]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/blame - net/wireless/nl80211.c
mac80211: fix broadcast frame handling for 4-addr AP VLANs
[mirror_ubuntu-artful-kernel.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
08645126 4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
55682965
JB
10#include <linux/list.h>
11#include <linux/if_ether.h>
12#include <linux/ieee80211.h>
13#include <linux/nl80211.h>
14#include <linux/rtnetlink.h>
15#include <linux/netlink.h>
2a519311 16#include <linux/etherdevice.h>
463d0183 17#include <net/net_namespace.h>
55682965
JB
18#include <net/genetlink.h>
19#include <net/cfg80211.h>
463d0183 20#include <net/sock.h>
55682965
JB
21#include "core.h"
22#include "nl80211.h"
b2e1b302 23#include "reg.h"
55682965
JB
24
25/* the netlink family */
26static struct genl_family nl80211_fam = {
27 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28 .name = "nl80211", /* have users key off the name instead */
29 .hdrsize = 0, /* no private header */
30 .version = 1, /* no particular meaning now */
31 .maxattr = NL80211_ATTR_MAX,
463d0183 32 .netnsok = true,
55682965
JB
33};
34
79c97e97 35/* internal helper: get rdev and dev */
463d0183 36static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 37 struct cfg80211_registered_device **rdev,
55682965
JB
38 struct net_device **dev)
39{
463d0183 40 struct nlattr **attrs = info->attrs;
55682965
JB
41 int ifindex;
42
bba95fef 43 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
44 return -EINVAL;
45
bba95fef 46 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 47 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
48 if (!*dev)
49 return -ENODEV;
50
463d0183 51 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 52 if (IS_ERR(*rdev)) {
55682965 53 dev_put(*dev);
79c97e97 54 return PTR_ERR(*rdev);
55682965
JB
55 }
56
57 return 0;
58}
59
60/* policy for the attributes */
61static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 64 .len = 20-1 },
31888487 65 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 66 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 67 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
68 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
55682965
JB
72
73 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
74 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
75 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
76
77 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 78 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 79
b9454e83 80 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
81 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
82 .len = WLAN_MAX_KEY_LEN },
83 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
84 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
85 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 86 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
87
88 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
89 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
90 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
91 .len = IEEE80211_MAX_DATA_LEN },
92 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
94 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
95 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
96 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
98 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 99 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 100 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 101 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
102 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_MESH_ID_LEN },
104 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 105
b2e1b302
LR
106 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
107 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
108
9f1ba906
JM
109 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
110 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
111 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
112 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
36aedc90 114
93da9cc1 115 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
116
36aedc90
JM
117 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
118 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
119
120 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
121 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
122 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
123 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
124 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
125
126 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
127 .len = IEEE80211_MAX_SSID_LEN },
128 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
129 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 130 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 131 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 132 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
133 [NL80211_ATTR_STA_FLAGS2] = {
134 .len = sizeof(struct nl80211_sta_flag_update),
135 },
3f77316c 136 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
137 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
138 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
139 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 140 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 141 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
55682965
JB
142};
143
b9454e83
JB
144/* policy for the attributes */
145static struct nla_policy
146nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
fffd0934 147 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
148 [NL80211_KEY_IDX] = { .type = NLA_U8 },
149 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
150 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
151 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
152 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
153};
154
a043897a
HS
155/* ifidx get helper */
156static int nl80211_get_ifidx(struct netlink_callback *cb)
157{
158 int res;
159
160 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
161 nl80211_fam.attrbuf, nl80211_fam.maxattr,
162 nl80211_policy);
163 if (res)
164 return res;
165
166 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
167 return -EINVAL;
168
169 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
170 if (!res)
171 return -EINVAL;
172 return res;
173}
174
f4a11bb0
JB
175/* IE validation */
176static bool is_valid_ie_attr(const struct nlattr *attr)
177{
178 const u8 *pos;
179 int len;
180
181 if (!attr)
182 return true;
183
184 pos = nla_data(attr);
185 len = nla_len(attr);
186
187 while (len) {
188 u8 elemlen;
189
190 if (len < 2)
191 return false;
192 len -= 2;
193
194 elemlen = pos[1];
195 if (elemlen > len)
196 return false;
197
198 len -= elemlen;
199 pos += 2 + elemlen;
200 }
201
202 return true;
203}
204
55682965
JB
205/* message building helper */
206static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
207 int flags, u8 cmd)
208{
209 /* since there is no private header just add the generic one */
210 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
211}
212
5dab3b8a
LR
213static int nl80211_msg_put_channel(struct sk_buff *msg,
214 struct ieee80211_channel *chan)
215{
216 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
217 chan->center_freq);
218
219 if (chan->flags & IEEE80211_CHAN_DISABLED)
220 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
221 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
222 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
223 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
224 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
225 if (chan->flags & IEEE80211_CHAN_RADAR)
226 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
227
228 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
229 DBM_TO_MBM(chan->max_power));
230
231 return 0;
232
233 nla_put_failure:
234 return -ENOBUFS;
235}
236
55682965
JB
237/* netlink command implementations */
238
b9454e83
JB
239struct key_parse {
240 struct key_params p;
241 int idx;
242 bool def, defmgmt;
243};
244
245static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
246{
247 struct nlattr *tb[NL80211_KEY_MAX + 1];
248 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
249 nl80211_key_policy);
250 if (err)
251 return err;
252
253 k->def = !!tb[NL80211_KEY_DEFAULT];
254 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
255
256 if (tb[NL80211_KEY_IDX])
257 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
258
259 if (tb[NL80211_KEY_DATA]) {
260 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
261 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
262 }
263
264 if (tb[NL80211_KEY_SEQ]) {
265 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
266 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
267 }
268
269 if (tb[NL80211_KEY_CIPHER])
270 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
271
272 return 0;
273}
274
275static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
276{
277 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
278 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
279 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
280 }
281
282 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
283 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
284 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
285 }
286
287 if (info->attrs[NL80211_ATTR_KEY_IDX])
288 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
289
290 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
291 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
292
293 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
294 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
295
296 return 0;
297}
298
299static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
300{
301 int err;
302
303 memset(k, 0, sizeof(*k));
304 k->idx = -1;
305
306 if (info->attrs[NL80211_ATTR_KEY])
307 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
308 else
309 err = nl80211_parse_key_old(info, k);
310
311 if (err)
312 return err;
313
314 if (k->def && k->defmgmt)
315 return -EINVAL;
316
317 if (k->idx != -1) {
318 if (k->defmgmt) {
319 if (k->idx < 4 || k->idx > 5)
320 return -EINVAL;
321 } else if (k->def) {
322 if (k->idx < 0 || k->idx > 3)
323 return -EINVAL;
324 } else {
325 if (k->idx < 0 || k->idx > 5)
326 return -EINVAL;
327 }
328 }
329
330 return 0;
331}
332
fffd0934
JB
333static struct cfg80211_cached_keys *
334nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
335 struct nlattr *keys)
336{
337 struct key_parse parse;
338 struct nlattr *key;
339 struct cfg80211_cached_keys *result;
340 int rem, err, def = 0;
341
342 result = kzalloc(sizeof(*result), GFP_KERNEL);
343 if (!result)
344 return ERR_PTR(-ENOMEM);
345
346 result->def = -1;
347 result->defmgmt = -1;
348
349 nla_for_each_nested(key, keys, rem) {
350 memset(&parse, 0, sizeof(parse));
351 parse.idx = -1;
352
353 err = nl80211_parse_key_new(key, &parse);
354 if (err)
355 goto error;
356 err = -EINVAL;
357 if (!parse.p.key)
358 goto error;
359 if (parse.idx < 0 || parse.idx > 4)
360 goto error;
361 if (parse.def) {
362 if (def)
363 goto error;
364 def = 1;
365 result->def = parse.idx;
366 } else if (parse.defmgmt)
367 goto error;
368 err = cfg80211_validate_key_settings(rdev, &parse.p,
369 parse.idx, NULL);
370 if (err)
371 goto error;
372 result->params[parse.idx].cipher = parse.p.cipher;
373 result->params[parse.idx].key_len = parse.p.key_len;
374 result->params[parse.idx].key = result->data[parse.idx];
375 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
376 }
377
378 return result;
379 error:
380 kfree(result);
381 return ERR_PTR(err);
382}
383
384static int nl80211_key_allowed(struct wireless_dev *wdev)
385{
386 ASSERT_WDEV_LOCK(wdev);
387
388 if (!netif_running(wdev->netdev))
389 return -ENETDOWN;
390
391 switch (wdev->iftype) {
392 case NL80211_IFTYPE_AP:
393 case NL80211_IFTYPE_AP_VLAN:
394 break;
395 case NL80211_IFTYPE_ADHOC:
396 if (!wdev->current_bss)
397 return -ENOLINK;
398 break;
399 case NL80211_IFTYPE_STATION:
400 if (wdev->sme_state != CFG80211_SME_CONNECTED)
401 return -ENOLINK;
402 break;
403 default:
404 return -EINVAL;
405 }
406
407 return 0;
408}
409
55682965
JB
410static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
411 struct cfg80211_registered_device *dev)
412{
413 void *hdr;
ee688b00
JB
414 struct nlattr *nl_bands, *nl_band;
415 struct nlattr *nl_freqs, *nl_freq;
416 struct nlattr *nl_rates, *nl_rate;
f59ac048 417 struct nlattr *nl_modes;
8fdc621d 418 struct nlattr *nl_cmds;
ee688b00
JB
419 enum ieee80211_band band;
420 struct ieee80211_channel *chan;
421 struct ieee80211_rate *rate;
422 int i;
f59ac048 423 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
424
425 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
426 if (!hdr)
427 return -1;
428
b5850a7a 429 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 430 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 431
f5ea9120
JB
432 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
433 cfg80211_rdev_list_generation);
434
b9a5f8ca
JM
435 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
436 dev->wiphy.retry_short);
437 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
438 dev->wiphy.retry_long);
439 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
440 dev->wiphy.frag_threshold);
441 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
442 dev->wiphy.rts_threshold);
443
2a519311
JB
444 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
445 dev->wiphy.max_scan_ssids);
18a83659
JB
446 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
447 dev->wiphy.max_scan_ie_len);
ee688b00 448
25e47c18
JB
449 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
450 sizeof(u32) * dev->wiphy.n_cipher_suites,
451 dev->wiphy.cipher_suites);
452
f59ac048
LR
453 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
454 if (!nl_modes)
455 goto nla_put_failure;
456
457 i = 0;
458 while (ifmodes) {
459 if (ifmodes & 1)
460 NLA_PUT_FLAG(msg, i);
461 ifmodes >>= 1;
462 i++;
463 }
464
465 nla_nest_end(msg, nl_modes);
466
ee688b00
JB
467 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
468 if (!nl_bands)
469 goto nla_put_failure;
470
471 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
472 if (!dev->wiphy.bands[band])
473 continue;
474
475 nl_band = nla_nest_start(msg, band);
476 if (!nl_band)
477 goto nla_put_failure;
478
d51626df
JB
479 /* add HT info */
480 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
481 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
482 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
483 &dev->wiphy.bands[band]->ht_cap.mcs);
484 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
485 dev->wiphy.bands[band]->ht_cap.cap);
486 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
487 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
488 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
489 dev->wiphy.bands[band]->ht_cap.ampdu_density);
490 }
491
ee688b00
JB
492 /* add frequencies */
493 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
494 if (!nl_freqs)
495 goto nla_put_failure;
496
497 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
498 nl_freq = nla_nest_start(msg, i);
499 if (!nl_freq)
500 goto nla_put_failure;
501
502 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
503
504 if (nl80211_msg_put_channel(msg, chan))
505 goto nla_put_failure;
e2f367f2 506
ee688b00
JB
507 nla_nest_end(msg, nl_freq);
508 }
509
510 nla_nest_end(msg, nl_freqs);
511
512 /* add bitrates */
513 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
514 if (!nl_rates)
515 goto nla_put_failure;
516
517 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
518 nl_rate = nla_nest_start(msg, i);
519 if (!nl_rate)
520 goto nla_put_failure;
521
522 rate = &dev->wiphy.bands[band]->bitrates[i];
523 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
524 rate->bitrate);
525 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
526 NLA_PUT_FLAG(msg,
527 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
528
529 nla_nest_end(msg, nl_rate);
530 }
531
532 nla_nest_end(msg, nl_rates);
533
534 nla_nest_end(msg, nl_band);
535 }
536 nla_nest_end(msg, nl_bands);
537
8fdc621d
JB
538 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
539 if (!nl_cmds)
540 goto nla_put_failure;
541
542 i = 0;
543#define CMD(op, n) \
544 do { \
545 if (dev->ops->op) { \
546 i++; \
547 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
548 } \
549 } while (0)
550
551 CMD(add_virtual_intf, NEW_INTERFACE);
552 CMD(change_virtual_intf, SET_INTERFACE);
553 CMD(add_key, NEW_KEY);
554 CMD(add_beacon, NEW_BEACON);
555 CMD(add_station, NEW_STATION);
556 CMD(add_mpath, NEW_MPATH);
557 CMD(set_mesh_params, SET_MESH_PARAMS);
558 CMD(change_bss, SET_BSS);
636a5d36
JM
559 CMD(auth, AUTHENTICATE);
560 CMD(assoc, ASSOCIATE);
561 CMD(deauth, DEAUTHENTICATE);
562 CMD(disassoc, DISASSOCIATE);
04a773ad 563 CMD(join_ibss, JOIN_IBSS);
463d0183
JB
564 if (dev->wiphy.netnsok) {
565 i++;
566 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
567 }
8fdc621d
JB
568
569#undef CMD
b23aa676 570
6829c878 571 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
572 i++;
573 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
574 }
575
6829c878 576 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
577 i++;
578 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
579 }
580
8fdc621d
JB
581 nla_nest_end(msg, nl_cmds);
582
55682965
JB
583 return genlmsg_end(msg, hdr);
584
585 nla_put_failure:
bc3ed28c
TG
586 genlmsg_cancel(msg, hdr);
587 return -EMSGSIZE;
55682965
JB
588}
589
590static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
591{
592 int idx = 0;
593 int start = cb->args[0];
594 struct cfg80211_registered_device *dev;
595
a1794390 596 mutex_lock(&cfg80211_mutex);
79c97e97 597 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
598 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
599 continue;
b4637271 600 if (++idx <= start)
55682965
JB
601 continue;
602 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
603 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
604 dev) < 0) {
605 idx--;
55682965 606 break;
b4637271 607 }
55682965 608 }
a1794390 609 mutex_unlock(&cfg80211_mutex);
55682965
JB
610
611 cb->args[0] = idx;
612
613 return skb->len;
614}
615
616static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
617{
618 struct sk_buff *msg;
619 struct cfg80211_registered_device *dev;
620
621 dev = cfg80211_get_dev_from_info(info);
622 if (IS_ERR(dev))
623 return PTR_ERR(dev);
624
fd2120ca 625 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
626 if (!msg)
627 goto out_err;
628
629 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
630 goto out_free;
631
4d0c8aea 632 cfg80211_unlock_rdev(dev);
55682965 633
134e6375 634 return genlmsg_reply(msg, info);
55682965
JB
635
636 out_free:
637 nlmsg_free(msg);
638 out_err:
4d0c8aea 639 cfg80211_unlock_rdev(dev);
55682965
JB
640 return -ENOBUFS;
641}
642
31888487
JM
643static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
644 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
645 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
646 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
647 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
648 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
649};
650
651static int parse_txq_params(struct nlattr *tb[],
652 struct ieee80211_txq_params *txq_params)
653{
654 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
655 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
656 !tb[NL80211_TXQ_ATTR_AIFS])
657 return -EINVAL;
658
659 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
660 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
661 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
662 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
663 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
664
665 return 0;
666}
667
55682965
JB
668static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
669{
670 struct cfg80211_registered_device *rdev;
31888487
JM
671 int result = 0, rem_txq_params = 0;
672 struct nlattr *nl_txq_params;
b9a5f8ca
JM
673 u32 changed;
674 u8 retry_short = 0, retry_long = 0;
675 u32 frag_threshold = 0, rts_threshold = 0;
55682965 676
4bbf4d56 677 rtnl_lock();
55682965 678
4bbf4d56
JB
679 mutex_lock(&cfg80211_mutex);
680
79c97e97 681 rdev = __cfg80211_rdev_from_info(info);
4bbf4d56 682 if (IS_ERR(rdev)) {
1f5fc70a 683 mutex_unlock(&cfg80211_mutex);
4bbf4d56
JB
684 result = PTR_ERR(rdev);
685 goto unlock;
686 }
687
688 mutex_lock(&rdev->mtx);
689
690 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
691 result = cfg80211_dev_rename(
692 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
693
694 mutex_unlock(&cfg80211_mutex);
695
696 if (result)
697 goto bad_res;
31888487
JM
698
699 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
700 struct ieee80211_txq_params txq_params;
701 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
702
703 if (!rdev->ops->set_txq_params) {
704 result = -EOPNOTSUPP;
705 goto bad_res;
706 }
707
708 nla_for_each_nested(nl_txq_params,
709 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
710 rem_txq_params) {
711 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
712 nla_data(nl_txq_params),
713 nla_len(nl_txq_params),
714 txq_params_policy);
715 result = parse_txq_params(tb, &txq_params);
716 if (result)
717 goto bad_res;
718
719 result = rdev->ops->set_txq_params(&rdev->wiphy,
720 &txq_params);
721 if (result)
722 goto bad_res;
723 }
724 }
55682965 725
72bdcf34 726 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
094d05dc 727 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
294196ab 728 u32 freq;
72bdcf34 729
306d6112
JB
730 result = -EINVAL;
731
094d05dc
S
732 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
733 channel_type = nla_get_u32(info->attrs[
734 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
735 if (channel_type != NL80211_CHAN_NO_HT &&
736 channel_type != NL80211_CHAN_HT20 &&
737 channel_type != NL80211_CHAN_HT40PLUS &&
738 channel_type != NL80211_CHAN_HT40MINUS)
72bdcf34 739 goto bad_res;
72bdcf34
JM
740 }
741
742 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
306d6112 743
59bbb6f7 744 mutex_lock(&rdev->devlist_mtx);
4b181144 745 result = rdev_set_freq(rdev, NULL, freq, channel_type);
59bbb6f7 746 mutex_unlock(&rdev->devlist_mtx);
72bdcf34
JM
747 if (result)
748 goto bad_res;
749 }
750
b9a5f8ca
JM
751 changed = 0;
752
753 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
754 retry_short = nla_get_u8(
755 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
756 if (retry_short == 0) {
757 result = -EINVAL;
758 goto bad_res;
759 }
760 changed |= WIPHY_PARAM_RETRY_SHORT;
761 }
762
763 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
764 retry_long = nla_get_u8(
765 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
766 if (retry_long == 0) {
767 result = -EINVAL;
768 goto bad_res;
769 }
770 changed |= WIPHY_PARAM_RETRY_LONG;
771 }
772
773 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
774 frag_threshold = nla_get_u32(
775 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
776 if (frag_threshold < 256) {
777 result = -EINVAL;
778 goto bad_res;
779 }
780 if (frag_threshold != (u32) -1) {
781 /*
782 * Fragments (apart from the last one) are required to
783 * have even length. Make the fragmentation code
784 * simpler by stripping LSB should someone try to use
785 * odd threshold value.
786 */
787 frag_threshold &= ~0x1;
788 }
789 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
790 }
791
792 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
793 rts_threshold = nla_get_u32(
794 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
795 changed |= WIPHY_PARAM_RTS_THRESHOLD;
796 }
797
798 if (changed) {
799 u8 old_retry_short, old_retry_long;
800 u32 old_frag_threshold, old_rts_threshold;
801
802 if (!rdev->ops->set_wiphy_params) {
803 result = -EOPNOTSUPP;
804 goto bad_res;
805 }
806
807 old_retry_short = rdev->wiphy.retry_short;
808 old_retry_long = rdev->wiphy.retry_long;
809 old_frag_threshold = rdev->wiphy.frag_threshold;
810 old_rts_threshold = rdev->wiphy.rts_threshold;
811
812 if (changed & WIPHY_PARAM_RETRY_SHORT)
813 rdev->wiphy.retry_short = retry_short;
814 if (changed & WIPHY_PARAM_RETRY_LONG)
815 rdev->wiphy.retry_long = retry_long;
816 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
817 rdev->wiphy.frag_threshold = frag_threshold;
818 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
819 rdev->wiphy.rts_threshold = rts_threshold;
820
821 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
822 if (result) {
823 rdev->wiphy.retry_short = old_retry_short;
824 rdev->wiphy.retry_long = old_retry_long;
825 rdev->wiphy.frag_threshold = old_frag_threshold;
826 rdev->wiphy.rts_threshold = old_rts_threshold;
827 }
828 }
72bdcf34 829
306d6112 830 bad_res:
4bbf4d56
JB
831 mutex_unlock(&rdev->mtx);
832 unlock:
833 rtnl_unlock();
55682965
JB
834 return result;
835}
836
837
838static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 839 struct cfg80211_registered_device *rdev,
55682965
JB
840 struct net_device *dev)
841{
842 void *hdr;
843
844 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
845 if (!hdr)
846 return -1;
847
848 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 849 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 850 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 851 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
852
853 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
854 rdev->devlist_generation ^
855 (cfg80211_rdev_list_generation << 2));
856
55682965
JB
857 return genlmsg_end(msg, hdr);
858
859 nla_put_failure:
bc3ed28c
TG
860 genlmsg_cancel(msg, hdr);
861 return -EMSGSIZE;
55682965
JB
862}
863
864static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
865{
866 int wp_idx = 0;
867 int if_idx = 0;
868 int wp_start = cb->args[0];
869 int if_start = cb->args[1];
f5ea9120 870 struct cfg80211_registered_device *rdev;
55682965
JB
871 struct wireless_dev *wdev;
872
a1794390 873 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
874 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
875 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 876 continue;
bba95fef
JB
877 if (wp_idx < wp_start) {
878 wp_idx++;
55682965 879 continue;
bba95fef 880 }
55682965
JB
881 if_idx = 0;
882
f5ea9120
JB
883 mutex_lock(&rdev->devlist_mtx);
884 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
885 if (if_idx < if_start) {
886 if_idx++;
55682965 887 continue;
bba95fef 888 }
55682965
JB
889 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
890 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
891 rdev, wdev->netdev) < 0) {
892 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
893 goto out;
894 }
895 if_idx++;
55682965 896 }
f5ea9120 897 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
898
899 wp_idx++;
55682965 900 }
bba95fef 901 out:
a1794390 902 mutex_unlock(&cfg80211_mutex);
55682965
JB
903
904 cb->args[0] = wp_idx;
905 cb->args[1] = if_idx;
906
907 return skb->len;
908}
909
910static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
911{
912 struct sk_buff *msg;
913 struct cfg80211_registered_device *dev;
914 struct net_device *netdev;
915 int err;
916
463d0183 917 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
918 if (err)
919 return err;
920
fd2120ca 921 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
922 if (!msg)
923 goto out_err;
924
d726405a
JB
925 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
926 dev, netdev) < 0)
55682965
JB
927 goto out_free;
928
929 dev_put(netdev);
4d0c8aea 930 cfg80211_unlock_rdev(dev);
55682965 931
134e6375 932 return genlmsg_reply(msg, info);
55682965
JB
933
934 out_free:
935 nlmsg_free(msg);
936 out_err:
937 dev_put(netdev);
4d0c8aea 938 cfg80211_unlock_rdev(dev);
55682965
JB
939 return -ENOBUFS;
940}
941
66f7ac50
MW
942static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
943 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
944 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
945 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
946 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
947 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
948};
949
950static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
951{
952 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
953 int flag;
954
955 *mntrflags = 0;
956
957 if (!nla)
958 return -EINVAL;
959
960 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
961 nla, mntr_flags_policy))
962 return -EINVAL;
963
964 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
965 if (flags[flag])
966 *mntrflags |= (1<<flag);
967
968 return 0;
969}
970
55682965
JB
971static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
972{
79c97e97 973 struct cfg80211_registered_device *rdev;
2ec600d6 974 struct vif_params params;
e36d56b6 975 int err;
04a773ad 976 enum nl80211_iftype otype, ntype;
55682965 977 struct net_device *dev;
92ffe055 978 u32 _flags, *flags = NULL;
ac7f9cfa 979 bool change = false;
55682965 980
2ec600d6
LCC
981 memset(&params, 0, sizeof(params));
982
3b85875a
JB
983 rtnl_lock();
984
463d0183 985 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 986 if (err)
3b85875a
JB
987 goto unlock_rtnl;
988
04a773ad 989 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 990
723b038d 991 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 992 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 993 if (otype != ntype)
ac7f9cfa 994 change = true;
04a773ad 995 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 996 err = -EINVAL;
723b038d 997 goto unlock;
ac7f9cfa 998 }
723b038d
JB
999 }
1000
92ffe055 1001 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1002 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1003 err = -EINVAL;
1004 goto unlock;
1005 }
2ec600d6
LCC
1006 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1007 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1008 change = true;
2ec600d6
LCC
1009 }
1010
8b787643
FF
1011 if (info->attrs[NL80211_ATTR_4ADDR]) {
1012 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1013 change = true;
1014 } else {
1015 params.use_4addr = -1;
1016 }
1017
92ffe055 1018 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1019 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1020 err = -EINVAL;
1021 goto unlock;
1022 }
1023 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1024 &_flags);
ac7f9cfa
JB
1025 if (err)
1026 goto unlock;
1027
1028 flags = &_flags;
1029 change = true;
92ffe055 1030 }
3b85875a 1031
ac7f9cfa 1032 if (change)
3d54d255 1033 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1034 else
1035 err = 0;
60719ffd 1036
55682965 1037 unlock:
e36d56b6 1038 dev_put(dev);
79c97e97 1039 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1040 unlock_rtnl:
1041 rtnl_unlock();
55682965
JB
1042 return err;
1043}
1044
1045static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1046{
79c97e97 1047 struct cfg80211_registered_device *rdev;
2ec600d6 1048 struct vif_params params;
55682965
JB
1049 int err;
1050 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1051 u32 flags;
55682965 1052
2ec600d6
LCC
1053 memset(&params, 0, sizeof(params));
1054
55682965
JB
1055 if (!info->attrs[NL80211_ATTR_IFNAME])
1056 return -EINVAL;
1057
1058 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1059 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1060 if (type > NL80211_IFTYPE_MAX)
1061 return -EINVAL;
1062 }
1063
3b85875a
JB
1064 rtnl_lock();
1065
79c97e97
JB
1066 rdev = cfg80211_get_dev_from_info(info);
1067 if (IS_ERR(rdev)) {
1068 err = PTR_ERR(rdev);
3b85875a
JB
1069 goto unlock_rtnl;
1070 }
55682965 1071
79c97e97
JB
1072 if (!rdev->ops->add_virtual_intf ||
1073 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1074 err = -EOPNOTSUPP;
1075 goto unlock;
1076 }
1077
2ec600d6
LCC
1078 if (type == NL80211_IFTYPE_MESH_POINT &&
1079 info->attrs[NL80211_ATTR_MESH_ID]) {
1080 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1081 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1082 }
1083
8b787643
FF
1084 if (info->attrs[NL80211_ATTR_4ADDR])
1085 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1086
66f7ac50
MW
1087 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1088 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1089 &flags);
79c97e97 1090 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1091 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1092 type, err ? NULL : &flags, &params);
2ec600d6 1093
55682965 1094 unlock:
79c97e97 1095 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1096 unlock_rtnl:
1097 rtnl_unlock();
55682965
JB
1098 return err;
1099}
1100
1101static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1102{
79c97e97 1103 struct cfg80211_registered_device *rdev;
463d0183 1104 int err;
55682965
JB
1105 struct net_device *dev;
1106
3b85875a
JB
1107 rtnl_lock();
1108
463d0183 1109 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1110 if (err)
3b85875a 1111 goto unlock_rtnl;
55682965 1112
79c97e97 1113 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1114 err = -EOPNOTSUPP;
1115 goto out;
1116 }
1117
463d0183 1118 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1119
1120 out:
79c97e97 1121 cfg80211_unlock_rdev(rdev);
463d0183 1122 dev_put(dev);
3b85875a
JB
1123 unlock_rtnl:
1124 rtnl_unlock();
55682965
JB
1125 return err;
1126}
1127
41ade00f
JB
1128struct get_key_cookie {
1129 struct sk_buff *msg;
1130 int error;
b9454e83 1131 int idx;
41ade00f
JB
1132};
1133
1134static void get_key_callback(void *c, struct key_params *params)
1135{
b9454e83 1136 struct nlattr *key;
41ade00f
JB
1137 struct get_key_cookie *cookie = c;
1138
1139 if (params->key)
1140 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1141 params->key_len, params->key);
1142
1143 if (params->seq)
1144 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1145 params->seq_len, params->seq);
1146
1147 if (params->cipher)
1148 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1149 params->cipher);
1150
b9454e83
JB
1151 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1152 if (!key)
1153 goto nla_put_failure;
1154
1155 if (params->key)
1156 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1157 params->key_len, params->key);
1158
1159 if (params->seq)
1160 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1161 params->seq_len, params->seq);
1162
1163 if (params->cipher)
1164 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1165 params->cipher);
1166
1167 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1168
1169 nla_nest_end(cookie->msg, key);
1170
41ade00f
JB
1171 return;
1172 nla_put_failure:
1173 cookie->error = 1;
1174}
1175
1176static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1177{
79c97e97 1178 struct cfg80211_registered_device *rdev;
41ade00f
JB
1179 int err;
1180 struct net_device *dev;
1181 u8 key_idx = 0;
1182 u8 *mac_addr = NULL;
1183 struct get_key_cookie cookie = {
1184 .error = 0,
1185 };
1186 void *hdr;
1187 struct sk_buff *msg;
1188
1189 if (info->attrs[NL80211_ATTR_KEY_IDX])
1190 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1191
3cfcf6ac 1192 if (key_idx > 5)
41ade00f
JB
1193 return -EINVAL;
1194
1195 if (info->attrs[NL80211_ATTR_MAC])
1196 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1197
3b85875a
JB
1198 rtnl_lock();
1199
463d0183 1200 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1201 if (err)
3b85875a 1202 goto unlock_rtnl;
41ade00f 1203
79c97e97 1204 if (!rdev->ops->get_key) {
41ade00f
JB
1205 err = -EOPNOTSUPP;
1206 goto out;
1207 }
1208
fd2120ca 1209 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1210 if (!msg) {
1211 err = -ENOMEM;
1212 goto out;
1213 }
1214
1215 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1216 NL80211_CMD_NEW_KEY);
1217
1218 if (IS_ERR(hdr)) {
1219 err = PTR_ERR(hdr);
6c95e2a2 1220 goto free_msg;
41ade00f
JB
1221 }
1222
1223 cookie.msg = msg;
b9454e83 1224 cookie.idx = key_idx;
41ade00f
JB
1225
1226 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1227 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1228 if (mac_addr)
1229 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1230
79c97e97 1231 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1232 &cookie, get_key_callback);
41ade00f
JB
1233
1234 if (err)
6c95e2a2 1235 goto free_msg;
41ade00f
JB
1236
1237 if (cookie.error)
1238 goto nla_put_failure;
1239
1240 genlmsg_end(msg, hdr);
134e6375 1241 err = genlmsg_reply(msg, info);
41ade00f
JB
1242 goto out;
1243
1244 nla_put_failure:
1245 err = -ENOBUFS;
6c95e2a2 1246 free_msg:
41ade00f
JB
1247 nlmsg_free(msg);
1248 out:
79c97e97 1249 cfg80211_unlock_rdev(rdev);
41ade00f 1250 dev_put(dev);
3b85875a
JB
1251 unlock_rtnl:
1252 rtnl_unlock();
1253
41ade00f
JB
1254 return err;
1255}
1256
1257static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1258{
79c97e97 1259 struct cfg80211_registered_device *rdev;
b9454e83 1260 struct key_parse key;
41ade00f
JB
1261 int err;
1262 struct net_device *dev;
3cfcf6ac
JM
1263 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1264 u8 key_index);
41ade00f 1265
b9454e83
JB
1266 err = nl80211_parse_key(info, &key);
1267 if (err)
1268 return err;
41ade00f 1269
b9454e83 1270 if (key.idx < 0)
41ade00f
JB
1271 return -EINVAL;
1272
b9454e83
JB
1273 /* only support setting default key */
1274 if (!key.def && !key.defmgmt)
41ade00f
JB
1275 return -EINVAL;
1276
3b85875a
JB
1277 rtnl_lock();
1278
463d0183 1279 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1280 if (err)
3b85875a 1281 goto unlock_rtnl;
41ade00f 1282
b9454e83 1283 if (key.def)
79c97e97 1284 func = rdev->ops->set_default_key;
3cfcf6ac 1285 else
79c97e97 1286 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1287
1288 if (!func) {
41ade00f
JB
1289 err = -EOPNOTSUPP;
1290 goto out;
1291 }
1292
fffd0934
JB
1293 wdev_lock(dev->ieee80211_ptr);
1294 err = nl80211_key_allowed(dev->ieee80211_ptr);
1295 if (!err)
1296 err = func(&rdev->wiphy, dev, key.idx);
1297
3d23e349 1298#ifdef CONFIG_CFG80211_WEXT
08645126 1299 if (!err) {
79c97e97 1300 if (func == rdev->ops->set_default_key)
b9454e83 1301 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1302 else
b9454e83 1303 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1304 }
1305#endif
fffd0934 1306 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1307
1308 out:
79c97e97 1309 cfg80211_unlock_rdev(rdev);
41ade00f 1310 dev_put(dev);
3b85875a
JB
1311
1312 unlock_rtnl:
1313 rtnl_unlock();
1314
41ade00f
JB
1315 return err;
1316}
1317
1318static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1319{
79c97e97 1320 struct cfg80211_registered_device *rdev;
fffd0934 1321 int err;
41ade00f 1322 struct net_device *dev;
b9454e83 1323 struct key_parse key;
41ade00f
JB
1324 u8 *mac_addr = NULL;
1325
b9454e83
JB
1326 err = nl80211_parse_key(info, &key);
1327 if (err)
1328 return err;
41ade00f 1329
b9454e83 1330 if (!key.p.key)
41ade00f
JB
1331 return -EINVAL;
1332
41ade00f
JB
1333 if (info->attrs[NL80211_ATTR_MAC])
1334 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1335
3b85875a
JB
1336 rtnl_lock();
1337
463d0183 1338 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1339 if (err)
3b85875a 1340 goto unlock_rtnl;
41ade00f 1341
fffd0934
JB
1342 if (!rdev->ops->add_key) {
1343 err = -EOPNOTSUPP;
25e47c18
JB
1344 goto out;
1345 }
1346
fffd0934
JB
1347 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1348 err = -EINVAL;
41ade00f
JB
1349 goto out;
1350 }
1351
fffd0934
JB
1352 wdev_lock(dev->ieee80211_ptr);
1353 err = nl80211_key_allowed(dev->ieee80211_ptr);
1354 if (!err)
1355 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1356 mac_addr, &key.p);
1357 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1358
1359 out:
79c97e97 1360 cfg80211_unlock_rdev(rdev);
41ade00f 1361 dev_put(dev);
3b85875a
JB
1362 unlock_rtnl:
1363 rtnl_unlock();
1364
41ade00f
JB
1365 return err;
1366}
1367
1368static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1369{
79c97e97 1370 struct cfg80211_registered_device *rdev;
41ade00f
JB
1371 int err;
1372 struct net_device *dev;
41ade00f 1373 u8 *mac_addr = NULL;
b9454e83 1374 struct key_parse key;
41ade00f 1375
b9454e83
JB
1376 err = nl80211_parse_key(info, &key);
1377 if (err)
1378 return err;
41ade00f
JB
1379
1380 if (info->attrs[NL80211_ATTR_MAC])
1381 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1382
3b85875a
JB
1383 rtnl_lock();
1384
463d0183 1385 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1386 if (err)
3b85875a 1387 goto unlock_rtnl;
41ade00f 1388
79c97e97 1389 if (!rdev->ops->del_key) {
41ade00f
JB
1390 err = -EOPNOTSUPP;
1391 goto out;
1392 }
1393
fffd0934
JB
1394 wdev_lock(dev->ieee80211_ptr);
1395 err = nl80211_key_allowed(dev->ieee80211_ptr);
1396 if (!err)
1397 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1398
3d23e349 1399#ifdef CONFIG_CFG80211_WEXT
08645126 1400 if (!err) {
b9454e83 1401 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1402 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1403 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1404 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1405 }
1406#endif
fffd0934 1407 wdev_unlock(dev->ieee80211_ptr);
08645126 1408
41ade00f 1409 out:
79c97e97 1410 cfg80211_unlock_rdev(rdev);
41ade00f 1411 dev_put(dev);
3b85875a
JB
1412
1413 unlock_rtnl:
1414 rtnl_unlock();
1415
41ade00f
JB
1416 return err;
1417}
1418
ed1b6cc7
JB
1419static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1420{
1421 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1422 struct beacon_parameters *info);
79c97e97 1423 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1424 int err;
1425 struct net_device *dev;
1426 struct beacon_parameters params;
1427 int haveinfo = 0;
1428
f4a11bb0
JB
1429 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1430 return -EINVAL;
1431
3b85875a
JB
1432 rtnl_lock();
1433
463d0183 1434 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1435 if (err)
3b85875a 1436 goto unlock_rtnl;
ed1b6cc7 1437
eec60b03
JM
1438 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1439 err = -EOPNOTSUPP;
1440 goto out;
1441 }
1442
ed1b6cc7
JB
1443 switch (info->genlhdr->cmd) {
1444 case NL80211_CMD_NEW_BEACON:
1445 /* these are required for NEW_BEACON */
1446 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1447 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1448 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1449 err = -EINVAL;
1450 goto out;
1451 }
1452
79c97e97 1453 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1454 break;
1455 case NL80211_CMD_SET_BEACON:
79c97e97 1456 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1457 break;
1458 default:
1459 WARN_ON(1);
1460 err = -EOPNOTSUPP;
1461 goto out;
1462 }
1463
1464 if (!call) {
1465 err = -EOPNOTSUPP;
1466 goto out;
1467 }
1468
1469 memset(&params, 0, sizeof(params));
1470
1471 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1472 params.interval =
1473 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1474 haveinfo = 1;
1475 }
1476
1477 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1478 params.dtim_period =
1479 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1480 haveinfo = 1;
1481 }
1482
1483 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1484 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1485 params.head_len =
1486 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1487 haveinfo = 1;
1488 }
1489
1490 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1491 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1492 params.tail_len =
1493 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1494 haveinfo = 1;
1495 }
1496
1497 if (!haveinfo) {
1498 err = -EINVAL;
1499 goto out;
1500 }
1501
79c97e97 1502 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1503
1504 out:
79c97e97 1505 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1506 dev_put(dev);
3b85875a
JB
1507 unlock_rtnl:
1508 rtnl_unlock();
1509
ed1b6cc7
JB
1510 return err;
1511}
1512
1513static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1514{
79c97e97 1515 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1516 int err;
1517 struct net_device *dev;
1518
3b85875a
JB
1519 rtnl_lock();
1520
463d0183 1521 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1522 if (err)
3b85875a 1523 goto unlock_rtnl;
ed1b6cc7 1524
79c97e97 1525 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1526 err = -EOPNOTSUPP;
1527 goto out;
1528 }
1529
eec60b03
JM
1530 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1531 err = -EOPNOTSUPP;
1532 goto out;
1533 }
79c97e97 1534 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1535
1536 out:
79c97e97 1537 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1538 dev_put(dev);
3b85875a
JB
1539 unlock_rtnl:
1540 rtnl_unlock();
1541
ed1b6cc7
JB
1542 return err;
1543}
1544
5727ef1b
JB
1545static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1546 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1547 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1548 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1549 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1550};
1551
eccb8e8f
JB
1552static int parse_station_flags(struct genl_info *info,
1553 struct station_parameters *params)
5727ef1b
JB
1554{
1555 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1556 struct nlattr *nla;
5727ef1b
JB
1557 int flag;
1558
eccb8e8f
JB
1559 /*
1560 * Try parsing the new attribute first so userspace
1561 * can specify both for older kernels.
1562 */
1563 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1564 if (nla) {
1565 struct nl80211_sta_flag_update *sta_flags;
1566
1567 sta_flags = nla_data(nla);
1568 params->sta_flags_mask = sta_flags->mask;
1569 params->sta_flags_set = sta_flags->set;
1570 if ((params->sta_flags_mask |
1571 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1572 return -EINVAL;
1573 return 0;
1574 }
1575
1576 /* if present, parse the old attribute */
5727ef1b 1577
eccb8e8f 1578 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1579 if (!nla)
1580 return 0;
1581
1582 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1583 nla, sta_flags_policy))
1584 return -EINVAL;
1585
eccb8e8f
JB
1586 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1587 params->sta_flags_mask &= ~1;
5727ef1b
JB
1588
1589 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1590 if (flags[flag])
eccb8e8f 1591 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1592
1593 return 0;
1594}
1595
420e7fab
HR
1596static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1597{
1598 int modulation, streams, bitrate;
1599
1600 if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1601 return rate->legacy;
1602
1603 /* the formula below does only work for MCS values smaller than 32 */
1604 if (rate->mcs >= 32)
1605 return 0;
1606
1607 modulation = rate->mcs & 7;
1608 streams = (rate->mcs >> 3) + 1;
1609
1610 bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1611 13500000 : 6500000;
1612
1613 if (modulation < 4)
1614 bitrate *= (modulation + 1);
1615 else if (modulation == 4)
1616 bitrate *= (modulation + 2);
1617 else
1618 bitrate *= (modulation + 3);
1619
1620 bitrate *= streams;
1621
1622 if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1623 bitrate = (bitrate / 9) * 10;
1624
1625 /* do NOT round down here */
1626 return (bitrate + 50000) / 100000;
1627}
1628
fd5b74dc
JB
1629static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1630 int flags, struct net_device *dev,
2ec600d6 1631 u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1632{
1633 void *hdr;
420e7fab
HR
1634 struct nlattr *sinfoattr, *txrate;
1635 u16 bitrate;
fd5b74dc
JB
1636
1637 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1638 if (!hdr)
1639 return -1;
1640
1641 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1642 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1643
f5ea9120
JB
1644 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1645
2ec600d6
LCC
1646 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1647 if (!sinfoattr)
fd5b74dc 1648 goto nla_put_failure;
2ec600d6
LCC
1649 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1650 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1651 sinfo->inactive_time);
1652 if (sinfo->filled & STATION_INFO_RX_BYTES)
1653 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1654 sinfo->rx_bytes);
1655 if (sinfo->filled & STATION_INFO_TX_BYTES)
1656 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1657 sinfo->tx_bytes);
1658 if (sinfo->filled & STATION_INFO_LLID)
1659 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1660 sinfo->llid);
1661 if (sinfo->filled & STATION_INFO_PLID)
1662 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1663 sinfo->plid);
1664 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1665 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1666 sinfo->plink_state);
420e7fab
HR
1667 if (sinfo->filled & STATION_INFO_SIGNAL)
1668 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1669 sinfo->signal);
1670 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1671 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1672 if (!txrate)
1673 goto nla_put_failure;
1674
1675 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1676 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1677 if (bitrate > 0)
1678 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1679
420e7fab
HR
1680 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1681 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1682 sinfo->txrate.mcs);
1683 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1684 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1685 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1686 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1687
1688 nla_nest_end(msg, txrate);
1689 }
98c8a60a
JM
1690 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1691 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1692 sinfo->rx_packets);
1693 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1694 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1695 sinfo->tx_packets);
2ec600d6 1696 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1697
1698 return genlmsg_end(msg, hdr);
1699
1700 nla_put_failure:
bc3ed28c
TG
1701 genlmsg_cancel(msg, hdr);
1702 return -EMSGSIZE;
fd5b74dc
JB
1703}
1704
2ec600d6 1705static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1706 struct netlink_callback *cb)
2ec600d6 1707{
2ec600d6
LCC
1708 struct station_info sinfo;
1709 struct cfg80211_registered_device *dev;
bba95fef 1710 struct net_device *netdev;
2ec600d6 1711 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1712 int ifidx = cb->args[0];
1713 int sta_idx = cb->args[1];
2ec600d6 1714 int err;
2ec600d6 1715
a043897a
HS
1716 if (!ifidx)
1717 ifidx = nl80211_get_ifidx(cb);
1718 if (ifidx < 0)
1719 return ifidx;
2ec600d6 1720
3b85875a
JB
1721 rtnl_lock();
1722
463d0183 1723 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1724 if (!netdev) {
1725 err = -ENODEV;
1726 goto out_rtnl;
1727 }
2ec600d6 1728
463d0183 1729 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1730 if (IS_ERR(dev)) {
1731 err = PTR_ERR(dev);
3b85875a 1732 goto out_rtnl;
bba95fef
JB
1733 }
1734
1735 if (!dev->ops->dump_station) {
eec60b03 1736 err = -EOPNOTSUPP;
bba95fef
JB
1737 goto out_err;
1738 }
1739
bba95fef
JB
1740 while (1) {
1741 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1742 mac_addr, &sinfo);
1743 if (err == -ENOENT)
1744 break;
1745 if (err)
3b85875a 1746 goto out_err;
bba95fef
JB
1747
1748 if (nl80211_send_station(skb,
1749 NETLINK_CB(cb->skb).pid,
1750 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1751 netdev, mac_addr,
1752 &sinfo) < 0)
1753 goto out;
1754
1755 sta_idx++;
1756 }
1757
1758
1759 out:
1760 cb->args[1] = sta_idx;
1761 err = skb->len;
bba95fef 1762 out_err:
4d0c8aea 1763 cfg80211_unlock_rdev(dev);
3b85875a
JB
1764 out_rtnl:
1765 rtnl_unlock();
bba95fef
JB
1766
1767 return err;
2ec600d6 1768}
fd5b74dc 1769
5727ef1b
JB
1770static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1771{
79c97e97 1772 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1773 int err;
1774 struct net_device *dev;
2ec600d6 1775 struct station_info sinfo;
fd5b74dc
JB
1776 struct sk_buff *msg;
1777 u8 *mac_addr = NULL;
1778
2ec600d6 1779 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1780
1781 if (!info->attrs[NL80211_ATTR_MAC])
1782 return -EINVAL;
1783
1784 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1785
3b85875a
JB
1786 rtnl_lock();
1787
463d0183 1788 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 1789 if (err)
3b85875a 1790 goto out_rtnl;
fd5b74dc 1791
79c97e97 1792 if (!rdev->ops->get_station) {
fd5b74dc
JB
1793 err = -EOPNOTSUPP;
1794 goto out;
1795 }
1796
79c97e97 1797 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1798 if (err)
1799 goto out;
1800
fd2120ca 1801 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1802 if (!msg)
1803 goto out;
1804
1805 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1806 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1807 goto out_free;
1808
134e6375 1809 err = genlmsg_reply(msg, info);
fd5b74dc
JB
1810 goto out;
1811
1812 out_free:
1813 nlmsg_free(msg);
fd5b74dc 1814 out:
79c97e97 1815 cfg80211_unlock_rdev(rdev);
fd5b74dc 1816 dev_put(dev);
3b85875a
JB
1817 out_rtnl:
1818 rtnl_unlock();
1819
fd5b74dc 1820 return err;
5727ef1b
JB
1821}
1822
1823/*
1824 * Get vlan interface making sure it is on the right wiphy.
1825 */
463d0183 1826static int get_vlan(struct genl_info *info,
5727ef1b
JB
1827 struct cfg80211_registered_device *rdev,
1828 struct net_device **vlan)
1829{
463d0183 1830 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
1831 *vlan = NULL;
1832
1833 if (vlanattr) {
463d0183
JB
1834 *vlan = dev_get_by_index(genl_info_net(info),
1835 nla_get_u32(vlanattr));
5727ef1b
JB
1836 if (!*vlan)
1837 return -ENODEV;
1838 if (!(*vlan)->ieee80211_ptr)
1839 return -EINVAL;
1840 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1841 return -EINVAL;
1842 }
1843 return 0;
1844}
1845
1846static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1847{
79c97e97 1848 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1849 int err;
1850 struct net_device *dev;
1851 struct station_parameters params;
1852 u8 *mac_addr = NULL;
1853
1854 memset(&params, 0, sizeof(params));
1855
1856 params.listen_interval = -1;
1857
1858 if (info->attrs[NL80211_ATTR_STA_AID])
1859 return -EINVAL;
1860
1861 if (!info->attrs[NL80211_ATTR_MAC])
1862 return -EINVAL;
1863
1864 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1865
1866 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1867 params.supported_rates =
1868 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1869 params.supported_rates_len =
1870 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1871 }
1872
1873 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1874 params.listen_interval =
1875 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1876
36aedc90
JM
1877 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1878 params.ht_capa =
1879 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1880
eccb8e8f 1881 if (parse_station_flags(info, &params))
5727ef1b
JB
1882 return -EINVAL;
1883
2ec600d6
LCC
1884 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1885 params.plink_action =
1886 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1887
3b85875a
JB
1888 rtnl_lock();
1889
463d0183 1890 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 1891 if (err)
3b85875a 1892 goto out_rtnl;
5727ef1b 1893
463d0183 1894 err = get_vlan(info, rdev, &params.vlan);
a97f4424 1895 if (err)
034d655e 1896 goto out;
a97f4424
JB
1897
1898 /* validate settings */
1899 err = 0;
1900
1901 switch (dev->ieee80211_ptr->iftype) {
1902 case NL80211_IFTYPE_AP:
1903 case NL80211_IFTYPE_AP_VLAN:
1904 /* disallow mesh-specific things */
1905 if (params.plink_action)
1906 err = -EINVAL;
1907 break;
1908 case NL80211_IFTYPE_STATION:
1909 /* disallow everything but AUTHORIZED flag */
1910 if (params.plink_action)
1911 err = -EINVAL;
1912 if (params.vlan)
1913 err = -EINVAL;
1914 if (params.supported_rates)
1915 err = -EINVAL;
1916 if (params.ht_capa)
1917 err = -EINVAL;
1918 if (params.listen_interval >= 0)
1919 err = -EINVAL;
1920 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1921 err = -EINVAL;
1922 break;
1923 case NL80211_IFTYPE_MESH_POINT:
1924 /* disallow things mesh doesn't support */
1925 if (params.vlan)
1926 err = -EINVAL;
1927 if (params.ht_capa)
1928 err = -EINVAL;
1929 if (params.listen_interval >= 0)
1930 err = -EINVAL;
1931 if (params.supported_rates)
1932 err = -EINVAL;
1933 if (params.sta_flags_mask)
1934 err = -EINVAL;
1935 break;
1936 default:
1937 err = -EINVAL;
034d655e
JB
1938 }
1939
5727ef1b
JB
1940 if (err)
1941 goto out;
1942
79c97e97 1943 if (!rdev->ops->change_station) {
5727ef1b
JB
1944 err = -EOPNOTSUPP;
1945 goto out;
1946 }
1947
79c97e97 1948 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
1949
1950 out:
1951 if (params.vlan)
1952 dev_put(params.vlan);
79c97e97 1953 cfg80211_unlock_rdev(rdev);
5727ef1b 1954 dev_put(dev);
3b85875a
JB
1955 out_rtnl:
1956 rtnl_unlock();
1957
5727ef1b
JB
1958 return err;
1959}
1960
1961static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1962{
79c97e97 1963 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1964 int err;
1965 struct net_device *dev;
1966 struct station_parameters params;
1967 u8 *mac_addr = NULL;
1968
1969 memset(&params, 0, sizeof(params));
1970
1971 if (!info->attrs[NL80211_ATTR_MAC])
1972 return -EINVAL;
1973
5727ef1b
JB
1974 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1975 return -EINVAL;
1976
1977 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1978 return -EINVAL;
1979
1980 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1981 params.supported_rates =
1982 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1983 params.supported_rates_len =
1984 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1985 params.listen_interval =
1986 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 1987
a97f4424
JB
1988 if (info->attrs[NL80211_ATTR_STA_AID]) {
1989 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1990 if (!params.aid || params.aid > IEEE80211_MAX_AID)
1991 return -EINVAL;
1992 }
51b50fbe 1993
36aedc90
JM
1994 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1995 params.ht_capa =
1996 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 1997
eccb8e8f 1998 if (parse_station_flags(info, &params))
5727ef1b
JB
1999 return -EINVAL;
2000
3b85875a
JB
2001 rtnl_lock();
2002
463d0183 2003 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2004 if (err)
3b85875a 2005 goto out_rtnl;
5727ef1b 2006
463d0183 2007 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2008 if (err)
e80cf853 2009 goto out;
a97f4424
JB
2010
2011 /* validate settings */
2012 err = 0;
2013
2014 switch (dev->ieee80211_ptr->iftype) {
2015 case NL80211_IFTYPE_AP:
2016 case NL80211_IFTYPE_AP_VLAN:
2017 /* all ok but must have AID */
2018 if (!params.aid)
2019 err = -EINVAL;
2020 break;
2021 case NL80211_IFTYPE_MESH_POINT:
2022 /* disallow things mesh doesn't support */
2023 if (params.vlan)
2024 err = -EINVAL;
2025 if (params.aid)
2026 err = -EINVAL;
2027 if (params.ht_capa)
2028 err = -EINVAL;
2029 if (params.listen_interval >= 0)
2030 err = -EINVAL;
2031 if (params.supported_rates)
2032 err = -EINVAL;
2033 if (params.sta_flags_mask)
2034 err = -EINVAL;
2035 break;
2036 default:
2037 err = -EINVAL;
e80cf853
JB
2038 }
2039
5727ef1b
JB
2040 if (err)
2041 goto out;
2042
79c97e97 2043 if (!rdev->ops->add_station) {
5727ef1b
JB
2044 err = -EOPNOTSUPP;
2045 goto out;
2046 }
2047
35a8efe1
JM
2048 if (!netif_running(dev)) {
2049 err = -ENETDOWN;
2050 goto out;
2051 }
2052
79c97e97 2053 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2054
2055 out:
2056 if (params.vlan)
2057 dev_put(params.vlan);
79c97e97 2058 cfg80211_unlock_rdev(rdev);
5727ef1b 2059 dev_put(dev);
3b85875a
JB
2060 out_rtnl:
2061 rtnl_unlock();
2062
5727ef1b
JB
2063 return err;
2064}
2065
2066static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2067{
79c97e97 2068 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2069 int err;
2070 struct net_device *dev;
2071 u8 *mac_addr = NULL;
2072
2073 if (info->attrs[NL80211_ATTR_MAC])
2074 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2075
3b85875a
JB
2076 rtnl_lock();
2077
463d0183 2078 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2079 if (err)
3b85875a 2080 goto out_rtnl;
5727ef1b 2081
e80cf853 2082 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
155cc9e4
AY
2083 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2084 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2085 err = -EINVAL;
2086 goto out;
2087 }
2088
79c97e97 2089 if (!rdev->ops->del_station) {
5727ef1b
JB
2090 err = -EOPNOTSUPP;
2091 goto out;
2092 }
2093
79c97e97 2094 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2095
2096 out:
79c97e97 2097 cfg80211_unlock_rdev(rdev);
5727ef1b 2098 dev_put(dev);
3b85875a
JB
2099 out_rtnl:
2100 rtnl_unlock();
2101
5727ef1b
JB
2102 return err;
2103}
2104
2ec600d6
LCC
2105static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2106 int flags, struct net_device *dev,
2107 u8 *dst, u8 *next_hop,
2108 struct mpath_info *pinfo)
2109{
2110 void *hdr;
2111 struct nlattr *pinfoattr;
2112
2113 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2114 if (!hdr)
2115 return -1;
2116
2117 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2118 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2119 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2120
f5ea9120
JB
2121 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2122
2ec600d6
LCC
2123 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2124 if (!pinfoattr)
2125 goto nla_put_failure;
2126 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2127 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2128 pinfo->frame_qlen);
d19b3bf6
RP
2129 if (pinfo->filled & MPATH_INFO_SN)
2130 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2131 pinfo->sn);
2ec600d6
LCC
2132 if (pinfo->filled & MPATH_INFO_METRIC)
2133 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2134 pinfo->metric);
2135 if (pinfo->filled & MPATH_INFO_EXPTIME)
2136 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2137 pinfo->exptime);
2138 if (pinfo->filled & MPATH_INFO_FLAGS)
2139 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2140 pinfo->flags);
2141 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2142 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2143 pinfo->discovery_timeout);
2144 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2145 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2146 pinfo->discovery_retries);
2147
2148 nla_nest_end(msg, pinfoattr);
2149
2150 return genlmsg_end(msg, hdr);
2151
2152 nla_put_failure:
bc3ed28c
TG
2153 genlmsg_cancel(msg, hdr);
2154 return -EMSGSIZE;
2ec600d6
LCC
2155}
2156
2157static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2158 struct netlink_callback *cb)
2ec600d6 2159{
2ec600d6
LCC
2160 struct mpath_info pinfo;
2161 struct cfg80211_registered_device *dev;
bba95fef 2162 struct net_device *netdev;
2ec600d6
LCC
2163 u8 dst[ETH_ALEN];
2164 u8 next_hop[ETH_ALEN];
bba95fef
JB
2165 int ifidx = cb->args[0];
2166 int path_idx = cb->args[1];
2ec600d6 2167 int err;
2ec600d6 2168
a043897a
HS
2169 if (!ifidx)
2170 ifidx = nl80211_get_ifidx(cb);
2171 if (ifidx < 0)
2172 return ifidx;
bba95fef 2173
3b85875a
JB
2174 rtnl_lock();
2175
463d0183 2176 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2177 if (!netdev) {
2178 err = -ENODEV;
2179 goto out_rtnl;
2180 }
bba95fef 2181
463d0183 2182 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2183 if (IS_ERR(dev)) {
2184 err = PTR_ERR(dev);
3b85875a 2185 goto out_rtnl;
bba95fef
JB
2186 }
2187
2188 if (!dev->ops->dump_mpath) {
eec60b03 2189 err = -EOPNOTSUPP;
bba95fef
JB
2190 goto out_err;
2191 }
2192
eec60b03
JM
2193 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2194 err = -EOPNOTSUPP;
0448b5fc 2195 goto out_err;
eec60b03
JM
2196 }
2197
bba95fef
JB
2198 while (1) {
2199 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2200 dst, next_hop, &pinfo);
2201 if (err == -ENOENT)
2ec600d6 2202 break;
bba95fef 2203 if (err)
3b85875a 2204 goto out_err;
2ec600d6 2205
bba95fef
JB
2206 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2207 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2208 netdev, dst, next_hop,
2209 &pinfo) < 0)
2210 goto out;
2ec600d6 2211
bba95fef 2212 path_idx++;
2ec600d6 2213 }
2ec600d6 2214
2ec600d6 2215
bba95fef
JB
2216 out:
2217 cb->args[1] = path_idx;
2218 err = skb->len;
bba95fef 2219 out_err:
4d0c8aea 2220 cfg80211_unlock_rdev(dev);
3b85875a
JB
2221 out_rtnl:
2222 rtnl_unlock();
bba95fef
JB
2223
2224 return err;
2ec600d6
LCC
2225}
2226
2227static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2228{
79c97e97 2229 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2230 int err;
2231 struct net_device *dev;
2232 struct mpath_info pinfo;
2233 struct sk_buff *msg;
2234 u8 *dst = NULL;
2235 u8 next_hop[ETH_ALEN];
2236
2237 memset(&pinfo, 0, sizeof(pinfo));
2238
2239 if (!info->attrs[NL80211_ATTR_MAC])
2240 return -EINVAL;
2241
2242 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2243
3b85875a
JB
2244 rtnl_lock();
2245
463d0183 2246 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2247 if (err)
3b85875a 2248 goto out_rtnl;
2ec600d6 2249
79c97e97 2250 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2251 err = -EOPNOTSUPP;
2252 goto out;
2253 }
2254
eec60b03
JM
2255 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2256 err = -EOPNOTSUPP;
2257 goto out;
2258 }
2259
79c97e97 2260 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2261 if (err)
2262 goto out;
2263
fd2120ca 2264 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2265 if (!msg)
2266 goto out;
2267
2268 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2269 dev, dst, next_hop, &pinfo) < 0)
2270 goto out_free;
2271
134e6375 2272 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2273 goto out;
2274
2275 out_free:
2276 nlmsg_free(msg);
2ec600d6 2277 out:
79c97e97 2278 cfg80211_unlock_rdev(rdev);
2ec600d6 2279 dev_put(dev);
3b85875a
JB
2280 out_rtnl:
2281 rtnl_unlock();
2282
2ec600d6
LCC
2283 return err;
2284}
2285
2286static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2287{
79c97e97 2288 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2289 int err;
2290 struct net_device *dev;
2291 u8 *dst = NULL;
2292 u8 *next_hop = NULL;
2293
2294 if (!info->attrs[NL80211_ATTR_MAC])
2295 return -EINVAL;
2296
2297 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2298 return -EINVAL;
2299
2300 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2301 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2302
3b85875a
JB
2303 rtnl_lock();
2304
463d0183 2305 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2306 if (err)
3b85875a 2307 goto out_rtnl;
2ec600d6 2308
79c97e97 2309 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2310 err = -EOPNOTSUPP;
2311 goto out;
2312 }
2313
eec60b03
JM
2314 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2315 err = -EOPNOTSUPP;
2316 goto out;
2317 }
2318
35a8efe1
JM
2319 if (!netif_running(dev)) {
2320 err = -ENETDOWN;
2321 goto out;
2322 }
2323
79c97e97 2324 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2325
2326 out:
79c97e97 2327 cfg80211_unlock_rdev(rdev);
2ec600d6 2328 dev_put(dev);
3b85875a
JB
2329 out_rtnl:
2330 rtnl_unlock();
2331
2ec600d6
LCC
2332 return err;
2333}
2334static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2335{
79c97e97 2336 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2337 int err;
2338 struct net_device *dev;
2339 u8 *dst = NULL;
2340 u8 *next_hop = NULL;
2341
2342 if (!info->attrs[NL80211_ATTR_MAC])
2343 return -EINVAL;
2344
2345 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2346 return -EINVAL;
2347
2348 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2349 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2350
3b85875a
JB
2351 rtnl_lock();
2352
463d0183 2353 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2354 if (err)
3b85875a 2355 goto out_rtnl;
2ec600d6 2356
79c97e97 2357 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2358 err = -EOPNOTSUPP;
2359 goto out;
2360 }
2361
eec60b03
JM
2362 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2363 err = -EOPNOTSUPP;
2364 goto out;
2365 }
2366
35a8efe1
JM
2367 if (!netif_running(dev)) {
2368 err = -ENETDOWN;
2369 goto out;
2370 }
2371
79c97e97 2372 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2373
2374 out:
79c97e97 2375 cfg80211_unlock_rdev(rdev);
2ec600d6 2376 dev_put(dev);
3b85875a
JB
2377 out_rtnl:
2378 rtnl_unlock();
2379
2ec600d6
LCC
2380 return err;
2381}
2382
2383static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2384{
79c97e97 2385 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2386 int err;
2387 struct net_device *dev;
2388 u8 *dst = NULL;
2389
2390 if (info->attrs[NL80211_ATTR_MAC])
2391 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2392
3b85875a
JB
2393 rtnl_lock();
2394
463d0183 2395 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2396 if (err)
3b85875a 2397 goto out_rtnl;
2ec600d6 2398
79c97e97 2399 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2400 err = -EOPNOTSUPP;
2401 goto out;
2402 }
2403
79c97e97 2404 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2405
2406 out:
79c97e97 2407 cfg80211_unlock_rdev(rdev);
2ec600d6 2408 dev_put(dev);
3b85875a
JB
2409 out_rtnl:
2410 rtnl_unlock();
2411
2ec600d6
LCC
2412 return err;
2413}
2414
9f1ba906
JM
2415static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2416{
79c97e97 2417 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2418 int err;
2419 struct net_device *dev;
2420 struct bss_parameters params;
2421
2422 memset(&params, 0, sizeof(params));
2423 /* default to not changing parameters */
2424 params.use_cts_prot = -1;
2425 params.use_short_preamble = -1;
2426 params.use_short_slot_time = -1;
2427
2428 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2429 params.use_cts_prot =
2430 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2431 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2432 params.use_short_preamble =
2433 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2434 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2435 params.use_short_slot_time =
2436 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2437 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2438 params.basic_rates =
2439 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2440 params.basic_rates_len =
2441 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2442 }
9f1ba906 2443
3b85875a
JB
2444 rtnl_lock();
2445
463d0183 2446 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2447 if (err)
3b85875a 2448 goto out_rtnl;
9f1ba906 2449
79c97e97 2450 if (!rdev->ops->change_bss) {
9f1ba906
JM
2451 err = -EOPNOTSUPP;
2452 goto out;
2453 }
2454
eec60b03
JM
2455 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2456 err = -EOPNOTSUPP;
2457 goto out;
2458 }
2459
79c97e97 2460 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2461
2462 out:
79c97e97 2463 cfg80211_unlock_rdev(rdev);
9f1ba906 2464 dev_put(dev);
3b85875a
JB
2465 out_rtnl:
2466 rtnl_unlock();
2467
9f1ba906
JM
2468 return err;
2469}
2470
b2e1b302
LR
2471static const struct nla_policy
2472 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2473 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2474 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2475 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2476 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2477 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2478 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2479};
2480
2481static int parse_reg_rule(struct nlattr *tb[],
2482 struct ieee80211_reg_rule *reg_rule)
2483{
2484 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2485 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2486
2487 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2488 return -EINVAL;
2489 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2490 return -EINVAL;
2491 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2492 return -EINVAL;
2493 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2494 return -EINVAL;
2495 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2496 return -EINVAL;
2497
2498 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2499
2500 freq_range->start_freq_khz =
2501 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2502 freq_range->end_freq_khz =
2503 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2504 freq_range->max_bandwidth_khz =
2505 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2506
2507 power_rule->max_eirp =
2508 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2509
2510 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2511 power_rule->max_antenna_gain =
2512 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2513
2514 return 0;
2515}
2516
2517static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2518{
2519 int r;
2520 char *data = NULL;
2521
80778f18
LR
2522 /*
2523 * You should only get this when cfg80211 hasn't yet initialized
2524 * completely when built-in to the kernel right between the time
2525 * window between nl80211_init() and regulatory_init(), if that is
2526 * even possible.
2527 */
2528 mutex_lock(&cfg80211_mutex);
2529 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2530 mutex_unlock(&cfg80211_mutex);
2531 return -EINPROGRESS;
80778f18 2532 }
fe33eb39 2533 mutex_unlock(&cfg80211_mutex);
80778f18 2534
fe33eb39
LR
2535 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2536 return -EINVAL;
b2e1b302
LR
2537
2538 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2539
2540#ifdef CONFIG_WIRELESS_OLD_REGULATORY
2541 /* We ignore world regdom requests with the old regdom setup */
fe33eb39
LR
2542 if (is_world_regdom(data))
2543 return -EINVAL;
b2e1b302 2544#endif
fe33eb39
LR
2545
2546 r = regulatory_hint_user(data);
2547
b2e1b302
LR
2548 return r;
2549}
2550
93da9cc1 2551static int nl80211_get_mesh_params(struct sk_buff *skb,
2552 struct genl_info *info)
2553{
79c97e97 2554 struct cfg80211_registered_device *rdev;
93da9cc1 2555 struct mesh_config cur_params;
2556 int err;
2557 struct net_device *dev;
2558 void *hdr;
2559 struct nlattr *pinfoattr;
2560 struct sk_buff *msg;
2561
3b85875a
JB
2562 rtnl_lock();
2563
93da9cc1 2564 /* Look up our device */
463d0183 2565 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2566 if (err)
3b85875a 2567 goto out_rtnl;
93da9cc1 2568
79c97e97 2569 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2570 err = -EOPNOTSUPP;
2571 goto out;
2572 }
2573
93da9cc1 2574 /* Get the mesh params */
79c97e97 2575 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2576 if (err)
2577 goto out;
2578
2579 /* Draw up a netlink message to send back */
fd2120ca 2580 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2581 if (!msg) {
2582 err = -ENOBUFS;
2583 goto out;
2584 }
2585 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2586 NL80211_CMD_GET_MESH_PARAMS);
2587 if (!hdr)
2588 goto nla_put_failure;
2589 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2590 if (!pinfoattr)
2591 goto nla_put_failure;
2592 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2593 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2594 cur_params.dot11MeshRetryTimeout);
2595 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2596 cur_params.dot11MeshConfirmTimeout);
2597 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2598 cur_params.dot11MeshHoldingTimeout);
2599 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2600 cur_params.dot11MeshMaxPeerLinks);
2601 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2602 cur_params.dot11MeshMaxRetries);
2603 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2604 cur_params.dot11MeshTTL);
2605 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2606 cur_params.auto_open_plinks);
2607 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2608 cur_params.dot11MeshHWMPmaxPREQretries);
2609 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2610 cur_params.path_refresh_time);
2611 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2612 cur_params.min_discovery_timeout);
2613 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2614 cur_params.dot11MeshHWMPactivePathTimeout);
2615 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2616 cur_params.dot11MeshHWMPpreqMinInterval);
2617 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2618 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2619 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2620 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2621 nla_nest_end(msg, pinfoattr);
2622 genlmsg_end(msg, hdr);
134e6375 2623 err = genlmsg_reply(msg, info);
93da9cc1 2624 goto out;
2625
3b85875a 2626 nla_put_failure:
93da9cc1 2627 genlmsg_cancel(msg, hdr);
2628 err = -EMSGSIZE;
3b85875a 2629 out:
93da9cc1 2630 /* Cleanup */
79c97e97 2631 cfg80211_unlock_rdev(rdev);
93da9cc1 2632 dev_put(dev);
3b85875a
JB
2633 out_rtnl:
2634 rtnl_unlock();
2635
93da9cc1 2636 return err;
2637}
2638
2639#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2640do {\
2641 if (table[attr_num]) {\
2642 cfg.param = nla_fn(table[attr_num]); \
2643 mask |= (1 << (attr_num - 1)); \
2644 } \
2645} while (0);\
2646
2647static struct nla_policy
2648nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2649 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2650 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2651 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2652 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2653 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2654 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2655 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2656
2657 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2658 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2659 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2660 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2661 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2662 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2663};
2664
2665static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2666{
2667 int err;
2668 u32 mask;
79c97e97 2669 struct cfg80211_registered_device *rdev;
93da9cc1 2670 struct net_device *dev;
2671 struct mesh_config cfg;
2672 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2673 struct nlattr *parent_attr;
2674
2675 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2676 if (!parent_attr)
2677 return -EINVAL;
2678 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2679 parent_attr, nl80211_meshconf_params_policy))
2680 return -EINVAL;
2681
3b85875a
JB
2682 rtnl_lock();
2683
463d0183 2684 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2685 if (err)
3b85875a 2686 goto out_rtnl;
93da9cc1 2687
79c97e97 2688 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2689 err = -EOPNOTSUPP;
2690 goto out;
2691 }
2692
93da9cc1 2693 /* This makes sure that there aren't more than 32 mesh config
2694 * parameters (otherwise our bitfield scheme would not work.) */
2695 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2696
2697 /* Fill in the params struct */
2698 mask = 0;
2699 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2700 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2701 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2702 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2703 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2704 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2705 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2706 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2707 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2708 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2709 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2710 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2711 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2712 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2713 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2714 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2715 nla_get_u8);
2716 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2717 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2718 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2719 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2720 nla_get_u16);
2721 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2722 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2723 nla_get_u32);
2724 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2725 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2726 nla_get_u16);
2727 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2728 dot11MeshHWMPnetDiameterTraversalTime,
2729 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2730 nla_get_u16);
63c5723b
RP
2731 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2732 dot11MeshHWMPRootMode, mask,
2733 NL80211_MESHCONF_HWMP_ROOTMODE,
2734 nla_get_u8);
93da9cc1 2735
2736 /* Apply changes */
79c97e97 2737 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2738
f3f92586 2739 out:
93da9cc1 2740 /* cleanup */
79c97e97 2741 cfg80211_unlock_rdev(rdev);
93da9cc1 2742 dev_put(dev);
3b85875a
JB
2743 out_rtnl:
2744 rtnl_unlock();
2745
93da9cc1 2746 return err;
2747}
2748
2749#undef FILL_IN_MESH_PARAM_IF_SET
2750
f130347c
LR
2751static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2752{
2753 struct sk_buff *msg;
2754 void *hdr = NULL;
2755 struct nlattr *nl_reg_rules;
2756 unsigned int i;
2757 int err = -EINVAL;
2758
a1794390 2759 mutex_lock(&cfg80211_mutex);
f130347c
LR
2760
2761 if (!cfg80211_regdomain)
2762 goto out;
2763
fd2120ca 2764 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2765 if (!msg) {
2766 err = -ENOBUFS;
2767 goto out;
2768 }
2769
2770 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2771 NL80211_CMD_GET_REG);
2772 if (!hdr)
2773 goto nla_put_failure;
2774
2775 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2776 cfg80211_regdomain->alpha2);
2777
2778 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2779 if (!nl_reg_rules)
2780 goto nla_put_failure;
2781
2782 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2783 struct nlattr *nl_reg_rule;
2784 const struct ieee80211_reg_rule *reg_rule;
2785 const struct ieee80211_freq_range *freq_range;
2786 const struct ieee80211_power_rule *power_rule;
2787
2788 reg_rule = &cfg80211_regdomain->reg_rules[i];
2789 freq_range = &reg_rule->freq_range;
2790 power_rule = &reg_rule->power_rule;
2791
2792 nl_reg_rule = nla_nest_start(msg, i);
2793 if (!nl_reg_rule)
2794 goto nla_put_failure;
2795
2796 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2797 reg_rule->flags);
2798 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2799 freq_range->start_freq_khz);
2800 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2801 freq_range->end_freq_khz);
2802 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2803 freq_range->max_bandwidth_khz);
2804 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2805 power_rule->max_antenna_gain);
2806 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2807 power_rule->max_eirp);
2808
2809 nla_nest_end(msg, nl_reg_rule);
2810 }
2811
2812 nla_nest_end(msg, nl_reg_rules);
2813
2814 genlmsg_end(msg, hdr);
134e6375 2815 err = genlmsg_reply(msg, info);
f130347c
LR
2816 goto out;
2817
2818nla_put_failure:
2819 genlmsg_cancel(msg, hdr);
2820 err = -EMSGSIZE;
2821out:
a1794390 2822 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2823 return err;
2824}
2825
b2e1b302
LR
2826static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2827{
2828 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2829 struct nlattr *nl_reg_rule;
2830 char *alpha2 = NULL;
2831 int rem_reg_rules = 0, r = 0;
2832 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2833 struct ieee80211_regdomain *rd = NULL;
2834
2835 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2836 return -EINVAL;
2837
2838 if (!info->attrs[NL80211_ATTR_REG_RULES])
2839 return -EINVAL;
2840
2841 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2842
2843 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2844 rem_reg_rules) {
2845 num_rules++;
2846 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2847 return -EINVAL;
b2e1b302
LR
2848 }
2849
61405e97
LR
2850 mutex_lock(&cfg80211_mutex);
2851
d0e18f83
LR
2852 if (!reg_is_valid_request(alpha2)) {
2853 r = -EINVAL;
2854 goto bad_reg;
2855 }
b2e1b302
LR
2856
2857 size_of_regd = sizeof(struct ieee80211_regdomain) +
2858 (num_rules * sizeof(struct ieee80211_reg_rule));
2859
2860 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2861 if (!rd) {
2862 r = -ENOMEM;
2863 goto bad_reg;
2864 }
b2e1b302
LR
2865
2866 rd->n_reg_rules = num_rules;
2867 rd->alpha2[0] = alpha2[0];
2868 rd->alpha2[1] = alpha2[1];
2869
2870 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2871 rem_reg_rules) {
2872 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2873 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2874 reg_rule_policy);
2875 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2876 if (r)
2877 goto bad_reg;
2878
2879 rule_idx++;
2880
d0e18f83
LR
2881 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2882 r = -EINVAL;
b2e1b302 2883 goto bad_reg;
d0e18f83 2884 }
b2e1b302
LR
2885 }
2886
2887 BUG_ON(rule_idx != num_rules);
2888
b2e1b302 2889 r = set_regdom(rd);
61405e97 2890
a1794390 2891 mutex_unlock(&cfg80211_mutex);
d0e18f83 2892
b2e1b302
LR
2893 return r;
2894
d2372b31 2895 bad_reg:
61405e97 2896 mutex_unlock(&cfg80211_mutex);
b2e1b302 2897 kfree(rd);
d0e18f83 2898 return r;
b2e1b302
LR
2899}
2900
83f5e2cf
JB
2901static int validate_scan_freqs(struct nlattr *freqs)
2902{
2903 struct nlattr *attr1, *attr2;
2904 int n_channels = 0, tmp1, tmp2;
2905
2906 nla_for_each_nested(attr1, freqs, tmp1) {
2907 n_channels++;
2908 /*
2909 * Some hardware has a limited channel list for
2910 * scanning, and it is pretty much nonsensical
2911 * to scan for a channel twice, so disallow that
2912 * and don't require drivers to check that the
2913 * channel list they get isn't longer than what
2914 * they can scan, as long as they can scan all
2915 * the channels they registered at once.
2916 */
2917 nla_for_each_nested(attr2, freqs, tmp2)
2918 if (attr1 != attr2 &&
2919 nla_get_u32(attr1) == nla_get_u32(attr2))
2920 return 0;
2921 }
2922
2923 return n_channels;
2924}
2925
2a519311
JB
2926static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2927{
79c97e97 2928 struct cfg80211_registered_device *rdev;
2a519311
JB
2929 struct net_device *dev;
2930 struct cfg80211_scan_request *request;
2931 struct cfg80211_ssid *ssid;
2932 struct ieee80211_channel *channel;
2933 struct nlattr *attr;
2934 struct wiphy *wiphy;
83f5e2cf 2935 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 2936 enum ieee80211_band band;
70692ad2 2937 size_t ie_len;
2a519311 2938
f4a11bb0
JB
2939 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2940 return -EINVAL;
2941
3b85875a
JB
2942 rtnl_lock();
2943
463d0183 2944 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 2945 if (err)
3b85875a 2946 goto out_rtnl;
2a519311 2947
79c97e97 2948 wiphy = &rdev->wiphy;
2a519311 2949
79c97e97 2950 if (!rdev->ops->scan) {
2a519311
JB
2951 err = -EOPNOTSUPP;
2952 goto out;
2953 }
2954
35a8efe1
JM
2955 if (!netif_running(dev)) {
2956 err = -ENETDOWN;
2957 goto out;
2958 }
2959
79c97e97 2960 if (rdev->scan_req) {
2a519311 2961 err = -EBUSY;
3b85875a 2962 goto out;
2a519311
JB
2963 }
2964
2965 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
2966 n_channels = validate_scan_freqs(
2967 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
2968 if (!n_channels) {
2969 err = -EINVAL;
3b85875a 2970 goto out;
2a519311
JB
2971 }
2972 } else {
83f5e2cf
JB
2973 n_channels = 0;
2974
2a519311
JB
2975 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2976 if (wiphy->bands[band])
2977 n_channels += wiphy->bands[band]->n_channels;
2978 }
2979
2980 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2981 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2982 n_ssids++;
2983
2984 if (n_ssids > wiphy->max_scan_ssids) {
2985 err = -EINVAL;
3b85875a 2986 goto out;
2a519311
JB
2987 }
2988
70692ad2
JM
2989 if (info->attrs[NL80211_ATTR_IE])
2990 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2991 else
2992 ie_len = 0;
2993
18a83659
JB
2994 if (ie_len > wiphy->max_scan_ie_len) {
2995 err = -EINVAL;
2996 goto out;
2997 }
2998
2a519311
JB
2999 request = kzalloc(sizeof(*request)
3000 + sizeof(*ssid) * n_ssids
70692ad2
JM
3001 + sizeof(channel) * n_channels
3002 + ie_len, GFP_KERNEL);
2a519311
JB
3003 if (!request) {
3004 err = -ENOMEM;
3b85875a 3005 goto out;
2a519311
JB
3006 }
3007
2a519311 3008 if (n_ssids)
5ba63533 3009 request->ssids = (void *)&request->channels[n_channels];
2a519311 3010 request->n_ssids = n_ssids;
70692ad2
JM
3011 if (ie_len) {
3012 if (request->ssids)
3013 request->ie = (void *)(request->ssids + n_ssids);
3014 else
3015 request->ie = (void *)(request->channels + n_channels);
3016 }
2a519311 3017
584991dc 3018 i = 0;
2a519311
JB
3019 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3020 /* user specified, bail out if channel not found */
2a519311 3021 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3022 struct ieee80211_channel *chan;
3023
3024 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3025
3026 if (!chan) {
2a519311
JB
3027 err = -EINVAL;
3028 goto out_free;
3029 }
584991dc
JB
3030
3031 /* ignore disabled channels */
3032 if (chan->flags & IEEE80211_CHAN_DISABLED)
3033 continue;
3034
3035 request->channels[i] = chan;
2a519311
JB
3036 i++;
3037 }
3038 } else {
3039 /* all channels */
2a519311
JB
3040 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3041 int j;
3042 if (!wiphy->bands[band])
3043 continue;
3044 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3045 struct ieee80211_channel *chan;
3046
3047 chan = &wiphy->bands[band]->channels[j];
3048
3049 if (chan->flags & IEEE80211_CHAN_DISABLED)
3050 continue;
3051
3052 request->channels[i] = chan;
2a519311
JB
3053 i++;
3054 }
3055 }
3056 }
3057
584991dc
JB
3058 if (!i) {
3059 err = -EINVAL;
3060 goto out_free;
3061 }
3062
3063 request->n_channels = i;
3064
2a519311
JB
3065 i = 0;
3066 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3067 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3068 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3069 err = -EINVAL;
3070 goto out_free;
3071 }
3072 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3073 request->ssids[i].ssid_len = nla_len(attr);
3074 i++;
3075 }
3076 }
3077
70692ad2
JM
3078 if (info->attrs[NL80211_ATTR_IE]) {
3079 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3080 memcpy((void *)request->ie,
3081 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3082 request->ie_len);
3083 }
3084
463d0183 3085 request->dev = dev;
79c97e97 3086 request->wiphy = &rdev->wiphy;
2a519311 3087
79c97e97
JB
3088 rdev->scan_req = request;
3089 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3090
463d0183 3091 if (!err) {
79c97e97 3092 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3093 dev_hold(dev);
3094 }
a538e2d5 3095
2a519311
JB
3096 out_free:
3097 if (err) {
79c97e97 3098 rdev->scan_req = NULL;
2a519311
JB
3099 kfree(request);
3100 }
2a519311 3101 out:
79c97e97 3102 cfg80211_unlock_rdev(rdev);
2a519311 3103 dev_put(dev);
3b85875a
JB
3104 out_rtnl:
3105 rtnl_unlock();
3106
2a519311
JB
3107 return err;
3108}
3109
3110static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3111 struct cfg80211_registered_device *rdev,
48ab905d
JB
3112 struct wireless_dev *wdev,
3113 struct cfg80211_internal_bss *intbss)
2a519311 3114{
48ab905d 3115 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3116 void *hdr;
3117 struct nlattr *bss;
48ab905d
JB
3118 int i;
3119
3120 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3121
3122 hdr = nl80211hdr_put(msg, pid, seq, flags,
3123 NL80211_CMD_NEW_SCAN_RESULTS);
3124 if (!hdr)
3125 return -1;
3126
f5ea9120 3127 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3128 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3129
3130 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3131 if (!bss)
3132 goto nla_put_failure;
3133 if (!is_zero_ether_addr(res->bssid))
3134 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3135 if (res->information_elements && res->len_information_elements)
3136 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3137 res->len_information_elements,
3138 res->information_elements);
3139 if (res->tsf)
3140 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3141 if (res->beacon_interval)
3142 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3143 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3144 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3145 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3146 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3147
77965c97 3148 switch (rdev->wiphy.signal_type) {
2a519311
JB
3149 case CFG80211_SIGNAL_TYPE_MBM:
3150 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3151 break;
3152 case CFG80211_SIGNAL_TYPE_UNSPEC:
3153 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3154 break;
3155 default:
3156 break;
3157 }
3158
48ab905d
JB
3159 switch (wdev->iftype) {
3160 case NL80211_IFTYPE_STATION:
3161 if (intbss == wdev->current_bss)
3162 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3163 NL80211_BSS_STATUS_ASSOCIATED);
3164 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3165 if (intbss != wdev->auth_bsses[i])
3166 continue;
3167 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3168 NL80211_BSS_STATUS_AUTHENTICATED);
3169 break;
3170 }
3171 break;
3172 case NL80211_IFTYPE_ADHOC:
3173 if (intbss == wdev->current_bss)
3174 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3175 NL80211_BSS_STATUS_IBSS_JOINED);
3176 break;
3177 default:
3178 break;
3179 }
3180
2a519311
JB
3181 nla_nest_end(msg, bss);
3182
3183 return genlmsg_end(msg, hdr);
3184
3185 nla_put_failure:
3186 genlmsg_cancel(msg, hdr);
3187 return -EMSGSIZE;
3188}
3189
3190static int nl80211_dump_scan(struct sk_buff *skb,
3191 struct netlink_callback *cb)
3192{
48ab905d
JB
3193 struct cfg80211_registered_device *rdev;
3194 struct net_device *dev;
2a519311 3195 struct cfg80211_internal_bss *scan;
48ab905d 3196 struct wireless_dev *wdev;
2a519311
JB
3197 int ifidx = cb->args[0];
3198 int start = cb->args[1], idx = 0;
3199 int err;
3200
a043897a
HS
3201 if (!ifidx)
3202 ifidx = nl80211_get_ifidx(cb);
3203 if (ifidx < 0)
3204 return ifidx;
3205 cb->args[0] = ifidx;
2a519311 3206
463d0183 3207 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3208 if (!dev)
2a519311
JB
3209 return -ENODEV;
3210
463d0183 3211 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3212 if (IS_ERR(rdev)) {
3213 err = PTR_ERR(rdev);
2a519311
JB
3214 goto out_put_netdev;
3215 }
3216
48ab905d 3217 wdev = dev->ieee80211_ptr;
2a519311 3218
48ab905d
JB
3219 wdev_lock(wdev);
3220 spin_lock_bh(&rdev->bss_lock);
3221 cfg80211_bss_expire(rdev);
3222
3223 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3224 if (++idx <= start)
3225 continue;
3226 if (nl80211_send_bss(skb,
3227 NETLINK_CB(cb->skb).pid,
3228 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3229 rdev, wdev, scan) < 0) {
2a519311
JB
3230 idx--;
3231 goto out;
3232 }
3233 }
3234
3235 out:
48ab905d
JB
3236 spin_unlock_bh(&rdev->bss_lock);
3237 wdev_unlock(wdev);
2a519311
JB
3238
3239 cb->args[1] = idx;
3240 err = skb->len;
48ab905d 3241 cfg80211_unlock_rdev(rdev);
2a519311 3242 out_put_netdev:
48ab905d 3243 dev_put(dev);
2a519311
JB
3244
3245 return err;
3246}
3247
61fa713c
HS
3248static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3249 int flags, struct net_device *dev,
3250 struct survey_info *survey)
3251{
3252 void *hdr;
3253 struct nlattr *infoattr;
3254
3255 /* Survey without a channel doesn't make sense */
3256 if (!survey->channel)
3257 return -EINVAL;
3258
3259 hdr = nl80211hdr_put(msg, pid, seq, flags,
3260 NL80211_CMD_NEW_SURVEY_RESULTS);
3261 if (!hdr)
3262 return -ENOMEM;
3263
3264 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3265
3266 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3267 if (!infoattr)
3268 goto nla_put_failure;
3269
3270 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3271 survey->channel->center_freq);
3272 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3273 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3274 survey->noise);
3275
3276 nla_nest_end(msg, infoattr);
3277
3278 return genlmsg_end(msg, hdr);
3279
3280 nla_put_failure:
3281 genlmsg_cancel(msg, hdr);
3282 return -EMSGSIZE;
3283}
3284
3285static int nl80211_dump_survey(struct sk_buff *skb,
3286 struct netlink_callback *cb)
3287{
3288 struct survey_info survey;
3289 struct cfg80211_registered_device *dev;
3290 struct net_device *netdev;
3291 int ifidx = cb->args[0];
3292 int survey_idx = cb->args[1];
3293 int res;
3294
3295 if (!ifidx)
3296 ifidx = nl80211_get_ifidx(cb);
3297 if (ifidx < 0)
3298 return ifidx;
3299 cb->args[0] = ifidx;
3300
3301 rtnl_lock();
3302
3303 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3304 if (!netdev) {
3305 res = -ENODEV;
3306 goto out_rtnl;
3307 }
3308
3309 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3310 if (IS_ERR(dev)) {
3311 res = PTR_ERR(dev);
3312 goto out_rtnl;
3313 }
3314
3315 if (!dev->ops->dump_survey) {
3316 res = -EOPNOTSUPP;
3317 goto out_err;
3318 }
3319
3320 while (1) {
3321 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3322 &survey);
3323 if (res == -ENOENT)
3324 break;
3325 if (res)
3326 goto out_err;
3327
3328 if (nl80211_send_survey(skb,
3329 NETLINK_CB(cb->skb).pid,
3330 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3331 netdev,
3332 &survey) < 0)
3333 goto out;
3334 survey_idx++;
3335 }
3336
3337 out:
3338 cb->args[1] = survey_idx;
3339 res = skb->len;
3340 out_err:
3341 cfg80211_unlock_rdev(dev);
3342 out_rtnl:
3343 rtnl_unlock();
3344
3345 return res;
3346}
3347
255e737e
JM
3348static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3349{
b23aa676
SO
3350 return auth_type <= NL80211_AUTHTYPE_MAX;
3351}
3352
3353static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3354{
3355 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3356 NL80211_WPA_VERSION_2));
3357}
3358
3359static bool nl80211_valid_akm_suite(u32 akm)
3360{
3361 return akm == WLAN_AKM_SUITE_8021X ||
3362 akm == WLAN_AKM_SUITE_PSK;
3363}
3364
3365static bool nl80211_valid_cipher_suite(u32 cipher)
3366{
3367 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3368 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3369 cipher == WLAN_CIPHER_SUITE_TKIP ||
3370 cipher == WLAN_CIPHER_SUITE_CCMP ||
3371 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3372}
3373
b23aa676 3374
636a5d36
JM
3375static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3376{
79c97e97 3377 struct cfg80211_registered_device *rdev;
636a5d36 3378 struct net_device *dev;
19957bb3
JB
3379 struct ieee80211_channel *chan;
3380 const u8 *bssid, *ssid, *ie = NULL;
3381 int err, ssid_len, ie_len = 0;
3382 enum nl80211_auth_type auth_type;
fffd0934 3383 struct key_parse key;
636a5d36 3384
f4a11bb0
JB
3385 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3386 return -EINVAL;
3387
3388 if (!info->attrs[NL80211_ATTR_MAC])
3389 return -EINVAL;
3390
1778092e
JM
3391 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3392 return -EINVAL;
3393
19957bb3
JB
3394 if (!info->attrs[NL80211_ATTR_SSID])
3395 return -EINVAL;
3396
3397 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3398 return -EINVAL;
3399
fffd0934
JB
3400 err = nl80211_parse_key(info, &key);
3401 if (err)
3402 return err;
3403
3404 if (key.idx >= 0) {
3405 if (!key.p.key || !key.p.key_len)
3406 return -EINVAL;
3407 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3408 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3409 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3410 key.p.key_len != WLAN_KEY_LEN_WEP104))
3411 return -EINVAL;
3412 if (key.idx > 4)
3413 return -EINVAL;
3414 } else {
3415 key.p.key_len = 0;
3416 key.p.key = NULL;
3417 }
3418
636a5d36
JM
3419 rtnl_lock();
3420
463d0183 3421 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3422 if (err)
3423 goto unlock_rtnl;
3424
79c97e97 3425 if (!rdev->ops->auth) {
636a5d36
JM
3426 err = -EOPNOTSUPP;
3427 goto out;
3428 }
3429
eec60b03
JM
3430 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3431 err = -EOPNOTSUPP;
3432 goto out;
3433 }
3434
35a8efe1
JM
3435 if (!netif_running(dev)) {
3436 err = -ENETDOWN;
3437 goto out;
3438 }
3439
19957bb3 3440 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3441 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3442 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3443 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3444 err = -EINVAL;
3445 goto out;
636a5d36
JM
3446 }
3447
19957bb3
JB
3448 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3449 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3450
3451 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3452 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3453 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3454 }
3455
19957bb3
JB
3456 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3457 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3458 err = -EINVAL;
3459 goto out;
636a5d36
JM
3460 }
3461
79c97e97 3462 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934
JB
3463 ssid, ssid_len, ie, ie_len,
3464 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
3465
3466out:
79c97e97 3467 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3468 dev_put(dev);
3469unlock_rtnl:
3470 rtnl_unlock();
3471 return err;
3472}
3473
b23aa676 3474static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3475 struct cfg80211_crypto_settings *settings,
3476 int cipher_limit)
b23aa676 3477{
c0b2bbd8
JB
3478 memset(settings, 0, sizeof(*settings));
3479
b23aa676
SO
3480 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3481
3482 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3483 void *data;
3484 int len, i;
3485
3486 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3487 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3488 settings->n_ciphers_pairwise = len / sizeof(u32);
3489
3490 if (len % sizeof(u32))
3491 return -EINVAL;
3492
3dc27d25 3493 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3494 return -EINVAL;
3495
3496 memcpy(settings->ciphers_pairwise, data, len);
3497
3498 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3499 if (!nl80211_valid_cipher_suite(
3500 settings->ciphers_pairwise[i]))
3501 return -EINVAL;
3502 }
3503
3504 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3505 settings->cipher_group =
3506 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3507 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3508 return -EINVAL;
3509 }
3510
3511 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3512 settings->wpa_versions =
3513 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3514 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3515 return -EINVAL;
3516 }
3517
3518 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3519 void *data;
3520 int len, i;
3521
3522 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3523 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3524 settings->n_akm_suites = len / sizeof(u32);
3525
3526 if (len % sizeof(u32))
3527 return -EINVAL;
3528
3529 memcpy(settings->akm_suites, data, len);
3530
3531 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3532 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3533 return -EINVAL;
3534 }
3535
3536 return 0;
3537}
3538
636a5d36
JM
3539static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3540{
19957bb3 3541 struct cfg80211_registered_device *rdev;
636a5d36 3542 struct net_device *dev;
19957bb3 3543 struct cfg80211_crypto_settings crypto;
59bbb6f7 3544 struct ieee80211_channel *chan, *fixedchan;
3e5d7649 3545 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3546 int err, ssid_len, ie_len = 0;
3547 bool use_mfp = false;
636a5d36 3548
f4a11bb0
JB
3549 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3550 return -EINVAL;
3551
3552 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3553 !info->attrs[NL80211_ATTR_SSID] ||
3554 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3555 return -EINVAL;
3556
636a5d36
JM
3557 rtnl_lock();
3558
463d0183 3559 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3560 if (err)
3561 goto unlock_rtnl;
3562
19957bb3 3563 if (!rdev->ops->assoc) {
636a5d36
JM
3564 err = -EOPNOTSUPP;
3565 goto out;
3566 }
3567
eec60b03
JM
3568 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3569 err = -EOPNOTSUPP;
3570 goto out;
3571 }
3572
35a8efe1
JM
3573 if (!netif_running(dev)) {
3574 err = -ENETDOWN;
3575 goto out;
3576 }
3577
19957bb3 3578 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3579
19957bb3
JB
3580 chan = ieee80211_get_channel(&rdev->wiphy,
3581 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3582 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3583 err = -EINVAL;
3584 goto out;
636a5d36
JM
3585 }
3586
59bbb6f7
JB
3587 mutex_lock(&rdev->devlist_mtx);
3588 fixedchan = rdev_fixed_channel(rdev, NULL);
3589 if (fixedchan && chan != fixedchan) {
3590 err = -EBUSY;
3591 mutex_unlock(&rdev->devlist_mtx);
3592 goto out;
3593 }
3594 mutex_unlock(&rdev->devlist_mtx);
3595
19957bb3
JB
3596 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3597 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3598
3599 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3600 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3601 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3602 }
3603
dc6382ce 3604 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3605 enum nl80211_mfp mfp =
dc6382ce 3606 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3607 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3608 use_mfp = true;
4f5dadce 3609 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3610 err = -EINVAL;
3611 goto out;
3612 }
3613 }
3614
3e5d7649
JB
3615 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3616 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3617
3dc27d25 3618 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3619 if (!err)
3e5d7649
JB
3620 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3621 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3622 &crypto);
636a5d36
JM
3623
3624out:
4d0c8aea 3625 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3626 dev_put(dev);
3627unlock_rtnl:
3628 rtnl_unlock();
3629 return err;
3630}
3631
3632static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3633{
79c97e97 3634 struct cfg80211_registered_device *rdev;
636a5d36 3635 struct net_device *dev;
19957bb3
JB
3636 const u8 *ie = NULL, *bssid;
3637 int err, ie_len = 0;
3638 u16 reason_code;
636a5d36 3639
f4a11bb0
JB
3640 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3641 return -EINVAL;
3642
3643 if (!info->attrs[NL80211_ATTR_MAC])
3644 return -EINVAL;
3645
3646 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3647 return -EINVAL;
3648
636a5d36
JM
3649 rtnl_lock();
3650
463d0183 3651 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3652 if (err)
3653 goto unlock_rtnl;
3654
79c97e97 3655 if (!rdev->ops->deauth) {
636a5d36
JM
3656 err = -EOPNOTSUPP;
3657 goto out;
3658 }
3659
eec60b03
JM
3660 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3661 err = -EOPNOTSUPP;
3662 goto out;
3663 }
3664
35a8efe1
JM
3665 if (!netif_running(dev)) {
3666 err = -ENETDOWN;
3667 goto out;
3668 }
3669
19957bb3 3670 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3671
19957bb3
JB
3672 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3673 if (reason_code == 0) {
f4a11bb0
JB
3674 /* Reason Code 0 is reserved */
3675 err = -EINVAL;
3676 goto out;
255e737e 3677 }
636a5d36
JM
3678
3679 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3680 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3681 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3682 }
3683
79c97e97 3684 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3685
3686out:
79c97e97 3687 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3688 dev_put(dev);
3689unlock_rtnl:
3690 rtnl_unlock();
3691 return err;
3692}
3693
3694static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3695{
79c97e97 3696 struct cfg80211_registered_device *rdev;
636a5d36 3697 struct net_device *dev;
19957bb3
JB
3698 const u8 *ie = NULL, *bssid;
3699 int err, ie_len = 0;
3700 u16 reason_code;
636a5d36 3701
f4a11bb0
JB
3702 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3703 return -EINVAL;
3704
3705 if (!info->attrs[NL80211_ATTR_MAC])
3706 return -EINVAL;
3707
3708 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3709 return -EINVAL;
3710
636a5d36
JM
3711 rtnl_lock();
3712
463d0183 3713 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3714 if (err)
3715 goto unlock_rtnl;
3716
79c97e97 3717 if (!rdev->ops->disassoc) {
636a5d36
JM
3718 err = -EOPNOTSUPP;
3719 goto out;
3720 }
3721
eec60b03
JM
3722 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3723 err = -EOPNOTSUPP;
3724 goto out;
3725 }
3726
35a8efe1
JM
3727 if (!netif_running(dev)) {
3728 err = -ENETDOWN;
3729 goto out;
3730 }
3731
19957bb3 3732 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3733
19957bb3
JB
3734 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3735 if (reason_code == 0) {
f4a11bb0
JB
3736 /* Reason Code 0 is reserved */
3737 err = -EINVAL;
3738 goto out;
255e737e 3739 }
636a5d36
JM
3740
3741 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3742 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3743 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3744 }
3745
79c97e97 3746 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3747
3748out:
79c97e97 3749 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3750 dev_put(dev);
3751unlock_rtnl:
3752 rtnl_unlock();
3753 return err;
3754}
3755
04a773ad
JB
3756static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3757{
79c97e97 3758 struct cfg80211_registered_device *rdev;
04a773ad
JB
3759 struct net_device *dev;
3760 struct cfg80211_ibss_params ibss;
3761 struct wiphy *wiphy;
fffd0934 3762 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3763 int err;
3764
8e30bc55
JB
3765 memset(&ibss, 0, sizeof(ibss));
3766
04a773ad
JB
3767 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3768 return -EINVAL;
3769
3770 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3771 !info->attrs[NL80211_ATTR_SSID] ||
3772 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3773 return -EINVAL;
3774
8e30bc55
JB
3775 ibss.beacon_interval = 100;
3776
3777 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3778 ibss.beacon_interval =
3779 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3780 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3781 return -EINVAL;
3782 }
3783
04a773ad
JB
3784 rtnl_lock();
3785
463d0183 3786 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3787 if (err)
3788 goto unlock_rtnl;
3789
79c97e97 3790 if (!rdev->ops->join_ibss) {
04a773ad
JB
3791 err = -EOPNOTSUPP;
3792 goto out;
3793 }
3794
3795 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3796 err = -EOPNOTSUPP;
3797 goto out;
3798 }
3799
3800 if (!netif_running(dev)) {
3801 err = -ENETDOWN;
3802 goto out;
3803 }
3804
79c97e97 3805 wiphy = &rdev->wiphy;
04a773ad
JB
3806
3807 if (info->attrs[NL80211_ATTR_MAC])
3808 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3809 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3810 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3811
3812 if (info->attrs[NL80211_ATTR_IE]) {
3813 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3814 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3815 }
3816
3817 ibss.channel = ieee80211_get_channel(wiphy,
3818 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3819 if (!ibss.channel ||
3820 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3821 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3822 err = -EINVAL;
3823 goto out;
3824 }
3825
3826 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3827 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3828
3829 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3830 connkeys = nl80211_parse_connkeys(rdev,
3831 info->attrs[NL80211_ATTR_KEYS]);
3832 if (IS_ERR(connkeys)) {
3833 err = PTR_ERR(connkeys);
3834 connkeys = NULL;
3835 goto out;
3836 }
3837 }
04a773ad 3838
fffd0934 3839 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
3840
3841out:
79c97e97 3842 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3843 dev_put(dev);
3844unlock_rtnl:
fffd0934
JB
3845 if (err)
3846 kfree(connkeys);
04a773ad
JB
3847 rtnl_unlock();
3848 return err;
3849}
3850
3851static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3852{
79c97e97 3853 struct cfg80211_registered_device *rdev;
04a773ad
JB
3854 struct net_device *dev;
3855 int err;
3856
3857 rtnl_lock();
3858
463d0183 3859 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3860 if (err)
3861 goto unlock_rtnl;
3862
79c97e97 3863 if (!rdev->ops->leave_ibss) {
04a773ad
JB
3864 err = -EOPNOTSUPP;
3865 goto out;
3866 }
3867
3868 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3869 err = -EOPNOTSUPP;
3870 goto out;
3871 }
3872
3873 if (!netif_running(dev)) {
3874 err = -ENETDOWN;
3875 goto out;
3876 }
3877
79c97e97 3878 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3879
3880out:
79c97e97 3881 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3882 dev_put(dev);
3883unlock_rtnl:
3884 rtnl_unlock();
3885 return err;
3886}
3887
aff89a9b
JB
3888#ifdef CONFIG_NL80211_TESTMODE
3889static struct genl_multicast_group nl80211_testmode_mcgrp = {
3890 .name = "testmode",
3891};
3892
3893static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3894{
3895 struct cfg80211_registered_device *rdev;
3896 int err;
3897
3898 if (!info->attrs[NL80211_ATTR_TESTDATA])
3899 return -EINVAL;
3900
3901 rtnl_lock();
3902
3903 rdev = cfg80211_get_dev_from_info(info);
3904 if (IS_ERR(rdev)) {
3905 err = PTR_ERR(rdev);
3906 goto unlock_rtnl;
3907 }
3908
3909 err = -EOPNOTSUPP;
3910 if (rdev->ops->testmode_cmd) {
3911 rdev->testmode_info = info;
3912 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3913 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3914 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3915 rdev->testmode_info = NULL;
3916 }
3917
4d0c8aea 3918 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
3919
3920 unlock_rtnl:
3921 rtnl_unlock();
3922 return err;
3923}
3924
3925static struct sk_buff *
3926__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3927 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3928{
3929 struct sk_buff *skb;
3930 void *hdr;
3931 struct nlattr *data;
3932
3933 skb = nlmsg_new(approxlen + 100, gfp);
3934 if (!skb)
3935 return NULL;
3936
3937 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3938 if (!hdr) {
3939 kfree_skb(skb);
3940 return NULL;
3941 }
3942
3943 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3944 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3945
3946 ((void **)skb->cb)[0] = rdev;
3947 ((void **)skb->cb)[1] = hdr;
3948 ((void **)skb->cb)[2] = data;
3949
3950 return skb;
3951
3952 nla_put_failure:
3953 kfree_skb(skb);
3954 return NULL;
3955}
3956
3957struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3958 int approxlen)
3959{
3960 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3961
3962 if (WARN_ON(!rdev->testmode_info))
3963 return NULL;
3964
3965 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3966 rdev->testmode_info->snd_pid,
3967 rdev->testmode_info->snd_seq,
3968 GFP_KERNEL);
3969}
3970EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3971
3972int cfg80211_testmode_reply(struct sk_buff *skb)
3973{
3974 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3975 void *hdr = ((void **)skb->cb)[1];
3976 struct nlattr *data = ((void **)skb->cb)[2];
3977
3978 if (WARN_ON(!rdev->testmode_info)) {
3979 kfree_skb(skb);
3980 return -EINVAL;
3981 }
3982
3983 nla_nest_end(skb, data);
3984 genlmsg_end(skb, hdr);
3985 return genlmsg_reply(skb, rdev->testmode_info);
3986}
3987EXPORT_SYMBOL(cfg80211_testmode_reply);
3988
3989struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3990 int approxlen, gfp_t gfp)
3991{
3992 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3993
3994 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3995}
3996EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3997
3998void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3999{
4000 void *hdr = ((void **)skb->cb)[1];
4001 struct nlattr *data = ((void **)skb->cb)[2];
4002
4003 nla_nest_end(skb, data);
4004 genlmsg_end(skb, hdr);
4005 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4006}
4007EXPORT_SYMBOL(cfg80211_testmode_event);
4008#endif
4009
b23aa676
SO
4010static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4011{
79c97e97 4012 struct cfg80211_registered_device *rdev;
b23aa676
SO
4013 struct net_device *dev;
4014 struct cfg80211_connect_params connect;
4015 struct wiphy *wiphy;
fffd0934 4016 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4017 int err;
4018
4019 memset(&connect, 0, sizeof(connect));
4020
4021 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4022 return -EINVAL;
4023
4024 if (!info->attrs[NL80211_ATTR_SSID] ||
4025 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4026 return -EINVAL;
4027
4028 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4029 connect.auth_type =
4030 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4031 if (!nl80211_valid_auth_type(connect.auth_type))
4032 return -EINVAL;
4033 } else
4034 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4035
4036 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4037
3dc27d25
JB
4038 err = nl80211_crypto_settings(info, &connect.crypto,
4039 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4040 if (err)
4041 return err;
4042 rtnl_lock();
4043
463d0183 4044 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4045 if (err)
4046 goto unlock_rtnl;
4047
4048 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4049 err = -EOPNOTSUPP;
4050 goto out;
4051 }
4052
4053 if (!netif_running(dev)) {
4054 err = -ENETDOWN;
4055 goto out;
4056 }
4057
79c97e97 4058 wiphy = &rdev->wiphy;
b23aa676 4059
b23aa676
SO
4060 if (info->attrs[NL80211_ATTR_MAC])
4061 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4062 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4063 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4064
4065 if (info->attrs[NL80211_ATTR_IE]) {
4066 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4067 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4068 }
4069
4070 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4071 connect.channel =
4072 ieee80211_get_channel(wiphy,
4073 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4074 if (!connect.channel ||
4075 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4076 err = -EINVAL;
4077 goto out;
4078 }
4079 }
4080
fffd0934
JB
4081 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4082 connkeys = nl80211_parse_connkeys(rdev,
4083 info->attrs[NL80211_ATTR_KEYS]);
4084 if (IS_ERR(connkeys)) {
4085 err = PTR_ERR(connkeys);
4086 connkeys = NULL;
4087 goto out;
4088 }
4089 }
4090
4091 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
4092
4093out:
79c97e97 4094 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4095 dev_put(dev);
4096unlock_rtnl:
fffd0934
JB
4097 if (err)
4098 kfree(connkeys);
b23aa676
SO
4099 rtnl_unlock();
4100 return err;
4101}
4102
4103static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4104{
79c97e97 4105 struct cfg80211_registered_device *rdev;
b23aa676
SO
4106 struct net_device *dev;
4107 int err;
4108 u16 reason;
4109
4110 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4111 reason = WLAN_REASON_DEAUTH_LEAVING;
4112 else
4113 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4114
4115 if (reason == 0)
4116 return -EINVAL;
4117
4118 rtnl_lock();
4119
463d0183 4120 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4121 if (err)
4122 goto unlock_rtnl;
4123
4124 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4125 err = -EOPNOTSUPP;
4126 goto out;
4127 }
4128
4129 if (!netif_running(dev)) {
4130 err = -ENETDOWN;
4131 goto out;
4132 }
4133
79c97e97 4134 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4135
4136out:
79c97e97 4137 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4138 dev_put(dev);
4139unlock_rtnl:
4140 rtnl_unlock();
4141 return err;
4142}
4143
463d0183
JB
4144static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4145{
4146 struct cfg80211_registered_device *rdev;
4147 struct net *net;
4148 int err;
4149 u32 pid;
4150
4151 if (!info->attrs[NL80211_ATTR_PID])
4152 return -EINVAL;
4153
4154 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4155
4156 rtnl_lock();
4157
4158 rdev = cfg80211_get_dev_from_info(info);
4159 if (IS_ERR(rdev)) {
4160 err = PTR_ERR(rdev);
8a8e05e5 4161 goto out_rtnl;
463d0183
JB
4162 }
4163
4164 net = get_net_ns_by_pid(pid);
4165 if (IS_ERR(net)) {
4166 err = PTR_ERR(net);
4167 goto out;
4168 }
4169
4170 err = 0;
4171
4172 /* check if anything to do */
4173 if (net_eq(wiphy_net(&rdev->wiphy), net))
4174 goto out_put_net;
4175
4176 err = cfg80211_switch_netns(rdev, net);
4177 out_put_net:
4178 put_net(net);
4179 out:
4180 cfg80211_unlock_rdev(rdev);
8a8e05e5 4181 out_rtnl:
463d0183
JB
4182 rtnl_unlock();
4183 return err;
4184}
4185
55682965
JB
4186static struct genl_ops nl80211_ops[] = {
4187 {
4188 .cmd = NL80211_CMD_GET_WIPHY,
4189 .doit = nl80211_get_wiphy,
4190 .dumpit = nl80211_dump_wiphy,
4191 .policy = nl80211_policy,
4192 /* can be retrieved by unprivileged users */
4193 },
4194 {
4195 .cmd = NL80211_CMD_SET_WIPHY,
4196 .doit = nl80211_set_wiphy,
4197 .policy = nl80211_policy,
4198 .flags = GENL_ADMIN_PERM,
4199 },
4200 {
4201 .cmd = NL80211_CMD_GET_INTERFACE,
4202 .doit = nl80211_get_interface,
4203 .dumpit = nl80211_dump_interface,
4204 .policy = nl80211_policy,
4205 /* can be retrieved by unprivileged users */
4206 },
4207 {
4208 .cmd = NL80211_CMD_SET_INTERFACE,
4209 .doit = nl80211_set_interface,
4210 .policy = nl80211_policy,
4211 .flags = GENL_ADMIN_PERM,
4212 },
4213 {
4214 .cmd = NL80211_CMD_NEW_INTERFACE,
4215 .doit = nl80211_new_interface,
4216 .policy = nl80211_policy,
4217 .flags = GENL_ADMIN_PERM,
4218 },
4219 {
4220 .cmd = NL80211_CMD_DEL_INTERFACE,
4221 .doit = nl80211_del_interface,
4222 .policy = nl80211_policy,
41ade00f
JB
4223 .flags = GENL_ADMIN_PERM,
4224 },
4225 {
4226 .cmd = NL80211_CMD_GET_KEY,
4227 .doit = nl80211_get_key,
4228 .policy = nl80211_policy,
4229 .flags = GENL_ADMIN_PERM,
4230 },
4231 {
4232 .cmd = NL80211_CMD_SET_KEY,
4233 .doit = nl80211_set_key,
4234 .policy = nl80211_policy,
4235 .flags = GENL_ADMIN_PERM,
4236 },
4237 {
4238 .cmd = NL80211_CMD_NEW_KEY,
4239 .doit = nl80211_new_key,
4240 .policy = nl80211_policy,
4241 .flags = GENL_ADMIN_PERM,
4242 },
4243 {
4244 .cmd = NL80211_CMD_DEL_KEY,
4245 .doit = nl80211_del_key,
4246 .policy = nl80211_policy,
55682965
JB
4247 .flags = GENL_ADMIN_PERM,
4248 },
ed1b6cc7
JB
4249 {
4250 .cmd = NL80211_CMD_SET_BEACON,
4251 .policy = nl80211_policy,
4252 .flags = GENL_ADMIN_PERM,
4253 .doit = nl80211_addset_beacon,
4254 },
4255 {
4256 .cmd = NL80211_CMD_NEW_BEACON,
4257 .policy = nl80211_policy,
4258 .flags = GENL_ADMIN_PERM,
4259 .doit = nl80211_addset_beacon,
4260 },
4261 {
4262 .cmd = NL80211_CMD_DEL_BEACON,
4263 .policy = nl80211_policy,
4264 .flags = GENL_ADMIN_PERM,
4265 .doit = nl80211_del_beacon,
4266 },
5727ef1b
JB
4267 {
4268 .cmd = NL80211_CMD_GET_STATION,
4269 .doit = nl80211_get_station,
2ec600d6 4270 .dumpit = nl80211_dump_station,
5727ef1b 4271 .policy = nl80211_policy,
5727ef1b
JB
4272 },
4273 {
4274 .cmd = NL80211_CMD_SET_STATION,
4275 .doit = nl80211_set_station,
4276 .policy = nl80211_policy,
4277 .flags = GENL_ADMIN_PERM,
4278 },
4279 {
4280 .cmd = NL80211_CMD_NEW_STATION,
4281 .doit = nl80211_new_station,
4282 .policy = nl80211_policy,
4283 .flags = GENL_ADMIN_PERM,
4284 },
4285 {
4286 .cmd = NL80211_CMD_DEL_STATION,
4287 .doit = nl80211_del_station,
4288 .policy = nl80211_policy,
2ec600d6
LCC
4289 .flags = GENL_ADMIN_PERM,
4290 },
4291 {
4292 .cmd = NL80211_CMD_GET_MPATH,
4293 .doit = nl80211_get_mpath,
4294 .dumpit = nl80211_dump_mpath,
4295 .policy = nl80211_policy,
4296 .flags = GENL_ADMIN_PERM,
4297 },
4298 {
4299 .cmd = NL80211_CMD_SET_MPATH,
4300 .doit = nl80211_set_mpath,
4301 .policy = nl80211_policy,
4302 .flags = GENL_ADMIN_PERM,
4303 },
4304 {
4305 .cmd = NL80211_CMD_NEW_MPATH,
4306 .doit = nl80211_new_mpath,
4307 .policy = nl80211_policy,
4308 .flags = GENL_ADMIN_PERM,
4309 },
4310 {
4311 .cmd = NL80211_CMD_DEL_MPATH,
4312 .doit = nl80211_del_mpath,
4313 .policy = nl80211_policy,
9f1ba906
JM
4314 .flags = GENL_ADMIN_PERM,
4315 },
4316 {
4317 .cmd = NL80211_CMD_SET_BSS,
4318 .doit = nl80211_set_bss,
4319 .policy = nl80211_policy,
b2e1b302
LR
4320 .flags = GENL_ADMIN_PERM,
4321 },
f130347c
LR
4322 {
4323 .cmd = NL80211_CMD_GET_REG,
4324 .doit = nl80211_get_reg,
4325 .policy = nl80211_policy,
4326 /* can be retrieved by unprivileged users */
4327 },
b2e1b302
LR
4328 {
4329 .cmd = NL80211_CMD_SET_REG,
4330 .doit = nl80211_set_reg,
4331 .policy = nl80211_policy,
4332 .flags = GENL_ADMIN_PERM,
4333 },
4334 {
4335 .cmd = NL80211_CMD_REQ_SET_REG,
4336 .doit = nl80211_req_set_reg,
4337 .policy = nl80211_policy,
93da9cc1 4338 .flags = GENL_ADMIN_PERM,
4339 },
4340 {
4341 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4342 .doit = nl80211_get_mesh_params,
4343 .policy = nl80211_policy,
4344 /* can be retrieved by unprivileged users */
4345 },
4346 {
4347 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4348 .doit = nl80211_set_mesh_params,
4349 .policy = nl80211_policy,
9aed3cc1
JM
4350 .flags = GENL_ADMIN_PERM,
4351 },
2a519311
JB
4352 {
4353 .cmd = NL80211_CMD_TRIGGER_SCAN,
4354 .doit = nl80211_trigger_scan,
4355 .policy = nl80211_policy,
4356 .flags = GENL_ADMIN_PERM,
4357 },
4358 {
4359 .cmd = NL80211_CMD_GET_SCAN,
4360 .policy = nl80211_policy,
4361 .dumpit = nl80211_dump_scan,
4362 },
636a5d36
JM
4363 {
4364 .cmd = NL80211_CMD_AUTHENTICATE,
4365 .doit = nl80211_authenticate,
4366 .policy = nl80211_policy,
4367 .flags = GENL_ADMIN_PERM,
4368 },
4369 {
4370 .cmd = NL80211_CMD_ASSOCIATE,
4371 .doit = nl80211_associate,
4372 .policy = nl80211_policy,
4373 .flags = GENL_ADMIN_PERM,
4374 },
4375 {
4376 .cmd = NL80211_CMD_DEAUTHENTICATE,
4377 .doit = nl80211_deauthenticate,
4378 .policy = nl80211_policy,
4379 .flags = GENL_ADMIN_PERM,
4380 },
4381 {
4382 .cmd = NL80211_CMD_DISASSOCIATE,
4383 .doit = nl80211_disassociate,
4384 .policy = nl80211_policy,
4385 .flags = GENL_ADMIN_PERM,
4386 },
04a773ad
JB
4387 {
4388 .cmd = NL80211_CMD_JOIN_IBSS,
4389 .doit = nl80211_join_ibss,
4390 .policy = nl80211_policy,
4391 .flags = GENL_ADMIN_PERM,
4392 },
4393 {
4394 .cmd = NL80211_CMD_LEAVE_IBSS,
4395 .doit = nl80211_leave_ibss,
4396 .policy = nl80211_policy,
4397 .flags = GENL_ADMIN_PERM,
4398 },
aff89a9b
JB
4399#ifdef CONFIG_NL80211_TESTMODE
4400 {
4401 .cmd = NL80211_CMD_TESTMODE,
4402 .doit = nl80211_testmode_do,
4403 .policy = nl80211_policy,
4404 .flags = GENL_ADMIN_PERM,
4405 },
4406#endif
b23aa676
SO
4407 {
4408 .cmd = NL80211_CMD_CONNECT,
4409 .doit = nl80211_connect,
4410 .policy = nl80211_policy,
4411 .flags = GENL_ADMIN_PERM,
4412 },
4413 {
4414 .cmd = NL80211_CMD_DISCONNECT,
4415 .doit = nl80211_disconnect,
4416 .policy = nl80211_policy,
4417 .flags = GENL_ADMIN_PERM,
4418 },
463d0183
JB
4419 {
4420 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4421 .doit = nl80211_wiphy_netns,
4422 .policy = nl80211_policy,
4423 .flags = GENL_ADMIN_PERM,
4424 },
61fa713c
HS
4425 {
4426 .cmd = NL80211_CMD_GET_SURVEY,
4427 .policy = nl80211_policy,
4428 .dumpit = nl80211_dump_survey,
4429 },
55682965 4430};
6039f6d2
JM
4431static struct genl_multicast_group nl80211_mlme_mcgrp = {
4432 .name = "mlme",
4433};
55682965
JB
4434
4435/* multicast groups */
4436static struct genl_multicast_group nl80211_config_mcgrp = {
4437 .name = "config",
4438};
2a519311
JB
4439static struct genl_multicast_group nl80211_scan_mcgrp = {
4440 .name = "scan",
4441};
73d54c9e
LR
4442static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4443 .name = "regulatory",
4444};
55682965
JB
4445
4446/* notification functions */
4447
4448void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4449{
4450 struct sk_buff *msg;
4451
fd2120ca 4452 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
4453 if (!msg)
4454 return;
4455
4456 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4457 nlmsg_free(msg);
4458 return;
4459 }
4460
463d0183
JB
4461 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4462 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
4463}
4464
362a415d
JB
4465static int nl80211_add_scan_req(struct sk_buff *msg,
4466 struct cfg80211_registered_device *rdev)
4467{
4468 struct cfg80211_scan_request *req = rdev->scan_req;
4469 struct nlattr *nest;
4470 int i;
4471
667503dd
JB
4472 ASSERT_RDEV_LOCK(rdev);
4473
362a415d
JB
4474 if (WARN_ON(!req))
4475 return 0;
4476
4477 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4478 if (!nest)
4479 goto nla_put_failure;
4480 for (i = 0; i < req->n_ssids; i++)
4481 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4482 nla_nest_end(msg, nest);
4483
4484 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4485 if (!nest)
4486 goto nla_put_failure;
4487 for (i = 0; i < req->n_channels; i++)
4488 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4489 nla_nest_end(msg, nest);
4490
4491 if (req->ie)
4492 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4493
4494 return 0;
4495 nla_put_failure:
4496 return -ENOBUFS;
4497}
4498
a538e2d5
JB
4499static int nl80211_send_scan_msg(struct sk_buff *msg,
4500 struct cfg80211_registered_device *rdev,
4501 struct net_device *netdev,
4502 u32 pid, u32 seq, int flags,
4503 u32 cmd)
2a519311
JB
4504{
4505 void *hdr;
4506
4507 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4508 if (!hdr)
4509 return -1;
4510
b5850a7a 4511 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
4512 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4513
362a415d
JB
4514 /* ignore errors and send incomplete event anyway */
4515 nl80211_add_scan_req(msg, rdev);
2a519311
JB
4516
4517 return genlmsg_end(msg, hdr);
4518
4519 nla_put_failure:
4520 genlmsg_cancel(msg, hdr);
4521 return -EMSGSIZE;
4522}
4523
a538e2d5
JB
4524void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4525 struct net_device *netdev)
4526{
4527 struct sk_buff *msg;
4528
4529 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4530 if (!msg)
4531 return;
4532
4533 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4534 NL80211_CMD_TRIGGER_SCAN) < 0) {
4535 nlmsg_free(msg);
4536 return;
4537 }
4538
463d0183
JB
4539 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4540 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
4541}
4542
2a519311
JB
4543void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4544 struct net_device *netdev)
4545{
4546 struct sk_buff *msg;
4547
fd2120ca 4548 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4549 if (!msg)
4550 return;
4551
a538e2d5
JB
4552 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4553 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
4554 nlmsg_free(msg);
4555 return;
4556 }
4557
463d0183
JB
4558 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4559 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4560}
4561
4562void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4563 struct net_device *netdev)
4564{
4565 struct sk_buff *msg;
4566
fd2120ca 4567 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4568 if (!msg)
4569 return;
4570
a538e2d5
JB
4571 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4572 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
4573 nlmsg_free(msg);
4574 return;
4575 }
4576
463d0183
JB
4577 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4578 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4579}
4580
73d54c9e
LR
4581/*
4582 * This can happen on global regulatory changes or device specific settings
4583 * based on custom world regulatory domains.
4584 */
4585void nl80211_send_reg_change_event(struct regulatory_request *request)
4586{
4587 struct sk_buff *msg;
4588 void *hdr;
4589
fd2120ca 4590 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
4591 if (!msg)
4592 return;
4593
4594 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4595 if (!hdr) {
4596 nlmsg_free(msg);
4597 return;
4598 }
4599
4600 /* Userspace can always count this one always being set */
4601 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4602
4603 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4604 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4605 NL80211_REGDOM_TYPE_WORLD);
4606 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4607 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4608 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4609 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4610 request->intersect)
4611 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4612 NL80211_REGDOM_TYPE_INTERSECTION);
4613 else {
4614 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4615 NL80211_REGDOM_TYPE_COUNTRY);
4616 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4617 }
4618
4619 if (wiphy_idx_valid(request->wiphy_idx))
4620 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4621
4622 if (genlmsg_end(msg, hdr) < 0) {
4623 nlmsg_free(msg);
4624 return;
4625 }
4626
bc43b28c 4627 rcu_read_lock();
463d0183 4628 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
4629 GFP_ATOMIC);
4630 rcu_read_unlock();
73d54c9e
LR
4631
4632 return;
4633
4634nla_put_failure:
4635 genlmsg_cancel(msg, hdr);
4636 nlmsg_free(msg);
4637}
4638
6039f6d2
JM
4639static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4640 struct net_device *netdev,
4641 const u8 *buf, size_t len,
e6d6e342 4642 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
4643{
4644 struct sk_buff *msg;
4645 void *hdr;
4646
e6d6e342 4647 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
4648 if (!msg)
4649 return;
4650
4651 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4652 if (!hdr) {
4653 nlmsg_free(msg);
4654 return;
4655 }
4656
4657 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4658 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4659 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4660
4661 if (genlmsg_end(msg, hdr) < 0) {
4662 nlmsg_free(msg);
4663 return;
4664 }
4665
463d0183
JB
4666 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4667 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
4668 return;
4669
4670 nla_put_failure:
4671 genlmsg_cancel(msg, hdr);
4672 nlmsg_free(msg);
4673}
4674
4675void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4676 struct net_device *netdev, const u8 *buf,
4677 size_t len, gfp_t gfp)
6039f6d2
JM
4678{
4679 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4680 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
4681}
4682
4683void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4684 struct net_device *netdev, const u8 *buf,
e6d6e342 4685 size_t len, gfp_t gfp)
6039f6d2 4686{
e6d6e342
JB
4687 nl80211_send_mlme_event(rdev, netdev, buf, len,
4688 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
4689}
4690
53b46b84 4691void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4692 struct net_device *netdev, const u8 *buf,
4693 size_t len, gfp_t gfp)
6039f6d2
JM
4694{
4695 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4696 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
4697}
4698
53b46b84
JM
4699void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4700 struct net_device *netdev, const u8 *buf,
e6d6e342 4701 size_t len, gfp_t gfp)
6039f6d2
JM
4702{
4703 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 4704 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
4705}
4706
1b06bb40
LR
4707static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4708 struct net_device *netdev, int cmd,
e6d6e342 4709 const u8 *addr, gfp_t gfp)
1965c853
JM
4710{
4711 struct sk_buff *msg;
4712 void *hdr;
4713
e6d6e342 4714 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
4715 if (!msg)
4716 return;
4717
4718 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4719 if (!hdr) {
4720 nlmsg_free(msg);
4721 return;
4722 }
4723
4724 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4725 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4726 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4727 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4728
4729 if (genlmsg_end(msg, hdr) < 0) {
4730 nlmsg_free(msg);
4731 return;
4732 }
4733
463d0183
JB
4734 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4735 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
4736 return;
4737
4738 nla_put_failure:
4739 genlmsg_cancel(msg, hdr);
4740 nlmsg_free(msg);
4741}
4742
4743void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4744 struct net_device *netdev, const u8 *addr,
4745 gfp_t gfp)
1965c853
JM
4746{
4747 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 4748 addr, gfp);
1965c853
JM
4749}
4750
4751void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
4752 struct net_device *netdev, const u8 *addr,
4753 gfp_t gfp)
1965c853 4754{
e6d6e342
JB
4755 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4756 addr, gfp);
1965c853
JM
4757}
4758
b23aa676
SO
4759void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4760 struct net_device *netdev, const u8 *bssid,
4761 const u8 *req_ie, size_t req_ie_len,
4762 const u8 *resp_ie, size_t resp_ie_len,
4763 u16 status, gfp_t gfp)
4764{
4765 struct sk_buff *msg;
4766 void *hdr;
4767
4768 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4769 if (!msg)
4770 return;
4771
4772 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4773 if (!hdr) {
4774 nlmsg_free(msg);
4775 return;
4776 }
4777
4778 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4779 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4780 if (bssid)
4781 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4782 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4783 if (req_ie)
4784 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4785 if (resp_ie)
4786 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4787
4788 if (genlmsg_end(msg, hdr) < 0) {
4789 nlmsg_free(msg);
4790 return;
4791 }
4792
463d0183
JB
4793 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4794 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
4795 return;
4796
4797 nla_put_failure:
4798 genlmsg_cancel(msg, hdr);
4799 nlmsg_free(msg);
4800
4801}
4802
4803void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4804 struct net_device *netdev, const u8 *bssid,
4805 const u8 *req_ie, size_t req_ie_len,
4806 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4807{
4808 struct sk_buff *msg;
4809 void *hdr;
4810
4811 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4812 if (!msg)
4813 return;
4814
4815 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4816 if (!hdr) {
4817 nlmsg_free(msg);
4818 return;
4819 }
4820
4821 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4822 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4823 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4824 if (req_ie)
4825 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4826 if (resp_ie)
4827 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4828
4829 if (genlmsg_end(msg, hdr) < 0) {
4830 nlmsg_free(msg);
4831 return;
4832 }
4833
463d0183
JB
4834 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4835 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
4836 return;
4837
4838 nla_put_failure:
4839 genlmsg_cancel(msg, hdr);
4840 nlmsg_free(msg);
4841
4842}
4843
4844void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4845 struct net_device *netdev, u16 reason,
667503dd 4846 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
4847{
4848 struct sk_buff *msg;
4849 void *hdr;
4850
667503dd 4851 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
4852 if (!msg)
4853 return;
4854
4855 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4856 if (!hdr) {
4857 nlmsg_free(msg);
4858 return;
4859 }
4860
4861 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4862 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4863 if (from_ap && reason)
4864 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4865 if (from_ap)
4866 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4867 if (ie)
4868 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4869
4870 if (genlmsg_end(msg, hdr) < 0) {
4871 nlmsg_free(msg);
4872 return;
4873 }
4874
463d0183
JB
4875 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4876 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
4877 return;
4878
4879 nla_put_failure:
4880 genlmsg_cancel(msg, hdr);
4881 nlmsg_free(msg);
4882
4883}
4884
04a773ad
JB
4885void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4886 struct net_device *netdev, const u8 *bssid,
4887 gfp_t gfp)
4888{
4889 struct sk_buff *msg;
4890 void *hdr;
4891
fd2120ca 4892 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
4893 if (!msg)
4894 return;
4895
4896 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4897 if (!hdr) {
4898 nlmsg_free(msg);
4899 return;
4900 }
4901
4902 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4903 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4904 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4905
4906 if (genlmsg_end(msg, hdr) < 0) {
4907 nlmsg_free(msg);
4908 return;
4909 }
4910
463d0183
JB
4911 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4912 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
4913 return;
4914
4915 nla_put_failure:
4916 genlmsg_cancel(msg, hdr);
4917 nlmsg_free(msg);
4918}
4919
a3b8b056
JM
4920void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4921 struct net_device *netdev, const u8 *addr,
4922 enum nl80211_key_type key_type, int key_id,
e6d6e342 4923 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
4924{
4925 struct sk_buff *msg;
4926 void *hdr;
4927
e6d6e342 4928 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
4929 if (!msg)
4930 return;
4931
4932 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4933 if (!hdr) {
4934 nlmsg_free(msg);
4935 return;
4936 }
4937
4938 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4939 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4940 if (addr)
4941 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4942 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4943 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4944 if (tsc)
4945 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4946
4947 if (genlmsg_end(msg, hdr) < 0) {
4948 nlmsg_free(msg);
4949 return;
4950 }
4951
463d0183
JB
4952 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4953 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
4954 return;
4955
4956 nla_put_failure:
4957 genlmsg_cancel(msg, hdr);
4958 nlmsg_free(msg);
4959}
4960
6bad8766
LR
4961void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
4962 struct ieee80211_channel *channel_before,
4963 struct ieee80211_channel *channel_after)
4964{
4965 struct sk_buff *msg;
4966 void *hdr;
4967 struct nlattr *nl_freq;
4968
fd2120ca 4969 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
4970 if (!msg)
4971 return;
4972
4973 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
4974 if (!hdr) {
4975 nlmsg_free(msg);
4976 return;
4977 }
4978
4979 /*
4980 * Since we are applying the beacon hint to a wiphy we know its
4981 * wiphy_idx is valid
4982 */
4983 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
4984
4985 /* Before */
4986 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
4987 if (!nl_freq)
4988 goto nla_put_failure;
4989 if (nl80211_msg_put_channel(msg, channel_before))
4990 goto nla_put_failure;
4991 nla_nest_end(msg, nl_freq);
4992
4993 /* After */
4994 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
4995 if (!nl_freq)
4996 goto nla_put_failure;
4997 if (nl80211_msg_put_channel(msg, channel_after))
4998 goto nla_put_failure;
4999 nla_nest_end(msg, nl_freq);
5000
5001 if (genlmsg_end(msg, hdr) < 0) {
5002 nlmsg_free(msg);
5003 return;
5004 }
5005
463d0183
JB
5006 rcu_read_lock();
5007 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5008 GFP_ATOMIC);
5009 rcu_read_unlock();
6bad8766
LR
5010
5011 return;
5012
5013nla_put_failure:
5014 genlmsg_cancel(msg, hdr);
5015 nlmsg_free(msg);
5016}
5017
55682965
JB
5018/* initialisation/exit functions */
5019
5020int nl80211_init(void)
5021{
0d63cbb5 5022 int err;
55682965 5023
0d63cbb5
MM
5024 err = genl_register_family_with_ops(&nl80211_fam,
5025 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
5026 if (err)
5027 return err;
5028
55682965
JB
5029 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
5030 if (err)
5031 goto err_out;
5032
2a519311
JB
5033 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
5034 if (err)
5035 goto err_out;
5036
73d54c9e
LR
5037 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
5038 if (err)
5039 goto err_out;
5040
6039f6d2
JM
5041 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
5042 if (err)
5043 goto err_out;
5044
aff89a9b
JB
5045#ifdef CONFIG_NL80211_TESTMODE
5046 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
5047 if (err)
5048 goto err_out;
5049#endif
5050
55682965
JB
5051 return 0;
5052 err_out:
5053 genl_unregister_family(&nl80211_fam);
5054 return err;
5055}
5056
5057void nl80211_exit(void)
5058{
5059 genl_unregister_family(&nl80211_fam);
5060}