]> git.proxmox.com Git - mirror_ubuntu-eoan-kernel.git/blame - net/wireless/nl80211.c
mac80211: send {ADD,DEL}BA on AC_VO like other mgmt frames, as per spec
[mirror_ubuntu-eoan-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
2a0e047e 22#include <net/inet_connection_sock.h>
55682965
JB
23#include "core.h"
24#include "nl80211.h"
b2e1b302 25#include "reg.h"
e35e4d28 26#include "rdev-ops.h"
55682965 27
5fb628e9
JM
28static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
29 struct genl_info *info,
30 struct cfg80211_crypto_settings *settings,
31 int cipher_limit);
32
f84f771d 33static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991 34 struct genl_info *info);
f84f771d 35static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
36 struct genl_info *info);
37
55682965
JB
38/* the netlink family */
39static struct genl_family nl80211_fam = {
fb4e1568
MH
40 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
41 .name = NL80211_GENL_NAME, /* have users key off the name instead */
42 .hdrsize = 0, /* no private header */
43 .version = 1, /* no particular meaning now */
55682965 44 .maxattr = NL80211_ATTR_MAX,
463d0183 45 .netnsok = true,
4c476991
JB
46 .pre_doit = nl80211_pre_doit,
47 .post_doit = nl80211_post_doit,
55682965
JB
48};
49
2a94fe48
JB
50/* multicast groups */
51enum nl80211_multicast_groups {
52 NL80211_MCGRP_CONFIG,
53 NL80211_MCGRP_SCAN,
54 NL80211_MCGRP_REGULATORY,
55 NL80211_MCGRP_MLME,
567ffc35 56 NL80211_MCGRP_VENDOR,
2a94fe48
JB
57 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
58};
59
60static const struct genl_multicast_group nl80211_mcgrps[] = {
61 [NL80211_MCGRP_CONFIG] = { .name = "config", },
62 [NL80211_MCGRP_SCAN] = { .name = "scan", },
63 [NL80211_MCGRP_REGULATORY] = { .name = "regulatory", },
64 [NL80211_MCGRP_MLME] = { .name = "mlme", },
567ffc35 65 [NL80211_MCGRP_VENDOR] = { .name = "vendor", },
2a94fe48
JB
66#ifdef CONFIG_NL80211_TESTMODE
67 [NL80211_MCGRP_TESTMODE] = { .name = "testmode", }
68#endif
69};
70
89a54e48
JB
71/* returns ERR_PTR values */
72static struct wireless_dev *
73__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 74{
89a54e48
JB
75 struct cfg80211_registered_device *rdev;
76 struct wireless_dev *result = NULL;
77 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
78 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
79 u64 wdev_id;
80 int wiphy_idx = -1;
81 int ifidx = -1;
55682965 82
5fe231e8 83 ASSERT_RTNL();
55682965 84
89a54e48
JB
85 if (!have_ifidx && !have_wdev_id)
86 return ERR_PTR(-EINVAL);
55682965 87
89a54e48
JB
88 if (have_ifidx)
89 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
90 if (have_wdev_id) {
91 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
92 wiphy_idx = wdev_id >> 32;
55682965
JB
93 }
94
89a54e48
JB
95 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
96 struct wireless_dev *wdev;
97
98 if (wiphy_net(&rdev->wiphy) != netns)
99 continue;
100
101 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
102 continue;
103
89a54e48
JB
104 list_for_each_entry(wdev, &rdev->wdev_list, list) {
105 if (have_ifidx && wdev->netdev &&
106 wdev->netdev->ifindex == ifidx) {
107 result = wdev;
108 break;
109 }
110 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
111 result = wdev;
112 break;
113 }
114 }
89a54e48
JB
115
116 if (result)
117 break;
118 }
119
120 if (result)
121 return result;
122 return ERR_PTR(-ENODEV);
55682965
JB
123}
124
a9455408 125static struct cfg80211_registered_device *
878d9ec7 126__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 127{
7fee4778
JB
128 struct cfg80211_registered_device *rdev = NULL, *tmp;
129 struct net_device *netdev;
a9455408 130
5fe231e8 131 ASSERT_RTNL();
a9455408 132
878d9ec7 133 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
134 !attrs[NL80211_ATTR_IFINDEX] &&
135 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
136 return ERR_PTR(-EINVAL);
137
878d9ec7 138 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 139 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 140 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 141
89a54e48
JB
142 if (attrs[NL80211_ATTR_WDEV]) {
143 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
144 struct wireless_dev *wdev;
145 bool found = false;
146
147 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
148 if (tmp) {
149 /* make sure wdev exists */
89a54e48
JB
150 list_for_each_entry(wdev, &tmp->wdev_list, list) {
151 if (wdev->identifier != (u32)wdev_id)
152 continue;
153 found = true;
154 break;
155 }
89a54e48
JB
156
157 if (!found)
158 tmp = NULL;
159
160 if (rdev && tmp != rdev)
161 return ERR_PTR(-EINVAL);
162 rdev = tmp;
163 }
164 }
165
878d9ec7
JB
166 if (attrs[NL80211_ATTR_IFINDEX]) {
167 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
7f2b8562 168 netdev = __dev_get_by_index(netns, ifindex);
7fee4778
JB
169 if (netdev) {
170 if (netdev->ieee80211_ptr)
171 tmp = wiphy_to_dev(
172 netdev->ieee80211_ptr->wiphy);
173 else
174 tmp = NULL;
175
7fee4778
JB
176 /* not wireless device -- return error */
177 if (!tmp)
178 return ERR_PTR(-EINVAL);
179
180 /* mismatch -- return error */
181 if (rdev && tmp != rdev)
182 return ERR_PTR(-EINVAL);
183
184 rdev = tmp;
a9455408 185 }
a9455408 186 }
a9455408 187
4f7eff10
JB
188 if (!rdev)
189 return ERR_PTR(-ENODEV);
a9455408 190
4f7eff10
JB
191 if (netns != wiphy_net(&rdev->wiphy))
192 return ERR_PTR(-ENODEV);
193
194 return rdev;
a9455408
JB
195}
196
197/*
198 * This function returns a pointer to the driver
199 * that the genl_info item that is passed refers to.
a9455408
JB
200 *
201 * The result of this can be a PTR_ERR and hence must
202 * be checked with IS_ERR() for errors.
203 */
204static struct cfg80211_registered_device *
4f7eff10 205cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 206{
5fe231e8 207 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
208}
209
55682965 210/* policy for the attributes */
b54452b0 211static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
212 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
213 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 214 .len = 20-1 },
31888487 215 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 216
72bdcf34 217 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 218 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
219 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
220 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
221 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
222
b9a5f8ca
JM
223 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
224 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
225 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
226 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 227 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
228
229 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
230 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
231 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 232
e007b857
EP
233 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
234 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 235
b9454e83 236 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
237 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
238 .len = WLAN_MAX_KEY_LEN },
239 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
240 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
241 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 242 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 243 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
244
245 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
246 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
247 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
248 .len = IEEE80211_MAX_DATA_LEN },
249 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
250 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
251 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
252 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
253 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
254 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
255 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 256 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 257 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 258 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 259 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 260 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 261 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 262
b2e1b302
LR
263 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
264 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
265
9f1ba906
JM
266 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
267 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
268 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
269 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
270 .len = NL80211_MAX_SUPP_RATES },
50b12f59 271 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 272
24bdd9f4 273 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 274 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 275
6c739419 276 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
277
278 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
279 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
280 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
281 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
282 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
283
284 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
285 .len = IEEE80211_MAX_SSID_LEN },
286 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
287 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 288 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 289 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 290 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
291 [NL80211_ATTR_STA_FLAGS2] = {
292 .len = sizeof(struct nl80211_sta_flag_update),
293 },
3f77316c 294 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
295 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
296 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
297 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
298 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
299 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 300 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 301 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
302 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
303 .len = WLAN_PMKID_LEN },
9588bbd5
JM
304 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
305 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 306 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
307 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
308 .len = IEEE80211_MAX_DATA_LEN },
309 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 310 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 311 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 312 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 313 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
314 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
315 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 316 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
317 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
318 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 319 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 320 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 321 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 322 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 323 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 324 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 325 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 326 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 327 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
328 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
329 .len = IEEE80211_MAX_DATA_LEN },
330 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
331 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 332 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 333 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 334 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
335 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
336 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
337 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
338 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
339 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 340 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
341 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
342 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 343 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
344 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
345 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
346 .len = NL80211_HT_CAPABILITY_LEN
347 },
1d9d9213 348 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 349 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 350 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 351 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 352 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 353 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 354 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 355 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
356 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
357 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
358 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
359 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
360 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
361 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 362 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
363 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
364 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
365 .len = NL80211_VHT_CAPABILITY_LEN,
366 },
355199e0
JM
367 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
368 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
369 .len = IEEE80211_MAX_DATA_LEN },
5e4b6f56 370 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 },
16ef1fe2
SW
371 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
372 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
373 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
374 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_U16 },
375 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_U16 },
c01fc9ad
SD
376 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY },
377 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY },
5336fa88 378 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
60f4a7b1 379 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
ad7e718c
JB
380 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
381 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
382 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
fa9ffc74
KP
383 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY,
384 .len = IEEE80211_QOS_MAP_LEN_MAX },
1df4a510
JM
385 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN },
386 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
55682965
JB
387};
388
e31b8213 389/* policy for the key attributes */
b54452b0 390static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 391 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
392 [NL80211_KEY_IDX] = { .type = NLA_U8 },
393 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 394 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
395 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
396 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 397 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
398 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
399};
400
401/* policy for the key default flags */
402static const struct nla_policy
403nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
404 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
405 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
406};
407
ff1b6e69
JB
408/* policy for WoWLAN attributes */
409static const struct nla_policy
410nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
411 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
412 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
413 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
414 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
415 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
416 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
417 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
418 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e
JB
419 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
420};
421
422static const struct nla_policy
423nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
424 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
425 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
426 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
427 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
428 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
429 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
430 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
431 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
432 },
433 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
434 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
435 },
436 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
437 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
438 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69
JB
439};
440
be29b99a
AK
441/* policy for coalesce rule attributes */
442static const struct nla_policy
443nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
444 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
445 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 },
446 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
447};
448
e5497d76
JB
449/* policy for GTK rekey offload attributes */
450static const struct nla_policy
451nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
452 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
453 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
454 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
455};
456
a1f1c21c
LC
457static const struct nla_policy
458nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 459 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 460 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 461 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
462};
463
97990a06
JB
464static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
465 struct netlink_callback *cb,
466 struct cfg80211_registered_device **rdev,
467 struct wireless_dev **wdev)
a043897a 468{
97990a06 469 int err;
a043897a 470
97990a06 471 rtnl_lock();
a043897a 472
97990a06
JB
473 if (!cb->args[0]) {
474 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
475 nl80211_fam.attrbuf, nl80211_fam.maxattr,
476 nl80211_policy);
477 if (err)
478 goto out_unlock;
67748893 479
97990a06
JB
480 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk),
481 nl80211_fam.attrbuf);
482 if (IS_ERR(*wdev)) {
483 err = PTR_ERR(*wdev);
484 goto out_unlock;
485 }
486 *rdev = wiphy_to_dev((*wdev)->wiphy);
c319d50b
JB
487 /* 0 is the first index - add 1 to parse only once */
488 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
489 cb->args[1] = (*wdev)->identifier;
490 } else {
c319d50b
JB
491 /* subtract the 1 again here */
492 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 493 struct wireless_dev *tmp;
67748893 494
97990a06
JB
495 if (!wiphy) {
496 err = -ENODEV;
497 goto out_unlock;
498 }
499 *rdev = wiphy_to_dev(wiphy);
500 *wdev = NULL;
67748893 501
97990a06
JB
502 list_for_each_entry(tmp, &(*rdev)->wdev_list, list) {
503 if (tmp->identifier == cb->args[1]) {
504 *wdev = tmp;
505 break;
506 }
507 }
67748893 508
97990a06
JB
509 if (!*wdev) {
510 err = -ENODEV;
511 goto out_unlock;
512 }
67748893
JB
513 }
514
67748893 515 return 0;
97990a06 516 out_unlock:
67748893
JB
517 rtnl_unlock();
518 return err;
519}
520
97990a06 521static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev)
67748893 522{
67748893
JB
523 rtnl_unlock();
524}
525
f4a11bb0
JB
526/* IE validation */
527static bool is_valid_ie_attr(const struct nlattr *attr)
528{
529 const u8 *pos;
530 int len;
531
532 if (!attr)
533 return true;
534
535 pos = nla_data(attr);
536 len = nla_len(attr);
537
538 while (len) {
539 u8 elemlen;
540
541 if (len < 2)
542 return false;
543 len -= 2;
544
545 elemlen = pos[1];
546 if (elemlen > len)
547 return false;
548
549 len -= elemlen;
550 pos += 2 + elemlen;
551 }
552
553 return true;
554}
555
55682965 556/* message building helper */
15e47304 557static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
558 int flags, u8 cmd)
559{
560 /* since there is no private header just add the generic one */
15e47304 561 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
562}
563
5dab3b8a 564static int nl80211_msg_put_channel(struct sk_buff *msg,
cdc89b97
JB
565 struct ieee80211_channel *chan,
566 bool large)
5dab3b8a 567{
9360ffd1
DM
568 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
569 chan->center_freq))
570 goto nla_put_failure;
5dab3b8a 571
9360ffd1
DM
572 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
573 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
574 goto nla_put_failure;
8fe02e16
LR
575 if (chan->flags & IEEE80211_CHAN_NO_IR) {
576 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
577 goto nla_put_failure;
578 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
579 goto nla_put_failure;
580 }
cdc89b97
JB
581 if (chan->flags & IEEE80211_CHAN_RADAR) {
582 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
583 goto nla_put_failure;
584 if (large) {
585 u32 time;
586
587 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
588
589 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
590 chan->dfs_state))
591 goto nla_put_failure;
592 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
593 time))
594 goto nla_put_failure;
595 }
596 }
5dab3b8a 597
fe1abafd
JB
598 if (large) {
599 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
600 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
601 goto nla_put_failure;
602 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
603 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
604 goto nla_put_failure;
605 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
606 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
607 goto nla_put_failure;
608 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
609 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
610 goto nla_put_failure;
611 }
612
9360ffd1
DM
613 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
614 DBM_TO_MBM(chan->max_power)))
615 goto nla_put_failure;
5dab3b8a
LR
616
617 return 0;
618
619 nla_put_failure:
620 return -ENOBUFS;
621}
622
55682965
JB
623/* netlink command implementations */
624
b9454e83
JB
625struct key_parse {
626 struct key_params p;
627 int idx;
e31b8213 628 int type;
b9454e83 629 bool def, defmgmt;
dbd2fd65 630 bool def_uni, def_multi;
b9454e83
JB
631};
632
633static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
634{
635 struct nlattr *tb[NL80211_KEY_MAX + 1];
636 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
637 nl80211_key_policy);
638 if (err)
639 return err;
640
641 k->def = !!tb[NL80211_KEY_DEFAULT];
642 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
643
dbd2fd65
JB
644 if (k->def) {
645 k->def_uni = true;
646 k->def_multi = true;
647 }
648 if (k->defmgmt)
649 k->def_multi = true;
650
b9454e83
JB
651 if (tb[NL80211_KEY_IDX])
652 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
653
654 if (tb[NL80211_KEY_DATA]) {
655 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
656 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
657 }
658
659 if (tb[NL80211_KEY_SEQ]) {
660 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
661 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
662 }
663
664 if (tb[NL80211_KEY_CIPHER])
665 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
666
e31b8213
JB
667 if (tb[NL80211_KEY_TYPE]) {
668 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
669 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
670 return -EINVAL;
671 }
672
dbd2fd65
JB
673 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
674 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
675 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
676 tb[NL80211_KEY_DEFAULT_TYPES],
677 nl80211_key_default_policy);
dbd2fd65
JB
678 if (err)
679 return err;
680
681 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
682 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
683 }
684
b9454e83
JB
685 return 0;
686}
687
688static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
689{
690 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
691 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
692 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
693 }
694
695 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
696 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
697 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
698 }
699
700 if (info->attrs[NL80211_ATTR_KEY_IDX])
701 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
702
703 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
704 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
705
706 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
707 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
708
dbd2fd65
JB
709 if (k->def) {
710 k->def_uni = true;
711 k->def_multi = true;
712 }
713 if (k->defmgmt)
714 k->def_multi = true;
715
e31b8213
JB
716 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
717 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
718 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
719 return -EINVAL;
720 }
721
dbd2fd65
JB
722 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
723 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
724 int err = nla_parse_nested(
725 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
726 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
727 nl80211_key_default_policy);
728 if (err)
729 return err;
730
731 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
732 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
733 }
734
b9454e83
JB
735 return 0;
736}
737
738static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
739{
740 int err;
741
742 memset(k, 0, sizeof(*k));
743 k->idx = -1;
e31b8213 744 k->type = -1;
b9454e83
JB
745
746 if (info->attrs[NL80211_ATTR_KEY])
747 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
748 else
749 err = nl80211_parse_key_old(info, k);
750
751 if (err)
752 return err;
753
754 if (k->def && k->defmgmt)
755 return -EINVAL;
756
dbd2fd65
JB
757 if (k->defmgmt) {
758 if (k->def_uni || !k->def_multi)
759 return -EINVAL;
760 }
761
b9454e83
JB
762 if (k->idx != -1) {
763 if (k->defmgmt) {
764 if (k->idx < 4 || k->idx > 5)
765 return -EINVAL;
766 } else if (k->def) {
767 if (k->idx < 0 || k->idx > 3)
768 return -EINVAL;
769 } else {
770 if (k->idx < 0 || k->idx > 5)
771 return -EINVAL;
772 }
773 }
774
775 return 0;
776}
777
fffd0934
JB
778static struct cfg80211_cached_keys *
779nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 780 struct nlattr *keys, bool *no_ht)
fffd0934
JB
781{
782 struct key_parse parse;
783 struct nlattr *key;
784 struct cfg80211_cached_keys *result;
785 int rem, err, def = 0;
786
787 result = kzalloc(sizeof(*result), GFP_KERNEL);
788 if (!result)
789 return ERR_PTR(-ENOMEM);
790
791 result->def = -1;
792 result->defmgmt = -1;
793
794 nla_for_each_nested(key, keys, rem) {
795 memset(&parse, 0, sizeof(parse));
796 parse.idx = -1;
797
798 err = nl80211_parse_key_new(key, &parse);
799 if (err)
800 goto error;
801 err = -EINVAL;
802 if (!parse.p.key)
803 goto error;
804 if (parse.idx < 0 || parse.idx > 4)
805 goto error;
806 if (parse.def) {
807 if (def)
808 goto error;
809 def = 1;
810 result->def = parse.idx;
dbd2fd65
JB
811 if (!parse.def_uni || !parse.def_multi)
812 goto error;
fffd0934
JB
813 } else if (parse.defmgmt)
814 goto error;
815 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 816 parse.idx, false, NULL);
fffd0934
JB
817 if (err)
818 goto error;
819 result->params[parse.idx].cipher = parse.p.cipher;
820 result->params[parse.idx].key_len = parse.p.key_len;
821 result->params[parse.idx].key = result->data[parse.idx];
822 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
823
824 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
825 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
826 if (no_ht)
827 *no_ht = true;
828 }
fffd0934
JB
829 }
830
831 return result;
832 error:
833 kfree(result);
834 return ERR_PTR(err);
835}
836
837static int nl80211_key_allowed(struct wireless_dev *wdev)
838{
839 ASSERT_WDEV_LOCK(wdev);
840
fffd0934
JB
841 switch (wdev->iftype) {
842 case NL80211_IFTYPE_AP:
843 case NL80211_IFTYPE_AP_VLAN:
074ac8df 844 case NL80211_IFTYPE_P2P_GO:
ff973af7 845 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
846 break;
847 case NL80211_IFTYPE_ADHOC:
fffd0934 848 case NL80211_IFTYPE_STATION:
074ac8df 849 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 850 if (!wdev->current_bss)
fffd0934
JB
851 return -ENOLINK;
852 break;
853 default:
854 return -EINVAL;
855 }
856
857 return 0;
858}
859
664834de
JM
860static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
861 struct nlattr *tb)
862{
863 struct ieee80211_channel *chan;
864
865 if (tb == NULL)
866 return NULL;
867 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb));
868 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
869 return NULL;
870 return chan;
871}
872
7527a782
JB
873static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
874{
875 struct nlattr *nl_modes = nla_nest_start(msg, attr);
876 int i;
877
878 if (!nl_modes)
879 goto nla_put_failure;
880
881 i = 0;
882 while (ifmodes) {
9360ffd1
DM
883 if ((ifmodes & 1) && nla_put_flag(msg, i))
884 goto nla_put_failure;
7527a782
JB
885 ifmodes >>= 1;
886 i++;
887 }
888
889 nla_nest_end(msg, nl_modes);
890 return 0;
891
892nla_put_failure:
893 return -ENOBUFS;
894}
895
896static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
897 struct sk_buff *msg,
898 bool large)
7527a782
JB
899{
900 struct nlattr *nl_combis;
901 int i, j;
902
903 nl_combis = nla_nest_start(msg,
904 NL80211_ATTR_INTERFACE_COMBINATIONS);
905 if (!nl_combis)
906 goto nla_put_failure;
907
908 for (i = 0; i < wiphy->n_iface_combinations; i++) {
909 const struct ieee80211_iface_combination *c;
910 struct nlattr *nl_combi, *nl_limits;
911
912 c = &wiphy->iface_combinations[i];
913
914 nl_combi = nla_nest_start(msg, i + 1);
915 if (!nl_combi)
916 goto nla_put_failure;
917
918 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
919 if (!nl_limits)
920 goto nla_put_failure;
921
922 for (j = 0; j < c->n_limits; j++) {
923 struct nlattr *nl_limit;
924
925 nl_limit = nla_nest_start(msg, j + 1);
926 if (!nl_limit)
927 goto nla_put_failure;
9360ffd1
DM
928 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
929 c->limits[j].max))
930 goto nla_put_failure;
7527a782
JB
931 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
932 c->limits[j].types))
933 goto nla_put_failure;
934 nla_nest_end(msg, nl_limit);
935 }
936
937 nla_nest_end(msg, nl_limits);
938
9360ffd1
DM
939 if (c->beacon_int_infra_match &&
940 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
941 goto nla_put_failure;
942 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
943 c->num_different_channels) ||
944 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
945 c->max_interfaces))
946 goto nla_put_failure;
cdc89b97
JB
947 if (large &&
948 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
949 c->radar_detect_widths))
950 goto nla_put_failure;
7527a782
JB
951
952 nla_nest_end(msg, nl_combi);
953 }
954
955 nla_nest_end(msg, nl_combis);
956
957 return 0;
958nla_put_failure:
959 return -ENOBUFS;
960}
961
3713b4e3 962#ifdef CONFIG_PM
b56cf720
JB
963static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
964 struct sk_buff *msg)
965{
964dc9e2 966 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
967 struct nlattr *nl_tcp;
968
969 if (!tcp)
970 return 0;
971
972 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
973 if (!nl_tcp)
974 return -ENOBUFS;
975
976 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
977 tcp->data_payload_max))
978 return -ENOBUFS;
979
980 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
981 tcp->data_payload_max))
982 return -ENOBUFS;
983
984 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
985 return -ENOBUFS;
986
987 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
988 sizeof(*tcp->tok), tcp->tok))
989 return -ENOBUFS;
990
991 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
992 tcp->data_interval_max))
993 return -ENOBUFS;
994
995 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
996 tcp->wake_payload_max))
997 return -ENOBUFS;
998
999 nla_nest_end(msg, nl_tcp);
1000 return 0;
1001}
1002
3713b4e3 1003static int nl80211_send_wowlan(struct sk_buff *msg,
b56cf720
JB
1004 struct cfg80211_registered_device *dev,
1005 bool large)
55682965 1006{
3713b4e3 1007 struct nlattr *nl_wowlan;
55682965 1008
964dc9e2 1009 if (!dev->wiphy.wowlan)
3713b4e3 1010 return 0;
55682965 1011
3713b4e3
JB
1012 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1013 if (!nl_wowlan)
1014 return -ENOBUFS;
9360ffd1 1015
964dc9e2 1016 if (((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 1017 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
964dc9e2 1018 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 1019 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
964dc9e2 1020 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 1021 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
964dc9e2 1022 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 1023 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
964dc9e2 1024 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 1025 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
964dc9e2 1026 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 1027 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
964dc9e2 1028 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 1029 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
964dc9e2 1030 ((dev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
1031 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1032 return -ENOBUFS;
9360ffd1 1033
964dc9e2 1034 if (dev->wiphy.wowlan->n_patterns) {
50ac6607 1035 struct nl80211_pattern_support pat = {
964dc9e2
JB
1036 .max_patterns = dev->wiphy.wowlan->n_patterns,
1037 .min_pattern_len = dev->wiphy.wowlan->pattern_min_len,
1038 .max_pattern_len = dev->wiphy.wowlan->pattern_max_len,
1039 .max_pkt_offset = dev->wiphy.wowlan->max_pkt_offset,
3713b4e3 1040 };
9360ffd1 1041
3713b4e3
JB
1042 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1043 sizeof(pat), &pat))
1044 return -ENOBUFS;
1045 }
9360ffd1 1046
b56cf720
JB
1047 if (large && nl80211_send_wowlan_tcp_caps(dev, msg))
1048 return -ENOBUFS;
1049
3713b4e3 1050 nla_nest_end(msg, nl_wowlan);
9360ffd1 1051
3713b4e3
JB
1052 return 0;
1053}
1054#endif
9360ffd1 1055
be29b99a
AK
1056static int nl80211_send_coalesce(struct sk_buff *msg,
1057 struct cfg80211_registered_device *dev)
1058{
1059 struct nl80211_coalesce_rule_support rule;
1060
1061 if (!dev->wiphy.coalesce)
1062 return 0;
1063
1064 rule.max_rules = dev->wiphy.coalesce->n_rules;
1065 rule.max_delay = dev->wiphy.coalesce->max_delay;
1066 rule.pat.max_patterns = dev->wiphy.coalesce->n_patterns;
1067 rule.pat.min_pattern_len = dev->wiphy.coalesce->pattern_min_len;
1068 rule.pat.max_pattern_len = dev->wiphy.coalesce->pattern_max_len;
1069 rule.pat.max_pkt_offset = dev->wiphy.coalesce->max_pkt_offset;
1070
1071 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1072 return -ENOBUFS;
1073
1074 return 0;
1075}
1076
3713b4e3
JB
1077static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1078 struct ieee80211_supported_band *sband)
1079{
1080 struct nlattr *nl_rates, *nl_rate;
1081 struct ieee80211_rate *rate;
1082 int i;
87bbbe22 1083
3713b4e3
JB
1084 /* add HT info */
1085 if (sband->ht_cap.ht_supported &&
1086 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1087 sizeof(sband->ht_cap.mcs),
1088 &sband->ht_cap.mcs) ||
1089 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1090 sband->ht_cap.cap) ||
1091 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1092 sband->ht_cap.ampdu_factor) ||
1093 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1094 sband->ht_cap.ampdu_density)))
1095 return -ENOBUFS;
afe0cbf8 1096
3713b4e3
JB
1097 /* add VHT info */
1098 if (sband->vht_cap.vht_supported &&
1099 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1100 sizeof(sband->vht_cap.vht_mcs),
1101 &sband->vht_cap.vht_mcs) ||
1102 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1103 sband->vht_cap.cap)))
1104 return -ENOBUFS;
f59ac048 1105
3713b4e3
JB
1106 /* add bitrates */
1107 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1108 if (!nl_rates)
1109 return -ENOBUFS;
ee688b00 1110
3713b4e3
JB
1111 for (i = 0; i < sband->n_bitrates; i++) {
1112 nl_rate = nla_nest_start(msg, i);
1113 if (!nl_rate)
1114 return -ENOBUFS;
ee688b00 1115
3713b4e3
JB
1116 rate = &sband->bitrates[i];
1117 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1118 rate->bitrate))
1119 return -ENOBUFS;
1120 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1121 nla_put_flag(msg,
1122 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1123 return -ENOBUFS;
ee688b00 1124
3713b4e3
JB
1125 nla_nest_end(msg, nl_rate);
1126 }
d51626df 1127
3713b4e3 1128 nla_nest_end(msg, nl_rates);
bf0c111e 1129
3713b4e3
JB
1130 return 0;
1131}
ee688b00 1132
3713b4e3
JB
1133static int
1134nl80211_send_mgmt_stypes(struct sk_buff *msg,
1135 const struct ieee80211_txrx_stypes *mgmt_stypes)
1136{
1137 u16 stypes;
1138 struct nlattr *nl_ftypes, *nl_ifs;
1139 enum nl80211_iftype ift;
1140 int i;
ee688b00 1141
3713b4e3
JB
1142 if (!mgmt_stypes)
1143 return 0;
5dab3b8a 1144
3713b4e3
JB
1145 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1146 if (!nl_ifs)
1147 return -ENOBUFS;
e2f367f2 1148
3713b4e3
JB
1149 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1150 nl_ftypes = nla_nest_start(msg, ift);
1151 if (!nl_ftypes)
1152 return -ENOBUFS;
1153 i = 0;
1154 stypes = mgmt_stypes[ift].tx;
1155 while (stypes) {
1156 if ((stypes & 1) &&
1157 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1158 (i << 4) | IEEE80211_FTYPE_MGMT))
1159 return -ENOBUFS;
1160 stypes >>= 1;
1161 i++;
ee688b00 1162 }
3713b4e3
JB
1163 nla_nest_end(msg, nl_ftypes);
1164 }
ee688b00 1165
3713b4e3 1166 nla_nest_end(msg, nl_ifs);
ee688b00 1167
3713b4e3
JB
1168 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1169 if (!nl_ifs)
1170 return -ENOBUFS;
ee688b00 1171
3713b4e3
JB
1172 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1173 nl_ftypes = nla_nest_start(msg, ift);
1174 if (!nl_ftypes)
1175 return -ENOBUFS;
1176 i = 0;
1177 stypes = mgmt_stypes[ift].rx;
1178 while (stypes) {
1179 if ((stypes & 1) &&
1180 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1181 (i << 4) | IEEE80211_FTYPE_MGMT))
1182 return -ENOBUFS;
1183 stypes >>= 1;
1184 i++;
1185 }
1186 nla_nest_end(msg, nl_ftypes);
1187 }
1188 nla_nest_end(msg, nl_ifs);
ee688b00 1189
3713b4e3
JB
1190 return 0;
1191}
ee688b00 1192
86e8cf98
JB
1193struct nl80211_dump_wiphy_state {
1194 s64 filter_wiphy;
1195 long start;
1196 long split_start, band_start, chan_start;
1197 bool split;
1198};
1199
3713b4e3
JB
1200static int nl80211_send_wiphy(struct cfg80211_registered_device *dev,
1201 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 1202 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
1203{
1204 void *hdr;
1205 struct nlattr *nl_bands, *nl_band;
1206 struct nlattr *nl_freqs, *nl_freq;
1207 struct nlattr *nl_cmds;
1208 enum ieee80211_band band;
1209 struct ieee80211_channel *chan;
1210 int i;
1211 const struct ieee80211_txrx_stypes *mgmt_stypes =
1212 dev->wiphy.mgmt_stypes;
fe1abafd 1213 u32 features;
ee688b00 1214
3713b4e3
JB
1215 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
1216 if (!hdr)
1217 return -ENOBUFS;
ee688b00 1218
86e8cf98
JB
1219 if (WARN_ON(!state))
1220 return -EINVAL;
ee688b00 1221
3713b4e3
JB
1222 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
1223 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1224 wiphy_name(&dev->wiphy)) ||
1225 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1226 cfg80211_rdev_list_generation))
8fdc621d
JB
1227 goto nla_put_failure;
1228
86e8cf98 1229 switch (state->split_start) {
3713b4e3
JB
1230 case 0:
1231 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1232 dev->wiphy.retry_short) ||
1233 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1234 dev->wiphy.retry_long) ||
1235 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1236 dev->wiphy.frag_threshold) ||
1237 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1238 dev->wiphy.rts_threshold) ||
1239 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1240 dev->wiphy.coverage_class) ||
1241 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1242 dev->wiphy.max_scan_ssids) ||
1243 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1244 dev->wiphy.max_sched_scan_ssids) ||
1245 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1246 dev->wiphy.max_scan_ie_len) ||
1247 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1248 dev->wiphy.max_sched_scan_ie_len) ||
1249 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
1250 dev->wiphy.max_match_sets))
9360ffd1 1251 goto nla_put_failure;
3713b4e3
JB
1252
1253 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
1254 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1255 goto nla_put_failure;
3713b4e3
JB
1256 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
1257 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1258 goto nla_put_failure;
1259 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
1260 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1261 goto nla_put_failure;
1262 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
1263 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1264 goto nla_put_failure;
1265 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
1266 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1267 goto nla_put_failure;
1268 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
1269 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1270 goto nla_put_failure;
86e8cf98
JB
1271 state->split_start++;
1272 if (state->split)
3713b4e3
JB
1273 break;
1274 case 1:
1275 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1276 sizeof(u32) * dev->wiphy.n_cipher_suites,
1277 dev->wiphy.cipher_suites))
1278 goto nla_put_failure;
4745fc09 1279
3713b4e3
JB
1280 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1281 dev->wiphy.max_num_pmkids))
1282 goto nla_put_failure;
b23aa676 1283
3713b4e3
JB
1284 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
1285 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1286 goto nla_put_failure;
b23aa676 1287
3713b4e3
JB
1288 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1289 dev->wiphy.available_antennas_tx) ||
1290 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1291 dev->wiphy.available_antennas_rx))
9360ffd1 1292 goto nla_put_failure;
b23aa676 1293
3713b4e3
JB
1294 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
1295 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1296 dev->wiphy.probe_resp_offload))
1297 goto nla_put_failure;
8fdc621d 1298
3713b4e3
JB
1299 if ((dev->wiphy.available_antennas_tx ||
1300 dev->wiphy.available_antennas_rx) &&
1301 dev->ops->get_antenna) {
1302 u32 tx_ant = 0, rx_ant = 0;
1303 int res;
1304 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
1305 if (!res) {
1306 if (nla_put_u32(msg,
1307 NL80211_ATTR_WIPHY_ANTENNA_TX,
1308 tx_ant) ||
1309 nla_put_u32(msg,
1310 NL80211_ATTR_WIPHY_ANTENNA_RX,
1311 rx_ant))
1312 goto nla_put_failure;
1313 }
1314 }
a293911d 1315
86e8cf98
JB
1316 state->split_start++;
1317 if (state->split)
3713b4e3
JB
1318 break;
1319 case 2:
1320 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1321 dev->wiphy.interface_modes))
1322 goto nla_put_failure;
86e8cf98
JB
1323 state->split_start++;
1324 if (state->split)
3713b4e3
JB
1325 break;
1326 case 3:
1327 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1328 if (!nl_bands)
1329 goto nla_put_failure;
f7ca38df 1330
86e8cf98
JB
1331 for (band = state->band_start;
1332 band < IEEE80211_NUM_BANDS; band++) {
3713b4e3 1333 struct ieee80211_supported_band *sband;
2e161f78 1334
3713b4e3 1335 sband = dev->wiphy.bands[band];
2e161f78 1336
3713b4e3
JB
1337 if (!sband)
1338 continue;
1339
1340 nl_band = nla_nest_start(msg, band);
1341 if (!nl_band)
2e161f78 1342 goto nla_put_failure;
3713b4e3 1343
86e8cf98 1344 switch (state->chan_start) {
3713b4e3
JB
1345 case 0:
1346 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 1347 goto nla_put_failure;
86e8cf98
JB
1348 state->chan_start++;
1349 if (state->split)
3713b4e3
JB
1350 break;
1351 default:
1352 /* add frequencies */
1353 nl_freqs = nla_nest_start(
1354 msg, NL80211_BAND_ATTR_FREQS);
1355 if (!nl_freqs)
1356 goto nla_put_failure;
1357
86e8cf98 1358 for (i = state->chan_start - 1;
3713b4e3
JB
1359 i < sband->n_channels;
1360 i++) {
1361 nl_freq = nla_nest_start(msg, i);
1362 if (!nl_freq)
1363 goto nla_put_failure;
1364
1365 chan = &sband->channels[i];
1366
86e8cf98
JB
1367 if (nl80211_msg_put_channel(
1368 msg, chan,
1369 state->split))
3713b4e3
JB
1370 goto nla_put_failure;
1371
1372 nla_nest_end(msg, nl_freq);
86e8cf98 1373 if (state->split)
3713b4e3
JB
1374 break;
1375 }
1376 if (i < sband->n_channels)
86e8cf98 1377 state->chan_start = i + 2;
3713b4e3 1378 else
86e8cf98 1379 state->chan_start = 0;
3713b4e3
JB
1380 nla_nest_end(msg, nl_freqs);
1381 }
1382
1383 nla_nest_end(msg, nl_band);
1384
86e8cf98 1385 if (state->split) {
3713b4e3 1386 /* start again here */
86e8cf98 1387 if (state->chan_start)
3713b4e3
JB
1388 band--;
1389 break;
2e161f78 1390 }
2e161f78 1391 }
3713b4e3 1392 nla_nest_end(msg, nl_bands);
2e161f78 1393
3713b4e3 1394 if (band < IEEE80211_NUM_BANDS)
86e8cf98 1395 state->band_start = band + 1;
3713b4e3 1396 else
86e8cf98 1397 state->band_start = 0;
74b70a4e 1398
3713b4e3 1399 /* if bands & channels are done, continue outside */
86e8cf98
JB
1400 if (state->band_start == 0 && state->chan_start == 0)
1401 state->split_start++;
1402 if (state->split)
3713b4e3
JB
1403 break;
1404 case 4:
1405 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1406 if (!nl_cmds)
2e161f78
JB
1407 goto nla_put_failure;
1408
3713b4e3
JB
1409 i = 0;
1410#define CMD(op, n) \
1411 do { \
1412 if (dev->ops->op) { \
1413 i++; \
1414 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1415 goto nla_put_failure; \
1416 } \
1417 } while (0)
1418
1419 CMD(add_virtual_intf, NEW_INTERFACE);
1420 CMD(change_virtual_intf, SET_INTERFACE);
1421 CMD(add_key, NEW_KEY);
1422 CMD(start_ap, START_AP);
1423 CMD(add_station, NEW_STATION);
1424 CMD(add_mpath, NEW_MPATH);
1425 CMD(update_mesh_config, SET_MESH_CONFIG);
1426 CMD(change_bss, SET_BSS);
1427 CMD(auth, AUTHENTICATE);
1428 CMD(assoc, ASSOCIATE);
1429 CMD(deauth, DEAUTHENTICATE);
1430 CMD(disassoc, DISASSOCIATE);
1431 CMD(join_ibss, JOIN_IBSS);
1432 CMD(join_mesh, JOIN_MESH);
1433 CMD(set_pmksa, SET_PMKSA);
1434 CMD(del_pmksa, DEL_PMKSA);
1435 CMD(flush_pmksa, FLUSH_PMKSA);
1436 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1437 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1438 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1439 CMD(mgmt_tx, FRAME);
1440 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1441 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1442 i++;
1443 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
2e161f78 1444 goto nla_put_failure;
2e161f78 1445 }
3713b4e3
JB
1446 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
1447 dev->ops->join_mesh) {
1448 i++;
1449 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1450 goto nla_put_failure;
1451 }
1452 CMD(set_wds_peer, SET_WDS_PEER);
1453 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1454 CMD(tdls_mgmt, TDLS_MGMT);
1455 CMD(tdls_oper, TDLS_OPER);
1456 }
1457 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1458 CMD(sched_scan_start, START_SCHED_SCAN);
1459 CMD(probe_client, PROBE_CLIENT);
1460 CMD(set_noack_map, SET_NOACK_MAP);
1461 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1462 i++;
1463 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1464 goto nla_put_failure;
1465 }
1466 CMD(start_p2p_device, START_P2P_DEVICE);
1467 CMD(set_mcast_rate, SET_MCAST_RATE);
86e8cf98 1468 if (state->split) {
5de17984
AS
1469 CMD(crit_proto_start, CRIT_PROTOCOL_START);
1470 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
16ef1fe2
SW
1471 if (dev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
1472 CMD(channel_switch, CHANNEL_SWITCH);
5de17984 1473 }
fa9ffc74 1474 CMD(set_qos_map, SET_QOS_MAP);
2e161f78 1475
3713b4e3
JB
1476#ifdef CONFIG_NL80211_TESTMODE
1477 CMD(testmode_cmd, TESTMODE);
1478#endif
ff1b6e69 1479
3713b4e3 1480#undef CMD
ff1b6e69 1481
3713b4e3
JB
1482 if (dev->ops->connect || dev->ops->auth) {
1483 i++;
1484 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
9360ffd1 1485 goto nla_put_failure;
ff1b6e69
JB
1486 }
1487
3713b4e3
JB
1488 if (dev->ops->disconnect || dev->ops->deauth) {
1489 i++;
1490 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1491 goto nla_put_failure;
1492 }
1493
1494 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
1495 state->split_start++;
1496 if (state->split)
3713b4e3
JB
1497 break;
1498 case 5:
1499 if (dev->ops->remain_on_channel &&
1500 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1501 nla_put_u32(msg,
1502 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1503 dev->wiphy.max_remain_on_channel_duration))
1504 goto nla_put_failure;
1505
1506 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1507 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1508 goto nla_put_failure;
1509
1510 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
1511 goto nla_put_failure;
86e8cf98
JB
1512 state->split_start++;
1513 if (state->split)
3713b4e3
JB
1514 break;
1515 case 6:
1516#ifdef CONFIG_PM
86e8cf98 1517 if (nl80211_send_wowlan(msg, dev, state->split))
3713b4e3 1518 goto nla_put_failure;
86e8cf98
JB
1519 state->split_start++;
1520 if (state->split)
3713b4e3
JB
1521 break;
1522#else
86e8cf98 1523 state->split_start++;
dfb89c56 1524#endif
3713b4e3
JB
1525 case 7:
1526 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1527 dev->wiphy.software_iftypes))
1528 goto nla_put_failure;
ff1b6e69 1529
86e8cf98
JB
1530 if (nl80211_put_iface_combinations(&dev->wiphy, msg,
1531 state->split))
3713b4e3 1532 goto nla_put_failure;
7527a782 1533
86e8cf98
JB
1534 state->split_start++;
1535 if (state->split)
3713b4e3
JB
1536 break;
1537 case 8:
1538 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1539 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1540 dev->wiphy.ap_sme_capa))
1541 goto nla_put_failure;
7527a782 1542
fe1abafd
JB
1543 features = dev->wiphy.features;
1544 /*
1545 * We can only add the per-channel limit information if the
1546 * dump is split, otherwise it makes it too big. Therefore
1547 * only advertise it in that case.
1548 */
86e8cf98 1549 if (state->split)
fe1abafd
JB
1550 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
1551 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 1552 goto nla_put_failure;
562a7480 1553
3713b4e3
JB
1554 if (dev->wiphy.ht_capa_mod_mask &&
1555 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1556 sizeof(*dev->wiphy.ht_capa_mod_mask),
1557 dev->wiphy.ht_capa_mod_mask))
1558 goto nla_put_failure;
1f074bd8 1559
3713b4e3
JB
1560 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1561 dev->wiphy.max_acl_mac_addrs &&
1562 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1563 dev->wiphy.max_acl_mac_addrs))
1564 goto nla_put_failure;
7e7c8926 1565
3713b4e3
JB
1566 /*
1567 * Any information below this point is only available to
1568 * applications that can deal with it being split. This
1569 * helps ensure that newly added capabilities don't break
1570 * older tools by overrunning their buffers.
1571 *
1572 * We still increment split_start so that in the split
1573 * case we'll continue with more data in the next round,
1574 * but break unconditionally so unsplit data stops here.
1575 */
86e8cf98 1576 state->split_start++;
3713b4e3
JB
1577 break;
1578 case 9:
fe1abafd
JB
1579 if (dev->wiphy.extended_capabilities &&
1580 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1581 dev->wiphy.extended_capabilities_len,
1582 dev->wiphy.extended_capabilities) ||
1583 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1584 dev->wiphy.extended_capabilities_len,
1585 dev->wiphy.extended_capabilities_mask)))
1586 goto nla_put_failure;
a50df0c4 1587
ee2aca34
JB
1588 if (dev->wiphy.vht_capa_mod_mask &&
1589 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1590 sizeof(*dev->wiphy.vht_capa_mod_mask),
1591 dev->wiphy.vht_capa_mod_mask))
1592 goto nla_put_failure;
1593
be29b99a
AK
1594 state->split_start++;
1595 break;
1596 case 10:
1597 if (nl80211_send_coalesce(msg, dev))
1598 goto nla_put_failure;
1599
01e0daa4
FF
1600 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
1601 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
1602 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
1603 goto nla_put_failure;
b43504cf
JM
1604
1605 if (dev->wiphy.max_ap_assoc_sta &&
1606 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
1607 dev->wiphy.max_ap_assoc_sta))
1608 goto nla_put_failure;
1609
ad7e718c
JB
1610 state->split_start++;
1611 break;
1612 case 11:
567ffc35
JB
1613 if (dev->wiphy.n_vendor_commands) {
1614 const struct nl80211_vendor_cmd_info *info;
1615 struct nlattr *nested;
1616
1617 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA);
1618 if (!nested)
1619 goto nla_put_failure;
1620
1621 for (i = 0; i < dev->wiphy.n_vendor_commands; i++) {
1622 info = &dev->wiphy.vendor_commands[i].info;
1623 if (nla_put(msg, i + 1, sizeof(*info), info))
1624 goto nla_put_failure;
1625 }
1626 nla_nest_end(msg, nested);
1627 }
1628
1629 if (dev->wiphy.n_vendor_events) {
1630 const struct nl80211_vendor_cmd_info *info;
1631 struct nlattr *nested;
ad7e718c 1632
567ffc35
JB
1633 nested = nla_nest_start(msg,
1634 NL80211_ATTR_VENDOR_EVENTS);
1635 if (!nested)
ad7e718c 1636 goto nla_put_failure;
567ffc35
JB
1637
1638 for (i = 0; i < dev->wiphy.n_vendor_events; i++) {
1639 info = &dev->wiphy.vendor_events[i];
1640 if (nla_put(msg, i + 1, sizeof(*info), info))
1641 goto nla_put_failure;
1642 }
1643 nla_nest_end(msg, nested);
1644 }
01e0daa4 1645
3713b4e3 1646 /* done */
86e8cf98 1647 state->split_start = 0;
3713b4e3
JB
1648 break;
1649 }
55682965
JB
1650 return genlmsg_end(msg, hdr);
1651
1652 nla_put_failure:
bc3ed28c
TG
1653 genlmsg_cancel(msg, hdr);
1654 return -EMSGSIZE;
55682965
JB
1655}
1656
86e8cf98
JB
1657static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
1658 struct netlink_callback *cb,
1659 struct nl80211_dump_wiphy_state *state)
1660{
1661 struct nlattr **tb = nl80211_fam.attrbuf;
1662 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1663 tb, nl80211_fam.maxattr, nl80211_policy);
1664 /* ignore parse errors for backward compatibility */
1665 if (ret)
1666 return 0;
1667
1668 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
1669 if (tb[NL80211_ATTR_WIPHY])
1670 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
1671 if (tb[NL80211_ATTR_WDEV])
1672 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
1673 if (tb[NL80211_ATTR_IFINDEX]) {
1674 struct net_device *netdev;
1675 struct cfg80211_registered_device *rdev;
1676 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
1677
7f2b8562 1678 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
86e8cf98
JB
1679 if (!netdev)
1680 return -ENODEV;
1681 if (netdev->ieee80211_ptr) {
1682 rdev = wiphy_to_dev(
1683 netdev->ieee80211_ptr->wiphy);
1684 state->filter_wiphy = rdev->wiphy_idx;
1685 }
86e8cf98
JB
1686 }
1687
1688 return 0;
1689}
1690
55682965
JB
1691static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1692{
645e77de 1693 int idx = 0, ret;
86e8cf98 1694 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
55682965 1695 struct cfg80211_registered_device *dev;
3a5a423b 1696
5fe231e8 1697 rtnl_lock();
86e8cf98
JB
1698 if (!state) {
1699 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
1700 if (!state) {
1701 rtnl_unlock();
86e8cf98 1702 return -ENOMEM;
3713b4e3 1703 }
86e8cf98
JB
1704 state->filter_wiphy = -1;
1705 ret = nl80211_dump_wiphy_parse(skb, cb, state);
1706 if (ret) {
1707 kfree(state);
1708 rtnl_unlock();
1709 return ret;
3713b4e3 1710 }
86e8cf98 1711 cb->args[0] = (long)state;
3713b4e3
JB
1712 }
1713
79c97e97 1714 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1715 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1716 continue;
86e8cf98 1717 if (++idx <= state->start)
55682965 1718 continue;
86e8cf98
JB
1719 if (state->filter_wiphy != -1 &&
1720 state->filter_wiphy != dev->wiphy_idx)
3713b4e3
JB
1721 continue;
1722 /* attempt to fit multiple wiphy data chunks into the skb */
1723 do {
1724 ret = nl80211_send_wiphy(dev, skb,
1725 NETLINK_CB(cb->skb).portid,
1726 cb->nlh->nlmsg_seq,
86e8cf98 1727 NLM_F_MULTI, state);
3713b4e3
JB
1728 if (ret < 0) {
1729 /*
1730 * If sending the wiphy data didn't fit (ENOBUFS
1731 * or EMSGSIZE returned), this SKB is still
1732 * empty (so it's not too big because another
1733 * wiphy dataset is already in the skb) and
1734 * we've not tried to adjust the dump allocation
1735 * yet ... then adjust the alloc size to be
1736 * bigger, and return 1 but with the empty skb.
1737 * This results in an empty message being RX'ed
1738 * in userspace, but that is ignored.
1739 *
1740 * We can then retry with the larger buffer.
1741 */
1742 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
1743 !skb->len &&
1744 cb->min_dump_alloc < 4096) {
1745 cb->min_dump_alloc = 4096;
d98cae64 1746 rtnl_unlock();
3713b4e3
JB
1747 return 1;
1748 }
1749 idx--;
1750 break;
645e77de 1751 }
86e8cf98 1752 } while (state->split_start > 0);
3713b4e3 1753 break;
55682965 1754 }
5fe231e8 1755 rtnl_unlock();
55682965 1756
86e8cf98 1757 state->start = idx;
55682965
JB
1758
1759 return skb->len;
1760}
1761
86e8cf98
JB
1762static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
1763{
1764 kfree((void *)cb->args[0]);
1765 return 0;
1766}
1767
55682965
JB
1768static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1769{
1770 struct sk_buff *msg;
4c476991 1771 struct cfg80211_registered_device *dev = info->user_ptr[0];
86e8cf98 1772 struct nl80211_dump_wiphy_state state = {};
55682965 1773
645e77de 1774 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 1775 if (!msg)
4c476991 1776 return -ENOMEM;
55682965 1777
3713b4e3 1778 if (nl80211_send_wiphy(dev, msg, info->snd_portid, info->snd_seq, 0,
86e8cf98 1779 &state) < 0) {
4c476991
JB
1780 nlmsg_free(msg);
1781 return -ENOBUFS;
1782 }
55682965 1783
134e6375 1784 return genlmsg_reply(msg, info);
55682965
JB
1785}
1786
31888487
JM
1787static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1788 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1789 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1790 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1791 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1792 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1793};
1794
1795static int parse_txq_params(struct nlattr *tb[],
1796 struct ieee80211_txq_params *txq_params)
1797{
a3304b0a 1798 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1799 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1800 !tb[NL80211_TXQ_ATTR_AIFS])
1801 return -EINVAL;
1802
a3304b0a 1803 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1804 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1805 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1806 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1807 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1808
a3304b0a
JB
1809 if (txq_params->ac >= NL80211_NUM_ACS)
1810 return -EINVAL;
1811
31888487
JM
1812 return 0;
1813}
1814
f444de05
JB
1815static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1816{
1817 /*
cc1d2806
JB
1818 * You can only set the channel explicitly for WDS interfaces,
1819 * all others have their channel managed via their respective
1820 * "establish a connection" command (connect, join, ...)
1821 *
1822 * For AP/GO and mesh mode, the channel can be set with the
1823 * channel userspace API, but is only stored and passed to the
1824 * low-level driver when the AP starts or the mesh is joined.
1825 * This is for backward compatibility, userspace can also give
1826 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1827 *
1828 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1829 * whatever else is going on, so they have their own special
1830 * operation to set the monitor channel if possible.
f444de05
JB
1831 */
1832 return !wdev ||
1833 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1834 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1835 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1836 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1837}
1838
683b6d3b
JB
1839static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1840 struct genl_info *info,
1841 struct cfg80211_chan_def *chandef)
1842{
dbeca2ea 1843 u32 control_freq;
683b6d3b
JB
1844
1845 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1846 return -EINVAL;
1847
1848 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1849
1850 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1851 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1852 chandef->center_freq1 = control_freq;
1853 chandef->center_freq2 = 0;
683b6d3b
JB
1854
1855 /* Primary channel not allowed */
1856 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1857 return -EINVAL;
1858
3d9d1d66
JB
1859 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1860 enum nl80211_channel_type chantype;
1861
1862 chantype = nla_get_u32(
1863 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1864
1865 switch (chantype) {
1866 case NL80211_CHAN_NO_HT:
1867 case NL80211_CHAN_HT20:
1868 case NL80211_CHAN_HT40PLUS:
1869 case NL80211_CHAN_HT40MINUS:
1870 cfg80211_chandef_create(chandef, chandef->chan,
1871 chantype);
1872 break;
1873 default:
1874 return -EINVAL;
1875 }
1876 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1877 chandef->width =
1878 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1879 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1880 chandef->center_freq1 =
1881 nla_get_u32(
1882 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1883 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1884 chandef->center_freq2 =
1885 nla_get_u32(
1886 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1887 }
1888
9f5e8f6e 1889 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1890 return -EINVAL;
1891
9f5e8f6e
JB
1892 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1893 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1894 return -EINVAL;
1895
2f301ab2
SW
1896 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
1897 chandef->width == NL80211_CHAN_WIDTH_10) &&
1898 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ))
1899 return -EINVAL;
1900
683b6d3b
JB
1901 return 0;
1902}
1903
f444de05
JB
1904static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1905 struct wireless_dev *wdev,
1906 struct genl_info *info)
1907{
683b6d3b 1908 struct cfg80211_chan_def chandef;
f444de05 1909 int result;
e8c9bd5b
JB
1910 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1911
1912 if (wdev)
1913 iftype = wdev->iftype;
f444de05 1914
f444de05
JB
1915 if (!nl80211_can_set_dev_channel(wdev))
1916 return -EOPNOTSUPP;
1917
683b6d3b
JB
1918 result = nl80211_parse_chandef(rdev, info, &chandef);
1919 if (result)
1920 return result;
f444de05 1921
e8c9bd5b 1922 switch (iftype) {
aa430da4
JB
1923 case NL80211_IFTYPE_AP:
1924 case NL80211_IFTYPE_P2P_GO:
1925 if (wdev->beacon_interval) {
1926 result = -EBUSY;
1927 break;
1928 }
683b6d3b 1929 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1930 result = -EINVAL;
1931 break;
1932 }
683b6d3b 1933 wdev->preset_chandef = chandef;
aa430da4
JB
1934 result = 0;
1935 break;
cc1d2806 1936 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1937 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1938 break;
e8c9bd5b 1939 case NL80211_IFTYPE_MONITOR:
683b6d3b 1940 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1941 break;
aa430da4 1942 default:
e8c9bd5b 1943 result = -EINVAL;
f444de05 1944 }
f444de05
JB
1945
1946 return result;
1947}
1948
1949static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1950{
4c476991
JB
1951 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1952 struct net_device *netdev = info->user_ptr[1];
f444de05 1953
4c476991 1954 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1955}
1956
e8347eba
BJ
1957static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1958{
43b19952
JB
1959 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1960 struct net_device *dev = info->user_ptr[1];
1961 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1962 const u8 *bssid;
e8347eba
BJ
1963
1964 if (!info->attrs[NL80211_ATTR_MAC])
1965 return -EINVAL;
1966
43b19952
JB
1967 if (netif_running(dev))
1968 return -EBUSY;
e8347eba 1969
43b19952
JB
1970 if (!rdev->ops->set_wds_peer)
1971 return -EOPNOTSUPP;
e8347eba 1972
43b19952
JB
1973 if (wdev->iftype != NL80211_IFTYPE_WDS)
1974 return -EOPNOTSUPP;
e8347eba
BJ
1975
1976 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1977 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1978}
1979
1980
55682965
JB
1981static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1982{
1983 struct cfg80211_registered_device *rdev;
f444de05
JB
1984 struct net_device *netdev = NULL;
1985 struct wireless_dev *wdev;
a1e567c8 1986 int result = 0, rem_txq_params = 0;
31888487 1987 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1988 u32 changed;
1989 u8 retry_short = 0, retry_long = 0;
1990 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1991 u8 coverage_class = 0;
55682965 1992
5fe231e8
JB
1993 ASSERT_RTNL();
1994
f444de05
JB
1995 /*
1996 * Try to find the wiphy and netdev. Normally this
1997 * function shouldn't need the netdev, but this is
1998 * done for backward compatibility -- previously
1999 * setting the channel was done per wiphy, but now
2000 * it is per netdev. Previous userland like hostapd
2001 * also passed a netdev to set_wiphy, so that it is
2002 * possible to let that go to the right netdev!
2003 */
4bbf4d56 2004
f444de05
JB
2005 if (info->attrs[NL80211_ATTR_IFINDEX]) {
2006 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
2007
7f2b8562 2008 netdev = __dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 2009 if (netdev && netdev->ieee80211_ptr)
f444de05 2010 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
5fe231e8 2011 else
f444de05 2012 netdev = NULL;
4bbf4d56
JB
2013 }
2014
f444de05 2015 if (!netdev) {
878d9ec7
JB
2016 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
2017 info->attrs);
5fe231e8 2018 if (IS_ERR(rdev))
4c476991 2019 return PTR_ERR(rdev);
f444de05
JB
2020 wdev = NULL;
2021 netdev = NULL;
2022 result = 0;
71fe96bf 2023 } else
f444de05 2024 wdev = netdev->ieee80211_ptr;
f444de05
JB
2025
2026 /*
2027 * end workaround code, by now the rdev is available
2028 * and locked, and wdev may or may not be NULL.
2029 */
4bbf4d56
JB
2030
2031 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
2032 result = cfg80211_dev_rename(
2033 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 2034
4bbf4d56 2035 if (result)
7f2b8562 2036 return result;
31888487
JM
2037
2038 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
2039 struct ieee80211_txq_params txq_params;
2040 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
2041
7f2b8562
YX
2042 if (!rdev->ops->set_txq_params)
2043 return -EOPNOTSUPP;
31888487 2044
7f2b8562
YX
2045 if (!netdev)
2046 return -EINVAL;
f70f01c2 2047
133a3ff2 2048 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7f2b8562
YX
2049 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2050 return -EINVAL;
133a3ff2 2051
7f2b8562
YX
2052 if (!netif_running(netdev))
2053 return -ENETDOWN;
2b5f8b0b 2054
31888487
JM
2055 nla_for_each_nested(nl_txq_params,
2056 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
2057 rem_txq_params) {
2058 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
2059 nla_data(nl_txq_params),
2060 nla_len(nl_txq_params),
2061 txq_params_policy);
2062 result = parse_txq_params(tb, &txq_params);
2063 if (result)
7f2b8562 2064 return result;
31888487 2065
e35e4d28
HG
2066 result = rdev_set_txq_params(rdev, netdev,
2067 &txq_params);
31888487 2068 if (result)
7f2b8562 2069 return result;
31888487
JM
2070 }
2071 }
55682965 2072
72bdcf34 2073 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
2074 result = __nl80211_set_channel(rdev,
2075 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
2076 info);
72bdcf34 2077 if (result)
7f2b8562 2078 return result;
72bdcf34
JM
2079 }
2080
98d2ff8b 2081 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 2082 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
2083 enum nl80211_tx_power_setting type;
2084 int idx, mbm = 0;
2085
c8442118
JB
2086 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
2087 txp_wdev = NULL;
2088
7f2b8562
YX
2089 if (!rdev->ops->set_tx_power)
2090 return -EOPNOTSUPP;
98d2ff8b
JO
2091
2092 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
2093 type = nla_get_u32(info->attrs[idx]);
2094
2095 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
7f2b8562
YX
2096 (type != NL80211_TX_POWER_AUTOMATIC))
2097 return -EINVAL;
98d2ff8b
JO
2098
2099 if (type != NL80211_TX_POWER_AUTOMATIC) {
2100 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
2101 mbm = nla_get_u32(info->attrs[idx]);
2102 }
2103
c8442118 2104 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b 2105 if (result)
7f2b8562 2106 return result;
98d2ff8b
JO
2107 }
2108
afe0cbf8
BR
2109 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
2110 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
2111 u32 tx_ant, rx_ant;
7f531e03
BR
2112 if ((!rdev->wiphy.available_antennas_tx &&
2113 !rdev->wiphy.available_antennas_rx) ||
7f2b8562
YX
2114 !rdev->ops->set_antenna)
2115 return -EOPNOTSUPP;
afe0cbf8
BR
2116
2117 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
2118 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
2119
a7ffac95 2120 /* reject antenna configurations which don't match the
7f531e03
BR
2121 * available antenna masks, except for the "all" mask */
2122 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
7f2b8562
YX
2123 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx)))
2124 return -EINVAL;
a7ffac95 2125
7f531e03
BR
2126 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
2127 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 2128
e35e4d28 2129 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8 2130 if (result)
7f2b8562 2131 return result;
afe0cbf8
BR
2132 }
2133
b9a5f8ca
JM
2134 changed = 0;
2135
2136 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
2137 retry_short = nla_get_u8(
2138 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
7f2b8562
YX
2139 if (retry_short == 0)
2140 return -EINVAL;
2141
b9a5f8ca
JM
2142 changed |= WIPHY_PARAM_RETRY_SHORT;
2143 }
2144
2145 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2146 retry_long = nla_get_u8(
2147 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
7f2b8562
YX
2148 if (retry_long == 0)
2149 return -EINVAL;
2150
b9a5f8ca
JM
2151 changed |= WIPHY_PARAM_RETRY_LONG;
2152 }
2153
2154 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2155 frag_threshold = nla_get_u32(
2156 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
7f2b8562
YX
2157 if (frag_threshold < 256)
2158 return -EINVAL;
2159
b9a5f8ca
JM
2160 if (frag_threshold != (u32) -1) {
2161 /*
2162 * Fragments (apart from the last one) are required to
2163 * have even length. Make the fragmentation code
2164 * simpler by stripping LSB should someone try to use
2165 * odd threshold value.
2166 */
2167 frag_threshold &= ~0x1;
2168 }
2169 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2170 }
2171
2172 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2173 rts_threshold = nla_get_u32(
2174 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2175 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2176 }
2177
81077e82
LT
2178 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
2179 coverage_class = nla_get_u8(
2180 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2181 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2182 }
2183
b9a5f8ca
JM
2184 if (changed) {
2185 u8 old_retry_short, old_retry_long;
2186 u32 old_frag_threshold, old_rts_threshold;
81077e82 2187 u8 old_coverage_class;
b9a5f8ca 2188
7f2b8562
YX
2189 if (!rdev->ops->set_wiphy_params)
2190 return -EOPNOTSUPP;
b9a5f8ca
JM
2191
2192 old_retry_short = rdev->wiphy.retry_short;
2193 old_retry_long = rdev->wiphy.retry_long;
2194 old_frag_threshold = rdev->wiphy.frag_threshold;
2195 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 2196 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
2197
2198 if (changed & WIPHY_PARAM_RETRY_SHORT)
2199 rdev->wiphy.retry_short = retry_short;
2200 if (changed & WIPHY_PARAM_RETRY_LONG)
2201 rdev->wiphy.retry_long = retry_long;
2202 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
2203 rdev->wiphy.frag_threshold = frag_threshold;
2204 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
2205 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
2206 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
2207 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 2208
e35e4d28 2209 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
2210 if (result) {
2211 rdev->wiphy.retry_short = old_retry_short;
2212 rdev->wiphy.retry_long = old_retry_long;
2213 rdev->wiphy.frag_threshold = old_frag_threshold;
2214 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 2215 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
2216 }
2217 }
7f2b8562 2218 return 0;
55682965
JB
2219}
2220
71bbc994
JB
2221static inline u64 wdev_id(struct wireless_dev *wdev)
2222{
2223 return (u64)wdev->identifier |
2224 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
2225}
55682965 2226
683b6d3b 2227static int nl80211_send_chandef(struct sk_buff *msg,
d2859df5 2228 const struct cfg80211_chan_def *chandef)
683b6d3b 2229{
9f5e8f6e 2230 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 2231
683b6d3b
JB
2232 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
2233 chandef->chan->center_freq))
2234 return -ENOBUFS;
3d9d1d66
JB
2235 switch (chandef->width) {
2236 case NL80211_CHAN_WIDTH_20_NOHT:
2237 case NL80211_CHAN_WIDTH_20:
2238 case NL80211_CHAN_WIDTH_40:
2239 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2240 cfg80211_get_chandef_type(chandef)))
2241 return -ENOBUFS;
2242 break;
2243 default:
2244 break;
2245 }
2246 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
2247 return -ENOBUFS;
2248 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
2249 return -ENOBUFS;
2250 if (chandef->center_freq2 &&
2251 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
2252 return -ENOBUFS;
2253 return 0;
2254}
2255
15e47304 2256static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 2257 struct cfg80211_registered_device *rdev,
72fb2abc 2258 struct wireless_dev *wdev)
55682965 2259{
72fb2abc 2260 struct net_device *dev = wdev->netdev;
55682965
JB
2261 void *hdr;
2262
15e47304 2263 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
2264 if (!hdr)
2265 return -1;
2266
72fb2abc
JB
2267 if (dev &&
2268 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 2269 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
2270 goto nla_put_failure;
2271
2272 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2273 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 2274 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 2275 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
2276 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2277 rdev->devlist_generation ^
2278 (cfg80211_rdev_list_generation << 2)))
2279 goto nla_put_failure;
f5ea9120 2280
5b7ccaf3 2281 if (rdev->ops->get_channel) {
683b6d3b
JB
2282 int ret;
2283 struct cfg80211_chan_def chandef;
2284
2285 ret = rdev_get_channel(rdev, wdev, &chandef);
2286 if (ret == 0) {
2287 if (nl80211_send_chandef(msg, &chandef))
2288 goto nla_put_failure;
2289 }
d91df0e3
PF
2290 }
2291
b84e7a05
AQ
2292 if (wdev->ssid_len) {
2293 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
2294 goto nla_put_failure;
2295 }
2296
55682965
JB
2297 return genlmsg_end(msg, hdr);
2298
2299 nla_put_failure:
bc3ed28c
TG
2300 genlmsg_cancel(msg, hdr);
2301 return -EMSGSIZE;
55682965
JB
2302}
2303
2304static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
2305{
2306 int wp_idx = 0;
2307 int if_idx = 0;
2308 int wp_start = cb->args[0];
2309 int if_start = cb->args[1];
f5ea9120 2310 struct cfg80211_registered_device *rdev;
55682965
JB
2311 struct wireless_dev *wdev;
2312
5fe231e8 2313 rtnl_lock();
f5ea9120
JB
2314 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2315 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2316 continue;
bba95fef
JB
2317 if (wp_idx < wp_start) {
2318 wp_idx++;
55682965 2319 continue;
bba95fef 2320 }
55682965
JB
2321 if_idx = 0;
2322
89a54e48 2323 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
2324 if (if_idx < if_start) {
2325 if_idx++;
55682965 2326 continue;
bba95fef 2327 }
15e47304 2328 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 2329 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 2330 rdev, wdev) < 0) {
bba95fef
JB
2331 goto out;
2332 }
2333 if_idx++;
55682965 2334 }
bba95fef
JB
2335
2336 wp_idx++;
55682965 2337 }
bba95fef 2338 out:
5fe231e8 2339 rtnl_unlock();
55682965
JB
2340
2341 cb->args[0] = wp_idx;
2342 cb->args[1] = if_idx;
2343
2344 return skb->len;
2345}
2346
2347static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
2348{
2349 struct sk_buff *msg;
4c476991 2350 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 2351 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2352
fd2120ca 2353 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 2354 if (!msg)
4c476991 2355 return -ENOMEM;
55682965 2356
15e47304 2357 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 2358 dev, wdev) < 0) {
4c476991
JB
2359 nlmsg_free(msg);
2360 return -ENOBUFS;
2361 }
55682965 2362
134e6375 2363 return genlmsg_reply(msg, info);
55682965
JB
2364}
2365
66f7ac50
MW
2366static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2367 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2368 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2369 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2370 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2371 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 2372 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
2373};
2374
2375static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2376{
2377 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2378 int flag;
2379
2380 *mntrflags = 0;
2381
2382 if (!nla)
2383 return -EINVAL;
2384
2385 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
2386 nla, mntr_flags_policy))
2387 return -EINVAL;
2388
2389 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2390 if (flags[flag])
2391 *mntrflags |= (1<<flag);
2392
2393 return 0;
2394}
2395
9bc383de 2396static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2397 struct net_device *netdev, u8 use_4addr,
2398 enum nl80211_iftype iftype)
9bc383de 2399{
ad4bb6f8 2400 if (!use_4addr) {
f350a0a8 2401 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2402 return -EBUSY;
9bc383de 2403 return 0;
ad4bb6f8 2404 }
9bc383de
JB
2405
2406 switch (iftype) {
2407 case NL80211_IFTYPE_AP_VLAN:
2408 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2409 return 0;
2410 break;
2411 case NL80211_IFTYPE_STATION:
2412 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2413 return 0;
2414 break;
2415 default:
2416 break;
2417 }
2418
2419 return -EOPNOTSUPP;
2420}
2421
55682965
JB
2422static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2423{
4c476991 2424 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2425 struct vif_params params;
e36d56b6 2426 int err;
04a773ad 2427 enum nl80211_iftype otype, ntype;
4c476991 2428 struct net_device *dev = info->user_ptr[1];
92ffe055 2429 u32 _flags, *flags = NULL;
ac7f9cfa 2430 bool change = false;
55682965 2431
2ec600d6
LCC
2432 memset(&params, 0, sizeof(params));
2433
04a773ad 2434 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2435
723b038d 2436 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2437 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2438 if (otype != ntype)
ac7f9cfa 2439 change = true;
4c476991
JB
2440 if (ntype > NL80211_IFTYPE_MAX)
2441 return -EINVAL;
723b038d
JB
2442 }
2443
92ffe055 2444 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2445 struct wireless_dev *wdev = dev->ieee80211_ptr;
2446
4c476991
JB
2447 if (ntype != NL80211_IFTYPE_MESH_POINT)
2448 return -EINVAL;
29cbe68c
JB
2449 if (netif_running(dev))
2450 return -EBUSY;
2451
2452 wdev_lock(wdev);
2453 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2454 IEEE80211_MAX_MESH_ID_LEN);
2455 wdev->mesh_id_up_len =
2456 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2457 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2458 wdev->mesh_id_up_len);
2459 wdev_unlock(wdev);
2ec600d6
LCC
2460 }
2461
8b787643
FF
2462 if (info->attrs[NL80211_ATTR_4ADDR]) {
2463 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2464 change = true;
ad4bb6f8 2465 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2466 if (err)
4c476991 2467 return err;
8b787643
FF
2468 } else {
2469 params.use_4addr = -1;
2470 }
2471
92ffe055 2472 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2473 if (ntype != NL80211_IFTYPE_MONITOR)
2474 return -EINVAL;
92ffe055
JB
2475 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2476 &_flags);
ac7f9cfa 2477 if (err)
4c476991 2478 return err;
ac7f9cfa
JB
2479
2480 flags = &_flags;
2481 change = true;
92ffe055 2482 }
3b85875a 2483
18003297 2484 if (flags && (*flags & MONITOR_FLAG_ACTIVE) &&
e057d3c3
FF
2485 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2486 return -EOPNOTSUPP;
2487
ac7f9cfa 2488 if (change)
3d54d255 2489 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2490 else
2491 err = 0;
60719ffd 2492
9bc383de
JB
2493 if (!err && params.use_4addr != -1)
2494 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2495
55682965
JB
2496 return err;
2497}
2498
2499static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2500{
4c476991 2501 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2502 struct vif_params params;
84efbb84 2503 struct wireless_dev *wdev;
1c90f9d4 2504 struct sk_buff *msg;
55682965
JB
2505 int err;
2506 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2507 u32 flags;
55682965 2508
2ec600d6
LCC
2509 memset(&params, 0, sizeof(params));
2510
55682965
JB
2511 if (!info->attrs[NL80211_ATTR_IFNAME])
2512 return -EINVAL;
2513
2514 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2515 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2516 if (type > NL80211_IFTYPE_MAX)
2517 return -EINVAL;
2518 }
2519
79c97e97 2520 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2521 !(rdev->wiphy.interface_modes & (1 << type)))
2522 return -EOPNOTSUPP;
55682965 2523
1c18f145
AS
2524 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2525 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2526 ETH_ALEN);
2527 if (!is_valid_ether_addr(params.macaddr))
2528 return -EADDRNOTAVAIL;
2529 }
2530
9bc383de 2531 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2532 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2533 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2534 if (err)
4c476991 2535 return err;
9bc383de 2536 }
8b787643 2537
1c90f9d4
JB
2538 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2539 if (!msg)
2540 return -ENOMEM;
2541
66f7ac50
MW
2542 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2543 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2544 &flags);
e057d3c3 2545
18003297 2546 if (!err && (flags & MONITOR_FLAG_ACTIVE) &&
e057d3c3
FF
2547 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2548 return -EOPNOTSUPP;
2549
e35e4d28
HG
2550 wdev = rdev_add_virtual_intf(rdev,
2551 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2552 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2553 if (IS_ERR(wdev)) {
2554 nlmsg_free(msg);
84efbb84 2555 return PTR_ERR(wdev);
1c90f9d4 2556 }
2ec600d6 2557
98104fde
JB
2558 switch (type) {
2559 case NL80211_IFTYPE_MESH_POINT:
2560 if (!info->attrs[NL80211_ATTR_MESH_ID])
2561 break;
29cbe68c
JB
2562 wdev_lock(wdev);
2563 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2564 IEEE80211_MAX_MESH_ID_LEN);
2565 wdev->mesh_id_up_len =
2566 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2567 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2568 wdev->mesh_id_up_len);
2569 wdev_unlock(wdev);
98104fde
JB
2570 break;
2571 case NL80211_IFTYPE_P2P_DEVICE:
2572 /*
2573 * P2P Device doesn't have a netdev, so doesn't go
2574 * through the netdev notifier and must be added here
2575 */
2576 mutex_init(&wdev->mtx);
2577 INIT_LIST_HEAD(&wdev->event_list);
2578 spin_lock_init(&wdev->event_lock);
2579 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2580 spin_lock_init(&wdev->mgmt_registrations_lock);
2581
98104fde
JB
2582 wdev->identifier = ++rdev->wdev_id;
2583 list_add_rcu(&wdev->list, &rdev->wdev_list);
2584 rdev->devlist_generation++;
98104fde
JB
2585 break;
2586 default:
2587 break;
29cbe68c
JB
2588 }
2589
15e47304 2590 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2591 rdev, wdev) < 0) {
2592 nlmsg_free(msg);
2593 return -ENOBUFS;
2594 }
2595
2596 return genlmsg_reply(msg, info);
55682965
JB
2597}
2598
2599static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2600{
4c476991 2601 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2602 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2603
4c476991
JB
2604 if (!rdev->ops->del_virtual_intf)
2605 return -EOPNOTSUPP;
55682965 2606
84efbb84
JB
2607 /*
2608 * If we remove a wireless device without a netdev then clear
2609 * user_ptr[1] so that nl80211_post_doit won't dereference it
2610 * to check if it needs to do dev_put(). Otherwise it crashes
2611 * since the wdev has been freed, unlike with a netdev where
2612 * we need the dev_put() for the netdev to really be freed.
2613 */
2614 if (!wdev->netdev)
2615 info->user_ptr[1] = NULL;
2616
e35e4d28 2617 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2618}
2619
1d9d9213
SW
2620static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2621{
2622 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2623 struct net_device *dev = info->user_ptr[1];
2624 u16 noack_map;
2625
2626 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2627 return -EINVAL;
2628
2629 if (!rdev->ops->set_noack_map)
2630 return -EOPNOTSUPP;
2631
2632 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2633
e35e4d28 2634 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2635}
2636
41ade00f
JB
2637struct get_key_cookie {
2638 struct sk_buff *msg;
2639 int error;
b9454e83 2640 int idx;
41ade00f
JB
2641};
2642
2643static void get_key_callback(void *c, struct key_params *params)
2644{
b9454e83 2645 struct nlattr *key;
41ade00f
JB
2646 struct get_key_cookie *cookie = c;
2647
9360ffd1
DM
2648 if ((params->key &&
2649 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2650 params->key_len, params->key)) ||
2651 (params->seq &&
2652 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2653 params->seq_len, params->seq)) ||
2654 (params->cipher &&
2655 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2656 params->cipher)))
2657 goto nla_put_failure;
41ade00f 2658
b9454e83
JB
2659 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2660 if (!key)
2661 goto nla_put_failure;
2662
9360ffd1
DM
2663 if ((params->key &&
2664 nla_put(cookie->msg, NL80211_KEY_DATA,
2665 params->key_len, params->key)) ||
2666 (params->seq &&
2667 nla_put(cookie->msg, NL80211_KEY_SEQ,
2668 params->seq_len, params->seq)) ||
2669 (params->cipher &&
2670 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2671 params->cipher)))
2672 goto nla_put_failure;
b9454e83 2673
9360ffd1
DM
2674 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2675 goto nla_put_failure;
b9454e83
JB
2676
2677 nla_nest_end(cookie->msg, key);
2678
41ade00f
JB
2679 return;
2680 nla_put_failure:
2681 cookie->error = 1;
2682}
2683
2684static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2685{
4c476991 2686 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2687 int err;
4c476991 2688 struct net_device *dev = info->user_ptr[1];
41ade00f 2689 u8 key_idx = 0;
e31b8213
JB
2690 const u8 *mac_addr = NULL;
2691 bool pairwise;
41ade00f
JB
2692 struct get_key_cookie cookie = {
2693 .error = 0,
2694 };
2695 void *hdr;
2696 struct sk_buff *msg;
2697
2698 if (info->attrs[NL80211_ATTR_KEY_IDX])
2699 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2700
3cfcf6ac 2701 if (key_idx > 5)
41ade00f
JB
2702 return -EINVAL;
2703
2704 if (info->attrs[NL80211_ATTR_MAC])
2705 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2706
e31b8213
JB
2707 pairwise = !!mac_addr;
2708 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2709 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2710 if (kt >= NUM_NL80211_KEYTYPES)
2711 return -EINVAL;
2712 if (kt != NL80211_KEYTYPE_GROUP &&
2713 kt != NL80211_KEYTYPE_PAIRWISE)
2714 return -EINVAL;
2715 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2716 }
2717
4c476991
JB
2718 if (!rdev->ops->get_key)
2719 return -EOPNOTSUPP;
41ade00f 2720
fd2120ca 2721 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2722 if (!msg)
2723 return -ENOMEM;
41ade00f 2724
15e47304 2725 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2726 NL80211_CMD_NEW_KEY);
cb35fba3 2727 if (!hdr)
9fe271af 2728 goto nla_put_failure;
41ade00f
JB
2729
2730 cookie.msg = msg;
b9454e83 2731 cookie.idx = key_idx;
41ade00f 2732
9360ffd1
DM
2733 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2734 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2735 goto nla_put_failure;
2736 if (mac_addr &&
2737 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2738 goto nla_put_failure;
41ade00f 2739
e31b8213
JB
2740 if (pairwise && mac_addr &&
2741 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2742 return -ENOENT;
2743
e35e4d28
HG
2744 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2745 get_key_callback);
41ade00f
JB
2746
2747 if (err)
6c95e2a2 2748 goto free_msg;
41ade00f
JB
2749
2750 if (cookie.error)
2751 goto nla_put_failure;
2752
2753 genlmsg_end(msg, hdr);
4c476991 2754 return genlmsg_reply(msg, info);
41ade00f
JB
2755
2756 nla_put_failure:
2757 err = -ENOBUFS;
6c95e2a2 2758 free_msg:
41ade00f 2759 nlmsg_free(msg);
41ade00f
JB
2760 return err;
2761}
2762
2763static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2764{
4c476991 2765 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2766 struct key_parse key;
41ade00f 2767 int err;
4c476991 2768 struct net_device *dev = info->user_ptr[1];
41ade00f 2769
b9454e83
JB
2770 err = nl80211_parse_key(info, &key);
2771 if (err)
2772 return err;
41ade00f 2773
b9454e83 2774 if (key.idx < 0)
41ade00f
JB
2775 return -EINVAL;
2776
b9454e83
JB
2777 /* only support setting default key */
2778 if (!key.def && !key.defmgmt)
41ade00f
JB
2779 return -EINVAL;
2780
dbd2fd65 2781 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2782
dbd2fd65
JB
2783 if (key.def) {
2784 if (!rdev->ops->set_default_key) {
2785 err = -EOPNOTSUPP;
2786 goto out;
2787 }
41ade00f 2788
dbd2fd65
JB
2789 err = nl80211_key_allowed(dev->ieee80211_ptr);
2790 if (err)
2791 goto out;
2792
e35e4d28 2793 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2794 key.def_uni, key.def_multi);
2795
2796 if (err)
2797 goto out;
fffd0934 2798
3d23e349 2799#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2800 dev->ieee80211_ptr->wext.default_key = key.idx;
2801#endif
2802 } else {
2803 if (key.def_uni || !key.def_multi) {
2804 err = -EINVAL;
2805 goto out;
2806 }
2807
2808 if (!rdev->ops->set_default_mgmt_key) {
2809 err = -EOPNOTSUPP;
2810 goto out;
2811 }
2812
2813 err = nl80211_key_allowed(dev->ieee80211_ptr);
2814 if (err)
2815 goto out;
2816
e35e4d28 2817 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2818 if (err)
2819 goto out;
2820
2821#ifdef CONFIG_CFG80211_WEXT
2822 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2823#endif
dbd2fd65
JB
2824 }
2825
2826 out:
fffd0934 2827 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2828
41ade00f
JB
2829 return err;
2830}
2831
2832static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2833{
4c476991 2834 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2835 int err;
4c476991 2836 struct net_device *dev = info->user_ptr[1];
b9454e83 2837 struct key_parse key;
e31b8213 2838 const u8 *mac_addr = NULL;
41ade00f 2839
b9454e83
JB
2840 err = nl80211_parse_key(info, &key);
2841 if (err)
2842 return err;
41ade00f 2843
b9454e83 2844 if (!key.p.key)
41ade00f
JB
2845 return -EINVAL;
2846
41ade00f
JB
2847 if (info->attrs[NL80211_ATTR_MAC])
2848 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2849
e31b8213
JB
2850 if (key.type == -1) {
2851 if (mac_addr)
2852 key.type = NL80211_KEYTYPE_PAIRWISE;
2853 else
2854 key.type = NL80211_KEYTYPE_GROUP;
2855 }
2856
2857 /* for now */
2858 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2859 key.type != NL80211_KEYTYPE_GROUP)
2860 return -EINVAL;
2861
4c476991
JB
2862 if (!rdev->ops->add_key)
2863 return -EOPNOTSUPP;
25e47c18 2864
e31b8213
JB
2865 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2866 key.type == NL80211_KEYTYPE_PAIRWISE,
2867 mac_addr))
4c476991 2868 return -EINVAL;
41ade00f 2869
fffd0934
JB
2870 wdev_lock(dev->ieee80211_ptr);
2871 err = nl80211_key_allowed(dev->ieee80211_ptr);
2872 if (!err)
e35e4d28
HG
2873 err = rdev_add_key(rdev, dev, key.idx,
2874 key.type == NL80211_KEYTYPE_PAIRWISE,
2875 mac_addr, &key.p);
fffd0934 2876 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2877
41ade00f
JB
2878 return err;
2879}
2880
2881static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2882{
4c476991 2883 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2884 int err;
4c476991 2885 struct net_device *dev = info->user_ptr[1];
41ade00f 2886 u8 *mac_addr = NULL;
b9454e83 2887 struct key_parse key;
41ade00f 2888
b9454e83
JB
2889 err = nl80211_parse_key(info, &key);
2890 if (err)
2891 return err;
41ade00f
JB
2892
2893 if (info->attrs[NL80211_ATTR_MAC])
2894 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2895
e31b8213
JB
2896 if (key.type == -1) {
2897 if (mac_addr)
2898 key.type = NL80211_KEYTYPE_PAIRWISE;
2899 else
2900 key.type = NL80211_KEYTYPE_GROUP;
2901 }
2902
2903 /* for now */
2904 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2905 key.type != NL80211_KEYTYPE_GROUP)
2906 return -EINVAL;
2907
4c476991
JB
2908 if (!rdev->ops->del_key)
2909 return -EOPNOTSUPP;
41ade00f 2910
fffd0934
JB
2911 wdev_lock(dev->ieee80211_ptr);
2912 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2913
2914 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2915 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2916 err = -ENOENT;
2917
fffd0934 2918 if (!err)
e35e4d28
HG
2919 err = rdev_del_key(rdev, dev, key.idx,
2920 key.type == NL80211_KEYTYPE_PAIRWISE,
2921 mac_addr);
41ade00f 2922
3d23e349 2923#ifdef CONFIG_CFG80211_WEXT
08645126 2924 if (!err) {
b9454e83 2925 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2926 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2927 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2928 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2929 }
2930#endif
fffd0934 2931 wdev_unlock(dev->ieee80211_ptr);
08645126 2932
41ade00f
JB
2933 return err;
2934}
2935
77765eaf
VT
2936/* This function returns an error or the number of nested attributes */
2937static int validate_acl_mac_addrs(struct nlattr *nl_attr)
2938{
2939 struct nlattr *attr;
2940 int n_entries = 0, tmp;
2941
2942 nla_for_each_nested(attr, nl_attr, tmp) {
2943 if (nla_len(attr) != ETH_ALEN)
2944 return -EINVAL;
2945
2946 n_entries++;
2947 }
2948
2949 return n_entries;
2950}
2951
2952/*
2953 * This function parses ACL information and allocates memory for ACL data.
2954 * On successful return, the calling function is responsible to free the
2955 * ACL buffer returned by this function.
2956 */
2957static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
2958 struct genl_info *info)
2959{
2960 enum nl80211_acl_policy acl_policy;
2961 struct nlattr *attr;
2962 struct cfg80211_acl_data *acl;
2963 int i = 0, n_entries, tmp;
2964
2965 if (!wiphy->max_acl_mac_addrs)
2966 return ERR_PTR(-EOPNOTSUPP);
2967
2968 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
2969 return ERR_PTR(-EINVAL);
2970
2971 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
2972 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
2973 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
2974 return ERR_PTR(-EINVAL);
2975
2976 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
2977 return ERR_PTR(-EINVAL);
2978
2979 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
2980 if (n_entries < 0)
2981 return ERR_PTR(n_entries);
2982
2983 if (n_entries > wiphy->max_acl_mac_addrs)
2984 return ERR_PTR(-ENOTSUPP);
2985
2986 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
2987 GFP_KERNEL);
2988 if (!acl)
2989 return ERR_PTR(-ENOMEM);
2990
2991 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
2992 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
2993 i++;
2994 }
2995
2996 acl->n_acl_entries = n_entries;
2997 acl->acl_policy = acl_policy;
2998
2999 return acl;
3000}
3001
3002static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
3003{
3004 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3005 struct net_device *dev = info->user_ptr[1];
3006 struct cfg80211_acl_data *acl;
3007 int err;
3008
3009 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3010 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3011 return -EOPNOTSUPP;
3012
3013 if (!dev->ieee80211_ptr->beacon_interval)
3014 return -EINVAL;
3015
3016 acl = parse_acl_data(&rdev->wiphy, info);
3017 if (IS_ERR(acl))
3018 return PTR_ERR(acl);
3019
3020 err = rdev_set_mac_acl(rdev, dev, acl);
3021
3022 kfree(acl);
3023
3024 return err;
3025}
3026
a1193be8 3027static int nl80211_parse_beacon(struct nlattr *attrs[],
8860020e 3028 struct cfg80211_beacon_data *bcn)
ed1b6cc7 3029{
8860020e 3030 bool haveinfo = false;
ed1b6cc7 3031
a1193be8
SW
3032 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) ||
3033 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) ||
3034 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
3035 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
3036 return -EINVAL;
3037
8860020e 3038 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 3039
a1193be8
SW
3040 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
3041 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
3042 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
3043 if (!bcn->head_len)
3044 return -EINVAL;
3045 haveinfo = true;
ed1b6cc7
JB
3046 }
3047
a1193be8
SW
3048 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
3049 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
3050 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 3051 haveinfo = true;
ed1b6cc7
JB
3052 }
3053
4c476991
JB
3054 if (!haveinfo)
3055 return -EINVAL;
3b85875a 3056
a1193be8
SW
3057 if (attrs[NL80211_ATTR_IE]) {
3058 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
3059 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
3060 }
3061
a1193be8 3062 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 3063 bcn->proberesp_ies =
a1193be8 3064 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 3065 bcn->proberesp_ies_len =
a1193be8 3066 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
3067 }
3068
a1193be8 3069 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 3070 bcn->assocresp_ies =
a1193be8 3071 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 3072 bcn->assocresp_ies_len =
a1193be8 3073 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
3074 }
3075
a1193be8
SW
3076 if (attrs[NL80211_ATTR_PROBE_RESP]) {
3077 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
3078 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
3079 }
3080
8860020e
JB
3081 return 0;
3082}
3083
46c1dd0c
FF
3084static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
3085 struct cfg80211_ap_settings *params)
3086{
3087 struct wireless_dev *wdev;
3088 bool ret = false;
3089
89a54e48 3090 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
3091 if (wdev->iftype != NL80211_IFTYPE_AP &&
3092 wdev->iftype != NL80211_IFTYPE_P2P_GO)
3093 continue;
3094
683b6d3b 3095 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
3096 continue;
3097
683b6d3b 3098 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
3099 ret = true;
3100 break;
3101 }
3102
46c1dd0c
FF
3103 return ret;
3104}
3105
e39e5b5e
JM
3106static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
3107 enum nl80211_auth_type auth_type,
3108 enum nl80211_commands cmd)
3109{
3110 if (auth_type > NL80211_AUTHTYPE_MAX)
3111 return false;
3112
3113 switch (cmd) {
3114 case NL80211_CMD_AUTHENTICATE:
3115 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
3116 auth_type == NL80211_AUTHTYPE_SAE)
3117 return false;
3118 return true;
3119 case NL80211_CMD_CONNECT:
3120 case NL80211_CMD_START_AP:
3121 /* SAE not supported yet */
3122 if (auth_type == NL80211_AUTHTYPE_SAE)
3123 return false;
3124 return true;
3125 default:
3126 return false;
3127 }
3128}
3129
8860020e
JB
3130static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
3131{
3132 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3133 struct net_device *dev = info->user_ptr[1];
3134 struct wireless_dev *wdev = dev->ieee80211_ptr;
3135 struct cfg80211_ap_settings params;
3136 int err;
04f39047 3137 u8 radar_detect_width = 0;
8860020e
JB
3138
3139 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3140 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3141 return -EOPNOTSUPP;
3142
3143 if (!rdev->ops->start_ap)
3144 return -EOPNOTSUPP;
3145
3146 if (wdev->beacon_interval)
3147 return -EALREADY;
3148
3149 memset(&params, 0, sizeof(params));
3150
3151 /* these are required for START_AP */
3152 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
3153 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
3154 !info->attrs[NL80211_ATTR_BEACON_HEAD])
3155 return -EINVAL;
3156
a1193be8 3157 err = nl80211_parse_beacon(info->attrs, &params.beacon);
8860020e
JB
3158 if (err)
3159 return err;
3160
3161 params.beacon_interval =
3162 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3163 params.dtim_period =
3164 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
3165
3166 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
3167 if (err)
3168 return err;
3169
3170 /*
3171 * In theory, some of these attributes should be required here
3172 * but since they were not used when the command was originally
3173 * added, keep them optional for old user space programs to let
3174 * them continue to work with drivers that do not need the
3175 * additional information -- drivers must check!
3176 */
3177 if (info->attrs[NL80211_ATTR_SSID]) {
3178 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3179 params.ssid_len =
3180 nla_len(info->attrs[NL80211_ATTR_SSID]);
3181 if (params.ssid_len == 0 ||
3182 params.ssid_len > IEEE80211_MAX_SSID_LEN)
3183 return -EINVAL;
3184 }
3185
3186 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
3187 params.hidden_ssid = nla_get_u32(
3188 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
3189 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
3190 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
3191 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
3192 return -EINVAL;
3193 }
3194
3195 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3196
3197 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3198 params.auth_type = nla_get_u32(
3199 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
3200 if (!nl80211_valid_auth_type(rdev, params.auth_type,
3201 NL80211_CMD_START_AP))
8860020e
JB
3202 return -EINVAL;
3203 } else
3204 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3205
3206 err = nl80211_crypto_settings(rdev, info, &params.crypto,
3207 NL80211_MAX_NR_CIPHER_SUITES);
3208 if (err)
3209 return err;
3210
1b658f11
VT
3211 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
3212 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
3213 return -EOPNOTSUPP;
3214 params.inactivity_timeout = nla_get_u16(
3215 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
3216 }
3217
53cabad7
JB
3218 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3219 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3220 return -EINVAL;
3221 params.p2p_ctwindow =
3222 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3223 if (params.p2p_ctwindow > 127)
3224 return -EINVAL;
3225 if (params.p2p_ctwindow != 0 &&
3226 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3227 return -EINVAL;
3228 }
3229
3230 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3231 u8 tmp;
3232
3233 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3234 return -EINVAL;
3235 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3236 if (tmp > 1)
3237 return -EINVAL;
3238 params.p2p_opp_ps = tmp;
3239 if (params.p2p_opp_ps != 0 &&
3240 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3241 return -EINVAL;
3242 }
3243
aa430da4 3244 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
3245 err = nl80211_parse_chandef(rdev, info, &params.chandef);
3246 if (err)
3247 return err;
3248 } else if (wdev->preset_chandef.chan) {
3249 params.chandef = wdev->preset_chandef;
46c1dd0c 3250 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
3251 return -EINVAL;
3252
683b6d3b 3253 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
3254 return -EINVAL;
3255
04f39047
SW
3256 err = cfg80211_chandef_dfs_required(wdev->wiphy, &params.chandef);
3257 if (err < 0)
3258 return err;
3259 if (err) {
3260 radar_detect_width = BIT(params.chandef.width);
3261 params.radar_required = true;
3262 }
3263
04f39047
SW
3264 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
3265 params.chandef.chan,
3266 CHAN_MODE_SHARED,
3267 radar_detect_width);
e4e32459
MK
3268 if (err)
3269 return err;
3270
77765eaf
VT
3271 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
3272 params.acl = parse_acl_data(&rdev->wiphy, info);
3273 if (IS_ERR(params.acl))
3274 return PTR_ERR(params.acl);
3275 }
3276
c56589ed 3277 wdev_lock(wdev);
e35e4d28 3278 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 3279 if (!err) {
683b6d3b 3280 wdev->preset_chandef = params.chandef;
8860020e 3281 wdev->beacon_interval = params.beacon_interval;
683b6d3b 3282 wdev->channel = params.chandef.chan;
06e191e2
AQ
3283 wdev->ssid_len = params.ssid_len;
3284 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 3285 }
c56589ed 3286 wdev_unlock(wdev);
77765eaf
VT
3287
3288 kfree(params.acl);
3289
56d1893d 3290 return err;
ed1b6cc7
JB
3291}
3292
8860020e
JB
3293static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
3294{
3295 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3296 struct net_device *dev = info->user_ptr[1];
3297 struct wireless_dev *wdev = dev->ieee80211_ptr;
3298 struct cfg80211_beacon_data params;
3299 int err;
3300
3301 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3302 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3303 return -EOPNOTSUPP;
3304
3305 if (!rdev->ops->change_beacon)
3306 return -EOPNOTSUPP;
3307
3308 if (!wdev->beacon_interval)
3309 return -EINVAL;
3310
a1193be8 3311 err = nl80211_parse_beacon(info->attrs, &params);
8860020e
JB
3312 if (err)
3313 return err;
3314
c56589ed
SW
3315 wdev_lock(wdev);
3316 err = rdev_change_beacon(rdev, dev, &params);
3317 wdev_unlock(wdev);
3318
3319 return err;
8860020e
JB
3320}
3321
3322static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 3323{
4c476991
JB
3324 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3325 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 3326
60771780 3327 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
3328}
3329
5727ef1b
JB
3330static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
3331 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
3332 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
3333 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 3334 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 3335 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 3336 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
3337};
3338
eccb8e8f 3339static int parse_station_flags(struct genl_info *info,
bdd3ae3d 3340 enum nl80211_iftype iftype,
eccb8e8f 3341 struct station_parameters *params)
5727ef1b
JB
3342{
3343 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 3344 struct nlattr *nla;
5727ef1b
JB
3345 int flag;
3346
eccb8e8f
JB
3347 /*
3348 * Try parsing the new attribute first so userspace
3349 * can specify both for older kernels.
3350 */
3351 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
3352 if (nla) {
3353 struct nl80211_sta_flag_update *sta_flags;
3354
3355 sta_flags = nla_data(nla);
3356 params->sta_flags_mask = sta_flags->mask;
3357 params->sta_flags_set = sta_flags->set;
77ee7c89 3358 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
3359 if ((params->sta_flags_mask |
3360 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
3361 return -EINVAL;
3362 return 0;
3363 }
3364
3365 /* if present, parse the old attribute */
5727ef1b 3366
eccb8e8f 3367 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
3368 if (!nla)
3369 return 0;
3370
3371 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
3372 nla, sta_flags_policy))
3373 return -EINVAL;
3374
bdd3ae3d
JB
3375 /*
3376 * Only allow certain flags for interface types so that
3377 * other attributes are silently ignored. Remember that
3378 * this is backward compatibility code with old userspace
3379 * and shouldn't be hit in other cases anyway.
3380 */
3381 switch (iftype) {
3382 case NL80211_IFTYPE_AP:
3383 case NL80211_IFTYPE_AP_VLAN:
3384 case NL80211_IFTYPE_P2P_GO:
3385 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3386 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3387 BIT(NL80211_STA_FLAG_WME) |
3388 BIT(NL80211_STA_FLAG_MFP);
3389 break;
3390 case NL80211_IFTYPE_P2P_CLIENT:
3391 case NL80211_IFTYPE_STATION:
3392 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3393 BIT(NL80211_STA_FLAG_TDLS_PEER);
3394 break;
3395 case NL80211_IFTYPE_MESH_POINT:
3396 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3397 BIT(NL80211_STA_FLAG_MFP) |
3398 BIT(NL80211_STA_FLAG_AUTHORIZED);
3399 default:
3400 return -EINVAL;
3401 }
5727ef1b 3402
3383b5a6
JB
3403 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
3404 if (flags[flag]) {
eccb8e8f 3405 params->sta_flags_set |= (1<<flag);
5727ef1b 3406
3383b5a6
JB
3407 /* no longer support new API additions in old API */
3408 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
3409 return -EINVAL;
3410 }
3411 }
3412
5727ef1b
JB
3413 return 0;
3414}
3415
c8dcfd8a
FF
3416static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
3417 int attr)
3418{
3419 struct nlattr *rate;
8eb41c8d
VK
3420 u32 bitrate;
3421 u16 bitrate_compat;
c8dcfd8a
FF
3422
3423 rate = nla_nest_start(msg, attr);
3424 if (!rate)
db9c64cf 3425 return false;
c8dcfd8a
FF
3426
3427 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
3428 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
3429 /* report 16-bit bitrate only if we can */
3430 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
3431 if (bitrate > 0 &&
3432 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
3433 return false;
3434 if (bitrate_compat > 0 &&
3435 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
3436 return false;
3437
3438 if (info->flags & RATE_INFO_FLAGS_MCS) {
3439 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
3440 return false;
3441 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3442 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3443 return false;
3444 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3445 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3446 return false;
3447 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3448 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3449 return false;
3450 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3451 return false;
3452 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3453 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3454 return false;
3455 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
3456 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
3457 return false;
3458 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
3459 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
3460 return false;
3461 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
3462 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
3463 return false;
3464 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3465 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3466 return false;
3467 }
c8dcfd8a
FF
3468
3469 nla_nest_end(msg, rate);
3470 return true;
c8dcfd8a
FF
3471}
3472
119363c7
FF
3473static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
3474 int id)
3475{
3476 void *attr;
3477 int i = 0;
3478
3479 if (!mask)
3480 return true;
3481
3482 attr = nla_nest_start(msg, id);
3483 if (!attr)
3484 return false;
3485
3486 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
3487 if (!(mask & BIT(i)))
3488 continue;
3489
3490 if (nla_put_u8(msg, i, signal[i]))
3491 return false;
3492 }
3493
3494 nla_nest_end(msg, attr);
3495
3496 return true;
3497}
3498
15e47304 3499static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
3500 int flags,
3501 struct cfg80211_registered_device *rdev,
3502 struct net_device *dev,
98b62183 3503 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3504{
3505 void *hdr;
f4263c98 3506 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3507
15e47304 3508 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
3509 if (!hdr)
3510 return -1;
3511
9360ffd1
DM
3512 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3513 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3514 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3515 goto nla_put_failure;
f5ea9120 3516
2ec600d6
LCC
3517 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3518 if (!sinfoattr)
fd5b74dc 3519 goto nla_put_failure;
9360ffd1
DM
3520 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
3521 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
3522 sinfo->connected_time))
3523 goto nla_put_failure;
3524 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
3525 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
3526 sinfo->inactive_time))
3527 goto nla_put_failure;
42745e03
VK
3528 if ((sinfo->filled & (STATION_INFO_RX_BYTES |
3529 STATION_INFO_RX_BYTES64)) &&
9360ffd1 3530 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 3531 (u32)sinfo->rx_bytes))
9360ffd1 3532 goto nla_put_failure;
42745e03 3533 if ((sinfo->filled & (STATION_INFO_TX_BYTES |
4325d724 3534 STATION_INFO_TX_BYTES64)) &&
9360ffd1 3535 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
3536 (u32)sinfo->tx_bytes))
3537 goto nla_put_failure;
3538 if ((sinfo->filled & STATION_INFO_RX_BYTES64) &&
3539 nla_put_u64(msg, NL80211_STA_INFO_RX_BYTES64,
3540 sinfo->rx_bytes))
3541 goto nla_put_failure;
3542 if ((sinfo->filled & STATION_INFO_TX_BYTES64) &&
3543 nla_put_u64(msg, NL80211_STA_INFO_TX_BYTES64,
9360ffd1
DM
3544 sinfo->tx_bytes))
3545 goto nla_put_failure;
3546 if ((sinfo->filled & STATION_INFO_LLID) &&
3547 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
3548 goto nla_put_failure;
3549 if ((sinfo->filled & STATION_INFO_PLID) &&
3550 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
3551 goto nla_put_failure;
3552 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
3553 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
3554 sinfo->plink_state))
3555 goto nla_put_failure;
66266b3a
JL
3556 switch (rdev->wiphy.signal_type) {
3557 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
3558 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
3559 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
3560 sinfo->signal))
3561 goto nla_put_failure;
3562 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
3563 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
3564 sinfo->signal_avg))
3565 goto nla_put_failure;
66266b3a
JL
3566 break;
3567 default:
3568 break;
3569 }
119363c7
FF
3570 if (sinfo->filled & STATION_INFO_CHAIN_SIGNAL) {
3571 if (!nl80211_put_signal(msg, sinfo->chains,
3572 sinfo->chain_signal,
3573 NL80211_STA_INFO_CHAIN_SIGNAL))
3574 goto nla_put_failure;
3575 }
3576 if (sinfo->filled & STATION_INFO_CHAIN_SIGNAL_AVG) {
3577 if (!nl80211_put_signal(msg, sinfo->chains,
3578 sinfo->chain_signal_avg,
3579 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
3580 goto nla_put_failure;
3581 }
420e7fab 3582 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3583 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3584 NL80211_STA_INFO_TX_BITRATE))
3585 goto nla_put_failure;
3586 }
3587 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3588 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3589 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3590 goto nla_put_failure;
420e7fab 3591 }
9360ffd1
DM
3592 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3593 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3594 sinfo->rx_packets))
3595 goto nla_put_failure;
3596 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3597 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3598 sinfo->tx_packets))
3599 goto nla_put_failure;
3600 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3601 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3602 sinfo->tx_retries))
3603 goto nla_put_failure;
3604 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3605 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3606 sinfo->tx_failed))
3607 goto nla_put_failure;
3608 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3609 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3610 sinfo->beacon_loss_count))
3611 goto nla_put_failure;
3b1c5a53
MP
3612 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3613 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3614 sinfo->local_pm))
3615 goto nla_put_failure;
3616 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3617 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3618 sinfo->peer_pm))
3619 goto nla_put_failure;
3620 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3621 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3622 sinfo->nonpeer_pm))
3623 goto nla_put_failure;
f4263c98
PS
3624 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3625 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3626 if (!bss_param)
3627 goto nla_put_failure;
3628
9360ffd1
DM
3629 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3630 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3631 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3632 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3633 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3634 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3635 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3636 sinfo->bss_param.dtim_period) ||
3637 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3638 sinfo->bss_param.beacon_interval))
3639 goto nla_put_failure;
f4263c98
PS
3640
3641 nla_nest_end(msg, bss_param);
3642 }
9360ffd1
DM
3643 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3644 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3645 sizeof(struct nl80211_sta_flag_update),
3646 &sinfo->sta_flags))
3647 goto nla_put_failure;
7eab0f64
JL
3648 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3649 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3650 sinfo->t_offset))
3651 goto nla_put_failure;
2ec600d6 3652 nla_nest_end(msg, sinfoattr);
fd5b74dc 3653
9360ffd1
DM
3654 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3655 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3656 sinfo->assoc_req_ies))
3657 goto nla_put_failure;
50d3dfb7 3658
fd5b74dc
JB
3659 return genlmsg_end(msg, hdr);
3660
3661 nla_put_failure:
bc3ed28c
TG
3662 genlmsg_cancel(msg, hdr);
3663 return -EMSGSIZE;
fd5b74dc
JB
3664}
3665
2ec600d6 3666static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3667 struct netlink_callback *cb)
2ec600d6 3668{
2ec600d6
LCC
3669 struct station_info sinfo;
3670 struct cfg80211_registered_device *dev;
97990a06 3671 struct wireless_dev *wdev;
2ec600d6 3672 u8 mac_addr[ETH_ALEN];
97990a06 3673 int sta_idx = cb->args[2];
2ec600d6 3674 int err;
2ec600d6 3675
97990a06 3676 err = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
3677 if (err)
3678 return err;
bba95fef 3679
97990a06
JB
3680 if (!wdev->netdev) {
3681 err = -EINVAL;
3682 goto out_err;
3683 }
3684
bba95fef 3685 if (!dev->ops->dump_station) {
eec60b03 3686 err = -EOPNOTSUPP;
bba95fef
JB
3687 goto out_err;
3688 }
3689
bba95fef 3690 while (1) {
f612cedf 3691 memset(&sinfo, 0, sizeof(sinfo));
97990a06 3692 err = rdev_dump_station(dev, wdev->netdev, sta_idx,
e35e4d28 3693 mac_addr, &sinfo);
bba95fef
JB
3694 if (err == -ENOENT)
3695 break;
3696 if (err)
3b85875a 3697 goto out_err;
bba95fef
JB
3698
3699 if (nl80211_send_station(skb,
15e47304 3700 NETLINK_CB(cb->skb).portid,
bba95fef 3701 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 3702 dev, wdev->netdev, mac_addr,
bba95fef
JB
3703 &sinfo) < 0)
3704 goto out;
3705
3706 sta_idx++;
3707 }
3708
3709
3710 out:
97990a06 3711 cb->args[2] = sta_idx;
bba95fef 3712 err = skb->len;
bba95fef 3713 out_err:
97990a06 3714 nl80211_finish_wdev_dump(dev);
bba95fef
JB
3715
3716 return err;
2ec600d6 3717}
fd5b74dc 3718
5727ef1b
JB
3719static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3720{
4c476991
JB
3721 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3722 struct net_device *dev = info->user_ptr[1];
2ec600d6 3723 struct station_info sinfo;
fd5b74dc
JB
3724 struct sk_buff *msg;
3725 u8 *mac_addr = NULL;
4c476991 3726 int err;
fd5b74dc 3727
2ec600d6 3728 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3729
3730 if (!info->attrs[NL80211_ATTR_MAC])
3731 return -EINVAL;
3732
3733 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3734
4c476991
JB
3735 if (!rdev->ops->get_station)
3736 return -EOPNOTSUPP;
3b85875a 3737
e35e4d28 3738 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3739 if (err)
4c476991 3740 return err;
2ec600d6 3741
fd2120ca 3742 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3743 if (!msg)
4c476991 3744 return -ENOMEM;
fd5b74dc 3745
15e47304 3746 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3747 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3748 nlmsg_free(msg);
3749 return -ENOBUFS;
3750 }
3b85875a 3751
4c476991 3752 return genlmsg_reply(msg, info);
5727ef1b
JB
3753}
3754
77ee7c89
JB
3755int cfg80211_check_station_change(struct wiphy *wiphy,
3756 struct station_parameters *params,
3757 enum cfg80211_station_type statype)
3758{
3759 if (params->listen_interval != -1)
3760 return -EINVAL;
3761 if (params->aid)
3762 return -EINVAL;
3763
3764 /* When you run into this, adjust the code below for the new flag */
3765 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
3766
3767 switch (statype) {
eef941e6
TP
3768 case CFG80211_STA_MESH_PEER_KERNEL:
3769 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3770 /*
3771 * No ignoring the TDLS flag here -- the userspace mesh
3772 * code doesn't have the bug of including TDLS in the
3773 * mask everywhere.
3774 */
3775 if (params->sta_flags_mask &
3776 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3777 BIT(NL80211_STA_FLAG_MFP) |
3778 BIT(NL80211_STA_FLAG_AUTHORIZED)))
3779 return -EINVAL;
3780 break;
3781 case CFG80211_STA_TDLS_PEER_SETUP:
3782 case CFG80211_STA_TDLS_PEER_ACTIVE:
3783 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3784 return -EINVAL;
3785 /* ignore since it can't change */
3786 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3787 break;
3788 default:
3789 /* disallow mesh-specific things */
3790 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3791 return -EINVAL;
3792 if (params->local_pm)
3793 return -EINVAL;
3794 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3795 return -EINVAL;
3796 }
3797
3798 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
3799 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
3800 /* TDLS can't be set, ... */
3801 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3802 return -EINVAL;
3803 /*
3804 * ... but don't bother the driver with it. This works around
3805 * a hostapd/wpa_supplicant issue -- it always includes the
3806 * TLDS_PEER flag in the mask even for AP mode.
3807 */
3808 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3809 }
3810
3811 if (statype != CFG80211_STA_TDLS_PEER_SETUP) {
3812 /* reject other things that can't change */
3813 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
3814 return -EINVAL;
3815 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
3816 return -EINVAL;
3817 if (params->supported_rates)
3818 return -EINVAL;
3819 if (params->ext_capab || params->ht_capa || params->vht_capa)
3820 return -EINVAL;
3821 }
3822
3823 if (statype != CFG80211_STA_AP_CLIENT) {
3824 if (params->vlan)
3825 return -EINVAL;
3826 }
3827
3828 switch (statype) {
3829 case CFG80211_STA_AP_MLME_CLIENT:
3830 /* Use this only for authorizing/unauthorizing a station */
3831 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
3832 return -EOPNOTSUPP;
3833 break;
3834 case CFG80211_STA_AP_CLIENT:
3835 /* accept only the listed bits */
3836 if (params->sta_flags_mask &
3837 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3838 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3839 BIT(NL80211_STA_FLAG_ASSOCIATED) |
3840 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3841 BIT(NL80211_STA_FLAG_WME) |
3842 BIT(NL80211_STA_FLAG_MFP)))
3843 return -EINVAL;
3844
3845 /* but authenticated/associated only if driver handles it */
3846 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3847 params->sta_flags_mask &
3848 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3849 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3850 return -EINVAL;
3851 break;
3852 case CFG80211_STA_IBSS:
3853 case CFG80211_STA_AP_STA:
3854 /* reject any changes other than AUTHORIZED */
3855 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3856 return -EINVAL;
3857 break;
3858 case CFG80211_STA_TDLS_PEER_SETUP:
3859 /* reject any changes other than AUTHORIZED or WME */
3860 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3861 BIT(NL80211_STA_FLAG_WME)))
3862 return -EINVAL;
3863 /* force (at least) rates when authorizing */
3864 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
3865 !params->supported_rates)
3866 return -EINVAL;
3867 break;
3868 case CFG80211_STA_TDLS_PEER_ACTIVE:
3869 /* reject any changes */
3870 return -EINVAL;
eef941e6 3871 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
3872 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
3873 return -EINVAL;
3874 break;
eef941e6 3875 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
3876 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
3877 return -EINVAL;
3878 break;
3879 }
3880
3881 return 0;
3882}
3883EXPORT_SYMBOL(cfg80211_check_station_change);
3884
5727ef1b 3885/*
c258d2de 3886 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3887 */
80b99899
JB
3888static struct net_device *get_vlan(struct genl_info *info,
3889 struct cfg80211_registered_device *rdev)
5727ef1b 3890{
463d0183 3891 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3892 struct net_device *v;
3893 int ret;
3894
3895 if (!vlanattr)
3896 return NULL;
3897
3898 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3899 if (!v)
3900 return ERR_PTR(-ENODEV);
3901
3902 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3903 ret = -EINVAL;
3904 goto error;
5727ef1b 3905 }
80b99899 3906
77ee7c89
JB
3907 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
3908 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3909 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
3910 ret = -EINVAL;
3911 goto error;
3912 }
3913
80b99899
JB
3914 if (!netif_running(v)) {
3915 ret = -ENETDOWN;
3916 goto error;
3917 }
3918
3919 return v;
3920 error:
3921 dev_put(v);
3922 return ERR_PTR(ret);
5727ef1b
JB
3923}
3924
94e860f1
JB
3925static const struct nla_policy
3926nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
df881293
JM
3927 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3928 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3929};
3930
ff276691
JB
3931static int nl80211_parse_sta_wme(struct genl_info *info,
3932 struct station_parameters *params)
df881293 3933{
df881293
JM
3934 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3935 struct nlattr *nla;
3936 int err;
3937
df881293
JM
3938 /* parse WME attributes if present */
3939 if (!info->attrs[NL80211_ATTR_STA_WME])
3940 return 0;
3941
3942 nla = info->attrs[NL80211_ATTR_STA_WME];
3943 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3944 nl80211_sta_wme_policy);
3945 if (err)
3946 return err;
3947
3948 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3949 params->uapsd_queues = nla_get_u8(
3950 tb[NL80211_STA_WME_UAPSD_QUEUES]);
3951 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3952 return -EINVAL;
3953
3954 if (tb[NL80211_STA_WME_MAX_SP])
3955 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
3956
3957 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3958 return -EINVAL;
3959
3960 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3961
3962 return 0;
3963}
3964
c01fc9ad
SD
3965static int nl80211_parse_sta_channel_info(struct genl_info *info,
3966 struct station_parameters *params)
3967{
3968 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
3969 params->supported_channels =
3970 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
3971 params->supported_channels_len =
3972 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
3973 /*
3974 * Need to include at least one (first channel, number of
3975 * channels) tuple for each subband, and must have proper
3976 * tuples for the rest of the data as well.
3977 */
3978 if (params->supported_channels_len < 2)
3979 return -EINVAL;
3980 if (params->supported_channels_len % 2)
3981 return -EINVAL;
3982 }
3983
3984 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
3985 params->supported_oper_classes =
3986 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
3987 params->supported_oper_classes_len =
3988 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
3989 /*
3990 * The value of the Length field of the Supported Operating
3991 * Classes element is between 2 and 253.
3992 */
3993 if (params->supported_oper_classes_len < 2 ||
3994 params->supported_oper_classes_len > 253)
3995 return -EINVAL;
3996 }
3997 return 0;
3998}
3999
ff276691
JB
4000static int nl80211_set_station_tdls(struct genl_info *info,
4001 struct station_parameters *params)
4002{
c01fc9ad 4003 int err;
ff276691 4004 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
4005 if (info->attrs[NL80211_ATTR_PEER_AID])
4006 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
4007 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4008 params->ht_capa =
4009 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4010 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4011 params->vht_capa =
4012 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4013
c01fc9ad
SD
4014 err = nl80211_parse_sta_channel_info(info, params);
4015 if (err)
4016 return err;
4017
ff276691
JB
4018 return nl80211_parse_sta_wme(info, params);
4019}
4020
5727ef1b
JB
4021static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
4022{
4c476991 4023 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4024 struct net_device *dev = info->user_ptr[1];
5727ef1b 4025 struct station_parameters params;
77ee7c89
JB
4026 u8 *mac_addr;
4027 int err;
5727ef1b
JB
4028
4029 memset(&params, 0, sizeof(params));
4030
4031 params.listen_interval = -1;
4032
77ee7c89
JB
4033 if (!rdev->ops->change_station)
4034 return -EOPNOTSUPP;
4035
5727ef1b
JB
4036 if (info->attrs[NL80211_ATTR_STA_AID])
4037 return -EINVAL;
4038
4039 if (!info->attrs[NL80211_ATTR_MAC])
4040 return -EINVAL;
4041
4042 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4043
4044 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
4045 params.supported_rates =
4046 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4047 params.supported_rates_len =
4048 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4049 }
4050
9d62a986
JM
4051 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4052 params.capability =
4053 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4054 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4055 }
4056
4057 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4058 params.ext_capab =
4059 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4060 params.ext_capab_len =
4061 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4062 }
4063
df881293 4064 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
ba23d206 4065 return -EINVAL;
36aedc90 4066
bdd3ae3d 4067 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4068 return -EINVAL;
4069
f8bacc21 4070 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
2ec600d6 4071 params.plink_action =
f8bacc21
JB
4072 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4073 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4074 return -EINVAL;
4075 }
2ec600d6 4076
f8bacc21 4077 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 4078 params.plink_state =
f8bacc21
JB
4079 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
4080 if (params.plink_state >= NUM_NL80211_PLINK_STATES)
4081 return -EINVAL;
4082 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
4083 }
9c3990aa 4084
3b1c5a53
MP
4085 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
4086 enum nl80211_mesh_power_mode pm = nla_get_u32(
4087 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
4088
4089 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
4090 pm > NL80211_MESH_POWER_MAX)
4091 return -EINVAL;
4092
4093 params.local_pm = pm;
4094 }
4095
77ee7c89
JB
4096 /* Include parameters for TDLS peer (will check later) */
4097 err = nl80211_set_station_tdls(info, &params);
4098 if (err)
4099 return err;
4100
4101 params.vlan = get_vlan(info, rdev);
4102 if (IS_ERR(params.vlan))
4103 return PTR_ERR(params.vlan);
4104
a97f4424
JB
4105 switch (dev->ieee80211_ptr->iftype) {
4106 case NL80211_IFTYPE_AP:
4107 case NL80211_IFTYPE_AP_VLAN:
074ac8df 4108 case NL80211_IFTYPE_P2P_GO:
074ac8df 4109 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 4110 case NL80211_IFTYPE_STATION:
267335d6 4111 case NL80211_IFTYPE_ADHOC:
a97f4424 4112 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
4113 break;
4114 default:
77ee7c89
JB
4115 err = -EOPNOTSUPP;
4116 goto out_put_vlan;
034d655e
JB
4117 }
4118
77ee7c89 4119 /* driver will call cfg80211_check_station_change() */
e35e4d28 4120 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 4121
77ee7c89 4122 out_put_vlan:
5727ef1b
JB
4123 if (params.vlan)
4124 dev_put(params.vlan);
3b85875a 4125
5727ef1b
JB
4126 return err;
4127}
4128
4129static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
4130{
4c476991 4131 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 4132 int err;
4c476991 4133 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4134 struct station_parameters params;
4135 u8 *mac_addr = NULL;
4136
4137 memset(&params, 0, sizeof(params));
4138
984c311b
JB
4139 if (!rdev->ops->add_station)
4140 return -EOPNOTSUPP;
4141
5727ef1b
JB
4142 if (!info->attrs[NL80211_ATTR_MAC])
4143 return -EINVAL;
4144
5727ef1b
JB
4145 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
4146 return -EINVAL;
4147
4148 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
4149 return -EINVAL;
4150
5e4b6f56
JM
4151 if (!info->attrs[NL80211_ATTR_STA_AID] &&
4152 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
4153 return -EINVAL;
4154
5727ef1b
JB
4155 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4156 params.supported_rates =
4157 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4158 params.supported_rates_len =
4159 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4160 params.listen_interval =
4161 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 4162
3d124ea2 4163 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 4164 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
4165 else
4166 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
0e956c13
TLSC
4167 if (!params.aid || params.aid > IEEE80211_MAX_AID)
4168 return -EINVAL;
51b50fbe 4169
9d62a986
JM
4170 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4171 params.capability =
4172 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4173 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4174 }
4175
4176 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4177 params.ext_capab =
4178 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4179 params.ext_capab_len =
4180 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4181 }
4182
36aedc90
JM
4183 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4184 params.ht_capa =
4185 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 4186
f461be3e
MP
4187 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4188 params.vht_capa =
4189 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4190
60f4a7b1
MK
4191 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
4192 params.opmode_notif_used = true;
4193 params.opmode_notif =
4194 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
4195 }
4196
f8bacc21 4197 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
96b78dff 4198 params.plink_action =
f8bacc21
JB
4199 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4200 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4201 return -EINVAL;
4202 }
96b78dff 4203
c01fc9ad
SD
4204 err = nl80211_parse_sta_channel_info(info, &params);
4205 if (err)
4206 return err;
4207
ff276691
JB
4208 err = nl80211_parse_sta_wme(info, &params);
4209 if (err)
4210 return err;
bdd90d5e 4211
bdd3ae3d 4212 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4213 return -EINVAL;
4214
77ee7c89
JB
4215 /* When you run into this, adjust the code below for the new flag */
4216 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
4217
bdd90d5e
JB
4218 switch (dev->ieee80211_ptr->iftype) {
4219 case NL80211_IFTYPE_AP:
4220 case NL80211_IFTYPE_AP_VLAN:
4221 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
4222 /* ignore WME attributes if iface/sta is not capable */
4223 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
4224 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
4225 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 4226
bdd90d5e 4227 /* TDLS peers cannot be added */
3d124ea2
JM
4228 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4229 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 4230 return -EINVAL;
bdd90d5e
JB
4231 /* but don't bother the driver with it */
4232 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 4233
d582cffb
JB
4234 /* allow authenticated/associated only if driver handles it */
4235 if (!(rdev->wiphy.features &
4236 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4237 params.sta_flags_mask &
4238 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4239 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4240 return -EINVAL;
4241
bdd90d5e
JB
4242 /* must be last in here for error handling */
4243 params.vlan = get_vlan(info, rdev);
4244 if (IS_ERR(params.vlan))
4245 return PTR_ERR(params.vlan);
4246 break;
4247 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
4248 /* ignore uAPSD data */
4249 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4250
d582cffb
JB
4251 /* associated is disallowed */
4252 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
4253 return -EINVAL;
bdd90d5e 4254 /* TDLS peers cannot be added */
3d124ea2
JM
4255 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
4256 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
4257 return -EINVAL;
4258 break;
4259 case NL80211_IFTYPE_STATION:
93d08f0b 4260 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
4261 /* ignore uAPSD data */
4262 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
4263
77ee7c89
JB
4264 /* these are disallowed */
4265 if (params.sta_flags_mask &
4266 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
4267 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 4268 return -EINVAL;
bdd90d5e
JB
4269 /* Only TDLS peers can be added */
4270 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
4271 return -EINVAL;
4272 /* Can only add if TDLS ... */
4273 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
4274 return -EOPNOTSUPP;
4275 /* ... with external setup is supported */
4276 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
4277 return -EOPNOTSUPP;
77ee7c89
JB
4278 /*
4279 * Older wpa_supplicant versions always mark the TDLS peer
4280 * as authorized, but it shouldn't yet be.
4281 */
4282 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
4283 break;
4284 default:
4285 return -EOPNOTSUPP;
c75786c9
EP
4286 }
4287
bdd90d5e 4288 /* be aware of params.vlan when changing code here */
5727ef1b 4289
e35e4d28 4290 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 4291
5727ef1b
JB
4292 if (params.vlan)
4293 dev_put(params.vlan);
5727ef1b
JB
4294 return err;
4295}
4296
4297static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
4298{
4c476991
JB
4299 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4300 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
4301 u8 *mac_addr = NULL;
4302
4303 if (info->attrs[NL80211_ATTR_MAC])
4304 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4305
e80cf853 4306 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 4307 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 4308 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4309 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4310 return -EINVAL;
5727ef1b 4311
4c476991
JB
4312 if (!rdev->ops->del_station)
4313 return -EOPNOTSUPP;
3b85875a 4314
e35e4d28 4315 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
4316}
4317
15e47304 4318static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
4319 int flags, struct net_device *dev,
4320 u8 *dst, u8 *next_hop,
4321 struct mpath_info *pinfo)
4322{
4323 void *hdr;
4324 struct nlattr *pinfoattr;
4325
15e47304 4326 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
4327 if (!hdr)
4328 return -1;
4329
9360ffd1
DM
4330 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4331 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
4332 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
4333 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
4334 goto nla_put_failure;
f5ea9120 4335
2ec600d6
LCC
4336 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
4337 if (!pinfoattr)
4338 goto nla_put_failure;
9360ffd1
DM
4339 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
4340 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
4341 pinfo->frame_qlen))
4342 goto nla_put_failure;
4343 if (((pinfo->filled & MPATH_INFO_SN) &&
4344 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
4345 ((pinfo->filled & MPATH_INFO_METRIC) &&
4346 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
4347 pinfo->metric)) ||
4348 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
4349 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
4350 pinfo->exptime)) ||
4351 ((pinfo->filled & MPATH_INFO_FLAGS) &&
4352 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
4353 pinfo->flags)) ||
4354 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
4355 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
4356 pinfo->discovery_timeout)) ||
4357 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
4358 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
4359 pinfo->discovery_retries)))
4360 goto nla_put_failure;
2ec600d6
LCC
4361
4362 nla_nest_end(msg, pinfoattr);
4363
4364 return genlmsg_end(msg, hdr);
4365
4366 nla_put_failure:
bc3ed28c
TG
4367 genlmsg_cancel(msg, hdr);
4368 return -EMSGSIZE;
2ec600d6
LCC
4369}
4370
4371static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 4372 struct netlink_callback *cb)
2ec600d6 4373{
2ec600d6
LCC
4374 struct mpath_info pinfo;
4375 struct cfg80211_registered_device *dev;
97990a06 4376 struct wireless_dev *wdev;
2ec600d6
LCC
4377 u8 dst[ETH_ALEN];
4378 u8 next_hop[ETH_ALEN];
97990a06 4379 int path_idx = cb->args[2];
2ec600d6 4380 int err;
2ec600d6 4381
97990a06 4382 err = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
4383 if (err)
4384 return err;
bba95fef
JB
4385
4386 if (!dev->ops->dump_mpath) {
eec60b03 4387 err = -EOPNOTSUPP;
bba95fef
JB
4388 goto out_err;
4389 }
4390
97990a06 4391 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 4392 err = -EOPNOTSUPP;
0448b5fc 4393 goto out_err;
eec60b03
JM
4394 }
4395
bba95fef 4396 while (1) {
97990a06
JB
4397 err = rdev_dump_mpath(dev, wdev->netdev, path_idx, dst,
4398 next_hop, &pinfo);
bba95fef 4399 if (err == -ENOENT)
2ec600d6 4400 break;
bba95fef 4401 if (err)
3b85875a 4402 goto out_err;
2ec600d6 4403
15e47304 4404 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 4405 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 4406 wdev->netdev, dst, next_hop,
bba95fef
JB
4407 &pinfo) < 0)
4408 goto out;
2ec600d6 4409
bba95fef 4410 path_idx++;
2ec600d6 4411 }
2ec600d6 4412
2ec600d6 4413
bba95fef 4414 out:
97990a06 4415 cb->args[2] = path_idx;
bba95fef 4416 err = skb->len;
bba95fef 4417 out_err:
97990a06 4418 nl80211_finish_wdev_dump(dev);
bba95fef 4419 return err;
2ec600d6
LCC
4420}
4421
4422static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
4423{
4c476991 4424 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 4425 int err;
4c476991 4426 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4427 struct mpath_info pinfo;
4428 struct sk_buff *msg;
4429 u8 *dst = NULL;
4430 u8 next_hop[ETH_ALEN];
4431
4432 memset(&pinfo, 0, sizeof(pinfo));
4433
4434 if (!info->attrs[NL80211_ATTR_MAC])
4435 return -EINVAL;
4436
4437 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4438
4c476991
JB
4439 if (!rdev->ops->get_mpath)
4440 return -EOPNOTSUPP;
2ec600d6 4441
4c476991
JB
4442 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4443 return -EOPNOTSUPP;
eec60b03 4444
e35e4d28 4445 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 4446 if (err)
4c476991 4447 return err;
2ec600d6 4448
fd2120ca 4449 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 4450 if (!msg)
4c476991 4451 return -ENOMEM;
2ec600d6 4452
15e47304 4453 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
4454 dev, dst, next_hop, &pinfo) < 0) {
4455 nlmsg_free(msg);
4456 return -ENOBUFS;
4457 }
3b85875a 4458
4c476991 4459 return genlmsg_reply(msg, info);
2ec600d6
LCC
4460}
4461
4462static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
4463{
4c476991
JB
4464 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4465 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4466 u8 *dst = NULL;
4467 u8 *next_hop = NULL;
4468
4469 if (!info->attrs[NL80211_ATTR_MAC])
4470 return -EINVAL;
4471
4472 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4473 return -EINVAL;
4474
4475 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4476 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4477
4c476991
JB
4478 if (!rdev->ops->change_mpath)
4479 return -EOPNOTSUPP;
35a8efe1 4480
4c476991
JB
4481 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4482 return -EOPNOTSUPP;
2ec600d6 4483
e35e4d28 4484 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 4485}
4c476991 4486
2ec600d6
LCC
4487static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
4488{
4c476991
JB
4489 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4490 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4491 u8 *dst = NULL;
4492 u8 *next_hop = NULL;
4493
4494 if (!info->attrs[NL80211_ATTR_MAC])
4495 return -EINVAL;
4496
4497 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
4498 return -EINVAL;
4499
4500 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4501 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
4502
4c476991
JB
4503 if (!rdev->ops->add_mpath)
4504 return -EOPNOTSUPP;
35a8efe1 4505
4c476991
JB
4506 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
4507 return -EOPNOTSUPP;
2ec600d6 4508
e35e4d28 4509 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
4510}
4511
4512static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
4513{
4c476991
JB
4514 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4515 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
4516 u8 *dst = NULL;
4517
4518 if (info->attrs[NL80211_ATTR_MAC])
4519 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
4520
4c476991
JB
4521 if (!rdev->ops->del_mpath)
4522 return -EOPNOTSUPP;
3b85875a 4523
e35e4d28 4524 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
4525}
4526
9f1ba906
JM
4527static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
4528{
4c476991
JB
4529 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4530 struct net_device *dev = info->user_ptr[1];
c56589ed 4531 struct wireless_dev *wdev = dev->ieee80211_ptr;
9f1ba906 4532 struct bss_parameters params;
c56589ed 4533 int err;
9f1ba906
JM
4534
4535 memset(&params, 0, sizeof(params));
4536 /* default to not changing parameters */
4537 params.use_cts_prot = -1;
4538 params.use_short_preamble = -1;
4539 params.use_short_slot_time = -1;
fd8aaaf3 4540 params.ap_isolate = -1;
50b12f59 4541 params.ht_opmode = -1;
53cabad7
JB
4542 params.p2p_ctwindow = -1;
4543 params.p2p_opp_ps = -1;
9f1ba906
JM
4544
4545 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
4546 params.use_cts_prot =
4547 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
4548 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
4549 params.use_short_preamble =
4550 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
4551 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
4552 params.use_short_slot_time =
4553 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
4554 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4555 params.basic_rates =
4556 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4557 params.basic_rates_len =
4558 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4559 }
fd8aaaf3
FF
4560 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
4561 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
4562 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
4563 params.ht_opmode =
4564 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 4565
53cabad7
JB
4566 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
4567 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4568 return -EINVAL;
4569 params.p2p_ctwindow =
4570 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
4571 if (params.p2p_ctwindow < 0)
4572 return -EINVAL;
4573 if (params.p2p_ctwindow != 0 &&
4574 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
4575 return -EINVAL;
4576 }
4577
4578 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
4579 u8 tmp;
4580
4581 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4582 return -EINVAL;
4583 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
4584 if (tmp > 1)
4585 return -EINVAL;
4586 params.p2p_opp_ps = tmp;
4587 if (params.p2p_opp_ps &&
4588 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
4589 return -EINVAL;
4590 }
4591
4c476991
JB
4592 if (!rdev->ops->change_bss)
4593 return -EOPNOTSUPP;
9f1ba906 4594
074ac8df 4595 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
4596 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4597 return -EOPNOTSUPP;
3b85875a 4598
c56589ed
SW
4599 wdev_lock(wdev);
4600 err = rdev_change_bss(rdev, dev, &params);
4601 wdev_unlock(wdev);
4602
4603 return err;
9f1ba906
JM
4604}
4605
b54452b0 4606static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
4607 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
4608 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
4609 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
4610 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
4611 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
4612 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
4613};
4614
4615static int parse_reg_rule(struct nlattr *tb[],
4616 struct ieee80211_reg_rule *reg_rule)
4617{
4618 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
4619 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
4620
4621 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
4622 return -EINVAL;
4623 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
4624 return -EINVAL;
4625 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
4626 return -EINVAL;
4627 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
4628 return -EINVAL;
4629 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
4630 return -EINVAL;
4631
4632 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
4633
4634 freq_range->start_freq_khz =
4635 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
4636 freq_range->end_freq_khz =
4637 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
4638 freq_range->max_bandwidth_khz =
4639 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
4640
4641 power_rule->max_eirp =
4642 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
4643
4644 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
4645 power_rule->max_antenna_gain =
4646 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
4647
4648 return 0;
4649}
4650
4651static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
4652{
4653 int r;
4654 char *data = NULL;
57b5ce07 4655 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 4656
80778f18
LR
4657 /*
4658 * You should only get this when cfg80211 hasn't yet initialized
4659 * completely when built-in to the kernel right between the time
4660 * window between nl80211_init() and regulatory_init(), if that is
4661 * even possible.
4662 */
458f4f9e 4663 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 4664 return -EINPROGRESS;
80778f18 4665
fe33eb39
LR
4666 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4667 return -EINVAL;
b2e1b302
LR
4668
4669 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4670
57b5ce07
LR
4671 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
4672 user_reg_hint_type =
4673 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
4674 else
4675 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
4676
4677 switch (user_reg_hint_type) {
4678 case NL80211_USER_REG_HINT_USER:
4679 case NL80211_USER_REG_HINT_CELL_BASE:
4680 break;
4681 default:
4682 return -EINVAL;
4683 }
4684
4685 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 4686
b2e1b302
LR
4687 return r;
4688}
4689
24bdd9f4 4690static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 4691 struct genl_info *info)
93da9cc1 4692{
4c476991 4693 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4694 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
4695 struct wireless_dev *wdev = dev->ieee80211_ptr;
4696 struct mesh_config cur_params;
4697 int err = 0;
93da9cc1 4698 void *hdr;
4699 struct nlattr *pinfoattr;
4700 struct sk_buff *msg;
4701
29cbe68c
JB
4702 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4703 return -EOPNOTSUPP;
4704
24bdd9f4 4705 if (!rdev->ops->get_mesh_config)
4c476991 4706 return -EOPNOTSUPP;
f3f92586 4707
29cbe68c
JB
4708 wdev_lock(wdev);
4709 /* If not connected, get default parameters */
4710 if (!wdev->mesh_id_len)
4711 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
4712 else
e35e4d28 4713 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
4714 wdev_unlock(wdev);
4715
93da9cc1 4716 if (err)
4c476991 4717 return err;
93da9cc1 4718
4719 /* Draw up a netlink message to send back */
fd2120ca 4720 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4721 if (!msg)
4722 return -ENOMEM;
15e47304 4723 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 4724 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 4725 if (!hdr)
efe1cf0c 4726 goto out;
24bdd9f4 4727 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 4728 if (!pinfoattr)
4729 goto nla_put_failure;
9360ffd1
DM
4730 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4731 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
4732 cur_params.dot11MeshRetryTimeout) ||
4733 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4734 cur_params.dot11MeshConfirmTimeout) ||
4735 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
4736 cur_params.dot11MeshHoldingTimeout) ||
4737 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
4738 cur_params.dot11MeshMaxPeerLinks) ||
4739 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
4740 cur_params.dot11MeshMaxRetries) ||
4741 nla_put_u8(msg, NL80211_MESHCONF_TTL,
4742 cur_params.dot11MeshTTL) ||
4743 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
4744 cur_params.element_ttl) ||
4745 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4746 cur_params.auto_open_plinks) ||
7eab0f64
JL
4747 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4748 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
4749 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4750 cur_params.dot11MeshHWMPmaxPREQretries) ||
4751 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
4752 cur_params.path_refresh_time) ||
4753 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4754 cur_params.min_discovery_timeout) ||
4755 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4756 cur_params.dot11MeshHWMPactivePathTimeout) ||
4757 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4758 cur_params.dot11MeshHWMPpreqMinInterval) ||
4759 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4760 cur_params.dot11MeshHWMPperrMinInterval) ||
4761 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4762 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
4763 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
4764 cur_params.dot11MeshHWMPRootMode) ||
4765 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4766 cur_params.dot11MeshHWMPRannInterval) ||
4767 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4768 cur_params.dot11MeshGateAnnouncementProtocol) ||
4769 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
4770 cur_params.dot11MeshForwarding) ||
4771 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
4772 cur_params.rssi_threshold) ||
4773 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4774 cur_params.ht_opmode) ||
4775 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4776 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
4777 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4778 cur_params.dot11MeshHWMProotInterval) ||
4779 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
4780 cur_params.dot11MeshHWMPconfirmationInterval) ||
4781 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
4782 cur_params.power_mode) ||
4783 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
4784 cur_params.dot11MeshAwakeWindowDuration) ||
4785 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
4786 cur_params.plink_timeout))
9360ffd1 4787 goto nla_put_failure;
93da9cc1 4788 nla_nest_end(msg, pinfoattr);
4789 genlmsg_end(msg, hdr);
4c476991 4790 return genlmsg_reply(msg, info);
93da9cc1 4791
3b85875a 4792 nla_put_failure:
93da9cc1 4793 genlmsg_cancel(msg, hdr);
efe1cf0c 4794 out:
d080e275 4795 nlmsg_free(msg);
4c476991 4796 return -ENOBUFS;
93da9cc1 4797}
4798
b54452b0 4799static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 4800 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
4801 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
4802 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
4803 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
4804 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
4805 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 4806 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 4807 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 4808 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 4809 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
4810 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
4811 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
4812 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
4813 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 4814 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 4815 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 4816 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 4817 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 4818 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 4819 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4820 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4821 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4822 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4823 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4824 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4825 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4826 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 4827 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
93da9cc1 4828};
4829
c80d545d
JC
4830static const struct nla_policy
4831 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4832 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4833 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4834 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4835 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 4836 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 4837 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
581a8b0f 4838 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4839 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4840 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4841};
4842
24bdd9f4 4843static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4844 struct mesh_config *cfg,
4845 u32 *mask_out)
93da9cc1 4846{
93da9cc1 4847 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4848 u32 mask = 0;
93da9cc1 4849
ea54fba2
MP
4850#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4851do { \
4852 if (tb[attr]) { \
4853 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4854 return -EINVAL; \
4855 cfg->param = fn(tb[attr]); \
4856 mask |= (1 << (attr - 1)); \
4857 } \
4858} while (0)
bd90fdcc
JB
4859
4860
24bdd9f4 4861 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4862 return -EINVAL;
4863 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4864 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4865 nl80211_meshconf_params_policy))
93da9cc1 4866 return -EINVAL;
4867
93da9cc1 4868 /* This makes sure that there aren't more than 32 mesh config
4869 * parameters (otherwise our bitfield scheme would not work.) */
4870 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4871
4872 /* Fill in the params struct */
ea54fba2 4873 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4874 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4875 nla_get_u16);
ea54fba2 4876 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4877 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4878 nla_get_u16);
ea54fba2 4879 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4880 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4881 nla_get_u16);
ea54fba2 4882 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4883 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4884 nla_get_u16);
ea54fba2 4885 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4886 mask, NL80211_MESHCONF_MAX_RETRIES,
4887 nla_get_u8);
ea54fba2 4888 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4889 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4890 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4891 mask, NL80211_MESHCONF_ELEMENT_TTL,
4892 nla_get_u8);
ea54fba2 4893 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4894 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4895 nla_get_u8);
ea54fba2
MP
4896 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4897 1, 255, mask,
a4f606ea
CYY
4898 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4899 nla_get_u32);
ea54fba2 4900 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4901 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4902 nla_get_u8);
ea54fba2 4903 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4904 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4905 nla_get_u32);
ea54fba2 4906 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4907 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4908 nla_get_u16);
ea54fba2
MP
4909 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4910 1, 65535, mask,
a4f606ea
CYY
4911 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4912 nla_get_u32);
93da9cc1 4913 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4914 1, 65535, mask,
4915 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4916 nla_get_u16);
dca7e943 4917 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4918 1, 65535, mask,
4919 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4920 nla_get_u16);
93da9cc1 4921 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4922 dot11MeshHWMPnetDiameterTraversalTime,
4923 1, 65535, mask,
a4f606ea
CYY
4924 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4925 nla_get_u16);
ea54fba2
MP
4926 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4927 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4928 nla_get_u8);
4929 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4930 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4931 nla_get_u16);
63c5723b 4932 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4933 dot11MeshGateAnnouncementProtocol, 0, 1,
4934 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4935 nla_get_u8);
ea54fba2 4936 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4937 mask, NL80211_MESHCONF_FORWARDING,
4938 nla_get_u8);
83374fe9 4939 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0,
a4f606ea 4940 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
83374fe9 4941 nla_get_s32);
ea54fba2 4942 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4943 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4944 nla_get_u16);
4945 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4946 1, 65535, mask,
ac1073a6
CYY
4947 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4948 nla_get_u32);
ea54fba2 4949 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4950 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4951 nla_get_u16);
4952 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4953 dot11MeshHWMPconfirmationInterval,
4954 1, 65535, mask,
728b19e5 4955 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4956 nla_get_u16);
3b1c5a53
MP
4957 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4958 NL80211_MESH_POWER_ACTIVE,
4959 NL80211_MESH_POWER_MAX,
4960 mask, NL80211_MESHCONF_POWER_MODE,
4961 nla_get_u32);
4962 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4963 0, 65535, mask,
4964 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
8e7c0538
CT
4965 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 1, 0xffffffff,
4966 mask, NL80211_MESHCONF_PLINK_TIMEOUT,
4967 nla_get_u32);
bd90fdcc
JB
4968 if (mask_out)
4969 *mask_out = mask;
c80d545d 4970
bd90fdcc
JB
4971 return 0;
4972
4973#undef FILL_IN_MESH_PARAM_IF_SET
4974}
4975
c80d545d
JC
4976static int nl80211_parse_mesh_setup(struct genl_info *info,
4977 struct mesh_setup *setup)
4978{
bb2798d4 4979 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
4980 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4981
4982 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4983 return -EINVAL;
4984 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4985 info->attrs[NL80211_ATTR_MESH_SETUP],
4986 nl80211_mesh_setup_params_policy))
4987 return -EINVAL;
4988
d299a1f2
JC
4989 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4990 setup->sync_method =
4991 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4992 IEEE80211_SYNC_METHOD_VENDOR :
4993 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4994
c80d545d
JC
4995 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4996 setup->path_sel_proto =
4997 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4998 IEEE80211_PATH_PROTOCOL_VENDOR :
4999 IEEE80211_PATH_PROTOCOL_HWMP;
5000
5001 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
5002 setup->path_metric =
5003 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
5004 IEEE80211_PATH_METRIC_VENDOR :
5005 IEEE80211_PATH_METRIC_AIRTIME;
5006
581a8b0f
JC
5007
5008 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 5009 struct nlattr *ieattr =
581a8b0f 5010 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
5011 if (!is_valid_ie_attr(ieattr))
5012 return -EINVAL;
581a8b0f
JC
5013 setup->ie = nla_data(ieattr);
5014 setup->ie_len = nla_len(ieattr);
c80d545d 5015 }
bb2798d4
TP
5016 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
5017 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
5018 return -EINVAL;
5019 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
5020 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
5021 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
5022 if (setup->is_secure)
5023 setup->user_mpm = true;
c80d545d 5024
6e16d90b
CT
5025 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
5026 if (!setup->user_mpm)
5027 return -EINVAL;
5028 setup->auth_id =
5029 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
5030 }
5031
c80d545d
JC
5032 return 0;
5033}
5034
24bdd9f4 5035static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 5036 struct genl_info *info)
bd90fdcc
JB
5037{
5038 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5039 struct net_device *dev = info->user_ptr[1];
29cbe68c 5040 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
5041 struct mesh_config cfg;
5042 u32 mask;
5043 int err;
5044
29cbe68c
JB
5045 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
5046 return -EOPNOTSUPP;
5047
24bdd9f4 5048 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
5049 return -EOPNOTSUPP;
5050
24bdd9f4 5051 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
5052 if (err)
5053 return err;
5054
29cbe68c
JB
5055 wdev_lock(wdev);
5056 if (!wdev->mesh_id_len)
5057 err = -ENOLINK;
5058
5059 if (!err)
e35e4d28 5060 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
5061
5062 wdev_unlock(wdev);
5063
5064 return err;
93da9cc1 5065}
5066
f130347c
LR
5067static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
5068{
458f4f9e 5069 const struct ieee80211_regdomain *regdom;
f130347c
LR
5070 struct sk_buff *msg;
5071 void *hdr = NULL;
5072 struct nlattr *nl_reg_rules;
5073 unsigned int i;
f130347c
LR
5074
5075 if (!cfg80211_regdomain)
5fe231e8 5076 return -EINVAL;
f130347c 5077
fd2120ca 5078 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5fe231e8
JB
5079 if (!msg)
5080 return -ENOBUFS;
f130347c 5081
15e47304 5082 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
5083 NL80211_CMD_GET_REG);
5084 if (!hdr)
efe1cf0c 5085 goto put_failure;
f130347c 5086
57b5ce07
LR
5087 if (reg_last_request_cell_base() &&
5088 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
5089 NL80211_USER_REG_HINT_CELL_BASE))
5090 goto nla_put_failure;
5091
458f4f9e
JB
5092 rcu_read_lock();
5093 regdom = rcu_dereference(cfg80211_regdomain);
5094
5095 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
5096 (regdom->dfs_region &&
5097 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
5098 goto nla_put_failure_rcu;
5099
f130347c
LR
5100 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
5101 if (!nl_reg_rules)
458f4f9e 5102 goto nla_put_failure_rcu;
f130347c 5103
458f4f9e 5104 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
5105 struct nlattr *nl_reg_rule;
5106 const struct ieee80211_reg_rule *reg_rule;
5107 const struct ieee80211_freq_range *freq_range;
5108 const struct ieee80211_power_rule *power_rule;
5109
458f4f9e 5110 reg_rule = &regdom->reg_rules[i];
f130347c
LR
5111 freq_range = &reg_rule->freq_range;
5112 power_rule = &reg_rule->power_rule;
5113
5114 nl_reg_rule = nla_nest_start(msg, i);
5115 if (!nl_reg_rule)
458f4f9e 5116 goto nla_put_failure_rcu;
f130347c 5117
9360ffd1
DM
5118 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
5119 reg_rule->flags) ||
5120 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
5121 freq_range->start_freq_khz) ||
5122 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
5123 freq_range->end_freq_khz) ||
5124 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
5125 freq_range->max_bandwidth_khz) ||
5126 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
5127 power_rule->max_antenna_gain) ||
5128 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
5129 power_rule->max_eirp))
458f4f9e 5130 goto nla_put_failure_rcu;
f130347c
LR
5131
5132 nla_nest_end(msg, nl_reg_rule);
5133 }
458f4f9e 5134 rcu_read_unlock();
f130347c
LR
5135
5136 nla_nest_end(msg, nl_reg_rules);
5137
5138 genlmsg_end(msg, hdr);
5fe231e8 5139 return genlmsg_reply(msg, info);
f130347c 5140
458f4f9e
JB
5141nla_put_failure_rcu:
5142 rcu_read_unlock();
f130347c
LR
5143nla_put_failure:
5144 genlmsg_cancel(msg, hdr);
efe1cf0c 5145put_failure:
d080e275 5146 nlmsg_free(msg);
5fe231e8 5147 return -EMSGSIZE;
f130347c
LR
5148}
5149
b2e1b302
LR
5150static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
5151{
5152 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
5153 struct nlattr *nl_reg_rule;
5154 char *alpha2 = NULL;
5155 int rem_reg_rules = 0, r = 0;
5156 u32 num_rules = 0, rule_idx = 0, size_of_regd;
4c7d3982 5157 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
b2e1b302
LR
5158 struct ieee80211_regdomain *rd = NULL;
5159
5160 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
5161 return -EINVAL;
5162
5163 if (!info->attrs[NL80211_ATTR_REG_RULES])
5164 return -EINVAL;
5165
5166 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
5167
8b60b078
LR
5168 if (info->attrs[NL80211_ATTR_DFS_REGION])
5169 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
5170
b2e1b302 5171 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5172 rem_reg_rules) {
b2e1b302
LR
5173 num_rules++;
5174 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 5175 return -EINVAL;
b2e1b302
LR
5176 }
5177
e438768f
LR
5178 if (!reg_is_valid_request(alpha2))
5179 return -EINVAL;
5180
b2e1b302 5181 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 5182 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
5183
5184 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
5185 if (!rd)
5186 return -ENOMEM;
b2e1b302
LR
5187
5188 rd->n_reg_rules = num_rules;
5189 rd->alpha2[0] = alpha2[0];
5190 rd->alpha2[1] = alpha2[1];
5191
8b60b078
LR
5192 /*
5193 * Disable DFS master mode if the DFS region was
5194 * not supported or known on this kernel.
5195 */
5196 if (reg_supported_dfs_region(dfs_region))
5197 rd->dfs_region = dfs_region;
5198
b2e1b302 5199 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 5200 rem_reg_rules) {
b2e1b302 5201 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
5202 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
5203 reg_rule_policy);
b2e1b302
LR
5204 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
5205 if (r)
5206 goto bad_reg;
5207
5208 rule_idx++;
5209
d0e18f83
LR
5210 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
5211 r = -EINVAL;
b2e1b302 5212 goto bad_reg;
d0e18f83 5213 }
b2e1b302
LR
5214 }
5215
b2e1b302 5216 r = set_regdom(rd);
6913b49a 5217 /* set_regdom took ownership */
1a919318 5218 rd = NULL;
b2e1b302 5219
d2372b31 5220 bad_reg:
b2e1b302 5221 kfree(rd);
d0e18f83 5222 return r;
b2e1b302
LR
5223}
5224
83f5e2cf
JB
5225static int validate_scan_freqs(struct nlattr *freqs)
5226{
5227 struct nlattr *attr1, *attr2;
5228 int n_channels = 0, tmp1, tmp2;
5229
5230 nla_for_each_nested(attr1, freqs, tmp1) {
5231 n_channels++;
5232 /*
5233 * Some hardware has a limited channel list for
5234 * scanning, and it is pretty much nonsensical
5235 * to scan for a channel twice, so disallow that
5236 * and don't require drivers to check that the
5237 * channel list they get isn't longer than what
5238 * they can scan, as long as they can scan all
5239 * the channels they registered at once.
5240 */
5241 nla_for_each_nested(attr2, freqs, tmp2)
5242 if (attr1 != attr2 &&
5243 nla_get_u32(attr1) == nla_get_u32(attr2))
5244 return 0;
5245 }
5246
5247 return n_channels;
5248}
5249
2a519311
JB
5250static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
5251{
4c476991 5252 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 5253 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 5254 struct cfg80211_scan_request *request;
2a519311
JB
5255 struct nlattr *attr;
5256 struct wiphy *wiphy;
83f5e2cf 5257 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 5258 size_t ie_len;
2a519311 5259
f4a11bb0
JB
5260 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5261 return -EINVAL;
5262
79c97e97 5263 wiphy = &rdev->wiphy;
2a519311 5264
4c476991
JB
5265 if (!rdev->ops->scan)
5266 return -EOPNOTSUPP;
2a519311 5267
f9f47529
JB
5268 if (rdev->scan_req) {
5269 err = -EBUSY;
5270 goto unlock;
5271 }
2a519311
JB
5272
5273 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
5274 n_channels = validate_scan_freqs(
5275 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
5276 if (!n_channels) {
5277 err = -EINVAL;
5278 goto unlock;
5279 }
2a519311 5280 } else {
bdfbec2d 5281 n_channels = ieee80211_get_num_supported_channels(wiphy);
2a519311
JB
5282 }
5283
5284 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5285 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
5286 n_ssids++;
5287
f9f47529
JB
5288 if (n_ssids > wiphy->max_scan_ssids) {
5289 err = -EINVAL;
5290 goto unlock;
5291 }
2a519311 5292
70692ad2
JM
5293 if (info->attrs[NL80211_ATTR_IE])
5294 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5295 else
5296 ie_len = 0;
5297
f9f47529
JB
5298 if (ie_len > wiphy->max_scan_ie_len) {
5299 err = -EINVAL;
5300 goto unlock;
5301 }
18a83659 5302
2a519311 5303 request = kzalloc(sizeof(*request)
a2cd43c5
LC
5304 + sizeof(*request->ssids) * n_ssids
5305 + sizeof(*request->channels) * n_channels
70692ad2 5306 + ie_len, GFP_KERNEL);
f9f47529
JB
5307 if (!request) {
5308 err = -ENOMEM;
5309 goto unlock;
5310 }
2a519311 5311
2a519311 5312 if (n_ssids)
5ba63533 5313 request->ssids = (void *)&request->channels[n_channels];
2a519311 5314 request->n_ssids = n_ssids;
70692ad2
JM
5315 if (ie_len) {
5316 if (request->ssids)
5317 request->ie = (void *)(request->ssids + n_ssids);
5318 else
5319 request->ie = (void *)(request->channels + n_channels);
5320 }
2a519311 5321
584991dc 5322 i = 0;
2a519311
JB
5323 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5324 /* user specified, bail out if channel not found */
2a519311 5325 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
5326 struct ieee80211_channel *chan;
5327
5328 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5329
5330 if (!chan) {
2a519311
JB
5331 err = -EINVAL;
5332 goto out_free;
5333 }
584991dc
JB
5334
5335 /* ignore disabled channels */
5336 if (chan->flags & IEEE80211_CHAN_DISABLED)
5337 continue;
5338
5339 request->channels[i] = chan;
2a519311
JB
5340 i++;
5341 }
5342 } else {
34850ab2
JB
5343 enum ieee80211_band band;
5344
2a519311 5345 /* all channels */
2a519311
JB
5346 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5347 int j;
5348 if (!wiphy->bands[band])
5349 continue;
5350 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
5351 struct ieee80211_channel *chan;
5352
5353 chan = &wiphy->bands[band]->channels[j];
5354
5355 if (chan->flags & IEEE80211_CHAN_DISABLED)
5356 continue;
5357
5358 request->channels[i] = chan;
2a519311
JB
5359 i++;
5360 }
5361 }
5362 }
5363
584991dc
JB
5364 if (!i) {
5365 err = -EINVAL;
5366 goto out_free;
5367 }
5368
5369 request->n_channels = i;
5370
2a519311
JB
5371 i = 0;
5372 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
5373 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 5374 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
5375 err = -EINVAL;
5376 goto out_free;
5377 }
57a27e1d 5378 request->ssids[i].ssid_len = nla_len(attr);
2a519311 5379 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
5380 i++;
5381 }
5382 }
5383
70692ad2
JM
5384 if (info->attrs[NL80211_ATTR_IE]) {
5385 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
5386 memcpy((void *)request->ie,
5387 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
5388 request->ie_len);
5389 }
5390
34850ab2 5391 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
5392 if (wiphy->bands[i])
5393 request->rates[i] =
5394 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
5395
5396 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
5397 nla_for_each_nested(attr,
5398 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
5399 tmp) {
5400 enum ieee80211_band band = nla_type(attr);
5401
84404623 5402 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
5403 err = -EINVAL;
5404 goto out_free;
5405 }
1b09cd82
FF
5406
5407 if (!wiphy->bands[band])
5408 continue;
5409
34850ab2
JB
5410 err = ieee80211_get_ratemask(wiphy->bands[band],
5411 nla_data(attr),
5412 nla_len(attr),
5413 &request->rates[band]);
5414 if (err)
5415 goto out_free;
5416 }
5417 }
5418
46856bbf 5419 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5420 request->flags = nla_get_u32(
5421 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
00c3a6ed
JB
5422 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5423 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) {
46856bbf
SL
5424 err = -EOPNOTSUPP;
5425 goto out_free;
5426 }
5427 }
ed473771 5428
e9f935e3
RM
5429 request->no_cck =
5430 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5431
fd014284 5432 request->wdev = wdev;
79c97e97 5433 request->wiphy = &rdev->wiphy;
15d6030b 5434 request->scan_start = jiffies;
2a519311 5435
79c97e97 5436 rdev->scan_req = request;
e35e4d28 5437 err = rdev_scan(rdev, request);
2a519311 5438
463d0183 5439 if (!err) {
fd014284
JB
5440 nl80211_send_scan_start(rdev, wdev);
5441 if (wdev->netdev)
5442 dev_hold(wdev->netdev);
4c476991 5443 } else {
2a519311 5444 out_free:
79c97e97 5445 rdev->scan_req = NULL;
2a519311
JB
5446 kfree(request);
5447 }
3b85875a 5448
f9f47529 5449 unlock:
2a519311
JB
5450 return err;
5451}
5452
807f8a8c
LC
5453static int nl80211_start_sched_scan(struct sk_buff *skb,
5454 struct genl_info *info)
5455{
5456 struct cfg80211_sched_scan_request *request;
5457 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5458 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
5459 struct nlattr *attr;
5460 struct wiphy *wiphy;
a1f1c21c 5461 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 5462 u32 interval;
807f8a8c
LC
5463 enum ieee80211_band band;
5464 size_t ie_len;
a1f1c21c 5465 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
5466
5467 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5468 !rdev->ops->sched_scan_start)
5469 return -EOPNOTSUPP;
5470
5471 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5472 return -EINVAL;
5473
bbe6ad6d
LC
5474 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
5475 return -EINVAL;
5476
5477 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
5478 if (interval == 0)
5479 return -EINVAL;
5480
807f8a8c
LC
5481 wiphy = &rdev->wiphy;
5482
5483 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5484 n_channels = validate_scan_freqs(
5485 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
5486 if (!n_channels)
5487 return -EINVAL;
5488 } else {
bdfbec2d 5489 n_channels = ieee80211_get_num_supported_channels(wiphy);
807f8a8c
LC
5490 }
5491
5492 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
5493 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
5494 tmp)
5495 n_ssids++;
5496
93b6aa69 5497 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
5498 return -EINVAL;
5499
a1f1c21c
LC
5500 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
5501 nla_for_each_nested(attr,
5502 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
5503 tmp)
5504 n_match_sets++;
5505
5506 if (n_match_sets > wiphy->max_match_sets)
5507 return -EINVAL;
5508
807f8a8c
LC
5509 if (info->attrs[NL80211_ATTR_IE])
5510 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5511 else
5512 ie_len = 0;
5513
5a865bad 5514 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
5515 return -EINVAL;
5516
c10841ca
LC
5517 if (rdev->sched_scan_req) {
5518 err = -EINPROGRESS;
5519 goto out;
5520 }
5521
807f8a8c 5522 request = kzalloc(sizeof(*request)
a2cd43c5 5523 + sizeof(*request->ssids) * n_ssids
a1f1c21c 5524 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 5525 + sizeof(*request->channels) * n_channels
807f8a8c 5526 + ie_len, GFP_KERNEL);
c10841ca
LC
5527 if (!request) {
5528 err = -ENOMEM;
5529 goto out;
5530 }
807f8a8c
LC
5531
5532 if (n_ssids)
5533 request->ssids = (void *)&request->channels[n_channels];
5534 request->n_ssids = n_ssids;
5535 if (ie_len) {
5536 if (request->ssids)
5537 request->ie = (void *)(request->ssids + n_ssids);
5538 else
5539 request->ie = (void *)(request->channels + n_channels);
5540 }
5541
a1f1c21c
LC
5542 if (n_match_sets) {
5543 if (request->ie)
5544 request->match_sets = (void *)(request->ie + ie_len);
5545 else if (request->ssids)
5546 request->match_sets =
5547 (void *)(request->ssids + n_ssids);
5548 else
5549 request->match_sets =
5550 (void *)(request->channels + n_channels);
5551 }
5552 request->n_match_sets = n_match_sets;
5553
807f8a8c
LC
5554 i = 0;
5555 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
5556 /* user specified, bail out if channel not found */
5557 nla_for_each_nested(attr,
5558 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
5559 tmp) {
5560 struct ieee80211_channel *chan;
5561
5562 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
5563
5564 if (!chan) {
5565 err = -EINVAL;
5566 goto out_free;
5567 }
5568
5569 /* ignore disabled channels */
5570 if (chan->flags & IEEE80211_CHAN_DISABLED)
5571 continue;
5572
5573 request->channels[i] = chan;
5574 i++;
5575 }
5576 } else {
5577 /* all channels */
5578 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5579 int j;
5580 if (!wiphy->bands[band])
5581 continue;
5582 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
5583 struct ieee80211_channel *chan;
5584
5585 chan = &wiphy->bands[band]->channels[j];
5586
5587 if (chan->flags & IEEE80211_CHAN_DISABLED)
5588 continue;
5589
5590 request->channels[i] = chan;
5591 i++;
5592 }
5593 }
5594 }
5595
5596 if (!i) {
5597 err = -EINVAL;
5598 goto out_free;
5599 }
5600
5601 request->n_channels = i;
5602
5603 i = 0;
5604 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
5605 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
5606 tmp) {
57a27e1d 5607 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
5608 err = -EINVAL;
5609 goto out_free;
5610 }
57a27e1d 5611 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
5612 memcpy(request->ssids[i].ssid, nla_data(attr),
5613 nla_len(attr));
807f8a8c
LC
5614 i++;
5615 }
5616 }
5617
a1f1c21c
LC
5618 i = 0;
5619 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
5620 nla_for_each_nested(attr,
5621 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
5622 tmp) {
88e920b4 5623 struct nlattr *ssid, *rssi;
a1f1c21c
LC
5624
5625 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
5626 nla_data(attr), nla_len(attr),
5627 nl80211_match_policy);
4a4ab0d7 5628 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
5629 if (ssid) {
5630 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
5631 err = -EINVAL;
5632 goto out_free;
5633 }
5634 memcpy(request->match_sets[i].ssid.ssid,
5635 nla_data(ssid), nla_len(ssid));
5636 request->match_sets[i].ssid.ssid_len =
5637 nla_len(ssid);
5638 }
88e920b4
TP
5639 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
5640 if (rssi)
5641 request->rssi_thold = nla_get_u32(rssi);
5642 else
5643 request->rssi_thold =
5644 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
5645 i++;
5646 }
5647 }
5648
807f8a8c
LC
5649 if (info->attrs[NL80211_ATTR_IE]) {
5650 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5651 memcpy((void *)request->ie,
5652 nla_data(info->attrs[NL80211_ATTR_IE]),
5653 request->ie_len);
5654 }
5655
46856bbf 5656 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5657 request->flags = nla_get_u32(
5658 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
00c3a6ed
JB
5659 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5660 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) {
46856bbf
SL
5661 err = -EOPNOTSUPP;
5662 goto out_free;
5663 }
5664 }
ed473771 5665
807f8a8c
LC
5666 request->dev = dev;
5667 request->wiphy = &rdev->wiphy;
bbe6ad6d 5668 request->interval = interval;
15d6030b 5669 request->scan_start = jiffies;
807f8a8c 5670
e35e4d28 5671 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
5672 if (!err) {
5673 rdev->sched_scan_req = request;
5674 nl80211_send_sched_scan(rdev, dev,
5675 NL80211_CMD_START_SCHED_SCAN);
5676 goto out;
5677 }
5678
5679out_free:
5680 kfree(request);
5681out:
5682 return err;
5683}
5684
5685static int nl80211_stop_sched_scan(struct sk_buff *skb,
5686 struct genl_info *info)
5687{
5688 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5689
5690 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5691 !rdev->ops->sched_scan_stop)
5692 return -EOPNOTSUPP;
5693
5fe231e8 5694 return __cfg80211_stop_sched_scan(rdev, false);
807f8a8c
LC
5695}
5696
04f39047
SW
5697static int nl80211_start_radar_detection(struct sk_buff *skb,
5698 struct genl_info *info)
5699{
5700 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5701 struct net_device *dev = info->user_ptr[1];
5702 struct wireless_dev *wdev = dev->ieee80211_ptr;
5703 struct cfg80211_chan_def chandef;
55f7435c 5704 enum nl80211_dfs_regions dfs_region;
04f39047
SW
5705 int err;
5706
55f7435c
LR
5707 dfs_region = reg_get_dfs_region(wdev->wiphy);
5708 if (dfs_region == NL80211_DFS_UNSET)
5709 return -EINVAL;
5710
04f39047
SW
5711 err = nl80211_parse_chandef(rdev, info, &chandef);
5712 if (err)
5713 return err;
5714
ff311bc1
SW
5715 if (netif_carrier_ok(dev))
5716 return -EBUSY;
5717
04f39047
SW
5718 if (wdev->cac_started)
5719 return -EBUSY;
5720
5721 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef);
5722 if (err < 0)
5723 return err;
5724
5725 if (err == 0)
5726 return -EINVAL;
5727
fe7c3a1f 5728 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef))
04f39047
SW
5729 return -EINVAL;
5730
5731 if (!rdev->ops->start_radar_detection)
5732 return -EOPNOTSUPP;
5733
04f39047
SW
5734 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
5735 chandef.chan, CHAN_MODE_SHARED,
5736 BIT(chandef.width));
5737 if (err)
5fe231e8 5738 return err;
04f39047
SW
5739
5740 err = rdev->ops->start_radar_detection(&rdev->wiphy, dev, &chandef);
5741 if (!err) {
5742 wdev->channel = chandef.chan;
5743 wdev->cac_started = true;
5744 wdev->cac_start_time = jiffies;
5745 }
04f39047
SW
5746 return err;
5747}
5748
16ef1fe2
SW
5749static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
5750{
5751 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5752 struct net_device *dev = info->user_ptr[1];
5753 struct wireless_dev *wdev = dev->ieee80211_ptr;
5754 struct cfg80211_csa_settings params;
5755 /* csa_attrs is defined static to avoid waste of stack size - this
5756 * function is called under RTNL lock, so this should not be a problem.
5757 */
5758 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
5759 u8 radar_detect_width = 0;
5760 int err;
ee4bc9e7 5761 bool need_new_beacon = false;
16ef1fe2
SW
5762
5763 if (!rdev->ops->channel_switch ||
5764 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
5765 return -EOPNOTSUPP;
5766
ee4bc9e7
SW
5767 switch (dev->ieee80211_ptr->iftype) {
5768 case NL80211_IFTYPE_AP:
5769 case NL80211_IFTYPE_P2P_GO:
5770 need_new_beacon = true;
5771
5772 /* useless if AP is not running */
5773 if (!wdev->beacon_interval)
1ff79dfa 5774 return -ENOTCONN;
ee4bc9e7
SW
5775 break;
5776 case NL80211_IFTYPE_ADHOC:
1ff79dfa
JB
5777 if (!wdev->ssid_len)
5778 return -ENOTCONN;
5779 break;
c6da674a 5780 case NL80211_IFTYPE_MESH_POINT:
1ff79dfa
JB
5781 if (!wdev->mesh_id_len)
5782 return -ENOTCONN;
ee4bc9e7
SW
5783 break;
5784 default:
16ef1fe2 5785 return -EOPNOTSUPP;
ee4bc9e7 5786 }
16ef1fe2
SW
5787
5788 memset(&params, 0, sizeof(params));
5789
5790 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5791 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
5792 return -EINVAL;
5793
5794 /* only important for AP, IBSS and mesh create IEs internally */
d0a361a5 5795 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
16ef1fe2
SW
5796 return -EINVAL;
5797
5798 params.count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
5799
ee4bc9e7
SW
5800 if (!need_new_beacon)
5801 goto skip_beacons;
5802
16ef1fe2
SW
5803 err = nl80211_parse_beacon(info->attrs, &params.beacon_after);
5804 if (err)
5805 return err;
5806
5807 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX,
5808 info->attrs[NL80211_ATTR_CSA_IES],
5809 nl80211_policy);
5810 if (err)
5811 return err;
5812
5813 err = nl80211_parse_beacon(csa_attrs, &params.beacon_csa);
5814 if (err)
5815 return err;
5816
5817 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
5818 return -EINVAL;
5819
5820 params.counter_offset_beacon =
5821 nla_get_u16(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
5822 if (params.counter_offset_beacon >= params.beacon_csa.tail_len)
5823 return -EINVAL;
5824
5825 /* sanity check - counters should be the same */
5826 if (params.beacon_csa.tail[params.counter_offset_beacon] !=
5827 params.count)
5828 return -EINVAL;
5829
5830 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
5831 params.counter_offset_presp =
5832 nla_get_u16(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
5833 if (params.counter_offset_presp >=
5834 params.beacon_csa.probe_resp_len)
5835 return -EINVAL;
5836
5837 if (params.beacon_csa.probe_resp[params.counter_offset_presp] !=
5838 params.count)
5839 return -EINVAL;
5840 }
5841
ee4bc9e7 5842skip_beacons:
16ef1fe2
SW
5843 err = nl80211_parse_chandef(rdev, info, &params.chandef);
5844 if (err)
5845 return err;
5846
5847 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
5848 return -EINVAL;
5849
ee4bc9e7 5850 if (dev->ieee80211_ptr->iftype == NL80211_IFTYPE_AP ||
5336fa88
SW
5851 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO ||
5852 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_ADHOC) {
ee4bc9e7
SW
5853 err = cfg80211_chandef_dfs_required(wdev->wiphy,
5854 &params.chandef);
5855 if (err < 0) {
5856 return err;
5857 } else if (err) {
5858 radar_detect_width = BIT(params.chandef.width);
5859 params.radar_required = true;
5860 }
16ef1fe2
SW
5861 }
5862
5863 err = cfg80211_can_use_iftype_chan(rdev, wdev, wdev->iftype,
5864 params.chandef.chan,
5865 CHAN_MODE_SHARED,
5866 radar_detect_width);
5867 if (err)
5868 return err;
5869
5870 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
5871 params.block_tx = true;
5872
c56589ed
SW
5873 wdev_lock(wdev);
5874 err = rdev_channel_switch(rdev, dev, &params);
5875 wdev_unlock(wdev);
5876
5877 return err;
16ef1fe2
SW
5878}
5879
9720bb3a
JB
5880static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
5881 u32 seq, int flags,
2a519311 5882 struct cfg80211_registered_device *rdev,
48ab905d
JB
5883 struct wireless_dev *wdev,
5884 struct cfg80211_internal_bss *intbss)
2a519311 5885{
48ab905d 5886 struct cfg80211_bss *res = &intbss->pub;
9caf0364 5887 const struct cfg80211_bss_ies *ies;
2a519311
JB
5888 void *hdr;
5889 struct nlattr *bss;
8cef2c9d 5890 bool tsf = false;
48ab905d
JB
5891
5892 ASSERT_WDEV_LOCK(wdev);
2a519311 5893
15e47304 5894 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
5895 NL80211_CMD_NEW_SCAN_RESULTS);
5896 if (!hdr)
5897 return -1;
5898
9720bb3a
JB
5899 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
5900
97990a06
JB
5901 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
5902 goto nla_put_failure;
5903 if (wdev->netdev &&
9360ffd1
DM
5904 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
5905 goto nla_put_failure;
97990a06
JB
5906 if (nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
5907 goto nla_put_failure;
2a519311
JB
5908
5909 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
5910 if (!bss)
5911 goto nla_put_failure;
9360ffd1 5912 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 5913 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 5914 goto nla_put_failure;
9caf0364
JB
5915
5916 rcu_read_lock();
5917 ies = rcu_dereference(res->ies);
8cef2c9d
JB
5918 if (ies) {
5919 if (nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5920 goto fail_unlock_rcu;
5921 tsf = true;
5922 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
5923 ies->len, ies->data))
5924 goto fail_unlock_rcu;
9caf0364
JB
5925 }
5926 ies = rcu_dereference(res->beacon_ies);
8cef2c9d
JB
5927 if (ies) {
5928 if (!tsf && nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5929 goto fail_unlock_rcu;
5930 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
5931 ies->len, ies->data))
5932 goto fail_unlock_rcu;
9caf0364
JB
5933 }
5934 rcu_read_unlock();
5935
9360ffd1
DM
5936 if (res->beacon_interval &&
5937 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
5938 goto nla_put_failure;
5939 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
5940 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
dcd6eac1 5941 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
5942 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
5943 jiffies_to_msecs(jiffies - intbss->ts)))
5944 goto nla_put_failure;
2a519311 5945
77965c97 5946 switch (rdev->wiphy.signal_type) {
2a519311 5947 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
5948 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
5949 goto nla_put_failure;
2a519311
JB
5950 break;
5951 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
5952 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
5953 goto nla_put_failure;
2a519311
JB
5954 break;
5955 default:
5956 break;
5957 }
5958
48ab905d 5959 switch (wdev->iftype) {
074ac8df 5960 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 5961 case NL80211_IFTYPE_STATION:
9360ffd1
DM
5962 if (intbss == wdev->current_bss &&
5963 nla_put_u32(msg, NL80211_BSS_STATUS,
5964 NL80211_BSS_STATUS_ASSOCIATED))
5965 goto nla_put_failure;
48ab905d
JB
5966 break;
5967 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
5968 if (intbss == wdev->current_bss &&
5969 nla_put_u32(msg, NL80211_BSS_STATUS,
5970 NL80211_BSS_STATUS_IBSS_JOINED))
5971 goto nla_put_failure;
48ab905d
JB
5972 break;
5973 default:
5974 break;
5975 }
5976
2a519311
JB
5977 nla_nest_end(msg, bss);
5978
5979 return genlmsg_end(msg, hdr);
5980
8cef2c9d
JB
5981 fail_unlock_rcu:
5982 rcu_read_unlock();
2a519311
JB
5983 nla_put_failure:
5984 genlmsg_cancel(msg, hdr);
5985 return -EMSGSIZE;
5986}
5987
97990a06 5988static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 5989{
48ab905d 5990 struct cfg80211_registered_device *rdev;
2a519311 5991 struct cfg80211_internal_bss *scan;
48ab905d 5992 struct wireless_dev *wdev;
97990a06 5993 int start = cb->args[2], idx = 0;
2a519311
JB
5994 int err;
5995
97990a06 5996 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893
JB
5997 if (err)
5998 return err;
2a519311 5999
48ab905d
JB
6000 wdev_lock(wdev);
6001 spin_lock_bh(&rdev->bss_lock);
6002 cfg80211_bss_expire(rdev);
6003
9720bb3a
JB
6004 cb->seq = rdev->bss_generation;
6005
48ab905d 6006 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
6007 if (++idx <= start)
6008 continue;
9720bb3a 6009 if (nl80211_send_bss(skb, cb,
2a519311 6010 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 6011 rdev, wdev, scan) < 0) {
2a519311 6012 idx--;
67748893 6013 break;
2a519311
JB
6014 }
6015 }
6016
48ab905d
JB
6017 spin_unlock_bh(&rdev->bss_lock);
6018 wdev_unlock(wdev);
2a519311 6019
97990a06
JB
6020 cb->args[2] = idx;
6021 nl80211_finish_wdev_dump(rdev);
2a519311 6022
67748893 6023 return skb->len;
2a519311
JB
6024}
6025
15e47304 6026static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
6027 int flags, struct net_device *dev,
6028 struct survey_info *survey)
6029{
6030 void *hdr;
6031 struct nlattr *infoattr;
6032
15e47304 6033 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
6034 NL80211_CMD_NEW_SURVEY_RESULTS);
6035 if (!hdr)
6036 return -ENOMEM;
6037
9360ffd1
DM
6038 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
6039 goto nla_put_failure;
61fa713c
HS
6040
6041 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
6042 if (!infoattr)
6043 goto nla_put_failure;
6044
9360ffd1
DM
6045 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
6046 survey->channel->center_freq))
6047 goto nla_put_failure;
6048
6049 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
6050 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
6051 goto nla_put_failure;
6052 if ((survey->filled & SURVEY_INFO_IN_USE) &&
6053 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
6054 goto nla_put_failure;
6055 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
6056 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
6057 survey->channel_time))
6058 goto nla_put_failure;
6059 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
6060 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
6061 survey->channel_time_busy))
6062 goto nla_put_failure;
6063 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
6064 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
6065 survey->channel_time_ext_busy))
6066 goto nla_put_failure;
6067 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
6068 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
6069 survey->channel_time_rx))
6070 goto nla_put_failure;
6071 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
6072 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
6073 survey->channel_time_tx))
6074 goto nla_put_failure;
61fa713c
HS
6075
6076 nla_nest_end(msg, infoattr);
6077
6078 return genlmsg_end(msg, hdr);
6079
6080 nla_put_failure:
6081 genlmsg_cancel(msg, hdr);
6082 return -EMSGSIZE;
6083}
6084
6085static int nl80211_dump_survey(struct sk_buff *skb,
6086 struct netlink_callback *cb)
6087{
6088 struct survey_info survey;
6089 struct cfg80211_registered_device *dev;
97990a06
JB
6090 struct wireless_dev *wdev;
6091 int survey_idx = cb->args[2];
61fa713c
HS
6092 int res;
6093
97990a06 6094 res = nl80211_prepare_wdev_dump(skb, cb, &dev, &wdev);
67748893
JB
6095 if (res)
6096 return res;
61fa713c 6097
97990a06
JB
6098 if (!wdev->netdev) {
6099 res = -EINVAL;
6100 goto out_err;
6101 }
6102
61fa713c
HS
6103 if (!dev->ops->dump_survey) {
6104 res = -EOPNOTSUPP;
6105 goto out_err;
6106 }
6107
6108 while (1) {
180cdc79
LR
6109 struct ieee80211_channel *chan;
6110
97990a06 6111 res = rdev_dump_survey(dev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
6112 if (res == -ENOENT)
6113 break;
6114 if (res)
6115 goto out_err;
6116
180cdc79
LR
6117 /* Survey without a channel doesn't make sense */
6118 if (!survey.channel) {
6119 res = -EINVAL;
6120 goto out;
6121 }
6122
6123 chan = ieee80211_get_channel(&dev->wiphy,
6124 survey.channel->center_freq);
6125 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
6126 survey_idx++;
6127 continue;
6128 }
6129
61fa713c 6130 if (nl80211_send_survey(skb,
15e47304 6131 NETLINK_CB(cb->skb).portid,
61fa713c 6132 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 6133 wdev->netdev, &survey) < 0)
61fa713c
HS
6134 goto out;
6135 survey_idx++;
6136 }
6137
6138 out:
97990a06 6139 cb->args[2] = survey_idx;
61fa713c
HS
6140 res = skb->len;
6141 out_err:
97990a06 6142 nl80211_finish_wdev_dump(dev);
61fa713c
HS
6143 return res;
6144}
6145
b23aa676
SO
6146static bool nl80211_valid_wpa_versions(u32 wpa_versions)
6147{
6148 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
6149 NL80211_WPA_VERSION_2));
6150}
6151
636a5d36
JM
6152static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
6153{
4c476991
JB
6154 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6155 struct net_device *dev = info->user_ptr[1];
19957bb3 6156 struct ieee80211_channel *chan;
e39e5b5e
JM
6157 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
6158 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 6159 enum nl80211_auth_type auth_type;
fffd0934 6160 struct key_parse key;
d5cdfacb 6161 bool local_state_change;
636a5d36 6162
f4a11bb0
JB
6163 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6164 return -EINVAL;
6165
6166 if (!info->attrs[NL80211_ATTR_MAC])
6167 return -EINVAL;
6168
1778092e
JM
6169 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
6170 return -EINVAL;
6171
19957bb3
JB
6172 if (!info->attrs[NL80211_ATTR_SSID])
6173 return -EINVAL;
6174
6175 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
6176 return -EINVAL;
6177
fffd0934
JB
6178 err = nl80211_parse_key(info, &key);
6179 if (err)
6180 return err;
6181
6182 if (key.idx >= 0) {
e31b8213
JB
6183 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
6184 return -EINVAL;
fffd0934
JB
6185 if (!key.p.key || !key.p.key_len)
6186 return -EINVAL;
6187 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
6188 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
6189 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
6190 key.p.key_len != WLAN_KEY_LEN_WEP104))
6191 return -EINVAL;
6192 if (key.idx > 4)
6193 return -EINVAL;
6194 } else {
6195 key.p.key_len = 0;
6196 key.p.key = NULL;
6197 }
6198
afea0b7a
JB
6199 if (key.idx >= 0) {
6200 int i;
6201 bool ok = false;
6202 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
6203 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
6204 ok = true;
6205 break;
6206 }
6207 }
4c476991
JB
6208 if (!ok)
6209 return -EINVAL;
afea0b7a
JB
6210 }
6211
4c476991
JB
6212 if (!rdev->ops->auth)
6213 return -EOPNOTSUPP;
636a5d36 6214
074ac8df 6215 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6216 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6217 return -EOPNOTSUPP;
eec60b03 6218
19957bb3 6219 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
664834de
JM
6220 chan = nl80211_get_valid_chan(&rdev->wiphy,
6221 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
6222 if (!chan)
4c476991 6223 return -EINVAL;
636a5d36 6224
19957bb3
JB
6225 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6226 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
6227
6228 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6229 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6230 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6231 }
6232
19957bb3 6233 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 6234 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 6235 return -EINVAL;
636a5d36 6236
e39e5b5e
JM
6237 if (auth_type == NL80211_AUTHTYPE_SAE &&
6238 !info->attrs[NL80211_ATTR_SAE_DATA])
6239 return -EINVAL;
6240
6241 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
6242 if (auth_type != NL80211_AUTHTYPE_SAE)
6243 return -EINVAL;
6244 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
6245 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
6246 /* need to include at least Auth Transaction and Status Code */
6247 if (sae_data_len < 4)
6248 return -EINVAL;
6249 }
6250
d5cdfacb
JM
6251 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6252
95de817b
JB
6253 /*
6254 * Since we no longer track auth state, ignore
6255 * requests to only change local state.
6256 */
6257 if (local_state_change)
6258 return 0;
6259
91bf9b26
JB
6260 wdev_lock(dev->ieee80211_ptr);
6261 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
6262 ssid, ssid_len, ie, ie_len,
6263 key.p.key, key.p.key_len, key.idx,
6264 sae_data, sae_data_len);
6265 wdev_unlock(dev->ieee80211_ptr);
6266 return err;
636a5d36
JM
6267}
6268
c0692b8f
JB
6269static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
6270 struct genl_info *info,
3dc27d25
JB
6271 struct cfg80211_crypto_settings *settings,
6272 int cipher_limit)
b23aa676 6273{
c0b2bbd8
JB
6274 memset(settings, 0, sizeof(*settings));
6275
b23aa676
SO
6276 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
6277
c0692b8f
JB
6278 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
6279 u16 proto;
6280 proto = nla_get_u16(
6281 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
6282 settings->control_port_ethertype = cpu_to_be16(proto);
6283 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
6284 proto != ETH_P_PAE)
6285 return -EINVAL;
6286 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
6287 settings->control_port_no_encrypt = true;
6288 } else
6289 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
6290
b23aa676
SO
6291 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
6292 void *data;
6293 int len, i;
6294
6295 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
6296 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
6297 settings->n_ciphers_pairwise = len / sizeof(u32);
6298
6299 if (len % sizeof(u32))
6300 return -EINVAL;
6301
3dc27d25 6302 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
6303 return -EINVAL;
6304
6305 memcpy(settings->ciphers_pairwise, data, len);
6306
6307 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
6308 if (!cfg80211_supported_cipher_suite(
6309 &rdev->wiphy,
b23aa676
SO
6310 settings->ciphers_pairwise[i]))
6311 return -EINVAL;
6312 }
6313
6314 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
6315 settings->cipher_group =
6316 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
6317 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
6318 settings->cipher_group))
b23aa676
SO
6319 return -EINVAL;
6320 }
6321
6322 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
6323 settings->wpa_versions =
6324 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
6325 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
6326 return -EINVAL;
6327 }
6328
6329 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
6330 void *data;
6d30240e 6331 int len;
b23aa676
SO
6332
6333 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
6334 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
6335 settings->n_akm_suites = len / sizeof(u32);
6336
6337 if (len % sizeof(u32))
6338 return -EINVAL;
6339
1b9ca027
JM
6340 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
6341 return -EINVAL;
6342
b23aa676 6343 memcpy(settings->akm_suites, data, len);
b23aa676
SO
6344 }
6345
6346 return 0;
6347}
6348
636a5d36
JM
6349static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
6350{
4c476991
JB
6351 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6352 struct net_device *dev = info->user_ptr[1];
f444de05 6353 struct ieee80211_channel *chan;
f62fab73
JB
6354 struct cfg80211_assoc_request req = {};
6355 const u8 *bssid, *ssid;
6356 int err, ssid_len = 0;
636a5d36 6357
f4a11bb0
JB
6358 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6359 return -EINVAL;
6360
6361 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
6362 !info->attrs[NL80211_ATTR_SSID] ||
6363 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
6364 return -EINVAL;
6365
4c476991
JB
6366 if (!rdev->ops->assoc)
6367 return -EOPNOTSUPP;
636a5d36 6368
074ac8df 6369 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6370 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6371 return -EOPNOTSUPP;
eec60b03 6372
19957bb3 6373 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6374
664834de
JM
6375 chan = nl80211_get_valid_chan(&rdev->wiphy,
6376 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
6377 if (!chan)
4c476991 6378 return -EINVAL;
636a5d36 6379
19957bb3
JB
6380 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6381 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
6382
6383 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
6384 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6385 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6386 }
6387
dc6382ce 6388 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 6389 enum nl80211_mfp mfp =
dc6382ce 6390 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 6391 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 6392 req.use_mfp = true;
4c476991
JB
6393 else if (mfp != NL80211_MFP_NO)
6394 return -EINVAL;
dc6382ce
JM
6395 }
6396
3e5d7649 6397 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 6398 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 6399
7e7c8926 6400 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 6401 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
6402
6403 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
6404 memcpy(&req.ht_capa_mask,
6405 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6406 sizeof(req.ht_capa_mask));
7e7c8926
BG
6407
6408 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 6409 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 6410 return -EINVAL;
f62fab73
JB
6411 memcpy(&req.ht_capa,
6412 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6413 sizeof(req.ht_capa));
7e7c8926
BG
6414 }
6415
ee2aca34 6416 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 6417 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
6418
6419 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
6420 memcpy(&req.vht_capa_mask,
6421 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
6422 sizeof(req.vht_capa_mask));
ee2aca34
JB
6423
6424 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 6425 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 6426 return -EINVAL;
f62fab73
JB
6427 memcpy(&req.vht_capa,
6428 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
6429 sizeof(req.vht_capa));
ee2aca34
JB
6430 }
6431
f62fab73 6432 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
6433 if (!err) {
6434 wdev_lock(dev->ieee80211_ptr);
f62fab73
JB
6435 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
6436 ssid, ssid_len, &req);
91bf9b26
JB
6437 wdev_unlock(dev->ieee80211_ptr);
6438 }
636a5d36 6439
636a5d36
JM
6440 return err;
6441}
6442
6443static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
6444{
4c476991
JB
6445 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6446 struct net_device *dev = info->user_ptr[1];
19957bb3 6447 const u8 *ie = NULL, *bssid;
91bf9b26 6448 int ie_len = 0, err;
19957bb3 6449 u16 reason_code;
d5cdfacb 6450 bool local_state_change;
636a5d36 6451
f4a11bb0
JB
6452 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6453 return -EINVAL;
6454
6455 if (!info->attrs[NL80211_ATTR_MAC])
6456 return -EINVAL;
6457
6458 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6459 return -EINVAL;
6460
4c476991
JB
6461 if (!rdev->ops->deauth)
6462 return -EOPNOTSUPP;
636a5d36 6463
074ac8df 6464 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6465 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6466 return -EOPNOTSUPP;
eec60b03 6467
19957bb3 6468 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6469
19957bb3
JB
6470 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6471 if (reason_code == 0) {
f4a11bb0 6472 /* Reason Code 0 is reserved */
4c476991 6473 return -EINVAL;
255e737e 6474 }
636a5d36
JM
6475
6476 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6477 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6478 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6479 }
6480
d5cdfacb
JM
6481 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6482
91bf9b26
JB
6483 wdev_lock(dev->ieee80211_ptr);
6484 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
6485 local_state_change);
6486 wdev_unlock(dev->ieee80211_ptr);
6487 return err;
636a5d36
JM
6488}
6489
6490static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
6491{
4c476991
JB
6492 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6493 struct net_device *dev = info->user_ptr[1];
19957bb3 6494 const u8 *ie = NULL, *bssid;
91bf9b26 6495 int ie_len = 0, err;
19957bb3 6496 u16 reason_code;
d5cdfacb 6497 bool local_state_change;
636a5d36 6498
f4a11bb0
JB
6499 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6500 return -EINVAL;
6501
6502 if (!info->attrs[NL80211_ATTR_MAC])
6503 return -EINVAL;
6504
6505 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6506 return -EINVAL;
6507
4c476991
JB
6508 if (!rdev->ops->disassoc)
6509 return -EOPNOTSUPP;
636a5d36 6510
074ac8df 6511 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6512 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6513 return -EOPNOTSUPP;
eec60b03 6514
19957bb3 6515 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 6516
19957bb3
JB
6517 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6518 if (reason_code == 0) {
f4a11bb0 6519 /* Reason Code 0 is reserved */
4c476991 6520 return -EINVAL;
255e737e 6521 }
636a5d36
JM
6522
6523 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
6524 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6525 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
6526 }
6527
d5cdfacb
JM
6528 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
6529
91bf9b26
JB
6530 wdev_lock(dev->ieee80211_ptr);
6531 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
6532 local_state_change);
6533 wdev_unlock(dev->ieee80211_ptr);
6534 return err;
636a5d36
JM
6535}
6536
dd5b4cc7
FF
6537static bool
6538nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
6539 int mcast_rate[IEEE80211_NUM_BANDS],
6540 int rateval)
6541{
6542 struct wiphy *wiphy = &rdev->wiphy;
6543 bool found = false;
6544 int band, i;
6545
6546 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
6547 struct ieee80211_supported_band *sband;
6548
6549 sband = wiphy->bands[band];
6550 if (!sband)
6551 continue;
6552
6553 for (i = 0; i < sband->n_bitrates; i++) {
6554 if (sband->bitrates[i].bitrate == rateval) {
6555 mcast_rate[band] = i + 1;
6556 found = true;
6557 break;
6558 }
6559 }
6560 }
6561
6562 return found;
6563}
6564
04a773ad
JB
6565static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
6566{
4c476991
JB
6567 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6568 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
6569 struct cfg80211_ibss_params ibss;
6570 struct wiphy *wiphy;
fffd0934 6571 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
6572 int err;
6573
8e30bc55
JB
6574 memset(&ibss, 0, sizeof(ibss));
6575
04a773ad
JB
6576 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6577 return -EINVAL;
6578
683b6d3b 6579 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
6580 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6581 return -EINVAL;
6582
8e30bc55
JB
6583 ibss.beacon_interval = 100;
6584
6585 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6586 ibss.beacon_interval =
6587 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6588 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
6589 return -EINVAL;
6590 }
6591
4c476991
JB
6592 if (!rdev->ops->join_ibss)
6593 return -EOPNOTSUPP;
04a773ad 6594
4c476991
JB
6595 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
6596 return -EOPNOTSUPP;
04a773ad 6597
79c97e97 6598 wiphy = &rdev->wiphy;
04a773ad 6599
39193498 6600 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 6601 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
6602
6603 if (!is_valid_ether_addr(ibss.bssid))
6604 return -EINVAL;
6605 }
04a773ad
JB
6606 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6607 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6608
6609 if (info->attrs[NL80211_ATTR_IE]) {
6610 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6611 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6612 }
6613
683b6d3b
JB
6614 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
6615 if (err)
6616 return err;
04a773ad 6617
683b6d3b 6618 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
6619 return -EINVAL;
6620
2f301ab2 6621 switch (ibss.chandef.width) {
bf372645
SW
6622 case NL80211_CHAN_WIDTH_5:
6623 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
6624 case NL80211_CHAN_WIDTH_20_NOHT:
6625 break;
6626 case NL80211_CHAN_WIDTH_20:
6627 case NL80211_CHAN_WIDTH_40:
6628 if (rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)
6629 break;
6630 default:
c04d6150 6631 return -EINVAL;
2f301ab2 6632 }
db9c64cf 6633
04a773ad 6634 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
6635 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
6636
fbd2c8dc
TP
6637 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
6638 u8 *rates =
6639 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6640 int n_rates =
6641 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6642 struct ieee80211_supported_band *sband =
683b6d3b 6643 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 6644
34850ab2
JB
6645 err = ieee80211_get_ratemask(sband, rates, n_rates,
6646 &ibss.basic_rates);
6647 if (err)
6648 return err;
fbd2c8dc 6649 }
dd5b4cc7 6650
803768f5
SW
6651 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6652 memcpy(&ibss.ht_capa_mask,
6653 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6654 sizeof(ibss.ht_capa_mask));
6655
6656 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
6657 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6658 return -EINVAL;
6659 memcpy(&ibss.ht_capa,
6660 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6661 sizeof(ibss.ht_capa));
6662 }
6663
dd5b4cc7
FF
6664 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6665 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
6666 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6667 return -EINVAL;
fbd2c8dc 6668
4c476991 6669 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
6670 bool no_ht = false;
6671
4c476991 6672 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
6673 info->attrs[NL80211_ATTR_KEYS],
6674 &no_ht);
4c476991
JB
6675 if (IS_ERR(connkeys))
6676 return PTR_ERR(connkeys);
de7044ee 6677
3d9d1d66
JB
6678 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
6679 no_ht) {
de7044ee
SM
6680 kfree(connkeys);
6681 return -EINVAL;
6682 }
4c476991 6683 }
04a773ad 6684
267335d6
AQ
6685 ibss.control_port =
6686 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
6687
5336fa88
SW
6688 ibss.userspace_handles_dfs =
6689 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
6690
4c476991 6691 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
6692 if (err)
6693 kfree(connkeys);
04a773ad
JB
6694 return err;
6695}
6696
6697static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
6698{
4c476991
JB
6699 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6700 struct net_device *dev = info->user_ptr[1];
04a773ad 6701
4c476991
JB
6702 if (!rdev->ops->leave_ibss)
6703 return -EOPNOTSUPP;
04a773ad 6704
4c476991
JB
6705 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
6706 return -EOPNOTSUPP;
04a773ad 6707
4c476991 6708 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
6709}
6710
f4e583c8
AQ
6711static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
6712{
6713 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6714 struct net_device *dev = info->user_ptr[1];
6715 int mcast_rate[IEEE80211_NUM_BANDS];
6716 u32 nla_rate;
6717 int err;
6718
6719 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
6720 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6721 return -EOPNOTSUPP;
6722
6723 if (!rdev->ops->set_mcast_rate)
6724 return -EOPNOTSUPP;
6725
6726 memset(mcast_rate, 0, sizeof(mcast_rate));
6727
6728 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
6729 return -EINVAL;
6730
6731 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
6732 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
6733 return -EINVAL;
6734
6735 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
6736
6737 return err;
6738}
6739
ad7e718c
JB
6740static struct sk_buff *
6741__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
6742 int approxlen, u32 portid, u32 seq,
6743 enum nl80211_commands cmd,
567ffc35
JB
6744 enum nl80211_attrs attr,
6745 const struct nl80211_vendor_cmd_info *info,
6746 gfp_t gfp)
ad7e718c
JB
6747{
6748 struct sk_buff *skb;
6749 void *hdr;
6750 struct nlattr *data;
6751
6752 skb = nlmsg_new(approxlen + 100, gfp);
6753 if (!skb)
6754 return NULL;
6755
6756 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
6757 if (!hdr) {
6758 kfree_skb(skb);
6759 return NULL;
6760 }
6761
6762 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
6763 goto nla_put_failure;
567ffc35
JB
6764
6765 if (info) {
6766 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
6767 info->vendor_id))
6768 goto nla_put_failure;
6769 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
6770 info->subcmd))
6771 goto nla_put_failure;
6772 }
6773
ad7e718c
JB
6774 data = nla_nest_start(skb, attr);
6775
6776 ((void **)skb->cb)[0] = rdev;
6777 ((void **)skb->cb)[1] = hdr;
6778 ((void **)skb->cb)[2] = data;
6779
6780 return skb;
6781
6782 nla_put_failure:
6783 kfree_skb(skb);
6784 return NULL;
6785}
f4e583c8 6786
e03ad6ea
JB
6787struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
6788 enum nl80211_commands cmd,
6789 enum nl80211_attrs attr,
6790 int vendor_event_idx,
6791 int approxlen, gfp_t gfp)
6792{
6793 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6794 const struct nl80211_vendor_cmd_info *info;
6795
6796 switch (cmd) {
6797 case NL80211_CMD_TESTMODE:
6798 if (WARN_ON(vendor_event_idx != -1))
6799 return NULL;
6800 info = NULL;
6801 break;
6802 case NL80211_CMD_VENDOR:
6803 if (WARN_ON(vendor_event_idx < 0 ||
6804 vendor_event_idx >= wiphy->n_vendor_events))
6805 return NULL;
6806 info = &wiphy->vendor_events[vendor_event_idx];
6807 break;
6808 default:
6809 WARN_ON(1);
6810 return NULL;
6811 }
6812
6813 return __cfg80211_alloc_vendor_skb(rdev, approxlen, 0, 0,
6814 cmd, attr, info, gfp);
6815}
6816EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
6817
6818void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
6819{
6820 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
6821 void *hdr = ((void **)skb->cb)[1];
6822 struct nlattr *data = ((void **)skb->cb)[2];
6823 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
6824
6825 nla_nest_end(skb, data);
6826 genlmsg_end(skb, hdr);
6827
6828 if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
6829 mcgrp = NL80211_MCGRP_VENDOR;
6830
6831 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0,
6832 mcgrp, gfp);
6833}
6834EXPORT_SYMBOL(__cfg80211_send_event_skb);
6835
aff89a9b 6836#ifdef CONFIG_NL80211_TESTMODE
aff89a9b
JB
6837static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
6838{
4c476991 6839 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
6840 struct wireless_dev *wdev =
6841 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
6842 int err;
6843
fc73f11f
DS
6844 if (!rdev->ops->testmode_cmd)
6845 return -EOPNOTSUPP;
6846
6847 if (IS_ERR(wdev)) {
6848 err = PTR_ERR(wdev);
6849 if (err != -EINVAL)
6850 return err;
6851 wdev = NULL;
6852 } else if (wdev->wiphy != &rdev->wiphy) {
6853 return -EINVAL;
6854 }
6855
aff89a9b
JB
6856 if (!info->attrs[NL80211_ATTR_TESTDATA])
6857 return -EINVAL;
6858
ad7e718c 6859 rdev->cur_cmd_info = info;
fc73f11f 6860 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
6861 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
6862 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
ad7e718c 6863 rdev->cur_cmd_info = NULL;
aff89a9b 6864
aff89a9b
JB
6865 return err;
6866}
6867
71063f0e
WYG
6868static int nl80211_testmode_dump(struct sk_buff *skb,
6869 struct netlink_callback *cb)
6870{
00918d33 6871 struct cfg80211_registered_device *rdev;
71063f0e
WYG
6872 int err;
6873 long phy_idx;
6874 void *data = NULL;
6875 int data_len = 0;
6876
5fe231e8
JB
6877 rtnl_lock();
6878
71063f0e
WYG
6879 if (cb->args[0]) {
6880 /*
6881 * 0 is a valid index, but not valid for args[0],
6882 * so we need to offset by 1.
6883 */
6884 phy_idx = cb->args[0] - 1;
6885 } else {
6886 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
6887 nl80211_fam.attrbuf, nl80211_fam.maxattr,
6888 nl80211_policy);
6889 if (err)
5fe231e8 6890 goto out_err;
00918d33 6891
2bd7e35d
JB
6892 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
6893 nl80211_fam.attrbuf);
6894 if (IS_ERR(rdev)) {
5fe231e8
JB
6895 err = PTR_ERR(rdev);
6896 goto out_err;
00918d33 6897 }
2bd7e35d
JB
6898 phy_idx = rdev->wiphy_idx;
6899 rdev = NULL;
2bd7e35d 6900
71063f0e
WYG
6901 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
6902 cb->args[1] =
6903 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
6904 }
6905
6906 if (cb->args[1]) {
6907 data = nla_data((void *)cb->args[1]);
6908 data_len = nla_len((void *)cb->args[1]);
6909 }
6910
00918d33
JB
6911 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
6912 if (!rdev) {
5fe231e8
JB
6913 err = -ENOENT;
6914 goto out_err;
71063f0e 6915 }
71063f0e 6916
00918d33 6917 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
6918 err = -EOPNOTSUPP;
6919 goto out_err;
6920 }
6921
6922 while (1) {
15e47304 6923 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
6924 cb->nlh->nlmsg_seq, NLM_F_MULTI,
6925 NL80211_CMD_TESTMODE);
6926 struct nlattr *tmdata;
6927
cb35fba3
DC
6928 if (!hdr)
6929 break;
6930
9360ffd1 6931 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
6932 genlmsg_cancel(skb, hdr);
6933 break;
6934 }
6935
6936 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
6937 if (!tmdata) {
6938 genlmsg_cancel(skb, hdr);
6939 break;
6940 }
e35e4d28 6941 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
6942 nla_nest_end(skb, tmdata);
6943
6944 if (err == -ENOBUFS || err == -ENOENT) {
6945 genlmsg_cancel(skb, hdr);
6946 break;
6947 } else if (err) {
6948 genlmsg_cancel(skb, hdr);
6949 goto out_err;
6950 }
6951
6952 genlmsg_end(skb, hdr);
6953 }
6954
6955 err = skb->len;
6956 /* see above */
6957 cb->args[0] = phy_idx + 1;
6958 out_err:
5fe231e8 6959 rtnl_unlock();
71063f0e
WYG
6960 return err;
6961}
aff89a9b
JB
6962#endif
6963
b23aa676
SO
6964static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
6965{
4c476991
JB
6966 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6967 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6968 struct cfg80211_connect_params connect;
6969 struct wiphy *wiphy;
fffd0934 6970 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
6971 int err;
6972
6973 memset(&connect, 0, sizeof(connect));
6974
6975 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6976 return -EINVAL;
6977
6978 if (!info->attrs[NL80211_ATTR_SSID] ||
6979 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6980 return -EINVAL;
6981
6982 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6983 connect.auth_type =
6984 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
6985 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
6986 NL80211_CMD_CONNECT))
b23aa676
SO
6987 return -EINVAL;
6988 } else
6989 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6990
6991 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
6992
c0692b8f 6993 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 6994 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
6995 if (err)
6996 return err;
b23aa676 6997
074ac8df 6998 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6999 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7000 return -EOPNOTSUPP;
b23aa676 7001
79c97e97 7002 wiphy = &rdev->wiphy;
b23aa676 7003
4486ea98
BS
7004 connect.bg_scan_period = -1;
7005 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
7006 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
7007 connect.bg_scan_period =
7008 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
7009 }
7010
b23aa676
SO
7011 if (info->attrs[NL80211_ATTR_MAC])
7012 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1df4a510
JM
7013 else if (info->attrs[NL80211_ATTR_MAC_HINT])
7014 connect.bssid_hint =
7015 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
b23aa676
SO
7016 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
7017 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
7018
7019 if (info->attrs[NL80211_ATTR_IE]) {
7020 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
7021 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
7022 }
7023
cee00a95
JM
7024 if (info->attrs[NL80211_ATTR_USE_MFP]) {
7025 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
7026 if (connect.mfp != NL80211_MFP_REQUIRED &&
7027 connect.mfp != NL80211_MFP_NO)
7028 return -EINVAL;
7029 } else {
7030 connect.mfp = NL80211_MFP_NO;
7031 }
7032
b23aa676 7033 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
664834de
JM
7034 connect.channel = nl80211_get_valid_chan(
7035 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]);
7036 if (!connect.channel)
1df4a510
JM
7037 return -EINVAL;
7038 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
664834de
JM
7039 connect.channel_hint = nl80211_get_valid_chan(
7040 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
7041 if (!connect.channel_hint)
4c476991 7042 return -EINVAL;
b23aa676
SO
7043 }
7044
fffd0934
JB
7045 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
7046 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 7047 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
7048 if (IS_ERR(connkeys))
7049 return PTR_ERR(connkeys);
fffd0934
JB
7050 }
7051
7e7c8926
BG
7052 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
7053 connect.flags |= ASSOC_REQ_DISABLE_HT;
7054
7055 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7056 memcpy(&connect.ht_capa_mask,
7057 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
7058 sizeof(connect.ht_capa_mask));
7059
7060 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
7061 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
7062 kfree(connkeys);
7e7c8926 7063 return -EINVAL;
b4e4f47e 7064 }
7e7c8926
BG
7065 memcpy(&connect.ht_capa,
7066 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
7067 sizeof(connect.ht_capa));
7068 }
7069
ee2aca34
JB
7070 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
7071 connect.flags |= ASSOC_REQ_DISABLE_VHT;
7072
7073 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
7074 memcpy(&connect.vht_capa_mask,
7075 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
7076 sizeof(connect.vht_capa_mask));
7077
7078 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
7079 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
7080 kfree(connkeys);
7081 return -EINVAL;
7082 }
7083 memcpy(&connect.vht_capa,
7084 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
7085 sizeof(connect.vht_capa));
7086 }
7087
83739b03
JB
7088 wdev_lock(dev->ieee80211_ptr);
7089 err = cfg80211_connect(rdev, dev, &connect, connkeys, NULL);
7090 wdev_unlock(dev->ieee80211_ptr);
fffd0934
JB
7091 if (err)
7092 kfree(connkeys);
b23aa676
SO
7093 return err;
7094}
7095
7096static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
7097{
4c476991
JB
7098 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7099 struct net_device *dev = info->user_ptr[1];
b23aa676 7100 u16 reason;
83739b03 7101 int ret;
b23aa676
SO
7102
7103 if (!info->attrs[NL80211_ATTR_REASON_CODE])
7104 reason = WLAN_REASON_DEAUTH_LEAVING;
7105 else
7106 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
7107
7108 if (reason == 0)
7109 return -EINVAL;
7110
074ac8df 7111 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7112 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7113 return -EOPNOTSUPP;
b23aa676 7114
83739b03
JB
7115 wdev_lock(dev->ieee80211_ptr);
7116 ret = cfg80211_disconnect(rdev, dev, reason, true);
7117 wdev_unlock(dev->ieee80211_ptr);
7118 return ret;
b23aa676
SO
7119}
7120
463d0183
JB
7121static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
7122{
4c476991 7123 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
7124 struct net *net;
7125 int err;
7126 u32 pid;
7127
7128 if (!info->attrs[NL80211_ATTR_PID])
7129 return -EINVAL;
7130
7131 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
7132
463d0183 7133 net = get_net_ns_by_pid(pid);
4c476991
JB
7134 if (IS_ERR(net))
7135 return PTR_ERR(net);
463d0183
JB
7136
7137 err = 0;
7138
7139 /* check if anything to do */
4c476991
JB
7140 if (!net_eq(wiphy_net(&rdev->wiphy), net))
7141 err = cfg80211_switch_netns(rdev, net);
463d0183 7142
463d0183 7143 put_net(net);
463d0183
JB
7144 return err;
7145}
7146
67fbb16b
SO
7147static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
7148{
4c476991 7149 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
7150 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
7151 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 7152 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
7153 struct cfg80211_pmksa pmksa;
7154
7155 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
7156
7157 if (!info->attrs[NL80211_ATTR_MAC])
7158 return -EINVAL;
7159
7160 if (!info->attrs[NL80211_ATTR_PMKID])
7161 return -EINVAL;
7162
67fbb16b
SO
7163 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
7164 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
7165
074ac8df 7166 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7167 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7168 return -EOPNOTSUPP;
67fbb16b
SO
7169
7170 switch (info->genlhdr->cmd) {
7171 case NL80211_CMD_SET_PMKSA:
7172 rdev_ops = rdev->ops->set_pmksa;
7173 break;
7174 case NL80211_CMD_DEL_PMKSA:
7175 rdev_ops = rdev->ops->del_pmksa;
7176 break;
7177 default:
7178 WARN_ON(1);
7179 break;
7180 }
7181
4c476991
JB
7182 if (!rdev_ops)
7183 return -EOPNOTSUPP;
67fbb16b 7184
4c476991 7185 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
7186}
7187
7188static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
7189{
4c476991
JB
7190 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7191 struct net_device *dev = info->user_ptr[1];
67fbb16b 7192
074ac8df 7193 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7194 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
7195 return -EOPNOTSUPP;
67fbb16b 7196
4c476991
JB
7197 if (!rdev->ops->flush_pmksa)
7198 return -EOPNOTSUPP;
67fbb16b 7199
e35e4d28 7200 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
7201}
7202
109086ce
AN
7203static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
7204{
7205 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7206 struct net_device *dev = info->user_ptr[1];
7207 u8 action_code, dialog_token;
7208 u16 status_code;
7209 u8 *peer;
7210
7211 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
7212 !rdev->ops->tdls_mgmt)
7213 return -EOPNOTSUPP;
7214
7215 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
7216 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
7217 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
7218 !info->attrs[NL80211_ATTR_IE] ||
7219 !info->attrs[NL80211_ATTR_MAC])
7220 return -EINVAL;
7221
7222 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
7223 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
7224 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
7225 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
7226
e35e4d28
HG
7227 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
7228 dialog_token, status_code,
7229 nla_data(info->attrs[NL80211_ATTR_IE]),
7230 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
7231}
7232
7233static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
7234{
7235 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7236 struct net_device *dev = info->user_ptr[1];
7237 enum nl80211_tdls_operation operation;
7238 u8 *peer;
7239
7240 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
7241 !rdev->ops->tdls_oper)
7242 return -EOPNOTSUPP;
7243
7244 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
7245 !info->attrs[NL80211_ATTR_MAC])
7246 return -EINVAL;
7247
7248 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
7249 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
7250
e35e4d28 7251 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
7252}
7253
9588bbd5
JM
7254static int nl80211_remain_on_channel(struct sk_buff *skb,
7255 struct genl_info *info)
7256{
4c476991 7257 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7258 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 7259 struct cfg80211_chan_def chandef;
9588bbd5
JM
7260 struct sk_buff *msg;
7261 void *hdr;
7262 u64 cookie;
683b6d3b 7263 u32 duration;
9588bbd5
JM
7264 int err;
7265
7266 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
7267 !info->attrs[NL80211_ATTR_DURATION])
7268 return -EINVAL;
7269
7270 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
7271
ebf348fc
JB
7272 if (!rdev->ops->remain_on_channel ||
7273 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
7274 return -EOPNOTSUPP;
7275
9588bbd5 7276 /*
ebf348fc
JB
7277 * We should be on that channel for at least a minimum amount of
7278 * time (10ms) but no longer than the driver supports.
9588bbd5 7279 */
ebf348fc 7280 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 7281 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
7282 return -EINVAL;
7283
683b6d3b
JB
7284 err = nl80211_parse_chandef(rdev, info, &chandef);
7285 if (err)
7286 return err;
9588bbd5
JM
7287
7288 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
7289 if (!msg)
7290 return -ENOMEM;
9588bbd5 7291
15e47304 7292 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 7293 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
7294 if (!hdr) {
7295 err = -ENOBUFS;
9588bbd5
JM
7296 goto free_msg;
7297 }
7298
683b6d3b
JB
7299 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
7300 duration, &cookie);
9588bbd5
JM
7301
7302 if (err)
7303 goto free_msg;
7304
9360ffd1
DM
7305 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7306 goto nla_put_failure;
9588bbd5
JM
7307
7308 genlmsg_end(msg, hdr);
4c476991
JB
7309
7310 return genlmsg_reply(msg, info);
9588bbd5
JM
7311
7312 nla_put_failure:
7313 err = -ENOBUFS;
7314 free_msg:
7315 nlmsg_free(msg);
9588bbd5
JM
7316 return err;
7317}
7318
7319static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
7320 struct genl_info *info)
7321{
4c476991 7322 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7323 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 7324 u64 cookie;
9588bbd5
JM
7325
7326 if (!info->attrs[NL80211_ATTR_COOKIE])
7327 return -EINVAL;
7328
4c476991
JB
7329 if (!rdev->ops->cancel_remain_on_channel)
7330 return -EOPNOTSUPP;
9588bbd5 7331
9588bbd5
JM
7332 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
7333
e35e4d28 7334 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
7335}
7336
13ae75b1
JM
7337static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
7338 u8 *rates, u8 rates_len)
7339{
7340 u8 i;
7341 u32 mask = 0;
7342
7343 for (i = 0; i < rates_len; i++) {
7344 int rate = (rates[i] & 0x7f) * 5;
7345 int ridx;
7346 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
7347 struct ieee80211_rate *srate =
7348 &sband->bitrates[ridx];
7349 if (rate == srate->bitrate) {
7350 mask |= 1 << ridx;
7351 break;
7352 }
7353 }
7354 if (ridx == sband->n_bitrates)
7355 return 0; /* rate not found */
7356 }
7357
7358 return mask;
7359}
7360
24db78c0
SW
7361static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
7362 u8 *rates, u8 rates_len,
7363 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
7364{
7365 u8 i;
7366
7367 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
7368
7369 for (i = 0; i < rates_len; i++) {
7370 int ridx, rbit;
7371
7372 ridx = rates[i] / 8;
7373 rbit = BIT(rates[i] % 8);
7374
7375 /* check validity */
910570b5 7376 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
7377 return false;
7378
7379 /* check availability */
7380 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
7381 mcs[ridx] |= rbit;
7382 else
7383 return false;
7384 }
7385
7386 return true;
7387}
7388
204e35a9
JD
7389static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
7390{
7391 u16 mcs_mask = 0;
7392
7393 switch (vht_mcs_map) {
7394 case IEEE80211_VHT_MCS_NOT_SUPPORTED:
7395 break;
7396 case IEEE80211_VHT_MCS_SUPPORT_0_7:
7397 mcs_mask = 0x00FF;
7398 break;
7399 case IEEE80211_VHT_MCS_SUPPORT_0_8:
7400 mcs_mask = 0x01FF;
7401 break;
7402 case IEEE80211_VHT_MCS_SUPPORT_0_9:
7403 mcs_mask = 0x03FF;
7404 break;
7405 default:
7406 break;
7407 }
7408
7409 return mcs_mask;
7410}
7411
7412static void vht_build_mcs_mask(u16 vht_mcs_map,
7413 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
7414{
7415 u8 nss;
7416
7417 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
7418 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
7419 vht_mcs_map >>= 2;
7420 }
7421}
7422
7423static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
7424 struct nl80211_txrate_vht *txrate,
7425 u16 mcs[NL80211_VHT_NSS_MAX])
7426{
7427 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
7428 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
7429 u8 i;
7430
7431 if (!sband->vht_cap.vht_supported)
7432 return false;
7433
7434 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
7435
7436 /* Build vht_mcs_mask from VHT capabilities */
7437 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
7438
7439 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
7440 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
7441 mcs[i] = txrate->mcs[i];
7442 else
7443 return false;
7444 }
7445
7446 return true;
7447}
7448
b54452b0 7449static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
7450 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
7451 .len = NL80211_MAX_SUPP_RATES },
d1e33e65
JD
7452 [NL80211_TXRATE_HT] = { .type = NLA_BINARY,
7453 .len = NL80211_MAX_SUPP_HT_RATES },
204e35a9 7454 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)},
0b9323f6 7455 [NL80211_TXRATE_GI] = { .type = NLA_U8 },
13ae75b1
JM
7456};
7457
7458static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
7459 struct genl_info *info)
7460{
7461 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 7462 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 7463 struct cfg80211_bitrate_mask mask;
4c476991
JB
7464 int rem, i;
7465 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
7466 struct nlattr *tx_rates;
7467 struct ieee80211_supported_band *sband;
204e35a9 7468 u16 vht_tx_mcs_map;
13ae75b1 7469
4c476991
JB
7470 if (!rdev->ops->set_bitrate_mask)
7471 return -EOPNOTSUPP;
13ae75b1
JM
7472
7473 memset(&mask, 0, sizeof(mask));
7474 /* Default to all rates enabled */
7475 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
7476 sband = rdev->wiphy.bands[i];
7869303b
JD
7477
7478 if (!sband)
7479 continue;
7480
7481 mask.control[i].legacy = (1 << sband->n_bitrates) - 1;
d1e33e65 7482 memcpy(mask.control[i].ht_mcs,
7869303b 7483 sband->ht_cap.mcs.rx_mask,
d1e33e65 7484 sizeof(mask.control[i].ht_mcs));
204e35a9
JD
7485
7486 if (!sband->vht_cap.vht_supported)
7487 continue;
7488
7489 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
7490 vht_build_mcs_mask(vht_tx_mcs_map, mask.control[i].vht_mcs);
13ae75b1
JM
7491 }
7492
b9243ab0
JD
7493 /* if no rates are given set it back to the defaults */
7494 if (!info->attrs[NL80211_ATTR_TX_RATES])
7495 goto out;
7496
13ae75b1
JM
7497 /*
7498 * The nested attribute uses enum nl80211_band as the index. This maps
7499 * directly to the enum ieee80211_band values used in cfg80211.
7500 */
24db78c0 7501 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
7502 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
7503 {
7504 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
7505 if (band < 0 || band >= IEEE80211_NUM_BANDS)
7506 return -EINVAL;
13ae75b1 7507 sband = rdev->wiphy.bands[band];
4c476991
JB
7508 if (sband == NULL)
7509 return -EINVAL;
13ae75b1
JM
7510 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
7511 nla_len(tx_rates), nl80211_txattr_policy);
7512 if (tb[NL80211_TXRATE_LEGACY]) {
7513 mask.control[band].legacy = rateset_to_mask(
7514 sband,
7515 nla_data(tb[NL80211_TXRATE_LEGACY]),
7516 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
7517 if ((mask.control[band].legacy == 0) &&
7518 nla_len(tb[NL80211_TXRATE_LEGACY]))
7519 return -EINVAL;
24db78c0 7520 }
d1e33e65 7521 if (tb[NL80211_TXRATE_HT]) {
24db78c0
SW
7522 if (!ht_rateset_to_mask(
7523 sband,
d1e33e65
JD
7524 nla_data(tb[NL80211_TXRATE_HT]),
7525 nla_len(tb[NL80211_TXRATE_HT]),
7526 mask.control[band].ht_mcs))
24db78c0
SW
7527 return -EINVAL;
7528 }
204e35a9
JD
7529 if (tb[NL80211_TXRATE_VHT]) {
7530 if (!vht_set_mcs_mask(
7531 sband,
7532 nla_data(tb[NL80211_TXRATE_VHT]),
7533 mask.control[band].vht_mcs))
7534 return -EINVAL;
7535 }
0b9323f6
JD
7536 if (tb[NL80211_TXRATE_GI]) {
7537 mask.control[band].gi =
7538 nla_get_u8(tb[NL80211_TXRATE_GI]);
7539 if (mask.control[band].gi > NL80211_TXRATE_FORCE_LGI)
7540 return -EINVAL;
7541 }
24db78c0
SW
7542
7543 if (mask.control[band].legacy == 0) {
204e35a9
JD
7544 /* don't allow empty legacy rates if HT or VHT
7545 * are not even supported.
7546 */
7547 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
7548 rdev->wiphy.bands[band]->vht_cap.vht_supported))
24db78c0
SW
7549 return -EINVAL;
7550
7551 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
d1e33e65 7552 if (mask.control[band].ht_mcs[i])
204e35a9
JD
7553 goto out;
7554
7555 for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
7556 if (mask.control[band].vht_mcs[i])
7557 goto out;
24db78c0
SW
7558
7559 /* legacy and mcs rates may not be both empty */
204e35a9 7560 return -EINVAL;
13ae75b1
JM
7561 }
7562 }
7563
b9243ab0 7564out:
e35e4d28 7565 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
7566}
7567
2e161f78 7568static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 7569{
4c476991 7570 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7571 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 7572 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
7573
7574 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
7575 return -EINVAL;
7576
2e161f78
JB
7577 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
7578 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 7579
71bbc994
JB
7580 switch (wdev->iftype) {
7581 case NL80211_IFTYPE_STATION:
7582 case NL80211_IFTYPE_ADHOC:
7583 case NL80211_IFTYPE_P2P_CLIENT:
7584 case NL80211_IFTYPE_AP:
7585 case NL80211_IFTYPE_AP_VLAN:
7586 case NL80211_IFTYPE_MESH_POINT:
7587 case NL80211_IFTYPE_P2P_GO:
98104fde 7588 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
7589 break;
7590 default:
4c476991 7591 return -EOPNOTSUPP;
71bbc994 7592 }
026331c4
JM
7593
7594 /* not much point in registering if we can't reply */
4c476991
JB
7595 if (!rdev->ops->mgmt_tx)
7596 return -EOPNOTSUPP;
026331c4 7597
15e47304 7598 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
7599 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
7600 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
7601}
7602
2e161f78 7603static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 7604{
4c476991 7605 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7606 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 7607 struct cfg80211_chan_def chandef;
026331c4 7608 int err;
d64d373f 7609 void *hdr = NULL;
026331c4 7610 u64 cookie;
e247bd90 7611 struct sk_buff *msg = NULL;
b176e629
AO
7612 struct cfg80211_mgmt_tx_params params = {
7613 .dont_wait_for_ack =
7614 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
7615 };
026331c4 7616
683b6d3b 7617 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
7618 return -EINVAL;
7619
4c476991
JB
7620 if (!rdev->ops->mgmt_tx)
7621 return -EOPNOTSUPP;
026331c4 7622
71bbc994 7623 switch (wdev->iftype) {
ea141b75
AQ
7624 case NL80211_IFTYPE_P2P_DEVICE:
7625 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
7626 return -EINVAL;
71bbc994
JB
7627 case NL80211_IFTYPE_STATION:
7628 case NL80211_IFTYPE_ADHOC:
7629 case NL80211_IFTYPE_P2P_CLIENT:
7630 case NL80211_IFTYPE_AP:
7631 case NL80211_IFTYPE_AP_VLAN:
7632 case NL80211_IFTYPE_MESH_POINT:
7633 case NL80211_IFTYPE_P2P_GO:
7634 break;
7635 default:
4c476991 7636 return -EOPNOTSUPP;
71bbc994 7637 }
026331c4 7638
f7ca38df 7639 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 7640 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df 7641 return -EINVAL;
b176e629 7642 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
7643
7644 /*
7645 * We should wait on the channel for at least a minimum amount
7646 * of time (10ms) but no longer than the driver supports.
7647 */
b176e629
AO
7648 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
7649 params.wait > rdev->wiphy.max_remain_on_channel_duration)
ebf348fc
JB
7650 return -EINVAL;
7651
f7ca38df
JB
7652 }
7653
b176e629 7654 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
f7ca38df 7655
b176e629 7656 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7c4ef712
JB
7657 return -EINVAL;
7658
b176e629 7659 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
e9f935e3 7660
ea141b75
AQ
7661 /* get the channel if any has been specified, otherwise pass NULL to
7662 * the driver. The latter will use the current one
7663 */
7664 chandef.chan = NULL;
7665 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
7666 err = nl80211_parse_chandef(rdev, info, &chandef);
7667 if (err)
7668 return err;
7669 }
7670
b176e629 7671 if (!chandef.chan && params.offchan)
ea141b75 7672 return -EINVAL;
026331c4 7673
b176e629 7674 if (!params.dont_wait_for_ack) {
e247bd90
JB
7675 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7676 if (!msg)
7677 return -ENOMEM;
026331c4 7678
15e47304 7679 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 7680 NL80211_CMD_FRAME);
cb35fba3
DC
7681 if (!hdr) {
7682 err = -ENOBUFS;
e247bd90
JB
7683 goto free_msg;
7684 }
026331c4 7685 }
e247bd90 7686
b176e629
AO
7687 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
7688 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
7689 params.chan = chandef.chan;
7690 err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
026331c4
JM
7691 if (err)
7692 goto free_msg;
7693
e247bd90 7694 if (msg) {
9360ffd1
DM
7695 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7696 goto nla_put_failure;
026331c4 7697
e247bd90
JB
7698 genlmsg_end(msg, hdr);
7699 return genlmsg_reply(msg, info);
7700 }
7701
7702 return 0;
026331c4
JM
7703
7704 nla_put_failure:
7705 err = -ENOBUFS;
7706 free_msg:
7707 nlmsg_free(msg);
026331c4
JM
7708 return err;
7709}
7710
f7ca38df
JB
7711static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
7712{
7713 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 7714 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
7715 u64 cookie;
7716
7717 if (!info->attrs[NL80211_ATTR_COOKIE])
7718 return -EINVAL;
7719
7720 if (!rdev->ops->mgmt_tx_cancel_wait)
7721 return -EOPNOTSUPP;
7722
71bbc994
JB
7723 switch (wdev->iftype) {
7724 case NL80211_IFTYPE_STATION:
7725 case NL80211_IFTYPE_ADHOC:
7726 case NL80211_IFTYPE_P2P_CLIENT:
7727 case NL80211_IFTYPE_AP:
7728 case NL80211_IFTYPE_AP_VLAN:
7729 case NL80211_IFTYPE_P2P_GO:
98104fde 7730 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
7731 break;
7732 default:
f7ca38df 7733 return -EOPNOTSUPP;
71bbc994 7734 }
f7ca38df
JB
7735
7736 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
7737
e35e4d28 7738 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
7739}
7740
ffb9eb3d
KV
7741static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
7742{
4c476991 7743 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 7744 struct wireless_dev *wdev;
4c476991 7745 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
7746 u8 ps_state;
7747 bool state;
7748 int err;
7749
4c476991
JB
7750 if (!info->attrs[NL80211_ATTR_PS_STATE])
7751 return -EINVAL;
ffb9eb3d
KV
7752
7753 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
7754
4c476991
JB
7755 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
7756 return -EINVAL;
ffb9eb3d
KV
7757
7758 wdev = dev->ieee80211_ptr;
7759
4c476991
JB
7760 if (!rdev->ops->set_power_mgmt)
7761 return -EOPNOTSUPP;
ffb9eb3d
KV
7762
7763 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
7764
7765 if (state == wdev->ps)
4c476991 7766 return 0;
ffb9eb3d 7767
e35e4d28 7768 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
7769 if (!err)
7770 wdev->ps = state;
ffb9eb3d
KV
7771 return err;
7772}
7773
7774static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
7775{
4c476991 7776 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
7777 enum nl80211_ps_state ps_state;
7778 struct wireless_dev *wdev;
4c476991 7779 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
7780 struct sk_buff *msg;
7781 void *hdr;
7782 int err;
7783
ffb9eb3d
KV
7784 wdev = dev->ieee80211_ptr;
7785
4c476991
JB
7786 if (!rdev->ops->set_power_mgmt)
7787 return -EOPNOTSUPP;
ffb9eb3d
KV
7788
7789 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
7790 if (!msg)
7791 return -ENOMEM;
ffb9eb3d 7792
15e47304 7793 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
7794 NL80211_CMD_GET_POWER_SAVE);
7795 if (!hdr) {
4c476991 7796 err = -ENOBUFS;
ffb9eb3d
KV
7797 goto free_msg;
7798 }
7799
7800 if (wdev->ps)
7801 ps_state = NL80211_PS_ENABLED;
7802 else
7803 ps_state = NL80211_PS_DISABLED;
7804
9360ffd1
DM
7805 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
7806 goto nla_put_failure;
ffb9eb3d
KV
7807
7808 genlmsg_end(msg, hdr);
4c476991 7809 return genlmsg_reply(msg, info);
ffb9eb3d 7810
4c476991 7811 nla_put_failure:
ffb9eb3d 7812 err = -ENOBUFS;
4c476991 7813 free_msg:
ffb9eb3d 7814 nlmsg_free(msg);
ffb9eb3d
KV
7815 return err;
7816}
7817
94e860f1
JB
7818static const struct nla_policy
7819nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
d6dc1a38
JO
7820 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
7821 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
7822 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
7823 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
7824 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
7825 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
7826};
7827
84f10708 7828static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 7829 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
7830{
7831 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 7832 struct net_device *dev = info->user_ptr[1];
1da5fcc8 7833 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 7834
d9d8b019 7835 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
7836 return -EINVAL;
7837
84f10708
TP
7838 if (!rdev->ops->set_cqm_txe_config)
7839 return -EOPNOTSUPP;
7840
7841 if (wdev->iftype != NL80211_IFTYPE_STATION &&
7842 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
7843 return -EOPNOTSUPP;
7844
e35e4d28 7845 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
7846}
7847
d6dc1a38
JO
7848static int nl80211_set_cqm_rssi(struct genl_info *info,
7849 s32 threshold, u32 hysteresis)
7850{
4c476991 7851 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 7852 struct net_device *dev = info->user_ptr[1];
1da5fcc8 7853 struct wireless_dev *wdev = dev->ieee80211_ptr;
d6dc1a38
JO
7854
7855 if (threshold > 0)
7856 return -EINVAL;
7857
1da5fcc8
JB
7858 /* disabling - hysteresis should also be zero then */
7859 if (threshold == 0)
7860 hysteresis = 0;
d6dc1a38 7861
4c476991
JB
7862 if (!rdev->ops->set_cqm_rssi_config)
7863 return -EOPNOTSUPP;
d6dc1a38 7864
074ac8df 7865 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
7866 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
7867 return -EOPNOTSUPP;
d6dc1a38 7868
e35e4d28 7869 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
7870}
7871
7872static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
7873{
7874 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
7875 struct nlattr *cqm;
7876 int err;
7877
7878 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
7879 if (!cqm)
7880 return -EINVAL;
d6dc1a38
JO
7881
7882 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
7883 nl80211_attr_cqm_policy);
7884 if (err)
1da5fcc8 7885 return err;
d6dc1a38
JO
7886
7887 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
7888 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
1da5fcc8
JB
7889 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
7890 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 7891
1da5fcc8
JB
7892 return nl80211_set_cqm_rssi(info, threshold, hysteresis);
7893 }
7894
7895 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
7896 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
7897 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
7898 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
7899 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
7900 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
7901
7902 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
7903 }
7904
7905 return -EINVAL;
d6dc1a38
JO
7906}
7907
29cbe68c
JB
7908static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
7909{
7910 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7911 struct net_device *dev = info->user_ptr[1];
7912 struct mesh_config cfg;
c80d545d 7913 struct mesh_setup setup;
29cbe68c
JB
7914 int err;
7915
7916 /* start with default */
7917 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 7918 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 7919
24bdd9f4 7920 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 7921 /* and parse parameters if given */
24bdd9f4 7922 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
7923 if (err)
7924 return err;
7925 }
7926
7927 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
7928 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
7929 return -EINVAL;
7930
c80d545d
JC
7931 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
7932 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
7933
4bb62344
CYY
7934 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
7935 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
7936 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
7937 return -EINVAL;
7938
9bdbf04d
MP
7939 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
7940 setup.beacon_interval =
7941 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
7942 if (setup.beacon_interval < 10 ||
7943 setup.beacon_interval > 10000)
7944 return -EINVAL;
7945 }
7946
7947 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
7948 setup.dtim_period =
7949 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
7950 if (setup.dtim_period < 1 || setup.dtim_period > 100)
7951 return -EINVAL;
7952 }
7953
c80d545d
JC
7954 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
7955 /* parse additional setup parameters if given */
7956 err = nl80211_parse_mesh_setup(info, &setup);
7957 if (err)
7958 return err;
7959 }
7960
d37bb18a
TP
7961 if (setup.user_mpm)
7962 cfg.auto_open_plinks = false;
7963
cc1d2806 7964 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
7965 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
7966 if (err)
7967 return err;
cc1d2806
JB
7968 } else {
7969 /* cfg80211_join_mesh() will sort it out */
683b6d3b 7970 setup.chandef.chan = NULL;
cc1d2806
JB
7971 }
7972
ffb3cf30
AN
7973 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
7974 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7975 int n_rates =
7976 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
7977 struct ieee80211_supported_band *sband;
7978
7979 if (!setup.chandef.chan)
7980 return -EINVAL;
7981
7982 sband = rdev->wiphy.bands[setup.chandef.chan->band];
7983
7984 err = ieee80211_get_ratemask(sband, rates, n_rates,
7985 &setup.basic_rates);
7986 if (err)
7987 return err;
7988 }
7989
c80d545d 7990 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
7991}
7992
7993static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
7994{
7995 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7996 struct net_device *dev = info->user_ptr[1];
7997
7998 return cfg80211_leave_mesh(rdev, dev);
7999}
8000
dfb89c56 8001#ifdef CONFIG_PM
bb92d199
AK
8002static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
8003 struct cfg80211_registered_device *rdev)
8004{
6abb9cb9 8005 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
8006 struct nlattr *nl_pats, *nl_pat;
8007 int i, pat_len;
8008
6abb9cb9 8009 if (!wowlan->n_patterns)
bb92d199
AK
8010 return 0;
8011
8012 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
8013 if (!nl_pats)
8014 return -ENOBUFS;
8015
6abb9cb9 8016 for (i = 0; i < wowlan->n_patterns; i++) {
bb92d199
AK
8017 nl_pat = nla_nest_start(msg, i + 1);
8018 if (!nl_pat)
8019 return -ENOBUFS;
6abb9cb9 8020 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 8021 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 8022 wowlan->patterns[i].mask) ||
50ac6607
AK
8023 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
8024 wowlan->patterns[i].pattern) ||
8025 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 8026 wowlan->patterns[i].pkt_offset))
bb92d199
AK
8027 return -ENOBUFS;
8028 nla_nest_end(msg, nl_pat);
8029 }
8030 nla_nest_end(msg, nl_pats);
8031
8032 return 0;
8033}
8034
2a0e047e
JB
8035static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
8036 struct cfg80211_wowlan_tcp *tcp)
8037{
8038 struct nlattr *nl_tcp;
8039
8040 if (!tcp)
8041 return 0;
8042
8043 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
8044 if (!nl_tcp)
8045 return -ENOBUFS;
8046
8047 if (nla_put_be32(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
8048 nla_put_be32(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
8049 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
8050 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
8051 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
8052 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
8053 tcp->payload_len, tcp->payload) ||
8054 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
8055 tcp->data_interval) ||
8056 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
8057 tcp->wake_len, tcp->wake_data) ||
8058 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
8059 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
8060 return -ENOBUFS;
8061
8062 if (tcp->payload_seq.len &&
8063 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
8064 sizeof(tcp->payload_seq), &tcp->payload_seq))
8065 return -ENOBUFS;
8066
8067 if (tcp->payload_tok.len &&
8068 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
8069 sizeof(tcp->payload_tok) + tcp->tokens_size,
8070 &tcp->payload_tok))
8071 return -ENOBUFS;
8072
e248ad30
JB
8073 nla_nest_end(msg, nl_tcp);
8074
2a0e047e
JB
8075 return 0;
8076}
8077
ff1b6e69
JB
8078static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
8079{
8080 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8081 struct sk_buff *msg;
8082 void *hdr;
2a0e047e 8083 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 8084
964dc9e2 8085 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
8086 return -EOPNOTSUPP;
8087
6abb9cb9 8088 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 8089 /* adjust size to have room for all the data */
6abb9cb9
JB
8090 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
8091 rdev->wiphy.wowlan_config->tcp->payload_len +
8092 rdev->wiphy.wowlan_config->tcp->wake_len +
8093 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
8094 }
8095
8096 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
8097 if (!msg)
8098 return -ENOMEM;
8099
15e47304 8100 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
8101 NL80211_CMD_GET_WOWLAN);
8102 if (!hdr)
8103 goto nla_put_failure;
8104
6abb9cb9 8105 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
8106 struct nlattr *nl_wowlan;
8107
8108 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
8109 if (!nl_wowlan)
8110 goto nla_put_failure;
8111
6abb9cb9 8112 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 8113 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 8114 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 8115 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 8116 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 8117 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 8118 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 8119 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 8120 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 8121 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 8122 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 8123 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 8124 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
8125 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
8126 goto nla_put_failure;
2a0e047e 8127
bb92d199
AK
8128 if (nl80211_send_wowlan_patterns(msg, rdev))
8129 goto nla_put_failure;
2a0e047e 8130
6abb9cb9
JB
8131 if (nl80211_send_wowlan_tcp(msg,
8132 rdev->wiphy.wowlan_config->tcp))
2a0e047e
JB
8133 goto nla_put_failure;
8134
ff1b6e69
JB
8135 nla_nest_end(msg, nl_wowlan);
8136 }
8137
8138 genlmsg_end(msg, hdr);
8139 return genlmsg_reply(msg, info);
8140
8141nla_put_failure:
8142 nlmsg_free(msg);
8143 return -ENOBUFS;
8144}
8145
2a0e047e
JB
8146static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
8147 struct nlattr *attr,
8148 struct cfg80211_wowlan *trig)
8149{
8150 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
8151 struct cfg80211_wowlan_tcp *cfg;
8152 struct nl80211_wowlan_tcp_data_token *tok = NULL;
8153 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
8154 u32 size;
8155 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
8156 int err, port;
8157
964dc9e2 8158 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
8159 return -EINVAL;
8160
8161 err = nla_parse(tb, MAX_NL80211_WOWLAN_TCP,
8162 nla_data(attr), nla_len(attr),
8163 nl80211_wowlan_tcp_policy);
8164 if (err)
8165 return err;
8166
8167 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
8168 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
8169 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
8170 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
8171 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
8172 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
8173 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
8174 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
8175 return -EINVAL;
8176
8177 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 8178 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
8179 return -EINVAL;
8180
8181 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 8182 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 8183 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
8184 return -EINVAL;
8185
8186 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 8187 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
8188 return -EINVAL;
8189
8190 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
8191 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
8192 return -EINVAL;
8193
8194 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
8195 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
8196
8197 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
8198 tokens_size = tokln - sizeof(*tok);
8199
8200 if (!tok->len || tokens_size % tok->len)
8201 return -EINVAL;
964dc9e2 8202 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 8203 return -EINVAL;
964dc9e2 8204 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 8205 return -EINVAL;
964dc9e2 8206 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 8207 return -EINVAL;
964dc9e2 8208 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
8209 return -EINVAL;
8210 if (tok->offset + tok->len > data_size)
8211 return -EINVAL;
8212 }
8213
8214 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
8215 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 8216 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
8217 return -EINVAL;
8218 if (seq->len == 0 || seq->len > 4)
8219 return -EINVAL;
8220 if (seq->len + seq->offset > data_size)
8221 return -EINVAL;
8222 }
8223
8224 size = sizeof(*cfg);
8225 size += data_size;
8226 size += wake_size + wake_mask_size;
8227 size += tokens_size;
8228
8229 cfg = kzalloc(size, GFP_KERNEL);
8230 if (!cfg)
8231 return -ENOMEM;
8232 cfg->src = nla_get_be32(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
8233 cfg->dst = nla_get_be32(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
8234 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
8235 ETH_ALEN);
8236 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
8237 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
8238 else
8239 port = 0;
8240#ifdef CONFIG_INET
8241 /* allocate a socket and port for it and use it */
8242 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
8243 IPPROTO_TCP, &cfg->sock, 1);
8244 if (err) {
8245 kfree(cfg);
8246 return err;
8247 }
8248 if (inet_csk_get_port(cfg->sock->sk, port)) {
8249 sock_release(cfg->sock);
8250 kfree(cfg);
8251 return -EADDRINUSE;
8252 }
8253 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
8254#else
8255 if (!port) {
8256 kfree(cfg);
8257 return -EINVAL;
8258 }
8259 cfg->src_port = port;
8260#endif
8261
8262 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
8263 cfg->payload_len = data_size;
8264 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
8265 memcpy((void *)cfg->payload,
8266 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
8267 data_size);
8268 if (seq)
8269 cfg->payload_seq = *seq;
8270 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
8271 cfg->wake_len = wake_size;
8272 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
8273 memcpy((void *)cfg->wake_data,
8274 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
8275 wake_size);
8276 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
8277 data_size + wake_size;
8278 memcpy((void *)cfg->wake_mask,
8279 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
8280 wake_mask_size);
8281 if (tok) {
8282 cfg->tokens_size = tokens_size;
8283 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
8284 }
8285
8286 trig->tcp = cfg;
8287
8288 return 0;
8289}
8290
ff1b6e69
JB
8291static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
8292{
8293 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8294 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 8295 struct cfg80211_wowlan new_triggers = {};
ae33bd81 8296 struct cfg80211_wowlan *ntrig;
964dc9e2 8297 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 8298 int err, i;
6abb9cb9 8299 bool prev_enabled = rdev->wiphy.wowlan_config;
ff1b6e69 8300
964dc9e2 8301 if (!wowlan)
ff1b6e69
JB
8302 return -EOPNOTSUPP;
8303
ae33bd81
JB
8304 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
8305 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 8306 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
8307 goto set_wakeup;
8308 }
ff1b6e69
JB
8309
8310 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
8311 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
8312 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
8313 nl80211_wowlan_policy);
8314 if (err)
8315 return err;
8316
8317 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
8318 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
8319 return -EINVAL;
8320 new_triggers.any = true;
8321 }
8322
8323 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
8324 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
8325 return -EINVAL;
8326 new_triggers.disconnect = true;
8327 }
8328
8329 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
8330 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
8331 return -EINVAL;
8332 new_triggers.magic_pkt = true;
8333 }
8334
77dbbb13
JB
8335 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
8336 return -EINVAL;
8337
8338 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
8339 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
8340 return -EINVAL;
8341 new_triggers.gtk_rekey_failure = true;
8342 }
8343
8344 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
8345 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
8346 return -EINVAL;
8347 new_triggers.eap_identity_req = true;
8348 }
8349
8350 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
8351 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
8352 return -EINVAL;
8353 new_triggers.four_way_handshake = true;
8354 }
8355
8356 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
8357 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
8358 return -EINVAL;
8359 new_triggers.rfkill_release = true;
8360 }
8361
ff1b6e69
JB
8362 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
8363 struct nlattr *pat;
8364 int n_patterns = 0;
bb92d199 8365 int rem, pat_len, mask_len, pkt_offset;
50ac6607 8366 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69
JB
8367
8368 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
8369 rem)
8370 n_patterns++;
8371 if (n_patterns > wowlan->n_patterns)
8372 return -EINVAL;
8373
8374 new_triggers.patterns = kcalloc(n_patterns,
8375 sizeof(new_triggers.patterns[0]),
8376 GFP_KERNEL);
8377 if (!new_triggers.patterns)
8378 return -ENOMEM;
8379
8380 new_triggers.n_patterns = n_patterns;
8381 i = 0;
8382
8383 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
8384 rem) {
50ac6607
AK
8385 nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
8386 nla_len(pat), NULL);
ff1b6e69 8387 err = -EINVAL;
50ac6607
AK
8388 if (!pat_tb[NL80211_PKTPAT_MASK] ||
8389 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 8390 goto error;
50ac6607 8391 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 8392 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 8393 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
8394 goto error;
8395 if (pat_len > wowlan->pattern_max_len ||
8396 pat_len < wowlan->pattern_min_len)
8397 goto error;
8398
50ac6607 8399 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
8400 pkt_offset = 0;
8401 else
8402 pkt_offset = nla_get_u32(
50ac6607 8403 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
8404 if (pkt_offset > wowlan->max_pkt_offset)
8405 goto error;
8406 new_triggers.patterns[i].pkt_offset = pkt_offset;
8407
ff1b6e69
JB
8408 new_triggers.patterns[i].mask =
8409 kmalloc(mask_len + pat_len, GFP_KERNEL);
8410 if (!new_triggers.patterns[i].mask) {
8411 err = -ENOMEM;
8412 goto error;
8413 }
8414 new_triggers.patterns[i].pattern =
8415 new_triggers.patterns[i].mask + mask_len;
8416 memcpy(new_triggers.patterns[i].mask,
50ac6607 8417 nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69
JB
8418 mask_len);
8419 new_triggers.patterns[i].pattern_len = pat_len;
8420 memcpy(new_triggers.patterns[i].pattern,
50ac6607 8421 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
8422 pat_len);
8423 i++;
8424 }
8425 }
8426
2a0e047e
JB
8427 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
8428 err = nl80211_parse_wowlan_tcp(
8429 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
8430 &new_triggers);
8431 if (err)
8432 goto error;
8433 }
8434
ae33bd81
JB
8435 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
8436 if (!ntrig) {
8437 err = -ENOMEM;
8438 goto error;
ff1b6e69 8439 }
ae33bd81 8440 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 8441 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 8442
ae33bd81 8443 set_wakeup:
6abb9cb9
JB
8444 if (rdev->ops->set_wakeup &&
8445 prev_enabled != !!rdev->wiphy.wowlan_config)
8446 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 8447
ff1b6e69
JB
8448 return 0;
8449 error:
8450 for (i = 0; i < new_triggers.n_patterns; i++)
8451 kfree(new_triggers.patterns[i].mask);
8452 kfree(new_triggers.patterns);
2a0e047e
JB
8453 if (new_triggers.tcp && new_triggers.tcp->sock)
8454 sock_release(new_triggers.tcp->sock);
8455 kfree(new_triggers.tcp);
ff1b6e69
JB
8456 return err;
8457}
dfb89c56 8458#endif
ff1b6e69 8459
be29b99a
AK
8460static int nl80211_send_coalesce_rules(struct sk_buff *msg,
8461 struct cfg80211_registered_device *rdev)
8462{
8463 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
8464 int i, j, pat_len;
8465 struct cfg80211_coalesce_rules *rule;
8466
8467 if (!rdev->coalesce->n_rules)
8468 return 0;
8469
8470 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE);
8471 if (!nl_rules)
8472 return -ENOBUFS;
8473
8474 for (i = 0; i < rdev->coalesce->n_rules; i++) {
8475 nl_rule = nla_nest_start(msg, i + 1);
8476 if (!nl_rule)
8477 return -ENOBUFS;
8478
8479 rule = &rdev->coalesce->rules[i];
8480 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
8481 rule->delay))
8482 return -ENOBUFS;
8483
8484 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
8485 rule->condition))
8486 return -ENOBUFS;
8487
8488 nl_pats = nla_nest_start(msg,
8489 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
8490 if (!nl_pats)
8491 return -ENOBUFS;
8492
8493 for (j = 0; j < rule->n_patterns; j++) {
8494 nl_pat = nla_nest_start(msg, j + 1);
8495 if (!nl_pat)
8496 return -ENOBUFS;
8497 pat_len = rule->patterns[j].pattern_len;
8498 if (nla_put(msg, NL80211_PKTPAT_MASK,
8499 DIV_ROUND_UP(pat_len, 8),
8500 rule->patterns[j].mask) ||
8501 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
8502 rule->patterns[j].pattern) ||
8503 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
8504 rule->patterns[j].pkt_offset))
8505 return -ENOBUFS;
8506 nla_nest_end(msg, nl_pat);
8507 }
8508 nla_nest_end(msg, nl_pats);
8509 nla_nest_end(msg, nl_rule);
8510 }
8511 nla_nest_end(msg, nl_rules);
8512
8513 return 0;
8514}
8515
8516static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
8517{
8518 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8519 struct sk_buff *msg;
8520 void *hdr;
8521
8522 if (!rdev->wiphy.coalesce)
8523 return -EOPNOTSUPP;
8524
8525 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8526 if (!msg)
8527 return -ENOMEM;
8528
8529 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8530 NL80211_CMD_GET_COALESCE);
8531 if (!hdr)
8532 goto nla_put_failure;
8533
8534 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
8535 goto nla_put_failure;
8536
8537 genlmsg_end(msg, hdr);
8538 return genlmsg_reply(msg, info);
8539
8540nla_put_failure:
8541 nlmsg_free(msg);
8542 return -ENOBUFS;
8543}
8544
8545void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
8546{
8547 struct cfg80211_coalesce *coalesce = rdev->coalesce;
8548 int i, j;
8549 struct cfg80211_coalesce_rules *rule;
8550
8551 if (!coalesce)
8552 return;
8553
8554 for (i = 0; i < coalesce->n_rules; i++) {
8555 rule = &coalesce->rules[i];
8556 for (j = 0; j < rule->n_patterns; j++)
8557 kfree(rule->patterns[j].mask);
8558 kfree(rule->patterns);
8559 }
8560 kfree(coalesce->rules);
8561 kfree(coalesce);
8562 rdev->coalesce = NULL;
8563}
8564
8565static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
8566 struct nlattr *rule,
8567 struct cfg80211_coalesce_rules *new_rule)
8568{
8569 int err, i;
8570 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
8571 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
8572 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
8573 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
8574
8575 err = nla_parse(tb, NL80211_ATTR_COALESCE_RULE_MAX, nla_data(rule),
8576 nla_len(rule), nl80211_coalesce_policy);
8577 if (err)
8578 return err;
8579
8580 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
8581 new_rule->delay =
8582 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
8583 if (new_rule->delay > coalesce->max_delay)
8584 return -EINVAL;
8585
8586 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
8587 new_rule->condition =
8588 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
8589 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH &&
8590 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH)
8591 return -EINVAL;
8592
8593 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
8594 return -EINVAL;
8595
8596 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
8597 rem)
8598 n_patterns++;
8599 if (n_patterns > coalesce->n_patterns)
8600 return -EINVAL;
8601
8602 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
8603 GFP_KERNEL);
8604 if (!new_rule->patterns)
8605 return -ENOMEM;
8606
8607 new_rule->n_patterns = n_patterns;
8608 i = 0;
8609
8610 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
8611 rem) {
8612 nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
8613 nla_len(pat), NULL);
8614 if (!pat_tb[NL80211_PKTPAT_MASK] ||
8615 !pat_tb[NL80211_PKTPAT_PATTERN])
8616 return -EINVAL;
8617 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
8618 mask_len = DIV_ROUND_UP(pat_len, 8);
8619 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
8620 return -EINVAL;
8621 if (pat_len > coalesce->pattern_max_len ||
8622 pat_len < coalesce->pattern_min_len)
8623 return -EINVAL;
8624
8625 if (!pat_tb[NL80211_PKTPAT_OFFSET])
8626 pkt_offset = 0;
8627 else
8628 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
8629 if (pkt_offset > coalesce->max_pkt_offset)
8630 return -EINVAL;
8631 new_rule->patterns[i].pkt_offset = pkt_offset;
8632
8633 new_rule->patterns[i].mask =
8634 kmalloc(mask_len + pat_len, GFP_KERNEL);
8635 if (!new_rule->patterns[i].mask)
8636 return -ENOMEM;
8637 new_rule->patterns[i].pattern =
8638 new_rule->patterns[i].mask + mask_len;
8639 memcpy(new_rule->patterns[i].mask,
8640 nla_data(pat_tb[NL80211_PKTPAT_MASK]), mask_len);
8641 new_rule->patterns[i].pattern_len = pat_len;
8642 memcpy(new_rule->patterns[i].pattern,
8643 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), pat_len);
8644 i++;
8645 }
8646
8647 return 0;
8648}
8649
8650static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
8651{
8652 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8653 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
8654 struct cfg80211_coalesce new_coalesce = {};
8655 struct cfg80211_coalesce *n_coalesce;
8656 int err, rem_rule, n_rules = 0, i, j;
8657 struct nlattr *rule;
8658 struct cfg80211_coalesce_rules *tmp_rule;
8659
8660 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
8661 return -EOPNOTSUPP;
8662
8663 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
8664 cfg80211_rdev_free_coalesce(rdev);
8665 rdev->ops->set_coalesce(&rdev->wiphy, NULL);
8666 return 0;
8667 }
8668
8669 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
8670 rem_rule)
8671 n_rules++;
8672 if (n_rules > coalesce->n_rules)
8673 return -EINVAL;
8674
8675 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
8676 GFP_KERNEL);
8677 if (!new_coalesce.rules)
8678 return -ENOMEM;
8679
8680 new_coalesce.n_rules = n_rules;
8681 i = 0;
8682
8683 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
8684 rem_rule) {
8685 err = nl80211_parse_coalesce_rule(rdev, rule,
8686 &new_coalesce.rules[i]);
8687 if (err)
8688 goto error;
8689
8690 i++;
8691 }
8692
8693 err = rdev->ops->set_coalesce(&rdev->wiphy, &new_coalesce);
8694 if (err)
8695 goto error;
8696
8697 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
8698 if (!n_coalesce) {
8699 err = -ENOMEM;
8700 goto error;
8701 }
8702 cfg80211_rdev_free_coalesce(rdev);
8703 rdev->coalesce = n_coalesce;
8704
8705 return 0;
8706error:
8707 for (i = 0; i < new_coalesce.n_rules; i++) {
8708 tmp_rule = &new_coalesce.rules[i];
8709 for (j = 0; j < tmp_rule->n_patterns; j++)
8710 kfree(tmp_rule->patterns[j].mask);
8711 kfree(tmp_rule->patterns);
8712 }
8713 kfree(new_coalesce.rules);
8714
8715 return err;
8716}
8717
e5497d76
JB
8718static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
8719{
8720 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8721 struct net_device *dev = info->user_ptr[1];
8722 struct wireless_dev *wdev = dev->ieee80211_ptr;
8723 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
8724 struct cfg80211_gtk_rekey_data rekey_data;
8725 int err;
8726
8727 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
8728 return -EINVAL;
8729
8730 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
8731 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
8732 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
8733 nl80211_rekey_policy);
8734 if (err)
8735 return err;
8736
8737 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
8738 return -ERANGE;
8739 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
8740 return -ERANGE;
8741 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
8742 return -ERANGE;
8743
8744 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
8745 NL80211_KEK_LEN);
8746 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
8747 NL80211_KCK_LEN);
8748 memcpy(rekey_data.replay_ctr,
8749 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
8750 NL80211_REPLAY_CTR_LEN);
8751
8752 wdev_lock(wdev);
8753 if (!wdev->current_bss) {
8754 err = -ENOTCONN;
8755 goto out;
8756 }
8757
8758 if (!rdev->ops->set_rekey_data) {
8759 err = -EOPNOTSUPP;
8760 goto out;
8761 }
8762
e35e4d28 8763 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
8764 out:
8765 wdev_unlock(wdev);
8766 return err;
8767}
8768
28946da7
JB
8769static int nl80211_register_unexpected_frame(struct sk_buff *skb,
8770 struct genl_info *info)
8771{
8772 struct net_device *dev = info->user_ptr[1];
8773 struct wireless_dev *wdev = dev->ieee80211_ptr;
8774
8775 if (wdev->iftype != NL80211_IFTYPE_AP &&
8776 wdev->iftype != NL80211_IFTYPE_P2P_GO)
8777 return -EINVAL;
8778
15e47304 8779 if (wdev->ap_unexpected_nlportid)
28946da7
JB
8780 return -EBUSY;
8781
15e47304 8782 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
8783 return 0;
8784}
8785
7f6cf311
JB
8786static int nl80211_probe_client(struct sk_buff *skb,
8787 struct genl_info *info)
8788{
8789 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8790 struct net_device *dev = info->user_ptr[1];
8791 struct wireless_dev *wdev = dev->ieee80211_ptr;
8792 struct sk_buff *msg;
8793 void *hdr;
8794 const u8 *addr;
8795 u64 cookie;
8796 int err;
8797
8798 if (wdev->iftype != NL80211_IFTYPE_AP &&
8799 wdev->iftype != NL80211_IFTYPE_P2P_GO)
8800 return -EOPNOTSUPP;
8801
8802 if (!info->attrs[NL80211_ATTR_MAC])
8803 return -EINVAL;
8804
8805 if (!rdev->ops->probe_client)
8806 return -EOPNOTSUPP;
8807
8808 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8809 if (!msg)
8810 return -ENOMEM;
8811
15e47304 8812 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 8813 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
8814 if (!hdr) {
8815 err = -ENOBUFS;
7f6cf311
JB
8816 goto free_msg;
8817 }
8818
8819 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
8820
e35e4d28 8821 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
8822 if (err)
8823 goto free_msg;
8824
9360ffd1
DM
8825 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8826 goto nla_put_failure;
7f6cf311
JB
8827
8828 genlmsg_end(msg, hdr);
8829
8830 return genlmsg_reply(msg, info);
8831
8832 nla_put_failure:
8833 err = -ENOBUFS;
8834 free_msg:
8835 nlmsg_free(msg);
8836 return err;
8837}
8838
5e760230
JB
8839static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
8840{
8841 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
8842 struct cfg80211_beacon_registration *reg, *nreg;
8843 int rv;
5e760230
JB
8844
8845 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
8846 return -EOPNOTSUPP;
8847
37c73b5f
BG
8848 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
8849 if (!nreg)
8850 return -ENOMEM;
8851
8852 /* First, check if already registered. */
8853 spin_lock_bh(&rdev->beacon_registrations_lock);
8854 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
8855 if (reg->nlportid == info->snd_portid) {
8856 rv = -EALREADY;
8857 goto out_err;
8858 }
8859 }
8860 /* Add it to the list */
8861 nreg->nlportid = info->snd_portid;
8862 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 8863
37c73b5f 8864 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
8865
8866 return 0;
37c73b5f
BG
8867out_err:
8868 spin_unlock_bh(&rdev->beacon_registrations_lock);
8869 kfree(nreg);
8870 return rv;
5e760230
JB
8871}
8872
98104fde
JB
8873static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
8874{
8875 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8876 struct wireless_dev *wdev = info->user_ptr[1];
8877 int err;
8878
8879 if (!rdev->ops->start_p2p_device)
8880 return -EOPNOTSUPP;
8881
8882 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
8883 return -EOPNOTSUPP;
8884
8885 if (wdev->p2p_started)
8886 return 0;
8887
98104fde 8888 err = cfg80211_can_add_interface(rdev, wdev->iftype);
98104fde
JB
8889 if (err)
8890 return err;
8891
eeb126e9 8892 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
8893 if (err)
8894 return err;
8895
8896 wdev->p2p_started = true;
98104fde 8897 rdev->opencount++;
98104fde
JB
8898
8899 return 0;
8900}
8901
8902static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
8903{
8904 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8905 struct wireless_dev *wdev = info->user_ptr[1];
8906
8907 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
8908 return -EOPNOTSUPP;
8909
8910 if (!rdev->ops->stop_p2p_device)
8911 return -EOPNOTSUPP;
8912
f9f47529 8913 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
8914
8915 return 0;
8916}
8917
3713b4e3
JB
8918static int nl80211_get_protocol_features(struct sk_buff *skb,
8919 struct genl_info *info)
8920{
8921 void *hdr;
8922 struct sk_buff *msg;
8923
8924 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8925 if (!msg)
8926 return -ENOMEM;
8927
8928 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8929 NL80211_CMD_GET_PROTOCOL_FEATURES);
8930 if (!hdr)
8931 goto nla_put_failure;
8932
8933 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
8934 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
8935 goto nla_put_failure;
8936
8937 genlmsg_end(msg, hdr);
8938 return genlmsg_reply(msg, info);
8939
8940 nla_put_failure:
8941 kfree_skb(msg);
8942 return -ENOBUFS;
8943}
8944
355199e0
JM
8945static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
8946{
8947 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8948 struct cfg80211_update_ft_ies_params ft_params;
8949 struct net_device *dev = info->user_ptr[1];
8950
8951 if (!rdev->ops->update_ft_ies)
8952 return -EOPNOTSUPP;
8953
8954 if (!info->attrs[NL80211_ATTR_MDID] ||
8955 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8956 return -EINVAL;
8957
8958 memset(&ft_params, 0, sizeof(ft_params));
8959 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
8960 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8961 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
8962
8963 return rdev_update_ft_ies(rdev, dev, &ft_params);
8964}
8965
5de17984
AS
8966static int nl80211_crit_protocol_start(struct sk_buff *skb,
8967 struct genl_info *info)
8968{
8969 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8970 struct wireless_dev *wdev = info->user_ptr[1];
8971 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
8972 u16 duration;
8973 int ret;
8974
8975 if (!rdev->ops->crit_proto_start)
8976 return -EOPNOTSUPP;
8977
8978 if (WARN_ON(!rdev->ops->crit_proto_stop))
8979 return -EINVAL;
8980
8981 if (rdev->crit_proto_nlportid)
8982 return -EBUSY;
8983
8984 /* determine protocol if provided */
8985 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
8986 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
8987
8988 if (proto >= NUM_NL80211_CRIT_PROTO)
8989 return -EINVAL;
8990
8991 /* timeout must be provided */
8992 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
8993 return -EINVAL;
8994
8995 duration =
8996 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
8997
8998 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
8999 return -ERANGE;
9000
9001 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
9002 if (!ret)
9003 rdev->crit_proto_nlportid = info->snd_portid;
9004
9005 return ret;
9006}
9007
9008static int nl80211_crit_protocol_stop(struct sk_buff *skb,
9009 struct genl_info *info)
9010{
9011 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9012 struct wireless_dev *wdev = info->user_ptr[1];
9013
9014 if (!rdev->ops->crit_proto_stop)
9015 return -EOPNOTSUPP;
9016
9017 if (rdev->crit_proto_nlportid) {
9018 rdev->crit_proto_nlportid = 0;
9019 rdev_crit_proto_stop(rdev, wdev);
9020 }
9021 return 0;
9022}
9023
ad7e718c
JB
9024static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
9025{
9026 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9027 struct wireless_dev *wdev =
9028 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
9029 int i, err;
9030 u32 vid, subcmd;
9031
9032 if (!rdev->wiphy.vendor_commands)
9033 return -EOPNOTSUPP;
9034
9035 if (IS_ERR(wdev)) {
9036 err = PTR_ERR(wdev);
9037 if (err != -EINVAL)
9038 return err;
9039 wdev = NULL;
9040 } else if (wdev->wiphy != &rdev->wiphy) {
9041 return -EINVAL;
9042 }
9043
9044 if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
9045 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
9046 return -EINVAL;
9047
9048 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
9049 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
9050 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
9051 const struct wiphy_vendor_command *vcmd;
9052 void *data = NULL;
9053 int len = 0;
9054
9055 vcmd = &rdev->wiphy.vendor_commands[i];
9056
9057 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
9058 continue;
9059
9060 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
9061 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
9062 if (!wdev)
9063 return -EINVAL;
9064 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
9065 !wdev->netdev)
9066 return -EINVAL;
9067
9068 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
9069 if (wdev->netdev &&
9070 !netif_running(wdev->netdev))
9071 return -ENETDOWN;
9072 if (!wdev->netdev && !wdev->p2p_started)
9073 return -ENETDOWN;
9074 }
9075 } else {
9076 wdev = NULL;
9077 }
9078
9079 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
9080 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
9081 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
9082 }
9083
9084 rdev->cur_cmd_info = info;
9085 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev,
9086 data, len);
9087 rdev->cur_cmd_info = NULL;
9088 return err;
9089 }
9090
9091 return -EOPNOTSUPP;
9092}
9093
9094struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
9095 enum nl80211_commands cmd,
9096 enum nl80211_attrs attr,
9097 int approxlen)
9098{
9099 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9100
9101 if (WARN_ON(!rdev->cur_cmd_info))
9102 return NULL;
9103
9104 return __cfg80211_alloc_vendor_skb(rdev, approxlen,
9105 rdev->cur_cmd_info->snd_portid,
9106 rdev->cur_cmd_info->snd_seq,
567ffc35 9107 cmd, attr, NULL, GFP_KERNEL);
ad7e718c
JB
9108}
9109EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
9110
9111int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
9112{
9113 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
9114 void *hdr = ((void **)skb->cb)[1];
9115 struct nlattr *data = ((void **)skb->cb)[2];
9116
9117 if (WARN_ON(!rdev->cur_cmd_info)) {
9118 kfree_skb(skb);
9119 return -EINVAL;
9120 }
9121
9122 nla_nest_end(skb, data);
9123 genlmsg_end(skb, hdr);
9124 return genlmsg_reply(skb, rdev->cur_cmd_info);
9125}
9126EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
9127
9128
fa9ffc74
KP
9129static int nl80211_set_qos_map(struct sk_buff *skb,
9130 struct genl_info *info)
9131{
9132 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9133 struct cfg80211_qos_map *qos_map = NULL;
9134 struct net_device *dev = info->user_ptr[1];
9135 u8 *pos, len, num_des, des_len, des;
9136 int ret;
9137
9138 if (!rdev->ops->set_qos_map)
9139 return -EOPNOTSUPP;
9140
9141 if (info->attrs[NL80211_ATTR_QOS_MAP]) {
9142 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
9143 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
9144
9145 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN ||
9146 len > IEEE80211_QOS_MAP_LEN_MAX)
9147 return -EINVAL;
9148
9149 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
9150 if (!qos_map)
9151 return -ENOMEM;
9152
9153 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
9154 if (num_des) {
9155 des_len = num_des *
9156 sizeof(struct cfg80211_dscp_exception);
9157 memcpy(qos_map->dscp_exception, pos, des_len);
9158 qos_map->num_des = num_des;
9159 for (des = 0; des < num_des; des++) {
9160 if (qos_map->dscp_exception[des].up > 7) {
9161 kfree(qos_map);
9162 return -EINVAL;
9163 }
9164 }
9165 pos += des_len;
9166 }
9167 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
9168 }
9169
9170 wdev_lock(dev->ieee80211_ptr);
9171 ret = nl80211_key_allowed(dev->ieee80211_ptr);
9172 if (!ret)
9173 ret = rdev_set_qos_map(rdev, dev, qos_map);
9174 wdev_unlock(dev->ieee80211_ptr);
9175
9176 kfree(qos_map);
9177 return ret;
9178}
9179
4c476991
JB
9180#define NL80211_FLAG_NEED_WIPHY 0x01
9181#define NL80211_FLAG_NEED_NETDEV 0x02
9182#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
9183#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
9184#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
9185 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 9186#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 9187/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
9188#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
9189 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991 9190
f84f771d 9191static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
9192 struct genl_info *info)
9193{
9194 struct cfg80211_registered_device *rdev;
89a54e48 9195 struct wireless_dev *wdev;
4c476991 9196 struct net_device *dev;
4c476991
JB
9197 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
9198
9199 if (rtnl)
9200 rtnl_lock();
9201
9202 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 9203 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
9204 if (IS_ERR(rdev)) {
9205 if (rtnl)
9206 rtnl_unlock();
9207 return PTR_ERR(rdev);
9208 }
9209 info->user_ptr[0] = rdev;
1bf614ef
JB
9210 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
9211 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
9212 ASSERT_RTNL();
9213
89a54e48
JB
9214 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
9215 info->attrs);
9216 if (IS_ERR(wdev)) {
4c476991
JB
9217 if (rtnl)
9218 rtnl_unlock();
89a54e48 9219 return PTR_ERR(wdev);
4c476991 9220 }
89a54e48 9221
89a54e48
JB
9222 dev = wdev->netdev;
9223 rdev = wiphy_to_dev(wdev->wiphy);
9224
1bf614ef
JB
9225 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
9226 if (!dev) {
1bf614ef
JB
9227 if (rtnl)
9228 rtnl_unlock();
9229 return -EINVAL;
9230 }
9231
9232 info->user_ptr[1] = dev;
9233 } else {
9234 info->user_ptr[1] = wdev;
41265714 9235 }
1bf614ef
JB
9236
9237 if (dev) {
9238 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
9239 !netif_running(dev)) {
1bf614ef
JB
9240 if (rtnl)
9241 rtnl_unlock();
9242 return -ENETDOWN;
9243 }
9244
9245 dev_hold(dev);
98104fde
JB
9246 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
9247 if (!wdev->p2p_started) {
98104fde
JB
9248 if (rtnl)
9249 rtnl_unlock();
9250 return -ENETDOWN;
9251 }
41265714 9252 }
89a54e48 9253
4c476991 9254 info->user_ptr[0] = rdev;
4c476991
JB
9255 }
9256
9257 return 0;
9258}
9259
f84f771d 9260static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
9261 struct genl_info *info)
9262{
1bf614ef
JB
9263 if (info->user_ptr[1]) {
9264 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
9265 struct wireless_dev *wdev = info->user_ptr[1];
9266
9267 if (wdev->netdev)
9268 dev_put(wdev->netdev);
9269 } else {
9270 dev_put(info->user_ptr[1]);
9271 }
9272 }
4c476991
JB
9273 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
9274 rtnl_unlock();
9275}
9276
4534de83 9277static const struct genl_ops nl80211_ops[] = {
55682965
JB
9278 {
9279 .cmd = NL80211_CMD_GET_WIPHY,
9280 .doit = nl80211_get_wiphy,
9281 .dumpit = nl80211_dump_wiphy,
86e8cf98 9282 .done = nl80211_dump_wiphy_done,
55682965
JB
9283 .policy = nl80211_policy,
9284 /* can be retrieved by unprivileged users */
5fe231e8
JB
9285 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9286 NL80211_FLAG_NEED_RTNL,
55682965
JB
9287 },
9288 {
9289 .cmd = NL80211_CMD_SET_WIPHY,
9290 .doit = nl80211_set_wiphy,
9291 .policy = nl80211_policy,
9292 .flags = GENL_ADMIN_PERM,
4c476991 9293 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
9294 },
9295 {
9296 .cmd = NL80211_CMD_GET_INTERFACE,
9297 .doit = nl80211_get_interface,
9298 .dumpit = nl80211_dump_interface,
9299 .policy = nl80211_policy,
9300 /* can be retrieved by unprivileged users */
5fe231e8
JB
9301 .internal_flags = NL80211_FLAG_NEED_WDEV |
9302 NL80211_FLAG_NEED_RTNL,
55682965
JB
9303 },
9304 {
9305 .cmd = NL80211_CMD_SET_INTERFACE,
9306 .doit = nl80211_set_interface,
9307 .policy = nl80211_policy,
9308 .flags = GENL_ADMIN_PERM,
4c476991
JB
9309 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9310 NL80211_FLAG_NEED_RTNL,
55682965
JB
9311 },
9312 {
9313 .cmd = NL80211_CMD_NEW_INTERFACE,
9314 .doit = nl80211_new_interface,
9315 .policy = nl80211_policy,
9316 .flags = GENL_ADMIN_PERM,
4c476991
JB
9317 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9318 NL80211_FLAG_NEED_RTNL,
55682965
JB
9319 },
9320 {
9321 .cmd = NL80211_CMD_DEL_INTERFACE,
9322 .doit = nl80211_del_interface,
9323 .policy = nl80211_policy,
41ade00f 9324 .flags = GENL_ADMIN_PERM,
84efbb84 9325 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 9326 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
9327 },
9328 {
9329 .cmd = NL80211_CMD_GET_KEY,
9330 .doit = nl80211_get_key,
9331 .policy = nl80211_policy,
9332 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9333 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9334 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
9335 },
9336 {
9337 .cmd = NL80211_CMD_SET_KEY,
9338 .doit = nl80211_set_key,
9339 .policy = nl80211_policy,
9340 .flags = GENL_ADMIN_PERM,
41265714 9341 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9342 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
9343 },
9344 {
9345 .cmd = NL80211_CMD_NEW_KEY,
9346 .doit = nl80211_new_key,
9347 .policy = nl80211_policy,
9348 .flags = GENL_ADMIN_PERM,
41265714 9349 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9350 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
9351 },
9352 {
9353 .cmd = NL80211_CMD_DEL_KEY,
9354 .doit = nl80211_del_key,
9355 .policy = nl80211_policy,
55682965 9356 .flags = GENL_ADMIN_PERM,
41265714 9357 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9358 NL80211_FLAG_NEED_RTNL,
55682965 9359 },
ed1b6cc7
JB
9360 {
9361 .cmd = NL80211_CMD_SET_BEACON,
9362 .policy = nl80211_policy,
9363 .flags = GENL_ADMIN_PERM,
8860020e 9364 .doit = nl80211_set_beacon,
2b5f8b0b 9365 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9366 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
9367 },
9368 {
8860020e 9369 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
9370 .policy = nl80211_policy,
9371 .flags = GENL_ADMIN_PERM,
8860020e 9372 .doit = nl80211_start_ap,
2b5f8b0b 9373 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9374 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
9375 },
9376 {
8860020e 9377 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
9378 .policy = nl80211_policy,
9379 .flags = GENL_ADMIN_PERM,
8860020e 9380 .doit = nl80211_stop_ap,
2b5f8b0b 9381 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9382 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 9383 },
5727ef1b
JB
9384 {
9385 .cmd = NL80211_CMD_GET_STATION,
9386 .doit = nl80211_get_station,
2ec600d6 9387 .dumpit = nl80211_dump_station,
5727ef1b 9388 .policy = nl80211_policy,
4c476991
JB
9389 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9390 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
9391 },
9392 {
9393 .cmd = NL80211_CMD_SET_STATION,
9394 .doit = nl80211_set_station,
9395 .policy = nl80211_policy,
9396 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9397 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9398 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
9399 },
9400 {
9401 .cmd = NL80211_CMD_NEW_STATION,
9402 .doit = nl80211_new_station,
9403 .policy = nl80211_policy,
9404 .flags = GENL_ADMIN_PERM,
41265714 9405 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9406 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
9407 },
9408 {
9409 .cmd = NL80211_CMD_DEL_STATION,
9410 .doit = nl80211_del_station,
9411 .policy = nl80211_policy,
2ec600d6 9412 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9413 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9414 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9415 },
9416 {
9417 .cmd = NL80211_CMD_GET_MPATH,
9418 .doit = nl80211_get_mpath,
9419 .dumpit = nl80211_dump_mpath,
9420 .policy = nl80211_policy,
9421 .flags = GENL_ADMIN_PERM,
41265714 9422 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9423 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9424 },
9425 {
9426 .cmd = NL80211_CMD_SET_MPATH,
9427 .doit = nl80211_set_mpath,
9428 .policy = nl80211_policy,
9429 .flags = GENL_ADMIN_PERM,
41265714 9430 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9431 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9432 },
9433 {
9434 .cmd = NL80211_CMD_NEW_MPATH,
9435 .doit = nl80211_new_mpath,
9436 .policy = nl80211_policy,
9437 .flags = GENL_ADMIN_PERM,
41265714 9438 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9439 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
9440 },
9441 {
9442 .cmd = NL80211_CMD_DEL_MPATH,
9443 .doit = nl80211_del_mpath,
9444 .policy = nl80211_policy,
9f1ba906 9445 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9446 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9447 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
9448 },
9449 {
9450 .cmd = NL80211_CMD_SET_BSS,
9451 .doit = nl80211_set_bss,
9452 .policy = nl80211_policy,
b2e1b302 9453 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9454 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9455 NL80211_FLAG_NEED_RTNL,
b2e1b302 9456 },
f130347c
LR
9457 {
9458 .cmd = NL80211_CMD_GET_REG,
9459 .doit = nl80211_get_reg,
9460 .policy = nl80211_policy,
5fe231e8 9461 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
9462 /* can be retrieved by unprivileged users */
9463 },
b2e1b302
LR
9464 {
9465 .cmd = NL80211_CMD_SET_REG,
9466 .doit = nl80211_set_reg,
9467 .policy = nl80211_policy,
9468 .flags = GENL_ADMIN_PERM,
5fe231e8 9469 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302
LR
9470 },
9471 {
9472 .cmd = NL80211_CMD_REQ_SET_REG,
9473 .doit = nl80211_req_set_reg,
9474 .policy = nl80211_policy,
93da9cc1 9475 .flags = GENL_ADMIN_PERM,
9476 },
9477 {
24bdd9f4
JC
9478 .cmd = NL80211_CMD_GET_MESH_CONFIG,
9479 .doit = nl80211_get_mesh_config,
93da9cc1 9480 .policy = nl80211_policy,
9481 /* can be retrieved by unprivileged users */
2b5f8b0b 9482 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9483 NL80211_FLAG_NEED_RTNL,
93da9cc1 9484 },
9485 {
24bdd9f4
JC
9486 .cmd = NL80211_CMD_SET_MESH_CONFIG,
9487 .doit = nl80211_update_mesh_config,
93da9cc1 9488 .policy = nl80211_policy,
9aed3cc1 9489 .flags = GENL_ADMIN_PERM,
29cbe68c 9490 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9491 NL80211_FLAG_NEED_RTNL,
9aed3cc1 9492 },
2a519311
JB
9493 {
9494 .cmd = NL80211_CMD_TRIGGER_SCAN,
9495 .doit = nl80211_trigger_scan,
9496 .policy = nl80211_policy,
9497 .flags = GENL_ADMIN_PERM,
fd014284 9498 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9499 NL80211_FLAG_NEED_RTNL,
2a519311
JB
9500 },
9501 {
9502 .cmd = NL80211_CMD_GET_SCAN,
9503 .policy = nl80211_policy,
9504 .dumpit = nl80211_dump_scan,
9505 },
807f8a8c
LC
9506 {
9507 .cmd = NL80211_CMD_START_SCHED_SCAN,
9508 .doit = nl80211_start_sched_scan,
9509 .policy = nl80211_policy,
9510 .flags = GENL_ADMIN_PERM,
9511 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9512 NL80211_FLAG_NEED_RTNL,
9513 },
9514 {
9515 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
9516 .doit = nl80211_stop_sched_scan,
9517 .policy = nl80211_policy,
9518 .flags = GENL_ADMIN_PERM,
9519 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9520 NL80211_FLAG_NEED_RTNL,
9521 },
636a5d36
JM
9522 {
9523 .cmd = NL80211_CMD_AUTHENTICATE,
9524 .doit = nl80211_authenticate,
9525 .policy = nl80211_policy,
9526 .flags = GENL_ADMIN_PERM,
41265714 9527 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9528 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
9529 },
9530 {
9531 .cmd = NL80211_CMD_ASSOCIATE,
9532 .doit = nl80211_associate,
9533 .policy = nl80211_policy,
9534 .flags = GENL_ADMIN_PERM,
41265714 9535 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9536 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
9537 },
9538 {
9539 .cmd = NL80211_CMD_DEAUTHENTICATE,
9540 .doit = nl80211_deauthenticate,
9541 .policy = nl80211_policy,
9542 .flags = GENL_ADMIN_PERM,
41265714 9543 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9544 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
9545 },
9546 {
9547 .cmd = NL80211_CMD_DISASSOCIATE,
9548 .doit = nl80211_disassociate,
9549 .policy = nl80211_policy,
9550 .flags = GENL_ADMIN_PERM,
41265714 9551 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9552 NL80211_FLAG_NEED_RTNL,
636a5d36 9553 },
04a773ad
JB
9554 {
9555 .cmd = NL80211_CMD_JOIN_IBSS,
9556 .doit = nl80211_join_ibss,
9557 .policy = nl80211_policy,
9558 .flags = GENL_ADMIN_PERM,
41265714 9559 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9560 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
9561 },
9562 {
9563 .cmd = NL80211_CMD_LEAVE_IBSS,
9564 .doit = nl80211_leave_ibss,
9565 .policy = nl80211_policy,
9566 .flags = GENL_ADMIN_PERM,
41265714 9567 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9568 NL80211_FLAG_NEED_RTNL,
04a773ad 9569 },
aff89a9b
JB
9570#ifdef CONFIG_NL80211_TESTMODE
9571 {
9572 .cmd = NL80211_CMD_TESTMODE,
9573 .doit = nl80211_testmode_do,
71063f0e 9574 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
9575 .policy = nl80211_policy,
9576 .flags = GENL_ADMIN_PERM,
4c476991
JB
9577 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9578 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
9579 },
9580#endif
b23aa676
SO
9581 {
9582 .cmd = NL80211_CMD_CONNECT,
9583 .doit = nl80211_connect,
9584 .policy = nl80211_policy,
9585 .flags = GENL_ADMIN_PERM,
41265714 9586 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9587 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
9588 },
9589 {
9590 .cmd = NL80211_CMD_DISCONNECT,
9591 .doit = nl80211_disconnect,
9592 .policy = nl80211_policy,
9593 .flags = GENL_ADMIN_PERM,
41265714 9594 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9595 NL80211_FLAG_NEED_RTNL,
b23aa676 9596 },
463d0183
JB
9597 {
9598 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
9599 .doit = nl80211_wiphy_netns,
9600 .policy = nl80211_policy,
9601 .flags = GENL_ADMIN_PERM,
4c476991
JB
9602 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9603 NL80211_FLAG_NEED_RTNL,
463d0183 9604 },
61fa713c
HS
9605 {
9606 .cmd = NL80211_CMD_GET_SURVEY,
9607 .policy = nl80211_policy,
9608 .dumpit = nl80211_dump_survey,
9609 },
67fbb16b
SO
9610 {
9611 .cmd = NL80211_CMD_SET_PMKSA,
9612 .doit = nl80211_setdel_pmksa,
9613 .policy = nl80211_policy,
9614 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9615 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9616 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
9617 },
9618 {
9619 .cmd = NL80211_CMD_DEL_PMKSA,
9620 .doit = nl80211_setdel_pmksa,
9621 .policy = nl80211_policy,
9622 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9623 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9624 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
9625 },
9626 {
9627 .cmd = NL80211_CMD_FLUSH_PMKSA,
9628 .doit = nl80211_flush_pmksa,
9629 .policy = nl80211_policy,
9630 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9631 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 9632 NL80211_FLAG_NEED_RTNL,
67fbb16b 9633 },
9588bbd5
JM
9634 {
9635 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
9636 .doit = nl80211_remain_on_channel,
9637 .policy = nl80211_policy,
9638 .flags = GENL_ADMIN_PERM,
71bbc994 9639 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9640 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
9641 },
9642 {
9643 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
9644 .doit = nl80211_cancel_remain_on_channel,
9645 .policy = nl80211_policy,
9646 .flags = GENL_ADMIN_PERM,
71bbc994 9647 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9648 NL80211_FLAG_NEED_RTNL,
9588bbd5 9649 },
13ae75b1
JM
9650 {
9651 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
9652 .doit = nl80211_set_tx_bitrate_mask,
9653 .policy = nl80211_policy,
9654 .flags = GENL_ADMIN_PERM,
4c476991
JB
9655 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9656 NL80211_FLAG_NEED_RTNL,
13ae75b1 9657 },
026331c4 9658 {
2e161f78
JB
9659 .cmd = NL80211_CMD_REGISTER_FRAME,
9660 .doit = nl80211_register_mgmt,
026331c4
JM
9661 .policy = nl80211_policy,
9662 .flags = GENL_ADMIN_PERM,
71bbc994 9663 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 9664 NL80211_FLAG_NEED_RTNL,
026331c4
JM
9665 },
9666 {
2e161f78
JB
9667 .cmd = NL80211_CMD_FRAME,
9668 .doit = nl80211_tx_mgmt,
026331c4 9669 .policy = nl80211_policy,
f7ca38df 9670 .flags = GENL_ADMIN_PERM,
71bbc994 9671 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
9672 NL80211_FLAG_NEED_RTNL,
9673 },
9674 {
9675 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
9676 .doit = nl80211_tx_mgmt_cancel_wait,
9677 .policy = nl80211_policy,
026331c4 9678 .flags = GENL_ADMIN_PERM,
71bbc994 9679 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 9680 NL80211_FLAG_NEED_RTNL,
026331c4 9681 },
ffb9eb3d
KV
9682 {
9683 .cmd = NL80211_CMD_SET_POWER_SAVE,
9684 .doit = nl80211_set_power_save,
9685 .policy = nl80211_policy,
9686 .flags = GENL_ADMIN_PERM,
4c476991
JB
9687 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9688 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
9689 },
9690 {
9691 .cmd = NL80211_CMD_GET_POWER_SAVE,
9692 .doit = nl80211_get_power_save,
9693 .policy = nl80211_policy,
9694 /* can be retrieved by unprivileged users */
4c476991
JB
9695 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9696 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 9697 },
d6dc1a38
JO
9698 {
9699 .cmd = NL80211_CMD_SET_CQM,
9700 .doit = nl80211_set_cqm,
9701 .policy = nl80211_policy,
9702 .flags = GENL_ADMIN_PERM,
4c476991
JB
9703 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9704 NL80211_FLAG_NEED_RTNL,
d6dc1a38 9705 },
f444de05
JB
9706 {
9707 .cmd = NL80211_CMD_SET_CHANNEL,
9708 .doit = nl80211_set_channel,
9709 .policy = nl80211_policy,
9710 .flags = GENL_ADMIN_PERM,
4c476991
JB
9711 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9712 NL80211_FLAG_NEED_RTNL,
f444de05 9713 },
e8347eba
BJ
9714 {
9715 .cmd = NL80211_CMD_SET_WDS_PEER,
9716 .doit = nl80211_set_wds_peer,
9717 .policy = nl80211_policy,
9718 .flags = GENL_ADMIN_PERM,
43b19952
JB
9719 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9720 NL80211_FLAG_NEED_RTNL,
e8347eba 9721 },
29cbe68c
JB
9722 {
9723 .cmd = NL80211_CMD_JOIN_MESH,
9724 .doit = nl80211_join_mesh,
9725 .policy = nl80211_policy,
9726 .flags = GENL_ADMIN_PERM,
9727 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9728 NL80211_FLAG_NEED_RTNL,
9729 },
9730 {
9731 .cmd = NL80211_CMD_LEAVE_MESH,
9732 .doit = nl80211_leave_mesh,
9733 .policy = nl80211_policy,
9734 .flags = GENL_ADMIN_PERM,
9735 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9736 NL80211_FLAG_NEED_RTNL,
9737 },
dfb89c56 9738#ifdef CONFIG_PM
ff1b6e69
JB
9739 {
9740 .cmd = NL80211_CMD_GET_WOWLAN,
9741 .doit = nl80211_get_wowlan,
9742 .policy = nl80211_policy,
9743 /* can be retrieved by unprivileged users */
9744 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9745 NL80211_FLAG_NEED_RTNL,
9746 },
9747 {
9748 .cmd = NL80211_CMD_SET_WOWLAN,
9749 .doit = nl80211_set_wowlan,
9750 .policy = nl80211_policy,
9751 .flags = GENL_ADMIN_PERM,
9752 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9753 NL80211_FLAG_NEED_RTNL,
9754 },
dfb89c56 9755#endif
e5497d76
JB
9756 {
9757 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
9758 .doit = nl80211_set_rekey_data,
9759 .policy = nl80211_policy,
9760 .flags = GENL_ADMIN_PERM,
9761 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9762 NL80211_FLAG_NEED_RTNL,
9763 },
109086ce
AN
9764 {
9765 .cmd = NL80211_CMD_TDLS_MGMT,
9766 .doit = nl80211_tdls_mgmt,
9767 .policy = nl80211_policy,
9768 .flags = GENL_ADMIN_PERM,
9769 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9770 NL80211_FLAG_NEED_RTNL,
9771 },
9772 {
9773 .cmd = NL80211_CMD_TDLS_OPER,
9774 .doit = nl80211_tdls_oper,
9775 .policy = nl80211_policy,
9776 .flags = GENL_ADMIN_PERM,
9777 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9778 NL80211_FLAG_NEED_RTNL,
9779 },
28946da7
JB
9780 {
9781 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
9782 .doit = nl80211_register_unexpected_frame,
9783 .policy = nl80211_policy,
9784 .flags = GENL_ADMIN_PERM,
9785 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9786 NL80211_FLAG_NEED_RTNL,
9787 },
7f6cf311
JB
9788 {
9789 .cmd = NL80211_CMD_PROBE_CLIENT,
9790 .doit = nl80211_probe_client,
9791 .policy = nl80211_policy,
9792 .flags = GENL_ADMIN_PERM,
2b5f8b0b 9793 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
9794 NL80211_FLAG_NEED_RTNL,
9795 },
5e760230
JB
9796 {
9797 .cmd = NL80211_CMD_REGISTER_BEACONS,
9798 .doit = nl80211_register_beacons,
9799 .policy = nl80211_policy,
9800 .flags = GENL_ADMIN_PERM,
9801 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9802 NL80211_FLAG_NEED_RTNL,
9803 },
1d9d9213
SW
9804 {
9805 .cmd = NL80211_CMD_SET_NOACK_MAP,
9806 .doit = nl80211_set_noack_map,
9807 .policy = nl80211_policy,
9808 .flags = GENL_ADMIN_PERM,
9809 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9810 NL80211_FLAG_NEED_RTNL,
9811 },
98104fde
JB
9812 {
9813 .cmd = NL80211_CMD_START_P2P_DEVICE,
9814 .doit = nl80211_start_p2p_device,
9815 .policy = nl80211_policy,
9816 .flags = GENL_ADMIN_PERM,
9817 .internal_flags = NL80211_FLAG_NEED_WDEV |
9818 NL80211_FLAG_NEED_RTNL,
9819 },
9820 {
9821 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
9822 .doit = nl80211_stop_p2p_device,
9823 .policy = nl80211_policy,
9824 .flags = GENL_ADMIN_PERM,
9825 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9826 NL80211_FLAG_NEED_RTNL,
9827 },
f4e583c8
AQ
9828 {
9829 .cmd = NL80211_CMD_SET_MCAST_RATE,
9830 .doit = nl80211_set_mcast_rate,
77765eaf
VT
9831 .policy = nl80211_policy,
9832 .flags = GENL_ADMIN_PERM,
9833 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9834 NL80211_FLAG_NEED_RTNL,
9835 },
9836 {
9837 .cmd = NL80211_CMD_SET_MAC_ACL,
9838 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
9839 .policy = nl80211_policy,
9840 .flags = GENL_ADMIN_PERM,
9841 .internal_flags = NL80211_FLAG_NEED_NETDEV |
9842 NL80211_FLAG_NEED_RTNL,
9843 },
04f39047
SW
9844 {
9845 .cmd = NL80211_CMD_RADAR_DETECT,
9846 .doit = nl80211_start_radar_detection,
9847 .policy = nl80211_policy,
9848 .flags = GENL_ADMIN_PERM,
9849 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9850 NL80211_FLAG_NEED_RTNL,
9851 },
3713b4e3
JB
9852 {
9853 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
9854 .doit = nl80211_get_protocol_features,
9855 .policy = nl80211_policy,
9856 },
355199e0
JM
9857 {
9858 .cmd = NL80211_CMD_UPDATE_FT_IES,
9859 .doit = nl80211_update_ft_ies,
9860 .policy = nl80211_policy,
9861 .flags = GENL_ADMIN_PERM,
9862 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9863 NL80211_FLAG_NEED_RTNL,
9864 },
5de17984
AS
9865 {
9866 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
9867 .doit = nl80211_crit_protocol_start,
9868 .policy = nl80211_policy,
9869 .flags = GENL_ADMIN_PERM,
9870 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9871 NL80211_FLAG_NEED_RTNL,
9872 },
9873 {
9874 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
9875 .doit = nl80211_crit_protocol_stop,
9876 .policy = nl80211_policy,
9877 .flags = GENL_ADMIN_PERM,
9878 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
9879 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
9880 },
9881 {
9882 .cmd = NL80211_CMD_GET_COALESCE,
9883 .doit = nl80211_get_coalesce,
9884 .policy = nl80211_policy,
9885 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9886 NL80211_FLAG_NEED_RTNL,
9887 },
9888 {
9889 .cmd = NL80211_CMD_SET_COALESCE,
9890 .doit = nl80211_set_coalesce,
9891 .policy = nl80211_policy,
9892 .flags = GENL_ADMIN_PERM,
9893 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9894 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
9895 },
9896 {
9897 .cmd = NL80211_CMD_CHANNEL_SWITCH,
9898 .doit = nl80211_channel_switch,
9899 .policy = nl80211_policy,
9900 .flags = GENL_ADMIN_PERM,
9901 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9902 NL80211_FLAG_NEED_RTNL,
9903 },
ad7e718c
JB
9904 {
9905 .cmd = NL80211_CMD_VENDOR,
9906 .doit = nl80211_vendor_cmd,
9907 .policy = nl80211_policy,
9908 .flags = GENL_ADMIN_PERM,
9909 .internal_flags = NL80211_FLAG_NEED_WIPHY |
9910 NL80211_FLAG_NEED_RTNL,
9911 },
fa9ffc74
KP
9912 {
9913 .cmd = NL80211_CMD_SET_QOS_MAP,
9914 .doit = nl80211_set_qos_map,
9915 .policy = nl80211_policy,
9916 .flags = GENL_ADMIN_PERM,
9917 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
9918 NL80211_FLAG_NEED_RTNL,
9919 },
55682965 9920};
9588bbd5 9921
55682965
JB
9922/* notification functions */
9923
9924void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
9925{
9926 struct sk_buff *msg;
86e8cf98 9927 struct nl80211_dump_wiphy_state state = {};
55682965 9928
fd2120ca 9929 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
9930 if (!msg)
9931 return;
9932
86e8cf98 9933 if (nl80211_send_wiphy(rdev, msg, 0, 0, 0, &state) < 0) {
55682965
JB
9934 nlmsg_free(msg);
9935 return;
9936 }
9937
68eb5503 9938 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 9939 NL80211_MCGRP_CONFIG, GFP_KERNEL);
55682965
JB
9940}
9941
362a415d
JB
9942static int nl80211_add_scan_req(struct sk_buff *msg,
9943 struct cfg80211_registered_device *rdev)
9944{
9945 struct cfg80211_scan_request *req = rdev->scan_req;
9946 struct nlattr *nest;
9947 int i;
9948
9949 if (WARN_ON(!req))
9950 return 0;
9951
9952 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
9953 if (!nest)
9954 goto nla_put_failure;
9360ffd1
DM
9955 for (i = 0; i < req->n_ssids; i++) {
9956 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
9957 goto nla_put_failure;
9958 }
362a415d
JB
9959 nla_nest_end(msg, nest);
9960
9961 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
9962 if (!nest)
9963 goto nla_put_failure;
9360ffd1
DM
9964 for (i = 0; i < req->n_channels; i++) {
9965 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
9966 goto nla_put_failure;
9967 }
362a415d
JB
9968 nla_nest_end(msg, nest);
9969
9360ffd1
DM
9970 if (req->ie &&
9971 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
9972 goto nla_put_failure;
362a415d 9973
ae917c9f
JB
9974 if (req->flags &&
9975 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
9976 goto nla_put_failure;
ed473771 9977
362a415d
JB
9978 return 0;
9979 nla_put_failure:
9980 return -ENOBUFS;
9981}
9982
a538e2d5
JB
9983static int nl80211_send_scan_msg(struct sk_buff *msg,
9984 struct cfg80211_registered_device *rdev,
fd014284 9985 struct wireless_dev *wdev,
15e47304 9986 u32 portid, u32 seq, int flags,
a538e2d5 9987 u32 cmd)
2a519311
JB
9988{
9989 void *hdr;
9990
15e47304 9991 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
9992 if (!hdr)
9993 return -1;
9994
9360ffd1 9995 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
9996 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9997 wdev->netdev->ifindex)) ||
9998 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 9999 goto nla_put_failure;
2a519311 10000
362a415d
JB
10001 /* ignore errors and send incomplete event anyway */
10002 nl80211_add_scan_req(msg, rdev);
2a519311
JB
10003
10004 return genlmsg_end(msg, hdr);
10005
10006 nla_put_failure:
10007 genlmsg_cancel(msg, hdr);
10008 return -EMSGSIZE;
10009}
10010
807f8a8c
LC
10011static int
10012nl80211_send_sched_scan_msg(struct sk_buff *msg,
10013 struct cfg80211_registered_device *rdev,
10014 struct net_device *netdev,
15e47304 10015 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
10016{
10017 void *hdr;
10018
15e47304 10019 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
10020 if (!hdr)
10021 return -1;
10022
9360ffd1
DM
10023 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10024 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
10025 goto nla_put_failure;
807f8a8c
LC
10026
10027 return genlmsg_end(msg, hdr);
10028
10029 nla_put_failure:
10030 genlmsg_cancel(msg, hdr);
10031 return -EMSGSIZE;
10032}
10033
a538e2d5 10034void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 10035 struct wireless_dev *wdev)
a538e2d5
JB
10036{
10037 struct sk_buff *msg;
10038
58050fce 10039 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
10040 if (!msg)
10041 return;
10042
fd014284 10043 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
10044 NL80211_CMD_TRIGGER_SCAN) < 0) {
10045 nlmsg_free(msg);
10046 return;
10047 }
10048
68eb5503 10049 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10050 NL80211_MCGRP_SCAN, GFP_KERNEL);
a538e2d5
JB
10051}
10052
2a519311 10053void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 10054 struct wireless_dev *wdev)
2a519311
JB
10055{
10056 struct sk_buff *msg;
10057
fd2120ca 10058 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
10059 if (!msg)
10060 return;
10061
fd014284 10062 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 10063 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
10064 nlmsg_free(msg);
10065 return;
10066 }
10067
68eb5503 10068 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10069 NL80211_MCGRP_SCAN, GFP_KERNEL);
2a519311
JB
10070}
10071
10072void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 10073 struct wireless_dev *wdev)
2a519311
JB
10074{
10075 struct sk_buff *msg;
10076
fd2120ca 10077 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
10078 if (!msg)
10079 return;
10080
fd014284 10081 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 10082 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
10083 nlmsg_free(msg);
10084 return;
10085 }
10086
68eb5503 10087 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10088 NL80211_MCGRP_SCAN, GFP_KERNEL);
2a519311
JB
10089}
10090
807f8a8c
LC
10091void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
10092 struct net_device *netdev)
10093{
10094 struct sk_buff *msg;
10095
10096 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10097 if (!msg)
10098 return;
10099
10100 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
10101 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
10102 nlmsg_free(msg);
10103 return;
10104 }
10105
68eb5503 10106 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10107 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
10108}
10109
10110void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
10111 struct net_device *netdev, u32 cmd)
10112{
10113 struct sk_buff *msg;
10114
58050fce 10115 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
10116 if (!msg)
10117 return;
10118
10119 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
10120 nlmsg_free(msg);
10121 return;
10122 }
10123
68eb5503 10124 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10125 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
10126}
10127
73d54c9e
LR
10128/*
10129 * This can happen on global regulatory changes or device specific settings
10130 * based on custom world regulatory domains.
10131 */
10132void nl80211_send_reg_change_event(struct regulatory_request *request)
10133{
10134 struct sk_buff *msg;
10135 void *hdr;
10136
fd2120ca 10137 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
10138 if (!msg)
10139 return;
10140
10141 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
10142 if (!hdr) {
10143 nlmsg_free(msg);
10144 return;
10145 }
10146
10147 /* Userspace can always count this one always being set */
9360ffd1
DM
10148 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
10149 goto nla_put_failure;
10150
10151 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
10152 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
10153 NL80211_REGDOM_TYPE_WORLD))
10154 goto nla_put_failure;
10155 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
10156 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
10157 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
10158 goto nla_put_failure;
10159 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
10160 request->intersect) {
10161 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
10162 NL80211_REGDOM_TYPE_INTERSECTION))
10163 goto nla_put_failure;
10164 } else {
10165 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
10166 NL80211_REGDOM_TYPE_COUNTRY) ||
10167 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
10168 request->alpha2))
10169 goto nla_put_failure;
10170 }
10171
f4173766 10172 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
10173 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
10174 goto nla_put_failure;
73d54c9e 10175
3b7b72ee 10176 genlmsg_end(msg, hdr);
73d54c9e 10177
bc43b28c 10178 rcu_read_lock();
68eb5503 10179 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 10180 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
bc43b28c 10181 rcu_read_unlock();
73d54c9e
LR
10182
10183 return;
10184
10185nla_put_failure:
10186 genlmsg_cancel(msg, hdr);
10187 nlmsg_free(msg);
10188}
10189
6039f6d2
JM
10190static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
10191 struct net_device *netdev,
10192 const u8 *buf, size_t len,
e6d6e342 10193 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
10194{
10195 struct sk_buff *msg;
10196 void *hdr;
10197
e6d6e342 10198 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
10199 if (!msg)
10200 return;
10201
10202 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
10203 if (!hdr) {
10204 nlmsg_free(msg);
10205 return;
10206 }
10207
9360ffd1
DM
10208 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10209 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10210 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
10211 goto nla_put_failure;
6039f6d2 10212
3b7b72ee 10213 genlmsg_end(msg, hdr);
6039f6d2 10214
68eb5503 10215 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10216 NL80211_MCGRP_MLME, gfp);
6039f6d2
JM
10217 return;
10218
10219 nla_put_failure:
10220 genlmsg_cancel(msg, hdr);
10221 nlmsg_free(msg);
10222}
10223
10224void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
10225 struct net_device *netdev, const u8 *buf,
10226 size_t len, gfp_t gfp)
6039f6d2
JM
10227{
10228 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 10229 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
10230}
10231
10232void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
10233 struct net_device *netdev, const u8 *buf,
e6d6e342 10234 size_t len, gfp_t gfp)
6039f6d2 10235{
e6d6e342
JB
10236 nl80211_send_mlme_event(rdev, netdev, buf, len,
10237 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
10238}
10239
53b46b84 10240void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
10241 struct net_device *netdev, const u8 *buf,
10242 size_t len, gfp_t gfp)
6039f6d2
JM
10243{
10244 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 10245 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
10246}
10247
53b46b84
JM
10248void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
10249 struct net_device *netdev, const u8 *buf,
e6d6e342 10250 size_t len, gfp_t gfp)
6039f6d2
JM
10251{
10252 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 10253 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
10254}
10255
6ff57cf8
JB
10256void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
10257 size_t len)
cf4e594e 10258{
947add36
JB
10259 struct wireless_dev *wdev = dev->ieee80211_ptr;
10260 struct wiphy *wiphy = wdev->wiphy;
10261 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6ff57cf8
JB
10262 const struct ieee80211_mgmt *mgmt = (void *)buf;
10263 u32 cmd;
947add36 10264
6ff57cf8
JB
10265 if (WARN_ON(len < 2))
10266 return;
cf4e594e 10267
6ff57cf8
JB
10268 if (ieee80211_is_deauth(mgmt->frame_control))
10269 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
10270 else
10271 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 10272
6ff57cf8
JB
10273 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
10274 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC);
cf4e594e 10275}
6ff57cf8 10276EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 10277
1b06bb40
LR
10278static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
10279 struct net_device *netdev, int cmd,
e6d6e342 10280 const u8 *addr, gfp_t gfp)
1965c853
JM
10281{
10282 struct sk_buff *msg;
10283 void *hdr;
10284
e6d6e342 10285 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
10286 if (!msg)
10287 return;
10288
10289 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
10290 if (!hdr) {
10291 nlmsg_free(msg);
10292 return;
10293 }
10294
9360ffd1
DM
10295 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10296 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10297 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
10298 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
10299 goto nla_put_failure;
1965c853 10300
3b7b72ee 10301 genlmsg_end(msg, hdr);
1965c853 10302
68eb5503 10303 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10304 NL80211_MCGRP_MLME, gfp);
1965c853
JM
10305 return;
10306
10307 nla_put_failure:
10308 genlmsg_cancel(msg, hdr);
10309 nlmsg_free(msg);
10310}
10311
10312void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
10313 struct net_device *netdev, const u8 *addr,
10314 gfp_t gfp)
1965c853
JM
10315{
10316 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 10317 addr, gfp);
1965c853
JM
10318}
10319
10320void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
10321 struct net_device *netdev, const u8 *addr,
10322 gfp_t gfp)
1965c853 10323{
e6d6e342
JB
10324 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
10325 addr, gfp);
1965c853
JM
10326}
10327
b23aa676
SO
10328void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
10329 struct net_device *netdev, const u8 *bssid,
10330 const u8 *req_ie, size_t req_ie_len,
10331 const u8 *resp_ie, size_t resp_ie_len,
10332 u16 status, gfp_t gfp)
10333{
10334 struct sk_buff *msg;
10335 void *hdr;
10336
58050fce 10337 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
10338 if (!msg)
10339 return;
10340
10341 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
10342 if (!hdr) {
10343 nlmsg_free(msg);
10344 return;
10345 }
10346
9360ffd1
DM
10347 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10348 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10349 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
10350 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
10351 (req_ie &&
10352 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
10353 (resp_ie &&
10354 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
10355 goto nla_put_failure;
b23aa676 10356
3b7b72ee 10357 genlmsg_end(msg, hdr);
b23aa676 10358
68eb5503 10359 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10360 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
10361 return;
10362
10363 nla_put_failure:
10364 genlmsg_cancel(msg, hdr);
10365 nlmsg_free(msg);
10366
10367}
10368
10369void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
10370 struct net_device *netdev, const u8 *bssid,
10371 const u8 *req_ie, size_t req_ie_len,
10372 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
10373{
10374 struct sk_buff *msg;
10375 void *hdr;
10376
58050fce 10377 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
10378 if (!msg)
10379 return;
10380
10381 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
10382 if (!hdr) {
10383 nlmsg_free(msg);
10384 return;
10385 }
10386
9360ffd1
DM
10387 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10388 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10389 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
10390 (req_ie &&
10391 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
10392 (resp_ie &&
10393 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
10394 goto nla_put_failure;
b23aa676 10395
3b7b72ee 10396 genlmsg_end(msg, hdr);
b23aa676 10397
68eb5503 10398 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10399 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
10400 return;
10401
10402 nla_put_failure:
10403 genlmsg_cancel(msg, hdr);
10404 nlmsg_free(msg);
10405
10406}
10407
10408void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
10409 struct net_device *netdev, u16 reason,
667503dd 10410 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
10411{
10412 struct sk_buff *msg;
10413 void *hdr;
10414
58050fce 10415 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
10416 if (!msg)
10417 return;
10418
10419 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
10420 if (!hdr) {
10421 nlmsg_free(msg);
10422 return;
10423 }
10424
9360ffd1
DM
10425 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10426 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10427 (from_ap && reason &&
10428 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
10429 (from_ap &&
10430 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
10431 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
10432 goto nla_put_failure;
b23aa676 10433
3b7b72ee 10434 genlmsg_end(msg, hdr);
b23aa676 10435
68eb5503 10436 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10437 NL80211_MCGRP_MLME, GFP_KERNEL);
b23aa676
SO
10438 return;
10439
10440 nla_put_failure:
10441 genlmsg_cancel(msg, hdr);
10442 nlmsg_free(msg);
10443
10444}
10445
04a773ad
JB
10446void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
10447 struct net_device *netdev, const u8 *bssid,
10448 gfp_t gfp)
10449{
10450 struct sk_buff *msg;
10451 void *hdr;
10452
fd2120ca 10453 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
10454 if (!msg)
10455 return;
10456
10457 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
10458 if (!hdr) {
10459 nlmsg_free(msg);
10460 return;
10461 }
10462
9360ffd1
DM
10463 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10464 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10465 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
10466 goto nla_put_failure;
04a773ad 10467
3b7b72ee 10468 genlmsg_end(msg, hdr);
04a773ad 10469
68eb5503 10470 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10471 NL80211_MCGRP_MLME, gfp);
04a773ad
JB
10472 return;
10473
10474 nla_put_failure:
10475 genlmsg_cancel(msg, hdr);
10476 nlmsg_free(msg);
10477}
10478
947add36
JB
10479void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
10480 const u8* ie, u8 ie_len, gfp_t gfp)
c93b5e71 10481{
947add36
JB
10482 struct wireless_dev *wdev = dev->ieee80211_ptr;
10483 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
c93b5e71
JC
10484 struct sk_buff *msg;
10485 void *hdr;
10486
947add36
JB
10487 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
10488 return;
10489
10490 trace_cfg80211_notify_new_peer_candidate(dev, addr);
10491
c93b5e71
JC
10492 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10493 if (!msg)
10494 return;
10495
10496 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
10497 if (!hdr) {
10498 nlmsg_free(msg);
10499 return;
10500 }
10501
9360ffd1 10502 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
10503 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10504 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1
DM
10505 (ie_len && ie &&
10506 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
10507 goto nla_put_failure;
c93b5e71 10508
3b7b72ee 10509 genlmsg_end(msg, hdr);
c93b5e71 10510
68eb5503 10511 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10512 NL80211_MCGRP_MLME, gfp);
c93b5e71
JC
10513 return;
10514
10515 nla_put_failure:
10516 genlmsg_cancel(msg, hdr);
10517 nlmsg_free(msg);
10518}
947add36 10519EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 10520
a3b8b056
JM
10521void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
10522 struct net_device *netdev, const u8 *addr,
10523 enum nl80211_key_type key_type, int key_id,
e6d6e342 10524 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
10525{
10526 struct sk_buff *msg;
10527 void *hdr;
10528
e6d6e342 10529 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
10530 if (!msg)
10531 return;
10532
10533 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
10534 if (!hdr) {
10535 nlmsg_free(msg);
10536 return;
10537 }
10538
9360ffd1
DM
10539 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10540 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
10541 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
10542 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
10543 (key_id != -1 &&
10544 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
10545 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
10546 goto nla_put_failure;
a3b8b056 10547
3b7b72ee 10548 genlmsg_end(msg, hdr);
a3b8b056 10549
68eb5503 10550 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10551 NL80211_MCGRP_MLME, gfp);
a3b8b056
JM
10552 return;
10553
10554 nla_put_failure:
10555 genlmsg_cancel(msg, hdr);
10556 nlmsg_free(msg);
10557}
10558
6bad8766
LR
10559void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
10560 struct ieee80211_channel *channel_before,
10561 struct ieee80211_channel *channel_after)
10562{
10563 struct sk_buff *msg;
10564 void *hdr;
10565 struct nlattr *nl_freq;
10566
fd2120ca 10567 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
10568 if (!msg)
10569 return;
10570
10571 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
10572 if (!hdr) {
10573 nlmsg_free(msg);
10574 return;
10575 }
10576
10577 /*
10578 * Since we are applying the beacon hint to a wiphy we know its
10579 * wiphy_idx is valid
10580 */
9360ffd1
DM
10581 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
10582 goto nla_put_failure;
6bad8766
LR
10583
10584 /* Before */
10585 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
10586 if (!nl_freq)
10587 goto nla_put_failure;
cdc89b97 10588 if (nl80211_msg_put_channel(msg, channel_before, false))
6bad8766
LR
10589 goto nla_put_failure;
10590 nla_nest_end(msg, nl_freq);
10591
10592 /* After */
10593 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
10594 if (!nl_freq)
10595 goto nla_put_failure;
cdc89b97 10596 if (nl80211_msg_put_channel(msg, channel_after, false))
6bad8766
LR
10597 goto nla_put_failure;
10598 nla_nest_end(msg, nl_freq);
10599
3b7b72ee 10600 genlmsg_end(msg, hdr);
6bad8766 10601
463d0183 10602 rcu_read_lock();
68eb5503 10603 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 10604 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
463d0183 10605 rcu_read_unlock();
6bad8766
LR
10606
10607 return;
10608
10609nla_put_failure:
10610 genlmsg_cancel(msg, hdr);
10611 nlmsg_free(msg);
10612}
10613
9588bbd5
JM
10614static void nl80211_send_remain_on_chan_event(
10615 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 10616 struct wireless_dev *wdev, u64 cookie,
9588bbd5 10617 struct ieee80211_channel *chan,
9588bbd5
JM
10618 unsigned int duration, gfp_t gfp)
10619{
10620 struct sk_buff *msg;
10621 void *hdr;
10622
10623 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10624 if (!msg)
10625 return;
10626
10627 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
10628 if (!hdr) {
10629 nlmsg_free(msg);
10630 return;
10631 }
10632
9360ffd1 10633 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10634 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10635 wdev->netdev->ifindex)) ||
00f53350 10636 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 10637 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
10638 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
10639 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
10640 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
10641 goto nla_put_failure;
9588bbd5 10642
9360ffd1
DM
10643 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
10644 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
10645 goto nla_put_failure;
9588bbd5 10646
3b7b72ee 10647 genlmsg_end(msg, hdr);
9588bbd5 10648
68eb5503 10649 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10650 NL80211_MCGRP_MLME, gfp);
9588bbd5
JM
10651 return;
10652
10653 nla_put_failure:
10654 genlmsg_cancel(msg, hdr);
10655 nlmsg_free(msg);
10656}
10657
947add36
JB
10658void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
10659 struct ieee80211_channel *chan,
10660 unsigned int duration, gfp_t gfp)
9588bbd5 10661{
947add36
JB
10662 struct wiphy *wiphy = wdev->wiphy;
10663 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10664
10665 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 10666 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 10667 rdev, wdev, cookie, chan,
42d97a59 10668 duration, gfp);
9588bbd5 10669}
947add36 10670EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 10671
947add36
JB
10672void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
10673 struct ieee80211_channel *chan,
10674 gfp_t gfp)
9588bbd5 10675{
947add36
JB
10676 struct wiphy *wiphy = wdev->wiphy;
10677 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
10678
10679 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 10680 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 10681 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 10682}
947add36 10683EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 10684
947add36
JB
10685void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
10686 struct station_info *sinfo, gfp_t gfp)
98b62183 10687{
947add36
JB
10688 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
10689 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
98b62183
JB
10690 struct sk_buff *msg;
10691
947add36
JB
10692 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
10693
58050fce 10694 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
10695 if (!msg)
10696 return;
10697
66266b3a
JL
10698 if (nl80211_send_station(msg, 0, 0, 0,
10699 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
10700 nlmsg_free(msg);
10701 return;
10702 }
10703
68eb5503 10704 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10705 NL80211_MCGRP_MLME, gfp);
98b62183 10706}
947add36 10707EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 10708
947add36 10709void cfg80211_del_sta(struct net_device *dev, const u8 *mac_addr, gfp_t gfp)
ec15e68b 10710{
947add36
JB
10711 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
10712 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
ec15e68b
JM
10713 struct sk_buff *msg;
10714 void *hdr;
10715
947add36
JB
10716 trace_cfg80211_del_sta(dev, mac_addr);
10717
58050fce 10718 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
10719 if (!msg)
10720 return;
10721
10722 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
10723 if (!hdr) {
10724 nlmsg_free(msg);
10725 return;
10726 }
10727
9360ffd1
DM
10728 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10729 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
10730 goto nla_put_failure;
ec15e68b 10731
3b7b72ee 10732 genlmsg_end(msg, hdr);
ec15e68b 10733
68eb5503 10734 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10735 NL80211_MCGRP_MLME, gfp);
ec15e68b
JM
10736 return;
10737
10738 nla_put_failure:
10739 genlmsg_cancel(msg, hdr);
10740 nlmsg_free(msg);
10741}
947add36 10742EXPORT_SYMBOL(cfg80211_del_sta);
ec15e68b 10743
947add36
JB
10744void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
10745 enum nl80211_connect_failed_reason reason,
10746 gfp_t gfp)
ed44a951 10747{
947add36
JB
10748 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
10749 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
ed44a951
PP
10750 struct sk_buff *msg;
10751 void *hdr;
10752
10753 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
10754 if (!msg)
10755 return;
10756
10757 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
10758 if (!hdr) {
10759 nlmsg_free(msg);
10760 return;
10761 }
10762
10763 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10764 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
10765 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
10766 goto nla_put_failure;
10767
10768 genlmsg_end(msg, hdr);
10769
68eb5503 10770 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10771 NL80211_MCGRP_MLME, gfp);
ed44a951
PP
10772 return;
10773
10774 nla_put_failure:
10775 genlmsg_cancel(msg, hdr);
10776 nlmsg_free(msg);
10777}
947add36 10778EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 10779
b92ab5d8
JB
10780static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
10781 const u8 *addr, gfp_t gfp)
28946da7
JB
10782{
10783 struct wireless_dev *wdev = dev->ieee80211_ptr;
10784 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
10785 struct sk_buff *msg;
10786 void *hdr;
15e47304 10787 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 10788
15e47304 10789 if (!nlportid)
28946da7
JB
10790 return false;
10791
10792 msg = nlmsg_new(100, gfp);
10793 if (!msg)
10794 return true;
10795
b92ab5d8 10796 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
10797 if (!hdr) {
10798 nlmsg_free(msg);
10799 return true;
10800 }
10801
9360ffd1
DM
10802 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
10803 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
10804 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
10805 goto nla_put_failure;
28946da7 10806
9c90a9f6 10807 genlmsg_end(msg, hdr);
15e47304 10808 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
10809 return true;
10810
10811 nla_put_failure:
10812 genlmsg_cancel(msg, hdr);
10813 nlmsg_free(msg);
10814 return true;
10815}
10816
947add36
JB
10817bool cfg80211_rx_spurious_frame(struct net_device *dev,
10818 const u8 *addr, gfp_t gfp)
b92ab5d8 10819{
947add36
JB
10820 struct wireless_dev *wdev = dev->ieee80211_ptr;
10821 bool ret;
10822
10823 trace_cfg80211_rx_spurious_frame(dev, addr);
10824
10825 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
10826 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
10827 trace_cfg80211_return_bool(false);
10828 return false;
10829 }
10830 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
10831 addr, gfp);
10832 trace_cfg80211_return_bool(ret);
10833 return ret;
b92ab5d8 10834}
947add36 10835EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 10836
947add36
JB
10837bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
10838 const u8 *addr, gfp_t gfp)
b92ab5d8 10839{
947add36
JB
10840 struct wireless_dev *wdev = dev->ieee80211_ptr;
10841 bool ret;
10842
10843 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
10844
10845 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
10846 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
10847 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
10848 trace_cfg80211_return_bool(false);
10849 return false;
10850 }
10851 ret = __nl80211_unexpected_frame(dev,
10852 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
10853 addr, gfp);
10854 trace_cfg80211_return_bool(ret);
10855 return ret;
b92ab5d8 10856}
947add36 10857EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 10858
2e161f78 10859int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 10860 struct wireless_dev *wdev, u32 nlportid,
804483e9 10861 int freq, int sig_dbm,
19504cf5 10862 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 10863{
71bbc994 10864 struct net_device *netdev = wdev->netdev;
026331c4
JM
10865 struct sk_buff *msg;
10866 void *hdr;
026331c4
JM
10867
10868 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10869 if (!msg)
10870 return -ENOMEM;
10871
2e161f78 10872 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
10873 if (!hdr) {
10874 nlmsg_free(msg);
10875 return -ENOMEM;
10876 }
10877
9360ffd1 10878 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10879 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10880 netdev->ifindex)) ||
a838490b 10881 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
10882 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
10883 (sig_dbm &&
10884 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
10885 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
10886 (flags &&
10887 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 10888 goto nla_put_failure;
026331c4 10889
3b7b72ee 10890 genlmsg_end(msg, hdr);
026331c4 10891
15e47304 10892 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
10893
10894 nla_put_failure:
10895 genlmsg_cancel(msg, hdr);
10896 nlmsg_free(msg);
10897 return -ENOBUFS;
10898}
10899
947add36
JB
10900void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
10901 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 10902{
947add36
JB
10903 struct wiphy *wiphy = wdev->wiphy;
10904 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
71bbc994 10905 struct net_device *netdev = wdev->netdev;
026331c4
JM
10906 struct sk_buff *msg;
10907 void *hdr;
10908
947add36
JB
10909 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
10910
026331c4
JM
10911 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
10912 if (!msg)
10913 return;
10914
2e161f78 10915 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
10916 if (!hdr) {
10917 nlmsg_free(msg);
10918 return;
10919 }
10920
9360ffd1 10921 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
10922 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
10923 netdev->ifindex)) ||
a838490b 10924 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1
DM
10925 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
10926 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
10927 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
10928 goto nla_put_failure;
026331c4 10929
3b7b72ee 10930 genlmsg_end(msg, hdr);
026331c4 10931
68eb5503 10932 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10933 NL80211_MCGRP_MLME, gfp);
026331c4
JM
10934 return;
10935
10936 nla_put_failure:
10937 genlmsg_cancel(msg, hdr);
10938 nlmsg_free(msg);
10939}
947add36 10940EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 10941
947add36
JB
10942void cfg80211_cqm_rssi_notify(struct net_device *dev,
10943 enum nl80211_cqm_rssi_threshold_event rssi_event,
10944 gfp_t gfp)
d6dc1a38 10945{
947add36
JB
10946 struct wireless_dev *wdev = dev->ieee80211_ptr;
10947 struct wiphy *wiphy = wdev->wiphy;
10948 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
d6dc1a38
JO
10949 struct sk_buff *msg;
10950 struct nlattr *pinfoattr;
10951 void *hdr;
10952
947add36
JB
10953 trace_cfg80211_cqm_rssi_notify(dev, rssi_event);
10954
58050fce 10955 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
10956 if (!msg)
10957 return;
10958
10959 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
10960 if (!hdr) {
10961 nlmsg_free(msg);
10962 return;
10963 }
10964
9360ffd1 10965 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 10966 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 10967 goto nla_put_failure;
d6dc1a38
JO
10968
10969 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
10970 if (!pinfoattr)
10971 goto nla_put_failure;
10972
9360ffd1
DM
10973 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
10974 rssi_event))
10975 goto nla_put_failure;
d6dc1a38
JO
10976
10977 nla_nest_end(msg, pinfoattr);
10978
3b7b72ee 10979 genlmsg_end(msg, hdr);
d6dc1a38 10980
68eb5503 10981 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 10982 NL80211_MCGRP_MLME, gfp);
d6dc1a38
JO
10983 return;
10984
10985 nla_put_failure:
10986 genlmsg_cancel(msg, hdr);
10987 nlmsg_free(msg);
10988}
947add36 10989EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 10990
947add36
JB
10991static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
10992 struct net_device *netdev, const u8 *bssid,
10993 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
10994{
10995 struct sk_buff *msg;
10996 struct nlattr *rekey_attr;
10997 void *hdr;
10998
58050fce 10999 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
11000 if (!msg)
11001 return;
11002
11003 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
11004 if (!hdr) {
11005 nlmsg_free(msg);
11006 return;
11007 }
11008
9360ffd1
DM
11009 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11010 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11011 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
11012 goto nla_put_failure;
e5497d76
JB
11013
11014 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
11015 if (!rekey_attr)
11016 goto nla_put_failure;
11017
9360ffd1
DM
11018 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
11019 NL80211_REPLAY_CTR_LEN, replay_ctr))
11020 goto nla_put_failure;
e5497d76
JB
11021
11022 nla_nest_end(msg, rekey_attr);
11023
3b7b72ee 11024 genlmsg_end(msg, hdr);
e5497d76 11025
68eb5503 11026 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11027 NL80211_MCGRP_MLME, gfp);
e5497d76
JB
11028 return;
11029
11030 nla_put_failure:
11031 genlmsg_cancel(msg, hdr);
11032 nlmsg_free(msg);
11033}
11034
947add36
JB
11035void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
11036 const u8 *replay_ctr, gfp_t gfp)
11037{
11038 struct wireless_dev *wdev = dev->ieee80211_ptr;
11039 struct wiphy *wiphy = wdev->wiphy;
11040 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
11041
11042 trace_cfg80211_gtk_rekey_notify(dev, bssid);
11043 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
11044}
11045EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
11046
11047static void
11048nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
11049 struct net_device *netdev, int index,
11050 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
11051{
11052 struct sk_buff *msg;
11053 struct nlattr *attr;
11054 void *hdr;
11055
58050fce 11056 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
11057 if (!msg)
11058 return;
11059
11060 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
11061 if (!hdr) {
11062 nlmsg_free(msg);
11063 return;
11064 }
11065
9360ffd1
DM
11066 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11067 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
11068 goto nla_put_failure;
c9df56b4
JM
11069
11070 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
11071 if (!attr)
11072 goto nla_put_failure;
11073
9360ffd1
DM
11074 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
11075 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
11076 (preauth &&
11077 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
11078 goto nla_put_failure;
c9df56b4
JM
11079
11080 nla_nest_end(msg, attr);
11081
3b7b72ee 11082 genlmsg_end(msg, hdr);
c9df56b4 11083
68eb5503 11084 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11085 NL80211_MCGRP_MLME, gfp);
c9df56b4
JM
11086 return;
11087
11088 nla_put_failure:
11089 genlmsg_cancel(msg, hdr);
11090 nlmsg_free(msg);
11091}
11092
947add36
JB
11093void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
11094 const u8 *bssid, bool preauth, gfp_t gfp)
11095{
11096 struct wireless_dev *wdev = dev->ieee80211_ptr;
11097 struct wiphy *wiphy = wdev->wiphy;
11098 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
11099
11100 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
11101 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
11102}
11103EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
11104
11105static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
11106 struct net_device *netdev,
11107 struct cfg80211_chan_def *chandef,
11108 gfp_t gfp)
5314526b
TP
11109{
11110 struct sk_buff *msg;
11111 void *hdr;
11112
58050fce 11113 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
11114 if (!msg)
11115 return;
11116
11117 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
11118 if (!hdr) {
11119 nlmsg_free(msg);
11120 return;
11121 }
11122
683b6d3b
JB
11123 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
11124 goto nla_put_failure;
11125
11126 if (nl80211_send_chandef(msg, chandef))
7eab0f64 11127 goto nla_put_failure;
5314526b
TP
11128
11129 genlmsg_end(msg, hdr);
11130
68eb5503 11131 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11132 NL80211_MCGRP_MLME, gfp);
5314526b
TP
11133 return;
11134
11135 nla_put_failure:
11136 genlmsg_cancel(msg, hdr);
11137 nlmsg_free(msg);
11138}
11139
947add36
JB
11140void cfg80211_ch_switch_notify(struct net_device *dev,
11141 struct cfg80211_chan_def *chandef)
84f10708 11142{
947add36
JB
11143 struct wireless_dev *wdev = dev->ieee80211_ptr;
11144 struct wiphy *wiphy = wdev->wiphy;
11145 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
11146
e487eaeb 11147 ASSERT_WDEV_LOCK(wdev);
947add36 11148
e487eaeb 11149 trace_cfg80211_ch_switch_notify(dev, chandef);
947add36
JB
11150
11151 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
ee4bc9e7 11152 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
b8456a14
CYY
11153 wdev->iftype != NL80211_IFTYPE_ADHOC &&
11154 wdev->iftype != NL80211_IFTYPE_MESH_POINT))
e487eaeb 11155 return;
947add36
JB
11156
11157 wdev->channel = chandef->chan;
11158 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL);
947add36
JB
11159}
11160EXPORT_SYMBOL(cfg80211_ch_switch_notify);
11161
11162void cfg80211_cqm_txe_notify(struct net_device *dev,
11163 const u8 *peer, u32 num_packets,
11164 u32 rate, u32 intvl, gfp_t gfp)
11165{
11166 struct wireless_dev *wdev = dev->ieee80211_ptr;
11167 struct wiphy *wiphy = wdev->wiphy;
11168 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
84f10708
TP
11169 struct sk_buff *msg;
11170 struct nlattr *pinfoattr;
11171 void *hdr;
11172
11173 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
11174 if (!msg)
11175 return;
11176
11177 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
11178 if (!hdr) {
11179 nlmsg_free(msg);
11180 return;
11181 }
11182
11183 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 11184 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
84f10708
TP
11185 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
11186 goto nla_put_failure;
11187
11188 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
11189 if (!pinfoattr)
11190 goto nla_put_failure;
11191
11192 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
11193 goto nla_put_failure;
11194
11195 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
11196 goto nla_put_failure;
11197
11198 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
11199 goto nla_put_failure;
11200
11201 nla_nest_end(msg, pinfoattr);
11202
11203 genlmsg_end(msg, hdr);
11204
68eb5503 11205 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11206 NL80211_MCGRP_MLME, gfp);
84f10708
TP
11207 return;
11208
11209 nla_put_failure:
11210 genlmsg_cancel(msg, hdr);
11211 nlmsg_free(msg);
11212}
947add36 11213EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
84f10708 11214
04f39047
SW
11215void
11216nl80211_radar_notify(struct cfg80211_registered_device *rdev,
d2859df5 11217 const struct cfg80211_chan_def *chandef,
04f39047
SW
11218 enum nl80211_radar_event event,
11219 struct net_device *netdev, gfp_t gfp)
11220{
11221 struct sk_buff *msg;
11222 void *hdr;
11223
11224 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11225 if (!msg)
11226 return;
11227
11228 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
11229 if (!hdr) {
11230 nlmsg_free(msg);
11231 return;
11232 }
11233
11234 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
11235 goto nla_put_failure;
11236
11237 /* NOP and radar events don't need a netdev parameter */
11238 if (netdev) {
11239 struct wireless_dev *wdev = netdev->ieee80211_ptr;
11240
11241 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11242 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
11243 goto nla_put_failure;
11244 }
11245
11246 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
11247 goto nla_put_failure;
11248
11249 if (nl80211_send_chandef(msg, chandef))
11250 goto nla_put_failure;
11251
9c90a9f6 11252 genlmsg_end(msg, hdr);
04f39047 11253
68eb5503 11254 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11255 NL80211_MCGRP_MLME, gfp);
04f39047
SW
11256 return;
11257
11258 nla_put_failure:
11259 genlmsg_cancel(msg, hdr);
11260 nlmsg_free(msg);
11261}
11262
947add36
JB
11263void cfg80211_cqm_pktloss_notify(struct net_device *dev,
11264 const u8 *peer, u32 num_packets, gfp_t gfp)
c063dbf5 11265{
947add36
JB
11266 struct wireless_dev *wdev = dev->ieee80211_ptr;
11267 struct wiphy *wiphy = wdev->wiphy;
11268 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
c063dbf5
JB
11269 struct sk_buff *msg;
11270 struct nlattr *pinfoattr;
11271 void *hdr;
11272
947add36
JB
11273 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
11274
58050fce 11275 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
11276 if (!msg)
11277 return;
11278
11279 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
11280 if (!hdr) {
11281 nlmsg_free(msg);
11282 return;
11283 }
11284
9360ffd1 11285 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 11286 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9360ffd1
DM
11287 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
11288 goto nla_put_failure;
c063dbf5
JB
11289
11290 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
11291 if (!pinfoattr)
11292 goto nla_put_failure;
11293
9360ffd1
DM
11294 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
11295 goto nla_put_failure;
c063dbf5
JB
11296
11297 nla_nest_end(msg, pinfoattr);
11298
3b7b72ee 11299 genlmsg_end(msg, hdr);
c063dbf5 11300
68eb5503 11301 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11302 NL80211_MCGRP_MLME, gfp);
c063dbf5
JB
11303 return;
11304
11305 nla_put_failure:
11306 genlmsg_cancel(msg, hdr);
11307 nlmsg_free(msg);
11308}
947add36 11309EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
c063dbf5 11310
7f6cf311
JB
11311void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
11312 u64 cookie, bool acked, gfp_t gfp)
11313{
11314 struct wireless_dev *wdev = dev->ieee80211_ptr;
11315 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
11316 struct sk_buff *msg;
11317 void *hdr;
7f6cf311 11318
4ee3e063
BL
11319 trace_cfg80211_probe_status(dev, addr, cookie, acked);
11320
58050fce 11321 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 11322
7f6cf311
JB
11323 if (!msg)
11324 return;
11325
11326 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
11327 if (!hdr) {
11328 nlmsg_free(msg);
11329 return;
11330 }
11331
9360ffd1
DM
11332 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11333 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
11334 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
11335 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
11336 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
11337 goto nla_put_failure;
7f6cf311 11338
9c90a9f6 11339 genlmsg_end(msg, hdr);
7f6cf311 11340
68eb5503 11341 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11342 NL80211_MCGRP_MLME, gfp);
7f6cf311
JB
11343 return;
11344
11345 nla_put_failure:
11346 genlmsg_cancel(msg, hdr);
11347 nlmsg_free(msg);
11348}
11349EXPORT_SYMBOL(cfg80211_probe_status);
11350
5e760230
JB
11351void cfg80211_report_obss_beacon(struct wiphy *wiphy,
11352 const u8 *frame, size_t len,
37c73b5f 11353 int freq, int sig_dbm)
5e760230
JB
11354{
11355 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
11356 struct sk_buff *msg;
11357 void *hdr;
37c73b5f 11358 struct cfg80211_beacon_registration *reg;
5e760230 11359
4ee3e063
BL
11360 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
11361
37c73b5f
BG
11362 spin_lock_bh(&rdev->beacon_registrations_lock);
11363 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
11364 msg = nlmsg_new(len + 100, GFP_ATOMIC);
11365 if (!msg) {
11366 spin_unlock_bh(&rdev->beacon_registrations_lock);
11367 return;
11368 }
5e760230 11369
37c73b5f
BG
11370 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
11371 if (!hdr)
11372 goto nla_put_failure;
5e760230 11373
37c73b5f
BG
11374 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11375 (freq &&
11376 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
11377 (sig_dbm &&
11378 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
11379 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
11380 goto nla_put_failure;
5e760230 11381
37c73b5f 11382 genlmsg_end(msg, hdr);
5e760230 11383
37c73b5f
BG
11384 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
11385 }
11386 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
11387 return;
11388
11389 nla_put_failure:
37c73b5f
BG
11390 spin_unlock_bh(&rdev->beacon_registrations_lock);
11391 if (hdr)
11392 genlmsg_cancel(msg, hdr);
5e760230
JB
11393 nlmsg_free(msg);
11394}
11395EXPORT_SYMBOL(cfg80211_report_obss_beacon);
11396
cd8f7cb4
JB
11397#ifdef CONFIG_PM
11398void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
11399 struct cfg80211_wowlan_wakeup *wakeup,
11400 gfp_t gfp)
11401{
11402 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
11403 struct sk_buff *msg;
11404 void *hdr;
9c90a9f6 11405 int size = 200;
cd8f7cb4
JB
11406
11407 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
11408
11409 if (wakeup)
11410 size += wakeup->packet_present_len;
11411
11412 msg = nlmsg_new(size, gfp);
11413 if (!msg)
11414 return;
11415
11416 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
11417 if (!hdr)
11418 goto free_msg;
11419
11420 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11421 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
11422 goto free_msg;
11423
11424 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11425 wdev->netdev->ifindex))
11426 goto free_msg;
11427
11428 if (wakeup) {
11429 struct nlattr *reasons;
11430
11431 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7fa322c8
JB
11432 if (!reasons)
11433 goto free_msg;
cd8f7cb4
JB
11434
11435 if (wakeup->disconnect &&
11436 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
11437 goto free_msg;
11438 if (wakeup->magic_pkt &&
11439 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
11440 goto free_msg;
11441 if (wakeup->gtk_rekey_failure &&
11442 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
11443 goto free_msg;
11444 if (wakeup->eap_identity_req &&
11445 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
11446 goto free_msg;
11447 if (wakeup->four_way_handshake &&
11448 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
11449 goto free_msg;
11450 if (wakeup->rfkill_release &&
11451 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
11452 goto free_msg;
11453
11454 if (wakeup->pattern_idx >= 0 &&
11455 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
11456 wakeup->pattern_idx))
11457 goto free_msg;
11458
ae917c9f
JB
11459 if (wakeup->tcp_match &&
11460 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
11461 goto free_msg;
2a0e047e 11462
ae917c9f
JB
11463 if (wakeup->tcp_connlost &&
11464 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
11465 goto free_msg;
2a0e047e 11466
ae917c9f
JB
11467 if (wakeup->tcp_nomoretokens &&
11468 nla_put_flag(msg,
11469 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
11470 goto free_msg;
2a0e047e 11471
cd8f7cb4
JB
11472 if (wakeup->packet) {
11473 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
11474 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
11475
11476 if (!wakeup->packet_80211) {
11477 pkt_attr =
11478 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
11479 len_attr =
11480 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
11481 }
11482
11483 if (wakeup->packet_len &&
11484 nla_put_u32(msg, len_attr, wakeup->packet_len))
11485 goto free_msg;
11486
11487 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
11488 wakeup->packet))
11489 goto free_msg;
11490 }
11491
11492 nla_nest_end(msg, reasons);
11493 }
11494
9c90a9f6 11495 genlmsg_end(msg, hdr);
cd8f7cb4 11496
68eb5503 11497 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11498 NL80211_MCGRP_MLME, gfp);
cd8f7cb4
JB
11499 return;
11500
11501 free_msg:
11502 nlmsg_free(msg);
11503}
11504EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
11505#endif
11506
3475b094
JM
11507void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
11508 enum nl80211_tdls_operation oper,
11509 u16 reason_code, gfp_t gfp)
11510{
11511 struct wireless_dev *wdev = dev->ieee80211_ptr;
11512 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
11513 struct sk_buff *msg;
11514 void *hdr;
3475b094
JM
11515
11516 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
11517 reason_code);
11518
11519 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11520 if (!msg)
11521 return;
11522
11523 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
11524 if (!hdr) {
11525 nlmsg_free(msg);
11526 return;
11527 }
11528
11529 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11530 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
11531 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
11532 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
11533 (reason_code > 0 &&
11534 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
11535 goto nla_put_failure;
11536
9c90a9f6 11537 genlmsg_end(msg, hdr);
3475b094 11538
68eb5503 11539 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11540 NL80211_MCGRP_MLME, gfp);
3475b094
JM
11541 return;
11542
11543 nla_put_failure:
11544 genlmsg_cancel(msg, hdr);
11545 nlmsg_free(msg);
11546}
11547EXPORT_SYMBOL(cfg80211_tdls_oper_request);
11548
026331c4
JM
11549static int nl80211_netlink_notify(struct notifier_block * nb,
11550 unsigned long state,
11551 void *_notify)
11552{
11553 struct netlink_notify *notify = _notify;
11554 struct cfg80211_registered_device *rdev;
11555 struct wireless_dev *wdev;
37c73b5f 11556 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
11557
11558 if (state != NETLINK_URELEASE)
11559 return NOTIFY_DONE;
11560
11561 rcu_read_lock();
11562
5e760230 11563 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 11564 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 11565 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
11566
11567 spin_lock_bh(&rdev->beacon_registrations_lock);
11568 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
11569 list) {
11570 if (reg->nlportid == notify->portid) {
11571 list_del(&reg->list);
11572 kfree(reg);
11573 break;
11574 }
11575 }
11576 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 11577 }
026331c4
JM
11578
11579 rcu_read_unlock();
11580
11581 return NOTIFY_DONE;
11582}
11583
11584static struct notifier_block nl80211_netlink_notifier = {
11585 .notifier_call = nl80211_netlink_notify,
11586};
11587
355199e0
JM
11588void cfg80211_ft_event(struct net_device *netdev,
11589 struct cfg80211_ft_event_params *ft_event)
11590{
11591 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
11592 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
11593 struct sk_buff *msg;
11594 void *hdr;
355199e0
JM
11595
11596 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
11597
11598 if (!ft_event->target_ap)
11599 return;
11600
11601 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11602 if (!msg)
11603 return;
11604
11605 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
ae917c9f
JB
11606 if (!hdr)
11607 goto out;
355199e0 11608
ae917c9f
JB
11609 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11610 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
11611 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
11612 goto out;
355199e0 11613
ae917c9f
JB
11614 if (ft_event->ies &&
11615 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
11616 goto out;
11617 if (ft_event->ric_ies &&
11618 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
11619 ft_event->ric_ies))
11620 goto out;
355199e0 11621
9c90a9f6 11622 genlmsg_end(msg, hdr);
355199e0 11623
68eb5503 11624 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 11625 NL80211_MCGRP_MLME, GFP_KERNEL);
ae917c9f
JB
11626 return;
11627 out:
11628 nlmsg_free(msg);
355199e0
JM
11629}
11630EXPORT_SYMBOL(cfg80211_ft_event);
11631
5de17984
AS
11632void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
11633{
11634 struct cfg80211_registered_device *rdev;
11635 struct sk_buff *msg;
11636 void *hdr;
11637 u32 nlportid;
11638
11639 rdev = wiphy_to_dev(wdev->wiphy);
11640 if (!rdev->crit_proto_nlportid)
11641 return;
11642
11643 nlportid = rdev->crit_proto_nlportid;
11644 rdev->crit_proto_nlportid = 0;
11645
11646 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11647 if (!msg)
11648 return;
11649
11650 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
11651 if (!hdr)
11652 goto nla_put_failure;
11653
11654 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11655 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
11656 goto nla_put_failure;
11657
11658 genlmsg_end(msg, hdr);
11659
11660 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
11661 return;
11662
11663 nla_put_failure:
11664 if (hdr)
11665 genlmsg_cancel(msg, hdr);
11666 nlmsg_free(msg);
11667
11668}
11669EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
11670
55682965
JB
11671/* initialisation/exit functions */
11672
11673int nl80211_init(void)
11674{
0d63cbb5 11675 int err;
55682965 11676
2a94fe48
JB
11677 err = genl_register_family_with_ops_groups(&nl80211_fam, nl80211_ops,
11678 nl80211_mcgrps);
55682965
JB
11679 if (err)
11680 return err;
11681
026331c4
JM
11682 err = netlink_register_notifier(&nl80211_netlink_notifier);
11683 if (err)
11684 goto err_out;
11685
55682965
JB
11686 return 0;
11687 err_out:
11688 genl_unregister_family(&nl80211_fam);
11689 return err;
11690}
11691
11692void nl80211_exit(void)
11693{
026331c4 11694 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
11695 genl_unregister_family(&nl80211_fam);
11696}