]> git.proxmox.com Git - mirror_ubuntu-eoan-kernel.git/blame - net/wireless/nl80211.c
cfg80211: remove scan ies NULL check
[mirror_ubuntu-eoan-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
e35e4d28 25#include "rdev-ops.h"
55682965 26
5fb628e9
JM
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
89a54e48
JB
49/* returns ERR_PTR values */
50static struct wireless_dev *
51__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 52{
89a54e48
JB
53 struct cfg80211_registered_device *rdev;
54 struct wireless_dev *result = NULL;
55 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
56 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
57 u64 wdev_id;
58 int wiphy_idx = -1;
59 int ifidx = -1;
55682965 60
89a54e48 61 assert_cfg80211_lock();
55682965 62
89a54e48
JB
63 if (!have_ifidx && !have_wdev_id)
64 return ERR_PTR(-EINVAL);
55682965 65
89a54e48
JB
66 if (have_ifidx)
67 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
68 if (have_wdev_id) {
69 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
70 wiphy_idx = wdev_id >> 32;
55682965
JB
71 }
72
89a54e48
JB
73 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
74 struct wireless_dev *wdev;
75
76 if (wiphy_net(&rdev->wiphy) != netns)
77 continue;
78
79 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
80 continue;
81
82 mutex_lock(&rdev->devlist_mtx);
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
94 mutex_unlock(&rdev->devlist_mtx);
95
96 if (result)
97 break;
98 }
99
100 if (result)
101 return result;
102 return ERR_PTR(-ENODEV);
55682965
JB
103}
104
a9455408 105static struct cfg80211_registered_device *
878d9ec7 106__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 107{
7fee4778
JB
108 struct cfg80211_registered_device *rdev = NULL, *tmp;
109 struct net_device *netdev;
a9455408
JB
110
111 assert_cfg80211_lock();
112
878d9ec7 113 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
114 !attrs[NL80211_ATTR_IFINDEX] &&
115 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
116 return ERR_PTR(-EINVAL);
117
878d9ec7 118 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 119 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 120 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 121
89a54e48
JB
122 if (attrs[NL80211_ATTR_WDEV]) {
123 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
124 struct wireless_dev *wdev;
125 bool found = false;
126
127 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
128 if (tmp) {
129 /* make sure wdev exists */
130 mutex_lock(&tmp->devlist_mtx);
131 list_for_each_entry(wdev, &tmp->wdev_list, list) {
132 if (wdev->identifier != (u32)wdev_id)
133 continue;
134 found = true;
135 break;
136 }
137 mutex_unlock(&tmp->devlist_mtx);
138
139 if (!found)
140 tmp = NULL;
141
142 if (rdev && tmp != rdev)
143 return ERR_PTR(-EINVAL);
144 rdev = tmp;
145 }
146 }
147
878d9ec7
JB
148 if (attrs[NL80211_ATTR_IFINDEX]) {
149 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 150 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
151 if (netdev) {
152 if (netdev->ieee80211_ptr)
153 tmp = wiphy_to_dev(
154 netdev->ieee80211_ptr->wiphy);
155 else
156 tmp = NULL;
157
158 dev_put(netdev);
159
160 /* not wireless device -- return error */
161 if (!tmp)
162 return ERR_PTR(-EINVAL);
163
164 /* mismatch -- return error */
165 if (rdev && tmp != rdev)
166 return ERR_PTR(-EINVAL);
167
168 rdev = tmp;
a9455408 169 }
a9455408 170 }
a9455408 171
4f7eff10
JB
172 if (!rdev)
173 return ERR_PTR(-ENODEV);
a9455408 174
4f7eff10
JB
175 if (netns != wiphy_net(&rdev->wiphy))
176 return ERR_PTR(-ENODEV);
177
178 return rdev;
a9455408
JB
179}
180
181/*
182 * This function returns a pointer to the driver
183 * that the genl_info item that is passed refers to.
184 * If successful, it returns non-NULL and also locks
185 * the driver's mutex!
186 *
187 * This means that you need to call cfg80211_unlock_rdev()
188 * before being allowed to acquire &cfg80211_mutex!
189 *
190 * This is necessary because we need to lock the global
191 * mutex to get an item off the list safely, and then
192 * we lock the rdev mutex so it doesn't go away under us.
193 *
194 * We don't want to keep cfg80211_mutex locked
195 * for all the time in order to allow requests on
196 * other interfaces to go through at the same time.
197 *
198 * The result of this can be a PTR_ERR and hence must
199 * be checked with IS_ERR() for errors.
200 */
201static struct cfg80211_registered_device *
4f7eff10 202cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408
JB
203{
204 struct cfg80211_registered_device *rdev;
205
206 mutex_lock(&cfg80211_mutex);
878d9ec7 207 rdev = __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
208
209 /* if it is not an error we grab the lock on
210 * it to assure it won't be going away while
211 * we operate on it */
212 if (!IS_ERR(rdev))
213 mutex_lock(&rdev->mtx);
214
215 mutex_unlock(&cfg80211_mutex);
216
217 return rdev;
218}
219
55682965 220/* policy for the attributes */
b54452b0 221static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
222 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
223 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 224 .len = 20-1 },
31888487 225 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 226
72bdcf34 227 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 228 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
229 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
230 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
231 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
232
b9a5f8ca
JM
233 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
234 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
235 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
236 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 237 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
238
239 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
240 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
241 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 242
e007b857
EP
243 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
244 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 245
b9454e83 246 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
247 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
248 .len = WLAN_MAX_KEY_LEN },
249 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
250 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
251 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 252 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 253 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
254
255 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
256 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
257 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
258 .len = IEEE80211_MAX_DATA_LEN },
259 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
260 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
261 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
262 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
263 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
264 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
265 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 266 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 267 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 268 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 269 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 270 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 271 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 272
b2e1b302
LR
273 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
274 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
275
9f1ba906
JM
276 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
277 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
278 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
279 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
280 .len = NL80211_MAX_SUPP_RATES },
50b12f59 281 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 282
24bdd9f4 283 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 284 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 285
6c739419 286 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
287
288 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
289 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
290 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
291 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
292 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
293
294 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
295 .len = IEEE80211_MAX_SSID_LEN },
296 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
297 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 298 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 299 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 300 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
301 [NL80211_ATTR_STA_FLAGS2] = {
302 .len = sizeof(struct nl80211_sta_flag_update),
303 },
3f77316c 304 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
305 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
306 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
307 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
308 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
309 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 310 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 311 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
312 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
313 .len = WLAN_PMKID_LEN },
9588bbd5
JM
314 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
315 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 316 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
317 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
318 .len = IEEE80211_MAX_DATA_LEN },
319 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 320 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 321 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 322 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 323 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
324 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
325 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 326 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
327 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
328 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 329 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 330 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 331 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 332 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 333 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 334 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 335 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 336 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 337 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
338 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
339 .len = IEEE80211_MAX_DATA_LEN },
340 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
341 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 342 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 343 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 344 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
345 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
346 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
347 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
348 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
349 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 350 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
351 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
352 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 353 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
354 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
355 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
356 .len = NL80211_HT_CAPABILITY_LEN
357 },
1d9d9213 358 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 359 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 360 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 361 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 362 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 363 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 364 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 365 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
366 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
367 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
368 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
369 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
55682965
JB
370};
371
e31b8213 372/* policy for the key attributes */
b54452b0 373static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 374 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
375 [NL80211_KEY_IDX] = { .type = NLA_U8 },
376 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 377 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
378 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
379 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 380 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
381 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
382};
383
384/* policy for the key default flags */
385static const struct nla_policy
386nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
387 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
388 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
389};
390
ff1b6e69
JB
391/* policy for WoWLAN attributes */
392static const struct nla_policy
393nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
394 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
395 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
396 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
397 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
398 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
399 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
400 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
401 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
402};
403
e5497d76
JB
404/* policy for GTK rekey offload attributes */
405static const struct nla_policy
406nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
407 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
408 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
409 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
410};
411
a1f1c21c
LC
412static const struct nla_policy
413nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 414 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 415 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 416 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
417};
418
a043897a
HS
419/* ifidx get helper */
420static int nl80211_get_ifidx(struct netlink_callback *cb)
421{
422 int res;
423
424 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
425 nl80211_fam.attrbuf, nl80211_fam.maxattr,
426 nl80211_policy);
427 if (res)
428 return res;
429
430 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
431 return -EINVAL;
432
433 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
434 if (!res)
435 return -EINVAL;
436 return res;
437}
438
67748893
JB
439static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
440 struct netlink_callback *cb,
441 struct cfg80211_registered_device **rdev,
442 struct net_device **dev)
443{
444 int ifidx = cb->args[0];
445 int err;
446
447 if (!ifidx)
448 ifidx = nl80211_get_ifidx(cb);
449 if (ifidx < 0)
450 return ifidx;
451
452 cb->args[0] = ifidx;
453
454 rtnl_lock();
455
456 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
457 if (!*dev) {
458 err = -ENODEV;
459 goto out_rtnl;
460 }
461
462 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
463 if (IS_ERR(*rdev)) {
464 err = PTR_ERR(*rdev);
67748893
JB
465 goto out_rtnl;
466 }
467
468 return 0;
469 out_rtnl:
470 rtnl_unlock();
471 return err;
472}
473
474static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
475{
476 cfg80211_unlock_rdev(rdev);
477 rtnl_unlock();
478}
479
f4a11bb0
JB
480/* IE validation */
481static bool is_valid_ie_attr(const struct nlattr *attr)
482{
483 const u8 *pos;
484 int len;
485
486 if (!attr)
487 return true;
488
489 pos = nla_data(attr);
490 len = nla_len(attr);
491
492 while (len) {
493 u8 elemlen;
494
495 if (len < 2)
496 return false;
497 len -= 2;
498
499 elemlen = pos[1];
500 if (elemlen > len)
501 return false;
502
503 len -= elemlen;
504 pos += 2 + elemlen;
505 }
506
507 return true;
508}
509
55682965 510/* message building helper */
15e47304 511static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
512 int flags, u8 cmd)
513{
514 /* since there is no private header just add the generic one */
15e47304 515 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
516}
517
5dab3b8a
LR
518static int nl80211_msg_put_channel(struct sk_buff *msg,
519 struct ieee80211_channel *chan)
520{
9360ffd1
DM
521 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
522 chan->center_freq))
523 goto nla_put_failure;
5dab3b8a 524
9360ffd1
DM
525 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
526 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
527 goto nla_put_failure;
528 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
529 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
530 goto nla_put_failure;
531 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
532 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
533 goto nla_put_failure;
534 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
535 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
536 goto nla_put_failure;
5dab3b8a 537
9360ffd1
DM
538 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
539 DBM_TO_MBM(chan->max_power)))
540 goto nla_put_failure;
5dab3b8a
LR
541
542 return 0;
543
544 nla_put_failure:
545 return -ENOBUFS;
546}
547
55682965
JB
548/* netlink command implementations */
549
b9454e83
JB
550struct key_parse {
551 struct key_params p;
552 int idx;
e31b8213 553 int type;
b9454e83 554 bool def, defmgmt;
dbd2fd65 555 bool def_uni, def_multi;
b9454e83
JB
556};
557
558static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
559{
560 struct nlattr *tb[NL80211_KEY_MAX + 1];
561 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
562 nl80211_key_policy);
563 if (err)
564 return err;
565
566 k->def = !!tb[NL80211_KEY_DEFAULT];
567 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
568
dbd2fd65
JB
569 if (k->def) {
570 k->def_uni = true;
571 k->def_multi = true;
572 }
573 if (k->defmgmt)
574 k->def_multi = true;
575
b9454e83
JB
576 if (tb[NL80211_KEY_IDX])
577 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
578
579 if (tb[NL80211_KEY_DATA]) {
580 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
581 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
582 }
583
584 if (tb[NL80211_KEY_SEQ]) {
585 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
586 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
587 }
588
589 if (tb[NL80211_KEY_CIPHER])
590 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
591
e31b8213
JB
592 if (tb[NL80211_KEY_TYPE]) {
593 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
594 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
595 return -EINVAL;
596 }
597
dbd2fd65
JB
598 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
599 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
600 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
601 tb[NL80211_KEY_DEFAULT_TYPES],
602 nl80211_key_default_policy);
dbd2fd65
JB
603 if (err)
604 return err;
605
606 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
607 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
608 }
609
b9454e83
JB
610 return 0;
611}
612
613static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
614{
615 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
616 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
617 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
618 }
619
620 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
621 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
622 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
623 }
624
625 if (info->attrs[NL80211_ATTR_KEY_IDX])
626 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
627
628 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
629 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
630
631 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
632 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
633
dbd2fd65
JB
634 if (k->def) {
635 k->def_uni = true;
636 k->def_multi = true;
637 }
638 if (k->defmgmt)
639 k->def_multi = true;
640
e31b8213
JB
641 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
642 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
643 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
644 return -EINVAL;
645 }
646
dbd2fd65
JB
647 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
648 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
649 int err = nla_parse_nested(
650 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
651 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
652 nl80211_key_default_policy);
653 if (err)
654 return err;
655
656 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
657 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
658 }
659
b9454e83
JB
660 return 0;
661}
662
663static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
664{
665 int err;
666
667 memset(k, 0, sizeof(*k));
668 k->idx = -1;
e31b8213 669 k->type = -1;
b9454e83
JB
670
671 if (info->attrs[NL80211_ATTR_KEY])
672 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
673 else
674 err = nl80211_parse_key_old(info, k);
675
676 if (err)
677 return err;
678
679 if (k->def && k->defmgmt)
680 return -EINVAL;
681
dbd2fd65
JB
682 if (k->defmgmt) {
683 if (k->def_uni || !k->def_multi)
684 return -EINVAL;
685 }
686
b9454e83
JB
687 if (k->idx != -1) {
688 if (k->defmgmt) {
689 if (k->idx < 4 || k->idx > 5)
690 return -EINVAL;
691 } else if (k->def) {
692 if (k->idx < 0 || k->idx > 3)
693 return -EINVAL;
694 } else {
695 if (k->idx < 0 || k->idx > 5)
696 return -EINVAL;
697 }
698 }
699
700 return 0;
701}
702
fffd0934
JB
703static struct cfg80211_cached_keys *
704nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 705 struct nlattr *keys, bool *no_ht)
fffd0934
JB
706{
707 struct key_parse parse;
708 struct nlattr *key;
709 struct cfg80211_cached_keys *result;
710 int rem, err, def = 0;
711
712 result = kzalloc(sizeof(*result), GFP_KERNEL);
713 if (!result)
714 return ERR_PTR(-ENOMEM);
715
716 result->def = -1;
717 result->defmgmt = -1;
718
719 nla_for_each_nested(key, keys, rem) {
720 memset(&parse, 0, sizeof(parse));
721 parse.idx = -1;
722
723 err = nl80211_parse_key_new(key, &parse);
724 if (err)
725 goto error;
726 err = -EINVAL;
727 if (!parse.p.key)
728 goto error;
729 if (parse.idx < 0 || parse.idx > 4)
730 goto error;
731 if (parse.def) {
732 if (def)
733 goto error;
734 def = 1;
735 result->def = parse.idx;
dbd2fd65
JB
736 if (!parse.def_uni || !parse.def_multi)
737 goto error;
fffd0934
JB
738 } else if (parse.defmgmt)
739 goto error;
740 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 741 parse.idx, false, NULL);
fffd0934
JB
742 if (err)
743 goto error;
744 result->params[parse.idx].cipher = parse.p.cipher;
745 result->params[parse.idx].key_len = parse.p.key_len;
746 result->params[parse.idx].key = result->data[parse.idx];
747 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
748
749 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
750 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
751 if (no_ht)
752 *no_ht = true;
753 }
fffd0934
JB
754 }
755
756 return result;
757 error:
758 kfree(result);
759 return ERR_PTR(err);
760}
761
762static int nl80211_key_allowed(struct wireless_dev *wdev)
763{
764 ASSERT_WDEV_LOCK(wdev);
765
fffd0934
JB
766 switch (wdev->iftype) {
767 case NL80211_IFTYPE_AP:
768 case NL80211_IFTYPE_AP_VLAN:
074ac8df 769 case NL80211_IFTYPE_P2P_GO:
ff973af7 770 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
771 break;
772 case NL80211_IFTYPE_ADHOC:
773 if (!wdev->current_bss)
774 return -ENOLINK;
775 break;
776 case NL80211_IFTYPE_STATION:
074ac8df 777 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
778 if (wdev->sme_state != CFG80211_SME_CONNECTED)
779 return -ENOLINK;
780 break;
781 default:
782 return -EINVAL;
783 }
784
785 return 0;
786}
787
7527a782
JB
788static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
789{
790 struct nlattr *nl_modes = nla_nest_start(msg, attr);
791 int i;
792
793 if (!nl_modes)
794 goto nla_put_failure;
795
796 i = 0;
797 while (ifmodes) {
9360ffd1
DM
798 if ((ifmodes & 1) && nla_put_flag(msg, i))
799 goto nla_put_failure;
7527a782
JB
800 ifmodes >>= 1;
801 i++;
802 }
803
804 nla_nest_end(msg, nl_modes);
805 return 0;
806
807nla_put_failure:
808 return -ENOBUFS;
809}
810
811static int nl80211_put_iface_combinations(struct wiphy *wiphy,
812 struct sk_buff *msg)
813{
814 struct nlattr *nl_combis;
815 int i, j;
816
817 nl_combis = nla_nest_start(msg,
818 NL80211_ATTR_INTERFACE_COMBINATIONS);
819 if (!nl_combis)
820 goto nla_put_failure;
821
822 for (i = 0; i < wiphy->n_iface_combinations; i++) {
823 const struct ieee80211_iface_combination *c;
824 struct nlattr *nl_combi, *nl_limits;
825
826 c = &wiphy->iface_combinations[i];
827
828 nl_combi = nla_nest_start(msg, i + 1);
829 if (!nl_combi)
830 goto nla_put_failure;
831
832 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
833 if (!nl_limits)
834 goto nla_put_failure;
835
836 for (j = 0; j < c->n_limits; j++) {
837 struct nlattr *nl_limit;
838
839 nl_limit = nla_nest_start(msg, j + 1);
840 if (!nl_limit)
841 goto nla_put_failure;
9360ffd1
DM
842 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
843 c->limits[j].max))
844 goto nla_put_failure;
7527a782
JB
845 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
846 c->limits[j].types))
847 goto nla_put_failure;
848 nla_nest_end(msg, nl_limit);
849 }
850
851 nla_nest_end(msg, nl_limits);
852
9360ffd1
DM
853 if (c->beacon_int_infra_match &&
854 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
855 goto nla_put_failure;
856 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
857 c->num_different_channels) ||
858 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
859 c->max_interfaces))
860 goto nla_put_failure;
11c4a075
SW
861 if (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
862 c->radar_detect_widths))
863 goto nla_put_failure;
7527a782
JB
864
865 nla_nest_end(msg, nl_combi);
866 }
867
868 nla_nest_end(msg, nl_combis);
869
870 return 0;
871nla_put_failure:
872 return -ENOBUFS;
873}
874
15e47304 875static int nl80211_send_wiphy(struct sk_buff *msg, u32 portid, u32 seq, int flags,
55682965
JB
876 struct cfg80211_registered_device *dev)
877{
878 void *hdr;
ee688b00
JB
879 struct nlattr *nl_bands, *nl_band;
880 struct nlattr *nl_freqs, *nl_freq;
881 struct nlattr *nl_rates, *nl_rate;
8fdc621d 882 struct nlattr *nl_cmds;
ee688b00
JB
883 enum ieee80211_band band;
884 struct ieee80211_channel *chan;
885 struct ieee80211_rate *rate;
886 int i;
2e161f78
JB
887 const struct ieee80211_txrx_stypes *mgmt_stypes =
888 dev->wiphy.mgmt_stypes;
55682965 889
15e47304 890 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
55682965
JB
891 if (!hdr)
892 return -1;
893
9360ffd1
DM
894 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
895 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
896 nla_put_u32(msg, NL80211_ATTR_GENERATION,
897 cfg80211_rdev_list_generation) ||
898 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
899 dev->wiphy.retry_short) ||
900 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
901 dev->wiphy.retry_long) ||
902 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
903 dev->wiphy.frag_threshold) ||
904 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
905 dev->wiphy.rts_threshold) ||
906 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
907 dev->wiphy.coverage_class) ||
908 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
909 dev->wiphy.max_scan_ssids) ||
910 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
911 dev->wiphy.max_sched_scan_ssids) ||
912 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
913 dev->wiphy.max_scan_ie_len) ||
914 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
915 dev->wiphy.max_sched_scan_ie_len) ||
916 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
917 dev->wiphy.max_match_sets))
918 goto nla_put_failure;
919
920 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
921 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
922 goto nla_put_failure;
923 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
924 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
925 goto nla_put_failure;
926 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
927 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
928 goto nla_put_failure;
929 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
930 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
931 goto nla_put_failure;
932 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
933 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
934 goto nla_put_failure;
935 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
936 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
937 goto nla_put_failure;
938
939 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
940 sizeof(u32) * dev->wiphy.n_cipher_suites,
941 dev->wiphy.cipher_suites))
942 goto nla_put_failure;
943
944 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
945 dev->wiphy.max_num_pmkids))
946 goto nla_put_failure;
947
948 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
949 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
950 goto nla_put_failure;
951
952 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
953 dev->wiphy.available_antennas_tx) ||
954 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
955 dev->wiphy.available_antennas_rx))
956 goto nla_put_failure;
957
958 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
959 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
960 dev->wiphy.probe_resp_offload))
961 goto nla_put_failure;
87bbbe22 962
7f531e03
BR
963 if ((dev->wiphy.available_antennas_tx ||
964 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
965 u32 tx_ant = 0, rx_ant = 0;
966 int res;
e35e4d28 967 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
afe0cbf8 968 if (!res) {
9360ffd1
DM
969 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
970 tx_ant) ||
971 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
972 rx_ant))
973 goto nla_put_failure;
afe0cbf8
BR
974 }
975 }
976
7527a782
JB
977 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
978 dev->wiphy.interface_modes))
f59ac048
LR
979 goto nla_put_failure;
980
ee688b00
JB
981 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
982 if (!nl_bands)
983 goto nla_put_failure;
984
985 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
986 if (!dev->wiphy.bands[band])
987 continue;
988
989 nl_band = nla_nest_start(msg, band);
990 if (!nl_band)
991 goto nla_put_failure;
992
d51626df 993 /* add HT info */
9360ffd1
DM
994 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
995 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
996 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
997 &dev->wiphy.bands[band]->ht_cap.mcs) ||
998 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
999 dev->wiphy.bands[band]->ht_cap.cap) ||
1000 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1001 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
1002 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1003 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
1004 goto nla_put_failure;
d51626df 1005
bf0c111e
MP
1006 /* add VHT info */
1007 if (dev->wiphy.bands[band]->vht_cap.vht_supported &&
1008 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1009 sizeof(dev->wiphy.bands[band]->vht_cap.vht_mcs),
1010 &dev->wiphy.bands[band]->vht_cap.vht_mcs) ||
1011 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1012 dev->wiphy.bands[band]->vht_cap.cap)))
1013 goto nla_put_failure;
1014
ee688b00
JB
1015 /* add frequencies */
1016 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
1017 if (!nl_freqs)
1018 goto nla_put_failure;
1019
1020 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
1021 nl_freq = nla_nest_start(msg, i);
1022 if (!nl_freq)
1023 goto nla_put_failure;
1024
1025 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
1026
1027 if (nl80211_msg_put_channel(msg, chan))
1028 goto nla_put_failure;
e2f367f2 1029
ee688b00
JB
1030 nla_nest_end(msg, nl_freq);
1031 }
1032
1033 nla_nest_end(msg, nl_freqs);
1034
1035 /* add bitrates */
1036 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1037 if (!nl_rates)
1038 goto nla_put_failure;
1039
1040 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
1041 nl_rate = nla_nest_start(msg, i);
1042 if (!nl_rate)
1043 goto nla_put_failure;
1044
1045 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
1046 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1047 rate->bitrate))
1048 goto nla_put_failure;
1049 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1050 nla_put_flag(msg,
1051 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1052 goto nla_put_failure;
ee688b00
JB
1053
1054 nla_nest_end(msg, nl_rate);
1055 }
1056
1057 nla_nest_end(msg, nl_rates);
1058
1059 nla_nest_end(msg, nl_band);
1060 }
1061 nla_nest_end(msg, nl_bands);
1062
8fdc621d
JB
1063 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1064 if (!nl_cmds)
1065 goto nla_put_failure;
1066
1067 i = 0;
1068#define CMD(op, n) \
1069 do { \
1070 if (dev->ops->op) { \
1071 i++; \
9360ffd1
DM
1072 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1073 goto nla_put_failure; \
8fdc621d
JB
1074 } \
1075 } while (0)
1076
1077 CMD(add_virtual_intf, NEW_INTERFACE);
1078 CMD(change_virtual_intf, SET_INTERFACE);
1079 CMD(add_key, NEW_KEY);
8860020e 1080 CMD(start_ap, START_AP);
8fdc621d
JB
1081 CMD(add_station, NEW_STATION);
1082 CMD(add_mpath, NEW_MPATH);
24bdd9f4 1083 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 1084 CMD(change_bss, SET_BSS);
636a5d36
JM
1085 CMD(auth, AUTHENTICATE);
1086 CMD(assoc, ASSOCIATE);
1087 CMD(deauth, DEAUTHENTICATE);
1088 CMD(disassoc, DISASSOCIATE);
04a773ad 1089 CMD(join_ibss, JOIN_IBSS);
29cbe68c 1090 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
1091 CMD(set_pmksa, SET_PMKSA);
1092 CMD(del_pmksa, DEL_PMKSA);
1093 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
1094 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1095 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 1096 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 1097 CMD(mgmt_tx, FRAME);
f7ca38df 1098 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 1099 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 1100 i++;
9360ffd1
DM
1101 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1102 goto nla_put_failure;
463d0183 1103 }
e8c9bd5b 1104 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 1105 dev->ops->join_mesh) {
aa430da4
JB
1106 i++;
1107 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1108 goto nla_put_failure;
1109 }
e8347eba 1110 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
1111 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1112 CMD(tdls_mgmt, TDLS_MGMT);
1113 CMD(tdls_oper, TDLS_OPER);
1114 }
807f8a8c
LC
1115 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1116 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 1117 CMD(probe_client, PROBE_CLIENT);
1d9d9213 1118 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
1119 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1120 i++;
9360ffd1
DM
1121 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1122 goto nla_put_failure;
5e760230 1123 }
98104fde 1124 CMD(start_p2p_device, START_P2P_DEVICE);
f4e583c8 1125 CMD(set_mcast_rate, SET_MCAST_RATE);
8fdc621d 1126
4745fc09
KV
1127#ifdef CONFIG_NL80211_TESTMODE
1128 CMD(testmode_cmd, TESTMODE);
1129#endif
1130
8fdc621d 1131#undef CMD
b23aa676 1132
6829c878 1133 if (dev->ops->connect || dev->ops->auth) {
b23aa676 1134 i++;
9360ffd1
DM
1135 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1136 goto nla_put_failure;
b23aa676
SO
1137 }
1138
6829c878 1139 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 1140 i++;
9360ffd1
DM
1141 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1142 goto nla_put_failure;
b23aa676
SO
1143 }
1144
8fdc621d
JB
1145 nla_nest_end(msg, nl_cmds);
1146
7c4ef712 1147 if (dev->ops->remain_on_channel &&
9360ffd1
DM
1148 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1149 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1150 dev->wiphy.max_remain_on_channel_duration))
1151 goto nla_put_failure;
a293911d 1152
9360ffd1
DM
1153 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1154 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1155 goto nla_put_failure;
f7ca38df 1156
2e161f78
JB
1157 if (mgmt_stypes) {
1158 u16 stypes;
1159 struct nlattr *nl_ftypes, *nl_ifs;
1160 enum nl80211_iftype ift;
1161
1162 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1163 if (!nl_ifs)
1164 goto nla_put_failure;
1165
1166 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1167 nl_ftypes = nla_nest_start(msg, ift);
1168 if (!nl_ftypes)
1169 goto nla_put_failure;
1170 i = 0;
1171 stypes = mgmt_stypes[ift].tx;
1172 while (stypes) {
9360ffd1
DM
1173 if ((stypes & 1) &&
1174 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1175 (i << 4) | IEEE80211_FTYPE_MGMT))
1176 goto nla_put_failure;
2e161f78
JB
1177 stypes >>= 1;
1178 i++;
1179 }
1180 nla_nest_end(msg, nl_ftypes);
1181 }
1182
74b70a4e
JB
1183 nla_nest_end(msg, nl_ifs);
1184
2e161f78
JB
1185 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1186 if (!nl_ifs)
1187 goto nla_put_failure;
1188
1189 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1190 nl_ftypes = nla_nest_start(msg, ift);
1191 if (!nl_ftypes)
1192 goto nla_put_failure;
1193 i = 0;
1194 stypes = mgmt_stypes[ift].rx;
1195 while (stypes) {
9360ffd1
DM
1196 if ((stypes & 1) &&
1197 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1198 (i << 4) | IEEE80211_FTYPE_MGMT))
1199 goto nla_put_failure;
2e161f78
JB
1200 stypes >>= 1;
1201 i++;
1202 }
1203 nla_nest_end(msg, nl_ftypes);
1204 }
1205 nla_nest_end(msg, nl_ifs);
1206 }
1207
dfb89c56 1208#ifdef CONFIG_PM
ff1b6e69
JB
1209 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1210 struct nlattr *nl_wowlan;
1211
1212 nl_wowlan = nla_nest_start(msg,
1213 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1214 if (!nl_wowlan)
1215 goto nla_put_failure;
1216
9360ffd1
DM
1217 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1218 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1219 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1220 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1221 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1222 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1223 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1224 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1225 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1226 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1227 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1228 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1229 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1230 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1231 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1232 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1233 goto nla_put_failure;
ff1b6e69
JB
1234 if (dev->wiphy.wowlan.n_patterns) {
1235 struct nl80211_wowlan_pattern_support pat = {
1236 .max_patterns = dev->wiphy.wowlan.n_patterns,
1237 .min_pattern_len =
1238 dev->wiphy.wowlan.pattern_min_len,
1239 .max_pattern_len =
1240 dev->wiphy.wowlan.pattern_max_len,
1241 };
9360ffd1
DM
1242 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1243 sizeof(pat), &pat))
1244 goto nla_put_failure;
ff1b6e69
JB
1245 }
1246
1247 nla_nest_end(msg, nl_wowlan);
1248 }
dfb89c56 1249#endif
ff1b6e69 1250
7527a782
JB
1251 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1252 dev->wiphy.software_iftypes))
1253 goto nla_put_failure;
1254
1255 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1256 goto nla_put_failure;
1257
9360ffd1
DM
1258 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1259 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1260 dev->wiphy.ap_sme_capa))
1261 goto nla_put_failure;
562a7480 1262
9360ffd1
DM
1263 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1264 dev->wiphy.features))
1265 goto nla_put_failure;
1f074bd8 1266
9360ffd1
DM
1267 if (dev->wiphy.ht_capa_mod_mask &&
1268 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1269 sizeof(*dev->wiphy.ht_capa_mod_mask),
1270 dev->wiphy.ht_capa_mod_mask))
1271 goto nla_put_failure;
7e7c8926 1272
77765eaf
VT
1273 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1274 dev->wiphy.max_acl_mac_addrs &&
1275 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1276 dev->wiphy.max_acl_mac_addrs))
1277 goto nla_put_failure;
1278
55682965
JB
1279 return genlmsg_end(msg, hdr);
1280
1281 nla_put_failure:
bc3ed28c
TG
1282 genlmsg_cancel(msg, hdr);
1283 return -EMSGSIZE;
55682965
JB
1284}
1285
1286static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1287{
1288 int idx = 0;
1289 int start = cb->args[0];
1290 struct cfg80211_registered_device *dev;
1291
a1794390 1292 mutex_lock(&cfg80211_mutex);
79c97e97 1293 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1294 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1295 continue;
b4637271 1296 if (++idx <= start)
55682965 1297 continue;
15e47304 1298 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).portid,
55682965 1299 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1300 dev) < 0) {
1301 idx--;
55682965 1302 break;
b4637271 1303 }
55682965 1304 }
a1794390 1305 mutex_unlock(&cfg80211_mutex);
55682965
JB
1306
1307 cb->args[0] = idx;
1308
1309 return skb->len;
1310}
1311
1312static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1313{
1314 struct sk_buff *msg;
4c476991 1315 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1316
fd2120ca 1317 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1318 if (!msg)
4c476991 1319 return -ENOMEM;
55682965 1320
15e47304 1321 if (nl80211_send_wiphy(msg, info->snd_portid, info->snd_seq, 0, dev) < 0) {
4c476991
JB
1322 nlmsg_free(msg);
1323 return -ENOBUFS;
1324 }
55682965 1325
134e6375 1326 return genlmsg_reply(msg, info);
55682965
JB
1327}
1328
31888487
JM
1329static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1330 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1331 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1332 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1333 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1334 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1335};
1336
1337static int parse_txq_params(struct nlattr *tb[],
1338 struct ieee80211_txq_params *txq_params)
1339{
a3304b0a 1340 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1341 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1342 !tb[NL80211_TXQ_ATTR_AIFS])
1343 return -EINVAL;
1344
a3304b0a 1345 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1346 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1347 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1348 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1349 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1350
a3304b0a
JB
1351 if (txq_params->ac >= NL80211_NUM_ACS)
1352 return -EINVAL;
1353
31888487
JM
1354 return 0;
1355}
1356
f444de05
JB
1357static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1358{
1359 /*
cc1d2806
JB
1360 * You can only set the channel explicitly for WDS interfaces,
1361 * all others have their channel managed via their respective
1362 * "establish a connection" command (connect, join, ...)
1363 *
1364 * For AP/GO and mesh mode, the channel can be set with the
1365 * channel userspace API, but is only stored and passed to the
1366 * low-level driver when the AP starts or the mesh is joined.
1367 * This is for backward compatibility, userspace can also give
1368 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1369 *
1370 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1371 * whatever else is going on, so they have their own special
1372 * operation to set the monitor channel if possible.
f444de05
JB
1373 */
1374 return !wdev ||
1375 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1376 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1377 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1378 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1379}
1380
683b6d3b
JB
1381static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1382 struct genl_info *info,
1383 struct cfg80211_chan_def *chandef)
1384{
dbeca2ea 1385 u32 control_freq;
683b6d3b
JB
1386
1387 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1388 return -EINVAL;
1389
1390 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1391
1392 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1393 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1394 chandef->center_freq1 = control_freq;
1395 chandef->center_freq2 = 0;
683b6d3b
JB
1396
1397 /* Primary channel not allowed */
1398 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1399 return -EINVAL;
1400
3d9d1d66
JB
1401 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1402 enum nl80211_channel_type chantype;
1403
1404 chantype = nla_get_u32(
1405 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1406
1407 switch (chantype) {
1408 case NL80211_CHAN_NO_HT:
1409 case NL80211_CHAN_HT20:
1410 case NL80211_CHAN_HT40PLUS:
1411 case NL80211_CHAN_HT40MINUS:
1412 cfg80211_chandef_create(chandef, chandef->chan,
1413 chantype);
1414 break;
1415 default:
1416 return -EINVAL;
1417 }
1418 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1419 chandef->width =
1420 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1421 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1422 chandef->center_freq1 =
1423 nla_get_u32(
1424 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1425 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1426 chandef->center_freq2 =
1427 nla_get_u32(
1428 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1429 }
1430
9f5e8f6e 1431 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1432 return -EINVAL;
1433
9f5e8f6e
JB
1434 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1435 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1436 return -EINVAL;
1437
683b6d3b
JB
1438 return 0;
1439}
1440
f444de05
JB
1441static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1442 struct wireless_dev *wdev,
1443 struct genl_info *info)
1444{
683b6d3b 1445 struct cfg80211_chan_def chandef;
f444de05 1446 int result;
e8c9bd5b
JB
1447 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1448
1449 if (wdev)
1450 iftype = wdev->iftype;
f444de05 1451
f444de05
JB
1452 if (!nl80211_can_set_dev_channel(wdev))
1453 return -EOPNOTSUPP;
1454
683b6d3b
JB
1455 result = nl80211_parse_chandef(rdev, info, &chandef);
1456 if (result)
1457 return result;
f444de05
JB
1458
1459 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1460 switch (iftype) {
aa430da4
JB
1461 case NL80211_IFTYPE_AP:
1462 case NL80211_IFTYPE_P2P_GO:
1463 if (wdev->beacon_interval) {
1464 result = -EBUSY;
1465 break;
1466 }
683b6d3b 1467 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1468 result = -EINVAL;
1469 break;
1470 }
683b6d3b 1471 wdev->preset_chandef = chandef;
aa430da4
JB
1472 result = 0;
1473 break;
cc1d2806 1474 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1475 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1476 break;
e8c9bd5b 1477 case NL80211_IFTYPE_MONITOR:
683b6d3b 1478 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1479 break;
aa430da4 1480 default:
e8c9bd5b 1481 result = -EINVAL;
f444de05
JB
1482 }
1483 mutex_unlock(&rdev->devlist_mtx);
1484
1485 return result;
1486}
1487
1488static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1489{
4c476991
JB
1490 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1491 struct net_device *netdev = info->user_ptr[1];
f444de05 1492
4c476991 1493 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1494}
1495
e8347eba
BJ
1496static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1497{
43b19952
JB
1498 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1499 struct net_device *dev = info->user_ptr[1];
1500 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1501 const u8 *bssid;
e8347eba
BJ
1502
1503 if (!info->attrs[NL80211_ATTR_MAC])
1504 return -EINVAL;
1505
43b19952
JB
1506 if (netif_running(dev))
1507 return -EBUSY;
e8347eba 1508
43b19952
JB
1509 if (!rdev->ops->set_wds_peer)
1510 return -EOPNOTSUPP;
e8347eba 1511
43b19952
JB
1512 if (wdev->iftype != NL80211_IFTYPE_WDS)
1513 return -EOPNOTSUPP;
e8347eba
BJ
1514
1515 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1516 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1517}
1518
1519
55682965
JB
1520static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1521{
1522 struct cfg80211_registered_device *rdev;
f444de05
JB
1523 struct net_device *netdev = NULL;
1524 struct wireless_dev *wdev;
a1e567c8 1525 int result = 0, rem_txq_params = 0;
31888487 1526 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1527 u32 changed;
1528 u8 retry_short = 0, retry_long = 0;
1529 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1530 u8 coverage_class = 0;
55682965 1531
f444de05
JB
1532 /*
1533 * Try to find the wiphy and netdev. Normally this
1534 * function shouldn't need the netdev, but this is
1535 * done for backward compatibility -- previously
1536 * setting the channel was done per wiphy, but now
1537 * it is per netdev. Previous userland like hostapd
1538 * also passed a netdev to set_wiphy, so that it is
1539 * possible to let that go to the right netdev!
1540 */
4bbf4d56
JB
1541 mutex_lock(&cfg80211_mutex);
1542
f444de05
JB
1543 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1544 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1545
1546 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1547 if (netdev && netdev->ieee80211_ptr) {
1548 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1549 mutex_lock(&rdev->mtx);
1550 } else
1551 netdev = NULL;
4bbf4d56
JB
1552 }
1553
f444de05 1554 if (!netdev) {
878d9ec7
JB
1555 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1556 info->attrs);
f444de05
JB
1557 if (IS_ERR(rdev)) {
1558 mutex_unlock(&cfg80211_mutex);
4c476991 1559 return PTR_ERR(rdev);
f444de05
JB
1560 }
1561 wdev = NULL;
1562 netdev = NULL;
1563 result = 0;
1564
1565 mutex_lock(&rdev->mtx);
71fe96bf 1566 } else
f444de05 1567 wdev = netdev->ieee80211_ptr;
f444de05
JB
1568
1569 /*
1570 * end workaround code, by now the rdev is available
1571 * and locked, and wdev may or may not be NULL.
1572 */
4bbf4d56
JB
1573
1574 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1575 result = cfg80211_dev_rename(
1576 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1577
1578 mutex_unlock(&cfg80211_mutex);
1579
1580 if (result)
1581 goto bad_res;
31888487
JM
1582
1583 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1584 struct ieee80211_txq_params txq_params;
1585 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1586
1587 if (!rdev->ops->set_txq_params) {
1588 result = -EOPNOTSUPP;
1589 goto bad_res;
1590 }
1591
f70f01c2
EP
1592 if (!netdev) {
1593 result = -EINVAL;
1594 goto bad_res;
1595 }
1596
133a3ff2
JB
1597 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1598 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1599 result = -EINVAL;
1600 goto bad_res;
1601 }
1602
2b5f8b0b
JB
1603 if (!netif_running(netdev)) {
1604 result = -ENETDOWN;
1605 goto bad_res;
1606 }
1607
31888487
JM
1608 nla_for_each_nested(nl_txq_params,
1609 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1610 rem_txq_params) {
1611 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1612 nla_data(nl_txq_params),
1613 nla_len(nl_txq_params),
1614 txq_params_policy);
1615 result = parse_txq_params(tb, &txq_params);
1616 if (result)
1617 goto bad_res;
1618
e35e4d28
HG
1619 result = rdev_set_txq_params(rdev, netdev,
1620 &txq_params);
31888487
JM
1621 if (result)
1622 goto bad_res;
1623 }
1624 }
55682965 1625
72bdcf34 1626 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1627 result = __nl80211_set_channel(rdev,
1628 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1629 info);
72bdcf34
JM
1630 if (result)
1631 goto bad_res;
1632 }
1633
98d2ff8b 1634 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 1635 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
1636 enum nl80211_tx_power_setting type;
1637 int idx, mbm = 0;
1638
c8442118
JB
1639 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
1640 txp_wdev = NULL;
1641
98d2ff8b 1642 if (!rdev->ops->set_tx_power) {
60ea385f 1643 result = -EOPNOTSUPP;
98d2ff8b
JO
1644 goto bad_res;
1645 }
1646
1647 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1648 type = nla_get_u32(info->attrs[idx]);
1649
1650 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1651 (type != NL80211_TX_POWER_AUTOMATIC)) {
1652 result = -EINVAL;
1653 goto bad_res;
1654 }
1655
1656 if (type != NL80211_TX_POWER_AUTOMATIC) {
1657 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1658 mbm = nla_get_u32(info->attrs[idx]);
1659 }
1660
c8442118 1661 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
1662 if (result)
1663 goto bad_res;
1664 }
1665
afe0cbf8
BR
1666 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1667 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1668 u32 tx_ant, rx_ant;
7f531e03
BR
1669 if ((!rdev->wiphy.available_antennas_tx &&
1670 !rdev->wiphy.available_antennas_rx) ||
1671 !rdev->ops->set_antenna) {
afe0cbf8
BR
1672 result = -EOPNOTSUPP;
1673 goto bad_res;
1674 }
1675
1676 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1677 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1678
a7ffac95 1679 /* reject antenna configurations which don't match the
7f531e03
BR
1680 * available antenna masks, except for the "all" mask */
1681 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1682 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1683 result = -EINVAL;
1684 goto bad_res;
1685 }
1686
7f531e03
BR
1687 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1688 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1689
e35e4d28 1690 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
1691 if (result)
1692 goto bad_res;
1693 }
1694
b9a5f8ca
JM
1695 changed = 0;
1696
1697 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1698 retry_short = nla_get_u8(
1699 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1700 if (retry_short == 0) {
1701 result = -EINVAL;
1702 goto bad_res;
1703 }
1704 changed |= WIPHY_PARAM_RETRY_SHORT;
1705 }
1706
1707 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1708 retry_long = nla_get_u8(
1709 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1710 if (retry_long == 0) {
1711 result = -EINVAL;
1712 goto bad_res;
1713 }
1714 changed |= WIPHY_PARAM_RETRY_LONG;
1715 }
1716
1717 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1718 frag_threshold = nla_get_u32(
1719 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1720 if (frag_threshold < 256) {
1721 result = -EINVAL;
1722 goto bad_res;
1723 }
1724 if (frag_threshold != (u32) -1) {
1725 /*
1726 * Fragments (apart from the last one) are required to
1727 * have even length. Make the fragmentation code
1728 * simpler by stripping LSB should someone try to use
1729 * odd threshold value.
1730 */
1731 frag_threshold &= ~0x1;
1732 }
1733 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1734 }
1735
1736 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1737 rts_threshold = nla_get_u32(
1738 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1739 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1740 }
1741
81077e82
LT
1742 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1743 coverage_class = nla_get_u8(
1744 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1745 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1746 }
1747
b9a5f8ca
JM
1748 if (changed) {
1749 u8 old_retry_short, old_retry_long;
1750 u32 old_frag_threshold, old_rts_threshold;
81077e82 1751 u8 old_coverage_class;
b9a5f8ca
JM
1752
1753 if (!rdev->ops->set_wiphy_params) {
1754 result = -EOPNOTSUPP;
1755 goto bad_res;
1756 }
1757
1758 old_retry_short = rdev->wiphy.retry_short;
1759 old_retry_long = rdev->wiphy.retry_long;
1760 old_frag_threshold = rdev->wiphy.frag_threshold;
1761 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1762 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1763
1764 if (changed & WIPHY_PARAM_RETRY_SHORT)
1765 rdev->wiphy.retry_short = retry_short;
1766 if (changed & WIPHY_PARAM_RETRY_LONG)
1767 rdev->wiphy.retry_long = retry_long;
1768 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1769 rdev->wiphy.frag_threshold = frag_threshold;
1770 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1771 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1772 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1773 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 1774
e35e4d28 1775 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
1776 if (result) {
1777 rdev->wiphy.retry_short = old_retry_short;
1778 rdev->wiphy.retry_long = old_retry_long;
1779 rdev->wiphy.frag_threshold = old_frag_threshold;
1780 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1781 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1782 }
1783 }
72bdcf34 1784
306d6112 1785 bad_res:
4bbf4d56 1786 mutex_unlock(&rdev->mtx);
f444de05
JB
1787 if (netdev)
1788 dev_put(netdev);
55682965
JB
1789 return result;
1790}
1791
71bbc994
JB
1792static inline u64 wdev_id(struct wireless_dev *wdev)
1793{
1794 return (u64)wdev->identifier |
1795 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
1796}
55682965 1797
683b6d3b
JB
1798static int nl80211_send_chandef(struct sk_buff *msg,
1799 struct cfg80211_chan_def *chandef)
1800{
9f5e8f6e 1801 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 1802
683b6d3b
JB
1803 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1804 chandef->chan->center_freq))
1805 return -ENOBUFS;
3d9d1d66
JB
1806 switch (chandef->width) {
1807 case NL80211_CHAN_WIDTH_20_NOHT:
1808 case NL80211_CHAN_WIDTH_20:
1809 case NL80211_CHAN_WIDTH_40:
1810 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1811 cfg80211_get_chandef_type(chandef)))
1812 return -ENOBUFS;
1813 break;
1814 default:
1815 break;
1816 }
1817 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
1818 return -ENOBUFS;
1819 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
1820 return -ENOBUFS;
1821 if (chandef->center_freq2 &&
1822 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
1823 return -ENOBUFS;
1824 return 0;
1825}
1826
15e47304 1827static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 1828 struct cfg80211_registered_device *rdev,
72fb2abc 1829 struct wireless_dev *wdev)
55682965 1830{
72fb2abc 1831 struct net_device *dev = wdev->netdev;
55682965
JB
1832 void *hdr;
1833
15e47304 1834 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
1835 if (!hdr)
1836 return -1;
1837
72fb2abc
JB
1838 if (dev &&
1839 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 1840 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
1841 goto nla_put_failure;
1842
1843 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1844 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 1845 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 1846 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
1847 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1848 rdev->devlist_generation ^
1849 (cfg80211_rdev_list_generation << 2)))
1850 goto nla_put_failure;
f5ea9120 1851
5b7ccaf3 1852 if (rdev->ops->get_channel) {
683b6d3b
JB
1853 int ret;
1854 struct cfg80211_chan_def chandef;
1855
1856 ret = rdev_get_channel(rdev, wdev, &chandef);
1857 if (ret == 0) {
1858 if (nl80211_send_chandef(msg, &chandef))
1859 goto nla_put_failure;
1860 }
d91df0e3
PF
1861 }
1862
b84e7a05
AQ
1863 if (wdev->ssid_len) {
1864 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
1865 goto nla_put_failure;
1866 }
1867
55682965
JB
1868 return genlmsg_end(msg, hdr);
1869
1870 nla_put_failure:
bc3ed28c
TG
1871 genlmsg_cancel(msg, hdr);
1872 return -EMSGSIZE;
55682965
JB
1873}
1874
1875static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1876{
1877 int wp_idx = 0;
1878 int if_idx = 0;
1879 int wp_start = cb->args[0];
1880 int if_start = cb->args[1];
f5ea9120 1881 struct cfg80211_registered_device *rdev;
55682965
JB
1882 struct wireless_dev *wdev;
1883
a1794390 1884 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1885 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1886 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1887 continue;
bba95fef
JB
1888 if (wp_idx < wp_start) {
1889 wp_idx++;
55682965 1890 continue;
bba95fef 1891 }
55682965
JB
1892 if_idx = 0;
1893
f5ea9120 1894 mutex_lock(&rdev->devlist_mtx);
89a54e48 1895 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
1896 if (if_idx < if_start) {
1897 if_idx++;
55682965 1898 continue;
bba95fef 1899 }
15e47304 1900 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 1901 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 1902 rdev, wdev) < 0) {
f5ea9120 1903 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1904 goto out;
1905 }
1906 if_idx++;
55682965 1907 }
f5ea9120 1908 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1909
1910 wp_idx++;
55682965 1911 }
bba95fef 1912 out:
a1794390 1913 mutex_unlock(&cfg80211_mutex);
55682965
JB
1914
1915 cb->args[0] = wp_idx;
1916 cb->args[1] = if_idx;
1917
1918 return skb->len;
1919}
1920
1921static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1922{
1923 struct sk_buff *msg;
4c476991 1924 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 1925 struct wireless_dev *wdev = info->user_ptr[1];
55682965 1926
fd2120ca 1927 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1928 if (!msg)
4c476991 1929 return -ENOMEM;
55682965 1930
15e47304 1931 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 1932 dev, wdev) < 0) {
4c476991
JB
1933 nlmsg_free(msg);
1934 return -ENOBUFS;
1935 }
55682965 1936
134e6375 1937 return genlmsg_reply(msg, info);
55682965
JB
1938}
1939
66f7ac50
MW
1940static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1941 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1942 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1943 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1944 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1945 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1946};
1947
1948static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1949{
1950 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1951 int flag;
1952
1953 *mntrflags = 0;
1954
1955 if (!nla)
1956 return -EINVAL;
1957
1958 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1959 nla, mntr_flags_policy))
1960 return -EINVAL;
1961
1962 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1963 if (flags[flag])
1964 *mntrflags |= (1<<flag);
1965
1966 return 0;
1967}
1968
9bc383de 1969static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1970 struct net_device *netdev, u8 use_4addr,
1971 enum nl80211_iftype iftype)
9bc383de 1972{
ad4bb6f8 1973 if (!use_4addr) {
f350a0a8 1974 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1975 return -EBUSY;
9bc383de 1976 return 0;
ad4bb6f8 1977 }
9bc383de
JB
1978
1979 switch (iftype) {
1980 case NL80211_IFTYPE_AP_VLAN:
1981 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1982 return 0;
1983 break;
1984 case NL80211_IFTYPE_STATION:
1985 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1986 return 0;
1987 break;
1988 default:
1989 break;
1990 }
1991
1992 return -EOPNOTSUPP;
1993}
1994
55682965
JB
1995static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1996{
4c476991 1997 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1998 struct vif_params params;
e36d56b6 1999 int err;
04a773ad 2000 enum nl80211_iftype otype, ntype;
4c476991 2001 struct net_device *dev = info->user_ptr[1];
92ffe055 2002 u32 _flags, *flags = NULL;
ac7f9cfa 2003 bool change = false;
55682965 2004
2ec600d6
LCC
2005 memset(&params, 0, sizeof(params));
2006
04a773ad 2007 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2008
723b038d 2009 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2010 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2011 if (otype != ntype)
ac7f9cfa 2012 change = true;
4c476991
JB
2013 if (ntype > NL80211_IFTYPE_MAX)
2014 return -EINVAL;
723b038d
JB
2015 }
2016
92ffe055 2017 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2018 struct wireless_dev *wdev = dev->ieee80211_ptr;
2019
4c476991
JB
2020 if (ntype != NL80211_IFTYPE_MESH_POINT)
2021 return -EINVAL;
29cbe68c
JB
2022 if (netif_running(dev))
2023 return -EBUSY;
2024
2025 wdev_lock(wdev);
2026 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2027 IEEE80211_MAX_MESH_ID_LEN);
2028 wdev->mesh_id_up_len =
2029 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2030 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2031 wdev->mesh_id_up_len);
2032 wdev_unlock(wdev);
2ec600d6
LCC
2033 }
2034
8b787643
FF
2035 if (info->attrs[NL80211_ATTR_4ADDR]) {
2036 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2037 change = true;
ad4bb6f8 2038 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2039 if (err)
4c476991 2040 return err;
8b787643
FF
2041 } else {
2042 params.use_4addr = -1;
2043 }
2044
92ffe055 2045 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2046 if (ntype != NL80211_IFTYPE_MONITOR)
2047 return -EINVAL;
92ffe055
JB
2048 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2049 &_flags);
ac7f9cfa 2050 if (err)
4c476991 2051 return err;
ac7f9cfa
JB
2052
2053 flags = &_flags;
2054 change = true;
92ffe055 2055 }
3b85875a 2056
ac7f9cfa 2057 if (change)
3d54d255 2058 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2059 else
2060 err = 0;
60719ffd 2061
9bc383de
JB
2062 if (!err && params.use_4addr != -1)
2063 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2064
55682965
JB
2065 return err;
2066}
2067
2068static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2069{
4c476991 2070 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2071 struct vif_params params;
84efbb84 2072 struct wireless_dev *wdev;
1c90f9d4 2073 struct sk_buff *msg;
55682965
JB
2074 int err;
2075 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2076 u32 flags;
55682965 2077
2ec600d6
LCC
2078 memset(&params, 0, sizeof(params));
2079
55682965
JB
2080 if (!info->attrs[NL80211_ATTR_IFNAME])
2081 return -EINVAL;
2082
2083 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2084 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2085 if (type > NL80211_IFTYPE_MAX)
2086 return -EINVAL;
2087 }
2088
79c97e97 2089 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2090 !(rdev->wiphy.interface_modes & (1 << type)))
2091 return -EOPNOTSUPP;
55682965 2092
1c18f145
AS
2093 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2094 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2095 ETH_ALEN);
2096 if (!is_valid_ether_addr(params.macaddr))
2097 return -EADDRNOTAVAIL;
2098 }
2099
9bc383de 2100 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2101 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2102 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2103 if (err)
4c476991 2104 return err;
9bc383de 2105 }
8b787643 2106
1c90f9d4
JB
2107 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2108 if (!msg)
2109 return -ENOMEM;
2110
66f7ac50
MW
2111 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2112 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2113 &flags);
e35e4d28
HG
2114 wdev = rdev_add_virtual_intf(rdev,
2115 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2116 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2117 if (IS_ERR(wdev)) {
2118 nlmsg_free(msg);
84efbb84 2119 return PTR_ERR(wdev);
1c90f9d4 2120 }
2ec600d6 2121
98104fde
JB
2122 switch (type) {
2123 case NL80211_IFTYPE_MESH_POINT:
2124 if (!info->attrs[NL80211_ATTR_MESH_ID])
2125 break;
29cbe68c
JB
2126 wdev_lock(wdev);
2127 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2128 IEEE80211_MAX_MESH_ID_LEN);
2129 wdev->mesh_id_up_len =
2130 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2131 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2132 wdev->mesh_id_up_len);
2133 wdev_unlock(wdev);
98104fde
JB
2134 break;
2135 case NL80211_IFTYPE_P2P_DEVICE:
2136 /*
2137 * P2P Device doesn't have a netdev, so doesn't go
2138 * through the netdev notifier and must be added here
2139 */
2140 mutex_init(&wdev->mtx);
2141 INIT_LIST_HEAD(&wdev->event_list);
2142 spin_lock_init(&wdev->event_lock);
2143 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2144 spin_lock_init(&wdev->mgmt_registrations_lock);
2145
2146 mutex_lock(&rdev->devlist_mtx);
2147 wdev->identifier = ++rdev->wdev_id;
2148 list_add_rcu(&wdev->list, &rdev->wdev_list);
2149 rdev->devlist_generation++;
2150 mutex_unlock(&rdev->devlist_mtx);
2151 break;
2152 default:
2153 break;
29cbe68c
JB
2154 }
2155
15e47304 2156 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2157 rdev, wdev) < 0) {
2158 nlmsg_free(msg);
2159 return -ENOBUFS;
2160 }
2161
2162 return genlmsg_reply(msg, info);
55682965
JB
2163}
2164
2165static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2166{
4c476991 2167 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2168 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2169
4c476991
JB
2170 if (!rdev->ops->del_virtual_intf)
2171 return -EOPNOTSUPP;
55682965 2172
84efbb84
JB
2173 /*
2174 * If we remove a wireless device without a netdev then clear
2175 * user_ptr[1] so that nl80211_post_doit won't dereference it
2176 * to check if it needs to do dev_put(). Otherwise it crashes
2177 * since the wdev has been freed, unlike with a netdev where
2178 * we need the dev_put() for the netdev to really be freed.
2179 */
2180 if (!wdev->netdev)
2181 info->user_ptr[1] = NULL;
2182
e35e4d28 2183 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2184}
2185
1d9d9213
SW
2186static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2187{
2188 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2189 struct net_device *dev = info->user_ptr[1];
2190 u16 noack_map;
2191
2192 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2193 return -EINVAL;
2194
2195 if (!rdev->ops->set_noack_map)
2196 return -EOPNOTSUPP;
2197
2198 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2199
e35e4d28 2200 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2201}
2202
41ade00f
JB
2203struct get_key_cookie {
2204 struct sk_buff *msg;
2205 int error;
b9454e83 2206 int idx;
41ade00f
JB
2207};
2208
2209static void get_key_callback(void *c, struct key_params *params)
2210{
b9454e83 2211 struct nlattr *key;
41ade00f
JB
2212 struct get_key_cookie *cookie = c;
2213
9360ffd1
DM
2214 if ((params->key &&
2215 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2216 params->key_len, params->key)) ||
2217 (params->seq &&
2218 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2219 params->seq_len, params->seq)) ||
2220 (params->cipher &&
2221 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2222 params->cipher)))
2223 goto nla_put_failure;
41ade00f 2224
b9454e83
JB
2225 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2226 if (!key)
2227 goto nla_put_failure;
2228
9360ffd1
DM
2229 if ((params->key &&
2230 nla_put(cookie->msg, NL80211_KEY_DATA,
2231 params->key_len, params->key)) ||
2232 (params->seq &&
2233 nla_put(cookie->msg, NL80211_KEY_SEQ,
2234 params->seq_len, params->seq)) ||
2235 (params->cipher &&
2236 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2237 params->cipher)))
2238 goto nla_put_failure;
b9454e83 2239
9360ffd1
DM
2240 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2241 goto nla_put_failure;
b9454e83
JB
2242
2243 nla_nest_end(cookie->msg, key);
2244
41ade00f
JB
2245 return;
2246 nla_put_failure:
2247 cookie->error = 1;
2248}
2249
2250static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2251{
4c476991 2252 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2253 int err;
4c476991 2254 struct net_device *dev = info->user_ptr[1];
41ade00f 2255 u8 key_idx = 0;
e31b8213
JB
2256 const u8 *mac_addr = NULL;
2257 bool pairwise;
41ade00f
JB
2258 struct get_key_cookie cookie = {
2259 .error = 0,
2260 };
2261 void *hdr;
2262 struct sk_buff *msg;
2263
2264 if (info->attrs[NL80211_ATTR_KEY_IDX])
2265 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2266
3cfcf6ac 2267 if (key_idx > 5)
41ade00f
JB
2268 return -EINVAL;
2269
2270 if (info->attrs[NL80211_ATTR_MAC])
2271 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2272
e31b8213
JB
2273 pairwise = !!mac_addr;
2274 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2275 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2276 if (kt >= NUM_NL80211_KEYTYPES)
2277 return -EINVAL;
2278 if (kt != NL80211_KEYTYPE_GROUP &&
2279 kt != NL80211_KEYTYPE_PAIRWISE)
2280 return -EINVAL;
2281 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2282 }
2283
4c476991
JB
2284 if (!rdev->ops->get_key)
2285 return -EOPNOTSUPP;
41ade00f 2286
fd2120ca 2287 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2288 if (!msg)
2289 return -ENOMEM;
41ade00f 2290
15e47304 2291 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2292 NL80211_CMD_NEW_KEY);
4c476991
JB
2293 if (IS_ERR(hdr))
2294 return PTR_ERR(hdr);
41ade00f
JB
2295
2296 cookie.msg = msg;
b9454e83 2297 cookie.idx = key_idx;
41ade00f 2298
9360ffd1
DM
2299 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2300 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2301 goto nla_put_failure;
2302 if (mac_addr &&
2303 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2304 goto nla_put_failure;
41ade00f 2305
e31b8213
JB
2306 if (pairwise && mac_addr &&
2307 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2308 return -ENOENT;
2309
e35e4d28
HG
2310 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2311 get_key_callback);
41ade00f
JB
2312
2313 if (err)
6c95e2a2 2314 goto free_msg;
41ade00f
JB
2315
2316 if (cookie.error)
2317 goto nla_put_failure;
2318
2319 genlmsg_end(msg, hdr);
4c476991 2320 return genlmsg_reply(msg, info);
41ade00f
JB
2321
2322 nla_put_failure:
2323 err = -ENOBUFS;
6c95e2a2 2324 free_msg:
41ade00f 2325 nlmsg_free(msg);
41ade00f
JB
2326 return err;
2327}
2328
2329static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2330{
4c476991 2331 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2332 struct key_parse key;
41ade00f 2333 int err;
4c476991 2334 struct net_device *dev = info->user_ptr[1];
41ade00f 2335
b9454e83
JB
2336 err = nl80211_parse_key(info, &key);
2337 if (err)
2338 return err;
41ade00f 2339
b9454e83 2340 if (key.idx < 0)
41ade00f
JB
2341 return -EINVAL;
2342
b9454e83
JB
2343 /* only support setting default key */
2344 if (!key.def && !key.defmgmt)
41ade00f
JB
2345 return -EINVAL;
2346
dbd2fd65 2347 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2348
dbd2fd65
JB
2349 if (key.def) {
2350 if (!rdev->ops->set_default_key) {
2351 err = -EOPNOTSUPP;
2352 goto out;
2353 }
41ade00f 2354
dbd2fd65
JB
2355 err = nl80211_key_allowed(dev->ieee80211_ptr);
2356 if (err)
2357 goto out;
2358
e35e4d28 2359 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2360 key.def_uni, key.def_multi);
2361
2362 if (err)
2363 goto out;
fffd0934 2364
3d23e349 2365#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2366 dev->ieee80211_ptr->wext.default_key = key.idx;
2367#endif
2368 } else {
2369 if (key.def_uni || !key.def_multi) {
2370 err = -EINVAL;
2371 goto out;
2372 }
2373
2374 if (!rdev->ops->set_default_mgmt_key) {
2375 err = -EOPNOTSUPP;
2376 goto out;
2377 }
2378
2379 err = nl80211_key_allowed(dev->ieee80211_ptr);
2380 if (err)
2381 goto out;
2382
e35e4d28 2383 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2384 if (err)
2385 goto out;
2386
2387#ifdef CONFIG_CFG80211_WEXT
2388 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2389#endif
dbd2fd65
JB
2390 }
2391
2392 out:
fffd0934 2393 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2394
41ade00f
JB
2395 return err;
2396}
2397
2398static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2399{
4c476991 2400 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2401 int err;
4c476991 2402 struct net_device *dev = info->user_ptr[1];
b9454e83 2403 struct key_parse key;
e31b8213 2404 const u8 *mac_addr = NULL;
41ade00f 2405
b9454e83
JB
2406 err = nl80211_parse_key(info, &key);
2407 if (err)
2408 return err;
41ade00f 2409
b9454e83 2410 if (!key.p.key)
41ade00f
JB
2411 return -EINVAL;
2412
41ade00f
JB
2413 if (info->attrs[NL80211_ATTR_MAC])
2414 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2415
e31b8213
JB
2416 if (key.type == -1) {
2417 if (mac_addr)
2418 key.type = NL80211_KEYTYPE_PAIRWISE;
2419 else
2420 key.type = NL80211_KEYTYPE_GROUP;
2421 }
2422
2423 /* for now */
2424 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2425 key.type != NL80211_KEYTYPE_GROUP)
2426 return -EINVAL;
2427
4c476991
JB
2428 if (!rdev->ops->add_key)
2429 return -EOPNOTSUPP;
25e47c18 2430
e31b8213
JB
2431 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2432 key.type == NL80211_KEYTYPE_PAIRWISE,
2433 mac_addr))
4c476991 2434 return -EINVAL;
41ade00f 2435
fffd0934
JB
2436 wdev_lock(dev->ieee80211_ptr);
2437 err = nl80211_key_allowed(dev->ieee80211_ptr);
2438 if (!err)
e35e4d28
HG
2439 err = rdev_add_key(rdev, dev, key.idx,
2440 key.type == NL80211_KEYTYPE_PAIRWISE,
2441 mac_addr, &key.p);
fffd0934 2442 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2443
41ade00f
JB
2444 return err;
2445}
2446
2447static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2448{
4c476991 2449 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2450 int err;
4c476991 2451 struct net_device *dev = info->user_ptr[1];
41ade00f 2452 u8 *mac_addr = NULL;
b9454e83 2453 struct key_parse key;
41ade00f 2454
b9454e83
JB
2455 err = nl80211_parse_key(info, &key);
2456 if (err)
2457 return err;
41ade00f
JB
2458
2459 if (info->attrs[NL80211_ATTR_MAC])
2460 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2461
e31b8213
JB
2462 if (key.type == -1) {
2463 if (mac_addr)
2464 key.type = NL80211_KEYTYPE_PAIRWISE;
2465 else
2466 key.type = NL80211_KEYTYPE_GROUP;
2467 }
2468
2469 /* for now */
2470 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2471 key.type != NL80211_KEYTYPE_GROUP)
2472 return -EINVAL;
2473
4c476991
JB
2474 if (!rdev->ops->del_key)
2475 return -EOPNOTSUPP;
41ade00f 2476
fffd0934
JB
2477 wdev_lock(dev->ieee80211_ptr);
2478 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2479
2480 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2481 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2482 err = -ENOENT;
2483
fffd0934 2484 if (!err)
e35e4d28
HG
2485 err = rdev_del_key(rdev, dev, key.idx,
2486 key.type == NL80211_KEYTYPE_PAIRWISE,
2487 mac_addr);
41ade00f 2488
3d23e349 2489#ifdef CONFIG_CFG80211_WEXT
08645126 2490 if (!err) {
b9454e83 2491 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2492 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2493 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2494 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2495 }
2496#endif
fffd0934 2497 wdev_unlock(dev->ieee80211_ptr);
08645126 2498
41ade00f
JB
2499 return err;
2500}
2501
77765eaf
VT
2502/* This function returns an error or the number of nested attributes */
2503static int validate_acl_mac_addrs(struct nlattr *nl_attr)
2504{
2505 struct nlattr *attr;
2506 int n_entries = 0, tmp;
2507
2508 nla_for_each_nested(attr, nl_attr, tmp) {
2509 if (nla_len(attr) != ETH_ALEN)
2510 return -EINVAL;
2511
2512 n_entries++;
2513 }
2514
2515 return n_entries;
2516}
2517
2518/*
2519 * This function parses ACL information and allocates memory for ACL data.
2520 * On successful return, the calling function is responsible to free the
2521 * ACL buffer returned by this function.
2522 */
2523static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
2524 struct genl_info *info)
2525{
2526 enum nl80211_acl_policy acl_policy;
2527 struct nlattr *attr;
2528 struct cfg80211_acl_data *acl;
2529 int i = 0, n_entries, tmp;
2530
2531 if (!wiphy->max_acl_mac_addrs)
2532 return ERR_PTR(-EOPNOTSUPP);
2533
2534 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
2535 return ERR_PTR(-EINVAL);
2536
2537 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
2538 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
2539 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
2540 return ERR_PTR(-EINVAL);
2541
2542 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
2543 return ERR_PTR(-EINVAL);
2544
2545 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
2546 if (n_entries < 0)
2547 return ERR_PTR(n_entries);
2548
2549 if (n_entries > wiphy->max_acl_mac_addrs)
2550 return ERR_PTR(-ENOTSUPP);
2551
2552 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
2553 GFP_KERNEL);
2554 if (!acl)
2555 return ERR_PTR(-ENOMEM);
2556
2557 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
2558 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
2559 i++;
2560 }
2561
2562 acl->n_acl_entries = n_entries;
2563 acl->acl_policy = acl_policy;
2564
2565 return acl;
2566}
2567
2568static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
2569{
2570 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2571 struct net_device *dev = info->user_ptr[1];
2572 struct cfg80211_acl_data *acl;
2573 int err;
2574
2575 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2576 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2577 return -EOPNOTSUPP;
2578
2579 if (!dev->ieee80211_ptr->beacon_interval)
2580 return -EINVAL;
2581
2582 acl = parse_acl_data(&rdev->wiphy, info);
2583 if (IS_ERR(acl))
2584 return PTR_ERR(acl);
2585
2586 err = rdev_set_mac_acl(rdev, dev, acl);
2587
2588 kfree(acl);
2589
2590 return err;
2591}
2592
8860020e
JB
2593static int nl80211_parse_beacon(struct genl_info *info,
2594 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2595{
8860020e 2596 bool haveinfo = false;
ed1b6cc7 2597
9946ecfb
JM
2598 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2599 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2600 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2601 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2602 return -EINVAL;
2603
8860020e 2604 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2605
ed1b6cc7 2606 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2607 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2608 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2609 if (!bcn->head_len)
2610 return -EINVAL;
2611 haveinfo = true;
ed1b6cc7
JB
2612 }
2613
2614 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2615 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2616 bcn->tail_len =
ed1b6cc7 2617 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2618 haveinfo = true;
ed1b6cc7
JB
2619 }
2620
4c476991
JB
2621 if (!haveinfo)
2622 return -EINVAL;
3b85875a 2623
9946ecfb 2624 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2625 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2626 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2627 }
2628
2629 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2630 bcn->proberesp_ies =
9946ecfb 2631 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2632 bcn->proberesp_ies_len =
9946ecfb
JM
2633 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2634 }
2635
2636 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2637 bcn->assocresp_ies =
9946ecfb 2638 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2639 bcn->assocresp_ies_len =
9946ecfb
JM
2640 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2641 }
2642
00f740e1 2643 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2644 bcn->probe_resp =
00f740e1 2645 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2646 bcn->probe_resp_len =
00f740e1
AN
2647 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2648 }
2649
8860020e
JB
2650 return 0;
2651}
2652
46c1dd0c
FF
2653static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2654 struct cfg80211_ap_settings *params)
2655{
2656 struct wireless_dev *wdev;
2657 bool ret = false;
2658
2659 mutex_lock(&rdev->devlist_mtx);
2660
89a54e48 2661 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2662 if (wdev->iftype != NL80211_IFTYPE_AP &&
2663 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2664 continue;
2665
683b6d3b 2666 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
2667 continue;
2668
683b6d3b 2669 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
2670 ret = true;
2671 break;
2672 }
2673
2674 mutex_unlock(&rdev->devlist_mtx);
2675
2676 return ret;
2677}
2678
e39e5b5e
JM
2679static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
2680 enum nl80211_auth_type auth_type,
2681 enum nl80211_commands cmd)
2682{
2683 if (auth_type > NL80211_AUTHTYPE_MAX)
2684 return false;
2685
2686 switch (cmd) {
2687 case NL80211_CMD_AUTHENTICATE:
2688 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
2689 auth_type == NL80211_AUTHTYPE_SAE)
2690 return false;
2691 return true;
2692 case NL80211_CMD_CONNECT:
2693 case NL80211_CMD_START_AP:
2694 /* SAE not supported yet */
2695 if (auth_type == NL80211_AUTHTYPE_SAE)
2696 return false;
2697 return true;
2698 default:
2699 return false;
2700 }
2701}
2702
8860020e
JB
2703static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2704{
2705 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2706 struct net_device *dev = info->user_ptr[1];
2707 struct wireless_dev *wdev = dev->ieee80211_ptr;
2708 struct cfg80211_ap_settings params;
2709 int err;
2710
2711 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2712 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2713 return -EOPNOTSUPP;
2714
2715 if (!rdev->ops->start_ap)
2716 return -EOPNOTSUPP;
2717
2718 if (wdev->beacon_interval)
2719 return -EALREADY;
2720
2721 memset(&params, 0, sizeof(params));
2722
2723 /* these are required for START_AP */
2724 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2725 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2726 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2727 return -EINVAL;
2728
2729 err = nl80211_parse_beacon(info, &params.beacon);
2730 if (err)
2731 return err;
2732
2733 params.beacon_interval =
2734 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2735 params.dtim_period =
2736 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2737
2738 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2739 if (err)
2740 return err;
2741
2742 /*
2743 * In theory, some of these attributes should be required here
2744 * but since they were not used when the command was originally
2745 * added, keep them optional for old user space programs to let
2746 * them continue to work with drivers that do not need the
2747 * additional information -- drivers must check!
2748 */
2749 if (info->attrs[NL80211_ATTR_SSID]) {
2750 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2751 params.ssid_len =
2752 nla_len(info->attrs[NL80211_ATTR_SSID]);
2753 if (params.ssid_len == 0 ||
2754 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2755 return -EINVAL;
2756 }
2757
2758 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2759 params.hidden_ssid = nla_get_u32(
2760 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2761 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2762 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2763 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2764 return -EINVAL;
2765 }
2766
2767 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2768
2769 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2770 params.auth_type = nla_get_u32(
2771 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
2772 if (!nl80211_valid_auth_type(rdev, params.auth_type,
2773 NL80211_CMD_START_AP))
8860020e
JB
2774 return -EINVAL;
2775 } else
2776 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2777
2778 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2779 NL80211_MAX_NR_CIPHER_SUITES);
2780 if (err)
2781 return err;
2782
1b658f11
VT
2783 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2784 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2785 return -EOPNOTSUPP;
2786 params.inactivity_timeout = nla_get_u16(
2787 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2788 }
2789
53cabad7
JB
2790 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
2791 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2792 return -EINVAL;
2793 params.p2p_ctwindow =
2794 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
2795 if (params.p2p_ctwindow > 127)
2796 return -EINVAL;
2797 if (params.p2p_ctwindow != 0 &&
2798 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
2799 return -EINVAL;
2800 }
2801
2802 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
2803 u8 tmp;
2804
2805 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2806 return -EINVAL;
2807 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
2808 if (tmp > 1)
2809 return -EINVAL;
2810 params.p2p_opp_ps = tmp;
2811 if (params.p2p_opp_ps != 0 &&
2812 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
2813 return -EINVAL;
2814 }
2815
aa430da4 2816 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
2817 err = nl80211_parse_chandef(rdev, info, &params.chandef);
2818 if (err)
2819 return err;
2820 } else if (wdev->preset_chandef.chan) {
2821 params.chandef = wdev->preset_chandef;
46c1dd0c 2822 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
2823 return -EINVAL;
2824
683b6d3b 2825 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
2826 return -EINVAL;
2827
e4e32459 2828 mutex_lock(&rdev->devlist_mtx);
683b6d3b 2829 err = cfg80211_can_use_chan(rdev, wdev, params.chandef.chan,
e4e32459
MK
2830 CHAN_MODE_SHARED);
2831 mutex_unlock(&rdev->devlist_mtx);
2832
2833 if (err)
2834 return err;
2835
77765eaf
VT
2836 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
2837 params.acl = parse_acl_data(&rdev->wiphy, info);
2838 if (IS_ERR(params.acl))
2839 return PTR_ERR(params.acl);
2840 }
2841
e35e4d28 2842 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 2843 if (!err) {
683b6d3b 2844 wdev->preset_chandef = params.chandef;
8860020e 2845 wdev->beacon_interval = params.beacon_interval;
683b6d3b 2846 wdev->channel = params.chandef.chan;
06e191e2
AQ
2847 wdev->ssid_len = params.ssid_len;
2848 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 2849 }
77765eaf
VT
2850
2851 kfree(params.acl);
2852
56d1893d 2853 return err;
ed1b6cc7
JB
2854}
2855
8860020e
JB
2856static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2857{
2858 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2859 struct net_device *dev = info->user_ptr[1];
2860 struct wireless_dev *wdev = dev->ieee80211_ptr;
2861 struct cfg80211_beacon_data params;
2862 int err;
2863
2864 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2865 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2866 return -EOPNOTSUPP;
2867
2868 if (!rdev->ops->change_beacon)
2869 return -EOPNOTSUPP;
2870
2871 if (!wdev->beacon_interval)
2872 return -EINVAL;
2873
2874 err = nl80211_parse_beacon(info, &params);
2875 if (err)
2876 return err;
2877
e35e4d28 2878 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
2879}
2880
2881static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2882{
4c476991
JB
2883 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2884 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 2885
60771780 2886 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
2887}
2888
5727ef1b
JB
2889static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2890 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2891 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2892 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2893 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2894 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2895 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2896};
2897
eccb8e8f 2898static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2899 enum nl80211_iftype iftype,
eccb8e8f 2900 struct station_parameters *params)
5727ef1b
JB
2901{
2902 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2903 struct nlattr *nla;
5727ef1b
JB
2904 int flag;
2905
eccb8e8f
JB
2906 /*
2907 * Try parsing the new attribute first so userspace
2908 * can specify both for older kernels.
2909 */
2910 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2911 if (nla) {
2912 struct nl80211_sta_flag_update *sta_flags;
2913
2914 sta_flags = nla_data(nla);
2915 params->sta_flags_mask = sta_flags->mask;
2916 params->sta_flags_set = sta_flags->set;
2917 if ((params->sta_flags_mask |
2918 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2919 return -EINVAL;
2920 return 0;
2921 }
2922
2923 /* if present, parse the old attribute */
5727ef1b 2924
eccb8e8f 2925 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2926 if (!nla)
2927 return 0;
2928
2929 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2930 nla, sta_flags_policy))
2931 return -EINVAL;
2932
bdd3ae3d
JB
2933 /*
2934 * Only allow certain flags for interface types so that
2935 * other attributes are silently ignored. Remember that
2936 * this is backward compatibility code with old userspace
2937 * and shouldn't be hit in other cases anyway.
2938 */
2939 switch (iftype) {
2940 case NL80211_IFTYPE_AP:
2941 case NL80211_IFTYPE_AP_VLAN:
2942 case NL80211_IFTYPE_P2P_GO:
2943 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2944 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2945 BIT(NL80211_STA_FLAG_WME) |
2946 BIT(NL80211_STA_FLAG_MFP);
2947 break;
2948 case NL80211_IFTYPE_P2P_CLIENT:
2949 case NL80211_IFTYPE_STATION:
2950 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2951 BIT(NL80211_STA_FLAG_TDLS_PEER);
2952 break;
2953 case NL80211_IFTYPE_MESH_POINT:
2954 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2955 BIT(NL80211_STA_FLAG_MFP) |
2956 BIT(NL80211_STA_FLAG_AUTHORIZED);
2957 default:
2958 return -EINVAL;
2959 }
5727ef1b 2960
3383b5a6
JB
2961 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2962 if (flags[flag]) {
eccb8e8f 2963 params->sta_flags_set |= (1<<flag);
5727ef1b 2964
3383b5a6
JB
2965 /* no longer support new API additions in old API */
2966 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2967 return -EINVAL;
2968 }
2969 }
2970
5727ef1b
JB
2971 return 0;
2972}
2973
c8dcfd8a
FF
2974static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2975 int attr)
2976{
2977 struct nlattr *rate;
8eb41c8d
VK
2978 u32 bitrate;
2979 u16 bitrate_compat;
c8dcfd8a
FF
2980
2981 rate = nla_nest_start(msg, attr);
2982 if (!rate)
db9c64cf 2983 return false;
c8dcfd8a
FF
2984
2985 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2986 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
2987 /* report 16-bit bitrate only if we can */
2988 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
2989 if (bitrate > 0 &&
2990 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
2991 return false;
2992 if (bitrate_compat > 0 &&
2993 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
2994 return false;
2995
2996 if (info->flags & RATE_INFO_FLAGS_MCS) {
2997 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
2998 return false;
2999 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3000 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3001 return false;
3002 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3003 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3004 return false;
3005 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3006 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3007 return false;
3008 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3009 return false;
3010 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3011 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3012 return false;
3013 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
3014 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
3015 return false;
3016 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
3017 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
3018 return false;
3019 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
3020 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
3021 return false;
3022 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3023 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3024 return false;
3025 }
c8dcfd8a
FF
3026
3027 nla_nest_end(msg, rate);
3028 return true;
c8dcfd8a
FF
3029}
3030
15e47304 3031static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
3032 int flags,
3033 struct cfg80211_registered_device *rdev,
3034 struct net_device *dev,
98b62183 3035 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3036{
3037 void *hdr;
f4263c98 3038 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3039
15e47304 3040 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
3041 if (!hdr)
3042 return -1;
3043
9360ffd1
DM
3044 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3045 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3046 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3047 goto nla_put_failure;
f5ea9120 3048
2ec600d6
LCC
3049 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3050 if (!sinfoattr)
fd5b74dc 3051 goto nla_put_failure;
9360ffd1
DM
3052 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
3053 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
3054 sinfo->connected_time))
3055 goto nla_put_failure;
3056 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
3057 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
3058 sinfo->inactive_time))
3059 goto nla_put_failure;
42745e03
VK
3060 if ((sinfo->filled & (STATION_INFO_RX_BYTES |
3061 STATION_INFO_RX_BYTES64)) &&
9360ffd1 3062 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 3063 (u32)sinfo->rx_bytes))
9360ffd1 3064 goto nla_put_failure;
42745e03
VK
3065 if ((sinfo->filled & (STATION_INFO_TX_BYTES |
3066 NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 3067 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
3068 (u32)sinfo->tx_bytes))
3069 goto nla_put_failure;
3070 if ((sinfo->filled & STATION_INFO_RX_BYTES64) &&
3071 nla_put_u64(msg, NL80211_STA_INFO_RX_BYTES64,
3072 sinfo->rx_bytes))
3073 goto nla_put_failure;
3074 if ((sinfo->filled & STATION_INFO_TX_BYTES64) &&
3075 nla_put_u64(msg, NL80211_STA_INFO_TX_BYTES64,
9360ffd1
DM
3076 sinfo->tx_bytes))
3077 goto nla_put_failure;
3078 if ((sinfo->filled & STATION_INFO_LLID) &&
3079 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
3080 goto nla_put_failure;
3081 if ((sinfo->filled & STATION_INFO_PLID) &&
3082 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
3083 goto nla_put_failure;
3084 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
3085 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
3086 sinfo->plink_state))
3087 goto nla_put_failure;
66266b3a
JL
3088 switch (rdev->wiphy.signal_type) {
3089 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
3090 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
3091 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
3092 sinfo->signal))
3093 goto nla_put_failure;
3094 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
3095 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
3096 sinfo->signal_avg))
3097 goto nla_put_failure;
66266b3a
JL
3098 break;
3099 default:
3100 break;
3101 }
420e7fab 3102 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3103 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3104 NL80211_STA_INFO_TX_BITRATE))
3105 goto nla_put_failure;
3106 }
3107 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3108 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3109 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3110 goto nla_put_failure;
420e7fab 3111 }
9360ffd1
DM
3112 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3113 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3114 sinfo->rx_packets))
3115 goto nla_put_failure;
3116 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3117 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3118 sinfo->tx_packets))
3119 goto nla_put_failure;
3120 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3121 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3122 sinfo->tx_retries))
3123 goto nla_put_failure;
3124 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3125 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3126 sinfo->tx_failed))
3127 goto nla_put_failure;
3128 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3129 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3130 sinfo->beacon_loss_count))
3131 goto nla_put_failure;
3b1c5a53
MP
3132 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3133 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3134 sinfo->local_pm))
3135 goto nla_put_failure;
3136 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3137 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3138 sinfo->peer_pm))
3139 goto nla_put_failure;
3140 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3141 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3142 sinfo->nonpeer_pm))
3143 goto nla_put_failure;
f4263c98
PS
3144 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3145 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3146 if (!bss_param)
3147 goto nla_put_failure;
3148
9360ffd1
DM
3149 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3150 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3151 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3152 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3153 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3154 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3155 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3156 sinfo->bss_param.dtim_period) ||
3157 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3158 sinfo->bss_param.beacon_interval))
3159 goto nla_put_failure;
f4263c98
PS
3160
3161 nla_nest_end(msg, bss_param);
3162 }
9360ffd1
DM
3163 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3164 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3165 sizeof(struct nl80211_sta_flag_update),
3166 &sinfo->sta_flags))
3167 goto nla_put_failure;
7eab0f64
JL
3168 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3169 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3170 sinfo->t_offset))
3171 goto nla_put_failure;
2ec600d6 3172 nla_nest_end(msg, sinfoattr);
fd5b74dc 3173
9360ffd1
DM
3174 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3175 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3176 sinfo->assoc_req_ies))
3177 goto nla_put_failure;
50d3dfb7 3178
fd5b74dc
JB
3179 return genlmsg_end(msg, hdr);
3180
3181 nla_put_failure:
bc3ed28c
TG
3182 genlmsg_cancel(msg, hdr);
3183 return -EMSGSIZE;
fd5b74dc
JB
3184}
3185
2ec600d6 3186static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3187 struct netlink_callback *cb)
2ec600d6 3188{
2ec600d6
LCC
3189 struct station_info sinfo;
3190 struct cfg80211_registered_device *dev;
bba95fef 3191 struct net_device *netdev;
2ec600d6 3192 u8 mac_addr[ETH_ALEN];
bba95fef 3193 int sta_idx = cb->args[1];
2ec600d6 3194 int err;
2ec600d6 3195
67748893
JB
3196 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3197 if (err)
3198 return err;
bba95fef
JB
3199
3200 if (!dev->ops->dump_station) {
eec60b03 3201 err = -EOPNOTSUPP;
bba95fef
JB
3202 goto out_err;
3203 }
3204
bba95fef 3205 while (1) {
f612cedf 3206 memset(&sinfo, 0, sizeof(sinfo));
e35e4d28
HG
3207 err = rdev_dump_station(dev, netdev, sta_idx,
3208 mac_addr, &sinfo);
bba95fef
JB
3209 if (err == -ENOENT)
3210 break;
3211 if (err)
3b85875a 3212 goto out_err;
bba95fef
JB
3213
3214 if (nl80211_send_station(skb,
15e47304 3215 NETLINK_CB(cb->skb).portid,
bba95fef 3216 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 3217 dev, netdev, mac_addr,
bba95fef
JB
3218 &sinfo) < 0)
3219 goto out;
3220
3221 sta_idx++;
3222 }
3223
3224
3225 out:
3226 cb->args[1] = sta_idx;
3227 err = skb->len;
bba95fef 3228 out_err:
67748893 3229 nl80211_finish_netdev_dump(dev);
bba95fef
JB
3230
3231 return err;
2ec600d6 3232}
fd5b74dc 3233
5727ef1b
JB
3234static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3235{
4c476991
JB
3236 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3237 struct net_device *dev = info->user_ptr[1];
2ec600d6 3238 struct station_info sinfo;
fd5b74dc
JB
3239 struct sk_buff *msg;
3240 u8 *mac_addr = NULL;
4c476991 3241 int err;
fd5b74dc 3242
2ec600d6 3243 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3244
3245 if (!info->attrs[NL80211_ATTR_MAC])
3246 return -EINVAL;
3247
3248 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3249
4c476991
JB
3250 if (!rdev->ops->get_station)
3251 return -EOPNOTSUPP;
3b85875a 3252
e35e4d28 3253 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3254 if (err)
4c476991 3255 return err;
2ec600d6 3256
fd2120ca 3257 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3258 if (!msg)
4c476991 3259 return -ENOMEM;
fd5b74dc 3260
15e47304 3261 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3262 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3263 nlmsg_free(msg);
3264 return -ENOBUFS;
3265 }
3b85875a 3266
4c476991 3267 return genlmsg_reply(msg, info);
5727ef1b
JB
3268}
3269
3270/*
c258d2de 3271 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3272 */
80b99899
JB
3273static struct net_device *get_vlan(struct genl_info *info,
3274 struct cfg80211_registered_device *rdev)
5727ef1b 3275{
463d0183 3276 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3277 struct net_device *v;
3278 int ret;
3279
3280 if (!vlanattr)
3281 return NULL;
3282
3283 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3284 if (!v)
3285 return ERR_PTR(-ENODEV);
3286
3287 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3288 ret = -EINVAL;
3289 goto error;
5727ef1b 3290 }
80b99899
JB
3291
3292 if (!netif_running(v)) {
3293 ret = -ENETDOWN;
3294 goto error;
3295 }
3296
3297 return v;
3298 error:
3299 dev_put(v);
3300 return ERR_PTR(ret);
5727ef1b
JB
3301}
3302
3303static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3304{
4c476991 3305 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3306 int err;
4c476991 3307 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3308 struct station_parameters params;
3309 u8 *mac_addr = NULL;
3310
3311 memset(&params, 0, sizeof(params));
3312
3313 params.listen_interval = -1;
57cf8043 3314 params.plink_state = -1;
5727ef1b
JB
3315
3316 if (info->attrs[NL80211_ATTR_STA_AID])
3317 return -EINVAL;
3318
3319 if (!info->attrs[NL80211_ATTR_MAC])
3320 return -EINVAL;
3321
3322 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3323
3324 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3325 params.supported_rates =
3326 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3327 params.supported_rates_len =
3328 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3329 }
3330
ba23d206
JB
3331 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL] ||
3332 info->attrs[NL80211_ATTR_HT_CAPABILITY])
3333 return -EINVAL;
36aedc90 3334
bdd90d5e
JB
3335 if (!rdev->ops->change_station)
3336 return -EOPNOTSUPP;
3337
bdd3ae3d 3338 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3339 return -EINVAL;
3340
2ec600d6
LCC
3341 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3342 params.plink_action =
3343 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3344
9c3990aa
JC
3345 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
3346 params.plink_state =
3347 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3348
3b1c5a53
MP
3349 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
3350 enum nl80211_mesh_power_mode pm = nla_get_u32(
3351 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
3352
3353 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
3354 pm > NL80211_MESH_POWER_MAX)
3355 return -EINVAL;
3356
3357 params.local_pm = pm;
3358 }
3359
a97f4424
JB
3360 switch (dev->ieee80211_ptr->iftype) {
3361 case NL80211_IFTYPE_AP:
3362 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3363 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
3364 /* disallow mesh-specific things */
3365 if (params.plink_action)
bdd90d5e 3366 return -EINVAL;
3b1c5a53
MP
3367 if (params.local_pm)
3368 return -EINVAL;
bdd90d5e
JB
3369
3370 /* TDLS can't be set, ... */
3371 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3372 return -EINVAL;
3373 /*
3374 * ... but don't bother the driver with it. This works around
3375 * a hostapd/wpa_supplicant issue -- it always includes the
3376 * TLDS_PEER flag in the mask even for AP mode.
3377 */
3378 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3379
3380 /* accept only the listed bits */
3381 if (params.sta_flags_mask &
3382 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
d582cffb
JB
3383 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3384 BIT(NL80211_STA_FLAG_ASSOCIATED) |
bdd90d5e
JB
3385 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3386 BIT(NL80211_STA_FLAG_WME) |
3387 BIT(NL80211_STA_FLAG_MFP)))
3388 return -EINVAL;
3389
d582cffb
JB
3390 /* but authenticated/associated only if driver handles it */
3391 if (!(rdev->wiphy.features &
3392 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3393 params.sta_flags_mask &
3394 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3395 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3396 return -EINVAL;
3397
ba23d206
JB
3398 /* reject other things that can't change */
3399 if (params.supported_rates)
3400 return -EINVAL;
3401
bdd90d5e
JB
3402 /* must be last in here for error handling */
3403 params.vlan = get_vlan(info, rdev);
3404 if (IS_ERR(params.vlan))
3405 return PTR_ERR(params.vlan);
a97f4424 3406 break;
074ac8df 3407 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3408 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
3409 /*
3410 * Don't allow userspace to change the TDLS_PEER flag,
3411 * but silently ignore attempts to change it since we
3412 * don't have state here to verify that it doesn't try
3413 * to change the flag.
3414 */
3415 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
3416 /* fall through */
3417 case NL80211_IFTYPE_ADHOC:
3418 /* disallow things sta doesn't support */
3419 if (params.plink_action)
3420 return -EINVAL;
3b1c5a53
MP
3421 if (params.local_pm)
3422 return -EINVAL;
bdd90d5e
JB
3423 /* reject any changes other than AUTHORIZED */
3424 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3425 return -EINVAL;
a97f4424
JB
3426 break;
3427 case NL80211_IFTYPE_MESH_POINT:
3428 /* disallow things mesh doesn't support */
3429 if (params.vlan)
bdd90d5e 3430 return -EINVAL;
ba23d206 3431 if (params.supported_rates)
bdd90d5e
JB
3432 return -EINVAL;
3433 /*
3434 * No special handling for TDLS here -- the userspace
3435 * mesh code doesn't have this bug.
3436 */
b39c48fa
JC
3437 if (params.sta_flags_mask &
3438 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 3439 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 3440 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 3441 return -EINVAL;
a97f4424
JB
3442 break;
3443 default:
bdd90d5e 3444 return -EOPNOTSUPP;
034d655e
JB
3445 }
3446
bdd90d5e 3447 /* be aware of params.vlan when changing code here */
5727ef1b 3448
e35e4d28 3449 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 3450
5727ef1b
JB
3451 if (params.vlan)
3452 dev_put(params.vlan);
3b85875a 3453
5727ef1b
JB
3454 return err;
3455}
3456
c75786c9
EP
3457static struct nla_policy
3458nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3459 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3460 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3461};
3462
5727ef1b
JB
3463static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3464{
4c476991 3465 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3466 int err;
4c476991 3467 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3468 struct station_parameters params;
3469 u8 *mac_addr = NULL;
3470
3471 memset(&params, 0, sizeof(params));
3472
3473 if (!info->attrs[NL80211_ATTR_MAC])
3474 return -EINVAL;
3475
5727ef1b
JB
3476 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3477 return -EINVAL;
3478
3479 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3480 return -EINVAL;
3481
0e956c13
TLSC
3482 if (!info->attrs[NL80211_ATTR_STA_AID])
3483 return -EINVAL;
3484
5727ef1b
JB
3485 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3486 params.supported_rates =
3487 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3488 params.supported_rates_len =
3489 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3490 params.listen_interval =
3491 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3492
0e956c13
TLSC
3493 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
3494 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3495 return -EINVAL;
51b50fbe 3496
36aedc90
JM
3497 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3498 params.ht_capa =
3499 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 3500
f461be3e
MP
3501 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3502 params.vht_capa =
3503 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3504
96b78dff
JC
3505 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3506 params.plink_action =
3507 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3508
bdd90d5e
JB
3509 if (!rdev->ops->add_station)
3510 return -EOPNOTSUPP;
3511
bdd3ae3d 3512 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3513 return -EINVAL;
3514
bdd90d5e
JB
3515 switch (dev->ieee80211_ptr->iftype) {
3516 case NL80211_IFTYPE_AP:
3517 case NL80211_IFTYPE_AP_VLAN:
3518 case NL80211_IFTYPE_P2P_GO:
3519 /* parse WME attributes if sta is WME capable */
3520 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3521 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
3522 info->attrs[NL80211_ATTR_STA_WME]) {
3523 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3524 struct nlattr *nla;
3525
3526 nla = info->attrs[NL80211_ATTR_STA_WME];
3527 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3528 nl80211_sta_wme_policy);
3529 if (err)
3530 return err;
3531
3532 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3533 params.uapsd_queues =
3534 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
3535 if (params.uapsd_queues &
3536 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3537 return -EINVAL;
c75786c9 3538
bdd90d5e
JB
3539 if (tb[NL80211_STA_WME_MAX_SP])
3540 params.max_sp =
3541 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 3542
bdd90d5e
JB
3543 if (params.max_sp &
3544 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3545 return -EINVAL;
4319e193 3546
bdd90d5e
JB
3547 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3548 }
3549 /* TDLS peers cannot be added */
3550 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3551 return -EINVAL;
bdd90d5e
JB
3552 /* but don't bother the driver with it */
3553 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3554
d582cffb
JB
3555 /* allow authenticated/associated only if driver handles it */
3556 if (!(rdev->wiphy.features &
3557 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3558 params.sta_flags_mask &
3559 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3560 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3561 return -EINVAL;
3562
bdd90d5e
JB
3563 /* must be last in here for error handling */
3564 params.vlan = get_vlan(info, rdev);
3565 if (IS_ERR(params.vlan))
3566 return PTR_ERR(params.vlan);
3567 break;
3568 case NL80211_IFTYPE_MESH_POINT:
d582cffb
JB
3569 /* associated is disallowed */
3570 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3571 return -EINVAL;
bdd90d5e
JB
3572 /* TDLS peers cannot be added */
3573 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3574 return -EINVAL;
3575 break;
3576 case NL80211_IFTYPE_STATION:
d582cffb
JB
3577 /* associated is disallowed */
3578 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3579 return -EINVAL;
bdd90d5e
JB
3580 /* Only TDLS peers can be added */
3581 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3582 return -EINVAL;
3583 /* Can only add if TDLS ... */
3584 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3585 return -EOPNOTSUPP;
3586 /* ... with external setup is supported */
3587 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3588 return -EOPNOTSUPP;
3589 break;
3590 default:
3591 return -EOPNOTSUPP;
c75786c9
EP
3592 }
3593
bdd90d5e 3594 /* be aware of params.vlan when changing code here */
5727ef1b 3595
e35e4d28 3596 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 3597
5727ef1b
JB
3598 if (params.vlan)
3599 dev_put(params.vlan);
5727ef1b
JB
3600 return err;
3601}
3602
3603static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3604{
4c476991
JB
3605 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3606 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3607 u8 *mac_addr = NULL;
3608
3609 if (info->attrs[NL80211_ATTR_MAC])
3610 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3611
e80cf853 3612 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3613 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3614 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3615 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3616 return -EINVAL;
5727ef1b 3617
4c476991
JB
3618 if (!rdev->ops->del_station)
3619 return -EOPNOTSUPP;
3b85875a 3620
e35e4d28 3621 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
3622}
3623
15e47304 3624static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
3625 int flags, struct net_device *dev,
3626 u8 *dst, u8 *next_hop,
3627 struct mpath_info *pinfo)
3628{
3629 void *hdr;
3630 struct nlattr *pinfoattr;
3631
15e47304 3632 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
3633 if (!hdr)
3634 return -1;
3635
9360ffd1
DM
3636 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3637 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3638 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3639 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3640 goto nla_put_failure;
f5ea9120 3641
2ec600d6
LCC
3642 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3643 if (!pinfoattr)
3644 goto nla_put_failure;
9360ffd1
DM
3645 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3646 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3647 pinfo->frame_qlen))
3648 goto nla_put_failure;
3649 if (((pinfo->filled & MPATH_INFO_SN) &&
3650 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3651 ((pinfo->filled & MPATH_INFO_METRIC) &&
3652 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3653 pinfo->metric)) ||
3654 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3655 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3656 pinfo->exptime)) ||
3657 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3658 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3659 pinfo->flags)) ||
3660 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3661 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3662 pinfo->discovery_timeout)) ||
3663 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3664 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3665 pinfo->discovery_retries)))
3666 goto nla_put_failure;
2ec600d6
LCC
3667
3668 nla_nest_end(msg, pinfoattr);
3669
3670 return genlmsg_end(msg, hdr);
3671
3672 nla_put_failure:
bc3ed28c
TG
3673 genlmsg_cancel(msg, hdr);
3674 return -EMSGSIZE;
2ec600d6
LCC
3675}
3676
3677static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3678 struct netlink_callback *cb)
2ec600d6 3679{
2ec600d6
LCC
3680 struct mpath_info pinfo;
3681 struct cfg80211_registered_device *dev;
bba95fef 3682 struct net_device *netdev;
2ec600d6
LCC
3683 u8 dst[ETH_ALEN];
3684 u8 next_hop[ETH_ALEN];
bba95fef 3685 int path_idx = cb->args[1];
2ec600d6 3686 int err;
2ec600d6 3687
67748893
JB
3688 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3689 if (err)
3690 return err;
bba95fef
JB
3691
3692 if (!dev->ops->dump_mpath) {
eec60b03 3693 err = -EOPNOTSUPP;
bba95fef
JB
3694 goto out_err;
3695 }
3696
eec60b03
JM
3697 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3698 err = -EOPNOTSUPP;
0448b5fc 3699 goto out_err;
eec60b03
JM
3700 }
3701
bba95fef 3702 while (1) {
e35e4d28
HG
3703 err = rdev_dump_mpath(dev, netdev, path_idx, dst, next_hop,
3704 &pinfo);
bba95fef 3705 if (err == -ENOENT)
2ec600d6 3706 break;
bba95fef 3707 if (err)
3b85875a 3708 goto out_err;
2ec600d6 3709
15e47304 3710 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef
JB
3711 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3712 netdev, dst, next_hop,
3713 &pinfo) < 0)
3714 goto out;
2ec600d6 3715
bba95fef 3716 path_idx++;
2ec600d6 3717 }
2ec600d6 3718
2ec600d6 3719
bba95fef
JB
3720 out:
3721 cb->args[1] = path_idx;
3722 err = skb->len;
bba95fef 3723 out_err:
67748893 3724 nl80211_finish_netdev_dump(dev);
bba95fef 3725 return err;
2ec600d6
LCC
3726}
3727
3728static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3729{
4c476991 3730 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3731 int err;
4c476991 3732 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3733 struct mpath_info pinfo;
3734 struct sk_buff *msg;
3735 u8 *dst = NULL;
3736 u8 next_hop[ETH_ALEN];
3737
3738 memset(&pinfo, 0, sizeof(pinfo));
3739
3740 if (!info->attrs[NL80211_ATTR_MAC])
3741 return -EINVAL;
3742
3743 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3744
4c476991
JB
3745 if (!rdev->ops->get_mpath)
3746 return -EOPNOTSUPP;
2ec600d6 3747
4c476991
JB
3748 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3749 return -EOPNOTSUPP;
eec60b03 3750
e35e4d28 3751 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 3752 if (err)
4c476991 3753 return err;
2ec600d6 3754
fd2120ca 3755 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3756 if (!msg)
4c476991 3757 return -ENOMEM;
2ec600d6 3758
15e47304 3759 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
3760 dev, dst, next_hop, &pinfo) < 0) {
3761 nlmsg_free(msg);
3762 return -ENOBUFS;
3763 }
3b85875a 3764
4c476991 3765 return genlmsg_reply(msg, info);
2ec600d6
LCC
3766}
3767
3768static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3769{
4c476991
JB
3770 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3771 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3772 u8 *dst = NULL;
3773 u8 *next_hop = NULL;
3774
3775 if (!info->attrs[NL80211_ATTR_MAC])
3776 return -EINVAL;
3777
3778 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3779 return -EINVAL;
3780
3781 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3782 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3783
4c476991
JB
3784 if (!rdev->ops->change_mpath)
3785 return -EOPNOTSUPP;
35a8efe1 3786
4c476991
JB
3787 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3788 return -EOPNOTSUPP;
2ec600d6 3789
e35e4d28 3790 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 3791}
4c476991 3792
2ec600d6
LCC
3793static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3794{
4c476991
JB
3795 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3796 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3797 u8 *dst = NULL;
3798 u8 *next_hop = NULL;
3799
3800 if (!info->attrs[NL80211_ATTR_MAC])
3801 return -EINVAL;
3802
3803 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3804 return -EINVAL;
3805
3806 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3807 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3808
4c476991
JB
3809 if (!rdev->ops->add_mpath)
3810 return -EOPNOTSUPP;
35a8efe1 3811
4c476991
JB
3812 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3813 return -EOPNOTSUPP;
2ec600d6 3814
e35e4d28 3815 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
3816}
3817
3818static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3819{
4c476991
JB
3820 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3821 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3822 u8 *dst = NULL;
3823
3824 if (info->attrs[NL80211_ATTR_MAC])
3825 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3826
4c476991
JB
3827 if (!rdev->ops->del_mpath)
3828 return -EOPNOTSUPP;
3b85875a 3829
e35e4d28 3830 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
3831}
3832
9f1ba906
JM
3833static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3834{
4c476991
JB
3835 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3836 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3837 struct bss_parameters params;
3838
3839 memset(&params, 0, sizeof(params));
3840 /* default to not changing parameters */
3841 params.use_cts_prot = -1;
3842 params.use_short_preamble = -1;
3843 params.use_short_slot_time = -1;
fd8aaaf3 3844 params.ap_isolate = -1;
50b12f59 3845 params.ht_opmode = -1;
53cabad7
JB
3846 params.p2p_ctwindow = -1;
3847 params.p2p_opp_ps = -1;
9f1ba906
JM
3848
3849 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3850 params.use_cts_prot =
3851 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3852 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3853 params.use_short_preamble =
3854 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3855 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3856 params.use_short_slot_time =
3857 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3858 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3859 params.basic_rates =
3860 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3861 params.basic_rates_len =
3862 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3863 }
fd8aaaf3
FF
3864 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3865 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3866 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3867 params.ht_opmode =
3868 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3869
53cabad7
JB
3870 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3871 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3872 return -EINVAL;
3873 params.p2p_ctwindow =
3874 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3875 if (params.p2p_ctwindow < 0)
3876 return -EINVAL;
3877 if (params.p2p_ctwindow != 0 &&
3878 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3879 return -EINVAL;
3880 }
3881
3882 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3883 u8 tmp;
3884
3885 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3886 return -EINVAL;
3887 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3888 if (tmp > 1)
3889 return -EINVAL;
3890 params.p2p_opp_ps = tmp;
3891 if (params.p2p_opp_ps &&
3892 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3893 return -EINVAL;
3894 }
3895
4c476991
JB
3896 if (!rdev->ops->change_bss)
3897 return -EOPNOTSUPP;
9f1ba906 3898
074ac8df 3899 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3900 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3901 return -EOPNOTSUPP;
3b85875a 3902
e35e4d28 3903 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
3904}
3905
b54452b0 3906static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3907 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3908 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3909 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3910 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3911 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3912 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3913};
3914
3915static int parse_reg_rule(struct nlattr *tb[],
3916 struct ieee80211_reg_rule *reg_rule)
3917{
3918 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3919 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3920
3921 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3922 return -EINVAL;
3923 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3924 return -EINVAL;
3925 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3926 return -EINVAL;
3927 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3928 return -EINVAL;
3929 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3930 return -EINVAL;
3931
3932 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3933
3934 freq_range->start_freq_khz =
3935 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3936 freq_range->end_freq_khz =
3937 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3938 freq_range->max_bandwidth_khz =
3939 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3940
3941 power_rule->max_eirp =
3942 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3943
3944 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3945 power_rule->max_antenna_gain =
3946 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3947
3948 return 0;
3949}
3950
3951static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3952{
3953 int r;
3954 char *data = NULL;
57b5ce07 3955 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 3956
80778f18
LR
3957 /*
3958 * You should only get this when cfg80211 hasn't yet initialized
3959 * completely when built-in to the kernel right between the time
3960 * window between nl80211_init() and regulatory_init(), if that is
3961 * even possible.
3962 */
458f4f9e 3963 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 3964 return -EINPROGRESS;
80778f18 3965
fe33eb39
LR
3966 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3967 return -EINVAL;
b2e1b302
LR
3968
3969 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3970
57b5ce07
LR
3971 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
3972 user_reg_hint_type =
3973 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
3974 else
3975 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
3976
3977 switch (user_reg_hint_type) {
3978 case NL80211_USER_REG_HINT_USER:
3979 case NL80211_USER_REG_HINT_CELL_BASE:
3980 break;
3981 default:
3982 return -EINVAL;
3983 }
3984
3985 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 3986
b2e1b302
LR
3987 return r;
3988}
3989
24bdd9f4 3990static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3991 struct genl_info *info)
93da9cc1 3992{
4c476991 3993 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3994 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3995 struct wireless_dev *wdev = dev->ieee80211_ptr;
3996 struct mesh_config cur_params;
3997 int err = 0;
93da9cc1 3998 void *hdr;
3999 struct nlattr *pinfoattr;
4000 struct sk_buff *msg;
4001
29cbe68c
JB
4002 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4003 return -EOPNOTSUPP;
4004
24bdd9f4 4005 if (!rdev->ops->get_mesh_config)
4c476991 4006 return -EOPNOTSUPP;
f3f92586 4007
29cbe68c
JB
4008 wdev_lock(wdev);
4009 /* If not connected, get default parameters */
4010 if (!wdev->mesh_id_len)
4011 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
4012 else
e35e4d28 4013 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
4014 wdev_unlock(wdev);
4015
93da9cc1 4016 if (err)
4c476991 4017 return err;
93da9cc1 4018
4019 /* Draw up a netlink message to send back */
fd2120ca 4020 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4021 if (!msg)
4022 return -ENOMEM;
15e47304 4023 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 4024 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 4025 if (!hdr)
efe1cf0c 4026 goto out;
24bdd9f4 4027 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 4028 if (!pinfoattr)
4029 goto nla_put_failure;
9360ffd1
DM
4030 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4031 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
4032 cur_params.dot11MeshRetryTimeout) ||
4033 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4034 cur_params.dot11MeshConfirmTimeout) ||
4035 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
4036 cur_params.dot11MeshHoldingTimeout) ||
4037 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
4038 cur_params.dot11MeshMaxPeerLinks) ||
4039 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
4040 cur_params.dot11MeshMaxRetries) ||
4041 nla_put_u8(msg, NL80211_MESHCONF_TTL,
4042 cur_params.dot11MeshTTL) ||
4043 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
4044 cur_params.element_ttl) ||
4045 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4046 cur_params.auto_open_plinks) ||
7eab0f64
JL
4047 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4048 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
4049 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4050 cur_params.dot11MeshHWMPmaxPREQretries) ||
4051 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
4052 cur_params.path_refresh_time) ||
4053 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4054 cur_params.min_discovery_timeout) ||
4055 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4056 cur_params.dot11MeshHWMPactivePathTimeout) ||
4057 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4058 cur_params.dot11MeshHWMPpreqMinInterval) ||
4059 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4060 cur_params.dot11MeshHWMPperrMinInterval) ||
4061 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4062 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
4063 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
4064 cur_params.dot11MeshHWMPRootMode) ||
4065 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4066 cur_params.dot11MeshHWMPRannInterval) ||
4067 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4068 cur_params.dot11MeshGateAnnouncementProtocol) ||
4069 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
4070 cur_params.dot11MeshForwarding) ||
4071 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
4072 cur_params.rssi_threshold) ||
4073 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4074 cur_params.ht_opmode) ||
4075 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4076 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
4077 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4078 cur_params.dot11MeshHWMProotInterval) ||
4079 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
4080 cur_params.dot11MeshHWMPconfirmationInterval) ||
4081 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
4082 cur_params.power_mode) ||
4083 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
4084 cur_params.dot11MeshAwakeWindowDuration))
9360ffd1 4085 goto nla_put_failure;
93da9cc1 4086 nla_nest_end(msg, pinfoattr);
4087 genlmsg_end(msg, hdr);
4c476991 4088 return genlmsg_reply(msg, info);
93da9cc1 4089
3b85875a 4090 nla_put_failure:
93da9cc1 4091 genlmsg_cancel(msg, hdr);
efe1cf0c 4092 out:
d080e275 4093 nlmsg_free(msg);
4c476991 4094 return -ENOBUFS;
93da9cc1 4095}
4096
b54452b0 4097static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 4098 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
4099 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
4100 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
4101 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
4102 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
4103 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 4104 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 4105 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 4106 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 4107 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
4108 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
4109 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
4110 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
4111 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 4112 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 4113 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 4114 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 4115 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 4116 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 4117 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4118 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4119 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4120 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4121 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4122 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4123 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4124 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
93da9cc1 4125};
4126
c80d545d
JC
4127static const struct nla_policy
4128 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4129 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4130 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4131 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4132 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 4133 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4134 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4135 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4136};
4137
24bdd9f4 4138static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4139 struct mesh_config *cfg,
4140 u32 *mask_out)
93da9cc1 4141{
93da9cc1 4142 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4143 u32 mask = 0;
93da9cc1 4144
ea54fba2
MP
4145#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4146do { \
4147 if (tb[attr]) { \
4148 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4149 return -EINVAL; \
4150 cfg->param = fn(tb[attr]); \
4151 mask |= (1 << (attr - 1)); \
4152 } \
4153} while (0)
bd90fdcc
JB
4154
4155
24bdd9f4 4156 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4157 return -EINVAL;
4158 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4159 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4160 nl80211_meshconf_params_policy))
93da9cc1 4161 return -EINVAL;
4162
93da9cc1 4163 /* This makes sure that there aren't more than 32 mesh config
4164 * parameters (otherwise our bitfield scheme would not work.) */
4165 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4166
4167 /* Fill in the params struct */
ea54fba2 4168 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4169 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4170 nla_get_u16);
ea54fba2 4171 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4172 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4173 nla_get_u16);
ea54fba2 4174 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4175 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4176 nla_get_u16);
ea54fba2 4177 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4178 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4179 nla_get_u16);
ea54fba2 4180 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4181 mask, NL80211_MESHCONF_MAX_RETRIES,
4182 nla_get_u8);
ea54fba2 4183 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4184 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4185 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4186 mask, NL80211_MESHCONF_ELEMENT_TTL,
4187 nla_get_u8);
ea54fba2 4188 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4189 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4190 nla_get_u8);
ea54fba2
MP
4191 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4192 1, 255, mask,
a4f606ea
CYY
4193 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4194 nla_get_u32);
ea54fba2 4195 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4196 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4197 nla_get_u8);
ea54fba2 4198 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4199 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4200 nla_get_u32);
ea54fba2 4201 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4202 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4203 nla_get_u16);
ea54fba2
MP
4204 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4205 1, 65535, mask,
a4f606ea
CYY
4206 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4207 nla_get_u32);
93da9cc1 4208 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4209 1, 65535, mask,
4210 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4211 nla_get_u16);
dca7e943 4212 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4213 1, 65535, mask,
4214 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4215 nla_get_u16);
93da9cc1 4216 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4217 dot11MeshHWMPnetDiameterTraversalTime,
4218 1, 65535, mask,
a4f606ea
CYY
4219 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4220 nla_get_u16);
ea54fba2
MP
4221 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4222 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4223 nla_get_u8);
4224 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4225 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4226 nla_get_u16);
63c5723b 4227 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4228 dot11MeshGateAnnouncementProtocol, 0, 1,
4229 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4230 nla_get_u8);
ea54fba2 4231 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4232 mask, NL80211_MESHCONF_FORWARDING,
4233 nla_get_u8);
ea54fba2 4234 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, 1, 255,
a4f606ea
CYY
4235 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
4236 nla_get_u32);
ea54fba2 4237 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4238 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4239 nla_get_u16);
4240 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4241 1, 65535, mask,
ac1073a6
CYY
4242 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4243 nla_get_u32);
ea54fba2 4244 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4245 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4246 nla_get_u16);
4247 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4248 dot11MeshHWMPconfirmationInterval,
4249 1, 65535, mask,
728b19e5 4250 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4251 nla_get_u16);
3b1c5a53
MP
4252 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4253 NL80211_MESH_POWER_ACTIVE,
4254 NL80211_MESH_POWER_MAX,
4255 mask, NL80211_MESHCONF_POWER_MODE,
4256 nla_get_u32);
4257 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4258 0, 65535, mask,
4259 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
bd90fdcc
JB
4260 if (mask_out)
4261 *mask_out = mask;
c80d545d 4262
bd90fdcc
JB
4263 return 0;
4264
4265#undef FILL_IN_MESH_PARAM_IF_SET
4266}
4267
c80d545d
JC
4268static int nl80211_parse_mesh_setup(struct genl_info *info,
4269 struct mesh_setup *setup)
4270{
4271 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4272
4273 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4274 return -EINVAL;
4275 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4276 info->attrs[NL80211_ATTR_MESH_SETUP],
4277 nl80211_mesh_setup_params_policy))
4278 return -EINVAL;
4279
d299a1f2
JC
4280 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4281 setup->sync_method =
4282 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4283 IEEE80211_SYNC_METHOD_VENDOR :
4284 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4285
c80d545d
JC
4286 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4287 setup->path_sel_proto =
4288 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4289 IEEE80211_PATH_PROTOCOL_VENDOR :
4290 IEEE80211_PATH_PROTOCOL_HWMP;
4291
4292 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4293 setup->path_metric =
4294 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4295 IEEE80211_PATH_METRIC_VENDOR :
4296 IEEE80211_PATH_METRIC_AIRTIME;
4297
581a8b0f
JC
4298
4299 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4300 struct nlattr *ieattr =
581a8b0f 4301 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4302 if (!is_valid_ie_attr(ieattr))
4303 return -EINVAL;
581a8b0f
JC
4304 setup->ie = nla_data(ieattr);
4305 setup->ie_len = nla_len(ieattr);
c80d545d 4306 }
b130e5ce
JC
4307 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4308 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
4309
4310 return 0;
4311}
4312
24bdd9f4 4313static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4314 struct genl_info *info)
bd90fdcc
JB
4315{
4316 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4317 struct net_device *dev = info->user_ptr[1];
29cbe68c 4318 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4319 struct mesh_config cfg;
4320 u32 mask;
4321 int err;
4322
29cbe68c
JB
4323 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4324 return -EOPNOTSUPP;
4325
24bdd9f4 4326 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4327 return -EOPNOTSUPP;
4328
24bdd9f4 4329 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4330 if (err)
4331 return err;
4332
29cbe68c
JB
4333 wdev_lock(wdev);
4334 if (!wdev->mesh_id_len)
4335 err = -ENOLINK;
4336
4337 if (!err)
e35e4d28 4338 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4339
4340 wdev_unlock(wdev);
4341
4342 return err;
93da9cc1 4343}
4344
f130347c
LR
4345static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4346{
458f4f9e 4347 const struct ieee80211_regdomain *regdom;
f130347c
LR
4348 struct sk_buff *msg;
4349 void *hdr = NULL;
4350 struct nlattr *nl_reg_rules;
4351 unsigned int i;
4352 int err = -EINVAL;
4353
a1794390 4354 mutex_lock(&cfg80211_mutex);
f130347c
LR
4355
4356 if (!cfg80211_regdomain)
4357 goto out;
4358
fd2120ca 4359 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
4360 if (!msg) {
4361 err = -ENOBUFS;
4362 goto out;
4363 }
4364
15e47304 4365 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4366 NL80211_CMD_GET_REG);
4367 if (!hdr)
efe1cf0c 4368 goto put_failure;
f130347c 4369
57b5ce07
LR
4370 if (reg_last_request_cell_base() &&
4371 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4372 NL80211_USER_REG_HINT_CELL_BASE))
4373 goto nla_put_failure;
4374
458f4f9e
JB
4375 rcu_read_lock();
4376 regdom = rcu_dereference(cfg80211_regdomain);
4377
4378 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
4379 (regdom->dfs_region &&
4380 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
4381 goto nla_put_failure_rcu;
4382
f130347c
LR
4383 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4384 if (!nl_reg_rules)
458f4f9e 4385 goto nla_put_failure_rcu;
f130347c 4386
458f4f9e 4387 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
4388 struct nlattr *nl_reg_rule;
4389 const struct ieee80211_reg_rule *reg_rule;
4390 const struct ieee80211_freq_range *freq_range;
4391 const struct ieee80211_power_rule *power_rule;
4392
458f4f9e 4393 reg_rule = &regdom->reg_rules[i];
f130347c
LR
4394 freq_range = &reg_rule->freq_range;
4395 power_rule = &reg_rule->power_rule;
4396
4397 nl_reg_rule = nla_nest_start(msg, i);
4398 if (!nl_reg_rule)
458f4f9e 4399 goto nla_put_failure_rcu;
f130347c 4400
9360ffd1
DM
4401 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4402 reg_rule->flags) ||
4403 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4404 freq_range->start_freq_khz) ||
4405 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
4406 freq_range->end_freq_khz) ||
4407 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
4408 freq_range->max_bandwidth_khz) ||
4409 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
4410 power_rule->max_antenna_gain) ||
4411 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
4412 power_rule->max_eirp))
458f4f9e 4413 goto nla_put_failure_rcu;
f130347c
LR
4414
4415 nla_nest_end(msg, nl_reg_rule);
4416 }
458f4f9e 4417 rcu_read_unlock();
f130347c
LR
4418
4419 nla_nest_end(msg, nl_reg_rules);
4420
4421 genlmsg_end(msg, hdr);
134e6375 4422 err = genlmsg_reply(msg, info);
f130347c
LR
4423 goto out;
4424
458f4f9e
JB
4425nla_put_failure_rcu:
4426 rcu_read_unlock();
f130347c
LR
4427nla_put_failure:
4428 genlmsg_cancel(msg, hdr);
efe1cf0c 4429put_failure:
d080e275 4430 nlmsg_free(msg);
f130347c
LR
4431 err = -EMSGSIZE;
4432out:
a1794390 4433 mutex_unlock(&cfg80211_mutex);
f130347c
LR
4434 return err;
4435}
4436
b2e1b302
LR
4437static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
4438{
4439 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
4440 struct nlattr *nl_reg_rule;
4441 char *alpha2 = NULL;
4442 int rem_reg_rules = 0, r = 0;
4443 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4444 u8 dfs_region = 0;
b2e1b302
LR
4445 struct ieee80211_regdomain *rd = NULL;
4446
4447 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4448 return -EINVAL;
4449
4450 if (!info->attrs[NL80211_ATTR_REG_RULES])
4451 return -EINVAL;
4452
4453 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4454
8b60b078
LR
4455 if (info->attrs[NL80211_ATTR_DFS_REGION])
4456 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4457
b2e1b302 4458 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4459 rem_reg_rules) {
b2e1b302
LR
4460 num_rules++;
4461 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4462 return -EINVAL;
b2e1b302
LR
4463 }
4464
b2e1b302 4465 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 4466 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
4467
4468 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
4469 if (!rd)
4470 return -ENOMEM;
b2e1b302
LR
4471
4472 rd->n_reg_rules = num_rules;
4473 rd->alpha2[0] = alpha2[0];
4474 rd->alpha2[1] = alpha2[1];
4475
8b60b078
LR
4476 /*
4477 * Disable DFS master mode if the DFS region was
4478 * not supported or known on this kernel.
4479 */
4480 if (reg_supported_dfs_region(dfs_region))
4481 rd->dfs_region = dfs_region;
4482
b2e1b302 4483 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4484 rem_reg_rules) {
b2e1b302 4485 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
4486 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
4487 reg_rule_policy);
b2e1b302
LR
4488 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
4489 if (r)
4490 goto bad_reg;
4491
4492 rule_idx++;
4493
d0e18f83
LR
4494 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
4495 r = -EINVAL;
b2e1b302 4496 goto bad_reg;
d0e18f83 4497 }
b2e1b302
LR
4498 }
4499
6913b49a
JB
4500 mutex_lock(&cfg80211_mutex);
4501
b2e1b302 4502 r = set_regdom(rd);
6913b49a 4503 /* set_regdom took ownership */
1a919318 4504 rd = NULL;
6913b49a 4505 mutex_unlock(&cfg80211_mutex);
b2e1b302 4506
d2372b31 4507 bad_reg:
b2e1b302 4508 kfree(rd);
d0e18f83 4509 return r;
b2e1b302
LR
4510}
4511
83f5e2cf
JB
4512static int validate_scan_freqs(struct nlattr *freqs)
4513{
4514 struct nlattr *attr1, *attr2;
4515 int n_channels = 0, tmp1, tmp2;
4516
4517 nla_for_each_nested(attr1, freqs, tmp1) {
4518 n_channels++;
4519 /*
4520 * Some hardware has a limited channel list for
4521 * scanning, and it is pretty much nonsensical
4522 * to scan for a channel twice, so disallow that
4523 * and don't require drivers to check that the
4524 * channel list they get isn't longer than what
4525 * they can scan, as long as they can scan all
4526 * the channels they registered at once.
4527 */
4528 nla_for_each_nested(attr2, freqs, tmp2)
4529 if (attr1 != attr2 &&
4530 nla_get_u32(attr1) == nla_get_u32(attr2))
4531 return 0;
4532 }
4533
4534 return n_channels;
4535}
4536
2a519311
JB
4537static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
4538{
4c476991 4539 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 4540 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 4541 struct cfg80211_scan_request *request;
2a519311
JB
4542 struct nlattr *attr;
4543 struct wiphy *wiphy;
83f5e2cf 4544 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 4545 size_t ie_len;
2a519311 4546
f4a11bb0
JB
4547 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4548 return -EINVAL;
4549
79c97e97 4550 wiphy = &rdev->wiphy;
2a519311 4551
4c476991
JB
4552 if (!rdev->ops->scan)
4553 return -EOPNOTSUPP;
2a519311 4554
4c476991
JB
4555 if (rdev->scan_req)
4556 return -EBUSY;
2a519311
JB
4557
4558 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
4559 n_channels = validate_scan_freqs(
4560 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
4561 if (!n_channels)
4562 return -EINVAL;
2a519311 4563 } else {
34850ab2 4564 enum ieee80211_band band;
83f5e2cf
JB
4565 n_channels = 0;
4566
2a519311
JB
4567 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4568 if (wiphy->bands[band])
4569 n_channels += wiphy->bands[band]->n_channels;
4570 }
4571
4572 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4573 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
4574 n_ssids++;
4575
4c476991
JB
4576 if (n_ssids > wiphy->max_scan_ssids)
4577 return -EINVAL;
2a519311 4578
70692ad2
JM
4579 if (info->attrs[NL80211_ATTR_IE])
4580 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4581 else
4582 ie_len = 0;
4583
4c476991
JB
4584 if (ie_len > wiphy->max_scan_ie_len)
4585 return -EINVAL;
18a83659 4586
2a519311 4587 request = kzalloc(sizeof(*request)
a2cd43c5
LC
4588 + sizeof(*request->ssids) * n_ssids
4589 + sizeof(*request->channels) * n_channels
70692ad2 4590 + ie_len, GFP_KERNEL);
4c476991
JB
4591 if (!request)
4592 return -ENOMEM;
2a519311 4593
2a519311 4594 if (n_ssids)
5ba63533 4595 request->ssids = (void *)&request->channels[n_channels];
2a519311 4596 request->n_ssids = n_ssids;
70692ad2
JM
4597 if (ie_len) {
4598 if (request->ssids)
4599 request->ie = (void *)(request->ssids + n_ssids);
4600 else
4601 request->ie = (void *)(request->channels + n_channels);
4602 }
2a519311 4603
584991dc 4604 i = 0;
2a519311
JB
4605 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4606 /* user specified, bail out if channel not found */
2a519311 4607 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
4608 struct ieee80211_channel *chan;
4609
4610 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4611
4612 if (!chan) {
2a519311
JB
4613 err = -EINVAL;
4614 goto out_free;
4615 }
584991dc
JB
4616
4617 /* ignore disabled channels */
4618 if (chan->flags & IEEE80211_CHAN_DISABLED)
4619 continue;
4620
4621 request->channels[i] = chan;
2a519311
JB
4622 i++;
4623 }
4624 } else {
34850ab2
JB
4625 enum ieee80211_band band;
4626
2a519311 4627 /* all channels */
2a519311
JB
4628 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4629 int j;
4630 if (!wiphy->bands[band])
4631 continue;
4632 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4633 struct ieee80211_channel *chan;
4634
4635 chan = &wiphy->bands[band]->channels[j];
4636
4637 if (chan->flags & IEEE80211_CHAN_DISABLED)
4638 continue;
4639
4640 request->channels[i] = chan;
2a519311
JB
4641 i++;
4642 }
4643 }
4644 }
4645
584991dc
JB
4646 if (!i) {
4647 err = -EINVAL;
4648 goto out_free;
4649 }
4650
4651 request->n_channels = i;
4652
2a519311
JB
4653 i = 0;
4654 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4655 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4656 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4657 err = -EINVAL;
4658 goto out_free;
4659 }
57a27e1d 4660 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4661 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4662 i++;
4663 }
4664 }
4665
70692ad2
JM
4666 if (info->attrs[NL80211_ATTR_IE]) {
4667 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4668 memcpy((void *)request->ie,
4669 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4670 request->ie_len);
4671 }
4672
34850ab2 4673 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4674 if (wiphy->bands[i])
4675 request->rates[i] =
4676 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4677
4678 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4679 nla_for_each_nested(attr,
4680 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4681 tmp) {
4682 enum ieee80211_band band = nla_type(attr);
4683
84404623 4684 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4685 err = -EINVAL;
4686 goto out_free;
4687 }
4688 err = ieee80211_get_ratemask(wiphy->bands[band],
4689 nla_data(attr),
4690 nla_len(attr),
4691 &request->rates[band]);
4692 if (err)
4693 goto out_free;
4694 }
4695 }
4696
46856bbf 4697 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4698 request->flags = nla_get_u32(
4699 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4700 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4701 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4702 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4703 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4704 err = -EOPNOTSUPP;
4705 goto out_free;
4706 }
4707 }
ed473771 4708
e9f935e3
RM
4709 request->no_cck =
4710 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4711
fd014284 4712 request->wdev = wdev;
79c97e97 4713 request->wiphy = &rdev->wiphy;
15d6030b 4714 request->scan_start = jiffies;
2a519311 4715
79c97e97 4716 rdev->scan_req = request;
e35e4d28 4717 err = rdev_scan(rdev, request);
2a519311 4718
463d0183 4719 if (!err) {
fd014284
JB
4720 nl80211_send_scan_start(rdev, wdev);
4721 if (wdev->netdev)
4722 dev_hold(wdev->netdev);
4c476991 4723 } else {
2a519311 4724 out_free:
79c97e97 4725 rdev->scan_req = NULL;
2a519311
JB
4726 kfree(request);
4727 }
3b85875a 4728
2a519311
JB
4729 return err;
4730}
4731
807f8a8c
LC
4732static int nl80211_start_sched_scan(struct sk_buff *skb,
4733 struct genl_info *info)
4734{
4735 struct cfg80211_sched_scan_request *request;
4736 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4737 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4738 struct nlattr *attr;
4739 struct wiphy *wiphy;
a1f1c21c 4740 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4741 u32 interval;
807f8a8c
LC
4742 enum ieee80211_band band;
4743 size_t ie_len;
a1f1c21c 4744 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4745
4746 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4747 !rdev->ops->sched_scan_start)
4748 return -EOPNOTSUPP;
4749
4750 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4751 return -EINVAL;
4752
bbe6ad6d
LC
4753 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4754 return -EINVAL;
4755
4756 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4757 if (interval == 0)
4758 return -EINVAL;
4759
807f8a8c
LC
4760 wiphy = &rdev->wiphy;
4761
4762 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4763 n_channels = validate_scan_freqs(
4764 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4765 if (!n_channels)
4766 return -EINVAL;
4767 } else {
4768 n_channels = 0;
4769
4770 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4771 if (wiphy->bands[band])
4772 n_channels += wiphy->bands[band]->n_channels;
4773 }
4774
4775 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4776 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4777 tmp)
4778 n_ssids++;
4779
93b6aa69 4780 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4781 return -EINVAL;
4782
a1f1c21c
LC
4783 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4784 nla_for_each_nested(attr,
4785 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4786 tmp)
4787 n_match_sets++;
4788
4789 if (n_match_sets > wiphy->max_match_sets)
4790 return -EINVAL;
4791
807f8a8c
LC
4792 if (info->attrs[NL80211_ATTR_IE])
4793 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4794 else
4795 ie_len = 0;
4796
5a865bad 4797 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4798 return -EINVAL;
4799
c10841ca
LC
4800 mutex_lock(&rdev->sched_scan_mtx);
4801
4802 if (rdev->sched_scan_req) {
4803 err = -EINPROGRESS;
4804 goto out;
4805 }
4806
807f8a8c 4807 request = kzalloc(sizeof(*request)
a2cd43c5 4808 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4809 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4810 + sizeof(*request->channels) * n_channels
807f8a8c 4811 + ie_len, GFP_KERNEL);
c10841ca
LC
4812 if (!request) {
4813 err = -ENOMEM;
4814 goto out;
4815 }
807f8a8c
LC
4816
4817 if (n_ssids)
4818 request->ssids = (void *)&request->channels[n_channels];
4819 request->n_ssids = n_ssids;
4820 if (ie_len) {
4821 if (request->ssids)
4822 request->ie = (void *)(request->ssids + n_ssids);
4823 else
4824 request->ie = (void *)(request->channels + n_channels);
4825 }
4826
a1f1c21c
LC
4827 if (n_match_sets) {
4828 if (request->ie)
4829 request->match_sets = (void *)(request->ie + ie_len);
4830 else if (request->ssids)
4831 request->match_sets =
4832 (void *)(request->ssids + n_ssids);
4833 else
4834 request->match_sets =
4835 (void *)(request->channels + n_channels);
4836 }
4837 request->n_match_sets = n_match_sets;
4838
807f8a8c
LC
4839 i = 0;
4840 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4841 /* user specified, bail out if channel not found */
4842 nla_for_each_nested(attr,
4843 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4844 tmp) {
4845 struct ieee80211_channel *chan;
4846
4847 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4848
4849 if (!chan) {
4850 err = -EINVAL;
4851 goto out_free;
4852 }
4853
4854 /* ignore disabled channels */
4855 if (chan->flags & IEEE80211_CHAN_DISABLED)
4856 continue;
4857
4858 request->channels[i] = chan;
4859 i++;
4860 }
4861 } else {
4862 /* all channels */
4863 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4864 int j;
4865 if (!wiphy->bands[band])
4866 continue;
4867 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4868 struct ieee80211_channel *chan;
4869
4870 chan = &wiphy->bands[band]->channels[j];
4871
4872 if (chan->flags & IEEE80211_CHAN_DISABLED)
4873 continue;
4874
4875 request->channels[i] = chan;
4876 i++;
4877 }
4878 }
4879 }
4880
4881 if (!i) {
4882 err = -EINVAL;
4883 goto out_free;
4884 }
4885
4886 request->n_channels = i;
4887
4888 i = 0;
4889 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4890 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4891 tmp) {
57a27e1d 4892 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4893 err = -EINVAL;
4894 goto out_free;
4895 }
57a27e1d 4896 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4897 memcpy(request->ssids[i].ssid, nla_data(attr),
4898 nla_len(attr));
807f8a8c
LC
4899 i++;
4900 }
4901 }
4902
a1f1c21c
LC
4903 i = 0;
4904 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4905 nla_for_each_nested(attr,
4906 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4907 tmp) {
88e920b4 4908 struct nlattr *ssid, *rssi;
a1f1c21c
LC
4909
4910 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4911 nla_data(attr), nla_len(attr),
4912 nl80211_match_policy);
4a4ab0d7 4913 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4914 if (ssid) {
4915 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4916 err = -EINVAL;
4917 goto out_free;
4918 }
4919 memcpy(request->match_sets[i].ssid.ssid,
4920 nla_data(ssid), nla_len(ssid));
4921 request->match_sets[i].ssid.ssid_len =
4922 nla_len(ssid);
4923 }
88e920b4
TP
4924 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
4925 if (rssi)
4926 request->rssi_thold = nla_get_u32(rssi);
4927 else
4928 request->rssi_thold =
4929 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
4930 i++;
4931 }
4932 }
4933
807f8a8c
LC
4934 if (info->attrs[NL80211_ATTR_IE]) {
4935 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4936 memcpy((void *)request->ie,
4937 nla_data(info->attrs[NL80211_ATTR_IE]),
4938 request->ie_len);
4939 }
4940
46856bbf 4941 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4942 request->flags = nla_get_u32(
4943 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4944 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4945 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4946 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4947 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4948 err = -EOPNOTSUPP;
4949 goto out_free;
4950 }
4951 }
ed473771 4952
807f8a8c
LC
4953 request->dev = dev;
4954 request->wiphy = &rdev->wiphy;
bbe6ad6d 4955 request->interval = interval;
15d6030b 4956 request->scan_start = jiffies;
807f8a8c 4957
e35e4d28 4958 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
4959 if (!err) {
4960 rdev->sched_scan_req = request;
4961 nl80211_send_sched_scan(rdev, dev,
4962 NL80211_CMD_START_SCHED_SCAN);
4963 goto out;
4964 }
4965
4966out_free:
4967 kfree(request);
4968out:
c10841ca 4969 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4970 return err;
4971}
4972
4973static int nl80211_stop_sched_scan(struct sk_buff *skb,
4974 struct genl_info *info)
4975{
4976 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4977 int err;
807f8a8c
LC
4978
4979 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4980 !rdev->ops->sched_scan_stop)
4981 return -EOPNOTSUPP;
4982
c10841ca
LC
4983 mutex_lock(&rdev->sched_scan_mtx);
4984 err = __cfg80211_stop_sched_scan(rdev, false);
4985 mutex_unlock(&rdev->sched_scan_mtx);
4986
4987 return err;
807f8a8c
LC
4988}
4989
9720bb3a
JB
4990static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4991 u32 seq, int flags,
2a519311 4992 struct cfg80211_registered_device *rdev,
48ab905d
JB
4993 struct wireless_dev *wdev,
4994 struct cfg80211_internal_bss *intbss)
2a519311 4995{
48ab905d 4996 struct cfg80211_bss *res = &intbss->pub;
9caf0364 4997 const struct cfg80211_bss_ies *ies;
2a519311
JB
4998 void *hdr;
4999 struct nlattr *bss;
48ab905d
JB
5000
5001 ASSERT_WDEV_LOCK(wdev);
2a519311 5002
15e47304 5003 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
5004 NL80211_CMD_NEW_SCAN_RESULTS);
5005 if (!hdr)
5006 return -1;
5007
9720bb3a
JB
5008 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
5009
9360ffd1
DM
5010 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
5011 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
5012 goto nla_put_failure;
2a519311
JB
5013
5014 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
5015 if (!bss)
5016 goto nla_put_failure;
9360ffd1 5017 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 5018 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 5019 goto nla_put_failure;
9caf0364
JB
5020
5021 rcu_read_lock();
5022 ies = rcu_dereference(res->ies);
5023 if (ies && ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
5024 ies->len, ies->data)) {
5025 rcu_read_unlock();
5026 goto nla_put_failure;
5027 }
5028 ies = rcu_dereference(res->beacon_ies);
5029 if (ies && ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
5030 ies->len, ies->data)) {
5031 rcu_read_unlock();
5032 goto nla_put_failure;
5033 }
5034 rcu_read_unlock();
5035
9360ffd1
DM
5036 if (res->tsf &&
5037 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
5038 goto nla_put_failure;
5039 if (res->beacon_interval &&
5040 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
5041 goto nla_put_failure;
5042 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
5043 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
5044 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
5045 jiffies_to_msecs(jiffies - intbss->ts)))
5046 goto nla_put_failure;
2a519311 5047
77965c97 5048 switch (rdev->wiphy.signal_type) {
2a519311 5049 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
5050 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
5051 goto nla_put_failure;
2a519311
JB
5052 break;
5053 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
5054 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
5055 goto nla_put_failure;
2a519311
JB
5056 break;
5057 default:
5058 break;
5059 }
5060
48ab905d 5061 switch (wdev->iftype) {
074ac8df 5062 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 5063 case NL80211_IFTYPE_STATION:
9360ffd1
DM
5064 if (intbss == wdev->current_bss &&
5065 nla_put_u32(msg, NL80211_BSS_STATUS,
5066 NL80211_BSS_STATUS_ASSOCIATED))
5067 goto nla_put_failure;
48ab905d
JB
5068 break;
5069 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
5070 if (intbss == wdev->current_bss &&
5071 nla_put_u32(msg, NL80211_BSS_STATUS,
5072 NL80211_BSS_STATUS_IBSS_JOINED))
5073 goto nla_put_failure;
48ab905d
JB
5074 break;
5075 default:
5076 break;
5077 }
5078
2a519311
JB
5079 nla_nest_end(msg, bss);
5080
5081 return genlmsg_end(msg, hdr);
5082
5083 nla_put_failure:
5084 genlmsg_cancel(msg, hdr);
5085 return -EMSGSIZE;
5086}
5087
5088static int nl80211_dump_scan(struct sk_buff *skb,
5089 struct netlink_callback *cb)
5090{
48ab905d
JB
5091 struct cfg80211_registered_device *rdev;
5092 struct net_device *dev;
2a519311 5093 struct cfg80211_internal_bss *scan;
48ab905d 5094 struct wireless_dev *wdev;
2a519311
JB
5095 int start = cb->args[1], idx = 0;
5096 int err;
5097
67748893
JB
5098 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
5099 if (err)
5100 return err;
2a519311 5101
48ab905d 5102 wdev = dev->ieee80211_ptr;
2a519311 5103
48ab905d
JB
5104 wdev_lock(wdev);
5105 spin_lock_bh(&rdev->bss_lock);
5106 cfg80211_bss_expire(rdev);
5107
9720bb3a
JB
5108 cb->seq = rdev->bss_generation;
5109
48ab905d 5110 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
5111 if (++idx <= start)
5112 continue;
9720bb3a 5113 if (nl80211_send_bss(skb, cb,
2a519311 5114 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 5115 rdev, wdev, scan) < 0) {
2a519311 5116 idx--;
67748893 5117 break;
2a519311
JB
5118 }
5119 }
5120
48ab905d
JB
5121 spin_unlock_bh(&rdev->bss_lock);
5122 wdev_unlock(wdev);
2a519311
JB
5123
5124 cb->args[1] = idx;
67748893 5125 nl80211_finish_netdev_dump(rdev);
2a519311 5126
67748893 5127 return skb->len;
2a519311
JB
5128}
5129
15e47304 5130static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
5131 int flags, struct net_device *dev,
5132 struct survey_info *survey)
5133{
5134 void *hdr;
5135 struct nlattr *infoattr;
5136
15e47304 5137 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
5138 NL80211_CMD_NEW_SURVEY_RESULTS);
5139 if (!hdr)
5140 return -ENOMEM;
5141
9360ffd1
DM
5142 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
5143 goto nla_put_failure;
61fa713c
HS
5144
5145 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
5146 if (!infoattr)
5147 goto nla_put_failure;
5148
9360ffd1
DM
5149 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
5150 survey->channel->center_freq))
5151 goto nla_put_failure;
5152
5153 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
5154 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
5155 goto nla_put_failure;
5156 if ((survey->filled & SURVEY_INFO_IN_USE) &&
5157 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
5158 goto nla_put_failure;
5159 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
5160 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
5161 survey->channel_time))
5162 goto nla_put_failure;
5163 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
5164 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
5165 survey->channel_time_busy))
5166 goto nla_put_failure;
5167 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
5168 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5169 survey->channel_time_ext_busy))
5170 goto nla_put_failure;
5171 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5172 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5173 survey->channel_time_rx))
5174 goto nla_put_failure;
5175 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5176 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5177 survey->channel_time_tx))
5178 goto nla_put_failure;
61fa713c
HS
5179
5180 nla_nest_end(msg, infoattr);
5181
5182 return genlmsg_end(msg, hdr);
5183
5184 nla_put_failure:
5185 genlmsg_cancel(msg, hdr);
5186 return -EMSGSIZE;
5187}
5188
5189static int nl80211_dump_survey(struct sk_buff *skb,
5190 struct netlink_callback *cb)
5191{
5192 struct survey_info survey;
5193 struct cfg80211_registered_device *dev;
5194 struct net_device *netdev;
61fa713c
HS
5195 int survey_idx = cb->args[1];
5196 int res;
5197
67748893
JB
5198 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
5199 if (res)
5200 return res;
61fa713c
HS
5201
5202 if (!dev->ops->dump_survey) {
5203 res = -EOPNOTSUPP;
5204 goto out_err;
5205 }
5206
5207 while (1) {
180cdc79
LR
5208 struct ieee80211_channel *chan;
5209
e35e4d28 5210 res = rdev_dump_survey(dev, netdev, survey_idx, &survey);
61fa713c
HS
5211 if (res == -ENOENT)
5212 break;
5213 if (res)
5214 goto out_err;
5215
180cdc79
LR
5216 /* Survey without a channel doesn't make sense */
5217 if (!survey.channel) {
5218 res = -EINVAL;
5219 goto out;
5220 }
5221
5222 chan = ieee80211_get_channel(&dev->wiphy,
5223 survey.channel->center_freq);
5224 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5225 survey_idx++;
5226 continue;
5227 }
5228
61fa713c 5229 if (nl80211_send_survey(skb,
15e47304 5230 NETLINK_CB(cb->skb).portid,
61fa713c
HS
5231 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5232 netdev,
5233 &survey) < 0)
5234 goto out;
5235 survey_idx++;
5236 }
5237
5238 out:
5239 cb->args[1] = survey_idx;
5240 res = skb->len;
5241 out_err:
67748893 5242 nl80211_finish_netdev_dump(dev);
61fa713c
HS
5243 return res;
5244}
5245
b23aa676
SO
5246static bool nl80211_valid_wpa_versions(u32 wpa_versions)
5247{
5248 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
5249 NL80211_WPA_VERSION_2));
5250}
5251
636a5d36
JM
5252static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
5253{
4c476991
JB
5254 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5255 struct net_device *dev = info->user_ptr[1];
19957bb3 5256 struct ieee80211_channel *chan;
e39e5b5e
JM
5257 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
5258 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 5259 enum nl80211_auth_type auth_type;
fffd0934 5260 struct key_parse key;
d5cdfacb 5261 bool local_state_change;
636a5d36 5262
f4a11bb0
JB
5263 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5264 return -EINVAL;
5265
5266 if (!info->attrs[NL80211_ATTR_MAC])
5267 return -EINVAL;
5268
1778092e
JM
5269 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
5270 return -EINVAL;
5271
19957bb3
JB
5272 if (!info->attrs[NL80211_ATTR_SSID])
5273 return -EINVAL;
5274
5275 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
5276 return -EINVAL;
5277
fffd0934
JB
5278 err = nl80211_parse_key(info, &key);
5279 if (err)
5280 return err;
5281
5282 if (key.idx >= 0) {
e31b8213
JB
5283 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
5284 return -EINVAL;
fffd0934
JB
5285 if (!key.p.key || !key.p.key_len)
5286 return -EINVAL;
5287 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
5288 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
5289 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
5290 key.p.key_len != WLAN_KEY_LEN_WEP104))
5291 return -EINVAL;
5292 if (key.idx > 4)
5293 return -EINVAL;
5294 } else {
5295 key.p.key_len = 0;
5296 key.p.key = NULL;
5297 }
5298
afea0b7a
JB
5299 if (key.idx >= 0) {
5300 int i;
5301 bool ok = false;
5302 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
5303 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
5304 ok = true;
5305 break;
5306 }
5307 }
4c476991
JB
5308 if (!ok)
5309 return -EINVAL;
afea0b7a
JB
5310 }
5311
4c476991
JB
5312 if (!rdev->ops->auth)
5313 return -EOPNOTSUPP;
636a5d36 5314
074ac8df 5315 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5316 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5317 return -EOPNOTSUPP;
eec60b03 5318
19957bb3 5319 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 5320 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 5321 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5322 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5323 return -EINVAL;
636a5d36 5324
19957bb3
JB
5325 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5326 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5327
5328 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5329 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5330 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5331 }
5332
19957bb3 5333 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 5334 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 5335 return -EINVAL;
636a5d36 5336
e39e5b5e
JM
5337 if (auth_type == NL80211_AUTHTYPE_SAE &&
5338 !info->attrs[NL80211_ATTR_SAE_DATA])
5339 return -EINVAL;
5340
5341 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
5342 if (auth_type != NL80211_AUTHTYPE_SAE)
5343 return -EINVAL;
5344 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
5345 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
5346 /* need to include at least Auth Transaction and Status Code */
5347 if (sae_data_len < 4)
5348 return -EINVAL;
5349 }
5350
d5cdfacb
JM
5351 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5352
95de817b
JB
5353 /*
5354 * Since we no longer track auth state, ignore
5355 * requests to only change local state.
5356 */
5357 if (local_state_change)
5358 return 0;
5359
4c476991
JB
5360 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
5361 ssid, ssid_len, ie, ie_len,
e39e5b5e
JM
5362 key.p.key, key.p.key_len, key.idx,
5363 sae_data, sae_data_len);
636a5d36
JM
5364}
5365
c0692b8f
JB
5366static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
5367 struct genl_info *info,
3dc27d25
JB
5368 struct cfg80211_crypto_settings *settings,
5369 int cipher_limit)
b23aa676 5370{
c0b2bbd8
JB
5371 memset(settings, 0, sizeof(*settings));
5372
b23aa676
SO
5373 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
5374
c0692b8f
JB
5375 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
5376 u16 proto;
5377 proto = nla_get_u16(
5378 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
5379 settings->control_port_ethertype = cpu_to_be16(proto);
5380 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
5381 proto != ETH_P_PAE)
5382 return -EINVAL;
5383 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
5384 settings->control_port_no_encrypt = true;
5385 } else
5386 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
5387
b23aa676
SO
5388 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
5389 void *data;
5390 int len, i;
5391
5392 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5393 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5394 settings->n_ciphers_pairwise = len / sizeof(u32);
5395
5396 if (len % sizeof(u32))
5397 return -EINVAL;
5398
3dc27d25 5399 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
5400 return -EINVAL;
5401
5402 memcpy(settings->ciphers_pairwise, data, len);
5403
5404 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
5405 if (!cfg80211_supported_cipher_suite(
5406 &rdev->wiphy,
b23aa676
SO
5407 settings->ciphers_pairwise[i]))
5408 return -EINVAL;
5409 }
5410
5411 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
5412 settings->cipher_group =
5413 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
5414 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
5415 settings->cipher_group))
b23aa676
SO
5416 return -EINVAL;
5417 }
5418
5419 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
5420 settings->wpa_versions =
5421 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
5422 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
5423 return -EINVAL;
5424 }
5425
5426 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
5427 void *data;
6d30240e 5428 int len;
b23aa676
SO
5429
5430 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
5431 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
5432 settings->n_akm_suites = len / sizeof(u32);
5433
5434 if (len % sizeof(u32))
5435 return -EINVAL;
5436
1b9ca027
JM
5437 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
5438 return -EINVAL;
5439
b23aa676 5440 memcpy(settings->akm_suites, data, len);
b23aa676
SO
5441 }
5442
5443 return 0;
5444}
5445
636a5d36
JM
5446static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
5447{
4c476991
JB
5448 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5449 struct net_device *dev = info->user_ptr[1];
19957bb3 5450 struct cfg80211_crypto_settings crypto;
f444de05 5451 struct ieee80211_channel *chan;
3e5d7649 5452 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
5453 int err, ssid_len, ie_len = 0;
5454 bool use_mfp = false;
7e7c8926
BG
5455 u32 flags = 0;
5456 struct ieee80211_ht_cap *ht_capa = NULL;
5457 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 5458
f4a11bb0
JB
5459 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5460 return -EINVAL;
5461
5462 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
5463 !info->attrs[NL80211_ATTR_SSID] ||
5464 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
5465 return -EINVAL;
5466
4c476991
JB
5467 if (!rdev->ops->assoc)
5468 return -EOPNOTSUPP;
636a5d36 5469
074ac8df 5470 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5471 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5472 return -EOPNOTSUPP;
eec60b03 5473
19957bb3 5474 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5475
19957bb3
JB
5476 chan = ieee80211_get_channel(&rdev->wiphy,
5477 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5478 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5479 return -EINVAL;
636a5d36 5480
19957bb3
JB
5481 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5482 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5483
5484 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5485 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5486 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5487 }
5488
dc6382ce 5489 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 5490 enum nl80211_mfp mfp =
dc6382ce 5491 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 5492 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 5493 use_mfp = true;
4c476991
JB
5494 else if (mfp != NL80211_MFP_NO)
5495 return -EINVAL;
dc6382ce
JM
5496 }
5497
3e5d7649
JB
5498 if (info->attrs[NL80211_ATTR_PREV_BSSID])
5499 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
5500
7e7c8926
BG
5501 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5502 flags |= ASSOC_REQ_DISABLE_HT;
5503
5504 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5505 ht_capa_mask =
5506 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
5507
5508 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5509 if (!ht_capa_mask)
5510 return -EINVAL;
5511 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5512 }
5513
c0692b8f 5514 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 5515 if (!err)
3e5d7649
JB
5516 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
5517 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
5518 &crypto, flags, ht_capa,
5519 ht_capa_mask);
636a5d36 5520
636a5d36
JM
5521 return err;
5522}
5523
5524static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
5525{
4c476991
JB
5526 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5527 struct net_device *dev = info->user_ptr[1];
19957bb3 5528 const u8 *ie = NULL, *bssid;
4c476991 5529 int ie_len = 0;
19957bb3 5530 u16 reason_code;
d5cdfacb 5531 bool local_state_change;
636a5d36 5532
f4a11bb0
JB
5533 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5534 return -EINVAL;
5535
5536 if (!info->attrs[NL80211_ATTR_MAC])
5537 return -EINVAL;
5538
5539 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5540 return -EINVAL;
5541
4c476991
JB
5542 if (!rdev->ops->deauth)
5543 return -EOPNOTSUPP;
636a5d36 5544
074ac8df 5545 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5546 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5547 return -EOPNOTSUPP;
eec60b03 5548
19957bb3 5549 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5550
19957bb3
JB
5551 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5552 if (reason_code == 0) {
f4a11bb0 5553 /* Reason Code 0 is reserved */
4c476991 5554 return -EINVAL;
255e737e 5555 }
636a5d36
JM
5556
5557 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5558 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5559 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5560 }
5561
d5cdfacb
JM
5562 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5563
4c476991
JB
5564 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
5565 local_state_change);
636a5d36
JM
5566}
5567
5568static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
5569{
4c476991
JB
5570 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5571 struct net_device *dev = info->user_ptr[1];
19957bb3 5572 const u8 *ie = NULL, *bssid;
4c476991 5573 int ie_len = 0;
19957bb3 5574 u16 reason_code;
d5cdfacb 5575 bool local_state_change;
636a5d36 5576
f4a11bb0
JB
5577 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5578 return -EINVAL;
5579
5580 if (!info->attrs[NL80211_ATTR_MAC])
5581 return -EINVAL;
5582
5583 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5584 return -EINVAL;
5585
4c476991
JB
5586 if (!rdev->ops->disassoc)
5587 return -EOPNOTSUPP;
636a5d36 5588
074ac8df 5589 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5590 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5591 return -EOPNOTSUPP;
eec60b03 5592
19957bb3 5593 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5594
19957bb3
JB
5595 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5596 if (reason_code == 0) {
f4a11bb0 5597 /* Reason Code 0 is reserved */
4c476991 5598 return -EINVAL;
255e737e 5599 }
636a5d36
JM
5600
5601 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5602 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5603 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5604 }
5605
d5cdfacb
JM
5606 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5607
4c476991
JB
5608 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
5609 local_state_change);
636a5d36
JM
5610}
5611
dd5b4cc7
FF
5612static bool
5613nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
5614 int mcast_rate[IEEE80211_NUM_BANDS],
5615 int rateval)
5616{
5617 struct wiphy *wiphy = &rdev->wiphy;
5618 bool found = false;
5619 int band, i;
5620
5621 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5622 struct ieee80211_supported_band *sband;
5623
5624 sband = wiphy->bands[band];
5625 if (!sband)
5626 continue;
5627
5628 for (i = 0; i < sband->n_bitrates; i++) {
5629 if (sband->bitrates[i].bitrate == rateval) {
5630 mcast_rate[band] = i + 1;
5631 found = true;
5632 break;
5633 }
5634 }
5635 }
5636
5637 return found;
5638}
5639
04a773ad
JB
5640static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
5641{
4c476991
JB
5642 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5643 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
5644 struct cfg80211_ibss_params ibss;
5645 struct wiphy *wiphy;
fffd0934 5646 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
5647 int err;
5648
8e30bc55
JB
5649 memset(&ibss, 0, sizeof(ibss));
5650
04a773ad
JB
5651 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5652 return -EINVAL;
5653
683b6d3b 5654 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
5655 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5656 return -EINVAL;
5657
8e30bc55
JB
5658 ibss.beacon_interval = 100;
5659
5660 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
5661 ibss.beacon_interval =
5662 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5663 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
5664 return -EINVAL;
5665 }
5666
4c476991
JB
5667 if (!rdev->ops->join_ibss)
5668 return -EOPNOTSUPP;
04a773ad 5669
4c476991
JB
5670 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5671 return -EOPNOTSUPP;
04a773ad 5672
79c97e97 5673 wiphy = &rdev->wiphy;
04a773ad 5674
39193498 5675 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 5676 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
5677
5678 if (!is_valid_ether_addr(ibss.bssid))
5679 return -EINVAL;
5680 }
04a773ad
JB
5681 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5682 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5683
5684 if (info->attrs[NL80211_ATTR_IE]) {
5685 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5686 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5687 }
5688
683b6d3b
JB
5689 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
5690 if (err)
5691 return err;
04a773ad 5692
683b6d3b 5693 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
5694 return -EINVAL;
5695
db9c64cf
JB
5696 if (ibss.chandef.width > NL80211_CHAN_WIDTH_40)
5697 return -EINVAL;
5698 if (ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
5699 !(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
c04d6150 5700 return -EINVAL;
db9c64cf 5701
04a773ad 5702 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5703 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5704
fbd2c8dc
TP
5705 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5706 u8 *rates =
5707 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5708 int n_rates =
5709 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5710 struct ieee80211_supported_band *sband =
683b6d3b 5711 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 5712
34850ab2
JB
5713 err = ieee80211_get_ratemask(sband, rates, n_rates,
5714 &ibss.basic_rates);
5715 if (err)
5716 return err;
fbd2c8dc 5717 }
dd5b4cc7
FF
5718
5719 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5720 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5721 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5722 return -EINVAL;
fbd2c8dc 5723
4c476991 5724 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
5725 bool no_ht = false;
5726
4c476991 5727 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
5728 info->attrs[NL80211_ATTR_KEYS],
5729 &no_ht);
4c476991
JB
5730 if (IS_ERR(connkeys))
5731 return PTR_ERR(connkeys);
de7044ee 5732
3d9d1d66
JB
5733 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
5734 no_ht) {
de7044ee
SM
5735 kfree(connkeys);
5736 return -EINVAL;
5737 }
4c476991 5738 }
04a773ad 5739
267335d6
AQ
5740 ibss.control_port =
5741 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5742
4c476991 5743 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5744 if (err)
5745 kfree(connkeys);
04a773ad
JB
5746 return err;
5747}
5748
5749static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5750{
4c476991
JB
5751 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5752 struct net_device *dev = info->user_ptr[1];
04a773ad 5753
4c476991
JB
5754 if (!rdev->ops->leave_ibss)
5755 return -EOPNOTSUPP;
04a773ad 5756
4c476991
JB
5757 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5758 return -EOPNOTSUPP;
04a773ad 5759
4c476991 5760 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5761}
5762
f4e583c8
AQ
5763static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
5764{
5765 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5766 struct net_device *dev = info->user_ptr[1];
5767 int mcast_rate[IEEE80211_NUM_BANDS];
5768 u32 nla_rate;
5769 int err;
5770
5771 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5772 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5773 return -EOPNOTSUPP;
5774
5775 if (!rdev->ops->set_mcast_rate)
5776 return -EOPNOTSUPP;
5777
5778 memset(mcast_rate, 0, sizeof(mcast_rate));
5779
5780 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
5781 return -EINVAL;
5782
5783 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
5784 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
5785 return -EINVAL;
5786
5787 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
5788
5789 return err;
5790}
5791
5792
aff89a9b
JB
5793#ifdef CONFIG_NL80211_TESTMODE
5794static struct genl_multicast_group nl80211_testmode_mcgrp = {
5795 .name = "testmode",
5796};
5797
5798static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5799{
4c476991 5800 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5801 int err;
5802
5803 if (!info->attrs[NL80211_ATTR_TESTDATA])
5804 return -EINVAL;
5805
aff89a9b
JB
5806 err = -EOPNOTSUPP;
5807 if (rdev->ops->testmode_cmd) {
5808 rdev->testmode_info = info;
e35e4d28 5809 err = rdev_testmode_cmd(rdev,
aff89a9b
JB
5810 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5811 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5812 rdev->testmode_info = NULL;
5813 }
5814
aff89a9b
JB
5815 return err;
5816}
5817
71063f0e
WYG
5818static int nl80211_testmode_dump(struct sk_buff *skb,
5819 struct netlink_callback *cb)
5820{
00918d33 5821 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5822 int err;
5823 long phy_idx;
5824 void *data = NULL;
5825 int data_len = 0;
5826
5827 if (cb->args[0]) {
5828 /*
5829 * 0 is a valid index, but not valid for args[0],
5830 * so we need to offset by 1.
5831 */
5832 phy_idx = cb->args[0] - 1;
5833 } else {
5834 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5835 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5836 nl80211_policy);
5837 if (err)
5838 return err;
00918d33 5839
2bd7e35d
JB
5840 mutex_lock(&cfg80211_mutex);
5841 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
5842 nl80211_fam.attrbuf);
5843 if (IS_ERR(rdev)) {
5844 mutex_unlock(&cfg80211_mutex);
5845 return PTR_ERR(rdev);
00918d33 5846 }
2bd7e35d
JB
5847 phy_idx = rdev->wiphy_idx;
5848 rdev = NULL;
5849 mutex_unlock(&cfg80211_mutex);
5850
71063f0e
WYG
5851 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5852 cb->args[1] =
5853 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5854 }
5855
5856 if (cb->args[1]) {
5857 data = nla_data((void *)cb->args[1]);
5858 data_len = nla_len((void *)cb->args[1]);
5859 }
5860
5861 mutex_lock(&cfg80211_mutex);
00918d33
JB
5862 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5863 if (!rdev) {
71063f0e
WYG
5864 mutex_unlock(&cfg80211_mutex);
5865 return -ENOENT;
5866 }
00918d33 5867 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5868 mutex_unlock(&cfg80211_mutex);
5869
00918d33 5870 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5871 err = -EOPNOTSUPP;
5872 goto out_err;
5873 }
5874
5875 while (1) {
15e47304 5876 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
5877 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5878 NL80211_CMD_TESTMODE);
5879 struct nlattr *tmdata;
5880
9360ffd1 5881 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5882 genlmsg_cancel(skb, hdr);
5883 break;
5884 }
5885
5886 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5887 if (!tmdata) {
5888 genlmsg_cancel(skb, hdr);
5889 break;
5890 }
e35e4d28 5891 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
5892 nla_nest_end(skb, tmdata);
5893
5894 if (err == -ENOBUFS || err == -ENOENT) {
5895 genlmsg_cancel(skb, hdr);
5896 break;
5897 } else if (err) {
5898 genlmsg_cancel(skb, hdr);
5899 goto out_err;
5900 }
5901
5902 genlmsg_end(skb, hdr);
5903 }
5904
5905 err = skb->len;
5906 /* see above */
5907 cb->args[0] = phy_idx + 1;
5908 out_err:
00918d33 5909 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5910 return err;
5911}
5912
aff89a9b
JB
5913static struct sk_buff *
5914__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 5915 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
5916{
5917 struct sk_buff *skb;
5918 void *hdr;
5919 struct nlattr *data;
5920
5921 skb = nlmsg_new(approxlen + 100, gfp);
5922 if (!skb)
5923 return NULL;
5924
15e47304 5925 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
5926 if (!hdr) {
5927 kfree_skb(skb);
5928 return NULL;
5929 }
5930
9360ffd1
DM
5931 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5932 goto nla_put_failure;
aff89a9b
JB
5933 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5934
5935 ((void **)skb->cb)[0] = rdev;
5936 ((void **)skb->cb)[1] = hdr;
5937 ((void **)skb->cb)[2] = data;
5938
5939 return skb;
5940
5941 nla_put_failure:
5942 kfree_skb(skb);
5943 return NULL;
5944}
5945
5946struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5947 int approxlen)
5948{
5949 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5950
5951 if (WARN_ON(!rdev->testmode_info))
5952 return NULL;
5953
5954 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 5955 rdev->testmode_info->snd_portid,
aff89a9b
JB
5956 rdev->testmode_info->snd_seq,
5957 GFP_KERNEL);
5958}
5959EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5960
5961int cfg80211_testmode_reply(struct sk_buff *skb)
5962{
5963 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5964 void *hdr = ((void **)skb->cb)[1];
5965 struct nlattr *data = ((void **)skb->cb)[2];
5966
5967 if (WARN_ON(!rdev->testmode_info)) {
5968 kfree_skb(skb);
5969 return -EINVAL;
5970 }
5971
5972 nla_nest_end(skb, data);
5973 genlmsg_end(skb, hdr);
5974 return genlmsg_reply(skb, rdev->testmode_info);
5975}
5976EXPORT_SYMBOL(cfg80211_testmode_reply);
5977
5978struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5979 int approxlen, gfp_t gfp)
5980{
5981 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5982
5983 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5984}
5985EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5986
5987void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5988{
5989 void *hdr = ((void **)skb->cb)[1];
5990 struct nlattr *data = ((void **)skb->cb)[2];
5991
5992 nla_nest_end(skb, data);
5993 genlmsg_end(skb, hdr);
5994 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5995}
5996EXPORT_SYMBOL(cfg80211_testmode_event);
5997#endif
5998
b23aa676
SO
5999static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
6000{
4c476991
JB
6001 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6002 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6003 struct cfg80211_connect_params connect;
6004 struct wiphy *wiphy;
fffd0934 6005 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
6006 int err;
6007
6008 memset(&connect, 0, sizeof(connect));
6009
6010 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6011 return -EINVAL;
6012
6013 if (!info->attrs[NL80211_ATTR_SSID] ||
6014 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6015 return -EINVAL;
6016
6017 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6018 connect.auth_type =
6019 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
6020 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
6021 NL80211_CMD_CONNECT))
b23aa676
SO
6022 return -EINVAL;
6023 } else
6024 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6025
6026 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
6027
c0692b8f 6028 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 6029 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
6030 if (err)
6031 return err;
b23aa676 6032
074ac8df 6033 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6034 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6035 return -EOPNOTSUPP;
b23aa676 6036
79c97e97 6037 wiphy = &rdev->wiphy;
b23aa676 6038
4486ea98
BS
6039 connect.bg_scan_period = -1;
6040 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
6041 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
6042 connect.bg_scan_period =
6043 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
6044 }
6045
b23aa676
SO
6046 if (info->attrs[NL80211_ATTR_MAC])
6047 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6048 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6049 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6050
6051 if (info->attrs[NL80211_ATTR_IE]) {
6052 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6053 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6054 }
6055
cee00a95
JM
6056 if (info->attrs[NL80211_ATTR_USE_MFP]) {
6057 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
6058 if (connect.mfp != NL80211_MFP_REQUIRED &&
6059 connect.mfp != NL80211_MFP_NO)
6060 return -EINVAL;
6061 } else {
6062 connect.mfp = NL80211_MFP_NO;
6063 }
6064
b23aa676
SO
6065 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6066 connect.channel =
6067 ieee80211_get_channel(wiphy,
6068 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
6069 if (!connect.channel ||
4c476991
JB
6070 connect.channel->flags & IEEE80211_CHAN_DISABLED)
6071 return -EINVAL;
b23aa676
SO
6072 }
6073
fffd0934
JB
6074 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
6075 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 6076 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
6077 if (IS_ERR(connkeys))
6078 return PTR_ERR(connkeys);
fffd0934
JB
6079 }
6080
7e7c8926
BG
6081 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
6082 connect.flags |= ASSOC_REQ_DISABLE_HT;
6083
6084 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6085 memcpy(&connect.ht_capa_mask,
6086 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6087 sizeof(connect.ht_capa_mask));
6088
6089 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
6090 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
6091 kfree(connkeys);
7e7c8926 6092 return -EINVAL;
b4e4f47e 6093 }
7e7c8926
BG
6094 memcpy(&connect.ht_capa,
6095 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6096 sizeof(connect.ht_capa));
6097 }
6098
fffd0934 6099 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
6100 if (err)
6101 kfree(connkeys);
b23aa676
SO
6102 return err;
6103}
6104
6105static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
6106{
4c476991
JB
6107 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6108 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6109 u16 reason;
6110
6111 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6112 reason = WLAN_REASON_DEAUTH_LEAVING;
6113 else
6114 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6115
6116 if (reason == 0)
6117 return -EINVAL;
6118
074ac8df 6119 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6120 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6121 return -EOPNOTSUPP;
b23aa676 6122
4c476991 6123 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
6124}
6125
463d0183
JB
6126static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
6127{
4c476991 6128 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
6129 struct net *net;
6130 int err;
6131 u32 pid;
6132
6133 if (!info->attrs[NL80211_ATTR_PID])
6134 return -EINVAL;
6135
6136 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
6137
463d0183 6138 net = get_net_ns_by_pid(pid);
4c476991
JB
6139 if (IS_ERR(net))
6140 return PTR_ERR(net);
463d0183
JB
6141
6142 err = 0;
6143
6144 /* check if anything to do */
4c476991
JB
6145 if (!net_eq(wiphy_net(&rdev->wiphy), net))
6146 err = cfg80211_switch_netns(rdev, net);
463d0183 6147
463d0183 6148 put_net(net);
463d0183
JB
6149 return err;
6150}
6151
67fbb16b
SO
6152static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
6153{
4c476991 6154 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
6155 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
6156 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 6157 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
6158 struct cfg80211_pmksa pmksa;
6159
6160 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
6161
6162 if (!info->attrs[NL80211_ATTR_MAC])
6163 return -EINVAL;
6164
6165 if (!info->attrs[NL80211_ATTR_PMKID])
6166 return -EINVAL;
6167
67fbb16b
SO
6168 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
6169 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6170
074ac8df 6171 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6172 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6173 return -EOPNOTSUPP;
67fbb16b
SO
6174
6175 switch (info->genlhdr->cmd) {
6176 case NL80211_CMD_SET_PMKSA:
6177 rdev_ops = rdev->ops->set_pmksa;
6178 break;
6179 case NL80211_CMD_DEL_PMKSA:
6180 rdev_ops = rdev->ops->del_pmksa;
6181 break;
6182 default:
6183 WARN_ON(1);
6184 break;
6185 }
6186
4c476991
JB
6187 if (!rdev_ops)
6188 return -EOPNOTSUPP;
67fbb16b 6189
4c476991 6190 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
6191}
6192
6193static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
6194{
4c476991
JB
6195 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6196 struct net_device *dev = info->user_ptr[1];
67fbb16b 6197
074ac8df 6198 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6199 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6200 return -EOPNOTSUPP;
67fbb16b 6201
4c476991
JB
6202 if (!rdev->ops->flush_pmksa)
6203 return -EOPNOTSUPP;
67fbb16b 6204
e35e4d28 6205 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
6206}
6207
109086ce
AN
6208static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
6209{
6210 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6211 struct net_device *dev = info->user_ptr[1];
6212 u8 action_code, dialog_token;
6213 u16 status_code;
6214 u8 *peer;
6215
6216 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6217 !rdev->ops->tdls_mgmt)
6218 return -EOPNOTSUPP;
6219
6220 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
6221 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
6222 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
6223 !info->attrs[NL80211_ATTR_IE] ||
6224 !info->attrs[NL80211_ATTR_MAC])
6225 return -EINVAL;
6226
6227 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6228 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
6229 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
6230 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
6231
e35e4d28
HG
6232 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
6233 dialog_token, status_code,
6234 nla_data(info->attrs[NL80211_ATTR_IE]),
6235 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
6236}
6237
6238static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
6239{
6240 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6241 struct net_device *dev = info->user_ptr[1];
6242 enum nl80211_tdls_operation operation;
6243 u8 *peer;
6244
6245 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6246 !rdev->ops->tdls_oper)
6247 return -EOPNOTSUPP;
6248
6249 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
6250 !info->attrs[NL80211_ATTR_MAC])
6251 return -EINVAL;
6252
6253 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
6254 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6255
e35e4d28 6256 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
6257}
6258
9588bbd5
JM
6259static int nl80211_remain_on_channel(struct sk_buff *skb,
6260 struct genl_info *info)
6261{
4c476991 6262 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6263 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6264 struct cfg80211_chan_def chandef;
9588bbd5
JM
6265 struct sk_buff *msg;
6266 void *hdr;
6267 u64 cookie;
683b6d3b 6268 u32 duration;
9588bbd5
JM
6269 int err;
6270
6271 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6272 !info->attrs[NL80211_ATTR_DURATION])
6273 return -EINVAL;
6274
6275 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
6276
ebf348fc
JB
6277 if (!rdev->ops->remain_on_channel ||
6278 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
6279 return -EOPNOTSUPP;
6280
9588bbd5 6281 /*
ebf348fc
JB
6282 * We should be on that channel for at least a minimum amount of
6283 * time (10ms) but no longer than the driver supports.
9588bbd5 6284 */
ebf348fc 6285 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 6286 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
6287 return -EINVAL;
6288
683b6d3b
JB
6289 err = nl80211_parse_chandef(rdev, info, &chandef);
6290 if (err)
6291 return err;
9588bbd5
JM
6292
6293 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6294 if (!msg)
6295 return -ENOMEM;
9588bbd5 6296
15e47304 6297 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5
JM
6298 NL80211_CMD_REMAIN_ON_CHANNEL);
6299
6300 if (IS_ERR(hdr)) {
6301 err = PTR_ERR(hdr);
6302 goto free_msg;
6303 }
6304
683b6d3b
JB
6305 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
6306 duration, &cookie);
9588bbd5
JM
6307
6308 if (err)
6309 goto free_msg;
6310
9360ffd1
DM
6311 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6312 goto nla_put_failure;
9588bbd5
JM
6313
6314 genlmsg_end(msg, hdr);
4c476991
JB
6315
6316 return genlmsg_reply(msg, info);
9588bbd5
JM
6317
6318 nla_put_failure:
6319 err = -ENOBUFS;
6320 free_msg:
6321 nlmsg_free(msg);
9588bbd5
JM
6322 return err;
6323}
6324
6325static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
6326 struct genl_info *info)
6327{
4c476991 6328 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6329 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 6330 u64 cookie;
9588bbd5
JM
6331
6332 if (!info->attrs[NL80211_ATTR_COOKIE])
6333 return -EINVAL;
6334
4c476991
JB
6335 if (!rdev->ops->cancel_remain_on_channel)
6336 return -EOPNOTSUPP;
9588bbd5 6337
9588bbd5
JM
6338 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6339
e35e4d28 6340 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
6341}
6342
13ae75b1
JM
6343static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
6344 u8 *rates, u8 rates_len)
6345{
6346 u8 i;
6347 u32 mask = 0;
6348
6349 for (i = 0; i < rates_len; i++) {
6350 int rate = (rates[i] & 0x7f) * 5;
6351 int ridx;
6352 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
6353 struct ieee80211_rate *srate =
6354 &sband->bitrates[ridx];
6355 if (rate == srate->bitrate) {
6356 mask |= 1 << ridx;
6357 break;
6358 }
6359 }
6360 if (ridx == sband->n_bitrates)
6361 return 0; /* rate not found */
6362 }
6363
6364 return mask;
6365}
6366
24db78c0
SW
6367static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
6368 u8 *rates, u8 rates_len,
6369 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
6370{
6371 u8 i;
6372
6373 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
6374
6375 for (i = 0; i < rates_len; i++) {
6376 int ridx, rbit;
6377
6378 ridx = rates[i] / 8;
6379 rbit = BIT(rates[i] % 8);
6380
6381 /* check validity */
910570b5 6382 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
6383 return false;
6384
6385 /* check availability */
6386 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
6387 mcs[ridx] |= rbit;
6388 else
6389 return false;
6390 }
6391
6392 return true;
6393}
6394
b54452b0 6395static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
6396 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
6397 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
6398 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
6399 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
6400};
6401
6402static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
6403 struct genl_info *info)
6404{
6405 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 6406 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 6407 struct cfg80211_bitrate_mask mask;
4c476991
JB
6408 int rem, i;
6409 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
6410 struct nlattr *tx_rates;
6411 struct ieee80211_supported_band *sband;
6412
6413 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
6414 return -EINVAL;
6415
4c476991
JB
6416 if (!rdev->ops->set_bitrate_mask)
6417 return -EOPNOTSUPP;
13ae75b1
JM
6418
6419 memset(&mask, 0, sizeof(mask));
6420 /* Default to all rates enabled */
6421 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
6422 sband = rdev->wiphy.bands[i];
6423 mask.control[i].legacy =
6424 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
6425 if (sband)
6426 memcpy(mask.control[i].mcs,
6427 sband->ht_cap.mcs.rx_mask,
6428 sizeof(mask.control[i].mcs));
6429 else
6430 memset(mask.control[i].mcs, 0,
6431 sizeof(mask.control[i].mcs));
13ae75b1
JM
6432 }
6433
6434 /*
6435 * The nested attribute uses enum nl80211_band as the index. This maps
6436 * directly to the enum ieee80211_band values used in cfg80211.
6437 */
24db78c0 6438 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
6439 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
6440 {
6441 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
6442 if (band < 0 || band >= IEEE80211_NUM_BANDS)
6443 return -EINVAL;
13ae75b1 6444 sband = rdev->wiphy.bands[band];
4c476991
JB
6445 if (sband == NULL)
6446 return -EINVAL;
13ae75b1
JM
6447 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
6448 nla_len(tx_rates), nl80211_txattr_policy);
6449 if (tb[NL80211_TXRATE_LEGACY]) {
6450 mask.control[band].legacy = rateset_to_mask(
6451 sband,
6452 nla_data(tb[NL80211_TXRATE_LEGACY]),
6453 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
6454 if ((mask.control[band].legacy == 0) &&
6455 nla_len(tb[NL80211_TXRATE_LEGACY]))
6456 return -EINVAL;
24db78c0
SW
6457 }
6458 if (tb[NL80211_TXRATE_MCS]) {
6459 if (!ht_rateset_to_mask(
6460 sband,
6461 nla_data(tb[NL80211_TXRATE_MCS]),
6462 nla_len(tb[NL80211_TXRATE_MCS]),
6463 mask.control[band].mcs))
6464 return -EINVAL;
6465 }
6466
6467 if (mask.control[band].legacy == 0) {
6468 /* don't allow empty legacy rates if HT
6469 * is not even supported. */
6470 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
6471 return -EINVAL;
6472
6473 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
6474 if (mask.control[band].mcs[i])
6475 break;
6476
6477 /* legacy and mcs rates may not be both empty */
6478 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 6479 return -EINVAL;
13ae75b1
JM
6480 }
6481 }
6482
e35e4d28 6483 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
6484}
6485
2e161f78 6486static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6487{
4c476991 6488 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6489 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 6490 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
6491
6492 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
6493 return -EINVAL;
6494
2e161f78
JB
6495 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
6496 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 6497
71bbc994
JB
6498 switch (wdev->iftype) {
6499 case NL80211_IFTYPE_STATION:
6500 case NL80211_IFTYPE_ADHOC:
6501 case NL80211_IFTYPE_P2P_CLIENT:
6502 case NL80211_IFTYPE_AP:
6503 case NL80211_IFTYPE_AP_VLAN:
6504 case NL80211_IFTYPE_MESH_POINT:
6505 case NL80211_IFTYPE_P2P_GO:
98104fde 6506 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6507 break;
6508 default:
4c476991 6509 return -EOPNOTSUPP;
71bbc994 6510 }
026331c4
JM
6511
6512 /* not much point in registering if we can't reply */
4c476991
JB
6513 if (!rdev->ops->mgmt_tx)
6514 return -EOPNOTSUPP;
026331c4 6515
15e47304 6516 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
6517 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
6518 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
6519}
6520
2e161f78 6521static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6522{
4c476991 6523 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6524 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6525 struct cfg80211_chan_def chandef;
026331c4 6526 int err;
d64d373f 6527 void *hdr = NULL;
026331c4 6528 u64 cookie;
e247bd90 6529 struct sk_buff *msg = NULL;
f7ca38df 6530 unsigned int wait = 0;
e247bd90
JB
6531 bool offchan, no_cck, dont_wait_for_ack;
6532
6533 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 6534
683b6d3b 6535 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
6536 return -EINVAL;
6537
4c476991
JB
6538 if (!rdev->ops->mgmt_tx)
6539 return -EOPNOTSUPP;
026331c4 6540
71bbc994
JB
6541 switch (wdev->iftype) {
6542 case NL80211_IFTYPE_STATION:
6543 case NL80211_IFTYPE_ADHOC:
6544 case NL80211_IFTYPE_P2P_CLIENT:
6545 case NL80211_IFTYPE_AP:
6546 case NL80211_IFTYPE_AP_VLAN:
6547 case NL80211_IFTYPE_MESH_POINT:
6548 case NL80211_IFTYPE_P2P_GO:
98104fde 6549 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6550 break;
6551 default:
4c476991 6552 return -EOPNOTSUPP;
71bbc994 6553 }
026331c4 6554
f7ca38df 6555 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 6556 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
6557 return -EINVAL;
6558 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
6559
6560 /*
6561 * We should wait on the channel for at least a minimum amount
6562 * of time (10ms) but no longer than the driver supports.
6563 */
6564 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
6565 wait > rdev->wiphy.max_remain_on_channel_duration)
6566 return -EINVAL;
6567
f7ca38df
JB
6568 }
6569
f7ca38df
JB
6570 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
6571
7c4ef712
JB
6572 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
6573 return -EINVAL;
6574
e9f935e3
RM
6575 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6576
683b6d3b
JB
6577 err = nl80211_parse_chandef(rdev, info, &chandef);
6578 if (err)
6579 return err;
026331c4 6580
e247bd90
JB
6581 if (!dont_wait_for_ack) {
6582 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6583 if (!msg)
6584 return -ENOMEM;
026331c4 6585
15e47304 6586 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 6587 NL80211_CMD_FRAME);
026331c4 6588
e247bd90
JB
6589 if (IS_ERR(hdr)) {
6590 err = PTR_ERR(hdr);
6591 goto free_msg;
6592 }
026331c4 6593 }
e247bd90 6594
683b6d3b 6595 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
6596 nla_data(info->attrs[NL80211_ATTR_FRAME]),
6597 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 6598 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
6599 if (err)
6600 goto free_msg;
6601
e247bd90 6602 if (msg) {
9360ffd1
DM
6603 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6604 goto nla_put_failure;
026331c4 6605
e247bd90
JB
6606 genlmsg_end(msg, hdr);
6607 return genlmsg_reply(msg, info);
6608 }
6609
6610 return 0;
026331c4
JM
6611
6612 nla_put_failure:
6613 err = -ENOBUFS;
6614 free_msg:
6615 nlmsg_free(msg);
026331c4
JM
6616 return err;
6617}
6618
f7ca38df
JB
6619static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
6620{
6621 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6622 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
6623 u64 cookie;
6624
6625 if (!info->attrs[NL80211_ATTR_COOKIE])
6626 return -EINVAL;
6627
6628 if (!rdev->ops->mgmt_tx_cancel_wait)
6629 return -EOPNOTSUPP;
6630
71bbc994
JB
6631 switch (wdev->iftype) {
6632 case NL80211_IFTYPE_STATION:
6633 case NL80211_IFTYPE_ADHOC:
6634 case NL80211_IFTYPE_P2P_CLIENT:
6635 case NL80211_IFTYPE_AP:
6636 case NL80211_IFTYPE_AP_VLAN:
6637 case NL80211_IFTYPE_P2P_GO:
98104fde 6638 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6639 break;
6640 default:
f7ca38df 6641 return -EOPNOTSUPP;
71bbc994 6642 }
f7ca38df
JB
6643
6644 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6645
e35e4d28 6646 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
6647}
6648
ffb9eb3d
KV
6649static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
6650{
4c476991 6651 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 6652 struct wireless_dev *wdev;
4c476991 6653 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6654 u8 ps_state;
6655 bool state;
6656 int err;
6657
4c476991
JB
6658 if (!info->attrs[NL80211_ATTR_PS_STATE])
6659 return -EINVAL;
ffb9eb3d
KV
6660
6661 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
6662
4c476991
JB
6663 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
6664 return -EINVAL;
ffb9eb3d
KV
6665
6666 wdev = dev->ieee80211_ptr;
6667
4c476991
JB
6668 if (!rdev->ops->set_power_mgmt)
6669 return -EOPNOTSUPP;
ffb9eb3d
KV
6670
6671 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
6672
6673 if (state == wdev->ps)
4c476991 6674 return 0;
ffb9eb3d 6675
e35e4d28 6676 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
6677 if (!err)
6678 wdev->ps = state;
ffb9eb3d
KV
6679 return err;
6680}
6681
6682static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
6683{
4c476991 6684 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
6685 enum nl80211_ps_state ps_state;
6686 struct wireless_dev *wdev;
4c476991 6687 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6688 struct sk_buff *msg;
6689 void *hdr;
6690 int err;
6691
ffb9eb3d
KV
6692 wdev = dev->ieee80211_ptr;
6693
4c476991
JB
6694 if (!rdev->ops->set_power_mgmt)
6695 return -EOPNOTSUPP;
ffb9eb3d
KV
6696
6697 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6698 if (!msg)
6699 return -ENOMEM;
ffb9eb3d 6700
15e47304 6701 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
6702 NL80211_CMD_GET_POWER_SAVE);
6703 if (!hdr) {
4c476991 6704 err = -ENOBUFS;
ffb9eb3d
KV
6705 goto free_msg;
6706 }
6707
6708 if (wdev->ps)
6709 ps_state = NL80211_PS_ENABLED;
6710 else
6711 ps_state = NL80211_PS_DISABLED;
6712
9360ffd1
DM
6713 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6714 goto nla_put_failure;
ffb9eb3d
KV
6715
6716 genlmsg_end(msg, hdr);
4c476991 6717 return genlmsg_reply(msg, info);
ffb9eb3d 6718
4c476991 6719 nla_put_failure:
ffb9eb3d 6720 err = -ENOBUFS;
4c476991 6721 free_msg:
ffb9eb3d 6722 nlmsg_free(msg);
ffb9eb3d
KV
6723 return err;
6724}
6725
d6dc1a38
JO
6726static struct nla_policy
6727nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6728 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6729 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6730 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
6731 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
6732 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
6733 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
6734};
6735
84f10708 6736static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 6737 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
6738{
6739 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6740 struct wireless_dev *wdev;
6741 struct net_device *dev = info->user_ptr[1];
6742
d9d8b019 6743 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
6744 return -EINVAL;
6745
6746 wdev = dev->ieee80211_ptr;
6747
6748 if (!rdev->ops->set_cqm_txe_config)
6749 return -EOPNOTSUPP;
6750
6751 if (wdev->iftype != NL80211_IFTYPE_STATION &&
6752 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6753 return -EOPNOTSUPP;
6754
e35e4d28 6755 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
6756}
6757
d6dc1a38
JO
6758static int nl80211_set_cqm_rssi(struct genl_info *info,
6759 s32 threshold, u32 hysteresis)
6760{
4c476991 6761 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6762 struct wireless_dev *wdev;
4c476991 6763 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6764
6765 if (threshold > 0)
6766 return -EINVAL;
6767
d6dc1a38
JO
6768 wdev = dev->ieee80211_ptr;
6769
4c476991
JB
6770 if (!rdev->ops->set_cqm_rssi_config)
6771 return -EOPNOTSUPP;
d6dc1a38 6772
074ac8df 6773 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6774 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6775 return -EOPNOTSUPP;
d6dc1a38 6776
e35e4d28 6777 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
6778}
6779
6780static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6781{
6782 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6783 struct nlattr *cqm;
6784 int err;
6785
6786 cqm = info->attrs[NL80211_ATTR_CQM];
6787 if (!cqm) {
6788 err = -EINVAL;
6789 goto out;
6790 }
6791
6792 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6793 nl80211_attr_cqm_policy);
6794 if (err)
6795 goto out;
6796
6797 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6798 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6799 s32 threshold;
6800 u32 hysteresis;
6801 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6802 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6803 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
84f10708
TP
6804 } else if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
6805 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
6806 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
6807 u32 rate, pkts, intvl;
6808 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
6809 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
6810 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
6811 err = nl80211_set_cqm_txe(info, rate, pkts, intvl);
d6dc1a38
JO
6812 } else
6813 err = -EINVAL;
6814
6815out:
6816 return err;
6817}
6818
29cbe68c
JB
6819static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6820{
6821 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6822 struct net_device *dev = info->user_ptr[1];
6823 struct mesh_config cfg;
c80d545d 6824 struct mesh_setup setup;
29cbe68c
JB
6825 int err;
6826
6827 /* start with default */
6828 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6829 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6830
24bdd9f4 6831 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6832 /* and parse parameters if given */
24bdd9f4 6833 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6834 if (err)
6835 return err;
6836 }
6837
6838 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6839 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6840 return -EINVAL;
6841
c80d545d
JC
6842 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6843 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6844
4bb62344
CYY
6845 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6846 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6847 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6848 return -EINVAL;
6849
9bdbf04d
MP
6850 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6851 setup.beacon_interval =
6852 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6853 if (setup.beacon_interval < 10 ||
6854 setup.beacon_interval > 10000)
6855 return -EINVAL;
6856 }
6857
6858 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
6859 setup.dtim_period =
6860 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
6861 if (setup.dtim_period < 1 || setup.dtim_period > 100)
6862 return -EINVAL;
6863 }
6864
c80d545d
JC
6865 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6866 /* parse additional setup parameters if given */
6867 err = nl80211_parse_mesh_setup(info, &setup);
6868 if (err)
6869 return err;
6870 }
6871
cc1d2806 6872 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
6873 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
6874 if (err)
6875 return err;
cc1d2806
JB
6876 } else {
6877 /* cfg80211_join_mesh() will sort it out */
683b6d3b 6878 setup.chandef.chan = NULL;
cc1d2806
JB
6879 }
6880
c80d545d 6881 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6882}
6883
6884static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6885{
6886 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6887 struct net_device *dev = info->user_ptr[1];
6888
6889 return cfg80211_leave_mesh(rdev, dev);
6890}
6891
dfb89c56 6892#ifdef CONFIG_PM
ff1b6e69
JB
6893static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6894{
6895 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6896 struct sk_buff *msg;
6897 void *hdr;
6898
6899 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6900 return -EOPNOTSUPP;
6901
6902 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6903 if (!msg)
6904 return -ENOMEM;
6905
15e47304 6906 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
6907 NL80211_CMD_GET_WOWLAN);
6908 if (!hdr)
6909 goto nla_put_failure;
6910
6911 if (rdev->wowlan) {
6912 struct nlattr *nl_wowlan;
6913
6914 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6915 if (!nl_wowlan)
6916 goto nla_put_failure;
6917
9360ffd1
DM
6918 if ((rdev->wowlan->any &&
6919 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6920 (rdev->wowlan->disconnect &&
6921 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6922 (rdev->wowlan->magic_pkt &&
6923 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6924 (rdev->wowlan->gtk_rekey_failure &&
6925 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6926 (rdev->wowlan->eap_identity_req &&
6927 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6928 (rdev->wowlan->four_way_handshake &&
6929 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6930 (rdev->wowlan->rfkill_release &&
6931 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6932 goto nla_put_failure;
ff1b6e69
JB
6933 if (rdev->wowlan->n_patterns) {
6934 struct nlattr *nl_pats, *nl_pat;
6935 int i, pat_len;
6936
6937 nl_pats = nla_nest_start(msg,
6938 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6939 if (!nl_pats)
6940 goto nla_put_failure;
6941
6942 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6943 nl_pat = nla_nest_start(msg, i + 1);
6944 if (!nl_pat)
6945 goto nla_put_failure;
6946 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6947 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6948 DIV_ROUND_UP(pat_len, 8),
6949 rdev->wowlan->patterns[i].mask) ||
6950 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6951 pat_len,
6952 rdev->wowlan->patterns[i].pattern))
6953 goto nla_put_failure;
ff1b6e69
JB
6954 nla_nest_end(msg, nl_pat);
6955 }
6956 nla_nest_end(msg, nl_pats);
6957 }
6958
6959 nla_nest_end(msg, nl_wowlan);
6960 }
6961
6962 genlmsg_end(msg, hdr);
6963 return genlmsg_reply(msg, info);
6964
6965nla_put_failure:
6966 nlmsg_free(msg);
6967 return -ENOBUFS;
6968}
6969
6970static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6971{
6972 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6973 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 6974 struct cfg80211_wowlan new_triggers = {};
ae33bd81 6975 struct cfg80211_wowlan *ntrig;
ff1b6e69
JB
6976 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6977 int err, i;
6d52563f 6978 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6979
6980 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6981 return -EOPNOTSUPP;
6982
ae33bd81
JB
6983 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
6984 cfg80211_rdev_free_wowlan(rdev);
6985 rdev->wowlan = NULL;
6986 goto set_wakeup;
6987 }
ff1b6e69
JB
6988
6989 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6990 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6991 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6992 nl80211_wowlan_policy);
6993 if (err)
6994 return err;
6995
6996 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6997 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6998 return -EINVAL;
6999 new_triggers.any = true;
7000 }
7001
7002 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
7003 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
7004 return -EINVAL;
7005 new_triggers.disconnect = true;
7006 }
7007
7008 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
7009 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
7010 return -EINVAL;
7011 new_triggers.magic_pkt = true;
7012 }
7013
77dbbb13
JB
7014 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
7015 return -EINVAL;
7016
7017 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
7018 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
7019 return -EINVAL;
7020 new_triggers.gtk_rekey_failure = true;
7021 }
7022
7023 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
7024 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
7025 return -EINVAL;
7026 new_triggers.eap_identity_req = true;
7027 }
7028
7029 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
7030 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
7031 return -EINVAL;
7032 new_triggers.four_way_handshake = true;
7033 }
7034
7035 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
7036 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
7037 return -EINVAL;
7038 new_triggers.rfkill_release = true;
7039 }
7040
ff1b6e69
JB
7041 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
7042 struct nlattr *pat;
7043 int n_patterns = 0;
7044 int rem, pat_len, mask_len;
7045 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
7046
7047 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7048 rem)
7049 n_patterns++;
7050 if (n_patterns > wowlan->n_patterns)
7051 return -EINVAL;
7052
7053 new_triggers.patterns = kcalloc(n_patterns,
7054 sizeof(new_triggers.patterns[0]),
7055 GFP_KERNEL);
7056 if (!new_triggers.patterns)
7057 return -ENOMEM;
7058
7059 new_triggers.n_patterns = n_patterns;
7060 i = 0;
7061
7062 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7063 rem) {
7064 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
7065 nla_data(pat), nla_len(pat), NULL);
7066 err = -EINVAL;
7067 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
7068 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
7069 goto error;
7070 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
7071 mask_len = DIV_ROUND_UP(pat_len, 8);
7072 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
7073 mask_len)
7074 goto error;
7075 if (pat_len > wowlan->pattern_max_len ||
7076 pat_len < wowlan->pattern_min_len)
7077 goto error;
7078
7079 new_triggers.patterns[i].mask =
7080 kmalloc(mask_len + pat_len, GFP_KERNEL);
7081 if (!new_triggers.patterns[i].mask) {
7082 err = -ENOMEM;
7083 goto error;
7084 }
7085 new_triggers.patterns[i].pattern =
7086 new_triggers.patterns[i].mask + mask_len;
7087 memcpy(new_triggers.patterns[i].mask,
7088 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
7089 mask_len);
7090 new_triggers.patterns[i].pattern_len = pat_len;
7091 memcpy(new_triggers.patterns[i].pattern,
7092 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
7093 pat_len);
7094 i++;
7095 }
7096 }
7097
ae33bd81
JB
7098 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
7099 if (!ntrig) {
7100 err = -ENOMEM;
7101 goto error;
ff1b6e69 7102 }
ae33bd81
JB
7103 cfg80211_rdev_free_wowlan(rdev);
7104 rdev->wowlan = ntrig;
ff1b6e69 7105
ae33bd81 7106 set_wakeup:
6d52563f 7107 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
e35e4d28 7108 rdev_set_wakeup(rdev, rdev->wowlan);
6d52563f 7109
ff1b6e69
JB
7110 return 0;
7111 error:
7112 for (i = 0; i < new_triggers.n_patterns; i++)
7113 kfree(new_triggers.patterns[i].mask);
7114 kfree(new_triggers.patterns);
7115 return err;
7116}
dfb89c56 7117#endif
ff1b6e69 7118
e5497d76
JB
7119static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
7120{
7121 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7122 struct net_device *dev = info->user_ptr[1];
7123 struct wireless_dev *wdev = dev->ieee80211_ptr;
7124 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
7125 struct cfg80211_gtk_rekey_data rekey_data;
7126 int err;
7127
7128 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
7129 return -EINVAL;
7130
7131 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
7132 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
7133 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
7134 nl80211_rekey_policy);
7135 if (err)
7136 return err;
7137
7138 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
7139 return -ERANGE;
7140 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
7141 return -ERANGE;
7142 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
7143 return -ERANGE;
7144
7145 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
7146 NL80211_KEK_LEN);
7147 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
7148 NL80211_KCK_LEN);
7149 memcpy(rekey_data.replay_ctr,
7150 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
7151 NL80211_REPLAY_CTR_LEN);
7152
7153 wdev_lock(wdev);
7154 if (!wdev->current_bss) {
7155 err = -ENOTCONN;
7156 goto out;
7157 }
7158
7159 if (!rdev->ops->set_rekey_data) {
7160 err = -EOPNOTSUPP;
7161 goto out;
7162 }
7163
e35e4d28 7164 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
7165 out:
7166 wdev_unlock(wdev);
7167 return err;
7168}
7169
28946da7
JB
7170static int nl80211_register_unexpected_frame(struct sk_buff *skb,
7171 struct genl_info *info)
7172{
7173 struct net_device *dev = info->user_ptr[1];
7174 struct wireless_dev *wdev = dev->ieee80211_ptr;
7175
7176 if (wdev->iftype != NL80211_IFTYPE_AP &&
7177 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7178 return -EINVAL;
7179
15e47304 7180 if (wdev->ap_unexpected_nlportid)
28946da7
JB
7181 return -EBUSY;
7182
15e47304 7183 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
7184 return 0;
7185}
7186
7f6cf311
JB
7187static int nl80211_probe_client(struct sk_buff *skb,
7188 struct genl_info *info)
7189{
7190 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7191 struct net_device *dev = info->user_ptr[1];
7192 struct wireless_dev *wdev = dev->ieee80211_ptr;
7193 struct sk_buff *msg;
7194 void *hdr;
7195 const u8 *addr;
7196 u64 cookie;
7197 int err;
7198
7199 if (wdev->iftype != NL80211_IFTYPE_AP &&
7200 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7201 return -EOPNOTSUPP;
7202
7203 if (!info->attrs[NL80211_ATTR_MAC])
7204 return -EINVAL;
7205
7206 if (!rdev->ops->probe_client)
7207 return -EOPNOTSUPP;
7208
7209 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7210 if (!msg)
7211 return -ENOMEM;
7212
15e47304 7213 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311
JB
7214 NL80211_CMD_PROBE_CLIENT);
7215
7216 if (IS_ERR(hdr)) {
7217 err = PTR_ERR(hdr);
7218 goto free_msg;
7219 }
7220
7221 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7222
e35e4d28 7223 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
7224 if (err)
7225 goto free_msg;
7226
9360ffd1
DM
7227 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7228 goto nla_put_failure;
7f6cf311
JB
7229
7230 genlmsg_end(msg, hdr);
7231
7232 return genlmsg_reply(msg, info);
7233
7234 nla_put_failure:
7235 err = -ENOBUFS;
7236 free_msg:
7237 nlmsg_free(msg);
7238 return err;
7239}
7240
5e760230
JB
7241static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
7242{
7243 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
7244 struct cfg80211_beacon_registration *reg, *nreg;
7245 int rv;
5e760230
JB
7246
7247 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
7248 return -EOPNOTSUPP;
7249
37c73b5f
BG
7250 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
7251 if (!nreg)
7252 return -ENOMEM;
7253
7254 /* First, check if already registered. */
7255 spin_lock_bh(&rdev->beacon_registrations_lock);
7256 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
7257 if (reg->nlportid == info->snd_portid) {
7258 rv = -EALREADY;
7259 goto out_err;
7260 }
7261 }
7262 /* Add it to the list */
7263 nreg->nlportid = info->snd_portid;
7264 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 7265
37c73b5f 7266 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
7267
7268 return 0;
37c73b5f
BG
7269out_err:
7270 spin_unlock_bh(&rdev->beacon_registrations_lock);
7271 kfree(nreg);
7272 return rv;
5e760230
JB
7273}
7274
98104fde
JB
7275static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
7276{
7277 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7278 struct wireless_dev *wdev = info->user_ptr[1];
7279 int err;
7280
7281 if (!rdev->ops->start_p2p_device)
7282 return -EOPNOTSUPP;
7283
7284 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7285 return -EOPNOTSUPP;
7286
7287 if (wdev->p2p_started)
7288 return 0;
7289
7290 mutex_lock(&rdev->devlist_mtx);
7291 err = cfg80211_can_add_interface(rdev, wdev->iftype);
7292 mutex_unlock(&rdev->devlist_mtx);
7293 if (err)
7294 return err;
7295
eeb126e9 7296 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
7297 if (err)
7298 return err;
7299
7300 wdev->p2p_started = true;
7301 mutex_lock(&rdev->devlist_mtx);
7302 rdev->opencount++;
7303 mutex_unlock(&rdev->devlist_mtx);
7304
7305 return 0;
7306}
7307
7308static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
7309{
7310 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7311 struct wireless_dev *wdev = info->user_ptr[1];
7312
7313 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7314 return -EOPNOTSUPP;
7315
7316 if (!rdev->ops->stop_p2p_device)
7317 return -EOPNOTSUPP;
7318
7319 if (!wdev->p2p_started)
7320 return 0;
7321
eeb126e9 7322 rdev_stop_p2p_device(rdev, wdev);
98104fde
JB
7323 wdev->p2p_started = false;
7324
7325 mutex_lock(&rdev->devlist_mtx);
7326 rdev->opencount--;
7327 mutex_unlock(&rdev->devlist_mtx);
7328
7329 if (WARN_ON(rdev->scan_req && rdev->scan_req->wdev == wdev)) {
7330 rdev->scan_req->aborted = true;
7331 ___cfg80211_scan_done(rdev, true);
7332 }
7333
7334 return 0;
7335}
7336
4c476991
JB
7337#define NL80211_FLAG_NEED_WIPHY 0x01
7338#define NL80211_FLAG_NEED_NETDEV 0x02
7339#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
7340#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
7341#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
7342 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 7343#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 7344/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
7345#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
7346 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
7347
7348static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
7349 struct genl_info *info)
7350{
7351 struct cfg80211_registered_device *rdev;
89a54e48 7352 struct wireless_dev *wdev;
4c476991 7353 struct net_device *dev;
4c476991
JB
7354 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
7355
7356 if (rtnl)
7357 rtnl_lock();
7358
7359 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 7360 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
7361 if (IS_ERR(rdev)) {
7362 if (rtnl)
7363 rtnl_unlock();
7364 return PTR_ERR(rdev);
7365 }
7366 info->user_ptr[0] = rdev;
1bf614ef
JB
7367 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
7368 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
89a54e48
JB
7369 mutex_lock(&cfg80211_mutex);
7370 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
7371 info->attrs);
7372 if (IS_ERR(wdev)) {
7373 mutex_unlock(&cfg80211_mutex);
4c476991
JB
7374 if (rtnl)
7375 rtnl_unlock();
89a54e48 7376 return PTR_ERR(wdev);
4c476991 7377 }
89a54e48 7378
89a54e48
JB
7379 dev = wdev->netdev;
7380 rdev = wiphy_to_dev(wdev->wiphy);
7381
1bf614ef
JB
7382 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
7383 if (!dev) {
7384 mutex_unlock(&cfg80211_mutex);
7385 if (rtnl)
7386 rtnl_unlock();
7387 return -EINVAL;
7388 }
7389
7390 info->user_ptr[1] = dev;
7391 } else {
7392 info->user_ptr[1] = wdev;
41265714 7393 }
1bf614ef
JB
7394
7395 if (dev) {
7396 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
7397 !netif_running(dev)) {
7398 mutex_unlock(&cfg80211_mutex);
7399 if (rtnl)
7400 rtnl_unlock();
7401 return -ENETDOWN;
7402 }
7403
7404 dev_hold(dev);
98104fde
JB
7405 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
7406 if (!wdev->p2p_started) {
7407 mutex_unlock(&cfg80211_mutex);
7408 if (rtnl)
7409 rtnl_unlock();
7410 return -ENETDOWN;
7411 }
41265714 7412 }
89a54e48 7413
89a54e48
JB
7414 cfg80211_lock_rdev(rdev);
7415
7416 mutex_unlock(&cfg80211_mutex);
7417
4c476991 7418 info->user_ptr[0] = rdev;
4c476991
JB
7419 }
7420
7421 return 0;
7422}
7423
7424static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
7425 struct genl_info *info)
7426{
7427 if (info->user_ptr[0])
7428 cfg80211_unlock_rdev(info->user_ptr[0]);
1bf614ef
JB
7429 if (info->user_ptr[1]) {
7430 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
7431 struct wireless_dev *wdev = info->user_ptr[1];
7432
7433 if (wdev->netdev)
7434 dev_put(wdev->netdev);
7435 } else {
7436 dev_put(info->user_ptr[1]);
7437 }
7438 }
4c476991
JB
7439 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
7440 rtnl_unlock();
7441}
7442
55682965
JB
7443static struct genl_ops nl80211_ops[] = {
7444 {
7445 .cmd = NL80211_CMD_GET_WIPHY,
7446 .doit = nl80211_get_wiphy,
7447 .dumpit = nl80211_dump_wiphy,
7448 .policy = nl80211_policy,
7449 /* can be retrieved by unprivileged users */
4c476991 7450 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
7451 },
7452 {
7453 .cmd = NL80211_CMD_SET_WIPHY,
7454 .doit = nl80211_set_wiphy,
7455 .policy = nl80211_policy,
7456 .flags = GENL_ADMIN_PERM,
4c476991 7457 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
7458 },
7459 {
7460 .cmd = NL80211_CMD_GET_INTERFACE,
7461 .doit = nl80211_get_interface,
7462 .dumpit = nl80211_dump_interface,
7463 .policy = nl80211_policy,
7464 /* can be retrieved by unprivileged users */
72fb2abc 7465 .internal_flags = NL80211_FLAG_NEED_WDEV,
55682965
JB
7466 },
7467 {
7468 .cmd = NL80211_CMD_SET_INTERFACE,
7469 .doit = nl80211_set_interface,
7470 .policy = nl80211_policy,
7471 .flags = GENL_ADMIN_PERM,
4c476991
JB
7472 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7473 NL80211_FLAG_NEED_RTNL,
55682965
JB
7474 },
7475 {
7476 .cmd = NL80211_CMD_NEW_INTERFACE,
7477 .doit = nl80211_new_interface,
7478 .policy = nl80211_policy,
7479 .flags = GENL_ADMIN_PERM,
4c476991
JB
7480 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7481 NL80211_FLAG_NEED_RTNL,
55682965
JB
7482 },
7483 {
7484 .cmd = NL80211_CMD_DEL_INTERFACE,
7485 .doit = nl80211_del_interface,
7486 .policy = nl80211_policy,
41ade00f 7487 .flags = GENL_ADMIN_PERM,
84efbb84 7488 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7489 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7490 },
7491 {
7492 .cmd = NL80211_CMD_GET_KEY,
7493 .doit = nl80211_get_key,
7494 .policy = nl80211_policy,
7495 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7496 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7497 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7498 },
7499 {
7500 .cmd = NL80211_CMD_SET_KEY,
7501 .doit = nl80211_set_key,
7502 .policy = nl80211_policy,
7503 .flags = GENL_ADMIN_PERM,
41265714 7504 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7505 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7506 },
7507 {
7508 .cmd = NL80211_CMD_NEW_KEY,
7509 .doit = nl80211_new_key,
7510 .policy = nl80211_policy,
7511 .flags = GENL_ADMIN_PERM,
41265714 7512 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7513 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7514 },
7515 {
7516 .cmd = NL80211_CMD_DEL_KEY,
7517 .doit = nl80211_del_key,
7518 .policy = nl80211_policy,
55682965 7519 .flags = GENL_ADMIN_PERM,
41265714 7520 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7521 NL80211_FLAG_NEED_RTNL,
55682965 7522 },
ed1b6cc7
JB
7523 {
7524 .cmd = NL80211_CMD_SET_BEACON,
7525 .policy = nl80211_policy,
7526 .flags = GENL_ADMIN_PERM,
8860020e 7527 .doit = nl80211_set_beacon,
2b5f8b0b 7528 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7529 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7530 },
7531 {
8860020e 7532 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
7533 .policy = nl80211_policy,
7534 .flags = GENL_ADMIN_PERM,
8860020e 7535 .doit = nl80211_start_ap,
2b5f8b0b 7536 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7537 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7538 },
7539 {
8860020e 7540 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
7541 .policy = nl80211_policy,
7542 .flags = GENL_ADMIN_PERM,
8860020e 7543 .doit = nl80211_stop_ap,
2b5f8b0b 7544 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7545 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 7546 },
5727ef1b
JB
7547 {
7548 .cmd = NL80211_CMD_GET_STATION,
7549 .doit = nl80211_get_station,
2ec600d6 7550 .dumpit = nl80211_dump_station,
5727ef1b 7551 .policy = nl80211_policy,
4c476991
JB
7552 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7553 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7554 },
7555 {
7556 .cmd = NL80211_CMD_SET_STATION,
7557 .doit = nl80211_set_station,
7558 .policy = nl80211_policy,
7559 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7560 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7561 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7562 },
7563 {
7564 .cmd = NL80211_CMD_NEW_STATION,
7565 .doit = nl80211_new_station,
7566 .policy = nl80211_policy,
7567 .flags = GENL_ADMIN_PERM,
41265714 7568 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7569 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7570 },
7571 {
7572 .cmd = NL80211_CMD_DEL_STATION,
7573 .doit = nl80211_del_station,
7574 .policy = nl80211_policy,
2ec600d6 7575 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7576 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7577 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7578 },
7579 {
7580 .cmd = NL80211_CMD_GET_MPATH,
7581 .doit = nl80211_get_mpath,
7582 .dumpit = nl80211_dump_mpath,
7583 .policy = nl80211_policy,
7584 .flags = GENL_ADMIN_PERM,
41265714 7585 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7586 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7587 },
7588 {
7589 .cmd = NL80211_CMD_SET_MPATH,
7590 .doit = nl80211_set_mpath,
7591 .policy = nl80211_policy,
7592 .flags = GENL_ADMIN_PERM,
41265714 7593 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7594 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7595 },
7596 {
7597 .cmd = NL80211_CMD_NEW_MPATH,
7598 .doit = nl80211_new_mpath,
7599 .policy = nl80211_policy,
7600 .flags = GENL_ADMIN_PERM,
41265714 7601 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7602 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7603 },
7604 {
7605 .cmd = NL80211_CMD_DEL_MPATH,
7606 .doit = nl80211_del_mpath,
7607 .policy = nl80211_policy,
9f1ba906 7608 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7609 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7610 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
7611 },
7612 {
7613 .cmd = NL80211_CMD_SET_BSS,
7614 .doit = nl80211_set_bss,
7615 .policy = nl80211_policy,
b2e1b302 7616 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7617 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7618 NL80211_FLAG_NEED_RTNL,
b2e1b302 7619 },
f130347c
LR
7620 {
7621 .cmd = NL80211_CMD_GET_REG,
7622 .doit = nl80211_get_reg,
7623 .policy = nl80211_policy,
7624 /* can be retrieved by unprivileged users */
7625 },
b2e1b302
LR
7626 {
7627 .cmd = NL80211_CMD_SET_REG,
7628 .doit = nl80211_set_reg,
7629 .policy = nl80211_policy,
7630 .flags = GENL_ADMIN_PERM,
7631 },
7632 {
7633 .cmd = NL80211_CMD_REQ_SET_REG,
7634 .doit = nl80211_req_set_reg,
7635 .policy = nl80211_policy,
93da9cc1 7636 .flags = GENL_ADMIN_PERM,
7637 },
7638 {
24bdd9f4
JC
7639 .cmd = NL80211_CMD_GET_MESH_CONFIG,
7640 .doit = nl80211_get_mesh_config,
93da9cc1 7641 .policy = nl80211_policy,
7642 /* can be retrieved by unprivileged users */
2b5f8b0b 7643 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7644 NL80211_FLAG_NEED_RTNL,
93da9cc1 7645 },
7646 {
24bdd9f4
JC
7647 .cmd = NL80211_CMD_SET_MESH_CONFIG,
7648 .doit = nl80211_update_mesh_config,
93da9cc1 7649 .policy = nl80211_policy,
9aed3cc1 7650 .flags = GENL_ADMIN_PERM,
29cbe68c 7651 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7652 NL80211_FLAG_NEED_RTNL,
9aed3cc1 7653 },
2a519311
JB
7654 {
7655 .cmd = NL80211_CMD_TRIGGER_SCAN,
7656 .doit = nl80211_trigger_scan,
7657 .policy = nl80211_policy,
7658 .flags = GENL_ADMIN_PERM,
fd014284 7659 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7660 NL80211_FLAG_NEED_RTNL,
2a519311
JB
7661 },
7662 {
7663 .cmd = NL80211_CMD_GET_SCAN,
7664 .policy = nl80211_policy,
7665 .dumpit = nl80211_dump_scan,
7666 },
807f8a8c
LC
7667 {
7668 .cmd = NL80211_CMD_START_SCHED_SCAN,
7669 .doit = nl80211_start_sched_scan,
7670 .policy = nl80211_policy,
7671 .flags = GENL_ADMIN_PERM,
7672 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7673 NL80211_FLAG_NEED_RTNL,
7674 },
7675 {
7676 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
7677 .doit = nl80211_stop_sched_scan,
7678 .policy = nl80211_policy,
7679 .flags = GENL_ADMIN_PERM,
7680 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7681 NL80211_FLAG_NEED_RTNL,
7682 },
636a5d36
JM
7683 {
7684 .cmd = NL80211_CMD_AUTHENTICATE,
7685 .doit = nl80211_authenticate,
7686 .policy = nl80211_policy,
7687 .flags = GENL_ADMIN_PERM,
41265714 7688 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7689 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7690 },
7691 {
7692 .cmd = NL80211_CMD_ASSOCIATE,
7693 .doit = nl80211_associate,
7694 .policy = nl80211_policy,
7695 .flags = GENL_ADMIN_PERM,
41265714 7696 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7697 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7698 },
7699 {
7700 .cmd = NL80211_CMD_DEAUTHENTICATE,
7701 .doit = nl80211_deauthenticate,
7702 .policy = nl80211_policy,
7703 .flags = GENL_ADMIN_PERM,
41265714 7704 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7705 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7706 },
7707 {
7708 .cmd = NL80211_CMD_DISASSOCIATE,
7709 .doit = nl80211_disassociate,
7710 .policy = nl80211_policy,
7711 .flags = GENL_ADMIN_PERM,
41265714 7712 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7713 NL80211_FLAG_NEED_RTNL,
636a5d36 7714 },
04a773ad
JB
7715 {
7716 .cmd = NL80211_CMD_JOIN_IBSS,
7717 .doit = nl80211_join_ibss,
7718 .policy = nl80211_policy,
7719 .flags = GENL_ADMIN_PERM,
41265714 7720 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7721 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
7722 },
7723 {
7724 .cmd = NL80211_CMD_LEAVE_IBSS,
7725 .doit = nl80211_leave_ibss,
7726 .policy = nl80211_policy,
7727 .flags = GENL_ADMIN_PERM,
41265714 7728 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7729 NL80211_FLAG_NEED_RTNL,
04a773ad 7730 },
aff89a9b
JB
7731#ifdef CONFIG_NL80211_TESTMODE
7732 {
7733 .cmd = NL80211_CMD_TESTMODE,
7734 .doit = nl80211_testmode_do,
71063f0e 7735 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
7736 .policy = nl80211_policy,
7737 .flags = GENL_ADMIN_PERM,
4c476991
JB
7738 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7739 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
7740 },
7741#endif
b23aa676
SO
7742 {
7743 .cmd = NL80211_CMD_CONNECT,
7744 .doit = nl80211_connect,
7745 .policy = nl80211_policy,
7746 .flags = GENL_ADMIN_PERM,
41265714 7747 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7748 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
7749 },
7750 {
7751 .cmd = NL80211_CMD_DISCONNECT,
7752 .doit = nl80211_disconnect,
7753 .policy = nl80211_policy,
7754 .flags = GENL_ADMIN_PERM,
41265714 7755 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7756 NL80211_FLAG_NEED_RTNL,
b23aa676 7757 },
463d0183
JB
7758 {
7759 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
7760 .doit = nl80211_wiphy_netns,
7761 .policy = nl80211_policy,
7762 .flags = GENL_ADMIN_PERM,
4c476991
JB
7763 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7764 NL80211_FLAG_NEED_RTNL,
463d0183 7765 },
61fa713c
HS
7766 {
7767 .cmd = NL80211_CMD_GET_SURVEY,
7768 .policy = nl80211_policy,
7769 .dumpit = nl80211_dump_survey,
7770 },
67fbb16b
SO
7771 {
7772 .cmd = NL80211_CMD_SET_PMKSA,
7773 .doit = nl80211_setdel_pmksa,
7774 .policy = nl80211_policy,
7775 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7776 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7777 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7778 },
7779 {
7780 .cmd = NL80211_CMD_DEL_PMKSA,
7781 .doit = nl80211_setdel_pmksa,
7782 .policy = nl80211_policy,
7783 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7784 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7785 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7786 },
7787 {
7788 .cmd = NL80211_CMD_FLUSH_PMKSA,
7789 .doit = nl80211_flush_pmksa,
7790 .policy = nl80211_policy,
7791 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7792 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7793 NL80211_FLAG_NEED_RTNL,
67fbb16b 7794 },
9588bbd5
JM
7795 {
7796 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
7797 .doit = nl80211_remain_on_channel,
7798 .policy = nl80211_policy,
7799 .flags = GENL_ADMIN_PERM,
71bbc994 7800 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7801 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
7802 },
7803 {
7804 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7805 .doit = nl80211_cancel_remain_on_channel,
7806 .policy = nl80211_policy,
7807 .flags = GENL_ADMIN_PERM,
71bbc994 7808 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7809 NL80211_FLAG_NEED_RTNL,
9588bbd5 7810 },
13ae75b1
JM
7811 {
7812 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
7813 .doit = nl80211_set_tx_bitrate_mask,
7814 .policy = nl80211_policy,
7815 .flags = GENL_ADMIN_PERM,
4c476991
JB
7816 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7817 NL80211_FLAG_NEED_RTNL,
13ae75b1 7818 },
026331c4 7819 {
2e161f78
JB
7820 .cmd = NL80211_CMD_REGISTER_FRAME,
7821 .doit = nl80211_register_mgmt,
026331c4
JM
7822 .policy = nl80211_policy,
7823 .flags = GENL_ADMIN_PERM,
71bbc994 7824 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7825 NL80211_FLAG_NEED_RTNL,
026331c4
JM
7826 },
7827 {
2e161f78
JB
7828 .cmd = NL80211_CMD_FRAME,
7829 .doit = nl80211_tx_mgmt,
026331c4 7830 .policy = nl80211_policy,
f7ca38df 7831 .flags = GENL_ADMIN_PERM,
71bbc994 7832 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
7833 NL80211_FLAG_NEED_RTNL,
7834 },
7835 {
7836 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
7837 .doit = nl80211_tx_mgmt_cancel_wait,
7838 .policy = nl80211_policy,
026331c4 7839 .flags = GENL_ADMIN_PERM,
71bbc994 7840 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7841 NL80211_FLAG_NEED_RTNL,
026331c4 7842 },
ffb9eb3d
KV
7843 {
7844 .cmd = NL80211_CMD_SET_POWER_SAVE,
7845 .doit = nl80211_set_power_save,
7846 .policy = nl80211_policy,
7847 .flags = GENL_ADMIN_PERM,
4c476991
JB
7848 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7849 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
7850 },
7851 {
7852 .cmd = NL80211_CMD_GET_POWER_SAVE,
7853 .doit = nl80211_get_power_save,
7854 .policy = nl80211_policy,
7855 /* can be retrieved by unprivileged users */
4c476991
JB
7856 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7857 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 7858 },
d6dc1a38
JO
7859 {
7860 .cmd = NL80211_CMD_SET_CQM,
7861 .doit = nl80211_set_cqm,
7862 .policy = nl80211_policy,
7863 .flags = GENL_ADMIN_PERM,
4c476991
JB
7864 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7865 NL80211_FLAG_NEED_RTNL,
d6dc1a38 7866 },
f444de05
JB
7867 {
7868 .cmd = NL80211_CMD_SET_CHANNEL,
7869 .doit = nl80211_set_channel,
7870 .policy = nl80211_policy,
7871 .flags = GENL_ADMIN_PERM,
4c476991
JB
7872 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7873 NL80211_FLAG_NEED_RTNL,
f444de05 7874 },
e8347eba
BJ
7875 {
7876 .cmd = NL80211_CMD_SET_WDS_PEER,
7877 .doit = nl80211_set_wds_peer,
7878 .policy = nl80211_policy,
7879 .flags = GENL_ADMIN_PERM,
43b19952
JB
7880 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7881 NL80211_FLAG_NEED_RTNL,
e8347eba 7882 },
29cbe68c
JB
7883 {
7884 .cmd = NL80211_CMD_JOIN_MESH,
7885 .doit = nl80211_join_mesh,
7886 .policy = nl80211_policy,
7887 .flags = GENL_ADMIN_PERM,
7888 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7889 NL80211_FLAG_NEED_RTNL,
7890 },
7891 {
7892 .cmd = NL80211_CMD_LEAVE_MESH,
7893 .doit = nl80211_leave_mesh,
7894 .policy = nl80211_policy,
7895 .flags = GENL_ADMIN_PERM,
7896 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7897 NL80211_FLAG_NEED_RTNL,
7898 },
dfb89c56 7899#ifdef CONFIG_PM
ff1b6e69
JB
7900 {
7901 .cmd = NL80211_CMD_GET_WOWLAN,
7902 .doit = nl80211_get_wowlan,
7903 .policy = nl80211_policy,
7904 /* can be retrieved by unprivileged users */
7905 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7906 NL80211_FLAG_NEED_RTNL,
7907 },
7908 {
7909 .cmd = NL80211_CMD_SET_WOWLAN,
7910 .doit = nl80211_set_wowlan,
7911 .policy = nl80211_policy,
7912 .flags = GENL_ADMIN_PERM,
7913 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7914 NL80211_FLAG_NEED_RTNL,
7915 },
dfb89c56 7916#endif
e5497d76
JB
7917 {
7918 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7919 .doit = nl80211_set_rekey_data,
7920 .policy = nl80211_policy,
7921 .flags = GENL_ADMIN_PERM,
7922 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7923 NL80211_FLAG_NEED_RTNL,
7924 },
109086ce
AN
7925 {
7926 .cmd = NL80211_CMD_TDLS_MGMT,
7927 .doit = nl80211_tdls_mgmt,
7928 .policy = nl80211_policy,
7929 .flags = GENL_ADMIN_PERM,
7930 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7931 NL80211_FLAG_NEED_RTNL,
7932 },
7933 {
7934 .cmd = NL80211_CMD_TDLS_OPER,
7935 .doit = nl80211_tdls_oper,
7936 .policy = nl80211_policy,
7937 .flags = GENL_ADMIN_PERM,
7938 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7939 NL80211_FLAG_NEED_RTNL,
7940 },
28946da7
JB
7941 {
7942 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7943 .doit = nl80211_register_unexpected_frame,
7944 .policy = nl80211_policy,
7945 .flags = GENL_ADMIN_PERM,
7946 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7947 NL80211_FLAG_NEED_RTNL,
7948 },
7f6cf311
JB
7949 {
7950 .cmd = NL80211_CMD_PROBE_CLIENT,
7951 .doit = nl80211_probe_client,
7952 .policy = nl80211_policy,
7953 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7954 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7955 NL80211_FLAG_NEED_RTNL,
7956 },
5e760230
JB
7957 {
7958 .cmd = NL80211_CMD_REGISTER_BEACONS,
7959 .doit = nl80211_register_beacons,
7960 .policy = nl80211_policy,
7961 .flags = GENL_ADMIN_PERM,
7962 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7963 NL80211_FLAG_NEED_RTNL,
7964 },
1d9d9213
SW
7965 {
7966 .cmd = NL80211_CMD_SET_NOACK_MAP,
7967 .doit = nl80211_set_noack_map,
7968 .policy = nl80211_policy,
7969 .flags = GENL_ADMIN_PERM,
7970 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7971 NL80211_FLAG_NEED_RTNL,
7972 },
98104fde
JB
7973 {
7974 .cmd = NL80211_CMD_START_P2P_DEVICE,
7975 .doit = nl80211_start_p2p_device,
7976 .policy = nl80211_policy,
7977 .flags = GENL_ADMIN_PERM,
7978 .internal_flags = NL80211_FLAG_NEED_WDEV |
7979 NL80211_FLAG_NEED_RTNL,
7980 },
7981 {
7982 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
7983 .doit = nl80211_stop_p2p_device,
7984 .policy = nl80211_policy,
7985 .flags = GENL_ADMIN_PERM,
7986 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
7987 NL80211_FLAG_NEED_RTNL,
7988 },
f4e583c8
AQ
7989 {
7990 .cmd = NL80211_CMD_SET_MCAST_RATE,
7991 .doit = nl80211_set_mcast_rate,
77765eaf
VT
7992 .policy = nl80211_policy,
7993 .flags = GENL_ADMIN_PERM,
7994 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7995 NL80211_FLAG_NEED_RTNL,
7996 },
7997 {
7998 .cmd = NL80211_CMD_SET_MAC_ACL,
7999 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
8000 .policy = nl80211_policy,
8001 .flags = GENL_ADMIN_PERM,
8002 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8003 NL80211_FLAG_NEED_RTNL,
8004 },
55682965 8005};
9588bbd5 8006
6039f6d2
JM
8007static struct genl_multicast_group nl80211_mlme_mcgrp = {
8008 .name = "mlme",
8009};
55682965
JB
8010
8011/* multicast groups */
8012static struct genl_multicast_group nl80211_config_mcgrp = {
8013 .name = "config",
8014};
2a519311
JB
8015static struct genl_multicast_group nl80211_scan_mcgrp = {
8016 .name = "scan",
8017};
73d54c9e
LR
8018static struct genl_multicast_group nl80211_regulatory_mcgrp = {
8019 .name = "regulatory",
8020};
55682965
JB
8021
8022/* notification functions */
8023
8024void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
8025{
8026 struct sk_buff *msg;
8027
fd2120ca 8028 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
8029 if (!msg)
8030 return;
8031
8032 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
8033 nlmsg_free(msg);
8034 return;
8035 }
8036
463d0183
JB
8037 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8038 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
8039}
8040
362a415d
JB
8041static int nl80211_add_scan_req(struct sk_buff *msg,
8042 struct cfg80211_registered_device *rdev)
8043{
8044 struct cfg80211_scan_request *req = rdev->scan_req;
8045 struct nlattr *nest;
8046 int i;
8047
667503dd
JB
8048 ASSERT_RDEV_LOCK(rdev);
8049
362a415d
JB
8050 if (WARN_ON(!req))
8051 return 0;
8052
8053 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
8054 if (!nest)
8055 goto nla_put_failure;
9360ffd1
DM
8056 for (i = 0; i < req->n_ssids; i++) {
8057 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
8058 goto nla_put_failure;
8059 }
362a415d
JB
8060 nla_nest_end(msg, nest);
8061
8062 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
8063 if (!nest)
8064 goto nla_put_failure;
9360ffd1
DM
8065 for (i = 0; i < req->n_channels; i++) {
8066 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
8067 goto nla_put_failure;
8068 }
362a415d
JB
8069 nla_nest_end(msg, nest);
8070
9360ffd1
DM
8071 if (req->ie &&
8072 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
8073 goto nla_put_failure;
362a415d 8074
ed473771
SL
8075 if (req->flags)
8076 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
8077
362a415d
JB
8078 return 0;
8079 nla_put_failure:
8080 return -ENOBUFS;
8081}
8082
a538e2d5
JB
8083static int nl80211_send_scan_msg(struct sk_buff *msg,
8084 struct cfg80211_registered_device *rdev,
fd014284 8085 struct wireless_dev *wdev,
15e47304 8086 u32 portid, u32 seq, int flags,
a538e2d5 8087 u32 cmd)
2a519311
JB
8088{
8089 void *hdr;
8090
15e47304 8091 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
8092 if (!hdr)
8093 return -1;
8094
9360ffd1 8095 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
8096 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8097 wdev->netdev->ifindex)) ||
8098 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 8099 goto nla_put_failure;
2a519311 8100
362a415d
JB
8101 /* ignore errors and send incomplete event anyway */
8102 nl80211_add_scan_req(msg, rdev);
2a519311
JB
8103
8104 return genlmsg_end(msg, hdr);
8105
8106 nla_put_failure:
8107 genlmsg_cancel(msg, hdr);
8108 return -EMSGSIZE;
8109}
8110
807f8a8c
LC
8111static int
8112nl80211_send_sched_scan_msg(struct sk_buff *msg,
8113 struct cfg80211_registered_device *rdev,
8114 struct net_device *netdev,
15e47304 8115 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
8116{
8117 void *hdr;
8118
15e47304 8119 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
8120 if (!hdr)
8121 return -1;
8122
9360ffd1
DM
8123 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8124 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8125 goto nla_put_failure;
807f8a8c
LC
8126
8127 return genlmsg_end(msg, hdr);
8128
8129 nla_put_failure:
8130 genlmsg_cancel(msg, hdr);
8131 return -EMSGSIZE;
8132}
8133
a538e2d5 8134void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 8135 struct wireless_dev *wdev)
a538e2d5
JB
8136{
8137 struct sk_buff *msg;
8138
58050fce 8139 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
8140 if (!msg)
8141 return;
8142
fd014284 8143 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
8144 NL80211_CMD_TRIGGER_SCAN) < 0) {
8145 nlmsg_free(msg);
8146 return;
8147 }
8148
463d0183
JB
8149 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8150 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
8151}
8152
2a519311 8153void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 8154 struct wireless_dev *wdev)
2a519311
JB
8155{
8156 struct sk_buff *msg;
8157
fd2120ca 8158 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8159 if (!msg)
8160 return;
8161
fd014284 8162 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8163 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
8164 nlmsg_free(msg);
8165 return;
8166 }
8167
463d0183
JB
8168 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8169 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8170}
8171
8172void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 8173 struct wireless_dev *wdev)
2a519311
JB
8174{
8175 struct sk_buff *msg;
8176
fd2120ca 8177 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8178 if (!msg)
8179 return;
8180
fd014284 8181 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8182 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
8183 nlmsg_free(msg);
8184 return;
8185 }
8186
463d0183
JB
8187 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8188 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8189}
8190
807f8a8c
LC
8191void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
8192 struct net_device *netdev)
8193{
8194 struct sk_buff *msg;
8195
8196 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8197 if (!msg)
8198 return;
8199
8200 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
8201 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
8202 nlmsg_free(msg);
8203 return;
8204 }
8205
8206 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8207 nl80211_scan_mcgrp.id, GFP_KERNEL);
8208}
8209
8210void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
8211 struct net_device *netdev, u32 cmd)
8212{
8213 struct sk_buff *msg;
8214
58050fce 8215 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
8216 if (!msg)
8217 return;
8218
8219 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
8220 nlmsg_free(msg);
8221 return;
8222 }
8223
8224 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8225 nl80211_scan_mcgrp.id, GFP_KERNEL);
8226}
8227
73d54c9e
LR
8228/*
8229 * This can happen on global regulatory changes or device specific settings
8230 * based on custom world regulatory domains.
8231 */
8232void nl80211_send_reg_change_event(struct regulatory_request *request)
8233{
8234 struct sk_buff *msg;
8235 void *hdr;
8236
fd2120ca 8237 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
8238 if (!msg)
8239 return;
8240
8241 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
8242 if (!hdr) {
8243 nlmsg_free(msg);
8244 return;
8245 }
8246
8247 /* Userspace can always count this one always being set */
9360ffd1
DM
8248 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
8249 goto nla_put_failure;
8250
8251 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
8252 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8253 NL80211_REGDOM_TYPE_WORLD))
8254 goto nla_put_failure;
8255 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
8256 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8257 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
8258 goto nla_put_failure;
8259 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
8260 request->intersect) {
8261 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8262 NL80211_REGDOM_TYPE_INTERSECTION))
8263 goto nla_put_failure;
8264 } else {
8265 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8266 NL80211_REGDOM_TYPE_COUNTRY) ||
8267 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
8268 request->alpha2))
8269 goto nla_put_failure;
8270 }
8271
f4173766 8272 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
8273 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
8274 goto nla_put_failure;
73d54c9e 8275
3b7b72ee 8276 genlmsg_end(msg, hdr);
73d54c9e 8277
bc43b28c 8278 rcu_read_lock();
463d0183 8279 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
8280 GFP_ATOMIC);
8281 rcu_read_unlock();
73d54c9e
LR
8282
8283 return;
8284
8285nla_put_failure:
8286 genlmsg_cancel(msg, hdr);
8287 nlmsg_free(msg);
8288}
8289
6039f6d2
JM
8290static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
8291 struct net_device *netdev,
8292 const u8 *buf, size_t len,
e6d6e342 8293 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
8294{
8295 struct sk_buff *msg;
8296 void *hdr;
8297
e6d6e342 8298 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
8299 if (!msg)
8300 return;
8301
8302 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8303 if (!hdr) {
8304 nlmsg_free(msg);
8305 return;
8306 }
8307
9360ffd1
DM
8308 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8309 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8310 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8311 goto nla_put_failure;
6039f6d2 8312
3b7b72ee 8313 genlmsg_end(msg, hdr);
6039f6d2 8314
463d0183
JB
8315 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8316 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
8317 return;
8318
8319 nla_put_failure:
8320 genlmsg_cancel(msg, hdr);
8321 nlmsg_free(msg);
8322}
8323
8324void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8325 struct net_device *netdev, const u8 *buf,
8326 size_t len, gfp_t gfp)
6039f6d2
JM
8327{
8328 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8329 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
8330}
8331
8332void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
8333 struct net_device *netdev, const u8 *buf,
e6d6e342 8334 size_t len, gfp_t gfp)
6039f6d2 8335{
e6d6e342
JB
8336 nl80211_send_mlme_event(rdev, netdev, buf, len,
8337 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
8338}
8339
53b46b84 8340void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8341 struct net_device *netdev, const u8 *buf,
8342 size_t len, gfp_t gfp)
6039f6d2
JM
8343{
8344 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8345 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
8346}
8347
53b46b84
JM
8348void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
8349 struct net_device *netdev, const u8 *buf,
e6d6e342 8350 size_t len, gfp_t gfp)
6039f6d2
JM
8351{
8352 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8353 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
8354}
8355
cf4e594e
JM
8356void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
8357 struct net_device *netdev, const u8 *buf,
8358 size_t len, gfp_t gfp)
8359{
8360 nl80211_send_mlme_event(rdev, netdev, buf, len,
8361 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
8362}
8363
8364void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
8365 struct net_device *netdev, const u8 *buf,
8366 size_t len, gfp_t gfp)
8367{
8368 nl80211_send_mlme_event(rdev, netdev, buf, len,
8369 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
8370}
8371
1b06bb40
LR
8372static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
8373 struct net_device *netdev, int cmd,
e6d6e342 8374 const u8 *addr, gfp_t gfp)
1965c853
JM
8375{
8376 struct sk_buff *msg;
8377 void *hdr;
8378
e6d6e342 8379 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
8380 if (!msg)
8381 return;
8382
8383 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8384 if (!hdr) {
8385 nlmsg_free(msg);
8386 return;
8387 }
8388
9360ffd1
DM
8389 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8390 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8391 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
8392 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8393 goto nla_put_failure;
1965c853 8394
3b7b72ee 8395 genlmsg_end(msg, hdr);
1965c853 8396
463d0183
JB
8397 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8398 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
8399 return;
8400
8401 nla_put_failure:
8402 genlmsg_cancel(msg, hdr);
8403 nlmsg_free(msg);
8404}
8405
8406void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8407 struct net_device *netdev, const u8 *addr,
8408 gfp_t gfp)
1965c853
JM
8409{
8410 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 8411 addr, gfp);
1965c853
JM
8412}
8413
8414void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8415 struct net_device *netdev, const u8 *addr,
8416 gfp_t gfp)
1965c853 8417{
e6d6e342
JB
8418 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
8419 addr, gfp);
1965c853
JM
8420}
8421
b23aa676
SO
8422void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
8423 struct net_device *netdev, const u8 *bssid,
8424 const u8 *req_ie, size_t req_ie_len,
8425 const u8 *resp_ie, size_t resp_ie_len,
8426 u16 status, gfp_t gfp)
8427{
8428 struct sk_buff *msg;
8429 void *hdr;
8430
58050fce 8431 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8432 if (!msg)
8433 return;
8434
8435 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
8436 if (!hdr) {
8437 nlmsg_free(msg);
8438 return;
8439 }
8440
9360ffd1
DM
8441 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8442 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8443 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
8444 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
8445 (req_ie &&
8446 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8447 (resp_ie &&
8448 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8449 goto nla_put_failure;
b23aa676 8450
3b7b72ee 8451 genlmsg_end(msg, hdr);
b23aa676 8452
463d0183
JB
8453 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8454 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8455 return;
8456
8457 nla_put_failure:
8458 genlmsg_cancel(msg, hdr);
8459 nlmsg_free(msg);
8460
8461}
8462
8463void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
8464 struct net_device *netdev, const u8 *bssid,
8465 const u8 *req_ie, size_t req_ie_len,
8466 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
8467{
8468 struct sk_buff *msg;
8469 void *hdr;
8470
58050fce 8471 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8472 if (!msg)
8473 return;
8474
8475 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
8476 if (!hdr) {
8477 nlmsg_free(msg);
8478 return;
8479 }
8480
9360ffd1
DM
8481 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8482 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8483 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
8484 (req_ie &&
8485 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8486 (resp_ie &&
8487 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8488 goto nla_put_failure;
b23aa676 8489
3b7b72ee 8490 genlmsg_end(msg, hdr);
b23aa676 8491
463d0183
JB
8492 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8493 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8494 return;
8495
8496 nla_put_failure:
8497 genlmsg_cancel(msg, hdr);
8498 nlmsg_free(msg);
8499
8500}
8501
8502void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
8503 struct net_device *netdev, u16 reason,
667503dd 8504 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
8505{
8506 struct sk_buff *msg;
8507 void *hdr;
8508
58050fce 8509 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
8510 if (!msg)
8511 return;
8512
8513 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
8514 if (!hdr) {
8515 nlmsg_free(msg);
8516 return;
8517 }
8518
9360ffd1
DM
8519 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8520 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8521 (from_ap && reason &&
8522 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
8523 (from_ap &&
8524 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
8525 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
8526 goto nla_put_failure;
b23aa676 8527
3b7b72ee 8528 genlmsg_end(msg, hdr);
b23aa676 8529
463d0183
JB
8530 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8531 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
8532 return;
8533
8534 nla_put_failure:
8535 genlmsg_cancel(msg, hdr);
8536 nlmsg_free(msg);
8537
8538}
8539
04a773ad
JB
8540void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
8541 struct net_device *netdev, const u8 *bssid,
8542 gfp_t gfp)
8543{
8544 struct sk_buff *msg;
8545 void *hdr;
8546
fd2120ca 8547 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
8548 if (!msg)
8549 return;
8550
8551 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
8552 if (!hdr) {
8553 nlmsg_free(msg);
8554 return;
8555 }
8556
9360ffd1
DM
8557 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8558 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8559 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8560 goto nla_put_failure;
04a773ad 8561
3b7b72ee 8562 genlmsg_end(msg, hdr);
04a773ad 8563
463d0183
JB
8564 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8565 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
8566 return;
8567
8568 nla_put_failure:
8569 genlmsg_cancel(msg, hdr);
8570 nlmsg_free(msg);
8571}
8572
c93b5e71
JC
8573void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
8574 struct net_device *netdev,
8575 const u8 *macaddr, const u8* ie, u8 ie_len,
8576 gfp_t gfp)
8577{
8578 struct sk_buff *msg;
8579 void *hdr;
8580
8581 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8582 if (!msg)
8583 return;
8584
8585 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
8586 if (!hdr) {
8587 nlmsg_free(msg);
8588 return;
8589 }
8590
9360ffd1
DM
8591 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8592 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8593 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
8594 (ie_len && ie &&
8595 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
8596 goto nla_put_failure;
c93b5e71 8597
3b7b72ee 8598 genlmsg_end(msg, hdr);
c93b5e71
JC
8599
8600 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8601 nl80211_mlme_mcgrp.id, gfp);
8602 return;
8603
8604 nla_put_failure:
8605 genlmsg_cancel(msg, hdr);
8606 nlmsg_free(msg);
8607}
8608
a3b8b056
JM
8609void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
8610 struct net_device *netdev, const u8 *addr,
8611 enum nl80211_key_type key_type, int key_id,
e6d6e342 8612 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
8613{
8614 struct sk_buff *msg;
8615 void *hdr;
8616
e6d6e342 8617 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
8618 if (!msg)
8619 return;
8620
8621 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
8622 if (!hdr) {
8623 nlmsg_free(msg);
8624 return;
8625 }
8626
9360ffd1
DM
8627 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8628 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8629 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
8630 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
8631 (key_id != -1 &&
8632 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
8633 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
8634 goto nla_put_failure;
a3b8b056 8635
3b7b72ee 8636 genlmsg_end(msg, hdr);
a3b8b056 8637
463d0183
JB
8638 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8639 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
8640 return;
8641
8642 nla_put_failure:
8643 genlmsg_cancel(msg, hdr);
8644 nlmsg_free(msg);
8645}
8646
6bad8766
LR
8647void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
8648 struct ieee80211_channel *channel_before,
8649 struct ieee80211_channel *channel_after)
8650{
8651 struct sk_buff *msg;
8652 void *hdr;
8653 struct nlattr *nl_freq;
8654
fd2120ca 8655 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
8656 if (!msg)
8657 return;
8658
8659 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
8660 if (!hdr) {
8661 nlmsg_free(msg);
8662 return;
8663 }
8664
8665 /*
8666 * Since we are applying the beacon hint to a wiphy we know its
8667 * wiphy_idx is valid
8668 */
9360ffd1
DM
8669 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8670 goto nla_put_failure;
6bad8766
LR
8671
8672 /* Before */
8673 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
8674 if (!nl_freq)
8675 goto nla_put_failure;
8676 if (nl80211_msg_put_channel(msg, channel_before))
8677 goto nla_put_failure;
8678 nla_nest_end(msg, nl_freq);
8679
8680 /* After */
8681 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
8682 if (!nl_freq)
8683 goto nla_put_failure;
8684 if (nl80211_msg_put_channel(msg, channel_after))
8685 goto nla_put_failure;
8686 nla_nest_end(msg, nl_freq);
8687
3b7b72ee 8688 genlmsg_end(msg, hdr);
6bad8766 8689
463d0183
JB
8690 rcu_read_lock();
8691 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
8692 GFP_ATOMIC);
8693 rcu_read_unlock();
6bad8766
LR
8694
8695 return;
8696
8697nla_put_failure:
8698 genlmsg_cancel(msg, hdr);
8699 nlmsg_free(msg);
8700}
8701
9588bbd5
JM
8702static void nl80211_send_remain_on_chan_event(
8703 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 8704 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8705 struct ieee80211_channel *chan,
9588bbd5
JM
8706 unsigned int duration, gfp_t gfp)
8707{
8708 struct sk_buff *msg;
8709 void *hdr;
8710
8711 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8712 if (!msg)
8713 return;
8714
8715 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8716 if (!hdr) {
8717 nlmsg_free(msg);
8718 return;
8719 }
8720
9360ffd1 8721 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8722 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8723 wdev->netdev->ifindex)) ||
00f53350 8724 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 8725 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
8726 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
8727 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
8728 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8729 goto nla_put_failure;
9588bbd5 8730
9360ffd1
DM
8731 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
8732 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
8733 goto nla_put_failure;
9588bbd5 8734
3b7b72ee 8735 genlmsg_end(msg, hdr);
9588bbd5
JM
8736
8737 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8738 nl80211_mlme_mcgrp.id, gfp);
8739 return;
8740
8741 nla_put_failure:
8742 genlmsg_cancel(msg, hdr);
8743 nlmsg_free(msg);
8744}
8745
8746void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
71bbc994 8747 struct wireless_dev *wdev, u64 cookie,
9588bbd5 8748 struct ieee80211_channel *chan,
9588bbd5
JM
8749 unsigned int duration, gfp_t gfp)
8750{
8751 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 8752 rdev, wdev, cookie, chan,
42d97a59 8753 duration, gfp);
9588bbd5
JM
8754}
8755
8756void nl80211_send_remain_on_channel_cancel(
71bbc994
JB
8757 struct cfg80211_registered_device *rdev,
8758 struct wireless_dev *wdev,
42d97a59 8759 u64 cookie, struct ieee80211_channel *chan, gfp_t gfp)
9588bbd5
JM
8760{
8761 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 8762 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5
JM
8763}
8764
98b62183
JB
8765void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
8766 struct net_device *dev, const u8 *mac_addr,
8767 struct station_info *sinfo, gfp_t gfp)
8768{
8769 struct sk_buff *msg;
8770
58050fce 8771 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
8772 if (!msg)
8773 return;
8774
66266b3a
JL
8775 if (nl80211_send_station(msg, 0, 0, 0,
8776 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
8777 nlmsg_free(msg);
8778 return;
8779 }
8780
8781 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8782 nl80211_mlme_mcgrp.id, gfp);
8783}
8784
ec15e68b
JM
8785void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
8786 struct net_device *dev, const u8 *mac_addr,
8787 gfp_t gfp)
8788{
8789 struct sk_buff *msg;
8790 void *hdr;
8791
58050fce 8792 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
8793 if (!msg)
8794 return;
8795
8796 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
8797 if (!hdr) {
8798 nlmsg_free(msg);
8799 return;
8800 }
8801
9360ffd1
DM
8802 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8803 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
8804 goto nla_put_failure;
ec15e68b 8805
3b7b72ee 8806 genlmsg_end(msg, hdr);
ec15e68b
JM
8807
8808 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8809 nl80211_mlme_mcgrp.id, gfp);
8810 return;
8811
8812 nla_put_failure:
8813 genlmsg_cancel(msg, hdr);
8814 nlmsg_free(msg);
8815}
8816
ed44a951
PP
8817void nl80211_send_conn_failed_event(struct cfg80211_registered_device *rdev,
8818 struct net_device *dev, const u8 *mac_addr,
8819 enum nl80211_connect_failed_reason reason,
8820 gfp_t gfp)
8821{
8822 struct sk_buff *msg;
8823 void *hdr;
8824
8825 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8826 if (!msg)
8827 return;
8828
8829 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
8830 if (!hdr) {
8831 nlmsg_free(msg);
8832 return;
8833 }
8834
8835 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8836 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
8837 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
8838 goto nla_put_failure;
8839
8840 genlmsg_end(msg, hdr);
8841
8842 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8843 nl80211_mlme_mcgrp.id, gfp);
8844 return;
8845
8846 nla_put_failure:
8847 genlmsg_cancel(msg, hdr);
8848 nlmsg_free(msg);
8849}
8850
b92ab5d8
JB
8851static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
8852 const u8 *addr, gfp_t gfp)
28946da7
JB
8853{
8854 struct wireless_dev *wdev = dev->ieee80211_ptr;
8855 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8856 struct sk_buff *msg;
8857 void *hdr;
8858 int err;
15e47304 8859 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 8860
15e47304 8861 if (!nlportid)
28946da7
JB
8862 return false;
8863
8864 msg = nlmsg_new(100, gfp);
8865 if (!msg)
8866 return true;
8867
b92ab5d8 8868 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
8869 if (!hdr) {
8870 nlmsg_free(msg);
8871 return true;
8872 }
8873
9360ffd1
DM
8874 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8875 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8876 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8877 goto nla_put_failure;
28946da7
JB
8878
8879 err = genlmsg_end(msg, hdr);
8880 if (err < 0) {
8881 nlmsg_free(msg);
8882 return true;
8883 }
8884
15e47304 8885 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
8886 return true;
8887
8888 nla_put_failure:
8889 genlmsg_cancel(msg, hdr);
8890 nlmsg_free(msg);
8891 return true;
8892}
8893
b92ab5d8
JB
8894bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
8895{
8896 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
8897 addr, gfp);
8898}
8899
8900bool nl80211_unexpected_4addr_frame(struct net_device *dev,
8901 const u8 *addr, gfp_t gfp)
8902{
8903 return __nl80211_unexpected_frame(dev,
8904 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
8905 addr, gfp);
8906}
8907
2e161f78 8908int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 8909 struct wireless_dev *wdev, u32 nlportid,
804483e9
JB
8910 int freq, int sig_dbm,
8911 const u8 *buf, size_t len, gfp_t gfp)
026331c4 8912{
71bbc994 8913 struct net_device *netdev = wdev->netdev;
026331c4
JM
8914 struct sk_buff *msg;
8915 void *hdr;
026331c4
JM
8916
8917 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8918 if (!msg)
8919 return -ENOMEM;
8920
2e161f78 8921 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
8922 if (!hdr) {
8923 nlmsg_free(msg);
8924 return -ENOMEM;
8925 }
8926
9360ffd1 8927 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8928 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8929 netdev->ifindex)) ||
9360ffd1
DM
8930 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8931 (sig_dbm &&
8932 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8933 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8934 goto nla_put_failure;
026331c4 8935
3b7b72ee 8936 genlmsg_end(msg, hdr);
026331c4 8937
15e47304 8938 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
8939
8940 nla_put_failure:
8941 genlmsg_cancel(msg, hdr);
8942 nlmsg_free(msg);
8943 return -ENOBUFS;
8944}
8945
2e161f78 8946void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
71bbc994 8947 struct wireless_dev *wdev, u64 cookie,
2e161f78
JB
8948 const u8 *buf, size_t len, bool ack,
8949 gfp_t gfp)
026331c4 8950{
71bbc994 8951 struct net_device *netdev = wdev->netdev;
026331c4
JM
8952 struct sk_buff *msg;
8953 void *hdr;
8954
8955 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8956 if (!msg)
8957 return;
8958
2e161f78 8959 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8960 if (!hdr) {
8961 nlmsg_free(msg);
8962 return;
8963 }
8964
9360ffd1 8965 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
8966 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8967 netdev->ifindex)) ||
9360ffd1
DM
8968 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8969 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8970 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8971 goto nla_put_failure;
026331c4 8972
3b7b72ee 8973 genlmsg_end(msg, hdr);
026331c4
JM
8974
8975 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8976 return;
8977
8978 nla_put_failure:
8979 genlmsg_cancel(msg, hdr);
8980 nlmsg_free(msg);
8981}
8982
d6dc1a38
JO
8983void
8984nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8985 struct net_device *netdev,
8986 enum nl80211_cqm_rssi_threshold_event rssi_event,
8987 gfp_t gfp)
8988{
8989 struct sk_buff *msg;
8990 struct nlattr *pinfoattr;
8991 void *hdr;
8992
58050fce 8993 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
8994 if (!msg)
8995 return;
8996
8997 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8998 if (!hdr) {
8999 nlmsg_free(msg);
9000 return;
9001 }
9002
9360ffd1
DM
9003 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9004 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9005 goto nla_put_failure;
d6dc1a38
JO
9006
9007 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9008 if (!pinfoattr)
9009 goto nla_put_failure;
9010
9360ffd1
DM
9011 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
9012 rssi_event))
9013 goto nla_put_failure;
d6dc1a38
JO
9014
9015 nla_nest_end(msg, pinfoattr);
9016
3b7b72ee 9017 genlmsg_end(msg, hdr);
d6dc1a38
JO
9018
9019 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9020 nl80211_mlme_mcgrp.id, gfp);
9021 return;
9022
9023 nla_put_failure:
9024 genlmsg_cancel(msg, hdr);
9025 nlmsg_free(msg);
9026}
9027
e5497d76
JB
9028void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
9029 struct net_device *netdev, const u8 *bssid,
9030 const u8 *replay_ctr, gfp_t gfp)
9031{
9032 struct sk_buff *msg;
9033 struct nlattr *rekey_attr;
9034 void *hdr;
9035
58050fce 9036 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
9037 if (!msg)
9038 return;
9039
9040 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
9041 if (!hdr) {
9042 nlmsg_free(msg);
9043 return;
9044 }
9045
9360ffd1
DM
9046 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9047 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9048 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
9049 goto nla_put_failure;
e5497d76
JB
9050
9051 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
9052 if (!rekey_attr)
9053 goto nla_put_failure;
9054
9360ffd1
DM
9055 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
9056 NL80211_REPLAY_CTR_LEN, replay_ctr))
9057 goto nla_put_failure;
e5497d76
JB
9058
9059 nla_nest_end(msg, rekey_attr);
9060
3b7b72ee 9061 genlmsg_end(msg, hdr);
e5497d76
JB
9062
9063 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9064 nl80211_mlme_mcgrp.id, gfp);
9065 return;
9066
9067 nla_put_failure:
9068 genlmsg_cancel(msg, hdr);
9069 nlmsg_free(msg);
9070}
9071
c9df56b4
JM
9072void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
9073 struct net_device *netdev, int index,
9074 const u8 *bssid, bool preauth, gfp_t gfp)
9075{
9076 struct sk_buff *msg;
9077 struct nlattr *attr;
9078 void *hdr;
9079
58050fce 9080 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
9081 if (!msg)
9082 return;
9083
9084 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
9085 if (!hdr) {
9086 nlmsg_free(msg);
9087 return;
9088 }
9089
9360ffd1
DM
9090 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9091 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9092 goto nla_put_failure;
c9df56b4
JM
9093
9094 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
9095 if (!attr)
9096 goto nla_put_failure;
9097
9360ffd1
DM
9098 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
9099 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
9100 (preauth &&
9101 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
9102 goto nla_put_failure;
c9df56b4
JM
9103
9104 nla_nest_end(msg, attr);
9105
3b7b72ee 9106 genlmsg_end(msg, hdr);
c9df56b4
JM
9107
9108 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9109 nl80211_mlme_mcgrp.id, gfp);
9110 return;
9111
9112 nla_put_failure:
9113 genlmsg_cancel(msg, hdr);
9114 nlmsg_free(msg);
9115}
9116
5314526b 9117void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
683b6d3b
JB
9118 struct net_device *netdev,
9119 struct cfg80211_chan_def *chandef, gfp_t gfp)
5314526b
TP
9120{
9121 struct sk_buff *msg;
9122 void *hdr;
9123
58050fce 9124 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
9125 if (!msg)
9126 return;
9127
9128 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
9129 if (!hdr) {
9130 nlmsg_free(msg);
9131 return;
9132 }
9133
683b6d3b
JB
9134 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9135 goto nla_put_failure;
9136
9137 if (nl80211_send_chandef(msg, chandef))
7eab0f64 9138 goto nla_put_failure;
5314526b
TP
9139
9140 genlmsg_end(msg, hdr);
9141
9142 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9143 nl80211_mlme_mcgrp.id, gfp);
9144 return;
9145
9146 nla_put_failure:
9147 genlmsg_cancel(msg, hdr);
9148 nlmsg_free(msg);
9149}
9150
84f10708
TP
9151void
9152nl80211_send_cqm_txe_notify(struct cfg80211_registered_device *rdev,
9153 struct net_device *netdev, const u8 *peer,
9154 u32 num_packets, u32 rate, u32 intvl, gfp_t gfp)
9155{
9156 struct sk_buff *msg;
9157 struct nlattr *pinfoattr;
9158 void *hdr;
9159
9160 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
9161 if (!msg)
9162 return;
9163
9164 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9165 if (!hdr) {
9166 nlmsg_free(msg);
9167 return;
9168 }
9169
9170 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9171 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9172 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9173 goto nla_put_failure;
9174
9175 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9176 if (!pinfoattr)
9177 goto nla_put_failure;
9178
9179 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
9180 goto nla_put_failure;
9181
9182 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
9183 goto nla_put_failure;
9184
9185 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
9186 goto nla_put_failure;
9187
9188 nla_nest_end(msg, pinfoattr);
9189
9190 genlmsg_end(msg, hdr);
9191
9192 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9193 nl80211_mlme_mcgrp.id, gfp);
9194 return;
9195
9196 nla_put_failure:
9197 genlmsg_cancel(msg, hdr);
9198 nlmsg_free(msg);
9199}
9200
c063dbf5
JB
9201void
9202nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
9203 struct net_device *netdev, const u8 *peer,
9204 u32 num_packets, gfp_t gfp)
9205{
9206 struct sk_buff *msg;
9207 struct nlattr *pinfoattr;
9208 void *hdr;
9209
58050fce 9210 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
9211 if (!msg)
9212 return;
9213
9214 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9215 if (!hdr) {
9216 nlmsg_free(msg);
9217 return;
9218 }
9219
9360ffd1
DM
9220 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9221 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9222 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9223 goto nla_put_failure;
c063dbf5
JB
9224
9225 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9226 if (!pinfoattr)
9227 goto nla_put_failure;
9228
9360ffd1
DM
9229 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
9230 goto nla_put_failure;
c063dbf5
JB
9231
9232 nla_nest_end(msg, pinfoattr);
9233
3b7b72ee 9234 genlmsg_end(msg, hdr);
c063dbf5
JB
9235
9236 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9237 nl80211_mlme_mcgrp.id, gfp);
9238 return;
9239
9240 nla_put_failure:
9241 genlmsg_cancel(msg, hdr);
9242 nlmsg_free(msg);
9243}
9244
7f6cf311
JB
9245void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
9246 u64 cookie, bool acked, gfp_t gfp)
9247{
9248 struct wireless_dev *wdev = dev->ieee80211_ptr;
9249 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9250 struct sk_buff *msg;
9251 void *hdr;
9252 int err;
9253
4ee3e063
BL
9254 trace_cfg80211_probe_status(dev, addr, cookie, acked);
9255
58050fce 9256 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 9257
7f6cf311
JB
9258 if (!msg)
9259 return;
9260
9261 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
9262 if (!hdr) {
9263 nlmsg_free(msg);
9264 return;
9265 }
9266
9360ffd1
DM
9267 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9268 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9269 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9270 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
9271 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
9272 goto nla_put_failure;
7f6cf311
JB
9273
9274 err = genlmsg_end(msg, hdr);
9275 if (err < 0) {
9276 nlmsg_free(msg);
9277 return;
9278 }
9279
9280 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9281 nl80211_mlme_mcgrp.id, gfp);
9282 return;
9283
9284 nla_put_failure:
9285 genlmsg_cancel(msg, hdr);
9286 nlmsg_free(msg);
9287}
9288EXPORT_SYMBOL(cfg80211_probe_status);
9289
5e760230
JB
9290void cfg80211_report_obss_beacon(struct wiphy *wiphy,
9291 const u8 *frame, size_t len,
37c73b5f 9292 int freq, int sig_dbm)
5e760230
JB
9293{
9294 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9295 struct sk_buff *msg;
9296 void *hdr;
37c73b5f 9297 struct cfg80211_beacon_registration *reg;
5e760230 9298
4ee3e063
BL
9299 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
9300
37c73b5f
BG
9301 spin_lock_bh(&rdev->beacon_registrations_lock);
9302 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
9303 msg = nlmsg_new(len + 100, GFP_ATOMIC);
9304 if (!msg) {
9305 spin_unlock_bh(&rdev->beacon_registrations_lock);
9306 return;
9307 }
5e760230 9308
37c73b5f
BG
9309 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
9310 if (!hdr)
9311 goto nla_put_failure;
5e760230 9312
37c73b5f
BG
9313 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9314 (freq &&
9315 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
9316 (sig_dbm &&
9317 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9318 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
9319 goto nla_put_failure;
5e760230 9320
37c73b5f 9321 genlmsg_end(msg, hdr);
5e760230 9322
37c73b5f
BG
9323 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
9324 }
9325 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
9326 return;
9327
9328 nla_put_failure:
37c73b5f
BG
9329 spin_unlock_bh(&rdev->beacon_registrations_lock);
9330 if (hdr)
9331 genlmsg_cancel(msg, hdr);
5e760230
JB
9332 nlmsg_free(msg);
9333}
9334EXPORT_SYMBOL(cfg80211_report_obss_beacon);
9335
cd8f7cb4
JB
9336#ifdef CONFIG_PM
9337void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
9338 struct cfg80211_wowlan_wakeup *wakeup,
9339 gfp_t gfp)
9340{
9341 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9342 struct sk_buff *msg;
9343 void *hdr;
9344 int err, size = 200;
9345
9346 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
9347
9348 if (wakeup)
9349 size += wakeup->packet_present_len;
9350
9351 msg = nlmsg_new(size, gfp);
9352 if (!msg)
9353 return;
9354
9355 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
9356 if (!hdr)
9357 goto free_msg;
9358
9359 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9360 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9361 goto free_msg;
9362
9363 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9364 wdev->netdev->ifindex))
9365 goto free_msg;
9366
9367 if (wakeup) {
9368 struct nlattr *reasons;
9369
9370 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
9371
9372 if (wakeup->disconnect &&
9373 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
9374 goto free_msg;
9375 if (wakeup->magic_pkt &&
9376 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
9377 goto free_msg;
9378 if (wakeup->gtk_rekey_failure &&
9379 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
9380 goto free_msg;
9381 if (wakeup->eap_identity_req &&
9382 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
9383 goto free_msg;
9384 if (wakeup->four_way_handshake &&
9385 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
9386 goto free_msg;
9387 if (wakeup->rfkill_release &&
9388 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
9389 goto free_msg;
9390
9391 if (wakeup->pattern_idx >= 0 &&
9392 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
9393 wakeup->pattern_idx))
9394 goto free_msg;
9395
9396 if (wakeup->packet) {
9397 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
9398 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
9399
9400 if (!wakeup->packet_80211) {
9401 pkt_attr =
9402 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
9403 len_attr =
9404 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
9405 }
9406
9407 if (wakeup->packet_len &&
9408 nla_put_u32(msg, len_attr, wakeup->packet_len))
9409 goto free_msg;
9410
9411 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
9412 wakeup->packet))
9413 goto free_msg;
9414 }
9415
9416 nla_nest_end(msg, reasons);
9417 }
9418
9419 err = genlmsg_end(msg, hdr);
9420 if (err < 0)
9421 goto free_msg;
9422
9423 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9424 nl80211_mlme_mcgrp.id, gfp);
9425 return;
9426
9427 free_msg:
9428 nlmsg_free(msg);
9429}
9430EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
9431#endif
9432
3475b094
JM
9433void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
9434 enum nl80211_tdls_operation oper,
9435 u16 reason_code, gfp_t gfp)
9436{
9437 struct wireless_dev *wdev = dev->ieee80211_ptr;
9438 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9439 struct sk_buff *msg;
9440 void *hdr;
9441 int err;
9442
9443 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
9444 reason_code);
9445
9446 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9447 if (!msg)
9448 return;
9449
9450 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
9451 if (!hdr) {
9452 nlmsg_free(msg);
9453 return;
9454 }
9455
9456 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9457 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9458 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
9459 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
9460 (reason_code > 0 &&
9461 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
9462 goto nla_put_failure;
9463
9464 err = genlmsg_end(msg, hdr);
9465 if (err < 0) {
9466 nlmsg_free(msg);
9467 return;
9468 }
9469
9470 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9471 nl80211_mlme_mcgrp.id, gfp);
9472 return;
9473
9474 nla_put_failure:
9475 genlmsg_cancel(msg, hdr);
9476 nlmsg_free(msg);
9477}
9478EXPORT_SYMBOL(cfg80211_tdls_oper_request);
9479
026331c4
JM
9480static int nl80211_netlink_notify(struct notifier_block * nb,
9481 unsigned long state,
9482 void *_notify)
9483{
9484 struct netlink_notify *notify = _notify;
9485 struct cfg80211_registered_device *rdev;
9486 struct wireless_dev *wdev;
37c73b5f 9487 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
9488
9489 if (state != NETLINK_URELEASE)
9490 return NOTIFY_DONE;
9491
9492 rcu_read_lock();
9493
5e760230 9494 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 9495 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 9496 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
9497
9498 spin_lock_bh(&rdev->beacon_registrations_lock);
9499 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
9500 list) {
9501 if (reg->nlportid == notify->portid) {
9502 list_del(&reg->list);
9503 kfree(reg);
9504 break;
9505 }
9506 }
9507 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 9508 }
026331c4
JM
9509
9510 rcu_read_unlock();
9511
9512 return NOTIFY_DONE;
9513}
9514
9515static struct notifier_block nl80211_netlink_notifier = {
9516 .notifier_call = nl80211_netlink_notify,
9517};
9518
55682965
JB
9519/* initialisation/exit functions */
9520
9521int nl80211_init(void)
9522{
0d63cbb5 9523 int err;
55682965 9524
0d63cbb5
MM
9525 err = genl_register_family_with_ops(&nl80211_fam,
9526 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
9527 if (err)
9528 return err;
9529
55682965
JB
9530 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
9531 if (err)
9532 goto err_out;
9533
2a519311
JB
9534 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
9535 if (err)
9536 goto err_out;
9537
73d54c9e
LR
9538 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
9539 if (err)
9540 goto err_out;
9541
6039f6d2
JM
9542 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
9543 if (err)
9544 goto err_out;
9545
aff89a9b
JB
9546#ifdef CONFIG_NL80211_TESTMODE
9547 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
9548 if (err)
9549 goto err_out;
9550#endif
9551
026331c4
JM
9552 err = netlink_register_notifier(&nl80211_netlink_notifier);
9553 if (err)
9554 goto err_out;
9555
55682965
JB
9556 return 0;
9557 err_out:
9558 genl_unregister_family(&nl80211_fam);
9559 return err;
9560}
9561
9562void nl80211_exit(void)
9563{
026331c4 9564 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
9565 genl_unregister_family(&nl80211_fam);
9566}