2688 NETLINK_CB(cb->skb).pid,
2689 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 2690 dev, netdev, mac_addr,
bba95fef
JB
2691 &sinfo) < 0)
2692 goto out;
2693
2694 sta_idx++;
2695 }
2696
2697
2698 out:
2699 cb->args[1] = sta_idx;
2700 err = skb->len;
bba95fef 2701 out_err:
67748893 2702 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2703
2704 return err;
2ec600d6 2705}
fd5b74dc 2706
5727ef1b
JB
2707static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2708{
4c476991
JB
2709 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2710 struct net_device *dev = info->user_ptr[1];
2ec600d6 2711 struct station_info sinfo;
fd5b74dc
JB
2712 struct sk_buff *msg;
2713 u8 *mac_addr = NULL;
4c476991 2714 int err;
fd5b74dc 2715
2ec600d6 2716 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2717
2718 if (!info->attrs[NL80211_ATTR_MAC])
2719 return -EINVAL;
2720
2721 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2722
4c476991
JB
2723 if (!rdev->ops->get_station)
2724 return -EOPNOTSUPP;
3b85875a 2725
4c476991 2726 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2727 if (err)
4c476991 2728 return err;
2ec600d6 2729
fd2120ca 2730 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2731 if (!msg)
4c476991 2732 return -ENOMEM;
fd5b74dc
JB
2733
2734 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
66266b3a 2735 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
2736 nlmsg_free(msg);
2737 return -ENOBUFS;
2738 }
3b85875a 2739
4c476991 2740 return genlmsg_reply(msg, info);
5727ef1b
JB
2741}
2742
2743/*
c258d2de 2744 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2745 */
80b99899
JB
2746static struct net_device *get_vlan(struct genl_info *info,
2747 struct cfg80211_registered_device *rdev)
5727ef1b 2748{
463d0183 2749 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
2750 struct net_device *v;
2751 int ret;
2752
2753 if (!vlanattr)
2754 return NULL;
2755
2756 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
2757 if (!v)
2758 return ERR_PTR(-ENODEV);
2759
2760 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
2761 ret = -EINVAL;
2762 goto error;
5727ef1b 2763 }
80b99899
JB
2764
2765 if (!netif_running(v)) {
2766 ret = -ENETDOWN;
2767 goto error;
2768 }
2769
2770 return v;
2771 error:
2772 dev_put(v);
2773 return ERR_PTR(ret);
5727ef1b
JB
2774}
2775
2776static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2777{
4c476991 2778 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2779 int err;
4c476991 2780 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2781 struct station_parameters params;
2782 u8 *mac_addr = NULL;
2783
2784 memset(&params, 0, sizeof(params));
2785
2786 params.listen_interval = -1;
57cf8043 2787 params.plink_state = -1;
5727ef1b
JB
2788
2789 if (info->attrs[NL80211_ATTR_STA_AID])
2790 return -EINVAL;
2791
2792 if (!info->attrs[NL80211_ATTR_MAC])
2793 return -EINVAL;
2794
2795 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2796
2797 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2798 params.supported_rates =
2799 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2800 params.supported_rates_len =
2801 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2802 }
2803
2804 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2805 params.listen_interval =
2806 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2807
36aedc90
JM
2808 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2809 params.ht_capa =
2810 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2811
bdd90d5e
JB
2812 if (!rdev->ops->change_station)
2813 return -EOPNOTSUPP;
2814
bdd3ae3d 2815 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2816 return -EINVAL;
2817
2ec600d6
LCC
2818 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2819 params.plink_action =
2820 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2821
9c3990aa
JC
2822 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2823 params.plink_state =
2824 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2825
a97f4424
JB
2826 switch (dev->ieee80211_ptr->iftype) {
2827 case NL80211_IFTYPE_AP:
2828 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2829 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2830 /* disallow mesh-specific things */
2831 if (params.plink_action)
bdd90d5e
JB
2832 return -EINVAL;
2833
2834 /* TDLS can't be set, ... */
2835 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2836 return -EINVAL;
2837 /*
2838 * ... but don't bother the driver with it. This works around
2839 * a hostapd/wpa_supplicant issue -- it always includes the
2840 * TLDS_PEER flag in the mask even for AP mode.
2841 */
2842 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2843
2844 /* accept only the listed bits */
2845 if (params.sta_flags_mask &
2846 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2847 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2848 BIT(NL80211_STA_FLAG_WME) |
2849 BIT(NL80211_STA_FLAG_MFP)))
2850 return -EINVAL;
2851
2852 /* must be last in here for error handling */
2853 params.vlan = get_vlan(info, rdev);
2854 if (IS_ERR(params.vlan))
2855 return PTR_ERR(params.vlan);
a97f4424 2856 break;
074ac8df 2857 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 2858 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
2859 /*
2860 * Don't allow userspace to change the TDLS_PEER flag,
2861 * but silently ignore attempts to change it since we
2862 * don't have state here to verify that it doesn't try
2863 * to change the flag.
2864 */
2865 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
2866 /* fall through */
2867 case NL80211_IFTYPE_ADHOC:
2868 /* disallow things sta doesn't support */
2869 if (params.plink_action)
2870 return -EINVAL;
2871 if (params.ht_capa)
2872 return -EINVAL;
2873 if (params.listen_interval >= 0)
2874 return -EINVAL;
bdd90d5e
JB
2875 /* reject any changes other than AUTHORIZED */
2876 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2877 return -EINVAL;
a97f4424
JB
2878 break;
2879 case NL80211_IFTYPE_MESH_POINT:
2880 /* disallow things mesh doesn't support */
2881 if (params.vlan)
bdd90d5e 2882 return -EINVAL;
a97f4424 2883 if (params.ht_capa)
bdd90d5e 2884 return -EINVAL;
a97f4424 2885 if (params.listen_interval >= 0)
bdd90d5e
JB
2886 return -EINVAL;
2887 /*
2888 * No special handling for TDLS here -- the userspace
2889 * mesh code doesn't have this bug.
2890 */
b39c48fa
JC
2891 if (params.sta_flags_mask &
2892 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2893 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2894 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 2895 return -EINVAL;
a97f4424
JB
2896 break;
2897 default:
bdd90d5e 2898 return -EOPNOTSUPP;
034d655e
JB
2899 }
2900
bdd90d5e 2901 /* be aware of params.vlan when changing code here */
5727ef1b 2902
79c97e97 2903 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 2904
5727ef1b
JB
2905 if (params.vlan)
2906 dev_put(params.vlan);
3b85875a 2907
5727ef1b
JB
2908 return err;
2909}
2910
c75786c9
EP
2911static struct nla_policy
2912nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2913 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2914 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2915};
2916
5727ef1b
JB
2917static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2918{
4c476991 2919 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2920 int err;
4c476991 2921 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2922 struct station_parameters params;
2923 u8 *mac_addr = NULL;
2924
2925 memset(&params, 0, sizeof(params));
2926
2927 if (!info->attrs[NL80211_ATTR_MAC])
2928 return -EINVAL;
2929
5727ef1b
JB
2930 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2931 return -EINVAL;
2932
2933 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2934 return -EINVAL;
2935
0e956c13
TLSC
2936 if (!info->attrs[NL80211_ATTR_STA_AID])
2937 return -EINVAL;
2938
5727ef1b
JB
2939 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2940 params.supported_rates =
2941 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2942 params.supported_rates_len =
2943 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2944 params.listen_interval =
2945 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2946
0e956c13
TLSC
2947 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2948 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2949 return -EINVAL;
51b50fbe 2950
36aedc90
JM
2951 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2952 params.ht_capa =
2953 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2954
96b78dff
JC
2955 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2956 params.plink_action =
2957 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2958
bdd90d5e
JB
2959 if (!rdev->ops->add_station)
2960 return -EOPNOTSUPP;
2961
bdd3ae3d 2962 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2963 return -EINVAL;
2964
bdd90d5e
JB
2965 switch (dev->ieee80211_ptr->iftype) {
2966 case NL80211_IFTYPE_AP:
2967 case NL80211_IFTYPE_AP_VLAN:
2968 case NL80211_IFTYPE_P2P_GO:
2969 /* parse WME attributes if sta is WME capable */
2970 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2971 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
2972 info->attrs[NL80211_ATTR_STA_WME]) {
2973 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2974 struct nlattr *nla;
2975
2976 nla = info->attrs[NL80211_ATTR_STA_WME];
2977 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2978 nl80211_sta_wme_policy);
2979 if (err)
2980 return err;
2981
2982 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2983 params.uapsd_queues =
2984 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
2985 if (params.uapsd_queues &
2986 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2987 return -EINVAL;
c75786c9 2988
bdd90d5e
JB
2989 if (tb[NL80211_STA_WME_MAX_SP])
2990 params.max_sp =
2991 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 2992
bdd90d5e
JB
2993 if (params.max_sp &
2994 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2995 return -EINVAL;
4319e193 2996
bdd90d5e
JB
2997 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
2998 }
2999 /* TDLS peers cannot be added */
3000 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3001 return -EINVAL;
bdd90d5e
JB
3002 /* but don't bother the driver with it */
3003 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3004
bdd90d5e
JB
3005 /* must be last in here for error handling */
3006 params.vlan = get_vlan(info, rdev);
3007 if (IS_ERR(params.vlan))
3008 return PTR_ERR(params.vlan);
3009 break;
3010 case NL80211_IFTYPE_MESH_POINT:
3011 /* TDLS peers cannot be added */
3012 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3013 return -EINVAL;
3014 break;
3015 case NL80211_IFTYPE_STATION:
3016 /* Only TDLS peers can be added */
3017 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3018 return -EINVAL;
3019 /* Can only add if TDLS ... */
3020 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3021 return -EOPNOTSUPP;
3022 /* ... with external setup is supported */
3023 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3024 return -EOPNOTSUPP;
3025 break;
3026 default:
3027 return -EOPNOTSUPP;
c75786c9
EP
3028 }
3029
bdd90d5e 3030 /* be aware of params.vlan when changing code here */
5727ef1b 3031
79c97e97 3032 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 3033
5727ef1b
JB
3034 if (params.vlan)
3035 dev_put(params.vlan);
5727ef1b
JB
3036 return err;
3037}
3038
3039static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3040{
4c476991
JB
3041 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3042 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3043 u8 *mac_addr = NULL;
3044
3045 if (info->attrs[NL80211_ATTR_MAC])
3046 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3047
e80cf853 3048 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3049 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3050 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3051 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3052 return -EINVAL;
5727ef1b 3053
4c476991
JB
3054 if (!rdev->ops->del_station)
3055 return -EOPNOTSUPP;
3b85875a 3056
4c476991 3057 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
3058}
3059
2ec600d6
LCC
3060static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
3061 int flags, struct net_device *dev,
3062 u8 *dst, u8 *next_hop,
3063 struct mpath_info *pinfo)
3064{
3065 void *hdr;
3066 struct nlattr *pinfoattr;
3067
3068 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
3069 if (!hdr)
3070 return -1;
3071
9360ffd1
DM
3072 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3073 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3074 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3075 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3076 goto nla_put_failure;
f5ea9120 3077
2ec600d6
LCC
3078 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3079 if (!pinfoattr)
3080 goto nla_put_failure;
9360ffd1
DM
3081 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3082 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3083 pinfo->frame_qlen))
3084 goto nla_put_failure;
3085 if (((pinfo->filled & MPATH_INFO_SN) &&
3086 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3087 ((pinfo->filled & MPATH_INFO_METRIC) &&
3088 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3089 pinfo->metric)) ||
3090 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3091 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3092 pinfo->exptime)) ||
3093 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3094 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3095 pinfo->flags)) ||
3096 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3097 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3098 pinfo->discovery_timeout)) ||
3099 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3100 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3101 pinfo->discovery_retries)))
3102 goto nla_put_failure;
2ec600d6
LCC
3103
3104 nla_nest_end(msg, pinfoattr);
3105
3106 return genlmsg_end(msg, hdr);
3107
3108 nla_put_failure:
bc3ed28c
TG
3109 genlmsg_cancel(msg, hdr);
3110 return -EMSGSIZE;
2ec600d6
LCC
3111}
3112
3113static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3114 struct netlink_callback *cb)
2ec600d6 3115{
2ec600d6
LCC
3116 struct mpath_info pinfo;
3117 struct cfg80211_registered_device *dev;
bba95fef 3118 struct net_device *netdev;
2ec600d6
LCC
3119 u8 dst[ETH_ALEN];
3120 u8 next_hop[ETH_ALEN];
bba95fef 3121 int path_idx = cb->args[1];
2ec600d6 3122 int err;
2ec600d6 3123
67748893
JB
3124 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3125 if (err)
3126 return err;
bba95fef
JB
3127
3128 if (!dev->ops->dump_mpath) {
eec60b03 3129 err = -EOPNOTSUPP;
bba95fef
JB
3130 goto out_err;
3131 }
3132
eec60b03
JM
3133 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3134 err = -EOPNOTSUPP;
0448b5fc 3135 goto out_err;
eec60b03
JM
3136 }
3137
bba95fef
JB
3138 while (1) {
3139 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
3140 dst, next_hop, &pinfo);
3141 if (err == -ENOENT)
2ec600d6 3142 break;
bba95fef 3143 if (err)
3b85875a 3144 goto out_err;
2ec600d6 3145
bba95fef
JB
3146 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
3147 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3148 netdev, dst, next_hop,
3149 &pinfo) < 0)
3150 goto out;
2ec600d6 3151
bba95fef 3152 path_idx++;
2ec600d6 3153 }
2ec600d6 3154
2ec600d6 3155
bba95fef
JB
3156 out:
3157 cb->args[1] = path_idx;
3158 err = skb->len;
bba95fef 3159 out_err:
67748893 3160 nl80211_finish_netdev_dump(dev);
bba95fef 3161 return err;
2ec600d6
LCC
3162}
3163
3164static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3165{
4c476991 3166 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3167 int err;
4c476991 3168 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3169 struct mpath_info pinfo;
3170 struct sk_buff *msg;
3171 u8 *dst = NULL;
3172 u8 next_hop[ETH_ALEN];
3173
3174 memset(&pinfo, 0, sizeof(pinfo));
3175
3176 if (!info->attrs[NL80211_ATTR_MAC])
3177 return -EINVAL;
3178
3179 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3180
4c476991
JB
3181 if (!rdev->ops->get_mpath)
3182 return -EOPNOTSUPP;
2ec600d6 3183
4c476991
JB
3184 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3185 return -EOPNOTSUPP;
eec60b03 3186
79c97e97 3187 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 3188 if (err)
4c476991 3189 return err;
2ec600d6 3190
fd2120ca 3191 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3192 if (!msg)
4c476991 3193 return -ENOMEM;
2ec600d6
LCC
3194
3195 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
3196 dev, dst, next_hop, &pinfo) < 0) {
3197 nlmsg_free(msg);
3198 return -ENOBUFS;
3199 }
3b85875a 3200
4c476991 3201 return genlmsg_reply(msg, info);
2ec600d6
LCC
3202}
3203
3204static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3205{
4c476991
JB
3206 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3207 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3208 u8 *dst = NULL;
3209 u8 *next_hop = NULL;
3210
3211 if (!info->attrs[NL80211_ATTR_MAC])
3212 return -EINVAL;
3213
3214 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3215 return -EINVAL;
3216
3217 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3218 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3219
4c476991
JB
3220 if (!rdev->ops->change_mpath)
3221 return -EOPNOTSUPP;
35a8efe1 3222
4c476991
JB
3223 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3224 return -EOPNOTSUPP;
2ec600d6 3225
4c476991 3226 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 3227}
4c476991 3228
2ec600d6
LCC
3229static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3230{
4c476991
JB
3231 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3232 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3233 u8 *dst = NULL;
3234 u8 *next_hop = NULL;
3235
3236 if (!info->attrs[NL80211_ATTR_MAC])
3237 return -EINVAL;
3238
3239 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3240 return -EINVAL;
3241
3242 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3243 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3244
4c476991
JB
3245 if (!rdev->ops->add_mpath)
3246 return -EOPNOTSUPP;
35a8efe1 3247
4c476991
JB
3248 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3249 return -EOPNOTSUPP;
2ec600d6 3250
4c476991 3251 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
3252}
3253
3254static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3255{
4c476991
JB
3256 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3257 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3258 u8 *dst = NULL;
3259
3260 if (info->attrs[NL80211_ATTR_MAC])
3261 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3262
4c476991
JB
3263 if (!rdev->ops->del_mpath)
3264 return -EOPNOTSUPP;
3b85875a 3265
4c476991 3266 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
3267}
3268
9f1ba906
JM
3269static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3270{
4c476991
JB
3271 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3272 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3273 struct bss_parameters params;
3274
3275 memset(&params, 0, sizeof(params));
3276 /* default to not changing parameters */
3277 params.use_cts_prot = -1;
3278 params.use_short_preamble = -1;
3279 params.use_short_slot_time = -1;
fd8aaaf3 3280 params.ap_isolate = -1;
50b12f59 3281 params.ht_opmode = -1;
9f1ba906
JM
3282
3283 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3284 params.use_cts_prot =
3285 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3286 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3287 params.use_short_preamble =
3288 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3289 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3290 params.use_short_slot_time =
3291 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3292 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3293 params.basic_rates =
3294 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3295 params.basic_rates_len =
3296 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3297 }
fd8aaaf3
FF
3298 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3299 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3300 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3301 params.ht_opmode =
3302 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3303
4c476991
JB
3304 if (!rdev->ops->change_bss)
3305 return -EOPNOTSUPP;
9f1ba906 3306
074ac8df 3307 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3308 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3309 return -EOPNOTSUPP;
3b85875a 3310
4c476991 3311 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
3312}
3313
b54452b0 3314static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3315 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3316 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3317 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3318 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3319 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3320 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3321};
3322
3323static int parse_reg_rule(struct nlattr *tb[],
3324 struct ieee80211_reg_rule *reg_rule)
3325{
3326 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3327 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3328
3329 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3330 return -EINVAL;
3331 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3332 return -EINVAL;
3333 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3334 return -EINVAL;
3335 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3336 return -EINVAL;
3337 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3338 return -EINVAL;
3339
3340 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3341
3342 freq_range->start_freq_khz =
3343 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3344 freq_range->end_freq_khz =
3345 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3346 freq_range->max_bandwidth_khz =
3347 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3348
3349 power_rule->max_eirp =
3350 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3351
3352 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3353 power_rule->max_antenna_gain =
3354 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3355
3356 return 0;
3357}
3358
3359static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3360{
3361 int r;
3362 char *data = NULL;
3363
80778f18
LR
3364 /*
3365 * You should only get this when cfg80211 hasn't yet initialized
3366 * completely when built-in to the kernel right between the time
3367 * window between nl80211_init() and regulatory_init(), if that is
3368 * even possible.
3369 */
3370 mutex_lock(&cfg80211_mutex);
3371 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3372 mutex_unlock(&cfg80211_mutex);
3373 return -EINPROGRESS;
80778f18 3374 }
fe33eb39 3375 mutex_unlock(&cfg80211_mutex);
80778f18 3376
fe33eb39
LR
3377 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3378 return -EINVAL;
b2e1b302
LR
3379
3380 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3381
fe33eb39
LR
3382 r = regulatory_hint_user(data);
3383
b2e1b302
LR
3384 return r;
3385}
3386
24bdd9f4 3387static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3388 struct genl_info *info)
93da9cc1 3389{
4c476991 3390 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3391 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3392 struct wireless_dev *wdev = dev->ieee80211_ptr;
3393 struct mesh_config cur_params;
3394 int err = 0;
93da9cc1 3395 void *hdr;
3396 struct nlattr *pinfoattr;
3397 struct sk_buff *msg;
3398
29cbe68c
JB
3399 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3400 return -EOPNOTSUPP;
3401
24bdd9f4 3402 if (!rdev->ops->get_mesh_config)
4c476991 3403 return -EOPNOTSUPP;
f3f92586 3404
29cbe68c
JB
3405 wdev_lock(wdev);
3406 /* If not connected, get default parameters */
3407 if (!wdev->mesh_id_len)
3408 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3409 else
24bdd9f4 3410 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3411 &cur_params);
3412 wdev_unlock(wdev);
3413
93da9cc1 3414 if (err)
4c476991 3415 return err;
93da9cc1 3416
3417 /* Draw up a netlink message to send back */
fd2120ca 3418 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3419 if (!msg)
3420 return -ENOMEM;
93da9cc1 3421 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3422 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3423 if (!hdr)
efe1cf0c 3424 goto out;
24bdd9f4 3425 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3426 if (!pinfoattr)
3427 goto nla_put_failure;
9360ffd1
DM
3428 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3429 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3430 cur_params.dot11MeshRetryTimeout) ||
3431 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3432 cur_params.dot11MeshConfirmTimeout) ||
3433 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3434 cur_params.dot11MeshHoldingTimeout) ||
3435 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3436 cur_params.dot11MeshMaxPeerLinks) ||
3437 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
3438 cur_params.dot11MeshMaxRetries) ||
3439 nla_put_u8(msg, NL80211_MESHCONF_TTL,
3440 cur_params.dot11MeshTTL) ||
3441 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3442 cur_params.element_ttl) ||
3443 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3444 cur_params.auto_open_plinks) ||
7eab0f64
JL
3445 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3446 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
3447 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3448 cur_params.dot11MeshHWMPmaxPREQretries) ||
3449 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3450 cur_params.path_refresh_time) ||
3451 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3452 cur_params.min_discovery_timeout) ||
3453 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3454 cur_params.dot11MeshHWMPactivePathTimeout) ||
3455 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3456 cur_params.dot11MeshHWMPpreqMinInterval) ||
3457 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3458 cur_params.dot11MeshHWMPperrMinInterval) ||
3459 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3460 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
3461 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3462 cur_params.dot11MeshHWMPRootMode) ||
3463 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3464 cur_params.dot11MeshHWMPRannInterval) ||
3465 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3466 cur_params.dot11MeshGateAnnouncementProtocol) ||
3467 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
3468 cur_params.dot11MeshForwarding) ||
3469 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
3470 cur_params.rssi_threshold) ||
3471 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
3472 cur_params.ht_opmode))
9360ffd1 3473 goto nla_put_failure;
93da9cc1 3474 nla_nest_end(msg, pinfoattr);
3475 genlmsg_end(msg, hdr);
4c476991 3476 return genlmsg_reply(msg, info);
93da9cc1 3477
3b85875a 3478 nla_put_failure:
93da9cc1 3479 genlmsg_cancel(msg, hdr);
efe1cf0c 3480 out:
d080e275 3481 nlmsg_free(msg);
4c476991 3482 return -ENOBUFS;
93da9cc1 3483}
3484
b54452b0 3485static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3486 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3487 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3488 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3489 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3490 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3491 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3492 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3493 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 3494 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 3495 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3496 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3497 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3498 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3499 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3500 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3501 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3502 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3503 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3504 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3505 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
3506 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
3507 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
93da9cc1 3508};
3509
c80d545d
JC
3510static const struct nla_policy
3511 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 3512 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
3513 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3514 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3515 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3516 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 3517 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3518 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3519};
3520
24bdd9f4 3521static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3522 struct mesh_config *cfg,
3523 u32 *mask_out)
93da9cc1 3524{
93da9cc1 3525 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3526 u32 mask = 0;
93da9cc1 3527
bd90fdcc
JB
3528#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3529do {\
3530 if (table[attr_num]) {\
3531 cfg->param = nla_fn(table[attr_num]); \
3532 mask |= (1 << (attr_num - 1)); \
3533 } \
3534} while (0);\
3535
3536
24bdd9f4 3537 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3538 return -EINVAL;
3539 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3540 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3541 nl80211_meshconf_params_policy))
93da9cc1 3542 return -EINVAL;
3543
93da9cc1 3544 /* This makes sure that there aren't more than 32 mesh config
3545 * parameters (otherwise our bitfield scheme would not work.) */
3546 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3547
3548 /* Fill in the params struct */
93da9cc1 3549 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
a4f606ea
CYY
3550 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
3551 nla_get_u16);
93da9cc1 3552 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
a4f606ea
CYY
3553 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3554 nla_get_u16);
93da9cc1 3555 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
a4f606ea
CYY
3556 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
3557 nla_get_u16);
93da9cc1 3558 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
a4f606ea
CYY
3559 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
3560 nla_get_u16);
93da9cc1 3561 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
a4f606ea
CYY
3562 mask, NL80211_MESHCONF_MAX_RETRIES,
3563 nla_get_u8);
93da9cc1 3564 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
a4f606ea 3565 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21 3566 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
a4f606ea
CYY
3567 mask, NL80211_MESHCONF_ELEMENT_TTL,
3568 nla_get_u8);
93da9cc1 3569 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
a4f606ea
CYY
3570 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3571 nla_get_u8);
3572 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, mask,
3573 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3574 nla_get_u32);
93da9cc1 3575 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
a4f606ea
CYY
3576 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3577 nla_get_u8);
93da9cc1 3578 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
a4f606ea
CYY
3579 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
3580 nla_get_u32);
93da9cc1 3581 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
a4f606ea
CYY
3582 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3583 nla_get_u16);
3584 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, mask,
3585 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3586 nla_get_u32);
93da9cc1 3587 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
a4f606ea
CYY
3588 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3589 nla_get_u16);
dca7e943 3590 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
a4f606ea
CYY
3591 mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3592 nla_get_u16);
0507e159 3593 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
3594 dot11MeshHWMPnetDiameterTraversalTime, mask,
3595 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3596 nla_get_u16);
3597 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
3598 NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
3599 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
3600 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3601 nla_get_u16);
16dd7267 3602 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
3603 dot11MeshGateAnnouncementProtocol, mask,
3604 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3605 nla_get_u8);
94f90656 3606 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
a4f606ea
CYY
3607 mask, NL80211_MESHCONF_FORWARDING,
3608 nla_get_u8);
55335137 3609 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
a4f606ea
CYY
3610 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
3611 nla_get_u32);
70c33eaa 3612 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode,
a4f606ea
CYY
3613 mask, NL80211_MESHCONF_HT_OPMODE,
3614 nla_get_u16);
bd90fdcc
JB
3615 if (mask_out)
3616 *mask_out = mask;
c80d545d 3617
bd90fdcc
JB
3618 return 0;
3619
3620#undef FILL_IN_MESH_PARAM_IF_SET
3621}
3622
c80d545d
JC
3623static int nl80211_parse_mesh_setup(struct genl_info *info,
3624 struct mesh_setup *setup)
3625{
3626 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3627
3628 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3629 return -EINVAL;
3630 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3631 info->attrs[NL80211_ATTR_MESH_SETUP],
3632 nl80211_mesh_setup_params_policy))
3633 return -EINVAL;
3634
d299a1f2
JC
3635 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
3636 setup->sync_method =
3637 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
3638 IEEE80211_SYNC_METHOD_VENDOR :
3639 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
3640
c80d545d
JC
3641 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3642 setup->path_sel_proto =
3643 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3644 IEEE80211_PATH_PROTOCOL_VENDOR :
3645 IEEE80211_PATH_PROTOCOL_HWMP;
3646
3647 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3648 setup->path_metric =
3649 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3650 IEEE80211_PATH_METRIC_VENDOR :
3651 IEEE80211_PATH_METRIC_AIRTIME;
3652
581a8b0f
JC
3653
3654 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3655 struct nlattr *ieattr =
581a8b0f 3656 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3657 if (!is_valid_ie_attr(ieattr))
3658 return -EINVAL;
581a8b0f
JC
3659 setup->ie = nla_data(ieattr);
3660 setup->ie_len = nla_len(ieattr);
c80d545d 3661 }
b130e5ce
JC
3662 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3663 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3664
3665 return 0;
3666}
3667
24bdd9f4 3668static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3669 struct genl_info *info)
bd90fdcc
JB
3670{
3671 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3672 struct net_device *dev = info->user_ptr[1];
29cbe68c 3673 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3674 struct mesh_config cfg;
3675 u32 mask;
3676 int err;
3677
29cbe68c
JB
3678 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3679 return -EOPNOTSUPP;
3680
24bdd9f4 3681 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3682 return -EOPNOTSUPP;
3683
24bdd9f4 3684 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3685 if (err)
3686 return err;
3687
29cbe68c
JB
3688 wdev_lock(wdev);
3689 if (!wdev->mesh_id_len)
3690 err = -ENOLINK;
3691
3692 if (!err)
24bdd9f4 3693 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3694 mask, &cfg);
3695
3696 wdev_unlock(wdev);
3697
3698 return err;
93da9cc1 3699}
3700
f130347c
LR
3701static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3702{
3703 struct sk_buff *msg;
3704 void *hdr = NULL;
3705 struct nlattr *nl_reg_rules;
3706 unsigned int i;
3707 int err = -EINVAL;
3708
a1794390 3709 mutex_lock(&cfg80211_mutex);
f130347c
LR
3710
3711 if (!cfg80211_regdomain)
3712 goto out;
3713
fd2120ca 3714 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3715 if (!msg) {
3716 err = -ENOBUFS;
3717 goto out;
3718 }
3719
3720 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3721 NL80211_CMD_GET_REG);
3722 if (!hdr)
efe1cf0c 3723 goto put_failure;
f130347c 3724
9360ffd1
DM
3725 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
3726 cfg80211_regdomain->alpha2) ||
3727 (cfg80211_regdomain->dfs_region &&
3728 nla_put_u8(msg, NL80211_ATTR_DFS_REGION,
3729 cfg80211_regdomain->dfs_region)))
3730 goto nla_put_failure;
f130347c
LR
3731
3732 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3733 if (!nl_reg_rules)
3734 goto nla_put_failure;
3735
3736 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3737 struct nlattr *nl_reg_rule;
3738 const struct ieee80211_reg_rule *reg_rule;
3739 const struct ieee80211_freq_range *freq_range;
3740 const struct ieee80211_power_rule *power_rule;
3741
3742 reg_rule = &cfg80211_regdomain->reg_rules[i];
3743 freq_range = &reg_rule->freq_range;
3744 power_rule = &reg_rule->power_rule;
3745
3746 nl_reg_rule = nla_nest_start(msg, i);
3747 if (!nl_reg_rule)
3748 goto nla_put_failure;
3749
9360ffd1
DM
3750 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3751 reg_rule->flags) ||
3752 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
3753 freq_range->start_freq_khz) ||
3754 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
3755 freq_range->end_freq_khz) ||
3756 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3757 freq_range->max_bandwidth_khz) ||
3758 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3759 power_rule->max_antenna_gain) ||
3760 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3761 power_rule->max_eirp))
3762 goto nla_put_failure;
f130347c
LR
3763
3764 nla_nest_end(msg, nl_reg_rule);
3765 }
3766
3767 nla_nest_end(msg, nl_reg_rules);
3768
3769 genlmsg_end(msg, hdr);
134e6375 3770 err = genlmsg_reply(msg, info);
f130347c
LR
3771 goto out;
3772
3773nla_put_failure:
3774 genlmsg_cancel(msg, hdr);
efe1cf0c 3775put_failure:
d080e275 3776 nlmsg_free(msg);
f130347c
LR
3777 err = -EMSGSIZE;
3778out:
a1794390 3779 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3780 return err;
3781}
3782
b2e1b302
LR
3783static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3784{
3785 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3786 struct nlattr *nl_reg_rule;
3787 char *alpha2 = NULL;
3788 int rem_reg_rules = 0, r = 0;
3789 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 3790 u8 dfs_region = 0;
b2e1b302
LR
3791 struct ieee80211_regdomain *rd = NULL;
3792
3793 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3794 return -EINVAL;
3795
3796 if (!info->attrs[NL80211_ATTR_REG_RULES])
3797 return -EINVAL;
3798
3799 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3800
8b60b078
LR
3801 if (info->attrs[NL80211_ATTR_DFS_REGION])
3802 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
3803
b2e1b302
LR
3804 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3805 rem_reg_rules) {
3806 num_rules++;
3807 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3808 return -EINVAL;
b2e1b302
LR
3809 }
3810
61405e97
LR
3811 mutex_lock(&cfg80211_mutex);
3812
d0e18f83
LR
3813 if (!reg_is_valid_request(alpha2)) {
3814 r = -EINVAL;
3815 goto bad_reg;
3816 }
b2e1b302
LR
3817
3818 size_of_regd = sizeof(struct ieee80211_regdomain) +
3819 (num_rules * sizeof(struct ieee80211_reg_rule));
3820
3821 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3822 if (!rd) {
3823 r = -ENOMEM;
3824 goto bad_reg;
3825 }
b2e1b302
LR
3826
3827 rd->n_reg_rules = num_rules;
3828 rd->alpha2[0] = alpha2[0];
3829 rd->alpha2[1] = alpha2[1];
3830
8b60b078
LR
3831 /*
3832 * Disable DFS master mode if the DFS region was
3833 * not supported or known on this kernel.
3834 */
3835 if (reg_supported_dfs_region(dfs_region))
3836 rd->dfs_region = dfs_region;
3837
b2e1b302
LR
3838 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3839 rem_reg_rules) {
3840 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3841 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3842 reg_rule_policy);
3843 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3844 if (r)
3845 goto bad_reg;
3846
3847 rule_idx++;
3848
d0e18f83
LR
3849 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3850 r = -EINVAL;
b2e1b302 3851 goto bad_reg;
d0e18f83 3852 }
b2e1b302
LR
3853 }
3854
3855 BUG_ON(rule_idx != num_rules);
3856
b2e1b302 3857 r = set_regdom(rd);
61405e97 3858
a1794390 3859 mutex_unlock(&cfg80211_mutex);
d0e18f83 3860
b2e1b302
LR
3861 return r;
3862
d2372b31 3863 bad_reg:
61405e97 3864 mutex_unlock(&cfg80211_mutex);
b2e1b302 3865 kfree(rd);
d0e18f83 3866 return r;
b2e1b302
LR
3867}
3868
83f5e2cf
JB
3869static int validate_scan_freqs(struct nlattr *freqs)
3870{
3871 struct nlattr *attr1, *attr2;
3872 int n_channels = 0, tmp1, tmp2;
3873
3874 nla_for_each_nested(attr1, freqs, tmp1) {
3875 n_channels++;
3876 /*
3877 * Some hardware has a limited channel list for
3878 * scanning, and it is pretty much nonsensical
3879 * to scan for a channel twice, so disallow that
3880 * and don't require drivers to check that the
3881 * channel list they get isn't longer than what
3882 * they can scan, as long as they can scan all
3883 * the channels they registered at once.
3884 */
3885 nla_for_each_nested(attr2, freqs, tmp2)
3886 if (attr1 != attr2 &&
3887 nla_get_u32(attr1) == nla_get_u32(attr2))
3888 return 0;
3889 }
3890
3891 return n_channels;
3892}
3893
2a519311
JB
3894static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3895{
4c476991
JB
3896 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3897 struct net_device *dev = info->user_ptr[1];
2a519311 3898 struct cfg80211_scan_request *request;
2a519311
JB
3899 struct nlattr *attr;
3900 struct wiphy *wiphy;
83f5e2cf 3901 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 3902 size_t ie_len;
2a519311 3903
f4a11bb0
JB
3904 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3905 return -EINVAL;
3906
79c97e97 3907 wiphy = &rdev->wiphy;
2a519311 3908
4c476991
JB
3909 if (!rdev->ops->scan)
3910 return -EOPNOTSUPP;
2a519311 3911
4c476991
JB
3912 if (rdev->scan_req)
3913 return -EBUSY;
2a519311
JB
3914
3915 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3916 n_channels = validate_scan_freqs(
3917 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3918 if (!n_channels)
3919 return -EINVAL;
2a519311 3920 } else {
34850ab2 3921 enum ieee80211_band band;
83f5e2cf
JB
3922 n_channels = 0;
3923
2a519311
JB
3924 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3925 if (wiphy->bands[band])
3926 n_channels += wiphy->bands[band]->n_channels;
3927 }
3928
3929 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3930 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3931 n_ssids++;
3932
4c476991
JB
3933 if (n_ssids > wiphy->max_scan_ssids)
3934 return -EINVAL;
2a519311 3935
70692ad2
JM
3936 if (info->attrs[NL80211_ATTR_IE])
3937 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3938 else
3939 ie_len = 0;
3940
4c476991
JB
3941 if (ie_len > wiphy->max_scan_ie_len)
3942 return -EINVAL;
18a83659 3943
2a519311 3944 request = kzalloc(sizeof(*request)
a2cd43c5
LC
3945 + sizeof(*request->ssids) * n_ssids
3946 + sizeof(*request->channels) * n_channels
70692ad2 3947 + ie_len, GFP_KERNEL);
4c476991
JB
3948 if (!request)
3949 return -ENOMEM;
2a519311 3950
2a519311 3951 if (n_ssids)
5ba63533 3952 request->ssids = (void *)&request->channels[n_channels];
2a519311 3953 request->n_ssids = n_ssids;
70692ad2
JM
3954 if (ie_len) {
3955 if (request->ssids)
3956 request->ie = (void *)(request->ssids + n_ssids);
3957 else
3958 request->ie = (void *)(request->channels + n_channels);
3959 }
2a519311 3960
584991dc 3961 i = 0;
2a519311
JB
3962 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3963 /* user specified, bail out if channel not found */
2a519311 3964 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3965 struct ieee80211_channel *chan;
3966
3967 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3968
3969 if (!chan) {
2a519311
JB
3970 err = -EINVAL;
3971 goto out_free;
3972 }
584991dc
JB
3973
3974 /* ignore disabled channels */
3975 if (chan->flags & IEEE80211_CHAN_DISABLED)
3976 continue;
3977
3978 request->channels[i] = chan;
2a519311
JB
3979 i++;
3980 }
3981 } else {
34850ab2
JB
3982 enum ieee80211_band band;
3983
2a519311 3984 /* all channels */
2a519311
JB
3985 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3986 int j;
3987 if (!wiphy->bands[band])
3988 continue;
3989 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3990 struct ieee80211_channel *chan;
3991
3992 chan = &wiphy->bands[band]->channels[j];
3993
3994 if (chan->flags & IEEE80211_CHAN_DISABLED)
3995 continue;
3996
3997 request->channels[i] = chan;
2a519311
JB
3998 i++;
3999 }
4000 }
4001 }
4002
584991dc
JB
4003 if (!i) {
4004 err = -EINVAL;
4005 goto out_free;
4006 }
4007
4008 request->n_channels = i;
4009
2a519311
JB
4010 i = 0;
4011 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4012 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4013 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4014 err = -EINVAL;
4015 goto out_free;
4016 }
57a27e1d 4017 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4018 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4019 i++;
4020 }
4021 }
4022
70692ad2
JM
4023 if (info->attrs[NL80211_ATTR_IE]) {
4024 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4025 memcpy((void *)request->ie,
4026 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4027 request->ie_len);
4028 }
4029
34850ab2 4030 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4031 if (wiphy->bands[i])
4032 request->rates[i] =
4033 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4034
4035 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4036 nla_for_each_nested(attr,
4037 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4038 tmp) {
4039 enum ieee80211_band band = nla_type(attr);
4040
84404623 4041 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4042 err = -EINVAL;
4043 goto out_free;
4044 }
4045 err = ieee80211_get_ratemask(wiphy->bands[band],
4046 nla_data(attr),
4047 nla_len(attr),
4048 &request->rates[band]);
4049 if (err)
4050 goto out_free;
4051 }
4052 }
4053
e9f935e3
RM
4054 request->no_cck =
4055 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4056
463d0183 4057 request->dev = dev;
79c97e97 4058 request->wiphy = &rdev->wiphy;
2a519311 4059
79c97e97
JB
4060 rdev->scan_req = request;
4061 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 4062
463d0183 4063 if (!err) {
79c97e97 4064 nl80211_send_scan_start(rdev, dev);
463d0183 4065 dev_hold(dev);
4c476991 4066 } else {
2a519311 4067 out_free:
79c97e97 4068 rdev->scan_req = NULL;
2a519311
JB
4069 kfree(request);
4070 }
3b85875a 4071
2a519311
JB
4072 return err;
4073}
4074
807f8a8c
LC
4075static int nl80211_start_sched_scan(struct sk_buff *skb,
4076 struct genl_info *info)
4077{
4078 struct cfg80211_sched_scan_request *request;
4079 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4080 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4081 struct nlattr *attr;
4082 struct wiphy *wiphy;
a1f1c21c 4083 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4084 u32 interval;
807f8a8c
LC
4085 enum ieee80211_band band;
4086 size_t ie_len;
a1f1c21c 4087 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4088
4089 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4090 !rdev->ops->sched_scan_start)
4091 return -EOPNOTSUPP;
4092
4093 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4094 return -EINVAL;
4095
bbe6ad6d
LC
4096 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4097 return -EINVAL;
4098
4099 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4100 if (interval == 0)
4101 return -EINVAL;
4102
807f8a8c
LC
4103 wiphy = &rdev->wiphy;
4104
4105 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4106 n_channels = validate_scan_freqs(
4107 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4108 if (!n_channels)
4109 return -EINVAL;
4110 } else {
4111 n_channels = 0;
4112
4113 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4114 if (wiphy->bands[band])
4115 n_channels += wiphy->bands[band]->n_channels;
4116 }
4117
4118 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4119 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4120 tmp)
4121 n_ssids++;
4122
93b6aa69 4123 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4124 return -EINVAL;
4125
a1f1c21c
LC
4126 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4127 nla_for_each_nested(attr,
4128 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4129 tmp)
4130 n_match_sets++;
4131
4132 if (n_match_sets > wiphy->max_match_sets)
4133 return -EINVAL;
4134
807f8a8c
LC
4135 if (info->attrs[NL80211_ATTR_IE])
4136 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4137 else
4138 ie_len = 0;
4139
5a865bad 4140 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4141 return -EINVAL;
4142
c10841ca
LC
4143 mutex_lock(&rdev->sched_scan_mtx);
4144
4145 if (rdev->sched_scan_req) {
4146 err = -EINPROGRESS;
4147 goto out;
4148 }
4149
807f8a8c 4150 request = kzalloc(sizeof(*request)
a2cd43c5 4151 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4152 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4153 + sizeof(*request->channels) * n_channels
807f8a8c 4154 + ie_len, GFP_KERNEL);
c10841ca
LC
4155 if (!request) {
4156 err = -ENOMEM;
4157 goto out;
4158 }
807f8a8c
LC
4159
4160 if (n_ssids)
4161 request->ssids = (void *)&request->channels[n_channels];
4162 request->n_ssids = n_ssids;
4163 if (ie_len) {
4164 if (request->ssids)
4165 request->ie = (void *)(request->ssids + n_ssids);
4166 else
4167 request->ie = (void *)(request->channels + n_channels);
4168 }
4169
a1f1c21c
LC
4170 if (n_match_sets) {
4171 if (request->ie)
4172 request->match_sets = (void *)(request->ie + ie_len);
4173 else if (request->ssids)
4174 request->match_sets =
4175 (void *)(request->ssids + n_ssids);
4176 else
4177 request->match_sets =
4178 (void *)(request->channels + n_channels);
4179 }
4180 request->n_match_sets = n_match_sets;
4181
807f8a8c
LC
4182 i = 0;
4183 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4184 /* user specified, bail out if channel not found */
4185 nla_for_each_nested(attr,
4186 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4187 tmp) {
4188 struct ieee80211_channel *chan;
4189
4190 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4191
4192 if (!chan) {
4193 err = -EINVAL;
4194 goto out_free;
4195 }
4196
4197 /* ignore disabled channels */
4198 if (chan->flags & IEEE80211_CHAN_DISABLED)
4199 continue;
4200
4201 request->channels[i] = chan;
4202 i++;
4203 }
4204 } else {
4205 /* all channels */
4206 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4207 int j;
4208 if (!wiphy->bands[band])
4209 continue;
4210 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4211 struct ieee80211_channel *chan;
4212
4213 chan = &wiphy->bands[band]->channels[j];
4214
4215 if (chan->flags & IEEE80211_CHAN_DISABLED)
4216 continue;
4217
4218 request->channels[i] = chan;
4219 i++;
4220 }
4221 }
4222 }
4223
4224 if (!i) {
4225 err = -EINVAL;
4226 goto out_free;
4227 }
4228
4229 request->n_channels = i;
4230
4231 i = 0;
4232 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4233 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4234 tmp) {
57a27e1d 4235 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4236 err = -EINVAL;
4237 goto out_free;
4238 }
57a27e1d 4239 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4240 memcpy(request->ssids[i].ssid, nla_data(attr),
4241 nla_len(attr));
807f8a8c
LC
4242 i++;
4243 }
4244 }
4245
a1f1c21c
LC
4246 i = 0;
4247 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4248 nla_for_each_nested(attr,
4249 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4250 tmp) {
4251 struct nlattr *ssid;
4252
4253 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4254 nla_data(attr), nla_len(attr),
4255 nl80211_match_policy);
4a4ab0d7 4256 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4257 if (ssid) {
4258 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4259 err = -EINVAL;
4260 goto out_free;
4261 }
4262 memcpy(request->match_sets[i].ssid.ssid,
4263 nla_data(ssid), nla_len(ssid));
4264 request->match_sets[i].ssid.ssid_len =
4265 nla_len(ssid);
4266 }
4267 i++;
4268 }
4269 }
4270
807f8a8c
LC
4271 if (info->attrs[NL80211_ATTR_IE]) {
4272 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4273 memcpy((void *)request->ie,
4274 nla_data(info->attrs[NL80211_ATTR_IE]),
4275 request->ie_len);
4276 }
4277
4278 request->dev = dev;
4279 request->wiphy = &rdev->wiphy;
bbe6ad6d 4280 request->interval = interval;
807f8a8c
LC
4281
4282 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
4283 if (!err) {
4284 rdev->sched_scan_req = request;
4285 nl80211_send_sched_scan(rdev, dev,
4286 NL80211_CMD_START_SCHED_SCAN);
4287 goto out;
4288 }
4289
4290out_free:
4291 kfree(request);
4292out:
c10841ca 4293 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4294 return err;
4295}
4296
4297static int nl80211_stop_sched_scan(struct sk_buff *skb,
4298 struct genl_info *info)
4299{
4300 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4301 int err;
807f8a8c
LC
4302
4303 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4304 !rdev->ops->sched_scan_stop)
4305 return -EOPNOTSUPP;
4306
c10841ca
LC
4307 mutex_lock(&rdev->sched_scan_mtx);
4308 err = __cfg80211_stop_sched_scan(rdev, false);
4309 mutex_unlock(&rdev->sched_scan_mtx);
4310
4311 return err;
807f8a8c
LC
4312}
4313
9720bb3a
JB
4314static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4315 u32 seq, int flags,
2a519311 4316 struct cfg80211_registered_device *rdev,
48ab905d
JB
4317 struct wireless_dev *wdev,
4318 struct cfg80211_internal_bss *intbss)
2a519311 4319{
48ab905d 4320 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
4321 void *hdr;
4322 struct nlattr *bss;
48ab905d
JB
4323
4324 ASSERT_WDEV_LOCK(wdev);
2a519311 4325
9720bb3a 4326 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
4327 NL80211_CMD_NEW_SCAN_RESULTS);
4328 if (!hdr)
4329 return -1;
4330
9720bb3a
JB
4331 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4332
9360ffd1
DM
4333 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
4334 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
4335 goto nla_put_failure;
2a519311
JB
4336
4337 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4338 if (!bss)
4339 goto nla_put_failure;
9360ffd1
DM
4340 if ((!is_zero_ether_addr(res->bssid) &&
4341 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)) ||
4342 (res->information_elements && res->len_information_elements &&
4343 nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4344 res->len_information_elements,
4345 res->information_elements)) ||
4346 (res->beacon_ies && res->len_beacon_ies &&
4347 res->beacon_ies != res->information_elements &&
4348 nla_put(msg, NL80211_BSS_BEACON_IES,
4349 res->len_beacon_ies, res->beacon_ies)))
4350 goto nla_put_failure;
4351 if (res->tsf &&
4352 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
4353 goto nla_put_failure;
4354 if (res->beacon_interval &&
4355 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
4356 goto nla_put_failure;
4357 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
4358 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
4359 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
4360 jiffies_to_msecs(jiffies - intbss->ts)))
4361 goto nla_put_failure;
2a519311 4362
77965c97 4363 switch (rdev->wiphy.signal_type) {
2a519311 4364 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
4365 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
4366 goto nla_put_failure;
2a519311
JB
4367 break;
4368 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
4369 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
4370 goto nla_put_failure;
2a519311
JB
4371 break;
4372 default:
4373 break;
4374 }
4375
48ab905d 4376 switch (wdev->iftype) {
074ac8df 4377 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 4378 case NL80211_IFTYPE_STATION:
9360ffd1
DM
4379 if (intbss == wdev->current_bss &&
4380 nla_put_u32(msg, NL80211_BSS_STATUS,
4381 NL80211_BSS_STATUS_ASSOCIATED))
4382 goto nla_put_failure;
48ab905d
JB
4383 break;
4384 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
4385 if (intbss == wdev->current_bss &&
4386 nla_put_u32(msg, NL80211_BSS_STATUS,
4387 NL80211_BSS_STATUS_IBSS_JOINED))
4388 goto nla_put_failure;
48ab905d
JB
4389 break;
4390 default:
4391 break;
4392 }
4393
2a519311
JB
4394 nla_nest_end(msg, bss);
4395
4396 return genlmsg_end(msg, hdr);
4397
4398 nla_put_failure:
4399 genlmsg_cancel(msg, hdr);
4400 return -EMSGSIZE;
4401}
4402
4403static int nl80211_dump_scan(struct sk_buff *skb,
4404 struct netlink_callback *cb)
4405{
48ab905d
JB
4406 struct cfg80211_registered_device *rdev;
4407 struct net_device *dev;
2a519311 4408 struct cfg80211_internal_bss *scan;
48ab905d 4409 struct wireless_dev *wdev;
2a519311
JB
4410 int start = cb->args[1], idx = 0;
4411 int err;
4412
67748893
JB
4413 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4414 if (err)
4415 return err;
2a519311 4416
48ab905d 4417 wdev = dev->ieee80211_ptr;
2a519311 4418
48ab905d
JB
4419 wdev_lock(wdev);
4420 spin_lock_bh(&rdev->bss_lock);
4421 cfg80211_bss_expire(rdev);
4422
9720bb3a
JB
4423 cb->seq = rdev->bss_generation;
4424
48ab905d 4425 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4426 if (++idx <= start)
4427 continue;
9720bb3a 4428 if (nl80211_send_bss(skb, cb,
2a519311 4429 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4430 rdev, wdev, scan) < 0) {
2a519311 4431 idx--;
67748893 4432 break;
2a519311
JB
4433 }
4434 }
4435
48ab905d
JB
4436 spin_unlock_bh(&rdev->bss_lock);
4437 wdev_unlock(wdev);
2a519311
JB
4438
4439 cb->args[1] = idx;
67748893 4440 nl80211_finish_netdev_dump(rdev);
2a519311 4441
67748893 4442 return skb->len;
2a519311
JB
4443}
4444
61fa713c
HS
4445static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4446 int flags, struct net_device *dev,
4447 struct survey_info *survey)
4448{
4449 void *hdr;
4450 struct nlattr *infoattr;
4451
61fa713c
HS
4452 hdr = nl80211hdr_put(msg, pid, seq, flags,
4453 NL80211_CMD_NEW_SURVEY_RESULTS);
4454 if (!hdr)
4455 return -ENOMEM;
4456
9360ffd1
DM
4457 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
4458 goto nla_put_failure;
61fa713c
HS
4459
4460 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4461 if (!infoattr)
4462 goto nla_put_failure;
4463
9360ffd1
DM
4464 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4465 survey->channel->center_freq))
4466 goto nla_put_failure;
4467
4468 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
4469 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
4470 goto nla_put_failure;
4471 if ((survey->filled & SURVEY_INFO_IN_USE) &&
4472 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
4473 goto nla_put_failure;
4474 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
4475 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4476 survey->channel_time))
4477 goto nla_put_failure;
4478 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
4479 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4480 survey->channel_time_busy))
4481 goto nla_put_failure;
4482 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
4483 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4484 survey->channel_time_ext_busy))
4485 goto nla_put_failure;
4486 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
4487 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4488 survey->channel_time_rx))
4489 goto nla_put_failure;
4490 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
4491 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4492 survey->channel_time_tx))
4493 goto nla_put_failure;
61fa713c
HS
4494
4495 nla_nest_end(msg, infoattr);
4496
4497 return genlmsg_end(msg, hdr);
4498
4499 nla_put_failure:
4500 genlmsg_cancel(msg, hdr);
4501 return -EMSGSIZE;
4502}
4503
4504static int nl80211_dump_survey(struct sk_buff *skb,
4505 struct netlink_callback *cb)
4506{
4507 struct survey_info survey;
4508 struct cfg80211_registered_device *dev;
4509 struct net_device *netdev;
61fa713c
HS
4510 int survey_idx = cb->args[1];
4511 int res;
4512
67748893
JB
4513 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4514 if (res)
4515 return res;
61fa713c
HS
4516
4517 if (!dev->ops->dump_survey) {
4518 res = -EOPNOTSUPP;
4519 goto out_err;
4520 }
4521
4522 while (1) {
180cdc79
LR
4523 struct ieee80211_channel *chan;
4524
61fa713c
HS
4525 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4526 &survey);
4527 if (res == -ENOENT)
4528 break;
4529 if (res)
4530 goto out_err;
4531
180cdc79
LR
4532 /* Survey without a channel doesn't make sense */
4533 if (!survey.channel) {
4534 res = -EINVAL;
4535 goto out;
4536 }
4537
4538 chan = ieee80211_get_channel(&dev->wiphy,
4539 survey.channel->center_freq);
4540 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4541 survey_idx++;
4542 continue;
4543 }
4544
61fa713c
HS
4545 if (nl80211_send_survey(skb,
4546 NETLINK_CB(cb->skb).pid,
4547 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4548 netdev,
4549 &survey) < 0)
4550 goto out;
4551 survey_idx++;
4552 }
4553
4554 out:
4555 cb->args[1] = survey_idx;
4556 res = skb->len;
4557 out_err:
67748893 4558 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4559 return res;
4560}
4561
255e737e
JM
4562static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4563{
b23aa676
SO
4564 return auth_type <= NL80211_AUTHTYPE_MAX;
4565}
4566
4567static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4568{
4569 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4570 NL80211_WPA_VERSION_2));
4571}
4572
636a5d36
JM
4573static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4574{
4c476991
JB
4575 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4576 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4577 struct ieee80211_channel *chan;
4578 const u8 *bssid, *ssid, *ie = NULL;
4579 int err, ssid_len, ie_len = 0;
4580 enum nl80211_auth_type auth_type;
fffd0934 4581 struct key_parse key;
d5cdfacb 4582 bool local_state_change;
636a5d36 4583
f4a11bb0
JB
4584 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4585 return -EINVAL;
4586
4587 if (!info->attrs[NL80211_ATTR_MAC])
4588 return -EINVAL;
4589
1778092e
JM
4590 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4591 return -EINVAL;
4592
19957bb3
JB
4593 if (!info->attrs[NL80211_ATTR_SSID])
4594 return -EINVAL;
4595
4596 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4597 return -EINVAL;
4598
fffd0934
JB
4599 err = nl80211_parse_key(info, &key);
4600 if (err)
4601 return err;
4602
4603 if (key.idx >= 0) {
e31b8213
JB
4604 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4605 return -EINVAL;
fffd0934
JB
4606 if (!key.p.key || !key.p.key_len)
4607 return -EINVAL;
4608 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4609 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4610 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4611 key.p.key_len != WLAN_KEY_LEN_WEP104))
4612 return -EINVAL;
4613 if (key.idx > 4)
4614 return -EINVAL;
4615 } else {
4616 key.p.key_len = 0;
4617 key.p.key = NULL;
4618 }
4619
afea0b7a
JB
4620 if (key.idx >= 0) {
4621 int i;
4622 bool ok = false;
4623 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4624 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4625 ok = true;
4626 break;
4627 }
4628 }
4c476991
JB
4629 if (!ok)
4630 return -EINVAL;
afea0b7a
JB
4631 }
4632
4c476991
JB
4633 if (!rdev->ops->auth)
4634 return -EOPNOTSUPP;
636a5d36 4635
074ac8df 4636 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4637 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4638 return -EOPNOTSUPP;
eec60b03 4639
19957bb3 4640 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4641 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4642 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4643 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4644 return -EINVAL;
636a5d36 4645
19957bb3
JB
4646 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4647 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4648
4649 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4650 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4651 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4652 }
4653
19957bb3 4654 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4655 if (!nl80211_valid_auth_type(auth_type))
4656 return -EINVAL;
636a5d36 4657
d5cdfacb
JM
4658 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4659
95de817b
JB
4660 /*
4661 * Since we no longer track auth state, ignore
4662 * requests to only change local state.
4663 */
4664 if (local_state_change)
4665 return 0;
4666
4c476991
JB
4667 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4668 ssid, ssid_len, ie, ie_len,
95de817b 4669 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
4670}
4671
c0692b8f
JB
4672static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4673 struct genl_info *info,
3dc27d25
JB
4674 struct cfg80211_crypto_settings *settings,
4675 int cipher_limit)
b23aa676 4676{
c0b2bbd8
JB
4677 memset(settings, 0, sizeof(*settings));
4678
b23aa676
SO
4679 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4680
c0692b8f
JB
4681 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4682 u16 proto;
4683 proto = nla_get_u16(
4684 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4685 settings->control_port_ethertype = cpu_to_be16(proto);
4686 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4687 proto != ETH_P_PAE)
4688 return -EINVAL;
4689 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4690 settings->control_port_no_encrypt = true;
4691 } else
4692 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4693
b23aa676
SO
4694 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4695 void *data;
4696 int len, i;
4697
4698 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4699 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4700 settings->n_ciphers_pairwise = len / sizeof(u32);
4701
4702 if (len % sizeof(u32))
4703 return -EINVAL;
4704
3dc27d25 4705 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4706 return -EINVAL;
4707
4708 memcpy(settings->ciphers_pairwise, data, len);
4709
4710 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4711 if (!cfg80211_supported_cipher_suite(
4712 &rdev->wiphy,
b23aa676
SO
4713 settings->ciphers_pairwise[i]))
4714 return -EINVAL;
4715 }
4716
4717 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4718 settings->cipher_group =
4719 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4720 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4721 settings->cipher_group))
b23aa676
SO
4722 return -EINVAL;
4723 }
4724
4725 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4726 settings->wpa_versions =
4727 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4728 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4729 return -EINVAL;
4730 }
4731
4732 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4733 void *data;
6d30240e 4734 int len;
b23aa676
SO
4735
4736 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4737 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4738 settings->n_akm_suites = len / sizeof(u32);
4739
4740 if (len % sizeof(u32))
4741 return -EINVAL;
4742
1b9ca027
JM
4743 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4744 return -EINVAL;
4745
b23aa676 4746 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4747 }
4748
4749 return 0;
4750}
4751
636a5d36
JM
4752static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4753{
4c476991
JB
4754 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4755 struct net_device *dev = info->user_ptr[1];
19957bb3 4756 struct cfg80211_crypto_settings crypto;
f444de05 4757 struct ieee80211_channel *chan;
3e5d7649 4758 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4759 int err, ssid_len, ie_len = 0;
4760 bool use_mfp = false;
7e7c8926
BG
4761 u32 flags = 0;
4762 struct ieee80211_ht_cap *ht_capa = NULL;
4763 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 4764
f4a11bb0
JB
4765 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4766 return -EINVAL;
4767
4768 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4769 !info->attrs[NL80211_ATTR_SSID] ||
4770 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4771 return -EINVAL;
4772
4c476991
JB
4773 if (!rdev->ops->assoc)
4774 return -EOPNOTSUPP;
636a5d36 4775
074ac8df 4776 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4777 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4778 return -EOPNOTSUPP;
eec60b03 4779
19957bb3 4780 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4781
19957bb3
JB
4782 chan = ieee80211_get_channel(&rdev->wiphy,
4783 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4784 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4785 return -EINVAL;
636a5d36 4786
19957bb3
JB
4787 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4788 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4789
4790 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4791 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4792 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4793 }
4794
dc6382ce 4795 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4796 enum nl80211_mfp mfp =
dc6382ce 4797 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4798 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4799 use_mfp = true;
4c476991
JB
4800 else if (mfp != NL80211_MFP_NO)
4801 return -EINVAL;
dc6382ce
JM
4802 }
4803
3e5d7649
JB
4804 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4805 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4806
7e7c8926
BG
4807 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
4808 flags |= ASSOC_REQ_DISABLE_HT;
4809
4810 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
4811 ht_capa_mask =
4812 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
4813
4814 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
4815 if (!ht_capa_mask)
4816 return -EINVAL;
4817 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4818 }
4819
c0692b8f 4820 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4821 if (!err)
3e5d7649
JB
4822 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4823 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
4824 &crypto, flags, ht_capa,
4825 ht_capa_mask);
636a5d36 4826
636a5d36
JM
4827 return err;
4828}
4829
4830static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4831{
4c476991
JB
4832 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4833 struct net_device *dev = info->user_ptr[1];
19957bb3 4834 const u8 *ie = NULL, *bssid;
4c476991 4835 int ie_len = 0;
19957bb3 4836 u16 reason_code;
d5cdfacb 4837 bool local_state_change;
636a5d36 4838
f4a11bb0
JB
4839 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4840 return -EINVAL;
4841
4842 if (!info->attrs[NL80211_ATTR_MAC])
4843 return -EINVAL;
4844
4845 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4846 return -EINVAL;
4847
4c476991
JB
4848 if (!rdev->ops->deauth)
4849 return -EOPNOTSUPP;
636a5d36 4850
074ac8df 4851 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4852 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4853 return -EOPNOTSUPP;
eec60b03 4854
19957bb3 4855 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4856
19957bb3
JB
4857 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4858 if (reason_code == 0) {
f4a11bb0 4859 /* Reason Code 0 is reserved */
4c476991 4860 return -EINVAL;
255e737e 4861 }
636a5d36
JM
4862
4863 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4864 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4865 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4866 }
4867
d5cdfacb
JM
4868 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4869
4c476991
JB
4870 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4871 local_state_change);
636a5d36
JM
4872}
4873
4874static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4875{
4c476991
JB
4876 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4877 struct net_device *dev = info->user_ptr[1];
19957bb3 4878 const u8 *ie = NULL, *bssid;
4c476991 4879 int ie_len = 0;
19957bb3 4880 u16 reason_code;
d5cdfacb 4881 bool local_state_change;
636a5d36 4882
f4a11bb0
JB
4883 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4884 return -EINVAL;
4885
4886 if (!info->attrs[NL80211_ATTR_MAC])
4887 return -EINVAL;
4888
4889 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4890 return -EINVAL;
4891
4c476991
JB
4892 if (!rdev->ops->disassoc)
4893 return -EOPNOTSUPP;
636a5d36 4894
074ac8df 4895 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4896 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4897 return -EOPNOTSUPP;
eec60b03 4898
19957bb3 4899 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4900
19957bb3
JB
4901 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4902 if (reason_code == 0) {
f4a11bb0 4903 /* Reason Code 0 is reserved */
4c476991 4904 return -EINVAL;
255e737e 4905 }
636a5d36
JM
4906
4907 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4908 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4909 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4910 }
4911
d5cdfacb
JM
4912 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4913
4c476991
JB
4914 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4915 local_state_change);
636a5d36
JM
4916}
4917
dd5b4cc7
FF
4918static bool
4919nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4920 int mcast_rate[IEEE80211_NUM_BANDS],
4921 int rateval)
4922{
4923 struct wiphy *wiphy = &rdev->wiphy;
4924 bool found = false;
4925 int band, i;
4926
4927 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4928 struct ieee80211_supported_band *sband;
4929
4930 sband = wiphy->bands[band];
4931 if (!sband)
4932 continue;
4933
4934 for (i = 0; i < sband->n_bitrates; i++) {
4935 if (sband->bitrates[i].bitrate == rateval) {
4936 mcast_rate[band] = i + 1;
4937 found = true;
4938 break;
4939 }
4940 }
4941 }
4942
4943 return found;
4944}
4945
04a773ad
JB
4946static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4947{
4c476991
JB
4948 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4949 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4950 struct cfg80211_ibss_params ibss;
4951 struct wiphy *wiphy;
fffd0934 4952 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4953 int err;
4954
8e30bc55
JB
4955 memset(&ibss, 0, sizeof(ibss));
4956
04a773ad
JB
4957 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4958 return -EINVAL;
4959
4960 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4961 !info->attrs[NL80211_ATTR_SSID] ||
4962 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4963 return -EINVAL;
4964
8e30bc55
JB
4965 ibss.beacon_interval = 100;
4966
4967 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4968 ibss.beacon_interval =
4969 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4970 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4971 return -EINVAL;
4972 }
4973
4c476991
JB
4974 if (!rdev->ops->join_ibss)
4975 return -EOPNOTSUPP;
04a773ad 4976
4c476991
JB
4977 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4978 return -EOPNOTSUPP;
04a773ad 4979
79c97e97 4980 wiphy = &rdev->wiphy;
04a773ad 4981
39193498 4982 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 4983 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
4984
4985 if (!is_valid_ether_addr(ibss.bssid))
4986 return -EINVAL;
4987 }
04a773ad
JB
4988 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4989 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4990
4991 if (info->attrs[NL80211_ATTR_IE]) {
4992 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4993 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4994 }
4995
54858ee5
AS
4996 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4997 enum nl80211_channel_type channel_type;
4998
cd6c6598 4999 if (!nl80211_valid_channel_type(info, &channel_type))
54858ee5
AS
5000 return -EINVAL;
5001
5002 if (channel_type != NL80211_CHAN_NO_HT &&
5003 !(wiphy->features & NL80211_FEATURE_HT_IBSS))
5004 return -EINVAL;
5005
5006 ibss.channel_type = channel_type;
5007 } else {
5008 ibss.channel_type = NL80211_CHAN_NO_HT;
5009 }
5010
5011 ibss.channel = rdev_freq_to_chan(rdev,
5012 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
5013 ibss.channel_type);
04a773ad
JB
5014 if (!ibss.channel ||
5015 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
5016 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
5017 return -EINVAL;
04a773ad 5018
54858ee5
AS
5019 /* Both channels should be able to initiate communication */
5020 if ((ibss.channel_type == NL80211_CHAN_HT40PLUS ||
5021 ibss.channel_type == NL80211_CHAN_HT40MINUS) &&
5022 !cfg80211_can_beacon_sec_chan(&rdev->wiphy, ibss.channel,
5023 ibss.channel_type))
5024 return -EINVAL;
5025
04a773ad 5026 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5027 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5028
fbd2c8dc
TP
5029 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5030 u8 *rates =
5031 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5032 int n_rates =
5033 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5034 struct ieee80211_supported_band *sband =
5035 wiphy->bands[ibss.channel->band];
fbd2c8dc 5036
34850ab2
JB
5037 err = ieee80211_get_ratemask(sband, rates, n_rates,
5038 &ibss.basic_rates);
5039 if (err)
5040 return err;
fbd2c8dc 5041 }
dd5b4cc7
FF
5042
5043 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5044 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5045 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5046 return -EINVAL;
fbd2c8dc 5047
4c476991
JB
5048 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5049 connkeys = nl80211_parse_connkeys(rdev,
5050 info->attrs[NL80211_ATTR_KEYS]);
5051 if (IS_ERR(connkeys))
5052 return PTR_ERR(connkeys);
5053 }
04a773ad 5054
267335d6
AQ
5055 ibss.control_port =
5056 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5057
4c476991 5058 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5059 if (err)
5060 kfree(connkeys);
04a773ad
JB
5061 return err;
5062}
5063
5064static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5065{
4c476991
JB
5066 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5067 struct net_device *dev = info->user_ptr[1];
04a773ad 5068
4c476991
JB
5069 if (!rdev->ops->leave_ibss)
5070 return -EOPNOTSUPP;
04a773ad 5071
4c476991
JB
5072 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5073 return -EOPNOTSUPP;
04a773ad 5074
4c476991 5075 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5076}
5077
aff89a9b
JB
5078#ifdef CONFIG_NL80211_TESTMODE
5079static struct genl_multicast_group nl80211_testmode_mcgrp = {
5080 .name = "testmode",
5081};
5082
5083static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5084{
4c476991 5085 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5086 int err;
5087
5088 if (!info->attrs[NL80211_ATTR_TESTDATA])
5089 return -EINVAL;
5090
aff89a9b
JB
5091 err = -EOPNOTSUPP;
5092 if (rdev->ops->testmode_cmd) {
5093 rdev->testmode_info = info;
5094 err = rdev->ops->testmode_cmd(&rdev->wiphy,
5095 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5096 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5097 rdev->testmode_info = NULL;
5098 }
5099
aff89a9b
JB
5100 return err;
5101}
5102
71063f0e
WYG
5103static int nl80211_testmode_dump(struct sk_buff *skb,
5104 struct netlink_callback *cb)
5105{
00918d33 5106 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5107 int err;
5108 long phy_idx;
5109 void *data = NULL;
5110 int data_len = 0;
5111
5112 if (cb->args[0]) {
5113 /*
5114 * 0 is a valid index, but not valid for args[0],
5115 * so we need to offset by 1.
5116 */
5117 phy_idx = cb->args[0] - 1;
5118 } else {
5119 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5120 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5121 nl80211_policy);
5122 if (err)
5123 return err;
00918d33
JB
5124 if (nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]) {
5125 phy_idx = nla_get_u32(
5126 nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
5127 } else {
5128 struct net_device *netdev;
5129
5130 err = get_rdev_dev_by_ifindex(sock_net(skb->sk),
5131 nl80211_fam.attrbuf,
5132 &rdev, &netdev);
5133 if (err)
5134 return err;
5135 dev_put(netdev);
5136 phy_idx = rdev->wiphy_idx;
5137 cfg80211_unlock_rdev(rdev);
5138 }
71063f0e
WYG
5139 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5140 cb->args[1] =
5141 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5142 }
5143
5144 if (cb->args[1]) {
5145 data = nla_data((void *)cb->args[1]);
5146 data_len = nla_len((void *)cb->args[1]);
5147 }
5148
5149 mutex_lock(&cfg80211_mutex);
00918d33
JB
5150 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5151 if (!rdev) {
71063f0e
WYG
5152 mutex_unlock(&cfg80211_mutex);
5153 return -ENOENT;
5154 }
00918d33 5155 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5156 mutex_unlock(&cfg80211_mutex);
5157
00918d33 5158 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5159 err = -EOPNOTSUPP;
5160 goto out_err;
5161 }
5162
5163 while (1) {
5164 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
5165 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5166 NL80211_CMD_TESTMODE);
5167 struct nlattr *tmdata;
5168
9360ffd1 5169 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5170 genlmsg_cancel(skb, hdr);
5171 break;
5172 }
5173
5174 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5175 if (!tmdata) {
5176 genlmsg_cancel(skb, hdr);
5177 break;
5178 }
00918d33
JB
5179 err = rdev->ops->testmode_dump(&rdev->wiphy, skb, cb,
5180 data, data_len);
71063f0e
WYG
5181 nla_nest_end(skb, tmdata);
5182
5183 if (err == -ENOBUFS || err == -ENOENT) {
5184 genlmsg_cancel(skb, hdr);
5185 break;
5186 } else if (err) {
5187 genlmsg_cancel(skb, hdr);
5188 goto out_err;
5189 }
5190
5191 genlmsg_end(skb, hdr);
5192 }
5193
5194 err = skb->len;
5195 /* see above */
5196 cb->args[0] = phy_idx + 1;
5197 out_err:
00918d33 5198 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5199 return err;
5200}
5201
aff89a9b
JB
5202static struct sk_buff *
5203__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
5204 int approxlen, u32 pid, u32 seq, gfp_t gfp)
5205{
5206 struct sk_buff *skb;
5207 void *hdr;
5208 struct nlattr *data;
5209
5210 skb = nlmsg_new(approxlen + 100, gfp);
5211 if (!skb)
5212 return NULL;
5213
5214 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
5215 if (!hdr) {
5216 kfree_skb(skb);
5217 return NULL;
5218 }
5219
9360ffd1
DM
5220 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5221 goto nla_put_failure;
aff89a9b
JB
5222 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5223
5224 ((void **)skb->cb)[0] = rdev;
5225 ((void **)skb->cb)[1] = hdr;
5226 ((void **)skb->cb)[2] = data;
5227
5228 return skb;
5229
5230 nla_put_failure:
5231 kfree_skb(skb);
5232 return NULL;
5233}
5234
5235struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5236 int approxlen)
5237{
5238 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5239
5240 if (WARN_ON(!rdev->testmode_info))
5241 return NULL;
5242
5243 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
5244 rdev->testmode_info->snd_pid,
5245 rdev->testmode_info->snd_seq,
5246 GFP_KERNEL);
5247}
5248EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5249
5250int cfg80211_testmode_reply(struct sk_buff *skb)
5251{
5252 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5253 void *hdr = ((void **)skb->cb)[1];
5254 struct nlattr *data = ((void **)skb->cb)[2];
5255
5256 if (WARN_ON(!rdev->testmode_info)) {
5257 kfree_skb(skb);
5258 return -EINVAL;
5259 }
5260
5261 nla_nest_end(skb, data);
5262 genlmsg_end(skb, hdr);
5263 return genlmsg_reply(skb, rdev->testmode_info);
5264}
5265EXPORT_SYMBOL(cfg80211_testmode_reply);
5266
5267struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5268 int approxlen, gfp_t gfp)
5269{
5270 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5271
5272 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5273}
5274EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5275
5276void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5277{
5278 void *hdr = ((void **)skb->cb)[1];
5279 struct nlattr *data = ((void **)skb->cb)[2];
5280
5281 nla_nest_end(skb, data);
5282 genlmsg_end(skb, hdr);
5283 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5284}
5285EXPORT_SYMBOL(cfg80211_testmode_event);
5286#endif
5287
b23aa676
SO
5288static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5289{
4c476991
JB
5290 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5291 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5292 struct cfg80211_connect_params connect;
5293 struct wiphy *wiphy;
fffd0934 5294 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5295 int err;
5296
5297 memset(&connect, 0, sizeof(connect));
5298
5299 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5300 return -EINVAL;
5301
5302 if (!info->attrs[NL80211_ATTR_SSID] ||
5303 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5304 return -EINVAL;
5305
5306 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5307 connect.auth_type =
5308 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
5309 if (!nl80211_valid_auth_type(connect.auth_type))
5310 return -EINVAL;
5311 } else
5312 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5313
5314 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5315
c0692b8f 5316 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5317 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5318 if (err)
5319 return err;
b23aa676 5320
074ac8df 5321 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5322 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5323 return -EOPNOTSUPP;
b23aa676 5324
79c97e97 5325 wiphy = &rdev->wiphy;
b23aa676 5326
4486ea98
BS
5327 connect.bg_scan_period = -1;
5328 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5329 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5330 connect.bg_scan_period =
5331 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5332 }
5333
b23aa676
SO
5334 if (info->attrs[NL80211_ATTR_MAC])
5335 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5336 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5337 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5338
5339 if (info->attrs[NL80211_ATTR_IE]) {
5340 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5341 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5342 }
5343
5344 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5345 connect.channel =
5346 ieee80211_get_channel(wiphy,
5347 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5348 if (!connect.channel ||
4c476991
JB
5349 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5350 return -EINVAL;
b23aa676
SO
5351 }
5352
fffd0934
JB
5353 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5354 connkeys = nl80211_parse_connkeys(rdev,
5355 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
5356 if (IS_ERR(connkeys))
5357 return PTR_ERR(connkeys);
fffd0934
JB
5358 }
5359
7e7c8926
BG
5360 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5361 connect.flags |= ASSOC_REQ_DISABLE_HT;
5362
5363 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5364 memcpy(&connect.ht_capa_mask,
5365 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5366 sizeof(connect.ht_capa_mask));
5367
5368 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5369 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5370 return -EINVAL;
5371 memcpy(&connect.ht_capa,
5372 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5373 sizeof(connect.ht_capa));
5374 }
5375
fffd0934 5376 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5377 if (err)
5378 kfree(connkeys);
b23aa676
SO
5379 return err;
5380}
5381
5382static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5383{
4c476991
JB
5384 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5385 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5386 u16 reason;
5387
5388 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5389 reason = WLAN_REASON_DEAUTH_LEAVING;
5390 else
5391 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5392
5393 if (reason == 0)
5394 return -EINVAL;
5395
074ac8df 5396 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5397 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5398 return -EOPNOTSUPP;
b23aa676 5399
4c476991 5400 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
5401}
5402
463d0183
JB
5403static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5404{
4c476991 5405 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
5406 struct net *net;
5407 int err;
5408 u32 pid;
5409
5410 if (!info->attrs[NL80211_ATTR_PID])
5411 return -EINVAL;
5412
5413 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5414
463d0183 5415 net = get_net_ns_by_pid(pid);
4c476991
JB
5416 if (IS_ERR(net))
5417 return PTR_ERR(net);
463d0183
JB
5418
5419 err = 0;
5420
5421 /* check if anything to do */
4c476991
JB
5422 if (!net_eq(wiphy_net(&rdev->wiphy), net))
5423 err = cfg80211_switch_netns(rdev, net);
463d0183 5424
463d0183 5425 put_net(net);
463d0183
JB
5426 return err;
5427}
5428
67fbb16b
SO
5429static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5430{
4c476991 5431 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
5432 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5433 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 5434 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
5435 struct cfg80211_pmksa pmksa;
5436
5437 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5438
5439 if (!info->attrs[NL80211_ATTR_MAC])
5440 return -EINVAL;
5441
5442 if (!info->attrs[NL80211_ATTR_PMKID])
5443 return -EINVAL;
5444
67fbb16b
SO
5445 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5446 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5447
074ac8df 5448 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5449 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5450 return -EOPNOTSUPP;
67fbb16b
SO
5451
5452 switch (info->genlhdr->cmd) {
5453 case NL80211_CMD_SET_PMKSA:
5454 rdev_ops = rdev->ops->set_pmksa;
5455 break;
5456 case NL80211_CMD_DEL_PMKSA:
5457 rdev_ops = rdev->ops->del_pmksa;
5458 break;
5459 default:
5460 WARN_ON(1);
5461 break;
5462 }
5463
4c476991
JB
5464 if (!rdev_ops)
5465 return -EOPNOTSUPP;
67fbb16b 5466
4c476991 5467 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
5468}
5469
5470static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5471{
4c476991
JB
5472 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5473 struct net_device *dev = info->user_ptr[1];
67fbb16b 5474
074ac8df 5475 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5476 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5477 return -EOPNOTSUPP;
67fbb16b 5478
4c476991
JB
5479 if (!rdev->ops->flush_pmksa)
5480 return -EOPNOTSUPP;
67fbb16b 5481
4c476991 5482 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5483}
5484
109086ce
AN
5485static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5486{
5487 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5488 struct net_device *dev = info->user_ptr[1];
5489 u8 action_code, dialog_token;
5490 u16 status_code;
5491 u8 *peer;
5492
5493 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5494 !rdev->ops->tdls_mgmt)
5495 return -EOPNOTSUPP;
5496
5497 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5498 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5499 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5500 !info->attrs[NL80211_ATTR_IE] ||
5501 !info->attrs[NL80211_ATTR_MAC])
5502 return -EINVAL;
5503
5504 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5505 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5506 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5507 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5508
5509 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5510 dialog_token, status_code,
5511 nla_data(info->attrs[NL80211_ATTR_IE]),
5512 nla_len(info->attrs[NL80211_ATTR_IE]));
5513}
5514
5515static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5516{
5517 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5518 struct net_device *dev = info->user_ptr[1];
5519 enum nl80211_tdls_operation operation;
5520 u8 *peer;
5521
5522 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5523 !rdev->ops->tdls_oper)
5524 return -EOPNOTSUPP;
5525
5526 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5527 !info->attrs[NL80211_ATTR_MAC])
5528 return -EINVAL;
5529
5530 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5531 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5532
5533 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5534}
5535
9588bbd5
JM
5536static int nl80211_remain_on_channel(struct sk_buff *skb,
5537 struct genl_info *info)
5538{
4c476991
JB
5539 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5540 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5541 struct ieee80211_channel *chan;
5542 struct sk_buff *msg;
5543 void *hdr;
5544 u64 cookie;
5545 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5546 u32 freq, duration;
5547 int err;
5548
5549 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5550 !info->attrs[NL80211_ATTR_DURATION])
5551 return -EINVAL;
5552
5553 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5554
ebf348fc
JB
5555 if (!rdev->ops->remain_on_channel ||
5556 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
5557 return -EOPNOTSUPP;
5558
9588bbd5 5559 /*
ebf348fc
JB
5560 * We should be on that channel for at least a minimum amount of
5561 * time (10ms) but no longer than the driver supports.
9588bbd5 5562 */
ebf348fc 5563 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 5564 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5565 return -EINVAL;
5566
cd6c6598
JB
5567 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
5568 !nl80211_valid_channel_type(info, &channel_type))
5569 return -EINVAL;
9588bbd5
JM
5570
5571 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5572 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5573 if (chan == NULL)
5574 return -EINVAL;
9588bbd5
JM
5575
5576 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5577 if (!msg)
5578 return -ENOMEM;
9588bbd5
JM
5579
5580 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5581 NL80211_CMD_REMAIN_ON_CHANNEL);
5582
5583 if (IS_ERR(hdr)) {
5584 err = PTR_ERR(hdr);
5585 goto free_msg;
5586 }
5587
5588 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5589 channel_type, duration, &cookie);
5590
5591 if (err)
5592 goto free_msg;
5593
9360ffd1
DM
5594 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
5595 goto nla_put_failure;
9588bbd5
JM
5596
5597 genlmsg_end(msg, hdr);
4c476991
JB
5598
5599 return genlmsg_reply(msg, info);
9588bbd5
JM
5600
5601 nla_put_failure:
5602 err = -ENOBUFS;
5603 free_msg:
5604 nlmsg_free(msg);
9588bbd5
JM
5605 return err;
5606}
5607
5608static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5609 struct genl_info *info)
5610{
4c476991
JB
5611 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5612 struct net_device *dev = info->user_ptr[1];
9588bbd5 5613 u64 cookie;
9588bbd5
JM
5614
5615 if (!info->attrs[NL80211_ATTR_COOKIE])
5616 return -EINVAL;
5617
4c476991
JB
5618 if (!rdev->ops->cancel_remain_on_channel)
5619 return -EOPNOTSUPP;
9588bbd5 5620
9588bbd5
JM
5621 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5622
4c476991 5623 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5624}
5625
13ae75b1
JM
5626static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5627 u8 *rates, u8 rates_len)
5628{
5629 u8 i;
5630 u32 mask = 0;
5631
5632 for (i = 0; i < rates_len; i++) {
5633 int rate = (rates[i] & 0x7f) * 5;
5634 int ridx;
5635 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5636 struct ieee80211_rate *srate =
5637 &sband->bitrates[ridx];
5638 if (rate == srate->bitrate) {
5639 mask |= 1 << ridx;
5640 break;
5641 }
5642 }
5643 if (ridx == sband->n_bitrates)
5644 return 0; /* rate not found */
5645 }
5646
5647 return mask;
5648}
5649
24db78c0
SW
5650static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
5651 u8 *rates, u8 rates_len,
5652 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
5653{
5654 u8 i;
5655
5656 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
5657
5658 for (i = 0; i < rates_len; i++) {
5659 int ridx, rbit;
5660
5661 ridx = rates[i] / 8;
5662 rbit = BIT(rates[i] % 8);
5663
5664 /* check validity */
910570b5 5665 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
5666 return false;
5667
5668 /* check availability */
5669 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5670 mcs[ridx] |= rbit;
5671 else
5672 return false;
5673 }
5674
5675 return true;
5676}
5677
b54452b0 5678static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5679 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5680 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
5681 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
5682 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
5683};
5684
5685static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5686 struct genl_info *info)
5687{
5688 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5689 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5690 struct cfg80211_bitrate_mask mask;
4c476991
JB
5691 int rem, i;
5692 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5693 struct nlattr *tx_rates;
5694 struct ieee80211_supported_band *sband;
5695
5696 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5697 return -EINVAL;
5698
4c476991
JB
5699 if (!rdev->ops->set_bitrate_mask)
5700 return -EOPNOTSUPP;
13ae75b1
JM
5701
5702 memset(&mask, 0, sizeof(mask));
5703 /* Default to all rates enabled */
5704 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5705 sband = rdev->wiphy.bands[i];
5706 mask.control[i].legacy =
5707 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
5708 if (sband)
5709 memcpy(mask.control[i].mcs,
5710 sband->ht_cap.mcs.rx_mask,
5711 sizeof(mask.control[i].mcs));
5712 else
5713 memset(mask.control[i].mcs, 0,
5714 sizeof(mask.control[i].mcs));
13ae75b1
JM
5715 }
5716
5717 /*
5718 * The nested attribute uses enum nl80211_band as the index. This maps
5719 * directly to the enum ieee80211_band values used in cfg80211.
5720 */
24db78c0 5721 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
5722 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5723 {
5724 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5725 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5726 return -EINVAL;
13ae75b1 5727 sband = rdev->wiphy.bands[band];
4c476991
JB
5728 if (sband == NULL)
5729 return -EINVAL;
13ae75b1
JM
5730 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5731 nla_len(tx_rates), nl80211_txattr_policy);
5732 if (tb[NL80211_TXRATE_LEGACY]) {
5733 mask.control[band].legacy = rateset_to_mask(
5734 sband,
5735 nla_data(tb[NL80211_TXRATE_LEGACY]),
5736 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
5737 if ((mask.control[band].legacy == 0) &&
5738 nla_len(tb[NL80211_TXRATE_LEGACY]))
5739 return -EINVAL;
24db78c0
SW
5740 }
5741 if (tb[NL80211_TXRATE_MCS]) {
5742 if (!ht_rateset_to_mask(
5743 sband,
5744 nla_data(tb[NL80211_TXRATE_MCS]),
5745 nla_len(tb[NL80211_TXRATE_MCS]),
5746 mask.control[band].mcs))
5747 return -EINVAL;
5748 }
5749
5750 if (mask.control[band].legacy == 0) {
5751 /* don't allow empty legacy rates if HT
5752 * is not even supported. */
5753 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
5754 return -EINVAL;
5755
5756 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5757 if (mask.control[band].mcs[i])
5758 break;
5759
5760 /* legacy and mcs rates may not be both empty */
5761 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 5762 return -EINVAL;
13ae75b1
JM
5763 }
5764 }
5765
4c476991 5766 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5767}
5768
2e161f78 5769static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5770{
4c476991
JB
5771 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5772 struct net_device *dev = info->user_ptr[1];
2e161f78 5773 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5774
5775 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5776 return -EINVAL;
5777
2e161f78
JB
5778 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5779 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5780
9d38d85d 5781 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5782 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5783 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5784 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5785 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5786 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5787 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5788 return -EOPNOTSUPP;
026331c4
JM
5789
5790 /* not much point in registering if we can't reply */
4c476991
JB
5791 if (!rdev->ops->mgmt_tx)
5792 return -EOPNOTSUPP;
026331c4 5793
4c476991 5794 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 5795 frame_type,
026331c4
JM
5796 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5797 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
5798}
5799
2e161f78 5800static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5801{
4c476991
JB
5802 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5803 struct net_device *dev = info->user_ptr[1];
026331c4
JM
5804 struct ieee80211_channel *chan;
5805 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 5806 bool channel_type_valid = false;
026331c4
JM
5807 u32 freq;
5808 int err;
d64d373f 5809 void *hdr = NULL;
026331c4 5810 u64 cookie;
e247bd90 5811 struct sk_buff *msg = NULL;
f7ca38df 5812 unsigned int wait = 0;
e247bd90
JB
5813 bool offchan, no_cck, dont_wait_for_ack;
5814
5815 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4
JM
5816
5817 if (!info->attrs[NL80211_ATTR_FRAME] ||
5818 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5819 return -EINVAL;
5820
4c476991
JB
5821 if (!rdev->ops->mgmt_tx)
5822 return -EOPNOTSUPP;
026331c4 5823
9d38d85d 5824 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5825 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5826 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5827 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5828 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5829 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5830 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5831 return -EOPNOTSUPP;
026331c4 5832
f7ca38df 5833 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 5834 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
5835 return -EINVAL;
5836 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
5837
5838 /*
5839 * We should wait on the channel for at least a minimum amount
5840 * of time (10ms) but no longer than the driver supports.
5841 */
5842 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
5843 wait > rdev->wiphy.max_remain_on_channel_duration)
5844 return -EINVAL;
5845
f7ca38df
JB
5846 }
5847
026331c4 5848 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
cd6c6598 5849 if (!nl80211_valid_channel_type(info, &channel_type))
4c476991 5850 return -EINVAL;
252aa631 5851 channel_type_valid = true;
026331c4
JM
5852 }
5853
f7ca38df
JB
5854 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5855
7c4ef712
JB
5856 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
5857 return -EINVAL;
5858
e9f935e3
RM
5859 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5860
026331c4
JM
5861 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5862 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5863 if (chan == NULL)
5864 return -EINVAL;
026331c4 5865
e247bd90
JB
5866 if (!dont_wait_for_ack) {
5867 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5868 if (!msg)
5869 return -ENOMEM;
026331c4 5870
e247bd90
JB
5871 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5872 NL80211_CMD_FRAME);
026331c4 5873
e247bd90
JB
5874 if (IS_ERR(hdr)) {
5875 err = PTR_ERR(hdr);
5876 goto free_msg;
5877 }
026331c4 5878 }
e247bd90 5879
f7ca38df
JB
5880 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5881 channel_type_valid, wait,
2e161f78
JB
5882 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5883 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 5884 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
5885 if (err)
5886 goto free_msg;
5887
e247bd90 5888 if (msg) {
9360ffd1
DM
5889 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
5890 goto nla_put_failure;
026331c4 5891
e247bd90
JB
5892 genlmsg_end(msg, hdr);
5893 return genlmsg_reply(msg, info);
5894 }
5895
5896 return 0;
026331c4
JM
5897
5898 nla_put_failure:
5899 err = -ENOBUFS;
5900 free_msg:
5901 nlmsg_free(msg);
026331c4
JM
5902 return err;
5903}
5904
f7ca38df
JB
5905static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5906{
5907 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5908 struct net_device *dev = info->user_ptr[1];
5909 u64 cookie;
5910
5911 if (!info->attrs[NL80211_ATTR_COOKIE])
5912 return -EINVAL;
5913
5914 if (!rdev->ops->mgmt_tx_cancel_wait)
5915 return -EOPNOTSUPP;
5916
5917 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5918 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5919 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5920 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5921 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5922 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5923 return -EOPNOTSUPP;
5924
5925 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5926
5927 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5928}
5929
ffb9eb3d
KV
5930static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5931{
4c476991 5932 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 5933 struct wireless_dev *wdev;
4c476991 5934 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5935 u8 ps_state;
5936 bool state;
5937 int err;
5938
4c476991
JB
5939 if (!info->attrs[NL80211_ATTR_PS_STATE])
5940 return -EINVAL;
ffb9eb3d
KV
5941
5942 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5943
4c476991
JB
5944 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5945 return -EINVAL;
ffb9eb3d
KV
5946
5947 wdev = dev->ieee80211_ptr;
5948
4c476991
JB
5949 if (!rdev->ops->set_power_mgmt)
5950 return -EOPNOTSUPP;
ffb9eb3d
KV
5951
5952 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5953
5954 if (state == wdev->ps)
4c476991 5955 return 0;
ffb9eb3d 5956
4c476991
JB
5957 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5958 wdev->ps_timeout);
5959 if (!err)
5960 wdev->ps = state;
ffb9eb3d
KV
5961 return err;
5962}
5963
5964static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5965{
4c476991 5966 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
5967 enum nl80211_ps_state ps_state;
5968 struct wireless_dev *wdev;
4c476991 5969 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5970 struct sk_buff *msg;
5971 void *hdr;
5972 int err;
5973
ffb9eb3d
KV
5974 wdev = dev->ieee80211_ptr;
5975
4c476991
JB
5976 if (!rdev->ops->set_power_mgmt)
5977 return -EOPNOTSUPP;
ffb9eb3d
KV
5978
5979 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5980 if (!msg)
5981 return -ENOMEM;
ffb9eb3d
KV
5982
5983 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5984 NL80211_CMD_GET_POWER_SAVE);
5985 if (!hdr) {
4c476991 5986 err = -ENOBUFS;
ffb9eb3d
KV
5987 goto free_msg;
5988 }
5989
5990 if (wdev->ps)
5991 ps_state = NL80211_PS_ENABLED;
5992 else
5993 ps_state = NL80211_PS_DISABLED;
5994
9360ffd1
DM
5995 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
5996 goto nla_put_failure;
ffb9eb3d
KV
5997
5998 genlmsg_end(msg, hdr);
4c476991 5999 return genlmsg_reply(msg, info);
ffb9eb3d 6000
4c476991 6001 nla_put_failure:
ffb9eb3d 6002 err = -ENOBUFS;
4c476991 6003 free_msg:
ffb9eb3d 6004 nlmsg_free(msg);
ffb9eb3d
KV
6005 return err;
6006}
6007
d6dc1a38
JO
6008static struct nla_policy
6009nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6010 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6011 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6012 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
6013};
6014
6015static int nl80211_set_cqm_rssi(struct genl_info *info,
6016 s32 threshold, u32 hysteresis)
6017{
4c476991 6018 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6019 struct wireless_dev *wdev;
4c476991 6020 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6021
6022 if (threshold > 0)
6023 return -EINVAL;
6024
d6dc1a38
JO
6025 wdev = dev->ieee80211_ptr;
6026
4c476991
JB
6027 if (!rdev->ops->set_cqm_rssi_config)
6028 return -EOPNOTSUPP;
d6dc1a38 6029
074ac8df 6030 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6031 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6032 return -EOPNOTSUPP;
d6dc1a38 6033
4c476991
JB
6034 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
6035 threshold, hysteresis);
d6dc1a38
JO
6036}
6037
6038static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6039{
6040 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6041 struct nlattr *cqm;
6042 int err;
6043
6044 cqm = info->attrs[NL80211_ATTR_CQM];
6045 if (!cqm) {
6046 err = -EINVAL;
6047 goto out;
6048 }
6049
6050 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6051 nl80211_attr_cqm_policy);
6052 if (err)
6053 goto out;
6054
6055 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6056 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6057 s32 threshold;
6058 u32 hysteresis;
6059 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6060 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6061 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
6062 } else
6063 err = -EINVAL;
6064
6065out:
6066 return err;
6067}
6068
29cbe68c
JB
6069static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6070{
6071 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6072 struct net_device *dev = info->user_ptr[1];
6073 struct mesh_config cfg;
c80d545d 6074 struct mesh_setup setup;
29cbe68c
JB
6075 int err;
6076
6077 /* start with default */
6078 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6079 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6080
24bdd9f4 6081 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6082 /* and parse parameters if given */
24bdd9f4 6083 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6084 if (err)
6085 return err;
6086 }
6087
6088 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6089 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6090 return -EINVAL;
6091
c80d545d
JC
6092 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6093 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6094
4bb62344
CYY
6095 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6096 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6097 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6098 return -EINVAL;
6099
c80d545d
JC
6100 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6101 /* parse additional setup parameters if given */
6102 err = nl80211_parse_mesh_setup(info, &setup);
6103 if (err)
6104 return err;
6105 }
6106
cc1d2806
JB
6107 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6108 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
6109
6110 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
6111 !nl80211_valid_channel_type(info, &channel_type))
6112 return -EINVAL;
6113
6114 setup.channel = rdev_freq_to_chan(rdev,
6115 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
6116 channel_type);
6117 if (!setup.channel)
6118 return -EINVAL;
6119 setup.channel_type = channel_type;
6120 } else {
6121 /* cfg80211_join_mesh() will sort it out */
6122 setup.channel = NULL;
6123 }
6124
c80d545d 6125 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6126}
6127
6128static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6129{
6130 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6131 struct net_device *dev = info->user_ptr[1];
6132
6133 return cfg80211_leave_mesh(rdev, dev);
6134}
6135
ff1b6e69
JB
6136static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6137{
6138 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6139 struct sk_buff *msg;
6140 void *hdr;
6141
6142 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6143 return -EOPNOTSUPP;
6144
6145 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6146 if (!msg)
6147 return -ENOMEM;
6148
6149 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6150 NL80211_CMD_GET_WOWLAN);
6151 if (!hdr)
6152 goto nla_put_failure;
6153
6154 if (rdev->wowlan) {
6155 struct nlattr *nl_wowlan;
6156
6157 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6158 if (!nl_wowlan)
6159 goto nla_put_failure;
6160
9360ffd1
DM
6161 if ((rdev->wowlan->any &&
6162 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6163 (rdev->wowlan->disconnect &&
6164 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6165 (rdev->wowlan->magic_pkt &&
6166 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6167 (rdev->wowlan->gtk_rekey_failure &&
6168 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6169 (rdev->wowlan->eap_identity_req &&
6170 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6171 (rdev->wowlan->four_way_handshake &&
6172 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6173 (rdev->wowlan->rfkill_release &&
6174 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6175 goto nla_put_failure;
ff1b6e69
JB
6176 if (rdev->wowlan->n_patterns) {
6177 struct nlattr *nl_pats, *nl_pat;
6178 int i, pat_len;
6179
6180 nl_pats = nla_nest_start(msg,
6181 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6182 if (!nl_pats)
6183 goto nla_put_failure;
6184
6185 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6186 nl_pat = nla_nest_start(msg, i + 1);
6187 if (!nl_pat)
6188 goto nla_put_failure;
6189 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6190 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6191 DIV_ROUND_UP(pat_len, 8),
6192 rdev->wowlan->patterns[i].mask) ||
6193 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6194 pat_len,
6195 rdev->wowlan->patterns[i].pattern))
6196 goto nla_put_failure;
ff1b6e69
JB
6197 nla_nest_end(msg, nl_pat);
6198 }
6199 nla_nest_end(msg, nl_pats);
6200 }
6201
6202 nla_nest_end(msg, nl_wowlan);
6203 }
6204
6205 genlmsg_end(msg, hdr);
6206 return genlmsg_reply(msg, info);
6207
6208nla_put_failure:
6209 nlmsg_free(msg);
6210 return -ENOBUFS;
6211}
6212
6213static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6214{
6215 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6216 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
6217 struct cfg80211_wowlan no_triggers = {};
6218 struct cfg80211_wowlan new_triggers = {};
6219 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6220 int err, i;
6d52563f 6221 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6222
6223 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6224 return -EOPNOTSUPP;
6225
6226 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
6227 goto no_triggers;
6228
6229 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6230 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6231 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6232 nl80211_wowlan_policy);
6233 if (err)
6234 return err;
6235
6236 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6237 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6238 return -EINVAL;
6239 new_triggers.any = true;
6240 }
6241
6242 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6243 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6244 return -EINVAL;
6245 new_triggers.disconnect = true;
6246 }
6247
6248 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6249 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6250 return -EINVAL;
6251 new_triggers.magic_pkt = true;
6252 }
6253
77dbbb13
JB
6254 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6255 return -EINVAL;
6256
6257 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6258 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6259 return -EINVAL;
6260 new_triggers.gtk_rekey_failure = true;
6261 }
6262
6263 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6264 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6265 return -EINVAL;
6266 new_triggers.eap_identity_req = true;
6267 }
6268
6269 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6270 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6271 return -EINVAL;
6272 new_triggers.four_way_handshake = true;
6273 }
6274
6275 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6276 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6277 return -EINVAL;
6278 new_triggers.rfkill_release = true;
6279 }
6280
ff1b6e69
JB
6281 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6282 struct nlattr *pat;
6283 int n_patterns = 0;
6284 int rem, pat_len, mask_len;
6285 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6286
6287 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6288 rem)
6289 n_patterns++;
6290 if (n_patterns > wowlan->n_patterns)
6291 return -EINVAL;
6292
6293 new_triggers.patterns = kcalloc(n_patterns,
6294 sizeof(new_triggers.patterns[0]),
6295 GFP_KERNEL);
6296 if (!new_triggers.patterns)
6297 return -ENOMEM;
6298
6299 new_triggers.n_patterns = n_patterns;
6300 i = 0;
6301
6302 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6303 rem) {
6304 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6305 nla_data(pat), nla_len(pat), NULL);
6306 err = -EINVAL;
6307 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6308 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6309 goto error;
6310 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6311 mask_len = DIV_ROUND_UP(pat_len, 8);
6312 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6313 mask_len)
6314 goto error;
6315 if (pat_len > wowlan->pattern_max_len ||
6316 pat_len < wowlan->pattern_min_len)
6317 goto error;
6318
6319 new_triggers.patterns[i].mask =
6320 kmalloc(mask_len + pat_len, GFP_KERNEL);
6321 if (!new_triggers.patterns[i].mask) {
6322 err = -ENOMEM;
6323 goto error;
6324 }
6325 new_triggers.patterns[i].pattern =
6326 new_triggers.patterns[i].mask + mask_len;
6327 memcpy(new_triggers.patterns[i].mask,
6328 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6329 mask_len);
6330 new_triggers.patterns[i].pattern_len = pat_len;
6331 memcpy(new_triggers.patterns[i].pattern,
6332 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6333 pat_len);
6334 i++;
6335 }
6336 }
6337
6338 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
6339 struct cfg80211_wowlan *ntrig;
6340 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
6341 GFP_KERNEL);
6342 if (!ntrig) {
6343 err = -ENOMEM;
6344 goto error;
6345 }
6346 cfg80211_rdev_free_wowlan(rdev);
6347 rdev->wowlan = ntrig;
6348 } else {
6349 no_triggers:
6350 cfg80211_rdev_free_wowlan(rdev);
6351 rdev->wowlan = NULL;
6352 }
6353
6d52563f
JB
6354 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
6355 rdev->ops->set_wakeup(&rdev->wiphy, rdev->wowlan);
6356
ff1b6e69
JB
6357 return 0;
6358 error:
6359 for (i = 0; i < new_triggers.n_patterns; i++)
6360 kfree(new_triggers.patterns[i].mask);
6361 kfree(new_triggers.patterns);
6362 return err;
6363}
6364
e5497d76
JB
6365static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6366{
6367 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6368 struct net_device *dev = info->user_ptr[1];
6369 struct wireless_dev *wdev = dev->ieee80211_ptr;
6370 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6371 struct cfg80211_gtk_rekey_data rekey_data;
6372 int err;
6373
6374 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6375 return -EINVAL;
6376
6377 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6378 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6379 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6380 nl80211_rekey_policy);
6381 if (err)
6382 return err;
6383
6384 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6385 return -ERANGE;
6386 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6387 return -ERANGE;
6388 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6389 return -ERANGE;
6390
6391 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6392 NL80211_KEK_LEN);
6393 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6394 NL80211_KCK_LEN);
6395 memcpy(rekey_data.replay_ctr,
6396 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6397 NL80211_REPLAY_CTR_LEN);
6398
6399 wdev_lock(wdev);
6400 if (!wdev->current_bss) {
6401 err = -ENOTCONN;
6402 goto out;
6403 }
6404
6405 if (!rdev->ops->set_rekey_data) {
6406 err = -EOPNOTSUPP;
6407 goto out;
6408 }
6409
6410 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
6411 out:
6412 wdev_unlock(wdev);
6413 return err;
6414}
6415
28946da7
JB
6416static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6417 struct genl_info *info)
6418{
6419 struct net_device *dev = info->user_ptr[1];
6420 struct wireless_dev *wdev = dev->ieee80211_ptr;
6421
6422 if (wdev->iftype != NL80211_IFTYPE_AP &&
6423 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6424 return -EINVAL;
6425
6426 if (wdev->ap_unexpected_nlpid)
6427 return -EBUSY;
6428
6429 wdev->ap_unexpected_nlpid = info->snd_pid;
6430 return 0;
6431}
6432
7f6cf311
JB
6433static int nl80211_probe_client(struct sk_buff *skb,
6434 struct genl_info *info)
6435{
6436 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6437 struct net_device *dev = info->user_ptr[1];
6438 struct wireless_dev *wdev = dev->ieee80211_ptr;
6439 struct sk_buff *msg;
6440 void *hdr;
6441 const u8 *addr;
6442 u64 cookie;
6443 int err;
6444
6445 if (wdev->iftype != NL80211_IFTYPE_AP &&
6446 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6447 return -EOPNOTSUPP;
6448
6449 if (!info->attrs[NL80211_ATTR_MAC])
6450 return -EINVAL;
6451
6452 if (!rdev->ops->probe_client)
6453 return -EOPNOTSUPP;
6454
6455 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6456 if (!msg)
6457 return -ENOMEM;
6458
6459 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6460 NL80211_CMD_PROBE_CLIENT);
6461
6462 if (IS_ERR(hdr)) {
6463 err = PTR_ERR(hdr);
6464 goto free_msg;
6465 }
6466
6467 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6468
6469 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
6470 if (err)
6471 goto free_msg;
6472
9360ffd1
DM
6473 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6474 goto nla_put_failure;
7f6cf311
JB
6475
6476 genlmsg_end(msg, hdr);
6477
6478 return genlmsg_reply(msg, info);
6479
6480 nla_put_failure:
6481 err = -ENOBUFS;
6482 free_msg:
6483 nlmsg_free(msg);
6484 return err;
6485}
6486
5e760230
JB
6487static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
6488{
6489 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6490
6491 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
6492 return -EOPNOTSUPP;
6493
6494 if (rdev->ap_beacons_nlpid)
6495 return -EBUSY;
6496
6497 rdev->ap_beacons_nlpid = info->snd_pid;
6498
6499 return 0;
6500}
6501
4c476991
JB
6502#define NL80211_FLAG_NEED_WIPHY 0x01
6503#define NL80211_FLAG_NEED_NETDEV 0x02
6504#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
6505#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
6506#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
6507 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
6508
6509static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
6510 struct genl_info *info)
6511{
6512 struct cfg80211_registered_device *rdev;
6513 struct net_device *dev;
6514 int err;
6515 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
6516
6517 if (rtnl)
6518 rtnl_lock();
6519
6520 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
6521 rdev = cfg80211_get_dev_from_info(info);
6522 if (IS_ERR(rdev)) {
6523 if (rtnl)
6524 rtnl_unlock();
6525 return PTR_ERR(rdev);
6526 }
6527 info->user_ptr[0] = rdev;
6528 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
00918d33
JB
6529 err = get_rdev_dev_by_ifindex(genl_info_net(info), info->attrs,
6530 &rdev, &dev);
4c476991
JB
6531 if (err) {
6532 if (rtnl)
6533 rtnl_unlock();
6534 return err;
6535 }
41265714
JB
6536 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
6537 !netif_running(dev)) {
d537f5fd
JB
6538 cfg80211_unlock_rdev(rdev);
6539 dev_put(dev);
41265714
JB
6540 if (rtnl)
6541 rtnl_unlock();
6542 return -ENETDOWN;
6543 }
4c476991
JB
6544 info->user_ptr[0] = rdev;
6545 info->user_ptr[1] = dev;
6546 }
6547
6548 return 0;
6549}
6550
6551static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
6552 struct genl_info *info)
6553{
6554 if (info->user_ptr[0])
6555 cfg80211_unlock_rdev(info->user_ptr[0]);
6556 if (info->user_ptr[1])
6557 dev_put(info->user_ptr[1]);
6558 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
6559 rtnl_unlock();
6560}
6561
55682965
JB
6562static struct genl_ops nl80211_ops[] = {
6563 {
6564 .cmd = NL80211_CMD_GET_WIPHY,
6565 .doit = nl80211_get_wiphy,
6566 .dumpit = nl80211_dump_wiphy,
6567 .policy = nl80211_policy,
6568 /* can be retrieved by unprivileged users */
4c476991 6569 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
6570 },
6571 {
6572 .cmd = NL80211_CMD_SET_WIPHY,
6573 .doit = nl80211_set_wiphy,
6574 .policy = nl80211_policy,
6575 .flags = GENL_ADMIN_PERM,
4c476991 6576 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
6577 },
6578 {
6579 .cmd = NL80211_CMD_GET_INTERFACE,
6580 .doit = nl80211_get_interface,
6581 .dumpit = nl80211_dump_interface,
6582 .policy = nl80211_policy,
6583 /* can be retrieved by unprivileged users */
4c476991 6584 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
6585 },
6586 {
6587 .cmd = NL80211_CMD_SET_INTERFACE,
6588 .doit = nl80211_set_interface,
6589 .policy = nl80211_policy,
6590 .flags = GENL_ADMIN_PERM,
4c476991
JB
6591 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6592 NL80211_FLAG_NEED_RTNL,
55682965
JB
6593 },
6594 {
6595 .cmd = NL80211_CMD_NEW_INTERFACE,
6596 .doit = nl80211_new_interface,
6597 .policy = nl80211_policy,
6598 .flags = GENL_ADMIN_PERM,
4c476991
JB
6599 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6600 NL80211_FLAG_NEED_RTNL,
55682965
JB
6601 },
6602 {
6603 .cmd = NL80211_CMD_DEL_INTERFACE,
6604 .doit = nl80211_del_interface,
6605 .policy = nl80211_policy,
41ade00f 6606 .flags = GENL_ADMIN_PERM,
4c476991
JB
6607 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6608 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6609 },
6610 {
6611 .cmd = NL80211_CMD_GET_KEY,
6612 .doit = nl80211_get_key,
6613 .policy = nl80211_policy,
6614 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6615 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6616 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6617 },
6618 {
6619 .cmd = NL80211_CMD_SET_KEY,
6620 .doit = nl80211_set_key,
6621 .policy = nl80211_policy,
6622 .flags = GENL_ADMIN_PERM,
41265714 6623 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6624 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6625 },
6626 {
6627 .cmd = NL80211_CMD_NEW_KEY,
6628 .doit = nl80211_new_key,
6629 .policy = nl80211_policy,
6630 .flags = GENL_ADMIN_PERM,
41265714 6631 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6632 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6633 },
6634 {
6635 .cmd = NL80211_CMD_DEL_KEY,
6636 .doit = nl80211_del_key,
6637 .policy = nl80211_policy,
55682965 6638 .flags = GENL_ADMIN_PERM,
41265714 6639 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6640 NL80211_FLAG_NEED_RTNL,
55682965 6641 },
ed1b6cc7
JB
6642 {
6643 .cmd = NL80211_CMD_SET_BEACON,
6644 .policy = nl80211_policy,
6645 .flags = GENL_ADMIN_PERM,
8860020e 6646 .doit = nl80211_set_beacon,
2b5f8b0b 6647 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6648 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6649 },
6650 {
8860020e 6651 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
6652 .policy = nl80211_policy,
6653 .flags = GENL_ADMIN_PERM,
8860020e 6654 .doit = nl80211_start_ap,
2b5f8b0b 6655 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6656 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6657 },
6658 {
8860020e 6659 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
6660 .policy = nl80211_policy,
6661 .flags = GENL_ADMIN_PERM,
8860020e 6662 .doit = nl80211_stop_ap,
2b5f8b0b 6663 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6664 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6665 },
5727ef1b
JB
6666 {
6667 .cmd = NL80211_CMD_GET_STATION,
6668 .doit = nl80211_get_station,
2ec600d6 6669 .dumpit = nl80211_dump_station,
5727ef1b 6670 .policy = nl80211_policy,
4c476991
JB
6671 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6672 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6673 },
6674 {
6675 .cmd = NL80211_CMD_SET_STATION,
6676 .doit = nl80211_set_station,
6677 .policy = nl80211_policy,
6678 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6679 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6680 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6681 },
6682 {
6683 .cmd = NL80211_CMD_NEW_STATION,
6684 .doit = nl80211_new_station,
6685 .policy = nl80211_policy,
6686 .flags = GENL_ADMIN_PERM,
41265714 6687 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6688 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6689 },
6690 {
6691 .cmd = NL80211_CMD_DEL_STATION,
6692 .doit = nl80211_del_station,
6693 .policy = nl80211_policy,
2ec600d6 6694 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6695 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6696 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6697 },
6698 {
6699 .cmd = NL80211_CMD_GET_MPATH,
6700 .doit = nl80211_get_mpath,
6701 .dumpit = nl80211_dump_mpath,
6702 .policy = nl80211_policy,
6703 .flags = GENL_ADMIN_PERM,
41265714 6704 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6705 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6706 },
6707 {
6708 .cmd = NL80211_CMD_SET_MPATH,
6709 .doit = nl80211_set_mpath,
6710 .policy = nl80211_policy,
6711 .flags = GENL_ADMIN_PERM,
41265714 6712 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6713 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6714 },
6715 {
6716 .cmd = NL80211_CMD_NEW_MPATH,
6717 .doit = nl80211_new_mpath,
6718 .policy = nl80211_policy,
6719 .flags = GENL_ADMIN_PERM,
41265714 6720 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6721 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6722 },
6723 {
6724 .cmd = NL80211_CMD_DEL_MPATH,
6725 .doit = nl80211_del_mpath,
6726 .policy = nl80211_policy,
9f1ba906 6727 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6728 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6729 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6730 },
6731 {
6732 .cmd = NL80211_CMD_SET_BSS,
6733 .doit = nl80211_set_bss,
6734 .policy = nl80211_policy,
b2e1b302 6735 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6736 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6737 NL80211_FLAG_NEED_RTNL,
b2e1b302 6738 },
f130347c
LR
6739 {
6740 .cmd = NL80211_CMD_GET_REG,
6741 .doit = nl80211_get_reg,
6742 .policy = nl80211_policy,
6743 /* can be retrieved by unprivileged users */
6744 },
b2e1b302
LR
6745 {
6746 .cmd = NL80211_CMD_SET_REG,
6747 .doit = nl80211_set_reg,
6748 .policy = nl80211_policy,
6749 .flags = GENL_ADMIN_PERM,
6750 },
6751 {
6752 .cmd = NL80211_CMD_REQ_SET_REG,
6753 .doit = nl80211_req_set_reg,
6754 .policy = nl80211_policy,
93da9cc1 6755 .flags = GENL_ADMIN_PERM,
6756 },
6757 {
24bdd9f4
JC
6758 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6759 .doit = nl80211_get_mesh_config,
93da9cc1 6760 .policy = nl80211_policy,
6761 /* can be retrieved by unprivileged users */
2b5f8b0b 6762 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6763 NL80211_FLAG_NEED_RTNL,
93da9cc1 6764 },
6765 {
24bdd9f4
JC
6766 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6767 .doit = nl80211_update_mesh_config,
93da9cc1 6768 .policy = nl80211_policy,
9aed3cc1 6769 .flags = GENL_ADMIN_PERM,
29cbe68c 6770 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6771 NL80211_FLAG_NEED_RTNL,
9aed3cc1 6772 },
2a519311
JB
6773 {
6774 .cmd = NL80211_CMD_TRIGGER_SCAN,
6775 .doit = nl80211_trigger_scan,
6776 .policy = nl80211_policy,
6777 .flags = GENL_ADMIN_PERM,
41265714 6778 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6779 NL80211_FLAG_NEED_RTNL,
2a519311
JB
6780 },
6781 {
6782 .cmd = NL80211_CMD_GET_SCAN,
6783 .policy = nl80211_policy,
6784 .dumpit = nl80211_dump_scan,
6785 },
807f8a8c
LC
6786 {
6787 .cmd = NL80211_CMD_START_SCHED_SCAN,
6788 .doit = nl80211_start_sched_scan,
6789 .policy = nl80211_policy,
6790 .flags = GENL_ADMIN_PERM,
6791 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6792 NL80211_FLAG_NEED_RTNL,
6793 },
6794 {
6795 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6796 .doit = nl80211_stop_sched_scan,
6797 .policy = nl80211_policy,
6798 .flags = GENL_ADMIN_PERM,
6799 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6800 NL80211_FLAG_NEED_RTNL,
6801 },
636a5d36
JM
6802 {
6803 .cmd = NL80211_CMD_AUTHENTICATE,
6804 .doit = nl80211_authenticate,
6805 .policy = nl80211_policy,
6806 .flags = GENL_ADMIN_PERM,
41265714 6807 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6808 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6809 },
6810 {
6811 .cmd = NL80211_CMD_ASSOCIATE,
6812 .doit = nl80211_associate,
6813 .policy = nl80211_policy,
6814 .flags = GENL_ADMIN_PERM,
41265714 6815 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6816 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6817 },
6818 {
6819 .cmd = NL80211_CMD_DEAUTHENTICATE,
6820 .doit = nl80211_deauthenticate,
6821 .policy = nl80211_policy,
6822 .flags = GENL_ADMIN_PERM,
41265714 6823 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6824 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6825 },
6826 {
6827 .cmd = NL80211_CMD_DISASSOCIATE,
6828 .doit = nl80211_disassociate,
6829 .policy = nl80211_policy,
6830 .flags = GENL_ADMIN_PERM,
41265714 6831 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6832 NL80211_FLAG_NEED_RTNL,
636a5d36 6833 },
04a773ad
JB
6834 {
6835 .cmd = NL80211_CMD_JOIN_IBSS,
6836 .doit = nl80211_join_ibss,
6837 .policy = nl80211_policy,
6838 .flags = GENL_ADMIN_PERM,
41265714 6839 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6840 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
6841 },
6842 {
6843 .cmd = NL80211_CMD_LEAVE_IBSS,
6844 .doit = nl80211_leave_ibss,
6845 .policy = nl80211_policy,
6846 .flags = GENL_ADMIN_PERM,
41265714 6847 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6848 NL80211_FLAG_NEED_RTNL,
04a773ad 6849 },
aff89a9b
JB
6850#ifdef CONFIG_NL80211_TESTMODE
6851 {
6852 .cmd = NL80211_CMD_TESTMODE,
6853 .doit = nl80211_testmode_do,
71063f0e 6854 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
6855 .policy = nl80211_policy,
6856 .flags = GENL_ADMIN_PERM,
4c476991
JB
6857 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6858 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
6859 },
6860#endif
b23aa676
SO
6861 {
6862 .cmd = NL80211_CMD_CONNECT,
6863 .doit = nl80211_connect,
6864 .policy = nl80211_policy,
6865 .flags = GENL_ADMIN_PERM,
41265714 6866 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6867 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
6868 },
6869 {
6870 .cmd = NL80211_CMD_DISCONNECT,
6871 .doit = nl80211_disconnect,
6872 .policy = nl80211_policy,
6873 .flags = GENL_ADMIN_PERM,
41265714 6874 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6875 NL80211_FLAG_NEED_RTNL,
b23aa676 6876 },
463d0183
JB
6877 {
6878 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6879 .doit = nl80211_wiphy_netns,
6880 .policy = nl80211_policy,
6881 .flags = GENL_ADMIN_PERM,
4c476991
JB
6882 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6883 NL80211_FLAG_NEED_RTNL,
463d0183 6884 },
61fa713c
HS
6885 {
6886 .cmd = NL80211_CMD_GET_SURVEY,
6887 .policy = nl80211_policy,
6888 .dumpit = nl80211_dump_survey,
6889 },
67fbb16b
SO
6890 {
6891 .cmd = NL80211_CMD_SET_PMKSA,
6892 .doit = nl80211_setdel_pmksa,
6893 .policy = nl80211_policy,
6894 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6895 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6896 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6897 },
6898 {
6899 .cmd = NL80211_CMD_DEL_PMKSA,
6900 .doit = nl80211_setdel_pmksa,
6901 .policy = nl80211_policy,
6902 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6903 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6904 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6905 },
6906 {
6907 .cmd = NL80211_CMD_FLUSH_PMKSA,
6908 .doit = nl80211_flush_pmksa,
6909 .policy = nl80211_policy,
6910 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6911 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6912 NL80211_FLAG_NEED_RTNL,
67fbb16b 6913 },
9588bbd5
JM
6914 {
6915 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6916 .doit = nl80211_remain_on_channel,
6917 .policy = nl80211_policy,
6918 .flags = GENL_ADMIN_PERM,
41265714 6919 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6920 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
6921 },
6922 {
6923 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6924 .doit = nl80211_cancel_remain_on_channel,
6925 .policy = nl80211_policy,
6926 .flags = GENL_ADMIN_PERM,
41265714 6927 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6928 NL80211_FLAG_NEED_RTNL,
9588bbd5 6929 },
13ae75b1
JM
6930 {
6931 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6932 .doit = nl80211_set_tx_bitrate_mask,
6933 .policy = nl80211_policy,
6934 .flags = GENL_ADMIN_PERM,
4c476991
JB
6935 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6936 NL80211_FLAG_NEED_RTNL,
13ae75b1 6937 },
026331c4 6938 {
2e161f78
JB
6939 .cmd = NL80211_CMD_REGISTER_FRAME,
6940 .doit = nl80211_register_mgmt,
026331c4
JM
6941 .policy = nl80211_policy,
6942 .flags = GENL_ADMIN_PERM,
4c476991
JB
6943 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6944 NL80211_FLAG_NEED_RTNL,
026331c4
JM
6945 },
6946 {
2e161f78
JB
6947 .cmd = NL80211_CMD_FRAME,
6948 .doit = nl80211_tx_mgmt,
026331c4 6949 .policy = nl80211_policy,
f7ca38df
JB
6950 .flags = GENL_ADMIN_PERM,
6951 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6952 NL80211_FLAG_NEED_RTNL,
6953 },
6954 {
6955 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6956 .doit = nl80211_tx_mgmt_cancel_wait,
6957 .policy = nl80211_policy,
026331c4 6958 .flags = GENL_ADMIN_PERM,
41265714 6959 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6960 NL80211_FLAG_NEED_RTNL,
026331c4 6961 },
ffb9eb3d
KV
6962 {
6963 .cmd = NL80211_CMD_SET_POWER_SAVE,
6964 .doit = nl80211_set_power_save,
6965 .policy = nl80211_policy,
6966 .flags = GENL_ADMIN_PERM,
4c476991
JB
6967 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6968 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
6969 },
6970 {
6971 .cmd = NL80211_CMD_GET_POWER_SAVE,
6972 .doit = nl80211_get_power_save,
6973 .policy = nl80211_policy,
6974 /* can be retrieved by unprivileged users */
4c476991
JB
6975 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6976 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 6977 },
d6dc1a38
JO
6978 {
6979 .cmd = NL80211_CMD_SET_CQM,
6980 .doit = nl80211_set_cqm,
6981 .policy = nl80211_policy,
6982 .flags = GENL_ADMIN_PERM,
4c476991
JB
6983 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6984 NL80211_FLAG_NEED_RTNL,
d6dc1a38 6985 },
f444de05
JB
6986 {
6987 .cmd = NL80211_CMD_SET_CHANNEL,
6988 .doit = nl80211_set_channel,
6989 .policy = nl80211_policy,
6990 .flags = GENL_ADMIN_PERM,
4c476991
JB
6991 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6992 NL80211_FLAG_NEED_RTNL,
f444de05 6993 },
e8347eba
BJ
6994 {
6995 .cmd = NL80211_CMD_SET_WDS_PEER,
6996 .doit = nl80211_set_wds_peer,
6997 .policy = nl80211_policy,
6998 .flags = GENL_ADMIN_PERM,
43b19952
JB
6999 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7000 NL80211_FLAG_NEED_RTNL,
e8347eba 7001 },
29cbe68c
JB
7002 {
7003 .cmd = NL80211_CMD_JOIN_MESH,
7004 .doit = nl80211_join_mesh,
7005 .policy = nl80211_policy,
7006 .flags = GENL_ADMIN_PERM,
7007 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7008 NL80211_FLAG_NEED_RTNL,
7009 },
7010 {
7011 .cmd = NL80211_CMD_LEAVE_MESH,
7012 .doit = nl80211_leave_mesh,
7013 .policy = nl80211_policy,
7014 .flags = GENL_ADMIN_PERM,
7015 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7016 NL80211_FLAG_NEED_RTNL,
7017 },
ff1b6e69
JB
7018 {
7019 .cmd = NL80211_CMD_GET_WOWLAN,
7020 .doit = nl80211_get_wowlan,
7021 .policy = nl80211_policy,
7022 /* can be retrieved by unprivileged users */
7023 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7024 NL80211_FLAG_NEED_RTNL,
7025 },
7026 {
7027 .cmd = NL80211_CMD_SET_WOWLAN,
7028 .doit = nl80211_set_wowlan,
7029 .policy = nl80211_policy,
7030 .flags = GENL_ADMIN_PERM,
7031 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7032 NL80211_FLAG_NEED_RTNL,
7033 },
e5497d76
JB
7034 {
7035 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7036 .doit = nl80211_set_rekey_data,
7037 .policy = nl80211_policy,
7038 .flags = GENL_ADMIN_PERM,
7039 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7040 NL80211_FLAG_NEED_RTNL,
7041 },
109086ce
AN
7042 {
7043 .cmd = NL80211_CMD_TDLS_MGMT,
7044 .doit = nl80211_tdls_mgmt,
7045 .policy = nl80211_policy,
7046 .flags = GENL_ADMIN_PERM,
7047 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7048 NL80211_FLAG_NEED_RTNL,
7049 },
7050 {
7051 .cmd = NL80211_CMD_TDLS_OPER,
7052 .doit = nl80211_tdls_oper,
7053 .policy = nl80211_policy,
7054 .flags = GENL_ADMIN_PERM,
7055 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7056 NL80211_FLAG_NEED_RTNL,
7057 },
28946da7
JB
7058 {
7059 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7060 .doit = nl80211_register_unexpected_frame,
7061 .policy = nl80211_policy,
7062 .flags = GENL_ADMIN_PERM,
7063 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7064 NL80211_FLAG_NEED_RTNL,
7065 },
7f6cf311
JB
7066 {
7067 .cmd = NL80211_CMD_PROBE_CLIENT,
7068 .doit = nl80211_probe_client,
7069 .policy = nl80211_policy,
7070 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7071 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7072 NL80211_FLAG_NEED_RTNL,
7073 },
5e760230
JB
7074 {
7075 .cmd = NL80211_CMD_REGISTER_BEACONS,
7076 .doit = nl80211_register_beacons,
7077 .policy = nl80211_policy,
7078 .flags = GENL_ADMIN_PERM,
7079 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7080 NL80211_FLAG_NEED_RTNL,
7081 },
1d9d9213
SW
7082 {
7083 .cmd = NL80211_CMD_SET_NOACK_MAP,
7084 .doit = nl80211_set_noack_map,
7085 .policy = nl80211_policy,
7086 .flags = GENL_ADMIN_PERM,
7087 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7088 NL80211_FLAG_NEED_RTNL,
7089 },
7090
55682965 7091};
9588bbd5 7092
6039f6d2
JM
7093static struct genl_multicast_group nl80211_mlme_mcgrp = {
7094 .name = "mlme",
7095};
55682965
JB
7096
7097/* multicast groups */
7098static struct genl_multicast_group nl80211_config_mcgrp = {
7099 .name = "config",
7100};
2a519311
JB
7101static struct genl_multicast_group nl80211_scan_mcgrp = {
7102 .name = "scan",
7103};
73d54c9e
LR
7104static struct genl_multicast_group nl80211_regulatory_mcgrp = {
7105 .name = "regulatory",
7106};
55682965
JB
7107
7108/* notification functions */
7109
7110void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
7111{
7112 struct sk_buff *msg;
7113
fd2120ca 7114 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
7115 if (!msg)
7116 return;
7117
7118 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
7119 nlmsg_free(msg);
7120 return;
7121 }
7122
463d0183
JB
7123 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7124 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
7125}
7126
362a415d
JB
7127static int nl80211_add_scan_req(struct sk_buff *msg,
7128 struct cfg80211_registered_device *rdev)
7129{
7130 struct cfg80211_scan_request *req = rdev->scan_req;
7131 struct nlattr *nest;
7132 int i;
7133
667503dd
JB
7134 ASSERT_RDEV_LOCK(rdev);
7135
362a415d
JB
7136 if (WARN_ON(!req))
7137 return 0;
7138
7139 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
7140 if (!nest)
7141 goto nla_put_failure;
9360ffd1
DM
7142 for (i = 0; i < req->n_ssids; i++) {
7143 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
7144 goto nla_put_failure;
7145 }
362a415d
JB
7146 nla_nest_end(msg, nest);
7147
7148 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
7149 if (!nest)
7150 goto nla_put_failure;
9360ffd1
DM
7151 for (i = 0; i < req->n_channels; i++) {
7152 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
7153 goto nla_put_failure;
7154 }
362a415d
JB
7155 nla_nest_end(msg, nest);
7156
9360ffd1
DM
7157 if (req->ie &&
7158 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
7159 goto nla_put_failure;
362a415d
JB
7160
7161 return 0;
7162 nla_put_failure:
7163 return -ENOBUFS;
7164}
7165
a538e2d5
JB
7166static int nl80211_send_scan_msg(struct sk_buff *msg,
7167 struct cfg80211_registered_device *rdev,
7168 struct net_device *netdev,
7169 u32 pid, u32 seq, int flags,
7170 u32 cmd)
2a519311
JB
7171{
7172 void *hdr;
7173
7174 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
7175 if (!hdr)
7176 return -1;
7177
9360ffd1
DM
7178 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7179 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7180 goto nla_put_failure;
2a519311 7181
362a415d
JB
7182 /* ignore errors and send incomplete event anyway */
7183 nl80211_add_scan_req(msg, rdev);
2a519311
JB
7184
7185 return genlmsg_end(msg, hdr);
7186
7187 nla_put_failure:
7188 genlmsg_cancel(msg, hdr);
7189 return -EMSGSIZE;
7190}
7191
807f8a8c
LC
7192static int
7193nl80211_send_sched_scan_msg(struct sk_buff *msg,
7194 struct cfg80211_registered_device *rdev,
7195 struct net_device *netdev,
7196 u32 pid, u32 seq, int flags, u32 cmd)
7197{
7198 void *hdr;
7199
7200 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
7201 if (!hdr)
7202 return -1;
7203
9360ffd1
DM
7204 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7205 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7206 goto nla_put_failure;
807f8a8c
LC
7207
7208 return genlmsg_end(msg, hdr);
7209
7210 nla_put_failure:
7211 genlmsg_cancel(msg, hdr);
7212 return -EMSGSIZE;
7213}
7214
a538e2d5
JB
7215void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
7216 struct net_device *netdev)
7217{
7218 struct sk_buff *msg;
7219
7220 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7221 if (!msg)
7222 return;
7223
7224 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7225 NL80211_CMD_TRIGGER_SCAN) < 0) {
7226 nlmsg_free(msg);
7227 return;
7228 }
7229
463d0183
JB
7230 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7231 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
7232}
7233
2a519311
JB
7234void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
7235 struct net_device *netdev)
7236{
7237 struct sk_buff *msg;
7238
fd2120ca 7239 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7240 if (!msg)
7241 return;
7242
a538e2d5
JB
7243 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7244 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
7245 nlmsg_free(msg);
7246 return;
7247 }
7248
463d0183
JB
7249 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7250 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7251}
7252
7253void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
7254 struct net_device *netdev)
7255{
7256 struct sk_buff *msg;
7257
fd2120ca 7258 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7259 if (!msg)
7260 return;
7261
a538e2d5
JB
7262 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7263 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
7264 nlmsg_free(msg);
7265 return;
7266 }
7267
463d0183
JB
7268 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7269 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7270}
7271
807f8a8c
LC
7272void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7273 struct net_device *netdev)
7274{
7275 struct sk_buff *msg;
7276
7277 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7278 if (!msg)
7279 return;
7280
7281 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7282 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
7283 nlmsg_free(msg);
7284 return;
7285 }
7286
7287 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7288 nl80211_scan_mcgrp.id, GFP_KERNEL);
7289}
7290
7291void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
7292 struct net_device *netdev, u32 cmd)
7293{
7294 struct sk_buff *msg;
7295
7296 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7297 if (!msg)
7298 return;
7299
7300 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
7301 nlmsg_free(msg);
7302 return;
7303 }
7304
7305 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7306 nl80211_scan_mcgrp.id, GFP_KERNEL);
7307}
7308
73d54c9e
LR
7309/*
7310 * This can happen on global regulatory changes or device specific settings
7311 * based on custom world regulatory domains.
7312 */
7313void nl80211_send_reg_change_event(struct regulatory_request *request)
7314{
7315 struct sk_buff *msg;
7316 void *hdr;
7317
fd2120ca 7318 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
7319 if (!msg)
7320 return;
7321
7322 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
7323 if (!hdr) {
7324 nlmsg_free(msg);
7325 return;
7326 }
7327
7328 /* Userspace can always count this one always being set */
9360ffd1
DM
7329 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
7330 goto nla_put_failure;
7331
7332 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
7333 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7334 NL80211_REGDOM_TYPE_WORLD))
7335 goto nla_put_failure;
7336 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
7337 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7338 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
7339 goto nla_put_failure;
7340 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
7341 request->intersect) {
7342 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7343 NL80211_REGDOM_TYPE_INTERSECTION))
7344 goto nla_put_failure;
7345 } else {
7346 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7347 NL80211_REGDOM_TYPE_COUNTRY) ||
7348 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
7349 request->alpha2))
7350 goto nla_put_failure;
7351 }
7352
7353 if (wiphy_idx_valid(request->wiphy_idx) &&
7354 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
7355 goto nla_put_failure;
73d54c9e 7356
3b7b72ee 7357 genlmsg_end(msg, hdr);
73d54c9e 7358
bc43b28c 7359 rcu_read_lock();
463d0183 7360 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
7361 GFP_ATOMIC);
7362 rcu_read_unlock();
73d54c9e
LR
7363
7364 return;
7365
7366nla_put_failure:
7367 genlmsg_cancel(msg, hdr);
7368 nlmsg_free(msg);
7369}
7370
6039f6d2
JM
7371static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
7372 struct net_device *netdev,
7373 const u8 *buf, size_t len,
e6d6e342 7374 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
7375{
7376 struct sk_buff *msg;
7377 void *hdr;
7378
e6d6e342 7379 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
7380 if (!msg)
7381 return;
7382
7383 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7384 if (!hdr) {
7385 nlmsg_free(msg);
7386 return;
7387 }
7388
9360ffd1
DM
7389 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7390 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7391 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
7392 goto nla_put_failure;
6039f6d2 7393
3b7b72ee 7394 genlmsg_end(msg, hdr);
6039f6d2 7395
463d0183
JB
7396 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7397 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
7398 return;
7399
7400 nla_put_failure:
7401 genlmsg_cancel(msg, hdr);
7402 nlmsg_free(msg);
7403}
7404
7405void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7406 struct net_device *netdev, const u8 *buf,
7407 size_t len, gfp_t gfp)
6039f6d2
JM
7408{
7409 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7410 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
7411}
7412
7413void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
7414 struct net_device *netdev, const u8 *buf,
e6d6e342 7415 size_t len, gfp_t gfp)
6039f6d2 7416{
e6d6e342
JB
7417 nl80211_send_mlme_event(rdev, netdev, buf, len,
7418 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
7419}
7420
53b46b84 7421void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7422 struct net_device *netdev, const u8 *buf,
7423 size_t len, gfp_t gfp)
6039f6d2
JM
7424{
7425 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7426 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
7427}
7428
53b46b84
JM
7429void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
7430 struct net_device *netdev, const u8 *buf,
e6d6e342 7431 size_t len, gfp_t gfp)
6039f6d2
JM
7432{
7433 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7434 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
7435}
7436
cf4e594e
JM
7437void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
7438 struct net_device *netdev, const u8 *buf,
7439 size_t len, gfp_t gfp)
7440{
7441 nl80211_send_mlme_event(rdev, netdev, buf, len,
7442 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
7443}
7444
7445void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
7446 struct net_device *netdev, const u8 *buf,
7447 size_t len, gfp_t gfp)
7448{
7449 nl80211_send_mlme_event(rdev, netdev, buf, len,
7450 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
7451}
7452
1b06bb40
LR
7453static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
7454 struct net_device *netdev, int cmd,
e6d6e342 7455 const u8 *addr, gfp_t gfp)
1965c853
JM
7456{
7457 struct sk_buff *msg;
7458 void *hdr;
7459
e6d6e342 7460 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
7461 if (!msg)
7462 return;
7463
7464 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7465 if (!hdr) {
7466 nlmsg_free(msg);
7467 return;
7468 }
7469
9360ffd1
DM
7470 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7471 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7472 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
7473 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
7474 goto nla_put_failure;
1965c853 7475
3b7b72ee 7476 genlmsg_end(msg, hdr);
1965c853 7477
463d0183
JB
7478 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7479 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
7480 return;
7481
7482 nla_put_failure:
7483 genlmsg_cancel(msg, hdr);
7484 nlmsg_free(msg);
7485}
7486
7487void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7488 struct net_device *netdev, const u8 *addr,
7489 gfp_t gfp)
1965c853
JM
7490{
7491 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 7492 addr, gfp);
1965c853
JM
7493}
7494
7495void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7496 struct net_device *netdev, const u8 *addr,
7497 gfp_t gfp)
1965c853 7498{
e6d6e342
JB
7499 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
7500 addr, gfp);
1965c853
JM
7501}
7502
b23aa676
SO
7503void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
7504 struct net_device *netdev, const u8 *bssid,
7505 const u8 *req_ie, size_t req_ie_len,
7506 const u8 *resp_ie, size_t resp_ie_len,
7507 u16 status, gfp_t gfp)
7508{
7509 struct sk_buff *msg;
7510 void *hdr;
7511
7512 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7513 if (!msg)
7514 return;
7515
7516 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
7517 if (!hdr) {
7518 nlmsg_free(msg);
7519 return;
7520 }
7521
9360ffd1
DM
7522 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7523 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7524 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
7525 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
7526 (req_ie &&
7527 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
7528 (resp_ie &&
7529 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
7530 goto nla_put_failure;
b23aa676 7531
3b7b72ee 7532 genlmsg_end(msg, hdr);
b23aa676 7533
463d0183
JB
7534 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7535 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7536 return;
7537
7538 nla_put_failure:
7539 genlmsg_cancel(msg, hdr);
7540 nlmsg_free(msg);
7541
7542}
7543
7544void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
7545 struct net_device *netdev, const u8 *bssid,
7546 const u8 *req_ie, size_t req_ie_len,
7547 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
7548{
7549 struct sk_buff *msg;
7550 void *hdr;
7551
7552 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7553 if (!msg)
7554 return;
7555
7556 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
7557 if (!hdr) {
7558 nlmsg_free(msg);
7559 return;
7560 }
7561
9360ffd1
DM
7562 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7563 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7564 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
7565 (req_ie &&
7566 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
7567 (resp_ie &&
7568 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
7569 goto nla_put_failure;
b23aa676 7570
3b7b72ee 7571 genlmsg_end(msg, hdr);
b23aa676 7572
463d0183
JB
7573 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7574 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7575 return;
7576
7577 nla_put_failure:
7578 genlmsg_cancel(msg, hdr);
7579 nlmsg_free(msg);
7580
7581}
7582
7583void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
7584 struct net_device *netdev, u16 reason,
667503dd 7585 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
7586{
7587 struct sk_buff *msg;
7588 void *hdr;
7589
667503dd 7590 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
7591 if (!msg)
7592 return;
7593
7594 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
7595 if (!hdr) {
7596 nlmsg_free(msg);
7597 return;
7598 }
7599
9360ffd1
DM
7600 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7601 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7602 (from_ap && reason &&
7603 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
7604 (from_ap &&
7605 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
7606 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
7607 goto nla_put_failure;
b23aa676 7608
3b7b72ee 7609 genlmsg_end(msg, hdr);
b23aa676 7610
463d0183
JB
7611 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7612 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
7613 return;
7614
7615 nla_put_failure:
7616 genlmsg_cancel(msg, hdr);
7617 nlmsg_free(msg);
7618
7619}
7620
04a773ad
JB
7621void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7622 struct net_device *netdev, const u8 *bssid,
7623 gfp_t gfp)
7624{
7625 struct sk_buff *msg;
7626 void *hdr;
7627
fd2120ca 7628 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7629 if (!msg)
7630 return;
7631
7632 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7633 if (!hdr) {
7634 nlmsg_free(msg);
7635 return;
7636 }
7637
9360ffd1
DM
7638 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7639 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7640 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
7641 goto nla_put_failure;
04a773ad 7642
3b7b72ee 7643 genlmsg_end(msg, hdr);
04a773ad 7644
463d0183
JB
7645 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7646 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7647 return;
7648
7649 nla_put_failure:
7650 genlmsg_cancel(msg, hdr);
7651 nlmsg_free(msg);
7652}
7653
c93b5e71
JC
7654void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7655 struct net_device *netdev,
7656 const u8 *macaddr, const u8* ie, u8 ie_len,
7657 gfp_t gfp)
7658{
7659 struct sk_buff *msg;
7660 void *hdr;
7661
7662 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7663 if (!msg)
7664 return;
7665
7666 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7667 if (!hdr) {
7668 nlmsg_free(msg);
7669 return;
7670 }
7671
9360ffd1
DM
7672 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7673 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7674 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
7675 (ie_len && ie &&
7676 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
7677 goto nla_put_failure;
c93b5e71 7678
3b7b72ee 7679 genlmsg_end(msg, hdr);
c93b5e71
JC
7680
7681 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7682 nl80211_mlme_mcgrp.id, gfp);
7683 return;
7684
7685 nla_put_failure:
7686 genlmsg_cancel(msg, hdr);
7687 nlmsg_free(msg);
7688}
7689
a3b8b056
JM
7690void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7691 struct net_device *netdev, const u8 *addr,
7692 enum nl80211_key_type key_type, int key_id,
e6d6e342 7693 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7694{
7695 struct sk_buff *msg;
7696 void *hdr;
7697
e6d6e342 7698 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7699 if (!msg)
7700 return;
7701
7702 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7703 if (!hdr) {
7704 nlmsg_free(msg);
7705 return;
7706 }
7707
9360ffd1
DM
7708 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7709 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7710 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
7711 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
7712 (key_id != -1 &&
7713 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
7714 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
7715 goto nla_put_failure;
a3b8b056 7716
3b7b72ee 7717 genlmsg_end(msg, hdr);
a3b8b056 7718
463d0183
JB
7719 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7720 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7721 return;
7722
7723 nla_put_failure:
7724 genlmsg_cancel(msg, hdr);
7725 nlmsg_free(msg);
7726}
7727
6bad8766
LR
7728void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7729 struct ieee80211_channel *channel_before,
7730 struct ieee80211_channel *channel_after)
7731{
7732 struct sk_buff *msg;
7733 void *hdr;
7734 struct nlattr *nl_freq;
7735
fd2120ca 7736 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7737 if (!msg)
7738 return;
7739
7740 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7741 if (!hdr) {
7742 nlmsg_free(msg);
7743 return;
7744 }
7745
7746 /*
7747 * Since we are applying the beacon hint to a wiphy we know its
7748 * wiphy_idx is valid
7749 */
9360ffd1
DM
7750 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
7751 goto nla_put_failure;
6bad8766
LR
7752
7753 /* Before */
7754 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7755 if (!nl_freq)
7756 goto nla_put_failure;
7757 if (nl80211_msg_put_channel(msg, channel_before))
7758 goto nla_put_failure;
7759 nla_nest_end(msg, nl_freq);
7760
7761 /* After */
7762 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7763 if (!nl_freq)
7764 goto nla_put_failure;
7765 if (nl80211_msg_put_channel(msg, channel_after))
7766 goto nla_put_failure;
7767 nla_nest_end(msg, nl_freq);
7768
3b7b72ee 7769 genlmsg_end(msg, hdr);
6bad8766 7770
463d0183
JB
7771 rcu_read_lock();
7772 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7773 GFP_ATOMIC);
7774 rcu_read_unlock();
6bad8766
LR
7775
7776 return;
7777
7778nla_put_failure:
7779 genlmsg_cancel(msg, hdr);
7780 nlmsg_free(msg);
7781}
7782
9588bbd5
JM
7783static void nl80211_send_remain_on_chan_event(
7784 int cmd, struct cfg80211_registered_device *rdev,
7785 struct net_device *netdev, u64 cookie,
7786 struct ieee80211_channel *chan,
7787 enum nl80211_channel_type channel_type,
7788 unsigned int duration, gfp_t gfp)
7789{
7790 struct sk_buff *msg;
7791 void *hdr;
7792
7793 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7794 if (!msg)
7795 return;
7796
7797 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7798 if (!hdr) {
7799 nlmsg_free(msg);
7800 return;
7801 }
7802
9360ffd1
DM
7803 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7804 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7805 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
7806 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type) ||
7807 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7808 goto nla_put_failure;
9588bbd5 7809
9360ffd1
DM
7810 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
7811 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
7812 goto nla_put_failure;
9588bbd5 7813
3b7b72ee 7814 genlmsg_end(msg, hdr);
9588bbd5
JM
7815
7816 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7817 nl80211_mlme_mcgrp.id, gfp);
7818 return;
7819
7820 nla_put_failure:
7821 genlmsg_cancel(msg, hdr);
7822 nlmsg_free(msg);
7823}
7824
7825void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7826 struct net_device *netdev, u64 cookie,
7827 struct ieee80211_channel *chan,
7828 enum nl80211_channel_type channel_type,
7829 unsigned int duration, gfp_t gfp)
7830{
7831 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7832 rdev, netdev, cookie, chan,
7833 channel_type, duration, gfp);
7834}
7835
7836void nl80211_send_remain_on_channel_cancel(
7837 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7838 u64 cookie, struct ieee80211_channel *chan,
7839 enum nl80211_channel_type channel_type, gfp_t gfp)
7840{
7841 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7842 rdev, netdev, cookie, chan,
7843 channel_type, 0, gfp);
7844}
7845
98b62183
JB
7846void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7847 struct net_device *dev, const u8 *mac_addr,
7848 struct station_info *sinfo, gfp_t gfp)
7849{
7850 struct sk_buff *msg;
7851
7852 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7853 if (!msg)
7854 return;
7855
66266b3a
JL
7856 if (nl80211_send_station(msg, 0, 0, 0,
7857 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
7858 nlmsg_free(msg);
7859 return;
7860 }
7861
7862 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7863 nl80211_mlme_mcgrp.id, gfp);
7864}
7865
ec15e68b
JM
7866void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7867 struct net_device *dev, const u8 *mac_addr,
7868 gfp_t gfp)
7869{
7870 struct sk_buff *msg;
7871 void *hdr;
7872
7873 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7874 if (!msg)
7875 return;
7876
7877 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7878 if (!hdr) {
7879 nlmsg_free(msg);
7880 return;
7881 }
7882
9360ffd1
DM
7883 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
7884 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
7885 goto nla_put_failure;
ec15e68b 7886
3b7b72ee 7887 genlmsg_end(msg, hdr);
ec15e68b
JM
7888
7889 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7890 nl80211_mlme_mcgrp.id, gfp);
7891 return;
7892
7893 nla_put_failure:
7894 genlmsg_cancel(msg, hdr);
7895 nlmsg_free(msg);
7896}
7897
b92ab5d8
JB
7898static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
7899 const u8 *addr, gfp_t gfp)
28946da7
JB
7900{
7901 struct wireless_dev *wdev = dev->ieee80211_ptr;
7902 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7903 struct sk_buff *msg;
7904 void *hdr;
7905 int err;
7906 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7907
7908 if (!nlpid)
7909 return false;
7910
7911 msg = nlmsg_new(100, gfp);
7912 if (!msg)
7913 return true;
7914
b92ab5d8 7915 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
7916 if (!hdr) {
7917 nlmsg_free(msg);
7918 return true;
7919 }
7920
9360ffd1
DM
7921 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7922 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
7923 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
7924 goto nla_put_failure;
28946da7
JB
7925
7926 err = genlmsg_end(msg, hdr);
7927 if (err < 0) {
7928 nlmsg_free(msg);
7929 return true;
7930 }
7931
7932 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7933 return true;
7934
7935 nla_put_failure:
7936 genlmsg_cancel(msg, hdr);
7937 nlmsg_free(msg);
7938 return true;
7939}
7940
b92ab5d8
JB
7941bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7942{
7943 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
7944 addr, gfp);
7945}
7946
7947bool nl80211_unexpected_4addr_frame(struct net_device *dev,
7948 const u8 *addr, gfp_t gfp)
7949{
7950 return __nl80211_unexpected_frame(dev,
7951 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
7952 addr, gfp);
7953}
7954
2e161f78
JB
7955int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7956 struct net_device *netdev, u32 nlpid,
804483e9
JB
7957 int freq, int sig_dbm,
7958 const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
7959{
7960 struct sk_buff *msg;
7961 void *hdr;
026331c4
JM
7962
7963 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7964 if (!msg)
7965 return -ENOMEM;
7966
2e161f78 7967 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
7968 if (!hdr) {
7969 nlmsg_free(msg);
7970 return -ENOMEM;
7971 }
7972
9360ffd1
DM
7973 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7974 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7975 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
7976 (sig_dbm &&
7977 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
7978 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
7979 goto nla_put_failure;
026331c4 7980
3b7b72ee 7981 genlmsg_end(msg, hdr);
026331c4 7982
3b7b72ee 7983 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
7984
7985 nla_put_failure:
7986 genlmsg_cancel(msg, hdr);
7987 nlmsg_free(msg);
7988 return -ENOBUFS;
7989}
7990
2e161f78
JB
7991void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7992 struct net_device *netdev, u64 cookie,
7993 const u8 *buf, size_t len, bool ack,
7994 gfp_t gfp)
026331c4
JM
7995{
7996 struct sk_buff *msg;
7997 void *hdr;
7998
7999 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8000 if (!msg)
8001 return;
8002
2e161f78 8003 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8004 if (!hdr) {
8005 nlmsg_free(msg);
8006 return;
8007 }
8008
9360ffd1
DM
8009 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8010 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8011 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8012 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8013 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8014 goto nla_put_failure;
026331c4 8015
3b7b72ee 8016 genlmsg_end(msg, hdr);
026331c4
JM
8017
8018 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8019 return;
8020
8021 nla_put_failure:
8022 genlmsg_cancel(msg, hdr);
8023 nlmsg_free(msg);
8024}
8025
d6dc1a38
JO
8026void
8027nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8028 struct net_device *netdev,
8029 enum nl80211_cqm_rssi_threshold_event rssi_event,
8030 gfp_t gfp)
8031{
8032 struct sk_buff *msg;
8033 struct nlattr *pinfoattr;
8034 void *hdr;
8035
8036 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8037 if (!msg)
8038 return;
8039
8040 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8041 if (!hdr) {
8042 nlmsg_free(msg);
8043 return;
8044 }
8045
9360ffd1
DM
8046 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8047 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8048 goto nla_put_failure;
d6dc1a38
JO
8049
8050 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8051 if (!pinfoattr)
8052 goto nla_put_failure;
8053
9360ffd1
DM
8054 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
8055 rssi_event))
8056 goto nla_put_failure;
d6dc1a38
JO
8057
8058 nla_nest_end(msg, pinfoattr);
8059
3b7b72ee 8060 genlmsg_end(msg, hdr);
d6dc1a38
JO
8061
8062 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8063 nl80211_mlme_mcgrp.id, gfp);
8064 return;
8065
8066 nla_put_failure:
8067 genlmsg_cancel(msg, hdr);
8068 nlmsg_free(msg);
8069}
8070
e5497d76
JB
8071void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
8072 struct net_device *netdev, const u8 *bssid,
8073 const u8 *replay_ctr, gfp_t gfp)
8074{
8075 struct sk_buff *msg;
8076 struct nlattr *rekey_attr;
8077 void *hdr;
8078
8079 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8080 if (!msg)
8081 return;
8082
8083 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
8084 if (!hdr) {
8085 nlmsg_free(msg);
8086 return;
8087 }
8088
9360ffd1
DM
8089 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8090 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8091 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8092 goto nla_put_failure;
e5497d76
JB
8093
8094 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
8095 if (!rekey_attr)
8096 goto nla_put_failure;
8097
9360ffd1
DM
8098 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
8099 NL80211_REPLAY_CTR_LEN, replay_ctr))
8100 goto nla_put_failure;
e5497d76
JB
8101
8102 nla_nest_end(msg, rekey_attr);
8103
3b7b72ee 8104 genlmsg_end(msg, hdr);
e5497d76
JB
8105
8106 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8107 nl80211_mlme_mcgrp.id, gfp);
8108 return;
8109
8110 nla_put_failure:
8111 genlmsg_cancel(msg, hdr);
8112 nlmsg_free(msg);
8113}
8114
c9df56b4
JM
8115void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
8116 struct net_device *netdev, int index,
8117 const u8 *bssid, bool preauth, gfp_t gfp)
8118{
8119 struct sk_buff *msg;
8120 struct nlattr *attr;
8121 void *hdr;
8122
8123 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8124 if (!msg)
8125 return;
8126
8127 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
8128 if (!hdr) {
8129 nlmsg_free(msg);
8130 return;
8131 }
8132
9360ffd1
DM
8133 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8134 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8135 goto nla_put_failure;
c9df56b4
JM
8136
8137 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
8138 if (!attr)
8139 goto nla_put_failure;
8140
9360ffd1
DM
8141 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
8142 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
8143 (preauth &&
8144 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
8145 goto nla_put_failure;
c9df56b4
JM
8146
8147 nla_nest_end(msg, attr);
8148
3b7b72ee 8149 genlmsg_end(msg, hdr);
c9df56b4
JM
8150
8151 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8152 nl80211_mlme_mcgrp.id, gfp);
8153 return;
8154
8155 nla_put_failure:
8156 genlmsg_cancel(msg, hdr);
8157 nlmsg_free(msg);
8158}
8159
5314526b
TP
8160void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
8161 struct net_device *netdev, int freq,
8162 enum nl80211_channel_type type, gfp_t gfp)
8163{
8164 struct sk_buff *msg;
8165 void *hdr;
8166
8167 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8168 if (!msg)
8169 return;
8170
8171 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
8172 if (!hdr) {
8173 nlmsg_free(msg);
8174 return;
8175 }
8176
7eab0f64
JL
8177 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8178 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8179 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, type))
8180 goto nla_put_failure;
5314526b
TP
8181
8182 genlmsg_end(msg, hdr);
8183
8184 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8185 nl80211_mlme_mcgrp.id, gfp);
8186 return;
8187
8188 nla_put_failure:
8189 genlmsg_cancel(msg, hdr);
8190 nlmsg_free(msg);
8191}
8192
c063dbf5
JB
8193void
8194nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
8195 struct net_device *netdev, const u8 *peer,
8196 u32 num_packets, gfp_t gfp)
8197{
8198 struct sk_buff *msg;
8199 struct nlattr *pinfoattr;
8200 void *hdr;
8201
8202 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8203 if (!msg)
8204 return;
8205
8206 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8207 if (!hdr) {
8208 nlmsg_free(msg);
8209 return;
8210 }
8211
9360ffd1
DM
8212 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8213 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8214 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
8215 goto nla_put_failure;
c063dbf5
JB
8216
8217 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8218 if (!pinfoattr)
8219 goto nla_put_failure;
8220
9360ffd1
DM
8221 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
8222 goto nla_put_failure;
c063dbf5
JB
8223
8224 nla_nest_end(msg, pinfoattr);
8225
3b7b72ee 8226 genlmsg_end(msg, hdr);
c063dbf5
JB
8227
8228 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8229 nl80211_mlme_mcgrp.id, gfp);
8230 return;
8231
8232 nla_put_failure:
8233 genlmsg_cancel(msg, hdr);
8234 nlmsg_free(msg);
8235}
8236
7f6cf311
JB
8237void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
8238 u64 cookie, bool acked, gfp_t gfp)
8239{
8240 struct wireless_dev *wdev = dev->ieee80211_ptr;
8241 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8242 struct sk_buff *msg;
8243 void *hdr;
8244 int err;
8245
8246 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8247 if (!msg)
8248 return;
8249
8250 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
8251 if (!hdr) {
8252 nlmsg_free(msg);
8253 return;
8254 }
8255
9360ffd1
DM
8256 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8257 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8258 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
8259 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8260 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
8261 goto nla_put_failure;
7f6cf311
JB
8262
8263 err = genlmsg_end(msg, hdr);
8264 if (err < 0) {
8265 nlmsg_free(msg);
8266 return;
8267 }
8268
8269 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8270 nl80211_mlme_mcgrp.id, gfp);
8271 return;
8272
8273 nla_put_failure:
8274 genlmsg_cancel(msg, hdr);
8275 nlmsg_free(msg);
8276}
8277EXPORT_SYMBOL(cfg80211_probe_status);
8278
5e760230
JB
8279void cfg80211_report_obss_beacon(struct wiphy *wiphy,
8280 const u8 *frame, size_t len,
804483e9 8281 int freq, int sig_dbm, gfp_t gfp)
5e760230
JB
8282{
8283 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
8284 struct sk_buff *msg;
8285 void *hdr;
8286 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
8287
8288 if (!nlpid)
8289 return;
8290
8291 msg = nlmsg_new(len + 100, gfp);
8292 if (!msg)
8293 return;
8294
8295 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
8296 if (!hdr) {
8297 nlmsg_free(msg);
8298 return;
8299 }
8300
9360ffd1
DM
8301 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8302 (freq &&
8303 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
8304 (sig_dbm &&
8305 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8306 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
8307 goto nla_put_failure;
5e760230
JB
8308
8309 genlmsg_end(msg, hdr);
8310
8311 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
8312 return;
8313
8314 nla_put_failure:
8315 genlmsg_cancel(msg, hdr);
8316 nlmsg_free(msg);
8317}
8318EXPORT_SYMBOL(cfg80211_report_obss_beacon);
8319
026331c4
JM
8320static int nl80211_netlink_notify(struct notifier_block * nb,
8321 unsigned long state,
8322 void *_notify)
8323{
8324 struct netlink_notify *notify = _notify;
8325 struct cfg80211_registered_device *rdev;
8326 struct wireless_dev *wdev;
8327
8328 if (state != NETLINK_URELEASE)
8329 return NOTIFY_DONE;
8330
8331 rcu_read_lock();
8332
5e760230 8333 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
026331c4 8334 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 8335 cfg80211_mlme_unregister_socket(wdev, notify->pid);
5e760230
JB
8336 if (rdev->ap_beacons_nlpid == notify->pid)
8337 rdev->ap_beacons_nlpid = 0;
8338 }
026331c4
JM
8339
8340 rcu_read_unlock();
8341
8342 return NOTIFY_DONE;
8343}
8344
8345static struct notifier_block nl80211_netlink_notifier = {
8346 .notifier_call = nl80211_netlink_notify,
8347};
8348
55682965
JB
8349/* initialisation/exit functions */
8350
8351int nl80211_init(void)
8352{
0d63cbb5 8353 int err;
55682965 8354
0d63cbb5
MM
8355 err = genl_register_family_with_ops(&nl80211_fam,
8356 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
8357 if (err)
8358 return err;
8359
55682965
JB
8360 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
8361 if (err)
8362 goto err_out;
8363
2a519311
JB
8364 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
8365 if (err)
8366 goto err_out;
8367
73d54c9e
LR
8368 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
8369 if (err)
8370 goto err_out;
8371
6039f6d2
JM
8372 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
8373 if (err)
8374 goto err_out;
8375
aff89a9b
JB
8376#ifdef CONFIG_NL80211_TESTMODE
8377 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
8378 if (err)
8379 goto err_out;
8380#endif
8381
026331c4
JM
8382 err = netlink_register_notifier(&nl80211_netlink_notifier);
8383 if (err)
8384 goto err_out;
8385
55682965
JB
8386 return 0;
8387 err_out:
8388 genl_unregister_family(&nl80211_fam);
8389 return err;
8390}
8391
8392void nl80211_exit(void)
8393{
026331c4 8394 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
8395 genl_unregister_family(&nl80211_fam);
8396}