]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: remove unused don't-encrypt flag
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965
JB
25
26/* the netlink family */
27static struct genl_family nl80211_fam = {
28 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
29 .name = "nl80211", /* have users key off the name instead */
30 .hdrsize = 0, /* no private header */
31 .version = 1, /* no particular meaning now */
32 .maxattr = NL80211_ATTR_MAX,
463d0183 33 .netnsok = true,
55682965
JB
34};
35
79c97e97 36/* internal helper: get rdev and dev */
463d0183 37static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 38 struct cfg80211_registered_device **rdev,
55682965
JB
39 struct net_device **dev)
40{
463d0183 41 struct nlattr **attrs = info->attrs;
55682965
JB
42 int ifindex;
43
bba95fef 44 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
45 return -EINVAL;
46
bba95fef 47 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 48 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
49 if (!*dev)
50 return -ENODEV;
51
463d0183 52 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 53 if (IS_ERR(*rdev)) {
55682965 54 dev_put(*dev);
79c97e97 55 return PTR_ERR(*rdev);
55682965
JB
56 }
57
58 return 0;
59}
60
61/* policy for the attributes */
b54452b0 62static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
63 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
64 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 65 .len = 20-1 },
31888487 66 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 67 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 68 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
69 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
71 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
72 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 73 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
74
75 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
76 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
77 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
78
79 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 80 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 81
b9454e83 82 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
83 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
84 .len = WLAN_MAX_KEY_LEN },
85 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
86 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
87 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 88 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
89
90 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
91 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
92 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
95 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
96 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
98 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
99 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
100 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 101 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 102 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 103 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
104 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
105 .len = IEEE80211_MAX_MESH_ID_LEN },
106 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 107
b2e1b302
LR
108 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
109 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
110
9f1ba906
JM
111 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
113 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
114 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
115 .len = NL80211_MAX_SUPP_RATES },
36aedc90 116
93da9cc1 117 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
118
36aedc90
JM
119 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
120 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
121
122 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
123 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
124 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
125 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
126 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
127
128 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
129 .len = IEEE80211_MAX_SSID_LEN },
130 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
131 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 132 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 133 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 134 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
135 [NL80211_ATTR_STA_FLAGS2] = {
136 .len = sizeof(struct nl80211_sta_flag_update),
137 },
3f77316c 138 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
139 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
140 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
141 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 142 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 143 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
144 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
145 .len = WLAN_PMKID_LEN },
9588bbd5
JM
146 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
147 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 148 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
149 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
150 .len = IEEE80211_MAX_DATA_LEN },
151 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 152 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 153 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 154 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 155 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
156
157 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
158 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
55682965
JB
159};
160
b9454e83 161/* policy for the attributes */
b54452b0 162static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 163 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
164 [NL80211_KEY_IDX] = { .type = NLA_U8 },
165 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
166 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
167 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
168 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
169};
170
a043897a
HS
171/* ifidx get helper */
172static int nl80211_get_ifidx(struct netlink_callback *cb)
173{
174 int res;
175
176 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
177 nl80211_fam.attrbuf, nl80211_fam.maxattr,
178 nl80211_policy);
179 if (res)
180 return res;
181
182 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
183 return -EINVAL;
184
185 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
186 if (!res)
187 return -EINVAL;
188 return res;
189}
190
f4a11bb0
JB
191/* IE validation */
192static bool is_valid_ie_attr(const struct nlattr *attr)
193{
194 const u8 *pos;
195 int len;
196
197 if (!attr)
198 return true;
199
200 pos = nla_data(attr);
201 len = nla_len(attr);
202
203 while (len) {
204 u8 elemlen;
205
206 if (len < 2)
207 return false;
208 len -= 2;
209
210 elemlen = pos[1];
211 if (elemlen > len)
212 return false;
213
214 len -= elemlen;
215 pos += 2 + elemlen;
216 }
217
218 return true;
219}
220
55682965
JB
221/* message building helper */
222static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
223 int flags, u8 cmd)
224{
225 /* since there is no private header just add the generic one */
226 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
227}
228
5dab3b8a
LR
229static int nl80211_msg_put_channel(struct sk_buff *msg,
230 struct ieee80211_channel *chan)
231{
232 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
233 chan->center_freq);
234
235 if (chan->flags & IEEE80211_CHAN_DISABLED)
236 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
237 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
238 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
239 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
240 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
241 if (chan->flags & IEEE80211_CHAN_RADAR)
242 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
243
244 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
245 DBM_TO_MBM(chan->max_power));
246
247 return 0;
248
249 nla_put_failure:
250 return -ENOBUFS;
251}
252
55682965
JB
253/* netlink command implementations */
254
b9454e83
JB
255struct key_parse {
256 struct key_params p;
257 int idx;
258 bool def, defmgmt;
259};
260
261static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
262{
263 struct nlattr *tb[NL80211_KEY_MAX + 1];
264 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
265 nl80211_key_policy);
266 if (err)
267 return err;
268
269 k->def = !!tb[NL80211_KEY_DEFAULT];
270 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
271
272 if (tb[NL80211_KEY_IDX])
273 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
274
275 if (tb[NL80211_KEY_DATA]) {
276 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
277 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
278 }
279
280 if (tb[NL80211_KEY_SEQ]) {
281 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
282 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
283 }
284
285 if (tb[NL80211_KEY_CIPHER])
286 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
287
288 return 0;
289}
290
291static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
292{
293 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
294 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
295 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
296 }
297
298 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
299 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
300 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
301 }
302
303 if (info->attrs[NL80211_ATTR_KEY_IDX])
304 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
305
306 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
307 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
308
309 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
310 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
311
312 return 0;
313}
314
315static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
316{
317 int err;
318
319 memset(k, 0, sizeof(*k));
320 k->idx = -1;
321
322 if (info->attrs[NL80211_ATTR_KEY])
323 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
324 else
325 err = nl80211_parse_key_old(info, k);
326
327 if (err)
328 return err;
329
330 if (k->def && k->defmgmt)
331 return -EINVAL;
332
333 if (k->idx != -1) {
334 if (k->defmgmt) {
335 if (k->idx < 4 || k->idx > 5)
336 return -EINVAL;
337 } else if (k->def) {
338 if (k->idx < 0 || k->idx > 3)
339 return -EINVAL;
340 } else {
341 if (k->idx < 0 || k->idx > 5)
342 return -EINVAL;
343 }
344 }
345
346 return 0;
347}
348
fffd0934
JB
349static struct cfg80211_cached_keys *
350nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
351 struct nlattr *keys)
352{
353 struct key_parse parse;
354 struct nlattr *key;
355 struct cfg80211_cached_keys *result;
356 int rem, err, def = 0;
357
358 result = kzalloc(sizeof(*result), GFP_KERNEL);
359 if (!result)
360 return ERR_PTR(-ENOMEM);
361
362 result->def = -1;
363 result->defmgmt = -1;
364
365 nla_for_each_nested(key, keys, rem) {
366 memset(&parse, 0, sizeof(parse));
367 parse.idx = -1;
368
369 err = nl80211_parse_key_new(key, &parse);
370 if (err)
371 goto error;
372 err = -EINVAL;
373 if (!parse.p.key)
374 goto error;
375 if (parse.idx < 0 || parse.idx > 4)
376 goto error;
377 if (parse.def) {
378 if (def)
379 goto error;
380 def = 1;
381 result->def = parse.idx;
382 } else if (parse.defmgmt)
383 goto error;
384 err = cfg80211_validate_key_settings(rdev, &parse.p,
385 parse.idx, NULL);
386 if (err)
387 goto error;
388 result->params[parse.idx].cipher = parse.p.cipher;
389 result->params[parse.idx].key_len = parse.p.key_len;
390 result->params[parse.idx].key = result->data[parse.idx];
391 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
392 }
393
394 return result;
395 error:
396 kfree(result);
397 return ERR_PTR(err);
398}
399
400static int nl80211_key_allowed(struct wireless_dev *wdev)
401{
402 ASSERT_WDEV_LOCK(wdev);
403
404 if (!netif_running(wdev->netdev))
405 return -ENETDOWN;
406
407 switch (wdev->iftype) {
408 case NL80211_IFTYPE_AP:
409 case NL80211_IFTYPE_AP_VLAN:
410 break;
411 case NL80211_IFTYPE_ADHOC:
412 if (!wdev->current_bss)
413 return -ENOLINK;
414 break;
415 case NL80211_IFTYPE_STATION:
416 if (wdev->sme_state != CFG80211_SME_CONNECTED)
417 return -ENOLINK;
418 break;
419 default:
420 return -EINVAL;
421 }
422
423 return 0;
424}
425
55682965
JB
426static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
427 struct cfg80211_registered_device *dev)
428{
429 void *hdr;
ee688b00
JB
430 struct nlattr *nl_bands, *nl_band;
431 struct nlattr *nl_freqs, *nl_freq;
432 struct nlattr *nl_rates, *nl_rate;
f59ac048 433 struct nlattr *nl_modes;
8fdc621d 434 struct nlattr *nl_cmds;
ee688b00
JB
435 enum ieee80211_band band;
436 struct ieee80211_channel *chan;
437 struct ieee80211_rate *rate;
438 int i;
f59ac048 439 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
440
441 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
442 if (!hdr)
443 return -1;
444
b5850a7a 445 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 446 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 447
f5ea9120
JB
448 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
449 cfg80211_rdev_list_generation);
450
b9a5f8ca
JM
451 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
452 dev->wiphy.retry_short);
453 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
454 dev->wiphy.retry_long);
455 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
456 dev->wiphy.frag_threshold);
457 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
458 dev->wiphy.rts_threshold);
81077e82
LT
459 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
460 dev->wiphy.coverage_class);
b9a5f8ca 461
2a519311
JB
462 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
463 dev->wiphy.max_scan_ssids);
18a83659
JB
464 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
465 dev->wiphy.max_scan_ie_len);
ee688b00 466
25e47c18
JB
467 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
468 sizeof(u32) * dev->wiphy.n_cipher_suites,
469 dev->wiphy.cipher_suites);
470
67fbb16b
SO
471 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
472 dev->wiphy.max_num_pmkids);
473
f59ac048
LR
474 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
475 if (!nl_modes)
476 goto nla_put_failure;
477
478 i = 0;
479 while (ifmodes) {
480 if (ifmodes & 1)
481 NLA_PUT_FLAG(msg, i);
482 ifmodes >>= 1;
483 i++;
484 }
485
486 nla_nest_end(msg, nl_modes);
487
ee688b00
JB
488 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
489 if (!nl_bands)
490 goto nla_put_failure;
491
492 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
493 if (!dev->wiphy.bands[band])
494 continue;
495
496 nl_band = nla_nest_start(msg, band);
497 if (!nl_band)
498 goto nla_put_failure;
499
d51626df
JB
500 /* add HT info */
501 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
502 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
503 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
504 &dev->wiphy.bands[band]->ht_cap.mcs);
505 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
506 dev->wiphy.bands[band]->ht_cap.cap);
507 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
508 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
509 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
510 dev->wiphy.bands[band]->ht_cap.ampdu_density);
511 }
512
ee688b00
JB
513 /* add frequencies */
514 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
515 if (!nl_freqs)
516 goto nla_put_failure;
517
518 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
519 nl_freq = nla_nest_start(msg, i);
520 if (!nl_freq)
521 goto nla_put_failure;
522
523 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
524
525 if (nl80211_msg_put_channel(msg, chan))
526 goto nla_put_failure;
e2f367f2 527
ee688b00
JB
528 nla_nest_end(msg, nl_freq);
529 }
530
531 nla_nest_end(msg, nl_freqs);
532
533 /* add bitrates */
534 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
535 if (!nl_rates)
536 goto nla_put_failure;
537
538 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
539 nl_rate = nla_nest_start(msg, i);
540 if (!nl_rate)
541 goto nla_put_failure;
542
543 rate = &dev->wiphy.bands[band]->bitrates[i];
544 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
545 rate->bitrate);
546 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
547 NLA_PUT_FLAG(msg,
548 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
549
550 nla_nest_end(msg, nl_rate);
551 }
552
553 nla_nest_end(msg, nl_rates);
554
555 nla_nest_end(msg, nl_band);
556 }
557 nla_nest_end(msg, nl_bands);
558
8fdc621d
JB
559 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
560 if (!nl_cmds)
561 goto nla_put_failure;
562
563 i = 0;
564#define CMD(op, n) \
565 do { \
566 if (dev->ops->op) { \
567 i++; \
568 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
569 } \
570 } while (0)
571
572 CMD(add_virtual_intf, NEW_INTERFACE);
573 CMD(change_virtual_intf, SET_INTERFACE);
574 CMD(add_key, NEW_KEY);
575 CMD(add_beacon, NEW_BEACON);
576 CMD(add_station, NEW_STATION);
577 CMD(add_mpath, NEW_MPATH);
578 CMD(set_mesh_params, SET_MESH_PARAMS);
579 CMD(change_bss, SET_BSS);
636a5d36
JM
580 CMD(auth, AUTHENTICATE);
581 CMD(assoc, ASSOCIATE);
582 CMD(deauth, DEAUTHENTICATE);
583 CMD(disassoc, DISASSOCIATE);
04a773ad 584 CMD(join_ibss, JOIN_IBSS);
67fbb16b
SO
585 CMD(set_pmksa, SET_PMKSA);
586 CMD(del_pmksa, DEL_PMKSA);
587 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 588 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 589 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
026331c4 590 CMD(action, ACTION);
5be83de5 591 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
592 i++;
593 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
594 }
f444de05 595 CMD(set_channel, SET_CHANNEL);
8fdc621d
JB
596
597#undef CMD
b23aa676 598
6829c878 599 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
600 i++;
601 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
602 }
603
6829c878 604 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
605 i++;
606 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
607 }
608
8fdc621d
JB
609 nla_nest_end(msg, nl_cmds);
610
55682965
JB
611 return genlmsg_end(msg, hdr);
612
613 nla_put_failure:
bc3ed28c
TG
614 genlmsg_cancel(msg, hdr);
615 return -EMSGSIZE;
55682965
JB
616}
617
618static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
619{
620 int idx = 0;
621 int start = cb->args[0];
622 struct cfg80211_registered_device *dev;
623
a1794390 624 mutex_lock(&cfg80211_mutex);
79c97e97 625 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
626 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
627 continue;
b4637271 628 if (++idx <= start)
55682965
JB
629 continue;
630 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
631 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
632 dev) < 0) {
633 idx--;
55682965 634 break;
b4637271 635 }
55682965 636 }
a1794390 637 mutex_unlock(&cfg80211_mutex);
55682965
JB
638
639 cb->args[0] = idx;
640
641 return skb->len;
642}
643
644static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
645{
646 struct sk_buff *msg;
647 struct cfg80211_registered_device *dev;
648
649 dev = cfg80211_get_dev_from_info(info);
650 if (IS_ERR(dev))
651 return PTR_ERR(dev);
652
fd2120ca 653 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
654 if (!msg)
655 goto out_err;
656
657 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
658 goto out_free;
659
4d0c8aea 660 cfg80211_unlock_rdev(dev);
55682965 661
134e6375 662 return genlmsg_reply(msg, info);
55682965
JB
663
664 out_free:
665 nlmsg_free(msg);
666 out_err:
4d0c8aea 667 cfg80211_unlock_rdev(dev);
55682965
JB
668 return -ENOBUFS;
669}
670
31888487
JM
671static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
672 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
673 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
674 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
675 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
676 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
677};
678
679static int parse_txq_params(struct nlattr *tb[],
680 struct ieee80211_txq_params *txq_params)
681{
682 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
683 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
684 !tb[NL80211_TXQ_ATTR_AIFS])
685 return -EINVAL;
686
687 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
688 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
689 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
690 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
691 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
692
693 return 0;
694}
695
f444de05
JB
696static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
697{
698 /*
699 * You can only set the channel explicitly for AP, mesh
700 * and WDS type interfaces; all others have their channel
701 * managed via their respective "establish a connection"
702 * command (connect, join, ...)
703 *
704 * Monitors are special as they are normally slaved to
705 * whatever else is going on, so they behave as though
706 * you tried setting the wiphy channel itself.
707 */
708 return !wdev ||
709 wdev->iftype == NL80211_IFTYPE_AP ||
710 wdev->iftype == NL80211_IFTYPE_WDS ||
711 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
712 wdev->iftype == NL80211_IFTYPE_MONITOR;
713}
714
715static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
716 struct wireless_dev *wdev,
717 struct genl_info *info)
718{
719 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
720 u32 freq;
721 int result;
722
723 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
724 return -EINVAL;
725
726 if (!nl80211_can_set_dev_channel(wdev))
727 return -EOPNOTSUPP;
728
729 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
730 channel_type = nla_get_u32(info->attrs[
731 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
732 if (channel_type != NL80211_CHAN_NO_HT &&
733 channel_type != NL80211_CHAN_HT20 &&
734 channel_type != NL80211_CHAN_HT40PLUS &&
735 channel_type != NL80211_CHAN_HT40MINUS)
736 return -EINVAL;
737 }
738
739 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
740
741 mutex_lock(&rdev->devlist_mtx);
742 if (wdev) {
743 wdev_lock(wdev);
744 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
745 wdev_unlock(wdev);
746 } else {
747 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
748 }
749 mutex_unlock(&rdev->devlist_mtx);
750
751 return result;
752}
753
754static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
755{
756 struct cfg80211_registered_device *rdev;
757 struct net_device *netdev;
758 int result;
759
760 rtnl_lock();
761
762 result = get_rdev_dev_by_info_ifindex(info, &rdev, &netdev);
763 if (result)
764 goto unlock;
765
766 result = __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
767
768 unlock:
769 rtnl_unlock();
770
771 return result;
772}
773
55682965
JB
774static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
775{
776 struct cfg80211_registered_device *rdev;
f444de05
JB
777 struct net_device *netdev = NULL;
778 struct wireless_dev *wdev;
779 int result, rem_txq_params = 0;
31888487 780 struct nlattr *nl_txq_params;
b9a5f8ca
JM
781 u32 changed;
782 u8 retry_short = 0, retry_long = 0;
783 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 784 u8 coverage_class = 0;
55682965 785
4bbf4d56 786 rtnl_lock();
55682965 787
f444de05
JB
788 /*
789 * Try to find the wiphy and netdev. Normally this
790 * function shouldn't need the netdev, but this is
791 * done for backward compatibility -- previously
792 * setting the channel was done per wiphy, but now
793 * it is per netdev. Previous userland like hostapd
794 * also passed a netdev to set_wiphy, so that it is
795 * possible to let that go to the right netdev!
796 */
4bbf4d56
JB
797 mutex_lock(&cfg80211_mutex);
798
f444de05
JB
799 if (info->attrs[NL80211_ATTR_IFINDEX]) {
800 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
801
802 netdev = dev_get_by_index(genl_info_net(info), ifindex);
803 if (netdev && netdev->ieee80211_ptr) {
804 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
805 mutex_lock(&rdev->mtx);
806 } else
807 netdev = NULL;
4bbf4d56
JB
808 }
809
f444de05
JB
810 if (!netdev) {
811 rdev = __cfg80211_rdev_from_info(info);
812 if (IS_ERR(rdev)) {
813 mutex_unlock(&cfg80211_mutex);
814 result = PTR_ERR(rdev);
815 goto unlock;
816 }
817 wdev = NULL;
818 netdev = NULL;
819 result = 0;
820
821 mutex_lock(&rdev->mtx);
822 } else if (netif_running(netdev) &&
823 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
824 wdev = netdev->ieee80211_ptr;
825 else
826 wdev = NULL;
827
828 /*
829 * end workaround code, by now the rdev is available
830 * and locked, and wdev may or may not be NULL.
831 */
4bbf4d56
JB
832
833 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
834 result = cfg80211_dev_rename(
835 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
836
837 mutex_unlock(&cfg80211_mutex);
838
839 if (result)
840 goto bad_res;
31888487
JM
841
842 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
843 struct ieee80211_txq_params txq_params;
844 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
845
846 if (!rdev->ops->set_txq_params) {
847 result = -EOPNOTSUPP;
848 goto bad_res;
849 }
850
851 nla_for_each_nested(nl_txq_params,
852 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
853 rem_txq_params) {
854 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
855 nla_data(nl_txq_params),
856 nla_len(nl_txq_params),
857 txq_params_policy);
858 result = parse_txq_params(tb, &txq_params);
859 if (result)
860 goto bad_res;
861
862 result = rdev->ops->set_txq_params(&rdev->wiphy,
863 &txq_params);
864 if (result)
865 goto bad_res;
866 }
867 }
55682965 868
72bdcf34 869 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 870 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
871 if (result)
872 goto bad_res;
873 }
874
98d2ff8b
JO
875 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
876 enum nl80211_tx_power_setting type;
877 int idx, mbm = 0;
878
879 if (!rdev->ops->set_tx_power) {
60ea385f 880 result = -EOPNOTSUPP;
98d2ff8b
JO
881 goto bad_res;
882 }
883
884 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
885 type = nla_get_u32(info->attrs[idx]);
886
887 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
888 (type != NL80211_TX_POWER_AUTOMATIC)) {
889 result = -EINVAL;
890 goto bad_res;
891 }
892
893 if (type != NL80211_TX_POWER_AUTOMATIC) {
894 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
895 mbm = nla_get_u32(info->attrs[idx]);
896 }
897
898 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
899 if (result)
900 goto bad_res;
901 }
902
b9a5f8ca
JM
903 changed = 0;
904
905 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
906 retry_short = nla_get_u8(
907 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
908 if (retry_short == 0) {
909 result = -EINVAL;
910 goto bad_res;
911 }
912 changed |= WIPHY_PARAM_RETRY_SHORT;
913 }
914
915 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
916 retry_long = nla_get_u8(
917 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
918 if (retry_long == 0) {
919 result = -EINVAL;
920 goto bad_res;
921 }
922 changed |= WIPHY_PARAM_RETRY_LONG;
923 }
924
925 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
926 frag_threshold = nla_get_u32(
927 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
928 if (frag_threshold < 256) {
929 result = -EINVAL;
930 goto bad_res;
931 }
932 if (frag_threshold != (u32) -1) {
933 /*
934 * Fragments (apart from the last one) are required to
935 * have even length. Make the fragmentation code
936 * simpler by stripping LSB should someone try to use
937 * odd threshold value.
938 */
939 frag_threshold &= ~0x1;
940 }
941 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
942 }
943
944 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
945 rts_threshold = nla_get_u32(
946 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
947 changed |= WIPHY_PARAM_RTS_THRESHOLD;
948 }
949
81077e82
LT
950 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
951 coverage_class = nla_get_u8(
952 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
953 changed |= WIPHY_PARAM_COVERAGE_CLASS;
954 }
955
b9a5f8ca
JM
956 if (changed) {
957 u8 old_retry_short, old_retry_long;
958 u32 old_frag_threshold, old_rts_threshold;
81077e82 959 u8 old_coverage_class;
b9a5f8ca
JM
960
961 if (!rdev->ops->set_wiphy_params) {
962 result = -EOPNOTSUPP;
963 goto bad_res;
964 }
965
966 old_retry_short = rdev->wiphy.retry_short;
967 old_retry_long = rdev->wiphy.retry_long;
968 old_frag_threshold = rdev->wiphy.frag_threshold;
969 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 970 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
971
972 if (changed & WIPHY_PARAM_RETRY_SHORT)
973 rdev->wiphy.retry_short = retry_short;
974 if (changed & WIPHY_PARAM_RETRY_LONG)
975 rdev->wiphy.retry_long = retry_long;
976 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
977 rdev->wiphy.frag_threshold = frag_threshold;
978 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
979 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
980 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
981 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
982
983 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
984 if (result) {
985 rdev->wiphy.retry_short = old_retry_short;
986 rdev->wiphy.retry_long = old_retry_long;
987 rdev->wiphy.frag_threshold = old_frag_threshold;
988 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 989 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
990 }
991 }
72bdcf34 992
306d6112 993 bad_res:
4bbf4d56 994 mutex_unlock(&rdev->mtx);
f444de05
JB
995 if (netdev)
996 dev_put(netdev);
4bbf4d56
JB
997 unlock:
998 rtnl_unlock();
55682965
JB
999 return result;
1000}
1001
1002
1003static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1004 struct cfg80211_registered_device *rdev,
55682965
JB
1005 struct net_device *dev)
1006{
1007 void *hdr;
1008
1009 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1010 if (!hdr)
1011 return -1;
1012
1013 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1014 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1015 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1016 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1017
1018 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1019 rdev->devlist_generation ^
1020 (cfg80211_rdev_list_generation << 2));
1021
55682965
JB
1022 return genlmsg_end(msg, hdr);
1023
1024 nla_put_failure:
bc3ed28c
TG
1025 genlmsg_cancel(msg, hdr);
1026 return -EMSGSIZE;
55682965
JB
1027}
1028
1029static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1030{
1031 int wp_idx = 0;
1032 int if_idx = 0;
1033 int wp_start = cb->args[0];
1034 int if_start = cb->args[1];
f5ea9120 1035 struct cfg80211_registered_device *rdev;
55682965
JB
1036 struct wireless_dev *wdev;
1037
a1794390 1038 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1039 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1040 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1041 continue;
bba95fef
JB
1042 if (wp_idx < wp_start) {
1043 wp_idx++;
55682965 1044 continue;
bba95fef 1045 }
55682965
JB
1046 if_idx = 0;
1047
f5ea9120
JB
1048 mutex_lock(&rdev->devlist_mtx);
1049 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1050 if (if_idx < if_start) {
1051 if_idx++;
55682965 1052 continue;
bba95fef 1053 }
55682965
JB
1054 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1055 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1056 rdev, wdev->netdev) < 0) {
1057 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1058 goto out;
1059 }
1060 if_idx++;
55682965 1061 }
f5ea9120 1062 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1063
1064 wp_idx++;
55682965 1065 }
bba95fef 1066 out:
a1794390 1067 mutex_unlock(&cfg80211_mutex);
55682965
JB
1068
1069 cb->args[0] = wp_idx;
1070 cb->args[1] = if_idx;
1071
1072 return skb->len;
1073}
1074
1075static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1076{
1077 struct sk_buff *msg;
1078 struct cfg80211_registered_device *dev;
1079 struct net_device *netdev;
1080 int err;
1081
463d0183 1082 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
1083 if (err)
1084 return err;
1085
fd2120ca 1086 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
1087 if (!msg)
1088 goto out_err;
1089
d726405a
JB
1090 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1091 dev, netdev) < 0)
55682965
JB
1092 goto out_free;
1093
1094 dev_put(netdev);
4d0c8aea 1095 cfg80211_unlock_rdev(dev);
55682965 1096
134e6375 1097 return genlmsg_reply(msg, info);
55682965
JB
1098
1099 out_free:
1100 nlmsg_free(msg);
1101 out_err:
1102 dev_put(netdev);
4d0c8aea 1103 cfg80211_unlock_rdev(dev);
55682965
JB
1104 return -ENOBUFS;
1105}
1106
66f7ac50
MW
1107static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1108 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1109 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1110 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1111 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1112 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1113};
1114
1115static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1116{
1117 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1118 int flag;
1119
1120 *mntrflags = 0;
1121
1122 if (!nla)
1123 return -EINVAL;
1124
1125 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1126 nla, mntr_flags_policy))
1127 return -EINVAL;
1128
1129 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1130 if (flags[flag])
1131 *mntrflags |= (1<<flag);
1132
1133 return 0;
1134}
1135
9bc383de 1136static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1137 struct net_device *netdev, u8 use_4addr,
1138 enum nl80211_iftype iftype)
9bc383de 1139{
ad4bb6f8 1140 if (!use_4addr) {
f350a0a8 1141 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1142 return -EBUSY;
9bc383de 1143 return 0;
ad4bb6f8 1144 }
9bc383de
JB
1145
1146 switch (iftype) {
1147 case NL80211_IFTYPE_AP_VLAN:
1148 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1149 return 0;
1150 break;
1151 case NL80211_IFTYPE_STATION:
1152 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1153 return 0;
1154 break;
1155 default:
1156 break;
1157 }
1158
1159 return -EOPNOTSUPP;
1160}
1161
55682965
JB
1162static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1163{
79c97e97 1164 struct cfg80211_registered_device *rdev;
2ec600d6 1165 struct vif_params params;
e36d56b6 1166 int err;
04a773ad 1167 enum nl80211_iftype otype, ntype;
55682965 1168 struct net_device *dev;
92ffe055 1169 u32 _flags, *flags = NULL;
ac7f9cfa 1170 bool change = false;
55682965 1171
2ec600d6
LCC
1172 memset(&params, 0, sizeof(params));
1173
3b85875a
JB
1174 rtnl_lock();
1175
463d0183 1176 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1177 if (err)
3b85875a
JB
1178 goto unlock_rtnl;
1179
04a773ad 1180 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1181
723b038d 1182 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1183 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1184 if (otype != ntype)
ac7f9cfa 1185 change = true;
04a773ad 1186 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 1187 err = -EINVAL;
723b038d 1188 goto unlock;
ac7f9cfa 1189 }
723b038d
JB
1190 }
1191
92ffe055 1192 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1193 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1194 err = -EINVAL;
1195 goto unlock;
1196 }
2ec600d6
LCC
1197 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1198 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1199 change = true;
2ec600d6
LCC
1200 }
1201
8b787643
FF
1202 if (info->attrs[NL80211_ATTR_4ADDR]) {
1203 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1204 change = true;
ad4bb6f8 1205 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de
JB
1206 if (err)
1207 goto unlock;
8b787643
FF
1208 } else {
1209 params.use_4addr = -1;
1210 }
1211
92ffe055 1212 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1213 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1214 err = -EINVAL;
1215 goto unlock;
1216 }
1217 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1218 &_flags);
ac7f9cfa
JB
1219 if (err)
1220 goto unlock;
1221
1222 flags = &_flags;
1223 change = true;
92ffe055 1224 }
3b85875a 1225
ac7f9cfa 1226 if (change)
3d54d255 1227 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1228 else
1229 err = 0;
60719ffd 1230
9bc383de
JB
1231 if (!err && params.use_4addr != -1)
1232 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1233
55682965 1234 unlock:
e36d56b6 1235 dev_put(dev);
79c97e97 1236 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1237 unlock_rtnl:
1238 rtnl_unlock();
55682965
JB
1239 return err;
1240}
1241
1242static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1243{
79c97e97 1244 struct cfg80211_registered_device *rdev;
2ec600d6 1245 struct vif_params params;
55682965
JB
1246 int err;
1247 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1248 u32 flags;
55682965 1249
2ec600d6
LCC
1250 memset(&params, 0, sizeof(params));
1251
55682965
JB
1252 if (!info->attrs[NL80211_ATTR_IFNAME])
1253 return -EINVAL;
1254
1255 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1256 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1257 if (type > NL80211_IFTYPE_MAX)
1258 return -EINVAL;
1259 }
1260
3b85875a
JB
1261 rtnl_lock();
1262
79c97e97
JB
1263 rdev = cfg80211_get_dev_from_info(info);
1264 if (IS_ERR(rdev)) {
1265 err = PTR_ERR(rdev);
3b85875a
JB
1266 goto unlock_rtnl;
1267 }
55682965 1268
79c97e97
JB
1269 if (!rdev->ops->add_virtual_intf ||
1270 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1271 err = -EOPNOTSUPP;
1272 goto unlock;
1273 }
1274
2ec600d6
LCC
1275 if (type == NL80211_IFTYPE_MESH_POINT &&
1276 info->attrs[NL80211_ATTR_MESH_ID]) {
1277 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1278 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1279 }
1280
9bc383de 1281 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1282 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1283 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de
JB
1284 if (err)
1285 goto unlock;
1286 }
8b787643 1287
66f7ac50
MW
1288 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1289 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1290 &flags);
79c97e97 1291 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1292 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1293 type, err ? NULL : &flags, &params);
2ec600d6 1294
55682965 1295 unlock:
79c97e97 1296 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1297 unlock_rtnl:
1298 rtnl_unlock();
55682965
JB
1299 return err;
1300}
1301
1302static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1303{
79c97e97 1304 struct cfg80211_registered_device *rdev;
463d0183 1305 int err;
55682965
JB
1306 struct net_device *dev;
1307
3b85875a
JB
1308 rtnl_lock();
1309
463d0183 1310 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1311 if (err)
3b85875a 1312 goto unlock_rtnl;
55682965 1313
79c97e97 1314 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1315 err = -EOPNOTSUPP;
1316 goto out;
1317 }
1318
463d0183 1319 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1320
1321 out:
79c97e97 1322 cfg80211_unlock_rdev(rdev);
463d0183 1323 dev_put(dev);
3b85875a
JB
1324 unlock_rtnl:
1325 rtnl_unlock();
55682965
JB
1326 return err;
1327}
1328
41ade00f
JB
1329struct get_key_cookie {
1330 struct sk_buff *msg;
1331 int error;
b9454e83 1332 int idx;
41ade00f
JB
1333};
1334
1335static void get_key_callback(void *c, struct key_params *params)
1336{
b9454e83 1337 struct nlattr *key;
41ade00f
JB
1338 struct get_key_cookie *cookie = c;
1339
1340 if (params->key)
1341 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1342 params->key_len, params->key);
1343
1344 if (params->seq)
1345 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1346 params->seq_len, params->seq);
1347
1348 if (params->cipher)
1349 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1350 params->cipher);
1351
b9454e83
JB
1352 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1353 if (!key)
1354 goto nla_put_failure;
1355
1356 if (params->key)
1357 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1358 params->key_len, params->key);
1359
1360 if (params->seq)
1361 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1362 params->seq_len, params->seq);
1363
1364 if (params->cipher)
1365 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1366 params->cipher);
1367
1368 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1369
1370 nla_nest_end(cookie->msg, key);
1371
41ade00f
JB
1372 return;
1373 nla_put_failure:
1374 cookie->error = 1;
1375}
1376
1377static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1378{
79c97e97 1379 struct cfg80211_registered_device *rdev;
41ade00f
JB
1380 int err;
1381 struct net_device *dev;
1382 u8 key_idx = 0;
1383 u8 *mac_addr = NULL;
1384 struct get_key_cookie cookie = {
1385 .error = 0,
1386 };
1387 void *hdr;
1388 struct sk_buff *msg;
1389
1390 if (info->attrs[NL80211_ATTR_KEY_IDX])
1391 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1392
3cfcf6ac 1393 if (key_idx > 5)
41ade00f
JB
1394 return -EINVAL;
1395
1396 if (info->attrs[NL80211_ATTR_MAC])
1397 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1398
3b85875a
JB
1399 rtnl_lock();
1400
463d0183 1401 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1402 if (err)
3b85875a 1403 goto unlock_rtnl;
41ade00f 1404
79c97e97 1405 if (!rdev->ops->get_key) {
41ade00f
JB
1406 err = -EOPNOTSUPP;
1407 goto out;
1408 }
1409
fd2120ca 1410 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1411 if (!msg) {
1412 err = -ENOMEM;
1413 goto out;
1414 }
1415
1416 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1417 NL80211_CMD_NEW_KEY);
1418
1419 if (IS_ERR(hdr)) {
1420 err = PTR_ERR(hdr);
6c95e2a2 1421 goto free_msg;
41ade00f
JB
1422 }
1423
1424 cookie.msg = msg;
b9454e83 1425 cookie.idx = key_idx;
41ade00f
JB
1426
1427 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1428 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1429 if (mac_addr)
1430 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1431
79c97e97 1432 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1433 &cookie, get_key_callback);
41ade00f
JB
1434
1435 if (err)
6c95e2a2 1436 goto free_msg;
41ade00f
JB
1437
1438 if (cookie.error)
1439 goto nla_put_failure;
1440
1441 genlmsg_end(msg, hdr);
134e6375 1442 err = genlmsg_reply(msg, info);
41ade00f
JB
1443 goto out;
1444
1445 nla_put_failure:
1446 err = -ENOBUFS;
6c95e2a2 1447 free_msg:
41ade00f
JB
1448 nlmsg_free(msg);
1449 out:
79c97e97 1450 cfg80211_unlock_rdev(rdev);
41ade00f 1451 dev_put(dev);
3b85875a
JB
1452 unlock_rtnl:
1453 rtnl_unlock();
1454
41ade00f
JB
1455 return err;
1456}
1457
1458static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1459{
79c97e97 1460 struct cfg80211_registered_device *rdev;
b9454e83 1461 struct key_parse key;
41ade00f
JB
1462 int err;
1463 struct net_device *dev;
3cfcf6ac
JM
1464 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1465 u8 key_index);
41ade00f 1466
b9454e83
JB
1467 err = nl80211_parse_key(info, &key);
1468 if (err)
1469 return err;
41ade00f 1470
b9454e83 1471 if (key.idx < 0)
41ade00f
JB
1472 return -EINVAL;
1473
b9454e83
JB
1474 /* only support setting default key */
1475 if (!key.def && !key.defmgmt)
41ade00f
JB
1476 return -EINVAL;
1477
3b85875a
JB
1478 rtnl_lock();
1479
463d0183 1480 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1481 if (err)
3b85875a 1482 goto unlock_rtnl;
41ade00f 1483
b9454e83 1484 if (key.def)
79c97e97 1485 func = rdev->ops->set_default_key;
3cfcf6ac 1486 else
79c97e97 1487 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1488
1489 if (!func) {
41ade00f
JB
1490 err = -EOPNOTSUPP;
1491 goto out;
1492 }
1493
fffd0934
JB
1494 wdev_lock(dev->ieee80211_ptr);
1495 err = nl80211_key_allowed(dev->ieee80211_ptr);
1496 if (!err)
1497 err = func(&rdev->wiphy, dev, key.idx);
1498
3d23e349 1499#ifdef CONFIG_CFG80211_WEXT
08645126 1500 if (!err) {
79c97e97 1501 if (func == rdev->ops->set_default_key)
b9454e83 1502 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1503 else
b9454e83 1504 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1505 }
1506#endif
fffd0934 1507 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1508
1509 out:
79c97e97 1510 cfg80211_unlock_rdev(rdev);
41ade00f 1511 dev_put(dev);
3b85875a
JB
1512
1513 unlock_rtnl:
1514 rtnl_unlock();
1515
41ade00f
JB
1516 return err;
1517}
1518
1519static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1520{
79c97e97 1521 struct cfg80211_registered_device *rdev;
fffd0934 1522 int err;
41ade00f 1523 struct net_device *dev;
b9454e83 1524 struct key_parse key;
41ade00f
JB
1525 u8 *mac_addr = NULL;
1526
b9454e83
JB
1527 err = nl80211_parse_key(info, &key);
1528 if (err)
1529 return err;
41ade00f 1530
b9454e83 1531 if (!key.p.key)
41ade00f
JB
1532 return -EINVAL;
1533
41ade00f
JB
1534 if (info->attrs[NL80211_ATTR_MAC])
1535 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1536
3b85875a
JB
1537 rtnl_lock();
1538
463d0183 1539 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1540 if (err)
3b85875a 1541 goto unlock_rtnl;
41ade00f 1542
fffd0934
JB
1543 if (!rdev->ops->add_key) {
1544 err = -EOPNOTSUPP;
25e47c18
JB
1545 goto out;
1546 }
1547
fffd0934
JB
1548 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1549 err = -EINVAL;
41ade00f
JB
1550 goto out;
1551 }
1552
fffd0934
JB
1553 wdev_lock(dev->ieee80211_ptr);
1554 err = nl80211_key_allowed(dev->ieee80211_ptr);
1555 if (!err)
1556 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1557 mac_addr, &key.p);
1558 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1559
1560 out:
79c97e97 1561 cfg80211_unlock_rdev(rdev);
41ade00f 1562 dev_put(dev);
3b85875a
JB
1563 unlock_rtnl:
1564 rtnl_unlock();
1565
41ade00f
JB
1566 return err;
1567}
1568
1569static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1570{
79c97e97 1571 struct cfg80211_registered_device *rdev;
41ade00f
JB
1572 int err;
1573 struct net_device *dev;
41ade00f 1574 u8 *mac_addr = NULL;
b9454e83 1575 struct key_parse key;
41ade00f 1576
b9454e83
JB
1577 err = nl80211_parse_key(info, &key);
1578 if (err)
1579 return err;
41ade00f
JB
1580
1581 if (info->attrs[NL80211_ATTR_MAC])
1582 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1583
3b85875a
JB
1584 rtnl_lock();
1585
463d0183 1586 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1587 if (err)
3b85875a 1588 goto unlock_rtnl;
41ade00f 1589
79c97e97 1590 if (!rdev->ops->del_key) {
41ade00f
JB
1591 err = -EOPNOTSUPP;
1592 goto out;
1593 }
1594
fffd0934
JB
1595 wdev_lock(dev->ieee80211_ptr);
1596 err = nl80211_key_allowed(dev->ieee80211_ptr);
1597 if (!err)
1598 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1599
3d23e349 1600#ifdef CONFIG_CFG80211_WEXT
08645126 1601 if (!err) {
b9454e83 1602 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1603 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1604 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1605 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1606 }
1607#endif
fffd0934 1608 wdev_unlock(dev->ieee80211_ptr);
08645126 1609
41ade00f 1610 out:
79c97e97 1611 cfg80211_unlock_rdev(rdev);
41ade00f 1612 dev_put(dev);
3b85875a
JB
1613
1614 unlock_rtnl:
1615 rtnl_unlock();
1616
41ade00f
JB
1617 return err;
1618}
1619
ed1b6cc7
JB
1620static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1621{
1622 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1623 struct beacon_parameters *info);
79c97e97 1624 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1625 int err;
1626 struct net_device *dev;
1627 struct beacon_parameters params;
1628 int haveinfo = 0;
1629
f4a11bb0
JB
1630 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1631 return -EINVAL;
1632
3b85875a
JB
1633 rtnl_lock();
1634
463d0183 1635 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1636 if (err)
3b85875a 1637 goto unlock_rtnl;
ed1b6cc7 1638
eec60b03
JM
1639 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1640 err = -EOPNOTSUPP;
1641 goto out;
1642 }
1643
ed1b6cc7
JB
1644 switch (info->genlhdr->cmd) {
1645 case NL80211_CMD_NEW_BEACON:
1646 /* these are required for NEW_BEACON */
1647 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1648 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1649 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1650 err = -EINVAL;
1651 goto out;
1652 }
1653
79c97e97 1654 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1655 break;
1656 case NL80211_CMD_SET_BEACON:
79c97e97 1657 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1658 break;
1659 default:
1660 WARN_ON(1);
1661 err = -EOPNOTSUPP;
1662 goto out;
1663 }
1664
1665 if (!call) {
1666 err = -EOPNOTSUPP;
1667 goto out;
1668 }
1669
1670 memset(&params, 0, sizeof(params));
1671
1672 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1673 params.interval =
1674 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1675 haveinfo = 1;
1676 }
1677
1678 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1679 params.dtim_period =
1680 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1681 haveinfo = 1;
1682 }
1683
1684 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1685 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1686 params.head_len =
1687 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1688 haveinfo = 1;
1689 }
1690
1691 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1692 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1693 params.tail_len =
1694 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1695 haveinfo = 1;
1696 }
1697
1698 if (!haveinfo) {
1699 err = -EINVAL;
1700 goto out;
1701 }
1702
79c97e97 1703 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1704
1705 out:
79c97e97 1706 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1707 dev_put(dev);
3b85875a
JB
1708 unlock_rtnl:
1709 rtnl_unlock();
1710
ed1b6cc7
JB
1711 return err;
1712}
1713
1714static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1715{
79c97e97 1716 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1717 int err;
1718 struct net_device *dev;
1719
3b85875a
JB
1720 rtnl_lock();
1721
463d0183 1722 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1723 if (err)
3b85875a 1724 goto unlock_rtnl;
ed1b6cc7 1725
79c97e97 1726 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1727 err = -EOPNOTSUPP;
1728 goto out;
1729 }
1730
eec60b03
JM
1731 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1732 err = -EOPNOTSUPP;
1733 goto out;
1734 }
79c97e97 1735 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1736
1737 out:
79c97e97 1738 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1739 dev_put(dev);
3b85875a
JB
1740 unlock_rtnl:
1741 rtnl_unlock();
1742
ed1b6cc7
JB
1743 return err;
1744}
1745
5727ef1b
JB
1746static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1747 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1748 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1749 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1750 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1751};
1752
eccb8e8f
JB
1753static int parse_station_flags(struct genl_info *info,
1754 struct station_parameters *params)
5727ef1b
JB
1755{
1756 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1757 struct nlattr *nla;
5727ef1b
JB
1758 int flag;
1759
eccb8e8f
JB
1760 /*
1761 * Try parsing the new attribute first so userspace
1762 * can specify both for older kernels.
1763 */
1764 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1765 if (nla) {
1766 struct nl80211_sta_flag_update *sta_flags;
1767
1768 sta_flags = nla_data(nla);
1769 params->sta_flags_mask = sta_flags->mask;
1770 params->sta_flags_set = sta_flags->set;
1771 if ((params->sta_flags_mask |
1772 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1773 return -EINVAL;
1774 return 0;
1775 }
1776
1777 /* if present, parse the old attribute */
5727ef1b 1778
eccb8e8f 1779 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1780 if (!nla)
1781 return 0;
1782
1783 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1784 nla, sta_flags_policy))
1785 return -EINVAL;
1786
eccb8e8f
JB
1787 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1788 params->sta_flags_mask &= ~1;
5727ef1b
JB
1789
1790 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1791 if (flags[flag])
eccb8e8f 1792 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1793
1794 return 0;
1795}
1796
fd5b74dc
JB
1797static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1798 int flags, struct net_device *dev,
98b62183 1799 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1800{
1801 void *hdr;
420e7fab
HR
1802 struct nlattr *sinfoattr, *txrate;
1803 u16 bitrate;
fd5b74dc
JB
1804
1805 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1806 if (!hdr)
1807 return -1;
1808
1809 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1810 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1811
f5ea9120
JB
1812 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1813
2ec600d6
LCC
1814 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1815 if (!sinfoattr)
fd5b74dc 1816 goto nla_put_failure;
2ec600d6
LCC
1817 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1818 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1819 sinfo->inactive_time);
1820 if (sinfo->filled & STATION_INFO_RX_BYTES)
1821 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1822 sinfo->rx_bytes);
1823 if (sinfo->filled & STATION_INFO_TX_BYTES)
1824 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1825 sinfo->tx_bytes);
1826 if (sinfo->filled & STATION_INFO_LLID)
1827 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1828 sinfo->llid);
1829 if (sinfo->filled & STATION_INFO_PLID)
1830 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1831 sinfo->plid);
1832 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1833 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1834 sinfo->plink_state);
420e7fab
HR
1835 if (sinfo->filled & STATION_INFO_SIGNAL)
1836 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1837 sinfo->signal);
1838 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1839 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1840 if (!txrate)
1841 goto nla_put_failure;
1842
254416aa
JL
1843 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1844 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
1845 if (bitrate > 0)
1846 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1847
420e7fab
HR
1848 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1849 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1850 sinfo->txrate.mcs);
1851 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1852 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1853 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1854 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1855
1856 nla_nest_end(msg, txrate);
1857 }
98c8a60a
JM
1858 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1859 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1860 sinfo->rx_packets);
1861 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1862 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1863 sinfo->tx_packets);
2ec600d6 1864 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1865
1866 return genlmsg_end(msg, hdr);
1867
1868 nla_put_failure:
bc3ed28c
TG
1869 genlmsg_cancel(msg, hdr);
1870 return -EMSGSIZE;
fd5b74dc
JB
1871}
1872
2ec600d6 1873static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1874 struct netlink_callback *cb)
2ec600d6 1875{
2ec600d6
LCC
1876 struct station_info sinfo;
1877 struct cfg80211_registered_device *dev;
bba95fef 1878 struct net_device *netdev;
2ec600d6 1879 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1880 int ifidx = cb->args[0];
1881 int sta_idx = cb->args[1];
2ec600d6 1882 int err;
2ec600d6 1883
a043897a
HS
1884 if (!ifidx)
1885 ifidx = nl80211_get_ifidx(cb);
1886 if (ifidx < 0)
1887 return ifidx;
2ec600d6 1888
3b85875a
JB
1889 rtnl_lock();
1890
463d0183 1891 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1892 if (!netdev) {
1893 err = -ENODEV;
1894 goto out_rtnl;
1895 }
2ec600d6 1896
463d0183 1897 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1898 if (IS_ERR(dev)) {
1899 err = PTR_ERR(dev);
3b85875a 1900 goto out_rtnl;
bba95fef
JB
1901 }
1902
1903 if (!dev->ops->dump_station) {
eec60b03 1904 err = -EOPNOTSUPP;
bba95fef
JB
1905 goto out_err;
1906 }
1907
bba95fef
JB
1908 while (1) {
1909 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1910 mac_addr, &sinfo);
1911 if (err == -ENOENT)
1912 break;
1913 if (err)
3b85875a 1914 goto out_err;
bba95fef
JB
1915
1916 if (nl80211_send_station(skb,
1917 NETLINK_CB(cb->skb).pid,
1918 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1919 netdev, mac_addr,
1920 &sinfo) < 0)
1921 goto out;
1922
1923 sta_idx++;
1924 }
1925
1926
1927 out:
1928 cb->args[1] = sta_idx;
1929 err = skb->len;
bba95fef 1930 out_err:
4d0c8aea 1931 cfg80211_unlock_rdev(dev);
3b85875a
JB
1932 out_rtnl:
1933 rtnl_unlock();
bba95fef
JB
1934
1935 return err;
2ec600d6 1936}
fd5b74dc 1937
5727ef1b
JB
1938static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1939{
79c97e97 1940 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1941 int err;
1942 struct net_device *dev;
2ec600d6 1943 struct station_info sinfo;
fd5b74dc
JB
1944 struct sk_buff *msg;
1945 u8 *mac_addr = NULL;
1946
2ec600d6 1947 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1948
1949 if (!info->attrs[NL80211_ATTR_MAC])
1950 return -EINVAL;
1951
1952 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1953
3b85875a
JB
1954 rtnl_lock();
1955
463d0183 1956 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 1957 if (err)
3b85875a 1958 goto out_rtnl;
fd5b74dc 1959
79c97e97 1960 if (!rdev->ops->get_station) {
fd5b74dc
JB
1961 err = -EOPNOTSUPP;
1962 goto out;
1963 }
1964
79c97e97 1965 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1966 if (err)
1967 goto out;
1968
fd2120ca 1969 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1970 if (!msg)
1971 goto out;
1972
1973 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1974 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1975 goto out_free;
1976
134e6375 1977 err = genlmsg_reply(msg, info);
fd5b74dc
JB
1978 goto out;
1979
1980 out_free:
1981 nlmsg_free(msg);
fd5b74dc 1982 out:
79c97e97 1983 cfg80211_unlock_rdev(rdev);
fd5b74dc 1984 dev_put(dev);
3b85875a
JB
1985 out_rtnl:
1986 rtnl_unlock();
1987
fd5b74dc 1988 return err;
5727ef1b
JB
1989}
1990
1991/*
c258d2de 1992 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 1993 */
463d0183 1994static int get_vlan(struct genl_info *info,
5727ef1b
JB
1995 struct cfg80211_registered_device *rdev,
1996 struct net_device **vlan)
1997{
463d0183 1998 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
1999 *vlan = NULL;
2000
2001 if (vlanattr) {
463d0183
JB
2002 *vlan = dev_get_by_index(genl_info_net(info),
2003 nla_get_u32(vlanattr));
5727ef1b
JB
2004 if (!*vlan)
2005 return -ENODEV;
2006 if (!(*vlan)->ieee80211_ptr)
2007 return -EINVAL;
2008 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2009 return -EINVAL;
c258d2de
FF
2010 if (!netif_running(*vlan))
2011 return -ENETDOWN;
5727ef1b
JB
2012 }
2013 return 0;
2014}
2015
2016static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2017{
79c97e97 2018 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2019 int err;
2020 struct net_device *dev;
2021 struct station_parameters params;
2022 u8 *mac_addr = NULL;
2023
2024 memset(&params, 0, sizeof(params));
2025
2026 params.listen_interval = -1;
2027
2028 if (info->attrs[NL80211_ATTR_STA_AID])
2029 return -EINVAL;
2030
2031 if (!info->attrs[NL80211_ATTR_MAC])
2032 return -EINVAL;
2033
2034 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2035
2036 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2037 params.supported_rates =
2038 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2039 params.supported_rates_len =
2040 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2041 }
2042
2043 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2044 params.listen_interval =
2045 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2046
36aedc90
JM
2047 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2048 params.ht_capa =
2049 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2050
eccb8e8f 2051 if (parse_station_flags(info, &params))
5727ef1b
JB
2052 return -EINVAL;
2053
2ec600d6
LCC
2054 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2055 params.plink_action =
2056 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2057
3b85875a
JB
2058 rtnl_lock();
2059
463d0183 2060 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2061 if (err)
3b85875a 2062 goto out_rtnl;
5727ef1b 2063
463d0183 2064 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2065 if (err)
034d655e 2066 goto out;
a97f4424
JB
2067
2068 /* validate settings */
2069 err = 0;
2070
2071 switch (dev->ieee80211_ptr->iftype) {
2072 case NL80211_IFTYPE_AP:
2073 case NL80211_IFTYPE_AP_VLAN:
2074 /* disallow mesh-specific things */
2075 if (params.plink_action)
2076 err = -EINVAL;
2077 break;
2078 case NL80211_IFTYPE_STATION:
2079 /* disallow everything but AUTHORIZED flag */
2080 if (params.plink_action)
2081 err = -EINVAL;
2082 if (params.vlan)
2083 err = -EINVAL;
2084 if (params.supported_rates)
2085 err = -EINVAL;
2086 if (params.ht_capa)
2087 err = -EINVAL;
2088 if (params.listen_interval >= 0)
2089 err = -EINVAL;
2090 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2091 err = -EINVAL;
2092 break;
2093 case NL80211_IFTYPE_MESH_POINT:
2094 /* disallow things mesh doesn't support */
2095 if (params.vlan)
2096 err = -EINVAL;
2097 if (params.ht_capa)
2098 err = -EINVAL;
2099 if (params.listen_interval >= 0)
2100 err = -EINVAL;
2101 if (params.supported_rates)
2102 err = -EINVAL;
2103 if (params.sta_flags_mask)
2104 err = -EINVAL;
2105 break;
2106 default:
2107 err = -EINVAL;
034d655e
JB
2108 }
2109
5727ef1b
JB
2110 if (err)
2111 goto out;
2112
79c97e97 2113 if (!rdev->ops->change_station) {
5727ef1b
JB
2114 err = -EOPNOTSUPP;
2115 goto out;
2116 }
2117
79c97e97 2118 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2119
2120 out:
2121 if (params.vlan)
2122 dev_put(params.vlan);
79c97e97 2123 cfg80211_unlock_rdev(rdev);
5727ef1b 2124 dev_put(dev);
3b85875a
JB
2125 out_rtnl:
2126 rtnl_unlock();
2127
5727ef1b
JB
2128 return err;
2129}
2130
2131static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2132{
79c97e97 2133 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2134 int err;
2135 struct net_device *dev;
2136 struct station_parameters params;
2137 u8 *mac_addr = NULL;
2138
2139 memset(&params, 0, sizeof(params));
2140
2141 if (!info->attrs[NL80211_ATTR_MAC])
2142 return -EINVAL;
2143
5727ef1b
JB
2144 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2145 return -EINVAL;
2146
2147 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2148 return -EINVAL;
2149
0e956c13
TLSC
2150 if (!info->attrs[NL80211_ATTR_STA_AID])
2151 return -EINVAL;
2152
5727ef1b
JB
2153 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2154 params.supported_rates =
2155 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2156 params.supported_rates_len =
2157 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2158 params.listen_interval =
2159 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2160
0e956c13
TLSC
2161 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2162 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2163 return -EINVAL;
51b50fbe 2164
36aedc90
JM
2165 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2166 params.ht_capa =
2167 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2168
eccb8e8f 2169 if (parse_station_flags(info, &params))
5727ef1b
JB
2170 return -EINVAL;
2171
3b85875a
JB
2172 rtnl_lock();
2173
463d0183 2174 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2175 if (err)
3b85875a 2176 goto out_rtnl;
5727ef1b 2177
0e956c13
TLSC
2178 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2179 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN) {
2180 err = -EINVAL;
2181 goto out;
2182 }
2183
463d0183 2184 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2185 if (err)
e80cf853 2186 goto out;
a97f4424
JB
2187
2188 /* validate settings */
2189 err = 0;
2190
79c97e97 2191 if (!rdev->ops->add_station) {
5727ef1b
JB
2192 err = -EOPNOTSUPP;
2193 goto out;
2194 }
2195
35a8efe1
JM
2196 if (!netif_running(dev)) {
2197 err = -ENETDOWN;
2198 goto out;
2199 }
2200
79c97e97 2201 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2202
2203 out:
2204 if (params.vlan)
2205 dev_put(params.vlan);
79c97e97 2206 cfg80211_unlock_rdev(rdev);
5727ef1b 2207 dev_put(dev);
3b85875a
JB
2208 out_rtnl:
2209 rtnl_unlock();
2210
5727ef1b
JB
2211 return err;
2212}
2213
2214static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2215{
79c97e97 2216 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2217 int err;
2218 struct net_device *dev;
2219 u8 *mac_addr = NULL;
2220
2221 if (info->attrs[NL80211_ATTR_MAC])
2222 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2223
3b85875a
JB
2224 rtnl_lock();
2225
463d0183 2226 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2227 if (err)
3b85875a 2228 goto out_rtnl;
5727ef1b 2229
e80cf853 2230 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02
MP
2231 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2232 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2233 err = -EINVAL;
2234 goto out;
2235 }
2236
79c97e97 2237 if (!rdev->ops->del_station) {
5727ef1b
JB
2238 err = -EOPNOTSUPP;
2239 goto out;
2240 }
2241
79c97e97 2242 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2243
2244 out:
79c97e97 2245 cfg80211_unlock_rdev(rdev);
5727ef1b 2246 dev_put(dev);
3b85875a
JB
2247 out_rtnl:
2248 rtnl_unlock();
2249
5727ef1b
JB
2250 return err;
2251}
2252
2ec600d6
LCC
2253static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2254 int flags, struct net_device *dev,
2255 u8 *dst, u8 *next_hop,
2256 struct mpath_info *pinfo)
2257{
2258 void *hdr;
2259 struct nlattr *pinfoattr;
2260
2261 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2262 if (!hdr)
2263 return -1;
2264
2265 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2266 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2267 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2268
f5ea9120
JB
2269 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2270
2ec600d6
LCC
2271 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2272 if (!pinfoattr)
2273 goto nla_put_failure;
2274 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2275 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2276 pinfo->frame_qlen);
d19b3bf6
RP
2277 if (pinfo->filled & MPATH_INFO_SN)
2278 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2279 pinfo->sn);
2ec600d6
LCC
2280 if (pinfo->filled & MPATH_INFO_METRIC)
2281 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2282 pinfo->metric);
2283 if (pinfo->filled & MPATH_INFO_EXPTIME)
2284 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2285 pinfo->exptime);
2286 if (pinfo->filled & MPATH_INFO_FLAGS)
2287 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2288 pinfo->flags);
2289 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2290 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2291 pinfo->discovery_timeout);
2292 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2293 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2294 pinfo->discovery_retries);
2295
2296 nla_nest_end(msg, pinfoattr);
2297
2298 return genlmsg_end(msg, hdr);
2299
2300 nla_put_failure:
bc3ed28c
TG
2301 genlmsg_cancel(msg, hdr);
2302 return -EMSGSIZE;
2ec600d6
LCC
2303}
2304
2305static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2306 struct netlink_callback *cb)
2ec600d6 2307{
2ec600d6
LCC
2308 struct mpath_info pinfo;
2309 struct cfg80211_registered_device *dev;
bba95fef 2310 struct net_device *netdev;
2ec600d6
LCC
2311 u8 dst[ETH_ALEN];
2312 u8 next_hop[ETH_ALEN];
bba95fef
JB
2313 int ifidx = cb->args[0];
2314 int path_idx = cb->args[1];
2ec600d6 2315 int err;
2ec600d6 2316
a043897a
HS
2317 if (!ifidx)
2318 ifidx = nl80211_get_ifidx(cb);
2319 if (ifidx < 0)
2320 return ifidx;
bba95fef 2321
3b85875a
JB
2322 rtnl_lock();
2323
463d0183 2324 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2325 if (!netdev) {
2326 err = -ENODEV;
2327 goto out_rtnl;
2328 }
bba95fef 2329
463d0183 2330 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2331 if (IS_ERR(dev)) {
2332 err = PTR_ERR(dev);
3b85875a 2333 goto out_rtnl;
bba95fef
JB
2334 }
2335
2336 if (!dev->ops->dump_mpath) {
eec60b03 2337 err = -EOPNOTSUPP;
bba95fef
JB
2338 goto out_err;
2339 }
2340
eec60b03
JM
2341 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2342 err = -EOPNOTSUPP;
0448b5fc 2343 goto out_err;
eec60b03
JM
2344 }
2345
bba95fef
JB
2346 while (1) {
2347 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2348 dst, next_hop, &pinfo);
2349 if (err == -ENOENT)
2ec600d6 2350 break;
bba95fef 2351 if (err)
3b85875a 2352 goto out_err;
2ec600d6 2353
bba95fef
JB
2354 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2355 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2356 netdev, dst, next_hop,
2357 &pinfo) < 0)
2358 goto out;
2ec600d6 2359
bba95fef 2360 path_idx++;
2ec600d6 2361 }
2ec600d6 2362
2ec600d6 2363
bba95fef
JB
2364 out:
2365 cb->args[1] = path_idx;
2366 err = skb->len;
bba95fef 2367 out_err:
4d0c8aea 2368 cfg80211_unlock_rdev(dev);
3b85875a
JB
2369 out_rtnl:
2370 rtnl_unlock();
bba95fef
JB
2371
2372 return err;
2ec600d6
LCC
2373}
2374
2375static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2376{
79c97e97 2377 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2378 int err;
2379 struct net_device *dev;
2380 struct mpath_info pinfo;
2381 struct sk_buff *msg;
2382 u8 *dst = NULL;
2383 u8 next_hop[ETH_ALEN];
2384
2385 memset(&pinfo, 0, sizeof(pinfo));
2386
2387 if (!info->attrs[NL80211_ATTR_MAC])
2388 return -EINVAL;
2389
2390 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2391
3b85875a
JB
2392 rtnl_lock();
2393
463d0183 2394 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2395 if (err)
3b85875a 2396 goto out_rtnl;
2ec600d6 2397
79c97e97 2398 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2399 err = -EOPNOTSUPP;
2400 goto out;
2401 }
2402
eec60b03
JM
2403 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2404 err = -EOPNOTSUPP;
2405 goto out;
2406 }
2407
79c97e97 2408 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2409 if (err)
2410 goto out;
2411
fd2120ca 2412 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2413 if (!msg)
2414 goto out;
2415
2416 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2417 dev, dst, next_hop, &pinfo) < 0)
2418 goto out_free;
2419
134e6375 2420 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2421 goto out;
2422
2423 out_free:
2424 nlmsg_free(msg);
2ec600d6 2425 out:
79c97e97 2426 cfg80211_unlock_rdev(rdev);
2ec600d6 2427 dev_put(dev);
3b85875a
JB
2428 out_rtnl:
2429 rtnl_unlock();
2430
2ec600d6
LCC
2431 return err;
2432}
2433
2434static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2435{
79c97e97 2436 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2437 int err;
2438 struct net_device *dev;
2439 u8 *dst = NULL;
2440 u8 *next_hop = NULL;
2441
2442 if (!info->attrs[NL80211_ATTR_MAC])
2443 return -EINVAL;
2444
2445 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2446 return -EINVAL;
2447
2448 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2449 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2450
3b85875a
JB
2451 rtnl_lock();
2452
463d0183 2453 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2454 if (err)
3b85875a 2455 goto out_rtnl;
2ec600d6 2456
79c97e97 2457 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2458 err = -EOPNOTSUPP;
2459 goto out;
2460 }
2461
eec60b03
JM
2462 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2463 err = -EOPNOTSUPP;
2464 goto out;
2465 }
2466
35a8efe1
JM
2467 if (!netif_running(dev)) {
2468 err = -ENETDOWN;
2469 goto out;
2470 }
2471
79c97e97 2472 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2473
2474 out:
79c97e97 2475 cfg80211_unlock_rdev(rdev);
2ec600d6 2476 dev_put(dev);
3b85875a
JB
2477 out_rtnl:
2478 rtnl_unlock();
2479
2ec600d6
LCC
2480 return err;
2481}
2482static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2483{
79c97e97 2484 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2485 int err;
2486 struct net_device *dev;
2487 u8 *dst = NULL;
2488 u8 *next_hop = NULL;
2489
2490 if (!info->attrs[NL80211_ATTR_MAC])
2491 return -EINVAL;
2492
2493 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2494 return -EINVAL;
2495
2496 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2497 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2498
3b85875a
JB
2499 rtnl_lock();
2500
463d0183 2501 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2502 if (err)
3b85875a 2503 goto out_rtnl;
2ec600d6 2504
79c97e97 2505 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2506 err = -EOPNOTSUPP;
2507 goto out;
2508 }
2509
eec60b03
JM
2510 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2511 err = -EOPNOTSUPP;
2512 goto out;
2513 }
2514
35a8efe1
JM
2515 if (!netif_running(dev)) {
2516 err = -ENETDOWN;
2517 goto out;
2518 }
2519
79c97e97 2520 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2521
2522 out:
79c97e97 2523 cfg80211_unlock_rdev(rdev);
2ec600d6 2524 dev_put(dev);
3b85875a
JB
2525 out_rtnl:
2526 rtnl_unlock();
2527
2ec600d6
LCC
2528 return err;
2529}
2530
2531static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2532{
79c97e97 2533 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2534 int err;
2535 struct net_device *dev;
2536 u8 *dst = NULL;
2537
2538 if (info->attrs[NL80211_ATTR_MAC])
2539 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2540
3b85875a
JB
2541 rtnl_lock();
2542
463d0183 2543 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2544 if (err)
3b85875a 2545 goto out_rtnl;
2ec600d6 2546
79c97e97 2547 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2548 err = -EOPNOTSUPP;
2549 goto out;
2550 }
2551
79c97e97 2552 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2553
2554 out:
79c97e97 2555 cfg80211_unlock_rdev(rdev);
2ec600d6 2556 dev_put(dev);
3b85875a
JB
2557 out_rtnl:
2558 rtnl_unlock();
2559
2ec600d6
LCC
2560 return err;
2561}
2562
9f1ba906
JM
2563static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2564{
79c97e97 2565 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2566 int err;
2567 struct net_device *dev;
2568 struct bss_parameters params;
2569
2570 memset(&params, 0, sizeof(params));
2571 /* default to not changing parameters */
2572 params.use_cts_prot = -1;
2573 params.use_short_preamble = -1;
2574 params.use_short_slot_time = -1;
fd8aaaf3 2575 params.ap_isolate = -1;
9f1ba906
JM
2576
2577 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2578 params.use_cts_prot =
2579 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2580 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2581 params.use_short_preamble =
2582 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2583 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2584 params.use_short_slot_time =
2585 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2586 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2587 params.basic_rates =
2588 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2589 params.basic_rates_len =
2590 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2591 }
fd8aaaf3
FF
2592 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2593 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
9f1ba906 2594
3b85875a
JB
2595 rtnl_lock();
2596
463d0183 2597 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2598 if (err)
3b85875a 2599 goto out_rtnl;
9f1ba906 2600
79c97e97 2601 if (!rdev->ops->change_bss) {
9f1ba906
JM
2602 err = -EOPNOTSUPP;
2603 goto out;
2604 }
2605
eec60b03
JM
2606 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2607 err = -EOPNOTSUPP;
2608 goto out;
2609 }
2610
79c97e97 2611 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2612
2613 out:
79c97e97 2614 cfg80211_unlock_rdev(rdev);
9f1ba906 2615 dev_put(dev);
3b85875a
JB
2616 out_rtnl:
2617 rtnl_unlock();
2618
9f1ba906
JM
2619 return err;
2620}
2621
b54452b0 2622static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2623 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2624 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2625 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2626 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2627 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2628 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2629};
2630
2631static int parse_reg_rule(struct nlattr *tb[],
2632 struct ieee80211_reg_rule *reg_rule)
2633{
2634 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2635 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2636
2637 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2638 return -EINVAL;
2639 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2640 return -EINVAL;
2641 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2642 return -EINVAL;
2643 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2644 return -EINVAL;
2645 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2646 return -EINVAL;
2647
2648 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2649
2650 freq_range->start_freq_khz =
2651 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2652 freq_range->end_freq_khz =
2653 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2654 freq_range->max_bandwidth_khz =
2655 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2656
2657 power_rule->max_eirp =
2658 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2659
2660 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2661 power_rule->max_antenna_gain =
2662 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2663
2664 return 0;
2665}
2666
2667static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2668{
2669 int r;
2670 char *data = NULL;
2671
80778f18
LR
2672 /*
2673 * You should only get this when cfg80211 hasn't yet initialized
2674 * completely when built-in to the kernel right between the time
2675 * window between nl80211_init() and regulatory_init(), if that is
2676 * even possible.
2677 */
2678 mutex_lock(&cfg80211_mutex);
2679 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2680 mutex_unlock(&cfg80211_mutex);
2681 return -EINPROGRESS;
80778f18 2682 }
fe33eb39 2683 mutex_unlock(&cfg80211_mutex);
80778f18 2684
fe33eb39
LR
2685 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2686 return -EINVAL;
b2e1b302
LR
2687
2688 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2689
fe33eb39
LR
2690 r = regulatory_hint_user(data);
2691
b2e1b302
LR
2692 return r;
2693}
2694
93da9cc1 2695static int nl80211_get_mesh_params(struct sk_buff *skb,
2696 struct genl_info *info)
2697{
79c97e97 2698 struct cfg80211_registered_device *rdev;
93da9cc1 2699 struct mesh_config cur_params;
2700 int err;
2701 struct net_device *dev;
2702 void *hdr;
2703 struct nlattr *pinfoattr;
2704 struct sk_buff *msg;
2705
3b85875a
JB
2706 rtnl_lock();
2707
93da9cc1 2708 /* Look up our device */
463d0183 2709 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2710 if (err)
3b85875a 2711 goto out_rtnl;
93da9cc1 2712
79c97e97 2713 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2714 err = -EOPNOTSUPP;
2715 goto out;
2716 }
2717
93da9cc1 2718 /* Get the mesh params */
79c97e97 2719 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2720 if (err)
2721 goto out;
2722
2723 /* Draw up a netlink message to send back */
fd2120ca 2724 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2725 if (!msg) {
2726 err = -ENOBUFS;
2727 goto out;
2728 }
2729 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2730 NL80211_CMD_GET_MESH_PARAMS);
2731 if (!hdr)
2732 goto nla_put_failure;
2733 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2734 if (!pinfoattr)
2735 goto nla_put_failure;
2736 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2737 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2738 cur_params.dot11MeshRetryTimeout);
2739 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2740 cur_params.dot11MeshConfirmTimeout);
2741 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2742 cur_params.dot11MeshHoldingTimeout);
2743 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2744 cur_params.dot11MeshMaxPeerLinks);
2745 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2746 cur_params.dot11MeshMaxRetries);
2747 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2748 cur_params.dot11MeshTTL);
2749 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2750 cur_params.auto_open_plinks);
2751 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2752 cur_params.dot11MeshHWMPmaxPREQretries);
2753 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2754 cur_params.path_refresh_time);
2755 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2756 cur_params.min_discovery_timeout);
2757 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2758 cur_params.dot11MeshHWMPactivePathTimeout);
2759 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2760 cur_params.dot11MeshHWMPpreqMinInterval);
2761 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2762 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2763 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2764 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2765 nla_nest_end(msg, pinfoattr);
2766 genlmsg_end(msg, hdr);
134e6375 2767 err = genlmsg_reply(msg, info);
93da9cc1 2768 goto out;
2769
3b85875a 2770 nla_put_failure:
93da9cc1 2771 genlmsg_cancel(msg, hdr);
d080e275 2772 nlmsg_free(msg);
93da9cc1 2773 err = -EMSGSIZE;
3b85875a 2774 out:
93da9cc1 2775 /* Cleanup */
79c97e97 2776 cfg80211_unlock_rdev(rdev);
93da9cc1 2777 dev_put(dev);
3b85875a
JB
2778 out_rtnl:
2779 rtnl_unlock();
2780
93da9cc1 2781 return err;
2782}
2783
2784#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2785do {\
2786 if (table[attr_num]) {\
2787 cfg.param = nla_fn(table[attr_num]); \
2788 mask |= (1 << (attr_num - 1)); \
2789 } \
2790} while (0);\
2791
b54452b0 2792static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2793 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2794 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2795 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2796 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2797 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2798 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2799 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2800
2801 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2802 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2803 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2804 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2805 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2806 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2807};
2808
2809static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2810{
2811 int err;
2812 u32 mask;
79c97e97 2813 struct cfg80211_registered_device *rdev;
93da9cc1 2814 struct net_device *dev;
2815 struct mesh_config cfg;
2816 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2817 struct nlattr *parent_attr;
2818
2819 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2820 if (!parent_attr)
2821 return -EINVAL;
2822 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2823 parent_attr, nl80211_meshconf_params_policy))
2824 return -EINVAL;
2825
3b85875a
JB
2826 rtnl_lock();
2827
463d0183 2828 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2829 if (err)
3b85875a 2830 goto out_rtnl;
93da9cc1 2831
79c97e97 2832 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2833 err = -EOPNOTSUPP;
2834 goto out;
2835 }
2836
93da9cc1 2837 /* This makes sure that there aren't more than 32 mesh config
2838 * parameters (otherwise our bitfield scheme would not work.) */
2839 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2840
2841 /* Fill in the params struct */
2842 mask = 0;
2843 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2844 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2845 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2846 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2847 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2848 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2849 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2850 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2851 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2852 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2853 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2854 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2855 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2856 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2857 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2858 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2859 nla_get_u8);
2860 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2861 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2862 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2863 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2864 nla_get_u16);
2865 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2866 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2867 nla_get_u32);
2868 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2869 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2870 nla_get_u16);
2871 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2872 dot11MeshHWMPnetDiameterTraversalTime,
2873 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2874 nla_get_u16);
63c5723b
RP
2875 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2876 dot11MeshHWMPRootMode, mask,
2877 NL80211_MESHCONF_HWMP_ROOTMODE,
2878 nla_get_u8);
93da9cc1 2879
2880 /* Apply changes */
79c97e97 2881 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2882
f3f92586 2883 out:
93da9cc1 2884 /* cleanup */
79c97e97 2885 cfg80211_unlock_rdev(rdev);
93da9cc1 2886 dev_put(dev);
3b85875a
JB
2887 out_rtnl:
2888 rtnl_unlock();
2889
93da9cc1 2890 return err;
2891}
2892
2893#undef FILL_IN_MESH_PARAM_IF_SET
2894
f130347c
LR
2895static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2896{
2897 struct sk_buff *msg;
2898 void *hdr = NULL;
2899 struct nlattr *nl_reg_rules;
2900 unsigned int i;
2901 int err = -EINVAL;
2902
a1794390 2903 mutex_lock(&cfg80211_mutex);
f130347c
LR
2904
2905 if (!cfg80211_regdomain)
2906 goto out;
2907
fd2120ca 2908 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2909 if (!msg) {
2910 err = -ENOBUFS;
2911 goto out;
2912 }
2913
2914 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2915 NL80211_CMD_GET_REG);
2916 if (!hdr)
2917 goto nla_put_failure;
2918
2919 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2920 cfg80211_regdomain->alpha2);
2921
2922 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2923 if (!nl_reg_rules)
2924 goto nla_put_failure;
2925
2926 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2927 struct nlattr *nl_reg_rule;
2928 const struct ieee80211_reg_rule *reg_rule;
2929 const struct ieee80211_freq_range *freq_range;
2930 const struct ieee80211_power_rule *power_rule;
2931
2932 reg_rule = &cfg80211_regdomain->reg_rules[i];
2933 freq_range = &reg_rule->freq_range;
2934 power_rule = &reg_rule->power_rule;
2935
2936 nl_reg_rule = nla_nest_start(msg, i);
2937 if (!nl_reg_rule)
2938 goto nla_put_failure;
2939
2940 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2941 reg_rule->flags);
2942 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2943 freq_range->start_freq_khz);
2944 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2945 freq_range->end_freq_khz);
2946 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2947 freq_range->max_bandwidth_khz);
2948 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2949 power_rule->max_antenna_gain);
2950 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2951 power_rule->max_eirp);
2952
2953 nla_nest_end(msg, nl_reg_rule);
2954 }
2955
2956 nla_nest_end(msg, nl_reg_rules);
2957
2958 genlmsg_end(msg, hdr);
134e6375 2959 err = genlmsg_reply(msg, info);
f130347c
LR
2960 goto out;
2961
2962nla_put_failure:
2963 genlmsg_cancel(msg, hdr);
d080e275 2964 nlmsg_free(msg);
f130347c
LR
2965 err = -EMSGSIZE;
2966out:
a1794390 2967 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2968 return err;
2969}
2970
b2e1b302
LR
2971static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2972{
2973 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2974 struct nlattr *nl_reg_rule;
2975 char *alpha2 = NULL;
2976 int rem_reg_rules = 0, r = 0;
2977 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2978 struct ieee80211_regdomain *rd = NULL;
2979
2980 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2981 return -EINVAL;
2982
2983 if (!info->attrs[NL80211_ATTR_REG_RULES])
2984 return -EINVAL;
2985
2986 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2987
2988 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2989 rem_reg_rules) {
2990 num_rules++;
2991 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2992 return -EINVAL;
b2e1b302
LR
2993 }
2994
61405e97
LR
2995 mutex_lock(&cfg80211_mutex);
2996
d0e18f83
LR
2997 if (!reg_is_valid_request(alpha2)) {
2998 r = -EINVAL;
2999 goto bad_reg;
3000 }
b2e1b302
LR
3001
3002 size_of_regd = sizeof(struct ieee80211_regdomain) +
3003 (num_rules * sizeof(struct ieee80211_reg_rule));
3004
3005 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3006 if (!rd) {
3007 r = -ENOMEM;
3008 goto bad_reg;
3009 }
b2e1b302
LR
3010
3011 rd->n_reg_rules = num_rules;
3012 rd->alpha2[0] = alpha2[0];
3013 rd->alpha2[1] = alpha2[1];
3014
3015 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3016 rem_reg_rules) {
3017 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3018 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3019 reg_rule_policy);
3020 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3021 if (r)
3022 goto bad_reg;
3023
3024 rule_idx++;
3025
d0e18f83
LR
3026 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3027 r = -EINVAL;
b2e1b302 3028 goto bad_reg;
d0e18f83 3029 }
b2e1b302
LR
3030 }
3031
3032 BUG_ON(rule_idx != num_rules);
3033
b2e1b302 3034 r = set_regdom(rd);
61405e97 3035
a1794390 3036 mutex_unlock(&cfg80211_mutex);
d0e18f83 3037
b2e1b302
LR
3038 return r;
3039
d2372b31 3040 bad_reg:
61405e97 3041 mutex_unlock(&cfg80211_mutex);
b2e1b302 3042 kfree(rd);
d0e18f83 3043 return r;
b2e1b302
LR
3044}
3045
83f5e2cf
JB
3046static int validate_scan_freqs(struct nlattr *freqs)
3047{
3048 struct nlattr *attr1, *attr2;
3049 int n_channels = 0, tmp1, tmp2;
3050
3051 nla_for_each_nested(attr1, freqs, tmp1) {
3052 n_channels++;
3053 /*
3054 * Some hardware has a limited channel list for
3055 * scanning, and it is pretty much nonsensical
3056 * to scan for a channel twice, so disallow that
3057 * and don't require drivers to check that the
3058 * channel list they get isn't longer than what
3059 * they can scan, as long as they can scan all
3060 * the channels they registered at once.
3061 */
3062 nla_for_each_nested(attr2, freqs, tmp2)
3063 if (attr1 != attr2 &&
3064 nla_get_u32(attr1) == nla_get_u32(attr2))
3065 return 0;
3066 }
3067
3068 return n_channels;
3069}
3070
2a519311
JB
3071static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3072{
79c97e97 3073 struct cfg80211_registered_device *rdev;
2a519311
JB
3074 struct net_device *dev;
3075 struct cfg80211_scan_request *request;
3076 struct cfg80211_ssid *ssid;
3077 struct ieee80211_channel *channel;
3078 struct nlattr *attr;
3079 struct wiphy *wiphy;
83f5e2cf 3080 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3081 enum ieee80211_band band;
70692ad2 3082 size_t ie_len;
2a519311 3083
f4a11bb0
JB
3084 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3085 return -EINVAL;
3086
3b85875a
JB
3087 rtnl_lock();
3088
463d0183 3089 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 3090 if (err)
3b85875a 3091 goto out_rtnl;
2a519311 3092
79c97e97 3093 wiphy = &rdev->wiphy;
2a519311 3094
79c97e97 3095 if (!rdev->ops->scan) {
2a519311
JB
3096 err = -EOPNOTSUPP;
3097 goto out;
3098 }
3099
35a8efe1
JM
3100 if (!netif_running(dev)) {
3101 err = -ENETDOWN;
3102 goto out;
3103 }
3104
79c97e97 3105 if (rdev->scan_req) {
2a519311 3106 err = -EBUSY;
3b85875a 3107 goto out;
2a519311
JB
3108 }
3109
3110 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3111 n_channels = validate_scan_freqs(
3112 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
3113 if (!n_channels) {
3114 err = -EINVAL;
3b85875a 3115 goto out;
2a519311
JB
3116 }
3117 } else {
83f5e2cf
JB
3118 n_channels = 0;
3119
2a519311
JB
3120 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3121 if (wiphy->bands[band])
3122 n_channels += wiphy->bands[band]->n_channels;
3123 }
3124
3125 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3126 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3127 n_ssids++;
3128
3129 if (n_ssids > wiphy->max_scan_ssids) {
3130 err = -EINVAL;
3b85875a 3131 goto out;
2a519311
JB
3132 }
3133
70692ad2
JM
3134 if (info->attrs[NL80211_ATTR_IE])
3135 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3136 else
3137 ie_len = 0;
3138
18a83659
JB
3139 if (ie_len > wiphy->max_scan_ie_len) {
3140 err = -EINVAL;
3141 goto out;
3142 }
3143
2a519311
JB
3144 request = kzalloc(sizeof(*request)
3145 + sizeof(*ssid) * n_ssids
70692ad2
JM
3146 + sizeof(channel) * n_channels
3147 + ie_len, GFP_KERNEL);
2a519311
JB
3148 if (!request) {
3149 err = -ENOMEM;
3b85875a 3150 goto out;
2a519311
JB
3151 }
3152
2a519311 3153 if (n_ssids)
5ba63533 3154 request->ssids = (void *)&request->channels[n_channels];
2a519311 3155 request->n_ssids = n_ssids;
70692ad2
JM
3156 if (ie_len) {
3157 if (request->ssids)
3158 request->ie = (void *)(request->ssids + n_ssids);
3159 else
3160 request->ie = (void *)(request->channels + n_channels);
3161 }
2a519311 3162
584991dc 3163 i = 0;
2a519311
JB
3164 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3165 /* user specified, bail out if channel not found */
2a519311 3166 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3167 struct ieee80211_channel *chan;
3168
3169 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3170
3171 if (!chan) {
2a519311
JB
3172 err = -EINVAL;
3173 goto out_free;
3174 }
584991dc
JB
3175
3176 /* ignore disabled channels */
3177 if (chan->flags & IEEE80211_CHAN_DISABLED)
3178 continue;
3179
3180 request->channels[i] = chan;
2a519311
JB
3181 i++;
3182 }
3183 } else {
3184 /* all channels */
2a519311
JB
3185 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3186 int j;
3187 if (!wiphy->bands[band])
3188 continue;
3189 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3190 struct ieee80211_channel *chan;
3191
3192 chan = &wiphy->bands[band]->channels[j];
3193
3194 if (chan->flags & IEEE80211_CHAN_DISABLED)
3195 continue;
3196
3197 request->channels[i] = chan;
2a519311
JB
3198 i++;
3199 }
3200 }
3201 }
3202
584991dc
JB
3203 if (!i) {
3204 err = -EINVAL;
3205 goto out_free;
3206 }
3207
3208 request->n_channels = i;
3209
2a519311
JB
3210 i = 0;
3211 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3212 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3213 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3214 err = -EINVAL;
3215 goto out_free;
3216 }
3217 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3218 request->ssids[i].ssid_len = nla_len(attr);
3219 i++;
3220 }
3221 }
3222
70692ad2
JM
3223 if (info->attrs[NL80211_ATTR_IE]) {
3224 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3225 memcpy((void *)request->ie,
3226 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3227 request->ie_len);
3228 }
3229
463d0183 3230 request->dev = dev;
79c97e97 3231 request->wiphy = &rdev->wiphy;
2a519311 3232
79c97e97
JB
3233 rdev->scan_req = request;
3234 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3235
463d0183 3236 if (!err) {
79c97e97 3237 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3238 dev_hold(dev);
3239 }
a538e2d5 3240
2a519311
JB
3241 out_free:
3242 if (err) {
79c97e97 3243 rdev->scan_req = NULL;
2a519311
JB
3244 kfree(request);
3245 }
2a519311 3246 out:
79c97e97 3247 cfg80211_unlock_rdev(rdev);
2a519311 3248 dev_put(dev);
3b85875a
JB
3249 out_rtnl:
3250 rtnl_unlock();
3251
2a519311
JB
3252 return err;
3253}
3254
3255static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3256 struct cfg80211_registered_device *rdev,
48ab905d
JB
3257 struct wireless_dev *wdev,
3258 struct cfg80211_internal_bss *intbss)
2a519311 3259{
48ab905d 3260 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3261 void *hdr;
3262 struct nlattr *bss;
48ab905d
JB
3263 int i;
3264
3265 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3266
3267 hdr = nl80211hdr_put(msg, pid, seq, flags,
3268 NL80211_CMD_NEW_SCAN_RESULTS);
3269 if (!hdr)
3270 return -1;
3271
f5ea9120 3272 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3273 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3274
3275 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3276 if (!bss)
3277 goto nla_put_failure;
3278 if (!is_zero_ether_addr(res->bssid))
3279 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3280 if (res->information_elements && res->len_information_elements)
3281 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3282 res->len_information_elements,
3283 res->information_elements);
34a6eddb
JM
3284 if (res->beacon_ies && res->len_beacon_ies &&
3285 res->beacon_ies != res->information_elements)
3286 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3287 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3288 if (res->tsf)
3289 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3290 if (res->beacon_interval)
3291 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3292 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3293 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3294 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3295 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3296
77965c97 3297 switch (rdev->wiphy.signal_type) {
2a519311
JB
3298 case CFG80211_SIGNAL_TYPE_MBM:
3299 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3300 break;
3301 case CFG80211_SIGNAL_TYPE_UNSPEC:
3302 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3303 break;
3304 default:
3305 break;
3306 }
3307
48ab905d
JB
3308 switch (wdev->iftype) {
3309 case NL80211_IFTYPE_STATION:
3310 if (intbss == wdev->current_bss)
3311 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3312 NL80211_BSS_STATUS_ASSOCIATED);
3313 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3314 if (intbss != wdev->auth_bsses[i])
3315 continue;
3316 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3317 NL80211_BSS_STATUS_AUTHENTICATED);
3318 break;
3319 }
3320 break;
3321 case NL80211_IFTYPE_ADHOC:
3322 if (intbss == wdev->current_bss)
3323 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3324 NL80211_BSS_STATUS_IBSS_JOINED);
3325 break;
3326 default:
3327 break;
3328 }
3329
2a519311
JB
3330 nla_nest_end(msg, bss);
3331
3332 return genlmsg_end(msg, hdr);
3333
3334 nla_put_failure:
3335 genlmsg_cancel(msg, hdr);
3336 return -EMSGSIZE;
3337}
3338
3339static int nl80211_dump_scan(struct sk_buff *skb,
3340 struct netlink_callback *cb)
3341{
48ab905d
JB
3342 struct cfg80211_registered_device *rdev;
3343 struct net_device *dev;
2a519311 3344 struct cfg80211_internal_bss *scan;
48ab905d 3345 struct wireless_dev *wdev;
2a519311
JB
3346 int ifidx = cb->args[0];
3347 int start = cb->args[1], idx = 0;
3348 int err;
3349
a043897a
HS
3350 if (!ifidx)
3351 ifidx = nl80211_get_ifidx(cb);
3352 if (ifidx < 0)
3353 return ifidx;
3354 cb->args[0] = ifidx;
2a519311 3355
463d0183 3356 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3357 if (!dev)
2a519311
JB
3358 return -ENODEV;
3359
463d0183 3360 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3361 if (IS_ERR(rdev)) {
3362 err = PTR_ERR(rdev);
2a519311
JB
3363 goto out_put_netdev;
3364 }
3365
48ab905d 3366 wdev = dev->ieee80211_ptr;
2a519311 3367
48ab905d
JB
3368 wdev_lock(wdev);
3369 spin_lock_bh(&rdev->bss_lock);
3370 cfg80211_bss_expire(rdev);
3371
3372 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3373 if (++idx <= start)
3374 continue;
3375 if (nl80211_send_bss(skb,
3376 NETLINK_CB(cb->skb).pid,
3377 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3378 rdev, wdev, scan) < 0) {
2a519311
JB
3379 idx--;
3380 goto out;
3381 }
3382 }
3383
3384 out:
48ab905d
JB
3385 spin_unlock_bh(&rdev->bss_lock);
3386 wdev_unlock(wdev);
2a519311
JB
3387
3388 cb->args[1] = idx;
3389 err = skb->len;
48ab905d 3390 cfg80211_unlock_rdev(rdev);
2a519311 3391 out_put_netdev:
48ab905d 3392 dev_put(dev);
2a519311
JB
3393
3394 return err;
3395}
3396
61fa713c
HS
3397static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3398 int flags, struct net_device *dev,
3399 struct survey_info *survey)
3400{
3401 void *hdr;
3402 struct nlattr *infoattr;
3403
3404 /* Survey without a channel doesn't make sense */
3405 if (!survey->channel)
3406 return -EINVAL;
3407
3408 hdr = nl80211hdr_put(msg, pid, seq, flags,
3409 NL80211_CMD_NEW_SURVEY_RESULTS);
3410 if (!hdr)
3411 return -ENOMEM;
3412
3413 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3414
3415 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3416 if (!infoattr)
3417 goto nla_put_failure;
3418
3419 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3420 survey->channel->center_freq);
3421 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3422 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3423 survey->noise);
3424
3425 nla_nest_end(msg, infoattr);
3426
3427 return genlmsg_end(msg, hdr);
3428
3429 nla_put_failure:
3430 genlmsg_cancel(msg, hdr);
3431 return -EMSGSIZE;
3432}
3433
3434static int nl80211_dump_survey(struct sk_buff *skb,
3435 struct netlink_callback *cb)
3436{
3437 struct survey_info survey;
3438 struct cfg80211_registered_device *dev;
3439 struct net_device *netdev;
3440 int ifidx = cb->args[0];
3441 int survey_idx = cb->args[1];
3442 int res;
3443
3444 if (!ifidx)
3445 ifidx = nl80211_get_ifidx(cb);
3446 if (ifidx < 0)
3447 return ifidx;
3448 cb->args[0] = ifidx;
3449
3450 rtnl_lock();
3451
3452 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3453 if (!netdev) {
3454 res = -ENODEV;
3455 goto out_rtnl;
3456 }
3457
3458 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3459 if (IS_ERR(dev)) {
3460 res = PTR_ERR(dev);
3461 goto out_rtnl;
3462 }
3463
3464 if (!dev->ops->dump_survey) {
3465 res = -EOPNOTSUPP;
3466 goto out_err;
3467 }
3468
3469 while (1) {
3470 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3471 &survey);
3472 if (res == -ENOENT)
3473 break;
3474 if (res)
3475 goto out_err;
3476
3477 if (nl80211_send_survey(skb,
3478 NETLINK_CB(cb->skb).pid,
3479 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3480 netdev,
3481 &survey) < 0)
3482 goto out;
3483 survey_idx++;
3484 }
3485
3486 out:
3487 cb->args[1] = survey_idx;
3488 res = skb->len;
3489 out_err:
3490 cfg80211_unlock_rdev(dev);
3491 out_rtnl:
3492 rtnl_unlock();
3493
3494 return res;
3495}
3496
255e737e
JM
3497static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3498{
b23aa676
SO
3499 return auth_type <= NL80211_AUTHTYPE_MAX;
3500}
3501
3502static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3503{
3504 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3505 NL80211_WPA_VERSION_2));
3506}
3507
3508static bool nl80211_valid_akm_suite(u32 akm)
3509{
3510 return akm == WLAN_AKM_SUITE_8021X ||
3511 akm == WLAN_AKM_SUITE_PSK;
3512}
3513
3514static bool nl80211_valid_cipher_suite(u32 cipher)
3515{
3516 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3517 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3518 cipher == WLAN_CIPHER_SUITE_TKIP ||
3519 cipher == WLAN_CIPHER_SUITE_CCMP ||
3520 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3521}
3522
b23aa676 3523
636a5d36
JM
3524static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3525{
79c97e97 3526 struct cfg80211_registered_device *rdev;
636a5d36 3527 struct net_device *dev;
19957bb3
JB
3528 struct ieee80211_channel *chan;
3529 const u8 *bssid, *ssid, *ie = NULL;
3530 int err, ssid_len, ie_len = 0;
3531 enum nl80211_auth_type auth_type;
fffd0934 3532 struct key_parse key;
d5cdfacb 3533 bool local_state_change;
636a5d36 3534
f4a11bb0
JB
3535 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3536 return -EINVAL;
3537
3538 if (!info->attrs[NL80211_ATTR_MAC])
3539 return -EINVAL;
3540
1778092e
JM
3541 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3542 return -EINVAL;
3543
19957bb3
JB
3544 if (!info->attrs[NL80211_ATTR_SSID])
3545 return -EINVAL;
3546
3547 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3548 return -EINVAL;
3549
fffd0934
JB
3550 err = nl80211_parse_key(info, &key);
3551 if (err)
3552 return err;
3553
3554 if (key.idx >= 0) {
3555 if (!key.p.key || !key.p.key_len)
3556 return -EINVAL;
3557 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3558 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3559 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3560 key.p.key_len != WLAN_KEY_LEN_WEP104))
3561 return -EINVAL;
3562 if (key.idx > 4)
3563 return -EINVAL;
3564 } else {
3565 key.p.key_len = 0;
3566 key.p.key = NULL;
3567 }
3568
636a5d36
JM
3569 rtnl_lock();
3570
463d0183 3571 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3572 if (err)
3573 goto unlock_rtnl;
3574
afea0b7a
JB
3575 if (key.idx >= 0) {
3576 int i;
3577 bool ok = false;
3578 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3579 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3580 ok = true;
3581 break;
3582 }
3583 }
3584 if (!ok) {
3585 err = -EINVAL;
3586 goto out;
3587 }
3588 }
3589
79c97e97 3590 if (!rdev->ops->auth) {
636a5d36
JM
3591 err = -EOPNOTSUPP;
3592 goto out;
3593 }
3594
eec60b03
JM
3595 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3596 err = -EOPNOTSUPP;
3597 goto out;
3598 }
3599
35a8efe1
JM
3600 if (!netif_running(dev)) {
3601 err = -ENETDOWN;
3602 goto out;
3603 }
3604
19957bb3 3605 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3606 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3607 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3608 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3609 err = -EINVAL;
3610 goto out;
636a5d36
JM
3611 }
3612
19957bb3
JB
3613 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3614 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3615
3616 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3617 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3618 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3619 }
3620
19957bb3
JB
3621 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3622 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3623 err = -EINVAL;
3624 goto out;
636a5d36
JM
3625 }
3626
d5cdfacb
JM
3627 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3628
79c97e97 3629 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934 3630 ssid, ssid_len, ie, ie_len,
d5cdfacb
JM
3631 key.p.key, key.p.key_len, key.idx,
3632 local_state_change);
636a5d36
JM
3633
3634out:
79c97e97 3635 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3636 dev_put(dev);
3637unlock_rtnl:
3638 rtnl_unlock();
3639 return err;
3640}
3641
b23aa676 3642static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3643 struct cfg80211_crypto_settings *settings,
3644 int cipher_limit)
b23aa676 3645{
c0b2bbd8
JB
3646 memset(settings, 0, sizeof(*settings));
3647
b23aa676
SO
3648 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3649
3650 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3651 void *data;
3652 int len, i;
3653
3654 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3655 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3656 settings->n_ciphers_pairwise = len / sizeof(u32);
3657
3658 if (len % sizeof(u32))
3659 return -EINVAL;
3660
3dc27d25 3661 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3662 return -EINVAL;
3663
3664 memcpy(settings->ciphers_pairwise, data, len);
3665
3666 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3667 if (!nl80211_valid_cipher_suite(
3668 settings->ciphers_pairwise[i]))
3669 return -EINVAL;
3670 }
3671
3672 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3673 settings->cipher_group =
3674 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3675 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3676 return -EINVAL;
3677 }
3678
3679 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3680 settings->wpa_versions =
3681 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3682 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3683 return -EINVAL;
3684 }
3685
3686 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3687 void *data;
3688 int len, i;
3689
3690 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3691 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3692 settings->n_akm_suites = len / sizeof(u32);
3693
3694 if (len % sizeof(u32))
3695 return -EINVAL;
3696
3697 memcpy(settings->akm_suites, data, len);
3698
3699 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3700 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3701 return -EINVAL;
3702 }
3703
3704 return 0;
3705}
3706
636a5d36
JM
3707static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3708{
19957bb3 3709 struct cfg80211_registered_device *rdev;
636a5d36 3710 struct net_device *dev;
19957bb3 3711 struct cfg80211_crypto_settings crypto;
f444de05 3712 struct ieee80211_channel *chan;
3e5d7649 3713 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3714 int err, ssid_len, ie_len = 0;
3715 bool use_mfp = false;
636a5d36 3716
f4a11bb0
JB
3717 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3718 return -EINVAL;
3719
3720 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3721 !info->attrs[NL80211_ATTR_SSID] ||
3722 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3723 return -EINVAL;
3724
636a5d36
JM
3725 rtnl_lock();
3726
463d0183 3727 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3728 if (err)
3729 goto unlock_rtnl;
3730
19957bb3 3731 if (!rdev->ops->assoc) {
636a5d36
JM
3732 err = -EOPNOTSUPP;
3733 goto out;
3734 }
3735
eec60b03
JM
3736 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3737 err = -EOPNOTSUPP;
3738 goto out;
3739 }
3740
35a8efe1
JM
3741 if (!netif_running(dev)) {
3742 err = -ENETDOWN;
3743 goto out;
3744 }
3745
19957bb3 3746 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3747
19957bb3
JB
3748 chan = ieee80211_get_channel(&rdev->wiphy,
3749 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3750 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3751 err = -EINVAL;
3752 goto out;
636a5d36
JM
3753 }
3754
19957bb3
JB
3755 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3756 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3757
3758 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3759 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3760 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3761 }
3762
dc6382ce 3763 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3764 enum nl80211_mfp mfp =
dc6382ce 3765 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3766 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3767 use_mfp = true;
4f5dadce 3768 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3769 err = -EINVAL;
3770 goto out;
3771 }
3772 }
3773
3e5d7649
JB
3774 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3775 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3776
3dc27d25 3777 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3778 if (!err)
3e5d7649
JB
3779 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3780 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3781 &crypto);
636a5d36
JM
3782
3783out:
4d0c8aea 3784 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3785 dev_put(dev);
3786unlock_rtnl:
3787 rtnl_unlock();
3788 return err;
3789}
3790
3791static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3792{
79c97e97 3793 struct cfg80211_registered_device *rdev;
636a5d36 3794 struct net_device *dev;
19957bb3
JB
3795 const u8 *ie = NULL, *bssid;
3796 int err, ie_len = 0;
3797 u16 reason_code;
d5cdfacb 3798 bool local_state_change;
636a5d36 3799
f4a11bb0
JB
3800 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3801 return -EINVAL;
3802
3803 if (!info->attrs[NL80211_ATTR_MAC])
3804 return -EINVAL;
3805
3806 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3807 return -EINVAL;
3808
636a5d36
JM
3809 rtnl_lock();
3810
463d0183 3811 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3812 if (err)
3813 goto unlock_rtnl;
3814
79c97e97 3815 if (!rdev->ops->deauth) {
636a5d36
JM
3816 err = -EOPNOTSUPP;
3817 goto out;
3818 }
3819
eec60b03
JM
3820 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3821 err = -EOPNOTSUPP;
3822 goto out;
3823 }
3824
35a8efe1
JM
3825 if (!netif_running(dev)) {
3826 err = -ENETDOWN;
3827 goto out;
3828 }
3829
19957bb3 3830 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3831
19957bb3
JB
3832 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3833 if (reason_code == 0) {
f4a11bb0
JB
3834 /* Reason Code 0 is reserved */
3835 err = -EINVAL;
3836 goto out;
255e737e 3837 }
636a5d36
JM
3838
3839 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3840 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3841 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3842 }
3843
d5cdfacb
JM
3844 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3845
3846 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3847 local_state_change);
636a5d36
JM
3848
3849out:
79c97e97 3850 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3851 dev_put(dev);
3852unlock_rtnl:
3853 rtnl_unlock();
3854 return err;
3855}
3856
3857static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3858{
79c97e97 3859 struct cfg80211_registered_device *rdev;
636a5d36 3860 struct net_device *dev;
19957bb3
JB
3861 const u8 *ie = NULL, *bssid;
3862 int err, ie_len = 0;
3863 u16 reason_code;
d5cdfacb 3864 bool local_state_change;
636a5d36 3865
f4a11bb0
JB
3866 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3867 return -EINVAL;
3868
3869 if (!info->attrs[NL80211_ATTR_MAC])
3870 return -EINVAL;
3871
3872 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3873 return -EINVAL;
3874
636a5d36
JM
3875 rtnl_lock();
3876
463d0183 3877 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3878 if (err)
3879 goto unlock_rtnl;
3880
79c97e97 3881 if (!rdev->ops->disassoc) {
636a5d36
JM
3882 err = -EOPNOTSUPP;
3883 goto out;
3884 }
3885
eec60b03
JM
3886 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3887 err = -EOPNOTSUPP;
3888 goto out;
3889 }
3890
35a8efe1
JM
3891 if (!netif_running(dev)) {
3892 err = -ENETDOWN;
3893 goto out;
3894 }
3895
19957bb3 3896 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3897
19957bb3
JB
3898 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3899 if (reason_code == 0) {
f4a11bb0
JB
3900 /* Reason Code 0 is reserved */
3901 err = -EINVAL;
3902 goto out;
255e737e 3903 }
636a5d36
JM
3904
3905 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3906 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3907 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3908 }
3909
d5cdfacb
JM
3910 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3911
3912 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3913 local_state_change);
636a5d36
JM
3914
3915out:
79c97e97 3916 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3917 dev_put(dev);
3918unlock_rtnl:
3919 rtnl_unlock();
3920 return err;
3921}
3922
04a773ad
JB
3923static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3924{
79c97e97 3925 struct cfg80211_registered_device *rdev;
04a773ad
JB
3926 struct net_device *dev;
3927 struct cfg80211_ibss_params ibss;
3928 struct wiphy *wiphy;
fffd0934 3929 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3930 int err;
3931
8e30bc55
JB
3932 memset(&ibss, 0, sizeof(ibss));
3933
04a773ad
JB
3934 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3935 return -EINVAL;
3936
3937 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3938 !info->attrs[NL80211_ATTR_SSID] ||
3939 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3940 return -EINVAL;
3941
8e30bc55
JB
3942 ibss.beacon_interval = 100;
3943
3944 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3945 ibss.beacon_interval =
3946 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3947 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3948 return -EINVAL;
3949 }
3950
04a773ad
JB
3951 rtnl_lock();
3952
463d0183 3953 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3954 if (err)
3955 goto unlock_rtnl;
3956
79c97e97 3957 if (!rdev->ops->join_ibss) {
04a773ad
JB
3958 err = -EOPNOTSUPP;
3959 goto out;
3960 }
3961
3962 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3963 err = -EOPNOTSUPP;
3964 goto out;
3965 }
3966
3967 if (!netif_running(dev)) {
3968 err = -ENETDOWN;
3969 goto out;
3970 }
3971
79c97e97 3972 wiphy = &rdev->wiphy;
04a773ad
JB
3973
3974 if (info->attrs[NL80211_ATTR_MAC])
3975 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3976 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3977 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3978
3979 if (info->attrs[NL80211_ATTR_IE]) {
3980 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3981 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3982 }
3983
3984 ibss.channel = ieee80211_get_channel(wiphy,
3985 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3986 if (!ibss.channel ||
3987 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3988 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3989 err = -EINVAL;
3990 goto out;
3991 }
3992
3993 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3994 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3995
3996 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3997 connkeys = nl80211_parse_connkeys(rdev,
3998 info->attrs[NL80211_ATTR_KEYS]);
3999 if (IS_ERR(connkeys)) {
4000 err = PTR_ERR(connkeys);
4001 connkeys = NULL;
4002 goto out;
4003 }
4004 }
04a773ad 4005
fbd2c8dc
TP
4006 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4007 u8 *rates =
4008 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4009 int n_rates =
4010 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4011 struct ieee80211_supported_band *sband =
4012 wiphy->bands[ibss.channel->band];
4013 int i, j;
4014
4015 if (n_rates == 0) {
4016 err = -EINVAL;
4017 goto out;
4018 }
4019
4020 for (i = 0; i < n_rates; i++) {
4021 int rate = (rates[i] & 0x7f) * 5;
4022 bool found = false;
4023
4024 for (j = 0; j < sband->n_bitrates; j++) {
4025 if (sband->bitrates[j].bitrate == rate) {
4026 found = true;
4027 ibss.basic_rates |= BIT(j);
4028 break;
4029 }
4030 }
4031 if (!found) {
4032 err = -EINVAL;
4033 goto out;
4034 }
4035 }
4036 } else {
4037 /*
4038 * If no rates were explicitly configured,
4039 * use the mandatory rate set for 11b or
4040 * 11a for maximum compatibility.
4041 */
4042 struct ieee80211_supported_band *sband =
4043 wiphy->bands[ibss.channel->band];
4044 int j;
4045 u32 flag = ibss.channel->band == IEEE80211_BAND_5GHZ ?
4046 IEEE80211_RATE_MANDATORY_A :
4047 IEEE80211_RATE_MANDATORY_B;
4048
4049 for (j = 0; j < sband->n_bitrates; j++) {
4050 if (sband->bitrates[j].flags & flag)
4051 ibss.basic_rates |= BIT(j);
4052 }
4053 }
4054
fffd0934 4055 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
4056
4057out:
79c97e97 4058 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4059 dev_put(dev);
4060unlock_rtnl:
fffd0934
JB
4061 if (err)
4062 kfree(connkeys);
04a773ad
JB
4063 rtnl_unlock();
4064 return err;
4065}
4066
4067static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4068{
79c97e97 4069 struct cfg80211_registered_device *rdev;
04a773ad
JB
4070 struct net_device *dev;
4071 int err;
4072
4073 rtnl_lock();
4074
463d0183 4075 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
4076 if (err)
4077 goto unlock_rtnl;
4078
79c97e97 4079 if (!rdev->ops->leave_ibss) {
04a773ad
JB
4080 err = -EOPNOTSUPP;
4081 goto out;
4082 }
4083
4084 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4085 err = -EOPNOTSUPP;
4086 goto out;
4087 }
4088
4089 if (!netif_running(dev)) {
4090 err = -ENETDOWN;
4091 goto out;
4092 }
4093
79c97e97 4094 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4095
4096out:
79c97e97 4097 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4098 dev_put(dev);
4099unlock_rtnl:
4100 rtnl_unlock();
4101 return err;
4102}
4103
aff89a9b
JB
4104#ifdef CONFIG_NL80211_TESTMODE
4105static struct genl_multicast_group nl80211_testmode_mcgrp = {
4106 .name = "testmode",
4107};
4108
4109static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4110{
4111 struct cfg80211_registered_device *rdev;
4112 int err;
4113
4114 if (!info->attrs[NL80211_ATTR_TESTDATA])
4115 return -EINVAL;
4116
4117 rtnl_lock();
4118
4119 rdev = cfg80211_get_dev_from_info(info);
4120 if (IS_ERR(rdev)) {
4121 err = PTR_ERR(rdev);
4122 goto unlock_rtnl;
4123 }
4124
4125 err = -EOPNOTSUPP;
4126 if (rdev->ops->testmode_cmd) {
4127 rdev->testmode_info = info;
4128 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4129 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4130 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4131 rdev->testmode_info = NULL;
4132 }
4133
4d0c8aea 4134 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
4135
4136 unlock_rtnl:
4137 rtnl_unlock();
4138 return err;
4139}
4140
4141static struct sk_buff *
4142__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4143 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4144{
4145 struct sk_buff *skb;
4146 void *hdr;
4147 struct nlattr *data;
4148
4149 skb = nlmsg_new(approxlen + 100, gfp);
4150 if (!skb)
4151 return NULL;
4152
4153 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4154 if (!hdr) {
4155 kfree_skb(skb);
4156 return NULL;
4157 }
4158
4159 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4160 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4161
4162 ((void **)skb->cb)[0] = rdev;
4163 ((void **)skb->cb)[1] = hdr;
4164 ((void **)skb->cb)[2] = data;
4165
4166 return skb;
4167
4168 nla_put_failure:
4169 kfree_skb(skb);
4170 return NULL;
4171}
4172
4173struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4174 int approxlen)
4175{
4176 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4177
4178 if (WARN_ON(!rdev->testmode_info))
4179 return NULL;
4180
4181 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4182 rdev->testmode_info->snd_pid,
4183 rdev->testmode_info->snd_seq,
4184 GFP_KERNEL);
4185}
4186EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4187
4188int cfg80211_testmode_reply(struct sk_buff *skb)
4189{
4190 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4191 void *hdr = ((void **)skb->cb)[1];
4192 struct nlattr *data = ((void **)skb->cb)[2];
4193
4194 if (WARN_ON(!rdev->testmode_info)) {
4195 kfree_skb(skb);
4196 return -EINVAL;
4197 }
4198
4199 nla_nest_end(skb, data);
4200 genlmsg_end(skb, hdr);
4201 return genlmsg_reply(skb, rdev->testmode_info);
4202}
4203EXPORT_SYMBOL(cfg80211_testmode_reply);
4204
4205struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4206 int approxlen, gfp_t gfp)
4207{
4208 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4209
4210 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4211}
4212EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4213
4214void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4215{
4216 void *hdr = ((void **)skb->cb)[1];
4217 struct nlattr *data = ((void **)skb->cb)[2];
4218
4219 nla_nest_end(skb, data);
4220 genlmsg_end(skb, hdr);
4221 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4222}
4223EXPORT_SYMBOL(cfg80211_testmode_event);
4224#endif
4225
b23aa676
SO
4226static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4227{
79c97e97 4228 struct cfg80211_registered_device *rdev;
b23aa676
SO
4229 struct net_device *dev;
4230 struct cfg80211_connect_params connect;
4231 struct wiphy *wiphy;
fffd0934 4232 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4233 int err;
4234
4235 memset(&connect, 0, sizeof(connect));
4236
4237 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4238 return -EINVAL;
4239
4240 if (!info->attrs[NL80211_ATTR_SSID] ||
4241 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4242 return -EINVAL;
4243
4244 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4245 connect.auth_type =
4246 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4247 if (!nl80211_valid_auth_type(connect.auth_type))
4248 return -EINVAL;
4249 } else
4250 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4251
4252 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4253
3dc27d25
JB
4254 err = nl80211_crypto_settings(info, &connect.crypto,
4255 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4256 if (err)
4257 return err;
4258 rtnl_lock();
4259
463d0183 4260 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4261 if (err)
4262 goto unlock_rtnl;
4263
4264 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4265 err = -EOPNOTSUPP;
4266 goto out;
4267 }
4268
4269 if (!netif_running(dev)) {
4270 err = -ENETDOWN;
4271 goto out;
4272 }
4273
79c97e97 4274 wiphy = &rdev->wiphy;
b23aa676 4275
b23aa676
SO
4276 if (info->attrs[NL80211_ATTR_MAC])
4277 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4278 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4279 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4280
4281 if (info->attrs[NL80211_ATTR_IE]) {
4282 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4283 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4284 }
4285
4286 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4287 connect.channel =
4288 ieee80211_get_channel(wiphy,
4289 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4290 if (!connect.channel ||
4291 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4292 err = -EINVAL;
4293 goto out;
4294 }
4295 }
4296
fffd0934
JB
4297 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4298 connkeys = nl80211_parse_connkeys(rdev,
4299 info->attrs[NL80211_ATTR_KEYS]);
4300 if (IS_ERR(connkeys)) {
4301 err = PTR_ERR(connkeys);
4302 connkeys = NULL;
4303 goto out;
4304 }
4305 }
4306
4307 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
4308
4309out:
79c97e97 4310 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4311 dev_put(dev);
4312unlock_rtnl:
fffd0934
JB
4313 if (err)
4314 kfree(connkeys);
b23aa676
SO
4315 rtnl_unlock();
4316 return err;
4317}
4318
4319static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4320{
79c97e97 4321 struct cfg80211_registered_device *rdev;
b23aa676
SO
4322 struct net_device *dev;
4323 int err;
4324 u16 reason;
4325
4326 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4327 reason = WLAN_REASON_DEAUTH_LEAVING;
4328 else
4329 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4330
4331 if (reason == 0)
4332 return -EINVAL;
4333
4334 rtnl_lock();
4335
463d0183 4336 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4337 if (err)
4338 goto unlock_rtnl;
4339
4340 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4341 err = -EOPNOTSUPP;
4342 goto out;
4343 }
4344
4345 if (!netif_running(dev)) {
4346 err = -ENETDOWN;
4347 goto out;
4348 }
4349
79c97e97 4350 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4351
4352out:
79c97e97 4353 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4354 dev_put(dev);
4355unlock_rtnl:
4356 rtnl_unlock();
4357 return err;
4358}
4359
463d0183
JB
4360static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4361{
4362 struct cfg80211_registered_device *rdev;
4363 struct net *net;
4364 int err;
4365 u32 pid;
4366
4367 if (!info->attrs[NL80211_ATTR_PID])
4368 return -EINVAL;
4369
4370 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4371
4372 rtnl_lock();
4373
4374 rdev = cfg80211_get_dev_from_info(info);
4375 if (IS_ERR(rdev)) {
4376 err = PTR_ERR(rdev);
8a8e05e5 4377 goto out_rtnl;
463d0183
JB
4378 }
4379
4380 net = get_net_ns_by_pid(pid);
4381 if (IS_ERR(net)) {
4382 err = PTR_ERR(net);
4383 goto out;
4384 }
4385
4386 err = 0;
4387
4388 /* check if anything to do */
4389 if (net_eq(wiphy_net(&rdev->wiphy), net))
4390 goto out_put_net;
4391
4392 err = cfg80211_switch_netns(rdev, net);
4393 out_put_net:
4394 put_net(net);
4395 out:
4396 cfg80211_unlock_rdev(rdev);
8a8e05e5 4397 out_rtnl:
463d0183
JB
4398 rtnl_unlock();
4399 return err;
4400}
4401
67fbb16b
SO
4402static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4403{
4404 struct cfg80211_registered_device *rdev;
4405 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4406 struct cfg80211_pmksa *pmksa) = NULL;
4407 int err;
4408 struct net_device *dev;
4409 struct cfg80211_pmksa pmksa;
4410
4411 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4412
4413 if (!info->attrs[NL80211_ATTR_MAC])
4414 return -EINVAL;
4415
4416 if (!info->attrs[NL80211_ATTR_PMKID])
4417 return -EINVAL;
4418
4419 rtnl_lock();
4420
4421 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4422 if (err)
4423 goto out_rtnl;
4424
4425 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4426 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4427
4428 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4429 err = -EOPNOTSUPP;
4430 goto out;
4431 }
4432
4433 switch (info->genlhdr->cmd) {
4434 case NL80211_CMD_SET_PMKSA:
4435 rdev_ops = rdev->ops->set_pmksa;
4436 break;
4437 case NL80211_CMD_DEL_PMKSA:
4438 rdev_ops = rdev->ops->del_pmksa;
4439 break;
4440 default:
4441 WARN_ON(1);
4442 break;
4443 }
4444
4445 if (!rdev_ops) {
4446 err = -EOPNOTSUPP;
4447 goto out;
4448 }
4449
4450 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4451
4452 out:
4453 cfg80211_unlock_rdev(rdev);
4454 dev_put(dev);
4455 out_rtnl:
4456 rtnl_unlock();
4457
4458 return err;
4459}
4460
4461static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4462{
4463 struct cfg80211_registered_device *rdev;
4464 int err;
4465 struct net_device *dev;
4466
4467 rtnl_lock();
4468
4469 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4470 if (err)
4471 goto out_rtnl;
4472
4473 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4474 err = -EOPNOTSUPP;
4475 goto out;
4476 }
4477
4478 if (!rdev->ops->flush_pmksa) {
4479 err = -EOPNOTSUPP;
4480 goto out;
4481 }
4482
4483 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4484
4485 out:
4486 cfg80211_unlock_rdev(rdev);
4487 dev_put(dev);
4488 out_rtnl:
4489 rtnl_unlock();
4490
4491 return err;
4492
4493}
4494
9588bbd5
JM
4495static int nl80211_remain_on_channel(struct sk_buff *skb,
4496 struct genl_info *info)
4497{
4498 struct cfg80211_registered_device *rdev;
4499 struct net_device *dev;
4500 struct ieee80211_channel *chan;
4501 struct sk_buff *msg;
4502 void *hdr;
4503 u64 cookie;
4504 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4505 u32 freq, duration;
4506 int err;
4507
4508 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4509 !info->attrs[NL80211_ATTR_DURATION])
4510 return -EINVAL;
4511
4512 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4513
4514 /*
4515 * We should be on that channel for at least one jiffie,
4516 * and more than 5 seconds seems excessive.
4517 */
4518 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4519 return -EINVAL;
4520
4521 rtnl_lock();
4522
4523 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4524 if (err)
4525 goto unlock_rtnl;
4526
4527 if (!rdev->ops->remain_on_channel) {
4528 err = -EOPNOTSUPP;
4529 goto out;
4530 }
4531
4532 if (!netif_running(dev)) {
4533 err = -ENETDOWN;
4534 goto out;
4535 }
4536
4537 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4538 channel_type = nla_get_u32(
4539 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4540 if (channel_type != NL80211_CHAN_NO_HT &&
4541 channel_type != NL80211_CHAN_HT20 &&
4542 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4543 channel_type != NL80211_CHAN_HT40MINUS) {
9588bbd5
JM
4544 err = -EINVAL;
4545 goto out;
579d7534 4546 }
9588bbd5
JM
4547 }
4548
4549 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4550 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4551 if (chan == NULL) {
4552 err = -EINVAL;
4553 goto out;
4554 }
4555
4556 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4557 if (!msg) {
4558 err = -ENOMEM;
4559 goto out;
4560 }
4561
4562 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4563 NL80211_CMD_REMAIN_ON_CHANNEL);
4564
4565 if (IS_ERR(hdr)) {
4566 err = PTR_ERR(hdr);
4567 goto free_msg;
4568 }
4569
4570 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4571 channel_type, duration, &cookie);
4572
4573 if (err)
4574 goto free_msg;
4575
4576 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4577
4578 genlmsg_end(msg, hdr);
4579 err = genlmsg_reply(msg, info);
4580 goto out;
4581
4582 nla_put_failure:
4583 err = -ENOBUFS;
4584 free_msg:
4585 nlmsg_free(msg);
4586 out:
4587 cfg80211_unlock_rdev(rdev);
4588 dev_put(dev);
4589 unlock_rtnl:
4590 rtnl_unlock();
4591 return err;
4592}
4593
4594static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4595 struct genl_info *info)
4596{
4597 struct cfg80211_registered_device *rdev;
4598 struct net_device *dev;
4599 u64 cookie;
4600 int err;
4601
4602 if (!info->attrs[NL80211_ATTR_COOKIE])
4603 return -EINVAL;
4604
4605 rtnl_lock();
4606
4607 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4608 if (err)
4609 goto unlock_rtnl;
4610
4611 if (!rdev->ops->cancel_remain_on_channel) {
4612 err = -EOPNOTSUPP;
4613 goto out;
4614 }
4615
4616 if (!netif_running(dev)) {
4617 err = -ENETDOWN;
4618 goto out;
4619 }
4620
4621 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4622
4623 err = rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4624
4625 out:
4626 cfg80211_unlock_rdev(rdev);
4627 dev_put(dev);
4628 unlock_rtnl:
4629 rtnl_unlock();
4630 return err;
4631}
4632
13ae75b1
JM
4633static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4634 u8 *rates, u8 rates_len)
4635{
4636 u8 i;
4637 u32 mask = 0;
4638
4639 for (i = 0; i < rates_len; i++) {
4640 int rate = (rates[i] & 0x7f) * 5;
4641 int ridx;
4642 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4643 struct ieee80211_rate *srate =
4644 &sband->bitrates[ridx];
4645 if (rate == srate->bitrate) {
4646 mask |= 1 << ridx;
4647 break;
4648 }
4649 }
4650 if (ridx == sband->n_bitrates)
4651 return 0; /* rate not found */
4652 }
4653
4654 return mask;
4655}
4656
b54452b0 4657static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4658 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4659 .len = NL80211_MAX_SUPP_RATES },
4660};
4661
4662static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4663 struct genl_info *info)
4664{
4665 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4666 struct cfg80211_registered_device *rdev;
4667 struct cfg80211_bitrate_mask mask;
4668 int err, rem, i;
4669 struct net_device *dev;
4670 struct nlattr *tx_rates;
4671 struct ieee80211_supported_band *sband;
4672
4673 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4674 return -EINVAL;
4675
4676 rtnl_lock();
4677
4678 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4679 if (err)
4680 goto unlock_rtnl;
4681
4682 if (!rdev->ops->set_bitrate_mask) {
4683 err = -EOPNOTSUPP;
4684 goto unlock;
4685 }
4686
4687 memset(&mask, 0, sizeof(mask));
4688 /* Default to all rates enabled */
4689 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4690 sband = rdev->wiphy.bands[i];
4691 mask.control[i].legacy =
4692 sband ? (1 << sband->n_bitrates) - 1 : 0;
4693 }
4694
4695 /*
4696 * The nested attribute uses enum nl80211_band as the index. This maps
4697 * directly to the enum ieee80211_band values used in cfg80211.
4698 */
4699 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4700 {
4701 enum ieee80211_band band = nla_type(tx_rates);
4702 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
4703 err = -EINVAL;
4704 goto unlock;
4705 }
4706 sband = rdev->wiphy.bands[band];
4707 if (sband == NULL) {
4708 err = -EINVAL;
4709 goto unlock;
4710 }
4711 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4712 nla_len(tx_rates), nl80211_txattr_policy);
4713 if (tb[NL80211_TXRATE_LEGACY]) {
4714 mask.control[band].legacy = rateset_to_mask(
4715 sband,
4716 nla_data(tb[NL80211_TXRATE_LEGACY]),
4717 nla_len(tb[NL80211_TXRATE_LEGACY]));
4718 if (mask.control[band].legacy == 0) {
4719 err = -EINVAL;
4720 goto unlock;
4721 }
4722 }
4723 }
4724
4725 err = rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4726
4727 unlock:
4728 dev_put(dev);
4729 cfg80211_unlock_rdev(rdev);
4730 unlock_rtnl:
4731 rtnl_unlock();
4732 return err;
4733}
4734
026331c4
JM
4735static int nl80211_register_action(struct sk_buff *skb, struct genl_info *info)
4736{
4737 struct cfg80211_registered_device *rdev;
4738 struct net_device *dev;
4739 int err;
4740
4741 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4742 return -EINVAL;
4743
4744 if (nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]) < 1)
4745 return -EINVAL;
4746
4747 rtnl_lock();
4748
4749 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4750 if (err)
4751 goto unlock_rtnl;
4752
9d38d85d
JB
4753 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4754 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
026331c4
JM
4755 err = -EOPNOTSUPP;
4756 goto out;
4757 }
4758
4759 /* not much point in registering if we can't reply */
4760 if (!rdev->ops->action) {
4761 err = -EOPNOTSUPP;
4762 goto out;
4763 }
4764
4765 err = cfg80211_mlme_register_action(dev->ieee80211_ptr, info->snd_pid,
4766 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4767 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4768 out:
4769 cfg80211_unlock_rdev(rdev);
4770 dev_put(dev);
4771 unlock_rtnl:
4772 rtnl_unlock();
4773 return err;
4774}
4775
4776static int nl80211_action(struct sk_buff *skb, struct genl_info *info)
4777{
4778 struct cfg80211_registered_device *rdev;
4779 struct net_device *dev;
4780 struct ieee80211_channel *chan;
4781 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4782 bool channel_type_valid = false;
026331c4
JM
4783 u32 freq;
4784 int err;
4785 void *hdr;
4786 u64 cookie;
4787 struct sk_buff *msg;
4788
4789 if (!info->attrs[NL80211_ATTR_FRAME] ||
4790 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4791 return -EINVAL;
4792
4793 rtnl_lock();
4794
4795 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4796 if (err)
4797 goto unlock_rtnl;
4798
4799 if (!rdev->ops->action) {
4800 err = -EOPNOTSUPP;
4801 goto out;
4802 }
4803
9d38d85d
JB
4804 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4805 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
026331c4
JM
4806 err = -EOPNOTSUPP;
4807 goto out;
4808 }
4809
4810 if (!netif_running(dev)) {
4811 err = -ENETDOWN;
4812 goto out;
4813 }
4814
4815 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4816 channel_type = nla_get_u32(
4817 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4818 if (channel_type != NL80211_CHAN_NO_HT &&
4819 channel_type != NL80211_CHAN_HT20 &&
4820 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4821 channel_type != NL80211_CHAN_HT40MINUS) {
026331c4
JM
4822 err = -EINVAL;
4823 goto out;
579d7534 4824 }
252aa631 4825 channel_type_valid = true;
026331c4
JM
4826 }
4827
4828 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4829 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4830 if (chan == NULL) {
4831 err = -EINVAL;
4832 goto out;
4833 }
4834
4835 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4836 if (!msg) {
4837 err = -ENOMEM;
4838 goto out;
4839 }
4840
4841 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4842 NL80211_CMD_ACTION);
4843
4844 if (IS_ERR(hdr)) {
4845 err = PTR_ERR(hdr);
4846 goto free_msg;
4847 }
4848 err = cfg80211_mlme_action(rdev, dev, chan, channel_type,
252aa631 4849 channel_type_valid,
026331c4
JM
4850 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4851 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4852 &cookie);
4853 if (err)
4854 goto free_msg;
4855
4856 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4857
4858 genlmsg_end(msg, hdr);
4859 err = genlmsg_reply(msg, info);
4860 goto out;
4861
4862 nla_put_failure:
4863 err = -ENOBUFS;
4864 free_msg:
4865 nlmsg_free(msg);
4866 out:
4867 cfg80211_unlock_rdev(rdev);
4868 dev_put(dev);
4869unlock_rtnl:
4870 rtnl_unlock();
4871 return err;
4872}
4873
ffb9eb3d
KV
4874static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4875{
4876 struct cfg80211_registered_device *rdev;
4877 struct wireless_dev *wdev;
4878 struct net_device *dev;
4879 u8 ps_state;
4880 bool state;
4881 int err;
4882
4883 if (!info->attrs[NL80211_ATTR_PS_STATE]) {
4884 err = -EINVAL;
4885 goto out;
4886 }
4887
4888 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4889
4890 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) {
4891 err = -EINVAL;
4892 goto out;
4893 }
4894
4895 rtnl_lock();
4896
4897 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4898 if (err)
4899 goto unlock_rdev;
4900
4901 wdev = dev->ieee80211_ptr;
4902
4903 if (!rdev->ops->set_power_mgmt) {
4904 err = -EOPNOTSUPP;
4905 goto unlock_rdev;
4906 }
4907
4908 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4909
4910 if (state == wdev->ps)
4911 goto unlock_rdev;
4912
4913 wdev->ps = state;
4914
4915 if (rdev->ops->set_power_mgmt(wdev->wiphy, dev, wdev->ps,
4916 wdev->ps_timeout))
4917 /* assume this means it's off */
4918 wdev->ps = false;
4919
4920unlock_rdev:
4921 cfg80211_unlock_rdev(rdev);
4922 dev_put(dev);
4923 rtnl_unlock();
4924
4925out:
4926 return err;
4927}
4928
4929static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4930{
4931 struct cfg80211_registered_device *rdev;
4932 enum nl80211_ps_state ps_state;
4933 struct wireless_dev *wdev;
4934 struct net_device *dev;
4935 struct sk_buff *msg;
4936 void *hdr;
4937 int err;
4938
4939 rtnl_lock();
4940
4941 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4942 if (err)
4943 goto unlock_rtnl;
4944
4945 wdev = dev->ieee80211_ptr;
4946
4947 if (!rdev->ops->set_power_mgmt) {
4948 err = -EOPNOTSUPP;
4949 goto out;
4950 }
4951
4952 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4953 if (!msg) {
4954 err = -ENOMEM;
4955 goto out;
4956 }
4957
4958 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4959 NL80211_CMD_GET_POWER_SAVE);
4960 if (!hdr) {
4961 err = -ENOMEM;
4962 goto free_msg;
4963 }
4964
4965 if (wdev->ps)
4966 ps_state = NL80211_PS_ENABLED;
4967 else
4968 ps_state = NL80211_PS_DISABLED;
4969
4970 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4971
4972 genlmsg_end(msg, hdr);
4973 err = genlmsg_reply(msg, info);
4974 goto out;
4975
4976nla_put_failure:
4977 err = -ENOBUFS;
4978
4979free_msg:
4980 nlmsg_free(msg);
4981
4982out:
4983 cfg80211_unlock_rdev(rdev);
4984 dev_put(dev);
4985
4986unlock_rtnl:
4987 rtnl_unlock();
4988
4989 return err;
4990}
4991
d6dc1a38
JO
4992static struct nla_policy
4993nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4994 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4995 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4996 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4997};
4998
4999static int nl80211_set_cqm_rssi(struct genl_info *info,
5000 s32 threshold, u32 hysteresis)
5001{
5002 struct cfg80211_registered_device *rdev;
5003 struct wireless_dev *wdev;
5004 struct net_device *dev;
5005 int err;
5006
5007 if (threshold > 0)
5008 return -EINVAL;
5009
5010 rtnl_lock();
5011
5012 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5013 if (err)
5014 goto unlock_rdev;
5015
5016 wdev = dev->ieee80211_ptr;
5017
5018 if (!rdev->ops->set_cqm_rssi_config) {
5019 err = -EOPNOTSUPP;
5020 goto unlock_rdev;
5021 }
5022
5023 if (wdev->iftype != NL80211_IFTYPE_STATION) {
5024 err = -EOPNOTSUPP;
5025 goto unlock_rdev;
5026 }
5027
5028 err = rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5029 threshold, hysteresis);
5030
5031unlock_rdev:
5032 cfg80211_unlock_rdev(rdev);
5033 dev_put(dev);
5034 rtnl_unlock();
5035
5036 return err;
5037}
5038
5039static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5040{
5041 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5042 struct nlattr *cqm;
5043 int err;
5044
5045 cqm = info->attrs[NL80211_ATTR_CQM];
5046 if (!cqm) {
5047 err = -EINVAL;
5048 goto out;
5049 }
5050
5051 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5052 nl80211_attr_cqm_policy);
5053 if (err)
5054 goto out;
5055
5056 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5057 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5058 s32 threshold;
5059 u32 hysteresis;
5060 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5061 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5062 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5063 } else
5064 err = -EINVAL;
5065
5066out:
5067 return err;
5068}
5069
55682965
JB
5070static struct genl_ops nl80211_ops[] = {
5071 {
5072 .cmd = NL80211_CMD_GET_WIPHY,
5073 .doit = nl80211_get_wiphy,
5074 .dumpit = nl80211_dump_wiphy,
5075 .policy = nl80211_policy,
5076 /* can be retrieved by unprivileged users */
5077 },
5078 {
5079 .cmd = NL80211_CMD_SET_WIPHY,
5080 .doit = nl80211_set_wiphy,
5081 .policy = nl80211_policy,
5082 .flags = GENL_ADMIN_PERM,
5083 },
5084 {
5085 .cmd = NL80211_CMD_GET_INTERFACE,
5086 .doit = nl80211_get_interface,
5087 .dumpit = nl80211_dump_interface,
5088 .policy = nl80211_policy,
5089 /* can be retrieved by unprivileged users */
5090 },
5091 {
5092 .cmd = NL80211_CMD_SET_INTERFACE,
5093 .doit = nl80211_set_interface,
5094 .policy = nl80211_policy,
5095 .flags = GENL_ADMIN_PERM,
5096 },
5097 {
5098 .cmd = NL80211_CMD_NEW_INTERFACE,
5099 .doit = nl80211_new_interface,
5100 .policy = nl80211_policy,
5101 .flags = GENL_ADMIN_PERM,
5102 },
5103 {
5104 .cmd = NL80211_CMD_DEL_INTERFACE,
5105 .doit = nl80211_del_interface,
5106 .policy = nl80211_policy,
41ade00f
JB
5107 .flags = GENL_ADMIN_PERM,
5108 },
5109 {
5110 .cmd = NL80211_CMD_GET_KEY,
5111 .doit = nl80211_get_key,
5112 .policy = nl80211_policy,
5113 .flags = GENL_ADMIN_PERM,
5114 },
5115 {
5116 .cmd = NL80211_CMD_SET_KEY,
5117 .doit = nl80211_set_key,
5118 .policy = nl80211_policy,
5119 .flags = GENL_ADMIN_PERM,
5120 },
5121 {
5122 .cmd = NL80211_CMD_NEW_KEY,
5123 .doit = nl80211_new_key,
5124 .policy = nl80211_policy,
5125 .flags = GENL_ADMIN_PERM,
5126 },
5127 {
5128 .cmd = NL80211_CMD_DEL_KEY,
5129 .doit = nl80211_del_key,
5130 .policy = nl80211_policy,
55682965
JB
5131 .flags = GENL_ADMIN_PERM,
5132 },
ed1b6cc7
JB
5133 {
5134 .cmd = NL80211_CMD_SET_BEACON,
5135 .policy = nl80211_policy,
5136 .flags = GENL_ADMIN_PERM,
5137 .doit = nl80211_addset_beacon,
5138 },
5139 {
5140 .cmd = NL80211_CMD_NEW_BEACON,
5141 .policy = nl80211_policy,
5142 .flags = GENL_ADMIN_PERM,
5143 .doit = nl80211_addset_beacon,
5144 },
5145 {
5146 .cmd = NL80211_CMD_DEL_BEACON,
5147 .policy = nl80211_policy,
5148 .flags = GENL_ADMIN_PERM,
5149 .doit = nl80211_del_beacon,
5150 },
5727ef1b
JB
5151 {
5152 .cmd = NL80211_CMD_GET_STATION,
5153 .doit = nl80211_get_station,
2ec600d6 5154 .dumpit = nl80211_dump_station,
5727ef1b 5155 .policy = nl80211_policy,
5727ef1b
JB
5156 },
5157 {
5158 .cmd = NL80211_CMD_SET_STATION,
5159 .doit = nl80211_set_station,
5160 .policy = nl80211_policy,
5161 .flags = GENL_ADMIN_PERM,
5162 },
5163 {
5164 .cmd = NL80211_CMD_NEW_STATION,
5165 .doit = nl80211_new_station,
5166 .policy = nl80211_policy,
5167 .flags = GENL_ADMIN_PERM,
5168 },
5169 {
5170 .cmd = NL80211_CMD_DEL_STATION,
5171 .doit = nl80211_del_station,
5172 .policy = nl80211_policy,
2ec600d6
LCC
5173 .flags = GENL_ADMIN_PERM,
5174 },
5175 {
5176 .cmd = NL80211_CMD_GET_MPATH,
5177 .doit = nl80211_get_mpath,
5178 .dumpit = nl80211_dump_mpath,
5179 .policy = nl80211_policy,
5180 .flags = GENL_ADMIN_PERM,
5181 },
5182 {
5183 .cmd = NL80211_CMD_SET_MPATH,
5184 .doit = nl80211_set_mpath,
5185 .policy = nl80211_policy,
5186 .flags = GENL_ADMIN_PERM,
5187 },
5188 {
5189 .cmd = NL80211_CMD_NEW_MPATH,
5190 .doit = nl80211_new_mpath,
5191 .policy = nl80211_policy,
5192 .flags = GENL_ADMIN_PERM,
5193 },
5194 {
5195 .cmd = NL80211_CMD_DEL_MPATH,
5196 .doit = nl80211_del_mpath,
5197 .policy = nl80211_policy,
9f1ba906
JM
5198 .flags = GENL_ADMIN_PERM,
5199 },
5200 {
5201 .cmd = NL80211_CMD_SET_BSS,
5202 .doit = nl80211_set_bss,
5203 .policy = nl80211_policy,
b2e1b302
LR
5204 .flags = GENL_ADMIN_PERM,
5205 },
f130347c
LR
5206 {
5207 .cmd = NL80211_CMD_GET_REG,
5208 .doit = nl80211_get_reg,
5209 .policy = nl80211_policy,
5210 /* can be retrieved by unprivileged users */
5211 },
b2e1b302
LR
5212 {
5213 .cmd = NL80211_CMD_SET_REG,
5214 .doit = nl80211_set_reg,
5215 .policy = nl80211_policy,
5216 .flags = GENL_ADMIN_PERM,
5217 },
5218 {
5219 .cmd = NL80211_CMD_REQ_SET_REG,
5220 .doit = nl80211_req_set_reg,
5221 .policy = nl80211_policy,
93da9cc1 5222 .flags = GENL_ADMIN_PERM,
5223 },
5224 {
5225 .cmd = NL80211_CMD_GET_MESH_PARAMS,
5226 .doit = nl80211_get_mesh_params,
5227 .policy = nl80211_policy,
5228 /* can be retrieved by unprivileged users */
5229 },
5230 {
5231 .cmd = NL80211_CMD_SET_MESH_PARAMS,
5232 .doit = nl80211_set_mesh_params,
5233 .policy = nl80211_policy,
9aed3cc1
JM
5234 .flags = GENL_ADMIN_PERM,
5235 },
2a519311
JB
5236 {
5237 .cmd = NL80211_CMD_TRIGGER_SCAN,
5238 .doit = nl80211_trigger_scan,
5239 .policy = nl80211_policy,
5240 .flags = GENL_ADMIN_PERM,
5241 },
5242 {
5243 .cmd = NL80211_CMD_GET_SCAN,
5244 .policy = nl80211_policy,
5245 .dumpit = nl80211_dump_scan,
5246 },
636a5d36
JM
5247 {
5248 .cmd = NL80211_CMD_AUTHENTICATE,
5249 .doit = nl80211_authenticate,
5250 .policy = nl80211_policy,
5251 .flags = GENL_ADMIN_PERM,
5252 },
5253 {
5254 .cmd = NL80211_CMD_ASSOCIATE,
5255 .doit = nl80211_associate,
5256 .policy = nl80211_policy,
5257 .flags = GENL_ADMIN_PERM,
5258 },
5259 {
5260 .cmd = NL80211_CMD_DEAUTHENTICATE,
5261 .doit = nl80211_deauthenticate,
5262 .policy = nl80211_policy,
5263 .flags = GENL_ADMIN_PERM,
5264 },
5265 {
5266 .cmd = NL80211_CMD_DISASSOCIATE,
5267 .doit = nl80211_disassociate,
5268 .policy = nl80211_policy,
5269 .flags = GENL_ADMIN_PERM,
5270 },
04a773ad
JB
5271 {
5272 .cmd = NL80211_CMD_JOIN_IBSS,
5273 .doit = nl80211_join_ibss,
5274 .policy = nl80211_policy,
5275 .flags = GENL_ADMIN_PERM,
5276 },
5277 {
5278 .cmd = NL80211_CMD_LEAVE_IBSS,
5279 .doit = nl80211_leave_ibss,
5280 .policy = nl80211_policy,
5281 .flags = GENL_ADMIN_PERM,
5282 },
aff89a9b
JB
5283#ifdef CONFIG_NL80211_TESTMODE
5284 {
5285 .cmd = NL80211_CMD_TESTMODE,
5286 .doit = nl80211_testmode_do,
5287 .policy = nl80211_policy,
5288 .flags = GENL_ADMIN_PERM,
5289 },
5290#endif
b23aa676
SO
5291 {
5292 .cmd = NL80211_CMD_CONNECT,
5293 .doit = nl80211_connect,
5294 .policy = nl80211_policy,
5295 .flags = GENL_ADMIN_PERM,
5296 },
5297 {
5298 .cmd = NL80211_CMD_DISCONNECT,
5299 .doit = nl80211_disconnect,
5300 .policy = nl80211_policy,
5301 .flags = GENL_ADMIN_PERM,
5302 },
463d0183
JB
5303 {
5304 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5305 .doit = nl80211_wiphy_netns,
5306 .policy = nl80211_policy,
5307 .flags = GENL_ADMIN_PERM,
5308 },
61fa713c
HS
5309 {
5310 .cmd = NL80211_CMD_GET_SURVEY,
5311 .policy = nl80211_policy,
5312 .dumpit = nl80211_dump_survey,
5313 },
67fbb16b
SO
5314 {
5315 .cmd = NL80211_CMD_SET_PMKSA,
5316 .doit = nl80211_setdel_pmksa,
5317 .policy = nl80211_policy,
5318 .flags = GENL_ADMIN_PERM,
5319 },
5320 {
5321 .cmd = NL80211_CMD_DEL_PMKSA,
5322 .doit = nl80211_setdel_pmksa,
5323 .policy = nl80211_policy,
5324 .flags = GENL_ADMIN_PERM,
5325 },
5326 {
5327 .cmd = NL80211_CMD_FLUSH_PMKSA,
5328 .doit = nl80211_flush_pmksa,
5329 .policy = nl80211_policy,
5330 .flags = GENL_ADMIN_PERM,
5331 },
9588bbd5
JM
5332 {
5333 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5334 .doit = nl80211_remain_on_channel,
5335 .policy = nl80211_policy,
5336 .flags = GENL_ADMIN_PERM,
5337 },
5338 {
5339 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5340 .doit = nl80211_cancel_remain_on_channel,
5341 .policy = nl80211_policy,
5342 .flags = GENL_ADMIN_PERM,
5343 },
13ae75b1
JM
5344 {
5345 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5346 .doit = nl80211_set_tx_bitrate_mask,
5347 .policy = nl80211_policy,
5348 .flags = GENL_ADMIN_PERM,
5349 },
026331c4
JM
5350 {
5351 .cmd = NL80211_CMD_REGISTER_ACTION,
5352 .doit = nl80211_register_action,
5353 .policy = nl80211_policy,
5354 .flags = GENL_ADMIN_PERM,
5355 },
5356 {
5357 .cmd = NL80211_CMD_ACTION,
5358 .doit = nl80211_action,
5359 .policy = nl80211_policy,
5360 .flags = GENL_ADMIN_PERM,
5361 },
ffb9eb3d
KV
5362 {
5363 .cmd = NL80211_CMD_SET_POWER_SAVE,
5364 .doit = nl80211_set_power_save,
5365 .policy = nl80211_policy,
5366 .flags = GENL_ADMIN_PERM,
5367 },
5368 {
5369 .cmd = NL80211_CMD_GET_POWER_SAVE,
5370 .doit = nl80211_get_power_save,
5371 .policy = nl80211_policy,
5372 /* can be retrieved by unprivileged users */
5373 },
d6dc1a38
JO
5374 {
5375 .cmd = NL80211_CMD_SET_CQM,
5376 .doit = nl80211_set_cqm,
5377 .policy = nl80211_policy,
5378 .flags = GENL_ADMIN_PERM,
5379 },
f444de05
JB
5380 {
5381 .cmd = NL80211_CMD_SET_CHANNEL,
5382 .doit = nl80211_set_channel,
5383 .policy = nl80211_policy,
5384 .flags = GENL_ADMIN_PERM,
5385 },
55682965 5386};
9588bbd5 5387
6039f6d2
JM
5388static struct genl_multicast_group nl80211_mlme_mcgrp = {
5389 .name = "mlme",
5390};
55682965
JB
5391
5392/* multicast groups */
5393static struct genl_multicast_group nl80211_config_mcgrp = {
5394 .name = "config",
5395};
2a519311
JB
5396static struct genl_multicast_group nl80211_scan_mcgrp = {
5397 .name = "scan",
5398};
73d54c9e
LR
5399static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5400 .name = "regulatory",
5401};
55682965
JB
5402
5403/* notification functions */
5404
5405void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5406{
5407 struct sk_buff *msg;
5408
fd2120ca 5409 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5410 if (!msg)
5411 return;
5412
5413 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5414 nlmsg_free(msg);
5415 return;
5416 }
5417
463d0183
JB
5418 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5419 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5420}
5421
362a415d
JB
5422static int nl80211_add_scan_req(struct sk_buff *msg,
5423 struct cfg80211_registered_device *rdev)
5424{
5425 struct cfg80211_scan_request *req = rdev->scan_req;
5426 struct nlattr *nest;
5427 int i;
5428
667503dd
JB
5429 ASSERT_RDEV_LOCK(rdev);
5430
362a415d
JB
5431 if (WARN_ON(!req))
5432 return 0;
5433
5434 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5435 if (!nest)
5436 goto nla_put_failure;
5437 for (i = 0; i < req->n_ssids; i++)
5438 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5439 nla_nest_end(msg, nest);
5440
5441 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5442 if (!nest)
5443 goto nla_put_failure;
5444 for (i = 0; i < req->n_channels; i++)
5445 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5446 nla_nest_end(msg, nest);
5447
5448 if (req->ie)
5449 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5450
5451 return 0;
5452 nla_put_failure:
5453 return -ENOBUFS;
5454}
5455
a538e2d5
JB
5456static int nl80211_send_scan_msg(struct sk_buff *msg,
5457 struct cfg80211_registered_device *rdev,
5458 struct net_device *netdev,
5459 u32 pid, u32 seq, int flags,
5460 u32 cmd)
2a519311
JB
5461{
5462 void *hdr;
5463
5464 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5465 if (!hdr)
5466 return -1;
5467
b5850a7a 5468 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5469 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5470
362a415d
JB
5471 /* ignore errors and send incomplete event anyway */
5472 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5473
5474 return genlmsg_end(msg, hdr);
5475
5476 nla_put_failure:
5477 genlmsg_cancel(msg, hdr);
5478 return -EMSGSIZE;
5479}
5480
a538e2d5
JB
5481void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5482 struct net_device *netdev)
5483{
5484 struct sk_buff *msg;
5485
5486 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5487 if (!msg)
5488 return;
5489
5490 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5491 NL80211_CMD_TRIGGER_SCAN) < 0) {
5492 nlmsg_free(msg);
5493 return;
5494 }
5495
463d0183
JB
5496 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5497 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5498}
5499
2a519311
JB
5500void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5501 struct net_device *netdev)
5502{
5503 struct sk_buff *msg;
5504
fd2120ca 5505 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5506 if (!msg)
5507 return;
5508
a538e2d5
JB
5509 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5510 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5511 nlmsg_free(msg);
5512 return;
5513 }
5514
463d0183
JB
5515 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5516 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5517}
5518
5519void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5520 struct net_device *netdev)
5521{
5522 struct sk_buff *msg;
5523
fd2120ca 5524 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5525 if (!msg)
5526 return;
5527
a538e2d5
JB
5528 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5529 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5530 nlmsg_free(msg);
5531 return;
5532 }
5533
463d0183
JB
5534 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5535 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5536}
5537
73d54c9e
LR
5538/*
5539 * This can happen on global regulatory changes or device specific settings
5540 * based on custom world regulatory domains.
5541 */
5542void nl80211_send_reg_change_event(struct regulatory_request *request)
5543{
5544 struct sk_buff *msg;
5545 void *hdr;
5546
fd2120ca 5547 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5548 if (!msg)
5549 return;
5550
5551 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5552 if (!hdr) {
5553 nlmsg_free(msg);
5554 return;
5555 }
5556
5557 /* Userspace can always count this one always being set */
5558 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5559
5560 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5561 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5562 NL80211_REGDOM_TYPE_WORLD);
5563 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5564 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5565 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5566 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5567 request->intersect)
5568 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5569 NL80211_REGDOM_TYPE_INTERSECTION);
5570 else {
5571 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5572 NL80211_REGDOM_TYPE_COUNTRY);
5573 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5574 }
5575
5576 if (wiphy_idx_valid(request->wiphy_idx))
5577 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5578
5579 if (genlmsg_end(msg, hdr) < 0) {
5580 nlmsg_free(msg);
5581 return;
5582 }
5583
bc43b28c 5584 rcu_read_lock();
463d0183 5585 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5586 GFP_ATOMIC);
5587 rcu_read_unlock();
73d54c9e
LR
5588
5589 return;
5590
5591nla_put_failure:
5592 genlmsg_cancel(msg, hdr);
5593 nlmsg_free(msg);
5594}
5595
6039f6d2
JM
5596static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5597 struct net_device *netdev,
5598 const u8 *buf, size_t len,
e6d6e342 5599 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5600{
5601 struct sk_buff *msg;
5602 void *hdr;
5603
e6d6e342 5604 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5605 if (!msg)
5606 return;
5607
5608 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5609 if (!hdr) {
5610 nlmsg_free(msg);
5611 return;
5612 }
5613
5614 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5615 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5616 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5617
5618 if (genlmsg_end(msg, hdr) < 0) {
5619 nlmsg_free(msg);
5620 return;
5621 }
5622
463d0183
JB
5623 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5624 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5625 return;
5626
5627 nla_put_failure:
5628 genlmsg_cancel(msg, hdr);
5629 nlmsg_free(msg);
5630}
5631
5632void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5633 struct net_device *netdev, const u8 *buf,
5634 size_t len, gfp_t gfp)
6039f6d2
JM
5635{
5636 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5637 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5638}
5639
5640void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5641 struct net_device *netdev, const u8 *buf,
e6d6e342 5642 size_t len, gfp_t gfp)
6039f6d2 5643{
e6d6e342
JB
5644 nl80211_send_mlme_event(rdev, netdev, buf, len,
5645 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5646}
5647
53b46b84 5648void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5649 struct net_device *netdev, const u8 *buf,
5650 size_t len, gfp_t gfp)
6039f6d2
JM
5651{
5652 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5653 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5654}
5655
53b46b84
JM
5656void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5657 struct net_device *netdev, const u8 *buf,
e6d6e342 5658 size_t len, gfp_t gfp)
6039f6d2
JM
5659{
5660 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5661 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5662}
5663
1b06bb40
LR
5664static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5665 struct net_device *netdev, int cmd,
e6d6e342 5666 const u8 *addr, gfp_t gfp)
1965c853
JM
5667{
5668 struct sk_buff *msg;
5669 void *hdr;
5670
e6d6e342 5671 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5672 if (!msg)
5673 return;
5674
5675 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5676 if (!hdr) {
5677 nlmsg_free(msg);
5678 return;
5679 }
5680
5681 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5682 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5683 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5684 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5685
5686 if (genlmsg_end(msg, hdr) < 0) {
5687 nlmsg_free(msg);
5688 return;
5689 }
5690
463d0183
JB
5691 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5692 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5693 return;
5694
5695 nla_put_failure:
5696 genlmsg_cancel(msg, hdr);
5697 nlmsg_free(msg);
5698}
5699
5700void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5701 struct net_device *netdev, const u8 *addr,
5702 gfp_t gfp)
1965c853
JM
5703{
5704 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5705 addr, gfp);
1965c853
JM
5706}
5707
5708void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5709 struct net_device *netdev, const u8 *addr,
5710 gfp_t gfp)
1965c853 5711{
e6d6e342
JB
5712 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5713 addr, gfp);
1965c853
JM
5714}
5715
b23aa676
SO
5716void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5717 struct net_device *netdev, const u8 *bssid,
5718 const u8 *req_ie, size_t req_ie_len,
5719 const u8 *resp_ie, size_t resp_ie_len,
5720 u16 status, gfp_t gfp)
5721{
5722 struct sk_buff *msg;
5723 void *hdr;
5724
5725 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5726 if (!msg)
5727 return;
5728
5729 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5730 if (!hdr) {
5731 nlmsg_free(msg);
5732 return;
5733 }
5734
5735 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5736 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5737 if (bssid)
5738 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5739 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5740 if (req_ie)
5741 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5742 if (resp_ie)
5743 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5744
5745 if (genlmsg_end(msg, hdr) < 0) {
5746 nlmsg_free(msg);
5747 return;
5748 }
5749
463d0183
JB
5750 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5751 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5752 return;
5753
5754 nla_put_failure:
5755 genlmsg_cancel(msg, hdr);
5756 nlmsg_free(msg);
5757
5758}
5759
5760void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5761 struct net_device *netdev, const u8 *bssid,
5762 const u8 *req_ie, size_t req_ie_len,
5763 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5764{
5765 struct sk_buff *msg;
5766 void *hdr;
5767
5768 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5769 if (!msg)
5770 return;
5771
5772 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5773 if (!hdr) {
5774 nlmsg_free(msg);
5775 return;
5776 }
5777
5778 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5779 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5780 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5781 if (req_ie)
5782 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5783 if (resp_ie)
5784 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5785
5786 if (genlmsg_end(msg, hdr) < 0) {
5787 nlmsg_free(msg);
5788 return;
5789 }
5790
463d0183
JB
5791 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5792 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5793 return;
5794
5795 nla_put_failure:
5796 genlmsg_cancel(msg, hdr);
5797 nlmsg_free(msg);
5798
5799}
5800
5801void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5802 struct net_device *netdev, u16 reason,
667503dd 5803 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5804{
5805 struct sk_buff *msg;
5806 void *hdr;
5807
667503dd 5808 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5809 if (!msg)
5810 return;
5811
5812 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5813 if (!hdr) {
5814 nlmsg_free(msg);
5815 return;
5816 }
5817
5818 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5819 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5820 if (from_ap && reason)
5821 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5822 if (from_ap)
5823 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5824 if (ie)
5825 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5826
5827 if (genlmsg_end(msg, hdr) < 0) {
5828 nlmsg_free(msg);
5829 return;
5830 }
5831
463d0183
JB
5832 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5833 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5834 return;
5835
5836 nla_put_failure:
5837 genlmsg_cancel(msg, hdr);
5838 nlmsg_free(msg);
5839
5840}
5841
04a773ad
JB
5842void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5843 struct net_device *netdev, const u8 *bssid,
5844 gfp_t gfp)
5845{
5846 struct sk_buff *msg;
5847 void *hdr;
5848
fd2120ca 5849 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5850 if (!msg)
5851 return;
5852
5853 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5854 if (!hdr) {
5855 nlmsg_free(msg);
5856 return;
5857 }
5858
5859 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5860 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5861 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5862
5863 if (genlmsg_end(msg, hdr) < 0) {
5864 nlmsg_free(msg);
5865 return;
5866 }
5867
463d0183
JB
5868 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5869 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5870 return;
5871
5872 nla_put_failure:
5873 genlmsg_cancel(msg, hdr);
5874 nlmsg_free(msg);
5875}
5876
a3b8b056
JM
5877void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5878 struct net_device *netdev, const u8 *addr,
5879 enum nl80211_key_type key_type, int key_id,
e6d6e342 5880 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5881{
5882 struct sk_buff *msg;
5883 void *hdr;
5884
e6d6e342 5885 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5886 if (!msg)
5887 return;
5888
5889 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5890 if (!hdr) {
5891 nlmsg_free(msg);
5892 return;
5893 }
5894
5895 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5896 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5897 if (addr)
5898 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5899 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5900 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5901 if (tsc)
5902 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5903
5904 if (genlmsg_end(msg, hdr) < 0) {
5905 nlmsg_free(msg);
5906 return;
5907 }
5908
463d0183
JB
5909 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5910 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5911 return;
5912
5913 nla_put_failure:
5914 genlmsg_cancel(msg, hdr);
5915 nlmsg_free(msg);
5916}
5917
6bad8766
LR
5918void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5919 struct ieee80211_channel *channel_before,
5920 struct ieee80211_channel *channel_after)
5921{
5922 struct sk_buff *msg;
5923 void *hdr;
5924 struct nlattr *nl_freq;
5925
fd2120ca 5926 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5927 if (!msg)
5928 return;
5929
5930 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5931 if (!hdr) {
5932 nlmsg_free(msg);
5933 return;
5934 }
5935
5936 /*
5937 * Since we are applying the beacon hint to a wiphy we know its
5938 * wiphy_idx is valid
5939 */
5940 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5941
5942 /* Before */
5943 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5944 if (!nl_freq)
5945 goto nla_put_failure;
5946 if (nl80211_msg_put_channel(msg, channel_before))
5947 goto nla_put_failure;
5948 nla_nest_end(msg, nl_freq);
5949
5950 /* After */
5951 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5952 if (!nl_freq)
5953 goto nla_put_failure;
5954 if (nl80211_msg_put_channel(msg, channel_after))
5955 goto nla_put_failure;
5956 nla_nest_end(msg, nl_freq);
5957
5958 if (genlmsg_end(msg, hdr) < 0) {
5959 nlmsg_free(msg);
5960 return;
5961 }
5962
463d0183
JB
5963 rcu_read_lock();
5964 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5965 GFP_ATOMIC);
5966 rcu_read_unlock();
6bad8766
LR
5967
5968 return;
5969
5970nla_put_failure:
5971 genlmsg_cancel(msg, hdr);
5972 nlmsg_free(msg);
5973}
5974
9588bbd5
JM
5975static void nl80211_send_remain_on_chan_event(
5976 int cmd, struct cfg80211_registered_device *rdev,
5977 struct net_device *netdev, u64 cookie,
5978 struct ieee80211_channel *chan,
5979 enum nl80211_channel_type channel_type,
5980 unsigned int duration, gfp_t gfp)
5981{
5982 struct sk_buff *msg;
5983 void *hdr;
5984
5985 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5986 if (!msg)
5987 return;
5988
5989 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5990 if (!hdr) {
5991 nlmsg_free(msg);
5992 return;
5993 }
5994
5995 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5996 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5997 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5998 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5999 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6000
6001 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6002 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6003
6004 if (genlmsg_end(msg, hdr) < 0) {
6005 nlmsg_free(msg);
6006 return;
6007 }
6008
6009 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6010 nl80211_mlme_mcgrp.id, gfp);
6011 return;
6012
6013 nla_put_failure:
6014 genlmsg_cancel(msg, hdr);
6015 nlmsg_free(msg);
6016}
6017
6018void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6019 struct net_device *netdev, u64 cookie,
6020 struct ieee80211_channel *chan,
6021 enum nl80211_channel_type channel_type,
6022 unsigned int duration, gfp_t gfp)
6023{
6024 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6025 rdev, netdev, cookie, chan,
6026 channel_type, duration, gfp);
6027}
6028
6029void nl80211_send_remain_on_channel_cancel(
6030 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6031 u64 cookie, struct ieee80211_channel *chan,
6032 enum nl80211_channel_type channel_type, gfp_t gfp)
6033{
6034 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6035 rdev, netdev, cookie, chan,
6036 channel_type, 0, gfp);
6037}
6038
98b62183
JB
6039void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6040 struct net_device *dev, const u8 *mac_addr,
6041 struct station_info *sinfo, gfp_t gfp)
6042{
6043 struct sk_buff *msg;
6044
6045 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6046 if (!msg)
6047 return;
6048
6049 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6050 nlmsg_free(msg);
6051 return;
6052 }
6053
6054 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6055 nl80211_mlme_mcgrp.id, gfp);
6056}
6057
026331c4
JM
6058int nl80211_send_action(struct cfg80211_registered_device *rdev,
6059 struct net_device *netdev, u32 nlpid,
6060 int freq, const u8 *buf, size_t len, gfp_t gfp)
6061{
6062 struct sk_buff *msg;
6063 void *hdr;
6064 int err;
6065
6066 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6067 if (!msg)
6068 return -ENOMEM;
6069
6070 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ACTION);
6071 if (!hdr) {
6072 nlmsg_free(msg);
6073 return -ENOMEM;
6074 }
6075
6076 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6077 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6078 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6079 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6080
6081 err = genlmsg_end(msg, hdr);
6082 if (err < 0) {
6083 nlmsg_free(msg);
6084 return err;
6085 }
6086
6087 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6088 if (err < 0)
6089 return err;
6090 return 0;
6091
6092 nla_put_failure:
6093 genlmsg_cancel(msg, hdr);
6094 nlmsg_free(msg);
6095 return -ENOBUFS;
6096}
6097
6098void nl80211_send_action_tx_status(struct cfg80211_registered_device *rdev,
6099 struct net_device *netdev, u64 cookie,
6100 const u8 *buf, size_t len, bool ack,
6101 gfp_t gfp)
6102{
6103 struct sk_buff *msg;
6104 void *hdr;
6105
6106 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6107 if (!msg)
6108 return;
6109
6110 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ACTION_TX_STATUS);
6111 if (!hdr) {
6112 nlmsg_free(msg);
6113 return;
6114 }
6115
6116 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6117 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6118 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6119 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6120 if (ack)
6121 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6122
6123 if (genlmsg_end(msg, hdr) < 0) {
6124 nlmsg_free(msg);
6125 return;
6126 }
6127
6128 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6129 return;
6130
6131 nla_put_failure:
6132 genlmsg_cancel(msg, hdr);
6133 nlmsg_free(msg);
6134}
6135
d6dc1a38
JO
6136void
6137nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6138 struct net_device *netdev,
6139 enum nl80211_cqm_rssi_threshold_event rssi_event,
6140 gfp_t gfp)
6141{
6142 struct sk_buff *msg;
6143 struct nlattr *pinfoattr;
6144 void *hdr;
6145
6146 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6147 if (!msg)
6148 return;
6149
6150 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6151 if (!hdr) {
6152 nlmsg_free(msg);
6153 return;
6154 }
6155
6156 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6157 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6158
6159 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6160 if (!pinfoattr)
6161 goto nla_put_failure;
6162
6163 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6164 rssi_event);
6165
6166 nla_nest_end(msg, pinfoattr);
6167
6168 if (genlmsg_end(msg, hdr) < 0) {
6169 nlmsg_free(msg);
6170 return;
6171 }
6172
6173 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6174 nl80211_mlme_mcgrp.id, gfp);
6175 return;
6176
6177 nla_put_failure:
6178 genlmsg_cancel(msg, hdr);
6179 nlmsg_free(msg);
6180}
6181
026331c4
JM
6182static int nl80211_netlink_notify(struct notifier_block * nb,
6183 unsigned long state,
6184 void *_notify)
6185{
6186 struct netlink_notify *notify = _notify;
6187 struct cfg80211_registered_device *rdev;
6188 struct wireless_dev *wdev;
6189
6190 if (state != NETLINK_URELEASE)
6191 return NOTIFY_DONE;
6192
6193 rcu_read_lock();
6194
6195 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6196 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
6197 cfg80211_mlme_unregister_actions(wdev, notify->pid);
6198
6199 rcu_read_unlock();
6200
6201 return NOTIFY_DONE;
6202}
6203
6204static struct notifier_block nl80211_netlink_notifier = {
6205 .notifier_call = nl80211_netlink_notify,
6206};
6207
55682965
JB
6208/* initialisation/exit functions */
6209
6210int nl80211_init(void)
6211{
0d63cbb5 6212 int err;
55682965 6213
0d63cbb5
MM
6214 err = genl_register_family_with_ops(&nl80211_fam,
6215 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6216 if (err)
6217 return err;
6218
55682965
JB
6219 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6220 if (err)
6221 goto err_out;
6222
2a519311
JB
6223 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6224 if (err)
6225 goto err_out;
6226
73d54c9e
LR
6227 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6228 if (err)
6229 goto err_out;
6230
6039f6d2
JM
6231 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6232 if (err)
6233 goto err_out;
6234
aff89a9b
JB
6235#ifdef CONFIG_NL80211_TESTMODE
6236 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6237 if (err)
6238 goto err_out;
6239#endif
6240
026331c4
JM
6241 err = netlink_register_notifier(&nl80211_netlink_notifier);
6242 if (err)
6243 goto err_out;
6244
55682965
JB
6245 return 0;
6246 err_out:
6247 genl_unregister_family(&nl80211_fam);
6248 return err;
6249}
6250
6251void nl80211_exit(void)
6252{
026331c4 6253 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6254 genl_unregister_family(&nl80211_fam);
6255}