]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
nl80211/mac80211: Perform PLINK_ACTION on new station
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
e31b8213 96 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
97
98 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101 .len = IEEE80211_MAX_DATA_LEN },
102 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
104 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 109 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 110 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 111 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
112 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113 .len = IEEE80211_MAX_MESH_ID_LEN },
114 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 115
b2e1b302
LR
116 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
9f1ba906
JM
119 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
122 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123 .len = NL80211_MAX_SUPP_RATES },
50b12f59 124 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 125
24bdd9f4 126 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 127 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 128
36aedc90
JM
129 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
130 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
131
132 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
133 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
134 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
135 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
136 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
137
138 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_SSID_LEN },
140 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
141 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 142 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 143 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 144 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
145 [NL80211_ATTR_STA_FLAGS2] = {
146 .len = sizeof(struct nl80211_sta_flag_update),
147 },
3f77316c 148 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
149 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
150 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
151 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
152 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
153 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 154 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 155 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
156 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
157 .len = WLAN_PMKID_LEN },
9588bbd5
JM
158 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
159 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 160 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
161 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
162 .len = IEEE80211_MAX_DATA_LEN },
163 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 164 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 165 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 166 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 167 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
168 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
169 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 170 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
171 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
172 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 173 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 174 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 175 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
55682965
JB
176};
177
e31b8213 178/* policy for the key attributes */
b54452b0 179static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 180 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
181 [NL80211_KEY_IDX] = { .type = NLA_U8 },
182 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
183 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
184 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
185 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 186 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
187 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
188};
189
190/* policy for the key default flags */
191static const struct nla_policy
192nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
193 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
194 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
195};
196
a043897a
HS
197/* ifidx get helper */
198static int nl80211_get_ifidx(struct netlink_callback *cb)
199{
200 int res;
201
202 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
203 nl80211_fam.attrbuf, nl80211_fam.maxattr,
204 nl80211_policy);
205 if (res)
206 return res;
207
208 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
209 return -EINVAL;
210
211 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
212 if (!res)
213 return -EINVAL;
214 return res;
215}
216
67748893
JB
217static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
218 struct netlink_callback *cb,
219 struct cfg80211_registered_device **rdev,
220 struct net_device **dev)
221{
222 int ifidx = cb->args[0];
223 int err;
224
225 if (!ifidx)
226 ifidx = nl80211_get_ifidx(cb);
227 if (ifidx < 0)
228 return ifidx;
229
230 cb->args[0] = ifidx;
231
232 rtnl_lock();
233
234 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
235 if (!*dev) {
236 err = -ENODEV;
237 goto out_rtnl;
238 }
239
240 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
241 if (IS_ERR(*rdev)) {
242 err = PTR_ERR(*rdev);
67748893
JB
243 goto out_rtnl;
244 }
245
246 return 0;
247 out_rtnl:
248 rtnl_unlock();
249 return err;
250}
251
252static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
253{
254 cfg80211_unlock_rdev(rdev);
255 rtnl_unlock();
256}
257
f4a11bb0
JB
258/* IE validation */
259static bool is_valid_ie_attr(const struct nlattr *attr)
260{
261 const u8 *pos;
262 int len;
263
264 if (!attr)
265 return true;
266
267 pos = nla_data(attr);
268 len = nla_len(attr);
269
270 while (len) {
271 u8 elemlen;
272
273 if (len < 2)
274 return false;
275 len -= 2;
276
277 elemlen = pos[1];
278 if (elemlen > len)
279 return false;
280
281 len -= elemlen;
282 pos += 2 + elemlen;
283 }
284
285 return true;
286}
287
55682965
JB
288/* message building helper */
289static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
290 int flags, u8 cmd)
291{
292 /* since there is no private header just add the generic one */
293 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
294}
295
5dab3b8a
LR
296static int nl80211_msg_put_channel(struct sk_buff *msg,
297 struct ieee80211_channel *chan)
298{
299 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
300 chan->center_freq);
301
302 if (chan->flags & IEEE80211_CHAN_DISABLED)
303 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
304 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
305 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
306 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
307 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
308 if (chan->flags & IEEE80211_CHAN_RADAR)
309 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
310
311 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
312 DBM_TO_MBM(chan->max_power));
313
314 return 0;
315
316 nla_put_failure:
317 return -ENOBUFS;
318}
319
55682965
JB
320/* netlink command implementations */
321
b9454e83
JB
322struct key_parse {
323 struct key_params p;
324 int idx;
e31b8213 325 int type;
b9454e83 326 bool def, defmgmt;
dbd2fd65 327 bool def_uni, def_multi;
b9454e83
JB
328};
329
330static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
331{
332 struct nlattr *tb[NL80211_KEY_MAX + 1];
333 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
334 nl80211_key_policy);
335 if (err)
336 return err;
337
338 k->def = !!tb[NL80211_KEY_DEFAULT];
339 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
340
dbd2fd65
JB
341 if (k->def) {
342 k->def_uni = true;
343 k->def_multi = true;
344 }
345 if (k->defmgmt)
346 k->def_multi = true;
347
b9454e83
JB
348 if (tb[NL80211_KEY_IDX])
349 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
350
351 if (tb[NL80211_KEY_DATA]) {
352 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
353 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
354 }
355
356 if (tb[NL80211_KEY_SEQ]) {
357 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
358 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
359 }
360
361 if (tb[NL80211_KEY_CIPHER])
362 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
363
e31b8213
JB
364 if (tb[NL80211_KEY_TYPE]) {
365 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
366 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
367 return -EINVAL;
368 }
369
dbd2fd65
JB
370 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
371 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
372 int err = nla_parse_nested(kdt,
373 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
374 tb[NL80211_KEY_DEFAULT_TYPES],
375 nl80211_key_default_policy);
376 if (err)
377 return err;
378
379 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
380 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
381 }
382
b9454e83
JB
383 return 0;
384}
385
386static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
387{
388 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
389 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
390 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
391 }
392
393 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
394 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
395 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
396 }
397
398 if (info->attrs[NL80211_ATTR_KEY_IDX])
399 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
400
401 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
402 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
403
404 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
405 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
406
dbd2fd65
JB
407 if (k->def) {
408 k->def_uni = true;
409 k->def_multi = true;
410 }
411 if (k->defmgmt)
412 k->def_multi = true;
413
e31b8213
JB
414 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
415 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
416 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
417 return -EINVAL;
418 }
419
dbd2fd65
JB
420 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
421 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
422 int err = nla_parse_nested(
423 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
424 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
425 nl80211_key_default_policy);
426 if (err)
427 return err;
428
429 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
430 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
431 }
432
b9454e83
JB
433 return 0;
434}
435
436static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
437{
438 int err;
439
440 memset(k, 0, sizeof(*k));
441 k->idx = -1;
e31b8213 442 k->type = -1;
b9454e83
JB
443
444 if (info->attrs[NL80211_ATTR_KEY])
445 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
446 else
447 err = nl80211_parse_key_old(info, k);
448
449 if (err)
450 return err;
451
452 if (k->def && k->defmgmt)
453 return -EINVAL;
454
dbd2fd65
JB
455 if (k->defmgmt) {
456 if (k->def_uni || !k->def_multi)
457 return -EINVAL;
458 }
459
b9454e83
JB
460 if (k->idx != -1) {
461 if (k->defmgmt) {
462 if (k->idx < 4 || k->idx > 5)
463 return -EINVAL;
464 } else if (k->def) {
465 if (k->idx < 0 || k->idx > 3)
466 return -EINVAL;
467 } else {
468 if (k->idx < 0 || k->idx > 5)
469 return -EINVAL;
470 }
471 }
472
473 return 0;
474}
475
fffd0934
JB
476static struct cfg80211_cached_keys *
477nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
478 struct nlattr *keys)
479{
480 struct key_parse parse;
481 struct nlattr *key;
482 struct cfg80211_cached_keys *result;
483 int rem, err, def = 0;
484
485 result = kzalloc(sizeof(*result), GFP_KERNEL);
486 if (!result)
487 return ERR_PTR(-ENOMEM);
488
489 result->def = -1;
490 result->defmgmt = -1;
491
492 nla_for_each_nested(key, keys, rem) {
493 memset(&parse, 0, sizeof(parse));
494 parse.idx = -1;
495
496 err = nl80211_parse_key_new(key, &parse);
497 if (err)
498 goto error;
499 err = -EINVAL;
500 if (!parse.p.key)
501 goto error;
502 if (parse.idx < 0 || parse.idx > 4)
503 goto error;
504 if (parse.def) {
505 if (def)
506 goto error;
507 def = 1;
508 result->def = parse.idx;
dbd2fd65
JB
509 if (!parse.def_uni || !parse.def_multi)
510 goto error;
fffd0934
JB
511 } else if (parse.defmgmt)
512 goto error;
513 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 514 parse.idx, false, NULL);
fffd0934
JB
515 if (err)
516 goto error;
517 result->params[parse.idx].cipher = parse.p.cipher;
518 result->params[parse.idx].key_len = parse.p.key_len;
519 result->params[parse.idx].key = result->data[parse.idx];
520 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
521 }
522
523 return result;
524 error:
525 kfree(result);
526 return ERR_PTR(err);
527}
528
529static int nl80211_key_allowed(struct wireless_dev *wdev)
530{
531 ASSERT_WDEV_LOCK(wdev);
532
fffd0934
JB
533 switch (wdev->iftype) {
534 case NL80211_IFTYPE_AP:
535 case NL80211_IFTYPE_AP_VLAN:
074ac8df 536 case NL80211_IFTYPE_P2P_GO:
fffd0934
JB
537 break;
538 case NL80211_IFTYPE_ADHOC:
539 if (!wdev->current_bss)
540 return -ENOLINK;
541 break;
542 case NL80211_IFTYPE_STATION:
074ac8df 543 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
544 if (wdev->sme_state != CFG80211_SME_CONNECTED)
545 return -ENOLINK;
546 break;
547 default:
548 return -EINVAL;
549 }
550
551 return 0;
552}
553
55682965
JB
554static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
555 struct cfg80211_registered_device *dev)
556{
557 void *hdr;
ee688b00
JB
558 struct nlattr *nl_bands, *nl_band;
559 struct nlattr *nl_freqs, *nl_freq;
560 struct nlattr *nl_rates, *nl_rate;
f59ac048 561 struct nlattr *nl_modes;
8fdc621d 562 struct nlattr *nl_cmds;
ee688b00
JB
563 enum ieee80211_band band;
564 struct ieee80211_channel *chan;
565 struct ieee80211_rate *rate;
566 int i;
f59ac048 567 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
568 const struct ieee80211_txrx_stypes *mgmt_stypes =
569 dev->wiphy.mgmt_stypes;
55682965
JB
570
571 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
572 if (!hdr)
573 return -1;
574
b5850a7a 575 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 576 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 577
f5ea9120
JB
578 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
579 cfg80211_rdev_list_generation);
580
b9a5f8ca
JM
581 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
582 dev->wiphy.retry_short);
583 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
584 dev->wiphy.retry_long);
585 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
586 dev->wiphy.frag_threshold);
587 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
588 dev->wiphy.rts_threshold);
81077e82
LT
589 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
590 dev->wiphy.coverage_class);
2a519311
JB
591 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
592 dev->wiphy.max_scan_ssids);
18a83659
JB
593 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
594 dev->wiphy.max_scan_ie_len);
ee688b00 595
e31b8213
JB
596 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
597 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
598 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
599 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
e31b8213 600
25e47c18
JB
601 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
602 sizeof(u32) * dev->wiphy.n_cipher_suites,
603 dev->wiphy.cipher_suites);
604
67fbb16b
SO
605 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
606 dev->wiphy.max_num_pmkids);
607
c0692b8f
JB
608 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
609 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
610
39fd5de4
BR
611 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
612 dev->wiphy.available_antennas_tx);
613 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
614 dev->wiphy.available_antennas_rx);
615
7f531e03
BR
616 if ((dev->wiphy.available_antennas_tx ||
617 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
618 u32 tx_ant = 0, rx_ant = 0;
619 int res;
620 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
621 if (!res) {
622 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
623 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
624 }
625 }
626
f59ac048
LR
627 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
628 if (!nl_modes)
629 goto nla_put_failure;
630
631 i = 0;
632 while (ifmodes) {
633 if (ifmodes & 1)
634 NLA_PUT_FLAG(msg, i);
635 ifmodes >>= 1;
636 i++;
637 }
638
639 nla_nest_end(msg, nl_modes);
640
ee688b00
JB
641 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
642 if (!nl_bands)
643 goto nla_put_failure;
644
645 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
646 if (!dev->wiphy.bands[band])
647 continue;
648
649 nl_band = nla_nest_start(msg, band);
650 if (!nl_band)
651 goto nla_put_failure;
652
d51626df
JB
653 /* add HT info */
654 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
655 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
656 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
657 &dev->wiphy.bands[band]->ht_cap.mcs);
658 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
659 dev->wiphy.bands[band]->ht_cap.cap);
660 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
661 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
662 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
663 dev->wiphy.bands[band]->ht_cap.ampdu_density);
664 }
665
ee688b00
JB
666 /* add frequencies */
667 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
668 if (!nl_freqs)
669 goto nla_put_failure;
670
671 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
672 nl_freq = nla_nest_start(msg, i);
673 if (!nl_freq)
674 goto nla_put_failure;
675
676 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
677
678 if (nl80211_msg_put_channel(msg, chan))
679 goto nla_put_failure;
e2f367f2 680
ee688b00
JB
681 nla_nest_end(msg, nl_freq);
682 }
683
684 nla_nest_end(msg, nl_freqs);
685
686 /* add bitrates */
687 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
688 if (!nl_rates)
689 goto nla_put_failure;
690
691 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
692 nl_rate = nla_nest_start(msg, i);
693 if (!nl_rate)
694 goto nla_put_failure;
695
696 rate = &dev->wiphy.bands[band]->bitrates[i];
697 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
698 rate->bitrate);
699 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
700 NLA_PUT_FLAG(msg,
701 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
702
703 nla_nest_end(msg, nl_rate);
704 }
705
706 nla_nest_end(msg, nl_rates);
707
708 nla_nest_end(msg, nl_band);
709 }
710 nla_nest_end(msg, nl_bands);
711
8fdc621d
JB
712 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
713 if (!nl_cmds)
714 goto nla_put_failure;
715
716 i = 0;
717#define CMD(op, n) \
718 do { \
719 if (dev->ops->op) { \
720 i++; \
721 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
722 } \
723 } while (0)
724
725 CMD(add_virtual_intf, NEW_INTERFACE);
726 CMD(change_virtual_intf, SET_INTERFACE);
727 CMD(add_key, NEW_KEY);
728 CMD(add_beacon, NEW_BEACON);
729 CMD(add_station, NEW_STATION);
730 CMD(add_mpath, NEW_MPATH);
24bdd9f4 731 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 732 CMD(change_bss, SET_BSS);
636a5d36
JM
733 CMD(auth, AUTHENTICATE);
734 CMD(assoc, ASSOCIATE);
735 CMD(deauth, DEAUTHENTICATE);
736 CMD(disassoc, DISASSOCIATE);
04a773ad 737 CMD(join_ibss, JOIN_IBSS);
29cbe68c 738 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
739 CMD(set_pmksa, SET_PMKSA);
740 CMD(del_pmksa, DEL_PMKSA);
741 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 742 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 743 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 744 CMD(mgmt_tx, FRAME);
f7ca38df 745 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 746 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
747 i++;
748 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
749 }
f444de05 750 CMD(set_channel, SET_CHANNEL);
e8347eba 751 CMD(set_wds_peer, SET_WDS_PEER);
8fdc621d
JB
752
753#undef CMD
b23aa676 754
6829c878 755 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
756 i++;
757 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
758 }
759
6829c878 760 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
761 i++;
762 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
763 }
764
8fdc621d
JB
765 nla_nest_end(msg, nl_cmds);
766
a293911d
JB
767 if (dev->ops->remain_on_channel)
768 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
769 dev->wiphy.max_remain_on_channel_duration);
770
f7ca38df
JB
771 /* for now at least assume all drivers have it */
772 if (dev->ops->mgmt_tx)
773 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
774
2e161f78
JB
775 if (mgmt_stypes) {
776 u16 stypes;
777 struct nlattr *nl_ftypes, *nl_ifs;
778 enum nl80211_iftype ift;
779
780 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
781 if (!nl_ifs)
782 goto nla_put_failure;
783
784 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
785 nl_ftypes = nla_nest_start(msg, ift);
786 if (!nl_ftypes)
787 goto nla_put_failure;
788 i = 0;
789 stypes = mgmt_stypes[ift].tx;
790 while (stypes) {
791 if (stypes & 1)
792 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
793 (i << 4) | IEEE80211_FTYPE_MGMT);
794 stypes >>= 1;
795 i++;
796 }
797 nla_nest_end(msg, nl_ftypes);
798 }
799
74b70a4e
JB
800 nla_nest_end(msg, nl_ifs);
801
2e161f78
JB
802 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
803 if (!nl_ifs)
804 goto nla_put_failure;
805
806 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
807 nl_ftypes = nla_nest_start(msg, ift);
808 if (!nl_ftypes)
809 goto nla_put_failure;
810 i = 0;
811 stypes = mgmt_stypes[ift].rx;
812 while (stypes) {
813 if (stypes & 1)
814 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
815 (i << 4) | IEEE80211_FTYPE_MGMT);
816 stypes >>= 1;
817 i++;
818 }
819 nla_nest_end(msg, nl_ftypes);
820 }
821 nla_nest_end(msg, nl_ifs);
822 }
823
55682965
JB
824 return genlmsg_end(msg, hdr);
825
826 nla_put_failure:
bc3ed28c
TG
827 genlmsg_cancel(msg, hdr);
828 return -EMSGSIZE;
55682965
JB
829}
830
831static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
832{
833 int idx = 0;
834 int start = cb->args[0];
835 struct cfg80211_registered_device *dev;
836
a1794390 837 mutex_lock(&cfg80211_mutex);
79c97e97 838 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
839 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
840 continue;
b4637271 841 if (++idx <= start)
55682965
JB
842 continue;
843 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
844 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
845 dev) < 0) {
846 idx--;
55682965 847 break;
b4637271 848 }
55682965 849 }
a1794390 850 mutex_unlock(&cfg80211_mutex);
55682965
JB
851
852 cb->args[0] = idx;
853
854 return skb->len;
855}
856
857static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
858{
859 struct sk_buff *msg;
4c476991 860 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 861
fd2120ca 862 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 863 if (!msg)
4c476991 864 return -ENOMEM;
55682965 865
4c476991
JB
866 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
867 nlmsg_free(msg);
868 return -ENOBUFS;
869 }
55682965 870
134e6375 871 return genlmsg_reply(msg, info);
55682965
JB
872}
873
31888487
JM
874static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
875 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
876 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
877 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
878 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
879 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
880};
881
882static int parse_txq_params(struct nlattr *tb[],
883 struct ieee80211_txq_params *txq_params)
884{
885 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
886 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
887 !tb[NL80211_TXQ_ATTR_AIFS])
888 return -EINVAL;
889
890 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
891 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
892 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
893 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
894 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
895
896 return 0;
897}
898
f444de05
JB
899static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
900{
901 /*
902 * You can only set the channel explicitly for AP, mesh
903 * and WDS type interfaces; all others have their channel
904 * managed via their respective "establish a connection"
905 * command (connect, join, ...)
906 *
907 * Monitors are special as they are normally slaved to
908 * whatever else is going on, so they behave as though
909 * you tried setting the wiphy channel itself.
910 */
911 return !wdev ||
912 wdev->iftype == NL80211_IFTYPE_AP ||
913 wdev->iftype == NL80211_IFTYPE_WDS ||
914 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
915 wdev->iftype == NL80211_IFTYPE_MONITOR ||
916 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
917}
918
919static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
920 struct wireless_dev *wdev,
921 struct genl_info *info)
922{
923 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
924 u32 freq;
925 int result;
926
927 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
928 return -EINVAL;
929
930 if (!nl80211_can_set_dev_channel(wdev))
931 return -EOPNOTSUPP;
932
933 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
934 channel_type = nla_get_u32(info->attrs[
935 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
936 if (channel_type != NL80211_CHAN_NO_HT &&
937 channel_type != NL80211_CHAN_HT20 &&
938 channel_type != NL80211_CHAN_HT40PLUS &&
939 channel_type != NL80211_CHAN_HT40MINUS)
940 return -EINVAL;
941 }
942
943 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
944
945 mutex_lock(&rdev->devlist_mtx);
946 if (wdev) {
947 wdev_lock(wdev);
948 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
949 wdev_unlock(wdev);
950 } else {
951 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
952 }
953 mutex_unlock(&rdev->devlist_mtx);
954
955 return result;
956}
957
958static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
959{
4c476991
JB
960 struct cfg80211_registered_device *rdev = info->user_ptr[0];
961 struct net_device *netdev = info->user_ptr[1];
f444de05 962
4c476991 963 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
964}
965
e8347eba
BJ
966static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
967{
43b19952
JB
968 struct cfg80211_registered_device *rdev = info->user_ptr[0];
969 struct net_device *dev = info->user_ptr[1];
970 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 971 const u8 *bssid;
e8347eba
BJ
972
973 if (!info->attrs[NL80211_ATTR_MAC])
974 return -EINVAL;
975
43b19952
JB
976 if (netif_running(dev))
977 return -EBUSY;
e8347eba 978
43b19952
JB
979 if (!rdev->ops->set_wds_peer)
980 return -EOPNOTSUPP;
e8347eba 981
43b19952
JB
982 if (wdev->iftype != NL80211_IFTYPE_WDS)
983 return -EOPNOTSUPP;
e8347eba
BJ
984
985 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 986 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
987}
988
989
55682965
JB
990static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
991{
992 struct cfg80211_registered_device *rdev;
f444de05
JB
993 struct net_device *netdev = NULL;
994 struct wireless_dev *wdev;
a1e567c8 995 int result = 0, rem_txq_params = 0;
31888487 996 struct nlattr *nl_txq_params;
b9a5f8ca
JM
997 u32 changed;
998 u8 retry_short = 0, retry_long = 0;
999 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1000 u8 coverage_class = 0;
55682965 1001
f444de05
JB
1002 /*
1003 * Try to find the wiphy and netdev. Normally this
1004 * function shouldn't need the netdev, but this is
1005 * done for backward compatibility -- previously
1006 * setting the channel was done per wiphy, but now
1007 * it is per netdev. Previous userland like hostapd
1008 * also passed a netdev to set_wiphy, so that it is
1009 * possible to let that go to the right netdev!
1010 */
4bbf4d56
JB
1011 mutex_lock(&cfg80211_mutex);
1012
f444de05
JB
1013 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1014 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1015
1016 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1017 if (netdev && netdev->ieee80211_ptr) {
1018 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1019 mutex_lock(&rdev->mtx);
1020 } else
1021 netdev = NULL;
4bbf4d56
JB
1022 }
1023
f444de05
JB
1024 if (!netdev) {
1025 rdev = __cfg80211_rdev_from_info(info);
1026 if (IS_ERR(rdev)) {
1027 mutex_unlock(&cfg80211_mutex);
4c476991 1028 return PTR_ERR(rdev);
f444de05
JB
1029 }
1030 wdev = NULL;
1031 netdev = NULL;
1032 result = 0;
1033
1034 mutex_lock(&rdev->mtx);
1035 } else if (netif_running(netdev) &&
1036 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1037 wdev = netdev->ieee80211_ptr;
1038 else
1039 wdev = NULL;
1040
1041 /*
1042 * end workaround code, by now the rdev is available
1043 * and locked, and wdev may or may not be NULL.
1044 */
4bbf4d56
JB
1045
1046 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1047 result = cfg80211_dev_rename(
1048 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1049
1050 mutex_unlock(&cfg80211_mutex);
1051
1052 if (result)
1053 goto bad_res;
31888487
JM
1054
1055 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1056 struct ieee80211_txq_params txq_params;
1057 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1058
1059 if (!rdev->ops->set_txq_params) {
1060 result = -EOPNOTSUPP;
1061 goto bad_res;
1062 }
1063
1064 nla_for_each_nested(nl_txq_params,
1065 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1066 rem_txq_params) {
1067 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1068 nla_data(nl_txq_params),
1069 nla_len(nl_txq_params),
1070 txq_params_policy);
1071 result = parse_txq_params(tb, &txq_params);
1072 if (result)
1073 goto bad_res;
1074
1075 result = rdev->ops->set_txq_params(&rdev->wiphy,
1076 &txq_params);
1077 if (result)
1078 goto bad_res;
1079 }
1080 }
55682965 1081
72bdcf34 1082 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1083 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1084 if (result)
1085 goto bad_res;
1086 }
1087
98d2ff8b
JO
1088 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1089 enum nl80211_tx_power_setting type;
1090 int idx, mbm = 0;
1091
1092 if (!rdev->ops->set_tx_power) {
60ea385f 1093 result = -EOPNOTSUPP;
98d2ff8b
JO
1094 goto bad_res;
1095 }
1096
1097 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1098 type = nla_get_u32(info->attrs[idx]);
1099
1100 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1101 (type != NL80211_TX_POWER_AUTOMATIC)) {
1102 result = -EINVAL;
1103 goto bad_res;
1104 }
1105
1106 if (type != NL80211_TX_POWER_AUTOMATIC) {
1107 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1108 mbm = nla_get_u32(info->attrs[idx]);
1109 }
1110
1111 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1112 if (result)
1113 goto bad_res;
1114 }
1115
afe0cbf8
BR
1116 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1117 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1118 u32 tx_ant, rx_ant;
7f531e03
BR
1119 if ((!rdev->wiphy.available_antennas_tx &&
1120 !rdev->wiphy.available_antennas_rx) ||
1121 !rdev->ops->set_antenna) {
afe0cbf8
BR
1122 result = -EOPNOTSUPP;
1123 goto bad_res;
1124 }
1125
1126 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1127 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1128
a7ffac95 1129 /* reject antenna configurations which don't match the
7f531e03
BR
1130 * available antenna masks, except for the "all" mask */
1131 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1132 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1133 result = -EINVAL;
1134 goto bad_res;
1135 }
1136
7f531e03
BR
1137 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1138 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1139
afe0cbf8
BR
1140 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1141 if (result)
1142 goto bad_res;
1143 }
1144
b9a5f8ca
JM
1145 changed = 0;
1146
1147 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1148 retry_short = nla_get_u8(
1149 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1150 if (retry_short == 0) {
1151 result = -EINVAL;
1152 goto bad_res;
1153 }
1154 changed |= WIPHY_PARAM_RETRY_SHORT;
1155 }
1156
1157 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1158 retry_long = nla_get_u8(
1159 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1160 if (retry_long == 0) {
1161 result = -EINVAL;
1162 goto bad_res;
1163 }
1164 changed |= WIPHY_PARAM_RETRY_LONG;
1165 }
1166
1167 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1168 frag_threshold = nla_get_u32(
1169 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1170 if (frag_threshold < 256) {
1171 result = -EINVAL;
1172 goto bad_res;
1173 }
1174 if (frag_threshold != (u32) -1) {
1175 /*
1176 * Fragments (apart from the last one) are required to
1177 * have even length. Make the fragmentation code
1178 * simpler by stripping LSB should someone try to use
1179 * odd threshold value.
1180 */
1181 frag_threshold &= ~0x1;
1182 }
1183 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1184 }
1185
1186 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1187 rts_threshold = nla_get_u32(
1188 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1189 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1190 }
1191
81077e82
LT
1192 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1193 coverage_class = nla_get_u8(
1194 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1195 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1196 }
1197
b9a5f8ca
JM
1198 if (changed) {
1199 u8 old_retry_short, old_retry_long;
1200 u32 old_frag_threshold, old_rts_threshold;
81077e82 1201 u8 old_coverage_class;
b9a5f8ca
JM
1202
1203 if (!rdev->ops->set_wiphy_params) {
1204 result = -EOPNOTSUPP;
1205 goto bad_res;
1206 }
1207
1208 old_retry_short = rdev->wiphy.retry_short;
1209 old_retry_long = rdev->wiphy.retry_long;
1210 old_frag_threshold = rdev->wiphy.frag_threshold;
1211 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1212 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1213
1214 if (changed & WIPHY_PARAM_RETRY_SHORT)
1215 rdev->wiphy.retry_short = retry_short;
1216 if (changed & WIPHY_PARAM_RETRY_LONG)
1217 rdev->wiphy.retry_long = retry_long;
1218 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1219 rdev->wiphy.frag_threshold = frag_threshold;
1220 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1221 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1222 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1223 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1224
1225 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1226 if (result) {
1227 rdev->wiphy.retry_short = old_retry_short;
1228 rdev->wiphy.retry_long = old_retry_long;
1229 rdev->wiphy.frag_threshold = old_frag_threshold;
1230 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1231 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1232 }
1233 }
72bdcf34 1234
306d6112 1235 bad_res:
4bbf4d56 1236 mutex_unlock(&rdev->mtx);
f444de05
JB
1237 if (netdev)
1238 dev_put(netdev);
55682965
JB
1239 return result;
1240}
1241
1242
1243static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1244 struct cfg80211_registered_device *rdev,
55682965
JB
1245 struct net_device *dev)
1246{
1247 void *hdr;
1248
1249 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1250 if (!hdr)
1251 return -1;
1252
1253 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1254 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1255 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1256 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1257
1258 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1259 rdev->devlist_generation ^
1260 (cfg80211_rdev_list_generation << 2));
1261
55682965
JB
1262 return genlmsg_end(msg, hdr);
1263
1264 nla_put_failure:
bc3ed28c
TG
1265 genlmsg_cancel(msg, hdr);
1266 return -EMSGSIZE;
55682965
JB
1267}
1268
1269static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1270{
1271 int wp_idx = 0;
1272 int if_idx = 0;
1273 int wp_start = cb->args[0];
1274 int if_start = cb->args[1];
f5ea9120 1275 struct cfg80211_registered_device *rdev;
55682965
JB
1276 struct wireless_dev *wdev;
1277
a1794390 1278 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1279 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1280 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1281 continue;
bba95fef
JB
1282 if (wp_idx < wp_start) {
1283 wp_idx++;
55682965 1284 continue;
bba95fef 1285 }
55682965
JB
1286 if_idx = 0;
1287
f5ea9120
JB
1288 mutex_lock(&rdev->devlist_mtx);
1289 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1290 if (if_idx < if_start) {
1291 if_idx++;
55682965 1292 continue;
bba95fef 1293 }
55682965
JB
1294 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1295 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1296 rdev, wdev->netdev) < 0) {
1297 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1298 goto out;
1299 }
1300 if_idx++;
55682965 1301 }
f5ea9120 1302 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1303
1304 wp_idx++;
55682965 1305 }
bba95fef 1306 out:
a1794390 1307 mutex_unlock(&cfg80211_mutex);
55682965
JB
1308
1309 cb->args[0] = wp_idx;
1310 cb->args[1] = if_idx;
1311
1312 return skb->len;
1313}
1314
1315static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1316{
1317 struct sk_buff *msg;
4c476991
JB
1318 struct cfg80211_registered_device *dev = info->user_ptr[0];
1319 struct net_device *netdev = info->user_ptr[1];
55682965 1320
fd2120ca 1321 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1322 if (!msg)
4c476991 1323 return -ENOMEM;
55682965 1324
d726405a 1325 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1326 dev, netdev) < 0) {
1327 nlmsg_free(msg);
1328 return -ENOBUFS;
1329 }
55682965 1330
134e6375 1331 return genlmsg_reply(msg, info);
55682965
JB
1332}
1333
66f7ac50
MW
1334static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1335 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1336 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1337 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1338 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1339 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1340};
1341
1342static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1343{
1344 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1345 int flag;
1346
1347 *mntrflags = 0;
1348
1349 if (!nla)
1350 return -EINVAL;
1351
1352 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1353 nla, mntr_flags_policy))
1354 return -EINVAL;
1355
1356 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1357 if (flags[flag])
1358 *mntrflags |= (1<<flag);
1359
1360 return 0;
1361}
1362
9bc383de 1363static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1364 struct net_device *netdev, u8 use_4addr,
1365 enum nl80211_iftype iftype)
9bc383de 1366{
ad4bb6f8 1367 if (!use_4addr) {
f350a0a8 1368 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1369 return -EBUSY;
9bc383de 1370 return 0;
ad4bb6f8 1371 }
9bc383de
JB
1372
1373 switch (iftype) {
1374 case NL80211_IFTYPE_AP_VLAN:
1375 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1376 return 0;
1377 break;
1378 case NL80211_IFTYPE_STATION:
1379 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1380 return 0;
1381 break;
1382 default:
1383 break;
1384 }
1385
1386 return -EOPNOTSUPP;
1387}
1388
55682965
JB
1389static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1390{
4c476991 1391 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1392 struct vif_params params;
e36d56b6 1393 int err;
04a773ad 1394 enum nl80211_iftype otype, ntype;
4c476991 1395 struct net_device *dev = info->user_ptr[1];
92ffe055 1396 u32 _flags, *flags = NULL;
ac7f9cfa 1397 bool change = false;
55682965 1398
2ec600d6
LCC
1399 memset(&params, 0, sizeof(params));
1400
04a773ad 1401 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1402
723b038d 1403 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1404 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1405 if (otype != ntype)
ac7f9cfa 1406 change = true;
4c476991
JB
1407 if (ntype > NL80211_IFTYPE_MAX)
1408 return -EINVAL;
723b038d
JB
1409 }
1410
92ffe055 1411 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1412 struct wireless_dev *wdev = dev->ieee80211_ptr;
1413
4c476991
JB
1414 if (ntype != NL80211_IFTYPE_MESH_POINT)
1415 return -EINVAL;
29cbe68c
JB
1416 if (netif_running(dev))
1417 return -EBUSY;
1418
1419 wdev_lock(wdev);
1420 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1421 IEEE80211_MAX_MESH_ID_LEN);
1422 wdev->mesh_id_up_len =
1423 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1424 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1425 wdev->mesh_id_up_len);
1426 wdev_unlock(wdev);
2ec600d6
LCC
1427 }
1428
8b787643
FF
1429 if (info->attrs[NL80211_ATTR_4ADDR]) {
1430 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1431 change = true;
ad4bb6f8 1432 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1433 if (err)
4c476991 1434 return err;
8b787643
FF
1435 } else {
1436 params.use_4addr = -1;
1437 }
1438
92ffe055 1439 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1440 if (ntype != NL80211_IFTYPE_MONITOR)
1441 return -EINVAL;
92ffe055
JB
1442 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1443 &_flags);
ac7f9cfa 1444 if (err)
4c476991 1445 return err;
ac7f9cfa
JB
1446
1447 flags = &_flags;
1448 change = true;
92ffe055 1449 }
3b85875a 1450
ac7f9cfa 1451 if (change)
3d54d255 1452 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1453 else
1454 err = 0;
60719ffd 1455
9bc383de
JB
1456 if (!err && params.use_4addr != -1)
1457 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1458
55682965
JB
1459 return err;
1460}
1461
1462static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1463{
4c476991 1464 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1465 struct vif_params params;
f9e10ce4 1466 struct net_device *dev;
55682965
JB
1467 int err;
1468 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1469 u32 flags;
55682965 1470
2ec600d6
LCC
1471 memset(&params, 0, sizeof(params));
1472
55682965
JB
1473 if (!info->attrs[NL80211_ATTR_IFNAME])
1474 return -EINVAL;
1475
1476 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1477 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1478 if (type > NL80211_IFTYPE_MAX)
1479 return -EINVAL;
1480 }
1481
79c97e97 1482 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1483 !(rdev->wiphy.interface_modes & (1 << type)))
1484 return -EOPNOTSUPP;
55682965 1485
9bc383de 1486 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1487 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1488 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1489 if (err)
4c476991 1490 return err;
9bc383de 1491 }
8b787643 1492
66f7ac50
MW
1493 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1494 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1495 &flags);
f9e10ce4 1496 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1497 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1498 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1499 if (IS_ERR(dev))
1500 return PTR_ERR(dev);
2ec600d6 1501
29cbe68c
JB
1502 if (type == NL80211_IFTYPE_MESH_POINT &&
1503 info->attrs[NL80211_ATTR_MESH_ID]) {
1504 struct wireless_dev *wdev = dev->ieee80211_ptr;
1505
1506 wdev_lock(wdev);
1507 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1508 IEEE80211_MAX_MESH_ID_LEN);
1509 wdev->mesh_id_up_len =
1510 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1511 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1512 wdev->mesh_id_up_len);
1513 wdev_unlock(wdev);
1514 }
1515
f9e10ce4 1516 return 0;
55682965
JB
1517}
1518
1519static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1520{
4c476991
JB
1521 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1522 struct net_device *dev = info->user_ptr[1];
55682965 1523
4c476991
JB
1524 if (!rdev->ops->del_virtual_intf)
1525 return -EOPNOTSUPP;
55682965 1526
4c476991 1527 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1528}
1529
41ade00f
JB
1530struct get_key_cookie {
1531 struct sk_buff *msg;
1532 int error;
b9454e83 1533 int idx;
41ade00f
JB
1534};
1535
1536static void get_key_callback(void *c, struct key_params *params)
1537{
b9454e83 1538 struct nlattr *key;
41ade00f
JB
1539 struct get_key_cookie *cookie = c;
1540
1541 if (params->key)
1542 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1543 params->key_len, params->key);
1544
1545 if (params->seq)
1546 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1547 params->seq_len, params->seq);
1548
1549 if (params->cipher)
1550 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1551 params->cipher);
1552
b9454e83
JB
1553 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1554 if (!key)
1555 goto nla_put_failure;
1556
1557 if (params->key)
1558 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1559 params->key_len, params->key);
1560
1561 if (params->seq)
1562 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1563 params->seq_len, params->seq);
1564
1565 if (params->cipher)
1566 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1567 params->cipher);
1568
1569 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1570
1571 nla_nest_end(cookie->msg, key);
1572
41ade00f
JB
1573 return;
1574 nla_put_failure:
1575 cookie->error = 1;
1576}
1577
1578static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1579{
4c476991 1580 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1581 int err;
4c476991 1582 struct net_device *dev = info->user_ptr[1];
41ade00f 1583 u8 key_idx = 0;
e31b8213
JB
1584 const u8 *mac_addr = NULL;
1585 bool pairwise;
41ade00f
JB
1586 struct get_key_cookie cookie = {
1587 .error = 0,
1588 };
1589 void *hdr;
1590 struct sk_buff *msg;
1591
1592 if (info->attrs[NL80211_ATTR_KEY_IDX])
1593 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1594
3cfcf6ac 1595 if (key_idx > 5)
41ade00f
JB
1596 return -EINVAL;
1597
1598 if (info->attrs[NL80211_ATTR_MAC])
1599 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1600
e31b8213
JB
1601 pairwise = !!mac_addr;
1602 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1603 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1604 if (kt >= NUM_NL80211_KEYTYPES)
1605 return -EINVAL;
1606 if (kt != NL80211_KEYTYPE_GROUP &&
1607 kt != NL80211_KEYTYPE_PAIRWISE)
1608 return -EINVAL;
1609 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1610 }
1611
4c476991
JB
1612 if (!rdev->ops->get_key)
1613 return -EOPNOTSUPP;
41ade00f 1614
fd2120ca 1615 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1616 if (!msg)
1617 return -ENOMEM;
41ade00f
JB
1618
1619 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1620 NL80211_CMD_NEW_KEY);
4c476991
JB
1621 if (IS_ERR(hdr))
1622 return PTR_ERR(hdr);
41ade00f
JB
1623
1624 cookie.msg = msg;
b9454e83 1625 cookie.idx = key_idx;
41ade00f
JB
1626
1627 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1628 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1629 if (mac_addr)
1630 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1631
e31b8213
JB
1632 if (pairwise && mac_addr &&
1633 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1634 return -ENOENT;
1635
1636 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1637 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1638
1639 if (err)
6c95e2a2 1640 goto free_msg;
41ade00f
JB
1641
1642 if (cookie.error)
1643 goto nla_put_failure;
1644
1645 genlmsg_end(msg, hdr);
4c476991 1646 return genlmsg_reply(msg, info);
41ade00f
JB
1647
1648 nla_put_failure:
1649 err = -ENOBUFS;
6c95e2a2 1650 free_msg:
41ade00f 1651 nlmsg_free(msg);
41ade00f
JB
1652 return err;
1653}
1654
1655static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1656{
4c476991 1657 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1658 struct key_parse key;
41ade00f 1659 int err;
4c476991 1660 struct net_device *dev = info->user_ptr[1];
41ade00f 1661
b9454e83
JB
1662 err = nl80211_parse_key(info, &key);
1663 if (err)
1664 return err;
41ade00f 1665
b9454e83 1666 if (key.idx < 0)
41ade00f
JB
1667 return -EINVAL;
1668
b9454e83
JB
1669 /* only support setting default key */
1670 if (!key.def && !key.defmgmt)
41ade00f
JB
1671 return -EINVAL;
1672
dbd2fd65 1673 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1674
dbd2fd65
JB
1675 if (key.def) {
1676 if (!rdev->ops->set_default_key) {
1677 err = -EOPNOTSUPP;
1678 goto out;
1679 }
41ade00f 1680
dbd2fd65
JB
1681 err = nl80211_key_allowed(dev->ieee80211_ptr);
1682 if (err)
1683 goto out;
1684
1685 if (!(rdev->wiphy.flags &
1686 WIPHY_FLAG_SUPPORTS_SEPARATE_DEFAULT_KEYS)) {
1687 if (!key.def_uni || !key.def_multi) {
1688 err = -EOPNOTSUPP;
1689 goto out;
1690 }
1691 }
1692
1693 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1694 key.def_uni, key.def_multi);
1695
1696 if (err)
1697 goto out;
fffd0934 1698
3d23e349 1699#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1700 dev->ieee80211_ptr->wext.default_key = key.idx;
1701#endif
1702 } else {
1703 if (key.def_uni || !key.def_multi) {
1704 err = -EINVAL;
1705 goto out;
1706 }
1707
1708 if (!rdev->ops->set_default_mgmt_key) {
1709 err = -EOPNOTSUPP;
1710 goto out;
1711 }
1712
1713 err = nl80211_key_allowed(dev->ieee80211_ptr);
1714 if (err)
1715 goto out;
1716
1717 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1718 dev, key.idx);
1719 if (err)
1720 goto out;
1721
1722#ifdef CONFIG_CFG80211_WEXT
1723 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1724#endif
dbd2fd65
JB
1725 }
1726
1727 out:
fffd0934 1728 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1729
41ade00f
JB
1730 return err;
1731}
1732
1733static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1734{
4c476991 1735 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1736 int err;
4c476991 1737 struct net_device *dev = info->user_ptr[1];
b9454e83 1738 struct key_parse key;
e31b8213 1739 const u8 *mac_addr = NULL;
41ade00f 1740
b9454e83
JB
1741 err = nl80211_parse_key(info, &key);
1742 if (err)
1743 return err;
41ade00f 1744
b9454e83 1745 if (!key.p.key)
41ade00f
JB
1746 return -EINVAL;
1747
41ade00f
JB
1748 if (info->attrs[NL80211_ATTR_MAC])
1749 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1750
e31b8213
JB
1751 if (key.type == -1) {
1752 if (mac_addr)
1753 key.type = NL80211_KEYTYPE_PAIRWISE;
1754 else
1755 key.type = NL80211_KEYTYPE_GROUP;
1756 }
1757
1758 /* for now */
1759 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1760 key.type != NL80211_KEYTYPE_GROUP)
1761 return -EINVAL;
1762
4c476991
JB
1763 if (!rdev->ops->add_key)
1764 return -EOPNOTSUPP;
25e47c18 1765
e31b8213
JB
1766 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1767 key.type == NL80211_KEYTYPE_PAIRWISE,
1768 mac_addr))
4c476991 1769 return -EINVAL;
41ade00f 1770
fffd0934
JB
1771 wdev_lock(dev->ieee80211_ptr);
1772 err = nl80211_key_allowed(dev->ieee80211_ptr);
1773 if (!err)
1774 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1775 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1776 mac_addr, &key.p);
1777 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1778
41ade00f
JB
1779 return err;
1780}
1781
1782static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1783{
4c476991 1784 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1785 int err;
4c476991 1786 struct net_device *dev = info->user_ptr[1];
41ade00f 1787 u8 *mac_addr = NULL;
b9454e83 1788 struct key_parse key;
41ade00f 1789
b9454e83
JB
1790 err = nl80211_parse_key(info, &key);
1791 if (err)
1792 return err;
41ade00f
JB
1793
1794 if (info->attrs[NL80211_ATTR_MAC])
1795 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1796
e31b8213
JB
1797 if (key.type == -1) {
1798 if (mac_addr)
1799 key.type = NL80211_KEYTYPE_PAIRWISE;
1800 else
1801 key.type = NL80211_KEYTYPE_GROUP;
1802 }
1803
1804 /* for now */
1805 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1806 key.type != NL80211_KEYTYPE_GROUP)
1807 return -EINVAL;
1808
4c476991
JB
1809 if (!rdev->ops->del_key)
1810 return -EOPNOTSUPP;
41ade00f 1811
fffd0934
JB
1812 wdev_lock(dev->ieee80211_ptr);
1813 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
1814
1815 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1816 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1817 err = -ENOENT;
1818
fffd0934 1819 if (!err)
e31b8213
JB
1820 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1821 key.type == NL80211_KEYTYPE_PAIRWISE,
1822 mac_addr);
41ade00f 1823
3d23e349 1824#ifdef CONFIG_CFG80211_WEXT
08645126 1825 if (!err) {
b9454e83 1826 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1827 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1828 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1829 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1830 }
1831#endif
fffd0934 1832 wdev_unlock(dev->ieee80211_ptr);
08645126 1833
41ade00f
JB
1834 return err;
1835}
1836
ed1b6cc7
JB
1837static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1838{
1839 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1840 struct beacon_parameters *info);
4c476991
JB
1841 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1842 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1843 struct beacon_parameters params;
1844 int haveinfo = 0;
1845
f4a11bb0
JB
1846 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1847 return -EINVAL;
1848
074ac8df 1849 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1850 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1851 return -EOPNOTSUPP;
eec60b03 1852
ed1b6cc7
JB
1853 switch (info->genlhdr->cmd) {
1854 case NL80211_CMD_NEW_BEACON:
1855 /* these are required for NEW_BEACON */
1856 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1857 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1858 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1859 return -EINVAL;
ed1b6cc7 1860
79c97e97 1861 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1862 break;
1863 case NL80211_CMD_SET_BEACON:
79c97e97 1864 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1865 break;
1866 default:
1867 WARN_ON(1);
4c476991 1868 return -EOPNOTSUPP;
ed1b6cc7
JB
1869 }
1870
4c476991
JB
1871 if (!call)
1872 return -EOPNOTSUPP;
ed1b6cc7
JB
1873
1874 memset(&params, 0, sizeof(params));
1875
1876 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1877 params.interval =
1878 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1879 haveinfo = 1;
1880 }
1881
1882 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1883 params.dtim_period =
1884 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1885 haveinfo = 1;
1886 }
1887
1888 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1889 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1890 params.head_len =
1891 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1892 haveinfo = 1;
1893 }
1894
1895 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1896 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1897 params.tail_len =
1898 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1899 haveinfo = 1;
1900 }
1901
4c476991
JB
1902 if (!haveinfo)
1903 return -EINVAL;
3b85875a 1904
4c476991 1905 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1906}
1907
1908static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1909{
4c476991
JB
1910 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1911 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1912
4c476991
JB
1913 if (!rdev->ops->del_beacon)
1914 return -EOPNOTSUPP;
ed1b6cc7 1915
074ac8df 1916 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1917 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1918 return -EOPNOTSUPP;
3b85875a 1919
4c476991 1920 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1921}
1922
5727ef1b
JB
1923static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1924 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1925 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1926 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1927 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 1928 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
5727ef1b
JB
1929};
1930
eccb8e8f
JB
1931static int parse_station_flags(struct genl_info *info,
1932 struct station_parameters *params)
5727ef1b
JB
1933{
1934 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1935 struct nlattr *nla;
5727ef1b
JB
1936 int flag;
1937
eccb8e8f
JB
1938 /*
1939 * Try parsing the new attribute first so userspace
1940 * can specify both for older kernels.
1941 */
1942 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1943 if (nla) {
1944 struct nl80211_sta_flag_update *sta_flags;
1945
1946 sta_flags = nla_data(nla);
1947 params->sta_flags_mask = sta_flags->mask;
1948 params->sta_flags_set = sta_flags->set;
1949 if ((params->sta_flags_mask |
1950 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1951 return -EINVAL;
1952 return 0;
1953 }
1954
1955 /* if present, parse the old attribute */
5727ef1b 1956
eccb8e8f 1957 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1958 if (!nla)
1959 return 0;
1960
1961 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1962 nla, sta_flags_policy))
1963 return -EINVAL;
1964
eccb8e8f
JB
1965 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1966 params->sta_flags_mask &= ~1;
5727ef1b
JB
1967
1968 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1969 if (flags[flag])
eccb8e8f 1970 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1971
1972 return 0;
1973}
1974
c8dcfd8a
FF
1975static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
1976 int attr)
1977{
1978 struct nlattr *rate;
1979 u16 bitrate;
1980
1981 rate = nla_nest_start(msg, attr);
1982 if (!rate)
1983 goto nla_put_failure;
1984
1985 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1986 bitrate = cfg80211_calculate_bitrate(info);
1987 if (bitrate > 0)
1988 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1989
1990 if (info->flags & RATE_INFO_FLAGS_MCS)
1991 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
1992 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1993 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1994 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
1995 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1996
1997 nla_nest_end(msg, rate);
1998 return true;
1999
2000nla_put_failure:
2001 return false;
2002}
2003
fd5b74dc
JB
2004static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2005 int flags, struct net_device *dev,
98b62183 2006 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2007{
2008 void *hdr;
f4263c98 2009 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2010
2011 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2012 if (!hdr)
2013 return -1;
2014
2015 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2016 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2017
f5ea9120
JB
2018 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2019
2ec600d6
LCC
2020 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2021 if (!sinfoattr)
fd5b74dc 2022 goto nla_put_failure;
2ec600d6
LCC
2023 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2024 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2025 sinfo->inactive_time);
2026 if (sinfo->filled & STATION_INFO_RX_BYTES)
2027 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2028 sinfo->rx_bytes);
2029 if (sinfo->filled & STATION_INFO_TX_BYTES)
2030 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2031 sinfo->tx_bytes);
2032 if (sinfo->filled & STATION_INFO_LLID)
2033 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2034 sinfo->llid);
2035 if (sinfo->filled & STATION_INFO_PLID)
2036 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2037 sinfo->plid);
2038 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2039 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2040 sinfo->plink_state);
420e7fab
HR
2041 if (sinfo->filled & STATION_INFO_SIGNAL)
2042 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2043 sinfo->signal);
541a45a1
BR
2044 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2045 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2046 sinfo->signal_avg);
420e7fab 2047 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2048 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2049 NL80211_STA_INFO_TX_BITRATE))
2050 goto nla_put_failure;
2051 }
2052 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2053 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2054 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2055 goto nla_put_failure;
420e7fab 2056 }
98c8a60a
JM
2057 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2058 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2059 sinfo->rx_packets);
2060 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2061 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2062 sinfo->tx_packets);
b206b4ef
BR
2063 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2064 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2065 sinfo->tx_retries);
2066 if (sinfo->filled & STATION_INFO_TX_FAILED)
2067 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2068 sinfo->tx_failed);
f4263c98
PS
2069 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2070 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2071 if (!bss_param)
2072 goto nla_put_failure;
2073
2074 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2075 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2076 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2077 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2078 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2079 NLA_PUT_FLAG(msg,
2080 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2081 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2082 sinfo->bss_param.dtim_period);
2083 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2084 sinfo->bss_param.beacon_interval);
2085
2086 nla_nest_end(msg, bss_param);
2087 }
2ec600d6 2088 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
2089
2090 return genlmsg_end(msg, hdr);
2091
2092 nla_put_failure:
bc3ed28c
TG
2093 genlmsg_cancel(msg, hdr);
2094 return -EMSGSIZE;
fd5b74dc
JB
2095}
2096
2ec600d6 2097static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2098 struct netlink_callback *cb)
2ec600d6 2099{
2ec600d6
LCC
2100 struct station_info sinfo;
2101 struct cfg80211_registered_device *dev;
bba95fef 2102 struct net_device *netdev;
2ec600d6 2103 u8 mac_addr[ETH_ALEN];
bba95fef 2104 int sta_idx = cb->args[1];
2ec600d6 2105 int err;
2ec600d6 2106
67748893
JB
2107 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2108 if (err)
2109 return err;
bba95fef
JB
2110
2111 if (!dev->ops->dump_station) {
eec60b03 2112 err = -EOPNOTSUPP;
bba95fef
JB
2113 goto out_err;
2114 }
2115
bba95fef
JB
2116 while (1) {
2117 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2118 mac_addr, &sinfo);
2119 if (err == -ENOENT)
2120 break;
2121 if (err)
3b85875a 2122 goto out_err;
bba95fef
JB
2123
2124 if (nl80211_send_station(skb,
2125 NETLINK_CB(cb->skb).pid,
2126 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2127 netdev, mac_addr,
2128 &sinfo) < 0)
2129 goto out;
2130
2131 sta_idx++;
2132 }
2133
2134
2135 out:
2136 cb->args[1] = sta_idx;
2137 err = skb->len;
bba95fef 2138 out_err:
67748893 2139 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2140
2141 return err;
2ec600d6 2142}
fd5b74dc 2143
5727ef1b
JB
2144static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2145{
4c476991
JB
2146 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2147 struct net_device *dev = info->user_ptr[1];
2ec600d6 2148 struct station_info sinfo;
fd5b74dc
JB
2149 struct sk_buff *msg;
2150 u8 *mac_addr = NULL;
4c476991 2151 int err;
fd5b74dc 2152
2ec600d6 2153 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2154
2155 if (!info->attrs[NL80211_ATTR_MAC])
2156 return -EINVAL;
2157
2158 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2159
4c476991
JB
2160 if (!rdev->ops->get_station)
2161 return -EOPNOTSUPP;
3b85875a 2162
4c476991 2163 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2164 if (err)
4c476991 2165 return err;
2ec600d6 2166
fd2120ca 2167 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2168 if (!msg)
4c476991 2169 return -ENOMEM;
fd5b74dc
JB
2170
2171 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2172 dev, mac_addr, &sinfo) < 0) {
2173 nlmsg_free(msg);
2174 return -ENOBUFS;
2175 }
3b85875a 2176
4c476991 2177 return genlmsg_reply(msg, info);
5727ef1b
JB
2178}
2179
2180/*
c258d2de 2181 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2182 */
463d0183 2183static int get_vlan(struct genl_info *info,
5727ef1b
JB
2184 struct cfg80211_registered_device *rdev,
2185 struct net_device **vlan)
2186{
463d0183 2187 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2188 *vlan = NULL;
2189
2190 if (vlanattr) {
463d0183
JB
2191 *vlan = dev_get_by_index(genl_info_net(info),
2192 nla_get_u32(vlanattr));
5727ef1b
JB
2193 if (!*vlan)
2194 return -ENODEV;
2195 if (!(*vlan)->ieee80211_ptr)
2196 return -EINVAL;
2197 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2198 return -EINVAL;
c258d2de
FF
2199 if (!netif_running(*vlan))
2200 return -ENETDOWN;
5727ef1b
JB
2201 }
2202 return 0;
2203}
2204
2205static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2206{
4c476991 2207 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2208 int err;
4c476991 2209 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2210 struct station_parameters params;
2211 u8 *mac_addr = NULL;
2212
2213 memset(&params, 0, sizeof(params));
2214
2215 params.listen_interval = -1;
2216
2217 if (info->attrs[NL80211_ATTR_STA_AID])
2218 return -EINVAL;
2219
2220 if (!info->attrs[NL80211_ATTR_MAC])
2221 return -EINVAL;
2222
2223 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2224
2225 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2226 params.supported_rates =
2227 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2228 params.supported_rates_len =
2229 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2230 }
2231
2232 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2233 params.listen_interval =
2234 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2235
36aedc90
JM
2236 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2237 params.ht_capa =
2238 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2239
eccb8e8f 2240 if (parse_station_flags(info, &params))
5727ef1b
JB
2241 return -EINVAL;
2242
2ec600d6
LCC
2243 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2244 params.plink_action =
2245 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2246
463d0183 2247 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2248 if (err)
034d655e 2249 goto out;
a97f4424
JB
2250
2251 /* validate settings */
2252 err = 0;
2253
2254 switch (dev->ieee80211_ptr->iftype) {
2255 case NL80211_IFTYPE_AP:
2256 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2257 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2258 /* disallow mesh-specific things */
2259 if (params.plink_action)
2260 err = -EINVAL;
2261 break;
074ac8df 2262 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2263 case NL80211_IFTYPE_STATION:
2264 /* disallow everything but AUTHORIZED flag */
2265 if (params.plink_action)
2266 err = -EINVAL;
2267 if (params.vlan)
2268 err = -EINVAL;
2269 if (params.supported_rates)
2270 err = -EINVAL;
2271 if (params.ht_capa)
2272 err = -EINVAL;
2273 if (params.listen_interval >= 0)
2274 err = -EINVAL;
2275 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2276 err = -EINVAL;
2277 break;
2278 case NL80211_IFTYPE_MESH_POINT:
2279 /* disallow things mesh doesn't support */
2280 if (params.vlan)
2281 err = -EINVAL;
2282 if (params.ht_capa)
2283 err = -EINVAL;
2284 if (params.listen_interval >= 0)
2285 err = -EINVAL;
2286 if (params.supported_rates)
2287 err = -EINVAL;
b39c48fa
JC
2288 if (params.sta_flags_mask &
2289 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2290 BIT(NL80211_STA_FLAG_AUTHORIZED)))
a97f4424
JB
2291 err = -EINVAL;
2292 break;
2293 default:
2294 err = -EINVAL;
034d655e
JB
2295 }
2296
5727ef1b
JB
2297 if (err)
2298 goto out;
2299
79c97e97 2300 if (!rdev->ops->change_station) {
5727ef1b
JB
2301 err = -EOPNOTSUPP;
2302 goto out;
2303 }
2304
79c97e97 2305 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2306
2307 out:
2308 if (params.vlan)
2309 dev_put(params.vlan);
3b85875a 2310
5727ef1b
JB
2311 return err;
2312}
2313
2314static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2315{
4c476991 2316 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2317 int err;
4c476991 2318 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2319 struct station_parameters params;
2320 u8 *mac_addr = NULL;
2321
2322 memset(&params, 0, sizeof(params));
2323
2324 if (!info->attrs[NL80211_ATTR_MAC])
2325 return -EINVAL;
2326
5727ef1b
JB
2327 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2328 return -EINVAL;
2329
2330 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2331 return -EINVAL;
2332
0e956c13
TLSC
2333 if (!info->attrs[NL80211_ATTR_STA_AID])
2334 return -EINVAL;
2335
5727ef1b
JB
2336 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2337 params.supported_rates =
2338 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2339 params.supported_rates_len =
2340 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2341 params.listen_interval =
2342 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2343
0e956c13
TLSC
2344 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2345 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2346 return -EINVAL;
51b50fbe 2347
36aedc90
JM
2348 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2349 params.ht_capa =
2350 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2351
96b78dff
JC
2352 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2353 params.plink_action =
2354 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2355
eccb8e8f 2356 if (parse_station_flags(info, &params))
5727ef1b
JB
2357 return -EINVAL;
2358
0e956c13 2359 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2360 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
96b78dff 2361 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2362 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2363 return -EINVAL;
0e956c13 2364
463d0183 2365 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2366 if (err)
e80cf853 2367 goto out;
a97f4424
JB
2368
2369 /* validate settings */
2370 err = 0;
2371
79c97e97 2372 if (!rdev->ops->add_station) {
5727ef1b
JB
2373 err = -EOPNOTSUPP;
2374 goto out;
2375 }
2376
79c97e97 2377 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2378
2379 out:
2380 if (params.vlan)
2381 dev_put(params.vlan);
5727ef1b
JB
2382 return err;
2383}
2384
2385static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2386{
4c476991
JB
2387 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2388 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2389 u8 *mac_addr = NULL;
2390
2391 if (info->attrs[NL80211_ATTR_MAC])
2392 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2393
e80cf853 2394 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2395 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2396 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2397 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2398 return -EINVAL;
5727ef1b 2399
4c476991
JB
2400 if (!rdev->ops->del_station)
2401 return -EOPNOTSUPP;
3b85875a 2402
4c476991 2403 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2404}
2405
2ec600d6
LCC
2406static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2407 int flags, struct net_device *dev,
2408 u8 *dst, u8 *next_hop,
2409 struct mpath_info *pinfo)
2410{
2411 void *hdr;
2412 struct nlattr *pinfoattr;
2413
2414 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2415 if (!hdr)
2416 return -1;
2417
2418 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2419 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2420 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2421
f5ea9120
JB
2422 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2423
2ec600d6
LCC
2424 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2425 if (!pinfoattr)
2426 goto nla_put_failure;
2427 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2428 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2429 pinfo->frame_qlen);
d19b3bf6
RP
2430 if (pinfo->filled & MPATH_INFO_SN)
2431 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2432 pinfo->sn);
2ec600d6
LCC
2433 if (pinfo->filled & MPATH_INFO_METRIC)
2434 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2435 pinfo->metric);
2436 if (pinfo->filled & MPATH_INFO_EXPTIME)
2437 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2438 pinfo->exptime);
2439 if (pinfo->filled & MPATH_INFO_FLAGS)
2440 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2441 pinfo->flags);
2442 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2443 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2444 pinfo->discovery_timeout);
2445 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2446 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2447 pinfo->discovery_retries);
2448
2449 nla_nest_end(msg, pinfoattr);
2450
2451 return genlmsg_end(msg, hdr);
2452
2453 nla_put_failure:
bc3ed28c
TG
2454 genlmsg_cancel(msg, hdr);
2455 return -EMSGSIZE;
2ec600d6
LCC
2456}
2457
2458static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2459 struct netlink_callback *cb)
2ec600d6 2460{
2ec600d6
LCC
2461 struct mpath_info pinfo;
2462 struct cfg80211_registered_device *dev;
bba95fef 2463 struct net_device *netdev;
2ec600d6
LCC
2464 u8 dst[ETH_ALEN];
2465 u8 next_hop[ETH_ALEN];
bba95fef 2466 int path_idx = cb->args[1];
2ec600d6 2467 int err;
2ec600d6 2468
67748893
JB
2469 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2470 if (err)
2471 return err;
bba95fef
JB
2472
2473 if (!dev->ops->dump_mpath) {
eec60b03 2474 err = -EOPNOTSUPP;
bba95fef
JB
2475 goto out_err;
2476 }
2477
eec60b03
JM
2478 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2479 err = -EOPNOTSUPP;
0448b5fc 2480 goto out_err;
eec60b03
JM
2481 }
2482
bba95fef
JB
2483 while (1) {
2484 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2485 dst, next_hop, &pinfo);
2486 if (err == -ENOENT)
2ec600d6 2487 break;
bba95fef 2488 if (err)
3b85875a 2489 goto out_err;
2ec600d6 2490
bba95fef
JB
2491 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2492 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2493 netdev, dst, next_hop,
2494 &pinfo) < 0)
2495 goto out;
2ec600d6 2496
bba95fef 2497 path_idx++;
2ec600d6 2498 }
2ec600d6 2499
2ec600d6 2500
bba95fef
JB
2501 out:
2502 cb->args[1] = path_idx;
2503 err = skb->len;
bba95fef 2504 out_err:
67748893 2505 nl80211_finish_netdev_dump(dev);
bba95fef 2506 return err;
2ec600d6
LCC
2507}
2508
2509static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2510{
4c476991 2511 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2512 int err;
4c476991 2513 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2514 struct mpath_info pinfo;
2515 struct sk_buff *msg;
2516 u8 *dst = NULL;
2517 u8 next_hop[ETH_ALEN];
2518
2519 memset(&pinfo, 0, sizeof(pinfo));
2520
2521 if (!info->attrs[NL80211_ATTR_MAC])
2522 return -EINVAL;
2523
2524 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2525
4c476991
JB
2526 if (!rdev->ops->get_mpath)
2527 return -EOPNOTSUPP;
2ec600d6 2528
4c476991
JB
2529 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2530 return -EOPNOTSUPP;
eec60b03 2531
79c97e97 2532 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2533 if (err)
4c476991 2534 return err;
2ec600d6 2535
fd2120ca 2536 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2537 if (!msg)
4c476991 2538 return -ENOMEM;
2ec600d6
LCC
2539
2540 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2541 dev, dst, next_hop, &pinfo) < 0) {
2542 nlmsg_free(msg);
2543 return -ENOBUFS;
2544 }
3b85875a 2545
4c476991 2546 return genlmsg_reply(msg, info);
2ec600d6
LCC
2547}
2548
2549static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2550{
4c476991
JB
2551 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2552 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2553 u8 *dst = NULL;
2554 u8 *next_hop = NULL;
2555
2556 if (!info->attrs[NL80211_ATTR_MAC])
2557 return -EINVAL;
2558
2559 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2560 return -EINVAL;
2561
2562 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2563 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2564
4c476991
JB
2565 if (!rdev->ops->change_mpath)
2566 return -EOPNOTSUPP;
35a8efe1 2567
4c476991
JB
2568 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2569 return -EOPNOTSUPP;
2ec600d6 2570
4c476991 2571 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2572}
4c476991 2573
2ec600d6
LCC
2574static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2575{
4c476991
JB
2576 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2577 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2578 u8 *dst = NULL;
2579 u8 *next_hop = NULL;
2580
2581 if (!info->attrs[NL80211_ATTR_MAC])
2582 return -EINVAL;
2583
2584 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2585 return -EINVAL;
2586
2587 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2588 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2589
4c476991
JB
2590 if (!rdev->ops->add_mpath)
2591 return -EOPNOTSUPP;
35a8efe1 2592
4c476991
JB
2593 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2594 return -EOPNOTSUPP;
2ec600d6 2595
4c476991 2596 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2597}
2598
2599static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2600{
4c476991
JB
2601 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2602 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2603 u8 *dst = NULL;
2604
2605 if (info->attrs[NL80211_ATTR_MAC])
2606 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2607
4c476991
JB
2608 if (!rdev->ops->del_mpath)
2609 return -EOPNOTSUPP;
3b85875a 2610
4c476991 2611 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2612}
2613
9f1ba906
JM
2614static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2615{
4c476991
JB
2616 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2617 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2618 struct bss_parameters params;
2619
2620 memset(&params, 0, sizeof(params));
2621 /* default to not changing parameters */
2622 params.use_cts_prot = -1;
2623 params.use_short_preamble = -1;
2624 params.use_short_slot_time = -1;
fd8aaaf3 2625 params.ap_isolate = -1;
50b12f59 2626 params.ht_opmode = -1;
9f1ba906
JM
2627
2628 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2629 params.use_cts_prot =
2630 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2631 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2632 params.use_short_preamble =
2633 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2634 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2635 params.use_short_slot_time =
2636 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2637 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2638 params.basic_rates =
2639 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2640 params.basic_rates_len =
2641 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2642 }
fd8aaaf3
FF
2643 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2644 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2645 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2646 params.ht_opmode =
2647 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2648
4c476991
JB
2649 if (!rdev->ops->change_bss)
2650 return -EOPNOTSUPP;
9f1ba906 2651
074ac8df 2652 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2653 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2654 return -EOPNOTSUPP;
3b85875a 2655
4c476991 2656 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2657}
2658
b54452b0 2659static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2660 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2661 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2662 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2663 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2664 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2665 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2666};
2667
2668static int parse_reg_rule(struct nlattr *tb[],
2669 struct ieee80211_reg_rule *reg_rule)
2670{
2671 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2672 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2673
2674 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2675 return -EINVAL;
2676 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2677 return -EINVAL;
2678 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2679 return -EINVAL;
2680 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2681 return -EINVAL;
2682 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2683 return -EINVAL;
2684
2685 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2686
2687 freq_range->start_freq_khz =
2688 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2689 freq_range->end_freq_khz =
2690 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2691 freq_range->max_bandwidth_khz =
2692 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2693
2694 power_rule->max_eirp =
2695 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2696
2697 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2698 power_rule->max_antenna_gain =
2699 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2700
2701 return 0;
2702}
2703
2704static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2705{
2706 int r;
2707 char *data = NULL;
2708
80778f18
LR
2709 /*
2710 * You should only get this when cfg80211 hasn't yet initialized
2711 * completely when built-in to the kernel right between the time
2712 * window between nl80211_init() and regulatory_init(), if that is
2713 * even possible.
2714 */
2715 mutex_lock(&cfg80211_mutex);
2716 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2717 mutex_unlock(&cfg80211_mutex);
2718 return -EINPROGRESS;
80778f18 2719 }
fe33eb39 2720 mutex_unlock(&cfg80211_mutex);
80778f18 2721
fe33eb39
LR
2722 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2723 return -EINVAL;
b2e1b302
LR
2724
2725 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2726
fe33eb39
LR
2727 r = regulatory_hint_user(data);
2728
b2e1b302
LR
2729 return r;
2730}
2731
24bdd9f4 2732static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 2733 struct genl_info *info)
93da9cc1 2734{
4c476991 2735 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 2736 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
2737 struct wireless_dev *wdev = dev->ieee80211_ptr;
2738 struct mesh_config cur_params;
2739 int err = 0;
93da9cc1 2740 void *hdr;
2741 struct nlattr *pinfoattr;
2742 struct sk_buff *msg;
2743
29cbe68c
JB
2744 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2745 return -EOPNOTSUPP;
2746
24bdd9f4 2747 if (!rdev->ops->get_mesh_config)
4c476991 2748 return -EOPNOTSUPP;
f3f92586 2749
29cbe68c
JB
2750 wdev_lock(wdev);
2751 /* If not connected, get default parameters */
2752 if (!wdev->mesh_id_len)
2753 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2754 else
24bdd9f4 2755 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2756 &cur_params);
2757 wdev_unlock(wdev);
2758
93da9cc1 2759 if (err)
4c476991 2760 return err;
93da9cc1 2761
2762 /* Draw up a netlink message to send back */
fd2120ca 2763 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2764 if (!msg)
2765 return -ENOMEM;
93da9cc1 2766 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 2767 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 2768 if (!hdr)
efe1cf0c 2769 goto out;
24bdd9f4 2770 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 2771 if (!pinfoattr)
2772 goto nla_put_failure;
2773 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2774 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2775 cur_params.dot11MeshRetryTimeout);
2776 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2777 cur_params.dot11MeshConfirmTimeout);
2778 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2779 cur_params.dot11MeshHoldingTimeout);
2780 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2781 cur_params.dot11MeshMaxPeerLinks);
2782 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2783 cur_params.dot11MeshMaxRetries);
2784 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2785 cur_params.dot11MeshTTL);
45904f21
JC
2786 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2787 cur_params.element_ttl);
93da9cc1 2788 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2789 cur_params.auto_open_plinks);
2790 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2791 cur_params.dot11MeshHWMPmaxPREQretries);
2792 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2793 cur_params.path_refresh_time);
2794 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2795 cur_params.min_discovery_timeout);
2796 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2797 cur_params.dot11MeshHWMPactivePathTimeout);
2798 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2799 cur_params.dot11MeshHWMPpreqMinInterval);
2800 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2801 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2802 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2803 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2804 nla_nest_end(msg, pinfoattr);
2805 genlmsg_end(msg, hdr);
4c476991 2806 return genlmsg_reply(msg, info);
93da9cc1 2807
3b85875a 2808 nla_put_failure:
93da9cc1 2809 genlmsg_cancel(msg, hdr);
efe1cf0c 2810 out:
d080e275 2811 nlmsg_free(msg);
4c476991 2812 return -ENOBUFS;
93da9cc1 2813}
2814
b54452b0 2815static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2816 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2817 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2818 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2819 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2820 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2821 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 2822 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 2823 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2824
2825 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2826 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2827 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2828 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2829 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2830 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2831};
2832
c80d545d
JC
2833static const struct nla_policy
2834 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2835 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2836 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 2837 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 2838 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d
JC
2839 .len = IEEE80211_MAX_DATA_LEN },
2840};
2841
24bdd9f4 2842static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
2843 struct mesh_config *cfg,
2844 u32 *mask_out)
93da9cc1 2845{
93da9cc1 2846 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 2847 u32 mask = 0;
93da9cc1 2848
bd90fdcc
JB
2849#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2850do {\
2851 if (table[attr_num]) {\
2852 cfg->param = nla_fn(table[attr_num]); \
2853 mask |= (1 << (attr_num - 1)); \
2854 } \
2855} while (0);\
2856
2857
24bdd9f4 2858 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 2859 return -EINVAL;
2860 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 2861 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 2862 nl80211_meshconf_params_policy))
93da9cc1 2863 return -EINVAL;
2864
93da9cc1 2865 /* This makes sure that there aren't more than 32 mesh config
2866 * parameters (otherwise our bitfield scheme would not work.) */
2867 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2868
2869 /* Fill in the params struct */
93da9cc1 2870 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2871 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2872 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2873 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2874 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2875 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2876 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2877 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2878 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2879 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2880 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2881 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
2882 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2883 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 2884 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2885 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2886 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2887 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2888 nla_get_u8);
2889 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2890 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2891 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2892 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2893 nla_get_u16);
2894 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2895 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2896 nla_get_u32);
2897 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2898 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2899 nla_get_u16);
2900 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2901 dot11MeshHWMPnetDiameterTraversalTime,
2902 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2903 nla_get_u16);
63c5723b
RP
2904 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2905 dot11MeshHWMPRootMode, mask,
2906 NL80211_MESHCONF_HWMP_ROOTMODE,
2907 nla_get_u8);
bd90fdcc
JB
2908 if (mask_out)
2909 *mask_out = mask;
c80d545d 2910
bd90fdcc
JB
2911 return 0;
2912
2913#undef FILL_IN_MESH_PARAM_IF_SET
2914}
2915
c80d545d
JC
2916static int nl80211_parse_mesh_setup(struct genl_info *info,
2917 struct mesh_setup *setup)
2918{
2919 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
2920
2921 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
2922 return -EINVAL;
2923 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
2924 info->attrs[NL80211_ATTR_MESH_SETUP],
2925 nl80211_mesh_setup_params_policy))
2926 return -EINVAL;
2927
2928 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
2929 setup->path_sel_proto =
2930 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
2931 IEEE80211_PATH_PROTOCOL_VENDOR :
2932 IEEE80211_PATH_PROTOCOL_HWMP;
2933
2934 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
2935 setup->path_metric =
2936 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
2937 IEEE80211_PATH_METRIC_VENDOR :
2938 IEEE80211_PATH_METRIC_AIRTIME;
2939
581a8b0f
JC
2940
2941 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 2942 struct nlattr *ieattr =
581a8b0f 2943 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
2944 if (!is_valid_ie_attr(ieattr))
2945 return -EINVAL;
581a8b0f
JC
2946 setup->ie = nla_data(ieattr);
2947 setup->ie_len = nla_len(ieattr);
c80d545d 2948 }
15d5dda6 2949 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
c80d545d
JC
2950
2951 return 0;
2952}
2953
24bdd9f4 2954static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 2955 struct genl_info *info)
bd90fdcc
JB
2956{
2957 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2958 struct net_device *dev = info->user_ptr[1];
29cbe68c 2959 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
2960 struct mesh_config cfg;
2961 u32 mask;
2962 int err;
2963
29cbe68c
JB
2964 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2965 return -EOPNOTSUPP;
2966
24bdd9f4 2967 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
2968 return -EOPNOTSUPP;
2969
24bdd9f4 2970 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
2971 if (err)
2972 return err;
2973
29cbe68c
JB
2974 wdev_lock(wdev);
2975 if (!wdev->mesh_id_len)
2976 err = -ENOLINK;
2977
2978 if (!err)
24bdd9f4 2979 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2980 mask, &cfg);
2981
2982 wdev_unlock(wdev);
2983
2984 return err;
93da9cc1 2985}
2986
f130347c
LR
2987static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2988{
2989 struct sk_buff *msg;
2990 void *hdr = NULL;
2991 struct nlattr *nl_reg_rules;
2992 unsigned int i;
2993 int err = -EINVAL;
2994
a1794390 2995 mutex_lock(&cfg80211_mutex);
f130347c
LR
2996
2997 if (!cfg80211_regdomain)
2998 goto out;
2999
fd2120ca 3000 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3001 if (!msg) {
3002 err = -ENOBUFS;
3003 goto out;
3004 }
3005
3006 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3007 NL80211_CMD_GET_REG);
3008 if (!hdr)
efe1cf0c 3009 goto put_failure;
f130347c
LR
3010
3011 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3012 cfg80211_regdomain->alpha2);
3013
3014 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3015 if (!nl_reg_rules)
3016 goto nla_put_failure;
3017
3018 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3019 struct nlattr *nl_reg_rule;
3020 const struct ieee80211_reg_rule *reg_rule;
3021 const struct ieee80211_freq_range *freq_range;
3022 const struct ieee80211_power_rule *power_rule;
3023
3024 reg_rule = &cfg80211_regdomain->reg_rules[i];
3025 freq_range = &reg_rule->freq_range;
3026 power_rule = &reg_rule->power_rule;
3027
3028 nl_reg_rule = nla_nest_start(msg, i);
3029 if (!nl_reg_rule)
3030 goto nla_put_failure;
3031
3032 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3033 reg_rule->flags);
3034 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3035 freq_range->start_freq_khz);
3036 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3037 freq_range->end_freq_khz);
3038 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3039 freq_range->max_bandwidth_khz);
3040 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3041 power_rule->max_antenna_gain);
3042 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3043 power_rule->max_eirp);
3044
3045 nla_nest_end(msg, nl_reg_rule);
3046 }
3047
3048 nla_nest_end(msg, nl_reg_rules);
3049
3050 genlmsg_end(msg, hdr);
134e6375 3051 err = genlmsg_reply(msg, info);
f130347c
LR
3052 goto out;
3053
3054nla_put_failure:
3055 genlmsg_cancel(msg, hdr);
efe1cf0c 3056put_failure:
d080e275 3057 nlmsg_free(msg);
f130347c
LR
3058 err = -EMSGSIZE;
3059out:
a1794390 3060 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3061 return err;
3062}
3063
b2e1b302
LR
3064static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3065{
3066 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3067 struct nlattr *nl_reg_rule;
3068 char *alpha2 = NULL;
3069 int rem_reg_rules = 0, r = 0;
3070 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3071 struct ieee80211_regdomain *rd = NULL;
3072
3073 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3074 return -EINVAL;
3075
3076 if (!info->attrs[NL80211_ATTR_REG_RULES])
3077 return -EINVAL;
3078
3079 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3080
3081 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3082 rem_reg_rules) {
3083 num_rules++;
3084 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3085 return -EINVAL;
b2e1b302
LR
3086 }
3087
61405e97
LR
3088 mutex_lock(&cfg80211_mutex);
3089
d0e18f83
LR
3090 if (!reg_is_valid_request(alpha2)) {
3091 r = -EINVAL;
3092 goto bad_reg;
3093 }
b2e1b302
LR
3094
3095 size_of_regd = sizeof(struct ieee80211_regdomain) +
3096 (num_rules * sizeof(struct ieee80211_reg_rule));
3097
3098 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3099 if (!rd) {
3100 r = -ENOMEM;
3101 goto bad_reg;
3102 }
b2e1b302
LR
3103
3104 rd->n_reg_rules = num_rules;
3105 rd->alpha2[0] = alpha2[0];
3106 rd->alpha2[1] = alpha2[1];
3107
3108 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3109 rem_reg_rules) {
3110 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3111 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3112 reg_rule_policy);
3113 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3114 if (r)
3115 goto bad_reg;
3116
3117 rule_idx++;
3118
d0e18f83
LR
3119 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3120 r = -EINVAL;
b2e1b302 3121 goto bad_reg;
d0e18f83 3122 }
b2e1b302
LR
3123 }
3124
3125 BUG_ON(rule_idx != num_rules);
3126
b2e1b302 3127 r = set_regdom(rd);
61405e97 3128
a1794390 3129 mutex_unlock(&cfg80211_mutex);
d0e18f83 3130
b2e1b302
LR
3131 return r;
3132
d2372b31 3133 bad_reg:
61405e97 3134 mutex_unlock(&cfg80211_mutex);
b2e1b302 3135 kfree(rd);
d0e18f83 3136 return r;
b2e1b302
LR
3137}
3138
83f5e2cf
JB
3139static int validate_scan_freqs(struct nlattr *freqs)
3140{
3141 struct nlattr *attr1, *attr2;
3142 int n_channels = 0, tmp1, tmp2;
3143
3144 nla_for_each_nested(attr1, freqs, tmp1) {
3145 n_channels++;
3146 /*
3147 * Some hardware has a limited channel list for
3148 * scanning, and it is pretty much nonsensical
3149 * to scan for a channel twice, so disallow that
3150 * and don't require drivers to check that the
3151 * channel list they get isn't longer than what
3152 * they can scan, as long as they can scan all
3153 * the channels they registered at once.
3154 */
3155 nla_for_each_nested(attr2, freqs, tmp2)
3156 if (attr1 != attr2 &&
3157 nla_get_u32(attr1) == nla_get_u32(attr2))
3158 return 0;
3159 }
3160
3161 return n_channels;
3162}
3163
2a519311
JB
3164static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3165{
4c476991
JB
3166 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3167 struct net_device *dev = info->user_ptr[1];
2a519311
JB
3168 struct cfg80211_scan_request *request;
3169 struct cfg80211_ssid *ssid;
3170 struct ieee80211_channel *channel;
3171 struct nlattr *attr;
3172 struct wiphy *wiphy;
83f5e2cf 3173 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3174 enum ieee80211_band band;
70692ad2 3175 size_t ie_len;
2a519311 3176
f4a11bb0
JB
3177 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3178 return -EINVAL;
3179
79c97e97 3180 wiphy = &rdev->wiphy;
2a519311 3181
4c476991
JB
3182 if (!rdev->ops->scan)
3183 return -EOPNOTSUPP;
2a519311 3184
4c476991
JB
3185 if (rdev->scan_req)
3186 return -EBUSY;
2a519311
JB
3187
3188 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3189 n_channels = validate_scan_freqs(
3190 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3191 if (!n_channels)
3192 return -EINVAL;
2a519311 3193 } else {
83f5e2cf
JB
3194 n_channels = 0;
3195
2a519311
JB
3196 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3197 if (wiphy->bands[band])
3198 n_channels += wiphy->bands[band]->n_channels;
3199 }
3200
3201 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3202 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3203 n_ssids++;
3204
4c476991
JB
3205 if (n_ssids > wiphy->max_scan_ssids)
3206 return -EINVAL;
2a519311 3207
70692ad2
JM
3208 if (info->attrs[NL80211_ATTR_IE])
3209 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3210 else
3211 ie_len = 0;
3212
4c476991
JB
3213 if (ie_len > wiphy->max_scan_ie_len)
3214 return -EINVAL;
18a83659 3215
2a519311
JB
3216 request = kzalloc(sizeof(*request)
3217 + sizeof(*ssid) * n_ssids
70692ad2
JM
3218 + sizeof(channel) * n_channels
3219 + ie_len, GFP_KERNEL);
4c476991
JB
3220 if (!request)
3221 return -ENOMEM;
2a519311 3222
2a519311 3223 if (n_ssids)
5ba63533 3224 request->ssids = (void *)&request->channels[n_channels];
2a519311 3225 request->n_ssids = n_ssids;
70692ad2
JM
3226 if (ie_len) {
3227 if (request->ssids)
3228 request->ie = (void *)(request->ssids + n_ssids);
3229 else
3230 request->ie = (void *)(request->channels + n_channels);
3231 }
2a519311 3232
584991dc 3233 i = 0;
2a519311
JB
3234 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3235 /* user specified, bail out if channel not found */
2a519311 3236 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3237 struct ieee80211_channel *chan;
3238
3239 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3240
3241 if (!chan) {
2a519311
JB
3242 err = -EINVAL;
3243 goto out_free;
3244 }
584991dc
JB
3245
3246 /* ignore disabled channels */
3247 if (chan->flags & IEEE80211_CHAN_DISABLED)
3248 continue;
3249
3250 request->channels[i] = chan;
2a519311
JB
3251 i++;
3252 }
3253 } else {
3254 /* all channels */
2a519311
JB
3255 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3256 int j;
3257 if (!wiphy->bands[band])
3258 continue;
3259 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3260 struct ieee80211_channel *chan;
3261
3262 chan = &wiphy->bands[band]->channels[j];
3263
3264 if (chan->flags & IEEE80211_CHAN_DISABLED)
3265 continue;
3266
3267 request->channels[i] = chan;
2a519311
JB
3268 i++;
3269 }
3270 }
3271 }
3272
584991dc
JB
3273 if (!i) {
3274 err = -EINVAL;
3275 goto out_free;
3276 }
3277
3278 request->n_channels = i;
3279
2a519311
JB
3280 i = 0;
3281 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3282 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3283 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3284 err = -EINVAL;
3285 goto out_free;
3286 }
3287 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3288 request->ssids[i].ssid_len = nla_len(attr);
3289 i++;
3290 }
3291 }
3292
70692ad2
JM
3293 if (info->attrs[NL80211_ATTR_IE]) {
3294 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3295 memcpy((void *)request->ie,
3296 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3297 request->ie_len);
3298 }
3299
463d0183 3300 request->dev = dev;
79c97e97 3301 request->wiphy = &rdev->wiphy;
2a519311 3302
79c97e97
JB
3303 rdev->scan_req = request;
3304 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3305
463d0183 3306 if (!err) {
79c97e97 3307 nl80211_send_scan_start(rdev, dev);
463d0183 3308 dev_hold(dev);
4c476991 3309 } else {
2a519311 3310 out_free:
79c97e97 3311 rdev->scan_req = NULL;
2a519311
JB
3312 kfree(request);
3313 }
3b85875a 3314
2a519311
JB
3315 return err;
3316}
3317
3318static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3319 struct cfg80211_registered_device *rdev,
48ab905d
JB
3320 struct wireless_dev *wdev,
3321 struct cfg80211_internal_bss *intbss)
2a519311 3322{
48ab905d 3323 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3324 void *hdr;
3325 struct nlattr *bss;
48ab905d
JB
3326 int i;
3327
3328 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3329
3330 hdr = nl80211hdr_put(msg, pid, seq, flags,
3331 NL80211_CMD_NEW_SCAN_RESULTS);
3332 if (!hdr)
3333 return -1;
3334
f5ea9120 3335 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3336 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3337
3338 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3339 if (!bss)
3340 goto nla_put_failure;
3341 if (!is_zero_ether_addr(res->bssid))
3342 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3343 if (res->information_elements && res->len_information_elements)
3344 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3345 res->len_information_elements,
3346 res->information_elements);
34a6eddb
JM
3347 if (res->beacon_ies && res->len_beacon_ies &&
3348 res->beacon_ies != res->information_elements)
3349 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3350 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3351 if (res->tsf)
3352 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3353 if (res->beacon_interval)
3354 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3355 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3356 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3357 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3358 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3359
77965c97 3360 switch (rdev->wiphy.signal_type) {
2a519311
JB
3361 case CFG80211_SIGNAL_TYPE_MBM:
3362 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3363 break;
3364 case CFG80211_SIGNAL_TYPE_UNSPEC:
3365 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3366 break;
3367 default:
3368 break;
3369 }
3370
48ab905d 3371 switch (wdev->iftype) {
074ac8df 3372 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3373 case NL80211_IFTYPE_STATION:
3374 if (intbss == wdev->current_bss)
3375 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3376 NL80211_BSS_STATUS_ASSOCIATED);
3377 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3378 if (intbss != wdev->auth_bsses[i])
3379 continue;
3380 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3381 NL80211_BSS_STATUS_AUTHENTICATED);
3382 break;
3383 }
3384 break;
3385 case NL80211_IFTYPE_ADHOC:
3386 if (intbss == wdev->current_bss)
3387 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3388 NL80211_BSS_STATUS_IBSS_JOINED);
3389 break;
3390 default:
3391 break;
3392 }
3393
2a519311
JB
3394 nla_nest_end(msg, bss);
3395
3396 return genlmsg_end(msg, hdr);
3397
3398 nla_put_failure:
3399 genlmsg_cancel(msg, hdr);
3400 return -EMSGSIZE;
3401}
3402
3403static int nl80211_dump_scan(struct sk_buff *skb,
3404 struct netlink_callback *cb)
3405{
48ab905d
JB
3406 struct cfg80211_registered_device *rdev;
3407 struct net_device *dev;
2a519311 3408 struct cfg80211_internal_bss *scan;
48ab905d 3409 struct wireless_dev *wdev;
2a519311
JB
3410 int start = cb->args[1], idx = 0;
3411 int err;
3412
67748893
JB
3413 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3414 if (err)
3415 return err;
2a519311 3416
48ab905d 3417 wdev = dev->ieee80211_ptr;
2a519311 3418
48ab905d
JB
3419 wdev_lock(wdev);
3420 spin_lock_bh(&rdev->bss_lock);
3421 cfg80211_bss_expire(rdev);
3422
3423 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3424 if (++idx <= start)
3425 continue;
3426 if (nl80211_send_bss(skb,
3427 NETLINK_CB(cb->skb).pid,
3428 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3429 rdev, wdev, scan) < 0) {
2a519311 3430 idx--;
67748893 3431 break;
2a519311
JB
3432 }
3433 }
3434
48ab905d
JB
3435 spin_unlock_bh(&rdev->bss_lock);
3436 wdev_unlock(wdev);
2a519311
JB
3437
3438 cb->args[1] = idx;
67748893 3439 nl80211_finish_netdev_dump(rdev);
2a519311 3440
67748893 3441 return skb->len;
2a519311
JB
3442}
3443
61fa713c
HS
3444static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3445 int flags, struct net_device *dev,
3446 struct survey_info *survey)
3447{
3448 void *hdr;
3449 struct nlattr *infoattr;
3450
3451 /* Survey without a channel doesn't make sense */
3452 if (!survey->channel)
3453 return -EINVAL;
3454
3455 hdr = nl80211hdr_put(msg, pid, seq, flags,
3456 NL80211_CMD_NEW_SURVEY_RESULTS);
3457 if (!hdr)
3458 return -ENOMEM;
3459
3460 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3461
3462 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3463 if (!infoattr)
3464 goto nla_put_failure;
3465
3466 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3467 survey->channel->center_freq);
3468 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3469 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3470 survey->noise);
17e5a808
FF
3471 if (survey->filled & SURVEY_INFO_IN_USE)
3472 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
3473 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3474 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3475 survey->channel_time);
3476 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3477 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3478 survey->channel_time_busy);
3479 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3480 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3481 survey->channel_time_ext_busy);
3482 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3483 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3484 survey->channel_time_rx);
3485 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3486 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3487 survey->channel_time_tx);
61fa713c
HS
3488
3489 nla_nest_end(msg, infoattr);
3490
3491 return genlmsg_end(msg, hdr);
3492
3493 nla_put_failure:
3494 genlmsg_cancel(msg, hdr);
3495 return -EMSGSIZE;
3496}
3497
3498static int nl80211_dump_survey(struct sk_buff *skb,
3499 struct netlink_callback *cb)
3500{
3501 struct survey_info survey;
3502 struct cfg80211_registered_device *dev;
3503 struct net_device *netdev;
61fa713c
HS
3504 int survey_idx = cb->args[1];
3505 int res;
3506
67748893
JB
3507 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3508 if (res)
3509 return res;
61fa713c
HS
3510
3511 if (!dev->ops->dump_survey) {
3512 res = -EOPNOTSUPP;
3513 goto out_err;
3514 }
3515
3516 while (1) {
3517 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3518 &survey);
3519 if (res == -ENOENT)
3520 break;
3521 if (res)
3522 goto out_err;
3523
3524 if (nl80211_send_survey(skb,
3525 NETLINK_CB(cb->skb).pid,
3526 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3527 netdev,
3528 &survey) < 0)
3529 goto out;
3530 survey_idx++;
3531 }
3532
3533 out:
3534 cb->args[1] = survey_idx;
3535 res = skb->len;
3536 out_err:
67748893 3537 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3538 return res;
3539}
3540
255e737e
JM
3541static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3542{
b23aa676
SO
3543 return auth_type <= NL80211_AUTHTYPE_MAX;
3544}
3545
3546static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3547{
3548 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3549 NL80211_WPA_VERSION_2));
3550}
3551
3552static bool nl80211_valid_akm_suite(u32 akm)
3553{
3554 return akm == WLAN_AKM_SUITE_8021X ||
3555 akm == WLAN_AKM_SUITE_PSK;
3556}
3557
3558static bool nl80211_valid_cipher_suite(u32 cipher)
3559{
3560 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3561 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3562 cipher == WLAN_CIPHER_SUITE_TKIP ||
3563 cipher == WLAN_CIPHER_SUITE_CCMP ||
3564 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3565}
3566
b23aa676 3567
636a5d36
JM
3568static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3569{
4c476991
JB
3570 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3571 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3572 struct ieee80211_channel *chan;
3573 const u8 *bssid, *ssid, *ie = NULL;
3574 int err, ssid_len, ie_len = 0;
3575 enum nl80211_auth_type auth_type;
fffd0934 3576 struct key_parse key;
d5cdfacb 3577 bool local_state_change;
636a5d36 3578
f4a11bb0
JB
3579 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3580 return -EINVAL;
3581
3582 if (!info->attrs[NL80211_ATTR_MAC])
3583 return -EINVAL;
3584
1778092e
JM
3585 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3586 return -EINVAL;
3587
19957bb3
JB
3588 if (!info->attrs[NL80211_ATTR_SSID])
3589 return -EINVAL;
3590
3591 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3592 return -EINVAL;
3593
fffd0934
JB
3594 err = nl80211_parse_key(info, &key);
3595 if (err)
3596 return err;
3597
3598 if (key.idx >= 0) {
e31b8213
JB
3599 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3600 return -EINVAL;
fffd0934
JB
3601 if (!key.p.key || !key.p.key_len)
3602 return -EINVAL;
3603 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3604 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3605 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3606 key.p.key_len != WLAN_KEY_LEN_WEP104))
3607 return -EINVAL;
3608 if (key.idx > 4)
3609 return -EINVAL;
3610 } else {
3611 key.p.key_len = 0;
3612 key.p.key = NULL;
3613 }
3614
afea0b7a
JB
3615 if (key.idx >= 0) {
3616 int i;
3617 bool ok = false;
3618 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3619 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3620 ok = true;
3621 break;
3622 }
3623 }
4c476991
JB
3624 if (!ok)
3625 return -EINVAL;
afea0b7a
JB
3626 }
3627
4c476991
JB
3628 if (!rdev->ops->auth)
3629 return -EOPNOTSUPP;
636a5d36 3630
074ac8df 3631 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3632 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3633 return -EOPNOTSUPP;
eec60b03 3634
19957bb3 3635 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3636 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3637 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3638 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3639 return -EINVAL;
636a5d36 3640
19957bb3
JB
3641 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3642 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3643
3644 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3645 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3646 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3647 }
3648
19957bb3 3649 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3650 if (!nl80211_valid_auth_type(auth_type))
3651 return -EINVAL;
636a5d36 3652
d5cdfacb
JM
3653 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3654
4c476991
JB
3655 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3656 ssid, ssid_len, ie, ie_len,
3657 key.p.key, key.p.key_len, key.idx,
3658 local_state_change);
636a5d36
JM
3659}
3660
c0692b8f
JB
3661static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3662 struct genl_info *info,
3dc27d25
JB
3663 struct cfg80211_crypto_settings *settings,
3664 int cipher_limit)
b23aa676 3665{
c0b2bbd8
JB
3666 memset(settings, 0, sizeof(*settings));
3667
b23aa676
SO
3668 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3669
c0692b8f
JB
3670 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3671 u16 proto;
3672 proto = nla_get_u16(
3673 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3674 settings->control_port_ethertype = cpu_to_be16(proto);
3675 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3676 proto != ETH_P_PAE)
3677 return -EINVAL;
3678 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3679 settings->control_port_no_encrypt = true;
3680 } else
3681 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3682
b23aa676
SO
3683 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3684 void *data;
3685 int len, i;
3686
3687 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3688 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3689 settings->n_ciphers_pairwise = len / sizeof(u32);
3690
3691 if (len % sizeof(u32))
3692 return -EINVAL;
3693
3dc27d25 3694 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3695 return -EINVAL;
3696
3697 memcpy(settings->ciphers_pairwise, data, len);
3698
3699 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3700 if (!nl80211_valid_cipher_suite(
3701 settings->ciphers_pairwise[i]))
3702 return -EINVAL;
3703 }
3704
3705 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3706 settings->cipher_group =
3707 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3708 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3709 return -EINVAL;
3710 }
3711
3712 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3713 settings->wpa_versions =
3714 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3715 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3716 return -EINVAL;
3717 }
3718
3719 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3720 void *data;
3721 int len, i;
3722
3723 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3724 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3725 settings->n_akm_suites = len / sizeof(u32);
3726
3727 if (len % sizeof(u32))
3728 return -EINVAL;
3729
3730 memcpy(settings->akm_suites, data, len);
3731
3732 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3733 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3734 return -EINVAL;
3735 }
3736
3737 return 0;
3738}
3739
636a5d36
JM
3740static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3741{
4c476991
JB
3742 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3743 struct net_device *dev = info->user_ptr[1];
19957bb3 3744 struct cfg80211_crypto_settings crypto;
f444de05 3745 struct ieee80211_channel *chan;
3e5d7649 3746 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3747 int err, ssid_len, ie_len = 0;
3748 bool use_mfp = false;
636a5d36 3749
f4a11bb0
JB
3750 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3751 return -EINVAL;
3752
3753 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3754 !info->attrs[NL80211_ATTR_SSID] ||
3755 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3756 return -EINVAL;
3757
4c476991
JB
3758 if (!rdev->ops->assoc)
3759 return -EOPNOTSUPP;
636a5d36 3760
074ac8df 3761 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3762 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3763 return -EOPNOTSUPP;
eec60b03 3764
19957bb3 3765 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3766
19957bb3
JB
3767 chan = ieee80211_get_channel(&rdev->wiphy,
3768 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3769 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3770 return -EINVAL;
636a5d36 3771
19957bb3
JB
3772 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3773 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3774
3775 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3776 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3777 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3778 }
3779
dc6382ce 3780 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3781 enum nl80211_mfp mfp =
dc6382ce 3782 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3783 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3784 use_mfp = true;
4c476991
JB
3785 else if (mfp != NL80211_MFP_NO)
3786 return -EINVAL;
dc6382ce
JM
3787 }
3788
3e5d7649
JB
3789 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3790 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3791
c0692b8f 3792 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3793 if (!err)
3e5d7649
JB
3794 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3795 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3796 &crypto);
636a5d36 3797
636a5d36
JM
3798 return err;
3799}
3800
3801static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3802{
4c476991
JB
3803 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3804 struct net_device *dev = info->user_ptr[1];
19957bb3 3805 const u8 *ie = NULL, *bssid;
4c476991 3806 int ie_len = 0;
19957bb3 3807 u16 reason_code;
d5cdfacb 3808 bool local_state_change;
636a5d36 3809
f4a11bb0
JB
3810 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3811 return -EINVAL;
3812
3813 if (!info->attrs[NL80211_ATTR_MAC])
3814 return -EINVAL;
3815
3816 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3817 return -EINVAL;
3818
4c476991
JB
3819 if (!rdev->ops->deauth)
3820 return -EOPNOTSUPP;
636a5d36 3821
074ac8df 3822 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3823 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3824 return -EOPNOTSUPP;
eec60b03 3825
19957bb3 3826 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3827
19957bb3
JB
3828 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3829 if (reason_code == 0) {
f4a11bb0 3830 /* Reason Code 0 is reserved */
4c476991 3831 return -EINVAL;
255e737e 3832 }
636a5d36
JM
3833
3834 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3835 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3836 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3837 }
3838
d5cdfacb
JM
3839 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3840
4c476991
JB
3841 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3842 local_state_change);
636a5d36
JM
3843}
3844
3845static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3846{
4c476991
JB
3847 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3848 struct net_device *dev = info->user_ptr[1];
19957bb3 3849 const u8 *ie = NULL, *bssid;
4c476991 3850 int ie_len = 0;
19957bb3 3851 u16 reason_code;
d5cdfacb 3852 bool local_state_change;
636a5d36 3853
f4a11bb0
JB
3854 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3855 return -EINVAL;
3856
3857 if (!info->attrs[NL80211_ATTR_MAC])
3858 return -EINVAL;
3859
3860 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3861 return -EINVAL;
3862
4c476991
JB
3863 if (!rdev->ops->disassoc)
3864 return -EOPNOTSUPP;
636a5d36 3865
074ac8df 3866 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3867 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3868 return -EOPNOTSUPP;
eec60b03 3869
19957bb3 3870 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3871
19957bb3
JB
3872 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3873 if (reason_code == 0) {
f4a11bb0 3874 /* Reason Code 0 is reserved */
4c476991 3875 return -EINVAL;
255e737e 3876 }
636a5d36
JM
3877
3878 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3879 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3880 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3881 }
3882
d5cdfacb
JM
3883 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3884
4c476991
JB
3885 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3886 local_state_change);
636a5d36
JM
3887}
3888
dd5b4cc7
FF
3889static bool
3890nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3891 int mcast_rate[IEEE80211_NUM_BANDS],
3892 int rateval)
3893{
3894 struct wiphy *wiphy = &rdev->wiphy;
3895 bool found = false;
3896 int band, i;
3897
3898 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3899 struct ieee80211_supported_band *sband;
3900
3901 sband = wiphy->bands[band];
3902 if (!sband)
3903 continue;
3904
3905 for (i = 0; i < sband->n_bitrates; i++) {
3906 if (sband->bitrates[i].bitrate == rateval) {
3907 mcast_rate[band] = i + 1;
3908 found = true;
3909 break;
3910 }
3911 }
3912 }
3913
3914 return found;
3915}
3916
04a773ad
JB
3917static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3918{
4c476991
JB
3919 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3920 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
3921 struct cfg80211_ibss_params ibss;
3922 struct wiphy *wiphy;
fffd0934 3923 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3924 int err;
3925
8e30bc55
JB
3926 memset(&ibss, 0, sizeof(ibss));
3927
04a773ad
JB
3928 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3929 return -EINVAL;
3930
3931 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3932 !info->attrs[NL80211_ATTR_SSID] ||
3933 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3934 return -EINVAL;
3935
8e30bc55
JB
3936 ibss.beacon_interval = 100;
3937
3938 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3939 ibss.beacon_interval =
3940 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3941 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3942 return -EINVAL;
3943 }
3944
4c476991
JB
3945 if (!rdev->ops->join_ibss)
3946 return -EOPNOTSUPP;
04a773ad 3947
4c476991
JB
3948 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3949 return -EOPNOTSUPP;
04a773ad 3950
79c97e97 3951 wiphy = &rdev->wiphy;
04a773ad
JB
3952
3953 if (info->attrs[NL80211_ATTR_MAC])
3954 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3955 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3956 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3957
3958 if (info->attrs[NL80211_ATTR_IE]) {
3959 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3960 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3961 }
3962
3963 ibss.channel = ieee80211_get_channel(wiphy,
3964 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3965 if (!ibss.channel ||
3966 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
3967 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
3968 return -EINVAL;
04a773ad
JB
3969
3970 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3971 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3972
fbd2c8dc
TP
3973 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3974 u8 *rates =
3975 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3976 int n_rates =
3977 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3978 struct ieee80211_supported_band *sband =
3979 wiphy->bands[ibss.channel->band];
3980 int i, j;
3981
4c476991
JB
3982 if (n_rates == 0)
3983 return -EINVAL;
fbd2c8dc
TP
3984
3985 for (i = 0; i < n_rates; i++) {
3986 int rate = (rates[i] & 0x7f) * 5;
3987 bool found = false;
3988
3989 for (j = 0; j < sband->n_bitrates; j++) {
3990 if (sband->bitrates[j].bitrate == rate) {
3991 found = true;
3992 ibss.basic_rates |= BIT(j);
3993 break;
3994 }
3995 }
4c476991
JB
3996 if (!found)
3997 return -EINVAL;
fbd2c8dc 3998 }
fbd2c8dc 3999 }
dd5b4cc7
FF
4000
4001 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4002 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4003 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4004 return -EINVAL;
fbd2c8dc 4005
4c476991
JB
4006 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4007 connkeys = nl80211_parse_connkeys(rdev,
4008 info->attrs[NL80211_ATTR_KEYS]);
4009 if (IS_ERR(connkeys))
4010 return PTR_ERR(connkeys);
4011 }
04a773ad 4012
4c476991 4013 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4014 if (err)
4015 kfree(connkeys);
04a773ad
JB
4016 return err;
4017}
4018
4019static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4020{
4c476991
JB
4021 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4022 struct net_device *dev = info->user_ptr[1];
04a773ad 4023
4c476991
JB
4024 if (!rdev->ops->leave_ibss)
4025 return -EOPNOTSUPP;
04a773ad 4026
4c476991
JB
4027 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4028 return -EOPNOTSUPP;
04a773ad 4029
4c476991 4030 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4031}
4032
aff89a9b
JB
4033#ifdef CONFIG_NL80211_TESTMODE
4034static struct genl_multicast_group nl80211_testmode_mcgrp = {
4035 .name = "testmode",
4036};
4037
4038static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4039{
4c476991 4040 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4041 int err;
4042
4043 if (!info->attrs[NL80211_ATTR_TESTDATA])
4044 return -EINVAL;
4045
aff89a9b
JB
4046 err = -EOPNOTSUPP;
4047 if (rdev->ops->testmode_cmd) {
4048 rdev->testmode_info = info;
4049 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4050 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4051 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4052 rdev->testmode_info = NULL;
4053 }
4054
aff89a9b
JB
4055 return err;
4056}
4057
4058static struct sk_buff *
4059__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4060 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4061{
4062 struct sk_buff *skb;
4063 void *hdr;
4064 struct nlattr *data;
4065
4066 skb = nlmsg_new(approxlen + 100, gfp);
4067 if (!skb)
4068 return NULL;
4069
4070 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4071 if (!hdr) {
4072 kfree_skb(skb);
4073 return NULL;
4074 }
4075
4076 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4077 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4078
4079 ((void **)skb->cb)[0] = rdev;
4080 ((void **)skb->cb)[1] = hdr;
4081 ((void **)skb->cb)[2] = data;
4082
4083 return skb;
4084
4085 nla_put_failure:
4086 kfree_skb(skb);
4087 return NULL;
4088}
4089
4090struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4091 int approxlen)
4092{
4093 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4094
4095 if (WARN_ON(!rdev->testmode_info))
4096 return NULL;
4097
4098 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4099 rdev->testmode_info->snd_pid,
4100 rdev->testmode_info->snd_seq,
4101 GFP_KERNEL);
4102}
4103EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4104
4105int cfg80211_testmode_reply(struct sk_buff *skb)
4106{
4107 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4108 void *hdr = ((void **)skb->cb)[1];
4109 struct nlattr *data = ((void **)skb->cb)[2];
4110
4111 if (WARN_ON(!rdev->testmode_info)) {
4112 kfree_skb(skb);
4113 return -EINVAL;
4114 }
4115
4116 nla_nest_end(skb, data);
4117 genlmsg_end(skb, hdr);
4118 return genlmsg_reply(skb, rdev->testmode_info);
4119}
4120EXPORT_SYMBOL(cfg80211_testmode_reply);
4121
4122struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4123 int approxlen, gfp_t gfp)
4124{
4125 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4126
4127 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4128}
4129EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4130
4131void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4132{
4133 void *hdr = ((void **)skb->cb)[1];
4134 struct nlattr *data = ((void **)skb->cb)[2];
4135
4136 nla_nest_end(skb, data);
4137 genlmsg_end(skb, hdr);
4138 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4139}
4140EXPORT_SYMBOL(cfg80211_testmode_event);
4141#endif
4142
b23aa676
SO
4143static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4144{
4c476991
JB
4145 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4146 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4147 struct cfg80211_connect_params connect;
4148 struct wiphy *wiphy;
fffd0934 4149 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4150 int err;
4151
4152 memset(&connect, 0, sizeof(connect));
4153
4154 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4155 return -EINVAL;
4156
4157 if (!info->attrs[NL80211_ATTR_SSID] ||
4158 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4159 return -EINVAL;
4160
4161 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4162 connect.auth_type =
4163 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4164 if (!nl80211_valid_auth_type(connect.auth_type))
4165 return -EINVAL;
4166 } else
4167 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4168
4169 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4170
c0692b8f 4171 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4172 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4173 if (err)
4174 return err;
b23aa676 4175
074ac8df 4176 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4177 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4178 return -EOPNOTSUPP;
b23aa676 4179
79c97e97 4180 wiphy = &rdev->wiphy;
b23aa676 4181
b23aa676
SO
4182 if (info->attrs[NL80211_ATTR_MAC])
4183 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4184 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4185 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4186
4187 if (info->attrs[NL80211_ATTR_IE]) {
4188 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4189 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4190 }
4191
4192 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4193 connect.channel =
4194 ieee80211_get_channel(wiphy,
4195 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4196 if (!connect.channel ||
4c476991
JB
4197 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4198 return -EINVAL;
b23aa676
SO
4199 }
4200
fffd0934
JB
4201 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4202 connkeys = nl80211_parse_connkeys(rdev,
4203 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4204 if (IS_ERR(connkeys))
4205 return PTR_ERR(connkeys);
fffd0934
JB
4206 }
4207
4208 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4209 if (err)
4210 kfree(connkeys);
b23aa676
SO
4211 return err;
4212}
4213
4214static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4215{
4c476991
JB
4216 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4217 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4218 u16 reason;
4219
4220 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4221 reason = WLAN_REASON_DEAUTH_LEAVING;
4222 else
4223 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4224
4225 if (reason == 0)
4226 return -EINVAL;
4227
074ac8df 4228 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4229 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4230 return -EOPNOTSUPP;
b23aa676 4231
4c476991 4232 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4233}
4234
463d0183
JB
4235static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4236{
4c476991 4237 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4238 struct net *net;
4239 int err;
4240 u32 pid;
4241
4242 if (!info->attrs[NL80211_ATTR_PID])
4243 return -EINVAL;
4244
4245 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4246
463d0183 4247 net = get_net_ns_by_pid(pid);
4c476991
JB
4248 if (IS_ERR(net))
4249 return PTR_ERR(net);
463d0183
JB
4250
4251 err = 0;
4252
4253 /* check if anything to do */
4c476991
JB
4254 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4255 err = cfg80211_switch_netns(rdev, net);
463d0183 4256
463d0183 4257 put_net(net);
463d0183
JB
4258 return err;
4259}
4260
67fbb16b
SO
4261static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4262{
4c476991 4263 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4264 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4265 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4266 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4267 struct cfg80211_pmksa pmksa;
4268
4269 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4270
4271 if (!info->attrs[NL80211_ATTR_MAC])
4272 return -EINVAL;
4273
4274 if (!info->attrs[NL80211_ATTR_PMKID])
4275 return -EINVAL;
4276
67fbb16b
SO
4277 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4278 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4279
074ac8df 4280 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4281 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4282 return -EOPNOTSUPP;
67fbb16b
SO
4283
4284 switch (info->genlhdr->cmd) {
4285 case NL80211_CMD_SET_PMKSA:
4286 rdev_ops = rdev->ops->set_pmksa;
4287 break;
4288 case NL80211_CMD_DEL_PMKSA:
4289 rdev_ops = rdev->ops->del_pmksa;
4290 break;
4291 default:
4292 WARN_ON(1);
4293 break;
4294 }
4295
4c476991
JB
4296 if (!rdev_ops)
4297 return -EOPNOTSUPP;
67fbb16b 4298
4c476991 4299 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4300}
4301
4302static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4303{
4c476991
JB
4304 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4305 struct net_device *dev = info->user_ptr[1];
67fbb16b 4306
074ac8df 4307 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4308 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4309 return -EOPNOTSUPP;
67fbb16b 4310
4c476991
JB
4311 if (!rdev->ops->flush_pmksa)
4312 return -EOPNOTSUPP;
67fbb16b 4313
4c476991 4314 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
4315}
4316
9588bbd5
JM
4317static int nl80211_remain_on_channel(struct sk_buff *skb,
4318 struct genl_info *info)
4319{
4c476991
JB
4320 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4321 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
4322 struct ieee80211_channel *chan;
4323 struct sk_buff *msg;
4324 void *hdr;
4325 u64 cookie;
4326 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4327 u32 freq, duration;
4328 int err;
4329
4330 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4331 !info->attrs[NL80211_ATTR_DURATION])
4332 return -EINVAL;
4333
4334 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4335
4336 /*
4337 * We should be on that channel for at least one jiffie,
4338 * and more than 5 seconds seems excessive.
4339 */
a293911d
JB
4340 if (!duration || !msecs_to_jiffies(duration) ||
4341 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
4342 return -EINVAL;
4343
4c476991
JB
4344 if (!rdev->ops->remain_on_channel)
4345 return -EOPNOTSUPP;
9588bbd5 4346
9588bbd5
JM
4347 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4348 channel_type = nla_get_u32(
4349 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4350 if (channel_type != NL80211_CHAN_NO_HT &&
4351 channel_type != NL80211_CHAN_HT20 &&
4352 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4353 channel_type != NL80211_CHAN_HT40MINUS)
4354 return -EINVAL;
9588bbd5
JM
4355 }
4356
4357 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4358 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4359 if (chan == NULL)
4360 return -EINVAL;
9588bbd5
JM
4361
4362 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4363 if (!msg)
4364 return -ENOMEM;
9588bbd5
JM
4365
4366 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4367 NL80211_CMD_REMAIN_ON_CHANNEL);
4368
4369 if (IS_ERR(hdr)) {
4370 err = PTR_ERR(hdr);
4371 goto free_msg;
4372 }
4373
4374 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4375 channel_type, duration, &cookie);
4376
4377 if (err)
4378 goto free_msg;
4379
4380 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4381
4382 genlmsg_end(msg, hdr);
4c476991
JB
4383
4384 return genlmsg_reply(msg, info);
9588bbd5
JM
4385
4386 nla_put_failure:
4387 err = -ENOBUFS;
4388 free_msg:
4389 nlmsg_free(msg);
9588bbd5
JM
4390 return err;
4391}
4392
4393static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4394 struct genl_info *info)
4395{
4c476991
JB
4396 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4397 struct net_device *dev = info->user_ptr[1];
9588bbd5 4398 u64 cookie;
9588bbd5
JM
4399
4400 if (!info->attrs[NL80211_ATTR_COOKIE])
4401 return -EINVAL;
4402
4c476991
JB
4403 if (!rdev->ops->cancel_remain_on_channel)
4404 return -EOPNOTSUPP;
9588bbd5 4405
9588bbd5
JM
4406 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4407
4c476991 4408 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
4409}
4410
13ae75b1
JM
4411static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4412 u8 *rates, u8 rates_len)
4413{
4414 u8 i;
4415 u32 mask = 0;
4416
4417 for (i = 0; i < rates_len; i++) {
4418 int rate = (rates[i] & 0x7f) * 5;
4419 int ridx;
4420 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4421 struct ieee80211_rate *srate =
4422 &sband->bitrates[ridx];
4423 if (rate == srate->bitrate) {
4424 mask |= 1 << ridx;
4425 break;
4426 }
4427 }
4428 if (ridx == sband->n_bitrates)
4429 return 0; /* rate not found */
4430 }
4431
4432 return mask;
4433}
4434
b54452b0 4435static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4436 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4437 .len = NL80211_MAX_SUPP_RATES },
4438};
4439
4440static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4441 struct genl_info *info)
4442{
4443 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4444 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4445 struct cfg80211_bitrate_mask mask;
4c476991
JB
4446 int rem, i;
4447 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4448 struct nlattr *tx_rates;
4449 struct ieee80211_supported_band *sband;
4450
4451 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4452 return -EINVAL;
4453
4c476991
JB
4454 if (!rdev->ops->set_bitrate_mask)
4455 return -EOPNOTSUPP;
13ae75b1
JM
4456
4457 memset(&mask, 0, sizeof(mask));
4458 /* Default to all rates enabled */
4459 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4460 sband = rdev->wiphy.bands[i];
4461 mask.control[i].legacy =
4462 sband ? (1 << sband->n_bitrates) - 1 : 0;
4463 }
4464
4465 /*
4466 * The nested attribute uses enum nl80211_band as the index. This maps
4467 * directly to the enum ieee80211_band values used in cfg80211.
4468 */
4469 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4470 {
4471 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4472 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4473 return -EINVAL;
13ae75b1 4474 sband = rdev->wiphy.bands[band];
4c476991
JB
4475 if (sband == NULL)
4476 return -EINVAL;
13ae75b1
JM
4477 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4478 nla_len(tx_rates), nl80211_txattr_policy);
4479 if (tb[NL80211_TXRATE_LEGACY]) {
4480 mask.control[band].legacy = rateset_to_mask(
4481 sband,
4482 nla_data(tb[NL80211_TXRATE_LEGACY]),
4483 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4484 if (mask.control[band].legacy == 0)
4485 return -EINVAL;
13ae75b1
JM
4486 }
4487 }
4488
4c476991 4489 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4490}
4491
2e161f78 4492static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4493{
4c476991
JB
4494 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4495 struct net_device *dev = info->user_ptr[1];
2e161f78 4496 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4497
4498 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4499 return -EINVAL;
4500
2e161f78
JB
4501 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4502 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4503
9d38d85d 4504 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4505 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4506 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4507 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4508 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4509 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4510 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4511 return -EOPNOTSUPP;
026331c4
JM
4512
4513 /* not much point in registering if we can't reply */
4c476991
JB
4514 if (!rdev->ops->mgmt_tx)
4515 return -EOPNOTSUPP;
026331c4 4516
4c476991 4517 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4518 frame_type,
026331c4
JM
4519 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4520 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4521}
4522
2e161f78 4523static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4524{
4c476991
JB
4525 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4526 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4527 struct ieee80211_channel *chan;
4528 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4529 bool channel_type_valid = false;
026331c4
JM
4530 u32 freq;
4531 int err;
4532 void *hdr;
4533 u64 cookie;
4534 struct sk_buff *msg;
f7ca38df
JB
4535 unsigned int wait = 0;
4536 bool offchan;
026331c4
JM
4537
4538 if (!info->attrs[NL80211_ATTR_FRAME] ||
4539 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4540 return -EINVAL;
4541
4c476991
JB
4542 if (!rdev->ops->mgmt_tx)
4543 return -EOPNOTSUPP;
026331c4 4544
9d38d85d 4545 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4546 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4547 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4548 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4549 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4550 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4551 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4552 return -EOPNOTSUPP;
026331c4 4553
f7ca38df
JB
4554 if (info->attrs[NL80211_ATTR_DURATION]) {
4555 if (!rdev->ops->mgmt_tx_cancel_wait)
4556 return -EINVAL;
4557 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4558 }
4559
026331c4
JM
4560 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4561 channel_type = nla_get_u32(
4562 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4563 if (channel_type != NL80211_CHAN_NO_HT &&
4564 channel_type != NL80211_CHAN_HT20 &&
4565 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4566 channel_type != NL80211_CHAN_HT40MINUS)
4567 return -EINVAL;
252aa631 4568 channel_type_valid = true;
026331c4
JM
4569 }
4570
f7ca38df
JB
4571 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4572
026331c4
JM
4573 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4574 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4575 if (chan == NULL)
4576 return -EINVAL;
026331c4
JM
4577
4578 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4579 if (!msg)
4580 return -ENOMEM;
026331c4
JM
4581
4582 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4583 NL80211_CMD_FRAME);
026331c4
JM
4584
4585 if (IS_ERR(hdr)) {
4586 err = PTR_ERR(hdr);
4587 goto free_msg;
4588 }
f7ca38df
JB
4589 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4590 channel_type_valid, wait,
2e161f78
JB
4591 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4592 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4593 &cookie);
026331c4
JM
4594 if (err)
4595 goto free_msg;
4596
4597 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4598
4599 genlmsg_end(msg, hdr);
4c476991 4600 return genlmsg_reply(msg, info);
026331c4
JM
4601
4602 nla_put_failure:
4603 err = -ENOBUFS;
4604 free_msg:
4605 nlmsg_free(msg);
026331c4
JM
4606 return err;
4607}
4608
f7ca38df
JB
4609static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4610{
4611 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4612 struct net_device *dev = info->user_ptr[1];
4613 u64 cookie;
4614
4615 if (!info->attrs[NL80211_ATTR_COOKIE])
4616 return -EINVAL;
4617
4618 if (!rdev->ops->mgmt_tx_cancel_wait)
4619 return -EOPNOTSUPP;
4620
4621 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4622 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4623 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4624 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4625 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4626 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4627 return -EOPNOTSUPP;
4628
4629 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4630
4631 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4632}
4633
ffb9eb3d
KV
4634static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4635{
4c476991 4636 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4637 struct wireless_dev *wdev;
4c476991 4638 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4639 u8 ps_state;
4640 bool state;
4641 int err;
4642
4c476991
JB
4643 if (!info->attrs[NL80211_ATTR_PS_STATE])
4644 return -EINVAL;
ffb9eb3d
KV
4645
4646 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4647
4c476991
JB
4648 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4649 return -EINVAL;
ffb9eb3d
KV
4650
4651 wdev = dev->ieee80211_ptr;
4652
4c476991
JB
4653 if (!rdev->ops->set_power_mgmt)
4654 return -EOPNOTSUPP;
ffb9eb3d
KV
4655
4656 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4657
4658 if (state == wdev->ps)
4c476991 4659 return 0;
ffb9eb3d 4660
4c476991
JB
4661 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4662 wdev->ps_timeout);
4663 if (!err)
4664 wdev->ps = state;
ffb9eb3d
KV
4665 return err;
4666}
4667
4668static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4669{
4c476991 4670 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4671 enum nl80211_ps_state ps_state;
4672 struct wireless_dev *wdev;
4c476991 4673 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4674 struct sk_buff *msg;
4675 void *hdr;
4676 int err;
4677
ffb9eb3d
KV
4678 wdev = dev->ieee80211_ptr;
4679
4c476991
JB
4680 if (!rdev->ops->set_power_mgmt)
4681 return -EOPNOTSUPP;
ffb9eb3d
KV
4682
4683 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4684 if (!msg)
4685 return -ENOMEM;
ffb9eb3d
KV
4686
4687 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4688 NL80211_CMD_GET_POWER_SAVE);
4689 if (!hdr) {
4c476991 4690 err = -ENOBUFS;
ffb9eb3d
KV
4691 goto free_msg;
4692 }
4693
4694 if (wdev->ps)
4695 ps_state = NL80211_PS_ENABLED;
4696 else
4697 ps_state = NL80211_PS_DISABLED;
4698
4699 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4700
4701 genlmsg_end(msg, hdr);
4c476991 4702 return genlmsg_reply(msg, info);
ffb9eb3d 4703
4c476991 4704 nla_put_failure:
ffb9eb3d 4705 err = -ENOBUFS;
4c476991 4706 free_msg:
ffb9eb3d 4707 nlmsg_free(msg);
ffb9eb3d
KV
4708 return err;
4709}
4710
d6dc1a38
JO
4711static struct nla_policy
4712nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4713 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4714 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4715 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4716};
4717
4718static int nl80211_set_cqm_rssi(struct genl_info *info,
4719 s32 threshold, u32 hysteresis)
4720{
4c476991 4721 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4722 struct wireless_dev *wdev;
4c476991 4723 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4724
4725 if (threshold > 0)
4726 return -EINVAL;
4727
d6dc1a38
JO
4728 wdev = dev->ieee80211_ptr;
4729
4c476991
JB
4730 if (!rdev->ops->set_cqm_rssi_config)
4731 return -EOPNOTSUPP;
d6dc1a38 4732
074ac8df 4733 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4734 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4735 return -EOPNOTSUPP;
d6dc1a38 4736
4c476991
JB
4737 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4738 threshold, hysteresis);
d6dc1a38
JO
4739}
4740
4741static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4742{
4743 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4744 struct nlattr *cqm;
4745 int err;
4746
4747 cqm = info->attrs[NL80211_ATTR_CQM];
4748 if (!cqm) {
4749 err = -EINVAL;
4750 goto out;
4751 }
4752
4753 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4754 nl80211_attr_cqm_policy);
4755 if (err)
4756 goto out;
4757
4758 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4759 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4760 s32 threshold;
4761 u32 hysteresis;
4762 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4763 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4764 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4765 } else
4766 err = -EINVAL;
4767
4768out:
4769 return err;
4770}
4771
29cbe68c
JB
4772static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
4773{
4774 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4775 struct net_device *dev = info->user_ptr[1];
4776 struct mesh_config cfg;
c80d545d 4777 struct mesh_setup setup;
29cbe68c
JB
4778 int err;
4779
4780 /* start with default */
4781 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 4782 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 4783
24bdd9f4 4784 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 4785 /* and parse parameters if given */
24bdd9f4 4786 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
4787 if (err)
4788 return err;
4789 }
4790
4791 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
4792 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
4793 return -EINVAL;
4794
c80d545d
JC
4795 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
4796 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4797
4798 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
4799 /* parse additional setup parameters if given */
4800 err = nl80211_parse_mesh_setup(info, &setup);
4801 if (err)
4802 return err;
4803 }
4804
4805 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
4806}
4807
4808static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
4809{
4810 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4811 struct net_device *dev = info->user_ptr[1];
4812
4813 return cfg80211_leave_mesh(rdev, dev);
4814}
4815
4c476991
JB
4816#define NL80211_FLAG_NEED_WIPHY 0x01
4817#define NL80211_FLAG_NEED_NETDEV 0x02
4818#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
4819#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
4820#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
4821 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
4822
4823static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
4824 struct genl_info *info)
4825{
4826 struct cfg80211_registered_device *rdev;
4827 struct net_device *dev;
4828 int err;
4829 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
4830
4831 if (rtnl)
4832 rtnl_lock();
4833
4834 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4835 rdev = cfg80211_get_dev_from_info(info);
4836 if (IS_ERR(rdev)) {
4837 if (rtnl)
4838 rtnl_unlock();
4839 return PTR_ERR(rdev);
4840 }
4841 info->user_ptr[0] = rdev;
4842 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
4843 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4844 if (err) {
4845 if (rtnl)
4846 rtnl_unlock();
4847 return err;
4848 }
41265714
JB
4849 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
4850 !netif_running(dev)) {
d537f5fd
JB
4851 cfg80211_unlock_rdev(rdev);
4852 dev_put(dev);
41265714
JB
4853 if (rtnl)
4854 rtnl_unlock();
4855 return -ENETDOWN;
4856 }
4c476991
JB
4857 info->user_ptr[0] = rdev;
4858 info->user_ptr[1] = dev;
4859 }
4860
4861 return 0;
4862}
4863
4864static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
4865 struct genl_info *info)
4866{
4867 if (info->user_ptr[0])
4868 cfg80211_unlock_rdev(info->user_ptr[0]);
4869 if (info->user_ptr[1])
4870 dev_put(info->user_ptr[1]);
4871 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
4872 rtnl_unlock();
4873}
4874
55682965
JB
4875static struct genl_ops nl80211_ops[] = {
4876 {
4877 .cmd = NL80211_CMD_GET_WIPHY,
4878 .doit = nl80211_get_wiphy,
4879 .dumpit = nl80211_dump_wiphy,
4880 .policy = nl80211_policy,
4881 /* can be retrieved by unprivileged users */
4c476991 4882 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
4883 },
4884 {
4885 .cmd = NL80211_CMD_SET_WIPHY,
4886 .doit = nl80211_set_wiphy,
4887 .policy = nl80211_policy,
4888 .flags = GENL_ADMIN_PERM,
4c476991 4889 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
4890 },
4891 {
4892 .cmd = NL80211_CMD_GET_INTERFACE,
4893 .doit = nl80211_get_interface,
4894 .dumpit = nl80211_dump_interface,
4895 .policy = nl80211_policy,
4896 /* can be retrieved by unprivileged users */
4c476991 4897 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
4898 },
4899 {
4900 .cmd = NL80211_CMD_SET_INTERFACE,
4901 .doit = nl80211_set_interface,
4902 .policy = nl80211_policy,
4903 .flags = GENL_ADMIN_PERM,
4c476991
JB
4904 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4905 NL80211_FLAG_NEED_RTNL,
55682965
JB
4906 },
4907 {
4908 .cmd = NL80211_CMD_NEW_INTERFACE,
4909 .doit = nl80211_new_interface,
4910 .policy = nl80211_policy,
4911 .flags = GENL_ADMIN_PERM,
4c476991
JB
4912 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4913 NL80211_FLAG_NEED_RTNL,
55682965
JB
4914 },
4915 {
4916 .cmd = NL80211_CMD_DEL_INTERFACE,
4917 .doit = nl80211_del_interface,
4918 .policy = nl80211_policy,
41ade00f 4919 .flags = GENL_ADMIN_PERM,
4c476991
JB
4920 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4921 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4922 },
4923 {
4924 .cmd = NL80211_CMD_GET_KEY,
4925 .doit = nl80211_get_key,
4926 .policy = nl80211_policy,
4927 .flags = GENL_ADMIN_PERM,
4c476991
JB
4928 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4929 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4930 },
4931 {
4932 .cmd = NL80211_CMD_SET_KEY,
4933 .doit = nl80211_set_key,
4934 .policy = nl80211_policy,
4935 .flags = GENL_ADMIN_PERM,
41265714 4936 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4937 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4938 },
4939 {
4940 .cmd = NL80211_CMD_NEW_KEY,
4941 .doit = nl80211_new_key,
4942 .policy = nl80211_policy,
4943 .flags = GENL_ADMIN_PERM,
41265714 4944 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4945 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4946 },
4947 {
4948 .cmd = NL80211_CMD_DEL_KEY,
4949 .doit = nl80211_del_key,
4950 .policy = nl80211_policy,
55682965 4951 .flags = GENL_ADMIN_PERM,
41265714 4952 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4953 NL80211_FLAG_NEED_RTNL,
55682965 4954 },
ed1b6cc7
JB
4955 {
4956 .cmd = NL80211_CMD_SET_BEACON,
4957 .policy = nl80211_policy,
4958 .flags = GENL_ADMIN_PERM,
4959 .doit = nl80211_addset_beacon,
4c476991
JB
4960 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4961 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4962 },
4963 {
4964 .cmd = NL80211_CMD_NEW_BEACON,
4965 .policy = nl80211_policy,
4966 .flags = GENL_ADMIN_PERM,
4967 .doit = nl80211_addset_beacon,
4c476991
JB
4968 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4969 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4970 },
4971 {
4972 .cmd = NL80211_CMD_DEL_BEACON,
4973 .policy = nl80211_policy,
4974 .flags = GENL_ADMIN_PERM,
4975 .doit = nl80211_del_beacon,
4c476991
JB
4976 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4977 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 4978 },
5727ef1b
JB
4979 {
4980 .cmd = NL80211_CMD_GET_STATION,
4981 .doit = nl80211_get_station,
2ec600d6 4982 .dumpit = nl80211_dump_station,
5727ef1b 4983 .policy = nl80211_policy,
4c476991
JB
4984 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4985 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4986 },
4987 {
4988 .cmd = NL80211_CMD_SET_STATION,
4989 .doit = nl80211_set_station,
4990 .policy = nl80211_policy,
4991 .flags = GENL_ADMIN_PERM,
4c476991
JB
4992 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4993 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4994 },
4995 {
4996 .cmd = NL80211_CMD_NEW_STATION,
4997 .doit = nl80211_new_station,
4998 .policy = nl80211_policy,
4999 .flags = GENL_ADMIN_PERM,
41265714 5000 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5001 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5002 },
5003 {
5004 .cmd = NL80211_CMD_DEL_STATION,
5005 .doit = nl80211_del_station,
5006 .policy = nl80211_policy,
2ec600d6 5007 .flags = GENL_ADMIN_PERM,
4c476991
JB
5008 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5009 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5010 },
5011 {
5012 .cmd = NL80211_CMD_GET_MPATH,
5013 .doit = nl80211_get_mpath,
5014 .dumpit = nl80211_dump_mpath,
5015 .policy = nl80211_policy,
5016 .flags = GENL_ADMIN_PERM,
41265714 5017 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5018 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5019 },
5020 {
5021 .cmd = NL80211_CMD_SET_MPATH,
5022 .doit = nl80211_set_mpath,
5023 .policy = nl80211_policy,
5024 .flags = GENL_ADMIN_PERM,
41265714 5025 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5026 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5027 },
5028 {
5029 .cmd = NL80211_CMD_NEW_MPATH,
5030 .doit = nl80211_new_mpath,
5031 .policy = nl80211_policy,
5032 .flags = GENL_ADMIN_PERM,
41265714 5033 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5034 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5035 },
5036 {
5037 .cmd = NL80211_CMD_DEL_MPATH,
5038 .doit = nl80211_del_mpath,
5039 .policy = nl80211_policy,
9f1ba906 5040 .flags = GENL_ADMIN_PERM,
4c476991
JB
5041 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5042 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
5043 },
5044 {
5045 .cmd = NL80211_CMD_SET_BSS,
5046 .doit = nl80211_set_bss,
5047 .policy = nl80211_policy,
b2e1b302 5048 .flags = GENL_ADMIN_PERM,
4c476991
JB
5049 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5050 NL80211_FLAG_NEED_RTNL,
b2e1b302 5051 },
f130347c
LR
5052 {
5053 .cmd = NL80211_CMD_GET_REG,
5054 .doit = nl80211_get_reg,
5055 .policy = nl80211_policy,
5056 /* can be retrieved by unprivileged users */
5057 },
b2e1b302
LR
5058 {
5059 .cmd = NL80211_CMD_SET_REG,
5060 .doit = nl80211_set_reg,
5061 .policy = nl80211_policy,
5062 .flags = GENL_ADMIN_PERM,
5063 },
5064 {
5065 .cmd = NL80211_CMD_REQ_SET_REG,
5066 .doit = nl80211_req_set_reg,
5067 .policy = nl80211_policy,
93da9cc1 5068 .flags = GENL_ADMIN_PERM,
5069 },
5070 {
24bdd9f4
JC
5071 .cmd = NL80211_CMD_GET_MESH_CONFIG,
5072 .doit = nl80211_get_mesh_config,
93da9cc1 5073 .policy = nl80211_policy,
5074 /* can be retrieved by unprivileged users */
4c476991
JB
5075 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5076 NL80211_FLAG_NEED_RTNL,
93da9cc1 5077 },
5078 {
24bdd9f4
JC
5079 .cmd = NL80211_CMD_SET_MESH_CONFIG,
5080 .doit = nl80211_update_mesh_config,
93da9cc1 5081 .policy = nl80211_policy,
9aed3cc1 5082 .flags = GENL_ADMIN_PERM,
29cbe68c 5083 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5084 NL80211_FLAG_NEED_RTNL,
9aed3cc1 5085 },
2a519311
JB
5086 {
5087 .cmd = NL80211_CMD_TRIGGER_SCAN,
5088 .doit = nl80211_trigger_scan,
5089 .policy = nl80211_policy,
5090 .flags = GENL_ADMIN_PERM,
41265714 5091 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5092 NL80211_FLAG_NEED_RTNL,
2a519311
JB
5093 },
5094 {
5095 .cmd = NL80211_CMD_GET_SCAN,
5096 .policy = nl80211_policy,
5097 .dumpit = nl80211_dump_scan,
5098 },
636a5d36
JM
5099 {
5100 .cmd = NL80211_CMD_AUTHENTICATE,
5101 .doit = nl80211_authenticate,
5102 .policy = nl80211_policy,
5103 .flags = GENL_ADMIN_PERM,
41265714 5104 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5105 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5106 },
5107 {
5108 .cmd = NL80211_CMD_ASSOCIATE,
5109 .doit = nl80211_associate,
5110 .policy = nl80211_policy,
5111 .flags = GENL_ADMIN_PERM,
41265714 5112 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5113 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5114 },
5115 {
5116 .cmd = NL80211_CMD_DEAUTHENTICATE,
5117 .doit = nl80211_deauthenticate,
5118 .policy = nl80211_policy,
5119 .flags = GENL_ADMIN_PERM,
41265714 5120 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5121 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5122 },
5123 {
5124 .cmd = NL80211_CMD_DISASSOCIATE,
5125 .doit = nl80211_disassociate,
5126 .policy = nl80211_policy,
5127 .flags = GENL_ADMIN_PERM,
41265714 5128 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5129 NL80211_FLAG_NEED_RTNL,
636a5d36 5130 },
04a773ad
JB
5131 {
5132 .cmd = NL80211_CMD_JOIN_IBSS,
5133 .doit = nl80211_join_ibss,
5134 .policy = nl80211_policy,
5135 .flags = GENL_ADMIN_PERM,
41265714 5136 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5137 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
5138 },
5139 {
5140 .cmd = NL80211_CMD_LEAVE_IBSS,
5141 .doit = nl80211_leave_ibss,
5142 .policy = nl80211_policy,
5143 .flags = GENL_ADMIN_PERM,
41265714 5144 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5145 NL80211_FLAG_NEED_RTNL,
04a773ad 5146 },
aff89a9b
JB
5147#ifdef CONFIG_NL80211_TESTMODE
5148 {
5149 .cmd = NL80211_CMD_TESTMODE,
5150 .doit = nl80211_testmode_do,
5151 .policy = nl80211_policy,
5152 .flags = GENL_ADMIN_PERM,
4c476991
JB
5153 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5154 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
5155 },
5156#endif
b23aa676
SO
5157 {
5158 .cmd = NL80211_CMD_CONNECT,
5159 .doit = nl80211_connect,
5160 .policy = nl80211_policy,
5161 .flags = GENL_ADMIN_PERM,
41265714 5162 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5163 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
5164 },
5165 {
5166 .cmd = NL80211_CMD_DISCONNECT,
5167 .doit = nl80211_disconnect,
5168 .policy = nl80211_policy,
5169 .flags = GENL_ADMIN_PERM,
41265714 5170 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5171 NL80211_FLAG_NEED_RTNL,
b23aa676 5172 },
463d0183
JB
5173 {
5174 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5175 .doit = nl80211_wiphy_netns,
5176 .policy = nl80211_policy,
5177 .flags = GENL_ADMIN_PERM,
4c476991
JB
5178 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5179 NL80211_FLAG_NEED_RTNL,
463d0183 5180 },
61fa713c
HS
5181 {
5182 .cmd = NL80211_CMD_GET_SURVEY,
5183 .policy = nl80211_policy,
5184 .dumpit = nl80211_dump_survey,
5185 },
67fbb16b
SO
5186 {
5187 .cmd = NL80211_CMD_SET_PMKSA,
5188 .doit = nl80211_setdel_pmksa,
5189 .policy = nl80211_policy,
5190 .flags = GENL_ADMIN_PERM,
4c476991
JB
5191 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5192 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5193 },
5194 {
5195 .cmd = NL80211_CMD_DEL_PMKSA,
5196 .doit = nl80211_setdel_pmksa,
5197 .policy = nl80211_policy,
5198 .flags = GENL_ADMIN_PERM,
4c476991
JB
5199 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5200 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5201 },
5202 {
5203 .cmd = NL80211_CMD_FLUSH_PMKSA,
5204 .doit = nl80211_flush_pmksa,
5205 .policy = nl80211_policy,
5206 .flags = GENL_ADMIN_PERM,
4c476991
JB
5207 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5208 NL80211_FLAG_NEED_RTNL,
67fbb16b 5209 },
9588bbd5
JM
5210 {
5211 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5212 .doit = nl80211_remain_on_channel,
5213 .policy = nl80211_policy,
5214 .flags = GENL_ADMIN_PERM,
41265714 5215 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5216 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
5217 },
5218 {
5219 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5220 .doit = nl80211_cancel_remain_on_channel,
5221 .policy = nl80211_policy,
5222 .flags = GENL_ADMIN_PERM,
41265714 5223 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5224 NL80211_FLAG_NEED_RTNL,
9588bbd5 5225 },
13ae75b1
JM
5226 {
5227 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5228 .doit = nl80211_set_tx_bitrate_mask,
5229 .policy = nl80211_policy,
5230 .flags = GENL_ADMIN_PERM,
4c476991
JB
5231 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5232 NL80211_FLAG_NEED_RTNL,
13ae75b1 5233 },
026331c4 5234 {
2e161f78
JB
5235 .cmd = NL80211_CMD_REGISTER_FRAME,
5236 .doit = nl80211_register_mgmt,
026331c4
JM
5237 .policy = nl80211_policy,
5238 .flags = GENL_ADMIN_PERM,
4c476991
JB
5239 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5240 NL80211_FLAG_NEED_RTNL,
026331c4
JM
5241 },
5242 {
2e161f78
JB
5243 .cmd = NL80211_CMD_FRAME,
5244 .doit = nl80211_tx_mgmt,
026331c4 5245 .policy = nl80211_policy,
f7ca38df
JB
5246 .flags = GENL_ADMIN_PERM,
5247 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5248 NL80211_FLAG_NEED_RTNL,
5249 },
5250 {
5251 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5252 .doit = nl80211_tx_mgmt_cancel_wait,
5253 .policy = nl80211_policy,
026331c4 5254 .flags = GENL_ADMIN_PERM,
41265714 5255 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5256 NL80211_FLAG_NEED_RTNL,
026331c4 5257 },
ffb9eb3d
KV
5258 {
5259 .cmd = NL80211_CMD_SET_POWER_SAVE,
5260 .doit = nl80211_set_power_save,
5261 .policy = nl80211_policy,
5262 .flags = GENL_ADMIN_PERM,
4c476991
JB
5263 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5264 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
5265 },
5266 {
5267 .cmd = NL80211_CMD_GET_POWER_SAVE,
5268 .doit = nl80211_get_power_save,
5269 .policy = nl80211_policy,
5270 /* can be retrieved by unprivileged users */
4c476991
JB
5271 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5272 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 5273 },
d6dc1a38
JO
5274 {
5275 .cmd = NL80211_CMD_SET_CQM,
5276 .doit = nl80211_set_cqm,
5277 .policy = nl80211_policy,
5278 .flags = GENL_ADMIN_PERM,
4c476991
JB
5279 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5280 NL80211_FLAG_NEED_RTNL,
d6dc1a38 5281 },
f444de05
JB
5282 {
5283 .cmd = NL80211_CMD_SET_CHANNEL,
5284 .doit = nl80211_set_channel,
5285 .policy = nl80211_policy,
5286 .flags = GENL_ADMIN_PERM,
4c476991
JB
5287 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5288 NL80211_FLAG_NEED_RTNL,
f444de05 5289 },
e8347eba
BJ
5290 {
5291 .cmd = NL80211_CMD_SET_WDS_PEER,
5292 .doit = nl80211_set_wds_peer,
5293 .policy = nl80211_policy,
5294 .flags = GENL_ADMIN_PERM,
43b19952
JB
5295 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5296 NL80211_FLAG_NEED_RTNL,
e8347eba 5297 },
29cbe68c
JB
5298 {
5299 .cmd = NL80211_CMD_JOIN_MESH,
5300 .doit = nl80211_join_mesh,
5301 .policy = nl80211_policy,
5302 .flags = GENL_ADMIN_PERM,
5303 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5304 NL80211_FLAG_NEED_RTNL,
5305 },
5306 {
5307 .cmd = NL80211_CMD_LEAVE_MESH,
5308 .doit = nl80211_leave_mesh,
5309 .policy = nl80211_policy,
5310 .flags = GENL_ADMIN_PERM,
5311 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5312 NL80211_FLAG_NEED_RTNL,
5313 },
55682965 5314};
9588bbd5 5315
6039f6d2
JM
5316static struct genl_multicast_group nl80211_mlme_mcgrp = {
5317 .name = "mlme",
5318};
55682965
JB
5319
5320/* multicast groups */
5321static struct genl_multicast_group nl80211_config_mcgrp = {
5322 .name = "config",
5323};
2a519311
JB
5324static struct genl_multicast_group nl80211_scan_mcgrp = {
5325 .name = "scan",
5326};
73d54c9e
LR
5327static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5328 .name = "regulatory",
5329};
55682965
JB
5330
5331/* notification functions */
5332
5333void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5334{
5335 struct sk_buff *msg;
5336
fd2120ca 5337 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5338 if (!msg)
5339 return;
5340
5341 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5342 nlmsg_free(msg);
5343 return;
5344 }
5345
463d0183
JB
5346 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5347 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5348}
5349
362a415d
JB
5350static int nl80211_add_scan_req(struct sk_buff *msg,
5351 struct cfg80211_registered_device *rdev)
5352{
5353 struct cfg80211_scan_request *req = rdev->scan_req;
5354 struct nlattr *nest;
5355 int i;
5356
667503dd
JB
5357 ASSERT_RDEV_LOCK(rdev);
5358
362a415d
JB
5359 if (WARN_ON(!req))
5360 return 0;
5361
5362 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5363 if (!nest)
5364 goto nla_put_failure;
5365 for (i = 0; i < req->n_ssids; i++)
5366 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5367 nla_nest_end(msg, nest);
5368
5369 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5370 if (!nest)
5371 goto nla_put_failure;
5372 for (i = 0; i < req->n_channels; i++)
5373 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5374 nla_nest_end(msg, nest);
5375
5376 if (req->ie)
5377 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5378
5379 return 0;
5380 nla_put_failure:
5381 return -ENOBUFS;
5382}
5383
a538e2d5
JB
5384static int nl80211_send_scan_msg(struct sk_buff *msg,
5385 struct cfg80211_registered_device *rdev,
5386 struct net_device *netdev,
5387 u32 pid, u32 seq, int flags,
5388 u32 cmd)
2a519311
JB
5389{
5390 void *hdr;
5391
5392 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5393 if (!hdr)
5394 return -1;
5395
b5850a7a 5396 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5397 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5398
362a415d
JB
5399 /* ignore errors and send incomplete event anyway */
5400 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5401
5402 return genlmsg_end(msg, hdr);
5403
5404 nla_put_failure:
5405 genlmsg_cancel(msg, hdr);
5406 return -EMSGSIZE;
5407}
5408
a538e2d5
JB
5409void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5410 struct net_device *netdev)
5411{
5412 struct sk_buff *msg;
5413
5414 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5415 if (!msg)
5416 return;
5417
5418 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5419 NL80211_CMD_TRIGGER_SCAN) < 0) {
5420 nlmsg_free(msg);
5421 return;
5422 }
5423
463d0183
JB
5424 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5425 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5426}
5427
2a519311
JB
5428void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5429 struct net_device *netdev)
5430{
5431 struct sk_buff *msg;
5432
fd2120ca 5433 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5434 if (!msg)
5435 return;
5436
a538e2d5
JB
5437 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5438 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5439 nlmsg_free(msg);
5440 return;
5441 }
5442
463d0183
JB
5443 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5444 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5445}
5446
5447void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5448 struct net_device *netdev)
5449{
5450 struct sk_buff *msg;
5451
fd2120ca 5452 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5453 if (!msg)
5454 return;
5455
a538e2d5
JB
5456 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5457 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5458 nlmsg_free(msg);
5459 return;
5460 }
5461
463d0183
JB
5462 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5463 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5464}
5465
73d54c9e
LR
5466/*
5467 * This can happen on global regulatory changes or device specific settings
5468 * based on custom world regulatory domains.
5469 */
5470void nl80211_send_reg_change_event(struct regulatory_request *request)
5471{
5472 struct sk_buff *msg;
5473 void *hdr;
5474
fd2120ca 5475 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5476 if (!msg)
5477 return;
5478
5479 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5480 if (!hdr) {
5481 nlmsg_free(msg);
5482 return;
5483 }
5484
5485 /* Userspace can always count this one always being set */
5486 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5487
5488 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5489 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5490 NL80211_REGDOM_TYPE_WORLD);
5491 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5492 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5493 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5494 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5495 request->intersect)
5496 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5497 NL80211_REGDOM_TYPE_INTERSECTION);
5498 else {
5499 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5500 NL80211_REGDOM_TYPE_COUNTRY);
5501 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5502 }
5503
5504 if (wiphy_idx_valid(request->wiphy_idx))
5505 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5506
5507 if (genlmsg_end(msg, hdr) < 0) {
5508 nlmsg_free(msg);
5509 return;
5510 }
5511
bc43b28c 5512 rcu_read_lock();
463d0183 5513 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5514 GFP_ATOMIC);
5515 rcu_read_unlock();
73d54c9e
LR
5516
5517 return;
5518
5519nla_put_failure:
5520 genlmsg_cancel(msg, hdr);
5521 nlmsg_free(msg);
5522}
5523
6039f6d2
JM
5524static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5525 struct net_device *netdev,
5526 const u8 *buf, size_t len,
e6d6e342 5527 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5528{
5529 struct sk_buff *msg;
5530 void *hdr;
5531
e6d6e342 5532 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5533 if (!msg)
5534 return;
5535
5536 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5537 if (!hdr) {
5538 nlmsg_free(msg);
5539 return;
5540 }
5541
5542 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5543 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5544 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5545
5546 if (genlmsg_end(msg, hdr) < 0) {
5547 nlmsg_free(msg);
5548 return;
5549 }
5550
463d0183
JB
5551 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5552 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5553 return;
5554
5555 nla_put_failure:
5556 genlmsg_cancel(msg, hdr);
5557 nlmsg_free(msg);
5558}
5559
5560void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5561 struct net_device *netdev, const u8 *buf,
5562 size_t len, gfp_t gfp)
6039f6d2
JM
5563{
5564 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5565 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5566}
5567
5568void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5569 struct net_device *netdev, const u8 *buf,
e6d6e342 5570 size_t len, gfp_t gfp)
6039f6d2 5571{
e6d6e342
JB
5572 nl80211_send_mlme_event(rdev, netdev, buf, len,
5573 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5574}
5575
53b46b84 5576void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5577 struct net_device *netdev, const u8 *buf,
5578 size_t len, gfp_t gfp)
6039f6d2
JM
5579{
5580 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5581 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5582}
5583
53b46b84
JM
5584void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5585 struct net_device *netdev, const u8 *buf,
e6d6e342 5586 size_t len, gfp_t gfp)
6039f6d2
JM
5587{
5588 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5589 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5590}
5591
cf4e594e
JM
5592void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
5593 struct net_device *netdev, const u8 *buf,
5594 size_t len, gfp_t gfp)
5595{
5596 nl80211_send_mlme_event(rdev, netdev, buf, len,
5597 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
5598}
5599
5600void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
5601 struct net_device *netdev, const u8 *buf,
5602 size_t len, gfp_t gfp)
5603{
5604 nl80211_send_mlme_event(rdev, netdev, buf, len,
5605 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
5606}
5607
1b06bb40
LR
5608static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5609 struct net_device *netdev, int cmd,
e6d6e342 5610 const u8 *addr, gfp_t gfp)
1965c853
JM
5611{
5612 struct sk_buff *msg;
5613 void *hdr;
5614
e6d6e342 5615 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5616 if (!msg)
5617 return;
5618
5619 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5620 if (!hdr) {
5621 nlmsg_free(msg);
5622 return;
5623 }
5624
5625 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5626 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5627 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5628 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5629
5630 if (genlmsg_end(msg, hdr) < 0) {
5631 nlmsg_free(msg);
5632 return;
5633 }
5634
463d0183
JB
5635 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5636 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5637 return;
5638
5639 nla_put_failure:
5640 genlmsg_cancel(msg, hdr);
5641 nlmsg_free(msg);
5642}
5643
5644void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5645 struct net_device *netdev, const u8 *addr,
5646 gfp_t gfp)
1965c853
JM
5647{
5648 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5649 addr, gfp);
1965c853
JM
5650}
5651
5652void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5653 struct net_device *netdev, const u8 *addr,
5654 gfp_t gfp)
1965c853 5655{
e6d6e342
JB
5656 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5657 addr, gfp);
1965c853
JM
5658}
5659
b23aa676
SO
5660void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5661 struct net_device *netdev, const u8 *bssid,
5662 const u8 *req_ie, size_t req_ie_len,
5663 const u8 *resp_ie, size_t resp_ie_len,
5664 u16 status, gfp_t gfp)
5665{
5666 struct sk_buff *msg;
5667 void *hdr;
5668
5669 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5670 if (!msg)
5671 return;
5672
5673 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5674 if (!hdr) {
5675 nlmsg_free(msg);
5676 return;
5677 }
5678
5679 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5680 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5681 if (bssid)
5682 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5683 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5684 if (req_ie)
5685 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5686 if (resp_ie)
5687 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5688
5689 if (genlmsg_end(msg, hdr) < 0) {
5690 nlmsg_free(msg);
5691 return;
5692 }
5693
463d0183
JB
5694 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5695 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5696 return;
5697
5698 nla_put_failure:
5699 genlmsg_cancel(msg, hdr);
5700 nlmsg_free(msg);
5701
5702}
5703
5704void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5705 struct net_device *netdev, const u8 *bssid,
5706 const u8 *req_ie, size_t req_ie_len,
5707 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5708{
5709 struct sk_buff *msg;
5710 void *hdr;
5711
5712 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5713 if (!msg)
5714 return;
5715
5716 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5717 if (!hdr) {
5718 nlmsg_free(msg);
5719 return;
5720 }
5721
5722 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5723 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5724 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5725 if (req_ie)
5726 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5727 if (resp_ie)
5728 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5729
5730 if (genlmsg_end(msg, hdr) < 0) {
5731 nlmsg_free(msg);
5732 return;
5733 }
5734
463d0183
JB
5735 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5736 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5737 return;
5738
5739 nla_put_failure:
5740 genlmsg_cancel(msg, hdr);
5741 nlmsg_free(msg);
5742
5743}
5744
5745void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5746 struct net_device *netdev, u16 reason,
667503dd 5747 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5748{
5749 struct sk_buff *msg;
5750 void *hdr;
5751
667503dd 5752 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5753 if (!msg)
5754 return;
5755
5756 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5757 if (!hdr) {
5758 nlmsg_free(msg);
5759 return;
5760 }
5761
5762 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5763 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5764 if (from_ap && reason)
5765 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5766 if (from_ap)
5767 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5768 if (ie)
5769 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5770
5771 if (genlmsg_end(msg, hdr) < 0) {
5772 nlmsg_free(msg);
5773 return;
5774 }
5775
463d0183
JB
5776 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5777 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5778 return;
5779
5780 nla_put_failure:
5781 genlmsg_cancel(msg, hdr);
5782 nlmsg_free(msg);
5783
5784}
5785
04a773ad
JB
5786void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5787 struct net_device *netdev, const u8 *bssid,
5788 gfp_t gfp)
5789{
5790 struct sk_buff *msg;
5791 void *hdr;
5792
fd2120ca 5793 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5794 if (!msg)
5795 return;
5796
5797 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5798 if (!hdr) {
5799 nlmsg_free(msg);
5800 return;
5801 }
5802
5803 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5804 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5805 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5806
5807 if (genlmsg_end(msg, hdr) < 0) {
5808 nlmsg_free(msg);
5809 return;
5810 }
5811
463d0183
JB
5812 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5813 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5814 return;
5815
5816 nla_put_failure:
5817 genlmsg_cancel(msg, hdr);
5818 nlmsg_free(msg);
5819}
5820
a3b8b056
JM
5821void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5822 struct net_device *netdev, const u8 *addr,
5823 enum nl80211_key_type key_type, int key_id,
e6d6e342 5824 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5825{
5826 struct sk_buff *msg;
5827 void *hdr;
5828
e6d6e342 5829 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5830 if (!msg)
5831 return;
5832
5833 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5834 if (!hdr) {
5835 nlmsg_free(msg);
5836 return;
5837 }
5838
5839 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5840 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5841 if (addr)
5842 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5843 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5844 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5845 if (tsc)
5846 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5847
5848 if (genlmsg_end(msg, hdr) < 0) {
5849 nlmsg_free(msg);
5850 return;
5851 }
5852
463d0183
JB
5853 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5854 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5855 return;
5856
5857 nla_put_failure:
5858 genlmsg_cancel(msg, hdr);
5859 nlmsg_free(msg);
5860}
5861
6bad8766
LR
5862void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5863 struct ieee80211_channel *channel_before,
5864 struct ieee80211_channel *channel_after)
5865{
5866 struct sk_buff *msg;
5867 void *hdr;
5868 struct nlattr *nl_freq;
5869
fd2120ca 5870 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5871 if (!msg)
5872 return;
5873
5874 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5875 if (!hdr) {
5876 nlmsg_free(msg);
5877 return;
5878 }
5879
5880 /*
5881 * Since we are applying the beacon hint to a wiphy we know its
5882 * wiphy_idx is valid
5883 */
5884 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5885
5886 /* Before */
5887 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5888 if (!nl_freq)
5889 goto nla_put_failure;
5890 if (nl80211_msg_put_channel(msg, channel_before))
5891 goto nla_put_failure;
5892 nla_nest_end(msg, nl_freq);
5893
5894 /* After */
5895 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5896 if (!nl_freq)
5897 goto nla_put_failure;
5898 if (nl80211_msg_put_channel(msg, channel_after))
5899 goto nla_put_failure;
5900 nla_nest_end(msg, nl_freq);
5901
5902 if (genlmsg_end(msg, hdr) < 0) {
5903 nlmsg_free(msg);
5904 return;
5905 }
5906
463d0183
JB
5907 rcu_read_lock();
5908 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5909 GFP_ATOMIC);
5910 rcu_read_unlock();
6bad8766
LR
5911
5912 return;
5913
5914nla_put_failure:
5915 genlmsg_cancel(msg, hdr);
5916 nlmsg_free(msg);
5917}
5918
9588bbd5
JM
5919static void nl80211_send_remain_on_chan_event(
5920 int cmd, struct cfg80211_registered_device *rdev,
5921 struct net_device *netdev, u64 cookie,
5922 struct ieee80211_channel *chan,
5923 enum nl80211_channel_type channel_type,
5924 unsigned int duration, gfp_t gfp)
5925{
5926 struct sk_buff *msg;
5927 void *hdr;
5928
5929 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5930 if (!msg)
5931 return;
5932
5933 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5934 if (!hdr) {
5935 nlmsg_free(msg);
5936 return;
5937 }
5938
5939 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5940 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5941 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5942 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5943 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5944
5945 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5946 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5947
5948 if (genlmsg_end(msg, hdr) < 0) {
5949 nlmsg_free(msg);
5950 return;
5951 }
5952
5953 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5954 nl80211_mlme_mcgrp.id, gfp);
5955 return;
5956
5957 nla_put_failure:
5958 genlmsg_cancel(msg, hdr);
5959 nlmsg_free(msg);
5960}
5961
5962void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5963 struct net_device *netdev, u64 cookie,
5964 struct ieee80211_channel *chan,
5965 enum nl80211_channel_type channel_type,
5966 unsigned int duration, gfp_t gfp)
5967{
5968 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5969 rdev, netdev, cookie, chan,
5970 channel_type, duration, gfp);
5971}
5972
5973void nl80211_send_remain_on_channel_cancel(
5974 struct cfg80211_registered_device *rdev, struct net_device *netdev,
5975 u64 cookie, struct ieee80211_channel *chan,
5976 enum nl80211_channel_type channel_type, gfp_t gfp)
5977{
5978 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5979 rdev, netdev, cookie, chan,
5980 channel_type, 0, gfp);
5981}
5982
98b62183
JB
5983void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5984 struct net_device *dev, const u8 *mac_addr,
5985 struct station_info *sinfo, gfp_t gfp)
5986{
5987 struct sk_buff *msg;
5988
5989 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5990 if (!msg)
5991 return;
5992
5993 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5994 nlmsg_free(msg);
5995 return;
5996 }
5997
5998 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5999 nl80211_mlme_mcgrp.id, gfp);
6000}
6001
ec15e68b
JM
6002void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
6003 struct net_device *dev, const u8 *mac_addr,
6004 gfp_t gfp)
6005{
6006 struct sk_buff *msg;
6007 void *hdr;
6008
6009 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6010 if (!msg)
6011 return;
6012
6013 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
6014 if (!hdr) {
6015 nlmsg_free(msg);
6016 return;
6017 }
6018
6019 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
6020 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
6021
6022 if (genlmsg_end(msg, hdr) < 0) {
6023 nlmsg_free(msg);
6024 return;
6025 }
6026
6027 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6028 nl80211_mlme_mcgrp.id, gfp);
6029 return;
6030
6031 nla_put_failure:
6032 genlmsg_cancel(msg, hdr);
6033 nlmsg_free(msg);
6034}
6035
2e161f78
JB
6036int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6037 struct net_device *netdev, u32 nlpid,
6038 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
6039{
6040 struct sk_buff *msg;
6041 void *hdr;
6042 int err;
6043
6044 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6045 if (!msg)
6046 return -ENOMEM;
6047
2e161f78 6048 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
6049 if (!hdr) {
6050 nlmsg_free(msg);
6051 return -ENOMEM;
6052 }
6053
6054 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6055 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6056 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6057 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6058
6059 err = genlmsg_end(msg, hdr);
6060 if (err < 0) {
6061 nlmsg_free(msg);
6062 return err;
6063 }
6064
6065 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6066 if (err < 0)
6067 return err;
6068 return 0;
6069
6070 nla_put_failure:
6071 genlmsg_cancel(msg, hdr);
6072 nlmsg_free(msg);
6073 return -ENOBUFS;
6074}
6075
2e161f78
JB
6076void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6077 struct net_device *netdev, u64 cookie,
6078 const u8 *buf, size_t len, bool ack,
6079 gfp_t gfp)
026331c4
JM
6080{
6081 struct sk_buff *msg;
6082 void *hdr;
6083
6084 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6085 if (!msg)
6086 return;
6087
2e161f78 6088 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6089 if (!hdr) {
6090 nlmsg_free(msg);
6091 return;
6092 }
6093
6094 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6095 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6096 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6097 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6098 if (ack)
6099 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6100
6101 if (genlmsg_end(msg, hdr) < 0) {
6102 nlmsg_free(msg);
6103 return;
6104 }
6105
6106 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6107 return;
6108
6109 nla_put_failure:
6110 genlmsg_cancel(msg, hdr);
6111 nlmsg_free(msg);
6112}
6113
d6dc1a38
JO
6114void
6115nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6116 struct net_device *netdev,
6117 enum nl80211_cqm_rssi_threshold_event rssi_event,
6118 gfp_t gfp)
6119{
6120 struct sk_buff *msg;
6121 struct nlattr *pinfoattr;
6122 void *hdr;
6123
6124 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6125 if (!msg)
6126 return;
6127
6128 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6129 if (!hdr) {
6130 nlmsg_free(msg);
6131 return;
6132 }
6133
6134 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6135 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6136
6137 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6138 if (!pinfoattr)
6139 goto nla_put_failure;
6140
6141 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6142 rssi_event);
6143
6144 nla_nest_end(msg, pinfoattr);
6145
6146 if (genlmsg_end(msg, hdr) < 0) {
6147 nlmsg_free(msg);
6148 return;
6149 }
6150
6151 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6152 nl80211_mlme_mcgrp.id, gfp);
6153 return;
6154
6155 nla_put_failure:
6156 genlmsg_cancel(msg, hdr);
6157 nlmsg_free(msg);
6158}
6159
c063dbf5
JB
6160void
6161nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6162 struct net_device *netdev, const u8 *peer,
6163 u32 num_packets, gfp_t gfp)
6164{
6165 struct sk_buff *msg;
6166 struct nlattr *pinfoattr;
6167 void *hdr;
6168
6169 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6170 if (!msg)
6171 return;
6172
6173 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6174 if (!hdr) {
6175 nlmsg_free(msg);
6176 return;
6177 }
6178
6179 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6180 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6181 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6182
6183 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6184 if (!pinfoattr)
6185 goto nla_put_failure;
6186
6187 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6188
6189 nla_nest_end(msg, pinfoattr);
6190
6191 if (genlmsg_end(msg, hdr) < 0) {
6192 nlmsg_free(msg);
6193 return;
6194 }
6195
6196 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6197 nl80211_mlme_mcgrp.id, gfp);
6198 return;
6199
6200 nla_put_failure:
6201 genlmsg_cancel(msg, hdr);
6202 nlmsg_free(msg);
6203}
6204
026331c4
JM
6205static int nl80211_netlink_notify(struct notifier_block * nb,
6206 unsigned long state,
6207 void *_notify)
6208{
6209 struct netlink_notify *notify = _notify;
6210 struct cfg80211_registered_device *rdev;
6211 struct wireless_dev *wdev;
6212
6213 if (state != NETLINK_URELEASE)
6214 return NOTIFY_DONE;
6215
6216 rcu_read_lock();
6217
6218 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6219 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6220 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6221
6222 rcu_read_unlock();
6223
6224 return NOTIFY_DONE;
6225}
6226
6227static struct notifier_block nl80211_netlink_notifier = {
6228 .notifier_call = nl80211_netlink_notify,
6229};
6230
55682965
JB
6231/* initialisation/exit functions */
6232
6233int nl80211_init(void)
6234{
0d63cbb5 6235 int err;
55682965 6236
0d63cbb5
MM
6237 err = genl_register_family_with_ops(&nl80211_fam,
6238 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6239 if (err)
6240 return err;
6241
55682965
JB
6242 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6243 if (err)
6244 goto err_out;
6245
2a519311
JB
6246 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6247 if (err)
6248 goto err_out;
6249
73d54c9e
LR
6250 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6251 if (err)
6252 goto err_out;
6253
6039f6d2
JM
6254 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6255 if (err)
6256 goto err_out;
6257
aff89a9b
JB
6258#ifdef CONFIG_NL80211_TESTMODE
6259 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6260 if (err)
6261 goto err_out;
6262#endif
6263
026331c4
JM
6264 err = netlink_register_notifier(&nl80211_netlink_notifier);
6265 if (err)
6266 goto err_out;
6267
55682965
JB
6268 return 0;
6269 err_out:
6270 genl_unregister_family(&nl80211_fam);
6271 return err;
6272}
6273
6274void nl80211_exit(void)
6275{
026331c4 6276 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6277 genl_unregister_family(&nl80211_fam);
6278}