]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
nl80211: Let userspace drive the peer link management states.
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
e31b8213 96 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
97
98 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101 .len = IEEE80211_MAX_DATA_LEN },
102 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
104 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 109 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 110 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 111 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
112 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113 .len = IEEE80211_MAX_MESH_ID_LEN },
114 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 115
b2e1b302
LR
116 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
9f1ba906
JM
119 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
122 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123 .len = NL80211_MAX_SUPP_RATES },
50b12f59 124 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 125
24bdd9f4 126 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 127 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 128
36aedc90
JM
129 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
130 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
131
132 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
133 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
134 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
135 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
136 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
137
138 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_SSID_LEN },
140 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
141 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 142 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 143 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 144 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
145 [NL80211_ATTR_STA_FLAGS2] = {
146 .len = sizeof(struct nl80211_sta_flag_update),
147 },
3f77316c 148 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
149 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
150 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
151 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
152 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
153 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 154 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 155 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
156 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
157 .len = WLAN_PMKID_LEN },
9588bbd5
JM
158 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
159 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 160 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
161 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
162 .len = IEEE80211_MAX_DATA_LEN },
163 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 164 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 165 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 166 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 167 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
168 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
169 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 170 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
171 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
172 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 173 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 174 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 175 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 176 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 177 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
55682965
JB
178};
179
e31b8213 180/* policy for the key attributes */
b54452b0 181static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 182 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
183 [NL80211_KEY_IDX] = { .type = NLA_U8 },
184 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
185 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
186 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
187 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 188 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
189 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
190};
191
192/* policy for the key default flags */
193static const struct nla_policy
194nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
195 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
196 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
197};
198
ff1b6e69
JB
199/* policy for WoWLAN attributes */
200static const struct nla_policy
201nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
202 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
203 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
204 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
205 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
206};
207
a043897a
HS
208/* ifidx get helper */
209static int nl80211_get_ifidx(struct netlink_callback *cb)
210{
211 int res;
212
213 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
214 nl80211_fam.attrbuf, nl80211_fam.maxattr,
215 nl80211_policy);
216 if (res)
217 return res;
218
219 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
220 return -EINVAL;
221
222 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
223 if (!res)
224 return -EINVAL;
225 return res;
226}
227
67748893
JB
228static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
229 struct netlink_callback *cb,
230 struct cfg80211_registered_device **rdev,
231 struct net_device **dev)
232{
233 int ifidx = cb->args[0];
234 int err;
235
236 if (!ifidx)
237 ifidx = nl80211_get_ifidx(cb);
238 if (ifidx < 0)
239 return ifidx;
240
241 cb->args[0] = ifidx;
242
243 rtnl_lock();
244
245 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
246 if (!*dev) {
247 err = -ENODEV;
248 goto out_rtnl;
249 }
250
251 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
252 if (IS_ERR(*rdev)) {
253 err = PTR_ERR(*rdev);
67748893
JB
254 goto out_rtnl;
255 }
256
257 return 0;
258 out_rtnl:
259 rtnl_unlock();
260 return err;
261}
262
263static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
264{
265 cfg80211_unlock_rdev(rdev);
266 rtnl_unlock();
267}
268
f4a11bb0
JB
269/* IE validation */
270static bool is_valid_ie_attr(const struct nlattr *attr)
271{
272 const u8 *pos;
273 int len;
274
275 if (!attr)
276 return true;
277
278 pos = nla_data(attr);
279 len = nla_len(attr);
280
281 while (len) {
282 u8 elemlen;
283
284 if (len < 2)
285 return false;
286 len -= 2;
287
288 elemlen = pos[1];
289 if (elemlen > len)
290 return false;
291
292 len -= elemlen;
293 pos += 2 + elemlen;
294 }
295
296 return true;
297}
298
55682965
JB
299/* message building helper */
300static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
301 int flags, u8 cmd)
302{
303 /* since there is no private header just add the generic one */
304 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
305}
306
5dab3b8a
LR
307static int nl80211_msg_put_channel(struct sk_buff *msg,
308 struct ieee80211_channel *chan)
309{
310 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
311 chan->center_freq);
312
313 if (chan->flags & IEEE80211_CHAN_DISABLED)
314 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
315 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
316 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
317 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
318 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
319 if (chan->flags & IEEE80211_CHAN_RADAR)
320 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
321
322 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
323 DBM_TO_MBM(chan->max_power));
324
325 return 0;
326
327 nla_put_failure:
328 return -ENOBUFS;
329}
330
55682965
JB
331/* netlink command implementations */
332
b9454e83
JB
333struct key_parse {
334 struct key_params p;
335 int idx;
e31b8213 336 int type;
b9454e83 337 bool def, defmgmt;
dbd2fd65 338 bool def_uni, def_multi;
b9454e83
JB
339};
340
341static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
342{
343 struct nlattr *tb[NL80211_KEY_MAX + 1];
344 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
345 nl80211_key_policy);
346 if (err)
347 return err;
348
349 k->def = !!tb[NL80211_KEY_DEFAULT];
350 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
351
dbd2fd65
JB
352 if (k->def) {
353 k->def_uni = true;
354 k->def_multi = true;
355 }
356 if (k->defmgmt)
357 k->def_multi = true;
358
b9454e83
JB
359 if (tb[NL80211_KEY_IDX])
360 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
361
362 if (tb[NL80211_KEY_DATA]) {
363 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
364 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
365 }
366
367 if (tb[NL80211_KEY_SEQ]) {
368 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
369 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
370 }
371
372 if (tb[NL80211_KEY_CIPHER])
373 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
374
e31b8213
JB
375 if (tb[NL80211_KEY_TYPE]) {
376 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
377 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
378 return -EINVAL;
379 }
380
dbd2fd65
JB
381 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
382 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
383 int err = nla_parse_nested(kdt,
384 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
385 tb[NL80211_KEY_DEFAULT_TYPES],
386 nl80211_key_default_policy);
387 if (err)
388 return err;
389
390 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
391 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
392 }
393
b9454e83
JB
394 return 0;
395}
396
397static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
398{
399 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
400 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
401 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
402 }
403
404 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
405 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
406 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
407 }
408
409 if (info->attrs[NL80211_ATTR_KEY_IDX])
410 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
411
412 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
413 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
414
415 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
416 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
417
dbd2fd65
JB
418 if (k->def) {
419 k->def_uni = true;
420 k->def_multi = true;
421 }
422 if (k->defmgmt)
423 k->def_multi = true;
424
e31b8213
JB
425 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
426 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
427 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
428 return -EINVAL;
429 }
430
dbd2fd65
JB
431 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
432 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
433 int err = nla_parse_nested(
434 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
435 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
436 nl80211_key_default_policy);
437 if (err)
438 return err;
439
440 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
441 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
442 }
443
b9454e83
JB
444 return 0;
445}
446
447static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
448{
449 int err;
450
451 memset(k, 0, sizeof(*k));
452 k->idx = -1;
e31b8213 453 k->type = -1;
b9454e83
JB
454
455 if (info->attrs[NL80211_ATTR_KEY])
456 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
457 else
458 err = nl80211_parse_key_old(info, k);
459
460 if (err)
461 return err;
462
463 if (k->def && k->defmgmt)
464 return -EINVAL;
465
dbd2fd65
JB
466 if (k->defmgmt) {
467 if (k->def_uni || !k->def_multi)
468 return -EINVAL;
469 }
470
b9454e83
JB
471 if (k->idx != -1) {
472 if (k->defmgmt) {
473 if (k->idx < 4 || k->idx > 5)
474 return -EINVAL;
475 } else if (k->def) {
476 if (k->idx < 0 || k->idx > 3)
477 return -EINVAL;
478 } else {
479 if (k->idx < 0 || k->idx > 5)
480 return -EINVAL;
481 }
482 }
483
484 return 0;
485}
486
fffd0934
JB
487static struct cfg80211_cached_keys *
488nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
489 struct nlattr *keys)
490{
491 struct key_parse parse;
492 struct nlattr *key;
493 struct cfg80211_cached_keys *result;
494 int rem, err, def = 0;
495
496 result = kzalloc(sizeof(*result), GFP_KERNEL);
497 if (!result)
498 return ERR_PTR(-ENOMEM);
499
500 result->def = -1;
501 result->defmgmt = -1;
502
503 nla_for_each_nested(key, keys, rem) {
504 memset(&parse, 0, sizeof(parse));
505 parse.idx = -1;
506
507 err = nl80211_parse_key_new(key, &parse);
508 if (err)
509 goto error;
510 err = -EINVAL;
511 if (!parse.p.key)
512 goto error;
513 if (parse.idx < 0 || parse.idx > 4)
514 goto error;
515 if (parse.def) {
516 if (def)
517 goto error;
518 def = 1;
519 result->def = parse.idx;
dbd2fd65
JB
520 if (!parse.def_uni || !parse.def_multi)
521 goto error;
fffd0934
JB
522 } else if (parse.defmgmt)
523 goto error;
524 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 525 parse.idx, false, NULL);
fffd0934
JB
526 if (err)
527 goto error;
528 result->params[parse.idx].cipher = parse.p.cipher;
529 result->params[parse.idx].key_len = parse.p.key_len;
530 result->params[parse.idx].key = result->data[parse.idx];
531 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
532 }
533
534 return result;
535 error:
536 kfree(result);
537 return ERR_PTR(err);
538}
539
540static int nl80211_key_allowed(struct wireless_dev *wdev)
541{
542 ASSERT_WDEV_LOCK(wdev);
543
fffd0934
JB
544 switch (wdev->iftype) {
545 case NL80211_IFTYPE_AP:
546 case NL80211_IFTYPE_AP_VLAN:
074ac8df 547 case NL80211_IFTYPE_P2P_GO:
fffd0934
JB
548 break;
549 case NL80211_IFTYPE_ADHOC:
550 if (!wdev->current_bss)
551 return -ENOLINK;
552 break;
553 case NL80211_IFTYPE_STATION:
074ac8df 554 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
555 if (wdev->sme_state != CFG80211_SME_CONNECTED)
556 return -ENOLINK;
557 break;
558 default:
559 return -EINVAL;
560 }
561
562 return 0;
563}
564
55682965
JB
565static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
566 struct cfg80211_registered_device *dev)
567{
568 void *hdr;
ee688b00
JB
569 struct nlattr *nl_bands, *nl_band;
570 struct nlattr *nl_freqs, *nl_freq;
571 struct nlattr *nl_rates, *nl_rate;
f59ac048 572 struct nlattr *nl_modes;
8fdc621d 573 struct nlattr *nl_cmds;
ee688b00
JB
574 enum ieee80211_band band;
575 struct ieee80211_channel *chan;
576 struct ieee80211_rate *rate;
577 int i;
f59ac048 578 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
579 const struct ieee80211_txrx_stypes *mgmt_stypes =
580 dev->wiphy.mgmt_stypes;
55682965
JB
581
582 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
583 if (!hdr)
584 return -1;
585
b5850a7a 586 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 587 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 588
f5ea9120
JB
589 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
590 cfg80211_rdev_list_generation);
591
b9a5f8ca
JM
592 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
593 dev->wiphy.retry_short);
594 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
595 dev->wiphy.retry_long);
596 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
597 dev->wiphy.frag_threshold);
598 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
599 dev->wiphy.rts_threshold);
81077e82
LT
600 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
601 dev->wiphy.coverage_class);
2a519311
JB
602 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
603 dev->wiphy.max_scan_ssids);
18a83659
JB
604 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
605 dev->wiphy.max_scan_ie_len);
ee688b00 606
e31b8213
JB
607 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
608 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
609 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
610 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
e31b8213 611
25e47c18
JB
612 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
613 sizeof(u32) * dev->wiphy.n_cipher_suites,
614 dev->wiphy.cipher_suites);
615
67fbb16b
SO
616 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
617 dev->wiphy.max_num_pmkids);
618
c0692b8f
JB
619 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
620 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
621
39fd5de4
BR
622 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
623 dev->wiphy.available_antennas_tx);
624 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
625 dev->wiphy.available_antennas_rx);
626
7f531e03
BR
627 if ((dev->wiphy.available_antennas_tx ||
628 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
629 u32 tx_ant = 0, rx_ant = 0;
630 int res;
631 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
632 if (!res) {
633 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
634 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
635 }
636 }
637
f59ac048
LR
638 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
639 if (!nl_modes)
640 goto nla_put_failure;
641
642 i = 0;
643 while (ifmodes) {
644 if (ifmodes & 1)
645 NLA_PUT_FLAG(msg, i);
646 ifmodes >>= 1;
647 i++;
648 }
649
650 nla_nest_end(msg, nl_modes);
651
ee688b00
JB
652 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
653 if (!nl_bands)
654 goto nla_put_failure;
655
656 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
657 if (!dev->wiphy.bands[band])
658 continue;
659
660 nl_band = nla_nest_start(msg, band);
661 if (!nl_band)
662 goto nla_put_failure;
663
d51626df
JB
664 /* add HT info */
665 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
666 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
667 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
668 &dev->wiphy.bands[band]->ht_cap.mcs);
669 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
670 dev->wiphy.bands[band]->ht_cap.cap);
671 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
672 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
673 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
674 dev->wiphy.bands[band]->ht_cap.ampdu_density);
675 }
676
ee688b00
JB
677 /* add frequencies */
678 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
679 if (!nl_freqs)
680 goto nla_put_failure;
681
682 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
683 nl_freq = nla_nest_start(msg, i);
684 if (!nl_freq)
685 goto nla_put_failure;
686
687 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
688
689 if (nl80211_msg_put_channel(msg, chan))
690 goto nla_put_failure;
e2f367f2 691
ee688b00
JB
692 nla_nest_end(msg, nl_freq);
693 }
694
695 nla_nest_end(msg, nl_freqs);
696
697 /* add bitrates */
698 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
699 if (!nl_rates)
700 goto nla_put_failure;
701
702 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
703 nl_rate = nla_nest_start(msg, i);
704 if (!nl_rate)
705 goto nla_put_failure;
706
707 rate = &dev->wiphy.bands[band]->bitrates[i];
708 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
709 rate->bitrate);
710 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
711 NLA_PUT_FLAG(msg,
712 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
713
714 nla_nest_end(msg, nl_rate);
715 }
716
717 nla_nest_end(msg, nl_rates);
718
719 nla_nest_end(msg, nl_band);
720 }
721 nla_nest_end(msg, nl_bands);
722
8fdc621d
JB
723 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
724 if (!nl_cmds)
725 goto nla_put_failure;
726
727 i = 0;
728#define CMD(op, n) \
729 do { \
730 if (dev->ops->op) { \
731 i++; \
732 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
733 } \
734 } while (0)
735
736 CMD(add_virtual_intf, NEW_INTERFACE);
737 CMD(change_virtual_intf, SET_INTERFACE);
738 CMD(add_key, NEW_KEY);
739 CMD(add_beacon, NEW_BEACON);
740 CMD(add_station, NEW_STATION);
741 CMD(add_mpath, NEW_MPATH);
24bdd9f4 742 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 743 CMD(change_bss, SET_BSS);
636a5d36
JM
744 CMD(auth, AUTHENTICATE);
745 CMD(assoc, ASSOCIATE);
746 CMD(deauth, DEAUTHENTICATE);
747 CMD(disassoc, DISASSOCIATE);
04a773ad 748 CMD(join_ibss, JOIN_IBSS);
29cbe68c 749 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
750 CMD(set_pmksa, SET_PMKSA);
751 CMD(del_pmksa, DEL_PMKSA);
752 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 753 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 754 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 755 CMD(mgmt_tx, FRAME);
f7ca38df 756 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 757 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
758 i++;
759 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
760 }
f444de05 761 CMD(set_channel, SET_CHANNEL);
e8347eba 762 CMD(set_wds_peer, SET_WDS_PEER);
8fdc621d
JB
763
764#undef CMD
b23aa676 765
6829c878 766 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
767 i++;
768 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
769 }
770
6829c878 771 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
772 i++;
773 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
774 }
775
8fdc621d
JB
776 nla_nest_end(msg, nl_cmds);
777
a293911d
JB
778 if (dev->ops->remain_on_channel)
779 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
780 dev->wiphy.max_remain_on_channel_duration);
781
f7ca38df
JB
782 /* for now at least assume all drivers have it */
783 if (dev->ops->mgmt_tx)
784 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
785
2e161f78
JB
786 if (mgmt_stypes) {
787 u16 stypes;
788 struct nlattr *nl_ftypes, *nl_ifs;
789 enum nl80211_iftype ift;
790
791 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
792 if (!nl_ifs)
793 goto nla_put_failure;
794
795 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
796 nl_ftypes = nla_nest_start(msg, ift);
797 if (!nl_ftypes)
798 goto nla_put_failure;
799 i = 0;
800 stypes = mgmt_stypes[ift].tx;
801 while (stypes) {
802 if (stypes & 1)
803 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
804 (i << 4) | IEEE80211_FTYPE_MGMT);
805 stypes >>= 1;
806 i++;
807 }
808 nla_nest_end(msg, nl_ftypes);
809 }
810
74b70a4e
JB
811 nla_nest_end(msg, nl_ifs);
812
2e161f78
JB
813 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
814 if (!nl_ifs)
815 goto nla_put_failure;
816
817 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
818 nl_ftypes = nla_nest_start(msg, ift);
819 if (!nl_ftypes)
820 goto nla_put_failure;
821 i = 0;
822 stypes = mgmt_stypes[ift].rx;
823 while (stypes) {
824 if (stypes & 1)
825 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
826 (i << 4) | IEEE80211_FTYPE_MGMT);
827 stypes >>= 1;
828 i++;
829 }
830 nla_nest_end(msg, nl_ftypes);
831 }
832 nla_nest_end(msg, nl_ifs);
833 }
834
ff1b6e69
JB
835 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
836 struct nlattr *nl_wowlan;
837
838 nl_wowlan = nla_nest_start(msg,
839 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
840 if (!nl_wowlan)
841 goto nla_put_failure;
842
843 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
844 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
845 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
846 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
847 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
848 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
849 if (dev->wiphy.wowlan.n_patterns) {
850 struct nl80211_wowlan_pattern_support pat = {
851 .max_patterns = dev->wiphy.wowlan.n_patterns,
852 .min_pattern_len =
853 dev->wiphy.wowlan.pattern_min_len,
854 .max_pattern_len =
855 dev->wiphy.wowlan.pattern_max_len,
856 };
857 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
858 sizeof(pat), &pat);
859 }
860
861 nla_nest_end(msg, nl_wowlan);
862 }
863
55682965
JB
864 return genlmsg_end(msg, hdr);
865
866 nla_put_failure:
bc3ed28c
TG
867 genlmsg_cancel(msg, hdr);
868 return -EMSGSIZE;
55682965
JB
869}
870
871static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
872{
873 int idx = 0;
874 int start = cb->args[0];
875 struct cfg80211_registered_device *dev;
876
a1794390 877 mutex_lock(&cfg80211_mutex);
79c97e97 878 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
879 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
880 continue;
b4637271 881 if (++idx <= start)
55682965
JB
882 continue;
883 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
884 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
885 dev) < 0) {
886 idx--;
55682965 887 break;
b4637271 888 }
55682965 889 }
a1794390 890 mutex_unlock(&cfg80211_mutex);
55682965
JB
891
892 cb->args[0] = idx;
893
894 return skb->len;
895}
896
897static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
898{
899 struct sk_buff *msg;
4c476991 900 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 901
fd2120ca 902 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 903 if (!msg)
4c476991 904 return -ENOMEM;
55682965 905
4c476991
JB
906 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
907 nlmsg_free(msg);
908 return -ENOBUFS;
909 }
55682965 910
134e6375 911 return genlmsg_reply(msg, info);
55682965
JB
912}
913
31888487
JM
914static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
915 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
916 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
917 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
918 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
919 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
920};
921
922static int parse_txq_params(struct nlattr *tb[],
923 struct ieee80211_txq_params *txq_params)
924{
925 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
926 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
927 !tb[NL80211_TXQ_ATTR_AIFS])
928 return -EINVAL;
929
930 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
931 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
932 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
933 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
934 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
935
936 return 0;
937}
938
f444de05
JB
939static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
940{
941 /*
942 * You can only set the channel explicitly for AP, mesh
943 * and WDS type interfaces; all others have their channel
944 * managed via their respective "establish a connection"
945 * command (connect, join, ...)
946 *
947 * Monitors are special as they are normally slaved to
948 * whatever else is going on, so they behave as though
949 * you tried setting the wiphy channel itself.
950 */
951 return !wdev ||
952 wdev->iftype == NL80211_IFTYPE_AP ||
953 wdev->iftype == NL80211_IFTYPE_WDS ||
954 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
955 wdev->iftype == NL80211_IFTYPE_MONITOR ||
956 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
957}
958
959static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
960 struct wireless_dev *wdev,
961 struct genl_info *info)
962{
963 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
964 u32 freq;
965 int result;
966
967 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
968 return -EINVAL;
969
970 if (!nl80211_can_set_dev_channel(wdev))
971 return -EOPNOTSUPP;
972
973 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
974 channel_type = nla_get_u32(info->attrs[
975 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
976 if (channel_type != NL80211_CHAN_NO_HT &&
977 channel_type != NL80211_CHAN_HT20 &&
978 channel_type != NL80211_CHAN_HT40PLUS &&
979 channel_type != NL80211_CHAN_HT40MINUS)
980 return -EINVAL;
981 }
982
983 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
984
985 mutex_lock(&rdev->devlist_mtx);
986 if (wdev) {
987 wdev_lock(wdev);
988 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
989 wdev_unlock(wdev);
990 } else {
991 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
992 }
993 mutex_unlock(&rdev->devlist_mtx);
994
995 return result;
996}
997
998static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
999{
4c476991
JB
1000 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1001 struct net_device *netdev = info->user_ptr[1];
f444de05 1002
4c476991 1003 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1004}
1005
e8347eba
BJ
1006static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1007{
43b19952
JB
1008 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1009 struct net_device *dev = info->user_ptr[1];
1010 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1011 const u8 *bssid;
e8347eba
BJ
1012
1013 if (!info->attrs[NL80211_ATTR_MAC])
1014 return -EINVAL;
1015
43b19952
JB
1016 if (netif_running(dev))
1017 return -EBUSY;
e8347eba 1018
43b19952
JB
1019 if (!rdev->ops->set_wds_peer)
1020 return -EOPNOTSUPP;
e8347eba 1021
43b19952
JB
1022 if (wdev->iftype != NL80211_IFTYPE_WDS)
1023 return -EOPNOTSUPP;
e8347eba
BJ
1024
1025 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1026 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1027}
1028
1029
55682965
JB
1030static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1031{
1032 struct cfg80211_registered_device *rdev;
f444de05
JB
1033 struct net_device *netdev = NULL;
1034 struct wireless_dev *wdev;
a1e567c8 1035 int result = 0, rem_txq_params = 0;
31888487 1036 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1037 u32 changed;
1038 u8 retry_short = 0, retry_long = 0;
1039 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1040 u8 coverage_class = 0;
55682965 1041
f444de05
JB
1042 /*
1043 * Try to find the wiphy and netdev. Normally this
1044 * function shouldn't need the netdev, but this is
1045 * done for backward compatibility -- previously
1046 * setting the channel was done per wiphy, but now
1047 * it is per netdev. Previous userland like hostapd
1048 * also passed a netdev to set_wiphy, so that it is
1049 * possible to let that go to the right netdev!
1050 */
4bbf4d56
JB
1051 mutex_lock(&cfg80211_mutex);
1052
f444de05
JB
1053 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1054 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1055
1056 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1057 if (netdev && netdev->ieee80211_ptr) {
1058 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1059 mutex_lock(&rdev->mtx);
1060 } else
1061 netdev = NULL;
4bbf4d56
JB
1062 }
1063
f444de05
JB
1064 if (!netdev) {
1065 rdev = __cfg80211_rdev_from_info(info);
1066 if (IS_ERR(rdev)) {
1067 mutex_unlock(&cfg80211_mutex);
4c476991 1068 return PTR_ERR(rdev);
f444de05
JB
1069 }
1070 wdev = NULL;
1071 netdev = NULL;
1072 result = 0;
1073
1074 mutex_lock(&rdev->mtx);
1075 } else if (netif_running(netdev) &&
1076 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1077 wdev = netdev->ieee80211_ptr;
1078 else
1079 wdev = NULL;
1080
1081 /*
1082 * end workaround code, by now the rdev is available
1083 * and locked, and wdev may or may not be NULL.
1084 */
4bbf4d56
JB
1085
1086 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1087 result = cfg80211_dev_rename(
1088 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1089
1090 mutex_unlock(&cfg80211_mutex);
1091
1092 if (result)
1093 goto bad_res;
31888487
JM
1094
1095 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1096 struct ieee80211_txq_params txq_params;
1097 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1098
1099 if (!rdev->ops->set_txq_params) {
1100 result = -EOPNOTSUPP;
1101 goto bad_res;
1102 }
1103
1104 nla_for_each_nested(nl_txq_params,
1105 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1106 rem_txq_params) {
1107 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1108 nla_data(nl_txq_params),
1109 nla_len(nl_txq_params),
1110 txq_params_policy);
1111 result = parse_txq_params(tb, &txq_params);
1112 if (result)
1113 goto bad_res;
1114
1115 result = rdev->ops->set_txq_params(&rdev->wiphy,
1116 &txq_params);
1117 if (result)
1118 goto bad_res;
1119 }
1120 }
55682965 1121
72bdcf34 1122 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1123 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1124 if (result)
1125 goto bad_res;
1126 }
1127
98d2ff8b
JO
1128 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1129 enum nl80211_tx_power_setting type;
1130 int idx, mbm = 0;
1131
1132 if (!rdev->ops->set_tx_power) {
60ea385f 1133 result = -EOPNOTSUPP;
98d2ff8b
JO
1134 goto bad_res;
1135 }
1136
1137 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1138 type = nla_get_u32(info->attrs[idx]);
1139
1140 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1141 (type != NL80211_TX_POWER_AUTOMATIC)) {
1142 result = -EINVAL;
1143 goto bad_res;
1144 }
1145
1146 if (type != NL80211_TX_POWER_AUTOMATIC) {
1147 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1148 mbm = nla_get_u32(info->attrs[idx]);
1149 }
1150
1151 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1152 if (result)
1153 goto bad_res;
1154 }
1155
afe0cbf8
BR
1156 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1157 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1158 u32 tx_ant, rx_ant;
7f531e03
BR
1159 if ((!rdev->wiphy.available_antennas_tx &&
1160 !rdev->wiphy.available_antennas_rx) ||
1161 !rdev->ops->set_antenna) {
afe0cbf8
BR
1162 result = -EOPNOTSUPP;
1163 goto bad_res;
1164 }
1165
1166 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1167 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1168
a7ffac95 1169 /* reject antenna configurations which don't match the
7f531e03
BR
1170 * available antenna masks, except for the "all" mask */
1171 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1172 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1173 result = -EINVAL;
1174 goto bad_res;
1175 }
1176
7f531e03
BR
1177 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1178 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1179
afe0cbf8
BR
1180 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1181 if (result)
1182 goto bad_res;
1183 }
1184
b9a5f8ca
JM
1185 changed = 0;
1186
1187 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1188 retry_short = nla_get_u8(
1189 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1190 if (retry_short == 0) {
1191 result = -EINVAL;
1192 goto bad_res;
1193 }
1194 changed |= WIPHY_PARAM_RETRY_SHORT;
1195 }
1196
1197 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1198 retry_long = nla_get_u8(
1199 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1200 if (retry_long == 0) {
1201 result = -EINVAL;
1202 goto bad_res;
1203 }
1204 changed |= WIPHY_PARAM_RETRY_LONG;
1205 }
1206
1207 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1208 frag_threshold = nla_get_u32(
1209 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1210 if (frag_threshold < 256) {
1211 result = -EINVAL;
1212 goto bad_res;
1213 }
1214 if (frag_threshold != (u32) -1) {
1215 /*
1216 * Fragments (apart from the last one) are required to
1217 * have even length. Make the fragmentation code
1218 * simpler by stripping LSB should someone try to use
1219 * odd threshold value.
1220 */
1221 frag_threshold &= ~0x1;
1222 }
1223 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1224 }
1225
1226 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1227 rts_threshold = nla_get_u32(
1228 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1229 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1230 }
1231
81077e82
LT
1232 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1233 coverage_class = nla_get_u8(
1234 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1235 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1236 }
1237
b9a5f8ca
JM
1238 if (changed) {
1239 u8 old_retry_short, old_retry_long;
1240 u32 old_frag_threshold, old_rts_threshold;
81077e82 1241 u8 old_coverage_class;
b9a5f8ca
JM
1242
1243 if (!rdev->ops->set_wiphy_params) {
1244 result = -EOPNOTSUPP;
1245 goto bad_res;
1246 }
1247
1248 old_retry_short = rdev->wiphy.retry_short;
1249 old_retry_long = rdev->wiphy.retry_long;
1250 old_frag_threshold = rdev->wiphy.frag_threshold;
1251 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1252 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1253
1254 if (changed & WIPHY_PARAM_RETRY_SHORT)
1255 rdev->wiphy.retry_short = retry_short;
1256 if (changed & WIPHY_PARAM_RETRY_LONG)
1257 rdev->wiphy.retry_long = retry_long;
1258 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1259 rdev->wiphy.frag_threshold = frag_threshold;
1260 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1261 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1262 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1263 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1264
1265 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1266 if (result) {
1267 rdev->wiphy.retry_short = old_retry_short;
1268 rdev->wiphy.retry_long = old_retry_long;
1269 rdev->wiphy.frag_threshold = old_frag_threshold;
1270 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1271 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1272 }
1273 }
72bdcf34 1274
306d6112 1275 bad_res:
4bbf4d56 1276 mutex_unlock(&rdev->mtx);
f444de05
JB
1277 if (netdev)
1278 dev_put(netdev);
55682965
JB
1279 return result;
1280}
1281
1282
1283static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1284 struct cfg80211_registered_device *rdev,
55682965
JB
1285 struct net_device *dev)
1286{
1287 void *hdr;
1288
1289 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1290 if (!hdr)
1291 return -1;
1292
1293 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1294 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1295 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1296 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1297
1298 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1299 rdev->devlist_generation ^
1300 (cfg80211_rdev_list_generation << 2));
1301
55682965
JB
1302 return genlmsg_end(msg, hdr);
1303
1304 nla_put_failure:
bc3ed28c
TG
1305 genlmsg_cancel(msg, hdr);
1306 return -EMSGSIZE;
55682965
JB
1307}
1308
1309static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1310{
1311 int wp_idx = 0;
1312 int if_idx = 0;
1313 int wp_start = cb->args[0];
1314 int if_start = cb->args[1];
f5ea9120 1315 struct cfg80211_registered_device *rdev;
55682965
JB
1316 struct wireless_dev *wdev;
1317
a1794390 1318 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1319 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1320 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1321 continue;
bba95fef
JB
1322 if (wp_idx < wp_start) {
1323 wp_idx++;
55682965 1324 continue;
bba95fef 1325 }
55682965
JB
1326 if_idx = 0;
1327
f5ea9120
JB
1328 mutex_lock(&rdev->devlist_mtx);
1329 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1330 if (if_idx < if_start) {
1331 if_idx++;
55682965 1332 continue;
bba95fef 1333 }
55682965
JB
1334 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1335 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1336 rdev, wdev->netdev) < 0) {
1337 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1338 goto out;
1339 }
1340 if_idx++;
55682965 1341 }
f5ea9120 1342 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1343
1344 wp_idx++;
55682965 1345 }
bba95fef 1346 out:
a1794390 1347 mutex_unlock(&cfg80211_mutex);
55682965
JB
1348
1349 cb->args[0] = wp_idx;
1350 cb->args[1] = if_idx;
1351
1352 return skb->len;
1353}
1354
1355static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1356{
1357 struct sk_buff *msg;
4c476991
JB
1358 struct cfg80211_registered_device *dev = info->user_ptr[0];
1359 struct net_device *netdev = info->user_ptr[1];
55682965 1360
fd2120ca 1361 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1362 if (!msg)
4c476991 1363 return -ENOMEM;
55682965 1364
d726405a 1365 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1366 dev, netdev) < 0) {
1367 nlmsg_free(msg);
1368 return -ENOBUFS;
1369 }
55682965 1370
134e6375 1371 return genlmsg_reply(msg, info);
55682965
JB
1372}
1373
66f7ac50
MW
1374static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1375 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1376 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1377 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1378 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1379 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1380};
1381
1382static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1383{
1384 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1385 int flag;
1386
1387 *mntrflags = 0;
1388
1389 if (!nla)
1390 return -EINVAL;
1391
1392 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1393 nla, mntr_flags_policy))
1394 return -EINVAL;
1395
1396 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1397 if (flags[flag])
1398 *mntrflags |= (1<<flag);
1399
1400 return 0;
1401}
1402
9bc383de 1403static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1404 struct net_device *netdev, u8 use_4addr,
1405 enum nl80211_iftype iftype)
9bc383de 1406{
ad4bb6f8 1407 if (!use_4addr) {
f350a0a8 1408 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1409 return -EBUSY;
9bc383de 1410 return 0;
ad4bb6f8 1411 }
9bc383de
JB
1412
1413 switch (iftype) {
1414 case NL80211_IFTYPE_AP_VLAN:
1415 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1416 return 0;
1417 break;
1418 case NL80211_IFTYPE_STATION:
1419 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1420 return 0;
1421 break;
1422 default:
1423 break;
1424 }
1425
1426 return -EOPNOTSUPP;
1427}
1428
55682965
JB
1429static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1430{
4c476991 1431 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1432 struct vif_params params;
e36d56b6 1433 int err;
04a773ad 1434 enum nl80211_iftype otype, ntype;
4c476991 1435 struct net_device *dev = info->user_ptr[1];
92ffe055 1436 u32 _flags, *flags = NULL;
ac7f9cfa 1437 bool change = false;
55682965 1438
2ec600d6
LCC
1439 memset(&params, 0, sizeof(params));
1440
04a773ad 1441 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1442
723b038d 1443 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1444 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1445 if (otype != ntype)
ac7f9cfa 1446 change = true;
4c476991
JB
1447 if (ntype > NL80211_IFTYPE_MAX)
1448 return -EINVAL;
723b038d
JB
1449 }
1450
92ffe055 1451 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1452 struct wireless_dev *wdev = dev->ieee80211_ptr;
1453
4c476991
JB
1454 if (ntype != NL80211_IFTYPE_MESH_POINT)
1455 return -EINVAL;
29cbe68c
JB
1456 if (netif_running(dev))
1457 return -EBUSY;
1458
1459 wdev_lock(wdev);
1460 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1461 IEEE80211_MAX_MESH_ID_LEN);
1462 wdev->mesh_id_up_len =
1463 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1464 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1465 wdev->mesh_id_up_len);
1466 wdev_unlock(wdev);
2ec600d6
LCC
1467 }
1468
8b787643
FF
1469 if (info->attrs[NL80211_ATTR_4ADDR]) {
1470 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1471 change = true;
ad4bb6f8 1472 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1473 if (err)
4c476991 1474 return err;
8b787643
FF
1475 } else {
1476 params.use_4addr = -1;
1477 }
1478
92ffe055 1479 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1480 if (ntype != NL80211_IFTYPE_MONITOR)
1481 return -EINVAL;
92ffe055
JB
1482 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1483 &_flags);
ac7f9cfa 1484 if (err)
4c476991 1485 return err;
ac7f9cfa
JB
1486
1487 flags = &_flags;
1488 change = true;
92ffe055 1489 }
3b85875a 1490
ac7f9cfa 1491 if (change)
3d54d255 1492 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1493 else
1494 err = 0;
60719ffd 1495
9bc383de
JB
1496 if (!err && params.use_4addr != -1)
1497 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1498
55682965
JB
1499 return err;
1500}
1501
1502static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1503{
4c476991 1504 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1505 struct vif_params params;
f9e10ce4 1506 struct net_device *dev;
55682965
JB
1507 int err;
1508 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1509 u32 flags;
55682965 1510
2ec600d6
LCC
1511 memset(&params, 0, sizeof(params));
1512
55682965
JB
1513 if (!info->attrs[NL80211_ATTR_IFNAME])
1514 return -EINVAL;
1515
1516 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1517 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1518 if (type > NL80211_IFTYPE_MAX)
1519 return -EINVAL;
1520 }
1521
79c97e97 1522 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1523 !(rdev->wiphy.interface_modes & (1 << type)))
1524 return -EOPNOTSUPP;
55682965 1525
9bc383de 1526 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1527 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1528 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1529 if (err)
4c476991 1530 return err;
9bc383de 1531 }
8b787643 1532
66f7ac50
MW
1533 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1534 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1535 &flags);
f9e10ce4 1536 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1537 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1538 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1539 if (IS_ERR(dev))
1540 return PTR_ERR(dev);
2ec600d6 1541
29cbe68c
JB
1542 if (type == NL80211_IFTYPE_MESH_POINT &&
1543 info->attrs[NL80211_ATTR_MESH_ID]) {
1544 struct wireless_dev *wdev = dev->ieee80211_ptr;
1545
1546 wdev_lock(wdev);
1547 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1548 IEEE80211_MAX_MESH_ID_LEN);
1549 wdev->mesh_id_up_len =
1550 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1551 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1552 wdev->mesh_id_up_len);
1553 wdev_unlock(wdev);
1554 }
1555
f9e10ce4 1556 return 0;
55682965
JB
1557}
1558
1559static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1560{
4c476991
JB
1561 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1562 struct net_device *dev = info->user_ptr[1];
55682965 1563
4c476991
JB
1564 if (!rdev->ops->del_virtual_intf)
1565 return -EOPNOTSUPP;
55682965 1566
4c476991 1567 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1568}
1569
41ade00f
JB
1570struct get_key_cookie {
1571 struct sk_buff *msg;
1572 int error;
b9454e83 1573 int idx;
41ade00f
JB
1574};
1575
1576static void get_key_callback(void *c, struct key_params *params)
1577{
b9454e83 1578 struct nlattr *key;
41ade00f
JB
1579 struct get_key_cookie *cookie = c;
1580
1581 if (params->key)
1582 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1583 params->key_len, params->key);
1584
1585 if (params->seq)
1586 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1587 params->seq_len, params->seq);
1588
1589 if (params->cipher)
1590 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1591 params->cipher);
1592
b9454e83
JB
1593 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1594 if (!key)
1595 goto nla_put_failure;
1596
1597 if (params->key)
1598 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1599 params->key_len, params->key);
1600
1601 if (params->seq)
1602 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1603 params->seq_len, params->seq);
1604
1605 if (params->cipher)
1606 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1607 params->cipher);
1608
1609 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1610
1611 nla_nest_end(cookie->msg, key);
1612
41ade00f
JB
1613 return;
1614 nla_put_failure:
1615 cookie->error = 1;
1616}
1617
1618static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1619{
4c476991 1620 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1621 int err;
4c476991 1622 struct net_device *dev = info->user_ptr[1];
41ade00f 1623 u8 key_idx = 0;
e31b8213
JB
1624 const u8 *mac_addr = NULL;
1625 bool pairwise;
41ade00f
JB
1626 struct get_key_cookie cookie = {
1627 .error = 0,
1628 };
1629 void *hdr;
1630 struct sk_buff *msg;
1631
1632 if (info->attrs[NL80211_ATTR_KEY_IDX])
1633 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1634
3cfcf6ac 1635 if (key_idx > 5)
41ade00f
JB
1636 return -EINVAL;
1637
1638 if (info->attrs[NL80211_ATTR_MAC])
1639 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1640
e31b8213
JB
1641 pairwise = !!mac_addr;
1642 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1643 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1644 if (kt >= NUM_NL80211_KEYTYPES)
1645 return -EINVAL;
1646 if (kt != NL80211_KEYTYPE_GROUP &&
1647 kt != NL80211_KEYTYPE_PAIRWISE)
1648 return -EINVAL;
1649 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1650 }
1651
4c476991
JB
1652 if (!rdev->ops->get_key)
1653 return -EOPNOTSUPP;
41ade00f 1654
fd2120ca 1655 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1656 if (!msg)
1657 return -ENOMEM;
41ade00f
JB
1658
1659 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1660 NL80211_CMD_NEW_KEY);
4c476991
JB
1661 if (IS_ERR(hdr))
1662 return PTR_ERR(hdr);
41ade00f
JB
1663
1664 cookie.msg = msg;
b9454e83 1665 cookie.idx = key_idx;
41ade00f
JB
1666
1667 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1668 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1669 if (mac_addr)
1670 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1671
e31b8213
JB
1672 if (pairwise && mac_addr &&
1673 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1674 return -ENOENT;
1675
1676 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1677 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1678
1679 if (err)
6c95e2a2 1680 goto free_msg;
41ade00f
JB
1681
1682 if (cookie.error)
1683 goto nla_put_failure;
1684
1685 genlmsg_end(msg, hdr);
4c476991 1686 return genlmsg_reply(msg, info);
41ade00f
JB
1687
1688 nla_put_failure:
1689 err = -ENOBUFS;
6c95e2a2 1690 free_msg:
41ade00f 1691 nlmsg_free(msg);
41ade00f
JB
1692 return err;
1693}
1694
1695static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1696{
4c476991 1697 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1698 struct key_parse key;
41ade00f 1699 int err;
4c476991 1700 struct net_device *dev = info->user_ptr[1];
41ade00f 1701
b9454e83
JB
1702 err = nl80211_parse_key(info, &key);
1703 if (err)
1704 return err;
41ade00f 1705
b9454e83 1706 if (key.idx < 0)
41ade00f
JB
1707 return -EINVAL;
1708
b9454e83
JB
1709 /* only support setting default key */
1710 if (!key.def && !key.defmgmt)
41ade00f
JB
1711 return -EINVAL;
1712
dbd2fd65 1713 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1714
dbd2fd65
JB
1715 if (key.def) {
1716 if (!rdev->ops->set_default_key) {
1717 err = -EOPNOTSUPP;
1718 goto out;
1719 }
41ade00f 1720
dbd2fd65
JB
1721 err = nl80211_key_allowed(dev->ieee80211_ptr);
1722 if (err)
1723 goto out;
1724
dbd2fd65
JB
1725 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1726 key.def_uni, key.def_multi);
1727
1728 if (err)
1729 goto out;
fffd0934 1730
3d23e349 1731#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1732 dev->ieee80211_ptr->wext.default_key = key.idx;
1733#endif
1734 } else {
1735 if (key.def_uni || !key.def_multi) {
1736 err = -EINVAL;
1737 goto out;
1738 }
1739
1740 if (!rdev->ops->set_default_mgmt_key) {
1741 err = -EOPNOTSUPP;
1742 goto out;
1743 }
1744
1745 err = nl80211_key_allowed(dev->ieee80211_ptr);
1746 if (err)
1747 goto out;
1748
1749 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1750 dev, key.idx);
1751 if (err)
1752 goto out;
1753
1754#ifdef CONFIG_CFG80211_WEXT
1755 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1756#endif
dbd2fd65
JB
1757 }
1758
1759 out:
fffd0934 1760 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1761
41ade00f
JB
1762 return err;
1763}
1764
1765static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1766{
4c476991 1767 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1768 int err;
4c476991 1769 struct net_device *dev = info->user_ptr[1];
b9454e83 1770 struct key_parse key;
e31b8213 1771 const u8 *mac_addr = NULL;
41ade00f 1772
b9454e83
JB
1773 err = nl80211_parse_key(info, &key);
1774 if (err)
1775 return err;
41ade00f 1776
b9454e83 1777 if (!key.p.key)
41ade00f
JB
1778 return -EINVAL;
1779
41ade00f
JB
1780 if (info->attrs[NL80211_ATTR_MAC])
1781 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1782
e31b8213
JB
1783 if (key.type == -1) {
1784 if (mac_addr)
1785 key.type = NL80211_KEYTYPE_PAIRWISE;
1786 else
1787 key.type = NL80211_KEYTYPE_GROUP;
1788 }
1789
1790 /* for now */
1791 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1792 key.type != NL80211_KEYTYPE_GROUP)
1793 return -EINVAL;
1794
4c476991
JB
1795 if (!rdev->ops->add_key)
1796 return -EOPNOTSUPP;
25e47c18 1797
e31b8213
JB
1798 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1799 key.type == NL80211_KEYTYPE_PAIRWISE,
1800 mac_addr))
4c476991 1801 return -EINVAL;
41ade00f 1802
fffd0934
JB
1803 wdev_lock(dev->ieee80211_ptr);
1804 err = nl80211_key_allowed(dev->ieee80211_ptr);
1805 if (!err)
1806 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1807 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1808 mac_addr, &key.p);
1809 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1810
41ade00f
JB
1811 return err;
1812}
1813
1814static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1815{
4c476991 1816 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1817 int err;
4c476991 1818 struct net_device *dev = info->user_ptr[1];
41ade00f 1819 u8 *mac_addr = NULL;
b9454e83 1820 struct key_parse key;
41ade00f 1821
b9454e83
JB
1822 err = nl80211_parse_key(info, &key);
1823 if (err)
1824 return err;
41ade00f
JB
1825
1826 if (info->attrs[NL80211_ATTR_MAC])
1827 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1828
e31b8213
JB
1829 if (key.type == -1) {
1830 if (mac_addr)
1831 key.type = NL80211_KEYTYPE_PAIRWISE;
1832 else
1833 key.type = NL80211_KEYTYPE_GROUP;
1834 }
1835
1836 /* for now */
1837 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1838 key.type != NL80211_KEYTYPE_GROUP)
1839 return -EINVAL;
1840
4c476991
JB
1841 if (!rdev->ops->del_key)
1842 return -EOPNOTSUPP;
41ade00f 1843
fffd0934
JB
1844 wdev_lock(dev->ieee80211_ptr);
1845 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
1846
1847 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1848 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1849 err = -ENOENT;
1850
fffd0934 1851 if (!err)
e31b8213
JB
1852 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1853 key.type == NL80211_KEYTYPE_PAIRWISE,
1854 mac_addr);
41ade00f 1855
3d23e349 1856#ifdef CONFIG_CFG80211_WEXT
08645126 1857 if (!err) {
b9454e83 1858 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1859 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1860 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1861 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1862 }
1863#endif
fffd0934 1864 wdev_unlock(dev->ieee80211_ptr);
08645126 1865
41ade00f
JB
1866 return err;
1867}
1868
ed1b6cc7
JB
1869static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1870{
1871 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1872 struct beacon_parameters *info);
4c476991
JB
1873 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1874 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1875 struct beacon_parameters params;
1876 int haveinfo = 0;
1877
f4a11bb0
JB
1878 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1879 return -EINVAL;
1880
074ac8df 1881 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1882 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1883 return -EOPNOTSUPP;
eec60b03 1884
ed1b6cc7
JB
1885 switch (info->genlhdr->cmd) {
1886 case NL80211_CMD_NEW_BEACON:
1887 /* these are required for NEW_BEACON */
1888 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1889 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1890 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1891 return -EINVAL;
ed1b6cc7 1892
79c97e97 1893 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1894 break;
1895 case NL80211_CMD_SET_BEACON:
79c97e97 1896 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1897 break;
1898 default:
1899 WARN_ON(1);
4c476991 1900 return -EOPNOTSUPP;
ed1b6cc7
JB
1901 }
1902
4c476991
JB
1903 if (!call)
1904 return -EOPNOTSUPP;
ed1b6cc7
JB
1905
1906 memset(&params, 0, sizeof(params));
1907
1908 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1909 params.interval =
1910 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1911 haveinfo = 1;
1912 }
1913
1914 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1915 params.dtim_period =
1916 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1917 haveinfo = 1;
1918 }
1919
1920 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1921 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1922 params.head_len =
1923 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1924 haveinfo = 1;
1925 }
1926
1927 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1928 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1929 params.tail_len =
1930 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1931 haveinfo = 1;
1932 }
1933
4c476991
JB
1934 if (!haveinfo)
1935 return -EINVAL;
3b85875a 1936
4c476991 1937 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1938}
1939
1940static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1941{
4c476991
JB
1942 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1943 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1944
4c476991
JB
1945 if (!rdev->ops->del_beacon)
1946 return -EOPNOTSUPP;
ed1b6cc7 1947
074ac8df 1948 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1949 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1950 return -EOPNOTSUPP;
3b85875a 1951
4c476991 1952 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1953}
1954
5727ef1b
JB
1955static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1956 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1957 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1958 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1959 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 1960 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
5727ef1b
JB
1961};
1962
eccb8e8f
JB
1963static int parse_station_flags(struct genl_info *info,
1964 struct station_parameters *params)
5727ef1b
JB
1965{
1966 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1967 struct nlattr *nla;
5727ef1b
JB
1968 int flag;
1969
eccb8e8f
JB
1970 /*
1971 * Try parsing the new attribute first so userspace
1972 * can specify both for older kernels.
1973 */
1974 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1975 if (nla) {
1976 struct nl80211_sta_flag_update *sta_flags;
1977
1978 sta_flags = nla_data(nla);
1979 params->sta_flags_mask = sta_flags->mask;
1980 params->sta_flags_set = sta_flags->set;
1981 if ((params->sta_flags_mask |
1982 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1983 return -EINVAL;
1984 return 0;
1985 }
1986
1987 /* if present, parse the old attribute */
5727ef1b 1988
eccb8e8f 1989 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1990 if (!nla)
1991 return 0;
1992
1993 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1994 nla, sta_flags_policy))
1995 return -EINVAL;
1996
eccb8e8f
JB
1997 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1998 params->sta_flags_mask &= ~1;
5727ef1b
JB
1999
2000 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2001 if (flags[flag])
eccb8e8f 2002 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2003
2004 return 0;
2005}
2006
c8dcfd8a
FF
2007static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2008 int attr)
2009{
2010 struct nlattr *rate;
2011 u16 bitrate;
2012
2013 rate = nla_nest_start(msg, attr);
2014 if (!rate)
2015 goto nla_put_failure;
2016
2017 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2018 bitrate = cfg80211_calculate_bitrate(info);
2019 if (bitrate > 0)
2020 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2021
2022 if (info->flags & RATE_INFO_FLAGS_MCS)
2023 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2024 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2025 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2026 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2027 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2028
2029 nla_nest_end(msg, rate);
2030 return true;
2031
2032nla_put_failure:
2033 return false;
2034}
2035
fd5b74dc
JB
2036static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2037 int flags, struct net_device *dev,
98b62183 2038 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2039{
2040 void *hdr;
f4263c98 2041 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2042
2043 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2044 if (!hdr)
2045 return -1;
2046
2047 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2048 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2049
f5ea9120
JB
2050 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2051
2ec600d6
LCC
2052 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2053 if (!sinfoattr)
fd5b74dc 2054 goto nla_put_failure;
ebe27c91
MSS
2055 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2056 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2057 sinfo->connected_time);
2ec600d6
LCC
2058 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2059 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2060 sinfo->inactive_time);
2061 if (sinfo->filled & STATION_INFO_RX_BYTES)
2062 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2063 sinfo->rx_bytes);
2064 if (sinfo->filled & STATION_INFO_TX_BYTES)
2065 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2066 sinfo->tx_bytes);
2067 if (sinfo->filled & STATION_INFO_LLID)
2068 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2069 sinfo->llid);
2070 if (sinfo->filled & STATION_INFO_PLID)
2071 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2072 sinfo->plid);
2073 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2074 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2075 sinfo->plink_state);
420e7fab
HR
2076 if (sinfo->filled & STATION_INFO_SIGNAL)
2077 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2078 sinfo->signal);
541a45a1
BR
2079 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2080 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2081 sinfo->signal_avg);
420e7fab 2082 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2083 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2084 NL80211_STA_INFO_TX_BITRATE))
2085 goto nla_put_failure;
2086 }
2087 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2088 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2089 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2090 goto nla_put_failure;
420e7fab 2091 }
98c8a60a
JM
2092 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2093 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2094 sinfo->rx_packets);
2095 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2096 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2097 sinfo->tx_packets);
b206b4ef
BR
2098 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2099 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2100 sinfo->tx_retries);
2101 if (sinfo->filled & STATION_INFO_TX_FAILED)
2102 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2103 sinfo->tx_failed);
f4263c98
PS
2104 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2105 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2106 if (!bss_param)
2107 goto nla_put_failure;
2108
2109 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2110 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2111 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2112 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2113 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2114 NLA_PUT_FLAG(msg,
2115 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2116 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2117 sinfo->bss_param.dtim_period);
2118 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2119 sinfo->bss_param.beacon_interval);
2120
2121 nla_nest_end(msg, bss_param);
2122 }
2ec600d6 2123 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
2124
2125 return genlmsg_end(msg, hdr);
2126
2127 nla_put_failure:
bc3ed28c
TG
2128 genlmsg_cancel(msg, hdr);
2129 return -EMSGSIZE;
fd5b74dc
JB
2130}
2131
2ec600d6 2132static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2133 struct netlink_callback *cb)
2ec600d6 2134{
2ec600d6
LCC
2135 struct station_info sinfo;
2136 struct cfg80211_registered_device *dev;
bba95fef 2137 struct net_device *netdev;
2ec600d6 2138 u8 mac_addr[ETH_ALEN];
bba95fef 2139 int sta_idx = cb->args[1];
2ec600d6 2140 int err;
2ec600d6 2141
67748893
JB
2142 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2143 if (err)
2144 return err;
bba95fef
JB
2145
2146 if (!dev->ops->dump_station) {
eec60b03 2147 err = -EOPNOTSUPP;
bba95fef
JB
2148 goto out_err;
2149 }
2150
bba95fef
JB
2151 while (1) {
2152 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2153 mac_addr, &sinfo);
2154 if (err == -ENOENT)
2155 break;
2156 if (err)
3b85875a 2157 goto out_err;
bba95fef
JB
2158
2159 if (nl80211_send_station(skb,
2160 NETLINK_CB(cb->skb).pid,
2161 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2162 netdev, mac_addr,
2163 &sinfo) < 0)
2164 goto out;
2165
2166 sta_idx++;
2167 }
2168
2169
2170 out:
2171 cb->args[1] = sta_idx;
2172 err = skb->len;
bba95fef 2173 out_err:
67748893 2174 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2175
2176 return err;
2ec600d6 2177}
fd5b74dc 2178
5727ef1b
JB
2179static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2180{
4c476991
JB
2181 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2182 struct net_device *dev = info->user_ptr[1];
2ec600d6 2183 struct station_info sinfo;
fd5b74dc
JB
2184 struct sk_buff *msg;
2185 u8 *mac_addr = NULL;
4c476991 2186 int err;
fd5b74dc 2187
2ec600d6 2188 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2189
2190 if (!info->attrs[NL80211_ATTR_MAC])
2191 return -EINVAL;
2192
2193 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2194
4c476991
JB
2195 if (!rdev->ops->get_station)
2196 return -EOPNOTSUPP;
3b85875a 2197
4c476991 2198 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2199 if (err)
4c476991 2200 return err;
2ec600d6 2201
fd2120ca 2202 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2203 if (!msg)
4c476991 2204 return -ENOMEM;
fd5b74dc
JB
2205
2206 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2207 dev, mac_addr, &sinfo) < 0) {
2208 nlmsg_free(msg);
2209 return -ENOBUFS;
2210 }
3b85875a 2211
4c476991 2212 return genlmsg_reply(msg, info);
5727ef1b
JB
2213}
2214
2215/*
c258d2de 2216 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2217 */
463d0183 2218static int get_vlan(struct genl_info *info,
5727ef1b
JB
2219 struct cfg80211_registered_device *rdev,
2220 struct net_device **vlan)
2221{
463d0183 2222 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2223 *vlan = NULL;
2224
2225 if (vlanattr) {
463d0183
JB
2226 *vlan = dev_get_by_index(genl_info_net(info),
2227 nla_get_u32(vlanattr));
5727ef1b
JB
2228 if (!*vlan)
2229 return -ENODEV;
2230 if (!(*vlan)->ieee80211_ptr)
2231 return -EINVAL;
2232 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2233 return -EINVAL;
c258d2de
FF
2234 if (!netif_running(*vlan))
2235 return -ENETDOWN;
5727ef1b
JB
2236 }
2237 return 0;
2238}
2239
2240static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2241{
4c476991 2242 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2243 int err;
4c476991 2244 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2245 struct station_parameters params;
2246 u8 *mac_addr = NULL;
2247
2248 memset(&params, 0, sizeof(params));
2249
2250 params.listen_interval = -1;
9c3990aa 2251 params.plink_state = PLINK_INVALID;
5727ef1b
JB
2252
2253 if (info->attrs[NL80211_ATTR_STA_AID])
2254 return -EINVAL;
2255
2256 if (!info->attrs[NL80211_ATTR_MAC])
2257 return -EINVAL;
2258
2259 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2260
2261 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2262 params.supported_rates =
2263 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2264 params.supported_rates_len =
2265 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2266 }
2267
2268 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2269 params.listen_interval =
2270 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2271
36aedc90
JM
2272 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2273 params.ht_capa =
2274 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2275
eccb8e8f 2276 if (parse_station_flags(info, &params))
5727ef1b
JB
2277 return -EINVAL;
2278
2ec600d6
LCC
2279 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2280 params.plink_action =
2281 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2282
9c3990aa
JC
2283 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2284 params.plink_state =
2285 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2286
463d0183 2287 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2288 if (err)
034d655e 2289 goto out;
a97f4424
JB
2290
2291 /* validate settings */
2292 err = 0;
2293
2294 switch (dev->ieee80211_ptr->iftype) {
2295 case NL80211_IFTYPE_AP:
2296 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2297 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2298 /* disallow mesh-specific things */
2299 if (params.plink_action)
2300 err = -EINVAL;
2301 break;
074ac8df 2302 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2303 case NL80211_IFTYPE_STATION:
2304 /* disallow everything but AUTHORIZED flag */
2305 if (params.plink_action)
2306 err = -EINVAL;
2307 if (params.vlan)
2308 err = -EINVAL;
2309 if (params.supported_rates)
2310 err = -EINVAL;
2311 if (params.ht_capa)
2312 err = -EINVAL;
2313 if (params.listen_interval >= 0)
2314 err = -EINVAL;
2315 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2316 err = -EINVAL;
2317 break;
2318 case NL80211_IFTYPE_MESH_POINT:
2319 /* disallow things mesh doesn't support */
2320 if (params.vlan)
2321 err = -EINVAL;
2322 if (params.ht_capa)
2323 err = -EINVAL;
2324 if (params.listen_interval >= 0)
2325 err = -EINVAL;
2326 if (params.supported_rates)
2327 err = -EINVAL;
b39c48fa
JC
2328 if (params.sta_flags_mask &
2329 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2330 BIT(NL80211_STA_FLAG_AUTHORIZED)))
a97f4424
JB
2331 err = -EINVAL;
2332 break;
2333 default:
2334 err = -EINVAL;
034d655e
JB
2335 }
2336
5727ef1b
JB
2337 if (err)
2338 goto out;
2339
79c97e97 2340 if (!rdev->ops->change_station) {
5727ef1b
JB
2341 err = -EOPNOTSUPP;
2342 goto out;
2343 }
2344
79c97e97 2345 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2346
2347 out:
2348 if (params.vlan)
2349 dev_put(params.vlan);
3b85875a 2350
5727ef1b
JB
2351 return err;
2352}
2353
2354static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2355{
4c476991 2356 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2357 int err;
4c476991 2358 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2359 struct station_parameters params;
2360 u8 *mac_addr = NULL;
2361
2362 memset(&params, 0, sizeof(params));
2363
2364 if (!info->attrs[NL80211_ATTR_MAC])
2365 return -EINVAL;
2366
5727ef1b
JB
2367 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2368 return -EINVAL;
2369
2370 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2371 return -EINVAL;
2372
0e956c13
TLSC
2373 if (!info->attrs[NL80211_ATTR_STA_AID])
2374 return -EINVAL;
2375
5727ef1b
JB
2376 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2377 params.supported_rates =
2378 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2379 params.supported_rates_len =
2380 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2381 params.listen_interval =
2382 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2383
0e956c13
TLSC
2384 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2385 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2386 return -EINVAL;
51b50fbe 2387
36aedc90
JM
2388 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2389 params.ht_capa =
2390 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2391
96b78dff
JC
2392 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2393 params.plink_action =
2394 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2395
eccb8e8f 2396 if (parse_station_flags(info, &params))
5727ef1b
JB
2397 return -EINVAL;
2398
0e956c13 2399 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2400 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
96b78dff 2401 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2402 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2403 return -EINVAL;
0e956c13 2404
463d0183 2405 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2406 if (err)
e80cf853 2407 goto out;
a97f4424
JB
2408
2409 /* validate settings */
2410 err = 0;
2411
79c97e97 2412 if (!rdev->ops->add_station) {
5727ef1b
JB
2413 err = -EOPNOTSUPP;
2414 goto out;
2415 }
2416
79c97e97 2417 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2418
2419 out:
2420 if (params.vlan)
2421 dev_put(params.vlan);
5727ef1b
JB
2422 return err;
2423}
2424
2425static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2426{
4c476991
JB
2427 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2428 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2429 u8 *mac_addr = NULL;
2430
2431 if (info->attrs[NL80211_ATTR_MAC])
2432 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2433
e80cf853 2434 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2435 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2436 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2437 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2438 return -EINVAL;
5727ef1b 2439
4c476991
JB
2440 if (!rdev->ops->del_station)
2441 return -EOPNOTSUPP;
3b85875a 2442
4c476991 2443 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2444}
2445
2ec600d6
LCC
2446static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2447 int flags, struct net_device *dev,
2448 u8 *dst, u8 *next_hop,
2449 struct mpath_info *pinfo)
2450{
2451 void *hdr;
2452 struct nlattr *pinfoattr;
2453
2454 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2455 if (!hdr)
2456 return -1;
2457
2458 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2459 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2460 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2461
f5ea9120
JB
2462 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2463
2ec600d6
LCC
2464 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2465 if (!pinfoattr)
2466 goto nla_put_failure;
2467 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2468 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2469 pinfo->frame_qlen);
d19b3bf6
RP
2470 if (pinfo->filled & MPATH_INFO_SN)
2471 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2472 pinfo->sn);
2ec600d6
LCC
2473 if (pinfo->filled & MPATH_INFO_METRIC)
2474 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2475 pinfo->metric);
2476 if (pinfo->filled & MPATH_INFO_EXPTIME)
2477 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2478 pinfo->exptime);
2479 if (pinfo->filled & MPATH_INFO_FLAGS)
2480 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2481 pinfo->flags);
2482 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2483 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2484 pinfo->discovery_timeout);
2485 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2486 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2487 pinfo->discovery_retries);
2488
2489 nla_nest_end(msg, pinfoattr);
2490
2491 return genlmsg_end(msg, hdr);
2492
2493 nla_put_failure:
bc3ed28c
TG
2494 genlmsg_cancel(msg, hdr);
2495 return -EMSGSIZE;
2ec600d6
LCC
2496}
2497
2498static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2499 struct netlink_callback *cb)
2ec600d6 2500{
2ec600d6
LCC
2501 struct mpath_info pinfo;
2502 struct cfg80211_registered_device *dev;
bba95fef 2503 struct net_device *netdev;
2ec600d6
LCC
2504 u8 dst[ETH_ALEN];
2505 u8 next_hop[ETH_ALEN];
bba95fef 2506 int path_idx = cb->args[1];
2ec600d6 2507 int err;
2ec600d6 2508
67748893
JB
2509 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2510 if (err)
2511 return err;
bba95fef
JB
2512
2513 if (!dev->ops->dump_mpath) {
eec60b03 2514 err = -EOPNOTSUPP;
bba95fef
JB
2515 goto out_err;
2516 }
2517
eec60b03
JM
2518 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2519 err = -EOPNOTSUPP;
0448b5fc 2520 goto out_err;
eec60b03
JM
2521 }
2522
bba95fef
JB
2523 while (1) {
2524 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2525 dst, next_hop, &pinfo);
2526 if (err == -ENOENT)
2ec600d6 2527 break;
bba95fef 2528 if (err)
3b85875a 2529 goto out_err;
2ec600d6 2530
bba95fef
JB
2531 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2532 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2533 netdev, dst, next_hop,
2534 &pinfo) < 0)
2535 goto out;
2ec600d6 2536
bba95fef 2537 path_idx++;
2ec600d6 2538 }
2ec600d6 2539
2ec600d6 2540
bba95fef
JB
2541 out:
2542 cb->args[1] = path_idx;
2543 err = skb->len;
bba95fef 2544 out_err:
67748893 2545 nl80211_finish_netdev_dump(dev);
bba95fef 2546 return err;
2ec600d6
LCC
2547}
2548
2549static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2550{
4c476991 2551 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2552 int err;
4c476991 2553 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2554 struct mpath_info pinfo;
2555 struct sk_buff *msg;
2556 u8 *dst = NULL;
2557 u8 next_hop[ETH_ALEN];
2558
2559 memset(&pinfo, 0, sizeof(pinfo));
2560
2561 if (!info->attrs[NL80211_ATTR_MAC])
2562 return -EINVAL;
2563
2564 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2565
4c476991
JB
2566 if (!rdev->ops->get_mpath)
2567 return -EOPNOTSUPP;
2ec600d6 2568
4c476991
JB
2569 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2570 return -EOPNOTSUPP;
eec60b03 2571
79c97e97 2572 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2573 if (err)
4c476991 2574 return err;
2ec600d6 2575
fd2120ca 2576 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2577 if (!msg)
4c476991 2578 return -ENOMEM;
2ec600d6
LCC
2579
2580 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2581 dev, dst, next_hop, &pinfo) < 0) {
2582 nlmsg_free(msg);
2583 return -ENOBUFS;
2584 }
3b85875a 2585
4c476991 2586 return genlmsg_reply(msg, info);
2ec600d6
LCC
2587}
2588
2589static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2590{
4c476991
JB
2591 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2592 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2593 u8 *dst = NULL;
2594 u8 *next_hop = NULL;
2595
2596 if (!info->attrs[NL80211_ATTR_MAC])
2597 return -EINVAL;
2598
2599 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2600 return -EINVAL;
2601
2602 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2603 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2604
4c476991
JB
2605 if (!rdev->ops->change_mpath)
2606 return -EOPNOTSUPP;
35a8efe1 2607
4c476991
JB
2608 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2609 return -EOPNOTSUPP;
2ec600d6 2610
4c476991 2611 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2612}
4c476991 2613
2ec600d6
LCC
2614static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2615{
4c476991
JB
2616 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2617 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2618 u8 *dst = NULL;
2619 u8 *next_hop = NULL;
2620
2621 if (!info->attrs[NL80211_ATTR_MAC])
2622 return -EINVAL;
2623
2624 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2625 return -EINVAL;
2626
2627 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2628 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2629
4c476991
JB
2630 if (!rdev->ops->add_mpath)
2631 return -EOPNOTSUPP;
35a8efe1 2632
4c476991
JB
2633 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2634 return -EOPNOTSUPP;
2ec600d6 2635
4c476991 2636 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2637}
2638
2639static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2640{
4c476991
JB
2641 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2642 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2643 u8 *dst = NULL;
2644
2645 if (info->attrs[NL80211_ATTR_MAC])
2646 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2647
4c476991
JB
2648 if (!rdev->ops->del_mpath)
2649 return -EOPNOTSUPP;
3b85875a 2650
4c476991 2651 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2652}
2653
9f1ba906
JM
2654static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2655{
4c476991
JB
2656 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2657 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2658 struct bss_parameters params;
2659
2660 memset(&params, 0, sizeof(params));
2661 /* default to not changing parameters */
2662 params.use_cts_prot = -1;
2663 params.use_short_preamble = -1;
2664 params.use_short_slot_time = -1;
fd8aaaf3 2665 params.ap_isolate = -1;
50b12f59 2666 params.ht_opmode = -1;
9f1ba906
JM
2667
2668 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2669 params.use_cts_prot =
2670 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2671 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2672 params.use_short_preamble =
2673 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2674 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2675 params.use_short_slot_time =
2676 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2677 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2678 params.basic_rates =
2679 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2680 params.basic_rates_len =
2681 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2682 }
fd8aaaf3
FF
2683 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2684 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2685 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2686 params.ht_opmode =
2687 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2688
4c476991
JB
2689 if (!rdev->ops->change_bss)
2690 return -EOPNOTSUPP;
9f1ba906 2691
074ac8df 2692 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2693 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2694 return -EOPNOTSUPP;
3b85875a 2695
4c476991 2696 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2697}
2698
b54452b0 2699static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2700 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2701 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2702 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2703 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2704 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2705 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2706};
2707
2708static int parse_reg_rule(struct nlattr *tb[],
2709 struct ieee80211_reg_rule *reg_rule)
2710{
2711 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2712 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2713
2714 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2715 return -EINVAL;
2716 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2717 return -EINVAL;
2718 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2719 return -EINVAL;
2720 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2721 return -EINVAL;
2722 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2723 return -EINVAL;
2724
2725 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2726
2727 freq_range->start_freq_khz =
2728 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2729 freq_range->end_freq_khz =
2730 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2731 freq_range->max_bandwidth_khz =
2732 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2733
2734 power_rule->max_eirp =
2735 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2736
2737 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2738 power_rule->max_antenna_gain =
2739 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2740
2741 return 0;
2742}
2743
2744static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2745{
2746 int r;
2747 char *data = NULL;
2748
80778f18
LR
2749 /*
2750 * You should only get this when cfg80211 hasn't yet initialized
2751 * completely when built-in to the kernel right between the time
2752 * window between nl80211_init() and regulatory_init(), if that is
2753 * even possible.
2754 */
2755 mutex_lock(&cfg80211_mutex);
2756 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2757 mutex_unlock(&cfg80211_mutex);
2758 return -EINPROGRESS;
80778f18 2759 }
fe33eb39 2760 mutex_unlock(&cfg80211_mutex);
80778f18 2761
fe33eb39
LR
2762 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2763 return -EINVAL;
b2e1b302
LR
2764
2765 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2766
fe33eb39
LR
2767 r = regulatory_hint_user(data);
2768
b2e1b302
LR
2769 return r;
2770}
2771
24bdd9f4 2772static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 2773 struct genl_info *info)
93da9cc1 2774{
4c476991 2775 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 2776 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
2777 struct wireless_dev *wdev = dev->ieee80211_ptr;
2778 struct mesh_config cur_params;
2779 int err = 0;
93da9cc1 2780 void *hdr;
2781 struct nlattr *pinfoattr;
2782 struct sk_buff *msg;
2783
29cbe68c
JB
2784 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2785 return -EOPNOTSUPP;
2786
24bdd9f4 2787 if (!rdev->ops->get_mesh_config)
4c476991 2788 return -EOPNOTSUPP;
f3f92586 2789
29cbe68c
JB
2790 wdev_lock(wdev);
2791 /* If not connected, get default parameters */
2792 if (!wdev->mesh_id_len)
2793 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2794 else
24bdd9f4 2795 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2796 &cur_params);
2797 wdev_unlock(wdev);
2798
93da9cc1 2799 if (err)
4c476991 2800 return err;
93da9cc1 2801
2802 /* Draw up a netlink message to send back */
fd2120ca 2803 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2804 if (!msg)
2805 return -ENOMEM;
93da9cc1 2806 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 2807 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 2808 if (!hdr)
efe1cf0c 2809 goto out;
24bdd9f4 2810 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 2811 if (!pinfoattr)
2812 goto nla_put_failure;
2813 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2814 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2815 cur_params.dot11MeshRetryTimeout);
2816 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2817 cur_params.dot11MeshConfirmTimeout);
2818 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2819 cur_params.dot11MeshHoldingTimeout);
2820 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2821 cur_params.dot11MeshMaxPeerLinks);
2822 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2823 cur_params.dot11MeshMaxRetries);
2824 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2825 cur_params.dot11MeshTTL);
45904f21
JC
2826 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2827 cur_params.element_ttl);
93da9cc1 2828 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2829 cur_params.auto_open_plinks);
2830 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2831 cur_params.dot11MeshHWMPmaxPREQretries);
2832 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2833 cur_params.path_refresh_time);
2834 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2835 cur_params.min_discovery_timeout);
2836 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2837 cur_params.dot11MeshHWMPactivePathTimeout);
2838 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2839 cur_params.dot11MeshHWMPpreqMinInterval);
2840 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2841 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2842 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2843 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2844 nla_nest_end(msg, pinfoattr);
2845 genlmsg_end(msg, hdr);
4c476991 2846 return genlmsg_reply(msg, info);
93da9cc1 2847
3b85875a 2848 nla_put_failure:
93da9cc1 2849 genlmsg_cancel(msg, hdr);
efe1cf0c 2850 out:
d080e275 2851 nlmsg_free(msg);
4c476991 2852 return -ENOBUFS;
93da9cc1 2853}
2854
b54452b0 2855static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2856 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2857 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2858 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2859 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2860 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2861 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 2862 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 2863 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2864
2865 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2866 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2867 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2868 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2869 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2870 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2871};
2872
c80d545d
JC
2873static const struct nla_policy
2874 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2875 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2876 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 2877 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 2878 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 2879 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 2880 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
2881};
2882
24bdd9f4 2883static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
2884 struct mesh_config *cfg,
2885 u32 *mask_out)
93da9cc1 2886{
93da9cc1 2887 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 2888 u32 mask = 0;
93da9cc1 2889
bd90fdcc
JB
2890#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2891do {\
2892 if (table[attr_num]) {\
2893 cfg->param = nla_fn(table[attr_num]); \
2894 mask |= (1 << (attr_num - 1)); \
2895 } \
2896} while (0);\
2897
2898
24bdd9f4 2899 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 2900 return -EINVAL;
2901 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 2902 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 2903 nl80211_meshconf_params_policy))
93da9cc1 2904 return -EINVAL;
2905
93da9cc1 2906 /* This makes sure that there aren't more than 32 mesh config
2907 * parameters (otherwise our bitfield scheme would not work.) */
2908 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2909
2910 /* Fill in the params struct */
93da9cc1 2911 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2912 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2913 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2914 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2915 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2916 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2917 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2918 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2919 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2920 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2921 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2922 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
2923 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2924 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 2925 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2926 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2927 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2928 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2929 nla_get_u8);
2930 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2931 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2932 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2933 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2934 nla_get_u16);
2935 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2936 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2937 nla_get_u32);
2938 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2939 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2940 nla_get_u16);
2941 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2942 dot11MeshHWMPnetDiameterTraversalTime,
2943 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2944 nla_get_u16);
63c5723b
RP
2945 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2946 dot11MeshHWMPRootMode, mask,
2947 NL80211_MESHCONF_HWMP_ROOTMODE,
2948 nla_get_u8);
bd90fdcc
JB
2949 if (mask_out)
2950 *mask_out = mask;
c80d545d 2951
bd90fdcc
JB
2952 return 0;
2953
2954#undef FILL_IN_MESH_PARAM_IF_SET
2955}
2956
c80d545d
JC
2957static int nl80211_parse_mesh_setup(struct genl_info *info,
2958 struct mesh_setup *setup)
2959{
2960 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
2961
2962 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
2963 return -EINVAL;
2964 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
2965 info->attrs[NL80211_ATTR_MESH_SETUP],
2966 nl80211_mesh_setup_params_policy))
2967 return -EINVAL;
2968
2969 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
2970 setup->path_sel_proto =
2971 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
2972 IEEE80211_PATH_PROTOCOL_VENDOR :
2973 IEEE80211_PATH_PROTOCOL_HWMP;
2974
2975 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
2976 setup->path_metric =
2977 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
2978 IEEE80211_PATH_METRIC_VENDOR :
2979 IEEE80211_PATH_METRIC_AIRTIME;
2980
581a8b0f
JC
2981
2982 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 2983 struct nlattr *ieattr =
581a8b0f 2984 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
2985 if (!is_valid_ie_attr(ieattr))
2986 return -EINVAL;
581a8b0f
JC
2987 setup->ie = nla_data(ieattr);
2988 setup->ie_len = nla_len(ieattr);
c80d545d 2989 }
b130e5ce
JC
2990 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
2991 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
2992
2993 return 0;
2994}
2995
24bdd9f4 2996static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 2997 struct genl_info *info)
bd90fdcc
JB
2998{
2999 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3000 struct net_device *dev = info->user_ptr[1];
29cbe68c 3001 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3002 struct mesh_config cfg;
3003 u32 mask;
3004 int err;
3005
29cbe68c
JB
3006 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3007 return -EOPNOTSUPP;
3008
24bdd9f4 3009 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3010 return -EOPNOTSUPP;
3011
24bdd9f4 3012 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3013 if (err)
3014 return err;
3015
29cbe68c
JB
3016 wdev_lock(wdev);
3017 if (!wdev->mesh_id_len)
3018 err = -ENOLINK;
3019
3020 if (!err)
24bdd9f4 3021 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3022 mask, &cfg);
3023
3024 wdev_unlock(wdev);
3025
3026 return err;
93da9cc1 3027}
3028
f130347c
LR
3029static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3030{
3031 struct sk_buff *msg;
3032 void *hdr = NULL;
3033 struct nlattr *nl_reg_rules;
3034 unsigned int i;
3035 int err = -EINVAL;
3036
a1794390 3037 mutex_lock(&cfg80211_mutex);
f130347c
LR
3038
3039 if (!cfg80211_regdomain)
3040 goto out;
3041
fd2120ca 3042 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3043 if (!msg) {
3044 err = -ENOBUFS;
3045 goto out;
3046 }
3047
3048 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3049 NL80211_CMD_GET_REG);
3050 if (!hdr)
efe1cf0c 3051 goto put_failure;
f130347c
LR
3052
3053 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3054 cfg80211_regdomain->alpha2);
3055
3056 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3057 if (!nl_reg_rules)
3058 goto nla_put_failure;
3059
3060 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3061 struct nlattr *nl_reg_rule;
3062 const struct ieee80211_reg_rule *reg_rule;
3063 const struct ieee80211_freq_range *freq_range;
3064 const struct ieee80211_power_rule *power_rule;
3065
3066 reg_rule = &cfg80211_regdomain->reg_rules[i];
3067 freq_range = &reg_rule->freq_range;
3068 power_rule = &reg_rule->power_rule;
3069
3070 nl_reg_rule = nla_nest_start(msg, i);
3071 if (!nl_reg_rule)
3072 goto nla_put_failure;
3073
3074 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3075 reg_rule->flags);
3076 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3077 freq_range->start_freq_khz);
3078 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3079 freq_range->end_freq_khz);
3080 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3081 freq_range->max_bandwidth_khz);
3082 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3083 power_rule->max_antenna_gain);
3084 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3085 power_rule->max_eirp);
3086
3087 nla_nest_end(msg, nl_reg_rule);
3088 }
3089
3090 nla_nest_end(msg, nl_reg_rules);
3091
3092 genlmsg_end(msg, hdr);
134e6375 3093 err = genlmsg_reply(msg, info);
f130347c
LR
3094 goto out;
3095
3096nla_put_failure:
3097 genlmsg_cancel(msg, hdr);
efe1cf0c 3098put_failure:
d080e275 3099 nlmsg_free(msg);
f130347c
LR
3100 err = -EMSGSIZE;
3101out:
a1794390 3102 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3103 return err;
3104}
3105
b2e1b302
LR
3106static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3107{
3108 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3109 struct nlattr *nl_reg_rule;
3110 char *alpha2 = NULL;
3111 int rem_reg_rules = 0, r = 0;
3112 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3113 struct ieee80211_regdomain *rd = NULL;
3114
3115 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3116 return -EINVAL;
3117
3118 if (!info->attrs[NL80211_ATTR_REG_RULES])
3119 return -EINVAL;
3120
3121 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3122
3123 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3124 rem_reg_rules) {
3125 num_rules++;
3126 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3127 return -EINVAL;
b2e1b302
LR
3128 }
3129
61405e97
LR
3130 mutex_lock(&cfg80211_mutex);
3131
d0e18f83
LR
3132 if (!reg_is_valid_request(alpha2)) {
3133 r = -EINVAL;
3134 goto bad_reg;
3135 }
b2e1b302
LR
3136
3137 size_of_regd = sizeof(struct ieee80211_regdomain) +
3138 (num_rules * sizeof(struct ieee80211_reg_rule));
3139
3140 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3141 if (!rd) {
3142 r = -ENOMEM;
3143 goto bad_reg;
3144 }
b2e1b302
LR
3145
3146 rd->n_reg_rules = num_rules;
3147 rd->alpha2[0] = alpha2[0];
3148 rd->alpha2[1] = alpha2[1];
3149
3150 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3151 rem_reg_rules) {
3152 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3153 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3154 reg_rule_policy);
3155 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3156 if (r)
3157 goto bad_reg;
3158
3159 rule_idx++;
3160
d0e18f83
LR
3161 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3162 r = -EINVAL;
b2e1b302 3163 goto bad_reg;
d0e18f83 3164 }
b2e1b302
LR
3165 }
3166
3167 BUG_ON(rule_idx != num_rules);
3168
b2e1b302 3169 r = set_regdom(rd);
61405e97 3170
a1794390 3171 mutex_unlock(&cfg80211_mutex);
d0e18f83 3172
b2e1b302
LR
3173 return r;
3174
d2372b31 3175 bad_reg:
61405e97 3176 mutex_unlock(&cfg80211_mutex);
b2e1b302 3177 kfree(rd);
d0e18f83 3178 return r;
b2e1b302
LR
3179}
3180
83f5e2cf
JB
3181static int validate_scan_freqs(struct nlattr *freqs)
3182{
3183 struct nlattr *attr1, *attr2;
3184 int n_channels = 0, tmp1, tmp2;
3185
3186 nla_for_each_nested(attr1, freqs, tmp1) {
3187 n_channels++;
3188 /*
3189 * Some hardware has a limited channel list for
3190 * scanning, and it is pretty much nonsensical
3191 * to scan for a channel twice, so disallow that
3192 * and don't require drivers to check that the
3193 * channel list they get isn't longer than what
3194 * they can scan, as long as they can scan all
3195 * the channels they registered at once.
3196 */
3197 nla_for_each_nested(attr2, freqs, tmp2)
3198 if (attr1 != attr2 &&
3199 nla_get_u32(attr1) == nla_get_u32(attr2))
3200 return 0;
3201 }
3202
3203 return n_channels;
3204}
3205
2a519311
JB
3206static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3207{
4c476991
JB
3208 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3209 struct net_device *dev = info->user_ptr[1];
2a519311
JB
3210 struct cfg80211_scan_request *request;
3211 struct cfg80211_ssid *ssid;
3212 struct ieee80211_channel *channel;
3213 struct nlattr *attr;
3214 struct wiphy *wiphy;
83f5e2cf 3215 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3216 enum ieee80211_band band;
70692ad2 3217 size_t ie_len;
2a519311 3218
f4a11bb0
JB
3219 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3220 return -EINVAL;
3221
79c97e97 3222 wiphy = &rdev->wiphy;
2a519311 3223
4c476991
JB
3224 if (!rdev->ops->scan)
3225 return -EOPNOTSUPP;
2a519311 3226
4c476991
JB
3227 if (rdev->scan_req)
3228 return -EBUSY;
2a519311
JB
3229
3230 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3231 n_channels = validate_scan_freqs(
3232 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3233 if (!n_channels)
3234 return -EINVAL;
2a519311 3235 } else {
83f5e2cf
JB
3236 n_channels = 0;
3237
2a519311
JB
3238 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3239 if (wiphy->bands[band])
3240 n_channels += wiphy->bands[band]->n_channels;
3241 }
3242
3243 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3244 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3245 n_ssids++;
3246
4c476991
JB
3247 if (n_ssids > wiphy->max_scan_ssids)
3248 return -EINVAL;
2a519311 3249
70692ad2
JM
3250 if (info->attrs[NL80211_ATTR_IE])
3251 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3252 else
3253 ie_len = 0;
3254
4c476991
JB
3255 if (ie_len > wiphy->max_scan_ie_len)
3256 return -EINVAL;
18a83659 3257
2a519311
JB
3258 request = kzalloc(sizeof(*request)
3259 + sizeof(*ssid) * n_ssids
70692ad2
JM
3260 + sizeof(channel) * n_channels
3261 + ie_len, GFP_KERNEL);
4c476991
JB
3262 if (!request)
3263 return -ENOMEM;
2a519311 3264
2a519311 3265 if (n_ssids)
5ba63533 3266 request->ssids = (void *)&request->channels[n_channels];
2a519311 3267 request->n_ssids = n_ssids;
70692ad2
JM
3268 if (ie_len) {
3269 if (request->ssids)
3270 request->ie = (void *)(request->ssids + n_ssids);
3271 else
3272 request->ie = (void *)(request->channels + n_channels);
3273 }
2a519311 3274
584991dc 3275 i = 0;
2a519311
JB
3276 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3277 /* user specified, bail out if channel not found */
2a519311 3278 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3279 struct ieee80211_channel *chan;
3280
3281 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3282
3283 if (!chan) {
2a519311
JB
3284 err = -EINVAL;
3285 goto out_free;
3286 }
584991dc
JB
3287
3288 /* ignore disabled channels */
3289 if (chan->flags & IEEE80211_CHAN_DISABLED)
3290 continue;
3291
3292 request->channels[i] = chan;
2a519311
JB
3293 i++;
3294 }
3295 } else {
3296 /* all channels */
2a519311
JB
3297 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3298 int j;
3299 if (!wiphy->bands[band])
3300 continue;
3301 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3302 struct ieee80211_channel *chan;
3303
3304 chan = &wiphy->bands[band]->channels[j];
3305
3306 if (chan->flags & IEEE80211_CHAN_DISABLED)
3307 continue;
3308
3309 request->channels[i] = chan;
2a519311
JB
3310 i++;
3311 }
3312 }
3313 }
3314
584991dc
JB
3315 if (!i) {
3316 err = -EINVAL;
3317 goto out_free;
3318 }
3319
3320 request->n_channels = i;
3321
2a519311
JB
3322 i = 0;
3323 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3324 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3325 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3326 err = -EINVAL;
3327 goto out_free;
3328 }
3329 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3330 request->ssids[i].ssid_len = nla_len(attr);
3331 i++;
3332 }
3333 }
3334
70692ad2
JM
3335 if (info->attrs[NL80211_ATTR_IE]) {
3336 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3337 memcpy((void *)request->ie,
3338 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3339 request->ie_len);
3340 }
3341
463d0183 3342 request->dev = dev;
79c97e97 3343 request->wiphy = &rdev->wiphy;
2a519311 3344
79c97e97
JB
3345 rdev->scan_req = request;
3346 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3347
463d0183 3348 if (!err) {
79c97e97 3349 nl80211_send_scan_start(rdev, dev);
463d0183 3350 dev_hold(dev);
4c476991 3351 } else {
2a519311 3352 out_free:
79c97e97 3353 rdev->scan_req = NULL;
2a519311
JB
3354 kfree(request);
3355 }
3b85875a 3356
2a519311
JB
3357 return err;
3358}
3359
3360static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3361 struct cfg80211_registered_device *rdev,
48ab905d
JB
3362 struct wireless_dev *wdev,
3363 struct cfg80211_internal_bss *intbss)
2a519311 3364{
48ab905d 3365 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3366 void *hdr;
3367 struct nlattr *bss;
48ab905d
JB
3368 int i;
3369
3370 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3371
3372 hdr = nl80211hdr_put(msg, pid, seq, flags,
3373 NL80211_CMD_NEW_SCAN_RESULTS);
3374 if (!hdr)
3375 return -1;
3376
f5ea9120 3377 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3378 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3379
3380 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3381 if (!bss)
3382 goto nla_put_failure;
3383 if (!is_zero_ether_addr(res->bssid))
3384 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3385 if (res->information_elements && res->len_information_elements)
3386 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3387 res->len_information_elements,
3388 res->information_elements);
34a6eddb
JM
3389 if (res->beacon_ies && res->len_beacon_ies &&
3390 res->beacon_ies != res->information_elements)
3391 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3392 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3393 if (res->tsf)
3394 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3395 if (res->beacon_interval)
3396 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3397 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3398 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3399 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3400 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3401
77965c97 3402 switch (rdev->wiphy.signal_type) {
2a519311
JB
3403 case CFG80211_SIGNAL_TYPE_MBM:
3404 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3405 break;
3406 case CFG80211_SIGNAL_TYPE_UNSPEC:
3407 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3408 break;
3409 default:
3410 break;
3411 }
3412
48ab905d 3413 switch (wdev->iftype) {
074ac8df 3414 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3415 case NL80211_IFTYPE_STATION:
3416 if (intbss == wdev->current_bss)
3417 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3418 NL80211_BSS_STATUS_ASSOCIATED);
3419 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3420 if (intbss != wdev->auth_bsses[i])
3421 continue;
3422 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3423 NL80211_BSS_STATUS_AUTHENTICATED);
3424 break;
3425 }
3426 break;
3427 case NL80211_IFTYPE_ADHOC:
3428 if (intbss == wdev->current_bss)
3429 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3430 NL80211_BSS_STATUS_IBSS_JOINED);
3431 break;
3432 default:
3433 break;
3434 }
3435
2a519311
JB
3436 nla_nest_end(msg, bss);
3437
3438 return genlmsg_end(msg, hdr);
3439
3440 nla_put_failure:
3441 genlmsg_cancel(msg, hdr);
3442 return -EMSGSIZE;
3443}
3444
3445static int nl80211_dump_scan(struct sk_buff *skb,
3446 struct netlink_callback *cb)
3447{
48ab905d
JB
3448 struct cfg80211_registered_device *rdev;
3449 struct net_device *dev;
2a519311 3450 struct cfg80211_internal_bss *scan;
48ab905d 3451 struct wireless_dev *wdev;
2a519311
JB
3452 int start = cb->args[1], idx = 0;
3453 int err;
3454
67748893
JB
3455 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3456 if (err)
3457 return err;
2a519311 3458
48ab905d 3459 wdev = dev->ieee80211_ptr;
2a519311 3460
48ab905d
JB
3461 wdev_lock(wdev);
3462 spin_lock_bh(&rdev->bss_lock);
3463 cfg80211_bss_expire(rdev);
3464
3465 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3466 if (++idx <= start)
3467 continue;
3468 if (nl80211_send_bss(skb,
3469 NETLINK_CB(cb->skb).pid,
3470 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3471 rdev, wdev, scan) < 0) {
2a519311 3472 idx--;
67748893 3473 break;
2a519311
JB
3474 }
3475 }
3476
48ab905d
JB
3477 spin_unlock_bh(&rdev->bss_lock);
3478 wdev_unlock(wdev);
2a519311
JB
3479
3480 cb->args[1] = idx;
67748893 3481 nl80211_finish_netdev_dump(rdev);
2a519311 3482
67748893 3483 return skb->len;
2a519311
JB
3484}
3485
61fa713c
HS
3486static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3487 int flags, struct net_device *dev,
3488 struct survey_info *survey)
3489{
3490 void *hdr;
3491 struct nlattr *infoattr;
3492
3493 /* Survey without a channel doesn't make sense */
3494 if (!survey->channel)
3495 return -EINVAL;
3496
3497 hdr = nl80211hdr_put(msg, pid, seq, flags,
3498 NL80211_CMD_NEW_SURVEY_RESULTS);
3499 if (!hdr)
3500 return -ENOMEM;
3501
3502 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3503
3504 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3505 if (!infoattr)
3506 goto nla_put_failure;
3507
3508 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3509 survey->channel->center_freq);
3510 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3511 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3512 survey->noise);
17e5a808
FF
3513 if (survey->filled & SURVEY_INFO_IN_USE)
3514 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
3515 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3516 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3517 survey->channel_time);
3518 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3519 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3520 survey->channel_time_busy);
3521 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3522 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3523 survey->channel_time_ext_busy);
3524 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3525 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3526 survey->channel_time_rx);
3527 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3528 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3529 survey->channel_time_tx);
61fa713c
HS
3530
3531 nla_nest_end(msg, infoattr);
3532
3533 return genlmsg_end(msg, hdr);
3534
3535 nla_put_failure:
3536 genlmsg_cancel(msg, hdr);
3537 return -EMSGSIZE;
3538}
3539
3540static int nl80211_dump_survey(struct sk_buff *skb,
3541 struct netlink_callback *cb)
3542{
3543 struct survey_info survey;
3544 struct cfg80211_registered_device *dev;
3545 struct net_device *netdev;
61fa713c
HS
3546 int survey_idx = cb->args[1];
3547 int res;
3548
67748893
JB
3549 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3550 if (res)
3551 return res;
61fa713c
HS
3552
3553 if (!dev->ops->dump_survey) {
3554 res = -EOPNOTSUPP;
3555 goto out_err;
3556 }
3557
3558 while (1) {
3559 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3560 &survey);
3561 if (res == -ENOENT)
3562 break;
3563 if (res)
3564 goto out_err;
3565
3566 if (nl80211_send_survey(skb,
3567 NETLINK_CB(cb->skb).pid,
3568 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3569 netdev,
3570 &survey) < 0)
3571 goto out;
3572 survey_idx++;
3573 }
3574
3575 out:
3576 cb->args[1] = survey_idx;
3577 res = skb->len;
3578 out_err:
67748893 3579 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3580 return res;
3581}
3582
255e737e
JM
3583static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3584{
b23aa676
SO
3585 return auth_type <= NL80211_AUTHTYPE_MAX;
3586}
3587
3588static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3589{
3590 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3591 NL80211_WPA_VERSION_2));
3592}
3593
3594static bool nl80211_valid_akm_suite(u32 akm)
3595{
3596 return akm == WLAN_AKM_SUITE_8021X ||
3597 akm == WLAN_AKM_SUITE_PSK;
3598}
3599
3600static bool nl80211_valid_cipher_suite(u32 cipher)
3601{
3602 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3603 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3604 cipher == WLAN_CIPHER_SUITE_TKIP ||
3605 cipher == WLAN_CIPHER_SUITE_CCMP ||
3606 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3607}
3608
b23aa676 3609
636a5d36
JM
3610static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3611{
4c476991
JB
3612 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3613 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3614 struct ieee80211_channel *chan;
3615 const u8 *bssid, *ssid, *ie = NULL;
3616 int err, ssid_len, ie_len = 0;
3617 enum nl80211_auth_type auth_type;
fffd0934 3618 struct key_parse key;
d5cdfacb 3619 bool local_state_change;
636a5d36 3620
f4a11bb0
JB
3621 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3622 return -EINVAL;
3623
3624 if (!info->attrs[NL80211_ATTR_MAC])
3625 return -EINVAL;
3626
1778092e
JM
3627 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3628 return -EINVAL;
3629
19957bb3
JB
3630 if (!info->attrs[NL80211_ATTR_SSID])
3631 return -EINVAL;
3632
3633 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3634 return -EINVAL;
3635
fffd0934
JB
3636 err = nl80211_parse_key(info, &key);
3637 if (err)
3638 return err;
3639
3640 if (key.idx >= 0) {
e31b8213
JB
3641 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3642 return -EINVAL;
fffd0934
JB
3643 if (!key.p.key || !key.p.key_len)
3644 return -EINVAL;
3645 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3646 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3647 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3648 key.p.key_len != WLAN_KEY_LEN_WEP104))
3649 return -EINVAL;
3650 if (key.idx > 4)
3651 return -EINVAL;
3652 } else {
3653 key.p.key_len = 0;
3654 key.p.key = NULL;
3655 }
3656
afea0b7a
JB
3657 if (key.idx >= 0) {
3658 int i;
3659 bool ok = false;
3660 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3661 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3662 ok = true;
3663 break;
3664 }
3665 }
4c476991
JB
3666 if (!ok)
3667 return -EINVAL;
afea0b7a
JB
3668 }
3669
4c476991
JB
3670 if (!rdev->ops->auth)
3671 return -EOPNOTSUPP;
636a5d36 3672
074ac8df 3673 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3674 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3675 return -EOPNOTSUPP;
eec60b03 3676
19957bb3 3677 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3678 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3679 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3680 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3681 return -EINVAL;
636a5d36 3682
19957bb3
JB
3683 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3684 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3685
3686 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3687 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3688 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3689 }
3690
19957bb3 3691 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3692 if (!nl80211_valid_auth_type(auth_type))
3693 return -EINVAL;
636a5d36 3694
d5cdfacb
JM
3695 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3696
4c476991
JB
3697 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3698 ssid, ssid_len, ie, ie_len,
3699 key.p.key, key.p.key_len, key.idx,
3700 local_state_change);
636a5d36
JM
3701}
3702
c0692b8f
JB
3703static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3704 struct genl_info *info,
3dc27d25
JB
3705 struct cfg80211_crypto_settings *settings,
3706 int cipher_limit)
b23aa676 3707{
c0b2bbd8
JB
3708 memset(settings, 0, sizeof(*settings));
3709
b23aa676
SO
3710 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3711
c0692b8f
JB
3712 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3713 u16 proto;
3714 proto = nla_get_u16(
3715 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3716 settings->control_port_ethertype = cpu_to_be16(proto);
3717 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3718 proto != ETH_P_PAE)
3719 return -EINVAL;
3720 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3721 settings->control_port_no_encrypt = true;
3722 } else
3723 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3724
b23aa676
SO
3725 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3726 void *data;
3727 int len, i;
3728
3729 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3730 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3731 settings->n_ciphers_pairwise = len / sizeof(u32);
3732
3733 if (len % sizeof(u32))
3734 return -EINVAL;
3735
3dc27d25 3736 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3737 return -EINVAL;
3738
3739 memcpy(settings->ciphers_pairwise, data, len);
3740
3741 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3742 if (!nl80211_valid_cipher_suite(
3743 settings->ciphers_pairwise[i]))
3744 return -EINVAL;
3745 }
3746
3747 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3748 settings->cipher_group =
3749 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3750 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3751 return -EINVAL;
3752 }
3753
3754 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3755 settings->wpa_versions =
3756 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3757 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3758 return -EINVAL;
3759 }
3760
3761 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3762 void *data;
3763 int len, i;
3764
3765 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3766 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3767 settings->n_akm_suites = len / sizeof(u32);
3768
3769 if (len % sizeof(u32))
3770 return -EINVAL;
3771
3772 memcpy(settings->akm_suites, data, len);
3773
3774 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3775 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3776 return -EINVAL;
3777 }
3778
3779 return 0;
3780}
3781
636a5d36
JM
3782static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3783{
4c476991
JB
3784 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3785 struct net_device *dev = info->user_ptr[1];
19957bb3 3786 struct cfg80211_crypto_settings crypto;
f444de05 3787 struct ieee80211_channel *chan;
3e5d7649 3788 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3789 int err, ssid_len, ie_len = 0;
3790 bool use_mfp = false;
636a5d36 3791
f4a11bb0
JB
3792 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3793 return -EINVAL;
3794
3795 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3796 !info->attrs[NL80211_ATTR_SSID] ||
3797 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3798 return -EINVAL;
3799
4c476991
JB
3800 if (!rdev->ops->assoc)
3801 return -EOPNOTSUPP;
636a5d36 3802
074ac8df 3803 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3804 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3805 return -EOPNOTSUPP;
eec60b03 3806
19957bb3 3807 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3808
19957bb3
JB
3809 chan = ieee80211_get_channel(&rdev->wiphy,
3810 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3811 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3812 return -EINVAL;
636a5d36 3813
19957bb3
JB
3814 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3815 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3816
3817 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3818 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3819 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3820 }
3821
dc6382ce 3822 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3823 enum nl80211_mfp mfp =
dc6382ce 3824 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3825 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3826 use_mfp = true;
4c476991
JB
3827 else if (mfp != NL80211_MFP_NO)
3828 return -EINVAL;
dc6382ce
JM
3829 }
3830
3e5d7649
JB
3831 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3832 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3833
c0692b8f 3834 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3835 if (!err)
3e5d7649
JB
3836 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3837 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3838 &crypto);
636a5d36 3839
636a5d36
JM
3840 return err;
3841}
3842
3843static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3844{
4c476991
JB
3845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3846 struct net_device *dev = info->user_ptr[1];
19957bb3 3847 const u8 *ie = NULL, *bssid;
4c476991 3848 int ie_len = 0;
19957bb3 3849 u16 reason_code;
d5cdfacb 3850 bool local_state_change;
636a5d36 3851
f4a11bb0
JB
3852 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3853 return -EINVAL;
3854
3855 if (!info->attrs[NL80211_ATTR_MAC])
3856 return -EINVAL;
3857
3858 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3859 return -EINVAL;
3860
4c476991
JB
3861 if (!rdev->ops->deauth)
3862 return -EOPNOTSUPP;
636a5d36 3863
074ac8df 3864 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3865 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3866 return -EOPNOTSUPP;
eec60b03 3867
19957bb3 3868 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3869
19957bb3
JB
3870 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3871 if (reason_code == 0) {
f4a11bb0 3872 /* Reason Code 0 is reserved */
4c476991 3873 return -EINVAL;
255e737e 3874 }
636a5d36
JM
3875
3876 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3877 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3878 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3879 }
3880
d5cdfacb
JM
3881 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3882
4c476991
JB
3883 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3884 local_state_change);
636a5d36
JM
3885}
3886
3887static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3888{
4c476991
JB
3889 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3890 struct net_device *dev = info->user_ptr[1];
19957bb3 3891 const u8 *ie = NULL, *bssid;
4c476991 3892 int ie_len = 0;
19957bb3 3893 u16 reason_code;
d5cdfacb 3894 bool local_state_change;
636a5d36 3895
f4a11bb0
JB
3896 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3897 return -EINVAL;
3898
3899 if (!info->attrs[NL80211_ATTR_MAC])
3900 return -EINVAL;
3901
3902 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3903 return -EINVAL;
3904
4c476991
JB
3905 if (!rdev->ops->disassoc)
3906 return -EOPNOTSUPP;
636a5d36 3907
074ac8df 3908 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3909 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3910 return -EOPNOTSUPP;
eec60b03 3911
19957bb3 3912 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3913
19957bb3
JB
3914 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3915 if (reason_code == 0) {
f4a11bb0 3916 /* Reason Code 0 is reserved */
4c476991 3917 return -EINVAL;
255e737e 3918 }
636a5d36
JM
3919
3920 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3921 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3922 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3923 }
3924
d5cdfacb
JM
3925 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3926
4c476991
JB
3927 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3928 local_state_change);
636a5d36
JM
3929}
3930
dd5b4cc7
FF
3931static bool
3932nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3933 int mcast_rate[IEEE80211_NUM_BANDS],
3934 int rateval)
3935{
3936 struct wiphy *wiphy = &rdev->wiphy;
3937 bool found = false;
3938 int band, i;
3939
3940 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3941 struct ieee80211_supported_band *sband;
3942
3943 sband = wiphy->bands[band];
3944 if (!sband)
3945 continue;
3946
3947 for (i = 0; i < sband->n_bitrates; i++) {
3948 if (sband->bitrates[i].bitrate == rateval) {
3949 mcast_rate[band] = i + 1;
3950 found = true;
3951 break;
3952 }
3953 }
3954 }
3955
3956 return found;
3957}
3958
04a773ad
JB
3959static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3960{
4c476991
JB
3961 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3962 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
3963 struct cfg80211_ibss_params ibss;
3964 struct wiphy *wiphy;
fffd0934 3965 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3966 int err;
3967
8e30bc55
JB
3968 memset(&ibss, 0, sizeof(ibss));
3969
04a773ad
JB
3970 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3971 return -EINVAL;
3972
3973 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3974 !info->attrs[NL80211_ATTR_SSID] ||
3975 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3976 return -EINVAL;
3977
8e30bc55
JB
3978 ibss.beacon_interval = 100;
3979
3980 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3981 ibss.beacon_interval =
3982 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3983 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3984 return -EINVAL;
3985 }
3986
4c476991
JB
3987 if (!rdev->ops->join_ibss)
3988 return -EOPNOTSUPP;
04a773ad 3989
4c476991
JB
3990 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3991 return -EOPNOTSUPP;
04a773ad 3992
79c97e97 3993 wiphy = &rdev->wiphy;
04a773ad
JB
3994
3995 if (info->attrs[NL80211_ATTR_MAC])
3996 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3997 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3998 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3999
4000 if (info->attrs[NL80211_ATTR_IE]) {
4001 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4002 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4003 }
4004
4005 ibss.channel = ieee80211_get_channel(wiphy,
4006 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4007 if (!ibss.channel ||
4008 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4009 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4010 return -EINVAL;
04a773ad
JB
4011
4012 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4013 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4014
fbd2c8dc
TP
4015 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4016 u8 *rates =
4017 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4018 int n_rates =
4019 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4020 struct ieee80211_supported_band *sband =
4021 wiphy->bands[ibss.channel->band];
4022 int i, j;
4023
4c476991
JB
4024 if (n_rates == 0)
4025 return -EINVAL;
fbd2c8dc
TP
4026
4027 for (i = 0; i < n_rates; i++) {
4028 int rate = (rates[i] & 0x7f) * 5;
4029 bool found = false;
4030
4031 for (j = 0; j < sband->n_bitrates; j++) {
4032 if (sband->bitrates[j].bitrate == rate) {
4033 found = true;
4034 ibss.basic_rates |= BIT(j);
4035 break;
4036 }
4037 }
4c476991
JB
4038 if (!found)
4039 return -EINVAL;
fbd2c8dc 4040 }
fbd2c8dc 4041 }
dd5b4cc7
FF
4042
4043 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4044 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4045 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4046 return -EINVAL;
fbd2c8dc 4047
4c476991
JB
4048 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4049 connkeys = nl80211_parse_connkeys(rdev,
4050 info->attrs[NL80211_ATTR_KEYS]);
4051 if (IS_ERR(connkeys))
4052 return PTR_ERR(connkeys);
4053 }
04a773ad 4054
4c476991 4055 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4056 if (err)
4057 kfree(connkeys);
04a773ad
JB
4058 return err;
4059}
4060
4061static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4062{
4c476991
JB
4063 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4064 struct net_device *dev = info->user_ptr[1];
04a773ad 4065
4c476991
JB
4066 if (!rdev->ops->leave_ibss)
4067 return -EOPNOTSUPP;
04a773ad 4068
4c476991
JB
4069 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4070 return -EOPNOTSUPP;
04a773ad 4071
4c476991 4072 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4073}
4074
aff89a9b
JB
4075#ifdef CONFIG_NL80211_TESTMODE
4076static struct genl_multicast_group nl80211_testmode_mcgrp = {
4077 .name = "testmode",
4078};
4079
4080static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4081{
4c476991 4082 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4083 int err;
4084
4085 if (!info->attrs[NL80211_ATTR_TESTDATA])
4086 return -EINVAL;
4087
aff89a9b
JB
4088 err = -EOPNOTSUPP;
4089 if (rdev->ops->testmode_cmd) {
4090 rdev->testmode_info = info;
4091 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4092 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4093 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4094 rdev->testmode_info = NULL;
4095 }
4096
aff89a9b
JB
4097 return err;
4098}
4099
4100static struct sk_buff *
4101__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4102 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4103{
4104 struct sk_buff *skb;
4105 void *hdr;
4106 struct nlattr *data;
4107
4108 skb = nlmsg_new(approxlen + 100, gfp);
4109 if (!skb)
4110 return NULL;
4111
4112 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4113 if (!hdr) {
4114 kfree_skb(skb);
4115 return NULL;
4116 }
4117
4118 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4119 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4120
4121 ((void **)skb->cb)[0] = rdev;
4122 ((void **)skb->cb)[1] = hdr;
4123 ((void **)skb->cb)[2] = data;
4124
4125 return skb;
4126
4127 nla_put_failure:
4128 kfree_skb(skb);
4129 return NULL;
4130}
4131
4132struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4133 int approxlen)
4134{
4135 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4136
4137 if (WARN_ON(!rdev->testmode_info))
4138 return NULL;
4139
4140 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4141 rdev->testmode_info->snd_pid,
4142 rdev->testmode_info->snd_seq,
4143 GFP_KERNEL);
4144}
4145EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4146
4147int cfg80211_testmode_reply(struct sk_buff *skb)
4148{
4149 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4150 void *hdr = ((void **)skb->cb)[1];
4151 struct nlattr *data = ((void **)skb->cb)[2];
4152
4153 if (WARN_ON(!rdev->testmode_info)) {
4154 kfree_skb(skb);
4155 return -EINVAL;
4156 }
4157
4158 nla_nest_end(skb, data);
4159 genlmsg_end(skb, hdr);
4160 return genlmsg_reply(skb, rdev->testmode_info);
4161}
4162EXPORT_SYMBOL(cfg80211_testmode_reply);
4163
4164struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4165 int approxlen, gfp_t gfp)
4166{
4167 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4168
4169 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4170}
4171EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4172
4173void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4174{
4175 void *hdr = ((void **)skb->cb)[1];
4176 struct nlattr *data = ((void **)skb->cb)[2];
4177
4178 nla_nest_end(skb, data);
4179 genlmsg_end(skb, hdr);
4180 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4181}
4182EXPORT_SYMBOL(cfg80211_testmode_event);
4183#endif
4184
b23aa676
SO
4185static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4186{
4c476991
JB
4187 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4188 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4189 struct cfg80211_connect_params connect;
4190 struct wiphy *wiphy;
fffd0934 4191 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4192 int err;
4193
4194 memset(&connect, 0, sizeof(connect));
4195
4196 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4197 return -EINVAL;
4198
4199 if (!info->attrs[NL80211_ATTR_SSID] ||
4200 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4201 return -EINVAL;
4202
4203 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4204 connect.auth_type =
4205 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4206 if (!nl80211_valid_auth_type(connect.auth_type))
4207 return -EINVAL;
4208 } else
4209 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4210
4211 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4212
c0692b8f 4213 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4214 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4215 if (err)
4216 return err;
b23aa676 4217
074ac8df 4218 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4219 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4220 return -EOPNOTSUPP;
b23aa676 4221
79c97e97 4222 wiphy = &rdev->wiphy;
b23aa676 4223
b23aa676
SO
4224 if (info->attrs[NL80211_ATTR_MAC])
4225 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4226 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4227 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4228
4229 if (info->attrs[NL80211_ATTR_IE]) {
4230 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4231 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4232 }
4233
4234 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4235 connect.channel =
4236 ieee80211_get_channel(wiphy,
4237 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4238 if (!connect.channel ||
4c476991
JB
4239 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4240 return -EINVAL;
b23aa676
SO
4241 }
4242
fffd0934
JB
4243 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4244 connkeys = nl80211_parse_connkeys(rdev,
4245 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4246 if (IS_ERR(connkeys))
4247 return PTR_ERR(connkeys);
fffd0934
JB
4248 }
4249
4250 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4251 if (err)
4252 kfree(connkeys);
b23aa676
SO
4253 return err;
4254}
4255
4256static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4257{
4c476991
JB
4258 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4259 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4260 u16 reason;
4261
4262 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4263 reason = WLAN_REASON_DEAUTH_LEAVING;
4264 else
4265 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4266
4267 if (reason == 0)
4268 return -EINVAL;
4269
074ac8df 4270 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4271 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4272 return -EOPNOTSUPP;
b23aa676 4273
4c476991 4274 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4275}
4276
463d0183
JB
4277static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4278{
4c476991 4279 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4280 struct net *net;
4281 int err;
4282 u32 pid;
4283
4284 if (!info->attrs[NL80211_ATTR_PID])
4285 return -EINVAL;
4286
4287 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4288
463d0183 4289 net = get_net_ns_by_pid(pid);
4c476991
JB
4290 if (IS_ERR(net))
4291 return PTR_ERR(net);
463d0183
JB
4292
4293 err = 0;
4294
4295 /* check if anything to do */
4c476991
JB
4296 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4297 err = cfg80211_switch_netns(rdev, net);
463d0183 4298
463d0183 4299 put_net(net);
463d0183
JB
4300 return err;
4301}
4302
67fbb16b
SO
4303static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4304{
4c476991 4305 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4306 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4307 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4308 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4309 struct cfg80211_pmksa pmksa;
4310
4311 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4312
4313 if (!info->attrs[NL80211_ATTR_MAC])
4314 return -EINVAL;
4315
4316 if (!info->attrs[NL80211_ATTR_PMKID])
4317 return -EINVAL;
4318
67fbb16b
SO
4319 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4320 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4321
074ac8df 4322 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4323 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4324 return -EOPNOTSUPP;
67fbb16b
SO
4325
4326 switch (info->genlhdr->cmd) {
4327 case NL80211_CMD_SET_PMKSA:
4328 rdev_ops = rdev->ops->set_pmksa;
4329 break;
4330 case NL80211_CMD_DEL_PMKSA:
4331 rdev_ops = rdev->ops->del_pmksa;
4332 break;
4333 default:
4334 WARN_ON(1);
4335 break;
4336 }
4337
4c476991
JB
4338 if (!rdev_ops)
4339 return -EOPNOTSUPP;
67fbb16b 4340
4c476991 4341 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4342}
4343
4344static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4345{
4c476991
JB
4346 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4347 struct net_device *dev = info->user_ptr[1];
67fbb16b 4348
074ac8df 4349 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4350 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4351 return -EOPNOTSUPP;
67fbb16b 4352
4c476991
JB
4353 if (!rdev->ops->flush_pmksa)
4354 return -EOPNOTSUPP;
67fbb16b 4355
4c476991 4356 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
4357}
4358
9588bbd5
JM
4359static int nl80211_remain_on_channel(struct sk_buff *skb,
4360 struct genl_info *info)
4361{
4c476991
JB
4362 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4363 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
4364 struct ieee80211_channel *chan;
4365 struct sk_buff *msg;
4366 void *hdr;
4367 u64 cookie;
4368 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4369 u32 freq, duration;
4370 int err;
4371
4372 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4373 !info->attrs[NL80211_ATTR_DURATION])
4374 return -EINVAL;
4375
4376 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4377
4378 /*
4379 * We should be on that channel for at least one jiffie,
4380 * and more than 5 seconds seems excessive.
4381 */
a293911d
JB
4382 if (!duration || !msecs_to_jiffies(duration) ||
4383 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
4384 return -EINVAL;
4385
4c476991
JB
4386 if (!rdev->ops->remain_on_channel)
4387 return -EOPNOTSUPP;
9588bbd5 4388
9588bbd5
JM
4389 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4390 channel_type = nla_get_u32(
4391 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4392 if (channel_type != NL80211_CHAN_NO_HT &&
4393 channel_type != NL80211_CHAN_HT20 &&
4394 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4395 channel_type != NL80211_CHAN_HT40MINUS)
4396 return -EINVAL;
9588bbd5
JM
4397 }
4398
4399 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4400 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4401 if (chan == NULL)
4402 return -EINVAL;
9588bbd5
JM
4403
4404 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4405 if (!msg)
4406 return -ENOMEM;
9588bbd5
JM
4407
4408 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4409 NL80211_CMD_REMAIN_ON_CHANNEL);
4410
4411 if (IS_ERR(hdr)) {
4412 err = PTR_ERR(hdr);
4413 goto free_msg;
4414 }
4415
4416 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4417 channel_type, duration, &cookie);
4418
4419 if (err)
4420 goto free_msg;
4421
4422 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4423
4424 genlmsg_end(msg, hdr);
4c476991
JB
4425
4426 return genlmsg_reply(msg, info);
9588bbd5
JM
4427
4428 nla_put_failure:
4429 err = -ENOBUFS;
4430 free_msg:
4431 nlmsg_free(msg);
9588bbd5
JM
4432 return err;
4433}
4434
4435static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4436 struct genl_info *info)
4437{
4c476991
JB
4438 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4439 struct net_device *dev = info->user_ptr[1];
9588bbd5 4440 u64 cookie;
9588bbd5
JM
4441
4442 if (!info->attrs[NL80211_ATTR_COOKIE])
4443 return -EINVAL;
4444
4c476991
JB
4445 if (!rdev->ops->cancel_remain_on_channel)
4446 return -EOPNOTSUPP;
9588bbd5 4447
9588bbd5
JM
4448 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4449
4c476991 4450 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
4451}
4452
13ae75b1
JM
4453static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4454 u8 *rates, u8 rates_len)
4455{
4456 u8 i;
4457 u32 mask = 0;
4458
4459 for (i = 0; i < rates_len; i++) {
4460 int rate = (rates[i] & 0x7f) * 5;
4461 int ridx;
4462 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4463 struct ieee80211_rate *srate =
4464 &sband->bitrates[ridx];
4465 if (rate == srate->bitrate) {
4466 mask |= 1 << ridx;
4467 break;
4468 }
4469 }
4470 if (ridx == sband->n_bitrates)
4471 return 0; /* rate not found */
4472 }
4473
4474 return mask;
4475}
4476
b54452b0 4477static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4478 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4479 .len = NL80211_MAX_SUPP_RATES },
4480};
4481
4482static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4483 struct genl_info *info)
4484{
4485 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4486 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4487 struct cfg80211_bitrate_mask mask;
4c476991
JB
4488 int rem, i;
4489 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4490 struct nlattr *tx_rates;
4491 struct ieee80211_supported_band *sband;
4492
4493 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4494 return -EINVAL;
4495
4c476991
JB
4496 if (!rdev->ops->set_bitrate_mask)
4497 return -EOPNOTSUPP;
13ae75b1
JM
4498
4499 memset(&mask, 0, sizeof(mask));
4500 /* Default to all rates enabled */
4501 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4502 sband = rdev->wiphy.bands[i];
4503 mask.control[i].legacy =
4504 sband ? (1 << sband->n_bitrates) - 1 : 0;
4505 }
4506
4507 /*
4508 * The nested attribute uses enum nl80211_band as the index. This maps
4509 * directly to the enum ieee80211_band values used in cfg80211.
4510 */
4511 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4512 {
4513 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4514 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4515 return -EINVAL;
13ae75b1 4516 sband = rdev->wiphy.bands[band];
4c476991
JB
4517 if (sband == NULL)
4518 return -EINVAL;
13ae75b1
JM
4519 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4520 nla_len(tx_rates), nl80211_txattr_policy);
4521 if (tb[NL80211_TXRATE_LEGACY]) {
4522 mask.control[band].legacy = rateset_to_mask(
4523 sband,
4524 nla_data(tb[NL80211_TXRATE_LEGACY]),
4525 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4526 if (mask.control[band].legacy == 0)
4527 return -EINVAL;
13ae75b1
JM
4528 }
4529 }
4530
4c476991 4531 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4532}
4533
2e161f78 4534static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4535{
4c476991
JB
4536 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4537 struct net_device *dev = info->user_ptr[1];
2e161f78 4538 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4539
4540 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4541 return -EINVAL;
4542
2e161f78
JB
4543 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4544 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4545
9d38d85d 4546 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4547 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4548 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4549 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4550 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4551 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4552 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4553 return -EOPNOTSUPP;
026331c4
JM
4554
4555 /* not much point in registering if we can't reply */
4c476991
JB
4556 if (!rdev->ops->mgmt_tx)
4557 return -EOPNOTSUPP;
026331c4 4558
4c476991 4559 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4560 frame_type,
026331c4
JM
4561 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4562 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4563}
4564
2e161f78 4565static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4566{
4c476991
JB
4567 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4568 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4569 struct ieee80211_channel *chan;
4570 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4571 bool channel_type_valid = false;
026331c4
JM
4572 u32 freq;
4573 int err;
4574 void *hdr;
4575 u64 cookie;
4576 struct sk_buff *msg;
f7ca38df
JB
4577 unsigned int wait = 0;
4578 bool offchan;
026331c4
JM
4579
4580 if (!info->attrs[NL80211_ATTR_FRAME] ||
4581 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4582 return -EINVAL;
4583
4c476991
JB
4584 if (!rdev->ops->mgmt_tx)
4585 return -EOPNOTSUPP;
026331c4 4586
9d38d85d 4587 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4588 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4589 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4590 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4591 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4592 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4593 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4594 return -EOPNOTSUPP;
026331c4 4595
f7ca38df
JB
4596 if (info->attrs[NL80211_ATTR_DURATION]) {
4597 if (!rdev->ops->mgmt_tx_cancel_wait)
4598 return -EINVAL;
4599 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4600 }
4601
026331c4
JM
4602 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4603 channel_type = nla_get_u32(
4604 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4605 if (channel_type != NL80211_CHAN_NO_HT &&
4606 channel_type != NL80211_CHAN_HT20 &&
4607 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4608 channel_type != NL80211_CHAN_HT40MINUS)
4609 return -EINVAL;
252aa631 4610 channel_type_valid = true;
026331c4
JM
4611 }
4612
f7ca38df
JB
4613 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4614
026331c4
JM
4615 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4616 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4617 if (chan == NULL)
4618 return -EINVAL;
026331c4
JM
4619
4620 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4621 if (!msg)
4622 return -ENOMEM;
026331c4
JM
4623
4624 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4625 NL80211_CMD_FRAME);
026331c4
JM
4626
4627 if (IS_ERR(hdr)) {
4628 err = PTR_ERR(hdr);
4629 goto free_msg;
4630 }
f7ca38df
JB
4631 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4632 channel_type_valid, wait,
2e161f78
JB
4633 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4634 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4635 &cookie);
026331c4
JM
4636 if (err)
4637 goto free_msg;
4638
4639 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4640
4641 genlmsg_end(msg, hdr);
4c476991 4642 return genlmsg_reply(msg, info);
026331c4
JM
4643
4644 nla_put_failure:
4645 err = -ENOBUFS;
4646 free_msg:
4647 nlmsg_free(msg);
026331c4
JM
4648 return err;
4649}
4650
f7ca38df
JB
4651static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4652{
4653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4654 struct net_device *dev = info->user_ptr[1];
4655 u64 cookie;
4656
4657 if (!info->attrs[NL80211_ATTR_COOKIE])
4658 return -EINVAL;
4659
4660 if (!rdev->ops->mgmt_tx_cancel_wait)
4661 return -EOPNOTSUPP;
4662
4663 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4664 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4665 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4666 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4667 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4668 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4669 return -EOPNOTSUPP;
4670
4671 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4672
4673 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4674}
4675
ffb9eb3d
KV
4676static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4677{
4c476991 4678 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4679 struct wireless_dev *wdev;
4c476991 4680 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4681 u8 ps_state;
4682 bool state;
4683 int err;
4684
4c476991
JB
4685 if (!info->attrs[NL80211_ATTR_PS_STATE])
4686 return -EINVAL;
ffb9eb3d
KV
4687
4688 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4689
4c476991
JB
4690 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4691 return -EINVAL;
ffb9eb3d
KV
4692
4693 wdev = dev->ieee80211_ptr;
4694
4c476991
JB
4695 if (!rdev->ops->set_power_mgmt)
4696 return -EOPNOTSUPP;
ffb9eb3d
KV
4697
4698 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4699
4700 if (state == wdev->ps)
4c476991 4701 return 0;
ffb9eb3d 4702
4c476991
JB
4703 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4704 wdev->ps_timeout);
4705 if (!err)
4706 wdev->ps = state;
ffb9eb3d
KV
4707 return err;
4708}
4709
4710static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4711{
4c476991 4712 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4713 enum nl80211_ps_state ps_state;
4714 struct wireless_dev *wdev;
4c476991 4715 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4716 struct sk_buff *msg;
4717 void *hdr;
4718 int err;
4719
ffb9eb3d
KV
4720 wdev = dev->ieee80211_ptr;
4721
4c476991
JB
4722 if (!rdev->ops->set_power_mgmt)
4723 return -EOPNOTSUPP;
ffb9eb3d
KV
4724
4725 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4726 if (!msg)
4727 return -ENOMEM;
ffb9eb3d
KV
4728
4729 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4730 NL80211_CMD_GET_POWER_SAVE);
4731 if (!hdr) {
4c476991 4732 err = -ENOBUFS;
ffb9eb3d
KV
4733 goto free_msg;
4734 }
4735
4736 if (wdev->ps)
4737 ps_state = NL80211_PS_ENABLED;
4738 else
4739 ps_state = NL80211_PS_DISABLED;
4740
4741 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4742
4743 genlmsg_end(msg, hdr);
4c476991 4744 return genlmsg_reply(msg, info);
ffb9eb3d 4745
4c476991 4746 nla_put_failure:
ffb9eb3d 4747 err = -ENOBUFS;
4c476991 4748 free_msg:
ffb9eb3d 4749 nlmsg_free(msg);
ffb9eb3d
KV
4750 return err;
4751}
4752
d6dc1a38
JO
4753static struct nla_policy
4754nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4755 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4756 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4757 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4758};
4759
4760static int nl80211_set_cqm_rssi(struct genl_info *info,
4761 s32 threshold, u32 hysteresis)
4762{
4c476991 4763 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4764 struct wireless_dev *wdev;
4c476991 4765 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4766
4767 if (threshold > 0)
4768 return -EINVAL;
4769
d6dc1a38
JO
4770 wdev = dev->ieee80211_ptr;
4771
4c476991
JB
4772 if (!rdev->ops->set_cqm_rssi_config)
4773 return -EOPNOTSUPP;
d6dc1a38 4774
074ac8df 4775 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4776 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4777 return -EOPNOTSUPP;
d6dc1a38 4778
4c476991
JB
4779 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4780 threshold, hysteresis);
d6dc1a38
JO
4781}
4782
4783static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4784{
4785 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4786 struct nlattr *cqm;
4787 int err;
4788
4789 cqm = info->attrs[NL80211_ATTR_CQM];
4790 if (!cqm) {
4791 err = -EINVAL;
4792 goto out;
4793 }
4794
4795 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4796 nl80211_attr_cqm_policy);
4797 if (err)
4798 goto out;
4799
4800 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4801 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4802 s32 threshold;
4803 u32 hysteresis;
4804 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4805 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4806 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4807 } else
4808 err = -EINVAL;
4809
4810out:
4811 return err;
4812}
4813
29cbe68c
JB
4814static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
4815{
4816 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4817 struct net_device *dev = info->user_ptr[1];
4818 struct mesh_config cfg;
c80d545d 4819 struct mesh_setup setup;
29cbe68c
JB
4820 int err;
4821
4822 /* start with default */
4823 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 4824 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 4825
24bdd9f4 4826 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 4827 /* and parse parameters if given */
24bdd9f4 4828 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
4829 if (err)
4830 return err;
4831 }
4832
4833 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
4834 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
4835 return -EINVAL;
4836
c80d545d
JC
4837 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
4838 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4839
4840 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
4841 /* parse additional setup parameters if given */
4842 err = nl80211_parse_mesh_setup(info, &setup);
4843 if (err)
4844 return err;
4845 }
4846
4847 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
4848}
4849
4850static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
4851{
4852 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4853 struct net_device *dev = info->user_ptr[1];
4854
4855 return cfg80211_leave_mesh(rdev, dev);
4856}
4857
ff1b6e69
JB
4858static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
4859{
4860 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4861 struct sk_buff *msg;
4862 void *hdr;
4863
4864 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
4865 return -EOPNOTSUPP;
4866
4867 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4868 if (!msg)
4869 return -ENOMEM;
4870
4871 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4872 NL80211_CMD_GET_WOWLAN);
4873 if (!hdr)
4874 goto nla_put_failure;
4875
4876 if (rdev->wowlan) {
4877 struct nlattr *nl_wowlan;
4878
4879 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
4880 if (!nl_wowlan)
4881 goto nla_put_failure;
4882
4883 if (rdev->wowlan->any)
4884 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
4885 if (rdev->wowlan->disconnect)
4886 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
4887 if (rdev->wowlan->magic_pkt)
4888 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
4889 if (rdev->wowlan->n_patterns) {
4890 struct nlattr *nl_pats, *nl_pat;
4891 int i, pat_len;
4892
4893 nl_pats = nla_nest_start(msg,
4894 NL80211_WOWLAN_TRIG_PKT_PATTERN);
4895 if (!nl_pats)
4896 goto nla_put_failure;
4897
4898 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
4899 nl_pat = nla_nest_start(msg, i + 1);
4900 if (!nl_pat)
4901 goto nla_put_failure;
4902 pat_len = rdev->wowlan->patterns[i].pattern_len;
4903 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
4904 DIV_ROUND_UP(pat_len, 8),
4905 rdev->wowlan->patterns[i].mask);
4906 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
4907 pat_len,
4908 rdev->wowlan->patterns[i].pattern);
4909 nla_nest_end(msg, nl_pat);
4910 }
4911 nla_nest_end(msg, nl_pats);
4912 }
4913
4914 nla_nest_end(msg, nl_wowlan);
4915 }
4916
4917 genlmsg_end(msg, hdr);
4918 return genlmsg_reply(msg, info);
4919
4920nla_put_failure:
4921 nlmsg_free(msg);
4922 return -ENOBUFS;
4923}
4924
4925static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
4926{
4927 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4928 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
4929 struct cfg80211_wowlan no_triggers = {};
4930 struct cfg80211_wowlan new_triggers = {};
4931 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
4932 int err, i;
4933
4934 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
4935 return -EOPNOTSUPP;
4936
4937 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
4938 goto no_triggers;
4939
4940 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
4941 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
4942 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
4943 nl80211_wowlan_policy);
4944 if (err)
4945 return err;
4946
4947 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
4948 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
4949 return -EINVAL;
4950 new_triggers.any = true;
4951 }
4952
4953 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
4954 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
4955 return -EINVAL;
4956 new_triggers.disconnect = true;
4957 }
4958
4959 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
4960 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
4961 return -EINVAL;
4962 new_triggers.magic_pkt = true;
4963 }
4964
4965 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
4966 struct nlattr *pat;
4967 int n_patterns = 0;
4968 int rem, pat_len, mask_len;
4969 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
4970
4971 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
4972 rem)
4973 n_patterns++;
4974 if (n_patterns > wowlan->n_patterns)
4975 return -EINVAL;
4976
4977 new_triggers.patterns = kcalloc(n_patterns,
4978 sizeof(new_triggers.patterns[0]),
4979 GFP_KERNEL);
4980 if (!new_triggers.patterns)
4981 return -ENOMEM;
4982
4983 new_triggers.n_patterns = n_patterns;
4984 i = 0;
4985
4986 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
4987 rem) {
4988 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
4989 nla_data(pat), nla_len(pat), NULL);
4990 err = -EINVAL;
4991 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
4992 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
4993 goto error;
4994 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
4995 mask_len = DIV_ROUND_UP(pat_len, 8);
4996 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
4997 mask_len)
4998 goto error;
4999 if (pat_len > wowlan->pattern_max_len ||
5000 pat_len < wowlan->pattern_min_len)
5001 goto error;
5002
5003 new_triggers.patterns[i].mask =
5004 kmalloc(mask_len + pat_len, GFP_KERNEL);
5005 if (!new_triggers.patterns[i].mask) {
5006 err = -ENOMEM;
5007 goto error;
5008 }
5009 new_triggers.patterns[i].pattern =
5010 new_triggers.patterns[i].mask + mask_len;
5011 memcpy(new_triggers.patterns[i].mask,
5012 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
5013 mask_len);
5014 new_triggers.patterns[i].pattern_len = pat_len;
5015 memcpy(new_triggers.patterns[i].pattern,
5016 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
5017 pat_len);
5018 i++;
5019 }
5020 }
5021
5022 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
5023 struct cfg80211_wowlan *ntrig;
5024 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
5025 GFP_KERNEL);
5026 if (!ntrig) {
5027 err = -ENOMEM;
5028 goto error;
5029 }
5030 cfg80211_rdev_free_wowlan(rdev);
5031 rdev->wowlan = ntrig;
5032 } else {
5033 no_triggers:
5034 cfg80211_rdev_free_wowlan(rdev);
5035 rdev->wowlan = NULL;
5036 }
5037
5038 return 0;
5039 error:
5040 for (i = 0; i < new_triggers.n_patterns; i++)
5041 kfree(new_triggers.patterns[i].mask);
5042 kfree(new_triggers.patterns);
5043 return err;
5044}
5045
4c476991
JB
5046#define NL80211_FLAG_NEED_WIPHY 0x01
5047#define NL80211_FLAG_NEED_NETDEV 0x02
5048#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
5049#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
5050#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
5051 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
5052
5053static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
5054 struct genl_info *info)
5055{
5056 struct cfg80211_registered_device *rdev;
5057 struct net_device *dev;
5058 int err;
5059 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
5060
5061 if (rtnl)
5062 rtnl_lock();
5063
5064 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
5065 rdev = cfg80211_get_dev_from_info(info);
5066 if (IS_ERR(rdev)) {
5067 if (rtnl)
5068 rtnl_unlock();
5069 return PTR_ERR(rdev);
5070 }
5071 info->user_ptr[0] = rdev;
5072 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
5073 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5074 if (err) {
5075 if (rtnl)
5076 rtnl_unlock();
5077 return err;
5078 }
41265714
JB
5079 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
5080 !netif_running(dev)) {
d537f5fd
JB
5081 cfg80211_unlock_rdev(rdev);
5082 dev_put(dev);
41265714
JB
5083 if (rtnl)
5084 rtnl_unlock();
5085 return -ENETDOWN;
5086 }
4c476991
JB
5087 info->user_ptr[0] = rdev;
5088 info->user_ptr[1] = dev;
5089 }
5090
5091 return 0;
5092}
5093
5094static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
5095 struct genl_info *info)
5096{
5097 if (info->user_ptr[0])
5098 cfg80211_unlock_rdev(info->user_ptr[0]);
5099 if (info->user_ptr[1])
5100 dev_put(info->user_ptr[1]);
5101 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
5102 rtnl_unlock();
5103}
5104
55682965
JB
5105static struct genl_ops nl80211_ops[] = {
5106 {
5107 .cmd = NL80211_CMD_GET_WIPHY,
5108 .doit = nl80211_get_wiphy,
5109 .dumpit = nl80211_dump_wiphy,
5110 .policy = nl80211_policy,
5111 /* can be retrieved by unprivileged users */
4c476991 5112 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
5113 },
5114 {
5115 .cmd = NL80211_CMD_SET_WIPHY,
5116 .doit = nl80211_set_wiphy,
5117 .policy = nl80211_policy,
5118 .flags = GENL_ADMIN_PERM,
4c476991 5119 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
5120 },
5121 {
5122 .cmd = NL80211_CMD_GET_INTERFACE,
5123 .doit = nl80211_get_interface,
5124 .dumpit = nl80211_dump_interface,
5125 .policy = nl80211_policy,
5126 /* can be retrieved by unprivileged users */
4c476991 5127 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
5128 },
5129 {
5130 .cmd = NL80211_CMD_SET_INTERFACE,
5131 .doit = nl80211_set_interface,
5132 .policy = nl80211_policy,
5133 .flags = GENL_ADMIN_PERM,
4c476991
JB
5134 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5135 NL80211_FLAG_NEED_RTNL,
55682965
JB
5136 },
5137 {
5138 .cmd = NL80211_CMD_NEW_INTERFACE,
5139 .doit = nl80211_new_interface,
5140 .policy = nl80211_policy,
5141 .flags = GENL_ADMIN_PERM,
4c476991
JB
5142 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5143 NL80211_FLAG_NEED_RTNL,
55682965
JB
5144 },
5145 {
5146 .cmd = NL80211_CMD_DEL_INTERFACE,
5147 .doit = nl80211_del_interface,
5148 .policy = nl80211_policy,
41ade00f 5149 .flags = GENL_ADMIN_PERM,
4c476991
JB
5150 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5151 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5152 },
5153 {
5154 .cmd = NL80211_CMD_GET_KEY,
5155 .doit = nl80211_get_key,
5156 .policy = nl80211_policy,
5157 .flags = GENL_ADMIN_PERM,
4c476991
JB
5158 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5159 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5160 },
5161 {
5162 .cmd = NL80211_CMD_SET_KEY,
5163 .doit = nl80211_set_key,
5164 .policy = nl80211_policy,
5165 .flags = GENL_ADMIN_PERM,
41265714 5166 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5167 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5168 },
5169 {
5170 .cmd = NL80211_CMD_NEW_KEY,
5171 .doit = nl80211_new_key,
5172 .policy = nl80211_policy,
5173 .flags = GENL_ADMIN_PERM,
41265714 5174 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5175 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
5176 },
5177 {
5178 .cmd = NL80211_CMD_DEL_KEY,
5179 .doit = nl80211_del_key,
5180 .policy = nl80211_policy,
55682965 5181 .flags = GENL_ADMIN_PERM,
41265714 5182 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5183 NL80211_FLAG_NEED_RTNL,
55682965 5184 },
ed1b6cc7
JB
5185 {
5186 .cmd = NL80211_CMD_SET_BEACON,
5187 .policy = nl80211_policy,
5188 .flags = GENL_ADMIN_PERM,
5189 .doit = nl80211_addset_beacon,
4c476991
JB
5190 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5191 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
5192 },
5193 {
5194 .cmd = NL80211_CMD_NEW_BEACON,
5195 .policy = nl80211_policy,
5196 .flags = GENL_ADMIN_PERM,
5197 .doit = nl80211_addset_beacon,
4c476991
JB
5198 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5199 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
5200 },
5201 {
5202 .cmd = NL80211_CMD_DEL_BEACON,
5203 .policy = nl80211_policy,
5204 .flags = GENL_ADMIN_PERM,
5205 .doit = nl80211_del_beacon,
4c476991
JB
5206 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5207 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 5208 },
5727ef1b
JB
5209 {
5210 .cmd = NL80211_CMD_GET_STATION,
5211 .doit = nl80211_get_station,
2ec600d6 5212 .dumpit = nl80211_dump_station,
5727ef1b 5213 .policy = nl80211_policy,
4c476991
JB
5214 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5215 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5216 },
5217 {
5218 .cmd = NL80211_CMD_SET_STATION,
5219 .doit = nl80211_set_station,
5220 .policy = nl80211_policy,
5221 .flags = GENL_ADMIN_PERM,
4c476991
JB
5222 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5223 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5224 },
5225 {
5226 .cmd = NL80211_CMD_NEW_STATION,
5227 .doit = nl80211_new_station,
5228 .policy = nl80211_policy,
5229 .flags = GENL_ADMIN_PERM,
41265714 5230 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5231 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
5232 },
5233 {
5234 .cmd = NL80211_CMD_DEL_STATION,
5235 .doit = nl80211_del_station,
5236 .policy = nl80211_policy,
2ec600d6 5237 .flags = GENL_ADMIN_PERM,
4c476991
JB
5238 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5239 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5240 },
5241 {
5242 .cmd = NL80211_CMD_GET_MPATH,
5243 .doit = nl80211_get_mpath,
5244 .dumpit = nl80211_dump_mpath,
5245 .policy = nl80211_policy,
5246 .flags = GENL_ADMIN_PERM,
41265714 5247 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5248 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5249 },
5250 {
5251 .cmd = NL80211_CMD_SET_MPATH,
5252 .doit = nl80211_set_mpath,
5253 .policy = nl80211_policy,
5254 .flags = GENL_ADMIN_PERM,
41265714 5255 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5256 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5257 },
5258 {
5259 .cmd = NL80211_CMD_NEW_MPATH,
5260 .doit = nl80211_new_mpath,
5261 .policy = nl80211_policy,
5262 .flags = GENL_ADMIN_PERM,
41265714 5263 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5264 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
5265 },
5266 {
5267 .cmd = NL80211_CMD_DEL_MPATH,
5268 .doit = nl80211_del_mpath,
5269 .policy = nl80211_policy,
9f1ba906 5270 .flags = GENL_ADMIN_PERM,
4c476991
JB
5271 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5272 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
5273 },
5274 {
5275 .cmd = NL80211_CMD_SET_BSS,
5276 .doit = nl80211_set_bss,
5277 .policy = nl80211_policy,
b2e1b302 5278 .flags = GENL_ADMIN_PERM,
4c476991
JB
5279 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5280 NL80211_FLAG_NEED_RTNL,
b2e1b302 5281 },
f130347c
LR
5282 {
5283 .cmd = NL80211_CMD_GET_REG,
5284 .doit = nl80211_get_reg,
5285 .policy = nl80211_policy,
5286 /* can be retrieved by unprivileged users */
5287 },
b2e1b302
LR
5288 {
5289 .cmd = NL80211_CMD_SET_REG,
5290 .doit = nl80211_set_reg,
5291 .policy = nl80211_policy,
5292 .flags = GENL_ADMIN_PERM,
5293 },
5294 {
5295 .cmd = NL80211_CMD_REQ_SET_REG,
5296 .doit = nl80211_req_set_reg,
5297 .policy = nl80211_policy,
93da9cc1 5298 .flags = GENL_ADMIN_PERM,
5299 },
5300 {
24bdd9f4
JC
5301 .cmd = NL80211_CMD_GET_MESH_CONFIG,
5302 .doit = nl80211_get_mesh_config,
93da9cc1 5303 .policy = nl80211_policy,
5304 /* can be retrieved by unprivileged users */
4c476991
JB
5305 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5306 NL80211_FLAG_NEED_RTNL,
93da9cc1 5307 },
5308 {
24bdd9f4
JC
5309 .cmd = NL80211_CMD_SET_MESH_CONFIG,
5310 .doit = nl80211_update_mesh_config,
93da9cc1 5311 .policy = nl80211_policy,
9aed3cc1 5312 .flags = GENL_ADMIN_PERM,
29cbe68c 5313 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5314 NL80211_FLAG_NEED_RTNL,
9aed3cc1 5315 },
2a519311
JB
5316 {
5317 .cmd = NL80211_CMD_TRIGGER_SCAN,
5318 .doit = nl80211_trigger_scan,
5319 .policy = nl80211_policy,
5320 .flags = GENL_ADMIN_PERM,
41265714 5321 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5322 NL80211_FLAG_NEED_RTNL,
2a519311
JB
5323 },
5324 {
5325 .cmd = NL80211_CMD_GET_SCAN,
5326 .policy = nl80211_policy,
5327 .dumpit = nl80211_dump_scan,
5328 },
636a5d36
JM
5329 {
5330 .cmd = NL80211_CMD_AUTHENTICATE,
5331 .doit = nl80211_authenticate,
5332 .policy = nl80211_policy,
5333 .flags = GENL_ADMIN_PERM,
41265714 5334 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5335 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5336 },
5337 {
5338 .cmd = NL80211_CMD_ASSOCIATE,
5339 .doit = nl80211_associate,
5340 .policy = nl80211_policy,
5341 .flags = GENL_ADMIN_PERM,
41265714 5342 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5343 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5344 },
5345 {
5346 .cmd = NL80211_CMD_DEAUTHENTICATE,
5347 .doit = nl80211_deauthenticate,
5348 .policy = nl80211_policy,
5349 .flags = GENL_ADMIN_PERM,
41265714 5350 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5351 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5352 },
5353 {
5354 .cmd = NL80211_CMD_DISASSOCIATE,
5355 .doit = nl80211_disassociate,
5356 .policy = nl80211_policy,
5357 .flags = GENL_ADMIN_PERM,
41265714 5358 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5359 NL80211_FLAG_NEED_RTNL,
636a5d36 5360 },
04a773ad
JB
5361 {
5362 .cmd = NL80211_CMD_JOIN_IBSS,
5363 .doit = nl80211_join_ibss,
5364 .policy = nl80211_policy,
5365 .flags = GENL_ADMIN_PERM,
41265714 5366 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5367 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
5368 },
5369 {
5370 .cmd = NL80211_CMD_LEAVE_IBSS,
5371 .doit = nl80211_leave_ibss,
5372 .policy = nl80211_policy,
5373 .flags = GENL_ADMIN_PERM,
41265714 5374 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5375 NL80211_FLAG_NEED_RTNL,
04a773ad 5376 },
aff89a9b
JB
5377#ifdef CONFIG_NL80211_TESTMODE
5378 {
5379 .cmd = NL80211_CMD_TESTMODE,
5380 .doit = nl80211_testmode_do,
5381 .policy = nl80211_policy,
5382 .flags = GENL_ADMIN_PERM,
4c476991
JB
5383 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5384 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
5385 },
5386#endif
b23aa676
SO
5387 {
5388 .cmd = NL80211_CMD_CONNECT,
5389 .doit = nl80211_connect,
5390 .policy = nl80211_policy,
5391 .flags = GENL_ADMIN_PERM,
41265714 5392 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5393 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
5394 },
5395 {
5396 .cmd = NL80211_CMD_DISCONNECT,
5397 .doit = nl80211_disconnect,
5398 .policy = nl80211_policy,
5399 .flags = GENL_ADMIN_PERM,
41265714 5400 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5401 NL80211_FLAG_NEED_RTNL,
b23aa676 5402 },
463d0183
JB
5403 {
5404 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5405 .doit = nl80211_wiphy_netns,
5406 .policy = nl80211_policy,
5407 .flags = GENL_ADMIN_PERM,
4c476991
JB
5408 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5409 NL80211_FLAG_NEED_RTNL,
463d0183 5410 },
61fa713c
HS
5411 {
5412 .cmd = NL80211_CMD_GET_SURVEY,
5413 .policy = nl80211_policy,
5414 .dumpit = nl80211_dump_survey,
5415 },
67fbb16b
SO
5416 {
5417 .cmd = NL80211_CMD_SET_PMKSA,
5418 .doit = nl80211_setdel_pmksa,
5419 .policy = nl80211_policy,
5420 .flags = GENL_ADMIN_PERM,
4c476991
JB
5421 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5422 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5423 },
5424 {
5425 .cmd = NL80211_CMD_DEL_PMKSA,
5426 .doit = nl80211_setdel_pmksa,
5427 .policy = nl80211_policy,
5428 .flags = GENL_ADMIN_PERM,
4c476991
JB
5429 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5430 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5431 },
5432 {
5433 .cmd = NL80211_CMD_FLUSH_PMKSA,
5434 .doit = nl80211_flush_pmksa,
5435 .policy = nl80211_policy,
5436 .flags = GENL_ADMIN_PERM,
4c476991
JB
5437 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5438 NL80211_FLAG_NEED_RTNL,
67fbb16b 5439 },
9588bbd5
JM
5440 {
5441 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5442 .doit = nl80211_remain_on_channel,
5443 .policy = nl80211_policy,
5444 .flags = GENL_ADMIN_PERM,
41265714 5445 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5446 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
5447 },
5448 {
5449 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5450 .doit = nl80211_cancel_remain_on_channel,
5451 .policy = nl80211_policy,
5452 .flags = GENL_ADMIN_PERM,
41265714 5453 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5454 NL80211_FLAG_NEED_RTNL,
9588bbd5 5455 },
13ae75b1
JM
5456 {
5457 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5458 .doit = nl80211_set_tx_bitrate_mask,
5459 .policy = nl80211_policy,
5460 .flags = GENL_ADMIN_PERM,
4c476991
JB
5461 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5462 NL80211_FLAG_NEED_RTNL,
13ae75b1 5463 },
026331c4 5464 {
2e161f78
JB
5465 .cmd = NL80211_CMD_REGISTER_FRAME,
5466 .doit = nl80211_register_mgmt,
026331c4
JM
5467 .policy = nl80211_policy,
5468 .flags = GENL_ADMIN_PERM,
4c476991
JB
5469 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5470 NL80211_FLAG_NEED_RTNL,
026331c4
JM
5471 },
5472 {
2e161f78
JB
5473 .cmd = NL80211_CMD_FRAME,
5474 .doit = nl80211_tx_mgmt,
026331c4 5475 .policy = nl80211_policy,
f7ca38df
JB
5476 .flags = GENL_ADMIN_PERM,
5477 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5478 NL80211_FLAG_NEED_RTNL,
5479 },
5480 {
5481 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5482 .doit = nl80211_tx_mgmt_cancel_wait,
5483 .policy = nl80211_policy,
026331c4 5484 .flags = GENL_ADMIN_PERM,
41265714 5485 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5486 NL80211_FLAG_NEED_RTNL,
026331c4 5487 },
ffb9eb3d
KV
5488 {
5489 .cmd = NL80211_CMD_SET_POWER_SAVE,
5490 .doit = nl80211_set_power_save,
5491 .policy = nl80211_policy,
5492 .flags = GENL_ADMIN_PERM,
4c476991
JB
5493 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5494 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
5495 },
5496 {
5497 .cmd = NL80211_CMD_GET_POWER_SAVE,
5498 .doit = nl80211_get_power_save,
5499 .policy = nl80211_policy,
5500 /* can be retrieved by unprivileged users */
4c476991
JB
5501 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5502 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 5503 },
d6dc1a38
JO
5504 {
5505 .cmd = NL80211_CMD_SET_CQM,
5506 .doit = nl80211_set_cqm,
5507 .policy = nl80211_policy,
5508 .flags = GENL_ADMIN_PERM,
4c476991
JB
5509 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5510 NL80211_FLAG_NEED_RTNL,
d6dc1a38 5511 },
f444de05
JB
5512 {
5513 .cmd = NL80211_CMD_SET_CHANNEL,
5514 .doit = nl80211_set_channel,
5515 .policy = nl80211_policy,
5516 .flags = GENL_ADMIN_PERM,
4c476991
JB
5517 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5518 NL80211_FLAG_NEED_RTNL,
f444de05 5519 },
e8347eba
BJ
5520 {
5521 .cmd = NL80211_CMD_SET_WDS_PEER,
5522 .doit = nl80211_set_wds_peer,
5523 .policy = nl80211_policy,
5524 .flags = GENL_ADMIN_PERM,
43b19952
JB
5525 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5526 NL80211_FLAG_NEED_RTNL,
e8347eba 5527 },
29cbe68c
JB
5528 {
5529 .cmd = NL80211_CMD_JOIN_MESH,
5530 .doit = nl80211_join_mesh,
5531 .policy = nl80211_policy,
5532 .flags = GENL_ADMIN_PERM,
5533 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5534 NL80211_FLAG_NEED_RTNL,
5535 },
5536 {
5537 .cmd = NL80211_CMD_LEAVE_MESH,
5538 .doit = nl80211_leave_mesh,
5539 .policy = nl80211_policy,
5540 .flags = GENL_ADMIN_PERM,
5541 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5542 NL80211_FLAG_NEED_RTNL,
5543 },
ff1b6e69
JB
5544 {
5545 .cmd = NL80211_CMD_GET_WOWLAN,
5546 .doit = nl80211_get_wowlan,
5547 .policy = nl80211_policy,
5548 /* can be retrieved by unprivileged users */
5549 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5550 NL80211_FLAG_NEED_RTNL,
5551 },
5552 {
5553 .cmd = NL80211_CMD_SET_WOWLAN,
5554 .doit = nl80211_set_wowlan,
5555 .policy = nl80211_policy,
5556 .flags = GENL_ADMIN_PERM,
5557 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5558 NL80211_FLAG_NEED_RTNL,
5559 },
55682965 5560};
9588bbd5 5561
6039f6d2
JM
5562static struct genl_multicast_group nl80211_mlme_mcgrp = {
5563 .name = "mlme",
5564};
55682965
JB
5565
5566/* multicast groups */
5567static struct genl_multicast_group nl80211_config_mcgrp = {
5568 .name = "config",
5569};
2a519311
JB
5570static struct genl_multicast_group nl80211_scan_mcgrp = {
5571 .name = "scan",
5572};
73d54c9e
LR
5573static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5574 .name = "regulatory",
5575};
55682965
JB
5576
5577/* notification functions */
5578
5579void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5580{
5581 struct sk_buff *msg;
5582
fd2120ca 5583 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5584 if (!msg)
5585 return;
5586
5587 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5588 nlmsg_free(msg);
5589 return;
5590 }
5591
463d0183
JB
5592 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5593 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5594}
5595
362a415d
JB
5596static int nl80211_add_scan_req(struct sk_buff *msg,
5597 struct cfg80211_registered_device *rdev)
5598{
5599 struct cfg80211_scan_request *req = rdev->scan_req;
5600 struct nlattr *nest;
5601 int i;
5602
667503dd
JB
5603 ASSERT_RDEV_LOCK(rdev);
5604
362a415d
JB
5605 if (WARN_ON(!req))
5606 return 0;
5607
5608 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5609 if (!nest)
5610 goto nla_put_failure;
5611 for (i = 0; i < req->n_ssids; i++)
5612 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5613 nla_nest_end(msg, nest);
5614
5615 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5616 if (!nest)
5617 goto nla_put_failure;
5618 for (i = 0; i < req->n_channels; i++)
5619 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5620 nla_nest_end(msg, nest);
5621
5622 if (req->ie)
5623 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5624
5625 return 0;
5626 nla_put_failure:
5627 return -ENOBUFS;
5628}
5629
a538e2d5
JB
5630static int nl80211_send_scan_msg(struct sk_buff *msg,
5631 struct cfg80211_registered_device *rdev,
5632 struct net_device *netdev,
5633 u32 pid, u32 seq, int flags,
5634 u32 cmd)
2a519311
JB
5635{
5636 void *hdr;
5637
5638 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5639 if (!hdr)
5640 return -1;
5641
b5850a7a 5642 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5643 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5644
362a415d
JB
5645 /* ignore errors and send incomplete event anyway */
5646 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5647
5648 return genlmsg_end(msg, hdr);
5649
5650 nla_put_failure:
5651 genlmsg_cancel(msg, hdr);
5652 return -EMSGSIZE;
5653}
5654
a538e2d5
JB
5655void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5656 struct net_device *netdev)
5657{
5658 struct sk_buff *msg;
5659
5660 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5661 if (!msg)
5662 return;
5663
5664 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5665 NL80211_CMD_TRIGGER_SCAN) < 0) {
5666 nlmsg_free(msg);
5667 return;
5668 }
5669
463d0183
JB
5670 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5671 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5672}
5673
2a519311
JB
5674void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5675 struct net_device *netdev)
5676{
5677 struct sk_buff *msg;
5678
fd2120ca 5679 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5680 if (!msg)
5681 return;
5682
a538e2d5
JB
5683 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5684 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5685 nlmsg_free(msg);
5686 return;
5687 }
5688
463d0183
JB
5689 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5690 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5691}
5692
5693void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5694 struct net_device *netdev)
5695{
5696 struct sk_buff *msg;
5697
fd2120ca 5698 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5699 if (!msg)
5700 return;
5701
a538e2d5
JB
5702 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5703 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5704 nlmsg_free(msg);
5705 return;
5706 }
5707
463d0183
JB
5708 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5709 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5710}
5711
73d54c9e
LR
5712/*
5713 * This can happen on global regulatory changes or device specific settings
5714 * based on custom world regulatory domains.
5715 */
5716void nl80211_send_reg_change_event(struct regulatory_request *request)
5717{
5718 struct sk_buff *msg;
5719 void *hdr;
5720
fd2120ca 5721 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5722 if (!msg)
5723 return;
5724
5725 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5726 if (!hdr) {
5727 nlmsg_free(msg);
5728 return;
5729 }
5730
5731 /* Userspace can always count this one always being set */
5732 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5733
5734 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5735 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5736 NL80211_REGDOM_TYPE_WORLD);
5737 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5738 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5739 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5740 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5741 request->intersect)
5742 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5743 NL80211_REGDOM_TYPE_INTERSECTION);
5744 else {
5745 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5746 NL80211_REGDOM_TYPE_COUNTRY);
5747 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5748 }
5749
5750 if (wiphy_idx_valid(request->wiphy_idx))
5751 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5752
5753 if (genlmsg_end(msg, hdr) < 0) {
5754 nlmsg_free(msg);
5755 return;
5756 }
5757
bc43b28c 5758 rcu_read_lock();
463d0183 5759 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5760 GFP_ATOMIC);
5761 rcu_read_unlock();
73d54c9e
LR
5762
5763 return;
5764
5765nla_put_failure:
5766 genlmsg_cancel(msg, hdr);
5767 nlmsg_free(msg);
5768}
5769
6039f6d2
JM
5770static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5771 struct net_device *netdev,
5772 const u8 *buf, size_t len,
e6d6e342 5773 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5774{
5775 struct sk_buff *msg;
5776 void *hdr;
5777
e6d6e342 5778 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5779 if (!msg)
5780 return;
5781
5782 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5783 if (!hdr) {
5784 nlmsg_free(msg);
5785 return;
5786 }
5787
5788 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5789 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5790 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5791
5792 if (genlmsg_end(msg, hdr) < 0) {
5793 nlmsg_free(msg);
5794 return;
5795 }
5796
463d0183
JB
5797 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5798 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5799 return;
5800
5801 nla_put_failure:
5802 genlmsg_cancel(msg, hdr);
5803 nlmsg_free(msg);
5804}
5805
5806void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5807 struct net_device *netdev, const u8 *buf,
5808 size_t len, gfp_t gfp)
6039f6d2
JM
5809{
5810 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5811 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5812}
5813
5814void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5815 struct net_device *netdev, const u8 *buf,
e6d6e342 5816 size_t len, gfp_t gfp)
6039f6d2 5817{
e6d6e342
JB
5818 nl80211_send_mlme_event(rdev, netdev, buf, len,
5819 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5820}
5821
53b46b84 5822void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5823 struct net_device *netdev, const u8 *buf,
5824 size_t len, gfp_t gfp)
6039f6d2
JM
5825{
5826 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5827 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5828}
5829
53b46b84
JM
5830void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5831 struct net_device *netdev, const u8 *buf,
e6d6e342 5832 size_t len, gfp_t gfp)
6039f6d2
JM
5833{
5834 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5835 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5836}
5837
cf4e594e
JM
5838void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
5839 struct net_device *netdev, const u8 *buf,
5840 size_t len, gfp_t gfp)
5841{
5842 nl80211_send_mlme_event(rdev, netdev, buf, len,
5843 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
5844}
5845
5846void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
5847 struct net_device *netdev, const u8 *buf,
5848 size_t len, gfp_t gfp)
5849{
5850 nl80211_send_mlme_event(rdev, netdev, buf, len,
5851 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
5852}
5853
1b06bb40
LR
5854static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5855 struct net_device *netdev, int cmd,
e6d6e342 5856 const u8 *addr, gfp_t gfp)
1965c853
JM
5857{
5858 struct sk_buff *msg;
5859 void *hdr;
5860
e6d6e342 5861 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5862 if (!msg)
5863 return;
5864
5865 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5866 if (!hdr) {
5867 nlmsg_free(msg);
5868 return;
5869 }
5870
5871 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5872 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5873 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5874 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5875
5876 if (genlmsg_end(msg, hdr) < 0) {
5877 nlmsg_free(msg);
5878 return;
5879 }
5880
463d0183
JB
5881 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5882 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5883 return;
5884
5885 nla_put_failure:
5886 genlmsg_cancel(msg, hdr);
5887 nlmsg_free(msg);
5888}
5889
5890void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5891 struct net_device *netdev, const u8 *addr,
5892 gfp_t gfp)
1965c853
JM
5893{
5894 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5895 addr, gfp);
1965c853
JM
5896}
5897
5898void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5899 struct net_device *netdev, const u8 *addr,
5900 gfp_t gfp)
1965c853 5901{
e6d6e342
JB
5902 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5903 addr, gfp);
1965c853
JM
5904}
5905
b23aa676
SO
5906void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5907 struct net_device *netdev, const u8 *bssid,
5908 const u8 *req_ie, size_t req_ie_len,
5909 const u8 *resp_ie, size_t resp_ie_len,
5910 u16 status, gfp_t gfp)
5911{
5912 struct sk_buff *msg;
5913 void *hdr;
5914
5915 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5916 if (!msg)
5917 return;
5918
5919 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5920 if (!hdr) {
5921 nlmsg_free(msg);
5922 return;
5923 }
5924
5925 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5926 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5927 if (bssid)
5928 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5929 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5930 if (req_ie)
5931 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5932 if (resp_ie)
5933 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5934
5935 if (genlmsg_end(msg, hdr) < 0) {
5936 nlmsg_free(msg);
5937 return;
5938 }
5939
463d0183
JB
5940 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5941 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5942 return;
5943
5944 nla_put_failure:
5945 genlmsg_cancel(msg, hdr);
5946 nlmsg_free(msg);
5947
5948}
5949
5950void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5951 struct net_device *netdev, const u8 *bssid,
5952 const u8 *req_ie, size_t req_ie_len,
5953 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5954{
5955 struct sk_buff *msg;
5956 void *hdr;
5957
5958 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5959 if (!msg)
5960 return;
5961
5962 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5963 if (!hdr) {
5964 nlmsg_free(msg);
5965 return;
5966 }
5967
5968 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5969 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5970 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5971 if (req_ie)
5972 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5973 if (resp_ie)
5974 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5975
5976 if (genlmsg_end(msg, hdr) < 0) {
5977 nlmsg_free(msg);
5978 return;
5979 }
5980
463d0183
JB
5981 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5982 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5983 return;
5984
5985 nla_put_failure:
5986 genlmsg_cancel(msg, hdr);
5987 nlmsg_free(msg);
5988
5989}
5990
5991void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5992 struct net_device *netdev, u16 reason,
667503dd 5993 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5994{
5995 struct sk_buff *msg;
5996 void *hdr;
5997
667503dd 5998 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5999 if (!msg)
6000 return;
6001
6002 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
6003 if (!hdr) {
6004 nlmsg_free(msg);
6005 return;
6006 }
6007
6008 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6009 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6010 if (from_ap && reason)
6011 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
6012 if (from_ap)
6013 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
6014 if (ie)
6015 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
6016
6017 if (genlmsg_end(msg, hdr) < 0) {
6018 nlmsg_free(msg);
6019 return;
6020 }
6021
463d0183
JB
6022 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6023 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
6024 return;
6025
6026 nla_put_failure:
6027 genlmsg_cancel(msg, hdr);
6028 nlmsg_free(msg);
6029
6030}
6031
04a773ad
JB
6032void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
6033 struct net_device *netdev, const u8 *bssid,
6034 gfp_t gfp)
6035{
6036 struct sk_buff *msg;
6037 void *hdr;
6038
fd2120ca 6039 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
6040 if (!msg)
6041 return;
6042
6043 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
6044 if (!hdr) {
6045 nlmsg_free(msg);
6046 return;
6047 }
6048
6049 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6050 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6051 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6052
6053 if (genlmsg_end(msg, hdr) < 0) {
6054 nlmsg_free(msg);
6055 return;
6056 }
6057
463d0183
JB
6058 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6059 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
6060 return;
6061
6062 nla_put_failure:
6063 genlmsg_cancel(msg, hdr);
6064 nlmsg_free(msg);
6065}
6066
c93b5e71
JC
6067void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
6068 struct net_device *netdev,
6069 const u8 *macaddr, const u8* ie, u8 ie_len,
6070 gfp_t gfp)
6071{
6072 struct sk_buff *msg;
6073 void *hdr;
6074
6075 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6076 if (!msg)
6077 return;
6078
6079 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
6080 if (!hdr) {
6081 nlmsg_free(msg);
6082 return;
6083 }
6084
6085 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6086 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6087 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
6088 if (ie_len && ie)
6089 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
6090
6091 if (genlmsg_end(msg, hdr) < 0) {
6092 nlmsg_free(msg);
6093 return;
6094 }
6095
6096 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6097 nl80211_mlme_mcgrp.id, gfp);
6098 return;
6099
6100 nla_put_failure:
6101 genlmsg_cancel(msg, hdr);
6102 nlmsg_free(msg);
6103}
6104
a3b8b056
JM
6105void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
6106 struct net_device *netdev, const u8 *addr,
6107 enum nl80211_key_type key_type, int key_id,
e6d6e342 6108 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
6109{
6110 struct sk_buff *msg;
6111 void *hdr;
6112
e6d6e342 6113 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
6114 if (!msg)
6115 return;
6116
6117 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
6118 if (!hdr) {
6119 nlmsg_free(msg);
6120 return;
6121 }
6122
6123 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6124 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6125 if (addr)
6126 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6127 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
6128 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
6129 if (tsc)
6130 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
6131
6132 if (genlmsg_end(msg, hdr) < 0) {
6133 nlmsg_free(msg);
6134 return;
6135 }
6136
463d0183
JB
6137 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6138 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
6139 return;
6140
6141 nla_put_failure:
6142 genlmsg_cancel(msg, hdr);
6143 nlmsg_free(msg);
6144}
6145
6bad8766
LR
6146void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
6147 struct ieee80211_channel *channel_before,
6148 struct ieee80211_channel *channel_after)
6149{
6150 struct sk_buff *msg;
6151 void *hdr;
6152 struct nlattr *nl_freq;
6153
fd2120ca 6154 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
6155 if (!msg)
6156 return;
6157
6158 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
6159 if (!hdr) {
6160 nlmsg_free(msg);
6161 return;
6162 }
6163
6164 /*
6165 * Since we are applying the beacon hint to a wiphy we know its
6166 * wiphy_idx is valid
6167 */
6168 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
6169
6170 /* Before */
6171 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
6172 if (!nl_freq)
6173 goto nla_put_failure;
6174 if (nl80211_msg_put_channel(msg, channel_before))
6175 goto nla_put_failure;
6176 nla_nest_end(msg, nl_freq);
6177
6178 /* After */
6179 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
6180 if (!nl_freq)
6181 goto nla_put_failure;
6182 if (nl80211_msg_put_channel(msg, channel_after))
6183 goto nla_put_failure;
6184 nla_nest_end(msg, nl_freq);
6185
6186 if (genlmsg_end(msg, hdr) < 0) {
6187 nlmsg_free(msg);
6188 return;
6189 }
6190
463d0183
JB
6191 rcu_read_lock();
6192 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6193 GFP_ATOMIC);
6194 rcu_read_unlock();
6bad8766
LR
6195
6196 return;
6197
6198nla_put_failure:
6199 genlmsg_cancel(msg, hdr);
6200 nlmsg_free(msg);
6201}
6202
9588bbd5
JM
6203static void nl80211_send_remain_on_chan_event(
6204 int cmd, struct cfg80211_registered_device *rdev,
6205 struct net_device *netdev, u64 cookie,
6206 struct ieee80211_channel *chan,
6207 enum nl80211_channel_type channel_type,
6208 unsigned int duration, gfp_t gfp)
6209{
6210 struct sk_buff *msg;
6211 void *hdr;
6212
6213 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6214 if (!msg)
6215 return;
6216
6217 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6218 if (!hdr) {
6219 nlmsg_free(msg);
6220 return;
6221 }
6222
6223 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6224 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6225 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
6226 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
6227 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6228
6229 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6230 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6231
6232 if (genlmsg_end(msg, hdr) < 0) {
6233 nlmsg_free(msg);
6234 return;
6235 }
6236
6237 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6238 nl80211_mlme_mcgrp.id, gfp);
6239 return;
6240
6241 nla_put_failure:
6242 genlmsg_cancel(msg, hdr);
6243 nlmsg_free(msg);
6244}
6245
6246void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6247 struct net_device *netdev, u64 cookie,
6248 struct ieee80211_channel *chan,
6249 enum nl80211_channel_type channel_type,
6250 unsigned int duration, gfp_t gfp)
6251{
6252 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6253 rdev, netdev, cookie, chan,
6254 channel_type, duration, gfp);
6255}
6256
6257void nl80211_send_remain_on_channel_cancel(
6258 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6259 u64 cookie, struct ieee80211_channel *chan,
6260 enum nl80211_channel_type channel_type, gfp_t gfp)
6261{
6262 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6263 rdev, netdev, cookie, chan,
6264 channel_type, 0, gfp);
6265}
6266
98b62183
JB
6267void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6268 struct net_device *dev, const u8 *mac_addr,
6269 struct station_info *sinfo, gfp_t gfp)
6270{
6271 struct sk_buff *msg;
6272
6273 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6274 if (!msg)
6275 return;
6276
6277 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6278 nlmsg_free(msg);
6279 return;
6280 }
6281
6282 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6283 nl80211_mlme_mcgrp.id, gfp);
6284}
6285
ec15e68b
JM
6286void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
6287 struct net_device *dev, const u8 *mac_addr,
6288 gfp_t gfp)
6289{
6290 struct sk_buff *msg;
6291 void *hdr;
6292
6293 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6294 if (!msg)
6295 return;
6296
6297 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
6298 if (!hdr) {
6299 nlmsg_free(msg);
6300 return;
6301 }
6302
6303 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
6304 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
6305
6306 if (genlmsg_end(msg, hdr) < 0) {
6307 nlmsg_free(msg);
6308 return;
6309 }
6310
6311 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6312 nl80211_mlme_mcgrp.id, gfp);
6313 return;
6314
6315 nla_put_failure:
6316 genlmsg_cancel(msg, hdr);
6317 nlmsg_free(msg);
6318}
6319
2e161f78
JB
6320int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6321 struct net_device *netdev, u32 nlpid,
6322 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
6323{
6324 struct sk_buff *msg;
6325 void *hdr;
6326 int err;
6327
6328 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6329 if (!msg)
6330 return -ENOMEM;
6331
2e161f78 6332 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
6333 if (!hdr) {
6334 nlmsg_free(msg);
6335 return -ENOMEM;
6336 }
6337
6338 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6339 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6340 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6341 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6342
6343 err = genlmsg_end(msg, hdr);
6344 if (err < 0) {
6345 nlmsg_free(msg);
6346 return err;
6347 }
6348
6349 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6350 if (err < 0)
6351 return err;
6352 return 0;
6353
6354 nla_put_failure:
6355 genlmsg_cancel(msg, hdr);
6356 nlmsg_free(msg);
6357 return -ENOBUFS;
6358}
6359
2e161f78
JB
6360void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6361 struct net_device *netdev, u64 cookie,
6362 const u8 *buf, size_t len, bool ack,
6363 gfp_t gfp)
026331c4
JM
6364{
6365 struct sk_buff *msg;
6366 void *hdr;
6367
6368 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6369 if (!msg)
6370 return;
6371
2e161f78 6372 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6373 if (!hdr) {
6374 nlmsg_free(msg);
6375 return;
6376 }
6377
6378 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6379 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6380 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6381 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6382 if (ack)
6383 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6384
6385 if (genlmsg_end(msg, hdr) < 0) {
6386 nlmsg_free(msg);
6387 return;
6388 }
6389
6390 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6391 return;
6392
6393 nla_put_failure:
6394 genlmsg_cancel(msg, hdr);
6395 nlmsg_free(msg);
6396}
6397
d6dc1a38
JO
6398void
6399nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6400 struct net_device *netdev,
6401 enum nl80211_cqm_rssi_threshold_event rssi_event,
6402 gfp_t gfp)
6403{
6404 struct sk_buff *msg;
6405 struct nlattr *pinfoattr;
6406 void *hdr;
6407
6408 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6409 if (!msg)
6410 return;
6411
6412 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6413 if (!hdr) {
6414 nlmsg_free(msg);
6415 return;
6416 }
6417
6418 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6419 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6420
6421 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6422 if (!pinfoattr)
6423 goto nla_put_failure;
6424
6425 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6426 rssi_event);
6427
6428 nla_nest_end(msg, pinfoattr);
6429
6430 if (genlmsg_end(msg, hdr) < 0) {
6431 nlmsg_free(msg);
6432 return;
6433 }
6434
6435 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6436 nl80211_mlme_mcgrp.id, gfp);
6437 return;
6438
6439 nla_put_failure:
6440 genlmsg_cancel(msg, hdr);
6441 nlmsg_free(msg);
6442}
6443
c063dbf5
JB
6444void
6445nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6446 struct net_device *netdev, const u8 *peer,
6447 u32 num_packets, gfp_t gfp)
6448{
6449 struct sk_buff *msg;
6450 struct nlattr *pinfoattr;
6451 void *hdr;
6452
6453 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6454 if (!msg)
6455 return;
6456
6457 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6458 if (!hdr) {
6459 nlmsg_free(msg);
6460 return;
6461 }
6462
6463 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6464 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6465 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6466
6467 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6468 if (!pinfoattr)
6469 goto nla_put_failure;
6470
6471 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6472
6473 nla_nest_end(msg, pinfoattr);
6474
6475 if (genlmsg_end(msg, hdr) < 0) {
6476 nlmsg_free(msg);
6477 return;
6478 }
6479
6480 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6481 nl80211_mlme_mcgrp.id, gfp);
6482 return;
6483
6484 nla_put_failure:
6485 genlmsg_cancel(msg, hdr);
6486 nlmsg_free(msg);
6487}
6488
026331c4
JM
6489static int nl80211_netlink_notify(struct notifier_block * nb,
6490 unsigned long state,
6491 void *_notify)
6492{
6493 struct netlink_notify *notify = _notify;
6494 struct cfg80211_registered_device *rdev;
6495 struct wireless_dev *wdev;
6496
6497 if (state != NETLINK_URELEASE)
6498 return NOTIFY_DONE;
6499
6500 rcu_read_lock();
6501
6502 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6503 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6504 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6505
6506 rcu_read_unlock();
6507
6508 return NOTIFY_DONE;
6509}
6510
6511static struct notifier_block nl80211_netlink_notifier = {
6512 .notifier_call = nl80211_netlink_notify,
6513};
6514
55682965
JB
6515/* initialisation/exit functions */
6516
6517int nl80211_init(void)
6518{
0d63cbb5 6519 int err;
55682965 6520
0d63cbb5
MM
6521 err = genl_register_family_with_ops(&nl80211_fam,
6522 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6523 if (err)
6524 return err;
6525
55682965
JB
6526 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6527 if (err)
6528 goto err_out;
6529
2a519311
JB
6530 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6531 if (err)
6532 goto err_out;
6533
73d54c9e
LR
6534 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6535 if (err)
6536 goto err_out;
6537
6039f6d2
JM
6538 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6539 if (err)
6540 goto err_out;
6541
aff89a9b
JB
6542#ifdef CONFIG_NL80211_TESTMODE
6543 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6544 if (err)
6545 goto err_out;
6546#endif
6547
026331c4
JM
6548 err = netlink_register_notifier(&nl80211_netlink_notifier);
6549 if (err)
6550 goto err_out;
6551
55682965
JB
6552 return 0;
6553 err_out:
6554 genl_unregister_family(&nl80211_fam);
6555 return err;
6556}
6557
6558void nl80211_exit(void)
6559{
026331c4 6560 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6561 genl_unregister_family(&nl80211_fam);
6562}