]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
atheros: define a common priv struct
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
08645126 4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
55682965
JB
10#include <linux/list.h>
11#include <linux/if_ether.h>
12#include <linux/ieee80211.h>
13#include <linux/nl80211.h>
14#include <linux/rtnetlink.h>
15#include <linux/netlink.h>
2a519311 16#include <linux/etherdevice.h>
463d0183 17#include <net/net_namespace.h>
55682965
JB
18#include <net/genetlink.h>
19#include <net/cfg80211.h>
463d0183 20#include <net/sock.h>
55682965
JB
21#include "core.h"
22#include "nl80211.h"
b2e1b302 23#include "reg.h"
55682965
JB
24
25/* the netlink family */
26static struct genl_family nl80211_fam = {
27 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28 .name = "nl80211", /* have users key off the name instead */
29 .hdrsize = 0, /* no private header */
30 .version = 1, /* no particular meaning now */
31 .maxattr = NL80211_ATTR_MAX,
463d0183 32 .netnsok = true,
55682965
JB
33};
34
79c97e97 35/* internal helper: get rdev and dev */
463d0183 36static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 37 struct cfg80211_registered_device **rdev,
55682965
JB
38 struct net_device **dev)
39{
463d0183 40 struct nlattr **attrs = info->attrs;
55682965
JB
41 int ifindex;
42
bba95fef 43 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
44 return -EINVAL;
45
bba95fef 46 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 47 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
48 if (!*dev)
49 return -ENODEV;
50
463d0183 51 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 52 if (IS_ERR(*rdev)) {
55682965 53 dev_put(*dev);
79c97e97 54 return PTR_ERR(*rdev);
55682965
JB
55 }
56
57 return 0;
58}
59
60/* policy for the attributes */
61static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 64 .len = 20-1 },
31888487 65 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 66 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 67 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
68 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
55682965
JB
72
73 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
74 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
75 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
76
77 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 78 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 79
b9454e83 80 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
81 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
82 .len = WLAN_MAX_KEY_LEN },
83 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
84 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
85 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 86 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
87
88 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
89 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
90 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
91 .len = IEEE80211_MAX_DATA_LEN },
92 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
94 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
95 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
96 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
98 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 99 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 100 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 101 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
102 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_MESH_ID_LEN },
104 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 105
b2e1b302
LR
106 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
107 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
108
9f1ba906
JM
109 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
110 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
111 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
112 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
36aedc90 114
93da9cc1 115 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
116
36aedc90
JM
117 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
118 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
119
120 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
121 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
122 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
123 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
124 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
125
126 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
127 .len = IEEE80211_MAX_SSID_LEN },
128 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
129 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 130 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 131 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 132 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
133 [NL80211_ATTR_STA_FLAGS2] = {
134 .len = sizeof(struct nl80211_sta_flag_update),
135 },
3f77316c 136 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
137 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
138 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
139 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 140 [NL80211_ATTR_PID] = { .type = NLA_U32 },
55682965
JB
141};
142
b9454e83
JB
143/* policy for the attributes */
144static struct nla_policy
145nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
fffd0934 146 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
147 [NL80211_KEY_IDX] = { .type = NLA_U8 },
148 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
149 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
150 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
151 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
152};
153
f4a11bb0
JB
154/* IE validation */
155static bool is_valid_ie_attr(const struct nlattr *attr)
156{
157 const u8 *pos;
158 int len;
159
160 if (!attr)
161 return true;
162
163 pos = nla_data(attr);
164 len = nla_len(attr);
165
166 while (len) {
167 u8 elemlen;
168
169 if (len < 2)
170 return false;
171 len -= 2;
172
173 elemlen = pos[1];
174 if (elemlen > len)
175 return false;
176
177 len -= elemlen;
178 pos += 2 + elemlen;
179 }
180
181 return true;
182}
183
55682965
JB
184/* message building helper */
185static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
186 int flags, u8 cmd)
187{
188 /* since there is no private header just add the generic one */
189 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
190}
191
5dab3b8a
LR
192static int nl80211_msg_put_channel(struct sk_buff *msg,
193 struct ieee80211_channel *chan)
194{
195 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
196 chan->center_freq);
197
198 if (chan->flags & IEEE80211_CHAN_DISABLED)
199 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
200 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
201 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
202 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
203 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
204 if (chan->flags & IEEE80211_CHAN_RADAR)
205 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
206
207 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
208 DBM_TO_MBM(chan->max_power));
209
210 return 0;
211
212 nla_put_failure:
213 return -ENOBUFS;
214}
215
55682965
JB
216/* netlink command implementations */
217
b9454e83
JB
218struct key_parse {
219 struct key_params p;
220 int idx;
221 bool def, defmgmt;
222};
223
224static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
225{
226 struct nlattr *tb[NL80211_KEY_MAX + 1];
227 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
228 nl80211_key_policy);
229 if (err)
230 return err;
231
232 k->def = !!tb[NL80211_KEY_DEFAULT];
233 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
234
235 if (tb[NL80211_KEY_IDX])
236 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
237
238 if (tb[NL80211_KEY_DATA]) {
239 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
240 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
241 }
242
243 if (tb[NL80211_KEY_SEQ]) {
244 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
245 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
246 }
247
248 if (tb[NL80211_KEY_CIPHER])
249 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
250
251 return 0;
252}
253
254static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
255{
256 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
257 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
258 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
259 }
260
261 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
262 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
263 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
264 }
265
266 if (info->attrs[NL80211_ATTR_KEY_IDX])
267 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
268
269 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
270 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
271
272 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
273 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
274
275 return 0;
276}
277
278static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
279{
280 int err;
281
282 memset(k, 0, sizeof(*k));
283 k->idx = -1;
284
285 if (info->attrs[NL80211_ATTR_KEY])
286 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
287 else
288 err = nl80211_parse_key_old(info, k);
289
290 if (err)
291 return err;
292
293 if (k->def && k->defmgmt)
294 return -EINVAL;
295
296 if (k->idx != -1) {
297 if (k->defmgmt) {
298 if (k->idx < 4 || k->idx > 5)
299 return -EINVAL;
300 } else if (k->def) {
301 if (k->idx < 0 || k->idx > 3)
302 return -EINVAL;
303 } else {
304 if (k->idx < 0 || k->idx > 5)
305 return -EINVAL;
306 }
307 }
308
309 return 0;
310}
311
fffd0934
JB
312static struct cfg80211_cached_keys *
313nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
314 struct nlattr *keys)
315{
316 struct key_parse parse;
317 struct nlattr *key;
318 struct cfg80211_cached_keys *result;
319 int rem, err, def = 0;
320
321 result = kzalloc(sizeof(*result), GFP_KERNEL);
322 if (!result)
323 return ERR_PTR(-ENOMEM);
324
325 result->def = -1;
326 result->defmgmt = -1;
327
328 nla_for_each_nested(key, keys, rem) {
329 memset(&parse, 0, sizeof(parse));
330 parse.idx = -1;
331
332 err = nl80211_parse_key_new(key, &parse);
333 if (err)
334 goto error;
335 err = -EINVAL;
336 if (!parse.p.key)
337 goto error;
338 if (parse.idx < 0 || parse.idx > 4)
339 goto error;
340 if (parse.def) {
341 if (def)
342 goto error;
343 def = 1;
344 result->def = parse.idx;
345 } else if (parse.defmgmt)
346 goto error;
347 err = cfg80211_validate_key_settings(rdev, &parse.p,
348 parse.idx, NULL);
349 if (err)
350 goto error;
351 result->params[parse.idx].cipher = parse.p.cipher;
352 result->params[parse.idx].key_len = parse.p.key_len;
353 result->params[parse.idx].key = result->data[parse.idx];
354 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
355 }
356
357 return result;
358 error:
359 kfree(result);
360 return ERR_PTR(err);
361}
362
363static int nl80211_key_allowed(struct wireless_dev *wdev)
364{
365 ASSERT_WDEV_LOCK(wdev);
366
367 if (!netif_running(wdev->netdev))
368 return -ENETDOWN;
369
370 switch (wdev->iftype) {
371 case NL80211_IFTYPE_AP:
372 case NL80211_IFTYPE_AP_VLAN:
373 break;
374 case NL80211_IFTYPE_ADHOC:
375 if (!wdev->current_bss)
376 return -ENOLINK;
377 break;
378 case NL80211_IFTYPE_STATION:
379 if (wdev->sme_state != CFG80211_SME_CONNECTED)
380 return -ENOLINK;
381 break;
382 default:
383 return -EINVAL;
384 }
385
386 return 0;
387}
388
55682965
JB
389static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
390 struct cfg80211_registered_device *dev)
391{
392 void *hdr;
ee688b00
JB
393 struct nlattr *nl_bands, *nl_band;
394 struct nlattr *nl_freqs, *nl_freq;
395 struct nlattr *nl_rates, *nl_rate;
f59ac048 396 struct nlattr *nl_modes;
8fdc621d 397 struct nlattr *nl_cmds;
ee688b00
JB
398 enum ieee80211_band band;
399 struct ieee80211_channel *chan;
400 struct ieee80211_rate *rate;
401 int i;
f59ac048 402 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
403
404 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
405 if (!hdr)
406 return -1;
407
b5850a7a 408 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 409 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 410
f5ea9120
JB
411 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
412 cfg80211_rdev_list_generation);
413
b9a5f8ca
JM
414 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
415 dev->wiphy.retry_short);
416 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
417 dev->wiphy.retry_long);
418 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
419 dev->wiphy.frag_threshold);
420 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
421 dev->wiphy.rts_threshold);
422
2a519311
JB
423 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
424 dev->wiphy.max_scan_ssids);
18a83659
JB
425 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
426 dev->wiphy.max_scan_ie_len);
ee688b00 427
25e47c18
JB
428 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
429 sizeof(u32) * dev->wiphy.n_cipher_suites,
430 dev->wiphy.cipher_suites);
431
f59ac048
LR
432 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
433 if (!nl_modes)
434 goto nla_put_failure;
435
436 i = 0;
437 while (ifmodes) {
438 if (ifmodes & 1)
439 NLA_PUT_FLAG(msg, i);
440 ifmodes >>= 1;
441 i++;
442 }
443
444 nla_nest_end(msg, nl_modes);
445
ee688b00
JB
446 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
447 if (!nl_bands)
448 goto nla_put_failure;
449
450 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
451 if (!dev->wiphy.bands[band])
452 continue;
453
454 nl_band = nla_nest_start(msg, band);
455 if (!nl_band)
456 goto nla_put_failure;
457
d51626df
JB
458 /* add HT info */
459 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
460 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
461 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
462 &dev->wiphy.bands[band]->ht_cap.mcs);
463 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
464 dev->wiphy.bands[band]->ht_cap.cap);
465 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
466 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
467 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
468 dev->wiphy.bands[band]->ht_cap.ampdu_density);
469 }
470
ee688b00
JB
471 /* add frequencies */
472 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
473 if (!nl_freqs)
474 goto nla_put_failure;
475
476 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
477 nl_freq = nla_nest_start(msg, i);
478 if (!nl_freq)
479 goto nla_put_failure;
480
481 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
482
483 if (nl80211_msg_put_channel(msg, chan))
484 goto nla_put_failure;
e2f367f2 485
ee688b00
JB
486 nla_nest_end(msg, nl_freq);
487 }
488
489 nla_nest_end(msg, nl_freqs);
490
491 /* add bitrates */
492 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
493 if (!nl_rates)
494 goto nla_put_failure;
495
496 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
497 nl_rate = nla_nest_start(msg, i);
498 if (!nl_rate)
499 goto nla_put_failure;
500
501 rate = &dev->wiphy.bands[band]->bitrates[i];
502 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
503 rate->bitrate);
504 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
505 NLA_PUT_FLAG(msg,
506 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
507
508 nla_nest_end(msg, nl_rate);
509 }
510
511 nla_nest_end(msg, nl_rates);
512
513 nla_nest_end(msg, nl_band);
514 }
515 nla_nest_end(msg, nl_bands);
516
8fdc621d
JB
517 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
518 if (!nl_cmds)
519 goto nla_put_failure;
520
521 i = 0;
522#define CMD(op, n) \
523 do { \
524 if (dev->ops->op) { \
525 i++; \
526 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
527 } \
528 } while (0)
529
530 CMD(add_virtual_intf, NEW_INTERFACE);
531 CMD(change_virtual_intf, SET_INTERFACE);
532 CMD(add_key, NEW_KEY);
533 CMD(add_beacon, NEW_BEACON);
534 CMD(add_station, NEW_STATION);
535 CMD(add_mpath, NEW_MPATH);
536 CMD(set_mesh_params, SET_MESH_PARAMS);
537 CMD(change_bss, SET_BSS);
636a5d36
JM
538 CMD(auth, AUTHENTICATE);
539 CMD(assoc, ASSOCIATE);
540 CMD(deauth, DEAUTHENTICATE);
541 CMD(disassoc, DISASSOCIATE);
04a773ad 542 CMD(join_ibss, JOIN_IBSS);
463d0183
JB
543 if (dev->wiphy.netnsok) {
544 i++;
545 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
546 }
8fdc621d
JB
547
548#undef CMD
b23aa676 549
6829c878 550 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
551 i++;
552 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
553 }
554
6829c878 555 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
556 i++;
557 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
558 }
559
8fdc621d
JB
560 nla_nest_end(msg, nl_cmds);
561
55682965
JB
562 return genlmsg_end(msg, hdr);
563
564 nla_put_failure:
bc3ed28c
TG
565 genlmsg_cancel(msg, hdr);
566 return -EMSGSIZE;
55682965
JB
567}
568
569static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
570{
571 int idx = 0;
572 int start = cb->args[0];
573 struct cfg80211_registered_device *dev;
574
a1794390 575 mutex_lock(&cfg80211_mutex);
79c97e97 576 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
577 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
578 continue;
b4637271 579 if (++idx <= start)
55682965
JB
580 continue;
581 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
582 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
583 dev) < 0) {
584 idx--;
55682965 585 break;
b4637271 586 }
55682965 587 }
a1794390 588 mutex_unlock(&cfg80211_mutex);
55682965
JB
589
590 cb->args[0] = idx;
591
592 return skb->len;
593}
594
595static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
596{
597 struct sk_buff *msg;
598 struct cfg80211_registered_device *dev;
599
600 dev = cfg80211_get_dev_from_info(info);
601 if (IS_ERR(dev))
602 return PTR_ERR(dev);
603
fd2120ca 604 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
605 if (!msg)
606 goto out_err;
607
608 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
609 goto out_free;
610
4d0c8aea 611 cfg80211_unlock_rdev(dev);
55682965 612
134e6375 613 return genlmsg_reply(msg, info);
55682965
JB
614
615 out_free:
616 nlmsg_free(msg);
617 out_err:
4d0c8aea 618 cfg80211_unlock_rdev(dev);
55682965
JB
619 return -ENOBUFS;
620}
621
31888487
JM
622static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
623 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
624 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
625 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
626 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
627 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
628};
629
630static int parse_txq_params(struct nlattr *tb[],
631 struct ieee80211_txq_params *txq_params)
632{
633 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
634 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
635 !tb[NL80211_TXQ_ATTR_AIFS])
636 return -EINVAL;
637
638 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
639 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
640 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
641 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
642 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
643
644 return 0;
645}
646
55682965
JB
647static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
648{
649 struct cfg80211_registered_device *rdev;
31888487
JM
650 int result = 0, rem_txq_params = 0;
651 struct nlattr *nl_txq_params;
b9a5f8ca
JM
652 u32 changed;
653 u8 retry_short = 0, retry_long = 0;
654 u32 frag_threshold = 0, rts_threshold = 0;
55682965 655
4bbf4d56 656 rtnl_lock();
55682965 657
4bbf4d56
JB
658 mutex_lock(&cfg80211_mutex);
659
79c97e97 660 rdev = __cfg80211_rdev_from_info(info);
4bbf4d56 661 if (IS_ERR(rdev)) {
1f5fc70a 662 mutex_unlock(&cfg80211_mutex);
4bbf4d56
JB
663 result = PTR_ERR(rdev);
664 goto unlock;
665 }
666
667 mutex_lock(&rdev->mtx);
668
669 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
670 result = cfg80211_dev_rename(
671 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
672
673 mutex_unlock(&cfg80211_mutex);
674
675 if (result)
676 goto bad_res;
31888487
JM
677
678 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
679 struct ieee80211_txq_params txq_params;
680 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
681
682 if (!rdev->ops->set_txq_params) {
683 result = -EOPNOTSUPP;
684 goto bad_res;
685 }
686
687 nla_for_each_nested(nl_txq_params,
688 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
689 rem_txq_params) {
690 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
691 nla_data(nl_txq_params),
692 nla_len(nl_txq_params),
693 txq_params_policy);
694 result = parse_txq_params(tb, &txq_params);
695 if (result)
696 goto bad_res;
697
698 result = rdev->ops->set_txq_params(&rdev->wiphy,
699 &txq_params);
700 if (result)
701 goto bad_res;
702 }
703 }
55682965 704
72bdcf34 705 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
094d05dc 706 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
294196ab 707 u32 freq;
72bdcf34 708
306d6112
JB
709 result = -EINVAL;
710
094d05dc
S
711 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
712 channel_type = nla_get_u32(info->attrs[
713 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
714 if (channel_type != NL80211_CHAN_NO_HT &&
715 channel_type != NL80211_CHAN_HT20 &&
716 channel_type != NL80211_CHAN_HT40PLUS &&
717 channel_type != NL80211_CHAN_HT40MINUS)
72bdcf34 718 goto bad_res;
72bdcf34
JM
719 }
720
721 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
306d6112 722
59bbb6f7 723 mutex_lock(&rdev->devlist_mtx);
4b181144 724 result = rdev_set_freq(rdev, NULL, freq, channel_type);
59bbb6f7 725 mutex_unlock(&rdev->devlist_mtx);
72bdcf34
JM
726 if (result)
727 goto bad_res;
728 }
729
b9a5f8ca
JM
730 changed = 0;
731
732 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
733 retry_short = nla_get_u8(
734 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
735 if (retry_short == 0) {
736 result = -EINVAL;
737 goto bad_res;
738 }
739 changed |= WIPHY_PARAM_RETRY_SHORT;
740 }
741
742 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
743 retry_long = nla_get_u8(
744 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
745 if (retry_long == 0) {
746 result = -EINVAL;
747 goto bad_res;
748 }
749 changed |= WIPHY_PARAM_RETRY_LONG;
750 }
751
752 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
753 frag_threshold = nla_get_u32(
754 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
755 if (frag_threshold < 256) {
756 result = -EINVAL;
757 goto bad_res;
758 }
759 if (frag_threshold != (u32) -1) {
760 /*
761 * Fragments (apart from the last one) are required to
762 * have even length. Make the fragmentation code
763 * simpler by stripping LSB should someone try to use
764 * odd threshold value.
765 */
766 frag_threshold &= ~0x1;
767 }
768 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
769 }
770
771 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
772 rts_threshold = nla_get_u32(
773 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
774 changed |= WIPHY_PARAM_RTS_THRESHOLD;
775 }
776
777 if (changed) {
778 u8 old_retry_short, old_retry_long;
779 u32 old_frag_threshold, old_rts_threshold;
780
781 if (!rdev->ops->set_wiphy_params) {
782 result = -EOPNOTSUPP;
783 goto bad_res;
784 }
785
786 old_retry_short = rdev->wiphy.retry_short;
787 old_retry_long = rdev->wiphy.retry_long;
788 old_frag_threshold = rdev->wiphy.frag_threshold;
789 old_rts_threshold = rdev->wiphy.rts_threshold;
790
791 if (changed & WIPHY_PARAM_RETRY_SHORT)
792 rdev->wiphy.retry_short = retry_short;
793 if (changed & WIPHY_PARAM_RETRY_LONG)
794 rdev->wiphy.retry_long = retry_long;
795 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
796 rdev->wiphy.frag_threshold = frag_threshold;
797 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
798 rdev->wiphy.rts_threshold = rts_threshold;
799
800 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
801 if (result) {
802 rdev->wiphy.retry_short = old_retry_short;
803 rdev->wiphy.retry_long = old_retry_long;
804 rdev->wiphy.frag_threshold = old_frag_threshold;
805 rdev->wiphy.rts_threshold = old_rts_threshold;
806 }
807 }
72bdcf34 808
306d6112 809 bad_res:
4bbf4d56
JB
810 mutex_unlock(&rdev->mtx);
811 unlock:
812 rtnl_unlock();
55682965
JB
813 return result;
814}
815
816
817static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 818 struct cfg80211_registered_device *rdev,
55682965
JB
819 struct net_device *dev)
820{
821 void *hdr;
822
823 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
824 if (!hdr)
825 return -1;
826
827 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 828 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 829 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 830 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
831
832 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
833 rdev->devlist_generation ^
834 (cfg80211_rdev_list_generation << 2));
835
55682965
JB
836 return genlmsg_end(msg, hdr);
837
838 nla_put_failure:
bc3ed28c
TG
839 genlmsg_cancel(msg, hdr);
840 return -EMSGSIZE;
55682965
JB
841}
842
843static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
844{
845 int wp_idx = 0;
846 int if_idx = 0;
847 int wp_start = cb->args[0];
848 int if_start = cb->args[1];
f5ea9120 849 struct cfg80211_registered_device *rdev;
55682965
JB
850 struct wireless_dev *wdev;
851
a1794390 852 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
853 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
854 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 855 continue;
bba95fef
JB
856 if (wp_idx < wp_start) {
857 wp_idx++;
55682965 858 continue;
bba95fef 859 }
55682965
JB
860 if_idx = 0;
861
f5ea9120
JB
862 mutex_lock(&rdev->devlist_mtx);
863 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
864 if (if_idx < if_start) {
865 if_idx++;
55682965 866 continue;
bba95fef 867 }
55682965
JB
868 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
869 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
870 rdev, wdev->netdev) < 0) {
871 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
872 goto out;
873 }
874 if_idx++;
55682965 875 }
f5ea9120 876 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
877
878 wp_idx++;
55682965 879 }
bba95fef 880 out:
a1794390 881 mutex_unlock(&cfg80211_mutex);
55682965
JB
882
883 cb->args[0] = wp_idx;
884 cb->args[1] = if_idx;
885
886 return skb->len;
887}
888
889static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
890{
891 struct sk_buff *msg;
892 struct cfg80211_registered_device *dev;
893 struct net_device *netdev;
894 int err;
895
463d0183 896 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
897 if (err)
898 return err;
899
fd2120ca 900 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
901 if (!msg)
902 goto out_err;
903
d726405a
JB
904 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
905 dev, netdev) < 0)
55682965
JB
906 goto out_free;
907
908 dev_put(netdev);
4d0c8aea 909 cfg80211_unlock_rdev(dev);
55682965 910
134e6375 911 return genlmsg_reply(msg, info);
55682965
JB
912
913 out_free:
914 nlmsg_free(msg);
915 out_err:
916 dev_put(netdev);
4d0c8aea 917 cfg80211_unlock_rdev(dev);
55682965
JB
918 return -ENOBUFS;
919}
920
66f7ac50
MW
921static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
922 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
923 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
924 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
925 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
926 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
927};
928
929static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
930{
931 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
932 int flag;
933
934 *mntrflags = 0;
935
936 if (!nla)
937 return -EINVAL;
938
939 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
940 nla, mntr_flags_policy))
941 return -EINVAL;
942
943 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
944 if (flags[flag])
945 *mntrflags |= (1<<flag);
946
947 return 0;
948}
949
55682965
JB
950static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
951{
79c97e97 952 struct cfg80211_registered_device *rdev;
2ec600d6 953 struct vif_params params;
e36d56b6 954 int err;
04a773ad 955 enum nl80211_iftype otype, ntype;
55682965 956 struct net_device *dev;
92ffe055 957 u32 _flags, *flags = NULL;
ac7f9cfa 958 bool change = false;
55682965 959
2ec600d6
LCC
960 memset(&params, 0, sizeof(params));
961
3b85875a
JB
962 rtnl_lock();
963
463d0183 964 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 965 if (err)
3b85875a
JB
966 goto unlock_rtnl;
967
04a773ad 968 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 969
723b038d 970 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 971 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 972 if (otype != ntype)
ac7f9cfa 973 change = true;
04a773ad 974 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 975 err = -EINVAL;
723b038d 976 goto unlock;
ac7f9cfa 977 }
723b038d
JB
978 }
979
92ffe055 980 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 981 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
982 err = -EINVAL;
983 goto unlock;
984 }
2ec600d6
LCC
985 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
986 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 987 change = true;
2ec600d6
LCC
988 }
989
92ffe055 990 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 991 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
992 err = -EINVAL;
993 goto unlock;
994 }
995 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
996 &_flags);
ac7f9cfa
JB
997 if (err)
998 goto unlock;
999
1000 flags = &_flags;
1001 change = true;
92ffe055 1002 }
3b85875a 1003
ac7f9cfa 1004 if (change)
3d54d255 1005 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1006 else
1007 err = 0;
60719ffd 1008
55682965 1009 unlock:
e36d56b6 1010 dev_put(dev);
79c97e97 1011 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1012 unlock_rtnl:
1013 rtnl_unlock();
55682965
JB
1014 return err;
1015}
1016
1017static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1018{
79c97e97 1019 struct cfg80211_registered_device *rdev;
2ec600d6 1020 struct vif_params params;
55682965
JB
1021 int err;
1022 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1023 u32 flags;
55682965 1024
2ec600d6
LCC
1025 memset(&params, 0, sizeof(params));
1026
55682965
JB
1027 if (!info->attrs[NL80211_ATTR_IFNAME])
1028 return -EINVAL;
1029
1030 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1031 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1032 if (type > NL80211_IFTYPE_MAX)
1033 return -EINVAL;
1034 }
1035
3b85875a
JB
1036 rtnl_lock();
1037
79c97e97
JB
1038 rdev = cfg80211_get_dev_from_info(info);
1039 if (IS_ERR(rdev)) {
1040 err = PTR_ERR(rdev);
3b85875a
JB
1041 goto unlock_rtnl;
1042 }
55682965 1043
79c97e97
JB
1044 if (!rdev->ops->add_virtual_intf ||
1045 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1046 err = -EOPNOTSUPP;
1047 goto unlock;
1048 }
1049
2ec600d6
LCC
1050 if (type == NL80211_IFTYPE_MESH_POINT &&
1051 info->attrs[NL80211_ATTR_MESH_ID]) {
1052 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1053 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1054 }
1055
66f7ac50
MW
1056 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1057 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1058 &flags);
79c97e97 1059 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1060 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1061 type, err ? NULL : &flags, &params);
2ec600d6 1062
55682965 1063 unlock:
79c97e97 1064 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1065 unlock_rtnl:
1066 rtnl_unlock();
55682965
JB
1067 return err;
1068}
1069
1070static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1071{
79c97e97 1072 struct cfg80211_registered_device *rdev;
463d0183 1073 int err;
55682965
JB
1074 struct net_device *dev;
1075
3b85875a
JB
1076 rtnl_lock();
1077
463d0183 1078 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1079 if (err)
3b85875a 1080 goto unlock_rtnl;
55682965 1081
79c97e97 1082 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1083 err = -EOPNOTSUPP;
1084 goto out;
1085 }
1086
463d0183 1087 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1088
1089 out:
79c97e97 1090 cfg80211_unlock_rdev(rdev);
463d0183 1091 dev_put(dev);
3b85875a
JB
1092 unlock_rtnl:
1093 rtnl_unlock();
55682965
JB
1094 return err;
1095}
1096
41ade00f
JB
1097struct get_key_cookie {
1098 struct sk_buff *msg;
1099 int error;
b9454e83 1100 int idx;
41ade00f
JB
1101};
1102
1103static void get_key_callback(void *c, struct key_params *params)
1104{
b9454e83 1105 struct nlattr *key;
41ade00f
JB
1106 struct get_key_cookie *cookie = c;
1107
1108 if (params->key)
1109 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1110 params->key_len, params->key);
1111
1112 if (params->seq)
1113 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1114 params->seq_len, params->seq);
1115
1116 if (params->cipher)
1117 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1118 params->cipher);
1119
b9454e83
JB
1120 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1121 if (!key)
1122 goto nla_put_failure;
1123
1124 if (params->key)
1125 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1126 params->key_len, params->key);
1127
1128 if (params->seq)
1129 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1130 params->seq_len, params->seq);
1131
1132 if (params->cipher)
1133 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1134 params->cipher);
1135
1136 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1137
1138 nla_nest_end(cookie->msg, key);
1139
41ade00f
JB
1140 return;
1141 nla_put_failure:
1142 cookie->error = 1;
1143}
1144
1145static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1146{
79c97e97 1147 struct cfg80211_registered_device *rdev;
41ade00f
JB
1148 int err;
1149 struct net_device *dev;
1150 u8 key_idx = 0;
1151 u8 *mac_addr = NULL;
1152 struct get_key_cookie cookie = {
1153 .error = 0,
1154 };
1155 void *hdr;
1156 struct sk_buff *msg;
1157
1158 if (info->attrs[NL80211_ATTR_KEY_IDX])
1159 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1160
3cfcf6ac 1161 if (key_idx > 5)
41ade00f
JB
1162 return -EINVAL;
1163
1164 if (info->attrs[NL80211_ATTR_MAC])
1165 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1166
3b85875a
JB
1167 rtnl_lock();
1168
463d0183 1169 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1170 if (err)
3b85875a 1171 goto unlock_rtnl;
41ade00f 1172
79c97e97 1173 if (!rdev->ops->get_key) {
41ade00f
JB
1174 err = -EOPNOTSUPP;
1175 goto out;
1176 }
1177
fd2120ca 1178 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1179 if (!msg) {
1180 err = -ENOMEM;
1181 goto out;
1182 }
1183
1184 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1185 NL80211_CMD_NEW_KEY);
1186
1187 if (IS_ERR(hdr)) {
1188 err = PTR_ERR(hdr);
6c95e2a2 1189 goto free_msg;
41ade00f
JB
1190 }
1191
1192 cookie.msg = msg;
b9454e83 1193 cookie.idx = key_idx;
41ade00f
JB
1194
1195 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1196 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1197 if (mac_addr)
1198 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1199
79c97e97 1200 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1201 &cookie, get_key_callback);
41ade00f
JB
1202
1203 if (err)
6c95e2a2 1204 goto free_msg;
41ade00f
JB
1205
1206 if (cookie.error)
1207 goto nla_put_failure;
1208
1209 genlmsg_end(msg, hdr);
134e6375 1210 err = genlmsg_reply(msg, info);
41ade00f
JB
1211 goto out;
1212
1213 nla_put_failure:
1214 err = -ENOBUFS;
6c95e2a2 1215 free_msg:
41ade00f
JB
1216 nlmsg_free(msg);
1217 out:
79c97e97 1218 cfg80211_unlock_rdev(rdev);
41ade00f 1219 dev_put(dev);
3b85875a
JB
1220 unlock_rtnl:
1221 rtnl_unlock();
1222
41ade00f
JB
1223 return err;
1224}
1225
1226static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1227{
79c97e97 1228 struct cfg80211_registered_device *rdev;
b9454e83 1229 struct key_parse key;
41ade00f
JB
1230 int err;
1231 struct net_device *dev;
3cfcf6ac
JM
1232 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1233 u8 key_index);
41ade00f 1234
b9454e83
JB
1235 err = nl80211_parse_key(info, &key);
1236 if (err)
1237 return err;
41ade00f 1238
b9454e83 1239 if (key.idx < 0)
41ade00f
JB
1240 return -EINVAL;
1241
b9454e83
JB
1242 /* only support setting default key */
1243 if (!key.def && !key.defmgmt)
41ade00f
JB
1244 return -EINVAL;
1245
3b85875a
JB
1246 rtnl_lock();
1247
463d0183 1248 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1249 if (err)
3b85875a 1250 goto unlock_rtnl;
41ade00f 1251
b9454e83 1252 if (key.def)
79c97e97 1253 func = rdev->ops->set_default_key;
3cfcf6ac 1254 else
79c97e97 1255 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1256
1257 if (!func) {
41ade00f
JB
1258 err = -EOPNOTSUPP;
1259 goto out;
1260 }
1261
fffd0934
JB
1262 wdev_lock(dev->ieee80211_ptr);
1263 err = nl80211_key_allowed(dev->ieee80211_ptr);
1264 if (!err)
1265 err = func(&rdev->wiphy, dev, key.idx);
1266
08645126
JB
1267#ifdef CONFIG_WIRELESS_EXT
1268 if (!err) {
79c97e97 1269 if (func == rdev->ops->set_default_key)
b9454e83 1270 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1271 else
b9454e83 1272 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1273 }
1274#endif
fffd0934 1275 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1276
1277 out:
79c97e97 1278 cfg80211_unlock_rdev(rdev);
41ade00f 1279 dev_put(dev);
3b85875a
JB
1280
1281 unlock_rtnl:
1282 rtnl_unlock();
1283
41ade00f
JB
1284 return err;
1285}
1286
1287static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1288{
79c97e97 1289 struct cfg80211_registered_device *rdev;
fffd0934 1290 int err;
41ade00f 1291 struct net_device *dev;
b9454e83 1292 struct key_parse key;
41ade00f
JB
1293 u8 *mac_addr = NULL;
1294
b9454e83
JB
1295 err = nl80211_parse_key(info, &key);
1296 if (err)
1297 return err;
41ade00f 1298
b9454e83 1299 if (!key.p.key)
41ade00f
JB
1300 return -EINVAL;
1301
41ade00f
JB
1302 if (info->attrs[NL80211_ATTR_MAC])
1303 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1304
3b85875a
JB
1305 rtnl_lock();
1306
463d0183 1307 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1308 if (err)
3b85875a 1309 goto unlock_rtnl;
41ade00f 1310
fffd0934
JB
1311 if (!rdev->ops->add_key) {
1312 err = -EOPNOTSUPP;
25e47c18
JB
1313 goto out;
1314 }
1315
fffd0934
JB
1316 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1317 err = -EINVAL;
41ade00f
JB
1318 goto out;
1319 }
1320
fffd0934
JB
1321 wdev_lock(dev->ieee80211_ptr);
1322 err = nl80211_key_allowed(dev->ieee80211_ptr);
1323 if (!err)
1324 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1325 mac_addr, &key.p);
1326 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1327
1328 out:
79c97e97 1329 cfg80211_unlock_rdev(rdev);
41ade00f 1330 dev_put(dev);
3b85875a
JB
1331 unlock_rtnl:
1332 rtnl_unlock();
1333
41ade00f
JB
1334 return err;
1335}
1336
1337static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1338{
79c97e97 1339 struct cfg80211_registered_device *rdev;
41ade00f
JB
1340 int err;
1341 struct net_device *dev;
41ade00f 1342 u8 *mac_addr = NULL;
b9454e83 1343 struct key_parse key;
41ade00f 1344
b9454e83
JB
1345 err = nl80211_parse_key(info, &key);
1346 if (err)
1347 return err;
41ade00f
JB
1348
1349 if (info->attrs[NL80211_ATTR_MAC])
1350 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1351
3b85875a
JB
1352 rtnl_lock();
1353
463d0183 1354 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1355 if (err)
3b85875a 1356 goto unlock_rtnl;
41ade00f 1357
79c97e97 1358 if (!rdev->ops->del_key) {
41ade00f
JB
1359 err = -EOPNOTSUPP;
1360 goto out;
1361 }
1362
fffd0934
JB
1363 wdev_lock(dev->ieee80211_ptr);
1364 err = nl80211_key_allowed(dev->ieee80211_ptr);
1365 if (!err)
1366 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1367
08645126
JB
1368#ifdef CONFIG_WIRELESS_EXT
1369 if (!err) {
b9454e83 1370 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1371 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1372 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1373 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1374 }
1375#endif
fffd0934 1376 wdev_unlock(dev->ieee80211_ptr);
08645126 1377
41ade00f 1378 out:
79c97e97 1379 cfg80211_unlock_rdev(rdev);
41ade00f 1380 dev_put(dev);
3b85875a
JB
1381
1382 unlock_rtnl:
1383 rtnl_unlock();
1384
41ade00f
JB
1385 return err;
1386}
1387
ed1b6cc7
JB
1388static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1389{
1390 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1391 struct beacon_parameters *info);
79c97e97 1392 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1393 int err;
1394 struct net_device *dev;
1395 struct beacon_parameters params;
1396 int haveinfo = 0;
1397
f4a11bb0
JB
1398 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1399 return -EINVAL;
1400
3b85875a
JB
1401 rtnl_lock();
1402
463d0183 1403 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1404 if (err)
3b85875a 1405 goto unlock_rtnl;
ed1b6cc7 1406
eec60b03
JM
1407 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1408 err = -EOPNOTSUPP;
1409 goto out;
1410 }
1411
ed1b6cc7
JB
1412 switch (info->genlhdr->cmd) {
1413 case NL80211_CMD_NEW_BEACON:
1414 /* these are required for NEW_BEACON */
1415 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1416 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1417 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1418 err = -EINVAL;
1419 goto out;
1420 }
1421
79c97e97 1422 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1423 break;
1424 case NL80211_CMD_SET_BEACON:
79c97e97 1425 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1426 break;
1427 default:
1428 WARN_ON(1);
1429 err = -EOPNOTSUPP;
1430 goto out;
1431 }
1432
1433 if (!call) {
1434 err = -EOPNOTSUPP;
1435 goto out;
1436 }
1437
1438 memset(&params, 0, sizeof(params));
1439
1440 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1441 params.interval =
1442 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1443 haveinfo = 1;
1444 }
1445
1446 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1447 params.dtim_period =
1448 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1449 haveinfo = 1;
1450 }
1451
1452 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1453 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1454 params.head_len =
1455 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1456 haveinfo = 1;
1457 }
1458
1459 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1460 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1461 params.tail_len =
1462 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1463 haveinfo = 1;
1464 }
1465
1466 if (!haveinfo) {
1467 err = -EINVAL;
1468 goto out;
1469 }
1470
79c97e97 1471 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1472
1473 out:
79c97e97 1474 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1475 dev_put(dev);
3b85875a
JB
1476 unlock_rtnl:
1477 rtnl_unlock();
1478
ed1b6cc7
JB
1479 return err;
1480}
1481
1482static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1483{
79c97e97 1484 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1485 int err;
1486 struct net_device *dev;
1487
3b85875a
JB
1488 rtnl_lock();
1489
463d0183 1490 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1491 if (err)
3b85875a 1492 goto unlock_rtnl;
ed1b6cc7 1493
79c97e97 1494 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1495 err = -EOPNOTSUPP;
1496 goto out;
1497 }
1498
eec60b03
JM
1499 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1500 err = -EOPNOTSUPP;
1501 goto out;
1502 }
79c97e97 1503 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1504
1505 out:
79c97e97 1506 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1507 dev_put(dev);
3b85875a
JB
1508 unlock_rtnl:
1509 rtnl_unlock();
1510
ed1b6cc7
JB
1511 return err;
1512}
1513
5727ef1b
JB
1514static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1515 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1516 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1517 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1518 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1519};
1520
eccb8e8f
JB
1521static int parse_station_flags(struct genl_info *info,
1522 struct station_parameters *params)
5727ef1b
JB
1523{
1524 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1525 struct nlattr *nla;
5727ef1b
JB
1526 int flag;
1527
eccb8e8f
JB
1528 /*
1529 * Try parsing the new attribute first so userspace
1530 * can specify both for older kernels.
1531 */
1532 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1533 if (nla) {
1534 struct nl80211_sta_flag_update *sta_flags;
1535
1536 sta_flags = nla_data(nla);
1537 params->sta_flags_mask = sta_flags->mask;
1538 params->sta_flags_set = sta_flags->set;
1539 if ((params->sta_flags_mask |
1540 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1541 return -EINVAL;
1542 return 0;
1543 }
1544
1545 /* if present, parse the old attribute */
5727ef1b 1546
eccb8e8f 1547 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1548 if (!nla)
1549 return 0;
1550
1551 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1552 nla, sta_flags_policy))
1553 return -EINVAL;
1554
eccb8e8f
JB
1555 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1556 params->sta_flags_mask &= ~1;
5727ef1b
JB
1557
1558 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1559 if (flags[flag])
eccb8e8f 1560 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1561
1562 return 0;
1563}
1564
420e7fab
HR
1565static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1566{
1567 int modulation, streams, bitrate;
1568
1569 if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1570 return rate->legacy;
1571
1572 /* the formula below does only work for MCS values smaller than 32 */
1573 if (rate->mcs >= 32)
1574 return 0;
1575
1576 modulation = rate->mcs & 7;
1577 streams = (rate->mcs >> 3) + 1;
1578
1579 bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1580 13500000 : 6500000;
1581
1582 if (modulation < 4)
1583 bitrate *= (modulation + 1);
1584 else if (modulation == 4)
1585 bitrate *= (modulation + 2);
1586 else
1587 bitrate *= (modulation + 3);
1588
1589 bitrate *= streams;
1590
1591 if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1592 bitrate = (bitrate / 9) * 10;
1593
1594 /* do NOT round down here */
1595 return (bitrate + 50000) / 100000;
1596}
1597
fd5b74dc
JB
1598static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1599 int flags, struct net_device *dev,
2ec600d6 1600 u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1601{
1602 void *hdr;
420e7fab
HR
1603 struct nlattr *sinfoattr, *txrate;
1604 u16 bitrate;
fd5b74dc
JB
1605
1606 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1607 if (!hdr)
1608 return -1;
1609
1610 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1611 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1612
f5ea9120
JB
1613 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1614
2ec600d6
LCC
1615 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1616 if (!sinfoattr)
fd5b74dc 1617 goto nla_put_failure;
2ec600d6
LCC
1618 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1619 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1620 sinfo->inactive_time);
1621 if (sinfo->filled & STATION_INFO_RX_BYTES)
1622 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1623 sinfo->rx_bytes);
1624 if (sinfo->filled & STATION_INFO_TX_BYTES)
1625 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1626 sinfo->tx_bytes);
1627 if (sinfo->filled & STATION_INFO_LLID)
1628 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1629 sinfo->llid);
1630 if (sinfo->filled & STATION_INFO_PLID)
1631 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1632 sinfo->plid);
1633 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1634 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1635 sinfo->plink_state);
420e7fab
HR
1636 if (sinfo->filled & STATION_INFO_SIGNAL)
1637 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1638 sinfo->signal);
1639 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1640 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1641 if (!txrate)
1642 goto nla_put_failure;
1643
1644 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1645 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1646 if (bitrate > 0)
1647 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1648
420e7fab
HR
1649 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1650 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1651 sinfo->txrate.mcs);
1652 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1653 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1654 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1655 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1656
1657 nla_nest_end(msg, txrate);
1658 }
98c8a60a
JM
1659 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1660 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1661 sinfo->rx_packets);
1662 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1663 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1664 sinfo->tx_packets);
2ec600d6 1665 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1666
1667 return genlmsg_end(msg, hdr);
1668
1669 nla_put_failure:
bc3ed28c
TG
1670 genlmsg_cancel(msg, hdr);
1671 return -EMSGSIZE;
fd5b74dc
JB
1672}
1673
2ec600d6 1674static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1675 struct netlink_callback *cb)
2ec600d6 1676{
2ec600d6
LCC
1677 struct station_info sinfo;
1678 struct cfg80211_registered_device *dev;
bba95fef 1679 struct net_device *netdev;
2ec600d6 1680 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1681 int ifidx = cb->args[0];
1682 int sta_idx = cb->args[1];
2ec600d6 1683 int err;
2ec600d6 1684
bba95fef
JB
1685 if (!ifidx) {
1686 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1687 nl80211_fam.attrbuf, nl80211_fam.maxattr,
1688 nl80211_policy);
1689 if (err)
1690 return err;
2ec600d6 1691
bba95fef
JB
1692 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1693 return -EINVAL;
2ec600d6 1694
bba95fef
JB
1695 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1696 if (!ifidx)
1697 return -EINVAL;
2ec600d6 1698 }
2ec600d6 1699
3b85875a
JB
1700 rtnl_lock();
1701
463d0183 1702 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1703 if (!netdev) {
1704 err = -ENODEV;
1705 goto out_rtnl;
1706 }
2ec600d6 1707
463d0183 1708 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1709 if (IS_ERR(dev)) {
1710 err = PTR_ERR(dev);
3b85875a 1711 goto out_rtnl;
bba95fef
JB
1712 }
1713
1714 if (!dev->ops->dump_station) {
eec60b03 1715 err = -EOPNOTSUPP;
bba95fef
JB
1716 goto out_err;
1717 }
1718
bba95fef
JB
1719 while (1) {
1720 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1721 mac_addr, &sinfo);
1722 if (err == -ENOENT)
1723 break;
1724 if (err)
3b85875a 1725 goto out_err;
bba95fef
JB
1726
1727 if (nl80211_send_station(skb,
1728 NETLINK_CB(cb->skb).pid,
1729 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1730 netdev, mac_addr,
1731 &sinfo) < 0)
1732 goto out;
1733
1734 sta_idx++;
1735 }
1736
1737
1738 out:
1739 cb->args[1] = sta_idx;
1740 err = skb->len;
bba95fef 1741 out_err:
4d0c8aea 1742 cfg80211_unlock_rdev(dev);
3b85875a
JB
1743 out_rtnl:
1744 rtnl_unlock();
bba95fef
JB
1745
1746 return err;
2ec600d6 1747}
fd5b74dc 1748
5727ef1b
JB
1749static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1750{
79c97e97 1751 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1752 int err;
1753 struct net_device *dev;
2ec600d6 1754 struct station_info sinfo;
fd5b74dc
JB
1755 struct sk_buff *msg;
1756 u8 *mac_addr = NULL;
1757
2ec600d6 1758 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1759
1760 if (!info->attrs[NL80211_ATTR_MAC])
1761 return -EINVAL;
1762
1763 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1764
3b85875a
JB
1765 rtnl_lock();
1766
463d0183 1767 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 1768 if (err)
3b85875a 1769 goto out_rtnl;
fd5b74dc 1770
79c97e97 1771 if (!rdev->ops->get_station) {
fd5b74dc
JB
1772 err = -EOPNOTSUPP;
1773 goto out;
1774 }
1775
79c97e97 1776 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1777 if (err)
1778 goto out;
1779
fd2120ca 1780 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1781 if (!msg)
1782 goto out;
1783
1784 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1785 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1786 goto out_free;
1787
134e6375 1788 err = genlmsg_reply(msg, info);
fd5b74dc
JB
1789 goto out;
1790
1791 out_free:
1792 nlmsg_free(msg);
fd5b74dc 1793 out:
79c97e97 1794 cfg80211_unlock_rdev(rdev);
fd5b74dc 1795 dev_put(dev);
3b85875a
JB
1796 out_rtnl:
1797 rtnl_unlock();
1798
fd5b74dc 1799 return err;
5727ef1b
JB
1800}
1801
1802/*
1803 * Get vlan interface making sure it is on the right wiphy.
1804 */
463d0183 1805static int get_vlan(struct genl_info *info,
5727ef1b
JB
1806 struct cfg80211_registered_device *rdev,
1807 struct net_device **vlan)
1808{
463d0183 1809 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
1810 *vlan = NULL;
1811
1812 if (vlanattr) {
463d0183
JB
1813 *vlan = dev_get_by_index(genl_info_net(info),
1814 nla_get_u32(vlanattr));
5727ef1b
JB
1815 if (!*vlan)
1816 return -ENODEV;
1817 if (!(*vlan)->ieee80211_ptr)
1818 return -EINVAL;
1819 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1820 return -EINVAL;
1821 }
1822 return 0;
1823}
1824
1825static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1826{
79c97e97 1827 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1828 int err;
1829 struct net_device *dev;
1830 struct station_parameters params;
1831 u8 *mac_addr = NULL;
1832
1833 memset(&params, 0, sizeof(params));
1834
1835 params.listen_interval = -1;
1836
1837 if (info->attrs[NL80211_ATTR_STA_AID])
1838 return -EINVAL;
1839
1840 if (!info->attrs[NL80211_ATTR_MAC])
1841 return -EINVAL;
1842
1843 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1844
1845 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1846 params.supported_rates =
1847 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1848 params.supported_rates_len =
1849 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1850 }
1851
1852 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1853 params.listen_interval =
1854 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1855
36aedc90
JM
1856 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1857 params.ht_capa =
1858 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1859
eccb8e8f 1860 if (parse_station_flags(info, &params))
5727ef1b
JB
1861 return -EINVAL;
1862
2ec600d6
LCC
1863 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1864 params.plink_action =
1865 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1866
3b85875a
JB
1867 rtnl_lock();
1868
463d0183 1869 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 1870 if (err)
3b85875a 1871 goto out_rtnl;
5727ef1b 1872
463d0183 1873 err = get_vlan(info, rdev, &params.vlan);
a97f4424 1874 if (err)
034d655e 1875 goto out;
a97f4424
JB
1876
1877 /* validate settings */
1878 err = 0;
1879
1880 switch (dev->ieee80211_ptr->iftype) {
1881 case NL80211_IFTYPE_AP:
1882 case NL80211_IFTYPE_AP_VLAN:
1883 /* disallow mesh-specific things */
1884 if (params.plink_action)
1885 err = -EINVAL;
1886 break;
1887 case NL80211_IFTYPE_STATION:
1888 /* disallow everything but AUTHORIZED flag */
1889 if (params.plink_action)
1890 err = -EINVAL;
1891 if (params.vlan)
1892 err = -EINVAL;
1893 if (params.supported_rates)
1894 err = -EINVAL;
1895 if (params.ht_capa)
1896 err = -EINVAL;
1897 if (params.listen_interval >= 0)
1898 err = -EINVAL;
1899 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1900 err = -EINVAL;
1901 break;
1902 case NL80211_IFTYPE_MESH_POINT:
1903 /* disallow things mesh doesn't support */
1904 if (params.vlan)
1905 err = -EINVAL;
1906 if (params.ht_capa)
1907 err = -EINVAL;
1908 if (params.listen_interval >= 0)
1909 err = -EINVAL;
1910 if (params.supported_rates)
1911 err = -EINVAL;
1912 if (params.sta_flags_mask)
1913 err = -EINVAL;
1914 break;
1915 default:
1916 err = -EINVAL;
034d655e
JB
1917 }
1918
5727ef1b
JB
1919 if (err)
1920 goto out;
1921
79c97e97 1922 if (!rdev->ops->change_station) {
5727ef1b
JB
1923 err = -EOPNOTSUPP;
1924 goto out;
1925 }
1926
79c97e97 1927 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
1928
1929 out:
1930 if (params.vlan)
1931 dev_put(params.vlan);
79c97e97 1932 cfg80211_unlock_rdev(rdev);
5727ef1b 1933 dev_put(dev);
3b85875a
JB
1934 out_rtnl:
1935 rtnl_unlock();
1936
5727ef1b
JB
1937 return err;
1938}
1939
1940static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1941{
79c97e97 1942 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1943 int err;
1944 struct net_device *dev;
1945 struct station_parameters params;
1946 u8 *mac_addr = NULL;
1947
1948 memset(&params, 0, sizeof(params));
1949
1950 if (!info->attrs[NL80211_ATTR_MAC])
1951 return -EINVAL;
1952
5727ef1b
JB
1953 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1954 return -EINVAL;
1955
1956 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1957 return -EINVAL;
1958
1959 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1960 params.supported_rates =
1961 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1962 params.supported_rates_len =
1963 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1964 params.listen_interval =
1965 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 1966
a97f4424
JB
1967 if (info->attrs[NL80211_ATTR_STA_AID]) {
1968 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1969 if (!params.aid || params.aid > IEEE80211_MAX_AID)
1970 return -EINVAL;
1971 }
51b50fbe 1972
36aedc90
JM
1973 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1974 params.ht_capa =
1975 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 1976
eccb8e8f 1977 if (parse_station_flags(info, &params))
5727ef1b
JB
1978 return -EINVAL;
1979
3b85875a
JB
1980 rtnl_lock();
1981
463d0183 1982 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 1983 if (err)
3b85875a 1984 goto out_rtnl;
5727ef1b 1985
463d0183 1986 err = get_vlan(info, rdev, &params.vlan);
a97f4424 1987 if (err)
e80cf853 1988 goto out;
a97f4424
JB
1989
1990 /* validate settings */
1991 err = 0;
1992
1993 switch (dev->ieee80211_ptr->iftype) {
1994 case NL80211_IFTYPE_AP:
1995 case NL80211_IFTYPE_AP_VLAN:
1996 /* all ok but must have AID */
1997 if (!params.aid)
1998 err = -EINVAL;
1999 break;
2000 case NL80211_IFTYPE_MESH_POINT:
2001 /* disallow things mesh doesn't support */
2002 if (params.vlan)
2003 err = -EINVAL;
2004 if (params.aid)
2005 err = -EINVAL;
2006 if (params.ht_capa)
2007 err = -EINVAL;
2008 if (params.listen_interval >= 0)
2009 err = -EINVAL;
2010 if (params.supported_rates)
2011 err = -EINVAL;
2012 if (params.sta_flags_mask)
2013 err = -EINVAL;
2014 break;
2015 default:
2016 err = -EINVAL;
e80cf853
JB
2017 }
2018
5727ef1b
JB
2019 if (err)
2020 goto out;
2021
79c97e97 2022 if (!rdev->ops->add_station) {
5727ef1b
JB
2023 err = -EOPNOTSUPP;
2024 goto out;
2025 }
2026
35a8efe1
JM
2027 if (!netif_running(dev)) {
2028 err = -ENETDOWN;
2029 goto out;
2030 }
2031
79c97e97 2032 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2033
2034 out:
2035 if (params.vlan)
2036 dev_put(params.vlan);
79c97e97 2037 cfg80211_unlock_rdev(rdev);
5727ef1b 2038 dev_put(dev);
3b85875a
JB
2039 out_rtnl:
2040 rtnl_unlock();
2041
5727ef1b
JB
2042 return err;
2043}
2044
2045static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2046{
79c97e97 2047 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2048 int err;
2049 struct net_device *dev;
2050 u8 *mac_addr = NULL;
2051
2052 if (info->attrs[NL80211_ATTR_MAC])
2053 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2054
3b85875a
JB
2055 rtnl_lock();
2056
463d0183 2057 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2058 if (err)
3b85875a 2059 goto out_rtnl;
5727ef1b 2060
e80cf853 2061 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
155cc9e4
AY
2062 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2063 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2064 err = -EINVAL;
2065 goto out;
2066 }
2067
79c97e97 2068 if (!rdev->ops->del_station) {
5727ef1b
JB
2069 err = -EOPNOTSUPP;
2070 goto out;
2071 }
2072
79c97e97 2073 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2074
2075 out:
79c97e97 2076 cfg80211_unlock_rdev(rdev);
5727ef1b 2077 dev_put(dev);
3b85875a
JB
2078 out_rtnl:
2079 rtnl_unlock();
2080
5727ef1b
JB
2081 return err;
2082}
2083
2ec600d6
LCC
2084static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2085 int flags, struct net_device *dev,
2086 u8 *dst, u8 *next_hop,
2087 struct mpath_info *pinfo)
2088{
2089 void *hdr;
2090 struct nlattr *pinfoattr;
2091
2092 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2093 if (!hdr)
2094 return -1;
2095
2096 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2097 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2098 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2099
f5ea9120
JB
2100 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2101
2ec600d6
LCC
2102 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2103 if (!pinfoattr)
2104 goto nla_put_failure;
2105 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2106 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2107 pinfo->frame_qlen);
2108 if (pinfo->filled & MPATH_INFO_DSN)
2109 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
2110 pinfo->dsn);
2111 if (pinfo->filled & MPATH_INFO_METRIC)
2112 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2113 pinfo->metric);
2114 if (pinfo->filled & MPATH_INFO_EXPTIME)
2115 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2116 pinfo->exptime);
2117 if (pinfo->filled & MPATH_INFO_FLAGS)
2118 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2119 pinfo->flags);
2120 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2121 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2122 pinfo->discovery_timeout);
2123 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2124 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2125 pinfo->discovery_retries);
2126
2127 nla_nest_end(msg, pinfoattr);
2128
2129 return genlmsg_end(msg, hdr);
2130
2131 nla_put_failure:
bc3ed28c
TG
2132 genlmsg_cancel(msg, hdr);
2133 return -EMSGSIZE;
2ec600d6
LCC
2134}
2135
2136static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2137 struct netlink_callback *cb)
2ec600d6 2138{
2ec600d6
LCC
2139 struct mpath_info pinfo;
2140 struct cfg80211_registered_device *dev;
bba95fef 2141 struct net_device *netdev;
2ec600d6
LCC
2142 u8 dst[ETH_ALEN];
2143 u8 next_hop[ETH_ALEN];
bba95fef
JB
2144 int ifidx = cb->args[0];
2145 int path_idx = cb->args[1];
2ec600d6 2146 int err;
2ec600d6 2147
bba95fef
JB
2148 if (!ifidx) {
2149 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2150 nl80211_fam.attrbuf, nl80211_fam.maxattr,
2151 nl80211_policy);
2152 if (err)
2153 return err;
2154
2155 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2156 return -EINVAL;
2157
2158 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2159 if (!ifidx)
2160 return -EINVAL;
2161 }
2162
3b85875a
JB
2163 rtnl_lock();
2164
463d0183 2165 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2166 if (!netdev) {
2167 err = -ENODEV;
2168 goto out_rtnl;
2169 }
bba95fef 2170
463d0183 2171 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2172 if (IS_ERR(dev)) {
2173 err = PTR_ERR(dev);
3b85875a 2174 goto out_rtnl;
bba95fef
JB
2175 }
2176
2177 if (!dev->ops->dump_mpath) {
eec60b03 2178 err = -EOPNOTSUPP;
bba95fef
JB
2179 goto out_err;
2180 }
2181
eec60b03
JM
2182 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2183 err = -EOPNOTSUPP;
0448b5fc 2184 goto out_err;
eec60b03
JM
2185 }
2186
bba95fef
JB
2187 while (1) {
2188 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2189 dst, next_hop, &pinfo);
2190 if (err == -ENOENT)
2ec600d6 2191 break;
bba95fef 2192 if (err)
3b85875a 2193 goto out_err;
2ec600d6 2194
bba95fef
JB
2195 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2196 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2197 netdev, dst, next_hop,
2198 &pinfo) < 0)
2199 goto out;
2ec600d6 2200
bba95fef 2201 path_idx++;
2ec600d6 2202 }
2ec600d6 2203
2ec600d6 2204
bba95fef
JB
2205 out:
2206 cb->args[1] = path_idx;
2207 err = skb->len;
bba95fef 2208 out_err:
4d0c8aea 2209 cfg80211_unlock_rdev(dev);
3b85875a
JB
2210 out_rtnl:
2211 rtnl_unlock();
bba95fef
JB
2212
2213 return err;
2ec600d6
LCC
2214}
2215
2216static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2217{
79c97e97 2218 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2219 int err;
2220 struct net_device *dev;
2221 struct mpath_info pinfo;
2222 struct sk_buff *msg;
2223 u8 *dst = NULL;
2224 u8 next_hop[ETH_ALEN];
2225
2226 memset(&pinfo, 0, sizeof(pinfo));
2227
2228 if (!info->attrs[NL80211_ATTR_MAC])
2229 return -EINVAL;
2230
2231 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2232
3b85875a
JB
2233 rtnl_lock();
2234
463d0183 2235 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2236 if (err)
3b85875a 2237 goto out_rtnl;
2ec600d6 2238
79c97e97 2239 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2240 err = -EOPNOTSUPP;
2241 goto out;
2242 }
2243
eec60b03
JM
2244 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2245 err = -EOPNOTSUPP;
2246 goto out;
2247 }
2248
79c97e97 2249 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2250 if (err)
2251 goto out;
2252
fd2120ca 2253 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2254 if (!msg)
2255 goto out;
2256
2257 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2258 dev, dst, next_hop, &pinfo) < 0)
2259 goto out_free;
2260
134e6375 2261 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2262 goto out;
2263
2264 out_free:
2265 nlmsg_free(msg);
2ec600d6 2266 out:
79c97e97 2267 cfg80211_unlock_rdev(rdev);
2ec600d6 2268 dev_put(dev);
3b85875a
JB
2269 out_rtnl:
2270 rtnl_unlock();
2271
2ec600d6
LCC
2272 return err;
2273}
2274
2275static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2276{
79c97e97 2277 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2278 int err;
2279 struct net_device *dev;
2280 u8 *dst = NULL;
2281 u8 *next_hop = NULL;
2282
2283 if (!info->attrs[NL80211_ATTR_MAC])
2284 return -EINVAL;
2285
2286 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2287 return -EINVAL;
2288
2289 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2290 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2291
3b85875a
JB
2292 rtnl_lock();
2293
463d0183 2294 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2295 if (err)
3b85875a 2296 goto out_rtnl;
2ec600d6 2297
79c97e97 2298 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2299 err = -EOPNOTSUPP;
2300 goto out;
2301 }
2302
eec60b03
JM
2303 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2304 err = -EOPNOTSUPP;
2305 goto out;
2306 }
2307
35a8efe1
JM
2308 if (!netif_running(dev)) {
2309 err = -ENETDOWN;
2310 goto out;
2311 }
2312
79c97e97 2313 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2314
2315 out:
79c97e97 2316 cfg80211_unlock_rdev(rdev);
2ec600d6 2317 dev_put(dev);
3b85875a
JB
2318 out_rtnl:
2319 rtnl_unlock();
2320
2ec600d6
LCC
2321 return err;
2322}
2323static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2324{
79c97e97 2325 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2326 int err;
2327 struct net_device *dev;
2328 u8 *dst = NULL;
2329 u8 *next_hop = NULL;
2330
2331 if (!info->attrs[NL80211_ATTR_MAC])
2332 return -EINVAL;
2333
2334 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2335 return -EINVAL;
2336
2337 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2338 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2339
3b85875a
JB
2340 rtnl_lock();
2341
463d0183 2342 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2343 if (err)
3b85875a 2344 goto out_rtnl;
2ec600d6 2345
79c97e97 2346 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2347 err = -EOPNOTSUPP;
2348 goto out;
2349 }
2350
eec60b03
JM
2351 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2352 err = -EOPNOTSUPP;
2353 goto out;
2354 }
2355
35a8efe1
JM
2356 if (!netif_running(dev)) {
2357 err = -ENETDOWN;
2358 goto out;
2359 }
2360
79c97e97 2361 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2362
2363 out:
79c97e97 2364 cfg80211_unlock_rdev(rdev);
2ec600d6 2365 dev_put(dev);
3b85875a
JB
2366 out_rtnl:
2367 rtnl_unlock();
2368
2ec600d6
LCC
2369 return err;
2370}
2371
2372static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2373{
79c97e97 2374 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2375 int err;
2376 struct net_device *dev;
2377 u8 *dst = NULL;
2378
2379 if (info->attrs[NL80211_ATTR_MAC])
2380 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2381
3b85875a
JB
2382 rtnl_lock();
2383
463d0183 2384 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2385 if (err)
3b85875a 2386 goto out_rtnl;
2ec600d6 2387
79c97e97 2388 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2389 err = -EOPNOTSUPP;
2390 goto out;
2391 }
2392
79c97e97 2393 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2394
2395 out:
79c97e97 2396 cfg80211_unlock_rdev(rdev);
2ec600d6 2397 dev_put(dev);
3b85875a
JB
2398 out_rtnl:
2399 rtnl_unlock();
2400
2ec600d6
LCC
2401 return err;
2402}
2403
9f1ba906
JM
2404static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2405{
79c97e97 2406 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2407 int err;
2408 struct net_device *dev;
2409 struct bss_parameters params;
2410
2411 memset(&params, 0, sizeof(params));
2412 /* default to not changing parameters */
2413 params.use_cts_prot = -1;
2414 params.use_short_preamble = -1;
2415 params.use_short_slot_time = -1;
2416
2417 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2418 params.use_cts_prot =
2419 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2420 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2421 params.use_short_preamble =
2422 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2423 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2424 params.use_short_slot_time =
2425 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2426 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2427 params.basic_rates =
2428 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2429 params.basic_rates_len =
2430 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2431 }
9f1ba906 2432
3b85875a
JB
2433 rtnl_lock();
2434
463d0183 2435 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2436 if (err)
3b85875a 2437 goto out_rtnl;
9f1ba906 2438
79c97e97 2439 if (!rdev->ops->change_bss) {
9f1ba906
JM
2440 err = -EOPNOTSUPP;
2441 goto out;
2442 }
2443
eec60b03
JM
2444 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2445 err = -EOPNOTSUPP;
2446 goto out;
2447 }
2448
79c97e97 2449 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2450
2451 out:
79c97e97 2452 cfg80211_unlock_rdev(rdev);
9f1ba906 2453 dev_put(dev);
3b85875a
JB
2454 out_rtnl:
2455 rtnl_unlock();
2456
9f1ba906
JM
2457 return err;
2458}
2459
b2e1b302
LR
2460static const struct nla_policy
2461 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2462 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2463 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2464 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2465 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2466 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2467 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2468};
2469
2470static int parse_reg_rule(struct nlattr *tb[],
2471 struct ieee80211_reg_rule *reg_rule)
2472{
2473 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2474 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2475
2476 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2477 return -EINVAL;
2478 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2479 return -EINVAL;
2480 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2481 return -EINVAL;
2482 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2483 return -EINVAL;
2484 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2485 return -EINVAL;
2486
2487 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2488
2489 freq_range->start_freq_khz =
2490 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2491 freq_range->end_freq_khz =
2492 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2493 freq_range->max_bandwidth_khz =
2494 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2495
2496 power_rule->max_eirp =
2497 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2498
2499 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2500 power_rule->max_antenna_gain =
2501 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2502
2503 return 0;
2504}
2505
2506static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2507{
2508 int r;
2509 char *data = NULL;
2510
80778f18
LR
2511 /*
2512 * You should only get this when cfg80211 hasn't yet initialized
2513 * completely when built-in to the kernel right between the time
2514 * window between nl80211_init() and regulatory_init(), if that is
2515 * even possible.
2516 */
2517 mutex_lock(&cfg80211_mutex);
2518 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2519 mutex_unlock(&cfg80211_mutex);
2520 return -EINPROGRESS;
80778f18 2521 }
fe33eb39 2522 mutex_unlock(&cfg80211_mutex);
80778f18 2523
fe33eb39
LR
2524 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2525 return -EINVAL;
b2e1b302
LR
2526
2527 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2528
2529#ifdef CONFIG_WIRELESS_OLD_REGULATORY
2530 /* We ignore world regdom requests with the old regdom setup */
fe33eb39
LR
2531 if (is_world_regdom(data))
2532 return -EINVAL;
b2e1b302 2533#endif
fe33eb39
LR
2534
2535 r = regulatory_hint_user(data);
2536
b2e1b302
LR
2537 return r;
2538}
2539
93da9cc1 2540static int nl80211_get_mesh_params(struct sk_buff *skb,
2541 struct genl_info *info)
2542{
79c97e97 2543 struct cfg80211_registered_device *rdev;
93da9cc1 2544 struct mesh_config cur_params;
2545 int err;
2546 struct net_device *dev;
2547 void *hdr;
2548 struct nlattr *pinfoattr;
2549 struct sk_buff *msg;
2550
3b85875a
JB
2551 rtnl_lock();
2552
93da9cc1 2553 /* Look up our device */
463d0183 2554 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2555 if (err)
3b85875a 2556 goto out_rtnl;
93da9cc1 2557
79c97e97 2558 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2559 err = -EOPNOTSUPP;
2560 goto out;
2561 }
2562
93da9cc1 2563 /* Get the mesh params */
79c97e97 2564 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2565 if (err)
2566 goto out;
2567
2568 /* Draw up a netlink message to send back */
fd2120ca 2569 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2570 if (!msg) {
2571 err = -ENOBUFS;
2572 goto out;
2573 }
2574 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2575 NL80211_CMD_GET_MESH_PARAMS);
2576 if (!hdr)
2577 goto nla_put_failure;
2578 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2579 if (!pinfoattr)
2580 goto nla_put_failure;
2581 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2582 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2583 cur_params.dot11MeshRetryTimeout);
2584 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2585 cur_params.dot11MeshConfirmTimeout);
2586 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2587 cur_params.dot11MeshHoldingTimeout);
2588 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2589 cur_params.dot11MeshMaxPeerLinks);
2590 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2591 cur_params.dot11MeshMaxRetries);
2592 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2593 cur_params.dot11MeshTTL);
2594 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2595 cur_params.auto_open_plinks);
2596 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2597 cur_params.dot11MeshHWMPmaxPREQretries);
2598 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2599 cur_params.path_refresh_time);
2600 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2601 cur_params.min_discovery_timeout);
2602 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2603 cur_params.dot11MeshHWMPactivePathTimeout);
2604 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2605 cur_params.dot11MeshHWMPpreqMinInterval);
2606 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2607 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2608 nla_nest_end(msg, pinfoattr);
2609 genlmsg_end(msg, hdr);
134e6375 2610 err = genlmsg_reply(msg, info);
93da9cc1 2611 goto out;
2612
3b85875a 2613 nla_put_failure:
93da9cc1 2614 genlmsg_cancel(msg, hdr);
2615 err = -EMSGSIZE;
3b85875a 2616 out:
93da9cc1 2617 /* Cleanup */
79c97e97 2618 cfg80211_unlock_rdev(rdev);
93da9cc1 2619 dev_put(dev);
3b85875a
JB
2620 out_rtnl:
2621 rtnl_unlock();
2622
93da9cc1 2623 return err;
2624}
2625
2626#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2627do {\
2628 if (table[attr_num]) {\
2629 cfg.param = nla_fn(table[attr_num]); \
2630 mask |= (1 << (attr_num - 1)); \
2631 } \
2632} while (0);\
2633
2634static struct nla_policy
2635nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2636 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2637 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2638 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2639 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2640 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2641 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2642 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2643
2644 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2645 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2646 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2647 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2648 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2649 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2650};
2651
2652static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2653{
2654 int err;
2655 u32 mask;
79c97e97 2656 struct cfg80211_registered_device *rdev;
93da9cc1 2657 struct net_device *dev;
2658 struct mesh_config cfg;
2659 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2660 struct nlattr *parent_attr;
2661
2662 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2663 if (!parent_attr)
2664 return -EINVAL;
2665 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2666 parent_attr, nl80211_meshconf_params_policy))
2667 return -EINVAL;
2668
3b85875a
JB
2669 rtnl_lock();
2670
463d0183 2671 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2672 if (err)
3b85875a 2673 goto out_rtnl;
93da9cc1 2674
79c97e97 2675 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2676 err = -EOPNOTSUPP;
2677 goto out;
2678 }
2679
93da9cc1 2680 /* This makes sure that there aren't more than 32 mesh config
2681 * parameters (otherwise our bitfield scheme would not work.) */
2682 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2683
2684 /* Fill in the params struct */
2685 mask = 0;
2686 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2687 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2688 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2689 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2690 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2691 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2692 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2693 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2694 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2695 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2696 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2697 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2698 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2699 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2700 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2701 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2702 nla_get_u8);
2703 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2704 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2705 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2706 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2707 nla_get_u16);
2708 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2709 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2710 nla_get_u32);
2711 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2712 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2713 nla_get_u16);
2714 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2715 dot11MeshHWMPnetDiameterTraversalTime,
2716 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2717 nla_get_u16);
2718
2719 /* Apply changes */
79c97e97 2720 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2721
f3f92586 2722 out:
93da9cc1 2723 /* cleanup */
79c97e97 2724 cfg80211_unlock_rdev(rdev);
93da9cc1 2725 dev_put(dev);
3b85875a
JB
2726 out_rtnl:
2727 rtnl_unlock();
2728
93da9cc1 2729 return err;
2730}
2731
2732#undef FILL_IN_MESH_PARAM_IF_SET
2733
f130347c
LR
2734static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2735{
2736 struct sk_buff *msg;
2737 void *hdr = NULL;
2738 struct nlattr *nl_reg_rules;
2739 unsigned int i;
2740 int err = -EINVAL;
2741
a1794390 2742 mutex_lock(&cfg80211_mutex);
f130347c
LR
2743
2744 if (!cfg80211_regdomain)
2745 goto out;
2746
fd2120ca 2747 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2748 if (!msg) {
2749 err = -ENOBUFS;
2750 goto out;
2751 }
2752
2753 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2754 NL80211_CMD_GET_REG);
2755 if (!hdr)
2756 goto nla_put_failure;
2757
2758 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2759 cfg80211_regdomain->alpha2);
2760
2761 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2762 if (!nl_reg_rules)
2763 goto nla_put_failure;
2764
2765 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2766 struct nlattr *nl_reg_rule;
2767 const struct ieee80211_reg_rule *reg_rule;
2768 const struct ieee80211_freq_range *freq_range;
2769 const struct ieee80211_power_rule *power_rule;
2770
2771 reg_rule = &cfg80211_regdomain->reg_rules[i];
2772 freq_range = &reg_rule->freq_range;
2773 power_rule = &reg_rule->power_rule;
2774
2775 nl_reg_rule = nla_nest_start(msg, i);
2776 if (!nl_reg_rule)
2777 goto nla_put_failure;
2778
2779 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2780 reg_rule->flags);
2781 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2782 freq_range->start_freq_khz);
2783 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2784 freq_range->end_freq_khz);
2785 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2786 freq_range->max_bandwidth_khz);
2787 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2788 power_rule->max_antenna_gain);
2789 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2790 power_rule->max_eirp);
2791
2792 nla_nest_end(msg, nl_reg_rule);
2793 }
2794
2795 nla_nest_end(msg, nl_reg_rules);
2796
2797 genlmsg_end(msg, hdr);
134e6375 2798 err = genlmsg_reply(msg, info);
f130347c
LR
2799 goto out;
2800
2801nla_put_failure:
2802 genlmsg_cancel(msg, hdr);
2803 err = -EMSGSIZE;
2804out:
a1794390 2805 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2806 return err;
2807}
2808
b2e1b302
LR
2809static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2810{
2811 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2812 struct nlattr *nl_reg_rule;
2813 char *alpha2 = NULL;
2814 int rem_reg_rules = 0, r = 0;
2815 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2816 struct ieee80211_regdomain *rd = NULL;
2817
2818 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2819 return -EINVAL;
2820
2821 if (!info->attrs[NL80211_ATTR_REG_RULES])
2822 return -EINVAL;
2823
2824 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2825
2826 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2827 rem_reg_rules) {
2828 num_rules++;
2829 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2830 return -EINVAL;
b2e1b302
LR
2831 }
2832
61405e97
LR
2833 mutex_lock(&cfg80211_mutex);
2834
d0e18f83
LR
2835 if (!reg_is_valid_request(alpha2)) {
2836 r = -EINVAL;
2837 goto bad_reg;
2838 }
b2e1b302
LR
2839
2840 size_of_regd = sizeof(struct ieee80211_regdomain) +
2841 (num_rules * sizeof(struct ieee80211_reg_rule));
2842
2843 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2844 if (!rd) {
2845 r = -ENOMEM;
2846 goto bad_reg;
2847 }
b2e1b302
LR
2848
2849 rd->n_reg_rules = num_rules;
2850 rd->alpha2[0] = alpha2[0];
2851 rd->alpha2[1] = alpha2[1];
2852
2853 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2854 rem_reg_rules) {
2855 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2856 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2857 reg_rule_policy);
2858 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2859 if (r)
2860 goto bad_reg;
2861
2862 rule_idx++;
2863
d0e18f83
LR
2864 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2865 r = -EINVAL;
b2e1b302 2866 goto bad_reg;
d0e18f83 2867 }
b2e1b302
LR
2868 }
2869
2870 BUG_ON(rule_idx != num_rules);
2871
b2e1b302 2872 r = set_regdom(rd);
61405e97 2873
a1794390 2874 mutex_unlock(&cfg80211_mutex);
d0e18f83 2875
b2e1b302
LR
2876 return r;
2877
d2372b31 2878 bad_reg:
61405e97 2879 mutex_unlock(&cfg80211_mutex);
b2e1b302 2880 kfree(rd);
d0e18f83 2881 return r;
b2e1b302
LR
2882}
2883
83f5e2cf
JB
2884static int validate_scan_freqs(struct nlattr *freqs)
2885{
2886 struct nlattr *attr1, *attr2;
2887 int n_channels = 0, tmp1, tmp2;
2888
2889 nla_for_each_nested(attr1, freqs, tmp1) {
2890 n_channels++;
2891 /*
2892 * Some hardware has a limited channel list for
2893 * scanning, and it is pretty much nonsensical
2894 * to scan for a channel twice, so disallow that
2895 * and don't require drivers to check that the
2896 * channel list they get isn't longer than what
2897 * they can scan, as long as they can scan all
2898 * the channels they registered at once.
2899 */
2900 nla_for_each_nested(attr2, freqs, tmp2)
2901 if (attr1 != attr2 &&
2902 nla_get_u32(attr1) == nla_get_u32(attr2))
2903 return 0;
2904 }
2905
2906 return n_channels;
2907}
2908
2a519311
JB
2909static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2910{
79c97e97 2911 struct cfg80211_registered_device *rdev;
2a519311
JB
2912 struct net_device *dev;
2913 struct cfg80211_scan_request *request;
2914 struct cfg80211_ssid *ssid;
2915 struct ieee80211_channel *channel;
2916 struct nlattr *attr;
2917 struct wiphy *wiphy;
83f5e2cf 2918 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 2919 enum ieee80211_band band;
70692ad2 2920 size_t ie_len;
2a519311 2921
f4a11bb0
JB
2922 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2923 return -EINVAL;
2924
3b85875a
JB
2925 rtnl_lock();
2926
463d0183 2927 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 2928 if (err)
3b85875a 2929 goto out_rtnl;
2a519311 2930
79c97e97 2931 wiphy = &rdev->wiphy;
2a519311 2932
79c97e97 2933 if (!rdev->ops->scan) {
2a519311
JB
2934 err = -EOPNOTSUPP;
2935 goto out;
2936 }
2937
35a8efe1
JM
2938 if (!netif_running(dev)) {
2939 err = -ENETDOWN;
2940 goto out;
2941 }
2942
79c97e97 2943 if (rdev->scan_req) {
2a519311 2944 err = -EBUSY;
3b85875a 2945 goto out;
2a519311
JB
2946 }
2947
2948 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
2949 n_channels = validate_scan_freqs(
2950 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
2951 if (!n_channels) {
2952 err = -EINVAL;
3b85875a 2953 goto out;
2a519311
JB
2954 }
2955 } else {
83f5e2cf
JB
2956 n_channels = 0;
2957
2a519311
JB
2958 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2959 if (wiphy->bands[band])
2960 n_channels += wiphy->bands[band]->n_channels;
2961 }
2962
2963 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2964 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2965 n_ssids++;
2966
2967 if (n_ssids > wiphy->max_scan_ssids) {
2968 err = -EINVAL;
3b85875a 2969 goto out;
2a519311
JB
2970 }
2971
70692ad2
JM
2972 if (info->attrs[NL80211_ATTR_IE])
2973 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2974 else
2975 ie_len = 0;
2976
18a83659
JB
2977 if (ie_len > wiphy->max_scan_ie_len) {
2978 err = -EINVAL;
2979 goto out;
2980 }
2981
2a519311
JB
2982 request = kzalloc(sizeof(*request)
2983 + sizeof(*ssid) * n_ssids
70692ad2
JM
2984 + sizeof(channel) * n_channels
2985 + ie_len, GFP_KERNEL);
2a519311
JB
2986 if (!request) {
2987 err = -ENOMEM;
3b85875a 2988 goto out;
2a519311
JB
2989 }
2990
2a519311
JB
2991 request->n_channels = n_channels;
2992 if (n_ssids)
5ba63533 2993 request->ssids = (void *)&request->channels[n_channels];
2a519311 2994 request->n_ssids = n_ssids;
70692ad2
JM
2995 if (ie_len) {
2996 if (request->ssids)
2997 request->ie = (void *)(request->ssids + n_ssids);
2998 else
2999 request->ie = (void *)(request->channels + n_channels);
3000 }
2a519311
JB
3001
3002 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3003 /* user specified, bail out if channel not found */
3004 request->n_channels = n_channels;
3005 i = 0;
3006 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3007 request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3008 if (!request->channels[i]) {
3009 err = -EINVAL;
3010 goto out_free;
3011 }
3012 i++;
3013 }
3014 } else {
3015 /* all channels */
3016 i = 0;
3017 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3018 int j;
3019 if (!wiphy->bands[band])
3020 continue;
3021 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3022 request->channels[i] = &wiphy->bands[band]->channels[j];
3023 i++;
3024 }
3025 }
3026 }
3027
3028 i = 0;
3029 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3030 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3031 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3032 err = -EINVAL;
3033 goto out_free;
3034 }
3035 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3036 request->ssids[i].ssid_len = nla_len(attr);
3037 i++;
3038 }
3039 }
3040
70692ad2
JM
3041 if (info->attrs[NL80211_ATTR_IE]) {
3042 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3043 memcpy((void *)request->ie,
3044 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3045 request->ie_len);
3046 }
3047
463d0183 3048 request->dev = dev;
79c97e97 3049 request->wiphy = &rdev->wiphy;
2a519311 3050
79c97e97
JB
3051 rdev->scan_req = request;
3052 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3053
463d0183 3054 if (!err) {
79c97e97 3055 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3056 dev_hold(dev);
3057 }
a538e2d5 3058
2a519311
JB
3059 out_free:
3060 if (err) {
79c97e97 3061 rdev->scan_req = NULL;
2a519311
JB
3062 kfree(request);
3063 }
2a519311 3064 out:
79c97e97 3065 cfg80211_unlock_rdev(rdev);
2a519311 3066 dev_put(dev);
3b85875a
JB
3067 out_rtnl:
3068 rtnl_unlock();
3069
2a519311
JB
3070 return err;
3071}
3072
3073static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3074 struct cfg80211_registered_device *rdev,
48ab905d
JB
3075 struct wireless_dev *wdev,
3076 struct cfg80211_internal_bss *intbss)
2a519311 3077{
48ab905d 3078 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3079 void *hdr;
3080 struct nlattr *bss;
48ab905d
JB
3081 int i;
3082
3083 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3084
3085 hdr = nl80211hdr_put(msg, pid, seq, flags,
3086 NL80211_CMD_NEW_SCAN_RESULTS);
3087 if (!hdr)
3088 return -1;
3089
f5ea9120 3090 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3091 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3092
3093 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3094 if (!bss)
3095 goto nla_put_failure;
3096 if (!is_zero_ether_addr(res->bssid))
3097 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3098 if (res->information_elements && res->len_information_elements)
3099 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3100 res->len_information_elements,
3101 res->information_elements);
3102 if (res->tsf)
3103 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3104 if (res->beacon_interval)
3105 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3106 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3107 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3108 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3109 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3110
77965c97 3111 switch (rdev->wiphy.signal_type) {
2a519311
JB
3112 case CFG80211_SIGNAL_TYPE_MBM:
3113 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3114 break;
3115 case CFG80211_SIGNAL_TYPE_UNSPEC:
3116 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3117 break;
3118 default:
3119 break;
3120 }
3121
48ab905d
JB
3122 switch (wdev->iftype) {
3123 case NL80211_IFTYPE_STATION:
3124 if (intbss == wdev->current_bss)
3125 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3126 NL80211_BSS_STATUS_ASSOCIATED);
3127 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3128 if (intbss != wdev->auth_bsses[i])
3129 continue;
3130 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3131 NL80211_BSS_STATUS_AUTHENTICATED);
3132 break;
3133 }
3134 break;
3135 case NL80211_IFTYPE_ADHOC:
3136 if (intbss == wdev->current_bss)
3137 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3138 NL80211_BSS_STATUS_IBSS_JOINED);
3139 break;
3140 default:
3141 break;
3142 }
3143
2a519311
JB
3144 nla_nest_end(msg, bss);
3145
3146 return genlmsg_end(msg, hdr);
3147
3148 nla_put_failure:
3149 genlmsg_cancel(msg, hdr);
3150 return -EMSGSIZE;
3151}
3152
3153static int nl80211_dump_scan(struct sk_buff *skb,
3154 struct netlink_callback *cb)
3155{
48ab905d
JB
3156 struct cfg80211_registered_device *rdev;
3157 struct net_device *dev;
2a519311 3158 struct cfg80211_internal_bss *scan;
48ab905d 3159 struct wireless_dev *wdev;
2a519311
JB
3160 int ifidx = cb->args[0];
3161 int start = cb->args[1], idx = 0;
3162 int err;
3163
3164 if (!ifidx) {
3165 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
3166 nl80211_fam.attrbuf, nl80211_fam.maxattr,
3167 nl80211_policy);
3168 if (err)
3169 return err;
3170
3171 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
3172 return -EINVAL;
3173
3174 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
3175 if (!ifidx)
3176 return -EINVAL;
3177 cb->args[0] = ifidx;
3178 }
3179
463d0183 3180 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3181 if (!dev)
2a519311
JB
3182 return -ENODEV;
3183
463d0183 3184 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3185 if (IS_ERR(rdev)) {
3186 err = PTR_ERR(rdev);
2a519311
JB
3187 goto out_put_netdev;
3188 }
3189
48ab905d 3190 wdev = dev->ieee80211_ptr;
2a519311 3191
48ab905d
JB
3192 wdev_lock(wdev);
3193 spin_lock_bh(&rdev->bss_lock);
3194 cfg80211_bss_expire(rdev);
3195
3196 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3197 if (++idx <= start)
3198 continue;
3199 if (nl80211_send_bss(skb,
3200 NETLINK_CB(cb->skb).pid,
3201 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3202 rdev, wdev, scan) < 0) {
2a519311
JB
3203 idx--;
3204 goto out;
3205 }
3206 }
3207
3208 out:
48ab905d
JB
3209 spin_unlock_bh(&rdev->bss_lock);
3210 wdev_unlock(wdev);
2a519311
JB
3211
3212 cb->args[1] = idx;
3213 err = skb->len;
48ab905d 3214 cfg80211_unlock_rdev(rdev);
2a519311 3215 out_put_netdev:
48ab905d 3216 dev_put(dev);
2a519311
JB
3217
3218 return err;
3219}
3220
255e737e
JM
3221static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3222{
b23aa676
SO
3223 return auth_type <= NL80211_AUTHTYPE_MAX;
3224}
3225
3226static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3227{
3228 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3229 NL80211_WPA_VERSION_2));
3230}
3231
3232static bool nl80211_valid_akm_suite(u32 akm)
3233{
3234 return akm == WLAN_AKM_SUITE_8021X ||
3235 akm == WLAN_AKM_SUITE_PSK;
3236}
3237
3238static bool nl80211_valid_cipher_suite(u32 cipher)
3239{
3240 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3241 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3242 cipher == WLAN_CIPHER_SUITE_TKIP ||
3243 cipher == WLAN_CIPHER_SUITE_CCMP ||
3244 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3245}
3246
b23aa676 3247
636a5d36
JM
3248static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3249{
79c97e97 3250 struct cfg80211_registered_device *rdev;
636a5d36 3251 struct net_device *dev;
19957bb3
JB
3252 struct ieee80211_channel *chan;
3253 const u8 *bssid, *ssid, *ie = NULL;
3254 int err, ssid_len, ie_len = 0;
3255 enum nl80211_auth_type auth_type;
fffd0934 3256 struct key_parse key;
636a5d36 3257
f4a11bb0
JB
3258 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3259 return -EINVAL;
3260
3261 if (!info->attrs[NL80211_ATTR_MAC])
3262 return -EINVAL;
3263
1778092e
JM
3264 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3265 return -EINVAL;
3266
19957bb3
JB
3267 if (!info->attrs[NL80211_ATTR_SSID])
3268 return -EINVAL;
3269
3270 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3271 return -EINVAL;
3272
fffd0934
JB
3273 err = nl80211_parse_key(info, &key);
3274 if (err)
3275 return err;
3276
3277 if (key.idx >= 0) {
3278 if (!key.p.key || !key.p.key_len)
3279 return -EINVAL;
3280 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3281 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3282 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3283 key.p.key_len != WLAN_KEY_LEN_WEP104))
3284 return -EINVAL;
3285 if (key.idx > 4)
3286 return -EINVAL;
3287 } else {
3288 key.p.key_len = 0;
3289 key.p.key = NULL;
3290 }
3291
636a5d36
JM
3292 rtnl_lock();
3293
463d0183 3294 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3295 if (err)
3296 goto unlock_rtnl;
3297
79c97e97 3298 if (!rdev->ops->auth) {
636a5d36
JM
3299 err = -EOPNOTSUPP;
3300 goto out;
3301 }
3302
eec60b03
JM
3303 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3304 err = -EOPNOTSUPP;
3305 goto out;
3306 }
3307
35a8efe1
JM
3308 if (!netif_running(dev)) {
3309 err = -ENETDOWN;
3310 goto out;
3311 }
3312
19957bb3 3313 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3314 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3315 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3316 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3317 err = -EINVAL;
3318 goto out;
636a5d36
JM
3319 }
3320
19957bb3
JB
3321 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3322 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3323
3324 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3325 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3326 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3327 }
3328
19957bb3
JB
3329 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3330 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3331 err = -EINVAL;
3332 goto out;
636a5d36
JM
3333 }
3334
79c97e97 3335 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934
JB
3336 ssid, ssid_len, ie, ie_len,
3337 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
3338
3339out:
79c97e97 3340 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3341 dev_put(dev);
3342unlock_rtnl:
3343 rtnl_unlock();
3344 return err;
3345}
3346
b23aa676 3347static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3348 struct cfg80211_crypto_settings *settings,
3349 int cipher_limit)
b23aa676 3350{
c0b2bbd8
JB
3351 memset(settings, 0, sizeof(*settings));
3352
b23aa676
SO
3353 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3354
3355 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3356 void *data;
3357 int len, i;
3358
3359 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3360 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3361 settings->n_ciphers_pairwise = len / sizeof(u32);
3362
3363 if (len % sizeof(u32))
3364 return -EINVAL;
3365
3dc27d25 3366 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3367 return -EINVAL;
3368
3369 memcpy(settings->ciphers_pairwise, data, len);
3370
3371 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3372 if (!nl80211_valid_cipher_suite(
3373 settings->ciphers_pairwise[i]))
3374 return -EINVAL;
3375 }
3376
3377 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3378 settings->cipher_group =
3379 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3380 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3381 return -EINVAL;
3382 }
3383
3384 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3385 settings->wpa_versions =
3386 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3387 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3388 return -EINVAL;
3389 }
3390
3391 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3392 void *data;
3393 int len, i;
3394
3395 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3396 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3397 settings->n_akm_suites = len / sizeof(u32);
3398
3399 if (len % sizeof(u32))
3400 return -EINVAL;
3401
3402 memcpy(settings->akm_suites, data, len);
3403
3404 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3405 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3406 return -EINVAL;
3407 }
3408
3409 return 0;
3410}
3411
636a5d36
JM
3412static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3413{
19957bb3 3414 struct cfg80211_registered_device *rdev;
636a5d36 3415 struct net_device *dev;
19957bb3 3416 struct cfg80211_crypto_settings crypto;
59bbb6f7 3417 struct ieee80211_channel *chan, *fixedchan;
3e5d7649 3418 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3419 int err, ssid_len, ie_len = 0;
3420 bool use_mfp = false;
636a5d36 3421
f4a11bb0
JB
3422 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3423 return -EINVAL;
3424
3425 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3426 !info->attrs[NL80211_ATTR_SSID] ||
3427 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3428 return -EINVAL;
3429
636a5d36
JM
3430 rtnl_lock();
3431
463d0183 3432 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3433 if (err)
3434 goto unlock_rtnl;
3435
19957bb3 3436 if (!rdev->ops->assoc) {
636a5d36
JM
3437 err = -EOPNOTSUPP;
3438 goto out;
3439 }
3440
eec60b03
JM
3441 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3442 err = -EOPNOTSUPP;
3443 goto out;
3444 }
3445
35a8efe1
JM
3446 if (!netif_running(dev)) {
3447 err = -ENETDOWN;
3448 goto out;
3449 }
3450
19957bb3 3451 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3452
19957bb3
JB
3453 chan = ieee80211_get_channel(&rdev->wiphy,
3454 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3455 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3456 err = -EINVAL;
3457 goto out;
636a5d36
JM
3458 }
3459
59bbb6f7
JB
3460 mutex_lock(&rdev->devlist_mtx);
3461 fixedchan = rdev_fixed_channel(rdev, NULL);
3462 if (fixedchan && chan != fixedchan) {
3463 err = -EBUSY;
3464 mutex_unlock(&rdev->devlist_mtx);
3465 goto out;
3466 }
3467 mutex_unlock(&rdev->devlist_mtx);
3468
19957bb3
JB
3469 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3470 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3471
3472 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3473 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3474 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3475 }
3476
dc6382ce 3477 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3478 enum nl80211_mfp mfp =
dc6382ce 3479 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3480 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3481 use_mfp = true;
4f5dadce 3482 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3483 err = -EINVAL;
3484 goto out;
3485 }
3486 }
3487
3e5d7649
JB
3488 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3489 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3490
3dc27d25 3491 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3492 if (!err)
3e5d7649
JB
3493 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3494 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3495 &crypto);
636a5d36
JM
3496
3497out:
4d0c8aea 3498 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3499 dev_put(dev);
3500unlock_rtnl:
3501 rtnl_unlock();
3502 return err;
3503}
3504
3505static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3506{
79c97e97 3507 struct cfg80211_registered_device *rdev;
636a5d36 3508 struct net_device *dev;
19957bb3
JB
3509 const u8 *ie = NULL, *bssid;
3510 int err, ie_len = 0;
3511 u16 reason_code;
636a5d36 3512
f4a11bb0
JB
3513 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3514 return -EINVAL;
3515
3516 if (!info->attrs[NL80211_ATTR_MAC])
3517 return -EINVAL;
3518
3519 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3520 return -EINVAL;
3521
636a5d36
JM
3522 rtnl_lock();
3523
463d0183 3524 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3525 if (err)
3526 goto unlock_rtnl;
3527
79c97e97 3528 if (!rdev->ops->deauth) {
636a5d36
JM
3529 err = -EOPNOTSUPP;
3530 goto out;
3531 }
3532
eec60b03
JM
3533 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3534 err = -EOPNOTSUPP;
3535 goto out;
3536 }
3537
35a8efe1
JM
3538 if (!netif_running(dev)) {
3539 err = -ENETDOWN;
3540 goto out;
3541 }
3542
19957bb3 3543 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3544
19957bb3
JB
3545 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3546 if (reason_code == 0) {
f4a11bb0
JB
3547 /* Reason Code 0 is reserved */
3548 err = -EINVAL;
3549 goto out;
255e737e 3550 }
636a5d36
JM
3551
3552 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3553 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3554 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3555 }
3556
79c97e97 3557 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3558
3559out:
79c97e97 3560 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3561 dev_put(dev);
3562unlock_rtnl:
3563 rtnl_unlock();
3564 return err;
3565}
3566
3567static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3568{
79c97e97 3569 struct cfg80211_registered_device *rdev;
636a5d36 3570 struct net_device *dev;
19957bb3
JB
3571 const u8 *ie = NULL, *bssid;
3572 int err, ie_len = 0;
3573 u16 reason_code;
636a5d36 3574
f4a11bb0
JB
3575 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3576 return -EINVAL;
3577
3578 if (!info->attrs[NL80211_ATTR_MAC])
3579 return -EINVAL;
3580
3581 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3582 return -EINVAL;
3583
636a5d36
JM
3584 rtnl_lock();
3585
463d0183 3586 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3587 if (err)
3588 goto unlock_rtnl;
3589
79c97e97 3590 if (!rdev->ops->disassoc) {
636a5d36
JM
3591 err = -EOPNOTSUPP;
3592 goto out;
3593 }
3594
eec60b03
JM
3595 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3596 err = -EOPNOTSUPP;
3597 goto out;
3598 }
3599
35a8efe1
JM
3600 if (!netif_running(dev)) {
3601 err = -ENETDOWN;
3602 goto out;
3603 }
3604
19957bb3 3605 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3606
19957bb3
JB
3607 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3608 if (reason_code == 0) {
f4a11bb0
JB
3609 /* Reason Code 0 is reserved */
3610 err = -EINVAL;
3611 goto out;
255e737e 3612 }
636a5d36
JM
3613
3614 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3615 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3616 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3617 }
3618
79c97e97 3619 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3620
3621out:
79c97e97 3622 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3623 dev_put(dev);
3624unlock_rtnl:
3625 rtnl_unlock();
3626 return err;
3627}
3628
04a773ad
JB
3629static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3630{
79c97e97 3631 struct cfg80211_registered_device *rdev;
04a773ad
JB
3632 struct net_device *dev;
3633 struct cfg80211_ibss_params ibss;
3634 struct wiphy *wiphy;
fffd0934 3635 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3636 int err;
3637
8e30bc55
JB
3638 memset(&ibss, 0, sizeof(ibss));
3639
04a773ad
JB
3640 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3641 return -EINVAL;
3642
3643 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3644 !info->attrs[NL80211_ATTR_SSID] ||
3645 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3646 return -EINVAL;
3647
8e30bc55
JB
3648 ibss.beacon_interval = 100;
3649
3650 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3651 ibss.beacon_interval =
3652 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3653 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3654 return -EINVAL;
3655 }
3656
04a773ad
JB
3657 rtnl_lock();
3658
463d0183 3659 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3660 if (err)
3661 goto unlock_rtnl;
3662
79c97e97 3663 if (!rdev->ops->join_ibss) {
04a773ad
JB
3664 err = -EOPNOTSUPP;
3665 goto out;
3666 }
3667
3668 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3669 err = -EOPNOTSUPP;
3670 goto out;
3671 }
3672
3673 if (!netif_running(dev)) {
3674 err = -ENETDOWN;
3675 goto out;
3676 }
3677
79c97e97 3678 wiphy = &rdev->wiphy;
04a773ad
JB
3679
3680 if (info->attrs[NL80211_ATTR_MAC])
3681 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3682 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3683 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3684
3685 if (info->attrs[NL80211_ATTR_IE]) {
3686 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3687 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3688 }
3689
3690 ibss.channel = ieee80211_get_channel(wiphy,
3691 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3692 if (!ibss.channel ||
3693 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3694 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3695 err = -EINVAL;
3696 goto out;
3697 }
3698
3699 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3700 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3701
3702 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3703 connkeys = nl80211_parse_connkeys(rdev,
3704 info->attrs[NL80211_ATTR_KEYS]);
3705 if (IS_ERR(connkeys)) {
3706 err = PTR_ERR(connkeys);
3707 connkeys = NULL;
3708 goto out;
3709 }
3710 }
04a773ad 3711
fffd0934 3712 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
3713
3714out:
79c97e97 3715 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3716 dev_put(dev);
3717unlock_rtnl:
fffd0934
JB
3718 if (err)
3719 kfree(connkeys);
04a773ad
JB
3720 rtnl_unlock();
3721 return err;
3722}
3723
3724static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3725{
79c97e97 3726 struct cfg80211_registered_device *rdev;
04a773ad
JB
3727 struct net_device *dev;
3728 int err;
3729
3730 rtnl_lock();
3731
463d0183 3732 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3733 if (err)
3734 goto unlock_rtnl;
3735
79c97e97 3736 if (!rdev->ops->leave_ibss) {
04a773ad
JB
3737 err = -EOPNOTSUPP;
3738 goto out;
3739 }
3740
3741 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3742 err = -EOPNOTSUPP;
3743 goto out;
3744 }
3745
3746 if (!netif_running(dev)) {
3747 err = -ENETDOWN;
3748 goto out;
3749 }
3750
79c97e97 3751 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3752
3753out:
79c97e97 3754 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3755 dev_put(dev);
3756unlock_rtnl:
3757 rtnl_unlock();
3758 return err;
3759}
3760
aff89a9b
JB
3761#ifdef CONFIG_NL80211_TESTMODE
3762static struct genl_multicast_group nl80211_testmode_mcgrp = {
3763 .name = "testmode",
3764};
3765
3766static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3767{
3768 struct cfg80211_registered_device *rdev;
3769 int err;
3770
3771 if (!info->attrs[NL80211_ATTR_TESTDATA])
3772 return -EINVAL;
3773
3774 rtnl_lock();
3775
3776 rdev = cfg80211_get_dev_from_info(info);
3777 if (IS_ERR(rdev)) {
3778 err = PTR_ERR(rdev);
3779 goto unlock_rtnl;
3780 }
3781
3782 err = -EOPNOTSUPP;
3783 if (rdev->ops->testmode_cmd) {
3784 rdev->testmode_info = info;
3785 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3786 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3787 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3788 rdev->testmode_info = NULL;
3789 }
3790
4d0c8aea 3791 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
3792
3793 unlock_rtnl:
3794 rtnl_unlock();
3795 return err;
3796}
3797
3798static struct sk_buff *
3799__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3800 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3801{
3802 struct sk_buff *skb;
3803 void *hdr;
3804 struct nlattr *data;
3805
3806 skb = nlmsg_new(approxlen + 100, gfp);
3807 if (!skb)
3808 return NULL;
3809
3810 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3811 if (!hdr) {
3812 kfree_skb(skb);
3813 return NULL;
3814 }
3815
3816 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3817 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3818
3819 ((void **)skb->cb)[0] = rdev;
3820 ((void **)skb->cb)[1] = hdr;
3821 ((void **)skb->cb)[2] = data;
3822
3823 return skb;
3824
3825 nla_put_failure:
3826 kfree_skb(skb);
3827 return NULL;
3828}
3829
3830struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3831 int approxlen)
3832{
3833 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3834
3835 if (WARN_ON(!rdev->testmode_info))
3836 return NULL;
3837
3838 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3839 rdev->testmode_info->snd_pid,
3840 rdev->testmode_info->snd_seq,
3841 GFP_KERNEL);
3842}
3843EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3844
3845int cfg80211_testmode_reply(struct sk_buff *skb)
3846{
3847 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3848 void *hdr = ((void **)skb->cb)[1];
3849 struct nlattr *data = ((void **)skb->cb)[2];
3850
3851 if (WARN_ON(!rdev->testmode_info)) {
3852 kfree_skb(skb);
3853 return -EINVAL;
3854 }
3855
3856 nla_nest_end(skb, data);
3857 genlmsg_end(skb, hdr);
3858 return genlmsg_reply(skb, rdev->testmode_info);
3859}
3860EXPORT_SYMBOL(cfg80211_testmode_reply);
3861
3862struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3863 int approxlen, gfp_t gfp)
3864{
3865 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3866
3867 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3868}
3869EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3870
3871void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3872{
3873 void *hdr = ((void **)skb->cb)[1];
3874 struct nlattr *data = ((void **)skb->cb)[2];
3875
3876 nla_nest_end(skb, data);
3877 genlmsg_end(skb, hdr);
3878 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3879}
3880EXPORT_SYMBOL(cfg80211_testmode_event);
3881#endif
3882
b23aa676
SO
3883static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3884{
79c97e97 3885 struct cfg80211_registered_device *rdev;
b23aa676
SO
3886 struct net_device *dev;
3887 struct cfg80211_connect_params connect;
3888 struct wiphy *wiphy;
fffd0934 3889 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
3890 int err;
3891
3892 memset(&connect, 0, sizeof(connect));
3893
3894 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3895 return -EINVAL;
3896
3897 if (!info->attrs[NL80211_ATTR_SSID] ||
3898 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3899 return -EINVAL;
3900
3901 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3902 connect.auth_type =
3903 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3904 if (!nl80211_valid_auth_type(connect.auth_type))
3905 return -EINVAL;
3906 } else
3907 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3908
3909 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3910
3dc27d25
JB
3911 err = nl80211_crypto_settings(info, &connect.crypto,
3912 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
3913 if (err)
3914 return err;
3915 rtnl_lock();
3916
463d0183 3917 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
3918 if (err)
3919 goto unlock_rtnl;
3920
3921 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3922 err = -EOPNOTSUPP;
3923 goto out;
3924 }
3925
3926 if (!netif_running(dev)) {
3927 err = -ENETDOWN;
3928 goto out;
3929 }
3930
79c97e97 3931 wiphy = &rdev->wiphy;
b23aa676 3932
b23aa676
SO
3933 if (info->attrs[NL80211_ATTR_MAC])
3934 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3935 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3936 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3937
3938 if (info->attrs[NL80211_ATTR_IE]) {
3939 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3940 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3941 }
3942
3943 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3944 connect.channel =
3945 ieee80211_get_channel(wiphy,
3946 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3947 if (!connect.channel ||
3948 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
3949 err = -EINVAL;
3950 goto out;
3951 }
3952 }
3953
fffd0934
JB
3954 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3955 connkeys = nl80211_parse_connkeys(rdev,
3956 info->attrs[NL80211_ATTR_KEYS]);
3957 if (IS_ERR(connkeys)) {
3958 err = PTR_ERR(connkeys);
3959 connkeys = NULL;
3960 goto out;
3961 }
3962 }
3963
3964 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
3965
3966out:
79c97e97 3967 cfg80211_unlock_rdev(rdev);
b23aa676
SO
3968 dev_put(dev);
3969unlock_rtnl:
fffd0934
JB
3970 if (err)
3971 kfree(connkeys);
b23aa676
SO
3972 rtnl_unlock();
3973 return err;
3974}
3975
3976static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
3977{
79c97e97 3978 struct cfg80211_registered_device *rdev;
b23aa676
SO
3979 struct net_device *dev;
3980 int err;
3981 u16 reason;
3982
3983 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3984 reason = WLAN_REASON_DEAUTH_LEAVING;
3985 else
3986 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3987
3988 if (reason == 0)
3989 return -EINVAL;
3990
3991 rtnl_lock();
3992
463d0183 3993 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
3994 if (err)
3995 goto unlock_rtnl;
3996
3997 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3998 err = -EOPNOTSUPP;
3999 goto out;
4000 }
4001
4002 if (!netif_running(dev)) {
4003 err = -ENETDOWN;
4004 goto out;
4005 }
4006
79c97e97 4007 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4008
4009out:
79c97e97 4010 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4011 dev_put(dev);
4012unlock_rtnl:
4013 rtnl_unlock();
4014 return err;
4015}
4016
463d0183
JB
4017static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4018{
4019 struct cfg80211_registered_device *rdev;
4020 struct net *net;
4021 int err;
4022 u32 pid;
4023
4024 if (!info->attrs[NL80211_ATTR_PID])
4025 return -EINVAL;
4026
4027 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4028
4029 rtnl_lock();
4030
4031 rdev = cfg80211_get_dev_from_info(info);
4032 if (IS_ERR(rdev)) {
4033 err = PTR_ERR(rdev);
4034 goto out;
4035 }
4036
4037 net = get_net_ns_by_pid(pid);
4038 if (IS_ERR(net)) {
4039 err = PTR_ERR(net);
4040 goto out;
4041 }
4042
4043 err = 0;
4044
4045 /* check if anything to do */
4046 if (net_eq(wiphy_net(&rdev->wiphy), net))
4047 goto out_put_net;
4048
4049 err = cfg80211_switch_netns(rdev, net);
4050 out_put_net:
4051 put_net(net);
4052 out:
4053 cfg80211_unlock_rdev(rdev);
4054 rtnl_unlock();
4055 return err;
4056}
4057
55682965
JB
4058static struct genl_ops nl80211_ops[] = {
4059 {
4060 .cmd = NL80211_CMD_GET_WIPHY,
4061 .doit = nl80211_get_wiphy,
4062 .dumpit = nl80211_dump_wiphy,
4063 .policy = nl80211_policy,
4064 /* can be retrieved by unprivileged users */
4065 },
4066 {
4067 .cmd = NL80211_CMD_SET_WIPHY,
4068 .doit = nl80211_set_wiphy,
4069 .policy = nl80211_policy,
4070 .flags = GENL_ADMIN_PERM,
4071 },
4072 {
4073 .cmd = NL80211_CMD_GET_INTERFACE,
4074 .doit = nl80211_get_interface,
4075 .dumpit = nl80211_dump_interface,
4076 .policy = nl80211_policy,
4077 /* can be retrieved by unprivileged users */
4078 },
4079 {
4080 .cmd = NL80211_CMD_SET_INTERFACE,
4081 .doit = nl80211_set_interface,
4082 .policy = nl80211_policy,
4083 .flags = GENL_ADMIN_PERM,
4084 },
4085 {
4086 .cmd = NL80211_CMD_NEW_INTERFACE,
4087 .doit = nl80211_new_interface,
4088 .policy = nl80211_policy,
4089 .flags = GENL_ADMIN_PERM,
4090 },
4091 {
4092 .cmd = NL80211_CMD_DEL_INTERFACE,
4093 .doit = nl80211_del_interface,
4094 .policy = nl80211_policy,
41ade00f
JB
4095 .flags = GENL_ADMIN_PERM,
4096 },
4097 {
4098 .cmd = NL80211_CMD_GET_KEY,
4099 .doit = nl80211_get_key,
4100 .policy = nl80211_policy,
4101 .flags = GENL_ADMIN_PERM,
4102 },
4103 {
4104 .cmd = NL80211_CMD_SET_KEY,
4105 .doit = nl80211_set_key,
4106 .policy = nl80211_policy,
4107 .flags = GENL_ADMIN_PERM,
4108 },
4109 {
4110 .cmd = NL80211_CMD_NEW_KEY,
4111 .doit = nl80211_new_key,
4112 .policy = nl80211_policy,
4113 .flags = GENL_ADMIN_PERM,
4114 },
4115 {
4116 .cmd = NL80211_CMD_DEL_KEY,
4117 .doit = nl80211_del_key,
4118 .policy = nl80211_policy,
55682965
JB
4119 .flags = GENL_ADMIN_PERM,
4120 },
ed1b6cc7
JB
4121 {
4122 .cmd = NL80211_CMD_SET_BEACON,
4123 .policy = nl80211_policy,
4124 .flags = GENL_ADMIN_PERM,
4125 .doit = nl80211_addset_beacon,
4126 },
4127 {
4128 .cmd = NL80211_CMD_NEW_BEACON,
4129 .policy = nl80211_policy,
4130 .flags = GENL_ADMIN_PERM,
4131 .doit = nl80211_addset_beacon,
4132 },
4133 {
4134 .cmd = NL80211_CMD_DEL_BEACON,
4135 .policy = nl80211_policy,
4136 .flags = GENL_ADMIN_PERM,
4137 .doit = nl80211_del_beacon,
4138 },
5727ef1b
JB
4139 {
4140 .cmd = NL80211_CMD_GET_STATION,
4141 .doit = nl80211_get_station,
2ec600d6 4142 .dumpit = nl80211_dump_station,
5727ef1b 4143 .policy = nl80211_policy,
5727ef1b
JB
4144 },
4145 {
4146 .cmd = NL80211_CMD_SET_STATION,
4147 .doit = nl80211_set_station,
4148 .policy = nl80211_policy,
4149 .flags = GENL_ADMIN_PERM,
4150 },
4151 {
4152 .cmd = NL80211_CMD_NEW_STATION,
4153 .doit = nl80211_new_station,
4154 .policy = nl80211_policy,
4155 .flags = GENL_ADMIN_PERM,
4156 },
4157 {
4158 .cmd = NL80211_CMD_DEL_STATION,
4159 .doit = nl80211_del_station,
4160 .policy = nl80211_policy,
2ec600d6
LCC
4161 .flags = GENL_ADMIN_PERM,
4162 },
4163 {
4164 .cmd = NL80211_CMD_GET_MPATH,
4165 .doit = nl80211_get_mpath,
4166 .dumpit = nl80211_dump_mpath,
4167 .policy = nl80211_policy,
4168 .flags = GENL_ADMIN_PERM,
4169 },
4170 {
4171 .cmd = NL80211_CMD_SET_MPATH,
4172 .doit = nl80211_set_mpath,
4173 .policy = nl80211_policy,
4174 .flags = GENL_ADMIN_PERM,
4175 },
4176 {
4177 .cmd = NL80211_CMD_NEW_MPATH,
4178 .doit = nl80211_new_mpath,
4179 .policy = nl80211_policy,
4180 .flags = GENL_ADMIN_PERM,
4181 },
4182 {
4183 .cmd = NL80211_CMD_DEL_MPATH,
4184 .doit = nl80211_del_mpath,
4185 .policy = nl80211_policy,
9f1ba906
JM
4186 .flags = GENL_ADMIN_PERM,
4187 },
4188 {
4189 .cmd = NL80211_CMD_SET_BSS,
4190 .doit = nl80211_set_bss,
4191 .policy = nl80211_policy,
b2e1b302
LR
4192 .flags = GENL_ADMIN_PERM,
4193 },
f130347c
LR
4194 {
4195 .cmd = NL80211_CMD_GET_REG,
4196 .doit = nl80211_get_reg,
4197 .policy = nl80211_policy,
4198 /* can be retrieved by unprivileged users */
4199 },
b2e1b302
LR
4200 {
4201 .cmd = NL80211_CMD_SET_REG,
4202 .doit = nl80211_set_reg,
4203 .policy = nl80211_policy,
4204 .flags = GENL_ADMIN_PERM,
4205 },
4206 {
4207 .cmd = NL80211_CMD_REQ_SET_REG,
4208 .doit = nl80211_req_set_reg,
4209 .policy = nl80211_policy,
93da9cc1 4210 .flags = GENL_ADMIN_PERM,
4211 },
4212 {
4213 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4214 .doit = nl80211_get_mesh_params,
4215 .policy = nl80211_policy,
4216 /* can be retrieved by unprivileged users */
4217 },
4218 {
4219 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4220 .doit = nl80211_set_mesh_params,
4221 .policy = nl80211_policy,
9aed3cc1
JM
4222 .flags = GENL_ADMIN_PERM,
4223 },
2a519311
JB
4224 {
4225 .cmd = NL80211_CMD_TRIGGER_SCAN,
4226 .doit = nl80211_trigger_scan,
4227 .policy = nl80211_policy,
4228 .flags = GENL_ADMIN_PERM,
4229 },
4230 {
4231 .cmd = NL80211_CMD_GET_SCAN,
4232 .policy = nl80211_policy,
4233 .dumpit = nl80211_dump_scan,
4234 },
636a5d36
JM
4235 {
4236 .cmd = NL80211_CMD_AUTHENTICATE,
4237 .doit = nl80211_authenticate,
4238 .policy = nl80211_policy,
4239 .flags = GENL_ADMIN_PERM,
4240 },
4241 {
4242 .cmd = NL80211_CMD_ASSOCIATE,
4243 .doit = nl80211_associate,
4244 .policy = nl80211_policy,
4245 .flags = GENL_ADMIN_PERM,
4246 },
4247 {
4248 .cmd = NL80211_CMD_DEAUTHENTICATE,
4249 .doit = nl80211_deauthenticate,
4250 .policy = nl80211_policy,
4251 .flags = GENL_ADMIN_PERM,
4252 },
4253 {
4254 .cmd = NL80211_CMD_DISASSOCIATE,
4255 .doit = nl80211_disassociate,
4256 .policy = nl80211_policy,
4257 .flags = GENL_ADMIN_PERM,
4258 },
04a773ad
JB
4259 {
4260 .cmd = NL80211_CMD_JOIN_IBSS,
4261 .doit = nl80211_join_ibss,
4262 .policy = nl80211_policy,
4263 .flags = GENL_ADMIN_PERM,
4264 },
4265 {
4266 .cmd = NL80211_CMD_LEAVE_IBSS,
4267 .doit = nl80211_leave_ibss,
4268 .policy = nl80211_policy,
4269 .flags = GENL_ADMIN_PERM,
4270 },
aff89a9b
JB
4271#ifdef CONFIG_NL80211_TESTMODE
4272 {
4273 .cmd = NL80211_CMD_TESTMODE,
4274 .doit = nl80211_testmode_do,
4275 .policy = nl80211_policy,
4276 .flags = GENL_ADMIN_PERM,
4277 },
4278#endif
b23aa676
SO
4279 {
4280 .cmd = NL80211_CMD_CONNECT,
4281 .doit = nl80211_connect,
4282 .policy = nl80211_policy,
4283 .flags = GENL_ADMIN_PERM,
4284 },
4285 {
4286 .cmd = NL80211_CMD_DISCONNECT,
4287 .doit = nl80211_disconnect,
4288 .policy = nl80211_policy,
4289 .flags = GENL_ADMIN_PERM,
4290 },
463d0183
JB
4291 {
4292 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4293 .doit = nl80211_wiphy_netns,
4294 .policy = nl80211_policy,
4295 .flags = GENL_ADMIN_PERM,
4296 },
55682965 4297};
6039f6d2
JM
4298static struct genl_multicast_group nl80211_mlme_mcgrp = {
4299 .name = "mlme",
4300};
55682965
JB
4301
4302/* multicast groups */
4303static struct genl_multicast_group nl80211_config_mcgrp = {
4304 .name = "config",
4305};
2a519311
JB
4306static struct genl_multicast_group nl80211_scan_mcgrp = {
4307 .name = "scan",
4308};
73d54c9e
LR
4309static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4310 .name = "regulatory",
4311};
55682965
JB
4312
4313/* notification functions */
4314
4315void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4316{
4317 struct sk_buff *msg;
4318
fd2120ca 4319 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
4320 if (!msg)
4321 return;
4322
4323 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4324 nlmsg_free(msg);
4325 return;
4326 }
4327
463d0183
JB
4328 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4329 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
4330}
4331
362a415d
JB
4332static int nl80211_add_scan_req(struct sk_buff *msg,
4333 struct cfg80211_registered_device *rdev)
4334{
4335 struct cfg80211_scan_request *req = rdev->scan_req;
4336 struct nlattr *nest;
4337 int i;
4338
667503dd
JB
4339 ASSERT_RDEV_LOCK(rdev);
4340
362a415d
JB
4341 if (WARN_ON(!req))
4342 return 0;
4343
4344 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4345 if (!nest)
4346 goto nla_put_failure;
4347 for (i = 0; i < req->n_ssids; i++)
4348 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4349 nla_nest_end(msg, nest);
4350
4351 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4352 if (!nest)
4353 goto nla_put_failure;
4354 for (i = 0; i < req->n_channels; i++)
4355 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4356 nla_nest_end(msg, nest);
4357
4358 if (req->ie)
4359 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4360
4361 return 0;
4362 nla_put_failure:
4363 return -ENOBUFS;
4364}
4365
a538e2d5
JB
4366static int nl80211_send_scan_msg(struct sk_buff *msg,
4367 struct cfg80211_registered_device *rdev,
4368 struct net_device *netdev,
4369 u32 pid, u32 seq, int flags,
4370 u32 cmd)
2a519311
JB
4371{
4372 void *hdr;
4373
4374 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4375 if (!hdr)
4376 return -1;
4377
b5850a7a 4378 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
4379 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4380
362a415d
JB
4381 /* ignore errors and send incomplete event anyway */
4382 nl80211_add_scan_req(msg, rdev);
2a519311
JB
4383
4384 return genlmsg_end(msg, hdr);
4385
4386 nla_put_failure:
4387 genlmsg_cancel(msg, hdr);
4388 return -EMSGSIZE;
4389}
4390
a538e2d5
JB
4391void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4392 struct net_device *netdev)
4393{
4394 struct sk_buff *msg;
4395
4396 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4397 if (!msg)
4398 return;
4399
4400 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4401 NL80211_CMD_TRIGGER_SCAN) < 0) {
4402 nlmsg_free(msg);
4403 return;
4404 }
4405
463d0183
JB
4406 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4407 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
4408}
4409
2a519311
JB
4410void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4411 struct net_device *netdev)
4412{
4413 struct sk_buff *msg;
4414
fd2120ca 4415 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4416 if (!msg)
4417 return;
4418
a538e2d5
JB
4419 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4420 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
4421 nlmsg_free(msg);
4422 return;
4423 }
4424
463d0183
JB
4425 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4426 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4427}
4428
4429void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4430 struct net_device *netdev)
4431{
4432 struct sk_buff *msg;
4433
fd2120ca 4434 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4435 if (!msg)
4436 return;
4437
a538e2d5
JB
4438 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4439 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
4440 nlmsg_free(msg);
4441 return;
4442 }
4443
463d0183
JB
4444 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4445 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4446}
4447
73d54c9e
LR
4448/*
4449 * This can happen on global regulatory changes or device specific settings
4450 * based on custom world regulatory domains.
4451 */
4452void nl80211_send_reg_change_event(struct regulatory_request *request)
4453{
4454 struct sk_buff *msg;
4455 void *hdr;
4456
fd2120ca 4457 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
4458 if (!msg)
4459 return;
4460
4461 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4462 if (!hdr) {
4463 nlmsg_free(msg);
4464 return;
4465 }
4466
4467 /* Userspace can always count this one always being set */
4468 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4469
4470 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4471 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4472 NL80211_REGDOM_TYPE_WORLD);
4473 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4474 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4475 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4476 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4477 request->intersect)
4478 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4479 NL80211_REGDOM_TYPE_INTERSECTION);
4480 else {
4481 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4482 NL80211_REGDOM_TYPE_COUNTRY);
4483 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4484 }
4485
4486 if (wiphy_idx_valid(request->wiphy_idx))
4487 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4488
4489 if (genlmsg_end(msg, hdr) < 0) {
4490 nlmsg_free(msg);
4491 return;
4492 }
4493
bc43b28c 4494 rcu_read_lock();
463d0183 4495 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
4496 GFP_ATOMIC);
4497 rcu_read_unlock();
73d54c9e
LR
4498
4499 return;
4500
4501nla_put_failure:
4502 genlmsg_cancel(msg, hdr);
4503 nlmsg_free(msg);
4504}
4505
6039f6d2
JM
4506static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4507 struct net_device *netdev,
4508 const u8 *buf, size_t len,
e6d6e342 4509 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
4510{
4511 struct sk_buff *msg;
4512 void *hdr;
4513
e6d6e342 4514 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
4515 if (!msg)
4516 return;
4517
4518 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4519 if (!hdr) {
4520 nlmsg_free(msg);
4521 return;
4522 }
4523
4524 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4525 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4526 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4527
4528 if (genlmsg_end(msg, hdr) < 0) {
4529 nlmsg_free(msg);
4530 return;
4531 }
4532
463d0183
JB
4533 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4534 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
4535 return;
4536
4537 nla_put_failure:
4538 genlmsg_cancel(msg, hdr);
4539 nlmsg_free(msg);
4540}
4541
4542void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4543 struct net_device *netdev, const u8 *buf,
4544 size_t len, gfp_t gfp)
6039f6d2
JM
4545{
4546 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4547 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
4548}
4549
4550void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4551 struct net_device *netdev, const u8 *buf,
e6d6e342 4552 size_t len, gfp_t gfp)
6039f6d2 4553{
e6d6e342
JB
4554 nl80211_send_mlme_event(rdev, netdev, buf, len,
4555 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
4556}
4557
53b46b84 4558void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4559 struct net_device *netdev, const u8 *buf,
4560 size_t len, gfp_t gfp)
6039f6d2
JM
4561{
4562 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4563 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
4564}
4565
53b46b84
JM
4566void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4567 struct net_device *netdev, const u8 *buf,
e6d6e342 4568 size_t len, gfp_t gfp)
6039f6d2
JM
4569{
4570 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4571 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
4572}
4573
1b06bb40
LR
4574static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4575 struct net_device *netdev, int cmd,
e6d6e342 4576 const u8 *addr, gfp_t gfp)
1965c853
JM
4577{
4578 struct sk_buff *msg;
4579 void *hdr;
4580
e6d6e342 4581 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
4582 if (!msg)
4583 return;
4584
4585 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4586 if (!hdr) {
4587 nlmsg_free(msg);
4588 return;
4589 }
4590
4591 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4592 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4593 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4594 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4595
4596 if (genlmsg_end(msg, hdr) < 0) {
4597 nlmsg_free(msg);
4598 return;
4599 }
4600
463d0183
JB
4601 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4602 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
4603 return;
4604
4605 nla_put_failure:
4606 genlmsg_cancel(msg, hdr);
4607 nlmsg_free(msg);
4608}
4609
4610void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4611 struct net_device *netdev, const u8 *addr,
4612 gfp_t gfp)
1965c853
JM
4613{
4614 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 4615 addr, gfp);
1965c853
JM
4616}
4617
4618void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4619 struct net_device *netdev, const u8 *addr,
4620 gfp_t gfp)
1965c853 4621{
e6d6e342
JB
4622 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4623 addr, gfp);
1965c853
JM
4624}
4625
b23aa676
SO
4626void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4627 struct net_device *netdev, const u8 *bssid,
4628 const u8 *req_ie, size_t req_ie_len,
4629 const u8 *resp_ie, size_t resp_ie_len,
4630 u16 status, gfp_t gfp)
4631{
4632 struct sk_buff *msg;
4633 void *hdr;
4634
4635 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4636 if (!msg)
4637 return;
4638
4639 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4640 if (!hdr) {
4641 nlmsg_free(msg);
4642 return;
4643 }
4644
4645 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4646 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4647 if (bssid)
4648 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4649 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4650 if (req_ie)
4651 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4652 if (resp_ie)
4653 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4654
4655 if (genlmsg_end(msg, hdr) < 0) {
4656 nlmsg_free(msg);
4657 return;
4658 }
4659
463d0183
JB
4660 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4661 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
4662 return;
4663
4664 nla_put_failure:
4665 genlmsg_cancel(msg, hdr);
4666 nlmsg_free(msg);
4667
4668}
4669
4670void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4671 struct net_device *netdev, const u8 *bssid,
4672 const u8 *req_ie, size_t req_ie_len,
4673 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4674{
4675 struct sk_buff *msg;
4676 void *hdr;
4677
4678 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4679 if (!msg)
4680 return;
4681
4682 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4683 if (!hdr) {
4684 nlmsg_free(msg);
4685 return;
4686 }
4687
4688 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4689 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4690 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4691 if (req_ie)
4692 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4693 if (resp_ie)
4694 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4695
4696 if (genlmsg_end(msg, hdr) < 0) {
4697 nlmsg_free(msg);
4698 return;
4699 }
4700
463d0183
JB
4701 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4702 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
4703 return;
4704
4705 nla_put_failure:
4706 genlmsg_cancel(msg, hdr);
4707 nlmsg_free(msg);
4708
4709}
4710
4711void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4712 struct net_device *netdev, u16 reason,
667503dd 4713 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
4714{
4715 struct sk_buff *msg;
4716 void *hdr;
4717
667503dd 4718 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
4719 if (!msg)
4720 return;
4721
4722 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4723 if (!hdr) {
4724 nlmsg_free(msg);
4725 return;
4726 }
4727
4728 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4729 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4730 if (from_ap && reason)
4731 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4732 if (from_ap)
4733 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4734 if (ie)
4735 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4736
4737 if (genlmsg_end(msg, hdr) < 0) {
4738 nlmsg_free(msg);
4739 return;
4740 }
4741
463d0183
JB
4742 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4743 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
4744 return;
4745
4746 nla_put_failure:
4747 genlmsg_cancel(msg, hdr);
4748 nlmsg_free(msg);
4749
4750}
4751
04a773ad
JB
4752void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4753 struct net_device *netdev, const u8 *bssid,
4754 gfp_t gfp)
4755{
4756 struct sk_buff *msg;
4757 void *hdr;
4758
fd2120ca 4759 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
4760 if (!msg)
4761 return;
4762
4763 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4764 if (!hdr) {
4765 nlmsg_free(msg);
4766 return;
4767 }
4768
4769 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4770 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4771 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4772
4773 if (genlmsg_end(msg, hdr) < 0) {
4774 nlmsg_free(msg);
4775 return;
4776 }
4777
463d0183
JB
4778 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4779 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
4780 return;
4781
4782 nla_put_failure:
4783 genlmsg_cancel(msg, hdr);
4784 nlmsg_free(msg);
4785}
4786
a3b8b056
JM
4787void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4788 struct net_device *netdev, const u8 *addr,
4789 enum nl80211_key_type key_type, int key_id,
e6d6e342 4790 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
4791{
4792 struct sk_buff *msg;
4793 void *hdr;
4794
e6d6e342 4795 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
4796 if (!msg)
4797 return;
4798
4799 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4800 if (!hdr) {
4801 nlmsg_free(msg);
4802 return;
4803 }
4804
4805 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4806 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4807 if (addr)
4808 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4809 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4810 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4811 if (tsc)
4812 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4813
4814 if (genlmsg_end(msg, hdr) < 0) {
4815 nlmsg_free(msg);
4816 return;
4817 }
4818
463d0183
JB
4819 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4820 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
4821 return;
4822
4823 nla_put_failure:
4824 genlmsg_cancel(msg, hdr);
4825 nlmsg_free(msg);
4826}
4827
6bad8766
LR
4828void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
4829 struct ieee80211_channel *channel_before,
4830 struct ieee80211_channel *channel_after)
4831{
4832 struct sk_buff *msg;
4833 void *hdr;
4834 struct nlattr *nl_freq;
4835
fd2120ca 4836 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
4837 if (!msg)
4838 return;
4839
4840 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
4841 if (!hdr) {
4842 nlmsg_free(msg);
4843 return;
4844 }
4845
4846 /*
4847 * Since we are applying the beacon hint to a wiphy we know its
4848 * wiphy_idx is valid
4849 */
4850 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
4851
4852 /* Before */
4853 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
4854 if (!nl_freq)
4855 goto nla_put_failure;
4856 if (nl80211_msg_put_channel(msg, channel_before))
4857 goto nla_put_failure;
4858 nla_nest_end(msg, nl_freq);
4859
4860 /* After */
4861 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
4862 if (!nl_freq)
4863 goto nla_put_failure;
4864 if (nl80211_msg_put_channel(msg, channel_after))
4865 goto nla_put_failure;
4866 nla_nest_end(msg, nl_freq);
4867
4868 if (genlmsg_end(msg, hdr) < 0) {
4869 nlmsg_free(msg);
4870 return;
4871 }
4872
463d0183
JB
4873 rcu_read_lock();
4874 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4875 GFP_ATOMIC);
4876 rcu_read_unlock();
6bad8766
LR
4877
4878 return;
4879
4880nla_put_failure:
4881 genlmsg_cancel(msg, hdr);
4882 nlmsg_free(msg);
4883}
4884
55682965
JB
4885/* initialisation/exit functions */
4886
4887int nl80211_init(void)
4888{
0d63cbb5 4889 int err;
55682965 4890
0d63cbb5
MM
4891 err = genl_register_family_with_ops(&nl80211_fam,
4892 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
4893 if (err)
4894 return err;
4895
55682965
JB
4896 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
4897 if (err)
4898 goto err_out;
4899
2a519311
JB
4900 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
4901 if (err)
4902 goto err_out;
4903
73d54c9e
LR
4904 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
4905 if (err)
4906 goto err_out;
4907
6039f6d2
JM
4908 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
4909 if (err)
4910 goto err_out;
4911
aff89a9b
JB
4912#ifdef CONFIG_NL80211_TESTMODE
4913 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
4914 if (err)
4915 goto err_out;
4916#endif
4917
55682965
JB
4918 return 0;
4919 err_out:
4920 genl_unregister_family(&nl80211_fam);
4921 return err;
4922}
4923
4924void nl80211_exit(void)
4925{
4926 genl_unregister_family(&nl80211_fam);
4927}