]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/wireless/nl80211.c
mac80211: send unexpected 4addr event
[mirror_ubuntu-bionic-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
79c97e97 49/* internal helper: get rdev and dev */
463d0183 50static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 51 struct cfg80211_registered_device **rdev,
55682965
JB
52 struct net_device **dev)
53{
463d0183 54 struct nlattr **attrs = info->attrs;
55682965
JB
55 int ifindex;
56
bba95fef 57 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
58 return -EINVAL;
59
bba95fef 60 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 61 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
62 if (!*dev)
63 return -ENODEV;
64
463d0183 65 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 66 if (IS_ERR(*rdev)) {
55682965 67 dev_put(*dev);
79c97e97 68 return PTR_ERR(*rdev);
55682965
JB
69 }
70
71 return 0;
72}
73
74/* policy for the attributes */
b54452b0 75static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
76 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
77 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 78 .len = 20-1 },
31888487 79 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 80 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 81 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
82 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
84 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
85 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 86 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
87
88 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
90 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
91
92 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 93 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 94
b9454e83 95 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
96 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
97 .len = WLAN_MAX_KEY_LEN },
98 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
99 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
100 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 101 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 102 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
103
104 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
105 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
106 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
107 .len = IEEE80211_MAX_DATA_LEN },
108 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
109 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
110 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
111 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
112 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
113 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
114 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 115 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 116 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 117 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
118 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
119 .len = IEEE80211_MAX_MESH_ID_LEN },
120 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 121
b2e1b302
LR
122 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
123 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
124
9f1ba906
JM
125 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
127 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
128 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
129 .len = NL80211_MAX_SUPP_RATES },
50b12f59 130 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 131
24bdd9f4 132 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 133 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 134
6c739419 135 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
136
137 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
138 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
140 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
141 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
142
143 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
144 .len = IEEE80211_MAX_SSID_LEN },
145 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
146 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 147 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 148 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 149 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
150 [NL80211_ATTR_STA_FLAGS2] = {
151 .len = sizeof(struct nl80211_sta_flag_update),
152 },
3f77316c 153 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
154 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
155 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
156 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
157 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
158 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 159 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 160 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
161 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
162 .len = WLAN_PMKID_LEN },
9588bbd5
JM
163 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
164 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 165 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
166 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
167 .len = IEEE80211_MAX_DATA_LEN },
168 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 169 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 170 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 171 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 172 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
173 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
174 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 175 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
176 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
177 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 178 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 179 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 180 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 181 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 182 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 183 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 184 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 185 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 186 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
187 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
188 .len = IEEE80211_MAX_DATA_LEN },
189 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
190 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 191 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 192 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 193 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
194 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
197 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
198 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
55682965
JB
199};
200
e31b8213 201/* policy for the key attributes */
b54452b0 202static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 203 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
204 [NL80211_KEY_IDX] = { .type = NLA_U8 },
205 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 206 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
207 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
208 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 209 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
210 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
211};
212
213/* policy for the key default flags */
214static const struct nla_policy
215nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
216 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
217 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
218};
219
ff1b6e69
JB
220/* policy for WoWLAN attributes */
221static const struct nla_policy
222nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
223 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
224 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
225 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
226 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
227 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
228 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
229 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
230 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
231};
232
e5497d76
JB
233/* policy for GTK rekey offload attributes */
234static const struct nla_policy
235nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
236 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
237 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
238 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
239};
240
a1f1c21c
LC
241static const struct nla_policy
242nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
243 [NL80211_ATTR_SCHED_SCAN_MATCH_SSID] = { .type = NLA_BINARY,
244 .len = IEEE80211_MAX_SSID_LEN },
245};
246
a043897a
HS
247/* ifidx get helper */
248static int nl80211_get_ifidx(struct netlink_callback *cb)
249{
250 int res;
251
252 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
253 nl80211_fam.attrbuf, nl80211_fam.maxattr,
254 nl80211_policy);
255 if (res)
256 return res;
257
258 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
259 return -EINVAL;
260
261 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
262 if (!res)
263 return -EINVAL;
264 return res;
265}
266
67748893
JB
267static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
268 struct netlink_callback *cb,
269 struct cfg80211_registered_device **rdev,
270 struct net_device **dev)
271{
272 int ifidx = cb->args[0];
273 int err;
274
275 if (!ifidx)
276 ifidx = nl80211_get_ifidx(cb);
277 if (ifidx < 0)
278 return ifidx;
279
280 cb->args[0] = ifidx;
281
282 rtnl_lock();
283
284 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
285 if (!*dev) {
286 err = -ENODEV;
287 goto out_rtnl;
288 }
289
290 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
291 if (IS_ERR(*rdev)) {
292 err = PTR_ERR(*rdev);
67748893
JB
293 goto out_rtnl;
294 }
295
296 return 0;
297 out_rtnl:
298 rtnl_unlock();
299 return err;
300}
301
302static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
303{
304 cfg80211_unlock_rdev(rdev);
305 rtnl_unlock();
306}
307
f4a11bb0
JB
308/* IE validation */
309static bool is_valid_ie_attr(const struct nlattr *attr)
310{
311 const u8 *pos;
312 int len;
313
314 if (!attr)
315 return true;
316
317 pos = nla_data(attr);
318 len = nla_len(attr);
319
320 while (len) {
321 u8 elemlen;
322
323 if (len < 2)
324 return false;
325 len -= 2;
326
327 elemlen = pos[1];
328 if (elemlen > len)
329 return false;
330
331 len -= elemlen;
332 pos += 2 + elemlen;
333 }
334
335 return true;
336}
337
55682965
JB
338/* message building helper */
339static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
340 int flags, u8 cmd)
341{
342 /* since there is no private header just add the generic one */
343 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
344}
345
5dab3b8a
LR
346static int nl80211_msg_put_channel(struct sk_buff *msg,
347 struct ieee80211_channel *chan)
348{
349 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
350 chan->center_freq);
351
352 if (chan->flags & IEEE80211_CHAN_DISABLED)
353 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
354 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
355 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
356 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
357 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
358 if (chan->flags & IEEE80211_CHAN_RADAR)
359 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
360
361 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
362 DBM_TO_MBM(chan->max_power));
363
364 return 0;
365
366 nla_put_failure:
367 return -ENOBUFS;
368}
369
55682965
JB
370/* netlink command implementations */
371
b9454e83
JB
372struct key_parse {
373 struct key_params p;
374 int idx;
e31b8213 375 int type;
b9454e83 376 bool def, defmgmt;
dbd2fd65 377 bool def_uni, def_multi;
b9454e83
JB
378};
379
380static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
381{
382 struct nlattr *tb[NL80211_KEY_MAX + 1];
383 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
384 nl80211_key_policy);
385 if (err)
386 return err;
387
388 k->def = !!tb[NL80211_KEY_DEFAULT];
389 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
390
dbd2fd65
JB
391 if (k->def) {
392 k->def_uni = true;
393 k->def_multi = true;
394 }
395 if (k->defmgmt)
396 k->def_multi = true;
397
b9454e83
JB
398 if (tb[NL80211_KEY_IDX])
399 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
400
401 if (tb[NL80211_KEY_DATA]) {
402 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
403 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
404 }
405
406 if (tb[NL80211_KEY_SEQ]) {
407 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
408 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
409 }
410
411 if (tb[NL80211_KEY_CIPHER])
412 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
413
e31b8213
JB
414 if (tb[NL80211_KEY_TYPE]) {
415 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
416 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
417 return -EINVAL;
418 }
419
dbd2fd65
JB
420 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
421 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
422 int err = nla_parse_nested(kdt,
423 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
424 tb[NL80211_KEY_DEFAULT_TYPES],
425 nl80211_key_default_policy);
426 if (err)
427 return err;
428
429 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
430 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
431 }
432
b9454e83
JB
433 return 0;
434}
435
436static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
437{
438 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
439 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
440 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
441 }
442
443 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
444 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
445 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
446 }
447
448 if (info->attrs[NL80211_ATTR_KEY_IDX])
449 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
450
451 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
452 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
453
454 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
455 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
456
dbd2fd65
JB
457 if (k->def) {
458 k->def_uni = true;
459 k->def_multi = true;
460 }
461 if (k->defmgmt)
462 k->def_multi = true;
463
e31b8213
JB
464 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
465 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
466 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
467 return -EINVAL;
468 }
469
dbd2fd65
JB
470 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
471 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
472 int err = nla_parse_nested(
473 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
474 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
475 nl80211_key_default_policy);
476 if (err)
477 return err;
478
479 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
480 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
481 }
482
b9454e83
JB
483 return 0;
484}
485
486static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
487{
488 int err;
489
490 memset(k, 0, sizeof(*k));
491 k->idx = -1;
e31b8213 492 k->type = -1;
b9454e83
JB
493
494 if (info->attrs[NL80211_ATTR_KEY])
495 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
496 else
497 err = nl80211_parse_key_old(info, k);
498
499 if (err)
500 return err;
501
502 if (k->def && k->defmgmt)
503 return -EINVAL;
504
dbd2fd65
JB
505 if (k->defmgmt) {
506 if (k->def_uni || !k->def_multi)
507 return -EINVAL;
508 }
509
b9454e83
JB
510 if (k->idx != -1) {
511 if (k->defmgmt) {
512 if (k->idx < 4 || k->idx > 5)
513 return -EINVAL;
514 } else if (k->def) {
515 if (k->idx < 0 || k->idx > 3)
516 return -EINVAL;
517 } else {
518 if (k->idx < 0 || k->idx > 5)
519 return -EINVAL;
520 }
521 }
522
523 return 0;
524}
525
fffd0934
JB
526static struct cfg80211_cached_keys *
527nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
528 struct nlattr *keys)
529{
530 struct key_parse parse;
531 struct nlattr *key;
532 struct cfg80211_cached_keys *result;
533 int rem, err, def = 0;
534
535 result = kzalloc(sizeof(*result), GFP_KERNEL);
536 if (!result)
537 return ERR_PTR(-ENOMEM);
538
539 result->def = -1;
540 result->defmgmt = -1;
541
542 nla_for_each_nested(key, keys, rem) {
543 memset(&parse, 0, sizeof(parse));
544 parse.idx = -1;
545
546 err = nl80211_parse_key_new(key, &parse);
547 if (err)
548 goto error;
549 err = -EINVAL;
550 if (!parse.p.key)
551 goto error;
552 if (parse.idx < 0 || parse.idx > 4)
553 goto error;
554 if (parse.def) {
555 if (def)
556 goto error;
557 def = 1;
558 result->def = parse.idx;
dbd2fd65
JB
559 if (!parse.def_uni || !parse.def_multi)
560 goto error;
fffd0934
JB
561 } else if (parse.defmgmt)
562 goto error;
563 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 564 parse.idx, false, NULL);
fffd0934
JB
565 if (err)
566 goto error;
567 result->params[parse.idx].cipher = parse.p.cipher;
568 result->params[parse.idx].key_len = parse.p.key_len;
569 result->params[parse.idx].key = result->data[parse.idx];
570 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
571 }
572
573 return result;
574 error:
575 kfree(result);
576 return ERR_PTR(err);
577}
578
579static int nl80211_key_allowed(struct wireless_dev *wdev)
580{
581 ASSERT_WDEV_LOCK(wdev);
582
fffd0934
JB
583 switch (wdev->iftype) {
584 case NL80211_IFTYPE_AP:
585 case NL80211_IFTYPE_AP_VLAN:
074ac8df 586 case NL80211_IFTYPE_P2P_GO:
ff973af7 587 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
588 break;
589 case NL80211_IFTYPE_ADHOC:
590 if (!wdev->current_bss)
591 return -ENOLINK;
592 break;
593 case NL80211_IFTYPE_STATION:
074ac8df 594 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
595 if (wdev->sme_state != CFG80211_SME_CONNECTED)
596 return -ENOLINK;
597 break;
598 default:
599 return -EINVAL;
600 }
601
602 return 0;
603}
604
7527a782
JB
605static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
606{
607 struct nlattr *nl_modes = nla_nest_start(msg, attr);
608 int i;
609
610 if (!nl_modes)
611 goto nla_put_failure;
612
613 i = 0;
614 while (ifmodes) {
615 if (ifmodes & 1)
616 NLA_PUT_FLAG(msg, i);
617 ifmodes >>= 1;
618 i++;
619 }
620
621 nla_nest_end(msg, nl_modes);
622 return 0;
623
624nla_put_failure:
625 return -ENOBUFS;
626}
627
628static int nl80211_put_iface_combinations(struct wiphy *wiphy,
629 struct sk_buff *msg)
630{
631 struct nlattr *nl_combis;
632 int i, j;
633
634 nl_combis = nla_nest_start(msg,
635 NL80211_ATTR_INTERFACE_COMBINATIONS);
636 if (!nl_combis)
637 goto nla_put_failure;
638
639 for (i = 0; i < wiphy->n_iface_combinations; i++) {
640 const struct ieee80211_iface_combination *c;
641 struct nlattr *nl_combi, *nl_limits;
642
643 c = &wiphy->iface_combinations[i];
644
645 nl_combi = nla_nest_start(msg, i + 1);
646 if (!nl_combi)
647 goto nla_put_failure;
648
649 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
650 if (!nl_limits)
651 goto nla_put_failure;
652
653 for (j = 0; j < c->n_limits; j++) {
654 struct nlattr *nl_limit;
655
656 nl_limit = nla_nest_start(msg, j + 1);
657 if (!nl_limit)
658 goto nla_put_failure;
659 NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
660 c->limits[j].max);
661 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
662 c->limits[j].types))
663 goto nla_put_failure;
664 nla_nest_end(msg, nl_limit);
665 }
666
667 nla_nest_end(msg, nl_limits);
668
669 if (c->beacon_int_infra_match)
670 NLA_PUT_FLAG(msg,
671 NL80211_IFACE_COMB_STA_AP_BI_MATCH);
672 NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
673 c->num_different_channels);
674 NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
675 c->max_interfaces);
676
677 nla_nest_end(msg, nl_combi);
678 }
679
680 nla_nest_end(msg, nl_combis);
681
682 return 0;
683nla_put_failure:
684 return -ENOBUFS;
685}
686
55682965
JB
687static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
688 struct cfg80211_registered_device *dev)
689{
690 void *hdr;
ee688b00
JB
691 struct nlattr *nl_bands, *nl_band;
692 struct nlattr *nl_freqs, *nl_freq;
693 struct nlattr *nl_rates, *nl_rate;
8fdc621d 694 struct nlattr *nl_cmds;
ee688b00
JB
695 enum ieee80211_band band;
696 struct ieee80211_channel *chan;
697 struct ieee80211_rate *rate;
698 int i;
2e161f78
JB
699 const struct ieee80211_txrx_stypes *mgmt_stypes =
700 dev->wiphy.mgmt_stypes;
55682965
JB
701
702 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
703 if (!hdr)
704 return -1;
705
b5850a7a 706 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 707 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 708
f5ea9120
JB
709 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
710 cfg80211_rdev_list_generation);
711
b9a5f8ca
JM
712 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
713 dev->wiphy.retry_short);
714 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
715 dev->wiphy.retry_long);
716 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
717 dev->wiphy.frag_threshold);
718 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
719 dev->wiphy.rts_threshold);
81077e82
LT
720 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
721 dev->wiphy.coverage_class);
2a519311
JB
722 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
723 dev->wiphy.max_scan_ssids);
93b6aa69
LC
724 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
725 dev->wiphy.max_sched_scan_ssids);
18a83659
JB
726 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
727 dev->wiphy.max_scan_ie_len);
5a865bad
LC
728 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
729 dev->wiphy.max_sched_scan_ie_len);
a1f1c21c
LC
730 NLA_PUT_U8(msg, NL80211_ATTR_MAX_MATCH_SETS,
731 dev->wiphy.max_match_sets);
ee688b00 732
e31b8213
JB
733 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
734 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
735 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
736 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
cedb5412
EP
737 if (dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD)
738 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_AP_UAPSD);
f4b34b55
VN
739 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)
740 NLA_PUT_FLAG(msg, NL80211_ATTR_ROAM_SUPPORT);
109086ce
AN
741 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)
742 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_SUPPORT);
743 if (dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)
744 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP);
f4b34b55 745
25e47c18
JB
746 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
747 sizeof(u32) * dev->wiphy.n_cipher_suites,
748 dev->wiphy.cipher_suites);
749
67fbb16b
SO
750 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
751 dev->wiphy.max_num_pmkids);
752
c0692b8f
JB
753 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
754 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
755
39fd5de4
BR
756 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
757 dev->wiphy.available_antennas_tx);
758 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
759 dev->wiphy.available_antennas_rx);
760
7f531e03
BR
761 if ((dev->wiphy.available_antennas_tx ||
762 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
763 u32 tx_ant = 0, rx_ant = 0;
764 int res;
765 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
766 if (!res) {
767 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
768 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
769 }
770 }
771
7527a782
JB
772 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
773 dev->wiphy.interface_modes))
f59ac048
LR
774 goto nla_put_failure;
775
ee688b00
JB
776 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
777 if (!nl_bands)
778 goto nla_put_failure;
779
780 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
781 if (!dev->wiphy.bands[band])
782 continue;
783
784 nl_band = nla_nest_start(msg, band);
785 if (!nl_band)
786 goto nla_put_failure;
787
d51626df
JB
788 /* add HT info */
789 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
790 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
791 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
792 &dev->wiphy.bands[band]->ht_cap.mcs);
793 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
794 dev->wiphy.bands[band]->ht_cap.cap);
795 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
796 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
797 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
798 dev->wiphy.bands[band]->ht_cap.ampdu_density);
799 }
800
ee688b00
JB
801 /* add frequencies */
802 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
803 if (!nl_freqs)
804 goto nla_put_failure;
805
806 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
807 nl_freq = nla_nest_start(msg, i);
808 if (!nl_freq)
809 goto nla_put_failure;
810
811 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
812
813 if (nl80211_msg_put_channel(msg, chan))
814 goto nla_put_failure;
e2f367f2 815
ee688b00
JB
816 nla_nest_end(msg, nl_freq);
817 }
818
819 nla_nest_end(msg, nl_freqs);
820
821 /* add bitrates */
822 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
823 if (!nl_rates)
824 goto nla_put_failure;
825
826 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
827 nl_rate = nla_nest_start(msg, i);
828 if (!nl_rate)
829 goto nla_put_failure;
830
831 rate = &dev->wiphy.bands[band]->bitrates[i];
832 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
833 rate->bitrate);
834 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
835 NLA_PUT_FLAG(msg,
836 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
837
838 nla_nest_end(msg, nl_rate);
839 }
840
841 nla_nest_end(msg, nl_rates);
842
843 nla_nest_end(msg, nl_band);
844 }
845 nla_nest_end(msg, nl_bands);
846
8fdc621d
JB
847 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
848 if (!nl_cmds)
849 goto nla_put_failure;
850
851 i = 0;
852#define CMD(op, n) \
853 do { \
854 if (dev->ops->op) { \
855 i++; \
856 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
857 } \
858 } while (0)
859
860 CMD(add_virtual_intf, NEW_INTERFACE);
861 CMD(change_virtual_intf, SET_INTERFACE);
862 CMD(add_key, NEW_KEY);
863 CMD(add_beacon, NEW_BEACON);
864 CMD(add_station, NEW_STATION);
865 CMD(add_mpath, NEW_MPATH);
24bdd9f4 866 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 867 CMD(change_bss, SET_BSS);
636a5d36
JM
868 CMD(auth, AUTHENTICATE);
869 CMD(assoc, ASSOCIATE);
870 CMD(deauth, DEAUTHENTICATE);
871 CMD(disassoc, DISASSOCIATE);
04a773ad 872 CMD(join_ibss, JOIN_IBSS);
29cbe68c 873 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
874 CMD(set_pmksa, SET_PMKSA);
875 CMD(del_pmksa, DEL_PMKSA);
876 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 877 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 878 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 879 CMD(mgmt_tx, FRAME);
f7ca38df 880 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 881 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
882 i++;
883 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
884 }
f444de05 885 CMD(set_channel, SET_CHANNEL);
e8347eba 886 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
887 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
888 CMD(tdls_mgmt, TDLS_MGMT);
889 CMD(tdls_oper, TDLS_OPER);
890 }
807f8a8c
LC
891 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
892 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 893 CMD(probe_client, PROBE_CLIENT);
5e760230
JB
894 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
895 i++;
896 NLA_PUT_U32(msg, i, NL80211_CMD_REGISTER_BEACONS);
897 }
8fdc621d
JB
898
899#undef CMD
b23aa676 900
6829c878 901 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
902 i++;
903 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
904 }
905
6829c878 906 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
907 i++;
908 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
909 }
910
8fdc621d
JB
911 nla_nest_end(msg, nl_cmds);
912
a293911d
JB
913 if (dev->ops->remain_on_channel)
914 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
915 dev->wiphy.max_remain_on_channel_duration);
916
d2da5878 917 if (dev->ops->mgmt_tx_cancel_wait)
f7ca38df
JB
918 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
919
2e161f78
JB
920 if (mgmt_stypes) {
921 u16 stypes;
922 struct nlattr *nl_ftypes, *nl_ifs;
923 enum nl80211_iftype ift;
924
925 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
926 if (!nl_ifs)
927 goto nla_put_failure;
928
929 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
930 nl_ftypes = nla_nest_start(msg, ift);
931 if (!nl_ftypes)
932 goto nla_put_failure;
933 i = 0;
934 stypes = mgmt_stypes[ift].tx;
935 while (stypes) {
936 if (stypes & 1)
937 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
938 (i << 4) | IEEE80211_FTYPE_MGMT);
939 stypes >>= 1;
940 i++;
941 }
942 nla_nest_end(msg, nl_ftypes);
943 }
944
74b70a4e
JB
945 nla_nest_end(msg, nl_ifs);
946
2e161f78
JB
947 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
948 if (!nl_ifs)
949 goto nla_put_failure;
950
951 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
952 nl_ftypes = nla_nest_start(msg, ift);
953 if (!nl_ftypes)
954 goto nla_put_failure;
955 i = 0;
956 stypes = mgmt_stypes[ift].rx;
957 while (stypes) {
958 if (stypes & 1)
959 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
960 (i << 4) | IEEE80211_FTYPE_MGMT);
961 stypes >>= 1;
962 i++;
963 }
964 nla_nest_end(msg, nl_ftypes);
965 }
966 nla_nest_end(msg, nl_ifs);
967 }
968
ff1b6e69
JB
969 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
970 struct nlattr *nl_wowlan;
971
972 nl_wowlan = nla_nest_start(msg,
973 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
974 if (!nl_wowlan)
975 goto nla_put_failure;
976
977 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
978 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
979 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
980 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
981 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
982 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
983 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
984 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
985 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
986 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
987 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
988 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
989 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
990 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
991 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
992 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
993 if (dev->wiphy.wowlan.n_patterns) {
994 struct nl80211_wowlan_pattern_support pat = {
995 .max_patterns = dev->wiphy.wowlan.n_patterns,
996 .min_pattern_len =
997 dev->wiphy.wowlan.pattern_min_len,
998 .max_pattern_len =
999 dev->wiphy.wowlan.pattern_max_len,
1000 };
1001 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1002 sizeof(pat), &pat);
1003 }
1004
1005 nla_nest_end(msg, nl_wowlan);
1006 }
1007
7527a782
JB
1008 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1009 dev->wiphy.software_iftypes))
1010 goto nla_put_failure;
1011
1012 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1013 goto nla_put_failure;
1014
562a7480
JB
1015 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME)
1016 NLA_PUT_U32(msg, NL80211_ATTR_DEVICE_AP_SME,
1017 dev->wiphy.ap_sme_capa);
1018
55682965
JB
1019 return genlmsg_end(msg, hdr);
1020
1021 nla_put_failure:
bc3ed28c
TG
1022 genlmsg_cancel(msg, hdr);
1023 return -EMSGSIZE;
55682965
JB
1024}
1025
1026static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1027{
1028 int idx = 0;
1029 int start = cb->args[0];
1030 struct cfg80211_registered_device *dev;
1031
a1794390 1032 mutex_lock(&cfg80211_mutex);
79c97e97 1033 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1034 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1035 continue;
b4637271 1036 if (++idx <= start)
55682965
JB
1037 continue;
1038 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1039 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1040 dev) < 0) {
1041 idx--;
55682965 1042 break;
b4637271 1043 }
55682965 1044 }
a1794390 1045 mutex_unlock(&cfg80211_mutex);
55682965
JB
1046
1047 cb->args[0] = idx;
1048
1049 return skb->len;
1050}
1051
1052static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1053{
1054 struct sk_buff *msg;
4c476991 1055 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1056
fd2120ca 1057 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1058 if (!msg)
4c476991 1059 return -ENOMEM;
55682965 1060
4c476991
JB
1061 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1062 nlmsg_free(msg);
1063 return -ENOBUFS;
1064 }
55682965 1065
134e6375 1066 return genlmsg_reply(msg, info);
55682965
JB
1067}
1068
31888487
JM
1069static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1070 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1071 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1072 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1073 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1074 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1075};
1076
1077static int parse_txq_params(struct nlattr *tb[],
1078 struct ieee80211_txq_params *txq_params)
1079{
1080 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
1081 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1082 !tb[NL80211_TXQ_ATTR_AIFS])
1083 return -EINVAL;
1084
1085 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
1086 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1087 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1088 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1089 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1090
1091 return 0;
1092}
1093
f444de05
JB
1094static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1095{
1096 /*
1097 * You can only set the channel explicitly for AP, mesh
1098 * and WDS type interfaces; all others have their channel
1099 * managed via their respective "establish a connection"
1100 * command (connect, join, ...)
1101 *
1102 * Monitors are special as they are normally slaved to
1103 * whatever else is going on, so they behave as though
1104 * you tried setting the wiphy channel itself.
1105 */
1106 return !wdev ||
1107 wdev->iftype == NL80211_IFTYPE_AP ||
1108 wdev->iftype == NL80211_IFTYPE_WDS ||
1109 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1110 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1111 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1112}
1113
1114static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1115 struct wireless_dev *wdev,
1116 struct genl_info *info)
1117{
1118 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1119 u32 freq;
1120 int result;
1121
1122 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1123 return -EINVAL;
1124
1125 if (!nl80211_can_set_dev_channel(wdev))
1126 return -EOPNOTSUPP;
1127
1128 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1129 channel_type = nla_get_u32(info->attrs[
1130 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1131 if (channel_type != NL80211_CHAN_NO_HT &&
1132 channel_type != NL80211_CHAN_HT20 &&
1133 channel_type != NL80211_CHAN_HT40PLUS &&
1134 channel_type != NL80211_CHAN_HT40MINUS)
1135 return -EINVAL;
1136 }
1137
1138 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1139
1140 mutex_lock(&rdev->devlist_mtx);
1141 if (wdev) {
1142 wdev_lock(wdev);
1143 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1144 wdev_unlock(wdev);
1145 } else {
1146 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1147 }
1148 mutex_unlock(&rdev->devlist_mtx);
1149
1150 return result;
1151}
1152
1153static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1154{
4c476991
JB
1155 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1156 struct net_device *netdev = info->user_ptr[1];
f444de05 1157
4c476991 1158 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1159}
1160
e8347eba
BJ
1161static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1162{
43b19952
JB
1163 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1164 struct net_device *dev = info->user_ptr[1];
1165 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1166 const u8 *bssid;
e8347eba
BJ
1167
1168 if (!info->attrs[NL80211_ATTR_MAC])
1169 return -EINVAL;
1170
43b19952
JB
1171 if (netif_running(dev))
1172 return -EBUSY;
e8347eba 1173
43b19952
JB
1174 if (!rdev->ops->set_wds_peer)
1175 return -EOPNOTSUPP;
e8347eba 1176
43b19952
JB
1177 if (wdev->iftype != NL80211_IFTYPE_WDS)
1178 return -EOPNOTSUPP;
e8347eba
BJ
1179
1180 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1181 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1182}
1183
1184
55682965
JB
1185static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1186{
1187 struct cfg80211_registered_device *rdev;
f444de05
JB
1188 struct net_device *netdev = NULL;
1189 struct wireless_dev *wdev;
a1e567c8 1190 int result = 0, rem_txq_params = 0;
31888487 1191 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1192 u32 changed;
1193 u8 retry_short = 0, retry_long = 0;
1194 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1195 u8 coverage_class = 0;
55682965 1196
f444de05
JB
1197 /*
1198 * Try to find the wiphy and netdev. Normally this
1199 * function shouldn't need the netdev, but this is
1200 * done for backward compatibility -- previously
1201 * setting the channel was done per wiphy, but now
1202 * it is per netdev. Previous userland like hostapd
1203 * also passed a netdev to set_wiphy, so that it is
1204 * possible to let that go to the right netdev!
1205 */
4bbf4d56
JB
1206 mutex_lock(&cfg80211_mutex);
1207
f444de05
JB
1208 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1209 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1210
1211 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1212 if (netdev && netdev->ieee80211_ptr) {
1213 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1214 mutex_lock(&rdev->mtx);
1215 } else
1216 netdev = NULL;
4bbf4d56
JB
1217 }
1218
f444de05
JB
1219 if (!netdev) {
1220 rdev = __cfg80211_rdev_from_info(info);
1221 if (IS_ERR(rdev)) {
1222 mutex_unlock(&cfg80211_mutex);
4c476991 1223 return PTR_ERR(rdev);
f444de05
JB
1224 }
1225 wdev = NULL;
1226 netdev = NULL;
1227 result = 0;
1228
1229 mutex_lock(&rdev->mtx);
1230 } else if (netif_running(netdev) &&
1231 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1232 wdev = netdev->ieee80211_ptr;
1233 else
1234 wdev = NULL;
1235
1236 /*
1237 * end workaround code, by now the rdev is available
1238 * and locked, and wdev may or may not be NULL.
1239 */
4bbf4d56
JB
1240
1241 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1242 result = cfg80211_dev_rename(
1243 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1244
1245 mutex_unlock(&cfg80211_mutex);
1246
1247 if (result)
1248 goto bad_res;
31888487
JM
1249
1250 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1251 struct ieee80211_txq_params txq_params;
1252 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1253
1254 if (!rdev->ops->set_txq_params) {
1255 result = -EOPNOTSUPP;
1256 goto bad_res;
1257 }
1258
f70f01c2
EP
1259 if (!netdev) {
1260 result = -EINVAL;
1261 goto bad_res;
1262 }
1263
133a3ff2
JB
1264 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1265 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1266 result = -EINVAL;
1267 goto bad_res;
1268 }
1269
31888487
JM
1270 nla_for_each_nested(nl_txq_params,
1271 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1272 rem_txq_params) {
1273 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1274 nla_data(nl_txq_params),
1275 nla_len(nl_txq_params),
1276 txq_params_policy);
1277 result = parse_txq_params(tb, &txq_params);
1278 if (result)
1279 goto bad_res;
1280
1281 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1282 netdev,
31888487
JM
1283 &txq_params);
1284 if (result)
1285 goto bad_res;
1286 }
1287 }
55682965 1288
72bdcf34 1289 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1290 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1291 if (result)
1292 goto bad_res;
1293 }
1294
98d2ff8b
JO
1295 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1296 enum nl80211_tx_power_setting type;
1297 int idx, mbm = 0;
1298
1299 if (!rdev->ops->set_tx_power) {
60ea385f 1300 result = -EOPNOTSUPP;
98d2ff8b
JO
1301 goto bad_res;
1302 }
1303
1304 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1305 type = nla_get_u32(info->attrs[idx]);
1306
1307 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1308 (type != NL80211_TX_POWER_AUTOMATIC)) {
1309 result = -EINVAL;
1310 goto bad_res;
1311 }
1312
1313 if (type != NL80211_TX_POWER_AUTOMATIC) {
1314 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1315 mbm = nla_get_u32(info->attrs[idx]);
1316 }
1317
1318 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1319 if (result)
1320 goto bad_res;
1321 }
1322
afe0cbf8
BR
1323 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1324 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1325 u32 tx_ant, rx_ant;
7f531e03
BR
1326 if ((!rdev->wiphy.available_antennas_tx &&
1327 !rdev->wiphy.available_antennas_rx) ||
1328 !rdev->ops->set_antenna) {
afe0cbf8
BR
1329 result = -EOPNOTSUPP;
1330 goto bad_res;
1331 }
1332
1333 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1334 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1335
a7ffac95 1336 /* reject antenna configurations which don't match the
7f531e03
BR
1337 * available antenna masks, except for the "all" mask */
1338 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1339 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1340 result = -EINVAL;
1341 goto bad_res;
1342 }
1343
7f531e03
BR
1344 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1345 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1346
afe0cbf8
BR
1347 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1348 if (result)
1349 goto bad_res;
1350 }
1351
b9a5f8ca
JM
1352 changed = 0;
1353
1354 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1355 retry_short = nla_get_u8(
1356 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1357 if (retry_short == 0) {
1358 result = -EINVAL;
1359 goto bad_res;
1360 }
1361 changed |= WIPHY_PARAM_RETRY_SHORT;
1362 }
1363
1364 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1365 retry_long = nla_get_u8(
1366 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1367 if (retry_long == 0) {
1368 result = -EINVAL;
1369 goto bad_res;
1370 }
1371 changed |= WIPHY_PARAM_RETRY_LONG;
1372 }
1373
1374 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1375 frag_threshold = nla_get_u32(
1376 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1377 if (frag_threshold < 256) {
1378 result = -EINVAL;
1379 goto bad_res;
1380 }
1381 if (frag_threshold != (u32) -1) {
1382 /*
1383 * Fragments (apart from the last one) are required to
1384 * have even length. Make the fragmentation code
1385 * simpler by stripping LSB should someone try to use
1386 * odd threshold value.
1387 */
1388 frag_threshold &= ~0x1;
1389 }
1390 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1391 }
1392
1393 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1394 rts_threshold = nla_get_u32(
1395 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1396 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1397 }
1398
81077e82
LT
1399 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1400 coverage_class = nla_get_u8(
1401 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1402 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1403 }
1404
b9a5f8ca
JM
1405 if (changed) {
1406 u8 old_retry_short, old_retry_long;
1407 u32 old_frag_threshold, old_rts_threshold;
81077e82 1408 u8 old_coverage_class;
b9a5f8ca
JM
1409
1410 if (!rdev->ops->set_wiphy_params) {
1411 result = -EOPNOTSUPP;
1412 goto bad_res;
1413 }
1414
1415 old_retry_short = rdev->wiphy.retry_short;
1416 old_retry_long = rdev->wiphy.retry_long;
1417 old_frag_threshold = rdev->wiphy.frag_threshold;
1418 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1419 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1420
1421 if (changed & WIPHY_PARAM_RETRY_SHORT)
1422 rdev->wiphy.retry_short = retry_short;
1423 if (changed & WIPHY_PARAM_RETRY_LONG)
1424 rdev->wiphy.retry_long = retry_long;
1425 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1426 rdev->wiphy.frag_threshold = frag_threshold;
1427 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1428 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1429 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1430 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1431
1432 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1433 if (result) {
1434 rdev->wiphy.retry_short = old_retry_short;
1435 rdev->wiphy.retry_long = old_retry_long;
1436 rdev->wiphy.frag_threshold = old_frag_threshold;
1437 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1438 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1439 }
1440 }
72bdcf34 1441
306d6112 1442 bad_res:
4bbf4d56 1443 mutex_unlock(&rdev->mtx);
f444de05
JB
1444 if (netdev)
1445 dev_put(netdev);
55682965
JB
1446 return result;
1447}
1448
1449
1450static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1451 struct cfg80211_registered_device *rdev,
55682965
JB
1452 struct net_device *dev)
1453{
1454 void *hdr;
1455
1456 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1457 if (!hdr)
1458 return -1;
1459
1460 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1461 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1462 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1463 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1464
1465 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1466 rdev->devlist_generation ^
1467 (cfg80211_rdev_list_generation << 2));
1468
55682965
JB
1469 return genlmsg_end(msg, hdr);
1470
1471 nla_put_failure:
bc3ed28c
TG
1472 genlmsg_cancel(msg, hdr);
1473 return -EMSGSIZE;
55682965
JB
1474}
1475
1476static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1477{
1478 int wp_idx = 0;
1479 int if_idx = 0;
1480 int wp_start = cb->args[0];
1481 int if_start = cb->args[1];
f5ea9120 1482 struct cfg80211_registered_device *rdev;
55682965
JB
1483 struct wireless_dev *wdev;
1484
a1794390 1485 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1486 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1487 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1488 continue;
bba95fef
JB
1489 if (wp_idx < wp_start) {
1490 wp_idx++;
55682965 1491 continue;
bba95fef 1492 }
55682965
JB
1493 if_idx = 0;
1494
f5ea9120
JB
1495 mutex_lock(&rdev->devlist_mtx);
1496 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1497 if (if_idx < if_start) {
1498 if_idx++;
55682965 1499 continue;
bba95fef 1500 }
55682965
JB
1501 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1502 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1503 rdev, wdev->netdev) < 0) {
1504 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1505 goto out;
1506 }
1507 if_idx++;
55682965 1508 }
f5ea9120 1509 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1510
1511 wp_idx++;
55682965 1512 }
bba95fef 1513 out:
a1794390 1514 mutex_unlock(&cfg80211_mutex);
55682965
JB
1515
1516 cb->args[0] = wp_idx;
1517 cb->args[1] = if_idx;
1518
1519 return skb->len;
1520}
1521
1522static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1523{
1524 struct sk_buff *msg;
4c476991
JB
1525 struct cfg80211_registered_device *dev = info->user_ptr[0];
1526 struct net_device *netdev = info->user_ptr[1];
55682965 1527
fd2120ca 1528 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1529 if (!msg)
4c476991 1530 return -ENOMEM;
55682965 1531
d726405a 1532 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1533 dev, netdev) < 0) {
1534 nlmsg_free(msg);
1535 return -ENOBUFS;
1536 }
55682965 1537
134e6375 1538 return genlmsg_reply(msg, info);
55682965
JB
1539}
1540
66f7ac50
MW
1541static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1542 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1543 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1544 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1545 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1546 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1547};
1548
1549static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1550{
1551 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1552 int flag;
1553
1554 *mntrflags = 0;
1555
1556 if (!nla)
1557 return -EINVAL;
1558
1559 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1560 nla, mntr_flags_policy))
1561 return -EINVAL;
1562
1563 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1564 if (flags[flag])
1565 *mntrflags |= (1<<flag);
1566
1567 return 0;
1568}
1569
9bc383de 1570static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1571 struct net_device *netdev, u8 use_4addr,
1572 enum nl80211_iftype iftype)
9bc383de 1573{
ad4bb6f8 1574 if (!use_4addr) {
f350a0a8 1575 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1576 return -EBUSY;
9bc383de 1577 return 0;
ad4bb6f8 1578 }
9bc383de
JB
1579
1580 switch (iftype) {
1581 case NL80211_IFTYPE_AP_VLAN:
1582 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1583 return 0;
1584 break;
1585 case NL80211_IFTYPE_STATION:
1586 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1587 return 0;
1588 break;
1589 default:
1590 break;
1591 }
1592
1593 return -EOPNOTSUPP;
1594}
1595
55682965
JB
1596static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1597{
4c476991 1598 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1599 struct vif_params params;
e36d56b6 1600 int err;
04a773ad 1601 enum nl80211_iftype otype, ntype;
4c476991 1602 struct net_device *dev = info->user_ptr[1];
92ffe055 1603 u32 _flags, *flags = NULL;
ac7f9cfa 1604 bool change = false;
55682965 1605
2ec600d6
LCC
1606 memset(&params, 0, sizeof(params));
1607
04a773ad 1608 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1609
723b038d 1610 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1611 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1612 if (otype != ntype)
ac7f9cfa 1613 change = true;
4c476991
JB
1614 if (ntype > NL80211_IFTYPE_MAX)
1615 return -EINVAL;
723b038d
JB
1616 }
1617
92ffe055 1618 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1619 struct wireless_dev *wdev = dev->ieee80211_ptr;
1620
4c476991
JB
1621 if (ntype != NL80211_IFTYPE_MESH_POINT)
1622 return -EINVAL;
29cbe68c
JB
1623 if (netif_running(dev))
1624 return -EBUSY;
1625
1626 wdev_lock(wdev);
1627 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1628 IEEE80211_MAX_MESH_ID_LEN);
1629 wdev->mesh_id_up_len =
1630 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1631 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1632 wdev->mesh_id_up_len);
1633 wdev_unlock(wdev);
2ec600d6
LCC
1634 }
1635
8b787643
FF
1636 if (info->attrs[NL80211_ATTR_4ADDR]) {
1637 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1638 change = true;
ad4bb6f8 1639 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1640 if (err)
4c476991 1641 return err;
8b787643
FF
1642 } else {
1643 params.use_4addr = -1;
1644 }
1645
92ffe055 1646 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1647 if (ntype != NL80211_IFTYPE_MONITOR)
1648 return -EINVAL;
92ffe055
JB
1649 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1650 &_flags);
ac7f9cfa 1651 if (err)
4c476991 1652 return err;
ac7f9cfa
JB
1653
1654 flags = &_flags;
1655 change = true;
92ffe055 1656 }
3b85875a 1657
ac7f9cfa 1658 if (change)
3d54d255 1659 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1660 else
1661 err = 0;
60719ffd 1662
9bc383de
JB
1663 if (!err && params.use_4addr != -1)
1664 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1665
55682965
JB
1666 return err;
1667}
1668
1669static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1670{
4c476991 1671 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1672 struct vif_params params;
f9e10ce4 1673 struct net_device *dev;
55682965
JB
1674 int err;
1675 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1676 u32 flags;
55682965 1677
2ec600d6
LCC
1678 memset(&params, 0, sizeof(params));
1679
55682965
JB
1680 if (!info->attrs[NL80211_ATTR_IFNAME])
1681 return -EINVAL;
1682
1683 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1684 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1685 if (type > NL80211_IFTYPE_MAX)
1686 return -EINVAL;
1687 }
1688
79c97e97 1689 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1690 !(rdev->wiphy.interface_modes & (1 << type)))
1691 return -EOPNOTSUPP;
55682965 1692
9bc383de 1693 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1694 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1695 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1696 if (err)
4c476991 1697 return err;
9bc383de 1698 }
8b787643 1699
66f7ac50
MW
1700 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1701 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1702 &flags);
f9e10ce4 1703 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1704 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1705 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1706 if (IS_ERR(dev))
1707 return PTR_ERR(dev);
2ec600d6 1708
29cbe68c
JB
1709 if (type == NL80211_IFTYPE_MESH_POINT &&
1710 info->attrs[NL80211_ATTR_MESH_ID]) {
1711 struct wireless_dev *wdev = dev->ieee80211_ptr;
1712
1713 wdev_lock(wdev);
1714 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1715 IEEE80211_MAX_MESH_ID_LEN);
1716 wdev->mesh_id_up_len =
1717 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1718 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1719 wdev->mesh_id_up_len);
1720 wdev_unlock(wdev);
1721 }
1722
f9e10ce4 1723 return 0;
55682965
JB
1724}
1725
1726static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1727{
4c476991
JB
1728 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1729 struct net_device *dev = info->user_ptr[1];
55682965 1730
4c476991
JB
1731 if (!rdev->ops->del_virtual_intf)
1732 return -EOPNOTSUPP;
55682965 1733
4c476991 1734 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1735}
1736
41ade00f
JB
1737struct get_key_cookie {
1738 struct sk_buff *msg;
1739 int error;
b9454e83 1740 int idx;
41ade00f
JB
1741};
1742
1743static void get_key_callback(void *c, struct key_params *params)
1744{
b9454e83 1745 struct nlattr *key;
41ade00f
JB
1746 struct get_key_cookie *cookie = c;
1747
1748 if (params->key)
1749 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1750 params->key_len, params->key);
1751
1752 if (params->seq)
1753 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1754 params->seq_len, params->seq);
1755
1756 if (params->cipher)
1757 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1758 params->cipher);
1759
b9454e83
JB
1760 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1761 if (!key)
1762 goto nla_put_failure;
1763
1764 if (params->key)
1765 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1766 params->key_len, params->key);
1767
1768 if (params->seq)
1769 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1770 params->seq_len, params->seq);
1771
1772 if (params->cipher)
1773 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1774 params->cipher);
1775
1776 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1777
1778 nla_nest_end(cookie->msg, key);
1779
41ade00f
JB
1780 return;
1781 nla_put_failure:
1782 cookie->error = 1;
1783}
1784
1785static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1786{
4c476991 1787 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1788 int err;
4c476991 1789 struct net_device *dev = info->user_ptr[1];
41ade00f 1790 u8 key_idx = 0;
e31b8213
JB
1791 const u8 *mac_addr = NULL;
1792 bool pairwise;
41ade00f
JB
1793 struct get_key_cookie cookie = {
1794 .error = 0,
1795 };
1796 void *hdr;
1797 struct sk_buff *msg;
1798
1799 if (info->attrs[NL80211_ATTR_KEY_IDX])
1800 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1801
3cfcf6ac 1802 if (key_idx > 5)
41ade00f
JB
1803 return -EINVAL;
1804
1805 if (info->attrs[NL80211_ATTR_MAC])
1806 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1807
e31b8213
JB
1808 pairwise = !!mac_addr;
1809 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1810 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1811 if (kt >= NUM_NL80211_KEYTYPES)
1812 return -EINVAL;
1813 if (kt != NL80211_KEYTYPE_GROUP &&
1814 kt != NL80211_KEYTYPE_PAIRWISE)
1815 return -EINVAL;
1816 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1817 }
1818
4c476991
JB
1819 if (!rdev->ops->get_key)
1820 return -EOPNOTSUPP;
41ade00f 1821
fd2120ca 1822 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1823 if (!msg)
1824 return -ENOMEM;
41ade00f
JB
1825
1826 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1827 NL80211_CMD_NEW_KEY);
4c476991
JB
1828 if (IS_ERR(hdr))
1829 return PTR_ERR(hdr);
41ade00f
JB
1830
1831 cookie.msg = msg;
b9454e83 1832 cookie.idx = key_idx;
41ade00f
JB
1833
1834 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1835 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1836 if (mac_addr)
1837 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1838
e31b8213
JB
1839 if (pairwise && mac_addr &&
1840 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1841 return -ENOENT;
1842
1843 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1844 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1845
1846 if (err)
6c95e2a2 1847 goto free_msg;
41ade00f
JB
1848
1849 if (cookie.error)
1850 goto nla_put_failure;
1851
1852 genlmsg_end(msg, hdr);
4c476991 1853 return genlmsg_reply(msg, info);
41ade00f
JB
1854
1855 nla_put_failure:
1856 err = -ENOBUFS;
6c95e2a2 1857 free_msg:
41ade00f 1858 nlmsg_free(msg);
41ade00f
JB
1859 return err;
1860}
1861
1862static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1863{
4c476991 1864 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1865 struct key_parse key;
41ade00f 1866 int err;
4c476991 1867 struct net_device *dev = info->user_ptr[1];
41ade00f 1868
b9454e83
JB
1869 err = nl80211_parse_key(info, &key);
1870 if (err)
1871 return err;
41ade00f 1872
b9454e83 1873 if (key.idx < 0)
41ade00f
JB
1874 return -EINVAL;
1875
b9454e83
JB
1876 /* only support setting default key */
1877 if (!key.def && !key.defmgmt)
41ade00f
JB
1878 return -EINVAL;
1879
dbd2fd65 1880 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1881
dbd2fd65
JB
1882 if (key.def) {
1883 if (!rdev->ops->set_default_key) {
1884 err = -EOPNOTSUPP;
1885 goto out;
1886 }
41ade00f 1887
dbd2fd65
JB
1888 err = nl80211_key_allowed(dev->ieee80211_ptr);
1889 if (err)
1890 goto out;
1891
dbd2fd65
JB
1892 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1893 key.def_uni, key.def_multi);
1894
1895 if (err)
1896 goto out;
fffd0934 1897
3d23e349 1898#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1899 dev->ieee80211_ptr->wext.default_key = key.idx;
1900#endif
1901 } else {
1902 if (key.def_uni || !key.def_multi) {
1903 err = -EINVAL;
1904 goto out;
1905 }
1906
1907 if (!rdev->ops->set_default_mgmt_key) {
1908 err = -EOPNOTSUPP;
1909 goto out;
1910 }
1911
1912 err = nl80211_key_allowed(dev->ieee80211_ptr);
1913 if (err)
1914 goto out;
1915
1916 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1917 dev, key.idx);
1918 if (err)
1919 goto out;
1920
1921#ifdef CONFIG_CFG80211_WEXT
1922 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1923#endif
dbd2fd65
JB
1924 }
1925
1926 out:
fffd0934 1927 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1928
41ade00f
JB
1929 return err;
1930}
1931
1932static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1933{
4c476991 1934 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1935 int err;
4c476991 1936 struct net_device *dev = info->user_ptr[1];
b9454e83 1937 struct key_parse key;
e31b8213 1938 const u8 *mac_addr = NULL;
41ade00f 1939
b9454e83
JB
1940 err = nl80211_parse_key(info, &key);
1941 if (err)
1942 return err;
41ade00f 1943
b9454e83 1944 if (!key.p.key)
41ade00f
JB
1945 return -EINVAL;
1946
41ade00f
JB
1947 if (info->attrs[NL80211_ATTR_MAC])
1948 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1949
e31b8213
JB
1950 if (key.type == -1) {
1951 if (mac_addr)
1952 key.type = NL80211_KEYTYPE_PAIRWISE;
1953 else
1954 key.type = NL80211_KEYTYPE_GROUP;
1955 }
1956
1957 /* for now */
1958 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1959 key.type != NL80211_KEYTYPE_GROUP)
1960 return -EINVAL;
1961
4c476991
JB
1962 if (!rdev->ops->add_key)
1963 return -EOPNOTSUPP;
25e47c18 1964
e31b8213
JB
1965 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1966 key.type == NL80211_KEYTYPE_PAIRWISE,
1967 mac_addr))
4c476991 1968 return -EINVAL;
41ade00f 1969
fffd0934
JB
1970 wdev_lock(dev->ieee80211_ptr);
1971 err = nl80211_key_allowed(dev->ieee80211_ptr);
1972 if (!err)
1973 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1974 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1975 mac_addr, &key.p);
1976 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1977
41ade00f
JB
1978 return err;
1979}
1980
1981static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1982{
4c476991 1983 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1984 int err;
4c476991 1985 struct net_device *dev = info->user_ptr[1];
41ade00f 1986 u8 *mac_addr = NULL;
b9454e83 1987 struct key_parse key;
41ade00f 1988
b9454e83
JB
1989 err = nl80211_parse_key(info, &key);
1990 if (err)
1991 return err;
41ade00f
JB
1992
1993 if (info->attrs[NL80211_ATTR_MAC])
1994 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1995
e31b8213
JB
1996 if (key.type == -1) {
1997 if (mac_addr)
1998 key.type = NL80211_KEYTYPE_PAIRWISE;
1999 else
2000 key.type = NL80211_KEYTYPE_GROUP;
2001 }
2002
2003 /* for now */
2004 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2005 key.type != NL80211_KEYTYPE_GROUP)
2006 return -EINVAL;
2007
4c476991
JB
2008 if (!rdev->ops->del_key)
2009 return -EOPNOTSUPP;
41ade00f 2010
fffd0934
JB
2011 wdev_lock(dev->ieee80211_ptr);
2012 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2013
2014 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2015 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2016 err = -ENOENT;
2017
fffd0934 2018 if (!err)
e31b8213
JB
2019 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2020 key.type == NL80211_KEYTYPE_PAIRWISE,
2021 mac_addr);
41ade00f 2022
3d23e349 2023#ifdef CONFIG_CFG80211_WEXT
08645126 2024 if (!err) {
b9454e83 2025 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2026 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2027 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2028 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2029 }
2030#endif
fffd0934 2031 wdev_unlock(dev->ieee80211_ptr);
08645126 2032
41ade00f
JB
2033 return err;
2034}
2035
ed1b6cc7
JB
2036static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
2037{
2038 int (*call)(struct wiphy *wiphy, struct net_device *dev,
2039 struct beacon_parameters *info);
4c476991
JB
2040 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2041 struct net_device *dev = info->user_ptr[1];
56d1893d 2042 struct wireless_dev *wdev = dev->ieee80211_ptr;
ed1b6cc7 2043 struct beacon_parameters params;
56d1893d 2044 int haveinfo = 0, err;
ed1b6cc7 2045
9946ecfb
JM
2046 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2047 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2048 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2049 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2050 return -EINVAL;
2051
074ac8df 2052 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2053 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2054 return -EOPNOTSUPP;
eec60b03 2055
56d1893d
JB
2056 memset(&params, 0, sizeof(params));
2057
ed1b6cc7
JB
2058 switch (info->genlhdr->cmd) {
2059 case NL80211_CMD_NEW_BEACON:
2060 /* these are required for NEW_BEACON */
2061 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2062 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
2063 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2064 return -EINVAL;
ed1b6cc7 2065
56d1893d
JB
2066 params.interval =
2067 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2068 params.dtim_period =
2069 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2070
2071 err = cfg80211_validate_beacon_int(rdev, params.interval);
2072 if (err)
2073 return err;
2074
32e9de84
JM
2075 /*
2076 * In theory, some of these attributes could be required for
2077 * NEW_BEACON, but since they were not used when the command was
2078 * originally added, keep them optional for old user space
2079 * programs to work with drivers that do not need the additional
2080 * information.
2081 */
2082 if (info->attrs[NL80211_ATTR_SSID]) {
2083 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2084 params.ssid_len =
2085 nla_len(info->attrs[NL80211_ATTR_SSID]);
2086 if (params.ssid_len == 0 ||
2087 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2088 return -EINVAL;
2089 }
2090
2091 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2092 params.hidden_ssid = nla_get_u32(
2093 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2094 if (params.hidden_ssid !=
2095 NL80211_HIDDEN_SSID_NOT_IN_USE &&
2096 params.hidden_ssid !=
2097 NL80211_HIDDEN_SSID_ZERO_LEN &&
2098 params.hidden_ssid !=
2099 NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2100 return -EINVAL;
2101 }
2102
5fb628e9
JM
2103 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2104
2105 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2106 params.auth_type = nla_get_u32(
2107 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2108 if (!nl80211_valid_auth_type(params.auth_type))
2109 return -EINVAL;
2110 } else
2111 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2112
2113 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2114 NL80211_MAX_NR_CIPHER_SUITES);
2115 if (err)
2116 return err;
2117
79c97e97 2118 call = rdev->ops->add_beacon;
ed1b6cc7
JB
2119 break;
2120 case NL80211_CMD_SET_BEACON:
79c97e97 2121 call = rdev->ops->set_beacon;
ed1b6cc7
JB
2122 break;
2123 default:
2124 WARN_ON(1);
4c476991 2125 return -EOPNOTSUPP;
ed1b6cc7
JB
2126 }
2127
4c476991
JB
2128 if (!call)
2129 return -EOPNOTSUPP;
ed1b6cc7 2130
ed1b6cc7
JB
2131 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
2132 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2133 params.head_len =
2134 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2135 haveinfo = 1;
2136 }
2137
2138 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
2139 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2140 params.tail_len =
2141 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2142 haveinfo = 1;
2143 }
2144
4c476991
JB
2145 if (!haveinfo)
2146 return -EINVAL;
3b85875a 2147
9946ecfb
JM
2148 if (info->attrs[NL80211_ATTR_IE]) {
2149 params.beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2150 params.beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2151 }
2152
2153 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
2154 params.proberesp_ies =
2155 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2156 params.proberesp_ies_len =
2157 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2158 }
2159
2160 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
2161 params.assocresp_ies =
2162 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2163 params.assocresp_ies_len =
2164 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2165 }
2166
56d1893d
JB
2167 err = call(&rdev->wiphy, dev, &params);
2168 if (!err && params.interval)
2169 wdev->beacon_interval = params.interval;
2170 return err;
ed1b6cc7
JB
2171}
2172
2173static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
2174{
4c476991
JB
2175 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2176 struct net_device *dev = info->user_ptr[1];
56d1893d
JB
2177 struct wireless_dev *wdev = dev->ieee80211_ptr;
2178 int err;
ed1b6cc7 2179
4c476991
JB
2180 if (!rdev->ops->del_beacon)
2181 return -EOPNOTSUPP;
ed1b6cc7 2182
074ac8df 2183 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2184 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2185 return -EOPNOTSUPP;
3b85875a 2186
56d1893d
JB
2187 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
2188 if (!err)
2189 wdev->beacon_interval = 0;
2190 return err;
ed1b6cc7
JB
2191}
2192
5727ef1b
JB
2193static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2194 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2195 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2196 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2197 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2198 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
5727ef1b
JB
2199};
2200
eccb8e8f
JB
2201static int parse_station_flags(struct genl_info *info,
2202 struct station_parameters *params)
5727ef1b
JB
2203{
2204 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2205 struct nlattr *nla;
5727ef1b
JB
2206 int flag;
2207
eccb8e8f
JB
2208 /*
2209 * Try parsing the new attribute first so userspace
2210 * can specify both for older kernels.
2211 */
2212 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2213 if (nla) {
2214 struct nl80211_sta_flag_update *sta_flags;
2215
2216 sta_flags = nla_data(nla);
2217 params->sta_flags_mask = sta_flags->mask;
2218 params->sta_flags_set = sta_flags->set;
2219 if ((params->sta_flags_mask |
2220 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2221 return -EINVAL;
2222 return 0;
2223 }
2224
2225 /* if present, parse the old attribute */
5727ef1b 2226
eccb8e8f 2227 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2228 if (!nla)
2229 return 0;
2230
2231 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2232 nla, sta_flags_policy))
2233 return -EINVAL;
2234
eccb8e8f
JB
2235 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
2236 params->sta_flags_mask &= ~1;
5727ef1b
JB
2237
2238 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2239 if (flags[flag])
eccb8e8f 2240 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2241
2242 return 0;
2243}
2244
c8dcfd8a
FF
2245static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2246 int attr)
2247{
2248 struct nlattr *rate;
2249 u16 bitrate;
2250
2251 rate = nla_nest_start(msg, attr);
2252 if (!rate)
2253 goto nla_put_failure;
2254
2255 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2256 bitrate = cfg80211_calculate_bitrate(info);
2257 if (bitrate > 0)
2258 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2259
2260 if (info->flags & RATE_INFO_FLAGS_MCS)
2261 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2262 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2263 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2264 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2265 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2266
2267 nla_nest_end(msg, rate);
2268 return true;
2269
2270nla_put_failure:
2271 return false;
2272}
2273
fd5b74dc
JB
2274static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2275 int flags, struct net_device *dev,
98b62183 2276 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2277{
2278 void *hdr;
f4263c98 2279 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2280
2281 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2282 if (!hdr)
2283 return -1;
2284
2285 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2286 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2287
f5ea9120
JB
2288 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2289
2ec600d6
LCC
2290 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2291 if (!sinfoattr)
fd5b74dc 2292 goto nla_put_failure;
ebe27c91
MSS
2293 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2294 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2295 sinfo->connected_time);
2ec600d6
LCC
2296 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2297 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2298 sinfo->inactive_time);
2299 if (sinfo->filled & STATION_INFO_RX_BYTES)
2300 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2301 sinfo->rx_bytes);
2302 if (sinfo->filled & STATION_INFO_TX_BYTES)
2303 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2304 sinfo->tx_bytes);
2305 if (sinfo->filled & STATION_INFO_LLID)
2306 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2307 sinfo->llid);
2308 if (sinfo->filled & STATION_INFO_PLID)
2309 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2310 sinfo->plid);
2311 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2312 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2313 sinfo->plink_state);
420e7fab
HR
2314 if (sinfo->filled & STATION_INFO_SIGNAL)
2315 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2316 sinfo->signal);
541a45a1
BR
2317 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2318 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2319 sinfo->signal_avg);
420e7fab 2320 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2321 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2322 NL80211_STA_INFO_TX_BITRATE))
2323 goto nla_put_failure;
2324 }
2325 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2326 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2327 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2328 goto nla_put_failure;
420e7fab 2329 }
98c8a60a
JM
2330 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2331 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2332 sinfo->rx_packets);
2333 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2334 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2335 sinfo->tx_packets);
b206b4ef
BR
2336 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2337 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2338 sinfo->tx_retries);
2339 if (sinfo->filled & STATION_INFO_TX_FAILED)
2340 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2341 sinfo->tx_failed);
f4263c98
PS
2342 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2343 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2344 if (!bss_param)
2345 goto nla_put_failure;
2346
2347 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2348 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2349 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2350 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2351 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2352 NLA_PUT_FLAG(msg,
2353 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2354 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2355 sinfo->bss_param.dtim_period);
2356 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2357 sinfo->bss_param.beacon_interval);
2358
2359 nla_nest_end(msg, bss_param);
2360 }
bb6e753e
HS
2361 if (sinfo->filled & STATION_INFO_STA_FLAGS)
2362 NLA_PUT(msg, NL80211_STA_INFO_STA_FLAGS,
2363 sizeof(struct nl80211_sta_flag_update),
2364 &sinfo->sta_flags);
2ec600d6 2365 nla_nest_end(msg, sinfoattr);
fd5b74dc 2366
040bdf71 2367 if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
50d3dfb7
JM
2368 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2369 sinfo->assoc_req_ies);
2370
fd5b74dc
JB
2371 return genlmsg_end(msg, hdr);
2372
2373 nla_put_failure:
bc3ed28c
TG
2374 genlmsg_cancel(msg, hdr);
2375 return -EMSGSIZE;
fd5b74dc
JB
2376}
2377
2ec600d6 2378static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2379 struct netlink_callback *cb)
2ec600d6 2380{
2ec600d6
LCC
2381 struct station_info sinfo;
2382 struct cfg80211_registered_device *dev;
bba95fef 2383 struct net_device *netdev;
2ec600d6 2384 u8 mac_addr[ETH_ALEN];
bba95fef 2385 int sta_idx = cb->args[1];
2ec600d6 2386 int err;
2ec600d6 2387
67748893
JB
2388 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2389 if (err)
2390 return err;
bba95fef
JB
2391
2392 if (!dev->ops->dump_station) {
eec60b03 2393 err = -EOPNOTSUPP;
bba95fef
JB
2394 goto out_err;
2395 }
2396
bba95fef 2397 while (1) {
f612cedf 2398 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2399 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2400 mac_addr, &sinfo);
2401 if (err == -ENOENT)
2402 break;
2403 if (err)
3b85875a 2404 goto out_err;
bba95fef
JB
2405
2406 if (nl80211_send_station(skb,
2407 NETLINK_CB(cb->skb).pid,
2408 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2409 netdev, mac_addr,
2410 &sinfo) < 0)
2411 goto out;
2412
2413 sta_idx++;
2414 }
2415
2416
2417 out:
2418 cb->args[1] = sta_idx;
2419 err = skb->len;
bba95fef 2420 out_err:
67748893 2421 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2422
2423 return err;
2ec600d6 2424}
fd5b74dc 2425
5727ef1b
JB
2426static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2427{
4c476991
JB
2428 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2429 struct net_device *dev = info->user_ptr[1];
2ec600d6 2430 struct station_info sinfo;
fd5b74dc
JB
2431 struct sk_buff *msg;
2432 u8 *mac_addr = NULL;
4c476991 2433 int err;
fd5b74dc 2434
2ec600d6 2435 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2436
2437 if (!info->attrs[NL80211_ATTR_MAC])
2438 return -EINVAL;
2439
2440 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2441
4c476991
JB
2442 if (!rdev->ops->get_station)
2443 return -EOPNOTSUPP;
3b85875a 2444
4c476991 2445 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2446 if (err)
4c476991 2447 return err;
2ec600d6 2448
fd2120ca 2449 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2450 if (!msg)
4c476991 2451 return -ENOMEM;
fd5b74dc
JB
2452
2453 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2454 dev, mac_addr, &sinfo) < 0) {
2455 nlmsg_free(msg);
2456 return -ENOBUFS;
2457 }
3b85875a 2458
4c476991 2459 return genlmsg_reply(msg, info);
5727ef1b
JB
2460}
2461
2462/*
c258d2de 2463 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2464 */
463d0183 2465static int get_vlan(struct genl_info *info,
5727ef1b
JB
2466 struct cfg80211_registered_device *rdev,
2467 struct net_device **vlan)
2468{
463d0183 2469 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2470 *vlan = NULL;
2471
2472 if (vlanattr) {
463d0183
JB
2473 *vlan = dev_get_by_index(genl_info_net(info),
2474 nla_get_u32(vlanattr));
5727ef1b
JB
2475 if (!*vlan)
2476 return -ENODEV;
2477 if (!(*vlan)->ieee80211_ptr)
2478 return -EINVAL;
2479 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2480 return -EINVAL;
c258d2de
FF
2481 if (!netif_running(*vlan))
2482 return -ENETDOWN;
5727ef1b
JB
2483 }
2484 return 0;
2485}
2486
2487static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2488{
4c476991 2489 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2490 int err;
4c476991 2491 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2492 struct station_parameters params;
2493 u8 *mac_addr = NULL;
2494
2495 memset(&params, 0, sizeof(params));
2496
2497 params.listen_interval = -1;
57cf8043 2498 params.plink_state = -1;
5727ef1b
JB
2499
2500 if (info->attrs[NL80211_ATTR_STA_AID])
2501 return -EINVAL;
2502
2503 if (!info->attrs[NL80211_ATTR_MAC])
2504 return -EINVAL;
2505
2506 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2507
2508 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2509 params.supported_rates =
2510 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2511 params.supported_rates_len =
2512 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2513 }
2514
2515 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2516 params.listen_interval =
2517 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2518
36aedc90
JM
2519 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2520 params.ht_capa =
2521 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2522
eccb8e8f 2523 if (parse_station_flags(info, &params))
5727ef1b
JB
2524 return -EINVAL;
2525
2ec600d6
LCC
2526 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2527 params.plink_action =
2528 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2529
9c3990aa
JC
2530 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2531 params.plink_state =
2532 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2533
463d0183 2534 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2535 if (err)
034d655e 2536 goto out;
a97f4424
JB
2537
2538 /* validate settings */
2539 err = 0;
2540
2541 switch (dev->ieee80211_ptr->iftype) {
2542 case NL80211_IFTYPE_AP:
2543 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2544 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2545 /* disallow mesh-specific things */
2546 if (params.plink_action)
2547 err = -EINVAL;
2548 break;
074ac8df 2549 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 2550 case NL80211_IFTYPE_STATION:
07ba55d7 2551 /* disallow things sta doesn't support */
a97f4424
JB
2552 if (params.plink_action)
2553 err = -EINVAL;
2554 if (params.vlan)
2555 err = -EINVAL;
07ba55d7
AN
2556 if (params.supported_rates &&
2557 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
a97f4424
JB
2558 err = -EINVAL;
2559 if (params.ht_capa)
2560 err = -EINVAL;
2561 if (params.listen_interval >= 0)
2562 err = -EINVAL;
07ba55d7
AN
2563 if (params.sta_flags_mask &
2564 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2565 BIT(NL80211_STA_FLAG_TDLS_PEER)))
2566 err = -EINVAL;
2567 /* can't change the TDLS bit */
2568 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
2569 (params.sta_flags_mask & BIT(NL80211_STA_FLAG_TDLS_PEER)))
a97f4424
JB
2570 err = -EINVAL;
2571 break;
2572 case NL80211_IFTYPE_MESH_POINT:
2573 /* disallow things mesh doesn't support */
2574 if (params.vlan)
2575 err = -EINVAL;
2576 if (params.ht_capa)
2577 err = -EINVAL;
2578 if (params.listen_interval >= 0)
2579 err = -EINVAL;
b39c48fa
JC
2580 if (params.sta_flags_mask &
2581 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2582 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2583 BIT(NL80211_STA_FLAG_AUTHORIZED)))
a97f4424
JB
2584 err = -EINVAL;
2585 break;
2586 default:
2587 err = -EINVAL;
034d655e
JB
2588 }
2589
5727ef1b
JB
2590 if (err)
2591 goto out;
2592
79c97e97 2593 if (!rdev->ops->change_station) {
5727ef1b
JB
2594 err = -EOPNOTSUPP;
2595 goto out;
2596 }
2597
79c97e97 2598 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2599
2600 out:
2601 if (params.vlan)
2602 dev_put(params.vlan);
3b85875a 2603
5727ef1b
JB
2604 return err;
2605}
2606
c75786c9
EP
2607static struct nla_policy
2608nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2609 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2610 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2611};
2612
5727ef1b
JB
2613static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2614{
4c476991 2615 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2616 int err;
4c476991 2617 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2618 struct station_parameters params;
2619 u8 *mac_addr = NULL;
2620
2621 memset(&params, 0, sizeof(params));
2622
2623 if (!info->attrs[NL80211_ATTR_MAC])
2624 return -EINVAL;
2625
5727ef1b
JB
2626 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2627 return -EINVAL;
2628
2629 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2630 return -EINVAL;
2631
0e956c13
TLSC
2632 if (!info->attrs[NL80211_ATTR_STA_AID])
2633 return -EINVAL;
2634
5727ef1b
JB
2635 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2636 params.supported_rates =
2637 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2638 params.supported_rates_len =
2639 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2640 params.listen_interval =
2641 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2642
0e956c13
TLSC
2643 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2644 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2645 return -EINVAL;
51b50fbe 2646
36aedc90
JM
2647 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2648 params.ht_capa =
2649 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2650
96b78dff
JC
2651 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2652 params.plink_action =
2653 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2654
eccb8e8f 2655 if (parse_station_flags(info, &params))
5727ef1b
JB
2656 return -EINVAL;
2657
c75786c9 2658 /* parse WME attributes if sta is WME capable */
cedb5412 2659 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
cd32984f 2660 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
c75786c9
EP
2661 info->attrs[NL80211_ATTR_STA_WME]) {
2662 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2663 struct nlattr *nla;
2664
2665 nla = info->attrs[NL80211_ATTR_STA_WME];
2666 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2667 nl80211_sta_wme_policy);
2668 if (err)
2669 return err;
2670
2671 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2672 params.uapsd_queues =
2673 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
4319e193
JB
2674 if (params.uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2675 return -EINVAL;
c75786c9
EP
2676
2677 if (tb[NL80211_STA_WME_MAX_SP])
2678 params.max_sp =
2679 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
4319e193
JB
2680
2681 if (params.max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2682 return -EINVAL;
3b9ce80c
JB
2683
2684 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
c75786c9
EP
2685 }
2686
0e956c13 2687 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2688 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
96b78dff 2689 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
07ba55d7
AN
2690 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO &&
2691 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION)
2692 return -EINVAL;
2693
2694 /*
2695 * Only managed stations can add TDLS peers, and only when the
2696 * wiphy supports external TDLS setup.
2697 */
2698 if (dev->ieee80211_ptr->iftype == NL80211_IFTYPE_STATION &&
2699 !((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
2700 (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
2701 (rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)))
4c476991 2702 return -EINVAL;
0e956c13 2703
463d0183 2704 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2705 if (err)
e80cf853 2706 goto out;
a97f4424
JB
2707
2708 /* validate settings */
2709 err = 0;
2710
79c97e97 2711 if (!rdev->ops->add_station) {
5727ef1b
JB
2712 err = -EOPNOTSUPP;
2713 goto out;
2714 }
2715
79c97e97 2716 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2717
2718 out:
2719 if (params.vlan)
2720 dev_put(params.vlan);
5727ef1b
JB
2721 return err;
2722}
2723
2724static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2725{
4c476991
JB
2726 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2727 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2728 u8 *mac_addr = NULL;
2729
2730 if (info->attrs[NL80211_ATTR_MAC])
2731 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2732
e80cf853 2733 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2734 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2735 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2736 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2737 return -EINVAL;
5727ef1b 2738
4c476991
JB
2739 if (!rdev->ops->del_station)
2740 return -EOPNOTSUPP;
3b85875a 2741
4c476991 2742 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2743}
2744
2ec600d6
LCC
2745static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2746 int flags, struct net_device *dev,
2747 u8 *dst, u8 *next_hop,
2748 struct mpath_info *pinfo)
2749{
2750 void *hdr;
2751 struct nlattr *pinfoattr;
2752
2753 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2754 if (!hdr)
2755 return -1;
2756
2757 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2758 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2759 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2760
f5ea9120
JB
2761 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2762
2ec600d6
LCC
2763 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2764 if (!pinfoattr)
2765 goto nla_put_failure;
2766 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2767 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2768 pinfo->frame_qlen);
d19b3bf6
RP
2769 if (pinfo->filled & MPATH_INFO_SN)
2770 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2771 pinfo->sn);
2ec600d6
LCC
2772 if (pinfo->filled & MPATH_INFO_METRIC)
2773 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2774 pinfo->metric);
2775 if (pinfo->filled & MPATH_INFO_EXPTIME)
2776 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2777 pinfo->exptime);
2778 if (pinfo->filled & MPATH_INFO_FLAGS)
2779 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2780 pinfo->flags);
2781 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2782 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2783 pinfo->discovery_timeout);
2784 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2785 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2786 pinfo->discovery_retries);
2787
2788 nla_nest_end(msg, pinfoattr);
2789
2790 return genlmsg_end(msg, hdr);
2791
2792 nla_put_failure:
bc3ed28c
TG
2793 genlmsg_cancel(msg, hdr);
2794 return -EMSGSIZE;
2ec600d6
LCC
2795}
2796
2797static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2798 struct netlink_callback *cb)
2ec600d6 2799{
2ec600d6
LCC
2800 struct mpath_info pinfo;
2801 struct cfg80211_registered_device *dev;
bba95fef 2802 struct net_device *netdev;
2ec600d6
LCC
2803 u8 dst[ETH_ALEN];
2804 u8 next_hop[ETH_ALEN];
bba95fef 2805 int path_idx = cb->args[1];
2ec600d6 2806 int err;
2ec600d6 2807
67748893
JB
2808 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2809 if (err)
2810 return err;
bba95fef
JB
2811
2812 if (!dev->ops->dump_mpath) {
eec60b03 2813 err = -EOPNOTSUPP;
bba95fef
JB
2814 goto out_err;
2815 }
2816
eec60b03
JM
2817 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2818 err = -EOPNOTSUPP;
0448b5fc 2819 goto out_err;
eec60b03
JM
2820 }
2821
bba95fef
JB
2822 while (1) {
2823 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2824 dst, next_hop, &pinfo);
2825 if (err == -ENOENT)
2ec600d6 2826 break;
bba95fef 2827 if (err)
3b85875a 2828 goto out_err;
2ec600d6 2829
bba95fef
JB
2830 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2831 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2832 netdev, dst, next_hop,
2833 &pinfo) < 0)
2834 goto out;
2ec600d6 2835
bba95fef 2836 path_idx++;
2ec600d6 2837 }
2ec600d6 2838
2ec600d6 2839
bba95fef
JB
2840 out:
2841 cb->args[1] = path_idx;
2842 err = skb->len;
bba95fef 2843 out_err:
67748893 2844 nl80211_finish_netdev_dump(dev);
bba95fef 2845 return err;
2ec600d6
LCC
2846}
2847
2848static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2849{
4c476991 2850 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2851 int err;
4c476991 2852 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2853 struct mpath_info pinfo;
2854 struct sk_buff *msg;
2855 u8 *dst = NULL;
2856 u8 next_hop[ETH_ALEN];
2857
2858 memset(&pinfo, 0, sizeof(pinfo));
2859
2860 if (!info->attrs[NL80211_ATTR_MAC])
2861 return -EINVAL;
2862
2863 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2864
4c476991
JB
2865 if (!rdev->ops->get_mpath)
2866 return -EOPNOTSUPP;
2ec600d6 2867
4c476991
JB
2868 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2869 return -EOPNOTSUPP;
eec60b03 2870
79c97e97 2871 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2872 if (err)
4c476991 2873 return err;
2ec600d6 2874
fd2120ca 2875 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2876 if (!msg)
4c476991 2877 return -ENOMEM;
2ec600d6
LCC
2878
2879 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2880 dev, dst, next_hop, &pinfo) < 0) {
2881 nlmsg_free(msg);
2882 return -ENOBUFS;
2883 }
3b85875a 2884
4c476991 2885 return genlmsg_reply(msg, info);
2ec600d6
LCC
2886}
2887
2888static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2889{
4c476991
JB
2890 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2891 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2892 u8 *dst = NULL;
2893 u8 *next_hop = NULL;
2894
2895 if (!info->attrs[NL80211_ATTR_MAC])
2896 return -EINVAL;
2897
2898 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2899 return -EINVAL;
2900
2901 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2902 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2903
4c476991
JB
2904 if (!rdev->ops->change_mpath)
2905 return -EOPNOTSUPP;
35a8efe1 2906
4c476991
JB
2907 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2908 return -EOPNOTSUPP;
2ec600d6 2909
4c476991 2910 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2911}
4c476991 2912
2ec600d6
LCC
2913static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2914{
4c476991
JB
2915 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2916 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2917 u8 *dst = NULL;
2918 u8 *next_hop = NULL;
2919
2920 if (!info->attrs[NL80211_ATTR_MAC])
2921 return -EINVAL;
2922
2923 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2924 return -EINVAL;
2925
2926 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2927 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2928
4c476991
JB
2929 if (!rdev->ops->add_mpath)
2930 return -EOPNOTSUPP;
35a8efe1 2931
4c476991
JB
2932 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2933 return -EOPNOTSUPP;
2ec600d6 2934
4c476991 2935 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2936}
2937
2938static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2939{
4c476991
JB
2940 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2941 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2942 u8 *dst = NULL;
2943
2944 if (info->attrs[NL80211_ATTR_MAC])
2945 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2946
4c476991
JB
2947 if (!rdev->ops->del_mpath)
2948 return -EOPNOTSUPP;
3b85875a 2949
4c476991 2950 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2951}
2952
9f1ba906
JM
2953static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2954{
4c476991
JB
2955 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2956 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2957 struct bss_parameters params;
2958
2959 memset(&params, 0, sizeof(params));
2960 /* default to not changing parameters */
2961 params.use_cts_prot = -1;
2962 params.use_short_preamble = -1;
2963 params.use_short_slot_time = -1;
fd8aaaf3 2964 params.ap_isolate = -1;
50b12f59 2965 params.ht_opmode = -1;
9f1ba906
JM
2966
2967 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2968 params.use_cts_prot =
2969 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2970 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2971 params.use_short_preamble =
2972 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2973 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2974 params.use_short_slot_time =
2975 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2976 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2977 params.basic_rates =
2978 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2979 params.basic_rates_len =
2980 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2981 }
fd8aaaf3
FF
2982 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2983 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2984 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2985 params.ht_opmode =
2986 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2987
4c476991
JB
2988 if (!rdev->ops->change_bss)
2989 return -EOPNOTSUPP;
9f1ba906 2990
074ac8df 2991 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2992 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2993 return -EOPNOTSUPP;
3b85875a 2994
4c476991 2995 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2996}
2997
b54452b0 2998static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2999 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3000 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3001 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3002 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3003 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3004 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3005};
3006
3007static int parse_reg_rule(struct nlattr *tb[],
3008 struct ieee80211_reg_rule *reg_rule)
3009{
3010 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3011 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3012
3013 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3014 return -EINVAL;
3015 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3016 return -EINVAL;
3017 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3018 return -EINVAL;
3019 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3020 return -EINVAL;
3021 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3022 return -EINVAL;
3023
3024 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3025
3026 freq_range->start_freq_khz =
3027 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3028 freq_range->end_freq_khz =
3029 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3030 freq_range->max_bandwidth_khz =
3031 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3032
3033 power_rule->max_eirp =
3034 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3035
3036 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3037 power_rule->max_antenna_gain =
3038 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3039
3040 return 0;
3041}
3042
3043static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3044{
3045 int r;
3046 char *data = NULL;
3047
80778f18
LR
3048 /*
3049 * You should only get this when cfg80211 hasn't yet initialized
3050 * completely when built-in to the kernel right between the time
3051 * window between nl80211_init() and regulatory_init(), if that is
3052 * even possible.
3053 */
3054 mutex_lock(&cfg80211_mutex);
3055 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3056 mutex_unlock(&cfg80211_mutex);
3057 return -EINPROGRESS;
80778f18 3058 }
fe33eb39 3059 mutex_unlock(&cfg80211_mutex);
80778f18 3060
fe33eb39
LR
3061 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3062 return -EINVAL;
b2e1b302
LR
3063
3064 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3065
fe33eb39
LR
3066 r = regulatory_hint_user(data);
3067
b2e1b302
LR
3068 return r;
3069}
3070
24bdd9f4 3071static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3072 struct genl_info *info)
93da9cc1 3073{
4c476991 3074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3075 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3076 struct wireless_dev *wdev = dev->ieee80211_ptr;
3077 struct mesh_config cur_params;
3078 int err = 0;
93da9cc1 3079 void *hdr;
3080 struct nlattr *pinfoattr;
3081 struct sk_buff *msg;
3082
29cbe68c
JB
3083 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3084 return -EOPNOTSUPP;
3085
24bdd9f4 3086 if (!rdev->ops->get_mesh_config)
4c476991 3087 return -EOPNOTSUPP;
f3f92586 3088
29cbe68c
JB
3089 wdev_lock(wdev);
3090 /* If not connected, get default parameters */
3091 if (!wdev->mesh_id_len)
3092 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3093 else
24bdd9f4 3094 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3095 &cur_params);
3096 wdev_unlock(wdev);
3097
93da9cc1 3098 if (err)
4c476991 3099 return err;
93da9cc1 3100
3101 /* Draw up a netlink message to send back */
fd2120ca 3102 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3103 if (!msg)
3104 return -ENOMEM;
93da9cc1 3105 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3106 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3107 if (!hdr)
efe1cf0c 3108 goto out;
24bdd9f4 3109 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3110 if (!pinfoattr)
3111 goto nla_put_failure;
3112 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3113 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3114 cur_params.dot11MeshRetryTimeout);
3115 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3116 cur_params.dot11MeshConfirmTimeout);
3117 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3118 cur_params.dot11MeshHoldingTimeout);
3119 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3120 cur_params.dot11MeshMaxPeerLinks);
3121 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
3122 cur_params.dot11MeshMaxRetries);
3123 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
3124 cur_params.dot11MeshTTL);
45904f21
JC
3125 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3126 cur_params.element_ttl);
93da9cc1 3127 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3128 cur_params.auto_open_plinks);
3129 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3130 cur_params.dot11MeshHWMPmaxPREQretries);
3131 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3132 cur_params.path_refresh_time);
3133 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3134 cur_params.min_discovery_timeout);
3135 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3136 cur_params.dot11MeshHWMPactivePathTimeout);
3137 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3138 cur_params.dot11MeshHWMPpreqMinInterval);
3139 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3140 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
3141 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3142 cur_params.dot11MeshHWMPRootMode);
0507e159
JC
3143 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3144 cur_params.dot11MeshHWMPRannInterval);
16dd7267
JC
3145 NLA_PUT_U8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3146 cur_params.dot11MeshGateAnnouncementProtocol);
93da9cc1 3147 nla_nest_end(msg, pinfoattr);
3148 genlmsg_end(msg, hdr);
4c476991 3149 return genlmsg_reply(msg, info);
93da9cc1 3150
3b85875a 3151 nla_put_failure:
93da9cc1 3152 genlmsg_cancel(msg, hdr);
efe1cf0c 3153 out:
d080e275 3154 nlmsg_free(msg);
4c476991 3155 return -ENOBUFS;
93da9cc1 3156}
3157
b54452b0 3158static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3159 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3160 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3161 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3162 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3163 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3164 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3165 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3166 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
3167
3168 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3169 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3170 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3171 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3172 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
3173 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3174 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3175 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3176 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
93da9cc1 3177};
3178
c80d545d
JC
3179static const struct nla_policy
3180 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
3181 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3182 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3183 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3184 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 3185 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3186 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3187};
3188
24bdd9f4 3189static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3190 struct mesh_config *cfg,
3191 u32 *mask_out)
93da9cc1 3192{
93da9cc1 3193 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3194 u32 mask = 0;
93da9cc1 3195
bd90fdcc
JB
3196#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3197do {\
3198 if (table[attr_num]) {\
3199 cfg->param = nla_fn(table[attr_num]); \
3200 mask |= (1 << (attr_num - 1)); \
3201 } \
3202} while (0);\
3203
3204
24bdd9f4 3205 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3206 return -EINVAL;
3207 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3208 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3209 nl80211_meshconf_params_policy))
93da9cc1 3210 return -EINVAL;
3211
93da9cc1 3212 /* This makes sure that there aren't more than 32 mesh config
3213 * parameters (otherwise our bitfield scheme would not work.) */
3214 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3215
3216 /* Fill in the params struct */
93da9cc1 3217 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3218 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3219 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3220 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3221 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3222 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3223 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3224 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3225 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3226 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3227 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3228 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
3229 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3230 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 3231 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3232 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
3233 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3234 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3235 nla_get_u8);
3236 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3237 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3238 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3239 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3240 nla_get_u16);
3241 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3242 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3243 nla_get_u32);
3244 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3245 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3246 nla_get_u16);
3247 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3248 dot11MeshHWMPnetDiameterTraversalTime,
3249 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3250 nla_get_u16);
63c5723b
RP
3251 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3252 dot11MeshHWMPRootMode, mask,
3253 NL80211_MESHCONF_HWMP_ROOTMODE,
3254 nla_get_u8);
0507e159
JC
3255 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3256 dot11MeshHWMPRannInterval, mask,
3257 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3258 nla_get_u16);
16dd7267
JC
3259 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3260 dot11MeshGateAnnouncementProtocol, mask,
3261 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3262 nla_get_u8);
bd90fdcc
JB
3263 if (mask_out)
3264 *mask_out = mask;
c80d545d 3265
bd90fdcc
JB
3266 return 0;
3267
3268#undef FILL_IN_MESH_PARAM_IF_SET
3269}
3270
c80d545d
JC
3271static int nl80211_parse_mesh_setup(struct genl_info *info,
3272 struct mesh_setup *setup)
3273{
3274 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3275
3276 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3277 return -EINVAL;
3278 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3279 info->attrs[NL80211_ATTR_MESH_SETUP],
3280 nl80211_mesh_setup_params_policy))
3281 return -EINVAL;
3282
3283 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3284 setup->path_sel_proto =
3285 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3286 IEEE80211_PATH_PROTOCOL_VENDOR :
3287 IEEE80211_PATH_PROTOCOL_HWMP;
3288
3289 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3290 setup->path_metric =
3291 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3292 IEEE80211_PATH_METRIC_VENDOR :
3293 IEEE80211_PATH_METRIC_AIRTIME;
3294
581a8b0f
JC
3295
3296 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3297 struct nlattr *ieattr =
581a8b0f 3298 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3299 if (!is_valid_ie_attr(ieattr))
3300 return -EINVAL;
581a8b0f
JC
3301 setup->ie = nla_data(ieattr);
3302 setup->ie_len = nla_len(ieattr);
c80d545d 3303 }
b130e5ce
JC
3304 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3305 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3306
3307 return 0;
3308}
3309
24bdd9f4 3310static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3311 struct genl_info *info)
bd90fdcc
JB
3312{
3313 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3314 struct net_device *dev = info->user_ptr[1];
29cbe68c 3315 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3316 struct mesh_config cfg;
3317 u32 mask;
3318 int err;
3319
29cbe68c
JB
3320 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3321 return -EOPNOTSUPP;
3322
24bdd9f4 3323 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3324 return -EOPNOTSUPP;
3325
24bdd9f4 3326 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3327 if (err)
3328 return err;
3329
29cbe68c
JB
3330 wdev_lock(wdev);
3331 if (!wdev->mesh_id_len)
3332 err = -ENOLINK;
3333
3334 if (!err)
24bdd9f4 3335 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3336 mask, &cfg);
3337
3338 wdev_unlock(wdev);
3339
3340 return err;
93da9cc1 3341}
3342
f130347c
LR
3343static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3344{
3345 struct sk_buff *msg;
3346 void *hdr = NULL;
3347 struct nlattr *nl_reg_rules;
3348 unsigned int i;
3349 int err = -EINVAL;
3350
a1794390 3351 mutex_lock(&cfg80211_mutex);
f130347c
LR
3352
3353 if (!cfg80211_regdomain)
3354 goto out;
3355
fd2120ca 3356 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3357 if (!msg) {
3358 err = -ENOBUFS;
3359 goto out;
3360 }
3361
3362 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3363 NL80211_CMD_GET_REG);
3364 if (!hdr)
efe1cf0c 3365 goto put_failure;
f130347c
LR
3366
3367 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3368 cfg80211_regdomain->alpha2);
3369
3370 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3371 if (!nl_reg_rules)
3372 goto nla_put_failure;
3373
3374 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3375 struct nlattr *nl_reg_rule;
3376 const struct ieee80211_reg_rule *reg_rule;
3377 const struct ieee80211_freq_range *freq_range;
3378 const struct ieee80211_power_rule *power_rule;
3379
3380 reg_rule = &cfg80211_regdomain->reg_rules[i];
3381 freq_range = &reg_rule->freq_range;
3382 power_rule = &reg_rule->power_rule;
3383
3384 nl_reg_rule = nla_nest_start(msg, i);
3385 if (!nl_reg_rule)
3386 goto nla_put_failure;
3387
3388 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3389 reg_rule->flags);
3390 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3391 freq_range->start_freq_khz);
3392 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3393 freq_range->end_freq_khz);
3394 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3395 freq_range->max_bandwidth_khz);
3396 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3397 power_rule->max_antenna_gain);
3398 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3399 power_rule->max_eirp);
3400
3401 nla_nest_end(msg, nl_reg_rule);
3402 }
3403
3404 nla_nest_end(msg, nl_reg_rules);
3405
3406 genlmsg_end(msg, hdr);
134e6375 3407 err = genlmsg_reply(msg, info);
f130347c
LR
3408 goto out;
3409
3410nla_put_failure:
3411 genlmsg_cancel(msg, hdr);
efe1cf0c 3412put_failure:
d080e275 3413 nlmsg_free(msg);
f130347c
LR
3414 err = -EMSGSIZE;
3415out:
a1794390 3416 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3417 return err;
3418}
3419
b2e1b302
LR
3420static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3421{
3422 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3423 struct nlattr *nl_reg_rule;
3424 char *alpha2 = NULL;
3425 int rem_reg_rules = 0, r = 0;
3426 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3427 struct ieee80211_regdomain *rd = NULL;
3428
3429 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3430 return -EINVAL;
3431
3432 if (!info->attrs[NL80211_ATTR_REG_RULES])
3433 return -EINVAL;
3434
3435 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3436
3437 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3438 rem_reg_rules) {
3439 num_rules++;
3440 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3441 return -EINVAL;
b2e1b302
LR
3442 }
3443
61405e97
LR
3444 mutex_lock(&cfg80211_mutex);
3445
d0e18f83
LR
3446 if (!reg_is_valid_request(alpha2)) {
3447 r = -EINVAL;
3448 goto bad_reg;
3449 }
b2e1b302
LR
3450
3451 size_of_regd = sizeof(struct ieee80211_regdomain) +
3452 (num_rules * sizeof(struct ieee80211_reg_rule));
3453
3454 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3455 if (!rd) {
3456 r = -ENOMEM;
3457 goto bad_reg;
3458 }
b2e1b302
LR
3459
3460 rd->n_reg_rules = num_rules;
3461 rd->alpha2[0] = alpha2[0];
3462 rd->alpha2[1] = alpha2[1];
3463
3464 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3465 rem_reg_rules) {
3466 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3467 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3468 reg_rule_policy);
3469 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3470 if (r)
3471 goto bad_reg;
3472
3473 rule_idx++;
3474
d0e18f83
LR
3475 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3476 r = -EINVAL;
b2e1b302 3477 goto bad_reg;
d0e18f83 3478 }
b2e1b302
LR
3479 }
3480
3481 BUG_ON(rule_idx != num_rules);
3482
b2e1b302 3483 r = set_regdom(rd);
61405e97 3484
a1794390 3485 mutex_unlock(&cfg80211_mutex);
d0e18f83 3486
b2e1b302
LR
3487 return r;
3488
d2372b31 3489 bad_reg:
61405e97 3490 mutex_unlock(&cfg80211_mutex);
b2e1b302 3491 kfree(rd);
d0e18f83 3492 return r;
b2e1b302
LR
3493}
3494
83f5e2cf
JB
3495static int validate_scan_freqs(struct nlattr *freqs)
3496{
3497 struct nlattr *attr1, *attr2;
3498 int n_channels = 0, tmp1, tmp2;
3499
3500 nla_for_each_nested(attr1, freqs, tmp1) {
3501 n_channels++;
3502 /*
3503 * Some hardware has a limited channel list for
3504 * scanning, and it is pretty much nonsensical
3505 * to scan for a channel twice, so disallow that
3506 * and don't require drivers to check that the
3507 * channel list they get isn't longer than what
3508 * they can scan, as long as they can scan all
3509 * the channels they registered at once.
3510 */
3511 nla_for_each_nested(attr2, freqs, tmp2)
3512 if (attr1 != attr2 &&
3513 nla_get_u32(attr1) == nla_get_u32(attr2))
3514 return 0;
3515 }
3516
3517 return n_channels;
3518}
3519
2a519311
JB
3520static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3521{
4c476991
JB
3522 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3523 struct net_device *dev = info->user_ptr[1];
2a519311 3524 struct cfg80211_scan_request *request;
2a519311
JB
3525 struct nlattr *attr;
3526 struct wiphy *wiphy;
83f5e2cf 3527 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 3528 size_t ie_len;
2a519311 3529
f4a11bb0
JB
3530 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3531 return -EINVAL;
3532
79c97e97 3533 wiphy = &rdev->wiphy;
2a519311 3534
4c476991
JB
3535 if (!rdev->ops->scan)
3536 return -EOPNOTSUPP;
2a519311 3537
4c476991
JB
3538 if (rdev->scan_req)
3539 return -EBUSY;
2a519311
JB
3540
3541 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3542 n_channels = validate_scan_freqs(
3543 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3544 if (!n_channels)
3545 return -EINVAL;
2a519311 3546 } else {
34850ab2 3547 enum ieee80211_band band;
83f5e2cf
JB
3548 n_channels = 0;
3549
2a519311
JB
3550 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3551 if (wiphy->bands[band])
3552 n_channels += wiphy->bands[band]->n_channels;
3553 }
3554
3555 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3556 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3557 n_ssids++;
3558
4c476991
JB
3559 if (n_ssids > wiphy->max_scan_ssids)
3560 return -EINVAL;
2a519311 3561
70692ad2
JM
3562 if (info->attrs[NL80211_ATTR_IE])
3563 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3564 else
3565 ie_len = 0;
3566
4c476991
JB
3567 if (ie_len > wiphy->max_scan_ie_len)
3568 return -EINVAL;
18a83659 3569
2a519311 3570 request = kzalloc(sizeof(*request)
a2cd43c5
LC
3571 + sizeof(*request->ssids) * n_ssids
3572 + sizeof(*request->channels) * n_channels
70692ad2 3573 + ie_len, GFP_KERNEL);
4c476991
JB
3574 if (!request)
3575 return -ENOMEM;
2a519311 3576
2a519311 3577 if (n_ssids)
5ba63533 3578 request->ssids = (void *)&request->channels[n_channels];
2a519311 3579 request->n_ssids = n_ssids;
70692ad2
JM
3580 if (ie_len) {
3581 if (request->ssids)
3582 request->ie = (void *)(request->ssids + n_ssids);
3583 else
3584 request->ie = (void *)(request->channels + n_channels);
3585 }
2a519311 3586
584991dc 3587 i = 0;
2a519311
JB
3588 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3589 /* user specified, bail out if channel not found */
2a519311 3590 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3591 struct ieee80211_channel *chan;
3592
3593 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3594
3595 if (!chan) {
2a519311
JB
3596 err = -EINVAL;
3597 goto out_free;
3598 }
584991dc
JB
3599
3600 /* ignore disabled channels */
3601 if (chan->flags & IEEE80211_CHAN_DISABLED)
3602 continue;
3603
3604 request->channels[i] = chan;
2a519311
JB
3605 i++;
3606 }
3607 } else {
34850ab2
JB
3608 enum ieee80211_band band;
3609
2a519311 3610 /* all channels */
2a519311
JB
3611 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3612 int j;
3613 if (!wiphy->bands[band])
3614 continue;
3615 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3616 struct ieee80211_channel *chan;
3617
3618 chan = &wiphy->bands[band]->channels[j];
3619
3620 if (chan->flags & IEEE80211_CHAN_DISABLED)
3621 continue;
3622
3623 request->channels[i] = chan;
2a519311
JB
3624 i++;
3625 }
3626 }
3627 }
3628
584991dc
JB
3629 if (!i) {
3630 err = -EINVAL;
3631 goto out_free;
3632 }
3633
3634 request->n_channels = i;
3635
2a519311
JB
3636 i = 0;
3637 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3638 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 3639 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
3640 err = -EINVAL;
3641 goto out_free;
3642 }
57a27e1d 3643 request->ssids[i].ssid_len = nla_len(attr);
2a519311 3644 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
3645 i++;
3646 }
3647 }
3648
70692ad2
JM
3649 if (info->attrs[NL80211_ATTR_IE]) {
3650 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3651 memcpy((void *)request->ie,
3652 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3653 request->ie_len);
3654 }
3655
34850ab2 3656 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
3657 if (wiphy->bands[i])
3658 request->rates[i] =
3659 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
3660
3661 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
3662 nla_for_each_nested(attr,
3663 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
3664 tmp) {
3665 enum ieee80211_band band = nla_type(attr);
3666
84404623 3667 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
3668 err = -EINVAL;
3669 goto out_free;
3670 }
3671 err = ieee80211_get_ratemask(wiphy->bands[band],
3672 nla_data(attr),
3673 nla_len(attr),
3674 &request->rates[band]);
3675 if (err)
3676 goto out_free;
3677 }
3678 }
3679
e9f935e3
RM
3680 request->no_cck =
3681 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
3682
463d0183 3683 request->dev = dev;
79c97e97 3684 request->wiphy = &rdev->wiphy;
2a519311 3685
79c97e97
JB
3686 rdev->scan_req = request;
3687 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3688
463d0183 3689 if (!err) {
79c97e97 3690 nl80211_send_scan_start(rdev, dev);
463d0183 3691 dev_hold(dev);
4c476991 3692 } else {
2a519311 3693 out_free:
79c97e97 3694 rdev->scan_req = NULL;
2a519311
JB
3695 kfree(request);
3696 }
3b85875a 3697
2a519311
JB
3698 return err;
3699}
3700
807f8a8c
LC
3701static int nl80211_start_sched_scan(struct sk_buff *skb,
3702 struct genl_info *info)
3703{
3704 struct cfg80211_sched_scan_request *request;
3705 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3706 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
3707 struct nlattr *attr;
3708 struct wiphy *wiphy;
a1f1c21c 3709 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 3710 u32 interval;
807f8a8c
LC
3711 enum ieee80211_band band;
3712 size_t ie_len;
a1f1c21c 3713 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
3714
3715 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3716 !rdev->ops->sched_scan_start)
3717 return -EOPNOTSUPP;
3718
3719 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3720 return -EINVAL;
3721
bbe6ad6d
LC
3722 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3723 return -EINVAL;
3724
3725 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3726 if (interval == 0)
3727 return -EINVAL;
3728
807f8a8c
LC
3729 wiphy = &rdev->wiphy;
3730
3731 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3732 n_channels = validate_scan_freqs(
3733 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3734 if (!n_channels)
3735 return -EINVAL;
3736 } else {
3737 n_channels = 0;
3738
3739 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3740 if (wiphy->bands[band])
3741 n_channels += wiphy->bands[band]->n_channels;
3742 }
3743
3744 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3745 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3746 tmp)
3747 n_ssids++;
3748
93b6aa69 3749 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
3750 return -EINVAL;
3751
a1f1c21c
LC
3752 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
3753 nla_for_each_nested(attr,
3754 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3755 tmp)
3756 n_match_sets++;
3757
3758 if (n_match_sets > wiphy->max_match_sets)
3759 return -EINVAL;
3760
807f8a8c
LC
3761 if (info->attrs[NL80211_ATTR_IE])
3762 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3763 else
3764 ie_len = 0;
3765
5a865bad 3766 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
3767 return -EINVAL;
3768
c10841ca
LC
3769 mutex_lock(&rdev->sched_scan_mtx);
3770
3771 if (rdev->sched_scan_req) {
3772 err = -EINPROGRESS;
3773 goto out;
3774 }
3775
807f8a8c 3776 request = kzalloc(sizeof(*request)
a2cd43c5 3777 + sizeof(*request->ssids) * n_ssids
a1f1c21c 3778 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 3779 + sizeof(*request->channels) * n_channels
807f8a8c 3780 + ie_len, GFP_KERNEL);
c10841ca
LC
3781 if (!request) {
3782 err = -ENOMEM;
3783 goto out;
3784 }
807f8a8c
LC
3785
3786 if (n_ssids)
3787 request->ssids = (void *)&request->channels[n_channels];
3788 request->n_ssids = n_ssids;
3789 if (ie_len) {
3790 if (request->ssids)
3791 request->ie = (void *)(request->ssids + n_ssids);
3792 else
3793 request->ie = (void *)(request->channels + n_channels);
3794 }
3795
a1f1c21c
LC
3796 if (n_match_sets) {
3797 if (request->ie)
3798 request->match_sets = (void *)(request->ie + ie_len);
3799 else if (request->ssids)
3800 request->match_sets =
3801 (void *)(request->ssids + n_ssids);
3802 else
3803 request->match_sets =
3804 (void *)(request->channels + n_channels);
3805 }
3806 request->n_match_sets = n_match_sets;
3807
807f8a8c
LC
3808 i = 0;
3809 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3810 /* user specified, bail out if channel not found */
3811 nla_for_each_nested(attr,
3812 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
3813 tmp) {
3814 struct ieee80211_channel *chan;
3815
3816 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3817
3818 if (!chan) {
3819 err = -EINVAL;
3820 goto out_free;
3821 }
3822
3823 /* ignore disabled channels */
3824 if (chan->flags & IEEE80211_CHAN_DISABLED)
3825 continue;
3826
3827 request->channels[i] = chan;
3828 i++;
3829 }
3830 } else {
3831 /* all channels */
3832 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3833 int j;
3834 if (!wiphy->bands[band])
3835 continue;
3836 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3837 struct ieee80211_channel *chan;
3838
3839 chan = &wiphy->bands[band]->channels[j];
3840
3841 if (chan->flags & IEEE80211_CHAN_DISABLED)
3842 continue;
3843
3844 request->channels[i] = chan;
3845 i++;
3846 }
3847 }
3848 }
3849
3850 if (!i) {
3851 err = -EINVAL;
3852 goto out_free;
3853 }
3854
3855 request->n_channels = i;
3856
3857 i = 0;
3858 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3859 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3860 tmp) {
57a27e1d 3861 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
3862 err = -EINVAL;
3863 goto out_free;
3864 }
57a27e1d 3865 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
3866 memcpy(request->ssids[i].ssid, nla_data(attr),
3867 nla_len(attr));
807f8a8c
LC
3868 i++;
3869 }
3870 }
3871
a1f1c21c
LC
3872 i = 0;
3873 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
3874 nla_for_each_nested(attr,
3875 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3876 tmp) {
3877 struct nlattr *ssid;
3878
3879 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
3880 nla_data(attr), nla_len(attr),
3881 nl80211_match_policy);
3882 ssid = tb[NL80211_ATTR_SCHED_SCAN_MATCH_SSID];
3883 if (ssid) {
3884 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
3885 err = -EINVAL;
3886 goto out_free;
3887 }
3888 memcpy(request->match_sets[i].ssid.ssid,
3889 nla_data(ssid), nla_len(ssid));
3890 request->match_sets[i].ssid.ssid_len =
3891 nla_len(ssid);
3892 }
3893 i++;
3894 }
3895 }
3896
807f8a8c
LC
3897 if (info->attrs[NL80211_ATTR_IE]) {
3898 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3899 memcpy((void *)request->ie,
3900 nla_data(info->attrs[NL80211_ATTR_IE]),
3901 request->ie_len);
3902 }
3903
3904 request->dev = dev;
3905 request->wiphy = &rdev->wiphy;
bbe6ad6d 3906 request->interval = interval;
807f8a8c
LC
3907
3908 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
3909 if (!err) {
3910 rdev->sched_scan_req = request;
3911 nl80211_send_sched_scan(rdev, dev,
3912 NL80211_CMD_START_SCHED_SCAN);
3913 goto out;
3914 }
3915
3916out_free:
3917 kfree(request);
3918out:
c10841ca 3919 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
3920 return err;
3921}
3922
3923static int nl80211_stop_sched_scan(struct sk_buff *skb,
3924 struct genl_info *info)
3925{
3926 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 3927 int err;
807f8a8c
LC
3928
3929 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3930 !rdev->ops->sched_scan_stop)
3931 return -EOPNOTSUPP;
3932
c10841ca
LC
3933 mutex_lock(&rdev->sched_scan_mtx);
3934 err = __cfg80211_stop_sched_scan(rdev, false);
3935 mutex_unlock(&rdev->sched_scan_mtx);
3936
3937 return err;
807f8a8c
LC
3938}
3939
9720bb3a
JB
3940static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
3941 u32 seq, int flags,
2a519311 3942 struct cfg80211_registered_device *rdev,
48ab905d
JB
3943 struct wireless_dev *wdev,
3944 struct cfg80211_internal_bss *intbss)
2a519311 3945{
48ab905d 3946 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3947 void *hdr;
3948 struct nlattr *bss;
48ab905d
JB
3949 int i;
3950
3951 ASSERT_WDEV_LOCK(wdev);
2a519311 3952
9720bb3a 3953 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
3954 NL80211_CMD_NEW_SCAN_RESULTS);
3955 if (!hdr)
3956 return -1;
3957
9720bb3a
JB
3958 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
3959
f5ea9120 3960 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3961 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3962
3963 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3964 if (!bss)
3965 goto nla_put_failure;
3966 if (!is_zero_ether_addr(res->bssid))
3967 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3968 if (res->information_elements && res->len_information_elements)
3969 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3970 res->len_information_elements,
3971 res->information_elements);
34a6eddb
JM
3972 if (res->beacon_ies && res->len_beacon_ies &&
3973 res->beacon_ies != res->information_elements)
3974 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3975 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3976 if (res->tsf)
3977 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3978 if (res->beacon_interval)
3979 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3980 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3981 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3982 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3983 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3984
77965c97 3985 switch (rdev->wiphy.signal_type) {
2a519311
JB
3986 case CFG80211_SIGNAL_TYPE_MBM:
3987 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3988 break;
3989 case CFG80211_SIGNAL_TYPE_UNSPEC:
3990 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3991 break;
3992 default:
3993 break;
3994 }
3995
48ab905d 3996 switch (wdev->iftype) {
074ac8df 3997 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3998 case NL80211_IFTYPE_STATION:
3999 if (intbss == wdev->current_bss)
4000 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4001 NL80211_BSS_STATUS_ASSOCIATED);
4002 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
4003 if (intbss != wdev->auth_bsses[i])
4004 continue;
4005 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4006 NL80211_BSS_STATUS_AUTHENTICATED);
4007 break;
4008 }
4009 break;
4010 case NL80211_IFTYPE_ADHOC:
4011 if (intbss == wdev->current_bss)
4012 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4013 NL80211_BSS_STATUS_IBSS_JOINED);
4014 break;
4015 default:
4016 break;
4017 }
4018
2a519311
JB
4019 nla_nest_end(msg, bss);
4020
4021 return genlmsg_end(msg, hdr);
4022
4023 nla_put_failure:
4024 genlmsg_cancel(msg, hdr);
4025 return -EMSGSIZE;
4026}
4027
4028static int nl80211_dump_scan(struct sk_buff *skb,
4029 struct netlink_callback *cb)
4030{
48ab905d
JB
4031 struct cfg80211_registered_device *rdev;
4032 struct net_device *dev;
2a519311 4033 struct cfg80211_internal_bss *scan;
48ab905d 4034 struct wireless_dev *wdev;
2a519311
JB
4035 int start = cb->args[1], idx = 0;
4036 int err;
4037
67748893
JB
4038 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4039 if (err)
4040 return err;
2a519311 4041
48ab905d 4042 wdev = dev->ieee80211_ptr;
2a519311 4043
48ab905d
JB
4044 wdev_lock(wdev);
4045 spin_lock_bh(&rdev->bss_lock);
4046 cfg80211_bss_expire(rdev);
4047
9720bb3a
JB
4048 cb->seq = rdev->bss_generation;
4049
48ab905d 4050 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4051 if (++idx <= start)
4052 continue;
9720bb3a 4053 if (nl80211_send_bss(skb, cb,
2a519311 4054 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4055 rdev, wdev, scan) < 0) {
2a519311 4056 idx--;
67748893 4057 break;
2a519311
JB
4058 }
4059 }
4060
48ab905d
JB
4061 spin_unlock_bh(&rdev->bss_lock);
4062 wdev_unlock(wdev);
2a519311
JB
4063
4064 cb->args[1] = idx;
67748893 4065 nl80211_finish_netdev_dump(rdev);
2a519311 4066
67748893 4067 return skb->len;
2a519311
JB
4068}
4069
61fa713c
HS
4070static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4071 int flags, struct net_device *dev,
4072 struct survey_info *survey)
4073{
4074 void *hdr;
4075 struct nlattr *infoattr;
4076
61fa713c
HS
4077 hdr = nl80211hdr_put(msg, pid, seq, flags,
4078 NL80211_CMD_NEW_SURVEY_RESULTS);
4079 if (!hdr)
4080 return -ENOMEM;
4081
4082 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
4083
4084 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4085 if (!infoattr)
4086 goto nla_put_failure;
4087
4088 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4089 survey->channel->center_freq);
4090 if (survey->filled & SURVEY_INFO_NOISE_DBM)
4091 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
4092 survey->noise);
17e5a808
FF
4093 if (survey->filled & SURVEY_INFO_IN_USE)
4094 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
4095 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
4096 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4097 survey->channel_time);
4098 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
4099 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4100 survey->channel_time_busy);
4101 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
4102 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4103 survey->channel_time_ext_busy);
4104 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
4105 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4106 survey->channel_time_rx);
4107 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
4108 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4109 survey->channel_time_tx);
61fa713c
HS
4110
4111 nla_nest_end(msg, infoattr);
4112
4113 return genlmsg_end(msg, hdr);
4114
4115 nla_put_failure:
4116 genlmsg_cancel(msg, hdr);
4117 return -EMSGSIZE;
4118}
4119
4120static int nl80211_dump_survey(struct sk_buff *skb,
4121 struct netlink_callback *cb)
4122{
4123 struct survey_info survey;
4124 struct cfg80211_registered_device *dev;
4125 struct net_device *netdev;
61fa713c
HS
4126 int survey_idx = cb->args[1];
4127 int res;
4128
67748893
JB
4129 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4130 if (res)
4131 return res;
61fa713c
HS
4132
4133 if (!dev->ops->dump_survey) {
4134 res = -EOPNOTSUPP;
4135 goto out_err;
4136 }
4137
4138 while (1) {
180cdc79
LR
4139 struct ieee80211_channel *chan;
4140
61fa713c
HS
4141 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4142 &survey);
4143 if (res == -ENOENT)
4144 break;
4145 if (res)
4146 goto out_err;
4147
180cdc79
LR
4148 /* Survey without a channel doesn't make sense */
4149 if (!survey.channel) {
4150 res = -EINVAL;
4151 goto out;
4152 }
4153
4154 chan = ieee80211_get_channel(&dev->wiphy,
4155 survey.channel->center_freq);
4156 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4157 survey_idx++;
4158 continue;
4159 }
4160
61fa713c
HS
4161 if (nl80211_send_survey(skb,
4162 NETLINK_CB(cb->skb).pid,
4163 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4164 netdev,
4165 &survey) < 0)
4166 goto out;
4167 survey_idx++;
4168 }
4169
4170 out:
4171 cb->args[1] = survey_idx;
4172 res = skb->len;
4173 out_err:
67748893 4174 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4175 return res;
4176}
4177
255e737e
JM
4178static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4179{
b23aa676
SO
4180 return auth_type <= NL80211_AUTHTYPE_MAX;
4181}
4182
4183static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4184{
4185 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4186 NL80211_WPA_VERSION_2));
4187}
4188
636a5d36
JM
4189static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4190{
4c476991
JB
4191 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4192 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4193 struct ieee80211_channel *chan;
4194 const u8 *bssid, *ssid, *ie = NULL;
4195 int err, ssid_len, ie_len = 0;
4196 enum nl80211_auth_type auth_type;
fffd0934 4197 struct key_parse key;
d5cdfacb 4198 bool local_state_change;
636a5d36 4199
f4a11bb0
JB
4200 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4201 return -EINVAL;
4202
4203 if (!info->attrs[NL80211_ATTR_MAC])
4204 return -EINVAL;
4205
1778092e
JM
4206 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4207 return -EINVAL;
4208
19957bb3
JB
4209 if (!info->attrs[NL80211_ATTR_SSID])
4210 return -EINVAL;
4211
4212 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4213 return -EINVAL;
4214
fffd0934
JB
4215 err = nl80211_parse_key(info, &key);
4216 if (err)
4217 return err;
4218
4219 if (key.idx >= 0) {
e31b8213
JB
4220 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4221 return -EINVAL;
fffd0934
JB
4222 if (!key.p.key || !key.p.key_len)
4223 return -EINVAL;
4224 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4225 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4226 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4227 key.p.key_len != WLAN_KEY_LEN_WEP104))
4228 return -EINVAL;
4229 if (key.idx > 4)
4230 return -EINVAL;
4231 } else {
4232 key.p.key_len = 0;
4233 key.p.key = NULL;
4234 }
4235
afea0b7a
JB
4236 if (key.idx >= 0) {
4237 int i;
4238 bool ok = false;
4239 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4240 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4241 ok = true;
4242 break;
4243 }
4244 }
4c476991
JB
4245 if (!ok)
4246 return -EINVAL;
afea0b7a
JB
4247 }
4248
4c476991
JB
4249 if (!rdev->ops->auth)
4250 return -EOPNOTSUPP;
636a5d36 4251
074ac8df 4252 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4253 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4254 return -EOPNOTSUPP;
eec60b03 4255
19957bb3 4256 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4257 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4258 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4259 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4260 return -EINVAL;
636a5d36 4261
19957bb3
JB
4262 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4263 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4264
4265 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4266 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4267 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4268 }
4269
19957bb3 4270 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4271 if (!nl80211_valid_auth_type(auth_type))
4272 return -EINVAL;
636a5d36 4273
d5cdfacb
JM
4274 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4275
4c476991
JB
4276 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4277 ssid, ssid_len, ie, ie_len,
4278 key.p.key, key.p.key_len, key.idx,
4279 local_state_change);
636a5d36
JM
4280}
4281
c0692b8f
JB
4282static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4283 struct genl_info *info,
3dc27d25
JB
4284 struct cfg80211_crypto_settings *settings,
4285 int cipher_limit)
b23aa676 4286{
c0b2bbd8
JB
4287 memset(settings, 0, sizeof(*settings));
4288
b23aa676
SO
4289 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4290
c0692b8f
JB
4291 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4292 u16 proto;
4293 proto = nla_get_u16(
4294 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4295 settings->control_port_ethertype = cpu_to_be16(proto);
4296 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4297 proto != ETH_P_PAE)
4298 return -EINVAL;
4299 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4300 settings->control_port_no_encrypt = true;
4301 } else
4302 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4303
b23aa676
SO
4304 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4305 void *data;
4306 int len, i;
4307
4308 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4309 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4310 settings->n_ciphers_pairwise = len / sizeof(u32);
4311
4312 if (len % sizeof(u32))
4313 return -EINVAL;
4314
3dc27d25 4315 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4316 return -EINVAL;
4317
4318 memcpy(settings->ciphers_pairwise, data, len);
4319
4320 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4321 if (!cfg80211_supported_cipher_suite(
4322 &rdev->wiphy,
b23aa676
SO
4323 settings->ciphers_pairwise[i]))
4324 return -EINVAL;
4325 }
4326
4327 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4328 settings->cipher_group =
4329 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4330 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4331 settings->cipher_group))
b23aa676
SO
4332 return -EINVAL;
4333 }
4334
4335 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4336 settings->wpa_versions =
4337 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4338 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4339 return -EINVAL;
4340 }
4341
4342 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4343 void *data;
6d30240e 4344 int len;
b23aa676
SO
4345
4346 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4347 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4348 settings->n_akm_suites = len / sizeof(u32);
4349
4350 if (len % sizeof(u32))
4351 return -EINVAL;
4352
1b9ca027
JM
4353 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4354 return -EINVAL;
4355
b23aa676 4356 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4357 }
4358
4359 return 0;
4360}
4361
636a5d36
JM
4362static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4363{
4c476991
JB
4364 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4365 struct net_device *dev = info->user_ptr[1];
19957bb3 4366 struct cfg80211_crypto_settings crypto;
f444de05 4367 struct ieee80211_channel *chan;
3e5d7649 4368 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4369 int err, ssid_len, ie_len = 0;
4370 bool use_mfp = false;
636a5d36 4371
f4a11bb0
JB
4372 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4373 return -EINVAL;
4374
4375 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4376 !info->attrs[NL80211_ATTR_SSID] ||
4377 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4378 return -EINVAL;
4379
4c476991
JB
4380 if (!rdev->ops->assoc)
4381 return -EOPNOTSUPP;
636a5d36 4382
074ac8df 4383 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4384 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4385 return -EOPNOTSUPP;
eec60b03 4386
19957bb3 4387 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4388
19957bb3
JB
4389 chan = ieee80211_get_channel(&rdev->wiphy,
4390 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4391 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4392 return -EINVAL;
636a5d36 4393
19957bb3
JB
4394 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4395 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4396
4397 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4398 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4399 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4400 }
4401
dc6382ce 4402 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4403 enum nl80211_mfp mfp =
dc6382ce 4404 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4405 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4406 use_mfp = true;
4c476991
JB
4407 else if (mfp != NL80211_MFP_NO)
4408 return -EINVAL;
dc6382ce
JM
4409 }
4410
3e5d7649
JB
4411 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4412 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4413
c0692b8f 4414 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4415 if (!err)
3e5d7649
JB
4416 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4417 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 4418 &crypto);
636a5d36 4419
636a5d36
JM
4420 return err;
4421}
4422
4423static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4424{
4c476991
JB
4425 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4426 struct net_device *dev = info->user_ptr[1];
19957bb3 4427 const u8 *ie = NULL, *bssid;
4c476991 4428 int ie_len = 0;
19957bb3 4429 u16 reason_code;
d5cdfacb 4430 bool local_state_change;
636a5d36 4431
f4a11bb0
JB
4432 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4433 return -EINVAL;
4434
4435 if (!info->attrs[NL80211_ATTR_MAC])
4436 return -EINVAL;
4437
4438 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4439 return -EINVAL;
4440
4c476991
JB
4441 if (!rdev->ops->deauth)
4442 return -EOPNOTSUPP;
636a5d36 4443
074ac8df 4444 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4445 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4446 return -EOPNOTSUPP;
eec60b03 4447
19957bb3 4448 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4449
19957bb3
JB
4450 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4451 if (reason_code == 0) {
f4a11bb0 4452 /* Reason Code 0 is reserved */
4c476991 4453 return -EINVAL;
255e737e 4454 }
636a5d36
JM
4455
4456 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4457 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4458 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4459 }
4460
d5cdfacb
JM
4461 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4462
4c476991
JB
4463 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4464 local_state_change);
636a5d36
JM
4465}
4466
4467static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4468{
4c476991
JB
4469 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4470 struct net_device *dev = info->user_ptr[1];
19957bb3 4471 const u8 *ie = NULL, *bssid;
4c476991 4472 int ie_len = 0;
19957bb3 4473 u16 reason_code;
d5cdfacb 4474 bool local_state_change;
636a5d36 4475
f4a11bb0
JB
4476 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4477 return -EINVAL;
4478
4479 if (!info->attrs[NL80211_ATTR_MAC])
4480 return -EINVAL;
4481
4482 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4483 return -EINVAL;
4484
4c476991
JB
4485 if (!rdev->ops->disassoc)
4486 return -EOPNOTSUPP;
636a5d36 4487
074ac8df 4488 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4489 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4490 return -EOPNOTSUPP;
eec60b03 4491
19957bb3 4492 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4493
19957bb3
JB
4494 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4495 if (reason_code == 0) {
f4a11bb0 4496 /* Reason Code 0 is reserved */
4c476991 4497 return -EINVAL;
255e737e 4498 }
636a5d36
JM
4499
4500 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4501 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4502 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4503 }
4504
d5cdfacb
JM
4505 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4506
4c476991
JB
4507 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4508 local_state_change);
636a5d36
JM
4509}
4510
dd5b4cc7
FF
4511static bool
4512nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4513 int mcast_rate[IEEE80211_NUM_BANDS],
4514 int rateval)
4515{
4516 struct wiphy *wiphy = &rdev->wiphy;
4517 bool found = false;
4518 int band, i;
4519
4520 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4521 struct ieee80211_supported_band *sband;
4522
4523 sband = wiphy->bands[band];
4524 if (!sband)
4525 continue;
4526
4527 for (i = 0; i < sband->n_bitrates; i++) {
4528 if (sband->bitrates[i].bitrate == rateval) {
4529 mcast_rate[band] = i + 1;
4530 found = true;
4531 break;
4532 }
4533 }
4534 }
4535
4536 return found;
4537}
4538
04a773ad
JB
4539static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4540{
4c476991
JB
4541 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4542 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4543 struct cfg80211_ibss_params ibss;
4544 struct wiphy *wiphy;
fffd0934 4545 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4546 int err;
4547
8e30bc55
JB
4548 memset(&ibss, 0, sizeof(ibss));
4549
04a773ad
JB
4550 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4551 return -EINVAL;
4552
4553 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4554 !info->attrs[NL80211_ATTR_SSID] ||
4555 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4556 return -EINVAL;
4557
8e30bc55
JB
4558 ibss.beacon_interval = 100;
4559
4560 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4561 ibss.beacon_interval =
4562 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4563 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4564 return -EINVAL;
4565 }
4566
4c476991
JB
4567 if (!rdev->ops->join_ibss)
4568 return -EOPNOTSUPP;
04a773ad 4569
4c476991
JB
4570 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4571 return -EOPNOTSUPP;
04a773ad 4572
79c97e97 4573 wiphy = &rdev->wiphy;
04a773ad 4574
39193498 4575 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 4576 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
4577
4578 if (!is_valid_ether_addr(ibss.bssid))
4579 return -EINVAL;
4580 }
04a773ad
JB
4581 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4582 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4583
4584 if (info->attrs[NL80211_ATTR_IE]) {
4585 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4586 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4587 }
4588
4589 ibss.channel = ieee80211_get_channel(wiphy,
4590 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4591 if (!ibss.channel ||
4592 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4593 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4594 return -EINVAL;
04a773ad
JB
4595
4596 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4597 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4598
fbd2c8dc
TP
4599 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4600 u8 *rates =
4601 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4602 int n_rates =
4603 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4604 struct ieee80211_supported_band *sband =
4605 wiphy->bands[ibss.channel->band];
34850ab2 4606 int err;
fbd2c8dc 4607
34850ab2
JB
4608 err = ieee80211_get_ratemask(sband, rates, n_rates,
4609 &ibss.basic_rates);
4610 if (err)
4611 return err;
fbd2c8dc 4612 }
dd5b4cc7
FF
4613
4614 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4615 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4616 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4617 return -EINVAL;
fbd2c8dc 4618
4c476991
JB
4619 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4620 connkeys = nl80211_parse_connkeys(rdev,
4621 info->attrs[NL80211_ATTR_KEYS]);
4622 if (IS_ERR(connkeys))
4623 return PTR_ERR(connkeys);
4624 }
04a773ad 4625
4c476991 4626 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4627 if (err)
4628 kfree(connkeys);
04a773ad
JB
4629 return err;
4630}
4631
4632static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4633{
4c476991
JB
4634 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4635 struct net_device *dev = info->user_ptr[1];
04a773ad 4636
4c476991
JB
4637 if (!rdev->ops->leave_ibss)
4638 return -EOPNOTSUPP;
04a773ad 4639
4c476991
JB
4640 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4641 return -EOPNOTSUPP;
04a773ad 4642
4c476991 4643 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4644}
4645
aff89a9b
JB
4646#ifdef CONFIG_NL80211_TESTMODE
4647static struct genl_multicast_group nl80211_testmode_mcgrp = {
4648 .name = "testmode",
4649};
4650
4651static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4652{
4c476991 4653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4654 int err;
4655
4656 if (!info->attrs[NL80211_ATTR_TESTDATA])
4657 return -EINVAL;
4658
aff89a9b
JB
4659 err = -EOPNOTSUPP;
4660 if (rdev->ops->testmode_cmd) {
4661 rdev->testmode_info = info;
4662 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4663 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4664 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4665 rdev->testmode_info = NULL;
4666 }
4667
aff89a9b
JB
4668 return err;
4669}
4670
71063f0e
WYG
4671static int nl80211_testmode_dump(struct sk_buff *skb,
4672 struct netlink_callback *cb)
4673{
4674 struct cfg80211_registered_device *dev;
4675 int err;
4676 long phy_idx;
4677 void *data = NULL;
4678 int data_len = 0;
4679
4680 if (cb->args[0]) {
4681 /*
4682 * 0 is a valid index, but not valid for args[0],
4683 * so we need to offset by 1.
4684 */
4685 phy_idx = cb->args[0] - 1;
4686 } else {
4687 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
4688 nl80211_fam.attrbuf, nl80211_fam.maxattr,
4689 nl80211_policy);
4690 if (err)
4691 return err;
4692 if (!nl80211_fam.attrbuf[NL80211_ATTR_WIPHY])
4693 return -EINVAL;
4694 phy_idx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
4695 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
4696 cb->args[1] =
4697 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
4698 }
4699
4700 if (cb->args[1]) {
4701 data = nla_data((void *)cb->args[1]);
4702 data_len = nla_len((void *)cb->args[1]);
4703 }
4704
4705 mutex_lock(&cfg80211_mutex);
4706 dev = cfg80211_rdev_by_wiphy_idx(phy_idx);
4707 if (!dev) {
4708 mutex_unlock(&cfg80211_mutex);
4709 return -ENOENT;
4710 }
4711 cfg80211_lock_rdev(dev);
4712 mutex_unlock(&cfg80211_mutex);
4713
4714 if (!dev->ops->testmode_dump) {
4715 err = -EOPNOTSUPP;
4716 goto out_err;
4717 }
4718
4719 while (1) {
4720 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
4721 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4722 NL80211_CMD_TESTMODE);
4723 struct nlattr *tmdata;
4724
4725 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, dev->wiphy_idx) < 0) {
4726 genlmsg_cancel(skb, hdr);
4727 break;
4728 }
4729
4730 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4731 if (!tmdata) {
4732 genlmsg_cancel(skb, hdr);
4733 break;
4734 }
4735 err = dev->ops->testmode_dump(&dev->wiphy, skb, cb,
4736 data, data_len);
4737 nla_nest_end(skb, tmdata);
4738
4739 if (err == -ENOBUFS || err == -ENOENT) {
4740 genlmsg_cancel(skb, hdr);
4741 break;
4742 } else if (err) {
4743 genlmsg_cancel(skb, hdr);
4744 goto out_err;
4745 }
4746
4747 genlmsg_end(skb, hdr);
4748 }
4749
4750 err = skb->len;
4751 /* see above */
4752 cb->args[0] = phy_idx + 1;
4753 out_err:
4754 cfg80211_unlock_rdev(dev);
4755 return err;
4756}
4757
aff89a9b
JB
4758static struct sk_buff *
4759__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4760 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4761{
4762 struct sk_buff *skb;
4763 void *hdr;
4764 struct nlattr *data;
4765
4766 skb = nlmsg_new(approxlen + 100, gfp);
4767 if (!skb)
4768 return NULL;
4769
4770 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4771 if (!hdr) {
4772 kfree_skb(skb);
4773 return NULL;
4774 }
4775
4776 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4777 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4778
4779 ((void **)skb->cb)[0] = rdev;
4780 ((void **)skb->cb)[1] = hdr;
4781 ((void **)skb->cb)[2] = data;
4782
4783 return skb;
4784
4785 nla_put_failure:
4786 kfree_skb(skb);
4787 return NULL;
4788}
4789
4790struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4791 int approxlen)
4792{
4793 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4794
4795 if (WARN_ON(!rdev->testmode_info))
4796 return NULL;
4797
4798 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4799 rdev->testmode_info->snd_pid,
4800 rdev->testmode_info->snd_seq,
4801 GFP_KERNEL);
4802}
4803EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4804
4805int cfg80211_testmode_reply(struct sk_buff *skb)
4806{
4807 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4808 void *hdr = ((void **)skb->cb)[1];
4809 struct nlattr *data = ((void **)skb->cb)[2];
4810
4811 if (WARN_ON(!rdev->testmode_info)) {
4812 kfree_skb(skb);
4813 return -EINVAL;
4814 }
4815
4816 nla_nest_end(skb, data);
4817 genlmsg_end(skb, hdr);
4818 return genlmsg_reply(skb, rdev->testmode_info);
4819}
4820EXPORT_SYMBOL(cfg80211_testmode_reply);
4821
4822struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4823 int approxlen, gfp_t gfp)
4824{
4825 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4826
4827 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4828}
4829EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4830
4831void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4832{
4833 void *hdr = ((void **)skb->cb)[1];
4834 struct nlattr *data = ((void **)skb->cb)[2];
4835
4836 nla_nest_end(skb, data);
4837 genlmsg_end(skb, hdr);
4838 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4839}
4840EXPORT_SYMBOL(cfg80211_testmode_event);
4841#endif
4842
b23aa676
SO
4843static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4844{
4c476991
JB
4845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4846 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4847 struct cfg80211_connect_params connect;
4848 struct wiphy *wiphy;
fffd0934 4849 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4850 int err;
4851
4852 memset(&connect, 0, sizeof(connect));
4853
4854 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4855 return -EINVAL;
4856
4857 if (!info->attrs[NL80211_ATTR_SSID] ||
4858 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4859 return -EINVAL;
4860
4861 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4862 connect.auth_type =
4863 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4864 if (!nl80211_valid_auth_type(connect.auth_type))
4865 return -EINVAL;
4866 } else
4867 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4868
4869 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4870
c0692b8f 4871 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4872 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4873 if (err)
4874 return err;
b23aa676 4875
074ac8df 4876 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4877 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4878 return -EOPNOTSUPP;
b23aa676 4879
79c97e97 4880 wiphy = &rdev->wiphy;
b23aa676 4881
b23aa676
SO
4882 if (info->attrs[NL80211_ATTR_MAC])
4883 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4884 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4885 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4886
4887 if (info->attrs[NL80211_ATTR_IE]) {
4888 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4889 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4890 }
4891
4892 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4893 connect.channel =
4894 ieee80211_get_channel(wiphy,
4895 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4896 if (!connect.channel ||
4c476991
JB
4897 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4898 return -EINVAL;
b23aa676
SO
4899 }
4900
fffd0934
JB
4901 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4902 connkeys = nl80211_parse_connkeys(rdev,
4903 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4904 if (IS_ERR(connkeys))
4905 return PTR_ERR(connkeys);
fffd0934
JB
4906 }
4907
4908 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4909 if (err)
4910 kfree(connkeys);
b23aa676
SO
4911 return err;
4912}
4913
4914static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4915{
4c476991
JB
4916 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4917 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4918 u16 reason;
4919
4920 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4921 reason = WLAN_REASON_DEAUTH_LEAVING;
4922 else
4923 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4924
4925 if (reason == 0)
4926 return -EINVAL;
4927
074ac8df 4928 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4929 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4930 return -EOPNOTSUPP;
b23aa676 4931
4c476991 4932 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4933}
4934
463d0183
JB
4935static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4936{
4c476991 4937 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4938 struct net *net;
4939 int err;
4940 u32 pid;
4941
4942 if (!info->attrs[NL80211_ATTR_PID])
4943 return -EINVAL;
4944
4945 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4946
463d0183 4947 net = get_net_ns_by_pid(pid);
4c476991
JB
4948 if (IS_ERR(net))
4949 return PTR_ERR(net);
463d0183
JB
4950
4951 err = 0;
4952
4953 /* check if anything to do */
4c476991
JB
4954 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4955 err = cfg80211_switch_netns(rdev, net);
463d0183 4956
463d0183 4957 put_net(net);
463d0183
JB
4958 return err;
4959}
4960
67fbb16b
SO
4961static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4962{
4c476991 4963 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4964 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4965 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4966 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4967 struct cfg80211_pmksa pmksa;
4968
4969 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4970
4971 if (!info->attrs[NL80211_ATTR_MAC])
4972 return -EINVAL;
4973
4974 if (!info->attrs[NL80211_ATTR_PMKID])
4975 return -EINVAL;
4976
67fbb16b
SO
4977 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4978 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4979
074ac8df 4980 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4981 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4982 return -EOPNOTSUPP;
67fbb16b
SO
4983
4984 switch (info->genlhdr->cmd) {
4985 case NL80211_CMD_SET_PMKSA:
4986 rdev_ops = rdev->ops->set_pmksa;
4987 break;
4988 case NL80211_CMD_DEL_PMKSA:
4989 rdev_ops = rdev->ops->del_pmksa;
4990 break;
4991 default:
4992 WARN_ON(1);
4993 break;
4994 }
4995
4c476991
JB
4996 if (!rdev_ops)
4997 return -EOPNOTSUPP;
67fbb16b 4998
4c476991 4999 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
5000}
5001
5002static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5003{
4c476991
JB
5004 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5005 struct net_device *dev = info->user_ptr[1];
67fbb16b 5006
074ac8df 5007 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5008 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5009 return -EOPNOTSUPP;
67fbb16b 5010
4c476991
JB
5011 if (!rdev->ops->flush_pmksa)
5012 return -EOPNOTSUPP;
67fbb16b 5013
4c476991 5014 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5015}
5016
109086ce
AN
5017static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5018{
5019 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5020 struct net_device *dev = info->user_ptr[1];
5021 u8 action_code, dialog_token;
5022 u16 status_code;
5023 u8 *peer;
5024
5025 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5026 !rdev->ops->tdls_mgmt)
5027 return -EOPNOTSUPP;
5028
5029 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5030 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5031 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5032 !info->attrs[NL80211_ATTR_IE] ||
5033 !info->attrs[NL80211_ATTR_MAC])
5034 return -EINVAL;
5035
5036 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5037 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5038 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5039 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5040
5041 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5042 dialog_token, status_code,
5043 nla_data(info->attrs[NL80211_ATTR_IE]),
5044 nla_len(info->attrs[NL80211_ATTR_IE]));
5045}
5046
5047static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5048{
5049 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5050 struct net_device *dev = info->user_ptr[1];
5051 enum nl80211_tdls_operation operation;
5052 u8 *peer;
5053
5054 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5055 !rdev->ops->tdls_oper)
5056 return -EOPNOTSUPP;
5057
5058 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5059 !info->attrs[NL80211_ATTR_MAC])
5060 return -EINVAL;
5061
5062 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5063 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5064
5065 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5066}
5067
9588bbd5
JM
5068static int nl80211_remain_on_channel(struct sk_buff *skb,
5069 struct genl_info *info)
5070{
4c476991
JB
5071 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5072 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5073 struct ieee80211_channel *chan;
5074 struct sk_buff *msg;
5075 void *hdr;
5076 u64 cookie;
5077 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5078 u32 freq, duration;
5079 int err;
5080
5081 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5082 !info->attrs[NL80211_ATTR_DURATION])
5083 return -EINVAL;
5084
5085 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5086
5087 /*
5088 * We should be on that channel for at least one jiffie,
5089 * and more than 5 seconds seems excessive.
5090 */
a293911d
JB
5091 if (!duration || !msecs_to_jiffies(duration) ||
5092 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5093 return -EINVAL;
5094
4c476991
JB
5095 if (!rdev->ops->remain_on_channel)
5096 return -EOPNOTSUPP;
9588bbd5 5097
9588bbd5
JM
5098 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5099 channel_type = nla_get_u32(
5100 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5101 if (channel_type != NL80211_CHAN_NO_HT &&
5102 channel_type != NL80211_CHAN_HT20 &&
5103 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5104 channel_type != NL80211_CHAN_HT40MINUS)
5105 return -EINVAL;
9588bbd5
JM
5106 }
5107
5108 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5109 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5110 if (chan == NULL)
5111 return -EINVAL;
9588bbd5
JM
5112
5113 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5114 if (!msg)
5115 return -ENOMEM;
9588bbd5
JM
5116
5117 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5118 NL80211_CMD_REMAIN_ON_CHANNEL);
5119
5120 if (IS_ERR(hdr)) {
5121 err = PTR_ERR(hdr);
5122 goto free_msg;
5123 }
5124
5125 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5126 channel_type, duration, &cookie);
5127
5128 if (err)
5129 goto free_msg;
5130
5131 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5132
5133 genlmsg_end(msg, hdr);
4c476991
JB
5134
5135 return genlmsg_reply(msg, info);
9588bbd5
JM
5136
5137 nla_put_failure:
5138 err = -ENOBUFS;
5139 free_msg:
5140 nlmsg_free(msg);
9588bbd5
JM
5141 return err;
5142}
5143
5144static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5145 struct genl_info *info)
5146{
4c476991
JB
5147 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5148 struct net_device *dev = info->user_ptr[1];
9588bbd5 5149 u64 cookie;
9588bbd5
JM
5150
5151 if (!info->attrs[NL80211_ATTR_COOKIE])
5152 return -EINVAL;
5153
4c476991
JB
5154 if (!rdev->ops->cancel_remain_on_channel)
5155 return -EOPNOTSUPP;
9588bbd5 5156
9588bbd5
JM
5157 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5158
4c476991 5159 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5160}
5161
13ae75b1
JM
5162static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5163 u8 *rates, u8 rates_len)
5164{
5165 u8 i;
5166 u32 mask = 0;
5167
5168 for (i = 0; i < rates_len; i++) {
5169 int rate = (rates[i] & 0x7f) * 5;
5170 int ridx;
5171 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5172 struct ieee80211_rate *srate =
5173 &sband->bitrates[ridx];
5174 if (rate == srate->bitrate) {
5175 mask |= 1 << ridx;
5176 break;
5177 }
5178 }
5179 if (ridx == sband->n_bitrates)
5180 return 0; /* rate not found */
5181 }
5182
5183 return mask;
5184}
5185
b54452b0 5186static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5187 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5188 .len = NL80211_MAX_SUPP_RATES },
5189};
5190
5191static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5192 struct genl_info *info)
5193{
5194 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5195 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5196 struct cfg80211_bitrate_mask mask;
4c476991
JB
5197 int rem, i;
5198 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5199 struct nlattr *tx_rates;
5200 struct ieee80211_supported_band *sband;
5201
5202 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5203 return -EINVAL;
5204
4c476991
JB
5205 if (!rdev->ops->set_bitrate_mask)
5206 return -EOPNOTSUPP;
13ae75b1
JM
5207
5208 memset(&mask, 0, sizeof(mask));
5209 /* Default to all rates enabled */
5210 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5211 sband = rdev->wiphy.bands[i];
5212 mask.control[i].legacy =
5213 sband ? (1 << sband->n_bitrates) - 1 : 0;
5214 }
5215
5216 /*
5217 * The nested attribute uses enum nl80211_band as the index. This maps
5218 * directly to the enum ieee80211_band values used in cfg80211.
5219 */
5220 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5221 {
5222 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5223 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5224 return -EINVAL;
13ae75b1 5225 sband = rdev->wiphy.bands[band];
4c476991
JB
5226 if (sband == NULL)
5227 return -EINVAL;
13ae75b1
JM
5228 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5229 nla_len(tx_rates), nl80211_txattr_policy);
5230 if (tb[NL80211_TXRATE_LEGACY]) {
5231 mask.control[band].legacy = rateset_to_mask(
5232 sband,
5233 nla_data(tb[NL80211_TXRATE_LEGACY]),
5234 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
5235 if (mask.control[band].legacy == 0)
5236 return -EINVAL;
13ae75b1
JM
5237 }
5238 }
5239
4c476991 5240 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5241}
5242
2e161f78 5243static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5244{
4c476991
JB
5245 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5246 struct net_device *dev = info->user_ptr[1];
2e161f78 5247 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5248
5249 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5250 return -EINVAL;
5251
2e161f78
JB
5252 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5253 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5254
9d38d85d 5255 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5256 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5257 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5258 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5259 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5260 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5261 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5262 return -EOPNOTSUPP;
026331c4
JM
5263
5264 /* not much point in registering if we can't reply */
4c476991
JB
5265 if (!rdev->ops->mgmt_tx)
5266 return -EOPNOTSUPP;
026331c4 5267
4c476991 5268 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 5269 frame_type,
026331c4
JM
5270 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5271 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
5272}
5273
2e161f78 5274static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5275{
4c476991
JB
5276 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5277 struct net_device *dev = info->user_ptr[1];
026331c4
JM
5278 struct ieee80211_channel *chan;
5279 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 5280 bool channel_type_valid = false;
026331c4
JM
5281 u32 freq;
5282 int err;
5283 void *hdr;
5284 u64 cookie;
5285 struct sk_buff *msg;
f7ca38df
JB
5286 unsigned int wait = 0;
5287 bool offchan;
e9f935e3 5288 bool no_cck;
026331c4
JM
5289
5290 if (!info->attrs[NL80211_ATTR_FRAME] ||
5291 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5292 return -EINVAL;
5293
4c476991
JB
5294 if (!rdev->ops->mgmt_tx)
5295 return -EOPNOTSUPP;
026331c4 5296
9d38d85d 5297 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5298 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5299 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5300 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5301 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5302 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5303 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5304 return -EOPNOTSUPP;
026331c4 5305
f7ca38df
JB
5306 if (info->attrs[NL80211_ATTR_DURATION]) {
5307 if (!rdev->ops->mgmt_tx_cancel_wait)
5308 return -EINVAL;
5309 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5310 }
5311
026331c4
JM
5312 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5313 channel_type = nla_get_u32(
5314 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5315 if (channel_type != NL80211_CHAN_NO_HT &&
5316 channel_type != NL80211_CHAN_HT20 &&
5317 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5318 channel_type != NL80211_CHAN_HT40MINUS)
5319 return -EINVAL;
252aa631 5320 channel_type_valid = true;
026331c4
JM
5321 }
5322
f7ca38df
JB
5323 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5324
e9f935e3
RM
5325 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5326
026331c4
JM
5327 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5328 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5329 if (chan == NULL)
5330 return -EINVAL;
026331c4
JM
5331
5332 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5333 if (!msg)
5334 return -ENOMEM;
026331c4
JM
5335
5336 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 5337 NL80211_CMD_FRAME);
026331c4
JM
5338
5339 if (IS_ERR(hdr)) {
5340 err = PTR_ERR(hdr);
5341 goto free_msg;
5342 }
f7ca38df
JB
5343 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5344 channel_type_valid, wait,
2e161f78
JB
5345 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5346 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e9f935e3 5347 no_cck, &cookie);
026331c4
JM
5348 if (err)
5349 goto free_msg;
5350
5351 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5352
5353 genlmsg_end(msg, hdr);
4c476991 5354 return genlmsg_reply(msg, info);
026331c4
JM
5355
5356 nla_put_failure:
5357 err = -ENOBUFS;
5358 free_msg:
5359 nlmsg_free(msg);
026331c4
JM
5360 return err;
5361}
5362
f7ca38df
JB
5363static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5364{
5365 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5366 struct net_device *dev = info->user_ptr[1];
5367 u64 cookie;
5368
5369 if (!info->attrs[NL80211_ATTR_COOKIE])
5370 return -EINVAL;
5371
5372 if (!rdev->ops->mgmt_tx_cancel_wait)
5373 return -EOPNOTSUPP;
5374
5375 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5376 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5377 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5378 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5379 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5380 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5381 return -EOPNOTSUPP;
5382
5383 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5384
5385 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5386}
5387
ffb9eb3d
KV
5388static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5389{
4c476991 5390 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 5391 struct wireless_dev *wdev;
4c476991 5392 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5393 u8 ps_state;
5394 bool state;
5395 int err;
5396
4c476991
JB
5397 if (!info->attrs[NL80211_ATTR_PS_STATE])
5398 return -EINVAL;
ffb9eb3d
KV
5399
5400 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5401
4c476991
JB
5402 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5403 return -EINVAL;
ffb9eb3d
KV
5404
5405 wdev = dev->ieee80211_ptr;
5406
4c476991
JB
5407 if (!rdev->ops->set_power_mgmt)
5408 return -EOPNOTSUPP;
ffb9eb3d
KV
5409
5410 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5411
5412 if (state == wdev->ps)
4c476991 5413 return 0;
ffb9eb3d 5414
4c476991
JB
5415 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5416 wdev->ps_timeout);
5417 if (!err)
5418 wdev->ps = state;
ffb9eb3d
KV
5419 return err;
5420}
5421
5422static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5423{
4c476991 5424 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
5425 enum nl80211_ps_state ps_state;
5426 struct wireless_dev *wdev;
4c476991 5427 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5428 struct sk_buff *msg;
5429 void *hdr;
5430 int err;
5431
ffb9eb3d
KV
5432 wdev = dev->ieee80211_ptr;
5433
4c476991
JB
5434 if (!rdev->ops->set_power_mgmt)
5435 return -EOPNOTSUPP;
ffb9eb3d
KV
5436
5437 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5438 if (!msg)
5439 return -ENOMEM;
ffb9eb3d
KV
5440
5441 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5442 NL80211_CMD_GET_POWER_SAVE);
5443 if (!hdr) {
4c476991 5444 err = -ENOBUFS;
ffb9eb3d
KV
5445 goto free_msg;
5446 }
5447
5448 if (wdev->ps)
5449 ps_state = NL80211_PS_ENABLED;
5450 else
5451 ps_state = NL80211_PS_DISABLED;
5452
5453 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5454
5455 genlmsg_end(msg, hdr);
4c476991 5456 return genlmsg_reply(msg, info);
ffb9eb3d 5457
4c476991 5458 nla_put_failure:
ffb9eb3d 5459 err = -ENOBUFS;
4c476991 5460 free_msg:
ffb9eb3d 5461 nlmsg_free(msg);
ffb9eb3d
KV
5462 return err;
5463}
5464
d6dc1a38
JO
5465static struct nla_policy
5466nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5467 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5468 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5469 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5470};
5471
5472static int nl80211_set_cqm_rssi(struct genl_info *info,
5473 s32 threshold, u32 hysteresis)
5474{
4c476991 5475 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 5476 struct wireless_dev *wdev;
4c476991 5477 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
5478
5479 if (threshold > 0)
5480 return -EINVAL;
5481
d6dc1a38
JO
5482 wdev = dev->ieee80211_ptr;
5483
4c476991
JB
5484 if (!rdev->ops->set_cqm_rssi_config)
5485 return -EOPNOTSUPP;
d6dc1a38 5486
074ac8df 5487 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5488 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
5489 return -EOPNOTSUPP;
d6dc1a38 5490
4c476991
JB
5491 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5492 threshold, hysteresis);
d6dc1a38
JO
5493}
5494
5495static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5496{
5497 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5498 struct nlattr *cqm;
5499 int err;
5500
5501 cqm = info->attrs[NL80211_ATTR_CQM];
5502 if (!cqm) {
5503 err = -EINVAL;
5504 goto out;
5505 }
5506
5507 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5508 nl80211_attr_cqm_policy);
5509 if (err)
5510 goto out;
5511
5512 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5513 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5514 s32 threshold;
5515 u32 hysteresis;
5516 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5517 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5518 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5519 } else
5520 err = -EINVAL;
5521
5522out:
5523 return err;
5524}
5525
29cbe68c
JB
5526static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5527{
5528 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5529 struct net_device *dev = info->user_ptr[1];
5530 struct mesh_config cfg;
c80d545d 5531 struct mesh_setup setup;
29cbe68c
JB
5532 int err;
5533
5534 /* start with default */
5535 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 5536 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 5537
24bdd9f4 5538 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 5539 /* and parse parameters if given */
24bdd9f4 5540 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
5541 if (err)
5542 return err;
5543 }
5544
5545 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5546 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5547 return -EINVAL;
5548
c80d545d
JC
5549 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5550 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5551
5552 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5553 /* parse additional setup parameters if given */
5554 err = nl80211_parse_mesh_setup(info, &setup);
5555 if (err)
5556 return err;
5557 }
5558
5559 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
5560}
5561
5562static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5563{
5564 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5565 struct net_device *dev = info->user_ptr[1];
5566
5567 return cfg80211_leave_mesh(rdev, dev);
5568}
5569
ff1b6e69
JB
5570static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5571{
5572 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5573 struct sk_buff *msg;
5574 void *hdr;
5575
5576 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5577 return -EOPNOTSUPP;
5578
5579 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5580 if (!msg)
5581 return -ENOMEM;
5582
5583 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5584 NL80211_CMD_GET_WOWLAN);
5585 if (!hdr)
5586 goto nla_put_failure;
5587
5588 if (rdev->wowlan) {
5589 struct nlattr *nl_wowlan;
5590
5591 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5592 if (!nl_wowlan)
5593 goto nla_put_failure;
5594
5595 if (rdev->wowlan->any)
5596 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5597 if (rdev->wowlan->disconnect)
5598 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5599 if (rdev->wowlan->magic_pkt)
5600 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
5601 if (rdev->wowlan->gtk_rekey_failure)
5602 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
5603 if (rdev->wowlan->eap_identity_req)
5604 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
5605 if (rdev->wowlan->four_way_handshake)
5606 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
5607 if (rdev->wowlan->rfkill_release)
5608 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
5609 if (rdev->wowlan->n_patterns) {
5610 struct nlattr *nl_pats, *nl_pat;
5611 int i, pat_len;
5612
5613 nl_pats = nla_nest_start(msg,
5614 NL80211_WOWLAN_TRIG_PKT_PATTERN);
5615 if (!nl_pats)
5616 goto nla_put_failure;
5617
5618 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5619 nl_pat = nla_nest_start(msg, i + 1);
5620 if (!nl_pat)
5621 goto nla_put_failure;
5622 pat_len = rdev->wowlan->patterns[i].pattern_len;
5623 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5624 DIV_ROUND_UP(pat_len, 8),
5625 rdev->wowlan->patterns[i].mask);
5626 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5627 pat_len,
5628 rdev->wowlan->patterns[i].pattern);
5629 nla_nest_end(msg, nl_pat);
5630 }
5631 nla_nest_end(msg, nl_pats);
5632 }
5633
5634 nla_nest_end(msg, nl_wowlan);
5635 }
5636
5637 genlmsg_end(msg, hdr);
5638 return genlmsg_reply(msg, info);
5639
5640nla_put_failure:
5641 nlmsg_free(msg);
5642 return -ENOBUFS;
5643}
5644
5645static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
5646{
5647 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5648 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
5649 struct cfg80211_wowlan no_triggers = {};
5650 struct cfg80211_wowlan new_triggers = {};
5651 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
5652 int err, i;
5653
5654 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5655 return -EOPNOTSUPP;
5656
5657 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
5658 goto no_triggers;
5659
5660 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
5661 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5662 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5663 nl80211_wowlan_policy);
5664 if (err)
5665 return err;
5666
5667 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
5668 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
5669 return -EINVAL;
5670 new_triggers.any = true;
5671 }
5672
5673 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
5674 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
5675 return -EINVAL;
5676 new_triggers.disconnect = true;
5677 }
5678
5679 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
5680 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
5681 return -EINVAL;
5682 new_triggers.magic_pkt = true;
5683 }
5684
77dbbb13
JB
5685 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
5686 return -EINVAL;
5687
5688 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
5689 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
5690 return -EINVAL;
5691 new_triggers.gtk_rekey_failure = true;
5692 }
5693
5694 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
5695 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
5696 return -EINVAL;
5697 new_triggers.eap_identity_req = true;
5698 }
5699
5700 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
5701 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
5702 return -EINVAL;
5703 new_triggers.four_way_handshake = true;
5704 }
5705
5706 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
5707 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
5708 return -EINVAL;
5709 new_triggers.rfkill_release = true;
5710 }
5711
ff1b6e69
JB
5712 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
5713 struct nlattr *pat;
5714 int n_patterns = 0;
5715 int rem, pat_len, mask_len;
5716 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
5717
5718 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5719 rem)
5720 n_patterns++;
5721 if (n_patterns > wowlan->n_patterns)
5722 return -EINVAL;
5723
5724 new_triggers.patterns = kcalloc(n_patterns,
5725 sizeof(new_triggers.patterns[0]),
5726 GFP_KERNEL);
5727 if (!new_triggers.patterns)
5728 return -ENOMEM;
5729
5730 new_triggers.n_patterns = n_patterns;
5731 i = 0;
5732
5733 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5734 rem) {
5735 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
5736 nla_data(pat), nla_len(pat), NULL);
5737 err = -EINVAL;
5738 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
5739 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
5740 goto error;
5741 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
5742 mask_len = DIV_ROUND_UP(pat_len, 8);
5743 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
5744 mask_len)
5745 goto error;
5746 if (pat_len > wowlan->pattern_max_len ||
5747 pat_len < wowlan->pattern_min_len)
5748 goto error;
5749
5750 new_triggers.patterns[i].mask =
5751 kmalloc(mask_len + pat_len, GFP_KERNEL);
5752 if (!new_triggers.patterns[i].mask) {
5753 err = -ENOMEM;
5754 goto error;
5755 }
5756 new_triggers.patterns[i].pattern =
5757 new_triggers.patterns[i].mask + mask_len;
5758 memcpy(new_triggers.patterns[i].mask,
5759 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
5760 mask_len);
5761 new_triggers.patterns[i].pattern_len = pat_len;
5762 memcpy(new_triggers.patterns[i].pattern,
5763 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
5764 pat_len);
5765 i++;
5766 }
5767 }
5768
5769 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
5770 struct cfg80211_wowlan *ntrig;
5771 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
5772 GFP_KERNEL);
5773 if (!ntrig) {
5774 err = -ENOMEM;
5775 goto error;
5776 }
5777 cfg80211_rdev_free_wowlan(rdev);
5778 rdev->wowlan = ntrig;
5779 } else {
5780 no_triggers:
5781 cfg80211_rdev_free_wowlan(rdev);
5782 rdev->wowlan = NULL;
5783 }
5784
5785 return 0;
5786 error:
5787 for (i = 0; i < new_triggers.n_patterns; i++)
5788 kfree(new_triggers.patterns[i].mask);
5789 kfree(new_triggers.patterns);
5790 return err;
5791}
5792
e5497d76
JB
5793static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
5794{
5795 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5796 struct net_device *dev = info->user_ptr[1];
5797 struct wireless_dev *wdev = dev->ieee80211_ptr;
5798 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
5799 struct cfg80211_gtk_rekey_data rekey_data;
5800 int err;
5801
5802 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
5803 return -EINVAL;
5804
5805 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
5806 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
5807 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
5808 nl80211_rekey_policy);
5809 if (err)
5810 return err;
5811
5812 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
5813 return -ERANGE;
5814 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
5815 return -ERANGE;
5816 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
5817 return -ERANGE;
5818
5819 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
5820 NL80211_KEK_LEN);
5821 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
5822 NL80211_KCK_LEN);
5823 memcpy(rekey_data.replay_ctr,
5824 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
5825 NL80211_REPLAY_CTR_LEN);
5826
5827 wdev_lock(wdev);
5828 if (!wdev->current_bss) {
5829 err = -ENOTCONN;
5830 goto out;
5831 }
5832
5833 if (!rdev->ops->set_rekey_data) {
5834 err = -EOPNOTSUPP;
5835 goto out;
5836 }
5837
5838 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
5839 out:
5840 wdev_unlock(wdev);
5841 return err;
5842}
5843
28946da7
JB
5844static int nl80211_register_unexpected_frame(struct sk_buff *skb,
5845 struct genl_info *info)
5846{
5847 struct net_device *dev = info->user_ptr[1];
5848 struct wireless_dev *wdev = dev->ieee80211_ptr;
5849
5850 if (wdev->iftype != NL80211_IFTYPE_AP &&
5851 wdev->iftype != NL80211_IFTYPE_P2P_GO)
5852 return -EINVAL;
5853
5854 if (wdev->ap_unexpected_nlpid)
5855 return -EBUSY;
5856
5857 wdev->ap_unexpected_nlpid = info->snd_pid;
5858 return 0;
5859}
5860
7f6cf311
JB
5861static int nl80211_probe_client(struct sk_buff *skb,
5862 struct genl_info *info)
5863{
5864 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5865 struct net_device *dev = info->user_ptr[1];
5866 struct wireless_dev *wdev = dev->ieee80211_ptr;
5867 struct sk_buff *msg;
5868 void *hdr;
5869 const u8 *addr;
5870 u64 cookie;
5871 int err;
5872
5873 if (wdev->iftype != NL80211_IFTYPE_AP &&
5874 wdev->iftype != NL80211_IFTYPE_P2P_GO)
5875 return -EOPNOTSUPP;
5876
5877 if (!info->attrs[NL80211_ATTR_MAC])
5878 return -EINVAL;
5879
5880 if (!rdev->ops->probe_client)
5881 return -EOPNOTSUPP;
5882
5883 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5884 if (!msg)
5885 return -ENOMEM;
5886
5887 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5888 NL80211_CMD_PROBE_CLIENT);
5889
5890 if (IS_ERR(hdr)) {
5891 err = PTR_ERR(hdr);
5892 goto free_msg;
5893 }
5894
5895 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5896
5897 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
5898 if (err)
5899 goto free_msg;
5900
5901 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5902
5903 genlmsg_end(msg, hdr);
5904
5905 return genlmsg_reply(msg, info);
5906
5907 nla_put_failure:
5908 err = -ENOBUFS;
5909 free_msg:
5910 nlmsg_free(msg);
5911 return err;
5912}
5913
5e760230
JB
5914static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
5915{
5916 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5917
5918 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
5919 return -EOPNOTSUPP;
5920
5921 if (rdev->ap_beacons_nlpid)
5922 return -EBUSY;
5923
5924 rdev->ap_beacons_nlpid = info->snd_pid;
5925
5926 return 0;
5927}
5928
4c476991
JB
5929#define NL80211_FLAG_NEED_WIPHY 0x01
5930#define NL80211_FLAG_NEED_NETDEV 0x02
5931#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
5932#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
5933#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
5934 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
5935
5936static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
5937 struct genl_info *info)
5938{
5939 struct cfg80211_registered_device *rdev;
5940 struct net_device *dev;
5941 int err;
5942 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
5943
5944 if (rtnl)
5945 rtnl_lock();
5946
5947 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
5948 rdev = cfg80211_get_dev_from_info(info);
5949 if (IS_ERR(rdev)) {
5950 if (rtnl)
5951 rtnl_unlock();
5952 return PTR_ERR(rdev);
5953 }
5954 info->user_ptr[0] = rdev;
5955 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
5956 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5957 if (err) {
5958 if (rtnl)
5959 rtnl_unlock();
5960 return err;
5961 }
41265714
JB
5962 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
5963 !netif_running(dev)) {
d537f5fd
JB
5964 cfg80211_unlock_rdev(rdev);
5965 dev_put(dev);
41265714
JB
5966 if (rtnl)
5967 rtnl_unlock();
5968 return -ENETDOWN;
5969 }
4c476991
JB
5970 info->user_ptr[0] = rdev;
5971 info->user_ptr[1] = dev;
5972 }
5973
5974 return 0;
5975}
5976
5977static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
5978 struct genl_info *info)
5979{
5980 if (info->user_ptr[0])
5981 cfg80211_unlock_rdev(info->user_ptr[0]);
5982 if (info->user_ptr[1])
5983 dev_put(info->user_ptr[1]);
5984 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
5985 rtnl_unlock();
5986}
5987
55682965
JB
5988static struct genl_ops nl80211_ops[] = {
5989 {
5990 .cmd = NL80211_CMD_GET_WIPHY,
5991 .doit = nl80211_get_wiphy,
5992 .dumpit = nl80211_dump_wiphy,
5993 .policy = nl80211_policy,
5994 /* can be retrieved by unprivileged users */
4c476991 5995 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
5996 },
5997 {
5998 .cmd = NL80211_CMD_SET_WIPHY,
5999 .doit = nl80211_set_wiphy,
6000 .policy = nl80211_policy,
6001 .flags = GENL_ADMIN_PERM,
4c476991 6002 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
6003 },
6004 {
6005 .cmd = NL80211_CMD_GET_INTERFACE,
6006 .doit = nl80211_get_interface,
6007 .dumpit = nl80211_dump_interface,
6008 .policy = nl80211_policy,
6009 /* can be retrieved by unprivileged users */
4c476991 6010 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
6011 },
6012 {
6013 .cmd = NL80211_CMD_SET_INTERFACE,
6014 .doit = nl80211_set_interface,
6015 .policy = nl80211_policy,
6016 .flags = GENL_ADMIN_PERM,
4c476991
JB
6017 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6018 NL80211_FLAG_NEED_RTNL,
55682965
JB
6019 },
6020 {
6021 .cmd = NL80211_CMD_NEW_INTERFACE,
6022 .doit = nl80211_new_interface,
6023 .policy = nl80211_policy,
6024 .flags = GENL_ADMIN_PERM,
4c476991
JB
6025 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6026 NL80211_FLAG_NEED_RTNL,
55682965
JB
6027 },
6028 {
6029 .cmd = NL80211_CMD_DEL_INTERFACE,
6030 .doit = nl80211_del_interface,
6031 .policy = nl80211_policy,
41ade00f 6032 .flags = GENL_ADMIN_PERM,
4c476991
JB
6033 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6034 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6035 },
6036 {
6037 .cmd = NL80211_CMD_GET_KEY,
6038 .doit = nl80211_get_key,
6039 .policy = nl80211_policy,
6040 .flags = GENL_ADMIN_PERM,
4c476991
JB
6041 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6042 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6043 },
6044 {
6045 .cmd = NL80211_CMD_SET_KEY,
6046 .doit = nl80211_set_key,
6047 .policy = nl80211_policy,
6048 .flags = GENL_ADMIN_PERM,
41265714 6049 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6050 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6051 },
6052 {
6053 .cmd = NL80211_CMD_NEW_KEY,
6054 .doit = nl80211_new_key,
6055 .policy = nl80211_policy,
6056 .flags = GENL_ADMIN_PERM,
41265714 6057 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6058 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6059 },
6060 {
6061 .cmd = NL80211_CMD_DEL_KEY,
6062 .doit = nl80211_del_key,
6063 .policy = nl80211_policy,
55682965 6064 .flags = GENL_ADMIN_PERM,
41265714 6065 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6066 NL80211_FLAG_NEED_RTNL,
55682965 6067 },
ed1b6cc7
JB
6068 {
6069 .cmd = NL80211_CMD_SET_BEACON,
6070 .policy = nl80211_policy,
6071 .flags = GENL_ADMIN_PERM,
6072 .doit = nl80211_addset_beacon,
4c476991
JB
6073 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6074 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6075 },
6076 {
6077 .cmd = NL80211_CMD_NEW_BEACON,
6078 .policy = nl80211_policy,
6079 .flags = GENL_ADMIN_PERM,
6080 .doit = nl80211_addset_beacon,
4c476991
JB
6081 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6082 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6083 },
6084 {
6085 .cmd = NL80211_CMD_DEL_BEACON,
6086 .policy = nl80211_policy,
6087 .flags = GENL_ADMIN_PERM,
6088 .doit = nl80211_del_beacon,
4c476991
JB
6089 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6090 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6091 },
5727ef1b
JB
6092 {
6093 .cmd = NL80211_CMD_GET_STATION,
6094 .doit = nl80211_get_station,
2ec600d6 6095 .dumpit = nl80211_dump_station,
5727ef1b 6096 .policy = nl80211_policy,
4c476991
JB
6097 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6098 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6099 },
6100 {
6101 .cmd = NL80211_CMD_SET_STATION,
6102 .doit = nl80211_set_station,
6103 .policy = nl80211_policy,
6104 .flags = GENL_ADMIN_PERM,
4c476991
JB
6105 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6106 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6107 },
6108 {
6109 .cmd = NL80211_CMD_NEW_STATION,
6110 .doit = nl80211_new_station,
6111 .policy = nl80211_policy,
6112 .flags = GENL_ADMIN_PERM,
41265714 6113 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6114 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6115 },
6116 {
6117 .cmd = NL80211_CMD_DEL_STATION,
6118 .doit = nl80211_del_station,
6119 .policy = nl80211_policy,
2ec600d6 6120 .flags = GENL_ADMIN_PERM,
4c476991
JB
6121 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6122 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6123 },
6124 {
6125 .cmd = NL80211_CMD_GET_MPATH,
6126 .doit = nl80211_get_mpath,
6127 .dumpit = nl80211_dump_mpath,
6128 .policy = nl80211_policy,
6129 .flags = GENL_ADMIN_PERM,
41265714 6130 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6131 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6132 },
6133 {
6134 .cmd = NL80211_CMD_SET_MPATH,
6135 .doit = nl80211_set_mpath,
6136 .policy = nl80211_policy,
6137 .flags = GENL_ADMIN_PERM,
41265714 6138 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6139 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6140 },
6141 {
6142 .cmd = NL80211_CMD_NEW_MPATH,
6143 .doit = nl80211_new_mpath,
6144 .policy = nl80211_policy,
6145 .flags = GENL_ADMIN_PERM,
41265714 6146 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6147 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6148 },
6149 {
6150 .cmd = NL80211_CMD_DEL_MPATH,
6151 .doit = nl80211_del_mpath,
6152 .policy = nl80211_policy,
9f1ba906 6153 .flags = GENL_ADMIN_PERM,
4c476991
JB
6154 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6155 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6156 },
6157 {
6158 .cmd = NL80211_CMD_SET_BSS,
6159 .doit = nl80211_set_bss,
6160 .policy = nl80211_policy,
b2e1b302 6161 .flags = GENL_ADMIN_PERM,
4c476991
JB
6162 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6163 NL80211_FLAG_NEED_RTNL,
b2e1b302 6164 },
f130347c
LR
6165 {
6166 .cmd = NL80211_CMD_GET_REG,
6167 .doit = nl80211_get_reg,
6168 .policy = nl80211_policy,
6169 /* can be retrieved by unprivileged users */
6170 },
b2e1b302
LR
6171 {
6172 .cmd = NL80211_CMD_SET_REG,
6173 .doit = nl80211_set_reg,
6174 .policy = nl80211_policy,
6175 .flags = GENL_ADMIN_PERM,
6176 },
6177 {
6178 .cmd = NL80211_CMD_REQ_SET_REG,
6179 .doit = nl80211_req_set_reg,
6180 .policy = nl80211_policy,
93da9cc1 6181 .flags = GENL_ADMIN_PERM,
6182 },
6183 {
24bdd9f4
JC
6184 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6185 .doit = nl80211_get_mesh_config,
93da9cc1 6186 .policy = nl80211_policy,
6187 /* can be retrieved by unprivileged users */
4c476991
JB
6188 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6189 NL80211_FLAG_NEED_RTNL,
93da9cc1 6190 },
6191 {
24bdd9f4
JC
6192 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6193 .doit = nl80211_update_mesh_config,
93da9cc1 6194 .policy = nl80211_policy,
9aed3cc1 6195 .flags = GENL_ADMIN_PERM,
29cbe68c 6196 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6197 NL80211_FLAG_NEED_RTNL,
9aed3cc1 6198 },
2a519311
JB
6199 {
6200 .cmd = NL80211_CMD_TRIGGER_SCAN,
6201 .doit = nl80211_trigger_scan,
6202 .policy = nl80211_policy,
6203 .flags = GENL_ADMIN_PERM,
41265714 6204 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6205 NL80211_FLAG_NEED_RTNL,
2a519311
JB
6206 },
6207 {
6208 .cmd = NL80211_CMD_GET_SCAN,
6209 .policy = nl80211_policy,
6210 .dumpit = nl80211_dump_scan,
6211 },
807f8a8c
LC
6212 {
6213 .cmd = NL80211_CMD_START_SCHED_SCAN,
6214 .doit = nl80211_start_sched_scan,
6215 .policy = nl80211_policy,
6216 .flags = GENL_ADMIN_PERM,
6217 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6218 NL80211_FLAG_NEED_RTNL,
6219 },
6220 {
6221 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6222 .doit = nl80211_stop_sched_scan,
6223 .policy = nl80211_policy,
6224 .flags = GENL_ADMIN_PERM,
6225 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6226 NL80211_FLAG_NEED_RTNL,
6227 },
636a5d36
JM
6228 {
6229 .cmd = NL80211_CMD_AUTHENTICATE,
6230 .doit = nl80211_authenticate,
6231 .policy = nl80211_policy,
6232 .flags = GENL_ADMIN_PERM,
41265714 6233 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6234 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6235 },
6236 {
6237 .cmd = NL80211_CMD_ASSOCIATE,
6238 .doit = nl80211_associate,
6239 .policy = nl80211_policy,
6240 .flags = GENL_ADMIN_PERM,
41265714 6241 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6242 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6243 },
6244 {
6245 .cmd = NL80211_CMD_DEAUTHENTICATE,
6246 .doit = nl80211_deauthenticate,
6247 .policy = nl80211_policy,
6248 .flags = GENL_ADMIN_PERM,
41265714 6249 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6250 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6251 },
6252 {
6253 .cmd = NL80211_CMD_DISASSOCIATE,
6254 .doit = nl80211_disassociate,
6255 .policy = nl80211_policy,
6256 .flags = GENL_ADMIN_PERM,
41265714 6257 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6258 NL80211_FLAG_NEED_RTNL,
636a5d36 6259 },
04a773ad
JB
6260 {
6261 .cmd = NL80211_CMD_JOIN_IBSS,
6262 .doit = nl80211_join_ibss,
6263 .policy = nl80211_policy,
6264 .flags = GENL_ADMIN_PERM,
41265714 6265 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6266 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
6267 },
6268 {
6269 .cmd = NL80211_CMD_LEAVE_IBSS,
6270 .doit = nl80211_leave_ibss,
6271 .policy = nl80211_policy,
6272 .flags = GENL_ADMIN_PERM,
41265714 6273 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6274 NL80211_FLAG_NEED_RTNL,
04a773ad 6275 },
aff89a9b
JB
6276#ifdef CONFIG_NL80211_TESTMODE
6277 {
6278 .cmd = NL80211_CMD_TESTMODE,
6279 .doit = nl80211_testmode_do,
71063f0e 6280 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
6281 .policy = nl80211_policy,
6282 .flags = GENL_ADMIN_PERM,
4c476991
JB
6283 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6284 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
6285 },
6286#endif
b23aa676
SO
6287 {
6288 .cmd = NL80211_CMD_CONNECT,
6289 .doit = nl80211_connect,
6290 .policy = nl80211_policy,
6291 .flags = GENL_ADMIN_PERM,
41265714 6292 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6293 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
6294 },
6295 {
6296 .cmd = NL80211_CMD_DISCONNECT,
6297 .doit = nl80211_disconnect,
6298 .policy = nl80211_policy,
6299 .flags = GENL_ADMIN_PERM,
41265714 6300 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6301 NL80211_FLAG_NEED_RTNL,
b23aa676 6302 },
463d0183
JB
6303 {
6304 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6305 .doit = nl80211_wiphy_netns,
6306 .policy = nl80211_policy,
6307 .flags = GENL_ADMIN_PERM,
4c476991
JB
6308 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6309 NL80211_FLAG_NEED_RTNL,
463d0183 6310 },
61fa713c
HS
6311 {
6312 .cmd = NL80211_CMD_GET_SURVEY,
6313 .policy = nl80211_policy,
6314 .dumpit = nl80211_dump_survey,
6315 },
67fbb16b
SO
6316 {
6317 .cmd = NL80211_CMD_SET_PMKSA,
6318 .doit = nl80211_setdel_pmksa,
6319 .policy = nl80211_policy,
6320 .flags = GENL_ADMIN_PERM,
4c476991
JB
6321 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6322 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6323 },
6324 {
6325 .cmd = NL80211_CMD_DEL_PMKSA,
6326 .doit = nl80211_setdel_pmksa,
6327 .policy = nl80211_policy,
6328 .flags = GENL_ADMIN_PERM,
4c476991
JB
6329 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6330 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6331 },
6332 {
6333 .cmd = NL80211_CMD_FLUSH_PMKSA,
6334 .doit = nl80211_flush_pmksa,
6335 .policy = nl80211_policy,
6336 .flags = GENL_ADMIN_PERM,
4c476991
JB
6337 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6338 NL80211_FLAG_NEED_RTNL,
67fbb16b 6339 },
9588bbd5
JM
6340 {
6341 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6342 .doit = nl80211_remain_on_channel,
6343 .policy = nl80211_policy,
6344 .flags = GENL_ADMIN_PERM,
41265714 6345 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6346 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
6347 },
6348 {
6349 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6350 .doit = nl80211_cancel_remain_on_channel,
6351 .policy = nl80211_policy,
6352 .flags = GENL_ADMIN_PERM,
41265714 6353 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6354 NL80211_FLAG_NEED_RTNL,
9588bbd5 6355 },
13ae75b1
JM
6356 {
6357 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6358 .doit = nl80211_set_tx_bitrate_mask,
6359 .policy = nl80211_policy,
6360 .flags = GENL_ADMIN_PERM,
4c476991
JB
6361 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6362 NL80211_FLAG_NEED_RTNL,
13ae75b1 6363 },
026331c4 6364 {
2e161f78
JB
6365 .cmd = NL80211_CMD_REGISTER_FRAME,
6366 .doit = nl80211_register_mgmt,
026331c4
JM
6367 .policy = nl80211_policy,
6368 .flags = GENL_ADMIN_PERM,
4c476991
JB
6369 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6370 NL80211_FLAG_NEED_RTNL,
026331c4
JM
6371 },
6372 {
2e161f78
JB
6373 .cmd = NL80211_CMD_FRAME,
6374 .doit = nl80211_tx_mgmt,
026331c4 6375 .policy = nl80211_policy,
f7ca38df
JB
6376 .flags = GENL_ADMIN_PERM,
6377 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6378 NL80211_FLAG_NEED_RTNL,
6379 },
6380 {
6381 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6382 .doit = nl80211_tx_mgmt_cancel_wait,
6383 .policy = nl80211_policy,
026331c4 6384 .flags = GENL_ADMIN_PERM,
41265714 6385 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6386 NL80211_FLAG_NEED_RTNL,
026331c4 6387 },
ffb9eb3d
KV
6388 {
6389 .cmd = NL80211_CMD_SET_POWER_SAVE,
6390 .doit = nl80211_set_power_save,
6391 .policy = nl80211_policy,
6392 .flags = GENL_ADMIN_PERM,
4c476991
JB
6393 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6394 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
6395 },
6396 {
6397 .cmd = NL80211_CMD_GET_POWER_SAVE,
6398 .doit = nl80211_get_power_save,
6399 .policy = nl80211_policy,
6400 /* can be retrieved by unprivileged users */
4c476991
JB
6401 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6402 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 6403 },
d6dc1a38
JO
6404 {
6405 .cmd = NL80211_CMD_SET_CQM,
6406 .doit = nl80211_set_cqm,
6407 .policy = nl80211_policy,
6408 .flags = GENL_ADMIN_PERM,
4c476991
JB
6409 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6410 NL80211_FLAG_NEED_RTNL,
d6dc1a38 6411 },
f444de05
JB
6412 {
6413 .cmd = NL80211_CMD_SET_CHANNEL,
6414 .doit = nl80211_set_channel,
6415 .policy = nl80211_policy,
6416 .flags = GENL_ADMIN_PERM,
4c476991
JB
6417 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6418 NL80211_FLAG_NEED_RTNL,
f444de05 6419 },
e8347eba
BJ
6420 {
6421 .cmd = NL80211_CMD_SET_WDS_PEER,
6422 .doit = nl80211_set_wds_peer,
6423 .policy = nl80211_policy,
6424 .flags = GENL_ADMIN_PERM,
43b19952
JB
6425 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6426 NL80211_FLAG_NEED_RTNL,
e8347eba 6427 },
29cbe68c
JB
6428 {
6429 .cmd = NL80211_CMD_JOIN_MESH,
6430 .doit = nl80211_join_mesh,
6431 .policy = nl80211_policy,
6432 .flags = GENL_ADMIN_PERM,
6433 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6434 NL80211_FLAG_NEED_RTNL,
6435 },
6436 {
6437 .cmd = NL80211_CMD_LEAVE_MESH,
6438 .doit = nl80211_leave_mesh,
6439 .policy = nl80211_policy,
6440 .flags = GENL_ADMIN_PERM,
6441 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6442 NL80211_FLAG_NEED_RTNL,
6443 },
ff1b6e69
JB
6444 {
6445 .cmd = NL80211_CMD_GET_WOWLAN,
6446 .doit = nl80211_get_wowlan,
6447 .policy = nl80211_policy,
6448 /* can be retrieved by unprivileged users */
6449 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6450 NL80211_FLAG_NEED_RTNL,
6451 },
6452 {
6453 .cmd = NL80211_CMD_SET_WOWLAN,
6454 .doit = nl80211_set_wowlan,
6455 .policy = nl80211_policy,
6456 .flags = GENL_ADMIN_PERM,
6457 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6458 NL80211_FLAG_NEED_RTNL,
6459 },
e5497d76
JB
6460 {
6461 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
6462 .doit = nl80211_set_rekey_data,
6463 .policy = nl80211_policy,
6464 .flags = GENL_ADMIN_PERM,
6465 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6466 NL80211_FLAG_NEED_RTNL,
6467 },
109086ce
AN
6468 {
6469 .cmd = NL80211_CMD_TDLS_MGMT,
6470 .doit = nl80211_tdls_mgmt,
6471 .policy = nl80211_policy,
6472 .flags = GENL_ADMIN_PERM,
6473 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6474 NL80211_FLAG_NEED_RTNL,
6475 },
6476 {
6477 .cmd = NL80211_CMD_TDLS_OPER,
6478 .doit = nl80211_tdls_oper,
6479 .policy = nl80211_policy,
6480 .flags = GENL_ADMIN_PERM,
6481 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6482 NL80211_FLAG_NEED_RTNL,
6483 },
28946da7
JB
6484 {
6485 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
6486 .doit = nl80211_register_unexpected_frame,
6487 .policy = nl80211_policy,
6488 .flags = GENL_ADMIN_PERM,
6489 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6490 NL80211_FLAG_NEED_RTNL,
6491 },
7f6cf311
JB
6492 {
6493 .cmd = NL80211_CMD_PROBE_CLIENT,
6494 .doit = nl80211_probe_client,
6495 .policy = nl80211_policy,
6496 .flags = GENL_ADMIN_PERM,
6497 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6498 NL80211_FLAG_NEED_RTNL,
6499 },
5e760230
JB
6500 {
6501 .cmd = NL80211_CMD_REGISTER_BEACONS,
6502 .doit = nl80211_register_beacons,
6503 .policy = nl80211_policy,
6504 .flags = GENL_ADMIN_PERM,
6505 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6506 NL80211_FLAG_NEED_RTNL,
6507 },
55682965 6508};
9588bbd5 6509
6039f6d2
JM
6510static struct genl_multicast_group nl80211_mlme_mcgrp = {
6511 .name = "mlme",
6512};
55682965
JB
6513
6514/* multicast groups */
6515static struct genl_multicast_group nl80211_config_mcgrp = {
6516 .name = "config",
6517};
2a519311
JB
6518static struct genl_multicast_group nl80211_scan_mcgrp = {
6519 .name = "scan",
6520};
73d54c9e
LR
6521static struct genl_multicast_group nl80211_regulatory_mcgrp = {
6522 .name = "regulatory",
6523};
55682965
JB
6524
6525/* notification functions */
6526
6527void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
6528{
6529 struct sk_buff *msg;
6530
fd2120ca 6531 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
6532 if (!msg)
6533 return;
6534
6535 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
6536 nlmsg_free(msg);
6537 return;
6538 }
6539
463d0183
JB
6540 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6541 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
6542}
6543
362a415d
JB
6544static int nl80211_add_scan_req(struct sk_buff *msg,
6545 struct cfg80211_registered_device *rdev)
6546{
6547 struct cfg80211_scan_request *req = rdev->scan_req;
6548 struct nlattr *nest;
6549 int i;
6550
667503dd
JB
6551 ASSERT_RDEV_LOCK(rdev);
6552
362a415d
JB
6553 if (WARN_ON(!req))
6554 return 0;
6555
6556 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
6557 if (!nest)
6558 goto nla_put_failure;
6559 for (i = 0; i < req->n_ssids; i++)
6560 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
6561 nla_nest_end(msg, nest);
6562
6563 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
6564 if (!nest)
6565 goto nla_put_failure;
6566 for (i = 0; i < req->n_channels; i++)
6567 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
6568 nla_nest_end(msg, nest);
6569
6570 if (req->ie)
6571 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
6572
6573 return 0;
6574 nla_put_failure:
6575 return -ENOBUFS;
6576}
6577
a538e2d5
JB
6578static int nl80211_send_scan_msg(struct sk_buff *msg,
6579 struct cfg80211_registered_device *rdev,
6580 struct net_device *netdev,
6581 u32 pid, u32 seq, int flags,
6582 u32 cmd)
2a519311
JB
6583{
6584 void *hdr;
6585
6586 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6587 if (!hdr)
6588 return -1;
6589
b5850a7a 6590 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
6591 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6592
362a415d
JB
6593 /* ignore errors and send incomplete event anyway */
6594 nl80211_add_scan_req(msg, rdev);
2a519311
JB
6595
6596 return genlmsg_end(msg, hdr);
6597
6598 nla_put_failure:
6599 genlmsg_cancel(msg, hdr);
6600 return -EMSGSIZE;
6601}
6602
807f8a8c
LC
6603static int
6604nl80211_send_sched_scan_msg(struct sk_buff *msg,
6605 struct cfg80211_registered_device *rdev,
6606 struct net_device *netdev,
6607 u32 pid, u32 seq, int flags, u32 cmd)
6608{
6609 void *hdr;
6610
6611 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6612 if (!hdr)
6613 return -1;
6614
6615 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6616 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6617
6618 return genlmsg_end(msg, hdr);
6619
6620 nla_put_failure:
6621 genlmsg_cancel(msg, hdr);
6622 return -EMSGSIZE;
6623}
6624
a538e2d5
JB
6625void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
6626 struct net_device *netdev)
6627{
6628 struct sk_buff *msg;
6629
6630 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6631 if (!msg)
6632 return;
6633
6634 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6635 NL80211_CMD_TRIGGER_SCAN) < 0) {
6636 nlmsg_free(msg);
6637 return;
6638 }
6639
463d0183
JB
6640 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6641 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
6642}
6643
2a519311
JB
6644void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
6645 struct net_device *netdev)
6646{
6647 struct sk_buff *msg;
6648
fd2120ca 6649 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
6650 if (!msg)
6651 return;
6652
a538e2d5
JB
6653 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6654 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
6655 nlmsg_free(msg);
6656 return;
6657 }
6658
463d0183
JB
6659 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6660 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
6661}
6662
6663void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
6664 struct net_device *netdev)
6665{
6666 struct sk_buff *msg;
6667
fd2120ca 6668 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
6669 if (!msg)
6670 return;
6671
a538e2d5
JB
6672 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6673 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
6674 nlmsg_free(msg);
6675 return;
6676 }
6677
463d0183
JB
6678 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6679 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
6680}
6681
807f8a8c
LC
6682void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
6683 struct net_device *netdev)
6684{
6685 struct sk_buff *msg;
6686
6687 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6688 if (!msg)
6689 return;
6690
6691 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
6692 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
6693 nlmsg_free(msg);
6694 return;
6695 }
6696
6697 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6698 nl80211_scan_mcgrp.id, GFP_KERNEL);
6699}
6700
6701void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
6702 struct net_device *netdev, u32 cmd)
6703{
6704 struct sk_buff *msg;
6705
6706 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6707 if (!msg)
6708 return;
6709
6710 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
6711 nlmsg_free(msg);
6712 return;
6713 }
6714
6715 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6716 nl80211_scan_mcgrp.id, GFP_KERNEL);
6717}
6718
73d54c9e
LR
6719/*
6720 * This can happen on global regulatory changes or device specific settings
6721 * based on custom world regulatory domains.
6722 */
6723void nl80211_send_reg_change_event(struct regulatory_request *request)
6724{
6725 struct sk_buff *msg;
6726 void *hdr;
6727
fd2120ca 6728 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
6729 if (!msg)
6730 return;
6731
6732 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
6733 if (!hdr) {
6734 nlmsg_free(msg);
6735 return;
6736 }
6737
6738 /* Userspace can always count this one always being set */
6739 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
6740
6741 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
6742 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6743 NL80211_REGDOM_TYPE_WORLD);
6744 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
6745 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6746 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
6747 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
6748 request->intersect)
6749 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6750 NL80211_REGDOM_TYPE_INTERSECTION);
6751 else {
6752 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6753 NL80211_REGDOM_TYPE_COUNTRY);
6754 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
6755 }
6756
6757 if (wiphy_idx_valid(request->wiphy_idx))
6758 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
6759
3b7b72ee 6760 genlmsg_end(msg, hdr);
73d54c9e 6761
bc43b28c 6762 rcu_read_lock();
463d0183 6763 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
6764 GFP_ATOMIC);
6765 rcu_read_unlock();
73d54c9e
LR
6766
6767 return;
6768
6769nla_put_failure:
6770 genlmsg_cancel(msg, hdr);
6771 nlmsg_free(msg);
6772}
6773
6039f6d2
JM
6774static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
6775 struct net_device *netdev,
6776 const u8 *buf, size_t len,
e6d6e342 6777 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
6778{
6779 struct sk_buff *msg;
6780 void *hdr;
6781
e6d6e342 6782 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
6783 if (!msg)
6784 return;
6785
6786 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6787 if (!hdr) {
6788 nlmsg_free(msg);
6789 return;
6790 }
6791
6792 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6793 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6794 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6795
3b7b72ee 6796 genlmsg_end(msg, hdr);
6039f6d2 6797
463d0183
JB
6798 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6799 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
6800 return;
6801
6802 nla_put_failure:
6803 genlmsg_cancel(msg, hdr);
6804 nlmsg_free(msg);
6805}
6806
6807void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6808 struct net_device *netdev, const u8 *buf,
6809 size_t len, gfp_t gfp)
6039f6d2
JM
6810{
6811 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6812 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
6813}
6814
6815void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
6816 struct net_device *netdev, const u8 *buf,
e6d6e342 6817 size_t len, gfp_t gfp)
6039f6d2 6818{
e6d6e342
JB
6819 nl80211_send_mlme_event(rdev, netdev, buf, len,
6820 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
6821}
6822
53b46b84 6823void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6824 struct net_device *netdev, const u8 *buf,
6825 size_t len, gfp_t gfp)
6039f6d2
JM
6826{
6827 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6828 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
6829}
6830
53b46b84
JM
6831void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
6832 struct net_device *netdev, const u8 *buf,
e6d6e342 6833 size_t len, gfp_t gfp)
6039f6d2
JM
6834{
6835 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 6836 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
6837}
6838
cf4e594e
JM
6839void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
6840 struct net_device *netdev, const u8 *buf,
6841 size_t len, gfp_t gfp)
6842{
6843 nl80211_send_mlme_event(rdev, netdev, buf, len,
6844 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
6845}
6846
6847void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
6848 struct net_device *netdev, const u8 *buf,
6849 size_t len, gfp_t gfp)
6850{
6851 nl80211_send_mlme_event(rdev, netdev, buf, len,
6852 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
6853}
6854
1b06bb40
LR
6855static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
6856 struct net_device *netdev, int cmd,
e6d6e342 6857 const u8 *addr, gfp_t gfp)
1965c853
JM
6858{
6859 struct sk_buff *msg;
6860 void *hdr;
6861
e6d6e342 6862 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
6863 if (!msg)
6864 return;
6865
6866 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6867 if (!hdr) {
6868 nlmsg_free(msg);
6869 return;
6870 }
6871
6872 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6873 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6874 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
6875 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6876
3b7b72ee 6877 genlmsg_end(msg, hdr);
1965c853 6878
463d0183
JB
6879 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6880 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
6881 return;
6882
6883 nla_put_failure:
6884 genlmsg_cancel(msg, hdr);
6885 nlmsg_free(msg);
6886}
6887
6888void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6889 struct net_device *netdev, const u8 *addr,
6890 gfp_t gfp)
1965c853
JM
6891{
6892 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 6893 addr, gfp);
1965c853
JM
6894}
6895
6896void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
6897 struct net_device *netdev, const u8 *addr,
6898 gfp_t gfp)
1965c853 6899{
e6d6e342
JB
6900 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
6901 addr, gfp);
1965c853
JM
6902}
6903
b23aa676
SO
6904void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
6905 struct net_device *netdev, const u8 *bssid,
6906 const u8 *req_ie, size_t req_ie_len,
6907 const u8 *resp_ie, size_t resp_ie_len,
6908 u16 status, gfp_t gfp)
6909{
6910 struct sk_buff *msg;
6911 void *hdr;
6912
6913 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6914 if (!msg)
6915 return;
6916
6917 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
6918 if (!hdr) {
6919 nlmsg_free(msg);
6920 return;
6921 }
6922
6923 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6924 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6925 if (bssid)
6926 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6927 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
6928 if (req_ie)
6929 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6930 if (resp_ie)
6931 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6932
3b7b72ee 6933 genlmsg_end(msg, hdr);
b23aa676 6934
463d0183
JB
6935 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6936 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
6937 return;
6938
6939 nla_put_failure:
6940 genlmsg_cancel(msg, hdr);
6941 nlmsg_free(msg);
6942
6943}
6944
6945void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
6946 struct net_device *netdev, const u8 *bssid,
6947 const u8 *req_ie, size_t req_ie_len,
6948 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
6949{
6950 struct sk_buff *msg;
6951 void *hdr;
6952
6953 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6954 if (!msg)
6955 return;
6956
6957 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
6958 if (!hdr) {
6959 nlmsg_free(msg);
6960 return;
6961 }
6962
6963 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6964 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6965 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6966 if (req_ie)
6967 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6968 if (resp_ie)
6969 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6970
3b7b72ee 6971 genlmsg_end(msg, hdr);
b23aa676 6972
463d0183
JB
6973 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6974 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
6975 return;
6976
6977 nla_put_failure:
6978 genlmsg_cancel(msg, hdr);
6979 nlmsg_free(msg);
6980
6981}
6982
6983void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
6984 struct net_device *netdev, u16 reason,
667503dd 6985 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
6986{
6987 struct sk_buff *msg;
6988 void *hdr;
6989
667503dd 6990 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
6991 if (!msg)
6992 return;
6993
6994 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
6995 if (!hdr) {
6996 nlmsg_free(msg);
6997 return;
6998 }
6999
7000 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7001 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7002 if (from_ap && reason)
7003 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
7004 if (from_ap)
7005 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
7006 if (ie)
7007 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
7008
3b7b72ee 7009 genlmsg_end(msg, hdr);
b23aa676 7010
463d0183
JB
7011 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7012 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
7013 return;
7014
7015 nla_put_failure:
7016 genlmsg_cancel(msg, hdr);
7017 nlmsg_free(msg);
7018
7019}
7020
04a773ad
JB
7021void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7022 struct net_device *netdev, const u8 *bssid,
7023 gfp_t gfp)
7024{
7025 struct sk_buff *msg;
7026 void *hdr;
7027
fd2120ca 7028 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7029 if (!msg)
7030 return;
7031
7032 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7033 if (!hdr) {
7034 nlmsg_free(msg);
7035 return;
7036 }
7037
7038 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7039 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7040 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7041
3b7b72ee 7042 genlmsg_end(msg, hdr);
04a773ad 7043
463d0183
JB
7044 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7045 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7046 return;
7047
7048 nla_put_failure:
7049 genlmsg_cancel(msg, hdr);
7050 nlmsg_free(msg);
7051}
7052
c93b5e71
JC
7053void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7054 struct net_device *netdev,
7055 const u8 *macaddr, const u8* ie, u8 ie_len,
7056 gfp_t gfp)
7057{
7058 struct sk_buff *msg;
7059 void *hdr;
7060
7061 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7062 if (!msg)
7063 return;
7064
7065 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7066 if (!hdr) {
7067 nlmsg_free(msg);
7068 return;
7069 }
7070
7071 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7072 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7073 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
7074 if (ie_len && ie)
7075 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
7076
3b7b72ee 7077 genlmsg_end(msg, hdr);
c93b5e71
JC
7078
7079 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7080 nl80211_mlme_mcgrp.id, gfp);
7081 return;
7082
7083 nla_put_failure:
7084 genlmsg_cancel(msg, hdr);
7085 nlmsg_free(msg);
7086}
7087
a3b8b056
JM
7088void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7089 struct net_device *netdev, const u8 *addr,
7090 enum nl80211_key_type key_type, int key_id,
e6d6e342 7091 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7092{
7093 struct sk_buff *msg;
7094 void *hdr;
7095
e6d6e342 7096 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7097 if (!msg)
7098 return;
7099
7100 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7101 if (!hdr) {
7102 nlmsg_free(msg);
7103 return;
7104 }
7105
7106 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7107 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7108 if (addr)
7109 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7110 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
a66b98db
AN
7111 if (key_id != -1)
7112 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
a3b8b056
JM
7113 if (tsc)
7114 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
7115
3b7b72ee 7116 genlmsg_end(msg, hdr);
a3b8b056 7117
463d0183
JB
7118 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7119 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7120 return;
7121
7122 nla_put_failure:
7123 genlmsg_cancel(msg, hdr);
7124 nlmsg_free(msg);
7125}
7126
6bad8766
LR
7127void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7128 struct ieee80211_channel *channel_before,
7129 struct ieee80211_channel *channel_after)
7130{
7131 struct sk_buff *msg;
7132 void *hdr;
7133 struct nlattr *nl_freq;
7134
fd2120ca 7135 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7136 if (!msg)
7137 return;
7138
7139 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7140 if (!hdr) {
7141 nlmsg_free(msg);
7142 return;
7143 }
7144
7145 /*
7146 * Since we are applying the beacon hint to a wiphy we know its
7147 * wiphy_idx is valid
7148 */
7149 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
7150
7151 /* Before */
7152 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7153 if (!nl_freq)
7154 goto nla_put_failure;
7155 if (nl80211_msg_put_channel(msg, channel_before))
7156 goto nla_put_failure;
7157 nla_nest_end(msg, nl_freq);
7158
7159 /* After */
7160 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7161 if (!nl_freq)
7162 goto nla_put_failure;
7163 if (nl80211_msg_put_channel(msg, channel_after))
7164 goto nla_put_failure;
7165 nla_nest_end(msg, nl_freq);
7166
3b7b72ee 7167 genlmsg_end(msg, hdr);
6bad8766 7168
463d0183
JB
7169 rcu_read_lock();
7170 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7171 GFP_ATOMIC);
7172 rcu_read_unlock();
6bad8766
LR
7173
7174 return;
7175
7176nla_put_failure:
7177 genlmsg_cancel(msg, hdr);
7178 nlmsg_free(msg);
7179}
7180
9588bbd5
JM
7181static void nl80211_send_remain_on_chan_event(
7182 int cmd, struct cfg80211_registered_device *rdev,
7183 struct net_device *netdev, u64 cookie,
7184 struct ieee80211_channel *chan,
7185 enum nl80211_channel_type channel_type,
7186 unsigned int duration, gfp_t gfp)
7187{
7188 struct sk_buff *msg;
7189 void *hdr;
7190
7191 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7192 if (!msg)
7193 return;
7194
7195 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7196 if (!hdr) {
7197 nlmsg_free(msg);
7198 return;
7199 }
7200
7201 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7202 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7203 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
7204 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
7205 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7206
7207 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
7208 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
7209
3b7b72ee 7210 genlmsg_end(msg, hdr);
9588bbd5
JM
7211
7212 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7213 nl80211_mlme_mcgrp.id, gfp);
7214 return;
7215
7216 nla_put_failure:
7217 genlmsg_cancel(msg, hdr);
7218 nlmsg_free(msg);
7219}
7220
7221void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7222 struct net_device *netdev, u64 cookie,
7223 struct ieee80211_channel *chan,
7224 enum nl80211_channel_type channel_type,
7225 unsigned int duration, gfp_t gfp)
7226{
7227 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7228 rdev, netdev, cookie, chan,
7229 channel_type, duration, gfp);
7230}
7231
7232void nl80211_send_remain_on_channel_cancel(
7233 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7234 u64 cookie, struct ieee80211_channel *chan,
7235 enum nl80211_channel_type channel_type, gfp_t gfp)
7236{
7237 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7238 rdev, netdev, cookie, chan,
7239 channel_type, 0, gfp);
7240}
7241
98b62183
JB
7242void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7243 struct net_device *dev, const u8 *mac_addr,
7244 struct station_info *sinfo, gfp_t gfp)
7245{
7246 struct sk_buff *msg;
7247
7248 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7249 if (!msg)
7250 return;
7251
7252 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
7253 nlmsg_free(msg);
7254 return;
7255 }
7256
7257 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7258 nl80211_mlme_mcgrp.id, gfp);
7259}
7260
ec15e68b
JM
7261void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7262 struct net_device *dev, const u8 *mac_addr,
7263 gfp_t gfp)
7264{
7265 struct sk_buff *msg;
7266 void *hdr;
7267
7268 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7269 if (!msg)
7270 return;
7271
7272 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7273 if (!hdr) {
7274 nlmsg_free(msg);
7275 return;
7276 }
7277
7278 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7279 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
7280
3b7b72ee 7281 genlmsg_end(msg, hdr);
ec15e68b
JM
7282
7283 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7284 nl80211_mlme_mcgrp.id, gfp);
7285 return;
7286
7287 nla_put_failure:
7288 genlmsg_cancel(msg, hdr);
7289 nlmsg_free(msg);
7290}
7291
b92ab5d8
JB
7292static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
7293 const u8 *addr, gfp_t gfp)
28946da7
JB
7294{
7295 struct wireless_dev *wdev = dev->ieee80211_ptr;
7296 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7297 struct sk_buff *msg;
7298 void *hdr;
7299 int err;
7300 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7301
7302 if (!nlpid)
7303 return false;
7304
7305 msg = nlmsg_new(100, gfp);
7306 if (!msg)
7307 return true;
7308
b92ab5d8 7309 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
7310 if (!hdr) {
7311 nlmsg_free(msg);
7312 return true;
7313 }
7314
7315 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7316 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7317 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7318
7319 err = genlmsg_end(msg, hdr);
7320 if (err < 0) {
7321 nlmsg_free(msg);
7322 return true;
7323 }
7324
7325 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7326 return true;
7327
7328 nla_put_failure:
7329 genlmsg_cancel(msg, hdr);
7330 nlmsg_free(msg);
7331 return true;
7332}
7333
b92ab5d8
JB
7334bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7335{
7336 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
7337 addr, gfp);
7338}
7339
7340bool nl80211_unexpected_4addr_frame(struct net_device *dev,
7341 const u8 *addr, gfp_t gfp)
7342{
7343 return __nl80211_unexpected_frame(dev,
7344 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
7345 addr, gfp);
7346}
7347
2e161f78
JB
7348int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7349 struct net_device *netdev, u32 nlpid,
7350 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
7351{
7352 struct sk_buff *msg;
7353 void *hdr;
026331c4
JM
7354
7355 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7356 if (!msg)
7357 return -ENOMEM;
7358
2e161f78 7359 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
7360 if (!hdr) {
7361 nlmsg_free(msg);
7362 return -ENOMEM;
7363 }
7364
7365 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7366 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7367 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7368 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7369
3b7b72ee 7370 genlmsg_end(msg, hdr);
026331c4 7371
3b7b72ee 7372 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
7373
7374 nla_put_failure:
7375 genlmsg_cancel(msg, hdr);
7376 nlmsg_free(msg);
7377 return -ENOBUFS;
7378}
7379
2e161f78
JB
7380void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7381 struct net_device *netdev, u64 cookie,
7382 const u8 *buf, size_t len, bool ack,
7383 gfp_t gfp)
026331c4
JM
7384{
7385 struct sk_buff *msg;
7386 void *hdr;
7387
7388 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7389 if (!msg)
7390 return;
7391
2e161f78 7392 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
7393 if (!hdr) {
7394 nlmsg_free(msg);
7395 return;
7396 }
7397
7398 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7399 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7400 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7401 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7402 if (ack)
7403 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7404
3b7b72ee 7405 genlmsg_end(msg, hdr);
026331c4
JM
7406
7407 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
7408 return;
7409
7410 nla_put_failure:
7411 genlmsg_cancel(msg, hdr);
7412 nlmsg_free(msg);
7413}
7414
d6dc1a38
JO
7415void
7416nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
7417 struct net_device *netdev,
7418 enum nl80211_cqm_rssi_threshold_event rssi_event,
7419 gfp_t gfp)
7420{
7421 struct sk_buff *msg;
7422 struct nlattr *pinfoattr;
7423 void *hdr;
7424
7425 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7426 if (!msg)
7427 return;
7428
7429 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7430 if (!hdr) {
7431 nlmsg_free(msg);
7432 return;
7433 }
7434
7435 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7436 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7437
7438 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7439 if (!pinfoattr)
7440 goto nla_put_failure;
7441
7442 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
7443 rssi_event);
7444
7445 nla_nest_end(msg, pinfoattr);
7446
3b7b72ee 7447 genlmsg_end(msg, hdr);
d6dc1a38
JO
7448
7449 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7450 nl80211_mlme_mcgrp.id, gfp);
7451 return;
7452
7453 nla_put_failure:
7454 genlmsg_cancel(msg, hdr);
7455 nlmsg_free(msg);
7456}
7457
e5497d76
JB
7458void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
7459 struct net_device *netdev, const u8 *bssid,
7460 const u8 *replay_ctr, gfp_t gfp)
7461{
7462 struct sk_buff *msg;
7463 struct nlattr *rekey_attr;
7464 void *hdr;
7465
7466 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7467 if (!msg)
7468 return;
7469
7470 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
7471 if (!hdr) {
7472 nlmsg_free(msg);
7473 return;
7474 }
7475
7476 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7477 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7478 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7479
7480 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
7481 if (!rekey_attr)
7482 goto nla_put_failure;
7483
7484 NLA_PUT(msg, NL80211_REKEY_DATA_REPLAY_CTR,
7485 NL80211_REPLAY_CTR_LEN, replay_ctr);
7486
7487 nla_nest_end(msg, rekey_attr);
7488
3b7b72ee 7489 genlmsg_end(msg, hdr);
e5497d76
JB
7490
7491 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7492 nl80211_mlme_mcgrp.id, gfp);
7493 return;
7494
7495 nla_put_failure:
7496 genlmsg_cancel(msg, hdr);
7497 nlmsg_free(msg);
7498}
7499
c9df56b4
JM
7500void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
7501 struct net_device *netdev, int index,
7502 const u8 *bssid, bool preauth, gfp_t gfp)
7503{
7504 struct sk_buff *msg;
7505 struct nlattr *attr;
7506 void *hdr;
7507
7508 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7509 if (!msg)
7510 return;
7511
7512 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
7513 if (!hdr) {
7514 nlmsg_free(msg);
7515 return;
7516 }
7517
7518 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7519 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7520
7521 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
7522 if (!attr)
7523 goto nla_put_failure;
7524
7525 NLA_PUT_U32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index);
7526 NLA_PUT(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid);
7527 if (preauth)
7528 NLA_PUT_FLAG(msg, NL80211_PMKSA_CANDIDATE_PREAUTH);
7529
7530 nla_nest_end(msg, attr);
7531
3b7b72ee 7532 genlmsg_end(msg, hdr);
c9df56b4
JM
7533
7534 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7535 nl80211_mlme_mcgrp.id, gfp);
7536 return;
7537
7538 nla_put_failure:
7539 genlmsg_cancel(msg, hdr);
7540 nlmsg_free(msg);
7541}
7542
c063dbf5
JB
7543void
7544nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
7545 struct net_device *netdev, const u8 *peer,
7546 u32 num_packets, gfp_t gfp)
7547{
7548 struct sk_buff *msg;
7549 struct nlattr *pinfoattr;
7550 void *hdr;
7551
7552 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7553 if (!msg)
7554 return;
7555
7556 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7557 if (!hdr) {
7558 nlmsg_free(msg);
7559 return;
7560 }
7561
7562 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7563 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7564 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
7565
7566 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7567 if (!pinfoattr)
7568 goto nla_put_failure;
7569
7570 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
7571
7572 nla_nest_end(msg, pinfoattr);
7573
3b7b72ee 7574 genlmsg_end(msg, hdr);
c063dbf5
JB
7575
7576 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7577 nl80211_mlme_mcgrp.id, gfp);
7578 return;
7579
7580 nla_put_failure:
7581 genlmsg_cancel(msg, hdr);
7582 nlmsg_free(msg);
7583}
7584
7f6cf311
JB
7585void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
7586 u64 cookie, bool acked, gfp_t gfp)
7587{
7588 struct wireless_dev *wdev = dev->ieee80211_ptr;
7589 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7590 struct sk_buff *msg;
7591 void *hdr;
7592 int err;
7593
7594 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7595 if (!msg)
7596 return;
7597
7598 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
7599 if (!hdr) {
7600 nlmsg_free(msg);
7601 return;
7602 }
7603
7604 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7605 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7606 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7607 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7608 if (acked)
7609 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7610
7611 err = genlmsg_end(msg, hdr);
7612 if (err < 0) {
7613 nlmsg_free(msg);
7614 return;
7615 }
7616
7617 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7618 nl80211_mlme_mcgrp.id, gfp);
7619 return;
7620
7621 nla_put_failure:
7622 genlmsg_cancel(msg, hdr);
7623 nlmsg_free(msg);
7624}
7625EXPORT_SYMBOL(cfg80211_probe_status);
7626
5e760230
JB
7627void cfg80211_report_obss_beacon(struct wiphy *wiphy,
7628 const u8 *frame, size_t len,
7629 int freq, gfp_t gfp)
7630{
7631 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
7632 struct sk_buff *msg;
7633 void *hdr;
7634 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
7635
7636 if (!nlpid)
7637 return;
7638
7639 msg = nlmsg_new(len + 100, gfp);
7640 if (!msg)
7641 return;
7642
7643 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
7644 if (!hdr) {
7645 nlmsg_free(msg);
7646 return;
7647 }
7648
7649 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7650 if (freq)
7651 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7652 NLA_PUT(msg, NL80211_ATTR_FRAME, len, frame);
7653
7654 genlmsg_end(msg, hdr);
7655
7656 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7657 return;
7658
7659 nla_put_failure:
7660 genlmsg_cancel(msg, hdr);
7661 nlmsg_free(msg);
7662}
7663EXPORT_SYMBOL(cfg80211_report_obss_beacon);
7664
026331c4
JM
7665static int nl80211_netlink_notify(struct notifier_block * nb,
7666 unsigned long state,
7667 void *_notify)
7668{
7669 struct netlink_notify *notify = _notify;
7670 struct cfg80211_registered_device *rdev;
7671 struct wireless_dev *wdev;
7672
7673 if (state != NETLINK_URELEASE)
7674 return NOTIFY_DONE;
7675
7676 rcu_read_lock();
7677
5e760230 7678 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
026331c4 7679 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 7680 cfg80211_mlme_unregister_socket(wdev, notify->pid);
5e760230
JB
7681 if (rdev->ap_beacons_nlpid == notify->pid)
7682 rdev->ap_beacons_nlpid = 0;
7683 }
026331c4
JM
7684
7685 rcu_read_unlock();
7686
7687 return NOTIFY_DONE;
7688}
7689
7690static struct notifier_block nl80211_netlink_notifier = {
7691 .notifier_call = nl80211_netlink_notify,
7692};
7693
55682965
JB
7694/* initialisation/exit functions */
7695
7696int nl80211_init(void)
7697{
0d63cbb5 7698 int err;
55682965 7699
0d63cbb5
MM
7700 err = genl_register_family_with_ops(&nl80211_fam,
7701 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
7702 if (err)
7703 return err;
7704
55682965
JB
7705 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
7706 if (err)
7707 goto err_out;
7708
2a519311
JB
7709 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
7710 if (err)
7711 goto err_out;
7712
73d54c9e
LR
7713 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
7714 if (err)
7715 goto err_out;
7716
6039f6d2
JM
7717 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
7718 if (err)
7719 goto err_out;
7720
aff89a9b
JB
7721#ifdef CONFIG_NL80211_TESTMODE
7722 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
7723 if (err)
7724 goto err_out;
7725#endif
7726
026331c4
JM
7727 err = netlink_register_notifier(&nl80211_netlink_notifier);
7728 if (err)
7729 goto err_out;
7730
55682965
JB
7731 return 0;
7732 err_out:
7733 genl_unregister_family(&nl80211_fam);
7734 return err;
7735}
7736
7737void nl80211_exit(void)
7738{
026331c4 7739 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
7740 genl_unregister_family(&nl80211_fam);
7741}