]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/blob - net/wireless/nl80211.c
wireless: remove CONFIG_WIRELESS_OLD_REGULATORY
[mirror_ubuntu-artful-kernel.git] / net / wireless / nl80211.c
1 /*
2 * This is the new netlink-based wireless configuration interface.
3 *
4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
5 */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/list.h>
11 #include <linux/if_ether.h>
12 #include <linux/ieee80211.h>
13 #include <linux/nl80211.h>
14 #include <linux/rtnetlink.h>
15 #include <linux/netlink.h>
16 #include <linux/etherdevice.h>
17 #include <net/net_namespace.h>
18 #include <net/genetlink.h>
19 #include <net/cfg80211.h>
20 #include <net/sock.h>
21 #include "core.h"
22 #include "nl80211.h"
23 #include "reg.h"
24
25 /* the netlink family */
26 static struct genl_family nl80211_fam = {
27 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28 .name = "nl80211", /* have users key off the name instead */
29 .hdrsize = 0, /* no private header */
30 .version = 1, /* no particular meaning now */
31 .maxattr = NL80211_ATTR_MAX,
32 .netnsok = true,
33 };
34
35 /* internal helper: get rdev and dev */
36 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
37 struct cfg80211_registered_device **rdev,
38 struct net_device **dev)
39 {
40 struct nlattr **attrs = info->attrs;
41 int ifindex;
42
43 if (!attrs[NL80211_ATTR_IFINDEX])
44 return -EINVAL;
45
46 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
47 *dev = dev_get_by_index(genl_info_net(info), ifindex);
48 if (!*dev)
49 return -ENODEV;
50
51 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
52 if (IS_ERR(*rdev)) {
53 dev_put(*dev);
54 return PTR_ERR(*rdev);
55 }
56
57 return 0;
58 }
59
60 /* policy for the attributes */
61 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
64 .len = 20-1 },
65 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
66 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
67 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
68 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
72
73 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
74 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
75 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
76
77 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
78 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
79
80 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
81 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
82 .len = WLAN_MAX_KEY_LEN },
83 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
84 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
85 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
86 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
87
88 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
89 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
90 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
91 .len = IEEE80211_MAX_DATA_LEN },
92 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
95 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
96 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
98 .len = NL80211_MAX_SUPP_RATES },
99 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
100 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
101 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
102 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_MESH_ID_LEN },
104 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
105
106 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
107 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
108
109 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
110 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
111 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
114
115 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
116
117 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
118 .len = NL80211_HT_CAPABILITY_LEN },
119
120 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
121 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
122 .len = IEEE80211_MAX_DATA_LEN },
123 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
124 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
125
126 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
127 .len = IEEE80211_MAX_SSID_LEN },
128 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
129 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
130 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
131 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
132 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
133 [NL80211_ATTR_STA_FLAGS2] = {
134 .len = sizeof(struct nl80211_sta_flag_update),
135 },
136 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
137 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
138 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
139 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
140 [NL80211_ATTR_PID] = { .type = NLA_U32 },
141 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
142 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
143 .len = WLAN_PMKID_LEN },
144 };
145
146 /* policy for the attributes */
147 static struct nla_policy
148 nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
149 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
150 [NL80211_KEY_IDX] = { .type = NLA_U8 },
151 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
152 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
153 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
154 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
155 };
156
157 /* ifidx get helper */
158 static int nl80211_get_ifidx(struct netlink_callback *cb)
159 {
160 int res;
161
162 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
163 nl80211_fam.attrbuf, nl80211_fam.maxattr,
164 nl80211_policy);
165 if (res)
166 return res;
167
168 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
169 return -EINVAL;
170
171 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
172 if (!res)
173 return -EINVAL;
174 return res;
175 }
176
177 /* IE validation */
178 static bool is_valid_ie_attr(const struct nlattr *attr)
179 {
180 const u8 *pos;
181 int len;
182
183 if (!attr)
184 return true;
185
186 pos = nla_data(attr);
187 len = nla_len(attr);
188
189 while (len) {
190 u8 elemlen;
191
192 if (len < 2)
193 return false;
194 len -= 2;
195
196 elemlen = pos[1];
197 if (elemlen > len)
198 return false;
199
200 len -= elemlen;
201 pos += 2 + elemlen;
202 }
203
204 return true;
205 }
206
207 /* message building helper */
208 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
209 int flags, u8 cmd)
210 {
211 /* since there is no private header just add the generic one */
212 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
213 }
214
215 static int nl80211_msg_put_channel(struct sk_buff *msg,
216 struct ieee80211_channel *chan)
217 {
218 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
219 chan->center_freq);
220
221 if (chan->flags & IEEE80211_CHAN_DISABLED)
222 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
223 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
224 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
225 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
226 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
227 if (chan->flags & IEEE80211_CHAN_RADAR)
228 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
229
230 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
231 DBM_TO_MBM(chan->max_power));
232
233 return 0;
234
235 nla_put_failure:
236 return -ENOBUFS;
237 }
238
239 /* netlink command implementations */
240
241 struct key_parse {
242 struct key_params p;
243 int idx;
244 bool def, defmgmt;
245 };
246
247 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
248 {
249 struct nlattr *tb[NL80211_KEY_MAX + 1];
250 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
251 nl80211_key_policy);
252 if (err)
253 return err;
254
255 k->def = !!tb[NL80211_KEY_DEFAULT];
256 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
257
258 if (tb[NL80211_KEY_IDX])
259 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
260
261 if (tb[NL80211_KEY_DATA]) {
262 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
263 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
264 }
265
266 if (tb[NL80211_KEY_SEQ]) {
267 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
268 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
269 }
270
271 if (tb[NL80211_KEY_CIPHER])
272 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
273
274 return 0;
275 }
276
277 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
278 {
279 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
280 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
281 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
282 }
283
284 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
285 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
286 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
287 }
288
289 if (info->attrs[NL80211_ATTR_KEY_IDX])
290 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
291
292 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
293 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
294
295 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
296 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
297
298 return 0;
299 }
300
301 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
302 {
303 int err;
304
305 memset(k, 0, sizeof(*k));
306 k->idx = -1;
307
308 if (info->attrs[NL80211_ATTR_KEY])
309 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
310 else
311 err = nl80211_parse_key_old(info, k);
312
313 if (err)
314 return err;
315
316 if (k->def && k->defmgmt)
317 return -EINVAL;
318
319 if (k->idx != -1) {
320 if (k->defmgmt) {
321 if (k->idx < 4 || k->idx > 5)
322 return -EINVAL;
323 } else if (k->def) {
324 if (k->idx < 0 || k->idx > 3)
325 return -EINVAL;
326 } else {
327 if (k->idx < 0 || k->idx > 5)
328 return -EINVAL;
329 }
330 }
331
332 return 0;
333 }
334
335 static struct cfg80211_cached_keys *
336 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
337 struct nlattr *keys)
338 {
339 struct key_parse parse;
340 struct nlattr *key;
341 struct cfg80211_cached_keys *result;
342 int rem, err, def = 0;
343
344 result = kzalloc(sizeof(*result), GFP_KERNEL);
345 if (!result)
346 return ERR_PTR(-ENOMEM);
347
348 result->def = -1;
349 result->defmgmt = -1;
350
351 nla_for_each_nested(key, keys, rem) {
352 memset(&parse, 0, sizeof(parse));
353 parse.idx = -1;
354
355 err = nl80211_parse_key_new(key, &parse);
356 if (err)
357 goto error;
358 err = -EINVAL;
359 if (!parse.p.key)
360 goto error;
361 if (parse.idx < 0 || parse.idx > 4)
362 goto error;
363 if (parse.def) {
364 if (def)
365 goto error;
366 def = 1;
367 result->def = parse.idx;
368 } else if (parse.defmgmt)
369 goto error;
370 err = cfg80211_validate_key_settings(rdev, &parse.p,
371 parse.idx, NULL);
372 if (err)
373 goto error;
374 result->params[parse.idx].cipher = parse.p.cipher;
375 result->params[parse.idx].key_len = parse.p.key_len;
376 result->params[parse.idx].key = result->data[parse.idx];
377 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
378 }
379
380 return result;
381 error:
382 kfree(result);
383 return ERR_PTR(err);
384 }
385
386 static int nl80211_key_allowed(struct wireless_dev *wdev)
387 {
388 ASSERT_WDEV_LOCK(wdev);
389
390 if (!netif_running(wdev->netdev))
391 return -ENETDOWN;
392
393 switch (wdev->iftype) {
394 case NL80211_IFTYPE_AP:
395 case NL80211_IFTYPE_AP_VLAN:
396 break;
397 case NL80211_IFTYPE_ADHOC:
398 if (!wdev->current_bss)
399 return -ENOLINK;
400 break;
401 case NL80211_IFTYPE_STATION:
402 if (wdev->sme_state != CFG80211_SME_CONNECTED)
403 return -ENOLINK;
404 break;
405 default:
406 return -EINVAL;
407 }
408
409 return 0;
410 }
411
412 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
413 struct cfg80211_registered_device *dev)
414 {
415 void *hdr;
416 struct nlattr *nl_bands, *nl_band;
417 struct nlattr *nl_freqs, *nl_freq;
418 struct nlattr *nl_rates, *nl_rate;
419 struct nlattr *nl_modes;
420 struct nlattr *nl_cmds;
421 enum ieee80211_band band;
422 struct ieee80211_channel *chan;
423 struct ieee80211_rate *rate;
424 int i;
425 u16 ifmodes = dev->wiphy.interface_modes;
426
427 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
428 if (!hdr)
429 return -1;
430
431 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
432 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
433
434 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
435 cfg80211_rdev_list_generation);
436
437 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
438 dev->wiphy.retry_short);
439 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
440 dev->wiphy.retry_long);
441 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
442 dev->wiphy.frag_threshold);
443 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
444 dev->wiphy.rts_threshold);
445
446 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
447 dev->wiphy.max_scan_ssids);
448 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
449 dev->wiphy.max_scan_ie_len);
450
451 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
452 sizeof(u32) * dev->wiphy.n_cipher_suites,
453 dev->wiphy.cipher_suites);
454
455 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
456 dev->wiphy.max_num_pmkids);
457
458 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
459 if (!nl_modes)
460 goto nla_put_failure;
461
462 i = 0;
463 while (ifmodes) {
464 if (ifmodes & 1)
465 NLA_PUT_FLAG(msg, i);
466 ifmodes >>= 1;
467 i++;
468 }
469
470 nla_nest_end(msg, nl_modes);
471
472 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
473 if (!nl_bands)
474 goto nla_put_failure;
475
476 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
477 if (!dev->wiphy.bands[band])
478 continue;
479
480 nl_band = nla_nest_start(msg, band);
481 if (!nl_band)
482 goto nla_put_failure;
483
484 /* add HT info */
485 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
486 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
487 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
488 &dev->wiphy.bands[band]->ht_cap.mcs);
489 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
490 dev->wiphy.bands[band]->ht_cap.cap);
491 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
492 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
493 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
494 dev->wiphy.bands[band]->ht_cap.ampdu_density);
495 }
496
497 /* add frequencies */
498 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
499 if (!nl_freqs)
500 goto nla_put_failure;
501
502 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
503 nl_freq = nla_nest_start(msg, i);
504 if (!nl_freq)
505 goto nla_put_failure;
506
507 chan = &dev->wiphy.bands[band]->channels[i];
508
509 if (nl80211_msg_put_channel(msg, chan))
510 goto nla_put_failure;
511
512 nla_nest_end(msg, nl_freq);
513 }
514
515 nla_nest_end(msg, nl_freqs);
516
517 /* add bitrates */
518 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
519 if (!nl_rates)
520 goto nla_put_failure;
521
522 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
523 nl_rate = nla_nest_start(msg, i);
524 if (!nl_rate)
525 goto nla_put_failure;
526
527 rate = &dev->wiphy.bands[band]->bitrates[i];
528 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
529 rate->bitrate);
530 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
531 NLA_PUT_FLAG(msg,
532 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
533
534 nla_nest_end(msg, nl_rate);
535 }
536
537 nla_nest_end(msg, nl_rates);
538
539 nla_nest_end(msg, nl_band);
540 }
541 nla_nest_end(msg, nl_bands);
542
543 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
544 if (!nl_cmds)
545 goto nla_put_failure;
546
547 i = 0;
548 #define CMD(op, n) \
549 do { \
550 if (dev->ops->op) { \
551 i++; \
552 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
553 } \
554 } while (0)
555
556 CMD(add_virtual_intf, NEW_INTERFACE);
557 CMD(change_virtual_intf, SET_INTERFACE);
558 CMD(add_key, NEW_KEY);
559 CMD(add_beacon, NEW_BEACON);
560 CMD(add_station, NEW_STATION);
561 CMD(add_mpath, NEW_MPATH);
562 CMD(set_mesh_params, SET_MESH_PARAMS);
563 CMD(change_bss, SET_BSS);
564 CMD(auth, AUTHENTICATE);
565 CMD(assoc, ASSOCIATE);
566 CMD(deauth, DEAUTHENTICATE);
567 CMD(disassoc, DISASSOCIATE);
568 CMD(join_ibss, JOIN_IBSS);
569 CMD(set_pmksa, SET_PMKSA);
570 CMD(del_pmksa, DEL_PMKSA);
571 CMD(flush_pmksa, FLUSH_PMKSA);
572 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
573 i++;
574 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
575 }
576
577 #undef CMD
578
579 if (dev->ops->connect || dev->ops->auth) {
580 i++;
581 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
582 }
583
584 if (dev->ops->disconnect || dev->ops->deauth) {
585 i++;
586 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
587 }
588
589 nla_nest_end(msg, nl_cmds);
590
591 return genlmsg_end(msg, hdr);
592
593 nla_put_failure:
594 genlmsg_cancel(msg, hdr);
595 return -EMSGSIZE;
596 }
597
598 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
599 {
600 int idx = 0;
601 int start = cb->args[0];
602 struct cfg80211_registered_device *dev;
603
604 mutex_lock(&cfg80211_mutex);
605 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
606 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
607 continue;
608 if (++idx <= start)
609 continue;
610 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
611 cb->nlh->nlmsg_seq, NLM_F_MULTI,
612 dev) < 0) {
613 idx--;
614 break;
615 }
616 }
617 mutex_unlock(&cfg80211_mutex);
618
619 cb->args[0] = idx;
620
621 return skb->len;
622 }
623
624 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
625 {
626 struct sk_buff *msg;
627 struct cfg80211_registered_device *dev;
628
629 dev = cfg80211_get_dev_from_info(info);
630 if (IS_ERR(dev))
631 return PTR_ERR(dev);
632
633 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
634 if (!msg)
635 goto out_err;
636
637 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
638 goto out_free;
639
640 cfg80211_unlock_rdev(dev);
641
642 return genlmsg_reply(msg, info);
643
644 out_free:
645 nlmsg_free(msg);
646 out_err:
647 cfg80211_unlock_rdev(dev);
648 return -ENOBUFS;
649 }
650
651 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
652 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
653 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
654 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
655 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
656 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
657 };
658
659 static int parse_txq_params(struct nlattr *tb[],
660 struct ieee80211_txq_params *txq_params)
661 {
662 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
663 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
664 !tb[NL80211_TXQ_ATTR_AIFS])
665 return -EINVAL;
666
667 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
668 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
669 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
670 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
671 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
672
673 return 0;
674 }
675
676 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
677 {
678 struct cfg80211_registered_device *rdev;
679 int result = 0, rem_txq_params = 0;
680 struct nlattr *nl_txq_params;
681 u32 changed;
682 u8 retry_short = 0, retry_long = 0;
683 u32 frag_threshold = 0, rts_threshold = 0;
684
685 rtnl_lock();
686
687 mutex_lock(&cfg80211_mutex);
688
689 rdev = __cfg80211_rdev_from_info(info);
690 if (IS_ERR(rdev)) {
691 mutex_unlock(&cfg80211_mutex);
692 result = PTR_ERR(rdev);
693 goto unlock;
694 }
695
696 mutex_lock(&rdev->mtx);
697
698 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
699 result = cfg80211_dev_rename(
700 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
701
702 mutex_unlock(&cfg80211_mutex);
703
704 if (result)
705 goto bad_res;
706
707 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
708 struct ieee80211_txq_params txq_params;
709 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
710
711 if (!rdev->ops->set_txq_params) {
712 result = -EOPNOTSUPP;
713 goto bad_res;
714 }
715
716 nla_for_each_nested(nl_txq_params,
717 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
718 rem_txq_params) {
719 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
720 nla_data(nl_txq_params),
721 nla_len(nl_txq_params),
722 txq_params_policy);
723 result = parse_txq_params(tb, &txq_params);
724 if (result)
725 goto bad_res;
726
727 result = rdev->ops->set_txq_params(&rdev->wiphy,
728 &txq_params);
729 if (result)
730 goto bad_res;
731 }
732 }
733
734 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
735 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
736 u32 freq;
737
738 result = -EINVAL;
739
740 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
741 channel_type = nla_get_u32(info->attrs[
742 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
743 if (channel_type != NL80211_CHAN_NO_HT &&
744 channel_type != NL80211_CHAN_HT20 &&
745 channel_type != NL80211_CHAN_HT40PLUS &&
746 channel_type != NL80211_CHAN_HT40MINUS)
747 goto bad_res;
748 }
749
750 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
751
752 mutex_lock(&rdev->devlist_mtx);
753 result = rdev_set_freq(rdev, NULL, freq, channel_type);
754 mutex_unlock(&rdev->devlist_mtx);
755 if (result)
756 goto bad_res;
757 }
758
759 changed = 0;
760
761 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
762 retry_short = nla_get_u8(
763 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
764 if (retry_short == 0) {
765 result = -EINVAL;
766 goto bad_res;
767 }
768 changed |= WIPHY_PARAM_RETRY_SHORT;
769 }
770
771 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
772 retry_long = nla_get_u8(
773 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
774 if (retry_long == 0) {
775 result = -EINVAL;
776 goto bad_res;
777 }
778 changed |= WIPHY_PARAM_RETRY_LONG;
779 }
780
781 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
782 frag_threshold = nla_get_u32(
783 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
784 if (frag_threshold < 256) {
785 result = -EINVAL;
786 goto bad_res;
787 }
788 if (frag_threshold != (u32) -1) {
789 /*
790 * Fragments (apart from the last one) are required to
791 * have even length. Make the fragmentation code
792 * simpler by stripping LSB should someone try to use
793 * odd threshold value.
794 */
795 frag_threshold &= ~0x1;
796 }
797 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
798 }
799
800 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
801 rts_threshold = nla_get_u32(
802 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
803 changed |= WIPHY_PARAM_RTS_THRESHOLD;
804 }
805
806 if (changed) {
807 u8 old_retry_short, old_retry_long;
808 u32 old_frag_threshold, old_rts_threshold;
809
810 if (!rdev->ops->set_wiphy_params) {
811 result = -EOPNOTSUPP;
812 goto bad_res;
813 }
814
815 old_retry_short = rdev->wiphy.retry_short;
816 old_retry_long = rdev->wiphy.retry_long;
817 old_frag_threshold = rdev->wiphy.frag_threshold;
818 old_rts_threshold = rdev->wiphy.rts_threshold;
819
820 if (changed & WIPHY_PARAM_RETRY_SHORT)
821 rdev->wiphy.retry_short = retry_short;
822 if (changed & WIPHY_PARAM_RETRY_LONG)
823 rdev->wiphy.retry_long = retry_long;
824 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
825 rdev->wiphy.frag_threshold = frag_threshold;
826 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
827 rdev->wiphy.rts_threshold = rts_threshold;
828
829 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
830 if (result) {
831 rdev->wiphy.retry_short = old_retry_short;
832 rdev->wiphy.retry_long = old_retry_long;
833 rdev->wiphy.frag_threshold = old_frag_threshold;
834 rdev->wiphy.rts_threshold = old_rts_threshold;
835 }
836 }
837
838 bad_res:
839 mutex_unlock(&rdev->mtx);
840 unlock:
841 rtnl_unlock();
842 return result;
843 }
844
845
846 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
847 struct cfg80211_registered_device *rdev,
848 struct net_device *dev)
849 {
850 void *hdr;
851
852 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
853 if (!hdr)
854 return -1;
855
856 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
857 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
858 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
859 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
860
861 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
862 rdev->devlist_generation ^
863 (cfg80211_rdev_list_generation << 2));
864
865 return genlmsg_end(msg, hdr);
866
867 nla_put_failure:
868 genlmsg_cancel(msg, hdr);
869 return -EMSGSIZE;
870 }
871
872 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
873 {
874 int wp_idx = 0;
875 int if_idx = 0;
876 int wp_start = cb->args[0];
877 int if_start = cb->args[1];
878 struct cfg80211_registered_device *rdev;
879 struct wireless_dev *wdev;
880
881 mutex_lock(&cfg80211_mutex);
882 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
883 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
884 continue;
885 if (wp_idx < wp_start) {
886 wp_idx++;
887 continue;
888 }
889 if_idx = 0;
890
891 mutex_lock(&rdev->devlist_mtx);
892 list_for_each_entry(wdev, &rdev->netdev_list, list) {
893 if (if_idx < if_start) {
894 if_idx++;
895 continue;
896 }
897 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
898 cb->nlh->nlmsg_seq, NLM_F_MULTI,
899 rdev, wdev->netdev) < 0) {
900 mutex_unlock(&rdev->devlist_mtx);
901 goto out;
902 }
903 if_idx++;
904 }
905 mutex_unlock(&rdev->devlist_mtx);
906
907 wp_idx++;
908 }
909 out:
910 mutex_unlock(&cfg80211_mutex);
911
912 cb->args[0] = wp_idx;
913 cb->args[1] = if_idx;
914
915 return skb->len;
916 }
917
918 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
919 {
920 struct sk_buff *msg;
921 struct cfg80211_registered_device *dev;
922 struct net_device *netdev;
923 int err;
924
925 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
926 if (err)
927 return err;
928
929 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
930 if (!msg)
931 goto out_err;
932
933 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
934 dev, netdev) < 0)
935 goto out_free;
936
937 dev_put(netdev);
938 cfg80211_unlock_rdev(dev);
939
940 return genlmsg_reply(msg, info);
941
942 out_free:
943 nlmsg_free(msg);
944 out_err:
945 dev_put(netdev);
946 cfg80211_unlock_rdev(dev);
947 return -ENOBUFS;
948 }
949
950 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
951 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
952 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
953 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
954 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
955 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
956 };
957
958 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
959 {
960 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
961 int flag;
962
963 *mntrflags = 0;
964
965 if (!nla)
966 return -EINVAL;
967
968 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
969 nla, mntr_flags_policy))
970 return -EINVAL;
971
972 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
973 if (flags[flag])
974 *mntrflags |= (1<<flag);
975
976 return 0;
977 }
978
979 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
980 struct net_device *netdev, u8 use_4addr,
981 enum nl80211_iftype iftype)
982 {
983 if (!use_4addr) {
984 if (netdev && netdev->br_port)
985 return -EBUSY;
986 return 0;
987 }
988
989 switch (iftype) {
990 case NL80211_IFTYPE_AP_VLAN:
991 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
992 return 0;
993 break;
994 case NL80211_IFTYPE_STATION:
995 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
996 return 0;
997 break;
998 default:
999 break;
1000 }
1001
1002 return -EOPNOTSUPP;
1003 }
1004
1005 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1006 {
1007 struct cfg80211_registered_device *rdev;
1008 struct vif_params params;
1009 int err;
1010 enum nl80211_iftype otype, ntype;
1011 struct net_device *dev;
1012 u32 _flags, *flags = NULL;
1013 bool change = false;
1014
1015 memset(&params, 0, sizeof(params));
1016
1017 rtnl_lock();
1018
1019 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1020 if (err)
1021 goto unlock_rtnl;
1022
1023 otype = ntype = dev->ieee80211_ptr->iftype;
1024
1025 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1026 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1027 if (otype != ntype)
1028 change = true;
1029 if (ntype > NL80211_IFTYPE_MAX) {
1030 err = -EINVAL;
1031 goto unlock;
1032 }
1033 }
1034
1035 if (info->attrs[NL80211_ATTR_MESH_ID]) {
1036 if (ntype != NL80211_IFTYPE_MESH_POINT) {
1037 err = -EINVAL;
1038 goto unlock;
1039 }
1040 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1041 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1042 change = true;
1043 }
1044
1045 if (info->attrs[NL80211_ATTR_4ADDR]) {
1046 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1047 change = true;
1048 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1049 if (err)
1050 goto unlock;
1051 } else {
1052 params.use_4addr = -1;
1053 }
1054
1055 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1056 if (ntype != NL80211_IFTYPE_MONITOR) {
1057 err = -EINVAL;
1058 goto unlock;
1059 }
1060 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1061 &_flags);
1062 if (err)
1063 goto unlock;
1064
1065 flags = &_flags;
1066 change = true;
1067 }
1068
1069 if (change)
1070 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1071 else
1072 err = 0;
1073
1074 if (!err && params.use_4addr != -1)
1075 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1076
1077 unlock:
1078 dev_put(dev);
1079 cfg80211_unlock_rdev(rdev);
1080 unlock_rtnl:
1081 rtnl_unlock();
1082 return err;
1083 }
1084
1085 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1086 {
1087 struct cfg80211_registered_device *rdev;
1088 struct vif_params params;
1089 int err;
1090 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1091 u32 flags;
1092
1093 memset(&params, 0, sizeof(params));
1094
1095 if (!info->attrs[NL80211_ATTR_IFNAME])
1096 return -EINVAL;
1097
1098 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1099 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1100 if (type > NL80211_IFTYPE_MAX)
1101 return -EINVAL;
1102 }
1103
1104 rtnl_lock();
1105
1106 rdev = cfg80211_get_dev_from_info(info);
1107 if (IS_ERR(rdev)) {
1108 err = PTR_ERR(rdev);
1109 goto unlock_rtnl;
1110 }
1111
1112 if (!rdev->ops->add_virtual_intf ||
1113 !(rdev->wiphy.interface_modes & (1 << type))) {
1114 err = -EOPNOTSUPP;
1115 goto unlock;
1116 }
1117
1118 if (type == NL80211_IFTYPE_MESH_POINT &&
1119 info->attrs[NL80211_ATTR_MESH_ID]) {
1120 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1121 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1122 }
1123
1124 if (info->attrs[NL80211_ATTR_4ADDR]) {
1125 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1126 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1127 if (err)
1128 goto unlock;
1129 }
1130
1131 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1132 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1133 &flags);
1134 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1135 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1136 type, err ? NULL : &flags, &params);
1137
1138 unlock:
1139 cfg80211_unlock_rdev(rdev);
1140 unlock_rtnl:
1141 rtnl_unlock();
1142 return err;
1143 }
1144
1145 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1146 {
1147 struct cfg80211_registered_device *rdev;
1148 int err;
1149 struct net_device *dev;
1150
1151 rtnl_lock();
1152
1153 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1154 if (err)
1155 goto unlock_rtnl;
1156
1157 if (!rdev->ops->del_virtual_intf) {
1158 err = -EOPNOTSUPP;
1159 goto out;
1160 }
1161
1162 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1163
1164 out:
1165 cfg80211_unlock_rdev(rdev);
1166 dev_put(dev);
1167 unlock_rtnl:
1168 rtnl_unlock();
1169 return err;
1170 }
1171
1172 struct get_key_cookie {
1173 struct sk_buff *msg;
1174 int error;
1175 int idx;
1176 };
1177
1178 static void get_key_callback(void *c, struct key_params *params)
1179 {
1180 struct nlattr *key;
1181 struct get_key_cookie *cookie = c;
1182
1183 if (params->key)
1184 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1185 params->key_len, params->key);
1186
1187 if (params->seq)
1188 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1189 params->seq_len, params->seq);
1190
1191 if (params->cipher)
1192 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1193 params->cipher);
1194
1195 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1196 if (!key)
1197 goto nla_put_failure;
1198
1199 if (params->key)
1200 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1201 params->key_len, params->key);
1202
1203 if (params->seq)
1204 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1205 params->seq_len, params->seq);
1206
1207 if (params->cipher)
1208 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1209 params->cipher);
1210
1211 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1212
1213 nla_nest_end(cookie->msg, key);
1214
1215 return;
1216 nla_put_failure:
1217 cookie->error = 1;
1218 }
1219
1220 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1221 {
1222 struct cfg80211_registered_device *rdev;
1223 int err;
1224 struct net_device *dev;
1225 u8 key_idx = 0;
1226 u8 *mac_addr = NULL;
1227 struct get_key_cookie cookie = {
1228 .error = 0,
1229 };
1230 void *hdr;
1231 struct sk_buff *msg;
1232
1233 if (info->attrs[NL80211_ATTR_KEY_IDX])
1234 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1235
1236 if (key_idx > 5)
1237 return -EINVAL;
1238
1239 if (info->attrs[NL80211_ATTR_MAC])
1240 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1241
1242 rtnl_lock();
1243
1244 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1245 if (err)
1246 goto unlock_rtnl;
1247
1248 if (!rdev->ops->get_key) {
1249 err = -EOPNOTSUPP;
1250 goto out;
1251 }
1252
1253 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1254 if (!msg) {
1255 err = -ENOMEM;
1256 goto out;
1257 }
1258
1259 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1260 NL80211_CMD_NEW_KEY);
1261
1262 if (IS_ERR(hdr)) {
1263 err = PTR_ERR(hdr);
1264 goto free_msg;
1265 }
1266
1267 cookie.msg = msg;
1268 cookie.idx = key_idx;
1269
1270 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1271 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1272 if (mac_addr)
1273 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1274
1275 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
1276 &cookie, get_key_callback);
1277
1278 if (err)
1279 goto free_msg;
1280
1281 if (cookie.error)
1282 goto nla_put_failure;
1283
1284 genlmsg_end(msg, hdr);
1285 err = genlmsg_reply(msg, info);
1286 goto out;
1287
1288 nla_put_failure:
1289 err = -ENOBUFS;
1290 free_msg:
1291 nlmsg_free(msg);
1292 out:
1293 cfg80211_unlock_rdev(rdev);
1294 dev_put(dev);
1295 unlock_rtnl:
1296 rtnl_unlock();
1297
1298 return err;
1299 }
1300
1301 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1302 {
1303 struct cfg80211_registered_device *rdev;
1304 struct key_parse key;
1305 int err;
1306 struct net_device *dev;
1307 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1308 u8 key_index);
1309
1310 err = nl80211_parse_key(info, &key);
1311 if (err)
1312 return err;
1313
1314 if (key.idx < 0)
1315 return -EINVAL;
1316
1317 /* only support setting default key */
1318 if (!key.def && !key.defmgmt)
1319 return -EINVAL;
1320
1321 rtnl_lock();
1322
1323 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1324 if (err)
1325 goto unlock_rtnl;
1326
1327 if (key.def)
1328 func = rdev->ops->set_default_key;
1329 else
1330 func = rdev->ops->set_default_mgmt_key;
1331
1332 if (!func) {
1333 err = -EOPNOTSUPP;
1334 goto out;
1335 }
1336
1337 wdev_lock(dev->ieee80211_ptr);
1338 err = nl80211_key_allowed(dev->ieee80211_ptr);
1339 if (!err)
1340 err = func(&rdev->wiphy, dev, key.idx);
1341
1342 #ifdef CONFIG_CFG80211_WEXT
1343 if (!err) {
1344 if (func == rdev->ops->set_default_key)
1345 dev->ieee80211_ptr->wext.default_key = key.idx;
1346 else
1347 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1348 }
1349 #endif
1350 wdev_unlock(dev->ieee80211_ptr);
1351
1352 out:
1353 cfg80211_unlock_rdev(rdev);
1354 dev_put(dev);
1355
1356 unlock_rtnl:
1357 rtnl_unlock();
1358
1359 return err;
1360 }
1361
1362 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1363 {
1364 struct cfg80211_registered_device *rdev;
1365 int err;
1366 struct net_device *dev;
1367 struct key_parse key;
1368 u8 *mac_addr = NULL;
1369
1370 err = nl80211_parse_key(info, &key);
1371 if (err)
1372 return err;
1373
1374 if (!key.p.key)
1375 return -EINVAL;
1376
1377 if (info->attrs[NL80211_ATTR_MAC])
1378 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1379
1380 rtnl_lock();
1381
1382 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1383 if (err)
1384 goto unlock_rtnl;
1385
1386 if (!rdev->ops->add_key) {
1387 err = -EOPNOTSUPP;
1388 goto out;
1389 }
1390
1391 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1392 err = -EINVAL;
1393 goto out;
1394 }
1395
1396 wdev_lock(dev->ieee80211_ptr);
1397 err = nl80211_key_allowed(dev->ieee80211_ptr);
1398 if (!err)
1399 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1400 mac_addr, &key.p);
1401 wdev_unlock(dev->ieee80211_ptr);
1402
1403 out:
1404 cfg80211_unlock_rdev(rdev);
1405 dev_put(dev);
1406 unlock_rtnl:
1407 rtnl_unlock();
1408
1409 return err;
1410 }
1411
1412 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1413 {
1414 struct cfg80211_registered_device *rdev;
1415 int err;
1416 struct net_device *dev;
1417 u8 *mac_addr = NULL;
1418 struct key_parse key;
1419
1420 err = nl80211_parse_key(info, &key);
1421 if (err)
1422 return err;
1423
1424 if (info->attrs[NL80211_ATTR_MAC])
1425 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1426
1427 rtnl_lock();
1428
1429 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1430 if (err)
1431 goto unlock_rtnl;
1432
1433 if (!rdev->ops->del_key) {
1434 err = -EOPNOTSUPP;
1435 goto out;
1436 }
1437
1438 wdev_lock(dev->ieee80211_ptr);
1439 err = nl80211_key_allowed(dev->ieee80211_ptr);
1440 if (!err)
1441 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
1442
1443 #ifdef CONFIG_CFG80211_WEXT
1444 if (!err) {
1445 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1446 dev->ieee80211_ptr->wext.default_key = -1;
1447 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1448 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1449 }
1450 #endif
1451 wdev_unlock(dev->ieee80211_ptr);
1452
1453 out:
1454 cfg80211_unlock_rdev(rdev);
1455 dev_put(dev);
1456
1457 unlock_rtnl:
1458 rtnl_unlock();
1459
1460 return err;
1461 }
1462
1463 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1464 {
1465 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1466 struct beacon_parameters *info);
1467 struct cfg80211_registered_device *rdev;
1468 int err;
1469 struct net_device *dev;
1470 struct beacon_parameters params;
1471 int haveinfo = 0;
1472
1473 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1474 return -EINVAL;
1475
1476 rtnl_lock();
1477
1478 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1479 if (err)
1480 goto unlock_rtnl;
1481
1482 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1483 err = -EOPNOTSUPP;
1484 goto out;
1485 }
1486
1487 switch (info->genlhdr->cmd) {
1488 case NL80211_CMD_NEW_BEACON:
1489 /* these are required for NEW_BEACON */
1490 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1491 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1492 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1493 err = -EINVAL;
1494 goto out;
1495 }
1496
1497 call = rdev->ops->add_beacon;
1498 break;
1499 case NL80211_CMD_SET_BEACON:
1500 call = rdev->ops->set_beacon;
1501 break;
1502 default:
1503 WARN_ON(1);
1504 err = -EOPNOTSUPP;
1505 goto out;
1506 }
1507
1508 if (!call) {
1509 err = -EOPNOTSUPP;
1510 goto out;
1511 }
1512
1513 memset(&params, 0, sizeof(params));
1514
1515 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1516 params.interval =
1517 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1518 haveinfo = 1;
1519 }
1520
1521 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1522 params.dtim_period =
1523 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1524 haveinfo = 1;
1525 }
1526
1527 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1528 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1529 params.head_len =
1530 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1531 haveinfo = 1;
1532 }
1533
1534 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1535 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1536 params.tail_len =
1537 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1538 haveinfo = 1;
1539 }
1540
1541 if (!haveinfo) {
1542 err = -EINVAL;
1543 goto out;
1544 }
1545
1546 err = call(&rdev->wiphy, dev, &params);
1547
1548 out:
1549 cfg80211_unlock_rdev(rdev);
1550 dev_put(dev);
1551 unlock_rtnl:
1552 rtnl_unlock();
1553
1554 return err;
1555 }
1556
1557 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1558 {
1559 struct cfg80211_registered_device *rdev;
1560 int err;
1561 struct net_device *dev;
1562
1563 rtnl_lock();
1564
1565 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1566 if (err)
1567 goto unlock_rtnl;
1568
1569 if (!rdev->ops->del_beacon) {
1570 err = -EOPNOTSUPP;
1571 goto out;
1572 }
1573
1574 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1575 err = -EOPNOTSUPP;
1576 goto out;
1577 }
1578 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
1579
1580 out:
1581 cfg80211_unlock_rdev(rdev);
1582 dev_put(dev);
1583 unlock_rtnl:
1584 rtnl_unlock();
1585
1586 return err;
1587 }
1588
1589 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1590 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1591 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1592 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1593 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1594 };
1595
1596 static int parse_station_flags(struct genl_info *info,
1597 struct station_parameters *params)
1598 {
1599 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1600 struct nlattr *nla;
1601 int flag;
1602
1603 /*
1604 * Try parsing the new attribute first so userspace
1605 * can specify both for older kernels.
1606 */
1607 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1608 if (nla) {
1609 struct nl80211_sta_flag_update *sta_flags;
1610
1611 sta_flags = nla_data(nla);
1612 params->sta_flags_mask = sta_flags->mask;
1613 params->sta_flags_set = sta_flags->set;
1614 if ((params->sta_flags_mask |
1615 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1616 return -EINVAL;
1617 return 0;
1618 }
1619
1620 /* if present, parse the old attribute */
1621
1622 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1623 if (!nla)
1624 return 0;
1625
1626 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1627 nla, sta_flags_policy))
1628 return -EINVAL;
1629
1630 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1631 params->sta_flags_mask &= ~1;
1632
1633 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1634 if (flags[flag])
1635 params->sta_flags_set |= (1<<flag);
1636
1637 return 0;
1638 }
1639
1640 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1641 int flags, struct net_device *dev,
1642 u8 *mac_addr, struct station_info *sinfo)
1643 {
1644 void *hdr;
1645 struct nlattr *sinfoattr, *txrate;
1646 u16 bitrate;
1647
1648 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1649 if (!hdr)
1650 return -1;
1651
1652 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1653 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1654
1655 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1656
1657 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1658 if (!sinfoattr)
1659 goto nla_put_failure;
1660 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1661 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1662 sinfo->inactive_time);
1663 if (sinfo->filled & STATION_INFO_RX_BYTES)
1664 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1665 sinfo->rx_bytes);
1666 if (sinfo->filled & STATION_INFO_TX_BYTES)
1667 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1668 sinfo->tx_bytes);
1669 if (sinfo->filled & STATION_INFO_LLID)
1670 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1671 sinfo->llid);
1672 if (sinfo->filled & STATION_INFO_PLID)
1673 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1674 sinfo->plid);
1675 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1676 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1677 sinfo->plink_state);
1678 if (sinfo->filled & STATION_INFO_SIGNAL)
1679 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1680 sinfo->signal);
1681 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1682 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1683 if (!txrate)
1684 goto nla_put_failure;
1685
1686 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1687 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
1688 if (bitrate > 0)
1689 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1690
1691 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1692 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1693 sinfo->txrate.mcs);
1694 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1695 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1696 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1697 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1698
1699 nla_nest_end(msg, txrate);
1700 }
1701 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1702 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1703 sinfo->rx_packets);
1704 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1705 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1706 sinfo->tx_packets);
1707 nla_nest_end(msg, sinfoattr);
1708
1709 return genlmsg_end(msg, hdr);
1710
1711 nla_put_failure:
1712 genlmsg_cancel(msg, hdr);
1713 return -EMSGSIZE;
1714 }
1715
1716 static int nl80211_dump_station(struct sk_buff *skb,
1717 struct netlink_callback *cb)
1718 {
1719 struct station_info sinfo;
1720 struct cfg80211_registered_device *dev;
1721 struct net_device *netdev;
1722 u8 mac_addr[ETH_ALEN];
1723 int ifidx = cb->args[0];
1724 int sta_idx = cb->args[1];
1725 int err;
1726
1727 if (!ifidx)
1728 ifidx = nl80211_get_ifidx(cb);
1729 if (ifidx < 0)
1730 return ifidx;
1731
1732 rtnl_lock();
1733
1734 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
1735 if (!netdev) {
1736 err = -ENODEV;
1737 goto out_rtnl;
1738 }
1739
1740 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
1741 if (IS_ERR(dev)) {
1742 err = PTR_ERR(dev);
1743 goto out_rtnl;
1744 }
1745
1746 if (!dev->ops->dump_station) {
1747 err = -EOPNOTSUPP;
1748 goto out_err;
1749 }
1750
1751 while (1) {
1752 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1753 mac_addr, &sinfo);
1754 if (err == -ENOENT)
1755 break;
1756 if (err)
1757 goto out_err;
1758
1759 if (nl80211_send_station(skb,
1760 NETLINK_CB(cb->skb).pid,
1761 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1762 netdev, mac_addr,
1763 &sinfo) < 0)
1764 goto out;
1765
1766 sta_idx++;
1767 }
1768
1769
1770 out:
1771 cb->args[1] = sta_idx;
1772 err = skb->len;
1773 out_err:
1774 cfg80211_unlock_rdev(dev);
1775 out_rtnl:
1776 rtnl_unlock();
1777
1778 return err;
1779 }
1780
1781 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1782 {
1783 struct cfg80211_registered_device *rdev;
1784 int err;
1785 struct net_device *dev;
1786 struct station_info sinfo;
1787 struct sk_buff *msg;
1788 u8 *mac_addr = NULL;
1789
1790 memset(&sinfo, 0, sizeof(sinfo));
1791
1792 if (!info->attrs[NL80211_ATTR_MAC])
1793 return -EINVAL;
1794
1795 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1796
1797 rtnl_lock();
1798
1799 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1800 if (err)
1801 goto out_rtnl;
1802
1803 if (!rdev->ops->get_station) {
1804 err = -EOPNOTSUPP;
1805 goto out;
1806 }
1807
1808 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
1809 if (err)
1810 goto out;
1811
1812 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1813 if (!msg)
1814 goto out;
1815
1816 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1817 dev, mac_addr, &sinfo) < 0)
1818 goto out_free;
1819
1820 err = genlmsg_reply(msg, info);
1821 goto out;
1822
1823 out_free:
1824 nlmsg_free(msg);
1825 out:
1826 cfg80211_unlock_rdev(rdev);
1827 dev_put(dev);
1828 out_rtnl:
1829 rtnl_unlock();
1830
1831 return err;
1832 }
1833
1834 /*
1835 * Get vlan interface making sure it is running and on the right wiphy.
1836 */
1837 static int get_vlan(struct genl_info *info,
1838 struct cfg80211_registered_device *rdev,
1839 struct net_device **vlan)
1840 {
1841 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
1842 *vlan = NULL;
1843
1844 if (vlanattr) {
1845 *vlan = dev_get_by_index(genl_info_net(info),
1846 nla_get_u32(vlanattr));
1847 if (!*vlan)
1848 return -ENODEV;
1849 if (!(*vlan)->ieee80211_ptr)
1850 return -EINVAL;
1851 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1852 return -EINVAL;
1853 if (!netif_running(*vlan))
1854 return -ENETDOWN;
1855 }
1856 return 0;
1857 }
1858
1859 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1860 {
1861 struct cfg80211_registered_device *rdev;
1862 int err;
1863 struct net_device *dev;
1864 struct station_parameters params;
1865 u8 *mac_addr = NULL;
1866
1867 memset(&params, 0, sizeof(params));
1868
1869 params.listen_interval = -1;
1870
1871 if (info->attrs[NL80211_ATTR_STA_AID])
1872 return -EINVAL;
1873
1874 if (!info->attrs[NL80211_ATTR_MAC])
1875 return -EINVAL;
1876
1877 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1878
1879 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1880 params.supported_rates =
1881 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1882 params.supported_rates_len =
1883 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1884 }
1885
1886 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1887 params.listen_interval =
1888 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1889
1890 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1891 params.ht_capa =
1892 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1893
1894 if (parse_station_flags(info, &params))
1895 return -EINVAL;
1896
1897 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1898 params.plink_action =
1899 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1900
1901 rtnl_lock();
1902
1903 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1904 if (err)
1905 goto out_rtnl;
1906
1907 err = get_vlan(info, rdev, &params.vlan);
1908 if (err)
1909 goto out;
1910
1911 /* validate settings */
1912 err = 0;
1913
1914 switch (dev->ieee80211_ptr->iftype) {
1915 case NL80211_IFTYPE_AP:
1916 case NL80211_IFTYPE_AP_VLAN:
1917 /* disallow mesh-specific things */
1918 if (params.plink_action)
1919 err = -EINVAL;
1920 break;
1921 case NL80211_IFTYPE_STATION:
1922 /* disallow everything but AUTHORIZED flag */
1923 if (params.plink_action)
1924 err = -EINVAL;
1925 if (params.vlan)
1926 err = -EINVAL;
1927 if (params.supported_rates)
1928 err = -EINVAL;
1929 if (params.ht_capa)
1930 err = -EINVAL;
1931 if (params.listen_interval >= 0)
1932 err = -EINVAL;
1933 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1934 err = -EINVAL;
1935 break;
1936 case NL80211_IFTYPE_MESH_POINT:
1937 /* disallow things mesh doesn't support */
1938 if (params.vlan)
1939 err = -EINVAL;
1940 if (params.ht_capa)
1941 err = -EINVAL;
1942 if (params.listen_interval >= 0)
1943 err = -EINVAL;
1944 if (params.supported_rates)
1945 err = -EINVAL;
1946 if (params.sta_flags_mask)
1947 err = -EINVAL;
1948 break;
1949 default:
1950 err = -EINVAL;
1951 }
1952
1953 if (err)
1954 goto out;
1955
1956 if (!rdev->ops->change_station) {
1957 err = -EOPNOTSUPP;
1958 goto out;
1959 }
1960
1961 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
1962
1963 out:
1964 if (params.vlan)
1965 dev_put(params.vlan);
1966 cfg80211_unlock_rdev(rdev);
1967 dev_put(dev);
1968 out_rtnl:
1969 rtnl_unlock();
1970
1971 return err;
1972 }
1973
1974 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1975 {
1976 struct cfg80211_registered_device *rdev;
1977 int err;
1978 struct net_device *dev;
1979 struct station_parameters params;
1980 u8 *mac_addr = NULL;
1981
1982 memset(&params, 0, sizeof(params));
1983
1984 if (!info->attrs[NL80211_ATTR_MAC])
1985 return -EINVAL;
1986
1987 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1988 return -EINVAL;
1989
1990 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1991 return -EINVAL;
1992
1993 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1994 params.supported_rates =
1995 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1996 params.supported_rates_len =
1997 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1998 params.listen_interval =
1999 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2000
2001 if (info->attrs[NL80211_ATTR_STA_AID]) {
2002 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2003 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2004 return -EINVAL;
2005 }
2006
2007 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2008 params.ht_capa =
2009 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2010
2011 if (parse_station_flags(info, &params))
2012 return -EINVAL;
2013
2014 rtnl_lock();
2015
2016 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2017 if (err)
2018 goto out_rtnl;
2019
2020 err = get_vlan(info, rdev, &params.vlan);
2021 if (err)
2022 goto out;
2023
2024 /* validate settings */
2025 err = 0;
2026
2027 switch (dev->ieee80211_ptr->iftype) {
2028 case NL80211_IFTYPE_AP:
2029 case NL80211_IFTYPE_AP_VLAN:
2030 /* all ok but must have AID */
2031 if (!params.aid)
2032 err = -EINVAL;
2033 break;
2034 case NL80211_IFTYPE_MESH_POINT:
2035 /* disallow things mesh doesn't support */
2036 if (params.vlan)
2037 err = -EINVAL;
2038 if (params.aid)
2039 err = -EINVAL;
2040 if (params.ht_capa)
2041 err = -EINVAL;
2042 if (params.listen_interval >= 0)
2043 err = -EINVAL;
2044 if (params.supported_rates)
2045 err = -EINVAL;
2046 if (params.sta_flags_mask)
2047 err = -EINVAL;
2048 break;
2049 default:
2050 err = -EINVAL;
2051 }
2052
2053 if (err)
2054 goto out;
2055
2056 if (!rdev->ops->add_station) {
2057 err = -EOPNOTSUPP;
2058 goto out;
2059 }
2060
2061 if (!netif_running(dev)) {
2062 err = -ENETDOWN;
2063 goto out;
2064 }
2065
2066 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2067
2068 out:
2069 if (params.vlan)
2070 dev_put(params.vlan);
2071 cfg80211_unlock_rdev(rdev);
2072 dev_put(dev);
2073 out_rtnl:
2074 rtnl_unlock();
2075
2076 return err;
2077 }
2078
2079 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2080 {
2081 struct cfg80211_registered_device *rdev;
2082 int err;
2083 struct net_device *dev;
2084 u8 *mac_addr = NULL;
2085
2086 if (info->attrs[NL80211_ATTR_MAC])
2087 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2088
2089 rtnl_lock();
2090
2091 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2092 if (err)
2093 goto out_rtnl;
2094
2095 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2096 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2097 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2098 err = -EINVAL;
2099 goto out;
2100 }
2101
2102 if (!rdev->ops->del_station) {
2103 err = -EOPNOTSUPP;
2104 goto out;
2105 }
2106
2107 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2108
2109 out:
2110 cfg80211_unlock_rdev(rdev);
2111 dev_put(dev);
2112 out_rtnl:
2113 rtnl_unlock();
2114
2115 return err;
2116 }
2117
2118 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2119 int flags, struct net_device *dev,
2120 u8 *dst, u8 *next_hop,
2121 struct mpath_info *pinfo)
2122 {
2123 void *hdr;
2124 struct nlattr *pinfoattr;
2125
2126 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2127 if (!hdr)
2128 return -1;
2129
2130 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2131 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2132 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2133
2134 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2135
2136 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2137 if (!pinfoattr)
2138 goto nla_put_failure;
2139 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2140 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2141 pinfo->frame_qlen);
2142 if (pinfo->filled & MPATH_INFO_SN)
2143 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2144 pinfo->sn);
2145 if (pinfo->filled & MPATH_INFO_METRIC)
2146 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2147 pinfo->metric);
2148 if (pinfo->filled & MPATH_INFO_EXPTIME)
2149 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2150 pinfo->exptime);
2151 if (pinfo->filled & MPATH_INFO_FLAGS)
2152 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2153 pinfo->flags);
2154 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2155 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2156 pinfo->discovery_timeout);
2157 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2158 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2159 pinfo->discovery_retries);
2160
2161 nla_nest_end(msg, pinfoattr);
2162
2163 return genlmsg_end(msg, hdr);
2164
2165 nla_put_failure:
2166 genlmsg_cancel(msg, hdr);
2167 return -EMSGSIZE;
2168 }
2169
2170 static int nl80211_dump_mpath(struct sk_buff *skb,
2171 struct netlink_callback *cb)
2172 {
2173 struct mpath_info pinfo;
2174 struct cfg80211_registered_device *dev;
2175 struct net_device *netdev;
2176 u8 dst[ETH_ALEN];
2177 u8 next_hop[ETH_ALEN];
2178 int ifidx = cb->args[0];
2179 int path_idx = cb->args[1];
2180 int err;
2181
2182 if (!ifidx)
2183 ifidx = nl80211_get_ifidx(cb);
2184 if (ifidx < 0)
2185 return ifidx;
2186
2187 rtnl_lock();
2188
2189 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
2190 if (!netdev) {
2191 err = -ENODEV;
2192 goto out_rtnl;
2193 }
2194
2195 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
2196 if (IS_ERR(dev)) {
2197 err = PTR_ERR(dev);
2198 goto out_rtnl;
2199 }
2200
2201 if (!dev->ops->dump_mpath) {
2202 err = -EOPNOTSUPP;
2203 goto out_err;
2204 }
2205
2206 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2207 err = -EOPNOTSUPP;
2208 goto out_err;
2209 }
2210
2211 while (1) {
2212 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2213 dst, next_hop, &pinfo);
2214 if (err == -ENOENT)
2215 break;
2216 if (err)
2217 goto out_err;
2218
2219 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2220 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2221 netdev, dst, next_hop,
2222 &pinfo) < 0)
2223 goto out;
2224
2225 path_idx++;
2226 }
2227
2228
2229 out:
2230 cb->args[1] = path_idx;
2231 err = skb->len;
2232 out_err:
2233 cfg80211_unlock_rdev(dev);
2234 out_rtnl:
2235 rtnl_unlock();
2236
2237 return err;
2238 }
2239
2240 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2241 {
2242 struct cfg80211_registered_device *rdev;
2243 int err;
2244 struct net_device *dev;
2245 struct mpath_info pinfo;
2246 struct sk_buff *msg;
2247 u8 *dst = NULL;
2248 u8 next_hop[ETH_ALEN];
2249
2250 memset(&pinfo, 0, sizeof(pinfo));
2251
2252 if (!info->attrs[NL80211_ATTR_MAC])
2253 return -EINVAL;
2254
2255 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2256
2257 rtnl_lock();
2258
2259 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2260 if (err)
2261 goto out_rtnl;
2262
2263 if (!rdev->ops->get_mpath) {
2264 err = -EOPNOTSUPP;
2265 goto out;
2266 }
2267
2268 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2269 err = -EOPNOTSUPP;
2270 goto out;
2271 }
2272
2273 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2274 if (err)
2275 goto out;
2276
2277 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2278 if (!msg)
2279 goto out;
2280
2281 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2282 dev, dst, next_hop, &pinfo) < 0)
2283 goto out_free;
2284
2285 err = genlmsg_reply(msg, info);
2286 goto out;
2287
2288 out_free:
2289 nlmsg_free(msg);
2290 out:
2291 cfg80211_unlock_rdev(rdev);
2292 dev_put(dev);
2293 out_rtnl:
2294 rtnl_unlock();
2295
2296 return err;
2297 }
2298
2299 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2300 {
2301 struct cfg80211_registered_device *rdev;
2302 int err;
2303 struct net_device *dev;
2304 u8 *dst = NULL;
2305 u8 *next_hop = NULL;
2306
2307 if (!info->attrs[NL80211_ATTR_MAC])
2308 return -EINVAL;
2309
2310 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2311 return -EINVAL;
2312
2313 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2314 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2315
2316 rtnl_lock();
2317
2318 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2319 if (err)
2320 goto out_rtnl;
2321
2322 if (!rdev->ops->change_mpath) {
2323 err = -EOPNOTSUPP;
2324 goto out;
2325 }
2326
2327 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2328 err = -EOPNOTSUPP;
2329 goto out;
2330 }
2331
2332 if (!netif_running(dev)) {
2333 err = -ENETDOWN;
2334 goto out;
2335 }
2336
2337 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2338
2339 out:
2340 cfg80211_unlock_rdev(rdev);
2341 dev_put(dev);
2342 out_rtnl:
2343 rtnl_unlock();
2344
2345 return err;
2346 }
2347 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2348 {
2349 struct cfg80211_registered_device *rdev;
2350 int err;
2351 struct net_device *dev;
2352 u8 *dst = NULL;
2353 u8 *next_hop = NULL;
2354
2355 if (!info->attrs[NL80211_ATTR_MAC])
2356 return -EINVAL;
2357
2358 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2359 return -EINVAL;
2360
2361 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2362 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2363
2364 rtnl_lock();
2365
2366 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2367 if (err)
2368 goto out_rtnl;
2369
2370 if (!rdev->ops->add_mpath) {
2371 err = -EOPNOTSUPP;
2372 goto out;
2373 }
2374
2375 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2376 err = -EOPNOTSUPP;
2377 goto out;
2378 }
2379
2380 if (!netif_running(dev)) {
2381 err = -ENETDOWN;
2382 goto out;
2383 }
2384
2385 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2386
2387 out:
2388 cfg80211_unlock_rdev(rdev);
2389 dev_put(dev);
2390 out_rtnl:
2391 rtnl_unlock();
2392
2393 return err;
2394 }
2395
2396 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2397 {
2398 struct cfg80211_registered_device *rdev;
2399 int err;
2400 struct net_device *dev;
2401 u8 *dst = NULL;
2402
2403 if (info->attrs[NL80211_ATTR_MAC])
2404 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2405
2406 rtnl_lock();
2407
2408 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2409 if (err)
2410 goto out_rtnl;
2411
2412 if (!rdev->ops->del_mpath) {
2413 err = -EOPNOTSUPP;
2414 goto out;
2415 }
2416
2417 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2418
2419 out:
2420 cfg80211_unlock_rdev(rdev);
2421 dev_put(dev);
2422 out_rtnl:
2423 rtnl_unlock();
2424
2425 return err;
2426 }
2427
2428 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2429 {
2430 struct cfg80211_registered_device *rdev;
2431 int err;
2432 struct net_device *dev;
2433 struct bss_parameters params;
2434
2435 memset(&params, 0, sizeof(params));
2436 /* default to not changing parameters */
2437 params.use_cts_prot = -1;
2438 params.use_short_preamble = -1;
2439 params.use_short_slot_time = -1;
2440
2441 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2442 params.use_cts_prot =
2443 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2444 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2445 params.use_short_preamble =
2446 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2447 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2448 params.use_short_slot_time =
2449 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2450 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2451 params.basic_rates =
2452 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2453 params.basic_rates_len =
2454 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2455 }
2456
2457 rtnl_lock();
2458
2459 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2460 if (err)
2461 goto out_rtnl;
2462
2463 if (!rdev->ops->change_bss) {
2464 err = -EOPNOTSUPP;
2465 goto out;
2466 }
2467
2468 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2469 err = -EOPNOTSUPP;
2470 goto out;
2471 }
2472
2473 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2474
2475 out:
2476 cfg80211_unlock_rdev(rdev);
2477 dev_put(dev);
2478 out_rtnl:
2479 rtnl_unlock();
2480
2481 return err;
2482 }
2483
2484 static const struct nla_policy
2485 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2486 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2487 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2488 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2489 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2490 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2491 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2492 };
2493
2494 static int parse_reg_rule(struct nlattr *tb[],
2495 struct ieee80211_reg_rule *reg_rule)
2496 {
2497 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2498 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2499
2500 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2501 return -EINVAL;
2502 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2503 return -EINVAL;
2504 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2505 return -EINVAL;
2506 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2507 return -EINVAL;
2508 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2509 return -EINVAL;
2510
2511 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2512
2513 freq_range->start_freq_khz =
2514 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2515 freq_range->end_freq_khz =
2516 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2517 freq_range->max_bandwidth_khz =
2518 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2519
2520 power_rule->max_eirp =
2521 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2522
2523 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2524 power_rule->max_antenna_gain =
2525 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2526
2527 return 0;
2528 }
2529
2530 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2531 {
2532 int r;
2533 char *data = NULL;
2534
2535 /*
2536 * You should only get this when cfg80211 hasn't yet initialized
2537 * completely when built-in to the kernel right between the time
2538 * window between nl80211_init() and regulatory_init(), if that is
2539 * even possible.
2540 */
2541 mutex_lock(&cfg80211_mutex);
2542 if (unlikely(!cfg80211_regdomain)) {
2543 mutex_unlock(&cfg80211_mutex);
2544 return -EINPROGRESS;
2545 }
2546 mutex_unlock(&cfg80211_mutex);
2547
2548 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2549 return -EINVAL;
2550
2551 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2552
2553 r = regulatory_hint_user(data);
2554
2555 return r;
2556 }
2557
2558 static int nl80211_get_mesh_params(struct sk_buff *skb,
2559 struct genl_info *info)
2560 {
2561 struct cfg80211_registered_device *rdev;
2562 struct mesh_config cur_params;
2563 int err;
2564 struct net_device *dev;
2565 void *hdr;
2566 struct nlattr *pinfoattr;
2567 struct sk_buff *msg;
2568
2569 rtnl_lock();
2570
2571 /* Look up our device */
2572 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2573 if (err)
2574 goto out_rtnl;
2575
2576 if (!rdev->ops->get_mesh_params) {
2577 err = -EOPNOTSUPP;
2578 goto out;
2579 }
2580
2581 /* Get the mesh params */
2582 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2583 if (err)
2584 goto out;
2585
2586 /* Draw up a netlink message to send back */
2587 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2588 if (!msg) {
2589 err = -ENOBUFS;
2590 goto out;
2591 }
2592 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2593 NL80211_CMD_GET_MESH_PARAMS);
2594 if (!hdr)
2595 goto nla_put_failure;
2596 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2597 if (!pinfoattr)
2598 goto nla_put_failure;
2599 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2600 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2601 cur_params.dot11MeshRetryTimeout);
2602 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2603 cur_params.dot11MeshConfirmTimeout);
2604 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2605 cur_params.dot11MeshHoldingTimeout);
2606 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2607 cur_params.dot11MeshMaxPeerLinks);
2608 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2609 cur_params.dot11MeshMaxRetries);
2610 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2611 cur_params.dot11MeshTTL);
2612 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2613 cur_params.auto_open_plinks);
2614 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2615 cur_params.dot11MeshHWMPmaxPREQretries);
2616 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2617 cur_params.path_refresh_time);
2618 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2619 cur_params.min_discovery_timeout);
2620 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2621 cur_params.dot11MeshHWMPactivePathTimeout);
2622 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2623 cur_params.dot11MeshHWMPpreqMinInterval);
2624 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2625 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2626 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2627 cur_params.dot11MeshHWMPRootMode);
2628 nla_nest_end(msg, pinfoattr);
2629 genlmsg_end(msg, hdr);
2630 err = genlmsg_reply(msg, info);
2631 goto out;
2632
2633 nla_put_failure:
2634 genlmsg_cancel(msg, hdr);
2635 err = -EMSGSIZE;
2636 out:
2637 /* Cleanup */
2638 cfg80211_unlock_rdev(rdev);
2639 dev_put(dev);
2640 out_rtnl:
2641 rtnl_unlock();
2642
2643 return err;
2644 }
2645
2646 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2647 do {\
2648 if (table[attr_num]) {\
2649 cfg.param = nla_fn(table[attr_num]); \
2650 mask |= (1 << (attr_num - 1)); \
2651 } \
2652 } while (0);\
2653
2654 static struct nla_policy
2655 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2656 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2657 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2658 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2659 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2660 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2661 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2662 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2663
2664 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2665 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2666 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2667 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2668 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2669 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2670 };
2671
2672 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2673 {
2674 int err;
2675 u32 mask;
2676 struct cfg80211_registered_device *rdev;
2677 struct net_device *dev;
2678 struct mesh_config cfg;
2679 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2680 struct nlattr *parent_attr;
2681
2682 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2683 if (!parent_attr)
2684 return -EINVAL;
2685 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2686 parent_attr, nl80211_meshconf_params_policy))
2687 return -EINVAL;
2688
2689 rtnl_lock();
2690
2691 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2692 if (err)
2693 goto out_rtnl;
2694
2695 if (!rdev->ops->set_mesh_params) {
2696 err = -EOPNOTSUPP;
2697 goto out;
2698 }
2699
2700 /* This makes sure that there aren't more than 32 mesh config
2701 * parameters (otherwise our bitfield scheme would not work.) */
2702 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2703
2704 /* Fill in the params struct */
2705 mask = 0;
2706 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2707 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2708 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2709 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2710 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2711 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2712 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2713 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2714 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2715 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2716 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2717 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2718 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2719 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2720 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2721 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2722 nla_get_u8);
2723 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2724 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2725 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2726 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2727 nla_get_u16);
2728 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2729 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2730 nla_get_u32);
2731 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2732 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2733 nla_get_u16);
2734 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2735 dot11MeshHWMPnetDiameterTraversalTime,
2736 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2737 nla_get_u16);
2738 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2739 dot11MeshHWMPRootMode, mask,
2740 NL80211_MESHCONF_HWMP_ROOTMODE,
2741 nla_get_u8);
2742
2743 /* Apply changes */
2744 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2745
2746 out:
2747 /* cleanup */
2748 cfg80211_unlock_rdev(rdev);
2749 dev_put(dev);
2750 out_rtnl:
2751 rtnl_unlock();
2752
2753 return err;
2754 }
2755
2756 #undef FILL_IN_MESH_PARAM_IF_SET
2757
2758 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2759 {
2760 struct sk_buff *msg;
2761 void *hdr = NULL;
2762 struct nlattr *nl_reg_rules;
2763 unsigned int i;
2764 int err = -EINVAL;
2765
2766 mutex_lock(&cfg80211_mutex);
2767
2768 if (!cfg80211_regdomain)
2769 goto out;
2770
2771 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2772 if (!msg) {
2773 err = -ENOBUFS;
2774 goto out;
2775 }
2776
2777 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2778 NL80211_CMD_GET_REG);
2779 if (!hdr)
2780 goto nla_put_failure;
2781
2782 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2783 cfg80211_regdomain->alpha2);
2784
2785 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2786 if (!nl_reg_rules)
2787 goto nla_put_failure;
2788
2789 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2790 struct nlattr *nl_reg_rule;
2791 const struct ieee80211_reg_rule *reg_rule;
2792 const struct ieee80211_freq_range *freq_range;
2793 const struct ieee80211_power_rule *power_rule;
2794
2795 reg_rule = &cfg80211_regdomain->reg_rules[i];
2796 freq_range = &reg_rule->freq_range;
2797 power_rule = &reg_rule->power_rule;
2798
2799 nl_reg_rule = nla_nest_start(msg, i);
2800 if (!nl_reg_rule)
2801 goto nla_put_failure;
2802
2803 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2804 reg_rule->flags);
2805 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2806 freq_range->start_freq_khz);
2807 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2808 freq_range->end_freq_khz);
2809 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2810 freq_range->max_bandwidth_khz);
2811 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2812 power_rule->max_antenna_gain);
2813 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2814 power_rule->max_eirp);
2815
2816 nla_nest_end(msg, nl_reg_rule);
2817 }
2818
2819 nla_nest_end(msg, nl_reg_rules);
2820
2821 genlmsg_end(msg, hdr);
2822 err = genlmsg_reply(msg, info);
2823 goto out;
2824
2825 nla_put_failure:
2826 genlmsg_cancel(msg, hdr);
2827 err = -EMSGSIZE;
2828 out:
2829 mutex_unlock(&cfg80211_mutex);
2830 return err;
2831 }
2832
2833 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2834 {
2835 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2836 struct nlattr *nl_reg_rule;
2837 char *alpha2 = NULL;
2838 int rem_reg_rules = 0, r = 0;
2839 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2840 struct ieee80211_regdomain *rd = NULL;
2841
2842 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2843 return -EINVAL;
2844
2845 if (!info->attrs[NL80211_ATTR_REG_RULES])
2846 return -EINVAL;
2847
2848 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2849
2850 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2851 rem_reg_rules) {
2852 num_rules++;
2853 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2854 return -EINVAL;
2855 }
2856
2857 mutex_lock(&cfg80211_mutex);
2858
2859 if (!reg_is_valid_request(alpha2)) {
2860 r = -EINVAL;
2861 goto bad_reg;
2862 }
2863
2864 size_of_regd = sizeof(struct ieee80211_regdomain) +
2865 (num_rules * sizeof(struct ieee80211_reg_rule));
2866
2867 rd = kzalloc(size_of_regd, GFP_KERNEL);
2868 if (!rd) {
2869 r = -ENOMEM;
2870 goto bad_reg;
2871 }
2872
2873 rd->n_reg_rules = num_rules;
2874 rd->alpha2[0] = alpha2[0];
2875 rd->alpha2[1] = alpha2[1];
2876
2877 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2878 rem_reg_rules) {
2879 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2880 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2881 reg_rule_policy);
2882 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2883 if (r)
2884 goto bad_reg;
2885
2886 rule_idx++;
2887
2888 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2889 r = -EINVAL;
2890 goto bad_reg;
2891 }
2892 }
2893
2894 BUG_ON(rule_idx != num_rules);
2895
2896 r = set_regdom(rd);
2897
2898 mutex_unlock(&cfg80211_mutex);
2899
2900 return r;
2901
2902 bad_reg:
2903 mutex_unlock(&cfg80211_mutex);
2904 kfree(rd);
2905 return r;
2906 }
2907
2908 static int validate_scan_freqs(struct nlattr *freqs)
2909 {
2910 struct nlattr *attr1, *attr2;
2911 int n_channels = 0, tmp1, tmp2;
2912
2913 nla_for_each_nested(attr1, freqs, tmp1) {
2914 n_channels++;
2915 /*
2916 * Some hardware has a limited channel list for
2917 * scanning, and it is pretty much nonsensical
2918 * to scan for a channel twice, so disallow that
2919 * and don't require drivers to check that the
2920 * channel list they get isn't longer than what
2921 * they can scan, as long as they can scan all
2922 * the channels they registered at once.
2923 */
2924 nla_for_each_nested(attr2, freqs, tmp2)
2925 if (attr1 != attr2 &&
2926 nla_get_u32(attr1) == nla_get_u32(attr2))
2927 return 0;
2928 }
2929
2930 return n_channels;
2931 }
2932
2933 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2934 {
2935 struct cfg80211_registered_device *rdev;
2936 struct net_device *dev;
2937 struct cfg80211_scan_request *request;
2938 struct cfg80211_ssid *ssid;
2939 struct ieee80211_channel *channel;
2940 struct nlattr *attr;
2941 struct wiphy *wiphy;
2942 int err, tmp, n_ssids = 0, n_channels, i;
2943 enum ieee80211_band band;
2944 size_t ie_len;
2945
2946 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2947 return -EINVAL;
2948
2949 rtnl_lock();
2950
2951 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2952 if (err)
2953 goto out_rtnl;
2954
2955 wiphy = &rdev->wiphy;
2956
2957 if (!rdev->ops->scan) {
2958 err = -EOPNOTSUPP;
2959 goto out;
2960 }
2961
2962 if (!netif_running(dev)) {
2963 err = -ENETDOWN;
2964 goto out;
2965 }
2966
2967 if (rdev->scan_req) {
2968 err = -EBUSY;
2969 goto out;
2970 }
2971
2972 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2973 n_channels = validate_scan_freqs(
2974 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2975 if (!n_channels) {
2976 err = -EINVAL;
2977 goto out;
2978 }
2979 } else {
2980 n_channels = 0;
2981
2982 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2983 if (wiphy->bands[band])
2984 n_channels += wiphy->bands[band]->n_channels;
2985 }
2986
2987 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2988 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2989 n_ssids++;
2990
2991 if (n_ssids > wiphy->max_scan_ssids) {
2992 err = -EINVAL;
2993 goto out;
2994 }
2995
2996 if (info->attrs[NL80211_ATTR_IE])
2997 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2998 else
2999 ie_len = 0;
3000
3001 if (ie_len > wiphy->max_scan_ie_len) {
3002 err = -EINVAL;
3003 goto out;
3004 }
3005
3006 request = kzalloc(sizeof(*request)
3007 + sizeof(*ssid) * n_ssids
3008 + sizeof(channel) * n_channels
3009 + ie_len, GFP_KERNEL);
3010 if (!request) {
3011 err = -ENOMEM;
3012 goto out;
3013 }
3014
3015 if (n_ssids)
3016 request->ssids = (void *)&request->channels[n_channels];
3017 request->n_ssids = n_ssids;
3018 if (ie_len) {
3019 if (request->ssids)
3020 request->ie = (void *)(request->ssids + n_ssids);
3021 else
3022 request->ie = (void *)(request->channels + n_channels);
3023 }
3024
3025 i = 0;
3026 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3027 /* user specified, bail out if channel not found */
3028 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3029 struct ieee80211_channel *chan;
3030
3031 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3032
3033 if (!chan) {
3034 err = -EINVAL;
3035 goto out_free;
3036 }
3037
3038 /* ignore disabled channels */
3039 if (chan->flags & IEEE80211_CHAN_DISABLED)
3040 continue;
3041
3042 request->channels[i] = chan;
3043 i++;
3044 }
3045 } else {
3046 /* all channels */
3047 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3048 int j;
3049 if (!wiphy->bands[band])
3050 continue;
3051 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3052 struct ieee80211_channel *chan;
3053
3054 chan = &wiphy->bands[band]->channels[j];
3055
3056 if (chan->flags & IEEE80211_CHAN_DISABLED)
3057 continue;
3058
3059 request->channels[i] = chan;
3060 i++;
3061 }
3062 }
3063 }
3064
3065 if (!i) {
3066 err = -EINVAL;
3067 goto out_free;
3068 }
3069
3070 request->n_channels = i;
3071
3072 i = 0;
3073 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3074 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3075 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3076 err = -EINVAL;
3077 goto out_free;
3078 }
3079 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3080 request->ssids[i].ssid_len = nla_len(attr);
3081 i++;
3082 }
3083 }
3084
3085 if (info->attrs[NL80211_ATTR_IE]) {
3086 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3087 memcpy((void *)request->ie,
3088 nla_data(info->attrs[NL80211_ATTR_IE]),
3089 request->ie_len);
3090 }
3091
3092 request->dev = dev;
3093 request->wiphy = &rdev->wiphy;
3094
3095 rdev->scan_req = request;
3096 err = rdev->ops->scan(&rdev->wiphy, dev, request);
3097
3098 if (!err) {
3099 nl80211_send_scan_start(rdev, dev);
3100 dev_hold(dev);
3101 }
3102
3103 out_free:
3104 if (err) {
3105 rdev->scan_req = NULL;
3106 kfree(request);
3107 }
3108 out:
3109 cfg80211_unlock_rdev(rdev);
3110 dev_put(dev);
3111 out_rtnl:
3112 rtnl_unlock();
3113
3114 return err;
3115 }
3116
3117 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3118 struct cfg80211_registered_device *rdev,
3119 struct wireless_dev *wdev,
3120 struct cfg80211_internal_bss *intbss)
3121 {
3122 struct cfg80211_bss *res = &intbss->pub;
3123 void *hdr;
3124 struct nlattr *bss;
3125 int i;
3126
3127 ASSERT_WDEV_LOCK(wdev);
3128
3129 hdr = nl80211hdr_put(msg, pid, seq, flags,
3130 NL80211_CMD_NEW_SCAN_RESULTS);
3131 if (!hdr)
3132 return -1;
3133
3134 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3135 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3136
3137 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3138 if (!bss)
3139 goto nla_put_failure;
3140 if (!is_zero_ether_addr(res->bssid))
3141 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3142 if (res->information_elements && res->len_information_elements)
3143 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3144 res->len_information_elements,
3145 res->information_elements);
3146 if (res->tsf)
3147 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3148 if (res->beacon_interval)
3149 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3150 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3151 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3152 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3153 jiffies_to_msecs(jiffies - intbss->ts));
3154
3155 switch (rdev->wiphy.signal_type) {
3156 case CFG80211_SIGNAL_TYPE_MBM:
3157 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3158 break;
3159 case CFG80211_SIGNAL_TYPE_UNSPEC:
3160 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3161 break;
3162 default:
3163 break;
3164 }
3165
3166 switch (wdev->iftype) {
3167 case NL80211_IFTYPE_STATION:
3168 if (intbss == wdev->current_bss)
3169 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3170 NL80211_BSS_STATUS_ASSOCIATED);
3171 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3172 if (intbss != wdev->auth_bsses[i])
3173 continue;
3174 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3175 NL80211_BSS_STATUS_AUTHENTICATED);
3176 break;
3177 }
3178 break;
3179 case NL80211_IFTYPE_ADHOC:
3180 if (intbss == wdev->current_bss)
3181 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3182 NL80211_BSS_STATUS_IBSS_JOINED);
3183 break;
3184 default:
3185 break;
3186 }
3187
3188 nla_nest_end(msg, bss);
3189
3190 return genlmsg_end(msg, hdr);
3191
3192 nla_put_failure:
3193 genlmsg_cancel(msg, hdr);
3194 return -EMSGSIZE;
3195 }
3196
3197 static int nl80211_dump_scan(struct sk_buff *skb,
3198 struct netlink_callback *cb)
3199 {
3200 struct cfg80211_registered_device *rdev;
3201 struct net_device *dev;
3202 struct cfg80211_internal_bss *scan;
3203 struct wireless_dev *wdev;
3204 int ifidx = cb->args[0];
3205 int start = cb->args[1], idx = 0;
3206 int err;
3207
3208 if (!ifidx)
3209 ifidx = nl80211_get_ifidx(cb);
3210 if (ifidx < 0)
3211 return ifidx;
3212 cb->args[0] = ifidx;
3213
3214 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
3215 if (!dev)
3216 return -ENODEV;
3217
3218 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3219 if (IS_ERR(rdev)) {
3220 err = PTR_ERR(rdev);
3221 goto out_put_netdev;
3222 }
3223
3224 wdev = dev->ieee80211_ptr;
3225
3226 wdev_lock(wdev);
3227 spin_lock_bh(&rdev->bss_lock);
3228 cfg80211_bss_expire(rdev);
3229
3230 list_for_each_entry(scan, &rdev->bss_list, list) {
3231 if (++idx <= start)
3232 continue;
3233 if (nl80211_send_bss(skb,
3234 NETLINK_CB(cb->skb).pid,
3235 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3236 rdev, wdev, scan) < 0) {
3237 idx--;
3238 goto out;
3239 }
3240 }
3241
3242 out:
3243 spin_unlock_bh(&rdev->bss_lock);
3244 wdev_unlock(wdev);
3245
3246 cb->args[1] = idx;
3247 err = skb->len;
3248 cfg80211_unlock_rdev(rdev);
3249 out_put_netdev:
3250 dev_put(dev);
3251
3252 return err;
3253 }
3254
3255 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3256 int flags, struct net_device *dev,
3257 struct survey_info *survey)
3258 {
3259 void *hdr;
3260 struct nlattr *infoattr;
3261
3262 /* Survey without a channel doesn't make sense */
3263 if (!survey->channel)
3264 return -EINVAL;
3265
3266 hdr = nl80211hdr_put(msg, pid, seq, flags,
3267 NL80211_CMD_NEW_SURVEY_RESULTS);
3268 if (!hdr)
3269 return -ENOMEM;
3270
3271 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3272
3273 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3274 if (!infoattr)
3275 goto nla_put_failure;
3276
3277 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3278 survey->channel->center_freq);
3279 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3280 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3281 survey->noise);
3282
3283 nla_nest_end(msg, infoattr);
3284
3285 return genlmsg_end(msg, hdr);
3286
3287 nla_put_failure:
3288 genlmsg_cancel(msg, hdr);
3289 return -EMSGSIZE;
3290 }
3291
3292 static int nl80211_dump_survey(struct sk_buff *skb,
3293 struct netlink_callback *cb)
3294 {
3295 struct survey_info survey;
3296 struct cfg80211_registered_device *dev;
3297 struct net_device *netdev;
3298 int ifidx = cb->args[0];
3299 int survey_idx = cb->args[1];
3300 int res;
3301
3302 if (!ifidx)
3303 ifidx = nl80211_get_ifidx(cb);
3304 if (ifidx < 0)
3305 return ifidx;
3306 cb->args[0] = ifidx;
3307
3308 rtnl_lock();
3309
3310 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3311 if (!netdev) {
3312 res = -ENODEV;
3313 goto out_rtnl;
3314 }
3315
3316 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3317 if (IS_ERR(dev)) {
3318 res = PTR_ERR(dev);
3319 goto out_rtnl;
3320 }
3321
3322 if (!dev->ops->dump_survey) {
3323 res = -EOPNOTSUPP;
3324 goto out_err;
3325 }
3326
3327 while (1) {
3328 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3329 &survey);
3330 if (res == -ENOENT)
3331 break;
3332 if (res)
3333 goto out_err;
3334
3335 if (nl80211_send_survey(skb,
3336 NETLINK_CB(cb->skb).pid,
3337 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3338 netdev,
3339 &survey) < 0)
3340 goto out;
3341 survey_idx++;
3342 }
3343
3344 out:
3345 cb->args[1] = survey_idx;
3346 res = skb->len;
3347 out_err:
3348 cfg80211_unlock_rdev(dev);
3349 out_rtnl:
3350 rtnl_unlock();
3351
3352 return res;
3353 }
3354
3355 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3356 {
3357 return auth_type <= NL80211_AUTHTYPE_MAX;
3358 }
3359
3360 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3361 {
3362 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3363 NL80211_WPA_VERSION_2));
3364 }
3365
3366 static bool nl80211_valid_akm_suite(u32 akm)
3367 {
3368 return akm == WLAN_AKM_SUITE_8021X ||
3369 akm == WLAN_AKM_SUITE_PSK;
3370 }
3371
3372 static bool nl80211_valid_cipher_suite(u32 cipher)
3373 {
3374 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3375 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3376 cipher == WLAN_CIPHER_SUITE_TKIP ||
3377 cipher == WLAN_CIPHER_SUITE_CCMP ||
3378 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3379 }
3380
3381
3382 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3383 {
3384 struct cfg80211_registered_device *rdev;
3385 struct net_device *dev;
3386 struct ieee80211_channel *chan;
3387 const u8 *bssid, *ssid, *ie = NULL;
3388 int err, ssid_len, ie_len = 0;
3389 enum nl80211_auth_type auth_type;
3390 struct key_parse key;
3391
3392 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3393 return -EINVAL;
3394
3395 if (!info->attrs[NL80211_ATTR_MAC])
3396 return -EINVAL;
3397
3398 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3399 return -EINVAL;
3400
3401 if (!info->attrs[NL80211_ATTR_SSID])
3402 return -EINVAL;
3403
3404 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3405 return -EINVAL;
3406
3407 err = nl80211_parse_key(info, &key);
3408 if (err)
3409 return err;
3410
3411 if (key.idx >= 0) {
3412 if (!key.p.key || !key.p.key_len)
3413 return -EINVAL;
3414 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3415 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3416 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3417 key.p.key_len != WLAN_KEY_LEN_WEP104))
3418 return -EINVAL;
3419 if (key.idx > 4)
3420 return -EINVAL;
3421 } else {
3422 key.p.key_len = 0;
3423 key.p.key = NULL;
3424 }
3425
3426 rtnl_lock();
3427
3428 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3429 if (err)
3430 goto unlock_rtnl;
3431
3432 if (!rdev->ops->auth) {
3433 err = -EOPNOTSUPP;
3434 goto out;
3435 }
3436
3437 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3438 err = -EOPNOTSUPP;
3439 goto out;
3440 }
3441
3442 if (!netif_running(dev)) {
3443 err = -ENETDOWN;
3444 goto out;
3445 }
3446
3447 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3448 chan = ieee80211_get_channel(&rdev->wiphy,
3449 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3450 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3451 err = -EINVAL;
3452 goto out;
3453 }
3454
3455 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3456 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3457
3458 if (info->attrs[NL80211_ATTR_IE]) {
3459 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3460 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3461 }
3462
3463 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3464 if (!nl80211_valid_auth_type(auth_type)) {
3465 err = -EINVAL;
3466 goto out;
3467 }
3468
3469 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3470 ssid, ssid_len, ie, ie_len,
3471 key.p.key, key.p.key_len, key.idx);
3472
3473 out:
3474 cfg80211_unlock_rdev(rdev);
3475 dev_put(dev);
3476 unlock_rtnl:
3477 rtnl_unlock();
3478 return err;
3479 }
3480
3481 static int nl80211_crypto_settings(struct genl_info *info,
3482 struct cfg80211_crypto_settings *settings,
3483 int cipher_limit)
3484 {
3485 memset(settings, 0, sizeof(*settings));
3486
3487 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3488
3489 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3490 void *data;
3491 int len, i;
3492
3493 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3494 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3495 settings->n_ciphers_pairwise = len / sizeof(u32);
3496
3497 if (len % sizeof(u32))
3498 return -EINVAL;
3499
3500 if (settings->n_ciphers_pairwise > cipher_limit)
3501 return -EINVAL;
3502
3503 memcpy(settings->ciphers_pairwise, data, len);
3504
3505 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3506 if (!nl80211_valid_cipher_suite(
3507 settings->ciphers_pairwise[i]))
3508 return -EINVAL;
3509 }
3510
3511 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3512 settings->cipher_group =
3513 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3514 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3515 return -EINVAL;
3516 }
3517
3518 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3519 settings->wpa_versions =
3520 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3521 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3522 return -EINVAL;
3523 }
3524
3525 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3526 void *data;
3527 int len, i;
3528
3529 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3530 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3531 settings->n_akm_suites = len / sizeof(u32);
3532
3533 if (len % sizeof(u32))
3534 return -EINVAL;
3535
3536 memcpy(settings->akm_suites, data, len);
3537
3538 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3539 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3540 return -EINVAL;
3541 }
3542
3543 return 0;
3544 }
3545
3546 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3547 {
3548 struct cfg80211_registered_device *rdev;
3549 struct net_device *dev;
3550 struct cfg80211_crypto_settings crypto;
3551 struct ieee80211_channel *chan, *fixedchan;
3552 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3553 int err, ssid_len, ie_len = 0;
3554 bool use_mfp = false;
3555
3556 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3557 return -EINVAL;
3558
3559 if (!info->attrs[NL80211_ATTR_MAC] ||
3560 !info->attrs[NL80211_ATTR_SSID] ||
3561 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3562 return -EINVAL;
3563
3564 rtnl_lock();
3565
3566 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3567 if (err)
3568 goto unlock_rtnl;
3569
3570 if (!rdev->ops->assoc) {
3571 err = -EOPNOTSUPP;
3572 goto out;
3573 }
3574
3575 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3576 err = -EOPNOTSUPP;
3577 goto out;
3578 }
3579
3580 if (!netif_running(dev)) {
3581 err = -ENETDOWN;
3582 goto out;
3583 }
3584
3585 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3586
3587 chan = ieee80211_get_channel(&rdev->wiphy,
3588 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3589 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3590 err = -EINVAL;
3591 goto out;
3592 }
3593
3594 mutex_lock(&rdev->devlist_mtx);
3595 fixedchan = rdev_fixed_channel(rdev, NULL);
3596 if (fixedchan && chan != fixedchan) {
3597 err = -EBUSY;
3598 mutex_unlock(&rdev->devlist_mtx);
3599 goto out;
3600 }
3601 mutex_unlock(&rdev->devlist_mtx);
3602
3603 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3604 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3605
3606 if (info->attrs[NL80211_ATTR_IE]) {
3607 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3608 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3609 }
3610
3611 if (info->attrs[NL80211_ATTR_USE_MFP]) {
3612 enum nl80211_mfp mfp =
3613 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3614 if (mfp == NL80211_MFP_REQUIRED)
3615 use_mfp = true;
3616 else if (mfp != NL80211_MFP_NO) {
3617 err = -EINVAL;
3618 goto out;
3619 }
3620 }
3621
3622 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3623 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3624
3625 err = nl80211_crypto_settings(info, &crypto, 1);
3626 if (!err)
3627 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3628 ssid, ssid_len, ie, ie_len, use_mfp,
3629 &crypto);
3630
3631 out:
3632 cfg80211_unlock_rdev(rdev);
3633 dev_put(dev);
3634 unlock_rtnl:
3635 rtnl_unlock();
3636 return err;
3637 }
3638
3639 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3640 {
3641 struct cfg80211_registered_device *rdev;
3642 struct net_device *dev;
3643 const u8 *ie = NULL, *bssid;
3644 int err, ie_len = 0;
3645 u16 reason_code;
3646
3647 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3648 return -EINVAL;
3649
3650 if (!info->attrs[NL80211_ATTR_MAC])
3651 return -EINVAL;
3652
3653 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3654 return -EINVAL;
3655
3656 rtnl_lock();
3657
3658 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3659 if (err)
3660 goto unlock_rtnl;
3661
3662 if (!rdev->ops->deauth) {
3663 err = -EOPNOTSUPP;
3664 goto out;
3665 }
3666
3667 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3668 err = -EOPNOTSUPP;
3669 goto out;
3670 }
3671
3672 if (!netif_running(dev)) {
3673 err = -ENETDOWN;
3674 goto out;
3675 }
3676
3677 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3678
3679 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3680 if (reason_code == 0) {
3681 /* Reason Code 0 is reserved */
3682 err = -EINVAL;
3683 goto out;
3684 }
3685
3686 if (info->attrs[NL80211_ATTR_IE]) {
3687 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3688 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3689 }
3690
3691 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
3692
3693 out:
3694 cfg80211_unlock_rdev(rdev);
3695 dev_put(dev);
3696 unlock_rtnl:
3697 rtnl_unlock();
3698 return err;
3699 }
3700
3701 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3702 {
3703 struct cfg80211_registered_device *rdev;
3704 struct net_device *dev;
3705 const u8 *ie = NULL, *bssid;
3706 int err, ie_len = 0;
3707 u16 reason_code;
3708
3709 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3710 return -EINVAL;
3711
3712 if (!info->attrs[NL80211_ATTR_MAC])
3713 return -EINVAL;
3714
3715 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3716 return -EINVAL;
3717
3718 rtnl_lock();
3719
3720 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3721 if (err)
3722 goto unlock_rtnl;
3723
3724 if (!rdev->ops->disassoc) {
3725 err = -EOPNOTSUPP;
3726 goto out;
3727 }
3728
3729 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3730 err = -EOPNOTSUPP;
3731 goto out;
3732 }
3733
3734 if (!netif_running(dev)) {
3735 err = -ENETDOWN;
3736 goto out;
3737 }
3738
3739 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3740
3741 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3742 if (reason_code == 0) {
3743 /* Reason Code 0 is reserved */
3744 err = -EINVAL;
3745 goto out;
3746 }
3747
3748 if (info->attrs[NL80211_ATTR_IE]) {
3749 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3750 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3751 }
3752
3753 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
3754
3755 out:
3756 cfg80211_unlock_rdev(rdev);
3757 dev_put(dev);
3758 unlock_rtnl:
3759 rtnl_unlock();
3760 return err;
3761 }
3762
3763 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3764 {
3765 struct cfg80211_registered_device *rdev;
3766 struct net_device *dev;
3767 struct cfg80211_ibss_params ibss;
3768 struct wiphy *wiphy;
3769 struct cfg80211_cached_keys *connkeys = NULL;
3770 int err;
3771
3772 memset(&ibss, 0, sizeof(ibss));
3773
3774 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3775 return -EINVAL;
3776
3777 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3778 !info->attrs[NL80211_ATTR_SSID] ||
3779 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3780 return -EINVAL;
3781
3782 ibss.beacon_interval = 100;
3783
3784 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3785 ibss.beacon_interval =
3786 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3787 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3788 return -EINVAL;
3789 }
3790
3791 rtnl_lock();
3792
3793 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3794 if (err)
3795 goto unlock_rtnl;
3796
3797 if (!rdev->ops->join_ibss) {
3798 err = -EOPNOTSUPP;
3799 goto out;
3800 }
3801
3802 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3803 err = -EOPNOTSUPP;
3804 goto out;
3805 }
3806
3807 if (!netif_running(dev)) {
3808 err = -ENETDOWN;
3809 goto out;
3810 }
3811
3812 wiphy = &rdev->wiphy;
3813
3814 if (info->attrs[NL80211_ATTR_MAC])
3815 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3816 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3817 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3818
3819 if (info->attrs[NL80211_ATTR_IE]) {
3820 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3821 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3822 }
3823
3824 ibss.channel = ieee80211_get_channel(wiphy,
3825 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3826 if (!ibss.channel ||
3827 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3828 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3829 err = -EINVAL;
3830 goto out;
3831 }
3832
3833 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3834 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3835
3836 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3837 connkeys = nl80211_parse_connkeys(rdev,
3838 info->attrs[NL80211_ATTR_KEYS]);
3839 if (IS_ERR(connkeys)) {
3840 err = PTR_ERR(connkeys);
3841 connkeys = NULL;
3842 goto out;
3843 }
3844 }
3845
3846 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
3847
3848 out:
3849 cfg80211_unlock_rdev(rdev);
3850 dev_put(dev);
3851 unlock_rtnl:
3852 if (err)
3853 kfree(connkeys);
3854 rtnl_unlock();
3855 return err;
3856 }
3857
3858 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3859 {
3860 struct cfg80211_registered_device *rdev;
3861 struct net_device *dev;
3862 int err;
3863
3864 rtnl_lock();
3865
3866 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3867 if (err)
3868 goto unlock_rtnl;
3869
3870 if (!rdev->ops->leave_ibss) {
3871 err = -EOPNOTSUPP;
3872 goto out;
3873 }
3874
3875 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3876 err = -EOPNOTSUPP;
3877 goto out;
3878 }
3879
3880 if (!netif_running(dev)) {
3881 err = -ENETDOWN;
3882 goto out;
3883 }
3884
3885 err = cfg80211_leave_ibss(rdev, dev, false);
3886
3887 out:
3888 cfg80211_unlock_rdev(rdev);
3889 dev_put(dev);
3890 unlock_rtnl:
3891 rtnl_unlock();
3892 return err;
3893 }
3894
3895 #ifdef CONFIG_NL80211_TESTMODE
3896 static struct genl_multicast_group nl80211_testmode_mcgrp = {
3897 .name = "testmode",
3898 };
3899
3900 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3901 {
3902 struct cfg80211_registered_device *rdev;
3903 int err;
3904
3905 if (!info->attrs[NL80211_ATTR_TESTDATA])
3906 return -EINVAL;
3907
3908 rtnl_lock();
3909
3910 rdev = cfg80211_get_dev_from_info(info);
3911 if (IS_ERR(rdev)) {
3912 err = PTR_ERR(rdev);
3913 goto unlock_rtnl;
3914 }
3915
3916 err = -EOPNOTSUPP;
3917 if (rdev->ops->testmode_cmd) {
3918 rdev->testmode_info = info;
3919 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3920 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3921 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3922 rdev->testmode_info = NULL;
3923 }
3924
3925 cfg80211_unlock_rdev(rdev);
3926
3927 unlock_rtnl:
3928 rtnl_unlock();
3929 return err;
3930 }
3931
3932 static struct sk_buff *
3933 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3934 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3935 {
3936 struct sk_buff *skb;
3937 void *hdr;
3938 struct nlattr *data;
3939
3940 skb = nlmsg_new(approxlen + 100, gfp);
3941 if (!skb)
3942 return NULL;
3943
3944 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3945 if (!hdr) {
3946 kfree_skb(skb);
3947 return NULL;
3948 }
3949
3950 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3951 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3952
3953 ((void **)skb->cb)[0] = rdev;
3954 ((void **)skb->cb)[1] = hdr;
3955 ((void **)skb->cb)[2] = data;
3956
3957 return skb;
3958
3959 nla_put_failure:
3960 kfree_skb(skb);
3961 return NULL;
3962 }
3963
3964 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3965 int approxlen)
3966 {
3967 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3968
3969 if (WARN_ON(!rdev->testmode_info))
3970 return NULL;
3971
3972 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3973 rdev->testmode_info->snd_pid,
3974 rdev->testmode_info->snd_seq,
3975 GFP_KERNEL);
3976 }
3977 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3978
3979 int cfg80211_testmode_reply(struct sk_buff *skb)
3980 {
3981 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3982 void *hdr = ((void **)skb->cb)[1];
3983 struct nlattr *data = ((void **)skb->cb)[2];
3984
3985 if (WARN_ON(!rdev->testmode_info)) {
3986 kfree_skb(skb);
3987 return -EINVAL;
3988 }
3989
3990 nla_nest_end(skb, data);
3991 genlmsg_end(skb, hdr);
3992 return genlmsg_reply(skb, rdev->testmode_info);
3993 }
3994 EXPORT_SYMBOL(cfg80211_testmode_reply);
3995
3996 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3997 int approxlen, gfp_t gfp)
3998 {
3999 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4000
4001 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4002 }
4003 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4004
4005 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4006 {
4007 void *hdr = ((void **)skb->cb)[1];
4008 struct nlattr *data = ((void **)skb->cb)[2];
4009
4010 nla_nest_end(skb, data);
4011 genlmsg_end(skb, hdr);
4012 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4013 }
4014 EXPORT_SYMBOL(cfg80211_testmode_event);
4015 #endif
4016
4017 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4018 {
4019 struct cfg80211_registered_device *rdev;
4020 struct net_device *dev;
4021 struct cfg80211_connect_params connect;
4022 struct wiphy *wiphy;
4023 struct cfg80211_cached_keys *connkeys = NULL;
4024 int err;
4025
4026 memset(&connect, 0, sizeof(connect));
4027
4028 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4029 return -EINVAL;
4030
4031 if (!info->attrs[NL80211_ATTR_SSID] ||
4032 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4033 return -EINVAL;
4034
4035 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4036 connect.auth_type =
4037 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4038 if (!nl80211_valid_auth_type(connect.auth_type))
4039 return -EINVAL;
4040 } else
4041 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4042
4043 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4044
4045 err = nl80211_crypto_settings(info, &connect.crypto,
4046 NL80211_MAX_NR_CIPHER_SUITES);
4047 if (err)
4048 return err;
4049 rtnl_lock();
4050
4051 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4052 if (err)
4053 goto unlock_rtnl;
4054
4055 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4056 err = -EOPNOTSUPP;
4057 goto out;
4058 }
4059
4060 if (!netif_running(dev)) {
4061 err = -ENETDOWN;
4062 goto out;
4063 }
4064
4065 wiphy = &rdev->wiphy;
4066
4067 if (info->attrs[NL80211_ATTR_MAC])
4068 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4069 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4070 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4071
4072 if (info->attrs[NL80211_ATTR_IE]) {
4073 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4074 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4075 }
4076
4077 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4078 connect.channel =
4079 ieee80211_get_channel(wiphy,
4080 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4081 if (!connect.channel ||
4082 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4083 err = -EINVAL;
4084 goto out;
4085 }
4086 }
4087
4088 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4089 connkeys = nl80211_parse_connkeys(rdev,
4090 info->attrs[NL80211_ATTR_KEYS]);
4091 if (IS_ERR(connkeys)) {
4092 err = PTR_ERR(connkeys);
4093 connkeys = NULL;
4094 goto out;
4095 }
4096 }
4097
4098 err = cfg80211_connect(rdev, dev, &connect, connkeys);
4099
4100 out:
4101 cfg80211_unlock_rdev(rdev);
4102 dev_put(dev);
4103 unlock_rtnl:
4104 if (err)
4105 kfree(connkeys);
4106 rtnl_unlock();
4107 return err;
4108 }
4109
4110 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4111 {
4112 struct cfg80211_registered_device *rdev;
4113 struct net_device *dev;
4114 int err;
4115 u16 reason;
4116
4117 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4118 reason = WLAN_REASON_DEAUTH_LEAVING;
4119 else
4120 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4121
4122 if (reason == 0)
4123 return -EINVAL;
4124
4125 rtnl_lock();
4126
4127 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4128 if (err)
4129 goto unlock_rtnl;
4130
4131 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4132 err = -EOPNOTSUPP;
4133 goto out;
4134 }
4135
4136 if (!netif_running(dev)) {
4137 err = -ENETDOWN;
4138 goto out;
4139 }
4140
4141 err = cfg80211_disconnect(rdev, dev, reason, true);
4142
4143 out:
4144 cfg80211_unlock_rdev(rdev);
4145 dev_put(dev);
4146 unlock_rtnl:
4147 rtnl_unlock();
4148 return err;
4149 }
4150
4151 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4152 {
4153 struct cfg80211_registered_device *rdev;
4154 struct net *net;
4155 int err;
4156 u32 pid;
4157
4158 if (!info->attrs[NL80211_ATTR_PID])
4159 return -EINVAL;
4160
4161 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4162
4163 rtnl_lock();
4164
4165 rdev = cfg80211_get_dev_from_info(info);
4166 if (IS_ERR(rdev)) {
4167 err = PTR_ERR(rdev);
4168 goto out_rtnl;
4169 }
4170
4171 net = get_net_ns_by_pid(pid);
4172 if (IS_ERR(net)) {
4173 err = PTR_ERR(net);
4174 goto out;
4175 }
4176
4177 err = 0;
4178
4179 /* check if anything to do */
4180 if (net_eq(wiphy_net(&rdev->wiphy), net))
4181 goto out_put_net;
4182
4183 err = cfg80211_switch_netns(rdev, net);
4184 out_put_net:
4185 put_net(net);
4186 out:
4187 cfg80211_unlock_rdev(rdev);
4188 out_rtnl:
4189 rtnl_unlock();
4190 return err;
4191 }
4192
4193 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4194 {
4195 struct cfg80211_registered_device *rdev;
4196 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4197 struct cfg80211_pmksa *pmksa) = NULL;
4198 int err;
4199 struct net_device *dev;
4200 struct cfg80211_pmksa pmksa;
4201
4202 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4203
4204 if (!info->attrs[NL80211_ATTR_MAC])
4205 return -EINVAL;
4206
4207 if (!info->attrs[NL80211_ATTR_PMKID])
4208 return -EINVAL;
4209
4210 rtnl_lock();
4211
4212 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4213 if (err)
4214 goto out_rtnl;
4215
4216 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4217 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4218
4219 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4220 err = -EOPNOTSUPP;
4221 goto out;
4222 }
4223
4224 switch (info->genlhdr->cmd) {
4225 case NL80211_CMD_SET_PMKSA:
4226 rdev_ops = rdev->ops->set_pmksa;
4227 break;
4228 case NL80211_CMD_DEL_PMKSA:
4229 rdev_ops = rdev->ops->del_pmksa;
4230 break;
4231 default:
4232 WARN_ON(1);
4233 break;
4234 }
4235
4236 if (!rdev_ops) {
4237 err = -EOPNOTSUPP;
4238 goto out;
4239 }
4240
4241 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4242
4243 out:
4244 cfg80211_unlock_rdev(rdev);
4245 dev_put(dev);
4246 out_rtnl:
4247 rtnl_unlock();
4248
4249 return err;
4250 }
4251
4252 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4253 {
4254 struct cfg80211_registered_device *rdev;
4255 int err;
4256 struct net_device *dev;
4257
4258 rtnl_lock();
4259
4260 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4261 if (err)
4262 goto out_rtnl;
4263
4264 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4265 err = -EOPNOTSUPP;
4266 goto out;
4267 }
4268
4269 if (!rdev->ops->flush_pmksa) {
4270 err = -EOPNOTSUPP;
4271 goto out;
4272 }
4273
4274 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4275
4276 out:
4277 cfg80211_unlock_rdev(rdev);
4278 dev_put(dev);
4279 out_rtnl:
4280 rtnl_unlock();
4281
4282 return err;
4283
4284 }
4285
4286 static struct genl_ops nl80211_ops[] = {
4287 {
4288 .cmd = NL80211_CMD_GET_WIPHY,
4289 .doit = nl80211_get_wiphy,
4290 .dumpit = nl80211_dump_wiphy,
4291 .policy = nl80211_policy,
4292 /* can be retrieved by unprivileged users */
4293 },
4294 {
4295 .cmd = NL80211_CMD_SET_WIPHY,
4296 .doit = nl80211_set_wiphy,
4297 .policy = nl80211_policy,
4298 .flags = GENL_ADMIN_PERM,
4299 },
4300 {
4301 .cmd = NL80211_CMD_GET_INTERFACE,
4302 .doit = nl80211_get_interface,
4303 .dumpit = nl80211_dump_interface,
4304 .policy = nl80211_policy,
4305 /* can be retrieved by unprivileged users */
4306 },
4307 {
4308 .cmd = NL80211_CMD_SET_INTERFACE,
4309 .doit = nl80211_set_interface,
4310 .policy = nl80211_policy,
4311 .flags = GENL_ADMIN_PERM,
4312 },
4313 {
4314 .cmd = NL80211_CMD_NEW_INTERFACE,
4315 .doit = nl80211_new_interface,
4316 .policy = nl80211_policy,
4317 .flags = GENL_ADMIN_PERM,
4318 },
4319 {
4320 .cmd = NL80211_CMD_DEL_INTERFACE,
4321 .doit = nl80211_del_interface,
4322 .policy = nl80211_policy,
4323 .flags = GENL_ADMIN_PERM,
4324 },
4325 {
4326 .cmd = NL80211_CMD_GET_KEY,
4327 .doit = nl80211_get_key,
4328 .policy = nl80211_policy,
4329 .flags = GENL_ADMIN_PERM,
4330 },
4331 {
4332 .cmd = NL80211_CMD_SET_KEY,
4333 .doit = nl80211_set_key,
4334 .policy = nl80211_policy,
4335 .flags = GENL_ADMIN_PERM,
4336 },
4337 {
4338 .cmd = NL80211_CMD_NEW_KEY,
4339 .doit = nl80211_new_key,
4340 .policy = nl80211_policy,
4341 .flags = GENL_ADMIN_PERM,
4342 },
4343 {
4344 .cmd = NL80211_CMD_DEL_KEY,
4345 .doit = nl80211_del_key,
4346 .policy = nl80211_policy,
4347 .flags = GENL_ADMIN_PERM,
4348 },
4349 {
4350 .cmd = NL80211_CMD_SET_BEACON,
4351 .policy = nl80211_policy,
4352 .flags = GENL_ADMIN_PERM,
4353 .doit = nl80211_addset_beacon,
4354 },
4355 {
4356 .cmd = NL80211_CMD_NEW_BEACON,
4357 .policy = nl80211_policy,
4358 .flags = GENL_ADMIN_PERM,
4359 .doit = nl80211_addset_beacon,
4360 },
4361 {
4362 .cmd = NL80211_CMD_DEL_BEACON,
4363 .policy = nl80211_policy,
4364 .flags = GENL_ADMIN_PERM,
4365 .doit = nl80211_del_beacon,
4366 },
4367 {
4368 .cmd = NL80211_CMD_GET_STATION,
4369 .doit = nl80211_get_station,
4370 .dumpit = nl80211_dump_station,
4371 .policy = nl80211_policy,
4372 },
4373 {
4374 .cmd = NL80211_CMD_SET_STATION,
4375 .doit = nl80211_set_station,
4376 .policy = nl80211_policy,
4377 .flags = GENL_ADMIN_PERM,
4378 },
4379 {
4380 .cmd = NL80211_CMD_NEW_STATION,
4381 .doit = nl80211_new_station,
4382 .policy = nl80211_policy,
4383 .flags = GENL_ADMIN_PERM,
4384 },
4385 {
4386 .cmd = NL80211_CMD_DEL_STATION,
4387 .doit = nl80211_del_station,
4388 .policy = nl80211_policy,
4389 .flags = GENL_ADMIN_PERM,
4390 },
4391 {
4392 .cmd = NL80211_CMD_GET_MPATH,
4393 .doit = nl80211_get_mpath,
4394 .dumpit = nl80211_dump_mpath,
4395 .policy = nl80211_policy,
4396 .flags = GENL_ADMIN_PERM,
4397 },
4398 {
4399 .cmd = NL80211_CMD_SET_MPATH,
4400 .doit = nl80211_set_mpath,
4401 .policy = nl80211_policy,
4402 .flags = GENL_ADMIN_PERM,
4403 },
4404 {
4405 .cmd = NL80211_CMD_NEW_MPATH,
4406 .doit = nl80211_new_mpath,
4407 .policy = nl80211_policy,
4408 .flags = GENL_ADMIN_PERM,
4409 },
4410 {
4411 .cmd = NL80211_CMD_DEL_MPATH,
4412 .doit = nl80211_del_mpath,
4413 .policy = nl80211_policy,
4414 .flags = GENL_ADMIN_PERM,
4415 },
4416 {
4417 .cmd = NL80211_CMD_SET_BSS,
4418 .doit = nl80211_set_bss,
4419 .policy = nl80211_policy,
4420 .flags = GENL_ADMIN_PERM,
4421 },
4422 {
4423 .cmd = NL80211_CMD_GET_REG,
4424 .doit = nl80211_get_reg,
4425 .policy = nl80211_policy,
4426 /* can be retrieved by unprivileged users */
4427 },
4428 {
4429 .cmd = NL80211_CMD_SET_REG,
4430 .doit = nl80211_set_reg,
4431 .policy = nl80211_policy,
4432 .flags = GENL_ADMIN_PERM,
4433 },
4434 {
4435 .cmd = NL80211_CMD_REQ_SET_REG,
4436 .doit = nl80211_req_set_reg,
4437 .policy = nl80211_policy,
4438 .flags = GENL_ADMIN_PERM,
4439 },
4440 {
4441 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4442 .doit = nl80211_get_mesh_params,
4443 .policy = nl80211_policy,
4444 /* can be retrieved by unprivileged users */
4445 },
4446 {
4447 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4448 .doit = nl80211_set_mesh_params,
4449 .policy = nl80211_policy,
4450 .flags = GENL_ADMIN_PERM,
4451 },
4452 {
4453 .cmd = NL80211_CMD_TRIGGER_SCAN,
4454 .doit = nl80211_trigger_scan,
4455 .policy = nl80211_policy,
4456 .flags = GENL_ADMIN_PERM,
4457 },
4458 {
4459 .cmd = NL80211_CMD_GET_SCAN,
4460 .policy = nl80211_policy,
4461 .dumpit = nl80211_dump_scan,
4462 },
4463 {
4464 .cmd = NL80211_CMD_AUTHENTICATE,
4465 .doit = nl80211_authenticate,
4466 .policy = nl80211_policy,
4467 .flags = GENL_ADMIN_PERM,
4468 },
4469 {
4470 .cmd = NL80211_CMD_ASSOCIATE,
4471 .doit = nl80211_associate,
4472 .policy = nl80211_policy,
4473 .flags = GENL_ADMIN_PERM,
4474 },
4475 {
4476 .cmd = NL80211_CMD_DEAUTHENTICATE,
4477 .doit = nl80211_deauthenticate,
4478 .policy = nl80211_policy,
4479 .flags = GENL_ADMIN_PERM,
4480 },
4481 {
4482 .cmd = NL80211_CMD_DISASSOCIATE,
4483 .doit = nl80211_disassociate,
4484 .policy = nl80211_policy,
4485 .flags = GENL_ADMIN_PERM,
4486 },
4487 {
4488 .cmd = NL80211_CMD_JOIN_IBSS,
4489 .doit = nl80211_join_ibss,
4490 .policy = nl80211_policy,
4491 .flags = GENL_ADMIN_PERM,
4492 },
4493 {
4494 .cmd = NL80211_CMD_LEAVE_IBSS,
4495 .doit = nl80211_leave_ibss,
4496 .policy = nl80211_policy,
4497 .flags = GENL_ADMIN_PERM,
4498 },
4499 #ifdef CONFIG_NL80211_TESTMODE
4500 {
4501 .cmd = NL80211_CMD_TESTMODE,
4502 .doit = nl80211_testmode_do,
4503 .policy = nl80211_policy,
4504 .flags = GENL_ADMIN_PERM,
4505 },
4506 #endif
4507 {
4508 .cmd = NL80211_CMD_CONNECT,
4509 .doit = nl80211_connect,
4510 .policy = nl80211_policy,
4511 .flags = GENL_ADMIN_PERM,
4512 },
4513 {
4514 .cmd = NL80211_CMD_DISCONNECT,
4515 .doit = nl80211_disconnect,
4516 .policy = nl80211_policy,
4517 .flags = GENL_ADMIN_PERM,
4518 },
4519 {
4520 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4521 .doit = nl80211_wiphy_netns,
4522 .policy = nl80211_policy,
4523 .flags = GENL_ADMIN_PERM,
4524 },
4525 {
4526 .cmd = NL80211_CMD_GET_SURVEY,
4527 .policy = nl80211_policy,
4528 .dumpit = nl80211_dump_survey,
4529 },
4530 {
4531 .cmd = NL80211_CMD_SET_PMKSA,
4532 .doit = nl80211_setdel_pmksa,
4533 .policy = nl80211_policy,
4534 .flags = GENL_ADMIN_PERM,
4535 },
4536 {
4537 .cmd = NL80211_CMD_DEL_PMKSA,
4538 .doit = nl80211_setdel_pmksa,
4539 .policy = nl80211_policy,
4540 .flags = GENL_ADMIN_PERM,
4541 },
4542 {
4543 .cmd = NL80211_CMD_FLUSH_PMKSA,
4544 .doit = nl80211_flush_pmksa,
4545 .policy = nl80211_policy,
4546 .flags = GENL_ADMIN_PERM,
4547 },
4548
4549 };
4550 static struct genl_multicast_group nl80211_mlme_mcgrp = {
4551 .name = "mlme",
4552 };
4553
4554 /* multicast groups */
4555 static struct genl_multicast_group nl80211_config_mcgrp = {
4556 .name = "config",
4557 };
4558 static struct genl_multicast_group nl80211_scan_mcgrp = {
4559 .name = "scan",
4560 };
4561 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4562 .name = "regulatory",
4563 };
4564
4565 /* notification functions */
4566
4567 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4568 {
4569 struct sk_buff *msg;
4570
4571 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4572 if (!msg)
4573 return;
4574
4575 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4576 nlmsg_free(msg);
4577 return;
4578 }
4579
4580 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4581 nl80211_config_mcgrp.id, GFP_KERNEL);
4582 }
4583
4584 static int nl80211_add_scan_req(struct sk_buff *msg,
4585 struct cfg80211_registered_device *rdev)
4586 {
4587 struct cfg80211_scan_request *req = rdev->scan_req;
4588 struct nlattr *nest;
4589 int i;
4590
4591 ASSERT_RDEV_LOCK(rdev);
4592
4593 if (WARN_ON(!req))
4594 return 0;
4595
4596 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4597 if (!nest)
4598 goto nla_put_failure;
4599 for (i = 0; i < req->n_ssids; i++)
4600 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4601 nla_nest_end(msg, nest);
4602
4603 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4604 if (!nest)
4605 goto nla_put_failure;
4606 for (i = 0; i < req->n_channels; i++)
4607 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4608 nla_nest_end(msg, nest);
4609
4610 if (req->ie)
4611 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4612
4613 return 0;
4614 nla_put_failure:
4615 return -ENOBUFS;
4616 }
4617
4618 static int nl80211_send_scan_msg(struct sk_buff *msg,
4619 struct cfg80211_registered_device *rdev,
4620 struct net_device *netdev,
4621 u32 pid, u32 seq, int flags,
4622 u32 cmd)
4623 {
4624 void *hdr;
4625
4626 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4627 if (!hdr)
4628 return -1;
4629
4630 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4631 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4632
4633 /* ignore errors and send incomplete event anyway */
4634 nl80211_add_scan_req(msg, rdev);
4635
4636 return genlmsg_end(msg, hdr);
4637
4638 nla_put_failure:
4639 genlmsg_cancel(msg, hdr);
4640 return -EMSGSIZE;
4641 }
4642
4643 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4644 struct net_device *netdev)
4645 {
4646 struct sk_buff *msg;
4647
4648 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4649 if (!msg)
4650 return;
4651
4652 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4653 NL80211_CMD_TRIGGER_SCAN) < 0) {
4654 nlmsg_free(msg);
4655 return;
4656 }
4657
4658 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4659 nl80211_scan_mcgrp.id, GFP_KERNEL);
4660 }
4661
4662 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4663 struct net_device *netdev)
4664 {
4665 struct sk_buff *msg;
4666
4667 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4668 if (!msg)
4669 return;
4670
4671 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4672 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
4673 nlmsg_free(msg);
4674 return;
4675 }
4676
4677 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4678 nl80211_scan_mcgrp.id, GFP_KERNEL);
4679 }
4680
4681 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4682 struct net_device *netdev)
4683 {
4684 struct sk_buff *msg;
4685
4686 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4687 if (!msg)
4688 return;
4689
4690 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4691 NL80211_CMD_SCAN_ABORTED) < 0) {
4692 nlmsg_free(msg);
4693 return;
4694 }
4695
4696 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4697 nl80211_scan_mcgrp.id, GFP_KERNEL);
4698 }
4699
4700 /*
4701 * This can happen on global regulatory changes or device specific settings
4702 * based on custom world regulatory domains.
4703 */
4704 void nl80211_send_reg_change_event(struct regulatory_request *request)
4705 {
4706 struct sk_buff *msg;
4707 void *hdr;
4708
4709 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4710 if (!msg)
4711 return;
4712
4713 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4714 if (!hdr) {
4715 nlmsg_free(msg);
4716 return;
4717 }
4718
4719 /* Userspace can always count this one always being set */
4720 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4721
4722 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4723 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4724 NL80211_REGDOM_TYPE_WORLD);
4725 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4726 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4727 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4728 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4729 request->intersect)
4730 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4731 NL80211_REGDOM_TYPE_INTERSECTION);
4732 else {
4733 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4734 NL80211_REGDOM_TYPE_COUNTRY);
4735 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4736 }
4737
4738 if (wiphy_idx_valid(request->wiphy_idx))
4739 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4740
4741 if (genlmsg_end(msg, hdr) < 0) {
4742 nlmsg_free(msg);
4743 return;
4744 }
4745
4746 rcu_read_lock();
4747 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4748 GFP_ATOMIC);
4749 rcu_read_unlock();
4750
4751 return;
4752
4753 nla_put_failure:
4754 genlmsg_cancel(msg, hdr);
4755 nlmsg_free(msg);
4756 }
4757
4758 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4759 struct net_device *netdev,
4760 const u8 *buf, size_t len,
4761 enum nl80211_commands cmd, gfp_t gfp)
4762 {
4763 struct sk_buff *msg;
4764 void *hdr;
4765
4766 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4767 if (!msg)
4768 return;
4769
4770 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4771 if (!hdr) {
4772 nlmsg_free(msg);
4773 return;
4774 }
4775
4776 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4777 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4778 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4779
4780 if (genlmsg_end(msg, hdr) < 0) {
4781 nlmsg_free(msg);
4782 return;
4783 }
4784
4785 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4786 nl80211_mlme_mcgrp.id, gfp);
4787 return;
4788
4789 nla_put_failure:
4790 genlmsg_cancel(msg, hdr);
4791 nlmsg_free(msg);
4792 }
4793
4794 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
4795 struct net_device *netdev, const u8 *buf,
4796 size_t len, gfp_t gfp)
4797 {
4798 nl80211_send_mlme_event(rdev, netdev, buf, len,
4799 NL80211_CMD_AUTHENTICATE, gfp);
4800 }
4801
4802 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4803 struct net_device *netdev, const u8 *buf,
4804 size_t len, gfp_t gfp)
4805 {
4806 nl80211_send_mlme_event(rdev, netdev, buf, len,
4807 NL80211_CMD_ASSOCIATE, gfp);
4808 }
4809
4810 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
4811 struct net_device *netdev, const u8 *buf,
4812 size_t len, gfp_t gfp)
4813 {
4814 nl80211_send_mlme_event(rdev, netdev, buf, len,
4815 NL80211_CMD_DEAUTHENTICATE, gfp);
4816 }
4817
4818 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4819 struct net_device *netdev, const u8 *buf,
4820 size_t len, gfp_t gfp)
4821 {
4822 nl80211_send_mlme_event(rdev, netdev, buf, len,
4823 NL80211_CMD_DISASSOCIATE, gfp);
4824 }
4825
4826 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4827 struct net_device *netdev, int cmd,
4828 const u8 *addr, gfp_t gfp)
4829 {
4830 struct sk_buff *msg;
4831 void *hdr;
4832
4833 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4834 if (!msg)
4835 return;
4836
4837 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4838 if (!hdr) {
4839 nlmsg_free(msg);
4840 return;
4841 }
4842
4843 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4844 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4845 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4846 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4847
4848 if (genlmsg_end(msg, hdr) < 0) {
4849 nlmsg_free(msg);
4850 return;
4851 }
4852
4853 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4854 nl80211_mlme_mcgrp.id, gfp);
4855 return;
4856
4857 nla_put_failure:
4858 genlmsg_cancel(msg, hdr);
4859 nlmsg_free(msg);
4860 }
4861
4862 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
4863 struct net_device *netdev, const u8 *addr,
4864 gfp_t gfp)
4865 {
4866 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
4867 addr, gfp);
4868 }
4869
4870 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
4871 struct net_device *netdev, const u8 *addr,
4872 gfp_t gfp)
4873 {
4874 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4875 addr, gfp);
4876 }
4877
4878 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4879 struct net_device *netdev, const u8 *bssid,
4880 const u8 *req_ie, size_t req_ie_len,
4881 const u8 *resp_ie, size_t resp_ie_len,
4882 u16 status, gfp_t gfp)
4883 {
4884 struct sk_buff *msg;
4885 void *hdr;
4886
4887 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4888 if (!msg)
4889 return;
4890
4891 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4892 if (!hdr) {
4893 nlmsg_free(msg);
4894 return;
4895 }
4896
4897 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4898 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4899 if (bssid)
4900 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4901 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4902 if (req_ie)
4903 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4904 if (resp_ie)
4905 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4906
4907 if (genlmsg_end(msg, hdr) < 0) {
4908 nlmsg_free(msg);
4909 return;
4910 }
4911
4912 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4913 nl80211_mlme_mcgrp.id, gfp);
4914 return;
4915
4916 nla_put_failure:
4917 genlmsg_cancel(msg, hdr);
4918 nlmsg_free(msg);
4919
4920 }
4921
4922 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4923 struct net_device *netdev, const u8 *bssid,
4924 const u8 *req_ie, size_t req_ie_len,
4925 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4926 {
4927 struct sk_buff *msg;
4928 void *hdr;
4929
4930 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4931 if (!msg)
4932 return;
4933
4934 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4935 if (!hdr) {
4936 nlmsg_free(msg);
4937 return;
4938 }
4939
4940 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4941 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4942 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4943 if (req_ie)
4944 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4945 if (resp_ie)
4946 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4947
4948 if (genlmsg_end(msg, hdr) < 0) {
4949 nlmsg_free(msg);
4950 return;
4951 }
4952
4953 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4954 nl80211_mlme_mcgrp.id, gfp);
4955 return;
4956
4957 nla_put_failure:
4958 genlmsg_cancel(msg, hdr);
4959 nlmsg_free(msg);
4960
4961 }
4962
4963 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4964 struct net_device *netdev, u16 reason,
4965 const u8 *ie, size_t ie_len, bool from_ap)
4966 {
4967 struct sk_buff *msg;
4968 void *hdr;
4969
4970 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4971 if (!msg)
4972 return;
4973
4974 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4975 if (!hdr) {
4976 nlmsg_free(msg);
4977 return;
4978 }
4979
4980 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4981 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4982 if (from_ap && reason)
4983 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4984 if (from_ap)
4985 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4986 if (ie)
4987 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4988
4989 if (genlmsg_end(msg, hdr) < 0) {
4990 nlmsg_free(msg);
4991 return;
4992 }
4993
4994 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4995 nl80211_mlme_mcgrp.id, GFP_KERNEL);
4996 return;
4997
4998 nla_put_failure:
4999 genlmsg_cancel(msg, hdr);
5000 nlmsg_free(msg);
5001
5002 }
5003
5004 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5005 struct net_device *netdev, const u8 *bssid,
5006 gfp_t gfp)
5007 {
5008 struct sk_buff *msg;
5009 void *hdr;
5010
5011 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5012 if (!msg)
5013 return;
5014
5015 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5016 if (!hdr) {
5017 nlmsg_free(msg);
5018 return;
5019 }
5020
5021 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5022 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5023 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5024
5025 if (genlmsg_end(msg, hdr) < 0) {
5026 nlmsg_free(msg);
5027 return;
5028 }
5029
5030 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5031 nl80211_mlme_mcgrp.id, gfp);
5032 return;
5033
5034 nla_put_failure:
5035 genlmsg_cancel(msg, hdr);
5036 nlmsg_free(msg);
5037 }
5038
5039 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5040 struct net_device *netdev, const u8 *addr,
5041 enum nl80211_key_type key_type, int key_id,
5042 const u8 *tsc, gfp_t gfp)
5043 {
5044 struct sk_buff *msg;
5045 void *hdr;
5046
5047 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5048 if (!msg)
5049 return;
5050
5051 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5052 if (!hdr) {
5053 nlmsg_free(msg);
5054 return;
5055 }
5056
5057 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5058 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5059 if (addr)
5060 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5061 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5062 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5063 if (tsc)
5064 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5065
5066 if (genlmsg_end(msg, hdr) < 0) {
5067 nlmsg_free(msg);
5068 return;
5069 }
5070
5071 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5072 nl80211_mlme_mcgrp.id, gfp);
5073 return;
5074
5075 nla_put_failure:
5076 genlmsg_cancel(msg, hdr);
5077 nlmsg_free(msg);
5078 }
5079
5080 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5081 struct ieee80211_channel *channel_before,
5082 struct ieee80211_channel *channel_after)
5083 {
5084 struct sk_buff *msg;
5085 void *hdr;
5086 struct nlattr *nl_freq;
5087
5088 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
5089 if (!msg)
5090 return;
5091
5092 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5093 if (!hdr) {
5094 nlmsg_free(msg);
5095 return;
5096 }
5097
5098 /*
5099 * Since we are applying the beacon hint to a wiphy we know its
5100 * wiphy_idx is valid
5101 */
5102 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5103
5104 /* Before */
5105 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5106 if (!nl_freq)
5107 goto nla_put_failure;
5108 if (nl80211_msg_put_channel(msg, channel_before))
5109 goto nla_put_failure;
5110 nla_nest_end(msg, nl_freq);
5111
5112 /* After */
5113 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5114 if (!nl_freq)
5115 goto nla_put_failure;
5116 if (nl80211_msg_put_channel(msg, channel_after))
5117 goto nla_put_failure;
5118 nla_nest_end(msg, nl_freq);
5119
5120 if (genlmsg_end(msg, hdr) < 0) {
5121 nlmsg_free(msg);
5122 return;
5123 }
5124
5125 rcu_read_lock();
5126 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5127 GFP_ATOMIC);
5128 rcu_read_unlock();
5129
5130 return;
5131
5132 nla_put_failure:
5133 genlmsg_cancel(msg, hdr);
5134 nlmsg_free(msg);
5135 }
5136
5137 /* initialisation/exit functions */
5138
5139 int nl80211_init(void)
5140 {
5141 int err;
5142
5143 err = genl_register_family_with_ops(&nl80211_fam,
5144 nl80211_ops, ARRAY_SIZE(nl80211_ops));
5145 if (err)
5146 return err;
5147
5148 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
5149 if (err)
5150 goto err_out;
5151
5152 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
5153 if (err)
5154 goto err_out;
5155
5156 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
5157 if (err)
5158 goto err_out;
5159
5160 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
5161 if (err)
5162 goto err_out;
5163
5164 #ifdef CONFIG_NL80211_TESTMODE
5165 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
5166 if (err)
5167 goto err_out;
5168 #endif
5169
5170 return 0;
5171 err_out:
5172 genl_unregister_family(&nl80211_fam);
5173 return err;
5174 }
5175
5176 void nl80211_exit(void)
5177 {
5178 genl_unregister_family(&nl80211_fam);
5179 }