]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: invoke the timer only with correct dot11MeshHWMPRootMode value
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
79c97e97 49/* internal helper: get rdev and dev */
00918d33
JB
50static int get_rdev_dev_by_ifindex(struct net *netns, struct nlattr **attrs,
51 struct cfg80211_registered_device **rdev,
52 struct net_device **dev)
55682965
JB
53{
54 int ifindex;
55
bba95fef 56 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
57 return -EINVAL;
58
bba95fef 59 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
00918d33 60 *dev = dev_get_by_index(netns, ifindex);
55682965
JB
61 if (!*dev)
62 return -ENODEV;
63
00918d33 64 *rdev = cfg80211_get_dev_from_ifindex(netns, ifindex);
79c97e97 65 if (IS_ERR(*rdev)) {
55682965 66 dev_put(*dev);
79c97e97 67 return PTR_ERR(*rdev);
55682965
JB
68 }
69
70 return 0;
71}
72
73/* policy for the attributes */
b54452b0 74static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
75 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
76 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 77 .len = 20-1 },
31888487 78 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 79 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 80 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
81 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
82 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
84 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 85 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
86
87 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
88 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 90
e007b857
EP
91 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
92 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 93
b9454e83 94 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
95 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
96 .len = WLAN_MAX_KEY_LEN },
97 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
98 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
99 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 100 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 101 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
102
103 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
104 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
105 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
106 .len = IEEE80211_MAX_DATA_LEN },
107 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
108 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
109 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
110 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
111 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
112 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 114 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 115 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 116 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 117 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 118 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 119 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 120
b2e1b302
LR
121 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
122 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
123
9f1ba906
JM
124 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
125 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
127 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
128 .len = NL80211_MAX_SUPP_RATES },
50b12f59 129 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 130
24bdd9f4 131 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 132 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 133
6c739419 134 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
135
136 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
137 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
138 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
139 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
140 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
141
142 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
143 .len = IEEE80211_MAX_SSID_LEN },
144 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
145 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 146 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 147 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 148 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
149 [NL80211_ATTR_STA_FLAGS2] = {
150 .len = sizeof(struct nl80211_sta_flag_update),
151 },
3f77316c 152 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
153 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
154 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
155 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
156 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
157 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 158 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 159 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
160 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
161 .len = WLAN_PMKID_LEN },
9588bbd5
JM
162 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
163 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 164 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
165 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
166 .len = IEEE80211_MAX_DATA_LEN },
167 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 168 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 169 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 170 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 171 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
172 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
173 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 174 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
175 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
176 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 177 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 178 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 179 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 180 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 181 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 182 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 183 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 184 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 185 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
186 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
187 .len = IEEE80211_MAX_DATA_LEN },
188 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
189 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 190 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 191 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 192 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
193 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
194 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
197 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 198 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
199 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
200 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 201 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
202 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
203 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
204 .len = NL80211_HT_CAPABILITY_LEN
205 },
1d9d9213 206 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 207 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 208 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
55682965
JB
209};
210
e31b8213 211/* policy for the key attributes */
b54452b0 212static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 213 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
214 [NL80211_KEY_IDX] = { .type = NLA_U8 },
215 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 216 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
217 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
218 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 219 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
220 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
221};
222
223/* policy for the key default flags */
224static const struct nla_policy
225nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
226 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
227 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
228};
229
ff1b6e69
JB
230/* policy for WoWLAN attributes */
231static const struct nla_policy
232nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
233 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
234 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
235 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
236 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
237 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
238 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
239 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
240 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
241};
242
e5497d76
JB
243/* policy for GTK rekey offload attributes */
244static const struct nla_policy
245nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
246 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
247 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
248 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
249};
250
a1f1c21c
LC
251static const struct nla_policy
252nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 253 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c
LC
254 .len = IEEE80211_MAX_SSID_LEN },
255};
256
a043897a
HS
257/* ifidx get helper */
258static int nl80211_get_ifidx(struct netlink_callback *cb)
259{
260 int res;
261
262 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
263 nl80211_fam.attrbuf, nl80211_fam.maxattr,
264 nl80211_policy);
265 if (res)
266 return res;
267
268 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
269 return -EINVAL;
270
271 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
272 if (!res)
273 return -EINVAL;
274 return res;
275}
276
67748893
JB
277static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
278 struct netlink_callback *cb,
279 struct cfg80211_registered_device **rdev,
280 struct net_device **dev)
281{
282 int ifidx = cb->args[0];
283 int err;
284
285 if (!ifidx)
286 ifidx = nl80211_get_ifidx(cb);
287 if (ifidx < 0)
288 return ifidx;
289
290 cb->args[0] = ifidx;
291
292 rtnl_lock();
293
294 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
295 if (!*dev) {
296 err = -ENODEV;
297 goto out_rtnl;
298 }
299
300 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
301 if (IS_ERR(*rdev)) {
302 err = PTR_ERR(*rdev);
67748893
JB
303 goto out_rtnl;
304 }
305
306 return 0;
307 out_rtnl:
308 rtnl_unlock();
309 return err;
310}
311
312static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
313{
314 cfg80211_unlock_rdev(rdev);
315 rtnl_unlock();
316}
317
f4a11bb0
JB
318/* IE validation */
319static bool is_valid_ie_attr(const struct nlattr *attr)
320{
321 const u8 *pos;
322 int len;
323
324 if (!attr)
325 return true;
326
327 pos = nla_data(attr);
328 len = nla_len(attr);
329
330 while (len) {
331 u8 elemlen;
332
333 if (len < 2)
334 return false;
335 len -= 2;
336
337 elemlen = pos[1];
338 if (elemlen > len)
339 return false;
340
341 len -= elemlen;
342 pos += 2 + elemlen;
343 }
344
345 return true;
346}
347
55682965
JB
348/* message building helper */
349static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
350 int flags, u8 cmd)
351{
352 /* since there is no private header just add the generic one */
353 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
354}
355
5dab3b8a
LR
356static int nl80211_msg_put_channel(struct sk_buff *msg,
357 struct ieee80211_channel *chan)
358{
9360ffd1
DM
359 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
360 chan->center_freq))
361 goto nla_put_failure;
5dab3b8a 362
9360ffd1
DM
363 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
364 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
365 goto nla_put_failure;
366 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
367 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
368 goto nla_put_failure;
369 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
370 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
371 goto nla_put_failure;
372 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
373 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
374 goto nla_put_failure;
5dab3b8a 375
9360ffd1
DM
376 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
377 DBM_TO_MBM(chan->max_power)))
378 goto nla_put_failure;
5dab3b8a
LR
379
380 return 0;
381
382 nla_put_failure:
383 return -ENOBUFS;
384}
385
55682965
JB
386/* netlink command implementations */
387
b9454e83
JB
388struct key_parse {
389 struct key_params p;
390 int idx;
e31b8213 391 int type;
b9454e83 392 bool def, defmgmt;
dbd2fd65 393 bool def_uni, def_multi;
b9454e83
JB
394};
395
396static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
397{
398 struct nlattr *tb[NL80211_KEY_MAX + 1];
399 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
400 nl80211_key_policy);
401 if (err)
402 return err;
403
404 k->def = !!tb[NL80211_KEY_DEFAULT];
405 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
406
dbd2fd65
JB
407 if (k->def) {
408 k->def_uni = true;
409 k->def_multi = true;
410 }
411 if (k->defmgmt)
412 k->def_multi = true;
413
b9454e83
JB
414 if (tb[NL80211_KEY_IDX])
415 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
416
417 if (tb[NL80211_KEY_DATA]) {
418 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
419 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
420 }
421
422 if (tb[NL80211_KEY_SEQ]) {
423 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
424 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
425 }
426
427 if (tb[NL80211_KEY_CIPHER])
428 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
429
e31b8213
JB
430 if (tb[NL80211_KEY_TYPE]) {
431 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
432 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
433 return -EINVAL;
434 }
435
dbd2fd65
JB
436 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
437 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
438 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
439 tb[NL80211_KEY_DEFAULT_TYPES],
440 nl80211_key_default_policy);
dbd2fd65
JB
441 if (err)
442 return err;
443
444 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
445 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
446 }
447
b9454e83
JB
448 return 0;
449}
450
451static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
452{
453 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
454 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
455 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
456 }
457
458 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
459 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
460 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
461 }
462
463 if (info->attrs[NL80211_ATTR_KEY_IDX])
464 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
465
466 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
467 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
468
469 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
470 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
471
dbd2fd65
JB
472 if (k->def) {
473 k->def_uni = true;
474 k->def_multi = true;
475 }
476 if (k->defmgmt)
477 k->def_multi = true;
478
e31b8213
JB
479 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
480 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
481 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
482 return -EINVAL;
483 }
484
dbd2fd65
JB
485 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
486 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
487 int err = nla_parse_nested(
488 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
489 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
490 nl80211_key_default_policy);
491 if (err)
492 return err;
493
494 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
495 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
496 }
497
b9454e83
JB
498 return 0;
499}
500
501static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
502{
503 int err;
504
505 memset(k, 0, sizeof(*k));
506 k->idx = -1;
e31b8213 507 k->type = -1;
b9454e83
JB
508
509 if (info->attrs[NL80211_ATTR_KEY])
510 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
511 else
512 err = nl80211_parse_key_old(info, k);
513
514 if (err)
515 return err;
516
517 if (k->def && k->defmgmt)
518 return -EINVAL;
519
dbd2fd65
JB
520 if (k->defmgmt) {
521 if (k->def_uni || !k->def_multi)
522 return -EINVAL;
523 }
524
b9454e83
JB
525 if (k->idx != -1) {
526 if (k->defmgmt) {
527 if (k->idx < 4 || k->idx > 5)
528 return -EINVAL;
529 } else if (k->def) {
530 if (k->idx < 0 || k->idx > 3)
531 return -EINVAL;
532 } else {
533 if (k->idx < 0 || k->idx > 5)
534 return -EINVAL;
535 }
536 }
537
538 return 0;
539}
540
fffd0934
JB
541static struct cfg80211_cached_keys *
542nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
543 struct nlattr *keys)
544{
545 struct key_parse parse;
546 struct nlattr *key;
547 struct cfg80211_cached_keys *result;
548 int rem, err, def = 0;
549
550 result = kzalloc(sizeof(*result), GFP_KERNEL);
551 if (!result)
552 return ERR_PTR(-ENOMEM);
553
554 result->def = -1;
555 result->defmgmt = -1;
556
557 nla_for_each_nested(key, keys, rem) {
558 memset(&parse, 0, sizeof(parse));
559 parse.idx = -1;
560
561 err = nl80211_parse_key_new(key, &parse);
562 if (err)
563 goto error;
564 err = -EINVAL;
565 if (!parse.p.key)
566 goto error;
567 if (parse.idx < 0 || parse.idx > 4)
568 goto error;
569 if (parse.def) {
570 if (def)
571 goto error;
572 def = 1;
573 result->def = parse.idx;
dbd2fd65
JB
574 if (!parse.def_uni || !parse.def_multi)
575 goto error;
fffd0934
JB
576 } else if (parse.defmgmt)
577 goto error;
578 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 579 parse.idx, false, NULL);
fffd0934
JB
580 if (err)
581 goto error;
582 result->params[parse.idx].cipher = parse.p.cipher;
583 result->params[parse.idx].key_len = parse.p.key_len;
584 result->params[parse.idx].key = result->data[parse.idx];
585 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
586 }
587
588 return result;
589 error:
590 kfree(result);
591 return ERR_PTR(err);
592}
593
594static int nl80211_key_allowed(struct wireless_dev *wdev)
595{
596 ASSERT_WDEV_LOCK(wdev);
597
fffd0934
JB
598 switch (wdev->iftype) {
599 case NL80211_IFTYPE_AP:
600 case NL80211_IFTYPE_AP_VLAN:
074ac8df 601 case NL80211_IFTYPE_P2P_GO:
ff973af7 602 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
603 break;
604 case NL80211_IFTYPE_ADHOC:
605 if (!wdev->current_bss)
606 return -ENOLINK;
607 break;
608 case NL80211_IFTYPE_STATION:
074ac8df 609 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
610 if (wdev->sme_state != CFG80211_SME_CONNECTED)
611 return -ENOLINK;
612 break;
613 default:
614 return -EINVAL;
615 }
616
617 return 0;
618}
619
7527a782
JB
620static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
621{
622 struct nlattr *nl_modes = nla_nest_start(msg, attr);
623 int i;
624
625 if (!nl_modes)
626 goto nla_put_failure;
627
628 i = 0;
629 while (ifmodes) {
9360ffd1
DM
630 if ((ifmodes & 1) && nla_put_flag(msg, i))
631 goto nla_put_failure;
7527a782
JB
632 ifmodes >>= 1;
633 i++;
634 }
635
636 nla_nest_end(msg, nl_modes);
637 return 0;
638
639nla_put_failure:
640 return -ENOBUFS;
641}
642
643static int nl80211_put_iface_combinations(struct wiphy *wiphy,
644 struct sk_buff *msg)
645{
646 struct nlattr *nl_combis;
647 int i, j;
648
649 nl_combis = nla_nest_start(msg,
650 NL80211_ATTR_INTERFACE_COMBINATIONS);
651 if (!nl_combis)
652 goto nla_put_failure;
653
654 for (i = 0; i < wiphy->n_iface_combinations; i++) {
655 const struct ieee80211_iface_combination *c;
656 struct nlattr *nl_combi, *nl_limits;
657
658 c = &wiphy->iface_combinations[i];
659
660 nl_combi = nla_nest_start(msg, i + 1);
661 if (!nl_combi)
662 goto nla_put_failure;
663
664 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
665 if (!nl_limits)
666 goto nla_put_failure;
667
668 for (j = 0; j < c->n_limits; j++) {
669 struct nlattr *nl_limit;
670
671 nl_limit = nla_nest_start(msg, j + 1);
672 if (!nl_limit)
673 goto nla_put_failure;
9360ffd1
DM
674 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
675 c->limits[j].max))
676 goto nla_put_failure;
7527a782
JB
677 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
678 c->limits[j].types))
679 goto nla_put_failure;
680 nla_nest_end(msg, nl_limit);
681 }
682
683 nla_nest_end(msg, nl_limits);
684
9360ffd1
DM
685 if (c->beacon_int_infra_match &&
686 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
687 goto nla_put_failure;
688 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
689 c->num_different_channels) ||
690 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
691 c->max_interfaces))
692 goto nla_put_failure;
7527a782
JB
693
694 nla_nest_end(msg, nl_combi);
695 }
696
697 nla_nest_end(msg, nl_combis);
698
699 return 0;
700nla_put_failure:
701 return -ENOBUFS;
702}
703
55682965
JB
704static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
705 struct cfg80211_registered_device *dev)
706{
707 void *hdr;
ee688b00
JB
708 struct nlattr *nl_bands, *nl_band;
709 struct nlattr *nl_freqs, *nl_freq;
710 struct nlattr *nl_rates, *nl_rate;
8fdc621d 711 struct nlattr *nl_cmds;
ee688b00
JB
712 enum ieee80211_band band;
713 struct ieee80211_channel *chan;
714 struct ieee80211_rate *rate;
715 int i;
2e161f78
JB
716 const struct ieee80211_txrx_stypes *mgmt_stypes =
717 dev->wiphy.mgmt_stypes;
55682965
JB
718
719 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
720 if (!hdr)
721 return -1;
722
9360ffd1
DM
723 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
724 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
725 nla_put_u32(msg, NL80211_ATTR_GENERATION,
726 cfg80211_rdev_list_generation) ||
727 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
728 dev->wiphy.retry_short) ||
729 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
730 dev->wiphy.retry_long) ||
731 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
732 dev->wiphy.frag_threshold) ||
733 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
734 dev->wiphy.rts_threshold) ||
735 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
736 dev->wiphy.coverage_class) ||
737 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
738 dev->wiphy.max_scan_ssids) ||
739 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
740 dev->wiphy.max_sched_scan_ssids) ||
741 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
742 dev->wiphy.max_scan_ie_len) ||
743 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
744 dev->wiphy.max_sched_scan_ie_len) ||
745 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
746 dev->wiphy.max_match_sets))
747 goto nla_put_failure;
748
749 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
750 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
751 goto nla_put_failure;
752 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
753 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
754 goto nla_put_failure;
755 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
756 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
757 goto nla_put_failure;
758 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
759 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
760 goto nla_put_failure;
761 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
762 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
763 goto nla_put_failure;
764 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
765 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
766 goto nla_put_failure;
767
768 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
769 sizeof(u32) * dev->wiphy.n_cipher_suites,
770 dev->wiphy.cipher_suites))
771 goto nla_put_failure;
772
773 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
774 dev->wiphy.max_num_pmkids))
775 goto nla_put_failure;
776
777 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
778 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
779 goto nla_put_failure;
780
781 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
782 dev->wiphy.available_antennas_tx) ||
783 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
784 dev->wiphy.available_antennas_rx))
785 goto nla_put_failure;
786
787 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
788 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
789 dev->wiphy.probe_resp_offload))
790 goto nla_put_failure;
87bbbe22 791
7f531e03
BR
792 if ((dev->wiphy.available_antennas_tx ||
793 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
794 u32 tx_ant = 0, rx_ant = 0;
795 int res;
796 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
797 if (!res) {
9360ffd1
DM
798 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
799 tx_ant) ||
800 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
801 rx_ant))
802 goto nla_put_failure;
afe0cbf8
BR
803 }
804 }
805
7527a782
JB
806 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
807 dev->wiphy.interface_modes))
f59ac048
LR
808 goto nla_put_failure;
809
ee688b00
JB
810 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
811 if (!nl_bands)
812 goto nla_put_failure;
813
814 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
815 if (!dev->wiphy.bands[band])
816 continue;
817
818 nl_band = nla_nest_start(msg, band);
819 if (!nl_band)
820 goto nla_put_failure;
821
d51626df 822 /* add HT info */
9360ffd1
DM
823 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
824 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
825 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
826 &dev->wiphy.bands[band]->ht_cap.mcs) ||
827 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
828 dev->wiphy.bands[band]->ht_cap.cap) ||
829 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
830 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
831 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
832 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
833 goto nla_put_failure;
d51626df 834
ee688b00
JB
835 /* add frequencies */
836 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
837 if (!nl_freqs)
838 goto nla_put_failure;
839
840 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
841 nl_freq = nla_nest_start(msg, i);
842 if (!nl_freq)
843 goto nla_put_failure;
844
845 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
846
847 if (nl80211_msg_put_channel(msg, chan))
848 goto nla_put_failure;
e2f367f2 849
ee688b00
JB
850 nla_nest_end(msg, nl_freq);
851 }
852
853 nla_nest_end(msg, nl_freqs);
854
855 /* add bitrates */
856 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
857 if (!nl_rates)
858 goto nla_put_failure;
859
860 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
861 nl_rate = nla_nest_start(msg, i);
862 if (!nl_rate)
863 goto nla_put_failure;
864
865 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
866 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
867 rate->bitrate))
868 goto nla_put_failure;
869 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
870 nla_put_flag(msg,
871 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
872 goto nla_put_failure;
ee688b00
JB
873
874 nla_nest_end(msg, nl_rate);
875 }
876
877 nla_nest_end(msg, nl_rates);
878
879 nla_nest_end(msg, nl_band);
880 }
881 nla_nest_end(msg, nl_bands);
882
8fdc621d
JB
883 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
884 if (!nl_cmds)
885 goto nla_put_failure;
886
887 i = 0;
888#define CMD(op, n) \
889 do { \
890 if (dev->ops->op) { \
891 i++; \
9360ffd1
DM
892 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
893 goto nla_put_failure; \
8fdc621d
JB
894 } \
895 } while (0)
896
897 CMD(add_virtual_intf, NEW_INTERFACE);
898 CMD(change_virtual_intf, SET_INTERFACE);
899 CMD(add_key, NEW_KEY);
8860020e 900 CMD(start_ap, START_AP);
8fdc621d
JB
901 CMD(add_station, NEW_STATION);
902 CMD(add_mpath, NEW_MPATH);
24bdd9f4 903 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 904 CMD(change_bss, SET_BSS);
636a5d36
JM
905 CMD(auth, AUTHENTICATE);
906 CMD(assoc, ASSOCIATE);
907 CMD(deauth, DEAUTHENTICATE);
908 CMD(disassoc, DISASSOCIATE);
04a773ad 909 CMD(join_ibss, JOIN_IBSS);
29cbe68c 910 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
911 CMD(set_pmksa, SET_PMKSA);
912 CMD(del_pmksa, DEL_PMKSA);
913 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
914 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
915 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 916 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 917 CMD(mgmt_tx, FRAME);
f7ca38df 918 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 919 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 920 i++;
9360ffd1
DM
921 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
922 goto nla_put_failure;
463d0183 923 }
e8c9bd5b 924 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 925 dev->ops->join_mesh) {
aa430da4
JB
926 i++;
927 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
928 goto nla_put_failure;
929 }
e8347eba 930 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
931 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
932 CMD(tdls_mgmt, TDLS_MGMT);
933 CMD(tdls_oper, TDLS_OPER);
934 }
807f8a8c
LC
935 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
936 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 937 CMD(probe_client, PROBE_CLIENT);
1d9d9213 938 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
939 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
940 i++;
9360ffd1
DM
941 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
942 goto nla_put_failure;
5e760230 943 }
8fdc621d 944
4745fc09
KV
945#ifdef CONFIG_NL80211_TESTMODE
946 CMD(testmode_cmd, TESTMODE);
947#endif
948
8fdc621d 949#undef CMD
b23aa676 950
6829c878 951 if (dev->ops->connect || dev->ops->auth) {
b23aa676 952 i++;
9360ffd1
DM
953 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
954 goto nla_put_failure;
b23aa676
SO
955 }
956
6829c878 957 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 958 i++;
9360ffd1
DM
959 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
960 goto nla_put_failure;
b23aa676
SO
961 }
962
8fdc621d
JB
963 nla_nest_end(msg, nl_cmds);
964
7c4ef712 965 if (dev->ops->remain_on_channel &&
9360ffd1
DM
966 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
967 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
968 dev->wiphy.max_remain_on_channel_duration))
969 goto nla_put_failure;
a293911d 970
9360ffd1
DM
971 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
972 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
973 goto nla_put_failure;
f7ca38df 974
2e161f78
JB
975 if (mgmt_stypes) {
976 u16 stypes;
977 struct nlattr *nl_ftypes, *nl_ifs;
978 enum nl80211_iftype ift;
979
980 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
981 if (!nl_ifs)
982 goto nla_put_failure;
983
984 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
985 nl_ftypes = nla_nest_start(msg, ift);
986 if (!nl_ftypes)
987 goto nla_put_failure;
988 i = 0;
989 stypes = mgmt_stypes[ift].tx;
990 while (stypes) {
9360ffd1
DM
991 if ((stypes & 1) &&
992 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
993 (i << 4) | IEEE80211_FTYPE_MGMT))
994 goto nla_put_failure;
2e161f78
JB
995 stypes >>= 1;
996 i++;
997 }
998 nla_nest_end(msg, nl_ftypes);
999 }
1000
74b70a4e
JB
1001 nla_nest_end(msg, nl_ifs);
1002
2e161f78
JB
1003 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1004 if (!nl_ifs)
1005 goto nla_put_failure;
1006
1007 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1008 nl_ftypes = nla_nest_start(msg, ift);
1009 if (!nl_ftypes)
1010 goto nla_put_failure;
1011 i = 0;
1012 stypes = mgmt_stypes[ift].rx;
1013 while (stypes) {
9360ffd1
DM
1014 if ((stypes & 1) &&
1015 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1016 (i << 4) | IEEE80211_FTYPE_MGMT))
1017 goto nla_put_failure;
2e161f78
JB
1018 stypes >>= 1;
1019 i++;
1020 }
1021 nla_nest_end(msg, nl_ftypes);
1022 }
1023 nla_nest_end(msg, nl_ifs);
1024 }
1025
ff1b6e69
JB
1026 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1027 struct nlattr *nl_wowlan;
1028
1029 nl_wowlan = nla_nest_start(msg,
1030 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1031 if (!nl_wowlan)
1032 goto nla_put_failure;
1033
9360ffd1
DM
1034 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1035 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1036 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1037 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1038 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1039 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1040 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1041 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1042 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1043 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1044 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1045 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1046 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1047 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1048 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1049 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1050 goto nla_put_failure;
ff1b6e69
JB
1051 if (dev->wiphy.wowlan.n_patterns) {
1052 struct nl80211_wowlan_pattern_support pat = {
1053 .max_patterns = dev->wiphy.wowlan.n_patterns,
1054 .min_pattern_len =
1055 dev->wiphy.wowlan.pattern_min_len,
1056 .max_pattern_len =
1057 dev->wiphy.wowlan.pattern_max_len,
1058 };
9360ffd1
DM
1059 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1060 sizeof(pat), &pat))
1061 goto nla_put_failure;
ff1b6e69
JB
1062 }
1063
1064 nla_nest_end(msg, nl_wowlan);
1065 }
1066
7527a782
JB
1067 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1068 dev->wiphy.software_iftypes))
1069 goto nla_put_failure;
1070
1071 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1072 goto nla_put_failure;
1073
9360ffd1
DM
1074 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1075 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1076 dev->wiphy.ap_sme_capa))
1077 goto nla_put_failure;
562a7480 1078
9360ffd1
DM
1079 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1080 dev->wiphy.features))
1081 goto nla_put_failure;
1f074bd8 1082
9360ffd1
DM
1083 if (dev->wiphy.ht_capa_mod_mask &&
1084 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1085 sizeof(*dev->wiphy.ht_capa_mod_mask),
1086 dev->wiphy.ht_capa_mod_mask))
1087 goto nla_put_failure;
7e7c8926 1088
55682965
JB
1089 return genlmsg_end(msg, hdr);
1090
1091 nla_put_failure:
bc3ed28c
TG
1092 genlmsg_cancel(msg, hdr);
1093 return -EMSGSIZE;
55682965
JB
1094}
1095
1096static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1097{
1098 int idx = 0;
1099 int start = cb->args[0];
1100 struct cfg80211_registered_device *dev;
1101
a1794390 1102 mutex_lock(&cfg80211_mutex);
79c97e97 1103 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1104 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1105 continue;
b4637271 1106 if (++idx <= start)
55682965
JB
1107 continue;
1108 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1109 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1110 dev) < 0) {
1111 idx--;
55682965 1112 break;
b4637271 1113 }
55682965 1114 }
a1794390 1115 mutex_unlock(&cfg80211_mutex);
55682965
JB
1116
1117 cb->args[0] = idx;
1118
1119 return skb->len;
1120}
1121
1122static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1123{
1124 struct sk_buff *msg;
4c476991 1125 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1126
fd2120ca 1127 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1128 if (!msg)
4c476991 1129 return -ENOMEM;
55682965 1130
4c476991
JB
1131 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1132 nlmsg_free(msg);
1133 return -ENOBUFS;
1134 }
55682965 1135
134e6375 1136 return genlmsg_reply(msg, info);
55682965
JB
1137}
1138
31888487
JM
1139static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1140 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1141 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1142 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1143 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1144 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1145};
1146
1147static int parse_txq_params(struct nlattr *tb[],
1148 struct ieee80211_txq_params *txq_params)
1149{
a3304b0a 1150 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1151 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1152 !tb[NL80211_TXQ_ATTR_AIFS])
1153 return -EINVAL;
1154
a3304b0a 1155 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1156 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1157 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1158 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1159 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1160
a3304b0a
JB
1161 if (txq_params->ac >= NL80211_NUM_ACS)
1162 return -EINVAL;
1163
31888487
JM
1164 return 0;
1165}
1166
f444de05
JB
1167static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1168{
1169 /*
cc1d2806
JB
1170 * You can only set the channel explicitly for WDS interfaces,
1171 * all others have their channel managed via their respective
1172 * "establish a connection" command (connect, join, ...)
1173 *
1174 * For AP/GO and mesh mode, the channel can be set with the
1175 * channel userspace API, but is only stored and passed to the
1176 * low-level driver when the AP starts or the mesh is joined.
1177 * This is for backward compatibility, userspace can also give
1178 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1179 *
1180 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1181 * whatever else is going on, so they have their own special
1182 * operation to set the monitor channel if possible.
f444de05
JB
1183 */
1184 return !wdev ||
1185 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1186 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1187 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1188 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1189}
1190
cd6c6598
JB
1191static bool nl80211_valid_channel_type(struct genl_info *info,
1192 enum nl80211_channel_type *channel_type)
1193{
1194 enum nl80211_channel_type tmp;
1195
1196 if (!info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE])
1197 return false;
1198
1199 tmp = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1200 if (tmp != NL80211_CHAN_NO_HT &&
1201 tmp != NL80211_CHAN_HT20 &&
1202 tmp != NL80211_CHAN_HT40PLUS &&
1203 tmp != NL80211_CHAN_HT40MINUS)
1204 return false;
1205
1206 if (channel_type)
1207 *channel_type = tmp;
1208
1209 return true;
1210}
1211
f444de05
JB
1212static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1213 struct wireless_dev *wdev,
1214 struct genl_info *info)
1215{
aa430da4 1216 struct ieee80211_channel *channel;
f444de05
JB
1217 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1218 u32 freq;
1219 int result;
e8c9bd5b
JB
1220 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1221
1222 if (wdev)
1223 iftype = wdev->iftype;
f444de05
JB
1224
1225 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1226 return -EINVAL;
1227
1228 if (!nl80211_can_set_dev_channel(wdev))
1229 return -EOPNOTSUPP;
1230
cd6c6598
JB
1231 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
1232 !nl80211_valid_channel_type(info, &channel_type))
1233 return -EINVAL;
f444de05
JB
1234
1235 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1236
1237 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1238 switch (iftype) {
aa430da4
JB
1239 case NL80211_IFTYPE_AP:
1240 case NL80211_IFTYPE_P2P_GO:
1241 if (wdev->beacon_interval) {
1242 result = -EBUSY;
1243 break;
1244 }
1245 channel = rdev_freq_to_chan(rdev, freq, channel_type);
1246 if (!channel || !cfg80211_can_beacon_sec_chan(&rdev->wiphy,
1247 channel,
1248 channel_type)) {
1249 result = -EINVAL;
1250 break;
1251 }
1252 wdev->preset_chan = channel;
1253 wdev->preset_chantype = channel_type;
1254 result = 0;
1255 break;
cc1d2806
JB
1256 case NL80211_IFTYPE_MESH_POINT:
1257 result = cfg80211_set_mesh_freq(rdev, wdev, freq, channel_type);
1258 break;
e8c9bd5b
JB
1259 case NL80211_IFTYPE_MONITOR:
1260 result = cfg80211_set_monitor_channel(rdev, freq, channel_type);
1261 break;
aa430da4 1262 default:
e8c9bd5b 1263 result = -EINVAL;
f444de05
JB
1264 }
1265 mutex_unlock(&rdev->devlist_mtx);
1266
1267 return result;
1268}
1269
1270static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1271{
4c476991
JB
1272 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1273 struct net_device *netdev = info->user_ptr[1];
f444de05 1274
4c476991 1275 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1276}
1277
e8347eba
BJ
1278static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1279{
43b19952
JB
1280 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1281 struct net_device *dev = info->user_ptr[1];
1282 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1283 const u8 *bssid;
e8347eba
BJ
1284
1285 if (!info->attrs[NL80211_ATTR_MAC])
1286 return -EINVAL;
1287
43b19952
JB
1288 if (netif_running(dev))
1289 return -EBUSY;
e8347eba 1290
43b19952
JB
1291 if (!rdev->ops->set_wds_peer)
1292 return -EOPNOTSUPP;
e8347eba 1293
43b19952
JB
1294 if (wdev->iftype != NL80211_IFTYPE_WDS)
1295 return -EOPNOTSUPP;
e8347eba
BJ
1296
1297 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1298 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1299}
1300
1301
55682965
JB
1302static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1303{
1304 struct cfg80211_registered_device *rdev;
f444de05
JB
1305 struct net_device *netdev = NULL;
1306 struct wireless_dev *wdev;
a1e567c8 1307 int result = 0, rem_txq_params = 0;
31888487 1308 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1309 u32 changed;
1310 u8 retry_short = 0, retry_long = 0;
1311 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1312 u8 coverage_class = 0;
55682965 1313
f444de05
JB
1314 /*
1315 * Try to find the wiphy and netdev. Normally this
1316 * function shouldn't need the netdev, but this is
1317 * done for backward compatibility -- previously
1318 * setting the channel was done per wiphy, but now
1319 * it is per netdev. Previous userland like hostapd
1320 * also passed a netdev to set_wiphy, so that it is
1321 * possible to let that go to the right netdev!
1322 */
4bbf4d56
JB
1323 mutex_lock(&cfg80211_mutex);
1324
f444de05
JB
1325 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1326 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1327
1328 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1329 if (netdev && netdev->ieee80211_ptr) {
1330 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1331 mutex_lock(&rdev->mtx);
1332 } else
1333 netdev = NULL;
4bbf4d56
JB
1334 }
1335
f444de05
JB
1336 if (!netdev) {
1337 rdev = __cfg80211_rdev_from_info(info);
1338 if (IS_ERR(rdev)) {
1339 mutex_unlock(&cfg80211_mutex);
4c476991 1340 return PTR_ERR(rdev);
f444de05
JB
1341 }
1342 wdev = NULL;
1343 netdev = NULL;
1344 result = 0;
1345
1346 mutex_lock(&rdev->mtx);
cc1d2806 1347 } else if (nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
f444de05
JB
1348 wdev = netdev->ieee80211_ptr;
1349 else
1350 wdev = NULL;
1351
1352 /*
1353 * end workaround code, by now the rdev is available
1354 * and locked, and wdev may or may not be NULL.
1355 */
4bbf4d56
JB
1356
1357 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1358 result = cfg80211_dev_rename(
1359 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1360
1361 mutex_unlock(&cfg80211_mutex);
1362
1363 if (result)
1364 goto bad_res;
31888487
JM
1365
1366 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1367 struct ieee80211_txq_params txq_params;
1368 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1369
1370 if (!rdev->ops->set_txq_params) {
1371 result = -EOPNOTSUPP;
1372 goto bad_res;
1373 }
1374
f70f01c2
EP
1375 if (!netdev) {
1376 result = -EINVAL;
1377 goto bad_res;
1378 }
1379
133a3ff2
JB
1380 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1381 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1382 result = -EINVAL;
1383 goto bad_res;
1384 }
1385
2b5f8b0b
JB
1386 if (!netif_running(netdev)) {
1387 result = -ENETDOWN;
1388 goto bad_res;
1389 }
1390
31888487
JM
1391 nla_for_each_nested(nl_txq_params,
1392 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1393 rem_txq_params) {
1394 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1395 nla_data(nl_txq_params),
1396 nla_len(nl_txq_params),
1397 txq_params_policy);
1398 result = parse_txq_params(tb, &txq_params);
1399 if (result)
1400 goto bad_res;
1401
1402 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1403 netdev,
31888487
JM
1404 &txq_params);
1405 if (result)
1406 goto bad_res;
1407 }
1408 }
55682965 1409
72bdcf34 1410 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1411 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1412 if (result)
1413 goto bad_res;
1414 }
1415
98d2ff8b
JO
1416 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1417 enum nl80211_tx_power_setting type;
1418 int idx, mbm = 0;
1419
1420 if (!rdev->ops->set_tx_power) {
60ea385f 1421 result = -EOPNOTSUPP;
98d2ff8b
JO
1422 goto bad_res;
1423 }
1424
1425 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1426 type = nla_get_u32(info->attrs[idx]);
1427
1428 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1429 (type != NL80211_TX_POWER_AUTOMATIC)) {
1430 result = -EINVAL;
1431 goto bad_res;
1432 }
1433
1434 if (type != NL80211_TX_POWER_AUTOMATIC) {
1435 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1436 mbm = nla_get_u32(info->attrs[idx]);
1437 }
1438
1439 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1440 if (result)
1441 goto bad_res;
1442 }
1443
afe0cbf8
BR
1444 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1445 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1446 u32 tx_ant, rx_ant;
7f531e03
BR
1447 if ((!rdev->wiphy.available_antennas_tx &&
1448 !rdev->wiphy.available_antennas_rx) ||
1449 !rdev->ops->set_antenna) {
afe0cbf8
BR
1450 result = -EOPNOTSUPP;
1451 goto bad_res;
1452 }
1453
1454 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1455 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1456
a7ffac95 1457 /* reject antenna configurations which don't match the
7f531e03
BR
1458 * available antenna masks, except for the "all" mask */
1459 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1460 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1461 result = -EINVAL;
1462 goto bad_res;
1463 }
1464
7f531e03
BR
1465 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1466 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1467
afe0cbf8
BR
1468 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1469 if (result)
1470 goto bad_res;
1471 }
1472
b9a5f8ca
JM
1473 changed = 0;
1474
1475 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1476 retry_short = nla_get_u8(
1477 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1478 if (retry_short == 0) {
1479 result = -EINVAL;
1480 goto bad_res;
1481 }
1482 changed |= WIPHY_PARAM_RETRY_SHORT;
1483 }
1484
1485 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1486 retry_long = nla_get_u8(
1487 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1488 if (retry_long == 0) {
1489 result = -EINVAL;
1490 goto bad_res;
1491 }
1492 changed |= WIPHY_PARAM_RETRY_LONG;
1493 }
1494
1495 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1496 frag_threshold = nla_get_u32(
1497 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1498 if (frag_threshold < 256) {
1499 result = -EINVAL;
1500 goto bad_res;
1501 }
1502 if (frag_threshold != (u32) -1) {
1503 /*
1504 * Fragments (apart from the last one) are required to
1505 * have even length. Make the fragmentation code
1506 * simpler by stripping LSB should someone try to use
1507 * odd threshold value.
1508 */
1509 frag_threshold &= ~0x1;
1510 }
1511 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1512 }
1513
1514 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1515 rts_threshold = nla_get_u32(
1516 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1517 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1518 }
1519
81077e82
LT
1520 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1521 coverage_class = nla_get_u8(
1522 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1523 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1524 }
1525
b9a5f8ca
JM
1526 if (changed) {
1527 u8 old_retry_short, old_retry_long;
1528 u32 old_frag_threshold, old_rts_threshold;
81077e82 1529 u8 old_coverage_class;
b9a5f8ca
JM
1530
1531 if (!rdev->ops->set_wiphy_params) {
1532 result = -EOPNOTSUPP;
1533 goto bad_res;
1534 }
1535
1536 old_retry_short = rdev->wiphy.retry_short;
1537 old_retry_long = rdev->wiphy.retry_long;
1538 old_frag_threshold = rdev->wiphy.frag_threshold;
1539 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1540 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1541
1542 if (changed & WIPHY_PARAM_RETRY_SHORT)
1543 rdev->wiphy.retry_short = retry_short;
1544 if (changed & WIPHY_PARAM_RETRY_LONG)
1545 rdev->wiphy.retry_long = retry_long;
1546 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1547 rdev->wiphy.frag_threshold = frag_threshold;
1548 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1549 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1550 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1551 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1552
1553 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1554 if (result) {
1555 rdev->wiphy.retry_short = old_retry_short;
1556 rdev->wiphy.retry_long = old_retry_long;
1557 rdev->wiphy.frag_threshold = old_frag_threshold;
1558 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1559 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1560 }
1561 }
72bdcf34 1562
306d6112 1563 bad_res:
4bbf4d56 1564 mutex_unlock(&rdev->mtx);
f444de05
JB
1565 if (netdev)
1566 dev_put(netdev);
55682965
JB
1567 return result;
1568}
1569
1570
1571static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1572 struct cfg80211_registered_device *rdev,
55682965
JB
1573 struct net_device *dev)
1574{
1575 void *hdr;
1576
1577 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1578 if (!hdr)
1579 return -1;
1580
9360ffd1
DM
1581 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
1582 nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1583 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name) ||
1584 nla_put_u32(msg, NL80211_ATTR_IFTYPE,
1585 dev->ieee80211_ptr->iftype) ||
1586 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1587 rdev->devlist_generation ^
1588 (cfg80211_rdev_list_generation << 2)))
1589 goto nla_put_failure;
f5ea9120 1590
d91df0e3
PF
1591 if (rdev->ops->get_channel) {
1592 struct ieee80211_channel *chan;
1593 enum nl80211_channel_type channel_type;
1594
1595 chan = rdev->ops->get_channel(&rdev->wiphy, &channel_type);
59ef43e6
JL
1596 if (chan &&
1597 (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1598 chan->center_freq) ||
1599 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1600 channel_type)))
1601 goto nla_put_failure;
d91df0e3
PF
1602 }
1603
55682965
JB
1604 return genlmsg_end(msg, hdr);
1605
1606 nla_put_failure:
bc3ed28c
TG
1607 genlmsg_cancel(msg, hdr);
1608 return -EMSGSIZE;
55682965
JB
1609}
1610
1611static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1612{
1613 int wp_idx = 0;
1614 int if_idx = 0;
1615 int wp_start = cb->args[0];
1616 int if_start = cb->args[1];
f5ea9120 1617 struct cfg80211_registered_device *rdev;
55682965
JB
1618 struct wireless_dev *wdev;
1619
a1794390 1620 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1621 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1622 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1623 continue;
bba95fef
JB
1624 if (wp_idx < wp_start) {
1625 wp_idx++;
55682965 1626 continue;
bba95fef 1627 }
55682965
JB
1628 if_idx = 0;
1629
f5ea9120
JB
1630 mutex_lock(&rdev->devlist_mtx);
1631 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1632 if (if_idx < if_start) {
1633 if_idx++;
55682965 1634 continue;
bba95fef 1635 }
55682965
JB
1636 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1637 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1638 rdev, wdev->netdev) < 0) {
1639 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1640 goto out;
1641 }
1642 if_idx++;
55682965 1643 }
f5ea9120 1644 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1645
1646 wp_idx++;
55682965 1647 }
bba95fef 1648 out:
a1794390 1649 mutex_unlock(&cfg80211_mutex);
55682965
JB
1650
1651 cb->args[0] = wp_idx;
1652 cb->args[1] = if_idx;
1653
1654 return skb->len;
1655}
1656
1657static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1658{
1659 struct sk_buff *msg;
4c476991
JB
1660 struct cfg80211_registered_device *dev = info->user_ptr[0];
1661 struct net_device *netdev = info->user_ptr[1];
55682965 1662
fd2120ca 1663 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1664 if (!msg)
4c476991 1665 return -ENOMEM;
55682965 1666
d726405a 1667 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1668 dev, netdev) < 0) {
1669 nlmsg_free(msg);
1670 return -ENOBUFS;
1671 }
55682965 1672
134e6375 1673 return genlmsg_reply(msg, info);
55682965
JB
1674}
1675
66f7ac50
MW
1676static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1677 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1678 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1679 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1680 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1681 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1682};
1683
1684static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1685{
1686 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1687 int flag;
1688
1689 *mntrflags = 0;
1690
1691 if (!nla)
1692 return -EINVAL;
1693
1694 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1695 nla, mntr_flags_policy))
1696 return -EINVAL;
1697
1698 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1699 if (flags[flag])
1700 *mntrflags |= (1<<flag);
1701
1702 return 0;
1703}
1704
9bc383de 1705static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1706 struct net_device *netdev, u8 use_4addr,
1707 enum nl80211_iftype iftype)
9bc383de 1708{
ad4bb6f8 1709 if (!use_4addr) {
f350a0a8 1710 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1711 return -EBUSY;
9bc383de 1712 return 0;
ad4bb6f8 1713 }
9bc383de
JB
1714
1715 switch (iftype) {
1716 case NL80211_IFTYPE_AP_VLAN:
1717 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1718 return 0;
1719 break;
1720 case NL80211_IFTYPE_STATION:
1721 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1722 return 0;
1723 break;
1724 default:
1725 break;
1726 }
1727
1728 return -EOPNOTSUPP;
1729}
1730
55682965
JB
1731static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1732{
4c476991 1733 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1734 struct vif_params params;
e36d56b6 1735 int err;
04a773ad 1736 enum nl80211_iftype otype, ntype;
4c476991 1737 struct net_device *dev = info->user_ptr[1];
92ffe055 1738 u32 _flags, *flags = NULL;
ac7f9cfa 1739 bool change = false;
55682965 1740
2ec600d6
LCC
1741 memset(&params, 0, sizeof(params));
1742
04a773ad 1743 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1744
723b038d 1745 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1746 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1747 if (otype != ntype)
ac7f9cfa 1748 change = true;
4c476991
JB
1749 if (ntype > NL80211_IFTYPE_MAX)
1750 return -EINVAL;
723b038d
JB
1751 }
1752
92ffe055 1753 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1754 struct wireless_dev *wdev = dev->ieee80211_ptr;
1755
4c476991
JB
1756 if (ntype != NL80211_IFTYPE_MESH_POINT)
1757 return -EINVAL;
29cbe68c
JB
1758 if (netif_running(dev))
1759 return -EBUSY;
1760
1761 wdev_lock(wdev);
1762 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1763 IEEE80211_MAX_MESH_ID_LEN);
1764 wdev->mesh_id_up_len =
1765 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1766 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1767 wdev->mesh_id_up_len);
1768 wdev_unlock(wdev);
2ec600d6
LCC
1769 }
1770
8b787643
FF
1771 if (info->attrs[NL80211_ATTR_4ADDR]) {
1772 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1773 change = true;
ad4bb6f8 1774 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1775 if (err)
4c476991 1776 return err;
8b787643
FF
1777 } else {
1778 params.use_4addr = -1;
1779 }
1780
92ffe055 1781 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1782 if (ntype != NL80211_IFTYPE_MONITOR)
1783 return -EINVAL;
92ffe055
JB
1784 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1785 &_flags);
ac7f9cfa 1786 if (err)
4c476991 1787 return err;
ac7f9cfa
JB
1788
1789 flags = &_flags;
1790 change = true;
92ffe055 1791 }
3b85875a 1792
ac7f9cfa 1793 if (change)
3d54d255 1794 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1795 else
1796 err = 0;
60719ffd 1797
9bc383de
JB
1798 if (!err && params.use_4addr != -1)
1799 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1800
55682965
JB
1801 return err;
1802}
1803
1804static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1805{
4c476991 1806 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1807 struct vif_params params;
f9e10ce4 1808 struct net_device *dev;
55682965
JB
1809 int err;
1810 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1811 u32 flags;
55682965 1812
2ec600d6
LCC
1813 memset(&params, 0, sizeof(params));
1814
55682965
JB
1815 if (!info->attrs[NL80211_ATTR_IFNAME])
1816 return -EINVAL;
1817
1818 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1819 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1820 if (type > NL80211_IFTYPE_MAX)
1821 return -EINVAL;
1822 }
1823
79c97e97 1824 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1825 !(rdev->wiphy.interface_modes & (1 << type)))
1826 return -EOPNOTSUPP;
55682965 1827
9bc383de 1828 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1829 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1830 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1831 if (err)
4c476991 1832 return err;
9bc383de 1833 }
8b787643 1834
66f7ac50
MW
1835 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1836 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1837 &flags);
f9e10ce4 1838 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1839 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1840 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1841 if (IS_ERR(dev))
1842 return PTR_ERR(dev);
2ec600d6 1843
29cbe68c
JB
1844 if (type == NL80211_IFTYPE_MESH_POINT &&
1845 info->attrs[NL80211_ATTR_MESH_ID]) {
1846 struct wireless_dev *wdev = dev->ieee80211_ptr;
1847
1848 wdev_lock(wdev);
1849 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1850 IEEE80211_MAX_MESH_ID_LEN);
1851 wdev->mesh_id_up_len =
1852 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1853 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1854 wdev->mesh_id_up_len);
1855 wdev_unlock(wdev);
1856 }
1857
f9e10ce4 1858 return 0;
55682965
JB
1859}
1860
1861static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1862{
4c476991
JB
1863 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1864 struct net_device *dev = info->user_ptr[1];
55682965 1865
4c476991
JB
1866 if (!rdev->ops->del_virtual_intf)
1867 return -EOPNOTSUPP;
55682965 1868
4c476991 1869 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1870}
1871
1d9d9213
SW
1872static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
1873{
1874 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1875 struct net_device *dev = info->user_ptr[1];
1876 u16 noack_map;
1877
1878 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
1879 return -EINVAL;
1880
1881 if (!rdev->ops->set_noack_map)
1882 return -EOPNOTSUPP;
1883
1884 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
1885
1886 return rdev->ops->set_noack_map(&rdev->wiphy, dev, noack_map);
1887}
1888
41ade00f
JB
1889struct get_key_cookie {
1890 struct sk_buff *msg;
1891 int error;
b9454e83 1892 int idx;
41ade00f
JB
1893};
1894
1895static void get_key_callback(void *c, struct key_params *params)
1896{
b9454e83 1897 struct nlattr *key;
41ade00f
JB
1898 struct get_key_cookie *cookie = c;
1899
9360ffd1
DM
1900 if ((params->key &&
1901 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
1902 params->key_len, params->key)) ||
1903 (params->seq &&
1904 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
1905 params->seq_len, params->seq)) ||
1906 (params->cipher &&
1907 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1908 params->cipher)))
1909 goto nla_put_failure;
41ade00f 1910
b9454e83
JB
1911 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1912 if (!key)
1913 goto nla_put_failure;
1914
9360ffd1
DM
1915 if ((params->key &&
1916 nla_put(cookie->msg, NL80211_KEY_DATA,
1917 params->key_len, params->key)) ||
1918 (params->seq &&
1919 nla_put(cookie->msg, NL80211_KEY_SEQ,
1920 params->seq_len, params->seq)) ||
1921 (params->cipher &&
1922 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
1923 params->cipher)))
1924 goto nla_put_failure;
b9454e83 1925
9360ffd1
DM
1926 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
1927 goto nla_put_failure;
b9454e83
JB
1928
1929 nla_nest_end(cookie->msg, key);
1930
41ade00f
JB
1931 return;
1932 nla_put_failure:
1933 cookie->error = 1;
1934}
1935
1936static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1937{
4c476991 1938 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1939 int err;
4c476991 1940 struct net_device *dev = info->user_ptr[1];
41ade00f 1941 u8 key_idx = 0;
e31b8213
JB
1942 const u8 *mac_addr = NULL;
1943 bool pairwise;
41ade00f
JB
1944 struct get_key_cookie cookie = {
1945 .error = 0,
1946 };
1947 void *hdr;
1948 struct sk_buff *msg;
1949
1950 if (info->attrs[NL80211_ATTR_KEY_IDX])
1951 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1952
3cfcf6ac 1953 if (key_idx > 5)
41ade00f
JB
1954 return -EINVAL;
1955
1956 if (info->attrs[NL80211_ATTR_MAC])
1957 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1958
e31b8213
JB
1959 pairwise = !!mac_addr;
1960 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1961 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1962 if (kt >= NUM_NL80211_KEYTYPES)
1963 return -EINVAL;
1964 if (kt != NL80211_KEYTYPE_GROUP &&
1965 kt != NL80211_KEYTYPE_PAIRWISE)
1966 return -EINVAL;
1967 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1968 }
1969
4c476991
JB
1970 if (!rdev->ops->get_key)
1971 return -EOPNOTSUPP;
41ade00f 1972
fd2120ca 1973 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1974 if (!msg)
1975 return -ENOMEM;
41ade00f
JB
1976
1977 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1978 NL80211_CMD_NEW_KEY);
4c476991
JB
1979 if (IS_ERR(hdr))
1980 return PTR_ERR(hdr);
41ade00f
JB
1981
1982 cookie.msg = msg;
b9454e83 1983 cookie.idx = key_idx;
41ade00f 1984
9360ffd1
DM
1985 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
1986 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
1987 goto nla_put_failure;
1988 if (mac_addr &&
1989 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
1990 goto nla_put_failure;
41ade00f 1991
e31b8213
JB
1992 if (pairwise && mac_addr &&
1993 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1994 return -ENOENT;
1995
1996 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1997 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1998
1999 if (err)
6c95e2a2 2000 goto free_msg;
41ade00f
JB
2001
2002 if (cookie.error)
2003 goto nla_put_failure;
2004
2005 genlmsg_end(msg, hdr);
4c476991 2006 return genlmsg_reply(msg, info);
41ade00f
JB
2007
2008 nla_put_failure:
2009 err = -ENOBUFS;
6c95e2a2 2010 free_msg:
41ade00f 2011 nlmsg_free(msg);
41ade00f
JB
2012 return err;
2013}
2014
2015static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2016{
4c476991 2017 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2018 struct key_parse key;
41ade00f 2019 int err;
4c476991 2020 struct net_device *dev = info->user_ptr[1];
41ade00f 2021
b9454e83
JB
2022 err = nl80211_parse_key(info, &key);
2023 if (err)
2024 return err;
41ade00f 2025
b9454e83 2026 if (key.idx < 0)
41ade00f
JB
2027 return -EINVAL;
2028
b9454e83
JB
2029 /* only support setting default key */
2030 if (!key.def && !key.defmgmt)
41ade00f
JB
2031 return -EINVAL;
2032
dbd2fd65 2033 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2034
dbd2fd65
JB
2035 if (key.def) {
2036 if (!rdev->ops->set_default_key) {
2037 err = -EOPNOTSUPP;
2038 goto out;
2039 }
41ade00f 2040
dbd2fd65
JB
2041 err = nl80211_key_allowed(dev->ieee80211_ptr);
2042 if (err)
2043 goto out;
2044
dbd2fd65
JB
2045 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
2046 key.def_uni, key.def_multi);
2047
2048 if (err)
2049 goto out;
fffd0934 2050
3d23e349 2051#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2052 dev->ieee80211_ptr->wext.default_key = key.idx;
2053#endif
2054 } else {
2055 if (key.def_uni || !key.def_multi) {
2056 err = -EINVAL;
2057 goto out;
2058 }
2059
2060 if (!rdev->ops->set_default_mgmt_key) {
2061 err = -EOPNOTSUPP;
2062 goto out;
2063 }
2064
2065 err = nl80211_key_allowed(dev->ieee80211_ptr);
2066 if (err)
2067 goto out;
2068
2069 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
2070 dev, key.idx);
2071 if (err)
2072 goto out;
2073
2074#ifdef CONFIG_CFG80211_WEXT
2075 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2076#endif
dbd2fd65
JB
2077 }
2078
2079 out:
fffd0934 2080 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2081
41ade00f
JB
2082 return err;
2083}
2084
2085static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2086{
4c476991 2087 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2088 int err;
4c476991 2089 struct net_device *dev = info->user_ptr[1];
b9454e83 2090 struct key_parse key;
e31b8213 2091 const u8 *mac_addr = NULL;
41ade00f 2092
b9454e83
JB
2093 err = nl80211_parse_key(info, &key);
2094 if (err)
2095 return err;
41ade00f 2096
b9454e83 2097 if (!key.p.key)
41ade00f
JB
2098 return -EINVAL;
2099
41ade00f
JB
2100 if (info->attrs[NL80211_ATTR_MAC])
2101 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2102
e31b8213
JB
2103 if (key.type == -1) {
2104 if (mac_addr)
2105 key.type = NL80211_KEYTYPE_PAIRWISE;
2106 else
2107 key.type = NL80211_KEYTYPE_GROUP;
2108 }
2109
2110 /* for now */
2111 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2112 key.type != NL80211_KEYTYPE_GROUP)
2113 return -EINVAL;
2114
4c476991
JB
2115 if (!rdev->ops->add_key)
2116 return -EOPNOTSUPP;
25e47c18 2117
e31b8213
JB
2118 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2119 key.type == NL80211_KEYTYPE_PAIRWISE,
2120 mac_addr))
4c476991 2121 return -EINVAL;
41ade00f 2122
fffd0934
JB
2123 wdev_lock(dev->ieee80211_ptr);
2124 err = nl80211_key_allowed(dev->ieee80211_ptr);
2125 if (!err)
2126 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 2127 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
2128 mac_addr, &key.p);
2129 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2130
41ade00f
JB
2131 return err;
2132}
2133
2134static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2135{
4c476991 2136 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2137 int err;
4c476991 2138 struct net_device *dev = info->user_ptr[1];
41ade00f 2139 u8 *mac_addr = NULL;
b9454e83 2140 struct key_parse key;
41ade00f 2141
b9454e83
JB
2142 err = nl80211_parse_key(info, &key);
2143 if (err)
2144 return err;
41ade00f
JB
2145
2146 if (info->attrs[NL80211_ATTR_MAC])
2147 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2148
e31b8213
JB
2149 if (key.type == -1) {
2150 if (mac_addr)
2151 key.type = NL80211_KEYTYPE_PAIRWISE;
2152 else
2153 key.type = NL80211_KEYTYPE_GROUP;
2154 }
2155
2156 /* for now */
2157 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2158 key.type != NL80211_KEYTYPE_GROUP)
2159 return -EINVAL;
2160
4c476991
JB
2161 if (!rdev->ops->del_key)
2162 return -EOPNOTSUPP;
41ade00f 2163
fffd0934
JB
2164 wdev_lock(dev->ieee80211_ptr);
2165 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2166
2167 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2168 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2169 err = -ENOENT;
2170
fffd0934 2171 if (!err)
e31b8213
JB
2172 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2173 key.type == NL80211_KEYTYPE_PAIRWISE,
2174 mac_addr);
41ade00f 2175
3d23e349 2176#ifdef CONFIG_CFG80211_WEXT
08645126 2177 if (!err) {
b9454e83 2178 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2179 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2180 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2181 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2182 }
2183#endif
fffd0934 2184 wdev_unlock(dev->ieee80211_ptr);
08645126 2185
41ade00f
JB
2186 return err;
2187}
2188
8860020e
JB
2189static int nl80211_parse_beacon(struct genl_info *info,
2190 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2191{
8860020e 2192 bool haveinfo = false;
ed1b6cc7 2193
9946ecfb
JM
2194 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2195 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2196 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2197 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2198 return -EINVAL;
2199
8860020e 2200 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2201
ed1b6cc7 2202 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2203 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2204 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2205 if (!bcn->head_len)
2206 return -EINVAL;
2207 haveinfo = true;
ed1b6cc7
JB
2208 }
2209
2210 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2211 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2212 bcn->tail_len =
ed1b6cc7 2213 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2214 haveinfo = true;
ed1b6cc7
JB
2215 }
2216
4c476991
JB
2217 if (!haveinfo)
2218 return -EINVAL;
3b85875a 2219
9946ecfb 2220 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2221 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2222 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2223 }
2224
2225 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2226 bcn->proberesp_ies =
9946ecfb 2227 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2228 bcn->proberesp_ies_len =
9946ecfb
JM
2229 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2230 }
2231
2232 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2233 bcn->assocresp_ies =
9946ecfb 2234 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2235 bcn->assocresp_ies_len =
9946ecfb
JM
2236 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2237 }
2238
00f740e1 2239 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2240 bcn->probe_resp =
00f740e1 2241 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2242 bcn->probe_resp_len =
00f740e1
AN
2243 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2244 }
2245
8860020e
JB
2246 return 0;
2247}
2248
2249static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2250{
2251 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2252 struct net_device *dev = info->user_ptr[1];
2253 struct wireless_dev *wdev = dev->ieee80211_ptr;
2254 struct cfg80211_ap_settings params;
2255 int err;
2256
2257 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2258 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2259 return -EOPNOTSUPP;
2260
2261 if (!rdev->ops->start_ap)
2262 return -EOPNOTSUPP;
2263
2264 if (wdev->beacon_interval)
2265 return -EALREADY;
2266
2267 memset(&params, 0, sizeof(params));
2268
2269 /* these are required for START_AP */
2270 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2271 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2272 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2273 return -EINVAL;
2274
2275 err = nl80211_parse_beacon(info, &params.beacon);
2276 if (err)
2277 return err;
2278
2279 params.beacon_interval =
2280 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2281 params.dtim_period =
2282 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2283
2284 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2285 if (err)
2286 return err;
2287
2288 /*
2289 * In theory, some of these attributes should be required here
2290 * but since they were not used when the command was originally
2291 * added, keep them optional for old user space programs to let
2292 * them continue to work with drivers that do not need the
2293 * additional information -- drivers must check!
2294 */
2295 if (info->attrs[NL80211_ATTR_SSID]) {
2296 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2297 params.ssid_len =
2298 nla_len(info->attrs[NL80211_ATTR_SSID]);
2299 if (params.ssid_len == 0 ||
2300 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2301 return -EINVAL;
2302 }
2303
2304 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2305 params.hidden_ssid = nla_get_u32(
2306 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2307 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2308 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2309 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2310 return -EINVAL;
2311 }
2312
2313 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2314
2315 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2316 params.auth_type = nla_get_u32(
2317 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2318 if (!nl80211_valid_auth_type(params.auth_type))
2319 return -EINVAL;
2320 } else
2321 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2322
2323 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2324 NL80211_MAX_NR_CIPHER_SUITES);
2325 if (err)
2326 return err;
2327
1b658f11
VT
2328 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2329 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2330 return -EOPNOTSUPP;
2331 params.inactivity_timeout = nla_get_u16(
2332 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2333 }
2334
aa430da4
JB
2335 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
2336 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
2337
2338 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
2339 !nl80211_valid_channel_type(info, &channel_type))
2340 return -EINVAL;
2341
2342 params.channel = rdev_freq_to_chan(rdev,
2343 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
2344 channel_type);
2345 if (!params.channel)
2346 return -EINVAL;
2347 params.channel_type = channel_type;
2348 } else if (wdev->preset_chan) {
2349 params.channel = wdev->preset_chan;
2350 params.channel_type = wdev->preset_chantype;
2351 } else
2352 return -EINVAL;
2353
2354 if (!cfg80211_can_beacon_sec_chan(&rdev->wiphy, params.channel,
2355 params.channel_type))
2356 return -EINVAL;
2357
8860020e
JB
2358 err = rdev->ops->start_ap(&rdev->wiphy, dev, &params);
2359 if (!err)
2360 wdev->beacon_interval = params.beacon_interval;
56d1893d 2361 return err;
ed1b6cc7
JB
2362}
2363
8860020e
JB
2364static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2365{
2366 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2367 struct net_device *dev = info->user_ptr[1];
2368 struct wireless_dev *wdev = dev->ieee80211_ptr;
2369 struct cfg80211_beacon_data params;
2370 int err;
2371
2372 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2373 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2374 return -EOPNOTSUPP;
2375
2376 if (!rdev->ops->change_beacon)
2377 return -EOPNOTSUPP;
2378
2379 if (!wdev->beacon_interval)
2380 return -EINVAL;
2381
2382 err = nl80211_parse_beacon(info, &params);
2383 if (err)
2384 return err;
2385
2386 return rdev->ops->change_beacon(&rdev->wiphy, dev, &params);
2387}
2388
2389static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2390{
4c476991
JB
2391 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2392 struct net_device *dev = info->user_ptr[1];
56d1893d
JB
2393 struct wireless_dev *wdev = dev->ieee80211_ptr;
2394 int err;
ed1b6cc7 2395
8860020e 2396 if (!rdev->ops->stop_ap)
4c476991 2397 return -EOPNOTSUPP;
ed1b6cc7 2398
074ac8df 2399 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2400 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2401 return -EOPNOTSUPP;
3b85875a 2402
8860020e
JB
2403 if (!wdev->beacon_interval)
2404 return -ENOENT;
2405
2406 err = rdev->ops->stop_ap(&rdev->wiphy, dev);
56d1893d
JB
2407 if (!err)
2408 wdev->beacon_interval = 0;
2409 return err;
ed1b6cc7
JB
2410}
2411
5727ef1b
JB
2412static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2413 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2414 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2415 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2416 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2417 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2418 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2419};
2420
eccb8e8f 2421static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2422 enum nl80211_iftype iftype,
eccb8e8f 2423 struct station_parameters *params)
5727ef1b
JB
2424{
2425 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2426 struct nlattr *nla;
5727ef1b
JB
2427 int flag;
2428
eccb8e8f
JB
2429 /*
2430 * Try parsing the new attribute first so userspace
2431 * can specify both for older kernels.
2432 */
2433 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2434 if (nla) {
2435 struct nl80211_sta_flag_update *sta_flags;
2436
2437 sta_flags = nla_data(nla);
2438 params->sta_flags_mask = sta_flags->mask;
2439 params->sta_flags_set = sta_flags->set;
2440 if ((params->sta_flags_mask |
2441 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2442 return -EINVAL;
2443 return 0;
2444 }
2445
2446 /* if present, parse the old attribute */
5727ef1b 2447
eccb8e8f 2448 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2449 if (!nla)
2450 return 0;
2451
2452 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2453 nla, sta_flags_policy))
2454 return -EINVAL;
2455
bdd3ae3d
JB
2456 /*
2457 * Only allow certain flags for interface types so that
2458 * other attributes are silently ignored. Remember that
2459 * this is backward compatibility code with old userspace
2460 * and shouldn't be hit in other cases anyway.
2461 */
2462 switch (iftype) {
2463 case NL80211_IFTYPE_AP:
2464 case NL80211_IFTYPE_AP_VLAN:
2465 case NL80211_IFTYPE_P2P_GO:
2466 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2467 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2468 BIT(NL80211_STA_FLAG_WME) |
2469 BIT(NL80211_STA_FLAG_MFP);
2470 break;
2471 case NL80211_IFTYPE_P2P_CLIENT:
2472 case NL80211_IFTYPE_STATION:
2473 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2474 BIT(NL80211_STA_FLAG_TDLS_PEER);
2475 break;
2476 case NL80211_IFTYPE_MESH_POINT:
2477 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2478 BIT(NL80211_STA_FLAG_MFP) |
2479 BIT(NL80211_STA_FLAG_AUTHORIZED);
2480 default:
2481 return -EINVAL;
2482 }
5727ef1b 2483
3383b5a6
JB
2484 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2485 if (flags[flag]) {
eccb8e8f 2486 params->sta_flags_set |= (1<<flag);
5727ef1b 2487
3383b5a6
JB
2488 /* no longer support new API additions in old API */
2489 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2490 return -EINVAL;
2491 }
2492 }
2493
5727ef1b
JB
2494 return 0;
2495}
2496
c8dcfd8a
FF
2497static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2498 int attr)
2499{
2500 struct nlattr *rate;
2501 u16 bitrate;
2502
2503 rate = nla_nest_start(msg, attr);
2504 if (!rate)
2505 goto nla_put_failure;
2506
2507 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2508 bitrate = cfg80211_calculate_bitrate(info);
9360ffd1
DM
2509 if ((bitrate > 0 &&
2510 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate)) ||
2511 ((info->flags & RATE_INFO_FLAGS_MCS) &&
2512 nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs)) ||
2513 ((info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) &&
2514 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH)) ||
2515 ((info->flags & RATE_INFO_FLAGS_SHORT_GI) &&
2516 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)))
2517 goto nla_put_failure;
c8dcfd8a
FF
2518
2519 nla_nest_end(msg, rate);
2520 return true;
2521
2522nla_put_failure:
2523 return false;
2524}
2525
fd5b74dc 2526static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
66266b3a
JL
2527 int flags,
2528 struct cfg80211_registered_device *rdev,
2529 struct net_device *dev,
98b62183 2530 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2531{
2532 void *hdr;
f4263c98 2533 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2534
2535 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2536 if (!hdr)
2537 return -1;
2538
9360ffd1
DM
2539 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2540 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
2541 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
2542 goto nla_put_failure;
f5ea9120 2543
2ec600d6
LCC
2544 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2545 if (!sinfoattr)
fd5b74dc 2546 goto nla_put_failure;
9360ffd1
DM
2547 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
2548 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2549 sinfo->connected_time))
2550 goto nla_put_failure;
2551 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
2552 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2553 sinfo->inactive_time))
2554 goto nla_put_failure;
2555 if ((sinfo->filled & STATION_INFO_RX_BYTES) &&
2556 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
2557 sinfo->rx_bytes))
2558 goto nla_put_failure;
2559 if ((sinfo->filled & STATION_INFO_TX_BYTES) &&
2560 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
2561 sinfo->tx_bytes))
2562 goto nla_put_failure;
2563 if ((sinfo->filled & STATION_INFO_LLID) &&
2564 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
2565 goto nla_put_failure;
2566 if ((sinfo->filled & STATION_INFO_PLID) &&
2567 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
2568 goto nla_put_failure;
2569 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
2570 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
2571 sinfo->plink_state))
2572 goto nla_put_failure;
66266b3a
JL
2573 switch (rdev->wiphy.signal_type) {
2574 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
2575 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
2576 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
2577 sinfo->signal))
2578 goto nla_put_failure;
2579 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
2580 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2581 sinfo->signal_avg))
2582 goto nla_put_failure;
66266b3a
JL
2583 break;
2584 default:
2585 break;
2586 }
420e7fab 2587 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2588 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2589 NL80211_STA_INFO_TX_BITRATE))
2590 goto nla_put_failure;
2591 }
2592 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2593 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2594 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2595 goto nla_put_failure;
420e7fab 2596 }
9360ffd1
DM
2597 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
2598 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
2599 sinfo->rx_packets))
2600 goto nla_put_failure;
2601 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
2602 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
2603 sinfo->tx_packets))
2604 goto nla_put_failure;
2605 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
2606 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
2607 sinfo->tx_retries))
2608 goto nla_put_failure;
2609 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
2610 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
2611 sinfo->tx_failed))
2612 goto nla_put_failure;
2613 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
2614 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
2615 sinfo->beacon_loss_count))
2616 goto nla_put_failure;
f4263c98
PS
2617 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2618 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2619 if (!bss_param)
2620 goto nla_put_failure;
2621
9360ffd1
DM
2622 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
2623 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
2624 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
2625 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
2626 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
2627 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
2628 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2629 sinfo->bss_param.dtim_period) ||
2630 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2631 sinfo->bss_param.beacon_interval))
2632 goto nla_put_failure;
f4263c98
PS
2633
2634 nla_nest_end(msg, bss_param);
2635 }
9360ffd1
DM
2636 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
2637 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
2638 sizeof(struct nl80211_sta_flag_update),
2639 &sinfo->sta_flags))
2640 goto nla_put_failure;
7eab0f64
JL
2641 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
2642 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
2643 sinfo->t_offset))
2644 goto nla_put_failure;
2ec600d6 2645 nla_nest_end(msg, sinfoattr);
fd5b74dc 2646
9360ffd1
DM
2647 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
2648 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2649 sinfo->assoc_req_ies))
2650 goto nla_put_failure;
50d3dfb7 2651
fd5b74dc
JB
2652 return genlmsg_end(msg, hdr);
2653
2654 nla_put_failure:
bc3ed28c
TG
2655 genlmsg_cancel(msg, hdr);
2656 return -EMSGSIZE;
fd5b74dc
JB
2657}
2658
2ec600d6 2659static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2660 struct netlink_callback *cb)
2ec600d6 2661{
2ec600d6
LCC
2662 struct station_info sinfo;
2663 struct cfg80211_registered_device *dev;
bba95fef 2664 struct net_device *netdev;
2ec600d6 2665 u8 mac_addr[ETH_ALEN];
bba95fef 2666 int sta_idx = cb->args[1];
2ec600d6 2667 int err;
2ec600d6 2668
67748893
JB
2669 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2670 if (err)
2671 return err;
bba95fef
JB
2672
2673 if (!dev->ops->dump_station) {
eec60b03 2674 err = -EOPNOTSUPP;
bba95fef
JB
2675 goto out_err;
2676 }
2677
bba95fef 2678 while (1) {
f612cedf 2679 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2680 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2681 mac_addr, &sinfo);
2682 if (err == -ENOENT)
2683 break;
2684 if (err)
3b85875a 2685 goto out_err;
bba95fef
JB
2686
2687 if (nl80211_send_station(skb,
2688 NETLINK_CB(cb->skb).pid,
2689 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 2690 dev, netdev, mac_addr,
bba95fef
JB
2691 &sinfo) < 0)
2692 goto out;
2693
2694 sta_idx++;
2695 }
2696
2697
2698 out:
2699 cb->args[1] = sta_idx;
2700 err = skb->len;
bba95fef 2701 out_err:
67748893 2702 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2703
2704 return err;
2ec600d6 2705}
fd5b74dc 2706
5727ef1b
JB
2707static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2708{
4c476991
JB
2709 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2710 struct net_device *dev = info->user_ptr[1];
2ec600d6 2711 struct station_info sinfo;
fd5b74dc
JB
2712 struct sk_buff *msg;
2713 u8 *mac_addr = NULL;
4c476991 2714 int err;
fd5b74dc 2715
2ec600d6 2716 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2717
2718 if (!info->attrs[NL80211_ATTR_MAC])
2719 return -EINVAL;
2720
2721 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2722
4c476991
JB
2723 if (!rdev->ops->get_station)
2724 return -EOPNOTSUPP;
3b85875a 2725
4c476991 2726 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2727 if (err)
4c476991 2728 return err;
2ec600d6 2729
fd2120ca 2730 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2731 if (!msg)
4c476991 2732 return -ENOMEM;
fd5b74dc
JB
2733
2734 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
66266b3a 2735 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
2736 nlmsg_free(msg);
2737 return -ENOBUFS;
2738 }
3b85875a 2739
4c476991 2740 return genlmsg_reply(msg, info);
5727ef1b
JB
2741}
2742
2743/*
c258d2de 2744 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2745 */
80b99899
JB
2746static struct net_device *get_vlan(struct genl_info *info,
2747 struct cfg80211_registered_device *rdev)
5727ef1b 2748{
463d0183 2749 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
2750 struct net_device *v;
2751 int ret;
2752
2753 if (!vlanattr)
2754 return NULL;
2755
2756 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
2757 if (!v)
2758 return ERR_PTR(-ENODEV);
2759
2760 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
2761 ret = -EINVAL;
2762 goto error;
5727ef1b 2763 }
80b99899
JB
2764
2765 if (!netif_running(v)) {
2766 ret = -ENETDOWN;
2767 goto error;
2768 }
2769
2770 return v;
2771 error:
2772 dev_put(v);
2773 return ERR_PTR(ret);
5727ef1b
JB
2774}
2775
2776static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2777{
4c476991 2778 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2779 int err;
4c476991 2780 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2781 struct station_parameters params;
2782 u8 *mac_addr = NULL;
2783
2784 memset(&params, 0, sizeof(params));
2785
2786 params.listen_interval = -1;
57cf8043 2787 params.plink_state = -1;
5727ef1b
JB
2788
2789 if (info->attrs[NL80211_ATTR_STA_AID])
2790 return -EINVAL;
2791
2792 if (!info->attrs[NL80211_ATTR_MAC])
2793 return -EINVAL;
2794
2795 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2796
2797 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2798 params.supported_rates =
2799 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2800 params.supported_rates_len =
2801 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2802 }
2803
2804 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2805 params.listen_interval =
2806 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2807
36aedc90
JM
2808 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2809 params.ht_capa =
2810 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2811
bdd90d5e
JB
2812 if (!rdev->ops->change_station)
2813 return -EOPNOTSUPP;
2814
bdd3ae3d 2815 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2816 return -EINVAL;
2817
2ec600d6
LCC
2818 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2819 params.plink_action =
2820 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2821
9c3990aa
JC
2822 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2823 params.plink_state =
2824 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2825
a97f4424
JB
2826 switch (dev->ieee80211_ptr->iftype) {
2827 case NL80211_IFTYPE_AP:
2828 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2829 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2830 /* disallow mesh-specific things */
2831 if (params.plink_action)
bdd90d5e
JB
2832 return -EINVAL;
2833
2834 /* TDLS can't be set, ... */
2835 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2836 return -EINVAL;
2837 /*
2838 * ... but don't bother the driver with it. This works around
2839 * a hostapd/wpa_supplicant issue -- it always includes the
2840 * TLDS_PEER flag in the mask even for AP mode.
2841 */
2842 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2843
2844 /* accept only the listed bits */
2845 if (params.sta_flags_mask &
2846 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2847 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2848 BIT(NL80211_STA_FLAG_WME) |
2849 BIT(NL80211_STA_FLAG_MFP)))
2850 return -EINVAL;
2851
2852 /* must be last in here for error handling */
2853 params.vlan = get_vlan(info, rdev);
2854 if (IS_ERR(params.vlan))
2855 return PTR_ERR(params.vlan);
a97f4424 2856 break;
074ac8df 2857 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 2858 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
2859 /*
2860 * Don't allow userspace to change the TDLS_PEER flag,
2861 * but silently ignore attempts to change it since we
2862 * don't have state here to verify that it doesn't try
2863 * to change the flag.
2864 */
2865 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
2866 /* fall through */
2867 case NL80211_IFTYPE_ADHOC:
2868 /* disallow things sta doesn't support */
2869 if (params.plink_action)
2870 return -EINVAL;
2871 if (params.ht_capa)
2872 return -EINVAL;
2873 if (params.listen_interval >= 0)
2874 return -EINVAL;
bdd90d5e
JB
2875 /* reject any changes other than AUTHORIZED */
2876 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2877 return -EINVAL;
a97f4424
JB
2878 break;
2879 case NL80211_IFTYPE_MESH_POINT:
2880 /* disallow things mesh doesn't support */
2881 if (params.vlan)
bdd90d5e 2882 return -EINVAL;
a97f4424 2883 if (params.ht_capa)
bdd90d5e 2884 return -EINVAL;
a97f4424 2885 if (params.listen_interval >= 0)
bdd90d5e
JB
2886 return -EINVAL;
2887 /*
2888 * No special handling for TDLS here -- the userspace
2889 * mesh code doesn't have this bug.
2890 */
b39c48fa
JC
2891 if (params.sta_flags_mask &
2892 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2893 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2894 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 2895 return -EINVAL;
a97f4424
JB
2896 break;
2897 default:
bdd90d5e 2898 return -EOPNOTSUPP;
034d655e
JB
2899 }
2900
bdd90d5e 2901 /* be aware of params.vlan when changing code here */
5727ef1b 2902
79c97e97 2903 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 2904
5727ef1b
JB
2905 if (params.vlan)
2906 dev_put(params.vlan);
3b85875a 2907
5727ef1b
JB
2908 return err;
2909}
2910
c75786c9
EP
2911static struct nla_policy
2912nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2913 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2914 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2915};
2916
5727ef1b
JB
2917static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2918{
4c476991 2919 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2920 int err;
4c476991 2921 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2922 struct station_parameters params;
2923 u8 *mac_addr = NULL;
2924
2925 memset(&params, 0, sizeof(params));
2926
2927 if (!info->attrs[NL80211_ATTR_MAC])
2928 return -EINVAL;
2929
5727ef1b
JB
2930 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2931 return -EINVAL;
2932
2933 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2934 return -EINVAL;
2935
0e956c13
TLSC
2936 if (!info->attrs[NL80211_ATTR_STA_AID])
2937 return -EINVAL;
2938
5727ef1b
JB
2939 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2940 params.supported_rates =
2941 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2942 params.supported_rates_len =
2943 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2944 params.listen_interval =
2945 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2946
0e956c13
TLSC
2947 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2948 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2949 return -EINVAL;
51b50fbe 2950
36aedc90
JM
2951 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2952 params.ht_capa =
2953 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2954
96b78dff
JC
2955 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2956 params.plink_action =
2957 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2958
bdd90d5e
JB
2959 if (!rdev->ops->add_station)
2960 return -EOPNOTSUPP;
2961
bdd3ae3d 2962 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2963 return -EINVAL;
2964
bdd90d5e
JB
2965 switch (dev->ieee80211_ptr->iftype) {
2966 case NL80211_IFTYPE_AP:
2967 case NL80211_IFTYPE_AP_VLAN:
2968 case NL80211_IFTYPE_P2P_GO:
2969 /* parse WME attributes if sta is WME capable */
2970 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2971 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
2972 info->attrs[NL80211_ATTR_STA_WME]) {
2973 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2974 struct nlattr *nla;
2975
2976 nla = info->attrs[NL80211_ATTR_STA_WME];
2977 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2978 nl80211_sta_wme_policy);
2979 if (err)
2980 return err;
2981
2982 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2983 params.uapsd_queues =
2984 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
2985 if (params.uapsd_queues &
2986 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2987 return -EINVAL;
c75786c9 2988
bdd90d5e
JB
2989 if (tb[NL80211_STA_WME_MAX_SP])
2990 params.max_sp =
2991 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 2992
bdd90d5e
JB
2993 if (params.max_sp &
2994 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2995 return -EINVAL;
4319e193 2996
bdd90d5e
JB
2997 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
2998 }
2999 /* TDLS peers cannot be added */
3000 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3001 return -EINVAL;
bdd90d5e
JB
3002 /* but don't bother the driver with it */
3003 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3004
bdd90d5e
JB
3005 /* must be last in here for error handling */
3006 params.vlan = get_vlan(info, rdev);
3007 if (IS_ERR(params.vlan))
3008 return PTR_ERR(params.vlan);
3009 break;
3010 case NL80211_IFTYPE_MESH_POINT:
3011 /* TDLS peers cannot be added */
3012 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3013 return -EINVAL;
3014 break;
3015 case NL80211_IFTYPE_STATION:
3016 /* Only TDLS peers can be added */
3017 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3018 return -EINVAL;
3019 /* Can only add if TDLS ... */
3020 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3021 return -EOPNOTSUPP;
3022 /* ... with external setup is supported */
3023 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3024 return -EOPNOTSUPP;
3025 break;
3026 default:
3027 return -EOPNOTSUPP;
c75786c9
EP
3028 }
3029
bdd90d5e 3030 /* be aware of params.vlan when changing code here */
5727ef1b 3031
79c97e97 3032 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 3033
5727ef1b
JB
3034 if (params.vlan)
3035 dev_put(params.vlan);
5727ef1b
JB
3036 return err;
3037}
3038
3039static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3040{
4c476991
JB
3041 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3042 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3043 u8 *mac_addr = NULL;
3044
3045 if (info->attrs[NL80211_ATTR_MAC])
3046 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3047
e80cf853 3048 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3049 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3050 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3051 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3052 return -EINVAL;
5727ef1b 3053
4c476991
JB
3054 if (!rdev->ops->del_station)
3055 return -EOPNOTSUPP;
3b85875a 3056
4c476991 3057 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
3058}
3059
2ec600d6
LCC
3060static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
3061 int flags, struct net_device *dev,
3062 u8 *dst, u8 *next_hop,
3063 struct mpath_info *pinfo)
3064{
3065 void *hdr;
3066 struct nlattr *pinfoattr;
3067
3068 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
3069 if (!hdr)
3070 return -1;
3071
9360ffd1
DM
3072 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3073 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3074 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3075 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3076 goto nla_put_failure;
f5ea9120 3077
2ec600d6
LCC
3078 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3079 if (!pinfoattr)
3080 goto nla_put_failure;
9360ffd1
DM
3081 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3082 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3083 pinfo->frame_qlen))
3084 goto nla_put_failure;
3085 if (((pinfo->filled & MPATH_INFO_SN) &&
3086 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3087 ((pinfo->filled & MPATH_INFO_METRIC) &&
3088 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3089 pinfo->metric)) ||
3090 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3091 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3092 pinfo->exptime)) ||
3093 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3094 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3095 pinfo->flags)) ||
3096 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3097 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3098 pinfo->discovery_timeout)) ||
3099 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3100 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3101 pinfo->discovery_retries)))
3102 goto nla_put_failure;
2ec600d6
LCC
3103
3104 nla_nest_end(msg, pinfoattr);
3105
3106 return genlmsg_end(msg, hdr);
3107
3108 nla_put_failure:
bc3ed28c
TG
3109 genlmsg_cancel(msg, hdr);
3110 return -EMSGSIZE;
2ec600d6
LCC
3111}
3112
3113static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3114 struct netlink_callback *cb)
2ec600d6 3115{
2ec600d6
LCC
3116 struct mpath_info pinfo;
3117 struct cfg80211_registered_device *dev;
bba95fef 3118 struct net_device *netdev;
2ec600d6
LCC
3119 u8 dst[ETH_ALEN];
3120 u8 next_hop[ETH_ALEN];
bba95fef 3121 int path_idx = cb->args[1];
2ec600d6 3122 int err;
2ec600d6 3123
67748893
JB
3124 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3125 if (err)
3126 return err;
bba95fef
JB
3127
3128 if (!dev->ops->dump_mpath) {
eec60b03 3129 err = -EOPNOTSUPP;
bba95fef
JB
3130 goto out_err;
3131 }
3132
eec60b03
JM
3133 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3134 err = -EOPNOTSUPP;
0448b5fc 3135 goto out_err;
eec60b03
JM
3136 }
3137
bba95fef
JB
3138 while (1) {
3139 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
3140 dst, next_hop, &pinfo);
3141 if (err == -ENOENT)
2ec600d6 3142 break;
bba95fef 3143 if (err)
3b85875a 3144 goto out_err;
2ec600d6 3145
bba95fef
JB
3146 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
3147 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3148 netdev, dst, next_hop,
3149 &pinfo) < 0)
3150 goto out;
2ec600d6 3151
bba95fef 3152 path_idx++;
2ec600d6 3153 }
2ec600d6 3154
2ec600d6 3155
bba95fef
JB
3156 out:
3157 cb->args[1] = path_idx;
3158 err = skb->len;
bba95fef 3159 out_err:
67748893 3160 nl80211_finish_netdev_dump(dev);
bba95fef 3161 return err;
2ec600d6
LCC
3162}
3163
3164static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3165{
4c476991 3166 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3167 int err;
4c476991 3168 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3169 struct mpath_info pinfo;
3170 struct sk_buff *msg;
3171 u8 *dst = NULL;
3172 u8 next_hop[ETH_ALEN];
3173
3174 memset(&pinfo, 0, sizeof(pinfo));
3175
3176 if (!info->attrs[NL80211_ATTR_MAC])
3177 return -EINVAL;
3178
3179 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3180
4c476991
JB
3181 if (!rdev->ops->get_mpath)
3182 return -EOPNOTSUPP;
2ec600d6 3183
4c476991
JB
3184 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3185 return -EOPNOTSUPP;
eec60b03 3186
79c97e97 3187 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 3188 if (err)
4c476991 3189 return err;
2ec600d6 3190
fd2120ca 3191 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3192 if (!msg)
4c476991 3193 return -ENOMEM;
2ec600d6
LCC
3194
3195 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
3196 dev, dst, next_hop, &pinfo) < 0) {
3197 nlmsg_free(msg);
3198 return -ENOBUFS;
3199 }
3b85875a 3200
4c476991 3201 return genlmsg_reply(msg, info);
2ec600d6
LCC
3202}
3203
3204static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3205{
4c476991
JB
3206 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3207 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3208 u8 *dst = NULL;
3209 u8 *next_hop = NULL;
3210
3211 if (!info->attrs[NL80211_ATTR_MAC])
3212 return -EINVAL;
3213
3214 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3215 return -EINVAL;
3216
3217 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3218 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3219
4c476991
JB
3220 if (!rdev->ops->change_mpath)
3221 return -EOPNOTSUPP;
35a8efe1 3222
4c476991
JB
3223 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3224 return -EOPNOTSUPP;
2ec600d6 3225
4c476991 3226 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 3227}
4c476991 3228
2ec600d6
LCC
3229static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3230{
4c476991
JB
3231 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3232 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3233 u8 *dst = NULL;
3234 u8 *next_hop = NULL;
3235
3236 if (!info->attrs[NL80211_ATTR_MAC])
3237 return -EINVAL;
3238
3239 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3240 return -EINVAL;
3241
3242 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3243 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3244
4c476991
JB
3245 if (!rdev->ops->add_mpath)
3246 return -EOPNOTSUPP;
35a8efe1 3247
4c476991
JB
3248 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3249 return -EOPNOTSUPP;
2ec600d6 3250
4c476991 3251 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
3252}
3253
3254static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3255{
4c476991
JB
3256 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3257 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3258 u8 *dst = NULL;
3259
3260 if (info->attrs[NL80211_ATTR_MAC])
3261 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3262
4c476991
JB
3263 if (!rdev->ops->del_mpath)
3264 return -EOPNOTSUPP;
3b85875a 3265
4c476991 3266 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
3267}
3268
9f1ba906
JM
3269static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3270{
4c476991
JB
3271 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3272 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3273 struct bss_parameters params;
3274
3275 memset(&params, 0, sizeof(params));
3276 /* default to not changing parameters */
3277 params.use_cts_prot = -1;
3278 params.use_short_preamble = -1;
3279 params.use_short_slot_time = -1;
fd8aaaf3 3280 params.ap_isolate = -1;
50b12f59 3281 params.ht_opmode = -1;
9f1ba906
JM
3282
3283 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3284 params.use_cts_prot =
3285 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3286 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3287 params.use_short_preamble =
3288 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3289 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3290 params.use_short_slot_time =
3291 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3292 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3293 params.basic_rates =
3294 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3295 params.basic_rates_len =
3296 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3297 }
fd8aaaf3
FF
3298 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3299 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3300 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3301 params.ht_opmode =
3302 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3303
4c476991
JB
3304 if (!rdev->ops->change_bss)
3305 return -EOPNOTSUPP;
9f1ba906 3306
074ac8df 3307 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3308 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3309 return -EOPNOTSUPP;
3b85875a 3310
4c476991 3311 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
3312}
3313
b54452b0 3314static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3315 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3316 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3317 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3318 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3319 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3320 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3321};
3322
3323static int parse_reg_rule(struct nlattr *tb[],
3324 struct ieee80211_reg_rule *reg_rule)
3325{
3326 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3327 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3328
3329 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3330 return -EINVAL;
3331 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3332 return -EINVAL;
3333 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3334 return -EINVAL;
3335 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3336 return -EINVAL;
3337 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3338 return -EINVAL;
3339
3340 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3341
3342 freq_range->start_freq_khz =
3343 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3344 freq_range->end_freq_khz =
3345 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3346 freq_range->max_bandwidth_khz =
3347 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3348
3349 power_rule->max_eirp =
3350 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3351
3352 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3353 power_rule->max_antenna_gain =
3354 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3355
3356 return 0;
3357}
3358
3359static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3360{
3361 int r;
3362 char *data = NULL;
3363
80778f18
LR
3364 /*
3365 * You should only get this when cfg80211 hasn't yet initialized
3366 * completely when built-in to the kernel right between the time
3367 * window between nl80211_init() and regulatory_init(), if that is
3368 * even possible.
3369 */
3370 mutex_lock(&cfg80211_mutex);
3371 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3372 mutex_unlock(&cfg80211_mutex);
3373 return -EINPROGRESS;
80778f18 3374 }
fe33eb39 3375 mutex_unlock(&cfg80211_mutex);
80778f18 3376
fe33eb39
LR
3377 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3378 return -EINVAL;
b2e1b302
LR
3379
3380 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3381
fe33eb39
LR
3382 r = regulatory_hint_user(data);
3383
b2e1b302
LR
3384 return r;
3385}
3386
24bdd9f4 3387static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3388 struct genl_info *info)
93da9cc1 3389{
4c476991 3390 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3391 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3392 struct wireless_dev *wdev = dev->ieee80211_ptr;
3393 struct mesh_config cur_params;
3394 int err = 0;
93da9cc1 3395 void *hdr;
3396 struct nlattr *pinfoattr;
3397 struct sk_buff *msg;
3398
29cbe68c
JB
3399 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3400 return -EOPNOTSUPP;
3401
24bdd9f4 3402 if (!rdev->ops->get_mesh_config)
4c476991 3403 return -EOPNOTSUPP;
f3f92586 3404
29cbe68c
JB
3405 wdev_lock(wdev);
3406 /* If not connected, get default parameters */
3407 if (!wdev->mesh_id_len)
3408 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3409 else
24bdd9f4 3410 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3411 &cur_params);
3412 wdev_unlock(wdev);
3413
93da9cc1 3414 if (err)
4c476991 3415 return err;
93da9cc1 3416
3417 /* Draw up a netlink message to send back */
fd2120ca 3418 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3419 if (!msg)
3420 return -ENOMEM;
93da9cc1 3421 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3422 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3423 if (!hdr)
efe1cf0c 3424 goto out;
24bdd9f4 3425 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3426 if (!pinfoattr)
3427 goto nla_put_failure;
9360ffd1
DM
3428 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3429 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3430 cur_params.dot11MeshRetryTimeout) ||
3431 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3432 cur_params.dot11MeshConfirmTimeout) ||
3433 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3434 cur_params.dot11MeshHoldingTimeout) ||
3435 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3436 cur_params.dot11MeshMaxPeerLinks) ||
3437 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
3438 cur_params.dot11MeshMaxRetries) ||
3439 nla_put_u8(msg, NL80211_MESHCONF_TTL,
3440 cur_params.dot11MeshTTL) ||
3441 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3442 cur_params.element_ttl) ||
3443 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3444 cur_params.auto_open_plinks) ||
7eab0f64
JL
3445 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3446 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
3447 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3448 cur_params.dot11MeshHWMPmaxPREQretries) ||
3449 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3450 cur_params.path_refresh_time) ||
3451 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3452 cur_params.min_discovery_timeout) ||
3453 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3454 cur_params.dot11MeshHWMPactivePathTimeout) ||
3455 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3456 cur_params.dot11MeshHWMPpreqMinInterval) ||
3457 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3458 cur_params.dot11MeshHWMPperrMinInterval) ||
3459 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3460 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
3461 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3462 cur_params.dot11MeshHWMPRootMode) ||
3463 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3464 cur_params.dot11MeshHWMPRannInterval) ||
3465 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3466 cur_params.dot11MeshGateAnnouncementProtocol) ||
3467 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
3468 cur_params.dot11MeshForwarding) ||
3469 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
3470 cur_params.rssi_threshold) ||
3471 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
3472 cur_params.ht_opmode) ||
3473 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
3474 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
3475 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
3476 cur_params.dot11MeshHWMProotInterval))
9360ffd1 3477 goto nla_put_failure;
93da9cc1 3478 nla_nest_end(msg, pinfoattr);
3479 genlmsg_end(msg, hdr);
4c476991 3480 return genlmsg_reply(msg, info);
93da9cc1 3481
3b85875a 3482 nla_put_failure:
93da9cc1 3483 genlmsg_cancel(msg, hdr);
efe1cf0c 3484 out:
d080e275 3485 nlmsg_free(msg);
4c476991 3486 return -ENOBUFS;
93da9cc1 3487}
3488
b54452b0 3489static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3490 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3491 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3492 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3493 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3494 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3495 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3496 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3497 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 3498 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 3499 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3500 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3501 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3502 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3503 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3504 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3505 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3506 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3507 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3508 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3509 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
3510 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
3511 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
3512 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
3513 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3514};
3515
c80d545d
JC
3516static const struct nla_policy
3517 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 3518 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
3519 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3520 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3521 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3522 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 3523 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3524 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3525};
3526
24bdd9f4 3527static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3528 struct mesh_config *cfg,
3529 u32 *mask_out)
93da9cc1 3530{
93da9cc1 3531 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3532 u32 mask = 0;
93da9cc1 3533
bd90fdcc
JB
3534#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3535do {\
3536 if (table[attr_num]) {\
3537 cfg->param = nla_fn(table[attr_num]); \
3538 mask |= (1 << (attr_num - 1)); \
3539 } \
3540} while (0);\
3541
3542
24bdd9f4 3543 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3544 return -EINVAL;
3545 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3546 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3547 nl80211_meshconf_params_policy))
93da9cc1 3548 return -EINVAL;
3549
93da9cc1 3550 /* This makes sure that there aren't more than 32 mesh config
3551 * parameters (otherwise our bitfield scheme would not work.) */
3552 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3553
3554 /* Fill in the params struct */
93da9cc1 3555 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
a4f606ea
CYY
3556 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
3557 nla_get_u16);
93da9cc1 3558 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
a4f606ea
CYY
3559 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3560 nla_get_u16);
93da9cc1 3561 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
a4f606ea
CYY
3562 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
3563 nla_get_u16);
93da9cc1 3564 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
a4f606ea
CYY
3565 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
3566 nla_get_u16);
93da9cc1 3567 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
a4f606ea
CYY
3568 mask, NL80211_MESHCONF_MAX_RETRIES,
3569 nla_get_u8);
93da9cc1 3570 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
a4f606ea 3571 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21 3572 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
a4f606ea
CYY
3573 mask, NL80211_MESHCONF_ELEMENT_TTL,
3574 nla_get_u8);
93da9cc1 3575 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
a4f606ea
CYY
3576 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3577 nla_get_u8);
3578 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, mask,
3579 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3580 nla_get_u32);
93da9cc1 3581 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
a4f606ea
CYY
3582 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3583 nla_get_u8);
93da9cc1 3584 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
a4f606ea
CYY
3585 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
3586 nla_get_u32);
93da9cc1 3587 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
a4f606ea
CYY
3588 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3589 nla_get_u16);
3590 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, mask,
3591 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3592 nla_get_u32);
93da9cc1 3593 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
a4f606ea
CYY
3594 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3595 nla_get_u16);
dca7e943 3596 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
a4f606ea
CYY
3597 mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3598 nla_get_u16);
0507e159 3599 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
3600 dot11MeshHWMPnetDiameterTraversalTime, mask,
3601 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3602 nla_get_u16);
3603 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
3604 NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
3605 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
3606 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3607 nla_get_u16);
16dd7267 3608 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
3609 dot11MeshGateAnnouncementProtocol, mask,
3610 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3611 nla_get_u8);
94f90656 3612 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
a4f606ea
CYY
3613 mask, NL80211_MESHCONF_FORWARDING,
3614 nla_get_u8);
55335137 3615 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
a4f606ea
CYY
3616 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
3617 nla_get_u32);
70c33eaa 3618 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode,
a4f606ea 3619 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
3620 nla_get_u16);
3621 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
3622 mask,
3623 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
3624 nla_get_u32);
3625 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval,
3626 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
a4f606ea 3627 nla_get_u16);
bd90fdcc
JB
3628 if (mask_out)
3629 *mask_out = mask;
c80d545d 3630
bd90fdcc
JB
3631 return 0;
3632
3633#undef FILL_IN_MESH_PARAM_IF_SET
3634}
3635
c80d545d
JC
3636static int nl80211_parse_mesh_setup(struct genl_info *info,
3637 struct mesh_setup *setup)
3638{
3639 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3640
3641 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3642 return -EINVAL;
3643 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3644 info->attrs[NL80211_ATTR_MESH_SETUP],
3645 nl80211_mesh_setup_params_policy))
3646 return -EINVAL;
3647
d299a1f2
JC
3648 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
3649 setup->sync_method =
3650 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
3651 IEEE80211_SYNC_METHOD_VENDOR :
3652 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
3653
c80d545d
JC
3654 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3655 setup->path_sel_proto =
3656 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3657 IEEE80211_PATH_PROTOCOL_VENDOR :
3658 IEEE80211_PATH_PROTOCOL_HWMP;
3659
3660 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3661 setup->path_metric =
3662 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3663 IEEE80211_PATH_METRIC_VENDOR :
3664 IEEE80211_PATH_METRIC_AIRTIME;
3665
581a8b0f
JC
3666
3667 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3668 struct nlattr *ieattr =
581a8b0f 3669 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3670 if (!is_valid_ie_attr(ieattr))
3671 return -EINVAL;
581a8b0f
JC
3672 setup->ie = nla_data(ieattr);
3673 setup->ie_len = nla_len(ieattr);
c80d545d 3674 }
b130e5ce
JC
3675 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3676 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3677
3678 return 0;
3679}
3680
24bdd9f4 3681static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3682 struct genl_info *info)
bd90fdcc
JB
3683{
3684 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3685 struct net_device *dev = info->user_ptr[1];
29cbe68c 3686 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3687 struct mesh_config cfg;
3688 u32 mask;
3689 int err;
3690
29cbe68c
JB
3691 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3692 return -EOPNOTSUPP;
3693
24bdd9f4 3694 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3695 return -EOPNOTSUPP;
3696
24bdd9f4 3697 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3698 if (err)
3699 return err;
3700
29cbe68c
JB
3701 wdev_lock(wdev);
3702 if (!wdev->mesh_id_len)
3703 err = -ENOLINK;
3704
3705 if (!err)
24bdd9f4 3706 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3707 mask, &cfg);
3708
3709 wdev_unlock(wdev);
3710
3711 return err;
93da9cc1 3712}
3713
f130347c
LR
3714static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3715{
3716 struct sk_buff *msg;
3717 void *hdr = NULL;
3718 struct nlattr *nl_reg_rules;
3719 unsigned int i;
3720 int err = -EINVAL;
3721
a1794390 3722 mutex_lock(&cfg80211_mutex);
f130347c
LR
3723
3724 if (!cfg80211_regdomain)
3725 goto out;
3726
fd2120ca 3727 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3728 if (!msg) {
3729 err = -ENOBUFS;
3730 goto out;
3731 }
3732
3733 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3734 NL80211_CMD_GET_REG);
3735 if (!hdr)
efe1cf0c 3736 goto put_failure;
f130347c 3737
9360ffd1
DM
3738 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
3739 cfg80211_regdomain->alpha2) ||
3740 (cfg80211_regdomain->dfs_region &&
3741 nla_put_u8(msg, NL80211_ATTR_DFS_REGION,
3742 cfg80211_regdomain->dfs_region)))
3743 goto nla_put_failure;
f130347c
LR
3744
3745 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3746 if (!nl_reg_rules)
3747 goto nla_put_failure;
3748
3749 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3750 struct nlattr *nl_reg_rule;
3751 const struct ieee80211_reg_rule *reg_rule;
3752 const struct ieee80211_freq_range *freq_range;
3753 const struct ieee80211_power_rule *power_rule;
3754
3755 reg_rule = &cfg80211_regdomain->reg_rules[i];
3756 freq_range = &reg_rule->freq_range;
3757 power_rule = &reg_rule->power_rule;
3758
3759 nl_reg_rule = nla_nest_start(msg, i);
3760 if (!nl_reg_rule)
3761 goto nla_put_failure;
3762
9360ffd1
DM
3763 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3764 reg_rule->flags) ||
3765 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
3766 freq_range->start_freq_khz) ||
3767 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
3768 freq_range->end_freq_khz) ||
3769 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3770 freq_range->max_bandwidth_khz) ||
3771 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3772 power_rule->max_antenna_gain) ||
3773 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3774 power_rule->max_eirp))
3775 goto nla_put_failure;
f130347c
LR
3776
3777 nla_nest_end(msg, nl_reg_rule);
3778 }
3779
3780 nla_nest_end(msg, nl_reg_rules);
3781
3782 genlmsg_end(msg, hdr);
134e6375 3783 err = genlmsg_reply(msg, info);
f130347c
LR
3784 goto out;
3785
3786nla_put_failure:
3787 genlmsg_cancel(msg, hdr);
efe1cf0c 3788put_failure:
d080e275 3789 nlmsg_free(msg);
f130347c
LR
3790 err = -EMSGSIZE;
3791out:
a1794390 3792 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3793 return err;
3794}
3795
b2e1b302
LR
3796static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3797{
3798 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3799 struct nlattr *nl_reg_rule;
3800 char *alpha2 = NULL;
3801 int rem_reg_rules = 0, r = 0;
3802 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 3803 u8 dfs_region = 0;
b2e1b302
LR
3804 struct ieee80211_regdomain *rd = NULL;
3805
3806 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3807 return -EINVAL;
3808
3809 if (!info->attrs[NL80211_ATTR_REG_RULES])
3810 return -EINVAL;
3811
3812 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3813
8b60b078
LR
3814 if (info->attrs[NL80211_ATTR_DFS_REGION])
3815 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
3816
b2e1b302
LR
3817 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3818 rem_reg_rules) {
3819 num_rules++;
3820 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3821 return -EINVAL;
b2e1b302
LR
3822 }
3823
61405e97
LR
3824 mutex_lock(&cfg80211_mutex);
3825
d0e18f83
LR
3826 if (!reg_is_valid_request(alpha2)) {
3827 r = -EINVAL;
3828 goto bad_reg;
3829 }
b2e1b302
LR
3830
3831 size_of_regd = sizeof(struct ieee80211_regdomain) +
3832 (num_rules * sizeof(struct ieee80211_reg_rule));
3833
3834 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3835 if (!rd) {
3836 r = -ENOMEM;
3837 goto bad_reg;
3838 }
b2e1b302
LR
3839
3840 rd->n_reg_rules = num_rules;
3841 rd->alpha2[0] = alpha2[0];
3842 rd->alpha2[1] = alpha2[1];
3843
8b60b078
LR
3844 /*
3845 * Disable DFS master mode if the DFS region was
3846 * not supported or known on this kernel.
3847 */
3848 if (reg_supported_dfs_region(dfs_region))
3849 rd->dfs_region = dfs_region;
3850
b2e1b302
LR
3851 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3852 rem_reg_rules) {
3853 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3854 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3855 reg_rule_policy);
3856 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3857 if (r)
3858 goto bad_reg;
3859
3860 rule_idx++;
3861
d0e18f83
LR
3862 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3863 r = -EINVAL;
b2e1b302 3864 goto bad_reg;
d0e18f83 3865 }
b2e1b302
LR
3866 }
3867
3868 BUG_ON(rule_idx != num_rules);
3869
b2e1b302 3870 r = set_regdom(rd);
61405e97 3871
a1794390 3872 mutex_unlock(&cfg80211_mutex);
d0e18f83 3873
b2e1b302
LR
3874 return r;
3875
d2372b31 3876 bad_reg:
61405e97 3877 mutex_unlock(&cfg80211_mutex);
b2e1b302 3878 kfree(rd);
d0e18f83 3879 return r;
b2e1b302
LR
3880}
3881
83f5e2cf
JB
3882static int validate_scan_freqs(struct nlattr *freqs)
3883{
3884 struct nlattr *attr1, *attr2;
3885 int n_channels = 0, tmp1, tmp2;
3886
3887 nla_for_each_nested(attr1, freqs, tmp1) {
3888 n_channels++;
3889 /*
3890 * Some hardware has a limited channel list for
3891 * scanning, and it is pretty much nonsensical
3892 * to scan for a channel twice, so disallow that
3893 * and don't require drivers to check that the
3894 * channel list they get isn't longer than what
3895 * they can scan, as long as they can scan all
3896 * the channels they registered at once.
3897 */
3898 nla_for_each_nested(attr2, freqs, tmp2)
3899 if (attr1 != attr2 &&
3900 nla_get_u32(attr1) == nla_get_u32(attr2))
3901 return 0;
3902 }
3903
3904 return n_channels;
3905}
3906
2a519311
JB
3907static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3908{
4c476991
JB
3909 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3910 struct net_device *dev = info->user_ptr[1];
2a519311 3911 struct cfg80211_scan_request *request;
2a519311
JB
3912 struct nlattr *attr;
3913 struct wiphy *wiphy;
83f5e2cf 3914 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 3915 size_t ie_len;
2a519311 3916
f4a11bb0
JB
3917 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3918 return -EINVAL;
3919
79c97e97 3920 wiphy = &rdev->wiphy;
2a519311 3921
4c476991
JB
3922 if (!rdev->ops->scan)
3923 return -EOPNOTSUPP;
2a519311 3924
4c476991
JB
3925 if (rdev->scan_req)
3926 return -EBUSY;
2a519311
JB
3927
3928 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3929 n_channels = validate_scan_freqs(
3930 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3931 if (!n_channels)
3932 return -EINVAL;
2a519311 3933 } else {
34850ab2 3934 enum ieee80211_band band;
83f5e2cf
JB
3935 n_channels = 0;
3936
2a519311
JB
3937 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3938 if (wiphy->bands[band])
3939 n_channels += wiphy->bands[band]->n_channels;
3940 }
3941
3942 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3943 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3944 n_ssids++;
3945
4c476991
JB
3946 if (n_ssids > wiphy->max_scan_ssids)
3947 return -EINVAL;
2a519311 3948
70692ad2
JM
3949 if (info->attrs[NL80211_ATTR_IE])
3950 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3951 else
3952 ie_len = 0;
3953
4c476991
JB
3954 if (ie_len > wiphy->max_scan_ie_len)
3955 return -EINVAL;
18a83659 3956
2a519311 3957 request = kzalloc(sizeof(*request)
a2cd43c5
LC
3958 + sizeof(*request->ssids) * n_ssids
3959 + sizeof(*request->channels) * n_channels
70692ad2 3960 + ie_len, GFP_KERNEL);
4c476991
JB
3961 if (!request)
3962 return -ENOMEM;
2a519311 3963
2a519311 3964 if (n_ssids)
5ba63533 3965 request->ssids = (void *)&request->channels[n_channels];
2a519311 3966 request->n_ssids = n_ssids;
70692ad2
JM
3967 if (ie_len) {
3968 if (request->ssids)
3969 request->ie = (void *)(request->ssids + n_ssids);
3970 else
3971 request->ie = (void *)(request->channels + n_channels);
3972 }
2a519311 3973
584991dc 3974 i = 0;
2a519311
JB
3975 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3976 /* user specified, bail out if channel not found */
2a519311 3977 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3978 struct ieee80211_channel *chan;
3979
3980 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3981
3982 if (!chan) {
2a519311
JB
3983 err = -EINVAL;
3984 goto out_free;
3985 }
584991dc
JB
3986
3987 /* ignore disabled channels */
3988 if (chan->flags & IEEE80211_CHAN_DISABLED)
3989 continue;
3990
3991 request->channels[i] = chan;
2a519311
JB
3992 i++;
3993 }
3994 } else {
34850ab2
JB
3995 enum ieee80211_band band;
3996
2a519311 3997 /* all channels */
2a519311
JB
3998 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3999 int j;
4000 if (!wiphy->bands[band])
4001 continue;
4002 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4003 struct ieee80211_channel *chan;
4004
4005 chan = &wiphy->bands[band]->channels[j];
4006
4007 if (chan->flags & IEEE80211_CHAN_DISABLED)
4008 continue;
4009
4010 request->channels[i] = chan;
2a519311
JB
4011 i++;
4012 }
4013 }
4014 }
4015
584991dc
JB
4016 if (!i) {
4017 err = -EINVAL;
4018 goto out_free;
4019 }
4020
4021 request->n_channels = i;
4022
2a519311
JB
4023 i = 0;
4024 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4025 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4026 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4027 err = -EINVAL;
4028 goto out_free;
4029 }
57a27e1d 4030 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4031 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4032 i++;
4033 }
4034 }
4035
70692ad2
JM
4036 if (info->attrs[NL80211_ATTR_IE]) {
4037 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4038 memcpy((void *)request->ie,
4039 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4040 request->ie_len);
4041 }
4042
34850ab2 4043 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4044 if (wiphy->bands[i])
4045 request->rates[i] =
4046 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4047
4048 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4049 nla_for_each_nested(attr,
4050 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4051 tmp) {
4052 enum ieee80211_band band = nla_type(attr);
4053
84404623 4054 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4055 err = -EINVAL;
4056 goto out_free;
4057 }
4058 err = ieee80211_get_ratemask(wiphy->bands[band],
4059 nla_data(attr),
4060 nla_len(attr),
4061 &request->rates[band]);
4062 if (err)
4063 goto out_free;
4064 }
4065 }
4066
e9f935e3
RM
4067 request->no_cck =
4068 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4069
463d0183 4070 request->dev = dev;
79c97e97 4071 request->wiphy = &rdev->wiphy;
2a519311 4072
79c97e97
JB
4073 rdev->scan_req = request;
4074 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 4075
463d0183 4076 if (!err) {
79c97e97 4077 nl80211_send_scan_start(rdev, dev);
463d0183 4078 dev_hold(dev);
4c476991 4079 } else {
2a519311 4080 out_free:
79c97e97 4081 rdev->scan_req = NULL;
2a519311
JB
4082 kfree(request);
4083 }
3b85875a 4084
2a519311
JB
4085 return err;
4086}
4087
807f8a8c
LC
4088static int nl80211_start_sched_scan(struct sk_buff *skb,
4089 struct genl_info *info)
4090{
4091 struct cfg80211_sched_scan_request *request;
4092 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4093 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4094 struct nlattr *attr;
4095 struct wiphy *wiphy;
a1f1c21c 4096 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4097 u32 interval;
807f8a8c
LC
4098 enum ieee80211_band band;
4099 size_t ie_len;
a1f1c21c 4100 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4101
4102 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4103 !rdev->ops->sched_scan_start)
4104 return -EOPNOTSUPP;
4105
4106 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4107 return -EINVAL;
4108
bbe6ad6d
LC
4109 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4110 return -EINVAL;
4111
4112 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4113 if (interval == 0)
4114 return -EINVAL;
4115
807f8a8c
LC
4116 wiphy = &rdev->wiphy;
4117
4118 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4119 n_channels = validate_scan_freqs(
4120 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4121 if (!n_channels)
4122 return -EINVAL;
4123 } else {
4124 n_channels = 0;
4125
4126 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4127 if (wiphy->bands[band])
4128 n_channels += wiphy->bands[band]->n_channels;
4129 }
4130
4131 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4132 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4133 tmp)
4134 n_ssids++;
4135
93b6aa69 4136 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4137 return -EINVAL;
4138
a1f1c21c
LC
4139 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4140 nla_for_each_nested(attr,
4141 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4142 tmp)
4143 n_match_sets++;
4144
4145 if (n_match_sets > wiphy->max_match_sets)
4146 return -EINVAL;
4147
807f8a8c
LC
4148 if (info->attrs[NL80211_ATTR_IE])
4149 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4150 else
4151 ie_len = 0;
4152
5a865bad 4153 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4154 return -EINVAL;
4155
c10841ca
LC
4156 mutex_lock(&rdev->sched_scan_mtx);
4157
4158 if (rdev->sched_scan_req) {
4159 err = -EINPROGRESS;
4160 goto out;
4161 }
4162
807f8a8c 4163 request = kzalloc(sizeof(*request)
a2cd43c5 4164 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4165 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4166 + sizeof(*request->channels) * n_channels
807f8a8c 4167 + ie_len, GFP_KERNEL);
c10841ca
LC
4168 if (!request) {
4169 err = -ENOMEM;
4170 goto out;
4171 }
807f8a8c
LC
4172
4173 if (n_ssids)
4174 request->ssids = (void *)&request->channels[n_channels];
4175 request->n_ssids = n_ssids;
4176 if (ie_len) {
4177 if (request->ssids)
4178 request->ie = (void *)(request->ssids + n_ssids);
4179 else
4180 request->ie = (void *)(request->channels + n_channels);
4181 }
4182
a1f1c21c
LC
4183 if (n_match_sets) {
4184 if (request->ie)
4185 request->match_sets = (void *)(request->ie + ie_len);
4186 else if (request->ssids)
4187 request->match_sets =
4188 (void *)(request->ssids + n_ssids);
4189 else
4190 request->match_sets =
4191 (void *)(request->channels + n_channels);
4192 }
4193 request->n_match_sets = n_match_sets;
4194
807f8a8c
LC
4195 i = 0;
4196 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4197 /* user specified, bail out if channel not found */
4198 nla_for_each_nested(attr,
4199 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4200 tmp) {
4201 struct ieee80211_channel *chan;
4202
4203 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4204
4205 if (!chan) {
4206 err = -EINVAL;
4207 goto out_free;
4208 }
4209
4210 /* ignore disabled channels */
4211 if (chan->flags & IEEE80211_CHAN_DISABLED)
4212 continue;
4213
4214 request->channels[i] = chan;
4215 i++;
4216 }
4217 } else {
4218 /* all channels */
4219 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4220 int j;
4221 if (!wiphy->bands[band])
4222 continue;
4223 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4224 struct ieee80211_channel *chan;
4225
4226 chan = &wiphy->bands[band]->channels[j];
4227
4228 if (chan->flags & IEEE80211_CHAN_DISABLED)
4229 continue;
4230
4231 request->channels[i] = chan;
4232 i++;
4233 }
4234 }
4235 }
4236
4237 if (!i) {
4238 err = -EINVAL;
4239 goto out_free;
4240 }
4241
4242 request->n_channels = i;
4243
4244 i = 0;
4245 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4246 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4247 tmp) {
57a27e1d 4248 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4249 err = -EINVAL;
4250 goto out_free;
4251 }
57a27e1d 4252 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4253 memcpy(request->ssids[i].ssid, nla_data(attr),
4254 nla_len(attr));
807f8a8c
LC
4255 i++;
4256 }
4257 }
4258
a1f1c21c
LC
4259 i = 0;
4260 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4261 nla_for_each_nested(attr,
4262 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4263 tmp) {
4264 struct nlattr *ssid;
4265
4266 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4267 nla_data(attr), nla_len(attr),
4268 nl80211_match_policy);
4a4ab0d7 4269 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4270 if (ssid) {
4271 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4272 err = -EINVAL;
4273 goto out_free;
4274 }
4275 memcpy(request->match_sets[i].ssid.ssid,
4276 nla_data(ssid), nla_len(ssid));
4277 request->match_sets[i].ssid.ssid_len =
4278 nla_len(ssid);
4279 }
4280 i++;
4281 }
4282 }
4283
807f8a8c
LC
4284 if (info->attrs[NL80211_ATTR_IE]) {
4285 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4286 memcpy((void *)request->ie,
4287 nla_data(info->attrs[NL80211_ATTR_IE]),
4288 request->ie_len);
4289 }
4290
4291 request->dev = dev;
4292 request->wiphy = &rdev->wiphy;
bbe6ad6d 4293 request->interval = interval;
807f8a8c
LC
4294
4295 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
4296 if (!err) {
4297 rdev->sched_scan_req = request;
4298 nl80211_send_sched_scan(rdev, dev,
4299 NL80211_CMD_START_SCHED_SCAN);
4300 goto out;
4301 }
4302
4303out_free:
4304 kfree(request);
4305out:
c10841ca 4306 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4307 return err;
4308}
4309
4310static int nl80211_stop_sched_scan(struct sk_buff *skb,
4311 struct genl_info *info)
4312{
4313 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4314 int err;
807f8a8c
LC
4315
4316 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4317 !rdev->ops->sched_scan_stop)
4318 return -EOPNOTSUPP;
4319
c10841ca
LC
4320 mutex_lock(&rdev->sched_scan_mtx);
4321 err = __cfg80211_stop_sched_scan(rdev, false);
4322 mutex_unlock(&rdev->sched_scan_mtx);
4323
4324 return err;
807f8a8c
LC
4325}
4326
9720bb3a
JB
4327static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4328 u32 seq, int flags,
2a519311 4329 struct cfg80211_registered_device *rdev,
48ab905d
JB
4330 struct wireless_dev *wdev,
4331 struct cfg80211_internal_bss *intbss)
2a519311 4332{
48ab905d 4333 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
4334 void *hdr;
4335 struct nlattr *bss;
48ab905d
JB
4336
4337 ASSERT_WDEV_LOCK(wdev);
2a519311 4338
9720bb3a 4339 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
4340 NL80211_CMD_NEW_SCAN_RESULTS);
4341 if (!hdr)
4342 return -1;
4343
9720bb3a
JB
4344 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4345
9360ffd1
DM
4346 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
4347 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
4348 goto nla_put_failure;
2a519311
JB
4349
4350 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4351 if (!bss)
4352 goto nla_put_failure;
9360ffd1
DM
4353 if ((!is_zero_ether_addr(res->bssid) &&
4354 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)) ||
4355 (res->information_elements && res->len_information_elements &&
4356 nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4357 res->len_information_elements,
4358 res->information_elements)) ||
4359 (res->beacon_ies && res->len_beacon_ies &&
4360 res->beacon_ies != res->information_elements &&
4361 nla_put(msg, NL80211_BSS_BEACON_IES,
4362 res->len_beacon_ies, res->beacon_ies)))
4363 goto nla_put_failure;
4364 if (res->tsf &&
4365 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
4366 goto nla_put_failure;
4367 if (res->beacon_interval &&
4368 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
4369 goto nla_put_failure;
4370 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
4371 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
4372 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
4373 jiffies_to_msecs(jiffies - intbss->ts)))
4374 goto nla_put_failure;
2a519311 4375
77965c97 4376 switch (rdev->wiphy.signal_type) {
2a519311 4377 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
4378 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
4379 goto nla_put_failure;
2a519311
JB
4380 break;
4381 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
4382 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
4383 goto nla_put_failure;
2a519311
JB
4384 break;
4385 default:
4386 break;
4387 }
4388
48ab905d 4389 switch (wdev->iftype) {
074ac8df 4390 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 4391 case NL80211_IFTYPE_STATION:
9360ffd1
DM
4392 if (intbss == wdev->current_bss &&
4393 nla_put_u32(msg, NL80211_BSS_STATUS,
4394 NL80211_BSS_STATUS_ASSOCIATED))
4395 goto nla_put_failure;
48ab905d
JB
4396 break;
4397 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
4398 if (intbss == wdev->current_bss &&
4399 nla_put_u32(msg, NL80211_BSS_STATUS,
4400 NL80211_BSS_STATUS_IBSS_JOINED))
4401 goto nla_put_failure;
48ab905d
JB
4402 break;
4403 default:
4404 break;
4405 }
4406
2a519311
JB
4407 nla_nest_end(msg, bss);
4408
4409 return genlmsg_end(msg, hdr);
4410
4411 nla_put_failure:
4412 genlmsg_cancel(msg, hdr);
4413 return -EMSGSIZE;
4414}
4415
4416static int nl80211_dump_scan(struct sk_buff *skb,
4417 struct netlink_callback *cb)
4418{
48ab905d
JB
4419 struct cfg80211_registered_device *rdev;
4420 struct net_device *dev;
2a519311 4421 struct cfg80211_internal_bss *scan;
48ab905d 4422 struct wireless_dev *wdev;
2a519311
JB
4423 int start = cb->args[1], idx = 0;
4424 int err;
4425
67748893
JB
4426 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4427 if (err)
4428 return err;
2a519311 4429
48ab905d 4430 wdev = dev->ieee80211_ptr;
2a519311 4431
48ab905d
JB
4432 wdev_lock(wdev);
4433 spin_lock_bh(&rdev->bss_lock);
4434 cfg80211_bss_expire(rdev);
4435
9720bb3a
JB
4436 cb->seq = rdev->bss_generation;
4437
48ab905d 4438 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4439 if (++idx <= start)
4440 continue;
9720bb3a 4441 if (nl80211_send_bss(skb, cb,
2a519311 4442 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4443 rdev, wdev, scan) < 0) {
2a519311 4444 idx--;
67748893 4445 break;
2a519311
JB
4446 }
4447 }
4448
48ab905d
JB
4449 spin_unlock_bh(&rdev->bss_lock);
4450 wdev_unlock(wdev);
2a519311
JB
4451
4452 cb->args[1] = idx;
67748893 4453 nl80211_finish_netdev_dump(rdev);
2a519311 4454
67748893 4455 return skb->len;
2a519311
JB
4456}
4457
61fa713c
HS
4458static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4459 int flags, struct net_device *dev,
4460 struct survey_info *survey)
4461{
4462 void *hdr;
4463 struct nlattr *infoattr;
4464
61fa713c
HS
4465 hdr = nl80211hdr_put(msg, pid, seq, flags,
4466 NL80211_CMD_NEW_SURVEY_RESULTS);
4467 if (!hdr)
4468 return -ENOMEM;
4469
9360ffd1
DM
4470 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
4471 goto nla_put_failure;
61fa713c
HS
4472
4473 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4474 if (!infoattr)
4475 goto nla_put_failure;
4476
9360ffd1
DM
4477 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4478 survey->channel->center_freq))
4479 goto nla_put_failure;
4480
4481 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
4482 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
4483 goto nla_put_failure;
4484 if ((survey->filled & SURVEY_INFO_IN_USE) &&
4485 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
4486 goto nla_put_failure;
4487 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
4488 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4489 survey->channel_time))
4490 goto nla_put_failure;
4491 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
4492 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4493 survey->channel_time_busy))
4494 goto nla_put_failure;
4495 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
4496 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4497 survey->channel_time_ext_busy))
4498 goto nla_put_failure;
4499 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
4500 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4501 survey->channel_time_rx))
4502 goto nla_put_failure;
4503 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
4504 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4505 survey->channel_time_tx))
4506 goto nla_put_failure;
61fa713c
HS
4507
4508 nla_nest_end(msg, infoattr);
4509
4510 return genlmsg_end(msg, hdr);
4511
4512 nla_put_failure:
4513 genlmsg_cancel(msg, hdr);
4514 return -EMSGSIZE;
4515}
4516
4517static int nl80211_dump_survey(struct sk_buff *skb,
4518 struct netlink_callback *cb)
4519{
4520 struct survey_info survey;
4521 struct cfg80211_registered_device *dev;
4522 struct net_device *netdev;
61fa713c
HS
4523 int survey_idx = cb->args[1];
4524 int res;
4525
67748893
JB
4526 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4527 if (res)
4528 return res;
61fa713c
HS
4529
4530 if (!dev->ops->dump_survey) {
4531 res = -EOPNOTSUPP;
4532 goto out_err;
4533 }
4534
4535 while (1) {
180cdc79
LR
4536 struct ieee80211_channel *chan;
4537
61fa713c
HS
4538 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4539 &survey);
4540 if (res == -ENOENT)
4541 break;
4542 if (res)
4543 goto out_err;
4544
180cdc79
LR
4545 /* Survey without a channel doesn't make sense */
4546 if (!survey.channel) {
4547 res = -EINVAL;
4548 goto out;
4549 }
4550
4551 chan = ieee80211_get_channel(&dev->wiphy,
4552 survey.channel->center_freq);
4553 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4554 survey_idx++;
4555 continue;
4556 }
4557
61fa713c
HS
4558 if (nl80211_send_survey(skb,
4559 NETLINK_CB(cb->skb).pid,
4560 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4561 netdev,
4562 &survey) < 0)
4563 goto out;
4564 survey_idx++;
4565 }
4566
4567 out:
4568 cb->args[1] = survey_idx;
4569 res = skb->len;
4570 out_err:
67748893 4571 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4572 return res;
4573}
4574
255e737e
JM
4575static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4576{
b23aa676
SO
4577 return auth_type <= NL80211_AUTHTYPE_MAX;
4578}
4579
4580static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4581{
4582 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4583 NL80211_WPA_VERSION_2));
4584}
4585
636a5d36
JM
4586static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4587{
4c476991
JB
4588 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4589 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4590 struct ieee80211_channel *chan;
4591 const u8 *bssid, *ssid, *ie = NULL;
4592 int err, ssid_len, ie_len = 0;
4593 enum nl80211_auth_type auth_type;
fffd0934 4594 struct key_parse key;
d5cdfacb 4595 bool local_state_change;
636a5d36 4596
f4a11bb0
JB
4597 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4598 return -EINVAL;
4599
4600 if (!info->attrs[NL80211_ATTR_MAC])
4601 return -EINVAL;
4602
1778092e
JM
4603 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4604 return -EINVAL;
4605
19957bb3
JB
4606 if (!info->attrs[NL80211_ATTR_SSID])
4607 return -EINVAL;
4608
4609 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4610 return -EINVAL;
4611
fffd0934
JB
4612 err = nl80211_parse_key(info, &key);
4613 if (err)
4614 return err;
4615
4616 if (key.idx >= 0) {
e31b8213
JB
4617 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4618 return -EINVAL;
fffd0934
JB
4619 if (!key.p.key || !key.p.key_len)
4620 return -EINVAL;
4621 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4622 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4623 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4624 key.p.key_len != WLAN_KEY_LEN_WEP104))
4625 return -EINVAL;
4626 if (key.idx > 4)
4627 return -EINVAL;
4628 } else {
4629 key.p.key_len = 0;
4630 key.p.key = NULL;
4631 }
4632
afea0b7a
JB
4633 if (key.idx >= 0) {
4634 int i;
4635 bool ok = false;
4636 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4637 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4638 ok = true;
4639 break;
4640 }
4641 }
4c476991
JB
4642 if (!ok)
4643 return -EINVAL;
afea0b7a
JB
4644 }
4645
4c476991
JB
4646 if (!rdev->ops->auth)
4647 return -EOPNOTSUPP;
636a5d36 4648
074ac8df 4649 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4650 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4651 return -EOPNOTSUPP;
eec60b03 4652
19957bb3 4653 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4654 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4655 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4656 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4657 return -EINVAL;
636a5d36 4658
19957bb3
JB
4659 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4660 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4661
4662 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4663 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4664 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4665 }
4666
19957bb3 4667 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4668 if (!nl80211_valid_auth_type(auth_type))
4669 return -EINVAL;
636a5d36 4670
d5cdfacb
JM
4671 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4672
95de817b
JB
4673 /*
4674 * Since we no longer track auth state, ignore
4675 * requests to only change local state.
4676 */
4677 if (local_state_change)
4678 return 0;
4679
4c476991
JB
4680 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4681 ssid, ssid_len, ie, ie_len,
95de817b 4682 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
4683}
4684
c0692b8f
JB
4685static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4686 struct genl_info *info,
3dc27d25
JB
4687 struct cfg80211_crypto_settings *settings,
4688 int cipher_limit)
b23aa676 4689{
c0b2bbd8
JB
4690 memset(settings, 0, sizeof(*settings));
4691
b23aa676
SO
4692 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4693
c0692b8f
JB
4694 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4695 u16 proto;
4696 proto = nla_get_u16(
4697 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4698 settings->control_port_ethertype = cpu_to_be16(proto);
4699 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4700 proto != ETH_P_PAE)
4701 return -EINVAL;
4702 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4703 settings->control_port_no_encrypt = true;
4704 } else
4705 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4706
b23aa676
SO
4707 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4708 void *data;
4709 int len, i;
4710
4711 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4712 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4713 settings->n_ciphers_pairwise = len / sizeof(u32);
4714
4715 if (len % sizeof(u32))
4716 return -EINVAL;
4717
3dc27d25 4718 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4719 return -EINVAL;
4720
4721 memcpy(settings->ciphers_pairwise, data, len);
4722
4723 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4724 if (!cfg80211_supported_cipher_suite(
4725 &rdev->wiphy,
b23aa676
SO
4726 settings->ciphers_pairwise[i]))
4727 return -EINVAL;
4728 }
4729
4730 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4731 settings->cipher_group =
4732 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4733 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4734 settings->cipher_group))
b23aa676
SO
4735 return -EINVAL;
4736 }
4737
4738 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4739 settings->wpa_versions =
4740 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4741 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4742 return -EINVAL;
4743 }
4744
4745 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4746 void *data;
6d30240e 4747 int len;
b23aa676
SO
4748
4749 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4750 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4751 settings->n_akm_suites = len / sizeof(u32);
4752
4753 if (len % sizeof(u32))
4754 return -EINVAL;
4755
1b9ca027
JM
4756 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4757 return -EINVAL;
4758
b23aa676 4759 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4760 }
4761
4762 return 0;
4763}
4764
636a5d36
JM
4765static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4766{
4c476991
JB
4767 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4768 struct net_device *dev = info->user_ptr[1];
19957bb3 4769 struct cfg80211_crypto_settings crypto;
f444de05 4770 struct ieee80211_channel *chan;
3e5d7649 4771 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4772 int err, ssid_len, ie_len = 0;
4773 bool use_mfp = false;
7e7c8926
BG
4774 u32 flags = 0;
4775 struct ieee80211_ht_cap *ht_capa = NULL;
4776 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 4777
f4a11bb0
JB
4778 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4779 return -EINVAL;
4780
4781 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4782 !info->attrs[NL80211_ATTR_SSID] ||
4783 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4784 return -EINVAL;
4785
4c476991
JB
4786 if (!rdev->ops->assoc)
4787 return -EOPNOTSUPP;
636a5d36 4788
074ac8df 4789 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4790 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4791 return -EOPNOTSUPP;
eec60b03 4792
19957bb3 4793 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4794
19957bb3
JB
4795 chan = ieee80211_get_channel(&rdev->wiphy,
4796 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4797 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4798 return -EINVAL;
636a5d36 4799
19957bb3
JB
4800 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4801 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4802
4803 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4804 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4805 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4806 }
4807
dc6382ce 4808 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4809 enum nl80211_mfp mfp =
dc6382ce 4810 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4811 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4812 use_mfp = true;
4c476991
JB
4813 else if (mfp != NL80211_MFP_NO)
4814 return -EINVAL;
dc6382ce
JM
4815 }
4816
3e5d7649
JB
4817 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4818 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4819
7e7c8926
BG
4820 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
4821 flags |= ASSOC_REQ_DISABLE_HT;
4822
4823 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
4824 ht_capa_mask =
4825 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
4826
4827 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
4828 if (!ht_capa_mask)
4829 return -EINVAL;
4830 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4831 }
4832
c0692b8f 4833 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4834 if (!err)
3e5d7649
JB
4835 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4836 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
4837 &crypto, flags, ht_capa,
4838 ht_capa_mask);
636a5d36 4839
636a5d36
JM
4840 return err;
4841}
4842
4843static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4844{
4c476991
JB
4845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4846 struct net_device *dev = info->user_ptr[1];
19957bb3 4847 const u8 *ie = NULL, *bssid;
4c476991 4848 int ie_len = 0;
19957bb3 4849 u16 reason_code;
d5cdfacb 4850 bool local_state_change;
636a5d36 4851
f4a11bb0
JB
4852 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4853 return -EINVAL;
4854
4855 if (!info->attrs[NL80211_ATTR_MAC])
4856 return -EINVAL;
4857
4858 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4859 return -EINVAL;
4860
4c476991
JB
4861 if (!rdev->ops->deauth)
4862 return -EOPNOTSUPP;
636a5d36 4863
074ac8df 4864 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4865 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4866 return -EOPNOTSUPP;
eec60b03 4867
19957bb3 4868 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4869
19957bb3
JB
4870 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4871 if (reason_code == 0) {
f4a11bb0 4872 /* Reason Code 0 is reserved */
4c476991 4873 return -EINVAL;
255e737e 4874 }
636a5d36
JM
4875
4876 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4877 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4878 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4879 }
4880
d5cdfacb
JM
4881 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4882
4c476991
JB
4883 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4884 local_state_change);
636a5d36
JM
4885}
4886
4887static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4888{
4c476991
JB
4889 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4890 struct net_device *dev = info->user_ptr[1];
19957bb3 4891 const u8 *ie = NULL, *bssid;
4c476991 4892 int ie_len = 0;
19957bb3 4893 u16 reason_code;
d5cdfacb 4894 bool local_state_change;
636a5d36 4895
f4a11bb0
JB
4896 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4897 return -EINVAL;
4898
4899 if (!info->attrs[NL80211_ATTR_MAC])
4900 return -EINVAL;
4901
4902 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4903 return -EINVAL;
4904
4c476991
JB
4905 if (!rdev->ops->disassoc)
4906 return -EOPNOTSUPP;
636a5d36 4907
074ac8df 4908 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4909 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4910 return -EOPNOTSUPP;
eec60b03 4911
19957bb3 4912 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4913
19957bb3
JB
4914 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4915 if (reason_code == 0) {
f4a11bb0 4916 /* Reason Code 0 is reserved */
4c476991 4917 return -EINVAL;
255e737e 4918 }
636a5d36
JM
4919
4920 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4921 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4922 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4923 }
4924
d5cdfacb
JM
4925 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4926
4c476991
JB
4927 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4928 local_state_change);
636a5d36
JM
4929}
4930
dd5b4cc7
FF
4931static bool
4932nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4933 int mcast_rate[IEEE80211_NUM_BANDS],
4934 int rateval)
4935{
4936 struct wiphy *wiphy = &rdev->wiphy;
4937 bool found = false;
4938 int band, i;
4939
4940 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4941 struct ieee80211_supported_band *sband;
4942
4943 sband = wiphy->bands[band];
4944 if (!sband)
4945 continue;
4946
4947 for (i = 0; i < sband->n_bitrates; i++) {
4948 if (sband->bitrates[i].bitrate == rateval) {
4949 mcast_rate[band] = i + 1;
4950 found = true;
4951 break;
4952 }
4953 }
4954 }
4955
4956 return found;
4957}
4958
04a773ad
JB
4959static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4960{
4c476991
JB
4961 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4962 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4963 struct cfg80211_ibss_params ibss;
4964 struct wiphy *wiphy;
fffd0934 4965 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4966 int err;
4967
8e30bc55
JB
4968 memset(&ibss, 0, sizeof(ibss));
4969
04a773ad
JB
4970 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4971 return -EINVAL;
4972
4973 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4974 !info->attrs[NL80211_ATTR_SSID] ||
4975 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4976 return -EINVAL;
4977
8e30bc55
JB
4978 ibss.beacon_interval = 100;
4979
4980 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4981 ibss.beacon_interval =
4982 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4983 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4984 return -EINVAL;
4985 }
4986
4c476991
JB
4987 if (!rdev->ops->join_ibss)
4988 return -EOPNOTSUPP;
04a773ad 4989
4c476991
JB
4990 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4991 return -EOPNOTSUPP;
04a773ad 4992
79c97e97 4993 wiphy = &rdev->wiphy;
04a773ad 4994
39193498 4995 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 4996 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
4997
4998 if (!is_valid_ether_addr(ibss.bssid))
4999 return -EINVAL;
5000 }
04a773ad
JB
5001 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5002 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5003
5004 if (info->attrs[NL80211_ATTR_IE]) {
5005 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5006 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5007 }
5008
54858ee5
AS
5009 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5010 enum nl80211_channel_type channel_type;
5011
cd6c6598 5012 if (!nl80211_valid_channel_type(info, &channel_type))
54858ee5
AS
5013 return -EINVAL;
5014
5015 if (channel_type != NL80211_CHAN_NO_HT &&
5016 !(wiphy->features & NL80211_FEATURE_HT_IBSS))
5017 return -EINVAL;
5018
5019 ibss.channel_type = channel_type;
5020 } else {
5021 ibss.channel_type = NL80211_CHAN_NO_HT;
5022 }
5023
5024 ibss.channel = rdev_freq_to_chan(rdev,
5025 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
5026 ibss.channel_type);
04a773ad
JB
5027 if (!ibss.channel ||
5028 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
5029 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
5030 return -EINVAL;
04a773ad 5031
54858ee5
AS
5032 /* Both channels should be able to initiate communication */
5033 if ((ibss.channel_type == NL80211_CHAN_HT40PLUS ||
5034 ibss.channel_type == NL80211_CHAN_HT40MINUS) &&
5035 !cfg80211_can_beacon_sec_chan(&rdev->wiphy, ibss.channel,
5036 ibss.channel_type))
5037 return -EINVAL;
5038
04a773ad 5039 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5040 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5041
fbd2c8dc
TP
5042 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5043 u8 *rates =
5044 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5045 int n_rates =
5046 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5047 struct ieee80211_supported_band *sband =
5048 wiphy->bands[ibss.channel->band];
fbd2c8dc 5049
34850ab2
JB
5050 err = ieee80211_get_ratemask(sband, rates, n_rates,
5051 &ibss.basic_rates);
5052 if (err)
5053 return err;
fbd2c8dc 5054 }
dd5b4cc7
FF
5055
5056 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5057 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5058 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5059 return -EINVAL;
fbd2c8dc 5060
4c476991
JB
5061 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5062 connkeys = nl80211_parse_connkeys(rdev,
5063 info->attrs[NL80211_ATTR_KEYS]);
5064 if (IS_ERR(connkeys))
5065 return PTR_ERR(connkeys);
5066 }
04a773ad 5067
267335d6
AQ
5068 ibss.control_port =
5069 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5070
4c476991 5071 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5072 if (err)
5073 kfree(connkeys);
04a773ad
JB
5074 return err;
5075}
5076
5077static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5078{
4c476991
JB
5079 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5080 struct net_device *dev = info->user_ptr[1];
04a773ad 5081
4c476991
JB
5082 if (!rdev->ops->leave_ibss)
5083 return -EOPNOTSUPP;
04a773ad 5084
4c476991
JB
5085 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5086 return -EOPNOTSUPP;
04a773ad 5087
4c476991 5088 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5089}
5090
aff89a9b
JB
5091#ifdef CONFIG_NL80211_TESTMODE
5092static struct genl_multicast_group nl80211_testmode_mcgrp = {
5093 .name = "testmode",
5094};
5095
5096static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5097{
4c476991 5098 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5099 int err;
5100
5101 if (!info->attrs[NL80211_ATTR_TESTDATA])
5102 return -EINVAL;
5103
aff89a9b
JB
5104 err = -EOPNOTSUPP;
5105 if (rdev->ops->testmode_cmd) {
5106 rdev->testmode_info = info;
5107 err = rdev->ops->testmode_cmd(&rdev->wiphy,
5108 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5109 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5110 rdev->testmode_info = NULL;
5111 }
5112
aff89a9b
JB
5113 return err;
5114}
5115
71063f0e
WYG
5116static int nl80211_testmode_dump(struct sk_buff *skb,
5117 struct netlink_callback *cb)
5118{
00918d33 5119 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5120 int err;
5121 long phy_idx;
5122 void *data = NULL;
5123 int data_len = 0;
5124
5125 if (cb->args[0]) {
5126 /*
5127 * 0 is a valid index, but not valid for args[0],
5128 * so we need to offset by 1.
5129 */
5130 phy_idx = cb->args[0] - 1;
5131 } else {
5132 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5133 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5134 nl80211_policy);
5135 if (err)
5136 return err;
00918d33
JB
5137 if (nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]) {
5138 phy_idx = nla_get_u32(
5139 nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
5140 } else {
5141 struct net_device *netdev;
5142
5143 err = get_rdev_dev_by_ifindex(sock_net(skb->sk),
5144 nl80211_fam.attrbuf,
5145 &rdev, &netdev);
5146 if (err)
5147 return err;
5148 dev_put(netdev);
5149 phy_idx = rdev->wiphy_idx;
5150 cfg80211_unlock_rdev(rdev);
5151 }
71063f0e
WYG
5152 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5153 cb->args[1] =
5154 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5155 }
5156
5157 if (cb->args[1]) {
5158 data = nla_data((void *)cb->args[1]);
5159 data_len = nla_len((void *)cb->args[1]);
5160 }
5161
5162 mutex_lock(&cfg80211_mutex);
00918d33
JB
5163 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5164 if (!rdev) {
71063f0e
WYG
5165 mutex_unlock(&cfg80211_mutex);
5166 return -ENOENT;
5167 }
00918d33 5168 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5169 mutex_unlock(&cfg80211_mutex);
5170
00918d33 5171 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5172 err = -EOPNOTSUPP;
5173 goto out_err;
5174 }
5175
5176 while (1) {
5177 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
5178 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5179 NL80211_CMD_TESTMODE);
5180 struct nlattr *tmdata;
5181
9360ffd1 5182 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5183 genlmsg_cancel(skb, hdr);
5184 break;
5185 }
5186
5187 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5188 if (!tmdata) {
5189 genlmsg_cancel(skb, hdr);
5190 break;
5191 }
00918d33
JB
5192 err = rdev->ops->testmode_dump(&rdev->wiphy, skb, cb,
5193 data, data_len);
71063f0e
WYG
5194 nla_nest_end(skb, tmdata);
5195
5196 if (err == -ENOBUFS || err == -ENOENT) {
5197 genlmsg_cancel(skb, hdr);
5198 break;
5199 } else if (err) {
5200 genlmsg_cancel(skb, hdr);
5201 goto out_err;
5202 }
5203
5204 genlmsg_end(skb, hdr);
5205 }
5206
5207 err = skb->len;
5208 /* see above */
5209 cb->args[0] = phy_idx + 1;
5210 out_err:
00918d33 5211 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5212 return err;
5213}
5214
aff89a9b
JB
5215static struct sk_buff *
5216__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
5217 int approxlen, u32 pid, u32 seq, gfp_t gfp)
5218{
5219 struct sk_buff *skb;
5220 void *hdr;
5221 struct nlattr *data;
5222
5223 skb = nlmsg_new(approxlen + 100, gfp);
5224 if (!skb)
5225 return NULL;
5226
5227 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
5228 if (!hdr) {
5229 kfree_skb(skb);
5230 return NULL;
5231 }
5232
9360ffd1
DM
5233 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5234 goto nla_put_failure;
aff89a9b
JB
5235 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5236
5237 ((void **)skb->cb)[0] = rdev;
5238 ((void **)skb->cb)[1] = hdr;
5239 ((void **)skb->cb)[2] = data;
5240
5241 return skb;
5242
5243 nla_put_failure:
5244 kfree_skb(skb);
5245 return NULL;
5246}
5247
5248struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5249 int approxlen)
5250{
5251 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5252
5253 if (WARN_ON(!rdev->testmode_info))
5254 return NULL;
5255
5256 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
5257 rdev->testmode_info->snd_pid,
5258 rdev->testmode_info->snd_seq,
5259 GFP_KERNEL);
5260}
5261EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5262
5263int cfg80211_testmode_reply(struct sk_buff *skb)
5264{
5265 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5266 void *hdr = ((void **)skb->cb)[1];
5267 struct nlattr *data = ((void **)skb->cb)[2];
5268
5269 if (WARN_ON(!rdev->testmode_info)) {
5270 kfree_skb(skb);
5271 return -EINVAL;
5272 }
5273
5274 nla_nest_end(skb, data);
5275 genlmsg_end(skb, hdr);
5276 return genlmsg_reply(skb, rdev->testmode_info);
5277}
5278EXPORT_SYMBOL(cfg80211_testmode_reply);
5279
5280struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5281 int approxlen, gfp_t gfp)
5282{
5283 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5284
5285 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5286}
5287EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5288
5289void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5290{
5291 void *hdr = ((void **)skb->cb)[1];
5292 struct nlattr *data = ((void **)skb->cb)[2];
5293
5294 nla_nest_end(skb, data);
5295 genlmsg_end(skb, hdr);
5296 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5297}
5298EXPORT_SYMBOL(cfg80211_testmode_event);
5299#endif
5300
b23aa676
SO
5301static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5302{
4c476991
JB
5303 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5304 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5305 struct cfg80211_connect_params connect;
5306 struct wiphy *wiphy;
fffd0934 5307 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5308 int err;
5309
5310 memset(&connect, 0, sizeof(connect));
5311
5312 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5313 return -EINVAL;
5314
5315 if (!info->attrs[NL80211_ATTR_SSID] ||
5316 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5317 return -EINVAL;
5318
5319 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5320 connect.auth_type =
5321 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
5322 if (!nl80211_valid_auth_type(connect.auth_type))
5323 return -EINVAL;
5324 } else
5325 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5326
5327 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5328
c0692b8f 5329 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5330 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5331 if (err)
5332 return err;
b23aa676 5333
074ac8df 5334 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5335 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5336 return -EOPNOTSUPP;
b23aa676 5337
79c97e97 5338 wiphy = &rdev->wiphy;
b23aa676 5339
4486ea98
BS
5340 connect.bg_scan_period = -1;
5341 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5342 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5343 connect.bg_scan_period =
5344 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5345 }
5346
b23aa676
SO
5347 if (info->attrs[NL80211_ATTR_MAC])
5348 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5349 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5350 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5351
5352 if (info->attrs[NL80211_ATTR_IE]) {
5353 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5354 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5355 }
5356
5357 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5358 connect.channel =
5359 ieee80211_get_channel(wiphy,
5360 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5361 if (!connect.channel ||
4c476991
JB
5362 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5363 return -EINVAL;
b23aa676
SO
5364 }
5365
fffd0934
JB
5366 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5367 connkeys = nl80211_parse_connkeys(rdev,
5368 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
5369 if (IS_ERR(connkeys))
5370 return PTR_ERR(connkeys);
fffd0934
JB
5371 }
5372
7e7c8926
BG
5373 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5374 connect.flags |= ASSOC_REQ_DISABLE_HT;
5375
5376 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5377 memcpy(&connect.ht_capa_mask,
5378 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5379 sizeof(connect.ht_capa_mask));
5380
5381 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5382 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5383 return -EINVAL;
5384 memcpy(&connect.ht_capa,
5385 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5386 sizeof(connect.ht_capa));
5387 }
5388
fffd0934 5389 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5390 if (err)
5391 kfree(connkeys);
b23aa676
SO
5392 return err;
5393}
5394
5395static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5396{
4c476991
JB
5397 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5398 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5399 u16 reason;
5400
5401 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5402 reason = WLAN_REASON_DEAUTH_LEAVING;
5403 else
5404 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5405
5406 if (reason == 0)
5407 return -EINVAL;
5408
074ac8df 5409 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5410 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5411 return -EOPNOTSUPP;
b23aa676 5412
4c476991 5413 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
5414}
5415
463d0183
JB
5416static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5417{
4c476991 5418 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
5419 struct net *net;
5420 int err;
5421 u32 pid;
5422
5423 if (!info->attrs[NL80211_ATTR_PID])
5424 return -EINVAL;
5425
5426 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5427
463d0183 5428 net = get_net_ns_by_pid(pid);
4c476991
JB
5429 if (IS_ERR(net))
5430 return PTR_ERR(net);
463d0183
JB
5431
5432 err = 0;
5433
5434 /* check if anything to do */
4c476991
JB
5435 if (!net_eq(wiphy_net(&rdev->wiphy), net))
5436 err = cfg80211_switch_netns(rdev, net);
463d0183 5437
463d0183 5438 put_net(net);
463d0183
JB
5439 return err;
5440}
5441
67fbb16b
SO
5442static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5443{
4c476991 5444 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
5445 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5446 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 5447 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
5448 struct cfg80211_pmksa pmksa;
5449
5450 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5451
5452 if (!info->attrs[NL80211_ATTR_MAC])
5453 return -EINVAL;
5454
5455 if (!info->attrs[NL80211_ATTR_PMKID])
5456 return -EINVAL;
5457
67fbb16b
SO
5458 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5459 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5460
074ac8df 5461 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5462 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5463 return -EOPNOTSUPP;
67fbb16b
SO
5464
5465 switch (info->genlhdr->cmd) {
5466 case NL80211_CMD_SET_PMKSA:
5467 rdev_ops = rdev->ops->set_pmksa;
5468 break;
5469 case NL80211_CMD_DEL_PMKSA:
5470 rdev_ops = rdev->ops->del_pmksa;
5471 break;
5472 default:
5473 WARN_ON(1);
5474 break;
5475 }
5476
4c476991
JB
5477 if (!rdev_ops)
5478 return -EOPNOTSUPP;
67fbb16b 5479
4c476991 5480 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
5481}
5482
5483static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5484{
4c476991
JB
5485 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5486 struct net_device *dev = info->user_ptr[1];
67fbb16b 5487
074ac8df 5488 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5489 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5490 return -EOPNOTSUPP;
67fbb16b 5491
4c476991
JB
5492 if (!rdev->ops->flush_pmksa)
5493 return -EOPNOTSUPP;
67fbb16b 5494
4c476991 5495 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5496}
5497
109086ce
AN
5498static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5499{
5500 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5501 struct net_device *dev = info->user_ptr[1];
5502 u8 action_code, dialog_token;
5503 u16 status_code;
5504 u8 *peer;
5505
5506 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5507 !rdev->ops->tdls_mgmt)
5508 return -EOPNOTSUPP;
5509
5510 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5511 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5512 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5513 !info->attrs[NL80211_ATTR_IE] ||
5514 !info->attrs[NL80211_ATTR_MAC])
5515 return -EINVAL;
5516
5517 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5518 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5519 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5520 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5521
5522 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5523 dialog_token, status_code,
5524 nla_data(info->attrs[NL80211_ATTR_IE]),
5525 nla_len(info->attrs[NL80211_ATTR_IE]));
5526}
5527
5528static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5529{
5530 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5531 struct net_device *dev = info->user_ptr[1];
5532 enum nl80211_tdls_operation operation;
5533 u8 *peer;
5534
5535 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5536 !rdev->ops->tdls_oper)
5537 return -EOPNOTSUPP;
5538
5539 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5540 !info->attrs[NL80211_ATTR_MAC])
5541 return -EINVAL;
5542
5543 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5544 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5545
5546 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5547}
5548
9588bbd5
JM
5549static int nl80211_remain_on_channel(struct sk_buff *skb,
5550 struct genl_info *info)
5551{
4c476991
JB
5552 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5553 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5554 struct ieee80211_channel *chan;
5555 struct sk_buff *msg;
5556 void *hdr;
5557 u64 cookie;
5558 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5559 u32 freq, duration;
5560 int err;
5561
5562 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5563 !info->attrs[NL80211_ATTR_DURATION])
5564 return -EINVAL;
5565
5566 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5567
ebf348fc
JB
5568 if (!rdev->ops->remain_on_channel ||
5569 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
5570 return -EOPNOTSUPP;
5571
9588bbd5 5572 /*
ebf348fc
JB
5573 * We should be on that channel for at least a minimum amount of
5574 * time (10ms) but no longer than the driver supports.
9588bbd5 5575 */
ebf348fc 5576 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 5577 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5578 return -EINVAL;
5579
cd6c6598
JB
5580 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
5581 !nl80211_valid_channel_type(info, &channel_type))
5582 return -EINVAL;
9588bbd5
JM
5583
5584 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5585 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5586 if (chan == NULL)
5587 return -EINVAL;
9588bbd5
JM
5588
5589 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5590 if (!msg)
5591 return -ENOMEM;
9588bbd5
JM
5592
5593 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5594 NL80211_CMD_REMAIN_ON_CHANNEL);
5595
5596 if (IS_ERR(hdr)) {
5597 err = PTR_ERR(hdr);
5598 goto free_msg;
5599 }
5600
5601 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5602 channel_type, duration, &cookie);
5603
5604 if (err)
5605 goto free_msg;
5606
9360ffd1
DM
5607 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
5608 goto nla_put_failure;
9588bbd5
JM
5609
5610 genlmsg_end(msg, hdr);
4c476991
JB
5611
5612 return genlmsg_reply(msg, info);
9588bbd5
JM
5613
5614 nla_put_failure:
5615 err = -ENOBUFS;
5616 free_msg:
5617 nlmsg_free(msg);
9588bbd5
JM
5618 return err;
5619}
5620
5621static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5622 struct genl_info *info)
5623{
4c476991
JB
5624 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5625 struct net_device *dev = info->user_ptr[1];
9588bbd5 5626 u64 cookie;
9588bbd5
JM
5627
5628 if (!info->attrs[NL80211_ATTR_COOKIE])
5629 return -EINVAL;
5630
4c476991
JB
5631 if (!rdev->ops->cancel_remain_on_channel)
5632 return -EOPNOTSUPP;
9588bbd5 5633
9588bbd5
JM
5634 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5635
4c476991 5636 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5637}
5638
13ae75b1
JM
5639static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5640 u8 *rates, u8 rates_len)
5641{
5642 u8 i;
5643 u32 mask = 0;
5644
5645 for (i = 0; i < rates_len; i++) {
5646 int rate = (rates[i] & 0x7f) * 5;
5647 int ridx;
5648 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5649 struct ieee80211_rate *srate =
5650 &sband->bitrates[ridx];
5651 if (rate == srate->bitrate) {
5652 mask |= 1 << ridx;
5653 break;
5654 }
5655 }
5656 if (ridx == sband->n_bitrates)
5657 return 0; /* rate not found */
5658 }
5659
5660 return mask;
5661}
5662
24db78c0
SW
5663static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
5664 u8 *rates, u8 rates_len,
5665 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
5666{
5667 u8 i;
5668
5669 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
5670
5671 for (i = 0; i < rates_len; i++) {
5672 int ridx, rbit;
5673
5674 ridx = rates[i] / 8;
5675 rbit = BIT(rates[i] % 8);
5676
5677 /* check validity */
910570b5 5678 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
5679 return false;
5680
5681 /* check availability */
5682 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5683 mcs[ridx] |= rbit;
5684 else
5685 return false;
5686 }
5687
5688 return true;
5689}
5690
b54452b0 5691static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5692 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5693 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
5694 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
5695 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
5696};
5697
5698static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5699 struct genl_info *info)
5700{
5701 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5702 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5703 struct cfg80211_bitrate_mask mask;
4c476991
JB
5704 int rem, i;
5705 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5706 struct nlattr *tx_rates;
5707 struct ieee80211_supported_band *sband;
5708
5709 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5710 return -EINVAL;
5711
4c476991
JB
5712 if (!rdev->ops->set_bitrate_mask)
5713 return -EOPNOTSUPP;
13ae75b1
JM
5714
5715 memset(&mask, 0, sizeof(mask));
5716 /* Default to all rates enabled */
5717 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5718 sband = rdev->wiphy.bands[i];
5719 mask.control[i].legacy =
5720 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
5721 if (sband)
5722 memcpy(mask.control[i].mcs,
5723 sband->ht_cap.mcs.rx_mask,
5724 sizeof(mask.control[i].mcs));
5725 else
5726 memset(mask.control[i].mcs, 0,
5727 sizeof(mask.control[i].mcs));
13ae75b1
JM
5728 }
5729
5730 /*
5731 * The nested attribute uses enum nl80211_band as the index. This maps
5732 * directly to the enum ieee80211_band values used in cfg80211.
5733 */
24db78c0 5734 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
5735 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5736 {
5737 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5738 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5739 return -EINVAL;
13ae75b1 5740 sband = rdev->wiphy.bands[band];
4c476991
JB
5741 if (sband == NULL)
5742 return -EINVAL;
13ae75b1
JM
5743 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5744 nla_len(tx_rates), nl80211_txattr_policy);
5745 if (tb[NL80211_TXRATE_LEGACY]) {
5746 mask.control[band].legacy = rateset_to_mask(
5747 sband,
5748 nla_data(tb[NL80211_TXRATE_LEGACY]),
5749 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
5750 if ((mask.control[band].legacy == 0) &&
5751 nla_len(tb[NL80211_TXRATE_LEGACY]))
5752 return -EINVAL;
24db78c0
SW
5753 }
5754 if (tb[NL80211_TXRATE_MCS]) {
5755 if (!ht_rateset_to_mask(
5756 sband,
5757 nla_data(tb[NL80211_TXRATE_MCS]),
5758 nla_len(tb[NL80211_TXRATE_MCS]),
5759 mask.control[band].mcs))
5760 return -EINVAL;
5761 }
5762
5763 if (mask.control[band].legacy == 0) {
5764 /* don't allow empty legacy rates if HT
5765 * is not even supported. */
5766 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
5767 return -EINVAL;
5768
5769 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5770 if (mask.control[band].mcs[i])
5771 break;
5772
5773 /* legacy and mcs rates may not be both empty */
5774 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 5775 return -EINVAL;
13ae75b1
JM
5776 }
5777 }
5778
4c476991 5779 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5780}
5781
2e161f78 5782static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5783{
4c476991
JB
5784 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5785 struct net_device *dev = info->user_ptr[1];
2e161f78 5786 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5787
5788 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5789 return -EINVAL;
5790
2e161f78
JB
5791 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5792 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5793
9d38d85d 5794 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5795 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5796 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5797 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5798 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5799 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5800 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5801 return -EOPNOTSUPP;
026331c4
JM
5802
5803 /* not much point in registering if we can't reply */
4c476991
JB
5804 if (!rdev->ops->mgmt_tx)
5805 return -EOPNOTSUPP;
026331c4 5806
4c476991 5807 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 5808 frame_type,
026331c4
JM
5809 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5810 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
5811}
5812
2e161f78 5813static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5814{
4c476991
JB
5815 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5816 struct net_device *dev = info->user_ptr[1];
026331c4
JM
5817 struct ieee80211_channel *chan;
5818 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 5819 bool channel_type_valid = false;
026331c4
JM
5820 u32 freq;
5821 int err;
d64d373f 5822 void *hdr = NULL;
026331c4 5823 u64 cookie;
e247bd90 5824 struct sk_buff *msg = NULL;
f7ca38df 5825 unsigned int wait = 0;
e247bd90
JB
5826 bool offchan, no_cck, dont_wait_for_ack;
5827
5828 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4
JM
5829
5830 if (!info->attrs[NL80211_ATTR_FRAME] ||
5831 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5832 return -EINVAL;
5833
4c476991
JB
5834 if (!rdev->ops->mgmt_tx)
5835 return -EOPNOTSUPP;
026331c4 5836
9d38d85d 5837 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5838 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5839 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5840 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5841 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5842 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5843 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5844 return -EOPNOTSUPP;
026331c4 5845
f7ca38df 5846 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 5847 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
5848 return -EINVAL;
5849 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
5850
5851 /*
5852 * We should wait on the channel for at least a minimum amount
5853 * of time (10ms) but no longer than the driver supports.
5854 */
5855 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
5856 wait > rdev->wiphy.max_remain_on_channel_duration)
5857 return -EINVAL;
5858
f7ca38df
JB
5859 }
5860
026331c4 5861 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
cd6c6598 5862 if (!nl80211_valid_channel_type(info, &channel_type))
4c476991 5863 return -EINVAL;
252aa631 5864 channel_type_valid = true;
026331c4
JM
5865 }
5866
f7ca38df
JB
5867 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5868
7c4ef712
JB
5869 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
5870 return -EINVAL;
5871
e9f935e3
RM
5872 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5873
026331c4
JM
5874 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5875 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5876 if (chan == NULL)
5877 return -EINVAL;
026331c4 5878
e247bd90
JB
5879 if (!dont_wait_for_ack) {
5880 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5881 if (!msg)
5882 return -ENOMEM;
026331c4 5883
e247bd90
JB
5884 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5885 NL80211_CMD_FRAME);
026331c4 5886
e247bd90
JB
5887 if (IS_ERR(hdr)) {
5888 err = PTR_ERR(hdr);
5889 goto free_msg;
5890 }
026331c4 5891 }
e247bd90 5892
f7ca38df
JB
5893 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5894 channel_type_valid, wait,
2e161f78
JB
5895 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5896 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 5897 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
5898 if (err)
5899 goto free_msg;
5900
e247bd90 5901 if (msg) {
9360ffd1
DM
5902 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
5903 goto nla_put_failure;
026331c4 5904
e247bd90
JB
5905 genlmsg_end(msg, hdr);
5906 return genlmsg_reply(msg, info);
5907 }
5908
5909 return 0;
026331c4
JM
5910
5911 nla_put_failure:
5912 err = -ENOBUFS;
5913 free_msg:
5914 nlmsg_free(msg);
026331c4
JM
5915 return err;
5916}
5917
f7ca38df
JB
5918static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5919{
5920 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5921 struct net_device *dev = info->user_ptr[1];
5922 u64 cookie;
5923
5924 if (!info->attrs[NL80211_ATTR_COOKIE])
5925 return -EINVAL;
5926
5927 if (!rdev->ops->mgmt_tx_cancel_wait)
5928 return -EOPNOTSUPP;
5929
5930 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5931 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5932 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5933 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5934 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5935 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5936 return -EOPNOTSUPP;
5937
5938 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5939
5940 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5941}
5942
ffb9eb3d
KV
5943static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5944{
4c476991 5945 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 5946 struct wireless_dev *wdev;
4c476991 5947 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5948 u8 ps_state;
5949 bool state;
5950 int err;
5951
4c476991
JB
5952 if (!info->attrs[NL80211_ATTR_PS_STATE])
5953 return -EINVAL;
ffb9eb3d
KV
5954
5955 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5956
4c476991
JB
5957 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5958 return -EINVAL;
ffb9eb3d
KV
5959
5960 wdev = dev->ieee80211_ptr;
5961
4c476991
JB
5962 if (!rdev->ops->set_power_mgmt)
5963 return -EOPNOTSUPP;
ffb9eb3d
KV
5964
5965 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5966
5967 if (state == wdev->ps)
4c476991 5968 return 0;
ffb9eb3d 5969
4c476991
JB
5970 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5971 wdev->ps_timeout);
5972 if (!err)
5973 wdev->ps = state;
ffb9eb3d
KV
5974 return err;
5975}
5976
5977static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5978{
4c476991 5979 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
5980 enum nl80211_ps_state ps_state;
5981 struct wireless_dev *wdev;
4c476991 5982 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5983 struct sk_buff *msg;
5984 void *hdr;
5985 int err;
5986
ffb9eb3d
KV
5987 wdev = dev->ieee80211_ptr;
5988
4c476991
JB
5989 if (!rdev->ops->set_power_mgmt)
5990 return -EOPNOTSUPP;
ffb9eb3d
KV
5991
5992 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5993 if (!msg)
5994 return -ENOMEM;
ffb9eb3d
KV
5995
5996 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5997 NL80211_CMD_GET_POWER_SAVE);
5998 if (!hdr) {
4c476991 5999 err = -ENOBUFS;
ffb9eb3d
KV
6000 goto free_msg;
6001 }
6002
6003 if (wdev->ps)
6004 ps_state = NL80211_PS_ENABLED;
6005 else
6006 ps_state = NL80211_PS_DISABLED;
6007
9360ffd1
DM
6008 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6009 goto nla_put_failure;
ffb9eb3d
KV
6010
6011 genlmsg_end(msg, hdr);
4c476991 6012 return genlmsg_reply(msg, info);
ffb9eb3d 6013
4c476991 6014 nla_put_failure:
ffb9eb3d 6015 err = -ENOBUFS;
4c476991 6016 free_msg:
ffb9eb3d 6017 nlmsg_free(msg);
ffb9eb3d
KV
6018 return err;
6019}
6020
d6dc1a38
JO
6021static struct nla_policy
6022nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6023 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6024 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6025 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
6026};
6027
6028static int nl80211_set_cqm_rssi(struct genl_info *info,
6029 s32 threshold, u32 hysteresis)
6030{
4c476991 6031 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6032 struct wireless_dev *wdev;
4c476991 6033 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6034
6035 if (threshold > 0)
6036 return -EINVAL;
6037
d6dc1a38
JO
6038 wdev = dev->ieee80211_ptr;
6039
4c476991
JB
6040 if (!rdev->ops->set_cqm_rssi_config)
6041 return -EOPNOTSUPP;
d6dc1a38 6042
074ac8df 6043 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6044 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6045 return -EOPNOTSUPP;
d6dc1a38 6046
4c476991
JB
6047 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
6048 threshold, hysteresis);
d6dc1a38
JO
6049}
6050
6051static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6052{
6053 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6054 struct nlattr *cqm;
6055 int err;
6056
6057 cqm = info->attrs[NL80211_ATTR_CQM];
6058 if (!cqm) {
6059 err = -EINVAL;
6060 goto out;
6061 }
6062
6063 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6064 nl80211_attr_cqm_policy);
6065 if (err)
6066 goto out;
6067
6068 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6069 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6070 s32 threshold;
6071 u32 hysteresis;
6072 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6073 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6074 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
6075 } else
6076 err = -EINVAL;
6077
6078out:
6079 return err;
6080}
6081
29cbe68c
JB
6082static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6083{
6084 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6085 struct net_device *dev = info->user_ptr[1];
6086 struct mesh_config cfg;
c80d545d 6087 struct mesh_setup setup;
29cbe68c
JB
6088 int err;
6089
6090 /* start with default */
6091 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6092 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6093
24bdd9f4 6094 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6095 /* and parse parameters if given */
24bdd9f4 6096 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6097 if (err)
6098 return err;
6099 }
6100
6101 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6102 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6103 return -EINVAL;
6104
c80d545d
JC
6105 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6106 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6107
4bb62344
CYY
6108 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6109 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6110 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6111 return -EINVAL;
6112
c80d545d
JC
6113 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6114 /* parse additional setup parameters if given */
6115 err = nl80211_parse_mesh_setup(info, &setup);
6116 if (err)
6117 return err;
6118 }
6119
cc1d2806
JB
6120 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6121 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
6122
6123 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
6124 !nl80211_valid_channel_type(info, &channel_type))
6125 return -EINVAL;
6126
6127 setup.channel = rdev_freq_to_chan(rdev,
6128 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
6129 channel_type);
6130 if (!setup.channel)
6131 return -EINVAL;
6132 setup.channel_type = channel_type;
6133 } else {
6134 /* cfg80211_join_mesh() will sort it out */
6135 setup.channel = NULL;
6136 }
6137
c80d545d 6138 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6139}
6140
6141static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6142{
6143 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6144 struct net_device *dev = info->user_ptr[1];
6145
6146 return cfg80211_leave_mesh(rdev, dev);
6147}
6148
ff1b6e69
JB
6149static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6150{
6151 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6152 struct sk_buff *msg;
6153 void *hdr;
6154
6155 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6156 return -EOPNOTSUPP;
6157
6158 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6159 if (!msg)
6160 return -ENOMEM;
6161
6162 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6163 NL80211_CMD_GET_WOWLAN);
6164 if (!hdr)
6165 goto nla_put_failure;
6166
6167 if (rdev->wowlan) {
6168 struct nlattr *nl_wowlan;
6169
6170 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6171 if (!nl_wowlan)
6172 goto nla_put_failure;
6173
9360ffd1
DM
6174 if ((rdev->wowlan->any &&
6175 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6176 (rdev->wowlan->disconnect &&
6177 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6178 (rdev->wowlan->magic_pkt &&
6179 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6180 (rdev->wowlan->gtk_rekey_failure &&
6181 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6182 (rdev->wowlan->eap_identity_req &&
6183 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6184 (rdev->wowlan->four_way_handshake &&
6185 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6186 (rdev->wowlan->rfkill_release &&
6187 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6188 goto nla_put_failure;
ff1b6e69
JB
6189 if (rdev->wowlan->n_patterns) {
6190 struct nlattr *nl_pats, *nl_pat;
6191 int i, pat_len;
6192
6193 nl_pats = nla_nest_start(msg,
6194 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6195 if (!nl_pats)
6196 goto nla_put_failure;
6197
6198 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6199 nl_pat = nla_nest_start(msg, i + 1);
6200 if (!nl_pat)
6201 goto nla_put_failure;
6202 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6203 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6204 DIV_ROUND_UP(pat_len, 8),
6205 rdev->wowlan->patterns[i].mask) ||
6206 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6207 pat_len,
6208 rdev->wowlan->patterns[i].pattern))
6209 goto nla_put_failure;
ff1b6e69
JB
6210 nla_nest_end(msg, nl_pat);
6211 }
6212 nla_nest_end(msg, nl_pats);
6213 }
6214
6215 nla_nest_end(msg, nl_wowlan);
6216 }
6217
6218 genlmsg_end(msg, hdr);
6219 return genlmsg_reply(msg, info);
6220
6221nla_put_failure:
6222 nlmsg_free(msg);
6223 return -ENOBUFS;
6224}
6225
6226static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6227{
6228 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6229 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
6230 struct cfg80211_wowlan no_triggers = {};
6231 struct cfg80211_wowlan new_triggers = {};
6232 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6233 int err, i;
6d52563f 6234 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6235
6236 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6237 return -EOPNOTSUPP;
6238
6239 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
6240 goto no_triggers;
6241
6242 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6243 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6244 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6245 nl80211_wowlan_policy);
6246 if (err)
6247 return err;
6248
6249 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6250 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6251 return -EINVAL;
6252 new_triggers.any = true;
6253 }
6254
6255 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6256 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6257 return -EINVAL;
6258 new_triggers.disconnect = true;
6259 }
6260
6261 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6262 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6263 return -EINVAL;
6264 new_triggers.magic_pkt = true;
6265 }
6266
77dbbb13
JB
6267 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6268 return -EINVAL;
6269
6270 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6271 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6272 return -EINVAL;
6273 new_triggers.gtk_rekey_failure = true;
6274 }
6275
6276 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6277 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6278 return -EINVAL;
6279 new_triggers.eap_identity_req = true;
6280 }
6281
6282 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6283 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6284 return -EINVAL;
6285 new_triggers.four_way_handshake = true;
6286 }
6287
6288 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6289 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6290 return -EINVAL;
6291 new_triggers.rfkill_release = true;
6292 }
6293
ff1b6e69
JB
6294 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6295 struct nlattr *pat;
6296 int n_patterns = 0;
6297 int rem, pat_len, mask_len;
6298 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6299
6300 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6301 rem)
6302 n_patterns++;
6303 if (n_patterns > wowlan->n_patterns)
6304 return -EINVAL;
6305
6306 new_triggers.patterns = kcalloc(n_patterns,
6307 sizeof(new_triggers.patterns[0]),
6308 GFP_KERNEL);
6309 if (!new_triggers.patterns)
6310 return -ENOMEM;
6311
6312 new_triggers.n_patterns = n_patterns;
6313 i = 0;
6314
6315 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6316 rem) {
6317 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6318 nla_data(pat), nla_len(pat), NULL);
6319 err = -EINVAL;
6320 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6321 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6322 goto error;
6323 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6324 mask_len = DIV_ROUND_UP(pat_len, 8);
6325 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6326 mask_len)
6327 goto error;
6328 if (pat_len > wowlan->pattern_max_len ||
6329 pat_len < wowlan->pattern_min_len)
6330 goto error;
6331
6332 new_triggers.patterns[i].mask =
6333 kmalloc(mask_len + pat_len, GFP_KERNEL);
6334 if (!new_triggers.patterns[i].mask) {
6335 err = -ENOMEM;
6336 goto error;
6337 }
6338 new_triggers.patterns[i].pattern =
6339 new_triggers.patterns[i].mask + mask_len;
6340 memcpy(new_triggers.patterns[i].mask,
6341 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6342 mask_len);
6343 new_triggers.patterns[i].pattern_len = pat_len;
6344 memcpy(new_triggers.patterns[i].pattern,
6345 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6346 pat_len);
6347 i++;
6348 }
6349 }
6350
6351 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
6352 struct cfg80211_wowlan *ntrig;
6353 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
6354 GFP_KERNEL);
6355 if (!ntrig) {
6356 err = -ENOMEM;
6357 goto error;
6358 }
6359 cfg80211_rdev_free_wowlan(rdev);
6360 rdev->wowlan = ntrig;
6361 } else {
6362 no_triggers:
6363 cfg80211_rdev_free_wowlan(rdev);
6364 rdev->wowlan = NULL;
6365 }
6366
6d52563f
JB
6367 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
6368 rdev->ops->set_wakeup(&rdev->wiphy, rdev->wowlan);
6369
ff1b6e69
JB
6370 return 0;
6371 error:
6372 for (i = 0; i < new_triggers.n_patterns; i++)
6373 kfree(new_triggers.patterns[i].mask);
6374 kfree(new_triggers.patterns);
6375 return err;
6376}
6377
e5497d76
JB
6378static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6379{
6380 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6381 struct net_device *dev = info->user_ptr[1];
6382 struct wireless_dev *wdev = dev->ieee80211_ptr;
6383 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6384 struct cfg80211_gtk_rekey_data rekey_data;
6385 int err;
6386
6387 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6388 return -EINVAL;
6389
6390 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6391 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6392 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6393 nl80211_rekey_policy);
6394 if (err)
6395 return err;
6396
6397 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6398 return -ERANGE;
6399 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6400 return -ERANGE;
6401 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6402 return -ERANGE;
6403
6404 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6405 NL80211_KEK_LEN);
6406 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6407 NL80211_KCK_LEN);
6408 memcpy(rekey_data.replay_ctr,
6409 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6410 NL80211_REPLAY_CTR_LEN);
6411
6412 wdev_lock(wdev);
6413 if (!wdev->current_bss) {
6414 err = -ENOTCONN;
6415 goto out;
6416 }
6417
6418 if (!rdev->ops->set_rekey_data) {
6419 err = -EOPNOTSUPP;
6420 goto out;
6421 }
6422
6423 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
6424 out:
6425 wdev_unlock(wdev);
6426 return err;
6427}
6428
28946da7
JB
6429static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6430 struct genl_info *info)
6431{
6432 struct net_device *dev = info->user_ptr[1];
6433 struct wireless_dev *wdev = dev->ieee80211_ptr;
6434
6435 if (wdev->iftype != NL80211_IFTYPE_AP &&
6436 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6437 return -EINVAL;
6438
6439 if (wdev->ap_unexpected_nlpid)
6440 return -EBUSY;
6441
6442 wdev->ap_unexpected_nlpid = info->snd_pid;
6443 return 0;
6444}
6445
7f6cf311
JB
6446static int nl80211_probe_client(struct sk_buff *skb,
6447 struct genl_info *info)
6448{
6449 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6450 struct net_device *dev = info->user_ptr[1];
6451 struct wireless_dev *wdev = dev->ieee80211_ptr;
6452 struct sk_buff *msg;
6453 void *hdr;
6454 const u8 *addr;
6455 u64 cookie;
6456 int err;
6457
6458 if (wdev->iftype != NL80211_IFTYPE_AP &&
6459 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6460 return -EOPNOTSUPP;
6461
6462 if (!info->attrs[NL80211_ATTR_MAC])
6463 return -EINVAL;
6464
6465 if (!rdev->ops->probe_client)
6466 return -EOPNOTSUPP;
6467
6468 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6469 if (!msg)
6470 return -ENOMEM;
6471
6472 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6473 NL80211_CMD_PROBE_CLIENT);
6474
6475 if (IS_ERR(hdr)) {
6476 err = PTR_ERR(hdr);
6477 goto free_msg;
6478 }
6479
6480 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6481
6482 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
6483 if (err)
6484 goto free_msg;
6485
9360ffd1
DM
6486 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6487 goto nla_put_failure;
7f6cf311
JB
6488
6489 genlmsg_end(msg, hdr);
6490
6491 return genlmsg_reply(msg, info);
6492
6493 nla_put_failure:
6494 err = -ENOBUFS;
6495 free_msg:
6496 nlmsg_free(msg);
6497 return err;
6498}
6499
5e760230
JB
6500static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
6501{
6502 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6503
6504 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
6505 return -EOPNOTSUPP;
6506
6507 if (rdev->ap_beacons_nlpid)
6508 return -EBUSY;
6509
6510 rdev->ap_beacons_nlpid = info->snd_pid;
6511
6512 return 0;
6513}
6514
4c476991
JB
6515#define NL80211_FLAG_NEED_WIPHY 0x01
6516#define NL80211_FLAG_NEED_NETDEV 0x02
6517#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
6518#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
6519#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
6520 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
6521
6522static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
6523 struct genl_info *info)
6524{
6525 struct cfg80211_registered_device *rdev;
6526 struct net_device *dev;
6527 int err;
6528 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
6529
6530 if (rtnl)
6531 rtnl_lock();
6532
6533 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
6534 rdev = cfg80211_get_dev_from_info(info);
6535 if (IS_ERR(rdev)) {
6536 if (rtnl)
6537 rtnl_unlock();
6538 return PTR_ERR(rdev);
6539 }
6540 info->user_ptr[0] = rdev;
6541 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
00918d33
JB
6542 err = get_rdev_dev_by_ifindex(genl_info_net(info), info->attrs,
6543 &rdev, &dev);
4c476991
JB
6544 if (err) {
6545 if (rtnl)
6546 rtnl_unlock();
6547 return err;
6548 }
41265714
JB
6549 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
6550 !netif_running(dev)) {
d537f5fd
JB
6551 cfg80211_unlock_rdev(rdev);
6552 dev_put(dev);
41265714
JB
6553 if (rtnl)
6554 rtnl_unlock();
6555 return -ENETDOWN;
6556 }
4c476991
JB
6557 info->user_ptr[0] = rdev;
6558 info->user_ptr[1] = dev;
6559 }
6560
6561 return 0;
6562}
6563
6564static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
6565 struct genl_info *info)
6566{
6567 if (info->user_ptr[0])
6568 cfg80211_unlock_rdev(info->user_ptr[0]);
6569 if (info->user_ptr[1])
6570 dev_put(info->user_ptr[1]);
6571 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
6572 rtnl_unlock();
6573}
6574
55682965
JB
6575static struct genl_ops nl80211_ops[] = {
6576 {
6577 .cmd = NL80211_CMD_GET_WIPHY,
6578 .doit = nl80211_get_wiphy,
6579 .dumpit = nl80211_dump_wiphy,
6580 .policy = nl80211_policy,
6581 /* can be retrieved by unprivileged users */
4c476991 6582 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
6583 },
6584 {
6585 .cmd = NL80211_CMD_SET_WIPHY,
6586 .doit = nl80211_set_wiphy,
6587 .policy = nl80211_policy,
6588 .flags = GENL_ADMIN_PERM,
4c476991 6589 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
6590 },
6591 {
6592 .cmd = NL80211_CMD_GET_INTERFACE,
6593 .doit = nl80211_get_interface,
6594 .dumpit = nl80211_dump_interface,
6595 .policy = nl80211_policy,
6596 /* can be retrieved by unprivileged users */
4c476991 6597 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
6598 },
6599 {
6600 .cmd = NL80211_CMD_SET_INTERFACE,
6601 .doit = nl80211_set_interface,
6602 .policy = nl80211_policy,
6603 .flags = GENL_ADMIN_PERM,
4c476991
JB
6604 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6605 NL80211_FLAG_NEED_RTNL,
55682965
JB
6606 },
6607 {
6608 .cmd = NL80211_CMD_NEW_INTERFACE,
6609 .doit = nl80211_new_interface,
6610 .policy = nl80211_policy,
6611 .flags = GENL_ADMIN_PERM,
4c476991
JB
6612 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6613 NL80211_FLAG_NEED_RTNL,
55682965
JB
6614 },
6615 {
6616 .cmd = NL80211_CMD_DEL_INTERFACE,
6617 .doit = nl80211_del_interface,
6618 .policy = nl80211_policy,
41ade00f 6619 .flags = GENL_ADMIN_PERM,
4c476991
JB
6620 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6621 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6622 },
6623 {
6624 .cmd = NL80211_CMD_GET_KEY,
6625 .doit = nl80211_get_key,
6626 .policy = nl80211_policy,
6627 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6628 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6629 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6630 },
6631 {
6632 .cmd = NL80211_CMD_SET_KEY,
6633 .doit = nl80211_set_key,
6634 .policy = nl80211_policy,
6635 .flags = GENL_ADMIN_PERM,
41265714 6636 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6637 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6638 },
6639 {
6640 .cmd = NL80211_CMD_NEW_KEY,
6641 .doit = nl80211_new_key,
6642 .policy = nl80211_policy,
6643 .flags = GENL_ADMIN_PERM,
41265714 6644 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6645 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6646 },
6647 {
6648 .cmd = NL80211_CMD_DEL_KEY,
6649 .doit = nl80211_del_key,
6650 .policy = nl80211_policy,
55682965 6651 .flags = GENL_ADMIN_PERM,
41265714 6652 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6653 NL80211_FLAG_NEED_RTNL,
55682965 6654 },
ed1b6cc7
JB
6655 {
6656 .cmd = NL80211_CMD_SET_BEACON,
6657 .policy = nl80211_policy,
6658 .flags = GENL_ADMIN_PERM,
8860020e 6659 .doit = nl80211_set_beacon,
2b5f8b0b 6660 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6661 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6662 },
6663 {
8860020e 6664 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
6665 .policy = nl80211_policy,
6666 .flags = GENL_ADMIN_PERM,
8860020e 6667 .doit = nl80211_start_ap,
2b5f8b0b 6668 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6669 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6670 },
6671 {
8860020e 6672 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
6673 .policy = nl80211_policy,
6674 .flags = GENL_ADMIN_PERM,
8860020e 6675 .doit = nl80211_stop_ap,
2b5f8b0b 6676 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6677 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6678 },
5727ef1b
JB
6679 {
6680 .cmd = NL80211_CMD_GET_STATION,
6681 .doit = nl80211_get_station,
2ec600d6 6682 .dumpit = nl80211_dump_station,
5727ef1b 6683 .policy = nl80211_policy,
4c476991
JB
6684 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6685 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6686 },
6687 {
6688 .cmd = NL80211_CMD_SET_STATION,
6689 .doit = nl80211_set_station,
6690 .policy = nl80211_policy,
6691 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6692 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6693 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6694 },
6695 {
6696 .cmd = NL80211_CMD_NEW_STATION,
6697 .doit = nl80211_new_station,
6698 .policy = nl80211_policy,
6699 .flags = GENL_ADMIN_PERM,
41265714 6700 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6701 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6702 },
6703 {
6704 .cmd = NL80211_CMD_DEL_STATION,
6705 .doit = nl80211_del_station,
6706 .policy = nl80211_policy,
2ec600d6 6707 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6708 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6709 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6710 },
6711 {
6712 .cmd = NL80211_CMD_GET_MPATH,
6713 .doit = nl80211_get_mpath,
6714 .dumpit = nl80211_dump_mpath,
6715 .policy = nl80211_policy,
6716 .flags = GENL_ADMIN_PERM,
41265714 6717 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6718 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6719 },
6720 {
6721 .cmd = NL80211_CMD_SET_MPATH,
6722 .doit = nl80211_set_mpath,
6723 .policy = nl80211_policy,
6724 .flags = GENL_ADMIN_PERM,
41265714 6725 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6726 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6727 },
6728 {
6729 .cmd = NL80211_CMD_NEW_MPATH,
6730 .doit = nl80211_new_mpath,
6731 .policy = nl80211_policy,
6732 .flags = GENL_ADMIN_PERM,
41265714 6733 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6734 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6735 },
6736 {
6737 .cmd = NL80211_CMD_DEL_MPATH,
6738 .doit = nl80211_del_mpath,
6739 .policy = nl80211_policy,
9f1ba906 6740 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6741 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6742 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6743 },
6744 {
6745 .cmd = NL80211_CMD_SET_BSS,
6746 .doit = nl80211_set_bss,
6747 .policy = nl80211_policy,
b2e1b302 6748 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6749 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6750 NL80211_FLAG_NEED_RTNL,
b2e1b302 6751 },
f130347c
LR
6752 {
6753 .cmd = NL80211_CMD_GET_REG,
6754 .doit = nl80211_get_reg,
6755 .policy = nl80211_policy,
6756 /* can be retrieved by unprivileged users */
6757 },
b2e1b302
LR
6758 {
6759 .cmd = NL80211_CMD_SET_REG,
6760 .doit = nl80211_set_reg,
6761 .policy = nl80211_policy,
6762 .flags = GENL_ADMIN_PERM,
6763 },
6764 {
6765 .cmd = NL80211_CMD_REQ_SET_REG,
6766 .doit = nl80211_req_set_reg,
6767 .policy = nl80211_policy,
93da9cc1 6768 .flags = GENL_ADMIN_PERM,
6769 },
6770 {
24bdd9f4
JC
6771 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6772 .doit = nl80211_get_mesh_config,
93da9cc1 6773 .policy = nl80211_policy,
6774 /* can be retrieved by unprivileged users */
2b5f8b0b 6775 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6776 NL80211_FLAG_NEED_RTNL,
93da9cc1 6777 },
6778 {
24bdd9f4
JC
6779 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6780 .doit = nl80211_update_mesh_config,
93da9cc1 6781 .policy = nl80211_policy,
9aed3cc1 6782 .flags = GENL_ADMIN_PERM,
29cbe68c 6783 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6784 NL80211_FLAG_NEED_RTNL,
9aed3cc1 6785 },
2a519311
JB
6786 {
6787 .cmd = NL80211_CMD_TRIGGER_SCAN,
6788 .doit = nl80211_trigger_scan,
6789 .policy = nl80211_policy,
6790 .flags = GENL_ADMIN_PERM,
41265714 6791 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6792 NL80211_FLAG_NEED_RTNL,
2a519311
JB
6793 },
6794 {
6795 .cmd = NL80211_CMD_GET_SCAN,
6796 .policy = nl80211_policy,
6797 .dumpit = nl80211_dump_scan,
6798 },
807f8a8c
LC
6799 {
6800 .cmd = NL80211_CMD_START_SCHED_SCAN,
6801 .doit = nl80211_start_sched_scan,
6802 .policy = nl80211_policy,
6803 .flags = GENL_ADMIN_PERM,
6804 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6805 NL80211_FLAG_NEED_RTNL,
6806 },
6807 {
6808 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6809 .doit = nl80211_stop_sched_scan,
6810 .policy = nl80211_policy,
6811 .flags = GENL_ADMIN_PERM,
6812 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6813 NL80211_FLAG_NEED_RTNL,
6814 },
636a5d36
JM
6815 {
6816 .cmd = NL80211_CMD_AUTHENTICATE,
6817 .doit = nl80211_authenticate,
6818 .policy = nl80211_policy,
6819 .flags = GENL_ADMIN_PERM,
41265714 6820 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6821 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6822 },
6823 {
6824 .cmd = NL80211_CMD_ASSOCIATE,
6825 .doit = nl80211_associate,
6826 .policy = nl80211_policy,
6827 .flags = GENL_ADMIN_PERM,
41265714 6828 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6829 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6830 },
6831 {
6832 .cmd = NL80211_CMD_DEAUTHENTICATE,
6833 .doit = nl80211_deauthenticate,
6834 .policy = nl80211_policy,
6835 .flags = GENL_ADMIN_PERM,
41265714 6836 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6837 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6838 },
6839 {
6840 .cmd = NL80211_CMD_DISASSOCIATE,
6841 .doit = nl80211_disassociate,
6842 .policy = nl80211_policy,
6843 .flags = GENL_ADMIN_PERM,
41265714 6844 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6845 NL80211_FLAG_NEED_RTNL,
636a5d36 6846 },
04a773ad
JB
6847 {
6848 .cmd = NL80211_CMD_JOIN_IBSS,
6849 .doit = nl80211_join_ibss,
6850 .policy = nl80211_policy,
6851 .flags = GENL_ADMIN_PERM,
41265714 6852 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6853 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
6854 },
6855 {
6856 .cmd = NL80211_CMD_LEAVE_IBSS,
6857 .doit = nl80211_leave_ibss,
6858 .policy = nl80211_policy,
6859 .flags = GENL_ADMIN_PERM,
41265714 6860 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6861 NL80211_FLAG_NEED_RTNL,
04a773ad 6862 },
aff89a9b
JB
6863#ifdef CONFIG_NL80211_TESTMODE
6864 {
6865 .cmd = NL80211_CMD_TESTMODE,
6866 .doit = nl80211_testmode_do,
71063f0e 6867 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
6868 .policy = nl80211_policy,
6869 .flags = GENL_ADMIN_PERM,
4c476991
JB
6870 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6871 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
6872 },
6873#endif
b23aa676
SO
6874 {
6875 .cmd = NL80211_CMD_CONNECT,
6876 .doit = nl80211_connect,
6877 .policy = nl80211_policy,
6878 .flags = GENL_ADMIN_PERM,
41265714 6879 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6880 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
6881 },
6882 {
6883 .cmd = NL80211_CMD_DISCONNECT,
6884 .doit = nl80211_disconnect,
6885 .policy = nl80211_policy,
6886 .flags = GENL_ADMIN_PERM,
41265714 6887 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6888 NL80211_FLAG_NEED_RTNL,
b23aa676 6889 },
463d0183
JB
6890 {
6891 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6892 .doit = nl80211_wiphy_netns,
6893 .policy = nl80211_policy,
6894 .flags = GENL_ADMIN_PERM,
4c476991
JB
6895 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6896 NL80211_FLAG_NEED_RTNL,
463d0183 6897 },
61fa713c
HS
6898 {
6899 .cmd = NL80211_CMD_GET_SURVEY,
6900 .policy = nl80211_policy,
6901 .dumpit = nl80211_dump_survey,
6902 },
67fbb16b
SO
6903 {
6904 .cmd = NL80211_CMD_SET_PMKSA,
6905 .doit = nl80211_setdel_pmksa,
6906 .policy = nl80211_policy,
6907 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6908 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6909 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6910 },
6911 {
6912 .cmd = NL80211_CMD_DEL_PMKSA,
6913 .doit = nl80211_setdel_pmksa,
6914 .policy = nl80211_policy,
6915 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6916 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6917 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6918 },
6919 {
6920 .cmd = NL80211_CMD_FLUSH_PMKSA,
6921 .doit = nl80211_flush_pmksa,
6922 .policy = nl80211_policy,
6923 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6924 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6925 NL80211_FLAG_NEED_RTNL,
67fbb16b 6926 },
9588bbd5
JM
6927 {
6928 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6929 .doit = nl80211_remain_on_channel,
6930 .policy = nl80211_policy,
6931 .flags = GENL_ADMIN_PERM,
41265714 6932 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6933 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
6934 },
6935 {
6936 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6937 .doit = nl80211_cancel_remain_on_channel,
6938 .policy = nl80211_policy,
6939 .flags = GENL_ADMIN_PERM,
41265714 6940 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6941 NL80211_FLAG_NEED_RTNL,
9588bbd5 6942 },
13ae75b1
JM
6943 {
6944 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6945 .doit = nl80211_set_tx_bitrate_mask,
6946 .policy = nl80211_policy,
6947 .flags = GENL_ADMIN_PERM,
4c476991
JB
6948 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6949 NL80211_FLAG_NEED_RTNL,
13ae75b1 6950 },
026331c4 6951 {
2e161f78
JB
6952 .cmd = NL80211_CMD_REGISTER_FRAME,
6953 .doit = nl80211_register_mgmt,
026331c4
JM
6954 .policy = nl80211_policy,
6955 .flags = GENL_ADMIN_PERM,
4c476991
JB
6956 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6957 NL80211_FLAG_NEED_RTNL,
026331c4
JM
6958 },
6959 {
2e161f78
JB
6960 .cmd = NL80211_CMD_FRAME,
6961 .doit = nl80211_tx_mgmt,
026331c4 6962 .policy = nl80211_policy,
f7ca38df
JB
6963 .flags = GENL_ADMIN_PERM,
6964 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6965 NL80211_FLAG_NEED_RTNL,
6966 },
6967 {
6968 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6969 .doit = nl80211_tx_mgmt_cancel_wait,
6970 .policy = nl80211_policy,
026331c4 6971 .flags = GENL_ADMIN_PERM,
41265714 6972 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6973 NL80211_FLAG_NEED_RTNL,
026331c4 6974 },
ffb9eb3d
KV
6975 {
6976 .cmd = NL80211_CMD_SET_POWER_SAVE,
6977 .doit = nl80211_set_power_save,
6978 .policy = nl80211_policy,
6979 .flags = GENL_ADMIN_PERM,
4c476991
JB
6980 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6981 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
6982 },
6983 {
6984 .cmd = NL80211_CMD_GET_POWER_SAVE,
6985 .doit = nl80211_get_power_save,
6986 .policy = nl80211_policy,
6987 /* can be retrieved by unprivileged users */
4c476991
JB
6988 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6989 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 6990 },
d6dc1a38
JO
6991 {
6992 .cmd = NL80211_CMD_SET_CQM,
6993 .doit = nl80211_set_cqm,
6994 .policy = nl80211_policy,
6995 .flags = GENL_ADMIN_PERM,
4c476991
JB
6996 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6997 NL80211_FLAG_NEED_RTNL,
d6dc1a38 6998 },
f444de05
JB
6999 {
7000 .cmd = NL80211_CMD_SET_CHANNEL,
7001 .doit = nl80211_set_channel,
7002 .policy = nl80211_policy,
7003 .flags = GENL_ADMIN_PERM,
4c476991
JB
7004 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7005 NL80211_FLAG_NEED_RTNL,
f444de05 7006 },
e8347eba
BJ
7007 {
7008 .cmd = NL80211_CMD_SET_WDS_PEER,
7009 .doit = nl80211_set_wds_peer,
7010 .policy = nl80211_policy,
7011 .flags = GENL_ADMIN_PERM,
43b19952
JB
7012 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7013 NL80211_FLAG_NEED_RTNL,
e8347eba 7014 },
29cbe68c
JB
7015 {
7016 .cmd = NL80211_CMD_JOIN_MESH,
7017 .doit = nl80211_join_mesh,
7018 .policy = nl80211_policy,
7019 .flags = GENL_ADMIN_PERM,
7020 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7021 NL80211_FLAG_NEED_RTNL,
7022 },
7023 {
7024 .cmd = NL80211_CMD_LEAVE_MESH,
7025 .doit = nl80211_leave_mesh,
7026 .policy = nl80211_policy,
7027 .flags = GENL_ADMIN_PERM,
7028 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7029 NL80211_FLAG_NEED_RTNL,
7030 },
ff1b6e69
JB
7031 {
7032 .cmd = NL80211_CMD_GET_WOWLAN,
7033 .doit = nl80211_get_wowlan,
7034 .policy = nl80211_policy,
7035 /* can be retrieved by unprivileged users */
7036 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7037 NL80211_FLAG_NEED_RTNL,
7038 },
7039 {
7040 .cmd = NL80211_CMD_SET_WOWLAN,
7041 .doit = nl80211_set_wowlan,
7042 .policy = nl80211_policy,
7043 .flags = GENL_ADMIN_PERM,
7044 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7045 NL80211_FLAG_NEED_RTNL,
7046 },
e5497d76
JB
7047 {
7048 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7049 .doit = nl80211_set_rekey_data,
7050 .policy = nl80211_policy,
7051 .flags = GENL_ADMIN_PERM,
7052 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7053 NL80211_FLAG_NEED_RTNL,
7054 },
109086ce
AN
7055 {
7056 .cmd = NL80211_CMD_TDLS_MGMT,
7057 .doit = nl80211_tdls_mgmt,
7058 .policy = nl80211_policy,
7059 .flags = GENL_ADMIN_PERM,
7060 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7061 NL80211_FLAG_NEED_RTNL,
7062 },
7063 {
7064 .cmd = NL80211_CMD_TDLS_OPER,
7065 .doit = nl80211_tdls_oper,
7066 .policy = nl80211_policy,
7067 .flags = GENL_ADMIN_PERM,
7068 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7069 NL80211_FLAG_NEED_RTNL,
7070 },
28946da7
JB
7071 {
7072 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7073 .doit = nl80211_register_unexpected_frame,
7074 .policy = nl80211_policy,
7075 .flags = GENL_ADMIN_PERM,
7076 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7077 NL80211_FLAG_NEED_RTNL,
7078 },
7f6cf311
JB
7079 {
7080 .cmd = NL80211_CMD_PROBE_CLIENT,
7081 .doit = nl80211_probe_client,
7082 .policy = nl80211_policy,
7083 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7084 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7085 NL80211_FLAG_NEED_RTNL,
7086 },
5e760230
JB
7087 {
7088 .cmd = NL80211_CMD_REGISTER_BEACONS,
7089 .doit = nl80211_register_beacons,
7090 .policy = nl80211_policy,
7091 .flags = GENL_ADMIN_PERM,
7092 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7093 NL80211_FLAG_NEED_RTNL,
7094 },
1d9d9213
SW
7095 {
7096 .cmd = NL80211_CMD_SET_NOACK_MAP,
7097 .doit = nl80211_set_noack_map,
7098 .policy = nl80211_policy,
7099 .flags = GENL_ADMIN_PERM,
7100 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7101 NL80211_FLAG_NEED_RTNL,
7102 },
7103
55682965 7104};
9588bbd5 7105
6039f6d2
JM
7106static struct genl_multicast_group nl80211_mlme_mcgrp = {
7107 .name = "mlme",
7108};
55682965
JB
7109
7110/* multicast groups */
7111static struct genl_multicast_group nl80211_config_mcgrp = {
7112 .name = "config",
7113};
2a519311
JB
7114static struct genl_multicast_group nl80211_scan_mcgrp = {
7115 .name = "scan",
7116};
73d54c9e
LR
7117static struct genl_multicast_group nl80211_regulatory_mcgrp = {
7118 .name = "regulatory",
7119};
55682965
JB
7120
7121/* notification functions */
7122
7123void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
7124{
7125 struct sk_buff *msg;
7126
fd2120ca 7127 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
7128 if (!msg)
7129 return;
7130
7131 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
7132 nlmsg_free(msg);
7133 return;
7134 }
7135
463d0183
JB
7136 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7137 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
7138}
7139
362a415d
JB
7140static int nl80211_add_scan_req(struct sk_buff *msg,
7141 struct cfg80211_registered_device *rdev)
7142{
7143 struct cfg80211_scan_request *req = rdev->scan_req;
7144 struct nlattr *nest;
7145 int i;
7146
667503dd
JB
7147 ASSERT_RDEV_LOCK(rdev);
7148
362a415d
JB
7149 if (WARN_ON(!req))
7150 return 0;
7151
7152 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
7153 if (!nest)
7154 goto nla_put_failure;
9360ffd1
DM
7155 for (i = 0; i < req->n_ssids; i++) {
7156 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
7157 goto nla_put_failure;
7158 }
362a415d
JB
7159 nla_nest_end(msg, nest);
7160
7161 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
7162 if (!nest)
7163 goto nla_put_failure;
9360ffd1
DM
7164 for (i = 0; i < req->n_channels; i++) {
7165 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
7166 goto nla_put_failure;
7167 }
362a415d
JB
7168 nla_nest_end(msg, nest);
7169
9360ffd1
DM
7170 if (req->ie &&
7171 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
7172 goto nla_put_failure;
362a415d
JB
7173
7174 return 0;
7175 nla_put_failure:
7176 return -ENOBUFS;
7177}
7178
a538e2d5
JB
7179static int nl80211_send_scan_msg(struct sk_buff *msg,
7180 struct cfg80211_registered_device *rdev,
7181 struct net_device *netdev,
7182 u32 pid, u32 seq, int flags,
7183 u32 cmd)
2a519311
JB
7184{
7185 void *hdr;
7186
7187 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
7188 if (!hdr)
7189 return -1;
7190
9360ffd1
DM
7191 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7192 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7193 goto nla_put_failure;
2a519311 7194
362a415d
JB
7195 /* ignore errors and send incomplete event anyway */
7196 nl80211_add_scan_req(msg, rdev);
2a519311
JB
7197
7198 return genlmsg_end(msg, hdr);
7199
7200 nla_put_failure:
7201 genlmsg_cancel(msg, hdr);
7202 return -EMSGSIZE;
7203}
7204
807f8a8c
LC
7205static int
7206nl80211_send_sched_scan_msg(struct sk_buff *msg,
7207 struct cfg80211_registered_device *rdev,
7208 struct net_device *netdev,
7209 u32 pid, u32 seq, int flags, u32 cmd)
7210{
7211 void *hdr;
7212
7213 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
7214 if (!hdr)
7215 return -1;
7216
9360ffd1
DM
7217 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7218 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7219 goto nla_put_failure;
807f8a8c
LC
7220
7221 return genlmsg_end(msg, hdr);
7222
7223 nla_put_failure:
7224 genlmsg_cancel(msg, hdr);
7225 return -EMSGSIZE;
7226}
7227
a538e2d5
JB
7228void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
7229 struct net_device *netdev)
7230{
7231 struct sk_buff *msg;
7232
7233 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7234 if (!msg)
7235 return;
7236
7237 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7238 NL80211_CMD_TRIGGER_SCAN) < 0) {
7239 nlmsg_free(msg);
7240 return;
7241 }
7242
463d0183
JB
7243 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7244 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
7245}
7246
2a519311
JB
7247void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
7248 struct net_device *netdev)
7249{
7250 struct sk_buff *msg;
7251
fd2120ca 7252 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7253 if (!msg)
7254 return;
7255
a538e2d5
JB
7256 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7257 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
7258 nlmsg_free(msg);
7259 return;
7260 }
7261
463d0183
JB
7262 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7263 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7264}
7265
7266void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
7267 struct net_device *netdev)
7268{
7269 struct sk_buff *msg;
7270
fd2120ca 7271 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7272 if (!msg)
7273 return;
7274
a538e2d5
JB
7275 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7276 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
7277 nlmsg_free(msg);
7278 return;
7279 }
7280
463d0183
JB
7281 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7282 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7283}
7284
807f8a8c
LC
7285void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7286 struct net_device *netdev)
7287{
7288 struct sk_buff *msg;
7289
7290 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7291 if (!msg)
7292 return;
7293
7294 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7295 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
7296 nlmsg_free(msg);
7297 return;
7298 }
7299
7300 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7301 nl80211_scan_mcgrp.id, GFP_KERNEL);
7302}
7303
7304void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
7305 struct net_device *netdev, u32 cmd)
7306{
7307 struct sk_buff *msg;
7308
7309 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7310 if (!msg)
7311 return;
7312
7313 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
7314 nlmsg_free(msg);
7315 return;
7316 }
7317
7318 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7319 nl80211_scan_mcgrp.id, GFP_KERNEL);
7320}
7321
73d54c9e
LR
7322/*
7323 * This can happen on global regulatory changes or device specific settings
7324 * based on custom world regulatory domains.
7325 */
7326void nl80211_send_reg_change_event(struct regulatory_request *request)
7327{
7328 struct sk_buff *msg;
7329 void *hdr;
7330
fd2120ca 7331 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
7332 if (!msg)
7333 return;
7334
7335 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
7336 if (!hdr) {
7337 nlmsg_free(msg);
7338 return;
7339 }
7340
7341 /* Userspace can always count this one always being set */
9360ffd1
DM
7342 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
7343 goto nla_put_failure;
7344
7345 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
7346 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7347 NL80211_REGDOM_TYPE_WORLD))
7348 goto nla_put_failure;
7349 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
7350 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7351 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
7352 goto nla_put_failure;
7353 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
7354 request->intersect) {
7355 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7356 NL80211_REGDOM_TYPE_INTERSECTION))
7357 goto nla_put_failure;
7358 } else {
7359 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7360 NL80211_REGDOM_TYPE_COUNTRY) ||
7361 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
7362 request->alpha2))
7363 goto nla_put_failure;
7364 }
7365
7366 if (wiphy_idx_valid(request->wiphy_idx) &&
7367 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
7368 goto nla_put_failure;
73d54c9e 7369
3b7b72ee 7370 genlmsg_end(msg, hdr);
73d54c9e 7371
bc43b28c 7372 rcu_read_lock();
463d0183 7373 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
7374 GFP_ATOMIC);
7375 rcu_read_unlock();
73d54c9e
LR
7376
7377 return;
7378
7379nla_put_failure:
7380 genlmsg_cancel(msg, hdr);
7381 nlmsg_free(msg);
7382}
7383
6039f6d2
JM
7384static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
7385 struct net_device *netdev,
7386 const u8 *buf, size_t len,
e6d6e342 7387 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
7388{
7389 struct sk_buff *msg;
7390 void *hdr;
7391
e6d6e342 7392 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
7393 if (!msg)
7394 return;
7395
7396 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7397 if (!hdr) {
7398 nlmsg_free(msg);
7399 return;
7400 }
7401
9360ffd1
DM
7402 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7403 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7404 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
7405 goto nla_put_failure;
6039f6d2 7406
3b7b72ee 7407 genlmsg_end(msg, hdr);
6039f6d2 7408
463d0183
JB
7409 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7410 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
7411 return;
7412
7413 nla_put_failure:
7414 genlmsg_cancel(msg, hdr);
7415 nlmsg_free(msg);
7416}
7417
7418void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7419 struct net_device *netdev, const u8 *buf,
7420 size_t len, gfp_t gfp)
6039f6d2
JM
7421{
7422 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7423 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
7424}
7425
7426void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
7427 struct net_device *netdev, const u8 *buf,
e6d6e342 7428 size_t len, gfp_t gfp)
6039f6d2 7429{
e6d6e342
JB
7430 nl80211_send_mlme_event(rdev, netdev, buf, len,
7431 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
7432}
7433
53b46b84 7434void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7435 struct net_device *netdev, const u8 *buf,
7436 size_t len, gfp_t gfp)
6039f6d2
JM
7437{
7438 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7439 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
7440}
7441
53b46b84
JM
7442void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
7443 struct net_device *netdev, const u8 *buf,
e6d6e342 7444 size_t len, gfp_t gfp)
6039f6d2
JM
7445{
7446 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7447 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
7448}
7449
cf4e594e
JM
7450void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
7451 struct net_device *netdev, const u8 *buf,
7452 size_t len, gfp_t gfp)
7453{
7454 nl80211_send_mlme_event(rdev, netdev, buf, len,
7455 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
7456}
7457
7458void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
7459 struct net_device *netdev, const u8 *buf,
7460 size_t len, gfp_t gfp)
7461{
7462 nl80211_send_mlme_event(rdev, netdev, buf, len,
7463 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
7464}
7465
1b06bb40
LR
7466static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
7467 struct net_device *netdev, int cmd,
e6d6e342 7468 const u8 *addr, gfp_t gfp)
1965c853
JM
7469{
7470 struct sk_buff *msg;
7471 void *hdr;
7472
e6d6e342 7473 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
7474 if (!msg)
7475 return;
7476
7477 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7478 if (!hdr) {
7479 nlmsg_free(msg);
7480 return;
7481 }
7482
9360ffd1
DM
7483 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7484 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7485 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
7486 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
7487 goto nla_put_failure;
1965c853 7488
3b7b72ee 7489 genlmsg_end(msg, hdr);
1965c853 7490
463d0183
JB
7491 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7492 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
7493 return;
7494
7495 nla_put_failure:
7496 genlmsg_cancel(msg, hdr);
7497 nlmsg_free(msg);
7498}
7499
7500void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7501 struct net_device *netdev, const u8 *addr,
7502 gfp_t gfp)
1965c853
JM
7503{
7504 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 7505 addr, gfp);
1965c853
JM
7506}
7507
7508void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7509 struct net_device *netdev, const u8 *addr,
7510 gfp_t gfp)
1965c853 7511{
e6d6e342
JB
7512 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
7513 addr, gfp);
1965c853
JM
7514}
7515
b23aa676
SO
7516void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
7517 struct net_device *netdev, const u8 *bssid,
7518 const u8 *req_ie, size_t req_ie_len,
7519 const u8 *resp_ie, size_t resp_ie_len,
7520 u16 status, gfp_t gfp)
7521{
7522 struct sk_buff *msg;
7523 void *hdr;
7524
7525 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7526 if (!msg)
7527 return;
7528
7529 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
7530 if (!hdr) {
7531 nlmsg_free(msg);
7532 return;
7533 }
7534
9360ffd1
DM
7535 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7536 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7537 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
7538 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
7539 (req_ie &&
7540 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
7541 (resp_ie &&
7542 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
7543 goto nla_put_failure;
b23aa676 7544
3b7b72ee 7545 genlmsg_end(msg, hdr);
b23aa676 7546
463d0183
JB
7547 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7548 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7549 return;
7550
7551 nla_put_failure:
7552 genlmsg_cancel(msg, hdr);
7553 nlmsg_free(msg);
7554
7555}
7556
7557void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
7558 struct net_device *netdev, const u8 *bssid,
7559 const u8 *req_ie, size_t req_ie_len,
7560 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
7561{
7562 struct sk_buff *msg;
7563 void *hdr;
7564
7565 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7566 if (!msg)
7567 return;
7568
7569 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
7570 if (!hdr) {
7571 nlmsg_free(msg);
7572 return;
7573 }
7574
9360ffd1
DM
7575 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7576 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7577 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
7578 (req_ie &&
7579 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
7580 (resp_ie &&
7581 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
7582 goto nla_put_failure;
b23aa676 7583
3b7b72ee 7584 genlmsg_end(msg, hdr);
b23aa676 7585
463d0183
JB
7586 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7587 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7588 return;
7589
7590 nla_put_failure:
7591 genlmsg_cancel(msg, hdr);
7592 nlmsg_free(msg);
7593
7594}
7595
7596void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
7597 struct net_device *netdev, u16 reason,
667503dd 7598 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
7599{
7600 struct sk_buff *msg;
7601 void *hdr;
7602
667503dd 7603 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
7604 if (!msg)
7605 return;
7606
7607 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
7608 if (!hdr) {
7609 nlmsg_free(msg);
7610 return;
7611 }
7612
9360ffd1
DM
7613 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7614 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7615 (from_ap && reason &&
7616 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
7617 (from_ap &&
7618 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
7619 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
7620 goto nla_put_failure;
b23aa676 7621
3b7b72ee 7622 genlmsg_end(msg, hdr);
b23aa676 7623
463d0183
JB
7624 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7625 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
7626 return;
7627
7628 nla_put_failure:
7629 genlmsg_cancel(msg, hdr);
7630 nlmsg_free(msg);
7631
7632}
7633
04a773ad
JB
7634void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7635 struct net_device *netdev, const u8 *bssid,
7636 gfp_t gfp)
7637{
7638 struct sk_buff *msg;
7639 void *hdr;
7640
fd2120ca 7641 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7642 if (!msg)
7643 return;
7644
7645 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7646 if (!hdr) {
7647 nlmsg_free(msg);
7648 return;
7649 }
7650
9360ffd1
DM
7651 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7652 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7653 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
7654 goto nla_put_failure;
04a773ad 7655
3b7b72ee 7656 genlmsg_end(msg, hdr);
04a773ad 7657
463d0183
JB
7658 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7659 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7660 return;
7661
7662 nla_put_failure:
7663 genlmsg_cancel(msg, hdr);
7664 nlmsg_free(msg);
7665}
7666
c93b5e71
JC
7667void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7668 struct net_device *netdev,
7669 const u8 *macaddr, const u8* ie, u8 ie_len,
7670 gfp_t gfp)
7671{
7672 struct sk_buff *msg;
7673 void *hdr;
7674
7675 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7676 if (!msg)
7677 return;
7678
7679 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7680 if (!hdr) {
7681 nlmsg_free(msg);
7682 return;
7683 }
7684
9360ffd1
DM
7685 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7686 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7687 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
7688 (ie_len && ie &&
7689 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
7690 goto nla_put_failure;
c93b5e71 7691
3b7b72ee 7692 genlmsg_end(msg, hdr);
c93b5e71
JC
7693
7694 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7695 nl80211_mlme_mcgrp.id, gfp);
7696 return;
7697
7698 nla_put_failure:
7699 genlmsg_cancel(msg, hdr);
7700 nlmsg_free(msg);
7701}
7702
a3b8b056
JM
7703void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7704 struct net_device *netdev, const u8 *addr,
7705 enum nl80211_key_type key_type, int key_id,
e6d6e342 7706 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7707{
7708 struct sk_buff *msg;
7709 void *hdr;
7710
e6d6e342 7711 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7712 if (!msg)
7713 return;
7714
7715 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7716 if (!hdr) {
7717 nlmsg_free(msg);
7718 return;
7719 }
7720
9360ffd1
DM
7721 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7722 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7723 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
7724 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
7725 (key_id != -1 &&
7726 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
7727 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
7728 goto nla_put_failure;
a3b8b056 7729
3b7b72ee 7730 genlmsg_end(msg, hdr);
a3b8b056 7731
463d0183
JB
7732 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7733 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7734 return;
7735
7736 nla_put_failure:
7737 genlmsg_cancel(msg, hdr);
7738 nlmsg_free(msg);
7739}
7740
6bad8766
LR
7741void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7742 struct ieee80211_channel *channel_before,
7743 struct ieee80211_channel *channel_after)
7744{
7745 struct sk_buff *msg;
7746 void *hdr;
7747 struct nlattr *nl_freq;
7748
fd2120ca 7749 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7750 if (!msg)
7751 return;
7752
7753 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7754 if (!hdr) {
7755 nlmsg_free(msg);
7756 return;
7757 }
7758
7759 /*
7760 * Since we are applying the beacon hint to a wiphy we know its
7761 * wiphy_idx is valid
7762 */
9360ffd1
DM
7763 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
7764 goto nla_put_failure;
6bad8766
LR
7765
7766 /* Before */
7767 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7768 if (!nl_freq)
7769 goto nla_put_failure;
7770 if (nl80211_msg_put_channel(msg, channel_before))
7771 goto nla_put_failure;
7772 nla_nest_end(msg, nl_freq);
7773
7774 /* After */
7775 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7776 if (!nl_freq)
7777 goto nla_put_failure;
7778 if (nl80211_msg_put_channel(msg, channel_after))
7779 goto nla_put_failure;
7780 nla_nest_end(msg, nl_freq);
7781
3b7b72ee 7782 genlmsg_end(msg, hdr);
6bad8766 7783
463d0183
JB
7784 rcu_read_lock();
7785 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7786 GFP_ATOMIC);
7787 rcu_read_unlock();
6bad8766
LR
7788
7789 return;
7790
7791nla_put_failure:
7792 genlmsg_cancel(msg, hdr);
7793 nlmsg_free(msg);
7794}
7795
9588bbd5
JM
7796static void nl80211_send_remain_on_chan_event(
7797 int cmd, struct cfg80211_registered_device *rdev,
7798 struct net_device *netdev, u64 cookie,
7799 struct ieee80211_channel *chan,
7800 enum nl80211_channel_type channel_type,
7801 unsigned int duration, gfp_t gfp)
7802{
7803 struct sk_buff *msg;
7804 void *hdr;
7805
7806 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7807 if (!msg)
7808 return;
7809
7810 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7811 if (!hdr) {
7812 nlmsg_free(msg);
7813 return;
7814 }
7815
9360ffd1
DM
7816 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7817 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7818 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
7819 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type) ||
7820 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7821 goto nla_put_failure;
9588bbd5 7822
9360ffd1
DM
7823 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
7824 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
7825 goto nla_put_failure;
9588bbd5 7826
3b7b72ee 7827 genlmsg_end(msg, hdr);
9588bbd5
JM
7828
7829 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7830 nl80211_mlme_mcgrp.id, gfp);
7831 return;
7832
7833 nla_put_failure:
7834 genlmsg_cancel(msg, hdr);
7835 nlmsg_free(msg);
7836}
7837
7838void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7839 struct net_device *netdev, u64 cookie,
7840 struct ieee80211_channel *chan,
7841 enum nl80211_channel_type channel_type,
7842 unsigned int duration, gfp_t gfp)
7843{
7844 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7845 rdev, netdev, cookie, chan,
7846 channel_type, duration, gfp);
7847}
7848
7849void nl80211_send_remain_on_channel_cancel(
7850 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7851 u64 cookie, struct ieee80211_channel *chan,
7852 enum nl80211_channel_type channel_type, gfp_t gfp)
7853{
7854 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7855 rdev, netdev, cookie, chan,
7856 channel_type, 0, gfp);
7857}
7858
98b62183
JB
7859void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7860 struct net_device *dev, const u8 *mac_addr,
7861 struct station_info *sinfo, gfp_t gfp)
7862{
7863 struct sk_buff *msg;
7864
7865 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7866 if (!msg)
7867 return;
7868
66266b3a
JL
7869 if (nl80211_send_station(msg, 0, 0, 0,
7870 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
7871 nlmsg_free(msg);
7872 return;
7873 }
7874
7875 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7876 nl80211_mlme_mcgrp.id, gfp);
7877}
7878
ec15e68b
JM
7879void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7880 struct net_device *dev, const u8 *mac_addr,
7881 gfp_t gfp)
7882{
7883 struct sk_buff *msg;
7884 void *hdr;
7885
7886 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7887 if (!msg)
7888 return;
7889
7890 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7891 if (!hdr) {
7892 nlmsg_free(msg);
7893 return;
7894 }
7895
9360ffd1
DM
7896 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
7897 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
7898 goto nla_put_failure;
ec15e68b 7899
3b7b72ee 7900 genlmsg_end(msg, hdr);
ec15e68b
JM
7901
7902 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7903 nl80211_mlme_mcgrp.id, gfp);
7904 return;
7905
7906 nla_put_failure:
7907 genlmsg_cancel(msg, hdr);
7908 nlmsg_free(msg);
7909}
7910
b92ab5d8
JB
7911static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
7912 const u8 *addr, gfp_t gfp)
28946da7
JB
7913{
7914 struct wireless_dev *wdev = dev->ieee80211_ptr;
7915 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7916 struct sk_buff *msg;
7917 void *hdr;
7918 int err;
7919 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7920
7921 if (!nlpid)
7922 return false;
7923
7924 msg = nlmsg_new(100, gfp);
7925 if (!msg)
7926 return true;
7927
b92ab5d8 7928 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
7929 if (!hdr) {
7930 nlmsg_free(msg);
7931 return true;
7932 }
7933
9360ffd1
DM
7934 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7935 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
7936 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
7937 goto nla_put_failure;
28946da7
JB
7938
7939 err = genlmsg_end(msg, hdr);
7940 if (err < 0) {
7941 nlmsg_free(msg);
7942 return true;
7943 }
7944
7945 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7946 return true;
7947
7948 nla_put_failure:
7949 genlmsg_cancel(msg, hdr);
7950 nlmsg_free(msg);
7951 return true;
7952}
7953
b92ab5d8
JB
7954bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7955{
7956 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
7957 addr, gfp);
7958}
7959
7960bool nl80211_unexpected_4addr_frame(struct net_device *dev,
7961 const u8 *addr, gfp_t gfp)
7962{
7963 return __nl80211_unexpected_frame(dev,
7964 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
7965 addr, gfp);
7966}
7967
2e161f78
JB
7968int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7969 struct net_device *netdev, u32 nlpid,
804483e9
JB
7970 int freq, int sig_dbm,
7971 const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
7972{
7973 struct sk_buff *msg;
7974 void *hdr;
026331c4
JM
7975
7976 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7977 if (!msg)
7978 return -ENOMEM;
7979
2e161f78 7980 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
7981 if (!hdr) {
7982 nlmsg_free(msg);
7983 return -ENOMEM;
7984 }
7985
9360ffd1
DM
7986 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7987 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7988 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
7989 (sig_dbm &&
7990 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
7991 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
7992 goto nla_put_failure;
026331c4 7993
3b7b72ee 7994 genlmsg_end(msg, hdr);
026331c4 7995
3b7b72ee 7996 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
7997
7998 nla_put_failure:
7999 genlmsg_cancel(msg, hdr);
8000 nlmsg_free(msg);
8001 return -ENOBUFS;
8002}
8003
2e161f78
JB
8004void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
8005 struct net_device *netdev, u64 cookie,
8006 const u8 *buf, size_t len, bool ack,
8007 gfp_t gfp)
026331c4
JM
8008{
8009 struct sk_buff *msg;
8010 void *hdr;
8011
8012 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8013 if (!msg)
8014 return;
8015
2e161f78 8016 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8017 if (!hdr) {
8018 nlmsg_free(msg);
8019 return;
8020 }
8021
9360ffd1
DM
8022 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8023 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8024 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8025 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8026 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8027 goto nla_put_failure;
026331c4 8028
3b7b72ee 8029 genlmsg_end(msg, hdr);
026331c4
JM
8030
8031 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8032 return;
8033
8034 nla_put_failure:
8035 genlmsg_cancel(msg, hdr);
8036 nlmsg_free(msg);
8037}
8038
d6dc1a38
JO
8039void
8040nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8041 struct net_device *netdev,
8042 enum nl80211_cqm_rssi_threshold_event rssi_event,
8043 gfp_t gfp)
8044{
8045 struct sk_buff *msg;
8046 struct nlattr *pinfoattr;
8047 void *hdr;
8048
8049 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8050 if (!msg)
8051 return;
8052
8053 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8054 if (!hdr) {
8055 nlmsg_free(msg);
8056 return;
8057 }
8058
9360ffd1
DM
8059 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8060 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8061 goto nla_put_failure;
d6dc1a38
JO
8062
8063 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8064 if (!pinfoattr)
8065 goto nla_put_failure;
8066
9360ffd1
DM
8067 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
8068 rssi_event))
8069 goto nla_put_failure;
d6dc1a38
JO
8070
8071 nla_nest_end(msg, pinfoattr);
8072
3b7b72ee 8073 genlmsg_end(msg, hdr);
d6dc1a38
JO
8074
8075 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8076 nl80211_mlme_mcgrp.id, gfp);
8077 return;
8078
8079 nla_put_failure:
8080 genlmsg_cancel(msg, hdr);
8081 nlmsg_free(msg);
8082}
8083
e5497d76
JB
8084void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
8085 struct net_device *netdev, const u8 *bssid,
8086 const u8 *replay_ctr, gfp_t gfp)
8087{
8088 struct sk_buff *msg;
8089 struct nlattr *rekey_attr;
8090 void *hdr;
8091
8092 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8093 if (!msg)
8094 return;
8095
8096 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
8097 if (!hdr) {
8098 nlmsg_free(msg);
8099 return;
8100 }
8101
9360ffd1
DM
8102 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8103 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8104 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8105 goto nla_put_failure;
e5497d76
JB
8106
8107 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
8108 if (!rekey_attr)
8109 goto nla_put_failure;
8110
9360ffd1
DM
8111 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
8112 NL80211_REPLAY_CTR_LEN, replay_ctr))
8113 goto nla_put_failure;
e5497d76
JB
8114
8115 nla_nest_end(msg, rekey_attr);
8116
3b7b72ee 8117 genlmsg_end(msg, hdr);
e5497d76
JB
8118
8119 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8120 nl80211_mlme_mcgrp.id, gfp);
8121 return;
8122
8123 nla_put_failure:
8124 genlmsg_cancel(msg, hdr);
8125 nlmsg_free(msg);
8126}
8127
c9df56b4
JM
8128void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
8129 struct net_device *netdev, int index,
8130 const u8 *bssid, bool preauth, gfp_t gfp)
8131{
8132 struct sk_buff *msg;
8133 struct nlattr *attr;
8134 void *hdr;
8135
8136 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8137 if (!msg)
8138 return;
8139
8140 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
8141 if (!hdr) {
8142 nlmsg_free(msg);
8143 return;
8144 }
8145
9360ffd1
DM
8146 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8147 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8148 goto nla_put_failure;
c9df56b4
JM
8149
8150 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
8151 if (!attr)
8152 goto nla_put_failure;
8153
9360ffd1
DM
8154 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
8155 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
8156 (preauth &&
8157 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
8158 goto nla_put_failure;
c9df56b4
JM
8159
8160 nla_nest_end(msg, attr);
8161
3b7b72ee 8162 genlmsg_end(msg, hdr);
c9df56b4
JM
8163
8164 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8165 nl80211_mlme_mcgrp.id, gfp);
8166 return;
8167
8168 nla_put_failure:
8169 genlmsg_cancel(msg, hdr);
8170 nlmsg_free(msg);
8171}
8172
5314526b
TP
8173void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
8174 struct net_device *netdev, int freq,
8175 enum nl80211_channel_type type, gfp_t gfp)
8176{
8177 struct sk_buff *msg;
8178 void *hdr;
8179
8180 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8181 if (!msg)
8182 return;
8183
8184 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
8185 if (!hdr) {
8186 nlmsg_free(msg);
8187 return;
8188 }
8189
7eab0f64
JL
8190 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8191 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8192 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, type))
8193 goto nla_put_failure;
5314526b
TP
8194
8195 genlmsg_end(msg, hdr);
8196
8197 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8198 nl80211_mlme_mcgrp.id, gfp);
8199 return;
8200
8201 nla_put_failure:
8202 genlmsg_cancel(msg, hdr);
8203 nlmsg_free(msg);
8204}
8205
c063dbf5
JB
8206void
8207nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
8208 struct net_device *netdev, const u8 *peer,
8209 u32 num_packets, gfp_t gfp)
8210{
8211 struct sk_buff *msg;
8212 struct nlattr *pinfoattr;
8213 void *hdr;
8214
8215 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8216 if (!msg)
8217 return;
8218
8219 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8220 if (!hdr) {
8221 nlmsg_free(msg);
8222 return;
8223 }
8224
9360ffd1
DM
8225 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8226 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8227 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
8228 goto nla_put_failure;
c063dbf5
JB
8229
8230 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8231 if (!pinfoattr)
8232 goto nla_put_failure;
8233
9360ffd1
DM
8234 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
8235 goto nla_put_failure;
c063dbf5
JB
8236
8237 nla_nest_end(msg, pinfoattr);
8238
3b7b72ee 8239 genlmsg_end(msg, hdr);
c063dbf5
JB
8240
8241 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8242 nl80211_mlme_mcgrp.id, gfp);
8243 return;
8244
8245 nla_put_failure:
8246 genlmsg_cancel(msg, hdr);
8247 nlmsg_free(msg);
8248}
8249
7f6cf311
JB
8250void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
8251 u64 cookie, bool acked, gfp_t gfp)
8252{
8253 struct wireless_dev *wdev = dev->ieee80211_ptr;
8254 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8255 struct sk_buff *msg;
8256 void *hdr;
8257 int err;
8258
8259 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8260 if (!msg)
8261 return;
8262
8263 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
8264 if (!hdr) {
8265 nlmsg_free(msg);
8266 return;
8267 }
8268
9360ffd1
DM
8269 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8270 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8271 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
8272 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8273 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
8274 goto nla_put_failure;
7f6cf311
JB
8275
8276 err = genlmsg_end(msg, hdr);
8277 if (err < 0) {
8278 nlmsg_free(msg);
8279 return;
8280 }
8281
8282 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8283 nl80211_mlme_mcgrp.id, gfp);
8284 return;
8285
8286 nla_put_failure:
8287 genlmsg_cancel(msg, hdr);
8288 nlmsg_free(msg);
8289}
8290EXPORT_SYMBOL(cfg80211_probe_status);
8291
5e760230
JB
8292void cfg80211_report_obss_beacon(struct wiphy *wiphy,
8293 const u8 *frame, size_t len,
804483e9 8294 int freq, int sig_dbm, gfp_t gfp)
5e760230
JB
8295{
8296 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
8297 struct sk_buff *msg;
8298 void *hdr;
8299 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
8300
8301 if (!nlpid)
8302 return;
8303
8304 msg = nlmsg_new(len + 100, gfp);
8305 if (!msg)
8306 return;
8307
8308 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
8309 if (!hdr) {
8310 nlmsg_free(msg);
8311 return;
8312 }
8313
9360ffd1
DM
8314 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8315 (freq &&
8316 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
8317 (sig_dbm &&
8318 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8319 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
8320 goto nla_put_failure;
5e760230
JB
8321
8322 genlmsg_end(msg, hdr);
8323
8324 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
8325 return;
8326
8327 nla_put_failure:
8328 genlmsg_cancel(msg, hdr);
8329 nlmsg_free(msg);
8330}
8331EXPORT_SYMBOL(cfg80211_report_obss_beacon);
8332
026331c4
JM
8333static int nl80211_netlink_notify(struct notifier_block * nb,
8334 unsigned long state,
8335 void *_notify)
8336{
8337 struct netlink_notify *notify = _notify;
8338 struct cfg80211_registered_device *rdev;
8339 struct wireless_dev *wdev;
8340
8341 if (state != NETLINK_URELEASE)
8342 return NOTIFY_DONE;
8343
8344 rcu_read_lock();
8345
5e760230 8346 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
026331c4 8347 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 8348 cfg80211_mlme_unregister_socket(wdev, notify->pid);
5e760230
JB
8349 if (rdev->ap_beacons_nlpid == notify->pid)
8350 rdev->ap_beacons_nlpid = 0;
8351 }
026331c4
JM
8352
8353 rcu_read_unlock();
8354
8355 return NOTIFY_DONE;
8356}
8357
8358static struct notifier_block nl80211_netlink_notifier = {
8359 .notifier_call = nl80211_netlink_notify,
8360};
8361
55682965
JB
8362/* initialisation/exit functions */
8363
8364int nl80211_init(void)
8365{
0d63cbb5 8366 int err;
55682965 8367
0d63cbb5
MM
8368 err = genl_register_family_with_ops(&nl80211_fam,
8369 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
8370 if (err)
8371 return err;
8372
55682965
JB
8373 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
8374 if (err)
8375 goto err_out;
8376
2a519311
JB
8377 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
8378 if (err)
8379 goto err_out;
8380
73d54c9e
LR
8381 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
8382 if (err)
8383 goto err_out;
8384
6039f6d2
JM
8385 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
8386 if (err)
8387 goto err_out;
8388
aff89a9b
JB
8389#ifdef CONFIG_NL80211_TESTMODE
8390 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
8391 if (err)
8392 goto err_out;
8393#endif
8394
026331c4
JM
8395 err = netlink_register_notifier(&nl80211_netlink_notifier);
8396 if (err)
8397 goto err_out;
8398
55682965
JB
8399 return 0;
8400 err_out:
8401 genl_unregister_family(&nl80211_fam);
8402 return err;
8403}
8404
8405void nl80211_exit(void)
8406{
026331c4 8407 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
8408 genl_unregister_family(&nl80211_fam);
8409}